DirectorySecurity AdvisoriesPricing
Sign in
Directory
opentelemetry-collector logoHELM

opentelemetry-collector

Helm chart
Last changed
Request a free trial

Contact our team to test out this Helm chart and related images for free. Please also indicate any other images you would like to evaluate.

Overview
Chart tags
Default values
Chart metadata
Images

Tag:
Compare:

1
# Default values for opentelemetry-collector.
2
# This is a YAML-formatted file.
3
# Declare variables to be passed into your templates.
4
5
nameOverride: ""
6
fullnameOverride: ""
7
# Valid values are "daemonset", "deployment", and "statefulset".
8
mode: ""
9
# Override the default apiVersion for custom controllers or for testing new API versions.
10
apiVersion: "apps/v1"
11
# Specify which namespace should be used to deploy the resources into
12
namespaceOverride: ""
13
# Handles basic configuration of components that
14
# also require k8s modifications to work correctly.
15
# .Values.config can be used to modify/add to a preset
16
# component configuration, but CANNOT be used to remove
17
# preset configuration. If you require removal of any
18
# sections of a preset configuration, you cannot use
19
# the preset. Instead, configure the component manually in
20
# .Values.config and use the other fields supplied in the
21
# values.yaml to configure k8s as necessary.
22
presets:
23
# Configures the collector to collect logs.
24
# Adds the file_log receiver to the logs pipeline
25
# and adds the necessary volumes and volume mounts.
26
# Best used with mode = daemonset.
27
# See https://opentelemetry.io/docs/kubernetes/collector/components/#filelog-receiver for details on the receiver.
28
logsCollection:
29
enabled: false
30
includeCollectorLogs: false
31
# Enabling this writes checkpoints in /var/lib/otelcol/ host directory.
32
# Note this changes collector's user to root, so that it can write to host directory.
33
storeCheckpoints: false
34
# The maximum bytes size of the recombined field.
35
# Once the size exceeds the limit, all received entries of the source will be combined and flushed.
36
maxRecombineLogSize: 102400
37
# Configures the collector to collect host metrics.
38
# Adds the hostmetrics receiver to the metrics pipeline
39
# and adds the necessary volumes and volume mounts.
40
# Best used with mode = daemonset.
41
# See https://opentelemetry.io/docs/kubernetes/collector/components/#host-metrics-receiver for details on the receiver.
42
hostMetrics:
43
enabled: false
44
# Configures the Kubernetes Processor to add Kubernetes metadata.
45
# Adds the k8s_attributes processor to all the pipelines
46
# and adds a preset of minimum required RBAC rules to ClusterRole.
47
# Best used with mode = daemonset.
48
# See https://opentelemetry.io/docs/kubernetes/collector/components/#kubernetes-attributes-processor for details on the receiver.
49
kubernetesAttributes:
50
enabled: false
51
# When enabled the processor will extract all labels for an associated pod and add them as resource attributes.
52
# The label's exact name will be the key.
53
extractAllPodLabels: false
54
# When enabled the processor will extract all annotations for an associated pod and add them as resource attributes.
55
# The annotation's exact name will be the key.
56
extractAllPodAnnotations: false
57
# Configures the collector to collect node, pod, and container metrics from the API server on a kubelet.
58
# Adds the kubeletstats receiver to the metrics pipeline
59
# and adds the necessary rules to ClusterRole.
60
# Best used with mode = daemonset.
61
# See https://opentelemetry.io/docs/kubernetes/collector/components/#kubeletstats-receiver for details on the receiver.
62
kubeletMetrics:
63
enabled: false
64
# Configures the collector to collect kubernetes events.
65
# Adds the k8sobjects receiver to the logs pipeline
66
# and collects kubernetes events by default.
67
# Best used with mode = deployment or statefulset.
68
# See https://opentelemetry.io/docs/kubernetes/collector/components/#kubernetes-objects-receiver for details on the receiver.
69
kubernetesEvents:
70
enabled: false
71
# When enabled, the preset uses the k8s_events receiver instead of k8sobjects. Will default to true in a future release.
72
useK8sEventsReceiver: false
73
# Collects Kubernetes objects via the k8sobjects receiver in pull mode (default interval: 1h).
74
# Can be used with mode = deployment, statefulset, or daemonset.
75
# Compatible with kubernetesEvents preset. Extra resources can be added via
76
# config.receivers.k8sobjects.objects (ClusterRole rules must be added manually via clusterRole.rules).
77
kubernetesObjects:
78
enabled: false
79
# When enabled with mode = daemonset, leader election is setup to prevent telemetry duplication.
80
# disableLeaderElection: false
81
# When enabled, watch mode is added alongside pull to stream real-time changes.
82
watch: false
83
# Core Kubernetes workload resources: pods, nodes, namespaces, services, serviceaccounts, deployments, replicasets, daemonsets, statefulsets, jobs, cronjobs
84
core:
85
enabled: true
86
# RBAC resources: roles, rolebindings, clusterroles, clusterrolebindings
87
rbac:
88
enabled: true
89
# Storage resources: storageclasses, persistentvolumes, persistentvolumeclaims
90
storage:
91
enabled: true
92
# Networking resources: ingresses, networkpolicies
93
networking:
94
enabled: true
95
# Autoscaling resources: horizontalpodautoscalers
96
autoscaling:
97
enabled: true
98
# VPA resources: verticalpodautoscalers (requires VPA CRD to be installed)
99
vpa:
100
enabled: false
101
# Policy resources: poddisruptionbudgets
102
policy:
103
enabled: true
104
# API extensions resources: customresourcedefinitions
105
apiExtensions:
106
enabled: true
107
# Kubernetes events, collected in watch mode.
108
events:
109
enabled: false
110
# Configures the Kubernetes Cluster Receiver to collect cluster-level metrics.
111
# Adds the k8s_cluster receiver to the metrics pipeline
112
# and adds the necessary rules to ClusterRole.
113
# Can be used with mode = deployment, statefulset, or daemonset.
114
# When used as a daemonset or with multiple replicas, leader election is set up to prevent duplication.
115
# See https://opentelemetry.io/docs/kubernetes/collector/components/#kubernetes-cluster-receiver for details on the receiver.
116
clusterMetrics:
117
enabled: false
118
# When enabled with mode = daemonset or with multiple replicas, leader election is set up to prevent telemetry duplication.
119
# disableLeaderElection: false
120
# Configures the collector to collect logs and metrics from pods with specific annotations.
121
# This preset can not be used together with the `logsCollection` preset.
122
# Adds the receiver_creator receiver to the logs and metrics pipelines
123
# and adds the necessary rules to ClusterRole.
124
# Best used with mode = daemonset.
125
# See https://github.com/open-telemetry/opentelemetry-collector-contrib/blob/main/receiver/receivercreator/README.md#generate-receiver-configurations-from-provided-hints for details on the receiver.
126
annotationDiscovery:
127
logs:
128
enabled: false
129
metrics:
130
enabled: false
131
# Configures the collector to collect profiling data.
132
# Adds profiles pipeline with the profiling receiver,
133
# and adds the necessary volumes, security context and host PID access.
134
#
135
# Warning: The profiling receiver requires elevated capabilities and hostPID,
136
# so it should be used with a dedicated collector distribution (e.g. otelcol-ebpf-profiler)
137
# rather than the general-purpose k8s distribution. This avoids granting elevated privileges
138
# to the same collector that handles metrics, traces, and logs.
139
# See https://github.com/open-telemetry/opentelemetry-collector-releases/tree/main/distributions/otelcol-ebpf-profiler for more details.
140
# When enabled, the collector is also scheduled on Linux nodes only.
141
profiling:
142
enabled: false
143
# Configures the collector to detect resource attributes using the resourcedetection processor.
144
# Adds the resourcedetection/env processor to all pipelines.
145
# Each detector can be enabled individually. Base detectors 'env' and 'k8s_api' are always included when any detector is enabled.
146
# Typically used to resolve the 'k8s.cluster.name' resource attribute.
147
# See https://github.com/open-telemetry/opentelemetry-collector-contrib/tree/main/processor/resourcedetectionprocessor for details.
148
resourceDetection:
149
enabled: false
150
env:
151
enabled: true
152
k8s_api:
153
enabled: true
154
eks:
155
enabled: false
156
aks:
157
enabled: false
158
gcp:
159
enabled: false
160
configMap:
161
# Specifies whether a configMap should be created (true by default)
162
create: true
163
# Specifies an existing ConfigMap to be mounted to the pod
164
# The ConfigMap MUST include the collector configuration via a key named 'relay' or the collector will not start.
165
# This also supports template content, which will eventually be converted to yaml.
166
existingName: ""
167
# Specifies the relative path to custom ConfigMap template file. This option SHOULD be used when bundling a custom
168
# ConfigMap template, as it enables pod restart via a template checksum annotation.
169
# existingPath: ""
170
# When enabled, the chart will configure the collector to emit its traces, metrics, and logs over http via the OTLP using the Otel Go SDK.
171
# If internalTelemetryViaOTLP.metrics.enabled the chart will remove the default prometheus receiver (which was configured to scrape the Collector's metrics).
172
# Learn more about the Collector telemetry at https://opentelemetry.io/docs/collector/internal-telemetry/.
173
#
174
# THIS OPTION IS EXPERIMENTAL AND SUBJECT TO BREAKING CHANGES
175
internalTelemetryViaOTLP:
176
# The endpoint where the telemetry will be exported
177
endpoint: ""
178
# Optional headers to configure the exporters
179
headers: []
180
# - name: "x-dest-auth"
181
# value: "some auth key"
182
traces:
183
enabled: false
184
# overrides internalTelemetryViaOTLP.endpoint for traces
185
endpoint: ""
186
# overrides internalTelemetryViaOTLP.headers for traces
187
headers: []
188
metrics:
189
enabled: false
190
# overrides internalTelemetryViaOTLP.endpoint for metrics
191
endpoint: ""
192
# overrides internalTelemetryViaOTLP.headers for metrics
193
headers: []
194
logs:
195
enabled: false
196
# overrides internalTelemetryViaOTLP.endpoint for logs
197
endpoint: ""
198
# overrides internalTelemetryViaOTLP.headers for logs
199
headers: []
200
# Rewrite deprecated component names (e.g. k8sattributes -> k8s_attributes
201
# processor, k8snode -> k8s_api resourcedetection detector) in the generated
202
# config. Set to false if using older Collector images that do not recognize the
203
# new names. Renamed from rewriteDeprecatedProcessorNames in chart 0.162.0.
204
rewriteDeprecatedComponentNames: true
205
# Base collector configuration.
206
# Supports templating. To escape existing instances of {{ }}, use {{` <original content> `}}.
207
# For example, {{ REDACTED_EMAIL }} becomes {{` {{ REDACTED_EMAIL }} `}}.
208
config:
209
exporters:
210
debug: {}
211
extensions:
212
# The health_check extension is mandatory for this chart.
213
# Without the health_check extension the collector will fail the readiness and liveness probes.
214
# The health_check extension can be modified, but should never be removed.
215
health_check:
216
endpoint: ${env:MY_POD_IP}:13133
217
processors:
218
batch: {}
219
# Default memory limiter configuration for the collector based on k8s resource limits.
220
memory_limiter:
221
# check_interval is the time between measurements of memory usage.
222
check_interval: 5s
223
# By default limit_mib is set to 80% of ".Values.resources.limits.memory"
224
limit_percentage: 80
225
# By default spike_limit_mib is set to 25% of ".Values.resources.limits.memory"
226
spike_limit_percentage: 25
227
receivers:
228
jaeger:
229
protocols:
230
grpc:
231
endpoint: ${env:MY_POD_IP}:14250
232
thrift_http:
233
endpoint: ${env:MY_POD_IP}:14268
234
thrift_compact:
235
endpoint: ${env:MY_POD_IP}:6831
236
otlp:
237
protocols:
238
grpc:
239
endpoint: ${env:MY_POD_IP}:4317
240
http:
241
endpoint: ${env:MY_POD_IP}:4318
242
# if internalTelemetryViaOTLP.metrics.enabled = true, prometheus receiver will be removed
243
prometheus:
244
config:
245
scrape_configs:
246
- job_name: opentelemetry-collector
247
scrape_interval: 10s
248
static_configs:
249
- targets:
250
- ${env:MY_POD_IP}:8888
251
zipkin:
252
endpoint: ${env:MY_POD_IP}:9411
253
service:
254
telemetry:
255
resource:
256
k8s.namespace.name: "${env:OTEL_K8S_NAMESPACE}"
257
k8s.node.name: "${env:OTEL_K8S_NODE_NAME}"
258
k8s.node.ip: "${env:OTEL_K8S_NODE_IP}"
259
k8s.pod.name: "${env:OTEL_K8S_POD_NAME}"
260
k8s.pod.ip: "${env:OTEL_K8S_POD_IP}"
261
host.name: "${env:OTEL_K8S_NODE_NAME}"
262
metrics:
263
readers:
264
- pull:
265
exporter:
266
prometheus:
267
host: ${env:MY_POD_IP}
268
port: 8888
269
extensions:
270
- health_check
271
pipelines:
272
logs:
273
exporters:
274
- debug
275
processors:
276
- memory_limiter
277
- batch
278
receivers:
279
- otlp
280
metrics:
281
exporters:
282
- debug
283
processors:
284
- memory_limiter
285
- batch
286
receivers:
287
- otlp
288
# if internalTelemetryViaOTLP.metrics.enabled = true, prometheus receiver will be removed
289
- prometheus
290
traces:
291
exporters:
292
- debug
293
processors:
294
- memory_limiter
295
- batch
296
receivers:
297
- otlp
298
- jaeger
299
- zipkin
300
# Helm currently has an issue (https://github.com/helm/helm/pull/12879) when using null to remove
301
# default configuration from a subchart. The result is that you cannot remove default configuration
302
# from `config`, such as a specific receiver or a specific pipeline, when the chart is used as a
303
# subchart.
304
#
305
# Until the helm bug is fixed, this field is provided as an alternative when using this chart as a subchart.
306
# It is not recommended to use this field when installing the chart directly.
307
#
308
# When not empty, `alternateConfig` will be used to set the collector's configuration. It has NO default
309
# values and IS NOT MERGED with config. Any configuration provided via `config` will be ignored when
310
# `alternateConfig` is set. You MUST provide your own collector configuration.
311
#
312
# Reminder that the healthcheck extension (or something else that provides the same functionality) is required.
313
#
314
# Components configured by presets will be injected in the same way they are for `config`.
315
alternateConfig: {}
316
image:
317
# If you want to use the core image `otel/opentelemetry-collector`, you also need to change `command.name` value to `otelcol`.
318
repository: chainreg.biz/chainguard-private/opentelemetry-collector-contrib
319
pullPolicy: IfNotPresent
320
# Overrides the image tag whose default is the chart appVersion.
321
tag: 0.162.0-r0
322
# When digest is set to a non-empty value, images will be pulled by digest (regardless of tag value).
323
digest: sha256:1fce741b83da131275c5a7c84c1d038e45135819da80102f7d4e7f0dc00b0f43
324
imagePullSecrets: []
325
# OpenTelemetry Collector executable
326
command:
327
name: ""
328
extraArgs: []
329
serviceAccount:
330
# Specifies whether a service account should be created
331
create: true
332
# Annotations to add to the service account
333
annotations: {}
334
# The name of the service account to use.
335
# If not set and create is true, a name is generated using the fullname template
336
name: ""
337
# Automatically mount a ServiceAccount's API credentials?
338
automountServiceAccountToken: true
339
clusterRole:
340
# Specifies whether a clusterRole should be created
341
# Some presets also trigger the creation of a cluster role and cluster role binding.
342
# If using one of those presets, this field is no-op.
343
create: false
344
# Annotations to add to the clusterRole
345
# Can be used in combination with presets that create a cluster role.
346
annotations: {}
347
# The name of the clusterRole to use.
348
# If not set a name is generated using the fullname template
349
# Can be used in combination with presets that create a cluster role.
350
name: ""
351
# A set of rules as documented here : https://kubernetes.io/docs/reference/access-authn-authz/rbac/
352
# Can be used in combination with presets that create a cluster role to add additional rules.
353
rules: []
354
# - apiGroups:
355
# - ''
356
# resources:
357
# - 'pods'
358
# - 'nodes'
359
# verbs:
360
# - 'get'
361
# - 'list'
362
# - 'watch'
363
364
clusterRoleBinding:
365
# Annotations to add to the clusterRoleBinding
366
# Can be used in combination with presets that create a cluster role binding.
367
annotations: {}
368
# The name of the clusterRoleBinding to use.
369
# If not set a name is generated using the fullname template
370
# Can be used in combination with presets that create a cluster role binding.
371
name: ""
372
podSecurityContext: {}
373
securityContext: {}
374
nodeSelector: {}
375
tolerations: []
376
affinity: {}
377
topologySpreadConstraints: []
378
# Allows for pod scheduler prioritisation
379
priorityClassName: ""
380
# Allows for pod to use a specific runtime class, e.g. gvisor, kata-containers
381
# Also useful for the pod security admissions plugins that rely on runtimeClassName
382
runtimeClassName: ""
383
terminationGracePeriodSeconds: 30
384
# This also supports template content, which will eventually be converted to yaml.
385
extraEnvs: []
386
# This also supports template content, which will eventually be converted to yaml.
387
extraEnvsFrom: []
388
# This also supports template content, which will eventually be converted to yaml.
389
extraVolumes: []
390
# This also supports template content, which will eventually be converted to yaml.
391
extraVolumeMounts: []
392
# This also supports template content, which will eventually be converted to yaml.
393
extraManifests: []
394
# Configuration for ports
395
# nodePort is also allowed
396
ports:
397
otlp:
398
enabled: true
399
containerPort: 4317
400
servicePort: 4317
401
hostPort: 4317
402
protocol: TCP
403
# nodePort: 30317
404
appProtocol: grpc
405
otlp-http:
406
enabled: true
407
containerPort: 4318
408
servicePort: 4318
409
hostPort: 4318
410
protocol: TCP
411
jaeger-compact:
412
enabled: true
413
containerPort: 6831
414
servicePort: 6831
415
hostPort: 6831
416
protocol: UDP
417
jaeger-thrift:
418
enabled: true
419
containerPort: 14268
420
servicePort: 14268
421
hostPort: 14268
422
protocol: TCP
423
jaeger-grpc:
424
enabled: true
425
containerPort: 14250
426
servicePort: 14250
427
hostPort: 14250
428
protocol: TCP
429
zipkin:
430
enabled: true
431
containerPort: 9411
432
servicePort: 9411
433
hostPort: 9411
434
protocol: TCP
435
metrics:
436
# The metrics port is disabled by default. However you need to enable the port
437
# in order to use the ServiceMonitor (serviceMonitor.enabled) or PodMonitor (podMonitor.enabled).
438
enabled: false
439
containerPort: 8888
440
servicePort: 8888
441
protocol: TCP
442
# When enabled, the chart will set the GOMEMLIMIT env var to 80% of the configured resources.limits.memory.
443
# If no resources.limits.memory are defined then enabling does nothing.
444
# It is HIGHLY recommend to enable this setting and set a value for resources.limits.memory.
445
useGOMEMLIMIT: true
446
# Container resize policy for in-place resource resize (Kubernetes >= 1.27).
447
# https://kubernetes.io/docs/concepts/workloads/autoscaling/#in-place-resizing
448
resizePolicy: []
449
# resizePolicy:
450
# - resourceName: cpu
451
# restartPolicy: NotRequired
452
# - resourceName: memory
453
# restartPolicy: RestartContainer
454
455
# Resource limits & requests.
456
# It is HIGHLY recommended to set resource limits.
457
resources: {}
458
# resources:
459
# limits:
460
# cpu: 250m
461
# memory: 512Mi
462
463
enableConfigChecksumAnnotation: true
464
podAnnotations: {}
465
podLabels: {}
466
# Common labels to add to all otel-collector resources. Evaluated as a template.
467
additionalLabels: {}
468
# app.kubernetes.io/part-of: my-app
469
470
# Host networking requested for this pod. Use the host's network namespace.
471
hostNetwork: false
472
# Enable sharing the host's PID namespace with the pod.
473
# WARNING: This grants visibility into all host processes and should only be enabled when required.
474
hostPID: false
475
# Adding entries to Pod /etc/hosts with HostAliases
476
# https://kubernetes.io/docs/tasks/network/customize-hosts-file-for-pods/
477
hostAliases: []
478
# - ip: "1.2.3.4"
479
# hostnames:
480
# - "my.host.com"
481
482
# Pod DNS policy ClusterFirst, ClusterFirstWithHostNet, None, Default, None
483
dnsPolicy: ""
484
# Custom DNS config. Required when DNS policy is None.
485
dnsConfig: {}
486
# Custom kube scheduler name.
487
schedulerName: ""
488
# only used with deployment and statefulset modes.
489
replicaCount: 1
490
revisionHistoryLimit: 10
491
annotations: {}
492
# List of extra sidecars to add.
493
# This also supports template content, which will eventually be converted to yaml.
494
extraContainers: []
495
# extraContainers:
496
# - name: test
497
# command:
498
# - cp
499
# args:
500
# - /bin/sleep
501
# - /test/sleep
502
# image: busybox:latest
503
# volumeMounts:
504
# - name: test
505
# mountPath: /test
506
507
# List of init container specs, e.g. for copying a binary to be executed as a lifecycle hook.
508
# This also supports template content, which will eventually be converted to yaml.
509
# Another usage of init containers is e.g. initializing filesystem permissions to the OTLP Collector user `10001` in case you are using persistence and the volume is producing a permission denied error for the OTLP Collector container.
510
initContainers: []
511
# initContainers:
512
# - name: test
513
# image: busybox:latest
514
# command:
515
# - cp
516
# args:
517
# - /bin/sleep
518
# - /test/sleep
519
# volumeMounts:
520
# - name: test
521
# mountPath: /test
522
# - name: init-fs
523
# image: busybox:latest
524
# command:
525
# - sh
526
# - '-c'
527
# - 'chown -R 10001: /var/lib/storage/otc' # use the path given as per `extensions.file_storage.directory` & `extraVolumeMounts[x].mountPath`
528
# volumeMounts:
529
# - name: opentelemetry-collector-data # use the name of the volume used for persistence
530
# mountPath: /var/lib/storage/otc # use the path given as per `extensions.file_storage.directory` & `extraVolumeMounts[x].mountPath`
531
532
# Pod lifecycle policies.
533
lifecycleHooks: {}
534
# lifecycleHooks:
535
# preStop:
536
# exec:
537
# command:
538
# - /test/sleep
539
# - "5"
540
541
# liveness probe configuration
542
# Ref: https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-startup-probes/
543
##
544
livenessProbe:
545
# Number of seconds after the container has started before startup, liveness or readiness probes are initiated.
546
# initialDelaySeconds: 1
547
# How often in seconds to perform the probe.
548
# periodSeconds: 10
549
# Number of seconds after which the probe times out.
550
# timeoutSeconds: 1
551
# Minimum consecutive failures for the probe to be considered failed after having succeeded.
552
# failureThreshold: 1
553
# Duration in seconds the pod needs to terminate gracefully upon probe failure.
554
# terminationGracePeriodSeconds: 10
555
httpGet:
556
port: 13133
557
path: /
558
# readiness probe configuration
559
# Ref: https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-startup-probes/
560
##
561
readinessProbe:
562
# Number of seconds after the container has started before startup, liveness or readiness probes are initiated.
563
# initialDelaySeconds: 1
564
# How often (in seconds) to perform the probe.
565
# periodSeconds: 10
566
# Number of seconds after which the probe times out.
567
# timeoutSeconds: 1
568
# Minimum consecutive successes for the probe to be considered successful after having failed.
569
# successThreshold: 1
570
# Minimum consecutive failures for the probe to be considered failed after having succeeded.
571
# failureThreshold: 1
572
httpGet:
573
port: 13133
574
path: /
575
# startup probe configuration
576
# Ref: https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-startup-probes/
577
##
578
startupProbe: {}
579
# Number of seconds after the container has started before startup probes are initiated.
580
# initialDelaySeconds: 1
581
# How often in seconds to perform the probe.
582
# periodSeconds: 10
583
# Number of seconds after which the probe times out.
584
# timeoutSeconds: 1
585
# Minimum consecutive failures for the probe to be considered failed after having succeeded.
586
# failureThreshold: 1
587
# Duration in seconds the pod needs to terminate gracefully upon probe failure.
588
# terminationGracePeriodSeconds: 10
589
# httpGet:
590
# port: 13133
591
# path: /
592
593
service:
594
# Enable the creation of a Service.
595
# By default, it's enabled on mode != daemonset.
596
# However, to enable it on mode = daemonset, its creation must be explicitly enabled
597
# enabled: true
598
type: ClusterIP
599
# Supported values: PreferClose (deprecated in K8s 1.33+), PreferSameZone, PreferSameNode
600
# trafficDistribution: PreferClose
601
# type: LoadBalancer
602
# loadBalancerIP: 1.2.3.4
603
# loadBalancerSourceRanges: []
604
605
# By default, Service of type 'LoadBalancer' or 'NodePort' will be created setting 'externalTrafficPolicy: Cluster'
606
# unless other value is explicitly set.
607
# Possible values are Cluster or Local (https://kubernetes.io/docs/tasks/access-application-cluster/create-external-load-balancer/#preserving-the-client-source-ip)
608
# externalTrafficPolicy: Cluster
609
annotations: {}
610
# By default, Service will be created setting 'internalTrafficPolicy: Local' on mode = daemonset
611
# unless other value is explicitly set.
612
# Setting 'internalTrafficPolicy: Cluster' on a daemonset is not recommended
613
# internalTrafficPolicy: Cluster
614
ingress:
615
enabled: false
616
# annotations: {}
617
# ingressClassName: nginx
618
# hosts:
619
# - host: collector.example.com
620
# paths:
621
# - path: /
622
# pathType: Prefix
623
# port: 4318
624
# tls:
625
# - secretName: collector-tls
626
# hosts:
627
# - collector.example.com
628
629
# Additional ingresses - only created if ingress.enabled is true
630
# Useful for when differently annotated ingress services are required
631
# Each additional ingress needs key "name" set to something unique
632
additionalIngresses: []
633
# - name: cloudwatch
634
# ingressClassName: nginx
635
# annotations: {}
636
# hosts:
637
# - host: collector.example.com
638
# paths:
639
# - path: /
640
# pathType: Prefix
641
# port: 4318
642
# tls:
643
# - secretName: collector-tls
644
# hosts:
645
# - collector.example.com
646
# Gateway API HTTPRoute. An alternative to ingress for exposing the
647
# collector's HTTP-based receivers through a Gateway API implementation.
648
# Requires the Gateway API CRDs to be installed in the cluster.
649
httproute:
650
enabled: false
651
# HTTPRoute apiVersion (defaults to "gateway.networking.k8s.io/v1" when empty)
652
apiVersion: ""
653
annotations: {}
654
# parentRefs reference the Gateway(s) this HTTPRoute is attached to
655
# parentRefs:
656
# - name: my-gateway
657
# namespace: gateway-system
658
# sectionName: otlp-http
659
parentRefs: []
660
# hostnames matched against the HTTP Host header to select this route
661
# hostnames:
662
# - collector.example.com
663
hostnames: []
664
# rules associate request matches with a backend port on the collector
665
# service. backendRefs "name" defaults to the collector service when omitted.
666
# rules:
667
# - matches:
668
# - path:
669
# type: PathPrefix
670
# value: /
671
# backendRefs:
672
# - port: 4318
673
rules: []
674
podMonitor:
675
# The pod monitor by default scrapes the metrics port.
676
# The metrics port needs to be enabled as well.
677
enabled: false
678
metricsEndpoints:
679
- port: metrics
680
# interval: 15s
681
# additional labels for the PodMonitor
682
extraLabels: {}
683
# release: kube-prometheus-stack
684
serviceMonitor:
685
# The service monitor by default scrapes the metrics port.
686
# The metrics port needs to be enabled as well.
687
enabled: false
688
metricsEndpoints:
689
- port: metrics
690
# interval: 15s
691
# additional labels for the ServiceMonitor
692
extraLabels: {}
693
# release: kube-prometheus-stack
694
# Used to set relabeling and metricRelabeling configs on the ServiceMonitor
695
# https://prometheus.io/docs/prometheus/latest/configuration/configuration/#relabel_config
696
relabelings: []
697
metricRelabelings: []
698
# Sets a sample limit on the ServiceMonitor
699
sampleLimit: 0
700
# PodDisruptionBudget is used only if mode is "deployment" or "statefulset"
701
podDisruptionBudget:
702
enabled: false
703
# minAvailable: 2
704
# maxUnavailable: 1
705
706
# autoscaling is used only if mode is "deployment" or "statefulset"
707
autoscaling:
708
enabled: false
709
minReplicas: 1
710
maxReplicas: 10
711
behavior: {}
712
targetCPUUtilizationPercentage: 80
713
# targetMemoryUtilizationPercentage: 80
714
# Supply an array of custom metrics to be used for autoscaling. It includes externalMetrics, objectMetrics, and podsMetrics.
715
additionalMetrics: []
716
rollout:
717
rollingUpdate: {}
718
# When 'mode: daemonset', maxSurge cannot be used when hostPort is set for any of the ports
719
# maxSurge: 25%
720
# maxUnavailable: 0
721
strategy: RollingUpdate
722
prometheusRule:
723
enabled: false
724
groups: []
725
# Create default rules for monitoring the collector
726
defaultRules:
727
enabled: false
728
## Additional labels for PrometheusRule alerts
729
additionalRuleLabels: {}
730
## Additional annotations for PrometheusRule alerts
731
additionalRuleAnnotations: {}
732
# additional labels for the PrometheusRule
733
extraLabels: {}
734
statefulset:
735
# volumeClaimTemplates for a statefulset
736
volumeClaimTemplates: []
737
podManagementPolicy: "Parallel"
738
# Controls if and how PVCs created by the StatefulSet are deleted. Available in Kubernetes 1.23+.
739
persistentVolumeClaimRetentionPolicy:
740
enabled: false
741
whenDeleted: Retain
742
whenScaled: Retain
743
networkPolicy:
744
enabled: false
745
# Annotations to add to the NetworkPolicy
746
annotations: {}
747
# Configure the 'from' clause of the NetworkPolicy.
748
# By default this will restrict traffic to ports enabled for the Collector. If
749
# you wish to further restrict traffic to other hosts or specific namespaces,
750
# see the standard NetworkPolicy 'spec.ingress.from' definition for more info:
751
# https://kubernetes.io/docs/reference/kubernetes-api/policy-resources/network-policy-v1/
752
allowIngressFrom: []
753
# # Allow traffic from any pod in any namespace, but not external hosts
754
# - namespaceSelector: {}
755
# # Allow external access from a specific cidr block
756
# - ipBlock:
757
# cidr: 192.168.1.64/32
758
# # Allow access from pods in specific namespaces
759
# - namespaceSelector:
760
# matchExpressions:
761
# - key: kubernetes.io/metadata.name
762
# operator: In
763
# values:
764
# - "cats"
765
# - "dogs"
766
767
# Add additional ingress rules to specific ports
768
# Useful to allow external hosts/services to access specific ports
769
# An example is allowing an external prometheus server to scrape metrics
770
#
771
# See the standard NetworkPolicy 'spec.ingress' definition for more info:
772
# https://kubernetes.io/docs/reference/kubernetes-api/policy-resources/network-policy-v1/
773
extraIngressRules: []
774
# - ports:
775
# - port: metrics
776
# protocol: TCP
777
# from:
778
# - ipBlock:
779
# cidr: 192.168.1.64/32
780
781
# Restrict egress traffic from the OpenTelemetry collector pod
782
# See the standard NetworkPolicy 'spec.egress' definition for more info:
783
# https://kubernetes.io/docs/reference/kubernetes-api/policy-resources/network-policy-v1/
784
egressRules: []
785
# - to:
786
# - namespaceSelector: {}
787
# - ipBlock:
788
# cidr: 192.168.10.10/24
789
# ports:
790
# - port: 1234
791
# protocol: TCP
792
# Allow containers to share processes across pod namespace
793
shareProcessNamespace: false
794

The trusted source for open source

Talk to an expert
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsChainguard OS PackagesChainguard ActionsChainguard Agent SkillsIntegrationsPricing
© 2026 Chainguard, Inc. All Rights Reserved.
Chainguard® and the Chainguard logo are registered trademarks of Chainguard, Inc. in the United States and/or other countries.
The other respective trademarks mentioned on this page are owned by the respective companies and use of them does not imply any affiliation or endorsement.