DirectorySecurity AdvisoriesPricing
Sign in
Directory
keda logoHELM

keda

Helm chart
Last changed
Request a free trial

Contact our team to test out this Helm chart and related images for free. Please also indicate any other images you would like to evaluate.

Overview
Chart versions
Default values
Chart metadata
Images

Tag:
Compare:

1
# Default values for keda.
2
# This is a YAML-formatted file.
3
# Declare variables to be passed into your templates.
4
5
global:
6
image:
7
# -- Global image registry of KEDA components
8
registry: null
9
# -- DNS config for KEDA components
10
dnsConfig: {}
11
# nameservers:
12
# - 1.2.3.4
13
# searches:
14
# - ns1.svc.cluster-domain.example
15
# - my.dns.search.suffix
16
# options:
17
# - name: ndots
18
# value: "1"
19
# - name: attempts
20
# value: "3"
21
image:
22
keda:
23
# -- Image registry of KEDA operator
24
registry: cgr.dev
25
# -- Image name of KEDA operator
26
repository: chainguard-private/keda
27
# -- Image tag of KEDA operator. Optional, given app version of Helm chart is used by default
28
tag: 2.21.0-r1@sha256:92e30f50d65cd2e54d52f32fbd1f38c13c51d992a7d29e658b7c73574c614872
29
metricsApiServer:
30
# -- Image registry of KEDA Metrics API Server
31
registry: cgr.dev
32
# -- Image name of KEDA Metrics API Server
33
repository: chainguard-private/keda-metrics-apiserver
34
# -- Image tag of KEDA Metrics API Server. Optional, given app version of Helm chart is used by default
35
tag: 2.21.0-r1@sha256:f79222ec5652498ba2647d108054c50a3382d2cbeef2976ee23fe04cadd6ae93
36
webhooks:
37
# -- Image registry of KEDA admission-webhooks
38
registry: cgr.dev
39
# -- Image name of KEDA admission-webhooks
40
repository: chainguard-private/keda-admission-webhooks
41
# -- Image tag of KEDA admission-webhooks . Optional, given app version of Helm chart is used by default
42
tag: 2.21.0-r1@sha256:0fbd35ac85de44f1d79579901cd875882ad58611d70575fc71ce05da17fc26cd
43
# -- Image pullPolicy for all KEDA components
44
pullPolicy: Always
45
# -- Kubernetes cluster name. Used in features such as emitting CloudEvents
46
clusterName: kubernetes-default
47
# -- Kubernetes cluster domain
48
clusterDomain: cluster.local
49
crds:
50
# -- Defines whether the KEDA CRDs have to be installed or not.
51
install: true
52
# -- Custom annotations specifically for CRDs
53
additionalAnnotations: {}
54
# foo: bar
55
# -- Defines Kubernetes namespaces to watch to scale their workloads. Default watches all namespaces
56
watchNamespace: ""
57
# -- Restricts the operator to reconcile only ScaledObjects and ScaledJobs (and their derived
58
# HorizontalPodAutoscalers) matching the given Kubernetes label selector. Default (empty) means
59
# no label-based filtering. Mirrors `watchNamespace`, but filters by label instead of by namespace.
60
# Examples: "environment=production", "tier in (gold,silver)", "!canary"
61
watchLabelSelector: ""
62
# -- Restricts the operator to reconcile only TriggerAuthentications and ClusterTriggerAuthentications
63
# matching the given Kubernetes label selector. Default (empty) means no label-based filtering.
64
# Decoupled from `watchLabelSelector` so a single cluster-scoped ClusterTriggerAuthentication can be
65
# shared across operators scoped to different label selectors.
66
watchLabelSelectorForTriggerauth: ""
67
# -- Name of secret to use to pull images to use to pull Docker images
68
imagePullSecrets: []
69
networkPolicy:
70
# -- Enable network policies
71
enabled: false
72
# -- Flavor of the network policies (cilium, kubernetes)
73
flavor: "cilium"
74
# -- Allow use of extra egress rules for cilium network policies
75
cilium:
76
operator:
77
extraEgressRules: []
78
# -- Allow use of extra egress rules for kubernetes network policies
79
kubernetes:
80
operator:
81
extraEgressRules: []
82
metricsServer:
83
extraEgressRules: []
84
webhooks:
85
extraEgressRules: []
86
operator:
87
serviceAccountTokens:
88
# -- Token audience policy for Vault and boundServiceAccountToken. When configured as "legacy", it disables enforcement and cannot be combined with configured audiences.
89
mode: enforce-audience # enforce-audience, legacy
90
# -- Approved audiences for extra token files; creates no mounts or minting defaults. Use audiences not accepted by kube-apiserver. Combined audience config.
91
additionalAllowedAudiences: []
92
# -- Optional endpoint filter, passed as KEDA_OUTBOUND_FILTER. Empty disables filtering. Max 64 KiB.
93
outboundFilter: {}
94
# Example policy (replace {} above):
95
# hashiCorpVault:
96
# mode: "off" # off, warn, or enforce
97
# allowedEndpoints: [] # exact HTTP(S) origins; empty denies all in enforce mode
98
# -- Name of the KEDA operator
99
name: keda-operator
100
# -- Additional KEDA Operator container environment variables
101
env: []
102
# - name: ENV_NAME
103
# value: 'ENV-VALUE'
104
# -- ReplicaSets for this Deployment you want to retain (Default: 10)
105
revisionHistoryLimit: 10
106
# -- Capability to configure the number of replicas for KEDA operator.
107
# While you can run more replicas of our operator, only one operator instance will be the leader and serving traffic.
108
# You can run multiple replicas, but they will not improve the performance of KEDA, it could only reduce downtime during a failover.
109
# Learn more in [our documentation](https://keda.sh/docs/latest/operate/cluster/#high-availability).
110
replicaCount: 1
111
# --Disable response compression for k8s restAPI in client-go.
112
# Disabling compression simply means that turns off the process of making data smaller for K8s restAPI in client-go for faster transmission.
113
disableCompression: true
114
# -- Port for the gRPC Metrics Service endpoint that the KEDA operator binds to and the metrics server connects to.
115
metricsServiceTargetPort: 9666
116
# -- Leader election ID (Lease resource name) for the controller manager. Defaults to operator.keda.sh.
117
# Override to allow multiple independent KEDA operator deployments in the same namespace.
118
# leaderElectionID: "operator.keda.sh"
119
# -- DNS config for KEDA operator pod
120
dnsConfig: {}
121
# use ClusterFirstWithHostNet if `useHostNetwork: true` https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-s-dns-policy
122
# -- Defined the DNS policy for the operator
123
dnsPolicy: ClusterFirst
124
# -- Enable operator to use host network
125
useHostNetwork: false
126
# -- (bool) Sets `hostUsers` on the KEDA operator pod. Leave unset to preserve the cluster default, `false` to run the pod in its own [user namespace](https://kubernetes.io/docs/concepts/workloads/pods/user-namespaces/), or `true` to explicitly use the host user namespace.
127
hostUsers:
128
# -- [Affinity] for pod scheduling for KEDA operator. Takes precedence over the `affinity` field
129
affinity: {}
130
# podAntiAffinity:
131
# requiredDuringSchedulingIgnoredDuringExecution:
132
# - labelSelector:
133
# matchExpressions:
134
# - key: app
135
# operator: In
136
# values:
137
# - keda-operator
138
# topologyKey: "kubernetes.io/hostname"
139
# -- Additional containers to run as part of the operator deployment
140
extraContainers: []
141
# - name: hello-many
142
# args:
143
# - -c
144
# - "while true; do echo hi; sleep 300; done"
145
# command:
146
# - /bin/sh
147
# image: 'busybox:glibc'
148
# -- Additional init containers to run as part of the operator deployment
149
extraInitContainers: []
150
# - name: hello-once
151
# args:
152
# - -c
153
# - "echo 'Hello World!'"
154
# command:
155
# - /bin/sh
156
# image: 'busybox:glibc'
157
# -- Liveness probes for operator ([docs](https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-startup-probes/))
158
livenessProbe:
159
initialDelaySeconds: 25
160
periodSeconds: 10
161
timeoutSeconds: 1
162
failureThreshold: 3
163
successThreshold: 1
164
# -- Readiness probes for operator ([docs](https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-startup-probes/#define-readiness-probes))
165
readinessProbe:
166
initialDelaySeconds: 20
167
periodSeconds: 3
168
timeoutSeconds: 1
169
failureThreshold: 3
170
successThreshold: 1
171
# -- Node selector for pod scheduling ([docs](https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/))
172
nodeSelector: {}
173
# -- Tolerations for pod scheduling ([docs](https://kubernetes.io/docs/concepts/scheduling-eviction/taint-and-toleration/))
174
tolerations: []
175
# -- Additional timeout beyond the ScaledObject or ScaledJob polling interval for Kubernetes API operations in scaling loops. Setting `0s` uses the polling interval as the timeout; the timeout cannot be disabled
176
kubernetesApiTimeout: 5s
177
metricsServer:
178
# -- Enable KEDA metrics server.
179
enabled: true
180
# -- Enable registering KEDA metrics server as external metrics API resource.
181
registerAPIService: true
182
# -- Additional Metrics Adapter container environment variables
183
env: []
184
# - name: ENV_NAME
185
# value: 'ENV-VALUE'
186
# -- ReplicaSets for this Deployment you want to retain (Default: 10)
187
revisionHistoryLimit: 10
188
# -- Capability to configure the number of replicas for KEDA metric server.
189
# While you can run more replicas of our metric server, only one instance will used and serve traffic.
190
# You can run multiple replicas, but they will not improve the performance of KEDA, it could only reduce downtime during a failover.
191
# Learn more in [our documentation](https://keda.sh/docs/latest/operate/cluster/#high-availability).
192
replicaCount: 1
193
# --Disable response compression for k8s restAPI in client-go.
194
# Disabling compression simply means that turns off the process of making data smaller for K8s restAPI in client-go for faster transmission.
195
disableCompression: true
196
# use ClusterFirstWithHostNet if `useHostNetwork: true` https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-s-dns-policy
197
# -- Defined the DNS policy for the metric server
198
dnsPolicy: ClusterFirst
199
# -- DNS config for KEDA metrics server pod
200
dnsConfig: {}
201
# -- Enable metric server to use host network
202
useHostNetwork: false
203
# -- (bool) Sets `hostUsers` on the KEDA metrics server pod. Leave unset to preserve the cluster default, `false` to run the pod in its own [user namespace](https://kubernetes.io/docs/concepts/workloads/pods/user-namespaces/), or `true` to explicitly use the host user namespace.
204
hostUsers:
205
# -- [Affinity] for pod scheduling for Metrics API Server. Takes precedence over the `affinity` field
206
affinity: {}
207
# podAntiAffinity:
208
# requiredDuringSchedulingIgnoredDuringExecution:
209
# - labelSelector:
210
# matchExpressions:
211
# - key: app
212
# operator: In
213
# values:
214
# - keda-operator-metrics-apiserver
215
# topologyKey: "kubernetes.io/hostname"
216
# -- Liveness probes for Metrics API Server ([docs](https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-startup-probes/))
217
livenessProbe:
218
initialDelaySeconds: 5
219
periodSeconds: 10
220
timeoutSeconds: 1
221
failureThreshold: 3
222
successThreshold: 1
223
# -- Readiness probes for Metrics API Server ([docs](https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-startup-probes/#define-readiness-probes))
224
readinessProbe:
225
initialDelaySeconds: 5
226
periodSeconds: 3
227
timeoutSeconds: 1
228
failureThreshold: 3
229
successThreshold: 1
230
# -- Node selector for pod scheduling ([docs](https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/))
231
nodeSelector: {}
232
# -- Tolerations for pod scheduling ([docs](https://kubernetes.io/docs/concepts/scheduling-eviction/taint-and-toleration/))
233
tolerations: []
234
webhooks:
235
# It also used to enable or disable webhook patching in the operator
236
enabled: true
237
# -- Additional KEDA admission webhook container environment variables
238
env: []
239
# - name: ENV_NAME
240
# value: 'ENV-VALUE'
241
# -- Port number to use for KEDA admission webhooks. Default is 9443.
242
port: ""
243
# -- Port number to use for KEDA admission webhooks health probe
244
healthProbePort: 8081
245
# -- DNS config for KEDA admission webhooks pod
246
dnsConfig: {}
247
# -- Liveness probes for admission webhooks ([docs](https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-startup-probes/))
248
livenessProbe:
249
initialDelaySeconds: 25
250
periodSeconds: 10
251
timeoutSeconds: 1
252
failureThreshold: 3
253
successThreshold: 1
254
# -- Readiness probes for admission webhooks ([docs](https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-startup-probes/#define-readiness-probes))
255
readinessProbe:
256
initialDelaySeconds: 20
257
periodSeconds: 3
258
timeoutSeconds: 1
259
failureThreshold: 3
260
successThreshold: 1
261
# -- Timeout in seconds for KEDA admission webhooks
262
timeoutSeconds: 10
263
# -- Enable webhook to use host network, this is required on EKS with custom CNI
264
useHostNetwork: false
265
# -- (bool) Sets `hostUsers` on the KEDA admission webhooks pod. Leave unset to preserve the cluster default, `false` to run the pod in its own [user namespace](https://kubernetes.io/docs/concepts/workloads/pods/user-namespaces/), or `true` to explicitly use the host user namespace.
266
hostUsers:
267
# -- Name of the KEDA admission webhooks
268
name: keda-admission-webhooks
269
# -- ReplicaSets for this Deployment you want to retain (Default: 10)
270
revisionHistoryLimit: 10
271
# -- Capability to configure the number of replicas for KEDA admission webhooks
272
replicaCount: 1
273
# -- [Affinity] for pod scheduling for KEDA admission webhooks. Takes precedence over the `affinity` field
274
affinity: {}
275
# podAntiAffinity:
276
# requiredDuringSchedulingIgnoredDuringExecution:
277
# - labelSelector:
278
# matchExpressions:
279
# - key: app
280
# operator: In
281
# values:
282
# - keda-admission-webhooks
283
# topologyKey: "kubernetes.io/hostname"
284
285
# -- [Failure policy](https://kubernetes.io/docs/reference/access-authn-authz/extensible-admission-controllers/#failure-policy) to use with KEDA admission webhooks
286
failurePolicy: Ignore
287
# -- Node selector for pod scheduling ([docs](https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/))
288
nodeSelector: {}
289
# -- Tolerations for pod scheduling ([docs](https://kubernetes.io/docs/concepts/scheduling-eviction/taint-and-toleration/))
290
tolerations: []
291
upgradeStrategy:
292
# -- Capability to configure [Deployment upgrade strategy] for operator
293
operator: {}
294
# type: RollingUpdate
295
# rollingUpdate:
296
# maxUnavailable: 1
297
# maxSurge: 1
298
299
# -- Capability to configure [Deployment upgrade strategy] for Metrics Api Server
300
metricsApiServer: {}
301
# type: RollingUpdate
302
# rollingUpdate:
303
# maxUnavailable: 1
304
# maxSurge: 1
305
306
# -- Capability to configure [Deployment upgrade strategy] for Admission webhooks
307
webhooks: {}
308
# type: RollingUpdate
309
# rollingUpdate:
310
# maxUnavailable: 1
311
# maxSurge: 1
312
podDisruptionBudget:
313
# -- Capability to configure [Pod Disruption Budget]
314
operator: {}
315
# minAvailable: 1
316
# maxUnavailable: 1
317
318
# -- Capability to configure [Pod Disruption Budget]
319
metricServer: {}
320
# minAvailable: 1
321
# maxUnavailable: 1
322
323
# -- Capability to configure [Pod Disruption Budget]
324
webhooks: {}
325
# minAvailable: 1
326
# maxUnavailable: 1
327
# -- Custom labels to add into metadata
328
additionalLabels: {}
329
# foo: bar
330
331
# -- Custom annotations to add into metadata
332
additionalAnnotations: {}
333
# foo: bar
334
335
podAnnotations:
336
# -- Pod annotations for KEDA operator
337
keda: {}
338
# -- Pod annotations for KEDA Metrics Adapter
339
metricsAdapter: {}
340
# -- Pod annotations for KEDA Admission webhooks
341
webhooks: {}
342
podLabels:
343
# -- Pod labels for KEDA operator
344
keda: {}
345
# -- Pod labels for KEDA Metrics Adapter
346
metricsAdapter: {}
347
# -- Pod labels for KEDA Admission webhooks
348
webhooks: {}
349
rbac:
350
# -- Specifies whether RBAC should be used
351
create: true
352
# -- Specifies whether RBAC for CRDs should be [aggregated](https://kubernetes.io/docs/reference/access-authn-authz/rbac/#aggregated-clusterroles) to default roles (view, edit, admin)
353
aggregateToDefaultRoles: false
354
# -- Whether RBAC for configured CRDs that can have a `scale` subresource should be created
355
enabledCustomScaledRefKinds: true
356
# -- Customize the namespace of k8s metrics-server deployment
357
# This could also be achieved by the Kubernetes control plane manager flag --use-service-account-credentials:
358
# [docs](https://kubernetes.io/docs/reference/command-line-tools-reference/kube-controller-manager/)
359
controlPlaneServiceAccountsNamespace: kube-system
360
# -- List of custom resources that support the `scale` subresource and can be referenced by `scaledobject.spec.scaleTargetRef`.
361
# The feature needs to be also enabled by `enabledCustomScaledRefKinds`.
362
# If left empty, RBAC for `apiGroups: *` and `resources: *, */scale` will be created
363
# note: Deployments and StatefulSets are supported out of the box
364
scaledRefKinds:
365
- apiGroup: "*"
366
kind: "*"
367
# - apiGroup: argoproj.io
368
# kind: Rollout
369
serviceAccount:
370
operator:
371
# -- Specifies whether a service account should be created
372
create: true
373
# -- The name of the service account to use.
374
name: keda-operator
375
# -- Specifies whether a service account should automount API-Credentials
376
automountServiceAccountToken: true
377
# -- Annotations to add to the service account
378
annotations: {}
379
metricServer:
380
# -- Specifies whether a service account should be created
381
create: true
382
# -- The name of the service account to use.
383
name: keda-metrics-server
384
# -- Specifies whether a service account should automount API-Credentials
385
automountServiceAccountToken: true
386
# -- Annotations to add to the service account
387
annotations: {}
388
webhooks:
389
# -- Specifies whether a service account should be created
390
create: true
391
# -- The name of the service account to use.
392
name: keda-webhook
393
# -- Specifies whether a service account should automount API-Credentials
394
automountServiceAccountToken: true
395
# -- Annotations to add to the service account
396
annotations: {}
397
podIdentity:
398
azureWorkload:
399
# -- Set to true to enable Azure Workload Identity usage.
400
# See https://keda.sh/docs/concepts/authentication/#azure-workload-identity
401
# This will be set as a label on the KEDA service account.
402
enabled: false
403
# Set to the value of the Azure Active Directory Client and Tenant Ids
404
# respectively. These will be set as annotations on the KEDA service account.
405
# -- Id of Azure Active Directory Client to use for authentication with Azure Workload Identity. ([docs](https://keda.sh/docs/concepts/authentication/#azure-workload-identity))
406
clientId: ""
407
# -- Id Azure Active Directory Tenant to use for authentication with for Azure Workload Identity. ([docs](https://keda.sh/docs/concepts/authentication/#azure-workload-identity))
408
tenantId: ""
409
# Set to the value of the service account token expiration duration.
410
# This will be set as an annotation on the KEDA service account.
411
# -- Duration in seconds to automatically expire tokens for the service account. ([docs](https://keda.sh/docs/concepts/authentication/#azure-workload-identity))
412
tokenExpiration: 3600
413
aws:
414
irsa:
415
# -- Specifies whether [AWS IAM Roles for Service Accounts (IRSA)](https://docs.aws.amazon.com/eks/latest/userguide/iam-roles-for-service-accounts.html) is to be enabled or not.
416
enabled: false
417
# -- Sets the token audience for IRSA.
418
# This will be set as an annotation on the KEDA service account.
419
audience: "sts.amazonaws.com"
420
# -- Set to the value of the ARN of an IAM role with a web identity provider.
421
# This will be set as an annotation on the KEDA service account.
422
roleArn: ""
423
# -- Sets the use of an STS regional endpoint instead of global.
424
# Recommended to use regional endpoint in almost all cases.
425
# This will be set as an annotation on the KEDA service account.
426
stsRegionalEndpoints: "true"
427
# -- Set to the value of the service account token expiration duration.
428
# This will be set as an annotation on the KEDA service account.
429
tokenExpiration: 86400
430
gcp:
431
# -- Set to true to enable GCP Workload Identity.
432
# See https://keda.sh/docs/2.10/authentication-providers/gcp-workload-identity/
433
# This will be set as a annotation on the KEDA service account.
434
enabled: false
435
# -- GCP IAM Service Account Email which you would like to use for workload identity.
436
gcpIAMServiceAccount: ""
437
# -- Set this if you are using an external scaler and want to communicate
438
# over TLS (recommended). This variable holds the name of the secret that
439
# will be mounted to the /grpccerts path on the Pod
440
grpcTLSCertsSecret: ""
441
# -- Set this if you are using HashiCorp Vault and want to communicate
442
# over TLS (recommended). This variable holds the name of the secret that
443
# will be mounted to the /vault path on the Pod
444
hashiCorpVaultTLS: ""
445
hashiCorpVault:
446
kubernetesAuth:
447
# -- Projected operator-token audience, also globally approved. Empty disables projection; does not configure named-SA minting. Use an audience not accepted by kube-apiserver.
448
audience: vault
449
# -- Mount directory for the Vault token (<path>/token). Empty/null disables projection and implicit file selection; explicit TA token paths remain usable.
450
projectedTokenMountPath: /var/run/secrets/keda-vault
451
logging:
452
operator:
453
# -- Logging level for KEDA Operator.
454
# allowed values: `debug`, `info`, `error`, or an integer value greater than 0, specified as string
455
level: info
456
# -- Logging format for KEDA Operator.
457
# allowed values: `json` or `console`
458
format: console
459
# -- Logging time encoding for KEDA Operator.
460
# allowed values are `epoch`, `millis`, `nano`, `iso8601`, `rfc3339` or `rfc3339nano`
461
timeEncoding: rfc3339
462
# -- If enabled, the stack traces will be also printed
463
stackTracesEnabled: false
464
metricServer:
465
# -- Logging level for Metrics Server (Deprecated).
466
# allowed values: `0` for info, `4` for debug, or an integer value greater than 0, specified as string
467
level: 0
468
# -- Logging stderrthreshold for Metrics Server (Deprecated)
469
# allowed values: 'DEBUG','INFO','WARN','ERROR','ALERT','EMERG'
470
stderrthreshold: ERROR
471
# -- Zap Logging level for Metrics Server.
472
# allowed values: `debug`, `info`, `error`, or an integer value greater than 0, specified as string
473
zapLevel: info
474
# -- Zap Logging encoder for Metrics Server.
475
# allowed values: `json` or `console`
476
zapEncoder: console
477
# -- Zap logging time encoding for Metrics Server.
478
# allowed values are `epoch`, `millis`, `nano`, `iso8601`, `rfc3339` or `rfc3339nano`
479
zapTimeEncoding: rfc3339
480
webhooks:
481
# -- Logging level for KEDA Operator.
482
# allowed values: `debug`, `info`, `error`, or an integer value greater than 0, specified as string
483
level: info
484
# -- Logging format for KEDA Admission webhooks.
485
# allowed values: `json` or `console`
486
format: console
487
# -- Logging time encoding for KEDA Operator.
488
# allowed values are `epoch`, `millis`, `nano`, `iso8601`, `rfc3339` or `rfc3339nano`
489
timeEncoding: rfc3339
490
# -- [Security context] for all containers
491
# @default -- [See below](#KEDA-is-secure-by-default)
492
securityContext:
493
# -- [Security context] of the operator container
494
# @default -- [See below](#KEDA-is-secure-by-default)
495
operator:
496
capabilities:
497
drop:
498
- ALL
499
allowPrivilegeEscalation: false
500
readOnlyRootFilesystem: true
501
seccompProfile:
502
type: RuntimeDefault
503
# -- [Security context] of the metricServer container
504
# @default -- [See below](#KEDA-is-secure-by-default)
505
metricServer:
506
capabilities:
507
drop:
508
- ALL
509
allowPrivilegeEscalation: false
510
readOnlyRootFilesystem: true
511
seccompProfile:
512
type: RuntimeDefault
513
# -- [Security context] of the admission webhooks container
514
# @default -- [See below](#KEDA-is-secure-by-default)
515
webhooks:
516
capabilities:
517
drop:
518
- ALL
519
allowPrivilegeEscalation: false
520
readOnlyRootFilesystem: true
521
seccompProfile:
522
type: RuntimeDefault
523
# -- [Pod security context] for all pods
524
# @default -- [See below](#KEDA-is-secure-by-default)
525
podSecurityContext:
526
# -- [Pod security context] of the KEDA operator pod
527
# @default -- [See below](#KEDA-is-secure-by-default)
528
operator:
529
runAsNonRoot: true
530
# runAsUser: 1000
531
# runAsGroup: 1000
532
# fsGroup: 1000
533
# -- [Pod security context] of the KEDA metrics apiserver pod
534
# @default -- [See below](#KEDA-is-secure-by-default)
535
metricServer:
536
runAsNonRoot: true
537
# runAsUser: 1000
538
# runAsGroup: 1000
539
# fsGroup: 1000
540
# -- [Pod security context] of the KEDA admission webhooks
541
# @default -- [See below](#KEDA-is-secure-by-default)
542
webhooks:
543
runAsNonRoot: true
544
# runAsUser: 1000
545
# runAsGroup: 1000
546
# fsGroup: 1000
547
service:
548
# -- KEDA Metric Server service type
549
type: ClusterIP
550
# -- HTTPS port for KEDA Metric Server service
551
portHttps: 443
552
# -- HTTPS port for KEDA Metric Server container
553
portHttpsTarget: 6443
554
# -- Annotations to add the KEDA Metric Server service
555
annotations: {}
556
# -- The minimum TLS version to use when KEDA components provide a TLS-enabled service.
557
minTlsVersion: "TLS13"
558
# -- The list of cipher suites to use when KEDA components provide a TLS-enabled service. When left empty or unset, the TLS implementation will provide a default list of cipher suites which are believed to be secure.
559
tlsCipherList: ""
560
# We provides the default values that we describe in our docs:
561
# https://keda.sh/docs/latest/operate/cluster/
562
# If you want to specify the resources (or totally remove the defaults), change or comment the following
563
# lines, adjust them as necessary, or simply add the curly braces after 'operator' and/or 'metricServer'
564
# and remove/comment the default values
565
resources:
566
# -- Manage [resource request & limits] of KEDA operator pod
567
operator:
568
limits:
569
cpu: 1
570
memory: 1000Mi
571
requests:
572
cpu: 100m
573
memory: 100Mi
574
# -- Manage [resource request & limits] of KEDA metrics apiserver pod
575
metricServer:
576
limits:
577
cpu: 1
578
memory: 1000Mi
579
requests:
580
cpu: 100m
581
memory: 100Mi
582
# -- Manage [resource request & limits] of KEDA admission webhooks pod
583
webhooks:
584
limits:
585
cpu: 1
586
memory: 1000Mi
587
requests:
588
cpu: 100m
589
memory: 100Mi
590
# -- Node selector for pod scheduling ([docs](https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/))
591
nodeSelector: {}
592
# -- Tolerations for pod scheduling ([docs](https://kubernetes.io/docs/concepts/scheduling-eviction/taint-and-toleration/))
593
tolerations: []
594
# -- HostAliases for pod networking ([docs](https://kubernetes.io/docs/concepts/services-networking/add-entries-to-pod-etc-hosts-with-host-aliases/))
595
hostAliases: []
596
topologySpreadConstraints:
597
# -- [Pod Topology Constraints] of KEDA operator pod
598
operator: []
599
# -- [Pod Topology Constraints] of KEDA metrics apiserver pod
600
metricsServer: []
601
# -- [Pod Topology Constraints] of KEDA admission webhooks pod
602
webhooks: []
603
# -- [Affinity] for pod scheduling for KEDA operator, Metrics API Server and KEDA admission webhooks.
604
affinity: {}
605
# podAntiAffinity:
606
# requiredDuringSchedulingIgnoredDuringExecution:
607
# - labelSelector:
608
# matchExpressions:
609
# - key: app
610
# operator: In
611
# values:
612
# - keda-operator
613
# - keda-operator-metrics-apiserver
614
# - keda-admission-webhooks
615
# topologyKey: "kubernetes.io/hostname"
616
617
# -- priorityClassName for all KEDA components
618
priorityClassName: ""
619
## The default HTTP timeout in milliseconds that KEDA should use
620
## when making requests to external services. Removing this defaults to a
621
## reasonable default
622
http:
623
# -- The default HTTP timeout to use for all scalers that use raw HTTP clients (some scalers use SDKs to access target services. These have built-in HTTP clients, and the timeout does not necessarily apply to them)
624
timeout: 3000
625
# -- Maximum number of idle HTTP connections across all hosts. Zero means no limit.
626
maxIdleConns: 0
627
# -- Maximum number of idle HTTP connections to keep per host
628
maxIdleConnsPerHost: 1000
629
# -- Maximum time an idle HTTP connection remains in the pool. Must be greater than zero.
630
idleConnTimeout: 90s
631
keepAlive:
632
# -- Enable HTTP connection keep alive
633
enabled: true
634
# -- The minimum TLS version to use for all scalers that use raw HTTP clients (some scalers use SDKs to access target services. These have built-in HTTP clients, and this value does not necessarily apply to them)
635
minTlsVersion: TLS12
636
# -- The list of cipher suites to use when making HTTP over TLS connections. When left empty or unset, the TLS implementation will provide a default list of cipher suites which are believed to be secure.
637
tlsCipherList: ""
638
## This setting lets you enable profiling for all of the components of KEDA and in the specific port you choose
639
## This can be useful when trying to investigate errors like memory leaks or CPU or even look at goroutines to understand better
640
## This setting is disabled by default
641
profiling:
642
operator:
643
# -- Enable profiling for KEDA operator
644
enabled: false
645
# -- Expose profiling on a specific port
646
port: 8082
647
metricsServer:
648
# -- Enable profiling for KEDA metrics server
649
enabled: false
650
# -- Expose profiling on a specific port
651
port: 8083
652
webhooks:
653
# -- Enable profiling for KEDA admission webhook
654
enabled: false
655
# -- Expose profiling on a specific port
656
port: 8084
657
## Extra KEDA Operator, Metrics Adapter and Admission Webhooks container arguments
658
extraArgs:
659
# -- Additional KEDA Operator container arguments
660
keda: {}
661
# -- Additional Metrics Adapter container arguments
662
metricsAdapter: {}
663
# -- Additional KEDA admission webhooks container arguments
664
webhooks: {}
665
# Example:
666
# webhooks:
667
# cache-miss-to-direct-client: "true"
668
# -- Additional environment variables that will be passed onto all KEDA components
669
env: []
670
# - name: ENV_NAME
671
# value: 'ENV-VALUE'
672
673
# Extra volumes and volume mounts for the deployment. Optional.
674
volumes:
675
keda:
676
# -- Extra volumes for KEDA deployment
677
extraVolumes: []
678
# -- Extra volume mounts for KEDA deployment
679
extraVolumeMounts: []
680
metricsApiServer:
681
# -- Extra volumes for metric server deployment
682
extraVolumes: []
683
# -- Extra volume mounts for metric server deployment
684
extraVolumeMounts: []
685
webhooks:
686
# -- Extra volumes for admission webhooks deployment
687
extraVolumes: []
688
# -- Extra volume mounts for admission webhooks deployment
689
extraVolumeMounts: []
690
prometheus:
691
metricServer:
692
# -- Enable metric server Prometheus metrics expose
693
enabled: false
694
# -- HTTP port used for exposing metrics server prometheus metrics
695
port: 8080
696
# -- HTTP port name for exposing metrics server prometheus metrics
697
portName: metrics
698
# -- App Protocol for service when scraping metrics endpoint
699
# appProtocol: http
700
serviceMonitor:
701
# -- Enables ServiceMonitor creation for the Prometheus Operator
702
enabled: false
703
# -- JobLabel selects the label from the associated Kubernetes service which will be used as the job label for all metrics. [ServiceMonitor Spec]
704
jobLabel: ""
705
# -- TargetLabels transfers labels from the Kubernetes `Service` onto the created metrics
706
targetLabels: []
707
# -- PodTargetLabels transfers labels on the Kubernetes `Pod` onto the created metrics
708
podTargetLabels: []
709
# -- Name of the service port this endpoint refers to. Mutually exclusive with targetPort
710
port: metrics
711
# -- Name or number of the target port of the Pod behind the Service, the port must be specified with container port property. Mutually exclusive with port
712
targetPort: ""
713
# -- Interval at which metrics should be scraped If not specified Prometheus’ global scrape interval is used.
714
interval: ""
715
# -- Timeout after which the scrape is ended If not specified, the Prometheus global scrape timeout is used unless it is less than Interval in which the latter is used
716
scrapeTimeout: ""
717
# -- DEPRECATED. List of expressions that define custom relabeling rules for metric server ServiceMonitor crd (prometheus operator). [RelabelConfig Spec]
718
relabellings: []
719
# -- List of expressions that define custom relabeling rules for metric server ServiceMonitor crd (prometheus operator). [RelabelConfig Spec]
720
relabelings: []
721
# -- List of expressions that define custom metric relabeling rules for metric server ServiceMonitor crd after scrape has happened (prometheus operator). [RelabelConfig Spec]
722
metricRelabelings: []
723
# -- Additional labels to add for metric server using ServiceMonitor crd (prometheus operator)
724
additionalLabels: {}
725
# -- HTTP scheme used for scraping. Defaults to `http`
726
scheme: http
727
# -- TLS configuration for scraping metrics
728
tlsConfig: {}
729
# caFile: /etc/prom-certs/root-cert.pem
730
# certFile: /etc/prom-certs/cert-chain.pem
731
# insecureSkipVerify: true
732
# keyFile: /etc/prom-certs/key.pem
733
podMonitor:
734
# -- Enables PodMonitor creation for the Prometheus Operator
735
enabled: false
736
# -- Scraping interval for metric server using podMonitor crd (prometheus operator)
737
interval: ""
738
# -- Scraping timeout for metric server using podMonitor crd (prometheus operator)
739
scrapeTimeout: ""
740
# -- Scraping namespace for metric server using podMonitor crd (prometheus operator)
741
namespace: ""
742
# -- Additional labels to add for metric server using podMonitor crd (prometheus operator)
743
additionalLabels: {}
744
# -- List of expressions that define custom relabeling rules for metric server podMonitor crd (prometheus operator)
745
relabelings: []
746
# -- List of expressions that define custom metric relabeling rules for metric server PodMonitor crd after scrape has happened (prometheus operator). [RelabelConfig Spec]
747
metricRelabelings: []
748
operator:
749
# -- Enable KEDA Operator prometheus metrics expose
750
enabled: false
751
# -- Port used for exposing KEDA Operator prometheus metrics
752
port: 8080
753
# -- App Protocol for service when scraping metrics endpoint
754
# appProtocol: http
755
serviceMonitor:
756
# -- Enables ServiceMonitor creation for the Prometheus Operator
757
enabled: false
758
# -- JobLabel selects the label from the associated Kubernetes service which will be used as the job label for all metrics. [ServiceMonitor Spec]
759
jobLabel: ""
760
# -- TargetLabels transfers labels from the Kubernetes `Service` onto the created metrics
761
targetLabels: []
762
# -- PodTargetLabels transfers labels on the Kubernetes `Pod` onto the created metrics
763
podTargetLabels: []
764
# -- Name of the service port this endpoint refers to. Mutually exclusive with targetPort
765
port: metrics
766
# -- Name or number of the target port of the Pod behind the Service,
767
# the port must be specified with container port property. Mutually exclusive with port
768
targetPort: ""
769
# -- Interval at which metrics should be scraped If not specified Prometheus’ global scrape interval is used.
770
interval: ""
771
# -- Timeout after which the scrape is ended If not specified, the Prometheus global scrape timeout is used unless it is less than Interval in which the latter is used
772
scrapeTimeout: ""
773
# -- DEPRECATED. List of expressions that define custom relabeling rules for metric server ServiceMonitor crd (prometheus operator). [RelabelConfig Spec]
774
relabellings: []
775
# -- List of expressions that define custom relabeling rules for metric server ServiceMonitor crd (prometheus operator). [RelabelConfig Spec]
776
relabelings: []
777
# -- List of expressions that define custom metric relabeling rules for metric server ServiceMonitor crd after scrape has happened (prometheus operator). [RelabelConfig Spec]
778
metricRelabelings: []
779
# -- Additional labels to add for metric server using ServiceMonitor crd (prometheus operator)
780
additionalLabels: {}
781
# -- HTTP scheme used for scraping. Defaults to `http`
782
scheme: http
783
# -- TLS configuration for scraping metrics
784
tlsConfig: {}
785
# caFile: /etc/prom-certs/root-cert.pem
786
# certFile: /etc/prom-certs/cert-chain.pem
787
# insecureSkipVerify: true
788
# keyFile: /etc/prom-certs/key.pem
789
podMonitor:
790
# -- Enables PodMonitor creation for the Prometheus Operator
791
enabled: false
792
# -- Scraping interval for KEDA Operator using podMonitor crd (prometheus operator)
793
interval: ""
794
# -- Scraping timeout for KEDA Operator using podMonitor crd (prometheus operator)
795
scrapeTimeout: ""
796
# -- Scraping namespace for KEDA Operator using podMonitor crd (prometheus operator)
797
namespace: ""
798
# -- Additional labels to add for KEDA Operator using podMonitor crd (prometheus operator)
799
additionalLabels: {}
800
# -- List of expressions that define custom relabeling rules for KEDA Operator podMonitor crd (prometheus operator)
801
relabelings: []
802
# -- List of expressions that define custom metric relabeling rules for metric server PodMonitor crd after scrape has happened (prometheus operator). [RelabelConfig Spec]
803
metricRelabelings: []
804
prometheusRules:
805
# -- Enables PrometheusRules creation for the Prometheus Operator
806
enabled: false
807
# -- Scraping namespace for KEDA Operator using prometheusRules crd (prometheus operator)
808
namespace: ""
809
# -- Additional labels to add for KEDA Operator using prometheusRules crd (prometheus operator)
810
additionalLabels: {}
811
# -- Additional alerts to add for KEDA Operator using prometheusRules crd (prometheus operator)
812
alerts: []
813
# - alert: KedaScalerErrors
814
# annotations:
815
# description: Keda scaledObject {{ $labels.scaledObject }} is experiencing errors with {{ $labels.scaler }} scaler
816
# summary: Keda Scaler {{ $labels.scaler }} Errors
817
# expr: sum by ( scaledObject , scaler) (rate(keda_metrics_adapter_scaler_errors[2m])) > 0
818
# for: 2m
819
# labels:
820
webhooks:
821
# -- Enable KEDA admission webhooks prometheus metrics expose
822
enabled: false
823
# -- Port used for exposing KEDA admission webhooks prometheus metrics
824
port: 8080
825
# -- App Protocol for service when scraping metrics endpoint
826
# appProtocol: http
827
serviceMonitor:
828
# -- Enables ServiceMonitor creation for the Prometheus webhooks
829
enabled: false
830
# -- jobLabel selects the label from the associated Kubernetes service which will be used as the job label for all metrics. [ServiceMonitor Spec]
831
jobLabel: ""
832
# -- TargetLabels transfers labels from the Kubernetes `Service` onto the created metrics
833
targetLabels: []
834
# -- PodTargetLabels transfers labels on the Kubernetes `Pod` onto the created metrics
835
podTargetLabels: []
836
# -- Name of the service port this endpoint refers to. Mutually exclusive with targetPort
837
port: metrics
838
# -- Name or number of the target port of the Pod behind the Service, the port must be specified with container port property. Mutually exclusive with port
839
targetPort: ""
840
# -- Interval at which metrics should be scraped If not specified Prometheus’ global scrape interval is used.
841
interval: ""
842
# -- Timeout after which the scrape is ended If not specified, the Prometheus global scrape timeout is used unless it is less than Interval in which the latter is used
843
scrapeTimeout: ""
844
# -- DEPRECATED. List of expressions that define custom relabeling rules for metric server ServiceMonitor crd (prometheus operator). [RelabelConfig Spec]
845
relabellings: []
846
# -- List of expressions that define custom relabeling rules for metric server ServiceMonitor crd (prometheus operator). [RelabelConfig Spec]
847
relabelings: []
848
# -- List of expressions that define custom metric relabeling rules for metric server ServiceMonitor crd after scrape has happened (prometheus operator). [RelabelConfig Spec]
849
metricRelabelings: []
850
# -- Additional labels to add for metric server using ServiceMonitor crd (prometheus operator)
851
additionalLabels: {}
852
# -- HTTP scheme used for scraping. Defaults to `http`
853
scheme: http
854
# -- TLS configuration for scraping metrics
855
tlsConfig: {}
856
# caFile: /etc/prom-certs/root-cert.pem
857
# certFile: /etc/prom-certs/cert-chain.pem
858
# insecureSkipVerify: true
859
# keyFile: /etc/prom-certs/key.pem
860
prometheusRules:
861
# -- Enables PrometheusRules creation for the Prometheus Operator
862
enabled: false
863
# -- Scraping namespace for KEDA admission webhooks using prometheusRules crd (prometheus operator)
864
namespace: ""
865
# -- Additional labels to add for KEDA admission webhooks using prometheusRules crd (prometheus operator)
866
additionalLabels: {}
867
# -- Additional alerts to add for KEDA admission webhooks using prometheusRules crd (prometheus operator)
868
alerts: []
869
opentelemetry:
870
collector:
871
# -- Uri of OpenTelemetry Collector to push telemetry to
872
uri: ""
873
operator:
874
# -- Enable pushing metrics to an OpenTelemetry Collector for operator
875
enabled: false
876
certificates:
877
# -- Enables the self generation for KEDA TLS certificates inside KEDA operator
878
autoGenerated: true
879
# -- Secret name to be mounted with KEDA TLS certificates
880
secretName: kedaorg-certs
881
# -- Path where KEDA TLS certificates are mounted
882
mountPath: /certs
883
certManager:
884
# -- Enables Cert-manager for certificate management
885
enabled: false
886
# -- Certificate duration
887
duration: 8760h0m0s # 1 year
888
# -- Certificate renewal time before expiration
889
renewBefore: 5840h0m0s # 8 months
890
# -- Generates a self-signed CA with Cert-manager.
891
# If generateCA is false, the secret with the CA
892
# has to be annotated with `cert-manager.io/allow-direct-injection: "true"`
893
generateCA: true
894
# -- Secret name where the CA is stored (generatedby cert-manager or user given)
895
caSecretName: "kedaorg-ca"
896
# -- Add labels/annotations to secrets created by Certificate resources
897
# [docs](https://cert-manager.io/docs/usage/certificate/#creating-certificate-resources)
898
secretTemplate: {}
899
# annotations:
900
# my-secret-annotation-1: "foo"
901
# my-secret-annotation-2: "bar"
902
# labels:
903
# my-secret-label: foo
904
# -- Reference to custom Issuer. If issuer.generate is false, then issuer.group, issuer.kind and issuer.name are required
905
issuer:
906
# -- Generates an Issuer resource with Cert-manager
907
generate: true
908
# -- Custom Issuer name. Required when generate: false
909
name: foo-org-ca
910
# -- Custom Issuer kind. Required when generate: false
911
kind: ClusterIssuer
912
# -- Custom Issuer group. Required when generate: false
913
group: cert-manager.io
914
operator:
915
# -- Enable APIService patching by KEDA operator. Controls whether KEDA operator will inject the self-generated TLS certificate into the APIService used by KEDA Metrics API Server.
916
# Only takes effect when certificates.autoGenerated is true and certificates.certManager.enabled is false.
917
# WARNING: If metricsServer.enabled is true and you disable this, you must ensure the APIService CA bundle is injected by an alternative mechanism (e.g. external controller, manual patching), otherwise the metrics API will fail TLS verification.
918
# apiServicePatching:
919
# enabled: false
920
# -- Location(s) of CA files for authentication of external TLS connections such as TLS-enabled metrics sources
921
# caDirs:
922
# - /custom/ca
923
permissions:
924
metricServer:
925
restrict:
926
# -- Restrict Secret Access for Metrics Server
927
secret: false
928
operator:
929
restrict:
930
# -- Restrict Secret Access for KEDA operator
931
# if true, KEDA operator will be able to read only secrets in {{ .Release.Namespace }} namespace
932
secret: false
933
# -- Array of strings denoting what secrets the KEDA operator will be able to read, this takes into account
934
# also the configured `watchNamespace`.
935
# the default is an empty array -> no restriction on the secret name
936
namesAllowList: []
937
# -- Creates roles and rolebindings from namespaced service accounts in the array which allow the KEDA operator
938
# to request service account tokens for use with the boundServiceAccountToken trigger source.
939
# Optional audience configures minting for this namespace/name; omit it in legacy mode.
940
# Enforce-audience mode requires a mapping here or in KEDA_SERVICE_ACCOUNT_TOKEN_AUDIENCES.
941
# If the namespace does not exist, this will cause the helm chart installation to fail.
942
serviceAccountTokenCreationRoles: []
943
# - name: metrics-reader
944
# namespace: apps
945
# audience: metrics-api
946
# -- Allow Keda to access all Service Token for KEDA operator
947
allowAllServiceAccountTokenCreation: false
948
# -- Array of extra K8s manifests to deploy
949
extraObjects: []
950
# - apiVersion: keda.sh/v1alpha1
951
# kind: ClusterTriggerAuthentication
952
# metadata:
953
# name: aws-credentials
954
# namespace: keda
955
# spec:
956
# podIdentity:
957
# provider: aws-eks
958
959
# -- Capability to turn on/off ASCII art in Helm installation notes
960
asciiArt: true
961
# -- When specified, each rendered resource will have `app.kubernetes.io/managed-by: ${this}` label on it. Useful, when using only helm template with some other solution.
962
customManagedBy: ""
963
# -- Enable service links in pods. Although enabled, mirroring k8s default, it is highly recommended to disable,
964
# due to its legacy status [Legacy container links](https://docs.docker.com/engine/network/links/)
965
enableServiceLinks: true
966

The trusted source for open source

Talk to an expert
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsChainguard OS PackagesChainguard ActionsChainguard Agent SkillsIntegrationsPricing
© 2026 Chainguard, Inc. All Rights Reserved.
Chainguard® and the Chainguard logo are registered trademarks of Chainguard, Inc. in the United States and/or other countries.
The other respective trademarks mentioned on this page are owned by the respective companies and use of them does not imply any affiliation or endorsement.