Skip to main content

Control Plane

Distribution support

Kubernetes (K8s) is the only supported distribution. K0s support was removed in vCluster v0.26 and K3s support was removed in v0.33. If your tenant clusters still use K3s, see the K3s to K8s migration guide before upgrading.

Config reference

controlPlane object

Configure vCluster's control plane components and deployment.

endpoint string

Endpoint is the endpoint of the virtual cluster. This is used to connect to the virtual cluster.

distro object

Distro holds virtual cluster related distro options. A distro cannot be changed after vCluster is deployed.

k8s object

K8S holds K8s relevant configuration.

enabled boolean false

Enabled specifies if the K8s distro should be enabled. Only one distro can be enabled at the same time.

version string

Version is the Kubernetes version to use.

apiServer object

APIServer holds configuration specific to starting the api server.

enabled boolean true

Enabled signals this container should be enabled.

command string[] []

Command is the command to start the distro binary. This will override the existing command.

extraArgs string[] []

ExtraArgs are additional arguments to pass to the distro binary.

controllerManager object

ControllerManager holds configuration specific to starting the controller manager.

enabled boolean true

Enabled signals this container should be enabled.

command string[] []

Command is the command to start the distro binary. This will override the existing command.

extraArgs string[] []

ExtraArgs are additional arguments to pass to the distro binary.

scheduler object

Scheduler holds configuration specific to starting the scheduler.

enabled boolean false

Enabled signals this container should be enabled.

command string[] []

Command is the command to start the distro binary. This will override the existing command.

extraArgs string[] []

ExtraArgs are additional arguments to pass to the distro binary.

image object

Image is the distro image

registry string ghcr.io

Registry is the registry of the container image, e.g. my-registry.com or ghcr.io. This setting can be globally overridden via the controlPlane.advanced.defaultImageRegistry option. Empty means docker hub.

repository string loft-sh/kubernetes

Repository is the repository of the container image, e.g. my-repo/my-image

tag string v1.36.0

Tag is the tag of the container image, and is the default version.

imagePullPolicy string

ImagePullPolicy is the pull policy for the distro image

env object[] []

Env are extra environment variables to use for the main container and NOT the init container.

resources object map[limits:map[cpu:100m memory:256Mi] requests:map[cpu:40m memory:64Mi]]

Resources for the distro init container

securityContext object {}

Security options can be used for the distro init container

standalone object

Standalone holds configuration for standalone mode. Standalone mode is set automatically when no container is detected and also implies privateNodes.enabled.

enabled boolean

Enabled defines if standalone mode should be enabled.

dataDir string /var/lib/vcluster

DataDir defines the data directory for the standalone mode.

autoNodes object

AutoNodes automatically deploys nodes for standalone mode.

provider string

Provider is the node provider of the nodes in this pool.

quantity integer

Quantity is the number of nodes to deploy for standalone mode.

nodeTypeSelector object[]

NodeTypeSelector filters the types of nodes that can be provisioned by this pool. All requirements must be met for a node type to be eligible.

property required string

Property is the property on the node type to select.

operator string

Operator is the comparison operator, such as "In", "NotIn", "Exists". If empty, defaults to "In".

values string[]

Values is the list of values to use for comparison. This is mutually exclusive with value.

value string

Value is the value to use for comparison. This is mutually exclusive with values.

joinNode object

JoinNode holds configuration for the standalone control plane node.

enabled boolean true

Enabled defines if the standalone node should be joined into the cluster. If false, only the control plane binaries will be executed and no node will show up in the actual cluster.

preInstallCommands string[]

PreInstallCommands are commands that will be executed before containerd, kubelet etc. is installed.

preJoinCommands string[]

PreJoinCommands are commands that will be executed before kubeadm join is executed.

postJoinCommands string[]

PostJoinCommands are commands that will be executed after kubeadm join is executed.

containerd object

Containerd holds configuration for the containerd join process.

enabled boolean true

Enabled defines if containerd should be installed and configured by vCluster.

registry object

Registry holds configuration for how containerd should be configured to use a registries.

configPath string

ConfigPath is the path to the containerd registry config.

mirrors {key: object}

Mirrors holds configuration for the containerd registry mirrors. E.g. myregistry.io:5000 or docker.io. See https://github.com/containerd/containerd/blob/main/docs/hosts.md for more details.

server string

Server is the fallback server to use for the containerd registry mirror. E.g. https://registry-1.docker.io. See https://github.com/containerd/containerd/blob/main/docs/hosts.md for more details.

caCert string[]

CACert are paths to CA certificates to use for the containerd registry mirror.

skipVerify boolean

SkipVerify is a boolean to skip the certificate verification for the containerd registry mirror and allows http connections.

capabilities string[]

Capabilities is a list of capabilities to enable for the containerd registry mirror. If empty, will use pull and resolve capabilities.

overridePath boolean

OverridePath is a boolean to override the path for the containerd registry mirror.

hosts object[]

Hosts holds configuration for the containerd registry mirror hosts. See https://github.com/containerd/containerd/blob/main/docs/hosts.md for more details.

server string

Server is the server to use for the containerd registry mirror host. E.g. http://192.168.31.250:5000.

caCert string[]

CACert are paths to CA certificates to use for the containerd registry mirror host.

skipVerify boolean

SkipVerify is a boolean to skip the certificate verification for the containerd registry mirror and allows http connections.

capabilities string[]

Capabilities is a list of capabilities to enable for the containerd registry mirror. If empty, will use pull and resolve capabilities.

overridePath boolean

OverridePath is a boolean to override the path for the containerd registry mirror.

auth {key: object}

Auth holds configuration for the containerd registry auth. See https://github.com/containerd/containerd/blob/main/docs/cri/registry.md#configure-registry-credentials for more details.

username string

Username is the username for the containerd registry.

password string

Password is the password for the containerd registry.

identityToken string

IdentityToken is the token for the containerd registry.

auth string

Auth is the auth config for the containerd registry.

pauseImage string

PauseImage is the image for the pause container.

caCertPath string

CACertPath is the path to the SSL certificate authority used to secure communications between node and control-plane. Defaults to "/etc/kubernetes/pki/ca.crt".

skipPhases string[]

SkipPhases is a list of phases to skip during command execution. The list of phases can be obtained with the "kubeadm join --help" command.

nodeRegistration object

NodeRegistration holds configuration for the node registration similar to the kubeadm node registration.

criSocket string

CRI socket is the socket for the CRI.

kubeletExtraArgs object[]

KubeletExtraArgs passes through extra arguments to the kubelet. The arguments here are passed to the kubelet command line via the environment file kubeadm writes at runtime for the kubelet to source. This overrides the generic base-level configuration in the kubelet-config ConfigMap Flags have higher priority when parsing. These values are local and specific to the node kubeadm is executing on. An argument name in this list is the flag name as it appears on the command line except without leading dash(es). Extra arguments will override existing default arguments. Duplicate extra arguments are allowed.

name string

Name is the name of the argument.

value string

Value is the value of the argument.

taints object[]

Taints are additional taints to set for the kubelet.

key string

Required. The taint key to be applied to a node.

value string

The taint value corresponding to the taint key.

effect string

Required. The effect of the taint on pods that do not tolerate the taint. Valid effects are NoSchedule, PreferNoSchedule and NoExecute.

ignorePreflightErrors string[]

IgnorePreflightErrors provides a slice of pre-flight errors to be ignored when the current node is registered, e.g. 'IsPrivilegedUser,Swap'. Value 'all' ignores errors from all checks.

imagePullPolicy string

ImagePullPolicy specifies the policy for image pulling during kubeadm "init" and "join" operations. The value of this field must be one of "Always", "IfNotPresent" or "Never". If this field is unset kubeadm will default it to "IfNotPresent", or pull the required images if not present on the host.

backingStore object

BackingStore defines which backing store to use for virtual cluster. If not defined will use embedded database as a default backing store.

etcd object

Etcd defines that etcd should be used as the backend for the virtual cluster

embedded object

Embedded defines to use embedded etcd as a storage backend for the virtual cluster

enabled boolean false

Enabled defines if the embedded etcd should be used.

migrateFromDeployedEtcd boolean false

MigrateFromDeployedEtcd signals that vCluster should migrate from the deployed external etcd to embedded etcd.

snapshotCount integer

SnapshotCount defines the number of snapshots to keep for the embedded etcd. Defaults to 10000 if less than 1.

extraArgs string[] []

ExtraArgs are additional arguments to pass to the embedded etcd.

deploy object

Deploy defines to use an external etcd that is deployed by the helm chart

enabled boolean false

Enabled defines that an external etcd should be deployed.

statefulSet object

StatefulSet holds options for the external etcd statefulSet.

enabled boolean true

Enabled defines if the statefulSet should be deployed

EnableServiceLinks for the StatefulSet pod

image object

Image is the image to use for the external etcd statefulSet

registry string registry.k8s.io

Registry is the registry of the container image, e.g. my-registry.com or ghcr.io. This setting can be globally overridden via the controlPlane.advanced.defaultImageRegistry option. Empty means docker hub.

repository string etcd

Repository is the repository of the container image, e.g. my-repo/my-image

tag string 3.6.8-0

Tag is the tag of the container image, and is the default version.

imagePullPolicy string

ImagePullPolicy is the pull policy for the external etcd image

env object[] []

Env are extra environment variables

extraArgs string[] []

ExtraArgs are appended to the etcd command.

resources object

Resources the etcd can consume

limits object

Limits are resource limits for the container

requests object map[cpu:20m memory:150Mi]

Requests are minimal resources that will be consumed by the container

pods object

Pods defines extra metadata for the etcd pods.

annotations object {}

Annotations are extra annotations for this resource.

labels object {}

Labels are extra labels for this resource.

highAvailability object

HighAvailability are high availability options

replicas integer 1

Replicas are the amount of pods to use.

scheduling object

Scheduling options for the etcd pods.

nodeSelector object {}

NodeSelector is the node selector to apply to the pod.

affinity object {}

Affinity is the affinity to apply to the pod.

tolerations object[] []

Tolerations are the tolerations to apply to the pod.

priorityClassName string

PriorityClassName is the priority class name for the the pod.

podManagementPolicy string Parallel

PodManagementPolicy is the statefulSet pod management policy.

topologySpreadConstraints object[] []

TopologySpreadConstraints are the topology spread constraints for the pod.

security object

Security options for the etcd pods.

podSecurityContext object {}

PodSecurityContext specifies security context options on the pod level.

containerSecurityContext object {}

ContainerSecurityContext specifies security context options on the container level.

persistence object

Persistence options for the etcd pods.

volumeClaim object

VolumeClaim can be used to configure the persistent volume claim.

enabled boolean true

Enabled enables deploying a persistent volume claim.

accessModes string[] [ReadWriteOnce]

AccessModes are the persistent volume claim access modes.

retentionPolicy string Retain

RetentionPolicy is the persistent volume claim retention policy.

size string 5Gi

Size is the persistent volume claim storage size.

storageClass string

StorageClass is the persistent volume claim storage class.

volumeClaimTemplates object[] []

VolumeClaimTemplates defines the volumeClaimTemplates for the statefulSet

addVolumes object[] []

AddVolumes defines extra volumes for the pod

addVolumeMounts object[]

AddVolumeMounts defines extra volume mounts for the container

name string

This must match the Name of a Volume.

readOnly boolean

Mounted read-only if true, read-write otherwise (false or unspecified). Defaults to false.

mountPath string

Path within the container at which the volume should be mounted. Must not contain ':'.

subPath string

Path within the volume from which the container's volume should be mounted. Defaults to "" (volume's root).

mountPropagation string

mountPropagation determines how mounts are propagated from the host to container and the other way around. When not set, MountPropagationNone is used. This field is beta in 1.10.

subPathExpr string

Expanded path within the volume from which the container's volume should be mounted. Behaves similarly to SubPath but environment variable references $(VAR_NAME) are expanded using the container's environment. Defaults to "" (volume's root). SubPathExpr and SubPath are mutually exclusive.

annotations object {}

Annotations are extra annotations for this resource.

labels object {}

Labels are extra labels for this resource.

service object

Service holds options for the external etcd service.

enabled boolean true

Enabled defines if the etcd service should be deployed

annotations object {}

Annotations are extra annotations for the external etcd service

headlessService object

HeadlessService holds options for the external etcd headless service.

annotations object {}

Annotations are extra annotations for the external etcd headless service

external object

External defines to use a self-hosted external etcd that is not deployed by the helm chart

enabled boolean false

Enabled defines if the external etcd should be used.

endpoint string

Endpoint holds the endpoint of the external etcd server, e.g. my-example-service:2379

tls object

TLS defines the tls configuration for the external etcd server

caFile string

CaFile is the path to the ca file

certFile string

CertFile is the path to the cert file

keyFile string

KeyFile is the path to the key file

database object

Database defines that a database backend should be used as the backend for the virtual cluster. This uses a project called kine under the hood which is a shim for bridging Kubernetes and relational databases.

embedded object

Embedded defines that an embedded database (sqlite) should be used as the backend for the virtual cluster

enabled boolean false

Enabled defines if the database should be used.

dataSource string

DataSource is the kine dataSource to use for the database. This depends on the database format. This is optional for the external database. Examples:

  • mysql: mysql://username:password@tcp(hostname:3306)/vcluster
  • postgres: postgres://username:password@hostname:5432/vcluster
identityProvider string

IdentityProvider is the kine identity provider to use when generating temporary authentication tokens for enhanced security. This is optional for the external database. Examples:

  • aws: RDS IAM Authentication
keyFile string

KeyFile is the key file to use for the database. This is optional.

certFile string

CertFile is the cert file to use for the database. This is optional.

caFile string

CaFile is the ca file to use for the database. This is optional.

extraArgs string[] []

ExtraArgs are additional arguments to pass to Kine.

external object

External defines that an external database should be used as the backend for the virtual cluster

enabled boolean false

Enabled defines if the database should be used.

dataSource string

DataSource is the kine dataSource to use for the database. This depends on the database format. This is optional for the external database. Examples:

  • mysql: mysql://username:password@tcp(hostname:3306)/vcluster
  • postgres: postgres://username:password@hostname:5432/vcluster
identityProvider string

IdentityProvider is the kine identity provider to use when generating temporary authentication tokens for enhanced security. This is optional for the external database. Examples:

  • aws: RDS IAM Authentication
keyFile string

KeyFile is the key file to use for the database. This is optional.

certFile string

CertFile is the cert file to use for the database. This is optional.

caFile string

CaFile is the ca file to use for the database. This is optional.

extraArgs string[] []

ExtraArgs are additional arguments to pass to Kine.

connector string

Connector specifies a secret located in a connected vCluster Platform that contains database server connection information to be used by Platform to create a database and database user for the vCluster. and non-privileged user. A kine endpoint should be created using the database and user on Platform registration. This is optional.

coredns object

CoreDNS defines everything related to the coredns that is deployed and used within the vCluster.

enabled boolean true

Enabled defines if coredns is enabled

embedded boolean false

Embedded defines if vCluster will start the embedded coredns service within the control-plane and not as a separate deployment. This is a PRO feature.

security object

Security defines pod or container security context.

podSecurityContext object {}

PodSecurityContext specifies security context options on the pod level.

containerSecurityContext object {}

ContainerSecurityContext specifies security context options on the container level.

service object

Service holds extra options for the coredns service deployed within the virtual cluster

spec object map[type:ClusterIP]

Spec holds extra options for the coredns service

annotations object {}

Annotations are extra annotations for this resource.

labels object {}

Labels are extra labels for this resource.

deployment object

Deployment holds extra options for the coredns deployment deployed within the virtual cluster

image string

Image is the coredns image to use

replicas integer 1

Replicas is the amount of coredns pods to run.

nodeSelector object {}

NodeSelector is the node selector to use for coredns.

affinity object {}

Affinity is the affinity to apply to the pod.

tolerations object[] []

Tolerations are the tolerations to apply to the pod.

resources object

Resources are the desired resources for coredns.

limits object map[cpu:1000m memory:170Mi]

Limits are resource limits for the container

requests object map[cpu:20m memory:64Mi]

Requests are minimal resources that will be consumed by the container

pods object

Pods is additional metadata for the coredns pods.

annotations object {}

Annotations are extra annotations for this resource.

labels object {}

Labels are extra labels for this resource.

annotations object {}

Annotations are extra annotations for this resource.

labels object {}

Labels are extra labels for this resource.

topologySpreadConstraints object[] [map[labelSelector:map[matchLabels:map[k8s-app:vcluster-kube-dns]] maxSkew:1 topologyKey:kubernetes.io/hostname whenUnsatisfiable:DoNotSchedule]]

TopologySpreadConstraints are the topology spread constraints for the CoreDNS pod.

overwriteConfig string

OverwriteConfig can be used to overwrite the coredns config

overwriteManifests string

OverwriteManifests can be used to overwrite the coredns manifests used to deploy coredns

priorityClassName string

PriorityClassName specifies the priority class name for the CoreDNS pods.

proxy object

Proxy defines options for the virtual cluster control plane proxy that is used to do authentication and intercept requests.

bindAddress string 0.0.0.0

BindAddress under which vCluster will expose the proxy.

port integer 8443

Port under which vCluster will expose the proxy. Changing port is currently not supported.

extraSANs string[] []

ExtraSANs are extra hostnames to sign the vCluster proxy certificate for.

hostPathMapper object

HostPathMapper defines if vCluster should rewrite host paths.

enabled boolean

Enabled specifies if the host path mapper will be used

central boolean

Central specifies if the central host path mapper will be used

ingress object

Ingress defines options for vCluster ingress deployed by Helm.

enabled boolean false

Enabled defines if the control plane ingress should be enabled

host string my-host.com

Host is the host where vCluster will be reachable

pathType string ImplementationSpecific

PathType is the path type of the ingress

spec object map[tls:[]]

Spec allows you to configure extra ingress options.

annotations object map[nginx.ingress.kubernetes.io/backend-protocol:HTTPS nginx.ingress.kubernetes.io/ssl-passthrough:true nginx.ingress.kubernetes.io/ssl-redirect:true]

Annotations are extra annotations for this resource.

labels object {}

Labels are extra labels for this resource.

tlsRoute object

TLSRoute defines options for vCluster TLS route deployed by Helm.

enabled boolean false

Enabled defines if the control plane should be exposed via a gateway api tls route. Make sure to enable tls passthrough in the gateway via tls.mode to "Passthrough"

apiVersion string gateway.networking.k8s.io/v1

APIVersion is the version of the gateway api tls route.

host string my-host.com

Host is the host where vCluster will be reachable

parentRefs object[] []

ParentRefs are the parent references for the TLS route

spec object {}

Spec allows you to configure extra tls route options.

annotations object {}

Annotations are extra annotations for this resource.

labels object {}

Labels are extra labels for this resource.

service object

Service defines options for vCluster service deployed by Helm.

enabled boolean true

Enabled defines if the control plane service should be enabled

spec object map[type:ClusterIP]

Spec allows you to configure extra service options.

kubeletNodePort integer 0

KubeletNodePort is the node port where the fake kubelet is exposed. Defaults to 0.

httpsNodePort integer 0

HTTPSNodePort is the node port where https is exposed. Defaults to 0.

annotations object {}

Annotations are extra annotations for this resource.

labels object {}

Labels are extra labels for this resource.

statefulSet object

StatefulSet defines options for vCluster statefulSet deployed by Helm.

highAvailability object

HighAvailability holds options related to high availability.

replicas integer 1

Replicas is the amount of replicas to use for the statefulSet.

leaseDuration integer 60

LeaseDuration is the time to lease for the leader.

renewDeadline integer 40

RenewDeadline is the deadline to renew a lease for the leader.

retryPeriod integer 15

RetryPeriod is the time until a replica will retry to get a lease.

resources object

Resources are the resource requests and limits for the statefulSet container.

limits object map[ephemeral-storage:10Gi memory:4Gi]

Limits are resource limits for the container

requests object map[cpu:200m ephemeral-storage:1Gi memory:256Mi]

Requests are minimal resources that will be consumed by the container

scheduling object

Scheduling holds options related to scheduling.

nodeSelector object {}

NodeSelector is the node selector to apply to the pod.

affinity object {}

Affinity is the affinity to apply to the pod.

tolerations object[] []

Tolerations are the tolerations to apply to the pod.

priorityClassName string

PriorityClassName is the priority class name for the the pod.

podManagementPolicy string Parallel

PodManagementPolicy is the statefulSet pod management policy.

topologySpreadConstraints object[] []

TopologySpreadConstraints are the topology spread constraints for the pod.

security object

Security defines pod or container security context.

podSecurityContext object {}

PodSecurityContext specifies security context options on the pod level.

containerSecurityContext object map[allowPrivilegeEscalation:false runAsGroup:0 runAsUser:0]

ContainerSecurityContext specifies security context options on the container level.

probes object

Probes enables or disables the main container probes.

livenessProbe object

LivenessProbe specifies if the liveness probe for the container should be enabled

enabled boolean true

Enabled defines if this option should be enabled.

failureThreshold integer 60

Number of consecutive failures for the probe to be considered failed

initialDelaySeconds integer 60

Time (in seconds) to wait before starting the liveness probe

timeoutSeconds integer 3

Maximum duration (in seconds) that the probe will wait for a response.

periodSeconds integer 2

Frequency (in seconds) to perform the probe

readinessProbe object

ReadinessProbe specifies if the readiness probe for the container should be enabled

enabled boolean true

Enabled defines if this option should be enabled.

failureThreshold integer 60

Number of consecutive failures for the probe to be considered failed

timeoutSeconds integer 3

Maximum duration (in seconds) that the probe will wait for a response.

periodSeconds integer 2

Frequency (in seconds) to perform the probe

startupProbe object

StartupProbe specifies if the startup probe for the container should be enabled

enabled boolean true

Enabled defines if this option should be enabled.

failureThreshold integer 300

Number of consecutive failures allowed before failing the pod

timeoutSeconds integer 3

Maximum duration (in seconds) that the probe will wait for a response.

periodSeconds integer 6

Frequency (in seconds) to perform the probe

persistence object

Persistence defines options around persistence for the statefulSet.

volumeClaim object

VolumeClaim can be used to configure the persistent volume claim.

enabled string|boolean auto

Enabled enables deploying a persistent volume claim. If auto, vCluster will automatically determine based on the chosen distro and other options if this is required.

accessModes string[] [ReadWriteOnce]

AccessModes are the persistent volume claim access modes.

retentionPolicy string Retain

RetentionPolicy is the persistent volume claim retention policy.

size string 5Gi

Size is the persistent volume claim storage size.

storageClass string

StorageClass is the persistent volume claim storage class.

volumeClaimTemplates object[] []

VolumeClaimTemplates defines the volumeClaimTemplates for the statefulSet

dataVolume object[] []

Allows you to override the dataVolume. Only works correctly if volumeClaim.enabled=false.

binariesVolume object[] [map[emptyDir:map[] name:binaries]]

BinariesVolume defines a binaries volume that is used to retrieve distro specific executables to be run by the syncer controller. This volume doesn't need to be persistent.

addVolumes object[] []

AddVolumes defines extra volumes for the pod

addVolumeMounts object[]

AddVolumeMounts defines extra volume mounts for the container

name string

This must match the Name of a Volume.

readOnly boolean

Mounted read-only if true, read-write otherwise (false or unspecified). Defaults to false.

mountPath string

Path within the container at which the volume should be mounted. Must not contain ':'.

subPath string

Path within the volume from which the container's volume should be mounted. Defaults to "" (volume's root).

mountPropagation string

mountPropagation determines how mounts are propagated from the host to container and the other way around. When not set, MountPropagationNone is used. This field is beta in 1.10.

subPathExpr string

Expanded path within the volume from which the container's volume should be mounted. Behaves similarly to SubPath but environment variable references $(VAR_NAME) are expanded using the container's environment. Defaults to "" (volume's root). SubPathExpr and SubPath are mutually exclusive.

EnableServiceLinks for the StatefulSet pod

annotations object {}

Annotations are extra annotations for this resource.

labels object {}

Labels are extra labels for this resource.

pods object

Additional labels or annotations for the statefulSet pods.

annotations object {}

Annotations are extra annotations for this resource.

labels object {}

Labels are extra labels for this resource.

image object

Image is the image for the controlPlane statefulSet container It defaults to the vCluster pro repository that includes the optional pro modules that are turned off by default. If you still want to use the pure OSS build, set the repository to 'loft-sh/vcluster-oss'.

registry string ghcr.io

Registry is the registry of the container image, e.g. my-registry.com or ghcr.io. This setting can be globally overridden via the controlPlane.advanced.defaultImageRegistry option. Empty means docker hub.

repository string loft-sh/vcluster-pro

Repository is the repository of the container image, e.g. my-repo/my-image

tag string

Tag is the tag of the container image, and is the default version.

imagePullPolicy string

ImagePullPolicy is the policy how to pull the image.

workingDir string

WorkingDir specifies in what folder the main process should get started.

command string[] []

Command allows you to override the main command.

args string[] []

Args allows you to override the main arguments.

env object[] []

Env are additional environment variables for the statefulSet container.

dnsPolicy string

Set DNS policy for the pod.

dnsConfig object

Specifies the DNS parameters of a pod.

nameservers string[]

A list of DNS name server IP addresses. This will be appended to the base nameservers generated from DNSPolicy. Duplicated nameservers will be removed.

searches string[]

A list of DNS search domains for host-name lookup. This will be appended to the base search paths generated from DNSPolicy. Duplicated search paths will be removed.

options object[]

A list of DNS resolver options. This will be merged with the base options generated from DNSPolicy. Duplicated entries will be removed. Resolution options given in Options will override those that appear in the base DNSPolicy.

name string

Required.

value string

initContainers object[] []

InitContainers are additional init containers for the statefulSet.

sidecarContainers object[] []

SidecarContainers are additional sidecar containers for the statefulSet.

hostAliases object[]

HostAliases allows you to add custom entries to the /etc/hosts file of each Pod created.

ip string
hostnames string[]

runtimeClassName string

RuntimeClassName is the runtime class to set for the statefulSet pods.

serviceMonitor object

ServiceMonitor can be used to automatically create a service monitor for vCluster deployment itself.

enabled boolean false

Enabled configures if Helm should create the service monitor.

labels object {}

Labels are the extra labels to add to the service monitor.

annotations object {}

Annotations are the extra annotations to add to the service monitor.

advanced object

Advanced holds additional configuration for the vCluster control plane.

defaultImageRegistry string

DefaultImageRegistry will be used as a prefix for all internal images deployed by vCluster or Helm. This makes it easy to upload all required vCluster images to a single private repository and set this value. Workload images are not affected by this.

virtualScheduler object

VirtualScheduler defines if a scheduler should be used within the virtual cluster or the scheduling decision for workloads will be made by the host cluster. Deprecated: Use ControlPlane.Distro.K8S.Scheduler instead.

enabled boolean false

Enabled defines if this option should be enabled.

serviceAccount object

ServiceAccount specifies options for the vCluster control plane service account.

enabled boolean true

Enabled specifies if the service account should get deployed.

name string

Name specifies what name to use for the service account.

imagePullSecrets object[]

ImagePullSecrets defines extra image pull secrets for the service account.

name string

Name of the image pull secret to use.

annotations object {}

Annotations are extra annotations for this resource.

labels object {}

Labels are extra labels for this resource.

workloadServiceAccount object

WorkloadServiceAccount specifies options for the service account that will be used for the workloads that run within the virtual cluster.

enabled boolean true

Enabled specifies if the service account for the workloads should get deployed.

name string

Name specifies what name to use for the service account for the virtual cluster workloads.

imagePullSecrets object[]

ImagePullSecrets defines extra image pull secrets for the workload service account.

name string

Name of the image pull secret to use.

annotations object {}

Annotations are extra annotations for this resource.

labels object {}

Labels are extra labels for this resource.

headlessService object

HeadlessService specifies options for the headless service used for the vCluster StatefulSet.

annotations object {}

Annotations are extra annotations for this resource.

labels object {}

Labels are extra labels for this resource.

konnectivity object

Konnectivity holds dedicated konnectivity configuration. This is only available when privateNodes.enabled is true.

server object

Server holds configuration for the konnectivity server.

enabled boolean true

Enabled defines if the konnectivity server should be enabled.

extraArgs string[] []

ExtraArgs are additional arguments to pass to the konnectivity server.

agent object

Agent holds configuration for the konnectivity agent.

enabled boolean true

Enabled defines if the konnectivity agent should be enabled.

replicas integer 1

Replicas is the number of replicas for the konnectivity agent.

image string

Image is the image for the konnectivity agent.

imagePullPolicy string

ImagePullPolicy is the policy how to pull the image.

nodeSelector object {}

NodeSelector is the node selector for the konnectivity agent.

priorityClassName string

PriorityClassName is the priority class name for the konnectivity agent.

tolerations object[] []

Tolerations is the tolerations for the konnectivity agent.

extraEnv object[] []

ExtraEnv is the extra environment variables for the konnectivity agent.

extraArgs string[] []

ExtraArgs are additional arguments to pass to the konnectivity agent.

registry object

Registry allows enabling an embedded docker image registry in vCluster. This is useful for air-gapped environments or when you don't have a public registry available to distribute images.

enabled boolean false

Enabled defines if the embedded registry should be enabled.

anonymousPull boolean true

AnonymousPull allows enabling anonymous pull for the embedded registry. This allows anybody to pull images from the registry without authentication.

config object {}

Config is the regular docker registry config. See https://distribution.github.io/distribution/about/configuration/ for more details.

cloudControllerManager object

CloudControllerManager holds configuration for the embedded cloud controller manager. This is only available when private nodes are enabled. The cloud controller manager is responsible for setting the node's ip addresses as well as the provider id for the node and other node metadata.

enabled boolean true

Enabled defines if the embedded cloud controller manager should be enabled. This defaults to true, but can be disabled if you want to use an external cloud controller manager such as AWS or GCP. The cloud controller manager is responsible for setting the node's ip addresses as well as the provider id for the node and other node metadata.

globalMetadata object

GlobalMetadata is metadata that will be added to all resources deployed by Helm.

annotations object {}

Annotations are extra annotations for this resource.

kubeVip object

KubeVip holds configuration for embedded kube-vip that announces the virtual cluster endpoint IP on layer 2.

enabled boolean false

Enabled defines if embedded kube-vip should be enabled.

interface string

Interface is the network interface on which the VIP is announced.

gateway string

Gateway is the gateway address in CIDR notation (e.g., 10.100.0.1/24). This is used to configure policy-based routing for the VIP and must include the subnet prefix.

podDisruptionBudget object

PodDisruptionBudget limits how many pods of an application can be voluntarily disrupted at once to ensure availability during maintenance or scaling operations.

enabled boolean false

Enabled defines if the pod disruption budget should be enabled.

minAvailable object

MinAvailable describes the minimal number or percentage of available pods.

maxUnavailable object

MaxUnavailable describes the minimal number or percentage of unavailable pods.

unhealthyPodEvictionPolicy string

UnhealthyPodEvictionPolicy defines the criteria when unhealthy pods should be considered for eviction. Currently supported values are:

  • IfHealthyBudget - pods that are in the Running phase but not yet healthy are considered disrupted and may be evicted even if the PodDisruptionBudget criteria are not met.
  • AlwaysAllow - pods that are in the Running phase but not yet healthy are considered disrupted and can be evicted regardless of whether the criteria in a PDB is met.