DirectorySecurity AdvisoriesPricing
Sign in
Directory
kargo logoHELM

kargo

Helm chart
Last changed
Request a free trial

Contact our team to test out this Helm chart and related images for free. Please also indicate any other images you would like to evaluate.

Overview
Chart tags
Default values
Chart metadata
Images

Tag:
Compare:

1
## Default values for kargo.
2
## A human-readable version can be found in the chart README.
3
## This is a YAML-formatted file.
4
## Declare variables to be passed into your templates.
5
6
## @section Image Parameters
7
image:
8
## @param image.repository Image repository of Kargo
9
repository: chainreg.biz/chainguard-private/kargo
10
## @param image.tag Overrides the image tag. The default tag is the value of `.Chart.AppVersion`
11
tag: 1.11.7-r0@sha256:66c0607e2ededf381ed8eea2bc2e3d1d06e0cc6876e9c73e958430f7ccac17ff
12
## @param image.pullPolicy Image pull policy
13
pullPolicy: IfNotPresent
14
## @param image.pullSecrets List of imagePullSecrets.
15
pullSecrets: []
16
# - name: regcred
17
## @section Global Parameters
18
global:
19
systemResources:
20
## @param global.systemResources.namespace Designates a namespace to contain resources associated with cluster-scoped resources and for which no cluster-scoped analog exists. For example, ClusterConfig is a cluster-scoped resource. Cluster-scoped webhook receivers, defined as part of that resource, each must reference a Secret, however, no such thing as a cluster-scoped Secret exists within Kubernetes. To work around that, all Secrets referenced by a ClusterConfig resource must be located in a designated namespace. NOTE: The namespace designated for this purpose is NOT the place to put resources that you want to share across all Projects. This namespace is strictly for namespaced resources that must be referenced by other, cluster-scoped resources.
21
namespace: kargo-system-resources
22
## @param global.systemResources.createNamespace Indicates whether the namespace specified by `global.systemResources.namespace` should be created when installing the chart.
23
createNamespace: true
24
## @param global.systemResources.createRBAC Indicates whether the Roles/RoleBindings in the namespace specified by `global.systemResources.namespace` should be created when installing the chart.
25
createRBAC: true
26
## @param global.systemResources.extraNamespaceAnnotations Additional annotations to be added to the namespace specified by `global.systemResources.namespace`.
27
extraNamespaceAnnotations: {}
28
## @param global.systemResources.extraNamespaceLabels Additional labels to be added to the namespace specified by `global.systemResources.namespace`.
29
extraNamespaceLabels: {}
30
sharedResources:
31
## @param global.sharedResources.namespace designates a namespace where shared resources can be located.
32
namespace: kargo-shared-resources
33
## @param global.sharedResources.createNamespace Indicates whether the namespace specified by `global.sharedResources.namespace` should be created when installing the chart.
34
createNamespace: true
35
## @param global.sharedResources.createRBAC Indicates whether the Roles/RoleBindings in the namespace specified by `global.sharedResources.namespace` should be created when installing the chart.
36
createRBAC: true
37
## @param global.sharedResources.extraNamespaceAnnotations Additional annotations to be added to the namespace specified by `global.sharedResources.namespace`.
38
extraNamespaceAnnotations: {}
39
## @param global.sharedResources.extraNamespaceLabels Additional labels to be added to the namespace specified by `global.sharedResources.namespace`.
40
extraNamespaceLabels: {}
41
## @param global.labels Labels to add to all resources.
42
labels: {}
43
## @param global.annotations Annotations to add to all resources.
44
annotations: {}
45
## @param global.podLabels Labels to add to all pods.
46
podLabels: {}
47
## @param global.podAnnotations Annotations to add to pods.
48
podAnnotations: {}
49
## ServiceAccount global settings
50
serviceAccount:
51
## @param global.serviceAccount.labels Global ServiceAccount labels.
52
labels: {}
53
## @param global.serviceAccount.annotations Global ServiceAccount annotations.
54
annotations: {}
55
# foo: bar
56
# another: value
57
## @param global.env Environment variables to add to all Kargo pods.
58
env: []
59
# - name: ENV_NAME
60
# value: value
61
## @param global.envFrom Environment variables to add to all Kargo pods from ConfigMaps or Secrets.
62
envFrom: []
63
# - configMapRef:
64
# name: config-map-name
65
# - secretRef:
66
# name: secret-name
67
68
## @param global.nodeSelector Default node selector for all Kargo pods.
69
nodeSelector: {}
70
## @param global.tolerations Default tolerations for all Kargo pods.
71
tolerations: []
72
## @param global.affinity Default affinity for all Kargo pods.
73
affinity: {}
74
## @param global.priorityClassName [nullable] Default priority class for all Kargo pods.
75
# priorityClassName:
76
## @param global.securityContext Default security context for all Kargo pods.
77
securityContext: {}
78
## @section Workloads
79
workloads:
80
## @param workloads.install Whether to install workload-bearing resources (Deployments, CronJobs, etc.) and their supporting resources.
81
install: true
82
## @section Data Plane
83
dataPlane:
84
## @param dataPlane.install Coarse switch that, when `false`, suppresses every data-plane resource — even where finer-grained flags (`crds.install`, `rbac.installClusterRoles`, `rbac.installClusterRoleBindings`, `webhooks.register`, `global.sharedResources.createNamespace`, `global.systemResources.createNamespace`) would otherwise install them. Note: Argo CD data-plane RBAC is governed separately by `argocd.dataPlane.install`.
85
install: true
86
controller:
87
## @param dataPlane.controller.install Coarse switch governing whether per-controller data-plane resources are rendered.
88
install: true
89
## @section Argo CD Data Plane
90
argocd:
91
## @param argocd.dataPlane.install Coarse switch governing Argo CD data-plane resources — the RBAC granting the controller access to Argo CD `Application` resources. Separate from `dataPlane.install` because Argo CD may reside in a different cluster than Kargo's own data plane.
92
dataPlane:
93
install: true
94
kargoController:
95
## @param argocd.dataPlane.kargoController.install Coarse switch governing whether per-Kargo-controller Argo CD data-plane resources are rendered.
96
install: true
97
## @section CRDs
98
crds:
99
## @param crds.install Indicates if Custom Resource Definitions should be installed and upgraded as part of the release. If set to `false`, the CRDs will only be installed if they do not already exist.
100
install: true
101
## @param crds.keep Indicates if Custom Resource Definitions should be kept when a release is uninstalled.
102
keep: true
103
## @section RBAC
104
rbac:
105
## @param rbac.installClusterRoles Indicates if `ClusterRoles` should be installed.
106
installClusterRoles: true
107
## @param rbac.installClusterRoleBindings Indicates if `ClusterRoleBindings` should be installed.
108
installClusterRoleBindings: true
109
## @section Webhooks
110
webhooks:
111
## @param webhooks.register Whether to create `ValidatingWebhookConfiguration` and `MutatingWebhookConfiguration` resources.
112
register: true
113
## @section KubeConfigs
114
## @descriptionStart
115
## Optionally point to Kubernetes Secrets containing kubeconfig for:
116
##
117
## 1. A remote cluster hosting Kargo resources
118
##
119
## 2. A remote cluster hosting Argo CD resources
120
##
121
## This flexibility is useful for various advanced use cases -- especially
122
## topologies where Kargo data may be sharded, with Kargo controllers distributed
123
## across many clusters. Either or both of these configurations may be the same.
124
## In the average case, these should all be left unspecified. All that are
125
## unspecified will default to configuration for the cluster in which the Kargo
126
## controller is running.
127
## @descriptionEnd
128
## @skip kubeconfigSecrets
129
kubeconfigSecrets: {}
130
## @param kubeconfigSecrets.kargo [nullable] Kubernetes `Secret` name containing kubeconfig for a remote Kubernetes cluster hosting Kargo resources. Used by all Kargo components.
131
# kargo: ""
132
## @param kubeconfigSecrets.argocd [nullable] Kubernetes `Secret` name containing kubeconfig for a remote Kubernetes cluster hosting Argo CD resources. Used by Kargo controller(s) only.
133
# argocd: ""
134
135
## @section API
136
api:
137
## @param api.enabled Whether the API server is enabled.
138
enabled: true
139
## @skip api.kubeconfigSecrets
140
kubeconfigSecrets: {}
141
## @param api.kubeconfigSecrets.kargo [nullable] Per-component override for `kubeconfigSecrets.kargo`. Lets the API server mount its own kubeconfig secret rather than the shared one. Falls back to the chart-level value when unset.
142
# kargo: ""
143
144
## @param api.replicas The number of API server pods.
145
replicas: 1
146
## @param api.revisionHistoryLimit Number of old ReplicaSets the API server Deployment retains for rollback.
147
revisionHistoryLimit: 10
148
## @param api.rollingUpdate Values merged into the chart-built `strategy.rollingUpdate` for the API server Deployment. Typically used to tune `maxSurge` and `maxUnavailable` (each an absolute number or a percentage). Default empty map — Kubernetes defaults (25% / 25%) apply.
149
rollingUpdate: {}
150
# maxSurge: 25%
151
# maxUnavailable: 25%
152
153
## @param api.host The domain name where Kargo's API server will be accessible. When applicable, this is used for generation of an Ingress resource, certificates, and the OpenID Connect issuer and callback URLs. Note: The value in this field MAY include a port number and MUST NOT specify the protocol (http vs https), which is automatically inferred from other configuration options.
154
host: localhost
155
## @param api.basePath URL path prefix at which the API server is reachable. When non-empty, MUST begin with a slash and MUST NOT end with one (e.g. `/kargo`). Used as the path on any chart-generated Ingress rule for the API server, and included in chart-generated URLs (`API_SERVER_BASE_URL`, `ADMIN_ACCOUNT_TOKEN_ISSUER`, `OIDC_ISSUER_URL`, etc.). The API server binary itself always serves at the root, so when this is set, the user is responsible for configuring their Ingress controller to strip the prefix before forwarding (e.g. via Traefik's `stripPrefix` middleware, NGINX's `rewrite`, etc.).
156
basePath: ""
157
## @param api.logLevel The log level for the API server. Valid options are ERROR, INFO, DEBUG, and TRACE (case insensitive). Note that INFO level messages are written during startup regardless of the selected level.
158
logLevel: INFO
159
## @param api.logFormat The format of logs from the API server. Valid options are CONSOLE or JSON (case insensitive).
160
logFormat: CONSOLE
161
## @param api.secretManagementEnabled Specifies whether Secret management is enabled. This affects the API server's ability to manage repository credentials and other Project-level Secrets, such as those used by AnalysisRuns for verification purposes. If using GitOps to manage Kargo Projects declaratively, the API's Secret management capabilities are not needed and can be disabled to effectively reduce the API server's attackable surface.
162
secretManagementEnabled: true
163
## @param api.permissiveCORSPolicyEnabled Whether to enable a permissive CORS (Cross Origin Resource Sharing) policy. This is sometimes advantageous during local development, but otherwise, should generally be left disabled.
164
permissiveCORSPolicyEnabled: false
165
## @param api.trustedProxies IP addresses or CIDRs of proxies (e.g. an ingress controller or load balancer) in front of the API server. When a request arrives from one of these, the client's IP address is taken from `api.clientIPHeader`, or else from the rightmost `X-Forwarded-For` entry that is not a trusted proxy. When empty, the client's IP address is always the address the request arrived from.
166
trustedProxies: []
167
## @param api.clientIPHeader A header that every trusted proxy sets to the client's IP address, e.g. `CF-Connecting-IP` or `X-Real-IP`. Only honored on requests arriving from a trusted proxy.
168
clientIPHeader: ""
169
requestLog:
170
## @param api.requestLog.allEnabled Whether to log every API request at INFO level. By default, only refused requests (401 and 403) are logged at INFO level and server errors at ERROR level, while all other requests are logged at DEBUG level.
171
allEnabled: false
172
## @param api.requestLog.sourceIPEnabled Whether to include the IP address each request came from in the API server's logs. IP addresses may be considered personal data, so this is disabled by default.
173
sourceIPEnabled: false
174
secret:
175
## @param api.secret.name Specifies the name of an existing Secret which contains the `ADMIN_ACCOUNT_PASSWORD_HASH` and `ADMIN_ACCOUNT_TOKEN_SIGNING_KEY` values. By setting this, the Secret will **not** be generated by Helm.
176
name: ""
177
adminAccount:
178
## @param api.adminAccount.enabled Whether to enable the admin account.
179
enabled: true
180
## @param api.adminAccount.passwordHash Bcrypt password hash for the admin account. A value **must** be provided for this field unless `api.secret.name` is specified.
181
passwordHash: ""
182
## @param api.adminAccount.tokenSigningKey Key used to sign ID tokens (JWTs) for the admin account. It is suggested that you generate this using a password manager or a command like: `openssl rand -base64 29 \| tr -d "=+/" \| cut`. A value **must** be provided for this field, unless `api.secret.name` is specified.
183
tokenSigningKey: ""
184
## @param api.adminAccount.tokenTTL Specifies how long ID tokens for the admin account are valid. (i.e. The expiry will be the time of issue plus this duration.)
185
tokenTTL: 24h
186
## Optionally provide custom ClusterRole permissions for the various built in roles. This is
187
## useful if you want to grant extra permissions to these roles without creating entirely new
188
## roles. These should be a list of valid `roles` as you would include in a `ClusterRole`
189
## resource.
190
clusterRoles:
191
admin:
192
## @param api.clusterRoles.admin.additionalRules Additional RBAC rules to add to the kargo-admin ClusterRole.
193
additionalRules: null
194
projectCreator:
195
## @param api.clusterRoles.projectCreator.additionalRules Additional RBAC rules to add to the kargo-project-creator ClusterRole.
196
additionalRules: null
197
user:
198
## @param api.clusterRoles.user.additionalRules Additional RBAC rules to add to the kargo-user ClusterRole.
199
additionalRules: null
200
viewer:
201
## @param api.clusterRoles.viewer.additionalRules Additional RBAC rules to add to the kargo-viewer ClusterRole.
202
additionalRules: null
203
## All settings related to enabling OpenID Connect as an authentication
204
## method.
205
oidc:
206
## @param api.oidc.enabled Whether to enable authentication using Open ID Connect.
207
## NOTE: Kargo uses the Authorization Code Flow with Proof Key for Code Exchange (PKCE) and does not require a client secret. Some OIDC identity providers may not support this. If yours does not, enabling the optional Dex server and configuring its connectors can adapt most identity providers to work this way.
208
## Note also: The PKCE code challenge used by Kargo is SHA256 hashed.
209
## For more information about PKCE, please visit: https://oauth.net/2/pkce/
210
enabled: false
211
## @param api.oidc.issuerURL The issuer URL for the identity provider. If Dex is enabled, this value will be ignored and the issuer URL will be automatically configured. If Dex is not enabled, this should be set to the issuer URL provided to you by your identity provider.
212
issuerURL:
213
## @param api.oidc.clientID The client ID for the OIDC client. If Dex is enabled, this value will be ignored and the client ID will be automatically configured. If Dex is not enabled, this should be set to the client ID provided to you by your identity provider.
214
clientID:
215
## @param api.oidc.cliClientID The client ID for the OIDC client used by CLI (optional). Needed by some OIDC providers (such as Dex) that require a separate Client ID for web app login vs. CLI login (`http://localhost`). If Dex is enabled, this value will be ignored and cli client ID will be automatically configured. If Dex is not enabled, and a different client app is configured for localhost CLI login, this should be the client ID configured in the IdP.
216
cliClientID:
217
## @param api.oidc.additionalScopes The additional scopes to send to the OIDC provider. This should be set to the scopes you wish to be provided to your identity provider from clients of Kargo, the scopes openid, profile and email are always requested and don't need to be added, this value is intended for any additional ones you require.
218
additionalScopes:
219
- groups
220
## @param api.oidc.usernameClaim The claim to use as the username for the user.
221
usernameClaim: email
222
admins:
223
## @param api.oidc.admins.claims Subjects having any of these claims will automatically be Kargo admins.
224
claims: {}
225
# sub:
226
# - alice
227
# - bob
228
# email:
229
# - alice@example.com
230
# - bob@examples.com
231
# groups:
232
# - kargo-admin
233
projectCreators:
234
## @param api.oidc.projectCreators.claims Subjects having any of these claims will automatically receive the permissions of the karo-user role (see `api.oidc.users`) **plus** permission to create new `Project`s. When a `Project` is created by such a user via the CLI or UI (i.e. through the API and not through `kubectl`) they will automatically receive admin permissions within that `Project` as well as permission to update and delete the cluster-scoped `Project` resource itself.
235
claims: {}
236
# sub:
237
# - alice
238
# - bob
239
# email:
240
# - alice@example.com
241
# - bob@examples.com
242
# groups:
243
# - kargo-project-creator
244
users:
245
## @param api.oidc.users.claims Subjects having any of these claims will automatically receive read-only access to all cluster-scoped Kargo resources. This is the minimum level of permissions that can be granted to a user to allow them to view the list of Projects and system-level configuration. This does not include any access to `Secrets`.
246
claims: {}
247
# sub:
248
# - alice
249
# - bob
250
# email:
251
# - alice@example.com
252
# - bob@examples.com
253
# groups:
254
# - kargo-user
255
viewers:
256
## @param api.oidc.viewers.claims Subjects having any of these claims will automatically receive read-only access to all Kargo resources. This does not include any access to `Secret`s.
257
claims: {}
258
# sub:
259
# - alice
260
# - bob
261
# email:
262
# - alice@example.com
263
# - bob@examples.com
264
# groups:
265
# - kargo-viewer
266
globalServiceAccounts:
267
## @param api.oidc.globalServiceAccounts.namespaces List of namespaces to look for shared service accounts.
268
namespaces: []
269
dex:
270
## @param api.oidc.dex.enabled Whether to enable Dex as the identity provider. When set to true, the Kargo installation will include a Dex server and the Kargo API server will be configured to make the /dex endpoint a reverse proxy for the Dex server.
271
enabled: false
272
## All settings related to using an externally-managed Dex server (one not installed by this chart). When `byo.enabled` is `true`, the chart will NOT install a Dex server but the Kargo API server will still proxy `/dex` to the externally-managed Dex server. Configure `api.oidc.issuerURL`, `api.oidc.clientID`, etc. just as you would for any other OIDC identity provider. Mutually exclusive with `api.oidc.dex.enabled`.
273
byo:
274
## @param api.oidc.dex.byo.enabled Whether to enable proxying to an externally-managed Dex server.
275
enabled: false
276
## @param api.oidc.dex.byo.serverAddress Address (scheme + host + optional port) at which the Kargo API server should reach the externally-managed Dex server. This is used for in-cluster traffic from the API server pod to Dex, not for what end-user clients see (clients see `api.oidc.issuerURL`). Defaults to `https://kargo-dex-server.<release.namespace>.svc` — matching the chart's convention for a Dex Service named `kargo-dex-server` in the release namespace.
277
serverAddress: ""
278
## @param api.oidc.dex.byo.caCertPath Path inside the Kargo API server container at which a CA certificate trusted by Dex is mounted. Optional. When set, the API server will use this certificate when making outbound TLS connections to the externally-managed Dex server. The cert itself must be made available via `api.containers` / `api.volumes` / `api.volumeMounts` (or another out-of-band mechanism).
279
caCertPath: ""
280
## @param api.oidc.dex.revisionHistoryLimit Number of old ReplicaSets the Dex server Deployment retains for rollback.
281
revisionHistoryLimit: 10
282
## @param api.oidc.dex.rollingUpdate Values merged into the chart-built `strategy.rollingUpdate` for the Dex server Deployment. Typically used to tune `maxSurge` and `maxUnavailable` (each an absolute number or a percentage). Default empty map — Kubernetes defaults (25% / 25%) apply.
283
rollingUpdate: {}
284
# maxSurge: 25%
285
# maxUnavailable: 25%
286
287
image:
288
## @param api.oidc.dex.image.repository Image repository of Dex
289
repository: chainreg.biz/chainguard-private/dex
290
## @param api.oidc.dex.image.tag Image tag for Dex.
291
tag: 2.46.0-r0@sha256:9b3d0cccc4b13032ae372d99eea071b3a6ee607a8e52151a1a42d0d97b9d346c
292
## @param api.oidc.dex.image.pullPolicy Image pull policy for Dex.
293
pullPolicy: IfNotPresent
294
## @param api.oidc.dex.image.pullSecrets List of imagePullSecrets.
295
pullSecrets: []
296
# - name: regcred
297
## @param api.oidc.dex.logLevel The log level for the Dex server. Since Dex server is a third-party software, its log level options differ from the other Kargo components. The valid options are: DEBUG, INFO, WARN, ERROR.
298
logLevel: INFO
299
## @param api.oidc.dex.logFormat The format of logs from the Dex server. Since Dex server is a third-party software, its log format options differ from the other Kargo components. The valid options are TEXT and JSON.
300
logFormat: TEXT
301
## @param api.oidc.dex.skipApprovalScreen Whether to skip Dex's own approval screen. Since upstream identity providers will already request user consent, this second approval screen from Dex can be both superfluous and confusing.
302
skipApprovalScreen: true
303
## @param api.oidc.dex.connectors Configure [Dex connectors](https://dexidp.io/docs/connectors/) to one or more upstream identity providers.
304
connectors: []
305
# - id: mock
306
# name: Example
307
# type: mockCallback
308
## Google Example
309
# - id: google
310
# name: Google
311
# type: google
312
# config:
313
# clientID: <your client ID>
314
# clientSecret: "$CLIENT_SECRET"
315
# redirectURI: <http(s)>://<api.host>/dex/callback
316
## GitHub Example
317
# - id: github
318
# name: GitHub
319
# type: github
320
# config:
321
# clientID: <your client ID>
322
# clientSecret: "$CLIENT_SECRET"
323
# redirectURI: <http(s)>://<api.host>/dex/callback
324
## Azure Example
325
# - id: microsoft
326
# name: microsoft
327
# type: microsoft
328
# config:
329
# clientID: <your client ID>
330
# clientSecret: "$CLIENT_SECRET"
331
# redirectURI: <http(s)>://<api.host>/dex/callback
332
# tenant: <tenant ID>
333
334
## ServiceAccount specific settings
335
serviceAccount:
336
## @param api.oidc.dex.serviceAccount.labels Additional labels to add to the Dex server ServiceAccount.
337
labels: {}
338
## @param api.oidc.dex.serviceAccount.annotations Additional annotations to add to the Dex server ServiceAccount.
339
annotations: {}
340
# foo: bar
341
# another: value
342
## @param api.oidc.dex.env Environment variables to add to Dex server pods. This is convenient for cases where api.oidc.dex.connectors needs to reference environment variables from a Secret that is managed "out of band" with a secret management solution such as Sealed Secrets.
343
env: []
344
# - name: CLIENT_SECRET
345
# valueFrom:
346
# secretKeyRef:
347
# name: github-dex
348
# key: dex.github.clientSecret
349
## @param api.oidc.dex.envFrom Environment variables to add to Dex server pods from ConfigMaps or Secrets. This is especially convenient for cases where api.oidc.dex.connectors needs to reference environment variables from a Secret that is managed "out of band" with a secret management solution such as Sealed Secrets.
350
envFrom: []
351
# - configMapRef:
352
# name: config-map-name
353
# - secretRef:
354
# name: secret-name
355
356
## @param api.oidc.dex.containers Additional sidecar containers to add to Dex pods. Rendered as literal YAML.
357
containers: []
358
## @param api.oidc.dex.initContainers Additional init containers to add to Dex pods. Rendered as literal YAML.
359
initContainers: []
360
## @param api.oidc.dex.volumes Add additional volumes to Dex pods. This is convenient for cases where api.oidc.dex.connectors needs to reference mounted data from a Secret that is managed "out of band" with a secret management solution such as Sealed Secrets.
361
volumes: []
362
# - name: google-json
363
# secret:
364
# defaultMode: 420
365
# secretName: kargo-google-groups-json
366
## @param api.oidc.dex.volumeMounts Add additional volume mounts to Dex pods. This is convenient for cases where api.oidc.dex.connectors needs to reference mounted data from a Secret that is managed "out of band" with a secret management solution such as Sealed Secrets.
367
volumeMounts:
368
# - mountPath: /tmp/oidc
369
# name: google-json
370
# readOnly: true
371
372
## @param api.oidc.dex.resources Resources limits and requests for the Dex server containers.
373
resources: {}
374
# limits:
375
# cpu: 100m
376
# memory: 128Mi
377
# requests:
378
# cpu: 100m
379
# memory: 128Mi
380
381
## @param api.oidc.dex.nodeSelector Node selector for Dex server pods. Defaults to `global.nodeSelector`.
382
nodeSelector: {}
383
## @param api.oidc.dex.tolerations Tolerations for Dex server pods. Defaults to `global.tolerations`.
384
tolerations: []
385
## @param api.oidc.dex.affinity Specifies pod affinity for the Dex server pods. Defaults to `global.affinity`.
386
affinity: {}
387
## @param api.oidc.dex.priorityClassName [nullable] Name of the priority class for the Dex server pods. Defaults to `global.priorityClassName`.
388
# priorityClassName:
389
## @param api.oidc.dex.annotations Annotations to add to the Dex server deployment. Merges with `global.annotations`, allowing you to override or add to the global annotations.
390
annotations: {}
391
## @param api.oidc.dex.podAnnotations Annotations to add to the Dex server pods. Merges with `global.podAnnotations`, allowing you to override or add to the global annotations.
392
podAnnotations: {}
393
## @param api.oidc.dex.securityContext Security context for Dex server pods. Defaults to `global.securityContext`.
394
securityContext: {}
395
probes:
396
## @param api.oidc.dex.probes.enabled Whether startup, liveness, and readiness probes should be included in the Dex server deployment. It is sometimes advantageous to disable these during local development.
397
enabled: true
398
## @param api.oidc.dex.probes.startupProbe [object] Values merged into the chart-built `startupProbe` for the Dex server. Typically used to tune timing fields like `initialDelaySeconds`, `periodSeconds`, `timeoutSeconds`, `successThreshold`, and `failureThreshold`.
399
startupProbe:
400
initialDelaySeconds: 10
401
# periodSeconds: 10
402
# timeoutSeconds: 1
403
# successThreshold: 1
404
failureThreshold: 30
405
## @param api.oidc.dex.probes.livenessProbe [object] Values merged into the chart-built `livenessProbe` for the Dex server. Default is an empty map, so the chart's `livenessProbe` renders with Kubernetes-default timings.
406
livenessProbe: {}
407
# initialDelaySeconds: 0
408
# periodSeconds: 10
409
# timeoutSeconds: 1
410
# successThreshold: 1
411
# failureThreshold: 3
412
## @param api.oidc.dex.probes.readinessProbe [object] Values merged into the chart-built `readinessProbe` for the Dex server.
413
readinessProbe:
414
initialDelaySeconds: 5
415
# periodSeconds: 10
416
# timeoutSeconds: 1
417
# successThreshold: 1
418
# failureThreshold: 3
419
tls:
420
## @param api.oidc.dex.tls.selfSignedCert Whether to generate a self-signed certificate for use with Dex. If `true`, `cert-manager` CRDs **must** be present in the cluster. The chart will create and use its own namespaced `Issuer`. If `false`, a cert `Secret` with the name specified by `api.oidc.dex.tls.secretName` **must** be provided in the same namespace as Kargo. There is no provision for running Dex without TLS.
421
selfSignedCert: true
422
## @param api.oidc.dex.tls.secretName Name of the cert `Secret` for use with Dex. When `api.oidc.dex.tls.selfSignedCert` is `true`, this will be the name of the generated cert `Secret`. When `api.oidc.dex.tls.selfSignedCert` is `false`, a cert `Secret` with this name **must** be provided in the same namespace as Kargo. There is no provision for running Dex without TLS.
423
secretName: kargo-dex-server-cert
424
argocd:
425
## @param api.argocd.urls Mapping of Argo CD shards names to URLs to support deep links to Argo CD URLs. If sharding is not used, map the empty string to the single Argo CD URL.
426
urls:
427
# "": https://argocd.example.com
428
# "shard2": https://argocd2.example.com
429
## All settings relating to the use of Argo Rollouts by the API Server.
430
rollouts:
431
## @param api.rollouts.integrationEnabled Specifies whether Argo Rollouts integration is enabled. When not enabled, the API server will not be capable of creating/updating/applying AnalysesTemplate resources in the Kargo control plane. When enabled, the API server will perform a sanity check at startup. If Argo Rollouts CRDs are not found, the API server will proceed as if this integration had been explicitly disabled. Explicitly disabling is still preferable if this integration is not desired, as it will grant fewer permissions to the API server.
432
integrationEnabled: true
433
## All settings related to streaming logs from the pods of AnalysisRuns using JobMetric providers.
434
logs:
435
## @param api.rollouts.logs.enabled Specifies whether support for streaming logs from AnalysisRuns using a JobMetric provider is enabled. This feature requires you to have forwarded and stored the logs yourself in a place where they can be retrieved with an HTTP GET.
436
enabled: false
437
## @param api.rollouts.logs.urlTemplate Instructs Kargo on how to construct a URL for the retrieval of relevant logs via HTTP GET. Expressions offset by ${{ }} are supported with the following variables pre-defined and injected with values: project (name), namespace (always equal to the Project's name), stage (name), analysisRun (name), metricName (name of the JobMetric), jobNamespace (namespace of the Job; may be different that the Project namespace as the Job may actually execute in a different cluster), jobName, container (name; since a Pod associated with a Job could have more than one). Example: "https://logs.kargo.example.com/${{project}}/${{analysisRun}}/${{jobName}}/${{container}}".
438
urlTemplate: ""
439
tokenSecret:
440
## @param api.rollouts.logs.tokenSecret.name specifies the name of a Kubernetes Secret managed "out of band" that contains a token usable for accessing job metric logs.
441
name:
442
## @param api.rollouts.logs.tokenSecret.key specifies the key in a Kubernetes Secret (named by name) that is managed "out of band" and contains a token usable for accessing job metric logs.
443
key:
444
## @param api.rollouts.logs.httpHeaders Specifies HTTP headers to include in the HTTP GET request for log retrieval. These are typically used for authentication. The header values support expressions offset by ${{ }}, with the same variables documented for urlTemplate pre-defined and injected with values.
445
httpHeaders: {}
446
## @param api.labels Labels to add to the api resources. Merges with `global.labels`, allowing you to override or add to the global labels.
447
labels: {}
448
## @param api.annotations Annotations to add to the api resources. Merges with `global.annotations`, allowing you to override or add to the global annotations.
449
annotations: {}
450
## @param api.podLabels Optional labels to add to pods. Merges with `global.podLabels`, allowing you to override or add to the global labels.
451
podLabels: {}
452
## @param api.podAnnotations Optional annotations to add to pods. Merges with `global.podAnnotations`, allowing you to override or add to the global annotations.
453
podAnnotations: {}
454
## ServiceAccount specific settings
455
serviceAccount:
456
## @param api.serviceAccount.labels Additional labels to add to the API server ServiceAccount.
457
labels: {}
458
## @param api.serviceAccount.annotations Additional annotations to add to the API server ServiceAccount.
459
annotations: {}
460
# foo: bar
461
# another: value
462
## @param api.env Environment variables to add to API server pods.
463
env: []
464
# - name: ENV_NAME
465
# value: value
466
## @param api.envFrom Environment variables to add to API server pods from ConfigMaps or Secrets.
467
envFrom: []
468
# - configMapRef:
469
# name: config-map-name
470
# - secretRef:
471
# name: secret-name
472
473
## @param api.containers Additional sidecar containers to add to API server pods. Rendered as literal YAML.
474
containers: []
475
## @param api.initContainers Additional init containers to add to API server pods. Rendered as literal YAML.
476
initContainers: []
477
## @param api.volumes Additional pod-level volumes for API server pods. Rendered as literal YAML.
478
volumes: []
479
## @param api.volumeMounts Additional volume mounts for the API server container. Rendered as literal YAML.
480
volumeMounts: []
481
## @param api.resources Resources limits and requests for the api containers.
482
resources: {}
483
# limits:
484
# cpu: 100m
485
# memory: 128Mi
486
# requests:
487
# cpu: 100m
488
# memory: 128Mi
489
490
## @param api.nodeSelector Node selector for api pods. Defaults to `global.nodeSelector`.
491
nodeSelector: {}
492
## @param api.tolerations Tolerations for api pods. Defaults to `global.tolerations`.
493
tolerations: []
494
## @param api.affinity Specifies pod affinity for api pods. Defaults to `global.affinity`.
495
affinity: {}
496
## @param api.topologySpreadConstraints Topology spread constraints for api pods.
497
## e.g.
498
## topologySpreadConstraints:
499
## - maxSkew: 1
500
## topologyKey: kubernetes.io/hostname
501
## whenUnsatisfiable: DoNotSchedule
502
## labelSelector:
503
## matchLabels:
504
## app.kubernetes.io/component: api
505
topologySpreadConstraints: []
506
## @param api.priorityClassName [nullable] Name of the priority class for api pods. Defaults to `global.priorityClassName`.
507
# priorityClassName:
508
## @param api.securityContext Security context for api pods. Defaults to `global.securityContext`.
509
securityContext: {}
510
podDisruptionBudget:
511
## @param api.podDisruptionBudget.enabled Whether to create a PodDisruptionBudget for the API server.
512
enabled: false
513
## @param api.podDisruptionBudget.minAvailable Minimum number/percentage of pods that must remain available during disruption. Cannot be used with maxUnavailable.
514
minAvailable: 1
515
## @param api.podDisruptionBudget.maxUnavailable Maximum number/percentage of pods that can be unavailable during disruption. Cannot be used with minAvailable.
516
maxUnavailable: ""
517
cabundle:
518
## @param api.cabundle.configMapName Specifies the name of an optional ConfigMap containing CA certs that is managed "out of band." Values in the ConfigMap named here should each contain a single PEM-encoded CA cert. If secretName is also defined, it will take precedence over this field.
519
configMapName: ""
520
## @param api.cabundle.secretName Specifies the name of an optional Secret containing CA certs that is managed "out of band." Values in the Secret named here should each contain a single PEM-encoded CA cert. If defined, the value of this field takes precedence over any in configMapName.
521
secretName: ""
522
probes:
523
## @param api.probes.enabled Whether startup, liveness, and readiness probes should be included in the API server deployment. It is sometimes advantageous to disable these during local development.
524
enabled: true
525
## @param api.probes.startupProbe [object] Values merged into the chart-built `startupProbe` for the API server. Typically used to tune timing fields like `initialDelaySeconds`, `periodSeconds`, `timeoutSeconds`, `successThreshold`, and `failureThreshold`.
526
startupProbe:
527
initialDelaySeconds: 10
528
# periodSeconds: 10
529
# timeoutSeconds: 1
530
# successThreshold: 1
531
failureThreshold: 30
532
## @param api.probes.livenessProbe [object] Values merged into the chart-built `livenessProbe` for the API server. Default is an empty map, so the chart's `livenessProbe` renders with Kubernetes-default timings.
533
livenessProbe: {}
534
# initialDelaySeconds: 0
535
# periodSeconds: 10
536
# timeoutSeconds: 1
537
# successThreshold: 1
538
# failureThreshold: 3
539
## @param api.probes.readinessProbe [object] Values merged into the chart-built `readinessProbe` for the API server.
540
readinessProbe:
541
initialDelaySeconds: 5
542
# periodSeconds: 10
543
# timeoutSeconds: 1
544
# successThreshold: 1
545
# failureThreshold: 3
546
tls:
547
## @param api.tls.enabled Whether to enable TLS directly on the API server. This is helpful if you do not intend to use an ingress controller or if you require TLS end-to-end. All other settings in this section EXCEPT `terminatedUpstream` will be ignored when this is set to `false`.
548
enabled: true
549
## @param api.tls.selfSignedCert Whether to generate a self-signed certificate for use by the API server. If `true`, `cert-manager` CRDs **must** be present in the cluster. The chart will create and use its own namespaced `Issuer`. If `false`, a cert `Secret` with the name specified by `api.tls.secretName` **must** be provided in the same namespace as Kargo. The value in this field has no effect if `api.tls.enabled` is `false`.
550
selfSignedCert: true
551
## @param api.tls.secretName Name of the cert `Secret` to use for the API server. When `api.tls.selfSignedCert` is `true`, this will be the name of the generated cert `Secret`. When `api.tls.selfSignedCert` is `false`, a cert `Secret` with this name **must** be provided in the same namespace as Kargo. The value in this field has no effect if `api.tls.enabled` is `false`.
552
secretName: kargo-api-cert
553
## @param api.tls.terminatedUpstream Whether TLS is terminated upstream, i.e. a load balancer, reverse-proxy, or an `Ingress` controller using a single wildcard cert is terminating it. Setting this to `true` forces all API server URLs to use HTTPS even if the `Ingress` (if applicable) or API server itself are listening for plain HTTP requests.
554
terminatedUpstream: false
555
ingress:
556
## @param api.ingress.enabled Whether to enable ingress by creating an Ingress resource. By default, this is disabled. Enabling ingress is advanced usage.
557
enabled: false
558
## @param api.ingress.annotations Annotations specified by your ingress controller to customize the behavior of the Ingress resource.
559
annotations: {}
560
# kubernetes.io/ingress.class: nginx
561
## @param api.ingress.ingressClassName If implemented by your ingress controller, specifies the ingress class. If your ingress controller does not support this, use the `kubernetes.io/ingress.class` annotation instead.
562
ingressClassName:
563
tls:
564
## @param api.ingress.tls.enabled Whether to associate a certificate with the Ingress resource.
565
enabled: true
566
## @param api.ingress.tls.selfSignedCert Whether to generate a self-signed certificate for use with the API server's `Ingress` resource. If `true`, `cert-manager` CRDs **must** be present in the cluster. The chart will create and use its own namespaced `Issuer`. If `false`, a cert `Secret` with the name specified by `api.ingress.tls.secretName` **must** be provided in the same namespace as Kargo. The value in this field has no effect if `api.ingress.tls.enabled` is `false`.
567
selfSignedCert: true
568
## @param api.ingress.tls.secretName Name of the cert `Secret` for use with the API server's `Ingress` resource. When `api.ingress.tls.selfSignedCert` is `true`, this will be the name of the generated cert `Secret`. When `api.ingress.tls.selfSignedCert` is `false`, a cert `Secret` with this name **must** be provided in the same namespace as Kargo. The value in this field has no effect if `api.ingress.tls.enabled` is `false`.
569
secretName: kargo-api-ingress-cert
570
## @param api.ingress.pathType You may want to use `Prefix` for some controllers (like AWS LoadBalancer Ingress controller), which don't support `/` as wildcard path when pathType is set to `ImplementationSpecific`
571
pathType: ImplementationSpecific
572
service:
573
## @param api.service.type If you're not going to use an ingress controller, you may want to change this value to `LoadBalancer` for production deployments. If running locally, you may want to change it to `NodePort` OR leave it as `ClusterIP` and use `kubectl port-forward` to map a port on the local network interface to the service.
574
type: ClusterIP
575
## @param api.service.nodePort [nullable] Host port the `Service` will be mapped to when `type` is either `NodePort` or `LoadBalancer`. If not specified, Kubernetes chooses.
576
# nodePort:
577
## @param api.service.annotations Annotations to add to the API server's service. Merges with `global.annotations`, allowing you to override or add to the global annotations.
578
annotations: {}
579
## @section Controller
580
## All settings for the controller component
581
controller:
582
## @param controller.enabled Whether the controller is enabled.
583
enabled: true
584
## @param controller.id [nullable] When set per-controller data plane resources will be suffixed with this value. This allows for the installation of multiple controllers into a single cluster or even a single namespace (each as its own, separate Helm release) without name collisions.
585
# id:
586
587
## @param controller.revisionHistoryLimit Number of old ReplicaSets the controller Deployment retains for rollback. The controller uses a `Recreate` rollout strategy (singleton), so `rollingUpdate.*` knobs do not apply.
588
revisionHistoryLimit: 10
589
## @skip controller.kubeconfigSecrets
590
kubeconfigSecrets: {}
591
## @param controller.kubeconfigSecrets.kargo [nullable] Per-component override for `kubeconfigSecrets.kargo`. Lets the controller mount its own kubeconfig secret rather than the shared one. Falls back to the chart-level value when unset.
592
# kargo: ""
593
## @param controller.kubeconfigSecrets.argocd [nullable] Per-component override for `kubeconfigSecrets.argocd`. Falls back to the chart-level value when unset.
594
# argocd: ""
595
596
## @param controller.logLevel The log level for the controller. Valid options are ERROR, INFO, DEBUG, and TRACE (case insensitive). Note that INFO level messages are written during startup regardless of the selected level.
597
logLevel: INFO
598
## @param controller.logFormat The format of logs from the controller. Valid options are CONSOLE or JSON (case insensitive).
599
logFormat: CONSOLE
600
## @param controller.isDefault When running multiple controllers backed by a single underlying control plane, designating this controller as the default will cause it to operate on resources not assigned to a specific shard. If `controller.shardName` is undefined, this controller will be considered the default **regardless** of the value of this field (as that was the behavior prior to the introduction of this field). If `controller.shardName` **is** defined, this controller will not be considered the default **unless, additionally** this field is `true`. i.e. A controller is effectively considered the default if `or (not controller.shardName) controller.isDefault`. If `controller.shardName` is defined **and** this field is `true`, this controller will operate **both** on resources explicitly assigned to it **as well as** those not assigned to a specific shard.
601
isDefault: false
602
## @param controller.shardName [nullable] When running multiple controllers backed by a single underlying control plane, specifying a shard name will cause this controller to operate **only** on resources with a matching shard name. Leaving this field undefined will designate this controller as the default controller that is responsible for resources that are not assigned to a specific shard **regardless** of the value of `controller.isDefault` (as that was the behavior prior to the introduction of `controller.isDefault`). If this field is defined, this controller will not be considered the default **unless, additionally** `controller.isDefault` is `true`. i.e. A controller is effectively considered the default if `or (not controller.shardName) controller.isDefault`. If this field is defined **and** `controller.isDefault` is true, this controller will operate **both** on resources explicitly assigned to it **as well as** those not assigned to a specific shard.
603
# shardName:
604
605
## @param controller.allowCredentialsOverHTTP Specifies whether the controller should allow credentials (for Git repositories, etc.) to be retrieved and used for operations over HTTP. This is generally discouraged, as it can expose sensitive information. When set to `false`, the controller will only allow credentials to be used over HTTPS (or other secure protocols).
606
allowCredentialsOverHTTP: false
607
## Reconciler-specific settings
608
reconcilers:
609
## @param controller.reconcilers.maxConcurrentReconciles specifies the maximum number of resources EACH of the controller's reconcilers can reconcile concurrently. This setting may also be overridden on a per-reconciler basis.
610
maxConcurrentReconciles: 4
611
controlFlowStages:
612
## @param controller.reconcilers.controlFlowStages.maxConcurrentReconciles optionally overrides the maximum number of control flow Stage resources the controller can reconcile concurrently.
613
maxConcurrentReconciles:
614
promotions:
615
## @param controller.reconcilers.promotions.maxConcurrentReconciles optionally overrides the maximum number of Promotion resources the controller can reconcile concurrently.
616
maxConcurrentReconciles:
617
promotionRequests:
618
## @param controller.reconcilers.promotionRequests.maxConcurrentReconciles optionally overrides the maximum number of PromotionRequest resources the controller can reconcile concurrently.
619
maxConcurrentReconciles:
620
stages:
621
## @param controller.reconcilers.stages.maxConcurrentReconciles optionally overrides the maximum number of (non-control flow) Stage resources the controller can reconcile concurrently.
622
maxConcurrentReconciles:
623
warehouses:
624
## @param controller.reconcilers.warehouses.maxConcurrentReconciles optionally overrides the maximum number of Warehouse resources the controller can reconcile concurrently.
625
maxConcurrentReconciles:
626
## @param controller.reconcilers.warehouses.minReconciliationInterval optionally sets the minimum reconciliation interval for Warehouse resources. Accepts duration format (e.g., "5m", "1h", "30s"). If a Warehouse specifies an interval lower than this minimum, the minimum value will be enforced instead. If not set, no minimum is enforced.
627
minReconciliationInterval: "5m0s"
628
gitClient:
629
## @param controller.gitClient.name Specifies the name of the Kargo controller (used when authoring Git commits).
630
name: "Kargo"
631
## @param controller.gitClient.email Specifies the email of the Kargo controller (used when authoring Git commits).
632
email: "no-reply@kargo.io"
633
## @param controller.gitClient.pushIntegrationPolicy Controls how remote changes are integrated before pushing. Options: AlwaysRebase (unconditionally rebase), RebaseOrMerge (rebase when safe, merge otherwise), RebaseOrFail (rebase when safe, fail otherwise), AlwaysMerge (unconditionally merge).
634
pushIntegrationPolicy: "RebaseOrMerge"
635
signingKeySecret:
636
## @param controller.gitClient.signingKeySecret.name Specifies the name of an existing `Secret` which contains the Git user's signing key. The value should be accessible under `.data.signingKey` in the same namespace as Kargo. When the signing key is a GPG key, the GPG key's name and email address identity must match the values defined for `controller.gitClient.name` and `controller.gitClient.email`.
637
name: ""
638
## @param controller.gitClient.signingKeySecret.type Specifies the type of the signing key. The currently supported and default option is `gpg`.
639
type: ""
640
githubPush:
641
## @param controller.githubPush.maxRevisions The maximum number of commits that the github-push step will replay via the GitHub API in a single push. This is a safety guardrail against accidentally replaying large numbers of commits.
642
maxRevisions: 10
643
## @param controller.githubPush.verifyUntrustedCommits When true, the github-push step will omit author/committer information for ALL commits replayed via the GitHub API, not just those signed by a trusted key. This causes GitHub to sign all commits with its own key, resulting in verified commits regardless of trust. Use with caution -- this manufactures trust where none exists.
644
verifyUntrustedCommits: false
645
images:
646
registries:
647
## @param controller.images.registries.rateLimit defines the rate limit in requests-per-second (on a per registry basis) that will be voluntarily enforced client-side for all interactions with container image registries. The default limit is very low, but tune this setting with great caution. Turning it up is not a guarantee of improved Warehouse performance. When registries begin enforcing rate limits because the client is not, the resulting errors may degrade performance worse than voluntarily observing a more conservative rate limit.
648
rateLimit: 20
649
cache:
650
## @param controller.images.cache.cacheByTagPolicy establishes a policy regarding the caching of container image metadata using tags as keys in order to realize a performance boost. Doing so is safest when it is known that image tags are immutable (never overwritten). Permissible values are: "Forbid" (no caching by tag; silently enforced), "Allow" (subscriptions MAY opt-in to caching by tag), "Require" (subscriptions MUST opt-in to caching by tag; effectively this is developer acknowledgement of the cache by tag behavior), "Force" (caching by tag is silently enforced).
651
cacheByTagPolicy: Allow
652
## @param controller.images.cache.maxEntries specifies the maximum number of entries in the internal image metadata cache.
653
maxEntries: 100000
654
push:
655
## @param controller.images.push.maxArtifactSize The maximum size (in bytes) for OCI artifact pushes that transfer blobs (cross-repository copies and local file pushes). Defaults to 1 GiB (1073741824). Set to 0 to block such pushes entirely, or -1 to disable the limit.
656
maxArtifactSize: 1073741824
657
## All settings relating to the Argo CD control plane this controller might
658
## integrate with.
659
argocd:
660
## @param controller.argocd.integrationEnabled Specifies whether Argo CD integration is enabled. When not enabled, the controller will not watch Argo CD Application resources or factor Application health and sync state into determinations of Stage health. Argo CD-based promotion mechanisms will also fail. When enabled, the controller will perform a sanity check at startup. If Argo CD CRDs are not found, the controller will proceed as if this integration had been explicitly disabled. Explicitly disabling is still preferable if this integration is not desired, as it will grant fewer permissions to the controller.
661
integrationEnabled: true
662
## @param controller.argocd.namespace The namespace into which Argo CD is installed.
663
namespace: argocd
664
## @param controller.argocd.watchArgocdNamespaceOnly Specifies whether the reconciler that watches Argo CD Applications for the sake of forcing related Stages to reconcile should only watch Argo CD Application resources residing in Argo CD's own namespace. Note: Older versions of Argo CD only supported Argo CD Application resources in Argo CD's own namespace, but newer versions support Argo CD Application resources in any namespace. This should usually be left as `false`.
665
watchArgocdNamespaceOnly: false
666
## All settings relating to the use of Argo Rollouts AnalysisTemplates and
667
## AnalysisRuns as a means of verifying Stages after a Promotion.
668
rollouts:
669
## @param controller.rollouts.integrationEnabled Specifies whether Argo Rollouts integration is enabled. When not enabled, the controller will not reconcile Argo Rollouts AnalysisRun resources and attempts to verify Stages via Analysis will fail. When enabled, the controller will perform a sanity check at startup. If Argo Rollouts CRDs are not found, the controller will proceed as if this integration had been explicitly disabled. Explicitly disabling is still preferable if this integration is not desired, as it will grant fewer permissions to the controller.
670
integrationEnabled: true
671
## @param controller.rollouts.controllerInstanceID Specifies a cluster on which Jobs corresponding to an AnalysisRun (used for Freight/Stage verification purposes) will be executed. This is useful in cases where the cluster hosting the Kargo control plane is not a suitable environment for executing user-defined logic. Kargo will use this as the value of the rgo-rollouts.argoproj.io/controller-instance-id label when creating AnalysisRuns. When this is left empty/undefined, no such label will be added to AnalysisRuns.
672
controllerInstanceID: ""
673
## @param controller.labels Labels to add to the api resources. Merges with `global.labels`, allowing you to override or add to the global labels.
674
labels: {}
675
## @param controller.annotations Annotations to add to the api resources. Merges with `global.annotations`, allowing you to override or add to the global annotations.
676
annotations: {}
677
## @param controller.podLabels Optional labels to add to pods. Merges with `global.podLabels`, allowing you to override or add to the global labels.
678
podLabels: {}
679
## @param controller.podAnnotations Optional annotations to add to pods. Merges with `global.podAnnotations`, allowing you to override or add to the global annotations.
680
podAnnotations: {}
681
## All settings relating to the service account for the controller
682
serviceAccount:
683
## @param controller.serviceAccount.iamRole Specifies the ARN of an AWS IAM role to be used by the controller in an IRSA-enabled EKS cluster.
684
iamRole: ""
685
## @param controller.serviceAccount.labels Additional labels to add to the controller ServiceAccount.
686
labels: {}
687
## @param controller.serviceAccount.annotations Additional annotations to add to the controller ServiceAccount.
688
annotations: {}
689
# foo: bar
690
# another: value
691
## @param controller.serviceAccount.clusterWideSecretReadingEnabled Specifies whether the controller's ServiceAccount should be granted read permissions to Secrets CLUSTER-WIDE in the Kargo control plane's cluster. Enabling this is highly discouraged and you do so at your own peril. When this is NOT enabled, the Kargo management controller will dynamically expand and contract the controller's permissions to read Secrets on a Project-by-Project basis.
692
clusterWideSecretReadingEnabled: false
693
## @param controller.initContainers Optional init containers to add to the controller pods. This is rendered as the literal YAML.
694
initContainers: []
695
# - name: download-tools
696
# image: alpine:3.8
697
# command: [ sh, -c ]
698
# args:
699
# - ls
700
701
## @param controller.env Environment variables to add to controller pods.
702
env: []
703
# - name: ENV_NAME
704
# value: value
705
## @param controller.envFrom Environment variables to add to controller pods from ConfigMaps or Secrets.
706
envFrom: []
707
# - configMapRef:
708
# name: config-map-name
709
# - secretRef:
710
# name: secret-name
711
712
## @param controller.containers Additional sidecar containers to add to controller pods. Rendered as literal YAML.
713
containers: []
714
## @param controller.volumes Volumes for the controller pods.
715
volumes: []
716
## @param controller.volumeMounts Volume mounts for the controller pods.
717
volumeMounts: []
718
## @param controller.resources Resources limits and requests for the controller containers.
719
resources: {}
720
# limits:
721
# cpu: 100m
722
# memory: 128Mi
723
# requests:
724
# cpu: 100m
725
# memory: 128Mi
726
727
## @param controller.nodeSelector Node selector for controller pods. Defaults to `global.nodeSelector`.
728
nodeSelector: {}
729
## @param controller.tolerations Tolerations for controller pods. Defaults to `global.tolerations`.
730
tolerations: []
731
## @param controller.affinity Specifies pod affinity for controller pods. Defaults to `global.affinity`.
732
affinity: {}
733
## @param controller.priorityClassName [nullable] Name of the priority class for controller pods. Defaults to `global.priorityClassName`.
734
# priorityClassName:
735
## @param controller.securityContext Security context for controller pods. Defaults to `global.securityContext`.
736
securityContext: {}
737
cabundle:
738
## @param controller.cabundle.configMapName Specifies the name of an optional ConfigMap containing CA certs that is managed "out of band." Values in the ConfigMap named here should each contain a single PEM-encoded CA cert. If secretName is also defined, it will take precedence over this field.
739
configMapName: ""
740
## @param controller.cabundle.secretName Specifies the name of an optional Secret containing CA certs that is managed "out of band." Values in the Secret named here should each contain a single PEM-encoded CA cert. If defined, the value of this field takes precedence over any in configMapName.
741
secretName: ""
742
## All settings relating to exposing the controller's Prometheus metrics.
743
metrics:
744
## @param controller.metrics.enabled Whether to expose the controller's Prometheus metrics. When enabled, the controller binds its metrics server (via `METRICS_BIND_ADDRESS`), declares a metrics container port, and a metrics `Service` is created. Metrics are served over plain HTTP.
745
enabled: false
746
service:
747
## @param controller.metrics.service.type The type of the metrics `Service`.
748
type: ClusterIP
749
## @param controller.metrics.service.clusterIP The cluster IP of the metrics `Service`. Set to `None` for a headless `Service`, which resolves directly to individual pod IPs -- useful for scrapers that perform their own endpoint discovery.
750
clusterIP: ""
751
## @param controller.metrics.service.annotations Annotations to add to the metrics `Service`.
752
annotations: {}
753
## @param controller.metrics.service.labels Additional labels to add to the metrics `Service`.
754
labels: {}
755
## @param controller.metrics.service.servicePort The port exposed by the metrics `Service`. Also used as the container port and the address the metrics server binds to.
756
servicePort: 9090
757
## @param controller.metrics.service.portName The name of the metrics port. Referenced by the `ServiceMonitor` endpoint.
758
portName: http-metrics
759
serviceMonitor:
760
## @param controller.metrics.serviceMonitor.enabled Whether to create a Prometheus Operator `ServiceMonitor` for the controller's metrics. Requires `controller.metrics.enabled` to be `true` and the Prometheus Operator CRDs (`monitoring.coreos.com/v1`) to be present in the cluster; otherwise it is silently skipped.
761
enabled: false
762
## @param controller.metrics.serviceMonitor.interval The scrape interval for the `ServiceMonitor`.
763
interval: 30s
764
## @param controller.metrics.serviceMonitor.scheme The scheme to use when scraping. Defaults to `http` (metrics are served over plain HTTP).
765
scheme: ""
766
## @param controller.metrics.serviceMonitor.tlsConfig TLS configuration for the `ServiceMonitor` endpoint. Rendered as literal YAML.
767
tlsConfig: {}
768
## @param controller.metrics.serviceMonitor.relabelings Relabeling rules applied to samples before scraping. Rendered as literal YAML.
769
relabelings: []
770
## @param controller.metrics.serviceMonitor.metricRelabelings Relabeling rules applied to samples before ingestion. Rendered as literal YAML.
771
metricRelabelings: []
772
## @param controller.metrics.serviceMonitor.additionalLabels Additional labels to add to the `ServiceMonitor`. Often required to match the label selector of your Prometheus Operator instance.
773
additionalLabels: {}
774
## @param controller.metrics.serviceMonitor.namespace The namespace in which to create the `ServiceMonitor`. Defaults to the release namespace.
775
namespace: ""
776
## @section Garbage Collector
777
garbageCollector:
778
## @param garbageCollector.enabled Whether the garbage collector is enabled.
779
enabled: true
780
## @skip garbageCollector.kubeconfigSecrets
781
kubeconfigSecrets: {}
782
## @param garbageCollector.kubeconfigSecrets.kargo [nullable] Per-component override for `kubeconfigSecrets.kargo`. Lets the garbage collector mount its own kubeconfig secret rather than the shared one. Falls back to the chart-level value when unset.
783
# kargo: ""
784
785
## @param garbageCollector.logLevel The log level for the garbage collector. Valid options are ERROR, INFO, DEBUG, and TRACE (case insensitive). Note that INFO level messages are written during startup regardless of the selected level.
786
logLevel: INFO
787
## @param garbageCollector.logFormat The format of logs from the garbage collector. Valid options are CONSOLE or JSON (case insensitive).
788
logFormat: CONSOLE
789
## @param garbageCollector.schedule When to run the garbage collector.
790
schedule: "0 * * * *"
791
## @param garbageCollector.suspend Whether to suspend the garbage collector CronJob. When `true`, the CronJob remains in place but stops launching new Jobs.
792
suspend: false
793
## @param garbageCollector.successfulJobsHistoryLimit Number of successful Job records to retain. Defaults to the Kubernetes CronJob default of `3`.
794
successfulJobsHistoryLimit: 3
795
## @param garbageCollector.failedJobsHistoryLimit Number of failed Job records to retain. Defaults to the Kubernetes CronJob default of `1`.
796
failedJobsHistoryLimit: 1
797
## @param garbageCollector.ttlSecondsAfterFinished Optional automatic cleanup delay (in seconds) for completed garbage collector Jobs. Each Job will be eligible for deletion this many seconds after it finishes. Leave empty/unset to retain Jobs indefinitely (subject to the `*JobsHistoryLimit` knobs).
798
ttlSecondsAfterFinished:
799
## @param garbageCollector.workers The number of concurrent workers to run. Tuning this too low will result in slow garbage collection. Tuning this too high will result in too many API calls and may result in throttling.
800
workers: 3
801
## @param garbageCollector.maxRetainedPromotions The ideal maximum number of Promotions OLDER than the oldest Promotion in a non-terminal phase (for each Stage) that may be spared by the garbage collector. The ACTUAL number of older Promotions spared may exceed this ideal if some Promotions that would otherwise be deleted do not meet the minimum age criterion.
802
maxRetainedPromotions: 20
803
## @param garbageCollector.minPromotionDeletionAge The minimum age a Promotion must be before considered eligible for garbage collection.
804
minPromotionDeletionAge: 336h # Two weeks
805
## @param garbageCollector.maxRetainedFreight The ideal maximum number of Freight OLDER than the oldest still in use (from each Warehouse) that may be spared by the garbage collector. The ACTUAL number of older Freight spared may exceed this ideal if some Freight that would otherwise be deleted do not meet the minimum age criterion.
806
maxRetainedFreight: 20
807
## @param garbageCollector.minFreightDeletionAge The minimum age Freight must be before considered eligible for garbage collection.
808
minFreightDeletionAge: 336h # Two weeks
809
## @param garbageCollector.labels Labels to add to the api resources. Merges with `global.labels`, allowing you to override or add to the global labels.
810
labels: {}
811
## @param garbageCollector.annotations Annotations to add to the api resources. Merges with `global.annotations`, allowing you to override or add to the global annotations.
812
annotations: {}
813
## @param garbageCollector.podLabels Optional labels to add to pods. Merges with `global.podLabels`, allowing you to override or add to the global labels.
814
podLabels: {}
815
## @param garbageCollector.podAnnotations Optional annotations to add to pods. Merges with `global.podAnnotations`, allowing you to override or add to the global annotations.
816
podAnnotations: {}
817
## ServiceAccount specific settings
818
serviceAccount:
819
## @param garbageCollector.serviceAccount.labels Additional labels to add to the managementController ServiceAccount.
820
labels: {}
821
## @param garbageCollector.serviceAccount.annotations Additional annotations to add to the managementController ServiceAccount.
822
annotations: {}
823
# foo: bar
824
# another: value
825
## @param garbageCollector.env Environment variables to add to garbage collector pods.
826
env: []
827
# - name: ENV_NAME
828
# value: value
829
## @param garbageCollector.envFrom Environment variables to add to garbage collector pods from ConfigMaps or Secrets.
830
envFrom: []
831
# - configMapRef:
832
# name: config-map-name
833
# - secretRef:
834
# name: secret-name
835
836
## @param garbageCollector.containers Additional sidecar containers to add to garbage collector pods. Rendered as literal YAML.
837
containers: []
838
## @param garbageCollector.initContainers Additional init containers to add to garbage collector pods. Rendered as literal YAML.
839
initContainers: []
840
## @param garbageCollector.volumes Additional pod-level volumes for garbage collector pods. Rendered as literal YAML.
841
volumes: []
842
## @param garbageCollector.volumeMounts Additional volume mounts for the garbage collector container. Rendered as literal YAML.
843
volumeMounts: []
844
## @param garbageCollector.resources Resources limits and requests for the garbage collector containers.
845
resources: {}
846
# limits:
847
# cpu: 100m
848
# memory: 128Mi
849
# requests:
850
# cpu: 100m
851
# memory: 128Mi
852
853
## @param garbageCollector.nodeSelector Node selector for the garbage collector pods. Defaults to `global.nodeSelector`.
854
nodeSelector: {}
855
## @param garbageCollector.tolerations Tolerations for the garbage collector pods. Defaults to `global.tolerations`.
856
tolerations: []
857
## @param garbageCollector.affinity Specifies pod affinity for the garbage collector pods. Defaults to `global.affinity`.
858
affinity: {}
859
## @param garbageCollector.priorityClassName [nullable] Name of the priority class for the garbage collector pods. Defaults to `global.priorityClassName`.
860
# priorityClassName:
861
## @param garbageCollector.securityContext Security context for garbage collector pods. Defaults to `global.securityContext`.
862
securityContext: {}
863
## @section External Webhooks Server
864
externalWebhooksServer:
865
## @param externalWebhooksServer.enabled Whether the external webhooks server is enabled.
866
enabled: true
867
## @skip externalWebhooksServer.kubeconfigSecrets
868
kubeconfigSecrets: {}
869
## @param externalWebhooksServer.kubeconfigSecrets.kargo [nullable] Per-component override for `kubeconfigSecrets.kargo`. Lets the external webhooks server mount its own kubeconfig secret rather than the shared one. Falls back to the chart-level value when unset.
870
# kargo: ""
871
872
## @param externalWebhooksServer.replicas The number of external webhooks server pods.
873
replicas: 1
874
## @param externalWebhooksServer.revisionHistoryLimit Number of old ReplicaSets the external webhooks server Deployment retains for rollback.
875
revisionHistoryLimit: 10
876
## @param externalWebhooksServer.rollingUpdate Values merged into the chart-built `strategy.rollingUpdate` for the external webhook server Deployment. Typically used to tune `maxSurge` and `maxUnavailable` (each an absolute number or a percentage). Default empty map — Kubernetes defaults (25% / 25%) apply.
877
rollingUpdate: {}
878
# maxSurge: 25%
879
# maxUnavailable: 25%
880
881
## @param externalWebhooksServer.host The domain name where Kargo's external webhooks server will be accessible. When applicable, this is used for generation of an Ingress resource and certificates. Note: The value in this field MAY include a port number and MUST NOT specify the protocol (http vs https), which is automatically inferred from other configuration options.
882
host: localhost
883
## @param externalWebhooksServer.basePath URL path prefix at which the external webhooks server is reachable. When non-empty, MUST begin with a slash and MUST NOT end with one (e.g. `/webhook`). Used as the path on any chart-generated Ingress rule for the external webhooks server, and included in `EXTERNAL_WEBHOOK_SERVER_BASE_URL`. When the external webhooks server has no Ingress of its own and instead piggybacks on the API server's Ingress, this defaults to `<api.basePath>/webhooks`. The external webhooks server binary itself always serves at the root, so when this is set, the user is responsible for configuring their Ingress controller to strip the prefix before forwarding (e.g. via Traefik's `stripPrefix` middleware, NGINX's `rewrite`, etc.).
884
basePath: ""
885
## @param externalWebhooksServer.logLevel The log level for the external webhooks server. Valid options are ERROR, INFO, DEBUG, and TRACE (case insensitive). Note that INFO level messages are written during startup regardless of the selected level.
886
logLevel: INFO
887
## @param externalWebhooksServer.logFormat The format of logs from the external webhooks server. Valid options are CONSOLE or JSON (case insensitive).
888
logFormat: CONSOLE
889
## @param externalWebhooksServer.labels Labels to add to the external webhook server resources. Merges with `global.labels`, allowing you to override or add to the global labels.
890
labels: {}
891
## @param externalWebhooksServer.annotations Annotations to add to the external webhook server resources. Merges with `global.annotations`, allowing you to override or add to the global annotations.
892
annotations: {}
893
## @param externalWebhooksServer.podLabels Optional labels to add to the external webhook server pods. Merges with `global.podLabels`, allowing you to override or add to the global labels.
894
podLabels: {}
895
## @param externalWebhooksServer.podAnnotations Optional annotations to add to the external webhook server pods. Merges with `global.podAnnotations`, allowing you to override or add to the global annotations.
896
podAnnotations: {}
897
## ServiceAccount specific settings
898
serviceAccount:
899
## @param externalWebhooksServer.serviceAccount.labels Additional labels to add to the externalWebHooksServer ServiceAccount.
900
labels: {}
901
## @param externalWebhooksServer.serviceAccount.annotations Additional annotations to add to the externalWebHooksServer ServiceAccount.
902
annotations: {}
903
# foo: bar
904
# another: value
905
## @param externalWebhooksServer.env Environment variables to add to external webhook server pods.
906
env: []
907
# - name: ENV_NAME
908
# value: value
909
## @param externalWebhooksServer.envFrom Environment variables to add to external webhook server pods from ConfigMaps or Secrets.
910
envFrom: []
911
# - configMapRef:
912
# name: config-map-name
913
# - secretRef:
914
# name: secret-name
915
916
## @param externalWebhooksServer.containers Additional sidecar containers to add to external webhook server pods. Rendered as literal YAML.
917
containers: []
918
## @param externalWebhooksServer.initContainers Additional init containers to add to external webhook server pods. Rendered as literal YAML.
919
initContainers: []
920
## @param externalWebhooksServer.volumes Additional pod-level volumes for external webhook server pods. Rendered as literal YAML.
921
volumes: []
922
## @param externalWebhooksServer.volumeMounts Additional volume mounts for the external webhook server container. Rendered as literal YAML.
923
volumeMounts: []
924
## @param externalWebhooksServer.resources Resources limits and requests for the external webhook server containers.
925
resources: {}
926
# limits:
927
# cpu: 100m
928
# memory: 128Mi
929
# requests:
930
# cpu: 100m
931
# memory: 128Mi
932
933
## @param externalWebhooksServer.nodeSelector Node selector for external webhook server pods. Defaults to `global.nodeSelector`.
934
nodeSelector: {}
935
## @param externalWebhooksServer.tolerations Tolerations for external webhook server pods. Defaults to `global.tolerations`.
936
tolerations: []
937
## @param externalWebhooksServer.affinity Specifies pod affinity for external webhook server pods. Defaults to `global.affinity`.
938
affinity: {}
939
## @param externalWebhooksServer.topologySpreadConstraints Topology spread constraints for external webhook server pods.
940
## e.g.
941
## topologySpreadConstraints:
942
## - maxSkew: 1
943
## topologyKey: kubernetes.io/hostname
944
## whenUnsatisfiable: DoNotSchedule
945
## labelSelector:
946
## matchLabels:
947
## app.kubernetes.io/component: external-webhooks-server
948
topologySpreadConstraints: []
949
## @param externalWebhooksServer.priorityClassName [nullable] Name of the priority class for external webhook server pods. Defaults to `global.priorityClassName`.
950
# priorityClassName:
951
## @param externalWebhooksServer.securityContext Security context for external webhook server pods. Defaults to `global.securityContext`.
952
securityContext: {}
953
podDisruptionBudget:
954
## @param externalWebhooksServer.podDisruptionBudget.enabled Whether to create a PodDisruptionBudget for the external webhook server.
955
enabled: false
956
## @param externalWebhooksServer.podDisruptionBudget.minAvailable Minimum number/percentage of pods that must remain available during disruption. Cannot be used with maxUnavailable.
957
minAvailable: 1
958
## @param externalWebhooksServer.podDisruptionBudget.maxUnavailable Maximum number/percentage of pods that can be unavailable during disruption. Cannot be used with minAvailable.
959
maxUnavailable: ""
960
probes:
961
## @param externalWebhooksServer.probes.enabled Whether startup, liveness, and readiness probes should be included in the external webhook server deployment. It is sometimes advantageous to disable these during local development.
962
enabled: true
963
## @param externalWebhooksServer.probes.startupProbe [object] Values merged into the chart-built `startupProbe` for the external webhook server. Typically used to tune timing fields like `initialDelaySeconds`, `periodSeconds`, `timeoutSeconds`, `successThreshold`, and `failureThreshold`.
964
startupProbe:
965
initialDelaySeconds: 10
966
# periodSeconds: 10
967
# timeoutSeconds: 1
968
# successThreshold: 1
969
failureThreshold: 30
970
## @param externalWebhooksServer.probes.livenessProbe [object] Values merged into the chart-built `livenessProbe` for the external webhook server. Default is an empty map, so the chart's `livenessProbe` renders with Kubernetes-default timings.
971
livenessProbe: {}
972
# initialDelaySeconds: 0
973
# periodSeconds: 10
974
# timeoutSeconds: 1
975
# successThreshold: 1
976
# failureThreshold: 3
977
## @param externalWebhooksServer.probes.readinessProbe [object] Values merged into the chart-built `readinessProbe` for the external webhook server.
978
readinessProbe:
979
initialDelaySeconds: 5
980
# periodSeconds: 10
981
# timeoutSeconds: 1
982
# successThreshold: 1
983
# failureThreshold: 3
984
tls:
985
## @param externalWebhooksServer.tls.enabled Whether to enable TLS directly on the external webhook server. This is helpful if you do not intend to use an ingress controller or if you require TLS end-to-end. All other settings in this section EXCEPT `terminatedUpstream` will be ignored when this is set to `false`.
986
enabled: true
987
## @param externalWebhooksServer.tls.selfSignedCert Whether to generate a self-signed certificate for use by the external webhooks server. If `true`, `cert-manager` CRDs **must** be present in the cluster. The chart will create and use its own namespaced `Issuer`. If `false`, a cert `Secret` with the name specified by `externalWebhooksServer.tls.secretName` **must** be provided in the same namespace as Kargo. The value in this field has no effect if `externalWebhooksServer.tls.enabled` is `false`.
988
selfSignedCert: true
989
## @param externalWebhooksServer.tls.secretName Name of the cert `Secret` to use for the external webhooks server. When `externalWebhooksServer.tls.selfSignedCert` is `true`, this will be the name of the generated cert `Secret`. When `externalWebhooksServer.tls.selfSignedCert` is `false`, a cert `Secret` with this name **must** be provided in the same namespace as Kargo. The value in this field has no effect if `externalWebhooksServer.tls.enabled` is `false`.
990
secretName: kargo-external-webhooks-server-cert
991
## @param externalWebhooksServer.tls.terminatedUpstream Whether TLS is terminated upstream, i.e. a load balancer, reverse-proxy, or an `Ingress` controller using a single wildcard cert is terminating it. Setting this to `true` forces all external webhook server URLs to use HTTPS even if the `Ingress` (if applicable) or external webhook server itself are listening for plain HTTP requests.
992
terminatedUpstream: false
993
ingress:
994
## @param externalWebhooksServer.ingress.enabled Whether to enable separate ingress for webhook by creating an Ingress resource. By default, this is disabled and webhook is exposed as part of kargo-api ingress. Enabling ingress is advanced usage.
995
enabled: false
996
## @param externalWebhooksServer.ingress.annotations Annotations specified by your ingress controller to customize the behavior of the Ingress resource.
997
annotations: {}
998
# kubernetes.io/ingress.class: nginx
999
## @param externalWebhooksServer.ingress.ingressClassName If implemented by your ingress controller, specifies the ingress class. If your ingress controller does not support this, use the `kubernetes.io/ingress.class` annotation instead.
1000
ingressClassName:
1001
tls:
1002
## @param externalWebhooksServer.ingress.tls.enabled Whether to associate a certificate with the Ingress resource.
1003
enabled: true
1004
## @param externalWebhooksServer.ingress.tls.selfSignedCert Whether to generate a self-signed certificate for use with the external webhook server's `Ingress` resource. If `true`, `cert-manager` CRDs **must** be present in the cluster. The chart will create and use its own namespaced `Issuer`. If `false`, a cert `Secret` with the name specified by `externalWebhooksServer.ingress.tls.secretName` **must** be provided in the same namespace as Kargo. The value in this field has no effect if `externalWebhooksServer.ingress.tls.enabled` is `false`.
1005
selfSignedCert: true
1006
## @param externalWebhooksServer.ingress.tls.secretName Name of the cert `Secret` for the external webhooks server's `Ingress` resource. When `externalWebhooksServer.ingress.tls.selfSignedCert` is `true`, this will be the name of the generated cert `Secret`. When `externalWebhooksServer.ingress.tls.selfSignedCert` is `false`, a cert `Secret` with this name **must** be provided in the same namespace as Kargo. The value in this field has no effect if `externalWebhooksServer.ingress.tls.enabled` is `false`.
1007
secretName: kargo-external-webhooks-server-ingress-cert
1008
## @param externalWebhooksServer.ingress.pathType You may want to use `Prefix` for some controllers (like AWS LoadBalancer Ingress controller), which don't support `/` as wildcard path when pathType is set to `ImplementationSpecific`
1009
pathType: ImplementationSpecific
1010
service:
1011
## @param externalWebhooksServer.service.type If you're not going to use an ingress controller, you may want to change this value to `LoadBalancer` for production deployments. If running locally, you may want to change it to `NodePort` OR leave it as `ClusterIP` and use `kubectl port-forward` to map a port on the local network interface to the service.
1012
type: ClusterIP
1013
## @param externalWebhooksServer.service.nodePort [nullable] Host port the `Service` will be mapped to when `type` is either `NodePort` or `LoadBalancer`. If not specified, Kubernetes chooses.
1014
# nodePort:
1015
## @param externalWebhooksServer.service.annotations Annotations to add to the external webhook server's service. Merges with `global.annotations`, allowing you to override or add to the global annotations.
1016
annotations: {}
1017
## @section Management Controller
1018
## All settings for the management controller component
1019
managementController:
1020
## @param managementController.enabled Whether the management controller is enabled.
1021
enabled: true
1022
## @param managementController.revisionHistoryLimit Number of old ReplicaSets the management controller Deployment retains for rollback. The management controller uses a `Recreate` rollout strategy (singleton), so `rollingUpdate.*` knobs do not apply.
1023
revisionHistoryLimit: 10
1024
## @skip managementController.kubeconfigSecrets
1025
kubeconfigSecrets: {}
1026
## @param managementController.kubeconfigSecrets.kargo [nullable] Per-component override for `kubeconfigSecrets.kargo`. Lets the management controller mount its own kubeconfig secret rather than the shared one. Falls back to the chart-level value when unset.
1027
# kargo: ""
1028
1029
## @param managementController.logLevel The log level for the management controller. Valid options are ERROR, INFO, DEBUG, and TRACE (case insensitive). Note that INFO level messages are written during startup regardless of the selected level.
1030
logLevel: INFO
1031
## @param managementController.logFormat The format of logs from the management controller. Valid options are CONSOLE or JSON (case insensitive).
1032
logFormat: CONSOLE
1033
## Reconciler-specific settings
1034
reconcilers:
1035
## @param managementController.reconcilers.maxConcurrentReconciles specifies the maximum number of resources EACH of the management controller's reconcilers can reconcile concurrently. This setting may also be overridden on a per-reconciler basis.
1036
maxConcurrentReconciles: 4
1037
namespaces:
1038
## @param managementController.reconcilers.namespaces.maxConcurrentReconciles optionally overrides the maximum number of Namespace resources the management controller can reconcile concurrently.
1039
maxConcurrentReconciles:
1040
projectConfigs:
1041
## @param managementController.reconcilers.projectConfigs.maxConcurrentReconciles optionally overrides the maximum number of ProjectConfig resources the management controller can reconcile concurrently.
1042
maxConcurrentReconciles:
1043
projects:
1044
## @param managementController.reconcilers.projects.maxConcurrentReconciles optionally overrides the maximum number of Project resources the management controller can reconcile concurrently.
1045
maxConcurrentReconciles:
1046
serviceAccounts:
1047
## @param managementController.reconcilers.serviceAccounts.maxConcurrentReconciles optionally overrides the maximum number of ServiceAccount resources the management controller can reconcile concurrently.
1048
maxConcurrentReconciles:
1049
## @param managementController.labels Labels to add to the api resources. Merges with `global.labels`, allowing you to override or add to the global labels.
1050
labels: {}
1051
## @param managementController.annotations Annotations to add to the api resources. Merges with `global.annotations`, allowing you to override or add to the global annotations.
1052
annotations: {}
1053
## @param managementController.podLabels Optional labels to add to pods. Merges with `global.podLabels`, allowing you to override or add to the global labels.
1054
podLabels: {}
1055
## @param managementController.podAnnotations Optional annotations to add to pods. Merges with `global.podAnnotations`, allowing you to override or add to the global annotations.
1056
podAnnotations: {}
1057
## ServiceAccount specific settings
1058
serviceAccount:
1059
## @param managementController.serviceAccount.labels Additional labels to add to the managementController ServiceAccount.
1060
labels: {}
1061
## @param managementController.serviceAccount.annotations Additional annotations to add to the managementController ServiceAccount.
1062
annotations: {}
1063
# foo: bar
1064
# another: value
1065
## @param managementController.env Environment variables to add to management controller pods.
1066
env: []
1067
# - name: ENV_NAME
1068
# value: value
1069
## @param managementController.envFrom Environment variables to add to management controller pods from ConfigMaps or Secrets.
1070
envFrom: []
1071
# - configMapRef:
1072
# name: config-map-name
1073
# - secretRef:
1074
# name: secret-name
1075
1076
## @param managementController.containers Additional sidecar containers to add to management controller pods. Rendered as literal YAML.
1077
containers: []
1078
## @param managementController.initContainers Additional init containers to add to management controller pods. Rendered as literal YAML.
1079
initContainers: []
1080
## @param managementController.volumes Additional pod-level volumes for management controller pods. Rendered as literal YAML.
1081
volumes: []
1082
## @param managementController.volumeMounts Additional volume mounts for the management controller container. Rendered as literal YAML.
1083
volumeMounts: []
1084
## @param managementController.resources Resources limits and requests for the management controller containers.
1085
resources: {}
1086
# limits:
1087
# cpu: 100m
1088
# memory: 128Mi
1089
# requests:
1090
# cpu: 100m
1091
# memory: 128Mi
1092
1093
## @param managementController.nodeSelector Node selector for management controller pods. Defaults to `global.nodeSelector`.
1094
nodeSelector: {}
1095
## @param managementController.tolerations Tolerations for management controller pods. Defaults to `global.tolerations`.
1096
tolerations: []
1097
## @param managementController.affinity Specifies pod affinity for management controller pods. Defaults to `global.affinity`.
1098
affinity: {}
1099
## @param managementController.priorityClassName [nullable] Name of the priority class for management controller pods. Defaults to `global.priorityClassName`.
1100
# priorityClassName:
1101
## @param managementController.securityContext Security context for management controller pods. Defaults to `global.securityContext`.
1102
securityContext: {}
1103
## All settings relating to exposing the management controller's Prometheus metrics.
1104
metrics:
1105
## @param managementController.metrics.enabled Whether to expose the management controller's Prometheus metrics. When enabled, the management controller binds its metrics server (via `METRICS_BIND_ADDRESS`), declares a metrics container port, and a metrics `Service` is created. Metrics are served over plain HTTP.
1106
enabled: false
1107
service:
1108
## @param managementController.metrics.service.type The type of the metrics `Service`.
1109
type: ClusterIP
1110
## @param managementController.metrics.service.clusterIP The cluster IP of the metrics `Service`. Set to `None` for a headless `Service`, which resolves directly to individual pod IPs -- useful for scrapers that perform their own endpoint discovery.
1111
clusterIP: ""
1112
## @param managementController.metrics.service.annotations Annotations to add to the metrics `Service`.
1113
annotations: {}
1114
## @param managementController.metrics.service.labels Additional labels to add to the metrics `Service`.
1115
labels: {}
1116
## @param managementController.metrics.service.servicePort The port exposed by the metrics `Service`. Also used as the container port and the address the metrics server binds to.
1117
servicePort: 9090
1118
## @param managementController.metrics.service.portName The name of the metrics port. Referenced by the `ServiceMonitor` endpoint.
1119
portName: http-metrics
1120
serviceMonitor:
1121
## @param managementController.metrics.serviceMonitor.enabled Whether to create a Prometheus Operator `ServiceMonitor` for the management controller's metrics. Requires `managementController.metrics.enabled` to be `true` and the Prometheus Operator CRDs (`monitoring.coreos.com/v1`) to be present in the cluster; otherwise it is silently skipped.
1122
enabled: false
1123
## @param managementController.metrics.serviceMonitor.interval The scrape interval for the `ServiceMonitor`.
1124
interval: 30s
1125
## @param managementController.metrics.serviceMonitor.scheme The scheme to use when scraping. Defaults to `http` (metrics are served over plain HTTP).
1126
scheme: ""
1127
## @param managementController.metrics.serviceMonitor.tlsConfig TLS configuration for the `ServiceMonitor` endpoint. Rendered as literal YAML.
1128
tlsConfig: {}
1129
## @param managementController.metrics.serviceMonitor.relabelings Relabeling rules applied to samples before scraping. Rendered as literal YAML.
1130
relabelings: []
1131
## @param managementController.metrics.serviceMonitor.metricRelabelings Relabeling rules applied to samples before ingestion. Rendered as literal YAML.
1132
metricRelabelings: []
1133
## @param managementController.metrics.serviceMonitor.additionalLabels Additional labels to add to the `ServiceMonitor`. Often required to match the label selector of your Prometheus Operator instance.
1134
additionalLabels: {}
1135
## @param managementController.metrics.serviceMonitor.namespace The namespace in which to create the `ServiceMonitor`. Defaults to the release namespace.
1136
namespace: ""
1137
## @section Webhooks Server
1138
webhooksServer:
1139
## @param webhooksServer.enabled Whether the webhooks server is enabled.
1140
enabled: true
1141
## @skip webhooksServer.kubeconfigSecrets
1142
kubeconfigSecrets: {}
1143
## @param webhooksServer.kubeconfigSecrets.kargo [nullable] Per-component override for `kubeconfigSecrets.kargo`. Lets the webhooks server mount its own kubeconfig secret rather than the shared one. Falls back to the chart-level value when unset.
1144
# kargo: ""
1145
1146
## @param webhooksServer.replicas The number of webhooks server pods.
1147
replicas: 1
1148
## @param webhooksServer.revisionHistoryLimit Number of old ReplicaSets the webhooks server Deployment retains for rollback.
1149
revisionHistoryLimit: 10
1150
## @param webhooksServer.rollingUpdate Values merged into the chart-built `strategy.rollingUpdate` for the webhooks server Deployment. Typically used to tune `maxSurge` and `maxUnavailable` (each an absolute number or a percentage). Default empty map — Kubernetes defaults (25% / 25%) apply.
1151
rollingUpdate: {}
1152
# maxSurge: 25%
1153
# maxUnavailable: 25%
1154
1155
## @param webhooksServer.logLevel The log level for the webhooks server. Valid options are ERROR, INFO, DEBUG, and TRACE (case insensitive). Note that INFO level messages are written during startup regardless of the selected level.
1156
logLevel: INFO
1157
## @param webhooksServer.logFormat The format of logs from the webhooks server. Valid options are CONSOLE or JSON (case insensitive).
1158
logFormat: CONSOLE
1159
## @param webhooksServer.controlplaneUserRegex Regular expression for matching controlplane users.
1160
controlplaneUserRegex: "" # ^system:serviceaccount:kargo:[a-z0-9]([-a-z0-9]*[a-z0-9])?$
1161
## @param webhooksServer.labels Labels to add to the webhook server resources. Merges with `global.labels`, allowing you to override or add to the global labels.
1162
labels: {}
1163
## @param webhooksServer.annotations Annotations to add to the webhook server resources. Merges with `global.annotations`, allowing you to override or add to the global annotations.
1164
annotations: {}
1165
## @param webhooksServer.podLabels Optional labels to add to the webhook server pods. Merges with `global.podLabels`, allowing you to override or add to the global labels.
1166
podLabels: {}
1167
## @param webhooksServer.podAnnotations Optional annotations to add to the webhook server pods. Merges with `global.podAnnotations`, allowing you to override or add to the global annotations.
1168
podAnnotations: {}
1169
## ServiceAccount specific settings
1170
serviceAccount:
1171
## @param webhooksServer.serviceAccount.labels Additional labels to add to the webhooks server ServiceAccount.
1172
labels: {}
1173
## @param webhooksServer.serviceAccount.annotations Additional annotations to add to the webhooks server ServiceAccount.
1174
annotations: {}
1175
# foo: bar
1176
# another: value
1177
## @param webhooksServer.env Environment variables to add to webhook server pods.
1178
env: []
1179
# - name: ENV_NAME
1180
# value: value
1181
## @param webhooksServer.envFrom Environment variables to add to webhook server pods from ConfigMaps or Secrets.
1182
envFrom: []
1183
# - configMapRef:
1184
# name: config-map-name
1185
# - secretRef:
1186
# name: secret-name
1187
1188
## @param webhooksServer.containers Additional sidecar containers to add to webhooks server pods. Rendered as literal YAML.
1189
containers: []
1190
## @param webhooksServer.initContainers Additional init containers to add to webhooks server pods. Rendered as literal YAML.
1191
initContainers: []
1192
## @param webhooksServer.volumes Additional pod-level volumes for webhooks server pods. Rendered as literal YAML.
1193
volumes: []
1194
## @param webhooksServer.volumeMounts Additional volume mounts for the webhooks server container. Rendered as literal YAML.
1195
volumeMounts: []
1196
## @param webhooksServer.resources Resources limits and requests for the webhooks server containers.
1197
resources: {}
1198
# limits:
1199
# cpu: 100m
1200
# memory: 128Mi
1201
# requests:
1202
# cpu: 100m
1203
# memory: 128Mi
1204
1205
## @param webhooksServer.nodeSelector Node selector for the webhooks server pods. Defaults to `global.nodeSelector`.
1206
nodeSelector: {}
1207
## @param webhooksServer.tolerations Tolerations for the webhooks server pods. Defaults to `global.tolerations`.
1208
tolerations: []
1209
## @param webhooksServer.affinity Specifies pod affinity for the webhooks server pods. Defaults to `global.affinity`.
1210
affinity: {}
1211
## @param webhooksServer.topologySpreadConstraints Topology spread constraints for webhooks server pods.
1212
## e.g.
1213
## topologySpreadConstraints:
1214
## - maxSkew: 1
1215
## topologyKey: kubernetes.io/hostname
1216
## whenUnsatisfiable: DoNotSchedule
1217
## labelSelector:
1218
## matchLabels:
1219
## app.kubernetes.io/component: webhooks-server
1220
topologySpreadConstraints: []
1221
## @param webhooksServer.priorityClassName [nullable] Name of the priority class for the webhooks server pods. Defaults to `global.priorityClassName`.
1222
# priorityClassName:
1223
## @param webhooksServer.securityContext Security context for webhooks server pods. Defaults to `global.securityContext`.
1224
securityContext: {}
1225
## All settings relating to exposing the webhooks server's Prometheus metrics.
1226
metrics:
1227
## @param webhooksServer.metrics.enabled Whether to expose the webhooks server's Prometheus metrics. When enabled, the webhooks server binds its metrics server (via `METRICS_BIND_ADDRESS`), declares a metrics container port, and a metrics `Service` is created. Metrics are served over plain HTTP.
1228
enabled: false
1229
service:
1230
## @param webhooksServer.metrics.service.type The type of the metrics `Service`.
1231
type: ClusterIP
1232
## @param webhooksServer.metrics.service.clusterIP The cluster IP of the metrics `Service`. Set to `None` for a headless `Service`, which resolves directly to individual pod IPs -- useful for scrapers that perform their own endpoint discovery.
1233
clusterIP: ""
1234
## @param webhooksServer.metrics.service.annotations Annotations to add to the metrics `Service`.
1235
annotations: {}
1236
## @param webhooksServer.metrics.service.labels Additional labels to add to the metrics `Service`.
1237
labels: {}
1238
## @param webhooksServer.metrics.service.servicePort The port exposed by the metrics `Service`. Also used as the container port and the address the metrics server binds to.
1239
servicePort: 9090
1240
## @param webhooksServer.metrics.service.portName The name of the metrics port. Referenced by the `ServiceMonitor` endpoint.
1241
portName: http-metrics
1242
serviceMonitor:
1243
## @param webhooksServer.metrics.serviceMonitor.enabled Whether to create a Prometheus Operator `ServiceMonitor` for the webhooks server's metrics. Requires `webhooksServer.metrics.enabled` to be `true` and the Prometheus Operator CRDs (`monitoring.coreos.com/v1`) to be present in the cluster; otherwise it is silently skipped.
1244
enabled: false
1245
## @param webhooksServer.metrics.serviceMonitor.interval The scrape interval for the `ServiceMonitor`.
1246
interval: 30s
1247
## @param webhooksServer.metrics.serviceMonitor.scheme The scheme to use when scraping. Defaults to `http` (metrics are served over plain HTTP).
1248
scheme: ""
1249
## @param webhooksServer.metrics.serviceMonitor.tlsConfig TLS configuration for the `ServiceMonitor` endpoint. Rendered as literal YAML.
1250
tlsConfig: {}
1251
## @param webhooksServer.metrics.serviceMonitor.relabelings Relabeling rules applied to samples before scraping. Rendered as literal YAML.
1252
relabelings: []
1253
## @param webhooksServer.metrics.serviceMonitor.metricRelabelings Relabeling rules applied to samples before ingestion. Rendered as literal YAML.
1254
metricRelabelings: []
1255
## @param webhooksServer.metrics.serviceMonitor.additionalLabels Additional labels to add to the `ServiceMonitor`. Often required to match the label selector of your Prometheus Operator instance.
1256
additionalLabels: {}
1257
## @param webhooksServer.metrics.serviceMonitor.namespace The namespace in which to create the `ServiceMonitor`. Defaults to the release namespace.
1258
namespace: ""
1259
podDisruptionBudget:
1260
## @param webhooksServer.podDisruptionBudget.enabled Whether to create a PodDisruptionBudget for the webhooks server.
1261
enabled: false
1262
## @param webhooksServer.podDisruptionBudget.minAvailable Minimum number/percentage of pods that must remain available during disruption. Cannot be used with maxUnavailable.
1263
minAvailable: 1
1264
## @param webhooksServer.podDisruptionBudget.maxUnavailable Maximum number/percentage of pods that can be unavailable during disruption. Cannot be used with minAvailable.
1265
maxUnavailable: ""
1266
tls:
1267
## @param webhooksServer.tls.selfSignedCert Whether to generate a self-signed certificate for the (internal) webhooks server. If `true`, `cert-manager` CRDs **must** be present in the cluster. The chart will create and use its own namespaced `Issuer`. If `false`, a cert `Secret` with the name specified by `webhooksServer.tls.secretName` **must** be provided in the same namespace as Kargo. If that cert is not already trusted by the Kubernetes API server, you must specify a value for `webhooksServer.tls.caBundle`. This is why it is strongly recommended to leave this setting as `true`. There is no provision for running the webhooks server without TLS because the Kubernetes API server will not communicate with non-TLS endpoints.
1268
selfSignedCert: true
1269
## @param webhooksServer.tls.secretName Name of the cert `Secret` for use with the (internal) webhooks server. When `webhooksServer.tls.selfSignedCert` is `true`, this will be the name of the generated cert `Secret`. When `webhooksServer.tls.selfSignedCert` is `false`, a cert `Secret` with this name **must** be provided in the same namespace as Kargo. There is no provision for running the webhooks server without TLS because the Kubernetes API server will not communicate with non TLS-endpoints.
1270
secretName: kargo-webhooks-server-cert
1271
## @param webhooksServer.tls.caBundle PEM-encoded TLS certificates for certificate authorities to trust when `webhooksServer.tls.selfSignedCert` is `false`. If the cert has been signed by an authority already trusted by the Kubernetes API server, this setting can be ignored.
1272
caBundle: ""
1273
# caBundle: |
1274
# -----BEGIN CERTIFICATE-----
1275
# ...
1276
# -----END CERTIFICATE-----
1277
## @param extraObjects An array describing additional, arbitrary Kubernetes resources to include when rendering this chart. Items in the array may be YAML objects or strings. Either may be templated. Templates will be evaluated against the same set of values as the rest of the chart.
1278
extraObjects: []
1279
# - apiVersion: v1
1280
# kind: ConfigMap
1281
# metadata:
1282
# name: custom-cm-1
1283
# data:
1284
# host: '{{ .Values.api.host }}'
1285
# - |
1286
# apiVersion: v1
1287
# kind: ConfigMap
1288
# metadata:
1289
# name: custom-cm-2
1290
# data:
1291
# host: {{ .Values.api.host }}
1292

The trusted source for open source

Talk to an expert
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsChainguard OS PackagesChainguard ActionsChainguard Agent SkillsIntegrationsPricing
© 2026 Chainguard, Inc. All Rights Reserved.
Chainguard® and the Chainguard logo are registered trademarks of Chainguard, Inc. in the United States and/or other countries.
The other respective trademarks mentioned on this page are owned by the respective companies and use of them does not imply any affiliation or endorsement.