Enterprise early access is open. Request access

Docs Reference Helm values

About this reference#

Generated from the values schema included with the release chart. Defaults and descriptions come straight from the chart, so this page cannot describe a value the chart does not ship.

Override any key with --set or a values file. See Profiles for the curated combinations.

nameOverride#

1 keys

KeyDefaultDescription
nameOverride "" —

fullnameOverride#

1 keys

KeyDefaultDescription
fullnameOverride "" —

global#

19 keys

KeyDefaultDescription
global — —
global.imageRegistry "" —
global.imagePullPolicy IfNotPresent —
global.namespaceOverride "" —
global.tenant default —
global.provider local —
global.region local —
global.clusterName local —
global.labels {} —
global.annotations {} —
global.imagePullSecrets [] —
global.automountServiceAccountToken true —
global.podSecurityContext {} —
global.securityContext {} —
global.nodeSelector {} —
global.tolerations [] —
global.affinity {} —
global.topologySpreadConstraints [] —
global.priorityClassName "" —

rbac#

2 keys

KeyDefaultDescription
rbac — —
rbac.create true —

serviceAccount#

4 keys

KeyDefaultDescription
serviceAccount — —
serviceAccount.create true —
serviceAccount.name "" —
serviceAccount.annotations {} —

migrations#

24 keys

KeyDefaultDescription
migrations — Production schema ownership is separated from long-running services. Enable this hook only with PostgreSQL stores whose autoMigrate setting is false.
migrations.enabled false —
migrations.image — —
migrations.image.repository ghcr.io/bitfid-inc/agentfleet-db-migrate —
migrations.image.tag v0.1.0 —
migrations.timeout "2m" —
migrations.backoffLimit 1 —
migrations.ttlSecondsAfterFinished 300 —
migrations.secrets — Empty existingSecret values fall back to the component runtime Secret. Production platforms should provide separate schema-owner credentials.
migrations.secrets.registry — —
migrations.secrets.registry.existingSecret "" —
migrations.secrets.registry.dsnKey dsn —
migrations.secrets.context — —
migrations.secrets.context.existingSecret "" —
migrations.secrets.context.dsnKey dsn —
migrations.secrets.approval — —
migrations.secrets.approval.existingSecret "" —
migrations.secrets.approval.dsnKey dsn —
migrations.secrets.console — —
migrations.secrets.console.existingSecret "" —
migrations.secrets.console.dsnKey dsn —
migrations.resources {} —
migrations.podLabels {} —
migrations.podAnnotations {} —

podDisruptionBudget#

4 keys

KeyDefaultDescription
podDisruptionBudget — —
podDisruptionBudget.enabled false —
podDisruptionBudget.minAvailable 1 —
podDisruptionBudget.maxUnavailable "" —

networkPolicy#

3 keys

KeyDefaultDescription
networkPolicy — —
networkPolicy.enabled false —
networkPolicy.additionalIngressFrom [] Additional ingress peers can be added for an external gateway or metrics collector.

operator#

32 keys

KeyDefaultDescription
operator — —
operator.enabled true —
operator.replicaCount 1 —
operator.image — —
operator.image.repository ghcr.io/bitfid-inc/agentfleet-operator —
operator.image.tag v0.1.0 —
operator.image.digest "" —
operator.service — —
operator.service.type ClusterIP —
operator.service.metricsPort 8080 —
operator.metrics — —
operator.metrics.port 8080 —
operator.probes — —
operator.probes.port 8081 —
operator.leaderElection — —
operator.leaderElection.enabled false —
operator.registry — —
operator.registry.enabled true —
operator.registry.url "" —
operator.protection — Settings for agents in protected namespaces, which a platform administrator marks with the label agentfleet.io/protection=managed. Each such agent runs under its own ServiceAccount with a Model Router token, a hardened pod, and only the Secrets listed in the namespace annotation agentfleet.io/allowed-secrets. Other namespaces are unaffected.
operator.protection.modelRouterURL "" Injected into protected agents as AGENTFLEET_MODEL_ROUTER_URL. Defaults to the in-chart Model Router when it is enabled.
operator.protection.runAsUser 65532 UID for protected agent pods. 0 relies on a numeric USER in the image.
operator.protection.enforcementProbe — Optional Helm hook that proves the cluster actually enforces an egress deny policy. Enable this wherever protected-path claims are made.
operator.protection.enforcementProbe.enabled false —
operator.protection.enforcementProbe.image — —
operator.protection.enforcementProbe.image.repository busybox —
operator.protection.enforcementProbe.image.tag "1.37.0" —
operator.protection.enforcementProbe.image.digest "" —
operator.protection.enforcementProbe.timeoutSeconds 10 —
operator.resources {} —
operator.podLabels {} —
operator.podAnnotations {} —

approval#

57 keys

KeyDefaultDescription
approval — Approval is optional because not every routing policy requires a human gate. Credentials are always read from caller-managed Secrets, never chart values.
approval.enabled false —
approval.replicaCount 1 —
approval.image — —
approval.image.repository ghcr.io/bitfid-inc/agentfleet-approval —
approval.image.tag v0.1.0 —
approval.image.digest "" —
approval.service — —
approval.service.type ClusterIP —
approval.service.port 8088 —
approval.external — —
approval.external.url "" Set a remote Approval base URL instead of deploying approval.enabled=true.
approval.external.allowInsecureHTTP false —
approval.clients — —
approval.clients.gateway — —
approval.clients.gateway.enabled true —
approval.clients.modelRouter — —
approval.clients.modelRouter.enabled true —
approval.clients.console — Approver access is opt-in because it requires authenticated tenant RBAC.
approval.clients.console.enabled false —
approval.serviceAccount — —
approval.serviceAccount.create true —
approval.serviceAccount.name "" —
approval.serviceAccount.annotations {} —
approval.serviceAccount.automountServiceAccountToken false Enable only when the selected workload-identity mechanism needs a projected token.
approval.storage — —
approval.storage.type memory —
approval.storage.postgres — —
approval.storage.postgres.existingSecret "" —
approval.storage.postgres.dsnKey dsn —
approval.storage.postgres.autoMigrate true —
approval.ttl — —
approval.ttl.default "1h" —
approval.ttl.maximum "720h" —
approval.ttl.claim "5m" —
approval.allowSelfApproval false —
approval.auth — —
approval.auth.mode token —
approval.auth.existingSecret "" —
approval.auth.workflowTokenKey workflow-token —
approval.auth.approverTokenKey approver-token —
approval.audit — —
approval.audit.mode async —
approval.audit.sinkType stdout —
approval.notification — —
approval.notification.webhook — —
approval.notification.webhook.url "" —
approval.notification.webhook.existingSecret "" —
approval.notification.webhook.tokenKey token —
approval.notification.webhook.timeout "5s" —
approval.sweeper — —
approval.sweeper.interval "30s" —
approval.sweeper.batchSize 100 —
approval.terminationGracePeriodSeconds 30 —
approval.resources {} —
approval.podLabels {} —
approval.podAnnotations {} —

gateway#

70 keys

KeyDefaultDescription
gateway — —
gateway.enabled true —
gateway.replicaCount 1 —
gateway.image — —
gateway.image.repository ghcr.io/bitfid-inc/agentfleet-gateway —
gateway.image.tag v0.1.0 —
gateway.image.digest "" —
gateway.service — —
gateway.service.type ClusterIP —
gateway.service.port 8080 —
gateway.config — —
gateway.config.metrics — —
gateway.config.metrics.enabled true —
gateway.config.metrics.path "" Empty inherits observability.metrics.path.
gateway.config.registryURL "" —
gateway.config.scheduler — —
gateway.config.scheduler.enabled false —
gateway.config.scheduler.url "" —
gateway.config.scheduler.failurePolicy fallback —
gateway.config.policy — —
gateway.config.policy.mode "off" —
gateway.config.policy.url "" —
gateway.config.policy.failurePolicy fail —
gateway.config.context — —
gateway.config.context.mode "off" —
gateway.config.context.url "" —
gateway.config.context.appendFailurePolicy continue —
gateway.config.audit — —
gateway.config.audit.mode "off" —
gateway.config.audit.sinkType "noop" —
gateway.config.a2a — —
gateway.config.a2a.delegationEnabled false —
gateway.config.a2a.delegationTimeout "10s" —
gateway.config.tenantAuthz — —
gateway.config.tenantAuthz.mode "off" —
gateway.config.tenantAuthz.source "static_config" —
gateway.config.tenantAuthz.static — —
gateway.config.tenantAuthz.static.memberships [] —
gateway.config.tenantAuthz.idpGroups — —
gateway.config.tenantAuthz.idpGroups.enabled false —
gateway.config.tenantAuthz.idpGroups.groupClaim "groups" —
gateway.config.tenantAuthz.idpGroups.stringClaimDelimiter " " —
gateway.config.tenantAuthz.idpGroups.includeMatchedGroups false —
gateway.config.tenantAuthz.idpGroups.mappings [] —
gateway.config.auth — —
gateway.config.auth.mode "off" —
gateway.config.auth.diagnosticsEnabled true —
gateway.config.auth.requireTenant false —
gateway.config.auth.requireActor false —
gateway.config.auth.headerDev — —
gateway.config.auth.headerDev.tenantHeader "X-AgentFleet-Tenant" —
gateway.config.auth.headerDev.actorHeader "X-AgentFleet-Actor" —
gateway.config.auth.headerDev.actorTypeHeader "X-AgentFleet-Actor-Type" —
gateway.config.auth.headerDev.allowBodyFallback true —
gateway.config.auth.oidcJwt — —
gateway.config.auth.oidcJwt.issuer "" —
gateway.config.auth.oidcJwt.audience [] —
gateway.config.auth.oidcJwt.jwksURL "" —
gateway.config.auth.oidcJwt.allowInsecureHTTP false —
gateway.config.auth.oidcJwt.tenantClaim "tenant_id" —
gateway.config.auth.oidcJwt.actorClaim "sub" —
gateway.config.auth.oidcJwt.actorTypeClaim "actor_type" —
gateway.config.auth.oidcJwt.allowedAlgorithms — —
gateway.config.auth.oidcJwt.clockSkew "60s" —
gateway.config.auth.oidcJwt.jwksCacheTTL "5m" —
gateway.config.auth.oidcJwt.jwksRefreshTimeout "5s" —
gateway.config.auth.oidcJwt.jwksRefreshMinInterval "60s" —
gateway.resources {} —
gateway.podLabels {} —
gateway.podAnnotations {} —

registry#

19 keys

KeyDefaultDescription
registry — —
registry.enabled true —
registry.replicaCount 1 —
registry.image — —
registry.image.repository ghcr.io/bitfid-inc/agentfleet-registry —
registry.image.tag v0.1.0 —
registry.image.digest "" —
registry.service — —
registry.service.type ClusterIP —
registry.service.port 8082 —
registry.storage — —
registry.storage.type memory —
registry.storage.postgres — —
registry.storage.postgres.existingSecret "" —
registry.storage.postgres.dsnKey dsn —
registry.storage.postgres.autoMigrate true —
registry.resources {} —
registry.podLabels {} —
registry.podAnnotations {} —

scheduler#

13 keys

KeyDefaultDescription
scheduler — —
scheduler.enabled true —
scheduler.replicaCount 1 —
scheduler.image — —
scheduler.image.repository ghcr.io/bitfid-inc/agentfleet-scheduler —
scheduler.image.tag v0.1.0 —
scheduler.image.digest "" —
scheduler.service — —
scheduler.service.type ClusterIP —
scheduler.service.port 8083 —
scheduler.resources {} —
scheduler.podLabels {} —
scheduler.podAnnotations {} —

policy#

15 keys

KeyDefaultDescription
policy — —
policy.enabled true —
policy.replicaCount 1 —
policy.image — —
policy.image.repository ghcr.io/bitfid-inc/agentfleet-policy —
policy.image.tag v0.1.0 —
policy.image.digest "" —
policy.service — —
policy.service.type ClusterIP —
policy.service.port 8084 —
policy.mode enforce —
policy.rules {} Operator-authored governance rules, rendered into the chart ConfigMap and mounted read-only. Leaving this empty means the policy service denies every request, so gateway.config.policy.mode=enforce needs rules here before any traffic is allowed through. Unknown keys fail startup rather than being ignored, so a typo cannot silently leave a restriction unenforced. Note: an allow list is only checked when the request carries that field. A request with no tenant is not matched by allowedTenants; defaultDecision is what stops it. Keep defaultDecision set to deny. rules: defaultDecision: deny allowedTenants: - enterprise-it allowedCapabilities: - it-triage
policy.resources {} —
policy.podLabels {} —
policy.podAnnotations {} —

guard#

26 keys

KeyDefaultDescription
guard — Optional local guardrail service. Disabled by default. When enabled it runs the deterministic secret and encoded-content detectors configured below; no model traffic passes through it until the Model Router is configured to call it.
guard.enabled false —
guard.replicaCount 1 —
guard.image — —
guard.image.repository ghcr.io/bitfid-inc/agentfleet-guard —
guard.image.tag v0.1.0 —
guard.image.digest "" —
guard.service — —
guard.service.type ClusterIP —
guard.service.port 8090 —
guard.serviceAccount — —
guard.serviceAccount.create true —
guard.serviceAccount.name "" —
guard.serviceAccount.annotations {} —
guard.serviceAccount.automountServiceAccountToken false —
guard.auth — Callers authenticate with a shared bearer token read from existingSecret. mode=off is for local development only and is rejected by the secure production profile.
guard.auth.mode token —
guard.auth.existingSecret "" —
guard.auth.tokenKey token —
guard.config — Detector manifests and tenant profiles, rendered into a GuardConfig file and mounted read-only. Guard refuses to start without at least one profile, and unknown keys fail startup. A profile's namespace must be the namespace of the agents it covers, and its mode (off, audit, or enforce) decides whether findings change a request. Start new profiles in audit. See examples/guard/values-secret-detection.yaml for a complete, tested example.
guard.config.detectors [] —
guard.config.profiles [] —
guard.terminationGracePeriodSeconds 30 —
guard.resources {} —
guard.podLabels {} —
guard.podAnnotations {} —

modelRouter#

89 keys

KeyDefaultDescription
modelRouter — —
modelRouter.enabled true —
modelRouter.replicaCount 1 —
modelRouter.image — —
modelRouter.image.repository ghcr.io/bitfid-inc/agentfleet-model-router —
modelRouter.image.tag v0.1.0 —
modelRouter.image.digest "" —
modelRouter.service — —
modelRouter.service.type ClusterIP —
modelRouter.service.port 8085 —
modelRouter.serviceAccount — —
modelRouter.serviceAccount.create true —
modelRouter.serviceAccount.name "" —
modelRouter.serviceAccount.annotations {} —
modelRouter.serviceAccount.automountServiceAccountToken false Enable only when provider or Kubernetes workload identity needs a projected token.
modelRouter.credentials — —
modelRouter.credentials.mode static static uses installation-wide Secret references; kubernetes resolves by tenant.
modelRouter.credentials.kubernetes — —
modelRouter.credentials.kubernetes.secretNamespace "" Empty uses the Helm release namespace.
modelRouter.credentials.kubernetes.cacheTTL "5m" —
modelRouter.credentials.kubernetes.mappings [] —
modelRouter.config — —
modelRouter.config.policyURL "" —
modelRouter.security — —
modelRouter.security.auth — —
modelRouter.security.auth.mode "off" —
modelRouter.security.auth.existingSecret "" —
modelRouter.security.auth.tokenKey token —
modelRouter.security.allowPolicyOff true —
modelRouter.security.allowUnauthenticatedPaidExecution false Explicit escape hatch for controlled local paid-provider fixtures.
modelRouter.security.limits — —
modelRouter.security.limits.requestsPerMinute 60 —
modelRouter.security.limits.modelCallsPerMinute 180 —
modelRouter.security.limits.maxConcurrentPerTenant 8 —
modelRouter.security.limits.maxModelsPerRequest 4 —
modelRouter.security.limits.maxOutputTokens 8192 —
modelRouter.security.limits.maxTrackedTenants 1000 —
modelRouter.metrics — —
modelRouter.metrics.enabled true —
modelRouter.metrics.path "" Empty inherits observability.metrics.path.
modelRouter.audit — —
modelRouter.audit.mode async off, async, or sync_required. sync_required fails the request if audit delivery fails.
modelRouter.audit.sinkType stdout —
modelRouter.comparison — —
modelRouter.comparison.enabled true —
modelRouter.comparison.contextURL "" Empty uses the in-chart Context service when context.enabled=true.
modelRouter.comparison.storageRequired false —
modelRouter.pricing — —
modelRouter.pricing.enabled false Rates are operator-managed so provider price changes do not require a release.
modelRouter.pricing.rates [] —
modelRouter.guard — Guard inspection of model input and output. Each binding selects the Guard profile for one tenant's agents in one namespace; callers cannot choose a profile. The profile's own mode decides whether findings change requests. failurePolicy (fail_closed or fail_open) decides what happens when Guard cannot answer. streaming (reject or uninspected) decides whether covered agents may stream, since streamed replies cannot be inspected first. The secure production profile requires fail_closed and reject.
modelRouter.guard.enabled false —
modelRouter.guard.url "" Defaults to the in-chart Guard Service when guard.enabled=true.
modelRouter.guard.existingSecret "" Token Secret for calling Guard. Defaults to guard.auth.existingSecret and guard.auth.tokenKey.
modelRouter.guard.tokenKey "" —
modelRouter.guard.bindings [] —
modelRouter.workloadIdentity — Accept agent ServiceAccount tokens from protected namespaces. The Model Router verifies each token with the Kubernetes TokenReview API and takes tenant and agent from the Registry, rejecting requests that claim different values. The shared token keeps working for Console and Gateway. Requires modelRouter.serviceAccount.automountServiceAccountToken=true so the Model Router can call TokenReview.
modelRouter.workloadIdentity.enabled false —
modelRouter.workloadIdentity.audience agentfleet-model-router —
modelRouter.workloadIdentity.cacheTTL "30s" How long a TokenReview result for an agent token is reused.
modelRouter.workloadIdentity.registryRefresh "5s" How long an agent's Registry tenant and phase are reused. This bounds how quickly a suspension reaches the Model Router; keep it well under 30s and no longer than cacheTTL.
modelRouter.workloadIdentity.registryURL "" Defaults to the in-chart Registry.
modelRouter.providers — —
modelRouter.providers.mock — —
modelRouter.providers.mock.enabled true —
modelRouter.providers.openai — —
modelRouter.providers.openai.enabled false —
modelRouter.providers.openai.existingSecret "" —
modelRouter.providers.openai.secretKey api-key —
modelRouter.providers.openai.baseURL "" —
modelRouter.providers.openai.organization "" —
modelRouter.providers.openai.project "" —
modelRouter.providers.openai.timeout "30s" —
modelRouter.providers.openai.allowInsecureHTTP false —
modelRouter.providers.anthropic — —
modelRouter.providers.anthropic.enabled false —
modelRouter.providers.anthropic.existingSecret "" —
modelRouter.providers.anthropic.secretKey api-key —
modelRouter.providers.anthropic.baseURL "" —
modelRouter.providers.anthropic.version "2023-06-01" —
modelRouter.providers.anthropic.timeout "30s" —
modelRouter.providers.anthropic.allowInsecureHTTP false —
modelRouter.providers.bedrock — —
modelRouter.providers.bedrock.enabled false —
modelRouter.providers.bedrock.region "" —
modelRouter.providers.bedrock.timeout "30s" —
modelRouter.resources {} —
modelRouter.podLabels {} —
modelRouter.podAnnotations {} —

context#

34 keys

KeyDefaultDescription
context — —
context.enabled false —
context.replicaCount 1 —
context.image — —
context.image.repository ghcr.io/bitfid-inc/agentfleet-context —
context.image.tag v0.1.0 —
context.image.digest "" —
context.service — —
context.service.type ClusterIP —
context.service.port 8086 —
context.mode "off" —
context.security — —
context.security.auth — —
context.security.auth.mode "off" —
context.security.auth.existingSecret "" —
context.security.auth.tokenKey token —
context.storage — —
context.storage.type memory —
context.storage.postgres — —
context.storage.postgres.existingSecret "" —
context.storage.postgres.dsnKey dsn —
context.storage.postgres.autoMigrate true —
context.retention — —
context.retention.days 7 —
context.cleanupInterval "5m" —
context.memory — —
context.memory.maxConversations 1000 —
context.memory.maxConversationsPerTenant 100 —
context.memory.maxTurnsPerConversation 100 —
context.memory.maxComparisonsPerConversation 20 —
context.memory.maxBytesPerConversation 262144 —
context.resources {} —
context.podLabels {} —
context.podAnnotations {} —

demoAgents#

48 keys

KeyDefaultDescription
demoAgents — —
demoAgents.enabled false —
demoAgents.namespace agentfleet-demo —
demoAgents.refund — —
demoAgents.refund.enabled true —
demoAgents.refund.replicaCount 1 —
demoAgents.refund.image — —
demoAgents.refund.image.repository ghcr.io/bitfid-inc/examples/refund-agent —
demoAgents.refund.image.tag v0.1.0 —
demoAgents.refund.image.digest "" —
demoAgents.refund.service — —
demoAgents.refund.service.port 8080 —
demoAgents.order — —
demoAgents.order.enabled true —
demoAgents.order.replicaCount 1 —
demoAgents.order.image — —
demoAgents.order.image.repository ghcr.io/bitfid-inc/examples/order-agent —
demoAgents.order.image.tag v0.1.0 —
demoAgents.order.image.digest "" —
demoAgents.order.service — —
demoAgents.order.service.port 8080 —
demoAgents.it — —
demoAgents.it.enabled true —
demoAgents.it.replicaCount 1 —
demoAgents.it.image — —
demoAgents.it.image.repository ghcr.io/bitfid-inc/examples/it-support-agent —
demoAgents.it.image.tag v0.1.0 —
demoAgents.it.image.digest "" —
demoAgents.it.service — —
demoAgents.it.service.port 8080 —
demoAgents.customerProfileMCP — —
demoAgents.customerProfileMCP.enabled false —
demoAgents.customerProfileMCP.replicaCount 1 —
demoAgents.customerProfileMCP.image — —
demoAgents.customerProfileMCP.image.repository ghcr.io/bitfid-inc/examples/customer-profile-mcp —
demoAgents.customerProfileMCP.image.tag v0.1.0 —
demoAgents.customerProfileMCP.image.digest "" —
demoAgents.customerProfileMCP.service — —
demoAgents.customerProfileMCP.service.port 8088 —
demoAgents.a2aPeer — —
demoAgents.a2aPeer.enabled false —
demoAgents.a2aPeer.replicaCount 1 —
demoAgents.a2aPeer.image — —
demoAgents.a2aPeer.image.repository ghcr.io/bitfid-inc/examples/a2a-peer —
demoAgents.a2aPeer.image.tag v0.1.0 —
demoAgents.a2aPeer.image.digest "" —
demoAgents.a2aPeer.service — —
demoAgents.a2aPeer.service.port 18090 —

mesh#

7 keys

KeyDefaultDescription
mesh — —
mesh.enabled false —
mesh.provider istio —
mesh.mode sidecar —
mesh.mtls permissive —
mesh.labels {} —
mesh.annotations {} —

observability#

71 keys

KeyDefaultDescription
observability — —
observability.enabled true —
observability.metrics — —
observability.metrics.enabled true —
observability.metrics.path /metrics —
observability.metrics.serviceMonitor — —
observability.metrics.serviceMonitor.enabled false —
observability.tracing — —
observability.tracing.enabled false —
observability.tracing.endpoint "" —
observability.logs — —
observability.logs.level info —
observability.audit — —
observability.audit.enabled true —
observability.audit.sink — —
observability.audit.sink.type noop —
observability.audit.sink.existingSecret "" —
observability.demo — —
observability.demo.enabled false Demo observability is intentionally opt-in. Production installs should usually connect AgentFleet to an existing metrics and audit platform.
observability.demo.prometheus — —
observability.demo.prometheus.enabled true —
observability.demo.prometheus.image — —
observability.demo.prometheus.image.repository prom/prometheus —
observability.demo.prometheus.image.tag v3.5.0 —
observability.demo.prometheus.image.digest "" —
observability.demo.prometheus.service — —
observability.demo.prometheus.service.type ClusterIP —
observability.demo.prometheus.service.port 9090 —
observability.demo.prometheus.resources {} —
observability.demo.prometheus.retention 6h —
observability.demo.grafana — —
observability.demo.grafana.enabled true —
observability.demo.grafana.image — —
observability.demo.grafana.image.repository grafana/grafana —
observability.demo.grafana.image.tag 12.1.1 —
observability.demo.grafana.image.digest "" —
observability.demo.grafana.service — —
observability.demo.grafana.service.type ClusterIP —
observability.demo.grafana.service.port 3000 —
observability.demo.grafana.adminUser admin —
observability.demo.grafana.adminPassword agentfleet-demo —
observability.demo.grafana.installClickHousePlugin true —
observability.demo.grafana.resources {} —
observability.demo.audit — —
observability.demo.audit.enabled false —
observability.demo.audit.clickhouse — —
observability.demo.audit.clickhouse.enabled true —
observability.demo.audit.clickhouse.image — —
observability.demo.audit.clickhouse.image.repository clickhouse/clickhouse-server —
observability.demo.audit.clickhouse.image.tag "25.7" —
observability.demo.audit.clickhouse.image.digest "" —
observability.demo.audit.clickhouse.service — —
observability.demo.audit.clickhouse.service.type ClusterIP —
observability.demo.audit.clickhouse.service.httpPort 8123 —
observability.demo.audit.clickhouse.service.nativePort 9000 —
observability.demo.audit.clickhouse.database agentfleet_audit —
observability.demo.audit.clickhouse.table otel_logs —
observability.demo.audit.clickhouse.username agentfleet —
observability.demo.audit.clickhouse.password agentfleet-audit-change-me —
observability.demo.audit.clickhouse.persistence — —
observability.demo.audit.clickhouse.persistence.enabled true —
observability.demo.audit.clickhouse.persistence.size 5Gi —
observability.demo.audit.clickhouse.persistence.storageClass "" —
observability.demo.audit.clickhouse.resources {} —
observability.demo.audit.collector — —
observability.demo.audit.collector.enabled true —
observability.demo.audit.collector.image — —
observability.demo.audit.collector.image.repository otel/opentelemetry-collector-contrib —
observability.demo.audit.collector.image.tag 0.155.0 —
observability.demo.audit.collector.image.digest "" —
observability.demo.audit.collector.resources {} —

postgresql#

27 keys

KeyDefaultDescription
postgresql — —
postgresql.enabled false —
postgresql.external — —
postgresql.external.host "" —
postgresql.external.port 5432 —
postgresql.external.database agentfleet —
postgresql.external.existingSecret "" —
postgresql.bundled — —
postgresql.bundled.enabled false Dev/local only. Production profiles must use an externally managed PostgreSQL service and caller-managed DSN Secrets.
postgresql.bundled.replicaCount 1 —
postgresql.bundled.image — —
postgresql.bundled.image.repository postgres —
postgresql.bundled.image.tag 16-alpine —
postgresql.bundled.image.digest "" —
postgresql.bundled.service — —
postgresql.bundled.service.port 5432 —
postgresql.bundled.auth — —
postgresql.bundled.auth.username agentfleet —
postgresql.bundled.auth.database agentfleet —
postgresql.bundled.auth.password "" Empty generates or reuses a chart-managed Secret password.
postgresql.bundled.persistence — —
postgresql.bundled.persistence.enabled true —
postgresql.bundled.persistence.size 1Gi —
postgresql.bundled.persistence.storageClass "" —
postgresql.bundled.resources {} —
postgresql.bundled.podLabels {} —
postgresql.bundled.podAnnotations {} —

redis#

6 keys

KeyDefaultDescription
redis — —
redis.enabled false —
redis.external — —
redis.external.host "" —
redis.external.port 6379 —
redis.external.existingSecret "" —

eventBus#

9 keys

KeyDefaultDescription
eventBus — —
eventBus.enabled false —
eventBus.type "" —
eventBus.kafka — —
eventBus.kafka.brokers [] —
eventBus.kafka.existingSecret "" —
eventBus.nats — —
eventBus.nats.url "" —
eventBus.nats.existingSecret "" —

integrations#

39 keys

KeyDefaultDescription
integrations — —
integrations.google — —
integrations.google.enabled false —
integrations.google.project "" —
integrations.google.region "" —
integrations.google.existingSecret "" —
integrations.databricks — —
integrations.databricks.enabled false —
integrations.databricks.workspaceURL "" —
integrations.databricks.existingSecret "" —
integrations.mcp — —
integrations.mcp.enabled false —
integrations.mcp.router — —
integrations.mcp.router.enabled false —
integrations.mcp.router.replicaCount 1 —
integrations.mcp.router.image — —
integrations.mcp.router.image.repository ghcr.io/bitfid-inc/agentfleet-mcp-router —
integrations.mcp.router.image.tag v0.1.0 —
integrations.mcp.router.image.digest "" —
integrations.mcp.router.service — —
integrations.mcp.router.service.type ClusterIP —
integrations.mcp.router.service.port 8087 —
integrations.mcp.router.metrics — —
integrations.mcp.router.metrics.enabled true —
integrations.mcp.router.metrics.path "" Empty inherits observability.metrics.path.
integrations.mcp.router.config — —
integrations.mcp.router.config.mode "off" —
integrations.mcp.router.config.discovery — —
integrations.mcp.router.config.discovery.refreshInterval "5m" —
integrations.mcp.router.config.call — —
integrations.mcp.router.config.call.timeout "15s" —
integrations.mcp.router.config.call.maxResponseBytes 1048576 —
integrations.mcp.router.resources {} —
integrations.mcp.router.podLabels {} —
integrations.mcp.router.podAnnotations {} —
integrations.mcp.servers [] —
integrations.a2a — —
integrations.a2a.enabled false —
integrations.a2a.agentCards [] —

console#

93 keys

KeyDefaultDescription
console — —
console.enabled false —
console.replicaCount 1 —
console.image — —
console.image.repository ghcr.io/bitfid-inc/agentfleet-console —
console.image.tag v0.1.0 —
console.image.digest "" —
console.service — —
console.service.type ClusterIP —
console.service.port 8089 —
console.serviceAccount — —
console.serviceAccount.create true —
console.serviceAccount.name "" —
console.serviceAccount.annotations {} —
console.usage — Usage Center is an optional tenant-scoped projection over model.call audit evidence. It does not store prompts or model replies.
console.usage.enabled false —
console.usage.clickhouse — —
console.usage.clickhouse.url "" —
console.usage.clickhouse.database agentfleet_audit —
console.usage.clickhouse.table otel_logs —
console.usage.clickhouse.username default —
console.usage.clickhouse.existingSecret "" —
console.usage.clickhouse.passwordKey password —
console.usage.clickhouse.allowInsecureHTTP false —
console.usage.queryTimeout "5s" —
console.usage.defaultWindow "168h" —
console.usage.maximumWindow "2160h" —
console.config — —
console.config.registryURL "" —
console.config.gatewayURL "" —
console.config.schedulerURL "" —
console.config.policyURL "" —
console.config.contextURL "" —
console.config.modelRouterURL "" —
console.config.mcpRouterURL "" —
console.config.a2aCardBaseURL "https://agentfleet.example.invalid/a2a/v1" —
console.config.defaultTenant "" —
console.config.auth — —
console.config.auth.mode "off" —
console.config.auth.requireTenant false —
console.config.auth.requireActor false —
console.config.auth.headerDev — —
console.config.auth.headerDev.tenantHeader "X-AgentFleet-Tenant" —
console.config.auth.headerDev.actorHeader "X-AgentFleet-Actor" —
console.config.auth.headerDev.actorTypeHeader "X-AgentFleet-Actor-Type" —
console.config.auth.oidc — —
console.config.auth.oidc.issuerURL "" —
console.config.auth.oidc.clientID "" —
console.config.auth.oidc.existingSecret "" —
console.config.auth.oidc.clientSecretKey client-secret —
console.config.auth.oidc.publicBaseURL "" —
console.config.auth.oidc.scopes — —
console.config.auth.oidc.tenantClaim tenant_id —
console.config.auth.oidc.groupsClaim groups —
console.config.auth.oidc.allowedAlgorithms — —
console.config.auth.oidc.allowInsecureHTTP false —
console.config.auth.oidc.discoveryTimeout "10s" —
console.config.auth.oidc.session — —
console.config.auth.oidc.session.store memory —
console.config.auth.oidc.session.cookieName agentfleet_console_session —
console.config.auth.oidc.session.secureCookie true —
console.config.auth.oidc.session.sameSite lax —
console.config.auth.oidc.session.ttl "8h" —
console.config.auth.oidc.session.loginStateTTL "10m" —
console.config.auth.oidc.session.maxSessions 10000 —
console.config.auth.oidc.session.maxLoginAttempts 1000 —
console.config.auth.oidc.session.postgres — —
console.config.auth.oidc.session.postgres.existingSecret "" —
console.config.auth.oidc.session.postgres.dsnKey dsn —
console.config.auth.oidc.session.postgres.autoMigrate true —
console.config.auth.oidc.session.postgres.sweepInterval "5m" —
console.config.tenantAuthz — —
console.config.tenantAuthz.mode "off" —
console.config.tenantAuthz.readRoles — —
console.config.tenantAuthz.static — —
console.config.tenantAuthz.static.memberships [] —
console.config.dependencyTimeout "2s" —
console.inventory — —
console.inventory.kubernetes — —
console.inventory.kubernetes.enabled true —
console.inventory.kubernetes.namespace "" —
console.inventory.kubernetes.kubeconfig "" —
console.inventory.kubernetes.context "" —
console.inventory.kubernetes.fallbackToFiles true —
console.catalog — —
console.catalog.routes [] —
console.catalog.policies [] —
console.catalog.useMCPRouterConfig true —
console.demoCatalog — —
console.demoCatalog.enabled false —
console.resources {} —
console.podLabels {} —
console.podAnnotations {} —

profiles#

9 keys

KeyDefaultDescription
profiles — —
profiles.demo — —
profiles.demo.enabled false —
profiles.mesh — —
profiles.mesh.enabled false —
profiles.observability — —
profiles.observability.enabled false —
profiles.production — —
profiles.production.enabled false —