1# Default values for Kong's Helm Chart.
2# Declare variables to be passed into your templates.
5# - Deployment parameters
7# - Ingress Controller parameters
8# - Postgres sub-chart parameters
9# - Miscellaneous parameters
10# - Kong Enterprise parameters
12# -----------------------------------------------------------------------------
13# Deployment parameters
14# -----------------------------------------------------------------------------
18 # Enable or disable Kong itself
19 # Setting this to false with ingressController.enabled=true will create a
20 # controller-only release.
22 # Control which predefined kong initContainers are enabled.
24 # Enable the init container which clears the stale PIDs from Kong's prefix directory.
27 # Image used by the clear-stale-pid init container. Defaults to the Kong image
32 # pullPolicy: IfNotPresent
36 - "$(KONG_PREFIX)/pids"
37 # The number of old `ReplicaSet`s to retain.
38 revisionHistoryLimit: 10
39 ## Minimum number of seconds for which a newly created pod should be ready without any of its container crashing,
40 ## for it to be considered available.
42 ## Specify the service account to create and to be assigned to the deployment / daemonset and for the migrations
45 # Automount the service account token. By default, this is disabled, and the token is only mounted on the controller
46 # container. Some sidecars require enabling this. Note that enabling this exposes Kubernetes credentials to Kong
47 # Lua code, increasing potential attack surface.
48 automountServiceAccountToken: false
49 ## Optionally specify the name of the service account to create and the annotations to add.
53 ## Optionally specify any extra sidecar containers to be included in the deployment
54 ## See https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.18/#container-v1-core
57 # image: sidecar:latest
60 # image: initcon:latest
67 ## Define any volumes and mounts you want present in the Kong proxy container
69 # - name: "volumeName"
71 # userDefinedVolumeMounts:
72 # - name: "volumeName"
73 # mountPath: "/opt/user/dir/mount"
75 # Enable creation of test resources for use with "helm test"
77 # Use a DaemonSet controller instead of a Deployment controller
80 # Set the Deployment's spec.template.hostname field.
81 # This propagates to Kong API endpoints that report
82 # the hostname, such as the admin API root and hybrid mode
83 # /clustering/data-planes endpoint
85 # kong_prefix empty dir size
91# Override namepsace for Kong chart resources. By default, the chart creates resources in the release namespace.
92# This may not be desirable when using this chart as a dependency.
95# -----------------------------------------------------------------------------
97# -----------------------------------------------------------------------------
99# Specify Kong configuration
100# This chart takes all entries defined under `.env` and transforms them into into `KONG_*`
101# environment variables for Kong containers.
102# Their names here should match the names used in https://github.com/Kong/kong/blob/master/kong.conf.default
103# See https://docs.konghq.com/latest/configuration also for additional details
104# Values here take precedence over values from other sections of values.yaml,
105# e.g. setting pg_user here will override the value normally set when postgresql.enabled
106# is set below. In general, you should not set values here if they are set elsewhere.
109 # the chart uses the traditional router (for Kong 3.x+) because the ingress
110 # controller generates traditional routes. if you do not use the controller,
111 # you may set this to "traditional_compatible" or "expressions" to use the new
113 router_flavor: "traditional"
114 nginx_worker_processes: "2"
115 proxy_access_log: /dev/stdout
116 admin_access_log: /dev/stdout
117 admin_gui_access_log: /dev/stdout
118 portal_api_access_log: /dev/stdout
119 proxy_error_log: /dev/stderr
120 admin_error_log: /dev/stderr
121 admin_gui_error_log: /dev/stderr
122 portal_api_error_log: /dev/stderr
123 prefix: /kong_prefix/
124# This section is any customer specific environments variables that doesn't require KONG_ prefix.
125# These custom environment variables are typicall used in custom plugins or serverless plugins to
126# access environment specific credentials or tokens.
127# Example as below, uncomment if required and add additional attributes as required.
128# Note that these environment variables will only apply to the proxy and init container. The ingress-controller
129# container has its own customEnv section.
137# client_name: testClient
139# Load all ConfigMap or Secret keys as environment variables:
140# https://kubernetes.io/docs/tasks/configure-pod-container/configure-pod-configmap/#configure-all-key-value-pairs-in-a-configmap-as-container-environment-variables
142# This section can be used to configure some extra labels that will be added to each Kubernetes object generated.
144# Specify Kong's Docker image and repository details here
146 repository: chainreg.biz/chainguard-private/kong
147 tag: 3.9.3-r7@sha256:43b61b1753058b40a625437ba0a0f2631b8cfb236c95f9fce72bd62a50eab539
149 # repository: kong/kong-gateway
152 # Specify a semver version if your image tag is not one (e.g. "nightly")
154 pullPolicy: IfNotPresent
155 ## Optionally specify an array of imagePullSecrets.
156 ## Secrets must be manually created in the namespace.
157 ## ref: https://kubernetes.io/docs/tasks/configure-pod-container/pull-image-private-registry/
160 # - myRegistrKeySecretName
161# Specify Kong admin API service and listener configuration
163 # Enable creating a Kubernetes service for the admin API
164 # Disabling this is recommended for most ingress controller configurations
165 # Enterprise users that wish to use Kong Manager with the controller should enable this
172 # To specify annotations or labels for the admin service, add them to the respective
173 # "annotations" or "labels" dictionaries below.
175 # service.beta.kubernetes.io/aws-load-balancer-proxy-protocol: "*"
178 # Enable plaintext HTTP listen for the admin API
179 # Disabling this and using a TLS listen only is recommended for most configuration
183 # Set a nodePort which is available if service type is NodePort
185 # Additional listen parameters, e.g. "reuseport", "backlog=16384"
188 # Enable HTTPS listen for the admin API
192 # Set a target port for the TLS port in the admin API service, useful when using TLS
193 # termination on an ELB.
194 # overrideServiceTargetPort: 8000
195 # Set a nodePort which is available if service type is NodePort
197 # Additional listen parameters, e.g. "reuseport", "backlog=16384"
200 # Specify the CA certificate to use for TLS verification of the Admin API client by:
201 # - secretName - the secret must contain a key named "tls.crt" with the PEM-encoded certificate.
202 # - caBundle (PEM-encoded certificate string).
203 # If both are set, caBundle takes precedence.
207 # Kong admin ingress settings. Useful if you want to expose the Admin
208 # API of Kong outside the k8s cluster.
210 # Enable/disable exposure using ingress.
214 # tls: kong-admin.example.com-tls
217 # Map of ingress annotations.
221 # Each path in an Ingress is required to have a corresponding path type. (ImplementationSpecific/Exact/Prefix)
222 pathType: ImplementationSpecific
223# Specify Kong status listener configuration
224# This listen is internal-only. It cannot be exposed through a service or ingress.
228 # Enable plaintext HTTP listen for the status listen
233 # Enable HTTPS listen for the status listen
234 # Kong versions prior to 2.1 do not support TLS status listens.
235 # This setting must remain false on those versions
239# Name the kong hybrid cluster CA certificate secret
240clusterCaSecretName: ""
241# Specify Kong cluster service and listener configuration
243# The cluster service *must* use TLS. It does not support the "http" block
244# available on other services.
246# The cluster service cannot be exposed through an Ingress, as it must perform
247# TLS client validation directly and is not compatible with TLS-terminating
248# proxies. If you need to expose it externally, you must use "type:
249# LoadBalancer" and use a TCP-only load balancer (check your Kubernetes
250# provider's documentation, as the configuration required for this varies).
253 # To specify annotations or labels for the cluster service, add them to the respective
254 # "annotations" or "labels" dictionaries below.
256 # service.beta.kubernetes.io/aws-load-balancer-proxy-protocol: "*"
268 # Kong cluster ingress settings. Useful if you want to split CP and DP
269 # in different clusters.
271 # Enable/disable exposure using ingress.
275 # tls: kong-cluster.example.com-tls
278 # Map of ingress annotations.
282 # Each path in an Ingress is required to have a corresponding path type. (ImplementationSpecific/Exact/Prefix)
283 pathType: ImplementationSpecific
284# Specify Kong proxy service configuration
286 # Enable creating a Kubernetes service for the proxy
289 loadBalancerClass: ""
293 # Configures optional firewall rules and in the VPC network to only allow certain source ranges.
294 loadBalancerSourceRanges: []
295 # Override proxy Service name
297 # To specify annotations or labels for the proxy service, add them to the respective
298 # "annotations" or "labels" dictionaries below.
300 # If terminating TLS at the ELB, the following annotations can be used
301 # "service.beta.kubernetes.io/aws-load-balancer-backend-protocol": "*",
302 # "service.beta.kubernetes.io/aws-load-balancer-cross-zone-load-balancing-enabled": "true",
303 # "service.beta.kubernetes.io/aws-load-balancer-ssl-cert": "arn:aws:acm:REGION:ACCOUNT:certificate/XXXXXX-XXXXXXX-XXXXXXX-XXXXXXXX",
304 # "service.beta.kubernetes.io/aws-load-balancer-ssl-ports": "kong-proxy-tls",
305 # "service.beta.kubernetes.io/aws-load-balancer-type": "elb"
307 enable-metrics: "true"
309 # Enable plaintext HTTP listen for the proxy
311 # Set the servicePort: 0 to skip exposing in the service but still
312 # let the port open in container to allow https to http mapping for
313 # tls terminated at LB.
316 # Set a nodePort which is available if service type is NodePort
318 # Additional listen parameters, e.g. "reuseport", "backlog=16384"
321 # Enable HTTPS listen for the proxy
325 # Set a target port for the TLS port in proxy service
326 # overrideServiceTargetPort: 8000
327 # Set a nodePort which is available if service type is NodePort
329 # Additional listen parameters, e.g. "reuseport", "backlog=16384"
332 # Specify the Service's TLS port's appProtocol. This can be useful when integrating with
333 # external load balancers that require the `appProtocol` field to be set (e.g. GCP).
335 # Define stream (TCP) listen
336 # To enable, remove "[]", uncomment the section below, and select your desired
337 # ports and parameters. Listens are dynamically named after their containerPort,
338 # e.g. "stream-9000" for the below.
339 # Note: although you can select the protocol here, you cannot set UDP if you
340 # use a LoadBalancer Service due to limitations in current Kubernetes versions.
341 # To proxy both TCP and UDP with LoadBalancers, you must enable the udpProxy Service
342 # in the next section and place all UDP stream listen configuration under it.
344 # # Set the container (internal) and service (external) ports for this listen.
345 # # These values should normally be the same. If your environment requires they
346 # # differ, note that Kong will match routes based on the containerPort only.
347 # - containerPort: 9000
350 # # Optionally set a static nodePort if the service type is NodePort
352 # # Additional listen parameters, e.g. "ssl", "reuseport", "backlog=16384"
353 # # "ssl" is required for SNI-based routes. It is not supported on versions <2.0
356 # Kong proxy ingress settings.
357 # Note: You need this only if you are using another Ingress Controller
358 # to expose Kong outside the k8s cluster.
360 # Enable/disable exposure using ingress.
363 # To specify annotations or labels for the ingress, add them to the respective
364 # "annotations" or "labels" dictionaries below.
369 # Ingress path (when used with hostname above).
371 # Each path in an Ingress is required to have a corresponding path type (when used with hostname above). (ImplementationSpecific/Exact/Prefix)
372 pathType: ImplementationSpecific
373 # Ingress hosts. Use this instead of or in combination with hostname to specify multiple ingress host configurations
375 # - host: kong-proxy.example.com
379 # # Each path in an Ingress is required to have a corresponding path type. (ImplementationSpecific/Exact/Prefix)
380 # pathType: ImplementationSpecific
381 # - host: kong-proxy-other.example.com
385 # # Each path in an Ingress is required to have a corresponding path type. (ImplementationSpecific/Exact/Prefix)
386 # pathType: ImplementationSpecific
389 # name: kong-other-proxy
394 # tls: kong-proxy.example.com-tls
395 # Or if multiple hosts/secrets needs to be configured:
397 # - secretName: kong-proxy.example.com-tls
399 # - kong-proxy.example.com
400 # - secretName: kong-proxy-other.example.com-tls
402 # - kong-proxy-other.example.com
403 # Optionally specify a static load balancer IP.
405# Specify Kong UDP proxy service configuration
406# Currently, LoadBalancer type Services are generally limited to a single transport protocol
407# Multi-protocol Services are an alpha feature as of Kubernetes 1.20:
408# https://kubernetes.io/docs/concepts/services-networking/service/#load-balancers-with-mixed-protocol-types
409# You should enable this Service if you proxy UDP traffic, and configure UDP stream listens under it
411 # Enable creating a Kubernetes service for UDP proxying
418 # To specify annotations or labels for the proxy service, add them to the respective
419 # "annotations" or "labels" dictionaries below.
421 # service.beta.kubernetes.io/aws-load-balancer-proxy-protocol: "*"
423 # Optionally specify a static load balancer IP.
426 # Define stream (UDP) listen
427 # To enable, remove "[]", uncomment the section below, and select your desired
428 # ports and parameters. Listens are dynamically named after their servicePort,
429 # e.g. "stream-9000" for the below.
431 # # Set the container (internal) and service (external) ports for this listen.
432 # # These values should normally be the same. If your environment requires they
433 # # differ, note that Kong will match routes based on the containerPort only.
434 # - containerPort: 9000
437 # # Optionally set a static nodePort if the service type is NodePort
439 # # Additional listen parameters, e.g. "ssl", "reuseport", "backlog=16384"
440 # # "ssl" is required for SNI-based routes. It is not supported on versions <2.0
442# Custom Kong plugins can be loaded into Kong by mounting the plugin code
443# into the file-system of Kong container.
444# The plugin code should be present in ConfigMap or Secret inside the same
445# namespace as Kong is being installed.
446# The `name` property refers to the name of the ConfigMap or Secret
447# itself, while the pluginName refers to the name of the plugin as it appears
449# Subdirectories (which are optional) require separate ConfigMaps/Secrets.
450# "path" indicates their directory under the main plugin directory: the example
451# below will mount the contents of kong-plugin-rewriter-migrations at "/opt/kong/rewriter/migrations".
454# - pluginName: rewriter
455# name: kong-plugin-rewriter
457# - name: kong-plugin-rewriter-migrations
460# - pluginName: rewriter
461# name: kong-plugin-rewriter
462# If your development cycle preinstalls the plugin as part of the image, this appends them to the plugins env var
463# preInstalled: sweet-plugin,another-sweet-plugin
464# Inject specified secrets as a volume in Kong Container at path /etc/secrets/{secret-name}/
465# This can be used to override default SSL certificates.
466# Be aware that the secret name will be used verbatim, and that certain types
467# of punctuation (e.g. `.`) can cause issues.
468# Example configuration
473# Enable/disable migration jobs, and set annotations for them
475 # Enable pre-upgrade migrations (run "kong migrations up")
477 # Enable post-upgrade migrations (run "kong migrations finish")
479 # Annotations to apply to migrations job pods
480 # By default, these disable service mesh sidecar injection for Istio and Kuma,
481 # as the sidecar containers do not terminate and prevent the jobs from completing
483 sidecar.istio.io/inject: false
484 # Additional annotations to apply to migration jobs
485 # This is helpful in certain non-Helm installation situations such as GitOps
486 # where additional control is required around this job creation.
488 # Optionally set a backoffLimit. If none is set, Jobs will use the cluster default
490 # Optionally set to specify the time-to-live (TTL) for a pod after it has completed its execution before automatic deletion. If left unset, pod lifetime is indefinite.
491 ttlSecondsAfterFinished:
493 # Example reasonable setting for "resources":
501 ## Optionally specify any extra sidecar containers to be included in the deployment
502 ## See https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.18/#container-v1-core
503 ## Keep in mind these containers should be terminated along with the main
504 ## migration containers
507 # image: sidecar:latest
508 ## Optionally set securitycontext for the wait-for-postgres migrations init container
511 # allowPrivilegeEscalation: false
515 # readOnlyRootFilesystem: true
518# Kong's configuration for DB-less mode
519# Note: Use this section only if you are deploying Kong in DB-less mode
520# and not as an Ingress Controller.
522 # Either Kong's configuration is managed from an existing ConfigMap (with Key: kong.yml)
524 # Or Kong's configuration is managed from an existing Secret (with Key: kong.yml)
526 # Or the configuration is passed in full-text below
528 # # _format_version: "1.1"
530 # # # Example configuration
531 # # # - name: example.com
532 # # # url: http://example.com
534 # # # - name: example
537 ## Optionally specify any extra sidecar containers to be included in the
539 ## See https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.18/#container-v1-core
542 # image: sidecar:latest
543# -----------------------------------------------------------------------------
544# Ingress Controller parameters
545# -----------------------------------------------------------------------------
547# Kong Ingress Controller's primary purpose is to satisfy Ingress resources
548# created in k8s. It uses CRDs for more fine grained control over routing and
549# for Kong specific configuration.
553 repository: chainreg.biz/chainguard-private/kong-ingress-controller
554 tag: 3.5.13-r7@sha256:7e987d1452b1ab2f442fdac824f776a96a646327bfa92b61f175af9238320088
555 # Optionally set a semantic version for version-gated features. This can normally
556 # be left unset. You only need to set this if your tag is not a semver string,
557 # such as when you are using a "next" tag. Set this to the effective semantic
558 # version of your tag: for example if using a "next" image for an unreleased 3.1.0
559 # version, set this to "3.1.0".
564 generateAdminApiService: false
568 # Specify individual namespaces to watch for ingress configuration. By default,
569 # when no namespaces are set, the controller watches all namespaces and uses a
570 # ClusterRole to grant access to Kubernetes resources. When you list specific
571 # namespaces, the controller will watch those namespaces only and will create
572 # namespaced-scoped Roles for each of them. The controller will still use a
573 # ClusterRole for cluster-scoped resources.
574 # Requires controller 2.0.0 or newer.
576 # Specify Kong Ingress Controller configuration via environment variables
578 # The controller disables TLS verification by default because Kong
579 # generates self-signed certificates by default. Set this to false once you
580 # have installed CA-signed certificates.
581 kong_admin_tls_skip_verify: true
582 # If using Kong Enterprise with RBAC enabled, uncomment the section below
583 # and specify the secret/key containing your admin token.
587 # name: CHANGEME-admin-token-secret
588 # key: CHANGEME-admin-token-key
589 # This section is any customer specific environments variables that doesn't require CONTROLLER_ prefix.
590 # Example as below, uncomment if required and add additional attributes as required.
592 # TZ: "Europe/Berlin"
594 # Load all ConfigMap or Secret keys as environment variables:
595 # https://kubernetes.io/docs/tasks/configure-pod-container/configure-pod-configmap/#configure-all-key-value-pairs-in-a-configmap-as-container-environment-variables
598 matchPolicy: Equivalent
600 # Limit the `secrets.plugins.validation.ingress-controller.konghq.com` webhook
601 # to only Secrets with the appropriate KIC "konghq.com/validate" label.
603 failurePolicy: Ignore
607 # namespaceSelector specifies namespaces in which the resources are validated by the `*.validations.kong.konghq.com` webhooks.
608 # For example, the `kube-system` namespace contains objects created by the Kubernetes system, like `kube-dns` service.
609 # You can exclude the kube-system namespace from being intercepted using below namespaceSelector:
612 # - key: kubernetes.io/metadata.name
616 namespaceSelector: {}
617 # objectSelector specifies label selectors applied to all admission webhooks.
618 # For the secrets webhooks (credentials and plugins), chart-required expressions
619 # (e.g. credential type filtering, konnect exclusion) are always included
620 # in addition to any expressions you specify here.
621 # This is useful for scoping webhooks per Kong instance in multi-instance clusters.
628 # Specifiy the secretName when the certificate is provided via a TLS secret
630 # Specifiy the CA bundle of the provided certificate.
631 # This is a PEM encoded CA bundle which will be used to validate the webhook certificate. If unspecified, system trust roots on the apiserver are used.
633 # | Add the CA bundle content here.
635 # Specify custom labels for the validation webhook service.
637 # Tune the default Kubernetes timeoutSeconds of 10 seconds
640 # Check existence and create the `IngressClass` with given name in the cluster.
641 # You can set it to `false` to disable the creation of `IngressClass` if your user to run helm does not have the permission to create `IngressClass`es.
642 createIngressClass: true
643 # annotations for IngressClass resource (Kubernetes 1.18+)
644 ingressClassAnnotations: {}
645 ## Define any volumes and mounts you want present in the ingress controller container
646 ## Volumes are defined above in deployment.userDefinedVolumes
647 # userDefinedVolumeMounts:
648 # - name: "volumeName"
649 # mountPath: "/opt/user/dir/mount"
651 # Specifies whether RBAC resources should be created
653 # Set to `false` to disable creating ClusterRole and ClusterRoleBinding, for the use cases where using ClusterRoles is not allowed.
654 # Warning: Reconciliation of some resources requires a ClusterRole because the controllers needs to watch cluster scoped resources.
655 # Disabling ClusterRoles causes them fail, so you need to disable the controllers when setting it to `false`.
656 # The resources includes:
657 # - All gateway API resources
659 # - `KNative/Ingress` (KIC 2.x only)
660 # - `KongClusterPlugin`
661 # - `KongVault`, `KongLicense` (KIC 3.1 and above)
662 enableClusterRoles: true
664 # Specifies whether RBAC policy rules for Gateway API resources should
665 # be generated regardless of the presence of Gateway API CRDs in the cluster.
666 # If this is disabled then RBAC policy rules for Gateway API resources will
667 # only be generated if the Gateway API CRDs are present in the cluster.
675 initialDelaySeconds: 5
685 initialDelaySeconds: 5
691 # Example reasonable setting for "resources":
702 # Deprecated: Specifies a Konnect Runtime Group's ID that the controller will push its data-plane config to.
704 # Specifies a Konnect Control Plane's ID that the controller will push its data-plane config to.
706 # Specifies a Konnect API hostname that the controller will use to push its data-plane config to.
707 # By default, this is set to US region's production API hostname.
708 # If you are using a different region, you can set this to the appropriate hostname (e.g. "eu.kic.api.konghq.com").
709 apiHostname: "us.kic.api.konghq.com"
710 # Specifies a secret that contains a client TLS certificate that the controller
711 # will use to authenticate against Konnect APIs.
712 tlsClientCertSecretName: "konnect-client-tls"
714 # Specifies whether the controller should fetch a license from Konnect and apply it to managed Gateways.
719 # Enable TLS client authentication for the Admin API.
721 # If set to false, Helm will generate certificates for you.
722 # If set to true, you are expected to provide your own secret (see secretName, caSecretName).
724 # Client TLS certificate/key pair secret name that Ingress Controller will use to authenticate with Kong Admin API.
725 # If certProvided is set to false, it is optional (can be specified though if you want to force Helm to use
726 # a specific secret name).
728 # CA TLS certificate/key pair secret name that the client TLS certificate is signed by.
729 # If certProvided is set to false, it is optional (can be specified though if you want to force Helm to use
730 # a specific secret name).
732# -----------------------------------------------------------------------------
733# Postgres sub-chart parameters
734# -----------------------------------------------------------------------------
736# Kong can run without a database or use Postgres as a backend datatstore for it's configuration.
737# By default, this chart installs Kong without a database.
739# If you would like to use a database, there are two options:
740# - (recommended) Deploy and maintain a database and pass the connection
741# details to Kong via the `env` section.
742# - You can use the below `postgresql` sub-chart to deploy a database
743# along-with Kong as part of a single Helm release. Running a database
744# independently is recommended for production, but the built-in Postgres is
745# useful for quickly creating test instances.
747# PostgreSQL chart documentation:
748# https://github.com/bitnami/charts/blob/master/bitnami/postgresql/README.md
750# WARNING: by default, the Postgres chart generates a random password each
751# time it upgrades, which breaks access to existing volumes. You should set a
752# password explicitly:
753# https://github.com/Kong/charts/blob/main/charts/kong/FAQs.md#kong-fails-to-start-after-helm-upgrade-when-postgres-is-used-what-do-i-do
759 # Default bitnami/postgres image is not available anymore, see:
760 # https://github.com/bitnami/containers/issues/83267 for details.
761 # If you want to use a DB backed Kong installation with Postgres,
762 # provide your own image here.
772 "ignore-check.kube-linter.io/no-read-only-root-fs": "writable fs is required"
777 containerSecurityContext:
781 allowPrivilegeEscalation: false
785# -----------------------------------------------------------------------------
786# Configure cert-manager integration
787# -----------------------------------------------------------------------------
790 # Set the certificate timers or leave on the default value
792 renewBefore: "360h0m0s"
793 # Default is 90d days
794 duration: "2160h0m0s"
795 # Set either `issuer` or `clusterIssuer` to the name of the desired cert manager issuer
796 # If left blank a built in self-signed issuer will be created and utilized
799 # Set proxy.enabled to true to issue default kong-proxy certificate with cert-manager
802 # Set `issuer` or `clusterIssuer` to name of alternate cert-manager clusterIssuer to override default
803 # self-signed issuer.
806 # Use commonName and dnsNames to set the common name and dns alt names which this
807 # certificate is valid for. Wildcard records are supported by the included self-signed issuer.
808 commonName: "app.example"
809 # Remove the "[]" and uncomment/change the examples to add SANs
814 # Set admin.enabled true to issue kong admin api certificate with cert-manager
817 # Set `issuer` or `clusterIssuer` to name of alternate cert-manager clusterIssuer to override default
818 # self-signed issuer.
821 # Use commonName and dnsNames to set the common name and dns alt names which this
822 # certificate is valid for. Wildcard records are supported by the included self-signed issuer.
823 commonName: "kong.example"
824 # Remove the "[]" and uncomment/change the examples to add SANs
826 # - "admin.kong.example"
827 # Set manager.enabled true to issue a dedicated Kong Manager (admin GUI) certificate with cert-manager
828 # If disabled, Kong Manager will fall back to using the admin certificate (backward compatible behavior).
831 # Set `issuer` or `clusterIssuer` to name of alternate cert-manager issuer to override default
834 # Use commonName and dnsNames to set the common name and dns alt names which this
835 # certificate is valid for. Wildcard records are supported by the included self-signed issuer.
836 commonName: "manager.kong.example"
837 # Remove the "[]" and uncomment/change the examples to add SANs
839 # - "manager.kong.example"
840 # Set portal.enabled to true to issue a developer portal certificate with cert-manager
843 # Set `issuer` or `clusterIssuer` to name of alternate cert-manager clusterIssuer to override default
844 # self-signed issuer.
847 # Use commonName and dnsNames to set the common name and dns alt names which this
848 # certificate is valid for. Wildcard records are supported by the included self-signed issuer.
849 commonName: "developer.example"
850 # Remove the "{}" and uncomment/change the examples to add SANs
852 # - "manager.kong.example"
853 # Set cluster.enabled true to issue kong hybrid mtls certificate with cert-manager
856 # Issuers used by the control and data plane releases must match for this certificate.
859 commonName: "kong_clustering"
861# -----------------------------------------------------------------------------
862# Miscellaneous parameters
863# -----------------------------------------------------------------------------
865 # Wait for the database to come online before starting Kong or running migrations
866 # If Kong is to access the database through a service mesh that injects a sidecar to
867 # Kong's container, this must be disabled. Otherwise there'll be a deadlock:
868 # InitContainer waiting for DB access that requires the sidecar, and the sidecar
869 # waiting for InitContainers to finish.
871 # Optionally specify an image that provides bash for pre-migration database
872 # checks. If none is specified, the chart uses the Kong image. The official
873 # Kong images provide bash
876 pullPolicy: IfNotPresent
882# maxUnavailable: "0%"
884# If you want to specify resources, uncomment the following
885# lines, adjust them as necessary, and remove the curly braces after 'resources:'.
894# Resources for initContainers (clear-stale-pid)
895# If not specified, defaults to the main container resources defined above
896initContainerResources: {}
904# readinessProbe for Kong pods
907 path: "/status/ready"
910 initialDelaySeconds: 5
915# livenessProbe for Kong pods
921 initialDelaySeconds: 5
926# startupProbe for Kong pods
932# initialDelaySeconds: 5
936# failureThreshold: 40
938# Proxy container lifecycle hooks
939# Ref: https://kubernetes.io/docs/concepts/containers/container-lifecycle-hooks/
943 # kong quit has a default timeout of 10 seconds, and a default wait of 0 seconds.
944 # Note: together they should be less than the terminationGracePeriodSeconds setting below.
949# Sets the termination grace period for pods spawned by the Kubernetes Deployment.
950# Ref: https://kubernetes.io/docs/concepts/containers/container-lifecycle-hooks/#hook-handler-execution
951terminationGracePeriodSeconds: 30
952# Affinity for pod assignment
953# Ref: https://kubernetes.io/docs/concepts/configuration/assign-pod-node/#affinity-and-anti-affinity
956# Topology spread constraints for pod assignment (requires Kubernetes >= 1.19)
957# Ref: https://kubernetes.io/docs/concepts/workloads/pods/pod-topology-spread-constraints/
958# topologySpreadConstraints: []
960# Tolerations for pod assignment
961# Ref: https://kubernetes.io/docs/concepts/configuration/taint-and-toleration/
963# Node labels for pod assignment
964# Ref: https://kubernetes.io/docs/user-guide/node-selection/
966# Annotation to be added to Kong pods
968 kuma.io/gateway: enabled
969 traffic.sidecar.istio.io/includeInboundPorts: ""
970# Labels to be added to Kong pods
973# It has no effect when autoscaling.enabled is set to true
975# Annotations to be added to Kong deployment
976deploymentAnnotations: {}
977# Enable autoscaling using HorizontalPodAutoscaler
978# When configuring an HPA, you must set resource requests on all containers via
979# "resources" and, if using the controller, "ingressController.resources" in values.yaml
986 ## targetCPUUtilizationPercentage only used if the cluster doesn't support autoscaling/v2 or autoscaling/v2beta
987 targetCPUUtilizationPercentage:
988 ## Otherwise for clusters that do support autoscaling/v2 or autoscaling/v2beta, use metrics
995 averageUtilization: 80
996# Kong Pod Disruption Budget
999 # Uncomment only one of the following when enabled is set to true
1000 # maxUnavailable: "50%"
1001 # minAvailable: "50%"
1002 unhealthyPodEvictionPolicy: IfHealthyBudget
1024 allowPrivilegeEscalation: false
1028 # Make the root filesystem read-only. This is not compatible with Kong Enterprise <1.5.
1029 # If you use Kong Enterprise <1.5, this must be set to false.
1030 readOnlyRootFilesystem: true
1031priorityClassName: ""
1032# securityContext for Kong pods.
1035 type: RuntimeDefault
1036# securityContext for containers.
1037# Set containerSecurityContext.enabled=false for OpenShift, where the platform
1038# automatically assigns UIDs/GIDs via Security Context Constraints (SCC).
1039containerSecurityContext:
1041 readOnlyRootFilesystem: true
1042 allowPrivilegeEscalation: false
1047 type: RuntimeDefault
1051## Optional DNS configuration for Kong pods
1052# dnsPolicy: ClusterFirst
1060# - default.svc.cluster.local
1061# - svc.cluster.local
1063# - us-east-1.compute.internal
1065 # Specifies whether ServiceMonitor for Prometheus operator should be created
1066 # If you wish to gather metrics from a Kong instance with the proxy disabled (such as a hybrid control plane), see:
1067 # https://github.com/Kong/charts/blob/main/charts/kong/README.md#prometheus-operator-integration
1069 trustCRDsExist: false
1071 # Specifies namespace, where ServiceMonitor should be installed
1072 # namespace: monitoring
1078# metricRelabelings: []
1081# -----------------------------------------------------------------------------
1082# Kong Enterprise parameters
1083# -----------------------------------------------------------------------------
1085# Toggle Kong Enterprise features on or off
1086# RBAC and SMTP configuration have additional options that must all be set together
1087# Other settings should be added to the "env" settings below
1090 # Kong Enterprise license secret name
1091 # This secret must contain a single 'license' key, containing your base64-encoded license data
1092 # The license secret is required to unlock all Enterprise features. If you omit it,
1093 # Kong will run in free mode, with some Enterprise features disabled.
1094 # license_secret: kong-enterprise-license
1101 admin_gui_auth: basic-auth
1102 # If RBAC is enabled, this Secret must contain an admin_gui_session_conf key
1103 # The key value must be a secret configuration, following the example at
1104 # https://docs.konghq.com/enterprise/latest/kong-manager/authentication/sessions
1105 # If using 3.6+ and OIDC, session configuration is instead handled in the auth configuration,
1106 # and this field can be left empty.
1107 session_conf_secret: "kong-session-config" # CHANGEME
1108 # If admin_gui_auth is not set to basic-auth, provide a secret name which
1109 # has an admin_gui_auth_conf key containing the plugin config JSON
1110 admin_gui_auth_conf_secret: CHANGEME-admin-gui-auth-conf-secret
1111 # For configuring emails and SMTP, please read through:
1112 # https://docs.konghq.com/enterprise/latest/developer-portal/configuration/smtp
1113 # https://docs.konghq.com/enterprise/latest/kong-manager/networking/email
1116 portal_emails_from: none@example.com
1117 portal_emails_reply_to: none@example.com
1118 admin_emails_from: none@example.com
1119 admin_emails_reply_to: none@example.com
1120 smtp_admin_emails: none@example.com
1121 smtp_host: smtp.example.com
1127 # If your SMTP server does not require authentication, this section can
1128 # be left as-is. If smtp_username is set to anything other than an empty
1129 # string, you must create a Secret with an smtp_password key containing
1130 # your SMTP password and specify its name here.
1131 smtp_username: '' # e.g. postmaster@example.com
1132 smtp_password_secret: CHANGEME-smtp-password
1134 # Enable creating a Kubernetes service for Kong Manager
1140 trafficDistribution:
1141 # To specify annotations or labels for the Manager service, add them to the respective
1142 # "annotations" or "labels" dictionaries below.
1144 # service.beta.kubernetes.io/aws-load-balancer-proxy-protocol: "*"
1147 # Enable plaintext HTTP listen for Kong Manager
1151 # Set a nodePort which is available if service type is NodePort
1153 # Additional listen parameters, e.g. "reuseport", "backlog=16384"
1156 # Enable HTTPS listen for Kong Manager
1160 # Set a nodePort which is available if service type is NodePort
1162 # Additional listen parameters, e.g. "reuseport", "backlog=16384"
1166 # Enable/disable exposure using ingress.
1170 # tls: kong-manager.example.com-tls
1173 # Map of ingress annotations.
1177 # Each path in an Ingress is required to have a corresponding path type. (ImplementationSpecific/Exact/Prefix)
1178 pathType: ImplementationSpecific
1180 # Enable creating a Kubernetes service for the Developer Portal
1186 trafficDistribution:
1187 # To specify annotations or labels for the Portal service, add them to the respective
1188 # "annotations" or "labels" dictionaries below.
1190 # service.beta.kubernetes.io/aws-load-balancer-proxy-protocol: "*"
1193 # Enable plaintext HTTP listen for the Developer Portal
1197 # Set a nodePort which is available if service type is NodePort
1199 # Additional listen parameters, e.g. "reuseport", "backlog=16384"
1202 # Enable HTTPS listen for the Developer Portal
1206 # Set a nodePort which is available if service type is NodePort
1208 # Additional listen parameters, e.g. "reuseport", "backlog=16384"
1212 # Enable/disable exposure using ingress.
1216 # tls: kong-portal.example.com-tls
1219 # Map of ingress annotations.
1223 # Each path in an Ingress is required to have a corresponding path type. (ImplementationSpecific/Exact/Prefix)
1224 pathType: ImplementationSpecific
1226 # Enable creating a Kubernetes service for the Developer Portal API
1232 trafficDistribution:
1233 # To specify annotations or labels for the Portal API service, add them to the respective
1234 # "annotations" or "labels" dictionaries below.
1236 # service.beta.kubernetes.io/aws-load-balancer-proxy-protocol: "*"
1239 # Enable plaintext HTTP listen for the Developer Portal API
1243 # Set a nodePort which is available if service type is NodePort
1245 # Additional listen parameters, e.g. "reuseport", "backlog=16384"
1248 # Enable HTTPS listen for the Developer Portal API
1252 # Set a nodePort which is available if service type is NodePort
1254 # Additional listen parameters, e.g. "reuseport", "backlog=16384"
1258 # Enable/disable exposure using ingress.
1262 # tls: kong-portalapi.example.com-tls
1265 # Map of ingress annotations.
1269 # Each path in an Ingress is required to have a corresponding path type. (ImplementationSpecific/Exact/Prefix)
1270 pathType: ImplementationSpecific
1273 # To specify annotations or labels for the cluster telemetry service, add them to the respective
1274 # "annotations" or "labels" dictionaries below.
1276 # service.beta.kubernetes.io/aws-load-balancer-proxy-protocol: "*"
1287 trafficDistribution:
1288 # Kong clustertelemetry ingress settings. Useful if you want to split
1289 # CP and DP in different clusters.
1291 # Enable/disable exposure using ingress.
1295 # tls: kong-clustertelemetry.example.com-tls
1298 # Map of ingress annotations.
1302 # Each path in an Ingress is required to have a corresponding path type. (ImplementationSpecific/Exact/Prefix)
1303 pathType: ImplementationSpecific
1306# - name: my-config-map
1307# mountPath: /mount/to/my/location
1308# subPath: my-subpath # Optional, if you wish to mount a single key and not the entire ConfigMap
1313# mountPath: /mount/to/my/location
1314# subPath: my-subpath # Optional, if you wish to mount a single key and not the entire ConfigMap
1318# - apiVersion: configuration.konghq.com/v1
1319# kind: KongClusterPlugin
1323# per_consumer: false