DirectorySecurity AdvisoriesPricing
Sign in
Directory
kong logoHELM

kong

Helm chart
Last changed
Request a free trial

Contact our team to test out this Helm chart and related images for free. Please also indicate any other images you would like to evaluate.

Overview
Chart tags
Default values
Chart metadata
Images

Tag:
Compare:

1
# Default values for Kong's Helm Chart.
2
# Declare variables to be passed into your templates.
3
#
4
# Sections:
5
# - Deployment parameters
6
# - Kong parameters
7
# - Ingress Controller parameters
8
# - Postgres sub-chart parameters
9
# - Miscellaneous parameters
10
# - Kong Enterprise parameters
11
12
# -----------------------------------------------------------------------------
13
# Deployment parameters
14
# -----------------------------------------------------------------------------
15
16
deployment:
17
kong:
18
# Enable or disable Kong itself
19
# Setting this to false with ingressController.enabled=true will create a
20
# controller-only release.
21
enabled: true
22
# Control which predefined kong initContainers are enabled.
23
initContainers:
24
# Enable the init container which clears the stale PIDs from Kong's prefix directory.
25
clearStalePid:
26
enabled: true
27
# Image used by the clear-stale-pid init container. Defaults to the Kong image
28
# when unset.
29
image: {}
30
# repository: busybox
31
# tag: "1.36"
32
# pullPolicy: IfNotPresent
33
command:
34
- "rm"
35
- "-vrf"
36
- "$(KONG_PREFIX)/pids"
37
# The number of old `ReplicaSet`s to retain.
38
revisionHistoryLimit: 10
39
## Minimum number of seconds for which a newly created pod should be ready without any of its container crashing,
40
## for it to be considered available.
41
# minReadySeconds: 60
42
## Specify the service account to create and to be assigned to the deployment / daemonset and for the migrations
43
serviceAccount:
44
create: true
45
# Automount the service account token. By default, this is disabled, and the token is only mounted on the controller
46
# container. Some sidecars require enabling this. Note that enabling this exposes Kubernetes credentials to Kong
47
# Lua code, increasing potential attack surface.
48
automountServiceAccountToken: false
49
## Optionally specify the name of the service account to create and the annotations to add.
50
# name:
51
# annotations: {}
52
53
## Optionally specify any extra sidecar containers to be included in the deployment
54
## See https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.18/#container-v1-core
55
# sidecarContainers:
56
# - name: sidecar
57
# image: sidecar:latest
58
# initContainers:
59
# - name: initcon
60
# image: initcon:latest
61
# hostAliases:
62
# - ip: "127.0.0.1"
63
# hostnames:
64
# - "foo.local"
65
# - "bar.local"
66
67
## Define any volumes and mounts you want present in the Kong proxy container
68
# userDefinedVolumes:
69
# - name: "volumeName"
70
# emptyDir: {}
71
# userDefinedVolumeMounts:
72
# - name: "volumeName"
73
# mountPath: "/opt/user/dir/mount"
74
test:
75
# Enable creation of test resources for use with "helm test"
76
enabled: false
77
# Use a DaemonSet controller instead of a Deployment controller
78
daemonset: false
79
hostNetwork: false
80
# Set the Deployment's spec.template.hostname field.
81
# This propagates to Kong API endpoints that report
82
# the hostname, such as the admin API root and hybrid mode
83
# /clustering/data-planes endpoint
84
hostname: ""
85
# kong_prefix empty dir size
86
prefixDir:
87
sizeLimit: 256Mi
88
# tmp empty dir size
89
tmpDir:
90
sizeLimit: 1Gi
91
# Override namepsace for Kong chart resources. By default, the chart creates resources in the release namespace.
92
# This may not be desirable when using this chart as a dependency.
93
# namespace: "example"
94
95
# -----------------------------------------------------------------------------
96
# Kong parameters
97
# -----------------------------------------------------------------------------
98
99
# Specify Kong configuration
100
# This chart takes all entries defined under `.env` and transforms them into into `KONG_*`
101
# environment variables for Kong containers.
102
# Their names here should match the names used in https://github.com/Kong/kong/blob/master/kong.conf.default
103
# See https://docs.konghq.com/latest/configuration also for additional details
104
# Values here take precedence over values from other sections of values.yaml,
105
# e.g. setting pg_user here will override the value normally set when postgresql.enabled
106
# is set below. In general, you should not set values here if they are set elsewhere.
107
env:
108
database: "off"
109
# the chart uses the traditional router (for Kong 3.x+) because the ingress
110
# controller generates traditional routes. if you do not use the controller,
111
# you may set this to "traditional_compatible" or "expressions" to use the new
112
# DSL-based router
113
router_flavor: "traditional"
114
nginx_worker_processes: "2"
115
proxy_access_log: /dev/stdout
116
admin_access_log: /dev/stdout
117
admin_gui_access_log: /dev/stdout
118
portal_api_access_log: /dev/stdout
119
proxy_error_log: /dev/stderr
120
admin_error_log: /dev/stderr
121
admin_gui_error_log: /dev/stderr
122
portal_api_error_log: /dev/stderr
123
prefix: /kong_prefix/
124
# This section is any customer specific environments variables that doesn't require KONG_ prefix.
125
# These custom environment variables are typicall used in custom plugins or serverless plugins to
126
# access environment specific credentials or tokens.
127
# Example as below, uncomment if required and add additional attributes as required.
128
# Note that these environment variables will only apply to the proxy and init container. The ingress-controller
129
# container has its own customEnv section.
130
131
# customEnv:
132
# api_token:
133
# valueFrom:
134
# secretKeyRef:
135
# key: token
136
# name: api_key
137
# client_name: testClient
138
139
# Load all ConfigMap or Secret keys as environment variables:
140
# https://kubernetes.io/docs/tasks/configure-pod-container/configure-pod-configmap/#configure-all-key-value-pairs-in-a-configmap-as-container-environment-variables
141
envFrom: []
142
# This section can be used to configure some extra labels that will be added to each Kubernetes object generated.
143
extraLabels: {}
144
# Specify Kong's Docker image and repository details here
145
image:
146
repository: chainreg.biz/chainguard-private/kong
147
tag: 3.9.3-r7@sha256:43b61b1753058b40a625437ba0a0f2631b8cfb236c95f9fce72bd62a50eab539
148
# Kong Enterprise
149
# repository: kong/kong-gateway
150
# tag: "3.9"
151
152
# Specify a semver version if your image tag is not one (e.g. "nightly")
153
effectiveSemver:
154
pullPolicy: IfNotPresent
155
## Optionally specify an array of imagePullSecrets.
156
## Secrets must be manually created in the namespace.
157
## ref: https://kubernetes.io/docs/tasks/configure-pod-container/pull-image-private-registry/
158
##
159
# pullSecrets:
160
# - myRegistrKeySecretName
161
# Specify Kong admin API service and listener configuration
162
admin:
163
# Enable creating a Kubernetes service for the admin API
164
# Disabling this is recommended for most ingress controller configurations
165
# Enterprise users that wish to use Kong Manager with the controller should enable this
166
enabled: false
167
type: NodePort
168
loadBalancerClass:
169
ipFamilyPolicy:
170
ipFamilies: []
171
trafficDistribution:
172
# To specify annotations or labels for the admin service, add them to the respective
173
# "annotations" or "labels" dictionaries below.
174
annotations: {}
175
# service.beta.kubernetes.io/aws-load-balancer-proxy-protocol: "*"
176
labels: {}
177
http:
178
# Enable plaintext HTTP listen for the admin API
179
# Disabling this and using a TLS listen only is recommended for most configuration
180
enabled: false
181
servicePort: 8001
182
containerPort: 8001
183
# Set a nodePort which is available if service type is NodePort
184
# nodePort: 32080
185
# Additional listen parameters, e.g. "reuseport", "backlog=16384"
186
parameters: []
187
tls:
188
# Enable HTTPS listen for the admin API
189
enabled: true
190
servicePort: 8444
191
containerPort: 8444
192
# Set a target port for the TLS port in the admin API service, useful when using TLS
193
# termination on an ELB.
194
# overrideServiceTargetPort: 8000
195
# Set a nodePort which is available if service type is NodePort
196
# nodePort: 32443
197
# Additional listen parameters, e.g. "reuseport", "backlog=16384"
198
parameters:
199
- http2
200
# Specify the CA certificate to use for TLS verification of the Admin API client by:
201
# - secretName - the secret must contain a key named "tls.crt" with the PEM-encoded certificate.
202
# - caBundle (PEM-encoded certificate string).
203
# If both are set, caBundle takes precedence.
204
client:
205
caBundle: ""
206
secretName: ""
207
# Kong admin ingress settings. Useful if you want to expose the Admin
208
# API of Kong outside the k8s cluster.
209
ingress:
210
# Enable/disable exposure using ingress.
211
enabled: false
212
ingressClassName:
213
# TLS secret name.
214
# tls: kong-admin.example.com-tls
215
# Ingress hostname
216
hostname:
217
# Map of ingress annotations.
218
annotations: {}
219
# Ingress path.
220
path: /
221
# Each path in an Ingress is required to have a corresponding path type. (ImplementationSpecific/Exact/Prefix)
222
pathType: ImplementationSpecific
223
# Specify Kong status listener configuration
224
# This listen is internal-only. It cannot be exposed through a service or ingress.
225
status:
226
enabled: true
227
http:
228
# Enable plaintext HTTP listen for the status listen
229
enabled: true
230
containerPort: 8100
231
parameters: []
232
tls:
233
# Enable HTTPS listen for the status listen
234
# Kong versions prior to 2.1 do not support TLS status listens.
235
# This setting must remain false on those versions
236
enabled: false
237
containerPort: 8543
238
parameters: []
239
# Name the kong hybrid cluster CA certificate secret
240
clusterCaSecretName: ""
241
# Specify Kong cluster service and listener configuration
242
#
243
# The cluster service *must* use TLS. It does not support the "http" block
244
# available on other services.
245
#
246
# The cluster service cannot be exposed through an Ingress, as it must perform
247
# TLS client validation directly and is not compatible with TLS-terminating
248
# proxies. If you need to expose it externally, you must use "type:
249
# LoadBalancer" and use a TCP-only load balancer (check your Kubernetes
250
# provider's documentation, as the configuration required for this varies).
251
cluster:
252
enabled: false
253
# To specify annotations or labels for the cluster service, add them to the respective
254
# "annotations" or "labels" dictionaries below.
255
annotations: {}
256
# service.beta.kubernetes.io/aws-load-balancer-proxy-protocol: "*"
257
labels: {}
258
tls:
259
enabled: false
260
servicePort: 8005
261
containerPort: 8005
262
parameters: []
263
type: ClusterIP
264
loadBalancerClass:
265
ipFamilyPolicy:
266
ipFamilies: []
267
trafficDistribution:
268
# Kong cluster ingress settings. Useful if you want to split CP and DP
269
# in different clusters.
270
ingress:
271
# Enable/disable exposure using ingress.
272
enabled: false
273
ingressClassName:
274
# TLS secret name.
275
# tls: kong-cluster.example.com-tls
276
# Ingress hostname
277
hostname:
278
# Map of ingress annotations.
279
annotations: {}
280
# Ingress path.
281
path: /
282
# Each path in an Ingress is required to have a corresponding path type. (ImplementationSpecific/Exact/Prefix)
283
pathType: ImplementationSpecific
284
# Specify Kong proxy service configuration
285
proxy:
286
# Enable creating a Kubernetes service for the proxy
287
enabled: true
288
type: LoadBalancer
289
loadBalancerClass: ""
290
ipFamilyPolicy:
291
ipFamilies: []
292
trafficDistribution:
293
# Configures optional firewall rules and in the VPC network to only allow certain source ranges.
294
loadBalancerSourceRanges: []
295
# Override proxy Service name
296
nameOverride: ""
297
# To specify annotations or labels for the proxy service, add them to the respective
298
# "annotations" or "labels" dictionaries below.
299
annotations: {}
300
# If terminating TLS at the ELB, the following annotations can be used
301
# "service.beta.kubernetes.io/aws-load-balancer-backend-protocol": "*",
302
# "service.beta.kubernetes.io/aws-load-balancer-cross-zone-load-balancing-enabled": "true",
303
# "service.beta.kubernetes.io/aws-load-balancer-ssl-cert": "arn:aws:acm:REGION:ACCOUNT:certificate/XXXXXX-XXXXXXX-XXXXXXX-XXXXXXXX",
304
# "service.beta.kubernetes.io/aws-load-balancer-ssl-ports": "kong-proxy-tls",
305
# "service.beta.kubernetes.io/aws-load-balancer-type": "elb"
306
labels:
307
enable-metrics: "true"
308
http:
309
# Enable plaintext HTTP listen for the proxy
310
enabled: true
311
# Set the servicePort: 0 to skip exposing in the service but still
312
# let the port open in container to allow https to http mapping for
313
# tls terminated at LB.
314
servicePort: 80
315
containerPort: 8000
316
# Set a nodePort which is available if service type is NodePort
317
# nodePort: 32080
318
# Additional listen parameters, e.g. "reuseport", "backlog=16384"
319
parameters: []
320
tls:
321
# Enable HTTPS listen for the proxy
322
enabled: true
323
servicePort: 443
324
containerPort: 8443
325
# Set a target port for the TLS port in proxy service
326
# overrideServiceTargetPort: 8000
327
# Set a nodePort which is available if service type is NodePort
328
# nodePort: 32443
329
# Additional listen parameters, e.g. "reuseport", "backlog=16384"
330
parameters:
331
- http2
332
# Specify the Service's TLS port's appProtocol. This can be useful when integrating with
333
# external load balancers that require the `appProtocol` field to be set (e.g. GCP).
334
appProtocol: ""
335
# Define stream (TCP) listen
336
# To enable, remove "[]", uncomment the section below, and select your desired
337
# ports and parameters. Listens are dynamically named after their containerPort,
338
# e.g. "stream-9000" for the below.
339
# Note: although you can select the protocol here, you cannot set UDP if you
340
# use a LoadBalancer Service due to limitations in current Kubernetes versions.
341
# To proxy both TCP and UDP with LoadBalancers, you must enable the udpProxy Service
342
# in the next section and place all UDP stream listen configuration under it.
343
stream: []
344
# # Set the container (internal) and service (external) ports for this listen.
345
# # These values should normally be the same. If your environment requires they
346
# # differ, note that Kong will match routes based on the containerPort only.
347
# - containerPort: 9000
348
# servicePort: 9000
349
# protocol: TCP
350
# # Optionally set a static nodePort if the service type is NodePort
351
# # nodePort: 32080
352
# # Additional listen parameters, e.g. "ssl", "reuseport", "backlog=16384"
353
# # "ssl" is required for SNI-based routes. It is not supported on versions <2.0
354
# parameters: []
355
356
# Kong proxy ingress settings.
357
# Note: You need this only if you are using another Ingress Controller
358
# to expose Kong outside the k8s cluster.
359
ingress:
360
# Enable/disable exposure using ingress.
361
enabled: false
362
ingressClassName:
363
# To specify annotations or labels for the ingress, add them to the respective
364
# "annotations" or "labels" dictionaries below.
365
annotations: {}
366
labels: {}
367
# Ingress hostname
368
hostname:
369
# Ingress path (when used with hostname above).
370
path: /
371
# Each path in an Ingress is required to have a corresponding path type (when used with hostname above). (ImplementationSpecific/Exact/Prefix)
372
pathType: ImplementationSpecific
373
# Ingress hosts. Use this instead of or in combination with hostname to specify multiple ingress host configurations
374
hosts: []
375
# - host: kong-proxy.example.com
376
# paths:
377
# # Ingress path.
378
# - path: /*
379
# # Each path in an Ingress is required to have a corresponding path type. (ImplementationSpecific/Exact/Prefix)
380
# pathType: ImplementationSpecific
381
# - host: kong-proxy-other.example.com
382
# paths:
383
# # Ingress path.
384
# - path: /other
385
# # Each path in an Ingress is required to have a corresponding path type. (ImplementationSpecific/Exact/Prefix)
386
# pathType: ImplementationSpecific
387
# backend:
388
# service:
389
# name: kong-other-proxy
390
# port:
391
# number: 80
392
#
393
# TLS secret(s)
394
# tls: kong-proxy.example.com-tls
395
# Or if multiple hosts/secrets needs to be configured:
396
# tls:
397
# - secretName: kong-proxy.example.com-tls
398
# hosts:
399
# - kong-proxy.example.com
400
# - secretName: kong-proxy-other.example.com-tls
401
# hosts:
402
# - kong-proxy-other.example.com
403
# Optionally specify a static load balancer IP.
404
# loadBalancerIP:
405
# Specify Kong UDP proxy service configuration
406
# Currently, LoadBalancer type Services are generally limited to a single transport protocol
407
# Multi-protocol Services are an alpha feature as of Kubernetes 1.20:
408
# https://kubernetes.io/docs/concepts/services-networking/service/#load-balancers-with-mixed-protocol-types
409
# You should enable this Service if you proxy UDP traffic, and configure UDP stream listens under it
410
udpProxy:
411
# Enable creating a Kubernetes service for UDP proxying
412
enabled: false
413
type: LoadBalancer
414
loadBalancerClass:
415
ipFamilyPolicy:
416
ipFamilies: []
417
trafficDistribution:
418
# To specify annotations or labels for the proxy service, add them to the respective
419
# "annotations" or "labels" dictionaries below.
420
annotations: {}
421
# service.beta.kubernetes.io/aws-load-balancer-proxy-protocol: "*"
422
labels: {}
423
# Optionally specify a static load balancer IP.
424
# loadBalancerIP:
425
426
# Define stream (UDP) listen
427
# To enable, remove "[]", uncomment the section below, and select your desired
428
# ports and parameters. Listens are dynamically named after their servicePort,
429
# e.g. "stream-9000" for the below.
430
stream: []
431
# # Set the container (internal) and service (external) ports for this listen.
432
# # These values should normally be the same. If your environment requires they
433
# # differ, note that Kong will match routes based on the containerPort only.
434
# - containerPort: 9000
435
# servicePort: 9000
436
# protocol: UDP
437
# # Optionally set a static nodePort if the service type is NodePort
438
# # nodePort: 32080
439
# # Additional listen parameters, e.g. "ssl", "reuseport", "backlog=16384"
440
# # "ssl" is required for SNI-based routes. It is not supported on versions <2.0
441
# parameters: []
442
# Custom Kong plugins can be loaded into Kong by mounting the plugin code
443
# into the file-system of Kong container.
444
# The plugin code should be present in ConfigMap or Secret inside the same
445
# namespace as Kong is being installed.
446
# The `name` property refers to the name of the ConfigMap or Secret
447
# itself, while the pluginName refers to the name of the plugin as it appears
448
# in Kong.
449
# Subdirectories (which are optional) require separate ConfigMaps/Secrets.
450
# "path" indicates their directory under the main plugin directory: the example
451
# below will mount the contents of kong-plugin-rewriter-migrations at "/opt/kong/rewriter/migrations".
452
plugins: {}
453
# configMaps:
454
# - pluginName: rewriter
455
# name: kong-plugin-rewriter
456
# subdirectories:
457
# - name: kong-plugin-rewriter-migrations
458
# path: migrations
459
# secrets:
460
# - pluginName: rewriter
461
# name: kong-plugin-rewriter
462
# If your development cycle preinstalls the plugin as part of the image, this appends them to the plugins env var
463
# preInstalled: sweet-plugin,another-sweet-plugin
464
# Inject specified secrets as a volume in Kong Container at path /etc/secrets/{secret-name}/
465
# This can be used to override default SSL certificates.
466
# Be aware that the secret name will be used verbatim, and that certain types
467
# of punctuation (e.g. `.`) can cause issues.
468
# Example configuration
469
# secretVolumes:
470
# - kong-proxy-tls
471
# - kong-admin-tls
472
secretVolumes: []
473
# Enable/disable migration jobs, and set annotations for them
474
migrations:
475
# Enable pre-upgrade migrations (run "kong migrations up")
476
preUpgrade: true
477
# Enable post-upgrade migrations (run "kong migrations finish")
478
postUpgrade: true
479
# Annotations to apply to migrations job pods
480
# By default, these disable service mesh sidecar injection for Istio and Kuma,
481
# as the sidecar containers do not terminate and prevent the jobs from completing
482
annotations:
483
sidecar.istio.io/inject: false
484
# Additional annotations to apply to migration jobs
485
# This is helpful in certain non-Helm installation situations such as GitOps
486
# where additional control is required around this job creation.
487
jobAnnotations: {}
488
# Optionally set a backoffLimit. If none is set, Jobs will use the cluster default
489
backoffLimit:
490
# Optionally set to specify the time-to-live (TTL) for a pod after it has completed its execution before automatic deletion. If left unset, pod lifetime is indefinite.
491
ttlSecondsAfterFinished:
492
resources: {}
493
# Example reasonable setting for "resources":
494
# resources:
495
# limits:
496
# cpu: 100m
497
# memory: 256Mi
498
# requests:
499
# cpu: 50m
500
# memory: 128Mi
501
## Optionally specify any extra sidecar containers to be included in the deployment
502
## See https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.18/#container-v1-core
503
## Keep in mind these containers should be terminated along with the main
504
## migration containers
505
# sidecarContainers:
506
# - name: sidecar
507
# image: sidecar:latest
508
## Optionally set securitycontext for the wait-for-postgres migrations init container
509
# waitContainer:
510
# securityContext:
511
# allowPrivilegeEscalation: false
512
# capabilities:
513
# drop:
514
# - ALL
515
# readOnlyRootFilesystem: true
516
# runAsNonRoot: true
517
# runAsUser: 1000
518
# Kong's configuration for DB-less mode
519
# Note: Use this section only if you are deploying Kong in DB-less mode
520
# and not as an Ingress Controller.
521
dblessConfig:
522
# Either Kong's configuration is managed from an existing ConfigMap (with Key: kong.yml)
523
configMap: ""
524
# Or Kong's configuration is managed from an existing Secret (with Key: kong.yml)
525
secret: ""
526
# Or the configuration is passed in full-text below
527
config: ""
528
# # _format_version: "1.1"
529
# # services:
530
# # # Example configuration
531
# # # - name: example.com
532
# # # url: http://example.com
533
# # # routes:
534
# # # - name: example
535
# # # paths:
536
# # # - "/example"
537
## Optionally specify any extra sidecar containers to be included in the
538
## migration jobs
539
## See https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.18/#container-v1-core
540
# sidecarContainers:
541
# - name: sidecar
542
# image: sidecar:latest
543
# -----------------------------------------------------------------------------
544
# Ingress Controller parameters
545
# -----------------------------------------------------------------------------
546
547
# Kong Ingress Controller's primary purpose is to satisfy Ingress resources
548
# created in k8s. It uses CRDs for more fine grained control over routing and
549
# for Kong specific configuration.
550
ingressController:
551
enabled: true
552
image:
553
repository: chainreg.biz/chainguard-private/kong-ingress-controller
554
tag: 3.5.13-r7@sha256:7e987d1452b1ab2f442fdac824f776a96a646327bfa92b61f175af9238320088
555
# Optionally set a semantic version for version-gated features. This can normally
556
# be left unset. You only need to set this if your tag is not a semver string,
557
# such as when you are using a "next" tag. Set this to the effective semantic
558
# version of your tag: for example if using a "next" image for an unreleased 3.1.0
559
# version, set this to "3.1.0".
560
effectiveSemver:
561
args: []
562
gatewayDiscovery:
563
enabled: false
564
generateAdminApiService: false
565
adminApiService:
566
namespace: ""
567
name: ""
568
# Specify individual namespaces to watch for ingress configuration. By default,
569
# when no namespaces are set, the controller watches all namespaces and uses a
570
# ClusterRole to grant access to Kubernetes resources. When you list specific
571
# namespaces, the controller will watch those namespaces only and will create
572
# namespaced-scoped Roles for each of them. The controller will still use a
573
# ClusterRole for cluster-scoped resources.
574
# Requires controller 2.0.0 or newer.
575
watchNamespaces: []
576
# Specify Kong Ingress Controller configuration via environment variables
577
env:
578
# The controller disables TLS verification by default because Kong
579
# generates self-signed certificates by default. Set this to false once you
580
# have installed CA-signed certificates.
581
kong_admin_tls_skip_verify: true
582
# If using Kong Enterprise with RBAC enabled, uncomment the section below
583
# and specify the secret/key containing your admin token.
584
# kong_admin_token:
585
# valueFrom:
586
# secretKeyRef:
587
# name: CHANGEME-admin-token-secret
588
# key: CHANGEME-admin-token-key
589
# This section is any customer specific environments variables that doesn't require CONTROLLER_ prefix.
590
# Example as below, uncomment if required and add additional attributes as required.
591
# customEnv:
592
# TZ: "Europe/Berlin"
593
594
# Load all ConfigMap or Secret keys as environment variables:
595
# https://kubernetes.io/docs/tasks/configure-pod-container/configure-pod-configmap/#configure-all-key-value-pairs-in-a-configmap-as-container-environment-variables
596
envFrom: []
597
admissionWebhook:
598
matchPolicy: Equivalent
599
enabled: true
600
# Limit the `secrets.plugins.validation.ingress-controller.konghq.com` webhook
601
# to only Secrets with the appropriate KIC "konghq.com/validate" label.
602
filterSecrets: false
603
failurePolicy: Ignore
604
port: 8080
605
certificate:
606
provided: false
607
# namespaceSelector specifies namespaces in which the resources are validated by the `*.validations.kong.konghq.com` webhooks.
608
# For example, the `kube-system` namespace contains objects created by the Kubernetes system, like `kube-dns` service.
609
# You can exclude the kube-system namespace from being intercepted using below namespaceSelector:
610
# namespaceSelector:
611
# matchExpressions:
612
# - key: kubernetes.io/metadata.name
613
# operator: NotIn
614
# values:
615
# - kube-system
616
namespaceSelector: {}
617
# objectSelector specifies label selectors applied to all admission webhooks.
618
# For the secrets webhooks (credentials and plugins), chart-required expressions
619
# (e.g. credential type filtering, konnect exclusion) are always included
620
# in addition to any expressions you specify here.
621
# This is useful for scoping webhooks per Kong instance in multi-instance clusters.
622
objectSelector:
623
matchExpressions:
624
- key: owner
625
operator: NotIn
626
values:
627
- helm
628
# Specifiy the secretName when the certificate is provided via a TLS secret
629
# secretName: ""
630
# Specifiy the CA bundle of the provided certificate.
631
# This is a PEM encoded CA bundle which will be used to validate the webhook certificate. If unspecified, system trust roots on the apiserver are used.
632
# caBundle:
633
# | Add the CA bundle content here.
634
service:
635
# Specify custom labels for the validation webhook service.
636
labels: {}
637
# Tune the default Kubernetes timeoutSeconds of 10 seconds
638
# timeoutSeconds: 10
639
ingressClass: kong
640
# Check existence and create the `IngressClass` with given name in the cluster.
641
# You can set it to `false` to disable the creation of `IngressClass` if your user to run helm does not have the permission to create `IngressClass`es.
642
createIngressClass: true
643
# annotations for IngressClass resource (Kubernetes 1.18+)
644
ingressClassAnnotations: {}
645
## Define any volumes and mounts you want present in the ingress controller container
646
## Volumes are defined above in deployment.userDefinedVolumes
647
# userDefinedVolumeMounts:
648
# - name: "volumeName"
649
# mountPath: "/opt/user/dir/mount"
650
rbac:
651
# Specifies whether RBAC resources should be created
652
create: true
653
# Set to `false` to disable creating ClusterRole and ClusterRoleBinding, for the use cases where using ClusterRoles is not allowed.
654
# Warning: Reconciliation of some resources requires a ClusterRole because the controllers needs to watch cluster scoped resources.
655
# Disabling ClusterRoles causes them fail, so you need to disable the controllers when setting it to `false`.
656
# The resources includes:
657
# - All gateway API resources
658
# - `IngressClass`
659
# - `KNative/Ingress` (KIC 2.x only)
660
# - `KongClusterPlugin`
661
# - `KongVault`, `KongLicense` (KIC 3.1 and above)
662
enableClusterRoles: true
663
gatewayAPI:
664
# Specifies whether RBAC policy rules for Gateway API resources should
665
# be generated regardless of the presence of Gateway API CRDs in the cluster.
666
# If this is disabled then RBAC policy rules for Gateway API resources will
667
# only be generated if the Gateway API CRDs are present in the cluster.
668
enabled: true
669
# general properties
670
livenessProbe:
671
httpGet:
672
path: "/healthz"
673
port: 10254
674
scheme: HTTP
675
initialDelaySeconds: 5
676
timeoutSeconds: 5
677
periodSeconds: 10
678
successThreshold: 1
679
failureThreshold: 3
680
readinessProbe:
681
httpGet:
682
path: "/readyz"
683
port: 10254
684
scheme: HTTP
685
initialDelaySeconds: 5
686
timeoutSeconds: 5
687
periodSeconds: 10
688
successThreshold: 1
689
failureThreshold: 3
690
resources: {}
691
# Example reasonable setting for "resources":
692
# resources:
693
# limits:
694
# cpu: 100m
695
# memory: 256Mi
696
# requests:
697
# cpu: 50m
698
# memory: 128Mi
699
700
konnect:
701
enabled: false
702
# Deprecated: Specifies a Konnect Runtime Group's ID that the controller will push its data-plane config to.
703
runtimeGroupID: ""
704
# Specifies a Konnect Control Plane's ID that the controller will push its data-plane config to.
705
controlPlaneID: ""
706
# Specifies a Konnect API hostname that the controller will use to push its data-plane config to.
707
# By default, this is set to US region's production API hostname.
708
# If you are using a different region, you can set this to the appropriate hostname (e.g. "eu.kic.api.konghq.com").
709
apiHostname: "us.kic.api.konghq.com"
710
# Specifies a secret that contains a client TLS certificate that the controller
711
# will use to authenticate against Konnect APIs.
712
tlsClientCertSecretName: "konnect-client-tls"
713
license:
714
# Specifies whether the controller should fetch a license from Konnect and apply it to managed Gateways.
715
enabled: false
716
adminApi:
717
tls:
718
client:
719
# Enable TLS client authentication for the Admin API.
720
enabled: false
721
# If set to false, Helm will generate certificates for you.
722
# If set to true, you are expected to provide your own secret (see secretName, caSecretName).
723
certProvided: false
724
# Client TLS certificate/key pair secret name that Ingress Controller will use to authenticate with Kong Admin API.
725
# If certProvided is set to false, it is optional (can be specified though if you want to force Helm to use
726
# a specific secret name).
727
secretName: ""
728
# CA TLS certificate/key pair secret name that the client TLS certificate is signed by.
729
# If certProvided is set to false, it is optional (can be specified though if you want to force Helm to use
730
# a specific secret name).
731
caSecretName: ""
732
# -----------------------------------------------------------------------------
733
# Postgres sub-chart parameters
734
# -----------------------------------------------------------------------------
735
736
# Kong can run without a database or use Postgres as a backend datatstore for it's configuration.
737
# By default, this chart installs Kong without a database.
738
739
# If you would like to use a database, there are two options:
740
# - (recommended) Deploy and maintain a database and pass the connection
741
# details to Kong via the `env` section.
742
# - You can use the below `postgresql` sub-chart to deploy a database
743
# along-with Kong as part of a single Helm release. Running a database
744
# independently is recommended for production, but the built-in Postgres is
745
# useful for quickly creating test instances.
746
747
# PostgreSQL chart documentation:
748
# https://github.com/bitnami/charts/blob/master/bitnami/postgresql/README.md
749
#
750
# WARNING: by default, the Postgres chart generates a random password each
751
# time it upgrades, which breaks access to existing volumes. You should set a
752
# password explicitly:
753
# https://github.com/Kong/charts/blob/main/charts/kong/FAQs.md#kong-fails-to-start-after-helm-upgrade-when-postgres-is-used-what-do-i-do
754
postgresql:
755
enabled: false
756
auth:
757
username: kong
758
database: kong
759
# Default bitnami/postgres image is not available anymore, see:
760
# https://github.com/bitnami/containers/issues/83267 for details.
761
# If you want to use a DB backed Kong installation with Postgres,
762
# provide your own image here.
763
image:
764
registry: ""
765
repository: ""
766
tag: ""
767
service:
768
ports:
769
postgresql: "5432"
770
primary:
771
annotations:
772
"ignore-check.kube-linter.io/no-read-only-root-fs": "writable fs is required"
773
podSecurityContext:
774
runAsNonRoot: true
775
seccompProfile:
776
type: RuntimeDefault
777
containerSecurityContext:
778
runAsNonRoot: true
779
seccompProfile:
780
type: RuntimeDefault
781
allowPrivilegeEscalation: false
782
capabilities:
783
drop:
784
- ALL
785
# -----------------------------------------------------------------------------
786
# Configure cert-manager integration
787
# -----------------------------------------------------------------------------
788
certificates:
789
enabled: false
790
# Set the certificate timers or leave on the default value
791
# Default is 15 days
792
renewBefore: "360h0m0s"
793
# Default is 90d days
794
duration: "2160h0m0s"
795
# Set either `issuer` or `clusterIssuer` to the name of the desired cert manager issuer
796
# If left blank a built in self-signed issuer will be created and utilized
797
issuer: ""
798
clusterIssuer: ""
799
# Set proxy.enabled to true to issue default kong-proxy certificate with cert-manager
800
proxy:
801
enabled: true
802
# Set `issuer` or `clusterIssuer` to name of alternate cert-manager clusterIssuer to override default
803
# self-signed issuer.
804
issuer: ""
805
clusterIssuer: ""
806
# Use commonName and dnsNames to set the common name and dns alt names which this
807
# certificate is valid for. Wildcard records are supported by the included self-signed issuer.
808
commonName: "app.example"
809
# Remove the "[]" and uncomment/change the examples to add SANs
810
dnsNames: []
811
# - "app.example"
812
# - "*.apps.example"
813
# - "*.kong.example"
814
# Set admin.enabled true to issue kong admin api certificate with cert-manager
815
admin:
816
enabled: true
817
# Set `issuer` or `clusterIssuer` to name of alternate cert-manager clusterIssuer to override default
818
# self-signed issuer.
819
issuer: ""
820
clusterIssuer: ""
821
# Use commonName and dnsNames to set the common name and dns alt names which this
822
# certificate is valid for. Wildcard records are supported by the included self-signed issuer.
823
commonName: "kong.example"
824
# Remove the "[]" and uncomment/change the examples to add SANs
825
dnsNames: []
826
# - "admin.kong.example"
827
# Set manager.enabled true to issue a dedicated Kong Manager (admin GUI) certificate with cert-manager
828
# If disabled, Kong Manager will fall back to using the admin certificate (backward compatible behavior).
829
manager:
830
enabled: false
831
# Set `issuer` or `clusterIssuer` to name of alternate cert-manager issuer to override default
832
issuer: ""
833
clusterIssuer: ""
834
# Use commonName and dnsNames to set the common name and dns alt names which this
835
# certificate is valid for. Wildcard records are supported by the included self-signed issuer.
836
commonName: "manager.kong.example"
837
# Remove the "[]" and uncomment/change the examples to add SANs
838
dnsNames: []
839
# - "manager.kong.example"
840
# Set portal.enabled to true to issue a developer portal certificate with cert-manager
841
portal:
842
enabled: true
843
# Set `issuer` or `clusterIssuer` to name of alternate cert-manager clusterIssuer to override default
844
# self-signed issuer.
845
issuer: ""
846
clusterIssuer: ""
847
# Use commonName and dnsNames to set the common name and dns alt names which this
848
# certificate is valid for. Wildcard records are supported by the included self-signed issuer.
849
commonName: "developer.example"
850
# Remove the "{}" and uncomment/change the examples to add SANs
851
dnsNames: []
852
# - "manager.kong.example"
853
# Set cluster.enabled true to issue kong hybrid mtls certificate with cert-manager
854
cluster:
855
enabled: true
856
# Issuers used by the control and data plane releases must match for this certificate.
857
issuer: ""
858
clusterIssuer: ""
859
commonName: "kong_clustering"
860
dnsNames: []
861
# -----------------------------------------------------------------------------
862
# Miscellaneous parameters
863
# -----------------------------------------------------------------------------
864
waitImage:
865
# Wait for the database to come online before starting Kong or running migrations
866
# If Kong is to access the database through a service mesh that injects a sidecar to
867
# Kong's container, this must be disabled. Otherwise there'll be a deadlock:
868
# InitContainer waiting for DB access that requires the sidecar, and the sidecar
869
# waiting for InitContainers to finish.
870
enabled: true
871
# Optionally specify an image that provides bash for pre-migration database
872
# checks. If none is specified, the chart uses the Kong image. The official
873
# Kong images provide bash
874
# repository: bash
875
# tag: 5
876
pullPolicy: IfNotPresent
877
# update strategy
878
updateStrategy: {}
879
# type: RollingUpdate
880
# rollingUpdate:
881
# maxSurge: "100%"
882
# maxUnavailable: "0%"
883
884
# If you want to specify resources, uncomment the following
885
# lines, adjust them as necessary, and remove the curly braces after 'resources:'.
886
resources: {}
887
# limits:
888
# cpu: 1
889
# memory: 2G
890
# requests:
891
# cpu: 1
892
# memory: 2G
893
894
# Resources for initContainers (clear-stale-pid)
895
# If not specified, defaults to the main container resources defined above
896
initContainerResources: {}
897
# limits:
898
# cpu: 100m
899
# memory: 128Mi
900
# requests:
901
# cpu: 50m
902
# memory: 64Mi
903
904
# readinessProbe for Kong pods
905
readinessProbe:
906
httpGet:
907
path: "/status/ready"
908
port: status
909
scheme: HTTP
910
initialDelaySeconds: 5
911
timeoutSeconds: 5
912
periodSeconds: 10
913
successThreshold: 1
914
failureThreshold: 3
915
# livenessProbe for Kong pods
916
livenessProbe:
917
httpGet:
918
path: "/status"
919
port: status
920
scheme: HTTP
921
initialDelaySeconds: 5
922
timeoutSeconds: 5
923
periodSeconds: 10
924
successThreshold: 1
925
failureThreshold: 3
926
# startupProbe for Kong pods
927
# startupProbe:
928
# httpGet:
929
# path: "/status"
930
# port: status
931
# scheme: HTTP
932
# initialDelaySeconds: 5
933
# timeoutSeconds: 5
934
# periodSeconds: 2
935
# successThreshold: 1
936
# failureThreshold: 40
937
938
# Proxy container lifecycle hooks
939
# Ref: https://kubernetes.io/docs/concepts/containers/container-lifecycle-hooks/
940
lifecycle:
941
preStop:
942
exec:
943
# kong quit has a default timeout of 10 seconds, and a default wait of 0 seconds.
944
# Note: together they should be less than the terminationGracePeriodSeconds setting below.
945
command:
946
- kong
947
- quit
948
- '--wait=15'
949
# Sets the termination grace period for pods spawned by the Kubernetes Deployment.
950
# Ref: https://kubernetes.io/docs/concepts/containers/container-lifecycle-hooks/#hook-handler-execution
951
terminationGracePeriodSeconds: 30
952
# Affinity for pod assignment
953
# Ref: https://kubernetes.io/docs/concepts/configuration/assign-pod-node/#affinity-and-anti-affinity
954
# affinity: {}
955
956
# Topology spread constraints for pod assignment (requires Kubernetes >= 1.19)
957
# Ref: https://kubernetes.io/docs/concepts/workloads/pods/pod-topology-spread-constraints/
958
# topologySpreadConstraints: []
959
960
# Tolerations for pod assignment
961
# Ref: https://kubernetes.io/docs/concepts/configuration/taint-and-toleration/
962
tolerations: []
963
# Node labels for pod assignment
964
# Ref: https://kubernetes.io/docs/user-guide/node-selection/
965
nodeSelector: {}
966
# Annotation to be added to Kong pods
967
podAnnotations:
968
kuma.io/gateway: enabled
969
traffic.sidecar.istio.io/includeInboundPorts: ""
970
# Labels to be added to Kong pods
971
podLabels: {}
972
# Kong pod count.
973
# It has no effect when autoscaling.enabled is set to true
974
replicaCount: 1
975
# Annotations to be added to Kong deployment
976
deploymentAnnotations: {}
977
# Enable autoscaling using HorizontalPodAutoscaler
978
# When configuring an HPA, you must set resource requests on all containers via
979
# "resources" and, if using the controller, "ingressController.resources" in values.yaml
980
autoscaling:
981
enabled: false
982
minReplicas: 2
983
maxReplicas: 5
984
annotations: {}
985
behavior: {}
986
## targetCPUUtilizationPercentage only used if the cluster doesn't support autoscaling/v2 or autoscaling/v2beta
987
targetCPUUtilizationPercentage:
988
## Otherwise for clusters that do support autoscaling/v2 or autoscaling/v2beta, use metrics
989
metrics:
990
- type: Resource
991
resource:
992
name: cpu
993
target:
994
type: Utilization
995
averageUtilization: 80
996
# Kong Pod Disruption Budget
997
podDisruptionBudget:
998
enabled: false
999
# Uncomment only one of the following when enabled is set to true
1000
# maxUnavailable: "50%"
1001
# minAvailable: "50%"
1002
unhealthyPodEvictionPolicy: IfHealthyBudget
1003
podSecurityPolicy:
1004
enabled: false
1005
labels: {}
1006
annotations: {}
1007
spec:
1008
privileged: false
1009
fsGroup:
1010
rule: RunAsAny
1011
runAsUser:
1012
rule: RunAsAny
1013
runAsGroup:
1014
rule: RunAsAny
1015
seLinux:
1016
rule: RunAsAny
1017
supplementalGroups:
1018
rule: RunAsAny
1019
volumes:
1020
- 'configMap'
1021
- 'secret'
1022
- 'emptyDir'
1023
- 'projected'
1024
allowPrivilegeEscalation: false
1025
hostNetwork: false
1026
hostIPC: false
1027
hostPID: false
1028
# Make the root filesystem read-only. This is not compatible with Kong Enterprise <1.5.
1029
# If you use Kong Enterprise <1.5, this must be set to false.
1030
readOnlyRootFilesystem: true
1031
priorityClassName: ""
1032
# securityContext for Kong pods.
1033
securityContext:
1034
seccompProfile:
1035
type: RuntimeDefault
1036
# securityContext for containers.
1037
# Set containerSecurityContext.enabled=false for OpenShift, where the platform
1038
# automatically assigns UIDs/GIDs via Security Context Constraints (SCC).
1039
containerSecurityContext:
1040
enabled: true
1041
readOnlyRootFilesystem: true
1042
allowPrivilegeEscalation: false
1043
runAsUser: 1000
1044
runAsGroup: 1000
1045
runAsNonRoot: true
1046
seccompProfile:
1047
type: RuntimeDefault
1048
capabilities:
1049
drop:
1050
- ALL
1051
## Optional DNS configuration for Kong pods
1052
# dnsPolicy: ClusterFirst
1053
# dnsConfig:
1054
# nameservers:
1055
# - "10.100.0.10"
1056
# options:
1057
# - name: ndots
1058
# value: "5"
1059
# searches:
1060
# - default.svc.cluster.local
1061
# - svc.cluster.local
1062
# - cluster.local
1063
# - us-east-1.compute.internal
1064
serviceMonitor:
1065
# Specifies whether ServiceMonitor for Prometheus operator should be created
1066
# If you wish to gather metrics from a Kong instance with the proxy disabled (such as a hybrid control plane), see:
1067
# https://github.com/Kong/charts/blob/main/charts/kong/README.md#prometheus-operator-integration
1068
enabled: false
1069
trustCRDsExist: false
1070
# interval: 30s
1071
# Specifies namespace, where ServiceMonitor should be installed
1072
# namespace: monitoring
1073
# labels:
1074
# foo: bar
1075
# targetLabels:
1076
# - foo
1077
# honorLabels: false
1078
# metricRelabelings: []
1079
# relabelings: []
1080
1081
# -----------------------------------------------------------------------------
1082
# Kong Enterprise parameters
1083
# -----------------------------------------------------------------------------
1084
1085
# Toggle Kong Enterprise features on or off
1086
# RBAC and SMTP configuration have additional options that must all be set together
1087
# Other settings should be added to the "env" settings below
1088
enterprise:
1089
enabled: false
1090
# Kong Enterprise license secret name
1091
# This secret must contain a single 'license' key, containing your base64-encoded license data
1092
# The license secret is required to unlock all Enterprise features. If you omit it,
1093
# Kong will run in free mode, with some Enterprise features disabled.
1094
# license_secret: kong-enterprise-license
1095
vitals:
1096
enabled: true
1097
portal:
1098
enabled: false
1099
rbac:
1100
enabled: false
1101
admin_gui_auth: basic-auth
1102
# If RBAC is enabled, this Secret must contain an admin_gui_session_conf key
1103
# The key value must be a secret configuration, following the example at
1104
# https://docs.konghq.com/enterprise/latest/kong-manager/authentication/sessions
1105
# If using 3.6+ and OIDC, session configuration is instead handled in the auth configuration,
1106
# and this field can be left empty.
1107
session_conf_secret: "kong-session-config" # CHANGEME
1108
# If admin_gui_auth is not set to basic-auth, provide a secret name which
1109
# has an admin_gui_auth_conf key containing the plugin config JSON
1110
admin_gui_auth_conf_secret: CHANGEME-admin-gui-auth-conf-secret
1111
# For configuring emails and SMTP, please read through:
1112
# https://docs.konghq.com/enterprise/latest/developer-portal/configuration/smtp
1113
# https://docs.konghq.com/enterprise/latest/kong-manager/networking/email
1114
smtp:
1115
enabled: false
1116
portal_emails_from: none@example.com
1117
portal_emails_reply_to: none@example.com
1118
admin_emails_from: none@example.com
1119
admin_emails_reply_to: none@example.com
1120
smtp_admin_emails: none@example.com
1121
smtp_host: smtp.example.com
1122
smtp_port: 587
1123
smtp_auth_type: ''
1124
smtp_ssl: nil
1125
smtp_starttls: true
1126
auth:
1127
# If your SMTP server does not require authentication, this section can
1128
# be left as-is. If smtp_username is set to anything other than an empty
1129
# string, you must create a Secret with an smtp_password key containing
1130
# your SMTP password and specify its name here.
1131
smtp_username: '' # e.g. postmaster@example.com
1132
smtp_password_secret: CHANGEME-smtp-password
1133
manager:
1134
# Enable creating a Kubernetes service for Kong Manager
1135
enabled: true
1136
type: NodePort
1137
loadBalancerClass:
1138
ipFamilyPolicy:
1139
ipFamilies: []
1140
trafficDistribution:
1141
# To specify annotations or labels for the Manager service, add them to the respective
1142
# "annotations" or "labels" dictionaries below.
1143
annotations: {}
1144
# service.beta.kubernetes.io/aws-load-balancer-proxy-protocol: "*"
1145
labels: {}
1146
http:
1147
# Enable plaintext HTTP listen for Kong Manager
1148
enabled: true
1149
servicePort: 8002
1150
containerPort: 8002
1151
# Set a nodePort which is available if service type is NodePort
1152
# nodePort: 32080
1153
# Additional listen parameters, e.g. "reuseport", "backlog=16384"
1154
parameters: []
1155
tls:
1156
# Enable HTTPS listen for Kong Manager
1157
enabled: true
1158
servicePort: 8445
1159
containerPort: 8445
1160
# Set a nodePort which is available if service type is NodePort
1161
# nodePort: 32443
1162
# Additional listen parameters, e.g. "reuseport", "backlog=16384"
1163
parameters:
1164
- http2
1165
ingress:
1166
# Enable/disable exposure using ingress.
1167
enabled: false
1168
ingressClassName:
1169
# TLS secret name.
1170
# tls: kong-manager.example.com-tls
1171
# Ingress hostname
1172
hostname:
1173
# Map of ingress annotations.
1174
annotations: {}
1175
# Ingress path.
1176
path: /
1177
# Each path in an Ingress is required to have a corresponding path type. (ImplementationSpecific/Exact/Prefix)
1178
pathType: ImplementationSpecific
1179
portal:
1180
# Enable creating a Kubernetes service for the Developer Portal
1181
enabled: true
1182
type: NodePort
1183
loadBalancerClass:
1184
ipFamilyPolicy:
1185
ipFamilies: []
1186
trafficDistribution:
1187
# To specify annotations or labels for the Portal service, add them to the respective
1188
# "annotations" or "labels" dictionaries below.
1189
annotations: {}
1190
# service.beta.kubernetes.io/aws-load-balancer-proxy-protocol: "*"
1191
labels: {}
1192
http:
1193
# Enable plaintext HTTP listen for the Developer Portal
1194
enabled: true
1195
servicePort: 8003
1196
containerPort: 8003
1197
# Set a nodePort which is available if service type is NodePort
1198
# nodePort: 32080
1199
# Additional listen parameters, e.g. "reuseport", "backlog=16384"
1200
parameters: []
1201
tls:
1202
# Enable HTTPS listen for the Developer Portal
1203
enabled: true
1204
servicePort: 8446
1205
containerPort: 8446
1206
# Set a nodePort which is available if service type is NodePort
1207
# nodePort: 32443
1208
# Additional listen parameters, e.g. "reuseport", "backlog=16384"
1209
parameters:
1210
- http2
1211
ingress:
1212
# Enable/disable exposure using ingress.
1213
enabled: false
1214
ingressClassName:
1215
# TLS secret name.
1216
# tls: kong-portal.example.com-tls
1217
# Ingress hostname
1218
hostname:
1219
# Map of ingress annotations.
1220
annotations: {}
1221
# Ingress path.
1222
path: /
1223
# Each path in an Ingress is required to have a corresponding path type. (ImplementationSpecific/Exact/Prefix)
1224
pathType: ImplementationSpecific
1225
portalapi:
1226
# Enable creating a Kubernetes service for the Developer Portal API
1227
enabled: true
1228
type: NodePort
1229
loadBalancerClass:
1230
ipFamilyPolicy:
1231
ipFamilies: []
1232
trafficDistribution:
1233
# To specify annotations or labels for the Portal API service, add them to the respective
1234
# "annotations" or "labels" dictionaries below.
1235
annotations: {}
1236
# service.beta.kubernetes.io/aws-load-balancer-proxy-protocol: "*"
1237
labels: {}
1238
http:
1239
# Enable plaintext HTTP listen for the Developer Portal API
1240
enabled: true
1241
servicePort: 8004
1242
containerPort: 8004
1243
# Set a nodePort which is available if service type is NodePort
1244
# nodePort: 32080
1245
# Additional listen parameters, e.g. "reuseport", "backlog=16384"
1246
parameters: []
1247
tls:
1248
# Enable HTTPS listen for the Developer Portal API
1249
enabled: true
1250
servicePort: 8447
1251
containerPort: 8447
1252
# Set a nodePort which is available if service type is NodePort
1253
# nodePort: 32443
1254
# Additional listen parameters, e.g. "reuseport", "backlog=16384"
1255
parameters:
1256
- http2
1257
ingress:
1258
# Enable/disable exposure using ingress.
1259
enabled: false
1260
ingressClassName:
1261
# TLS secret name.
1262
# tls: kong-portalapi.example.com-tls
1263
# Ingress hostname
1264
hostname:
1265
# Map of ingress annotations.
1266
annotations: {}
1267
# Ingress path.
1268
path: /
1269
# Each path in an Ingress is required to have a corresponding path type. (ImplementationSpecific/Exact/Prefix)
1270
pathType: ImplementationSpecific
1271
clustertelemetry:
1272
enabled: false
1273
# To specify annotations or labels for the cluster telemetry service, add them to the respective
1274
# "annotations" or "labels" dictionaries below.
1275
annotations: {}
1276
# service.beta.kubernetes.io/aws-load-balancer-proxy-protocol: "*"
1277
labels: {}
1278
tls:
1279
enabled: false
1280
servicePort: 8006
1281
containerPort: 8006
1282
parameters: []
1283
type: ClusterIP
1284
loadBalancerClass:
1285
ipFamilyPolicy:
1286
ipFamilies: []
1287
trafficDistribution:
1288
# Kong clustertelemetry ingress settings. Useful if you want to split
1289
# CP and DP in different clusters.
1290
ingress:
1291
# Enable/disable exposure using ingress.
1292
enabled: false
1293
ingressClassName:
1294
# TLS secret name.
1295
# tls: kong-clustertelemetry.example.com-tls
1296
# Ingress hostname
1297
hostname:
1298
# Map of ingress annotations.
1299
annotations: {}
1300
# Ingress path.
1301
path: /
1302
# Each path in an Ingress is required to have a corresponding path type. (ImplementationSpecific/Exact/Prefix)
1303
pathType: ImplementationSpecific
1304
extraConfigMaps: []
1305
# extraConfigMaps:
1306
# - name: my-config-map
1307
# mountPath: /mount/to/my/location
1308
# subPath: my-subpath # Optional, if you wish to mount a single key and not the entire ConfigMap
1309
1310
extraSecrets: []
1311
# extraSecrets:
1312
# - name: my-secret
1313
# mountPath: /mount/to/my/location
1314
# subPath: my-subpath # Optional, if you wish to mount a single key and not the entire ConfigMap
1315
1316
extraObjects: []
1317
# extraObjects:
1318
# - apiVersion: configuration.konghq.com/v1
1319
# kind: KongClusterPlugin
1320
# metadata:
1321
# name: prometheus
1322
# config:
1323
# per_consumer: false
1324
# plugin: prometheus
1325

The trusted source for open source

Talk to an expert
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsChainguard OS PackagesChainguard ActionsChainguard Agent SkillsIntegrationsPricing
© 2026 Chainguard, Inc. All Rights Reserved.
Chainguard® and the Chainguard logo are registered trademarks of Chainguard, Inc. in the United States and/or other countries.
The other respective trademarks mentioned on this page are owned by the respective companies and use of them does not imply any affiliation or endorsement.