Helm Chart Values Reference
Warning
This feature is currently in beta. It may change in a future version without prior notice. See the Beta Features page for the full list of beta features and their planned release. If you’re using this feature, we encourage you to share your feedback to help with the evaluation process.
This document provides a detailed description of the configurable options available in the Helm chart values file for deploying OnSphere. These values allow you to define global settings and fine-tune the behavior of individual modules.
Helm beginners may follow Getting Started section before going further.
Global Configuration
Those settings are generally used for shared configuration between modules.
Field |
Description |
|---|---|
registry |
Docker image registry used to pull container images. |
generateCertificate |
Enable automatic TLS certificate generation for modules. Requires a ServiceAccount with permissions to create secrets. If not set, certificate generation must be handled manually or via a tool like cert-manager. |
hostname |
Hostname of the current deployment stack. Required for certificate generation. |
adminLogin.generate |
Enabled by default, this option automatically create a secure password for OnSphere admin login. Secret name is |
adminLogin.name |
Name of the secret that contains the admin login. |
version |
Version of OnSphere’s modules. |
dispatcherVersion |
Version of the dispatcher module. This allow to define another version different from the one of the modules. See Upgrading unmanaged configuration. (Optional) |
imagePullSecrets |
List of secret name used to pull images. |
loadbalancer |
Configuration of a loadalancer for external request. |
loadbalancer.enable |
Enable creation of loadbalancer. |
loadbalancer.name |
Name of the service of type LoadBalancer. Default: “loadbalancer-exposed-svc” |
loadbalancer.externalIP |
External IP that will be attribuated to the loadbalancer. (Optional) |
loadbalancer.allocateLoadBalancerNodePorts |
Enable node port allocation for loadbalancer. Default: false |
loadbalancer.selector |
This property is a Dictionnary that represent a key/value selector for services that are allowed to expose port outside. Default: { lbtype: external } |
clusterDomain |
Internal Kubernetes cluster domain for pod name resolution (e.g., cluster.local). |
defaultStorageClass |
If defined, |
authorizedKeys |
List of SSH public keys used to access osp-configuration-dispatcher without a password. |
Some modules have static IDs or configurations that should not be modified:
keycloak.serviceName: Reserved identifier for Keycloak services.
rights.moduleId: Module identifier for the rights system. Do not change.
Default Module Defaults
To prevent duplication, a special configuration moduleDefault allow to define resources by default for all modules. This configuration is override in case the resource is specified for a module.
moduleDefault.resources
Defines the default resource requests and limits for modules.
resources:
limits:
cpu: 500m
memory: 512Mi
requests:
cpu: 100m
memory: 256Mi
Modules Configuration (modulesConfiguration)
The modulesConfiguration section defines a map of modules to be deployed. Each item in the map describes one module and its configuration. This section is instance-specific and tailored per deployment.
The following table describe minimal required configuration for every modules:
Field |
Description |
|---|---|
type |
Type of the module (e.g., osp_web, osp_mysql). Refer to https://docs.sdn.ch/onsphere/latest/ for a list of types. |
present |
Whether the module should be deployed (true) or omitted (false). |
deploymentName |
Name of the deployment to be created. |
serviceName |
Service name for cluster communication. |
moduleId |
Identifier that links the deployment with its configuration. Must match the configuration module path (e.g., modules.scripts.scripts-1). |
Each module accepts the following fields:
Field |
Description |
|---|---|
debug |
Enable debug port (5005). |
metrics |
Set the annotations |
logs |
Set the annotations |
podAnnotations |
Allow to inject custom pod annotations into the deployment. |
resources |
Module-specific CPU and memory requests/limits. |
resources.limits.cpu |
CPU limit (e.g., 500m, 2). |
resources.limits.memory |
Memory limit (e.g., 512Mi, 2Gi). |
resources.requests.cpu |
CPU request for scheduling. |
resources.requests.memory |
Memory request for scheduling. |
ports |
List of additional ports to expose. |
ports.[i].number |
Port number to expose (e.g., 5000, 8080). |
ports.[i].protocol |
Protocol to use (e.g., TCP, UDP). |
ports.[i].name |
Name of the port. Used for to expose port on external loadbalancer. Required when ports.[i].exposure is to BOTH or EXTERNAL. |
ports.[i].exposure |
Enum that describe port exposition. INTERNAL to expose port only to service ClusterIP named in .serviceName. EXTERNAL to only expose port on LoadBalancer defined in Global Configuration. BOTH. To expose on both services. If no loadbalancer are created, all ports are exposed on internal service. |
pvc |
List of persistent volume claims. |
pvc.[i].name |
PVC name suffix used in final naming. |
pvc.[i].size |
Requested storage size (e.g., 5Gi). |
pvc.[i].storageClass |
Kubernetes storage class. |
pvc.[i].pvRef |
Name of the persistentVolume to bound. |
pvc.[i].mountPath |
Mount path inside the container. |
extraSecrets |
List of Kubernetes secrets to mount into the pod. |
extraSecrets.secretName |
Name of the Kubernetes secret. |
extraSecrets.mounts |
List of mount configurations. |
extraSecrets.mounts.subPath |
Specific key inside the secret to mount. |
extraSecrets.mounts.mountPath |
Path in the container to mount the secret key. |
env |
List of environment variables to inject. |
env.name |
Name of the environment variable. |
env.value |
Value of the environment variable. |
mongoConfiguration.enable |
Enable MongoDB support for the module. |
mongoConfiguration.username |
Username used for connecting to MongoDB. |
mongoConfiguration.mountPath |
Mount path for MongoDB password or secrets. |
mongoConfiguration.dbname |
Database name for the module. |
deploymentStrategyType |
This set the update strategy for Deployment only. Set this value to one of the supported strategy. Warning Ensure the module support parallel update mode in section Modules capabilities. Modules that do not support parallel update mode may publish duplicate messages. |
image |
Image name (not including registry). If undefined, it will take field “type” and replace “_” by “-“. |
topologyKey |
Kubernetes topology key for anti-affinity scheduling. |
extraDNS |
Additional DNS names to resolve for this module. |
startupProbe |
Allow to define the startup probe. |
livenessProbe |
Allow to define the liveness probe. |
readinessProbe |
Allow to define the readiness probe. |
Some configuration are available only for some type of modules.
osp_mongo
Specific settings for module of type osp_mongo.
Field |
Description |
|---|---|
replicaName |
Name of the replicaset that will be created. |
replicaCount |
Number of replicate to create. |
maxSkew |
StatefullSet topology constraint that define how much pod may be scheduled on same node. |
wiredTrigerCacheGB |
Mongodb settings that set the cache size. See official documentation. |
keyfileSecret |
Name of the secret that contains replica’s shared key file. |
adminUsername |
Name of mongo admin user that is created. |
adminPassword |
Password of admin user |
topologyKey |
Label of the topology key to spread replicaset member |
portNumber |
Port of the db that listen for queries |
storage |
Settings of the pvc for mongodb |
osp_rabbitmq
Specific settings for module of type osp_rabbitmq.
Field |
Description |
|---|---|
managementInterface |
Expose rabbitmq management interface |
osp_configuration_dispatcher
Specific settings for module of type osp_configuration_dispatcher.
Field |
Description |
|---|---|
livenessProbe.initialDelaySeconds |
Delay before liveness probe starts. |
livenessProbe.timeoutSeconds |
Timeout for liveness check. |
livenessProbe.periodSeconds |
Time between probe checks. |
livenessProbe.successThreshold |
Minimum consecutive successes for probe to pass. |
livenessProbe.failureThreshold |
Number of failed checks before restart. |
gitService.name |
Git service name used by the configuration dispatcher. |
gitService.port |
Git service port used by the configuration dispatcher. |
Special Notes
Immutable moduleId: Some modules such as rights or keycloak have a moduleId that must not be modified. It ensures compatibility with the configuration dispatcher.
Certificate requirements: If generateCertificate is false, ensure TLS certificates are provided manually or via other certificate managers like cert-manager.
Secrets and mounts: Ensure Kubernetes secrets used in extraSecrets are properly defined and available in the namespace.
References
OnSphere Docs: https://docs.sdn.ch/onsphere/latest/
Helm documentation: https://helm.sh/docs/
Kubernetes concepts: https://kubernetes.io/docs