3 # -- Overrides the Docker registry globally for all images, excluding enterprise.
5 # -- Optional list of imagePullSecrets for all images, excluding enterprise.
6 # Names of existing secrets with private container registry credentials.
7 # Ref: https://kubernetes.io/docs/concepts/containers/images/#specifying-imagepullsecrets-on-a-pod
9 # pullSecrets: [ my-dockerconfigjson-secret ]
11 # -- Adding common labels to all K8S resources including pods
13 # -- Adding labels to K8S resources (excluding pods)
15 # -- Adding labels to all pods
17 # -- Overrides the priorityClassName for all pods
18 priorityClassName: null
19 # -- configures cluster domain ("cluster.local" by default)
20 clusterDomain: 'cluster.local'
21 # -- configures DNS service name
22 dnsService: 'kube-dns'
23 # -- configures DNS service namespace
24 dnsNamespace: 'kube-system'
26 # -- Fraction of the container memory limit used to compute GOMEMLIMIT (e.g. 0.85 = 85%).
27 # Set to 0 to disable automatic GOMEMLIMIT injection.
28 goMemLimitFactor: 0.85
29 # -- Value to set for GOGC alongside GOMEMLIMIT. Lowering below the default of 100 reduces
30 # heap growth between GC cycles, working in tandem with GOMEMLIMIT to smooth memory usage.
31 # Set to 0 to disable automatic GOGC injection.
33 # -- Common environment variables to add to all pods directly managed by this chart.
34 # scope: admin-api, compactor, distributor, enterprise-federation-frontend, gateway, ingester, memcached, metrics-generator, querier, query-frontend, tokengen
36 # -- Common environment variables which come from a ConfigMap or Secret to add to all pods directly managed by this chart.
37 # scope: admin-api, compactor, distributor, enterprise-federation-frontend, gateway, ingester, memcached, metrics-generator, querier, query-frontend, tokengen
39 # -- Common args to add to all pods directly managed by this chart.
40 # scope: admin-api, compactor, distributor, enterprise-federation-frontend, gateway, ingester, memcached, metrics-generator, querier, query-frontend, tokengen
42 # -- Global storage class to be used for persisted components
45# fullnameOverride: tempo
47# -- Configuration is loaded from the secret called 'externalConfigSecretName'.
48# If 'useExternalConfig' is true, then the configuration is not generated, just
49# consumed. Top level keys for `tempo.yaml` and `overrides.yaml` are to be
50# provided by the user.
51useExternalConfig: false
52# -- Defines what kind of object stores the configuration, a ConfigMap or a Secret.
53# In order to move sensitive information (such as credentials) from the ConfigMap/Secret to a more secure location (e.g. vault), it is possible to use [environment variables in the configuration](https://grafana.com/docs/mimir/latest/operators-guide/configuring/reference-configuration-parameters/#use-environment-variables-in-the-configuration).
54# Such environment variables can be then stored in a separate Secret and injected via the global.extraEnvFrom value. For details about environment injection from a Secret please see [Secrets](https://kubernetes.io/docs/concepts/configuration/secret/#use-case-as-container-environment-variables).
55configStorageType: ConfigMap
56# -- Name of the Secret or ConfigMap that contains the configuration (used for naming even if config is internal).
57externalConfigSecretName: '{{ include "tempo.resourceName" (dict "ctx" . "component" "config") }}'
58# -- Name of the Secret or ConfigMap that contains the runtime configuration (used for naming even if config is internal).
59externalRuntimeConfigName: '{{ include "tempo.resourceName" (dict "ctx" . "component" "runtime") }}'
60# -- When 'useExternalConfig' is true, then changing 'externalConfigVersion' triggers restart of services - otherwise changes to the configuration cause a restart.
61externalConfigVersion: '0'
62# -- If true, Tempo will report anonymous usage data about the shape of a deployment to Grafana Labs
64# -- Enable streaming over HTTP for tempo and Tempo gateway(nginx)
65streamOverHTTPEnabled: false
67 # -- Pod DNS config applied to all components. Override per component with `<component>.dnsConfig` or `defaults.dnsConfig`.
70 # -- The Docker registry. Overrides `global.image.registry`
72 # -- Optional list of imagePullSecrets. Overrides `global.image.pullSecrets`
74 # -- Docker image repository
75 repository: chainguard-private/tempo
76 # -- Overrides the image tag whose default is the chart's appVersion
77 tag: 3.0.3-r8@sha256:3afa2b3dbcf20b0c476cd05c7fc68a4bb30f64d92439fed7b1ba403662ce5349
78 pullPolicy: IfNotPresent
83 initialDelaySeconds: 60
89 initialDelaySeconds: 30
91 # -- Startup probe for all Tempo binary pods. Disabled by default.
93 # -- Global labels for all tempo pods
95 # -- Common annotations for all pods
97 # -- The number of old ReplicaSets to retain to allow rollback
98 revisionHistoryLimit: 10
99 # -- SecurityContext holds container-level security attributes and common container settings
104 allowPrivilegeEscalation: false
108 readOnlyRootFilesystem: true
109 # -- podSecurityContext holds pod-level security attributes and common container settings
112 # -- Structured tempo configuration
114 # -- Memberlist service configuration.
116 # -- Adds the appProtocol field to the memberlist service. This allows memberlist to work with istio protocol selection. Set the optional service protocol. Ex: "tcp", "http" or "https".
118 # -- Adds the service field to the memberlist service
120 # -- Sets optional annotations to the service field of the memberlist service.
123 # -- Configure the IP families for all tempo services
124 # See the Service spec for details: https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.31/#servicespec-v1-core
128 # -- Configure the IP family policy for all tempo services. SingleStack, PreferDualStack or RequireDualStack
129 ipFamilyPolicy: 'SingleStack'
130 # -- Default traffic distribution for all non-headless tempo services (PreferSameZone or PreferSameNode).
131 # See https://kubernetes.io/docs/concepts/services-networking/service/#traffic-distribution.
132 # Can be overridden per component via <component>.service.trafficDistribution.
133 trafficDistribution: null
134 # -- Point the live-store, block-builder, backend-scheduler, backend-worker and
135 # metrics-generator StatefulSets at the headless Service of their own component as the
136 # governing service, and publish the not-ready addresses of those Services. The default
137 # `false` keeps the short, unprefixed name that the chart has always written. That name
138 # matches no Service, so the stable per-pod DNS names do not resolve. The memcached
139 # StatefulSets already write the full resource name and are not affected.
140 # `spec.serviceName` is immutable, and a pod takes its subdomain at creation only. Enable
141 # this only together with the manual StatefulSet delete and the pod restart described
142 # under `Upgrading` in the chart README.
143 useHeadlessGoverningService: false
144# -- Default values applied to every pod in this chart.
145# These values are overridden by component-specific settings.
147 # -- Default pod DNS config for all pods. Overridden per component by `<component>.dnsConfig`; falls back to `tempo.dnsConfig`.
149 # -- Default pod-level security context for all pods
150 podSecurityContext: {}
151 # -- Default container-level security context for all containers
152 containerSecurityContext: {}
153 # -- Default annotations for all pods
155 # -- Default labels for all pods
157 # -- Default node selector for all pods
159 # -- Default tolerations for all pods
161 # -- Default affinity for all pods
163 # -- Default priority class name for all pods
164 priorityClassName: ""
165 # -- Default resource requests and limits for all pods
167 # -- Default extra CLI args for all Tempo binary pods
169 # -- Default extra environment variables for all pods
171 # -- Default extra environment variables from ConfigMaps or Secrets for all pods
173 # -- Default extra volume mounts for all pods
174 extraVolumeMounts: []
175 # -- Default extra volumes for all pods
177 # -- Default liveness probe for all Tempo binary pods. Overridden by `tempo.livenessProbe` and `<component>.livenessProbe`.
179 # -- Default readiness probe for all Tempo binary pods. Overridden by `tempo.readinessProbe` and `<component>.readinessProbe`.
181 # -- Default startup probe for all Tempo binary pods. Overridden by `tempo.startupProbe` and `<component>.startupProbe`.
184 # -- Specifies whether a ServiceAccount should be created
186 # -- The name of the ServiceAccount to use.
187 # If not set and create is true, a name is generated using the fullname template
189 # -- Image pull secrets for the service account
191 # -- Labels for the service account
193 # -- Annotations for the service account
195 automountServiceAccountToken: false
197 # -- Specifies whether RBAC manifests should be created
199# Configuration for the metrics-generator
201 # -- Specifies whether a metrics-generator should be deployed
203 # -- Kind of deployment [StatefulSet/Deployment]
205 # -- Annotations for the metrics-generator StatefulSet
207 # -- Number of replicas for the metrics-generator
209 # -- hostAliases to add
214 # -- Pod DNS config for this component. Falls back to `defaults.dnsConfig`, then `tempo.dnsConfig`.
216 # -- Init containers for the metrics generator pod
219 # -- The Docker registry for the metrics-generator image. Overrides `tempo.image.registry`
221 # -- Optional list of imagePullSecrets. Overrides `tempo.image.pullSecrets`
223 # -- Docker image repository for the metrics-generator image. Overrides `tempo.image.repository`
225 # -- Docker image tag for the metrics-generator image. Overrides `tempo.image.tag`
227 # -- The name of the PriorityClass for metrics-generator pods
228 priorityClassName: null
229 # -- Labels for metrics-generator pods
231 # -- Annotations for metrics-generator pods
233 # -- Additional CLI args for the metrics-generator
235 # -- Environment variables to add to the metrics-generator pods
237 # -- Environment variables from secrets or configmaps to add to the metrics-generator pods
239 # -- Startup probe for metrics-generator pods. Uses `tempo.startupProbe` as default if not set.
241 # -- Resource requests and limits for the metrics-generator
243 # -- Grace period to allow the metrics-generator to shutdown before it is killed. Especially for the ingestor,
244 # this must be increased. It must be long enough so metrics-generators can be gracefully shutdown flushing/transferring
245 # all data and to successfully leave the member ring on shutdown.
246 terminationGracePeriodSeconds: 300
247 # -- topologySpread for metrics-generator pods. Passed through `tpl` and, thus, to be configured as string
248 # @default -- Defaults to allow skew no more then 1 node per AZ
249 topologySpreadConstraints: |
251 topologyKey: topology.kubernetes.io/zone
252 whenUnsatisfiable: ScheduleAnyway
255 {{- include "tempo.selectorLabels" (dict "ctx" . "component" "metrics-generator") | nindent 6 }}
256 # -- Affinity for metrics-generator pods. Passed through `tpl` and, thus, to be configured as string
257 # @default -- Hard node and soft zone anti-affinity
260 requiredDuringSchedulingIgnoredDuringExecution:
263 {{- include "tempo.selectorLabels" (dict "ctx" . "component" "metrics-generator") | nindent 10 }}
264 topologyKey: kubernetes.io/hostname
265 preferredDuringSchedulingIgnoredDuringExecution:
270 {{- include "tempo.selectorLabels" (dict "ctx" . "component" "metrics-generator") | nindent 12 }}
271 topologyKey: topology.kubernetes.io/zone
272 # -- Pod Disruption Budget configuration
274 # -- Enable PodDisruptionBudget for metrics-generator
276 # -- Set unhealthyPodEvictionPolicy for the metrics-generator PodDisruptionBudget. Requires policy/v1.
277 unhealthyPodEvictionPolicy: ""
278 # -- Pod Disruption Budget maxUnavailable
280 # -- Minimum number of seconds for which a newly created Pod should be ready without any of its containers crashing/terminating
282 # -- Node selector for metrics-generator pods
284 # -- Tolerations for metrics-generator pods
286 # -- Persistence configuration for metrics-generator
288 # -- Enable creating PVCs if you have kind set to StatefulSet. This disables using local disk or memory configured in walEmptyDir
290 # -- Enable StatefulSetRecreation for changes to PVC size.
291 # This means that the StatefulSet will be deleted, recreated (with the same name) and rolled when a change to the
292 # PVC size is detected. That way the PVC can be resized without manual intervention.
293 enableStatefulSetRecreationForSizeChange: false
295 # -- Storage class to be used.
296 # If defined, storageClassName: <storageClass>.
297 # If set to "-", storageClassName: "", which disables dynamic provisioning.
298 # If empty or set to null, no storageClassName spec is
299 # set, choosing the default provisioner (gp2 on AWS, standard on GKE, AWS, and OpenStack).
301 # -- Annotations for metrics generator PVCs
303 # -- Labels for metrics generator PVCs
305 # -- The EmptyDir location where the /var/tempo will be mounted on. Defaults to local disk, can be set to memory.
307 ## Here shows how to configure 1Gi memory as emptyDir.
308 ## Ref: https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.19/#emptydirvolumesource-v1-core
311 # -- Extra volumes for metrics-generator pods
312 extraVolumeMounts: []
313 # -- Extra volumes for metrics-generator deployment
315 # -- Containers to add to the metrics-generator pods
317 persistentVolumeClaimRetentionPolicy:
318 # -- Enable Persistent volume retention policy for StatefulSet
320 # -- Volume retention behavior when the replica count of the StatefulSet is reduced
322 # -- Volume retention behavior that applies when the StatefulSet is deleted
329 - name: http-memberlist
335 # -- More information on configuration: https://grafana.com/docs/tempo/latest/configuration/#metrics-generator
338 collection_interval: 15s
342 # -- For processors to be enabled and generate metrics, pass the names of the processors to `overrides.defaults.metrics_generator.processors` value like `[service-graphs, span-metrics]`.
344 # -- Additional dimensions to add to the metrics along with the default dimensions.
345 # -- The resource and span attributes to be added to the service graph metrics, if present.
347 histogram_buckets: [0.1, 0.2, 0.4, 0.8, 1.6, 3.2, 6.4, 12.8]
352 # -- Additional dimensions to add to the metrics along with the default dimensions.
353 # -- The resource and span attributes to be added to the span metrics, if present.
355 histogram_buckets: [0.002, 0.004, 0.008, 0.016, 0.032, 0.064, 0.128, 0.256, 0.512, 1.02, 2.05, 4.10]
359 remote_write_flush_deadline: 1m
360 # Whether to add X-Scope-OrgID header in remote write requests
361 remote_write_add_org_id_header: true
362 # -- A list of remote write endpoints.
363 # -- https://prometheus.io/docs/prometheus/latest/configuration/configuration/#remote_write
365 # -- Used by the local blocks processor to store a wal for traces.
366 metrics_ingestion_time_range_slack: 30s
368 # -- Annotations for Metrics Generator service
370 # -- Traffic distribution for the Metrics Generator service (PreferSameZone or PreferSameNode). Overrides tempo.service.trafficDistribution.
371 trafficDistribution: null
373 # -- Annotations for Metrics Generator discovery service
375 # -- Adds the appProtocol field to the metricsGenerator service. This allows metricsGenerator to work with istio protocol selection.
377 # -- Set the optional gRPC service protocol. Ex: "grpc", "http2" or "https"
379# Configuration for the distributor
381 # -- Number of replicas for the distributor
383 # -- Annotations for distributor deployment
385 # -- hostAliases to add
390 # -- Pod DNS config for this component. Falls back to `defaults.dnsConfig`, then `tempo.dnsConfig`.
393 # -- Enable autoscaling for the distributor
395 # -- Minimum autoscaling replicas for the distributor
397 # -- Maximum autoscaling replicas for the distributor
399 # -- Autoscaling behavior configuration for the distributor
401 # -- Target CPU utilisation percentage for the distributor
402 targetCPUUtilizationPercentage: 60
403 # -- Target memory utilisation percentage for the distributor
404 targetMemoryUtilizationPercentage:
406 # -- The Docker registry for the distributor image. Overrides `tempo.image.registry`
408 # -- Optional list of imagePullSecrets. Overrides `tempo.image.pullSecrets`
410 # -- Docker image repository for the distributor image. Overrides `tempo.image.repository`
412 # -- Docker image tag for the distributor image. Overrides `tempo.image.tag`
415 # -- Annotations for distributor service
417 # -- Labels for distributor service
419 # -- Type of service for the distributor
421 # -- If type is LoadBalancer you can assign the IP to the LoadBalancer
423 # -- If type is LoadBalancer limit incoming traffic from IPs.
424 loadBalancerSourceRanges: []
425 # -- If type is LoadBalancer you can set it to 'Local' [preserve the client source IP](https://kubernetes.io/docs/tasks/access-application-cluster/create-external-load-balancer/#preserving-the-client-source-ip)
426 externalTrafficPolicy: null
427 # -- https://kubernetes.io/docs/concepts/services-networking/service-traffic-policy/
428 internalTrafficPolicy: Cluster
429 # -- Traffic distribution for the distributor service (PreferSameZone or PreferSameNode). Overrides tempo.service.trafficDistribution.
430 trafficDistribution: null
432 # -- Annotations for distributorDiscovery service
434 # -- Labels for distributorDiscovery service
436 # -- The name of the PriorityClass for distributor pods
437 priorityClassName: null
438 # -- Labels for distributor pods
440 # -- Annotations for distributor pods
442 # -- Additional CLI args for the distributor
444 # -- Environment variables to add to the distributor pods
446 # -- Environment variables from secrets or configmaps to add to the distributor pods
448 # -- Init containers to add to the distributor pods
450 # -- Containers to add to the distributor pod
452 # -- Additional ports to expose on the distributor container (e.g. trace receiver ports).
453 # Standard ports (http-metrics, http-memberlist) are always added automatically.
455 # -- Liveness probe for distributor pods. Uses `tempo.livenessProbe` as default if not set.
457 # -- Readiness probe for distributor pods. Uses `tempo.readinessProbe` as default if not set.
459 # -- Startup probe for distributor pods. Uses `tempo.startupProbe` as default if not set.
461 # -- Resource requests and limits for the distributor
463 # -- On SIGTERM, report not-ready and wait this long before shutdown so the LB drains the pod before connections are cut.
464 # "0s" (default) disables. When enabling, keep terminationGracePeriodSeconds above shutdownDelay + server.graceful_shutdown_timeout.
466 # -- Grace period to allow the distributor to shutdown before it is killed
467 terminationGracePeriodSeconds: 30
468 # -- Container lifecycle hooks for the distributor
470 # -- topologySpread for distributor pods. Passed through `tpl` and, thus, to be configured as string
471 # @default -- Defaults to allow skew no more then 1 node per AZ
472 topologySpreadConstraints: |
474 topologyKey: topology.kubernetes.io/zone
475 whenUnsatisfiable: ScheduleAnyway
478 {{- include "tempo.selectorLabels" (dict "ctx" . "component" "distributor") | nindent 6 }}
479 # -- Affinity for distributor pods. Passed through `tpl` and, thus, to be configured as string
480 # @default -- Hard node and soft zone anti-affinity
483 requiredDuringSchedulingIgnoredDuringExecution:
486 {{- include "tempo.selectorLabels" (dict "ctx" . "component" "distributor") | nindent 10 }}
487 topologyKey: kubernetes.io/hostname
488 preferredDuringSchedulingIgnoredDuringExecution:
493 {{- include "tempo.selectorLabels" (dict "ctx" . "component" "distributor") | nindent 12 }}
494 topologyKey: topology.kubernetes.io/zone
495 # Strategy of updating pods
500 # -- Pod Disruption Budget configuration
502 # -- Enable PodDisruptionBudget for distributor
504 # -- Set unhealthyPodEvictionPolicy for the distributor PodDisruptionBudget. Requires policy/v1.
505 unhealthyPodEvictionPolicy: ""
506 # -- Pod Disruption Budget maxUnavailable
508 # -- Minimum number of seconds for which a newly created Pod should be ready without any of its containers crashing/terminating
510 # -- Node selector for distributor pods
512 # -- Tolerations for distributor pods
514 # -- Extra volumes for distributor pods
515 extraVolumeMounts: []
516 # -- Extra volumes for distributor deployment
519 # -- Enable to log every received trace id to help debug ingestion
520 # -- WARNING: Deprecated. Use log_received_spans instead.
521 log_received_traces: null
522 # -- Enable to log every received span to help debug ingestion or calculate span error distributions using the logs
525 include_all_attributes: false
526 filter_by_status_error: false
529 include_all_attributes: false
530 filter_by_status_error: false
531 # -- Disables write extension with inactive ingesters
533 # -- Trace Attribute bytes limit. This is the maximum number of bytes that can be used in a trace. 0 for no limit. Set to null to omit from config.
534 max_attribute_bytes: null
535 # Configures usage trackers in the distributor which expose metrics of ingested traffic grouped by configurable
536 # attributes exposed on /usage_metrics.
538 # -- Enables the "cost-attribution" usage tracker. Per-tenant attributes are configured in overrides.
540 # -- Maximum number of series per tenant.
541 max_cardinality: 10000
542 # -- Interval after which a series is considered stale and will be deleted from the registry.
543 # -- Once a metrics series is deleted, it won't be emitted anymore, keeping active series low.
544 stale_duration: 15m0s
545 # -- Adds the appProtocol field to the distributor service. This allows distributor to work with istio protocol selection.
547 # -- Set the optional gRPC service protocol. Ex: "grpc", "http2" or "https"
549# -- EXPERIMENTAL Feature, disabled by default
550# Configuration for the backend-scheduler
552 # -- Specifies whether a backend-scheduler and backend-worker
553 # -- should be deployed.
555 # -- Annotations for backend-scheduler StatefulSet
557 # -- Labels for the backend-scheduler StatefulSet
559 # -- hostAliases to add
564 # -- Pod DNS config for this component. Falls back to `defaults.dnsConfig`, then `tempo.dnsConfig`.
566 # -- Init containers to add to the backend-scheduler pod
569 # -- The Docker registry for the backend-scheduler image. Overrides `tempo.image.registry`
571 # -- Optional list of imagePullSecrets. Overrides `tempo.image.pullSecrets`
573 # -- Docker image repository for the backend-scheduler image. Overrides `tempo.image.repository`
575 # -- Docker image tag for the backend-scheduler image. Overrides `tempo.image.tag`
577 # -- The name of the PriorityClass for backend-scheduler pod
578 priorityClassName: null
579 # -- Labels for backend-scheduler pod
581 # -- Annotations for backend-scheduler pod
583 # -- Additional CLI args for the backend-scheduler
585 # -- Environment variables to add to the backend-scheduler pod
587 # -- Environment variables from secrets or configmaps to add to the backend-scheduler pod
589 # -- Additional ports to expose on the backend-scheduler container
590 # Standard ports (grpc, http-metrics, http-memberlist) are always added automatically.
592 # -- Liveness probe for backend-scheduler pod. Uses `tempo.livenessProbe` as default if not set.
594 # -- Readiness probe for backend-scheduler pod. Uses `tempo.readinessProbe` as default if not set.
596 # -- Startup probe for backend-scheduler pod. Uses `tempo.startupProbe` as default if not set.
598 # -- Resource requests and limits for the backend-scheduler
600 # -- Grace period to allow the backend-scheduler to shutdown before it is killed
601 terminationGracePeriodSeconds: 30
602 # -- topologySpread for backend-scheduler pods. Passed through `tpl` and, thus, to be configured as string
603 # @default -- Defaults to allow skew no more then 1 node per AZ
604 topologySpreadConstraints: |
606 topologyKey: topology.kubernetes.io/zone
607 whenUnsatisfiable: ScheduleAnyway
610 {{- include "tempo.selectorLabels" (dict "ctx" . "component" "backend-scheduler") | nindent 6 }}
611 # -- Affinity for backend-scheduler pods. Passed through `tpl` and, thus, to be configured as string
612 # @default -- Soft node and soft zone anti-affinity
615 preferredDuringSchedulingIgnoredDuringExecution:
620 {{- include "tempo.selectorLabels" (dict "ctx" . "component" "backend-scheduler") | nindent 12 }}
621 topologyKey: kubernetes.io/hostname
626 {{- include "tempo.selectorLabels" (dict "ctx" . "component" "backend-scheduler") | nindent 12 }}
627 topologyKey: topology.kubernetes.io/zone
628 # -- Node selector for backend-scheduler pod
630 # -- Tolerations for backend-scheduler pod
632 # -- Extra volumes for backend-scheduler pod
633 extraVolumeMounts: []
634 # -- Extra volumes for backend-scheduler StatefulSet
636 # -- Containers to add to the backend-scheduler pods
638 # -- Persistence configuration for backend-scheduler
640 # -- Enable creating a PVC for the backend-scheduler data volume, so its local
641 # work path survives a pod restart instead of being lost with the emptyDir.
643 # -- Enable StatefulSetRecreation for changes to PVC size
644 enableStatefulSetRecreationForSizeChange: false
645 # -- use emptyDir with ramdisk instead of PVC. **Please note that all data in backend-scheduler will be lost on pod restart**
647 # -- Size of persistent or memory disk
649 # -- Storage class to be used.
650 # If defined, storageClassName: <storageClass>.
651 # If set to "-", storageClassName: "", which disables dynamic provisioning.
652 # If empty or set to null, no storageClassName spec is
653 # set, choosing the default provisioner (gp2 on AWS, standard on GKE, AWS, and OpenStack).
655 # -- Annotations for backend-scheduler's persist volume claim
657 # -- Labels for backend-scheduler's persist volume claim
659 # -- Spec for the `data` volume when persistence is disabled. By default an
660 # empty `emptyDir: {}`; set e.g. `sizeLimit` or `medium: Memory` as needed.
662 # -- updateStrategy of the backend-scheduler statefulset.
666 persistentVolumeClaimRetentionPolicy:
667 # -- Enable Persistent volume retention policy for StatefulSet
669 # -- Volume retention behavior when the replica count of the StatefulSet is reduced
671 # -- Volume retention behavior that applies when the StatefulSet is deleted
674 # -- How often to flush the work cache to backend storage
675 backend_flush_interval: 1m
676 # -- How long to wait for a worker to complete a job before timing out internally
678 # -- Path to store local work cache files
679 local_work_path: /var/tempo
680 # -- How often to perform maintenance tasks (pruning old jobs, checking for dead jobs, etc.)
681 maintenance_interval: 1m
682 # -- Provider configuration for job generation
684 # -- Compaction job configuration
686 # -- Compaction configuration
688 # -- Duration to keep blocks
690 # Duration to keep blocks that have been compacted elsewhere
691 compacted_block_retention: 1h
692 # -- The time between compaction cycles
693 compaction_cycle: 30s
694 # -- Blocks in this time window will be compacted together
695 compaction_window: 1h
696 # -- Maximum size of a compacted block in bytes
697 # -- This should be set to a lower value, ideally 5GB or less
698 # -- 100GB is a legacy default for v2 storage format which is
699 # -- no longer even available as of Tempo 2.1.x
700 # -- https://github.com/grafana/tempo/discussions/5301
701 max_block_bytes: 107374182400
702 # -- Maximum number of traces in a compacted block. WARNING: Deprecated. Use max_block_bytes instead.
703 max_compaction_objects: 6000000
704 # -- The maximum amount of time to spend compacting a single tenant before moving to the next
705 max_time_per_tenant: 5m
706 # -- Number of tenants to process in parallel during retention
707 retention_concurrency: 10
708 # -- Maximum number of compaction jobs to create per tenant
709 max_compaction_level: 0
710 # -- Maximum number of blocks to compact together
712 # -- Maximum compaction level (0 means no limit)
713 max_jobs_per_tenant: 1000
714 # -- How often to measure tenant block lists and create new compaction jobs
716 # -- Minimum time between compaction cycles for a tenant
717 min_cycle_interval: 30s
718 # -- Minimum number of blocks required for compaction
720 # -- Retention job configuration
722 # -- How often to check for blocks that need to be deleted due to retention
724 # -- Work cache configuration
726 # -- After this duration, jobs that have not been updated are considered dead and will be reassigned.
727 dead_job_timeout: 24h
728 # -- How long to keep completed or failed jobs in the work cache before pruning them.
731 # -- Annotations for backend-scheduler service
733# Configuration for the backend-worker
735 # -- Number of replicas for the backend-worker
737 # -- Autoscaling configurations
739 # -- Enable autoscaling for the backend-worker
741 # -- Minimum autoscaling replicas for the backend-worker
743 # -- Maximum autoscaling replicas for the backend-worker
745 # -- Autoscaling via HPA object
748 # -- Autoscaling behavior configuration for the backend-worker
750 # -- Target CPU utilisation percentage for the backend-worker
751 targetCPUUtilizationPercentage: 100
752 # -- Target memory utilisation percentage for the backend-worker
753 targetMemoryUtilizationPercentage:
754 # -- Autoscaling via keda/ScaledObject
756 # requires https://keda.sh/
759 # scaledobject.keda.sh/transfer-hpa-ownership: "true" # Use to transfer an existing HPA ownership to this ScaledObject
760 # validations.keda.sh/hpa-ownership: "true" # Use to disable HPA ownership validation on this ScaledObject
761 # autoscaling.keda.sh/paused: "true" # Use to pause autoscaling of objects explicitly
762 pollingInterval: null # Optional. Default: 30 seconds
763 cooldownPeriod: null # Optional. Default: 300 seconds
764 initialCooldownPeriod: null # Optional. Default: 0 seconds
765 # Optional. Section to specify advanced options
767 # # Optional. Section to specify advanced options
768 # horizontalPodAutoscalerConfig:
769 # # Optional. Default: keda-hpa-{scaled-object-name}
771 # # Optional. Use to modify HPA's scaling behavior
774 # # stabilizationWindowSeconds: 300
775 # # Optional. Section to specify scaling modifiers
777 # target: null # Mandatory. New target if metrics are anyhow composed together
778 # activationTarget: null # Optional. New activation target if metrics are anyhow composed together
779 # metricType: null # Optional. Metric type to be used if metrics are anyhow composed together
780 # formula: null # Mandatory. Formula for calculation
782 # failureThreshold: null # Mandatory if fallback section is included
783 # replicas: null # Mandatory if fallback section is included
784 # behavior: null # Optional. Default: "static"
785 # -- List of autoscaling triggers for the compactor
787 # - name: tempo-outstanding-compaction-blocks
788 ## https://keda.sh/docs/2.19/concepts/authentication/
789 ## authenticationRef:
790 ## name: {trigger-authentication-name} or {cluster-trigger-authentication-name}
791 ## kind: TriggerAuthentication or ClusterTriggerAuthentication
794 # serverAddress: "http://<prometheus-host>:9090"
797 # sum by (cluster, namespace, tenant) (
798 # tempodb_compaction_outstanding_blocks{container="backend-scheduler", namespace=~".*"}
800 # ignoring(tenant) group_left count by (cluster, namespace)(
801 # tempo_build_info{container="backend-worker", namespace=~".*"}
803 # customHeaders: X-Scope-OrgID=<tenant-id>
804 # -- Annotations for backend-worker StatefulSet
806 # -- Labels for the backend-worker StatefulSet
808 # -- hostAliases to add
813 # -- Pod DNS config for this component. Falls back to `defaults.dnsConfig`, then `tempo.dnsConfig`.
815 # -- Init containers to add to the backend-worker pods
818 # -- The Docker registry for the backend-worker image. Overrides `tempo.image.registry`
820 # -- Optional list of imagePullSecrets. Overrides `tempo.image.pullSecrets`
822 # -- Docker image repository for the backend-worker image. Overrides `tempo.image.repository`
824 # -- Docker image tag for the backend-worker image. Overrides `tempo.image.tag`
826 # -- The name of the PriorityClass for backend-worker pods
827 priorityClassName: null
828 # -- Labels for backend-worker pods
830 # -- Annotations for backend-worker pods
832 # -- Additional CLI args for the backend-worker
834 # -- Environment variables to add to the backend-worker pods
836 # -- Environment variables from secrets or configmaps to add to the backend-worker pods
838 # -- Liveness probe for backend-worker pods. Uses `tempo.livenessProbe` as default if not set.
840 # -- Readiness probe for backend-worker pods. Uses `tempo.readinessProbe` as default if not set.
842 # -- Startup probe for backend-worker pods. Uses `tempo.startupProbe` as default if not set.
844 # -- Resource requests and limits for the backend-worker
846 # -- Grace period to allow the backend-worker to shutdown before it is killed
847 terminationGracePeriodSeconds: 30
848 # -- topologySpread for backend-worker pods. Passed through `tpl` and, thus, to be configured as string
849 # @default -- Defaults to allow skew no more then 1 node per AZ
850 topologySpreadConstraints: |
852 topologyKey: topology.kubernetes.io/zone
853 whenUnsatisfiable: ScheduleAnyway
856 {{- include "tempo.selectorLabels" (dict "ctx" . "component" "backend-worker") | nindent 6 }}
857 # -- Affinity for backend-worker pods. Passed through `tpl` and, thus, to be configured as string
858 # @default -- Soft node and soft zone anti-affinity
861 preferredDuringSchedulingIgnoredDuringExecution:
866 {{- include "tempo.selectorLabels" (dict "ctx" . "component" "backend-worker") | nindent 12 }}
867 topologyKey: kubernetes.io/hostname
872 {{- include "tempo.selectorLabels" (dict "ctx" . "component" "backend-worker") | nindent 12 }}
873 topologyKey: topology.kubernetes.io/zone
874 # -- Node selector for backend-worker pods
876 # -- Tolerations for backend-worker pods
878 # -- Extra volumes for backend-worker pods
879 extraVolumeMounts: []
880 # -- Extra volumes for backend-worker StatefulSet
882 # -- Containers to add to the backend-worker pods
884 # -- updateStrategy of the backend-worker statefulset.
888 persistentVolumeClaimRetentionPolicy:
889 # -- Enable Persistent volume retention policy for StatefulSet
891 # -- Volume retention behavior when the replica count of the StatefulSet is reduced
893 # -- Volume retention behavior that applies when the StatefulSet is deleted
896 backend_scheduler_client:
897 # -- gRPC client configuration
898 grpc_client_config: {}
899 # -- Backoff configuration for retrying failed jobs
904 # -- Compaction settings
905 # -- .Values.backendScheduler.compaction.compaction will be used
907 # -- Timeout for finishing the current job before shutting down the worker
908 finish_on_shutdown_timeout: 30s
910 # -- Annotations for backend-worker service
912# -- Ingest configuration. Sets the top-level `ingest:` block in tempo.yaml.
913# Required for Tempo 3.0 microservices mode. Distributors write spans to Kafka;
914# block-builders and live-stores consume from it.
915# The number of block-builder and live-store replicas must equal the Kafka partition count.
918 # -- Kafka broker address (e.g. "kafka.kafka-namespace.svc.cluster.local:9092")
920 # -- Kafka topic name for trace data
922 # -- Automatically create the topic if it does not exist
923 auto_create_topic_enabled: true
924 # -- Number of partitions for the auto-created topic.
925 # Block-builder and live-store replica count must match this value.
926 auto_create_topic_default_partitions: 3
927# Configuration for the block-builder (Tempo 3.0+)
928# Consumes spans from Kafka and writes blocks to object storage.
929# One replica per Kafka partition — replica count must equal ingest.kafka.auto_create_topic_default_partitions.
931 # -- Enable the block-builder. Requires ingest.kafka.address to be set.
933 # -- Number of replicas. Must equal the Kafka partition count.
935 # -- Annotations for the block-builder StatefulSet
937 # -- Labels for the block-builder StatefulSet
939 # -- hostAliases to add
941 # -- Pod DNS config for this component. Falls back to `defaults.dnsConfig`, then `tempo.dnsConfig`.
943 # -- Init containers to add to the block-builder pod
946 # -- The Docker registry for the block-builder image. Overrides `tempo.image.registry`
948 # -- Optional list of imagePullSecrets. Overrides `tempo.image.pullSecrets`
950 # -- Docker image repository for the block-builder image. Overrides `tempo.image.repository`
952 # -- Docker image tag for the block-builder image. Overrides `tempo.image.tag`
954 # -- The name of the PriorityClass for block-builder pods
955 priorityClassName: null
956 # -- Labels for block-builder pods
958 # -- Annotations for block-builder pods
960 # -- Additional CLI args for the block-builder
962 # -- Environment variables to add to the block-builder pods
964 # -- Environment variables from secrets or configmaps to add to the block-builder pods
966 # -- Additional ports to expose on the block-builder container
968 # -- Liveness probe for block-builder pods. Uses `tempo.livenessProbe` as default if not set.
970 # -- Readiness probe for block-builder pods. Uses `tempo.readinessProbe` as default if not set.
972 # -- Startup probe for block-builder pods. Uses `tempo.startupProbe` as default if not set.
974 # -- Resource requests and limits for the block-builder
976 # -- Grace period to allow the block-builder to flush its WAL before being killed
977 terminationGracePeriodSeconds: 300
978 # -- topologySpread for block-builder pods. Passed through `tpl`.
979 topologySpreadConstraints: |
981 topologyKey: topology.kubernetes.io/zone
982 whenUnsatisfiable: ScheduleAnyway
985 {{- include "tempo.selectorLabels" (dict "ctx" . "component" "block-builder") | nindent 6 }}
986 # -- Affinity for block-builder pods. Passed through `tpl`.
989 preferredDuringSchedulingIgnoredDuringExecution:
994 {{- include "tempo.selectorLabels" (dict "ctx" . "component" "block-builder") | nindent 12 }}
995 topologyKey: kubernetes.io/hostname
996 # -- Node selector for block-builder pods
998 # -- Tolerations for block-builder pods
1000 # -- Extra volumes for block-builder pods
1001 extraVolumeMounts: []
1002 # -- Extra volumes for block-builder StatefulSet
1004 # -- Containers to add to the block-builder pods
1006 # -- updateStrategy of the block-builder StatefulSet
1010 # -- Pod Disruption Budget configuration
1011 podDisruptionBudget:
1012 # -- Enable PodDisruptionBudget for block-builder
1014 # -- Set unhealthyPodEvictionPolicy for the block-builder PodDisruptionBudget. Requires policy/v1.
1015 unhealthyPodEvictionPolicy: ""
1016 # -- Pod Disruption Budget maxUnavailable
1019 # -- Annotations for block-builder service
1022 # -- Number of Kafka partitions each block-builder instance consumes.
1023 # Each pod consumes this many partitions starting from its ordinal * partitions_per_instance.
1024 partitions_per_instance: 1
1025# Configuration for the live-store (Tempo 3.0+)
1026# Consumes spans from Kafka and serves recent-data queries (last ~30 minutes).
1027# One replica per Kafka partition — replica count must equal ingest.kafka.auto_create_topic_default_partitions.
1029 # -- Enable the live-store. Requires ingest.kafka.address to be set.
1031 # -- Number of replicas. Must equal the Kafka partition count.
1033 # -- Annotations for the live-store StatefulSet
1035 # -- Labels for the live-store StatefulSet
1037 # -- hostAliases to add
1039 # -- Pod DNS config for this component. Falls back to `defaults.dnsConfig`, then `tempo.dnsConfig`.
1041 # -- Init containers to add to the live-store pod
1044 # -- The Docker registry for the live-store image. Overrides `tempo.image.registry`
1046 # -- Optional list of imagePullSecrets. Overrides `tempo.image.pullSecrets`
1048 # -- Docker image repository for the live-store image. Overrides `tempo.image.repository`
1050 # -- Docker image tag for the live-store image. Overrides `tempo.image.tag`
1052 # -- The name of the PriorityClass for live-store pods
1053 priorityClassName: null
1054 # -- Labels for live-store pods
1056 # -- Annotations for live-store pods
1058 # -- Additional CLI args for the live-store
1060 # -- Environment variables to add to the live-store pods
1062 # -- Environment variables from secrets or configmaps to add to the live-store pods
1064 # -- Additional ports to expose on the live-store container
1066 # -- Liveness probe for live-store pods. Uses `tempo.livenessProbe` as default if not set.
1068 # -- Readiness probe for live-store pods. Uses `tempo.readinessProbe` as default if not set.
1070 # -- Startup probe for live-store pods. Uses `tempo.startupProbe` as default if not set.
1072 # -- Resource requests and limits for the live-store
1074 # -- Grace period to allow the live-store to shut down before being killed
1075 terminationGracePeriodSeconds: 60
1076 # -- topologySpread for live-store pods. Passed through `tpl`.
1077 topologySpreadConstraints: |
1079 topologyKey: topology.kubernetes.io/zone
1080 whenUnsatisfiable: ScheduleAnyway
1083 {{- include "tempo.selectorLabels" (dict "ctx" . "component" "live-store") | nindent 6 }}
1084 # -- Affinity for live-store pods. Passed through `tpl`.
1087 preferredDuringSchedulingIgnoredDuringExecution:
1092 {{- include "tempo.selectorLabels" (dict "ctx" . "component" "live-store") | nindent 12 }}
1093 topologyKey: kubernetes.io/hostname
1094 # -- Node selector for live-store pods
1096 # -- Tolerations for live-store pods
1098 # -- Extra volumes for live-store pods
1099 extraVolumeMounts: []
1100 # -- Extra volumes for live-store StatefulSet
1102 # -- Containers to add to the live-store pods
1104 # -- updateStrategy of the live-store StatefulSet
1108 # -- Persistence configuration for live-store
1110 # -- Enable creating PVCs for the live-store data volume. The WAL and local
1111 # blocks then survive a restart, so the live-store resumes from its committed
1112 # Kafka offset (never further back than 2 x complete_block_timeout) instead of
1113 # re-reading that whole window, as it must when it starts with no local data.
1115 # -- Enable StatefulSetRecreation for changes to PVC size
1116 enableStatefulSetRecreationForSizeChange: false
1117 # -- use emptyDir with ramdisk instead of PVC. **Please note that all data in live-store will be lost on pod restart**
1119 # -- Size of persistent or memory disk
1121 # -- Storage class to be used.
1122 # If defined, storageClassName: <storageClass>.
1123 # If set to "-", storageClassName: "", which disables dynamic provisioning.
1124 # If empty or set to null, no storageClassName spec is
1125 # set, choosing the default provisioner (gp2 on AWS, standard on GKE, AWS, and OpenStack).
1127 # -- Annotations for live-store's persist volume claim
1129 # -- Labels for live-store's persist volume claim
1131 # -- Spec for the `data` volume when persistence is disabled. By default an
1132 # empty `emptyDir: {}`; set e.g. `sizeLimit` or `medium: Memory` as needed.
1134 # Note: the retained volume also holds the live-store's shutdown marker
1135 # (`/var/tempo/live-store/shutdown-marker`). It is removed on a graceful shutdown,
1136 # but if a pod is force-killed after the rollout-operator has called
1137 # `prepare-downscale` (grace period exceeded, OOMKill, node loss), a stale marker
1138 # is left on the volume. On scale-up that pod then starts with
1139 # `create-partition-on-startup=false` and its partition will not become ACTIVE, so
1140 # it takes no writes. If a scaled-up live-store never becomes ready, or its
1141 # partition stays INACTIVE, remove the shutdown marker from its PVC or call
1142 # `DELETE /live-store/prepare-downscale` on it.
1143 persistentVolumeClaimRetentionPolicy:
1144 # -- Enable Persistent volume retention policy for the live-store StatefulSet
1146 # -- Volume retention behaviour when the StatefulSet replica count is reduced
1148 # -- Volume retention behaviour when the StatefulSet is deleted
1150 # Zone-aware replication spreads the live-stores over failure domains such as
1151 # availability zones, racks or data centres. Every zone runs a full set of
1152 # live-stores, so each Kafka partition gets one owner per zone (RF equals the
1153 # number of zones). The read quorum is 1: a querier only needs an answer from
1154 # one zone, so recent-trace queries survive the loss of a zone.
1155 # Requires `rollout_operator.enabled: true`.
1156 zoneAwareReplication:
1157 # -- Enable zone-aware replication for the live-store
1159 # -- Set to true when a rollout-operator already runs in this namespace and is
1160 # not installed by this chart. Skips the `rollout_operator.enabled` check.
1161 rolloutOperatorManagedExternally: false
1162 # -- Topology key of the failure domain. When set, the live-stores of one zone
1163 # never share a domain with the live-stores of another zone. The cluster must
1164 # hold at least as many domains as there are zones, otherwise the extra zones
1165 # stay unschedulable. With neither this nor a `nodeSelector` on every zone,
1166 # the zones still give separate pods and one partition owner each, but two
1167 # zones can share a failure domain.
1169 # -- Maximum number of live-stores the rollout-operator restarts at the same
1170 # time inside one zone. The rollout-operator always moves one zone at a time.
1171 # A zone with fewer live-stores than this restarts as a whole, which the read
1172 # quorum of 1 covers, at the cost of the read capacity of that zone.
1174 # -- Reject every scale-down of the live-stores. The live-store count must
1175 # match the Kafka partition count, so an accidental scale-down drops the
1176 # recent-read tier of the partitions that go away. Needs the rollout-operator
1177 # webhooks. Cannot be combined with `prepareDownscale.enabled`.
1179 # Coordinated scale-down through the rollout-operator admission webhook. It
1180 # guards a lower `liveStore.replicas`, which retires the last Kafka
1181 # partitions. On such a scale-down the webhook calls `httpPath` on every
1182 # live-store that goes away, which moves its partition to INACTIVE and stops
1183 # the writes to it. The webhook then rejects the scale-down of a second zone
1184 # until `minTimeBetweenZonesDownscale` has passed, so the zones go down one
1185 # at a time. A rejected scale-down fails the `helm upgrade`: wait for the
1186 # window, then run the upgrade again.
1188 # The webhook is the only mechanism the chart uses, so a pod stops as soon
1189 # as its partition is INACTIVE. The remaining zones still own that partition
1190 # and still hold its recent traces, which is what keeps the read path whole
1191 # until the last zone goes down. Do not remove a zone from the `zones` list
1192 # in the same step: that deletes the StatefulSet, which the webhook never
1195 # -- Enable the coordinated scale-down
1197 # -- Minimum time between the scale-down of two zones. Must be longer than
1198 # the period a live-store still serves recent traces, because the last
1199 # zone to go down takes the last owner of the retired partitions with it.
1200 minTimeBetweenZonesDownscale: 12h
1201 # -- Endpoint the webhook calls on every live-store that goes away. Must
1202 # accept a POST while the partition is still ACTIVE.
1203 # `live-store/prepare-downscale` does not: it answers 409 until the
1204 # partition is INACTIVE, so it needs the delayed-downscale mechanism of
1205 # the rollout-operator, which this chart does not configure.
1206 httpPath: live-store/prepare-partition-downscale
1207 # Voluntary evictions of zone-aware live-stores, through the
1208 # ZoneAwarePodDisruptionBudget of the rollout-operator. A native
1209 # PodDisruptionBudget counts pods, so it cannot tell that the same pod
1210 # ordinal in two zones holds every owner of one partition. This one counts
1211 # per partition across zones and rejects an eviction that would take the
1212 # last owner, whatever the budget of a single zone allows.
1214 # Needs the ZoneAwarePodDisruptionBudget CRD and the pod eviction webhook of
1215 # the rollout-operator. The bundled subchart installs both. The webhook
1216 # rejects an eviction while the rollout-operator is unreachable, so this
1217 # never opens a window. While this is on, it replaces the
1218 # `liveStore.podDisruptionBudget` object.
1219 podDisruptionBudget:
1220 # -- Guard the evictions with a ZoneAwarePodDisruptionBudget. Set to false
1221 # to keep a single native PodDisruptionBudget over all zones instead.
1223 # -- Live-stores of one partition that may be unavailable at the same
1224 # time, counted over every zone. 1 keeps a partition served through any
1225 # single voluntary eviction. 0 rejects every voluntary eviction.
1227 # -- Regular expression that returns the partition of a live-store from
1228 # its pod name. The rollout-operator anchors it with `^` and `$`, so it
1229 # must match the whole name. The default reads the pod ordinal, which is
1230 # the Kafka partition, and holds for any zone name.
1231 podNamePartitionRegex: ".*-([0-9]+)"
1232 # -- Capture group of the partition. Only needed when
1233 # `podNamePartitionRegex` holds more than one group.
1234 podNameRegexGroup: null
1235 # -- Minimum time after a live-store becomes ready before another owner of
1236 # the same partition may be evicted. A Go duration, so days are not a
1237 # unit. Set this when the live-stores run with the default
1238 # `readiness-target-lag` of 0, because a live-store then reports ready
1239 # while it still replays its partition.
1240 crossZoneEvictionDelay: null
1241 # -- Zones to deploy. At least 2 zones are required. Every zone runs
1242 # `liveStore.replicas` live-stores. A zone name must be a DNS label: it
1243 # becomes a StatefulSet name suffix and the value of the zone label.
1246 # -- Node selector for the live-stores of this zone. Merged on top of
1247 # `liveStore.nodeSelector`, or of `defaults.nodeSelector`.
1249 # -- Extra affinity for the live-stores of this zone. Merged on top of
1250 # `liveStore.affinity`. The zone anti-affinity of `topologyKey`
1251 # overwrites a `podAntiAffinity` here.
1253 # -- Extra annotations for the StatefulSet of this zone
1255 # -- Extra annotations for the pods of this zone
1262 # -- Pod Disruption Budget configuration
1263 podDisruptionBudget:
1264 # -- Enable PodDisruptionBudget for live-store
1266 # -- Set unhealthyPodEvictionPolicy for the live-store PodDisruptionBudget. Requires policy/v1.
1267 unhealthyPodEvictionPolicy: ""
1268 # -- Pod Disruption Budget maxUnavailable. With zone-aware replication the
1269 # budget covers the live-stores of every zone together, because the same pod
1270 # ordinal in two zones holds every owner of one partition.
1273 # -- Annotations for live-store service
1275 # -- Extra live-store configuration. Merged verbatim into the `live_store:` config block.
1276 # See https://grafana.com/docs/tempo/latest/configuration/#live-store for available fields.
1281# Configuration for the querier
1283 # -- Number of replicas for the querier
1285 # -- hostAliases to add
1290 # -- Pod DNS config for this component. Falls back to `defaults.dnsConfig`, then `tempo.dnsConfig`.
1292 # -- Annotations for querier deployment
1295 # -- Enable autoscaling for the querier
1297 # -- Minimum autoscaling replicas for the querier
1299 # -- Maximum autoscaling replicas for the querier
1301 # -- Autoscaling behavior configuration for the querier
1303 # -- Target CPU utilisation percentage for the querier
1304 targetCPUUtilizationPercentage: 60
1305 # -- Target memory utilisation percentage for the querier
1306 targetMemoryUtilizationPercentage:
1308 # -- The Docker registry for the querier image. Overrides `tempo.image.registry`
1310 # -- Optional list of imagePullSecrets. Overrides `tempo.image.pullSecrets`
1312 # -- Docker image repository for the querier image. Overrides `tempo.image.repository`
1314 # -- Docker image tag for the querier image. Overrides `tempo.image.tag`
1316 # -- The name of the PriorityClass for querier pods
1317 priorityClassName: null
1318 # -- Labels for querier pods
1320 # -- Annotations for querier pods
1322 # -- Additional CLI args for the querier
1324 # -- Environment variables to add to the querier pods
1326 # -- Environment variables from secrets or configmaps to add to the querier pods
1328 # -- Liveness probe for querier pods. Uses `tempo.livenessProbe` as default if not set.
1330 # -- Readiness probe for querier pods. Uses `tempo.readinessProbe` as default if not set.
1332 # -- Startup probe for querier pods. Uses `tempo.startupProbe` as default if not set.
1334 # -- Resource requests and limits for the querier
1336 # -- Grace period to allow the querier to shutdown before it is killed
1337 terminationGracePeriodSeconds: 30
1338 # -- topologySpread for querier pods. Passed through `tpl` and, thus, to be configured as string
1339 # @default -- Defaults to allow skew no more then 1 node per AZ
1340 topologySpreadConstraints: |
1342 topologyKey: topology.kubernetes.io/zone
1343 whenUnsatisfiable: ScheduleAnyway
1346 {{- include "tempo.selectorLabels" (dict "ctx" . "component" "querier") | nindent 6 }}
1347 # -- Affinity for querier pods. Passed through `tpl` and, thus, to be configured as string
1348 # @default -- Hard node and soft zone anti-affinity
1351 requiredDuringSchedulingIgnoredDuringExecution:
1354 {{- include "tempo.selectorLabels" (dict "ctx" . "component" "querier" "memberlist" true) | nindent 10 }}
1355 topologyKey: kubernetes.io/hostname
1356 preferredDuringSchedulingIgnoredDuringExecution:
1361 {{- include "tempo.selectorLabels" (dict "ctx" . "component" "querier" "memberlist" true) | nindent 12 }}
1362 topologyKey: topology.kubernetes.io/zone
1363 # -- Pod Disruption Budget configuration
1364 podDisruptionBudget:
1365 # -- Enable PodDisruptionBudget for querier
1367 # -- Set unhealthyPodEvictionPolicy for the querier PodDisruptionBudget. Requires policy/v1.
1368 unhealthyPodEvictionPolicy: ""
1369 # -- Pod Disruption Budget maxUnavailable
1371 # -- Max Surge for querier pods
1374 # -- Maximum number of Pods that can be unavailable during the update process
1376 # -- Minimum number of seconds for which a newly created Pod should be ready without any of its containers crashing/terminating
1378 # -- Node selector for querier pods
1380 # -- Tolerations for querier pods
1382 # -- Init containers for the querier pod
1384 # -- Containers to add to the querier pods
1386 # -- Additional ports to expose on the querier container.
1387 # Standard ports (http-metrics, http-memberlist) are always added automatically.
1389 # -- Extra volumes for querier pods
1390 extraVolumeMounts: []
1391 # -- Extra volumes for querier deployment
1395 # -- gRPC client configuration
1396 grpc_client_config: {}
1398 # -- Timeout for trace lookup requests
1401 # -- Timeout for search requests
1403 # -- This value controls the overall number of simultaneous subqueries that the querier will service at once. It does not distinguish between the types of queries.
1404 max_concurrent_queries: 20
1406 # -- Annotations for querier service
1408 # -- Traffic distribution for the querier service (PreferSameZone or PreferSameNode). Overrides tempo.service.trafficDistribution.
1409 trafficDistribution: null
1410 # -- Adds the appProtocol field to the querier service. This allows querier to work with istio protocol selection.
1412 # -- Set the optional gRPC service protocol. Ex: "grpc", "http2" or "https"
1414# Configuration for the query-frontend
1417 # -- Required for grafana version <7.5 for compatibility with jaeger-ui. Doesn't work on ARM arch
1420 # -- The Docker registry for the tempo-query image. Overrides `tempo.image.registry`
1422 # -- Optional list of imagePullSecrets. Overrides `tempo.image.pullSecrets`
1424 # -- Docker image repository for the tempo-query image. Overrides `tempo.image.repository`
1425 repository: grafana/tempo-query
1426 # -- Docker image tag for the tempo-query image. Overrides `tempo.image.tag`
1428 # -- Resource requests and limits for the query
1430 # -- Additional CLI args for tempo-query pods
1432 # -- Environment variables to add to the tempo-query pods
1434 # -- Environment variables from secrets or configmaps to add to the tempo-query pods
1436 # -- Extra volumes for tempo-query pods
1437 extraVolumeMounts: []
1438 # -- Extra volumes for tempo-query deployment
1441 backend: 127.0.0.1:3200
1442 # -- Number of replicas for the query-frontend
1444 # -- Annotations for the query-frontend Deployment
1446 # -- hostAliases to add
1451 # -- Pod DNS config for this component. Falls back to `defaults.dnsConfig`, then `tempo.dnsConfig`.
1454 # -- Maximum number of outstanding requests per tenant per frontend; requests beyond this error with HTTP 429.
1455 max_outstanding_per_tenant: 2000
1456 # -- Number of times to retry a request sent to a querier
1459 # -- The number of concurrent jobs to execute when searching the backend
1460 concurrent_jobs: 1000
1461 # -- The target number of bytes for each job to handle when performing a backend search
1462 target_bytes_per_job: 104857600
1463 # -- The maximum allowed value of spans per span set. 0 disables this limit.
1464 max_spans_per_span_set: 100
1465 # -- The maximum allowed value for the limit parameter on search requests. 0 disables this limit.
1466 # max_result_limit: 262144 maximum number of results returned by search requests
1467 # -- Trace by ID lookup configuration
1469 # -- The number of shards to split a trace by ID query into.
1472 # -- The number of concurrent jobs to execute when querying the backend.
1473 concurrent_jobs: 1000
1474 # -- The target number of bytes for each job to handle when querying the backend.
1475 target_bytes_per_job: 104857600
1476 # -- The maximum allowed time range for a metrics query.
1477 # 0 disables this limit.
1479 # -- query_backend_after controls where the query-frontend searches for traces.
1480 # Time ranges newer than query_backend_after will be searched in the live-stores only.
1481 # Time ranges older than query_backend_after will be searched in the backend/object storage only.
1482 query_backend_after: 15m
1483 # -- The target length of time for each job to handle when querying the backend.
1485 # -- If set to a non-zero value, it's value will be used to decide if query is within SLO or not.
1486 # Query is within SLO if it returned 200 within duration_slo seconds OR processed throughput_slo bytes/s data.
1487 # NOTE: `duration_slo` and `throughput_bytes_slo` both must be configured for it to work
1489 # -- If set to a non-zero value, it's value will be used to decide if query is within SLO or not.
1490 # Query is within SLO if it returned 200 within duration_slo seconds OR processed throughput_slo bytes/s data.
1491 throughput_bytes_slo: 0
1493 # -- Enable autoscaling for the query-frontend
1495 # -- Minimum autoscaling replicas for the query-frontend
1497 # -- Maximum autoscaling replicas for the query-frontend
1499 # -- Autoscaling behavior configuration for the query-frontend
1501 # -- Target CPU utilisation percentage for the query-frontend
1502 targetCPUUtilizationPercentage: 60
1503 # -- Target memory utilisation percentage for the query-frontend
1504 targetMemoryUtilizationPercentage:
1506 # -- The Docker registry for the query-frontend image. Overrides `tempo.image.registry`
1508 # -- Optional list of imagePullSecrets. Overrides `tempo.image.pullSecrets`
1510 # -- Docker image repository for the query-frontend image. Overrides `tempo.image.repository`
1512 # -- Docker image tag for the query-frontend image. Overrides `tempo.image.tag`
1515 # -- Port of the query-frontend service
1517 # -- http Metrics port of the query-frontend service
1518 httpMetricsPort: 3200
1519 # -- gRPC Port of the query-frontend service
1521 # -- Annotations for queryFrontend service
1523 # -- Labels for queryFrontend service
1525 # -- Type of service for the queryFrontend
1527 # -- Traffic distribution for the queryFrontend service (PreferSameZone or PreferSameNode). Overrides tempo.service.trafficDistribution.
1528 trafficDistribution: null
1529 # -- If type is LoadBalancer you can assign the IP to the LoadBalancer
1531 # -- If type is LoadBalancer limit incoming traffic from IPs.
1532 loadBalancerSourceRanges: []
1534 # -- Annotations for queryFrontendDiscovery service
1536 # -- Labels for queryFrontendDiscovery service
1539 # -- Specifies whether an ingress for the Jaeger should be created
1541 # -- Ingress Class Name. MAY be required for Kubernetes versions >= 1.18
1542 # ingressClassName: nginx
1543 # -- Annotations for the Jaeger ingress
1545 # -- Hosts configuration for the Jaeger ingress
1547 - host: query.tempo.example.com
1550 # -- pathType (e.g. ImplementationSpecific, Prefix, .. etc.) might also be required by some Ingress Controllers
1552 # -- TLS configuration for the Jaeger ingress
1554 - secretName: tempo-query-tls
1556 - query.tempo.example.com
1557 # -- Gateway API route configuration for the query-frontend (Jaeger UI).
1558 # Multiple routes can be added by adding a dictionary key like the 'main' route.
1561 # -- Specifies whether a Gateway API route for the query-frontend should be created
1563 # -- Set the route apiVersion, e.g. gateway.networking.k8s.io/v1 or gateway.networking.k8s.io/v1beta1
1564 # If not set, the latest available version will be auto-detected
1566 # -- Set the route kind
1567 # Valid options are GRPCRoute, HTTPRoute, TCPRoute, TLSRoute, UDPRoute
1569 # -- Route annotations
1573 # -- Hostnames for the route
1575 # - query.tempo.example.com
1576 # -- Parent references (gateway to attach to)
1578 # - name: my-gateway
1579 # namespace: gateway-namespace
1580 # -- Matches define conditions for matching incoming requests
1585 # -- Timeouts define the timeouts that can be configured for an HTTP request.
1586 # Ref. https://gateway-api.sigs.k8s.io/api-types/httproute/#timeouts-optional
1588 # -- Filters define the filters that are applied to requests that match this rule.
1590 # -- Additional custom rules that can be added to the route
1592 # -- The name of the PriorityClass for query-frontend pods
1593 priorityClassName: null
1594 # -- Labels for queryFrontend pods
1596 # -- Annotations for query-frontend pods
1598 # -- Additional CLI args for the query-frontend
1600 # -- Environment variables to add to the query-frontend pods
1602 # -- Environment variables from secrets or configmaps to add to the query-frontend pods
1604 # -- Liveness probe for query-frontend pods. Uses `tempo.livenessProbe` as default if not set.
1606 # -- Readiness probe for query-frontend pods. Uses `tempo.readinessProbe` as default if not set.
1608 # -- Startup probe for query-frontend pods. Uses `tempo.startupProbe` as default if not set.
1610 # -- Resource requests and limits for the query-frontend
1612 # -- Grace period to allow the query-frontend to shutdown before it is killed
1613 terminationGracePeriodSeconds: 30
1614 # -- topologySpread for query-frontend pods. Passed through `tpl` and, thus, to be configured as string
1615 # @default -- Defaults to allow skew no more then 1 node per AZ
1616 topologySpreadConstraints: |
1618 topologyKey: topology.kubernetes.io/zone
1619 whenUnsatisfiable: ScheduleAnyway
1622 {{- include "tempo.selectorLabels" (dict "ctx" . "component" "query-frontend") | nindent 6 }}
1623 # -- Affinity for query-frontend pods. Passed through `tpl` and, thus, to be configured as string
1624 # @default -- Hard node and soft zone anti-affinity
1627 requiredDuringSchedulingIgnoredDuringExecution:
1630 {{- include "tempo.selectorLabels" (dict "ctx" . "component" "query-frontend") | nindent 10 }}
1631 topologyKey: kubernetes.io/hostname
1632 preferredDuringSchedulingIgnoredDuringExecution:
1637 {{- include "tempo.selectorLabels" (dict "ctx" . "component" "query-frontend") | nindent 12 }}
1638 topologyKey: topology.kubernetes.io/zone
1639 # -- Pod Disruption Budget configuration
1640 podDisruptionBudget:
1641 # -- Enable PodDisruptionBudget for query-frontend
1643 # -- Set unhealthyPodEvictionPolicy for the query-frontend PodDisruptionBudget. Requires policy/v1.
1644 unhealthyPodEvictionPolicy: ""
1645 # -- Pod Disruption Budget maxUnavailable
1647 # -- Minimum number of seconds for which a newly created Pod should be ready without any of its containers crashing/terminating
1649 # -- Node selector for query-frontend pods
1651 # -- Tolerations for query-frontend pods
1653 # -- Init containers for the query-frontend pod
1655 # -- Containers to add to the query-frontend pods
1657 # -- Additional ports to expose on the query-frontend container.
1658 # The gRPC port is included by default. Standard ports (http-metrics, http-memberlist)
1659 # are always added automatically by the pod template.
1661 - containerPort: 9095
1664 # -- Extra volumes for query-frontend pods
1665 extraVolumeMounts: []
1666 # -- Extra volumes for query-frontend deployment
1668 # -- Adds the appProtocol field to the queryFrontend service. This allows queryFrontend to work with istio protocol selection.
1670 # -- Set the optional gRPC service protocol. Ex: "grpc", "http2" or "https"
1673 # -- Enables Tempo MCP Server
1675# Configuration for the federation-frontend
1676# Can only be enabled if enterprise.enabled is true - requires license.
1677enterpriseFederationFrontend:
1678 # -- Specifies whether a federation-frontend should be deployed
1680 # -- Number of replicas for the federation-frontend
1682 # -- Annotations for the federation-frontend Deployment
1684 # -- hostAliases to add
1690 # - name: own-data-center
1691 # url: http://get/tempo
1692 # - name: grafana-cloud
1693 # url: https://tempo-us-central1.grafana.net/tempo
1695 # username: <instance-id>
1698 # -- Enable autoscaling for the federation-frontend
1700 # -- Minimum autoscaling replicas for the federation-frontend
1702 # -- Maximum autoscaling replicas for the federation-frontend
1704 # -- Target CPU utilisation percentage for the federation-frontend
1705 targetCPUUtilizationPercentage: 60
1706 # -- Target memory utilisation percentage for the federation-frontend
1707 targetMemoryUtilizationPercentage:
1709 # -- The Docker registry for the federation-frontend image. Overrides `tempo.image.registry`
1711 # -- Optional list of imagePullSecrets. Overrides `tempo.image.pullSecrets`
1713 # -- Docker image repository for the federation-frontend image. Overrides `tempo.image.repository`
1715 # -- Docker image tag for the federation-frontend image. Overrides `tempo.image.tag`
1718 # -- Port of the federation-frontend service
1720 # -- Annotations for enterpriseFederationFrontend service
1722 # -- Type of service for the enterpriseFederationFrontend
1724 # -- If type is LoadBalancer you can assign the IP to the LoadBalancer
1726 # -- If type is LoadBalancer limit incoming traffic from IPs.
1727 loadBalancerSourceRanges: []
1728 # -- The name of the PriorityClass for federation-frontend pods
1729 priorityClassName: null
1730 # -- Labels for enterpriseFederationFrontend pods
1732 # -- Annotations for federation-frontend pods
1734 # -- Additional CLI args for the federation-frontend
1736 # -- Environment variables to add to the federation-frontend pods
1738 # -- Environment variables from secrets or configmaps to add to the federation-frontend pods
1740 # -- Resource requests and limits for the federation-frontend
1742 # -- Grace period to allow the federation-frontend to shutdown before it is killed
1743 terminationGracePeriodSeconds: 30
1744 # -- topologySpread for federation-frontend pods. Passed through `tpl` and, thus, to be configured as string
1745 # @default -- Defaults to allow skew no more then 1 node per AZ
1746 topologySpreadConstraints: |
1748 topologyKey: failure-domain.beta.kubernetes.io/zone
1749 whenUnsatisfiable: ScheduleAnyway
1752 {{- include "tempo.selectorLabels" (dict "ctx" . "component" "federation-frontend") | nindent 6 }}
1753 # -- Affinity for federation-frontend pods. Passed through `tpl` and, thus, to be configured as string
1754 # @default -- Hard node and soft zone anti-affinity
1757 requiredDuringSchedulingIgnoredDuringExecution:
1760 {{- include "tempo.selectorLabels" (dict "ctx" . "component" "federation-frontend") | nindent 10 }}
1761 topologyKey: kubernetes.io/hostname
1762 preferredDuringSchedulingIgnoredDuringExecution:
1767 {{- include "tempo.selectorLabels" (dict "ctx" . "component" "federation-frontend") | nindent 12 }}
1768 topologyKey: failure-domain.beta.kubernetes.io/zone
1769 # -- Pod Disruption Budget configuration
1770 podDisruptionBudget:
1771 # -- Enable PodDisruptionBudget for enterprise-federation-frontend
1773 # -- Pod Disruption Budget maxUnavailable
1775 # -- Node selector for federation-frontend pods
1777 # -- Tolerations for federation-frontend pods
1779 # -- Extra volumes for federation-frontend pods
1780 extraVolumeMounts: []
1781 # -- Extra volumes for federation-frontend deployment
1783multitenancyEnabled: false
1785 # -- Enable rollout-operator. It must be enabled when using Zone Aware Replication.
1793 type: RuntimeDefault
1794 # Set the container security context
1796 readOnlyRootFilesystem: true
1799 allowPrivilegeEscalation: false
1803 # -- Enable Tempo to ingest Jaeger gRPC traces
1805 # -- Jaeger gRPC receiver config
1808 # -- Enable Tempo to ingest Jaeger Thrift Binary traces
1810 # -- Jaeger Thrift Binary receiver config
1813 # -- Enable Tempo to ingest Jaeger Thrift Compact traces
1815 # -- Jaeger Thrift Compact receiver config
1818 # -- Enable Tempo to ingest Jaeger Thrift HTTP traces
1820 # -- Jaeger Thrift HTTP receiver config
1823 # -- Enable Tempo to ingest Zipkin traces
1825 # -- Zipkin receiver config
1829 # -- Enable Tempo to ingest Open Telemetry HTTP traces
1831 # -- HTTP receiver advanced config
1834 # -- Enable Tempo to ingest Open Telemetry gRPC traces
1836 # -- gRPC receiver advanced config
1838 # -- Default OTLP gRPC port
1840 # -- Enable Tempo to ingest traces from Kafka. Reference: https://github.com/open-telemetry/opentelemetry-collector-contrib/tree/main/receiver/kafkareceiver
1842# -- Memberlist configuration. Please refer to https://grafana.com/docs/tempo/latest/configuration/#memberlist
1845 cluster_label: "{{ .Release.Name }}.{{ .Release.Namespace }}"
1846 randomize_node_name: true
1847 stream_timeout: "10s"
1848 retransmit_factor: 2
1849 pull_push_interval: "30s"
1850 gossip_interval: "1s"
1852 gossip_to_dead_nodes_time: "30s"
1853 min_join_backoff: "1s"
1854 max_join_backoff: "1m"
1855 max_join_retries: 10
1856 abort_if_cluster_join_fails: false
1857 rejoin_interval: "0s"
1858 left_ingesters_timeout: "5m"
1862 packet_dial_timeout: "5s"
1863 packet_write_timeout: "5s"
1864# -- Config file contents for Tempo distributed. Passed through the `tpl` function to allow templating
1866# @default -- See values.yaml
1868 multitenancy_enabled: {{ .Values.multitenancyEnabled }}
1870 stream_over_http_enabled: {{ .Values.streamOverHTTPEnabled }}
1873 reporting_enabled: {{ .Values.reportingEnabled }}
1875 {{- if .Values.enterprise.enabled }}
1877 path: "/license/license.jwt"
1889 http_api_prefix: {{get .Values.tempo.structuredConfig "http_api_prefix"}}
1893 backend: {{.Values.storage.admin.backend}}
1894 {{- if eq .Values.storage.admin.backend "s3"}}
1896 {{- toYaml .Values.storage.admin.s3 | nindent 6}}
1898 {{- if eq .Values.storage.admin.backend "gcs"}}
1900 {{- toYaml .Values.storage.admin.gcs | nindent 6}}
1902 {{- if eq .Values.storage.admin.backend "azure"}}
1904 {{- toYaml .Values.storage.admin.azure | nindent 6}}
1906 {{- if eq .Values.storage.admin.backend "swift"}}
1908 {{- toYaml .Values.storage.admin.swift | nindent 6}}
1910 {{- if eq .Values.storage.admin.backend "filesystem"}}
1912 {{- toYaml .Values.storage.admin.filesystem | nindent 6}}
1916 {{- if and .Values.enterprise.enabled .Values.enterpriseGateway.useDefaultProxyURLs }}
1920 url: http://{{ template "tempo.fullname" . }}-admin-api.{{ .Release.Namespace }}.svc:{{ include "tempo.serverHttpListenPort" . }}
1921 {{- if .Values.backendScheduler.enabled }}
1923 url: http://{{ template "tempo.fullname" . }}-backend-worker.{{ .Release.Namespace }}.svc:{{ include "tempo.serverHttpListenPort" . }}
1926 url: http://{{ template "tempo.fullname" . }}-admin-api.{{ .Release.Namespace }}.svc:{{ include "tempo.serverHttpListenPort" . }}
1928 url: http://{{ template "tempo.fullname" . }}-distributor.{{ .Release.Namespace }}.svc:{{ include "tempo.serverHttpListenPort" . }}
1930 url: h2c://{{ template "tempo.fullname" . }}-distributor.{{ .Release.Namespace }}.svc:4317
1932 url: http://{{ template "tempo.fullname" . }}-distributor.{{ .Release.Namespace }}.svc:4318
1934 url: http://{{ template "tempo.fullname" . }}-querier.{{ .Release.Namespace }}.svc:{{ include "tempo.serverHttpListenPort" . }}
1936 url: http://{{ template "tempo.fullname" . }}-query-frontend.{{ .Release.Namespace }}.svc:{{ include "tempo.serverHttpListenPort" . }}{{get .Values.tempo.structuredConfig "http_api_prefix"}}
1938 {{- if and .Values.enterprise.enabled .Values.enterpriseGateway.proxy }}
1940 proxy: {{- toYaml .Values.enterpriseGateway.proxy | nindent 6 }}
1944 {{- if .Values.backendScheduler.enabled }}
1947 prune_age: {{ .Values.backendScheduler.config.work.prune_age }}
1948 dead_job_timeout: {{ .Values.backendScheduler.config.work.dead_job_timeout }}
1949 maintenance_interval: {{ .Values.backendScheduler.config.maintenance_interval }}
1950 backend_flush_interval: {{ .Values.backendScheduler.config.backend_flush_interval }}
1953 interval: {{ .Values.backendScheduler.config.provider.retention.interval }}
1956 block_retention: {{ .Values.backendScheduler.config.provider.compaction.compaction.block_retention }}
1957 compacted_block_retention: {{ .Values.backendScheduler.config.provider.compaction.compaction.compacted_block_retention }}
1958 compaction_cycle: {{ .Values.backendScheduler.config.provider.compaction.compaction.compaction_cycle }}
1959 compaction_window: {{ .Values.backendScheduler.config.provider.compaction.compaction.compaction_window }}
1960 max_block_bytes: {{ .Values.backendScheduler.config.provider.compaction.compaction.max_block_bytes }}
1961 max_compaction_objects: {{ .Values.backendScheduler.config.provider.compaction.compaction.max_compaction_objects }}
1962 max_time_per_tenant: {{ .Values.backendScheduler.config.provider.compaction.compaction.max_time_per_tenant }}
1963 retention_concurrency: {{ .Values.backendScheduler.config.provider.compaction.compaction.retention_concurrency }}
1964 max_jobs_per_tenant: {{ .Values.backendScheduler.config.provider.compaction.max_jobs_per_tenant }}
1965 min_input_blocks: {{ .Values.backendScheduler.config.provider.compaction.min_input_blocks }}
1966 max_input_blocks: {{ .Values.backendScheduler.config.provider.compaction.max_input_blocks }}
1967 max_compaction_level: {{ .Values.backendScheduler.config.provider.compaction.max_compaction_level }}
1968 min_cycle_interval: {{ .Values.backendScheduler.config.provider.compaction.min_cycle_interval }}
1969 job_timeout: {{ .Values.backendScheduler.config.job_timeout }}
1970 local_work_path: {{ .Values.backendScheduler.config.local_work_path }}
1972 {{- with .Values.backendWorker.config.backend_scheduler_client.grpc_client_config }}
1973 backend_scheduler_client:
1975 {{- toYaml . | nindent 6 }}
1979 backend_scheduler_addr: {{ include "tempo.resourceName" (dict "ctx" . "component" "backend-scheduler") }}:9095
1981 min_period: {{ .Values.backendWorker.config.backoff.min_period }}
1982 max_period: {{ .Values.backendWorker.config.backoff.max_period }}
1983 max_retries: {{ .Values.backendWorker.config.backoff.max_retries }}
1984 {{- $compaction_default := .Values.backendScheduler.config.provider.compaction.compaction }}
1985 {{- $worker_overrides := .Values.backendWorker.config.compaction }}
1986 {{- $compaction := mergeOverwrite (deepCopy $compaction_default) $worker_overrides }}
1988 {{- toYaml $compaction | nindent 6 }}
1989 finish_on_shutdown_timeout: {{ .Values.backendWorker.config.finish_on_shutdown_timeout }}
1994 {{- if .Values.blockBuilder.enabled }}
1996 partitions_per_instance: {{ .Values.blockBuilder.config.partitions_per_instance }}
1998 {{- if .Values.liveStore.enabled }}
2000 {{- with .Values.liveStore.config }}
2001 {{- toYaml . | nindent 4 }}
2004 {{- if and .Values.enterprise.enabled .Values.enterpriseFederationFrontend.enabled }}
2007 {{- toYaml .Values.enterpriseFederationFrontend.proxy_targets | nindent 6 }}
2009 {{- if .Values.metricsGenerator.enabled }}
2015 {{- toYaml .Values.metricsGenerator.config.processor | nindent 6 }}
2017 {{- toYaml .Values.metricsGenerator.config.storage | nindent 6 }}
2019 {{- toYaml .Values.metricsGenerator.config.registry | nindent 6 }}
2020 metrics_ingestion_time_range_slack: {{ .Values.metricsGenerator.config.metrics_ingestion_time_range_slack }}
2023 {{- if .Values.distributor.config.cost_attribution.enabled }}
2026 enabled: {{ .Values.distributor.config.cost_attribution.enabled }}
2027 max_cardinality: {{ .Values.distributor.config.cost_attribution.max_cardinality }}
2028 stale_duration: {{ .Values.distributor.config.cost_attribution.stale_duration }}
2034 {{- if or (.Values.traces.jaeger.thriftCompact.enabled) (.Values.traces.jaeger.thriftBinary.enabled) (.Values.traces.jaeger.thriftHttp.enabled) (.Values.traces.jaeger.grpc.enabled) }}
2037 {{- if .Values.traces.jaeger.thriftCompact.enabled }}
2039 {{- $mergedJaegerThriftCompactConfig := mustMergeOverwrite (dict "endpoint" "0.0.0.0:6831") .Values.traces.jaeger.thriftCompact.receiverConfig }}
2040 {{- toYaml $mergedJaegerThriftCompactConfig | nindent 10 }}
2042 {{- if .Values.traces.jaeger.thriftBinary.enabled }}
2044 {{- $mergedJaegerThriftBinaryConfig := mustMergeOverwrite (dict "endpoint" "0.0.0.0:6832") .Values.traces.jaeger.thriftBinary.receiverConfig }}
2045 {{- toYaml $mergedJaegerThriftBinaryConfig | nindent 10 }}
2047 {{- if .Values.traces.jaeger.thriftHttp.enabled }}
2049 {{- $mergedJaegerThriftHttpConfig := mustMergeOverwrite (dict "endpoint" "0.0.0.0:14268") .Values.traces.jaeger.thriftHttp.receiverConfig }}
2050 {{- toYaml $mergedJaegerThriftHttpConfig | nindent 10 }}
2052 {{- if .Values.traces.jaeger.grpc.enabled }}
2054 {{- $mergedJaegerGrpcConfig := mustMergeOverwrite (dict "endpoint" "0.0.0.0:14250") .Values.traces.jaeger.grpc.receiverConfig }}
2055 {{- toYaml $mergedJaegerGrpcConfig | nindent 10 }}
2058 {{- if .Values.traces.zipkin.enabled }}
2060 {{- $mergedZipkinReceiverConfig := mustMergeOverwrite (dict "endpoint" "0.0.0.0:9411") .Values.traces.zipkin.receiverConfig }}
2061 {{- toYaml $mergedZipkinReceiverConfig | nindent 6 }}
2063 {{- if or (.Values.traces.otlp.http.enabled) (.Values.traces.otlp.grpc.enabled) }}
2066 {{- if .Values.traces.otlp.http.enabled }}
2068 {{- $mergedOtlpHttpReceiverConfig := mustMergeOverwrite (dict "endpoint" "0.0.0.0:4318") .Values.traces.otlp.http.receiverConfig }}
2069 {{- toYaml $mergedOtlpHttpReceiverConfig | nindent 10 }}
2071 {{- if .Values.traces.otlp.grpc.enabled }}
2073 {{- $mergedOtlpGrpcReceiverConfig := mustMergeOverwrite (dict "endpoint" "0.0.0.0:4317") .Values.traces.otlp.grpc.receiverConfig }}
2074 {{- toYaml $mergedOtlpGrpcReceiverConfig | nindent 10 }}
2077 {{- if .Values.traces.kafka }}
2079 {{- toYaml .Values.traces.kafka | nindent 6 }}
2081 {{- if .Values.distributor.config.log_discarded_spans.enabled }}
2082 log_discarded_spans:
2083 enabled: {{ .Values.distributor.config.log_discarded_spans.enabled }}
2084 include_all_attributes: {{ .Values.distributor.config.log_discarded_spans.include_all_attributes }}
2085 filter_by_status_error: {{ .Values.distributor.config.log_discarded_spans.filter_by_status_error }}
2087 {{- if or .Values.distributor.config.log_received_traces .Values.distributor.config.log_received_spans.enabled }}
2089 enabled: {{ or .Values.distributor.config.log_received_traces .Values.distributor.config.log_received_spans.enabled }}
2090 include_all_attributes: {{ .Values.distributor.config.log_received_spans.include_all_attributes }}
2091 filter_by_status_error: {{ .Values.distributor.config.log_received_spans.filter_by_status_error }}
2093 {{- if .Values.distributor.config.extend_writes }}
2094 extend_writes: {{ .Values.distributor.config.extend_writes }}
2096 {{- if not (eq .Values.distributor.config.max_attribute_bytes nil) }}
2097 max_attribute_bytes: {{ .Values.distributor.config.max_attribute_bytes }}
2101 frontend_address: {{ include "tempo.resourceName" (dict "ctx" . "component" "query-frontend-discovery") }}:9095
2102 {{- if .Values.querier.config.frontend_worker.grpc_client_config }}
2104 {{- toYaml .Values.querier.config.frontend_worker.grpc_client_config | nindent 6 }}
2107 query_timeout: {{ .Values.querier.config.trace_by_id.query_timeout }}
2109 query_timeout: {{ .Values.querier.config.search.query_timeout }}
2110 max_concurrent_queries: {{ .Values.querier.config.max_concurrent_queries }}
2112 {{- if not .Values.enterprise.enabled }}
2114 enabled: {{ .Values.queryFrontend.mcp_server.enabled }}
2116 max_outstanding_per_tenant: {{ .Values.queryFrontend.config.max_outstanding_per_tenant }}
2117 max_retries: {{ .Values.queryFrontend.config.max_retries }}
2119 target_bytes_per_job: {{ .Values.queryFrontend.config.search.target_bytes_per_job }}
2120 concurrent_jobs: {{ .Values.queryFrontend.config.search.concurrent_jobs }}
2121 max_spans_per_span_set: {{ .Values.queryFrontend.config.search.max_spans_per_span_set }}
2122 {{- with .Values.queryFrontend.config.search.max_result_limit }}
2123 max_result_limit: {{ . }}
2126 query_shards: {{ .Values.queryFrontend.config.trace_by_id.query_shards }}
2128 concurrent_jobs: {{ .Values.queryFrontend.config.metrics.concurrent_jobs }}
2129 target_bytes_per_job: {{ .Values.queryFrontend.config.metrics.target_bytes_per_job }}
2130 max_duration: {{ .Values.queryFrontend.config.metrics.max_duration }}
2131 query_backend_after: {{ .Values.queryFrontend.config.metrics.query_backend_after }}
2132 interval: {{ .Values.queryFrontend.config.metrics.interval }}
2133 duration_slo: {{ .Values.queryFrontend.config.metrics.duration_slo }}
2134 throughput_bytes_slo: {{ .Values.queryFrontend.config.metrics.throughput_bytes_slo }}
2135 {{- with .Values.ingest.kafka.address }}
2139 topic: {{ $.Values.ingest.kafka.topic }}
2140 auto_create_topic_enabled: {{ $.Values.ingest.kafka.auto_create_topic_enabled }}
2141 auto_create_topic_default_partitions: {{ $.Values.ingest.kafka.auto_create_topic_default_partitions }}
2144 {{- with .Values.memberlist }}
2145 {{- toYaml . | nindent 2 }}
2148 - dns+{{ include "tempo.fullname" . }}-gossip-ring:{{ .Values.memberlist.bind_port }}
2150 {{- toYaml .Values.overrides | nindent 2 }}
2152 http_listen_port: {{ .Values.server.httpListenPort }}
2153 log_level: {{ .Values.server.logLevel }}
2154 log_format: {{ .Values.server.logFormat }}
2155 grpc_server_max_recv_msg_size: {{ .Values.server.grpc_server_max_recv_msg_size }}
2156 grpc_server_max_send_msg_size: {{ .Values.server.grpc_server_max_send_msg_size }}
2157 http_server_read_timeout: {{ .Values.server.http_server_read_timeout }}
2158 http_server_write_timeout: {{ .Values.server.http_server_write_timeout }}
2160 {{- include "tempo.cacheConfig" . | nindent 2}}
2163 {{- if .Values.storage.trace.block.version }}
2165 version: {{.Values.storage.trace.block.version}}
2166 {{- if .Values.storage.trace.block.dedicated_columns}}
2167 parquet_dedicated_columns:
2168 {{ .Values.storage.trace.block.dedicated_columns | toYaml | nindent 8}}
2172 max_workers: {{ .Values.storage.trace.pool.max_workers }}
2173 queue_depth: {{ .Values.storage.trace.pool.queue_depth }}
2174 backend: {{.Values.storage.trace.backend}}
2175 {{- if eq .Values.storage.trace.backend "s3"}}
2177 {{- toYaml .Values.storage.trace.s3 | nindent 6}}
2179 {{- if eq .Values.storage.trace.backend "gcs"}}
2181 {{- toYaml .Values.storage.trace.gcs | nindent 6}}
2183 {{- if eq .Values.storage.trace.backend "azure"}}
2185 {{- toYaml .Values.storage.trace.azure | nindent 6}}
2189 path: /var/tempo/traces
2191 path: /var/tempo/wal
2193 {{- toYaml .Values.storage.trace.search | nindent 6}}
2195 {{- if .Values.storage.trace.blocklist_poll }}
2196 blocklist_poll: {{ .Values.storage.trace.blocklist_poll }}
2198 {{- if .Values.storage.trace.blocklist_poll_concurrency }}
2199 blocklist_poll_concurrency: {{ .Values.storage.trace.blocklist_poll_concurrency }}
2201 {{- if .Values.storage.trace.blocklist_poll_fallback }}
2202 blocklist_poll_fallback: {{ .Values.storage.trace.blocklist_poll_fallback }}
2204 {{- if .Values.storage.trace.blocklist_poll_tenant_index_builders }}
2205 blocklist_poll_tenant_index_builders: {{ .Values.storage.trace.blocklist_poll_tenant_index_builders }}
2207 {{- if .Values.storage.trace.blocklist_poll_stale_tenant_index }}
2208 blocklist_poll_stale_tenant_index: {{ .Values.storage.trace.blocklist_poll_stale_tenant_index }}
2210 {{- if .Values.storage.trace.empty_tenant_deletion_age }}
2211 empty_tenant_deletion_age: {{ .Values.storage.trace.empty_tenant_deletion_age }}
2213 {{- if .Values.storage.trace.empty_tenant_deletion_enabled }}
2214 empty_tenant_deletion_enabled: {{ .Values.storage.trace.empty_tenant_deletion_enabled }}
2216# Set Tempo server configuration
2217# Refers to https://grafana.com/docs/tempo/latest/configuration/#server
2219 # -- HTTP server listen host
2220 httpListenPort: 3200
2221 # -- Log level. Can be set to debug, info (default), warn, error
2223 # -- Log format. Can be set to logfmt (default) or json.
2225 # -- Max gRPC message size that can be received
2226 grpc_server_max_recv_msg_size: 4194304
2227 # -- Max gRPC message size that can be sent
2228 grpc_server_max_send_msg_size: 4194304
2229 # -- Read timeout for HTTP server
2230 http_server_read_timeout: 30s
2231 # -- Write timeout for HTTP server
2232 http_server_write_timeout: 30s
2233# Use this block to configure caches available throughout the application.
2234# Multiple caches can be created and assigned roles which determine how they are used by Tempo.
2235# https://grafana.com/docs/tempo/latest/configuration/#cache
2236# When memcached.enabled is true (the default), the cache.caches list is auto-generated from the
2237# memcached and per-role memcached sections (memcachedBloom, memcachedParquetFooter, memcachedFrontendSearch).
2238# When memcached.enabled is false, this block is passed through verbatim to allow configuring external caches.
2242 host: '{{ include "tempo.fullname" . }}-memcached'
2243 service: memcached-client
2244 consistent_hash: true
2250# To configure a different storage backend instead of local storage:
2256# storage_account_name:
2257# storage_account_key:
2260 # Settings for the block storage backend and buckets.
2262 # -- The supported block versions are specified here https://grafana.com/docs/tempo/latest/configuration/parquet/
2264 # -- Lis with dedicated attribute columns (only for vParquet3 or later)
2265 dedicated_columns: []
2266 # -- The supported storage backends are gcs, s3 and azure, as specified in https://grafana.com/docs/tempo/latest/configuration/#storage
2268 # The worker pool is used primarily when finding traces by id, but is also used by others.
2270 # -- Total number of workers pulling jobs from the queue
2272 # -- Length of job queue. imporatant for querier as it queues a job for every block it has to search
2274 # The supported search are specified here https://grafana.com/docs/tempo/latest/configuration/#search-config
2276 # -- Number of traces to prefetch while scanning blocks. Increasing this value can improve trace search performance at the cost of memory.
2277 prefetch_trace_count: 1000
2278 # -- How often to repoll the backend for new blocks
2280 # -- Number of blocks to process in parallel during polling.
2281 blocklist_poll_concurrency: null
2282 # -- By default components will pull the blocklist from the tenant index. If that fails the component can
2283 # -- fallback to scanning the entire bucket. Set to false to disable this behavior.
2284 blocklist_poll_fallback: null
2285 # -- Maximum number of compactors that should build the tenant index. All other components will download the index.
2286 blocklist_poll_tenant_index_builders: null
2287 # -- The oldest allowable tenant index.
2288 blocklist_poll_stale_tenant_index: null
2289 # -- How fast the poller will delete a tenant if it is empty. Will need to be enabled in 'empty_tenant_deletion_enabled'.
2290 empty_tenant_deletion_age: null
2291 # -- Delete empty tenants.
2292 empty_tenant_deletion_enabled: null
2293 # Settings for the Admin client storage backend and buckets. Only valid is enterprise.enabled is true
2295 # -- The supported storage backends are gcs, s3 and azure, as specified in https://grafana.com/docs/enterprise-traces/latest/configure/reference/#admin_client_config
2297# -- The standard overrides configuration section. This can include a `defaults` object for applying to all tenants (not to be confused with the `global` property of the same name, which overrides `max_byte_per_trace` for all tenants). For an example on how to enable the metrics generator using the `overrides` object, see the 'Activate metrics generator' section below. Refer to [Standard overrides](https://grafana.com/docs/tempo/latest/configuration/#standard-overrides) for more details.
2299 # -- default config values for all tenants, can be overridden by per-tenant overrides. If a tenant's specific overrides are not found in the `per_tenant_overrides` block, the values in this `default` block will be used. Configs inside this block should follow the new overrides indentation format
2301 # -- Path to the per tenant override config file. The values of the `per_tenant_overrides` config below will be written to the default path which is `/runtime-config/overrides.yaml`. Users can set tenant-specific overrides settings in a separate file and point per_tenant_override_config to it if not using the per_tenant_overrides block below.
2302 per_tenant_override_config: /runtime-config/overrides.yaml
2303# -- The `per tenant` runtime overrides in place of the `per_tenant_override_config` file for Tempo (see `overrides` and the `per_tenant_override_config` property). This allows overriding the configs like `ingestion` and `global` values on a per-tenant basis. Note that *all* values must be given for each per-tenant configuration block. Refer to [Runtime overrides](https://grafana.com/docs/tempo/latest/configuration/#runtime-overrides) documentation for more details.
2304per_tenant_overrides:
2311# memcached is for all of the Tempo pieces to coordinate with each other.
2312# you can use your own self deployed memcached by setting `memcached.enabled` to false and `memcached.host` + `memcached.service`
2314 # -- Specified whether the memcached cachce should be enabled
2317 # -- The Docker registry for the Memcached image. Overrides `global.image.registry`
2319 # -- Optional list of imagePullSecrets. Overrides `global.image.pullSecrets`
2321 # -- Memcached Docker image repository
2322 repository: chainguard-private/memcached
2323 # -- Memcached Docker image tag
2324 tag: 1.6.45-r5@sha256:1c8af17d7a5ad133b93af700b90fd7da4be7be6f8b13a83757de5050072a58b6
2325 # -- Memcached Docker image pull policy
2326 pullPolicy: IfNotPresent
2328 # Number of replicas for memchached
2330 # -- Timeout for cache operations
2332 # -- Enable consistent hashing for cache
2333 consistentHash: true
2334 # -- Additional CLI args for memcached
2336 # -- Toleration for memcached pods
2338 # -- Environment variables to add to memcached pods
2340 # -- Environment variables from secrets or configmaps to add to memcached pods
2342 # -- Labels for memcached pods
2344 # -- Annotations for memcached pods
2346 # -- Resource requests and limits for memcached
2348 # -- topologySpread for memcached pods. Passed through `tpl` and, thus, to be configured as string
2349 # @default -- Defaults to allow skew no more than 1 node per AZ
2350 topologySpreadConstraints: |
2352 topologyKey: topology.kubernetes.io/zone
2353 whenUnsatisfiable: ScheduleAnyway
2356 {{- include "tempo.selectorLabels" (dict "ctx" . "component" "memcached") | nindent 6 }}
2357 # -- Affinity for memcached pods. Passed through `tpl` and, thus, to be configured as string
2358 # @default -- Hard node and soft zone anti-affinity
2361 requiredDuringSchedulingIgnoredDuringExecution:
2364 {{- include "tempo.selectorLabels" (dict "ctx" . "component" "memcached") | nindent 10 }}
2365 topologyKey: kubernetes.io/hostname
2366 preferredDuringSchedulingIgnoredDuringExecution:
2371 {{- include "tempo.selectorLabels" (dict "ctx" . "component" "memcached") | nindent 12 }}
2372 topologyKey: topology.kubernetes.io/zone
2373 # -- Pod Disruption Budget configuration
2374 podDisruptionBudget:
2375 # -- Enable PodDisruptionBudget for memcached
2377 # -- Set unhealthyPodEvictionPolicy for the memcached PodDisruptionBudget. Requires policy/v1.
2378 unhealthyPodEvictionPolicy: ""
2379 # -- Pod Disruption Budget maxUnavailable
2381 # -- Init containers for the memcached pod
2383 # -- Containers to add to the memcached pods
2385 # -- Extra volumes for memcached pods
2386 extraVolumeMounts: []
2387 # -- Extra volumes for memcached statefulSet
2390 # -- Annotations for memcached service
2392 # -- configuration for readiness probe for memcached statefulset
2396 initialDelaySeconds: 5
2401 # -- configuration for liveness probe for memcached statefulset
2403 initialDelaySeconds: 30
2409 # -- Specifies whether the Memcached Exporter should be enabled
2411 # -- hostAliases to add
2417 # -- The Docker registry for the Memcached Exporter image. Overrides `global.image.registry`
2419 # -- Optional list of imagePullSecrets. Overrides `global.image.pullSecrets`
2421 # -- Memcached Exporter Docker image repository
2422 repository: prom/memcached-exporter
2423 # -- Memcached Exporter Docker image tag
2425 # -- Memcached Exporter Docker image pull policy
2426 pullPolicy: IfNotPresent
2427 # -- Memcached Exporter resource requests and limits
2429 # -- Additional CLI args for the memcached exporter
2431# -- Configuration for a dedicated memcached cluster for the bloom cache role.
2432# When enabled, bloom cache is served by its own memcached StatefulSet.
2433# Image is shared with the main `memcached` section.
2435 # -- Enable a dedicated memcached cluster for the bloom cache role
2437 # -- Annotations for the memcached-bloom StatefulSet
2439 # -- Number of replicas for the bloom memcached StatefulSet
2441 # -- Timeout for bloom cache operations
2443 # -- Enable consistent hashing for bloom cache
2444 consistentHash: true
2445 # -- Additional CLI args for memcached
2447 # -- Tolerations for memcached-bloom pods
2449 # -- Environment variables to add to memcached-bloom pods
2451 # -- Environment variables from secrets or configmaps to add to memcached-bloom pods
2453 # -- Labels for memcached-bloom pods
2455 # -- Annotations for memcached-bloom pods
2457 # -- Resource requests and limits for memcached-bloom
2459 # -- topologySpread for memcached-bloom pods. Passed through `tpl` and, thus, to be configured as string
2460 # @default -- Defaults to allow skew no more than 1 node per AZ
2461 topologySpreadConstraints: |
2463 topologyKey: topology.kubernetes.io/zone
2464 whenUnsatisfiable: ScheduleAnyway
2467 {{- include "tempo.selectorLabels" (dict "ctx" . "component" "memcached-bloom") | nindent 6 }}
2468 # -- Affinity for memcached-bloom pods. Passed through `tpl` and, thus, to be configured as string
2469 # @default -- Hard node and soft zone anti-affinity
2472 requiredDuringSchedulingIgnoredDuringExecution:
2475 {{- include "tempo.selectorLabels" (dict "ctx" . "component" "memcached-bloom") | nindent 10 }}
2476 topologyKey: kubernetes.io/hostname
2477 preferredDuringSchedulingIgnoredDuringExecution:
2482 {{- include "tempo.selectorLabels" (dict "ctx" . "component" "memcached-bloom") | nindent 12 }}
2483 topologyKey: topology.kubernetes.io/zone
2484 # -- Pod Disruption Budget configuration
2485 podDisruptionBudget:
2486 # -- Enable PodDisruptionBudget for memcached-bloom
2488 # -- Pod Disruption Budget maxUnavailable
2490 # -- Init containers for the memcached-bloom pod
2492 # -- Containers to add to the memcached-bloom pods
2494 # -- Extra volume mounts for memcached-bloom pods
2495 extraVolumeMounts: []
2496 # -- Extra volumes for memcached-bloom StatefulSet
2499 # -- Annotations for memcached-bloom service
2501 # -- configuration for readiness probe for memcached-bloom statefulset
2505 initialDelaySeconds: 5
2510 # -- configuration for liveness probe for memcached-bloom statefulset
2512 initialDelaySeconds: 30
2517# -- Configuration for a dedicated memcached cluster for the parquet-footer cache role.
2518# When enabled, parquet-footer cache is served by its own memcached StatefulSet.
2519# Image is shared with the main `memcached` section.
2520memcachedParquetFooter:
2521 # -- Enable a dedicated memcached cluster for the parquet-footer cache role
2523 # -- Annotations for the memcached-parquet-footer StatefulSet
2525 # -- Number of replicas for the parquet-footer memcached StatefulSet
2527 # -- Timeout for parquet-footer cache operations
2529 # -- Enable consistent hashing for parquet-footer cache
2530 consistentHash: true
2531 # -- Additional CLI args for memcached
2533 # -- Tolerations for memcached-parquet-footer pods
2535 # -- Environment variables to add to memcached-parquet-footer pods
2537 # -- Environment variables from secrets or configmaps to add to memcached-parquet-footer pods
2539 # -- Labels for memcached-parquet-footer pods
2541 # -- Annotations for memcached-parquet-footer pods
2543 # -- Resource requests and limits for memcached-parquet-footer
2545 # -- topologySpread for memcached-parquet-footer pods. Passed through `tpl` and, thus, to be configured as string
2546 # @default -- Defaults to allow skew no more than 1 node per AZ
2547 topologySpreadConstraints: |
2549 topologyKey: topology.kubernetes.io/zone
2550 whenUnsatisfiable: ScheduleAnyway
2553 {{- include "tempo.selectorLabels" (dict "ctx" . "component" "memcached-parquet-footer") | nindent 6 }}
2554 # -- Affinity for memcached-parquet-footer pods. Passed through `tpl` and, thus, to be configured as string
2555 # @default -- Hard node and soft zone anti-affinity
2558 requiredDuringSchedulingIgnoredDuringExecution:
2561 {{- include "tempo.selectorLabels" (dict "ctx" . "component" "memcached-parquet-footer") | nindent 10 }}
2562 topologyKey: kubernetes.io/hostname
2563 preferredDuringSchedulingIgnoredDuringExecution:
2568 {{- include "tempo.selectorLabels" (dict "ctx" . "component" "memcached-parquet-footer") | nindent 12 }}
2569 topologyKey: topology.kubernetes.io/zone
2570 # -- Pod Disruption Budget configuration
2571 podDisruptionBudget:
2572 # -- Enable PodDisruptionBudget for memcached-parquet-footer
2574 # -- Pod Disruption Budget maxUnavailable
2576 # -- Init containers for the memcached-parquet-footer pod
2578 # -- Containers to add to the memcached-parquet-footer pods
2580 # -- Extra volume mounts for memcached-parquet-footer pods
2581 extraVolumeMounts: []
2582 # -- Extra volumes for memcached-parquet-footer StatefulSet
2585 # -- Annotations for memcached-parquet-footer service
2587 # -- configuration for readiness probe for memcached-parquet-footer statefulset
2591 initialDelaySeconds: 5
2596 # -- configuration for liveness probe for memcached-parquet-footer statefulset
2598 initialDelaySeconds: 30
2603# -- Configuration for a dedicated memcached cluster for the frontend-search cache role.
2604# When enabled, frontend-search cache is served by its own memcached StatefulSet.
2605# Image is shared with the main `memcached` section.
2606memcachedFrontendSearch:
2607 # -- Enable a dedicated memcached cluster for the frontend-search cache role
2609 # -- Annotations for the memcached-frontend-search StatefulSet
2611 # -- Number of replicas for the frontend-search memcached StatefulSet
2613 # -- Timeout for frontend-search cache operations
2615 # -- Enable consistent hashing for frontend-search cache
2616 consistentHash: true
2617 # -- Additional CLI args for memcached
2619 # -- Tolerations for memcached-frontend-search pods
2621 # -- Environment variables to add to memcached-frontend-search pods
2623 # -- Environment variables from secrets or configmaps to add to memcached-frontend-search pods
2625 # -- Labels for memcached-frontend-search pods
2627 # -- Annotations for memcached-frontend-search pods
2629 # -- Resource requests and limits for memcached-frontend-search
2631 # -- topologySpread for memcached-frontend-search pods. Passed through `tpl` and, thus, to be configured as string
2632 # @default -- Defaults to allow skew no more than 1 node per AZ
2633 topologySpreadConstraints: |
2635 topologyKey: topology.kubernetes.io/zone
2636 whenUnsatisfiable: ScheduleAnyway
2639 {{- include "tempo.selectorLabels" (dict "ctx" . "component" "memcached-frontend-search") | nindent 6 }}
2640 # -- Affinity for memcached-frontend-search pods. Passed through `tpl` and, thus, to be configured as string
2641 # @default -- Hard node and soft zone anti-affinity
2644 requiredDuringSchedulingIgnoredDuringExecution:
2647 {{- include "tempo.selectorLabels" (dict "ctx" . "component" "memcached-frontend-search") | nindent 10 }}
2648 topologyKey: kubernetes.io/hostname
2649 preferredDuringSchedulingIgnoredDuringExecution:
2654 {{- include "tempo.selectorLabels" (dict "ctx" . "component" "memcached-frontend-search") | nindent 12 }}
2655 topologyKey: topology.kubernetes.io/zone
2656 # -- Pod Disruption Budget configuration
2657 podDisruptionBudget:
2658 # -- Enable PodDisruptionBudget for memcached-frontend-search
2660 # -- Pod Disruption Budget maxUnavailable
2662 # -- Init containers for the memcached-frontend-search pod
2664 # -- Containers to add to the memcached-frontend-search pods
2666 # -- Extra volume mounts for memcached-frontend-search pods
2667 extraVolumeMounts: []
2668 # -- Extra volumes for memcached-frontend-search StatefulSet
2671 # -- Annotations for memcached-frontend-search service
2673 # -- configuration for readiness probe for memcached-frontend-search statefulset
2677 initialDelaySeconds: 5
2682 # -- configuration for liveness probe for memcached-frontend-search statefulset
2684 initialDelaySeconds: 30
2690 # ServiceMonitor configuration
2692 # -- If enabled, ServiceMonitor resources for Prometheus Operator are created
2694 # -- Alternative namespace for ServiceMonitor resources
2696 # -- Namespace selector for ServiceMonitor resources
2697 namespaceSelector: {}
2698 # -- ServiceMonitor annotations
2700 # -- Additional ServiceMonitor labels
2702 # -- ServiceMonitor scrape interval
2704 # -- ServiceMonitor scrape timeout in Go duration format (e.g. 15s)
2706 # -- ServiceMonitor relabel configs to apply to samples before scraping
2707 # https://github.com/prometheus-operator/prometheus-operator/blob/master/Documentation/api.md#relabelconfig
2709 # -- ServiceMonitor metric relabel configs to apply to samples before ingestion
2710 # https://github.com/prometheus-operator/prometheus-operator/blob/main/Documentation/api.md#endpoint
2711 metricRelabelings: []
2712 # -- ServiceMonitor will use http by default, but you can pick https as well
2714 # -- ServiceMonitor will use these tlsConfig settings to make the health check requests
2716 # metaMonitoringAgent configures the built in Grafana Agent that can scrape metrics and logs and send them to a local or remote destination
2718 # -- Controls whether to create PodLogs, MetricsInstance, LogsInstance, and GrafanaAgent CRs to scrape the
2719 # ServiceMonitors of the chart and ship metrics and logs to the remote endpoints below.
2720 # Note that you need to configure serviceMonitor in order to have some metrics available.
2722 # -- Controls whether to install the Grafana Agent Operator and its CRDs.
2723 # Note that helm will not install CRDs if this flag is enabled during an upgrade.
2724 # In that case install the CRDs manually from https://github.com/grafana/agent/tree/main/production/operator/crds
2725 installOperator: false
2727 # -- Default destination for logs. The config here is translated to Promtail client
2728 # configuration to write logs to this Loki-compatible remote. Optional.
2730 # -- Full URL for Loki push endpoint. Usually ends in /loki/api/v1/push
2733 # -- Used to set X-Scope-OrgID header on requests. Usually not used in combination with username and password.
2735 # -- Basic authentication username. Optional.
2737 # -- The value under key passwordSecretKey in this secret will be used as the basic authentication password. Required only if passwordSecretKey is set.
2738 passwordSecretName: ''
2739 # -- The value under this key in passwordSecretName will be used as the basic authentication password. Required only if passwordSecretName is set.
2740 passwordSecretKey: ''
2741 # -- Client configurations for the LogsInstance that will scrape Mimir pods. Follows the format of .remote.
2742 additionalClientConfigs: []
2744 # -- Default destination for metrics. The config here is translated to remote_write
2745 # configuration to push metrics to this Prometheus-compatible remote. Optional.
2746 # Note that you need to configure serviceMonitor in order to have some metrics available.
2748 # -- Full URL for Prometheus remote-write. Usually ends in /push
2750 # -- Used to add HTTP headers to remote-write requests.
2753 # -- Basic authentication username. Optional.
2755 # -- The value under key passwordSecretKey in this secret will be used as the basic authentication password. Required only if passwordSecretKey is set.
2756 passwordSecretName: ''
2757 # -- The value under this key in passwordSecretName will be used as the basic authentication password. Required only if passwordSecretName is set.
2758 passwordSecretKey: ''
2759 # -- Additional remote-write for the MetricsInstance that will scrape Mimir pods. Follows the format of .remote.
2760 additionalRemoteWriteConfigs: []
2762 # -- When grafanaAgent.enabled and serviceMonitor.enabled, controls whether to create ServiceMonitors CRs
2763 # for cadvisor, kubelet, and kube-state-metrics. The scraped metrics are reduced to those pertaining to
2766 # -- Controls service discovery of kube-state-metrics.
2768 namespace: kube-system
2770 app.kubernetes.io/name: kube-state-metrics
2771 # -- Sets the namespace of the resources. Leave empty or unset to use the same namespace as the Helm release.
2773 # -- Labels to add to all monitoring.grafana.com custom resources.
2774 # Does not affect the ServiceMonitors for kubernetes metrics; use serviceMonitor.labels for that.
2776 # -- Annotations to add to all monitoring.grafana.com custom resources.
2777 # Does not affect the ServiceMonitors for kubernetes metrics; use serviceMonitor.annotations for that.
2779# Rules for the Prometheus Operator
2781 # -- If enabled, a PrometheusRule resource for Prometheus Operator is created
2783 # -- Alternative namespace for the PrometheusRule resource
2785 # -- PrometheusRule annotations
2787 # -- Additional PrometheusRule labels
2789 # -- Contents of Prometheus rules file
2791 # - name: loki-rules
2793 # - record: job:loki_request_duration_seconds_bucket:sum_rate
2794 # expr: sum(rate(loki_request_duration_seconds_bucket[1m])) by (le, job)
2795 # - record: job_route:loki_request_duration_seconds_bucket:sum_rate
2796 # expr: sum(rate(loki_request_duration_seconds_bucket[1m])) by (le, job, route)
2797 # - record: node_namespace_pod_container:container_cpu_usage_seconds_total:sum_rate
2798 # expr: sum(rate(container_cpu_usage_seconds_total[1m])) by (node, namespace, pod, container)
2799# Configuration for the gateway
2801 # -- Specifies whether the gateway should be enabled
2803 # -- Number of replicas for the gateway
2805 # -- hostAliases to add
2811 # -- Enable autoscaling for the gateway
2813 # -- Minimum autoscaling replicas for the gateway
2815 # -- Maximum autoscaling replicas for the gateway
2817 # -- Autoscaling behavior configuration for the gateway
2819 # -- Target CPU utilisation percentage for the gateway
2820 targetCPUUtilizationPercentage: 60
2821 # -- Target memory utilisation percentage for the gateway
2822 targetMemoryUtilizationPercentage:
2823 # -- Enable logging of 2xx and 3xx HTTP requests
2824 verboseLogging: true
2826 # -- The Docker registry for the gateway image. Overrides `global.image.registry`
2828 # -- Optional list of imagePullSecrets. Overrides `global.image.pullSecrets`
2830 # -- The gateway image repository
2831 repository: nginxinc/nginx-unprivileged
2832 # -- The gateway image tag
2834 # -- The gateway image pull policy
2835 pullPolicy: IfNotPresent
2836 # -- The name of the PriorityClass for gateway pods
2837 priorityClassName: null
2838 # -- Labels for gateway pods
2840 # -- Annotations for gateway deployment
2842 # -- Annotations for gateway pods
2844 # -- Additional CLI args for the gateway
2846 # -- Environment variables to add to the gateway pods
2848 # -- Environment variables from secrets or configmaps to add to the gateway pods
2850 # -- Volumes to add to the gateway pods
2852 # -- Volume mounts to add to the gateway pods
2853 extraVolumeMounts: []
2854 # -- Containers to add to the gateway pods
2856 # -- Resource requests and limits for the gateway
2858 # -- Grace period to allow the gateway to shutdown before it is killed
2859 terminationGracePeriodSeconds: 30
2860 # -- topologySpread for gateway pods. Passed through `tpl` and, thus, to be configured as string
2861 # @default -- Defaults to allow skew no more than 1 node per AZ
2862 topologySpreadConstraints: |
2864 topologyKey: topology.kubernetes.io/zone
2865 whenUnsatisfiable: ScheduleAnyway
2868 {{- include "tempo.selectorLabels" (dict "ctx" . "component" "gateway") | nindent 6 }}
2869 # -- Affinity for gateway pods. Passed through `tpl` and, thus, to be configured as string
2870 # @default -- Hard node and soft zone anti-affinity
2873 requiredDuringSchedulingIgnoredDuringExecution:
2876 {{- include "tempo.selectorLabels" (dict "ctx" . "component" "gateway") | nindent 10 }}
2877 topologyKey: kubernetes.io/hostname
2878 preferredDuringSchedulingIgnoredDuringExecution:
2883 {{- include "tempo.selectorLabels" (dict "ctx" . "component" "gateway") | nindent 12 }}
2884 topologyKey: topology.kubernetes.io/zone
2885 # -- Pod Disruption Budget configuration
2886 podDisruptionBudget:
2887 # -- Enable PodDisruptionBudget for gateway
2889 # -- Set unhealthyPodEvictionPolicy for the gateway PodDisruptionBudget. Requires policy/v1.
2890 unhealthyPodEvictionPolicy: ""
2891 # -- Pod Disruption Budget maxUnavailable
2893 # -- Minimum number of seconds for which a newly created Pod should be ready without any of its containers crashing/terminating
2895 # -- Node selector for gateway pods
2897 # -- Tolerations for gateway pods
2899 # Gateway service configuration
2901 # -- Port of the gateway service
2903 # -- Type of the gateway service
2905 # -- Traffic distribution for the gateway service (PreferSameZone or PreferSameNode). Overrides tempo.service.trafficDistribution.
2906 trafficDistribution: null
2907 # -- ClusterIP of the gateway service
2909 # -- Node port if service type is NodePort
2911 # -- Node port for the gRPC port if service type is NodePort
2913 # -- Load balancer IP address if service type is LoadBalancer
2914 loadBalancerIP: null
2915 # -- Annotations for the gateway service
2917 # -- Labels for gateway service
2919 # -- Additional ports to be opened on gateway service (e.g. for RPC connections)
2921 # Gateway ingress configuration
2923 # -- Specifies whether an ingress for the gateway should be created
2925 # -- Labels for the gateway ingress
2927 # -- Ingress Class Name. MAY be required for Kubernetes versions >= 1.18
2928 # ingressClassName: nginx
2929 # -- Annotations for the gateway ingress
2931 # -- Hosts configuration for the gateway ingress
2933 - host: gateway.tempo.example.com
2936 # -- pathType (e.g. ImplementationSpecific, Prefix, .. etc.) might also be required by some Ingress Controllers
2938 # -- TLS configuration for the gateway ingress
2940 - secretName: tempo-gateway-tls
2942 - gateway.tempo.example.com
2943 # -- Gateway API route configuration for the gateway.
2944 # Multiple routes can be added by adding a dictionary key like the 'main' route.
2947 # -- Specifies whether a Gateway API route for the gateway should be created
2949 # -- Set the route apiVersion, e.g. gateway.networking.k8s.io/v1 or gateway.networking.k8s.io/v1beta1
2950 # If not set, the latest available version will be auto-detected
2952 # -- Set the route kind
2953 # Valid options are GRPCRoute, HTTPRoute, TCPRoute, TLSRoute, UDPRoute
2955 # -- Route annotations
2959 # -- Hostnames for the route
2961 # - gateway.tempo.example.com
2962 # -- Parent references (gateway to attach to)
2964 # - name: my-gateway
2965 # namespace: gateway-namespace
2966 # -- Matches define conditions for matching incoming requests
2971 # -- Timeouts define the timeouts that can be configured for an HTTP request.
2972 # Ref. https://gateway-api.sigs.k8s.io/api-types/httproute/#timeouts-optional
2974 # -- Filters define the filters that are applied to requests that match this rule.
2976 # -- Additional custom rules that can be added to the route
2978 # Basic auth configuration
2980 # -- Enables basic authentication for the gateway
2982 # -- The basic auth username for the gateway
2984 # -- The basic auth password for the gateway
2986 # -- Uses the specified username and password to compute a htpasswd using Sprig's `htpasswd` function.
2987 # The value is templated using `tpl`. Override this to use a custom htpasswd, e.g. in case the default causes
2990 {{ htpasswd (required "'gateway.basicAuth.username' is required" .Values.gateway.basicAuth.username) (required "'gateway.basicAuth.password' is required" .Values.gateway.basicAuth.password) }}
2991 # -- Existing basic auth secret to use. Must contain '.htpasswd'
2992 existingSecret: null
2993 # Configures the liveness probe for the gateway
2998 initialDelaySeconds: 30
3000 # Configures the readiness probe for the gateway
3005 initialDelaySeconds: 15
3008 # -- NGINX log format
3010 main '$remote_addr - $remote_user [$time_local] $status '
3011 '"$request" $body_bytes_sent "$http_referer" '
3012 '"$http_user_agent" "$http_x_forwarded_for"';
3013 # -- Allows appending custom configuration to the main context
3015 # -- Allows appending custom configuration to the server block
3017 # -- Allows appending custom configuration to the http block
3019 # -- Whether ssl should be appended to the listen directive of the server block or not.
3021 # -- TLS secret name containing the certificate and key to be used if ssl is enabled. The secret must contain 'tls.crt' and 'tls.key'. Required if ssl is true.
3023 # -- Allows overriding the DNS resolver address nginx will use
3025 # -- Configures whether or not NGINX bind IPv6
3027 # -- Config file contents for Nginx. Passed through the `tpl` function to allow templating
3028 # @default -- See values.yaml
3030 worker_processes 5; ## Default: 1
3031 error_log /dev/stderr;
3033 worker_rlimit_nofile 8192;
3035 {{- with .Values.gateway.nginxConfig.mainSnippet }}
3040 worker_connections 4096; ## Default: 1024
3044 client_body_temp_path /tmp/client_temp;
3045 proxy_temp_path /tmp/proxy_temp_path;
3046 fastcgi_temp_path /tmp/fastcgi_temp;
3047 uwsgi_temp_path /tmp/uwsgi_temp;
3048 scgi_temp_path /tmp/scgi_temp;
3050 proxy_http_version 1.1;
3052 default_type application/octet-stream;
3053 log_format {{ .Values.gateway.nginxConfig.logFormat }}
3055 {{- if .Values.gateway.verboseLogging }}
3056 access_log /dev/stderr main;
3059 map $status $loggable {
3063 access_log /dev/stderr main if=$loggable;
3068 {{- if .Values.gateway.nginxConfig.resolver }}
3069 resolver {{ .Values.gateway.nginxConfig.resolver }};
3071 resolver {{ .Values.global.dnsService }}.{{ .Values.global.dnsNamespace }}.svc.{{ .Values.global.clusterDomain }};
3074 {{- with .Values.gateway.nginxConfig.httpSnippet }}
3079 listen 8080 {{- if .Values.gateway.nginxConfig.ssl }} ssl{{- end }};
3080 {{- if .Values.gateway.nginxConfig.enableIPv6 }}
3081 listen [::]:8080 {{- if .Values.gateway.nginxConfig.ssl }} ssl{{- end }};
3084 {{- if .Values.streamOverHTTPEnabled }}
3086 location /tempopb.StreamingQuerier/ {
3087 set $query_frontend {{ include "tempo.resourceName" (dict "ctx" . "component" "query-frontend") }}.{{ .Release.Namespace }}.svc.{{ .Values.global.clusterDomain }};
3088 grpc_pass grpc://$query_frontend:3200;
3092 {{- if .Values.gateway.basicAuth.enabled }}
3094 auth_basic_user_file /etc/nginx/secrets/.htpasswd;
3102 location = /jaeger/api/traces {
3103 set $distributor {{ include "tempo.resourceName" (dict "ctx" . "component" "distributor") }}.{{ .Release.Namespace }}.svc.{{ .Values.global.clusterDomain }};
3104 proxy_pass http://$distributor:14268/api/traces;
3107 location = /zipkin/spans {
3108 set $distributor {{ include "tempo.resourceName" (dict "ctx" . "component" "distributor") }}.{{ .Release.Namespace }}.svc.{{ .Values.global.clusterDomain }};
3109 proxy_pass http://$distributor:9411/spans;
3112 location = /v1/traces {
3113 set $distributor {{ include "tempo.resourceName" (dict "ctx" . "component" "distributor") }}.{{ .Release.Namespace }}.svc.{{ .Values.global.clusterDomain }};
3114 proxy_pass http://$distributor:4318/v1/traces;
3117 location = /otlp/v1/traces {
3118 set $distributor {{ include "tempo.resourceName" (dict "ctx" . "component" "distributor") }}.{{ .Release.Namespace }}.svc.{{ .Values.global.clusterDomain }};
3119 proxy_pass http://$distributor:4318/v1/traces;
3123 set $query_frontend {{ include "tempo.resourceName" (dict "ctx" . "component" "query-frontend") }}.{{ .Release.Namespace }}.svc.{{ .Values.global.clusterDomain }};
3124 proxy_pass http://$query_frontend:3200$request_uri;
3128 set $ingester {{ include "tempo.resourceName" (dict "ctx" . "component" "ingester") }}.{{ .Release.Namespace }}.svc.{{ .Values.global.clusterDomain }};
3129 proxy_pass http://$ingester:3200$request_uri;
3132 location = /shutdown {
3133 set $ingester {{ include "tempo.resourceName" (dict "ctx" . "component" "ingester") }}.{{ .Release.Namespace }}.svc.{{ .Values.global.clusterDomain }};
3134 proxy_pass http://$ingester:3200$request_uri;
3137 location = /distributor/ring {
3138 set $distributor {{ include "tempo.resourceName" (dict "ctx" . "component" "distributor") }}.{{ .Release.Namespace }}.svc.{{ .Values.global.clusterDomain }};
3139 proxy_pass http://$distributor:3200$request_uri;
3142 location = /ingester/ring {
3143 set $distributor {{ include "tempo.resourceName" (dict "ctx" . "component" "distributor") }}.{{ .Release.Namespace }}.svc.{{ .Values.global.clusterDomain }};
3144 proxy_pass http://$distributor:3200$request_uri;
3147 location = /compactor/ring {
3148 set $compactor {{ include "tempo.resourceName" (dict "ctx" . "component" "compactor") }}.{{ .Release.Namespace }}.svc.{{ .Values.global.clusterDomain }};
3149 proxy_pass http://$compactor:3200$request_uri;
3152 {{- if .Values.backendScheduler.enabled }}
3153 location = /backend-worker/ring {
3154 set $backend_worker {{ include "tempo.resourceName" (dict "ctx" . "component" "backend-worker") }}.{{ .Release.Namespace }}.svc.{{ .Values.global.clusterDomain }};
3155 proxy_pass http://$backend_worker:3200$request_uri;
3159 {{- if .Values.gateway.nginxConfig.ssl }}
3160 ssl_certificate /etc/nginx/ssl/tls.crt;
3161 ssl_certificate_key /etc/nginx/ssl/tls.key;
3164 {{- with .Values.gateway.nginxConfig.serverSnippet }}
3169 {{- if .Values.traces.otlp.grpc.enabled }}
3172 listen {{ .Values.traces.otlp.grpc.port }} http2 {{- if .Values.gateway.nginxConfig.ssl }} ssl{{- end }};
3173 {{- if .Values.gateway.nginxConfig.enableIPv6 }}
3174 listen [::]:{{ .Values.traces.otlp.grpc.port }} http2 {{- if .Values.gateway.nginxConfig.ssl }} ssl{{- end }};
3177 {{- if .Values.gateway.basicAuth.enabled }}
3179 auth_basic_user_file /etc/nginx/secrets/.htpasswd;
3182 location = /opentelemetry.proto.collector.trace.v1.TraceService/Export {
3183 set $distributor {{ include "tempo.resourceName" (dict "ctx" . "component" "distributor") }}.{{ .Release.Namespace }}.svc.{{ .Values.global.clusterDomain }};
3184 grpc_pass grpc://$distributor:{{ .Values.traces.otlp.grpc.port }};
3187 location ~ /opentelemetry {
3188 set $distributor {{ include "tempo.resourceName" (dict "ctx" . "component" "distributor") }}.{{ .Release.Namespace }}.svc.{{ .Values.global.clusterDomain }};
3189 grpc_pass grpc://$distributor:{{ .Values.traces.otlp.grpc.port }};
3192 {{- if .Values.gateway.nginxConfig.ssl }}
3193 ssl_certificate /etc/nginx/ssl/tls.crt;
3194 ssl_certificate_key /etc/nginx/ssl/tls.key;
3197 {{- with .Values.gateway.nginxConfig.serverSnippet }}
3204 # -- If you enable this, make sure to disable the gateway's ingress.
3206 # ingressClassName: nginx
3212 - path: /distributor/ring
3213 # -- pathType (e.g. ImplementationSpecific, Prefix, .. etc.) might also be required by some Ingress Controllers
3215 - path: /live-store/ring
3216 - path: /partition-ring
3217 - path: /metrics-generator/ring
3222 - path: /status/backendscheduler
3225# -- Gateway API route configuration.
3226# Multiple routes can be added by adding a dictionary key like the 'main' route.
3227# This is useful for creating both HTTPRoute and GRPCRoute resources (e.g. for OTLP HTTP + gRPC).
3230 # -- Specifies whether a Gateway API route should be created
3232 # -- Set the route apiVersion, e.g. gateway.networking.k8s.io/v1 or gateway.networking.k8s.io/v1beta1
3233 # If not set, the latest available version will be auto-detected
3235 # -- Set the route kind
3236 # Valid options are GRPCRoute, HTTPRoute, TCPRoute, TLSRoute, UDPRoute
3238 # -- Route annotations
3242 # -- Hostnames for the route
3244 # - tempo.example.com
3245 # -- Parent references (gateway to attach to)
3247 # - name: my-gateway
3248 # namespace: gateway-namespace
3249 # -- Paths to route to backend services. Each key is a service name suffix, and the value is a list of path matches.
3253 # -- pathType for the match (e.g. PathPrefix, Exact)
3254 pathType: PathPrefix
3255 # -- OTLP HTTP receiver port. This path is only rendered when traces.otlp.http.enabled is true.
3257 - path: /distributor/ring
3258 pathType: PathPrefix
3259 - path: /live-store/ring
3260 pathType: PathPrefix
3261 - path: /partition-ring
3262 pathType: PathPrefix
3263 - path: /metrics-generator/ring
3264 pathType: PathPrefix
3266 pathType: PathPrefix
3269 pathType: PathPrefix
3271 - path: /status/backendscheduler
3272 pathType: PathPrefix
3273##############################################################################
3274# The values in and after the `enterprise:` key configure the enterprise features
3276 # Enable enterprise features. License must be provided, nginx gateway is not installed, instead
3277 # the enterprise gateway is used.
3280 # -- Grafana Enterprise Traces container image repository. Note: for Grafana Tempo use the value 'image.repository'
3281 repository: grafana/enterprise-traces
3282 # -- Grafana Enterprise Traces container image tag. Note: for Grafana Tempo use the value 'image.tag'
3284 # Note: pullPolicy and optional pullSecrets are set in toplevel 'image' section, not here
3285# In order to use Grafana Enterprise Traces features, you will need to provide the contents of your Grafana Enterprise Traces
3286# license, either by providing the contents of the license.jwt, or the name Kubernetes Secret that contains your license.jwt.
3287# To set the license contents, use the flag `--set-file 'license.contents=./license.jwt'`
3288# To use your own Kubernetes Secret, `--set license.external=true`.
3290 contents: 'NOTAVALIDLICENSE'
3292 secretName: '{{ include "tempo.resourceName" (dict "ctx" . "component" "license") }}'
3293# Settings for the initial admin(istrator) token generator job. Can only be enabled if
3294# enterprise.enabled is true - requires license.
3297 # -- hostAliases to add
3306 storeTokenInSecret: false
3307 # -- Name of the secret to store the admin token. If not specified, defaults to "<release-name>-admin-token"
3308 adminTokenSecret: "admin-token"
3310 # -- The Docker registry for the tokengenJob image. Overrides `tempo.image.registry`
3312 # -- Optional list of imagePullSecrets. Overrides `tempo.image.pullSecrets`
3314 # -- Docker image repository for the tokengenJob image. Overrides `tempo.image.repository`
3316 # -- Docker image tag for the tokengenJob image. Overrides `tempo.image.tag`
3319 # -- The SecurityContext for tokenjobgen containers
3320 containerSecurityContext:
3321 readOnlyRootFilesystem: true
3323 # -- Whether the job should be part of the deployment
3325 # -- Name of the secret to store provisioned tokens in
3326 provisionedSecretPrefix: null
3327 # -- Hook type(s) to customize when the job runs. defaults to post-install
3328 hookType: "post-install"
3329 # -- URL for the admin API service. Must be set to a valid URL.
3330 # Example: "http://tempo-admin-api.namespace.svc:3100"
3332 # -- Additional tenants to be created. Each tenant will get a read and write policy
3333 # and associated token. Tenant must have a name and a namespace for the secret containing
3334 # the token to be created in. For example
3335 # additionalTenants:
3337 # secretNamespace: grafana
3338 additionalTenants: []
3339 # -- Additional arguments for the provisioner command
3341 # -- Additional Kubernetes environment
3343 # -- Additional labels for the `provisioner` Job
3345 # -- Additional annotations for the `provisioner` Job
3347 # -- Affinity for tokengen Pods
3349 # -- Node selector for tokengen Pods
3351 # -- Tolerations for tokengen Pods
3353 # -- The name of the PriorityClass for provisioner Job
3354 priorityClassName: null
3355 # -- Run containers as nonroot user (uid=10001)`
3360 # -- Provisioner image to Utilize
3362 # -- The Docker registry
3363 registry: us-docker.pkg.dev
3364 # -- Docker image repository
3365 repository: grafanalabs-global/docker-enterprise-provisioner-prod/enterprise-provisioner
3366 # -- Overrides the image tag whose default is the chart's appVersion
3368 # -- Overrides the image tag with an image digest
3370 # -- Docker image pull policy
3371 pullPolicy: IfNotPresent
3372 # -- Volume mounts to add to the provisioner pods
3373 extraVolumeMounts: []
3374 # -- Volumes to add to the provisioner pods
3377 repository: alpine/kubectl
3379 pullPolicy: IfNotPresent
3380# Settings for the admin_api service providing authentication and authorization service.
3381# Can only be enabled if enterprise.enabled is true - requires license.
3384 # -- hostAliases to add
3395 # -- The Docker registry for the adminApi image. Overrides `tempo.image.registry`
3397 # -- Optional list of imagePullSecrets. Overrides `tempo.image.pullSecrets`
3399 # -- Docker image repository for the adminApi image. Overrides `tempo.image.repository`
3401 # -- Docker image tag for the adminApi image. Overrides `tempo.image.tag`
3412 # -- topologySpread for admin-api pods. Passed through `tpl` and, thus, to be configured as string
3413 # @default -- Defaults to allow skew no more than 1 node per AZ
3414 topologySpreadConstraints: |
3416 topologyKey: topology.kubernetes.io/zone
3417 whenUnsatisfiable: ScheduleAnyway
3420 {{- include "tempo.selectorLabels" (dict "ctx" . "component" "admin-api") | nindent 6 }}
3421 # -- Affinity for admin-api pods. Passed through `tpl` and, thus, to be configured as string
3422 # @default -- Soft node and soft zone anti-affinity
3425 preferredDuringSchedulingIgnoredDuringExecution:
3430 {{- include "tempo.selectorLabels" (dict "ctx" . "component" "admin-api") | nindent 12 }}
3431 topologyKey: kubernetes.io/hostname
3436 {{- include "tempo.selectorLabels" (dict "ctx" . "component" "admin-api") | nindent 12 }}
3437 topologyKey: topology.kubernetes.io/zone
3438 # Pod Disruption Budget
3439 podDisruptionBudget: {}
3441 # -- The SecurityContext for admin_api containers
3442 containerSecurityContext:
3443 readOnlyRootFilesystem: true
3451 initialDelaySeconds: 45
3456 terminationGracePeriodSeconds: 60
3460 extraVolumeMounts: []
3463# Settings for the gateway service providing authentication and authorization via the admin_api.
3464# Can only be enabled if enterprise.enabled is true - requires license.
3466 # -- If you want to use your own proxy URLs, set this to false.
3467 useDefaultProxyURLs: true
3468 # -- Proxy URLs defined in this object will be used if useDefaultProxyURLs is set to false.
3471 # -- hostAliases to add
3478 # -- The Docker registry for the enterpriseGateway image. Overrides `tempo.image.registry`
3480 # -- Optional list of imagePullSecrets. Overrides `tempo.image.pullSecrets`
3482 # -- Docker image repository for the enterpriseGateway image. Overrides `tempo.image.repository`
3484 # -- Docker image tag for the enterpriseGateway image. Overrides `tempo.image.tag`
3488 # -- Port of the enterprise gateway service; if left undefined, the service will listen on the same port as the pod
3490 # -- Type of the enterprise gateway service
3492 # -- ClusterIP of the enterprise gateway service
3494 # -- Load balancer IP address if service type is LoadBalancer for enterprise gateway service
3495 loadBalancerIP: null
3496 # -- Annotations for the enterprise gateway service
3498 # -- Labels for enterprise gateway service
3507 # Pod Disruption Budget
3508 podDisruptionBudget: {}
3510 # -- topologySpread for enterprise-gateway pods. Passed through `tpl` and, thus, to be configured as string
3511 # @default -- Defaults to allow skew no more than 1 node per AZ
3512 topologySpreadConstraints: |
3514 topologyKey: topology.kubernetes.io/zone
3515 whenUnsatisfiable: ScheduleAnyway
3518 {{- include "tempo.selectorLabels" (dict "ctx" . "component" "enterprise-gateway") | nindent 6 }}
3519 # -- Affinity for enterprise-gateway pods. Passed through `tpl` and, thus, to be configured as string
3520 # @default -- Soft node and soft zone anti-affinity
3523 preferredDuringSchedulingIgnoredDuringExecution:
3528 {{- include "tempo.selectorLabels" (dict "ctx" . "component" "enterprise-gateway") | nindent 12 }}
3529 topologyKey: kubernetes.io/hostname
3534 {{- include "tempo.selectorLabels" (dict "ctx" . "component" "enterprise-gateway") | nindent 12 }}
3535 topologyKey: topology.kubernetes.io/zone
3537 # -- The SecurityContext for enterprise-gateway containers
3538 containerSecurityContext:
3539 readOnlyRootFilesystem: true
3548 initialDelaySeconds: 45
3553 terminationGracePeriodSeconds: 60
3557 extraVolumeMounts: []
3560 # Ingress configuration
3562 # -- Specifies whether an ingress for the enterprise-gateway should be created
3564 # -- Ingress Class Name. MAY be required for Kubernetes versions >= 1.18
3565 # ingressClassName: gateway
3566 # -- Annotations for the enterprise-gateway ingress
3568 # -- Hosts configuration for the enterprise-gateway ingress
3570 - host: gateway.get.example.com
3573 # -- pathType (e.g. ImplementationSpecific, Prefix, .. etc.) might also be required by some Ingress Controllers
3575 # -- TLS configuration for the enterprise-gateway ingress
3577 - secretName: get-gateway-tls
3579 - gateway.get.example.com
3580# -- extraObjects could be utilized to add dynamic manifests via values
3584# - apiVersion: kubernetes-client.io/v1
3585# kind: ExternalSecret
3587# name: tempo-secrets-{{ .Release.Name }}
3591# - key: secret-access-key
3593# Alternatively, you can use strings, which lets you use additional templating features:
3596# apiVersion: kubernetes-client.io/v1
3597# kind: ExternalSecret
3599# name: tempo-secrets-{{ .Release.Name }}
3603# - key: secret-access-key
3604# name: {{ include "some-other-template" }}
3608 # -- Enable helm test hooks that run a BATS trace roundtrip against the live cluster.
3609 # WARNING: enabling this and running `helm test` ingests real trace data into object storage.
3610 # Traces age out via retention; Tempo has no delete API.