2 # -- Common tag for Argo Workflows images. Defaults to `.Chart.AppVersion`.
4 # -- imagePullPolicy to apply to all containers
6 # -- Secrets with credentials to pull images from a private registry
8 # - name: argo-pull-secret
9## Custom resource configuration
11 # -- Install and upgrade CRDs
13 # -- Keep CRDs on chart uninstall
15 # -- Use full CRDs with complete OpenAPI schemas. When false, uses minified CRDs with x-kubernetes-preserve-unknown-fields.
16 # Full CRDs are very large and are installed via a pre-install/pre-upgrade hook Job that uses server-side apply.
18 # -- Annotations to be added to all CRDs (only applies when crds.full=false)
20 # Configuration for the CRD install Job (only used when crds.full=true)
22 # -- Image for the container that applies the full CRDs. It bundles the CRDs for its own tag, so keep it in step with the app version.
23 ## Ref: https://argo-workflows.readthedocs.io/en/latest/crd-installer/
25 # -- Registry to use for the CRD installer
27 # -- Repository to use for the CRD installer
28 repository: chainguard-private/kubectl
29 # -- Image tag for the CRD installer. Defaults to `.Values.images.tag`.
30 tag: 1.37.1-r0@sha256:a13c468ad8ace94610c1cfe07b1de2c156d09ffd0aa9faf9e31c75f66c41b8c6
31 # -- Resources for the CRD install Job containers
33 # -- Node selector for the CRD install Job
35 # -- Pod security context for the CRD install Job pod
36 podSecurityContext: {}
37 # -- Optional labels to add to the CRD install Job pod
39 # -- Tolerations for the CRD install Job
41 # -- Image pull secrets for the CRD install Job
42 # @default -- `.Values.images.pullSecrets`
44 # -- Security context for the CRD install Job container
46 readOnlyRootFilesystem: true
48 allowPrivilegeEscalation: false
56 # -- Extra environment variables to provide to the CRD install Job container
58# -- Create ClusterRoles that extend existing ClusterRoles to interact with Argo Workflows CRDs.
59## Ref: https://kubernetes.io/docs/reference/access-authn-authz/rbac/#aggregated-clusterroles
60createAggregateRoles: true
61# -- String to partially override "argo-workflows.fullname" template
63# -- String to fully override "argo-workflows.fullname" template
65# -- Override the namespace
66# @default -- `.Release.Namespace`
68# -- Labels to set on all resources
70# -- Override the Kubernetes version, which is used to evaluate certain manifests
71kubeVersionOverride: ""
74 # -- String to override apiVersion of autoscaling rendered by this helm chart
75 autoscaling: "" # autoscaling/v2
76 # -- String to override apiVersion of GKE resources rendered by this helm chart
77 cloudgoogle: "" # cloud.google.com/v1
78 # -- String to override apiVersion of monitoring CRDs (ServiceMonitor) rendered by this helm chart
79 monitoring: "" # monitoring.coreos.com/v1
80# -- Restrict Argo to operate only in a single namespace (the namespace of the
81# Helm release) by apply Roles and RoleBindings instead of the Cluster
82# equivalents, and start workflow-controller with the --namespaced flag. Use it
83# in clusters with strict access policy.
86 # -- Deprecated; use controller.workflowNamespaces instead.
89 # -- Specifies whether a service account should be created
91 # -- Specifies whether a secret for each service account should be created
93 # -- Labels applied to created service account
95 # -- Annotations applied to created service account
97 # -- Service account which is used to run workflows
99 # -- Secrets with credentials to pull images from a private registry. Same format as `.Values.images.pullSecrets`
102 # -- Adds Role and RoleBinding for the above specified service account to be able to run workflows.
103 # A Role and Rolebinding pair is also created for each namespace in controller.workflowNamespaces (see below)
105 # -- Allows permissions for the Argo Agent. Only required if using http/plugin templates
106 agentPermissions: false
107 # -- Allows permissions for the Argo Artifact GC pod. Only required if using artifact gc
109 # -- Extra service accounts to be added to the RoleBinding
111 # - name: my-service-account
112 # namespace: my-namespace
113 # -- Additional rules for the service account that runs the workflows.
117 # -- Registry to use for the controller
119 # -- Registry to use for the controller
120 repository: chainguard-private/argo-workflowcontroller
121 # -- Image tag for the workflow controller. Defaults to `.Values.images.tag`.
122 tag: 4.1.4-r0@sha256:c776dbc00dbabc586b865b019602a584c3feb3dc89b8d429af57b5675f325b82
123 # -- parallelism dictates how many workflows can be running at the same time
125 # -- Globally limits the rate at which pods are created.
126 # This is intended to mitigate flooding of the Kubernetes API server by workflows with a large amount of
128 resourceRateLimit: {}
133 # -- Adds Role and RoleBinding for the controller.
135 # -- Allows controller to get, list, and watch certain k8s secrets
137 # -- Allows controller to get, list and watch all k8s secrets. Can only be used if secretWhitelist is empty.
138 accessAllSecrets: false
139 # -- Allows controller to create and update ConfigMaps. Enables memoization feature
140 writeConfigMaps: false
142 # -- Create a ConfigMap for the controller
146 # -- ConfigMap annotations
148 # -- Add checksum/config pod annotation to restart the controller when the ConfigMap changes. Alternative to the built-in config watcher; does not cover semaphore ConfigMaps.
149 restartOnChange: false
150 # -- Limits the maximum number of incomplete workflows in a namespace
151 namespaceParallelism:
152 # -- Resolves ongoing, uncommon AWS EKS bug: https://github.com/argoproj/argo-workflows/pull/4224
154 # -- deploymentAnnotations is an optional map of annotations to be applied to the controller Deployment
155 deploymentAnnotations: {}
156 # -- podAnnotations is an optional map of annotations to be applied to the controller Pods
158 # -- Optional labels to add to the controller pods
160 # -- SecurityContext to set on the controller pods
161 podSecurityContext: {}
164 # -- Enables prometheus metrics server
166 # -- Path is the path where metrics are emitted. Must start with a "/".
168 # -- Frequency at which prometheus scrapes metrics
170 # -- Port is the port where metrics are emitted
172 # -- How often custom metrics are cleared from memory
174 # -- Flag that instructs prometheus to ignore metric emission errors.
176 # -- Flag that use a self-signed cert for TLS
178 # -- Container metrics port name
180 # -- Service metrics port
182 # -- Service metrics port name
183 servicePortName: metrics
184 # -- serviceMonitor scheme
186 # -- Flag to enable headless service
187 headlessService: false
188 # -- When true, honorLabels preserves the metric’s labels when they collide with the target’s labels.
189 ## Ref: https://github.com/prometheus-operator/prometheus-operator/blob/main/Documentation/api.md#honorlabels
191 # -- ServiceMonitor relabel configs to apply to samples before scraping
192 ## Ref: https://github.com/prometheus-operator/prometheus-operator/blob/main/Documentation/api.md#relabelconfig
194 # -- ServiceMonitor metric relabel configs to apply to samples before ingestion
195 ## Ref: https://github.com/prometheus-operator/prometheus-operator/blob/main/Documentation/api.md#endpoint
196 metricRelabelings: []
197 # -- ServiceMonitor will add labels from the service to the Prometheus metric
198 ## Ref: https://github.com/prometheus-operator/prometheus-operator/blob/main/Documentation/api.md#servicemonitorspec
200 # -- Manipulate the metrics created by the workflow controller
201 ## Ref: https://argo-workflows.readthedocs.io/en/latest/metrics/#modifiers
203 # -- the controller container's securityContext
205 readOnlyRootFilesystem: true
207 allowPrivilegeEscalation: false
211 # -- enable Workflow Archive to store the status of workflows. Postgres, MySQL (>= 5.7.8) and MariaDB (>= 10.2.7, requires Argo Workflows v4.1+) are available.
212 ## Ref: https://argo-workflows.readthedocs.io/en/stable/workflow-archive/
217 # # save the entire workflow into etcd and DB
218 # nodeStatusOffLoad: false
219 # # enable archiving of old workflows
225 # tableName: argo_workflows
226 # # the database secrets must be in the same namespace of the controller
228 # name: argo-postgres-config
231 # name: argo-postgres-config
233 # # Instead of passwordSecret, Postgres can authenticate with a token.
234 # # Requires Argo Workflows v4.1+; userNameSecret is still required.
235 # # Microsoft Entra ID (needs Azure Workload Identity on the controller's service account):
238 # scope: https://ossrdbms-aad.database.windows.net/.default
239 # # AWS RDS IAM authentication (needs IRSA or EKS Pod Identity on the controller's service account):
244 # # sslMode must be one of: disable, require, verify-ca, verify-full
245 # # you can find more information about those ssl options here: https://godoc.org/github.com/lib/pq
251 # tableName: argo_workflows
253 # name: argo-mysql-config
256 # name: argo-mysql-config
259 # -- Default values that will apply to all Workflows from this controller, unless overridden on the Workflow-level.
260 # Only valid for 2.7+
261 ## See more: https://argo-workflows.readthedocs.io/en/stable/default-workflow-specs/
265 # secondsAfterCompletion: 86400
266 # # Ref: https://argo-workflows.readthedocs.io/en/stable/artifact-repository-ref/
267 # artifactRepositoryRef:
268 # configMap: my-artifact-repository # default is "artifact-repositories"
269 # key: v2-s3-artifact-repository # default can be set by the `workflows.argoproj.io/default-artifact-repository` annotation in config map.
271 # -- Number of workflow workers
272 workflowWorkers: # 32
273 # -- Number of workflow TTL workers
274 workflowTTLWorkers: # 4
275 # -- Number of pod cleanup workers
276 podCleanupWorkers: # 4
277 # -- Number of cron workflow workers
278 # Only valid for 3.5+
279 cronWorkflowWorkers: # 8
280 # -- Restricts the Workflows that the controller will process.
281 # Only valid for 2.9+
282 workflowRestrictions: {}
283 # templateReferencing: Strict|Secure
285 # telemetryConfig controls the path and port for prometheus telemetry. Telemetry is enabled and emitted in the same endpoint
286 # as metrics by default, but can be overridden using this config.
288 # -- Enables prometheus telemetry server
292 # -- Frequency at which prometheus scrapes telemetry data
294 # -- telemetry container port
296 # -- How often custom metrics are cleared from memory
298 # -- Flag that instructs prometheus to ignore metric emission errors.
300 # -- Flag that use a self-signed cert for TLS
302 # -- telemetry service port
304 # -- telemetry service port name
305 servicePortName: telemetry
306 # -- telemetry serviceMonitor scheme to use
309 # -- Enable a prometheus ServiceMonitor
311 # -- Prometheus ServiceMonitor labels
313 # -- Prometheus ServiceMonitor namespace
314 namespace: "" # "monitoring"
316 # -- Create a service account for the controller
318 # -- Service account name
320 # -- Labels applied to created service account
322 # -- Annotations applied to created service account
324 # -- Workflow controller name string
325 name: workflow-controller
326 # -- Specify all namespaces where this workflow controller instance will manage
327 # workflows. This controls where the service account and RBAC resources will
328 # be created. Only valid when singleNamespace is false.
332 # -- Configures the controller to filter workflow submissions
333 # to only those which have a matching instanceID attribute.
334 ## NOTE: If `instanceID.enabled` is set to `true` then either `instanceID.userReleaseName`
335 ## or `instanceID.explicitID` must be defined.
337 # -- Use ReleaseName as instanceID
338 useReleaseName: false
339 # useReleaseName: true
341 # -- Use a custom instanceID
343 # explicitID: unique-argo-controller-identifier
345 # -- Set the logging level (one of: `debug`, `info`, `warn`, `error`)
347 # -- Set the glog logging level
349 # -- Set the logging format (one of: `text`, `json`)
351 # -- Service type of the controller Service
352 serviceType: ClusterIP
353 # -- Annotations to be applied to the controller Service
354 serviceAnnotations: {}
355 # -- Optional labels to add to the controller Service
357 # -- The class of the load balancer implementation
358 loadBalancerClass: ""
359 # -- Source ranges to allow access to service from. Only applies to service type `LoadBalancer`
360 loadBalancerSourceRanges: []
361 # -- Resource limits and requests for the controller
363 # -- Configure liveness [probe] for the controller
364 # @default -- See [values.yaml]
370 initialDelaySeconds: 90
373 # -- Extra environment variables to provide to the controller container
378 # -- envFrom to pass to the controller container
380 # -- Extra arguments to be added to the controller
382 # -- Additional volume mounts to the controller main container
384 # -- Additional volumes to the controller pod
386 # -- The number of controller pods to run
388 # -- The number of revisions to keep.
389 revisionHistoryLimit: 10
391 # -- Configure [Pod Disruption Budget] for the controller pods
397 kubernetes.io/os: linux
398 # -- [Tolerations] for use with node taints
400 # -- Assign custom [affinity] rules
402 # -- Assign custom [TopologySpreadConstraints] rules to the workflow controller
403 ## Ref: https://kubernetes.io/docs/concepts/workloads/pods/pod-topology-spread-constraints/
404 ## If labelSelector is left out, it will default to the labelSelector configuration of the deployment
405 topologySpreadConstraints: []
407 # topologyKey: topology.kubernetes.io/zone
408 # whenUnsatisfiable: DoNotSchedule
410 # -- Leverage a PriorityClass to ensure your pods survive resource shortages.
411 ## ref: https://kubernetes.io/docs/concepts/configuration/pod-priority-preemption/
412 priorityClassName: ""
413 # -- Configure Argo Server to show custom [links]
414 ## Ref: https://argo-workflows.readthedocs.io/en/stable/links/
416 # -- Configure Argo Server to show custom [columns]
417 ## Ref: https://github.com/argoproj/argo-workflows/pull/10693
419 # -- Set ui navigation bar background color
421 clusterWorkflowTemplates:
422 # -- Create a ClusterRole and CRB for the controller to access ClusterWorkflowTemplates.
424 # -- Extra service accounts to be added to the ClusterRoleBinding
426 # - name: my-service-account
427 # namespace: my-namespace
428 # -- Extra containers to be added to the controller deployment
430 # -- Enables init containers to be added to the controller deployment
431 extraInitContainers: []
432 # -- Workflow retention by number of workflows
439 # -- Enable to emit events on node completion.
440 ## This can take up a lot of space in k8s (typically etcd) resulting in errors when trying to create new events:
441 ## "Unable to create audit event: etcdserver: mvcc: database space exceeded"
444 # -- Enable to emit events on workflow status changes.
445 ## This can take up a lot of space in k8s (typically etcd), resulting in errors when trying to create new events:
446 ## "Unable to create audit event: etcdserver: mvcc: database space exceeded"
448 # -- Configure when workflow controller runs in a different k8s cluster with the workflow workloads,
449 # or needs to communicate with the k8s apiserver using an out-of-cluster kubeconfig secret.
450 # @default -- `{}` (See [values.yaml])
452 # # name of the kubeconfig secret, may not be empty when kubeConfig specified
453 # secretName: kubeconfig-secret
454 # # key of the kubeconfig secret, may not be empty when kubeConfig specified
455 # secretKey: kubeconfig
456 # # mounting path of the kubeconfig secret, default to /kube/config
457 # mountPath: /kubeconfig/mount/path
458 # # volume name when mounting the secret, default to kubeconfig
459 # volumeName: kube-config-volume
461 # -- Specifies the duration in seconds before a terminating pod is forcefully killed. A zero value indicates that the pod will be forcefully terminated immediately.
462 # @default -- `30` seconds (Kubernetes default)
463 podGCGracePeriodSeconds:
464 # -- The duration in seconds before the pods in the GC queue get deleted. A zero value indicates that the pods will be deleted immediately.
465 # @default -- `5s` (Argo Workflows default)
466 podGCDeleteDelayDuration: ""
467 # -- enable Synchronization to use a database. Postgres and MySQL (>= 5.7.8) are available.
468 ## Ref: https://argo-workflows.readthedocs.io/en/latest/workflow-controller-configmap/#syncconfig
470 # controllerName: argo-workflows
478 # tableName: argo_workflows
479 # # the database secrets must be in the same namespace of the controller
481 # name: argo-postgres-config
484 # name: argo-postgres-config
487 # # sslMode must be one of: disable, require, verify-ca, verify-full
488 # # you can find more information about those ssl options here: https://godoc.org/github.com/lib/pq
494 # tableName: argo_workflows
496 # name: argo-mysql-config
499 # name: argo-mysql-config
503 # -- Enable to restart of pods that fail before entering Running state.
504 ## This is useful for recovering from transient infrastructure issues like node eviction due to DiskPressure or MemoryPressure without requiring a retryStrategy on every template.
505 ## ref: https://argo-workflows.readthedocs.io/en/latest/pod-restarts/
507 # -- Maximum number of automatic restarts per node before giving up.
509 # -- Disable the creation of agent pods, which are used for HTTP and Plugin templates. When enabled, HTTP and Plugin templates will not be processed by this controller.
510 # Only valid for 4.1+
511 disableAgentPodCreation: false
513 # -- Enable the init-less pod layout (beta), which provides the executor to workflow pods through an image volume instead of an init container.
514 # Only valid for 4.1+. Requires the `ImageVolume` feature gate on the kube-apiserver and all kubelets (beta in Kubernetes v1.33-1.35, enabled by default from v1.36).
515 ## Ref: https://argo-workflows.readthedocs.io/en/latest/initless-pod/
517# mainContainer adds default config for main container that could be overriden in workflows template
519 # -- imagePullPolicy to apply to Workflow main container. Defaults to `.Values.images.pullPolicy`.
521 # -- Resource limits and requests for the Workflow main container
523 # -- Adds environment variables for the Workflow main container
525 # -- Adds reference environment variables for the Workflow main container
527 # -- sets security context for the Workflow main container
529# executor controls how the init and wait container should be customized
532 # -- Registry to use for the Workflow Executors
534 # -- Repository to use for the Workflow Executors
535 repository: chainguard-private/argo-exec
536 # -- Image tag for the workflow executor. Defaults to `.Values.images.tag`.
537 tag: 4.1.4-r0@sha256:7f66db0c84b668f3be71ba4cc9d12a11ee43b181fd714dec9fdeb3cab0d0cb45
538 # -- Image PullPolicy to use for the Workflow Executors. Defaults to `.Values.images.pullPolicy`.
540 # -- Use the `-nonroot` executor image variant. When enabled, the `-nonroot` suffix is appended to the resolved image tag.
542 # -- Resource limits and requests for the Workflow Executors
544 # -- Passes arguments to the executor processes
546 # -- Adds environment variables for the executor.
548 # -- sets security context for the executor container
551 # -- Deploy the Argo Server
553 # -- Value for base href in index.html. Used if the server is running behind reverse proxy under subpath different from /.
554 ## only updates base url of resources on client side,
555 ## it's expected that a proxy server rewrites the request URL and gets rid of this prefix
556 ## https://github.com/argoproj/argo-workflows/issues/716#issuecomment-433213190
559 # -- Registry to use for the server
561 # -- Repository to use for the server
562 repository: chainguard-private/argo-cli
563 # -- Image tag for the Argo Workflows server. Defaults to `.Values.images.tag`.
564 tag: 4.1.4-r0@sha256:7c1438ae5b28158ad7f3904f46aae982733af3ce6f63a10094c8a04d91eb20b1
565 # -- optional map of annotations to be applied to the ui Deployment
566 deploymentAnnotations: {}
567 # -- optional map of annotations to be applied to the ui Pods
569 # -- Optional labels to add to the UI pods
571 # -- SecurityContext to set on the server pods
572 podSecurityContext: {}
574 # -- Adds Role and RoleBinding for the server.
576 # -- Servers container-level security context
578 readOnlyRootFilesystem: false
580 allowPrivilegeEscalation: false
584 # -- Server name string
586 # -- Service type for server pods
587 serviceType: ClusterIP
588 # -- Service port for server
590 # -- Service target port for server
591 serviceTargetPort: 2746
592 # -- Service node port
593 serviceNodePort: # 32746
594 # -- Service port name
595 servicePortName: "" # http
596 # -- Mapping between IP and hostnames that will be injected as entries in the pod's hosts files
603 # -- Create a service account for the server
605 # -- Service account name
607 # -- Labels applied to created service account
609 # -- Annotations applied to created service account
611 # -- Annotations to be applied to the UI Service
612 serviceAnnotations: {}
613 # -- Optional labels to add to the UI Service
615 # -- The class of the load balancer implementation
616 loadBalancerClass: ""
617 # -- Static IP address to assign to loadBalancer service type `LoadBalancer`
619 # -- Source ranges to allow access to service from. Only applies to service type `LoadBalancer`
620 loadBalancerSourceRanges: []
621 # -- Resource limits and requests for the server
623 # -- The number of server pods to run
625 # -- The number of revisions to keep.
626 revisionHistoryLimit: 10
627 ## Argo Server Horizontal Pod Autoscaler
629 # -- Enable Horizontal Pod Autoscaler ([HPA]) for the Argo Server
631 # -- Minimum number of replicas for the Argo Server [HPA]
633 # -- Maximum number of replicas for the Argo Server [HPA]
635 # -- Average CPU utilization percentage for the Argo Server [HPA]
636 targetCPUUtilizationPercentage: 50
637 # -- Average memory utilization percentage for the Argo Server [HPA]
638 targetMemoryUtilizationPercentage: 50
639 # -- Configures the scaling behavior of the target in both Up and Down directions.
640 # This is only available on HPA apiVersion `autoscaling/v2beta2` and newer
643 # stabilizationWindowSeconds: 300
649 # stabilizationWindowSeconds: 300
654 # -- Configure [Pod Disruption Budget] for the server pods
660 kubernetes.io/os: linux
661 # -- [Tolerations] for use with node taints
663 # -- Assign custom [affinity] rules
665 # -- Assign custom [TopologySpreadConstraints] rules to the argo server
666 ## Ref: https://kubernetes.io/docs/concepts/workloads/pods/pod-topology-spread-constraints/
667 ## If labelSelector is left out, it will default to the labelSelector configuration of the deployment
668 topologySpreadConstraints: []
670 # topologyKey: topology.kubernetes.io/zone
671 # whenUnsatisfiable: DoNotSchedule
673 # -- Leverage a PriorityClass to ensure your pods survive resource shortages
674 ## ref: https://kubernetes.io/docs/concepts/configuration/pod-priority-preemption/
675 priorityClassName: ""
676 # -- Run the argo server in "secure" mode. Configure this value instead of `--secure` in extraArgs.
677 ## See the following documentation for more details on secure mode:
678 ## https://argo-workflows.readthedocs.io/en/stable/tls/
680 # -- Extra environment variables to provide to the argo-server container
685 # -- envFrom to pass to the argo-server container
687 # -- Deprecated; use server.authModes instead.
689 # -- A list of supported authentication modes. Available values are `server`, `client`, or `sso`. If you provide sso, please configure `.Values.server.sso` as well.
690 ## Ref: https://argo-workflows.readthedocs.io/en/stable/argo-server-auth-mode/
692 # -- Extra arguments to provide to the Argo server binary.
693 ## Ref: https://argo-workflows.readthedocs.io/en/stable/argo-server/#options
696 # -- Set the logging level (one of: `debug`, `info`, `warn`, `error`)
698 # -- Set the glog logging level
700 # -- Set the logging format (one of: `text`, `json`)
702 # -- Volume to be mounted in Pods for temporary files.
705 # -- Additional volume mounts to the server main container.
707 # -- Additional volumes to the server pod.
709 ## Ingress configuration.
710 # ref: https://kubernetes.io/docs/concepts/services-networking/ingress/
712 # -- Enable an ingress resource
714 # -- Additional ingress annotations
716 # -- Additional ingress labels
718 # -- Defines which ingress controller will implement the resource
720 # -- List of ingress hosts
721 ## Hostnames must be provided if Ingress is enabled.
722 ## Secrets must be manually created in the namespace
724 # - argoworkflows.example.com
726 # -- List of ingress paths
729 # -- Ingress path type. One of `Exact`, `Prefix` or `ImplementationSpecific`
731 # -- Additional ingress paths
735 # serviceName: ssl-redirect
736 # servicePort: use-annotation
737 ## for Kubernetes >=1.19 (when "networking.k8s.io/v1" is used)
744 # name: use-annotation
746 # -- Ingress TLS configuration
748 # - secretName: argoworkflows-example-tls
750 # - argoworkflows.example.com
751 ## Create a Google Backendconfig for use with the GKE Ingress Controller
752 ## https://cloud.google.com/kubernetes-engine/docs/how-to/ingress-configuration#configuring_ingress_features_through_backendconfig_parameters
754 # -- Enable BackendConfig custom resource for Google Kubernetes Engine
756 # -- [BackendConfigSpec]
761 # oauthclientCredentials:
762 # secretName: argoworkflows-secret
764 ## Create a Google Managed Certificate for use with the GKE Ingress Controller
765 ## https://cloud.google.com/kubernetes-engine/docs/how-to/managed-certs
766 GKEmanagedCertificate:
767 # -- Enable ManagedCertificate custom resource for Google Kubernetes Engine.
769 # -- Domains for the Google Managed Certificate
771 - argoworkflows.example.com
772 ## Create a Google FrontendConfig Custom Resource, for use with the GKE Ingress Controller
773 ## https://cloud.google.com/kubernetes-engine/docs/how-to/ingress-features#configuring_ingress_features_through_frontendconfig_parameters
775 # -- Enable FrontConfig custom resource for Google Kubernetes Engine
777 # -- [FrontendConfigSpec]
782 # responseCodeName: RESPONSE_CODE
784 # Gateway API HTTPRoute configuration
785 # NOTE: Gateway API support is in EXPERIMENTAL status
786 # Support depends on your Gateway controller implementation
787 # Some controllers may require additional configuration (e.g., BackendTLSPolicy for HTTPS backends)
788 # Refer to https://gateway-api.sigs.k8s.io/implementations/ for controller-specific details
790 # -- Enable HTTPRoute resource for Argo Workflows server (Gateway API)
792 # -- Additional HTTPRoute labels
794 # -- Additional HTTPRoute annotations
796 # -- Gateway API parentRefs for the HTTPRoute
797 ## Must reference an existing Gateway
798 # @default -- `[]` (See [values.yaml])
800 # - name: example-gateway
801 # namespace: example-gateway-namespace
803 # -- List of hostnames for the HTTPRoute
804 # @default -- `[]` (See [values.yaml])
806 # - argoworkflows.example.com
807 # -- HTTPRoute rules configuration
808 # @default -- `[]` (See [values.yaml])
815 # - type: RequestHeaderModifier
816 # requestHeaderModifier:
818 # - name: X-Custom-Header
819 # value: custom-value
823 # Gateway API BackendTLSPolicy configuration
824 # NOTE: BackendTLSPolicy support is in EXPERIMENTAL status
825 # Required for HTTPS backends when using Gateway API
826 # Not all Gateway controllers support this resource (e.g., Cilium does not support it yet)
828 # -- Enable BackendTLSPolicy resource for Argo Workflows server (Gateway API)
830 # -- Additional BackendTLSPolicy labels
832 # -- Additional BackendTLSPolicy annotations
834 # -- Target references for the BackendTLSPolicy
835 # @default -- `[]` (See [values.yaml])
839 # name: argo-workflows-server
841 # -- TLS validation configuration
842 # @default -- `{}` (See [values.yaml])
844 # hostname: argo-workflows-server.argo.svc.cluster.local
846 # - name: example-ca-cert
849 # wellKnownCACertificates: System
850 clusterWorkflowTemplates:
851 # -- Create a ClusterRole and CRB for the server to access ClusterWorkflowTemplates.
853 # -- Give the server permissions to edit ClusterWorkflowTemplates.
855 # SSO configuration when SSO is specified as a server auth mode.
857 # -- Create SSO configuration. If you set `true` , please also set `.Values.server.authModes` as `sso`.
859 # -- The root URL of the OIDC identity provider
860 issuer: https://accounts.google.com
862 # -- Name of secret to retrieve the app OIDC client ID
863 name: argo-server-sso
864 # -- Key of secret to retrieve the app OIDC client ID
867 # -- Name of a secret to retrieve the app OIDC client secret
868 name: argo-server-sso
869 # -- Key of a secret to retrieve the app OIDC client secret
871 # -- The OIDC redirect URL. Should be in the form <argo-root-url>/oauth2/callback.
874 # -- Adds ServiceAccount Policy to server (Cluster)Role.
876 # -- Whitelist to allow server to fetch Secrets
877 ## When present, restricts secrets the server can read to a given list.
878 ## You can use it to restrict the server to only be able to access the
879 ## service account token secrets that are associated with service accounts
880 ## used for authorization.
882 # -- Scopes requested from the SSO ID provider
883 ## The 'groups' scope requests group membership information, which is usually used for authorization decisions.
886 # -- Define how long your login is valid for (in hours)
887 ## If omitted, defaults to 10h.
889 # -- Alternate root URLs that can be included for some OIDC providers
891 # -- Override claim name for OIDC groups
892 customGroupClaimName: ""
893 # -- Specify the user info endpoint that contains the groups claim
894 ## Configure this if your OIDC provider provides groups information only using the user-info endpoint (e.g. Okta)
896 # -- Skip TLS verification for the HTTP client
897 insecureSkipVerify: false
898 # -- Custom PEM encoded CA certificate file contents used to validate the OIDC provider's certificate
900 # -- Filter the groups returned by the OIDC provider
901 ## A logical "OR" is used between each regex in the list
902 filterGroupsRegex: []
904 # - ".*argo-workflow.*"
905 # -- Extra containers to be added to the server deployment
907 # -- Enables init containers to be added to the server deployment
908 extraInitContainers: []
909 # -- Specify postStart and preStop lifecycle hooks for server container
911 # -- terminationGracePeriodSeconds for container lifecycle hook
912 terminationGracePeriodSeconds: 30
913 ## livenessProbe for server
914 ## Ref: https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-startup-probes/
916 # -- Enable Kubernetes liveness probe for server
919 # -- Http port to use for the liveness probe
921 # -- Http path to use for the liveness probe
923 # -- Minimum consecutive failures for the [probe] to be considered failed after having succeeded
925 # -- Number of seconds after the container has started before [probe] is initiated
926 initialDelaySeconds: 10
927 # -- How often (in seconds) to perform the [probe]
929 # -- Number of seconds after which the [probe] times out
931 # -- Minimum consecutive successes for the [probe] to be considered successful after having failed
933# -- Array of extra K8s manifests to deploy
935# - apiVersion: secrets-store.csi.x-k8s.io/v1
936# kind: SecretProviderClass
938# name: argo-server-sso
943# - objectName: "argo/server/sso"
944# objectType: "secretsmanager"
947# objectAlias: "client_id"
948# - path: "client_secret"
949# objectAlias: "client_secret"
953# objectName: client_id
954# - key: client_secret
955# objectName: client_secret
956# secretName: argo-server-sso-secrets-store
959# -- Use static credentials for S3 (eg. when not using AWS IRSA)
960useStaticCredentials: true
962 # -- Archive the main container logs as an artifact
964 # -- Store artifact in a S3-compliant object store
965 # @default -- See [values.yaml]
967 # # Note the `key` attribute is not the actual secret, it's the PATH to
968 # # the contents in the associated secret, as defined by the `name` attribute.
970 # name: "{{ .Release.Name }}-minio"
973 # name: "{{ .Release.Name }}-minio"
975 # sessionTokenSecret:
976 # name: "{{ .Release.Name }}-minio"
978 # # insecure will disable TLS. Primarily used for minio installs not configured with TLS
988 # # addressingStyle must be one of: "" (auto-detect), path, virtual-hosted
989 # # Only valid for 4.1+
990 # addressingStyle: ""
992 # enableEncryption: true
993 # -- Store artifact in a GCS object store
994 # @default -- `{}` (See [values.yaml])
996 # bucket: <project>-argo
997 # keyFormat: "{{ \"{{workflow.namespace}}/{{workflow.name}}/{{pod.name}}\" }}"
998 # # serviceAccountKeySecret is a secret selector.
999 # # It references the k8s secret named 'my-gcs-credentials'.
1000 # # This secret is expected to have the key 'serviceAccountKey',
1001 # # containing the base64 encoded credentials
1004 # # If it's running on GKE and Workload Identity is used,
1005 # # serviceAccountKeySecret is not needed.
1006 # serviceAccountKeySecret:
1007 # name: my-gcs-credentials
1008 # key: serviceAccountKey
1009 # -- Store artifact in Azure Blob Storage
1010 # @default -- `{}` (See [values.yaml])
1012 # endpoint: https://mystorageaccountname.blob.core.windows.net
1013 # container: my-container-name
1014 # blobNameFormat: path/in/container
1015 # # accountKeySecret is a secret selector.
1016 # # It references the k8s secret named 'my-azure-storage-credentials'.
1017 # # This secret is expected to have the key 'account-access-key',
1018 # # containing the base64 encoded credentials to the storage account.
1019 # # If a managed identity has been assigned to the machines running the
1020 # # workflow (e.g., https://docs.microsoft.com/en-us/azure/aks/use-managed-identity)
1021 # # then accountKeySecret is not needed, and useSDKCreds should be
1022 # # set to true instead:
1025 # name: my-azure-storage-credentials
1026 # key: account-access-key
1027# -- The section of custom artifact repository.
1028# Utilize a custom artifact repository that is not one of the current base ones (s3, gcs, azure)
1029customArtifactRepository: {}
1031# repoUrl: https://artifactory.example.com/raw
1033# name: artifactory-creds
1036# name: artifactory-creds
1039# -- The section of [artifact repository ref](https://argo-workflows.readthedocs.io/en/stable/artifact-repository-ref/).
1040# Each map key is the name of configmap
1041# @default -- `{}` (See [values.yaml])
1042artifactRepositoryRef: {}
1044# # If you want to use this config map by default, name it "artifact-repositories".
1045# # Otherwise, you can provide a reference to a
1046# # different config map in `artifactRepositoryRef.configMap`.
1047# artifact-repositories:
1048# # -- v3.0 and after - if you want to use a specific key, put that key into this annotation.
1050# workflows.argoproj.io/default-artifact-repository: default-v1-s3-artifact-repository
1051# # 1st data of configmap. See above artifactRepository or customArtifactRepository.
1052# default-v1-s3-artifact-repository:
1056# endpoint: minio:9000
1059# name: my-minio-cred
1062# name: my-minio-cred
1065# oss-artifact-repository:
1068# endpoint: http://oss-cn-zhangjiakou-internal.aliyuncs.com
1070# # accessKeySecret and secretKeySecret are secret selectors.
1071# # It references the k8s secret named 'bucket-workflow-artifect-credentials'.
1072# # This secret is expected to have the keys 'accessKey'
1073# # and 'secretKey', containing the base64 encoded credentials
1076# name: $mybucket-credentials
1079# name: $mybucket-credentials
1082# another-artifact-repositories:
1084# workflows.argoproj.io/default-artifact-repository: gcs
1087# keyFormat: prefix/in/bucket/{{workflow.name}}/{{pod.name}}
1088# serviceAccountKeySecret:
1089# name: my-gcs-credentials
1090# key: serviceAccountKey
1093 # -- The command/args for each image on workflow, needed when the command is not specified and the emissary executor is used.
1094 ## See more: https://argo-workflows.readthedocs.io/en/stable/workflow-executors/#emissary-emissary
1096 # argoproj/argosay:v2:
1098 # docker/whalesay:latest: