1# Default values for keda.
2# This is a YAML-formatted file.
3# Declare variables to be passed into your templates.
7 # -- Global image registry of KEDA components
9 # -- DNS config for KEDA components
14 # - ns1.svc.cluster-domain.example
15 # - my.dns.search.suffix
23 # -- Image registry of KEDA operator
25 # -- Image name of KEDA operator
26 repository: chainguard-private/keda
27 # -- Image tag of KEDA operator. Optional, given app version of Helm chart is used by default
28 tag: 2.21.0-r1@sha256:92e30f50d65cd2e54d52f32fbd1f38c13c51d992a7d29e658b7c73574c614872
30 # -- Image registry of KEDA Metrics API Server
32 # -- Image name of KEDA Metrics API Server
33 repository: chainguard-private/keda-metrics-apiserver
34 # -- Image tag of KEDA Metrics API Server. Optional, given app version of Helm chart is used by default
35 tag: 2.21.0-r1@sha256:f79222ec5652498ba2647d108054c50a3382d2cbeef2976ee23fe04cadd6ae93
37 # -- Image registry of KEDA admission-webhooks
39 # -- Image name of KEDA admission-webhooks
40 repository: chainguard-private/keda-admission-webhooks
41 # -- Image tag of KEDA admission-webhooks . Optional, given app version of Helm chart is used by default
42 tag: 2.21.0-r1@sha256:0fbd35ac85de44f1d79579901cd875882ad58611d70575fc71ce05da17fc26cd
43 # -- Image pullPolicy for all KEDA components
45# -- Kubernetes cluster name. Used in features such as emitting CloudEvents
46clusterName: kubernetes-default
47# -- Kubernetes cluster domain
48clusterDomain: cluster.local
50 # -- Defines whether the KEDA CRDs have to be installed or not.
52 # -- Custom annotations specifically for CRDs
53 additionalAnnotations: {}
55# -- Defines Kubernetes namespaces to watch to scale their workloads. Default watches all namespaces
57# -- Restricts the operator to reconcile only ScaledObjects and ScaledJobs (and their derived
58# HorizontalPodAutoscalers) matching the given Kubernetes label selector. Default (empty) means
59# no label-based filtering. Mirrors `watchNamespace`, but filters by label instead of by namespace.
60# Examples: "environment=production", "tier in (gold,silver)", "!canary"
62# -- Restricts the operator to reconcile only TriggerAuthentications and ClusterTriggerAuthentications
63# matching the given Kubernetes label selector. Default (empty) means no label-based filtering.
64# Decoupled from `watchLabelSelector` so a single cluster-scoped ClusterTriggerAuthentication can be
65# shared across operators scoped to different label selectors.
66watchLabelSelectorForTriggerauth: ""
67# -- Name of secret to use to pull images to use to pull Docker images
70 # -- Enable network policies
72 # -- Flavor of the network policies (cilium, kubernetes)
74 # -- Allow use of extra egress rules for cilium network policies
78 # -- Allow use of extra egress rules for kubernetes network policies
88 # -- Token audience policy for Vault and boundServiceAccountToken. When configured as "legacy", it disables enforcement and cannot be combined with configured audiences.
89 mode: enforce-audience # enforce-audience, legacy
90 # -- Approved audiences for extra token files; creates no mounts or minting defaults. Use audiences not accepted by kube-apiserver. Combined audience config.
91 additionalAllowedAudiences: []
92 # -- Optional endpoint filter, passed as KEDA_OUTBOUND_FILTER. Empty disables filtering. Max 64 KiB.
94 # Example policy (replace {} above):
96 # mode: "off" # off, warn, or enforce
97 # allowedEndpoints: [] # exact HTTP(S) origins; empty denies all in enforce mode
98 # -- Name of the KEDA operator
100 # -- Additional KEDA Operator container environment variables
104 # -- ReplicaSets for this Deployment you want to retain (Default: 10)
105 revisionHistoryLimit: 10
106 # -- Capability to configure the number of replicas for KEDA operator.
107 # While you can run more replicas of our operator, only one operator instance will be the leader and serving traffic.
108 # You can run multiple replicas, but they will not improve the performance of KEDA, it could only reduce downtime during a failover.
109 # Learn more in [our documentation](https://keda.sh/docs/latest/operate/cluster/#high-availability).
111 # --Disable response compression for k8s restAPI in client-go.
112 # Disabling compression simply means that turns off the process of making data smaller for K8s restAPI in client-go for faster transmission.
113 disableCompression: true
114 # -- Port for the gRPC Metrics Service endpoint that the KEDA operator binds to and the metrics server connects to.
115 metricsServiceTargetPort: 9666
116 # -- Leader election ID (Lease resource name) for the controller manager. Defaults to operator.keda.sh.
117 # Override to allow multiple independent KEDA operator deployments in the same namespace.
118 # leaderElectionID: "operator.keda.sh"
119 # -- DNS config for KEDA operator pod
121 # use ClusterFirstWithHostNet if `useHostNetwork: true` https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-s-dns-policy
122 # -- Defined the DNS policy for the operator
123 dnsPolicy: ClusterFirst
124 # -- Enable operator to use host network
125 useHostNetwork: false
126 # -- (bool) Sets `hostUsers` on the KEDA operator pod. Leave unset to preserve the cluster default, `false` to run the pod in its own [user namespace](https://kubernetes.io/docs/concepts/workloads/pods/user-namespaces/), or `true` to explicitly use the host user namespace.
128 # -- [Affinity] for pod scheduling for KEDA operator. Takes precedence over the `affinity` field
131 # requiredDuringSchedulingIgnoredDuringExecution:
138 # topologyKey: "kubernetes.io/hostname"
139 # -- Additional containers to run as part of the operator deployment
144 # - "while true; do echo hi; sleep 300; done"
147 # image: 'busybox:glibc'
148 # -- Additional init containers to run as part of the operator deployment
149 extraInitContainers: []
153 # - "echo 'Hello World!'"
156 # image: 'busybox:glibc'
157 # -- Liveness probes for operator ([docs](https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-startup-probes/))
159 initialDelaySeconds: 25
164 # -- Readiness probes for operator ([docs](https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-startup-probes/#define-readiness-probes))
166 initialDelaySeconds: 20
171 # -- Node selector for pod scheduling ([docs](https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/))
173 # -- Tolerations for pod scheduling ([docs](https://kubernetes.io/docs/concepts/scheduling-eviction/taint-and-toleration/))
175 # -- Additional timeout beyond the ScaledObject or ScaledJob polling interval for Kubernetes API operations in scaling loops. Setting `0s` uses the polling interval as the timeout; the timeout cannot be disabled
176 kubernetesApiTimeout: 5s
178 # -- Enable KEDA metrics server.
180 # -- Enable registering KEDA metrics server as external metrics API resource.
181 registerAPIService: true
182 # -- Additional Metrics Adapter container environment variables
186 # -- ReplicaSets for this Deployment you want to retain (Default: 10)
187 revisionHistoryLimit: 10
188 # -- Capability to configure the number of replicas for KEDA metric server.
189 # While you can run more replicas of our metric server, only one instance will used and serve traffic.
190 # You can run multiple replicas, but they will not improve the performance of KEDA, it could only reduce downtime during a failover.
191 # Learn more in [our documentation](https://keda.sh/docs/latest/operate/cluster/#high-availability).
193 # --Disable response compression for k8s restAPI in client-go.
194 # Disabling compression simply means that turns off the process of making data smaller for K8s restAPI in client-go for faster transmission.
195 disableCompression: true
196 # use ClusterFirstWithHostNet if `useHostNetwork: true` https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-s-dns-policy
197 # -- Defined the DNS policy for the metric server
198 dnsPolicy: ClusterFirst
199 # -- DNS config for KEDA metrics server pod
201 # -- Enable metric server to use host network
202 useHostNetwork: false
203 # -- (bool) Sets `hostUsers` on the KEDA metrics server pod. Leave unset to preserve the cluster default, `false` to run the pod in its own [user namespace](https://kubernetes.io/docs/concepts/workloads/pods/user-namespaces/), or `true` to explicitly use the host user namespace.
205 # -- [Affinity] for pod scheduling for Metrics API Server. Takes precedence over the `affinity` field
208 # requiredDuringSchedulingIgnoredDuringExecution:
214 # - keda-operator-metrics-apiserver
215 # topologyKey: "kubernetes.io/hostname"
216 # -- Liveness probes for Metrics API Server ([docs](https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-startup-probes/))
218 initialDelaySeconds: 5
223 # -- Readiness probes for Metrics API Server ([docs](https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-startup-probes/#define-readiness-probes))
225 initialDelaySeconds: 5
230 # -- Node selector for pod scheduling ([docs](https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/))
232 # -- Tolerations for pod scheduling ([docs](https://kubernetes.io/docs/concepts/scheduling-eviction/taint-and-toleration/))
235 # It also used to enable or disable webhook patching in the operator
237 # -- Additional KEDA admission webhook container environment variables
241 # -- Port number to use for KEDA admission webhooks. Default is 9443.
243 # -- Port number to use for KEDA admission webhooks health probe
244 healthProbePort: 8081
245 # -- DNS config for KEDA admission webhooks pod
247 # -- Liveness probes for admission webhooks ([docs](https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-startup-probes/))
249 initialDelaySeconds: 25
254 # -- Readiness probes for admission webhooks ([docs](https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-startup-probes/#define-readiness-probes))
256 initialDelaySeconds: 20
261 # -- Timeout in seconds for KEDA admission webhooks
263 # -- Enable webhook to use host network, this is required on EKS with custom CNI
264 useHostNetwork: false
265 # -- (bool) Sets `hostUsers` on the KEDA admission webhooks pod. Leave unset to preserve the cluster default, `false` to run the pod in its own [user namespace](https://kubernetes.io/docs/concepts/workloads/pods/user-namespaces/), or `true` to explicitly use the host user namespace.
267 # -- Name of the KEDA admission webhooks
268 name: keda-admission-webhooks
269 # -- ReplicaSets for this Deployment you want to retain (Default: 10)
270 revisionHistoryLimit: 10
271 # -- Capability to configure the number of replicas for KEDA admission webhooks
273 # -- [Affinity] for pod scheduling for KEDA admission webhooks. Takes precedence over the `affinity` field
276 # requiredDuringSchedulingIgnoredDuringExecution:
282 # - keda-admission-webhooks
283 # topologyKey: "kubernetes.io/hostname"
285 # -- [Failure policy](https://kubernetes.io/docs/reference/access-authn-authz/extensible-admission-controllers/#failure-policy) to use with KEDA admission webhooks
286 failurePolicy: Ignore
287 # -- Node selector for pod scheduling ([docs](https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/))
289 # -- Tolerations for pod scheduling ([docs](https://kubernetes.io/docs/concepts/scheduling-eviction/taint-and-toleration/))
292 # -- Capability to configure [Deployment upgrade strategy] for operator
294 # type: RollingUpdate
299 # -- Capability to configure [Deployment upgrade strategy] for Metrics Api Server
301 # type: RollingUpdate
306 # -- Capability to configure [Deployment upgrade strategy] for Admission webhooks
308 # type: RollingUpdate
313 # -- Capability to configure [Pod Disruption Budget]
318 # -- Capability to configure [Pod Disruption Budget]
323 # -- Capability to configure [Pod Disruption Budget]
327# -- Custom labels to add into metadata
331# -- Custom annotations to add into metadata
332additionalAnnotations: {}
336 # -- Pod annotations for KEDA operator
338 # -- Pod annotations for KEDA Metrics Adapter
340 # -- Pod annotations for KEDA Admission webhooks
343 # -- Pod labels for KEDA operator
345 # -- Pod labels for KEDA Metrics Adapter
347 # -- Pod labels for KEDA Admission webhooks
350 # -- Specifies whether RBAC should be used
352 # -- Specifies whether RBAC for CRDs should be [aggregated](https://kubernetes.io/docs/reference/access-authn-authz/rbac/#aggregated-clusterroles) to default roles (view, edit, admin)
353 aggregateToDefaultRoles: false
354 # -- Whether RBAC for configured CRDs that can have a `scale` subresource should be created
355 enabledCustomScaledRefKinds: true
356 # -- Customize the namespace of k8s metrics-server deployment
357 # This could also be achieved by the Kubernetes control plane manager flag --use-service-account-credentials:
358 # [docs](https://kubernetes.io/docs/reference/command-line-tools-reference/kube-controller-manager/)
359 controlPlaneServiceAccountsNamespace: kube-system
360 # -- List of custom resources that support the `scale` subresource and can be referenced by `scaledobject.spec.scaleTargetRef`.
361 # The feature needs to be also enabled by `enabledCustomScaledRefKinds`.
362 # If left empty, RBAC for `apiGroups: *` and `resources: *, */scale` will be created
363 # note: Deployments and StatefulSets are supported out of the box
367 # - apiGroup: argoproj.io
371 # -- Specifies whether a service account should be created
373 # -- The name of the service account to use.
375 # -- Specifies whether a service account should automount API-Credentials
376 automountServiceAccountToken: true
377 # -- Annotations to add to the service account
380 # -- Specifies whether a service account should be created
382 # -- The name of the service account to use.
383 name: keda-metrics-server
384 # -- Specifies whether a service account should automount API-Credentials
385 automountServiceAccountToken: true
386 # -- Annotations to add to the service account
389 # -- Specifies whether a service account should be created
391 # -- The name of the service account to use.
393 # -- Specifies whether a service account should automount API-Credentials
394 automountServiceAccountToken: true
395 # -- Annotations to add to the service account
399 # -- Set to true to enable Azure Workload Identity usage.
400 # See https://keda.sh/docs/concepts/authentication/#azure-workload-identity
401 # This will be set as a label on the KEDA service account.
403 # Set to the value of the Azure Active Directory Client and Tenant Ids
404 # respectively. These will be set as annotations on the KEDA service account.
405 # -- Id of Azure Active Directory Client to use for authentication with Azure Workload Identity. ([docs](https://keda.sh/docs/concepts/authentication/#azure-workload-identity))
407 # -- Id Azure Active Directory Tenant to use for authentication with for Azure Workload Identity. ([docs](https://keda.sh/docs/concepts/authentication/#azure-workload-identity))
409 # Set to the value of the service account token expiration duration.
410 # This will be set as an annotation on the KEDA service account.
411 # -- Duration in seconds to automatically expire tokens for the service account. ([docs](https://keda.sh/docs/concepts/authentication/#azure-workload-identity))
412 tokenExpiration: 3600
415 # -- Specifies whether [AWS IAM Roles for Service Accounts (IRSA)](https://docs.aws.amazon.com/eks/latest/userguide/iam-roles-for-service-accounts.html) is to be enabled or not.
417 # -- Sets the token audience for IRSA.
418 # This will be set as an annotation on the KEDA service account.
419 audience: "sts.amazonaws.com"
420 # -- Set to the value of the ARN of an IAM role with a web identity provider.
421 # This will be set as an annotation on the KEDA service account.
423 # -- Sets the use of an STS regional endpoint instead of global.
424 # Recommended to use regional endpoint in almost all cases.
425 # This will be set as an annotation on the KEDA service account.
426 stsRegionalEndpoints: "true"
427 # -- Set to the value of the service account token expiration duration.
428 # This will be set as an annotation on the KEDA service account.
429 tokenExpiration: 86400
431 # -- Set to true to enable GCP Workload Identity.
432 # See https://keda.sh/docs/2.10/authentication-providers/gcp-workload-identity/
433 # This will be set as a annotation on the KEDA service account.
435 # -- GCP IAM Service Account Email which you would like to use for workload identity.
436 gcpIAMServiceAccount: ""
437# -- Set this if you are using an external scaler and want to communicate
438# over TLS (recommended). This variable holds the name of the secret that
439# will be mounted to the /grpccerts path on the Pod
440grpcTLSCertsSecret: ""
441# -- Set this if you are using HashiCorp Vault and want to communicate
442# over TLS (recommended). This variable holds the name of the secret that
443# will be mounted to the /vault path on the Pod
447 # -- Projected operator-token audience, also globally approved. Empty disables projection; does not configure named-SA minting. Use an audience not accepted by kube-apiserver.
449 # -- Mount directory for the Vault token (<path>/token). Empty/null disables projection and implicit file selection; explicit TA token paths remain usable.
450 projectedTokenMountPath: /var/run/secrets/keda-vault
453 # -- Logging level for KEDA Operator.
454 # allowed values: `debug`, `info`, `error`, or an integer value greater than 0, specified as string
456 # -- Logging format for KEDA Operator.
457 # allowed values: `json` or `console`
459 # -- Logging time encoding for KEDA Operator.
460 # allowed values are `epoch`, `millis`, `nano`, `iso8601`, `rfc3339` or `rfc3339nano`
461 timeEncoding: rfc3339
462 # -- If enabled, the stack traces will be also printed
463 stackTracesEnabled: false
465 # -- Logging level for Metrics Server (Deprecated).
466 # allowed values: `0` for info, `4` for debug, or an integer value greater than 0, specified as string
468 # -- Logging stderrthreshold for Metrics Server (Deprecated)
469 # allowed values: 'DEBUG','INFO','WARN','ERROR','ALERT','EMERG'
470 stderrthreshold: ERROR
471 # -- Zap Logging level for Metrics Server.
472 # allowed values: `debug`, `info`, `error`, or an integer value greater than 0, specified as string
474 # -- Zap Logging encoder for Metrics Server.
475 # allowed values: `json` or `console`
477 # -- Zap logging time encoding for Metrics Server.
478 # allowed values are `epoch`, `millis`, `nano`, `iso8601`, `rfc3339` or `rfc3339nano`
479 zapTimeEncoding: rfc3339
481 # -- Logging level for KEDA Operator.
482 # allowed values: `debug`, `info`, `error`, or an integer value greater than 0, specified as string
484 # -- Logging format for KEDA Admission webhooks.
485 # allowed values: `json` or `console`
487 # -- Logging time encoding for KEDA Operator.
488 # allowed values are `epoch`, `millis`, `nano`, `iso8601`, `rfc3339` or `rfc3339nano`
489 timeEncoding: rfc3339
490# -- [Security context] for all containers
491# @default -- [See below](#KEDA-is-secure-by-default)
493 # -- [Security context] of the operator container
494 # @default -- [See below](#KEDA-is-secure-by-default)
499 allowPrivilegeEscalation: false
500 readOnlyRootFilesystem: true
503 # -- [Security context] of the metricServer container
504 # @default -- [See below](#KEDA-is-secure-by-default)
509 allowPrivilegeEscalation: false
510 readOnlyRootFilesystem: true
513 # -- [Security context] of the admission webhooks container
514 # @default -- [See below](#KEDA-is-secure-by-default)
519 allowPrivilegeEscalation: false
520 readOnlyRootFilesystem: true
523# -- [Pod security context] for all pods
524# @default -- [See below](#KEDA-is-secure-by-default)
526 # -- [Pod security context] of the KEDA operator pod
527 # @default -- [See below](#KEDA-is-secure-by-default)
533 # -- [Pod security context] of the KEDA metrics apiserver pod
534 # @default -- [See below](#KEDA-is-secure-by-default)
540 # -- [Pod security context] of the KEDA admission webhooks
541 # @default -- [See below](#KEDA-is-secure-by-default)
548 # -- KEDA Metric Server service type
550 # -- HTTPS port for KEDA Metric Server service
552 # -- HTTPS port for KEDA Metric Server container
553 portHttpsTarget: 6443
554 # -- Annotations to add the KEDA Metric Server service
556 # -- The minimum TLS version to use when KEDA components provide a TLS-enabled service.
557 minTlsVersion: "TLS13"
558 # -- The list of cipher suites to use when KEDA components provide a TLS-enabled service. When left empty or unset, the TLS implementation will provide a default list of cipher suites which are believed to be secure.
560# We provides the default values that we describe in our docs:
561# https://keda.sh/docs/latest/operate/cluster/
562# If you want to specify the resources (or totally remove the defaults), change or comment the following
563# lines, adjust them as necessary, or simply add the curly braces after 'operator' and/or 'metricServer'
564# and remove/comment the default values
566 # -- Manage [resource request & limits] of KEDA operator pod
574 # -- Manage [resource request & limits] of KEDA metrics apiserver pod
582 # -- Manage [resource request & limits] of KEDA admission webhooks pod
590# -- Node selector for pod scheduling ([docs](https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/))
592# -- Tolerations for pod scheduling ([docs](https://kubernetes.io/docs/concepts/scheduling-eviction/taint-and-toleration/))
594# -- HostAliases for pod networking ([docs](https://kubernetes.io/docs/concepts/services-networking/add-entries-to-pod-etc-hosts-with-host-aliases/))
596topologySpreadConstraints:
597 # -- [Pod Topology Constraints] of KEDA operator pod
599 # -- [Pod Topology Constraints] of KEDA metrics apiserver pod
601 # -- [Pod Topology Constraints] of KEDA admission webhooks pod
603# -- [Affinity] for pod scheduling for KEDA operator, Metrics API Server and KEDA admission webhooks.
606# requiredDuringSchedulingIgnoredDuringExecution:
613# - keda-operator-metrics-apiserver
614# - keda-admission-webhooks
615# topologyKey: "kubernetes.io/hostname"
617# -- priorityClassName for all KEDA components
619## The default HTTP timeout in milliseconds that KEDA should use
620## when making requests to external services. Removing this defaults to a
623 # -- The default HTTP timeout to use for all scalers that use raw HTTP clients (some scalers use SDKs to access target services. These have built-in HTTP clients, and the timeout does not necessarily apply to them)
625 # -- Maximum number of idle HTTP connections across all hosts. Zero means no limit.
627 # -- Maximum number of idle HTTP connections to keep per host
628 maxIdleConnsPerHost: 1000
629 # -- Maximum time an idle HTTP connection remains in the pool. Must be greater than zero.
632 # -- Enable HTTP connection keep alive
634 # -- The minimum TLS version to use for all scalers that use raw HTTP clients (some scalers use SDKs to access target services. These have built-in HTTP clients, and this value does not necessarily apply to them)
636 # -- The list of cipher suites to use when making HTTP over TLS connections. When left empty or unset, the TLS implementation will provide a default list of cipher suites which are believed to be secure.
638## This setting lets you enable profiling for all of the components of KEDA and in the specific port you choose
639## This can be useful when trying to investigate errors like memory leaks or CPU or even look at goroutines to understand better
640## This setting is disabled by default
643 # -- Enable profiling for KEDA operator
645 # -- Expose profiling on a specific port
648 # -- Enable profiling for KEDA metrics server
650 # -- Expose profiling on a specific port
653 # -- Enable profiling for KEDA admission webhook
655 # -- Expose profiling on a specific port
657## Extra KEDA Operator, Metrics Adapter and Admission Webhooks container arguments
659 # -- Additional KEDA Operator container arguments
661 # -- Additional Metrics Adapter container arguments
663 # -- Additional KEDA admission webhooks container arguments
667 # cache-miss-to-direct-client: "true"
668# -- Additional environment variables that will be passed onto all KEDA components
673# Extra volumes and volume mounts for the deployment. Optional.
676 # -- Extra volumes for KEDA deployment
678 # -- Extra volume mounts for KEDA deployment
679 extraVolumeMounts: []
681 # -- Extra volumes for metric server deployment
683 # -- Extra volume mounts for metric server deployment
684 extraVolumeMounts: []
686 # -- Extra volumes for admission webhooks deployment
688 # -- Extra volume mounts for admission webhooks deployment
689 extraVolumeMounts: []
692 # -- Enable metric server Prometheus metrics expose
694 # -- HTTP port used for exposing metrics server prometheus metrics
696 # -- HTTP port name for exposing metrics server prometheus metrics
698 # -- App Protocol for service when scraping metrics endpoint
701 # -- Enables ServiceMonitor creation for the Prometheus Operator
703 # -- JobLabel selects the label from the associated Kubernetes service which will be used as the job label for all metrics. [ServiceMonitor Spec]
705 # -- TargetLabels transfers labels from the Kubernetes `Service` onto the created metrics
707 # -- PodTargetLabels transfers labels on the Kubernetes `Pod` onto the created metrics
709 # -- Name of the service port this endpoint refers to. Mutually exclusive with targetPort
711 # -- Name or number of the target port of the Pod behind the Service, the port must be specified with container port property. Mutually exclusive with port
713 # -- Interval at which metrics should be scraped If not specified Prometheus’ global scrape interval is used.
715 # -- Timeout after which the scrape is ended If not specified, the Prometheus global scrape timeout is used unless it is less than Interval in which the latter is used
717 # -- DEPRECATED. List of expressions that define custom relabeling rules for metric server ServiceMonitor crd (prometheus operator). [RelabelConfig Spec]
719 # -- List of expressions that define custom relabeling rules for metric server ServiceMonitor crd (prometheus operator). [RelabelConfig Spec]
721 # -- List of expressions that define custom metric relabeling rules for metric server ServiceMonitor crd after scrape has happened (prometheus operator). [RelabelConfig Spec]
722 metricRelabelings: []
723 # -- Additional labels to add for metric server using ServiceMonitor crd (prometheus operator)
725 # -- HTTP scheme used for scraping. Defaults to `http`
727 # -- TLS configuration for scraping metrics
729 # caFile: /etc/prom-certs/root-cert.pem
730 # certFile: /etc/prom-certs/cert-chain.pem
731 # insecureSkipVerify: true
732 # keyFile: /etc/prom-certs/key.pem
734 # -- Enables PodMonitor creation for the Prometheus Operator
736 # -- Scraping interval for metric server using podMonitor crd (prometheus operator)
738 # -- Scraping timeout for metric server using podMonitor crd (prometheus operator)
740 # -- Scraping namespace for metric server using podMonitor crd (prometheus operator)
742 # -- Additional labels to add for metric server using podMonitor crd (prometheus operator)
744 # -- List of expressions that define custom relabeling rules for metric server podMonitor crd (prometheus operator)
746 # -- List of expressions that define custom metric relabeling rules for metric server PodMonitor crd after scrape has happened (prometheus operator). [RelabelConfig Spec]
747 metricRelabelings: []
749 # -- Enable KEDA Operator prometheus metrics expose
751 # -- Port used for exposing KEDA Operator prometheus metrics
753 # -- App Protocol for service when scraping metrics endpoint
756 # -- Enables ServiceMonitor creation for the Prometheus Operator
758 # -- JobLabel selects the label from the associated Kubernetes service which will be used as the job label for all metrics. [ServiceMonitor Spec]
760 # -- TargetLabels transfers labels from the Kubernetes `Service` onto the created metrics
762 # -- PodTargetLabels transfers labels on the Kubernetes `Pod` onto the created metrics
764 # -- Name of the service port this endpoint refers to. Mutually exclusive with targetPort
766 # -- Name or number of the target port of the Pod behind the Service,
767 # the port must be specified with container port property. Mutually exclusive with port
769 # -- Interval at which metrics should be scraped If not specified Prometheus’ global scrape interval is used.
771 # -- Timeout after which the scrape is ended If not specified, the Prometheus global scrape timeout is used unless it is less than Interval in which the latter is used
773 # -- DEPRECATED. List of expressions that define custom relabeling rules for metric server ServiceMonitor crd (prometheus operator). [RelabelConfig Spec]
775 # -- List of expressions that define custom relabeling rules for metric server ServiceMonitor crd (prometheus operator). [RelabelConfig Spec]
777 # -- List of expressions that define custom metric relabeling rules for metric server ServiceMonitor crd after scrape has happened (prometheus operator). [RelabelConfig Spec]
778 metricRelabelings: []
779 # -- Additional labels to add for metric server using ServiceMonitor crd (prometheus operator)
781 # -- HTTP scheme used for scraping. Defaults to `http`
783 # -- TLS configuration for scraping metrics
785 # caFile: /etc/prom-certs/root-cert.pem
786 # certFile: /etc/prom-certs/cert-chain.pem
787 # insecureSkipVerify: true
788 # keyFile: /etc/prom-certs/key.pem
790 # -- Enables PodMonitor creation for the Prometheus Operator
792 # -- Scraping interval for KEDA Operator using podMonitor crd (prometheus operator)
794 # -- Scraping timeout for KEDA Operator using podMonitor crd (prometheus operator)
796 # -- Scraping namespace for KEDA Operator using podMonitor crd (prometheus operator)
798 # -- Additional labels to add for KEDA Operator using podMonitor crd (prometheus operator)
800 # -- List of expressions that define custom relabeling rules for KEDA Operator podMonitor crd (prometheus operator)
802 # -- List of expressions that define custom metric relabeling rules for metric server PodMonitor crd after scrape has happened (prometheus operator). [RelabelConfig Spec]
803 metricRelabelings: []
805 # -- Enables PrometheusRules creation for the Prometheus Operator
807 # -- Scraping namespace for KEDA Operator using prometheusRules crd (prometheus operator)
809 # -- Additional labels to add for KEDA Operator using prometheusRules crd (prometheus operator)
811 # -- Additional alerts to add for KEDA Operator using prometheusRules crd (prometheus operator)
813 # - alert: KedaScalerErrors
815 # description: Keda scaledObject {{ $labels.scaledObject }} is experiencing errors with {{ $labels.scaler }} scaler
816 # summary: Keda Scaler {{ $labels.scaler }} Errors
817 # expr: sum by ( scaledObject , scaler) (rate(keda_metrics_adapter_scaler_errors[2m])) > 0
821 # -- Enable KEDA admission webhooks prometheus metrics expose
823 # -- Port used for exposing KEDA admission webhooks prometheus metrics
825 # -- App Protocol for service when scraping metrics endpoint
828 # -- Enables ServiceMonitor creation for the Prometheus webhooks
830 # -- jobLabel selects the label from the associated Kubernetes service which will be used as the job label for all metrics. [ServiceMonitor Spec]
832 # -- TargetLabels transfers labels from the Kubernetes `Service` onto the created metrics
834 # -- PodTargetLabels transfers labels on the Kubernetes `Pod` onto the created metrics
836 # -- Name of the service port this endpoint refers to. Mutually exclusive with targetPort
838 # -- Name or number of the target port of the Pod behind the Service, the port must be specified with container port property. Mutually exclusive with port
840 # -- Interval at which metrics should be scraped If not specified Prometheus’ global scrape interval is used.
842 # -- Timeout after which the scrape is ended If not specified, the Prometheus global scrape timeout is used unless it is less than Interval in which the latter is used
844 # -- DEPRECATED. List of expressions that define custom relabeling rules for metric server ServiceMonitor crd (prometheus operator). [RelabelConfig Spec]
846 # -- List of expressions that define custom relabeling rules for metric server ServiceMonitor crd (prometheus operator). [RelabelConfig Spec]
848 # -- List of expressions that define custom metric relabeling rules for metric server ServiceMonitor crd after scrape has happened (prometheus operator). [RelabelConfig Spec]
849 metricRelabelings: []
850 # -- Additional labels to add for metric server using ServiceMonitor crd (prometheus operator)
852 # -- HTTP scheme used for scraping. Defaults to `http`
854 # -- TLS configuration for scraping metrics
856 # caFile: /etc/prom-certs/root-cert.pem
857 # certFile: /etc/prom-certs/cert-chain.pem
858 # insecureSkipVerify: true
859 # keyFile: /etc/prom-certs/key.pem
861 # -- Enables PrometheusRules creation for the Prometheus Operator
863 # -- Scraping namespace for KEDA admission webhooks using prometheusRules crd (prometheus operator)
865 # -- Additional labels to add for KEDA admission webhooks using prometheusRules crd (prometheus operator)
867 # -- Additional alerts to add for KEDA admission webhooks using prometheusRules crd (prometheus operator)
871 # -- Uri of OpenTelemetry Collector to push telemetry to
874 # -- Enable pushing metrics to an OpenTelemetry Collector for operator
877 # -- Enables the self generation for KEDA TLS certificates inside KEDA operator
879 # -- Secret name to be mounted with KEDA TLS certificates
880 secretName: kedaorg-certs
881 # -- Path where KEDA TLS certificates are mounted
884 # -- Enables Cert-manager for certificate management
886 # -- Certificate duration
887 duration: 8760h0m0s # 1 year
888 # -- Certificate renewal time before expiration
889 renewBefore: 5840h0m0s # 8 months
890 # -- Generates a self-signed CA with Cert-manager.
891 # If generateCA is false, the secret with the CA
892 # has to be annotated with `cert-manager.io/allow-direct-injection: "true"`
894 # -- Secret name where the CA is stored (generatedby cert-manager or user given)
895 caSecretName: "kedaorg-ca"
896 # -- Add labels/annotations to secrets created by Certificate resources
897 # [docs](https://cert-manager.io/docs/usage/certificate/#creating-certificate-resources)
900 # my-secret-annotation-1: "foo"
901 # my-secret-annotation-2: "bar"
903 # my-secret-label: foo
904 # -- Reference to custom Issuer. If issuer.generate is false, then issuer.group, issuer.kind and issuer.name are required
906 # -- Generates an Issuer resource with Cert-manager
908 # -- Custom Issuer name. Required when generate: false
910 # -- Custom Issuer kind. Required when generate: false
912 # -- Custom Issuer group. Required when generate: false
913 group: cert-manager.io
915 # -- Enable APIService patching by KEDA operator. Controls whether KEDA operator will inject the self-generated TLS certificate into the APIService used by KEDA Metrics API Server.
916 # Only takes effect when certificates.autoGenerated is true and certificates.certManager.enabled is false.
917 # WARNING: If metricsServer.enabled is true and you disable this, you must ensure the APIService CA bundle is injected by an alternative mechanism (e.g. external controller, manual patching), otherwise the metrics API will fail TLS verification.
918 # apiServicePatching:
920 # -- Location(s) of CA files for authentication of external TLS connections such as TLS-enabled metrics sources
926 # -- Restrict Secret Access for Metrics Server
930 # -- Restrict Secret Access for KEDA operator
931 # if true, KEDA operator will be able to read only secrets in {{ .Release.Namespace }} namespace
933 # -- Array of strings denoting what secrets the KEDA operator will be able to read, this takes into account
934 # also the configured `watchNamespace`.
935 # the default is an empty array -> no restriction on the secret name
937 # -- Creates roles and rolebindings from namespaced service accounts in the array which allow the KEDA operator
938 # to request service account tokens for use with the boundServiceAccountToken trigger source.
939 # Optional audience configures minting for this namespace/name; omit it in legacy mode.
940 # Enforce-audience mode requires a mapping here or in KEDA_SERVICE_ACCOUNT_TOKEN_AUDIENCES.
941 # If the namespace does not exist, this will cause the helm chart installation to fail.
942 serviceAccountTokenCreationRoles: []
943 # - name: metrics-reader
945 # audience: metrics-api
946 # -- Allow Keda to access all Service Token for KEDA operator
947 allowAllServiceAccountTokenCreation: false
948# -- Array of extra K8s manifests to deploy
950# - apiVersion: keda.sh/v1alpha1
951# kind: ClusterTriggerAuthentication
953# name: aws-credentials
959# -- Capability to turn on/off ASCII art in Helm installation notes
961# -- When specified, each rendered resource will have `app.kubernetes.io/managed-by: ${this}` label on it. Useful, when using only helm template with some other solution.
963# -- Enable service links in pods. Although enabled, mirroring k8s default, it is highly recommended to disable,
964# due to its legacy status [Legacy container links](https://docs.docker.com/engine/network/links/)
965enableServiceLinks: true