Helm values¶
Every value of the keeper chart, with its default. Nothing is specific to any organization: set endpoints,
hostnames and credentials for your deployment.
charts/keeper/values.yaml
# Keeper Helm values. Nothing here is specific to any organization: set every endpoint, hostname and
# credential for your deployment (see docs and examples/).
image:
# Required, for example registry.example.com/keeper/keeper
repository: ""
tag: ""
pullPolicy: IfNotPresent
# Names of existing image pull secrets in the release namespace. They are also copied into sandbox namespaces.
pullSecrets: []
# Install / upgrade the CRDs with the release.
installCRDs: true
# Optional cluster name used in metrics and audit records.
clusterName: ""
logLevel: info
controller:
replicas: 2
resources:
requests: { cpu: 50m, memory: 128Mi }
limits: { memory: 512Mi }
extraEnv: []
# Garbage collection interval per store and orphan horizon.
gcInterval: 24h
orphanAge: 24h
resyncInterval: 1m
api:
replicas: 2
resources:
requests: { cpu: 50m, memory: 128Mi }
limits: { memory: 1Gi }
extraEnv: []
service:
type: ClusterIP
port: 80
nodePort: null
# External URL of the console (used in links and the CLI), for example https://keeper.example.com
externalURL: ""
# Console authentication.
auth:
# none: no authentication (only for local development; every request is anonymous with role "viewer" unless
# auth.devRole is set). cloudflare-access: verify the Cf-Access-Jwt-Assertion JWT.
provider: none
devRole: ""
cloudflareAccess:
# Access team domain, for example myteam.cloudflareaccess.com
teamDomain: ""
# Application audience (AUD) tag.
audience: ""
# Override the JWKS URL (default https://<teamDomain>/cdn-cgi/access/certs).
jwksURL: ""
# Load the JWKS from a ConfigMap key "jwks.json" in the release namespace instead (air-gapped tests).
jwksConfigMap: ""
# Role mapping. Each role lists emails and/or Access groups. Roles: viewer, operator, restorer, restorer-admin.
roles:
viewer: []
operator: []
restorer: []
restorer-admin: []
# Optional scoping of roles by org/project label: { "alice@example.com": { orgs: [acme], projects: [] } }
scopes: {}
# Sandbox exposure for external clients.
expose:
# none: sandboxes are reachable in-cluster only. cloudflare: tunnel TCP routes + Access applications.
provider: none
cloudflare:
accountID: ""
zoneID: ""
# Zone name, for example example.com
zone: ""
tunnelID: ""
# Hostname pattern for sandbox routes; {id} is replaced by the sandbox id.
hostnamePattern: "sbx-{id}.db.example.com"
# Secret with key "token": Cloudflare API token (Tunnel edit, DNS edit, Access apps edit).
apiTokenSecret: ""
# Access policy for sandbox routes: emails and groups allowed.
allowEmails: []
allowGroups: []
# Override the Cloudflare API base URL (tests, proxies). Default https://api.cloudflare.com/client/v4.
apiURL: ""
# cloudflared connector Deployment (console + sandbox routes). Needs a tunnel token secret (key "token").
cloudflared:
enabled: false
image: cloudflare/cloudflared:2025.9.1
replicas: 2
tunnelTokenSecret: ""
# Public hostname of the console route, for example keeper.example.com (configured in the tunnel).
consoleHostname: ""
sandbox:
defaultTTL: 24h
maxTTL: 168h
# Namespaces that contain BackupTargets. Keeper gets a Role there to read its target credential secrets.
targetNamespaces: []
# Only secrets whose names start with this prefix may be referenced by targets ("" disables the check).
secretPrefix: "keeper-"
metrics:
serviceMonitor:
enabled: false
interval: 30s
labels: {}
prometheusRule:
enabled: false
labels: {}
# Hours without a successful full backup before BackupOverdue fires, per env label.
overdueHours: { prod: 26, default: 50 }
grafanaDashboard:
enabled: false
# Label the Grafana sidecar watches.
labels: { grafana_dashboard: "1" }
# Example shared policies (prod, dev, critical) in the release namespace. They need a BackupStore name.
examplePolicies:
enabled: false
store: ""
timeZone: UTC
# Compression of backup data. Empty: zstd at level default (on). Example: { level: better }, or
# { algorithm: none } for data that is already compressed (ADR 0013).
compression: {}
podSecurityContext:
runAsNonRoot: true
runAsUser: 65532
seccompProfile: { type: RuntimeDefault }
securityContext:
allowPrivilegeEscalation: false
readOnlyRootFilesystem: true
capabilities: { drop: [ALL] }
nodeSelector: {}
tolerations: []
affinity: {}