Saltar a contenido

Values de Helm

Todos los values del chart de kubelatch (oci://ghcr.io/picaportelabs/charts/kubelatch), con su valor por defecto. El chart los valida antes de instalar nada: si falta config.baseURL, hay una clave desconocida o una combinación no encaja, helm install se detiene con un mensaje que la nombra. Cómo usarlos está en Instalar; qué hace cada variable de kubelatch, en Configuración.

La tabla se genera desde los comentarios del values.yaml del chart (make helm-docs), así que está en inglés en los dos idiomas.

Key Default Description
nameOverride "" Overrides the chart name in resource names and labels.
fullnameOverride "" Overrides the full resource name (by default the release name, or <release>-kubelatch when the release name does not contain kubelatch).
image.repository ghcr.io/picaportelabs/kubelatch Image repository.
image.tag "" Image tag. Empty means the chart's appVersion.
image.pullPolicy IfNotPresent Image pull policy.
imagePullSecrets [] Secrets with registry credentials, as [{name: ...}].
exposure loadBalancer How clients reach kubelatch: loadBalancer (L4 Service, TLS terminated by kubelatch on 8443) or ingress (ClusterIP on 8080 in plain HTTP behind an ingress-nginx Ingress that terminates TLS).
config.baseURL "" KUBELATCH_BASE_URL, required: the exact public URL, without a trailing slash.
config.instanceID default KUBELATCH_INSTANCE_ID: value of the kubelatch.io/instance label on the objects kubelatch creates in the clusters.
config.auditRetention 90d KUBELATCH_AUDIT_RETENTION: <n>d or a Go duration; 0 keeps everything unless the instance never had a key, which caps it at 24 hours.
config.trustedProxies "" KUBELATCH_TRUSTED_PROXIES: comma-separated CIDRs whose X-Forwarded-For is believed. Empty behind an L4 load balancer; required with exposure: ingress (only the ingress controller's pods).
config.kubeconfigCA "" KUBELATCH_KUBECONFIG_CA: path to a PEM bundle embedded in issued kubeconfigs (a private CA). exposure: loadBalancer only, where kubelatch mounts its own TLS secret: with a private cert-manager issuer, /etc/kubelatch/tls/ca.crt. Not mounted with exposure: ingress.
config.protectedNamespaces "" KUBELATCH_PROTECTED_NAMESPACES: comma-separated namespaces that accept no grants, on top of the built-in list.
config.requirePSA "" KUBELATCH_REQUIRE_PSA: "false" lets developer, debugger and admin grants into namespaces without Pod Security Admission. Empty keeps kubelatch's default (true).
config.accessContact "" KUBELATCH_ACCESS_CONTACT: who a person asks for access (a mailto:, an https:// URL or a short text), linked from Home.
config.updateCheck "" KUBELATCH_UPDATE_CHECK: "false" stops the daily check for a newer kubelatch (it sends nothing). Empty keeps kubelatch's default (true).
config.updateCheckURL "" KUBELATCH_UPDATE_CHECK_URL: where the version check reads the latest published version; an internal mirror in air-gapped installations. A URL with a user or password is refused here: set it in the Secret instead.
config.maxTTLUser "" KUBELATCH_MAX_TTL_USER: longest credential a person can issue.
config.maxTTLBot "" KUBELATCH_MAX_TTL_BOT: longest credential for a bot.
config.cliSessionTTL "" KUBELATCH_CLI_SESSION_TTL: lifetime of a kubelatch login session (at most maxTTLUser).
config.ciTokenTTL "" KUBELATCH_CI_TOKEN_TTL: lifetime of the credentials the GitHub Actions exchange issues.
config.mcpEnabled "" KUBELATCH_MCP_ENABLED: serve the MCP endpoint for AI agents at /mcp ("false" turns it off).
config.mcpRateLimit "" KUBELATCH_MCP_RATE_LIMIT: requests to /mcp per minute and credential (per session for a delegated AI agent).
config.agentSessionTTL "" KUBELATCH_AGENT_SESSION_TTL: duration a person's consent to an AI agent proposes (default 8h).
config.agentSessionMaxTTL "" KUBELATCH_AGENT_SESSION_MAX_TTL: longest duration a person may give an AI agent (default 24h, at most maxTTLUser).
config.agentApprovalWait "" KUBELATCH_AGENT_APPROVAL_WAIT: how long an AI agent's call waits for a person to decide a held write before it answers pending again (default 50s, 0s to 4m; 0s answers at once). Keep it under the proxy's read timeout in front of kubelatch.
config.githubActionsIssuer "" KUBELATCH_GITHUB_ACTIONS_ISSUER: OIDC issuer of GitHub Actions tokens (GitHub Enterprise Server only).
config.logLevel info KUBELATCH_LOG_LEVEL: debug, info, warn or error. debug adds a line for every /healthz and /readyz probe.
config.logFormat json KUBELATCH_LOG_FORMAT: json (one object per line) or text (key=value).
config.github.org "" GITHUB_ORG: turns GitHub login on; the four GITHUB_APP_* secrets must then be in the Secret.
config.github.requireOrg2FA true GITHUB_REQUIRE_ORG_2FA: reject GitHub logins while the organization does not require two-factor.
config.github.url "" GITHUB_URL: GitHub Enterprise Server only.
config.github.apiURL "" GITHUB_API_URL: GitHub Enterprise Server only.
mail.from "" KUBELATCH_MAIL_FROM: the sender, such as kubelatch <noreply@example.com>, on a domain verified in Resend. Set it together with KUBELATCH_RESEND_API_KEY in the Secret (secrets.env or secrets.existingSecret): a send-only key restricted to that domain. Empty leaves e-mail off and links are copied by hand.
secrets.existingSecret kubelatch-secrets Name of an existing Secret loaded whole into the pod. Ignored with secrets.create. Empty is only valid with postgres.mode: cnpg and secrets.generateEncryptionKey.
secrets.create false Create the Secret <fullname>-secrets from secrets.env instead of using secrets.existingSecret. The values then live in your values file.
secrets.env {} Variables of the chart-created Secret (secrets.create), such as DATABASE_URL and KUBELATCH_ENCRYPTION_KEY.
secrets.generateEncryptionKey false Generate KUBELATCH_ENCRYPTION_KEY once into the Secret <fullname>-encryption-key, reused on every upgrade and kept on helm uninstall. Needs a live cluster at render time (lookup): not for helm template or GitOps tools that render offline.
extraEnvFrom [] More envFrom sources for the kubelatch container, for example [{secretRef: {name: kubelatch-github}}].
postgres.mode external external (DATABASE_URL comes from the Secret) or cnpg (the chart creates a CloudNativePG Cluster named <fullname>-db; the operator must be installed first).
postgres.cnpg.instances 1 Postgres instances: 1, or 3 for high availability.
postgres.cnpg.imageName ghcr.io/cloudnative-pg/postgresql:17-standard-trixie Postgres image (CloudNativePG operand image). Pin a minor version (17.6-standard-trixie) to control upgrades.
postgres.cnpg.storage.size 10Gi Size of each instance's volume.
postgres.cnpg.storage.storageClass "" StorageClass of the volumes. Empty uses the cluster default.
postgres.cnpg.resources {} Resources of each Postgres instance.
postgres.cnpg.affinity {} Affinity of the Postgres instances (CloudNativePG affinity block).
postgres.cnpg.bootstrap {} Replaces the Cluster's bootstrap block (by default initdb of the database kubelatch owned by kubelatch): recovery to restore from a backup, or initdb.import to import an existing database.
postgres.cnpg.externalClusters [] externalClusters of the Cluster: the source of a recovery or an import.
postgres.cnpg.operatorNamespace cnpg-system Namespace of the CloudNativePG operator, allowed through the database's NetworkPolicy.
postgres.cnpg.backup.enabled false Back up base backups and WAL to object storage with the Barman Cloud Plugin (installed next to the operator), plus a daily ScheduledBackup.
postgres.cnpg.backup.destinationPath "" Object store URL: s3://bucket/path, gs://... or https://<account>.blob.core.windows.net/<container>/....
postgres.cnpg.backup.endpointURL "" Endpoint for S3-compatible stores that are not AWS (MinIO...).
postgres.cnpg.backup.credentials {} Credentials block of the plugin's ObjectStore, as in its documentation: s3Credentials, googleCredentials or azureCredentials, each pointing at keys of a Secret.
postgres.cnpg.backup.serverName "" Folder of this Cluster in the object store. Empty means the Cluster's name; a restored Cluster must write to a new one.
postgres.cnpg.backup.retentionPolicy 30d How long backups are kept (<n>d, <n>w or <n>m).
postgres.cnpg.backup.schedule "0 0 3 * * *" Cron schedule of the ScheduledBackup, with seconds (CloudNativePG syntax): daily at 03:00.
service.type LoadBalancer Service type with exposure: loadBalancer: LoadBalancer, or NodePort where there is no load balancer. Ignored with ingress (always ClusterIP).
service.port 443 Service port with exposure: loadBalancer.
service.nodePort null Fixed node port (NodePort type only).
service.externalTrafficPolicy Local Keep the client's source IP (audit and per-IP limits). Ignored with ingress.
service.annotations {} Service annotations, for example the cloud's load balancer settings.
ingress.host "" Host of the Ingress, required with exposure: ingress.
ingress.className nginx IngressClass.
ingress.annotations {} Extra Ingress annotations, merged over the ingress-nginx ones the proxy needs (timeouts, body size, buffering).
tls.existingSecret kubelatch-tls Secret with tls.crt and tls.key (and ca.crt with a private CA). Mounted by kubelatch with exposure: loadBalancer; used by the Ingress with exposure: ingress. Ignored with tls.certManager.enabled.
tls.certManager.enabled false Create a cert-manager Certificate (ECDSA P-256) that fills the Secret <fullname>-tls.
tls.certManager.dnsNames [] DNS names of the certificate. Empty means the host of config.baseURL.
tls.certManager.duration 2160h Lifetime of the certificate (90 days).
tls.certManager.renewBefore 720h Renew this long before it expires (30 days: kubelatch warns when less is left).
tls.certManager.issuerRef.name letsencrypt Issuer name.
tls.certManager.issuerRef.kind ClusterIssuer ClusterIssuer or Issuer.
replicas 1 Replicas of kubelatch. Two or more add a PodDisruptionBudget.
shutdownDelaySeconds 5 Seconds a terminating pod keeps serving before it gets SIGTERM (a preStop sleep): kube-proxy and the load balancer keep sending it new connections for a while, and they must not find the port closed. Raise it when your load balancer takes longer to stop sending traffic to a target. At most 25, so the 30 s shutdown still fits in the 60 s grace period.
pdb.minAvailable 1 minAvailable of the PodDisruptionBudget (only with replicas > 1).
networkPolicy.enabled true Restrict ingress to kubelatch (8443 from anywhere with a load balancer; 8080 only from the ingress controller's namespace) and, with postgres.mode: cnpg, to the database (5432 from kubelatch and the operator). Needs a CNI that enforces NetworkPolicy. Required with exposure: ingress.
networkPolicy.ingressControllerNamespace ingress-nginx Namespace of the ingress controller (exposure: ingress).
hardening.enabled false Install the ValidatingAdmissionPolicy that only lets kubelatch's reconciler bind kubelatch-* roles. Cluster-scoped: only when this cluster is also registered in kubelatch, and after its bootstrap.
namespace.create false Render the release namespace with the restricted Pod Security label (kept on uninstall). Only installable with Helm 3.17 or later and helm install --create-namespace --take-ownership.
resources.requests.cpu 100m CPU request.
resources.requests.memory 128Mi Memory request.
resources.limits.memory 512Mi Memory limit: argon2id uses 19 MiB per hash, at most 4 at once.
nodeSelector {} Node selector of the kubelatch pods.
tolerations [] Tolerations of the kubelatch pods.
affinity {} Affinity of the kubelatch pods.
podAnnotations {} Extra annotations of the kubelatch pods.
podLabels {} Extra labels of the kubelatch pods.
extraContainers [] Extra containers in the kubelatch pod (a tunnel sidecar for private clusters). They must run under the restricted Pod Security level.
extraVolumes [] Extra volumes of the kubelatch pod.
extraVolumeMounts [] Extra volume mounts for the kubelatch container (e.g. the CA of an external Postgres, mounted from extraVolumes).