2 # image.repository -- pvc-autoresizer image repository to use.
3 repository: chainreg.biz/chainguard-private/pvc-autoresizer
4 # image.reference -- pvc-autoresizer image reference (a tag and/or a digest, e.g. "0.21.0@sha256:...") to use.
5 reference: 0.21.1-r0@sha256:2ad6f769f3ac69328166c21fcc0e623efdf90e9ed7a140a744cc4ede9cddca92
6 # image.pullPolicy -- pvc-autoresizer image pullPolicy.
8 # image.pullSecrets -- List of image pull secret names to use for pulling the pvc-autoresizer image (applied to the pod spec).
10 # - name: my-registry-secret
12 # controller.replicas -- Specify the number of replicas of the controller Pod.
15 # controller.args.useK8sMetricsApi -- Use Kubernetes metrics API instead of Prometheus.
16 # Used as "--use-k8s-metrics-api" option
17 useK8sMetricsApi: false
18 # controller.args.prometheusURL -- Specify Prometheus URL to query volume stats.
19 # Used as "--prometheus-url" option
20 prometheusURL: http://prometheus-prometheus-oper-prometheus.prometheus.svc:9090
21 # controller.args.namespaces -- Specify namespaces to control the pvcs of. Empty for all namespaces.
22 # Used as "--namespaces" option
24 # controller.args.interval -- Specify interval to monitor pvc capacity.
25 # Used as "--interval" option
27 # controller.args.additionalArgs -- Specify additional args.
29 # controller.resources -- Specify resources.
34 # controller.annotations -- Annotations to be added to controller deployment.
36 # controller.podLabels -- Pod labels to be added to controller pods.
38 # controller.podAnnotations -- Annotations to be added to controller pods.
41 # controller.podDisruptionBudget.enabled -- Specify podDisruptionBudget enabled.
43 # controller.podSecurityContext -- Security Context to be applied to the controller pods.
44 podSecurityContext: {}
45 # controller.securityContext -- Security Context to be applied to the controller container within controller pods.
47 # allowPrivilegeEscalation: false
51 # readOnlyRootFilesystem: true
55 # type: RuntimeDefault
57 # controller.terminationGracePeriodSeconds -- Specify terminationGracePeriodSeconds.
58 terminationGracePeriodSeconds: # 10
59 # controller.tolerations -- Ensure pods are not scheduled on inappropriate nodes.
61 # controller.nodeSelector -- Map of key-value pairs for scheduling pods on specific nodes.
63 # controller.affinity -- Affinity for controller deployment.
66 # requiredDuringSchedulingIgnoredDuringExecution:
69 # - key: app.kubernetes.io/name
73 # topologyKey: topology.kubernetes.io/zone
75 # preferredDuringSchedulingIgnoredDuringExecution:
80 # - key: app.kubernetes.io/name
84 # topologyKey: topology.kubernetes.io/zone
86 # controller.priorityClassName -- Priority class name to be applied to the controller pods.
88 # priorityClassName: system-cluster-critical
89# -- deploy a PodMonitor. This is not tested in CI so make sure to test it yourself.
91 # podMonitor.enabled -- If true, creates a Prometheus Operator PodMonitor.
93 # podMonitor.scheme -- Scheme to use for scraping.
95 # podMonitor.honorLabels -- If true, preserves the metric's labels when they collide with the target's labels.
97 # podMonitor.interval -- Interval that Prometheus scrapes metrics.
99 # podMonitor.scrapeTimeout -- The timeout after which the scrape is ended
101 # podMonitor.namespace -- Namespace which Prometheus is running in.
103 # podMonitor.relabelings -- RelabelConfigs to apply to samples before scraping.
105 # - sourceLabels: [__meta_kubernetes_service_label_cluster]
106 # targetLabel: cluster
111 # podMonitor.metricRelabelings -- MetricRelabelConfigs to apply to samples before ingestion.
112 metricRelabelings: []
113 # - sourceLabels: [__meta_kubernetes_service_label_cluster]
114 # targetLabel: cluster
119 # podMonitor.additionalLabels -- Additional labels that can be used so PodMonitor will be discovered by Prometheus.
123 # webhook.certificate.generate -- Creates a self-signed certificate for 10 years. Once the validity period has expired, simply delete the controller secret and execute helm upgrade.
125 # webhook.certificate.dnsDomain -- Cluster DNS domain (required for requesting TLS certificates).
126 dnsDomain: cluster.local
127 # webhook.caBundle -- Specify the certificate to be used for AdmissionWebhook.
128 caBundle: # Base64-encoded, PEM-encoded CA certificate that signs the server certificate.
129 # webhook.existingCertManagerIssuer -- Specify the cert-manager issuer to be used for AdmissionWebhook.
130 existingCertManagerIssuer: {}
131 # group: cert-manager.io
133 # name: webhook-issuer
135 # webhook.pvcMutatingWebhook.enabled -- Enable PVC MutatingWebhook.
138 # cert-manager.enabled -- Install cert-manager together.
139 ## ref: https://cert-manager.io/docs/installation/helm/#installing-with-helm
142 # serviceAccount.enabled -- Creates a ServiceAccount for the controller deployment.
144 # serviceAccount.automountServiceAccountToken -- Controls the automatic mounting of ServiceAccount API credentials.
145 automountServiceAccountToken: true
146 # serviceAccount.name -- The name for the newly created or existing service account.
148 # serviceAccount.imagePullSecrets -- List of image pull secret names to attach to the ServiceAccount (applied to all pods using the SA).
150 # - name: my-registry-secret