1## Default values for kargo.
2## A human-readable version can be found in the chart README.
3## This is a YAML-formatted file.
4## Declare variables to be passed into your templates.
6## @section Image Parameters
8 ## @param image.repository Image repository of Kargo
9 repository: chainreg.biz/chainguard-private/kargo
10 ## @param image.tag Overrides the image tag. The default tag is the value of `.Chart.AppVersion`
11 tag: 1.11.7-r0@sha256:66c0607e2ededf381ed8eea2bc2e3d1d06e0cc6876e9c73e958430f7ccac17ff
12 ## @param image.pullPolicy Image pull policy
13 pullPolicy: IfNotPresent
14 ## @param image.pullSecrets List of imagePullSecrets.
17## @section Global Parameters
20 ## @param global.systemResources.namespace Designates a namespace to contain resources associated with cluster-scoped resources and for which no cluster-scoped analog exists. For example, ClusterConfig is a cluster-scoped resource. Cluster-scoped webhook receivers, defined as part of that resource, each must reference a Secret, however, no such thing as a cluster-scoped Secret exists within Kubernetes. To work around that, all Secrets referenced by a ClusterConfig resource must be located in a designated namespace. NOTE: The namespace designated for this purpose is NOT the place to put resources that you want to share across all Projects. This namespace is strictly for namespaced resources that must be referenced by other, cluster-scoped resources.
21 namespace: kargo-system-resources
22 ## @param global.systemResources.createNamespace Indicates whether the namespace specified by `global.systemResources.namespace` should be created when installing the chart.
24 ## @param global.systemResources.createRBAC Indicates whether the Roles/RoleBindings in the namespace specified by `global.systemResources.namespace` should be created when installing the chart.
26 ## @param global.systemResources.extraNamespaceAnnotations Additional annotations to be added to the namespace specified by `global.systemResources.namespace`.
27 extraNamespaceAnnotations: {}
28 ## @param global.systemResources.extraNamespaceLabels Additional labels to be added to the namespace specified by `global.systemResources.namespace`.
29 extraNamespaceLabels: {}
31 ## @param global.sharedResources.namespace designates a namespace where shared resources can be located.
32 namespace: kargo-shared-resources
33 ## @param global.sharedResources.createNamespace Indicates whether the namespace specified by `global.sharedResources.namespace` should be created when installing the chart.
35 ## @param global.sharedResources.createRBAC Indicates whether the Roles/RoleBindings in the namespace specified by `global.sharedResources.namespace` should be created when installing the chart.
37 ## @param global.sharedResources.extraNamespaceAnnotations Additional annotations to be added to the namespace specified by `global.sharedResources.namespace`.
38 extraNamespaceAnnotations: {}
39 ## @param global.sharedResources.extraNamespaceLabels Additional labels to be added to the namespace specified by `global.sharedResources.namespace`.
40 extraNamespaceLabels: {}
41 ## @param global.labels Labels to add to all resources.
43 ## @param global.annotations Annotations to add to all resources.
45 ## @param global.podLabels Labels to add to all pods.
47 ## @param global.podAnnotations Annotations to add to pods.
49 ## ServiceAccount global settings
51 ## @param global.serviceAccount.labels Global ServiceAccount labels.
53 ## @param global.serviceAccount.annotations Global ServiceAccount annotations.
57 ## @param global.env Environment variables to add to all Kargo pods.
61 ## @param global.envFrom Environment variables to add to all Kargo pods from ConfigMaps or Secrets.
64 # name: config-map-name
68 ## @param global.nodeSelector Default node selector for all Kargo pods.
70 ## @param global.tolerations Default tolerations for all Kargo pods.
72 ## @param global.affinity Default affinity for all Kargo pods.
74 ## @param global.priorityClassName [nullable] Default priority class for all Kargo pods.
76 ## @param global.securityContext Default security context for all Kargo pods.
80 ## @param workloads.install Whether to install workload-bearing resources (Deployments, CronJobs, etc.) and their supporting resources.
84 ## @param dataPlane.install Coarse switch that, when `false`, suppresses every data-plane resource — even where finer-grained flags (`crds.install`, `rbac.installClusterRoles`, `rbac.installClusterRoleBindings`, `webhooks.register`, `global.sharedResources.createNamespace`, `global.systemResources.createNamespace`) would otherwise install them. Note: Argo CD data-plane RBAC is governed separately by `argocd.dataPlane.install`.
87 ## @param dataPlane.controller.install Coarse switch governing whether per-controller data-plane resources are rendered.
89## @section Argo CD Data Plane
91 ## @param argocd.dataPlane.install Coarse switch governing Argo CD data-plane resources — the RBAC granting the controller access to Argo CD `Application` resources. Separate from `dataPlane.install` because Argo CD may reside in a different cluster than Kargo's own data plane.
95 ## @param argocd.dataPlane.kargoController.install Coarse switch governing whether per-Kargo-controller Argo CD data-plane resources are rendered.
99 ## @param crds.install Indicates if Custom Resource Definitions should be installed and upgraded as part of the release. If set to `false`, the CRDs will only be installed if they do not already exist.
101 ## @param crds.keep Indicates if Custom Resource Definitions should be kept when a release is uninstalled.
105 ## @param rbac.installClusterRoles Indicates if `ClusterRoles` should be installed.
106 installClusterRoles: true
107 ## @param rbac.installClusterRoleBindings Indicates if `ClusterRoleBindings` should be installed.
108 installClusterRoleBindings: true
111 ## @param webhooks.register Whether to create `ValidatingWebhookConfiguration` and `MutatingWebhookConfiguration` resources.
113## @section KubeConfigs
115## Optionally point to Kubernetes Secrets containing kubeconfig for:
117## 1. A remote cluster hosting Kargo resources
119## 2. A remote cluster hosting Argo CD resources
121## This flexibility is useful for various advanced use cases -- especially
122## topologies where Kargo data may be sharded, with Kargo controllers distributed
123## across many clusters. Either or both of these configurations may be the same.
124## In the average case, these should all be left unspecified. All that are
125## unspecified will default to configuration for the cluster in which the Kargo
126## controller is running.
128## @skip kubeconfigSecrets
130## @param kubeconfigSecrets.kargo [nullable] Kubernetes `Secret` name containing kubeconfig for a remote Kubernetes cluster hosting Kargo resources. Used by all Kargo components.
132## @param kubeconfigSecrets.argocd [nullable] Kubernetes `Secret` name containing kubeconfig for a remote Kubernetes cluster hosting Argo CD resources. Used by Kargo controller(s) only.
137 ## @param api.enabled Whether the API server is enabled.
139 ## @skip api.kubeconfigSecrets
140 kubeconfigSecrets: {}
141 ## @param api.kubeconfigSecrets.kargo [nullable] Per-component override for `kubeconfigSecrets.kargo`. Lets the API server mount its own kubeconfig secret rather than the shared one. Falls back to the chart-level value when unset.
144 ## @param api.replicas The number of API server pods.
146 ## @param api.revisionHistoryLimit Number of old ReplicaSets the API server Deployment retains for rollback.
147 revisionHistoryLimit: 10
148 ## @param api.rollingUpdate Values merged into the chart-built `strategy.rollingUpdate` for the API server Deployment. Typically used to tune `maxSurge` and `maxUnavailable` (each an absolute number or a percentage). Default empty map — Kubernetes defaults (25% / 25%) apply.
151 # maxUnavailable: 25%
153 ## @param api.host The domain name where Kargo's API server will be accessible. When applicable, this is used for generation of an Ingress resource, certificates, and the OpenID Connect issuer and callback URLs. Note: The value in this field MAY include a port number and MUST NOT specify the protocol (http vs https), which is automatically inferred from other configuration options.
155 ## @param api.basePath URL path prefix at which the API server is reachable. When non-empty, MUST begin with a slash and MUST NOT end with one (e.g. `/kargo`). Used as the path on any chart-generated Ingress rule for the API server, and included in chart-generated URLs (`API_SERVER_BASE_URL`, `ADMIN_ACCOUNT_TOKEN_ISSUER`, `OIDC_ISSUER_URL`, etc.). The API server binary itself always serves at the root, so when this is set, the user is responsible for configuring their Ingress controller to strip the prefix before forwarding (e.g. via Traefik's `stripPrefix` middleware, NGINX's `rewrite`, etc.).
157 ## @param api.logLevel The log level for the API server. Valid options are ERROR, INFO, DEBUG, and TRACE (case insensitive). Note that INFO level messages are written during startup regardless of the selected level.
159 ## @param api.logFormat The format of logs from the API server. Valid options are CONSOLE or JSON (case insensitive).
161 ## @param api.secretManagementEnabled Specifies whether Secret management is enabled. This affects the API server's ability to manage repository credentials and other Project-level Secrets, such as those used by AnalysisRuns for verification purposes. If using GitOps to manage Kargo Projects declaratively, the API's Secret management capabilities are not needed and can be disabled to effectively reduce the API server's attackable surface.
162 secretManagementEnabled: true
163 ## @param api.permissiveCORSPolicyEnabled Whether to enable a permissive CORS (Cross Origin Resource Sharing) policy. This is sometimes advantageous during local development, but otherwise, should generally be left disabled.
164 permissiveCORSPolicyEnabled: false
165 ## @param api.trustedProxies IP addresses or CIDRs of proxies (e.g. an ingress controller or load balancer) in front of the API server. When a request arrives from one of these, the client's IP address is taken from `api.clientIPHeader`, or else from the rightmost `X-Forwarded-For` entry that is not a trusted proxy. When empty, the client's IP address is always the address the request arrived from.
167 ## @param api.clientIPHeader A header that every trusted proxy sets to the client's IP address, e.g. `CF-Connecting-IP` or `X-Real-IP`. Only honored on requests arriving from a trusted proxy.
170 ## @param api.requestLog.allEnabled Whether to log every API request at INFO level. By default, only refused requests (401 and 403) are logged at INFO level and server errors at ERROR level, while all other requests are logged at DEBUG level.
172 ## @param api.requestLog.sourceIPEnabled Whether to include the IP address each request came from in the API server's logs. IP addresses may be considered personal data, so this is disabled by default.
173 sourceIPEnabled: false
175 ## @param api.secret.name Specifies the name of an existing Secret which contains the `ADMIN_ACCOUNT_PASSWORD_HASH` and `ADMIN_ACCOUNT_TOKEN_SIGNING_KEY` values. By setting this, the Secret will **not** be generated by Helm.
178 ## @param api.adminAccount.enabled Whether to enable the admin account.
180 ## @param api.adminAccount.passwordHash Bcrypt password hash for the admin account. A value **must** be provided for this field unless `api.secret.name` is specified.
182 ## @param api.adminAccount.tokenSigningKey Key used to sign ID tokens (JWTs) for the admin account. It is suggested that you generate this using a password manager or a command like: `openssl rand -base64 29 \| tr -d "=+/" \| cut`. A value **must** be provided for this field, unless `api.secret.name` is specified.
184 ## @param api.adminAccount.tokenTTL Specifies how long ID tokens for the admin account are valid. (i.e. The expiry will be the time of issue plus this duration.)
186 ## Optionally provide custom ClusterRole permissions for the various built in roles. This is
187 ## useful if you want to grant extra permissions to these roles without creating entirely new
188 ## roles. These should be a list of valid `roles` as you would include in a `ClusterRole`
192 ## @param api.clusterRoles.admin.additionalRules Additional RBAC rules to add to the kargo-admin ClusterRole.
193 additionalRules: null
195 ## @param api.clusterRoles.projectCreator.additionalRules Additional RBAC rules to add to the kargo-project-creator ClusterRole.
196 additionalRules: null
198 ## @param api.clusterRoles.user.additionalRules Additional RBAC rules to add to the kargo-user ClusterRole.
199 additionalRules: null
201 ## @param api.clusterRoles.viewer.additionalRules Additional RBAC rules to add to the kargo-viewer ClusterRole.
202 additionalRules: null
203 ## All settings related to enabling OpenID Connect as an authentication
206 ## @param api.oidc.enabled Whether to enable authentication using Open ID Connect.
207 ## NOTE: Kargo uses the Authorization Code Flow with Proof Key for Code Exchange (PKCE) and does not require a client secret. Some OIDC identity providers may not support this. If yours does not, enabling the optional Dex server and configuring its connectors can adapt most identity providers to work this way.
208 ## Note also: The PKCE code challenge used by Kargo is SHA256 hashed.
209 ## For more information about PKCE, please visit: https://oauth.net/2/pkce/
211 ## @param api.oidc.issuerURL The issuer URL for the identity provider. If Dex is enabled, this value will be ignored and the issuer URL will be automatically configured. If Dex is not enabled, this should be set to the issuer URL provided to you by your identity provider.
213 ## @param api.oidc.clientID The client ID for the OIDC client. If Dex is enabled, this value will be ignored and the client ID will be automatically configured. If Dex is not enabled, this should be set to the client ID provided to you by your identity provider.
215 ## @param api.oidc.cliClientID The client ID for the OIDC client used by CLI (optional). Needed by some OIDC providers (such as Dex) that require a separate Client ID for web app login vs. CLI login (`http://localhost`). If Dex is enabled, this value will be ignored and cli client ID will be automatically configured. If Dex is not enabled, and a different client app is configured for localhost CLI login, this should be the client ID configured in the IdP.
217 ## @param api.oidc.additionalScopes The additional scopes to send to the OIDC provider. This should be set to the scopes you wish to be provided to your identity provider from clients of Kargo, the scopes openid, profile and email are always requested and don't need to be added, this value is intended for any additional ones you require.
220 ## @param api.oidc.usernameClaim The claim to use as the username for the user.
223 ## @param api.oidc.admins.claims Subjects having any of these claims will automatically be Kargo admins.
229 # - alice@example.com
234 ## @param api.oidc.projectCreators.claims Subjects having any of these claims will automatically receive the permissions of the karo-user role (see `api.oidc.users`) **plus** permission to create new `Project`s. When a `Project` is created by such a user via the CLI or UI (i.e. through the API and not through `kubectl`) they will automatically receive admin permissions within that `Project` as well as permission to update and delete the cluster-scoped `Project` resource itself.
240 # - alice@example.com
243 # - kargo-project-creator
245 ## @param api.oidc.users.claims Subjects having any of these claims will automatically receive read-only access to all cluster-scoped Kargo resources. This is the minimum level of permissions that can be granted to a user to allow them to view the list of Projects and system-level configuration. This does not include any access to `Secrets`.
251 # - alice@example.com
256 ## @param api.oidc.viewers.claims Subjects having any of these claims will automatically receive read-only access to all Kargo resources. This does not include any access to `Secret`s.
262 # - alice@example.com
266 globalServiceAccounts:
267 ## @param api.oidc.globalServiceAccounts.namespaces List of namespaces to look for shared service accounts.
270 ## @param api.oidc.dex.enabled Whether to enable Dex as the identity provider. When set to true, the Kargo installation will include a Dex server and the Kargo API server will be configured to make the /dex endpoint a reverse proxy for the Dex server.
272 ## All settings related to using an externally-managed Dex server (one not installed by this chart). When `byo.enabled` is `true`, the chart will NOT install a Dex server but the Kargo API server will still proxy `/dex` to the externally-managed Dex server. Configure `api.oidc.issuerURL`, `api.oidc.clientID`, etc. just as you would for any other OIDC identity provider. Mutually exclusive with `api.oidc.dex.enabled`.
274 ## @param api.oidc.dex.byo.enabled Whether to enable proxying to an externally-managed Dex server.
276 ## @param api.oidc.dex.byo.serverAddress Address (scheme + host + optional port) at which the Kargo API server should reach the externally-managed Dex server. This is used for in-cluster traffic from the API server pod to Dex, not for what end-user clients see (clients see `api.oidc.issuerURL`). Defaults to `https://kargo-dex-server.<release.namespace>.svc` — matching the chart's convention for a Dex Service named `kargo-dex-server` in the release namespace.
278 ## @param api.oidc.dex.byo.caCertPath Path inside the Kargo API server container at which a CA certificate trusted by Dex is mounted. Optional. When set, the API server will use this certificate when making outbound TLS connections to the externally-managed Dex server. The cert itself must be made available via `api.containers` / `api.volumes` / `api.volumeMounts` (or another out-of-band mechanism).
280 ## @param api.oidc.dex.revisionHistoryLimit Number of old ReplicaSets the Dex server Deployment retains for rollback.
281 revisionHistoryLimit: 10
282 ## @param api.oidc.dex.rollingUpdate Values merged into the chart-built `strategy.rollingUpdate` for the Dex server Deployment. Typically used to tune `maxSurge` and `maxUnavailable` (each an absolute number or a percentage). Default empty map — Kubernetes defaults (25% / 25%) apply.
285 # maxUnavailable: 25%
288 ## @param api.oidc.dex.image.repository Image repository of Dex
289 repository: chainreg.biz/chainguard-private/dex
290 ## @param api.oidc.dex.image.tag Image tag for Dex.
291 tag: 2.46.0-r0@sha256:9b3d0cccc4b13032ae372d99eea071b3a6ee607a8e52151a1a42d0d97b9d346c
292 ## @param api.oidc.dex.image.pullPolicy Image pull policy for Dex.
293 pullPolicy: IfNotPresent
294 ## @param api.oidc.dex.image.pullSecrets List of imagePullSecrets.
297 ## @param api.oidc.dex.logLevel The log level for the Dex server. Since Dex server is a third-party software, its log level options differ from the other Kargo components. The valid options are: DEBUG, INFO, WARN, ERROR.
299 ## @param api.oidc.dex.logFormat The format of logs from the Dex server. Since Dex server is a third-party software, its log format options differ from the other Kargo components. The valid options are TEXT and JSON.
301 ## @param api.oidc.dex.skipApprovalScreen Whether to skip Dex's own approval screen. Since upstream identity providers will already request user consent, this second approval screen from Dex can be both superfluous and confusing.
302 skipApprovalScreen: true
303 ## @param api.oidc.dex.connectors Configure [Dex connectors](https://dexidp.io/docs/connectors/) to one or more upstream identity providers.
313 # clientID: <your client ID>
314 # clientSecret: "$CLIENT_SECRET"
315 # redirectURI: <http(s)>://<api.host>/dex/callback
321 # clientID: <your client ID>
322 # clientSecret: "$CLIENT_SECRET"
323 # redirectURI: <http(s)>://<api.host>/dex/callback
329 # clientID: <your client ID>
330 # clientSecret: "$CLIENT_SECRET"
331 # redirectURI: <http(s)>://<api.host>/dex/callback
332 # tenant: <tenant ID>
334 ## ServiceAccount specific settings
336 ## @param api.oidc.dex.serviceAccount.labels Additional labels to add to the Dex server ServiceAccount.
338 ## @param api.oidc.dex.serviceAccount.annotations Additional annotations to add to the Dex server ServiceAccount.
342 ## @param api.oidc.dex.env Environment variables to add to Dex server pods. This is convenient for cases where api.oidc.dex.connectors needs to reference environment variables from a Secret that is managed "out of band" with a secret management solution such as Sealed Secrets.
344 # - name: CLIENT_SECRET
348 # key: dex.github.clientSecret
349 ## @param api.oidc.dex.envFrom Environment variables to add to Dex server pods from ConfigMaps or Secrets. This is especially convenient for cases where api.oidc.dex.connectors needs to reference environment variables from a Secret that is managed "out of band" with a secret management solution such as Sealed Secrets.
352 # name: config-map-name
356 ## @param api.oidc.dex.containers Additional sidecar containers to add to Dex pods. Rendered as literal YAML.
358 ## @param api.oidc.dex.initContainers Additional init containers to add to Dex pods. Rendered as literal YAML.
360 ## @param api.oidc.dex.volumes Add additional volumes to Dex pods. This is convenient for cases where api.oidc.dex.connectors needs to reference mounted data from a Secret that is managed "out of band" with a secret management solution such as Sealed Secrets.
362 # - name: google-json
365 # secretName: kargo-google-groups-json
366 ## @param api.oidc.dex.volumeMounts Add additional volume mounts to Dex pods. This is convenient for cases where api.oidc.dex.connectors needs to reference mounted data from a Secret that is managed "out of band" with a secret management solution such as Sealed Secrets.
368 # - mountPath: /tmp/oidc
372 ## @param api.oidc.dex.resources Resources limits and requests for the Dex server containers.
381 ## @param api.oidc.dex.nodeSelector Node selector for Dex server pods. Defaults to `global.nodeSelector`.
383 ## @param api.oidc.dex.tolerations Tolerations for Dex server pods. Defaults to `global.tolerations`.
385 ## @param api.oidc.dex.affinity Specifies pod affinity for the Dex server pods. Defaults to `global.affinity`.
387 ## @param api.oidc.dex.priorityClassName [nullable] Name of the priority class for the Dex server pods. Defaults to `global.priorityClassName`.
389 ## @param api.oidc.dex.annotations Annotations to add to the Dex server deployment. Merges with `global.annotations`, allowing you to override or add to the global annotations.
391 ## @param api.oidc.dex.podAnnotations Annotations to add to the Dex server pods. Merges with `global.podAnnotations`, allowing you to override or add to the global annotations.
393 ## @param api.oidc.dex.securityContext Security context for Dex server pods. Defaults to `global.securityContext`.
396 ## @param api.oidc.dex.probes.enabled Whether startup, liveness, and readiness probes should be included in the Dex server deployment. It is sometimes advantageous to disable these during local development.
398 ## @param api.oidc.dex.probes.startupProbe [object] Values merged into the chart-built `startupProbe` for the Dex server. Typically used to tune timing fields like `initialDelaySeconds`, `periodSeconds`, `timeoutSeconds`, `successThreshold`, and `failureThreshold`.
400 initialDelaySeconds: 10
403 # successThreshold: 1
405 ## @param api.oidc.dex.probes.livenessProbe [object] Values merged into the chart-built `livenessProbe` for the Dex server. Default is an empty map, so the chart's `livenessProbe` renders with Kubernetes-default timings.
407 # initialDelaySeconds: 0
410 # successThreshold: 1
411 # failureThreshold: 3
412 ## @param api.oidc.dex.probes.readinessProbe [object] Values merged into the chart-built `readinessProbe` for the Dex server.
414 initialDelaySeconds: 5
417 # successThreshold: 1
418 # failureThreshold: 3
420 ## @param api.oidc.dex.tls.selfSignedCert Whether to generate a self-signed certificate for use with Dex. If `true`, `cert-manager` CRDs **must** be present in the cluster. The chart will create and use its own namespaced `Issuer`. If `false`, a cert `Secret` with the name specified by `api.oidc.dex.tls.secretName` **must** be provided in the same namespace as Kargo. There is no provision for running Dex without TLS.
422 ## @param api.oidc.dex.tls.secretName Name of the cert `Secret` for use with Dex. When `api.oidc.dex.tls.selfSignedCert` is `true`, this will be the name of the generated cert `Secret`. When `api.oidc.dex.tls.selfSignedCert` is `false`, a cert `Secret` with this name **must** be provided in the same namespace as Kargo. There is no provision for running Dex without TLS.
423 secretName: kargo-dex-server-cert
425 ## @param api.argocd.urls Mapping of Argo CD shards names to URLs to support deep links to Argo CD URLs. If sharding is not used, map the empty string to the single Argo CD URL.
427 # "": https://argocd.example.com
428 # "shard2": https://argocd2.example.com
429 ## All settings relating to the use of Argo Rollouts by the API Server.
431 ## @param api.rollouts.integrationEnabled Specifies whether Argo Rollouts integration is enabled. When not enabled, the API server will not be capable of creating/updating/applying AnalysesTemplate resources in the Kargo control plane. When enabled, the API server will perform a sanity check at startup. If Argo Rollouts CRDs are not found, the API server will proceed as if this integration had been explicitly disabled. Explicitly disabling is still preferable if this integration is not desired, as it will grant fewer permissions to the API server.
432 integrationEnabled: true
433 ## All settings related to streaming logs from the pods of AnalysisRuns using JobMetric providers.
435 ## @param api.rollouts.logs.enabled Specifies whether support for streaming logs from AnalysisRuns using a JobMetric provider is enabled. This feature requires you to have forwarded and stored the logs yourself in a place where they can be retrieved with an HTTP GET.
437 ## @param api.rollouts.logs.urlTemplate Instructs Kargo on how to construct a URL for the retrieval of relevant logs via HTTP GET. Expressions offset by ${{ }} are supported with the following variables pre-defined and injected with values: project (name), namespace (always equal to the Project's name), stage (name), analysisRun (name), metricName (name of the JobMetric), jobNamespace (namespace of the Job; may be different that the Project namespace as the Job may actually execute in a different cluster), jobName, container (name; since a Pod associated with a Job could have more than one). Example: "https://logs.kargo.example.com/${{project}}/${{analysisRun}}/${{jobName}}/${{container}}".
440 ## @param api.rollouts.logs.tokenSecret.name specifies the name of a Kubernetes Secret managed "out of band" that contains a token usable for accessing job metric logs.
442 ## @param api.rollouts.logs.tokenSecret.key specifies the key in a Kubernetes Secret (named by name) that is managed "out of band" and contains a token usable for accessing job metric logs.
444 ## @param api.rollouts.logs.httpHeaders Specifies HTTP headers to include in the HTTP GET request for log retrieval. These are typically used for authentication. The header values support expressions offset by ${{ }}, with the same variables documented for urlTemplate pre-defined and injected with values.
446 ## @param api.labels Labels to add to the api resources. Merges with `global.labels`, allowing you to override or add to the global labels.
448 ## @param api.annotations Annotations to add to the api resources. Merges with `global.annotations`, allowing you to override or add to the global annotations.
450 ## @param api.podLabels Optional labels to add to pods. Merges with `global.podLabels`, allowing you to override or add to the global labels.
452 ## @param api.podAnnotations Optional annotations to add to pods. Merges with `global.podAnnotations`, allowing you to override or add to the global annotations.
454 ## ServiceAccount specific settings
456 ## @param api.serviceAccount.labels Additional labels to add to the API server ServiceAccount.
458 ## @param api.serviceAccount.annotations Additional annotations to add to the API server ServiceAccount.
462 ## @param api.env Environment variables to add to API server pods.
466 ## @param api.envFrom Environment variables to add to API server pods from ConfigMaps or Secrets.
469 # name: config-map-name
473 ## @param api.containers Additional sidecar containers to add to API server pods. Rendered as literal YAML.
475 ## @param api.initContainers Additional init containers to add to API server pods. Rendered as literal YAML.
477 ## @param api.volumes Additional pod-level volumes for API server pods. Rendered as literal YAML.
479 ## @param api.volumeMounts Additional volume mounts for the API server container. Rendered as literal YAML.
481 ## @param api.resources Resources limits and requests for the api containers.
490 ## @param api.nodeSelector Node selector for api pods. Defaults to `global.nodeSelector`.
492 ## @param api.tolerations Tolerations for api pods. Defaults to `global.tolerations`.
494 ## @param api.affinity Specifies pod affinity for api pods. Defaults to `global.affinity`.
496 ## @param api.topologySpreadConstraints Topology spread constraints for api pods.
498 ## topologySpreadConstraints:
500 ## topologyKey: kubernetes.io/hostname
501 ## whenUnsatisfiable: DoNotSchedule
504 ## app.kubernetes.io/component: api
505 topologySpreadConstraints: []
506 ## @param api.priorityClassName [nullable] Name of the priority class for api pods. Defaults to `global.priorityClassName`.
508 ## @param api.securityContext Security context for api pods. Defaults to `global.securityContext`.
511 ## @param api.podDisruptionBudget.enabled Whether to create a PodDisruptionBudget for the API server.
513 ## @param api.podDisruptionBudget.minAvailable Minimum number/percentage of pods that must remain available during disruption. Cannot be used with maxUnavailable.
515 ## @param api.podDisruptionBudget.maxUnavailable Maximum number/percentage of pods that can be unavailable during disruption. Cannot be used with minAvailable.
518 ## @param api.cabundle.configMapName Specifies the name of an optional ConfigMap containing CA certs that is managed "out of band." Values in the ConfigMap named here should each contain a single PEM-encoded CA cert. If secretName is also defined, it will take precedence over this field.
520 ## @param api.cabundle.secretName Specifies the name of an optional Secret containing CA certs that is managed "out of band." Values in the Secret named here should each contain a single PEM-encoded CA cert. If defined, the value of this field takes precedence over any in configMapName.
523 ## @param api.probes.enabled Whether startup, liveness, and readiness probes should be included in the API server deployment. It is sometimes advantageous to disable these during local development.
525 ## @param api.probes.startupProbe [object] Values merged into the chart-built `startupProbe` for the API server. Typically used to tune timing fields like `initialDelaySeconds`, `periodSeconds`, `timeoutSeconds`, `successThreshold`, and `failureThreshold`.
527 initialDelaySeconds: 10
530 # successThreshold: 1
532 ## @param api.probes.livenessProbe [object] Values merged into the chart-built `livenessProbe` for the API server. Default is an empty map, so the chart's `livenessProbe` renders with Kubernetes-default timings.
534 # initialDelaySeconds: 0
537 # successThreshold: 1
538 # failureThreshold: 3
539 ## @param api.probes.readinessProbe [object] Values merged into the chart-built `readinessProbe` for the API server.
541 initialDelaySeconds: 5
544 # successThreshold: 1
545 # failureThreshold: 3
547 ## @param api.tls.enabled Whether to enable TLS directly on the API server. This is helpful if you do not intend to use an ingress controller or if you require TLS end-to-end. All other settings in this section EXCEPT `terminatedUpstream` will be ignored when this is set to `false`.
549 ## @param api.tls.selfSignedCert Whether to generate a self-signed certificate for use by the API server. If `true`, `cert-manager` CRDs **must** be present in the cluster. The chart will create and use its own namespaced `Issuer`. If `false`, a cert `Secret` with the name specified by `api.tls.secretName` **must** be provided in the same namespace as Kargo. The value in this field has no effect if `api.tls.enabled` is `false`.
551 ## @param api.tls.secretName Name of the cert `Secret` to use for the API server. When `api.tls.selfSignedCert` is `true`, this will be the name of the generated cert `Secret`. When `api.tls.selfSignedCert` is `false`, a cert `Secret` with this name **must** be provided in the same namespace as Kargo. The value in this field has no effect if `api.tls.enabled` is `false`.
552 secretName: kargo-api-cert
553 ## @param api.tls.terminatedUpstream Whether TLS is terminated upstream, i.e. a load balancer, reverse-proxy, or an `Ingress` controller using a single wildcard cert is terminating it. Setting this to `true` forces all API server URLs to use HTTPS even if the `Ingress` (if applicable) or API server itself are listening for plain HTTP requests.
554 terminatedUpstream: false
556 ## @param api.ingress.enabled Whether to enable ingress by creating an Ingress resource. By default, this is disabled. Enabling ingress is advanced usage.
558 ## @param api.ingress.annotations Annotations specified by your ingress controller to customize the behavior of the Ingress resource.
560 # kubernetes.io/ingress.class: nginx
561 ## @param api.ingress.ingressClassName If implemented by your ingress controller, specifies the ingress class. If your ingress controller does not support this, use the `kubernetes.io/ingress.class` annotation instead.
564 ## @param api.ingress.tls.enabled Whether to associate a certificate with the Ingress resource.
566 ## @param api.ingress.tls.selfSignedCert Whether to generate a self-signed certificate for use with the API server's `Ingress` resource. If `true`, `cert-manager` CRDs **must** be present in the cluster. The chart will create and use its own namespaced `Issuer`. If `false`, a cert `Secret` with the name specified by `api.ingress.tls.secretName` **must** be provided in the same namespace as Kargo. The value in this field has no effect if `api.ingress.tls.enabled` is `false`.
568 ## @param api.ingress.tls.secretName Name of the cert `Secret` for use with the API server's `Ingress` resource. When `api.ingress.tls.selfSignedCert` is `true`, this will be the name of the generated cert `Secret`. When `api.ingress.tls.selfSignedCert` is `false`, a cert `Secret` with this name **must** be provided in the same namespace as Kargo. The value in this field has no effect if `api.ingress.tls.enabled` is `false`.
569 secretName: kargo-api-ingress-cert
570 ## @param api.ingress.pathType You may want to use `Prefix` for some controllers (like AWS LoadBalancer Ingress controller), which don't support `/` as wildcard path when pathType is set to `ImplementationSpecific`
571 pathType: ImplementationSpecific
573 ## @param api.service.type If you're not going to use an ingress controller, you may want to change this value to `LoadBalancer` for production deployments. If running locally, you may want to change it to `NodePort` OR leave it as `ClusterIP` and use `kubectl port-forward` to map a port on the local network interface to the service.
575 ## @param api.service.nodePort [nullable] Host port the `Service` will be mapped to when `type` is either `NodePort` or `LoadBalancer`. If not specified, Kubernetes chooses.
577 ## @param api.service.annotations Annotations to add to the API server's service. Merges with `global.annotations`, allowing you to override or add to the global annotations.
579## @section Controller
580## All settings for the controller component
582 ## @param controller.enabled Whether the controller is enabled.
584 ## @param controller.id [nullable] When set per-controller data plane resources will be suffixed with this value. This allows for the installation of multiple controllers into a single cluster or even a single namespace (each as its own, separate Helm release) without name collisions.
587 ## @param controller.revisionHistoryLimit Number of old ReplicaSets the controller Deployment retains for rollback. The controller uses a `Recreate` rollout strategy (singleton), so `rollingUpdate.*` knobs do not apply.
588 revisionHistoryLimit: 10
589 ## @skip controller.kubeconfigSecrets
590 kubeconfigSecrets: {}
591 ## @param controller.kubeconfigSecrets.kargo [nullable] Per-component override for `kubeconfigSecrets.kargo`. Lets the controller mount its own kubeconfig secret rather than the shared one. Falls back to the chart-level value when unset.
593 ## @param controller.kubeconfigSecrets.argocd [nullable] Per-component override for `kubeconfigSecrets.argocd`. Falls back to the chart-level value when unset.
596 ## @param controller.logLevel The log level for the controller. Valid options are ERROR, INFO, DEBUG, and TRACE (case insensitive). Note that INFO level messages are written during startup regardless of the selected level.
598 ## @param controller.logFormat The format of logs from the controller. Valid options are CONSOLE or JSON (case insensitive).
600 ## @param controller.isDefault When running multiple controllers backed by a single underlying control plane, designating this controller as the default will cause it to operate on resources not assigned to a specific shard. If `controller.shardName` is undefined, this controller will be considered the default **regardless** of the value of this field (as that was the behavior prior to the introduction of this field). If `controller.shardName` **is** defined, this controller will not be considered the default **unless, additionally** this field is `true`. i.e. A controller is effectively considered the default if `or (not controller.shardName) controller.isDefault`. If `controller.shardName` is defined **and** this field is `true`, this controller will operate **both** on resources explicitly assigned to it **as well as** those not assigned to a specific shard.
602 ## @param controller.shardName [nullable] When running multiple controllers backed by a single underlying control plane, specifying a shard name will cause this controller to operate **only** on resources with a matching shard name. Leaving this field undefined will designate this controller as the default controller that is responsible for resources that are not assigned to a specific shard **regardless** of the value of `controller.isDefault` (as that was the behavior prior to the introduction of `controller.isDefault`). If this field is defined, this controller will not be considered the default **unless, additionally** `controller.isDefault` is `true`. i.e. A controller is effectively considered the default if `or (not controller.shardName) controller.isDefault`. If this field is defined **and** `controller.isDefault` is true, this controller will operate **both** on resources explicitly assigned to it **as well as** those not assigned to a specific shard.
605 ## @param controller.allowCredentialsOverHTTP Specifies whether the controller should allow credentials (for Git repositories, etc.) to be retrieved and used for operations over HTTP. This is generally discouraged, as it can expose sensitive information. When set to `false`, the controller will only allow credentials to be used over HTTPS (or other secure protocols).
606 allowCredentialsOverHTTP: false
607 ## Reconciler-specific settings
609 ## @param controller.reconcilers.maxConcurrentReconciles specifies the maximum number of resources EACH of the controller's reconcilers can reconcile concurrently. This setting may also be overridden on a per-reconciler basis.
610 maxConcurrentReconciles: 4
612 ## @param controller.reconcilers.controlFlowStages.maxConcurrentReconciles optionally overrides the maximum number of control flow Stage resources the controller can reconcile concurrently.
613 maxConcurrentReconciles:
615 ## @param controller.reconcilers.promotions.maxConcurrentReconciles optionally overrides the maximum number of Promotion resources the controller can reconcile concurrently.
616 maxConcurrentReconciles:
618 ## @param controller.reconcilers.promotionRequests.maxConcurrentReconciles optionally overrides the maximum number of PromotionRequest resources the controller can reconcile concurrently.
619 maxConcurrentReconciles:
621 ## @param controller.reconcilers.stages.maxConcurrentReconciles optionally overrides the maximum number of (non-control flow) Stage resources the controller can reconcile concurrently.
622 maxConcurrentReconciles:
624 ## @param controller.reconcilers.warehouses.maxConcurrentReconciles optionally overrides the maximum number of Warehouse resources the controller can reconcile concurrently.
625 maxConcurrentReconciles:
626 ## @param controller.reconcilers.warehouses.minReconciliationInterval optionally sets the minimum reconciliation interval for Warehouse resources. Accepts duration format (e.g., "5m", "1h", "30s"). If a Warehouse specifies an interval lower than this minimum, the minimum value will be enforced instead. If not set, no minimum is enforced.
627 minReconciliationInterval: "5m0s"
629 ## @param controller.gitClient.name Specifies the name of the Kargo controller (used when authoring Git commits).
631 ## @param controller.gitClient.email Specifies the email of the Kargo controller (used when authoring Git commits).
632 email: "no-reply@kargo.io"
633 ## @param controller.gitClient.pushIntegrationPolicy Controls how remote changes are integrated before pushing. Options: AlwaysRebase (unconditionally rebase), RebaseOrMerge (rebase when safe, merge otherwise), RebaseOrFail (rebase when safe, fail otherwise), AlwaysMerge (unconditionally merge).
634 pushIntegrationPolicy: "RebaseOrMerge"
636 ## @param controller.gitClient.signingKeySecret.name Specifies the name of an existing `Secret` which contains the Git user's signing key. The value should be accessible under `.data.signingKey` in the same namespace as Kargo. When the signing key is a GPG key, the GPG key's name and email address identity must match the values defined for `controller.gitClient.name` and `controller.gitClient.email`.
638 ## @param controller.gitClient.signingKeySecret.type Specifies the type of the signing key. The currently supported and default option is `gpg`.
641 ## @param controller.githubPush.maxRevisions The maximum number of commits that the github-push step will replay via the GitHub API in a single push. This is a safety guardrail against accidentally replaying large numbers of commits.
643 ## @param controller.githubPush.verifyUntrustedCommits When true, the github-push step will omit author/committer information for ALL commits replayed via the GitHub API, not just those signed by a trusted key. This causes GitHub to sign all commits with its own key, resulting in verified commits regardless of trust. Use with caution -- this manufactures trust where none exists.
644 verifyUntrustedCommits: false
647 ## @param controller.images.registries.rateLimit defines the rate limit in requests-per-second (on a per registry basis) that will be voluntarily enforced client-side for all interactions with container image registries. The default limit is very low, but tune this setting with great caution. Turning it up is not a guarantee of improved Warehouse performance. When registries begin enforcing rate limits because the client is not, the resulting errors may degrade performance worse than voluntarily observing a more conservative rate limit.
650 ## @param controller.images.cache.cacheByTagPolicy establishes a policy regarding the caching of container image metadata using tags as keys in order to realize a performance boost. Doing so is safest when it is known that image tags are immutable (never overwritten). Permissible values are: "Forbid" (no caching by tag; silently enforced), "Allow" (subscriptions MAY opt-in to caching by tag), "Require" (subscriptions MUST opt-in to caching by tag; effectively this is developer acknowledgement of the cache by tag behavior), "Force" (caching by tag is silently enforced).
651 cacheByTagPolicy: Allow
652 ## @param controller.images.cache.maxEntries specifies the maximum number of entries in the internal image metadata cache.
655 ## @param controller.images.push.maxArtifactSize The maximum size (in bytes) for OCI artifact pushes that transfer blobs (cross-repository copies and local file pushes). Defaults to 1 GiB (1073741824). Set to 0 to block such pushes entirely, or -1 to disable the limit.
656 maxArtifactSize: 1073741824
657 ## All settings relating to the Argo CD control plane this controller might
660 ## @param controller.argocd.integrationEnabled Specifies whether Argo CD integration is enabled. When not enabled, the controller will not watch Argo CD Application resources or factor Application health and sync state into determinations of Stage health. Argo CD-based promotion mechanisms will also fail. When enabled, the controller will perform a sanity check at startup. If Argo CD CRDs are not found, the controller will proceed as if this integration had been explicitly disabled. Explicitly disabling is still preferable if this integration is not desired, as it will grant fewer permissions to the controller.
661 integrationEnabled: true
662 ## @param controller.argocd.namespace The namespace into which Argo CD is installed.
664 ## @param controller.argocd.watchArgocdNamespaceOnly Specifies whether the reconciler that watches Argo CD Applications for the sake of forcing related Stages to reconcile should only watch Argo CD Application resources residing in Argo CD's own namespace. Note: Older versions of Argo CD only supported Argo CD Application resources in Argo CD's own namespace, but newer versions support Argo CD Application resources in any namespace. This should usually be left as `false`.
665 watchArgocdNamespaceOnly: false
666 ## All settings relating to the use of Argo Rollouts AnalysisTemplates and
667 ## AnalysisRuns as a means of verifying Stages after a Promotion.
669 ## @param controller.rollouts.integrationEnabled Specifies whether Argo Rollouts integration is enabled. When not enabled, the controller will not reconcile Argo Rollouts AnalysisRun resources and attempts to verify Stages via Analysis will fail. When enabled, the controller will perform a sanity check at startup. If Argo Rollouts CRDs are not found, the controller will proceed as if this integration had been explicitly disabled. Explicitly disabling is still preferable if this integration is not desired, as it will grant fewer permissions to the controller.
670 integrationEnabled: true
671 ## @param controller.rollouts.controllerInstanceID Specifies a cluster on which Jobs corresponding to an AnalysisRun (used for Freight/Stage verification purposes) will be executed. This is useful in cases where the cluster hosting the Kargo control plane is not a suitable environment for executing user-defined logic. Kargo will use this as the value of the rgo-rollouts.argoproj.io/controller-instance-id label when creating AnalysisRuns. When this is left empty/undefined, no such label will be added to AnalysisRuns.
672 controllerInstanceID: ""
673 ## @param controller.labels Labels to add to the api resources. Merges with `global.labels`, allowing you to override or add to the global labels.
675 ## @param controller.annotations Annotations to add to the api resources. Merges with `global.annotations`, allowing you to override or add to the global annotations.
677 ## @param controller.podLabels Optional labels to add to pods. Merges with `global.podLabels`, allowing you to override or add to the global labels.
679 ## @param controller.podAnnotations Optional annotations to add to pods. Merges with `global.podAnnotations`, allowing you to override or add to the global annotations.
681 ## All settings relating to the service account for the controller
683 ## @param controller.serviceAccount.iamRole Specifies the ARN of an AWS IAM role to be used by the controller in an IRSA-enabled EKS cluster.
685 ## @param controller.serviceAccount.labels Additional labels to add to the controller ServiceAccount.
687 ## @param controller.serviceAccount.annotations Additional annotations to add to the controller ServiceAccount.
691 ## @param controller.serviceAccount.clusterWideSecretReadingEnabled Specifies whether the controller's ServiceAccount should be granted read permissions to Secrets CLUSTER-WIDE in the Kargo control plane's cluster. Enabling this is highly discouraged and you do so at your own peril. When this is NOT enabled, the Kargo management controller will dynamically expand and contract the controller's permissions to read Secrets on a Project-by-Project basis.
692 clusterWideSecretReadingEnabled: false
693 ## @param controller.initContainers Optional init containers to add to the controller pods. This is rendered as the literal YAML.
695 # - name: download-tools
697 # command: [ sh, -c ]
701 ## @param controller.env Environment variables to add to controller pods.
705 ## @param controller.envFrom Environment variables to add to controller pods from ConfigMaps or Secrets.
708 # name: config-map-name
712 ## @param controller.containers Additional sidecar containers to add to controller pods. Rendered as literal YAML.
714 ## @param controller.volumes Volumes for the controller pods.
716 ## @param controller.volumeMounts Volume mounts for the controller pods.
718 ## @param controller.resources Resources limits and requests for the controller containers.
727 ## @param controller.nodeSelector Node selector for controller pods. Defaults to `global.nodeSelector`.
729 ## @param controller.tolerations Tolerations for controller pods. Defaults to `global.tolerations`.
731 ## @param controller.affinity Specifies pod affinity for controller pods. Defaults to `global.affinity`.
733 ## @param controller.priorityClassName [nullable] Name of the priority class for controller pods. Defaults to `global.priorityClassName`.
735 ## @param controller.securityContext Security context for controller pods. Defaults to `global.securityContext`.
738 ## @param controller.cabundle.configMapName Specifies the name of an optional ConfigMap containing CA certs that is managed "out of band." Values in the ConfigMap named here should each contain a single PEM-encoded CA cert. If secretName is also defined, it will take precedence over this field.
740 ## @param controller.cabundle.secretName Specifies the name of an optional Secret containing CA certs that is managed "out of band." Values in the Secret named here should each contain a single PEM-encoded CA cert. If defined, the value of this field takes precedence over any in configMapName.
742 ## All settings relating to exposing the controller's Prometheus metrics.
744 ## @param controller.metrics.enabled Whether to expose the controller's Prometheus metrics. When enabled, the controller binds its metrics server (via `METRICS_BIND_ADDRESS`), declares a metrics container port, and a metrics `Service` is created. Metrics are served over plain HTTP.
747 ## @param controller.metrics.service.type The type of the metrics `Service`.
749 ## @param controller.metrics.service.clusterIP The cluster IP of the metrics `Service`. Set to `None` for a headless `Service`, which resolves directly to individual pod IPs -- useful for scrapers that perform their own endpoint discovery.
751 ## @param controller.metrics.service.annotations Annotations to add to the metrics `Service`.
753 ## @param controller.metrics.service.labels Additional labels to add to the metrics `Service`.
755 ## @param controller.metrics.service.servicePort The port exposed by the metrics `Service`. Also used as the container port and the address the metrics server binds to.
757 ## @param controller.metrics.service.portName The name of the metrics port. Referenced by the `ServiceMonitor` endpoint.
758 portName: http-metrics
760 ## @param controller.metrics.serviceMonitor.enabled Whether to create a Prometheus Operator `ServiceMonitor` for the controller's metrics. Requires `controller.metrics.enabled` to be `true` and the Prometheus Operator CRDs (`monitoring.coreos.com/v1`) to be present in the cluster; otherwise it is silently skipped.
762 ## @param controller.metrics.serviceMonitor.interval The scrape interval for the `ServiceMonitor`.
764 ## @param controller.metrics.serviceMonitor.scheme The scheme to use when scraping. Defaults to `http` (metrics are served over plain HTTP).
766 ## @param controller.metrics.serviceMonitor.tlsConfig TLS configuration for the `ServiceMonitor` endpoint. Rendered as literal YAML.
768 ## @param controller.metrics.serviceMonitor.relabelings Relabeling rules applied to samples before scraping. Rendered as literal YAML.
770 ## @param controller.metrics.serviceMonitor.metricRelabelings Relabeling rules applied to samples before ingestion. Rendered as literal YAML.
771 metricRelabelings: []
772 ## @param controller.metrics.serviceMonitor.additionalLabels Additional labels to add to the `ServiceMonitor`. Often required to match the label selector of your Prometheus Operator instance.
774 ## @param controller.metrics.serviceMonitor.namespace The namespace in which to create the `ServiceMonitor`. Defaults to the release namespace.
776## @section Garbage Collector
778 ## @param garbageCollector.enabled Whether the garbage collector is enabled.
780 ## @skip garbageCollector.kubeconfigSecrets
781 kubeconfigSecrets: {}
782 ## @param garbageCollector.kubeconfigSecrets.kargo [nullable] Per-component override for `kubeconfigSecrets.kargo`. Lets the garbage collector mount its own kubeconfig secret rather than the shared one. Falls back to the chart-level value when unset.
785 ## @param garbageCollector.logLevel The log level for the garbage collector. Valid options are ERROR, INFO, DEBUG, and TRACE (case insensitive). Note that INFO level messages are written during startup regardless of the selected level.
787 ## @param garbageCollector.logFormat The format of logs from the garbage collector. Valid options are CONSOLE or JSON (case insensitive).
789 ## @param garbageCollector.schedule When to run the garbage collector.
790 schedule: "0 * * * *"
791 ## @param garbageCollector.suspend Whether to suspend the garbage collector CronJob. When `true`, the CronJob remains in place but stops launching new Jobs.
793 ## @param garbageCollector.successfulJobsHistoryLimit Number of successful Job records to retain. Defaults to the Kubernetes CronJob default of `3`.
794 successfulJobsHistoryLimit: 3
795 ## @param garbageCollector.failedJobsHistoryLimit Number of failed Job records to retain. Defaults to the Kubernetes CronJob default of `1`.
796 failedJobsHistoryLimit: 1
797 ## @param garbageCollector.ttlSecondsAfterFinished Optional automatic cleanup delay (in seconds) for completed garbage collector Jobs. Each Job will be eligible for deletion this many seconds after it finishes. Leave empty/unset to retain Jobs indefinitely (subject to the `*JobsHistoryLimit` knobs).
798 ttlSecondsAfterFinished:
799 ## @param garbageCollector.workers The number of concurrent workers to run. Tuning this too low will result in slow garbage collection. Tuning this too high will result in too many API calls and may result in throttling.
801 ## @param garbageCollector.maxRetainedPromotions The ideal maximum number of Promotions OLDER than the oldest Promotion in a non-terminal phase (for each Stage) that may be spared by the garbage collector. The ACTUAL number of older Promotions spared may exceed this ideal if some Promotions that would otherwise be deleted do not meet the minimum age criterion.
802 maxRetainedPromotions: 20
803 ## @param garbageCollector.minPromotionDeletionAge The minimum age a Promotion must be before considered eligible for garbage collection.
804 minPromotionDeletionAge: 336h # Two weeks
805 ## @param garbageCollector.maxRetainedFreight The ideal maximum number of Freight OLDER than the oldest still in use (from each Warehouse) that may be spared by the garbage collector. The ACTUAL number of older Freight spared may exceed this ideal if some Freight that would otherwise be deleted do not meet the minimum age criterion.
806 maxRetainedFreight: 20
807 ## @param garbageCollector.minFreightDeletionAge The minimum age Freight must be before considered eligible for garbage collection.
808 minFreightDeletionAge: 336h # Two weeks
809 ## @param garbageCollector.labels Labels to add to the api resources. Merges with `global.labels`, allowing you to override or add to the global labels.
811 ## @param garbageCollector.annotations Annotations to add to the api resources. Merges with `global.annotations`, allowing you to override or add to the global annotations.
813 ## @param garbageCollector.podLabels Optional labels to add to pods. Merges with `global.podLabels`, allowing you to override or add to the global labels.
815 ## @param garbageCollector.podAnnotations Optional annotations to add to pods. Merges with `global.podAnnotations`, allowing you to override or add to the global annotations.
817 ## ServiceAccount specific settings
819 ## @param garbageCollector.serviceAccount.labels Additional labels to add to the managementController ServiceAccount.
821 ## @param garbageCollector.serviceAccount.annotations Additional annotations to add to the managementController ServiceAccount.
825 ## @param garbageCollector.env Environment variables to add to garbage collector pods.
829 ## @param garbageCollector.envFrom Environment variables to add to garbage collector pods from ConfigMaps or Secrets.
832 # name: config-map-name
836 ## @param garbageCollector.containers Additional sidecar containers to add to garbage collector pods. Rendered as literal YAML.
838 ## @param garbageCollector.initContainers Additional init containers to add to garbage collector pods. Rendered as literal YAML.
840 ## @param garbageCollector.volumes Additional pod-level volumes for garbage collector pods. Rendered as literal YAML.
842 ## @param garbageCollector.volumeMounts Additional volume mounts for the garbage collector container. Rendered as literal YAML.
844 ## @param garbageCollector.resources Resources limits and requests for the garbage collector containers.
853 ## @param garbageCollector.nodeSelector Node selector for the garbage collector pods. Defaults to `global.nodeSelector`.
855 ## @param garbageCollector.tolerations Tolerations for the garbage collector pods. Defaults to `global.tolerations`.
857 ## @param garbageCollector.affinity Specifies pod affinity for the garbage collector pods. Defaults to `global.affinity`.
859 ## @param garbageCollector.priorityClassName [nullable] Name of the priority class for the garbage collector pods. Defaults to `global.priorityClassName`.
861 ## @param garbageCollector.securityContext Security context for garbage collector pods. Defaults to `global.securityContext`.
863## @section External Webhooks Server
864externalWebhooksServer:
865 ## @param externalWebhooksServer.enabled Whether the external webhooks server is enabled.
867 ## @skip externalWebhooksServer.kubeconfigSecrets
868 kubeconfigSecrets: {}
869 ## @param externalWebhooksServer.kubeconfigSecrets.kargo [nullable] Per-component override for `kubeconfigSecrets.kargo`. Lets the external webhooks server mount its own kubeconfig secret rather than the shared one. Falls back to the chart-level value when unset.
872 ## @param externalWebhooksServer.replicas The number of external webhooks server pods.
874 ## @param externalWebhooksServer.revisionHistoryLimit Number of old ReplicaSets the external webhooks server Deployment retains for rollback.
875 revisionHistoryLimit: 10
876 ## @param externalWebhooksServer.rollingUpdate Values merged into the chart-built `strategy.rollingUpdate` for the external webhook server Deployment. Typically used to tune `maxSurge` and `maxUnavailable` (each an absolute number or a percentage). Default empty map — Kubernetes defaults (25% / 25%) apply.
879 # maxUnavailable: 25%
881 ## @param externalWebhooksServer.host The domain name where Kargo's external webhooks server will be accessible. When applicable, this is used for generation of an Ingress resource and certificates. Note: The value in this field MAY include a port number and MUST NOT specify the protocol (http vs https), which is automatically inferred from other configuration options.
883 ## @param externalWebhooksServer.basePath URL path prefix at which the external webhooks server is reachable. When non-empty, MUST begin with a slash and MUST NOT end with one (e.g. `/webhook`). Used as the path on any chart-generated Ingress rule for the external webhooks server, and included in `EXTERNAL_WEBHOOK_SERVER_BASE_URL`. When the external webhooks server has no Ingress of its own and instead piggybacks on the API server's Ingress, this defaults to `<api.basePath>/webhooks`. The external webhooks server binary itself always serves at the root, so when this is set, the user is responsible for configuring their Ingress controller to strip the prefix before forwarding (e.g. via Traefik's `stripPrefix` middleware, NGINX's `rewrite`, etc.).
885 ## @param externalWebhooksServer.logLevel The log level for the external webhooks server. Valid options are ERROR, INFO, DEBUG, and TRACE (case insensitive). Note that INFO level messages are written during startup regardless of the selected level.
887 ## @param externalWebhooksServer.logFormat The format of logs from the external webhooks server. Valid options are CONSOLE or JSON (case insensitive).
889 ## @param externalWebhooksServer.labels Labels to add to the external webhook server resources. Merges with `global.labels`, allowing you to override or add to the global labels.
891 ## @param externalWebhooksServer.annotations Annotations to add to the external webhook server resources. Merges with `global.annotations`, allowing you to override or add to the global annotations.
893 ## @param externalWebhooksServer.podLabels Optional labels to add to the external webhook server pods. Merges with `global.podLabels`, allowing you to override or add to the global labels.
895 ## @param externalWebhooksServer.podAnnotations Optional annotations to add to the external webhook server pods. Merges with `global.podAnnotations`, allowing you to override or add to the global annotations.
897 ## ServiceAccount specific settings
899 ## @param externalWebhooksServer.serviceAccount.labels Additional labels to add to the externalWebHooksServer ServiceAccount.
901 ## @param externalWebhooksServer.serviceAccount.annotations Additional annotations to add to the externalWebHooksServer ServiceAccount.
905 ## @param externalWebhooksServer.env Environment variables to add to external webhook server pods.
909 ## @param externalWebhooksServer.envFrom Environment variables to add to external webhook server pods from ConfigMaps or Secrets.
912 # name: config-map-name
916 ## @param externalWebhooksServer.containers Additional sidecar containers to add to external webhook server pods. Rendered as literal YAML.
918 ## @param externalWebhooksServer.initContainers Additional init containers to add to external webhook server pods. Rendered as literal YAML.
920 ## @param externalWebhooksServer.volumes Additional pod-level volumes for external webhook server pods. Rendered as literal YAML.
922 ## @param externalWebhooksServer.volumeMounts Additional volume mounts for the external webhook server container. Rendered as literal YAML.
924 ## @param externalWebhooksServer.resources Resources limits and requests for the external webhook server containers.
933 ## @param externalWebhooksServer.nodeSelector Node selector for external webhook server pods. Defaults to `global.nodeSelector`.
935 ## @param externalWebhooksServer.tolerations Tolerations for external webhook server pods. Defaults to `global.tolerations`.
937 ## @param externalWebhooksServer.affinity Specifies pod affinity for external webhook server pods. Defaults to `global.affinity`.
939 ## @param externalWebhooksServer.topologySpreadConstraints Topology spread constraints for external webhook server pods.
941 ## topologySpreadConstraints:
943 ## topologyKey: kubernetes.io/hostname
944 ## whenUnsatisfiable: DoNotSchedule
947 ## app.kubernetes.io/component: external-webhooks-server
948 topologySpreadConstraints: []
949 ## @param externalWebhooksServer.priorityClassName [nullable] Name of the priority class for external webhook server pods. Defaults to `global.priorityClassName`.
951 ## @param externalWebhooksServer.securityContext Security context for external webhook server pods. Defaults to `global.securityContext`.
954 ## @param externalWebhooksServer.podDisruptionBudget.enabled Whether to create a PodDisruptionBudget for the external webhook server.
956 ## @param externalWebhooksServer.podDisruptionBudget.minAvailable Minimum number/percentage of pods that must remain available during disruption. Cannot be used with maxUnavailable.
958 ## @param externalWebhooksServer.podDisruptionBudget.maxUnavailable Maximum number/percentage of pods that can be unavailable during disruption. Cannot be used with minAvailable.
961 ## @param externalWebhooksServer.probes.enabled Whether startup, liveness, and readiness probes should be included in the external webhook server deployment. It is sometimes advantageous to disable these during local development.
963 ## @param externalWebhooksServer.probes.startupProbe [object] Values merged into the chart-built `startupProbe` for the external webhook server. Typically used to tune timing fields like `initialDelaySeconds`, `periodSeconds`, `timeoutSeconds`, `successThreshold`, and `failureThreshold`.
965 initialDelaySeconds: 10
968 # successThreshold: 1
970 ## @param externalWebhooksServer.probes.livenessProbe [object] Values merged into the chart-built `livenessProbe` for the external webhook server. Default is an empty map, so the chart's `livenessProbe` renders with Kubernetes-default timings.
972 # initialDelaySeconds: 0
975 # successThreshold: 1
976 # failureThreshold: 3
977 ## @param externalWebhooksServer.probes.readinessProbe [object] Values merged into the chart-built `readinessProbe` for the external webhook server.
979 initialDelaySeconds: 5
982 # successThreshold: 1
983 # failureThreshold: 3
985 ## @param externalWebhooksServer.tls.enabled Whether to enable TLS directly on the external webhook server. This is helpful if you do not intend to use an ingress controller or if you require TLS end-to-end. All other settings in this section EXCEPT `terminatedUpstream` will be ignored when this is set to `false`.
987 ## @param externalWebhooksServer.tls.selfSignedCert Whether to generate a self-signed certificate for use by the external webhooks server. If `true`, `cert-manager` CRDs **must** be present in the cluster. The chart will create and use its own namespaced `Issuer`. If `false`, a cert `Secret` with the name specified by `externalWebhooksServer.tls.secretName` **must** be provided in the same namespace as Kargo. The value in this field has no effect if `externalWebhooksServer.tls.enabled` is `false`.
989 ## @param externalWebhooksServer.tls.secretName Name of the cert `Secret` to use for the external webhooks server. When `externalWebhooksServer.tls.selfSignedCert` is `true`, this will be the name of the generated cert `Secret`. When `externalWebhooksServer.tls.selfSignedCert` is `false`, a cert `Secret` with this name **must** be provided in the same namespace as Kargo. The value in this field has no effect if `externalWebhooksServer.tls.enabled` is `false`.
990 secretName: kargo-external-webhooks-server-cert
991 ## @param externalWebhooksServer.tls.terminatedUpstream Whether TLS is terminated upstream, i.e. a load balancer, reverse-proxy, or an `Ingress` controller using a single wildcard cert is terminating it. Setting this to `true` forces all external webhook server URLs to use HTTPS even if the `Ingress` (if applicable) or external webhook server itself are listening for plain HTTP requests.
992 terminatedUpstream: false
994 ## @param externalWebhooksServer.ingress.enabled Whether to enable separate ingress for webhook by creating an Ingress resource. By default, this is disabled and webhook is exposed as part of kargo-api ingress. Enabling ingress is advanced usage.
996 ## @param externalWebhooksServer.ingress.annotations Annotations specified by your ingress controller to customize the behavior of the Ingress resource.
998 # kubernetes.io/ingress.class: nginx
999 ## @param externalWebhooksServer.ingress.ingressClassName If implemented by your ingress controller, specifies the ingress class. If your ingress controller does not support this, use the `kubernetes.io/ingress.class` annotation instead.
1002 ## @param externalWebhooksServer.ingress.tls.enabled Whether to associate a certificate with the Ingress resource.
1004 ## @param externalWebhooksServer.ingress.tls.selfSignedCert Whether to generate a self-signed certificate for use with the external webhook server's `Ingress` resource. If `true`, `cert-manager` CRDs **must** be present in the cluster. The chart will create and use its own namespaced `Issuer`. If `false`, a cert `Secret` with the name specified by `externalWebhooksServer.ingress.tls.secretName` **must** be provided in the same namespace as Kargo. The value in this field has no effect if `externalWebhooksServer.ingress.tls.enabled` is `false`.
1005 selfSignedCert: true
1006 ## @param externalWebhooksServer.ingress.tls.secretName Name of the cert `Secret` for the external webhooks server's `Ingress` resource. When `externalWebhooksServer.ingress.tls.selfSignedCert` is `true`, this will be the name of the generated cert `Secret`. When `externalWebhooksServer.ingress.tls.selfSignedCert` is `false`, a cert `Secret` with this name **must** be provided in the same namespace as Kargo. The value in this field has no effect if `externalWebhooksServer.ingress.tls.enabled` is `false`.
1007 secretName: kargo-external-webhooks-server-ingress-cert
1008 ## @param externalWebhooksServer.ingress.pathType You may want to use `Prefix` for some controllers (like AWS LoadBalancer Ingress controller), which don't support `/` as wildcard path when pathType is set to `ImplementationSpecific`
1009 pathType: ImplementationSpecific
1011 ## @param externalWebhooksServer.service.type If you're not going to use an ingress controller, you may want to change this value to `LoadBalancer` for production deployments. If running locally, you may want to change it to `NodePort` OR leave it as `ClusterIP` and use `kubectl port-forward` to map a port on the local network interface to the service.
1013 ## @param externalWebhooksServer.service.nodePort [nullable] Host port the `Service` will be mapped to when `type` is either `NodePort` or `LoadBalancer`. If not specified, Kubernetes chooses.
1015 ## @param externalWebhooksServer.service.annotations Annotations to add to the external webhook server's service. Merges with `global.annotations`, allowing you to override or add to the global annotations.
1017## @section Management Controller
1018## All settings for the management controller component
1019managementController:
1020 ## @param managementController.enabled Whether the management controller is enabled.
1022 ## @param managementController.revisionHistoryLimit Number of old ReplicaSets the management controller Deployment retains for rollback. The management controller uses a `Recreate` rollout strategy (singleton), so `rollingUpdate.*` knobs do not apply.
1023 revisionHistoryLimit: 10
1024 ## @skip managementController.kubeconfigSecrets
1025 kubeconfigSecrets: {}
1026 ## @param managementController.kubeconfigSecrets.kargo [nullable] Per-component override for `kubeconfigSecrets.kargo`. Lets the management controller mount its own kubeconfig secret rather than the shared one. Falls back to the chart-level value when unset.
1029 ## @param managementController.logLevel The log level for the management controller. Valid options are ERROR, INFO, DEBUG, and TRACE (case insensitive). Note that INFO level messages are written during startup regardless of the selected level.
1031 ## @param managementController.logFormat The format of logs from the management controller. Valid options are CONSOLE or JSON (case insensitive).
1033 ## Reconciler-specific settings
1035 ## @param managementController.reconcilers.maxConcurrentReconciles specifies the maximum number of resources EACH of the management controller's reconcilers can reconcile concurrently. This setting may also be overridden on a per-reconciler basis.
1036 maxConcurrentReconciles: 4
1038 ## @param managementController.reconcilers.namespaces.maxConcurrentReconciles optionally overrides the maximum number of Namespace resources the management controller can reconcile concurrently.
1039 maxConcurrentReconciles:
1041 ## @param managementController.reconcilers.projectConfigs.maxConcurrentReconciles optionally overrides the maximum number of ProjectConfig resources the management controller can reconcile concurrently.
1042 maxConcurrentReconciles:
1044 ## @param managementController.reconcilers.projects.maxConcurrentReconciles optionally overrides the maximum number of Project resources the management controller can reconcile concurrently.
1045 maxConcurrentReconciles:
1047 ## @param managementController.reconcilers.serviceAccounts.maxConcurrentReconciles optionally overrides the maximum number of ServiceAccount resources the management controller can reconcile concurrently.
1048 maxConcurrentReconciles:
1049 ## @param managementController.labels Labels to add to the api resources. Merges with `global.labels`, allowing you to override or add to the global labels.
1051 ## @param managementController.annotations Annotations to add to the api resources. Merges with `global.annotations`, allowing you to override or add to the global annotations.
1053 ## @param managementController.podLabels Optional labels to add to pods. Merges with `global.podLabels`, allowing you to override or add to the global labels.
1055 ## @param managementController.podAnnotations Optional annotations to add to pods. Merges with `global.podAnnotations`, allowing you to override or add to the global annotations.
1057 ## ServiceAccount specific settings
1059 ## @param managementController.serviceAccount.labels Additional labels to add to the managementController ServiceAccount.
1061 ## @param managementController.serviceAccount.annotations Additional annotations to add to the managementController ServiceAccount.
1065 ## @param managementController.env Environment variables to add to management controller pods.
1069 ## @param managementController.envFrom Environment variables to add to management controller pods from ConfigMaps or Secrets.
1072 # name: config-map-name
1076 ## @param managementController.containers Additional sidecar containers to add to management controller pods. Rendered as literal YAML.
1078 ## @param managementController.initContainers Additional init containers to add to management controller pods. Rendered as literal YAML.
1080 ## @param managementController.volumes Additional pod-level volumes for management controller pods. Rendered as literal YAML.
1082 ## @param managementController.volumeMounts Additional volume mounts for the management controller container. Rendered as literal YAML.
1084 ## @param managementController.resources Resources limits and requests for the management controller containers.
1093 ## @param managementController.nodeSelector Node selector for management controller pods. Defaults to `global.nodeSelector`.
1095 ## @param managementController.tolerations Tolerations for management controller pods. Defaults to `global.tolerations`.
1097 ## @param managementController.affinity Specifies pod affinity for management controller pods. Defaults to `global.affinity`.
1099 ## @param managementController.priorityClassName [nullable] Name of the priority class for management controller pods. Defaults to `global.priorityClassName`.
1100 # priorityClassName:
1101 ## @param managementController.securityContext Security context for management controller pods. Defaults to `global.securityContext`.
1103 ## All settings relating to exposing the management controller's Prometheus metrics.
1105 ## @param managementController.metrics.enabled Whether to expose the management controller's Prometheus metrics. When enabled, the management controller binds its metrics server (via `METRICS_BIND_ADDRESS`), declares a metrics container port, and a metrics `Service` is created. Metrics are served over plain HTTP.
1108 ## @param managementController.metrics.service.type The type of the metrics `Service`.
1110 ## @param managementController.metrics.service.clusterIP The cluster IP of the metrics `Service`. Set to `None` for a headless `Service`, which resolves directly to individual pod IPs -- useful for scrapers that perform their own endpoint discovery.
1112 ## @param managementController.metrics.service.annotations Annotations to add to the metrics `Service`.
1114 ## @param managementController.metrics.service.labels Additional labels to add to the metrics `Service`.
1116 ## @param managementController.metrics.service.servicePort The port exposed by the metrics `Service`. Also used as the container port and the address the metrics server binds to.
1118 ## @param managementController.metrics.service.portName The name of the metrics port. Referenced by the `ServiceMonitor` endpoint.
1119 portName: http-metrics
1121 ## @param managementController.metrics.serviceMonitor.enabled Whether to create a Prometheus Operator `ServiceMonitor` for the management controller's metrics. Requires `managementController.metrics.enabled` to be `true` and the Prometheus Operator CRDs (`monitoring.coreos.com/v1`) to be present in the cluster; otherwise it is silently skipped.
1123 ## @param managementController.metrics.serviceMonitor.interval The scrape interval for the `ServiceMonitor`.
1125 ## @param managementController.metrics.serviceMonitor.scheme The scheme to use when scraping. Defaults to `http` (metrics are served over plain HTTP).
1127 ## @param managementController.metrics.serviceMonitor.tlsConfig TLS configuration for the `ServiceMonitor` endpoint. Rendered as literal YAML.
1129 ## @param managementController.metrics.serviceMonitor.relabelings Relabeling rules applied to samples before scraping. Rendered as literal YAML.
1131 ## @param managementController.metrics.serviceMonitor.metricRelabelings Relabeling rules applied to samples before ingestion. Rendered as literal YAML.
1132 metricRelabelings: []
1133 ## @param managementController.metrics.serviceMonitor.additionalLabels Additional labels to add to the `ServiceMonitor`. Often required to match the label selector of your Prometheus Operator instance.
1134 additionalLabels: {}
1135 ## @param managementController.metrics.serviceMonitor.namespace The namespace in which to create the `ServiceMonitor`. Defaults to the release namespace.
1137## @section Webhooks Server
1139 ## @param webhooksServer.enabled Whether the webhooks server is enabled.
1141 ## @skip webhooksServer.kubeconfigSecrets
1142 kubeconfigSecrets: {}
1143 ## @param webhooksServer.kubeconfigSecrets.kargo [nullable] Per-component override for `kubeconfigSecrets.kargo`. Lets the webhooks server mount its own kubeconfig secret rather than the shared one. Falls back to the chart-level value when unset.
1146 ## @param webhooksServer.replicas The number of webhooks server pods.
1148 ## @param webhooksServer.revisionHistoryLimit Number of old ReplicaSets the webhooks server Deployment retains for rollback.
1149 revisionHistoryLimit: 10
1150 ## @param webhooksServer.rollingUpdate Values merged into the chart-built `strategy.rollingUpdate` for the webhooks server Deployment. Typically used to tune `maxSurge` and `maxUnavailable` (each an absolute number or a percentage). Default empty map — Kubernetes defaults (25% / 25%) apply.
1153 # maxUnavailable: 25%
1155 ## @param webhooksServer.logLevel The log level for the webhooks server. Valid options are ERROR, INFO, DEBUG, and TRACE (case insensitive). Note that INFO level messages are written during startup regardless of the selected level.
1157 ## @param webhooksServer.logFormat The format of logs from the webhooks server. Valid options are CONSOLE or JSON (case insensitive).
1159 ## @param webhooksServer.controlplaneUserRegex Regular expression for matching controlplane users.
1160 controlplaneUserRegex: "" # ^system:serviceaccount:kargo:[a-z0-9]([-a-z0-9]*[a-z0-9])?$
1161 ## @param webhooksServer.labels Labels to add to the webhook server resources. Merges with `global.labels`, allowing you to override or add to the global labels.
1163 ## @param webhooksServer.annotations Annotations to add to the webhook server resources. Merges with `global.annotations`, allowing you to override or add to the global annotations.
1165 ## @param webhooksServer.podLabels Optional labels to add to the webhook server pods. Merges with `global.podLabels`, allowing you to override or add to the global labels.
1167 ## @param webhooksServer.podAnnotations Optional annotations to add to the webhook server pods. Merges with `global.podAnnotations`, allowing you to override or add to the global annotations.
1169 ## ServiceAccount specific settings
1171 ## @param webhooksServer.serviceAccount.labels Additional labels to add to the webhooks server ServiceAccount.
1173 ## @param webhooksServer.serviceAccount.annotations Additional annotations to add to the webhooks server ServiceAccount.
1177 ## @param webhooksServer.env Environment variables to add to webhook server pods.
1181 ## @param webhooksServer.envFrom Environment variables to add to webhook server pods from ConfigMaps or Secrets.
1184 # name: config-map-name
1188 ## @param webhooksServer.containers Additional sidecar containers to add to webhooks server pods. Rendered as literal YAML.
1190 ## @param webhooksServer.initContainers Additional init containers to add to webhooks server pods. Rendered as literal YAML.
1192 ## @param webhooksServer.volumes Additional pod-level volumes for webhooks server pods. Rendered as literal YAML.
1194 ## @param webhooksServer.volumeMounts Additional volume mounts for the webhooks server container. Rendered as literal YAML.
1196 ## @param webhooksServer.resources Resources limits and requests for the webhooks server containers.
1205 ## @param webhooksServer.nodeSelector Node selector for the webhooks server pods. Defaults to `global.nodeSelector`.
1207 ## @param webhooksServer.tolerations Tolerations for the webhooks server pods. Defaults to `global.tolerations`.
1209 ## @param webhooksServer.affinity Specifies pod affinity for the webhooks server pods. Defaults to `global.affinity`.
1211 ## @param webhooksServer.topologySpreadConstraints Topology spread constraints for webhooks server pods.
1213 ## topologySpreadConstraints:
1215 ## topologyKey: kubernetes.io/hostname
1216 ## whenUnsatisfiable: DoNotSchedule
1219 ## app.kubernetes.io/component: webhooks-server
1220 topologySpreadConstraints: []
1221 ## @param webhooksServer.priorityClassName [nullable] Name of the priority class for the webhooks server pods. Defaults to `global.priorityClassName`.
1222 # priorityClassName:
1223 ## @param webhooksServer.securityContext Security context for webhooks server pods. Defaults to `global.securityContext`.
1225 ## All settings relating to exposing the webhooks server's Prometheus metrics.
1227 ## @param webhooksServer.metrics.enabled Whether to expose the webhooks server's Prometheus metrics. When enabled, the webhooks server binds its metrics server (via `METRICS_BIND_ADDRESS`), declares a metrics container port, and a metrics `Service` is created. Metrics are served over plain HTTP.
1230 ## @param webhooksServer.metrics.service.type The type of the metrics `Service`.
1232 ## @param webhooksServer.metrics.service.clusterIP The cluster IP of the metrics `Service`. Set to `None` for a headless `Service`, which resolves directly to individual pod IPs -- useful for scrapers that perform their own endpoint discovery.
1234 ## @param webhooksServer.metrics.service.annotations Annotations to add to the metrics `Service`.
1236 ## @param webhooksServer.metrics.service.labels Additional labels to add to the metrics `Service`.
1238 ## @param webhooksServer.metrics.service.servicePort The port exposed by the metrics `Service`. Also used as the container port and the address the metrics server binds to.
1240 ## @param webhooksServer.metrics.service.portName The name of the metrics port. Referenced by the `ServiceMonitor` endpoint.
1241 portName: http-metrics
1243 ## @param webhooksServer.metrics.serviceMonitor.enabled Whether to create a Prometheus Operator `ServiceMonitor` for the webhooks server's metrics. Requires `webhooksServer.metrics.enabled` to be `true` and the Prometheus Operator CRDs (`monitoring.coreos.com/v1`) to be present in the cluster; otherwise it is silently skipped.
1245 ## @param webhooksServer.metrics.serviceMonitor.interval The scrape interval for the `ServiceMonitor`.
1247 ## @param webhooksServer.metrics.serviceMonitor.scheme The scheme to use when scraping. Defaults to `http` (metrics are served over plain HTTP).
1249 ## @param webhooksServer.metrics.serviceMonitor.tlsConfig TLS configuration for the `ServiceMonitor` endpoint. Rendered as literal YAML.
1251 ## @param webhooksServer.metrics.serviceMonitor.relabelings Relabeling rules applied to samples before scraping. Rendered as literal YAML.
1253 ## @param webhooksServer.metrics.serviceMonitor.metricRelabelings Relabeling rules applied to samples before ingestion. Rendered as literal YAML.
1254 metricRelabelings: []
1255 ## @param webhooksServer.metrics.serviceMonitor.additionalLabels Additional labels to add to the `ServiceMonitor`. Often required to match the label selector of your Prometheus Operator instance.
1256 additionalLabels: {}
1257 ## @param webhooksServer.metrics.serviceMonitor.namespace The namespace in which to create the `ServiceMonitor`. Defaults to the release namespace.
1259 podDisruptionBudget:
1260 ## @param webhooksServer.podDisruptionBudget.enabled Whether to create a PodDisruptionBudget for the webhooks server.
1262 ## @param webhooksServer.podDisruptionBudget.minAvailable Minimum number/percentage of pods that must remain available during disruption. Cannot be used with maxUnavailable.
1264 ## @param webhooksServer.podDisruptionBudget.maxUnavailable Maximum number/percentage of pods that can be unavailable during disruption. Cannot be used with minAvailable.
1267 ## @param webhooksServer.tls.selfSignedCert Whether to generate a self-signed certificate for the (internal) webhooks server. If `true`, `cert-manager` CRDs **must** be present in the cluster. The chart will create and use its own namespaced `Issuer`. If `false`, a cert `Secret` with the name specified by `webhooksServer.tls.secretName` **must** be provided in the same namespace as Kargo. If that cert is not already trusted by the Kubernetes API server, you must specify a value for `webhooksServer.tls.caBundle`. This is why it is strongly recommended to leave this setting as `true`. There is no provision for running the webhooks server without TLS because the Kubernetes API server will not communicate with non-TLS endpoints.
1268 selfSignedCert: true
1269 ## @param webhooksServer.tls.secretName Name of the cert `Secret` for use with the (internal) webhooks server. When `webhooksServer.tls.selfSignedCert` is `true`, this will be the name of the generated cert `Secret`. When `webhooksServer.tls.selfSignedCert` is `false`, a cert `Secret` with this name **must** be provided in the same namespace as Kargo. There is no provision for running the webhooks server without TLS because the Kubernetes API server will not communicate with non TLS-endpoints.
1270 secretName: kargo-webhooks-server-cert
1271 ## @param webhooksServer.tls.caBundle PEM-encoded TLS certificates for certificate authorities to trust when `webhooksServer.tls.selfSignedCert` is `false`. If the cert has been signed by an authority already trusted by the Kubernetes API server, this setting can be ignored.
1274 # -----BEGIN CERTIFICATE-----
1276 # -----END CERTIFICATE-----
1277## @param extraObjects An array describing additional, arbitrary Kubernetes resources to include when rendering this chart. Items in the array may be YAML objects or strings. Either may be templated. Templates will be evaluated against the same set of values as the rest of the chart.
1284# host: '{{ .Values.api.host }}'
1291# host: {{ .Values.api.host }}