Values reference
This page lists the Helm values of the two Foundation4 charts and of the included charts, grouped by component, with type, default and effect. Keys that are unused or need care are marked. Operators who write the values file of a deployment need this page. Configuration reference describes the configuration that the values produce inside the containers.
Releases and values files
Foundation4 installs as two Helm releases in the namespace foundation4ai, and both releases read the same values file:
| Release | Chart | Top-level keys read |
|---|---|---|
foundation4ai-core | foundation4ai-core 0.3.0 | global, postgres, redis, nats, prometheus |
foundation4ai | foundation4ai 0.3.0 | global, api-server, dashboard, ingress, httpRoute |
Each release ignores the keys of the other release. The procedures of the Deploy and operate pages pass foundation4ai.values.yaml, the production values file that Install on Kubernetes creates; an evaluation installation passes evaluation.values.yaml in the same commands. The release names are fixed in practice: the application chart reads the Secret foundation4ai-core by name, and the cache reads the Secret foundation4ai-core-redis, so both releases keep the names above and share one namespace.
The core chart includes four charts: PostgreSQL 1.6.1 (key postgres), Valkey 0.9.3 as the Redis-compatible cache (key redis), NATS 2.12.4 (key nats) and Prometheus 28.9.1 (key prometheus). The application chart includes the api-server and dashboard charts. The following commands print the defaults of a chart and the values of an installed release:
helm show values ./charts/foundation4ai-core
helm show values ./charts/foundation4ai-core/charts/nats-2.12.4.tgz
helm get values foundation4ai -n foundation4ai
Expected result: the first two commands print the default values of the chart, and the last prints the values that the operator supplied to the release.
Profiles
The following values differ between the two deployment profiles. Install for evaluation uses the evaluation profile, and Install on Kubernetes describes the production profile.
| Key | Evaluation | Production |
|---|---|---|
postgres.enabled | true, bundled PostgreSQL on a temporary volume | false, external PostgreSQL through POSTGRES_URL |
api-server.replicaCount.worker | 1 | Default 3 or more |
api-server.resources | Not set | Requests and limits set |
| Image repositories | A registry, or images loaded onto the node | An internal registry or mirror |
ingress or httpRoute | Optional | Enabled, with TLS |
| Storage classes | Default StorageClass | Set for NATS JetStream and Prometheus |
Global values
| Key | Type | Default | Effect |
|---|---|---|---|
global.serverImageTag | String | None | Tag of the API server image, used by the API server, workers and hook Jobs. Required: without a tag, the image reference ends in :. |
global.grpcImageTag | String | None | Tag of the gRPC service image. Required. |
global.dashboardImageTag | String | None | Tag of the dashboard image. Required when the dashboard is enabled. |
global.imagePullSecrets | List | [] | Pull secrets. The Foundation4 charts read a list of name entries; Valkey reads a list of names. |
global.image.registry, global.image.pullSecretNames | String, list of names | None, [] | Registry prefix and pull secrets of the NATS images |
global.imageRegistry | String | "" | Registry prefix of the Valkey image |
global.secrets.existingSecret | String | foundation4ai-secrets | Secret that the core release reads. The application chart declares the key and does not read the key. |
The core release reads the following key names in foundation4ai-secrets. The first seven keys are declared in the values file; the others are read with the defaults shown.
| Key | Default | Read when |
|---|---|---|
global.secrets.postgresUrlKey | POSTGRES_URL | postgres.enabled is false |
global.secrets.postgresUserKey | POSTGRES_USER | postgres.enabled is true |
global.secrets.postgresUserPasswordKey | POSTGRES_PASSWORD | postgres.enabled is true |
global.secrets.postgresDatabaseKey | POSTGRES_DATABASE | postgres.enabled is true |
global.secrets.postgresSuperuserPasswordKey | POSTGRES_SUPERUSER_PASSWORD | Never; the PostgreSQL chart reads postgres.settings.superuserPassword.secretKey |
global.secrets.redisUrlKey | REDIS_URL | redis.enabled is false |
global.secrets.redisPasswordKey | REDIS_PASSWORD | redis.enabled is true |
global.secrets.natsUrlKey | NATS_URL | nats.enabled is false |
global.secrets.prometheusUrlKey | PROMETHEUS_URL | prometheus.enabled is false |
global.secrets.appLicenseKey, appSecretKey, appMasterKey, appMasterSecretKey | FOUNDATION4AI_APP_LICENSE, FOUNDATION4AI_APP_SECRET, FOUNDATION4AI_APP_MASTER_KEY, FOUNDATION4AI_APP_MASTER_SECRET | Always |
The comments in the values files describe secrets set directly as values and randomly generated secrets. Neither is implemented: every credential comes from foundation4ai-secrets, as described in Secrets and keys.
Core chart dependencies
| Key | Default | Effect when false |
|---|---|---|
postgres.enabled | false | The database URL comes from POSTGRES_URL |
redis.enabled | true | The cache URL comes from REDIS_URL |
nats.enabled | true | The NATS JetStream URL comes from NATS_URL, a key that foundation4ai.secrets.env.template does not list |
prometheus.enabled | true | The chart reads PROMETHEUS_URL, a key that the template does not list. No process uses the value. |
Disabling NATS JetStream or Prometheus without the corresponding key in foundation4ai-secrets is expected to stop the core release at render time (inferred). The operator adds NATS_URL, or PROMETHEUS_URL with any value, before disabling the dependency.
PostgreSQL
The bundled PostgreSQL serves the evaluation profile only. Database describes the external database of the production profile.
| Key | Default | Effect |
|---|---|---|
postgres.image.repository, postgres.image.tag | pgvector/pgvector, pg18-trixie | PostgreSQL 18 with the pgvector extension |
postgres.image.registry | Docker Hub (PostgreSQL chart default) | Registry of the image |
postgres.settings.existingSecret, postgres.settings.superuserPassword.secretKey | foundation4ai-secrets, POSTGRES_SUPERUSER_PASSWORD | Superuser password |
postgres.userDatabase.* | foundation4ai-secrets, keys POSTGRES_DATABASE, POSTGRES_USER, POSTGRES_PASSWORD | Application database and user |
postgres.customScripts.01-init-extension.sql | CREATE EXTENSION IF NOT EXISTS vector; | Creates the pgvector extension |
postgres.persistence.* | enabled: true, size: 8Gi | Not read by the PostgreSQL chart. The database stores data on a temporary pod volume. |
postgres.imagePullSecrets | [] | List of name entries |
postgres.resources | {} | No requests or limits |
Redis-compatible cache (Valkey)
| Key | Default | Effect |
|---|---|---|
redis.auth.enabled | true | Password authentication |
redis.auth.usersExistingSecret | foundation4ai-core-redis | Secret that the core chart creates from REDIS_PASSWORD, with the key default |
redis.auth.aclUsers.default.permissions | ~* &* +@all | Permissions of the default user |
redis.image.repository | valkey/valkey | Image; the tag defaults to the chart application version, 9.0.1 |
redis.dataStorage.enabled | false | Cache content lives in memory and is lost when the pod restarts |
redis.imagePullSecrets | [] | List of names |
redis.resources | {} | No requests or limits |
NATS JetStream
| Key | Default | Effect |
|---|---|---|
nats.config.cluster.enabled, nats.config.cluster.replicas | true, 3 | 3 NATS servers in a StatefulSet |
nats.config.jetstream.enabled | true | JetStream persistence, required by Foundation4 |
nats.config.jetstream.fileStore.pvc.size | 10Gi | Volume claim of each server |
nats.config.jetstream.fileStore.pvc.storageClassName | Not set | The default StorageClass applies |
nats.container.resources | {} | No requests or limits |
nats.podDisruptionBudget.enabled | true | A PodDisruptionBudget for the NATS servers |
nats.natsBox.enabled | true | The utility Deployment foundation4ai-core-nats-box, which carries the nats command-line tool |
nats.promExporter.enabled | false | Prometheus exporter for NATS server and JetStream metrics |
nats.container.image, nats.reloader.image, nats.natsBox.container.image | nats 2.12.4-alpine, natsio/nats-server-config-reloader 0.21.1, natsio/nats-box 0.19.3 | Images |
Prometheus
| Key | Default | Effect |
|---|---|---|
prometheus.alertmanager.enabled, prometheus.kube-state-metrics.enabled, prometheus.prometheus-node-exporter.enabled, prometheus.prometheus-pushgateway.enabled | false | Only the Prometheus server is installed |
prometheus.server.ingress.enabled | false | No external access to Prometheus |
prometheus.scrapeConfigs | null | Removes the default jobs of the Prometheus chart. Prometheus can fail at startup if a default job of the same name remains. |
prometheus.serverFiles.prometheus.yml.scrape_configs | Job kubernetes-pods | Scrapes pods annotated prometheus.io/app: foundation4ai and prometheus.io/scrape: "true" every 10 seconds |
prometheus.extraScrapeConfigs | "" | Further jobs, as YAML text |
prometheus.server.persistentVolume.size, prometheus.server.persistentVolume.storageClass | 8Gi, not set | Metrics volume |
prometheus.server.retention | 15d | Metrics retention |
prometheus.server.resources | {} | No requests or limits |
prometheus.imagePullSecrets | [] | List of name entries |
Monitoring and logging describes the scrape job and the worker metrics that the job misses.
API server and workers
The api-server chart creates the API server Deployment foundation4ai-api-server, the worker Deployment foundation4ai-api-server-worker, the Service foundation4ai-api-server, the hook ConfigMap and Secret foundation4ai-api-server and three hook Jobs.
| Key | Type | Default | Effect |
|---|---|---|---|
api-server.enabled | Boolean | true | Installs the chart |
api-server.secret | String | foundation4ai-core | Secret of the core release, loaded as environment variables and read by the hook Jobs |
api-server.replicaCount.server | Integer | 1 | API server replicas, when autoscaling is off |
api-server.replicaCount.worker | Integer | 3 | Worker replicas, when autoscaling is off |
api-server.image.repository | String | The provider's registry | API server image, also used by the workers and hook Jobs |
api-server.image.repositoryGrpc | String | The provider's registry | gRPC service image |
api-server.image.pullPolicy | String | IfNotPresent | Pull policy of both images |
api-server.image.tag, api-server.image.tagGrpc | String | "" | Tags that take precedence over the global tags |
api-server.imagePullSecrets | List | [] | Used by the worker pods and hook Jobs when global.imagePullSecrets is empty. The API server pod ignores the key. |
api-server.serviceAccount.create, automount, annotations, name | Mixed | true, true, {}, "" | ServiceAccount of the API server pods. The worker pods and hook Jobs use the namespace default ServiceAccount. |
api-server.podAnnotations | Map | {} | Added to the API server and worker pods, next to the fixed Prometheus annotations |
api-server.podLabels | Map | {} | Added to the API server pods only |
api-server.podSecurityContext | Map | {} | Pod security context of the API server and worker pods |
api-server.securityContext | Map | {} | Security context of the server, worker and both grpc containers |
api-server.service.type, api-server.service.port | String, integer | ClusterIP, 80 | Service of the API server, which targets container port 8000 |
api-server.resources | Map | {} | Requests and limits of the server, worker and both grpc containers. The hook Jobs receive none. |
api-server.autoscaling.server.* | Map | enabled: false, minReplicas: 1, maxReplicas: 100, targetCPUUtilizationPercentage: 80 | HorizontalPodAutoscaler of the API server. targetMemoryUtilizationPercentage adds a memory target. |
api-server.autoscaling.worker.* | Map | enabled: false, minReplicas: 3, maxReplicas: 100, targetCPUUtilizationPercentage: 80 | HorizontalPodAutoscaler of the workers |
api-server.nodeSelector, tolerations, affinity | Map, list, map | Empty | Scheduling of the API server and worker pods. The hook Jobs receive none. |
api-server.volumes, api-server.volumeMounts | List | [] | Declared for extra volumes. A non-empty value renders at the wrong indentation, so the manifests are expected to fail to parse (inferred). |
api-server.configs | Map of strings | {} | Entries of the ConfigMap, mounted in /app/config and loaded as environment variables |
api-server.secrets | Map of strings | Not declared | Entries of the Secret, mounted in /app/config and loaded as environment variables |
api-server.secretsAnnotations | Map | {} | Annotations of the Secret foundation4ai-api-server |
api-server.models, api-server.packages | List | Not declared | Model and package images, as described in Models, packages and air-gapped installs |
api-server.nameOverride, api-server.fullnameOverride | String | "" | Change object names. The ingress, the HTTPRoute and the Secret lookups assume the default names, so a deployment leaves both empty. |
Dashboard
| Key | Type | Default | Effect |
|---|---|---|---|
dashboard.enabled | Boolean | true | Installs the dashboard Deployment and Service foundation4ai-dashboard, container port 3000 |
dashboard.replicaCount | Integer | 1 | Dashboard replicas |
dashboard.image.repository, pullPolicy, tag | String | The provider's registry, IfNotPresent, "" | Dashboard image; the tag falls back to global.dashboardImageTag |
dashboard.imagePullSecrets | List | [] | Used when global.imagePullSecrets is empty |
dashboard.serviceAccount.*, podAnnotations, podLabels, podSecurityContext, securityContext | Mixed | Chart defaults | Standard pod settings |
dashboard.service.type, dashboard.service.port | String, integer | ClusterIP, 80 | Service of the dashboard |
dashboard.resources | Map | {} | Not read |
dashboard.livenessProbe | Map | Not declared | When set, the chart adds fixed liveness and readiness probes on / and renders the value of this key as the container resources. A probe definition in this key therefore produces an invalid manifest (inferred). |
dashboard.volumes, volumeMounts, nodeSelector, tolerations, affinity | Mixed | Empty | Standard pod settings |
The dashboard container therefore runs without probes and without resource settings by default. A map of requests and limits in dashboard.livenessProbe enables both the fixed probes and those resources (inferred), and a LimitRange in the namespace gives the container default requests and limits without that key.
Ingress and HTTPRoute
| Key | Default | Effect |
|---|---|---|
ingress.enabled | false | Creates the Ingress foundation4ai |
ingress.className | "" | Ingress class |
ingress.annotations | {} | Annotations of the Ingress |
ingress.hosts[].host | chart-example.local | Host names. Each host routes /dashboard to the dashboard and / to the API server. hosts[].paths is not read. |
ingress.tls | [] | TLS entries with secretName and hosts |
httpRoute.enabled | false | Creates the Gateway API HTTPRoute foundation4ai |
httpRoute.annotations | {} | Annotations of the HTTPRoute |
httpRoute.parentRefs | name: gateway, sectionName: http | Gateway and listener |
httpRoute.hostnames | chart-example.local | Host names |
The HTTPRoute sends /dashboard to the dashboard, redirects the exact path / to /dashboard and sends every other path to the API server. API and dashboard access describes both options.
The application chart also declares monitoring.enabled, monitoring.secret and monitoring.service.port. No template reads these keys.
Keys that need care
- Image tags. The comments state that an empty tag defaults to the chart version, but the templates fall back only to the global tag. The three global tags are required.
- Pull secrets. Valkey reads
global.imagePullSecretsas names while the Foundation4 charts readnameentries, so the values add the secret name underredis.imagePullSecrets, as described in Charts, images and installation bundle. Model and package pull secrets reach only the API server pod. - Resources. One
api-server.resourcesblock applies to the Foundation4 process and to the gRPC service in both Deployments. Scaling and performance describes sizing. - Worker metrics. The worker pods carry the Prometheus port annotation
8000, while the worker serves metrics on port 9090, so the scrape job does not collect worker metrics. - Bundled PostgreSQL.
postgres.persistencehas no effect, so the bundled database loses data when the pod is rescheduled. - Scrape configuration.
prometheus.scrapeConfigs: nullremoves the default jobs of the Prometheus chart. A restored defaultkubernetes-podsjob shares the name of the core chart job, and Troubleshooting describes the correction. - Rendering without a cluster. The Secrets of both releases read existing Secrets from the cluster at install time, so
helm templateand GitOps tools that render offline fail to render the charts or produce empty credentials. - Restarts. The hook ConfigMap and Secrets change without a pod restart, so every change to
configs,secretsor a credential is followed bykubectl rollout restart. - Extra volumes.
api-server.volumesandapi-server.volumeMountsare not usable in chart version 0.3.0. - Hook Jobs and workers. The hook Jobs take no resources, security context or scheduling values, and the worker pods take no
podLabelsand no ServiceAccount. A namespace with required resource limits, a restrictive Pod Security level or tainted nodes needs matching namespace defaults for these pods.
Production values example
The following values file sets the keys that a production installation usually sets. Every value in angle brackets is replaced. The API server runs 2 replicas so that the API stays available while one pod restarts.
global:
serverImageTag: "<api server image tag>"
grpcImageTag: "<grpc service image tag>"
dashboardImageTag: "<dashboard image tag>"
imagePullSecrets:
- name: <pull secret>
postgres:
enabled: false
nats:
config:
jetstream:
fileStore:
pvc:
storageClassName: <storage class>
prometheus:
server:
persistentVolume:
storageClass: <storage class>
api-server:
image:
repository: <registry>/foundation4ai-api
repositoryGrpc: <registry>/foundation4ai-grpc
replicaCount:
server: 2
worker: 3
resources:
requests:
cpu: <cpu request>
memory: <memory request>
limits:
memory: <memory limit>
dashboard:
image:
repository: <registry>/foundation4ai-dashboard
ingress:
enabled: true
className: <ingress class>
hosts:
- host: <host name>
tls:
- secretName: <tls secret>
hosts:
- <host name>