Skip to main content

Configuration

Every chart value lives under the global namespace so it can be shared across sub-charts. The most common parameters:

The chart does not create or select a Kubernetes namespace — choose one at install time with helm install --namespace <ns> --create-namespace.

ParameterDescriptionDefault
global.mainAddressPublic base URL for all components.required
global.portController API port. Falls back to 80/443 based on TLS.""
global.tlsEnabledEnable HTTPS for external traffic.false
global.installMongoUse the bundled MongoDB.true
global.installVictoriaMetricsUse the bundled VictoriaMetrics.true
global.installClickhouseUse the bundled ClickHouse (raw API-events store).true
global.installCollectorDeploy the bundled elchi-collector (API discovery).true
global.installGslbDeploy the GSLB DNS component.false
global.internalCommunicationEnable internal-only communication between services.false
global.versionsList of Elchi backend versions to deploy (illustrative — see Envoy versions for the current set).[v1.6.15-v0.14.0-envoy1.39.0]
global.jwt.secretJWT signing secret. Leave empty and the chart generates one; an explicit value needs 32+ characters. See Credentials."" (generated)
global.jwt.accessTokenDurationAccess token lifetime."1h"
global.jwt.refreshTokenDurationRefresh token lifetime."5h"
global.elchiBackend.controlPlaneDefaultReplicasDefault replica count for control-plane services.4
global.elchiBackend.controllerDefaultReplicasDefault replica count for controller services.4
global.cors.allowedOriginsCORS allowed origins. Comma-separated, or * for all."*"

Credentials​

Since chart 2.0.0 every credential the platform needs lives in ONE Kubernetes Secret — elchi-stack-secrets by default — and the chart resolves each one in this order:

  1. the explicit value you set (global.jwt.secret, global.mongodb.password, …);
  2. the value already in the Secret from an earlier install or upgrade;
  3. a generated one, when global.secrets.autoGenerate is true (the default).

So a plain helm install needs no credentials at all, and a later helm upgrade never rotates what is already running. The Secret carries helm.sh/resource-policy: keep, so helm uninstall leaves it behind — reinstalling into the same namespace adopts the existing credentials instead of locking you out of your own MongoDB volume.

Secret keyValueGenerated length
ELCHI_JWT_SECRETglobal.jwt.secret — signs API tokens and derives the license KEK.48
MONGODB_PASSWORDglobal.mongodb.password32
CLICKHOUSE_PASSWORDglobal.clickhouse.password32
HASH_SALTglobal.collector.hashSalt — pseudonymizes client identifiers.48
GSLB_SECRETglobal.gslb.secret48
GRAFANA_PASSWORDglobal.grafana.password24
ParameterDescriptionDefault
global.secrets.nameName of the Secret holding every credential.elchi-stack-secrets
global.secrets.autoGenerateGenerate a missing credential at install time.true
global.secrets.adoptLegacyDefaultsOne-shot seed of the pre-2.0.0 built-in defaults on the first upgrade.false
Two cases that need your attention

GitOps / helm template. Generation reads the cluster through lookup, which returns nothing when the manifests are rendered outside it — every run would then invent new credentials. For Argo CD, Flux or any rendered pipeline, set global.secrets.autoGenerate: false and supply all six values explicitly (from your own secret store).

Upgrading a release installed before 2.0.0. Those chart versions had built-in default passwords and no shared Secret, so the chart cannot know what your datastores are using and refuses to guess. Set global.secrets.adoptLegacyDefaults: true for that one upgrade — it seeds the Secret with those former defaults so the running system keeps working — then rotate each credential.

Because they end up inside connection URIs, MONGODB_PASSWORD and CLICKHOUSE_PASSWORD must be URL-safe: an explicit value is accepted only if it matches [A-Za-z0-9._~-]+ (the unreserved URI characters). Anything else is rejected at render time rather than producing a DSN that silently fails to parse.

External MongoDB parameters​

When global.installMongo: false, point Elchi at your own MongoDB cluster:

ParameterDescription
global.mongodb.hostsConnection hosts (comma-separated for replica sets).
global.mongodb.usernameMongoDB username (default "elchi").
global.mongodb.passwordMongoDB password.
global.mongodb.databaseDatabase name (default "elchi").
global.mongodb.schemeConnection scheme — mongodb or mongodb+srv.
global.mongodb.replicasetReplica set name, if applicable.
global.mongodb.tlsEnabledEnable TLS connection to MongoDB.
global.mongodb.authSourceAuthentication source database.
global.mongodb.authMechanismAuthentication mechanism.

External VictoriaMetrics​

When global.installVictoriaMetrics: false, set:

ParameterDescription
global.victoriametrics.endpointExternal VictoriaMetrics endpoint. Accepts http://host:port or host:port.

External ClickHouse​

When global.installClickhouse: false, point the collector at your own ClickHouse cluster:

ParameterDescription
global.clickhouse.hostsConnection hosts for the raw API-events store.
global.clickhouse.passwordClickHouse password — set your own; do not commit it.
Subchart toggles feed the collector

global.installClickhouse and global.installCollector drive the API discovery pipeline: the collector writes raw events to ClickHouse and the endpoint inventory to MongoDB. Turn installGslb on only when you need the GSLB DNS component. Which datastores each shipped profile bundles vs. externalizes is summarized in Values Profiles.