DirectorySecurity AdvisoriesPricing
Sign in
Directory
proxysql logoHELM

proxysql

Helm chart
Last changed
Request a free trial

Contact our team to test out this Helm chart and related images for free. Please also indicate any other images you would like to evaluate.

Overview
Chart tags
Default values
Chart metadata
Images

Tag:
Compare:

1
# Default values for proxysql.
2
# This is a YAML-formatted file.
3
# Declare variables to be passed into your templates.
4
5
image:
6
registry: chainreg.biz
7
repository: chainguard-private/proxysql
8
tag: 3.0.11-r4@sha256:047d2ef4a7d2e5dcba2939957ce1fe8f23d3c6d21bf12f47dffe9316c28ea54e
9
pullPolicy: IfNotPresent
10
imagePullSecrets: []
11
nameOverride: ""
12
fullnameOverride: ""
13
serviceAccount:
14
# Specifies whether a service account should be created
15
create: true
16
# The name of the service account to use.
17
# If not set and create is true, a name is generated using the fullname template
18
name:
19
podSecurityContext:
20
runAsNonRoot: true
21
fsGroup: 65532
22
runAsUser: 65532
23
runAsGroup: 65532
24
securityContext: {}
25
# capabilities:
26
# drop:
27
# - ALL
28
# readOnlyRootFilesystem: true
29
# runAsNonRoot: true
30
# runAsUser: 1000
31
32
## ProxySQL service configuration
33
service:
34
## ProxySQL service type
35
type: ClusterIP
36
# clusterIP: None
37
38
## SQL proxying port
39
proxyPort: 6033
40
## Specify the >proxy< NodePort value for the LoadBalancer and NodePort service types.
41
## ref: https://kubernetes.io/docs/concepts/services-networking/service/#type-nodeport
42
##
43
# proxyNodePort:
44
45
## Admin and clustering port
46
adminPort: 6032
47
## Specify the >admin< NodePort value for the LoadBalancer and NodePort service types.
48
## ref: https://kubernetes.io/docs/concepts/services-networking/service/#type-nodeport
49
##
50
# adminNodePort:
51
52
## Admin Web UI port
53
webPort: 6080
54
## Specify the >web< NodePort value for the LoadBalancer and NodePort service types.
55
## ref: https://kubernetes.io/docs/concepts/services-networking/service/#type-nodeport
56
##
57
# webNodePort:
58
59
## Provide any additional annotations which may be required.
60
## The value is evaluated as a template, so, for example, the value can depend on .Release or .Chart
61
annotations: {}
62
## Set the LoadBalancer service type to internal only.
63
## ref: https://kubernetes.io/docs/concepts/services-networking/service/#internal-load-balancer
64
##
65
# loadBalancerIP:
66
## Load Balancer sources
67
## https://kubernetes.io/docs/tasks/access-application-cluster/configure-cloud-provider-firewall/#restrict-access-for-loadbalancer-service
68
##
69
# loadBalancerSourceRanges:
70
# - 10.10.10.0/24
71
72
# Default pod resource allocation.
73
# Will be applied if not specified otherwise.
74
resources: {}
75
# We usually recommend not to specify default resources and to leave this as a conscious
76
# choice for the user. This also increases chances charts run on environments with little
77
# resources, such as Minikube. If you do want to specify resources, uncomment the following
78
# lines, adjust them as necessary, and remove the curly braces after 'resources:'.
79
# limits:
80
# cpu: 100m
81
# memory: 128Mi
82
# requests:
83
# cpu: 100m
84
# memory: 128Mi
85
86
# Default node selectors.
87
# Will be applied if not specified otherwise.
88
nodeSelector: {}
89
# Default pod tolerations.
90
# Will be applied if not specified otherwise.
91
tolerations: []
92
# Default node affinity.
93
# Will be applied if not specified otherwise.
94
affinity: {}
95
# Common annotations to add to all resources (sub-charts are not considered).
96
# Evaluated as a template
97
commonAnnotations: {}
98
# Common labels to add to all resources (sub-charts are not considered).
99
# Evaluated as a template
100
commonLabels: {}
101
# Default pod annotations.
102
# Will be applied if not specified otherwise.
103
podAnnotations: {}
104
# Default pod labels.
105
# If labels are same as commonLabels , this will take precedence
106
podLabels: {}
107
## Specify pod disruption budget
108
## ref: https://kubernetes.io/docs/tasks/run-application/configure-pdb/
109
##
110
podDisruptionBudget:
111
enabled: false
112
minAvailable: 1
113
# maxUnavailable: 1
114
startupProbe:
115
enabled: false
116
initialDelaySeconds: 5
117
periodSeconds: 3
118
timeoutSeconds: 1
119
failureThreshold: 10
120
successThreshold: 1
121
readinessProbe:
122
enabled: false
123
initialDelaySeconds: 0
124
periodSeconds: 10
125
timeoutSeconds: 5
126
failureThreshold: 60
127
successThreshold: 1
128
livenessProbe:
129
enabled: false
130
initialDelaySeconds: 5
131
periodSeconds: 10
132
timeoutSeconds: 5
133
failureThreshold: 3
134
successThreshold: 1
135
# Enable SSL communication with the backend MySQL servers
136
ssl:
137
## When a cert and a key or fromSecret are provided use_ssl is be enabled automaticaly (in mysql_servers items)
138
# if use_ssl is not specified.
139
auto: true
140
## Sets the values for the SSL CA, Cert and private Key in PEM format.
141
ca: ""
142
cert: ""
143
key: ""
144
sslDir: "/etc/proxysql" # ProxySQL SSL directory
145
ca_file: "ca.pem" # Name of the CA file
146
cert_file: "cert.pem" # Name of the Cert file
147
key_file: "key.pem" # Name of the private Key file
148
## Loads ca.pem, cert.pem, and key.pem from an existingSecret
149
fromSecret: ""
150
secret:
151
# This are the variables to set `admin_credentials`
152
# WARNING: Set the `admin_credentials` variable to a non-default user other than admin`.
153
# ProxySQL reserves the default `admin` user for local connection via localhost only.
154
admin_user: "proxysql-admin"
155
admin_password: "proxysql"
156
admin_variables:
157
debug: false
158
# admin/clustering listening interfaces
159
# NOTE:
160
# The mysql_ifaces parameter (e.g. interfaces="0.0.0.0:6032") is
161
# configured by default based on `.Values.service.adminPort`
162
# mysql_ifaces: "0.0.0.0:6032"
163
164
# refresh_interval: 2000
165
mysql_variables:
166
## ref: https://github.com/sysown/proxysql/wiki/Global-variables
167
#
168
169
# Listening IP and port for proxy connections
170
# NOTE:
171
# The interfaces parameter (e.g. interfaces="0.0.0.0:6033") is
172
# configured by default based on `.Values.service.proxyPort`
173
# interfaces: "0.0.0.0:6033"
174
175
## The number of background threads that ProxySQL uses in order to process MySQL traffic
176
threads: 4
177
## The maximum number of client connections that the proxy can handle.
178
max_connections: 2048
179
default_query_delay: 0
180
## Mechanism for specifying the maximal duration of queries to the backend MySQL (in ms)
181
default_query_timeout: 3600000
182
## Enables or disables MySQL Monitor.
183
# ref: https://github.com/sysown/proxysql/wiki/Monitor-Module
184
monitor_enabled: false
185
# monitor_username: "monitor"
186
# monitor_password: "monitor"
187
# monitor_history: 600000
188
## Configures ProxySQL mysql users.
189
# For MySQL 8.0 paswords must be mysql_native_password.
190
# ref: https://github.com/sysown/proxysql/wiki/MySQL-8.0
191
#
192
mysql_users:
193
# - username: "user"
194
# password: "password"
195
# default_hostgroup: 0
196
# max_connections: 200
197
# default_schema: "information_schema"
198
# active: 1
199
200
## Define MySQL backend servers
201
#
202
mysql_servers:
203
# - address: "172.17.0.1"
204
# port: 3306
205
# hostgroup: 0
206
# max_connections: 200
207
208
## Defines MySQL Query Rules (routing)
209
#
210
mysql_query_rules:
211
## Note that rule_id is not required! Since it's automaticaly set
212
# based on the array index.
213
#
214
# - active: 1
215
# match_pattern: "^SELECT .* FOR UPDATE$"
216
# destination_hostgroup: 0
217
# apply: 1
218
219
## If enabled, generate automagically a list of proxysql servers based on the
220
# the number statefullset 'proxysql-core' replicas (default 3).
221
use_default_proxysql_servers: true
222
## Defines an additional list of ProxySQL peers (clustering).
223
# For example, externally hosted proxysql core servers.
224
# ref: https://proxysql.com/documentation/proxysql-cluster/
225
additional_proxysql_servers:
226
# - hostname : peer’s hostname/IP
227
# port : peer’s port
228
# weight : currently unused, but in the roadmap for future enhancements
229
# comment : free form comment field
230
proxysql_cluster:
231
enabled: false
232
secret:
233
# This are the variables to set `admin_credentials` and corresponding `cluster_` variables
234
cluster_username: "proxysql-cluster"
235
cluster_password: "proxysql"
236
core:
237
## DNS Example:
238
# headless-svc: proxysql-core.<namespace>.svc.cluster.local
239
# sts-pod: proxysql-core-0.proxysql-core.<namespace>.svc.cluster.local
240
enabled: true
241
# Number of core/main ProxySQL nodes to listen for changes on AdminPort
242
# It is recommended to use one of the following number of replicas: 3, 5, 7, or 9.
243
replicas: 3
244
# Restart ProxySQL if crashes
245
exit_on_error: false
246
statefullset:
247
nodeSelector: {}
248
tolerations: []
249
affinity: {}
250
podAnnotations: {}
251
resources: {}
252
# limits:
253
# cpu: 100m
254
# memory: 128Mi
255
# requests:
256
# cpu: 100m
257
# memory: 128Mi
258
service:
259
# Override default core service name
260
name:
261
satellite:
262
# Select the Kubernetes Resource type for the Satellite nodes,
263
# either "DaemonSet" or "Deployment"
264
kind: "DaemonSet"
265
enabled: true
266
# Only applies if kind=Deployment
267
replicas: 3
268
# Restart ProxySQL if crashes
269
exit_on_error: false
270
daemonset:
271
nodeSelector: {}
272
tolerations: []
273
affinity: {}
274
# See ref: https://kubernetes.io/docs/concepts/workloads/controllers/daemonset/#scheduled-by-default-scheduler
275
# nodeAffinity:
276
# requiredDuringSchedulingIgnoredDuringExecution:
277
# nodeSelectorTerms:
278
# - matchFields:
279
# - key: metadata.name
280
# operator: In
281
# values:
282
# - target-host-name
283
podAnnotations: {}
284
resources: {}
285
# limits:
286
# cpu: 100m
287
# memory: 128Mi
288
# requests:
289
# cpu: 100m
290
# memory: 128Mi
291
service:
292
# Override default satellite service name
293
name:
294
# Cluster Init job
295
# Execute SQL operations/transactions to force proxysql
296
# to update the internal runtime_checksums_values, in order for satellites
297
# to pick up any changes.
298
# This is necessary because on each update the cluster config versioning
299
# starts at version/checksum = 0. As per specification the satellites won't sync the changes
300
# until the version/checksum is not 0.
301
job:
302
enabled: true
303
# Retry 3 times until failed
304
backoffLimit: 3
305
# delete the job resource after given seconds
306
ttlSecondsAfterFinished: 86400
307
nodeSelector: {}
308
tolerations: []
309
affinity: {}
310
podAnnotations: {}
311
resources: {}
312
# limits:
313
# cpu: 100m
314
# memory: 128Mi
315
# requests:
316
# cpu: 100m
317
# memory: 128Mi
318
healthcheck:
319
# This is the healtcheck script executed by the k8s probes
320
psql_user: null # If not set use `.mysql_variables.monitor_username`
321
psql_pass: null # If not set use `.mysql_variables.monitor_password`
322
psql_host: "127.0.0.1" # The listening core host/pod. NOTE: User 'monitor' can only connect locally
323
psql_host_port: null # The admin port. If not set use `.service.adminPort`
324
diff_check_limit: 10 # How many diff_check errors are tolerated before the healthcheck fails
325
kill_if_healthcheck_failed: true # Kill proxysql daemon if the healthcheck fails the test
326
verbose: false
327
command: ["/bin/sh", "-c", "/usr/local/bin/proxysql_cluster_healthcheck.sh"]
328
# Enable debugging container along the proxysql instance
329
# It may be usefull to access the proxysql admin interface locally to debug issues
330
debug:
331
sidecar:
332
# inject a debug sidecar container to all proxysql Pods
333
enabled: false
334
image: mysql:debian
335
command:
336
- /bin/sleep
337
- infinity
338
securityContext:
339
runAsUser: 999
340
runAsGroup: 999
341
terminationGracePeriodSeconds: 60
342

The trusted source for open source

Talk to an expert
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsChainguard OS PackagesChainguard ActionsChainguard Agent SkillsIntegrationsPricing
© 2026 Chainguard, Inc. All Rights Reserved.
Chainguard® and the Chainguard logo are registered trademarks of Chainguard, Inc. in the United States and/or other countries.
The other respective trademarks mentioned on this page are owned by the respective companies and use of them does not imply any affiliation or endorsement.