DirectorySecurity AdvisoriesPricing
Sign in
Directory
pgwatch logoHELM

pgwatch

Helm chart
Last changed
Request a free trial

Contact our team to test out this Helm chart and related images for free. Please also indicate any other images you would like to evaluate.

Overview
Chart tags
Default values
Chart metadata
Images

Tag:

1
# ==============================================================================
2
# Global Settings
3
# ==============================================================================
4
5
# -- Global Security Context
6
# When enabled: false (default), only component-specific securityContext blocks are rendered as-is, if they exist.
7
# When enabled: true, global values are the baseline and component-specific values are merged on top (component wins).
8
securityContext:
9
# -- Master switch. Set to true to apply global defaults to all components.
10
enabled: false
11
# -- Pod-level security context. https://kubernetes.io/docs/reference/kubernetes-api/workload-resources/pod-v1/#PodSecurityContext
12
pod:
13
runAsNonRoot: true
14
runAsUser: 1000
15
runAsGroup: 1000
16
fsGroup: 1000
17
fsGroupChangePolicy: "OnRootMismatch"
18
seccompProfile:
19
type: RuntimeDefault
20
# -- Container-level security context. https://kubernetes.io/docs/reference/kubernetes-api/workload-resources/pod-v1/#SecurityContext
21
container:
22
allowPrivilegeEscalation: false
23
readOnlyRootFilesystem: false
24
capabilities:
25
drop:
26
- ALL
27
# -- Extra arbitrary Kubernetes resources to deploy alongside the chart.
28
# Follows the Bitnami extraDeploy pattern: each item is rendered via `tpl`,
29
# so you can use Helm template expressions inside the objects.
30
# Ideal for ServiceMonitors, CRDs, additional ConfigMaps, or any resource
31
# not covered by the standard chart templates.
32
# No validation is performed; users are responsible for correctness.
33
#
34
extraDeploy: []
35
# ==============================================================================
36
# pgwatch
37
# ==============================================================================
38
pgwatch:
39
# == Core Settings ==
40
image:
41
repository: chainreg.biz/scratch-images/test-tmp/pgwatch
42
tag: 5.3.0-r6@sha256:866453ed13193d7e70784df9d0053e4501adb7687b11bc5927f063783a19785a
43
# -- Resource requests and limits for the pgwatch deployment.
44
resources: {}
45
# -- Web UI listen port. Must match PW_WEBADDR (default :8080). Used for containerPort and Service.
46
webPort: 8080
47
# -- Monitored sources: databases pgwatch should monitor (PW_SOURCES).
48
# If unset, pgwatch auto-generates a PostgreSQL URI from the metrics database settings (default).
49
# Set 'files' to use file-based source configuration instead.
50
# Source files are mounted under /tmp/pgwatch-sources and pgwatch reads the directory.
51
# This supports multiple source files; pgwatch v5 images including the fix for
52
# https://github.com/cybertec-postgresql/pgwatch/issues/1368 skip Kubernetes
53
# ConfigMap atomic-writer internals while walking the directory.
54
# See configs/sample-sources.yaml for the file format.
55
# Ref: https://pgwat.ch/v5.x/reference/cli_env.html#sources
56
sources:
57
# -- Multiple YAML source files to create inside the pod.
58
# Keys become filenames in /tmp/pgwatch-sources and values are raw YAML contents.
59
# For a single source file, provide one entry in this map.
60
# Escape dots in filenames when using --set-file, for example:
61
# --set-file pgwatch.sources.files.custom-sources\.yaml=./custom-sources.yaml
62
# --set-file pgwatch.sources.files.custom-sources2\.yml=./custom-sources2.yml
63
files: {}
64
# TODO: Implement existingConfigMap - mount an existing user-managed ConfigMap
65
# directly instead of creating one from 'files'.
66
# -- Ingress resource for the pgwatch web UI.
67
ingress:
68
enabled: false
69
# -- Ingress class (e.g. "nginx", "traefik"). Omitted if empty.
70
className: ""
71
# -- Annotations passed to the Ingress metadata (e.g. cert-manager.io/cluster-issuer).
72
annotations: {}
73
# -- Host rules with paths.
74
# Example:
75
# hosts:
76
# - host: pgwatch.example.com
77
# paths:
78
# - path: /
79
# pathType: Prefix
80
hosts: []
81
# -- TLS secret references. Secrets must already exist in the namespace
82
# (create them manually or via cert-manager triggered by the annotation above).
83
# Example:
84
# tls:
85
# - secretName: pgwatch-tls
86
# hosts:
87
# - pgwatch.example.com
88
tls: []
89
# -- Sub-path for reverse-proxy setups (e.g. "/pgwatch").
90
# Injected as PW_WEBBASEPATH -> passed to pgwatch as --web-base-path.
91
webBasePath: ""
92
# -- Component-specific overrides for the pgwatch Deployment.
93
securityContext:
94
pod: {}
95
container: {}
96
# -- Additional environment variables for the pgwatch container.
97
# Merged with chart defaults; user-supplied values take precedence.
98
# Example:
99
# env:
100
# PW_LOGLEVEL: "debug"
101
# PW_WEBBASEPATH: "/pgwatch"
102
# METRIC_DATABASE_PORT: "5433"
103
env: {}
104
# -- Inject env vars from existing ConfigMaps or Secrets.
105
# Example:
106
# envFrom:
107
# - configMapRef:
108
# name: my-pgwatch-config
109
# - secretRef:
110
# name: my-pgwatch-secret
111
envFrom: []
112
# == Metrics sink: PostgreSQL ==
113
postgres:
114
enablePgSink: true
115
settings:
116
retentionDays: 31
117
# -- Set to true to deploy a new PostgreSQL StatefulSet (default).
118
createMetricDatabase: true
119
# -- New PostgreSQL instance — active when createMetricDatabase: true.
120
newPgDatabase:
121
image: chainreg.biz/scratch-images/test-tmp/postgres:18.6-r2@sha256:d29ce53b6f9796ef6fdf48e251ca9dececbd4570c0f71798082e09cd023dd17c
122
# -- Resource requests and limits for the Metrics Database StatefulSet.
123
resources: {}
124
volume:
125
size: '10Gi'
126
storageClass: 'standard'
127
# -- Resource requests and limits for the Metrics Database init job.
128
dbInitJob:
129
resources: {}
130
# requests:
131
# cpu: "25m"
132
# memory: "64Mi"
133
# limits:
134
# cpu: "200m"
135
# memory: "128Mi"
136
# -- Resource requests and limits for the Metrics Database initContainers.
137
initContainers:
138
resources: {}
139
# requests:
140
# cpu: "10m"
141
# memory: "16Mi"
142
# limits:
143
# cpu: "100m"
144
# memory: "64Mi"
145
# -- External database connection (active when createMetricDatabase: false).
146
# Set credentials via credentials.* below; username/password here are deprecated.
147
# useExistingDatabase:
148
# endpoint: postgresql.local
149
# port: '5432'
150
# database: PGWATCH_DATABASE
151
# grafanaDatabase: pgwatch_grafana # optional, default: pgwatch_grafana
152
# sslmode: require
153
# # username: # DEPRECATED, use credentials.username
154
# # password: # DEPRECATED, use credentials.password
155
156
# -- Credentials for pgwatch and Grafana to connect to the metrics database.
157
#
158
# Precedence:
159
# 1. credentials.existingSecret — chart creates no Secret; keys read via usernameKey/passwordKey
160
# 2. credentials.username / password — chart creates pgwatch-postgresql-secret-pgwatch
161
# 3. DEPRECATED: useExistingDatabase.username / password — still works, emits warning
162
credentials:
163
# -- Name of an existing Secret that contains the pgwatch username/password.
164
# When set, the chart will not create pgwatch-postgresql-secret-pgwatch.
165
existingSecret: ""
166
username: "pgwatch"
167
password: ""
168
# -- Secret key containing the username when existingSecret is used.
169
usernameKey: "username"
170
# -- Secret key containing the password when existingSecret is used.
171
passwordKey: "password"
172
# -- Admin password for the built-in PostgreSQL StatefulSet.
173
# Only applies when createMetricDatabase: true and timescaledb.enabled: false.
174
# Has no effect for external databases or TimescaleDB subchart.
175
adminCredentials:
176
# -- Password for the postgres superuser stored in the admin Secret.
177
password: ""
178
# -- Name of an existing Secret that contains the postgres admin password.
179
# When set, the chart will not create pgwatch-postgresql-secret-postgres.
180
existingSecret: ""
181
# -- Secret key containing the postgres admin password.
182
passwordKey: "password"
183
# -- Component-specific overrides for the PostgreSQL StatefulSet.
184
securityContext:
185
pod: {}
186
container: {}
187
# -- Additional environment variables for the postgres container.
188
# Merged with chart defaults; user-supplied values take precedence.
189
# Example:
190
# env:
191
# POSTGRES_MAX_CONNECTIONS: "200"
192
env: {}
193
# -- Inject env vars from existing ConfigMaps or Secrets.
194
# Example:
195
# envFrom:
196
# - secretRef:
197
# name: my-postgres-secret
198
envFrom: []
199
# == Metrics sink: Prometheus ==
200
prometheus:
201
enablePromSink: true
202
# -- New Prometheus instance — active when createPrometheus: true.
203
newPrometheus:
204
createPrometheus: true
205
image: chainreg.biz/scratch-images/test-tmp/prometheus:3.14.0-r3@sha256:28cf39fd5fe744abf9c7ab0d683fbefa10e73bc203c36aef446607ce59a112ef
206
# -- Resource requests and limits for the Prometheus deployment.
207
resources: {}
208
settings:
209
retentionDays: 31
210
volume:
211
size: '10Gi'
212
storageClass: 'standard'
213
# -- Resource requests and limits for the Prometheus initContainers.
214
initContainers:
215
resources: {}
216
# -- Existing Prometheus instance — active when createPrometheus: false.
217
#
218
# TODO: Implement use_existing_prometheus
219
#
220
# use_existing_prometheus:
221
# endpoint: prometheus.local
222
# port: '9090'
223
224
# -- Component-specific overrides for the Prometheus Deployment.
225
# The official Prometheus image runs as UID/GID 65534 (nobody).
226
securityContext:
227
pod:
228
runAsUser: 65534
229
runAsGroup: 65534
230
fsGroup: 65534
231
container: {}
232
# -- Additional environment variables for the prometheus container.
233
# Example:
234
# env:
235
# GOMAXPROCS: "2"
236
env: {}
237
# -- Inject env vars from existing ConfigMaps or Secrets.
238
# Example:
239
# envFrom:
240
# - configMapRef:
241
# name: my-prometheus-config
242
envFrom: []
243
# == Visualization: Grafana ==
244
grafana:
245
# -- Set to true to use the official Grafana Helm subchart instead of the
246
# custom Grafana Deployment bundled in this chart.
247
# When true: grafana-deployment.yaml, grafana-dashboard-config.yaml and
248
# grafana-svc are skipped; the grafana: top-level section controls the subchart.
249
# When false (default): the custom Deployment runs exactly as before.
250
useSubchart: false
251
image: chainreg.biz/scratch-images/test-tmp/grafana:v13.2.1-r5@sha256:1d29c4cff64c29a364b83468b241cec291592cddb93f5ed50d7d16087edf7d1a
252
# -- Resource requests and limits for the Grafana deployment.
253
resources: {}
254
enableGrafana: true
255
# -- Controls which Grafana datasources are provisioned.
256
# Independent of the sink settings (enablePgSink / enablePromSink), which control
257
# what pgwatch writes to. These control what Grafana is configured to query.
258
enableDatasources:
259
postgres: true
260
prometheus: true
261
# -- Component-specific overrides for the Grafana Deployment.
262
# The official Grafana image runs as UID/GID 472.
263
securityContext:
264
pod:
265
runAsUser: 472
266
runAsGroup: 472
267
fsGroup: 472
268
container: {}
269
# -- Additional environment variables for the grafana container.
270
# Merged with chart defaults; user-supplied values take precedence.
271
# Example:
272
# env:
273
# GF_SERVER_ROOT_URL: "https://grafana.example.com"
274
# GF_LOG_LEVEL: "warn"
275
env: {}
276
# -- Inject env vars from existing ConfigMaps or Secrets.
277
# Example:
278
# envFrom:
279
# - secretRef:
280
# name: my-grafana-secret
281
envFrom: []
282
# ==============================================================================
283
# Subchart pass-throughs (opt-in)
284
# ==============================================================================
285
286
# TimescaleDB subchart — opt-in (Needs timescaledb.enabled: true).
287
# Replaces the built-in PostgreSQL StatefulSet; a post-install Job bootstraps the pgwatch user/databases.
288
# All keys under timescaledb: are passed through directly to the subchart.
289
# Ref: https://artifacthub.io/packages/helm/cloudpirates-timescaledb/timescaledb
290
timescaledb:
291
enabled: false
292
image:
293
# -- TimescaleDB image tag. Override to select a different PG/TS version.
294
# Available tags: https://hub.docker.com/r/timescale/timescaledb/tags
295
tag: "2.26.2-pg18"
296
auth:
297
# -- Password for the postgres admin user.
298
# If empty a random password is generated and stored in the release secret.
299
postgresPassword: ""
300
# -- Name of an existing Secret that already contains the postgres password.
301
# When set, postgresPassword is ignored.
302
existingSecret: ""
303
persistence:
304
enabled: true
305
# -- Storage size for the TimescaleDB data volume.
306
size: 10Gi
307
# -- StorageClass for the PVC. Uses the cluster default when empty.
308
storageClass: ""
309
# Grafana subchart — opt-in (pgwatch.grafana.useSubchart: true).
310
# Replaces the custom Grafana Deployment; datasources are auto-provisioned via the k8s-sidecar.
311
# All keys under grafana: are passed through directly to the subchart.
312
# Ref: https://github.com/grafana-community/helm-charts/tree/main/charts/grafana
313
grafana:
314
# -- Sidecar configuration for automatic dashboard and datasource discovery.
315
# The sidecar watches ConfigMaps labelled grafana_dashboard=1 / grafana_datasource=1
316
# in the same namespace and injects them at runtime — no pod restart needed.
317
sidecar:
318
dashboards:
319
enabled: true
320
# -- Label key used to identify dashboard ConfigMaps.
321
label: grafana_dashboard
322
# -- Annotation key on dashboard ConfigMaps that determines the target
323
# subdirectory on disk (e.g. "postgresql" -> /tmp/dashboards/postgresql/).
324
# Must match the grafana_dashboard_folder annotation used in the dashboard
325
# ConfigMap templates (grafana-postgresql-dashboards.yaml, grafana-prometheus-dashboards.yaml).
326
folderAnnotation: grafana_dashboard_folder
327
datasources:
328
enabled: true
329
# -- Label key used to identify datasource ConfigMaps.
330
label: grafana_datasource
331
grafana.ini:
332
auth.anonymous:
333
enabled: true
334
org_role: Admin
335
dashboards:
336
default_home_dashboard_path: /tmp/dashboards/postgresql/1-global-db-overview.json
337
# -- Optional env vars injected into the Grafana subchart main container.
338
# When pgwatch.grafana.useSubchart=true and datasource credentials come from an
339
# existing Secret with custom keys, mirror those keys here via envValueFrom so
340
# Grafana can resolve ${PGWATCH_METRICS_DS_USER} / ${PGWATCH_METRICS_DS_PASSWORD}
341
# placeholders from the datasource ConfigMap.
342
envValueFrom: {}
343

The trusted source for open source

Talk to an expert
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsChainguard OS PackagesChainguard ActionsChainguard Agent SkillsIntegrationsPricing
© 2026 Chainguard, Inc. All Rights Reserved.
Chainguard® and the Chainguard logo are registered trademarks of Chainguard, Inc. in the United States and/or other countries.
The other respective trademarks mentioned on this page are owned by the respective companies and use of them does not imply any affiliation or endorsement.