Skip to main content

Registry Server Helm values

Configure the Registry Server deployment with these Helm values.

This reference lists values declared in the chart's default values.yaml. Templates can also accept optional settings and inherited global values.

Chart: toolhive-registry-server. Chart version: 1.5.2. Source: values.yaml at v1.5.2.

Values​

replicaCount​

Type: int

Default: 1

Number of replicas

image.registryServerUrl​

Type: string

Default: "ghcr.io/stacklok/thv-registry-api:v1.5.2"

URL of the registry server image

image.pullPolicy​

Type: string

Default: "IfNotPresent"

Image pull policy

imagePullSecrets​

Type: list

Default: []

Image pull secrets for private registries

nameOverride​

Type: string

Default: ""

Override the name of the chart

fullnameOverride​

Type: string

Default: ""

Override the full name of the chart

serviceAccount.create​

Type: bool

Default: true

Specifies whether a service account should be created

serviceAccount.annotations​

Type: object

Default: {}

Annotations to add to the service account

serviceAccount.name​

Type: string

Default: "toolhive-registry-server"

The name of the service account to use

podAnnotations​

Type: object

Default: {}

Annotations to add to the pod

podLabels​

Type: object

Default: {}

Labels to add to the pod

podSecurityContext​

Type: object

Default: {}

Pod security context

securityContext​

Type: object

Default value
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
readOnlyRootFilesystem: true
runAsNonRoot: true
runAsUser: 65535
seccompProfile:
type: RuntimeDefault

Container security context

service.type​

Type: string

Default: "ClusterIP"

Service type

service.port​

Type: int

Default: 8080

Service port

service.exposeInternalPort​

Type: bool

Default: true

Whether the Service publishes service.internalPort at all. The internal port carries no authentication, audit logging, or rate limiting by design (see "Internal Port Exposure" below); if service.type is set to anything other than the default ClusterIP, that Service publishes the internal port externally too, since there is no per-port guard. Set this to false to keep the internal port pod-local (reachable only via port-forward) if you change service.type and don't want that.

service.internalPort​

Type: int

Default: 8081

Internal service port (health checks, metrics). The container always listens on 8081 regardless of this value — this only changes the port the Service publishes that listener on, the same as service.port above. Only takes effect when service.exposeInternalPort is true.

service.annotations​

Type: object

Default: {}

Service annotations

resources​

Type: object

Default: {"limits":{"cpu":"500m","memory":"512Mi"},"requests":{"cpu":"100m","memory":"128Mi"}}

Resource requests and limits (matching operator defaults)

livenessProbe​

Type: object

Default: {"httpGet":{"path":"/health","port":"internal-http"},"initialDelaySeconds":30,"periodSeconds":10}

Liveness probe configuration

readinessProbe​

Type: object

Default value
httpGet:
path: /readiness
port: internal-http
initialDelaySeconds: 5
periodSeconds: 5

Readiness probe configuration

nodeSelector​

Type: object

Default: {}

Node selector for pod scheduling

tolerations​

Type: list

Default: []

Tolerations for pod scheduling

affinity​

Type: object

Default: {}

Affinity rules for pod scheduling

initContainers​

Type: list

Default: []

Init containers to run before the main container Use this for setup tasks like preparing pgpass files, waiting for dependencies, etc. Init containers share the same volumes as the main container (extraVolumes)

config​

Type: object

Default value
auth:
mode: anonymous
database:
database: toolhive_registry
host: ''
port: 5432
sslMode: require
user: thv_user
registries:
- name: default
sources:
- toolhive
sources:
- git:
branch: main
path: pkg/catalog/toolhive/data/registry-upstream.json
repository: https://github.com/stacklok/toolhive-catalog.git
name: toolhive
syncPolicy:
interval: 30m

Registry Server configuration rendered into a Kubernetes ConfigMap. This block accepts application configuration fields beyond the defaults shown here. See Configuration for sources, registries, and sync policies, and Database for database settings. Supply passwords through Secret-backed environment variables rather than this block.

extraEnv​

Type: list

Default: []

Additional environment variables to add to the container Use this for secrets, feature flags, or runtime configuration

extraEnvFrom​

Type: list

Default: []

Additional environment variables from ConfigMap or Secret references

extraVolumes​

Type: list

Default: []

Additional volumes to add to the pod

extraVolumeMounts​

Type: list

Default: []

Additional volume mounts to add to the container

rbac​

Type: object

Default: {"allowedNamespaces":[],"scope":"cluster"}

RBAC configuration for the registry server

rbac.scope​

Type: string

Default: "cluster"

Scope of the RBAC configuration.

  • cluster: The registry server will have cluster-wide permissions via ClusterRole and ClusterRoleBinding.
  • namespace: The registry server will have permissions to watch resources in the namespaces specified in allowedNamespaces. The registry server will have a ClusterRole and RoleBinding for each namespace in allowedNamespaces.

rbac.allowedNamespaces​

Type: list

Default: []

List of namespaces that the registry server is allowed to watch. Only used if scope is set to "namespace".