Skip to content

Helm values

Every value of the keeper chart, with its default. Nothing is specific to any organization: set endpoints, hostnames and credentials for your deployment.

charts/keeper/values.yaml
# Keeper Helm values. Nothing here is specific to any organization: set every endpoint, hostname and
# credential for your deployment (see docs and examples/).

image:
  # Required, for example registry.example.com/keeper/keeper
  repository: ""
  tag: ""
  pullPolicy: IfNotPresent
  # Names of existing image pull secrets in the release namespace. They are also copied into sandbox namespaces.
  pullSecrets: []

# Install / upgrade the CRDs with the release.
installCRDs: true

# Optional cluster name used in metrics and audit records.
clusterName: ""

logLevel: info

controller:
  replicas: 2
  resources:
    requests: { cpu: 50m, memory: 128Mi }
    limits: { memory: 512Mi }
  extraEnv: []
  # Garbage collection interval per store and orphan horizon.
  gcInterval: 24h
  orphanAge: 24h
  resyncInterval: 1m

api:
  replicas: 2
  resources:
    requests: { cpu: 50m, memory: 128Mi }
    limits: { memory: 1Gi }
  extraEnv: []
  service:
    type: ClusterIP
    port: 80
    nodePort: null
  # External URL of the console (used in links and the CLI), for example https://keeper.example.com
  externalURL: ""

# Console authentication.
auth:
  # none: no authentication (only for local development; every request is anonymous with role "viewer" unless
  #       auth.devRole is set). cloudflare-access: verify the Cf-Access-Jwt-Assertion JWT.
  provider: none
  devRole: ""
  cloudflareAccess:
    # Access team domain, for example myteam.cloudflareaccess.com
    teamDomain: ""
    # Application audience (AUD) tag.
    audience: ""
    # Override the JWKS URL (default https://<teamDomain>/cdn-cgi/access/certs).
    jwksURL: ""
    # Load the JWKS from a ConfigMap key "jwks.json" in the release namespace instead (air-gapped tests).
    jwksConfigMap: ""
  # Role mapping. Each role lists emails and/or Access groups. Roles: viewer, operator, restorer, restorer-admin.
  roles:
    viewer: []
    operator: []
    restorer: []
    restorer-admin: []
  # Optional scoping of roles by org/project label: { "alice@example.com": { orgs: [acme], projects: [] } }
  scopes: {}

# Sandbox exposure for external clients.
expose:
  # none: sandboxes are reachable in-cluster only. cloudflare: tunnel TCP routes + Access applications.
  provider: none
  cloudflare:
    accountID: ""
    zoneID: ""
    # Zone name, for example example.com
    zone: ""
    tunnelID: ""
    # Hostname pattern for sandbox routes; {id} is replaced by the sandbox id.
    hostnamePattern: "sbx-{id}.db.example.com"
    # Secret with key "token": Cloudflare API token (Tunnel edit, DNS edit, Access apps edit).
    apiTokenSecret: ""
    # Access policy for sandbox routes: emails and groups allowed.
    allowEmails: []
    allowGroups: []
    # Override the Cloudflare API base URL (tests, proxies). Default https://api.cloudflare.com/client/v4.
    apiURL: ""
  # cloudflared connector Deployment (console + sandbox routes). Needs a tunnel token secret (key "token").
  cloudflared:
    enabled: false
    image: cloudflare/cloudflared:2025.9.1
    replicas: 2
    tunnelTokenSecret: ""
    # Public hostname of the console route, for example keeper.example.com (configured in the tunnel).
    consoleHostname: ""

sandbox:
  defaultTTL: 24h
  maxTTL: 168h

# Namespaces that contain BackupTargets. Keeper gets a Role there to read its target credential secrets.
targetNamespaces: []
# Only secrets whose names start with this prefix may be referenced by targets ("" disables the check).
secretPrefix: "keeper-"

metrics:
  serviceMonitor:
    enabled: false
    interval: 30s
    labels: {}
  prometheusRule:
    enabled: false
    labels: {}
    # Hours without a successful full backup before BackupOverdue fires, per env label.
    overdueHours: { prod: 26, default: 50 }
  grafanaDashboard:
    enabled: false
    # Label the Grafana sidecar watches.
    labels: { grafana_dashboard: "1" }

# Example shared policies (prod, dev, critical) in the release namespace. They need a BackupStore name.
examplePolicies:
  enabled: false
  store: ""
  timeZone: UTC
  # Compression of backup data. Empty: zstd at level default (on). Example: { level: better }, or
  # { algorithm: none } for data that is already compressed (ADR 0013).
  compression: {}

podSecurityContext:
  runAsNonRoot: true
  runAsUser: 65532
  seccompProfile: { type: RuntimeDefault }
securityContext:
  allowPrivilegeEscalation: false
  readOnlyRootFilesystem: true
  capabilities: { drop: [ALL] }

nodeSelector: {}
tolerations: []
affinity: {}