# ──────────────────────────────────────────────────────────── # CloudHost Platform — Helm values # Deploy: helm upgrade --install cloudhost ./backend/helm/cloudhost-platform -n cloudhost --create-namespace # ──────────────────────────────────────────────────────────── nameOverride: "" fullnameOverride: "" namespace: cloudhost createNamespace: true global: storageClass: "" images: postgres: postgres:16-alpine redis: redis:7-alpine busybox: busybox:1.36 backend: repository: cloudhost-backend tag: "1.0.0" pullPolicy: IfNotPresent frontend: repository: cloudhost-frontend tag: "1.0.0" pullPolicy: IfNotPresent postgres: enabled: true database: cloudhost username: cloudhost # Leave empty to auto-generate on first install (stored in Secret) password: "" storage: 10Gi resources: {} redis: enabled: true storage: 1Gi resources: {} backend: enabled: true replicas: 1 imagePullSecrets: - name: registry-pull-secret uploads: size: 20Gi sourceStorage: enabled: false existingSecret: ceph-app-sources-credentials resources: {} extraEnv: {} env: NODE_ENV: production PORT: "4000" JWT_EXPIRES_IN: 15m JWT_REFRESH_EXPIRES_IN: 7d PLATFORM_DOMAIN: apps.cloudhost.local REGISTRY_URL: registry.cloudhost-builds.svc.cluster.local:5000 REGISTRY_PULL_URL: registry.cloudhost-builds.svc.cluster.local:5000 BUILD_NAMESPACE: cloudhost-builds BUILD_SERVICE_ACCOUNT: kaniko-builder UPLOAD_DIR: /app/uploads PLATFORM_CREATE_STORAGE_CLASS: "true" PLATFORM_STORAGE_CLASS: cloudhost-expandable PLATFORM_STORAGE_PROVISIONER: rancher.io/local-path ELASTICSEARCH_HOST: elasticsearch.logging.svc.cluster.local ELASTICSEARCH_AUTO_PORT_FORWARD: "false" frontend: enabled: true replicas: 1 imagePullSecrets: - name: registry-pull-secret resources: {} # JWT secrets — set in production (values-production.example.yaml) secrets: # Use a pre-created Secret instead of chart-managed one. Required for GitOps # (Argo CD renders with `helm template`, so lookup/randAlphaNum regenerate on # every sync). Secret must contain keys: postgres-password, jwt-secret, # jwt-refresh-secret, cluster-kubeconfig-key. existingSecret: "" jwtSecret: "" jwtRefreshSecret: "" # AES key for encrypting stored kubeconfigs (64 hex chars or any passphrase) clusterKubeconfigKey: "" ingress: enabled: true className: nginx frontend: host: platform.cloudhost.local # Optional dedicated host for the authenticated panel. Empty = disabled # (single-origin, dev). Production (abrban): panel.abrban.com panel: host: "" api: host: api.cloudhost.local singleHost: enabled: false host: platform.cloudhost.local apiPath: /api annotations: {} tls: enabled: true clusterIssuer: letsencrypt-prod secretName: "" migrations: enabled: true image: postgres:16-alpine monitoring: enabled: false backups: postgres: enabled: false schedule: "0 3 * * *" storageSize: 10Gi