| 123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537 |
- ## Global image configuration
- global:
- ## Overrides the Docker registry globally for all images
- imageRegistry: ""
- ## Add additional image pull secrets globally
- ## Support both full format (- name: secret) and short format (- secret)
- ## These will be merged with any chart-specific pull secrets
- imagePullSecrets: []
- ## Workload type - Deployment or StatefulSet
- ## StatefulSet is useful for stable storage and network identity
- ## When using StatefulSet, PVCs are managed via volumeClaimTemplates
- workload:
- ## Kind can be either "Deployment" or "StatefulSet"
- kind: Deployment
- ## Number of pgAdmin4 replicas
- replicaCount: 1
- ## pgAdmin4 container image
- image:
- registry: docker.io
- repository: dpage/pgadmin4
- ## Overrides the image tag whose default is the chart appVersion
- tag: ""
- pullPolicy: IfNotPresent
- ## Optionally specify an array of imagePullSecrets
- ## Secrets must be manually created in the namespace
- ## Ref: https://kubernetes.io/docs/tasks/configure-pod-container/pull-image-private-registry/
- imagePullSecrets: []
- # - RegistryKeySecret
- ## Deployment annotations
- annotations: {}
- ## The number of old history to retain to allow rollback
- revisionHistoryLimit: 10
- ## Add labels to all the deployed resources
- commonLabels: {}
- ## Priority class name for pod scheduling
- priorityClassName: ""
- ## Deployment entrypoint override
- ## Useful when there's a requirement to modify container's default
- ## Ref: https://www.vaultproject.io/docs/platform/k8s/injector/examples#environment-variable-example
- ## Ref: https://github.com/postgres/pgadmin4/blob/master/Dockerfile#L206
- # command: "['/bin/sh', '-c', 'source /vault/secrets/config && <entrypoint script>']"
- ## Service configuration
- service:
- type: ClusterIP
- clusterIP: ""
- loadBalancerIP: ""
- port: 80
- targetPort: 80
- # targetPort: 4181 # To be used with a proxy extraContainer
- portName: http
- ## Special annotations at the service level, e.g.
- ## this will set vnet internal IPs rather than public IPs
- ## service.beta.kubernetes.io/azure-load-balancer-internal: "true"
- annotations: {}
- ## Specify the nodePort value for the service types
- ## Ref: https://kubernetes.io/docs/concepts/services-networking/service/#type-nodeport
- # nodePort:
- ## Pod Service Account
- ## Ref: https://kubernetes.io/docs/tasks/configure-pod-container/configure-service-account/
- serviceAccount:
- ## Specifies whether a service account should be created
- create: false
- ## Annotations to add to the service account
- annotations: {}
- ## The name of the service account to use
- ## If not set and create is true, a name is generated using the fullname template
- name: ""
- ## Opt out of API credential automounting
- ## If you don't want the kubelet to automatically mount a ServiceAccount's API credentials,
- ## you can opt out of the default behavior
- automountServiceAccountToken: false
- ## Pod HostAliases
- ## Ref: https://kubernetes.io/docs/tasks/network/customize-hosts-file-for-pods/
- hostAliases: []
- # - ip: "127.0.0.1"
- # hostnames:
- # - "pgadmin4.local"
- ## Strategy used to replace old Pods by new ones
- ## Ref: https://kubernetes.io/docs/concepts/workloads/controllers/deployment/#strategy
- strategy: {}
- # type: RollingUpdate
- # rollingUpdate:
- # maxSurge: 0
- # maxUnavailable: 1
- ## Pre-load pgAdmin4 with servers at first start-up
- ## Servers are imported only the first time the config DB is created
- ## Ref: https://www.pgadmin.org/docs/pgadmin4/latest/import_export_servers.html
- serverDefinitions:
- ## Enable/disable server import
- enabled: false
- ## Storage for the server JSON:
- ## ConfigMap - plain text (good for non-secret data)
- ## Secret - base-64 (better for credentials)
- resourceType: ConfigMap
- ## Use this only when `resourceType` = ConfigMap - point to an existing ConfigMap
- ## that already holds your `servers.json`
- existingConfigmap: ""
- ## Use this only when `resourceType` = Secret - point to an existing Secret
- ## that already holds your `servers.json`
- existingSecret: ""
- ## Set to true to put raw JSON under `stringData` (handy for dry-runs/debug)
- ## Leave false to keep the default base-64 in `data`
- useStringData: false
- ## Inline server definitions (ignore if you point to an existing resource)
- ## You can use Helm templates here, e.g. Host: "{{ .Values.example.host }}"
- servers:
- # firstServer:
- # Name: "Minimally Defined Server"
- # Group: "Servers"
- # Username: "postgres"
- # Host: "{{ .Values.example.host }}"
- # Port: "{{ .Values.example.port }}"
- # SSLMode: "prefer"
- # MaintenanceDB: "postgres"
- ## Pre-load pgAdmin4 with user preferences
- ## This mounts a preferences.json file to override default UI settings such as themes,
- ## display options, or query tool behavior
- ## Ref: https://www.pgadmin.org/docs/pgadmin4/latest/preferences.html
- preferences:
- ## Enable/disable preferences
- enabled: false
- ## If using an existing ConfigMap, it must contain a key named `preferences.json`
- existingConfigMap: ""
- data: {}
- # misc:user_interface:theme: dark
- ## Network policy configuration
- networkPolicy:
- enabled: true
- ## HTTP route configuration
- httpRoute:
- enabled: false
- annotations: {}
- hostnames: []
- parentRefs: {}
- matches: []
- ## Ingress configuration
- ## Ref: https://kubernetes.io/docs/concepts/services-networking/ingress/
- ingress:
- enabled: false
- ## For Kubernetes >= 1.18 you should specify the ingress-controller via the field ingressClassName
- ## Ref: https://kubernetes.io/blog/2020/04/02/improvements-to-the-ingress-api-in-kubernetes-1.18/#specifying-the-class-of-an-ingress
- # ingressClassName: nginx
- annotations: {}
- # kubernetes.io/ingress.class: nginx
- # kubernetes.io/tls-acme: "true"
- labels: {}
- hosts:
- - host: chart-example.local
- paths:
- - path: /
- pathType: Prefix
- tls: []
- # - secretName: chart-example-tls
- # hosts:
- # - chart-example.local
- ## Istio ingress configuration
- ## Use Istio Gateway and VirtualService instead of Ingress
- istioIngress:
- enabled: false
- ## The label selector for your existing Istio Ingress Gateway pods
- ## This tells the Gateway resource which gateway deployment to attach to
- ## Example: "ingressgateway" is a common default label
- selector: ""
- ## A list of hostnames this Gateway will manage
- endpoints:
- - "test.example.com"
- ## TLS configuration for Istio Gateway
- tls:
- enabled: false
- ## The name of the K8s Secret containing the cert
- ## Istio's Gateway resource will reference this name in its credentialName field
- ## Should be in istio-ingress namespace where istio ingress gateway is installed
- secretCertName: "my-istio-tls-secret"
- ## Defines the ports on the Istio Ingress Gateway
- gateway:
- enabled: false
- ports:
- http:
- number: 80
- protocol: HTTP
- ## If true, the template generates a rule to redirect HTTP->HTTPS
- isTlsRedirect: true
- isTlsTermination: false
- https:
- number: 443
- protocol: HTTPS
- isTlsRedirect: false
- ## If true, the gateway terminates TLS (handles HTTPS)
- isTlsTermination: true
- ## SIMPLE: Standard TLS, MUTUAL: mTLS, PASSTHROUGH: Send TLS to pod
- tlsMode: SIMPLE
- ## Istio VirtualService configuration
- ## The VirtualService defines how traffic is routed after it enters the Gateway
- virtualService:
- enabled: false
- gateway: ""
- config:
- ## http is a list of ordered routing rules. First match wins
- http:
- - name: "pgadmin-route"
- match:
- - uri:
- prefix: "/"
- route:
- - destination:
- host: "pgadmin"
- portNumber: 80
- weight: 100
- rewrite:
- uri: "/"
- corsPolicy:
- allowOrigins:
- - exact: "*"
- allowHeaders:
- - "*"
- allowMethods:
- - "*"
- exposeHeaders:
- - "*"
- maxAge: "24h"
- ## Additional config maps to be mounted inside a container
- ## Can be used to map config maps for sidecar as well
- extraConfigmapMounts: []
- # - name: certs-configmap
- # mountPath: /etc/ssl/certs
- # subPath: ""
- # configMap: certs-configmap
- # readOnly: true
- ## Additional secret mounts to be mounted inside a container
- extraSecretMounts: []
- # - name: pgpassfile
- # secret: pgpassfile
- # subPath: pgpassfile
- # mountPath: "/var/lib/pgadmin/storage/pgadmin/file.pgpass"
- # readOnly: true
- ## Additional volumes to be mounted inside a container
- extraVolumeMounts: []
- ## Specify additional containers in extraContainers
- ## For example, to add an authentication proxy to a pgadmin4 pod
- extraContainers: |
- # - name: proxy
- # image: quay.io/gambol99/keycloak-proxy:latest
- # args:
- # - -provider=github
- # - -client-id=
- # - -client-secret=
- # - -github-org=<ORG_NAME>
- # - -email-domain=*
- # - -cookie-secret=
- # - -http-address=http://0.0.0.0:4181
- # - -upstream-url=http://127.0.0.1:3000
- # ports:
- # - name: proxy-web
- # containerPort: 4181
- ## Name of existing secret to use for default pgadmin credentials
- ## env.password will be ignored and picked up from this secret
- existingSecret: ""
- ## Name of key in existing secret to use for default pgadmin credentials
- ## Only used when existingSecret is set
- secretKeys:
- pgadminPasswordKey: password
- ## pgAdmin4 startup configuration
- ## Values in here get injected as environment variables
- ## Chart reinstall needed to apply changes
- env:
- ## Can be email or nickname
- email: creylopez@yahoo.es
- password: Rey-1176
- # pgpassfile: /var/lib/pgadmin/storage/pgadmin/file.pgpass
- ## Set context path for application (e.g. /pgadmin4/*)
- # contextPath: /pgadmin4
- ## If True, allows pgAdmin4 to create session cookies based on IP address
- ## Ref: https://www.pgadmin.org/docs/pgadmin4/latest/config_py.html
- enhanced_cookie_protection: "False"
- ## Add custom environment variables that will be injected to deployment
- ## Ref: https://www.pgadmin.org/docs/pgadmin4/latest/container_deployment.html
- variables: []
- # - name: PGADMIN_LISTEN_ADDRESS
- # value: "0.0.0.0"
- # - name: PGADMIN_LISTEN_PORT
- # value: "8080"
- ## Additional environment variables from ConfigMaps
- envVarsFromConfigMaps: []
- # - array-of
- # - config-map-names
- ## Additional environment variables from Secrets
- envVarsFromSecrets: []
- # - array-of
- # - secret-names
- ## Additional environment variables
- envVarsExtra: []
- # - name: POSTGRES_USERNAME
- # valueFrom:
- # secretKeyRef:
- # name: pgadmin.pgadmin-db.credentials.postgresql.acid.zalan.do
- # key: username
- # - name: POSTGRES_PASSWORD
- # valueFrom:
- # secretKeyRef:
- # name: pgadmin.pgadmin-db.credentials.postgresql.acid.zalan.do
- # key: password
- ## Persistent volume configuration
- persistentVolume:
- ## If true, pgAdmin4 will create/use a Persistent Volume Claim
- ## If false, use emptyDir
- enabled: true
- ## pgAdmin4 Persistent Volume Claim annotations
- annotations: {}
- ## pgAdmin4 Persistent Volume access modes
- ## Must match those of existing PV or dynamic provisioner
- ## Ref: http://kubernetes.io/docs/user-guide/persistent-volumes/
- accessModes:
- - ReadWriteOnce
- ## pgAdmin4 Persistent Volume Size
- size: 1Gi
- ## pgAdmin4 Persistent Volume Storage Class
- ## If defined, storageClassName: <storageClass>
- ## If set to "-", storageClassName: "", which disables dynamic provisioning
- ## If undefined (the default) or set to null, no storageClassName spec is
- ## set, choosing the default provisioner (gp2 on AWS, standard on GKE, AWS & OpenStack)
- # storageClass: "-"
- # existingClaim: ""
- ## Subdirectory of pgAdmin4 Persistent Volume to mount
- ## Useful if the volume's root directory is not empty
- subPath: ""
- ## Additional volumes to be added to the deployment
- extraVolumes: []
- ## Security context to be added to pgAdmin4 pods
- securityContext:
- runAsUser: 5050
- runAsGroup: 5050
- fsGroup: 5050
- ## Container security context
- containerSecurityContext:
- enabled: false
- allowPrivilegeEscalation: false
- ## pgAdmin4 health check probe configuration
- ## Ref: https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-startup-probes/
- livenessProbe:
- periodSeconds: 20
- timeoutSeconds: 5
- failureThreshold: 3
- readinessProbe:
- periodSeconds: 10
- timeoutSeconds: 3
- failureThreshold: 3
- startupProbe:
- failureThreshold: 18
- periodSeconds: 10
- ## Required to be enabled pre pgAdmin4 4.16 release, to set the ACL on /var/lib/pgadmin
- ## Ref: https://kubernetes.io/docs/concepts/workloads/pods/init-containers/
- VolumePermissions:
- ## If true, enables an InitContainer to set permissions on /var/lib/pgadmin
- enabled: false
- ## List of extra manifests to deploy
- extraDeploy: []
- ## Additional InitContainers to initialize the pod
- extraInitContainers: |
- # - name: add-folder-for-pgpass
- # image: "dpage/pgadmin4:latest"
- # command: ["/bin/mkdir", "-p", "/var/lib/pgadmin/storage/pgadmin"]
- # volumeMounts:
- # - name: pgadmin-data
- # mountPath: /var/lib/pgadmin
- # securityContext:
- # runAsUser: 5050
- ## Container port configuration
- containerPorts:
- http: 80
- ## Resource limits and requests
- ## We usually recommend not to specify default resources and to leave this as a conscious
- ## choice for the user. This also increases chances charts run on environments with little
- ## resources, such as Minikube. If you do want to specify resources, uncomment the following
- ## lines, adjust them as necessary, and remove the curly braces after 'resources:'
- ## You might also want to increase failure threshold value in startup probe configuration to
- ## allow the container to start successfully on CPU limited environments
- resources: {}
- # limits:
- # cpu: 100m
- # memory: 128Mi
- # requests:
- # cpu: 100m
- # memory: 128Mi
- ## Horizontal Pod Autoscaling
- ## Ref: https://kubernetes.io/docs/tasks/run-application/horizontal-pod-autoscale/
- autoscaling:
- enabled: false
- minReplicas: 1
- maxReplicas: 100
- targetCPUUtilizationPercentage: 80
- # targetMemoryUtilizationPercentage: 80
- ## Node labels for pgAdmin4 pod assignment
- ## Ref: https://kubernetes.io/docs/user-guide/node-selection/
- nodeSelector: {}
- ## Node tolerations for server scheduling to nodes with taints
- ## Ref: https://kubernetes.io/docs/concepts/configuration/assign-pod-node/
- tolerations: []
- ## Pod affinity
- affinity: {}
- ## Topology Spread Constraints to control how Pods are spread across your cluster
- ## Ref: https://kubernetes.io/docs/concepts/scheduling-eviction/topology-spread-constraints/
- topologySpreadConstraints: []
- ## Pod DNS Policy
- ## Ref: https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-s-dns-policy
- dnsPolicy: ""
- ## Update pod DNS Config
- ## Ref: https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/#pod-dns-config
- dnsConfig: {}
- # nameservers:
- # - 192.0.2.1
- # searches:
- # - ns1.svc.cluster-domain.example
- # - my.dns.search.suffix
- # options:
- # - name: ndots
- # value: "2"
- # - name: edns0
- ## Pod annotations
- podAnnotations: {}
- ## Templated pod annotations
- templatedPodAnnotations: |-
- # checksum/configmap-oauth2: {{ include "<parent-chart-name>/templates/configmap-oauth2.yaml" $ | sha256sum }}
- # checksum/secret-oauth2: "{{ include "<parent-chart-name>/templates/secret-oauth2.yaml" $ | sha256sum }}"
- # checksum/secret-pgpass: "{{ include "<parent-chart-name>/templates/secret-pgpass.yaml" $ | sha256sum }}"
- ## Pod labels
- podLabels: {}
- # key1: value1
- # key2: value2
- ## The name of the Namespace to deploy
- ## If not set, .Release.Namespace is used
- namespace: null
- ## Init container configuration
- init:
- ## Init container resources
- resources: {}
- ## Chart test configuration
- test:
- enabled: true
- ## Container image for test-connection.yaml
- image:
- registry: docker.io
- repository: busybox
- tag: latest
- ## Resources request/limit for test-connection Pod
- resources: {}
- # limits:
- # cpu: 50m
- # memory: 32Mi
- # requests:
- # cpu: 25m
- # memory: 16Mi
- ## Security context for test-connection Pod
- securityContext:
- runAsUser: 5051
- runAsGroup: 5051
- fsGroup: 5051
- ## Container Security context for test-connection Pod
- containerSecurityContext:
- readOnlyRootFilesystem: true
|