Skip to main content
Version: 0.30.0

Helm Values Reference

Complete reference for all Helm chart values. Charts are published to the DecisionBox Helm repository:

helm repo add decisionbox https://decisionbox-io.github.io/decisionbox-platform
helm repo update

Source code for the charts is in helm-charts/.

decisionbox-api​

Image​

KeyTypeDefaultDescription
replicaCountint1Number of API replicas
image.repositorystringghcr.io/decisionbox-io/decisionbox-apiContainer image
image.tagstringmainImage tag (defaults to appVersion if not set)
image.pullPolicystringAlwaysPull policy
imagePullSecretslist[]Image pull secrets (set for private registries)

Deployment​

KeyTypeDefaultDescription
namespacestringdecisionboxKubernetes namespace
containerPortint8080Container port
serviceAccountNamestringdecisionbox-apiAPI service account name
serviceAccountAnnotationsmap{}API SA annotations (e.g., Workload Identity)
serviceAccountLabelsmap{}API SA labels (e.g., Azure Workload Identity azure.workload.identity/use)
agentServiceAccount.namestringdecisionbox-agentAgent service account name (for K8s Jobs)
agentServiceAccount.annotationsmap{}Agent SA annotations (e.g., Workload Identity for read-only access)
agentServiceAccount.labelsmap{}Agent SA labels (e.g., Azure Workload Identity)
podLabelsmap{}Extra labels on pod template (required for Azure Workload Identity webhook)

Environment Variables​

KeyTypeDefaultDescription
env.ENVstringprodEnvironment name
env.LOG_LEVELstringwarnLog level (debug, info, warn, error)
env.MONGODB_URIstring—MongoDB connection string (required if mongodb.enabled=false)
env.MONGODB_DBstringdecisionboxMongoDB database name
env.SECRET_PROVIDERstringmongodbSecret provider: mongodb, gcp, aws, or azure
env.SECRET_NAMESPACEstringdecisionboxSecret name prefix
env.SECRET_GCP_PROJECT_IDstring—GCP project (when SECRET_PROVIDER=gcp)
env.SECRET_AWS_REGIONstring—AWS region (when SECRET_PROVIDER=aws)
env.SECRET_AZURE_VAULT_URLstring—Azure Key Vault URL (when SECRET_PROVIDER=azure)
env.RUNNER_MODEstringkubernetesAgent runner: kubernetes or subprocess
env.AGENT_IMAGEstringghcr.io/decisionbox-io/decisionbox-agent:latestAgent container image
env.AGENT_NAMESPACEstringdecisionboxNamespace for agent Jobs
env.AGENT_SERVICE_ACCOUNTstringdecisionbox-agentK8s service account for agent Jobs (Workload Identity)
env.AGENT_JOB_TIMEOUT_HOURSstring25Wall-clock budget for one agent run (K8s Job ActiveDeadlineSeconds + subprocess watcher). Hard kill at this cap; paired with the 24h DISCOVERY_MAX_DURATION default so the in-agent cap fires first with 1h headroom for graceful persistence. If you raise DISCOVERY_MAX_DURATION, raise this in lockstep.
env.DISCOVERY_MAX_DURATIONstringunset → agent default 24hIn-agent ctx cap. Go duration format (24h, 168h). Set to 0 to disable and rely only on per-step budgets. Must be less than AGENT_JOB_TIMEOUT_HOURS so the agent fails gracefully rather than getting killed mid-write.
env.QDRANT_URLstring—Qdrant gRPC URL (e.g., qdrant:6334)
env.QDRANT_API_KEYstring—Qdrant API key (injected via Secret if qdrant.enabled=true)
extraEnvmap{}Additional env vars (key/value map; values must be strings) merged with env.
extraEnvFromlist[]Additional env sources (e.g., secretRef).

Resources​

KeyTypeDefaultDescription
resources.requests.cpustring100mCPU request
resources.requests.memorystring512MiMemory request
resources.limits.cpustring1000mCPU limit
resources.limits.memorystring2GiMemory limit

Lifecycle​

KeyTypeDefaultDescription
terminationGracePeriodSecondsint45SIGTERM-to-SIGKILL window. The API's graceful-shutdown sequence is: HTTP drain (10 s) → background-jobs drain (15 s, accommodates plugin-spawned long-running goroutines whose terminal Mongo writes must land before disconnect) → deferred Mongo disconnect. Worst case is 25 s; 45 s leaves 20 s of slack for signal delivery, scheduler latency, kubelet variance, and Mongo round-trip. Lower this only when no plugin extends the shutdown drain.

Service​

KeyTypeDefaultDescription
service.typestringClusterIPService type
service.portint8080Service port

Ingress​

KeyTypeDefaultDescription
ingress.enabledboolfalseEnable ingress (keep disabled — API is internal)
ingress.ingressClassNamestring""Ingress class (e.g., alb for AWS, nginx for NGINX)
ingress.annotationsmap{}Ingress annotations (e.g., ALB scheme, target type)
ingress.hoststring""Hostname for host-based routing
ingress.tlsSecretNamestring""TLS secret name
ingress.pathTypestringPrefixIngress path type
ingress.pathstring/Ingress path

RBAC​

KeyTypeDefaultDescription
rbac.enabledbooltrueCreate Role + RoleBinding for agent Jobs
rbac.roleNamestringagent-job-managerRole name

Probes​

KeyTypeDefaultDescription
livenessProbe.pathstring/healthLiveness endpoint
livenessProbe.initialDelaySecondsint15Initial delay
livenessProbe.periodSecondsint30Check interval
readinessProbe.pathstring/healthReadiness endpoint
readinessProbe.initialDelaySecondsint5Initial delay
readinessProbe.periodSecondsint10Check interval

Security Context​

KeyTypeDefaultDescription
securityContext.runAsNonRootbooltrueRequire non-root
securityContext.runAsUserint1000User ID
securityContext.fsGroupint1000Filesystem group
containerSecurityContext.readOnlyRootFilesystembooltrueRead-only root FS
containerSecurityContext.allowPrivilegeEscalationboolfalseNo privilege escalation
containerSecurityContext.capabilities.droplist[ALL]Drop all capabilities

MongoDB Subchart​

KeyTypeDefaultDescription
mongodb.enabledbooltrueDeploy bundled MongoDB
mongodb.architecturestringstandaloneMongoDB architecture
mongodb.auth.enabledboolfalseEnable MongoDB authentication
mongodb.persistence.sizestring1GiPersistent volume size

When mongodb.enabled=true, the deployment includes an init container that waits for MongoDB to be ready. The MongoDB URI is auto-computed from the chart values.

For production, set mongodb.enabled=false and provide env.MONGODB_URI pointing to your MongoDB instance (Atlas or self-hosted).

Vector Search (Qdrant)​

KeyTypeDefaultDescription
qdrant.enabledboolfalseEnable vector search support (deploys Qdrant subchart)
qdrant.urlstring""Qdrant gRPC endpoint (auto-computed if empty)
qdrant.apiKeystring""Optional API key (created as a K8s Secret)

When qdrant.enabled=true, the chart includes the qdrant-helm subchart. If url is empty, it is automatically set to ${releaseName}-qdrant:6334.

Qdrant Subchart Config​

You can pass any values to the Qdrant subchart via the qdrant key. Common overrides:

  • qdrant.persistence.size: Default 2Gi
  • qdrant.service.type: Default ClusterIP

decisionbox-dashboard​

Image​

KeyTypeDefaultDescription
replicaCountint1Number of dashboard replicas
image.repositorystringghcr.io/decisionbox-io/decisionbox-dashboardContainer image
image.tagstringmainImage tag
image.pullPolicystringAlwaysPull policy
imagePullSecretslist[]Image pull secrets (set for private registries)

Deployment​

KeyTypeDefaultDescription
namespacestringdecisionboxKubernetes namespace
containerPortint3000Container port
automountServiceAccountTokenboolfalseDashboard does not need K8s API access

Environment Variables​

KeyTypeDefaultDescription
env.API_URLstringhttp://decisionbox-api-service:8080API service URL (internal)
extraEnvmap{}Additional env vars (key/value map; values must be strings) merged with env.
extraEnvFromlist[]Additional env sources (e.g., secretRef).
cloudArmor.enabledboolfalseWhen true, the GCE ingress is annotated with cloud.google.com/backend-config so a Cloud Armor security policy applies to incoming requests.
cloudArmor.securityPolicystring""Name of the Cloud Armor security policy to attach (required when cloudArmor.enabled is true).

The dashboard proxies /api/* requests to the API URL. This must point to the API's ClusterIP service.

Resources​

KeyTypeDefaultDescription
resources.requests.cpustring100mCPU request
resources.requests.memorystring128MiMemory request
resources.limits.cpustring500mCPU limit
resources.limits.memorystring512MiMemory limit

Service​

KeyTypeDefaultDescription
service.typestringClusterIPService type
service.portint3000Service port

Ingress​

KeyTypeDefaultDescription
ingress.enabledbooltrueEnable ingress (dashboard is user-facing)
ingress.ingressClassNamestring""Ingress class (e.g., alb for AWS, nginx for NGINX)
ingress.annotationsmap{}Ingress annotations (e.g., ALB scheme, target type)
ingress.hoststring""Hostname
ingress.tlsSecretNamestring""TLS secret
ingress.pathTypestringPrefixPath type
ingress.pathstring/Path

Probes​

KeyTypeDefaultDescription
livenessProbe.pathstring/healthLiveness endpoint
livenessProbe.initialDelaySecondsint15Initial delay
livenessProbe.periodSecondsint15Check interval
readinessProbe.pathstring/healthReadiness endpoint
readinessProbe.initialDelaySecondsint5Initial delay
readinessProbe.periodSecondsint10Check interval

Security Context​

Same as the API chart — non-root (UID 1000), read-only filesystem, no capabilities, seccomp RuntimeDefault. The dashboard mounts /tmp and /app/.next/cache as emptyDir volumes.


Example: Production Values File​

Sensitive values (MONGODB_URI, SECRET_ENCRYPTION_KEY) are stored in a K8s Secret and injected via extraEnvFrom — never in the values file.

# values-prod.yaml (API)

mongodb:
enabled: false

env:
LOG_LEVEL: "warn"
MONGODB_DB: "decisionbox_prod"
SECRET_PROVIDER: "gcp"
SECRET_GCP_PROJECT_ID: "my-project"
SECRET_NAMESPACE: "decisionbox"

extraEnvFrom:
- secretRef:
name: decisionbox-api-secrets

serviceAccountAnnotations:
iam.gke.io/gcp-service-account: "[email protected]"

resources:
requests:
cpu: "250m"
memory: "1Gi"
limits:
cpu: "2000m"
memory: "4Gi"

Create the K8s Secret separately:

kubectl create secret generic decisionbox-api-secrets \
--from-literal=SECRET_ENCRYPTION_KEY="$(openssl rand -base64 32)" \
--from-literal=MONGODB_URI="mongodb+srv://user:[email protected]/decisionbox_prod" \
-n decisionbox

AWS (EKS + Secrets Manager + Bedrock)​

# values-prod.yaml (API)

mongodb:
enabled: false

env:
LOG_LEVEL: "warn"
MONGODB_DB: "decisionbox_prod"
SECRET_PROVIDER: "aws"
SECRET_NAMESPACE: "decisionbox"

extraEnvFrom:
- secretRef:
name: decisionbox-api-secrets

serviceAccountAnnotations:
eks.amazonaws.com/role-arn: "arn:aws:iam::123456789012:role/decisionbox-prod-api"

agentServiceAccount:
annotations:
eks.amazonaws.com/role-arn: "arn:aws:iam::123456789012:role/decisionbox-prod-agent"

resources:
requests:
cpu: "250m"
memory: "1Gi"
limits:
cpu: "2000m"
memory: "4Gi"

Azure (AKS + Key Vault)​

# values-prod.yaml (API)

mongodb:
enabled: false

env:
LOG_LEVEL: "warn"
MONGODB_DB: "decisionbox_prod"
SECRET_PROVIDER: "azure"
SECRET_AZURE_VAULT_URL: "https://decisionbox-prod-kv.vault.azure.net/"
SECRET_NAMESPACE: "decisionbox"

extraEnvFrom:
- secretRef:
name: decisionbox-api-secrets

serviceAccountAnnotations:
azure.workload.identity/client-id: "<api-managed-identity-client-id>"
serviceAccountLabels:
azure.workload.identity/use: "true"

agentServiceAccount:
annotations:
azure.workload.identity/client-id: "<agent-managed-identity-client-id>"
labels:
azure.workload.identity/use: "true"

podLabels:
azure.workload.identity/use: "true"

automountServiceAccountToken: true

resources:
requests:
cpu: "250m"
memory: "1Gi"
limits:
cpu: "2000m"
memory: "4Gi"

Next Steps​