DirectorySecurity AdvisoriesPricing
Sign in
Directory
garage logoHELM

garage

Helm chart
Last changed
Request a free trial

Contact our team to test out this Helm chart and related images for free. Please also indicate any other images you would like to evaluate.

Overview
Chart tags
Default values
Chart metadata
Images

Tag:
Compare:

1
# Default values for garage.
2
# This is a YAML-formatted file.
3
# Declare variables to be passed into your templates.
4
5
# -- Additional labels to add to all resources created by this chart
6
commonLabels: {}
7
# app.kubernetes.io/part-of: storage
8
# team: platform
9
10
# Garage configuration. These values configure Garage and render to garage.toml unless noted otherwise.
11
garage:
12
# -- Can be changed for better performance on certain systems, use "sqlite" to prioritize durability
13
# https://garagehq.deuxfleurs.fr/documentation/reference-manual/configuration/#db_engine
14
dbEngine: "lmdb"
15
# -- Defaults is 1MB, an increase can result in better performance in certain scenarios
16
# https://garagehq.deuxfleurs.fr/documentation/reference-manual/configuration/#block_size
17
blockSize: "1048576"
18
# -- Default to 3 replicas, see the replication_factor section at
19
# https://garagehq.deuxfleurs.fr/documentation/reference-manual/configuration/#replication_factor
20
replicationFactor: "3"
21
# -- Start Garage with `--single-node`, run one StatefulSet replica, and render replication_factor = 1 in the generated garage.toml,
22
# if using garageTomlString or existingConfigMap, set replication_factor = 1 yourself.
23
singleNode: false
24
# -- By default, enable read-after-write consistency guarantees, see the consistency_mode section at
25
# https://garagehq.deuxfleurs.fr/documentation/reference-manual/configuration/#consistency_mode
26
consistencyMode: "consistent"
27
# -- zstd compression level of stored blocks
28
# https://garagehq.deuxfleurs.fr/documentation/reference-manual/configuration/#compression_level
29
compressionLevel: "1"
30
# -- If this value is set, Garage will automatically take a snapshot of the metadata DB file at a regular interval and save it in the metadata directory.
31
# https://garagehq.deuxfleurs.fr/documentation/reference-manual/configuration/#metadata_auto_snapshot_interval
32
metadataAutoSnapshotInterval: ""
33
# -- Port used for node-to-node RPC
34
rpcBindAddr: "[::]:3901"
35
# -- If not given, a random secret will be generated and stored in a Secret object
36
rpcSecret: ""
37
# -- If you want to provide an rpcSecret within an existing k8s secret,
38
# specify the secret name here, and store the value under the secret key `rpcSecret`
39
# the default secret will not be created
40
existingRpcSecret: ""
41
# -- This is not required if you use the integrated kubernetes discovery
42
bootstrapPeers: []
43
# -- Set to true if you want to use k8s discovery but install the CRDs manually outside
44
# of the helm chart, for example if you operate at namespace level without cluster resources
45
kubernetesSkipCrd: false
46
# -- Set to true if you want to use roles instead of cluster roles
47
noClusterRole: false
48
s3:
49
api:
50
bindAddr: "[::]:3900"
51
region: "garage"
52
rootDomain: ".s3.garage.tld"
53
web:
54
bindAddr: "[::]:3902"
55
rootDomain: ".web.garage.tld"
56
index: "index.html"
57
admin:
58
apiBindAddr: "[::]:3903"
59
# -- Additional configuration to append to garage.toml. Use a multi-line string for custom config.
60
# Example:
61
# additionalTopLevelConfig: |-
62
# data_fsync = true
63
additionalTopLevelConfig: ""
64
# -- if not empty string, allow using an existing ConfigMap for the garage.toml,
65
# if set, ignores garage.toml
66
existingConfigMap: ""
67
# -- String Template for the garage configuration
68
# if set, ignores above values.
69
# Values can be templated,
70
# see https://garagehq.deuxfleurs.fr/documentation/reference-manual/configuration/
71
garageTomlString: ""
72
# Data persistence
73
persistence:
74
enabled: true
75
meta:
76
# storageClass: "fast-storage-class"
77
size: 100Mi
78
# used only for daemon sets
79
hostPath: /var/lib/garage/meta
80
data:
81
# storageClass: "slow-storage-class"
82
size: 100Mi
83
# used only for daemon sets
84
hostPath: /var/lib/garage/data
85
# Deployment configuration
86
deployment:
87
# -- Switchable to DaemonSet
88
kind: StatefulSet
89
# -- Number of StatefulSet replicas/garage nodes to start
90
replicaCount: 3
91
# -- If using statefulset, allow Parallel or OrderedReady (default)
92
podManagementPolicy: OrderedReady
93
image:
94
# -- default to amd64 docker image
95
repository: chainreg.biz/chainguard-private/garage
96
# -- set the image tag, please prefer using the chart version and not this,
97
# to avoid compatibility issues
98
tag: 2.4.1-r3@sha256:ab207d538f50ecfa01c042df32423f41725db6bfb3a8e20c84e2486f7389bc12
99
pullPolicy: IfNotPresent
100
initImage:
101
repository: chainreg.biz/chainguard-private/busybox
102
tag: glibc-1.38.0-r2@sha256:7a438bd8593293ec90b6249fd8a51259874dadc11c3a9976bbcc0b935ce4cb51
103
pullPolicy: IfNotPresent
104
# -- set if you need credentials to pull your custom image
105
imagePullSecrets: []
106
nameOverride: ""
107
fullnameOverride: ""
108
serviceAccount:
109
# -- Specifies whether a service account should be created
110
create: true
111
# -- Annotations to add to the service account
112
annotations: {}
113
# -- The name of the service account to use.
114
# If not set and create is true, a name is generated using the fullname template
115
name: ""
116
# -- additional pod annotations
117
podAnnotations: {}
118
podSecurityContext:
119
runAsUser: 1000
120
runAsGroup: 1000
121
fsGroup: 1000
122
fsGroupChangePolicy: "OnRootMismatch"
123
runAsNonRoot: true
124
securityContext:
125
# -- The default security context is heavily restricted,
126
# feel free to tune it to your requirements
127
capabilities:
128
drop:
129
- ALL
130
readOnlyRootFilesystem: true
131
service:
132
# -- You can rely on any service to expose your cluster
133
# - ClusterIP (+ Ingress)
134
# - NodePort (+ Ingress)
135
# - LoadBalancer
136
type: ClusterIP
137
# -- Annotations to add to the service
138
annotations: {}
139
s3:
140
api:
141
port: 3900
142
web:
143
port: 3902
144
# NOTE: the admin API is excluded for now as it is not consistent across nodes
145
ingress:
146
s3:
147
api:
148
enabled: false
149
# -- Rely _either_ on the className or the annotation below but not both!
150
# If you want to use the className, set
151
# className: "nginx"
152
# and replace "nginx" by an Ingress controller name,
153
# examples [here](https://kubernetes.io/docs/concepts/services-networking/ingress-controllers).
154
annotations: {}
155
# kubernetes.io/ingress.class: "nginx"
156
# kubernetes.io/tls-acme: "true"
157
labels: {}
158
hosts:
159
# -- garage S3 API endpoint, to be used with awscli for example
160
- host: "s3.garage.tld"
161
paths:
162
- path: /
163
pathType: Prefix
164
# -- garage S3 API endpoint, DNS style bucket access
165
- host: "*.s3.garage.tld"
166
paths:
167
- path: /
168
pathType: Prefix
169
tls: []
170
# - secretName: my-garage-cluster-tls
171
# hosts:
172
# - kubernetes.docker.internal
173
web:
174
enabled: false
175
# -- Rely _either_ on the className or the annotation below but not both!
176
# If you want to use the className, set
177
# className: "nginx"
178
# and replace "nginx" by an Ingress controller name,
179
# examples [here](https://kubernetes.io/docs/concepts/services-networking/ingress-controllers).
180
annotations: {}
181
# kubernetes.io/ingress.class: nginx
182
# kubernetes.io/tls-acme: "true"
183
labels: {}
184
hosts:
185
# -- wildcard website access with bucket name prefix
186
- host: "*.web.garage.tld"
187
paths:
188
- path: /
189
pathType: Prefix
190
# -- specific bucket access with FQDN bucket
191
- host: "mywebpage.example.com"
192
paths:
193
- path: /
194
pathType: Prefix
195
tls: []
196
# - secretName: my-garage-cluster-tls
197
# hosts:
198
# - kubernetes.docker.internal
199
resources: {}
200
# The following are indicative for a small-size deployment, for anything serious double them.
201
# limits:
202
# cpu: 100m
203
# memory: 1024Mi
204
# requests:
205
# cpu: 100m
206
# memory: 512Mi
207
208
# -- Specifies a livenessProbe
209
livenessProbe: {}
210
#httpGet:
211
# path: /health
212
# port: 3903 # or the port from garage.admin.apiBindAddr
213
#initialDelaySeconds: 5
214
#periodSeconds: 30
215
# -- Specifies a readinessProbe
216
readinessProbe: {}
217
#httpGet:
218
# path: /health
219
# port: 3903 # or the port from garage.admin.apiBindAddr
220
#initialDelaySeconds: 5
221
#periodSeconds: 30
222
223
nodeSelector: {}
224
tolerations: []
225
affinity: {}
226
# -- Optional priority class name to assign to the pods.
227
# See https://kubernetes.io/docs/concepts/scheduling-eviction/pod-priority-preemption/
228
priorityClassName: ""
229
# -- Extra container env vars, as a list of {name, value} objects (same shape
230
# as a Pod container's env)
231
environment: {}
232
# -- Override the container entrypoint.
233
command: []
234
# -- Override the container arguments.
235
args: []
236
# -- Extra volumes, as a list of volume objects (same shape as a PodSpec's volumes)
237
extraVolumes: {}
238
# -- Extra volume mounts, as a list of mount objects (same shape as a container's volumeMounts)
239
extraVolumeMounts: {}
240
monitoring:
241
metrics:
242
# -- If true, a service for monitoring is created with a prometheus.io/scrape annotation
243
enabled: false
244
serviceMonitor:
245
# -- If true, a ServiceMonitor CRD is created for a prometheus operator
246
# https://github.com/coreos/prometheus-operator
247
enabled: false
248
path: /metrics
249
# namespace: monitoring (defaults to use the namespace this chart is deployed to)
250
labels: {}
251
interval: 15s
252
scheme: http
253
tlsConfig: {}
254
scrapeTimeout: 10s
255
relabelings: []
256
tracing:
257
# -- specify a sink endpoint for OpenTelemetry Traces, eg. `http://localhost:4317`
258
sink: ""
259

The trusted source for open source

Talk to an expert
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsChainguard OS PackagesChainguard ActionsChainguard Agent SkillsIntegrationsPricing
© 2026 Chainguard, Inc. All Rights Reserved.
Chainguard® and the Chainguard logo are registered trademarks of Chainguard, Inc. in the United States and/or other countries.
The other respective trademarks mentioned on this page are owned by the respective companies and use of them does not imply any affiliation or endorsement.