Files
redis-cluster/values.yaml
Corrado Mulas a407903a8d First Commit
2026-07-23 12:09:41 +02:00

248 lines
7.3 KiB
YAML

# Native Redis Cluster topology. The member StatefulSets contain
# shards * (replicasPerShard + 1) pods. Changing either value after the cluster
# contains data requires an explicit Redis reshard/add-node operation; a Helm
# upgrade alone intentionally does not mutate the slot map.
cluster:
# -- Independently writable hash-slot primaries. Redis requires at least 3
# for automatic failover elections.
shards: 3
# -- Readable, failover-capable replicas attached to every shard primary.
replicasPerShard: 1
# -- Dedicated node-to-node cluster bus port.
busPort: 16379
nodeTimeoutMilliseconds: 10000
requireFullCoverage: true
allowReadsWhenDown: false
migrationBarrier: 1
image:
repository: redis
tag: 7.4-alpine
pullPolicy: IfNotPresent
imagePullSecrets: []
nameOverride: ""
fullnameOverride: ""
auth:
enabled: false
# -- Password. Leave empty to auto-generate one (persisted across upgrades
# via helm lookup).
password: ""
# -- Use an existing secret instead of creating one.
existingSecret: ""
existingSecretKey: redis-password
redis:
port: 6379
# -- Cap Redis memory usage; keep it below the container memory limit.
maxmemory: 384mb
maxmemoryPolicy: noeviction
# -- Extra lines appended verbatim to redis.conf.
extraConfig: ""
resources:
requests:
cpu: 70m
memory: 256Mi
limits:
memory: 512Mi
probes:
redis:
# -- Redis may need to recover AOF and rejoin the cluster after a worker or
# storage outage. Startup failures are tolerated for 15 minutes.
startup:
initialDelaySeconds: 10
periodSeconds: 5
timeoutSeconds: 4
failureThreshold: 180
# -- Ten consecutive failed checks over 150 seconds are required before
# Kubernetes restarts Redis. LOADING and CLUSTERDOWN remain live states.
liveness:
periodSeconds: 15
timeoutSeconds: 8
failureThreshold: 10
# -- Readiness only controls traffic; it never restarts the container.
readiness:
periodSeconds: 5
timeoutSeconds: 4
failureThreshold: 3
# Redis Cluster clients must reach the exact member named by MOVED/ASK replies.
# When enabled, the Kubernetes LoadBalancer implementation allocates one
# endpoint per member plus a balanced bootstrap endpoint. Pods discover their
# assigned endpoint from the Kubernetes API before Redis starts.
externalAccess:
# -- Disabled by default because this creates one LoadBalancer per Redis
# member plus one bootstrap LoadBalancer and can incur provider charges.
enabled: false
port: 6379
bootstrap:
annotations: {}
memberServices:
annotations: {}
loadBalancerClass: ""
externalTrafficPolicy: Cluster
# -- Strongly recommended: restrict this to the client networks. An empty
# list leaves reachability to the LoadBalancer/firewall implementation.
loadBalancerSourceRanges: []
allocateLoadBalancerNodePorts: true
endpointDiscovery:
image:
repository: curlimages/curl
tag: 8.21.0
pullPolicy: IfNotPresent
resources:
requests:
cpu: 5m
memory: 8Mi
limits:
memory: 32Mi
metrics:
enabled: true
image:
# -- redis_exporter's own release registry (upstream project; also mirrored
# at quay.io/oliver006/redis_exporter and docker.io/oliver006/redis_exporter).
# GHCR avoids Docker Hub pull rate limits.
repository: ghcr.io/oliver006/redis_exporter
tag: v1.87.0-alpine
pullPolicy: IfNotPresent
port: 9121
resources:
requests:
cpu: 25m
memory: 32Mi
limits:
memory: 64Mi
serviceMonitor:
# -- Requires the Prometheus Operator CRDs (kube-prometheus-stack).
enabled: false
interval: 30s
scrapeTimeout: 10s
# -- Extra labels so your Prometheus instance selects this ServiceMonitor,
# e.g. release: kube-prometheus-stack
labels: {}
# Optional browser UI for inspecting and operating this Redis Cluster. The
# component is disabled by default; enabling it creates one RedisInsight pod,
# its Service and storage, and (when requested) an Istio HTTP route.
redisInsight:
enabled: false
image:
repository: redis/redisinsight
tag: 3.8.0
pullPolicy: IfNotPresent
port: 5540
connection:
# -- Empty automatically uses this release's balanced bootstrap endpoint:
# internal Service DNS normally, or the discovered LoadBalancer ingress
# address when external access is enabled. Set a hostname/IP to override.
host: ""
# -- Zero automatically follows externalAccess.port or redis.port.
port: 0
alias: redis-cluster
tls: false
persistence:
enabled: true
# -- Empty uses the cluster's default StorageClass.
storageClass: ""
accessModes:
- ReadWriteOnce
size: 1Gi
annotations: {}
resources:
requests:
cpu: 50m
memory: 128Mi
limits:
memory: 512Mi
podAnnotations: {}
nodeSelector: {}
tolerations: []
ingress:
enabled: false
host: ""
gatewaySelector:
istio: ingressgateway
requestTimeout: 60s
tls:
enabled: false
# -- Name of an existing TLS Secret available to the Istio ingress
# gateway. Required when TLS is enabled.
credentialName: ""
certificate:
# -- Ask cert-manager to create credentialName. Leave false when the
# Secret is managed outside this chart.
create: false
issuerName: ""
issuerKind: ClusterIssuer
# -- Empty creates the Certificate in the release namespace. Some
# Istio installations require gateway credentials in istio-system;
# set that namespace explicitly when needed.
secretNamespace: ""
persistence:
enabled: true
# -- Empty uses the cluster's default StorageClass.
storageClass: ""
accessModes:
- ReadWriteOnce
# -- Requested capacity for every Redis member PVC. The chart imposes no
# upper bound; the StorageClass and cluster quota decide what is available.
size: 3Gi
annotations: {}
istio:
# -- Keep the Envoy sidecar OFF the Redis pods (recommended). Redis Cluster
# uses direct pod-to-pod client and cluster-bus connections. Client pods can reach
# Redis from inside the mesh (mTLS in PERMISSIVE mode, or add a
# PeerAuthentication exception for this workload if you run STRICT).
injectSidecar: false
networkPolicy:
# -- Standard Kubernetes NetworkPolicy. Enforcement depends on the installed
# CNI. Pod-to-pod client, replication, key-migration, and cluster-bus traffic
# is always allowed.
enabled: false
# -- Allow any pod in the cluster to reach the Redis client port.
# Set to false and fill extraIngress to lock down clients.
allowExternal: true
# -- Extra "from" peers allowed on the client ports when allowExternal=false,
# e.g. [{namespaceSelector: {matchLabels: {kubernetes.io/metadata.name: myapp}}}]
extraIngress: []
# -- Namespaces allowed to scrape metrics (empty = any).
metricsFromNamespaces: []
podDisruptionBudget:
enabled: true
maxUnavailable: 1
serviceAccount:
create: true
name: ""
annotations: {}
nodeSelector: {}
tolerations: []
topologySpreadConstraints: []
priorityClassName: ""
podAnnotations: {}
podLabels: {}
podSecurityContext:
fsGroup: 999
runAsNonRoot: true
containerSecurityContext:
runAsUser: 999
runAsGroup: 999
allowPrivilegeEscalation: false
readOnlyRootFilesystem: true
capabilities:
drop:
- ALL
terminationGracePeriodSeconds: 30