DirectorySecurity AdvisoriesPricing
Sign in
Directory
rancher logoHELM

rancher

Helm chart
Last changed
Request a free trial

Contact our team to test out this Helm chart and related images for free. Please also indicate any other images you would like to evaluate.

Overview
Chart tags
Default values
Chart metadata
Images

Tag:

1
# Additional Trusted CAs.
2
# Enable this flag and add your CA certs as a secret named tls-ca-additional in the namespace.
3
# See README.md for details.
4
additionalTrustedCAs: false
5
antiAffinity: preferred
6
topologyKey: kubernetes.io/hostname
7
# Source: https://ranchermanager.docs.rancher.com/how-to-guides/advanced-user-guides/enable-api-audit-log
8
auditLog:
9
enabled: false
10
# level can be one of 0, 1, 2, or 3 with 3 being the most verbose. This value is a system level default and may
11
# impact the verbosity on any AuditPolicies you define. See below for a description of each log level:
12
# 0: Only log metadata such as URI, method, user, etc
13
# 1: Log metadata, request headers, and response headers
14
# 2: Log metadata, request header, response headers, and request body
15
# 3: Log metadata, request header, response heaeders, request body, and response body
16
level: 0
17
# destination may be one of "sidecar" or "hostpath". When set to "sidecar" logs will be sent and output to a sidecar
18
# container called "rancher-audit-log". When "hostpath" logs are written to a hostpath volume called "audit-log" to
19
# a directory configured by auditLog.hostPath.
20
destination: sidecar
21
hostPath: /var/log/rancher/audit/
22
maxAge: 1
23
maxBackup: 1
24
maxSize: 100
25
# Set pod resource requests/limits for Audit log sidecar (ONLY used if destination=sidecar).
26
resources: {}
27
# Image for collecting rancher audit logs.
28
# Important: update pkg/image/export/resolve.go when this default image is changed, so that it's reflected accordingly in rancher-images.txt generated for air-gapped setups.
29
image:
30
# Optional: Image-specific registry override
31
# registry: ""
32
repository: chainreg.biz/scratch-images/test-tmp/busybox
33
tag: glibc-1.38.0-r2@sha256:d1b547b0872788e6d173054336777a28ed06723ded636113773c013b61c45f8d
34
# Optional: Image-specific pullPolicy Override
35
# options: Always, Never, IfNotPresent
36
pullPolicy: "IfNotPresent"
37
# Timeout for rancher controllers to complete a cache sync. Larger clusters may need to increase this value.
38
# cacheSyncTimeout: 5m
39
40
# As of Rancher v2.5.0 this flag is deprecated and must be set to 'true' in order for Rancher to start
41
addLocal: "true"
42
# Add debug flag to Rancher server
43
debug: false
44
# Control how the Rancher agents validate TLS connections
45
# Valid options: strict, or system-store
46
# Note, for new installations empty will default to strict on 2.9+, or system-store on 2.8 or older
47
agentTLSMode: ""
48
# Extra environment variables passed to the rancher pods.
49
# extraEnv:
50
# - name: CATTLE_TLS_MIN_VERSION
51
# value: "1.0"
52
53
# Fully qualified name to reach your Rancher server
54
# hostname: rancher.my.org
55
56
## Optional array of imagePullSecrets containing private registry credentials
57
## Ref: https://kubernetes.io/docs/tasks/configure-pod-container/pull-image-private-registry/
58
imagePullSecrets: []
59
# - name: secretName
60
61
### ingress ###
62
# Readme for details and instruction on adding tls secrets.
63
ingress:
64
# If set to false, ingress will not be created
65
# Defaults to true
66
# options: true, false
67
enabled: true
68
includeDefaultExtraAnnotations: true
69
extraAnnotations: {}
70
ingressClassName: ""
71
# Certain ingress controllers will require the pathType or path to be set to a different value.
72
pathType: ImplementationSpecific
73
path: "/"
74
# Backend port number; should use either: 80, or 443.
75
# Must use 443 when `service.disableHTTP` is set to true.
76
servicePort: 80
77
# configurationSnippet - Add additional Nginx configuration. This example statically sets a header on the ingress.
78
# configurationSnippet: |
79
# more_set_input_headers "X-Forwarded-Host: {{ .Values.hostname }}";
80
tls:
81
# options: rancher, letsEncrypt, secret
82
source: rancher
83
secretName: tls-rancher-ingress
84
### service ###
85
# Override to use NodePort or LoadBalancer service type - default is ClusterIP
86
service:
87
type: ""
88
annotations: {}
89
# An optional security setting to disables the HTTP port of the rancher service
90
# When set true, you must also set `ingress.servicePort` to 443 and the appropriate ingress annotation to use HTTPS
91
disableHTTP: false
92
### LetsEncrypt config ###
93
# ProTip: The production environment only allows you to register a name 5 times a week.
94
# Use staging until you have your config right.
95
letsEncrypt:
96
# email: none@example.com
97
environment: production
98
ingress:
99
# options: traefik, nginx
100
class: ""
101
# If you are using certs signed by a private CA set to 'true' and set the 'tls-ca'
102
# in the 'cattle-system' namespace. See the README.md for details
103
privateCA: false
104
# http[s] proxy server passed into rancher server.
105
# proxy: http://<username>@<password>:<url>:<port>
106
107
# comma separated list of domains or ip addresses that will not use the proxy
108
noProxy: 127.0.0.0/8,10.0.0.0/8,172.16.0.0/12,192.168.0.0/16,.svc,.cluster.local
109
# Rancher image configuration
110
image:
111
# Optional: Image-specific registry override
112
# registry: ""
113
repository: chainreg.biz/scratch-images/test-tmp/rancher
114
# Defaults to .Chart.appVersion
115
# rancher/rancher image tag. https://hub.docker.com/r/rancher/rancher/tags/
116
tag: 2.12.13-r1@sha256:3bb63c6984c07b0a404779c0ed338f051a824914c83a4467999c03baf79606a6
117
pullPolicy: IfNotPresent
118
## Deprecation Notice: `rancherImage`, `rancherImageTag`, and `rancherImagePullPolicy` are deprecated - use `image.*` fields instead.
119
# Override the name of the Rancher image to pull.
120
# To override the registry location use systemDefaultRegistry instead.
121
# rancherImage: ""
122
# rancher/rancher image tag. https://hub.docker.com/r/rancher/rancher/tags/
123
# Defaults to .Chart.appVersion
124
# rancherImageTag: v2.0.7
125
# Override imagePullPolicy for rancher server images
126
# options: Always, Never, IfNotPresent
127
# Defaults to IfNotPresent
128
# rancherImagePullPolicy: <pullPolicy>
129
130
# aggregationRegistrationTimeout: 5m
131
132
# Number of Rancher server replicas. Setting to negative number will dynamically between 0 and the abs(replicas) based on available nodes.
133
# of available nodes in the cluster
134
replicas: 3
135
# Set priorityClassName to avoid eviction
136
priorityClassName: rancher-critical
137
# Set pod resource requests/limits for Rancher.
138
resources: {}
139
#
140
# tls
141
# Where to offload the TLS/SSL encryption
142
# - ingress (default)
143
# - external
144
tls: ingress
145
# Set a custom image registry mirror to pull Rancher images from; useful in air-gapped environments.
146
systemDefaultRegistry: ""
147
# Set to use the packaged system charts
148
useBundledSystemChart: false
149
# Certmanager version compatibility
150
certmanager:
151
version: ""
152
# Rancher custom logos persistence
153
customLogos:
154
enabled: false
155
volumeSubpaths:
156
emberUi: "ember"
157
vueUi: "vue"
158
## Volume kind to use for persistence: persistentVolumeClaim, configMap
159
volumeKind: persistentVolumeClaim
160
## Use an existing volume. Custom logos should be copied to the volume by the user
161
# volumeName: custom-logos
162
## Just for volumeKind: persistentVolumeClaim
163
## To disables dynamic provisioning, set storageClass: "" or storageClass: "-"
164
# storageClass: "-"
165
accessMode: ReadWriteOnce
166
size: 1Gi
167
# Rancher post-delete hook
168
postDelete:
169
enabled: true
170
image:
171
# Optional: Image-specific registry override
172
# registry: ""
173
repository: chainreg.biz/scratch-images/test-tmp/rancher-shell
174
tag: 0.5.3-r1@sha256:bb1a6bd63c7fabb7f1dc959c0fc853171435fbe1b64679cbd1fc2f2830e0679d
175
# Optional: Image-specific pullPolicy Override
176
# options: Always, Never, IfNotPresent
177
# pullPolicy: "Always"
178
namespaceList:
179
- cattle-fleet-system
180
- cattle-system
181
- rancher-operator-system
182
# Number of seconds to wait for an app to be uninstalled
183
timeout: 120
184
# by default, the job will fail if it fail to uninstall any of the apps
185
ignoreTimeoutError: false
186
preUpgrade:
187
image:
188
# Optional: Image-specific registry override
189
# registry: ""
190
repository: chainreg.biz/scratch-images/test-tmp/rancher-shell
191
tag: 0.5.3-r1@sha256:bb1a6bd63c7fabb7f1dc959c0fc853171435fbe1b64679cbd1fc2f2830e0679d
192
# Optional: Image-specific pull policy override
193
# pullPolicy: "Always"
194
# Set a bootstrap password. If leave empty, a random password will be generated.
195
bootstrapPassword: ""
196
startupProbe:
197
## should be ready within 2 minutes
198
timeoutSeconds: 5
199
periodSeconds: 10
200
failureThreshold: 12
201
# Additional taints to tolerate
202
extraTolerations: {}
203
# Additional node selector terms for the rancher deployment
204
# Ex:
205
# - key: topology.kubernetes.io/zone
206
# operator: In
207
# values:
208
# - us-north-42
209
extraNodeSelectorTerms: {}
210
livenessProbe:
211
timeoutSeconds: 5
212
periodSeconds: 30
213
failureThreshold: 5
214
readinessProbe:
215
timeoutSeconds: 5
216
periodSeconds: 30
217
failureThreshold: 5
218
# Enable host networking for Rancher pods.
219
# Required for EKS clusters using non-VPC CNIs (e.g. Calico).
220
hostNetwork: false
221
# helm values to use when installing the rancher-webhook chart.
222
# helm values set here will override all other global values used when installing the webhook such as priorityClassName and systemRegistry settings.
223
webhook: ""
224
# helm values to use when installing the fleet chart.
225
# helm values set here will override all other global values used when installing the fleet chart.
226
fleet: ""
227
# Create a dynamic manifests via values:
228
# Beware: There will be no validation on these resource manifests in `extraObjects` - they must be valid k8s resources.
229
# If you encounter issues installing/upgrading rancher while using these, please investigate these first.
230
extraObjects: []
231
# - apiVersion: "networking.k8s.io/v1"
232
# kind: NetworkPolicy
233
# metadata:
234
# name: allow-https-444-to-rancher
235
# namespace: your-namespace # Change to the appropriate namespace
236
# spec:
237
# podSelector:
238
# matchLabels:
239
# app: rancher # Selects pods labeled with "app: rancher"
240
# policyTypes:
241
# - Ingress # Controls inbound traffic to the selected pods
242
# ingress:
243
# - ports:
244
# - protocol: TCP
245
# port: 444 # Allows only TCP traffic on port 444 (custom HTTPS port)
246
# # Since no other ingress rules are defined, all other traffic is denied by default.
247
# - apiVersion: "networking.k8s.io/v1"
248
# kind: NetworkPolicy
249
# metadata:
250
# name: rancher-deny-ingress
251
# namespace: cattle-system
252
# spec:
253
# podSelector:
254
# matchLabels:
255
# app: rancher
256
# policyTypes:
257
# - Ingress
258

The trusted source for open source

Talk to an expert
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsChainguard OS PackagesChainguard ActionsChainguard Agent SkillsIntegrationsPricing
© 2026 Chainguard, Inc. All Rights Reserved.
Chainguard® and the Chainguard logo are registered trademarks of Chainguard, Inc. in the United States and/or other countries.
The other respective trademarks mentioned on this page are owned by the respective companies and use of them does not imply any affiliation or endorsement.