Reference
Helm values
The chart values most installs touch, grouped by purpose, with their defaults.
This page condenses the values of the telark chart
(oci://ghcr.io/telark/charts/telark). The complete list, generated from
the chart and checked in CI, is
charts/telark/VALUES.md;
the explained reference is the
chart README.
Set values with --set key=value or -f values.yaml. Helm does not
remember --set flags across upgrades: pass them again on every
helm upgrade, or keep them in a values file.
| Key | Default | Notes |
|---|
app.auth.bootstrap.admins | [] | Admin emails. The render fails while it is empty and self-registration is off. |
app.persistence.storageClass | "" | A ReadWriteMany class for the two exporter replicas of standard and performance. The render fails on "" unless app.singleNode=true. "-" disables provisioning. |
| Key | Default | Notes |
|---|
app.name | telark | Prefix of every resource name. The API group stays telark.io. |
app.namespace | telark | Must match the release namespace (-n). |
app.mode | standard | minimal, standard or performance: replicas, resources, rate limits and disruption budgets of every Telark service. Subcharts keep their own sizing. |
app.singleNode | false | One exporter replica on ReadWriteOnce, so no RWX class is needed. |
crds.enabled | true | Installs the telark-crds subchart. Set false to manage CRDs out of band. |
app.image.registry | ghcr.io/telark | Registry hosting the service images. |
app.image.pullPolicy | Always | Pull policy of every service container. |
app.image.pullSecrets, global.imagePullSecrets | [] | Only for a private registry or mirror. |
| Key | Default | Notes |
|---|
app.auth.passkey.id | "" | WebAuthn relying-party ID. Empty follows the request host. Required with ingress.enabled or gateway.enabled. |
app.auth.passkey.origin | "" | Allowed origins, comma-separated. Empty follows the request Origin. Required with ingress.enabled or gateway.enabled. |
app.auth.passkey.name | Dashboard App | Name shown in the browser's passkey prompt. |
app.auth.passkey.selfRegistration | "false" | "true" lets anyone who reaches the dashboard register a ReadOnly passkey account. Google sign-in is not affected. |
app.auth.oidc.existingSecret | "" | A Secret you manage (key googleJwkJson) for the pinned Google keys, for cluster-less renders. |
The Google client ID and the Google switch are runtime settings on
TelarkConfig, edited in Settings, not chart values.
| Key | Default | Notes |
|---|
ingress.enabled | false | Ingress to the dashboard. |
ingress.className, ingress.host, ingress.tls, ingress.annotations | "", "", [], {} | Controller class, hostname and TLS. |
gateway.enabled | false | Gateway API HTTPRoute instead of an Ingress. |
gateway.parentRefs, gateway.hostnames | [], [] | Gateway listeners to attach to, and hostnames. |
Without either, reach the dashboard with
kubectl port-forward -n telark svc/telark-ui-service 3000:8080.
| Key | Default | Notes |
|---|
app.kyverno.enabled | true | Installs the Kyverno subchart, which enforces protection plans. |
app.kyverno.failOpen | true | While Kyverno is down, admission lets requests through, enforce plans included. Must equal kyverno.features.forceFailurePolicyIgnore.enabled. |
kyverno.admissionController.replicas | 2 | With a disruption budget of minAvailable: 1. |
| Key | Default | Notes |
|---|
app.ollama.enabled | true | Installs Ollama, the local model runtime for Insights. |
app.ollama.autoPull | true | Lets the analyzer download a missing model; false for air-gapped installs (no runtime egress). |
app.ollama.runtimeUrl | "" | An Ollama-API endpoint you run. Empty uses the subchart. |
ollama.resources | requests 250m and 1536Mi, limit 2 CPU | One size for every mode. See Insights hardware profiles. |
ollama.persistentVolume.size | 10Gi | Model volume, kept on uninstall. 20Gi to try 8B models. |
services.analyzer.env.ANALYZER_MODE | fast | deep for the tool-calling mode. |
| Key | Default | Notes |
|---|
app.persistence.enabled | true | Provisions the exporter's snapshot and report volumes. |
app.persistence.size | 10Gi | Snapshot volume (minimal: 1Gi). |
app.persistence.reportsSize | 2Gi | Report volume (minimal: 512Mi, performance: 10Gi). |
redis.master.persistence.size | 4Gi | Redis volume. |
nats.persistence.size | 4Gi | NATS JetStream volume. |
| Key | Default | Notes |
|---|
app.crdGuard.enabled, app.crdGuard.enforce | true, true | Only Telark's own service accounts may write telark.io resources and the OIDC trust Secret. enforce: false only audits. |
app.crdGuard.extraAllowedUsers | [] | Break-glass usernames also allowed to write them. |
app.networkPolicy.enabled | true | Ingress NetworkPolicies for Telark pods and NATS. Needs a CNI that enforces them. |
app.serviceToken.value, app.serviceToken.existingSecret | "", "" | Shared service token. Empty generates one on install and reads it back on upgrade; set existingSecret for cluster-less renders. |
nats.existingSecrets.publisher, nats.existingSecrets.consumer | "", "" | Your own NATS user Secrets, for cluster-less renders. |
| Key | Default | Notes |
|---|
app.serviceDefaults.autoscaling.enabled | true | CPU autoscaling of every service except the exporter (minimal: off). |
app.serviceDefaults.autoscaling.minReplicas, maxReplicas | 1, 3 | performance: up to 5. |
app.serviceDefaults.autoscaling.targetCPUUtilizationPercentage | 80 | |
vpa.enabled | false | Installs the VPA operator and one VPA per service. |
metrics-server.enabled | true | Needed for usage-based Insights rules and autoscaling. |
monitoring.serviceMonitor.enabled | false | Prometheus-Operator ServiceMonitor for each service's /metrics. |
monitoring.serviceMonitor.labels | {} | Must match your Prometheus serviceMonitorSelector. |
Each service has a services.<svc> block (exporter, discovery,
analyzer, notifier, auth, ui) with enabled, replicas,
nodeSelector, tolerations, affinity and env. Tunables go in
services.<svc>.env; see Environment variables.
Resources come from the shared app.shared.resources block (requests
100m and 128Mi, limits 500m and 512Mi), resized by app.mode.
| Subchart | Version |
|---|
| Kyverno | 3.9.1 |
| Redis (Bitnami) | 23.0.10 |
| NATS (Bitnami) | 9.0.28 |
| Ollama | 1.50.0 |
| metrics-server | 3.12.2 |
| VPA (Fairwinds) | 5.1.0 |
The chart requires Kubernetes 1.30 or later.