DirectorySecurity AdvisoriesPricing
Sign in
Directory
dragonfly-operator logoHELM

dragonfly-operator

Helm chart
Last changed
Request a free trial

Contact our team to test out this Helm chart and related images for free. Please also indicate any other images you would like to evaluate.

Overview
Chart versions
Default values
Chart metadata
Images

Tag:
Compare:

1
# Default values for dragonfly-operator.
2
# This is a YAML-formatted file.
3
# Declare variables to be passed into your templates.
4
5
replicaCount: 1
6
## Custom resource configuration
7
crds:
8
# -- Install and upgrade CRDs
9
install: true
10
# -- Keep CRDs on chart uninstall
11
keep: true
12
nameOverride: ""
13
fullnameOverride: ""
14
namespaceOverride: ""
15
# -- Default dragonfly image to use
16
dragonflyImage: cgr.dev/chainguard-private/dragonfly:2.0.0-r1@sha256:b0c56344b2613ba0d3cd144514cdce59c76a585a066492428f6fa1eb0a86fbbe
17
# -- Additional labels to add to all resources
18
additionalLabels: {}
19
# app: dragonfly-operator
20
21
# -- Create aggregated cluster roles for view, edit, and admin
22
createAggregateRoles: true
23
# -- Restrict the operator to specific namespaces (comma-separated, e.g. "ns1,ns2").
24
# When set, namespace-scoped Roles are created in each watched namespace instead of a
25
# cluster-wide ClusterRole, allowing deployment without ClusterRole permissions.
26
# Leave empty to watch all namespaces (default; requires ClusterRole).
27
# To fully avoid ClusterRoles, also set rbacProxy.enabled=false and createAggregateRoles=false.
28
watchNamespaces: ""
29
serviceAccount:
30
# Specifies whether a service account should be created
31
create: true
32
# Automatically mount a ServiceAccount's API credentials?
33
automount: true
34
# Annotations to add to the service account
35
annotations: {}
36
# The name of the service account to use.
37
# If not set and create is true, a name is generated using the fullname template
38
name: dragonfly-operator-controller-manager
39
podAnnotations:
40
kubectl.kubernetes.io/default-container: manager
41
podLabels: {}
42
# Additional annotations to add to deployments
43
deploymentAnnotations: {}
44
# Additional labels to add to deployments
45
deploymentLabels: {}
46
podSecurityContext:
47
runAsNonRoot: true
48
service:
49
# Annotations to add to the operator Service
50
annotations: {}
51
type: ClusterIP
52
port: 8443
53
metricsPort: 8080
54
terminationGracePeriodSeconds: 10
55
rbacProxy:
56
enabled: true
57
image:
58
repository: cgr.dev/chainguard-private/kube-rbac-proxy
59
pullPolicy: IfNotPresent
60
# Overrides the image tag whose default is the chart appVersion.
61
tag: 0.23.0-r0@sha256:6b81442e7d6810548030473a81c8befb52954a7ec8a40a377e1865195f164834
62
extraArgs: {}
63
resources:
64
limits:
65
cpu: 500m
66
memory: 128Mi
67
requests:
68
cpu: 10m
69
memory: 64Mi
70
securityContext:
71
allowPrivilegeEscalation: false
72
capabilities:
73
drop:
74
- ALL
75
manager:
76
image:
77
repository: cgr.dev/chainguard-private/dragonfly-operator
78
pullPolicy: IfNotPresent
79
# Overrides the image tag whose default is the chart appVersion.
80
tag: 1.7.0-r0@sha256:dc6067e41441e5352a42ba674252c213d411bfaba231ac1cac3ef301e485abdf
81
extraArgs: {}
82
resources: {}
83
# limits:
84
# cpu: 500m
85
# memory: 128Mi
86
# requests:
87
# cpu: 10m
88
# memory: 64Mi
89
90
livenessProbe:
91
httpGet:
92
path: /healthz
93
port: 8081
94
initialDelaySeconds: 15
95
periodSeconds: 20
96
readinessProbe:
97
httpGet:
98
path: /readyz
99
port: 8081
100
initialDelaySeconds: 5
101
periodSeconds: 10
102
securityContext:
103
allowPrivilegeEscalation: false
104
capabilities:
105
drop:
106
- ALL
107
# -- Priority class name for the operator pod
108
priorityClassName: ""
109
nodeSelector: {}
110
tolerations: []
111
# -- Assign custom [TopologySpreadConstraints] rules to the application controller
112
# @default -- `[]` (defaults to global.topologySpreadConstraints)
113
## Ref: https://kubernetes.io/docs/concepts/workloads/pods/pod-topology-spread-constraints/
114
## If labelSelector is left out, it will default to the labelSelector configuration of the deployment
115
topologySpreadConstraints: []
116
# - maxSkew: 1
117
# topologyKey: topology.kubernetes.io/zone
118
# whenUnsatisfiable: DoNotSchedule
119
affinity: {}
120
# nodeAffinity:
121
# requiredDuringSchedulingIgnoredDuringExecution:
122
# nodeSelectorTerms:
123
# - matchExpressions:
124
# - key: kubernetes.io/arch
125
# operator: In
126
# values:
127
# - amd64
128
# - arm64
129
# - ppc64le
130
# - s390x
131
# - key: kubernetes.io/os
132
# operator: In
133
# values:
134
# - linux
135
136
# -- A [PodDisruptionBudget] for the operator pod, useful when running more
137
# than one replica (replicaCount > 1) so voluntary disruptions (e.g. node
138
# drains) keep at least one operator pod available.
139
## Ref: https://kubernetes.io/docs/tasks/run-application/configure-pdb/
140
podDisruptionBudget:
141
# When set true a PodDisruptionBudget is created for the operator pod
142
enabled: false
143
# minAvailable and maxUnavailable are mutually exclusive; minAvailable takes
144
# precedence when both are set. Each may be an integer or a percentage string.
145
minAvailable: 1
146
maxUnavailable: ""
147
# unhealthyPodEvictionPolicy controls how unhealthy pods are counted (requires
148
# Kubernetes 1.27+). Leave empty to use the cluster default (IfHealthyBudget).
149
unhealthyPodEvictionPolicy: ""
150
serviceMonitor:
151
# When set true then use a ServiceMonitor to configure scraping
152
enabled: false
153
# Set how frequently Prometheus should scrape
154
interval: 30s
155
# Set path to cloudwatch-exporter telemtery-path
156
path: /metrics
157
# Set labels for the ServiceMonitor, use this to define your scrape label for Prometheus Operator
158
labels: {}
159
# Set timeout for scrape
160
timeout: 10s
161
# Set relabelings for the ServiceMonitor, use to apply to samples before scraping
162
relabelings: []
163
# Set metricRelabelings for the ServiceMonitor, use to apply to samples for ingestion
164
metricRelabelings: []
165
# Example - note the Kubernetes convention of camelCase instead of Prometheus' snake_case
166
# metricRelabelings:
167
# - sourceLabels: [dbinstance_identifier]
168
# action: replace
169
# replacement: mydbname
170
# targetLabel: dbname
171
172
# When rbacProxy is enabled, a ClusterRoleBinding is needed to grant the
173
# Prometheus service account access to the /metrics endpoint via kube-rbac-proxy.
174
rbacProxyMetricsReader:
175
# -- Create a ClusterRoleBinding for the Prometheus service account
176
create: false
177
# -- Name of the Prometheus ServiceAccount
178
serviceAccountName: ""
179
# -- Namespace of the Prometheus ServiceAccount
180
serviceAccountNamespace: ""
181
grafanaDashboard:
182
enabled: false
183
folder: database
184
# -- Grafana dashboard configmap annotations.
185
annotations:
186
name: grafana_folder
187
# -- Grafana dashboard configmap labels
188
labels:
189
name: grafana_dashboard
190
grafanaOperator:
191
enabled: false
192
allowCrossNamespaceImport: true
193
# -- Selected labels for Grafana instance
194
matchLabels: {}
195

The trusted source for open source

Talk to an expert
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsChainguard OS PackagesChainguard ActionsChainguard Agent SkillsIntegrationsPricing
© 2026 Chainguard, Inc. All Rights Reserved.
Chainguard® and the Chainguard logo are registered trademarks of Chainguard, Inc. in the United States and/or other countries.
The other respective trademarks mentioned on this page are owned by the respective companies and use of them does not imply any affiliation or endorsement.