248 lines
7.3 KiB
YAML
248 lines
7.3 KiB
YAML
# Native Redis Cluster topology. The member StatefulSets contain
|
|
# shards * (replicasPerShard + 1) pods. Changing either value after the cluster
|
|
# contains data requires an explicit Redis reshard/add-node operation; a Helm
|
|
# upgrade alone intentionally does not mutate the slot map.
|
|
cluster:
|
|
# -- Independently writable hash-slot primaries. Redis requires at least 3
|
|
# for automatic failover elections.
|
|
shards: 3
|
|
# -- Readable, failover-capable replicas attached to every shard primary.
|
|
replicasPerShard: 1
|
|
# -- Dedicated node-to-node cluster bus port.
|
|
busPort: 16379
|
|
nodeTimeoutMilliseconds: 10000
|
|
requireFullCoverage: true
|
|
allowReadsWhenDown: false
|
|
migrationBarrier: 1
|
|
|
|
image:
|
|
repository: redis
|
|
tag: 7.4-alpine
|
|
pullPolicy: IfNotPresent
|
|
|
|
imagePullSecrets: []
|
|
nameOverride: ""
|
|
fullnameOverride: ""
|
|
|
|
auth:
|
|
enabled: false
|
|
# -- Password. Leave empty to auto-generate one (persisted across upgrades
|
|
# via helm lookup).
|
|
password: ""
|
|
# -- Use an existing secret instead of creating one.
|
|
existingSecret: ""
|
|
existingSecretKey: redis-password
|
|
|
|
redis:
|
|
port: 6379
|
|
# -- Cap Redis memory usage; keep it below the container memory limit.
|
|
maxmemory: 384mb
|
|
maxmemoryPolicy: noeviction
|
|
# -- Extra lines appended verbatim to redis.conf.
|
|
extraConfig: ""
|
|
resources:
|
|
requests:
|
|
cpu: 70m
|
|
memory: 256Mi
|
|
limits:
|
|
memory: 512Mi
|
|
|
|
probes:
|
|
redis:
|
|
# -- Redis may need to recover AOF and rejoin the cluster after a worker or
|
|
# storage outage. Startup failures are tolerated for 15 minutes.
|
|
startup:
|
|
initialDelaySeconds: 10
|
|
periodSeconds: 5
|
|
timeoutSeconds: 4
|
|
failureThreshold: 180
|
|
# -- Ten consecutive failed checks over 150 seconds are required before
|
|
# Kubernetes restarts Redis. LOADING and CLUSTERDOWN remain live states.
|
|
liveness:
|
|
periodSeconds: 15
|
|
timeoutSeconds: 8
|
|
failureThreshold: 10
|
|
# -- Readiness only controls traffic; it never restarts the container.
|
|
readiness:
|
|
periodSeconds: 5
|
|
timeoutSeconds: 4
|
|
failureThreshold: 3
|
|
|
|
# Redis Cluster clients must reach the exact member named by MOVED/ASK replies.
|
|
# When enabled, the Kubernetes LoadBalancer implementation allocates one
|
|
# endpoint per member plus a balanced bootstrap endpoint. Pods discover their
|
|
# assigned endpoint from the Kubernetes API before Redis starts.
|
|
externalAccess:
|
|
# -- Disabled by default because this creates one LoadBalancer per Redis
|
|
# member plus one bootstrap LoadBalancer and can incur provider charges.
|
|
enabled: false
|
|
port: 6379
|
|
bootstrap:
|
|
annotations: {}
|
|
memberServices:
|
|
annotations: {}
|
|
loadBalancerClass: ""
|
|
externalTrafficPolicy: Cluster
|
|
# -- Strongly recommended: restrict this to the client networks. An empty
|
|
# list leaves reachability to the LoadBalancer/firewall implementation.
|
|
loadBalancerSourceRanges: []
|
|
allocateLoadBalancerNodePorts: true
|
|
endpointDiscovery:
|
|
image:
|
|
repository: curlimages/curl
|
|
tag: 8.21.0
|
|
pullPolicy: IfNotPresent
|
|
resources:
|
|
requests:
|
|
cpu: 5m
|
|
memory: 8Mi
|
|
limits:
|
|
memory: 32Mi
|
|
|
|
metrics:
|
|
enabled: true
|
|
image:
|
|
# -- redis_exporter's own release registry (upstream project; also mirrored
|
|
# at quay.io/oliver006/redis_exporter and docker.io/oliver006/redis_exporter).
|
|
# GHCR avoids Docker Hub pull rate limits.
|
|
repository: ghcr.io/oliver006/redis_exporter
|
|
tag: v1.87.0-alpine
|
|
pullPolicy: IfNotPresent
|
|
port: 9121
|
|
resources:
|
|
requests:
|
|
cpu: 25m
|
|
memory: 32Mi
|
|
limits:
|
|
memory: 64Mi
|
|
serviceMonitor:
|
|
# -- Requires the Prometheus Operator CRDs (kube-prometheus-stack).
|
|
enabled: false
|
|
interval: 30s
|
|
scrapeTimeout: 10s
|
|
# -- Extra labels so your Prometheus instance selects this ServiceMonitor,
|
|
# e.g. release: kube-prometheus-stack
|
|
labels: {}
|
|
|
|
# Optional browser UI for inspecting and operating this Redis Cluster. The
|
|
# component is disabled by default; enabling it creates one RedisInsight pod,
|
|
# its Service and storage, and (when requested) an Istio HTTP route.
|
|
redisInsight:
|
|
enabled: false
|
|
image:
|
|
repository: redis/redisinsight
|
|
tag: 3.8.0
|
|
pullPolicy: IfNotPresent
|
|
port: 5540
|
|
connection:
|
|
# -- Empty automatically uses this release's balanced bootstrap endpoint:
|
|
# internal Service DNS normally, or the discovered LoadBalancer ingress
|
|
# address when external access is enabled. Set a hostname/IP to override.
|
|
host: ""
|
|
# -- Zero automatically follows externalAccess.port or redis.port.
|
|
port: 0
|
|
alias: redis-cluster
|
|
tls: false
|
|
persistence:
|
|
enabled: true
|
|
# -- Empty uses the cluster's default StorageClass.
|
|
storageClass: ""
|
|
accessModes:
|
|
- ReadWriteOnce
|
|
size: 1Gi
|
|
annotations: {}
|
|
resources:
|
|
requests:
|
|
cpu: 50m
|
|
memory: 128Mi
|
|
limits:
|
|
memory: 512Mi
|
|
podAnnotations: {}
|
|
nodeSelector: {}
|
|
tolerations: []
|
|
ingress:
|
|
enabled: false
|
|
host: ""
|
|
gatewaySelector:
|
|
istio: ingressgateway
|
|
requestTimeout: 60s
|
|
tls:
|
|
enabled: false
|
|
# -- Name of an existing TLS Secret available to the Istio ingress
|
|
# gateway. Required when TLS is enabled.
|
|
credentialName: ""
|
|
certificate:
|
|
# -- Ask cert-manager to create credentialName. Leave false when the
|
|
# Secret is managed outside this chart.
|
|
create: false
|
|
issuerName: ""
|
|
issuerKind: ClusterIssuer
|
|
# -- Empty creates the Certificate in the release namespace. Some
|
|
# Istio installations require gateway credentials in istio-system;
|
|
# set that namespace explicitly when needed.
|
|
secretNamespace: ""
|
|
|
|
persistence:
|
|
enabled: true
|
|
# -- Empty uses the cluster's default StorageClass.
|
|
storageClass: ""
|
|
accessModes:
|
|
- ReadWriteOnce
|
|
# -- Requested capacity for every Redis member PVC. The chart imposes no
|
|
# upper bound; the StorageClass and cluster quota decide what is available.
|
|
size: 3Gi
|
|
annotations: {}
|
|
|
|
istio:
|
|
# -- Keep the Envoy sidecar OFF the Redis pods (recommended). Redis Cluster
|
|
# uses direct pod-to-pod client and cluster-bus connections. Client pods can reach
|
|
# Redis from inside the mesh (mTLS in PERMISSIVE mode, or add a
|
|
# PeerAuthentication exception for this workload if you run STRICT).
|
|
injectSidecar: false
|
|
|
|
networkPolicy:
|
|
# -- Standard Kubernetes NetworkPolicy. Enforcement depends on the installed
|
|
# CNI. Pod-to-pod client, replication, key-migration, and cluster-bus traffic
|
|
# is always allowed.
|
|
enabled: false
|
|
# -- Allow any pod in the cluster to reach the Redis client port.
|
|
# Set to false and fill extraIngress to lock down clients.
|
|
allowExternal: true
|
|
# -- Extra "from" peers allowed on the client ports when allowExternal=false,
|
|
# e.g. [{namespaceSelector: {matchLabels: {kubernetes.io/metadata.name: myapp}}}]
|
|
extraIngress: []
|
|
# -- Namespaces allowed to scrape metrics (empty = any).
|
|
metricsFromNamespaces: []
|
|
|
|
podDisruptionBudget:
|
|
enabled: true
|
|
maxUnavailable: 1
|
|
|
|
serviceAccount:
|
|
create: true
|
|
name: ""
|
|
annotations: {}
|
|
|
|
nodeSelector: {}
|
|
tolerations: []
|
|
topologySpreadConstraints: []
|
|
priorityClassName: ""
|
|
|
|
podAnnotations: {}
|
|
podLabels: {}
|
|
|
|
podSecurityContext:
|
|
fsGroup: 999
|
|
runAsNonRoot: true
|
|
|
|
containerSecurityContext:
|
|
runAsUser: 999
|
|
runAsGroup: 999
|
|
allowPrivilegeEscalation: false
|
|
readOnlyRootFilesystem: true
|
|
capabilities:
|
|
drop:
|
|
- ALL
|
|
|
|
terminationGracePeriodSeconds: 30
|