Konfidence is pre-release software. Concepts and APIs are unstable and subject to change.
Skip to content

konfidence ​

Type: application

Konfidence operator for orchestrating multi-service deployments (with bundled CRDs).

Homepage: https://github.com/konfidence-project/konfidence

Maintainers ​

NameEmailUrl
Konfidence maintainers

Source Code ​

Requirements ​

Kubernetes: >=1.27.0-0

Values ​

KeyTypeDefaultDescription
affinityobject{}Affinity rules for the controller Pod.
api.database.connectionSecretRef.keystring"db-connection"Key inside that Secret holding the connection string.
api.database.connectionSecretRef.namestring""Name of the Secret in the release namespace holding the Postgres connection string. Required when api.session.storageType is db-pg.
api.database.maxConnIdleTimestring"5m"Maximum idle time of a connection.
api.database.maxConnLifetimestring"30m"Maximum lifetime of a connection.
api.database.maxConnsint10Maximum number of open connections.
api.database.minConnsint5Minimum number of idle connections kept open.
api.enabledbooltrueDeploy the API server. When false, all API server resources (Deployment, Service, RBAC) are skipped.
api.envlist[]Additional environment variables for the API server container.
api.extraArgslist[]Extra CLI arguments appended to the API server container args list.
api.hostAliaseslist[]Host aliases added to the API pod. Used by local development to reach an identity provider on the host.
api.image.pullPolicystring"IfNotPresent"API server image pull policy.
api.image.repositorystring"ghcr.io/konfidence-project/api"API server image repository.
api.image.tagstring""API server image tag. Defaults to .Chart.AppVersion when empty.
api.ingress.annotationsobject{}Annotations to add to the Ingress, for example for cert-manager.
api.ingress.classNamestring""IngressClass to use.
api.ingress.enabledboolfalseCreate an Ingress for the API server.
api.ingress.hostslist[{"host":"","paths":[{"path":"/","pathType":"Prefix"}]}]Hosts and paths routed to the API server. host is required on each entry.
api.ingress.tlslist[]TLS configuration of the Ingress.
api.migrations.connectionSecretRef.keystring""Key inside that Secret. Empty uses api.database.connectionSecretRef.key.
api.migrations.connectionSecretRef.namestring""Secret holding the connection string for migrations. Empty uses api.database.connectionSecretRef. Set it when migrations need a role with DDL privileges that the API itself must not have.
api.migrations.enabledbooltrueRun the migration Job. Disable only when you apply migrations outside the chart.
api.migrations.hookWeightstring"0"Helm hook weight relative to other pre-install/pre-upgrade hooks. Lower values run first.
api.migrations.resourcesobject{}Resource requests and limits for the migration Job container.
api.oidc.allowedReturnHostslist[]Hostnames permitted for absolute redirects after login, matched exactly on any port. When empty, only root-relative return paths are accepted.
api.oidc.authorizationURLstring""Authorization endpoint. Defaults to the discovery document when empty.
api.oidc.clientIdstring""OAuth client id registered at the provider.
api.oidc.clientSecretRef.keystring"client-secret"Key inside that Secret holding the client secret.
api.oidc.clientSecretRef.namestring""Name of the Secret in the release namespace holding the client secret.
api.oidc.deviceAuthURLstring""Device authorization endpoint. Defaults to the discovery document when empty.
api.oidc.enabledbooltrueEnable login through an OpenID Connect provider. When true, issuerURL must be set or the API server refuses to start.
api.oidc.issuerURLstring""Issuer URL of the OpenID Connect provider.
api.oidc.jwksCacheTTLstring"15m"How long fetched JWKS signing keys are cached before they are fetched again.
api.oidc.jwksURLstring""JWKS endpoint. Defaults to the discovery document when empty.
api.oidc.pkceEnabledbooltrueUse PKCE for the authorization code flow.
api.oidc.redirectURLstring""Redirect URL registered at the provider, ending in /api/v1/auth/callback.
api.oidc.scopesstring"openid,profile,email"Comma-separated scopes requested at login. Add the scope that makes your provider include group membership, since role bindings match users by group.
api.oidc.stateExpirationstring"15m"Lifetime of the login state parameter.
api.oidc.tokenURLstring""Token endpoint. Defaults to the value from the provider's discovery document when empty.
api.oidc.userInfoURLstring""UserInfo endpoint. Defaults to the discovery document when empty.
api.podAnnotationsobject{}Annotations to add to the API server Pod.
api.podDisruptionBudget.enabledboolfalseEnable the PodDisruptionBudget for the API server.
api.podDisruptionBudget.maxUnavailableint1Maximum number of pods that may be unavailable.
api.podDisruptionBudget.minAvailablestringnilMinimum number of pods that must be available. Set exactly one of minAvailable or maxUnavailable.
api.podLabelsobject{}Labels to add to the API server Pod.
api.replicasint1Number of API server replicas.
api.resourcesobject{}Resource requests and limits for the API server container.
api.server.addrstring":8090"TCP address the API server listens on inside the container.
api.server.logLevelstring"info"Log level of the API server.
api.server.readTimeoutstring"10s"HTTP read timeout.
api.server.shutdownTimeoutstring"15s"Grace period for in-flight requests on shutdown.
api.server.writeTimeoutstring"10s"HTTP write timeout.
api.service.annotationsobject{}Annotations to add to the Service.
api.service.nodePortstring""Node port when type is NodePort.
api.service.portint8090Service port.
api.service.typestring"ClusterIP"Service type. ClusterIP is reachable inside the cluster only.
api.session.cleanupIntervalstring"15m"Interval at which expired sessions are removed.
api.session.cookie.httpOnlybooltrueMark the session cookie HttpOnly.
api.session.cookie.namestring"kden-session"Name of the session cookie.
api.session.cookie.sameSitestring"SameSiteStrictMode"SameSite attribute of the session cookie.
api.session.cookie.securebooltrueMark the session cookie Secure. Browsers then send it over HTTPS only.
api.session.expirationstring"12h"Session lifetime.
api.session.storageTypestring"in-memory"Session storage backend.
api.volumeMountslist[]Extra volume mounts on the API server container.
api.volumeslist[]Extra volumes mounted onto the API server Pod.
containerSecurityContextobject{"allowPrivilegeEscalation":false,"capabilities":{"drop":["ALL"]},"readOnlyRootFilesystem":true}Container-level security context.
controller.controllersstring"*"Comma-separated list of sub-controllers, or "*" for all.
controller.healthProbeBindAddressstring":8081"Bind address for the health probe endpoint.
controller.installbooltrueDeploy the controller. When false, the chart renders only the CRDs (gated by crd.install) and skips Deployment, ServiceAccount, RBAC, Service, ServiceMonitor, and PodDisruptionBudget. Useful for installing CRDs into a local development cluster without running the controller.
controller.leaderElectionbooltrueEnable leader election for the controller.
controller.leaseIdstring"konfidence-operator.konfidence.cloud"Lease ID used for leader election.
controller.metricsBindAddressstring":8080"Bind address for the Prometheus /metrics endpoint. Set to "0" to disable the metrics server entirely (also suppresses the metrics container port, Service, and ServiceMonitor).
crd.annotationsobject{}Extra annotations merged onto every CRD. Useful for tools that inspect CRD metadata (e.g. Argo CD: argocd.argoproj.io/sync-options: ServerSideApply=true to avoid the client-side apply size limit).
crd.installbooltrueApply CRDs alongside the controller. Disable for GitOps setups that manage CRDs out-of-band.
crd.keepbooltrueOn helm uninstall, retain CRDs to protect existing CRs. Strongly recommended.
crd.labelsobject{}Extra labels merged onto every CRD.
envlist[]Additional environment variables for the controller container.
extraArgslist[]Additional command-line arguments passed to the controller binary.
fullnameOverridestring""Override the fully-qualified app name used in resource names.
image.pullPolicystring"IfNotPresent"Operator image pull policy.
image.repositorystring"ghcr.io/konfidence-project/konfidence-operator"Operator image repository.
image.tagstring""Operator image tag. Defaults to .Chart.AppVersion when empty.
imagePullSecretslist[]Image pull secrets for private registries.
nameOverridestring""Override the chart name used in resource names.
nodeSelectorobject{}Node selector for the controller Pod.
podAnnotationsobject{}Annotations to add to the controller Pod.
podDisruptionBudget.enabledboolfalseEnable the PodDisruptionBudget for the controller.
podDisruptionBudget.maxUnavailableint1Maximum number of pods that may be unavailable.
podDisruptionBudget.minAvailablestringnilMinimum number of pods that must be available. Set exactly one of minAvailable or maxUnavailable. Both accept an integer or a percentage string (e.g. "50%").
podLabelsobject{}Labels to add to the controller Pod.
replicasint1Number of controller replicas. Use >= 2 with controller.leaderElection: true for HA.
resourcesobject{"limits":{"cpu":"500m","memory":"512Mi"},"requests":{"cpu":"100m","memory":"128Mi"}}Resource requests and limits for the controller container.
securityContextobject{"runAsNonRoot":true,"runAsUser":65532,"seccompProfile":{"type":"RuntimeDefault"}}Pod-level security context.
serviceAccount.annotationsobject{}Annotations to add to the ServiceAccount.
serviceAccount.createbooltrueCreate a ServiceAccount for the controller.
serviceAccount.namestring""Name of the ServiceAccount to use. Defaults to the fully-qualified app name when empty.
serviceMonitor.enabledboolfalseEnable the ServiceMonitor resource. Requires the monitoring.coreos.com CRDs.
serviceMonitor.intervalstring"30s"Scrape interval.
serviceMonitor.labelsobject{}Extra labels merged onto the ServiceMonitor — typically the label selector your Prometheus instance uses (e.g. release: kube-prometheus).
serviceMonitor.metricRelabelingslist[]Metric relabeling rules applied after scraping.
serviceMonitor.namespacestring""Namespace to create the ServiceMonitor in. Defaults to the release namespace. Override when your Prometheus instance only watches a specific namespace.
serviceMonitor.relabelingslist[]Relabeling rules applied to scraped samples before ingestion.
serviceMonitor.scrapeTimeoutstring"10s"Scrape timeout.
tolerationslist[]Tolerations for the controller Pod.
volumeMountslist[]Extra volume mounts on the manager container, corresponding to volumes.
volumeslist[]Extra volumes mounted onto the manager Pod. Use these for additional secrets, CA bundles, or other files the controller needs at runtime. An emptyDir is always mounted at /tmp (the OCM transfer writes there, and the root filesystem is read-only).
webhook.annotationsobject{}Extra annotations for the ValidatingWebhookConfiguration resource, for example cert-manager.io/inject-ca-from.
webhook.caBundlestring""Base64-encoded CA certificate for the webhook's TLS certificate. Leave empty when using a CA injection mechanism (e.g. cert-manager). REQUIRED for self-signed certificates without an injection mechanism. WARNING: if empty and no injection occurs, the API server skips TLS verification (not recommended).
webhook.certDirstring"/tmp/k8s-webhook-server/serving-certs"Directory inside the container where TLS certificates are mounted. The Secret specified by certificateSecret will be mounted here.
webhook.certificateSecretstring"konfidence-webhook-server-cert"Name of the Secret containing tls.crt and tls.key in the release namespace. You must create this Secret before installing the chart, or set enabled: false.
webhook.enabledbooltrueEnable the validating admission webhooks. Requires the TLS Secret named by webhook.certificateSecret to exist before the controller starts.
webhook.failurePolicystring"Fail"Fail blocks requests if the webhook is unavailable. Set to Ignore for less strict validation (allow requests if the webhook is down).
webhook.labelsobject{}Extra labels for the ValidatingWebhookConfiguration resource.
webhook.portint9443Port the webhook server listens on inside the container.

Autogenerated from chart metadata using helm-docs v1.14.2

EU and German government funding logos

Funded by the European Union – NextGenerationEU.

The views and opinions expressed are solely those of the author(s) and do not necessarily reflect the views of the European Union or the European Commission. Neither the European Union nor the European Commission can be held responsible for them.