Helm chart values
Generated from values.yaml and values.schema.json at build time. The chart is validated against the schema on install, so a value outside these constraints fails helm install.
| Chart | celld-operator 0.1.0-dev |
| App version | dev |
| Kubernetes | >=1.31.0-0 |
| Description | Kubernetes lifecycle operator for celld on EKS, S3 and EBS |
Install CRDs explicitly before the first install and on every upgrade; Helm never upgrades or deletes them. Read the operations contract before changing networkPolicyEnforced, memberReplacementDelay, launcherImage.
Values
Section titled “Values”| Key | Default | Required | Description |
|---|---|---|---|
replicaCount |
2 |
yes | Install CRDs on first install. Helm does not upgrade or delete CRDs; see docs/operations.md. Range 1–10. |
image.repository |
"ghcr.io/ewhauser/celld-operator" |
yes | Length 1–∞. |
image.tag |
"" |
yes | |
image.digest |
"" |
yes | Pattern ^$|^sha256:[a-f0-9]{64}$. |
image.pullPolicy |
"IfNotPresent" |
yes | One of Always, IfNotPresent, Never. |
imagePullSecrets |
[] |
||
launcherImage |
"" |
Deprecated and ignored: fleets run celld directly. Kept so existing values still install. Pattern ^$|^[^\s]+@sha256:[a-f0-9]{64}$. |
|
networkPolicyEnforced |
false |
yes | |
memberReplacementDelay |
"10m" |
How long one PersistentFleet member may stay down, while every other member is ready, before the operator replaces it on a fresh disk. At least 1m. Pattern ^([0-9]+(h|m|s))+$. |
|
fleetNamespaces |
[] |
Namespaces that will hold CelldFleet resources. The chart renders the namespaced Role and RoleBinding from config/rbac/fleet-namespace.yaml into each; the cluster role alone cannot reconcile a fleet. | |
serviceAccount.annotations |
{} |
||
podAnnotations |
{} |
Annotations on the operator Pod template, for example Datadog autodiscovery checks against the metrics port. Values must be strings. | |
podLabels |
{} |
Labels on the operator Pod template. Fleets with spec.mesh.istio need the operator in the mesh to read member state under STRICT mTLS, for example sidecar.istio.io/inject: “true”. Values must be strings. | |
resources.requests.cpu |
"100m" |
||
resources.requests.memory |
"128Mi" |
||
resources.limits.memory |
"256Mi" |
||
nodeSelector |
{} |
||
tolerations |
[] |
||
affinity |
{} |
Spread operator replicas where worker capacity permits. | |
metrics.enabled |
false |
yes | |
metrics.port |
8084 |
yes | Range 1024–65535. |
metrics.serviceMonitor.enabled |
false |
||
metrics.serviceMonitor.labels |
{} |
||
metrics.serviceMonitor.interval |
"30s" |
||
metrics.prometheusRule.enabled |
false |
||
metrics.prometheusRule.labels |
{} |
Rendered resources
Section titled “Rendered resources”| Template | Purpose |
|---|---|
deployment.yaml |
Two-replica controller Deployment with leader election, health probes and the opt-in flags rendered from values. |
metrics.yaml |
Optional metrics Service, ServiceMonitor and PrometheusRule (metrics.*). |
pdb.yaml |
PodDisruptionBudget keeping one controller replica available. |
rbac-fleet-namespaces.yaml |
The namespaced fleet Role and RoleBinding rendered into every entry of fleetNamespaces. |
rbac.yaml |
ClusterRole limited to the fleet API and StorageClass reads, plus the leader-election Role. |
serviceaccount.yaml |
Controller ServiceAccount for Kubernetes access; it needs no AWS IAM role. |
Experimental software for evaluation.Capabilities and limitations· Contribute