About this reference#
Generated from the values schema included with the release chart. Defaults and descriptions come straight from the chart, so this page cannot describe a value the chart does not ship.
Override any key with --set or a values file. See Profiles for the
curated combinations.
nameOverride#
| Key | Default | Description |
|---|---|---|
| nameOverride | "" | — |
fullnameOverride#
| Key | Default | Description |
|---|---|---|
| fullnameOverride | "" | — |
global#
| Key | Default | Description |
|---|---|---|
| global | — | — |
| global.imageRegistry | "" | — |
| global.imagePullPolicy | IfNotPresent | — |
| global.namespaceOverride | "" | — |
| global.tenant | default | — |
| global.provider | local | — |
| global.region | local | — |
| global.clusterName | local | — |
| global.labels | {} | — |
| global.annotations | {} | — |
| global.imagePullSecrets | [] | — |
| global.automountServiceAccountToken | true | — |
| global.podSecurityContext | {} | — |
| global.securityContext | {} | — |
| global.nodeSelector | {} | — |
| global.tolerations | [] | — |
| global.affinity | {} | — |
| global.topologySpreadConstraints | [] | — |
| global.priorityClassName | "" | — |
rbac#
| Key | Default | Description |
|---|---|---|
| rbac | — | — |
| rbac.create | true | — |
serviceAccount#
| Key | Default | Description |
|---|---|---|
| serviceAccount | — | — |
| serviceAccount.create | true | — |
| serviceAccount.name | "" | — |
| serviceAccount.annotations | {} | — |
migrations#
| Key | Default | Description |
|---|---|---|
| migrations | — | Production schema ownership is separated from long-running services. Enable this hook only with PostgreSQL stores whose autoMigrate setting is false. |
| migrations.enabled | false | — |
| migrations.image | — | — |
| migrations.image.repository | ghcr.io/bitfid-inc/agentfleet-db-migrate | — |
| migrations.image.tag | v0.1.0 | — |
| migrations.timeout | "2m" | — |
| migrations.backoffLimit | 1 | — |
| migrations.ttlSecondsAfterFinished | 300 | — |
| migrations.secrets | — | Empty existingSecret values fall back to the component runtime Secret. Production platforms should provide separate schema-owner credentials. |
| migrations.secrets.registry | — | — |
| migrations.secrets.registry.existingSecret | "" | — |
| migrations.secrets.registry.dsnKey | dsn | — |
| migrations.secrets.context | — | — |
| migrations.secrets.context.existingSecret | "" | — |
| migrations.secrets.context.dsnKey | dsn | — |
| migrations.secrets.approval | — | — |
| migrations.secrets.approval.existingSecret | "" | — |
| migrations.secrets.approval.dsnKey | dsn | — |
| migrations.secrets.console | — | — |
| migrations.secrets.console.existingSecret | "" | — |
| migrations.secrets.console.dsnKey | dsn | — |
| migrations.resources | {} | — |
| migrations.podLabels | {} | — |
| migrations.podAnnotations | {} | — |
podDisruptionBudget#
| Key | Default | Description |
|---|---|---|
| podDisruptionBudget | — | — |
| podDisruptionBudget.enabled | false | — |
| podDisruptionBudget.minAvailable | 1 | — |
| podDisruptionBudget.maxUnavailable | "" | — |
networkPolicy#
| Key | Default | Description |
|---|---|---|
| networkPolicy | — | — |
| networkPolicy.enabled | false | — |
| networkPolicy.additionalIngressFrom | [] | Additional ingress peers can be added for an external gateway or metrics collector. |
operator#
| Key | Default | Description |
|---|---|---|
| operator | — | — |
| operator.enabled | true | — |
| operator.replicaCount | 1 | — |
| operator.image | — | — |
| operator.image.repository | ghcr.io/bitfid-inc/agentfleet-operator | — |
| operator.image.tag | v0.1.0 | — |
| operator.image.digest | "" | — |
| operator.service | — | — |
| operator.service.type | ClusterIP | — |
| operator.service.metricsPort | 8080 | — |
| operator.metrics | — | — |
| operator.metrics.port | 8080 | — |
| operator.probes | — | — |
| operator.probes.port | 8081 | — |
| operator.leaderElection | — | — |
| operator.leaderElection.enabled | false | — |
| operator.registry | — | — |
| operator.registry.enabled | true | — |
| operator.registry.url | "" | — |
| operator.protection | — | Settings for agents in protected namespaces, which a platform administrator marks with the label agentfleet.io/protection=managed. Each such agent runs under its own ServiceAccount with a Model Router token, a hardened pod, and only the Secrets listed in the namespace annotation agentfleet.io/allowed-secrets. Other namespaces are unaffected. |
| operator.protection.modelRouterURL | "" | Injected into protected agents as AGENTFLEET_MODEL_ROUTER_URL. Defaults to the in-chart Model Router when it is enabled. |
| operator.protection.runAsUser | 65532 | UID for protected agent pods. 0 relies on a numeric USER in the image. |
| operator.protection.enforcementProbe | — | Optional Helm hook that proves the cluster actually enforces an egress deny policy. Enable this wherever protected-path claims are made. |
| operator.protection.enforcementProbe.enabled | false | — |
| operator.protection.enforcementProbe.image | — | — |
| operator.protection.enforcementProbe.image.repository | busybox | — |
| operator.protection.enforcementProbe.image.tag | "1.37.0" | — |
| operator.protection.enforcementProbe.image.digest | "" | — |
| operator.protection.enforcementProbe.timeoutSeconds | 10 | — |
| operator.resources | {} | — |
| operator.podLabels | {} | — |
| operator.podAnnotations | {} | — |
approval#
| Key | Default | Description |
|---|---|---|
| approval | — | Approval is optional because not every routing policy requires a human gate. Credentials are always read from caller-managed Secrets, never chart values. |
| approval.enabled | false | — |
| approval.replicaCount | 1 | — |
| approval.image | — | — |
| approval.image.repository | ghcr.io/bitfid-inc/agentfleet-approval | — |
| approval.image.tag | v0.1.0 | — |
| approval.image.digest | "" | — |
| approval.service | — | — |
| approval.service.type | ClusterIP | — |
| approval.service.port | 8088 | — |
| approval.external | — | — |
| approval.external.url | "" | Set a remote Approval base URL instead of deploying approval.enabled=true. |
| approval.external.allowInsecureHTTP | false | — |
| approval.clients | — | — |
| approval.clients.gateway | — | — |
| approval.clients.gateway.enabled | true | — |
| approval.clients.modelRouter | — | — |
| approval.clients.modelRouter.enabled | true | — |
| approval.clients.console | — | Approver access is opt-in because it requires authenticated tenant RBAC. |
| approval.clients.console.enabled | false | — |
| approval.serviceAccount | — | — |
| approval.serviceAccount.create | true | — |
| approval.serviceAccount.name | "" | — |
| approval.serviceAccount.annotations | {} | — |
| approval.serviceAccount.automountServiceAccountToken | false | Enable only when the selected workload-identity mechanism needs a projected token. |
| approval.storage | — | — |
| approval.storage.type | memory | — |
| approval.storage.postgres | — | — |
| approval.storage.postgres.existingSecret | "" | — |
| approval.storage.postgres.dsnKey | dsn | — |
| approval.storage.postgres.autoMigrate | true | — |
| approval.ttl | — | — |
| approval.ttl.default | "1h" | — |
| approval.ttl.maximum | "720h" | — |
| approval.ttl.claim | "5m" | — |
| approval.allowSelfApproval | false | — |
| approval.auth | — | — |
| approval.auth.mode | token | — |
| approval.auth.existingSecret | "" | — |
| approval.auth.workflowTokenKey | workflow-token | — |
| approval.auth.approverTokenKey | approver-token | — |
| approval.audit | — | — |
| approval.audit.mode | async | — |
| approval.audit.sinkType | stdout | — |
| approval.notification | — | — |
| approval.notification.webhook | — | — |
| approval.notification.webhook.url | "" | — |
| approval.notification.webhook.existingSecret | "" | — |
| approval.notification.webhook.tokenKey | token | — |
| approval.notification.webhook.timeout | "5s" | — |
| approval.sweeper | — | — |
| approval.sweeper.interval | "30s" | — |
| approval.sweeper.batchSize | 100 | — |
| approval.terminationGracePeriodSeconds | 30 | — |
| approval.resources | {} | — |
| approval.podLabels | {} | — |
| approval.podAnnotations | {} | — |
gateway#
| Key | Default | Description |
|---|---|---|
| gateway | — | — |
| gateway.enabled | true | — |
| gateway.replicaCount | 1 | — |
| gateway.image | — | — |
| gateway.image.repository | ghcr.io/bitfid-inc/agentfleet-gateway | — |
| gateway.image.tag | v0.1.0 | — |
| gateway.image.digest | "" | — |
| gateway.service | — | — |
| gateway.service.type | ClusterIP | — |
| gateway.service.port | 8080 | — |
| gateway.config | — | — |
| gateway.config.metrics | — | — |
| gateway.config.metrics.enabled | true | — |
| gateway.config.metrics.path | "" | Empty inherits observability.metrics.path. |
| gateway.config.registryURL | "" | — |
| gateway.config.scheduler | — | — |
| gateway.config.scheduler.enabled | false | — |
| gateway.config.scheduler.url | "" | — |
| gateway.config.scheduler.failurePolicy | fallback | — |
| gateway.config.policy | — | — |
| gateway.config.policy.mode | "off" | — |
| gateway.config.policy.url | "" | — |
| gateway.config.policy.failurePolicy | fail | — |
| gateway.config.context | — | — |
| gateway.config.context.mode | "off" | — |
| gateway.config.context.url | "" | — |
| gateway.config.context.appendFailurePolicy | continue | — |
| gateway.config.audit | — | — |
| gateway.config.audit.mode | "off" | — |
| gateway.config.audit.sinkType | "noop" | — |
| gateway.config.a2a | — | — |
| gateway.config.a2a.delegationEnabled | false | — |
| gateway.config.a2a.delegationTimeout | "10s" | — |
| gateway.config.tenantAuthz | — | — |
| gateway.config.tenantAuthz.mode | "off" | — |
| gateway.config.tenantAuthz.source | "static_config" | — |
| gateway.config.tenantAuthz.static | — | — |
| gateway.config.tenantAuthz.static.memberships | [] | — |
| gateway.config.tenantAuthz.idpGroups | — | — |
| gateway.config.tenantAuthz.idpGroups.enabled | false | — |
| gateway.config.tenantAuthz.idpGroups.groupClaim | "groups" | — |
| gateway.config.tenantAuthz.idpGroups.stringClaimDelimiter | " " | — |
| gateway.config.tenantAuthz.idpGroups.includeMatchedGroups | false | — |
| gateway.config.tenantAuthz.idpGroups.mappings | [] | — |
| gateway.config.auth | — | — |
| gateway.config.auth.mode | "off" | — |
| gateway.config.auth.diagnosticsEnabled | true | — |
| gateway.config.auth.requireTenant | false | — |
| gateway.config.auth.requireActor | false | — |
| gateway.config.auth.headerDev | — | — |
| gateway.config.auth.headerDev.tenantHeader | "X-AgentFleet-Tenant" | — |
| gateway.config.auth.headerDev.actorHeader | "X-AgentFleet-Actor" | — |
| gateway.config.auth.headerDev.actorTypeHeader | "X-AgentFleet-Actor-Type" | — |
| gateway.config.auth.headerDev.allowBodyFallback | true | — |
| gateway.config.auth.oidcJwt | — | — |
| gateway.config.auth.oidcJwt.issuer | "" | — |
| gateway.config.auth.oidcJwt.audience | [] | — |
| gateway.config.auth.oidcJwt.jwksURL | "" | — |
| gateway.config.auth.oidcJwt.allowInsecureHTTP | false | — |
| gateway.config.auth.oidcJwt.tenantClaim | "tenant_id" | — |
| gateway.config.auth.oidcJwt.actorClaim | "sub" | — |
| gateway.config.auth.oidcJwt.actorTypeClaim | "actor_type" | — |
| gateway.config.auth.oidcJwt.allowedAlgorithms | — | — |
| gateway.config.auth.oidcJwt.clockSkew | "60s" | — |
| gateway.config.auth.oidcJwt.jwksCacheTTL | "5m" | — |
| gateway.config.auth.oidcJwt.jwksRefreshTimeout | "5s" | — |
| gateway.config.auth.oidcJwt.jwksRefreshMinInterval | "60s" | — |
| gateway.resources | {} | — |
| gateway.podLabels | {} | — |
| gateway.podAnnotations | {} | — |
registry#
| Key | Default | Description |
|---|---|---|
| registry | — | — |
| registry.enabled | true | — |
| registry.replicaCount | 1 | — |
| registry.image | — | — |
| registry.image.repository | ghcr.io/bitfid-inc/agentfleet-registry | — |
| registry.image.tag | v0.1.0 | — |
| registry.image.digest | "" | — |
| registry.service | — | — |
| registry.service.type | ClusterIP | — |
| registry.service.port | 8082 | — |
| registry.storage | — | — |
| registry.storage.type | memory | — |
| registry.storage.postgres | — | — |
| registry.storage.postgres.existingSecret | "" | — |
| registry.storage.postgres.dsnKey | dsn | — |
| registry.storage.postgres.autoMigrate | true | — |
| registry.resources | {} | — |
| registry.podLabels | {} | — |
| registry.podAnnotations | {} | — |
scheduler#
| Key | Default | Description |
|---|---|---|
| scheduler | — | — |
| scheduler.enabled | true | — |
| scheduler.replicaCount | 1 | — |
| scheduler.image | — | — |
| scheduler.image.repository | ghcr.io/bitfid-inc/agentfleet-scheduler | — |
| scheduler.image.tag | v0.1.0 | — |
| scheduler.image.digest | "" | — |
| scheduler.service | — | — |
| scheduler.service.type | ClusterIP | — |
| scheduler.service.port | 8083 | — |
| scheduler.resources | {} | — |
| scheduler.podLabels | {} | — |
| scheduler.podAnnotations | {} | — |
policy#
| Key | Default | Description |
|---|---|---|
| policy | — | — |
| policy.enabled | true | — |
| policy.replicaCount | 1 | — |
| policy.image | — | — |
| policy.image.repository | ghcr.io/bitfid-inc/agentfleet-policy | — |
| policy.image.tag | v0.1.0 | — |
| policy.image.digest | "" | — |
| policy.service | — | — |
| policy.service.type | ClusterIP | — |
| policy.service.port | 8084 | — |
| policy.mode | enforce | — |
| policy.rules | {} | Operator-authored governance rules, rendered into the chart ConfigMap and mounted read-only. Leaving this empty means the policy service denies every request, so gateway.config.policy.mode=enforce needs rules here before any traffic is allowed through. Unknown keys fail startup rather than being ignored, so a typo cannot silently leave a restriction unenforced. Note: an allow list is only checked when the request carries that field. A request with no tenant is not matched by allowedTenants; defaultDecision is what stops it. Keep defaultDecision set to deny. rules: defaultDecision: deny allowedTenants: - enterprise-it allowedCapabilities: - it-triage |
| policy.resources | {} | — |
| policy.podLabels | {} | — |
| policy.podAnnotations | {} | — |
guard#
| Key | Default | Description |
|---|---|---|
| guard | — | Optional local guardrail service. Disabled by default. When enabled it runs the deterministic secret and encoded-content detectors configured below; no model traffic passes through it until the Model Router is configured to call it. |
| guard.enabled | false | — |
| guard.replicaCount | 1 | — |
| guard.image | — | — |
| guard.image.repository | ghcr.io/bitfid-inc/agentfleet-guard | — |
| guard.image.tag | v0.1.0 | — |
| guard.image.digest | "" | — |
| guard.service | — | — |
| guard.service.type | ClusterIP | — |
| guard.service.port | 8090 | — |
| guard.serviceAccount | — | — |
| guard.serviceAccount.create | true | — |
| guard.serviceAccount.name | "" | — |
| guard.serviceAccount.annotations | {} | — |
| guard.serviceAccount.automountServiceAccountToken | false | — |
| guard.auth | — | Callers authenticate with a shared bearer token read from existingSecret. mode=off is for local development only and is rejected by the secure production profile. |
| guard.auth.mode | token | — |
| guard.auth.existingSecret | "" | — |
| guard.auth.tokenKey | token | — |
| guard.config | — | Detector manifests and tenant profiles, rendered into a GuardConfig file and mounted read-only. Guard refuses to start without at least one profile, and unknown keys fail startup. A profile's namespace must be the namespace of the agents it covers, and its mode (off, audit, or enforce) decides whether findings change a request. Start new profiles in audit. See examples/guard/values-secret-detection.yaml for a complete, tested example. |
| guard.config.detectors | [] | — |
| guard.config.profiles | [] | — |
| guard.terminationGracePeriodSeconds | 30 | — |
| guard.resources | {} | — |
| guard.podLabels | {} | — |
| guard.podAnnotations | {} | — |
modelRouter#
| Key | Default | Description |
|---|---|---|
| modelRouter | — | — |
| modelRouter.enabled | true | — |
| modelRouter.replicaCount | 1 | — |
| modelRouter.image | — | — |
| modelRouter.image.repository | ghcr.io/bitfid-inc/agentfleet-model-router | — |
| modelRouter.image.tag | v0.1.0 | — |
| modelRouter.image.digest | "" | — |
| modelRouter.service | — | — |
| modelRouter.service.type | ClusterIP | — |
| modelRouter.service.port | 8085 | — |
| modelRouter.serviceAccount | — | — |
| modelRouter.serviceAccount.create | true | — |
| modelRouter.serviceAccount.name | "" | — |
| modelRouter.serviceAccount.annotations | {} | — |
| modelRouter.serviceAccount.automountServiceAccountToken | false | Enable only when provider or Kubernetes workload identity needs a projected token. |
| modelRouter.credentials | — | — |
| modelRouter.credentials.mode | static | static uses installation-wide Secret references; kubernetes resolves by tenant. |
| modelRouter.credentials.kubernetes | — | — |
| modelRouter.credentials.kubernetes.secretNamespace | "" | Empty uses the Helm release namespace. |
| modelRouter.credentials.kubernetes.cacheTTL | "5m" | — |
| modelRouter.credentials.kubernetes.mappings | [] | — |
| modelRouter.config | — | — |
| modelRouter.config.policyURL | "" | — |
| modelRouter.security | — | — |
| modelRouter.security.auth | — | — |
| modelRouter.security.auth.mode | "off" | — |
| modelRouter.security.auth.existingSecret | "" | — |
| modelRouter.security.auth.tokenKey | token | — |
| modelRouter.security.allowPolicyOff | true | — |
| modelRouter.security.allowUnauthenticatedPaidExecution | false | Explicit escape hatch for controlled local paid-provider fixtures. |
| modelRouter.security.limits | — | — |
| modelRouter.security.limits.requestsPerMinute | 60 | — |
| modelRouter.security.limits.modelCallsPerMinute | 180 | — |
| modelRouter.security.limits.maxConcurrentPerTenant | 8 | — |
| modelRouter.security.limits.maxModelsPerRequest | 4 | — |
| modelRouter.security.limits.maxOutputTokens | 8192 | — |
| modelRouter.security.limits.maxTrackedTenants | 1000 | — |
| modelRouter.metrics | — | — |
| modelRouter.metrics.enabled | true | — |
| modelRouter.metrics.path | "" | Empty inherits observability.metrics.path. |
| modelRouter.audit | — | — |
| modelRouter.audit.mode | async | off, async, or sync_required. sync_required fails the request if audit delivery fails. |
| modelRouter.audit.sinkType | stdout | — |
| modelRouter.comparison | — | — |
| modelRouter.comparison.enabled | true | — |
| modelRouter.comparison.contextURL | "" | Empty uses the in-chart Context service when context.enabled=true. |
| modelRouter.comparison.storageRequired | false | — |
| modelRouter.pricing | — | — |
| modelRouter.pricing.enabled | false | Rates are operator-managed so provider price changes do not require a release. |
| modelRouter.pricing.rates | [] | — |
| modelRouter.guard | — | Guard inspection of model input and output. Each binding selects the Guard profile for one tenant's agents in one namespace; callers cannot choose a profile. The profile's own mode decides whether findings change requests. failurePolicy (fail_closed or fail_open) decides what happens when Guard cannot answer. streaming (reject or uninspected) decides whether covered agents may stream, since streamed replies cannot be inspected first. The secure production profile requires fail_closed and reject. |
| modelRouter.guard.enabled | false | — |
| modelRouter.guard.url | "" | Defaults to the in-chart Guard Service when guard.enabled=true. |
| modelRouter.guard.existingSecret | "" | Token Secret for calling Guard. Defaults to guard.auth.existingSecret and guard.auth.tokenKey. |
| modelRouter.guard.tokenKey | "" | — |
| modelRouter.guard.bindings | [] | — |
| modelRouter.workloadIdentity | — | Accept agent ServiceAccount tokens from protected namespaces. The Model Router verifies each token with the Kubernetes TokenReview API and takes tenant and agent from the Registry, rejecting requests that claim different values. The shared token keeps working for Console and Gateway. Requires modelRouter.serviceAccount.automountServiceAccountToken=true so the Model Router can call TokenReview. |
| modelRouter.workloadIdentity.enabled | false | — |
| modelRouter.workloadIdentity.audience | agentfleet-model-router | — |
| modelRouter.workloadIdentity.cacheTTL | "30s" | How long a TokenReview result for an agent token is reused. |
| modelRouter.workloadIdentity.registryRefresh | "5s" | How long an agent's Registry tenant and phase are reused. This bounds how quickly a suspension reaches the Model Router; keep it well under 30s and no longer than cacheTTL. |
| modelRouter.workloadIdentity.registryURL | "" | Defaults to the in-chart Registry. |
| modelRouter.providers | — | — |
| modelRouter.providers.mock | — | — |
| modelRouter.providers.mock.enabled | true | — |
| modelRouter.providers.openai | — | — |
| modelRouter.providers.openai.enabled | false | — |
| modelRouter.providers.openai.existingSecret | "" | — |
| modelRouter.providers.openai.secretKey | api-key | — |
| modelRouter.providers.openai.baseURL | "" | — |
| modelRouter.providers.openai.organization | "" | — |
| modelRouter.providers.openai.project | "" | — |
| modelRouter.providers.openai.timeout | "30s" | — |
| modelRouter.providers.openai.allowInsecureHTTP | false | — |
| modelRouter.providers.anthropic | — | — |
| modelRouter.providers.anthropic.enabled | false | — |
| modelRouter.providers.anthropic.existingSecret | "" | — |
| modelRouter.providers.anthropic.secretKey | api-key | — |
| modelRouter.providers.anthropic.baseURL | "" | — |
| modelRouter.providers.anthropic.version | "2023-06-01" | — |
| modelRouter.providers.anthropic.timeout | "30s" | — |
| modelRouter.providers.anthropic.allowInsecureHTTP | false | — |
| modelRouter.providers.bedrock | — | — |
| modelRouter.providers.bedrock.enabled | false | — |
| modelRouter.providers.bedrock.region | "" | — |
| modelRouter.providers.bedrock.timeout | "30s" | — |
| modelRouter.resources | {} | — |
| modelRouter.podLabels | {} | — |
| modelRouter.podAnnotations | {} | — |
context#
| Key | Default | Description |
|---|---|---|
| context | — | — |
| context.enabled | false | — |
| context.replicaCount | 1 | — |
| context.image | — | — |
| context.image.repository | ghcr.io/bitfid-inc/agentfleet-context | — |
| context.image.tag | v0.1.0 | — |
| context.image.digest | "" | — |
| context.service | — | — |
| context.service.type | ClusterIP | — |
| context.service.port | 8086 | — |
| context.mode | "off" | — |
| context.security | — | — |
| context.security.auth | — | — |
| context.security.auth.mode | "off" | — |
| context.security.auth.existingSecret | "" | — |
| context.security.auth.tokenKey | token | — |
| context.storage | — | — |
| context.storage.type | memory | — |
| context.storage.postgres | — | — |
| context.storage.postgres.existingSecret | "" | — |
| context.storage.postgres.dsnKey | dsn | — |
| context.storage.postgres.autoMigrate | true | — |
| context.retention | — | — |
| context.retention.days | 7 | — |
| context.cleanupInterval | "5m" | — |
| context.memory | — | — |
| context.memory.maxConversations | 1000 | — |
| context.memory.maxConversationsPerTenant | 100 | — |
| context.memory.maxTurnsPerConversation | 100 | — |
| context.memory.maxComparisonsPerConversation | 20 | — |
| context.memory.maxBytesPerConversation | 262144 | — |
| context.resources | {} | — |
| context.podLabels | {} | — |
| context.podAnnotations | {} | — |
demoAgents#
| Key | Default | Description |
|---|---|---|
| demoAgents | — | — |
| demoAgents.enabled | false | — |
| demoAgents.namespace | agentfleet-demo | — |
| demoAgents.refund | — | — |
| demoAgents.refund.enabled | true | — |
| demoAgents.refund.replicaCount | 1 | — |
| demoAgents.refund.image | — | — |
| demoAgents.refund.image.repository | ghcr.io/bitfid-inc/examples/refund-agent | — |
| demoAgents.refund.image.tag | v0.1.0 | — |
| demoAgents.refund.image.digest | "" | — |
| demoAgents.refund.service | — | — |
| demoAgents.refund.service.port | 8080 | — |
| demoAgents.order | — | — |
| demoAgents.order.enabled | true | — |
| demoAgents.order.replicaCount | 1 | — |
| demoAgents.order.image | — | — |
| demoAgents.order.image.repository | ghcr.io/bitfid-inc/examples/order-agent | — |
| demoAgents.order.image.tag | v0.1.0 | — |
| demoAgents.order.image.digest | "" | — |
| demoAgents.order.service | — | — |
| demoAgents.order.service.port | 8080 | — |
| demoAgents.it | — | — |
| demoAgents.it.enabled | true | — |
| demoAgents.it.replicaCount | 1 | — |
| demoAgents.it.image | — | — |
| demoAgents.it.image.repository | ghcr.io/bitfid-inc/examples/it-support-agent | — |
| demoAgents.it.image.tag | v0.1.0 | — |
| demoAgents.it.image.digest | "" | — |
| demoAgents.it.service | — | — |
| demoAgents.it.service.port | 8080 | — |
| demoAgents.customerProfileMCP | — | — |
| demoAgents.customerProfileMCP.enabled | false | — |
| demoAgents.customerProfileMCP.replicaCount | 1 | — |
| demoAgents.customerProfileMCP.image | — | — |
| demoAgents.customerProfileMCP.image.repository | ghcr.io/bitfid-inc/examples/customer-profile-mcp | — |
| demoAgents.customerProfileMCP.image.tag | v0.1.0 | — |
| demoAgents.customerProfileMCP.image.digest | "" | — |
| demoAgents.customerProfileMCP.service | — | — |
| demoAgents.customerProfileMCP.service.port | 8088 | — |
| demoAgents.a2aPeer | — | — |
| demoAgents.a2aPeer.enabled | false | — |
| demoAgents.a2aPeer.replicaCount | 1 | — |
| demoAgents.a2aPeer.image | — | — |
| demoAgents.a2aPeer.image.repository | ghcr.io/bitfid-inc/examples/a2a-peer | — |
| demoAgents.a2aPeer.image.tag | v0.1.0 | — |
| demoAgents.a2aPeer.image.digest | "" | — |
| demoAgents.a2aPeer.service | — | — |
| demoAgents.a2aPeer.service.port | 18090 | — |
mesh#
| Key | Default | Description |
|---|---|---|
| mesh | — | — |
| mesh.enabled | false | — |
| mesh.provider | istio | — |
| mesh.mode | sidecar | — |
| mesh.mtls | permissive | — |
| mesh.labels | {} | — |
| mesh.annotations | {} | — |
observability#
| Key | Default | Description |
|---|---|---|
| observability | — | — |
| observability.enabled | true | — |
| observability.metrics | — | — |
| observability.metrics.enabled | true | — |
| observability.metrics.path | /metrics | — |
| observability.metrics.serviceMonitor | — | — |
| observability.metrics.serviceMonitor.enabled | false | — |
| observability.tracing | — | — |
| observability.tracing.enabled | false | — |
| observability.tracing.endpoint | "" | — |
| observability.logs | — | — |
| observability.logs.level | info | — |
| observability.audit | — | — |
| observability.audit.enabled | true | — |
| observability.audit.sink | — | — |
| observability.audit.sink.type | noop | — |
| observability.audit.sink.existingSecret | "" | — |
| observability.demo | — | — |
| observability.demo.enabled | false | Demo observability is intentionally opt-in. Production installs should usually connect AgentFleet to an existing metrics and audit platform. |
| observability.demo.prometheus | — | — |
| observability.demo.prometheus.enabled | true | — |
| observability.demo.prometheus.image | — | — |
| observability.demo.prometheus.image.repository | prom/prometheus | — |
| observability.demo.prometheus.image.tag | v3.5.0 | — |
| observability.demo.prometheus.image.digest | "" | — |
| observability.demo.prometheus.service | — | — |
| observability.demo.prometheus.service.type | ClusterIP | — |
| observability.demo.prometheus.service.port | 9090 | — |
| observability.demo.prometheus.resources | {} | — |
| observability.demo.prometheus.retention | 6h | — |
| observability.demo.grafana | — | — |
| observability.demo.grafana.enabled | true | — |
| observability.demo.grafana.image | — | — |
| observability.demo.grafana.image.repository | grafana/grafana | — |
| observability.demo.grafana.image.tag | 12.1.1 | — |
| observability.demo.grafana.image.digest | "" | — |
| observability.demo.grafana.service | — | — |
| observability.demo.grafana.service.type | ClusterIP | — |
| observability.demo.grafana.service.port | 3000 | — |
| observability.demo.grafana.adminUser | admin | — |
| observability.demo.grafana.adminPassword | agentfleet-demo | — |
| observability.demo.grafana.installClickHousePlugin | true | — |
| observability.demo.grafana.resources | {} | — |
| observability.demo.audit | — | — |
| observability.demo.audit.enabled | false | — |
| observability.demo.audit.clickhouse | — | — |
| observability.demo.audit.clickhouse.enabled | true | — |
| observability.demo.audit.clickhouse.image | — | — |
| observability.demo.audit.clickhouse.image.repository | clickhouse/clickhouse-server | — |
| observability.demo.audit.clickhouse.image.tag | "25.7" | — |
| observability.demo.audit.clickhouse.image.digest | "" | — |
| observability.demo.audit.clickhouse.service | — | — |
| observability.demo.audit.clickhouse.service.type | ClusterIP | — |
| observability.demo.audit.clickhouse.service.httpPort | 8123 | — |
| observability.demo.audit.clickhouse.service.nativePort | 9000 | — |
| observability.demo.audit.clickhouse.database | agentfleet_audit | — |
| observability.demo.audit.clickhouse.table | otel_logs | — |
| observability.demo.audit.clickhouse.username | agentfleet | — |
| observability.demo.audit.clickhouse.password | agentfleet-audit-change-me | — |
| observability.demo.audit.clickhouse.persistence | — | — |
| observability.demo.audit.clickhouse.persistence.enabled | true | — |
| observability.demo.audit.clickhouse.persistence.size | 5Gi | — |
| observability.demo.audit.clickhouse.persistence.storageClass | "" | — |
| observability.demo.audit.clickhouse.resources | {} | — |
| observability.demo.audit.collector | — | — |
| observability.demo.audit.collector.enabled | true | — |
| observability.demo.audit.collector.image | — | — |
| observability.demo.audit.collector.image.repository | otel/opentelemetry-collector-contrib | — |
| observability.demo.audit.collector.image.tag | 0.155.0 | — |
| observability.demo.audit.collector.image.digest | "" | — |
| observability.demo.audit.collector.resources | {} | — |
postgresql#
| Key | Default | Description |
|---|---|---|
| postgresql | — | — |
| postgresql.enabled | false | — |
| postgresql.external | — | — |
| postgresql.external.host | "" | — |
| postgresql.external.port | 5432 | — |
| postgresql.external.database | agentfleet | — |
| postgresql.external.existingSecret | "" | — |
| postgresql.bundled | — | — |
| postgresql.bundled.enabled | false | Dev/local only. Production profiles must use an externally managed PostgreSQL service and caller-managed DSN Secrets. |
| postgresql.bundled.replicaCount | 1 | — |
| postgresql.bundled.image | — | — |
| postgresql.bundled.image.repository | postgres | — |
| postgresql.bundled.image.tag | 16-alpine | — |
| postgresql.bundled.image.digest | "" | — |
| postgresql.bundled.service | — | — |
| postgresql.bundled.service.port | 5432 | — |
| postgresql.bundled.auth | — | — |
| postgresql.bundled.auth.username | agentfleet | — |
| postgresql.bundled.auth.database | agentfleet | — |
| postgresql.bundled.auth.password | "" | Empty generates or reuses a chart-managed Secret password. |
| postgresql.bundled.persistence | — | — |
| postgresql.bundled.persistence.enabled | true | — |
| postgresql.bundled.persistence.size | 1Gi | — |
| postgresql.bundled.persistence.storageClass | "" | — |
| postgresql.bundled.resources | {} | — |
| postgresql.bundled.podLabels | {} | — |
| postgresql.bundled.podAnnotations | {} | — |
redis#
| Key | Default | Description |
|---|---|---|
| redis | — | — |
| redis.enabled | false | — |
| redis.external | — | — |
| redis.external.host | "" | — |
| redis.external.port | 6379 | — |
| redis.external.existingSecret | "" | — |
eventBus#
| Key | Default | Description |
|---|---|---|
| eventBus | — | — |
| eventBus.enabled | false | — |
| eventBus.type | "" | — |
| eventBus.kafka | — | — |
| eventBus.kafka.brokers | [] | — |
| eventBus.kafka.existingSecret | "" | — |
| eventBus.nats | — | — |
| eventBus.nats.url | "" | — |
| eventBus.nats.existingSecret | "" | — |
integrations#
| Key | Default | Description |
|---|---|---|
| integrations | — | — |
| integrations.google | — | — |
| integrations.google.enabled | false | — |
| integrations.google.project | "" | — |
| integrations.google.region | "" | — |
| integrations.google.existingSecret | "" | — |
| integrations.databricks | — | — |
| integrations.databricks.enabled | false | — |
| integrations.databricks.workspaceURL | "" | — |
| integrations.databricks.existingSecret | "" | — |
| integrations.mcp | — | — |
| integrations.mcp.enabled | false | — |
| integrations.mcp.router | — | — |
| integrations.mcp.router.enabled | false | — |
| integrations.mcp.router.replicaCount | 1 | — |
| integrations.mcp.router.image | — | — |
| integrations.mcp.router.image.repository | ghcr.io/bitfid-inc/agentfleet-mcp-router | — |
| integrations.mcp.router.image.tag | v0.1.0 | — |
| integrations.mcp.router.image.digest | "" | — |
| integrations.mcp.router.service | — | — |
| integrations.mcp.router.service.type | ClusterIP | — |
| integrations.mcp.router.service.port | 8087 | — |
| integrations.mcp.router.metrics | — | — |
| integrations.mcp.router.metrics.enabled | true | — |
| integrations.mcp.router.metrics.path | "" | Empty inherits observability.metrics.path. |
| integrations.mcp.router.config | — | — |
| integrations.mcp.router.config.mode | "off" | — |
| integrations.mcp.router.config.discovery | — | — |
| integrations.mcp.router.config.discovery.refreshInterval | "5m" | — |
| integrations.mcp.router.config.call | — | — |
| integrations.mcp.router.config.call.timeout | "15s" | — |
| integrations.mcp.router.config.call.maxResponseBytes | 1048576 | — |
| integrations.mcp.router.resources | {} | — |
| integrations.mcp.router.podLabels | {} | — |
| integrations.mcp.router.podAnnotations | {} | — |
| integrations.mcp.servers | [] | — |
| integrations.a2a | — | — |
| integrations.a2a.enabled | false | — |
| integrations.a2a.agentCards | [] | — |
console#
| Key | Default | Description |
|---|---|---|
| console | — | — |
| console.enabled | false | — |
| console.replicaCount | 1 | — |
| console.image | — | — |
| console.image.repository | ghcr.io/bitfid-inc/agentfleet-console | — |
| console.image.tag | v0.1.0 | — |
| console.image.digest | "" | — |
| console.service | — | — |
| console.service.type | ClusterIP | — |
| console.service.port | 8089 | — |
| console.serviceAccount | — | — |
| console.serviceAccount.create | true | — |
| console.serviceAccount.name | "" | — |
| console.serviceAccount.annotations | {} | — |
| console.usage | — | Usage Center is an optional tenant-scoped projection over model.call audit evidence. It does not store prompts or model replies. |
| console.usage.enabled | false | — |
| console.usage.clickhouse | — | — |
| console.usage.clickhouse.url | "" | — |
| console.usage.clickhouse.database | agentfleet_audit | — |
| console.usage.clickhouse.table | otel_logs | — |
| console.usage.clickhouse.username | default | — |
| console.usage.clickhouse.existingSecret | "" | — |
| console.usage.clickhouse.passwordKey | password | — |
| console.usage.clickhouse.allowInsecureHTTP | false | — |
| console.usage.queryTimeout | "5s" | — |
| console.usage.defaultWindow | "168h" | — |
| console.usage.maximumWindow | "2160h" | — |
| console.config | — | — |
| console.config.registryURL | "" | — |
| console.config.gatewayURL | "" | — |
| console.config.schedulerURL | "" | — |
| console.config.policyURL | "" | — |
| console.config.contextURL | "" | — |
| console.config.modelRouterURL | "" | — |
| console.config.mcpRouterURL | "" | — |
| console.config.a2aCardBaseURL | "https://agentfleet.example.invalid/a2a/v1" | — |
| console.config.defaultTenant | "" | — |
| console.config.auth | — | — |
| console.config.auth.mode | "off" | — |
| console.config.auth.requireTenant | false | — |
| console.config.auth.requireActor | false | — |
| console.config.auth.headerDev | — | — |
| console.config.auth.headerDev.tenantHeader | "X-AgentFleet-Tenant" | — |
| console.config.auth.headerDev.actorHeader | "X-AgentFleet-Actor" | — |
| console.config.auth.headerDev.actorTypeHeader | "X-AgentFleet-Actor-Type" | — |
| console.config.auth.oidc | — | — |
| console.config.auth.oidc.issuerURL | "" | — |
| console.config.auth.oidc.clientID | "" | — |
| console.config.auth.oidc.existingSecret | "" | — |
| console.config.auth.oidc.clientSecretKey | client-secret | — |
| console.config.auth.oidc.publicBaseURL | "" | — |
| console.config.auth.oidc.scopes | — | — |
| console.config.auth.oidc.tenantClaim | tenant_id | — |
| console.config.auth.oidc.groupsClaim | groups | — |
| console.config.auth.oidc.allowedAlgorithms | — | — |
| console.config.auth.oidc.allowInsecureHTTP | false | — |
| console.config.auth.oidc.discoveryTimeout | "10s" | — |
| console.config.auth.oidc.session | — | — |
| console.config.auth.oidc.session.store | memory | — |
| console.config.auth.oidc.session.cookieName | agentfleet_console_session | — |
| console.config.auth.oidc.session.secureCookie | true | — |
| console.config.auth.oidc.session.sameSite | lax | — |
| console.config.auth.oidc.session.ttl | "8h" | — |
| console.config.auth.oidc.session.loginStateTTL | "10m" | — |
| console.config.auth.oidc.session.maxSessions | 10000 | — |
| console.config.auth.oidc.session.maxLoginAttempts | 1000 | — |
| console.config.auth.oidc.session.postgres | — | — |
| console.config.auth.oidc.session.postgres.existingSecret | "" | — |
| console.config.auth.oidc.session.postgres.dsnKey | dsn | — |
| console.config.auth.oidc.session.postgres.autoMigrate | true | — |
| console.config.auth.oidc.session.postgres.sweepInterval | "5m" | — |
| console.config.tenantAuthz | — | — |
| console.config.tenantAuthz.mode | "off" | — |
| console.config.tenantAuthz.readRoles | — | — |
| console.config.tenantAuthz.static | — | — |
| console.config.tenantAuthz.static.memberships | [] | — |
| console.config.dependencyTimeout | "2s" | — |
| console.inventory | — | — |
| console.inventory.kubernetes | — | — |
| console.inventory.kubernetes.enabled | true | — |
| console.inventory.kubernetes.namespace | "" | — |
| console.inventory.kubernetes.kubeconfig | "" | — |
| console.inventory.kubernetes.context | "" | — |
| console.inventory.kubernetes.fallbackToFiles | true | — |
| console.catalog | — | — |
| console.catalog.routes | [] | — |
| console.catalog.policies | [] | — |
| console.catalog.useMCPRouterConfig | true | — |
| console.demoCatalog | — | — |
| console.demoCatalog.enabled | false | — |
| console.resources | {} | — |
| console.podLabels | {} | — |
| console.podAnnotations | {} | — |
profiles#
| Key | Default | Description |
|---|---|---|
| profiles | — | — |
| profiles.demo | — | — |
| profiles.demo.enabled | false | — |
| profiles.mesh | — | — |
| profiles.mesh.enabled | false | — |
| profiles.observability | — | — |
| profiles.observability.enabled | false | — |
| profiles.production | — | — |
| profiles.production.enabled | false | — |