Skip to main content

Values reference

This page lists the Helm values of the two Foundation4 charts and of the included charts, grouped by component, with type, default and effect. Keys that are unused or need care are marked. Operators who write the values file of a deployment need this page. Configuration reference describes the configuration that the values produce inside the containers.

Releases and values files​

Foundation4 installs as two Helm releases in the namespace foundation4ai, and both releases read the same values file:

ReleaseChartTop-level keys read
foundation4ai-corefoundation4ai-core 0.3.0global, postgres, redis, nats, prometheus
foundation4aifoundation4ai 0.3.0global, api-server, dashboard, ingress, httpRoute

Each release ignores the keys of the other release. The procedures of the Deploy and operate pages pass foundation4ai.values.yaml, the production values file that Install on Kubernetes creates; an evaluation installation passes evaluation.values.yaml in the same commands. The release names are fixed in practice: the application chart reads the Secret foundation4ai-core by name, and the cache reads the Secret foundation4ai-core-redis, so both releases keep the names above and share one namespace.

The core chart includes four charts: PostgreSQL 1.6.1 (key postgres), Valkey 0.9.3 as the Redis-compatible cache (key redis), NATS 2.12.4 (key nats) and Prometheus 28.9.1 (key prometheus). The application chart includes the api-server and dashboard charts. The following commands print the defaults of a chart and the values of an installed release:

helm show values ./charts/foundation4ai-core
helm show values ./charts/foundation4ai-core/charts/nats-2.12.4.tgz
helm get values foundation4ai -n foundation4ai

Expected result: the first two commands print the default values of the chart, and the last prints the values that the operator supplied to the release.

Profiles​

The following values differ between the two deployment profiles. Install for evaluation uses the evaluation profile, and Install on Kubernetes describes the production profile.

KeyEvaluationProduction
postgres.enabledtrue, bundled PostgreSQL on a temporary volumefalse, external PostgreSQL through POSTGRES_URL
api-server.replicaCount.worker1Default 3 or more
api-server.resourcesNot setRequests and limits set
Image repositoriesA registry, or images loaded onto the nodeAn internal registry or mirror
ingress or httpRouteOptionalEnabled, with TLS
Storage classesDefault StorageClassSet for NATS JetStream and Prometheus

Global values​

KeyTypeDefaultEffect
global.serverImageTagStringNoneTag of the API server image, used by the API server, workers and hook Jobs. Required: without a tag, the image reference ends in :.
global.grpcImageTagStringNoneTag of the gRPC service image. Required.
global.dashboardImageTagStringNoneTag of the dashboard image. Required when the dashboard is enabled.
global.imagePullSecretsList[]Pull secrets. The Foundation4 charts read a list of name entries; Valkey reads a list of names.
global.image.registry, global.image.pullSecretNamesString, list of namesNone, []Registry prefix and pull secrets of the NATS images
global.imageRegistryString""Registry prefix of the Valkey image
global.secrets.existingSecretStringfoundation4ai-secretsSecret that the core release reads. The application chart declares the key and does not read the key.

The core release reads the following key names in foundation4ai-secrets. The first seven keys are declared in the values file; the others are read with the defaults shown.

KeyDefaultRead when
global.secrets.postgresUrlKeyPOSTGRES_URLpostgres.enabled is false
global.secrets.postgresUserKeyPOSTGRES_USERpostgres.enabled is true
global.secrets.postgresUserPasswordKeyPOSTGRES_PASSWORDpostgres.enabled is true
global.secrets.postgresDatabaseKeyPOSTGRES_DATABASEpostgres.enabled is true
global.secrets.postgresSuperuserPasswordKeyPOSTGRES_SUPERUSER_PASSWORDNever; the PostgreSQL chart reads postgres.settings.superuserPassword.secretKey
global.secrets.redisUrlKeyREDIS_URLredis.enabled is false
global.secrets.redisPasswordKeyREDIS_PASSWORDredis.enabled is true
global.secrets.natsUrlKeyNATS_URLnats.enabled is false
global.secrets.prometheusUrlKeyPROMETHEUS_URLprometheus.enabled is false
global.secrets.appLicenseKey, appSecretKey, appMasterKey, appMasterSecretKeyFOUNDATION4AI_APP_LICENSE, FOUNDATION4AI_APP_SECRET, FOUNDATION4AI_APP_MASTER_KEY, FOUNDATION4AI_APP_MASTER_SECRETAlways

The comments in the values files describe secrets set directly as values and randomly generated secrets. Neither is implemented: every credential comes from foundation4ai-secrets, as described in Secrets and keys.

Core chart dependencies​

KeyDefaultEffect when false
postgres.enabledfalseThe database URL comes from POSTGRES_URL
redis.enabledtrueThe cache URL comes from REDIS_URL
nats.enabledtrueThe NATS JetStream URL comes from NATS_URL, a key that foundation4ai.secrets.env.template does not list
prometheus.enabledtrueThe chart reads PROMETHEUS_URL, a key that the template does not list. No process uses the value.

Disabling NATS JetStream or Prometheus without the corresponding key in foundation4ai-secrets is expected to stop the core release at render time (inferred). The operator adds NATS_URL, or PROMETHEUS_URL with any value, before disabling the dependency.

PostgreSQL​

The bundled PostgreSQL serves the evaluation profile only. Database describes the external database of the production profile.

KeyDefaultEffect
postgres.image.repository, postgres.image.tagpgvector/pgvector, pg18-trixiePostgreSQL 18 with the pgvector extension
postgres.image.registryDocker Hub (PostgreSQL chart default)Registry of the image
postgres.settings.existingSecret, postgres.settings.superuserPassword.secretKeyfoundation4ai-secrets, POSTGRES_SUPERUSER_PASSWORDSuperuser password
postgres.userDatabase.*foundation4ai-secrets, keys POSTGRES_DATABASE, POSTGRES_USER, POSTGRES_PASSWORDApplication database and user
postgres.customScripts.01-init-extension.sqlCREATE EXTENSION IF NOT EXISTS vector;Creates the pgvector extension
postgres.persistence.*enabled: true, size: 8GiNot read by the PostgreSQL chart. The database stores data on a temporary pod volume.
postgres.imagePullSecrets[]List of name entries
postgres.resources{}No requests or limits

Redis-compatible cache (Valkey)​

KeyDefaultEffect
redis.auth.enabledtruePassword authentication
redis.auth.usersExistingSecretfoundation4ai-core-redisSecret that the core chart creates from REDIS_PASSWORD, with the key default
redis.auth.aclUsers.default.permissions~* &* +@allPermissions of the default user
redis.image.repositoryvalkey/valkeyImage; the tag defaults to the chart application version, 9.0.1
redis.dataStorage.enabledfalseCache content lives in memory and is lost when the pod restarts
redis.imagePullSecrets[]List of names
redis.resources{}No requests or limits

NATS JetStream​

KeyDefaultEffect
nats.config.cluster.enabled, nats.config.cluster.replicastrue, 33 NATS servers in a StatefulSet
nats.config.jetstream.enabledtrueJetStream persistence, required by Foundation4
nats.config.jetstream.fileStore.pvc.size10GiVolume claim of each server
nats.config.jetstream.fileStore.pvc.storageClassNameNot setThe default StorageClass applies
nats.container.resources{}No requests or limits
nats.podDisruptionBudget.enabledtrueA PodDisruptionBudget for the NATS servers
nats.natsBox.enabledtrueThe utility Deployment foundation4ai-core-nats-box, which carries the nats command-line tool
nats.promExporter.enabledfalsePrometheus exporter for NATS server and JetStream metrics
nats.container.image, nats.reloader.image, nats.natsBox.container.imagenats 2.12.4-alpine, natsio/nats-server-config-reloader 0.21.1, natsio/nats-box 0.19.3Images

Prometheus​

KeyDefaultEffect
prometheus.alertmanager.enabled, prometheus.kube-state-metrics.enabled, prometheus.prometheus-node-exporter.enabled, prometheus.prometheus-pushgateway.enabledfalseOnly the Prometheus server is installed
prometheus.server.ingress.enabledfalseNo external access to Prometheus
prometheus.scrapeConfigsnullRemoves the default jobs of the Prometheus chart. Prometheus can fail at startup if a default job of the same name remains.
prometheus.serverFiles.prometheus.yml.scrape_configsJob kubernetes-podsScrapes pods annotated prometheus.io/app: foundation4ai and prometheus.io/scrape: "true" every 10 seconds
prometheus.extraScrapeConfigs""Further jobs, as YAML text
prometheus.server.persistentVolume.size, prometheus.server.persistentVolume.storageClass8Gi, not setMetrics volume
prometheus.server.retention15dMetrics retention
prometheus.server.resources{}No requests or limits
prometheus.imagePullSecrets[]List of name entries

Monitoring and logging describes the scrape job and the worker metrics that the job misses.

API server and workers​

The api-server chart creates the API server Deployment foundation4ai-api-server, the worker Deployment foundation4ai-api-server-worker, the Service foundation4ai-api-server, the hook ConfigMap and Secret foundation4ai-api-server and three hook Jobs.

KeyTypeDefaultEffect
api-server.enabledBooleantrueInstalls the chart
api-server.secretStringfoundation4ai-coreSecret of the core release, loaded as environment variables and read by the hook Jobs
api-server.replicaCount.serverInteger1API server replicas, when autoscaling is off
api-server.replicaCount.workerInteger3Worker replicas, when autoscaling is off
api-server.image.repositoryStringThe provider's registryAPI server image, also used by the workers and hook Jobs
api-server.image.repositoryGrpcStringThe provider's registrygRPC service image
api-server.image.pullPolicyStringIfNotPresentPull policy of both images
api-server.image.tag, api-server.image.tagGrpcString""Tags that take precedence over the global tags
api-server.imagePullSecretsList[]Used by the worker pods and hook Jobs when global.imagePullSecrets is empty. The API server pod ignores the key.
api-server.serviceAccount.create, automount, annotations, nameMixedtrue, true, {}, ""ServiceAccount of the API server pods. The worker pods and hook Jobs use the namespace default ServiceAccount.
api-server.podAnnotationsMap{}Added to the API server and worker pods, next to the fixed Prometheus annotations
api-server.podLabelsMap{}Added to the API server pods only
api-server.podSecurityContextMap{}Pod security context of the API server and worker pods
api-server.securityContextMap{}Security context of the server, worker and both grpc containers
api-server.service.type, api-server.service.portString, integerClusterIP, 80Service of the API server, which targets container port 8000
api-server.resourcesMap{}Requests and limits of the server, worker and both grpc containers. The hook Jobs receive none.
api-server.autoscaling.server.*Mapenabled: false, minReplicas: 1, maxReplicas: 100, targetCPUUtilizationPercentage: 80HorizontalPodAutoscaler of the API server. targetMemoryUtilizationPercentage adds a memory target.
api-server.autoscaling.worker.*Mapenabled: false, minReplicas: 3, maxReplicas: 100, targetCPUUtilizationPercentage: 80HorizontalPodAutoscaler of the workers
api-server.nodeSelector, tolerations, affinityMap, list, mapEmptyScheduling of the API server and worker pods. The hook Jobs receive none.
api-server.volumes, api-server.volumeMountsList[]Declared for extra volumes. A non-empty value renders at the wrong indentation, so the manifests are expected to fail to parse (inferred).
api-server.configsMap of strings{}Entries of the ConfigMap, mounted in /app/config and loaded as environment variables
api-server.secretsMap of stringsNot declaredEntries of the Secret, mounted in /app/config and loaded as environment variables
api-server.secretsAnnotationsMap{}Annotations of the Secret foundation4ai-api-server
api-server.models, api-server.packagesListNot declaredModel and package images, as described in Models, packages and air-gapped installs
api-server.nameOverride, api-server.fullnameOverrideString""Change object names. The ingress, the HTTPRoute and the Secret lookups assume the default names, so a deployment leaves both empty.

Dashboard​

KeyTypeDefaultEffect
dashboard.enabledBooleantrueInstalls the dashboard Deployment and Service foundation4ai-dashboard, container port 3000
dashboard.replicaCountInteger1Dashboard replicas
dashboard.image.repository, pullPolicy, tagStringThe provider's registry, IfNotPresent, ""Dashboard image; the tag falls back to global.dashboardImageTag
dashboard.imagePullSecretsList[]Used when global.imagePullSecrets is empty
dashboard.serviceAccount.*, podAnnotations, podLabels, podSecurityContext, securityContextMixedChart defaultsStandard pod settings
dashboard.service.type, dashboard.service.portString, integerClusterIP, 80Service of the dashboard
dashboard.resourcesMap{}Not read
dashboard.livenessProbeMapNot declaredWhen set, the chart adds fixed liveness and readiness probes on / and renders the value of this key as the container resources. A probe definition in this key therefore produces an invalid manifest (inferred).
dashboard.volumes, volumeMounts, nodeSelector, tolerations, affinityMixedEmptyStandard pod settings

The dashboard container therefore runs without probes and without resource settings by default. A map of requests and limits in dashboard.livenessProbe enables both the fixed probes and those resources (inferred), and a LimitRange in the namespace gives the container default requests and limits without that key.

Ingress and HTTPRoute​

KeyDefaultEffect
ingress.enabledfalseCreates the Ingress foundation4ai
ingress.className""Ingress class
ingress.annotations{}Annotations of the Ingress
ingress.hosts[].hostchart-example.localHost names. Each host routes /dashboard to the dashboard and / to the API server. hosts[].paths is not read.
ingress.tls[]TLS entries with secretName and hosts
httpRoute.enabledfalseCreates the Gateway API HTTPRoute foundation4ai
httpRoute.annotations{}Annotations of the HTTPRoute
httpRoute.parentRefsname: gateway, sectionName: httpGateway and listener
httpRoute.hostnameschart-example.localHost names

The HTTPRoute sends /dashboard to the dashboard, redirects the exact path / to /dashboard and sends every other path to the API server. API and dashboard access describes both options.

The application chart also declares monitoring.enabled, monitoring.secret and monitoring.service.port. No template reads these keys.

Keys that need care​

  • Image tags. The comments state that an empty tag defaults to the chart version, but the templates fall back only to the global tag. The three global tags are required.
  • Pull secrets. Valkey reads global.imagePullSecrets as names while the Foundation4 charts read name entries, so the values add the secret name under redis.imagePullSecrets, as described in Charts, images and installation bundle. Model and package pull secrets reach only the API server pod.
  • Resources. One api-server.resources block applies to the Foundation4 process and to the gRPC service in both Deployments. Scaling and performance describes sizing.
  • Worker metrics. The worker pods carry the Prometheus port annotation 8000, while the worker serves metrics on port 9090, so the scrape job does not collect worker metrics.
  • Bundled PostgreSQL. postgres.persistence has no effect, so the bundled database loses data when the pod is rescheduled.
  • Scrape configuration. prometheus.scrapeConfigs: null removes the default jobs of the Prometheus chart. A restored default kubernetes-pods job shares the name of the core chart job, and Troubleshooting describes the correction.
  • Rendering without a cluster. The Secrets of both releases read existing Secrets from the cluster at install time, so helm template and GitOps tools that render offline fail to render the charts or produce empty credentials.
  • Restarts. The hook ConfigMap and Secrets change without a pod restart, so every change to configs, secrets or a credential is followed by kubectl rollout restart.
  • Extra volumes. api-server.volumes and api-server.volumeMounts are not usable in chart version 0.3.0.
  • Hook Jobs and workers. The hook Jobs take no resources, security context or scheduling values, and the worker pods take no podLabels and no ServiceAccount. A namespace with required resource limits, a restrictive Pod Security level or tainted nodes needs matching namespace defaults for these pods.

Production values example​

The following values file sets the keys that a production installation usually sets. Every value in angle brackets is replaced. The API server runs 2 replicas so that the API stays available while one pod restarts.

global:
serverImageTag: "<api server image tag>"
grpcImageTag: "<grpc service image tag>"
dashboardImageTag: "<dashboard image tag>"
imagePullSecrets:
- name: <pull secret>

postgres:
enabled: false

nats:
config:
jetstream:
fileStore:
pvc:
storageClassName: <storage class>

prometheus:
server:
persistentVolume:
storageClass: <storage class>

api-server:
image:
repository: <registry>/foundation4ai-api
repositoryGrpc: <registry>/foundation4ai-grpc
replicaCount:
server: 2
worker: 3
resources:
requests:
cpu: <cpu request>
memory: <memory request>
limits:
memory: <memory limit>

dashboard:
image:
repository: <registry>/foundation4ai-dashboard

ingress:
enabled: true
className: <ingress class>
hosts:
- host: <host name>
tls:
- secretName: <tls secret>
hosts:
- <host name>