1# Default values for jenkins.
2# This is a YAML-formatted file.
3# Declare name/value pairs to be passed into your templates.
6## Overrides for generated resource names
7# See templates/_helpers.tpl
8# -- Override the resource name prefix
9# @default -- `Chart.Name`
11# -- Override the full resource names
12# @default -- `jenkins-(release-name)` or `jenkins` if the release-name is `jenkins`
14# -- Override the deployment namespace
15# @default -- `Release.Namespace`
17# For FQDN resolving of the controller service. Change this value to match your existing configuration.
18# ref: https://github.com/kubernetes/dns/blob/master/docs/specification.md
19# -- Override the cluster name for FQDN resolving
20clusterZone: "cluster.local"
21# -- The URL of the Kubernetes API server
22kubernetesURL: "https://kubernetes.default"
23# -- The Jenkins credentials to access the Kubernetes API server. For the default cluster it is not needed.
25# -- Enables rendering of the helm.sh/chart label to the annotations
27# -- Configures extra labels for the agent all objects
29# -- Configures extra manifests
32 # -- Used for label app.kubernetes.io/component
33 componentName: "jenkins-controller"
35 # -- Controller image registry
37 # -- Controller image repository
38 repository: chainguard-private/jenkins
39 # -- Controller image tag override; i.e., tag: "2.440.1-jdk21"
40 tag: 2.585-r0-jdk21@sha256:93a33d8d98b203d046c48a9de603844f934db291a9d748aafde2b66ee3caba69
41 # -- Controller image tag label
43 # -- Controller image pull policy
45 # -- Number of replicas. Max 1. Can be set to 0 for maintenance scenarios.
47 # -- Controller image pull secret
49 # -- Lifecycle specification for controller-container
57 # -- Disable use of remember me
58 disableRememberMe: false
59 # -- Set Number of executors
61 # -- Sets the executor mode of the Jenkins node. Possible values are "NORMAL" or "EXCLUSIVE"
62 executorMode: "NORMAL"
63 # -- Append Jenkins labels to the controller
64 customJenkinsLabels: []
66 # When enabling LDAP or another non-Jenkins identity source, the built-in admin account will no longer exist.
67 # If you disable the non-Jenkins identity store and instead use the Jenkins internal one,
68 # you should revert controller.admin.username to your preferred admin user:
70 # -- Admin username created as a secret if `controller.admin.createSecret` is true
72 # -- Admin password created as a secret if `controller.admin.createSecret` is true
73 # @default -- <random password>
75 # -- The key in the existing admin secret containing the username
76 userKey: jenkins-admin-user
77 # -- The key in the existing admin secret containing the password
78 passwordKey: jenkins-admin-password
79 # The default configuration uses this secret to configure an admin user
80 # If you don't need that user or use a different security realm, then you can disable it
81 # -- Create secret for admin user
83 # -- The name of an existing secret containing the admin credentials
85 # -- Email address for the administrator of the Jenkins instance
87 # This value should not be changed unless you use your custom image of jenkins or any derived from.
88 # If you want to use Cloudbees Jenkins Distribution docker, you should set jenkinsHome: "/var/cloudbees-jenkins-distribution"
89 # -- Custom Jenkins home path
90 jenkinsHome: "/var/jenkins_home"
91 # This value should not be changed unless you use your custom image of jenkins or any derived from.
92 # If you want to use Cloudbees Jenkins Distribution docker, you should set jenkinsRef: "/usr/share/cloudbees-jenkins-distribution/ref"
93 # -- Custom Jenkins reference path
94 jenkinsRef: "/usr/share/jenkins/ref"
95 # Path to the jenkins war file which is used by jenkins-plugin-cli.
96 jenkinsWar: "/usr/share/jenkins/jenkins.war"
97 # Override the default arguments passed to the war
101 # -- Resource allocation (Requests and Limits)
109 # Share process namespace to allow sidecar containers to interact with processes in other containers in the same pod
110 shareProcessNamespace: false
111 # Service links might cause issue if running in a namespace with a large amount of services
112 # that might cause a slow startup when plugins are copied from ref to volume
113 # Set to true to keep previous behavior
114 # See https://github.com/kubernetes/kubernetes/issues/121787
115 enableServiceLinks: false
116 # Overrides the init container default values
117 # -- Resources allocation (Requests and Limits) for Init Container
118 initContainerResources: {}
119 # initContainerResources:
126 # -- Environment variable sources for Init Container
127 initContainerEnvFrom: []
128 # useful for i.e., http_proxy
129 # -- Environment variables for Init Container
133 # value: "http://192.168.64.1:3128"
135 # -- Environment variable sources for Jenkins Container
137 # -- Environment variables for Jenkins Container
140 # value: "http://192.168.64.1:3128"
142 # Set min/max heap here if needed with "-Xms512m -Xmx512m"
143 # -- Append to `JAVA_OPTS` env var
145 # -- Append to `JENKINS_OPTS` env var
147 # If you are using the ingress definitions provided by this chart via the `controller.ingress` block,
148 # the configured hostname will be the ingress hostname starting with `https://`
149 # or `http://` depending on the `tls` configuration.
150 # The Protocol can be overwritten by specifying `controller.jenkinsUrlProtocol`.
151 # -- Set protocol for Jenkins URL; `https` if `controller.ingress.tls`, `http` otherwise
153 # -- Set Jenkins URL if you are not using the ingress definitions provided by the chart
155 # If you set this prefix and use ingress controller, then you might want to set the ingress path below
157 # -- Root URI Jenkins will be served on
159 # -- Enable pod security context (must be `true` if podSecurityContextOverride, runAsUser or fsGroup are set)
160 usePodSecurityContext: true
161 # Note that `runAsUser`, `fsGroup`, and `securityContextCapabilities` are
162 # being deprecated and replaced by `podSecurityContextOverride`.
163 # Set runAsUser to 1000 to let Jenkins run as non-root user 'jenkins', which exists in 'jenkins/jenkins' docker image.
164 # When configuring runAsUser to a different value than 0 also set fsGroup to the same value:
165 # -- Deprecated in favor of `controller.podSecurityContextOverride`. uid that jenkins runs with.
167 # -- Deprecated in favor of `controller.podSecurityContextOverride`. uid that will be used for persistent volume.
169 # -- Deprecated in favor of `controller.podSecurityContextOverride`. fsGroupChangePolicy for the pod security context
170 fsGroupChangePolicy: OnRootMismatch
171 # If you have PodSecurityPolicies that require dropping of capabilities as suggested by CIS K8s benchmark, put them here
172 # securityContextCapabilities:
175 securityContextCapabilities: {}
176 # In the case of mounting an ext4 filesystem, it might be desirable to use `supplementalGroups` instead of `fsGroup` in
177 # the `securityContext` block: https://github.com/kubernetes/kubernetes/issues/67014#issuecomment-589915496
178 # podSecurityContextOverride:
181 # supplementalGroups: [1000]
183 # -- Completely overwrites the contents of the pod security context, ignoring the values provided for `runAsUser`, `fsGroup`, and `securityContextCapabilities`
184 podSecurityContextOverride: ~
185 # -- Allow controlling the securityContext for the jenkins container
186 containerSecurityContext:
189 readOnlyRootFilesystem: true
190 allowPrivilegeEscalation: false
191 # -- enable or disable the controller k8s service
193 # For minikube, set this to NodePort, elsewhere uses LoadBalancer
194 # Use ClusterIP if your setup includes ingress controller
195 # -- k8s service type
196 serviceType: ClusterIP
197 # -- k8s service clusterIP. Only used if serviceType is ClusterIP
199 # -- k8s service port
203 # -- k8s node port. Only used if serviceType is NodePort
205 # Use Local to preserve the client source IP and avoids a second hop for LoadBalancer and NodePort type services,
206 # but risks potentially imbalanced traffic spreading.
207 serviceExternalTrafficPolicy:
208 # If enabled, the controller is available through its service before its pods reports ready. Makes startup screen and
209 # auto-reload on restart feature possible.
210 publishNotReadyAddresses:
211 # -- Jenkins controller service annotations
212 serviceAnnotations: {}
213 # -- Jenkins controller custom labels for the StatefulSet
214 statefulSetLabels: {}
217 # -- Labels for the Jenkins controller-service
219 # service.beta.kubernetes.io/aws-load-balancer-backend-protocol: https
221 # Put labels on Jenkins controller pod
222 # -- Custom Pod labels (an object with `label-key: label-value` pairs)
224 # Enable Kubernetes Startup, Liveness and Readiness Probes
225 # if Startup Probe is supported, enable it too
226 # ~ 2 minutes to allow Jenkins to restart when upgrading plugins. Set ReadinessTimeout to be shorter than LivenessTimeout.
227 # ref: https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-startup-probes
228 # -- Enable Kubernetes Probes configuration configured in `controller.probes`
232 # -- Set the failure threshold for the startup probe
235 # -- Set the Pod's HTTP path for the startup probe
236 path: '{{ default "" .Values.controller.jenkinsUriPrefix }}/login'
237 # -- Set the Pod's HTTP port to use for the startup probe
239 # -- Set the time interval between two startup probes executions in seconds
241 # -- Set the timeout for the startup probe in seconds
244 # -- Set the failure threshold for the liveness probe
247 # -- Set the Pod's HTTP path for the liveness probe
248 path: '{{ default "" .Values.controller.jenkinsUriPrefix }}/login'
249 # -- Set the Pod's HTTP port to use for the liveness probe
251 # -- Set the time interval between two liveness probes executions in seconds
253 # -- Set the timeout for the liveness probe in seconds
255 # If Startup Probe is not supported on your Kubernetes cluster, you might want to use "initialDelaySeconds" instead.
256 # It delays the initial liveness probe while Jenkins is starting
257 # -- Set the initial delay for the liveness probe in seconds
260 # -- Set the failure threshold for the readiness probe
263 # -- Set the Pod's HTTP path for the liveness probe
264 path: '{{ default "" .Values.controller.jenkinsUriPrefix }}/login'
265 # -- Set the Pod's HTTP port to use for the readiness probe
267 # -- Set the time interval between two readiness probes executions in seconds
269 # -- Set the timeout for the readiness probe in seconds
271 # If Startup Probe is not supported on your Kubernetes cluster, you might want to use "initialDelaySeconds" instead.
272 # It delays the initial readiness probe while Jenkins is starting
273 # -- Set the initial delay for the readiness probe in seconds
275 # PodDisruptionBudget config
277 # ref: https://kubernetes.io/docs/tasks/run-application/configure-pdb/
279 # -- Enable Kubernetes Pod Disruption Budget configuration
281 # For Kubernetes v1.5+, use 'policy/v1beta1'
282 # For Kubernetes v1.21+, use 'policy/v1'
283 # -- Policy API version
284 apiVersion: "policy/v1beta1"
287 # -- Number of pods that can be unavailable. Either an absolute number or a percentage
289 # -- Create Agent listener service
290 agentListenerEnabled: true
291 # -- Listening port for agents
292 agentListenerPort: 50000
293 # -- Host port to listen for agents
294 agentListenerHostPort:
295 # -- Node port to listen for agents
296 agentListenerNodePort:
297 # ref: https://kubernetes.io/docs/concepts/services-networking/service/#traffic-policies
298 # -- Traffic Policy of for the agentListener service
299 agentListenerExternalTrafficPolicy:
300 # -- Allowed inbound IP for the agentListener service
301 agentListenerLoadBalancerSourceRanges:
303 # -- Disabled agent protocols
304 disabledAgentProtocols:
309 # -- Enable the default CSRF Crumb issuer
311 # -- Enable proxy compatibility. This setting is ignored if you are not on the current LTS release and will be dropped with the next LTS.
312 proxyCompatability: true
313 # Kubernetes service type for the JNLP agent service
314 # agentListenerServiceType is the Kubernetes Service type for the JNLP agent service,
315 # either 'LoadBalancer', 'NodePort', or 'ClusterIP'
316 # Note if you set this to 'LoadBalancer', you *must* define annotations to secure it. By default,
317 # this will be an external load balancer and allowing inbound 0.0.0.0/0, a HUGE
318 # security risk: https://github.com/kubernetes/charts/issues/1341
319 # -- Defines how to expose the agentListener service
320 agentListenerServiceType: "ClusterIP"
321 # -- Annotations for the agentListener service
322 agentListenerServiceAnnotations: {}
323 # Optionally, assign an IP to the LoadBalancer agentListenerService LoadBalancer
324 # GKE users: only regional static IPs will work for Service Load balancer.
325 # -- Static IP for the agentListener LoadBalancer
326 agentListenerLoadBalancerIP:
327 # -- Whether legacy remoting security should be enabled
328 legacyRemotingSecurityEnabled: false
329 # Example of a 'LoadBalancer'-type agent listener with annotations securing it
330 # agentListenerServiceType: LoadBalancer
331 # agentListenerServiceAnnotations:
332 # service.beta.kubernetes.io/aws-load-balancer-internal: "True"
333 # service.beta.kubernetes.io/load-balancer-source-ranges: "172.0.0.0/8, 10.0.0.0/8"
335 # LoadBalancerSourcesRange is a list of allowed CIDR values, which are combined with ServicePort to
336 # set allowed inbound rules on the security group assigned to the controller load balancer
337 # -- Allowed inbound IP addresses
338 loadBalancerSourceRanges:
340 # -- Optionally assign a known public LB IP
342 # Optionally configure a JMX port. This requires additional javaOpts, for example,
344 # -Dcom.sun.management.jmxremote.port=4000
345 # -Dcom.sun.management.jmxremote.authenticate=false
346 # -Dcom.sun.management.jmxremote.ssl=false
348 # -- Open a port, for JMX stats
350 # -- Optionally configure other ports to expose in the controller container
352 # - name: BuildInfoProxy
354 # targetPort: 9010 (Optional: Use to explicitly set targetPort if different from port)
356 # Plugins will be installed during Jenkins controller start
357 # -- List of Jenkins plugins to install. If you don't want to install plugins, set it to `false`
359 - kubernetes:4557.ve746270f672f
360 - workflow-aggregator:608.v67378e9d3db_1
362 - configuration-as-code:2131.vb_a_13ed96f755
363 # If set to false, Jenkins will download the minimum required version of all dependencies.
364 # -- Download the minimum required version or latest version of all dependencies
365 installLatestPlugins: true
366 # -- Set to true to download the latest version of any plugin that is requested to have the latest version
367 installLatestSpecifiedPlugins: false
368 # -- List of plugins to install in addition to those listed in controller.installPlugins
369 additionalPlugins: []
370 # Without this; whenever the controller gets restarted (Evicted, etc.) it will fetch plugin updates that have the potential to cause breakage.
371 # Note that for this to work, `persistence.enabled` needs to be set to `true`
372 # -- Initialize only on first installation. Ensures plugins do not get updated inadvertently. Requires `persistence.enabled` to be set to `true`
373 initializeOnce: false
374 # Enable to always override the installed plugins with the values of 'controller.installPlugins' on upgrade or redeployment.
375 # -- Overwrite installed plugins on start
376 overwritePlugins: false
377 # Configures if plugins bundled with `controller.image` should be overwritten with the values of 'controller.installPlugins' on upgrade or redeployment.
378 # -- Overwrite plugins that are already installed in the controller image
379 overwritePluginsFromImage: true
380 # Configures the restrictions for naming projects. Set this key to null or empty to skip it in the default config.
381 projectNamingStrategy: standard
382 # Useful with ghprb plugin. The OWASP plugin is not installed by default, please update controller.installPlugins.
383 # -- Enable HTML parsing using OWASP Markup Formatter Plugin (antisamy-markup-formatter)
384 enableRawHtmlMarkupFormatter: false
385 # This is ignored if enableRawHtmlMarkupFormatter is true
386 # -- Yaml of the markup formatter to use
387 markupFormatter: plainText
388 # Used to approve a list of groovy functions in pipelines used the script-security plugin. Can be viewed under /scriptApproval
389 # -- List of groovy functions to approve
391 # - "method groovy.json.JsonSlurperClassic parseText java.lang.String"
392 # - "new groovy.json.JsonSlurperClassic"
394 # -- Map of groovy init scripts to be executed during Jenkins controller start
397 # print 'adding global pipeline libraries, register properties, bootstrap jobs...'
398 # -- Name of the existing ConfigMap that contains init scripts
400 # 'name' is a name of an existing secret in the same namespace as jenkins,
401 # 'keyName' is the name of one of the keys inside the current secret.
402 # the 'name' and 'keyName' are concatenated with a '-' in between, so for example:
403 # an existing secret "secret-credentials" and a key inside it named "github-password" should be used in JCasC as ${secret-credentials-github-password}
404 # 'name' and 'keyName' must be lowercase RFC 1123 label must consist of lower case alphanumeric characters or '-',
405 # and must start and end with an alphanumeric character (e.g. 'my-name', or '123-abc')
406 # existingSecret existing secret "secret-credentials" and a key inside it named "github-username" should be used in JCasC as ${github-username}
407 # When using existingSecret no need to specify the keyName under additionalExistingSecrets.
409 # -- List of additional existing secrets to mount
410 additionalExistingSecrets: []
411 # ref: https://github.com/jenkinsci/configuration-as-code-plugin/blob/master/docs/features/secrets.adoc#kubernetes-secrets
412 # additionalExistingSecrets:
413 # - name: secret-name-1
415 # - name: secret-name-1
418 # -- List of additional secrets to create and mount
419 additionalSecrets: []
420 # ref: https://github.com/jenkinsci/configuration-as-code-plugin/blob/master/docs/features/secrets.adoc#kubernetes-secrets
422 # - name: nameOfSecret
425 # Generate SecretClaim resources to create Kubernetes secrets from HashiCorp Vault using kube-vault-controller.
426 # 'name' is the name of the secret that will be created in Kubernetes. The Jenkins fullname is prepended to this value.
427 # 'path' is the fully qualified path to the secret in Vault
428 # 'type' is an optional Kubernetes secret type. The default is 'Opaque'
429 # 'renew' is an optional secret renewal time in seconds
430 # -- List of `SecretClaim` resources to create
432 # - name: secretName # required
433 # path: testPath # required
434 # type: kubernetes.io/tls # optional
435 # renew: 60 # optional
437 # -- Name of default cloud configuration.
438 cloudName: "kubernetes"
439 # -- Traits for the chart-generated Kubernetes cloud (for example, `ephemeralContainer`). Additional clouds inherit these unless overridden by `additionalClouds.<name>.controller.cloudTraits`.
441 # Below is the implementation of Jenkins Configuration as Code. Add a key under configScripts for each configuration area,
442 # where each corresponds to a plugin or section of the UI. Each key (prior to | character) is just a label, and can be any value.
443 # Keys are only used to give the section a meaningful name. The only restriction is they may only contain RFC 1123 \ DNS label
444 # characters: lowercase letters, numbers, and hyphens. The keys become the name of a configuration yaml file on the controller in
445 # /var/jenkins_home/casc_configs (by default) and will be processed by the Configuration as Code Plugin. The lines after each |
446 # become the content of the configuration yaml file. The first line after this is a JCasC root element, e.g., jenkins, credentials,
447 # etc. Best reference is https://<jenkins_url>/configuration-as-code/reference. The example below creates a welcome message:
449 # -- Enables default Jenkins configuration via configuration as code plugin
451 # If true, the init container deletes all the plugin config files and Jenkins Config as Code overwrites any existing configuration
452 # -- Whether Jenkins Config as Code should overwrite any existing configuration
453 overwriteConfiguration: false
454 # -- Remote URLs for configuration files.
456 # - https://acme.org/jenkins.yaml
457 # -- List of Jenkins Config as Code scripts
461 # systemMessage: Welcome to our CI\CD server. This Jenkins is configured and managed 'as code'.
463 # Allows adding to the top-level security JCasC section. For legacy purposes, by default, the chart includes apiToken configurations
464 # -- Jenkins Config as Code security-section
467 creationOfLegacyTokenEnabled: false
468 tokenGenerationOnCreationEnabled: false
469 usageStatisticsEnabled: true
470 # Ignored if securityRealm is defined in controller.JCasC.configScripts
471 # -- Jenkins Config as Code Security Realm-section
477 - id: "${chart-admin-username}"
478 name: "Jenkins Admin"
479 password: "${chart-admin-password}"
480 # Ignored if authorizationStrategy is defined in controller.JCasC.configScripts
481 # -- Jenkins Config as Code Authorization Strategy-section
482 authorizationStrategy: |-
483 loggedInUsersCanDoAnything:
484 allowAnonymousRead: false
485 # -- Annotations for the JCasC ConfigMap
486 configMapAnnotations: {}
487 # -- Custom init-container specification in raw-yaml format
488 customInitContainers: []
489 # - name: custom-init
491 # imagePullPolicy: Always
492 # command: [ "uname", "-a" ]
496 # If enabled: true, Jenkins Configuration as Code will be reloaded on-the-fly without a reboot.
497 # If false or not-specified, JCasC changes will cause a reboot and will only be applied at the subsequent start-up.
498 # Auto-reload uses the http://<jenkins_url>/reload-configuration-as-code endpoint to reapply config when changes to
499 # the configScripts are detected.
500 # -- Enable Jenkins Config as Code auto-reload
503 # -- Registry for the image that triggers the reload
505 # -- Repository of the image that triggers the reload
506 repository: chainguard-private/k8s-sidecar
507 # -- Tag for the image that triggers the reload
508 tag: 2.11.2-r4@sha256:9af4a4aeb34f5b92ed2344b2a7bfbfee21863c6e98a752a29a8df1454ddb8158
509 imagePullPolicy: IfNotPresent
510 # -- Port for sidecar health probes
519 # -- Enables additional volume mounts for the config auto-reload container
520 additionalVolumeMounts: []
521 # - name: auto-reload-config
522 # mountPath: /var/config/logger
523 # - name: auto-reload-logs
524 # mountPath: /var/log/auto_reload
525 # -- Config auto-reload logging settings
527 # See default settings https://github.com/kiwigrid/k8s-sidecar/blob/master/src/logger.py
529 # -- Enables custom log config utilizing using the settings below.
537 # -- The scheme to use when connecting to the Jenkins configuration as code endpoint
539 # -- Skip TLS verification when connecting to the Jenkins configuration as code endpoint
541 # -- How many connection-related errors to retry on
543 # -- How many seconds to wait before updating config-maps/secrets (sets METHOD=SLEEP on the sidecar)
545 # -- Environment variable sources for the Jenkins Config as Code auto-reload container
547 # -- Environment variables for the Jenkins Config as Code auto-reload container
549 # - name: REQ_TIMEOUT
552 # SSH port value can be set to any unused TCP port. The default, 1044, is a non-standard SSH port that has been chosen at random.
553 # This is only used to reload JCasC config from the sidecar container running in the Jenkins controller pod.
554 # This TCP port will not be open in the pod (unless you specifically configure this), so Jenkins will not be
555 # accessible via SSH from outside the pod. Note if you use non-root pod privileges (runAsUser & fsGroup),
556 # this must be > 1024:
558 # folder in the pod that should hold the collected dashboards:
559 folder: "/var/jenkins_home/casc_configs"
560 # If specified, the sidecar will search for JCasC config-maps inside this namespace.
561 # Otherwise, the namespace in which the sidecar is running will be used.
562 # It's also possible to specify ALL to search in all namespaces:
564 # -- Enable container security context
565 containerSecurityContext:
566 readOnlyRootFilesystem: true
567 allowPrivilegeEscalation: false
568 # -- Configures additional sidecar container(s) for the Jenkins controller
569 additionalSidecarContainers: []
570 ## The example below runs the client for https://smee.io as sidecar container next to Jenkins,
571 ## that allows triggering build behind a secure firewall.
572 ## https://jenkins.io/blog/2019/01/07/webhook-firewalls/#triggering-builds-with-webhooks-behind-a-secure-firewall
574 ## Note: To use it you should go to https://smee.io/new and update the url to the generated one.
576 # image: docker.io/twalter/smee-client:1.0.2
577 # args: ["--port", "{{ .Values.controller.servicePort }}", "--path", "/github-webhook/", "--url", "https://smee.io/new"]
585 # -- Name of the Kubernetes scheduler to use
587 # ref: https://kubernetes.io/docs/concepts/configuration/assign-pod-node/#nodeselector
588 # -- Node labels for pod assignment
590 # ref: https://kubernetes.io/docs/concepts/configuration/assign-pod-node/#taints-and-tolerations-beta-feature
591 # -- Toleration labels for pod assignment
593 # -- Set TerminationGracePeriodSeconds
594 terminationGracePeriodSeconds:
595 # -- Set the termination message path
596 terminationMessagePath:
597 # -- Set the termination message policy
598 terminationMessagePolicy:
599 # -- Affinity settings
601 # Leverage a priorityClass to ensure your pods survive resource shortages
602 # ref: https://kubernetes.io/docs/concepts/configuration/pod-priority-preemption/
603 # -- The name of a `priorityClass` to apply to the controller pod
605 # -- Annotations for controller pod
607 # -- Annotations for controller StatefulSet
608 statefulSetAnnotations: {}
609 # ref: https://kubernetes.io/docs/concepts/workloads/controllers/statefulset/#update-strategies
610 # -- Update strategy for StatefulSet
612 # ref: https://kubernetes.io/docs/concepts/workloads/controllers/statefulset/#managing-revision-history
613 # -- Maximum number of revisions that will be maintained in the StatefulSet's revision history
614 revisionHistoryLimit:
615 # -- Topology spread constraints
616 topologySpreadConstraints: []
617 # -- DNS config for the pod
620 # -- Enables the Primary ingress
622 # Override for the default paths that map requests to the backend
623 # -- Override for the default Primary Ingress paths
626 # serviceName: ssl-redirect
627 # servicePort: use-annotation
630 # {{ template "jenkins.fullname" . }}
631 # # Don't use string here, use only integer value!
634 # -- Primary Ingress rule pathType, choices are: Exact, ImplementationSpecific, Prefix
635 pathType: ImplementationSpecific
636 # For Kubernetes v1.14+, use 'networking.k8s.io/v1beta1'
637 # For Kubernetes v1.19+, use 'networking.k8s.io/v1'
638 # -- Primary Ingress API version
639 apiVersion: "networking.k8s.io/v1"
640 # -- Primary Ingress labels
642 # -- Primary Ingress annotations
644 # kubernetes.io/ingress.class: nginx
645 # kubernetes.io/tls-acme: "true"
646 # For Kubernetes >= 1.18 you should specify the ingress-controller via the field ingressClassName
647 # See https://kubernetes.io/blog/2020/04/02/improvements-to-the-ingress-api-in-kubernetes-1.18/#specifying-the-class-of-an-ingress
648 # ingressClassName: nginx
649 # -- Primary Ingress ingressClassName
651 # Set this path to jenkinsUriPrefix above or use annotations to rewrite path
652 # -- Primary Ingress path
654 # configures the hostname e.g. jenkins.example.com
655 # -- Primary Ingress hostname
657 # -- Primary Hostname to serve assets from
659 # -- Primary Ingress TLS configuration
661 # - secretName: jenkins.cluster.local
663 # - jenkins.cluster.local
664 # often you want to have your controller all locked down and private,
665 # but you still want to get webhooks from your SCM
666 # A secondary ingress will let you expose different urls
667 # with a different configuration
669 # -- Enables the Secondary Ingress
671 # paths you want forwarded to the backend
673 # -- Secondary Ingress paths
675 # -- Secondary Ingress rule pathType, choices are: Exact, ImplementationSpecific, Prefix
676 pathType: ImplementationSpecific
677 # For Kubernetes v1.14+, use 'networking.k8s.io/v1beta1'
678 # For Kubernetes v1.19+, use 'networking.k8s.io/v1'
679 # -- Secondary Ingress API version
680 apiVersion: "networking.k8s.io/v1"
681 # -- Secondary Ingress labels
683 # -- Secondary Ingress annotations
685 # kubernetes.io/ingress.class: nginx
686 # kubernetes.io/tls-acme: "true"
687 # For Kubernetes >= 1.18 you should specify the ingress-controller via the field ingressClassName
688 # See https://kubernetes.io/blog/2020/04/02/improvements-to-the-ingress-api-in-kubernetes-1.18/#specifying-the-class-of-an-ingress
689 # -- Secondary Ingress ingressClassName
691 # configures the hostname e.g., jenkins-external.example.com
692 # -- Secondary Ingress hostname
694 # -- Secondary Ingress TLS configuration
696 # - secretName: jenkins-external.example.com
698 # - jenkins-external.example.com
699 # If you're running on GKE and need to configure a backendconfig
700 # to finish ingress setup, use the following values.
701 # Docs: https://cloud.google.com/kubernetes-engine/docs/concepts/backendconfig
703 # -- Enables backendconfig
705 # -- backendconfig API version
706 apiVersion: "extensions/v1beta1"
707 # -- backendconfig name
709 # -- backendconfig labels
711 # -- backendconfig annotations
713 # -- backendconfig spec
717 # -- Enables openshift route
721 # -- Route annotations
725 # Gateway API HTTPRoute
727 # Toggle to create an HTTPRoute resource alongside the existing ingress definition
729 apiVersion: "gateway.networking.k8s.io/v1"
731 # specify the Gateway instance to bind the HTTPRoute to.
733 # - name: envoy-gateway-bundle
734 # namespace: envoy-gateway-system
735 # Reuse ingress host information if true; set to false to manage hostnames below
736 reuseIngressConfiguration: false
737 # Hostnames to use for the http route, only used if reuseIngressConfiguration is false.
739 # Extra HTTPRoute rules that will be appended before the default backend
741 # -- HTTPRoute annotations
743 # -- Filters applied to the default HTTPRoute rule
745 # -- Timeouts applied to the default HTTPRoute rule. Requires Gateway API v1.2+ and controller support
747 # -- Allows for adding entries to Pod /etc/hosts
749 # ref: https://kubernetes.io/docs/concepts/services-networking/add-entries-to-pod-etc-hosts-with-host-aliases/
751 # - ip: 192.168.50.50
758 # Expose Prometheus metrics
760 # If enabled, add the prometheus plugin to the list of plugins to install
761 # https://plugins.jenkins.io/prometheus
763 # -- Enables prometheus service monitor
765 # -- Additional labels to add to the service monitor object
766 serviceMonitorAdditionalLabels: {}
767 # -- Set a custom namespace where to deploy ServiceMonitor resource
768 serviceMonitorNamespace:
769 # -- How often prometheus should scrape metrics
771 # Defaults to the default endpoint used by the prometheus plugin
772 # -- The endpoint prometheus should get metrics from
773 scrapeEndpoint: /prometheus
774 # See here: https://prometheus.io/docs/prometheus/latest/configuration/alerting_rules/
775 # The `groups` root object is added by default, add the rule entries
776 # -- Array of prometheus alerting rules
778 # -- Additional labels to add to the PrometheusRule object
779 alertingRulesAdditionalLabels: {}
780 # -- Set a custom namespace where to deploy PrometheusRule resource
781 prometheusRuleNamespace: ""
782 # RelabelConfigs to apply to samples before scraping. Prometheus Operator automatically adds
783 # relabelings for a few standard Kubernetes fields. The original scrape job’s name
784 # is available via the __tmp_prometheus_job_name label.
785 # More info: https://prometheus.io/docs/prometheus/latest/configuration/configuration/#relabel_config
787 # MetricRelabelConfigs to apply to samples before ingestion.
788 metricRelabelings: []
790 # If enabled, It creates Google Managed Prometheus scraping config
792 # Set a custom namespace where to deploy PodMonitoring resource
793 # serviceMonitorNamespace: ""
795 # This is the default endpoint used by the prometheus plugin
796 scrapeEndpoint: /prometheus
797 # -- Can be used to disable rendering controller test resources when using helm template
800 # -- Enables HTTPS keystore on jenkins controller
802 # -- Name of the secret that already has SSL keystore
803 jenkinsHttpsJksSecretName: ""
804 # -- Name of the key in the secret that already has SSL keystore
805 jenkinsHttpsJksSecretKey: "jenkins-jks-file"
806 # -- Name of the secret that contains the JKS password, if it is not in the same secret as the JKS file
807 jenkinsHttpsJksPasswordSecretName: ""
808 # -- Name of the key in the secret that contains the JKS password
809 jenkinsHttpsJksPasswordSecretKey: "https-jks-password"
810 disableSecretMount: false
811 # When HTTPS keystore is enabled, servicePort and targetPort will be used as HTTPS port
812 # -- HTTP Port that Jenkins should listen to along with HTTPS, it also serves as the liveness and readiness probes port.
814 # -- Path of HTTPS keystore file
815 path: "/var/jenkins_keystore"
816 # -- Jenkins keystore filename which will appear under controller.httpsKeyStore.path
817 fileName: "keystore.jks"
818 # -- Jenkins keystore password
820 # -- Base64 encoded Keystore content. Keystore must be converted to base64 then being pasted here
821 jenkinsKeyStoreBase64Encoded:
822 # Convert keystore.jks files content to base64 > $ cat keystore.jks | base64
823# /u3+7QAAAAIAAAABAAAAAQANamVua2luc2NpLmNvbQAAAW2r/b1ZAAAFATCCBP0wDgYKKwYBBAEq
824# AhEBAQUABIIE6QbCqasvoHS0pSwYqSvdydMCB9t+VNfwhFIiiuAelJfO5sSe2SebJbtwHgLcRz1Z
825# gMtWgOSFdl3bWSzA7vrW2LED52h+jXLYSWvZzuDuh8hYO85m10ikF6QR+dTi4jra0whIFDvq3pxe
826# TnESxEsN+DvbZM3jA3qsjQJSeISNpDjO099dqQvHpnCn18lyk7J4TWJ8sOQQb1EM2zDAfAOSqA/x
827# QuPEFl74DlY+5DIk6EBvpmWhaMSvXzWZACGA0sYqa157dq7O0AqmuLG/EI5EkHETO4CrtBW+yLcy
828# 2dUCXOMA+j+NjM1BjrQkYE5vtSfNO6lFZcISyKo5pTFlcA7ut0Fx2nZ8GhHTn32CpeWwNcZBn1gR
829# pZVt6DxVVkhTAkMLhR4rL2wGIi/1WRs23ZOLGKtyDNvDHnQyDiQEoJGy9nAthA8aNHa3cfdF10vB
830# Drb19vtpFHmpvKEEhpk2EBRF4fTi644Fuhu2Ied6118AlaPvEea+n6G4vBz+8RWuVCmZjLU+7h8l
831# Hy3/WdUPoIL5eW7Kz+hS+sRTFzfu9C48dMkQH3a6f3wSY+mufizNF9U298r98TnYy+PfDJK0bstG
832# Ph6yPWx8DGXKQBwrhWJWXI6JwZDeC5Ny+l8p1SypTmAjpIaSW3ge+KgcL6Wtt1R5hUV1ajVwVSUi
833# HF/FachKqPqyLJFZTGjNrxnmNYpt8P1d5JTvJfmfr55Su/P9n7kcyWp7zMcb2Q5nlXt4tWogOHLI
834# OzEWKCacbFfVHE+PpdrcvCVZMDzFogIq5EqGTOZe2poPpBVE+1y9mf5+TXBegy5HToLWvmfmJNTO
835# NCDuBjgLs2tdw2yMPm4YEr57PnMX5gGTC3f2ZihXCIJDCRCdQ9sVBOjIQbOCzxFXkVITo0BAZhCi
836# Yz61wt3Ud8e//zhXWCkCsSV+IZCxxPzhEFd+RFVjW0Nm9hsb2FgAhkXCjsGROgoleYgaZJWvQaAg
837# UyBzMmKDPKTllBHyE3Gy1ehBNGPgEBChf17/9M+j8pcm1OmlM434ctWQ4qW7RU56//yq1soFY0Te
838# fu2ei03a6m68fYuW6s7XEEK58QisJWRAvEbpwu/eyqfs7PsQ+zSgJHyk2rO95IxdMtEESb2GRuoi
839# Bs+AHNdYFTAi+GBWw9dvEgqQ0Mpv0//6bBE/Fb4d7b7f56uUNnnE7mFnjGmGQN+MvC62pfwfvJTT
840# EkT1iZ9kjM9FprTFWXT4UmO3XTvesGeE50sV9YPm71X4DCQwc4KE8vyuwj0s6oMNAUACW2ClU9QQ
841# y0tRpaF1tzs4N42Q5zl0TzWxbCCjAtC3u6xf+c8MCGrr7DzNhm42LOQiHTa4MwX4x96q7235oiAU
842# iQqSI/hyF5yLpWw4etyUvsx2/0/0wkuTU1FozbLoCWJEWcPS7QadMrRRISxHf0YobIeQyz34regl
843# t1qSQ3dCU9D6AHLgX6kqllx4X0fnFq7LtfN7fA2itW26v+kAT2QFZ3qZhINGfofCja/pITC1uNAZ
844# gsJaTMcQ600krj/ynoxnjT+n1gmeqThac6/Mi3YlVeRtaxI2InL82ZuD+w/dfY9OpPssQjy3xiQa
845# jPuaMWXRxz/sS9syOoGVH7XBwKrWpQcpchozWJt40QV5DslJkclcr8aC2AGlzuJMTdEgz1eqV0+H
846# bAXG9HRHN/0eJTn1/QAAAAEABVguNTA5AAADjzCCA4swggJzAhRGqVxH4HTLYPGO4rzHcCPeGDKn
847# xTANBgkqhkiG9w0BAQsFADCBgTELMAkGA1UEBhMCY2ExEDAOBgNVBAgMB29udGFyaW8xEDAOBgNV
848# BAcMB3Rvcm9udG8xFDASBgNVBAoMC2plbmtpbnN0ZXN0MRkwFwYDVQQDDBBqZW5raW5zdGVzdC5p
849# bmZvMR0wGwYJKoZIhvcNAQkBFg50ZXN0QHRlc3QuaW5mbzAeFw0xOTEwMDgxNTI5NTVaFw0xOTEx
850# MDcxNTI5NTVaMIGBMQswCQYDVQQGEwJjYTEQMA4GA1UECAwHb250YXJpbzEQMA4GA1UEBwwHdG9y
851# b250bzEUMBIGA1UECgwLamVua2luc3Rlc3QxGTAXBgNVBAMMEGplbmtpbnN0ZXN0LmluZm8xHTAb
852# BgkqhkiG9w0BCQEWDnRlc3RAdGVzdC5pbmZvMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKC
853# AQEA02q352JTHGvROMBhSHvSv+vnoOTDKSTz2aLQn0tYrIRqRo+8bfmMjXuhkwZPSnCpvUGNAJ+w
854# Jrt/dqMoYUjCBkjylD/qHmnXN5EwS1cMg1Djh65gi5JJLFJ7eNcoSsr/0AJ+TweIal1jJSP3t3PF
855# 9Uv21gm6xdm7HnNK66WpUUXLDTKaIs/jtagVY1bLOo9oEVeLN4nT2CYWztpMvdCyEDUzgEdDbmrP
856# F5nKUPK5hrFqo1Dc5rUI4ZshL3Lpv398aMxv6n2adQvuL++URMEbXXBhxOrT6rCtYzbcR5fkwS9i
857# d3Br45CoWOQro02JAepoU0MQKY5+xQ4Bq9Q7tB9BAwIDAQABMA0GCSqGSIb3DQEBCwUAA4IBAQAe
858# 4xc+mSvKkrKBHg9/zpkWgZUiOp4ENJCi8H4tea/PCM439v6y/kfjT/okOokFvX8N5aa1OSz2Vsrl
859# m8kjIc6hiA7bKzT6lb0EyjUShFFZ5jmGVP4S7/hviDvgB5yEQxOPpumkdRP513YnEGj/o9Pazi5h
860# /MwpRxxazoda9r45kqQpyG+XoM4pB+Fd3JzMc4FUGxfVPxJU4jLawnJJiZ3vqiSyaB0YyUL+Er1Q
861# 6NnqtR4gEBF0ZVlQmkycFvD4EC2boP943dLqNUvop+4R3SM1QMM6P5u8iTXtHd/VN4MwMyy1wtog
862# hYAzODo1Jt59pcqqKJEas0C/lFJEB3frw4ImNx5fNlJYOpx+ijfQs9m39CevDq0=
865 # -- Add the environment proxy settings form jenkins controller to the agents.
866 addMasterProxyEnvVars: false
867 # -- Enable Kubernetes plugin jnlp-agent podTemplate
869 # -- The name of the pod template to use for providing default values
870 defaultsProviderTemplate: ""
871 # Useful for not including a serviceAccount in the template if `false`
872 # -- Use `serviceAccountAgent.name` as the default value for defaults template `serviceAccount`
873 useDefaultServiceAccount: true
874 # -- Override the default service account
875 # @default -- `serviceAccountAgent.name` if `agent.useDefaultServiceAccount` is `true`
877 # For connecting to the Jenkins controller
878 # -- Overrides the Kubernetes Jenkins URL
880 # connects to the specified host and port, instead of connecting directly to the Jenkins controller
881 # -- Overrides the Kubernetes Jenkins tunnel
883 # -- Disables the verification of the controller certificate on remote connection. This flag correspond to the "Disable https certificate check" flag in kubernetes plugin UI
885 # -- Enable the possibility to restrict the usage of this agent to specific folder. This flag correspond to the "Restrict pipeline support to authorized folders" flag in kubernetes plugin UI
886 usageRestricted: false
887 # -- The connection timeout in seconds for connections to Kubernetes API. The minimum value is 5
888 kubernetesConnectTimeout: 5
889 # -- The read timeout in seconds for connections to Kubernetes API. The minimum value is 15
890 kubernetesReadTimeout: 15
891 # -- The maximum concurrent connections to Kubernetes API
892 maxRequestsPerHostStr: "32"
893 # -- Time in minutes after which the Kubernetes cloud plugin will clean up an idle worker that has not already terminated
895 # -- Seconds to wait for pod to be running
897 # -- Namespace in which the Kubernetes agents should be launched
899 # -- Custom Pod labels (an object with `label-key: label-value` pairs)
901 # -- Custom registry used to pull the agent jnlp image from
904 # -- Registry to pull the agent jnlp image from
906 # -- Repository to pull the agent jnlp image from
907 repository: chainguard-private/jenkins-inbound-agent
908 # -- Tag of the image to pull
909 tag: 2.585-r0-jdk21@sha256:6b5be6e83a98d3f09e49e168dce8f16faa4e5f8c63c244532e7dfa8549a7754f
910 # -- Configure working directory for default agent
911 workingDir: "/home/jenkins/agent"
912 nodeUsageMode: "NORMAL"
913 # -- Append Jenkins labels to the agent
914 customJenkinsLabels: []
915 # -- Name of the secret to be used to pull the image
917 componentName: "jenkins-agent"
918 # -- Enables agent communication via websockets
920 directConnection: false
921 # -- Agent privileged container
923 # -- Configure container user
925 # -- Configure container group
927 # -- Enables the agent to use the host network
928 hostNetworking: false
929 # -- Resources allocation (Requests and Limits)
940 # execArgs: "cat /tmp/healthy"
941 # failureThreshold: 3
942 # initialDelaySeconds: 0
944 # successThreshold: 1
947 # You may want to change this to true while testing a new image
948 # -- Always pull agent container image before build
949 alwaysPullImage: false
950 # When using Pod Security Admission in the Agents namespace with the restricted Pod Security Standard,
951 # the jnlp container cannot be scheduled without overriding its container definition with a securityContext.
952 # This option allows to automatically inject in the jnlp container a securityContext
953 # that is suitable for the use of the restricted Pod Security Standard.
954 # -- Set a restricted securityContext on jnlp containers
955 restrictedPssSecurityContext: false
956 # Controls how agent pods are retained after the Jenkins build completes
957 # Possible values: Always, Never, OnFailure
958 podRetention: "Never"
959 # Disable if you do not want the Yaml the agent pod template to show up
960 # in the job Console Output. This can be helpful for either security reasons
961 # or simply to clean up the output to make it easier to read.
963 # You can define the volumes that you want to mount for this container
964 # Allowed types are: ConfigMap, EmptyDir, EphemeralVolume, HostPath, Nfs, PVC, Secret
965 # Configure the attributes as they appear in the corresponding Java class for that type
966 # https://github.com/jenkinsci/kubernetes-plugin/tree/master/src/main/java/org/csanchez/jenkins/plugins/kubernetes/volumes
967 # -- Additional volumes
970 # configMapName: myconfigmap
971 # mountPath: /var/myapp/myconfigmap
973 # mountPath: /var/myapp/myemptydir
975 # - type: EphemeralVolume
976 # mountPath: /var/myapp/myephemeralvolume
977 # accessModes: ReadWriteOnce
979 # storageClassName: mystorageclass
981 # hostPath: /var/lib/containers
982 # mountPath: /var/myapp/myhostpath
984 # mountPath: /var/myapp/mynfs
986 # serverAddress: "192.0.2.0"
987 # serverPath: /var/lib/containers
990 # mountPath: /var/myapp/mypvc
994 # mountPath: /var/myapp/mysecret
995 # secretName: mysecret
996 # Pod-wide environment, these vars are visible to any container in the agent pod
998 # You can define the workspaceVolume that you want to mount for this container
999 # Allowed types are: DynamicPVC, EmptyDir, EphemeralVolume, HostPath, Nfs, PVC
1000 # Configure the attributes as they appear in the corresponding Java class for that type
1001 # https://github.com/jenkinsci/kubernetes-plugin/tree/master/src/main/java/org/csanchez/jenkins/plugins/kubernetes/volumes/workspace
1002 # -- Workspace volume (defaults to EmptyDir)
1004 ## DynamicPVC example
1005 # - type: DynamicPVC
1006 # configMapName: myconfigmap
1010 ## EphemeralVolume example
1011 # - type: EphemeralVolume
1012 # accessModes: ReadWriteOnce
1013 # requestsSize: 10Gi
1014 # storageClassName: mystorageclass
1017 # hostPath: /var/lib/containers
1021 # serverAddress: "192.0.2.0"
1022 # serverPath: /var/lib/containers
1028 # Pod-wide environment, these vars are visible to any container in the agent pod
1029 # -- Environment variables for the agent Pod
1032 # value: /usr/local/bin
1033 # -- Mount a secret as environment variable
1036 # optional: false # default: false
1037 # secretKey: MY-K8S-PATH
1038 # secretName: my-k8s-secret
1040 # -- Node labels for pod assignment
1042 # Key Value selectors. Ex:
1046 # -- Command to execute when side container starts
1048 # -- Arguments passed to command to execute
1049 args: "${computer.jnlpmac} ${computer.name}"
1050 # -- Side container name
1051 sideContainerName: "jnlp"
1052 # Doesn't allocate pseudo TTY by default
1053 # -- Allocate pseudo tty to the side container
1055 # -- Max number of agents to launch for a whole cluster.
1057 # -- Max number of agents to launch for this type of agent
1058 instanceCap: 2147483647
1059 # -- Agent Pod base name
1061 # Enables garbage collection of orphan pods for this Kubernetes cloud. (beta)
1063 # -- When enabled, Jenkins will periodically check for orphan pods that have not been touched for the given timeout period and delete them.
1065 # -- Namespaces to look at for garbage collection, in addition to the default namespace defined for the cloud. One namespace per line.
1070 # -- Timeout value for orphaned pods
1072 # -- Allows the Pod to remain active for reuse until the configured number of minutes has passed since the last step was executed on it
1074 # The raw yaml of a Pod API Object, for example, this allows usage of toleration for agent pods.
1075 # https://github.com/jenkinsci/kubernetes-plugin#using-yaml-to-define-pod-templates
1076 # https://kubernetes.io/docs/concepts/configuration/taint-and-toleration/
1077 # -- The raw yaml of a Pod API Object to merge into the agent spec
1088 # -- Defines how the raw yaml field gets merged with yaml definitions from inherited pod templates. Possible values: "merge" or "override"
1089 yamlMergeStrategy: "override"
1090 # -- Controls whether the defined yaml merge strategy will be inherited if another defined pod template is configured to inherit from the current one
1091 inheritYamlMergeStrategy: false
1092 # -- Timeout in seconds for an agent to be online
1094 # -- Annotations to apply to the pod
1096 # Containers specified here are added to all agents. Set key empty to remove container from additional agents.
1097 # -- Add additional containers to the agents
1098 additionalContainers: []
1099 # - sideContainerName: dind
1101 # repository: docker
1103 # command: dockerd-entrypoint.sh
1114 # Useful when configuring agents only with the podTemplates value, since the default podTemplate populated by values mentioned above will be excluded in the rendered template.
1115 # -- Disable the default Jenkins Agent configuration
1116 disableDefaultAgent: false
1117 # Below is the implementation of custom pod templates for the default configured kubernetes cloud.
1118 # Add a key under podTemplates for each pod template. Each key (prior to | character) is just a label, and can be any value.
1119 # Keys are only used to give the pod template a meaningful name. The only restriction is they may only contain RFC 1123 \ DNS label
1120 # characters: lowercase letters, numbers, and hyphens. Each pod template can contain multiple containers.
1121 # For this pod templates configuration to be loaded, the following values must be set:
1122 # controller.JCasC.defaultConfig: true
1123 # Best reference is https://<jenkins_url>/configuration-as-code/reference#Cloud-kubernetes. The example below creates a python pod template.
1124 # -- Configures extra pod templates for the default kubernetes cloud
1128 # label: jenkins-python
1129 # serviceAccount: jenkins
1133 # command: "/bin/sh -c"
1137 # resourceRequestCpu: "400m"
1138 # resourceRequestMemory: "512Mi"
1139 # resourceLimitCpu: "1"
1140 # resourceLimitMemory: "1024Mi"
1141# Inherits all values from `agent` so you only need to specify values which differ
1142# -- Configure additional
1146# customJenkinsLabels: maven
1147# # An example of overriding the jnlp container
1148# # sideContainerName: jnlp
1150# repository: jenkins/jnlp-agent-maven
1154# customJenkinsLabels: python
1155# sideContainerName: python
1159# command: "/bin/sh -c"
1163# Here you can add additional clouds
1164# They inherit all values from the default cloud (including the main agent), so
1165# you only need to specify values which differ. If you want to override
1166# default additionalAgents with the additionalClouds.additionalAgents set
1167# additionalAgentsOverride to `true`.
1168# To override inherited cloud traits, set controller.cloudTraits for that cloud (use [] to clear them).
1171# kubernetesURL: https://api.remote-cloud.com
1174# - ephemeralContainer
1175# additionalAgentsOverride: true
1179# customJenkinsLabels: maven
1180# # An example of overriding the jnlp container
1181# # sideContainerName: jnlp
1183# repository: jenkins/jnlp-agent-maven
1185# namespace: my-other-maven-namespace
1187# kubernetesURL: https://api.remote-cloud.com
1190 # -- Enable the use of a Jenkins PVC
1192 # A manually managed Persistent Volume and Claim
1193 # Requires persistence.enabled: true
1194 # If defined, PVC must be created manually before volume will be bound
1195 # -- Provide the name of a PVC
1197 # jenkins data Persistent Volume Storage Class
1198 # If defined, storageClassName: <storageClass>
1199 # If set to "-", storageClassName: "", which disables dynamic provisioning
1200 # If undefined (the default) or set to null, no storageClassName spec is
1201 # set, choosing the default provisioner (gp2 on AWS, standard on GKE, AWS & OpenStack)
1202 # -- Storage class for the PVC
1204 # -- Annotations for the PVC
1206 # -- Labels for the PVC
1208 # -- The PVC access mode
1209 accessMode: "ReadWriteOnce"
1210 # -- The size of the PVC
1212 # ref: https://kubernetes.io/docs/concepts/storage/volume-pvc-datasource/
1213 # -- Existing data source to clone PVC from
1216 # kind: PersistentVolumeClaim
1218 # -- SubPath for jenkins-home mount
1220 # -- Additional volumes
1225 # -- Additional mounts
1227 # - mountPath: /var/nothing
1231 # -- Enable the creation of NetworkPolicy resources
1233 # For Kubernetes v1.4, v1.5 and v1.6, use 'extensions/v1beta1'
1234 # For Kubernetes v1.7, use 'networking.k8s.io/v1'
1235 # -- NetworkPolicy ApiVersion
1236 apiVersion: networking.k8s.io/v1
1237 # You can allow agents to connect from both within the cluster (from within specific/all namespaces) AND/OR from a given external IP range
1239 # -- Allow internal agents (from the same cluster) to connect to controller. Agent pods will be filtered based on PodLabels
1241 # -- A map of labels (keys/values) that agent pods must have to be able to connect to controller
1243 # -- A map of labels (keys/values) that agents namespaces must have to be able to connect to controller
1245 # project: myproject
1247 # -- The IP range from which external agents are allowed to connect to controller, i.e., 172.17.0.0/16
1249 # -- A list of IP sub-ranges to be excluded from the allowlisted IP range
1252## Install Default RBAC roles and bindings
1254 # -- Whether RBAC resources are created
1256 # -- Whether the Jenkins service account should be able to read Kubernetes secrets
1258 # -- Whether the Jenkins service account should be able to use the OpenShift "nonroot" Security Context Constraints
1259 useOpenShiftNonRootSCC: false
1261 # -- Configures if a ServiceAccount with this name should be created
1263 # The name of the ServiceAccount is autogenerated by default
1264 # -- The name of the ServiceAccount to be used by access-controlled resources
1266 # -- Configures annotations for the ServiceAccount
1268 # -- Configures extra labels for the ServiceAccount
1270 # -- Controller ServiceAccount image pull secret
1271 imagePullSecretName:
1272 # -- Auto-mount ServiceAccount token
1273 automountServiceAccountToken: true
1275 # -- Configures if an agent ServiceAccount should be created
1277 # If not set and create is true, a name is generated using the fullname template
1278 # -- The name of the agent ServiceAccount to be used by access-controlled resources
1280 # -- Configures annotations for the agent ServiceAccount
1282 # -- Configures extra labels for the agent ServiceAccount
1284 # -- Agent ServiceAccount image pull secret
1285 imagePullSecretName:
1286 # -- Auto-mount ServiceAccount token
1287 automountServiceAccountToken: true
1288# -- Checks if any deprecated values are used
1289checkDeprecation: true
1290awsSecurityGroupPolicies:
1294 securityGroupIds: []
1296# Here you can configure unit tests values when executing the helm unittest in the CONTRIBUTING.md
1298 # A testing framework for bash
1300 # Bash Automated Testing System (BATS)
1301 # -- Name of the secret to be used to pull the image
1302 imagePullSecretName: ""
1304 # -- Registry of the image used to test the framework
1305 registry: "docker.io"
1306 # -- Repository of the image used to test the framework
1307 repository: "bats/bats"
1308 # -- Tag of the image to test the framework