Helm values¶
Every value of the kubelatch chart (oci://ghcr.io/picaportelabs/charts/kubelatch), with its default. The chart validates them before installing anything: a missing config.baseURL, an unknown key or a combination that doesn't fit stops helm install with a message that names it. How to use them is in Install; what each kubelatch variable does is in Configuration.
This table is generated from the comments of the chart's values.yaml (make helm-docs), so it is in English in both languages.
| Key | Default | Description |
|---|---|---|
nameOverride |
"" |
Overrides the chart name in resource names and labels. |
fullnameOverride |
"" |
Overrides the full resource name (by default the release name, or <release>-kubelatch when the release name does not contain kubelatch). |
image.repository |
ghcr.io/picaportelabs/kubelatch |
Image repository. |
image.tag |
"" |
Image tag. Empty means the chart's appVersion. |
image.pullPolicy |
IfNotPresent |
Image pull policy. |
imagePullSecrets |
[] |
Secrets with registry credentials, as [{name: ...}]. |
exposure |
loadBalancer |
How clients reach kubelatch: loadBalancer (L4 Service, TLS terminated by kubelatch on 8443) or ingress (ClusterIP on 8080 in plain HTTP behind an ingress-nginx Ingress that terminates TLS). |
config.baseURL |
"" |
KUBELATCH_BASE_URL, required: the exact public URL, without a trailing slash. |
config.instanceID |
default |
KUBELATCH_INSTANCE_ID: value of the kubelatch.io/instance label on the objects kubelatch creates in the clusters. |
config.auditRetention |
90d |
KUBELATCH_AUDIT_RETENTION: <n>d or a Go duration; 0 keeps everything unless the instance never had a key, which caps it at 24 hours. |
config.trustedProxies |
"" |
KUBELATCH_TRUSTED_PROXIES: comma-separated CIDRs whose X-Forwarded-For is believed. Empty behind an L4 load balancer; required with exposure: ingress (only the ingress controller's pods). |
config.kubeconfigCA |
"" |
KUBELATCH_KUBECONFIG_CA: path to a PEM bundle embedded in issued kubeconfigs (a private CA). exposure: loadBalancer only, where kubelatch mounts its own TLS secret: with a private cert-manager issuer, /etc/kubelatch/tls/ca.crt. Not mounted with exposure: ingress. |
config.protectedNamespaces |
"" |
KUBELATCH_PROTECTED_NAMESPACES: comma-separated namespaces that accept no grants, on top of the built-in list. |
config.requirePSA |
"" |
KUBELATCH_REQUIRE_PSA: "false" lets developer, debugger and admin grants into namespaces without Pod Security Admission. Empty keeps kubelatch's default (true). |
config.accessContact |
"" |
KUBELATCH_ACCESS_CONTACT: who a person asks for access (a mailto:, an https:// URL or a short text), linked from Home. |
config.updateCheck |
"" |
KUBELATCH_UPDATE_CHECK: "false" stops the daily check for a newer kubelatch (it sends nothing). Empty keeps kubelatch's default (true). |
config.updateCheckURL |
"" |
KUBELATCH_UPDATE_CHECK_URL: where the version check reads the latest published version; an internal mirror in air-gapped installations. A URL with a user or password is refused here: set it in the Secret instead. |
config.maxTTLUser |
"" |
KUBELATCH_MAX_TTL_USER: longest credential a person can issue. |
config.maxTTLBot |
"" |
KUBELATCH_MAX_TTL_BOT: longest credential for a bot. |
config.cliSessionTTL |
"" |
KUBELATCH_CLI_SESSION_TTL: lifetime of a kubelatch login session (at most maxTTLUser). |
config.ciTokenTTL |
"" |
KUBELATCH_CI_TOKEN_TTL: lifetime of the credentials the GitHub Actions exchange issues. |
config.mcpEnabled |
"" |
KUBELATCH_MCP_ENABLED: serve the MCP endpoint for AI agents at /mcp ("false" turns it off). |
config.mcpRateLimit |
"" |
KUBELATCH_MCP_RATE_LIMIT: requests to /mcp per minute and credential (per session for a delegated AI agent). |
config.agentSessionTTL |
"" |
KUBELATCH_AGENT_SESSION_TTL: duration a person's consent to an AI agent proposes (default 8h). |
config.agentSessionMaxTTL |
"" |
KUBELATCH_AGENT_SESSION_MAX_TTL: longest duration a person may give an AI agent (default 24h, at most maxTTLUser). |
config.agentApprovalWait |
"" |
KUBELATCH_AGENT_APPROVAL_WAIT: how long an AI agent's call waits for a person to decide a held write before it answers pending again (default 50s, 0s to 4m; 0s answers at once). Keep it under the proxy's read timeout in front of kubelatch. |
config.githubActionsIssuer |
"" |
KUBELATCH_GITHUB_ACTIONS_ISSUER: OIDC issuer of GitHub Actions tokens (GitHub Enterprise Server only). |
config.logLevel |
info |
KUBELATCH_LOG_LEVEL: debug, info, warn or error. debug adds a line for every /healthz and /readyz probe. |
config.logFormat |
json |
KUBELATCH_LOG_FORMAT: json (one object per line) or text (key=value). |
config.github.org |
"" |
GITHUB_ORG: turns GitHub login on; the four GITHUB_APP_* secrets must then be in the Secret. |
config.github.requireOrg2FA |
true |
GITHUB_REQUIRE_ORG_2FA: reject GitHub logins while the organization does not require two-factor. |
config.github.url |
"" |
GITHUB_URL: GitHub Enterprise Server only. |
config.github.apiURL |
"" |
GITHUB_API_URL: GitHub Enterprise Server only. |
mail.from |
"" |
KUBELATCH_MAIL_FROM: the sender, such as kubelatch <noreply@example.com>, on a domain verified in Resend. Set it together with KUBELATCH_RESEND_API_KEY in the Secret (secrets.env or secrets.existingSecret): a send-only key restricted to that domain. Empty leaves e-mail off and links are copied by hand. |
secrets.existingSecret |
kubelatch-secrets |
Name of an existing Secret loaded whole into the pod. Ignored with secrets.create. Empty is only valid with postgres.mode: cnpg and secrets.generateEncryptionKey. |
secrets.create |
false |
Create the Secret <fullname>-secrets from secrets.env instead of using secrets.existingSecret. The values then live in your values file. |
secrets.env |
{} |
Variables of the chart-created Secret (secrets.create), such as DATABASE_URL and KUBELATCH_ENCRYPTION_KEY. |
secrets.generateEncryptionKey |
false |
Generate KUBELATCH_ENCRYPTION_KEY once into the Secret <fullname>-encryption-key, reused on every upgrade and kept on helm uninstall. Needs a live cluster at render time (lookup): not for helm template or GitOps tools that render offline. |
extraEnvFrom |
[] |
More envFrom sources for the kubelatch container, for example [{secretRef: {name: kubelatch-github}}]. |
postgres.mode |
external |
external (DATABASE_URL comes from the Secret) or cnpg (the chart creates a CloudNativePG Cluster named <fullname>-db; the operator must be installed first). |
postgres.cnpg.instances |
1 |
Postgres instances: 1, or 3 for high availability. |
postgres.cnpg.imageName |
ghcr.io/cloudnative-pg/postgresql:17-standard-trixie |
Postgres image (CloudNativePG operand image). Pin a minor version (17.6-standard-trixie) to control upgrades. |
postgres.cnpg.storage.size |
10Gi |
Size of each instance's volume. |
postgres.cnpg.storage.storageClass |
"" |
StorageClass of the volumes. Empty uses the cluster default. |
postgres.cnpg.resources |
{} |
Resources of each Postgres instance. |
postgres.cnpg.affinity |
{} |
Affinity of the Postgres instances (CloudNativePG affinity block). |
postgres.cnpg.bootstrap |
{} |
Replaces the Cluster's bootstrap block (by default initdb of the database kubelatch owned by kubelatch): recovery to restore from a backup, or initdb.import to import an existing database. |
postgres.cnpg.externalClusters |
[] |
externalClusters of the Cluster: the source of a recovery or an import. |
postgres.cnpg.operatorNamespace |
cnpg-system |
Namespace of the CloudNativePG operator, allowed through the database's NetworkPolicy. |
postgres.cnpg.backup.enabled |
false |
Back up base backups and WAL to object storage with the Barman Cloud Plugin (installed next to the operator), plus a daily ScheduledBackup. |
postgres.cnpg.backup.destinationPath |
"" |
Object store URL: s3://bucket/path, gs://... or https://<account>.blob.core.windows.net/<container>/.... |
postgres.cnpg.backup.endpointURL |
"" |
Endpoint for S3-compatible stores that are not AWS (MinIO...). |
postgres.cnpg.backup.credentials |
{} |
Credentials block of the plugin's ObjectStore, as in its documentation: s3Credentials, googleCredentials or azureCredentials, each pointing at keys of a Secret. |
postgres.cnpg.backup.serverName |
"" |
Folder of this Cluster in the object store. Empty means the Cluster's name; a restored Cluster must write to a new one. |
postgres.cnpg.backup.retentionPolicy |
30d |
How long backups are kept (<n>d, <n>w or <n>m). |
postgres.cnpg.backup.schedule |
"0 0 3 * * *" |
Cron schedule of the ScheduledBackup, with seconds (CloudNativePG syntax): daily at 03:00. |
service.type |
LoadBalancer |
Service type with exposure: loadBalancer: LoadBalancer, or NodePort where there is no load balancer. Ignored with ingress (always ClusterIP). |
service.port |
443 |
Service port with exposure: loadBalancer. |
service.nodePort |
null |
Fixed node port (NodePort type only). |
service.externalTrafficPolicy |
Local |
Keep the client's source IP (audit and per-IP limits). Ignored with ingress. |
service.annotations |
{} |
Service annotations, for example the cloud's load balancer settings. |
ingress.host |
"" |
Host of the Ingress, required with exposure: ingress. |
ingress.className |
nginx |
IngressClass. |
ingress.annotations |
{} |
Extra Ingress annotations, merged over the ingress-nginx ones the proxy needs (timeouts, body size, buffering). |
tls.existingSecret |
kubelatch-tls |
Secret with tls.crt and tls.key (and ca.crt with a private CA). Mounted by kubelatch with exposure: loadBalancer; used by the Ingress with exposure: ingress. Ignored with tls.certManager.enabled. |
tls.certManager.enabled |
false |
Create a cert-manager Certificate (ECDSA P-256) that fills the Secret <fullname>-tls. |
tls.certManager.dnsNames |
[] |
DNS names of the certificate. Empty means the host of config.baseURL. |
tls.certManager.duration |
2160h |
Lifetime of the certificate (90 days). |
tls.certManager.renewBefore |
720h |
Renew this long before it expires (30 days: kubelatch warns when less is left). |
tls.certManager.issuerRef.name |
letsencrypt |
Issuer name. |
tls.certManager.issuerRef.kind |
ClusterIssuer |
ClusterIssuer or Issuer. |
replicas |
1 |
Replicas of kubelatch. Two or more add a PodDisruptionBudget. |
shutdownDelaySeconds |
5 |
Seconds a terminating pod keeps serving before it gets SIGTERM (a preStop sleep): kube-proxy and the load balancer keep sending it new connections for a while, and they must not find the port closed. Raise it when your load balancer takes longer to stop sending traffic to a target. At most 25, so the 30 s shutdown still fits in the 60 s grace period. |
pdb.minAvailable |
1 |
minAvailable of the PodDisruptionBudget (only with replicas > 1). |
networkPolicy.enabled |
true |
Restrict ingress to kubelatch (8443 from anywhere with a load balancer; 8080 only from the ingress controller's namespace) and, with postgres.mode: cnpg, to the database (5432 from kubelatch and the operator). Needs a CNI that enforces NetworkPolicy. Required with exposure: ingress. |
networkPolicy.ingressControllerNamespace |
ingress-nginx |
Namespace of the ingress controller (exposure: ingress). |
hardening.enabled |
false |
Install the ValidatingAdmissionPolicy that only lets kubelatch's reconciler bind kubelatch-* roles. Cluster-scoped: only when this cluster is also registered in kubelatch, and after its bootstrap. |
namespace.create |
false |
Render the release namespace with the restricted Pod Security label (kept on uninstall). Only installable with Helm 3.17 or later and helm install --create-namespace --take-ownership. |
resources.requests.cpu |
100m |
CPU request. |
resources.requests.memory |
128Mi |
Memory request. |
resources.limits.memory |
512Mi |
Memory limit: argon2id uses 19 MiB per hash, at most 4 at once. |
nodeSelector |
{} |
Node selector of the kubelatch pods. |
tolerations |
[] |
Tolerations of the kubelatch pods. |
affinity |
{} |
Affinity of the kubelatch pods. |
podAnnotations |
{} |
Extra annotations of the kubelatch pods. |
podLabels |
{} |
Extra labels of the kubelatch pods. |
extraContainers |
[] |
Extra containers in the kubelatch pod (a tunnel sidecar for private clusters). They must run under the restricted Pod Security level. |
extraVolumes |
[] |
Extra volumes of the kubelatch pod. |
extraVolumeMounts |
[] |
Extra volume mounts for the kubelatch container (e.g. the CA of an external Postgres, mounted from extraVolumes). |