1# Default values for dragonfly-operator.
2# This is a YAML-formatted file.
3# Declare variables to be passed into your templates.
6## Custom resource configuration
8 # -- Install and upgrade CRDs
10 # -- Keep CRDs on chart uninstall
15# -- Default dragonfly image to use
16dragonflyImage: cgr.dev/chainguard-private/dragonfly:2.0.0-r1@sha256:b0c56344b2613ba0d3cd144514cdce59c76a585a066492428f6fa1eb0a86fbbe
17# -- Additional labels to add to all resources
19# app: dragonfly-operator
21# -- Create aggregated cluster roles for view, edit, and admin
22createAggregateRoles: true
23# -- Restrict the operator to specific namespaces (comma-separated, e.g. "ns1,ns2").
24# When set, namespace-scoped Roles are created in each watched namespace instead of a
25# cluster-wide ClusterRole, allowing deployment without ClusterRole permissions.
26# Leave empty to watch all namespaces (default; requires ClusterRole).
27# To fully avoid ClusterRoles, also set rbacProxy.enabled=false and createAggregateRoles=false.
30 # Specifies whether a service account should be created
32 # Automatically mount a ServiceAccount's API credentials?
34 # Annotations to add to the service account
36 # The name of the service account to use.
37 # If not set and create is true, a name is generated using the fullname template
38 name: dragonfly-operator-controller-manager
40 kubectl.kubernetes.io/default-container: manager
42# Additional annotations to add to deployments
43deploymentAnnotations: {}
44# Additional labels to add to deployments
49 # Annotations to add to the operator Service
54terminationGracePeriodSeconds: 10
58 repository: cgr.dev/chainguard-private/kube-rbac-proxy
59 pullPolicy: IfNotPresent
60 # Overrides the image tag whose default is the chart appVersion.
61 tag: 0.23.0-r0@sha256:6b81442e7d6810548030473a81c8befb52954a7ec8a40a377e1865195f164834
71 allowPrivilegeEscalation: false
77 repository: cgr.dev/chainguard-private/dragonfly-operator
78 pullPolicy: IfNotPresent
79 # Overrides the image tag whose default is the chart appVersion.
80 tag: 1.7.0-r0@sha256:dc6067e41441e5352a42ba674252c213d411bfaba231ac1cac3ef301e485abdf
94 initialDelaySeconds: 15
100 initialDelaySeconds: 5
103 allowPrivilegeEscalation: false
107 # -- Priority class name for the operator pod
108 priorityClassName: ""
111 # -- Assign custom [TopologySpreadConstraints] rules to the application controller
112 # @default -- `[]` (defaults to global.topologySpreadConstraints)
113 ## Ref: https://kubernetes.io/docs/concepts/workloads/pods/pod-topology-spread-constraints/
114 ## If labelSelector is left out, it will default to the labelSelector configuration of the deployment
115 topologySpreadConstraints: []
117 # topologyKey: topology.kubernetes.io/zone
118 # whenUnsatisfiable: DoNotSchedule
121# requiredDuringSchedulingIgnoredDuringExecution:
124# - key: kubernetes.io/arch
131# - key: kubernetes.io/os
136# -- A [PodDisruptionBudget] for the operator pod, useful when running more
137# than one replica (replicaCount > 1) so voluntary disruptions (e.g. node
138# drains) keep at least one operator pod available.
139## Ref: https://kubernetes.io/docs/tasks/run-application/configure-pdb/
141 # When set true a PodDisruptionBudget is created for the operator pod
143 # minAvailable and maxUnavailable are mutually exclusive; minAvailable takes
144 # precedence when both are set. Each may be an integer or a percentage string.
147 # unhealthyPodEvictionPolicy controls how unhealthy pods are counted (requires
148 # Kubernetes 1.27+). Leave empty to use the cluster default (IfHealthyBudget).
149 unhealthyPodEvictionPolicy: ""
151 # When set true then use a ServiceMonitor to configure scraping
153 # Set how frequently Prometheus should scrape
155 # Set path to cloudwatch-exporter telemtery-path
157 # Set labels for the ServiceMonitor, use this to define your scrape label for Prometheus Operator
159 # Set timeout for scrape
161 # Set relabelings for the ServiceMonitor, use to apply to samples before scraping
163 # Set metricRelabelings for the ServiceMonitor, use to apply to samples for ingestion
164 metricRelabelings: []
165 # Example - note the Kubernetes convention of camelCase instead of Prometheus' snake_case
167 # - sourceLabels: [dbinstance_identifier]
169 # replacement: mydbname
170 # targetLabel: dbname
172 # When rbacProxy is enabled, a ClusterRoleBinding is needed to grant the
173 # Prometheus service account access to the /metrics endpoint via kube-rbac-proxy.
174 rbacProxyMetricsReader:
175 # -- Create a ClusterRoleBinding for the Prometheus service account
177 # -- Name of the Prometheus ServiceAccount
178 serviceAccountName: ""
179 # -- Namespace of the Prometheus ServiceAccount
180 serviceAccountNamespace: ""
184 # -- Grafana dashboard configmap annotations.
187 # -- Grafana dashboard configmap labels
189 name: grafana_dashboard
192 allowCrossNamespaceImport: true
193 # -- Selected labels for Grafana instance