DirectorySecurity AdvisoriesPricing
Sign in
Directory
opensearch-operator logoHELM

opensearch-operator

Helm chart
Last changed
Request a free trial

Contact our team to test out this Helm chart and related images for free. Please also indicate any other images you would like to evaluate.

Overview
Chart versions
Default values
Chart metadata
Images

Tag:
Compare:

1
nameOverride: ""
2
fullnameOverride: ""
3
podAnnotations: {}
4
podLabels: {}
5
nodeSelector: {}
6
tolerations: []
7
securityContext:
8
runAsNonRoot: true
9
priorityClassName: ""
10
manager:
11
securityContext:
12
allowPrivilegeEscalation: false
13
extraEnv: []
14
resources:
15
limits:
16
cpu: 1000m
17
memory: 500Mi
18
requests:
19
cpu: 200m
20
memory: 350Mi
21
livenessProbe:
22
failureThreshold: 3
23
httpGet:
24
path: /healthz
25
port: 8081
26
periodSeconds: 15
27
successThreshold: 1
28
timeoutSeconds: 3
29
initialDelaySeconds: 10
30
readinessProbe:
31
failureThreshold: 3
32
httpGet:
33
path: /readyz
34
port: 8081
35
periodSeconds: 15
36
successThreshold: 1
37
timeoutSeconds: 3
38
initialDelaySeconds: 10
39
# Set this to true to enable the standard go pprof endpoints on port 6060 (https://pkg.go.dev/net/http/pprof)
40
# Should only be used for debugging purposes
41
pprofEndpointsEnabled: false
42
image:
43
repository: cgr.dev/chainguard-private/opensearch-k8s-operator-fips
44
## tag default uses appVersion from Chart.yaml, to override specify tag tag: "v1.1"
45
tag: 3.0.0-r1@sha256:dc3afa280e952d7c77ddbdc0f368df460f84a5dc56e64eac8ba65d5850d14512
46
pullPolicy: "Always"
47
## Optional array of imagePullSecrets containing private registry credentials
48
imagePullSecrets: []
49
# - name: secretName
50
51
dnsBase: cluster.local
52
# Log level of the operator. Possible values: debug, info, warn, error
53
loglevel: info
54
# If a watchNamespace is specified, the manager's cache will be restricted to
55
# watch objects in the desired namespace. Defaults is to watch all namespaces.
56
# To watch multiple namespaces, separate them by commas, or define it as a list.
57
# Examples:
58
# watchNamespace: ns1,ns2
59
# watchNamespace: [ns1, ns2]
60
watchNamespace:
61
# -- Global default max concurrent reconciles for all controllers.
62
maxConcurrentReconciles: 1
63
# -- Per-controller overrides (controller name -> max concurrent reconciles). Example: `{opensearchcluster: 4}`.
64
maxConcurrentReconcilesPerController: {}
65
metricsBindAddress: 127.0.0.1:8080
66
# Install the Custom Resource Definitions with Helm
67
installCRDs: true
68
legacyAPI:
69
# -- Enable support for the deprecated `opensearch.opster.io/v1` API group. When false, deprecated CRDs, webhooks, RBAC rules, and manager watches are skipped.
70
enabled: true
71
serviceAccount:
72
# Specifies whether a service account should be created
73
create: true
74
# The name of the service account to use.
75
# If not set and create is true, a name is generated using the fullname template
76
name: ""
77
# kubeRbacProxy has been replaced with controller-runtime's built-in
78
# WithAuthenticationAndAuthorization for metrics endpoint protection.
79
# This provides equivalent security functionality without external dependencies.
80
#
81
# kubeRbacProxy:
82
# enable: false
83
84
## If this is set to true, RoleBindings will be used instead of ClusterRoleBindings, in order to restrict permissions
85
## to the namespace where the operator and OpenSearch cluster are deployed. In that case, specify the namespace in the
86
## manager.watchNamespace field.
87
##
88
## When useRoleBindings is true:
89
## - Manager and proxy roles will be created as namespace-scoped Roles instead of ClusterRoles
90
## - The metrics ClusterRole will NOT be created, as nonResourceURLs (like /metrics) cannot be used in namespace-scoped Roles
91
## - The operator's /metrics endpoint is exposed via kube-apiserver and requires authentication (TokenReviews) and
92
## authorization (SubjectAccessReviews). If you need to access metrics with monitoring tools, you must create the
93
## appropriate ClusterRole and ClusterRoleBinding manually
94
##
95
## If false (default), ClusterRoleBindings will be used and the metrics ClusterRole will be created
96
useRoleBindings: false
97
# Webhook configuration
98
webhook:
99
# Enable validation webhooks
100
enabled: true
101
# Port exposed by the webhook server container
102
port: 9443
103
# Failure policy for webhooks. Options: Fail, Ignore
104
failurePolicy: Fail
105
# Secret name for webhook TLS certificates (used when certManager.enabled is false)
106
# Defaults to: <release-name>-opensearch-operator-webhook-server-cert
107
# If certManager is disabled, you must manually create this secret with:
108
# - tls.crt: The TLS certificate
109
# - tls.key: The TLS private key
110
# - ca.crt: The CA certificate (optional, for client verification)
111
# The certificate should be valid for:
112
# - <release-name>-opensearch-operator-webhook-service.<namespace>.svc
113
# - <release-name>-opensearch-operator-webhook-service.<namespace>.svc.cluster.local
114
secretName: ""
115
# Cert-manager configuration for webhook certificates
116
certManager:
117
# Enable cert-manager for automatic certificate management
118
# If set to false, you must manually create the TLS secret (see webhook.secretName above)
119
enabled: true
120

The trusted source for open source

Talk to an expert
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsChainguard OS PackagesChainguard ActionsChainguard Agent SkillsIntegrationsPricing
© 2026 Chainguard, Inc. All Rights Reserved.
Chainguard® and the Chainguard logo are registered trademarks of Chainguard, Inc. in the United States and/or other countries.
The other respective trademarks mentioned on this page are owned by the respective companies and use of them does not imply any affiliation or endorsement.