1# ==============================================================================
3# ==============================================================================
5# -- Global Security Context
6# When enabled: false (default), only component-specific securityContext blocks are rendered as-is, if they exist.
7# When enabled: true, global values are the baseline and component-specific values are merged on top (component wins).
9 # -- Master switch. Set to true to apply global defaults to all components.
11 # -- Pod-level security context. https://kubernetes.io/docs/reference/kubernetes-api/workload-resources/pod-v1/#PodSecurityContext
17 fsGroupChangePolicy: "OnRootMismatch"
20 # -- Container-level security context. https://kubernetes.io/docs/reference/kubernetes-api/workload-resources/pod-v1/#SecurityContext
22 allowPrivilegeEscalation: false
23 readOnlyRootFilesystem: false
27# -- Extra arbitrary Kubernetes resources to deploy alongside the chart.
28# Follows the Bitnami extraDeploy pattern: each item is rendered via `tpl`,
29# so you can use Helm template expressions inside the objects.
30# Ideal for ServiceMonitors, CRDs, additional ConfigMaps, or any resource
31# not covered by the standard chart templates.
32# No validation is performed; users are responsible for correctness.
35# ==============================================================================
37# ==============================================================================
41 repository: chainreg.biz/scratch-images/test-tmp/pgwatch
42 tag: 5.3.0-r6@sha256:866453ed13193d7e70784df9d0053e4501adb7687b11bc5927f063783a19785a
43 # -- Resource requests and limits for the pgwatch deployment.
45 # -- Web UI listen port. Must match PW_WEBADDR (default :8080). Used for containerPort and Service.
47 # -- Monitored sources: databases pgwatch should monitor (PW_SOURCES).
48 # If unset, pgwatch auto-generates a PostgreSQL URI from the metrics database settings (default).
49 # Set 'files' to use file-based source configuration instead.
50 # Source files are mounted under /tmp/pgwatch-sources and pgwatch reads the directory.
51 # This supports multiple source files; pgwatch v5 images including the fix for
52 # https://github.com/cybertec-postgresql/pgwatch/issues/1368 skip Kubernetes
53 # ConfigMap atomic-writer internals while walking the directory.
54 # See configs/sample-sources.yaml for the file format.
55 # Ref: https://pgwat.ch/v5.x/reference/cli_env.html#sources
57 # -- Multiple YAML source files to create inside the pod.
58 # Keys become filenames in /tmp/pgwatch-sources and values are raw YAML contents.
59 # For a single source file, provide one entry in this map.
60 # Escape dots in filenames when using --set-file, for example:
61 # --set-file pgwatch.sources.files.custom-sources\.yaml=./custom-sources.yaml
62 # --set-file pgwatch.sources.files.custom-sources2\.yml=./custom-sources2.yml
64 # TODO: Implement existingConfigMap - mount an existing user-managed ConfigMap
65 # directly instead of creating one from 'files'.
66 # -- Ingress resource for the pgwatch web UI.
69 # -- Ingress class (e.g. "nginx", "traefik"). Omitted if empty.
71 # -- Annotations passed to the Ingress metadata (e.g. cert-manager.io/cluster-issuer).
73 # -- Host rules with paths.
76 # - host: pgwatch.example.com
81 # -- TLS secret references. Secrets must already exist in the namespace
82 # (create them manually or via cert-manager triggered by the annotation above).
85 # - secretName: pgwatch-tls
87 # - pgwatch.example.com
89 # -- Sub-path for reverse-proxy setups (e.g. "/pgwatch").
90 # Injected as PW_WEBBASEPATH -> passed to pgwatch as --web-base-path.
92 # -- Component-specific overrides for the pgwatch Deployment.
96 # -- Additional environment variables for the pgwatch container.
97 # Merged with chart defaults; user-supplied values take precedence.
100 # PW_LOGLEVEL: "debug"
101 # PW_WEBBASEPATH: "/pgwatch"
102 # METRIC_DATABASE_PORT: "5433"
104 # -- Inject env vars from existing ConfigMaps or Secrets.
108 # name: my-pgwatch-config
110 # name: my-pgwatch-secret
112 # == Metrics sink: PostgreSQL ==
117 # -- Set to true to deploy a new PostgreSQL StatefulSet (default).
118 createMetricDatabase: true
119 # -- New PostgreSQL instance — active when createMetricDatabase: true.
121 image: chainreg.biz/scratch-images/test-tmp/postgres:18.6-r2@sha256:d29ce53b6f9796ef6fdf48e251ca9dececbd4570c0f71798082e09cd023dd17c
122 # -- Resource requests and limits for the Metrics Database StatefulSet.
126 storageClass: 'standard'
127 # -- Resource requests and limits for the Metrics Database init job.
136 # -- Resource requests and limits for the Metrics Database initContainers.
145 # -- External database connection (active when createMetricDatabase: false).
146 # Set credentials via credentials.* below; username/password here are deprecated.
147 # useExistingDatabase:
148 # endpoint: postgresql.local
150 # database: PGWATCH_DATABASE
151 # grafanaDatabase: pgwatch_grafana # optional, default: pgwatch_grafana
153 # # username: # DEPRECATED, use credentials.username
154 # # password: # DEPRECATED, use credentials.password
156 # -- Credentials for pgwatch and Grafana to connect to the metrics database.
159 # 1. credentials.existingSecret — chart creates no Secret; keys read via usernameKey/passwordKey
160 # 2. credentials.username / password — chart creates pgwatch-postgresql-secret-pgwatch
161 # 3. DEPRECATED: useExistingDatabase.username / password — still works, emits warning
163 # -- Name of an existing Secret that contains the pgwatch username/password.
164 # When set, the chart will not create pgwatch-postgresql-secret-pgwatch.
168 # -- Secret key containing the username when existingSecret is used.
169 usernameKey: "username"
170 # -- Secret key containing the password when existingSecret is used.
171 passwordKey: "password"
172 # -- Admin password for the built-in PostgreSQL StatefulSet.
173 # Only applies when createMetricDatabase: true and timescaledb.enabled: false.
174 # Has no effect for external databases or TimescaleDB subchart.
176 # -- Password for the postgres superuser stored in the admin Secret.
178 # -- Name of an existing Secret that contains the postgres admin password.
179 # When set, the chart will not create pgwatch-postgresql-secret-postgres.
181 # -- Secret key containing the postgres admin password.
182 passwordKey: "password"
183 # -- Component-specific overrides for the PostgreSQL StatefulSet.
187 # -- Additional environment variables for the postgres container.
188 # Merged with chart defaults; user-supplied values take precedence.
191 # POSTGRES_MAX_CONNECTIONS: "200"
193 # -- Inject env vars from existing ConfigMaps or Secrets.
197 # name: my-postgres-secret
199 # == Metrics sink: Prometheus ==
202 # -- New Prometheus instance — active when createPrometheus: true.
204 createPrometheus: true
205 image: chainreg.biz/scratch-images/test-tmp/prometheus:3.14.0-r3@sha256:28cf39fd5fe744abf9c7ab0d683fbefa10e73bc203c36aef446607ce59a112ef
206 # -- Resource requests and limits for the Prometheus deployment.
212 storageClass: 'standard'
213 # -- Resource requests and limits for the Prometheus initContainers.
216 # -- Existing Prometheus instance — active when createPrometheus: false.
218 # TODO: Implement use_existing_prometheus
220 # use_existing_prometheus:
221 # endpoint: prometheus.local
224 # -- Component-specific overrides for the Prometheus Deployment.
225 # The official Prometheus image runs as UID/GID 65534 (nobody).
232 # -- Additional environment variables for the prometheus container.
237 # -- Inject env vars from existing ConfigMaps or Secrets.
241 # name: my-prometheus-config
243 # == Visualization: Grafana ==
245 # -- Set to true to use the official Grafana Helm subchart instead of the
246 # custom Grafana Deployment bundled in this chart.
247 # When true: grafana-deployment.yaml, grafana-dashboard-config.yaml and
248 # grafana-svc are skipped; the grafana: top-level section controls the subchart.
249 # When false (default): the custom Deployment runs exactly as before.
251 image: chainreg.biz/scratch-images/test-tmp/grafana:v13.2.1-r5@sha256:1d29c4cff64c29a364b83468b241cec291592cddb93f5ed50d7d16087edf7d1a
252 # -- Resource requests and limits for the Grafana deployment.
255 # -- Controls which Grafana datasources are provisioned.
256 # Independent of the sink settings (enablePgSink / enablePromSink), which control
257 # what pgwatch writes to. These control what Grafana is configured to query.
261 # -- Component-specific overrides for the Grafana Deployment.
262 # The official Grafana image runs as UID/GID 472.
269 # -- Additional environment variables for the grafana container.
270 # Merged with chart defaults; user-supplied values take precedence.
273 # GF_SERVER_ROOT_URL: "https://grafana.example.com"
274 # GF_LOG_LEVEL: "warn"
276 # -- Inject env vars from existing ConfigMaps or Secrets.
280 # name: my-grafana-secret
282# ==============================================================================
283# Subchart pass-throughs (opt-in)
284# ==============================================================================
286# TimescaleDB subchart — opt-in (Needs timescaledb.enabled: true).
287# Replaces the built-in PostgreSQL StatefulSet; a post-install Job bootstraps the pgwatch user/databases.
288# All keys under timescaledb: are passed through directly to the subchart.
289# Ref: https://artifacthub.io/packages/helm/cloudpirates-timescaledb/timescaledb
293 # -- TimescaleDB image tag. Override to select a different PG/TS version.
294 # Available tags: https://hub.docker.com/r/timescale/timescaledb/tags
297 # -- Password for the postgres admin user.
298 # If empty a random password is generated and stored in the release secret.
300 # -- Name of an existing Secret that already contains the postgres password.
301 # When set, postgresPassword is ignored.
305 # -- Storage size for the TimescaleDB data volume.
307 # -- StorageClass for the PVC. Uses the cluster default when empty.
309# Grafana subchart — opt-in (pgwatch.grafana.useSubchart: true).
310# Replaces the custom Grafana Deployment; datasources are auto-provisioned via the k8s-sidecar.
311# All keys under grafana: are passed through directly to the subchart.
312# Ref: https://github.com/grafana-community/helm-charts/tree/main/charts/grafana
314 # -- Sidecar configuration for automatic dashboard and datasource discovery.
315 # The sidecar watches ConfigMaps labelled grafana_dashboard=1 / grafana_datasource=1
316 # in the same namespace and injects them at runtime — no pod restart needed.
320 # -- Label key used to identify dashboard ConfigMaps.
321 label: grafana_dashboard
322 # -- Annotation key on dashboard ConfigMaps that determines the target
323 # subdirectory on disk (e.g. "postgresql" -> /tmp/dashboards/postgresql/).
324 # Must match the grafana_dashboard_folder annotation used in the dashboard
325 # ConfigMap templates (grafana-postgresql-dashboards.yaml, grafana-prometheus-dashboards.yaml).
326 folderAnnotation: grafana_dashboard_folder
329 # -- Label key used to identify datasource ConfigMaps.
330 label: grafana_datasource
336 default_home_dashboard_path: /tmp/dashboards/postgresql/1-global-db-overview.json
337 # -- Optional env vars injected into the Grafana subchart main container.
338 # When pgwatch.grafana.useSubchart=true and datasource credentials come from an
339 # existing Secret with custom keys, mirror those keys here via envValueFrom so
340 # Grafana can resolve ${PGWATCH_METRICS_DS_USER} / ${PGWATCH_METRICS_DS_PASSWORD}
341 # placeholders from the datasource ConfigMap.