1# Default values for proxysql.
2# This is a YAML-formatted file.
3# Declare variables to be passed into your templates.
7 repository: chainguard-private/proxysql
8 tag: 3.0.11-r4@sha256:047d2ef4a7d2e5dcba2939957ce1fe8f23d3c6d21bf12f47dffe9316c28ea54e
9 pullPolicy: IfNotPresent
14 # Specifies whether a service account should be created
16 # The name of the service account to use.
17 # If not set and create is true, a name is generated using the fullname template
28# readOnlyRootFilesystem: true
32## ProxySQL service configuration
34 ## ProxySQL service type
40 ## Specify the >proxy< NodePort value for the LoadBalancer and NodePort service types.
41 ## ref: https://kubernetes.io/docs/concepts/services-networking/service/#type-nodeport
45 ## Admin and clustering port
47 ## Specify the >admin< NodePort value for the LoadBalancer and NodePort service types.
48 ## ref: https://kubernetes.io/docs/concepts/services-networking/service/#type-nodeport
54 ## Specify the >web< NodePort value for the LoadBalancer and NodePort service types.
55 ## ref: https://kubernetes.io/docs/concepts/services-networking/service/#type-nodeport
59 ## Provide any additional annotations which may be required.
60 ## The value is evaluated as a template, so, for example, the value can depend on .Release or .Chart
62 ## Set the LoadBalancer service type to internal only.
63 ## ref: https://kubernetes.io/docs/concepts/services-networking/service/#internal-load-balancer
66## Load Balancer sources
67## https://kubernetes.io/docs/tasks/access-application-cluster/configure-cloud-provider-firewall/#restrict-access-for-loadbalancer-service
69# loadBalancerSourceRanges:
72# Default pod resource allocation.
73# Will be applied if not specified otherwise.
75# We usually recommend not to specify default resources and to leave this as a conscious
76# choice for the user. This also increases chances charts run on environments with little
77# resources, such as Minikube. If you do want to specify resources, uncomment the following
78# lines, adjust them as necessary, and remove the curly braces after 'resources:'.
86# Default node selectors.
87# Will be applied if not specified otherwise.
89# Default pod tolerations.
90# Will be applied if not specified otherwise.
92# Default node affinity.
93# Will be applied if not specified otherwise.
95# Common annotations to add to all resources (sub-charts are not considered).
96# Evaluated as a template
98# Common labels to add to all resources (sub-charts are not considered).
99# Evaluated as a template
101# Default pod annotations.
102# Will be applied if not specified otherwise.
105# If labels are same as commonLabels , this will take precedence
107## Specify pod disruption budget
108## ref: https://kubernetes.io/docs/tasks/run-application/configure-pdb/
116 initialDelaySeconds: 5
123 initialDelaySeconds: 0
130 initialDelaySeconds: 5
135# Enable SSL communication with the backend MySQL servers
137 ## When a cert and a key or fromSecret are provided use_ssl is be enabled automaticaly (in mysql_servers items)
138 # if use_ssl is not specified.
140 ## Sets the values for the SSL CA, Cert and private Key in PEM format.
144 sslDir: "/etc/proxysql" # ProxySQL SSL directory
145 ca_file: "ca.pem" # Name of the CA file
146 cert_file: "cert.pem" # Name of the Cert file
147 key_file: "key.pem" # Name of the private Key file
148 ## Loads ca.pem, cert.pem, and key.pem from an existingSecret
151 # This are the variables to set `admin_credentials`
152 # WARNING: Set the `admin_credentials` variable to a non-default user other than admin`.
153 # ProxySQL reserves the default `admin` user for local connection via localhost only.
154 admin_user: "proxysql-admin"
155 admin_password: "proxysql"
158 # admin/clustering listening interfaces
160 # The mysql_ifaces parameter (e.g. interfaces="0.0.0.0:6032") is
161 # configured by default based on `.Values.service.adminPort`
162 # mysql_ifaces: "0.0.0.0:6032"
164 # refresh_interval: 2000
166 ## ref: https://github.com/sysown/proxysql/wiki/Global-variables
169 # Listening IP and port for proxy connections
171 # The interfaces parameter (e.g. interfaces="0.0.0.0:6033") is
172 # configured by default based on `.Values.service.proxyPort`
173 # interfaces: "0.0.0.0:6033"
175 ## The number of background threads that ProxySQL uses in order to process MySQL traffic
177 ## The maximum number of client connections that the proxy can handle.
178 max_connections: 2048
179 default_query_delay: 0
180 ## Mechanism for specifying the maximal duration of queries to the backend MySQL (in ms)
181 default_query_timeout: 3600000
182 ## Enables or disables MySQL Monitor.
183 # ref: https://github.com/sysown/proxysql/wiki/Monitor-Module
184 monitor_enabled: false
185 # monitor_username: "monitor"
186 # monitor_password: "monitor"
187 # monitor_history: 600000
188## Configures ProxySQL mysql users.
189# For MySQL 8.0 paswords must be mysql_native_password.
190# ref: https://github.com/sysown/proxysql/wiki/MySQL-8.0
194# password: "password"
195# default_hostgroup: 0
196# max_connections: 200
197# default_schema: "information_schema"
200## Define MySQL backend servers
203# - address: "172.17.0.1"
206# max_connections: 200
208## Defines MySQL Query Rules (routing)
211## Note that rule_id is not required! Since it's automaticaly set
212# based on the array index.
215# match_pattern: "^SELECT .* FOR UPDATE$"
216# destination_hostgroup: 0
219## If enabled, generate automagically a list of proxysql servers based on the
220# the number statefullset 'proxysql-core' replicas (default 3).
221use_default_proxysql_servers: true
222## Defines an additional list of ProxySQL peers (clustering).
223# For example, externally hosted proxysql core servers.
224# ref: https://proxysql.com/documentation/proxysql-cluster/
225additional_proxysql_servers:
226# - hostname : peer’s hostname/IP
228# weight : currently unused, but in the roadmap for future enhancements
229# comment : free form comment field
233 # This are the variables to set `admin_credentials` and corresponding `cluster_` variables
234 cluster_username: "proxysql-cluster"
235 cluster_password: "proxysql"
238 # headless-svc: proxysql-core.<namespace>.svc.cluster.local
239 # sts-pod: proxysql-core-0.proxysql-core.<namespace>.svc.cluster.local
241 # Number of core/main ProxySQL nodes to listen for changes on AdminPort
242 # It is recommended to use one of the following number of replicas: 3, 5, 7, or 9.
244 # Restart ProxySQL if crashes
259 # Override default core service name
262 # Select the Kubernetes Resource type for the Satellite nodes,
263 # either "DaemonSet" or "Deployment"
266 # Only applies if kind=Deployment
268 # Restart ProxySQL if crashes
274 # See ref: https://kubernetes.io/docs/concepts/workloads/controllers/daemonset/#scheduled-by-default-scheduler
276 # requiredDuringSchedulingIgnoredDuringExecution:
279 # - key: metadata.name
292 # Override default satellite service name
295 # Execute SQL operations/transactions to force proxysql
296 # to update the internal runtime_checksums_values, in order for satellites
297 # to pick up any changes.
298 # This is necessary because on each update the cluster config versioning
299 # starts at version/checksum = 0. As per specification the satellites won't sync the changes
300 # until the version/checksum is not 0.
303 # Retry 3 times until failed
305 # delete the job resource after given seconds
306 ttlSecondsAfterFinished: 86400
319 # This is the healtcheck script executed by the k8s probes
320 psql_user: null # If not set use `.mysql_variables.monitor_username`
321 psql_pass: null # If not set use `.mysql_variables.monitor_password`
322 psql_host: "127.0.0.1" # The listening core host/pod. NOTE: User 'monitor' can only connect locally
323 psql_host_port: null # The admin port. If not set use `.service.adminPort`
324 diff_check_limit: 10 # How many diff_check errors are tolerated before the healthcheck fails
325 kill_if_healthcheck_failed: true # Kill proxysql daemon if the healthcheck fails the test
327 command: ["/bin/sh", "-c", "/usr/local/bin/proxysql_cluster_healthcheck.sh"]
328# Enable debugging container along the proxysql instance
329# It may be usefull to access the proxysql admin interface locally to debug issues
332 # inject a debug sidecar container to all proxysql Pods
341terminationGracePeriodSeconds: 60