Reference

Helm values

The chart values most installs touch, grouped by purpose, with their defaults.

This page condenses the values of the telark chart (oci://ghcr.io/telark/charts/telark). The complete list, generated from the chart and checked in CI, is charts/telark/VALUES.md; the explained reference is the chart README.

Set values with --set key=value or -f values.yaml. Helm does not remember --set flags across upgrades: pass them again on every helm upgrade, or keep them in a values file.

Required at install

KeyDefaultNotes
app.auth.bootstrap.admins[]Admin emails. The render fails while it is empty and self-registration is off.
app.persistence.storageClass""A ReadWriteMany class for the two exporter replicas of standard and performance. The render fails on "" unless app.singleNode=true. "-" disables provisioning.

Install shape

KeyDefaultNotes
app.nametelarkPrefix of every resource name. The API group stays telark.io.
app.namespacetelarkMust match the release namespace (-n).
app.modestandardminimal, standard or performance: replicas, resources, rate limits and disruption budgets of every Telark service. Subcharts keep their own sizing.
app.singleNodefalseOne exporter replica on ReadWriteOnce, so no RWX class is needed.
crds.enabledtrueInstalls the telark-crds subchart. Set false to manage CRDs out of band.
app.image.registryghcr.io/telarkRegistry hosting the service images.
app.image.pullPolicyAlwaysPull policy of every service container.
app.image.pullSecrets, global.imagePullSecrets[]Only for a private registry or mirror.

Sign-in

KeyDefaultNotes
app.auth.passkey.id""WebAuthn relying-party ID. Empty follows the request host. Required with ingress.enabled or gateway.enabled.
app.auth.passkey.origin""Allowed origins, comma-separated. Empty follows the request Origin. Required with ingress.enabled or gateway.enabled.
app.auth.passkey.nameDashboard AppName shown in the browser's passkey prompt.
app.auth.passkey.selfRegistration"false""true" lets anyone who reaches the dashboard register a ReadOnly passkey account. Google sign-in is not affected.
app.auth.oidc.existingSecret""A Secret you manage (key googleJwkJson) for the pinned Google keys, for cluster-less renders.

The Google client ID and the Google switch are runtime settings on TelarkConfig, edited in Settings, not chart values.

Dashboard access

KeyDefaultNotes
ingress.enabledfalseIngress to the dashboard.
ingress.className, ingress.host, ingress.tls, ingress.annotations"", "", [], {}Controller class, hostname and TLS.
gateway.enabledfalseGateway API HTTPRoute instead of an Ingress.
gateway.parentRefs, gateway.hostnames[], []Gateway listeners to attach to, and hostnames.

Without either, reach the dashboard with kubectl port-forward -n telark svc/telark-ui-service 3000:8080.

Policy engine

KeyDefaultNotes
app.kyverno.enabledtrueInstalls the Kyverno subchart, which enforces protection plans.
app.kyverno.failOpentrueWhile Kyverno is down, admission lets requests through, enforce plans included. Must equal kyverno.features.forceFailurePolicyIgnore.enabled.
kyverno.admissionController.replicas2With a disruption budget of minAvailable: 1.

Insights runtime

KeyDefaultNotes
app.ollama.enabledtrueInstalls Ollama, the local model runtime for Insights.
app.ollama.autoPulltrueLets the analyzer download a missing model; false for air-gapped installs (no runtime egress).
app.ollama.runtimeUrl""An Ollama-API endpoint you run. Empty uses the subchart.
ollama.resourcesrequests 250m and 1536Mi, limit 2 CPUOne size for every mode. See Insights hardware profiles.
ollama.persistentVolume.size10GiModel volume, kept on uninstall. 20Gi to try 8B models.
services.analyzer.env.ANALYZER_MODEfastdeep for the tool-calling mode.

Storage

KeyDefaultNotes
app.persistence.enabledtrueProvisions the exporter's snapshot and report volumes.
app.persistence.size10GiSnapshot volume (minimal: 1Gi).
app.persistence.reportsSize2GiReport volume (minimal: 512Mi, performance: 10Gi).
redis.master.persistence.size4GiRedis volume.
nats.persistence.size4GiNATS JetStream volume.

Security

KeyDefaultNotes
app.crdGuard.enabled, app.crdGuard.enforcetrue, trueOnly Telark's own service accounts may write telark.io resources and the OIDC trust Secret. enforce: false only audits.
app.crdGuard.extraAllowedUsers[]Break-glass usernames also allowed to write them.
app.networkPolicy.enabledtrueIngress NetworkPolicies for Telark pods and NATS. Needs a CNI that enforces them.
app.serviceToken.value, app.serviceToken.existingSecret"", ""Shared service token. Empty generates one on install and reads it back on upgrade; set existingSecret for cluster-less renders.
nats.existingSecrets.publisher, nats.existingSecrets.consumer"", ""Your own NATS user Secrets, for cluster-less renders.

Scaling and monitoring

KeyDefaultNotes
app.serviceDefaults.autoscaling.enabledtrueCPU autoscaling of every service except the exporter (minimal: off).
app.serviceDefaults.autoscaling.minReplicas, maxReplicas1, 3performance: up to 5.
app.serviceDefaults.autoscaling.targetCPUUtilizationPercentage80
vpa.enabledfalseInstalls the VPA operator and one VPA per service.
metrics-server.enabledtrueNeeded for usage-based Insights rules and autoscaling.
monitoring.serviceMonitor.enabledfalsePrometheus-Operator ServiceMonitor for each service's /metrics.
monitoring.serviceMonitor.labels{}Must match your Prometheus serviceMonitorSelector.

Per-service settings

Each service has a services.<svc> block (exporter, discovery, analyzer, notifier, auth, ui) with enabled, replicas, nodeSelector, tolerations, affinity and env. Tunables go in services.<svc>.env; see Environment variables. Resources come from the shared app.shared.resources block (requests 100m and 128Mi, limits 500m and 512Mi), resized by app.mode.

Subchart versions

SubchartVersion
Kyverno3.9.1
Redis (Bitnami)23.0.10
NATS (Bitnami)9.0.28
Ollama1.50.0
metrics-server3.12.2
VPA (Fairwinds)5.1.0

The chart requires Kubernetes 1.30 or later.