1# Additional Trusted CAs.
2# Enable this flag and add your CA certs as a secret named tls-ca-additional in the namespace.
3# See README.md for details.
4additionalTrustedCAs: false
6topologyKey: kubernetes.io/hostname
7# Source: https://ranchermanager.docs.rancher.com/how-to-guides/advanced-user-guides/enable-api-audit-log
10 # level can be one of 0, 1, 2, or 3 with 3 being the most verbose. This value is a system level default and may
11 # impact the verbosity on any AuditPolicies you define. See below for a description of each log level:
12 # 0: Only log metadata such as URI, method, user, etc
13 # 1: Log metadata, request headers, and response headers
14 # 2: Log metadata, request header, response headers, and request body
15 # 3: Log metadata, request header, response heaeders, request body, and response body
17 # destination may be one of "sidecar" or "hostpath". When set to "sidecar" logs will be sent and output to a sidecar
18 # container called "rancher-audit-log". When "hostpath" logs are written to a hostpath volume called "audit-log" to
19 # a directory configured by auditLog.hostPath.
21 hostPath: /var/log/rancher/audit/
25 # Set pod resource requests/limits for Audit log sidecar (ONLY used if destination=sidecar).
27 # Image for collecting rancher audit logs.
28 # Important: update pkg/image/export/resolve.go when this default image is changed, so that it's reflected accordingly in rancher-images.txt generated for air-gapped setups.
30 # Optional: Image-specific registry override
32 repository: chainreg.biz/scratch-images/test-tmp/busybox
33 tag: glibc-1.38.0-r2@sha256:d1b547b0872788e6d173054336777a28ed06723ded636113773c013b61c45f8d
34 # Optional: Image-specific pullPolicy Override
35 # options: Always, Never, IfNotPresent
36 pullPolicy: "IfNotPresent"
37# Timeout for rancher controllers to complete a cache sync. Larger clusters may need to increase this value.
40# As of Rancher v2.5.0 this flag is deprecated and must be set to 'true' in order for Rancher to start
42# Add debug flag to Rancher server
44# Control how the Rancher agents validate TLS connections
45# Valid options: strict, or system-store
46# Note, for new installations empty will default to strict on 2.9+, or system-store on 2.8 or older
48# Extra environment variables passed to the rancher pods.
50# - name: CATTLE_TLS_MIN_VERSION
53# Fully qualified name to reach your Rancher server
54# hostname: rancher.my.org
56## Optional array of imagePullSecrets containing private registry credentials
57## Ref: https://kubernetes.io/docs/tasks/configure-pod-container/pull-image-private-registry/
62# Readme for details and instruction on adding tls secrets.
64 # If set to false, ingress will not be created
66 # options: true, false
68 includeDefaultExtraAnnotations: true
71 # Certain ingress controllers will require the pathType or path to be set to a different value.
72 pathType: ImplementationSpecific
74 # Backend port number; should use either: 80, or 443.
75 # Must use 443 when `service.disableHTTP` is set to true.
77 # configurationSnippet - Add additional Nginx configuration. This example statically sets a header on the ingress.
78 # configurationSnippet: |
79 # more_set_input_headers "X-Forwarded-Host: {{ .Values.hostname }}";
81 # options: rancher, letsEncrypt, secret
83 secretName: tls-rancher-ingress
85# Override to use NodePort or LoadBalancer service type - default is ClusterIP
89 # An optional security setting to disables the HTTP port of the rancher service
90 # When set true, you must also set `ingress.servicePort` to 443 and the appropriate ingress annotation to use HTTPS
92### LetsEncrypt config ###
93# ProTip: The production environment only allows you to register a name 5 times a week.
94# Use staging until you have your config right.
96 # email: none@example.com
97 environment: production
99 # options: traefik, nginx
101# If you are using certs signed by a private CA set to 'true' and set the 'tls-ca'
102# in the 'cattle-system' namespace. See the README.md for details
104# http[s] proxy server passed into rancher server.
105# proxy: http://<username>@<password>:<url>:<port>
107# comma separated list of domains or ip addresses that will not use the proxy
108noProxy: 127.0.0.0/8,10.0.0.0/8,172.16.0.0/12,192.168.0.0/16,.svc,.cluster.local
109# Rancher image configuration
111 # Optional: Image-specific registry override
113 repository: chainreg.biz/scratch-images/test-tmp/rancher
114 # Defaults to .Chart.appVersion
115 # rancher/rancher image tag. https://hub.docker.com/r/rancher/rancher/tags/
116 tag: 2.12.13-r1@sha256:3bb63c6984c07b0a404779c0ed338f051a824914c83a4467999c03baf79606a6
117 pullPolicy: IfNotPresent
118## Deprecation Notice: `rancherImage`, `rancherImageTag`, and `rancherImagePullPolicy` are deprecated - use `image.*` fields instead.
119# Override the name of the Rancher image to pull.
120# To override the registry location use systemDefaultRegistry instead.
122# rancher/rancher image tag. https://hub.docker.com/r/rancher/rancher/tags/
123# Defaults to .Chart.appVersion
124# rancherImageTag: v2.0.7
125# Override imagePullPolicy for rancher server images
126# options: Always, Never, IfNotPresent
127# Defaults to IfNotPresent
128# rancherImagePullPolicy: <pullPolicy>
130# aggregationRegistrationTimeout: 5m
132# Number of Rancher server replicas. Setting to negative number will dynamically between 0 and the abs(replicas) based on available nodes.
133# of available nodes in the cluster
135# Set priorityClassName to avoid eviction
136priorityClassName: rancher-critical
137# Set pod resource requests/limits for Rancher.
141# Where to offload the TLS/SSL encryption
145# Set a custom image registry mirror to pull Rancher images from; useful in air-gapped environments.
146systemDefaultRegistry: ""
147# Set to use the packaged system charts
148useBundledSystemChart: false
149# Certmanager version compatibility
152# Rancher custom logos persistence
158 ## Volume kind to use for persistence: persistentVolumeClaim, configMap
159 volumeKind: persistentVolumeClaim
160 ## Use an existing volume. Custom logos should be copied to the volume by the user
161 # volumeName: custom-logos
162 ## Just for volumeKind: persistentVolumeClaim
163 ## To disables dynamic provisioning, set storageClass: "" or storageClass: "-"
165 accessMode: ReadWriteOnce
167# Rancher post-delete hook
171 # Optional: Image-specific registry override
173 repository: chainreg.biz/scratch-images/test-tmp/rancher-shell
174 tag: 0.5.3-r1@sha256:bb1a6bd63c7fabb7f1dc959c0fc853171435fbe1b64679cbd1fc2f2830e0679d
175 # Optional: Image-specific pullPolicy Override
176 # options: Always, Never, IfNotPresent
177 # pullPolicy: "Always"
179 - cattle-fleet-system
181 - rancher-operator-system
182 # Number of seconds to wait for an app to be uninstalled
184 # by default, the job will fail if it fail to uninstall any of the apps
185 ignoreTimeoutError: false
188 # Optional: Image-specific registry override
190 repository: chainreg.biz/scratch-images/test-tmp/rancher-shell
191 tag: 0.5.3-r1@sha256:bb1a6bd63c7fabb7f1dc959c0fc853171435fbe1b64679cbd1fc2f2830e0679d
192 # Optional: Image-specific pull policy override
193 # pullPolicy: "Always"
194# Set a bootstrap password. If leave empty, a random password will be generated.
197 ## should be ready within 2 minutes
201# Additional taints to tolerate
203# Additional node selector terms for the rancher deployment
205# - key: topology.kubernetes.io/zone
209extraNodeSelectorTerms: {}
218# Enable host networking for Rancher pods.
219# Required for EKS clusters using non-VPC CNIs (e.g. Calico).
221# helm values to use when installing the rancher-webhook chart.
222# helm values set here will override all other global values used when installing the webhook such as priorityClassName and systemRegistry settings.
224# helm values to use when installing the fleet chart.
225# helm values set here will override all other global values used when installing the fleet chart.
227# Create a dynamic manifests via values:
228# Beware: There will be no validation on these resource manifests in `extraObjects` - they must be valid k8s resources.
229# If you encounter issues installing/upgrading rancher while using these, please investigate these first.
231# - apiVersion: "networking.k8s.io/v1"
234# name: allow-https-444-to-rancher
235# namespace: your-namespace # Change to the appropriate namespace
239# app: rancher # Selects pods labeled with "app: rancher"
241# - Ingress # Controls inbound traffic to the selected pods
245# port: 444 # Allows only TCP traffic on port 444 (custom HTTPS port)
246# # Since no other ingress rules are defined, all other traffic is denied by default.
247# - apiVersion: "networking.k8s.io/v1"
250# name: rancher-deny-ingress
251# namespace: cattle-system