Registry Server Helm values
Configure the Registry Server deployment with these Helm values.
This reference lists values declared in the chart's default values.yaml.
Templates can also accept optional settings and inherited global values.
Chart: toolhive-registry-server. Chart version: 1.5.2. Source:
values.yaml
at v1.5.2.
Values
replicaCount
Type: int
Default: 1
Number of replicas
image.registryServerUrl
Type: string
Default: "ghcr.io/stacklok/thv-registry-api:v1.5.2"
URL of the registry server image
image.pullPolicy
Type: string
Default: "IfNotPresent"
Image pull policy
imagePullSecrets
Type: list
Default: []
Image pull secrets for private registries
nameOverride
Type: string
Default: ""
Override the name of the chart
fullnameOverride
Type: string
Default: ""
Override the full name of the chart
serviceAccount.create
Type: bool
Default: true
Specifies whether a service account should be created
serviceAccount.annotations
Type: object
Default: {}
Annotations to add to the service account
serviceAccount.name
Type: string
Default: "toolhive-registry-server"
The name of the service account to use
podAnnotations
Type: object
Default: {}
Annotations to add to the pod
podLabels
Type: object
Default: {}
Labels to add to the pod
podSecurityContext
Type: object
Default: {}
Pod security context
securityContext
Type: object
Default value
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
readOnlyRootFilesystem: true
runAsNonRoot: true
runAsUser: 65535
seccompProfile:
type: RuntimeDefault
Container security context
service.type
Type: string
Default: "ClusterIP"
Service type
service.port
Type: int
Default: 8080
Service port
service.exposeInternalPort
Type: bool
Default: true
Whether the Service publishes service.internalPort at all. The internal port carries no authentication, audit logging, or rate limiting by design (see "Internal Port Exposure" below); if service.type is set to anything other than the default ClusterIP, that Service publishes the internal port externally too, since there is no per-port guard. Set this to false to keep the internal port pod-local (reachable only via port-forward) if you change service.type and don't want that.
service.internalPort
Type: int
Default: 8081
Internal service port (health checks, metrics). The container always listens on 8081 regardless of this value — this only changes the port the Service publishes that listener on, the same as service.port above. Only takes effect when service.exposeInternalPort is true.
service.annotations
Type: object
Default: {}
Service annotations
resources
Type: object
Default:
{"limits":{"cpu":"500m","memory":"512Mi"},"requests":{"cpu":"100m","memory":"128Mi"}}
Resource requests and limits (matching operator defaults)
livenessProbe
Type: object
Default:
{"httpGet":{"path":"/health","port":"internal-http"},"initialDelaySeconds":30,"periodSeconds":10}
Liveness probe configuration
readinessProbe
Type: object
Default value
httpGet:
path: /readiness
port: internal-http
initialDelaySeconds: 5
periodSeconds: 5
Readiness probe configuration
nodeSelector
Type: object
Default: {}
Node selector for pod scheduling
tolerations
Type: list
Default: []
Tolerations for pod scheduling
affinity
Type: object
Default: {}
Affinity rules for pod scheduling
initContainers
Type: list
Default: []
Init containers to run before the main container Use this for setup tasks like preparing pgpass files, waiting for dependencies, etc. Init containers share the same volumes as the main container (extraVolumes)
config
Type: object
Default value
auth:
mode: anonymous
database:
database: toolhive_registry
host: ''
port: 5432
sslMode: require
user: thv_user
registries:
- name: default
sources:
- toolhive
sources:
- git:
branch: main
path: pkg/catalog/toolhive/data/registry-upstream.json
repository: https://github.com/stacklok/toolhive-catalog.git
name: toolhive
syncPolicy:
interval: 30m
Registry Server configuration rendered into a Kubernetes ConfigMap. This block accepts application configuration fields beyond the defaults shown here. See Configuration for sources, registries, and sync policies, and Database for database settings. Supply passwords through Secret-backed environment variables rather than this block.
extraEnv
Type: list
Default: []
Additional environment variables to add to the container Use this for secrets, feature flags, or runtime configuration
extraEnvFrom
Type: list
Default: []
Additional environment variables from ConfigMap or Secret references
extraVolumes
Type: list
Default: []
Additional volumes to add to the pod
extraVolumeMounts
Type: list
Default: []
Additional volume mounts to add to the container
rbac
Type: object
Default: {"allowedNamespaces":[],"scope":"cluster"}
RBAC configuration for the registry server
rbac.scope
Type: string
Default: "cluster"
Scope of the RBAC configuration.
- cluster: The registry server will have cluster-wide permissions via ClusterRole and ClusterRoleBinding.
- namespace: The registry server will have permissions to watch resources in the
namespaces specified in
allowedNamespaces. The registry server will have a ClusterRole and RoleBinding for each namespace inallowedNamespaces.
rbac.allowedNamespaces
Type: list
Default: []
List of namespaces that the registry server is allowed to watch. Only used if scope is set to "namespace".