Skip to main content

Operator Helm values

Configure the ToolHive operator with these Helm values.

This reference lists values declared in the chart's default values.yaml. Templates can also accept optional settings and inherited global values.

Chart: toolhive-operator. Chart version: 0.51.4. Source: values.yaml at v0.51.4.

Values​

nameOverride​

Type: string

Default: ""

Override the name of the chart

fullnameOverride​

Type: string

Default: "toolhive-operator"

Provide a fully-qualified name override for resources

operator​

Type: object

Default value
affinity: {}
autoscaling:
enabled: false
maxReplicas: 100
minReplicas: 1
targetCPUUtilizationPercentage: 80
containerSecurityContext:
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
readOnlyRootFilesystem: true
runAsNonRoot: true
runAsUser: 1000
seccompProfile:
type: RuntimeDefault
defaultImagePullSecrets: []
defaultRedis:
addr: ''
existingSecret: ''
existingSecretKey: ''
env: []
features:
experimental: false
storageVersionMigrator: true
gc:
gogc: 75
gomemlimit: 110MiB
image: ghcr.io/stacklok/toolhive/operator:v0.51.4
imageDiscovery:
enabled: false
resources: {}
imagePullPolicy: IfNotPresent
imagePullSecrets: []
leaderElectionRole:
binding:
name: toolhive-operator-leader-election-rolebinding
name: toolhive-operator-leader-election-role
rules:
- apiGroups:
- ''
resources:
- configmaps
verbs:
- get
- list
- watch
- create
- update
- patch
- delete
- apiGroups:
- coordination.k8s.io
resources:
- leases
verbs:
- get
- list
- watch
- create
- update
- patch
- delete
- apiGroups:
- events.k8s.io
resources:
- events
verbs:
- create
- patch
livenessProbe:
httpGet:
path: /healthz
port: health
initialDelaySeconds: 15
periodSeconds: 20
nodeSelector: {}
podAnnotations: {}
podLabels: {}
podSecurityContext:
runAsNonRoot: true
ports:
- containerPort: 8080
name: metrics
protocol: TCP
- containerPort: 8081
name: health
protocol: TCP
proxyHost: 0.0.0.0
rbac:
allowedNamespaces: []
scope: cluster
readinessProbe:
httpGet:
path: /readyz
port: health
initialDelaySeconds: 5
periodSeconds: 10
replicaCount: 1
resources:
limits:
cpu: 500m
memory: 128Mi
requests:
cpu: 10m
memory: 64Mi
serviceAccount:
annotations: {}
automountServiceAccountToken: true
create: true
labels: {}
name: toolhive-operator
tolerations: []
toolhiveRunnerImage: ghcr.io/stacklok/toolhive/proxyrunner:v0.51.4
vmcpImage: ghcr.io/stacklok/toolhive/vmcp:v0.51.4
volumeMounts: []
volumes: []

All values for the operator deployment and associated resources

operator.features.experimental​

Type: bool

Default: false

Enable experimental features

operator.features.storageVersionMigrator​

Type: bool

Default: true

Enable the StorageVersionMigrator controller, which auto-cleans status.storedVersions on opted-in toolhive.stacklok.dev CRDs so a future release can drop deprecated versions (e.g. v1alpha1) without orphaning etcd objects in the cluster. Enabled by default; set to false to opt out and handle storage-version cleanup yourself. Sets TOOLHIVE_ENABLE_STORAGE_VERSION_MIGRATOR in the operator deployment. Requires operator.rbac.scope=cluster — the controller watches cluster-scoped CRDs and re-stores resources across all namespaces, so the chart rejects this being true when scope is namespace.

operator.replicaCount​

Type: int

Default: 1

Number of replicas for the operator deployment

operator.imagePullSecrets​

Type: list

Default: []

List of image pull secrets to use

operator.defaultImagePullSecrets​

Type: list

Default: []

List of image pull secrets that the operator applies as defaults to every workload it spawns (proxy runners, vMCP servers, registry API, etc.). Per-CR imagePullSecrets take precedence on name collisions; chart-level entries are appended additively. The operator parses these once at startup from the TOOLHIVE_DEFAULT_IMAGE_PULL_SECRETS environment variable. The Secrets must exist in the namespace where each workload is created.

Each entry may be either a plain string (the Secret name) or an object with a name field, e.g.:

defaultImagePullSecrets:
- regcred
- name: otherscred

The two shapes are equivalent; the object form matches operator.imagePullSecrets above for convenience.

operator.defaultRedis​

Type: object

Default: {"addr":"","existingSecret":"","existingSecretKey":""}

Default Redis/Valkey address used by the operator when a workload CR has no sessionStorage configured. The operator injects this as TOOLHIVE_DEFAULT_REDIS_ADDR on pods it creates. When empty, no global Redis default is active. Override per-CR with spec.sessionStorage.

global.redis.host (from a parent umbrella chart) is used as fallback when addr is empty here. Both express the same addr concept; addr takes precedence.

For the password, reference a pre-existing Kubernetes Secret:

defaultRedis:
addr: 'myredis.svc:6379'
existingSecret: 'redis-credentials'
existingSecretKey: 'password'

operator.defaultRedis.addr​

Type: string

Default: ""

addr is the Redis/Valkey address (host:port).

operator.defaultRedis.existingSecret​

Type: string

Default: ""

existingSecret is the name of a Secret containing the Redis password.

operator.defaultRedis.existingSecretKey​

Type: string

Default: ""

existingSecretKey is the key within existingSecret that holds the password. Empty means use global.redis.existingSecretKey or fall back to "redis-password".

operator.image​

Type: string

Default: "ghcr.io/stacklok/toolhive/operator:v0.51.4"

Container image for the operator

operator.imagePullPolicy​

Type: string

Default: "IfNotPresent"

Image pull policy for the operator container

operator.toolhiveRunnerImage​

Type: string

Default: "ghcr.io/stacklok/toolhive/proxyrunner:v0.51.4"

Image to use for ToolHive runners

operator.vmcpImage​

Type: string

Default: "ghcr.io/stacklok/toolhive/vmcp:v0.51.4"

Image to use for Virtual MCP Server (vMCP) deployments

operator.imageDiscovery​

Type: object

Default: {"enabled":false,"resources":{}}

Air-gap image-discovery aid. toolhiveRunnerImage, vmcpImage, and registryAPI.image are never rendered as chart image: keys — the operator only injects them into child workloads at runtime via env vars (TOOLHIVE_RUNNER_IMAGE / VMCP_IMAGE / TOOLHIVE_REGISTRY_API_IMAGE). Static manifest scanners used by air-gap tooling (e.g. a vendor portal's image list generator) discover images by reading image: keys out of helm template output, so they miss these three and an air-gapped customer can hit ImagePullBackOff on the first MCPServer / VirtualMCPServer / MCPRegistry create.

Enabling this renders a replicas: 0 Deployment (<release-name>-image-discovery) whose pod template references all three images. A zero-replica Deployment never has Kubernetes schedule a pod from it, so the images are never pulled or run — this exists purely to put the refs in front of a static manifest scan.

operator.imageDiscovery.enabled​

Type: bool

Default: false

Render the zero-replica image-discovery Deployment described above.

operator.imageDiscovery.resources​

Type: object

Default: {}

Resource requests/limits for the image-discovery Deployment's containers. Admission control (a LimitRange, an OPA/Kyverno policy requiring explicit requests) validates these at CREATE time even though replicas: 0 means nothing ever actually runs, so this is exposed separately from operator.resources for clusters that need it set.

operator.proxyHost​

Type: string

Default: "0.0.0.0"

Host for the proxy deployed by the operator

operator.env​

Type: list

Default: []

Environment variables to set in the operator container. Supported toolhive-specific variables include:

  • TOOLHIVE_SKIP_UPDATE_CHECK: set to "true" to disable the operator's periodic update check against the ToolHive update API. Also disables the usage-metrics collection that is gated on the same check.

operator.ports​

Type: list

Default value
- containerPort: 8080
name: metrics
protocol: TCP
- containerPort: 8081
name: health
protocol: TCP

List of ports to expose from the operator container

operator.podAnnotations​

Type: object

Default: {}

Annotations to add to the operator pod

operator.podLabels​

Type: object

Default: {}

Labels to add to the operator pod

operator.podSecurityContext​

Type: object

Default: {"runAsNonRoot":true}

Pod security context settings

operator.containerSecurityContext​

Type: object

Default value
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
readOnlyRootFilesystem: true
runAsNonRoot: true
runAsUser: 1000
seccompProfile:
type: RuntimeDefault

Container security context settings for the operator

operator.livenessProbe​

Type: object

Default: {"httpGet":{"path":"/healthz","port":"health"},"initialDelaySeconds":15,"periodSeconds":20}

Liveness probe configuration for the operator

operator.readinessProbe​

Type: object

Default: {"httpGet":{"path":"/readyz","port":"health"},"initialDelaySeconds":5,"periodSeconds":10}

Readiness probe configuration for the operator

operator.autoscaling​

Type: object

Default: {"enabled":false,"maxReplicas":100,"minReplicas":1,"targetCPUUtilizationPercentage":80}

Configuration for horizontal pod autoscaling

operator.autoscaling.enabled​

Type: bool

Default: false

Enable autoscaling for the operator

operator.autoscaling.minReplicas​

Type: int

Default: 1

Minimum number of replicas

operator.autoscaling.maxReplicas​

Type: int

Default: 100

Maximum number of replicas

operator.autoscaling.targetCPUUtilizationPercentage​

Type: int

Default: 80

Target CPU utilization percentage for autoscaling

operator.resources​

Type: object

Default: {"limits":{"cpu":"500m","memory":"128Mi"},"requests":{"cpu":"10m","memory":"64Mi"}}

Resource requests and limits for the operator container

operator.gc​

Type: object

Default: {"gogc":75,"gomemlimit":"110MiB"}

Go memory limits and garbage collection percentage for the operator container

operator.gc.gomemlimit​

Type: string

Default: "110MiB"

Go memory limits for the operator container

operator.gc.gogc​

Type: int

Default: 75

Go garbage collection percentage for the operator container

operator.rbac​

Type: object

Default: {"allowedNamespaces":[],"scope":"cluster"}

RBAC configuration for the operator

operator.rbac.scope​

Type: string

Default: "cluster"

Scope of the RBAC configuration.

  • cluster: The operator will have cluster-wide permissions via ClusterRole and ClusterRoleBinding.
  • namespace: The operator will have permissions to manage resources in the namespaces specified in allowedNamespaces. The operator will have a ClusterRole and RoleBinding for each namespace in allowedNamespaces.

operator.rbac.allowedNamespaces​

Type: list

Default: []

List of namespaces that the operator is allowed to have permissions to manage. Only used if scope is set to "namespace".

operator.serviceAccount​

Type: object

Default value
annotations: {}
automountServiceAccountToken: true
create: true
labels: {}
name: toolhive-operator

Service account configuration for the operator

operator.serviceAccount.create​

Type: bool

Default: true

Specifies whether a service account should be created

operator.serviceAccount.automountServiceAccountToken​

Type: bool

Default: true

Automatically mount a ServiceAccount's API credentials

operator.serviceAccount.annotations​

Type: object

Default: {}

Annotations to add to the service account

operator.serviceAccount.labels​

Type: object

Default: {}

Labels to add to the service account

operator.serviceAccount.name​

Type: string

Default: "toolhive-operator"

The name of the service account to use. If not set and create is true, a name is generated.

operator.leaderElectionRole​

Type: object

Default value
binding:
name: toolhive-operator-leader-election-rolebinding
name: toolhive-operator-leader-election-role
rules:
- apiGroups:
- ''
resources:
- configmaps
verbs:
- get
- list
- watch
- create
- update
- patch
- delete
- apiGroups:
- coordination.k8s.io
resources:
- leases
verbs:
- get
- list
- watch
- create
- update
- patch
- delete
- apiGroups:
- events.k8s.io
resources:
- events
verbs:
- create
- patch

Leader election role configuration

operator.leaderElectionRole.name​

Type: string

Default: "toolhive-operator-leader-election-role"

Name of the role for leader election

operator.leaderElectionRole.binding.name​

Type: string

Default: "toolhive-operator-leader-election-rolebinding"

Name of the role binding for leader election

operator.leaderElectionRole.rules​

Type: list

Default value
- apiGroups:
- ''
resources:
- configmaps
verbs:
- get
- list
- watch
- create
- update
- patch
- delete
- apiGroups:
- coordination.k8s.io
resources:
- leases
verbs:
- get
- list
- watch
- create
- update
- patch
- delete
- apiGroups:
- events.k8s.io
resources:
- events
verbs:
- create
- patch

Rules for the leader election role

operator.volumes​

Type: list

Default: []

Additional volumes to mount on the operator pod

operator.volumeMounts​

Type: list

Default: []

Additional volume mounts on the operator container

operator.nodeSelector​

Type: object

Default: {}

Node selector for the operator pod

operator.tolerations​

Type: list

Default: []

Tolerations for the operator pod

operator.affinity​

Type: object

Default: {}

Affinity settings for the operator pod

registryAPI​

Type: object

Default: {"image":"ghcr.io/stacklok/thv-registry-api:v1.5.2"}

All values for the registry API deployment and associated resources

registryAPI.image​

Type: string

Default: "ghcr.io/stacklok/thv-registry-api:v1.5.2"

Container image for the registry API