Skip to content

cfgate.iocfgate v0.2.0-alpha.11 · Release documentation

Helm v1.10.0 values

The chart’s commented values are the configuration reference. User overrides remain authoritative during upgrades.

# cfgate Helm chart values
# Gateway API-native Kubernetes operator for Cloudflare Tunnel, DNS, and Access
# Number of controller replicas
replicaCount: 2
# Kubernetes shutdown allowance; recovery must also tolerate forced termination.
terminationGracePeriodSeconds: 30
image:
repository: ghcr.io/cfgate/cfgate
pullPolicy: IfNotPresent
# Explicit tag or repository overrides opt out of the chart's verified default pin.
tag: ""
# Optional sha256 digest; takes precedence over tag, including for custom repositories.
digest: ""
imagePullSecrets: []
nameOverride: ""
fullnameOverride: ""
namespaceOverride: ""
# Controller settings; installation identity defaults to the actual Pod namespace.
controller:
clusterDomain: cluster.local
# Override only for a deliberate installation-identity migration.
installationNamespace: ""
# Positive whole seconds per Cloudflare API attempt.
cloudflareRequestTimeoutSeconds: 30
# Aggregate limits include the fallback rule and serialized origin settings.
maxIngressRules: 1000
# At least 67 bytes, enough for emergency HTTP 503 withdrawal.
maxConfigurationBytes: 1048576
# Install CRDs with the chart
# Set to false if CRDs are managed separately (e.g., via kubectl apply)
installCRDs: true
# Create RBAC resources (ClusterRole, ClusterRoleBinding)
rbac:
create: true
serviceAccount:
# Specifies whether a service account should be created
create: true
# The name of the service account to use
# If not set and create is true, a name is generated using the fullname template
name: ""
# Annotations to add to the service account
annotations: {}
# Metrics configuration
metrics:
# Port for the metrics endpoint
port: 8080
# Metrics service configuration
service:
enabled: true
port: 8080
annotations: {}
# Prometheus ServiceMonitor configuration
serviceMonitor:
enabled: false
# Namespace for the ServiceMonitor (defaults to release namespace)
namespace: ""
# Scrape interval
interval: 30s
# Additional labels for the ServiceMonitor
labels: {}
# Health probe configuration
health:
port: 8081
# Resource requests and limits
resources:
requests:
cpu: 100m
memory: 128Mi
limits:
cpu: 500m
memory: 256Mi
# Container security context
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
readOnlyRootFilesystem: true
# Pod security context
podSecurityContext:
runAsNonRoot: true
seccompProfile:
type: RuntimeDefault
nodeSelector: {}
tolerations: []
affinity: {}
podAnnotations: {}
podLabels: {}