DirectorySecurity AdvisoriesPricing
Sign in
Directory
argo-workflows logoHELM

argo-workflows

Helm chart
Last changed
Request a free trial

Contact our team to test out this Helm chart and related images for free. Please also indicate any other images you would like to evaluate.

Overview
Chart versions
Default values
Chart metadata
Images

Tag:
Compare:

1
images:
2
# -- Common tag for Argo Workflows images. Defaults to `.Chart.AppVersion`.
3
tag: ""
4
# -- imagePullPolicy to apply to all containers
5
pullPolicy: Always
6
# -- Secrets with credentials to pull images from a private registry
7
pullSecrets: []
8
# - name: argo-pull-secret
9
## Custom resource configuration
10
crds:
11
# -- Install and upgrade CRDs
12
install: true
13
# -- Keep CRDs on chart uninstall
14
keep: true
15
# -- Use full CRDs with complete OpenAPI schemas. When false, uses minified CRDs with x-kubernetes-preserve-unknown-fields.
16
# Full CRDs are very large and are installed via a pre-install/pre-upgrade hook Job that uses server-side apply.
17
full: true
18
# -- Annotations to be added to all CRDs (only applies when crds.full=false)
19
annotations: {}
20
# Configuration for the CRD install Job (only used when crds.full=true)
21
upgradeJob:
22
# -- Image for the container that applies the full CRDs. It bundles the CRDs for its own tag, so keep it in step with the app version.
23
## Ref: https://argo-workflows.readthedocs.io/en/latest/crd-installer/
24
image:
25
# -- Registry to use for the CRD installer
26
registry: cgr.dev
27
# -- Repository to use for the CRD installer
28
repository: chainguard-private/kubectl
29
# -- Image tag for the CRD installer. Defaults to `.Values.images.tag`.
30
tag: 1.37.1-r0@sha256:a13c468ad8ace94610c1cfe07b1de2c156d09ffd0aa9faf9e31c75f66c41b8c6
31
# -- Resources for the CRD install Job containers
32
resources: {}
33
# -- Node selector for the CRD install Job
34
nodeSelector: {}
35
# -- Pod security context for the CRD install Job pod
36
podSecurityContext: {}
37
# -- Optional labels to add to the CRD install Job pod
38
podLabels: {}
39
# -- Tolerations for the CRD install Job
40
tolerations: []
41
# -- Image pull secrets for the CRD install Job
42
# @default -- `.Values.images.pullSecrets`
43
imagePullSecrets: []
44
# -- Security context for the CRD install Job container
45
securityContext:
46
readOnlyRootFilesystem: true
47
runAsNonRoot: true
48
allowPrivilegeEscalation: false
49
runAsUser: 8737
50
runAsGroup: 8737
51
seccompProfile:
52
type: RuntimeDefault
53
capabilities:
54
drop:
55
- ALL
56
# -- Extra environment variables to provide to the CRD install Job container
57
extraEnv: []
58
# -- Create ClusterRoles that extend existing ClusterRoles to interact with Argo Workflows CRDs.
59
## Ref: https://kubernetes.io/docs/reference/access-authn-authz/rbac/#aggregated-clusterroles
60
createAggregateRoles: true
61
# -- String to partially override "argo-workflows.fullname" template
62
nameOverride:
63
# -- String to fully override "argo-workflows.fullname" template
64
fullnameOverride:
65
# -- Override the namespace
66
# @default -- `.Release.Namespace`
67
namespaceOverride: ""
68
# -- Labels to set on all resources
69
commonLabels: {}
70
# -- Override the Kubernetes version, which is used to evaluate certain manifests
71
kubeVersionOverride: ""
72
# Override APIVersions
73
apiVersionOverrides:
74
# -- String to override apiVersion of autoscaling rendered by this helm chart
75
autoscaling: "" # autoscaling/v2
76
# -- String to override apiVersion of GKE resources rendered by this helm chart
77
cloudgoogle: "" # cloud.google.com/v1
78
# -- String to override apiVersion of monitoring CRDs (ServiceMonitor) rendered by this helm chart
79
monitoring: "" # monitoring.coreos.com/v1
80
# -- Restrict Argo to operate only in a single namespace (the namespace of the
81
# Helm release) by apply Roles and RoleBindings instead of the Cluster
82
# equivalents, and start workflow-controller with the --namespaced flag. Use it
83
# in clusters with strict access policy.
84
singleNamespace: false
85
workflow:
86
# -- Deprecated; use controller.workflowNamespaces instead.
87
namespace:
88
serviceAccount:
89
# -- Specifies whether a service account should be created
90
create: false
91
# -- Specifies whether a secret for each service account should be created
92
createSecret: false
93
# -- Labels applied to created service account
94
labels: {}
95
# -- Annotations applied to created service account
96
annotations: {}
97
# -- Service account which is used to run workflows
98
name: "argo-workflow"
99
# -- Secrets with credentials to pull images from a private registry. Same format as `.Values.images.pullSecrets`
100
pullSecrets: []
101
rbac:
102
# -- Adds Role and RoleBinding for the above specified service account to be able to run workflows.
103
# A Role and Rolebinding pair is also created for each namespace in controller.workflowNamespaces (see below)
104
create: true
105
# -- Allows permissions for the Argo Agent. Only required if using http/plugin templates
106
agentPermissions: false
107
# -- Allows permissions for the Argo Artifact GC pod. Only required if using artifact gc
108
artifactGC: false
109
# -- Extra service accounts to be added to the RoleBinding
110
serviceAccounts: []
111
# - name: my-service-account
112
# namespace: my-namespace
113
# -- Additional rules for the service account that runs the workflows.
114
rules: []
115
controller:
116
image:
117
# -- Registry to use for the controller
118
registry: cgr.dev
119
# -- Registry to use for the controller
120
repository: chainguard-private/argo-workflowcontroller
121
# -- Image tag for the workflow controller. Defaults to `.Values.images.tag`.
122
tag: 4.1.4-r0@sha256:c776dbc00dbabc586b865b019602a584c3feb3dc89b8d429af57b5675f325b82
123
# -- parallelism dictates how many workflows can be running at the same time
124
parallelism:
125
# -- Globally limits the rate at which pods are created.
126
# This is intended to mitigate flooding of the Kubernetes API server by workflows with a large amount of
127
# parallel nodes.
128
resourceRateLimit: {}
129
# limit: 10
130
# burst: 1
131
132
rbac:
133
# -- Adds Role and RoleBinding for the controller.
134
create: true
135
# -- Allows controller to get, list, and watch certain k8s secrets
136
secretWhitelist: []
137
# -- Allows controller to get, list and watch all k8s secrets. Can only be used if secretWhitelist is empty.
138
accessAllSecrets: false
139
# -- Allows controller to create and update ConfigMaps. Enables memoization feature
140
writeConfigMaps: false
141
configMap:
142
# -- Create a ConfigMap for the controller
143
create: true
144
# -- ConfigMap name
145
name: ""
146
# -- ConfigMap annotations
147
annotations: {}
148
# -- Add checksum/config pod annotation to restart the controller when the ConfigMap changes. Alternative to the built-in config watcher; does not cover semaphore ConfigMaps.
149
restartOnChange: false
150
# -- Limits the maximum number of incomplete workflows in a namespace
151
namespaceParallelism:
152
# -- Resolves ongoing, uncommon AWS EKS bug: https://github.com/argoproj/argo-workflows/pull/4224
153
initialDelay:
154
# -- deploymentAnnotations is an optional map of annotations to be applied to the controller Deployment
155
deploymentAnnotations: {}
156
# -- podAnnotations is an optional map of annotations to be applied to the controller Pods
157
podAnnotations: {}
158
# -- Optional labels to add to the controller pods
159
podLabels: {}
160
# -- SecurityContext to set on the controller pods
161
podSecurityContext: {}
162
# podPortName: http
163
metricsConfig:
164
# -- Enables prometheus metrics server
165
enabled: false
166
# -- Path is the path where metrics are emitted. Must start with a "/".
167
path: /metrics
168
# -- Frequency at which prometheus scrapes metrics
169
interval: 30s
170
# -- Port is the port where metrics are emitted
171
port: 9090
172
# -- How often custom metrics are cleared from memory
173
metricsTTL: ""
174
# -- Flag that instructs prometheus to ignore metric emission errors.
175
ignoreErrors: false
176
# -- Flag that use a self-signed cert for TLS
177
secure: false
178
# -- Container metrics port name
179
portName: metrics
180
# -- Service metrics port
181
servicePort: 8080
182
# -- Service metrics port name
183
servicePortName: metrics
184
# -- serviceMonitor scheme
185
scheme: http
186
# -- Flag to enable headless service
187
headlessService: false
188
# -- When true, honorLabels preserves the metric’s labels when they collide with the target’s labels.
189
## Ref: https://github.com/prometheus-operator/prometheus-operator/blob/main/Documentation/api.md#honorlabels
190
honorLabels: false
191
# -- ServiceMonitor relabel configs to apply to samples before scraping
192
## Ref: https://github.com/prometheus-operator/prometheus-operator/blob/main/Documentation/api.md#relabelconfig
193
relabelings: []
194
# -- ServiceMonitor metric relabel configs to apply to samples before ingestion
195
## Ref: https://github.com/prometheus-operator/prometheus-operator/blob/main/Documentation/api.md#endpoint
196
metricRelabelings: []
197
# -- ServiceMonitor will add labels from the service to the Prometheus metric
198
## Ref: https://github.com/prometheus-operator/prometheus-operator/blob/main/Documentation/api.md#servicemonitorspec
199
targetLabels: []
200
# -- Manipulate the metrics created by the workflow controller
201
## Ref: https://argo-workflows.readthedocs.io/en/latest/metrics/#modifiers
202
modifiers: {}
203
# -- the controller container's securityContext
204
securityContext:
205
readOnlyRootFilesystem: true
206
runAsNonRoot: true
207
allowPrivilegeEscalation: false
208
capabilities:
209
drop:
210
- ALL
211
# -- enable Workflow Archive to store the status of workflows. Postgres, MySQL (>= 5.7.8) and MariaDB (>= 10.2.7, requires Argo Workflows v4.1+) are available.
212
## Ref: https://argo-workflows.readthedocs.io/en/stable/workflow-archive/
213
persistence: {}
214
# connectionPool:
215
# maxIdleConns: 100
216
# maxOpenConns: 0
217
# # save the entire workflow into etcd and DB
218
# nodeStatusOffLoad: false
219
# # enable archiving of old workflows
220
# archive: false
221
# postgresql:
222
# host: localhost
223
# port: 5432
224
# database: postgres
225
# tableName: argo_workflows
226
# # the database secrets must be in the same namespace of the controller
227
# userNameSecret:
228
# name: argo-postgres-config
229
# key: username
230
# passwordSecret:
231
# name: argo-postgres-config
232
# key: password
233
# # Instead of passwordSecret, Postgres can authenticate with a token.
234
# # Requires Argo Workflows v4.1+; userNameSecret is still required.
235
# # Microsoft Entra ID (needs Azure Workload Identity on the controller's service account):
236
# azureToken:
237
# enabled: true
238
# scope: https://ossrdbms-aad.database.windows.net/.default
239
# # AWS RDS IAM authentication (needs IRSA or EKS Pod Identity on the controller's service account):
240
# awsRDSToken:
241
# enabled: true
242
# region: us-east-1
243
# ssl: true
244
# # sslMode must be one of: disable, require, verify-ca, verify-full
245
# # you can find more information about those ssl options here: https://godoc.org/github.com/lib/pq
246
# sslMode: require
247
# mysql:
248
# host: localhost
249
# port: 3306
250
# database: argo
251
# tableName: argo_workflows
252
# userNameSecret:
253
# name: argo-mysql-config
254
# key: username
255
# passwordSecret:
256
# name: argo-mysql-config
257
# key: password
258
259
# -- Default values that will apply to all Workflows from this controller, unless overridden on the Workflow-level.
260
# Only valid for 2.7+
261
## See more: https://argo-workflows.readthedocs.io/en/stable/default-workflow-specs/
262
workflowDefaults: {}
263
# spec:
264
# ttlStrategy:
265
# secondsAfterCompletion: 86400
266
# # Ref: https://argo-workflows.readthedocs.io/en/stable/artifact-repository-ref/
267
# artifactRepositoryRef:
268
# configMap: my-artifact-repository # default is "artifact-repositories"
269
# key: v2-s3-artifact-repository # default can be set by the `workflows.argoproj.io/default-artifact-repository` annotation in config map.
270
271
# -- Number of workflow workers
272
workflowWorkers: # 32
273
# -- Number of workflow TTL workers
274
workflowTTLWorkers: # 4
275
# -- Number of pod cleanup workers
276
podCleanupWorkers: # 4
277
# -- Number of cron workflow workers
278
# Only valid for 3.5+
279
cronWorkflowWorkers: # 8
280
# -- Restricts the Workflows that the controller will process.
281
# Only valid for 2.9+
282
workflowRestrictions: {}
283
# templateReferencing: Strict|Secure
284
285
# telemetryConfig controls the path and port for prometheus telemetry. Telemetry is enabled and emitted in the same endpoint
286
# as metrics by default, but can be overridden using this config.
287
telemetryConfig:
288
# -- Enables prometheus telemetry server
289
enabled: false
290
# -- telemetry path
291
path: /telemetry
292
# -- Frequency at which prometheus scrapes telemetry data
293
interval: 30s
294
# -- telemetry container port
295
port: 8081
296
# -- How often custom metrics are cleared from memory
297
metricsTTL: ""
298
# -- Flag that instructs prometheus to ignore metric emission errors.
299
ignoreErrors: false
300
# -- Flag that use a self-signed cert for TLS
301
secure: false
302
# -- telemetry service port
303
servicePort: 8081
304
# -- telemetry service port name
305
servicePortName: telemetry
306
# -- telemetry serviceMonitor scheme to use
307
scheme: http
308
serviceMonitor:
309
# -- Enable a prometheus ServiceMonitor
310
enabled: false
311
# -- Prometheus ServiceMonitor labels
312
additionalLabels: {}
313
# -- Prometheus ServiceMonitor namespace
314
namespace: "" # "monitoring"
315
serviceAccount:
316
# -- Create a service account for the controller
317
create: true
318
# -- Service account name
319
name: ""
320
# -- Labels applied to created service account
321
labels: {}
322
# -- Annotations applied to created service account
323
annotations: {}
324
# -- Workflow controller name string
325
name: workflow-controller
326
# -- Specify all namespaces where this workflow controller instance will manage
327
# workflows. This controls where the service account and RBAC resources will
328
# be created. Only valid when singleNamespace is false.
329
workflowNamespaces:
330
- default
331
instanceID:
332
# -- Configures the controller to filter workflow submissions
333
# to only those which have a matching instanceID attribute.
334
## NOTE: If `instanceID.enabled` is set to `true` then either `instanceID.userReleaseName`
335
## or `instanceID.explicitID` must be defined.
336
enabled: false
337
# -- Use ReleaseName as instanceID
338
useReleaseName: false
339
# useReleaseName: true
340
341
# -- Use a custom instanceID
342
explicitID: ""
343
# explicitID: unique-argo-controller-identifier
344
logging:
345
# -- Set the logging level (one of: `debug`, `info`, `warn`, `error`)
346
level: info
347
# -- Set the glog logging level
348
globallevel: "0"
349
# -- Set the logging format (one of: `text`, `json`)
350
format: "text"
351
# -- Service type of the controller Service
352
serviceType: ClusterIP
353
# -- Annotations to be applied to the controller Service
354
serviceAnnotations: {}
355
# -- Optional labels to add to the controller Service
356
serviceLabels: {}
357
# -- The class of the load balancer implementation
358
loadBalancerClass: ""
359
# -- Source ranges to allow access to service from. Only applies to service type `LoadBalancer`
360
loadBalancerSourceRanges: []
361
# -- Resource limits and requests for the controller
362
resources: {}
363
# -- Configure liveness [probe] for the controller
364
# @default -- See [values.yaml]
365
livenessProbe:
366
httpGet:
367
port: 6060
368
path: /healthz
369
failureThreshold: 3
370
initialDelaySeconds: 90
371
periodSeconds: 60
372
timeoutSeconds: 30
373
# -- Extra environment variables to provide to the controller container
374
extraEnv: []
375
# - name: FOO
376
# value: "bar"
377
378
# -- envFrom to pass to the controller container
379
envFrom: []
380
# -- Extra arguments to be added to the controller
381
extraArgs: []
382
# -- Additional volume mounts to the controller main container
383
volumeMounts: []
384
# -- Additional volumes to the controller pod
385
volumes: []
386
# -- The number of controller pods to run
387
replicas: 1
388
# -- The number of revisions to keep.
389
revisionHistoryLimit: 10
390
pdb:
391
# -- Configure [Pod Disruption Budget] for the controller pods
392
enabled: false
393
# minAvailable: 1
394
# maxUnavailable: 1
395
# -- [Node selector]
396
nodeSelector:
397
kubernetes.io/os: linux
398
# -- [Tolerations] for use with node taints
399
tolerations: []
400
# -- Assign custom [affinity] rules
401
affinity: {}
402
# -- Assign custom [TopologySpreadConstraints] rules to the workflow controller
403
## Ref: https://kubernetes.io/docs/concepts/workloads/pods/pod-topology-spread-constraints/
404
## If labelSelector is left out, it will default to the labelSelector configuration of the deployment
405
topologySpreadConstraints: []
406
# - maxSkew: 1
407
# topologyKey: topology.kubernetes.io/zone
408
# whenUnsatisfiable: DoNotSchedule
409
410
# -- Leverage a PriorityClass to ensure your pods survive resource shortages.
411
## ref: https://kubernetes.io/docs/concepts/configuration/pod-priority-preemption/
412
priorityClassName: ""
413
# -- Configure Argo Server to show custom [links]
414
## Ref: https://argo-workflows.readthedocs.io/en/stable/links/
415
links: []
416
# -- Configure Argo Server to show custom [columns]
417
## Ref: https://github.com/argoproj/argo-workflows/pull/10693
418
columns: []
419
# -- Set ui navigation bar background color
420
navColor: ""
421
clusterWorkflowTemplates:
422
# -- Create a ClusterRole and CRB for the controller to access ClusterWorkflowTemplates.
423
enabled: true
424
# -- Extra service accounts to be added to the ClusterRoleBinding
425
serviceAccounts: []
426
# - name: my-service-account
427
# namespace: my-namespace
428
# -- Extra containers to be added to the controller deployment
429
extraContainers: []
430
# -- Enables init containers to be added to the controller deployment
431
extraInitContainers: []
432
# -- Workflow retention by number of workflows
433
retentionPolicy: {}
434
# completed: 10
435
# failed: 3
436
# errored: 3
437
438
nodeEvents:
439
# -- Enable to emit events on node completion.
440
## This can take up a lot of space in k8s (typically etcd) resulting in errors when trying to create new events:
441
## "Unable to create audit event: etcdserver: mvcc: database space exceeded"
442
enabled: true
443
workflowEvents:
444
# -- Enable to emit events on workflow status changes.
445
## This can take up a lot of space in k8s (typically etcd), resulting in errors when trying to create new events:
446
## "Unable to create audit event: etcdserver: mvcc: database space exceeded"
447
enabled: true
448
# -- Configure when workflow controller runs in a different k8s cluster with the workflow workloads,
449
# or needs to communicate with the k8s apiserver using an out-of-cluster kubeconfig secret.
450
# @default -- `{}` (See [values.yaml])
451
kubeConfig: {}
452
# # name of the kubeconfig secret, may not be empty when kubeConfig specified
453
# secretName: kubeconfig-secret
454
# # key of the kubeconfig secret, may not be empty when kubeConfig specified
455
# secretKey: kubeconfig
456
# # mounting path of the kubeconfig secret, default to /kube/config
457
# mountPath: /kubeconfig/mount/path
458
# # volume name when mounting the secret, default to kubeconfig
459
# volumeName: kube-config-volume
460
461
# -- Specifies the duration in seconds before a terminating pod is forcefully killed. A zero value indicates that the pod will be forcefully terminated immediately.
462
# @default -- `30` seconds (Kubernetes default)
463
podGCGracePeriodSeconds:
464
# -- The duration in seconds before the pods in the GC queue get deleted. A zero value indicates that the pods will be deleted immediately.
465
# @default -- `5s` (Argo Workflows default)
466
podGCDeleteDelayDuration: ""
467
# -- enable Synchronization to use a database. Postgres and MySQL (>= 5.7.8) are available.
468
## Ref: https://argo-workflows.readthedocs.io/en/latest/workflow-controller-configmap/#syncconfig
469
synchronization: {}
470
# controllerName: argo-workflows
471
# connectionPool:
472
# maxIdleConns: 100
473
# maxOpenConns: 0
474
# postgresql:
475
# host: localhost
476
# port: 5432
477
# database: postgres
478
# tableName: argo_workflows
479
# # the database secrets must be in the same namespace of the controller
480
# userNameSecret:
481
# name: argo-postgres-config
482
# key: username
483
# passwordSecret:
484
# name: argo-postgres-config
485
# key: password
486
# ssl: true
487
# # sslMode must be one of: disable, require, verify-ca, verify-full
488
# # you can find more information about those ssl options here: https://godoc.org/github.com/lib/pq
489
# sslMode: require
490
# mysql:
491
# host: localhost
492
# port: 3306
493
# database: argo
494
# tableName: argo_workflows
495
# userNameSecret:
496
# name: argo-mysql-config
497
# key: username
498
# passwordSecret:
499
# name: argo-mysql-config
500
# key: password
501
502
failedPodRestart:
503
# -- Enable to restart of pods that fail before entering Running state.
504
## This is useful for recovering from transient infrastructure issues like node eviction due to DiskPressure or MemoryPressure without requiring a retryStrategy on every template.
505
## ref: https://argo-workflows.readthedocs.io/en/latest/pod-restarts/
506
enabled: false
507
# -- Maximum number of automatic restarts per node before giving up.
508
maxRestarts: 3
509
# -- Disable the creation of agent pods, which are used for HTTP and Plugin templates. When enabled, HTTP and Plugin templates will not be processed by this controller.
510
# Only valid for 4.1+
511
disableAgentPodCreation: false
512
initlessPod:
513
# -- Enable the init-less pod layout (beta), which provides the executor to workflow pods through an image volume instead of an init container.
514
# Only valid for 4.1+. Requires the `ImageVolume` feature gate on the kube-apiserver and all kubelets (beta in Kubernetes v1.33-1.35, enabled by default from v1.36).
515
## Ref: https://argo-workflows.readthedocs.io/en/latest/initless-pod/
516
enabled: false
517
# mainContainer adds default config for main container that could be overriden in workflows template
518
mainContainer:
519
# -- imagePullPolicy to apply to Workflow main container. Defaults to `.Values.images.pullPolicy`.
520
imagePullPolicy: ""
521
# -- Resource limits and requests for the Workflow main container
522
resources: {}
523
# -- Adds environment variables for the Workflow main container
524
env: []
525
# -- Adds reference environment variables for the Workflow main container
526
envFrom: []
527
# -- sets security context for the Workflow main container
528
securityContext: {}
529
# executor controls how the init and wait container should be customized
530
executor:
531
image:
532
# -- Registry to use for the Workflow Executors
533
registry: cgr.dev
534
# -- Repository to use for the Workflow Executors
535
repository: chainguard-private/argo-exec
536
# -- Image tag for the workflow executor. Defaults to `.Values.images.tag`.
537
tag: 4.1.4-r0@sha256:7f66db0c84b668f3be71ba4cc9d12a11ee43b181fd714dec9fdeb3cab0d0cb45
538
# -- Image PullPolicy to use for the Workflow Executors. Defaults to `.Values.images.pullPolicy`.
539
pullPolicy: ""
540
# -- Use the `-nonroot` executor image variant. When enabled, the `-nonroot` suffix is appended to the resolved image tag.
541
nonroot: false
542
# -- Resource limits and requests for the Workflow Executors
543
resources: {}
544
# -- Passes arguments to the executor processes
545
args: []
546
# -- Adds environment variables for the executor.
547
env: []
548
# -- sets security context for the executor container
549
securityContext: {}
550
server:
551
# -- Deploy the Argo Server
552
enabled: true
553
# -- Value for base href in index.html. Used if the server is running behind reverse proxy under subpath different from /.
554
## only updates base url of resources on client side,
555
## it's expected that a proxy server rewrites the request URL and gets rid of this prefix
556
## https://github.com/argoproj/argo-workflows/issues/716#issuecomment-433213190
557
baseHref: /
558
image:
559
# -- Registry to use for the server
560
registry: cgr.dev
561
# -- Repository to use for the server
562
repository: chainguard-private/argo-cli
563
# -- Image tag for the Argo Workflows server. Defaults to `.Values.images.tag`.
564
tag: 4.1.4-r0@sha256:7c1438ae5b28158ad7f3904f46aae982733af3ce6f63a10094c8a04d91eb20b1
565
# -- optional map of annotations to be applied to the ui Deployment
566
deploymentAnnotations: {}
567
# -- optional map of annotations to be applied to the ui Pods
568
podAnnotations: {}
569
# -- Optional labels to add to the UI pods
570
podLabels: {}
571
# -- SecurityContext to set on the server pods
572
podSecurityContext: {}
573
rbac:
574
# -- Adds Role and RoleBinding for the server.
575
create: true
576
# -- Servers container-level security context
577
securityContext:
578
readOnlyRootFilesystem: false
579
runAsNonRoot: true
580
allowPrivilegeEscalation: false
581
capabilities:
582
drop:
583
- ALL
584
# -- Server name string
585
name: server
586
# -- Service type for server pods
587
serviceType: ClusterIP
588
# -- Service port for server
589
servicePort: 2746
590
# -- Service target port for server
591
serviceTargetPort: 2746
592
# -- Service node port
593
serviceNodePort: # 32746
594
# -- Service port name
595
servicePortName: "" # http
596
# -- Mapping between IP and hostnames that will be injected as entries in the pod's hosts files
597
hostAliases: []
598
# - ip: 10.20.30.40
599
# hostnames:
600
# - git.myhostname
601
602
serviceAccount:
603
# -- Create a service account for the server
604
create: true
605
# -- Service account name
606
name: ""
607
# -- Labels applied to created service account
608
labels: {}
609
# -- Annotations applied to created service account
610
annotations: {}
611
# -- Annotations to be applied to the UI Service
612
serviceAnnotations: {}
613
# -- Optional labels to add to the UI Service
614
serviceLabels: {}
615
# -- The class of the load balancer implementation
616
loadBalancerClass: ""
617
# -- Static IP address to assign to loadBalancer service type `LoadBalancer`
618
loadBalancerIP: ""
619
# -- Source ranges to allow access to service from. Only applies to service type `LoadBalancer`
620
loadBalancerSourceRanges: []
621
# -- Resource limits and requests for the server
622
resources: {}
623
# -- The number of server pods to run
624
replicas: 1
625
# -- The number of revisions to keep.
626
revisionHistoryLimit: 10
627
## Argo Server Horizontal Pod Autoscaler
628
autoscaling:
629
# -- Enable Horizontal Pod Autoscaler ([HPA]) for the Argo Server
630
enabled: false
631
# -- Minimum number of replicas for the Argo Server [HPA]
632
minReplicas: 1
633
# -- Maximum number of replicas for the Argo Server [HPA]
634
maxReplicas: 5
635
# -- Average CPU utilization percentage for the Argo Server [HPA]
636
targetCPUUtilizationPercentage: 50
637
# -- Average memory utilization percentage for the Argo Server [HPA]
638
targetMemoryUtilizationPercentage: 50
639
# -- Configures the scaling behavior of the target in both Up and Down directions.
640
# This is only available on HPA apiVersion `autoscaling/v2beta2` and newer
641
behavior: {}
642
# scaleDown:
643
# stabilizationWindowSeconds: 300
644
# policies:
645
# - type: Pods
646
# value: 1
647
# periodSeconds: 180
648
# scaleUp:
649
# stabilizationWindowSeconds: 300
650
# policies:
651
# - type: Pods
652
# value: 2
653
pdb:
654
# -- Configure [Pod Disruption Budget] for the server pods
655
enabled: false
656
# minAvailable: 1
657
# maxUnavailable: 1
658
# -- [Node selector]
659
nodeSelector:
660
kubernetes.io/os: linux
661
# -- [Tolerations] for use with node taints
662
tolerations: []
663
# -- Assign custom [affinity] rules
664
affinity: {}
665
# -- Assign custom [TopologySpreadConstraints] rules to the argo server
666
## Ref: https://kubernetes.io/docs/concepts/workloads/pods/pod-topology-spread-constraints/
667
## If labelSelector is left out, it will default to the labelSelector configuration of the deployment
668
topologySpreadConstraints: []
669
# - maxSkew: 1
670
# topologyKey: topology.kubernetes.io/zone
671
# whenUnsatisfiable: DoNotSchedule
672
673
# -- Leverage a PriorityClass to ensure your pods survive resource shortages
674
## ref: https://kubernetes.io/docs/concepts/configuration/pod-priority-preemption/
675
priorityClassName: ""
676
# -- Run the argo server in "secure" mode. Configure this value instead of `--secure` in extraArgs.
677
## See the following documentation for more details on secure mode:
678
## https://argo-workflows.readthedocs.io/en/stable/tls/
679
secure: false
680
# -- Extra environment variables to provide to the argo-server container
681
extraEnv: []
682
# - name: FOO
683
# value: "bar"
684
685
# -- envFrom to pass to the argo-server container
686
envFrom: []
687
# -- Deprecated; use server.authModes instead.
688
authMode: ""
689
# -- A list of supported authentication modes. Available values are `server`, `client`, or `sso`. If you provide sso, please configure `.Values.server.sso` as well.
690
## Ref: https://argo-workflows.readthedocs.io/en/stable/argo-server-auth-mode/
691
authModes: []
692
# -- Extra arguments to provide to the Argo server binary.
693
## Ref: https://argo-workflows.readthedocs.io/en/stable/argo-server/#options
694
extraArgs: []
695
logging:
696
# -- Set the logging level (one of: `debug`, `info`, `warn`, `error`)
697
level: info
698
# -- Set the glog logging level
699
globallevel: "0"
700
# -- Set the logging format (one of: `text`, `json`)
701
format: "text"
702
# -- Volume to be mounted in Pods for temporary files.
703
tmpVolume:
704
emptyDir: {}
705
# -- Additional volume mounts to the server main container.
706
volumeMounts: []
707
# -- Additional volumes to the server pod.
708
volumes: []
709
## Ingress configuration.
710
# ref: https://kubernetes.io/docs/concepts/services-networking/ingress/
711
ingress:
712
# -- Enable an ingress resource
713
enabled: false
714
# -- Additional ingress annotations
715
annotations: {}
716
# -- Additional ingress labels
717
labels: {}
718
# -- Defines which ingress controller will implement the resource
719
ingressClassName: ""
720
# -- List of ingress hosts
721
## Hostnames must be provided if Ingress is enabled.
722
## Secrets must be manually created in the namespace
723
hosts: []
724
# - argoworkflows.example.com
725
726
# -- List of ingress paths
727
paths:
728
- /
729
# -- Ingress path type. One of `Exact`, `Prefix` or `ImplementationSpecific`
730
pathType: Prefix
731
# -- Additional ingress paths
732
extraPaths: []
733
# - path: /*
734
# backend:
735
# serviceName: ssl-redirect
736
# servicePort: use-annotation
737
## for Kubernetes >=1.19 (when "networking.k8s.io/v1" is used)
738
# - path: /*
739
# pathType: Prefix
740
# backend:
741
# service
742
# name: ssl-redirect
743
# port:
744
# name: use-annotation
745
746
# -- Ingress TLS configuration
747
tls: []
748
# - secretName: argoworkflows-example-tls
749
# hosts:
750
# - argoworkflows.example.com
751
## Create a Google Backendconfig for use with the GKE Ingress Controller
752
## https://cloud.google.com/kubernetes-engine/docs/how-to/ingress-configuration#configuring_ingress_features_through_backendconfig_parameters
753
GKEbackendConfig:
754
# -- Enable BackendConfig custom resource for Google Kubernetes Engine
755
enabled: false
756
# -- [BackendConfigSpec]
757
spec: {}
758
# spec:
759
# iap:
760
# enabled: true
761
# oauthclientCredentials:
762
# secretName: argoworkflows-secret
763
764
## Create a Google Managed Certificate for use with the GKE Ingress Controller
765
## https://cloud.google.com/kubernetes-engine/docs/how-to/managed-certs
766
GKEmanagedCertificate:
767
# -- Enable ManagedCertificate custom resource for Google Kubernetes Engine.
768
enabled: false
769
# -- Domains for the Google Managed Certificate
770
domains:
771
- argoworkflows.example.com
772
## Create a Google FrontendConfig Custom Resource, for use with the GKE Ingress Controller
773
## https://cloud.google.com/kubernetes-engine/docs/how-to/ingress-features#configuring_ingress_features_through_frontendconfig_parameters
774
GKEfrontendConfig:
775
# -- Enable FrontConfig custom resource for Google Kubernetes Engine
776
enabled: false
777
# -- [FrontendConfigSpec]
778
spec: {}
779
# spec:
780
# redirectToHttps:
781
# enabled: true
782
# responseCodeName: RESPONSE_CODE
783
784
# Gateway API HTTPRoute configuration
785
# NOTE: Gateway API support is in EXPERIMENTAL status
786
# Support depends on your Gateway controller implementation
787
# Some controllers may require additional configuration (e.g., BackendTLSPolicy for HTTPS backends)
788
# Refer to https://gateway-api.sigs.k8s.io/implementations/ for controller-specific details
789
httproute:
790
# -- Enable HTTPRoute resource for Argo Workflows server (Gateway API)
791
enabled: false
792
# -- Additional HTTPRoute labels
793
labels: {}
794
# -- Additional HTTPRoute annotations
795
annotations: {}
796
# -- Gateway API parentRefs for the HTTPRoute
797
## Must reference an existing Gateway
798
# @default -- `[]` (See [values.yaml])
799
parentRefs: []
800
# - name: example-gateway
801
# namespace: example-gateway-namespace
802
# sectionName: https
803
# -- List of hostnames for the HTTPRoute
804
# @default -- `[]` (See [values.yaml])
805
hostnames: []
806
# - argoworkflows.example.com
807
# -- HTTPRoute rules configuration
808
# @default -- `[]` (See [values.yaml])
809
rules:
810
- matches:
811
- path:
812
type: PathPrefix
813
value: /
814
# filters: []
815
# - type: RequestHeaderModifier
816
# requestHeaderModifier:
817
# add:
818
# - name: X-Custom-Header
819
# value: custom-value
820
# timeouts:
821
# request: 10s
822
# backendRequest: 2s
823
# Gateway API BackendTLSPolicy configuration
824
# NOTE: BackendTLSPolicy support is in EXPERIMENTAL status
825
# Required for HTTPS backends when using Gateway API
826
# Not all Gateway controllers support this resource (e.g., Cilium does not support it yet)
827
backendTLSPolicy:
828
# -- Enable BackendTLSPolicy resource for Argo Workflows server (Gateway API)
829
enabled: false
830
# -- Additional BackendTLSPolicy labels
831
labels: {}
832
# -- Additional BackendTLSPolicy annotations
833
annotations: {}
834
# -- Target references for the BackendTLSPolicy
835
# @default -- `[]` (See [values.yaml])
836
targetRefs: []
837
# - group: ""
838
# kind: Service
839
# name: argo-workflows-server
840
# sectionName: https
841
# -- TLS validation configuration
842
# @default -- `{}` (See [values.yaml])
843
validation: {}
844
# hostname: argo-workflows-server.argo.svc.cluster.local
845
# caCertificateRefs:
846
# - name: example-ca-cert
847
# group: ""
848
# kind: ConfigMap
849
# wellKnownCACertificates: System
850
clusterWorkflowTemplates:
851
# -- Create a ClusterRole and CRB for the server to access ClusterWorkflowTemplates.
852
enabled: true
853
# -- Give the server permissions to edit ClusterWorkflowTemplates.
854
enableEditing: true
855
# SSO configuration when SSO is specified as a server auth mode.
856
sso:
857
# -- Create SSO configuration. If you set `true` , please also set `.Values.server.authModes` as `sso`.
858
enabled: false
859
# -- The root URL of the OIDC identity provider
860
issuer: https://accounts.google.com
861
clientId:
862
# -- Name of secret to retrieve the app OIDC client ID
863
name: argo-server-sso
864
# -- Key of secret to retrieve the app OIDC client ID
865
key: client-id
866
clientSecret:
867
# -- Name of a secret to retrieve the app OIDC client secret
868
name: argo-server-sso
869
# -- Key of a secret to retrieve the app OIDC client secret
870
key: client-secret
871
# -- The OIDC redirect URL. Should be in the form <argo-root-url>/oauth2/callback.
872
redirectUrl: ""
873
rbac:
874
# -- Adds ServiceAccount Policy to server (Cluster)Role.
875
enabled: true
876
# -- Whitelist to allow server to fetch Secrets
877
## When present, restricts secrets the server can read to a given list.
878
## You can use it to restrict the server to only be able to access the
879
## service account token secrets that are associated with service accounts
880
## used for authorization.
881
secretWhitelist: []
882
# -- Scopes requested from the SSO ID provider
883
## The 'groups' scope requests group membership information, which is usually used for authorization decisions.
884
scopes: []
885
# - groups
886
# -- Define how long your login is valid for (in hours)
887
## If omitted, defaults to 10h.
888
sessionExpiry: ""
889
# -- Alternate root URLs that can be included for some OIDC providers
890
issuerAlias: ""
891
# -- Override claim name for OIDC groups
892
customGroupClaimName: ""
893
# -- Specify the user info endpoint that contains the groups claim
894
## Configure this if your OIDC provider provides groups information only using the user-info endpoint (e.g. Okta)
895
userInfoPath: ""
896
# -- Skip TLS verification for the HTTP client
897
insecureSkipVerify: false
898
# -- Custom PEM encoded CA certificate file contents used to validate the OIDC provider's certificate
899
rootCA: ""
900
# -- Filter the groups returned by the OIDC provider
901
## A logical "OR" is used between each regex in the list
902
filterGroupsRegex: []
903
# - ".*argo-wf.*"
904
# - ".*argo-workflow.*"
905
# -- Extra containers to be added to the server deployment
906
extraContainers: []
907
# -- Enables init containers to be added to the server deployment
908
extraInitContainers: []
909
# -- Specify postStart and preStop lifecycle hooks for server container
910
lifecycle: {}
911
# -- terminationGracePeriodSeconds for container lifecycle hook
912
terminationGracePeriodSeconds: 30
913
## livenessProbe for server
914
## Ref: https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-startup-probes/
915
livenessProbe:
916
# -- Enable Kubernetes liveness probe for server
917
enabled: false
918
httpGet:
919
# -- Http port to use for the liveness probe
920
port: 2746
921
# -- Http path to use for the liveness probe
922
path: /
923
# -- Minimum consecutive failures for the [probe] to be considered failed after having succeeded
924
failureThreshold: 3
925
# -- Number of seconds after the container has started before [probe] is initiated
926
initialDelaySeconds: 10
927
# -- How often (in seconds) to perform the [probe]
928
periodSeconds: 10
929
# -- Number of seconds after which the [probe] times out
930
timeoutSeconds: 1
931
# -- Minimum consecutive successes for the [probe] to be considered successful after having failed
932
successThreshold: 1
933
# -- Array of extra K8s manifests to deploy
934
extraObjects: []
935
# - apiVersion: secrets-store.csi.x-k8s.io/v1
936
# kind: SecretProviderClass
937
# metadata:
938
# name: argo-server-sso
939
# spec:
940
# provider: aws
941
# parameters:
942
# objects: |
943
# - objectName: "argo/server/sso"
944
# objectType: "secretsmanager"
945
# jmesPath:
946
# - path: "client_id"
947
# objectAlias: "client_id"
948
# - path: "client_secret"
949
# objectAlias: "client_secret"
950
# secretObjects:
951
# - data:
952
# - key: client_id
953
# objectName: client_id
954
# - key: client_secret
955
# objectName: client_secret
956
# secretName: argo-server-sso-secrets-store
957
# type: Opaque
958
959
# -- Use static credentials for S3 (eg. when not using AWS IRSA)
960
useStaticCredentials: true
961
artifactRepository:
962
# -- Archive the main container logs as an artifact
963
archiveLogs: false
964
# -- Store artifact in a S3-compliant object store
965
# @default -- See [values.yaml]
966
s3: {}
967
# # Note the `key` attribute is not the actual secret, it's the PATH to
968
# # the contents in the associated secret, as defined by the `name` attribute.
969
# accessKeySecret:
970
# name: "{{ .Release.Name }}-minio"
971
# key: accesskey
972
# secretKeySecret:
973
# name: "{{ .Release.Name }}-minio"
974
# key: secretkey
975
# sessionTokenSecret:
976
# name: "{{ .Release.Name }}-minio"
977
# key: sessionToken
978
# # insecure will disable TLS. Primarily used for minio installs not configured with TLS
979
# insecure: false
980
# caSecret:
981
# name: ca-root
982
# key: cert.pem
983
# bucket:
984
# endpoint:
985
# region:
986
# roleARN:
987
# useSDKCreds: true
988
# # addressingStyle must be one of: "" (auto-detect), path, virtual-hosted
989
# # Only valid for 4.1+
990
# addressingStyle: ""
991
# encryptionOptions:
992
# enableEncryption: true
993
# -- Store artifact in a GCS object store
994
# @default -- `{}` (See [values.yaml])
995
gcs: {}
996
# bucket: <project>-argo
997
# keyFormat: "{{ \"{{workflow.namespace}}/{{workflow.name}}/{{pod.name}}\" }}"
998
# # serviceAccountKeySecret is a secret selector.
999
# # It references the k8s secret named 'my-gcs-credentials'.
1000
# # This secret is expected to have the key 'serviceAccountKey',
1001
# # containing the base64 encoded credentials
1002
# # to the bucket.
1003
# #
1004
# # If it's running on GKE and Workload Identity is used,
1005
# # serviceAccountKeySecret is not needed.
1006
# serviceAccountKeySecret:
1007
# name: my-gcs-credentials
1008
# key: serviceAccountKey
1009
# -- Store artifact in Azure Blob Storage
1010
# @default -- `{}` (See [values.yaml])
1011
azure: {}
1012
# endpoint: https://mystorageaccountname.blob.core.windows.net
1013
# container: my-container-name
1014
# blobNameFormat: path/in/container
1015
# # accountKeySecret is a secret selector.
1016
# # It references the k8s secret named 'my-azure-storage-credentials'.
1017
# # This secret is expected to have the key 'account-access-key',
1018
# # containing the base64 encoded credentials to the storage account.
1019
# # If a managed identity has been assigned to the machines running the
1020
# # workflow (e.g., https://docs.microsoft.com/en-us/azure/aks/use-managed-identity)
1021
# # then accountKeySecret is not needed, and useSDKCreds should be
1022
# # set to true instead:
1023
# useSDKCreds: true
1024
# accountKeySecret:
1025
# name: my-azure-storage-credentials
1026
# key: account-access-key
1027
# -- The section of custom artifact repository.
1028
# Utilize a custom artifact repository that is not one of the current base ones (s3, gcs, azure)
1029
customArtifactRepository: {}
1030
# artifactory:
1031
# repoUrl: https://artifactory.example.com/raw
1032
# usernameSecret:
1033
# name: artifactory-creds
1034
# key: username
1035
# passwordSecret:
1036
# name: artifactory-creds
1037
# key: password
1038
1039
# -- The section of [artifact repository ref](https://argo-workflows.readthedocs.io/en/stable/artifact-repository-ref/).
1040
# Each map key is the name of configmap
1041
# @default -- `{}` (See [values.yaml])
1042
artifactRepositoryRef: {}
1043
# # -- 1st ConfigMap
1044
# # If you want to use this config map by default, name it "artifact-repositories".
1045
# # Otherwise, you can provide a reference to a
1046
# # different config map in `artifactRepositoryRef.configMap`.
1047
# artifact-repositories:
1048
# # -- v3.0 and after - if you want to use a specific key, put that key into this annotation.
1049
# annotations:
1050
# workflows.argoproj.io/default-artifact-repository: default-v1-s3-artifact-repository
1051
# # 1st data of configmap. See above artifactRepository or customArtifactRepository.
1052
# default-v1-s3-artifact-repository:
1053
# archiveLogs: false
1054
# s3:
1055
# bucket: my-bucket
1056
# endpoint: minio:9000
1057
# insecure: true
1058
# accessKeySecret:
1059
# name: my-minio-cred
1060
# key: accesskey
1061
# secretKeySecret:
1062
# name: my-minio-cred
1063
# key: secretkey
1064
# # 2nd data
1065
# oss-artifact-repository:
1066
# archiveLogs: false
1067
# oss:
1068
# endpoint: http://oss-cn-zhangjiakou-internal.aliyuncs.com
1069
# bucket: $mybucket
1070
# # accessKeySecret and secretKeySecret are secret selectors.
1071
# # It references the k8s secret named 'bucket-workflow-artifect-credentials'.
1072
# # This secret is expected to have the keys 'accessKey'
1073
# # and 'secretKey', containing the base64 encoded credentials
1074
# # to the bucket.
1075
# accessKeySecret:
1076
# name: $mybucket-credentials
1077
# key: accessKey
1078
# secretKeySecret:
1079
# name: $mybucket-credentials
1080
# key: secretKey
1081
# # 2nd ConfigMap
1082
# another-artifact-repositories:
1083
# annotations:
1084
# workflows.argoproj.io/default-artifact-repository: gcs
1085
# gcs:
1086
# bucket: my-bucket
1087
# keyFormat: prefix/in/bucket/{{workflow.name}}/{{pod.name}}
1088
# serviceAccountKeySecret:
1089
# name: my-gcs-credentials
1090
# key: serviceAccountKey
1091
1092
emissary:
1093
# -- The command/args for each image on workflow, needed when the command is not specified and the emissary executor is used.
1094
## See more: https://argo-workflows.readthedocs.io/en/stable/workflow-executors/#emissary-emissary
1095
images: []
1096
# argoproj/argosay:v2:
1097
# cmd: [/argosay]
1098
# docker/whalesay:latest:
1099
# cmd: [/bin/bash]
1100

The trusted source for open source

Talk to an expert
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsChainguard OS PackagesChainguard ActionsChainguard Agent SkillsIntegrationsPricing
© 2026 Chainguard, Inc. All Rights Reserved.
Chainguard® and the Chainguard logo are registered trademarks of Chainguard, Inc. in the United States and/or other countries.
The other respective trademarks mentioned on this page are owned by the respective companies and use of them does not imply any affiliation or endorsement.