DirectorySecurity AdvisoriesPricing
Sign in
Directory
prometheus-alertmanager logoHELM

prometheus-alertmanager

Helm chart
Last changed
Request a free trial

Contact our team to test out this Helm chart and related images for free. Please also indicate any other images you would like to evaluate.

Overview
Chart versions
Default values
Chart metadata
Images

Tag:
Compare:

1
# yaml-language-server: $schema=values.schema.json
2
# Default values for alertmanager.
3
# This is a YAML-formatted file.
4
# Declare variables to be passed into your templates.
5
6
replicaCount: 1
7
# Number of old history to retain to allow rollback
8
# Default Kubernetes value is set to 10
9
revisionHistoryLimit: 10
10
image:
11
repository: cgr.dev/chainguard-private/prometheus-alertmanager
12
pullPolicy: IfNotPresent
13
# Overrides the image tag whose default is the chart appVersion.
14
tag: 0.34.1-r1@sha256:8e540ca56e8d95ff6b80505ca2703c816fab3ee6ef5f12b2021a44117939c722
15
# Full external URL where alertmanager is reachable, used for backlinks.
16
baseURL: ""
17
extraArgs: {}
18
## Additional Alertmanager Secret mounts
19
# Defines additional mounts with secrets. Secrets must be manually created in the namespace.
20
extraSecretMounts: []
21
# - name: secret-files
22
# mountPath: /etc/secrets
23
# subPath: ""
24
# secretName: alertmanager-secret-files
25
# readOnly: true
26
27
imagePullSecrets: []
28
nameOverride: ""
29
fullnameOverride: ""
30
## namespaceOverride overrides the namespace which the resources will be deployed in
31
namespaceOverride: ""
32
automountServiceAccountToken: true
33
## Running within a user namespace.
34
# Kubernetes server must be at or later than version v1.25.
35
# Kubernetes v1.25 through to v1.27 recognise UserNamespacesStatelessPodsSupport.
36
# Kubernetes v1.28 through to v1.32 need to enable the UserNamespacesSupport feature gate.
37
hostUsers: false
38
serviceAccount:
39
# Specifies whether a service account should be created
40
create: true
41
# Annotations to add to the service account
42
annotations: {}
43
# The name of the service account to use.
44
# If not set and create is true, a name is generated using the fullname template
45
name: ""
46
# Sets priorityClassName in alertmanager pod
47
priorityClassName: ""
48
# Sets schedulerName in alertmanager pod
49
schedulerName: ""
50
podSecurityContext:
51
fsGroup: 65534
52
dnsConfig: {}
53
# nameservers:
54
# - 1.2.3.4
55
# searches:
56
# - ns1.svc.cluster-domain.example
57
# - my.dns.search.suffix
58
# options:
59
# - name: ndots
60
# value: "2"
61
# - name: edns0
62
hostAliases: []
63
# - ip: "127.0.0.1"
64
# hostnames:
65
# - "foo.local"
66
# - "bar.local"
67
# - ip: "10.1.2.3"
68
# hostnames:
69
# - "foo.remote"
70
# - "bar.remote"
71
securityContext:
72
allowPrivilegeEscalation: false
73
capabilities:
74
drop: ["ALL"]
75
readOnlyRootFilesystem: true
76
runAsNonRoot: true
77
runAsUser: 65534
78
runAsGroup: 65534
79
seccompProfile:
80
type: RuntimeDefault
81
additionalPeers: []
82
## Additional InitContainers to initialize the pod
83
##
84
extraInitContainers: []
85
## Additional containers to add to the stateful set. This will allow to setup sidecarContainers like a proxy to integrate
86
## alertmanager with an external tool like teams that has not direct integration.
87
##
88
extraContainers: []
89
containerPortName: http
90
livenessProbe:
91
httpGet:
92
path: /-/healthy
93
port: http
94
periodSeconds: 10
95
initialDelaySeconds: 2
96
readinessProbe:
97
httpGet:
98
path: /-/ready
99
port: http
100
periodSeconds: 10
101
service:
102
annotations: {}
103
labels: {}
104
type: ClusterIP
105
port: 9093
106
clusterPort: 9094
107
loadBalancerIP: "" # Assign ext IP when Service type is LoadBalancer
108
loadBalancerSourceRanges: [] # Only allow access to loadBalancerIP from these IPs
109
# if you want to force a specific nodePort. Must be use with service.type=NodePort
110
# nodePort:
111
112
# Optionally specify extra list of additional ports exposed on both services
113
extraPorts: []
114
# ip dual stack
115
ipDualStack:
116
enabled: false
117
ipFamilies: ["IPv6", "IPv4"]
118
ipFamilyPolicy: "PreferDualStack"
119
# Configuration for creating a separate Service for each statefulset Alertmanager replica
120
#
121
servicePerReplica:
122
enabled: false
123
annotations: {}
124
# Loadbalancer source IP ranges
125
# Only used if servicePerReplica.type is "LoadBalancer"
126
loadBalancerSourceRanges: []
127
# Denotes if this Service desires to route external traffic to node-local or cluster-wide endpoints
128
#
129
externalTrafficPolicy: Cluster
130
# Service type
131
#
132
type: ClusterIP
133
serviceMonitor:
134
enabled: false
135
namespace: ""
136
additionalLabels: {}
137
interval: ""
138
scrapeTimeout: ""
139
path: /metrics
140
scheme: ""
141
tlsConfig: {}
142
bearerTokenFile: ""
143
basicAuth: {}
144
honorLabels: false
145
metricRelabelings: []
146
relabelings: []
147
ingress:
148
enabled: false
149
className: ""
150
labels: {}
151
annotations: {}
152
# kubernetes.io/ingress.class: nginx
153
# kubernetes.io/tls-acme: "true"
154
hosts:
155
- host: alertmanager.domain.com
156
paths:
157
- path: /
158
pathType: ImplementationSpecific
159
tls: []
160
# - secretName: chart-example-tls
161
# hosts:
162
# - alertmanager.domain.com
163
# Configuration for creating an Ingress that will map to each Alertmanager replica service
164
# alertmanager.servicePerReplica must be enabled
165
#
166
ingressPerReplica:
167
enabled: false
168
# className for the ingresses
169
#
170
className: ""
171
annotations: {}
172
labels: {}
173
# Final form of the hostname for each per replica ingress is
174
# {{ ingressPerReplica.hostPrefix }}-{{ $replicaNumber }}.{{ ingressPerReplica.hostDomain }}
175
#
176
# Prefix for the per replica ingress that will have `-$replicaNumber`
177
# appended to the end
178
hostPrefix: "alertmanager"
179
# Domain that will be used for the per replica ingress
180
hostDomain: "domain.com"
181
# Paths to use for ingress rules
182
#
183
paths:
184
- /
185
# PathType for ingress rules
186
#
187
pathType: ImplementationSpecific
188
# Secret name containing the TLS certificate for alertmanager per replica ingress
189
# Secret must be manually created in the namespace
190
tlsSecretName: ""
191
# Separated secret for each per replica Ingress. Can be used together with cert-manager
192
#
193
tlsSecretPerReplica:
194
enabled: false
195
# Final form of the secret for each per replica ingress is
196
# {{ tlsSecretPerReplica.prefix }}-{{ $replicaNumber }}
197
#
198
prefix: "alertmanager"
199
## route (map) allows configuration of Gateway API HTTPRoute resources
200
## Requires Gateway API resources and a suitable controller installed within the cluster
201
## Ref. https://gateway-api.sigs.k8s.io/guides/http-routing/
202
route:
203
main:
204
## Enable this route
205
enabled: false
206
## apiVersion set by default to "gateway.networking.k8s.io/v1"
207
apiVersion: ""
208
## kind set by default to HTTPRoute
209
kind: ""
210
## Annotations to attach to the HTTPRoute resource
211
annotations: {}
212
## Labels to attach to the HTTPRoute resource
213
labels: {}
214
## ParentRefs references the resources (usually Gateways) this HTTPRoute should be attached to
215
parentRefs: []
216
# - name: contour
217
# sectionName: http
218
219
## Hostnames (templated) defines a set of hostnames that should match against the HTTP Host
220
## header to select an HTTPRoute used to process the request
221
hostnames: []
222
# - alertmanager.domain.com
223
224
## additionalRules (templated) allows adding custom rules to the route
225
additionalRules: []
226
## Filters define the filters that are applied to requests that match this rule
227
filters: []
228
## Matches define conditions used for matching the rule against incoming HTTP requests
229
matches:
230
- path:
231
type: PathPrefix
232
value: /
233
## httpsRedirect adds a filter for redirecting to https (HTTP 301 Moved Permanently).
234
## To redirect HTTP traffic to HTTPS, you need a Gateway with both HTTP and HTTPS listeners.
235
## Matches and filters do not take effect if enabled.
236
## Ref. https://gateway-api.sigs.k8s.io/guides/http-redirect-rewrite/
237
httpsRedirect: false
238
resources: {}
239
# We usually recommend not to specify default resources and to leave this as a conscious
240
# choice for the user. This also increases chances charts run on environments with little
241
# resources, such as Minikube. If you do want to specify resources, uncomment the following
242
# lines, adjust them as necessary, and remove the curly braces after 'resources:'.
243
# limits:
244
# cpu: 100m
245
# memory: 128Mi
246
# requests:
247
# cpu: 10m
248
# memory: 32Mi
249
250
nodeSelector: {}
251
tolerations: []
252
affinity: {}
253
## Pod anti-affinity can prevent the scheduler from placing Alertmanager replicas on the same node.
254
## The default value "soft" means that the scheduler should *prefer* to not schedule two replica pods onto the same node but no guarantee is provided.
255
## The value "hard" means that the scheduler is *required* to not schedule two replica pods onto the same node.
256
## The value "" will disable pod anti-affinity so that no anti-affinity rules will be configured.
257
##
258
podAntiAffinity: ""
259
## If anti-affinity is enabled sets the topologyKey to use for anti-affinity.
260
## This can be changed to, for example, failure-domain.beta.kubernetes.io/zone
261
##
262
podAntiAffinityTopologyKey: kubernetes.io/hostname
263
## Topology spread constraints rely on node labels to identify the topology domain(s) that each Node is in.
264
## Ref: https://kubernetes.io/docs/concepts/workloads/pods/pod-topology-spread-constraints/
265
topologySpreadConstraints: []
266
# - maxSkew: 1
267
# topologyKey: failure-domain.beta.kubernetes.io/zone
268
# whenUnsatisfiable: DoNotSchedule
269
# labelSelector:
270
# matchLabels:
271
# app.kubernetes.io/instance: alertmanager
272
273
statefulSet:
274
labels: {}
275
annotations: {}
276
## Minimum number of seconds for which a newly created pod should be ready without any of its container crashing for it to
277
## be considered available. Defaults to 0 (pod will be considered available as soon as it is ready).
278
## This is an alpha field from kubernetes 1.22 until 1.24 which requires enabling the StatefulSetMinReadySeconds
279
## feature gate.
280
## Ref: https://kubernetes.io/docs/concepts/workloads/controllers/statefulset/#minimum-ready-seconds
281
minReadySeconds: 0
282
podAnnotations: {}
283
podLabels: {}
284
# Ref: https://kubernetes.io/docs/tasks/run-application/configure-pdb/
285
podDisruptionBudget: {}
286
# maxUnavailable: 1
287
# minAvailable: 1
288
289
command: []
290
persistence:
291
## If true, storage will create or use Persistence Volume
292
## If false, storage will use emptyDir
293
##
294
enabled: true
295
## Custom annotations for the PVC created by the alertmanager StatefulSet.
296
## Useful for configuring storage provider options such as disk type, KMS encryption keys, or custom volume name prefixes.
297
annotations: {}
298
## Custom labels for the PVC created by the alertmanager StatefulSet.
299
## Useful for selecting, grouping, and organizing so that they can be queried or targeted in deployments, policies, etc.
300
labels: {}
301
## Persistent Volume Storage Class
302
## If defined, storageClassName: <storageClass>
303
## If set to "-", storageClassName: "", which disables dynamic provisioning
304
## If undefined (the default) or set to null, no storageClassName spec is
305
## set, choosing the default provisioner.
306
##
307
# storageClass: "-"
308
accessModes:
309
- ReadWriteOnce
310
size: 50Mi
311
## Configure emptyDir volume
312
##
313
emptyDir: {}
314
configAnnotations: {}
315
## For example if you want to provide private data from a secret vault
316
## https://github.com/banzaicloud/bank-vaults/tree/main/charts/vault-secrets-webhook
317
## P.s.: Add option `configMapMutation: true` for vault-secrets-webhook
318
# vault.security.banzaicloud.io/vault-role: "admin"
319
# vault.security.banzaicloud.io/vault-addr: "https://vault.vault.svc.cluster.local:8200"
320
# vault.security.banzaicloud.io/vault-skip-verify: "true"
321
# vault.security.banzaicloud.io/vault-path: "kubernetes"
322
## Example for inject secret
323
# slack_api_url: '${vault:secret/data/slack-hook-alerts#URL}'
324
325
config:
326
enabled: true
327
global: {}
328
# slack_api_url: ''
329
330
templates:
331
- '/etc/alertmanager/*.tmpl'
332
receivers:
333
- name: default-receiver
334
# slack_configs:
335
# - channel: '@you'
336
# send_resolved: true
337
route:
338
group_wait: 10s
339
group_interval: 5m
340
receiver: default-receiver
341
repeat_interval: 3h
342
## Monitors ConfigMap changes and POSTs to a URL
343
## Ref: https://github.com/prometheus-operator/prometheus-operator/tree/main/cmd/prometheus-config-reloader
344
##
345
configmapReload:
346
## If false, the configmap-reload container will not be deployed
347
##
348
enabled: true
349
## configmap-reload container name
350
##
351
name: configmap-reload
352
## configmap-reload container image
353
##
354
image:
355
repository: cgr.dev/chainguard-private/prometheus-config-reloader
356
tag: 0.94.1-r0@sha256:aa192f1cb69e16c96969dfc15ceb201d48dfca74840bf8ff944327ebd671c06f
357
pullPolicy: IfNotPresent
358
containerPort: 8080
359
## configmap-reload resource requests and limits
360
## Ref: http://kubernetes.io/docs/user-guide/compute-resources/
361
##
362
resources: {}
363
livenessProbe:
364
httpGet:
365
path: /healthz
366
port: metrics
367
scheme: HTTP
368
periodSeconds: 10
369
initialDelaySeconds: 2
370
readinessProbe:
371
httpGet:
372
path: /healthz
373
port: metrics
374
scheme: HTTP
375
periodSeconds: 10
376
extraArgs: {}
377
## Optionally specify extra list of additional volumeMounts
378
extraVolumeMounts: []
379
# - name: extras
380
# mountPath: /usr/share/extras
381
# readOnly: true
382
383
## Optionally specify extra environment variables to add to alertmanager container
384
extraEnv: []
385
# - name: FOO
386
# value: BAR
387
388
securityContext:
389
allowPrivilegeEscalation: false
390
capabilities:
391
drop: ["ALL"]
392
readOnlyRootFilesystem: true
393
runAsNonRoot: true
394
runAsUser: 65534
395
runAsGroup: 65534
396
seccompProfile:
397
type: RuntimeDefault
398
templates: {}
399
# alertmanager.tmpl: |-
400
401
## Optionally specify extra list of additional volumeMounts
402
extraVolumeMounts: []
403
# - name: extras
404
# mountPath: /usr/share/extras
405
# readOnly: true
406
407
## Optionally specify extra list of additional volumes
408
extraVolumes: []
409
# - name: extras
410
# emptyDir: {}
411
412
## Optionally specify extra environment variables to add to alertmanager container
413
extraEnv: []
414
# - name: FOO
415
# value: BAR
416
417
testFramework:
418
enabled: false
419
annotations:
420
"helm.sh/hook": test-success
421
# "helm.sh/hook-delete-policy": "before-hook-creation,hook-succeeded"
422
# --- Vertical Pod Autoscaler
423
verticalPodAutoscaler:
424
# -- Use VPA for alertmanager
425
enabled: false
426
# recommenders:
427
# - name: 'alternative'
428
# updatePolicy:
429
# updateMode: "Auto"
430
# minReplicas: 1
431
# resourcePolicy:
432
# containerPolicies:
433
# - containerName: '*'
434
# minAllowed:
435
# cpu: 100m
436
# memory: 128Mi
437
# maxAllowed:
438
# cpu: 1
439
# memory: 500Mi
440
# controlledResources: ["cpu", "memory"]
441
# --- Extra Pod Configs
442
extraPodConfigs: {}
443
# dnsPolicy: ClusterFirstWithHostNet
444
# hostNetwork: true
445

The trusted source for open source

Talk to an expert
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsChainguard OS PackagesChainguard ActionsChainguard Agent SkillsIntegrationsPricing
© 2026 Chainguard, Inc. All Rights Reserved.
Chainguard® and the Chainguard logo are registered trademarks of Chainguard, Inc. in the United States and/or other countries.
The other respective trademarks mentioned on this page are owned by the respective companies and use of them does not imply any affiliation or endorsement.