Start after installing with Helm. Enable one optional component at a time and verify its effect.
Kubernetes operations
These are all disabled by default. Each needs more than its enabled flag to behave the way you would expect.
NetworkPolicy
networkPolicy.enabled=true installs a default-deny posture. It does not infer where your traffic comes from, so the namespaces must be named explicitly or the matching inbound rule is simply not emitted:
networkPolicy:
enabled: true
ingressNamespace: "ingress-nginx" # without this, no ingress-controller traffic reaches the API
monitoringNamespace: "monitoring" # without this, Prometheus cannot scrape /metrics
egress:
smtpCidrs: ["0.0.0.0/0"] # ports 25/465/587 from api and worker pods
httpsCidrs: ["0.0.0.0/0"] # port 443: OAuth/SAML, integrations, webhooks
kubeApiServerCidrs: [] # required when the CertOps controller is enabled
Egress CIDRs default to 0.0.0.0/0 to preserve out-of-the-box behavior; narrow them to your real endpoints, or set a list to [] to disable that protocol's egress entirely.
Leaving ingressNamespace empty omits the rule allowing the Ingress controller to reach the API. Internal dashboard and auto-sync rules still exist, but external API calls through the Ingress controller can fail even though every pod is Ready.
Autoscaling and pod disruption budgets
api:
autoscaling:
enabled: true
minReplicas: 2
maxReplicas: 5
targetCPUUtilizationPercentage: 80
podDisruptionBudget:
enabled: true
minAvailable: 1 # maxUnavailable takes precedence if you set both
ServiceMonitor
Enabling it is not enough on its own: kube-prometheus-stack only selects ServiceMonitors carrying the release label it was configured to match, so set labels as well.
monitoring:
serviceMonitor:
enabled: true
labels:
release: kube-prometheus-stack # must match your Prometheus serviceMonitorSelector
interval: 30s
Pinning images (private registries, air-gapped, reproducible deploys)
Image tags default to the chart's appVersion. For a mirrored registry or a byte-for-byte reproducible deploy:
global:
imageRegistry: "registry.internal.example.com"
imagePullSecrets:
- name: my-registry-credentials
api:
image:
digest: "sha256:..." # takes precedence over tag; from the release manifest