Operator Helm values
Configure the ToolHive operator with these Helm values.
This reference lists values declared in the chart's default values.yaml.
Templates can also accept optional settings and inherited global values.
Chart: toolhive-operator. Chart version: 0.51.4. Source:
values.yaml
at v0.51.4.
Values
nameOverride
Type: string
Default: ""
Override the name of the chart
fullnameOverride
Type: string
Default: "toolhive-operator"
Provide a fully-qualified name override for resources
operator
Type: object
Default value
affinity: {}
autoscaling:
enabled: false
maxReplicas: 100
minReplicas: 1
targetCPUUtilizationPercentage: 80
containerSecurityContext:
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
readOnlyRootFilesystem: true
runAsNonRoot: true
runAsUser: 1000
seccompProfile:
type: RuntimeDefault
defaultImagePullSecrets: []
defaultRedis:
addr: ''
existingSecret: ''
existingSecretKey: ''
env: []
features:
experimental: false
storageVersionMigrator: true
gc:
gogc: 75
gomemlimit: 110MiB
image: ghcr.io/stacklok/toolhive/operator:v0.51.4
imageDiscovery:
enabled: false
resources: {}
imagePullPolicy: IfNotPresent
imagePullSecrets: []
leaderElectionRole:
binding:
name: toolhive-operator-leader-election-rolebinding
name: toolhive-operator-leader-election-role
rules:
- apiGroups:
- ''
resources:
- configmaps
verbs:
- get
- list
- watch
- create
- update
- patch
- delete
- apiGroups:
- coordination.k8s.io
resources:
- leases
verbs:
- get
- list
- watch
- create
- update
- patch
- delete
- apiGroups:
- events.k8s.io
resources:
- events
verbs:
- create
- patch
livenessProbe:
httpGet:
path: /healthz
port: health
initialDelaySeconds: 15
periodSeconds: 20
nodeSelector: {}
podAnnotations: {}
podLabels: {}
podSecurityContext:
runAsNonRoot: true
ports:
- containerPort: 8080
name: metrics
protocol: TCP
- containerPort: 8081
name: health
protocol: TCP
proxyHost: 0.0.0.0
rbac:
allowedNamespaces: []
scope: cluster
readinessProbe:
httpGet:
path: /readyz
port: health
initialDelaySeconds: 5
periodSeconds: 10
replicaCount: 1
resources:
limits:
cpu: 500m
memory: 128Mi
requests:
cpu: 10m
memory: 64Mi
serviceAccount:
annotations: {}
automountServiceAccountToken: true
create: true
labels: {}
name: toolhive-operator
tolerations: []
toolhiveRunnerImage: ghcr.io/stacklok/toolhive/proxyrunner:v0.51.4
vmcpImage: ghcr.io/stacklok/toolhive/vmcp:v0.51.4
volumeMounts: []
volumes: []
All values for the operator deployment and associated resources
operator.features.experimental
Type: bool
Default: false
Enable experimental features
operator.features.storageVersionMigrator
Type: bool
Default: true
Enable the StorageVersionMigrator controller, which auto-cleans
status.storedVersions on opted-in toolhive.stacklok.dev CRDs so a future release
can drop deprecated versions (e.g. v1alpha1) without orphaning etcd objects in
the cluster. Enabled by default; set to false to opt out and handle
storage-version cleanup yourself. Sets TOOLHIVE_ENABLE_STORAGE_VERSION_MIGRATOR
in the operator deployment. Requires operator.rbac.scope=cluster — the
controller watches cluster-scoped CRDs and re-stores resources across all
namespaces, so the chart rejects this being true when scope is namespace.
operator.replicaCount
Type: int
Default: 1
Number of replicas for the operator deployment
operator.imagePullSecrets
Type: list
Default: []
List of image pull secrets to use
operator.defaultImagePullSecrets
Type: list
Default: []
List of image pull secrets that the operator applies as defaults to every
workload it spawns (proxy runners, vMCP servers, registry API, etc.). Per-CR
imagePullSecrets take precedence on name collisions; chart-level entries are
appended additively. The operator parses these once at startup from the
TOOLHIVE_DEFAULT_IMAGE_PULL_SECRETS environment variable. The Secrets must exist
in the namespace where each workload is created.
Each entry may be either a plain string (the Secret name) or an object with a
name field, e.g.:
defaultImagePullSecrets:
- regcred
- name: otherscred
The two shapes are equivalent; the object form matches
operator.imagePullSecrets above for convenience.
operator.defaultRedis
Type: object
Default: {"addr":"","existingSecret":"","existingSecretKey":""}
Default Redis/Valkey address used by the operator when a workload CR has no sessionStorage configured. The operator injects this as TOOLHIVE_DEFAULT_REDIS_ADDR on pods it creates. When empty, no global Redis default is active. Override per-CR with spec.sessionStorage.
global.redis.host (from a parent umbrella chart) is used as fallback when addr is empty here. Both express the same addr concept; addr takes precedence.
For the password, reference a pre-existing Kubernetes Secret:
defaultRedis:
addr: 'myredis.svc:6379'
existingSecret: 'redis-credentials'
existingSecretKey: 'password'
operator.defaultRedis.addr
Type: string
Default: ""
addr is the Redis/Valkey address (host:port).
operator.defaultRedis.existingSecret
Type: string
Default: ""
existingSecret is the name of a Secret containing the Redis password.
operator.defaultRedis.existingSecretKey
Type: string
Default: ""
existingSecretKey is the key within existingSecret that holds the password. Empty means use global.redis.existingSecretKey or fall back to "redis-password".
operator.image
Type: string
Default: "ghcr.io/stacklok/toolhive/operator:v0.51.4"
Container image for the operator
operator.imagePullPolicy
Type: string
Default: "IfNotPresent"
Image pull policy for the operator container
operator.toolhiveRunnerImage
Type: string
Default: "ghcr.io/stacklok/toolhive/proxyrunner:v0.51.4"
Image to use for ToolHive runners
operator.vmcpImage
Type: string
Default: "ghcr.io/stacklok/toolhive/vmcp:v0.51.4"
Image to use for Virtual MCP Server (vMCP) deployments
operator.imageDiscovery
Type: object
Default: {"enabled":false,"resources":{}}
Air-gap image-discovery aid. toolhiveRunnerImage, vmcpImage, and
registryAPI.image are never rendered as chart image: keys — the operator only
injects them into child workloads at runtime via env vars (TOOLHIVE_RUNNER_IMAGE
/ VMCP_IMAGE / TOOLHIVE_REGISTRY_API_IMAGE). Static manifest scanners used by
air-gap tooling (e.g. a vendor portal's image list generator) discover images by
reading image: keys out of helm template output, so they miss these three
and an air-gapped customer can hit ImagePullBackOff on the first MCPServer /
VirtualMCPServer / MCPRegistry create.
Enabling this renders a replicas: 0 Deployment
(<release-name>-image-discovery) whose pod template references all three
images. A zero-replica Deployment never has Kubernetes schedule a pod from it,
so the images are never pulled or run — this exists purely to put the refs in
front of a static manifest scan.
operator.imageDiscovery.enabled
Type: bool
Default: false
Render the zero-replica image-discovery Deployment described above.
operator.imageDiscovery.resources
Type: object
Default: {}
Resource requests/limits for the image-discovery Deployment's containers. Admission control (a LimitRange, an OPA/Kyverno policy requiring explicit requests) validates these at CREATE time even though replicas: 0 means nothing ever actually runs, so this is exposed separately from operator.resources for clusters that need it set.
operator.proxyHost
Type: string
Default: "0.0.0.0"
Host for the proxy deployed by the operator
operator.env
Type: list
Default: []
Environment variables to set in the operator container. Supported toolhive-specific variables include:
- TOOLHIVE_SKIP_UPDATE_CHECK: set to "true" to disable the operator's periodic update check against the ToolHive update API. Also disables the usage-metrics collection that is gated on the same check.
operator.ports
Type: list
Default value
- containerPort: 8080
name: metrics
protocol: TCP
- containerPort: 8081
name: health
protocol: TCP
List of ports to expose from the operator container
operator.podAnnotations
Type: object
Default: {}
Annotations to add to the operator pod
operator.podLabels
Type: object
Default: {}
Labels to add to the operator pod
operator.podSecurityContext
Type: object
Default: {"runAsNonRoot":true}
Pod security context settings
operator.containerSecurityContext
Type: object
Default value
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
readOnlyRootFilesystem: true
runAsNonRoot: true
runAsUser: 1000
seccompProfile:
type: RuntimeDefault
Container security context settings for the operator
operator.livenessProbe
Type: object
Default:
{"httpGet":{"path":"/healthz","port":"health"},"initialDelaySeconds":15,"periodSeconds":20}
Liveness probe configuration for the operator
operator.readinessProbe
Type: object
Default:
{"httpGet":{"path":"/readyz","port":"health"},"initialDelaySeconds":5,"periodSeconds":10}
Readiness probe configuration for the operator
operator.autoscaling
Type: object
Default:
{"enabled":false,"maxReplicas":100,"minReplicas":1,"targetCPUUtilizationPercentage":80}
Configuration for horizontal pod autoscaling
operator.autoscaling.enabled
Type: bool
Default: false
Enable autoscaling for the operator
operator.autoscaling.minReplicas
Type: int
Default: 1
Minimum number of replicas
operator.autoscaling.maxReplicas
Type: int
Default: 100
Maximum number of replicas
operator.autoscaling.targetCPUUtilizationPercentage
Type: int
Default: 80
Target CPU utilization percentage for autoscaling
operator.resources
Type: object
Default:
{"limits":{"cpu":"500m","memory":"128Mi"},"requests":{"cpu":"10m","memory":"64Mi"}}
Resource requests and limits for the operator container
operator.gc
Type: object
Default: {"gogc":75,"gomemlimit":"110MiB"}
Go memory limits and garbage collection percentage for the operator container
operator.gc.gomemlimit
Type: string
Default: "110MiB"
Go memory limits for the operator container
operator.gc.gogc
Type: int
Default: 75
Go garbage collection percentage for the operator container
operator.rbac
Type: object
Default: {"allowedNamespaces":[],"scope":"cluster"}
RBAC configuration for the operator
operator.rbac.scope
Type: string
Default: "cluster"
Scope of the RBAC configuration.
- cluster: The operator will have cluster-wide permissions via ClusterRole and ClusterRoleBinding.
- namespace: The operator will have permissions to manage resources in the
namespaces specified in
allowedNamespaces. The operator will have a ClusterRole and RoleBinding for each namespace inallowedNamespaces.
operator.rbac.allowedNamespaces
Type: list
Default: []
List of namespaces that the operator is allowed to have permissions to manage. Only used if scope is set to "namespace".
operator.serviceAccount
Type: object
Default value
annotations: {}
automountServiceAccountToken: true
create: true
labels: {}
name: toolhive-operator
Service account configuration for the operator
operator.serviceAccount.create
Type: bool
Default: true
Specifies whether a service account should be created
operator.serviceAccount.automountServiceAccountToken
Type: bool
Default: true
Automatically mount a ServiceAccount's API credentials
operator.serviceAccount.annotations
Type: object
Default: {}
Annotations to add to the service account
operator.serviceAccount.labels
Type: object
Default: {}
Labels to add to the service account
operator.serviceAccount.name
Type: string
Default: "toolhive-operator"
The name of the service account to use. If not set and create is true, a name is generated.
operator.leaderElectionRole
Type: object
Default value
binding:
name: toolhive-operator-leader-election-rolebinding
name: toolhive-operator-leader-election-role
rules:
- apiGroups:
- ''
resources:
- configmaps
verbs:
- get
- list
- watch
- create
- update
- patch
- delete
- apiGroups:
- coordination.k8s.io
resources:
- leases
verbs:
- get
- list
- watch
- create
- update
- patch
- delete
- apiGroups:
- events.k8s.io
resources:
- events
verbs:
- create
- patch
Leader election role configuration
operator.leaderElectionRole.name
Type: string
Default: "toolhive-operator-leader-election-role"
Name of the role for leader election
operator.leaderElectionRole.binding.name
Type: string
Default: "toolhive-operator-leader-election-rolebinding"
Name of the role binding for leader election
operator.leaderElectionRole.rules
Type: list
Default value
- apiGroups:
- ''
resources:
- configmaps
verbs:
- get
- list
- watch
- create
- update
- patch
- delete
- apiGroups:
- coordination.k8s.io
resources:
- leases
verbs:
- get
- list
- watch
- create
- update
- patch
- delete
- apiGroups:
- events.k8s.io
resources:
- events
verbs:
- create
- patch
Rules for the leader election role
operator.volumes
Type: list
Default: []
Additional volumes to mount on the operator pod
operator.volumeMounts
Type: list
Default: []
Additional volume mounts on the operator container
operator.nodeSelector
Type: object
Default: {}
Node selector for the operator pod
operator.tolerations
Type: list
Default: []
Tolerations for the operator pod
operator.affinity
Type: object
Default: {}
Affinity settings for the operator pod
registryAPI
Type: object
Default: {"image":"ghcr.io/stacklok/thv-registry-api:v1.5.2"}
All values for the registry API deployment and associated resources
registryAPI.image
Type: string
Default: "ghcr.io/stacklok/thv-registry-api:v1.5.2"
Container image for the registry API