DirectorySecurity AdvisoriesPricing
Sign in
Directory
mimir-distributed logoHELM

mimir-distributed

Helm chart
Last changed
Request a free trial

Contact our team to test out this Helm chart and related images for free. Please also indicate any other images you would like to evaluate.

Overview
Chart tags
Default values
Chart metadata
Images

Tag:
Compare:

1
# The default values specified in this file are enough to deploy all of the
2
# Grafana Mimir microservices but are not suitable for production load.
3
# To configure the resources for higher scale, refer to the small.yaml file.
4
# For production load with high availability, refer to the large.yaml values file.
5
6
# Note: The values in this file are not backward compatible. Copying and pasting the values is discouraged, but if you do so,
7
# make sure to use the values.yaml from the branch or tag that matches the mimir-distributed Helm chart version that you
8
# want to install. You also can see values.yaml for a specific version by running
9
# `helm show values grafana/mimir-distributed --version <version>`
10
11
# If you want to get the values file from Github, build the URL as follows because we git tag every release:
12
# `https://github.com/grafana/mimir/blob/mimir-distributed-<chart-version>/operations/helm/charts/mimir-distributed/values.yaml`.
13
# For example, https://github.com/grafana/mimir/blob/mimir-distributed-release-6.2/operations/helm/charts/mimir-distributed/values.yaml.
14
15
# -- Overrides the version used to determine compatibility of resources with the target Kubernetes cluster.
16
# This is useful when using `helm template`, because then helm will use the client version of kubectl as the Kubernetes version,
17
# which may or may not match your cluster's server version. Example: 'v1.24.4'. Set to null to use the version that helm
18
# devises.
19
kubeVersionOverride: null
20
# -- Overrides the chart's name. Used to change mimir/enterprise-metrics infix in the resource names. E.g. myRelease-mimir-ingester-1 to myRelease-nameOverride-ingester-1.
21
# This option is used to align resource names with Cortex, when doing a migration from Cortex to Grafana Mimir.
22
# Note: Grafana provided dashboards rely on the default naming and will need changes.
23
nameOverride: null
24
# -- Overrides the chart's computed fullname. Used to change the full prefix of resource names. E.g. myRelease-mimir-ingester-1 to fullnameOverride-ingester-1.
25
# Note: Grafana provided dashboards rely on the default naming and will need changes.
26
fullnameOverride: null
27
image:
28
# -- Grafana Mimir container image repository
29
repository: chainreg.biz/chainguard-private/grafana-mimir
30
# -- Grafana Mimir container image tag
31
# When set it takes precedence over what is defined as "appVersion" in Chart.yaml.
32
# tag: 3.2.0
33
# -- Container pull policy
34
pullPolicy: IfNotPresent
35
# -- Optionally specify an array of imagePullSecrets
36
# Secrets must be manually created in the namespace.
37
# ref: https://kubernetes.io/docs/tasks/configure-pod-container/pull-image-private-registry/
38
# pullSecrets:
39
# - myRegistryKeySecretName
40
41
tag: 3.2.1-r0@sha256:ca3ae0dca04bc84ba01be3034df9312b3e065383f596b7bd01118c327accdfdb
42
global:
43
# -- Definitions to set up nginx resolver
44
dnsService: kube-dns
45
dnsNamespace: kube-system
46
clusterDomain: cluster.local.
47
dnsConfig: {}
48
# -- Common environment variables to add to all pods directly managed by this chart.
49
# scope: alertmanager, compactor, continuous-test, distributor, gateway, ingester, memcached, nginx, overrides-exporter, querier, query-frontend, query-scheduler, ruler, store-gateway, smoke-test
50
extraEnv: []
51
# -- Common source of environment injections to add to all pods directly managed by this chart.
52
# scope: alertmanager, compactor, continuous-test, distributor, gateway, ingester, memcached, nginx, overrides-exporter, querier, query-frontend, query-scheduler, ruler, store-gateway, smoke-test
53
# For example to inject values from a Secret, use:
54
# extraEnvFrom:
55
# - secretRef:
56
# name: mysecret
57
extraEnvFrom: []
58
# -- Common volumes to add to all pods directly managed by this chart.
59
# scope: alertmanager, compactor, continuous-test, distributor, gateway, ingester, memcached, nginx, overrides-exporter, querier, query-frontend, query-scheduler, ruler, store-gateway, smoke-test
60
extraVolumes: []
61
# -- Common mount points to add to all pods directly managed by this chart.
62
# scope: alertmanager, compactor, continuous-test, distributor, gateway, ingester, memcached, nginx, overrides-exporter, querier, query-frontend, query-scheduler, ruler, store-gateway, smoke-test
63
extraVolumeMounts: []
64
# -- Pod annotations for all pods directly managed by this chart. Usable for example to associate a version to 'global.extraEnv' and 'global.extraEnvFrom' and trigger a restart of the affected services.
65
# scope: alertmanager, compactor, distributor, gateway, ingester, memcached, nginx, overrides-exporter, querier, query-frontend, query-scheduler, ruler, store-gateway
66
podAnnotations: {}
67
# -- Pod labels for all pods directly managed by this chart.
68
# scope: alertmanager, compactor, distributor, gateway, ingester, memcached, nginx, overrides-exporter, querier, query-frontend, query-scheduler, ruler, store-gateway
69
podLabels: {}
70
serviceAccount:
71
# -- Whether to create a service account or not. In case 'create' is false, do set 'name' to an existing service account name.
72
create: true
73
# -- Override for the generated service account name.
74
name:
75
annotations: {}
76
labels: {}
77
# -- Configuration is loaded from the secret called 'externalConfigSecretName'. If 'useExternalConfig' is true, then the configuration is not generated, just consumed.
78
useExternalConfig: false
79
# -- Defines what kind of object stores the configuration, a ConfigMap or a Secret.
80
# In order to move sensitive information (such as credentials) from the ConfigMap/Secret to a more secure location (e.g. vault), it is possible to use [environment variables in the configuration](https://grafana.com/docs/mimir/latest/reference-configuration-parameters/#use-environment-variables-in-the-configuration).
81
# Such environment variables can be then stored in a separate Secret and injected via the global.extraEnvFrom value. For details about environment injection from a Secret please see [Secrets](https://kubernetes.io/docs/concepts/configuration/secret/#use-case-as-container-environment-variables).
82
configStorageType: ConfigMap
83
# -- Name of the Secret or ConfigMap that contains the configuration (used for naming even if config is internal).
84
externalConfigSecretName: '{{ include "mimir.resourceName" (dict "ctx" . "component" "config") }}'
85
# -- When 'useExternalConfig' is true, then changing 'externalConfigVersion' triggers restart of services - otherwise changes to the configuration cause a restart.
86
externalConfigVersion: "0"
87
# --Vault Agent config to mount secrets to TLS configurable components. This requires Vault and Vault Agent to already be running.
88
vaultAgent:
89
enabled: false
90
# -- Vault Kubernetes Authentication role
91
roleName: ""
92
# -- Path to client certificate in Vault
93
clientCertPath: ""
94
# -- Path to client key in Vault
95
clientKeyPath: ""
96
# -- Path to server certificate in Vault
97
serverCertPath: ""
98
# -- Path to server key in Vault
99
serverKeyPath: ""
100
# -- Path to client CA certificate in Vault
101
caCertPath: ""
102
mimir:
103
# -- Base config file for Grafana Mimir. Contains Helm templates that are evaulated at install/upgrade.
104
# To modify the resulting configuration, either copy and alter 'mimir.config' as a whole or use the 'mimir.structuredConfig' to add and modify certain YAML elements.
105
config: |
106
usage_stats:
107
installation_mode: helm
108
109
activity_tracker:
110
filepath: /active-query-tracker/activity.log
111
112
alertmanager:
113
data_dir: /data
114
enable_api: true
115
external_url: /alertmanager
116
{{- if .Values.alertmanager.zoneAwareReplication.enabled }}
117
sharding_ring:
118
zone_awareness_enabled: true
119
{{- end }}
120
{{- if .Values.alertmanager.fallbackConfig }}
121
fallback_config_file: /configs/alertmanager_fallback_config.yaml
122
{{- end }}
123
124
{{- if .Values.minio.enabled }}
125
alertmanager_storage:
126
backend: s3
127
s3:
128
access_key_id: {{ .Values.minio.rootUser }}
129
bucket_name: {{ include "mimir.minioBucketPrefix" . }}-ruler
130
endpoint: {{ template "minio.fullname" .Subcharts.minio }}.{{ .Release.Namespace }}.svc:{{ .Values.minio.service.port }}
131
insecure: true
132
secret_access_key: {{ .Values.minio.rootPassword }}
133
{{- end }}
134
135
# This configures how the store-gateway synchronizes blocks stored in the bucket. It uses Minio by default for getting started (configured via flags) but this should be changed for production deployments.
136
blocks_storage:
137
backend: s3
138
bucket_store:
139
{{- if index .Values "chunks-cache" "enabled" }}
140
chunks_cache:
141
backend: memcached
142
memcached:
143
addresses: {{ include "mimir.chunksCacheAddress" . }}
144
max_item_size: {{ mul (index .Values "chunks-cache").maxItemMemory 1024 1024 }}
145
timeout: 750ms
146
max_idle_connections: 150
147
{{- end }}
148
{{- if index .Values "index-cache" "enabled" }}
149
index_cache:
150
backend: memcached
151
memcached:
152
addresses: {{ include "mimir.indexCacheAddress" . }}
153
max_item_size: {{ mul (index .Values "index-cache").maxItemMemory 1024 1024 }}
154
timeout: 750ms
155
max_idle_connections: 150
156
{{- end }}
157
{{- if index .Values "metadata-cache" "enabled" }}
158
metadata_cache:
159
backend: memcached
160
memcached:
161
addresses: {{ include "mimir.metadataCacheAddress" . }}
162
max_item_size: {{ mul (index .Values "metadata-cache").maxItemMemory 1024 1024 }}
163
max_idle_connections: 150
164
{{- end }}
165
sync_dir: /data/tsdb-sync
166
{{- if .Values.minio.enabled }}
167
s3:
168
access_key_id: {{ .Values.minio.rootUser }}
169
bucket_name: {{ include "mimir.minioBucketPrefix" . }}-tsdb
170
endpoint: {{ template "minio.fullname" .Subcharts.minio }}.{{ .Release.Namespace }}.svc:{{ .Values.minio.service.port }}
171
insecure: true
172
secret_access_key: {{ .Values.minio.rootPassword }}
173
{{- end }}
174
tsdb:
175
dir: /data/tsdb
176
head_compaction_interval: 15m
177
wal_replay_concurrency: 3
178
179
compactor:
180
compaction_interval: 30m
181
deletion_delay: 2h
182
max_closing_blocks_concurrency: 2
183
max_opening_blocks_concurrency: 4
184
symbols_flushers_concurrency: 4
185
first_level_compaction_wait_period: 25m
186
data_dir: "/data"
187
sharding_ring:
188
wait_stability_min_duration: 1m
189
heartbeat_period: 1m
190
heartbeat_timeout: 4m
191
192
distributor:
193
# Increase the default remote write timeout (applied to writing to Kafka too) because writing
194
# to Kafka-compatible backend may be slower than writing directly to ingesters.
195
remote_timeout: 5s
196
ring:
197
heartbeat_period: 1m
198
heartbeat_timeout: 4m
199
200
frontend:
201
parallelize_shardable_queries: true
202
{{- if index .Values "results-cache" "enabled" }}
203
results_cache:
204
backend: memcached
205
memcached:
206
timeout: 500ms
207
addresses: {{ include "mimir.resultsCacheAddress" . }}
208
max_item_size: {{ mul (index .Values "results-cache").maxItemMemory 1024 1024 }}
209
cache_results: true
210
query_sharding_target_series_per_shard: 2500
211
{{- end }}
212
scheduler_address: {{ template "mimir.fullname" . }}-query-scheduler-headless.{{ .Release.Namespace }}.svc:{{ include "mimir.serverGrpcListenPort" . }}
213
214
frontend_worker:
215
grpc_client_config:
216
max_send_msg_size: 419430400 # 400MiB
217
scheduler_address: {{ template "mimir.fullname" . }}-query-scheduler-headless.{{ .Release.Namespace }}.svc:{{ include "mimir.serverGrpcListenPort" . }}
218
219
ingest_storage:
220
enabled: true
221
kafka:
222
{{- if .Values.kafka.enabled }}
223
# Address of Kafka broker to bootstrap the connection.
224
address: {{ template "mimir.fullname" . }}-kafka.{{ .Release.Namespace }}.svc.{{ $.Values.global.clusterDomain }}:{{ $.Values.kafka.service.port }}
225
{{- end }}
226
# Topic name.
227
topic: mimir-ingest
228
# Mimir will auto-create the topic on start up.
229
# The topic MUST be provisioned with no fewer partitions than the maximum number of ingester replicas. The value of 100 is for demo purposes.
230
auto_create_topic_enabled: true
231
auto_create_topic_default_partitions: 100
232
233
ingester:
234
# Disallow Push gRPC API; everything comes through Kafka in the ingest storage architecture.
235
push_grpc_method_enabled: false
236
ring:
237
final_sleep: 0s
238
num_tokens: 512
239
tokens_file_path: /data/tokens
240
unregister_on_shutdown: false
241
heartbeat_period: 2m
242
heartbeat_timeout: 10m
243
{{- if .Values.ingester.zoneAwareReplication.enabled }}
244
zone_awareness_enabled: true
245
{{- end }}
246
247
ingester_client:
248
grpc_client_config:
249
max_recv_msg_size: 104857600
250
max_send_msg_size: 104857600
251
252
limits:
253
# Limit queries to 500 days. You can override this on a per-tenant basis.
254
max_total_query_length: 12000h
255
# Adjust max query parallelism to 16x sharding, without sharding we can run 15d queries fully in parallel.
256
# With sharding we can further shard each day another 16 times. 15 days * 16 shards = 240 subqueries.
257
max_query_parallelism: 240
258
# Avoid caching results newer than 10m because some samples can be delayed
259
# This presents caching incomplete results
260
max_cache_freshness: 10m
261
262
memberlist:
263
abort_if_cluster_join_fails: false
264
compression_enabled: false
265
join_members:
266
- dns+{{ include "mimir.fullname" . }}-gossip-ring.{{ .Release.Namespace }}.svc.{{ .Values.global.clusterDomain }}:{{ include "mimir.memberlistBindPort" . }}
267
268
querier:
269
max_concurrent: 8
270
271
query_scheduler:
272
# Increase from default of 100 to account for queries created by query sharding
273
max_outstanding_requests_per_tenant: 800
274
275
ruler:
276
alertmanager_url: dnssrvnoa+http://_http-metrics._tcp.{{ template "mimir.fullname" . }}-alertmanager-headless.{{ .Release.Namespace }}.svc.{{ .Values.global.clusterDomain }}/alertmanager
277
enable_api: true
278
rule_path: /data
279
{{- if .Values.ruler.remoteEvaluationDedicatedQueryPath }}
280
query_frontend:
281
address: dns:///{{ template "mimir.fullname" . }}-ruler-query-frontend.{{ .Release.Namespace }}.svc:{{ include "mimir.serverGrpcListenPort" . }}
282
{{- end }}
283
284
{{- if or (.Values.minio.enabled) (index .Values "metadata-cache" "enabled") }}
285
ruler_storage:
286
{{- if .Values.minio.enabled }}
287
backend: s3
288
s3:
289
endpoint: {{ template "minio.fullname" .Subcharts.minio }}.{{ .Release.Namespace }}.svc:{{ .Values.minio.service.port }}
290
bucket_name: {{ include "mimir.minioBucketPrefix" . }}-ruler
291
access_key_id: {{ .Values.minio.rootUser }}
292
secret_access_key: {{ .Values.minio.rootPassword }}
293
insecure: true
294
{{- end }}
295
{{- if index .Values "metadata-cache" "enabled" }}
296
cache:
297
backend: memcached
298
memcached:
299
addresses: {{ include "mimir.metadataCacheAddress" . }}
300
max_item_size: {{ mul (index .Values "metadata-cache").maxItemMemory 1024 1024 }}
301
timeout: 500ms
302
{{- end }}
303
{{- end }}
304
305
runtime_config:
306
file: /var/{{ include "mimir.name" . }}/runtime.yaml
307
308
store_gateway:
309
sharding_ring:
310
heartbeat_period: 1m
311
heartbeat_timeout: 10m
312
wait_stability_min_duration: 1m
313
{{- if .Values.store_gateway.zoneAwareReplication.enabled }}
314
kvstore:
315
prefix: multi-zone/
316
{{- end }}
317
tokens_file_path: /data/tokens
318
unregister_on_shutdown: false
319
{{- if .Values.store_gateway.zoneAwareReplication.enabled }}
320
zone_awareness_enabled: true
321
{{- end }}
322
# -- Additional structured values on top of the text based 'mimir.config'. Applied after the text based config is evaluated for templates. Enables adding and modifying YAML elements in the evaulated 'mimir.config'.
323
#
324
# Additionally, consider the optional "insecure_skip_verify" key below, it allows you to skip_verify_false in case the s3_endpoint certificate is not trusted.
325
# For more information see https://grafana.com/docs/mimir/latest/references/configuration-parameters/
326
#
327
# Example:
328
#
329
# structuredConfig:
330
# common:
331
# storage:
332
# backend: s3
333
# s3:
334
# bucket_name: "${BUCKET_NAME}"
335
# endpoint: "${BUCKET_HOST}:${BUCKET_PORT}"
336
# access_key_id: "${AWS_ACCESS_KEY_ID}" # This is a secret injected via an environment variable
337
# secret_access_key: "${AWS_SECRET_ACCESS_KEY}" # This is a secret injected via an environment variable
338
# http:
339
# insecure_skip_verify: true
340
structuredConfig: {}
341
# -- runtimeConfig provides a reloadable runtime configuration. Changing the runtimeConfig doesn't require a restart of all components.
342
# For more infromation see https://grafana.com/docs/mimir/latest/configure/about-runtime-configuration/
343
#
344
# Example:
345
#
346
# runtimeConfig:
347
# ingester_limits: # limits that each ingester replica enforces
348
# max_ingestion_rate: 20000
349
# max_series: 1500000
350
# max_tenants: 1000
351
# max_inflight_push_requests: 30000
352
# distributor_limits: # limits that each distributor replica enforces
353
# max_ingestion_rate: 20000
354
# max_inflight_push_requests: 30000
355
# max_inflight_push_requests_bytes: 50000000
356
# overrides:
357
# tenant-1: # limits for tenant-1 that the whole cluster enforces
358
# ingestion_tenant_shard_size: 9
359
# max_global_series_per_user: 1500000
360
# max_fetched_series_per_query: 100000
361
runtimeConfig: {}
362
# RBAC configuration
363
rbac:
364
# -- If true, PodSecurityPolicy will be rendered by the chart on Kubernetes 1.24.
365
# By default the PodSecurityPolicy is not rendered on version 1.24.
366
create: true
367
# -- PSP configuration
368
podSecurityPolicy:
369
seccompProfile: runtime/default
370
privileged: false
371
allowPrivilegeEscalation: false
372
hostNetwork: false
373
hostIPC: false
374
hostPID: false
375
readOnlyRootFilesystem: true
376
runAsUser:
377
rule: "MustRunAsNonRoot"
378
seLinux:
379
rule: "RunAsAny"
380
supplementalGroups:
381
rule: "MustRunAs"
382
ranges:
383
- min: 1
384
max: 65535
385
fsGroup:
386
rule: "MustRunAs"
387
ranges:
388
- min: 1
389
max: 65535
390
additionalVolumes: []
391
forcePSPOnKubernetes124: false
392
# -- For GKE/EKS/AKS use 'type: psp'. For OpenShift use 'type: scc'
393
type: psp
394
# -- podSecurityContext is the default pod security context for Mimir, gateway, and cache components.
395
# When installing on OpenShift, override podSecurityContext settings with
396
#
397
# rbac:
398
# podSecurityContext:
399
# fsGroup: null
400
# runAsGroup: null
401
# runAsUser: null
402
podSecurityContext:
403
fsGroup: 10001
404
runAsGroup: 10001
405
runAsNonRoot: true
406
runAsUser: 10001
407
seccompProfile:
408
type: RuntimeDefault
409
# -- KEDA Autoscaling configuration
410
kedaAutoscaling:
411
# -- A Prometheus-compatible URL. Cadvisor and Mimir metrics for the Mimir pods are expected in this server.
412
# For more information on the required metrics see [Monitor system health](https://grafana.com/docs/helm-charts/mimir-distributed/latest/run-production-environment-with-helm/monitor-system-health/).
413
# If empty, the helm chart uses the metamonitoring URL from metaMonitoring.grafanaAgent.metrics.remote.url.
414
# If that is empty, then the Mimir cluster is used.
415
prometheusAddress: ""
416
customHeaders: {}
417
pollingInterval: 10
418
ignoreNullValues: true
419
unsafeSsl: false
420
# If your metrics are stored in a datasource with multiple mimir instances extra labels to filter the data are required to get the right metric.
421
toPromQLLabelSelector:
422
# - cluster!="eu-west"
423
# - app="foobar"
424
425
# -- KEDA fallback configuration. This section specifies fallback options when the scaler fails to get metrics from the source.
426
# For more information, refer to the [KEDA ScaledObject specification](https://keda.sh/docs/2.18/reference/scaledobject-spec/).
427
fallback:
428
# -- Enable fallback behavior when the scaler fails to get metrics.
429
enabled: false
430
# failureThreshold: 3 # Number of consecutive failures before activating fallback behavior
431
# replicas: 6 # Number of replicas to scale to when fallback is triggered
432
# behavior: "static" # Fallback behavior type. Options: "static", "currentReplicas", "currentReplicasIfHigher", "currentReplicasIfLower"
433
# # static: Use the fallback.replicas value
434
# # currentReplicas: Use the current replica count
435
# # currentReplicasIfHigher: Use current replicas if higher than fallback.replicas, otherwise use fallback.replicas
436
# # currentReplicasIfLower: Use current replicas if lower than fallback.replicas, otherwise use fallback.replicas
437
# --KEDA trigger authentication settings.
438
# ref: https://keda.sh/docs/2.16/scalers/pulsar/#authentication-parameters
439
authentication:
440
enabled: false
441
authModes: ""
442
secretTargetRef: []
443
# - key: username
444
# name: my-secret-name
445
# parameter: username
446
# - key: password
447
# name: my-secret-name
448
# parameter: password
449
alertmanager:
450
enabled: true
451
# -- Total number of replicas for the alertmanager across all availability zones
452
# If alertmanager.zoneAwareReplication.enabled=false, this number is taken as is.
453
# Otherwise each zone starts `ceil(replicas / number_of_zones)` number of pods.
454
# E.g. if 'replicas' is set to 4 and there are 3 zones, then 4/3=1.33 and after rounding up it means 2 pods per zone are started.
455
replicas: 1
456
revisionHistoryLimit: null
457
# -- Allows to override the container image of the alertmanager component.
458
# When set it takes precedence over what is defined in global "image".
459
image:
460
# repository: grafana/mimir
461
# tag: 3.2.0
462
statefulSet:
463
enabled: true
464
# -- Dedicated service account for alertmanager pods.
465
# If not set, the default service account defined at the begining of this file will be used.
466
# This service account can be used even if the default one is not set.
467
serviceAccount:
468
create: false
469
# -- Alertmanager specific service account name. If not set and create is set to true, the default
470
# name will be the default mimir service account's name with the "-alertmanager" suffix.
471
name: ""
472
annotations: {}
473
labels: {}
474
service:
475
annotations: {}
476
labels: {}
477
# -- https://kubernetes.io/docs/concepts/services-networking/service-traffic-policy/
478
internalTrafficPolicy: Cluster
479
type: ClusterIP
480
extraPorts: []
481
# - port: 11811
482
# protocol: TCP
483
# name: reverse-proxy
484
# targetPort: 11811
485
# -- Optionally set the scheduler for pods of the alertmanager
486
schedulerName: ""
487
resources:
488
requests:
489
cpu: 10m
490
memory: 32Mi
491
# -- Fallback config for alertmanager.
492
# When a tenant doesn't have an Alertmanager configuration, the Grafana Mimir Alertmanager uses the fallback configuration.
493
fallbackConfig: |
494
receivers:
495
- name: default-receiver
496
route:
497
receiver: default-receiver
498
extraArgs: {}
499
# Pod Labels
500
podLabels: {}
501
# Pod Annotations
502
podAnnotations: {}
503
# -- Pod Disruption Budget for alertmanager, this will be applied across availability zones to prevent losing redundancy
504
podDisruptionBudget:
505
maxUnavailable: 1
506
# -- The name of the PriorityClass for alertmanager pods
507
priorityClassName: null
508
dnsConfig: {}
509
# -- NodeSelector to pin alertmanager pods to certain set of nodes. This is ignored when alertmanager.zoneAwareReplication.enabled=true.
510
nodeSelector: {}
511
# -- Pod affinity settings for the alertmanager. This is ignored when alertmanager.zoneAwareReplication.enabled=true.
512
affinity: {}
513
# -- topologySpreadConstraints allows to customize the default topologySpreadConstraints. This can be either a single dict as shown below or a slice of topologySpreadConstraints.
514
# labelSelector is taken from the constraint itself (if it exists) or is generated by the chart using the same selectors as for services.
515
topologySpreadConstraints:
516
maxSkew: 1
517
topologyKey: kubernetes.io/hostname
518
whenUnsatisfiable: ScheduleAnyway
519
# minDomains: 1
520
# nodeAffinityPolicy: Honor
521
# nodeTaintsPolicy: Honor
522
# matchLabelKeys:
523
# - pod-template-hash
524
annotations: {}
525
persistence:
526
# SubPath in emptyDir for persistence, only enabled if alertmanager.statefulSet.enabled is false
527
subPath:
528
persistentVolume:
529
# If true and alertmanager.statefulSet.enabled is true,
530
# Alertmanager will create/use a Persistent Volume Claim
531
# If false, use emptyDir
532
enabled: true
533
# Alertmanager data Persistent Volume Claim template name
534
#
535
name: storage
536
# Alertmanager data Persistent Volume Claim annotations
537
#
538
annotations: {}
539
# Alertmanager data Persistent Volume Claim labels
540
#
541
labels: {}
542
# Alertmanager data Persistent Volume access modes
543
# Must match those of existing PV or dynamic provisioner
544
# Ref: http://kubernetes.io/docs/user-guide/persistent-volumes/
545
#
546
accessModes:
547
- ReadWriteOnce
548
# Alertmanager data Persistent Volume size
549
#
550
size: 1Gi
551
# Subdirectory of Alertmanager data Persistent Volume to mount
552
# Useful if the volume's root directory is not empty
553
#
554
subPath: ""
555
# Alertmanager data Persistent Volume Storage Class
556
# If defined, storageClassName: <storageClass>
557
# If set to "-", storageClassName: "", which disables dynamic provisioning
558
# If undefined (the default) or set to null, no storageClassName spec is
559
# set, choosing the default provisioner.
560
#
561
# A per-zone storageClass configuration in `alertmanager.zoneAwareReplication.zones[*].storageClass` takes precedence over this field.
562
# storageClass: "-"
563
564
# Alertmanager data Persistent Volume Attributes Class
565
# Allows you to dynamically modify a volume's attributes on the fly
566
# Requires Kubernetes 1.31+ and a CSI driver with ModifyVolume support.
567
# Must reference an existing cluster VolumeAttributesClass.
568
# A per-zone volumeAttributesClassName in `alertmanager.zoneAwareReplication.zones[*].volumeAttributesClassName` takes precedence over this field when set.
569
# volumeAttributesClassName: my-cluster-vac
570
571
# -- Enable StatefulSetAutoDeletePVC feature
572
# https://kubernetes.io/docs/concepts/workloads/controllers/statefulset/#persistentvolumeclaim-retention
573
enableRetentionPolicy: false
574
whenDeleted: Retain
575
whenScaled: Retain
576
readinessProbe:
577
httpGet:
578
path: /ready
579
port: http-metrics
580
initialDelaySeconds: 45
581
# -- SecurityContext override for alermeneger pods
582
securityContext: {}
583
# -- The SecurityContext for alertmanager containers
584
containerSecurityContext:
585
allowPrivilegeEscalation: false
586
readOnlyRootFilesystem: true
587
capabilities:
588
drop: [ALL]
589
# Tolerations for pod assignment
590
# ref: https://kubernetes.io/docs/concepts/configuration/taint-and-toleration/
591
tolerations: []
592
strategy:
593
type: RollingUpdate
594
rollingUpdate:
595
maxSurge: 0
596
maxUnavailable: 1
597
# -- updateStrategy of the alertmanager statefulset. This is ignored when alertmanager.zoneAwareReplication.enabled=true.
598
statefulStrategy:
599
type: RollingUpdate
600
terminationGracePeriodSeconds: 900
601
initContainers: []
602
# Init containers to be added to the alertmanager pod.
603
# - name: my-init-container
604
# image: busybox:latest
605
# command: ['sh', '-c', 'echo hello']
606
607
extraContainers: []
608
# Additional containers to be added to the alertmanager pod.
609
# - name: reverse-proxy
610
# image: angelbarrera92/basic-auth-reverse-proxy:dev
611
# args:
612
# - "serve"
613
# - "--upstream=http://localhost:3100"
614
# - "--auth-config=/etc/reverse-proxy-conf/authn.yaml"
615
# ports:
616
# - name: http
617
# containerPort: 11811
618
# protocol: TCP
619
# volumeMounts:
620
# - name: reverse-proxy-auth-config
621
# mountPath: /etc/reverse-proxy-conf
622
623
extraVolumes: []
624
# Additional volumes to the alertmanager pod.
625
# - name: reverse-proxy-auth-config
626
# secret:
627
# secretName: reverse-proxy-auth-config
628
629
# Extra volume mounts that will be added to the alertmanager container
630
extraVolumeMounts: []
631
# Extra env variables to pass to the alertmanager container
632
env: []
633
extraEnvFrom: []
634
# -- Options to configure zone-aware replication for alertmanager
635
# Example configuration with full geographical redundancy:
636
# rollout_operator:
637
# enabled: true
638
# alertmanager:
639
# zoneAwareReplication:
640
# enabled: true
641
# topologyKey: 'kubernetes.io/hostname' # This generates default anti-affinity rules
642
# zones: # Zone list has to be fully redefined for modification. Update with you actual zones or skip to use logical zones only.
643
# - name: zone-a
644
# nodeSelector:
645
# topology.kubernetes.io/zone: us-central1-a
646
# - name: zone-b
647
# nodeSelector:
648
# topology.kubernetes.io/zone: us-central1-b
649
# - name: zone-c
650
# nodeSelector:
651
# topology.kubernetes.io/zone: us-central1-c
652
#
653
zoneAwareReplication:
654
# -- Enable zone-aware replication for alertmanager
655
enabled: false
656
# -- Maximum number of alertmanagers that can be unavailable per zone during rollout
657
maxUnavailable: 2
658
# -- topologyKey to use in pod anti-affinity. If unset, no anti-affinity rules are generated. If set, the generated anti-affinity rule makes sure that pods from different zones do not mix.
659
# E.g.: topologyKey: 'kubernetes.io/hostname'
660
topologyKey: null
661
# -- Auxiliary values for migration, see https://grafana.com/docs/helm-charts/mimir-distributed/latest/migration-guides/migrate-from-single-zone-with-helm/
662
migration:
663
# -- Indicate if migration is ongoing for multi zone alertmanager
664
enabled: false
665
# -- Start zone-aware alertmanagers
666
writePath: false
667
# -- Zone definitions for alertmanager zones. Note: you have to redefine the whole list to change parts as YAML does not allow to modify parts of a list.
668
zones:
669
# -- Name of the zone, used in labels and selectors. Must follow Kubernetes naming restrictions: https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/
670
- name: zone-a
671
# -- nodeselector to restrict where pods of this zone can be placed. E.g.:
672
# nodeSelector:
673
# topology.kubernetes.io/zone: zone-a
674
nodeSelector: null
675
# -- extraAffinity adds user defined custom affinity rules (merged with generated rules)
676
extraAffinity: {}
677
# -- Alertmanager data Persistent Volume Storage Class
678
# If defined, storageClassName: <storageClass>
679
# If set to "-", then use `storageClassName: ""`, which disables dynamic provisioning
680
# If undefined or set to null (the default), then fall back to the value of `alertmanager.persistentVolume.storageClass`.
681
storageClass: null
682
# -- Persistent Volume VolumeAttributesClass for this zone.
683
# If undefined or set to null (the default), then fall back to the component `persistentVolume.volumeAttributesClassName`.
684
volumeAttributesClassName: null
685
# -- noDownscale adds a label that can be used by the rollout-operator as documented in the rollout-operator repo: https://github.com/grafana/rollout-operator#webhooks
686
noDownscale: false
687
# -- downscaleLeader is an Annotation used by the rollout-operator to coordinate downscaling across zones.
688
# Set to the StatefulSet name that should lead downscaling for this component (typically the previous zone).
689
# Example: "mimir-alertmanager-zone-a" for zone-b, "mimir-alertmanager-zone-b" for zone-c.
690
# If undefined or set to null (the default), this zone won't be designated as a downscale leader.
691
downscaleLeader: null
692
# -- Name of the zone, used in labels and selectors. Must follow Kubernetes naming restrictions: https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/
693
- name: zone-b
694
# -- nodeselector to restrict where pods of this zone can be placed. E.g.:
695
# nodeSelector:
696
# topology.kubernetes.io/zone: zone-b
697
nodeSelector: null
698
# -- extraAffinity adds user defined custom affinity rules (merged with generated rules)
699
extraAffinity: {}
700
# -- Alertmanager data Persistent Volume Storage Class
701
# If defined, storageClassName: <storageClass>
702
# If set to "-", then use `storageClassName: ""`, which disables dynamic provisioning
703
# If undefined or set to null (the default), then fall back to the value of `alertmanager.persistentVolume.storageClass`.
704
storageClass: null
705
# -- Persistent Volume VolumeAttributesClass for this zone.
706
# If undefined or set to null (the default), then fall back to the component `persistentVolume.volumeAttributesClassName`.
707
volumeAttributesClassName: null
708
# -- noDownscale adds a label that can be used by the rollout-operator as documented in the rollout-operator repo: https://github.com/grafana/rollout-operator#webhooks
709
noDownscale: false
710
# -- downscaleLeader is an Annotation used by the rollout-operator to coordinate downscaling across zones.
711
# Set to the StatefulSet name that should lead downscaling for this component (typically the previous zone).
712
# Example: "mimir-alertmanager-zone-a" for zone-b, "mimir-alertmanager-zone-b" for zone-c.
713
# If undefined or set to null (the default), this zone won't be designated as a downscale leader.
714
downscaleLeader: null
715
# -- Name of the zone, used in labels and selectors. Must follow Kubernetes naming restrictions: https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/
716
- name: zone-c
717
# -- nodeselector to restrict where pods of this zone can be placed. E.g.:
718
# nodeSelector:
719
# topology.kubernetes.io/zone: zone-c
720
nodeSelector: null
721
# -- extraAffinity adds user defined custom affinity rules (merged with generated rules)
722
extraAffinity: {}
723
# -- Alertmanager data Persistent Volume Storage Class
724
# If defined, storageClassName: <storageClass>
725
# If set to "-", then use `storageClassName: ""`, which disables dynamic provisioning
726
# If undefined or set to null (the default), then fall back to the value of `alertmanager.persistentVolume.storageClass`.
727
storageClass: null
728
# -- Persistent Volume VolumeAttributesClass for this zone.
729
# If undefined or set to null (the default), then fall back to the component `persistentVolume.volumeAttributesClassName`.
730
volumeAttributesClassName: null
731
# -- noDownscale adds a label that can be used by the rollout-operator as documented in the rollout-operator repo: https://github.com/grafana/rollout-operator#webhooks
732
noDownscale: false
733
# -- downscaleLeader is an Annotation used by the rollout-operator to coordinate downscaling across zones.
734
# Set to the StatefulSet name that should lead downscaling for this component (typically the previous zone).
735
# Example: "mimir-alertmanager-zone-a" for zone-b, "mimir-alertmanager-zone-b" for zone-c.
736
# If undefined or set to null (the default), this zone won't be designated as a downscale leader.
737
downscaleLeader: null
738
distributor:
739
# -- Whether to render the manifests related to the distributor component.
740
enabled: true
741
# -- Allows to override the container image of the distributor component.
742
# When set it takes precedence over what is defined in global "image".
743
image:
744
# repository: grafana/mimir
745
# tag: 3.2.0
746
747
# Setting it to null will produce a deployment without replicas set, allowing you to use autoscaling with the deployment
748
replicas: 1
749
revisionHistoryLimit: null
750
# -- [Experimental] Configure autoscaling via KEDA (https://keda.sh). This requires having
751
# KEDA already installed in the Kubernetes cluster. The metrics for scaling are read
752
# according to top-level kedaAutoscaling.prometheusAddress (defaulting to metamonitoring remote-write destination).
753
# Basic auth and extra HTTP headers from metaMonitoring are ignored, please use customHeaders.
754
# The remote URL is used even if metamonitoring is disabled.
755
# For more details about migrating to autoscaling, refer to https://grafana.com/docs/helm-charts/mimir-distributed/latest/configure/configure-autoscaling/#migrate-existing-deployments
756
kedaAutoscaling:
757
enabled: false
758
# -- preserveReplicas gives you the option to migrate from non-autoscaled to autoscaled deployments without losing replicas. When set to true, the replica fields in the component will be left intact.
759
# For more details about migrating to autoscaling, refer to https://grafana.com/docs/helm-charts/mimir-distributed/latest/configure/configure-autoscaling/#migrate-existing-deployments
760
preserveReplicas: false
761
minReplicaCount: 1
762
maxReplicaCount: 10
763
# -- Target CPU utilization percentage for KEDA autoscaling. This controls the headroom each pod has compared to its current usage.
764
# targetting lower percentages overprovisions the containers, so they can handle bursts of traffic and tolerate failures without waiting to scale out.
765
targetCPUUtilizationPercentage: 100
766
# -- Target memory utilization percentage for KEDA autoscaling. This controls the headroom each pod has compared to its current usage.
767
# targetting lower percentages overprovisions the containers, so they can handle bursts of traffic and tolerate failures without waiting to scale out.
768
targetMemoryUtilizationPercentage: 100
769
behavior:
770
scaleDown:
771
policies:
772
- periodSeconds: 600
773
type: Percent
774
value: 10
775
# -- Fallback configuration for this component. If not set (null), the global kedaAutoscaling.fallback configuration is used.
776
# fallback: {}
777
service:
778
annotations: {}
779
labels: {}
780
# -- https://kubernetes.io/docs/concepts/services-networking/service-traffic-policy/
781
internalTrafficPolicy: Cluster
782
type: ClusterIP
783
extraPorts: []
784
# -- https://kubernetes.io/docs/concepts/services-networking/service/#traffic-distribution
785
trafficDistribution: ""
786
resources:
787
requests:
788
cpu: 100m
789
memory: 512Mi
790
# Additional distributor container arguments, e.g. log level (debug, info, warn, error)
791
extraArgs: {}
792
# Pod Labels
793
podLabels: {}
794
# Pod Annotations
795
podAnnotations: {}
796
# Pod Disruption Budget
797
podDisruptionBudget:
798
maxUnavailable: 1
799
# -- The name of the PriorityClass for distributor pods
800
priorityClassName: null
801
dnsConfig: {}
802
nodeSelector: {}
803
affinity: {}
804
# -- topologySpreadConstraints allows to customize the default topologySpreadConstraints. This can be either a single dict as shown below or a slice of topologySpreadConstraints.
805
# labelSelector is taken from the constraint itself (if it exists) or is generated by the chart using the same selectors as for services.
806
topologySpreadConstraints:
807
maxSkew: 1
808
topologyKey: kubernetes.io/hostname
809
whenUnsatisfiable: ScheduleAnyway
810
# minDomains: 1
811
# nodeAffinityPolicy: Honor
812
# nodeTaintsPolicy: Honor
813
# matchLabelKeys:
814
# - pod-template-hash
815
annotations: {}
816
persistence:
817
subPath:
818
readinessProbe:
819
httpGet:
820
path: /ready
821
port: http-metrics
822
initialDelaySeconds: 45
823
# -- SecurityContext override for distributor pods
824
securityContext: {}
825
# -- The SecurityContext for distributor containers
826
containerSecurityContext:
827
allowPrivilegeEscalation: false
828
readOnlyRootFilesystem: true
829
capabilities:
830
drop: [ALL]
831
strategy:
832
type: RollingUpdate
833
rollingUpdate:
834
maxUnavailable: 0
835
maxSurge: 15%
836
# Keep the termination grace period higher than the -shutdown-delay configured on the distributor.
837
terminationGracePeriodSeconds: 100
838
tolerations: []
839
initContainers: []
840
extraContainers: []
841
extraVolumes: []
842
extraVolumeMounts: []
843
env: []
844
extraEnvFrom: []
845
ingester:
846
# -- Whether to render the manifests related to the ingester component.
847
enabled: true
848
# -- Allows to override the container image of the ingester component.
849
# When set it takes precedence over what is defined in global "image".
850
image:
851
# repository: grafana/mimir
852
# tag: 3.2.0
853
854
# -- Total number of replicas for the ingester across all availability zones
855
# If ingester.zoneAwareReplication.enabled=false, this number is taken as is.
856
# Otherwise each zone starts `ceil(replicas / number_of_zones)` number of pods.
857
# E.g. if 'replicas' is set to 4 and there are 3 zones, then 4/3=1.33 and after rounding up it means 2 pods per zone are started.
858
replicas: 3
859
revisionHistoryLimit: null
860
statefulSet:
861
enabled: true
862
service:
863
annotations: {}
864
labels: {}
865
# -- https://kubernetes.io/docs/concepts/services-networking/service-traffic-policy/
866
internalTrafficPolicy: Cluster
867
type: ClusterIP
868
extraPorts: []
869
# -- https://kubernetes.io/docs/concepts/services-networking/service/#traffic-distribution
870
# Note: This service is only used for admin endpoints like TSDB statistics, not for write or read path traffic.
871
trafficDistribution: ""
872
# -- Optionally set the scheduler for pods of the ingester
873
schedulerName: ""
874
resources:
875
requests:
876
cpu: 100m
877
memory: 512Mi
878
# Additional ingester container arguments, e.g. log level (debug, info, warn, error)
879
extraArgs: {}
880
# Pod Labels
881
podLabels: {}
882
# Pod Annotations
883
podAnnotations: {}
884
# -- The name of the PriorityClass for ingester pods
885
priorityClassName: null
886
# -- Pod Disruption Budget for ingester, this will be applied across availability zones to prevent losing redundancy
887
podDisruptionBudget:
888
maxUnavailable: 1
889
podManagementPolicy: Parallel
890
# -- NodeSelector to pin ingester pods to certain set of nodes. This is ignored when ingester.zoneAwareReplication.enabled=true.
891
nodeSelector: {}
892
# -- Pod affinity settings for the ingester. This is ignored when ingester.zoneAwareReplication.enabled=true.
893
affinity: {}
894
dnsConfig: {}
895
# -- topologySpreadConstraints allows to customize the default topologySpreadConstraints. This can be either a single dict as shown below or a slice of topologySpreadConstraints.
896
# labelSelector is taken from the constraint itself (if it exists) or is generated by the chart using the same selectors as for services.
897
# It is recommended to replace this with requiredDuringSchedulingIgnoredDuringExecution podAntiAffinity rules when
898
# deploying to production.
899
topologySpreadConstraints:
900
maxSkew: 1
901
topologyKey: kubernetes.io/hostname
902
whenUnsatisfiable: ScheduleAnyway
903
# minDomains: 1
904
# nodeAffinityPolicy: Honor
905
# nodeTaintsPolicy: Honor
906
# matchLabelKeys:
907
# - pod-template-hash
908
annotations: {}
909
persistentVolume:
910
# If true and ingester.statefulSet.enabled is true,
911
# Ingester will create/use a Persistent Volume Claim
912
# If false, use emptyDir
913
# It is advisable to enable volume persistence in ingester to avoid losing metrics.
914
#
915
enabled: true
916
# Ingester data Persistent Volume Claim template name
917
#
918
name: storage
919
# Ingester data Persistent Volume Claim annotations
920
#
921
annotations: {}
922
# Ingester data Persistent Volume Claim labels
923
#
924
labels: {}
925
# Ingester data Persistent Volume access modes
926
# Must match those of existing PV or dynamic provisioner
927
# Ref: http://kubernetes.io/docs/user-guide/persistent-volumes/
928
accessModes:
929
- ReadWriteOnce
930
# Ingester data Persistent Volume size
931
size: 2Gi
932
# Subdirectory of Ingester data Persistent Volume to mount
933
# Useful if the volume's root directory is not empty
934
subPath: ""
935
# -- Enable StatefulSetAutoDeletePVC feature
936
# https://kubernetes.io/docs/concepts/workloads/controllers/statefulset/#persistentvolumeclaim-retention
937
enableRetentionPolicy: false
938
whenDeleted: Retain
939
whenScaled: Retain
940
# Ingester data Persistent Volume Storage Class
941
# If defined, storageClassName: <storageClass>
942
# If set to "-", storageClassName: "", which disables dynamic provisioning
943
# If undefined (the default) or set to null, no storageClassName spec is
944
# set, choosing the default provisioner.
945
#
946
# A per-zone storageClass configuration in `ingester.zoneAwareReplication.zones[*].storageClass` takes precedence over this field.
947
#
948
# storageClass: "-"
949
# Ingester data Persistent Volume Attributes Class
950
# Allows you to dynamically modify a volume's attributes on the fly
951
# Requires Kubernetes 1.31+ and a CSI driver with ModifyVolume support.
952
# Must reference an existing cluster VolumeAttributesClass.
953
# A per-zone volumeAttributesClassName in `ingester.zoneAwareReplication.zones[*].volumeAttributesClassName` takes precedence over this field when set.
954
# volumeAttributesClassName: my-cluster-vac
955
956
livenessProbe: null
957
readinessProbe:
958
httpGet:
959
path: /ready
960
port: http-metrics
961
initialDelaySeconds: 60
962
# -- SecurityContext override for ingester pods
963
securityContext: {}
964
# -- The SecurityContext for ingester containers
965
containerSecurityContext:
966
allowPrivilegeEscalation: false
967
readOnlyRootFilesystem: true
968
capabilities:
969
drop: [ALL]
970
# -- updateStrategy of the ingester statefulset. This is ignored when ingester.zoneAwareReplication.enabled=true.
971
statefulStrategy:
972
type: RollingUpdate
973
terminationGracePeriodSeconds: 1200
974
tolerations: []
975
initContainers: []
976
extraContainers: []
977
extraVolumes: []
978
extraVolumeMounts: []
979
env: []
980
extraEnvFrom: []
981
# -- Options to configure zone-aware replication for ingester
982
# Example configuration with full geographical redundancy:
983
# rollout_operator:
984
# enabled: true
985
# ingester:
986
# zoneAwareReplication:
987
# enabled: true
988
# topologyKey: 'kubernetes.io/hostname' # This generates default anti-affinity rules
989
# zones: # Zone list has to be fully redefined for modification. Update with you actual zones or skip to use logical zones only.
990
# - name: zone-a
991
# nodeSelector:
992
# topology.kubernetes.io/zone: us-central1-a
993
# storageClass: storage-class-us-central1-a
994
# - name: zone-b
995
# nodeSelector:
996
# topology.kubernetes.io/zone: us-central1-b
997
# storageClass: storage-class-us-central1-b
998
# - name: zone-c
999
# nodeSelector:
1000
# topology.kubernetes.io/zone: us-central1-c
1001
# storageClass: storage-class-us-central1-c
1002
#
1003
zoneAwareReplication:
1004
# -- Enable zone-aware replication for ingester
1005
enabled: true
1006
# -- Maximum number of ingesters that can be unavailable per zone during rollout
1007
maxUnavailable: 50
1008
# -- Minimum time for the rollout operator to wait between ingester zone down scales
1009
minTimeBetweenZonesDownscale: 12h
1010
# -- topologyKey to use in pod anti-affinity. If unset, no anti-affinity rules are generated. If set, the generated anti-affinity rule makes sure that pods from different zones do not mix.
1011
# E.g.: topologyKey: 'kubernetes.io/hostname'
1012
topologyKey: null
1013
# -- When true and zone-aware replication is enabled, automatically set the
1014
# -ingest-storage.kafka.client-rack flag on each ingester zone to its zone name.
1015
# This enables Kafka rack-aware consumption so that ingesters prefer reading
1016
# from Kafka replicas in the same availability zone, reducing cross-AZ traffic.
1017
# Set to false if you want to manage client-rack manually via extraArgs.
1018
autoIngestStorageClientRack: true
1019
# -- Auxiliary values for migration, see https://grafana.com/docs/helm-charts/mimir-distributed/latest/migration-guides/migrate-from-single-zone-with-helm/
1020
migration:
1021
# -- Indicate if migration is ongoing for multi zone ingester
1022
enabled: false
1023
# -- Exclude default zone on write path
1024
excludeDefaultZone: false
1025
# -- Enable zone-awareness, read path only
1026
readPath: false
1027
# -- Total number of replicas to start in availability zones when migration is enabled
1028
replicas: 0
1029
# -- Scale default zone ingesters to 0
1030
scaleDownDefaultZone: false
1031
# -- Enable zone-awareness, write path only
1032
writePath: false
1033
# -- Zone definitions for ingester zones. Note: you have to redefine the whole list to change parts as YAML does not allow to modify parts of a list.
1034
# When ingest storage is enabled, 2 zones are sufficient since Kafka handles replication. 3 zones are required for classic (non-ingest-storage) architecture.
1035
zones:
1036
# -- Name of the zone, used in labels and selectors. Must follow Kubernetes naming restrictions: https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/
1037
- name: zone-a
1038
# -- nodeselector to restrict where pods of this zone can be placed. E.g.:
1039
# nodeSelector:
1040
# topology.kubernetes.io/zone: zone-a
1041
nodeSelector: null
1042
# -- extraAffinity adds user defined custom affinity rules (merged with generated rules)
1043
extraAffinity: {}
1044
# -- Ingester data Persistent Volume Storage Class
1045
# If defined, storageClassName: <storageClass>
1046
# If set to "-", then use `storageClassName: ""`, which disables dynamic provisioning
1047
# If undefined or set to null (the default), then fall back to the value of `ingester.persistentVolume.storageClass`.
1048
storageClass: null
1049
# -- Persistent Volume VolumeAttributesClass for this zone.
1050
# If undefined or set to null (the default), then fall back to the component `persistentVolume.volumeAttributesClassName`.
1051
volumeAttributesClassName: null
1052
# -- noDownscale adds a label that can be used by the rollout-operator as documented in the rollout-operator repo: https://github.com/grafana/rollout-operator#webhooks
1053
noDownscale: false
1054
# -- downscaleLeader is an Annotation used by the rollout-operator to coordinate downscaling across zones.
1055
# Set to the StatefulSet name that should lead downscaling for this component (typically the previous zone).
1056
# Example: "mimir-ingester-zone-a" for zone-b, "mimir-ingester-zone-b" for zone-c.
1057
# If undefined or set to null (the default), this zone won't be designated as a downscale leader.
1058
downscaleLeader: null
1059
# -- prepareDownscale adds labels and annotations for the rollout-operator to prepare downscaling: https://github.com/grafana/rollout-operator#how-scaling-up-and-down-works
1060
prepareDownscale: true
1061
# -- Name of the zone, used in labels and selectors. Must follow Kubernetes naming restrictions: https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/
1062
- name: zone-b
1063
# -- nodeselector to restrict where pods of this zone can be placed. E.g.:
1064
# nodeSelector:
1065
# topology.kubernetes.io/zone: zone-b
1066
nodeSelector: null
1067
# -- extraAffinity adds user defined custom affinity rules (merged with generated rules)
1068
extraAffinity: {}
1069
# -- Ingester data Persistent Volume Storage Class
1070
# If defined, storageClassName: <storageClass>
1071
# If set to "-", then use `storageClassName: ""`, which disables dynamic provisioning
1072
# If undefined or set to null (the default), then fall back to the value of `ingester.persistentVolume.storageClass`.
1073
storageClass: null
1074
# -- Persistent Volume VolumeAttributesClass for this zone.
1075
# If undefined or set to null (the default), then fall back to the component `persistentVolume.volumeAttributesClassName`.
1076
volumeAttributesClassName: null
1077
# -- noDownscale adds a label that can be used by the rollout-operator as documented in the rollout-operator repo: https://github.com/grafana/rollout-operator#webhooks
1078
noDownscale: false
1079
# -- downscaleLeader is an Annotation used by the rollout-operator to coordinate downscaling across zones.
1080
# Set to the StatefulSet name that should lead downscaling for this component (typically the previous zone).
1081
# Example: "mimir-ingester-zone-a" for zone-b, "mimir-ingester-zone-b" for zone-c.
1082
# If undefined or set to null (the default), this zone won't be designated as a downscale leader.
1083
downscaleLeader: null
1084
# -- prepareDownscale adds labels and annotations for the rollout-operator to prepare downscaling: https://github.com/grafana/rollout-operator#how-scaling-up-and-down-works
1085
prepareDownscale: true
1086
# -- Name of the zone, used in labels and selectors. Must follow Kubernetes naming restrictions: https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/
1087
- name: zone-c
1088
# -- nodeselector to restrict where pods of this zone can be placed. E.g.:
1089
# nodeSelector:
1090
# topology.kubernetes.io/zone: zone-c
1091
nodeSelector: null
1092
# -- extraAffinity adds user defined custom affinity rules (merged with generated rules)
1093
extraAffinity: {}
1094
# -- Ingester data Persistent Volume Storage Class
1095
# If defined, storageClassName: <storageClass>
1096
# If set to "-", then use `storageClassName: ""`, which disables dynamic provisioning
1097
# If undefined or set to null (the default), then fall back to the value of `ingester.persistentVolume.storageClass`.
1098
storageClass: null
1099
# -- Persistent Volume VolumeAttributesClass for this zone.
1100
# If undefined or set to null (the default), then fall back to the component `persistentVolume.volumeAttributesClassName`.
1101
volumeAttributesClassName: null
1102
# -- noDownscale adds a label that can be used by the rollout-operator as documented in the rollout-operator repo: https://github.com/grafana/rollout-operator#webhooks
1103
noDownscale: false
1104
# -- downscaleLeader is an Annotation used by the rollout-operator to coordinate downscaling across zones.
1105
# Set to the StatefulSet name that should lead downscaling for this component (typically the previous zone).
1106
# Example: "mimir-ingester-zone-a" for zone-b, "mimir-ingester-zone-b" for zone-c.
1107
# If undefined or set to null (the default), this zone won't be designated as a downscale leader.
1108
downscaleLeader: null
1109
# -- prepareDownscale adds labels and annotations for the rollout-operator to prepare downscaling: https://github.com/grafana/rollout-operator#how-scaling-up-and-down-works
1110
prepareDownscale: true
1111
overrides_exporter:
1112
enabled: true
1113
# -- Allows to override the container image of the overrides-exporter component.
1114
# When set it takes precedence over what is defined in global "image".
1115
image:
1116
# repository: grafana/mimir
1117
# tag: 3.2.0
1118
replicas: 1
1119
revisionHistoryLimit: null
1120
annotations: {}
1121
initContainers: []
1122
service:
1123
annotations: {}
1124
labels: {}
1125
# -- https://kubernetes.io/docs/concepts/services-networking/service-traffic-policy/
1126
internalTrafficPolicy: Cluster
1127
type: ClusterIP
1128
extraPorts: []
1129
strategy:
1130
type: RollingUpdate
1131
rollingUpdate:
1132
maxUnavailable: 0
1133
maxSurge: 15%
1134
podLabels: {}
1135
podAnnotations: {}
1136
# Pod Disruption Budget
1137
podDisruptionBudget:
1138
maxUnavailable: 1
1139
# -- The name of the PriorityClass for overrides-exporter pods
1140
priorityClassName: null
1141
dnsConfig: {}
1142
nodeSelector: {}
1143
affinity: {}
1144
# -- topologySpreadConstraints allows to customize the default topologySpreadConstraints. This can be either a single dict as shown below or a slice of topologySpreadConstraints.
1145
# labelSelector is taken from the constraint itself (if it exists) or is generated by the chart using the same selectors as for services.
1146
topologySpreadConstraints: {}
1147
# maxSkew: 1
1148
# topologyKey: kubernetes.io/hostname
1149
# whenUnsatisfiable: ScheduleAnyway
1150
# minDomains: 1
1151
# nodeAffinityPolicy: Honor
1152
# nodeTaintsPolicy: Honor
1153
# matchLabelKeys:
1154
# - pod-template-hash
1155
1156
# -- SecurityContext override for overrides-exporter pods
1157
securityContext: {}
1158
# -- The SecurityContext for overrides-exporter containers
1159
containerSecurityContext:
1160
allowPrivilegeEscalation: false
1161
readOnlyRootFilesystem: true
1162
capabilities:
1163
drop: [ALL]
1164
extraArgs: {}
1165
persistence:
1166
subPath:
1167
livenessProbe:
1168
httpGet:
1169
path: /ready
1170
port: http-metrics
1171
initialDelaySeconds: 45
1172
readinessProbe:
1173
httpGet:
1174
path: /ready
1175
port: http-metrics
1176
initialDelaySeconds: 45
1177
resources:
1178
requests:
1179
cpu: 100m
1180
memory: 128Mi
1181
terminationGracePeriodSeconds: 30
1182
tolerations: []
1183
extraContainers: []
1184
extraVolumes: []
1185
extraVolumeMounts: []
1186
env: []
1187
extraEnvFrom: []
1188
ruler:
1189
enabled: true
1190
# -- Allows to override the container image of the ruler component.
1191
# When set it takes precedence over what is defined in global "image".
1192
image:
1193
# repository: grafana/mimir
1194
# tag: 3.2.0
1195
replicas: 1
1196
revisionHistoryLimit: null
1197
# -- [Experimental] Configure autoscaling via KEDA (https://keda.sh). This requires having
1198
# KEDA already installed in the Kubernetes cluster. The metrics for scaling are read
1199
# according to top-level kedaAutoscaling.prometheusAddress (defaulting to metamonitoring remote-write destination).
1200
# Basic auth and extra HTTP headers from metaMonitoring are ignored, please use customHeaders.
1201
# The remote URL is used even if metamonitoring is disabled.
1202
# For more details about migrating to autoscaling, refer to https://grafana.com/docs/helm-charts/mimir-distributed/latest/configure/configure-autoscaling/#migrate-existing-deployments
1203
kedaAutoscaling:
1204
enabled: false
1205
# -- preserveReplicas gives you the option to migrate from non-autoscaled to autoscaled deployments without losing replicas. When set to true, the replica fields in the component will be left intact.
1206
# For more details about migrating to autoscaling, refer to https://grafana.com/docs/helm-charts/mimir-distributed/latest/configure/configure-autoscaling/#migrate-existing-deployments
1207
preserveReplicas: false
1208
minReplicaCount: 1
1209
maxReplicaCount: 10
1210
# -- Target CPU utilization percentage for KEDA autoscaling. This controls the headroom each pod has compared to its current usage.
1211
# targetting lower percentages overprovisions the containers, so they can handle bursts of traffic and tolerate failures without waiting to scale out.
1212
targetCPUUtilizationPercentage: 100
1213
# -- Target memory utilization percentage for KEDA autoscaling. This controls the headroom each pod has compared to its current usage.
1214
# targetting lower percentages overprovisions the containers, so they can handle bursts of traffic and tolerate failures without waiting to scale out.
1215
targetMemoryUtilizationPercentage: 100
1216
behavior:
1217
scaleDown:
1218
policies:
1219
- periodSeconds: 600
1220
type: Percent
1221
value: 10
1222
# -- Fallback configuration for this component. If not set (null), the global kedaAutoscaling.fallback configuration is used.
1223
# fallback: {}
1224
service:
1225
annotations: {}
1226
labels: {}
1227
# -- https://kubernetes.io/docs/concepts/services-networking/service-traffic-policy/
1228
internalTrafficPolicy: Cluster
1229
type: ClusterIP
1230
extraPorts: []
1231
# -- Dedicated service account for ruler pods.
1232
# If not set, the default service account defined at the begining of this file will be used.
1233
# This service account can be used even if the default one is not set.
1234
serviceAccount:
1235
create: false
1236
# -- Ruler specific service account name. If not set and create is set to true, the default
1237
# name will be the default mimir service account's name with the "-ruler" suffix.
1238
name: ""
1239
annotations: {}
1240
labels: {}
1241
resources:
1242
requests:
1243
cpu: 100m
1244
memory: 128Mi
1245
# Additional ruler container arguments, e.g. log level (debug, info, warn, error)
1246
extraArgs: {}
1247
# log.level: debug
1248
1249
# -- Size in bytes of the memory ballast (-mem-ballast-size-bytes). The ballast reduces GC frequency
1250
# and CPU usage around ruler start and rollouts. It must be smaller than any GOMEMLIMIT set on the
1251
# ruler, otherwise the GC thrashes permanently. Set to 0 to disable the ballast.
1252
memBallastSizeBytes: 1073741824
1253
# Pod Labels
1254
podLabels: {}
1255
# Pod Annotations
1256
podAnnotations: {}
1257
# Pod Disruption Budget
1258
podDisruptionBudget:
1259
maxUnavailable: 1
1260
dnsConfig: {}
1261
nodeSelector: {}
1262
affinity: {}
1263
# -- topologySpreadConstraints allows to customize the default topologySpreadConstraints. This can be either a single dict as shown below or a slice of topologySpreadConstraints.
1264
# labelSelector is taken from the constraint itself (if it exists) or is generated by the chart using the same selectors as for services.
1265
topologySpreadConstraints:
1266
maxSkew: 1
1267
topologyKey: kubernetes.io/hostname
1268
whenUnsatisfiable: ScheduleAnyway
1269
# minDomains: 1
1270
# nodeAffinityPolicy: Honor
1271
# nodeTaintsPolicy: Honor
1272
# matchLabelKeys:
1273
# - pod-template-hash
1274
annotations: {}
1275
persistence:
1276
subPath:
1277
readinessProbe:
1278
httpGet:
1279
path: /ready
1280
port: http-metrics
1281
initialDelaySeconds: 45
1282
# -- SecurityContext override for ruler pods
1283
securityContext: {}
1284
# -- The SecurityContext for ruler containers
1285
containerSecurityContext:
1286
allowPrivilegeEscalation: false
1287
readOnlyRootFilesystem: true
1288
capabilities:
1289
drop: [ALL]
1290
strategy:
1291
type: RollingUpdate
1292
rollingUpdate:
1293
maxSurge: 50%
1294
maxUnavailable: 0
1295
terminationGracePeriodSeconds: 600
1296
tolerations: []
1297
initContainers: []
1298
extraContainers: []
1299
extraVolumes: []
1300
extraVolumeMounts: []
1301
env: []
1302
extraEnvFrom: []
1303
# -- If set to true, a dedicated query path will be deployed for the ruler and operational mode will be set to use remote evaluation. https://grafana.com/docs/mimir/latest/references/architecture/components/ruler/#remote
1304
# -- This is useful for isolating the ruler queries from other queriers (api/grafana).
1305
remoteEvaluationDedicatedQueryPath: false
1306
# -- Only deployed if .Values.ruler.remoteEvaluationDedicatedQueryPath
1307
ruler_querier:
1308
# -- Allows to override the container image of the ruler-querier component.
1309
# When set it takes precedence over what is defined in global "image".
1310
image:
1311
# repository: grafana/mimir
1312
# tag: 3.2.0
1313
replicas: 2
1314
revisionHistoryLimit: null
1315
# -- [Experimental] Configure autoscaling via KEDA (https://keda.sh). This requires having
1316
# KEDA already installed in the Kubernetes cluster. The metrics for scaling are read
1317
# according to top-level kedaAutoscaling.prometheusAddress (defaulting to metamonitoring remote-write destination).
1318
# Basic auth and extra HTTP headers from metaMonitoring are ignored, please use customHeaders.
1319
# The remote URL is used even if metamonitoring is disabled.
1320
# For more details about migrating to autoscaling, refer to https://grafana.com/docs/helm-charts/mimir-distributed/latest/configure/configure-autoscaling/#migrate-existing-deployments
1321
kedaAutoscaling:
1322
enabled: false
1323
# -- preserveReplicas gives you the option to migrate from non-autoscaled to autoscaled deployments without losing replicas. When set to true, the replica fields in the component will be left intact.
1324
# For more details about migrating to autoscaling, refer to https://grafana.com/docs/helm-charts/mimir-distributed/latest/configure/configure-autoscaling/#migrate-existing-deployments
1325
preserveReplicas: false
1326
minReplicaCount: 1
1327
maxReplicaCount: 10
1328
querySchedulerInflightRequestsThreshold: 12
1329
behavior:
1330
scaleDown:
1331
policies:
1332
- periodSeconds: 120
1333
type: Percent
1334
value: 10
1335
stabilizationWindowSeconds: 600
1336
scaleUp:
1337
policies:
1338
- periodSeconds: 120
1339
type: Percent
1340
value: 50
1341
- periodSeconds: 120
1342
type: Pods
1343
value: 15
1344
stabilizationWindowSeconds: 60
1345
# -- Fallback configuration for this component. If not set (null), the global kedaAutoscaling.fallback configuration is used.
1346
# fallback: {}
1347
service:
1348
annotations: {}
1349
labels: {}
1350
# -- https://kubernetes.io/docs/concepts/services-networking/service-traffic-policy/
1351
internalTrafficPolicy: Cluster
1352
type: ClusterIP
1353
extraPorts: []
1354
resources:
1355
requests:
1356
cpu: 100m
1357
memory: 128Mi
1358
# Additional ruler-querier container arguments, e.g. log level (debug, info, warn, error)
1359
extraArgs: {}
1360
# Pod Labels
1361
podLabels: {}
1362
# Pod Annotations
1363
podAnnotations: {}
1364
# Pod Disruption Budget
1365
podDisruptionBudget:
1366
maxUnavailable: 1
1367
# -- The name of the PriorityClass for ruler-querier pods
1368
priorityClassName: null
1369
dnsConfig: {}
1370
nodeSelector: {}
1371
affinity: {}
1372
# -- topologySpreadConstraints allows to customize the default topologySpreadConstraints. This can be either a single dict as shown below or a slice of topologySpreadConstraints.
1373
# labelSelector is taken from the constraint itself (if it exists) or is generated by the chart using the same selectors as for services.
1374
topologySpreadConstraints:
1375
maxSkew: 1
1376
topologyKey: kubernetes.io/hostname
1377
whenUnsatisfiable: ScheduleAnyway
1378
# minDomains: 1
1379
# nodeAffinityPolicy: Honor
1380
# nodeTaintsPolicy: Honor
1381
# matchLabelKeys:
1382
# - pod-template-hash
1383
annotations: {}
1384
persistence:
1385
subPath:
1386
readinessProbe:
1387
httpGet:
1388
path: /ready
1389
port: http-metrics
1390
initialDelaySeconds: 45
1391
# -- SecurityContext override for ruler-querier pods
1392
securityContext: {}
1393
# -- The SecurityContext for ruler-querier containers
1394
containerSecurityContext:
1395
allowPrivilegeEscalation: false
1396
readOnlyRootFilesystem: true
1397
capabilities:
1398
drop: [ALL]
1399
strategy:
1400
type: RollingUpdate
1401
rollingUpdate:
1402
maxUnavailable: 0
1403
maxSurge: 15%
1404
terminationGracePeriodSeconds: 180
1405
tolerations: []
1406
initContainers: []
1407
extraContainers: []
1408
extraVolumes: []
1409
extraVolumeMounts: []
1410
env: []
1411
extraEnvFrom: []
1412
# -- Only deployed if .Values.ruler.remoteEvaluationDedicatedQueryPath
1413
ruler_query_frontend:
1414
# -- Allows to override the container image of the ruler-query-frontend component.
1415
# When set it takes precedence over what is defined in global "image".
1416
image:
1417
# repository: grafana/mimir
1418
# tag: 3.2.0
1419
1420
# Setting it to null will produce a deployment without replicas set, allowing you to use autoscaling with the deployment
1421
replicas: 1
1422
revisionHistoryLimit: null
1423
# -- [Experimental] Configure autoscaling via KEDA (https://keda.sh). This requires having
1424
# KEDA already installed in the Kubernetes cluster. The metrics for scaling are read
1425
# according to top-level kedaAutoscaling.prometheusAddress (defaulting to metamonitoring remote-write destination).
1426
# Basic auth and extra HTTP headers from metaMonitoring are ignored, please use customHeaders.
1427
# The remote URL is used even if metamonitoring is disabled.
1428
# For more details about migrating to autoscaling, refer to https://grafana.com/docs/helm-charts/mimir-distributed/latest/configure/configure-autoscaling/#migrate-existing-deployments
1429
kedaAutoscaling:
1430
enabled: false
1431
# -- preserveReplicas gives you the option to migrate from non-autoscaled to autoscaled deployments without losing replicas. When set to true, the replica fields in the component will be left intact.
1432
# For more details about migrating to autoscaling, refer to https://grafana.com/docs/helm-charts/mimir-distributed/latest/configure/configure-autoscaling/#migrate-existing-deployments
1433
preserveReplicas: false
1434
minReplicaCount: 1
1435
maxReplicaCount: 10
1436
# -- Target CPU utilization percentage for KEDA autoscaling. This controls the headroom each pod has compared to its current usage.
1437
# targetting lower percentages overprovisions the containers, so they can handle bursts of traffic and tolerate failures without waiting to scale out.
1438
targetCPUUtilizationPercentage: 75
1439
# -- Target memory utilization percentage for KEDA autoscaling. This controls the headroom each pod has compared to its current usage.
1440
# targetting lower percentages overprovisions the containers, so they can handle bursts of traffic and tolerate failures without waiting to scale out.
1441
targetMemoryUtilizationPercentage: 100
1442
behavior:
1443
scaleDown:
1444
policies:
1445
- periodSeconds: 60
1446
type: Percent
1447
value: 10
1448
# -- Fallback configuration for this component. If not set (null), the global kedaAutoscaling.fallback configuration is used.
1449
# fallback: {}
1450
service:
1451
annotations: {}
1452
labels: {}
1453
# -- https://kubernetes.io/docs/concepts/services-networking/service-traffic-policy/
1454
internalTrafficPolicy: Cluster
1455
type: ClusterIP
1456
extraPorts: []
1457
resources:
1458
requests:
1459
cpu: 100m
1460
memory: 128Mi
1461
# Additional ruler-query-frontend container arguments, e.g. log level (debug, info, warn, error)
1462
extraArgs: {}
1463
# Pod Labels
1464
podLabels: {}
1465
# Pod Annotations
1466
podAnnotations: {}
1467
# Pod Disruption Budget
1468
podDisruptionBudget:
1469
maxUnavailable: 1
1470
# -- The name of the PriorityClass for ruler-query-frontend pods
1471
priorityClassName: null
1472
dnsConfig: {}
1473
nodeSelector: {}
1474
affinity: {}
1475
# -- topologySpreadConstraints allows to customize the default topologySpreadConstraints. This can be either a single dict as shown below or a slice of topologySpreadConstraints.
1476
# labelSelector is taken from the constraint itself (if it exists) or is generated by the chart using the same selectors as for services.
1477
topologySpreadConstraints:
1478
maxSkew: 1
1479
topologyKey: kubernetes.io/hostname
1480
whenUnsatisfiable: ScheduleAnyway
1481
# minDomains: 1
1482
# nodeAffinityPolicy: Honor
1483
# nodeTaintsPolicy: Honor
1484
# matchLabelKeys:
1485
# - pod-template-hash
1486
annotations: {}
1487
persistence:
1488
subPath:
1489
readinessProbe:
1490
httpGet:
1491
path: /ready
1492
port: http-metrics
1493
initialDelaySeconds: 45
1494
# -- SecurityContext override for query-fronted pods
1495
securityContext: {}
1496
# -- The SecurityContext for ruler-query-frontend containers
1497
containerSecurityContext:
1498
allowPrivilegeEscalation: false
1499
readOnlyRootFilesystem: true
1500
capabilities:
1501
drop: [ALL]
1502
strategy:
1503
type: RollingUpdate
1504
rollingUpdate:
1505
maxUnavailable: 0
1506
maxSurge: 15%
1507
terminationGracePeriodSeconds: 390
1508
tolerations: []
1509
initContainers: []
1510
extraContainers: []
1511
extraVolumes: []
1512
extraVolumeMounts: []
1513
env: []
1514
extraEnvFrom: []
1515
# -- Only deployed if .Values.ruler.remoteEvaluationDedicatedQueryPath
1516
ruler_query_scheduler:
1517
# -- Allows to override the container image of the ruler-query-scheduler component.
1518
# When set it takes precedence over what is defined in global "image".
1519
image:
1520
# repository: grafana/mimir
1521
# tag: 3.2.0
1522
replicas: 2
1523
revisionHistoryLimit: null
1524
service:
1525
annotations: {}
1526
labels: {}
1527
# -- https://kubernetes.io/docs/concepts/services-networking/service-traffic-policy/
1528
internalTrafficPolicy: Cluster
1529
type: ClusterIP
1530
extraPorts: []
1531
resources:
1532
requests:
1533
cpu: 100m
1534
memory: 128Mi
1535
# Additional ruler-query-scheduler container arguments, e.g. log level (debug, info, warn, error)
1536
extraArgs: {}
1537
# Pod Labels
1538
podLabels: {}
1539
# Pod Annotations
1540
podAnnotations: {}
1541
# Pod Disruption Budget
1542
podDisruptionBudget:
1543
maxUnavailable: 1
1544
# -- The name of the PriorityClass for ruler-query-scheduler pods
1545
priorityClassName: null
1546
dnsConfig: {}
1547
nodeSelector: {}
1548
affinity: {}
1549
# -- topologySpreadConstraints allows to customize the default topologySpreadConstraints. This can be either a single dict as shown below or a slice of topologySpreadConstraints.
1550
# labelSelector is taken from the constraint itself (if it exists) or is generated by the chart using the same selectors as for services.
1551
topologySpreadConstraints:
1552
maxSkew: 1
1553
topologyKey: kubernetes.io/hostname
1554
whenUnsatisfiable: ScheduleAnyway
1555
# minDomains: 1
1556
# nodeAffinityPolicy: Honor
1557
# nodeTaintsPolicy: Honor
1558
# matchLabelKeys:
1559
# - pod-template-hash
1560
annotations: {}
1561
persistence:
1562
subPath:
1563
readinessProbe:
1564
httpGet:
1565
path: /ready
1566
port: http-metrics
1567
initialDelaySeconds: 45
1568
# -- SecurityContext override for ruler-query-scheduler pods
1569
securityContext: {}
1570
# -- The SecurityContext for ruler-query-scheduler containers
1571
containerSecurityContext:
1572
allowPrivilegeEscalation: false
1573
readOnlyRootFilesystem: true
1574
capabilities:
1575
drop: [ALL]
1576
strategy:
1577
type: RollingUpdate
1578
rollingUpdate:
1579
maxUnavailable: 0
1580
maxSurge: 1
1581
terminationGracePeriodSeconds: 180
1582
tolerations: []
1583
initContainers: []
1584
extraContainers: []
1585
extraVolumes: []
1586
extraVolumeMounts: []
1587
env: []
1588
extraEnvFrom: []
1589
querier:
1590
# -- Whether to render the manifests related to the querier component.
1591
enabled: true
1592
# -- Allows to override the container image of the querier component.
1593
# When set it takes precedence over what is defined in global "image".
1594
image:
1595
# repository: grafana/mimir
1596
# tag: 3.2.0
1597
replicas: 2
1598
revisionHistoryLimit: null
1599
# -- [Experimental] Configure autoscaling via KEDA (https://keda.sh). This requires having
1600
# KEDA already installed in the Kubernetes cluster. The metrics for scaling are read
1601
# according to top-level kedaAutoscaling.prometheusAddress (defaulting to metamonitoring remote-write destination).
1602
# Basic auth and extra HTTP headers from metaMonitoring are ignored, please use customHeaders.
1603
# The remote URL is used even if metamonitoring is disabled.
1604
# For more details about migrating to autoscaling, refer to https://grafana.com/docs/helm-charts/mimir-distributed/latest/configure/configure-autoscaling/#migrate-existing-deployments
1605
kedaAutoscaling:
1606
enabled: false
1607
# -- preserveReplicas gives you the option to migrate from non-autoscaled to autoscaled deployments without losing replicas. When set to true, the replica fields in the component will be left intact.
1608
# For more details about migrating to autoscaling, refer to https://grafana.com/docs/helm-charts/mimir-distributed/latest/configure/configure-autoscaling/#migrate-existing-deployments
1609
preserveReplicas: false
1610
minReplicaCount: 1
1611
maxReplicaCount: 10
1612
querySchedulerInflightRequestsThreshold: 12
1613
# -- predictiveScalingEnabled scales up the querier based on the inflight requests in the past.
1614
# This helps with scaling up for predictable traffic patterns and minimizing HTTP 429 responses due to filled query queues.
1615
# Due to false positive items it can increase the querier TCO.
1616
predictiveScalingEnabled: false
1617
# -- The period to consider when considering scheduler metrics for predictive scaling.
1618
# This is usually slightly lower than the period of the repeating query events to give scaling up lead time.
1619
predictiveScalingPeriod: 6d23h30m
1620
# -- The time range to consider when considering scheduler metrics for predictive scaling.
1621
# For example: if lookback is 30m and period is 6d23h30m,
1622
# the querier will scale based on the maximum inflight queries between 6d23h30m and 7d ago.
1623
predictiveScalingLookback: 30m
1624
behavior:
1625
scaleDown:
1626
policies:
1627
- periodSeconds: 120
1628
type: Percent
1629
value: 10
1630
stabilizationWindowSeconds: 600
1631
scaleUp:
1632
policies:
1633
- periodSeconds: 120
1634
type: Percent
1635
value: 50
1636
- periodSeconds: 120
1637
type: Pods
1638
value: 15
1639
stabilizationWindowSeconds: 60
1640
# -- Fallback configuration for this component. If not set (null), the global kedaAutoscaling.fallback configuration is used.
1641
# fallback: {}
1642
service:
1643
annotations: {}
1644
labels: {}
1645
# -- https://kubernetes.io/docs/concepts/services-networking/service-traffic-policy/
1646
internalTrafficPolicy: Cluster
1647
type: ClusterIP
1648
extraPorts: []
1649
# -- https://kubernetes.io/docs/concepts/services-networking/service/#traffic-distribution
1650
trafficDistribution: ""
1651
resources:
1652
requests:
1653
cpu: 100m
1654
memory: 128Mi
1655
# Additional querier container arguments, e.g. log level (debug, info, warn, error)
1656
extraArgs: {}
1657
# Pod Labels
1658
podLabels: {}
1659
# Pod Annotations
1660
podAnnotations: {}
1661
# Pod Disruption Budget
1662
podDisruptionBudget:
1663
maxUnavailable: 1
1664
# -- The name of the PriorityClass for querier pods
1665
priorityClassName: null
1666
dnsConfig: {}
1667
nodeSelector: {}
1668
affinity: {}
1669
# -- topologySpreadConstraints allows to customize the default topologySpreadConstraints. This can be either a single dict as shown below or a slice of topologySpreadConstraints.
1670
# labelSelector is taken from the constraint itself (if it exists) or is generated by the chart using the same selectors as for services.
1671
topologySpreadConstraints:
1672
maxSkew: 1
1673
topologyKey: kubernetes.io/hostname
1674
whenUnsatisfiable: ScheduleAnyway
1675
# minDomains: 1
1676
# nodeAffinityPolicy: Honor
1677
# nodeTaintsPolicy: Honor
1678
# matchLabelKeys:
1679
# - pod-template-hash
1680
annotations: {}
1681
persistence:
1682
subPath:
1683
readinessProbe:
1684
httpGet:
1685
path: /ready
1686
port: http-metrics
1687
initialDelaySeconds: 45
1688
# -- SecurityContext override for querier pods
1689
securityContext: {}
1690
# -- The SecurityContext for querier containers
1691
containerSecurityContext:
1692
allowPrivilegeEscalation: false
1693
readOnlyRootFilesystem: true
1694
capabilities:
1695
drop: [ALL]
1696
strategy:
1697
type: RollingUpdate
1698
rollingUpdate:
1699
maxUnavailable: 0
1700
maxSurge: 15%
1701
terminationGracePeriodSeconds: 180
1702
tolerations: []
1703
initContainers: []
1704
extraContainers: []
1705
extraVolumes: []
1706
extraVolumeMounts: []
1707
env: []
1708
extraEnvFrom: []
1709
query_frontend:
1710
# -- Whether to render the manifests related to the query-frontend component.
1711
enabled: true
1712
# -- Allows to override the container image of the query-frontend component.
1713
# When set it takes precedence over what is defined in global "image".
1714
image:
1715
# repository: grafana/mimir
1716
# tag: 3.2.0
1717
1718
# Setting it to null will produce a deployment without replicas set, allowing you to use autoscaling with the deployment
1719
replicas: 1
1720
revisionHistoryLimit: null
1721
# -- [Experimental] Configure autoscaling via KEDA (https://keda.sh). This requires having
1722
# KEDA already installed in the Kubernetes cluster. The metrics for scaling are read
1723
# according to top-level kedaAutoscaling.prometheusAddress (defaulting to metamonitoring remote-write destination).
1724
# Basic auth and extra HTTP headers from metaMonitoring are ignored, please use customHeaders.
1725
# The remote URL is used even if metamonitoring is disabled.
1726
# For more details about migrating to autoscaling, refer to https://grafana.com/docs/helm-charts/mimir-distributed/latest/configure/configure-autoscaling/#migrate-existing-deployments
1727
kedaAutoscaling:
1728
enabled: false
1729
# -- preserveReplicas gives you the option to migrate from non-autoscaled to autoscaled deployments without losing replicas. When set to true, the replica fields in the component will be left intact.
1730
# For more details about migrating to autoscaling, refer to https://grafana.com/docs/helm-charts/mimir-distributed/latest/configure/configure-autoscaling/#migrate-existing-deployments
1731
preserveReplicas: false
1732
minReplicaCount: 1
1733
maxReplicaCount: 10
1734
# -- Target CPU utilization percentage for KEDA autoscaling. This controls the headroom each pod has compared to its current usage.
1735
# targetting lower percentages overprovisions the containers, so they can handle bursts of traffic and tolerate failures without waiting to scale out.
1736
targetCPUUtilizationPercentage: 75
1737
# -- Target memory utilization percentage for KEDA autoscaling. This controls the headroom each pod has compared to its current usage.
1738
# targetting lower percentages overprovisions the containers, so they can handle bursts of traffic and tolerate failures without waiting to scale out.
1739
targetMemoryUtilizationPercentage: 100
1740
behavior:
1741
scaleDown:
1742
policies:
1743
- periodSeconds: 60
1744
type: Percent
1745
value: 10
1746
# -- Fallback configuration for this component. If not set (null), the global kedaAutoscaling.fallback configuration is used.
1747
# fallback: {}
1748
service:
1749
annotations: {}
1750
labels: {}
1751
# -- https://kubernetes.io/docs/concepts/services-networking/service-traffic-policy/
1752
internalTrafficPolicy: Cluster
1753
type: ClusterIP
1754
extraPorts: []
1755
# -- https://kubernetes.io/docs/concepts/services-networking/service/#traffic-distribution
1756
trafficDistribution: ""
1757
resources:
1758
requests:
1759
cpu: 100m
1760
memory: 128Mi
1761
# Additional query-frontend container arguments, e.g. log level (debug, info, warn, error)
1762
extraArgs: {}
1763
# Pod Labels
1764
podLabels: {}
1765
# Pod Annotations
1766
podAnnotations: {}
1767
# Pod Disruption Budget
1768
podDisruptionBudget:
1769
maxUnavailable: 1
1770
# -- The name of the PriorityClass for query-frontend pods
1771
priorityClassName: null
1772
dnsConfig: {}
1773
nodeSelector: {}
1774
affinity: {}
1775
# -- topologySpreadConstraints allows to customize the default topologySpreadConstraints. This can be either a single dict as shown below or a slice of topologySpreadConstraints.
1776
# labelSelector is taken from the constraint itself (if it exists) or is generated by the chart using the same selectors as for services.
1777
topologySpreadConstraints:
1778
maxSkew: 1
1779
topologyKey: kubernetes.io/hostname
1780
whenUnsatisfiable: ScheduleAnyway
1781
# minDomains: 1
1782
# nodeAffinityPolicy: Honor
1783
# nodeTaintsPolicy: Honor
1784
# matchLabelKeys:
1785
# - pod-template-hash
1786
annotations: {}
1787
persistence:
1788
subPath:
1789
readinessProbe:
1790
httpGet:
1791
path: /ready
1792
port: http-metrics
1793
initialDelaySeconds: 45
1794
# -- SecurityContext override for query-fronted pods
1795
securityContext: {}
1796
# -- The SecurityContext for query-frontend containers
1797
containerSecurityContext:
1798
allowPrivilegeEscalation: false
1799
readOnlyRootFilesystem: true
1800
capabilities:
1801
drop: [ALL]
1802
strategy:
1803
type: RollingUpdate
1804
rollingUpdate:
1805
maxUnavailable: 0
1806
maxSurge: 15%
1807
terminationGracePeriodSeconds: 390
1808
tolerations: []
1809
initContainers: []
1810
extraContainers: []
1811
extraVolumes: []
1812
extraVolumeMounts: []
1813
env: []
1814
extraEnvFrom: []
1815
query_scheduler:
1816
enabled: true
1817
# -- Allows to override the container image of the query-scheduler component.
1818
# When set it takes precedence over what is defined in global "image".
1819
image:
1820
# repository: grafana/mimir
1821
# tag: 3.2.0
1822
replicas: 2
1823
revisionHistoryLimit: null
1824
service:
1825
annotations: {}
1826
labels: {}
1827
# -- https://kubernetes.io/docs/concepts/services-networking/service-traffic-policy/
1828
internalTrafficPolicy: Cluster
1829
type: ClusterIP
1830
extraPorts: []
1831
# -- https://kubernetes.io/docs/concepts/services-networking/service/#traffic-distribution
1832
trafficDistribution: ""
1833
resources:
1834
requests:
1835
cpu: 100m
1836
memory: 128Mi
1837
# Additional query-scheduler container arguments, e.g. log level (debug, info, warn, error)
1838
extraArgs: {}
1839
# Pod Labels
1840
podLabels: {}
1841
# Pod Annotations
1842
podAnnotations: {}
1843
# Pod Disruption Budget
1844
podDisruptionBudget:
1845
maxUnavailable: 1
1846
# -- The name of the PriorityClass for query-scheduler pods
1847
priorityClassName: null
1848
dnsConfig: {}
1849
nodeSelector: {}
1850
affinity: {}
1851
# -- topologySpreadConstraints allows to customize the default topologySpreadConstraints. This can be either a single dict as shown below or a slice of topologySpreadConstraints.
1852
# labelSelector is taken from the constraint itself (if it exists) or is generated by the chart using the same selectors as for services.
1853
topologySpreadConstraints:
1854
maxSkew: 1
1855
topologyKey: kubernetes.io/hostname
1856
whenUnsatisfiable: ScheduleAnyway
1857
# minDomains: 1
1858
# nodeAffinityPolicy: Honor
1859
# nodeTaintsPolicy: Honor
1860
# matchLabelKeys:
1861
# - pod-template-hash
1862
annotations: {}
1863
persistence:
1864
subPath:
1865
readinessProbe:
1866
httpGet:
1867
path: /ready
1868
port: http-metrics
1869
initialDelaySeconds: 45
1870
# -- SecurityContext override for query-scheduler pods
1871
securityContext: {}
1872
# -- The SecurityContext for query-scheduler containers
1873
containerSecurityContext:
1874
allowPrivilegeEscalation: false
1875
readOnlyRootFilesystem: true
1876
capabilities:
1877
drop: [ALL]
1878
strategy:
1879
type: RollingUpdate
1880
rollingUpdate:
1881
maxUnavailable: 0
1882
maxSurge: 1
1883
terminationGracePeriodSeconds: 180
1884
tolerations: []
1885
initContainers: []
1886
extraContainers: []
1887
extraVolumes: []
1888
extraVolumeMounts: []
1889
env: []
1890
extraEnvFrom: []
1891
store_gateway:
1892
# -- Whether to render the manifests related to the store-gateway component.
1893
enabled: true
1894
# -- Allows to override the container image of the store-gateway component.
1895
# When set it takes precedence over what is defined in global "image".
1896
image:
1897
# repository: grafana/mimir
1898
# tag: 3.2.0
1899
1900
# -- Total number of replicas for the store-gateway across all availability zones
1901
# If store_gateway.zoneAwareReplication.enabled=false, this number is taken as is.
1902
# Otherwise each zone starts `ceil(replicas / number_of_zones)` number of pods.
1903
# E.g. if 'replicas' is set to 4 and there are 3 zones, then 4/3=1.33 and after rounding up it means 2 pods per zone are started.
1904
replicas: 1
1905
revisionHistoryLimit: null
1906
service:
1907
annotations: {}
1908
labels: {}
1909
# -- https://kubernetes.io/docs/concepts/services-networking/service-traffic-policy/
1910
internalTrafficPolicy: Cluster
1911
type: ClusterIP
1912
extraPorts: []
1913
# -- https://kubernetes.io/docs/concepts/services-networking/service/#traffic-distribution
1914
# Note: This service is not responsible for read path traffic.
1915
trafficDistribution: ""
1916
# -- Optionally set the scheduler for pods of the store-gateway
1917
schedulerName: ""
1918
resources:
1919
requests:
1920
cpu: 100m
1921
memory: 512Mi
1922
# Additional store-gateway container arguments, e.g. log level (debug, info, warn, error)
1923
extraArgs: {}
1924
# Pod Labels
1925
podLabels: {}
1926
# Pod Annotations
1927
podAnnotations: {}
1928
# -- Management policy for store-gateway pods
1929
# New variable introduced with Helm chart version 5.1.0. For backwards compatibility it is set to `OrderedReady`
1930
# On new deployments it is highly recommended to switch it to `Parallel` as this will be the new default from 6.0.0
1931
podManagementPolicy: OrderedReady
1932
# -- Pod Disruption Budget for store-gateway, this will be applied across availability zones to prevent losing redundancy
1933
podDisruptionBudget:
1934
maxUnavailable: 1
1935
# -- The name of the PriorityClass for store-gateway pods
1936
priorityClassName: null
1937
dnsConfig: {}
1938
# -- NodeSelector to pin store-gateway pods to certain set of nodes. This is ignored when store_gateway.zoneAwareReplication.enabled=true.
1939
nodeSelector: {}
1940
# -- Pod affinity settings for the store_gateway. This is ignored when store_gateway.zoneAwareReplication.enabled=true.
1941
affinity: {}
1942
# -- topologySpreadConstraints allows to customize the default topologySpreadConstraints. This can be either a single dict as shown below or a slice of topologySpreadConstraints.
1943
# labelSelector is taken from the constraint itself (if it exists) or is generated by the chart using the same selectors as for services.
1944
# It is recommended to replace this with requiredDuringSchedulingIgnoredDuringExecution podAntiAffinity rules when
1945
# deploying to production.
1946
topologySpreadConstraints:
1947
maxSkew: 1
1948
topologyKey: kubernetes.io/hostname
1949
whenUnsatisfiable: ScheduleAnyway
1950
# minDomains: 1
1951
# nodeAffinityPolicy: Honor
1952
# nodeTaintsPolicy: Honor
1953
# matchLabelKeys:
1954
# - pod-template-hash
1955
annotations: {}
1956
persistentVolume:
1957
# If true Store-gateway will create/use a Persistent Volume Claim
1958
# If false, use emptyDir
1959
#
1960
enabled: true
1961
# additional settings for emptyDir like medium or sizeLimit
1962
#
1963
emptyDir: {}
1964
# medium: Memory
1965
# sizeLimit: 1Gi
1966
1967
# Store-gateway data Persistent Volume Claim template name
1968
#
1969
name: storage
1970
# Store-gateway data Persistent Volume Claim annotations
1971
#
1972
annotations: {}
1973
# Store-gateway data Persistent Volume Claim labels
1974
#
1975
labels: {}
1976
# Store-gateway data Persistent Volume access modes
1977
# Must match those of existing PV or dynamic provisioner
1978
# Ref: http://kubernetes.io/docs/user-guide/persistent-volumes/
1979
#
1980
accessModes:
1981
- ReadWriteOnce
1982
# Store-gateway data Persistent Volume size
1983
#
1984
size: 2Gi
1985
# Subdirectory of Store-gateway data Persistent Volume to mount
1986
# Useful if the volume's root directory is not empty
1987
#
1988
subPath: ""
1989
# Store-gateway data Persistent Volume Storage Class
1990
# If defined, storageClassName: <storageClass>
1991
# If set to "-", storageClassName: "", which disables dynamic provisioning
1992
# If undefined (the default) or set to null, no storageClassName spec is
1993
# set, choosing the default provisioner.
1994
#
1995
# A per-zone storageClass configuration in `store_gateway.zoneAwareReplication.zones[*].storageClass` takes precedence over this field.
1996
# storageClass: "-"
1997
1998
# volumeAttributesClassName: my-cluster-vac
1999
# Requires Kubernetes 1.31+ and a CSI driver with ModifyVolume support.
2000
# Must reference an existing cluster VolumeAttributesClass.
2001
# A per-zone volumeAttributesClassName in `store_gateway.zoneAwareReplication.zones[*].volumeAttributesClassName` takes precedence over this field when set.
2002
2003
# -- Enable StatefulSetAutoDeletePVC feature
2004
# https://kubernetes.io/docs/concepts/workloads/controllers/statefulset/#persistentvolumeclaim-retention
2005
enableRetentionPolicy: false
2006
whenDeleted: Retain
2007
whenScaled: Retain
2008
readinessProbe:
2009
httpGet:
2010
path: /ready
2011
port: http-metrics
2012
initialDelaySeconds: 60
2013
# -- SecurityContext override for store-gateway pods
2014
securityContext: {}
2015
# -- The SecurityContext for store-gateway containers
2016
containerSecurityContext:
2017
allowPrivilegeEscalation: false
2018
readOnlyRootFilesystem: true
2019
capabilities:
2020
drop: [ALL]
2021
# -- updateStrategy of the store-gateway statefulset. This is ignored when store_gateway.zoneAwareReplication.enabled=true.
2022
strategy:
2023
type: RollingUpdate
2024
terminationGracePeriodSeconds: 120
2025
# -- The maximum size of a query response in bytes. Sets max send size for store-gateway and receive size for queriers.
2026
grpcMaxQueryResponseSizeBytes: "209715200"
2027
tolerations: []
2028
initContainers: []
2029
extraContainers: []
2030
extraVolumes: []
2031
extraVolumeMounts: []
2032
env: []
2033
extraEnvFrom: []
2034
# -- Options to configure zone-aware replication for store-gateway
2035
# Example configuration with full geographical redundancy:
2036
# rollout_operator:
2037
# enabled: true
2038
# store_gateway:
2039
# zoneAwareReplication:
2040
# enabled: true
2041
# topologyKey: 'kubernetes.io/hostname' # This generates default anti-affinity rules
2042
# zones: # Zone list has to be fully redefined for modification. Update with you actual zones or skip to use logical zones only.
2043
# - name: zone-a
2044
# nodeSelector:
2045
# topology.kubernetes.io/zone: us-central1-a
2046
# - name: zone-b
2047
# nodeSelector:
2048
# topology.kubernetes.io/zone: us-central1-b
2049
# - name: zone-c
2050
# nodeSelector:
2051
# topology.kubernetes.io/zone: us-central1-c
2052
#
2053
zoneAwareReplication:
2054
# -- Enable zone-aware replication for store-gateway
2055
enabled: true
2056
# -- Maximum number of store-gateways that can be unavailable per zone during rollout
2057
maxUnavailable: 50
2058
# -- Minimum time for the rollout operator to wait between store-gateway zone down scales
2059
minTimeBetweenZonesDownscale: 30m
2060
# -- topologyKey to use in pod anti-affinity. If unset, no anti-affinity rules are generated. If set, the generated anti-affinity rule makes sure that pods from different zones do not mix.
2061
# E.g.: topologyKey: 'kubernetes.io/hostname'
2062
topologyKey: null
2063
# -- Auxiliary values for migration, see https://grafana.com/docs/helm-charts/mimir-distributed/latest/migration-guides/migrate-from-single-zone-with-helm/
2064
migration:
2065
# -- Indicate if migration is ongoing for multi zone store-gateway
2066
enabled: false
2067
# -- Enable zone-awareness on the readPath
2068
readPath: false
2069
# -- Zone definitions for store-gateway zones. Note: you have to redefine the whole list to change parts as YAML does not allow to modify parts of a list.
2070
zones:
2071
# -- Name of the zone, used in labels and selectors. Must follow Kubernetes naming restrictions: https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/
2072
- name: zone-a
2073
# -- nodeselector to restrict where pods of this zone can be placed. E.g.:
2074
# nodeSelector:
2075
# topology.kubernetes.io/zone: zone-a
2076
nodeSelector: null
2077
# -- extraAffinity adds user defined custom affinity rules (merged with generated rules)
2078
extraAffinity: {}
2079
# -- StoreGateway data Persistent Volume Storage Class
2080
# If defined, storageClassName: <storageClass>
2081
# If set to "-", then use `storageClassName: ""`, which disables dynamic provisioning
2082
# If undefined or set to null (the default), then fall back to the value of `store_gateway.persistentVolume.storageClass`.
2083
storageClass: null
2084
# -- Persistent Volume VolumeAttributesClass for this zone.
2085
# If undefined or set to null (the default), then fall back to the component `persistentVolume.volumeAttributesClassName`.
2086
volumeAttributesClassName: null
2087
# -- noDownscale adds a label that can be used by the rollout-operator as documented in the rollout-operator repo: https://github.com/grafana/rollout-operator#webhooks
2088
noDownscale: false
2089
# -- downscaleLeader is an Annotation used by the rollout-operator to coordinate downscaling across zones.
2090
# Set to the StatefulSet name that should lead downscaling for this component (typically the previous zone).
2091
# Example: "mimir-store-gateway-zone-a" for zone-b, "mimir-store-gateway-zone-b" for zone-c.
2092
# If undefined or set to null (the default), this zone won't be designated as a downscale leader.
2093
downscaleLeader: null
2094
# -- prepareDownscale adds labels and annotations for the rollout-operator to prepare downscaling: https://github.com/grafana/rollout-operator#how-scaling-up-and-down-works
2095
prepareDownscale: true
2096
# -- Name of the zone, used in labels and selectors. Must follow Kubernetes naming restrictions: https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/
2097
- name: zone-b
2098
# -- nodeselector to restrict where pods of this zone can be placed. E.g.:
2099
# nodeSelector:
2100
# topology.kubernetes.io/zone: zone-b
2101
nodeSelector: null
2102
# -- extraAffinity adds user defined custom affinity rules (merged with generated rules)
2103
extraAffinity: {}
2104
# -- StoreGateway data Persistent Volume Storage Class
2105
# If defined, storageClassName: <storageClass>
2106
# If set to "-", then use `storageClassName: ""`, which disables dynamic provisioning
2107
# If undefined or set to null (the default), then fall back to the value of `store_gateway.persistentVolume.storageClass`.
2108
storageClass: null
2109
# -- Persistent Volume VolumeAttributesClass for this zone.
2110
# If undefined or set to null (the default), then fall back to the component `persistentVolume.volumeAttributesClassName`.
2111
volumeAttributesClassName: null
2112
# -- noDownscale adds a label that can be used by the rollout-operator as documented in the rollout-operator repo: https://github.com/grafana/rollout-operator#webhooks
2113
noDownscale: false
2114
# -- downscaleLeader is an Annotation used by the rollout-operator to coordinate downscaling across zones.
2115
# Set to the StatefulSet name that should lead downscaling for this component (typically the previous zone).
2116
# Example: "mimir-store-gateway-zone-a" for zone-b, "mimir-store-gateway-zone-b" for zone-c.
2117
# If undefined or set to null (the default), this zone won't be designated as a downscale leader.
2118
downscaleLeader: null
2119
# -- prepareDownscale adds labels and annotations for the rollout-operator to prepare downscaling: https://github.com/grafana/rollout-operator#how-scaling-up-and-down-works
2120
prepareDownscale: true
2121
# -- Name of the zone, used in labels and selectors. Must follow Kubernetes naming restrictions: https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/
2122
- name: zone-c
2123
# -- nodeselector to restrict where pods of this zone can be placed. E.g.:
2124
# nodeSelector:
2125
# topology.kubernetes.io/zone: zone-c
2126
nodeSelector: null
2127
# -- extraAffinity adds user defined custom affinity rules (merged with generated rules)
2128
extraAffinity: {}
2129
# -- StoreGateway data Persistent Volume Storage Class
2130
# If defined, storageClassName: <storageClass>
2131
# If set to "-", then use `storageClassName: ""`, which disables dynamic provisioning
2132
# If undefined or set to null (the default), then fall back to the value of `store_gateway.persistentVolume.storageClass`.
2133
storageClass: null
2134
# -- Persistent Volume VolumeAttributesClass for this zone.
2135
# If undefined or set to null (the default), then fall back to the component `persistentVolume.volumeAttributesClassName`.
2136
volumeAttributesClassName: null
2137
# -- noDownscale adds a label that can be used by the rollout-operator as documented in the rollout-operator repo: https://github.com/grafana/rollout-operator#webhooks
2138
noDownscale: false
2139
# -- downscaleLeader is an Annotation used by the rollout-operator to coordinate downscaling across zones.
2140
# Set to the StatefulSet name that should lead downscaling for this component (typically the previous zone).
2141
# Example: "mimir-store-gateway-zone-a" for zone-b, "mimir-store-gateway-zone-b" for zone-c.
2142
# If undefined or set to null (the default), this zone won't be designated as a downscale leader.
2143
downscaleLeader: null
2144
# -- prepareDownscale adds labels and annotations for the rollout-operator to prepare downscaling: https://github.com/grafana/rollout-operator#how-scaling-up-and-down-works
2145
prepareDownscale: true
2146
compactor:
2147
# -- Whether to render the manifests related to the compactor component.
2148
enabled: true
2149
# -- Allows to override the container image of the compactor component.
2150
# When set it takes precedence over what is defined in global "image".
2151
image:
2152
# repository: grafana/mimir
2153
# tag: 3.2.0
2154
replicas: 1
2155
revisionHistoryLimit: null
2156
service:
2157
annotations: {}
2158
labels: {}
2159
# -- https://kubernetes.io/docs/concepts/services-networking/service-traffic-policy/
2160
internalTrafficPolicy: Cluster
2161
type: ClusterIP
2162
extraPorts: []
2163
# -- Optionally set the scheduler for pods of the compactor
2164
schedulerName: ""
2165
resources:
2166
requests:
2167
cpu: 100m
2168
memory: 512Mi
2169
# Additional compactor container arguments, e.g. log level (debug, info, warn, error)
2170
extraArgs: {}
2171
# Pod Labels
2172
podLabels: {}
2173
# Pod Annotations
2174
podAnnotations: {}
2175
# Pod Disruption Budget
2176
podDisruptionBudget:
2177
maxUnavailable: 1
2178
podManagementPolicy: OrderedReady
2179
# -- The name of the PriorityClass for compactor pods
2180
priorityClassName: null
2181
dnsConfig: {}
2182
nodeSelector: {}
2183
affinity: {}
2184
# -- topologySpreadConstraints allows to customize the default topologySpreadConstraints. This can be either a single dict as shown below or a slice of topologySpreadConstraints.
2185
# labelSelector is taken from the constraint itself (if it exists) or is generated by the chart using the same selectors as for services.
2186
topologySpreadConstraints:
2187
maxSkew: 1
2188
topologyKey: kubernetes.io/hostname
2189
whenUnsatisfiable: ScheduleAnyway
2190
# minDomains: 1
2191
# nodeAffinityPolicy: Honor
2192
# nodeTaintsPolicy: Honor
2193
# matchLabelKeys:
2194
# - pod-template-hash
2195
annotations: {}
2196
persistentVolume:
2197
# If true compactor will create/use a Persistent Volume Claim
2198
# If false, use emptyDir
2199
#
2200
enabled: true
2201
# compactor data Persistent Volume Claim template name
2202
#
2203
name: storage
2204
# compactor data Persistent Volume Claim annotations
2205
#
2206
annotations: {}
2207
# compactor data Persistent Volume Claim labels
2208
#
2209
labels: {}
2210
# compactor data Persistent Volume access modes
2211
# Must match those of existing PV or dynamic provisioner
2212
# Ref: http://kubernetes.io/docs/user-guide/persistent-volumes/
2213
#
2214
accessModes:
2215
- ReadWriteOnce
2216
# compactor data Persistent Volume size
2217
#
2218
size: 2Gi
2219
# Subdirectory of compactor data Persistent Volume to mount
2220
# Useful if the volume's root directory is not empty
2221
#
2222
subPath: ""
2223
# compactor data Persistent Volume Storage Class
2224
# If defined, storageClassName: <storageClass>
2225
# If set to "-", storageClassName: "", which disables dynamic provisioning
2226
# If undefined (the default) or set to null, no storageClassName spec is
2227
# set, choosing the default provisioner.
2228
#
2229
# storageClass: "-"
2230
2231
# compactor Persistent Volume Attributes Class
2232
# Allows you to dynamically modify a volume's attributes on the fly
2233
# Requires Kubernetes 1.31+ and a CSI driver with ModifyVolume support.
2234
# Must reference an existing cluster VolumeAttributesClass.
2235
# volumeAttributesClassName: my-cluster-vac
2236
2237
# -- Enable StatefulSetAutoDeletePVC feature
2238
# https://kubernetes.io/docs/concepts/workloads/controllers/statefulset/#persistentvolumeclaim-retention
2239
enableRetentionPolicy: false
2240
whenDeleted: Retain
2241
whenScaled: Retain
2242
readinessProbe:
2243
httpGet:
2244
path: /ready
2245
port: http-metrics
2246
initialDelaySeconds: 60
2247
# -- SecurityContext override for compactor pods
2248
securityContext: {}
2249
# -- The SecurityContext for compactor containers
2250
containerSecurityContext:
2251
allowPrivilegeEscalation: false
2252
readOnlyRootFilesystem: true
2253
capabilities:
2254
drop: [ALL]
2255
strategy:
2256
type: RollingUpdate
2257
terminationGracePeriodSeconds: 900
2258
tolerations: []
2259
initContainers: []
2260
extraContainers: []
2261
extraVolumes: []
2262
extraVolumeMounts: []
2263
env: []
2264
extraEnvFrom: []
2265
gossip_ring:
2266
service:
2267
annotations: {}
2268
memcached:
2269
image:
2270
# -- Memcached Docker image repository
2271
repository: chainreg.biz/chainguard-private/memcached
2272
# -- Memcached Docker image tag
2273
tag: 1.6.45-r3@sha256:3905846a49548e6c72928c992a512d14e7f33a13338febea10b9be16cccc3049
2274
# -- Memcached Docker image pull policy
2275
pullPolicy: IfNotPresent
2276
# -- The SecurityContext override for memcached pods
2277
podSecurityContext: {}
2278
# -- The name of the PriorityClass for memcached pods
2279
priorityClassName: null
2280
# -- The SecurityContext for memcached containers
2281
containerSecurityContext:
2282
readOnlyRootFilesystem: true
2283
capabilities:
2284
drop: [ALL]
2285
allowPrivilegeEscalation: false
2286
memcachedExporter:
2287
# -- Whether memcached metrics should be exported
2288
enabled: true
2289
image:
2290
repository: chainreg.biz/chainguard-private/memcached-exporter
2291
tag: 0.17.0-r3@sha256:e9a5267b225f17dbd3617e60c31dd41791ea1e7009704de82a577035c073a897
2292
pullPolicy: IfNotPresent
2293
resources:
2294
requests:
2295
cpu: 50m
2296
memory: 50Mi
2297
limits:
2298
memory: 250Mi
2299
# -- The SecurityContext for memcached exporter containers
2300
containerSecurityContext:
2301
readOnlyRootFilesystem: true
2302
capabilities:
2303
drop: [ALL]
2304
allowPrivilegeEscalation: false
2305
# -- Extra args to add to the exporter container.
2306
# Example:
2307
# extraArgs:
2308
# memcached.tls.enable: true
2309
# memcached.tls.cert-file: /certs/cert.crt
2310
# memcached.tls.key-file: /certs/cert.key
2311
# memcached.tls.ca-file: /certs/ca.crt
2312
# memcached.tls.insecure-skip-verify: false
2313
# memcached.tls.server-name: memcached
2314
extraArgs: {}
2315
chunks-cache:
2316
# -- Specifies whether memcached based chunks-cache should be enabled
2317
enabled: false
2318
# -- How long each pod must be ready for before the next one is started/restarted
2319
minReadySeconds: 60
2320
# -- Total number of chunks-cache replicas
2321
replicas: 1
2322
# -- Number of old ReplicaSets to retain to allow rollback (if not set, the default Kubernetes value is set to 10)
2323
revisionHistoryLimit: null
2324
# -- Port of the chunks-cache service
2325
port: 11211
2326
# -- Amount of memory allocated to chunks-cache for object storage (in MB).
2327
allocatedMemory: 8192
2328
# -- Maximum item memory for chunks-cache (in MB).
2329
maxItemMemory: 1
2330
# -- Maximum number of connections allowed
2331
connectionLimit: 16384
2332
# -- Extra init containers for chunks-cache pods
2333
initContainers: []
2334
# -- Annotations for the chunks-cache pods
2335
annotations: {}
2336
# -- Node selector for chunks-cache pods
2337
nodeSelector: {}
2338
# -- Affinity for chunks-cache pods
2339
affinity: {}
2340
dnsConfig: {}
2341
# -- topologySpreadConstraints allows to customize the default topologySpreadConstraints. This can be either a single dict as shown below or a slice of topologySpreadConstraints.
2342
# labelSelector is taken from the constraint itself (if it exists) or is generated by the chart using the same selectors as for services.
2343
topologySpreadConstraints: {}
2344
# maxSkew: 1
2345
# topologyKey: kubernetes.io/hostname
2346
# whenUnsatisfiable: ScheduleAnyway
2347
# minDomains: 1
2348
# nodeAffinityPolicy: Honor
2349
# nodeTaintsPolicy: Honor
2350
# matchLabelKeys:
2351
# - pod-template-hash
2352
2353
# -- Tolerations for chunks-cache pods
2354
tolerations: []
2355
# -- Pod Disruption Budget
2356
podDisruptionBudget:
2357
maxUnavailable: 1
2358
# -- The name of the PriorityClass for chunks-cache pods
2359
priorityClassName: null
2360
# -- Labels for chunks-cache pods
2361
podLabels: {}
2362
# -- Annotations for chunks-cache pods
2363
podAnnotations: {}
2364
# -- Management policy for chunks-cache pods
2365
podManagementPolicy: Parallel
2366
# -- Grace period to allow the chunks-cache to shutdown before it is killed
2367
terminationGracePeriodSeconds: 30
2368
# -- Stateful chunks-cache strategy
2369
statefulStrategy:
2370
type: RollingUpdate
2371
# -- Add extended options for chunks-cache memcached container. The format is the same as for the memcached -o/--extend flag.
2372
# Example:
2373
# extraExtendedOptions: 'tls,no_hashexpand'
2374
extraExtendedOptions: ""
2375
# -- Additional CLI args for chunks-cache
2376
extraArgs: {}
2377
# -- Additional containers to be added to the chunks-cache pod.
2378
extraContainers: []
2379
# -- Additional volumes to be added to the chunks-cache pod (applies to both memcached and exporter containers).
2380
# Example:
2381
# extraVolumes:
2382
# - name: extra-volume
2383
# secret:
2384
# secretName: extra-volume-secret
2385
extraVolumes: []
2386
# -- Additional volume mounts to be added to the chunks-cache pod (applies to both memcached and exporter containers).
2387
# Example:
2388
# extraVolumeMounts:
2389
# - name: extra-volume
2390
# mountPath: /etc/extra-volume
2391
# readOnly: true
2392
extraVolumeMounts: []
2393
# -- List of additional PVCs to be created for the chunks-cache statefulset
2394
volumeClaimTemplates: []
2395
# -- Resource requests and limits for the chunks-cache
2396
# By default a safe memory limit will be requested based on allocatedMemory value (floor (* 1.2 allocatedMemory)).
2397
resources: null
2398
# -- Service annotations and labels
2399
service:
2400
annotations: {}
2401
labels: {}
2402
extraPorts: []
2403
index-cache:
2404
# -- Specifies whether memcached based index-cache should be enabled
2405
enabled: false
2406
# -- How long each pod must be ready for before the next one is started/restarted
2407
minReadySeconds: 60
2408
# -- Total number of index-cache replicas
2409
replicas: 1
2410
# -- Number of old ReplicaSets to retain to allow rollback (if not set, the default Kubernetes value is set to 10)
2411
revisionHistoryLimit: null
2412
# -- Port of the index-cache service
2413
port: 11211
2414
# -- Amount of memory allocated to index-cache for object storage (in MB).
2415
allocatedMemory: 2048
2416
# -- Maximum item index-cache for memcached (in MB).
2417
maxItemMemory: 5
2418
# -- Maximum number of connections allowed
2419
connectionLimit: 16384
2420
# -- Extra init containers for index-cache pods
2421
initContainers: []
2422
# -- Annotations for the index-cache pods
2423
annotations: {}
2424
# -- Node selector for index-cache pods
2425
nodeSelector: {}
2426
# -- Affinity for index-cache pods
2427
affinity: {}
2428
dnsConfig: {}
2429
# -- topologySpreadConstraints allows to customize the default topologySpreadConstraints. This can be either a single dict as shown below or a slice of topologySpreadConstraints.
2430
# labelSelector is taken from the constraint itself (if it exists) or is generated by the chart using the same selectors as for services.
2431
topologySpreadConstraints: {}
2432
# maxSkew: 1
2433
# topologyKey: kubernetes.io/hostname
2434
# whenUnsatisfiable: ScheduleAnyway
2435
# minDomains: 1
2436
# nodeAffinityPolicy: Honor
2437
# nodeTaintsPolicy: Honor
2438
# matchLabelKeys:
2439
# - pod-template-hash
2440
2441
# -- Tolerations for index-cache pods
2442
tolerations: []
2443
# -- Pod Disruption Budget
2444
podDisruptionBudget:
2445
maxUnavailable: 1
2446
# -- The name of the PriorityClass for index-cache pods
2447
priorityClassName: null
2448
# -- Labels for index-cache pods
2449
podLabels: {}
2450
# -- Annotations for index-cache pods
2451
podAnnotations: {}
2452
# -- Management policy for index-cache pods
2453
podManagementPolicy: Parallel
2454
# -- Grace period to allow the index-cache to shutdown before it is killed
2455
terminationGracePeriodSeconds: 30
2456
# -- Stateful index-cache strategy
2457
statefulStrategy:
2458
type: RollingUpdate
2459
# -- Add extended options for index-cache memcached container. The format is the same as for the memcached -o/--extend flag.
2460
# Example:
2461
# extraExtendedOptions: 'tls,modern,track_sizes'
2462
extraExtendedOptions: ""
2463
# -- Additional CLI args for index-cache
2464
extraArgs: {}
2465
# -- Additional containers to be added to the index-cache pod.
2466
extraContainers: []
2467
# -- Additional volumes to be added to the index-cache pod (applies to both memcached and exporter containers).
2468
# Example:
2469
# extraVolumes:
2470
# - name: extra-volume
2471
# secret:
2472
# secretName: extra-volume-secret
2473
extraVolumes: []
2474
# -- Additional volume mounts to be added to the index-cache pod (applies to both memcached and exporter containers).
2475
# Example:
2476
# extraVolumeMounts:
2477
# - name: extra-volume
2478
# mountPath: /etc/extra-volume
2479
# readOnly: true
2480
extraVolumeMounts: []
2481
# -- List of additional PVCs to be created for the index-cache statefulset
2482
volumeClaimTemplates: []
2483
# -- Resource requests and limits for the index-cache
2484
# By default a safe memory limit will be requested based on allocatedMemory value (floor (* 1.2 allocatedMemory)).
2485
resources: null
2486
# -- Service annotations and labels
2487
service:
2488
annotations: {}
2489
labels: {}
2490
extraPorts: []
2491
metadata-cache:
2492
# -- Specifies whether memcached based metadata-cache should be enabled
2493
enabled: false
2494
# -- How long each pod must be ready for before the next one is started/restarted
2495
minReadySeconds: 60
2496
# -- Total number of metadata-cache replicas
2497
replicas: 1
2498
# -- Number of old ReplicaSets to retain to allow rollback (if not set, the default Kubernetes value is set to 10)
2499
revisionHistoryLimit: null
2500
# -- Port of the metadata-cache service
2501
port: 11211
2502
# -- Amount of memory allocated to metadata-cache for object storage (in MB).
2503
allocatedMemory: 512
2504
# -- Maximum item metadata-cache for memcached (in MB).
2505
maxItemMemory: 1
2506
# -- Maximum number of connections allowed
2507
connectionLimit: 16384
2508
# -- Extra init containers for metadata-cache pods
2509
initContainers: []
2510
# -- Annotations for the metadata-cache pods
2511
annotations: {}
2512
# -- Node selector for metadata-cache pods
2513
nodeSelector: {}
2514
# -- Affinity for metadata-cache pods
2515
affinity: {}
2516
dnsConfig: {}
2517
# -- topologySpreadConstraints allows to customize the default topologySpreadConstraints. This can be either a single dict as shown below or a slice of topologySpreadConstraints.
2518
# labelSelector is taken from the constraint itself (if it exists) or is generated by the chart using the same selectors as for services.
2519
topologySpreadConstraints: {}
2520
# maxSkew: 1
2521
# topologyKey: kubernetes.io/hostname
2522
# whenUnsatisfiable: ScheduleAnyway
2523
# minDomains: 1
2524
# nodeAffinityPolicy: Honor
2525
# nodeTaintsPolicy: Honor
2526
# matchLabelKeys:
2527
# - pod-template-hash
2528
2529
# -- Tolerations for metadata-cache pods
2530
tolerations: []
2531
# -- Pod Disruption Budget
2532
podDisruptionBudget:
2533
maxUnavailable: 1
2534
# -- The name of the PriorityClass for metadata-cache pods
2535
priorityClassName: null
2536
# -- Labels for metadata-cache pods
2537
podLabels: {}
2538
# -- Annotations for metadata-cache pods
2539
podAnnotations: {}
2540
# -- Management policy for metadata-cache pods
2541
podManagementPolicy: Parallel
2542
# -- Grace period to allow the metadata-cache to shutdown before it is killed
2543
terminationGracePeriodSeconds: 30
2544
# -- Stateful metadata-cache strategy
2545
statefulStrategy:
2546
type: RollingUpdate
2547
# -- Add extended options for metadata-cache memcached container. The format is the same as for the memcached -o/--extend flag.
2548
# Example:
2549
# extraExtendedOptions: 'tls,modern,track_sizes'
2550
extraExtendedOptions: ""
2551
# -- Additional CLI args for metadata-cache
2552
extraArgs: {}
2553
# -- Additional containers to be added to the metadata-cache pod.
2554
extraContainers: []
2555
# -- Additional volumes to be added to the metadata-cache pod (applies to both memcached and exporter containers).
2556
# Example:
2557
# extraVolumes:
2558
# - name: extra-volume
2559
# secret:
2560
# secretName: extra-volume-secret
2561
extraVolumes: []
2562
# -- Additional volume mounts to be added to the metadata-cache pod (applies to both memcached and exporter containers).
2563
# Example:
2564
# extraVolumeMounts:
2565
# - name: extra-volume
2566
# mountPath: /etc/extra-volume
2567
# readOnly: true
2568
extraVolumeMounts: []
2569
# -- List of additional PVCs to be created for the metadata-cache statefulset
2570
volumeClaimTemplates: []
2571
# -- Resource requests and limits for the metadata-cache
2572
# By default a safe memory limit will be requested based on allocatedMemory value (floor (* 1.2 allocatedMemory)).
2573
resources: null
2574
# -- Service annotations and labels
2575
service:
2576
annotations: {}
2577
labels: {}
2578
extraPorts: []
2579
results-cache:
2580
# -- Specifies whether memcached based results-cache should be enabled
2581
enabled: false
2582
# -- How long each pod must be ready for before the next one is started/restarted
2583
minReadySeconds: 60
2584
# -- Total number of results-cache replicas
2585
replicas: 1
2586
# -- Number of old ReplicaSets to retain to allow rollback (if not set, the default Kubernetes value is set to 10)
2587
revisionHistoryLimit: null
2588
# -- Port of the results-cache service
2589
port: 11211
2590
# -- Amount of memory allocated to results-cache for object storage (in MB).
2591
allocatedMemory: 512
2592
# -- Maximum item results-cache for memcached (in MB).
2593
maxItemMemory: 25
2594
# -- Maximum number of connections allowed
2595
connectionLimit: 16384
2596
# -- Extra init containers for results-cache pods
2597
initContainers: []
2598
# -- Annotations for the results-cache pods
2599
annotations: {}
2600
# -- Node selector for results-cache pods
2601
nodeSelector: {}
2602
# -- Affinity for results-cache pods
2603
affinity: {}
2604
dnsConfig: {}
2605
# -- topologySpreadConstraints allows to customize the default topologySpreadConstraints. This can be either a single dict as shown below or a slice of topologySpreadConstraints.
2606
# labelSelector is taken from the constraint itself (if it exists) or is generated by the chart using the same selectors as for services.
2607
topologySpreadConstraints: {}
2608
# maxSkew: 1
2609
# topologyKey: kubernetes.io/hostname
2610
# whenUnsatisfiable: ScheduleAnyway
2611
# minDomains: 1
2612
# nodeAffinityPolicy: Honor
2613
# nodeTaintsPolicy: Honor
2614
# matchLabelKeys:
2615
# - pod-template-hash
2616
2617
# -- Tolerations for results-cache pods
2618
tolerations: []
2619
# -- Pod Disruption Budget
2620
podDisruptionBudget:
2621
maxUnavailable: 1
2622
# -- The name of the PriorityClass for results-cache pods
2623
priorityClassName: null
2624
# -- Labels for results-cache pods
2625
podLabels: {}
2626
# -- Annotations for results-cache pods
2627
podAnnotations: {}
2628
# -- Management policy for results-cache pods
2629
podManagementPolicy: Parallel
2630
# -- Grace period to allow the results-cache to shutdown before it is killed
2631
terminationGracePeriodSeconds: 30
2632
# -- Stateful results-cache strategy
2633
statefulStrategy:
2634
type: RollingUpdate
2635
# -- Add extended options for results-cache memcached container. The format is the same as for the memcached -o/--extend flag.
2636
# Example:
2637
# extraExtendedOptions: 'tls,modern,track_sizes'
2638
extraExtendedOptions: ""
2639
# -- Additional CLI args for results-cache
2640
extraArgs: {}
2641
# -- Additional containers to be added to the results-cache pod.
2642
extraContainers: []
2643
# -- Additional volumes to be added to the results-cache pod (applies to both memcached and exporter containers).
2644
# Example:
2645
# extraVolumes:
2646
# - name: extra-volume
2647
# secret:
2648
# secretName: extra-volume-secret
2649
extraVolumes: []
2650
# -- Additional volume mounts to be added to the results-cache pod (applies to both memcached and exporter containers).
2651
# Example:
2652
# extraVolumeMounts:
2653
# - name: extra-volume
2654
# mountPath: /etc/extra-volume
2655
# readOnly: true
2656
extraVolumeMounts: []
2657
# -- List of additional PVCs to be created for the results-cache statefulset
2658
volumeClaimTemplates: []
2659
# -- Resource requests and limits for the results-cache
2660
# By default a safe memory limit will be requested based on allocatedMemory value (floor (* 1.2 allocatedMemory)).
2661
resources: null
2662
# -- Service annotations and labels
2663
service:
2664
annotations: {}
2665
labels: {}
2666
extraPorts: []
2667
# -- Setting for the Grafana Rollout Operator https://github.com/grafana/helm-charts/tree/main/charts/rollout-operator
2668
rollout_operator:
2669
enabled: true
2670
# -- podSecurityContext is the pod security context for the rollout operator.
2671
# When installing on OpenShift, override podSecurityContext settings with
2672
#
2673
# rollout_operator:
2674
# podSecurityContext:
2675
# fsGroup: null
2676
# runAsGroup: null
2677
# runAsUser: null
2678
podSecurityContext:
2679
fsGroup: 10001
2680
runAsGroup: 10001
2681
runAsNonRoot: true
2682
runAsUser: 10001
2683
seccompProfile:
2684
type: RuntimeDefault
2685
# Set the container security context
2686
securityContext:
2687
readOnlyRootFilesystem: true
2688
capabilities:
2689
drop: [ALL]
2690
allowPrivilegeEscalation: false
2691
minio:
2692
enabled: true
2693
mode: standalone
2694
rootUser: grafana-mimir
2695
buckets:
2696
- name: mimir-tsdb
2697
policy: none
2698
purge: false
2699
- name: mimir-ruler
2700
policy: none
2701
purge: false
2702
persistence:
2703
size: 5Gi
2704
resources:
2705
requests:
2706
cpu: 100m
2707
memory: 128Mi
2708
rootPassword: supersecret
2709
# Changed the mc config path to '/tmp' from '/etc' as '/etc' is only writable by root and OpenShift will not permit this.
2710
configPathmc: "/tmp/minio/mc/"
2711
kafka:
2712
# -- Enable Kafka for ingest-storage architecture
2713
enabled: true
2714
image:
2715
# -- The container image registry
2716
registry: chainreg.biz
2717
# -- The container image repository
2718
repository: chainguard-private/kafka-native
2719
# -- The container image tag
2720
tag: 4.3.1-r2@sha256:5ac9f1465549e846d550edb00a57569741c767bf9613f6890460410f289103b4
2721
# -- The container image pull policy
2722
pullPolicy: IfNotPresent
2723
# -- Kafka service port
2724
service:
2725
port: 9092
2726
controllerPort: 9093
2727
# -- Service type
2728
type: ClusterIP
2729
# -- Service annotations
2730
annotations: {}
2731
# -- Service labels
2732
labels: {}
2733
# -- Kafka persistence configuration
2734
persistence:
2735
# If false, use emptyDir
2736
enabled: true
2737
size: 5Gi
2738
storageClassName: ""
2739
# volumeAttributesClassName: my-cluster-vac
2740
# Requires Kubernetes 1.31+ and a CSI driver with ModifyVolume support.
2741
# Must reference an existing cluster VolumeAttributesClass.
2742
# Additional settings for emptyDir if persistence is disabled
2743
emptyDir: {}
2744
# -- Resource requests and limits for Kafka
2745
resources:
2746
requests:
2747
cpu: 1
2748
memory: 1Gi
2749
limits: {}
2750
# -- DNS configuration for Kafka pods
2751
dnsConfig: {}
2752
# -- Node selector for Kafka pods
2753
nodeSelector: {}
2754
# -- Tolerations for Kafka pods
2755
tolerations: []
2756
# -- Affinity for Kafka pods
2757
affinity: {}
2758
# -- Pod Disruption Budget
2759
podDisruptionBudget:
2760
maxUnavailable: 1
2761
# -- The name of the PriorityClass for Kafka pods
2762
priorityClassName: null
2763
# -- Labels for Kafka pods
2764
podLabels: {}
2765
# -- Annotations for Kafka pods
2766
podAnnotations: {}
2767
# -- Security context for Kafka pods
2768
securityContext:
2769
fsGroup: 1001
2770
runAsGroup: 1001
2771
runAsNonRoot: true
2772
runAsUser: 1001
2773
seccompProfile:
2774
type: RuntimeDefault
2775
# -- Container security context for Kafka containers
2776
containerSecurityContext:
2777
readOnlyRootFilesystem: true
2778
capabilities:
2779
drop: [ALL]
2780
allowPrivilegeEscalation: false
2781
# -- Grace period to allow Kafka to shutdown before it is killed
2782
terminationGracePeriodSeconds: 30
2783
# -- Kafka log retention period in hours
2784
logRetentionHours: 24
2785
# -- Additional environment variables for Kafka.
2786
# Entries are merged by name into the default Kafka env vars, following the same pattern as other chart components.
2787
# A user-provided entry with the same name as a default overrides the default in-place (preserving list order).
2788
env: []
2789
# -- Additional environment variables from secrets or configmaps
2790
extraEnvFrom: []
2791
# -- Use either this ingress or the gateway, but not both at once.
2792
# If you enable this, make sure to disable the gateway's ingress.
2793
ingress:
2794
enabled: false
2795
# ingressClassName: nginx
2796
annotations: {}
2797
paths:
2798
distributor:
2799
- path: /distributor
2800
# -- pathType (e.g. ImplementationSpecific, Prefix, .. etc.) might also be required by some Ingress Controllers
2801
# pathType: Prefix
2802
- path: /api/v1/push
2803
- path: /otlp/v1/metrics
2804
alertmanager:
2805
- path: /alertmanager
2806
- path: /multitenant_alertmanager/status
2807
- path: /multitenant_alertmanager/configs
2808
- path: /api/v1/alerts
2809
ruler:
2810
- path: /prometheus/config/v1/rules
2811
- path: /prometheus/api/v1/rules
2812
- path: /prometheus/api/v1/alerts
2813
query-frontend:
2814
- path: /prometheus
2815
- path: /api/v1/status/buildinfo
2816
compactor:
2817
- path: /api/v1/upload/block/
2818
hosts:
2819
- mimir.example.com
2820
# tls:
2821
# - secretName: mimir-distributed-tls
2822
# hosts:
2823
# - mimir.example.com
2824
# -- An nginx reverse proxy deployment that is meant to receive traffic for Mimir.
2825
gateway:
2826
# -- Whether to render the manifests related to the gateway component.
2827
enabled: true
2828
# -- Number of replicas for the Deployment
2829
replicas: 1
2830
revisionHistoryLimit: null
2831
dnsConfig: {}
2832
# -- HorizontalPodAutoscaler
2833
autoscaling:
2834
enabled: false
2835
minReplicas: 1
2836
maxReplicas: 3
2837
# -- Target CPU utilization percentage for nginx HPA. This controls the averageUtilization value for the HPA.
2838
# Setting it to null disables the CPU utilization autoscaling.
2839
targetCPUUtilizationPercentage: 70
2840
# -- Target memory utilization percentage for nginx HPA. This controls the averageUtilization value for the HPA.
2841
# Setting it to null disables the memory utilization autoscaling.
2842
targetMemoryUtilizationPercentage: 70
2843
# -- Deployment strategy. See `kubectl explain deployment.spec.strategy` for more,
2844
# ref: https://kubernetes.io/docs/concepts/workloads/controllers/deployment/#strategy
2845
strategy:
2846
type: RollingUpdate
2847
rollingUpdate:
2848
maxUnavailable: 0
2849
maxSurge: 15%
2850
# -- The name of the PriorityClass
2851
priorityClassName: null
2852
# -- Labels for Deployment Pods
2853
podLabels: {}
2854
# -- Annotations Deployment Pods
2855
podAnnotations: {}
2856
# -- PodDisruptionBudget https://kubernetes.io/docs/tasks/run-application/configure-pdb/
2857
podDisruptionBudget:
2858
maxUnavailable: 1
2859
# -- Additional CLI args for the container
2860
extraArgs: {}
2861
# -- Environment variables to add to the Pods. https://kubernetes.io/docs/tasks/inject-data-application/define-environment-variable-container/
2862
env: []
2863
# -- Environment variables from secrets or configmaps to add to the Pods.
2864
extraEnvFrom: []
2865
# -- Volumes to add to the Pods
2866
extraVolumes: []
2867
# -- Volume mounts to add to the Pods
2868
extraVolumeMounts: []
2869
# -- Additional containers to be added to the Pods.
2870
extraContainers: []
2871
# - name: dnsmasq
2872
# image: "janeczku/go-dnsmasq:release-1.0.7"
2873
# imagePullPolicy: IfNotPresent
2874
# args:
2875
# - --listen
2876
# - "127.0.0.1:8053"
2877
# - --hostsfile=/etc/hosts
2878
# - --enable-search
2879
# - --verbose
2880
2881
# -- Init containers https://kubernetes.io/docs/concepts/workloads/pods/init-containers/
2882
initContainers: []
2883
# -- SecurityContext override for gateway pods
2884
securityContext: {}
2885
# -- The SecurityContext for gateway containers
2886
containerSecurityContext:
2887
allowPrivilegeEscalation: false
2888
readOnlyRootFilesystem: true
2889
capabilities:
2890
drop: [ALL]
2891
# -- Resource requests and limits for the container
2892
resources: {}
2893
# -- Grace period to allow the gateway container to shut down before it is killed
2894
terminationGracePeriodSeconds: 30
2895
affinity: {}
2896
# -- topologySpreadConstraints allows to customize the default topologySpreadConstraints. This can be either a single dict as shown below or a slice of topologySpreadConstraints.
2897
# labelSelector is taken from the constraint itself (if it exists) or is generated by the chart using the same selectors as for services.
2898
topologySpreadConstraints:
2899
maxSkew: 1
2900
topologyKey: kubernetes.io/hostname
2901
whenUnsatisfiable: ScheduleAnyway
2902
# minDomains: 1
2903
# nodeAffinityPolicy: Honor
2904
# nodeTaintsPolicy: Honor
2905
# matchLabelKeys:
2906
# - pod-template-hash
2907
# Annotations for the Deployment
2908
annotations: {}
2909
# -- Node selector for Deployment Pods
2910
nodeSelector: {}
2911
# -- Tolerations for Deployment Pods
2912
tolerations: []
2913
# -- Gateway Service configuration
2914
service:
2915
# -- Port on which the Service listens
2916
port: 80
2917
# -- Type of the Service
2918
type: ClusterIP
2919
# -- ClusterIP of the Service
2920
clusterIP: null
2921
# -- Node port if service type is NodePort
2922
nodePort: null
2923
# -- Load balancer IP address if service type is LoadBalancer
2924
loadBalancerIP: null
2925
# -- Annotations for the Service
2926
annotations: {}
2927
# -- Labels for the Service
2928
labels: {}
2929
# -- DEPRECATED Legacy compatibility port, set to 'null' to disable
2930
legacyPort: 8080
2931
# -- Overrides the name of the Service.
2932
# By using the same name as the nginx gateway Service, Helm will not delete the Service Resource.
2933
# Instead, it will update the existing one in place.
2934
# If left as an empty string, a name is generated.
2935
nameOverride: ""
2936
# -- https://kubernetes.io/docs/concepts/services-networking/service-traffic-policy/
2937
internalTrafficPolicy: Cluster
2938
extraPorts: []
2939
# -- https://kubernetes.io/docs/concepts/services-networking/service/#traffic-distribution
2940
trafficDistribution: ""
2941
ingress:
2942
enabled: false
2943
# -- Overrides the name of the Ingress.
2944
# By using the same name as the nginx gateway Ingress, Helm will not delete the Ingress Resource.
2945
# Instead, it will update the existing one in place.
2946
# If left as an empty string, a name is generated.
2947
nameOverride: ""
2948
# -- Ingress Class Name. MAY be required for Kubernetes versions >= 1.18
2949
ingressClassName: ""
2950
# -- Labels for the Ingress
2951
labels: {}
2952
# -- Annotations for the Ingress
2953
annotations: {}
2954
# -- Hosts configuration for the Ingress
2955
hosts:
2956
# -- Passed through the `tpl` function to allow templating.
2957
- host: "{{ .Release.Name }}.mimir.example.com"
2958
paths:
2959
- path: /
2960
# -- pathType (e.g. ImplementationSpecific, Prefix, .. etc.) might also be required by some Ingress Controllers
2961
# pathType: Prefix
2962
# -- TLS configuration for the nginx ingress
2963
tls:
2964
- secretName: mimir-tls
2965
# -- Hosts included in the tls certificate. Passed through the `tpl` function to allow templating.
2966
hosts:
2967
- "{{ .Release.Name }}.mimir.example.com"
2968
# -- OpenShift Route configuration
2969
route:
2970
enabled: false
2971
# -- Annotations for the Route
2972
annotations: {}
2973
# -- Passed through the `tpl` function to allow templating.
2974
host: "{{ .Release.Name }}.mimir.example.com"
2975
tls:
2976
# -- More details about TLS configuration and termination types: https://docs.openshift.com/container-platform/3.11/architecture/networking/routes.html#secured-routes
2977
# For OpenShift 4: https://docs.openshift.com/container-platform/4.11/networking/routes/secured-routes.html
2978
termination: edge
2979
readinessProbe:
2980
httpGet:
2981
path: /ready
2982
port: http-metrics
2983
initialDelaySeconds: 15
2984
timeoutSeconds: 1
2985
nginx:
2986
# -- Enable logging of 2xx and 3xx HTTP requests
2987
verboseLogging: true
2988
# -- Image for the nginx. pullPolicy and optional pullSecrets are set in toplevel 'image' section, not here.
2989
image:
2990
# -- The Docker registry for nginx image
2991
registry: chainreg.biz
2992
# -- The nginx image repository
2993
repository: chainguard-private/nginx
2994
# -- The nginx image tag
2995
tag: mainline@sha256:26227f1fa80092c4d5c80c83ee490c144db5bf7e43de5904d4ee8897b6d7d275
2996
# -- Basic auth configuration
2997
basicAuth:
2998
# -- Enables basic authentication for nginx
2999
enabled: false
3000
# -- The basic auth username for nginx
3001
username: null
3002
# -- The basic auth password for nginx
3003
password: null
3004
# -- Uses the specified username and password to compute a htpasswd using Sprig's `htpasswd` function.
3005
# The value is templated using `tpl`. Override this to use a custom htpasswd, e.g. in case the default causes
3006
# high CPU load.
3007
htpasswd: >-
3008
{{ htpasswd (required "'gateway.nginx.basicAuth.username' is required" .Values.gateway.nginx.basicAuth.username) (required "'gateway.nginx.basicAuth.password' is required" .Values.gateway.nginx.basicAuth.password) }}
3009
# -- Name of an existing basic auth secret to use instead of gateway.nginx.basicAuth.htpasswd. Must contain '.htpasswd' key
3010
existingSecret: null
3011
config:
3012
# -- NGINX log format
3013
logFormat: |-
3014
main '$remote_addr - $remote_user [$time_local] $status '
3015
'"$request" $body_bytes_sent "$http_referer" '
3016
'"$http_user_agent" "$http_x_forwarded_for"';
3017
# -- Sets the log level of the NGINX error log. One of `debug`, `info`, `notice`, `warn`, `error`, `crit`, `alert`, or `emerg`
3018
errorLogLevel: error
3019
# -- Enables NGINX access logs
3020
accessLogEnabled: true
3021
# -- Allows appending custom configuration to the server block
3022
serverSnippet: ""
3023
# -- Allows appending custom configuration to the http block
3024
httpSnippet: ""
3025
# -- Allow to set client_max_body_size in the nginx configuration
3026
clientMaxBodySize: 540M
3027
# -- Allows to set a custom resolver
3028
resolver: null
3029
# -- Configures whether or not NGINX bind IPv6
3030
enableIPv6: true
3031
# -- Config file contents for Nginx. Passed through the `tpl` function to allow templating.
3032
file: |
3033
worker_processes 5; ## Default: 1
3034
error_log /dev/stderr {{ .Values.gateway.nginx.config.errorLogLevel }};
3035
pid /tmp/nginx.pid;
3036
worker_rlimit_nofile 8192;
3037
3038
events {
3039
worker_connections 4096; ## Default: 1024
3040
}
3041
3042
http {
3043
client_body_temp_path /tmp/client_temp;
3044
proxy_temp_path /tmp/proxy_temp_path;
3045
fastcgi_temp_path /tmp/fastcgi_temp;
3046
uwsgi_temp_path /tmp/uwsgi_temp;
3047
scgi_temp_path /tmp/scgi_temp;
3048
3049
default_type application/octet-stream;
3050
log_format {{ .Values.gateway.nginx.config.logFormat }}
3051
3052
{{- if .Values.gateway.nginx.verboseLogging }}
3053
access_log /dev/stderr main;
3054
{{- else }}
3055
3056
map $status $loggable {
3057
~^[23] 0;
3058
default 1;
3059
}
3060
access_log {{ .Values.gateway.nginx.config.accessLogEnabled | ternary "/dev/stderr main if=$loggable;" "off;" }}
3061
{{- end }}
3062
3063
sendfile on;
3064
tcp_nopush on;
3065
proxy_http_version 1.1;
3066
3067
{{- if .Values.gateway.nginx.config.resolver }}
3068
resolver {{ .Values.gateway.nginx.config.resolver }};
3069
{{- else }}
3070
resolver {{ .Values.global.dnsService }}.{{ .Values.global.dnsNamespace }}.svc.{{ .Values.global.clusterDomain }};
3071
{{- end }}
3072
3073
{{- with .Values.gateway.nginx.config.httpSnippet }}
3074
{{ . | nindent 2 }}
3075
{{- end }}
3076
3077
# Ensure that X-Scope-OrgID is always present, default to the no_auth_tenant for backwards compatibility when multi-tenancy was turned off.
3078
map $http_x_scope_orgid $ensured_x_scope_orgid {
3079
default $http_x_scope_orgid;
3080
"" "{{ include "mimir.noAuthTenant" . }}";
3081
}
3082
3083
map $http_x_scope_orgid $has_multiple_orgid_headers {
3084
default 0;
3085
"~^.+,.+$" 1;
3086
}
3087
3088
proxy_read_timeout 300;
3089
server {
3090
listen {{ include "mimir.serverHttpListenPort" . }};
3091
{{- if .Values.gateway.nginx.config.enableIPv6 }}
3092
listen [::]:{{ include "mimir.serverHttpListenPort" . }};
3093
{{- end }}
3094
3095
{{- if .Values.gateway.nginx.config.clientMaxBodySize }}
3096
client_max_body_size {{ .Values.gateway.nginx.config.clientMaxBodySize }};
3097
{{- end }}
3098
3099
{{- if .Values.gateway.nginx.basicAuth.enabled }}
3100
auth_basic "Mimir";
3101
auth_basic_user_file /etc/nginx/secrets/.htpasswd;
3102
{{- end }}
3103
3104
if ($has_multiple_orgid_headers = 1) {
3105
return 400 'Sending multiple X-Scope-OrgID headers is not allowed. Use a single header with | as separator instead.';
3106
}
3107
3108
location = / {
3109
return 200 'OK';
3110
auth_basic off;
3111
}
3112
3113
location = /ready {
3114
return 200 'OK';
3115
auth_basic off;
3116
}
3117
3118
proxy_set_header X-Scope-OrgID $ensured_x_scope_orgid;
3119
3120
# Distributor endpoints
3121
location /distributor {
3122
set $distributor {{ template "mimir.fullname" . }}-distributor-headless.{{ .Release.Namespace }}.svc.{{ .Values.global.clusterDomain }};
3123
proxy_pass http://$distributor:{{ include "mimir.serverHttpListenPort" . }}$request_uri;
3124
}
3125
location = /api/v1/push {
3126
set $distributor {{ template "mimir.fullname" . }}-distributor-headless.{{ .Release.Namespace }}.svc.{{ .Values.global.clusterDomain }};
3127
proxy_pass http://$distributor:{{ include "mimir.serverHttpListenPort" . }}$request_uri;
3128
}
3129
location /otlp/v1/metrics {
3130
set $distributor {{ template "mimir.fullname" . }}-distributor-headless.{{ .Release.Namespace }}.svc.{{ .Values.global.clusterDomain }};
3131
proxy_pass http://$distributor:{{ include "mimir.serverHttpListenPort" . }}$request_uri;
3132
}
3133
3134
# Alertmanager endpoints
3135
location {{ template "mimir.alertmanagerHttpPrefix" . }} {
3136
set $alertmanager {{ template "mimir.fullname" . }}-alertmanager-headless.{{ .Release.Namespace }}.svc.{{ .Values.global.clusterDomain }};
3137
proxy_pass http://$alertmanager:{{ include "mimir.serverHttpListenPort" . }}$request_uri;
3138
}
3139
location = /multitenant_alertmanager/status {
3140
set $alertmanager {{ template "mimir.fullname" . }}-alertmanager-headless.{{ .Release.Namespace }}.svc.{{ .Values.global.clusterDomain }};
3141
proxy_pass http://$alertmanager:{{ include "mimir.serverHttpListenPort" . }}$request_uri;
3142
}
3143
location = /multitenant_alertmanager/configs {
3144
set $alertmanager {{ template "mimir.fullname" . }}-alertmanager-headless.{{ .Release.Namespace }}.svc.{{ .Values.global.clusterDomain }};
3145
proxy_pass http://$alertmanager:{{ include "mimir.serverHttpListenPort" . }}$request_uri;
3146
}
3147
location = /api/v1/alerts {
3148
set $alertmanager {{ template "mimir.fullname" . }}-alertmanager-headless.{{ .Release.Namespace }}.svc.{{ .Values.global.clusterDomain }};
3149
proxy_pass http://$alertmanager:{{ include "mimir.serverHttpListenPort" . }}$request_uri;
3150
}
3151
3152
# Ruler endpoints
3153
location {{ template "mimir.prometheusHttpPrefix" . }}/config/v1/rules {
3154
set $ruler {{ template "mimir.fullname" . }}-ruler.{{ .Release.Namespace }}.svc.{{ .Values.global.clusterDomain }};
3155
proxy_pass http://$ruler:{{ include "mimir.serverHttpListenPort" . }}$request_uri;
3156
}
3157
location {{ template "mimir.prometheusHttpPrefix" . }}/api/v1/rules {
3158
set $ruler {{ template "mimir.fullname" . }}-ruler.{{ .Release.Namespace }}.svc.{{ .Values.global.clusterDomain }};
3159
proxy_pass http://$ruler:{{ include "mimir.serverHttpListenPort" . }}$request_uri;
3160
}
3161
3162
location {{ template "mimir.prometheusHttpPrefix" . }}/api/v1/alerts {
3163
set $ruler {{ template "mimir.fullname" . }}-ruler.{{ .Release.Namespace }}.svc.{{ .Values.global.clusterDomain }};
3164
proxy_pass http://$ruler:{{ include "mimir.serverHttpListenPort" . }}$request_uri;
3165
}
3166
location = /ruler/ring {
3167
set $ruler {{ template "mimir.fullname" . }}-ruler.{{ .Release.Namespace }}.svc.{{ .Values.global.clusterDomain }};
3168
proxy_pass http://$ruler:{{ include "mimir.serverHttpListenPort" . }}$request_uri;
3169
}
3170
3171
# Rest of {{ template "mimir.prometheusHttpPrefix" . }} goes to the query frontend
3172
location {{ template "mimir.prometheusHttpPrefix" . }} {
3173
set $query_frontend {{ template "mimir.fullname" . }}-query-frontend.{{ .Release.Namespace }}.svc.{{ .Values.global.clusterDomain }};
3174
proxy_pass http://$query_frontend:{{ include "mimir.serverHttpListenPort" . }}$request_uri;
3175
}
3176
3177
# Buildinfo endpoint can go to any component
3178
location = /api/v1/status/buildinfo {
3179
set $query_frontend {{ template "mimir.fullname" . }}-query-frontend.{{ .Release.Namespace }}.svc.{{ .Values.global.clusterDomain }};
3180
proxy_pass http://$query_frontend:{{ include "mimir.serverHttpListenPort" . }}$request_uri;
3181
}
3182
3183
# Compactor endpoint for uploading blocks
3184
location /api/v1/upload/block/ {
3185
set $compactor {{ template "mimir.fullname" . }}-compactor.{{ .Release.Namespace }}.svc.{{ .Values.global.clusterDomain }};
3186
proxy_pass http://$compactor:{{ include "mimir.serverHttpListenPort" . }}$request_uri;
3187
}
3188
3189
{{- with .Values.gateway.nginx.config.serverSnippet }}
3190
{{ . | nindent 4 }}
3191
{{- end }}
3192
}
3193
}
3194
metaMonitoring:
3195
# Dashboard configuration for deploying Grafana dashboards for Mimir
3196
dashboards:
3197
# -- If enabled, Grafana dashboards are deployed
3198
enabled: false
3199
# -- Alternative namespace to create dashboards ConfigMaps in. They are created in the Helm release namespace by default.
3200
namespace: null
3201
# -- Annotations to add to the Grafana dashboard ConfigMap
3202
annotations:
3203
k8s-sidecar-target-directory: /tmp/dashboards/Mimir Dashboards
3204
# -- Labels to add to the Grafana dashboard ConfigMap
3205
labels:
3206
grafana_dashboard: "1"
3207
# ServiceMonitor configuration for monitoring Kubernetes Services with Prometheus Operator, Grafana Agent (deprecated), and/or Grafana Alloy
3208
serviceMonitor:
3209
# -- If enabled, ServiceMonitor resources for Prometheus Operator are created
3210
enabled: false
3211
# -- To disable setting a 'cluster' label in metrics, set to 'null'.
3212
# To overwrite the 'cluster' label with your own value, set to a non-empty string.
3213
# Keep empty string "" to have the default value in the 'cluster' label, which is the helm release name for Mimir.
3214
clusterLabel: ""
3215
# -- Alternative namespace for ServiceMonitor resources
3216
# If left unset, the default is to install the ServiceMonitor resources in the namespace where the chart is installed, i.e. the namespace specified for the helm command.
3217
namespace: null
3218
# -- Namespace selector for ServiceMonitor resources
3219
# If left unset, the default is to select the namespace where the chart is installed, i.e. the namespace specified for the helm command.
3220
namespaceSelector: null
3221
# -- ServiceMonitor annotations
3222
annotations: {}
3223
# -- Additional ServiceMonitor labels
3224
labels: {}
3225
# -- ServiceMonitor scrape interval
3226
interval: null
3227
# -- ServiceMonitor scrape timeout in Go duration format (e.g. 15s)
3228
scrapeTimeout: null
3229
# -- ServiceMonitor relabel configs to apply to targets before scraping
3230
# https://github.com/prometheus-operator/prometheus-operator/blob/main/Documentation/api.md#monitoring.coreos.com/v1.RelabelConfig
3231
relabelings: []
3232
# -- ServiceMonitor metric relabel configs to apply to samples before ingestion
3233
# https://github.com/prometheus-operator/prometheus-operator/blob/main/Documentation/api.md#monitoring.coreos.com/v1.RelabelConfig
3234
metricRelabelings: []
3235
# -- ServiceMonitor will use http by default, but you can pick https as well
3236
scheme: http
3237
# -- ServiceMonitor will use these tlsConfig settings to make the health check requests
3238
tlsConfig: null
3239
# Rules for the Prometheus Operator
3240
prometheusRule:
3241
# -- If enabled, a PrometheusRule resource for Prometheus Operator is created
3242
enabled: false
3243
# -- Create standard Mimir alerts in Prometheus Operator via a PrometheusRule CRD
3244
mimirAlerts: false
3245
# -- Create standard Mimir recording rules in Prometheus Operator via a PrometheusRule CRD
3246
mimirRules: false
3247
# -- PrometheusRule annotations
3248
annotations: {}
3249
# -- Additional PrometheusRule labels. To find out what your Prometheus operator expects,
3250
# see the Prometheus object and field spec.ruleSelector
3251
labels: {}
3252
# -- prometheusRule namespace. This should be the namespace where the Prometheus Operator is installed,
3253
# unless the Prometheus Operator is set up to look for rules outside its namespace
3254
namespace: null
3255
# -- Contents of Prometheus rules file
3256
groups: []
3257
# - name: mimir_api_1
3258
# rules:
3259
# - expr: histogram_quantile(0.99, sum(rate(cortex_request_duration_seconds_bucket[4m]))
3260
# by (le, cluster, job))
3261
# record: cluster_job:cortex_request_duration_seconds:99quantile
3262
# - expr: histogram_quantile(0.50, sum(rate(cortex_request_duration_seconds_bucket[4m]))
3263
# by (le, cluster, job))
3264
# record: cluster_job:cortex_request_duration_seconds:50quantile
3265
# - expr: sum(rate(cortex_request_duration_seconds_sum[4m])) by (cluster, job) / sum(rate(cortex_request_duration_seconds_count[4m]))
3266
# by (cluster, job)
3267
# record: cluster_job:cortex_request_duration_seconds:avg
3268
# - expr: sum(rate(cortex_request_duration_seconds_bucket[4m])) by (le, cluster, job)
3269
# record: cluster_job:cortex_request_duration_seconds_bucket:sum_rate
3270
# - expr: sum(rate(cortex_request_duration_seconds_sum[4m])) by (cluster, job)
3271
# record: cluster_job:cortex_request_duration_seconds_sum:sum_rate
3272
# - expr: sum(rate(cortex_request_duration_seconds_count[4m])) by (cluster, job)
3273
# record: cluster_job:cortex_request_duration_seconds_count:sum_rate
3274
3275
# -- DEPRECATED: Grafana Agent is deprecated and will reach the End-of-Support in the end of 2025.
3276
# Users are recommended to switch to Grafana k8s-monitoring, that orchestrates the lifecycle of Grafana Alloy instances, and comes with built-in support for monitoring Grafana LGTM stacks (https://github.com/grafana/k8s-monitoring-helm/tree/k8s-monitoring-3.2.2/charts/k8s-monitoring)
3277
# metaMonitoring.grafanaAgent configures the built in Grafana Agent that can scrape metrics and logs and send them to a local or remote destination
3278
grafanaAgent:
3279
# -- Controls whether to create PodLogs, MetricsInstance, LogsInstance, and GrafanaAgent CRs to scrape the
3280
# ServiceMonitors of the chart and ship metrics and logs to the remote endpoints below.
3281
# Note that you need to configure serviceMonitor in order to have some metrics available.
3282
enabled: false
3283
# -- Controls the image repository and tag for config-reloader and grafana-agent containers in the meta-monitoring
3284
# StatefulSet and DaemonSet created by the grafana-agent-operator. You can define one or both sections under imageRepo.
3285
# If a section is defined, you must pass repo, image and tag keys.
3286
imageRepo:
3287
# configReloader:
3288
# repo: quay.io
3289
# image: prometheus-operator/prometheus-config-reloader
3290
# tag: v0.47.0
3291
# grafanaAgent:
3292
# repo: docker.io
3293
# image: grafana/agent
3294
# tag: v0.29.0
3295
3296
# -- Resource requests and limits for the grafana-agent and config-reloader containers in the meta-monitoring
3297
# StatefulSet and DaemonSet created by the grafana-agent-operator. You can define one or both sections under resources.
3298
resources:
3299
# configReloader:
3300
# requests:
3301
# cpu: 5m
3302
# memory: 10Mi
3303
# limits:
3304
# memory: 50Mi
3305
# grafanaAgent:
3306
# requests:
3307
# cpu: 20m
3308
# memory: 700Mi
3309
# limits:
3310
# memory: 1400Mi
3311
3312
# -- Controls whether to install the Grafana Agent Operator and its CRDs.
3313
# Note that helm will not install CRDs if this flag is enabled during an upgrade.
3314
# In that case install the CRDs manually from https://github.com/grafana/agent/tree/main/operations/agent-static-operator/crds
3315
installOperator: false
3316
logs:
3317
# -- Controls whether to create resources PodLogs and LogsInstance resources
3318
enabled: true
3319
# -- To disable setting a 'cluster' label in logs, set to 'null'.
3320
# To overwrite the 'cluster' label with your own value, set to a non-empty string.
3321
# Keep empty string "" to have the default value in the 'cluster' label, which is the helm release name for Mimir.
3322
clusterLabel: ""
3323
# -- Default destination for logs. The config here is translated to Promtail client
3324
# configuration to write logs to this Loki-compatible remote. Optional.
3325
remote:
3326
# -- Full URL for Loki push endpoint. Usually ends in /loki/api/v1/push
3327
url: ""
3328
auth:
3329
# -- Used to set X-Scope-OrgID header on requests. Usually not used in combination with username and password.
3330
tenantId: ""
3331
# -- Basic authentication username. Optional.
3332
username: ""
3333
# -- The value under key passwordSecretKey in this secret will be used as the basic authentication password. Required only if passwordSecretKey is set.
3334
passwordSecretName: ""
3335
# -- The value under this key in passwordSecretName will be used as the basic authentication password. Required only if passwordSecretName is set.
3336
passwordSecretKey: ""
3337
# -- Client configurations for the LogsInstance that will scrape Mimir pods. Follows the format of .remote.
3338
additionalClientConfigs: []
3339
metrics:
3340
# -- Controls whether to create MetricsInstance resources and ServiceMonitor resources for scraping Kubernetes (when .scrapeK8s.enabled=true).
3341
enabled: true
3342
# -- Default destination for metrics. The config here is translated to remote_write
3343
# configuration to push metrics to this Prometheus-compatible remote. Optional.
3344
# Note that you need to configure serviceMonitor in order to have some metrics available.
3345
#
3346
# If you leave the metaMonitoring.grafanaAgent.metrics.remote.url field empty,
3347
# then the chart automatically fills in the address of the Mimir NGINX Service.
3348
#
3349
# If metaMonitoring.grafanaAgent.metrics.remote.url is not set,
3350
# then the metamonitoring metrics are sent to the Mimir cluster.
3351
# You can query these metrics using the HTTP header X-Scope-OrgID: metamonitoring
3352
remote:
3353
# -- Full URL for Prometheus remote-write. Usually ends in /push.
3354
# If you leave the url field empty, then the chart automatically fills in the
3355
# address of the Mimir NGINX Service.
3356
url: ""
3357
# -- Used to add HTTP headers to remote-write requests.
3358
headers: {}
3359
auth:
3360
# -- Basic authentication username. Optional.
3361
username: ""
3362
# -- The value under key passwordSecretKey in this secret will be used as the basic authentication password. Required only if passwordSecretKey is set.
3363
passwordSecretName: ""
3364
# -- The value under this key in passwordSecretName will be used as the basic authentication password. Required only if passwordSecretName is set.
3365
passwordSecretKey: ""
3366
# -- Configuration for SigV4 authentication.
3367
# sigv4:
3368
# accessKey: abcd
3369
# profile: default
3370
# region: us-east-1
3371
# roleARN: arn:aws:iam::1234:role/1234
3372
# secretKey: abcd
3373
sigv4: {}
3374
# -- Additional remote-write for the MetricsInstance that will scrape Mimir pods. Follows the format of .remote.
3375
additionalRemoteWriteConfigs: []
3376
scrapeK8s:
3377
# -- When grafanaAgent.enabled and serviceMonitor.enabled, controls whether to create ServiceMonitors CRs
3378
# for cadvisor, kubelet, and kube-state-metrics. The scraped metrics are reduced to those pertaining to
3379
# Mimir pods only.
3380
enabled: true
3381
# -- Controls service discovery of kube-state-metrics.
3382
kubeStateMetrics:
3383
namespace: kube-system
3384
labelSelectors:
3385
app.kubernetes.io/name: kube-state-metrics
3386
service:
3387
port: http-metrics
3388
# -- The scrape interval for all ServiceMonitors.
3389
scrapeInterval: 60s
3390
# -- Sets the namespace of the resources. Leave empty or unset to use the same namespace as the Helm release.
3391
namespace: ""
3392
# -- Labels to add to all monitoring.grafana.com custom resources.
3393
# Does not affect the ServiceMonitors for kubernetes metrics; use serviceMonitor.labels for that.
3394
labels: {}
3395
# -- Annotations to add to all monitoring.grafana.com custom resources.
3396
# Does not affect the ServiceMonitors for kubernetes metrics; use serviceMonitor.annotations for that.
3397
annotations: {}
3398
# -- SecurityContext of Grafana Agent pods. This is different from the SecurityContext that the operator pod runs with.
3399
# The operator pod SecurityContext is configured in the grafana-agent-operator.podSecurityContext value.
3400
# As of mimir-distributed 4.0.0 the Agent DaemonSet that collects logs needs to run as root and be able to access the
3401
# pod logs on each host. Because of that the agent subchart is incompatible with the PodSecurityPolicy of the
3402
# mimir-distributed chart and with the Restricted policy of Pod Security Standards https://kubernetes.io/docs/concepts/security/pod-security-standards/
3403
podSecurityContext:
3404
# fsGroup: 10001
3405
# runAsGroup: 10001
3406
# runAsNonRoot: true
3407
# runAsUser: 10001
3408
# seccompProfile:
3409
# type: RuntimeDefault
3410
3411
# -- SecurityContext of Grafana Agent containers. This is different from the SecurityContext that the operator container runs with.
3412
# As of mimir-distributed 4.0.0 the agent subchart needs to have root file system write access so that the Agent pods can write temporary files where.
3413
# This makes the subchart incompatible with the PodSecurityPolicy of the mimir-distributed chart.
3414
containerSecurityContext:
3415
# allowPrivilegeEscalation: false
3416
# runAsUser: 10001
3417
# capabilities:
3418
# drop: [ALL]
3419
3420
# -- Node selector for Deployment Pods
3421
nodeSelector: {}
3422
# -- Tolerations for Deployment Pods
3423
tolerations: []
3424
# -- topologySpreadConstraints allows to customize the default topologySpreadConstraints.
3425
# More info: https://kubernetes.io/docs/concepts/scheduling-eviction/topology-spread-constraints/#topologyspreadconstraints-field
3426
topologySpreadConstraints:
3427
- maxSkew: 1
3428
topologyKey: kubernetes.io/hostname
3429
whenUnsatisfiable: ScheduleAnyway
3430
# minDomains: 1
3431
# nodeAffinityPolicy: Honor
3432
# nodeTaintsPolicy: Honor
3433
# matchLabelKeys:
3434
# - pod-template-hash
3435
# -- DEPRECATED: Grafana Agent is deprecated and will reach the End-of-Support in the end of 2025.
3436
# Users are recommended to switch to Grafana k8s-monitoring (https://github.com/grafana/k8s-monitoring-helm/tree/k8s-monitoring-3.2.2/charts/k8s-monitoring)
3437
# -- Values exposed by the [Grafana agent-operator chart](https://github.com/grafana/helm-charts/blob/main/charts/agent-operator/values.yaml)
3438
grafana-agent-operator:
3439
podSecurityContext:
3440
fsGroup: 10001
3441
runAsGroup: 10001
3442
runAsNonRoot: true
3443
runAsUser: 10001
3444
seccompProfile:
3445
type: RuntimeDefault
3446
containerSecurityContext:
3447
allowPrivilegeEscalation: false
3448
readOnlyRootFilesystem: true
3449
capabilities:
3450
drop: [ALL]
3451
smoke_test:
3452
# -- Allows to override the container image of the smoke-test component.
3453
# When set it takes precedence over what is defined in global "image".
3454
image:
3455
# repository: grafana/mimir
3456
# tag: 3.2.0
3457
# -- Controls the backoffLimit on the Kubernetes Job. The Job is marked as failed after that many retries.
3458
backoffLimit: 5
3459
# The image section has been removed as continuous test is now a module of the regular Mimir image.
3460
# See settings for the image at the top image section.
3461
tenantId: ""
3462
extraArgs: {}
3463
env: []
3464
extraEnvFrom: []
3465
annotations: {}
3466
initContainers: []
3467
resources: {}
3468
# -- The name of the PriorityClass for smoke-test pods
3469
priorityClassName: null
3470
dnsConfig: {}
3471
# -- Settings for mimir-continuous-test.
3472
# This continuously writes and reads metrics from Mimir.
3473
# https://grafana.com/docs/mimir/latest/manage/tools/mimir-continuous-test/
3474
continuous_test:
3475
enabled: false
3476
# -- Allows to override the container image of the continuous-test component.
3477
# When set it takes precedence over what is defined in global "image".
3478
image:
3479
# repository: grafana/mimir-continuous-test
3480
# tag: 3.2.0
3481
# -- Number of replicas to start of continuous test
3482
replicas: 1
3483
revisionHistoryLimit: null
3484
# The image section has been removed as continuous test is now a module of the regular Mimir image.
3485
# See settings for the image at the top image section.
3486
# -- The endpoints to use for writing to and reading metrics from your instance.
3487
# Defaults to the gateway URL, but you may want to test from an external ingress which you can configure here.
3488
## -- Mimir Write Endpoint to use for writing metrics to your instance. Defaults to mimir.gatewayUrl if not set.
3489
write:
3490
# -- Mimir Read Endpoint to use for querying metrics from your instance. Defaults to mimir.gatewayUrl if not set. Path /prometheus is appended to value.
3491
read:
3492
# -- Authentication settings of continuous test
3493
auth:
3494
# -- Type of authentication to use (tenantId, basicAuth, bearerToken)
3495
type: tenantId
3496
# -- The tenant to use for tenantId or basicAuth authentication type
3497
# In case of tenantId authentication, it is injected as the X-Scope-OrgID header on requests.
3498
# In case of basicAuth, it is set as the username.
3499
tenant: "mimir-continuous-test"
3500
# -- Password for basicAuth auth (note: can be environment variable from secret attached in extraEnvFrom, e.g. $(PASSWORD))
3501
password: null
3502
# -- Bearer token for bearerToken auth (note: can be environment variable from secret attached in extraEnvFrom, e.g. $(TOKEN))
3503
bearerToken: null
3504
# -- The maximum number of series to write in a single request.
3505
numSeries: 1000
3506
# -- How far back in the past metrics can be queried at most.
3507
maxQueryAge: "48h"
3508
# -- Interval between test runs
3509
runInterval: "5m"
3510
# -- Pod affinity settings for the continuous test replicas
3511
affinity: {}
3512
# -- Annotations for the continuous test Deployment
3513
annotations: {}
3514
# -- The SecurityContext for continuous test containers
3515
containerSecurityContext:
3516
readOnlyRootFilesystem: true
3517
allowPrivilegeEscalation: false
3518
capabilities:
3519
drop: [ALL]
3520
# -- Extra environment variables for continuous test containers
3521
env: []
3522
# -- Extra command line arguments for the continuous test container
3523
extraArgs: {}
3524
# -- Extra environment from secret/configmap for continuous test containers
3525
extraEnvFrom: []
3526
# -- Extra volumes for the continuous test container
3527
extraVolumes: []
3528
# -- Extra volume mounts for the continuous test container
3529
extraVolumeMounts: []
3530
# -- Extra containers for the continuous test Deployment
3531
extraContainers: []
3532
# -- Extra initContainers for the continuous test Deployment
3533
initContainers: []
3534
# -- Nodeselector of continuous test replicas
3535
nodeSelector: {}
3536
# -- The name of the PriorityClass for continuous test pods
3537
priorityClassName: null
3538
# -- Kubernetes resource requests and limits for continuous test
3539
resources:
3540
limits:
3541
memory: 1Gi
3542
requests:
3543
cpu: "1"
3544
memory: 512Mi
3545
# -- Security context for the continuous test Deployment
3546
securityContext: {}
3547
# -- Service for monitoring continuous test
3548
service:
3549
annotations: {}
3550
labels: {}
3551
extraPorts: []
3552
# -- Upgrade strategy for the continuous test Deployment
3553
strategy:
3554
type: RollingUpdate
3555
rollingUpdate:
3556
maxSurge: 0
3557
maxUnavailable: 1
3558
dnsConfig: {}
3559
tolerations: []
3560
terminationGracePeriodSeconds: 30
3561
# -- Add dynamic manifests via values. Example:
3562
# extraObjects:
3563
# - kind: ConfigMap
3564
# apiVersion: v1
3565
# metadata:
3566
# name: extra-cm-{{ .Release.Name }}
3567
# data: |
3568
# extra.yml: "does-my-install-need-extra-info: true"
3569
# alternatively, you can use strings, which lets you use the mimir defines:
3570
# extraObjects:
3571
# - |
3572
# kind: ConfigMap
3573
# apiVersion: v1
3574
# metadata:
3575
# name: extra-cm-{{ .Release.Name }}
3576
# data: |
3577
# extra.yml: "{{ include some-mimir-define }}"
3578
extraObjects: []
3579

The trusted source for open source

Talk to an expert
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsChainguard OS PackagesChainguard ActionsChainguard Agent SkillsIntegrationsPricing
© 2026 Chainguard, Inc. All Rights Reserved.
Chainguard® and the Chainguard logo are registered trademarks of Chainguard, Inc. in the United States and/or other countries.
The other respective trademarks mentioned on this page are owned by the respective companies and use of them does not imply any affiliation or endorsement.