DirectorySecurity AdvisoriesPricing
Sign in
Directory
traefik logoHELM

traefik

Helm chart
Last changed
Request a free trial

Contact our team to test out this Helm chart and related images for free. Please also indicate any other images you would like to evaluate.

Overview
Chart versions
Default values
Chart metadata
Images

Tag:

1
# Default values for Traefik
2
# This is a YAML-formatted file.
3
# Declare variables to be passed into templates
4
5
image: # @schema additionalProperties: false
6
# -- Traefik image host registry. Defaults to `docker.io` for Traefik Proxy and `ghcr.io` for Traefik Hub (when `hub.enabled` is true).
7
registry: cgr.dev # @schema type:[string, null]
8
# -- Traefik image repository. Defaults to `traefik` for Traefik Proxy and `traefik/traefik-hub` for Traefik Hub (when `hub.enabled` is true).
9
repository: chainguard-private/traefik # @schema type:[string, null]
10
# -- defaults to appVersion. It's used for version checking, even prefixed with experimental- or latest-.
11
# To pin by digest, prefer `image.digest`. A `<version>@<digest>` combo is also accepted here; in that case the digest is what Kubernetes verifies and the version is informational (and can drift from the underlying image).
12
tag: latest@sha256:07d27927e3d9fbc7cd51d6fc10ed4bc77c4729a4922a69eb6010641702eb6483 # @schema type:[string, null]
13
# -- Traefik image digest (e.g. `sha256:abc...`). When set, takes precedence over `tag`. Set `versionOverride` alongside it so the chart's version-checking logic knows the version (it cannot be derived from the digest).
14
digest: # @schema type:[string, null]; pattern:^sha256:[a-f0-9]{64}$
15
# -- Traefik image pull policy
16
pullPolicy: IfNotPresent
17
# -- Add additional label to all resources
18
commonLabels: {}
19
deployment:
20
# -- Enable deployment
21
enabled: true
22
# -- Deployment or DaemonSet
23
kind: Deployment
24
# -- Number of pods of the deployment (only applies when kind == Deployment).
25
# Set to null to omit spec.replicas, e.g. when an external controller (HPA/KEDA) owns scaling.
26
replicas: 1 # @schema type:[integer, null];minimum:0
27
# -- (int) Number of old history to retain to allow rollback (If not set, default Kubernetes value is set to 10)
28
revisionHistoryLimit: # @schema type:[integer, null];minimum:0
29
# -- Amount of time (in seconds) before Kubernetes will send the SIGKILL signal if Traefik does not shut down
30
terminationGracePeriodSeconds: 60
31
# -- The minimum number of seconds Traefik needs to be up and running before the DaemonSet/Deployment controller considers it available
32
minReadySeconds: 0
33
# -- (string/int) Override the liveness/readiness port. This is useful to integrate traefik
34
# with an external Load Balancer that performs healthchecks.
35
# @default -- `ports.traefik.port`
36
healthchecksPort: # @schema type:[string, integer, null]; minimum:0
37
# -- Override the liveness/readiness host. Useful for getting ping to respond on non-default entryPoint.
38
# @default -- `ports.traefik.hostIP` if set, otherwise Pod IP
39
healthchecksHost: ""
40
# -- Override the liveness/readiness scheme. Useful for getting ping to
41
# respond on websecure entryPoint.
42
healthchecksScheme: # @schema enum:[HTTP, HTTPS, null]; type:[string, null]; default: HTTP
43
# -- Override the readiness path.
44
# @default -- `/ping`
45
readinessPath: ""
46
# -- Override the liveness path.
47
# @default -- `/ping`
48
livenessPath: ""
49
# -- Additional deployment annotations (e.g. for jaeger-operator sidecar injection)
50
annotations: {}
51
# -- Additional deployment labels (e.g. for filtering deployment by custom labels)
52
labels: {}
53
# -- Additional pod annotations (e.g. for mesh injection or prometheus scraping)
54
# It supports templating. One can set it with values like traefik/name: '{{ template "traefik.name" . }}'
55
podAnnotations: {}
56
# -- Additional Pod labels (e.g. for filtering Pod by custom labels)
57
# It supports templating. One can set it with values like traefik/name: '{{ template "traefik.name" . }}'
58
podLabels: {}
59
# -- Additional containers (e.g. for metric offloading sidecars)
60
additionalContainers: []
61
# https://docs.datadoghq.com/developers/dogstatsd/unix_socket/?tab=host
62
# - name: socat-proxy
63
# image: alpine/socat:1.0.5
64
# args: ["-s", "-u", "udp-recv:8125", "unix-sendto:/socket/socket"]
65
# volumeMounts:
66
# - name: dsdsocket
67
# mountPath: /socket
68
# -- Additional volumes available for use with initContainers and additionalContainers
69
additionalVolumes: []
70
# - name: dsdsocket
71
# hostPath:
72
# path: /var/run/statsd-exporter
73
# -- Additional initContainers (e.g. for setting file permission as shown below)
74
initContainers: []
75
# The "volume-permissions" init container is required if you run into permission issues.
76
# Related issue: https://github.com/traefik/traefik-helm-chart/issues/396
77
# - name: volume-permissions
78
# image: busybox:latest
79
# command: ["sh", "-c", "touch /data/acme.json; chmod -v 600 /data/acme.json"]
80
# volumeMounts:
81
# - name: data
82
# mountPath: /data
83
# -- Use process namespace sharing
84
shareProcessNamespace: false
85
# -- (bool) Whether to use the host user namespace. Setting this to false enables user namespaces,
86
# which can improve security by isolating the pod's users from the host.
87
# See https://kubernetes.io/docs/concepts/workloads/pods/user-namespaces/
88
# @default -- unset (inherits cluster default)
89
hostUsers: # @schema type:[boolean, null]
90
# -- Custom pod DNS policy. Apply if `hostNetwork: true`
91
dnsPolicy: ""
92
# -- Custom pod [DNS config](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.30/#poddnsconfig-v1-core)
93
dnsConfig: {}
94
# -- Custom [host aliases](https://kubernetes.io/docs/tasks/network/customize-hosts-file-for-pods/)
95
hostAliases: []
96
# -- Pull secret for fetching traefik container image
97
imagePullSecrets: []
98
# -- Pod lifecycle actions
99
lifecycle: {}
100
# preStop:
101
# sleep:
102
# seconds: 20
103
# postStart:
104
# httpGet:
105
# path: /ping
106
# port: 8080
107
# host: localhost
108
# scheme: HTTP
109
# -- Set a runtimeClassName on pod
110
runtimeClassName: ""
111
# -- Percentage of memory limit to set for GOMEMLIMIT, set as decimal (0.9 = 90%, 0.95 = 95% etc). Only takes effect when resources.limits.memory is set. Set to 0 to disable (e.g. when using VPA or setting it via env)
112
goMemLimitPercentage: 0.9
113
# -- [Pod Disruption Budget](https://kubernetes.io/docs/reference/kubernetes-api/policy-resources/pod-disruption-budget-v1/)
114
# @default -- See _values.yaml_
115
podDisruptionBudget: # @schema additionalProperties: false
116
enabled: false
117
maxUnavailable: # @schema type:[string, integer, null];minimum:0
118
minAvailable: # @schema type:[string, integer, null];minimum:0
119
ingressClass: # @schema additionalProperties: false
120
# -- Create a default IngressClass for Traefik
121
enabled: true
122
isDefaultClass: true
123
name: ""
124
core: # @schema additionalProperties: false
125
# -- Can be used to use globally v2 router syntax. Deprecated since v3.4 /!\.
126
# See https://doc.traefik.io/traefik/v3.0/migration/v2-to-v3/#new-v3-syntax-notable-changes
127
defaultRuleSyntax: ""
128
# Traefik experimental features
129
experimental:
130
# -- Defines whether all plugins must be loaded successfully for Traefik to start
131
abortOnPluginFailure: false
132
fastProxy:
133
# -- Enables the FastProxy implementation.
134
enabled: false
135
# -- Enable debug mode for the FastProxy implementation.
136
debug: false
137
kubernetesGateway:
138
# -- Enable traefik experimental GatewayClass CRD
139
enabled: false
140
# -- Enable experimental plugins
141
plugins: {}
142
# -- Enable experimental local plugins
143
localPlugins: {}
144
# -- Enable OTLP logging experimental feature.
145
otlpLogs: false
146
# -- Enable Knative provider experimental feature.
147
knative: false
148
gateway:
149
# -- When providers.kubernetesGateway.enabled, deploy a default gateway
150
enabled: true
151
# -- Set a custom name to gateway
152
name: ""
153
# -- By default, Gateway is created in the same `Namespace` as Traefik.
154
namespace: ""
155
# -- Additional gateway annotations (e.g. for cert-manager.io/issuer)
156
annotations: {}
157
# -- [Infrastructure](https://kubernetes.io/blog/2023/11/28/gateway-api-ga/#gateway-infrastructure-labels)
158
infrastructure: {}
159
# -- Configure this Gateway as a [Default Gateway](https://kubernetes.io/blog/2025/11/06/gateway-api-v1-4/#introducing-default-gateways)
160
# by setting the `defaultScope` field (e.g. `All` or `Namespace`).
161
defaultScope: null # @schema enum:["All", "None", null]; type:[string, null]; default: null
162
listeners:
163
web:
164
# -- Port is the network port. Multiple listeners may use the same port, subject to the Listener compatibility rules.
165
# The port must match a port declared in ports section.
166
port: 8000
167
# -- Optional hostname. See [Hostname](https://gateway-api.sigs.k8s.io/reference/spec/#gateway.networking.k8s.io/v1.Hostname)
168
hostname: ""
169
# Specify expected protocol on this listener. See [ProtocolType](https://gateway-api.sigs.k8s.io/reference/spec/#gateway.networking.k8s.io/v1.ProtocolType)
170
protocol: HTTP
171
# -- (object) Routes are restricted to namespace of the gateway [by default](https://gateway-api.sigs.k8s.io/reference/spec/#gateway.networking.k8s.io/v1.FromNamespaces
172
namespacePolicy: # @schema type:[object, null]
173
# websecure listener is disabled by default because certificateRefs needs to be added,
174
# or you may specify TLS protocol with Passthrough mode and add "--providers.kubernetesGateway.experimentalChannel=true" in additionalArguments section.
175
# websecure:
176
# # -- Port is the network port. Multiple listeners may use the same port, subject to the Listener compatibility rules.
177
# # The port must match a port declared in ports section.
178
# port: 8443
179
# # -- Optional hostname. See [Hostname](https://gateway-api.sigs.k8s.io/reference/spec/#gateway.networking.k8s.io/v1.Hostname)
180
# hostname:
181
# # Specify expected protocol on this listener See [ProtocolType](https://gateway-api.sigs.k8s.io/reference/spec/#gateway.networking.k8s.io/v1.ProtocolType)
182
# protocol: HTTPS
183
# # -- Routes are restricted to namespace of the gateway [by default](https://gateway-api.sigs.k8s.io/reference/spec/#gateway.networking.k8s.io/v1.FromNamespaces)
184
# namespacePolicy:
185
# # -- Add certificates for TLS or HTTPS protocols. See [GatewayTLSConfig](https://gateway-api.sigs.k8s.io/reference/spec/#gateway.networking.k8s.io%2fv1.GatewayTLSConfig)
186
# certificateRefs:
187
# # -- TLS behavior for the TLS session initiated by the client. See [TLSModeType](https://gateway-api.sigs.k8s.io/reference/spec/#gateway.networking.k8s.io/v1.TLSModeType).
188
# mode:
189
gatewayClass: # @schema additionalProperties: false
190
# -- When providers.kubernetesGateway.enabled and gateway.enabled, deploy a default gatewayClass
191
enabled: true
192
# -- Set a custom name to GatewayClass
193
name: ""
194
# -- Additional gatewayClass labels (e.g. for filtering gateway objects by custom labels)
195
labels: {}
196
api: # @schema additionalProperties: false
197
# -- Enable the dashboard
198
dashboard: true
199
# -- Custom name for the dashboard (v3.7+).
200
dashboardName: "" # @schema type:[string, null]
201
# -- (bool) Disable the advertisement from the dashboard.
202
disableDashboardAd: # @schema type:[boolean, null]
203
# -- (bool) Enable the insecure API (HTTP)
204
insecure: # @schema type:[boolean, null]
205
# -- (bool) Enable the debug API
206
debug: # @schema type:[boolean, null]
207
# -- Configure API basePath
208
basePath: "" # @schema type:[string, null]; default: "/"
209
# -- Only dashboard & healthcheck IngressRoute are supported.
210
# It's recommended to create workloads CR outside of this Chart.
211
# @default -- See _values.yaml_
212
ingressRoute:
213
dashboard:
214
# -- Create an IngressRoute for the dashboard
215
enabled: false
216
# -- Additional ingressRoute annotations (e.g. for kubernetes.io/ingress.class)
217
annotations: {}
218
# -- Additional ingressRoute labels (e.g. for filtering IngressRoute by custom labels)
219
labels: {}
220
# -- The router match rule used for the dashboard ingressRoute
221
matchRule: PathPrefix(`/dashboard`) || PathPrefix(`/api`)
222
# -- The internal service used for the dashboard ingressRoute
223
# @default -- api@internal
224
services:
225
- name: api@internal
226
kind: TraefikService
227
# -- Specify the allowed entrypoints to use for the dashboard ingress route, (e.g. traefik, web, websecure).
228
# By default, it's using traefik entrypoint, which is not exposed.
229
# /!\ Do not expose your dashboard without any protection over the internet /!\
230
entryPoints: ["traefik"]
231
# -- Additional ingressRoute middlewares (e.g. for authentication)
232
middlewares: []
233
# -- TLS options (e.g. secret containing certificate)
234
tls: {}
235
healthcheck:
236
# -- Create an IngressRoute for the healthcheck probe
237
enabled: false
238
# -- Additional ingressRoute annotations (e.g. for kubernetes.io/ingress.class)
239
annotations: {}
240
# -- Additional ingressRoute labels (e.g. for filtering IngressRoute by custom labels)
241
labels: {}
242
# -- The router match rule used for the healthcheck ingressRoute
243
matchRule: PathPrefix(`/ping`)
244
# -- The internal service used for the healthcheck ingressRoute
245
# @default -- ping@internal
246
services:
247
- name: ping@internal
248
kind: TraefikService
249
# -- Specify the allowed entrypoints to use for the healthcheck ingress route, (e.g. traefik, web, websecure).
250
# By default, it's using traefik entrypoint, which is not exposed.
251
entryPoints: ["traefik"]
252
# -- Additional ingressRoute middlewares (e.g. for authentication)
253
middlewares: []
254
# -- TLS options (e.g. secret containing certificate)
255
tls: {}
256
updateStrategy: # @schema additionalProperties: false
257
# -- Customize updateStrategy of Deployment or DaemonSet
258
type: RollingUpdate
259
rollingUpdate:
260
maxUnavailable: 0 # @schema type:[integer, string, null]
261
maxSurge: 1 # @schema type:[integer, string, null]
262
readinessProbe: # @schema additionalProperties: false
263
# -- The number of consecutive failures allowed before considering the probe as failed.
264
failureThreshold: 1
265
# -- The number of seconds to wait before starting the first probe.
266
initialDelaySeconds: 2
267
# -- The number of seconds to wait between consecutive probes.
268
periodSeconds: 10
269
# -- The minimum consecutive successes required to consider the probe successful.
270
successThreshold: 1
271
# -- The number of seconds to wait for a probe response before considering it as failed.
272
timeoutSeconds: 2
273
livenessProbe: # @schema additionalProperties: false
274
# -- The number of consecutive failures allowed before considering the probe as failed.
275
failureThreshold: 3
276
# -- The number of seconds to wait before starting the first probe.
277
initialDelaySeconds: 2
278
# -- The number of seconds to wait between consecutive probes.
279
periodSeconds: 10
280
# -- The minimum consecutive successes required to consider the probe successful.
281
successThreshold: 1
282
# -- The number of seconds to wait for a probe response before considering it as failed.
283
timeoutSeconds: 2
284
# -- Define [Startup Probe](https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-startup-probes/#define-startup-probes)
285
startupProbe: {}
286
# @schema additionalProperties: false
287
providers:
288
# -- Defines the routing precedence between providers. See [upstream documentation](https://doc.traefik.io/traefik/reference/install-configuration/providers/overview/#routing-precedence) for the default order.
289
precedence: []
290
# @schema additionalProperties: false
291
kubernetesCRD:
292
# -- Load Kubernetes IngressRoute provider
293
enabled: true
294
# -- Allows IngressRoute to reference resources in namespace other than theirs
295
allowCrossNamespace: false
296
# -- Allows to reference ExternalName services in IngressRoute
297
allowExternalNameServices: false
298
# -- Allows to return 503 when there are no endpoints available
299
allowEmptyServices: true
300
# -- List of namespaces from which IngressRoute, IngressRouteTCP, IngressRouteUDP, and TraefikService are allowed to declare cross-provider references. Requires traefik v3.7.1+.
301
crossProviderNamespaces: []
302
# -- When the parameter is set, only resources containing an annotation with the same value are processed. Otherwise, resources missing the annotation, having an empty value, or the value traefik are processed. It will also set required annotation on Dashboard and Healthcheck IngressRoute when enabled.
303
ingressClass: ""
304
# -- See [upstream documentation](https://doc.traefik.io/traefik/reference/install-configuration/providers/kubernetes/kubernetes-ingress/#opt-providers-kubernetesIngress-labelselector)
305
labelSelector: ""
306
# -- Array of namespaces to watch. If left empty, Traefik watches all namespaces. . When using `rbac.namespaced`, it will watch helm release namespace and namespaces listed in this array.
307
namespaces: []
308
# -- Defines whether to use Native Kubernetes load-balancing mode by default.
309
nativeLBByDefault: false
310
# @schema additionalProperties: false
311
kubernetesIngress:
312
# -- Load Kubernetes Ingress provider
313
enabled: true
314
# -- Allows to reference ExternalName services in Ingress
315
allowExternalNameServices: false
316
# -- Allows to return 503 when there are no endpoints available
317
allowEmptyServices: true
318
# -- List of namespaces from which Ingresses or Services are allowed to declare Middlewares, TLSOptions, or ServersTransport references. Requires traefik v3.7.1+.
319
crossProviderNamespaces: []
320
# -- Only for Traefik v3.0, Deprecated since v3.1. See [upstream documentation](https://doc.traefik.io/traefik/v3.0/providers/kubernetes-ingress/#disableingressclasslookup)
321
disableIngressClassLookup: false
322
# -- When ingressClass is set, only Ingresses containing an annotation with the same value are processed. Otherwise, Ingresses missing the annotation, having an empty value, or the value traefik are processed.
323
ingressClass: # @schema type:[string, null]
324
labelSelector: # @schema type:[string, null]
325
# -- Array of namespaces to watch. If left empty, Traefik watches all namespaces. . When using `rbac.namespaced`, it will watch helm release namespace and namespaces listed in this array.
326
namespaces: []
327
# IP used for Kubernetes Ingress endpoints
328
publishedService:
329
# -- Enable [publishedService](https://doc.traefik.io/traefik/reference/install-configuration/providers/kubernetes/kubernetes-ingress/#ingressendpointpublishedservice),
330
# usually with the Service provided by this Chart. It's possible to use it with an external Service using pathOverride.
331
enabled: true
332
# -- Override path of Kubernetes Service used to copy status from. Format: namespace/servicename.
333
# Default to Service deployed with this Chart.
334
pathOverride: ""
335
# @schema additionalProperties: false
336
ingressEndpoint:
337
# -- Hostname used for Kubernetes Ingress endpoints
338
hostname: "" # @schema type:[string, null]
339
# -- IP used for Kubernetes Ingress endpoints
340
ip: "" # @schema type:[string, null]
341
# -- Defines whether to use Native Kubernetes load-balancing mode by default.
342
nativeLBByDefault: false
343
# -- Defines whether to make prefix matching strictly comply with the Kubernetes Ingress specification.
344
strictPrefixMatching: false
345
# @schema additionalProperties: false
346
kubernetesGateway:
347
# -- Enable Traefik Gateway provider for Gateway API
348
enabled: false
349
# -- List of namespaces from which Gateway API routes are allowed to declare TraefikService backendRef references. Requires traefik v3.7.1+.
350
crossProviderNamespaces: []
351
# -- Toggles support for the Experimental Channel resources (Gateway API release channels documentation).
352
# This option currently enables support for TCPRoute and TLSRoute.
353
experimentalChannel: false
354
# -- Array of namespaces to watch. If left empty, Traefik watches all namespaces. kubernetesGateway provider requires ClusterRole and as a consequence `rbac.namespaced` is not supported.
355
namespaces: []
356
# -- A label selector can be defined to filter on specific GatewayClass objects only.
357
labelSelector: ""
358
# -- Defines whether to use Native Kubernetes load-balancing mode by default.
359
nativeLBByDefault: false
360
# -- (int) Maximum QPS to the Kubernetes API server. A negative value disables client-side ratelimiting (v3.7.3+). Defaults to 50.
361
qps: # @schema type:[integer, null]
362
# -- (int) Maximum burst of requests to the Kubernetes API server (v3.7.3+). Defaults to 100.
363
burst: # @schema type:[integer, null]
364
statusAddress:
365
# -- This IP will get copied to the Gateway status.addresses, and currently only supports one IP value (IPv4 or IPv6).
366
ip: ""
367
# -- This Hostname will get copied to the Gateway status.addresses.
368
hostname: ""
369
service:
370
# -- The Kubernetes service to copy status addresses from. When using third parties tools like External-DNS, this option can be used to copy the service loadbalancer.status (containing the service's endpoints IPs) to the gateways. Default to Service of this Chart.
371
enabled: true
372
name: ""
373
namespace: ""
374
# @schema additionalProperties: false
375
file:
376
# -- Create a file provider
377
enabled: false
378
# -- Allows Traefik to automatically watch for file changes
379
watch: true
380
# -- File content as an object (will be YAML-formatted, go template supported) (see https://doc.traefik.io/traefik/reference/install-configuration/providers/others/file/)
381
content: {}
382
# @schema additionalProperties: false
383
kubernetesIngressNGINX:
384
# -- Enable Kubernetes Ingress NGINX provider
385
enabled: false
386
# -- Ingress Class Controller value this controller satisfies
387
controllerClass: "k8s.io/ingress-nginx"
388
# -- Name of the ingress class this controller satisfies
389
ingressClass: "nginx"
390
# -- Define if Ingress Controller should watch for Ingress Class by Name together with Controller Class
391
ingressClassByName: false
392
# -- Define if Ingress Controller should also watch for Ingresses without an IngressClass or the annotation specified
393
watchIngressWithoutClass: false
394
# -- Single namespace the controller watches for updates to Kubernetes objects. Mutually exclusive with watchNamespaceSelector.
395
watchNamespace: ""
396
# -- Select namespaces the controller watches for updates to Kubernetes objects. Mutually exclusive with watchNamespace.
397
# It requires a ClusterRole to list and watch namespaces, and is therefore incompatible with `rbac.namespaced`.
398
watchNamespaceSelector: ""
399
publishService:
400
# -- Enable publishService. Service fronting the Ingress controller, used to set the load-balancer status of Ingress objects.
401
# Usually the Service provided by this Chart. It's possible to use it with an external Service using pathOverride.
402
enabled: false
403
# -- Override path of Kubernetes Service used to copy status from. Format: namespace/servicename.
404
# Default to Service deployed with this Chart.
405
pathOverride: ""
406
# -- Customized address (or addresses, separated by comma) to set as the load-balancer status of Ingress objects this controller satisfies
407
publishStatusAddress: ""
408
# -- Service used to serve HTTP requests not matching any known server name (catch-all). Takes the form 'namespace/name'
409
defaultBackendService: ""
410
# -- Disable support for Services of type ExternalName
411
disableSvcExternalName: false
412
# -- Ingress refresh throttle duration
413
throttleDuration: ""
414
# -- Kubernetes certificate authority file path (not needed for in-cluster client)
415
certAuthFilePath: ""
416
# -- Kubernetes server endpoint (required for external cluster client)
417
endpoint: ""
418
# -- Kubernetes bearer token (not needed for in-cluster client). It accepts either a token value or a file path to the token
419
token: ""
420
# -- (bool) Defines whether to enable request buffering (default: false)
421
proxyRequestBuffering: null # @schema type:[boolean, null]
422
# -- (int) Default buffer size for reading client request body in bytes (default: 16384)
423
clientBodyBufferSize: # @schema type:[integer, null]
424
# -- (int) Default maximum size of a client request body in bytes (default: 1048576)
425
proxyBodySize: # @schema type:[integer, null]
426
# -- (bool) Defines whether to enable response buffering (default: false)
427
proxyBuffering: null # @schema type:[boolean, null]
428
# -- (int) Default buffer size for reading the response body in bytes (default: 8192)
429
proxyBufferSize: # @schema type:[integer, null]
430
# -- (int) Default number of buffers for reading a response (default: 4)
431
proxyBuffersNumber: # @schema type:[integer, null]
432
# -- (int) Amount of time to wait until a connection to a server can be established. Unitless, in seconds (default: 60)
433
proxyConnectTimeout: # @schema type:[integer, null]
434
# -- (int) Amount of time between two successive read operations. Unitless, in seconds (default: 60)
435
proxyReadTimeout: # @schema type:[integer, null]
436
# -- (int) Amount of time between two successive write operations. Unitless, in seconds (default: 60)
437
proxySendTimeout: # @schema type:[integer, null]
438
# -- Defines in which cases a request should be retried (default: "error timeout")
439
proxyNextUpstream: ""
440
# -- (int) Limits the number of possible tries if the backend server does not reply (default: 3)
441
proxyNextUpstreamTries: # @schema type:[integer, null]
442
# -- (int) Limits the total elapsed time to retry the request. Unitless, in seconds (default: 0)
443
proxyNextUpstreamTimeout: # @schema type:[integer, null]
444
# -- Defines which HTTP status codes should result in calling the default backend to return an error page
445
customHTTPErrors: []
446
# -- (int) Defines the idle timeout for keep-alive connections to upstream servers. Unitless, in seconds (default: 60)
447
upstreamKeepaliveTimeout: # @schema type:[integer, null]
448
# -- (bool) Allow Ingress to reference resources (e.g. ConfigMaps, Secrets) in different namespaces (default: false)
449
allowCrossNamespaceResources: null # @schema type:[boolean, null]
450
# -- List of allowed response headers inside the custom headers annotations
451
globalAllowedResponseHeaders: []
452
# -- URL to the service that provides authentication for all the locations. Per ingress auth-url annotation has precedence over this option.
453
globalAuthUrl: ""
454
# -- When set, the strategy is applied to every generated IPAllowList middleware.
455
# @default -- See below
456
ipAllowListStrategy:
457
# -- Number of trusted proxy hops to skip when extracting the client IP from the X-Forwarded-For header. 0 disables depth-based extraction. (default: 0)
458
depth: 0
459
# -- List of IPs to exclude when scanning the X-Forwarded-For header to find the client IP.
460
excludedIPS: []
461
# -- IPv6 subnet size used to group IPv6 addresses when checking the allow list. 0 disables subnet grouping.
462
ipv6Subnet: 0
463
# -- (bool) Enables parsing and adding -snippet annotations/directives (default: false)
464
allowSnippetAnnotations: null # @schema type:[boolean, null]
465
# -- (bool) Defines whether to reject the entire ingress when any path contains regex characters and pathType is Prefix or Exact (default: true)
466
strictValidatePathType: null # @schema type:[boolean, null]
467
# -- Defines the EntryPoint to use for HTTP requests
468
httpEntryPoint: "web"
469
# -- Defines the EntryPoint to use for HTTPS requests
470
httpsEntryPoint: "websecure"
471
# @schema additionalProperties: false
472
modsec:
473
# -- Enable ModSec engine. Requires Traefik Hub >= v3.20.0-ea.8.
474
enabled: false
475
# -- Enable OWASP Core Rules.
476
owaspCoreRules: false
477
# -- Custom ModSec rules snippet.
478
snippet: ""
479
# @schema additionalProperties: false
480
knative:
481
# -- Enable Knative provider
482
enabled: false
483
# -- Array of namespaces to watch. If left empty, Traefik watches all namespaces. . When using `rbac.namespaced`, it will watch helm release namespace and namespaces listed in this array.
484
namespaces: []
485
# -- Allow filtering Knative Ingress objects
486
labelSelector: ""
487
# -- Add volumes to the traefik pod. The volume name will be passed to tpl.
488
# This can be used to mount a cert pair or a configmap that holds a config.toml file.
489
# After the volume has been mounted, add the configs into traefik by using the `additionalArguments` list below, eg:
490
# `additionalArguments:
491
# - "--providers.file.filename=/config/dynamic.toml"
492
# - "--ping"
493
# - "--ping.entrypoint=web"`
494
volumes: []
495
# - name: public-cert
496
# mountPath: "/certs"
497
# type: secret
498
# - name: '{{ printf "%s-configs" .Release.Name }}'
499
# mountPath: "/config"
500
# type: configMap
501
502
# -- Additional volumeMounts to add to the Traefik container
503
additionalVolumeMounts: []
504
# -- For instance when using a logshipper for access logs
505
# - name: traefik-logs
506
# mountPath: /var/log/traefik
507
508
# -- See [logs reference](https://doc.traefik.io/traefik/reference/install-configuration/observability/logs-and-accesslogs/)
509
log:
510
# -- Set [logs format](https://doc.traefik.io/traefik/reference/install-configuration/observability/logs-and-accesslogs/#opt-log-format)
511
format: # @schema enum:["common", "json", null]; type:[string, null]; default: "common"
512
# By default, the level is set to INFO.
513
# -- Alternative logging levels are TRACE, DEBUG, INFO, WARN, ERROR, FATAL, and PANIC.
514
level: "INFO" # @schema enum:[TRACE,DEBUG,INFO,WARN,ERROR,FATAL,PANIC]; default: "INFO"
515
# -- To write the logs into a log file, use the filePath option.
516
filePath: ""
517
# -- When set to true and format is common, it disables the colorized output.
518
noColor: false
519
otlp:
520
# -- Set to true in order to enable OpenTelemetry on logs. Note that experimental.otlpLogs needs to be enabled.
521
enabled: false
522
# -- Service name used in OTLP backend. Default: traefik.
523
serviceName: # @schema type:[string, null]
524
http:
525
# -- Set to true in order to send logs to the OpenTelemetry Collector using HTTP.
526
enabled: false
527
# -- Format: <scheme>://<host>:<port><path>. Default: https://localhost:4318/v1/logs
528
endpoint: ""
529
# -- Additional headers sent with logs by the reporter to the OpenTelemetry Collector.
530
headers: {}
531
## Defines the TLS configuration used by the reporter to send logs to the OpenTelemetry Collector.
532
tls:
533
# -- The path to the certificate authority, it defaults to the system bundle.
534
ca: ""
535
# -- The path to the public certificate. When using this option, setting the key option is required.
536
cert: ""
537
# -- The path to the private key. When using this option, setting the cert option is required.
538
key: ""
539
# -- (bool) When set to true, the TLS connection accepts any certificate presented by the server regardless of the hostnames it covers.
540
insecureSkipVerify: # @schema type:[boolean, null]
541
grpc:
542
# -- Set to true in order to send logs to the OpenTelemetry Collector using gRPC
543
enabled: false
544
# -- Format: <host>:<port>. Default: "localhost:4317"
545
endpoint: ""
546
# -- Allows reporter to send logs to the OpenTelemetry Collector without using a secured protocol.
547
insecure: false
548
## Defines the TLS configuration used by the reporter to send logs to the OpenTelemetry Collector.
549
tls:
550
# -- The path to the certificate authority, it defaults to the system bundle.
551
ca: ""
552
# -- The path to the public certificate. When using this option, setting the key option is required.
553
cert: ""
554
# -- The path to the private key. When using this option, setting the cert option is required.
555
key: ""
556
# -- (bool) When set to true, the TLS connection accepts any certificate presented by the server regardless of the hostnames it covers.
557
insecureSkipVerify: # @schema type:[boolean, null]
558
# -- Defines additional resource attributes to be sent to the collector.
559
resourceAttributes: {}
560
# -- See [access logs reference](https://doc.traefik.io/traefik/reference/install-configuration/observability/logs-and-accesslogs/)
561
accessLog:
562
# -- To enable access logs
563
enabled: false
564
# -- Set [access log format](https://doc.traefik.io/traefik/reference/install-configuration/observability/logs-and-accesslogs/#opt-accesslog-format)
565
format: # @schema enum:["common", "genericCLF", "json", null]; type:[string, null]; default: "common"
566
# filePath: "/var/log/traefik/access.log
567
# -- (int) Set [bufferingSize](https://doc.traefik.io/traefik/reference/install-configuration/observability/logs-and-accesslogs/#opt-accesslog-bufferingSize)
568
bufferingSize: # @schema type:[integer, null]
569
# -- Set [timezone](https://doc.traefik.io/traefik/reference/install-configuration/observability/logs-and-accesslogs/#time-zones)
570
timezone: ""
571
# -- Set [filtering](https://doc.traefik.io/traefik/observe/logs-and-access-logs/#access-log-filters)
572
# @default -- See below
573
filters: # @schema additionalProperties: false
574
# -- Set statusCodes, to limit the access logs to requests with a status codes in the specified range
575
statusCodes: ""
576
# -- Set retryAttempts, to keep the access logs when at least one retry has happened
577
retryAttempts: false
578
# -- Set minDuration, to keep access logs when requests take longer than the specified duration
579
minDuration: ""
580
# -- Enables accessLogs for internal resources. Default: false.
581
addInternals: false
582
# -- Enables access log output alongside OTLP (v3.7+).
583
dualOutput: false
584
fields:
585
# -- Set default mode for fields.names
586
defaultMode: keep # @schema enum:[keep, drop, redact]; default: keep
587
# -- Names of the fields to limit.
588
names: {}
589
headers:
590
# -- [Limit logged fields or headers](https://doc.traefik.io/traefik/observe/logs-and-access-logs/#log-fields-customization)
591
defaultMode: drop # @schema enum:[keep, drop, redact]; default: drop
592
names: {}
593
queryParameters:
594
# -- Keep or drop all query parameters in the RequestPath access log field (v3.7.3+).
595
defaultMode: # @schema enum:[keep, drop, null]; type:[string, null]; default: null
596
otlp:
597
# -- Set to true in order to enable OpenTelemetry on access logs. Note that experimental.otlpLogs needs to be enabled.
598
enabled: false
599
# -- Service name used in OTLP backend. Default: traefik.
600
serviceName: # @schema type:[string, null]
601
http:
602
# -- Set to true in order to send access logs to the OpenTelemetry Collector using HTTP.
603
enabled: false
604
# -- Format: <scheme>://<host>:<port><path>. Default: https://localhost:4318/v1/logs
605
endpoint: ""
606
# -- Additional headers sent with access logs by the reporter to the OpenTelemetry Collector.
607
headers: {}
608
## Defines the TLS configuration used by the reporter to send access logs to the OpenTelemetry Collector.
609
tls:
610
# -- The path to the certificate authority, it defaults to the system bundle.
611
ca: ""
612
# -- The path to the public certificate. When using this option, setting the key option is required.
613
cert: ""
614
# -- The path to the private key. When using this option, setting the cert option is required.
615
key: ""
616
# -- (bool) When set to true, the TLS connection accepts any certificate presented by the server regardless of the hostnames it covers.
617
insecureSkipVerify: # @schema type:[boolean, null]
618
grpc:
619
# -- Set to true in order to send access logs to the OpenTelemetry Collector using gRPC
620
enabled: false
621
# -- Format: <host>:<port>. Default: "localhost:4317"
622
endpoint: ""
623
# -- Allows reporter to send access logs to the OpenTelemetry Collector without using a secured protocol.
624
insecure: false
625
## Defines the TLS configuration used by the reporter to send access logs to the OpenTelemetry Collector.
626
tls:
627
# -- The path to the certificate authority, it defaults to the system bundle.
628
ca: ""
629
# -- The path to the public certificate. When using this option, setting the key option is required.
630
cert: ""
631
# -- The path to the private key. When using this option, setting the cert option is required.
632
key: ""
633
# -- (bool) When set to true, the TLS connection accepts any certificate presented by the server regardless of the hostnames it covers.
634
insecureSkipVerify: # @schema type:[boolean, null]
635
# -- Defines additional resource attributes to be sent to the collector.
636
resourceAttributes: {}
637
metrics:
638
# -- Enable metrics for internal resources. Default: false
639
addInternals: false
640
## Prometheus is enabled by default.
641
## It can be disabled by setting "prometheus: null"
642
prometheus:
643
# -- Entry point used to expose metrics.
644
entryPoint: metrics
645
# -- (bool) Enable metrics on entry points. Default: true
646
addEntryPointsLabels: # @schema type:[boolean, null]
647
# -- (bool) Enable metrics on routers. Default: false
648
addRoutersLabels: # @schema type:[boolean, null]
649
# -- (bool) Enable metrics on services. Default: true
650
addServicesLabels: # @schema type:[boolean, null]
651
# -- Buckets for latency metrics. Default="0.1,0.3,1.2,5.0"
652
buckets: ""
653
# -- When manualRouting is true, it disables the default internal router in
654
## order to allow creating a custom router for prometheus@internal service.
655
manualRouting: false
656
# -- Add HTTP header labels to metrics. See EXAMPLES.md or upstream doc for usage.
657
headerLabels: {} # @schema type:[object, null]
658
service:
659
# -- Create a dedicated metrics service to use with ServiceMonitor
660
enabled: false
661
labels: {}
662
annotations: {}
663
# -- (bool) When set to true, it won't check if Prometheus Operator CRDs are deployed
664
disableAPICheck: # @schema type:[boolean, null]
665
serviceMonitor:
666
# -- Enable optional CR for Prometheus Operator. See EXAMPLES.md for more details.
667
enabled: false
668
apiVersion: "monitoring.coreos.com/v1"
669
metricRelabelings: []
670
relabelings: []
671
jobLabel: ""
672
interval: ""
673
honorLabels: false
674
scrapeTimeout: ""
675
honorTimestamps: false
676
enableHttp2: false
677
followRedirects: false
678
additionalLabels: {}
679
namespace: ""
680
namespaceSelector: {}
681
prometheusRule:
682
# -- Enable optional CR for Prometheus Operator. See EXAMPLES.md for more details.
683
enabled: false
684
apiVersion: "monitoring.coreos.com/v1"
685
additionalLabels: {}
686
namespace: ""
687
# datadog:
688
# ## Address instructs exporter to send metrics to datadog-agent at this address.
689
# address: "127.0.0.1:8125"
690
# ## The interval used by the exporter to push metrics to datadog-agent. Default=10s
691
# # pushInterval: 30s
692
# ## The prefix to use for metrics collection. Default="traefik"
693
# # prefix: traefik
694
# ## Enable metrics on entry points. Default=true
695
# # addEntryPointsLabels: false
696
# ## Enable metrics on routers. Default=false
697
# # addRoutersLabels: true
698
# ## Enable metrics on services. Default=true
699
# # addServicesLabels: false
700
# influxdb2:
701
# ## Address instructs exporter to send metrics to influxdb v2 at this address.
702
# address: localhost:8086
703
# ## Token with which to connect to InfluxDB v2.
704
# token: xxx
705
# ## Organisation where metrics will be stored.
706
# org: ""
707
# ## Bucket where metrics will be stored.
708
# bucket: ""
709
# ## The interval used by the exporter to push metrics to influxdb. Default=10s
710
# # pushInterval: 30s
711
# ## Additional labels (influxdb tags) on all metrics.
712
# # additionalLabels:
713
# # env: production
714
# # foo: bar
715
# ## Enable metrics on entry points. Default=true
716
# # addEntryPointsLabels: false
717
# ## Enable metrics on routers. Default=false
718
# # addRoutersLabels: true
719
# ## Enable metrics on services. Default=true
720
# # addServicesLabels: false
721
# statsd:
722
# ## Address instructs exporter to send metrics to statsd at this address.
723
# address: localhost:8125
724
# ## The interval used by the exporter to push metrics to influxdb. Default=10s
725
# # pushInterval: 30s
726
# ## The prefix to use for metrics collection. Default="traefik"
727
# # prefix: traefik
728
# ## Enable metrics on entry points. Default=true
729
# # addEntryPointsLabels: false
730
# ## Enable metrics on routers. Default=false
731
# # addRoutersLabels: true
732
# ## Enable metrics on services. Default=true
733
# # addServicesLabels: false
734
otlp:
735
# -- Set to true in order to enable the OpenTelemetry metrics
736
enabled: false
737
# -- (bool) Enable metrics on entry points. Default: true
738
addEntryPointsLabels: # @schema type:[boolean, null]
739
# -- (bool) Enable metrics on routers. Default: false
740
addRoutersLabels: # @schema type:[boolean, null]
741
# -- (bool) Enable metrics on services. Default: true
742
addServicesLabels: # @schema type:[boolean, null]
743
# -- Explicit boundaries for Histogram data points. Default: [.005, .01, .025, .05, .1, .25, .5, 1, 2.5, 5, 10]
744
explicitBoundaries: []
745
# -- Interval at which metrics are sent to the OpenTelemetry Collector. Default: 10s
746
pushInterval: ""
747
# -- Service name used in OTLP backend. Default: traefik.
748
serviceName: # @schema type:[string, null]
749
http:
750
# -- Set to true in order to send metrics to the OpenTelemetry Collector using HTTP.
751
enabled: false
752
# -- Format: <scheme>://<host>:<port><path>. Default: https://localhost:4318/v1/metrics
753
endpoint: ""
754
# -- Additional headers sent with metrics by the reporter to the OpenTelemetry Collector.
755
headers: {}
756
## Defines the TLS configuration used by the reporter to send metrics to the OpenTelemetry Collector.
757
tls:
758
# -- The path to the certificate authority, it defaults to the system bundle.
759
ca: ""
760
# -- The path to the public certificate. When using this option, setting the key option is required.
761
cert: ""
762
# -- The path to the private key. When using this option, setting the cert option is required.
763
key: ""
764
# -- (bool) When set to true, the TLS connection accepts any certificate presented by the server regardless of the hostnames it covers.
765
insecureSkipVerify: # @schema type:[boolean, null]
766
grpc:
767
# -- Set to true in order to send metrics to the OpenTelemetry Collector using gRPC
768
enabled: false
769
# -- Format: <host>:<port>. Default: "localhost:4317"
770
endpoint: ""
771
# -- Allows reporter to send metrics to the OpenTelemetry Collector without using a secured protocol.
772
insecure: false
773
## Defines the TLS configuration used by the reporter to send metrics to the OpenTelemetry Collector.
774
tls:
775
# -- The path to the certificate authority, it defaults to the system bundle.
776
ca: ""
777
# -- The path to the public certificate. When using this option, setting the key option is required.
778
cert: ""
779
# -- The path to the private key. When using this option, setting the cert option is required.
780
key: ""
781
# -- (bool) When set to true, the TLS connection accepts any certificate presented by the server regardless of the hostnames it covers.
782
insecureSkipVerify: # @schema type:[boolean, null]
783
# -- Defines additional resource attributes to be sent to the collector.
784
resourceAttributes: {}
785
ocsp:
786
# -- Enable OCSP stapling support.
787
# See https://doc.traefik.io/traefik/reference/install-configuration/tls/ocsp/
788
enabled: false
789
# -- Defines the OCSP responder URLs to use instead of the one provided by the certificate.
790
responderOverrides: {}
791
## Tracing
792
# -- https://doc.traefik.io/traefik/reference/install-configuration/observability/tracing/
793
# @default -- See _values.yaml_
794
tracing: # @schema additionalProperties: false
795
# -- Enables tracing for internal resources. Default: false.
796
addInternals: false
797
# -- Service name used in selected backend. Default: traefik.
798
serviceName: # @schema type:[string, null]
799
# -- Defines additional resource attributes to be sent to the collector.
800
resourceAttributes: {}
801
# -- Defines the list of request headers to add as attributes. It applies to client and server kind spans.
802
capturedRequestHeaders: []
803
# -- Defines the list of response headers to add as attributes. It applies to client and server kind spans.
804
capturedResponseHeaders: []
805
# -- By default, all query parameters are redacted. Defines the list of query parameters to not redact.
806
safeQueryParams: []
807
# -- (float) The proportion of requests to trace, specified between 0.0 and 1.0. Default: 1.0.
808
sampleRate: # @schema type:[number, null]; minimum:0; maximum:1
809
otlp:
810
# -- See https://doc.traefik.io/traefik/reference/install-configuration/observability/tracing/#configuration-options
811
enabled: false
812
http:
813
# -- Set to true in order to send metrics to the OpenTelemetry Collector using HTTP.
814
enabled: false
815
# -- Format: <scheme>://<host>:<port><path>. Default: https://localhost:4318/v1/tracing
816
endpoint: ""
817
# -- Additional headers sent with metrics by the reporter to the OpenTelemetry Collector.
818
headers: {}
819
## Defines the TLS configuration used by the reporter to send metrics to the OpenTelemetry Collector.
820
tls:
821
# -- The path to the certificate authority, it defaults to the system bundle.
822
ca: ""
823
# -- The path to the public certificate. When using this option, setting the key option is required.
824
cert: ""
825
# -- The path to the private key. When using this option, setting the cert option is required.
826
key: ""
827
# -- (bool) When set to true, the TLS connection accepts any certificate presented by the server regardless of the hostnames it covers.
828
insecureSkipVerify: # @schema type:[boolean, null]
829
grpc:
830
# -- Set to true in order to send metrics to the OpenTelemetry Collector using gRPC
831
enabled: false
832
# -- Format: <host>:<port>. Default: "localhost:4317"
833
endpoint: ""
834
# -- Allows reporter to send metrics to the OpenTelemetry Collector without using a secured protocol.
835
insecure: false
836
## Defines the TLS configuration used by the reporter to send metrics to the OpenTelemetry Collector.
837
tls:
838
# -- The path to the certificate authority, it defaults to the system bundle.
839
ca: ""
840
# -- The path to the public certificate. When using this option, setting the key option is required.
841
cert: ""
842
# -- The path to the private key. When using this option, setting the cert option is required.
843
key: ""
844
# -- (bool) When set to true, the TLS connection accepts any certificate presented by the server regardless of the hostnames it covers.
845
insecureSkipVerify: # @schema type:[boolean, null]
846
global:
847
checkNewVersion: true
848
# -- Please take time to consider whether or not you wish to share anonymous data with us
849
# See https://doc.traefik.io/traefik/contributing/data-collection/
850
sendAnonymousUsage: false
851
# -- Disable appending RemoteAddr to X-Forwarded-For header globally (v3.7+).
852
notAppendXForwardedFor: false
853
# -- Required for Azure Marketplace integration.
854
# See https://learn.microsoft.com/en-us/partner-center/marketplace-offers/azure-container-technical-assets-kubernetes?tabs=linux,linux2#update-the-helm-chart
855
# @default -- See _values.yaml_
856
azure:
857
enabled: false
858
images:
859
proxy:
860
image: chainguard-private/traefik
861
tag: latest@sha256:07d27927e3d9fbc7cd51d6fc10ed4bc77c4729a4922a69eb6010641702eb6483
862
registry: cgr.dev
863
hub:
864
image: chainguard-private/traefik
865
tag: latest@sha256:07d27927e3d9fbc7cd51d6fc10ed4bc77c4729a4922a69eb6010641702eb6483
866
registry: cgr.dev
867
# -- Additional arguments to be passed at Traefik's binary
868
# See [CLI Reference](https://docs.traefik.io/reference/static-configuration/cli/)
869
# Use curly braces to pass values: `helm install --set="additionalArguments={--providers.kubernetesingress.ingressclass=traefik-internal,--log.level=DEBUG}"`
870
additionalArguments: []
871
# - "--providers.kubernetesingress.ingressclass=traefik-internal"
872
# - "--log.level=DEBUG"
873
874
# -- Additional Environment variables to be passed to Traefik's binary
875
env: []
876
# -- Environment variables to be passed to Traefik's binary from configMaps or secrets
877
envFrom: []
878
# @schema mergeProperties: true
879
ports:
880
# @schema additionalProperties: false
881
traefik:
882
port: 8080
883
# -- (int) Use hostPort if set.
884
hostPort: # @schema type:[integer, null]; minimum:0
885
# -- Use hostIP if set. If not set, Kubernetes will default to 0.0.0.0, which
886
# means it's listening on all your interfaces and all your IPs. You may want
887
# to set this value if you need traefik to listen on specific interface
888
# only.
889
hostIP: # @schema type:[string, null]
890
# Defines whether the port is exposed if service.type is LoadBalancer or
891
# NodePort.
892
#
893
# -- You SHOULD NOT expose the traefik port on production deployments.
894
# If you want to access it from outside your cluster,
895
# use `kubectl port-forward` or create a secure ingress
896
expose:
897
default: false
898
# -- The exposed port for this service
899
exposedPort: 8080
900
# -- The port protocol (TCP/UDP)
901
protocol: TCP
902
observability: # @schema additionalProperties: false
903
# -- (bool) Defines whether a router attached to this EntryPoint produces metrics by default.
904
metrics: # @schema type:[boolean, null]; default: true
905
# -- (bool) Defines whether a router attached to this EntryPoint produces access-logs by default.
906
accessLogs: # @schema type:[boolean, null]; default: true
907
# -- (bool) Defines whether a router attached to this EntryPoint produces traces by default.
908
tracing: # @schema type:[boolean, null]; default: true
909
# -- Defines the tracing verbosity level for routers attached to this EntryPoint.
910
traceVerbosity: # @schema enum:[minimal, detailed, null]; type:[string, null]; default: minimal
911
web:
912
# -- (bool) Enable this entrypoint as a default entrypoint. When a service doesn't explicitly set an entrypoint it will only use this entrypoint.
913
asDefault: # @schema type: [boolean, null]; default: null
914
port: 8000
915
# hostPort: 8000
916
# containerPort: 8000
917
expose:
918
default: true
919
exposedPort: 80
920
# -- (string/int) Different target traefik port on the cluster, useful for IP type LB
921
targetPort: # @schema type:[string, integer, null]; minimum:0
922
# -- The port protocol (TCP/UDP)
923
protocol: TCP
924
# -- (int) See [upstream documentation](https://kubernetes.io/docs/concepts/services-networking/service/#type-nodeport)
925
nodePort: # @schema type:[integer, null]; minimum:0
926
# -- See [upstream documentation](https://doc.traefik.io/traefik/reference/install-configuration/entrypoints/#allowacmebypass)
927
allowACMEByPass: false
928
http:
929
redirections:
930
# -- Port Redirections
931
# Added in 2.2, one can make permanent redirects via entrypoints.
932
# Same sets of parameters: to, scheme, permanent and priority.
933
# https://doc.traefik.io/traefik/reference/install-configuration/entrypoints/#configuration-example
934
entryPoint: {}
935
forwardedHeaders:
936
# -- Trust forwarded headers information (X-Forwarded-*).
937
trustedIPs: []
938
insecure: false
939
# -- Disable appending RemoteAddr to X-Forwarded-For header (v3.7+).
940
notAppendXForwardedFor: false
941
proxyProtocol:
942
# -- Enable the Proxy Protocol header parsing for the entry point
943
trustedIPs: []
944
insecure: false
945
# -- Set transport settings for the entrypoint
946
# @default -- nil
947
transport:
948
respondingTimeouts:
949
readTimeout: # @schema type:[string, integer, null]
950
writeTimeout: # @schema type:[string, integer, null]
951
idleTimeout: # @schema type:[string, integer, null]
952
lifeCycle:
953
requestAcceptGraceTimeout: # @schema type:[string, integer, null]
954
graceTimeOut: # @schema type:[string, integer, null]
955
keepAliveMaxRequests: # @schema type:[integer, null]; minimum:0
956
keepAliveMaxTime: # @schema type:[string, integer, null]
957
# -- (bool) Enable this port as an uplink for multi cluster.
958
# ⚠️ This feature is experimental and requires Traefik Hub with a specific subscription.
959
uplink: # @schema type: [boolean, null]; default: null
960
observability: # @schema additionalProperties: false
961
# -- (bool) Enables metrics for this entryPoint.
962
metrics: # @schema type:[boolean, null]; default: true
963
# -- (bool) Enables access-logs for this entryPoint.
964
accessLogs: # @schema type:[boolean, null]; default: true
965
# -- (bool) Enables tracing for this entryPoint.
966
tracing: # @schema type:[boolean, null]; default: true
967
# -- Defines the tracing verbosity level for this entryPoint.
968
traceVerbosity: # @schema enum:[minimal, detailed, null]; type:[string, null]; default: minimal
969
websecure:
970
## -- Enable this entrypoint as a default entrypoint. When a service doesn't explicitly set an entrypoint it will only use this entrypoint.
971
# asDefault: true
972
port: 8443
973
# -- (int) Use hostPort if set.
974
hostPort: # @schema type:[integer, null]; minimum:0
975
# -- (int) Use containerPort if set.
976
containerPort: # @schema type:[integer, null]; minimum:0
977
expose:
978
default: true
979
exposedPort: 443
980
# -- (string/int) Different target traefik port on the cluster, useful for IP type LB
981
targetPort: # @schema type:[string, integer, null]; minimum:0
982
# -- The port protocol (TCP/UDP)
983
protocol: TCP
984
# -- (int) See [upstream documentation](https://kubernetes.io/docs/concepts/services-networking/service/#type-nodeport)
985
nodePort: # @schema type:[integer, null]; minimum:0
986
# -- See [upstream documentation](https://kubernetes.io/docs/concepts/services-networking/service/#application-protocol)
987
appProtocol: # @schema type:[string, null]
988
# -- See [upstream documentation](https://doc.traefik.io/traefik/reference/install-configuration/entrypoints/#allowacmebypass)
989
allowACMEByPass: false
990
http:
991
# -- See [upstream documentation](https://doc.traefik.io/traefik/security/request-path/#encoded-character-filtering)
992
# @default -- nil
993
encodedCharacters: # @schema additionalProperties: false
994
allowEncodedSlash: # @schema type:[boolean, null]
995
allowEncodedBackSlash: # @schema type:[boolean, null]
996
allowEncodedNullCharacter: # @schema type:[boolean, null]
997
allowEncodedSemicolon: # @schema type:[boolean, null]
998
allowEncodedPercent: # @schema type:[boolean, null]
999
allowEncodedQuestionMark: # @schema type:[boolean, null]
1000
allowEncodedHash: # @schema type:[boolean, null]
1001
# -- (int) Maximum size of request headers in bytes. Default: 1048576 (1 MB)
1002
maxHeaderBytes: # @schema type:[integer, null]; minimum:0
1003
# -- See [upstream documentation](https://doc.traefik.io/traefik/reference/install-configuration/entrypoints/#httpmiddlewares)
1004
middlewares: [] # @schema type: [array, null]
1005
# -- (bool) See [upstream documentation](https://doc.traefik.io/traefik/security/request-path/#path-sanitization)
1006
sanitizePath: # @schema type:[boolean, null]
1007
# -- Defines how request headers with underscores in their names are handled (v3.7.6+).
1008
# See [upstream documentation](https://doc.traefik.io/traefik/reference/install-configuration/entrypoints/#underscoreheadersstrategy)
1009
underscoreHeadersStrategy: # @schema enum:[keep, delete, reject, null]; type:[string, null]
1010
tls:
1011
# -- See [upstream documentation](https://doc.traefik.io/traefik/reference/install-configuration/entrypoints/#opt-http-tls)
1012
# @default -- true
1013
enabled: true
1014
options: ""
1015
certResolver: ""
1016
domains: []
1017
http3:
1018
# -- Enable HTTP/3 on the entrypoint. It also enables the http3 experimental feature.
1019
# See [upstream documentation](https://doc.traefik.io/traefik/reference/install-configuration/entrypoints/#opt-http3).
1020
# There are known limitations when trying to listen on same ports for TCP & UDP ([kubernetes#47249](https://github.com/kubernetes/kubernetes/issues/47249#issuecomment-587960741)): this chart works around it using a dual Service.
1021
enabled: false
1022
# -- (int) Defines the UDP port to advertise as the HTTP/3 authority.
1023
advertisedPort: # @schema type:[integer, null]; minimum:0
1024
forwardedHeaders:
1025
# -- Trust forwarded headers information (X-Forwarded-*).
1026
trustedIPs: []
1027
insecure: false
1028
# -- Disable appending RemoteAddr to X-Forwarded-For header (v3.7+).
1029
notAppendXForwardedFor: false
1030
proxyProtocol:
1031
# -- Enable the Proxy Protocol header parsing for the entry point
1032
trustedIPs: []
1033
insecure: false
1034
# -- Set transport settings for the entrypoint
1035
# @default -- nil
1036
transport:
1037
respondingTimeouts:
1038
readTimeout: # @schema type:[string, integer, null]
1039
writeTimeout: # @schema type:[string, integer, null]
1040
idleTimeout: # @schema type:[string, integer, null]
1041
lifeCycle:
1042
requestAcceptGraceTimeout: # @schema type:[string, integer, null]
1043
graceTimeOut: # @schema type:[string, integer, null]
1044
keepAliveMaxRequests: # @schema type:[integer, null]; minimum:0
1045
keepAliveMaxTime: # @schema type:[string, integer, null]
1046
observability: # @schema additionalProperties: false
1047
# -- (bool) Enables metrics for this entryPoint.
1048
metrics: # @schema type:[boolean, null]; default: true
1049
# -- (bool) Enables access-logs for this entryPoint.
1050
accessLogs: # @schema type:[boolean, null]; default: true
1051
# -- (bool) Enables tracing for this entryPoint.
1052
tracing: # @schema type:[boolean, null]; default: true
1053
# -- Defines the tracing verbosity level for this entryPoint.
1054
traceVerbosity: # @schema enum:[minimal, detailed, null]; type:[string, null]; default: minimal
1055
metrics:
1056
# -- When using hostNetwork, use another port to avoid conflict with node exporter:
1057
# https://github.com/prometheus/prometheus/wiki/Default-port-allocations
1058
port: 9100
1059
# -- You may not want to expose the metrics port on production deployments.
1060
# If you want to access it from outside your cluster,
1061
# use `kubectl port-forward` or create a secure ingress
1062
expose:
1063
default: false
1064
# -- The exposed port for this service
1065
exposedPort: 9100
1066
# -- The port protocol (TCP/UDP)
1067
protocol: TCP
1068
observability: # @schema additionalProperties: false
1069
# -- (bool) Enables metrics for this entryPoint.
1070
metrics: # @schema type:[boolean, null]; default: true
1071
# -- (bool) Enables access-logs for this entryPoint.
1072
accessLogs: # @schema type:[boolean, null]; default: true
1073
# -- (bool) Enables tracing for this entryPoint.
1074
tracing: # @schema type:[boolean, null]; default: true
1075
# -- Defines the tracing verbosity level for this entryPoint.
1076
traceVerbosity: # @schema enum:[minimal, detailed, null]; type:[string, null]; default: minimal
1077
# -- TLS Options are created as [TLSOption CRDs](https://doc.traefik.io/traefik/reference/routing-configuration/kubernetes/crd/tls/tlsoption/)
1078
# When using `labelSelector`, you'll need to set labels on tlsOption accordingly.
1079
# See EXAMPLE.md for details.
1080
tlsOptions: {}
1081
# -- TLS Store are created as [TLSStore CRDs](https://doc.traefik.io/traefik/reference/routing-configuration/kubernetes/crd/tls/tlsstore/).
1082
# This is useful if you want to set a default certificate. See EXAMPLE.md for details.
1083
tlsStore: {}
1084
service:
1085
enabled: true
1086
# -- Override the default Service name. Useful for adopting an existing Service (e.g., during migration from another ingress controller).
1087
nameOverride: "" # @schema type:[string, null]
1088
# -- Single service is using `MixedProtocolLBService` feature gate.
1089
# When set to false, it will create two Service, one for TCP and one for UDP.
1090
single: true
1091
# -- Additional annotations applied to both TCP and UDP services (e.g. for cloud provider specific config)
1092
annotations: {}
1093
# -- Additional annotations for TCP service only
1094
annotationsTCP: {}
1095
# -- Additional annotations for UDP service only
1096
annotationsUDP: {}
1097
# -- Additional service labels (e.g. for filtering Service by custom labels)
1098
labels: {}
1099
# -- Additional entries here will be added to the Service [spec](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.35/#servicespec-v1-core).
1100
# Cannot contain selector or ports entries.
1101
spec:
1102
type: LoadBalancer
1103
# -- Can be used to create multiple Service.
1104
# See EXAMPLES.md for more details.
1105
additionalServices: {}
1106
autoscaling: # @schema additionalProperties: false
1107
# -- Create HorizontalPodAutoscaler object.
1108
# See EXAMPLES.md for more details.
1109
enabled: false
1110
# -- (int) minReplicas is the lower limit for the number of replicas to which the autoscaler can scale down. It defaults to 1 pod.
1111
minReplicas: # @schema type:[integer, null]; minimum:0
1112
# -- (int) maxReplicas is the upper limit for the number of pods that can be set by the autoscaler; cannot be smaller than MinReplicas.
1113
maxReplicas: # @schema type:[integer, null]; minimum:0
1114
# -- metrics contains the specifications for which to use to calculate the desired replica count (the maximum replica count across all metrics will be used).
1115
metrics: []
1116
# -- behavior configures the scaling behavior of the target in both Up and Down directions (scaleUp and scaleDown fields respectively).
1117
behavior: {}
1118
# -- scaleTargetRef points to the target resource to scale, and is used for the pods for which metrics should be collected, as well as to actually change the replica count.
1119
# @default -- Traefik Deployment
1120
scaleTargetRef:
1121
apiVersion: apps/v1
1122
kind: Deployment
1123
name: "{{ template \"traefik.fullname\" . }}"
1124
persistence:
1125
# -- Enable persistence using Persistent Volume Claims
1126
# ref: http://kubernetes.io/docs/user-guide/persistent-volumes/.
1127
# It can be used to store TLS certificates along with `certificatesResolvers.<name>.acme.storage` option
1128
enabled: false
1129
name: data
1130
existingClaim: ""
1131
accessMode: ReadWriteOnce
1132
size: 128Mi
1133
storageClass: # @schema type:[string, null]
1134
volumeName: ""
1135
path: /data
1136
annotations: {}
1137
# -- Only mount a subpath of the Volume into the pod
1138
subPath: ""
1139
# -- Certificates resolvers configuration.
1140
# Ref: https://doc.traefik.io/traefik/reference/install-configuration/tls/certificate-resolvers/acme/
1141
# See EXAMPLES.md for more details.
1142
certificatesResolvers: {}
1143
# -- If hostNetwork is true, runs traefik in the host network namespace
1144
# To prevent unschedulable pods due to port collisions, if hostNetwork=true
1145
# and replicas>1, a pod anti-affinity is recommended and will be set if the
1146
# affinity is left as default.
1147
hostNetwork: false
1148
rbac: # @schema additionalProperties: false
1149
# -- Whether Role Based Access Control objects like roles and rolebindings should be created
1150
enabled: true
1151
# -- When set to true: <br />
1152
# 1. It switches respectively the use of `ClusterRole` and `ClusterRoleBinding` to `Role` and `RoleBinding`.<br />
1153
# 2. It adds `disableClusterScopeResources` on Ingress and CRD (Kubernetes) providers<br />
1154
# **NOTE**: `IngressClass`, `NodePortLB` and **Gateway** provider cannot be used with namespaced RBAC. <br />
1155
# See [upstream documentation](https://doc.traefik.io/traefik/reference/install-configuration/providers/kubernetes/kubernetes-ingress/#opt-providers-kubernetesIngress-disableClusterScopeResources) for more details.
1156
namespaced: false
1157
# -- Enable user-facing roles
1158
# https://kubernetes.io/docs/reference/access-authn-authz/rbac/#user-facing-roles
1159
aggregateTo: []
1160
# -- The service account the pods will use to interact with the Kubernetes API
1161
serviceAccount: # @schema additionalProperties: false
1162
# If set, an existing service account is used
1163
# If not set, a service account is created automatically using the fullname template
1164
name: ""
1165
# -- Additional serviceAccount annotations (e.g. for oidc authentication)
1166
serviceAccountAnnotations: {}
1167
# -- [Resources](https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/) for `traefik` container.
1168
resources: {}
1169
# -- This example pod anti-affinity forces the scheduler to put traefik pods
1170
# -- on nodes where no other traefik pods are scheduled.
1171
# It should be used when hostNetwork: true to prevent port conflicts
1172
affinity: {}
1173
# podAntiAffinity:
1174
# requiredDuringSchedulingIgnoredDuringExecution:
1175
# - labelSelector:
1176
# matchLabels:
1177
# app.kubernetes.io/name: '{{ template "traefik.name" . }}'
1178
# app.kubernetes.io/instance: '{{ .Release.Name }}-{{ include "traefik.namespace" . }}'
1179
# topologyKey: kubernetes.io/hostname
1180
1181
# -- nodeSelector is the simplest recommended form of node selection constraint.
1182
nodeSelector: {}
1183
# -- Tolerations allow the scheduler to schedule pods with matching taints.
1184
tolerations: []
1185
# -- You can use topology spread constraints to control
1186
# how Pods are spread across your cluster among failure-domains.
1187
topologySpreadConstraints: []
1188
# This example topologySpreadConstraints forces the scheduler to put traefik pods
1189
# on nodes where no other traefik pods are scheduled.
1190
# - labelSelector:
1191
# matchLabels:
1192
# app.kubernetes.io/name: '{{ template "traefik.name" . }}'
1193
# maxSkew: 1
1194
# topologyKey: kubernetes.io/hostname
1195
# whenUnsatisfiable: DoNotSchedule
1196
1197
# -- [Pod Priority and Preemption](https://kubernetes.io/docs/concepts/scheduling-eviction/pod-priority-preemption/)
1198
priorityClassName: ""
1199
# -- [SecurityContext](https://kubernetes.io/docs/reference/kubernetes-api/workload-resources/pod-v1/#security-context-1)
1200
# @default -- See _values.yaml_
1201
securityContext:
1202
allowPrivilegeEscalation: false
1203
capabilities:
1204
drop: [ALL]
1205
readOnlyRootFilesystem: true
1206
# -- [Pod Security Context](https://kubernetes.io/docs/reference/kubernetes-api/workload-resources/pod-v1/#security-context)
1207
# @default -- See _values.yaml_
1208
podSecurityContext:
1209
runAsGroup: 65532
1210
runAsNonRoot: true
1211
runAsUser: 65532
1212
seccompProfile:
1213
type: RuntimeDefault
1214
#
1215
# -- Extra objects to deploy (value evaluated as a template)
1216
#
1217
# In some cases, it can avoid the need for additional, extended or adhoc deployments.
1218
# See #595 for more details and traefik/tests/values/extra.yaml for example.
1219
extraObjects: []
1220
# -- This field overrides the default Release Namespace for Helm.
1221
# It will not affect optional CRDs such as `ServiceMonitor` and `PrometheusRules`
1222
namespaceOverride: ""
1223
# -- This field overrides the default app.kubernetes.io/instance label for all Objects.
1224
instanceLabelOverride: ""
1225
# -- This field overrides the default version extracted from image.tag. Required when pinning by `image.digest`, since the version cannot be derived from a digest.
1226
versionOverride: ""
1227
# -- overrides the app.kubernetes.io/name label
1228
nameOverride: ""
1229
# -- Overrides the resource name for templates (i.e deployment, service, etc..)
1230
fullnameOverride: ""
1231
# Traefik Hub configuration. See https://doc.traefik.io/traefik-hub/
1232
hub: # @schema additionalProperties: false
1233
# -- (bool) Install Traefik Hub. Without `hub.token`, it runs in proxy mode: a drop-in Traefik
1234
# Proxy, which requires Traefik Hub >= v3.21.0-ea.
1235
# @default -- `true` when `hub.token` is set
1236
enabled: # @schema type:[boolean, null]
1237
# -- Name of `Secret` with key 'token' set to a valid license token.
1238
# It enables API Gateway.
1239
token: ""
1240
# -- Mount path for token secret.
1241
tokenMountPath: "/etc/secrets"
1242
# -- Use the hardened image variant. It appends `-hardened` to the tag and defaults the image
1243
# to `registry.traefik.io/traefik-hub`. Requires `hub.enabled` and Traefik Hub >= v3.21.0-ea.
1244
hardened: false
1245
# -- (bool) Disables all external network connections.
1246
offline: # @schema type:[boolean, null]
1247
# -- By default, Traefik Hub provider watches all namespaces. When using `rbac.namespaced`, it will watch helm release namespace and namespaces listed in this array.
1248
namespaces: [] # @schema required:true
1249
apimanagement:
1250
# -- Set to true in order to enable API Management. Requires a valid license token.
1251
enabled: false
1252
admission:
1253
# -- WebHook admission server listen address. Default: "0.0.0.0:9943".
1254
listenAddr: ""
1255
# -- Certificate name of the WebHook admission server. Default: "hub-agent-cert".
1256
secretName: "hub-agent-cert"
1257
# -- By default, this chart handles directly the tls certificate required for the admission webhook. It's possible to disable this behavior and handle it outside of the chart. See EXAMPLES.md for more details.
1258
selfManagedCertificate: false
1259
# -- Set custom certificate for the WebHook admission server. The certificate should be specified with _tls.crt_ and _tls.key_ in base64 encoding.
1260
customWebhookCertificate: {}
1261
# -- Set it to false if you need to disable Traefik Hub pod restart when mutating webhook certificate is updated. It's done with a label update.
1262
restartOnCertificateChange: true
1263
# -- Set custom annotations.
1264
annotations: {}
1265
openApi:
1266
# -- When set to true, it will only accept paths and methods that are explicitly defined in its OpenAPI specification
1267
validateRequestMethodAndPath: false
1268
mcpgateway:
1269
# -- Set to true in order to enable AI MCP Gateway. Requires a valid license token.
1270
enabled: false
1271
# -- (int) Hard limit for the size of request bodies inspected by the gateway. Accepts a plain integer representing **bytes**. The default value is `1048576` (1 MiB).
1272
maxRequestBodySize: # @schema type:[integer, null]; minimum:0
1273
aigateway:
1274
# -- Set to true in order to enable AI Gateway. Requires a valid license token.
1275
enabled: false
1276
# -- (int) Hard limit for the size of request bodies inspected by the gateway. Accepts a plain integer representing **bytes**. The default value is `1048576` (1 MiB).
1277
maxRequestBodySize: # @schema type:[integer, null]; minimum:0
1278
providers:
1279
consulCatalogEnterprise:
1280
# -- Enable Consul Catalog Enterprise backend with default settings.
1281
enabled: false
1282
# -- Use local agent caching for catalog reads.
1283
cache: false
1284
# -- Enable Consul Connect support.
1285
connectAware: false
1286
# -- Consider every service as Connect capable by default.
1287
connectByDefault: false
1288
# -- Constraints is an expression that Traefik matches against the container's labels
1289
constraints: ""
1290
# -- Default rule.
1291
defaultRule: "Host(`{{ normalize .Name }}`)"
1292
endpoint:
1293
# -- The address of the Consul server
1294
address: ""
1295
# -- Data center to use. If not provided, the default agent data center is used
1296
datacenter: ""
1297
# -- (int) WaitTime limits how long a Watch will block. If not provided, the agent default
1298
endpointWaitTime: # @schema type:[integer, null]
1299
httpauth:
1300
# -- Basic Auth password
1301
password: ""
1302
# -- Basic Auth username
1303
username: ""
1304
# -- The URI scheme for the Consul server
1305
scheme: ""
1306
tls:
1307
# -- TLS CA
1308
ca: ""
1309
# -- TLS cert
1310
cert: ""
1311
# -- TLS insecure skip verify
1312
insecureSkipVerify: false
1313
# -- TLS key
1314
key: ""
1315
# -- Token is used to provide a per-request ACL token which overrides the agent's
1316
token: ""
1317
# -- Expose containers by default.
1318
exposedByDefault: true
1319
# -- Sets the namespaces used to discover services (Consul Enterprise only).
1320
namespaces: ""
1321
# -- Sets the partition used to discover services (Consul Enterprise only).
1322
partition: ""
1323
# -- Prefix for consul service tags.
1324
prefix: "traefik"
1325
# -- Interval for checking Consul API.
1326
refreshInterval: 15
1327
# -- Forces the read to be fully consistent.
1328
requireConsistent: false
1329
# -- Name of the Traefik service in Consul Catalog (needs to be registered via the
1330
serviceName: "traefik"
1331
# -- Use stale consistency for catalog reads.
1332
stale: false
1333
# -- A list of service health statuses to allow taking traffic.
1334
strictChecks: "passing, warning"
1335
# -- Watch Consul API events.
1336
watch: false
1337
microcks:
1338
# -- Enable Microcks provider.
1339
enabled: false
1340
auth:
1341
# -- Microcks API client ID.
1342
clientId: ""
1343
# -- Microcks API client secret.
1344
clientSecret: ""
1345
# -- Microcks API endpoint.
1346
endpoint: ""
1347
# -- Microcks API token.
1348
token: ""
1349
# -- Microcks API endpoint.
1350
endpoint: ""
1351
# -- Polling interval for Microcks API.
1352
pollInterval: 30
1353
# -- Polling timeout for Microcks API.
1354
pollTimeout: 5
1355
tls:
1356
# -- TLS CA
1357
ca: ""
1358
# -- TLS cert
1359
cert: ""
1360
# -- TLS insecure skip verify
1361
insecureSkipVerify: false
1362
# -- TLS key
1363
key: ""
1364
multicluster:
1365
# -- Enable Multi-cluster provider.
1366
enabled: false
1367
# -- Polling interval for Multi-cluster.
1368
pollInterval: 5
1369
# -- Polling timeout for Multi-cluster.
1370
pollTimeout: 5
1371
# @schema mergeProperties: true
1372
# -- Child cluster configurations, keyed by a unique name.
1373
# @default -- {}
1374
children:
1375
# @schema additionalProperties: false
1376
cluster-1:
1377
# -- URL of the child cluster's uplink entrypoint.
1378
address: ""
1379
# -- TLS and transport configuration for connecting to this child.
1380
# @default -- {}
1381
serversTransport:
1382
# -- (bool) Disable TLS certificate verification. **Not recommended for production.**
1383
# @default -- false
1384
insecureSkipVerify: # @schema type:[boolean, null]
1385
# -- Server name used for SNI and certificate verification.
1386
serverName: ""
1387
rootCAs: []
1388
certificates: []
1389
# -- (int) Maximum idle connections per host.
1390
# @default -- 200
1391
maxIdleConnsPerHost: # @schema type:[integer, null]
1392
# -- (bool) Disable HTTP/2 for connections to this child.
1393
# @default -- false
1394
disableHTTP2: # @schema type:[boolean, null]
1395
# -- Minimum TLS version (e.g. `VersionTLS12`, `VersionTLS13`).
1396
minVersion: ""
1397
# -- Maximum TLS version (e.g. `VersionTLS12`, `VersionTLS13`).
1398
maxVersion: ""
1399
# -- List of supported cipher suites for TLS versions up to 1.2.
1400
cipherSuites: []
1401
# -- URI used to match against SAN URIs during the server's certificate verification.
1402
peerCertURI: ""
1403
forwardingTimeouts:
1404
# @schema type:[string, integer, null]
1405
# -- Timeout for establishing connections.
1406
# @default -- 30s
1407
dialTimeout:
1408
# @schema type:[string, integer, null]
1409
# -- Timeout for reading response headers.
1410
# @default -- 0s
1411
responseHeaderTimeout:
1412
# @schema type:[string, integer, null]
1413
# -- Timeout for idle connections.
1414
# @default -- 90s
1415
idleConnTimeout:
1416
# @schema type:[string, integer, null]
1417
# -- Timeout for HTTP/2 server ping frames.
1418
# @default -- 15s
1419
pingTimeout:
1420
# @schema type:[string, integer, null]
1421
# -- Timeout for HTTP/2 connection idle reads.
1422
# @default -- 0s
1423
readIdleTimeout:
1424
# @schema type:[string, integer, null]
1425
# -- Timeout for reading the request body.
1426
# @default -- 0s
1427
readTimeout:
1428
# @schema type:[string, integer, null]
1429
# -- Timeout for writing the response.
1430
# @default -- 0s
1431
writeTimeout:
1432
spiffe:
1433
ids: []
1434
# @schema type:[string, integer, null]
1435
# -- SPIFFE trust domain.
1436
trustDomain: ""
1437
# @schema additionalProperties: false
1438
nutanixPrismCentral:
1439
# -- Enable Nutanix Prism Central provider.
1440
enabled: false
1441
# -- Prism Central endpoint.
1442
endpoint: ""
1443
# -- Prism Central username.
1444
username: ""
1445
# -- Prism Central password.
1446
password: ""
1447
# -- Prism Central API key.
1448
apiKey: ""
1449
# -- Base configuration file path.
1450
filename: ""
1451
# -- Polling interval for Nutanix Prism Central API.
1452
pollInterval: 30
1453
# -- Polling timeout for Nutanix Prism Central API.
1454
pollTimeout: 5
1455
# -- Category key used to derive the service name.
1456
serviceNameCategoryKey: "TraefikServiceName"
1457
# -- Filter VMs by VPCs. List of `{ uuid: "<vpc-uuid>" }` entries.
1458
allowedVpcs: []
1459
tls:
1460
# -- TLS CA
1461
ca: ""
1462
# -- TLS cert
1463
cert: ""
1464
# -- TLS key
1465
key: ""
1466
# -- TLS insecure skip verify
1467
insecureSkipVerify: false
1468
redis:
1469
# -- (bool) Enable Redis Cluster. Default: true.
1470
cluster: # @schema type:[boolean, null]
1471
# -- (int) Database used to store information. Default: 0.
1472
database: # @schema type:[integer, null]
1473
# -- Endpoints of the Redis instances to connect to. Default: "".
1474
endpoints: ""
1475
# -- The username to use when connecting to Redis endpoints. Default: "".
1476
username: ""
1477
# -- The password to use when connecting to Redis endpoints. Default: "".
1478
password: ""
1479
sentinel:
1480
# -- Name of the set of main nodes to use for main selection. Required when using Sentinel. Default: "".
1481
masterset: ""
1482
# -- Username to use for sentinel authentication (can be different from endpoint username). Default: "".
1483
username: ""
1484
# -- Password to use for sentinel authentication (can be different from endpoint password). Default: "".
1485
password: ""
1486
# -- Timeout applied on connection with redis. Default: "0s".
1487
timeout: ""
1488
tls:
1489
# -- Path to the certificate authority used for the secured connection.
1490
ca: ""
1491
# -- Path to the public certificate used for the secure connection.
1492
cert: ""
1493
# -- Path to the private key used for the secure connection.
1494
key: ""
1495
# -- When insecureSkipVerify is set to true, the TLS connection accepts any certificate presented by the server. Default: false.
1496
insecureSkipVerify: false
1497
# -- (bool) Enable export of error logs to the platform. Default: true.
1498
sendlogs: # @schema type:[boolean, null]
1499
tracing:
1500
additionalTraceHeaders:
1501
# -- Tracing headers to duplicate.
1502
# To configure the following, tracing.otlp.enabled needs to be set to true.
1503
# @default -- See below
1504
enabled: false
1505
traceContext:
1506
# -- Name of the header that will contain the parent-id header copy.
1507
parentId: ""
1508
# -- Name of the header that will contain the trace-id copy.
1509
traceId: ""
1510
# -- Name of the header that will contain the traceparent copy.
1511
traceParent: ""
1512
# -- Name of the header that will contain the tracestate copy.
1513
traceState: ""
1514
# Define private plugin sources
1515
pluginRegistry:
1516
sources: {}
1517
# -- Required for OCI Marketplace integration.
1518
# See https://docs.public.content.oci.oraclecloud.com/en-us/iaas/Content/Marketplace/understanding-helm-charts.htm
1519
# @default -- See _values.yaml_
1520
oci_meta:
1521
# -- Enable specific values for Oracle Cloud Infrastructure
1522
enabled: false
1523
# -- It needs to be an ocir repo
1524
repo: cgr.dev
1525
images:
1526
proxy:
1527
image: chainguard-private/traefik
1528
tag: latest@sha256:07d27927e3d9fbc7cd51d6fc10ed4bc77c4729a4922a69eb6010641702eb6483
1529
hub:
1530
image: chainguard-private/traefik
1531
tag: latest@sha256:07d27927e3d9fbc7cd51d6fc10ed4bc77c4729a4922a69eb6010641702eb6483
1532
# -- Required for IBM Cloud Marketplace integration.
1533
# Injected by IBM Cloud Catalog when deploying via IBM Cloud Schematics. This value is not used by the chart.
1534
offering_version: "" # @schema type:[string, null]
1535
# -- Allow the Helm chart to be used as optional subchart.
1536
enabled: true # @schema type:boolean; const:true
1537

The trusted source for open source

Talk to an expert
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsChainguard OS PackagesChainguard ActionsChainguard Agent SkillsIntegrationsPricing
© 2026 Chainguard, Inc. All Rights Reserved.
Chainguard® and the Chainguard logo are registered trademarks of Chainguard, Inc. in the United States and/or other countries.
The other respective trademarks mentioned on this page are owned by the respective companies and use of them does not imply any affiliation or endorsement.