Environment variables
The runtime settings each Telark service reads, with the values the chart sets.
The chart sets each service's environment from services.<svc>.env and,
for the templated ones, from app.* values. Override one with:
--set services.<svc>.env.<VARIABLE>=<value>The Chart column is what a standard install runs. minimal and
performance override a few; they are noted in the Notes column. When
the chart sets nothing, the service falls back to its built-in default.
Settings that change at runtime (excluded namespaces, snapshot
retention, the Insights switch and model, Google sign-in) live on the
TelarkConfig resource and are edited in Settings, not here. See
TelarkConfig.
Every service
| Variable | Chart | Notes |
|---|---|---|
TELARK_SERVICE_TOKEN | from telark-service-token-secret | Shared service token. A service refuses to start without it. |
REDIS_HOST, REDIS_PORT | <release>-redis-master, 6379 | Set by the chart. |
NATS_HOST | <release>-nats | discovery and notifier only. |
CORS_ALLOWED_ORIGINS | "" | Origins that get CORS headers, for local development. The dashboard proxies every API on its own origin, so production needs none. |
discovery-service
| Variable | Chart | Notes |
|---|---|---|
PROTECTION_PLAN_TICK_INTERVAL_SEC | 31 | Plan controller interval: window edges, health and drift repair. |
PROTECTION_PLAN_REPORT_CHECKPOINT_SEC | 900 | How often running plans checkpoint violations into their report ledger. Clamped to 60–1800. minimal: 1800. |
PROTECTION_PLAN_REPORT_MAX_VIOLATIONS | 5000 | Violations one report keeps; beyond that it is marked truncated. minimal: 2000. |
DISCOVERY_K8S_CLIENT_QPS, DISCOVERY_K8S_CLIENT_BURST | 100, 200 | Kubernetes client rate limits. minimal: 50, 100. performance: 300, 600. |
DISCOVERY_ROLLBACK_K8S_CLIENT_QPS, DISCOVERY_ROLLBACK_K8S_CLIENT_BURST | 100, 200 | The rollback controller's own client budget, also used by report checkpoints. |
DISCOVERY_ROLLBACK_WORKERS | not set (built-in 4) | Rollback workers on the leader. |
DISCOVERY_INFORMER_RESYNC_SEC | 600 | Informer resync interval. |
DISCOVERY_ROLLBACK_INFORMER_RESYNC_SEC | 600 | Resync interval of the rollback controller's informer. |
DISCOVERY_INFORMER_RESYNC_JITTER_FRACTION | 0.2 | Per-replica jitter on resyncs. |
DISCOVERY_INFORMER_COALESCING_WINDOW_SEC | 5 | How long events are buffered per application before one change is recorded. |
DISCOVERY_INFORMER_COALESCING_MAX_WAIT_SEC | 10 | Longest wait before a forced flush. |
COORDINATION_ELECTION_TTL_SEC, COORDINATION_ELECTION_RENEW_SEC | 15, 5 | Leader lease and renewal. |
COORDINATION_LOCK_TTL_SEC, COORDINATION_LOCK_HEARTBEAT_SEC | 120, 30 | Per-application lock and heartbeat. |
FORCE_SYNC_WORKERS | 6 | Force-sync workers on the leader. minimal: 2. performance: 12. |
DISCOVERY_AUTO_CLEANUP_ENABLED | "true" | Removes an application whose workloads are all gone. |
DISCOVERY_AUTO_CLEANUP_EMPTY_CYCLES_REQUIRED | 2 | Consecutive empty cycles before removal. |
DISCOVERY_AUTO_CLEANUP_CYCLE_INTERVAL_SEC | 60 | Cleanup cycle. performance: 120. |
INSIGHTS_INDEX_REFRESH_SEC | 15 | How often each replica picks up insight changes for the Insights page. |
INSIGHTS_INDEX_RESYNC_SEC | 300 | Full resync of the Insights page index. |
INSIGHTS_STALE_AFTER_SEC | 86400 | An active card not seen for this long shows as Stale. |
exporter-service
| Variable | Chart | Notes |
|---|---|---|
SNAPSHOTS_PATH | /snapshots | Mount path of the snapshot volume. |
REPORTS_PATH | /reports | Mount path of the report volume. |
SNAPSHOT_GC_INTERVAL_SEC | 3600 | Sweeps snapshot files no application references (older than an hour) and orphaned report directories. 0 turns it off. minimal: 7200. performance: 900. |
EXPORTER_K8S_CLIENT_QPS, EXPORTER_K8S_CLIENT_BURST | 50, 100 | Kubernetes client rate limits. minimal: 20, 40. performance: 200, 400. |
BOOTSTRAP_ADMINS | app.auth.bootstrap.admins | A session may not create or claim a user with one of these emails. |
OIDC_TRUST_SECRET_NAME | telark-oidc-trust-secret | Secret the exporter writes the pinned Google keys to; follows app.auth.oidc.existingSecret. |
auth-service
| Variable | Chart | Notes |
|---|---|---|
BOOTSTRAP_ADMINS | app.auth.bootstrap.admins | Emails that get the Admin role from a verified identity. |
SELF_REGISTRATION_ENABLED | app.auth.passkey.selfRegistration ("false") | Open passkey registration, ReadOnly role. Auth refuses to start when this is off and BOOTSTRAP_ADMINS is empty. |
RP_ID | app.auth.passkey.id ("") | WebAuthn relying-party ID. Empty follows the request host. |
RP_ORIGIN | app.auth.passkey.origin ("") | Allowed origins, comma-separated. Empty follows the request Origin. |
RP_NAME | app.auth.passkey.name (Dashboard App) | Name in the passkey prompt. |
CHALLENGE_TIMEOUT | 60 | Passkey challenge lifetime, seconds. |
SESSION_EXPIRY | 24 | Session lifetime, hours. |
OIDC_TRUST_FILE | /etc/telark/oidc/googleJwkJson | Pinned Google key set, mounted from the trust Secret and re-read on change. |
REDIS_DB | 1 | Redis database auth uses. |
CLEANUP_WORKERS_PER_TYPE | 2 | Deletion-cleanup workers per record type. minimal: 1. performance: 4. |
Behind an Ingress or Gateway, set RP_ID and RP_ORIGIN through
app.auth.passkey.id and app.auth.passkey.origin to the dashboard's
public domain.
notifier-service
| Variable | Chart | Notes |
|---|---|---|
NOTIFIER_APPLY_WORKERS | 8 | Apply workers; one application always maps to the same worker, so its updates stay ordered. minimal: 2. performance: 32. |
analyzer-service
| Variable | Chart | Notes |
|---|---|---|
OLLAMA_HOST | http://<release>-ollama:11434, or app.ollama.runtimeUrl | Model runtime endpoint. |
OLLAMA_AUTO_PULL | app.ollama.autoPull (true) | Pull a missing model. false for air-gapped installs. |
ANALYZER_MODE | fast | fast: rules, then one narration. deep: the model investigates with tools. Any other value stops the pod at start. |
ANALYZER_NUM_THREAD | 2 | CPU threads per model call. Equal to the runtime's CPU limit, never above the node's vCPUs. |
ANALYZER_NARRATE_TIMEOUT_SEC | 45 | Longest wait for the narration; on timeout cards keep the rule text. |
ANALYZER_CONTEXT_TOKENS | 4096 | Model context window. Deep mode wants 8192. |
ANALYZER_MAX_STEPS, ANALYZER_MAX_TOOL_CALLS | 8, 8 | Deep mode: loop steps and tool calls per run. |
ANALYZER_WALL_SEC | 480 | Deep mode: time budget of one run. |
ANALYZER_QUEUE_MAX | 100 | Queued jobs above which manual Analyze answers 429. |
ANALYZER_AUTO_COOLDOWN_SEC, ANALYZER_MANUAL_COOLDOWN_SEC | 600, 60 | Per-application cooldown of automatic and manual runs. |
ANALYZER_CONFIG_POLL_SEC | 30 | How often TelarkConfig and the runtime are re-checked. |
ANALYZER_REVIEW_INTERVAL_SEC | 7200 | Re-review an unchanged application after this long. 0 turns the sweep off; Analyze still reviews. |
ANALYZER_REVIEW_TICK_SEC | 120 | Sweep tick. |
ANALYZER_REVIEW_APPS_PER_MIN | 20 | Sweep pace. minimal: 10. performance: 60. |
ANALYZER_REVIEW_WORKLOADS_MAX | 10 | Workloads read per review, those with an incident first. |
ANALYZER_USAGE_MIN_SAMPLES, ANALYZER_USAGE_MIN_SPAN_SEC | 12, 43200 | Usage samples, and the time they must span, before usage rules fire. |
ANALYZER_CHANGE_VELOCITY_PER_DAY | 20 | Changes per day (seven-day average) that flag change_risk.high_velocity. |
ANALYZER_CHANGE_RISK_MIN_SPAN_SEC | 259200 | History an application needs before change-risk rules apply. |
ANALYZER_PRODUCTION_PATTERN | (^|[-_.])(prod|production|prd)($|[-_.]) | Case-insensitive. Matches namespaces and plan environments that count as production. An invalid pattern stops the pod at start. |