DirectorySecurity AdvisoriesPricing
Sign in
Directory
k8s-gateway logoHELM

k8s-gateway

Helm chart
Last changed
Request a free trial

Contact our team to test out this Helm chart and related images for free. Please also indicate any other images you would like to evaluate.

Overview
Chart tags
Default values
Chart metadata
Images

Tag:
Compare:

1
image:
2
registry: chainreg.biz
3
repository: chainguard-private/k8s_gateway
4
tag: 1.8.2-r12@sha256:ea377d1bef319c983e887d6aa9bb5e5b1e34d3d2af06a344b0c4611f42b94c37
5
pullPolicy: IfNotPresent
6
# Reference to one or more secrets to be used when pulling images.
7
# For more information, see [Pull an Image from a Private Registry](https://kubernetes.io/docs/tasks/configure-pod-container/pull-image-private-registry/).
8
#
9
# For example:
10
# imagePullSecrets:
11
# - name: "image-pull-secret"
12
imagePullSecrets: []
13
# Delegated domain
14
domain: ""
15
# Prefer the hostname or IP in LoadBalancer status entries
16
loadBalancerAddressPreference: hostname
17
# Optional scheme for DNS server (e.g., "tls://", "https://", "grpc://")
18
# Used to enable DoT (DNS over TLS), DoH (DNS over HTTPS), or gRPC protocols
19
# Leave empty for standard DNS
20
# See: https://coredns.io/plugins/tls/
21
scheme: ""
22
# Labels to apply to all resources
23
customLabels: {}
24
# Annotations to apply to pods
25
podAnnotations: {}
26
# TTL for non-apex responses (in seconds)
27
ttl: 300
28
# Resources (CPU, memory etc)
29
resources: {}
30
# Limit what kind of resources to watch, e.g. watchedResources: ["Ingress"]
31
watchedResources: ["Ingress", "Service"]
32
filters:
33
ingressClasses: []
34
gatewayClasses: []
35
serviceLabelSelectors: []
36
# Service name of a secondary DNS server (should be `serviceName.namespace`)
37
secondary: ""
38
# Enabled fallthrough for k8s_gateway
39
fallthrough:
40
enabled: false
41
zones: []
42
# Override the default `serviceName.namespace` domain apex
43
apex: ""
44
# Optional configuration option for DNS01 challenge that will redirect all acme
45
# challenge requests to external cloud domain (e.g. managed by cert-manager)
46
# See: https://cert-manager.io/docs/configuration/acme/dns01/
47
dnsChallenge:
48
enabled: false
49
domain: dns01.clouddns.com
50
# Optional plugins that will be enabled in the zone, e.g. "forward . /etc/resolve.conf"
51
extraZonePlugins:
52
- name: log
53
- name: errors
54
# Serves a /health endpoint on :8080, required for livenessProbe
55
- name: health
56
configBlock: |-
57
lameduck 5s
58
# Serves a /ready endpoint on :8181, required for readinessProbe
59
- name: ready
60
# Serves a /metrics endpoint on :9153, required for serviceMonitor
61
- name: prometheus
62
parameters: 0.0.0.0:9153
63
- name: forward
64
parameters: . /etc/resolv.conf
65
- name: loop
66
- name: reload
67
- name: loadbalance
68
# Example TLS configuration (requires scheme: "tls://" and TLS certificates)
69
# - name: tls
70
# parameters: /etc/coredns/tls/tls.crt /etc/coredns/tls/tls.key
71
# configBlock: |-
72
# client_auth {
73
# type request
74
# }
75
76
serviceAccount:
77
create: true
78
name: ""
79
annotations: {}
80
service:
81
type: LoadBalancer
82
port: 53
83
annotations: {}
84
labels: {}
85
# nodePort: 30053
86
# loadBalancerIP: 192.168.1.2
87
# loadBalancerClass:
88
# clusterIP: 10.43.0.53
89
# externalTrafficPolicy: Local
90
# externalIPs:
91
# - 192.168.1.3
92
# One of SingleStack, PreferDualStack, or RequireDualStack.
93
# ipFamilyPolicy: SingleStack
94
# List of IP families (e.g. IPv4 and/or IPv6).
95
# ref: https://kubernetes.io/docs/concepts/services-networking/dual-stack/#services
96
# ipFamilies:
97
# - IPv4
98
# - IPv6
99
useTcp: false
100
nodeSelector: {}
101
tolerations: []
102
topologySpreadConstraints: []
103
affinity: {}
104
replicaCount: 1
105
# Optional PriorityClass that will be used in the Deployment, e.g. priorityClassName: "system-cluster-critical"
106
priorityClassName: ""
107
debug:
108
enabled: false
109
secure: true
110
podSecurityContext: {}
111
securityContext: {}
112
# file plugin
113
zoneFiles: []
114
# - filename: example.db
115
# # Optional
116
# domains: example.com
117
# fallthrough:
118
# enabled: true
119
# zones:
120
# - test.example.com
121
# reload: 1m
122
# contents: |
123
# example.com. IN SOA sns.dns.icann.com. noc.dns.icann.com. 2015082541 7200 3600 1209600 3600
124
# example.com. IN NS b.iana-servers.net.
125
# example.com. IN NS a.iana-servers.net.
126
# example.com. IN A 192.168.99.102
127
# *.example.com. IN A 192.168.99.102
128
129
extraVolumes: []
130
# extraVolumes:
131
# - name: tsig-secret
132
# secret:
133
# secretName: tsig-secret
134
extraVolumeMounts: []
135
# extraVolumeMounts:
136
# - name: tsig-volume
137
# mountPath: /etc/tsig
138
# subPath: tsig.key
139
# readOnly: true
140

The trusted source for open source

Talk to an expert
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsChainguard OS PackagesChainguard ActionsChainguard Agent SkillsIntegrationsPricing
© 2026 Chainguard, Inc. All Rights Reserved.
Chainguard® and the Chainguard logo are registered trademarks of Chainguard, Inc. in the United States and/or other countries.
The other respective trademarks mentioned on this page are owned by the respective companies and use of them does not imply any affiliation or endorsement.