1# Default values for prometheus-node-exporter.
2# This is a YAML-formatted file.
3# Declare variables to be passed into your templates.
5# Prometheus scrape service annotation flag
9 repository: chainguard-private/prometheus-node-exporter
10 # Overrides the image tag whose default is {{ printf "v%s" .Chart.AppVersion }}
12 # Use the distroless image variant.
14 pullPolicy: IfNotPresent
15 digest: sha256:c192c8fc0b139bfa2f9e4c89eb08bbae4c79feb6dfed8466f08b4115f0510f5e
17# - name: "image-pull-secret"
20# Number of old history to retain to allow rollback
21# Default Kubernetes value is set to 10
22revisionHistoryLimit: 10
24 # To help compatibility with other charts which use global.imagePullSecrets.
25 # Allow either an array of {name: pullSecret} maps (k8s-style), or an array of strings (more common helm-style).
37 # Allow parent charts to override registry hostname
39# Configure kube-rbac-proxy. When enabled, creates a kube-rbac-proxy to protect the node-exporter http endpoint.
40# The requests are served through the same service but requests are HTTPS.
43 ## Set environment variables as name/value pairs
48 repository: chainguard-private/kube-rbac-proxy
50 sha: sha256:6b81442e7d6810548030473a81c8befb52954a7ec8a40a377e1865195f164834
51 pullPolicy: IfNotPresent
52 # List of additional cli arguments to configure kube-rbac-proxy
53 # for example: --tls-cipher-suites, --log-file, etc.
54 # all the possible args can be found here: https://github.com/brancz/kube-rbac-proxy#usage
56 ## Specify security settings for a Container
57 ## Allows overrides and additional options compared to (Pod) securityContext
58 ## Ref: https://kubernetes.io/docs/tasks/configure-pod-container/security-context/#set-the-security-context-for-a-container
59 containerSecurityContext: {}
60 # Specify the port used for the Node exporter container (upstream port)
62 # Host/interface prefix for --secure-listen-address (for example ":" or "$(POD_IP):")
64 # Specify the name of the container port
66 # Configure a hostPort. If true, hostPort will be enabled in the container and set to service.port.
68 # Configure Proxy Endpoints Port
69 # This is the port being probed for readiness
70 proxyEndpointsPort: 8888
71 # Configure a hostPort. If true, hostPort will be enabled in the container and set to proxyEndpointsPort.
72 enableProxyEndpointsHostPort: false
74 # We usually recommend not to specify default resources and to leave this as a conscious
75 # choice for the user. This also increases chances charts run on environments with little
76 # resources, such as Minikube. If you do want to specify resources, uncomment the following
77 # lines, adjust them as necessary, and remove the curly braces after 'resources:'.
85 ## Additional volume mounts in the kube-rbac-proxy container
86 ## See extraVolumes below
88 # - name: extra-volume
92 ## tls enables using TLS resources from a volume on secret referred to in tlsSecret below.
93 ## When enabling tlsClientAuth, client CA certificate must be set in tlsSecret.caItem.
94 ## Ref. https://github.com/brancz/kube-rbac-proxy/issues/187
98## tlsSecret refers to an existing secret holding TLS items: client CA certificate, private key and certificate.
99## secretName and volumeName can be templated.
100## If enabled, volume volumeName gets created on secret secretName.
101## The volume's resources will be used by kube-rbac-proxy if kubeRBACProxy.tls.enabled is set.
104 ## Key with client CA certificate (optional)
106 ## Key with certificate
108 ## Key with private key
110 ## Name of an existing secret
111 secretName: prometheus-node-exporter-tls
112 ## Name of the volume to be created
113 volumeName: prometheus-node-exporter-tls
114## Service configuration
116 ## Creating a service is enabled by default
120 ## IP address for type ClusterIP
122 ## Default service port. Sets the port of the exposed container as well (NE or kubeRBACProxy).
123 ## Use "servicePort" below if changing the service port only is desired.
125 ## Service port. Use this field if you wish to set a different service port
126 ## without changing the container port ("port" above).
128 ## Targeted port in the pod. Must refer to an open container port ("port" or "portName").
131 ## Name of the service port. Sets the port name of the main container (NE) as well.
133 ## Port number for service type NodePort
135 ## If true, node exporter will listen on all interfaces
136 listenOnAllInterfaces: true
137 ## Additional annotations and labels for the service
140 ## Dual stack settings for the service
141 ## https://kubernetes.io/docs/concepts/services-networking/dual-stack/#services
144 ipFamilies: ["IPv6", "IPv4"]
145 ipFamilyPolicy: "PreferDualStack"
146 ## External/Internal traffic policy setting (Cluster, Local)
147 ## https://kubernetes.io/docs/reference/networking/virtual-ips/#traffic-policies
148 externalTrafficPolicy: ""
149 internalTrafficPolicy: ""
150# Set a NetworkPolicy with:
151# ingress only on service.port or custom policy
157# Additional environment variables that will be passed to the daemonset
168 # List of pod labels to add to node exporter metrics
169 # https://github.com/prometheus-operator/prometheus-operator/blob/main/Documentation/api-reference/api.md#servicemonitor
171 # List of target labels to add to node exporter metrics
172 # https://github.com/prometheus-operator/prometheus-operator/blob/main/Documentation/api-reference/api.md#servicemonitor
178 ## proxyUrl: URL of a proxy that should be used for scraping.
181 ## Override serviceMonitor selector
184 ## Attach node metadata to discovered targets. Requires Prometheus v2.35.0 and above.
189 metricRelabelings: []
192 ## prometheus.monitor.apiVersion ApiVersion for the serviceMonitor Resource(defaults to "monitoring.coreos.com/v1")
194 ## SampleLimit defines per-scrape limit on number of scraped samples that will be accepted.
197 ## TargetLimit defines a limit on the number of scraped targets that will be accepted.
200 ## Per-scrape limit on number of labels that will be accepted for a sample. Only valid in Prometheus versions 2.27.0 and newer.
203 ## Per-scrape limit on length of labels name that will be accepted for a sample. Only valid in Prometheus versions 2.27.0 and newer.
205 labelNameLengthLimit: 0
206 ## Per-scrape limit on length of labels value that will be accepted for a sample. Only valid in Prometheus versions 2.27.0 and newer.
208 labelValueLengthLimit: 0
209 # PodMonitor defines monitoring for a set of pods.
210 # ref. https://github.com/prometheus-operator/prometheus-operator/blob/main/Documentation/api-reference/api.md#podmonitor
211 # Using a PodMonitor may be preferred in some environments where there is very large number
212 # of Node Exporter endpoints (1000+) behind a single service.
213 # The PodMonitor is disabled by default. When switching from ServiceMonitor to PodMonitor,
214 # the time series resulting from the configuration through PodMonitor may have different labels.
215 # For instance, there will not be the service label any longer which might
216 # affect PromQL queries selecting that label.
219 # Namespace in which to deploy the pod monitor. Defaults to the release namespace.
221 # Additional labels, e.g. setting a label for pod monitor selector as set in prometheus
223 # release: kube-prometheus-stack
224 # PodTargetLabels transfers labels of the Kubernetes Pod onto the target.
226 # apiVersion defaults to monitoring.coreos.com/v1.
228 # Override pod selector to select pod objects.
230 # Attach node metadata to discovered targets. Requires Prometheus v2.35.0 and above.
233 # The label to use to retrieve the job name from. Defaults to label app.kubernetes.io/name.
235 # Scheme/protocol to use for scraping.
237 # Path to scrape metrics at.
239 # BasicAuth allow an endpoint to authenticate over basic authentication.
240 # More info: https://prometheus.io/docs/operating/configuration/#endpoint
242 # Secret to mount to read bearer token for scraping targets.
243 # The secret needs to be in the same namespace as the pod monitor and accessible by the Prometheus Operator.
244 # https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.24/#secretkeyselector-v1-core
245 bearerTokenSecret: {}
246 # TLS configuration to use when scraping the endpoint.
248 # Authorization section for this endpoint.
249 # https://github.com/prometheus-operator/prometheus-operator/blob/main/Documentation/api-reference/api.md#safeauthorization
251 # OAuth2 for the URL. Only valid in Prometheus versions 2.27.0 and newer.
252 # https://github.com/prometheus-operator/prometheus-operator/blob/main/Documentation/api-reference/api.md#oauth2
254 # ProxyURL eg http://proxyserver:2195. Directs scrapes through proxy to this endpoint.
256 # Interval at which endpoints should be scraped. If not specified Prometheus' global scrape interval is used.
258 # Timeout after which the scrape is ended. If not specified, the Prometheus global scrape interval is used.
260 # HonorTimestamps controls whether Prometheus respects the timestamps present in scraped data.
261 honorTimestamps: true
262 # HonorLabels chooses the metric's labels on collisions with target labels.
264 # Whether to enable HTTP2. Default false.
266 # Drop pods that are not running. (Failed, Succeeded).
267 # Enabled by default. More info: https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle/#pod-phase
269 # FollowRedirects configures whether scrape requests follow HTTP 3xx redirects. Default false.
271 # Optional HTTP URL parameters
273 # RelabelConfigs to apply to samples before scraping. Prometheus Operator automatically adds
274 # relabelings for a few standard Kubernetes fields. The original scrape job's name
275 # is available via the __tmp_prometheus_job_name label.
276 # More info: https://prometheus.io/docs/prometheus/latest/configuration/configuration/#relabel_config
278 # MetricRelabelConfigs to apply to samples before ingestion.
279 metricRelabelings: []
280 # SampleLimit defines per-scrape limit on number of scraped samples that will be accepted.
282 # TargetLimit defines a limit on the number of scraped targets that will be accepted.
284 # Per-scrape limit on number of labels that will be accepted for a sample.
285 # Only valid in Prometheus versions 2.27.0 and newer.
287 # Per-scrape limit on length of labels name that will be accepted for a sample.
288 # Only valid in Prometheus versions 2.27.0 and newer.
289 labelNameLengthLimit: 0
290 # Per-scrape limit on length of labels value that will be accepted for a sample.
291 # Only valid in Prometheus versions 2.27.0 and newer.
292 labelValueLengthLimit: 0
293## Customize the updateStrategy if set
299# We usually recommend not to specify default resources and to leave this as a conscious
300# choice for the user. This also increases chances charts run on environments with little
301# resources, such as Minikube. If you do want to specify resources, uncomment the following
302# lines, adjust them as necessary, and remove the curly braces after 'resources:'.
310# Specify the container restart policy passed to the Node Export container
311# Possible Values: Always (default)|OnFailure|Never
314 # Specifies whether a ServiceAccount should be created
316 # The name of the ServiceAccount to use.
317 # If not set and create is true, a name is generated using the fullname template
321 automountServiceAccountToken: false
327containerSecurityContext:
328 readOnlyRootFilesystem: true
333 ## If true, create & use RBAC resources
336# for deployments that have node_exporter deployed outside of the cluster, list
337# their addresses here
339# Expose the service to the host network
341# hostUsers should be `true` or `~` if hostNetwork is true
342# for more information on the limitations of hostUsers
343# see https://kubernetes.io/docs/concepts/workloads/pods/user-namespaces/#limitations
345# Share the host process ID namespace
347# Share the host ipc namespace
349# Mount the node's root file system (/) at /host/root in the container
352 # Defines how new mounts in existing mounts on the node or in the container
353 # are propagated to the container or node, respectively. Possible values are
354 # None, HostToContainer, and Bidirectional. If this field is omitted, then
355 # None is used. More information on:
356 # https://kubernetes.io/docs/concepts/storage/volumes/#mount-propagation
357 mountPropagation: HostToContainer
358# Mount the node's proc file system (/proc) at /host/proc in the container
360 # Possible values are None, HostToContainer, and Bidirectional
362# Mount the node's sys file system (/sys) at /host/sys in the container
364 # Possible values are None, HostToContainer, and Bidirectional
366## Assign a group of affinity scheduling rules
367## The default nodeAffinity excludes Fargate nodes and virtual kubelets from scheduling
368## unless overridden by hard node affinity set in the field.
371# requiredDuringSchedulingIgnoredDuringExecution:
374# - key: metadata.name
379# Annotations to be added to node exporter pods
381 # Fix for very slow GKE cluster upgrades
382 cluster-autoscaler.kubernetes.io/safe-to-evict: "true"
383# Extra labels to add to node exporter pods (can be templated)
385## Extra labels to attach to all resources (can be templated)
387# Annotations to be added to node exporter daemonset
388daemonsetAnnotations: {}
389## set to true to add the release label so scraping of the servicemonitor with kube-prometheus-stack works out of the box
391# DNS policy for prometheus-node-exporter pods
392# When hostNetwork is true, you typically want "Default" or "ClusterFirstWithHostNet"
393# Ref: https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-s-dns-policy
395# Custom DNS configuration to be added to prometheus-node-exporter pods
400# - ns1.svc.cluster-domain.example
401# - my.dns.search.suffix
407## Assign a nodeSelector if operating a hybrid cluster
410 kubernetes.io/os: linux
411 # kubernetes.io/arch: amd64
412# Specify grace period for graceful termination of pods. Defaults to 30 if null or not specified
413terminationGracePeriodSeconds: null
417# Enable or disable container termination message settings
418# https://kubernetes.io/docs/tasks/debug/debug-application/determine-reason-pod-failure/
419terminationMessageParams:
421 # If enabled, specify the path for termination messages
422 terminationMessagePath: /dev/termination-log
423 # If enabled, specify the policy for termination messages
424 terminationMessagePolicy: File
425## Assign a PriorityClassName to pods if set
426# priorityClassName: ""
428## Additional container arguments
431 - --collector.filesystem.mount-points-exclude=^/(dev|proc|sys|run/containerd/.+|var/lib/docker/.+|var/lib/kubelet/.+)($|/)
432 - --collector.filesystem.fs-types-exclude=^(autofs|binfmt_misc|bpf|cgroup2?|configfs|debugfs|devpts|devtmpfs|fusectl|hugetlbfs|iso9660|mqueue|nsfs|overlay|proc|procfs|pstore|rpc_pipefs|securityfs|selinuxfs|squashfs|sysfs|tracefs|erofs)$
433# - --collector.diskstats.ignored-devices=^(ram|loop|fd|(h|s|v)d[a-z]|nvme\\d+n\\d+p)\\d+$
434# - --collector.textfile.directory=/run/prometheus
436## Additional mounts from the host to node-exporter container
438extraHostVolumeMounts: []
440# hostPath: <hostPath>
441# https://kubernetes.io/docs/concepts/storage/volumes/#hostpath-volume-types
442# type: "" (Default)|DirectoryOrCreate|Directory|FileOrCreate|File|Socket|CharDevice|BlockDevice
443# mountPath: <mountPath>
444# readOnly: true|false
445# mountPropagation: None|HostToContainer|Bidirectional
447## Additional configmaps to be mounted.
450# - name: <configMapName>
451# mountPath: <mountPath>
454# - name: <secretName>
455# mountPath: <mountPatch>
457## Override the deployment namespace
460## Additional containers for export metrics to text file; fields image,imagePullPolicy,securityContext take default value from main container
463# - name: nvidia-dcgm-exporter
464# image: nvidia/dcgm-exporter:1.4.3
469## Volume for sidecar containers
471sidecarVolumeMount: []
472# - name: collector-textfiles
473# mountPath: /run/prometheus
476## Additional mounts from the host to sidecar containers
478sidecarHostVolumeMounts: []
480# hostPath: <hostPath>
481# mountPath: <mountPath>
482# readOnly: true|false
483# mountPropagation: None|HostToContainer|Bidirectional
485## Additional InitContainers to initialize the pod
487extraInitContainers: []
488## Additional InitContainer to fix hostfile permissions required for some exporters. All fixes are disabled by default.
490permissionInitContainer:
493 repository: prometheus/busybox
496 pullPolicy: IfNotPresent
502 # Fixes /sys/devices/virtual/powercap/*/energy_uj
503 # Collector enabled by default
505 # Fixes /proc/slabinfo
506 # Collector disabled by default
516 initialDelaySeconds: 0
527 initialDelaySeconds: 0
531# Enable vertical pod autoscaler support for prometheus-node-exporter
532verticalPodAutoscaler:
534 # Recommender responsible for generating recommendation for the object.
535 # List should be empty (then the default recommender will generate the recommendation)
536 # or contain exactly one recommender.
538 # - name: custom-recommender-performance
540 # List of resources that the vertical pod autoscaler can control. Defaults to cpu and memory
541 controlledResources: []
542 # Specifies which resource values should be controlled: RequestsOnly or RequestsAndLimits.
543 # controlledValues: RequestsAndLimits
545 # Define the max allowed resources for the pod
549 # Define the min allowed resources for the pod
554# Specifies minimal number of replicas which need to be alive for VPA Updater to attempt pod eviction
556# Specifies whether recommended updates are applied when a Pod is started and whether recommended updates
557# are applied during the life of a Pod. Possible values are "Off", "Initial", "Recreate", and "Auto".
560# Extra manifests to deploy as an array
566# name: prometheus-extra
570## Extra volumes to become available in the pod
572# - name: extra-volume
576# secretName: node-exporter-secret
578## Extra volume mounts in the node-exporter container
580# - name: extra-volume
584# Override version of app, required if image.tag is defined and does not follow semver