DirectorySecurity AdvisoriesPricing
Sign in
Directory
kates logoHELM

kates

Helm chart
Last changed
Request a free trial

Contact our team to test out this Helm chart and related images for free. Please also indicate any other images you would like to evaluate.

Overview
Chart tags
Default values
Chart metadata
Images

Tag:
Compare:

1
# -- Global configuration
2
global:
3
# -- Override the image registry for all images in the chart
4
# Useful for air-gapped clusters that mirror images to an internal registry
5
imageRegistry: ""
6
# -- Override image pull secrets globally
7
imagePullSecrets: []
8
# -- Kubernetes cluster DNS domain
9
clusterDomain: "cluster.local"
10
# -- Enable production guard rails: template rendering fails if insecure
11
# chart defaults (e.g. the default database password) would reach the
12
# cluster. Enabled in values-prod.yaml; leave false for dev/kind.
13
productionMode: false
14
# -- Number of KATES replicas
15
replicaCount: 1
16
# -- Container image configuration
17
image:
18
# -- Image repository
19
repository: chainreg.biz/chainguard-private/kates-fips
20
# -- Image tag. Must be the release that carries the non-blocking health
21
# endpoints the probe defaults below depend on (>= 1.22.0).
22
tag: 1.24.0-r1@sha256:c690097b5bc51234a5e3184847038e6bb18ca283d47815a1da1af5022bf93446
23
# -- Image pull policy
24
pullPolicy: IfNotPresent
25
# -- Secrets for pulling images from private registries
26
imagePullSecrets: []
27
# -- Override the chart name
28
nameOverride: ""
29
# -- Override the full release name
30
fullnameOverride: ""
31
# -- DNS policy for pods (ClusterFirst, Default, None, ClusterFirstWithHostNet)
32
dnsPolicy: ""
33
# -- Custom DNS configuration (nameservers, searches, options)
34
dnsConfig: {}
35
# -- Service account configuration
36
serviceAccount:
37
# -- Create a ServiceAccount
38
create: true
39
# -- ServiceAccount name (auto-generated if empty)
40
name: ""
41
# -- Extra annotations for the ServiceAccount
42
annotations: {}
43
# -- Automount the service account token
44
automount: true
45
# -- RBAC configuration
46
rbac:
47
# -- Create ClusterRole and ClusterRoleBinding
48
create: true
49
# -- Grant the writes the direct Kubernetes chaos backend makes itself
50
# (KATES_CHAOS_PROVIDER=kubernetes, or hybrid without Litmus): NetworkPolicies,
51
# StatefulSet scaling, and pod ephemeral containers. Litmus runs its
52
# experiments as litmus-admin and needs none of this.
53
directChaos: false
54
# -- Extra RBAC rules (e.g. for Litmus Chaos integration)
55
extraRules: []
56
# -- Extra annotations to add to pods
57
podAnnotations: {}
58
# -- Extra labels to add to pods
59
podLabels: {}
60
# -- Kubernetes Service configuration
61
service:
62
# -- Service type
63
type: ClusterIP
64
# -- HTTP service port
65
port: 8080
66
# -- NodePort value (only when type=NodePort)
67
nodePort: ""
68
# -- Application protocol hint for service mesh
69
appProtocol: http
70
# -- Extra annotations for the Service
71
annotations: {}
72
# -- gRPC port configuration
73
grpc:
74
# -- gRPC container/service port
75
port: 9000
76
# -- gRPC NodePort value (only when type=NodePort)
77
nodePort: ""
78
# -- Ingress configuration
79
ingress:
80
# -- Enable Ingress
81
enabled: false
82
# -- Ingress class name (e.g. nginx)
83
className: ""
84
# -- Extra Ingress annotations
85
annotations: {}
86
# -- cert-manager integration
87
certManager:
88
# -- Enable cert-manager annotations
89
enabled: false
90
# -- Issuer or ClusterIssuer name
91
issuerName: ""
92
# -- Issuer kind (ClusterIssuer or Issuer)
93
issuerKind: ClusterIssuer
94
# -- Ingress hosts
95
hosts:
96
- host: kates.local
97
paths:
98
- path: /
99
pathType: Prefix
100
# -- TLS configuration
101
tls: []
102
# -- gRPC Ingress (separate Ingress resource for gRPC traffic)
103
grpc:
104
# -- Enable gRPC Ingress
105
enabled: false
106
# -- gRPC Ingress hostname
107
host: grpc.kates.local
108
# -- Extra gRPC Ingress annotations
109
annotations: {}
110
# -- gRPC TLS configuration
111
tls: []
112
# -- Resource requests and limits for the KATES container
113
resources:
114
requests:
115
memory: "2Gi"
116
cpu: "500m"
117
limits:
118
memory: "4Gi"
119
cpu: "2"
120
# -- Flyway schema migration behaviour
121
flyway:
122
# -- Repair the schema history on startup before migrating.
123
#
124
# DEVELOPMENT ONLY. It fixes "Migration checksum mismatch", which happens when
125
# an unreleased migration is edited after a local database already applied it.
126
# On a real database that mismatch means the file and the schema genuinely
127
# disagree, and silently rewriting the history hides it — so this stays off by
128
# default and is enabled in the local overlays.
129
repairAtStart: false
130
# -- Container args, replacing the image's CMD. Empty means "use the image's
131
# own default". The native image sets its heap percentage through CMD, since a
132
# native binary ignores JAVA_TOOL_OPTIONS; override it here rather than
133
# rebuilding the image.
134
containerArgs: []
135
# -- JVM configuration
136
#
137
# JVM IMAGE ONLY. A GraalVM native image does not read JAVA_TOOL_OPTIONS, so
138
# everything here is silently ignored when running a `-native` tag — see
139
# values-native.yaml, which empties it for that reason.
140
jvm:
141
# -- JVM options passed via JAVA_TOOL_OPTIONS (ignored by the native image)
142
options: "-Xms512m -Xmx2560m -XX:+UseZGC -XX:+ZGenerational"
143
# -- Pod-level security context (PSS restricted compliant)
144
# NOTE: runAsUser and fsGroup are intentionally unset so that platforms
145
# like OpenShift can assign random UIDs via their Security Context Constraints.
146
# Set them explicitly in your environment values file if needed.
147
securityContext:
148
runAsNonRoot: true
149
runAsUser: 100
150
fsGroup: 100
151
seccompProfile:
152
type: RuntimeDefault
153
# -- Container-level security context (PSS restricted compliant)
154
containerSecurityContext:
155
allowPrivilegeEscalation: false
156
readOnlyRootFilesystem: true
157
runAsNonRoot: true
158
capabilities:
159
drop:
160
- ALL
161
# -- Grace period for pod termination (seconds)
162
terminationGracePeriodSeconds: 60
163
# -- Deployment update strategy
164
strategy:
165
type: RollingUpdate
166
rollingUpdate:
167
maxSurge: 1
168
maxUnavailable: 0
169
# -- Horizontal Pod Autoscaler configuration
170
autoscaling:
171
# -- Enable HPA
172
enabled: false
173
# -- Minimum replicas
174
minReplicas: 1
175
# -- Maximum replicas
176
maxReplicas: 5
177
# -- Target CPU utilization percentage
178
targetCPUUtilizationPercentage: 80
179
# -- Target memory utilization percentage (empty to disable)
180
targetMemoryUtilizationPercentage: ""
181
# -- Custom metrics for HPA
182
customMetrics: []
183
# -- Scale behavior policies
184
behavior:
185
scaleDown:
186
stabilizationWindowSeconds: 300
187
policies:
188
- type: Pods
189
value: 1
190
periodSeconds: 60
191
scaleUp:
192
stabilizationWindowSeconds: 30
193
policies:
194
- type: Pods
195
value: 2
196
periodSeconds: 60
197
# -- Pod Disruption Budget configuration
198
podDisruptionBudget:
199
# -- Enable PDB
200
enabled: false
201
# -- Minimum available pods (overrides maxUnavailable)
202
minAvailable: ""
203
# -- Maximum unavailable pods
204
maxUnavailable: 1
205
# -- Unhealthy pod eviction policy
206
unhealthyPodEvictionPolicy: IfHealthy
207
# -- Priority class name for pod scheduling
208
priorityClassName: ""
209
# -- Topology spread constraints for pod scheduling
210
topologySpreadConstraints: []
211
# -- Node selector for pod scheduling
212
nodeSelector: {}
213
# -- Tolerations for pod scheduling
214
tolerations: []
215
# -- Affinity rules (includes default pod anti-affinity for HA)
216
affinity:
217
podAntiAffinity:
218
preferredDuringSchedulingIgnoredDuringExecution:
219
- weight: 100
220
podAffinityTerm:
221
labelSelector:
222
matchExpressions:
223
- key: app.kubernetes.io/name
224
operator: In
225
values:
226
- kates
227
topologyKey: kubernetes.io/hostname
228
# -- Extra environment variables for the KATES container
229
extraEnv: []
230
# -- Extra init containers (e.g. for Vault secret fetching, schema migration)
231
extraInitContainers: []
232
# -- Extra volumes
233
extraVolumes: []
234
# -- Extra volume mounts
235
extraVolumeMounts: []
236
# -- API key authentication
237
apiKey:
238
# -- Enable API key authentication
239
enabled: true
240
# -- API key value (auto-generated 32-char key if empty)
241
value: ""
242
# -- Use an existing Secret instead of creating one
243
existingSecret: ""
244
# -- Key in the existing Secret
245
secretKey: "api-key"
246
# -- Health probe configuration
247
#
248
# Every probe points at a MicroProfile health endpoint, never at a business
249
# endpoint. `/api/health` looks like the obvious readiness URL but calls
250
# ClusterHealthService.isReachable() — an uncached AdminClient round-trip with a
251
# 5s blocking get — on every request. Since a probe's timeoutSeconds defaults to
252
# 1s, a cluster whose Kafka is still coming up fails EVERY readiness probe and
253
# the pod never goes Ready, even though the app is fine. `/q/health/ready` reads
254
# the periodically-refreshed KafkaReachabilityCache instead and never blocks on a
255
# broker.
256
probes:
257
# -- Startup probe (gates readiness/liveness probes)
258
startup:
259
path: /q/health/started
260
# 60 x 2s = 120s of JVM boot budget. 30 (60s) is not enough on a
261
# CPU-constrained node: the kubelet kills the container mid-boot and the
262
# restart loop reads as "kates takes forever to start".
263
failureThreshold: 60
264
periodSeconds: 2
265
timeoutSeconds: 3
266
# -- Readiness probe
267
readiness:
268
path: /q/health/ready
269
initialDelaySeconds: 5
270
periodSeconds: 10
271
timeoutSeconds: 5
272
failureThreshold: 3
273
# -- Liveness probe
274
liveness:
275
path: /q/health/live
276
initialDelaySeconds: 15
277
periodSeconds: 30
278
timeoutSeconds: 5
279
failureThreshold: 3
280
# -- Container lifecycle hooks
281
lifecycle:
282
# -- Seconds to sleep in preStop hook (allows LB drain)
283
preStopSleepSeconds: 5
284
# -- Init container configuration
285
initContainers:
286
# -- Busybox image for wait-for-postgres init container
287
waitForPostgres:
288
image: chainreg.biz/chainguard-private/netcat:1.238-r1@sha256:b961470bd7a9a1ece5f8bf51b2accd244cebc7a83767ab08da80821e403eb140
289
pullPolicy: IfNotPresent
290
# -- Kafka connection configuration
291
kafka:
292
# -- Kafka bootstrap servers
293
bootstrapServers: "krafter-kafka-bootstrap.kafka.svc:9092"
294
# -- Namespace where CDC integration test KafkaTopic CRs are managed (empty = auto-detect)
295
topicNamespace: ""
296
# -- Client rack ID for rack-aware consumption
297
clientRack: ""
298
# -- Security protocol
299
security:
300
protocol: SASL_PLAINTEXT
301
# -- SASL authentication
302
sasl:
303
# -- Enable SASL
304
enabled: true
305
# -- SASL mechanism
306
mechanism: SCRAM-SHA-512
307
# -- SASL username
308
username: kates-backend
309
# -- K8s Secret name containing the SASL password
310
secretName: kates-backend
311
# -- Key in the Secret containing the SASL password
312
secretKey: password
313
# -- OAuthBearer configuration (when mechanism=OAUTHBEARER)
314
oauthbearer:
315
tokenEndpointUrl: ""
316
clientId: ""
317
clientSecretName: ""
318
clientSecretKey: client-secret
319
# -- SSL/TLS configuration
320
ssl:
321
# -- Enable SSL
322
enabled: false
323
# -- Truststore configuration
324
truststore:
325
secretName: ""
326
key: truststore.jks
327
password: ""
328
# -- Keystore configuration
329
keystore:
330
secretName: ""
331
key: keystore.jks
332
password: ""
333
# -- Trogdor coordinator configuration
334
trogdor:
335
# -- Trogdor coordinator URL
336
coordinatorUrl: "http://trogdor-coordinator.kafka.svc:8889"
337
# -- Trogdor agents that run tasks (KATES_TROGDOR_AGENT_NODES): node names
338
# from the coordinator's platform config, comma-separated; a run's tasks take
339
# them in turn. node0 is the name in the trogdor.conf Kafka ships. A name the
340
# coordinator does not know fails the task with "Unknown node names".
341
agentNodes: "node0"
342
# -- Prometheus the backend queries for a disruption's Kafka metrics
343
prometheus:
344
# -- Prometheus base URL (KATES_PROMETHEUS_URL). The default is the Service
345
# kube-prometheus-stack creates for charts/monitoring installed as release
346
# `monitoring` in namespace `monitoring`, which is what `kates deploy` does
347
# (it sets this for the namespace it uses). `make monitoring` installs that
348
# release in namespace `kafka`: set
349
# http://monitoring-kube-prometheus-prometheus.kafka.svc:9090 there, and
350
# networkPolicy.prometheus.namespace to kafka. Unreachable, a disruption's
351
# Prometheus metrics are missing and its SLA verdict lists them unevaluated.
352
url: "http://monitoring-kube-prometheus-prometheus.monitoring.svc:9090"
353
# -- Benchmark engine configuration
354
engine:
355
# -- Default benchmark backend (native or trogdor)
356
defaultBackend: "native"
357
# -- Fault tolerance timeout configuration (ms)
358
faultTolerance:
359
topicService:
360
# -- Timeout for all TopicService operations
361
timeoutMs: "35000"
362
clusterHealthService:
363
# -- Default timeout for cluster health operations
364
defaultTimeoutMs: "35000"
365
# -- Timeout for reachability check
366
reachableTimeoutMs: "10000"
367
# -- Timeout for full health check
368
healthCheckTimeoutMs: "60000"
369
consumerGroupService:
370
# -- Timeout for consumer group operations
371
timeoutMs: "35000"
372
# -- NetworkPolicy configuration
373
networkPolicy:
374
# -- Enable NetworkPolicy
375
enabled: true
376
# -- Ingress rules
377
ingressRules:
378
- from:
379
- namespaceSelector: {}
380
ports:
381
- port: 8080
382
protocol: TCP
383
- from:
384
- namespaceSelector: {}
385
ports:
386
- port: 8080
387
protocol: TCP
388
# -- Kafka egress configuration
389
kafka:
390
namespace: kafka
391
port: 9092
392
# -- Prometheus egress configuration: the namespace prometheus.url points
393
# into. The policy used to allow `monitoring` whatever this said.
394
prometheus:
395
namespace: monitoring
396
port: 9090
397
# -- Extra egress rules
398
egressRules: []
399
# -- Observability and monitoring
400
metrics:
401
# -- Prometheus ServiceMonitor
402
serviceMonitor:
403
# -- Enable ServiceMonitor
404
enabled: false
405
# -- Target namespace for the ServiceMonitor
406
namespace: ""
407
# -- Scrape interval
408
interval: "30s"
409
# -- Scrape timeout
410
scrapeTimeout: ""
411
# -- Extra labels for ServiceMonitor
412
labels: {}
413
# -- Metric relabeling rules
414
metricRelabelings: []
415
# -- Relabeling rules
416
relabelings: []
417
# -- PrometheusRule for alerting
418
prometheusRule:
419
# -- Enable PrometheusRule
420
enabled: false
421
# -- Target namespace for the PrometheusRule
422
namespace: ""
423
# -- Extra labels
424
labels: {}
425
# -- Alert rules
426
rules:
427
- alert: KatesDown
428
expr: up{job="{{ include \"kates.fullname\" . }}"} == 0
429
for: 5m
430
labels:
431
severity: critical
432
annotations:
433
summary: "KATES instance is down"
434
description: "KATES pod {{ $labels.pod }} has been down for more than 5 minutes."
435
- alert: KatesHighErrorRate
436
expr: rate(http_server_requests_seconds_count{job="{{ include \"kates.fullname\" . }}", status=~"5.."}[5m]) > 0.1
437
for: 5m
438
labels:
439
severity: warning
440
annotations:
441
summary: "KATES high error rate"
442
description: "KATES is returning more than 10% 5xx responses."
443
# -- GONE in 0.9.0: the "KATES — Overview" board (dashboards/kates-overview/)
444
# is delivered by charts/monitoring with every other board in dashboards/
445
# (its `dashboards.enabled`), scoped to a release by its `$job` template
446
# variable. A release that still sets any `metrics.grafanaDashboard.*` key
447
# is REFUSED with the new location named (this chart has no values schema,
448
# so without the refusal the key would be accepted and silently ignored).
449
# -- Bundled PostgreSQL configuration.
450
# A self-contained single-instance StatefulSet on the official `postgres`
451
# image (no Bitnami). For production HA, set enabled=false and point
452
# externalDatabase at a managed cluster (CloudNativePG recommended).
453
postgresql:
454
# -- Deploy bundled PostgreSQL
455
enabled: true
456
# -- PostgreSQL image (official library image; Alpine variants also work)
457
image:
458
repository: chainreg.biz/chainguard-private/postgres-fips
459
tag: 16.15-r5@sha256:720d154c20c41279f2872ee0e158fc60d9a11fecd6d4ac793f3e1e49b0022f08
460
# -- Database authentication
461
auth:
462
# -- Database name
463
database: kates
464
# -- Database username
465
username: kates
466
# -- Database password (ignored if existingSecret is set)
467
password: kates
468
# -- Use an existing Secret for DB credentials
469
existingSecret: ""
470
# -- Key in the existing Secret
471
passwordKey: "password"
472
# -- Node selector for the embedded PostgreSQL pod (dev/test only)
473
nodeSelector: {}
474
# -- Tolerations for the embedded PostgreSQL pod
475
tolerations: []
476
# -- Affinity rules for the embedded PostgreSQL pod
477
affinity: {}
478
# -- PVC storage configuration
479
storage:
480
# -- Storage size
481
size: 1Gi
482
# -- Storage class (empty for default)
483
storageClass: ""
484
# -- PostgreSQL resource requests and limits
485
resources:
486
requests:
487
memory: "128Mi"
488
cpu: "100m"
489
limits:
490
memory: "256Mi"
491
cpu: "250m"
492
# -- PostgreSQL pod security context
493
securityContext:
494
runAsNonRoot: true
495
runAsUser: 999
496
fsGroup: 999
497
# -- PostgreSQL container security context
498
containerSecurityContext:
499
allowPrivilegeEscalation: false
500
capabilities:
501
drop:
502
- ALL
503
# -- JDBC connection pool settings
504
connectionPool:
505
# -- Maximum pool size
506
maxSize: "20"
507
# -- Minimum pool size
508
minSize: "5"
509
# -- External database configuration (when postgresql.enabled=false).
510
# Recommended for production HA: run a CloudNativePG `Cluster` (official
511
# postgres images, streaming replication, backups) and point host/port at its
512
# `-rw` service, e.g. host: kates-db-rw.database.svc — no Bitnami involved.
513
externalDatabase:
514
# -- Enable external database
515
enabled: false
516
# -- Database host
517
host: ""
518
# -- Database port
519
port: 5432
520
# -- Database name
521
database: kates
522
# -- Database username
523
username: kates
524
# -- Database password (ignored if existingSecret is set)
525
password: ""
526
# -- Use an existing Secret for DB credentials
527
existingSecret: ""
528
# -- Key in the existing Secret
529
passwordKey: "password"
530
# -- Default benchmark parameters (fallback for all test types)
531
defaults:
532
replicationFactor: "3"
533
partitions: "3"
534
minInsyncReplicas: "2"
535
acks: "all"
536
batchSize: "65536"
537
lingerMs: "5"
538
compressionType: "lz4"
539
recordSize: "1024"
540
numRecords: "1000000"
541
throughput: "-1"
542
durationMs: "600000"
543
numProducers: "1"
544
numConsumers: "1"
545
# -- Per-test-type parameter overrides
546
tests:
547
# -- LOAD: baseline throughput test
548
load:
549
partitions: "3"
550
batchSize: "65536"
551
lingerMs: "5"
552
numRecords: "1000000"
553
durationMs: "600000"
554
numProducers: "1"
555
# -- STRESS: high-concurrency, large batches
556
stress:
557
partitions: "6"
558
batchSize: "131072"
559
lingerMs: "10"
560
numRecords: "5000000"
561
durationMs: "900000"
562
numProducers: "3"
563
# -- SPIKE: burst traffic, low-latency
564
spike:
565
acks: "1"
566
batchSize: "131072"
567
lingerMs: "0"
568
compressionType: "none"
569
numRecords: "2000000"
570
durationMs: "300000"
571
# -- ENDURANCE: long-running, rate-limited
572
endurance:
573
numRecords: "10000000"
574
throughput: "5000"
575
durationMs: "3600000"
576
# -- VOLUME: large records, high batch size
577
volume:
578
partitions: "6"
579
batchSize: "262144"
580
lingerMs: "50"
581
recordSize: "10240"
582
numRecords: "2000000"
583
# -- CAPACITY: max parallelism
584
capacity:
585
partitions: "12"
586
batchSize: "131072"
587
lingerMs: "10"
588
numRecords: "10000000"
589
durationMs: "1200000"
590
numProducers: "5"
591
# -- ROUNDTRIP: latency-focused
592
roundtrip:
593
batchSize: "16384"
594
lingerMs: "0"
595
compressionType: "none"
596
numRecords: "500000"
597
throughput: "10000"
598
# -- PostgreSQL backup CronJob
599
backup:
600
# -- Enable backup CronJob
601
enabled: false
602
# -- Cron schedule expression
603
schedule: "0 2 * * *"
604
# -- PostgreSQL image for pg_dump
605
image: chainreg.biz/chainguard-private/postgres-fips:16.15-r5@sha256:720d154c20c41279f2872ee0e158fc60d9a11fecd6d4ac793f3e1e49b0022f08
606
# -- Days to retain backups
607
retention: 7
608
# -- Backup persistence
609
persistence:
610
enabled: false
611
existingClaim: ""
612
storageClass: ""
613
size: 5Gi
614
# -- Backup job resources
615
resources:
616
requests:
617
memory: "64Mi"
618
cpu: "50m"
619
limits:
620
memory: "256Mi"
621
cpu: "250m"
622
# -- Pre-upgrade Flyway migration Job
623
migration:
624
# -- Enable migration Job (runs as pre-upgrade Helm hook)
625
enabled: false
626
# -- Override image (defaults to KATES app image)
627
image: chainreg.biz/chainguard-private/kates-fips:1.24.0-r1@sha256:c690097b5bc51234a5e3184847038e6bb18ca283d47815a1da1af5022bf93446
628
# -- Custom command (overrides default Flyway migration)
629
command: []
630
# -- Maximum retry attempts
631
backoffLimit: 3
632
# -- Maximum Job duration (seconds)
633
activeDeadlineSeconds: 600
634
# -- Migration job resources
635
resources:
636
requests:
637
memory: "256Mi"
638
cpu: "100m"
639
limits:
640
memory: "512Mi"
641
cpu: "500m"
642
# -- Stale test run cleanup CronJob
643
cleanup:
644
# -- Enable cleanup CronJob
645
enabled: false
646
# -- Cron schedule expression
647
schedule: "0 4 * * 0"
648
# -- Delete completed test runs older than N days
649
retentionDays: 30
650
# -- Curl image for API calls
651
image: chainreg.biz/chainguard-private/min-toolkit-debug-fips:latest@sha256:76f732b60df11113cc47422ea95d65543229da16b6e23f5f8d551f8bb0c3ccce
652
# -- Kyverno pod security policies (requires Kyverno controller in cluster)
653
kyvernoPolicy:
654
# -- Enable Kyverno ClusterPolicy for the kates namespace
655
enabled: false
656
# -- Policy action: Audit (observe only) or Enforce (block non-compliant)
657
action: Audit
658
# -- Enable mutation rules to auto-inject security contexts
659
mutate: true
660
# -- Enable image registry restriction
661
restrictRegistries: false
662
# -- Allowed image registries (when restrictRegistries is true)
663
allowedRegistries:
664
- ghcr.io/bmscomp/
665
- docker.io/bitnami/
666
- registry.k8s.io/
667
- quay.io/strimzi/
668
- curlimages/
669
# -- GONE in 0.9.0: the Kyverno board (dashboards/kyverno-security/) is
670
# delivered by charts/monitoring with every other board in dashboards/ (its
671
# `dashboards.enabled`) — one Kyverno per cluster, one board, and it belongs
672
# where the rest of the cluster's boards live. `grafanaDashboard` (both the
673
# bool and the map shape) and `grafanaDashboardNamespace` are REFUSED if
674
# set, with the new location named.
675
# -- Cosign image signature verification
676
cosign:
677
# -- Enable image signature verification via Cosign
678
enabled: false
679
# -- Image patterns requiring valid signatures
680
imagePatterns:
681
- "ghcr.io/bmscomp/*"
682
# -- Cosign public key (PEM format) — set via --set-file or Secrets
683
publicKey: ""
684
# -- Auto-generate default-deny NetworkPolicies for new namespaces
685
networkPolicyGeneration:
686
enabled: false
687
# -- Namespaces to exclude from default-deny generation
688
excludeNamespaces:
689
- kube-system
690
- kube-public
691
- kube-node-lease
692
- kyverno
693
- strimzi-operator
694
- monitoring
695
- kafka
696
- cert-manager
697
- litmus
698
- "kates-detect-*"
699
# -- PolicyExceptions for dev/test namespaces
700
policyExceptions:
701
# -- Enable PolicyException resources
702
enabled: false
703
# -- Dev namespaces where policies are relaxed
704
namespaces:
705
- kates-dev
706
- kates-staging
707
# -- Policies to create exceptions for
708
exemptPolicies:
709
- kates-pod-security-standards
710
# -- Rules to exempt in dev namespaces
711
exemptRules:
712
- validate-readonly-rootfs
713
- require-resource-limits
714
- disallow-latest-tag
715
# -- Monitoring integration
716
monitoring:
717
# -- Enable telemetry export (Jaeger)
718
enabled: true
719

The trusted source for open source

Talk to an expert
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsChainguard OS PackagesChainguard ActionsChainguard Agent SkillsIntegrationsPricing
© 2026 Chainguard, Inc. All Rights Reserved.
Chainguard® and the Chainguard logo are registered trademarks of Chainguard, Inc. in the United States and/or other countries.
The other respective trademarks mentioned on this page are owned by the respective companies and use of them does not imply any affiliation or endorsement.