DirectorySecurity AdvisoriesPricing
Sign in
Directory
tempo-distributed logoHELM

tempo-distributed

Helm chart
Last changed
Request a free trial

Contact our team to test out this Helm chart and related images for free. Please also indicate any other images you would like to evaluate.

Overview
Chart tags
Default values
Chart metadata
Images

Tag:
Compare:

1
global:
2
image:
3
# -- Overrides the Docker registry globally for all images, excluding enterprise.
4
registry: docker.io
5
# -- Optional list of imagePullSecrets for all images, excluding enterprise.
6
# Names of existing secrets with private container registry credentials.
7
# Ref: https://kubernetes.io/docs/concepts/containers/images/#specifying-imagepullsecrets-on-a-pod
8
# Example:
9
# pullSecrets: [ my-dockerconfigjson-secret ]
10
pullSecrets: []
11
# -- Adding common labels to all K8S resources including pods
12
commonLabels: {}
13
# -- Adding labels to K8S resources (excluding pods)
14
labels: {}
15
# -- Adding labels to all pods
16
podLabels: {}
17
# -- Overrides the priorityClassName for all pods
18
priorityClassName: null
19
# -- configures cluster domain ("cluster.local" by default)
20
clusterDomain: 'cluster.local'
21
# -- configures DNS service name
22
dnsService: 'kube-dns'
23
# -- configures DNS service namespace
24
dnsNamespace: 'kube-system'
25
goSettings:
26
# -- Fraction of the container memory limit used to compute GOMEMLIMIT (e.g. 0.85 = 85%).
27
# Set to 0 to disable automatic GOMEMLIMIT injection.
28
goMemLimitFactor: 0.85
29
# -- Value to set for GOGC alongside GOMEMLIMIT. Lowering below the default of 100 reduces
30
# heap growth between GC cycles, working in tandem with GOMEMLIMIT to smooth memory usage.
31
# Set to 0 to disable automatic GOGC injection.
32
gogc: 80
33
# -- Common environment variables to add to all pods directly managed by this chart.
34
# scope: admin-api, compactor, distributor, enterprise-federation-frontend, gateway, ingester, memcached, metrics-generator, querier, query-frontend, tokengen
35
extraEnv: []
36
# -- Common environment variables which come from a ConfigMap or Secret to add to all pods directly managed by this chart.
37
# scope: admin-api, compactor, distributor, enterprise-federation-frontend, gateway, ingester, memcached, metrics-generator, querier, query-frontend, tokengen
38
extraEnvFrom: []
39
# -- Common args to add to all pods directly managed by this chart.
40
# scope: admin-api, compactor, distributor, enterprise-federation-frontend, gateway, ingester, memcached, metrics-generator, querier, query-frontend, tokengen
41
extraArgs: []
42
# -- Global storage class to be used for persisted components
43
storageClass: null
44
fullnameOverride: ''
45
# fullnameOverride: tempo
46
47
# -- Configuration is loaded from the secret called 'externalConfigSecretName'.
48
# If 'useExternalConfig' is true, then the configuration is not generated, just
49
# consumed. Top level keys for `tempo.yaml` and `overrides.yaml` are to be
50
# provided by the user.
51
useExternalConfig: false
52
# -- Defines what kind of object stores the configuration, a ConfigMap or a Secret.
53
# In order to move sensitive information (such as credentials) from the ConfigMap/Secret to a more secure location (e.g. vault), it is possible to use [environment variables in the configuration](https://grafana.com/docs/mimir/latest/operators-guide/configuring/reference-configuration-parameters/#use-environment-variables-in-the-configuration).
54
# Such environment variables can be then stored in a separate Secret and injected via the global.extraEnvFrom value. For details about environment injection from a Secret please see [Secrets](https://kubernetes.io/docs/concepts/configuration/secret/#use-case-as-container-environment-variables).
55
configStorageType: ConfigMap
56
# -- Name of the Secret or ConfigMap that contains the configuration (used for naming even if config is internal).
57
externalConfigSecretName: '{{ include "tempo.resourceName" (dict "ctx" . "component" "config") }}'
58
# -- Name of the Secret or ConfigMap that contains the runtime configuration (used for naming even if config is internal).
59
externalRuntimeConfigName: '{{ include "tempo.resourceName" (dict "ctx" . "component" "runtime") }}'
60
# -- When 'useExternalConfig' is true, then changing 'externalConfigVersion' triggers restart of services - otherwise changes to the configuration cause a restart.
61
externalConfigVersion: '0'
62
# -- If true, Tempo will report anonymous usage data about the shape of a deployment to Grafana Labs
63
reportingEnabled: true
64
# -- Enable streaming over HTTP for tempo and Tempo gateway(nginx)
65
streamOverHTTPEnabled: false
66
tempo:
67
# -- Pod DNS config applied to all components. Override per component with `<component>.dnsConfig` or `defaults.dnsConfig`.
68
dnsConfig: {}
69
image:
70
# -- The Docker registry. Overrides `global.image.registry`
71
registry: cgr.dev
72
# -- Optional list of imagePullSecrets. Overrides `global.image.pullSecrets`
73
pullSecrets: []
74
# -- Docker image repository
75
repository: chainguard-private/tempo
76
# -- Overrides the image tag whose default is the chart's appVersion
77
tag: 3.0.3-r8@sha256:3afa2b3dbcf20b0c476cd05c7fc68a4bb30f64d92439fed7b1ba403662ce5349
78
pullPolicy: IfNotPresent
79
livenessProbe:
80
httpGet:
81
path: /ready
82
port: http-metrics
83
initialDelaySeconds: 60
84
timeoutSeconds: 5
85
readinessProbe:
86
httpGet:
87
path: /ready
88
port: http-metrics
89
initialDelaySeconds: 30
90
timeoutSeconds: 1
91
# -- Startup probe for all Tempo binary pods. Disabled by default.
92
startupProbe: {}
93
# -- Global labels for all tempo pods
94
podLabels: {}
95
# -- Common annotations for all pods
96
podAnnotations: {}
97
# -- The number of old ReplicaSets to retain to allow rollback
98
revisionHistoryLimit: 10
99
# -- SecurityContext holds container-level security attributes and common container settings
100
securityContext:
101
runAsNonRoot: true
102
runAsUser: 1000
103
runAsGroup: 1000
104
allowPrivilegeEscalation: false
105
capabilities:
106
drop:
107
- ALL
108
readOnlyRootFilesystem: true
109
# -- podSecurityContext holds pod-level security attributes and common container settings
110
podSecurityContext:
111
fsGroup: 1000
112
# -- Structured tempo configuration
113
structuredConfig: {}
114
# -- Memberlist service configuration.
115
memberlist:
116
# -- Adds the appProtocol field to the memberlist service. This allows memberlist to work with istio protocol selection. Set the optional service protocol. Ex: "tcp", "http" or "https".
117
appProtocol: null
118
# -- Adds the service field to the memberlist service
119
service:
120
# -- Sets optional annotations to the service field of the memberlist service.
121
annotations: {}
122
service:
123
# -- Configure the IP families for all tempo services
124
# See the Service spec for details: https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.31/#servicespec-v1-core
125
ipFamilies:
126
- 'IPv4'
127
# - 'IPv6'
128
# -- Configure the IP family policy for all tempo services. SingleStack, PreferDualStack or RequireDualStack
129
ipFamilyPolicy: 'SingleStack'
130
# -- Default traffic distribution for all non-headless tempo services (PreferSameZone or PreferSameNode).
131
# See https://kubernetes.io/docs/concepts/services-networking/service/#traffic-distribution.
132
# Can be overridden per component via <component>.service.trafficDistribution.
133
trafficDistribution: null
134
# -- Point the live-store, block-builder, backend-scheduler, backend-worker and
135
# metrics-generator StatefulSets at the headless Service of their own component as the
136
# governing service, and publish the not-ready addresses of those Services. The default
137
# `false` keeps the short, unprefixed name that the chart has always written. That name
138
# matches no Service, so the stable per-pod DNS names do not resolve. The memcached
139
# StatefulSets already write the full resource name and are not affected.
140
# `spec.serviceName` is immutable, and a pod takes its subdomain at creation only. Enable
141
# this only together with the manual StatefulSet delete and the pod restart described
142
# under `Upgrading` in the chart README.
143
useHeadlessGoverningService: false
144
# -- Default values applied to every pod in this chart.
145
# These values are overridden by component-specific settings.
146
defaults:
147
# -- Default pod DNS config for all pods. Overridden per component by `<component>.dnsConfig`; falls back to `tempo.dnsConfig`.
148
dnsConfig: {}
149
# -- Default pod-level security context for all pods
150
podSecurityContext: {}
151
# -- Default container-level security context for all containers
152
containerSecurityContext: {}
153
# -- Default annotations for all pods
154
podAnnotations: {}
155
# -- Default labels for all pods
156
podLabels: {}
157
# -- Default node selector for all pods
158
nodeSelector: {}
159
# -- Default tolerations for all pods
160
tolerations: []
161
# -- Default affinity for all pods
162
affinity: {}
163
# -- Default priority class name for all pods
164
priorityClassName: ""
165
# -- Default resource requests and limits for all pods
166
resources: {}
167
# -- Default extra CLI args for all Tempo binary pods
168
extraArgs: []
169
# -- Default extra environment variables for all pods
170
extraEnv: []
171
# -- Default extra environment variables from ConfigMaps or Secrets for all pods
172
extraEnvFrom: []
173
# -- Default extra volume mounts for all pods
174
extraVolumeMounts: []
175
# -- Default extra volumes for all pods
176
extraVolumes: []
177
# -- Default liveness probe for all Tempo binary pods. Overridden by `tempo.livenessProbe` and `<component>.livenessProbe`.
178
livenessProbe: {}
179
# -- Default readiness probe for all Tempo binary pods. Overridden by `tempo.readinessProbe` and `<component>.readinessProbe`.
180
readinessProbe: {}
181
# -- Default startup probe for all Tempo binary pods. Overridden by `tempo.startupProbe` and `<component>.startupProbe`.
182
startupProbe: {}
183
serviceAccount:
184
# -- Specifies whether a ServiceAccount should be created
185
create: true
186
# -- The name of the ServiceAccount to use.
187
# If not set and create is true, a name is generated using the fullname template
188
name: null
189
# -- Image pull secrets for the service account
190
imagePullSecrets: []
191
# -- Labels for the service account
192
labels: {}
193
# -- Annotations for the service account
194
annotations: {}
195
automountServiceAccountToken: false
196
rbac:
197
# -- Specifies whether RBAC manifests should be created
198
create: false
199
# Configuration for the metrics-generator
200
metricsGenerator:
201
# -- Specifies whether a metrics-generator should be deployed
202
enabled: false
203
# -- Kind of deployment [StatefulSet/Deployment]
204
kind: Deployment
205
# -- Annotations for the metrics-generator StatefulSet
206
annotations: {}
207
# -- Number of replicas for the metrics-generator
208
replicas: 1
209
# -- hostAliases to add
210
hostAliases: []
211
# - ip: 1.2.3.4
212
# hostnames:
213
# - domain.tld
214
# -- Pod DNS config for this component. Falls back to `defaults.dnsConfig`, then `tempo.dnsConfig`.
215
dnsConfig: {}
216
# -- Init containers for the metrics generator pod
217
initContainers: []
218
image:
219
# -- The Docker registry for the metrics-generator image. Overrides `tempo.image.registry`
220
registry: null
221
# -- Optional list of imagePullSecrets. Overrides `tempo.image.pullSecrets`
222
pullSecrets: []
223
# -- Docker image repository for the metrics-generator image. Overrides `tempo.image.repository`
224
repository: null
225
# -- Docker image tag for the metrics-generator image. Overrides `tempo.image.tag`
226
tag: null
227
# -- The name of the PriorityClass for metrics-generator pods
228
priorityClassName: null
229
# -- Labels for metrics-generator pods
230
podLabels: {}
231
# -- Annotations for metrics-generator pods
232
podAnnotations: {}
233
# -- Additional CLI args for the metrics-generator
234
extraArgs: []
235
# -- Environment variables to add to the metrics-generator pods
236
extraEnv: []
237
# -- Environment variables from secrets or configmaps to add to the metrics-generator pods
238
extraEnvFrom: []
239
# -- Startup probe for metrics-generator pods. Uses `tempo.startupProbe` as default if not set.
240
startupProbe: {}
241
# -- Resource requests and limits for the metrics-generator
242
resources: {}
243
# -- Grace period to allow the metrics-generator to shutdown before it is killed. Especially for the ingestor,
244
# this must be increased. It must be long enough so metrics-generators can be gracefully shutdown flushing/transferring
245
# all data and to successfully leave the member ring on shutdown.
246
terminationGracePeriodSeconds: 300
247
# -- topologySpread for metrics-generator pods. Passed through `tpl` and, thus, to be configured as string
248
# @default -- Defaults to allow skew no more then 1 node per AZ
249
topologySpreadConstraints: |
250
- maxSkew: 1
251
topologyKey: topology.kubernetes.io/zone
252
whenUnsatisfiable: ScheduleAnyway
253
labelSelector:
254
matchLabels:
255
{{- include "tempo.selectorLabels" (dict "ctx" . "component" "metrics-generator") | nindent 6 }}
256
# -- Affinity for metrics-generator pods. Passed through `tpl` and, thus, to be configured as string
257
# @default -- Hard node and soft zone anti-affinity
258
affinity: |
259
podAntiAffinity:
260
requiredDuringSchedulingIgnoredDuringExecution:
261
- labelSelector:
262
matchLabels:
263
{{- include "tempo.selectorLabels" (dict "ctx" . "component" "metrics-generator") | nindent 10 }}
264
topologyKey: kubernetes.io/hostname
265
preferredDuringSchedulingIgnoredDuringExecution:
266
- weight: 100
267
podAffinityTerm:
268
labelSelector:
269
matchLabels:
270
{{- include "tempo.selectorLabels" (dict "ctx" . "component" "metrics-generator") | nindent 12 }}
271
topologyKey: topology.kubernetes.io/zone
272
# -- Pod Disruption Budget configuration
273
podDisruptionBudget:
274
# -- Enable PodDisruptionBudget for metrics-generator
275
enabled: true
276
# -- Set unhealthyPodEvictionPolicy for the metrics-generator PodDisruptionBudget. Requires policy/v1.
277
unhealthyPodEvictionPolicy: ""
278
# -- Pod Disruption Budget maxUnavailable
279
maxUnavailable: 1
280
# -- Minimum number of seconds for which a newly created Pod should be ready without any of its containers crashing/terminating
281
minReadySeconds: 10
282
# -- Node selector for metrics-generator pods
283
nodeSelector: {}
284
# -- Tolerations for metrics-generator pods
285
tolerations: []
286
# -- Persistence configuration for metrics-generator
287
persistence:
288
# -- Enable creating PVCs if you have kind set to StatefulSet. This disables using local disk or memory configured in walEmptyDir
289
enabled: false
290
# -- Enable StatefulSetRecreation for changes to PVC size.
291
# This means that the StatefulSet will be deleted, recreated (with the same name) and rolled when a change to the
292
# PVC size is detected. That way the PVC can be resized without manual intervention.
293
enableStatefulSetRecreationForSizeChange: false
294
size: 10Gi
295
# -- Storage class to be used.
296
# If defined, storageClassName: <storageClass>.
297
# If set to "-", storageClassName: "", which disables dynamic provisioning.
298
# If empty or set to null, no storageClassName spec is
299
# set, choosing the default provisioner (gp2 on AWS, standard on GKE, AWS, and OpenStack).
300
storageClass: null
301
# -- Annotations for metrics generator PVCs
302
annotations: {}
303
# -- Labels for metrics generator PVCs
304
labels: {}
305
# -- The EmptyDir location where the /var/tempo will be mounted on. Defaults to local disk, can be set to memory.
306
walEmptyDir: {}
307
## Here shows how to configure 1Gi memory as emptyDir.
308
## Ref: https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.19/#emptydirvolumesource-v1-core
309
# medium: "Memory"
310
# sizeLimit: 1Gi
311
# -- Extra volumes for metrics-generator pods
312
extraVolumeMounts: []
313
# -- Extra volumes for metrics-generator deployment
314
extraVolumes: []
315
# -- Containers to add to the metrics-generator pods
316
extraContainers: []
317
persistentVolumeClaimRetentionPolicy:
318
# -- Enable Persistent volume retention policy for StatefulSet
319
enabled: false
320
# -- Volume retention behavior when the replica count of the StatefulSet is reduced
321
whenScaled: Retain
322
# -- Volume retention behavior that applies when the StatefulSet is deleted
323
whenDeleted: Retain
324
# -- Default ports
325
ports:
326
- name: grpc
327
port: 9095
328
service: true
329
- name: http-memberlist
330
port: 7946
331
service: false
332
- name: http-metrics
333
port: 3200
334
service: true
335
# -- More information on configuration: https://grafana.com/docs/tempo/latest/configuration/#metrics-generator
336
config:
337
registry:
338
collection_interval: 15s
339
external_labels: {}
340
stale_duration: 15m
341
processor:
342
# -- For processors to be enabled and generate metrics, pass the names of the processors to `overrides.defaults.metrics_generator.processors` value like `[service-graphs, span-metrics]`.
343
service_graphs:
344
# -- Additional dimensions to add to the metrics along with the default dimensions.
345
# -- The resource and span attributes to be added to the service graph metrics, if present.
346
dimensions: []
347
histogram_buckets: [0.1, 0.2, 0.4, 0.8, 1.6, 3.2, 6.4, 12.8]
348
max_items: 10000
349
wait: 10s
350
workers: 10
351
span_metrics:
352
# -- Additional dimensions to add to the metrics along with the default dimensions.
353
# -- The resource and span attributes to be added to the span metrics, if present.
354
dimensions: []
355
histogram_buckets: [0.002, 0.004, 0.008, 0.016, 0.032, 0.064, 0.128, 0.256, 0.512, 1.02, 2.05, 4.10]
356
storage:
357
path: /var/tempo/wal
358
wal:
359
remote_write_flush_deadline: 1m
360
# Whether to add X-Scope-OrgID header in remote write requests
361
remote_write_add_org_id_header: true
362
# -- A list of remote write endpoints.
363
# -- https://prometheus.io/docs/prometheus/latest/configuration/configuration/#remote_write
364
remote_write: []
365
# -- Used by the local blocks processor to store a wal for traces.
366
metrics_ingestion_time_range_slack: 30s
367
service:
368
# -- Annotations for Metrics Generator service
369
annotations: {}
370
# -- Traffic distribution for the Metrics Generator service (PreferSameZone or PreferSameNode). Overrides tempo.service.trafficDistribution.
371
trafficDistribution: null
372
serviceDiscovery:
373
# -- Annotations for Metrics Generator discovery service
374
annotations: {}
375
# -- Adds the appProtocol field to the metricsGenerator service. This allows metricsGenerator to work with istio protocol selection.
376
appProtocol:
377
# -- Set the optional gRPC service protocol. Ex: "grpc", "http2" or "https"
378
grpc: null
379
# Configuration for the distributor
380
distributor:
381
# -- Number of replicas for the distributor
382
replicas: 1
383
# -- Annotations for distributor deployment
384
annotations: {}
385
# -- hostAliases to add
386
hostAliases: []
387
# - ip: 1.2.3.4
388
# hostnames:
389
# - domain.tld
390
# -- Pod DNS config for this component. Falls back to `defaults.dnsConfig`, then `tempo.dnsConfig`.
391
dnsConfig: {}
392
autoscaling:
393
# -- Enable autoscaling for the distributor
394
enabled: false
395
# -- Minimum autoscaling replicas for the distributor
396
minReplicas: 1
397
# -- Maximum autoscaling replicas for the distributor
398
maxReplicas: 3
399
# -- Autoscaling behavior configuration for the distributor
400
behavior: {}
401
# -- Target CPU utilisation percentage for the distributor
402
targetCPUUtilizationPercentage: 60
403
# -- Target memory utilisation percentage for the distributor
404
targetMemoryUtilizationPercentage:
405
image:
406
# -- The Docker registry for the distributor image. Overrides `tempo.image.registry`
407
registry: null
408
# -- Optional list of imagePullSecrets. Overrides `tempo.image.pullSecrets`
409
pullSecrets: []
410
# -- Docker image repository for the distributor image. Overrides `tempo.image.repository`
411
repository: null
412
# -- Docker image tag for the distributor image. Overrides `tempo.image.tag`
413
tag: null
414
service:
415
# -- Annotations for distributor service
416
annotations: {}
417
# -- Labels for distributor service
418
labels: {}
419
# -- Type of service for the distributor
420
type: ClusterIP
421
# -- If type is LoadBalancer you can assign the IP to the LoadBalancer
422
loadBalancerIP: ''
423
# -- If type is LoadBalancer limit incoming traffic from IPs.
424
loadBalancerSourceRanges: []
425
# -- If type is LoadBalancer you can set it to 'Local' [preserve the client source IP](https://kubernetes.io/docs/tasks/access-application-cluster/create-external-load-balancer/#preserving-the-client-source-ip)
426
externalTrafficPolicy: null
427
# -- https://kubernetes.io/docs/concepts/services-networking/service-traffic-policy/
428
internalTrafficPolicy: Cluster
429
# -- Traffic distribution for the distributor service (PreferSameZone or PreferSameNode). Overrides tempo.service.trafficDistribution.
430
trafficDistribution: null
431
serviceDiscovery:
432
# -- Annotations for distributorDiscovery service
433
annotations: {}
434
# -- Labels for distributorDiscovery service
435
labels: {}
436
# -- The name of the PriorityClass for distributor pods
437
priorityClassName: null
438
# -- Labels for distributor pods
439
podLabels: {}
440
# -- Annotations for distributor pods
441
podAnnotations: {}
442
# -- Additional CLI args for the distributor
443
extraArgs: []
444
# -- Environment variables to add to the distributor pods
445
extraEnv: []
446
# -- Environment variables from secrets or configmaps to add to the distributor pods
447
extraEnvFrom: []
448
# -- Init containers to add to the distributor pods
449
initContainers: []
450
# -- Containers to add to the distributor pod
451
extraContainers: []
452
# -- Additional ports to expose on the distributor container (e.g. trace receiver ports).
453
# Standard ports (http-metrics, http-memberlist) are always added automatically.
454
extraPorts: []
455
# -- Liveness probe for distributor pods. Uses `tempo.livenessProbe` as default if not set.
456
livenessProbe: {}
457
# -- Readiness probe for distributor pods. Uses `tempo.readinessProbe` as default if not set.
458
readinessProbe: {}
459
# -- Startup probe for distributor pods. Uses `tempo.startupProbe` as default if not set.
460
startupProbe: {}
461
# -- Resource requests and limits for the distributor
462
resources: {}
463
# -- On SIGTERM, report not-ready and wait this long before shutdown so the LB drains the pod before connections are cut.
464
# "0s" (default) disables. When enabling, keep terminationGracePeriodSeconds above shutdownDelay + server.graceful_shutdown_timeout.
465
shutdownDelay: 0s
466
# -- Grace period to allow the distributor to shutdown before it is killed
467
terminationGracePeriodSeconds: 30
468
# -- Container lifecycle hooks for the distributor
469
lifecycle: {}
470
# -- topologySpread for distributor pods. Passed through `tpl` and, thus, to be configured as string
471
# @default -- Defaults to allow skew no more then 1 node per AZ
472
topologySpreadConstraints: |
473
- maxSkew: 1
474
topologyKey: topology.kubernetes.io/zone
475
whenUnsatisfiable: ScheduleAnyway
476
labelSelector:
477
matchLabels:
478
{{- include "tempo.selectorLabels" (dict "ctx" . "component" "distributor") | nindent 6 }}
479
# -- Affinity for distributor pods. Passed through `tpl` and, thus, to be configured as string
480
# @default -- Hard node and soft zone anti-affinity
481
affinity: |
482
podAntiAffinity:
483
requiredDuringSchedulingIgnoredDuringExecution:
484
- labelSelector:
485
matchLabels:
486
{{- include "tempo.selectorLabels" (dict "ctx" . "component" "distributor") | nindent 10 }}
487
topologyKey: kubernetes.io/hostname
488
preferredDuringSchedulingIgnoredDuringExecution:
489
- weight: 100
490
podAffinityTerm:
491
labelSelector:
492
matchLabels:
493
{{- include "tempo.selectorLabels" (dict "ctx" . "component" "distributor") | nindent 12 }}
494
topologyKey: topology.kubernetes.io/zone
495
# Strategy of updating pods
496
strategy:
497
rollingUpdate:
498
maxSurge: 0
499
maxUnavailable: 1
500
# -- Pod Disruption Budget configuration
501
podDisruptionBudget:
502
# -- Enable PodDisruptionBudget for distributor
503
enabled: true
504
# -- Set unhealthyPodEvictionPolicy for the distributor PodDisruptionBudget. Requires policy/v1.
505
unhealthyPodEvictionPolicy: ""
506
# -- Pod Disruption Budget maxUnavailable
507
maxUnavailable: 1
508
# -- Minimum number of seconds for which a newly created Pod should be ready without any of its containers crashing/terminating
509
minReadySeconds: 10
510
# -- Node selector for distributor pods
511
nodeSelector: {}
512
# -- Tolerations for distributor pods
513
tolerations: []
514
# -- Extra volumes for distributor pods
515
extraVolumeMounts: []
516
# -- Extra volumes for distributor deployment
517
extraVolumes: []
518
config:
519
# -- Enable to log every received trace id to help debug ingestion
520
# -- WARNING: Deprecated. Use log_received_spans instead.
521
log_received_traces: null
522
# -- Enable to log every received span to help debug ingestion or calculate span error distributions using the logs
523
log_received_spans:
524
enabled: false
525
include_all_attributes: false
526
filter_by_status_error: false
527
log_discarded_spans:
528
enabled: false
529
include_all_attributes: false
530
filter_by_status_error: false
531
# -- Disables write extension with inactive ingesters
532
extend_writes: null
533
# -- Trace Attribute bytes limit. This is the maximum number of bytes that can be used in a trace. 0 for no limit. Set to null to omit from config.
534
max_attribute_bytes: null
535
# Configures usage trackers in the distributor which expose metrics of ingested traffic grouped by configurable
536
# attributes exposed on /usage_metrics.
537
cost_attribution:
538
# -- Enables the "cost-attribution" usage tracker. Per-tenant attributes are configured in overrides.
539
enabled: false
540
# -- Maximum number of series per tenant.
541
max_cardinality: 10000
542
# -- Interval after which a series is considered stale and will be deleted from the registry.
543
# -- Once a metrics series is deleted, it won't be emitted anymore, keeping active series low.
544
stale_duration: 15m0s
545
# -- Adds the appProtocol field to the distributor service. This allows distributor to work with istio protocol selection.
546
appProtocol:
547
# -- Set the optional gRPC service protocol. Ex: "grpc", "http2" or "https"
548
grpc: null
549
# -- EXPERIMENTAL Feature, disabled by default
550
# Configuration for the backend-scheduler
551
backendScheduler:
552
# -- Specifies whether a backend-scheduler and backend-worker
553
# -- should be deployed.
554
enabled: true
555
# -- Annotations for backend-scheduler StatefulSet
556
annotations: {}
557
# -- Labels for the backend-scheduler StatefulSet
558
labels: {}
559
# -- hostAliases to add
560
hostAliases: []
561
# - ip: 1.2.3.4
562
# hostnames:
563
# - domain.tld
564
# -- Pod DNS config for this component. Falls back to `defaults.dnsConfig`, then `tempo.dnsConfig`.
565
dnsConfig: {}
566
# -- Init containers to add to the backend-scheduler pod
567
initContainers: []
568
image:
569
# -- The Docker registry for the backend-scheduler image. Overrides `tempo.image.registry`
570
registry: null
571
# -- Optional list of imagePullSecrets. Overrides `tempo.image.pullSecrets`
572
pullSecrets: []
573
# -- Docker image repository for the backend-scheduler image. Overrides `tempo.image.repository`
574
repository: null
575
# -- Docker image tag for the backend-scheduler image. Overrides `tempo.image.tag`
576
tag: null
577
# -- The name of the PriorityClass for backend-scheduler pod
578
priorityClassName: null
579
# -- Labels for backend-scheduler pod
580
podLabels: {}
581
# -- Annotations for backend-scheduler pod
582
podAnnotations: {}
583
# -- Additional CLI args for the backend-scheduler
584
extraArgs: []
585
# -- Environment variables to add to the backend-scheduler pod
586
extraEnv: []
587
# -- Environment variables from secrets or configmaps to add to the backend-scheduler pod
588
extraEnvFrom: []
589
# -- Additional ports to expose on the backend-scheduler container
590
# Standard ports (grpc, http-metrics, http-memberlist) are always added automatically.
591
extraPorts: []
592
# -- Liveness probe for backend-scheduler pod. Uses `tempo.livenessProbe` as default if not set.
593
livenessProbe: {}
594
# -- Readiness probe for backend-scheduler pod. Uses `tempo.readinessProbe` as default if not set.
595
readinessProbe: {}
596
# -- Startup probe for backend-scheduler pod. Uses `tempo.startupProbe` as default if not set.
597
startupProbe: {}
598
# -- Resource requests and limits for the backend-scheduler
599
resources: {}
600
# -- Grace period to allow the backend-scheduler to shutdown before it is killed
601
terminationGracePeriodSeconds: 30
602
# -- topologySpread for backend-scheduler pods. Passed through `tpl` and, thus, to be configured as string
603
# @default -- Defaults to allow skew no more then 1 node per AZ
604
topologySpreadConstraints: |
605
- maxSkew: 1
606
topologyKey: topology.kubernetes.io/zone
607
whenUnsatisfiable: ScheduleAnyway
608
labelSelector:
609
matchLabels:
610
{{- include "tempo.selectorLabels" (dict "ctx" . "component" "backend-scheduler") | nindent 6 }}
611
# -- Affinity for backend-scheduler pods. Passed through `tpl` and, thus, to be configured as string
612
# @default -- Soft node and soft zone anti-affinity
613
affinity: |
614
podAntiAffinity:
615
preferredDuringSchedulingIgnoredDuringExecution:
616
- weight: 100
617
podAffinityTerm:
618
labelSelector:
619
matchLabels:
620
{{- include "tempo.selectorLabels" (dict "ctx" . "component" "backend-scheduler") | nindent 12 }}
621
topologyKey: kubernetes.io/hostname
622
- weight: 75
623
podAffinityTerm:
624
labelSelector:
625
matchLabels:
626
{{- include "tempo.selectorLabels" (dict "ctx" . "component" "backend-scheduler") | nindent 12 }}
627
topologyKey: topology.kubernetes.io/zone
628
# -- Node selector for backend-scheduler pod
629
nodeSelector: {}
630
# -- Tolerations for backend-scheduler pod
631
tolerations: []
632
# -- Extra volumes for backend-scheduler pod
633
extraVolumeMounts: []
634
# -- Extra volumes for backend-scheduler StatefulSet
635
extraVolumes: []
636
# -- Containers to add to the backend-scheduler pods
637
extraContainers: []
638
# -- Persistence configuration for backend-scheduler
639
persistence:
640
# -- Enable creating a PVC for the backend-scheduler data volume, so its local
641
# work path survives a pod restart instead of being lost with the emptyDir.
642
enabled: false
643
# -- Enable StatefulSetRecreation for changes to PVC size
644
enableStatefulSetRecreationForSizeChange: false
645
# -- use emptyDir with ramdisk instead of PVC. **Please note that all data in backend-scheduler will be lost on pod restart**
646
inMemory: false
647
# -- Size of persistent or memory disk
648
size: 10Gi
649
# -- Storage class to be used.
650
# If defined, storageClassName: <storageClass>.
651
# If set to "-", storageClassName: "", which disables dynamic provisioning.
652
# If empty or set to null, no storageClassName spec is
653
# set, choosing the default provisioner (gp2 on AWS, standard on GKE, AWS, and OpenStack).
654
storageClass: null
655
# -- Annotations for backend-scheduler's persist volume claim
656
annotations: {}
657
# -- Labels for backend-scheduler's persist volume claim
658
labels: {}
659
# -- Spec for the `data` volume when persistence is disabled. By default an
660
# empty `emptyDir: {}`; set e.g. `sizeLimit` or `medium: Memory` as needed.
661
walEmptyDir: {}
662
# -- updateStrategy of the backend-scheduler statefulset.
663
statefulStrategy:
664
rollingUpdate:
665
partition: 0
666
persistentVolumeClaimRetentionPolicy:
667
# -- Enable Persistent volume retention policy for StatefulSet
668
enabled: false
669
# -- Volume retention behavior when the replica count of the StatefulSet is reduced
670
whenScaled: Retain
671
# -- Volume retention behavior that applies when the StatefulSet is deleted
672
whenDeleted: Retain
673
config:
674
# -- How often to flush the work cache to backend storage
675
backend_flush_interval: 1m
676
# -- How long to wait for a worker to complete a job before timing out internally
677
job_timeout: 15s
678
# -- Path to store local work cache files
679
local_work_path: /var/tempo
680
# -- How often to perform maintenance tasks (pruning old jobs, checking for dead jobs, etc.)
681
maintenance_interval: 1m
682
# -- Provider configuration for job generation
683
provider:
684
# -- Compaction job configuration
685
compaction:
686
# -- Compaction configuration
687
compaction:
688
# -- Duration to keep blocks
689
block_retention: 48h
690
# Duration to keep blocks that have been compacted elsewhere
691
compacted_block_retention: 1h
692
# -- The time between compaction cycles
693
compaction_cycle: 30s
694
# -- Blocks in this time window will be compacted together
695
compaction_window: 1h
696
# -- Maximum size of a compacted block in bytes
697
# -- This should be set to a lower value, ideally 5GB or less
698
# -- 100GB is a legacy default for v2 storage format which is
699
# -- no longer even available as of Tempo 2.1.x
700
# -- https://github.com/grafana/tempo/discussions/5301
701
max_block_bytes: 107374182400
702
# -- Maximum number of traces in a compacted block. WARNING: Deprecated. Use max_block_bytes instead.
703
max_compaction_objects: 6000000
704
# -- The maximum amount of time to spend compacting a single tenant before moving to the next
705
max_time_per_tenant: 5m
706
# -- Number of tenants to process in parallel during retention
707
retention_concurrency: 10
708
# -- Maximum number of compaction jobs to create per tenant
709
max_compaction_level: 0
710
# -- Maximum number of blocks to compact together
711
max_input_blocks: 4
712
# -- Maximum compaction level (0 means no limit)
713
max_jobs_per_tenant: 1000
714
# -- How often to measure tenant block lists and create new compaction jobs
715
measure_interval: 1m
716
# -- Minimum time between compaction cycles for a tenant
717
min_cycle_interval: 30s
718
# -- Minimum number of blocks required for compaction
719
min_input_blocks: 2
720
# -- Retention job configuration
721
retention:
722
# -- How often to check for blocks that need to be deleted due to retention
723
interval: 1h
724
# -- Work cache configuration
725
work:
726
# -- After this duration, jobs that have not been updated are considered dead and will be reassigned.
727
dead_job_timeout: 24h
728
# -- How long to keep completed or failed jobs in the work cache before pruning them.
729
prune_age: 1h
730
service:
731
# -- Annotations for backend-scheduler service
732
annotations: {}
733
# Configuration for the backend-worker
734
backendWorker:
735
# -- Number of replicas for the backend-worker
736
replicas: 1
737
# -- Autoscaling configurations
738
autoscaling:
739
# -- Enable autoscaling for the backend-worker
740
enabled: false
741
# -- Minimum autoscaling replicas for the backend-worker
742
minReplicas: 1
743
# -- Maximum autoscaling replicas for the backend-worker
744
maxReplicas: 3
745
# -- Autoscaling via HPA object
746
hpa:
747
enabled: false
748
# -- Autoscaling behavior configuration for the backend-worker
749
behavior: {}
750
# -- Target CPU utilisation percentage for the backend-worker
751
targetCPUUtilizationPercentage: 100
752
# -- Target memory utilisation percentage for the backend-worker
753
targetMemoryUtilizationPercentage:
754
# -- Autoscaling via keda/ScaledObject
755
keda:
756
# requires https://keda.sh/
757
enabled: false
758
annotations: {}
759
# scaledobject.keda.sh/transfer-hpa-ownership: "true" # Use to transfer an existing HPA ownership to this ScaledObject
760
# validations.keda.sh/hpa-ownership: "true" # Use to disable HPA ownership validation on this ScaledObject
761
# autoscaling.keda.sh/paused: "true" # Use to pause autoscaling of objects explicitly
762
pollingInterval: null # Optional. Default: 30 seconds
763
cooldownPeriod: null # Optional. Default: 300 seconds
764
initialCooldownPeriod: null # Optional. Default: 0 seconds
765
# Optional. Section to specify advanced options
766
advanced: {}
767
# # Optional. Section to specify advanced options
768
# horizontalPodAutoscalerConfig:
769
# # Optional. Default: keda-hpa-{scaled-object-name}
770
# name: null
771
# # Optional. Use to modify HPA's scaling behavior
772
# behavior: null
773
# # scaleDown:
774
# # stabilizationWindowSeconds: 300
775
# # Optional. Section to specify scaling modifiers
776
# scalingModifiers:
777
# target: null # Mandatory. New target if metrics are anyhow composed together
778
# activationTarget: null # Optional. New activation target if metrics are anyhow composed together
779
# metricType: null # Optional. Metric type to be used if metrics are anyhow composed together
780
# formula: null # Mandatory. Formula for calculation
781
fallback: {}
782
# failureThreshold: null # Mandatory if fallback section is included
783
# replicas: null # Mandatory if fallback section is included
784
# behavior: null # Optional. Default: "static"
785
# -- List of autoscaling triggers for the compactor
786
triggers: []
787
# - name: tempo-outstanding-compaction-blocks
788
## https://keda.sh/docs/2.19/concepts/authentication/
789
## authenticationRef:
790
## name: {trigger-authentication-name} or {cluster-trigger-authentication-name}
791
## kind: TriggerAuthentication or ClusterTriggerAuthentication
792
# type: prometheus
793
# metadata:
794
# serverAddress: "http://<prometheus-host>:9090"
795
# threshold: "250"
796
# query: |-
797
# sum by (cluster, namespace, tenant) (
798
# tempodb_compaction_outstanding_blocks{container="backend-scheduler", namespace=~".*"}
799
# ) /
800
# ignoring(tenant) group_left count by (cluster, namespace)(
801
# tempo_build_info{container="backend-worker", namespace=~".*"}
802
# )
803
# customHeaders: X-Scope-OrgID=<tenant-id>
804
# -- Annotations for backend-worker StatefulSet
805
annotations: {}
806
# -- Labels for the backend-worker StatefulSet
807
labels: {}
808
# -- hostAliases to add
809
hostAliases: []
810
# - ip: 1.2.3.4
811
# hostnames:
812
# - domain.tld
813
# -- Pod DNS config for this component. Falls back to `defaults.dnsConfig`, then `tempo.dnsConfig`.
814
dnsConfig: {}
815
# -- Init containers to add to the backend-worker pods
816
initContainers: []
817
image:
818
# -- The Docker registry for the backend-worker image. Overrides `tempo.image.registry`
819
registry: null
820
# -- Optional list of imagePullSecrets. Overrides `tempo.image.pullSecrets`
821
pullSecrets: []
822
# -- Docker image repository for the backend-worker image. Overrides `tempo.image.repository`
823
repository: null
824
# -- Docker image tag for the backend-worker image. Overrides `tempo.image.tag`
825
tag: null
826
# -- The name of the PriorityClass for backend-worker pods
827
priorityClassName: null
828
# -- Labels for backend-worker pods
829
podLabels: {}
830
# -- Annotations for backend-worker pods
831
podAnnotations: {}
832
# -- Additional CLI args for the backend-worker
833
extraArgs: []
834
# -- Environment variables to add to the backend-worker pods
835
extraEnv: []
836
# -- Environment variables from secrets or configmaps to add to the backend-worker pods
837
extraEnvFrom: []
838
# -- Liveness probe for backend-worker pods. Uses `tempo.livenessProbe` as default if not set.
839
livenessProbe: {}
840
# -- Readiness probe for backend-worker pods. Uses `tempo.readinessProbe` as default if not set.
841
readinessProbe: {}
842
# -- Startup probe for backend-worker pods. Uses `tempo.startupProbe` as default if not set.
843
startupProbe: {}
844
# -- Resource requests and limits for the backend-worker
845
resources: {}
846
# -- Grace period to allow the backend-worker to shutdown before it is killed
847
terminationGracePeriodSeconds: 30
848
# -- topologySpread for backend-worker pods. Passed through `tpl` and, thus, to be configured as string
849
# @default -- Defaults to allow skew no more then 1 node per AZ
850
topologySpreadConstraints: |
851
- maxSkew: 1
852
topologyKey: topology.kubernetes.io/zone
853
whenUnsatisfiable: ScheduleAnyway
854
labelSelector:
855
matchLabels:
856
{{- include "tempo.selectorLabels" (dict "ctx" . "component" "backend-worker") | nindent 6 }}
857
# -- Affinity for backend-worker pods. Passed through `tpl` and, thus, to be configured as string
858
# @default -- Soft node and soft zone anti-affinity
859
affinity: |
860
podAntiAffinity:
861
preferredDuringSchedulingIgnoredDuringExecution:
862
- weight: 100
863
podAffinityTerm:
864
labelSelector:
865
matchLabels:
866
{{- include "tempo.selectorLabels" (dict "ctx" . "component" "backend-worker") | nindent 12 }}
867
topologyKey: kubernetes.io/hostname
868
- weight: 75
869
podAffinityTerm:
870
labelSelector:
871
matchLabels:
872
{{- include "tempo.selectorLabels" (dict "ctx" . "component" "backend-worker") | nindent 12 }}
873
topologyKey: topology.kubernetes.io/zone
874
# -- Node selector for backend-worker pods
875
nodeSelector: {}
876
# -- Tolerations for backend-worker pods
877
tolerations: []
878
# -- Extra volumes for backend-worker pods
879
extraVolumeMounts: []
880
# -- Extra volumes for backend-worker StatefulSet
881
extraVolumes: []
882
# -- Containers to add to the backend-worker pods
883
extraContainers: []
884
# -- updateStrategy of the backend-worker statefulset.
885
statefulStrategy:
886
rollingUpdate:
887
partition: 0
888
persistentVolumeClaimRetentionPolicy:
889
# -- Enable Persistent volume retention policy for StatefulSet
890
enabled: false
891
# -- Volume retention behavior when the replica count of the StatefulSet is reduced
892
whenScaled: Retain
893
# -- Volume retention behavior that applies when the StatefulSet is deleted
894
whenDeleted: Retain
895
config:
896
backend_scheduler_client:
897
# -- gRPC client configuration
898
grpc_client_config: {}
899
# -- Backoff configuration for retrying failed jobs
900
backoff:
901
min_period: 100ms
902
max_period: 1m
903
max_retries: 0
904
# -- Compaction settings
905
# -- .Values.backendScheduler.compaction.compaction will be used
906
compaction: {}
907
# -- Timeout for finishing the current job before shutting down the worker
908
finish_on_shutdown_timeout: 30s
909
service:
910
# -- Annotations for backend-worker service
911
annotations: {}
912
# -- Ingest configuration. Sets the top-level `ingest:` block in tempo.yaml.
913
# Required for Tempo 3.0 microservices mode. Distributors write spans to Kafka;
914
# block-builders and live-stores consume from it.
915
# The number of block-builder and live-store replicas must equal the Kafka partition count.
916
ingest:
917
kafka:
918
# -- Kafka broker address (e.g. "kafka.kafka-namespace.svc.cluster.local:9092")
919
address: ""
920
# -- Kafka topic name for trace data
921
topic: tempo-traces
922
# -- Automatically create the topic if it does not exist
923
auto_create_topic_enabled: true
924
# -- Number of partitions for the auto-created topic.
925
# Block-builder and live-store replica count must match this value.
926
auto_create_topic_default_partitions: 3
927
# Configuration for the block-builder (Tempo 3.0+)
928
# Consumes spans from Kafka and writes blocks to object storage.
929
# One replica per Kafka partition — replica count must equal ingest.kafka.auto_create_topic_default_partitions.
930
blockBuilder:
931
# -- Enable the block-builder. Requires ingest.kafka.address to be set.
932
enabled: true
933
# -- Number of replicas. Must equal the Kafka partition count.
934
replicas: 3
935
# -- Annotations for the block-builder StatefulSet
936
annotations: {}
937
# -- Labels for the block-builder StatefulSet
938
labels: {}
939
# -- hostAliases to add
940
hostAliases: []
941
# -- Pod DNS config for this component. Falls back to `defaults.dnsConfig`, then `tempo.dnsConfig`.
942
dnsConfig: {}
943
# -- Init containers to add to the block-builder pod
944
initContainers: []
945
image:
946
# -- The Docker registry for the block-builder image. Overrides `tempo.image.registry`
947
registry: null
948
# -- Optional list of imagePullSecrets. Overrides `tempo.image.pullSecrets`
949
pullSecrets: []
950
# -- Docker image repository for the block-builder image. Overrides `tempo.image.repository`
951
repository: null
952
# -- Docker image tag for the block-builder image. Overrides `tempo.image.tag`
953
tag: null
954
# -- The name of the PriorityClass for block-builder pods
955
priorityClassName: null
956
# -- Labels for block-builder pods
957
podLabels: {}
958
# -- Annotations for block-builder pods
959
podAnnotations: {}
960
# -- Additional CLI args for the block-builder
961
extraArgs: []
962
# -- Environment variables to add to the block-builder pods
963
extraEnv: []
964
# -- Environment variables from secrets or configmaps to add to the block-builder pods
965
extraEnvFrom: []
966
# -- Additional ports to expose on the block-builder container
967
extraPorts: []
968
# -- Liveness probe for block-builder pods. Uses `tempo.livenessProbe` as default if not set.
969
livenessProbe: {}
970
# -- Readiness probe for block-builder pods. Uses `tempo.readinessProbe` as default if not set.
971
readinessProbe: {}
972
# -- Startup probe for block-builder pods. Uses `tempo.startupProbe` as default if not set.
973
startupProbe: {}
974
# -- Resource requests and limits for the block-builder
975
resources: {}
976
# -- Grace period to allow the block-builder to flush its WAL before being killed
977
terminationGracePeriodSeconds: 300
978
# -- topologySpread for block-builder pods. Passed through `tpl`.
979
topologySpreadConstraints: |
980
- maxSkew: 1
981
topologyKey: topology.kubernetes.io/zone
982
whenUnsatisfiable: ScheduleAnyway
983
labelSelector:
984
matchLabels:
985
{{- include "tempo.selectorLabels" (dict "ctx" . "component" "block-builder") | nindent 6 }}
986
# -- Affinity for block-builder pods. Passed through `tpl`.
987
affinity: |
988
podAntiAffinity:
989
preferredDuringSchedulingIgnoredDuringExecution:
990
- weight: 100
991
podAffinityTerm:
992
labelSelector:
993
matchLabels:
994
{{- include "tempo.selectorLabels" (dict "ctx" . "component" "block-builder") | nindent 12 }}
995
topologyKey: kubernetes.io/hostname
996
# -- Node selector for block-builder pods
997
nodeSelector: {}
998
# -- Tolerations for block-builder pods
999
tolerations: []
1000
# -- Extra volumes for block-builder pods
1001
extraVolumeMounts: []
1002
# -- Extra volumes for block-builder StatefulSet
1003
extraVolumes: []
1004
# -- Containers to add to the block-builder pods
1005
extraContainers: []
1006
# -- updateStrategy of the block-builder StatefulSet
1007
statefulStrategy:
1008
rollingUpdate:
1009
partition: 0
1010
# -- Pod Disruption Budget configuration
1011
podDisruptionBudget:
1012
# -- Enable PodDisruptionBudget for block-builder
1013
enabled: true
1014
# -- Set unhealthyPodEvictionPolicy for the block-builder PodDisruptionBudget. Requires policy/v1.
1015
unhealthyPodEvictionPolicy: ""
1016
# -- Pod Disruption Budget maxUnavailable
1017
maxUnavailable: 1
1018
service:
1019
# -- Annotations for block-builder service
1020
annotations: {}
1021
config:
1022
# -- Number of Kafka partitions each block-builder instance consumes.
1023
# Each pod consumes this many partitions starting from its ordinal * partitions_per_instance.
1024
partitions_per_instance: 1
1025
# Configuration for the live-store (Tempo 3.0+)
1026
# Consumes spans from Kafka and serves recent-data queries (last ~30 minutes).
1027
# One replica per Kafka partition — replica count must equal ingest.kafka.auto_create_topic_default_partitions.
1028
liveStore:
1029
# -- Enable the live-store. Requires ingest.kafka.address to be set.
1030
enabled: true
1031
# -- Number of replicas. Must equal the Kafka partition count.
1032
replicas: 3
1033
# -- Annotations for the live-store StatefulSet
1034
annotations: {}
1035
# -- Labels for the live-store StatefulSet
1036
labels: {}
1037
# -- hostAliases to add
1038
hostAliases: []
1039
# -- Pod DNS config for this component. Falls back to `defaults.dnsConfig`, then `tempo.dnsConfig`.
1040
dnsConfig: {}
1041
# -- Init containers to add to the live-store pod
1042
initContainers: []
1043
image:
1044
# -- The Docker registry for the live-store image. Overrides `tempo.image.registry`
1045
registry: null
1046
# -- Optional list of imagePullSecrets. Overrides `tempo.image.pullSecrets`
1047
pullSecrets: []
1048
# -- Docker image repository for the live-store image. Overrides `tempo.image.repository`
1049
repository: null
1050
# -- Docker image tag for the live-store image. Overrides `tempo.image.tag`
1051
tag: null
1052
# -- The name of the PriorityClass for live-store pods
1053
priorityClassName: null
1054
# -- Labels for live-store pods
1055
podLabels: {}
1056
# -- Annotations for live-store pods
1057
podAnnotations: {}
1058
# -- Additional CLI args for the live-store
1059
extraArgs: []
1060
# -- Environment variables to add to the live-store pods
1061
extraEnv: []
1062
# -- Environment variables from secrets or configmaps to add to the live-store pods
1063
extraEnvFrom: []
1064
# -- Additional ports to expose on the live-store container
1065
extraPorts: []
1066
# -- Liveness probe for live-store pods. Uses `tempo.livenessProbe` as default if not set.
1067
livenessProbe: {}
1068
# -- Readiness probe for live-store pods. Uses `tempo.readinessProbe` as default if not set.
1069
readinessProbe: {}
1070
# -- Startup probe for live-store pods. Uses `tempo.startupProbe` as default if not set.
1071
startupProbe: {}
1072
# -- Resource requests and limits for the live-store
1073
resources: {}
1074
# -- Grace period to allow the live-store to shut down before being killed
1075
terminationGracePeriodSeconds: 60
1076
# -- topologySpread for live-store pods. Passed through `tpl`.
1077
topologySpreadConstraints: |
1078
- maxSkew: 1
1079
topologyKey: topology.kubernetes.io/zone
1080
whenUnsatisfiable: ScheduleAnyway
1081
labelSelector:
1082
matchLabels:
1083
{{- include "tempo.selectorLabels" (dict "ctx" . "component" "live-store") | nindent 6 }}
1084
# -- Affinity for live-store pods. Passed through `tpl`.
1085
affinity: |
1086
podAntiAffinity:
1087
preferredDuringSchedulingIgnoredDuringExecution:
1088
- weight: 100
1089
podAffinityTerm:
1090
labelSelector:
1091
matchLabels:
1092
{{- include "tempo.selectorLabels" (dict "ctx" . "component" "live-store") | nindent 12 }}
1093
topologyKey: kubernetes.io/hostname
1094
# -- Node selector for live-store pods
1095
nodeSelector: {}
1096
# -- Tolerations for live-store pods
1097
tolerations: []
1098
# -- Extra volumes for live-store pods
1099
extraVolumeMounts: []
1100
# -- Extra volumes for live-store StatefulSet
1101
extraVolumes: []
1102
# -- Containers to add to the live-store pods
1103
extraContainers: []
1104
# -- updateStrategy of the live-store StatefulSet
1105
statefulStrategy:
1106
rollingUpdate:
1107
partition: 0
1108
# -- Persistence configuration for live-store
1109
persistence:
1110
# -- Enable creating PVCs for the live-store data volume. The WAL and local
1111
# blocks then survive a restart, so the live-store resumes from its committed
1112
# Kafka offset (never further back than 2 x complete_block_timeout) instead of
1113
# re-reading that whole window, as it must when it starts with no local data.
1114
enabled: false
1115
# -- Enable StatefulSetRecreation for changes to PVC size
1116
enableStatefulSetRecreationForSizeChange: false
1117
# -- use emptyDir with ramdisk instead of PVC. **Please note that all data in live-store will be lost on pod restart**
1118
inMemory: false
1119
# -- Size of persistent or memory disk
1120
size: 10Gi
1121
# -- Storage class to be used.
1122
# If defined, storageClassName: <storageClass>.
1123
# If set to "-", storageClassName: "", which disables dynamic provisioning.
1124
# If empty or set to null, no storageClassName spec is
1125
# set, choosing the default provisioner (gp2 on AWS, standard on GKE, AWS, and OpenStack).
1126
storageClass: null
1127
# -- Annotations for live-store's persist volume claim
1128
annotations: {}
1129
# -- Labels for live-store's persist volume claim
1130
labels: {}
1131
# -- Spec for the `data` volume when persistence is disabled. By default an
1132
# empty `emptyDir: {}`; set e.g. `sizeLimit` or `medium: Memory` as needed.
1133
walEmptyDir: {}
1134
# Note: the retained volume also holds the live-store's shutdown marker
1135
# (`/var/tempo/live-store/shutdown-marker`). It is removed on a graceful shutdown,
1136
# but if a pod is force-killed after the rollout-operator has called
1137
# `prepare-downscale` (grace period exceeded, OOMKill, node loss), a stale marker
1138
# is left on the volume. On scale-up that pod then starts with
1139
# `create-partition-on-startup=false` and its partition will not become ACTIVE, so
1140
# it takes no writes. If a scaled-up live-store never becomes ready, or its
1141
# partition stays INACTIVE, remove the shutdown marker from its PVC or call
1142
# `DELETE /live-store/prepare-downscale` on it.
1143
persistentVolumeClaimRetentionPolicy:
1144
# -- Enable Persistent volume retention policy for the live-store StatefulSet
1145
enabled: false
1146
# -- Volume retention behaviour when the StatefulSet replica count is reduced
1147
whenScaled: Retain
1148
# -- Volume retention behaviour when the StatefulSet is deleted
1149
whenDeleted: Retain
1150
# Zone-aware replication spreads the live-stores over failure domains such as
1151
# availability zones, racks or data centres. Every zone runs a full set of
1152
# live-stores, so each Kafka partition gets one owner per zone (RF equals the
1153
# number of zones). The read quorum is 1: a querier only needs an answer from
1154
# one zone, so recent-trace queries survive the loss of a zone.
1155
# Requires `rollout_operator.enabled: true`.
1156
zoneAwareReplication:
1157
# -- Enable zone-aware replication for the live-store
1158
enabled: false
1159
# -- Set to true when a rollout-operator already runs in this namespace and is
1160
# not installed by this chart. Skips the `rollout_operator.enabled` check.
1161
rolloutOperatorManagedExternally: false
1162
# -- Topology key of the failure domain. When set, the live-stores of one zone
1163
# never share a domain with the live-stores of another zone. The cluster must
1164
# hold at least as many domains as there are zones, otherwise the extra zones
1165
# stay unschedulable. With neither this nor a `nodeSelector` on every zone,
1166
# the zones still give separate pods and one partition owner each, but two
1167
# zones can share a failure domain.
1168
topologyKey: null
1169
# -- Maximum number of live-stores the rollout-operator restarts at the same
1170
# time inside one zone. The rollout-operator always moves one zone at a time.
1171
# A zone with fewer live-stores than this restarts as a whole, which the read
1172
# quorum of 1 covers, at the cost of the read capacity of that zone.
1173
maxUnavailable: 25
1174
# -- Reject every scale-down of the live-stores. The live-store count must
1175
# match the Kafka partition count, so an accidental scale-down drops the
1176
# recent-read tier of the partitions that go away. Needs the rollout-operator
1177
# webhooks. Cannot be combined with `prepareDownscale.enabled`.
1178
noDownscale: false
1179
# Coordinated scale-down through the rollout-operator admission webhook. It
1180
# guards a lower `liveStore.replicas`, which retires the last Kafka
1181
# partitions. On such a scale-down the webhook calls `httpPath` on every
1182
# live-store that goes away, which moves its partition to INACTIVE and stops
1183
# the writes to it. The webhook then rejects the scale-down of a second zone
1184
# until `minTimeBetweenZonesDownscale` has passed, so the zones go down one
1185
# at a time. A rejected scale-down fails the `helm upgrade`: wait for the
1186
# window, then run the upgrade again.
1187
#
1188
# The webhook is the only mechanism the chart uses, so a pod stops as soon
1189
# as its partition is INACTIVE. The remaining zones still own that partition
1190
# and still hold its recent traces, which is what keeps the read path whole
1191
# until the last zone goes down. Do not remove a zone from the `zones` list
1192
# in the same step: that deletes the StatefulSet, which the webhook never
1193
# sees.
1194
prepareDownscale:
1195
# -- Enable the coordinated scale-down
1196
enabled: false
1197
# -- Minimum time between the scale-down of two zones. Must be longer than
1198
# the period a live-store still serves recent traces, because the last
1199
# zone to go down takes the last owner of the retired partitions with it.
1200
minTimeBetweenZonesDownscale: 12h
1201
# -- Endpoint the webhook calls on every live-store that goes away. Must
1202
# accept a POST while the partition is still ACTIVE.
1203
# `live-store/prepare-downscale` does not: it answers 409 until the
1204
# partition is INACTIVE, so it needs the delayed-downscale mechanism of
1205
# the rollout-operator, which this chart does not configure.
1206
httpPath: live-store/prepare-partition-downscale
1207
# Voluntary evictions of zone-aware live-stores, through the
1208
# ZoneAwarePodDisruptionBudget of the rollout-operator. A native
1209
# PodDisruptionBudget counts pods, so it cannot tell that the same pod
1210
# ordinal in two zones holds every owner of one partition. This one counts
1211
# per partition across zones and rejects an eviction that would take the
1212
# last owner, whatever the budget of a single zone allows.
1213
#
1214
# Needs the ZoneAwarePodDisruptionBudget CRD and the pod eviction webhook of
1215
# the rollout-operator. The bundled subchart installs both. The webhook
1216
# rejects an eviction while the rollout-operator is unreachable, so this
1217
# never opens a window. While this is on, it replaces the
1218
# `liveStore.podDisruptionBudget` object.
1219
podDisruptionBudget:
1220
# -- Guard the evictions with a ZoneAwarePodDisruptionBudget. Set to false
1221
# to keep a single native PodDisruptionBudget over all zones instead.
1222
enabled: true
1223
# -- Live-stores of one partition that may be unavailable at the same
1224
# time, counted over every zone. 1 keeps a partition served through any
1225
# single voluntary eviction. 0 rejects every voluntary eviction.
1226
maxUnavailable: 1
1227
# -- Regular expression that returns the partition of a live-store from
1228
# its pod name. The rollout-operator anchors it with `^` and `$`, so it
1229
# must match the whole name. The default reads the pod ordinal, which is
1230
# the Kafka partition, and holds for any zone name.
1231
podNamePartitionRegex: ".*-([0-9]+)"
1232
# -- Capture group of the partition. Only needed when
1233
# `podNamePartitionRegex` holds more than one group.
1234
podNameRegexGroup: null
1235
# -- Minimum time after a live-store becomes ready before another owner of
1236
# the same partition may be evicted. A Go duration, so days are not a
1237
# unit. Set this when the live-stores run with the default
1238
# `readiness-target-lag` of 0, because a live-store then reports ready
1239
# while it still replays its partition.
1240
crossZoneEvictionDelay: null
1241
# -- Zones to deploy. At least 2 zones are required. Every zone runs
1242
# `liveStore.replicas` live-stores. A zone name must be a DNS label: it
1243
# becomes a StatefulSet name suffix and the value of the zone label.
1244
zones:
1245
- name: zone-a
1246
# -- Node selector for the live-stores of this zone. Merged on top of
1247
# `liveStore.nodeSelector`, or of `defaults.nodeSelector`.
1248
nodeSelector: null
1249
# -- Extra affinity for the live-stores of this zone. Merged on top of
1250
# `liveStore.affinity`. The zone anti-affinity of `topologyKey`
1251
# overwrites a `podAntiAffinity` here.
1252
extraAffinity: {}
1253
# -- Extra annotations for the StatefulSet of this zone
1254
annotations: {}
1255
# -- Extra annotations for the pods of this zone
1256
podAnnotations: {}
1257
- name: zone-b
1258
nodeSelector: null
1259
extraAffinity: {}
1260
annotations: {}
1261
podAnnotations: {}
1262
# -- Pod Disruption Budget configuration
1263
podDisruptionBudget:
1264
# -- Enable PodDisruptionBudget for live-store
1265
enabled: true
1266
# -- Set unhealthyPodEvictionPolicy for the live-store PodDisruptionBudget. Requires policy/v1.
1267
unhealthyPodEvictionPolicy: ""
1268
# -- Pod Disruption Budget maxUnavailable. With zone-aware replication the
1269
# budget covers the live-stores of every zone together, because the same pod
1270
# ordinal in two zones holds every owner of one partition.
1271
maxUnavailable: 1
1272
service:
1273
# -- Annotations for live-store service
1274
annotations: {}
1275
# -- Extra live-store configuration. Merged verbatim into the `live_store:` config block.
1276
# See https://grafana.com/docs/tempo/latest/configuration/#live-store for available fields.
1277
config:
1278
ring:
1279
kvstore:
1280
store: memberlist
1281
# Configuration for the querier
1282
querier:
1283
# -- Number of replicas for the querier
1284
replicas: 1
1285
# -- hostAliases to add
1286
hostAliases: []
1287
# - ip: 1.2.3.4
1288
# hostnames:
1289
# - domain.tld
1290
# -- Pod DNS config for this component. Falls back to `defaults.dnsConfig`, then `tempo.dnsConfig`.
1291
dnsConfig: {}
1292
# -- Annotations for querier deployment
1293
annotations: {}
1294
autoscaling:
1295
# -- Enable autoscaling for the querier
1296
enabled: false
1297
# -- Minimum autoscaling replicas for the querier
1298
minReplicas: 1
1299
# -- Maximum autoscaling replicas for the querier
1300
maxReplicas: 3
1301
# -- Autoscaling behavior configuration for the querier
1302
behavior: {}
1303
# -- Target CPU utilisation percentage for the querier
1304
targetCPUUtilizationPercentage: 60
1305
# -- Target memory utilisation percentage for the querier
1306
targetMemoryUtilizationPercentage:
1307
image:
1308
# -- The Docker registry for the querier image. Overrides `tempo.image.registry`
1309
registry: null
1310
# -- Optional list of imagePullSecrets. Overrides `tempo.image.pullSecrets`
1311
pullSecrets: []
1312
# -- Docker image repository for the querier image. Overrides `tempo.image.repository`
1313
repository: null
1314
# -- Docker image tag for the querier image. Overrides `tempo.image.tag`
1315
tag: null
1316
# -- The name of the PriorityClass for querier pods
1317
priorityClassName: null
1318
# -- Labels for querier pods
1319
podLabels: {}
1320
# -- Annotations for querier pods
1321
podAnnotations: {}
1322
# -- Additional CLI args for the querier
1323
extraArgs: []
1324
# -- Environment variables to add to the querier pods
1325
extraEnv: []
1326
# -- Environment variables from secrets or configmaps to add to the querier pods
1327
extraEnvFrom: []
1328
# -- Liveness probe for querier pods. Uses `tempo.livenessProbe` as default if not set.
1329
livenessProbe: {}
1330
# -- Readiness probe for querier pods. Uses `tempo.readinessProbe` as default if not set.
1331
readinessProbe: {}
1332
# -- Startup probe for querier pods. Uses `tempo.startupProbe` as default if not set.
1333
startupProbe: {}
1334
# -- Resource requests and limits for the querier
1335
resources: {}
1336
# -- Grace period to allow the querier to shutdown before it is killed
1337
terminationGracePeriodSeconds: 30
1338
# -- topologySpread for querier pods. Passed through `tpl` and, thus, to be configured as string
1339
# @default -- Defaults to allow skew no more then 1 node per AZ
1340
topologySpreadConstraints: |
1341
- maxSkew: 1
1342
topologyKey: topology.kubernetes.io/zone
1343
whenUnsatisfiable: ScheduleAnyway
1344
labelSelector:
1345
matchLabels:
1346
{{- include "tempo.selectorLabels" (dict "ctx" . "component" "querier") | nindent 6 }}
1347
# -- Affinity for querier pods. Passed through `tpl` and, thus, to be configured as string
1348
# @default -- Hard node and soft zone anti-affinity
1349
affinity: |
1350
podAntiAffinity:
1351
requiredDuringSchedulingIgnoredDuringExecution:
1352
- labelSelector:
1353
matchLabels:
1354
{{- include "tempo.selectorLabels" (dict "ctx" . "component" "querier" "memberlist" true) | nindent 10 }}
1355
topologyKey: kubernetes.io/hostname
1356
preferredDuringSchedulingIgnoredDuringExecution:
1357
- weight: 100
1358
podAffinityTerm:
1359
labelSelector:
1360
matchLabels:
1361
{{- include "tempo.selectorLabels" (dict "ctx" . "component" "querier" "memberlist" true) | nindent 12 }}
1362
topologyKey: topology.kubernetes.io/zone
1363
# -- Pod Disruption Budget configuration
1364
podDisruptionBudget:
1365
# -- Enable PodDisruptionBudget for querier
1366
enabled: true
1367
# -- Set unhealthyPodEvictionPolicy for the querier PodDisruptionBudget. Requires policy/v1.
1368
unhealthyPodEvictionPolicy: ""
1369
# -- Pod Disruption Budget maxUnavailable
1370
maxUnavailable: 1
1371
# -- Max Surge for querier pods
1372
maxSurge: 0
1373
rollingUpdate:
1374
# -- Maximum number of Pods that can be unavailable during the update process
1375
maxUnavailable: 1
1376
# -- Minimum number of seconds for which a newly created Pod should be ready without any of its containers crashing/terminating
1377
minReadySeconds: 10
1378
# -- Node selector for querier pods
1379
nodeSelector: {}
1380
# -- Tolerations for querier pods
1381
tolerations: []
1382
# -- Init containers for the querier pod
1383
initContainers: []
1384
# -- Containers to add to the querier pods
1385
extraContainers: []
1386
# -- Additional ports to expose on the querier container.
1387
# Standard ports (http-metrics, http-memberlist) are always added automatically.
1388
extraPorts: []
1389
# -- Extra volumes for querier pods
1390
extraVolumeMounts: []
1391
# -- Extra volumes for querier deployment
1392
extraVolumes: []
1393
config:
1394
frontend_worker:
1395
# -- gRPC client configuration
1396
grpc_client_config: {}
1397
trace_by_id:
1398
# -- Timeout for trace lookup requests
1399
query_timeout: 10s
1400
search:
1401
# -- Timeout for search requests
1402
query_timeout: 30s
1403
# -- This value controls the overall number of simultaneous subqueries that the querier will service at once. It does not distinguish between the types of queries.
1404
max_concurrent_queries: 20
1405
service:
1406
# -- Annotations for querier service
1407
annotations: {}
1408
# -- Traffic distribution for the querier service (PreferSameZone or PreferSameNode). Overrides tempo.service.trafficDistribution.
1409
trafficDistribution: null
1410
# -- Adds the appProtocol field to the querier service. This allows querier to work with istio protocol selection.
1411
appProtocol:
1412
# -- Set the optional gRPC service protocol. Ex: "grpc", "http2" or "https"
1413
grpc: null
1414
# Configuration for the query-frontend
1415
queryFrontend:
1416
query:
1417
# -- Required for grafana version <7.5 for compatibility with jaeger-ui. Doesn't work on ARM arch
1418
enabled: false
1419
image:
1420
# -- The Docker registry for the tempo-query image. Overrides `tempo.image.registry`
1421
registry: null
1422
# -- Optional list of imagePullSecrets. Overrides `tempo.image.pullSecrets`
1423
pullSecrets: []
1424
# -- Docker image repository for the tempo-query image. Overrides `tempo.image.repository`
1425
repository: grafana/tempo-query
1426
# -- Docker image tag for the tempo-query image. Overrides `tempo.image.tag`
1427
tag: null
1428
# -- Resource requests and limits for the query
1429
resources: {}
1430
# -- Additional CLI args for tempo-query pods
1431
extraArgs: []
1432
# -- Environment variables to add to the tempo-query pods
1433
extraEnv: []
1434
# -- Environment variables from secrets or configmaps to add to the tempo-query pods
1435
extraEnvFrom: []
1436
# -- Extra volumes for tempo-query pods
1437
extraVolumeMounts: []
1438
# -- Extra volumes for tempo-query deployment
1439
extraVolumes: []
1440
config: |
1441
backend: 127.0.0.1:3200
1442
# -- Number of replicas for the query-frontend
1443
replicas: 1
1444
# -- Annotations for the query-frontend Deployment
1445
annotations: {}
1446
# -- hostAliases to add
1447
hostAliases: []
1448
# - ip: 1.2.3.4
1449
# hostnames:
1450
# - domain.tld
1451
# -- Pod DNS config for this component. Falls back to `defaults.dnsConfig`, then `tempo.dnsConfig`.
1452
dnsConfig: {}
1453
config:
1454
# -- Maximum number of outstanding requests per tenant per frontend; requests beyond this error with HTTP 429.
1455
max_outstanding_per_tenant: 2000
1456
# -- Number of times to retry a request sent to a querier
1457
max_retries: 2
1458
search:
1459
# -- The number of concurrent jobs to execute when searching the backend
1460
concurrent_jobs: 1000
1461
# -- The target number of bytes for each job to handle when performing a backend search
1462
target_bytes_per_job: 104857600
1463
# -- The maximum allowed value of spans per span set. 0 disables this limit.
1464
max_spans_per_span_set: 100
1465
# -- The maximum allowed value for the limit parameter on search requests. 0 disables this limit.
1466
# max_result_limit: 262144 maximum number of results returned by search requests
1467
# -- Trace by ID lookup configuration
1468
trace_by_id:
1469
# -- The number of shards to split a trace by ID query into.
1470
query_shards: 50
1471
metrics:
1472
# -- The number of concurrent jobs to execute when querying the backend.
1473
concurrent_jobs: 1000
1474
# -- The target number of bytes for each job to handle when querying the backend.
1475
target_bytes_per_job: 104857600
1476
# -- The maximum allowed time range for a metrics query.
1477
# 0 disables this limit.
1478
max_duration: 3h
1479
# -- query_backend_after controls where the query-frontend searches for traces.
1480
# Time ranges newer than query_backend_after will be searched in the live-stores only.
1481
# Time ranges older than query_backend_after will be searched in the backend/object storage only.
1482
query_backend_after: 15m
1483
# -- The target length of time for each job to handle when querying the backend.
1484
interval: 5m
1485
# -- If set to a non-zero value, it's value will be used to decide if query is within SLO or not.
1486
# Query is within SLO if it returned 200 within duration_slo seconds OR processed throughput_slo bytes/s data.
1487
# NOTE: `duration_slo` and `throughput_bytes_slo` both must be configured for it to work
1488
duration_slo: 0s
1489
# -- If set to a non-zero value, it's value will be used to decide if query is within SLO or not.
1490
# Query is within SLO if it returned 200 within duration_slo seconds OR processed throughput_slo bytes/s data.
1491
throughput_bytes_slo: 0
1492
autoscaling:
1493
# -- Enable autoscaling for the query-frontend
1494
enabled: false
1495
# -- Minimum autoscaling replicas for the query-frontend
1496
minReplicas: 1
1497
# -- Maximum autoscaling replicas for the query-frontend
1498
maxReplicas: 3
1499
# -- Autoscaling behavior configuration for the query-frontend
1500
behavior: {}
1501
# -- Target CPU utilisation percentage for the query-frontend
1502
targetCPUUtilizationPercentage: 60
1503
# -- Target memory utilisation percentage for the query-frontend
1504
targetMemoryUtilizationPercentage:
1505
image:
1506
# -- The Docker registry for the query-frontend image. Overrides `tempo.image.registry`
1507
registry: null
1508
# -- Optional list of imagePullSecrets. Overrides `tempo.image.pullSecrets`
1509
pullSecrets: []
1510
# -- Docker image repository for the query-frontend image. Overrides `tempo.image.repository`
1511
repository: null
1512
# -- Docker image tag for the query-frontend image. Overrides `tempo.image.tag`
1513
tag: null
1514
service:
1515
# -- Port of the query-frontend service
1516
port: 16686
1517
# -- http Metrics port of the query-frontend service
1518
httpMetricsPort: 3200
1519
# -- gRPC Port of the query-frontend service
1520
grpcPort: 9095
1521
# -- Annotations for queryFrontend service
1522
annotations: {}
1523
# -- Labels for queryFrontend service
1524
labels: {}
1525
# -- Type of service for the queryFrontend
1526
type: ClusterIP
1527
# -- Traffic distribution for the queryFrontend service (PreferSameZone or PreferSameNode). Overrides tempo.service.trafficDistribution.
1528
trafficDistribution: null
1529
# -- If type is LoadBalancer you can assign the IP to the LoadBalancer
1530
loadBalancerIP: ""
1531
# -- If type is LoadBalancer limit incoming traffic from IPs.
1532
loadBalancerSourceRanges: []
1533
serviceDiscovery:
1534
# -- Annotations for queryFrontendDiscovery service
1535
annotations: {}
1536
# -- Labels for queryFrontendDiscovery service
1537
labels: {}
1538
ingress:
1539
# -- Specifies whether an ingress for the Jaeger should be created
1540
enabled: false
1541
# -- Ingress Class Name. MAY be required for Kubernetes versions >= 1.18
1542
# ingressClassName: nginx
1543
# -- Annotations for the Jaeger ingress
1544
annotations: {}
1545
# -- Hosts configuration for the Jaeger ingress
1546
hosts:
1547
- host: query.tempo.example.com
1548
paths:
1549
- path: /
1550
# -- pathType (e.g. ImplementationSpecific, Prefix, .. etc.) might also be required by some Ingress Controllers
1551
# pathType: Prefix
1552
# -- TLS configuration for the Jaeger ingress
1553
tls:
1554
- secretName: tempo-query-tls
1555
hosts:
1556
- query.tempo.example.com
1557
# -- Gateway API route configuration for the query-frontend (Jaeger UI).
1558
# Multiple routes can be added by adding a dictionary key like the 'main' route.
1559
route:
1560
main:
1561
# -- Specifies whether a Gateway API route for the query-frontend should be created
1562
enabled: false
1563
# -- Set the route apiVersion, e.g. gateway.networking.k8s.io/v1 or gateway.networking.k8s.io/v1beta1
1564
# If not set, the latest available version will be auto-detected
1565
apiVersion: ""
1566
# -- Set the route kind
1567
# Valid options are GRPCRoute, HTTPRoute, TCPRoute, TLSRoute, UDPRoute
1568
kind: HTTPRoute
1569
# -- Route annotations
1570
annotations: {}
1571
# -- Route labels
1572
labels: {}
1573
# -- Hostnames for the route
1574
hostnames: []
1575
# - query.tempo.example.com
1576
# -- Parent references (gateway to attach to)
1577
parentRefs: []
1578
# - name: my-gateway
1579
# namespace: gateway-namespace
1580
# -- Matches define conditions for matching incoming requests
1581
matches:
1582
- path:
1583
type: PathPrefix
1584
value: /
1585
# -- Timeouts define the timeouts that can be configured for an HTTP request.
1586
# Ref. https://gateway-api.sigs.k8s.io/api-types/httproute/#timeouts-optional
1587
timeouts: {}
1588
# -- Filters define the filters that are applied to requests that match this rule.
1589
filters: []
1590
# -- Additional custom rules that can be added to the route
1591
additionalRules: []
1592
# -- The name of the PriorityClass for query-frontend pods
1593
priorityClassName: null
1594
# -- Labels for queryFrontend pods
1595
podLabels: {}
1596
# -- Annotations for query-frontend pods
1597
podAnnotations: {}
1598
# -- Additional CLI args for the query-frontend
1599
extraArgs: []
1600
# -- Environment variables to add to the query-frontend pods
1601
extraEnv: []
1602
# -- Environment variables from secrets or configmaps to add to the query-frontend pods
1603
extraEnvFrom: []
1604
# -- Liveness probe for query-frontend pods. Uses `tempo.livenessProbe` as default if not set.
1605
livenessProbe: {}
1606
# -- Readiness probe for query-frontend pods. Uses `tempo.readinessProbe` as default if not set.
1607
readinessProbe: {}
1608
# -- Startup probe for query-frontend pods. Uses `tempo.startupProbe` as default if not set.
1609
startupProbe: {}
1610
# -- Resource requests and limits for the query-frontend
1611
resources: {}
1612
# -- Grace period to allow the query-frontend to shutdown before it is killed
1613
terminationGracePeriodSeconds: 30
1614
# -- topologySpread for query-frontend pods. Passed through `tpl` and, thus, to be configured as string
1615
# @default -- Defaults to allow skew no more then 1 node per AZ
1616
topologySpreadConstraints: |
1617
- maxSkew: 1
1618
topologyKey: topology.kubernetes.io/zone
1619
whenUnsatisfiable: ScheduleAnyway
1620
labelSelector:
1621
matchLabels:
1622
{{- include "tempo.selectorLabels" (dict "ctx" . "component" "query-frontend") | nindent 6 }}
1623
# -- Affinity for query-frontend pods. Passed through `tpl` and, thus, to be configured as string
1624
# @default -- Hard node and soft zone anti-affinity
1625
affinity: |
1626
podAntiAffinity:
1627
requiredDuringSchedulingIgnoredDuringExecution:
1628
- labelSelector:
1629
matchLabels:
1630
{{- include "tempo.selectorLabels" (dict "ctx" . "component" "query-frontend") | nindent 10 }}
1631
topologyKey: kubernetes.io/hostname
1632
preferredDuringSchedulingIgnoredDuringExecution:
1633
- weight: 100
1634
podAffinityTerm:
1635
labelSelector:
1636
matchLabels:
1637
{{- include "tempo.selectorLabels" (dict "ctx" . "component" "query-frontend") | nindent 12 }}
1638
topologyKey: topology.kubernetes.io/zone
1639
# -- Pod Disruption Budget configuration
1640
podDisruptionBudget:
1641
# -- Enable PodDisruptionBudget for query-frontend
1642
enabled: true
1643
# -- Set unhealthyPodEvictionPolicy for the query-frontend PodDisruptionBudget. Requires policy/v1.
1644
unhealthyPodEvictionPolicy: ""
1645
# -- Pod Disruption Budget maxUnavailable
1646
maxUnavailable: 1
1647
# -- Minimum number of seconds for which a newly created Pod should be ready without any of its containers crashing/terminating
1648
minReadySeconds: 10
1649
# -- Node selector for query-frontend pods
1650
nodeSelector: {}
1651
# -- Tolerations for query-frontend pods
1652
tolerations: []
1653
# -- Init containers for the query-frontend pod
1654
initContainers: []
1655
# -- Containers to add to the query-frontend pods
1656
extraContainers: []
1657
# -- Additional ports to expose on the query-frontend container.
1658
# The gRPC port is included by default. Standard ports (http-metrics, http-memberlist)
1659
# are always added automatically by the pod template.
1660
extraPorts:
1661
- containerPort: 9095
1662
name: grpc
1663
protocol: TCP
1664
# -- Extra volumes for query-frontend pods
1665
extraVolumeMounts: []
1666
# -- Extra volumes for query-frontend deployment
1667
extraVolumes: []
1668
# -- Adds the appProtocol field to the queryFrontend service. This allows queryFrontend to work with istio protocol selection.
1669
appProtocol:
1670
# -- Set the optional gRPC service protocol. Ex: "grpc", "http2" or "https"
1671
grpc: null
1672
mcp_server:
1673
# -- Enables Tempo MCP Server
1674
enabled: false
1675
# Configuration for the federation-frontend
1676
# Can only be enabled if enterprise.enabled is true - requires license.
1677
enterpriseFederationFrontend:
1678
# -- Specifies whether a federation-frontend should be deployed
1679
enabled: false
1680
# -- Number of replicas for the federation-frontend
1681
replicas: 1
1682
# -- Annotations for the federation-frontend Deployment
1683
annotations: {}
1684
# -- hostAliases to add
1685
hostAliases: []
1686
# - ip: 1.2.3.4
1687
# hostnames:
1688
# - domain.tld
1689
proxy_targets: []
1690
# - name: own-data-center
1691
# url: http://get/tempo
1692
# - name: grafana-cloud
1693
# url: https://tempo-us-central1.grafana.net/tempo
1694
# basic_auth:
1695
# username: <instance-id>
1696
# password: <token>
1697
autoscaling:
1698
# -- Enable autoscaling for the federation-frontend
1699
enabled: false
1700
# -- Minimum autoscaling replicas for the federation-frontend
1701
minReplicas: 1
1702
# -- Maximum autoscaling replicas for the federation-frontend
1703
maxReplicas: 3
1704
# -- Target CPU utilisation percentage for the federation-frontend
1705
targetCPUUtilizationPercentage: 60
1706
# -- Target memory utilisation percentage for the federation-frontend
1707
targetMemoryUtilizationPercentage:
1708
image:
1709
# -- The Docker registry for the federation-frontend image. Overrides `tempo.image.registry`
1710
registry: null
1711
# -- Optional list of imagePullSecrets. Overrides `tempo.image.pullSecrets`
1712
pullSecrets: []
1713
# -- Docker image repository for the federation-frontend image. Overrides `tempo.image.repository`
1714
repository: null
1715
# -- Docker image tag for the federation-frontend image. Overrides `tempo.image.tag`
1716
tag: null
1717
service:
1718
# -- Port of the federation-frontend service
1719
port: 3200
1720
# -- Annotations for enterpriseFederationFrontend service
1721
annotations: {}
1722
# -- Type of service for the enterpriseFederationFrontend
1723
type: ClusterIP
1724
# -- If type is LoadBalancer you can assign the IP to the LoadBalancer
1725
loadBalancerIP: ""
1726
# -- If type is LoadBalancer limit incoming traffic from IPs.
1727
loadBalancerSourceRanges: []
1728
# -- The name of the PriorityClass for federation-frontend pods
1729
priorityClassName: null
1730
# -- Labels for enterpriseFederationFrontend pods
1731
podLabels: {}
1732
# -- Annotations for federation-frontend pods
1733
podAnnotations: {}
1734
# -- Additional CLI args for the federation-frontend
1735
extraArgs: []
1736
# -- Environment variables to add to the federation-frontend pods
1737
extraEnv: []
1738
# -- Environment variables from secrets or configmaps to add to the federation-frontend pods
1739
extraEnvFrom: []
1740
# -- Resource requests and limits for the federation-frontend
1741
resources: {}
1742
# -- Grace period to allow the federation-frontend to shutdown before it is killed
1743
terminationGracePeriodSeconds: 30
1744
# -- topologySpread for federation-frontend pods. Passed through `tpl` and, thus, to be configured as string
1745
# @default -- Defaults to allow skew no more then 1 node per AZ
1746
topologySpreadConstraints: |
1747
- maxSkew: 1
1748
topologyKey: failure-domain.beta.kubernetes.io/zone
1749
whenUnsatisfiable: ScheduleAnyway
1750
labelSelector:
1751
matchLabels:
1752
{{- include "tempo.selectorLabels" (dict "ctx" . "component" "federation-frontend") | nindent 6 }}
1753
# -- Affinity for federation-frontend pods. Passed through `tpl` and, thus, to be configured as string
1754
# @default -- Hard node and soft zone anti-affinity
1755
affinity: |
1756
podAntiAffinity:
1757
requiredDuringSchedulingIgnoredDuringExecution:
1758
- labelSelector:
1759
matchLabels:
1760
{{- include "tempo.selectorLabels" (dict "ctx" . "component" "federation-frontend") | nindent 10 }}
1761
topologyKey: kubernetes.io/hostname
1762
preferredDuringSchedulingIgnoredDuringExecution:
1763
- weight: 100
1764
podAffinityTerm:
1765
labelSelector:
1766
matchLabels:
1767
{{- include "tempo.selectorLabels" (dict "ctx" . "component" "federation-frontend") | nindent 12 }}
1768
topologyKey: failure-domain.beta.kubernetes.io/zone
1769
# -- Pod Disruption Budget configuration
1770
podDisruptionBudget:
1771
# -- Enable PodDisruptionBudget for enterprise-federation-frontend
1772
enabled: true
1773
# -- Pod Disruption Budget maxUnavailable
1774
maxUnavailable: 1
1775
# -- Node selector for federation-frontend pods
1776
nodeSelector: {}
1777
# -- Tolerations for federation-frontend pods
1778
tolerations: []
1779
# -- Extra volumes for federation-frontend pods
1780
extraVolumeMounts: []
1781
# -- Extra volumes for federation-frontend deployment
1782
extraVolumes: []
1783
multitenancyEnabled: false
1784
rollout_operator:
1785
# -- Enable rollout-operator. It must be enabled when using Zone Aware Replication.
1786
enabled: false
1787
podSecurityContext:
1788
fsGroup: 10001
1789
runAsGroup: 10001
1790
runAsNonRoot: true
1791
runAsUser: 10001
1792
seccompProfile:
1793
type: RuntimeDefault
1794
# Set the container security context
1795
securityContext:
1796
readOnlyRootFilesystem: true
1797
capabilities:
1798
drop: [ALL]
1799
allowPrivilegeEscalation: false
1800
traces:
1801
jaeger:
1802
grpc:
1803
# -- Enable Tempo to ingest Jaeger gRPC traces
1804
enabled: false
1805
# -- Jaeger gRPC receiver config
1806
receiverConfig: {}
1807
thriftBinary:
1808
# -- Enable Tempo to ingest Jaeger Thrift Binary traces
1809
enabled: false
1810
# -- Jaeger Thrift Binary receiver config
1811
receiverConfig: {}
1812
thriftCompact:
1813
# -- Enable Tempo to ingest Jaeger Thrift Compact traces
1814
enabled: false
1815
# -- Jaeger Thrift Compact receiver config
1816
receiverConfig: {}
1817
thriftHttp:
1818
# -- Enable Tempo to ingest Jaeger Thrift HTTP traces
1819
enabled: false
1820
# -- Jaeger Thrift HTTP receiver config
1821
receiverConfig: {}
1822
zipkin:
1823
# -- Enable Tempo to ingest Zipkin traces
1824
enabled: false
1825
# -- Zipkin receiver config
1826
receiverConfig: {}
1827
otlp:
1828
http:
1829
# -- Enable Tempo to ingest Open Telemetry HTTP traces
1830
enabled: false
1831
# -- HTTP receiver advanced config
1832
receiverConfig: {}
1833
grpc:
1834
# -- Enable Tempo to ingest Open Telemetry gRPC traces
1835
enabled: false
1836
# -- gRPC receiver advanced config
1837
receiverConfig: {}
1838
# -- Default OTLP gRPC port
1839
port: 4317
1840
# -- Enable Tempo to ingest traces from Kafka. Reference: https://github.com/open-telemetry/opentelemetry-collector-contrib/tree/main/receiver/kafkareceiver
1841
kafka: {}
1842
# -- Memberlist configuration. Please refer to https://grafana.com/docs/tempo/latest/configuration/#memberlist
1843
memberlist:
1844
node_name: ""
1845
cluster_label: "{{ .Release.Name }}.{{ .Release.Namespace }}"
1846
randomize_node_name: true
1847
stream_timeout: "10s"
1848
retransmit_factor: 2
1849
pull_push_interval: "30s"
1850
gossip_interval: "1s"
1851
gossip_nodes: 2
1852
gossip_to_dead_nodes_time: "30s"
1853
min_join_backoff: "1s"
1854
max_join_backoff: "1m"
1855
max_join_retries: 10
1856
abort_if_cluster_join_fails: false
1857
rejoin_interval: "0s"
1858
left_ingesters_timeout: "5m"
1859
leave_timeout: "5s"
1860
bind_addr: []
1861
bind_port: 7946
1862
packet_dial_timeout: "5s"
1863
packet_write_timeout: "5s"
1864
# -- Config file contents for Tempo distributed. Passed through the `tpl` function to allow templating
1865
1866
# @default -- See values.yaml
1867
config: |
1868
multitenancy_enabled: {{ .Values.multitenancyEnabled }}
1869
1870
stream_over_http_enabled: {{ .Values.streamOverHTTPEnabled }}
1871
1872
usage_report:
1873
reporting_enabled: {{ .Values.reportingEnabled }}
1874
1875
{{- if .Values.enterprise.enabled }}
1876
license:
1877
path: "/license/license.jwt"
1878
1879
admin_api:
1880
leader_election:
1881
enabled: true
1882
ring:
1883
kvstore:
1884
store: "memberlist"
1885
1886
auth:
1887
type: enterprise
1888
1889
http_api_prefix: {{get .Values.tempo.structuredConfig "http_api_prefix"}}
1890
1891
admin_client:
1892
storage:
1893
backend: {{.Values.storage.admin.backend}}
1894
{{- if eq .Values.storage.admin.backend "s3"}}
1895
s3:
1896
{{- toYaml .Values.storage.admin.s3 | nindent 6}}
1897
{{- end}}
1898
{{- if eq .Values.storage.admin.backend "gcs"}}
1899
gcs:
1900
{{- toYaml .Values.storage.admin.gcs | nindent 6}}
1901
{{- end}}
1902
{{- if eq .Values.storage.admin.backend "azure"}}
1903
azure:
1904
{{- toYaml .Values.storage.admin.azure | nindent 6}}
1905
{{- end}}
1906
{{- if eq .Values.storage.admin.backend "swift"}}
1907
swift:
1908
{{- toYaml .Values.storage.admin.swift | nindent 6}}
1909
{{- end}}
1910
{{- if eq .Values.storage.admin.backend "filesystem"}}
1911
filesystem:
1912
{{- toYaml .Values.storage.admin.filesystem | nindent 6}}
1913
{{- end}}
1914
{{- end }}
1915
1916
{{- if and .Values.enterprise.enabled .Values.enterpriseGateway.useDefaultProxyURLs }}
1917
gateway:
1918
proxy:
1919
admin_api:
1920
url: http://{{ template "tempo.fullname" . }}-admin-api.{{ .Release.Namespace }}.svc:{{ include "tempo.serverHttpListenPort" . }}
1921
{{- if .Values.backendScheduler.enabled }}
1922
backend_worker:
1923
url: http://{{ template "tempo.fullname" . }}-backend-worker.{{ .Release.Namespace }}.svc:{{ include "tempo.serverHttpListenPort" . }}
1924
{{- end }}
1925
default:
1926
url: http://{{ template "tempo.fullname" . }}-admin-api.{{ .Release.Namespace }}.svc:{{ include "tempo.serverHttpListenPort" . }}
1927
distributor:
1928
url: http://{{ template "tempo.fullname" . }}-distributor.{{ .Release.Namespace }}.svc:{{ include "tempo.serverHttpListenPort" . }}
1929
otlp/grpc:
1930
url: h2c://{{ template "tempo.fullname" . }}-distributor.{{ .Release.Namespace }}.svc:4317
1931
otlp/http:
1932
url: http://{{ template "tempo.fullname" . }}-distributor.{{ .Release.Namespace }}.svc:4318
1933
querier:
1934
url: http://{{ template "tempo.fullname" . }}-querier.{{ .Release.Namespace }}.svc:{{ include "tempo.serverHttpListenPort" . }}
1935
query_frontend:
1936
url: http://{{ template "tempo.fullname" . }}-query-frontend.{{ .Release.Namespace }}.svc:{{ include "tempo.serverHttpListenPort" . }}{{get .Values.tempo.structuredConfig "http_api_prefix"}}
1937
{{else}}
1938
{{- if and .Values.enterprise.enabled .Values.enterpriseGateway.proxy }}
1939
gateway:
1940
proxy: {{- toYaml .Values.enterpriseGateway.proxy | nindent 6 }}
1941
{{- end }}
1942
{{- end }}
1943
1944
{{- if .Values.backendScheduler.enabled }}
1945
backend_scheduler:
1946
work:
1947
prune_age: {{ .Values.backendScheduler.config.work.prune_age }}
1948
dead_job_timeout: {{ .Values.backendScheduler.config.work.dead_job_timeout }}
1949
maintenance_interval: {{ .Values.backendScheduler.config.maintenance_interval }}
1950
backend_flush_interval: {{ .Values.backendScheduler.config.backend_flush_interval }}
1951
provider:
1952
retention:
1953
interval: {{ .Values.backendScheduler.config.provider.retention.interval }}
1954
compaction:
1955
compaction:
1956
block_retention: {{ .Values.backendScheduler.config.provider.compaction.compaction.block_retention }}
1957
compacted_block_retention: {{ .Values.backendScheduler.config.provider.compaction.compaction.compacted_block_retention }}
1958
compaction_cycle: {{ .Values.backendScheduler.config.provider.compaction.compaction.compaction_cycle }}
1959
compaction_window: {{ .Values.backendScheduler.config.provider.compaction.compaction.compaction_window }}
1960
max_block_bytes: {{ .Values.backendScheduler.config.provider.compaction.compaction.max_block_bytes }}
1961
max_compaction_objects: {{ .Values.backendScheduler.config.provider.compaction.compaction.max_compaction_objects }}
1962
max_time_per_tenant: {{ .Values.backendScheduler.config.provider.compaction.compaction.max_time_per_tenant }}
1963
retention_concurrency: {{ .Values.backendScheduler.config.provider.compaction.compaction.retention_concurrency }}
1964
max_jobs_per_tenant: {{ .Values.backendScheduler.config.provider.compaction.max_jobs_per_tenant }}
1965
min_input_blocks: {{ .Values.backendScheduler.config.provider.compaction.min_input_blocks }}
1966
max_input_blocks: {{ .Values.backendScheduler.config.provider.compaction.max_input_blocks }}
1967
max_compaction_level: {{ .Values.backendScheduler.config.provider.compaction.max_compaction_level }}
1968
min_cycle_interval: {{ .Values.backendScheduler.config.provider.compaction.min_cycle_interval }}
1969
job_timeout: {{ .Values.backendScheduler.config.job_timeout }}
1970
local_work_path: {{ .Values.backendScheduler.config.local_work_path }}
1971
1972
{{- with .Values.backendWorker.config.backend_scheduler_client.grpc_client_config }}
1973
backend_scheduler_client:
1974
grpc_client_config:
1975
{{- toYaml . | nindent 6 }}
1976
1977
{{- end }}
1978
backend_worker:
1979
backend_scheduler_addr: {{ include "tempo.resourceName" (dict "ctx" . "component" "backend-scheduler") }}:9095
1980
backoff:
1981
min_period: {{ .Values.backendWorker.config.backoff.min_period }}
1982
max_period: {{ .Values.backendWorker.config.backoff.max_period }}
1983
max_retries: {{ .Values.backendWorker.config.backoff.max_retries }}
1984
{{- $compaction_default := .Values.backendScheduler.config.provider.compaction.compaction }}
1985
{{- $worker_overrides := .Values.backendWorker.config.compaction }}
1986
{{- $compaction := mergeOverwrite (deepCopy $compaction_default) $worker_overrides }}
1987
compaction:
1988
{{- toYaml $compaction | nindent 6 }}
1989
finish_on_shutdown_timeout: {{ .Values.backendWorker.config.finish_on_shutdown_timeout }}
1990
ring:
1991
kvstore:
1992
store: memberlist
1993
{{- end }}
1994
{{- if .Values.blockBuilder.enabled }}
1995
block_builder:
1996
partitions_per_instance: {{ .Values.blockBuilder.config.partitions_per_instance }}
1997
{{- end }}
1998
{{- if .Values.liveStore.enabled }}
1999
live_store:
2000
{{- with .Values.liveStore.config }}
2001
{{- toYaml . | nindent 4 }}
2002
{{- end }}
2003
{{- end }}
2004
{{- if and .Values.enterprise.enabled .Values.enterpriseFederationFrontend.enabled }}
2005
federation:
2006
proxy_targets:
2007
{{- toYaml .Values.enterpriseFederationFrontend.proxy_targets | nindent 6 }}
2008
{{- end }}
2009
{{- if .Values.metricsGenerator.enabled }}
2010
metrics_generator:
2011
ring:
2012
kvstore:
2013
store: memberlist
2014
processor:
2015
{{- toYaml .Values.metricsGenerator.config.processor | nindent 6 }}
2016
storage:
2017
{{- toYaml .Values.metricsGenerator.config.storage | nindent 6 }}
2018
registry:
2019
{{- toYaml .Values.metricsGenerator.config.registry | nindent 6 }}
2020
metrics_ingestion_time_range_slack: {{ .Values.metricsGenerator.config.metrics_ingestion_time_range_slack }}
2021
{{- end }}
2022
distributor:
2023
{{- if .Values.distributor.config.cost_attribution.enabled }}
2024
usage:
2025
cost_attribution:
2026
enabled: {{ .Values.distributor.config.cost_attribution.enabled }}
2027
max_cardinality: {{ .Values.distributor.config.cost_attribution.max_cardinality }}
2028
stale_duration: {{ .Values.distributor.config.cost_attribution.stale_duration }}
2029
{{- end }}
2030
ring:
2031
kvstore:
2032
store: memberlist
2033
receivers:
2034
{{- if or (.Values.traces.jaeger.thriftCompact.enabled) (.Values.traces.jaeger.thriftBinary.enabled) (.Values.traces.jaeger.thriftHttp.enabled) (.Values.traces.jaeger.grpc.enabled) }}
2035
jaeger:
2036
protocols:
2037
{{- if .Values.traces.jaeger.thriftCompact.enabled }}
2038
thrift_compact:
2039
{{- $mergedJaegerThriftCompactConfig := mustMergeOverwrite (dict "endpoint" "0.0.0.0:6831") .Values.traces.jaeger.thriftCompact.receiverConfig }}
2040
{{- toYaml $mergedJaegerThriftCompactConfig | nindent 10 }}
2041
{{- end }}
2042
{{- if .Values.traces.jaeger.thriftBinary.enabled }}
2043
thrift_binary:
2044
{{- $mergedJaegerThriftBinaryConfig := mustMergeOverwrite (dict "endpoint" "0.0.0.0:6832") .Values.traces.jaeger.thriftBinary.receiverConfig }}
2045
{{- toYaml $mergedJaegerThriftBinaryConfig | nindent 10 }}
2046
{{- end }}
2047
{{- if .Values.traces.jaeger.thriftHttp.enabled }}
2048
thrift_http:
2049
{{- $mergedJaegerThriftHttpConfig := mustMergeOverwrite (dict "endpoint" "0.0.0.0:14268") .Values.traces.jaeger.thriftHttp.receiverConfig }}
2050
{{- toYaml $mergedJaegerThriftHttpConfig | nindent 10 }}
2051
{{- end }}
2052
{{- if .Values.traces.jaeger.grpc.enabled }}
2053
grpc:
2054
{{- $mergedJaegerGrpcConfig := mustMergeOverwrite (dict "endpoint" "0.0.0.0:14250") .Values.traces.jaeger.grpc.receiverConfig }}
2055
{{- toYaml $mergedJaegerGrpcConfig | nindent 10 }}
2056
{{- end }}
2057
{{- end }}
2058
{{- if .Values.traces.zipkin.enabled }}
2059
zipkin:
2060
{{- $mergedZipkinReceiverConfig := mustMergeOverwrite (dict "endpoint" "0.0.0.0:9411") .Values.traces.zipkin.receiverConfig }}
2061
{{- toYaml $mergedZipkinReceiverConfig | nindent 6 }}
2062
{{- end }}
2063
{{- if or (.Values.traces.otlp.http.enabled) (.Values.traces.otlp.grpc.enabled) }}
2064
otlp:
2065
protocols:
2066
{{- if .Values.traces.otlp.http.enabled }}
2067
http:
2068
{{- $mergedOtlpHttpReceiverConfig := mustMergeOverwrite (dict "endpoint" "0.0.0.0:4318") .Values.traces.otlp.http.receiverConfig }}
2069
{{- toYaml $mergedOtlpHttpReceiverConfig | nindent 10 }}
2070
{{- end }}
2071
{{- if .Values.traces.otlp.grpc.enabled }}
2072
grpc:
2073
{{- $mergedOtlpGrpcReceiverConfig := mustMergeOverwrite (dict "endpoint" "0.0.0.0:4317") .Values.traces.otlp.grpc.receiverConfig }}
2074
{{- toYaml $mergedOtlpGrpcReceiverConfig | nindent 10 }}
2075
{{- end }}
2076
{{- end }}
2077
{{- if .Values.traces.kafka }}
2078
kafka:
2079
{{- toYaml .Values.traces.kafka | nindent 6 }}
2080
{{- end }}
2081
{{- if .Values.distributor.config.log_discarded_spans.enabled }}
2082
log_discarded_spans:
2083
enabled: {{ .Values.distributor.config.log_discarded_spans.enabled }}
2084
include_all_attributes: {{ .Values.distributor.config.log_discarded_spans.include_all_attributes }}
2085
filter_by_status_error: {{ .Values.distributor.config.log_discarded_spans.filter_by_status_error }}
2086
{{- end }}
2087
{{- if or .Values.distributor.config.log_received_traces .Values.distributor.config.log_received_spans.enabled }}
2088
log_received_spans:
2089
enabled: {{ or .Values.distributor.config.log_received_traces .Values.distributor.config.log_received_spans.enabled }}
2090
include_all_attributes: {{ .Values.distributor.config.log_received_spans.include_all_attributes }}
2091
filter_by_status_error: {{ .Values.distributor.config.log_received_spans.filter_by_status_error }}
2092
{{- end }}
2093
{{- if .Values.distributor.config.extend_writes }}
2094
extend_writes: {{ .Values.distributor.config.extend_writes }}
2095
{{- end }}
2096
{{- if not (eq .Values.distributor.config.max_attribute_bytes nil) }}
2097
max_attribute_bytes: {{ .Values.distributor.config.max_attribute_bytes }}
2098
{{- end }}
2099
querier:
2100
frontend_worker:
2101
frontend_address: {{ include "tempo.resourceName" (dict "ctx" . "component" "query-frontend-discovery") }}:9095
2102
{{- if .Values.querier.config.frontend_worker.grpc_client_config }}
2103
grpc_client_config:
2104
{{- toYaml .Values.querier.config.frontend_worker.grpc_client_config | nindent 6 }}
2105
{{- end }}
2106
trace_by_id:
2107
query_timeout: {{ .Values.querier.config.trace_by_id.query_timeout }}
2108
search:
2109
query_timeout: {{ .Values.querier.config.search.query_timeout }}
2110
max_concurrent_queries: {{ .Values.querier.config.max_concurrent_queries }}
2111
query_frontend:
2112
{{- if not .Values.enterprise.enabled }}
2113
mcp_server:
2114
enabled: {{ .Values.queryFrontend.mcp_server.enabled }}
2115
{{- end }}
2116
max_outstanding_per_tenant: {{ .Values.queryFrontend.config.max_outstanding_per_tenant }}
2117
max_retries: {{ .Values.queryFrontend.config.max_retries }}
2118
search:
2119
target_bytes_per_job: {{ .Values.queryFrontend.config.search.target_bytes_per_job }}
2120
concurrent_jobs: {{ .Values.queryFrontend.config.search.concurrent_jobs }}
2121
max_spans_per_span_set: {{ .Values.queryFrontend.config.search.max_spans_per_span_set }}
2122
{{- with .Values.queryFrontend.config.search.max_result_limit }}
2123
max_result_limit: {{ . }}
2124
{{- end }}
2125
trace_by_id:
2126
query_shards: {{ .Values.queryFrontend.config.trace_by_id.query_shards }}
2127
metrics:
2128
concurrent_jobs: {{ .Values.queryFrontend.config.metrics.concurrent_jobs }}
2129
target_bytes_per_job: {{ .Values.queryFrontend.config.metrics.target_bytes_per_job }}
2130
max_duration: {{ .Values.queryFrontend.config.metrics.max_duration }}
2131
query_backend_after: {{ .Values.queryFrontend.config.metrics.query_backend_after }}
2132
interval: {{ .Values.queryFrontend.config.metrics.interval }}
2133
duration_slo: {{ .Values.queryFrontend.config.metrics.duration_slo }}
2134
throughput_bytes_slo: {{ .Values.queryFrontend.config.metrics.throughput_bytes_slo }}
2135
{{- with .Values.ingest.kafka.address }}
2136
ingest:
2137
kafka:
2138
address: {{ . }}
2139
topic: {{ $.Values.ingest.kafka.topic }}
2140
auto_create_topic_enabled: {{ $.Values.ingest.kafka.auto_create_topic_enabled }}
2141
auto_create_topic_default_partitions: {{ $.Values.ingest.kafka.auto_create_topic_default_partitions }}
2142
{{- end }}
2143
memberlist:
2144
{{- with .Values.memberlist }}
2145
{{- toYaml . | nindent 2 }}
2146
{{- end }}
2147
join_members:
2148
- dns+{{ include "tempo.fullname" . }}-gossip-ring:{{ .Values.memberlist.bind_port }}
2149
overrides:
2150
{{- toYaml .Values.overrides | nindent 2 }}
2151
server:
2152
http_listen_port: {{ .Values.server.httpListenPort }}
2153
log_level: {{ .Values.server.logLevel }}
2154
log_format: {{ .Values.server.logFormat }}
2155
grpc_server_max_recv_msg_size: {{ .Values.server.grpc_server_max_recv_msg_size }}
2156
grpc_server_max_send_msg_size: {{ .Values.server.grpc_server_max_send_msg_size }}
2157
http_server_read_timeout: {{ .Values.server.http_server_read_timeout }}
2158
http_server_write_timeout: {{ .Values.server.http_server_write_timeout }}
2159
cache:
2160
{{- include "tempo.cacheConfig" . | nindent 2}}
2161
storage:
2162
trace:
2163
{{- if .Values.storage.trace.block.version }}
2164
block:
2165
version: {{.Values.storage.trace.block.version}}
2166
{{- if .Values.storage.trace.block.dedicated_columns}}
2167
parquet_dedicated_columns:
2168
{{ .Values.storage.trace.block.dedicated_columns | toYaml | nindent 8}}
2169
{{- end }}
2170
{{- end }}
2171
pool:
2172
max_workers: {{ .Values.storage.trace.pool.max_workers }}
2173
queue_depth: {{ .Values.storage.trace.pool.queue_depth }}
2174
backend: {{.Values.storage.trace.backend}}
2175
{{- if eq .Values.storage.trace.backend "s3"}}
2176
s3:
2177
{{- toYaml .Values.storage.trace.s3 | nindent 6}}
2178
{{- end }}
2179
{{- if eq .Values.storage.trace.backend "gcs"}}
2180
gcs:
2181
{{- toYaml .Values.storage.trace.gcs | nindent 6}}
2182
{{- end }}
2183
{{- if eq .Values.storage.trace.backend "azure"}}
2184
azure:
2185
{{- toYaml .Values.storage.trace.azure | nindent 6}}
2186
{{- end }}
2187
blocklist_poll: 5m
2188
local:
2189
path: /var/tempo/traces
2190
wal:
2191
path: /var/tempo/wal
2192
search:
2193
{{- toYaml .Values.storage.trace.search | nindent 6}}
2194
2195
{{- if .Values.storage.trace.blocklist_poll }}
2196
blocklist_poll: {{ .Values.storage.trace.blocklist_poll }}
2197
{{- end }}
2198
{{- if .Values.storage.trace.blocklist_poll_concurrency }}
2199
blocklist_poll_concurrency: {{ .Values.storage.trace.blocklist_poll_concurrency }}
2200
{{- end }}
2201
{{- if .Values.storage.trace.blocklist_poll_fallback }}
2202
blocklist_poll_fallback: {{ .Values.storage.trace.blocklist_poll_fallback }}
2203
{{- end }}
2204
{{- if .Values.storage.trace.blocklist_poll_tenant_index_builders }}
2205
blocklist_poll_tenant_index_builders: {{ .Values.storage.trace.blocklist_poll_tenant_index_builders }}
2206
{{- end }}
2207
{{- if .Values.storage.trace.blocklist_poll_stale_tenant_index }}
2208
blocklist_poll_stale_tenant_index: {{ .Values.storage.trace.blocklist_poll_stale_tenant_index }}
2209
{{- end }}
2210
{{- if .Values.storage.trace.empty_tenant_deletion_age }}
2211
empty_tenant_deletion_age: {{ .Values.storage.trace.empty_tenant_deletion_age }}
2212
{{- end }}
2213
{{- if .Values.storage.trace.empty_tenant_deletion_enabled }}
2214
empty_tenant_deletion_enabled: {{ .Values.storage.trace.empty_tenant_deletion_enabled }}
2215
{{- end }}
2216
# Set Tempo server configuration
2217
# Refers to https://grafana.com/docs/tempo/latest/configuration/#server
2218
server:
2219
# -- HTTP server listen host
2220
httpListenPort: 3200
2221
# -- Log level. Can be set to debug, info (default), warn, error
2222
logLevel: info
2223
# -- Log format. Can be set to logfmt (default) or json.
2224
logFormat: logfmt
2225
# -- Max gRPC message size that can be received
2226
grpc_server_max_recv_msg_size: 4194304
2227
# -- Max gRPC message size that can be sent
2228
grpc_server_max_send_msg_size: 4194304
2229
# -- Read timeout for HTTP server
2230
http_server_read_timeout: 30s
2231
# -- Write timeout for HTTP server
2232
http_server_write_timeout: 30s
2233
# Use this block to configure caches available throughout the application.
2234
# Multiple caches can be created and assigned roles which determine how they are used by Tempo.
2235
# https://grafana.com/docs/tempo/latest/configuration/#cache
2236
# When memcached.enabled is true (the default), the cache.caches list is auto-generated from the
2237
# memcached and per-role memcached sections (memcachedBloom, memcachedParquetFooter, memcachedFrontendSearch).
2238
# When memcached.enabled is false, this block is passed through verbatim to allow configuring external caches.
2239
cache:
2240
caches:
2241
- memcached:
2242
host: '{{ include "tempo.fullname" . }}-memcached'
2243
service: memcached-client
2244
consistent_hash: true
2245
timeout: 500ms
2246
roles:
2247
- parquet-footer
2248
- bloom
2249
- frontend-search
2250
# To configure a different storage backend instead of local storage:
2251
# storage:
2252
# trace:
2253
# backend: azure
2254
# azure:
2255
# container_name:
2256
# storage_account_name:
2257
# storage_account_key:
2258
storage:
2259
trace:
2260
# Settings for the block storage backend and buckets.
2261
block:
2262
# -- The supported block versions are specified here https://grafana.com/docs/tempo/latest/configuration/parquet/
2263
version: null
2264
# -- Lis with dedicated attribute columns (only for vParquet3 or later)
2265
dedicated_columns: []
2266
# -- The supported storage backends are gcs, s3 and azure, as specified in https://grafana.com/docs/tempo/latest/configuration/#storage
2267
backend: local
2268
# The worker pool is used primarily when finding traces by id, but is also used by others.
2269
pool:
2270
# -- Total number of workers pulling jobs from the queue
2271
max_workers: 400
2272
# -- Length of job queue. imporatant for querier as it queues a job for every block it has to search
2273
queue_depth: 20000
2274
# The supported search are specified here https://grafana.com/docs/tempo/latest/configuration/#search-config
2275
search:
2276
# -- Number of traces to prefetch while scanning blocks. Increasing this value can improve trace search performance at the cost of memory.
2277
prefetch_trace_count: 1000
2278
# -- How often to repoll the backend for new blocks
2279
blocklist_poll: 5m
2280
# -- Number of blocks to process in parallel during polling.
2281
blocklist_poll_concurrency: null
2282
# -- By default components will pull the blocklist from the tenant index. If that fails the component can
2283
# -- fallback to scanning the entire bucket. Set to false to disable this behavior.
2284
blocklist_poll_fallback: null
2285
# -- Maximum number of compactors that should build the tenant index. All other components will download the index.
2286
blocklist_poll_tenant_index_builders: null
2287
# -- The oldest allowable tenant index.
2288
blocklist_poll_stale_tenant_index: null
2289
# -- How fast the poller will delete a tenant if it is empty. Will need to be enabled in 'empty_tenant_deletion_enabled'.
2290
empty_tenant_deletion_age: null
2291
# -- Delete empty tenants.
2292
empty_tenant_deletion_enabled: null
2293
# Settings for the Admin client storage backend and buckets. Only valid is enterprise.enabled is true
2294
admin:
2295
# -- The supported storage backends are gcs, s3 and azure, as specified in https://grafana.com/docs/enterprise-traces/latest/configure/reference/#admin_client_config
2296
backend: filesystem
2297
# -- The standard overrides configuration section. This can include a `defaults` object for applying to all tenants (not to be confused with the `global` property of the same name, which overrides `max_byte_per_trace` for all tenants). For an example on how to enable the metrics generator using the `overrides` object, see the 'Activate metrics generator' section below. Refer to [Standard overrides](https://grafana.com/docs/tempo/latest/configuration/#standard-overrides) for more details.
2298
overrides:
2299
# -- default config values for all tenants, can be overridden by per-tenant overrides. If a tenant's specific overrides are not found in the `per_tenant_overrides` block, the values in this `default` block will be used. Configs inside this block should follow the new overrides indentation format
2300
defaults: {}
2301
# -- Path to the per tenant override config file. The values of the `per_tenant_overrides` config below will be written to the default path which is `/runtime-config/overrides.yaml`. Users can set tenant-specific overrides settings in a separate file and point per_tenant_override_config to it if not using the per_tenant_overrides block below.
2302
per_tenant_override_config: /runtime-config/overrides.yaml
2303
# -- The `per tenant` runtime overrides in place of the `per_tenant_override_config` file for Tempo (see `overrides` and the `per_tenant_override_config` property). This allows overriding the configs like `ingestion` and `global` values on a per-tenant basis. Note that *all* values must be given for each per-tenant configuration block. Refer to [Runtime overrides](https://grafana.com/docs/tempo/latest/configuration/#runtime-overrides) documentation for more details.
2304
per_tenant_overrides:
2305
# 'tenant-id':
2306
# metrics_generator:
2307
# processors:
2308
# - service-graphs
2309
# - span-metrics
2310
2311
# memcached is for all of the Tempo pieces to coordinate with each other.
2312
# you can use your own self deployed memcached by setting `memcached.enabled` to false and `memcached.host` + `memcached.service`
2313
memcached:
2314
# -- Specified whether the memcached cachce should be enabled
2315
enabled: true
2316
image:
2317
# -- The Docker registry for the Memcached image. Overrides `global.image.registry`
2318
registry: cgr.dev
2319
# -- Optional list of imagePullSecrets. Overrides `global.image.pullSecrets`
2320
pullSecrets: []
2321
# -- Memcached Docker image repository
2322
repository: chainguard-private/memcached
2323
# -- Memcached Docker image tag
2324
tag: 1.6.45-r5@sha256:1c8af17d7a5ad133b93af700b90fd7da4be7be6f8b13a83757de5050072a58b6
2325
# -- Memcached Docker image pull policy
2326
pullPolicy: IfNotPresent
2327
host: memcached
2328
# Number of replicas for memchached
2329
replicas: 1
2330
# -- Timeout for cache operations
2331
timeout: 500ms
2332
# -- Enable consistent hashing for cache
2333
consistentHash: true
2334
# -- Additional CLI args for memcached
2335
extraArgs: []
2336
# -- Toleration for memcached pods
2337
tolerations: []
2338
# -- Environment variables to add to memcached pods
2339
extraEnv: []
2340
# -- Environment variables from secrets or configmaps to add to memcached pods
2341
extraEnvFrom: []
2342
# -- Labels for memcached pods
2343
podLabels: {}
2344
# -- Annotations for memcached pods
2345
podAnnotations: {}
2346
# -- Resource requests and limits for memcached
2347
resources: {}
2348
# -- topologySpread for memcached pods. Passed through `tpl` and, thus, to be configured as string
2349
# @default -- Defaults to allow skew no more than 1 node per AZ
2350
topologySpreadConstraints: |
2351
- maxSkew: 1
2352
topologyKey: topology.kubernetes.io/zone
2353
whenUnsatisfiable: ScheduleAnyway
2354
labelSelector:
2355
matchLabels:
2356
{{- include "tempo.selectorLabels" (dict "ctx" . "component" "memcached") | nindent 6 }}
2357
# -- Affinity for memcached pods. Passed through `tpl` and, thus, to be configured as string
2358
# @default -- Hard node and soft zone anti-affinity
2359
affinity: |
2360
podAntiAffinity:
2361
requiredDuringSchedulingIgnoredDuringExecution:
2362
- labelSelector:
2363
matchLabels:
2364
{{- include "tempo.selectorLabels" (dict "ctx" . "component" "memcached") | nindent 10 }}
2365
topologyKey: kubernetes.io/hostname
2366
preferredDuringSchedulingIgnoredDuringExecution:
2367
- weight: 100
2368
podAffinityTerm:
2369
labelSelector:
2370
matchLabels:
2371
{{- include "tempo.selectorLabels" (dict "ctx" . "component" "memcached") | nindent 12 }}
2372
topologyKey: topology.kubernetes.io/zone
2373
# -- Pod Disruption Budget configuration
2374
podDisruptionBudget:
2375
# -- Enable PodDisruptionBudget for memcached
2376
enabled: true
2377
# -- Set unhealthyPodEvictionPolicy for the memcached PodDisruptionBudget. Requires policy/v1.
2378
unhealthyPodEvictionPolicy: ""
2379
# -- Pod Disruption Budget maxUnavailable
2380
maxUnavailable: 1
2381
# -- Init containers for the memcached pod
2382
initContainers: []
2383
# -- Containers to add to the memcached pods
2384
extraContainers: []
2385
# -- Extra volumes for memcached pods
2386
extraVolumeMounts: []
2387
# -- Extra volumes for memcached statefulSet
2388
extraVolumes: []
2389
service:
2390
# -- Annotations for memcached service
2391
annotations: {}
2392
# -- configuration for readiness probe for memcached statefulset
2393
readinessProbe:
2394
tcpSocket:
2395
port: client
2396
initialDelaySeconds: 5
2397
periodSeconds: 5
2398
timeoutSeconds: 3
2399
failureThreshold: 6
2400
successThreshold: 1
2401
# -- configuration for liveness probe for memcached statefulset
2402
livenessProbe:
2403
initialDelaySeconds: 30
2404
periodSeconds: 10
2405
timeoutSeconds: 5
2406
failureThreshold: 6
2407
successThreshold: 1
2408
memcachedExporter:
2409
# -- Specifies whether the Memcached Exporter should be enabled
2410
enabled: false
2411
# -- hostAliases to add
2412
hostAliases: []
2413
# - ip: 1.2.3.4
2414
# hostnames:
2415
# - domain.tld
2416
image:
2417
# -- The Docker registry for the Memcached Exporter image. Overrides `global.image.registry`
2418
registry: null
2419
# -- Optional list of imagePullSecrets. Overrides `global.image.pullSecrets`
2420
pullSecrets: []
2421
# -- Memcached Exporter Docker image repository
2422
repository: prom/memcached-exporter
2423
# -- Memcached Exporter Docker image tag
2424
tag: v0.17.0
2425
# -- Memcached Exporter Docker image pull policy
2426
pullPolicy: IfNotPresent
2427
# -- Memcached Exporter resource requests and limits
2428
resources: {}
2429
# -- Additional CLI args for the memcached exporter
2430
extraArgs: []
2431
# -- Configuration for a dedicated memcached cluster for the bloom cache role.
2432
# When enabled, bloom cache is served by its own memcached StatefulSet.
2433
# Image is shared with the main `memcached` section.
2434
memcachedBloom:
2435
# -- Enable a dedicated memcached cluster for the bloom cache role
2436
enabled: false
2437
# -- Annotations for the memcached-bloom StatefulSet
2438
annotations: {}
2439
# -- Number of replicas for the bloom memcached StatefulSet
2440
replicas: 1
2441
# -- Timeout for bloom cache operations
2442
timeout: 500ms
2443
# -- Enable consistent hashing for bloom cache
2444
consistentHash: true
2445
# -- Additional CLI args for memcached
2446
extraArgs: []
2447
# -- Tolerations for memcached-bloom pods
2448
tolerations: []
2449
# -- Environment variables to add to memcached-bloom pods
2450
extraEnv: []
2451
# -- Environment variables from secrets or configmaps to add to memcached-bloom pods
2452
extraEnvFrom: []
2453
# -- Labels for memcached-bloom pods
2454
podLabels: {}
2455
# -- Annotations for memcached-bloom pods
2456
podAnnotations: {}
2457
# -- Resource requests and limits for memcached-bloom
2458
resources: {}
2459
# -- topologySpread for memcached-bloom pods. Passed through `tpl` and, thus, to be configured as string
2460
# @default -- Defaults to allow skew no more than 1 node per AZ
2461
topologySpreadConstraints: |
2462
- maxSkew: 1
2463
topologyKey: topology.kubernetes.io/zone
2464
whenUnsatisfiable: ScheduleAnyway
2465
labelSelector:
2466
matchLabels:
2467
{{- include "tempo.selectorLabels" (dict "ctx" . "component" "memcached-bloom") | nindent 6 }}
2468
# -- Affinity for memcached-bloom pods. Passed through `tpl` and, thus, to be configured as string
2469
# @default -- Hard node and soft zone anti-affinity
2470
affinity: |
2471
podAntiAffinity:
2472
requiredDuringSchedulingIgnoredDuringExecution:
2473
- labelSelector:
2474
matchLabels:
2475
{{- include "tempo.selectorLabels" (dict "ctx" . "component" "memcached-bloom") | nindent 10 }}
2476
topologyKey: kubernetes.io/hostname
2477
preferredDuringSchedulingIgnoredDuringExecution:
2478
- weight: 100
2479
podAffinityTerm:
2480
labelSelector:
2481
matchLabels:
2482
{{- include "tempo.selectorLabels" (dict "ctx" . "component" "memcached-bloom") | nindent 12 }}
2483
topologyKey: topology.kubernetes.io/zone
2484
# -- Pod Disruption Budget configuration
2485
podDisruptionBudget:
2486
# -- Enable PodDisruptionBudget for memcached-bloom
2487
enabled: true
2488
# -- Pod Disruption Budget maxUnavailable
2489
maxUnavailable: 1
2490
# -- Init containers for the memcached-bloom pod
2491
initContainers: []
2492
# -- Containers to add to the memcached-bloom pods
2493
extraContainers: []
2494
# -- Extra volume mounts for memcached-bloom pods
2495
extraVolumeMounts: []
2496
# -- Extra volumes for memcached-bloom StatefulSet
2497
extraVolumes: []
2498
service:
2499
# -- Annotations for memcached-bloom service
2500
annotations: {}
2501
# -- configuration for readiness probe for memcached-bloom statefulset
2502
readinessProbe:
2503
tcpSocket:
2504
port: client
2505
initialDelaySeconds: 5
2506
periodSeconds: 5
2507
timeoutSeconds: 3
2508
failureThreshold: 6
2509
successThreshold: 1
2510
# -- configuration for liveness probe for memcached-bloom statefulset
2511
livenessProbe:
2512
initialDelaySeconds: 30
2513
periodSeconds: 10
2514
timeoutSeconds: 5
2515
failureThreshold: 6
2516
successThreshold: 1
2517
# -- Configuration for a dedicated memcached cluster for the parquet-footer cache role.
2518
# When enabled, parquet-footer cache is served by its own memcached StatefulSet.
2519
# Image is shared with the main `memcached` section.
2520
memcachedParquetFooter:
2521
# -- Enable a dedicated memcached cluster for the parquet-footer cache role
2522
enabled: false
2523
# -- Annotations for the memcached-parquet-footer StatefulSet
2524
annotations: {}
2525
# -- Number of replicas for the parquet-footer memcached StatefulSet
2526
replicas: 1
2527
# -- Timeout for parquet-footer cache operations
2528
timeout: 500ms
2529
# -- Enable consistent hashing for parquet-footer cache
2530
consistentHash: true
2531
# -- Additional CLI args for memcached
2532
extraArgs: []
2533
# -- Tolerations for memcached-parquet-footer pods
2534
tolerations: []
2535
# -- Environment variables to add to memcached-parquet-footer pods
2536
extraEnv: []
2537
# -- Environment variables from secrets or configmaps to add to memcached-parquet-footer pods
2538
extraEnvFrom: []
2539
# -- Labels for memcached-parquet-footer pods
2540
podLabels: {}
2541
# -- Annotations for memcached-parquet-footer pods
2542
podAnnotations: {}
2543
# -- Resource requests and limits for memcached-parquet-footer
2544
resources: {}
2545
# -- topologySpread for memcached-parquet-footer pods. Passed through `tpl` and, thus, to be configured as string
2546
# @default -- Defaults to allow skew no more than 1 node per AZ
2547
topologySpreadConstraints: |
2548
- maxSkew: 1
2549
topologyKey: topology.kubernetes.io/zone
2550
whenUnsatisfiable: ScheduleAnyway
2551
labelSelector:
2552
matchLabels:
2553
{{- include "tempo.selectorLabels" (dict "ctx" . "component" "memcached-parquet-footer") | nindent 6 }}
2554
# -- Affinity for memcached-parquet-footer pods. Passed through `tpl` and, thus, to be configured as string
2555
# @default -- Hard node and soft zone anti-affinity
2556
affinity: |
2557
podAntiAffinity:
2558
requiredDuringSchedulingIgnoredDuringExecution:
2559
- labelSelector:
2560
matchLabels:
2561
{{- include "tempo.selectorLabels" (dict "ctx" . "component" "memcached-parquet-footer") | nindent 10 }}
2562
topologyKey: kubernetes.io/hostname
2563
preferredDuringSchedulingIgnoredDuringExecution:
2564
- weight: 100
2565
podAffinityTerm:
2566
labelSelector:
2567
matchLabels:
2568
{{- include "tempo.selectorLabels" (dict "ctx" . "component" "memcached-parquet-footer") | nindent 12 }}
2569
topologyKey: topology.kubernetes.io/zone
2570
# -- Pod Disruption Budget configuration
2571
podDisruptionBudget:
2572
# -- Enable PodDisruptionBudget for memcached-parquet-footer
2573
enabled: true
2574
# -- Pod Disruption Budget maxUnavailable
2575
maxUnavailable: 1
2576
# -- Init containers for the memcached-parquet-footer pod
2577
initContainers: []
2578
# -- Containers to add to the memcached-parquet-footer pods
2579
extraContainers: []
2580
# -- Extra volume mounts for memcached-parquet-footer pods
2581
extraVolumeMounts: []
2582
# -- Extra volumes for memcached-parquet-footer StatefulSet
2583
extraVolumes: []
2584
service:
2585
# -- Annotations for memcached-parquet-footer service
2586
annotations: {}
2587
# -- configuration for readiness probe for memcached-parquet-footer statefulset
2588
readinessProbe:
2589
tcpSocket:
2590
port: client
2591
initialDelaySeconds: 5
2592
periodSeconds: 5
2593
timeoutSeconds: 3
2594
failureThreshold: 6
2595
successThreshold: 1
2596
# -- configuration for liveness probe for memcached-parquet-footer statefulset
2597
livenessProbe:
2598
initialDelaySeconds: 30
2599
periodSeconds: 10
2600
timeoutSeconds: 5
2601
failureThreshold: 6
2602
successThreshold: 1
2603
# -- Configuration for a dedicated memcached cluster for the frontend-search cache role.
2604
# When enabled, frontend-search cache is served by its own memcached StatefulSet.
2605
# Image is shared with the main `memcached` section.
2606
memcachedFrontendSearch:
2607
# -- Enable a dedicated memcached cluster for the frontend-search cache role
2608
enabled: false
2609
# -- Annotations for the memcached-frontend-search StatefulSet
2610
annotations: {}
2611
# -- Number of replicas for the frontend-search memcached StatefulSet
2612
replicas: 1
2613
# -- Timeout for frontend-search cache operations
2614
timeout: 500ms
2615
# -- Enable consistent hashing for frontend-search cache
2616
consistentHash: true
2617
# -- Additional CLI args for memcached
2618
extraArgs: []
2619
# -- Tolerations for memcached-frontend-search pods
2620
tolerations: []
2621
# -- Environment variables to add to memcached-frontend-search pods
2622
extraEnv: []
2623
# -- Environment variables from secrets or configmaps to add to memcached-frontend-search pods
2624
extraEnvFrom: []
2625
# -- Labels for memcached-frontend-search pods
2626
podLabels: {}
2627
# -- Annotations for memcached-frontend-search pods
2628
podAnnotations: {}
2629
# -- Resource requests and limits for memcached-frontend-search
2630
resources: {}
2631
# -- topologySpread for memcached-frontend-search pods. Passed through `tpl` and, thus, to be configured as string
2632
# @default -- Defaults to allow skew no more than 1 node per AZ
2633
topologySpreadConstraints: |
2634
- maxSkew: 1
2635
topologyKey: topology.kubernetes.io/zone
2636
whenUnsatisfiable: ScheduleAnyway
2637
labelSelector:
2638
matchLabels:
2639
{{- include "tempo.selectorLabels" (dict "ctx" . "component" "memcached-frontend-search") | nindent 6 }}
2640
# -- Affinity for memcached-frontend-search pods. Passed through `tpl` and, thus, to be configured as string
2641
# @default -- Hard node and soft zone anti-affinity
2642
affinity: |
2643
podAntiAffinity:
2644
requiredDuringSchedulingIgnoredDuringExecution:
2645
- labelSelector:
2646
matchLabels:
2647
{{- include "tempo.selectorLabels" (dict "ctx" . "component" "memcached-frontend-search") | nindent 10 }}
2648
topologyKey: kubernetes.io/hostname
2649
preferredDuringSchedulingIgnoredDuringExecution:
2650
- weight: 100
2651
podAffinityTerm:
2652
labelSelector:
2653
matchLabels:
2654
{{- include "tempo.selectorLabels" (dict "ctx" . "component" "memcached-frontend-search") | nindent 12 }}
2655
topologyKey: topology.kubernetes.io/zone
2656
# -- Pod Disruption Budget configuration
2657
podDisruptionBudget:
2658
# -- Enable PodDisruptionBudget for memcached-frontend-search
2659
enabled: true
2660
# -- Pod Disruption Budget maxUnavailable
2661
maxUnavailable: 1
2662
# -- Init containers for the memcached-frontend-search pod
2663
initContainers: []
2664
# -- Containers to add to the memcached-frontend-search pods
2665
extraContainers: []
2666
# -- Extra volume mounts for memcached-frontend-search pods
2667
extraVolumeMounts: []
2668
# -- Extra volumes for memcached-frontend-search StatefulSet
2669
extraVolumes: []
2670
service:
2671
# -- Annotations for memcached-frontend-search service
2672
annotations: {}
2673
# -- configuration for readiness probe for memcached-frontend-search statefulset
2674
readinessProbe:
2675
tcpSocket:
2676
port: client
2677
initialDelaySeconds: 5
2678
periodSeconds: 5
2679
timeoutSeconds: 3
2680
failureThreshold: 6
2681
successThreshold: 1
2682
# -- configuration for liveness probe for memcached-frontend-search statefulset
2683
livenessProbe:
2684
initialDelaySeconds: 30
2685
periodSeconds: 10
2686
timeoutSeconds: 5
2687
failureThreshold: 6
2688
successThreshold: 1
2689
metaMonitoring:
2690
# ServiceMonitor configuration
2691
serviceMonitor:
2692
# -- If enabled, ServiceMonitor resources for Prometheus Operator are created
2693
enabled: false
2694
# -- Alternative namespace for ServiceMonitor resources
2695
namespace: null
2696
# -- Namespace selector for ServiceMonitor resources
2697
namespaceSelector: {}
2698
# -- ServiceMonitor annotations
2699
annotations: {}
2700
# -- Additional ServiceMonitor labels
2701
labels: {}
2702
# -- ServiceMonitor scrape interval
2703
interval: null
2704
# -- ServiceMonitor scrape timeout in Go duration format (e.g. 15s)
2705
scrapeTimeout: null
2706
# -- ServiceMonitor relabel configs to apply to samples before scraping
2707
# https://github.com/prometheus-operator/prometheus-operator/blob/master/Documentation/api.md#relabelconfig
2708
relabelings: []
2709
# -- ServiceMonitor metric relabel configs to apply to samples before ingestion
2710
# https://github.com/prometheus-operator/prometheus-operator/blob/main/Documentation/api.md#endpoint
2711
metricRelabelings: []
2712
# -- ServiceMonitor will use http by default, but you can pick https as well
2713
scheme: http
2714
# -- ServiceMonitor will use these tlsConfig settings to make the health check requests
2715
tlsConfig: null
2716
# metaMonitoringAgent configures the built in Grafana Agent that can scrape metrics and logs and send them to a local or remote destination
2717
grafanaAgent:
2718
# -- Controls whether to create PodLogs, MetricsInstance, LogsInstance, and GrafanaAgent CRs to scrape the
2719
# ServiceMonitors of the chart and ship metrics and logs to the remote endpoints below.
2720
# Note that you need to configure serviceMonitor in order to have some metrics available.
2721
enabled: false
2722
# -- Controls whether to install the Grafana Agent Operator and its CRDs.
2723
# Note that helm will not install CRDs if this flag is enabled during an upgrade.
2724
# In that case install the CRDs manually from https://github.com/grafana/agent/tree/main/production/operator/crds
2725
installOperator: false
2726
logs:
2727
# -- Default destination for logs. The config here is translated to Promtail client
2728
# configuration to write logs to this Loki-compatible remote. Optional.
2729
remote:
2730
# -- Full URL for Loki push endpoint. Usually ends in /loki/api/v1/push
2731
url: ''
2732
auth:
2733
# -- Used to set X-Scope-OrgID header on requests. Usually not used in combination with username and password.
2734
tenantId: ''
2735
# -- Basic authentication username. Optional.
2736
username: ''
2737
# -- The value under key passwordSecretKey in this secret will be used as the basic authentication password. Required only if passwordSecretKey is set.
2738
passwordSecretName: ''
2739
# -- The value under this key in passwordSecretName will be used as the basic authentication password. Required only if passwordSecretName is set.
2740
passwordSecretKey: ''
2741
# -- Client configurations for the LogsInstance that will scrape Mimir pods. Follows the format of .remote.
2742
additionalClientConfigs: []
2743
metrics:
2744
# -- Default destination for metrics. The config here is translated to remote_write
2745
# configuration to push metrics to this Prometheus-compatible remote. Optional.
2746
# Note that you need to configure serviceMonitor in order to have some metrics available.
2747
remote:
2748
# -- Full URL for Prometheus remote-write. Usually ends in /push
2749
url: ''
2750
# -- Used to add HTTP headers to remote-write requests.
2751
headers: {}
2752
auth:
2753
# -- Basic authentication username. Optional.
2754
username: ''
2755
# -- The value under key passwordSecretKey in this secret will be used as the basic authentication password. Required only if passwordSecretKey is set.
2756
passwordSecretName: ''
2757
# -- The value under this key in passwordSecretName will be used as the basic authentication password. Required only if passwordSecretName is set.
2758
passwordSecretKey: ''
2759
# -- Additional remote-write for the MetricsInstance that will scrape Mimir pods. Follows the format of .remote.
2760
additionalRemoteWriteConfigs: []
2761
scrapeK8s:
2762
# -- When grafanaAgent.enabled and serviceMonitor.enabled, controls whether to create ServiceMonitors CRs
2763
# for cadvisor, kubelet, and kube-state-metrics. The scraped metrics are reduced to those pertaining to
2764
# Mimir pods only.
2765
enabled: true
2766
# -- Controls service discovery of kube-state-metrics.
2767
kubeStateMetrics:
2768
namespace: kube-system
2769
labelSelectors:
2770
app.kubernetes.io/name: kube-state-metrics
2771
# -- Sets the namespace of the resources. Leave empty or unset to use the same namespace as the Helm release.
2772
namespace: ''
2773
# -- Labels to add to all monitoring.grafana.com custom resources.
2774
# Does not affect the ServiceMonitors for kubernetes metrics; use serviceMonitor.labels for that.
2775
labels: {}
2776
# -- Annotations to add to all monitoring.grafana.com custom resources.
2777
# Does not affect the ServiceMonitors for kubernetes metrics; use serviceMonitor.annotations for that.
2778
annotations: {}
2779
# Rules for the Prometheus Operator
2780
prometheusRule:
2781
# -- If enabled, a PrometheusRule resource for Prometheus Operator is created
2782
enabled: false
2783
# -- Alternative namespace for the PrometheusRule resource
2784
namespace: null
2785
# -- PrometheusRule annotations
2786
annotations: {}
2787
# -- Additional PrometheusRule labels
2788
labels: {}
2789
# -- Contents of Prometheus rules file
2790
groups: []
2791
# - name: loki-rules
2792
# rules:
2793
# - record: job:loki_request_duration_seconds_bucket:sum_rate
2794
# expr: sum(rate(loki_request_duration_seconds_bucket[1m])) by (le, job)
2795
# - record: job_route:loki_request_duration_seconds_bucket:sum_rate
2796
# expr: sum(rate(loki_request_duration_seconds_bucket[1m])) by (le, job, route)
2797
# - record: node_namespace_pod_container:container_cpu_usage_seconds_total:sum_rate
2798
# expr: sum(rate(container_cpu_usage_seconds_total[1m])) by (node, namespace, pod, container)
2799
# Configuration for the gateway
2800
gateway:
2801
# -- Specifies whether the gateway should be enabled
2802
enabled: false
2803
# -- Number of replicas for the gateway
2804
replicas: 1
2805
# -- hostAliases to add
2806
hostAliases: []
2807
# - ip: 1.2.3.4
2808
# hostnames:
2809
# - domain.tld
2810
autoscaling:
2811
# -- Enable autoscaling for the gateway
2812
enabled: false
2813
# -- Minimum autoscaling replicas for the gateway
2814
minReplicas: 1
2815
# -- Maximum autoscaling replicas for the gateway
2816
maxReplicas: 3
2817
# -- Autoscaling behavior configuration for the gateway
2818
behavior: {}
2819
# -- Target CPU utilisation percentage for the gateway
2820
targetCPUUtilizationPercentage: 60
2821
# -- Target memory utilisation percentage for the gateway
2822
targetMemoryUtilizationPercentage:
2823
# -- Enable logging of 2xx and 3xx HTTP requests
2824
verboseLogging: true
2825
image:
2826
# -- The Docker registry for the gateway image. Overrides `global.image.registry`
2827
registry: null
2828
# -- Optional list of imagePullSecrets. Overrides `global.image.pullSecrets`
2829
pullSecrets: []
2830
# -- The gateway image repository
2831
repository: nginxinc/nginx-unprivileged
2832
# -- The gateway image tag
2833
tag: 1.31-alpine
2834
# -- The gateway image pull policy
2835
pullPolicy: IfNotPresent
2836
# -- The name of the PriorityClass for gateway pods
2837
priorityClassName: null
2838
# -- Labels for gateway pods
2839
podLabels: {}
2840
# -- Annotations for gateway deployment
2841
annotations: {}
2842
# -- Annotations for gateway pods
2843
podAnnotations: {}
2844
# -- Additional CLI args for the gateway
2845
extraArgs: []
2846
# -- Environment variables to add to the gateway pods
2847
extraEnv: []
2848
# -- Environment variables from secrets or configmaps to add to the gateway pods
2849
extraEnvFrom: []
2850
# -- Volumes to add to the gateway pods
2851
extraVolumes: []
2852
# -- Volume mounts to add to the gateway pods
2853
extraVolumeMounts: []
2854
# -- Containers to add to the gateway pods
2855
extraContainers: []
2856
# -- Resource requests and limits for the gateway
2857
resources: {}
2858
# -- Grace period to allow the gateway to shutdown before it is killed
2859
terminationGracePeriodSeconds: 30
2860
# -- topologySpread for gateway pods. Passed through `tpl` and, thus, to be configured as string
2861
# @default -- Defaults to allow skew no more than 1 node per AZ
2862
topologySpreadConstraints: |
2863
- maxSkew: 1
2864
topologyKey: topology.kubernetes.io/zone
2865
whenUnsatisfiable: ScheduleAnyway
2866
labelSelector:
2867
matchLabels:
2868
{{- include "tempo.selectorLabels" (dict "ctx" . "component" "gateway") | nindent 6 }}
2869
# -- Affinity for gateway pods. Passed through `tpl` and, thus, to be configured as string
2870
# @default -- Hard node and soft zone anti-affinity
2871
affinity: |
2872
podAntiAffinity:
2873
requiredDuringSchedulingIgnoredDuringExecution:
2874
- labelSelector:
2875
matchLabels:
2876
{{- include "tempo.selectorLabels" (dict "ctx" . "component" "gateway") | nindent 10 }}
2877
topologyKey: kubernetes.io/hostname
2878
preferredDuringSchedulingIgnoredDuringExecution:
2879
- weight: 100
2880
podAffinityTerm:
2881
labelSelector:
2882
matchLabels:
2883
{{- include "tempo.selectorLabels" (dict "ctx" . "component" "gateway") | nindent 12 }}
2884
topologyKey: topology.kubernetes.io/zone
2885
# -- Pod Disruption Budget configuration
2886
podDisruptionBudget:
2887
# -- Enable PodDisruptionBudget for gateway
2888
enabled: true
2889
# -- Set unhealthyPodEvictionPolicy for the gateway PodDisruptionBudget. Requires policy/v1.
2890
unhealthyPodEvictionPolicy: ""
2891
# -- Pod Disruption Budget maxUnavailable
2892
maxUnavailable: 1
2893
# -- Minimum number of seconds for which a newly created Pod should be ready without any of its containers crashing/terminating
2894
minReadySeconds: 10
2895
# -- Node selector for gateway pods
2896
nodeSelector: {}
2897
# -- Tolerations for gateway pods
2898
tolerations: []
2899
# Gateway service configuration
2900
service:
2901
# -- Port of the gateway service
2902
port: 80
2903
# -- Type of the gateway service
2904
type: ClusterIP
2905
# -- Traffic distribution for the gateway service (PreferSameZone or PreferSameNode). Overrides tempo.service.trafficDistribution.
2906
trafficDistribution: null
2907
# -- ClusterIP of the gateway service
2908
clusterIP: null
2909
# -- Node port if service type is NodePort
2910
nodePort: null
2911
# -- Node port for the gRPC port if service type is NodePort
2912
grpcNodePort: null
2913
# -- Load balancer IP address if service type is LoadBalancer
2914
loadBalancerIP: null
2915
# -- Annotations for the gateway service
2916
annotations: {}
2917
# -- Labels for gateway service
2918
labels: {}
2919
# -- Additional ports to be opened on gateway service (e.g. for RPC connections)
2920
additionalPorts: []
2921
# Gateway ingress configuration
2922
ingress:
2923
# -- Specifies whether an ingress for the gateway should be created
2924
enabled: false
2925
# -- Labels for the gateway ingress
2926
labels: {}
2927
# -- Ingress Class Name. MAY be required for Kubernetes versions >= 1.18
2928
# ingressClassName: nginx
2929
# -- Annotations for the gateway ingress
2930
annotations: {}
2931
# -- Hosts configuration for the gateway ingress
2932
hosts:
2933
- host: gateway.tempo.example.com
2934
paths:
2935
- path: /
2936
# -- pathType (e.g. ImplementationSpecific, Prefix, .. etc.) might also be required by some Ingress Controllers
2937
# pathType: Prefix
2938
# -- TLS configuration for the gateway ingress
2939
tls:
2940
- secretName: tempo-gateway-tls
2941
hosts:
2942
- gateway.tempo.example.com
2943
# -- Gateway API route configuration for the gateway.
2944
# Multiple routes can be added by adding a dictionary key like the 'main' route.
2945
route:
2946
main:
2947
# -- Specifies whether a Gateway API route for the gateway should be created
2948
enabled: false
2949
# -- Set the route apiVersion, e.g. gateway.networking.k8s.io/v1 or gateway.networking.k8s.io/v1beta1
2950
# If not set, the latest available version will be auto-detected
2951
apiVersion: ""
2952
# -- Set the route kind
2953
# Valid options are GRPCRoute, HTTPRoute, TCPRoute, TLSRoute, UDPRoute
2954
kind: HTTPRoute
2955
# -- Route annotations
2956
annotations: {}
2957
# -- Route labels
2958
labels: {}
2959
# -- Hostnames for the route
2960
hostnames: []
2961
# - gateway.tempo.example.com
2962
# -- Parent references (gateway to attach to)
2963
parentRefs: []
2964
# - name: my-gateway
2965
# namespace: gateway-namespace
2966
# -- Matches define conditions for matching incoming requests
2967
matches:
2968
- path:
2969
type: PathPrefix
2970
value: /
2971
# -- Timeouts define the timeouts that can be configured for an HTTP request.
2972
# Ref. https://gateway-api.sigs.k8s.io/api-types/httproute/#timeouts-optional
2973
timeouts: {}
2974
# -- Filters define the filters that are applied to requests that match this rule.
2975
filters: []
2976
# -- Additional custom rules that can be added to the route
2977
additionalRules: []
2978
# Basic auth configuration
2979
basicAuth:
2980
# -- Enables basic authentication for the gateway
2981
enabled: false
2982
# -- The basic auth username for the gateway
2983
username: null
2984
# -- The basic auth password for the gateway
2985
password: null
2986
# -- Uses the specified username and password to compute a htpasswd using Sprig's `htpasswd` function.
2987
# The value is templated using `tpl`. Override this to use a custom htpasswd, e.g. in case the default causes
2988
# high CPU load.
2989
htpasswd: >-
2990
{{ htpasswd (required "'gateway.basicAuth.username' is required" .Values.gateway.basicAuth.username) (required "'gateway.basicAuth.password' is required" .Values.gateway.basicAuth.password) }}
2991
# -- Existing basic auth secret to use. Must contain '.htpasswd'
2992
existingSecret: null
2993
# Configures the liveness probe for the gateway
2994
livenessProbe:
2995
httpGet:
2996
path: /
2997
port: http-metrics
2998
initialDelaySeconds: 30
2999
timeoutSeconds: 5
3000
# Configures the readiness probe for the gateway
3001
readinessProbe:
3002
httpGet:
3003
path: /
3004
port: http-metrics
3005
initialDelaySeconds: 15
3006
timeoutSeconds: 1
3007
nginxConfig:
3008
# -- NGINX log format
3009
logFormat: |-
3010
main '$remote_addr - $remote_user [$time_local] $status '
3011
'"$request" $body_bytes_sent "$http_referer" '
3012
'"$http_user_agent" "$http_x_forwarded_for"';
3013
# -- Allows appending custom configuration to the main context
3014
mainSnippet: ''
3015
# -- Allows appending custom configuration to the server block
3016
serverSnippet: ''
3017
# -- Allows appending custom configuration to the http block
3018
httpSnippet: ''
3019
# -- Whether ssl should be appended to the listen directive of the server block or not.
3020
ssl: false
3021
# -- TLS secret name containing the certificate and key to be used if ssl is enabled. The secret must contain 'tls.crt' and 'tls.key'. Required if ssl is true.
3022
tlsSecretName: ''
3023
# -- Allows overriding the DNS resolver address nginx will use
3024
resolver: ''
3025
# -- Configures whether or not NGINX bind IPv6
3026
enableIPv6: false
3027
# -- Config file contents for Nginx. Passed through the `tpl` function to allow templating
3028
# @default -- See values.yaml
3029
file: |
3030
worker_processes 5; ## Default: 1
3031
error_log /dev/stderr;
3032
pid /tmp/nginx.pid;
3033
worker_rlimit_nofile 8192;
3034
3035
{{- with .Values.gateway.nginxConfig.mainSnippet }}
3036
{{ . | nindent 0 }}
3037
{{- end }}
3038
3039
events {
3040
worker_connections 4096; ## Default: 1024
3041
}
3042
3043
http {
3044
client_body_temp_path /tmp/client_temp;
3045
proxy_temp_path /tmp/proxy_temp_path;
3046
fastcgi_temp_path /tmp/fastcgi_temp;
3047
uwsgi_temp_path /tmp/uwsgi_temp;
3048
scgi_temp_path /tmp/scgi_temp;
3049
3050
proxy_http_version 1.1;
3051
3052
default_type application/octet-stream;
3053
log_format {{ .Values.gateway.nginxConfig.logFormat }}
3054
3055
{{- if .Values.gateway.verboseLogging }}
3056
access_log /dev/stderr main;
3057
{{- else }}
3058
3059
map $status $loggable {
3060
~^[23] 0;
3061
default 1;
3062
}
3063
access_log /dev/stderr main if=$loggable;
3064
{{- end }}
3065
3066
sendfile on;
3067
tcp_nopush on;
3068
{{- if .Values.gateway.nginxConfig.resolver }}
3069
resolver {{ .Values.gateway.nginxConfig.resolver }};
3070
{{- else }}
3071
resolver {{ .Values.global.dnsService }}.{{ .Values.global.dnsNamespace }}.svc.{{ .Values.global.clusterDomain }};
3072
{{- end }}
3073
3074
{{- with .Values.gateway.nginxConfig.httpSnippet }}
3075
{{ . | nindent 2 }}
3076
{{- end }}
3077
3078
server {
3079
listen 8080 {{- if .Values.gateway.nginxConfig.ssl }} ssl{{- end }};
3080
{{- if .Values.gateway.nginxConfig.enableIPv6 }}
3081
listen [::]:8080 {{- if .Values.gateway.nginxConfig.ssl }} ssl{{- end }};
3082
{{- end }}
3083
3084
{{- if .Values.streamOverHTTPEnabled }}
3085
http2 on;
3086
location /tempopb.StreamingQuerier/ {
3087
set $query_frontend {{ include "tempo.resourceName" (dict "ctx" . "component" "query-frontend") }}.{{ .Release.Namespace }}.svc.{{ .Values.global.clusterDomain }};
3088
grpc_pass grpc://$query_frontend:3200;
3089
}
3090
{{- end }}
3091
3092
{{- if .Values.gateway.basicAuth.enabled }}
3093
auth_basic "Tempo";
3094
auth_basic_user_file /etc/nginx/secrets/.htpasswd;
3095
{{- end }}
3096
3097
location = / {
3098
return 200 'OK';
3099
auth_basic off;
3100
}
3101
3102
location = /jaeger/api/traces {
3103
set $distributor {{ include "tempo.resourceName" (dict "ctx" . "component" "distributor") }}.{{ .Release.Namespace }}.svc.{{ .Values.global.clusterDomain }};
3104
proxy_pass http://$distributor:14268/api/traces;
3105
}
3106
3107
location = /zipkin/spans {
3108
set $distributor {{ include "tempo.resourceName" (dict "ctx" . "component" "distributor") }}.{{ .Release.Namespace }}.svc.{{ .Values.global.clusterDomain }};
3109
proxy_pass http://$distributor:9411/spans;
3110
}
3111
3112
location = /v1/traces {
3113
set $distributor {{ include "tempo.resourceName" (dict "ctx" . "component" "distributor") }}.{{ .Release.Namespace }}.svc.{{ .Values.global.clusterDomain }};
3114
proxy_pass http://$distributor:4318/v1/traces;
3115
}
3116
3117
location = /otlp/v1/traces {
3118
set $distributor {{ include "tempo.resourceName" (dict "ctx" . "component" "distributor") }}.{{ .Release.Namespace }}.svc.{{ .Values.global.clusterDomain }};
3119
proxy_pass http://$distributor:4318/v1/traces;
3120
}
3121
3122
location ^~ /api {
3123
set $query_frontend {{ include "tempo.resourceName" (dict "ctx" . "component" "query-frontend") }}.{{ .Release.Namespace }}.svc.{{ .Values.global.clusterDomain }};
3124
proxy_pass http://$query_frontend:3200$request_uri;
3125
}
3126
3127
location = /flush {
3128
set $ingester {{ include "tempo.resourceName" (dict "ctx" . "component" "ingester") }}.{{ .Release.Namespace }}.svc.{{ .Values.global.clusterDomain }};
3129
proxy_pass http://$ingester:3200$request_uri;
3130
}
3131
3132
location = /shutdown {
3133
set $ingester {{ include "tempo.resourceName" (dict "ctx" . "component" "ingester") }}.{{ .Release.Namespace }}.svc.{{ .Values.global.clusterDomain }};
3134
proxy_pass http://$ingester:3200$request_uri;
3135
}
3136
3137
location = /distributor/ring {
3138
set $distributor {{ include "tempo.resourceName" (dict "ctx" . "component" "distributor") }}.{{ .Release.Namespace }}.svc.{{ .Values.global.clusterDomain }};
3139
proxy_pass http://$distributor:3200$request_uri;
3140
}
3141
3142
location = /ingester/ring {
3143
set $distributor {{ include "tempo.resourceName" (dict "ctx" . "component" "distributor") }}.{{ .Release.Namespace }}.svc.{{ .Values.global.clusterDomain }};
3144
proxy_pass http://$distributor:3200$request_uri;
3145
}
3146
3147
location = /compactor/ring {
3148
set $compactor {{ include "tempo.resourceName" (dict "ctx" . "component" "compactor") }}.{{ .Release.Namespace }}.svc.{{ .Values.global.clusterDomain }};
3149
proxy_pass http://$compactor:3200$request_uri;
3150
}
3151
3152
{{- if .Values.backendScheduler.enabled }}
3153
location = /backend-worker/ring {
3154
set $backend_worker {{ include "tempo.resourceName" (dict "ctx" . "component" "backend-worker") }}.{{ .Release.Namespace }}.svc.{{ .Values.global.clusterDomain }};
3155
proxy_pass http://$backend_worker:3200$request_uri;
3156
}
3157
{{- end }}
3158
3159
{{- if .Values.gateway.nginxConfig.ssl }}
3160
ssl_certificate /etc/nginx/ssl/tls.crt;
3161
ssl_certificate_key /etc/nginx/ssl/tls.key;
3162
{{- end }}
3163
3164
{{- with .Values.gateway.nginxConfig.serverSnippet }}
3165
{{ . | nindent 4 }}
3166
{{- end }}
3167
}
3168
3169
{{- if .Values.traces.otlp.grpc.enabled }}
3170
# OTLP gRPC
3171
server {
3172
listen {{ .Values.traces.otlp.grpc.port }} http2 {{- if .Values.gateway.nginxConfig.ssl }} ssl{{- end }};
3173
{{- if .Values.gateway.nginxConfig.enableIPv6 }}
3174
listen [::]:{{ .Values.traces.otlp.grpc.port }} http2 {{- if .Values.gateway.nginxConfig.ssl }} ssl{{- end }};
3175
{{- end }}
3176
3177
{{- if .Values.gateway.basicAuth.enabled }}
3178
auth_basic "Tempo";
3179
auth_basic_user_file /etc/nginx/secrets/.htpasswd;
3180
{{- end }}
3181
3182
location = /opentelemetry.proto.collector.trace.v1.TraceService/Export {
3183
set $distributor {{ include "tempo.resourceName" (dict "ctx" . "component" "distributor") }}.{{ .Release.Namespace }}.svc.{{ .Values.global.clusterDomain }};
3184
grpc_pass grpc://$distributor:{{ .Values.traces.otlp.grpc.port }};
3185
}
3186
3187
location ~ /opentelemetry {
3188
set $distributor {{ include "tempo.resourceName" (dict "ctx" . "component" "distributor") }}.{{ .Release.Namespace }}.svc.{{ .Values.global.clusterDomain }};
3189
grpc_pass grpc://$distributor:{{ .Values.traces.otlp.grpc.port }};
3190
}
3191
3192
{{- if .Values.gateway.nginxConfig.ssl }}
3193
ssl_certificate /etc/nginx/ssl/tls.crt;
3194
ssl_certificate_key /etc/nginx/ssl/tls.key;
3195
{{- end }}
3196
3197
{{- with .Values.gateway.nginxConfig.serverSnippet }}
3198
{{ . | nindent 4 }}
3199
{{- end }}
3200
}
3201
{{- end }}
3202
}
3203
ingress:
3204
# -- If you enable this, make sure to disable the gateway's ingress.
3205
enabled: false
3206
# ingressClassName: nginx
3207
annotations: {}
3208
paths:
3209
distributor:
3210
- path: /v1/traces
3211
port: 4318
3212
- path: /distributor/ring
3213
# -- pathType (e.g. ImplementationSpecific, Prefix, .. etc.) might also be required by some Ingress Controllers
3214
# pathType: Prefix
3215
- path: /live-store/ring
3216
- path: /partition-ring
3217
- path: /metrics-generator/ring
3218
- path: /memberlist
3219
query-frontend:
3220
- path: /api
3221
backend-scheduler:
3222
- path: /status/backendscheduler
3223
hosts:
3224
- tempo.example.com
3225
# -- Gateway API route configuration.
3226
# Multiple routes can be added by adding a dictionary key like the 'main' route.
3227
# This is useful for creating both HTTPRoute and GRPCRoute resources (e.g. for OTLP HTTP + gRPC).
3228
route:
3229
main:
3230
# -- Specifies whether a Gateway API route should be created
3231
enabled: false
3232
# -- Set the route apiVersion, e.g. gateway.networking.k8s.io/v1 or gateway.networking.k8s.io/v1beta1
3233
# If not set, the latest available version will be auto-detected
3234
apiVersion: ""
3235
# -- Set the route kind
3236
# Valid options are GRPCRoute, HTTPRoute, TCPRoute, TLSRoute, UDPRoute
3237
kind: HTTPRoute
3238
# -- Route annotations
3239
annotations: {}
3240
# -- Route labels
3241
labels: {}
3242
# -- Hostnames for the route
3243
hostnames: []
3244
# - tempo.example.com
3245
# -- Parent references (gateway to attach to)
3246
parentRefs: []
3247
# - name: my-gateway
3248
# namespace: gateway-namespace
3249
# -- Paths to route to backend services. Each key is a service name suffix, and the value is a list of path matches.
3250
paths:
3251
distributor:
3252
- path: /v1/traces
3253
# -- pathType for the match (e.g. PathPrefix, Exact)
3254
pathType: PathPrefix
3255
# -- OTLP HTTP receiver port. This path is only rendered when traces.otlp.http.enabled is true.
3256
port: 4318
3257
- path: /distributor/ring
3258
pathType: PathPrefix
3259
- path: /live-store/ring
3260
pathType: PathPrefix
3261
- path: /partition-ring
3262
pathType: PathPrefix
3263
- path: /metrics-generator/ring
3264
pathType: PathPrefix
3265
- path: /memberlist
3266
pathType: PathPrefix
3267
query-frontend:
3268
- path: /api
3269
pathType: PathPrefix
3270
backend-scheduler:
3271
- path: /status/backendscheduler
3272
pathType: PathPrefix
3273
##############################################################################
3274
# The values in and after the `enterprise:` key configure the enterprise features
3275
enterprise:
3276
# Enable enterprise features. License must be provided, nginx gateway is not installed, instead
3277
# the enterprise gateway is used.
3278
enabled: false
3279
image:
3280
# -- Grafana Enterprise Traces container image repository. Note: for Grafana Tempo use the value 'image.repository'
3281
repository: grafana/enterprise-traces
3282
# -- Grafana Enterprise Traces container image tag. Note: for Grafana Tempo use the value 'image.tag'
3283
tag: v2.8.11
3284
# Note: pullPolicy and optional pullSecrets are set in toplevel 'image' section, not here
3285
# In order to use Grafana Enterprise Traces features, you will need to provide the contents of your Grafana Enterprise Traces
3286
# license, either by providing the contents of the license.jwt, or the name Kubernetes Secret that contains your license.jwt.
3287
# To set the license contents, use the flag `--set-file 'license.contents=./license.jwt'`
3288
# To use your own Kubernetes Secret, `--set license.external=true`.
3289
license:
3290
contents: 'NOTAVALIDLICENSE'
3291
external: false
3292
secretName: '{{ include "tempo.resourceName" (dict "ctx" . "component" "license") }}'
3293
# Settings for the initial admin(istrator) token generator job. Can only be enabled if
3294
# enterprise.enabled is true - requires license.
3295
tokengenJob:
3296
enable: true
3297
# -- hostAliases to add
3298
hostAliases: []
3299
# - ip: 1.2.3.4
3300
# hostnames:
3301
# - domain.tld
3302
extraArgs: {}
3303
env: []
3304
extraEnvFrom: []
3305
annotations: {}
3306
storeTokenInSecret: false
3307
# -- Name of the secret to store the admin token. If not specified, defaults to "<release-name>-admin-token"
3308
adminTokenSecret: "admin-token"
3309
image:
3310
# -- The Docker registry for the tokengenJob image. Overrides `tempo.image.registry`
3311
registry: null
3312
# -- Optional list of imagePullSecrets. Overrides `tempo.image.pullSecrets`
3313
pullSecrets: []
3314
# -- Docker image repository for the tokengenJob image. Overrides `tempo.image.repository`
3315
repository: null
3316
# -- Docker image tag for the tokengenJob image. Overrides `tempo.image.tag`
3317
tag: null
3318
initContainers: []
3319
# -- The SecurityContext for tokenjobgen containers
3320
containerSecurityContext:
3321
readOnlyRootFilesystem: true
3322
provisioner:
3323
# -- Whether the job should be part of the deployment
3324
enabled: false
3325
# -- Name of the secret to store provisioned tokens in
3326
provisionedSecretPrefix: null
3327
# -- Hook type(s) to customize when the job runs. defaults to post-install
3328
hookType: "post-install"
3329
# -- URL for the admin API service. Must be set to a valid URL.
3330
# Example: "http://tempo-admin-api.namespace.svc:3100"
3331
apiUrl: ""
3332
# -- Additional tenants to be created. Each tenant will get a read and write policy
3333
# and associated token. Tenant must have a name and a namespace for the secret containing
3334
# the token to be created in. For example
3335
# additionalTenants:
3336
# - name: tempo
3337
# secretNamespace: grafana
3338
additionalTenants: []
3339
# -- Additional arguments for the provisioner command
3340
extraArgs: {}
3341
# -- Additional Kubernetes environment
3342
env: []
3343
# -- Additional labels for the `provisioner` Job
3344
labels: {}
3345
# -- Additional annotations for the `provisioner` Job
3346
annotations: {}
3347
# -- Affinity for tokengen Pods
3348
affinity: {}
3349
# -- Node selector for tokengen Pods
3350
nodeSelector: {}
3351
# -- Tolerations for tokengen Pods
3352
tolerations: []
3353
# -- The name of the PriorityClass for provisioner Job
3354
priorityClassName: null
3355
# -- Run containers as nonroot user (uid=10001)`
3356
securityContext:
3357
runAsNonRoot: true
3358
runAsGroup: 10001
3359
runAsUser: 10001
3360
# -- Provisioner image to Utilize
3361
image:
3362
# -- The Docker registry
3363
registry: us-docker.pkg.dev
3364
# -- Docker image repository
3365
repository: grafanalabs-global/docker-enterprise-provisioner-prod/enterprise-provisioner
3366
# -- Overrides the image tag whose default is the chart's appVersion
3367
tag: null
3368
# -- Overrides the image tag with an image digest
3369
digest: null
3370
# -- Docker image pull policy
3371
pullPolicy: IfNotPresent
3372
# -- Volume mounts to add to the provisioner pods
3373
extraVolumeMounts: []
3374
# -- Volumes to add to the provisioner pods
3375
extraVolumes: []
3376
kubectlImage:
3377
repository: alpine/kubectl
3378
tag: latest
3379
pullPolicy: IfNotPresent
3380
# Settings for the admin_api service providing authentication and authorization service.
3381
# Can only be enabled if enterprise.enabled is true - requires license.
3382
adminApi:
3383
replicas: 1
3384
# -- hostAliases to add
3385
hostAliases: []
3386
# - ip: 1.2.3.4
3387
# hostnames:
3388
# - domain.tld
3389
3390
annotations: {}
3391
service:
3392
annotations: {}
3393
labels: {}
3394
image:
3395
# -- The Docker registry for the adminApi image. Overrides `tempo.image.registry`
3396
registry: null
3397
# -- Optional list of imagePullSecrets. Overrides `tempo.image.pullSecrets`
3398
pullSecrets: []
3399
# -- Docker image repository for the adminApi image. Overrides `tempo.image.repository`
3400
repository: null
3401
# -- Docker image tag for the adminApi image. Overrides `tempo.image.tag`
3402
tag: null
3403
initContainers: []
3404
strategy:
3405
type: RollingUpdate
3406
rollingUpdate:
3407
maxSurge: 0
3408
maxUnavailable: 1
3409
podLabels: {}
3410
podAnnotations: {}
3411
nodeSelector: {}
3412
# -- topologySpread for admin-api pods. Passed through `tpl` and, thus, to be configured as string
3413
# @default -- Defaults to allow skew no more than 1 node per AZ
3414
topologySpreadConstraints: |
3415
- maxSkew: 1
3416
topologyKey: topology.kubernetes.io/zone
3417
whenUnsatisfiable: ScheduleAnyway
3418
labelSelector:
3419
matchLabels:
3420
{{- include "tempo.selectorLabels" (dict "ctx" . "component" "admin-api") | nindent 6 }}
3421
# -- Affinity for admin-api pods. Passed through `tpl` and, thus, to be configured as string
3422
# @default -- Soft node and soft zone anti-affinity
3423
affinity: |
3424
podAntiAffinity:
3425
preferredDuringSchedulingIgnoredDuringExecution:
3426
- weight: 100
3427
podAffinityTerm:
3428
labelSelector:
3429
matchLabels:
3430
{{- include "tempo.selectorLabels" (dict "ctx" . "component" "admin-api") | nindent 12 }}
3431
topologyKey: kubernetes.io/hostname
3432
- weight: 75
3433
podAffinityTerm:
3434
labelSelector:
3435
matchLabels:
3436
{{- include "tempo.selectorLabels" (dict "ctx" . "component" "admin-api") | nindent 12 }}
3437
topologyKey: topology.kubernetes.io/zone
3438
# Pod Disruption Budget
3439
podDisruptionBudget: {}
3440
securityContext: {}
3441
# -- The SecurityContext for admin_api containers
3442
containerSecurityContext:
3443
readOnlyRootFilesystem: true
3444
extraArgs: {}
3445
persistence:
3446
subPath:
3447
readinessProbe:
3448
httpGet:
3449
path: /ready
3450
port: http-metrics
3451
initialDelaySeconds: 45
3452
resources:
3453
requests:
3454
cpu: 10m
3455
memory: 32Mi
3456
terminationGracePeriodSeconds: 60
3457
tolerations: []
3458
extraContainers: []
3459
extraVolumes: []
3460
extraVolumeMounts: []
3461
env: []
3462
extraEnvFrom: []
3463
# Settings for the gateway service providing authentication and authorization via the admin_api.
3464
# Can only be enabled if enterprise.enabled is true - requires license.
3465
enterpriseGateway:
3466
# -- If you want to use your own proxy URLs, set this to false.
3467
useDefaultProxyURLs: true
3468
# -- Proxy URLs defined in this object will be used if useDefaultProxyURLs is set to false.
3469
proxy: {}
3470
replicas: 1
3471
# -- hostAliases to add
3472
hostAliases: []
3473
# - ip: 1.2.3.4
3474
# hostnames:
3475
# - domain.tld
3476
3477
image:
3478
# -- The Docker registry for the enterpriseGateway image. Overrides `tempo.image.registry`
3479
registry: null
3480
# -- Optional list of imagePullSecrets. Overrides `tempo.image.pullSecrets`
3481
pullSecrets: []
3482
# -- Docker image repository for the enterpriseGateway image. Overrides `tempo.image.repository`
3483
repository: null
3484
# -- Docker image tag for the enterpriseGateway image. Overrides `tempo.image.tag`
3485
tag: null
3486
annotations: {}
3487
service:
3488
# -- Port of the enterprise gateway service; if left undefined, the service will listen on the same port as the pod
3489
port: null
3490
# -- Type of the enterprise gateway service
3491
type: ClusterIP
3492
# -- ClusterIP of the enterprise gateway service
3493
clusterIP: null
3494
# -- Load balancer IP address if service type is LoadBalancer for enterprise gateway service
3495
loadBalancerIP: null
3496
# -- Annotations for the enterprise gateway service
3497
annotations: {}
3498
# -- Labels for enterprise gateway service
3499
labels: {}
3500
strategy:
3501
type: RollingUpdate
3502
rollingUpdate:
3503
maxSurge: 0
3504
maxUnavailable: 1
3505
podLabels: {}
3506
podAnnotations: {}
3507
# Pod Disruption Budget
3508
podDisruptionBudget: {}
3509
nodeSelector: {}
3510
# -- topologySpread for enterprise-gateway pods. Passed through `tpl` and, thus, to be configured as string
3511
# @default -- Defaults to allow skew no more than 1 node per AZ
3512
topologySpreadConstraints: |
3513
- maxSkew: 1
3514
topologyKey: topology.kubernetes.io/zone
3515
whenUnsatisfiable: ScheduleAnyway
3516
labelSelector:
3517
matchLabels:
3518
{{- include "tempo.selectorLabels" (dict "ctx" . "component" "enterprise-gateway") | nindent 6 }}
3519
# -- Affinity for enterprise-gateway pods. Passed through `tpl` and, thus, to be configured as string
3520
# @default -- Soft node and soft zone anti-affinity
3521
affinity: |
3522
podAntiAffinity:
3523
preferredDuringSchedulingIgnoredDuringExecution:
3524
- weight: 100
3525
podAffinityTerm:
3526
labelSelector:
3527
matchLabels:
3528
{{- include "tempo.selectorLabels" (dict "ctx" . "component" "enterprise-gateway") | nindent 12 }}
3529
topologyKey: kubernetes.io/hostname
3530
- weight: 75
3531
podAffinityTerm:
3532
labelSelector:
3533
matchLabels:
3534
{{- include "tempo.selectorLabels" (dict "ctx" . "component" "enterprise-gateway") | nindent 12 }}
3535
topologyKey: topology.kubernetes.io/zone
3536
securityContext: {}
3537
# -- The SecurityContext for enterprise-gateway containers
3538
containerSecurityContext:
3539
readOnlyRootFilesystem: true
3540
initContainers: []
3541
extraArgs: {}
3542
persistence:
3543
subPath:
3544
readinessProbe:
3545
httpGet:
3546
path: /ready
3547
port: http-metrics
3548
initialDelaySeconds: 45
3549
resources:
3550
requests:
3551
cpu: 10m
3552
memory: 32Mi
3553
terminationGracePeriodSeconds: 60
3554
tolerations: []
3555
extraContainers: []
3556
extraVolumes: []
3557
extraVolumeMounts: []
3558
env: []
3559
extraEnvFrom: []
3560
# Ingress configuration
3561
ingress:
3562
# -- Specifies whether an ingress for the enterprise-gateway should be created
3563
enabled: false
3564
# -- Ingress Class Name. MAY be required for Kubernetes versions >= 1.18
3565
# ingressClassName: gateway
3566
# -- Annotations for the enterprise-gateway ingress
3567
annotations: {}
3568
# -- Hosts configuration for the enterprise-gateway ingress
3569
hosts:
3570
- host: gateway.get.example.com
3571
paths:
3572
- path: /
3573
# -- pathType (e.g. ImplementationSpecific, Prefix, .. etc.) might also be required by some Ingress Controllers
3574
# pathType: Prefix
3575
# -- TLS configuration for the enterprise-gateway ingress
3576
tls:
3577
- secretName: get-gateway-tls
3578
hosts:
3579
- gateway.get.example.com
3580
# -- extraObjects could be utilized to add dynamic manifests via values
3581
extraObjects: []
3582
# Examples:
3583
# extraObjects:
3584
# - apiVersion: kubernetes-client.io/v1
3585
# kind: ExternalSecret
3586
# metadata:
3587
# name: tempo-secrets-{{ .Release.Name }}
3588
# spec:
3589
# backendType: aws
3590
# data:
3591
# - key: secret-access-key
3592
# name: awssm-secret
3593
# Alternatively, you can use strings, which lets you use additional templating features:
3594
# extraObjects:
3595
# - |
3596
# apiVersion: kubernetes-client.io/v1
3597
# kind: ExternalSecret
3598
# metadata:
3599
# name: tempo-secrets-{{ .Release.Name }}
3600
# spec:
3601
# backendType: aws
3602
# data:
3603
# - key: secret-access-key
3604
# name: {{ include "some-other-template" }}
3605
3606
tests:
3607
integration:
3608
# -- Enable helm test hooks that run a BATS trace roundtrip against the live cluster.
3609
# WARNING: enabling this and running `helm test` ingests real trace data into object storage.
3610
# Traces age out via retention; Tempo has no delete API.
3611
enabled: false
3612

The trusted source for open source

Talk to an expert
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsChainguard OS PackagesChainguard ActionsChainguard Agent SkillsIntegrationsPricing
© 2026 Chainguard, Inc. All Rights Reserved.
Chainguard® and the Chainguard logo are registered trademarks of Chainguard, Inc. in the United States and/or other countries.
The other respective trademarks mentioned on this page are owned by the respective companies and use of them does not imply any affiliation or endorsement.