values.yaml used when installing the ngrok Kubernetes Operator. You can reference these values and change them individually with --set flags while installing/upgrading the ngrok Kubernetes Operator.
You can also see these values in the ngrok Operator repo.
Helm values
helm values
##
## @section Common parameters
##
## @param nameOverride String to partially override generated resource names
## @param fullnameOverride String to fully override generated resource names
## @param commonLabels Labels to add to all deployed objects
## @param commonAnnotations Annotations to add to all deployed objects
##
nameOverride: ""
fullnameOverride: ""
commonLabels: {}
commonAnnotations: {}
##
## @section Image configuration
##
## @param image.registry The ngrok operator image registry.
## @param image.repository The ngrok operator image repository.
## @param image.tag The ngrok operator image tag. Defaults to the chart's appVersion if not specified
## @param image.pullPolicy The ngrok operator image pull policy.
## @param image.pullSecrets An array of imagePullSecrets to be used when pulling the image.
##
image:
registry: docker.io
repository: ngrok/ngrok-operator
tag: ""
pullPolicy: IfNotPresent
## Example
## pullSecrets:
## - name: my-imagepull-secret
##
pullSecrets: []
##
## @section RBAC
##
## @param crdAccessRoles.create Whether to create editor/viewer ClusterRoles for CRDs
## @param crdAccessRoles.annotations Annotations for CRD access ClusterRoles (e.g., RBAC aggregation)
##
crdAccessRoles:
create: true
annotations: {}
##
## @section Custom Resource Definitions installation
##
## @param installCRDs When true, the ngrok CRDs will be installed alongside the operator
##
installCRDs: true
##
## @section ngrok
##
## How the operator connects to ngrok and what it does. Set once for every
## component: which component reads a setting is an implementation detail.
## `log` is the exception and can be overridden for one component under
## `components.<component>.log` (for example `components.agent.log.level`).
##
## An empty value means "not set": the operator's built-in default applies.
## Those defaults live in the operator binary and are listed here for reference.
##
## @param ngrok.credentials.secret.name The name of the secret the credentials are in. If not provided, one will be generated using the helm release name.
## @param ngrok.credentials.accessToken Your ngrok access token. Used by every component that needs one, unless overridden below.
## @param ngrok.credentials.agent.accessToken Optional access token for the agent-manager only. Falls back to ngrok.credentials.accessToken.
## @param ngrok.credentials.apiManager.accessToken Optional access token for the api-manager only. Falls back to ngrok.credentials.accessToken.
## @param ngrok.description Description of this installation in the ngrok dashboard. Default: `The official ngrok Kubernetes Operator.`
## @param ngrok.region ngrok region to use. Default: the account's default region
## @param ngrok.serverAddr Address of the ngrok server to use for tunnels. Default: the ngrok default
## @param ngrok.apiURL Base URL for the ngrok API. Default: the ngrok default
## @param ngrok.rootCAs Root CAs to trust: `trusted` for the ngrok CA, `host` for the host's CA bundle. Default: `trusted`
## @param ngrok.metadata Key/value pairs added as metadata to the ngrok API resources the operator creates
## @param ngrok.clusterDomain Cluster domain used when resolving in-cluster service addresses. Default: `svc.cluster.local`
## @param ngrok.log.level Log level: `debug`, `info`, `error`, `panic`, or an integer for more verbose debug levels. Default: `info`
## @param ngrok.log.format Log format: `json` or `console`. Default: `json`
## @param ngrok.log.stacktraceLevel Level at and above which stacktraces are captured: `info`, `error` or `panic`. Default: `error`
## @param ngrok.features.ingress.enabled Enable the Kubernetes Ingress controller
## @param ngrok.features.ingress.controllerName Controller name matched by IngressClasses, and set on the IngressClass this chart creates
## @param ngrok.features.ingress.watchNamespace Namespace to watch for Ingress and AgentEndpoint resources. Default: all namespaces
## @param ngrok.features.ingress.ingressClass.name IngressClass resource name
## @param ngrok.features.ingress.ingressClass.create Create the IngressClass resource
## @param ngrok.features.ingress.ingressClass.default Set the IngressClass as the cluster default
## @param ngrok.features.gateway.enabled Enable Gateway API support, if the Gateway API CRDs are detected
## @param ngrok.features.gateway.disableReferenceGrants Disable the ReferenceGrant requirement for cross-namespace references
## @param ngrok.features.bindings.enabled Enable the Endpoint Bindings feature, including the bindings-forwarder
## @param ngrok.features.bindings.endpointSelectors CEL expressions filtering which endpoints are projected into this cluster. Default: `["true"]`
## @param ngrok.features.bindings.serviceAnnotations Annotations applied to projected services
## @param ngrok.features.bindings.serviceLabels Labels applied to projected services
## @param ngrok.features.bindings.ingressEndpoint Hostname of the bindings ingress endpoint. Default: `kubernetes-binding-ingress.ngrok.io:443`
## @param ngrok.features.domains.defaultReclaimPolicy Reclaim policy given to the Domains the operator creates: `Delete` or `Retain`. Default: `Delete`
## @param ngrok.features.cleanup.enabled Run a pre-delete hook on uninstall that deletes the KubernetesOperator resource, so the operator drains before it is removed
## @param ngrok.features.cleanup.timeout Seconds the hook waits for the drain to finish
## @param ngrok.features.cleanup.drainPolicy What the drain does with the ngrok API resources the operator created: `Delete` or `Retain`. Default: `Retain`
## @param ngrok.features.oneClickDemoMode.enabled Start without credentials and become Ready without reconciling, for marketplace installs. Also skips rendering the agent and bindings-forwarder
##
ngrok:
credentials:
secret:
name: ""
accessToken: ""
## One token for everything is the simple path. The per-component values set a
## separate token for each component, falling back to accessToken when empty,
## so each token can be scoped to only the permissions its component needs.
agent:
accessToken: ""
apiManager:
accessToken: ""
description: ""
region: ""
serverAddr: ""
apiURL: ""
rootCAs: ""
metadata: {}
clusterDomain: ""
log:
level: ""
format: ""
stacktraceLevel: ""
features:
ingress:
enabled: true
controllerName: k8s.ngrok.com/ingress-controller
watchNamespace: ""
ingressClass:
name: ngrok
create: true
default: false
gateway:
enabled: true
disableReferenceGrants: false
bindings:
enabled: false
endpointSelectors: []
serviceAnnotations: {}
serviceLabels: {}
ingressEndpoint: ""
domains:
defaultReclaimPolicy: ""
cleanup:
enabled: true
timeout: 300
drainPolicy: ""
oneClickDemoMode:
enabled: false
##
## @section Components
##
## Kubernetes settings for each pod the chart runs.
##
## `components.common` applies to the api-manager, agent and bindings-forwarder.
## Each of them can override any common key, listed commented out under the
## component:
## - a key the component leaves unset inherits the common value;
## - a non-empty map merges with the common one, the component winning per key;
## - any other value, including an empty `{}`, `[]` or `""`, replaces it, so
## `components.agent.tolerations: []` drops the common tolerations for the
## agent alone.
## A null value is removed by Helm before the chart sees it, so setting one key
## of a map to null clears the whole map for that component.
##
## Commented-out keys have no chart default; Kubernetes' own default applies
## until one is set.
##
## @param components.common.podAnnotations Pod annotations
## @param components.common.podLabels Pod labels
## @param components.common.nodeSelector Node labels for pod assignment
## @param components.common.tolerations Tolerations for pod assignment
## @param components.common.affinity Affinity rules. Overrides the presets below when set
## @param components.common.podAffinityPreset Pod affinity preset. Ignored if `affinity` is set. Allowed values: `soft` or `hard`
## @param components.common.podAntiAffinityPreset Pod anti-affinity preset. Ignored if `affinity` is set. Allowed values: `soft` or `hard`
## @param components.common.nodeAffinityPreset.type Node affinity preset type. Ignored if `affinity` is set. Allowed values: `soft` or `hard`
## @param components.common.nodeAffinityPreset.key Node label key to match. Ignored if `affinity` is set.
## @param components.common.nodeAffinityPreset.values Node label values to match. Ignored if `affinity` is set.
## @param components.common.topologySpreadConstraints Topology spread constraints for pod assignment
## @param components.common.priorityClassName Priority class for pod scheduling
## @param components.common.extraEnv Additional environment variables, as a map of name to value. A name the chart also sets replaces the chart's entry
## @extra components.common.lifecycle Container lifecycle hooks
## @extra components.common.extraVolumes Additional volumes
## @extra components.common.extraVolumeMounts Additional volume mounts
## @extra components.common.terminationGracePeriodSeconds Graceful shutdown period, in seconds. Kubernetes default: `30`
## @extra components.common.updateStrategy Deployment update strategy. Kubernetes default: `RollingUpdate`
##
## @section Components: API Manager
##
## @param components.apiManager.replicaCount The number of api-manager replicas to run
## @param components.apiManager.podDisruptionBudget.create Whether to create a PodDisruptionBudget
## @param components.apiManager.podDisruptionBudget.maxUnavailable Maximum unavailable pods
## @extra components.apiManager.podDisruptionBudget.minAvailable Minimum available pods. Set this instead of `maxUnavailable`, not alongside it
## @param components.apiManager.serviceAccount.create Whether to create a ServiceAccount
## @extra components.apiManager.serviceAccount.name ServiceAccount name. Generated if empty
## @extra components.apiManager.serviceAccount.annotations ServiceAccount annotations
## @extra components.apiManager.resources Resource requests and limits
## @extra components.apiManager.log Overrides of `ngrok.log` for the api-manager
## @extra components.apiManager.podAnnotations Overrides `components.common.podAnnotations` for the api-manager
## @extra components.apiManager.podLabels Overrides `components.common.podLabels` for the api-manager
## @extra components.apiManager.nodeSelector Overrides `components.common.nodeSelector` for the api-manager
## @extra components.apiManager.tolerations Overrides `components.common.tolerations` for the api-manager
## @extra components.apiManager.affinity Overrides `components.common.affinity` for the api-manager
## @extra components.apiManager.podAffinityPreset Overrides `components.common.podAffinityPreset` for the api-manager
## @extra components.apiManager.podAntiAffinityPreset Overrides `components.common.podAntiAffinityPreset` for the api-manager
## @extra components.apiManager.nodeAffinityPreset Overrides `components.common.nodeAffinityPreset` for the api-manager
## @extra components.apiManager.topologySpreadConstraints Overrides `components.common.topologySpreadConstraints` for the api-manager
## @extra components.apiManager.priorityClassName Overrides `components.common.priorityClassName` for the api-manager
## @extra components.apiManager.extraEnv Overrides `components.common.extraEnv` for the api-manager
## @extra components.apiManager.lifecycle Overrides `components.common.lifecycle` for the api-manager
## @extra components.apiManager.extraVolumes Overrides `components.common.extraVolumes` for the api-manager
## @extra components.apiManager.extraVolumeMounts Overrides `components.common.extraVolumeMounts` for the api-manager
## @extra components.apiManager.terminationGracePeriodSeconds Overrides `components.common.terminationGracePeriodSeconds` for the api-manager
## @extra components.apiManager.updateStrategy Overrides `components.common.updateStrategy` for the api-manager
##
## @section Components: Agent
##
## @param components.agent.replicaCount The number of agent replicas to run
## @param components.agent.serviceAccount.create Whether to create a ServiceAccount
## @extra components.agent.serviceAccount.name ServiceAccount name. Generated if empty
## @extra components.agent.serviceAccount.annotations ServiceAccount annotations
## @extra components.agent.resources Resource requests and limits
## @extra components.agent.log Overrides of `ngrok.log` for the agent
## @extra components.agent.podAnnotations Overrides `components.common.podAnnotations` for the agent
## @extra components.agent.podLabels Overrides `components.common.podLabels` for the agent
## @extra components.agent.nodeSelector Overrides `components.common.nodeSelector` for the agent
## @extra components.agent.tolerations Overrides `components.common.tolerations` for the agent
## @extra components.agent.affinity Overrides `components.common.affinity` for the agent
## @extra components.agent.podAffinityPreset Overrides `components.common.podAffinityPreset` for the agent
## @extra components.agent.podAntiAffinityPreset Overrides `components.common.podAntiAffinityPreset` for the agent
## @extra components.agent.nodeAffinityPreset Overrides `components.common.nodeAffinityPreset` for the agent
## @extra components.agent.topologySpreadConstraints Overrides `components.common.topologySpreadConstraints` for the agent
## @extra components.agent.priorityClassName Overrides `components.common.priorityClassName` for the agent
## @extra components.agent.extraEnv Overrides `components.common.extraEnv` for the agent
## @extra components.agent.lifecycle Overrides `components.common.lifecycle` for the agent
## @extra components.agent.extraVolumes Overrides `components.common.extraVolumes` for the agent
## @extra components.agent.extraVolumeMounts Overrides `components.common.extraVolumeMounts` for the agent
## @extra components.agent.terminationGracePeriodSeconds Overrides `components.common.terminationGracePeriodSeconds` for the agent
## @extra components.agent.updateStrategy Overrides `components.common.updateStrategy` for the agent
##
## @section Components: Bindings Forwarder
##
## Rendered only when `ngrok.features.bindings.enabled` is true.
##
## @param components.bindingsForwarder.replicaCount The number of bindings-forwarder replicas to run
## @param components.bindingsForwarder.serviceAccount.create Whether to create a ServiceAccount
## @extra components.bindingsForwarder.serviceAccount.name ServiceAccount name. Generated if empty
## @extra components.bindingsForwarder.serviceAccount.annotations ServiceAccount annotations
## @extra components.bindingsForwarder.resources Resource requests and limits
## @extra components.bindingsForwarder.log Overrides of `ngrok.log` for the bindings-forwarder
## @extra components.bindingsForwarder.podAnnotations Overrides `components.common.podAnnotations` for the bindings-forwarder
## @extra components.bindingsForwarder.podLabels Overrides `components.common.podLabels` for the bindings-forwarder
## @extra components.bindingsForwarder.nodeSelector Overrides `components.common.nodeSelector` for the bindings-forwarder
## @extra components.bindingsForwarder.tolerations Overrides `components.common.tolerations` for the bindings-forwarder
## @extra components.bindingsForwarder.affinity Overrides `components.common.affinity` for the bindings-forwarder
## @extra components.bindingsForwarder.podAffinityPreset Overrides `components.common.podAffinityPreset` for the bindings-forwarder
## @extra components.bindingsForwarder.podAntiAffinityPreset Overrides `components.common.podAntiAffinityPreset` for the bindings-forwarder
## @extra components.bindingsForwarder.nodeAffinityPreset Overrides `components.common.nodeAffinityPreset` for the bindings-forwarder
## @extra components.bindingsForwarder.topologySpreadConstraints Overrides `components.common.topologySpreadConstraints` for the bindings-forwarder
## @extra components.bindingsForwarder.priorityClassName Overrides `components.common.priorityClassName` for the bindings-forwarder
## @extra components.bindingsForwarder.extraEnv Overrides `components.common.extraEnv` for the bindings-forwarder
## @extra components.bindingsForwarder.lifecycle Overrides `components.common.lifecycle` for the bindings-forwarder
## @extra components.bindingsForwarder.extraVolumes Overrides `components.common.extraVolumes` for the bindings-forwarder
## @extra components.bindingsForwarder.extraVolumeMounts Overrides `components.common.extraVolumeMounts` for the bindings-forwarder
## @extra components.bindingsForwarder.terminationGracePeriodSeconds Overrides `components.common.terminationGracePeriodSeconds` for the bindings-forwarder
## @extra components.bindingsForwarder.updateStrategy Overrides `components.common.updateStrategy` for the bindings-forwarder
##
## @section Components: Cleanup Hook
##
## The pod of the pre-delete hook `ngrok.features.cleanup` runs. It does not
## take `components.common`.
##
## @param components.cleanupHook.image.repository The repository for the kubectl image used by the cleanup hook
## @param components.cleanupHook.image.tag The tag for the kubectl image
## @param components.cleanupHook.image.pullPolicy The pull policy for the cleanup hook image
## @param components.cleanupHook.resources.limits The resources limits for the cleanup hook container
## @param components.cleanupHook.resources.requests The requested resources for the cleanup hook container
##
components:
common:
podAnnotations: {}
podLabels: {}
nodeSelector: {}
tolerations: []
affinity: {}
podAffinityPreset: ""
podAntiAffinityPreset: soft
nodeAffinityPreset:
type: ""
key: ""
values: []
topologySpreadConstraints: []
priorityClassName: ""
extraEnv: {}
# lifecycle: {}
# extraVolumes: []
# extraVolumeMounts: []
# terminationGracePeriodSeconds: 30
# updateStrategy:
# type: RollingUpdate
apiManager:
replicaCount: 1
podDisruptionBudget:
create: false
maxUnavailable: "1"
# minAvailable: ""
serviceAccount:
create: true
# name: ""
# annotations: {}
# resources:
# limits: {}
# requests: {}
# log: {} # overrides of ngrok.log
## Overrides of components.common:
# podAnnotations: {}
# podLabels: {}
# nodeSelector: {}
# tolerations: []
# affinity: {}
# podAffinityPreset: ""
# podAntiAffinityPreset: ""
# nodeAffinityPreset: {}
# topologySpreadConstraints: []
# priorityClassName: ""
# extraEnv: {}
# lifecycle: {}
# extraVolumes: []
# extraVolumeMounts: []
# terminationGracePeriodSeconds: 30
# updateStrategy:
# type: RollingUpdate
agent:
replicaCount: 1
serviceAccount:
create: true
# name: ""
# annotations: {}
# resources:
# limits: {}
# requests: {}
# log: {} # overrides of ngrok.log
## Overrides of components.common:
# podAnnotations: {}
# podLabels: {}
# nodeSelector: {}
# tolerations: []
# affinity: {}
# podAffinityPreset: ""
# podAntiAffinityPreset: ""
# nodeAffinityPreset: {}
# topologySpreadConstraints: []
# priorityClassName: ""
# extraEnv: {}
# lifecycle: {}
# extraVolumes: []
# extraVolumeMounts: []
# terminationGracePeriodSeconds: 30
# updateStrategy:
# type: RollingUpdate
bindingsForwarder:
replicaCount: 1
serviceAccount:
create: true
# name: ""
# annotations: {}
# resources:
# limits: {}
# requests: {}
# log: {} # overrides of ngrok.log
## Overrides of components.common:
# podAnnotations: {}
# podLabels: {}
# nodeSelector: {}
# tolerations: []
# affinity: {}
# podAffinityPreset: ""
# podAntiAffinityPreset: ""
# nodeAffinityPreset: {}
# topologySpreadConstraints: []
# priorityClassName: ""
# extraEnv: {}
# lifecycle: {}
# extraVolumes: []
# extraVolumeMounts: []
# terminationGracePeriodSeconds: 30
# updateStrategy:
# type: RollingUpdate
cleanupHook:
image:
repository: bitnami/kubectl
tag: latest
pullPolicy: IfNotPresent
resources:
limits: {}
requests: {}
Common configurations
This section provides some common use cases and recommendations when using this helm chart in a production setting.Deployment scaling
By default, the replica count is set to 1 viareplicaCount. Override this to 2 or more to ensure high availability during roll-outs and failures, and to spread out the load.
ngrok region
ngrok runs globally distributed tunnel servers around the world to enable fast, low latency traffic to your applications. See ngrok’s points of presence for more information on ngrok’s regions. Similar to the agent, if you do not explicitly pick a region via helm when installing the Operator, the Operator will attempt to pick the region with the least latency, which is usually the one geographically closest to your machine. Specifying a region applies this setting across all agent connect URLs in your cluster; regions cannot currently be configured on a per-connection basis. See the helm valueregion to configure a specific region for the controller to use.
Watching specific namespaces
By default, the Operator watches all namespaces. It’s a common use case to need a controller to watch only a specific namespace in the case where you may run a controller in a namespace for each team or environment. In order to watch only a specific namespace for ingress objects, you can set the helm valuewatchNamespace to the namespace you want to watch.