1# yaml-language-server: $schema=values.schema.json
2# Default values for alertmanager.
3# This is a YAML-formatted file.
4# Declare variables to be passed into your templates.
7# Number of old history to retain to allow rollback
8# Default Kubernetes value is set to 10
9revisionHistoryLimit: 10
11 repository: cgr.dev/chainguard-private/prometheus-alertmanager
12 pullPolicy: IfNotPresent
13 # Overrides the image tag whose default is the chart appVersion.
14 tag: 0.34.1-r1@sha256:8e540ca56e8d95ff6b80505ca2703c816fab3ee6ef5f12b2021a44117939c722
15# Full external URL where alertmanager is reachable, used for backlinks.
18## Additional Alertmanager Secret mounts
19# Defines additional mounts with secrets. Secrets must be manually created in the namespace.
22# mountPath: /etc/secrets
24# secretName: alertmanager-secret-files
30## namespaceOverride overrides the namespace which the resources will be deployed in
32automountServiceAccountToken: true
33## Running within a user namespace.
34# Kubernetes server must be at or later than version v1.25.
35# Kubernetes v1.25 through to v1.27 recognise UserNamespacesStatelessPodsSupport.
36# Kubernetes v1.28 through to v1.32 need to enable the UserNamespacesSupport feature gate.
39 # Specifies whether a service account should be created
41 # Annotations to add to the service account
43 # The name of the service account to use.
44 # If not set and create is true, a name is generated using the fullname template
46# Sets priorityClassName in alertmanager pod
48# Sets schedulerName in alertmanager pod
56# - ns1.svc.cluster-domain.example
57# - my.dns.search.suffix
72 allowPrivilegeEscalation: false
75 readOnlyRootFilesystem: true
82## Additional InitContainers to initialize the pod
84extraInitContainers: []
85## Additional containers to add to the stateful set. This will allow to setup sidecarContainers like a proxy to integrate
86## alertmanager with an external tool like teams that has not direct integration.
89containerPortName: http
95 initialDelaySeconds: 2
107 loadBalancerIP: "" # Assign ext IP when Service type is LoadBalancer
108 loadBalancerSourceRanges: [] # Only allow access to loadBalancerIP from these IPs
109 # if you want to force a specific nodePort. Must be use with service.type=NodePort
112 # Optionally specify extra list of additional ports exposed on both services
117 ipFamilies: ["IPv6", "IPv4"]
118 ipFamilyPolicy: "PreferDualStack"
119# Configuration for creating a separate Service for each statefulset Alertmanager replica
124 # Loadbalancer source IP ranges
125 # Only used if servicePerReplica.type is "LoadBalancer"
126 loadBalancerSourceRanges: []
127 # Denotes if this Service desires to route external traffic to node-local or cluster-wide endpoints
129 externalTrafficPolicy: Cluster
145 metricRelabelings: []
152 # kubernetes.io/ingress.class: nginx
153 # kubernetes.io/tls-acme: "true"
155 - host: alertmanager.domain.com
158 pathType: ImplementationSpecific
160 # - secretName: chart-example-tls
162 # - alertmanager.domain.com
163# Configuration for creating an Ingress that will map to each Alertmanager replica service
164# alertmanager.servicePerReplica must be enabled
168 # className for the ingresses
173 # Final form of the hostname for each per replica ingress is
174 # {{ ingressPerReplica.hostPrefix }}-{{ $replicaNumber }}.{{ ingressPerReplica.hostDomain }}
176 # Prefix for the per replica ingress that will have `-$replicaNumber`
177 # appended to the end
178 hostPrefix: "alertmanager"
179 # Domain that will be used for the per replica ingress
180 hostDomain: "domain.com"
181 # Paths to use for ingress rules
185 # PathType for ingress rules
187 pathType: ImplementationSpecific
188 # Secret name containing the TLS certificate for alertmanager per replica ingress
189 # Secret must be manually created in the namespace
191 # Separated secret for each per replica Ingress. Can be used together with cert-manager
195 # Final form of the secret for each per replica ingress is
196 # {{ tlsSecretPerReplica.prefix }}-{{ $replicaNumber }}
198 prefix: "alertmanager"
199## route (map) allows configuration of Gateway API HTTPRoute resources
200## Requires Gateway API resources and a suitable controller installed within the cluster
201## Ref. https://gateway-api.sigs.k8s.io/guides/http-routing/
206 ## apiVersion set by default to "gateway.networking.k8s.io/v1"
208 ## kind set by default to HTTPRoute
210 ## Annotations to attach to the HTTPRoute resource
212 ## Labels to attach to the HTTPRoute resource
214 ## ParentRefs references the resources (usually Gateways) this HTTPRoute should be attached to
219 ## Hostnames (templated) defines a set of hostnames that should match against the HTTP Host
220 ## header to select an HTTPRoute used to process the request
222 # - alertmanager.domain.com
224 ## additionalRules (templated) allows adding custom rules to the route
226 ## Filters define the filters that are applied to requests that match this rule
228 ## Matches define conditions used for matching the rule against incoming HTTP requests
233 ## httpsRedirect adds a filter for redirecting to https (HTTP 301 Moved Permanently).
234 ## To redirect HTTP traffic to HTTPS, you need a Gateway with both HTTP and HTTPS listeners.
235 ## Matches and filters do not take effect if enabled.
236 ## Ref. https://gateway-api.sigs.k8s.io/guides/http-redirect-rewrite/
239# We usually recommend not to specify default resources and to leave this as a conscious
240# choice for the user. This also increases chances charts run on environments with little
241# resources, such as Minikube. If you do want to specify resources, uncomment the following
242# lines, adjust them as necessary, and remove the curly braces after 'resources:'.
253## Pod anti-affinity can prevent the scheduler from placing Alertmanager replicas on the same node.
254## The default value "soft" means that the scheduler should *prefer* to not schedule two replica pods onto the same node but no guarantee is provided.
255## The value "hard" means that the scheduler is *required* to not schedule two replica pods onto the same node.
256## The value "" will disable pod anti-affinity so that no anti-affinity rules will be configured.
259## If anti-affinity is enabled sets the topologyKey to use for anti-affinity.
260## This can be changed to, for example, failure-domain.beta.kubernetes.io/zone
262podAntiAffinityTopologyKey: kubernetes.io/hostname
263## Topology spread constraints rely on node labels to identify the topology domain(s) that each Node is in.
264## Ref: https://kubernetes.io/docs/concepts/workloads/pods/pod-topology-spread-constraints/
265topologySpreadConstraints: []
267# topologyKey: failure-domain.beta.kubernetes.io/zone
268# whenUnsatisfiable: DoNotSchedule
271# app.kubernetes.io/instance: alertmanager
276## Minimum number of seconds for which a newly created pod should be ready without any of its container crashing for it to
277## be considered available. Defaults to 0 (pod will be considered available as soon as it is ready).
278## This is an alpha field from kubernetes 1.22 until 1.24 which requires enabling the StatefulSetMinReadySeconds
280## Ref: https://kubernetes.io/docs/concepts/workloads/controllers/statefulset/#minimum-ready-seconds
284# Ref: https://kubernetes.io/docs/tasks/run-application/configure-pdb/
285podDisruptionBudget: {}
291 ## If true, storage will create or use Persistence Volume
292 ## If false, storage will use emptyDir
295 ## Custom annotations for the PVC created by the alertmanager StatefulSet.
296 ## Useful for configuring storage provider options such as disk type, KMS encryption keys, or custom volume name prefixes.
298 ## Custom labels for the PVC created by the alertmanager StatefulSet.
299 ## Useful for selecting, grouping, and organizing so that they can be queried or targeted in deployments, policies, etc.
301 ## Persistent Volume Storage Class
302 ## If defined, storageClassName: <storageClass>
303 ## If set to "-", storageClassName: "", which disables dynamic provisioning
304 ## If undefined (the default) or set to null, no storageClassName spec is
305 ## set, choosing the default provisioner.
311 ## Configure emptyDir volume
315## For example if you want to provide private data from a secret vault
316## https://github.com/banzaicloud/bank-vaults/tree/main/charts/vault-secrets-webhook
317## P.s.: Add option `configMapMutation: true` for vault-secrets-webhook
318# vault.security.banzaicloud.io/vault-role: "admin"
319# vault.security.banzaicloud.io/vault-addr: "https://vault.vault.svc.cluster.local:8200"
320# vault.security.banzaicloud.io/vault-skip-verify: "true"
321# vault.security.banzaicloud.io/vault-path: "kubernetes"
322## Example for inject secret
323# slack_api_url: '${vault:secret/data/slack-hook-alerts#URL}'
331 - '/etc/alertmanager/*.tmpl'
333 - name: default-receiver
336 # send_resolved: true
340 receiver: default-receiver
342## Monitors ConfigMap changes and POSTs to a URL
343## Ref: https://github.com/prometheus-operator/prometheus-operator/tree/main/cmd/prometheus-config-reloader
346 ## If false, the configmap-reload container will not be deployed
349 ## configmap-reload container name
351 name: configmap-reload
352 ## configmap-reload container image
355 repository: cgr.dev/chainguard-private/prometheus-config-reloader
356 tag: 0.94.1-r0@sha256:aa192f1cb69e16c96969dfc15ceb201d48dfca74840bf8ff944327ebd671c06f
357 pullPolicy: IfNotPresent
359 ## configmap-reload resource requests and limits
360 ## Ref: http://kubernetes.io/docs/user-guide/compute-resources/
369 initialDelaySeconds: 2
377 ## Optionally specify extra list of additional volumeMounts
378 extraVolumeMounts: []
380 # mountPath: /usr/share/extras
383 ## Optionally specify extra environment variables to add to alertmanager container
389 allowPrivilegeEscalation: false
392 readOnlyRootFilesystem: true
399# alertmanager.tmpl: |-
401## Optionally specify extra list of additional volumeMounts
404# mountPath: /usr/share/extras
407## Optionally specify extra list of additional volumes
412## Optionally specify extra environment variables to add to alertmanager container
420 "helm.sh/hook": test-success
421 # "helm.sh/hook-delete-policy": "before-hook-creation,hook-succeeded"
422# --- Vertical Pod Autoscaler
423verticalPodAutoscaler:
424 # -- Use VPA for alertmanager
427 # - name: 'alternative'
433 # - containerName: '*'
440 # controlledResources: ["cpu", "memory"]
441# --- Extra Pod Configs
443# dnsPolicy: ClusterFirstWithHostNet