{"id":31646059,"url":"https://github.com/codefresh-io/codefresh-onprem-helm","last_synced_at":"2026-03-10T19:01:26.825Z","repository":{"id":263453085,"uuid":"835320231","full_name":"codefresh-io/codefresh-onprem-helm","owner":"codefresh-io","description":"Codefresh platform Helm chart for on-premises installation","archived":false,"fork":false,"pushed_at":"2026-03-10T15:05:59.000Z","size":38036,"stargazers_count":1,"open_issues_count":7,"forks_count":1,"subscribers_count":1,"default_branch":"main","last_synced_at":"2026-03-10T15:53:34.333Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":null,"language":"Go Template","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":null,"status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/codefresh-io.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":null,"code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":"CODEOWNERS","security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2024-07-29T15:37:23.000Z","updated_at":"2026-03-06T12:34:01.000Z","dependencies_parsed_at":"2026-02-12T16:01:49.531Z","dependency_job_id":"d0dcb627-43c5-4b47-81c8-41c3bd57ed2e","html_url":"https://github.com/codefresh-io/codefresh-onprem-helm","commit_stats":null,"previous_names":["codefresh-io/codefresh-onprem-helm"],"tags_count":479,"template":false,"template_full_name":null,"purl":"pkg:github/codefresh-io/codefresh-onprem-helm","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/codefresh-io%2Fcodefresh-onprem-helm","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/codefresh-io%2Fcodefresh-onprem-helm/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/codefresh-io%2Fcodefresh-onprem-helm/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/codefresh-io%2Fcodefresh-onprem-helm/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/codefresh-io","download_url":"https://codeload.github.com/codefresh-io/codefresh-onprem-helm/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/codefresh-io%2Fcodefresh-onprem-helm/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":30348853,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-03-10T15:55:29.454Z","status":"ssl_error","status_checked_at":"2026-03-10T15:54:58.440Z","response_time":106,"last_error":"SSL_connect returned=1 errno=0 peeraddr=140.82.121.5:443 state=error: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2025-10-07T05:19:38.791Z","updated_at":"2026-03-10T19:01:26.798Z","avatar_url":"https://github.com/codefresh-io.png","language":"Go Template","funding_links":[],"categories":[],"sub_categories":[],"readme":"## Codefresh On-Premises\n\n![Version: 0.0.0](https://img.shields.io/badge/Version-0.0.0-informational?style=flat-square) ![AppVersion: 0.0.0](https://img.shields.io/badge/AppVersion-0.0.0-informational?style=flat-square)\n\nHelm chart for deploying [Codefresh On-Premises](https://codefresh.io/docs/docs/getting-started/intro-to-codefresh/) to Kubernetes.\n\n## Table of Content\n\n- [Prerequisites](#prerequisites)\n- [Get Repo Info](#get-repo-info)\n- [Install Chart](#install-chart)\n- [Changes to the Bitnami catalog](#changes-to-the-bitnami-catalog)\n- [Chart Configuration](#chart-configuration)\n  - [Persistent services](#persistent-services)\n  - [Configuring external services](#configuring-external-services)\n    - [External MongoDB](#external-mongodb)\n    - [External MongoDB with MTLS](#external-mongodb-with-mtls)\n    - [External PostgresSQL](#external-postgressql)\n    - [External Redis](#external-redis)\n    - [External Redis with MTLS](#external-redis-with-mtls)\n    - [External RabbitMQ](#external-rabbitmq)\n    - [External Consul](#external-consul)\n    - [External Nats](#external-nats)\n    - [BoltDB data in Cronus service](#boltdb-data-in-cronus-service)\n  - [Configuring Ingress-NGINX](#configuring-ingress-nginx)\n    - [ELB with SSL Termination (Classic Load Balancer)](#elb-with-ssl-termination-classic-load-balancer)\n    - [NLB (Network Load Balancer)](#nlb-network-load-balancer)\n  - [Configuration with ALB (Application Load Balancer)](#configuration-with-alb-application-load-balancer)\n  - [Configuration with Private Registry](#configuration-with-private-registry)\n  - [Configuration with multi-role CF-API](#configuration-with-multi-role-cf-api)\n  - [High Availability](#high-availability)\n  - [Mounting private CA certs](#mounting-private-ca-certs)\n- [Installing on OpenShift](#installing-on-openshift)\n- [Firebase Configuration](#firebase-configuration)\n- [Additional configuration](#additional-configuration)\n  - [Retention policy for builds and logs](#retention-policy-for-builds-and-logs)\n  - [Projects pipelines limit](#projects-pipelines-limit)\n  - [Enable session cookie](#enable-session-cookie)\n  - [X-Frame-Options response header](#x-frame-options-response-header)\n  - [Image digests in containers](#image-digests-in-containers)\n  - [Hermes configuration](#hermes-configuration)\n- [Configuring OIDC Provider](#configuring-oidc-provider)\n- [Maintaining MongoDB indexes](#maintaining-mongodb-indexes)\n- [Upgrading](#upgrading)\n  - [To 2.0.0](#to-2-0-0)\n  - [To 2.0.12](#to-2-0-12)\n  - [To 2.0.17](#to-2-0-17)\n  - [To 2.1.0](#to-2-1-0)\n  - [To 2.1.7](#to-2-1-7)\n  - [To 2.2.0](#to-2-2-0)\n  - [To 2.3.0](#to-2-3-0)\n  - [To 2.4.0](#to-2-4-0)\n  - [To 2.5.0](#to-2-5-0)\n  - [To 2.6.0](#to-2-6-0)\n  - [To 2.7.0](#to-2-7-0)\n  - [To 2.8.0](#to-2-8-0)\n  - [To 2.9.0](#to-2-9-0)\n  - [To 2.9.9](#to-2-9-9)\n- [Rollback](#rollback)\n- [Troubleshooting](#troubleshooting)\n- [Values](#values)\n\n⚠️⚠️⚠️\n\u003e Since version 2.1.7 chart is pushed **only** to OCI registry at `oci://quay.io/codefresh/codefresh`\n\n\u003e Versions prior to 2.1.7 are still available in ChartMuseum at `http://chartmuseum.codefresh.io/codefresh`\n\n## Prerequisites\n\n- Kubernetes **\u003e= 1.28 \u0026\u0026 \u003c= 1.32** (Supported versions mean that installation passed for the versions listed; however, it **may** work on older k8s versions as well)\n- Helm **3.8.0+**\n- PV provisioner support in the underlying infrastructure (with [resizing](https://kubernetes.io/blog/2018/07/12/resizing-persistent-volumes-using-kubernetes/) available)\n- Minimal 4vCPU and 8Gi Memory available in the cluster (for production usage the recommended minimal cluster capacity is at least 12vCPUs and 36Gi Memory)\n- GCR Service Account JSON `sa.json` (provided by Codefresh, contact support@codefresh.io)\n- Firebase [Realtime Database URL](https://firebase.google.com/docs/database/web/start#create_a_database) with [legacy token](https://firebase.google.com/docs/database/rest/auth#legacy_tokens). See [Firebase Configuration](#firebase-configuration)\n- Valid TLS certificates for Ingress\n- When [external](#external-postgressql) PostgreSQL is used, `pg_cron` and `pg_partman` extensions **must be enabled** for [analytics](https://codefresh.io/docs/docs/dashboards/home-dashboard/#pipelines-dashboard) to work (see [AWS RDS example](https://docs.aws.amazon.com/AmazonRDS/latest/UserGuide/PostgreSQL_pg_cron.html#PostgreSQL_pg_cron.enable)). The `pg_cron` extension should be the 1.4 version or higher for Azure Postgres DB.\n- Redis persistent storage is required for CRON triggers in CI pipelines. Make sure that your external Redis instance supports persistence (AOF or RDB). It's recommended to deploy in-cluster Redis with persistence enabled (e.g. [bitnami/redis](https://github.com/bitnami/charts/tree/main/bitnami/redis) or [redis-ha](https://github.com/DandyDeveloper/charts/blob/master/charts/redis-ha/Chart.yaml)). See [Hermes configuration](#hermes-configuration) for more details.\n\n## Get Repo Info\n\n```console\nhelm show all oci://quay.io/codefresh/codefresh\n```\nSee [Use OCI-based registries](https://helm.sh/docs/topics/registries/)\n\n## Install Chart\n\n**Important:** only helm 3.8.0+ is supported\n\n\u003e ⚠️ The default chart configuration with embedded databases is **not intended for production usage**! You should use Cloud PaaS for MongoDB, PostgreSQL, Redis and RabbitMQ.\nSee [Configuring external services](#configuring-external-services) section for details.\n\nEdit default `values.yaml` or create empty `cf-values.yaml`\n\n- Pass `sa.json` (as a single line) to `.Values.imageCredentials.password`\n\n```yaml\n# -- Credentials for Image Pull Secret object\nimageCredentials:\n  registry: us-docker.pkg.dev\n  username: _json_key\n  password: '{ \"type\": \"service_account\", \"project_id\": \"codefresh-enterprise\", \"private_key_id\": ... }'\n```\n\n- Specify `.Values.global.appUrl`, `.Values.global.firebaseUrl`, `.Values.global.firebaseSecret`, `.Values.global.env.MONGOOSE_AUTO_INDEX`, `.Values.global.env.MONGO_AUTOMATIC_INDEX_CREATION`\n\n```yaml\nglobal:\n  # -- Application root url. Will be used in Ingress as hostname\n  appUrl: onprem.mydomain.com\n\n  # -- Firebase URL for logs streaming.\n  firebaseUrl: \u003c\u003e\n  # -- Firebase URL for logs streaming from existing secret\n  firebaseUrlSecretKeyRef: {}\n  # E.g.\n  # firebaseUrlSecretKeyRef:\n  #   name: my-secret\n  #   key: firebase-url\n\n  # -- Firebase Secret.\n  firebaseSecret: \u003c\u003e\n  # -- Firebase Secret from existing secret\n  firebaseSecretSecretKeyRef: {}\n  # E.g.\n  # firebaseSecretSecretKeyRef:\n  #   name: my-secret\n  #   key: firebase-secret\n\n  # -- Enable index creation in MongoDB\n  # This is required for first-time installations!\n  # Before usage in Production, you must set it to `false` or remove it!\n  env:\n    MONGOOSE_AUTO_INDEX: \"true\"\n    MONGO_AUTOMATIC_INDEX_CREATION: \"true\"\n\n```\n\n- Specify `.Values.ingress.tls.cert` and `.Values.ingress.tls.key` OR `.Values.ingress.tls.existingSecret`\n\n```yaml\ningress:\n  # -- Enable the Ingress\n  enabled: true\n  # -- Set the ingressClass that is used for the ingress.\n  # Default `nginx-codefresh` is created from `ingress-nginx` controller subchart\n  # If you specify a different ingress class, disable `ingress-nginx` subchart (see below)\n  ingressClassName: nginx-codefresh\n  tls:\n    # -- Enable TLS\n    enabled: true\n    # -- Default secret name to be created with provided `cert` and `key` below\n    secretName: \"star.codefresh.io\"\n    # -- Certificate (base64 encoded)\n    cert: \"\"\n    # -- Private key (base64 encoded)\n    key: \"\"\n    # -- Existing `kubernetes.io/tls` type secret with TLS certificates (keys: `tls.crt`, `tls.key`)\n    existingSecret: \"\"\n\ningress-nginx:\n  # -- Enable ingress-nginx controller\n  enabled: true\n```\n\n- *Or specify your own `.Values.ingress.ingressClassName` (disable built-in ingress-nginx subchart)*\n\n```yaml\ningress:\n  # -- Enable the Ingress\n  enabled: true\n  # -- Set the ingressClass that is used for the ingress.\n  ingressClassName: nginx\n\ningress-nginx:\n  # -- Disable ingress-nginx controller\n  enabled: false\n```\n\n- Install the chart\n\n```console\n  helm upgrade --install cf oci://quay.io/codefresh/codefresh \\\n      -f cf-values.yaml \\\n      --namespace codefresh \\\n      --create-namespace \\\n      --debug \\\n      --wait \\\n      --timeout 15m\n  ```\n\n### ⚠️ **MANDATORY** Post-Installation Action Items\n\nOnce your Codefresh On-Prem instance is installed, configured, and confirmed to be ready for production use, the following variables must be set to `false` or removed:\n\n```yaml\nglobal:\n  env:\n    MONGOOSE_AUTO_INDEX: \"false\"\n    MONGO_AUTOMATIC_INDEX_CREATION: \"false\"\n```\n\n## Changes to the Bitnami catalog\n\nDue to changes in the Bitnami catalog (Ref: [Upcoming changes to the Bitnami catalog (effective August 28th, 2025)](https://github.com/bitnami/containers/issues/83267)), the following subcharts have been updated to use `docker.io/bitnamilegacy` repository:\n\n- MongoDB\n- PostgreSQL\n- Redis\n- RabbitMQ\n- Nats\n- Consul\n\n[Bitnami Legacy repository](https://hub.docker.com/u/bitnamilegacy) catalog will receive no further updates or support and should only be used for temporary evaluation purposes. For production usage, please consider externalizing these services as described in [Configuring external services](#configuring-external-services) section.\n\nIf you have an option to use [Bitnami Secure Images](https://www.arrow.com/globalecs/uk/products/bitnami-secure-images/?utm_source=google\u0026utm_medium=paidsearch\u0026utm_campaign=bitnami\u0026gad_source=1\u0026gad_campaignid=22996675622), you need to override image repository and tag for each of Bitnami subcharts used in Codefresh chart and [provide a valid image pull secret](https://kubernetes.io/docs/tasks/configure-pod-container/pull-image-private-registry/#registry-secret-existing-credentials).\n\n```yaml\nmongodb:\n  image:\n    repository: bitnami/mongodb\n    tag: \u003cversion\u003e\n  pullSecrets:\n    - my-bitnami-registry-secret\n\nredis:\n  image:\n    repository: bitnami/redis\n    tag: \u003cversion\u003e\n  pullSecrets:\n    - my-bitnami-registry-secret\n\npostgresql:\n  image:\n    repository: bitnami/postgresql\n    tag: \u003cversion\u003e\n  pullSecrets:\n    - my-bitnami-registry-secret\n\nrabbitmq:\n  image:\n    repository: bitnami/rabbitmq\n    tag: \u003cversion\u003e\n  pullSecrets:\n    - my-bitnami-registry-secret\n\nnats:\n  image:\n    repository: bitnami/nats\n    tag: \u003cversion\u003e\n  pullSecrets:\n    - my-bitnami-registry-secret\n\nconsul:\n  image:\n    repository: bitnami/consul\n    tag: \u003cversion\u003e\n  pullSecrets:\n    - my-bitnami-registry-secret\n```\n\n## Chart Configuration\n\nSee [Customizing the Chart Before Installing](https://helm.sh/docs/intro/using_helm/#customizing-the-chart-before-installing). To see all configurable options with detailed comments, visit the chart's [values.yaml](./values.yaml), or run these configuration commands:\n\n```console\nhelm show values codefresh/codefresh\n```\n\n### Persistent services\n\nCodefresh relies on several persistent services to store its data:\n\n- **MongoDB**: Stores all account data (account settings, users, projects, pipelines, builds etc.)\n- **PostgreSQL**: Stores data about events for the account (pipeline updates, deletes, etc.). The audit log uses the data from this database.\n- **Redis**: Used for caching, and as a key-value store for cron trigger manager.\n- **RabbitMQ**: Used for message queueing.\n- **Consul**: Used for store data about Windows runtimes\n- **Cronus**: Used for storing CRON triggers data\n\nThe following table reflects the recommended and supported versions of these databases for different Codefresh releases:\n\n| Codefresh version | MongoDB | PostgreSQL | Redis | RabbitMQ | Nats | Consul |\n| :---              | :---    | :---       | :---  | :---     | :--- | :---   |\n| 2.10.x            | \\\u003e=4.2 \\\u003c=7.x \u003cbr\u003e Recommended: 7.x (`featureCompatibilityVersion: 7.0`)| \\\u003e= 16.x \\\u003c= 17.x \u003cbr\u003e Recommended: 17.x | \\\u003e= 7.x \\\u003c= 8.x \u003cbr\u003e Recommended: 8\\.x | 3.13.x \\| 4.0.x \\| 4.1.x \u003cbr\u003e Recommended: 4.1.x | 2.11.x \u003cbr\u003e Recommended: 2.11.x | 1.21.x \u003cbr\u003e Recommended: 1.21.x |\n| 2.9.x             | \\\u003e=4.2 \\\u003c=7.x \u003cbr\u003e Recommended: 7.x (`featureCompatibilityVersion: 7.0`)| \\\u003e= 16.x \\\u003c= 17.x \u003cbr\u003e Recommended: 17.x | \\\u003e= 7.0.x \\\u003c= 7.4.x \u003cbr\u003e Recommended: 7.4.x | 3.13.x \\| 4.0.x \\| 4.1.x \u003cbr\u003e Recommended: 4.1.x | 2.11.x \u003cbr\u003e Recommended: 2.11.x | 1.21.x \u003cbr\u003e Recommended: 1.21.x |\n| 2.8.x             | \\\u003e=4.2 \\\u003c=7.x \u003cbr\u003e Recommended: 7.x (`featureCompatibilityVersion: 6.0`)| \\\u003e= 13.x \\\u003c= 17.x \u003cbr\u003e Recommended: 16.x \\| 17.x | \\\u003e= 7.0.x \\\u003c= 7.4.x \u003cbr\u003e Recommended: 7.4.x | 3.13.x \\| 4.0.x \\| 4.1.x \u003cbr\u003e Recommended: 4.0.x | 2.11.x \u003cbr\u003e Recommended: 2.11.x | 1.21.x \u003cbr\u003e Recommended: 1.21.x |\n| 2.7.x             | \\\u003e=4.2 \\\u003c=6.x \u003cbr\u003e Recommended: 6.x (`featureCompatibilityVersion: 6.0`)| 13.x | 7.0.x | 3.13.x | 2.10.x, 2.11.x  | 1.20.x, 1.21.x |\n| 2.6.x             | \\\u003e=4.2 \\\u003c=6.x \u003cbr\u003e Recommended: 6.x (`featureCompatibilityVersion: 5.0`)| 13.x | 7.0.x | 3.13.x | 2.10.x  | 1.20.x |\n\n\u003e Running on netfs (nfs, cifs) is not recommended.\n\n\u003e Docker daemon (`cf-builder` stateful set) can be run on block storage only.\n\nAll of them can be externalized. See the next sections.\n\n### Configuring external services\n\nThe chart contains required dependencies for the corresponding services\n- [bitnami/mongodb](https://github.com/bitnami/charts/tree/main/bitnami/mongodb)\n- [bitnami/postgresql](https://github.com/bitnami/charts/tree/main/bitnami/postgresql)\n- [bitnami/redis](https://github.com/bitnami/charts/tree/main/bitnami/redis)\n- [bitnami/rabbitmq](https://github.com/bitnami/charts/tree/main/bitnami/rabbitmq)\n\nTo use external services like [MongoDB Atlas Database](https://www.mongodb.com/atlas/database) or [Amazon RDS for PostgreSQL](https://aws.amazon.com/rds/postgresql/) you need to adjust the values accordingly:\n\n#### External MongoDB\n\n\u003e ⚠️ **Important!** If you use MongoDB Atlas, you must create user with `Write` permissions before installing Codefresh: \u003cbr\u003e\n\u003e Then, provide the user credentials in the chart values at \u003cbr\u003e\n`.Values.global.mongodbUser/mongodbRootUserSecretKeyRef` \u003cbr\u003e\n`.Values.global.mongodbPassword/mongodbRootPasswordSecretKeyRef` \u003cbr\u003e\n`.Values.seed.mongoSeedJob.mongodbRootUser/mongodbRootUserSecretKeyRef` \u003cbr\u003e\n`.Values.seed.mongoSeedJob.mongodbRootPassword/mongodbRootPasswordSecretKeyRef` \u003cbr\u003e\n\u003e Ref: \u003cbr\u003e\n\u003e [Create Users in Atlas](https://www.mongodb.com/docs/atlas/security-add-mongodb-users/#configure-database-users)\n\n`values.yaml` for external MongoDB:\n\n```yaml\nseed:\n  mongoSeedJob:\n    # -- Enable mongo seed job. Seeds the required data (default idp/user/account), creates cfuser and required databases.\n    enabled: true\n    # -- Root user in plain text (required ONLY for seed job!).\n    mongodbRootUser: \"root\"\n    # -- Root user from existing secret\n    mongodbRootUserSecretKeyRef: {}\n    # E.g.\n    # mongodbRootUserSecretKeyRef:\n    #   name: my-secret\n    #   key: mongodb-root-user\n\n    # -- Root password in plain text (required ONLY for seed job!).\n    mongodbRootPassword: \"password\"\n    # -- Root password from existing secret\n    mongodbRootPasswordSecretKeyRef: {}\n    # E.g.\n    # mongodbRootPasswordSecretKeyRef:\n    #   name: my-secret\n    #   key: mongodb-root-password\n\nglobal:\n  # -- LEGACY (but still supported) - Use `.global.mongodbProtocol` + `.global.mongodbUser/mongodbUserSecretKeyRef` + `.global.mongodbPassword/mongodbPasswordSecretKeyRef` + `.global.mongodbHost/mongodbHostSecretKeyRef` + `.global.mongodbOptions` instead\n  # Default MongoDB URI. Will be used by ALL services to communicate with MongoDB.\n  # Ref: https://www.mongodb.com/docs/manual/reference/connection-string/\n  # Note! `defaultauthdb` is omitted on purpose (i.e. mongodb://.../[defaultauthdb]).\n  mongoURI: \"\"\n  # E.g.\n  # mongoURI: \"mongodb://cfuser:mTiXcU2wafr9@cf-mongodb:27017/\"\n\n  # -- Set mongodb protocol (`mongodb` / `mongodb+srv`)\n  mongodbProtocol: mongodb\n  # -- Set mongodb user in plain text\n  mongodbUser: \"cfuser\"\n  # -- Set mongodb user from existing secret\n  mongodbUserSecretKeyRef: {}\n  # E.g.\n  # mongodbUserSecretKeyRef:\n  #   name: my-secret\n  #   key: mongodb-user\n\n  # -- Set mongodb password in plain text\n  mongodbPassword: \"password\"\n  # -- Set mongodb password from existing secret\n  mongodbPasswordSecretKeyRef: {}\n  # E.g.\n  # mongodbPasswordSecretKeyRef:\n  #   name: my-secret\n  #   key: mongodb-password\n\n  # -- Set mongodb host in plain text\n  mongodbHost: \"my-mongodb.prod.svc.cluster.local:27017\"\n  # -- Set mongodb host from existing secret\n  mongodbHostSecretKeyRef: {}\n  # E.g.\n  # mongodbHostSecretKeyRef:\n  #   name: my-secret\n  #   key: monogdb-host\n\n  # -- Set mongodb connection string options\n  # Ref: https://www.mongodb.com/docs/manual/reference/connection-string/#connection-string-options\n  mongodbOptions: \"retryWrites=true\"\n\nmongodb:\n  # -- Disable mongodb subchart installation\n  enabled: false\n```\n\n##### Migrating from built-in MongoDB to external MongoDB\n\n\u003e **Note!** `MongoDB` is main database for Codefresh storing all the data about users, projects, pipelines, builds etc.\n\nWe're recommending to use `mongodump` and `mongorestore` tools to migrate ALL the data from built-in MongoDB to external MongoDB.\n\nThe connection string or `MONGODB_*` environment variables for built-in MongoDB can be obtained in `cfapi` secret.\n\n[mongodump](https://www.mongodb.com/docs/database-tools/mongodump/)\n\n[mongorestore](https://www.mongodb.com/docs/database-tools/mongorestore/)\n\n#### External MongoDB with MTLS\n\nIn order to use MTLS (Mutual TLS) for MongoDB, you need:\n\n* Create a K8S secret that contains the certificate (certificate file and private key).\n  The K8S secret should have one `ca.pem` key.\n```console\ncat cert.crt \u003e ca.pem\ncat cert.key \u003e\u003e ca.pem\nkubectl create secret generic my-mongodb-tls --from-file=ca.pem\n```\n\n*  Add `.Values.global.volumes` and `.Values.global.volumeMounts` to mount the secret into all the services.\n```yaml\nglobal:\n  volumes:\n    mongodb-tls:\n      enabled: true\n      type: secret\n      nameOverride: my-mongodb-tls\n      optional: true\n\n  volumeMounts:\n    mongodb-tls:\n      path:\n      - mountPath: /etc/ssl/mongodb/ca.pem\n        subPath: ca.pem\n\n  env:\n    MONGODB_SSL_ENABLED: true\n    MTLS_CERT_PATH: /etc/ssl/mongodb/ca.pem\n    RUNTIME_MTLS_CERT_PATH: /etc/ssl/mongodb/ca.pem\n    RUNTIME_MONGO_TLS: \"true\"\n    # Set these env vars to 'false' if self-signed certificate is used to avoid x509 errors\n    RUNTIME_MONGO_TLS_VALIDATE: \"false\"\n    MONGO_MTLS_VALIDATE: \"false\"\n```\n\n#### External PostgresSQL\n\n```yaml\nseed:\n  postgresSeedJob:\n    # -- Enable postgres seed job. Creates required user and databases.\n    enabled: true\n    # -- (optional) \"postgres\" admin user in plain text (required ONLY for seed job!)\n    # Must be a privileged user allowed to create databases and grant roles.\n    # If omitted, username and password from `.Values.global.postgresUser/postgresPassword` will be used.\n    postgresUser: \"postgres\"\n    # -- (optional) \"postgres\" admin user from exising secret\n    postgresUserSecretKeyRef: {}\n    # E.g.\n    # postgresUserSecretKeyRef:\n    #   name: my-secret\n    #   key: postgres-user\n\n    # -- (optional) Password for \"postgres\" admin user (required ONLY for seed job!)\n    postgresPassword: \"password\"\n    # -- (optional) Password for \"postgres\" admin user from existing secret\n    postgresPasswordSecretKeyRef: {}\n    # E.g.\n    # postgresPasswordSecretKeyRef:\n    #   name: my-secret\n    #   key: postgres-password\n\nglobal:\n  # -- Set postgres user in plain text\n  postgresUser: cf_user\n  # -- Set postgres user from existing secret\n  postgresUserSecretKeyRef: {}\n  # E.g.\n  # postgresUserSecretKeyRef:\n  #   name: my-secret\n  #   key: postgres-user\n\n  # -- Set postgres password in plain text\n  postgresPassword: password\n  # -- Set postgres password from existing secret\n  postgresPasswordSecretKeyRef: {}\n  # E.g.\n  # postgresPasswordSecretKeyRef:\n  #   name: my-secret\n  #   key: postgres-password\n\n  # -- Set postgres service address in plain text.\n  postgresHostname: \"my-postgres.domain.us-east-1.rds.amazonaws.com\"\n  # -- Set postgres service from existing secret\n  postgresHostnameSecretKeyRef: {}\n  # E.g.\n  # postgresHostnameSecretKeyRef:\n  #   name: my-secret\n  #   key: postgres-hostname\n\n  # -- Set postgres port number\n  postgresPort: 5432\n\n  # -- Set postgres schema name for audit database in plain text.\n  auditPostgresSchemaName: \"public\"\n\n  # -- Disables saving events from eventbus into postgres.\n  # When it is set to “false” all events (workflows, jobs, user etc.) from eventbus are starting saving to postgres and following services (charts-manager, cluster-providers, context-manager, cfapi, cf-platform-analytics, gitops-dashboard-manager, pipeline-manager, kube-integration, tasker-kubernetes, runtime-environment-manager) start requiring postgres connection.\n  disablePostgresForEventbus: \"true\"\n\npostgresql:\n  # -- Disable postgresql subchart installation\n  enabled: false\n```\n\n##### Migrating from built-in PostgreSQL to external PostgreSQL\n\n\u003e **Note!** `PostgreSQL` is storing audit logs and analytics data for Codefresh.\n\nWe recommend using `pg_dumpall`/`pg_dump` and `psql`/`pg_restore` tools to migrate ALL the data from built-in PostgreSQL to external PostgreSQL.\n\nThe connection string or `POSTGRES_*` environment variables for built-in PostgreSQL can be obtained in `cfapi` secret.\n\n[pg_dumpall](https://www.postgresql.org/docs/current/app-pg-dumpall.html)\n\n[pg_dump](https://www.postgresql.org/docs/current/app-pgdump.html)\n\n[pg_restore](https://www.postgresql.org/docs/current/app-pgrestore.html)\n\n##### Using SSL with a PostgreSQL\n\nProvide the following env vars to enforce SSL connection to PostgresSQL:\n\n```yaml\nglobal:\n  env:\n    # More info in the official docs: https://www.postgresql.org/docs/current/libpq-envars.html\n    PGSSLMODE: \"require\"\n\nhelm-repo-manager:\n  env:\n    POSTGRES_DISABLE_SSL: \"false\"\n```\n\n\u003e ⚠️ **Important!**\u003cbr /\u003e\n\u003e We do not support custom CA configuration for PostgreSQL, including self-signed certificates. This may cause incompatibility with some providers' default configurations.\u003cbr /\u003e\n\u003e In particular, Amazon RDS for PostgreSQL version 15 and later requires SSL encryption by default ([ref](https://docs.aws.amazon.com/AmazonRDS/latest/UserGuide/PostgreSQL.Concepts.General.SSL.html#PostgreSQL.Concepts.General.SSL.Requiring)).\u003cbr /\u003e\n\u003e We recommend disabling SSL on the provider side in such cases or using the following steps to mount custom CA certificates: [Mounting private CA certs](#mounting-private-ca-certs)\n\n#### External Redis\n\n```yaml\nglobal:\n  # -- Set redis password in plain text\n  redisPassword: password\n  # -- Set redis service port\n  redisPort: 6379\n  # -- Set redis password from existing secret\n  redisPasswordSecretKeyRef: {}\n  # E.g.\n  # redisPasswordSecretKeyRef:\n  #   name: my-secret\n  #   key: redis-password\n\n  # -- Set redis hostname in plain text. Takes precedence over `global.redisService`!\n  redisUrl: \"my-redis.namespace.svc.cluster.local\"\n  # -- Set redis hostname from existing secret.\n  redisUrlSecretKeyRef: {}\n  # E.g.\n  # redisUrlSecretKeyRef:\n  #   name: my-secret\n  #   key: redis-url\n\nredis:\n  # -- Disable redis subchart installation\n  enabled: false\n\n```\n\n\u003e If ElastiCache is used, set `REDIS_TLS` to `true` in `.Values.global.env`\n\n\u003e ⚠️ ElastiCache with **Cluster mode** is not supported!\n\n##### Migrating from built-in Redis to external Redis\n\n\u003e **Note!** `Redis` among cache is storing data about CRON triggers.\n\n\u003e assuming Codefresh is installed in `codefresh` namespace with `cf` release name\n\n- Get the redis password\n\n```console\nkubectl get secret cf-redis -n codefresh -o json | jq -r '.data[\"redis-password\"]' | base64 -d\n```\n\n- Exec into built-in Redis pod\n\n```console\nkubectl -n codefresh --stdin --tty exec pod/cf-redis-master-0 -- /bin/bash\n\n# Create a dump of the existing data\nredis-cli -a \u003cREDIS_PASSWORD\u003e SAVE\n```\n\n- Copy the dump file from the pod to local machine\n\n```console\nkubectl -n codefresh cp pod/cf-redis-master-0:/data/dump.rdb ./dump.rdb\n```\n\n- Import the dump file to external Redis (based on your Redis distribution)\n\n[Restore an RDB file](https://redis.io/tutorials/guides/import/#restore-an-rdb-file)\n\n#### External Redis with MTLS\n\nIn order to use [MTLS (Mutual TLS) for Redis](https://redis.io/docs/management/security/encryption/), you need:\n\n* Create a K8S secret that contains the certificate (ca, certificate and private key).\n```console\ncat ca.crt tls.crt \u003e tls.crt\nkubectl create secret tls my-redis-tls --cert=tls.crt --key=tls.key --dry-run=client -o yaml | kubectl apply -f -\n```\n\n*  Add `.Values.global.volumes` and `.Values.global.volumeMounts` to mount the secret into all the services.\n```yaml\nglobal:\n  volumes:\n    redis-tls:\n      enabled: true\n      type: secret\n      # Existing secret with TLS certificates (keys: `ca.crt` , `tls.crt`, `tls.key`)\n      nameOverride: my-redis-tls\n      optional: true\n\n  volumeMounts:\n    redis-tls:\n      path:\n      - mountPath: /etc/ssl/redis\n\n  env:\n    REDIS_TLS: true\n    REDIS_CA_PATH: /etc/ssl/redis/ca.crt\n    REDIS_CLIENT_CERT_PATH : /etc/ssl/redis/tls.crt\n    REDIS_CLIENT_KEY_PATH: /etc/ssl/redis/tls.key\n    # Set these env vars like that if self-signed certificate is used to avoid x509 errors\n    REDIS_REJECT_UNAUTHORIZED: false\n    REDIS_TLS_SKIP_VERIFY: true\n```\n\n#### External RabbitMQ\n\n```yaml\nglobal:\n  # -- Set rabbitmq protocol (`amqp/amqps`)\n  rabbitmqProtocol: amqp\n  # -- Set rabbitmq username in plain text\n  rabbitmqUsername: user\n  # -- Set rabbitmq username from existing secret\n  rabbitmqUsernameSecretKeyRef: {}\n  # E.g.\n  # rabbitmqUsernameSecretKeyRef:\n  #   name: my-secret\n  #   key: rabbitmq-username\n\n  # -- Set rabbitmq password in plain text\n  rabbitmqPassword: password\n  # -- Set rabbitmq password from existing secret\n  rabbitmqPasswordSecretKeyRef: {}\n  # E.g.\n  # rabbitmqPasswordSecretKeyRef:\n  #   name: my-secret\n  #   key: rabbitmq-password\n\n  # -- Set rabbitmq service address in plain text. Takes precedence over `global.rabbitService`!\n  rabbitmqHostname: \"my-rabbitmq.namespace.svc.cluster.local:5672\"\n  # -- Set rabbitmq service address from existing secret.\n  rabbitmqHostnameSecretKeyRef: {}\n  # E.g.\n  # rabbitmqHostnameSecretKeyRef:\n  #   name: my-secret\n  #   key: rabbitmq-hostname\n\nrabbitmq:\n  # -- Disable rabbitmq subchart installation\n  enabled: false\n```\n\n#### External Consul\n\n```yaml\nglobal:\n  # -- Set consul service address\n  consulHost: \"my-consul-headless.namespace.svc.cluster.local\"\n\nconsul:\n  # -- Disable consul subchart installation\n  enabled: false\n```\n\n##### Migrating from built-in Consul to external Consul\n\n\u003e **Note!** `Consul` is containg data about Windows runtimes only. If you don't use Windows runtimes in your Codefresh instance, you can skip this migration.\n\n\u003e assuming Codefresh is installed in `codefresh` namespace with `cf` release name\n\n- Port-forward to built-in Consul\n\n```console\nkubectl port-forward svc/cf-consul 8500:8500 -n codefresh\n```\n\n- Export data from built-in Consul\n\n```console\ncurl -s http://localhost:8500/v1/snapshot \u003e consul.backup\n```\n\n- Port-forward to external Consul\n\n```console\nkubectl port-forward svc/my-external-consul-service 8500:8500 -n my-namespace\n```\n\n- Import data to external Consul\n\n```console\ncurl -v -T consul.backup http://localhost:8500/v1/snapshot\n```\n\n#### External Nats\n\n```yaml\nglobal:\n  # -- Set nats service address\n  queueServers: \"nats://my-nats.namespace.svc.cluster.local:4222\"\n\nnats:\n  # -- Disable nats subchart installation\n  enabled: false\n```\n\n#### BoltDB data in Cronus service\n\n`Cronus` service is using embedded `BoltDB` database to store CRON triggers data. The data is stored at `/var/boltdb/events.db` file inside the `cf-cronus` pod.\n\nThere is no option to externalize `Cronus` storage at the moment.\n\nIn case of migration to another k8s cluster, you may need to copy the `events.db` file from the existing `cf-cronus` pod and mount it to the new `cf-cronus` pod to preserve the CRON triggers data.\n\n- Copy `events.db` file from `cf-cronus` pod\n\n```console\n# Old cluster\nkubectl -n codefresh cp pod/cf-cronus-0:/var/boltdb/events.db ./events.db\n```\n\n- Copy `events.db` file to the new `cf-cronus` pod\n\n```console\n# New cluster\nkubectl -n codefresh cp ./events.db pod/cf-cronus-0:/var/boltdb/events.db\n```\n\n### Configuring Ingress-NGINX\n\nThe chart deploys the [ingress-nginx](https://github.com/kubernetes/ingress-nginx/tree/main) and exposes controller behind a Service of `Type=LoadBalancer`\n\nAll installation options for `ingress-nginx` are described at [Configuration](https://github.com/kubernetes/ingress-nginx/tree/main/charts/ingress-nginx#configuration)\n\nRelevant examples for Codefesh are below:\n\n#### ELB with SSL Termination (Classic Load Balancer)\n\n*certificate provided from ACM*\n\n```yaml\ningress-nginx:\n  controller:\n    service:\n      annotations:\n        service.beta.kubernetes.io/aws-load-balancer-backend-protocol: \"tcp\"\n        service.beta.kubernetes.io/aws-load-balancer-ssl-ports: \"443\"\n        service.beta.kubernetes.io/aws-load-balancer-connection-idle-timeout: '3600'\n        service.beta.kubernetes.io/aws-load-balancer-ssl-cert: \u003c CERTIFICATE ARN \u003e\n      targetPorts:\n        http: http\n        https: http\n\n# -- Ingress\ningress:\n  tls:\n    # -- Disable TLS\n    enabled: false\n```\n\n#### NLB (Network Load Balancer)\n\n*certificate provided as base64 string or as exisiting k8s secret*\n\n```yaml\ningress-nginx:\n  controller:\n    service:\n      annotations:\n        service.beta.kubernetes.io/aws-load-balancer-type: nlb\n        service.beta.kubernetes.io/aws-load-balancer-backend-protocol: tcp\n        service.beta.kubernetes.io/aws-load-balancer-connection-idle-timeout: '3600'\n        service.beta.kubernetes.io/aws-load-balancer-cross-zone-load-balancing-enabled: 'true'\n\n# -- Ingress\ningress:\n  tls:\n    # -- Enable TLS\n    enabled: true\n    # -- Default secret name to be created with provided `cert` and `key` below\n    secretName: \"star.codefresh.io\"\n    # -- Certificate (base64 encoded)\n    cert: \"LS0tLS1CRUdJTiBDRVJ....\"\n    # -- Private key (base64 encoded)\n    key: \"LS0tLS1CRUdJTiBSU0E...\"\n    # -- Existing `kubernetes.io/tls` type secret with TLS certificates (keys: `tls.crt`, `tls.key`)\n    existingSecret: \"\"\n```\n\n### Configuration with ALB (Application Load Balancer)\n\n*[Application Load Balancer](https://github.com/kubernetes-sigs/aws-load-balancer-controller/tree/main/helm/aws-load-balancer-controller) should be deployed to the cluster*\n\n```yaml\ningress-nginx:\n  # -- Disable ingress-nginx subchart installation\n  enabled: false\n\ningress:\n  # -- ALB contoller ingress class\n  ingressClassName: alb\n  annotations:\n    alb.ingress.kubernetes.io/actions.ssl-redirect: '{\"Type\": \"redirect\", \"RedirectConfig\":{ \"Protocol\": \"HTTPS\", \"Port\": \"443\", \"StatusCode\": \"HTTP_301\"}}'\n    alb.ingress.kubernetes.io/backend-protocol: HTTP\n    alb.ingress.kubernetes.io/certificate-arn: \u003cARN\u003e\n    alb.ingress.kubernetes.io/listen-ports: '[{\"HTTP\": 80}, {\"HTTPS\":443}]'\n    alb.ingress.kubernetes.io/scheme: internet-facing\n    alb.ingress.kubernetes.io/success-codes: 200,404\n    alb.ingress.kubernetes.io/target-type: ip\n services:\n    # For ALB /* asterisk is required in path\n    internal-gateway:\n      - /*\n\n```\n\n### Configuration with Private Registry\n\nIf you install/upgrade Codefresh on an air-gapped environment without access to public registries (i.e. `quay.io`/`docker.io`) or Codefresh Enterprise registry at `gcr.io`, you will have to mirror the images to your organization’s container registry.\n\n- Obtain [image list](https://github.com/codefresh-io/onprem-images/tree/master/releases) for specific release\n\n- [Push images](https://github.com/codefresh-io/onprem-images/blob/master/push-to-registry.sh) to private docker registry\n\n- Specify image registry in values\n\n```yaml\nglobal:\n  imageRegistry: myregistry.domain.com\n\n```\n\nThere are 3 types of images, with the values above in rendered manifests images will be converted as follows:\n\n**non-Codefresh** like:\n\n```yaml\nbitnami/mongo:4.2\nregistry.k8s.io/ingress-nginx/controller:v1.4.0\npostgres:13\n```\nconverted to:\n```yaml\nmyregistry.domain.com/bitnami/mongodb:4.2\nmyregistry.domain.com/ingress-nginx/controller:v1.2.0\nmyregistry.domain.com/postgres:13\n```\n\nCodefresh **public** images like:\n```yaml\nquay.io/codefresh/dind:20.10.13-1.25.2\nquay.io/codefresh/engine:1.147.8\nquay.io/codefresh/cf-docker-builder:1.1.14\n```\nconverted to:\n```yaml\nmyregistry.domain.com/codefresh/dind:20.10.13-1.25.2\nmyregistry.domain.com/codefresh/engine:1.147.8\nmyregistry.domain.com/codefresh/cf-docker-builder:1.1.14\n```\n\nCodefresh **private** images like:\n```yaml\ngcr.io/codefresh-enterprise/codefresh/cf-api:21.153.6\ngcr.io/codefresh-enterprise/codefresh/cf-ui:14.69.38\ngcr.io/codefresh-enterprise/codefresh/pipeline-manager:3.121.7\n```\nconverted to:\n\n```yaml\nmyregistry.domain.com/codefresh/cf-api:21.153.6\nmyregistry.domain.com/codefresh/cf-ui:14.69.38\nmyregistry.domain.com/codefresh/pipeline-manager:3.121.7\n```\n\nUse the example below to override repository for all templates:\n\n```yaml\n\nglobal:\n  imagePullSecrets:\n    - cf-registry\n\ningress-nginx:\n  controller:\n    image:\n      registry: myregistry.domain.com\n      image: codefresh/controller\n\nmongodb:\n  image:\n    repository: codefresh/mongodb\n\npostgresql:\n  image:\n    repository: codefresh/postgresql\n\nconsul:\n  image:\n    repository: codefresh/consul\n\nredis:\n  image:\n    repository: codefresh/redis\n\nrabbitmq:\n  image:\n    repository: codefresh/rabbitmq\n\nnats:\n  image:\n    repository: codefresh/nats\n\nbuilder:\n  container:\n    image:\n      repository: codefresh/docker\n\nrunner:\n  container:\n    image:\n      repository: codefresh/docker\n\ninternal-gateway:\n  container:\n    image:\n      repository: codefresh/nginx-unprivileged\n\nhelm-repo-manager:\n  chartmuseum:\n    image:\n      repository: myregistry.domain.com/codefresh/chartmuseum\n\ncf-platform-analytics-platform:\n  redis:\n    image:\n      repository: codefresh/redis\n```\n\n### Configuration with multi-role CF-API\n\nThe chart installs cf-api as a single deployment. Though, at a larger scale, we do recommend to split cf-api to multiple roles (one deployment per role) as follows:\n\n```yaml\n\nglobal:\n  # -- Change internal cfapi service address\n  cfapiService: cfapi-internal\n  # -- Change endpoints cfapi service address\n  cfapiEndpointsService: cfapi-endpoints\n\ncfapi: \u0026cf-api\n  # -- Disable default cfapi deployment\n  enabled: false\n  # -- (optional) Enable the autoscaler\n  # The value will be merged into each cfapi role. So you can specify it once.\n  hpa:\n    enabled: true\n# Enable cf-api roles\ncfapi-auth:\n  \u003c\u003c: *cf-api\n  enabled: true\ncfapi-internal:\n  \u003c\u003c: *cf-api\n  enabled: true\ncfapi-ws:\n  \u003c\u003c: *cf-api\n  enabled: true\ncfapi-admin:\n  \u003c\u003c: *cf-api\n  enabled: true\ncfapi-endpoints:\n  \u003c\u003c: *cf-api\n  enabled: true\ncfapi-terminators:\n  \u003c\u003c: *cf-api\n  enabled: true\ncfapi-sso-group-synchronizer:\n  \u003c\u003c: *cf-api\n  enabled: true\ncfapi-buildmanager:\n  \u003c\u003c: *cf-api\n  enabled: true\ncfapi-cacheevictmanager:\n  \u003c\u003c: *cf-api\n  enabled: true\ncfapi-eventsmanagersubscriptions:\n  \u003c\u003c: *cf-api\n  enabled: true\ncfapi-kubernetesresourcemonitor:\n  \u003c\u003c: *cf-api\n  enabled: true\ncfapi-environments:\n  \u003c\u003c: *cf-api\n  enabled: true\ncfapi-gitops-resource-receiver:\n  \u003c\u003c: *cf-api\n  enabled: true\ncfapi-downloadlogmanager:\n  \u003c\u003c: *cf-api\n  enabled: true\ncfapi-teams:\n  \u003c\u003c: *cf-api\n  enabled: true\ncfapi-kubernetes-endpoints:\n  \u003c\u003c: *cf-api\n  enabled: true\ncfapi-test-reporting:\n  \u003c\u003c: *cf-api\n  enabled: true\n```\n\n### High Availability\n\nThe chart installs the non-HA version of Codefresh by default. If you want to run Codefresh in HA mode, use the example values below.\n\n\u003e **Note!** `cronus` is not supported in HA mode, otherwise builds with CRON triggers will be duplicated\n\n`values.yaml`\n```yaml\ncfapi:\n  hpa:\n    enabled: true\n    # These are the defaults for all Codefresh subcharts\n    # minReplicas: 2\n    # maxReplicas: 10\n    # targetCPUUtilizationPercentage: 70\n\nargo-platform:\n  abac:\n    hpa:\n      enabled: true\n\n  analytics-reporter:\n    hpa:\n      enabled: true\n\n  api-events:\n    hpa:\n      enabled: true\n\n  api-graphql:\n    hpa:\n      enabled: true\n\n  audit:\n    hpa:\n      enabled: true\n\n  cron-executor:\n    hpa:\n      enabled: true\n\n  event-handler:\n    hpa:\n      enabled: true\n\n  ui:\n    hpa:\n      enabled: true\n\ncfui:\n  hpa:\n    enabled: true\n\ninternal-gateway:\n  hpa:\n    enabled: true\n\ncf-broadcaster:\n  hpa:\n    enabled: true\n\ncf-platform-analytics-platform:\n  hpa:\n    enabled: true\n\ncharts-manager:\n  hpa:\n    enabled: true\n\ncluster-providers:\n  hpa:\n    enabled: true\n\ncontext-manager:\n  hpa:\n    enabled: true\n\ngitops-dashboard-manager:\n  hpa:\n    enabled: true\n\nhelm-repo-manager:\n  hpa:\n    enabled: true\n\nhermes:\n  hpa:\n    enabled: true\n\nk8s-monitor:\n  hpa:\n    enabled: true\n\nkube-integration:\n  hpa:\n    enabled: true\n\nnomios:\n  hpa:\n    enabled: true\n\npipeline-manager:\n  hpa:\n    enabled: true\n\nruntime-environment-manager:\n  hpa:\n    enabled: true\n\ntasker-kubernetes:\n  hpa:\n    enabled: true\n\n```\n\nFor infra services (MongoDB, PostgreSQL, RabbitMQ, Redis, Consul, Nats, Ingress-NGINX) from built-in Bitnami charts you can use the following example:\n\n\u003e **Note!** Use [topologySpreadConstraints](https://kubernetes.io/docs/concepts/workloads/pods/pod-topology-spread-constraints/#spread-constraints-for-pods) for better resiliency\n\n`values.yaml`\n```yaml\nglobal:\n  postgresService: postgresql-ha-pgpool\n  mongodbHost: cf-mongodb-0,cf-mongodb-1,cf-mongodb-2  # Replace `cf` with your Helm Release name\n  mongodbOptions: replicaSet=rs0\u0026retryWrites=true\n  redisUrl: cf-redis-ha-haproxy\n\nbuilder:\n  controller:\n    replicas: 3\n\nconsul:\n  replicaCount: 3\n\ncfsign:\n  controller:\n    replicas: 3\n  persistence:\n    certs-data:\n      enabled: false\n  volumes:\n    certs-data:\n      type: emptyDir\n  initContainers:\n    volume-permissions:\n      enabled: false\n\ningress-nginx:\n  controller:\n    autoscaling:\n      enabled: true\n\nmongodb:\n  architecture: replicaset\n  replicaCount: 3\n  externalAccess:\n    enabled: true\n    service:\n      type: ClusterIP\n\nnats:\n  replicaCount: 3\n\npostgresql:\n  enabled: false\n\npostgresql-ha:\n  enabled: true\n  volumePermissions:\n    enabled: true\n\nrabbitmq:\n  replicaCount: 3\n\nredis:\n  enabled: false\n\nredis-ha:\n  enabled: true\n```\n\n### Mounting private CA certs\n\n```yaml\nglobal:\n  env:\n    NODE_EXTRA_CA_CERTS: /etc/ssl/custom/ca.crt\n\n  volumes:\n    custom-ca:\n      enabled: true\n      type: secret\n      existingName: my-custom-ca-cert # exisiting K8s secret object with the CA cert\n      optional: true\n\n  volumeMounts:\n    custom-ca:\n      path:\n      - mountPath: /etc/ssl/custom/ca.crt\n        subPath: ca.crt\n```\n\n## Installing on OpenShift\n\nTo deploy Codefresh On-Prem on OpenShift use the following values example:\n\n```yaml\ningress:\n  ingressClassName: openshift-default\n\nglobal:\n  dnsService: dns-default\n  dnsNamespace: openshift-dns\n  clusterDomain: cluster.local\n\n# Requires privileged SCC.\nbuilder:\n  enabled: false\n\ncfapi:\n  podSecurityContext:\n    enabled: false\n\ncf-platform-analytics-platform:\n  redis:\n    master:\n      podSecurityContext:\n        enabled: false\n      containerSecurityContext:\n        enabled: false\n\ncfsign:\n  podSecurityContext:\n    enabled: false\n  initContainers:\n    volume-permissions:\n      enabled: false\n\ncfui:\n  podSecurityContext:\n    enabled: false\n\ninternal-gateway:\n  podSecurityContext:\n    enabled: false\n\nhelm-repo-manager:\n  chartmuseum:\n    securityContext:\n      enabled: false\n\nconsul:\n  podSecurityContext:\n    enabled: false\n  containerSecurityContext:\n    enabled: false\n\ncronus:\n  podSecurityContext:\n    enabled: false\n\ningress-nginx:\n  enabled: false\n\nmongodb:\n  podSecurityContext:\n    enabled: false\n  containerSecurityContext:\n    enabled: false\n\npostgresql:\n  primary:\n    podSecurityContext:\n      enabled: false\n    containerSecurityContext:\n      enabled: false\n\nredis:\n  master:\n    podSecurityContext:\n      enabled: false\n    containerSecurityContext:\n      enabled: false\n\nrabbitmq:\n  podSecurityContext:\n    enabled: false\n  containerSecurityContext:\n    enabled: false\n\n# Requires privileged SCC.\nrunner:\n  enabled: false\n```\n\n## Firebase Configuration\n\nAs outlined in [prerequisites](#prerequisites), it's required to set up a Firebase database for builds logs streaming:\n\n- [Create a Database](https://firebase.google.com/docs/database/web/start#create_a_database).\n- Create a [Legacy token](https://firebase.google.com/docs/database/rest/auth#legacy_tokens) for authentication.\n- Set the following rules for the database:\n```json\n{\n   \"rules\": {\n       \"build-logs\": {\n           \"$jobId\":{\n               \".read\": \"!root.child('production/build-logs/'+$jobId).exists() || (auth != null \u0026\u0026 auth.admin == true) || (auth == null \u0026\u0026 data.child('visibility').exists() \u0026\u0026 data.child('visibility').val() == 'public') || ( auth != null \u0026\u0026 data.child('accountId').exists() \u0026\u0026 auth.accountId == data.child('accountId').val() )\",\n               \".write\": \"auth != null \u0026\u0026 data.child('accountId').exists() \u0026\u0026 auth.accountId == data.child('accountId').val()\"\n           }\n       },\n       \"environment-logs\": {\n           \"$environmentId\":{\n               \".read\": \"!root.child('production/environment-logs/'+$environmentId).exists() || ( auth != null \u0026\u0026 data.child('accountId').exists() \u0026\u0026 auth.accountId == data.child('accountId').val() )\",\n               \".write\": \"auth != null \u0026\u0026 data.child('accountId').exists() \u0026\u0026 auth.accountId == data.child('accountId').val()\"\n           }\n       }\n   }\n}\n```\n\nHowever, if you're in an air-gapped environment, you can omit this prerequisite and use a built-in logging system (i.e. `OfflineLogging` feature-flag).\nSee [feature management](https://codefresh.io/docs/docs/installation/on-premises/on-prem-feature-management)\n\n## Additional configuration\n\n### Retention policy for builds and logs\n\nWith this method, Codefresh by default deletes builds older than six months.\n\nThe retention mechanism removes data from the following collections: `workflowproccesses`, `workflowrequests`, `workflowrevisions`\n\n```yaml\ncfapi:\n  env:\n    # Determines if automatic build deletion through the Cron job is enabled.\n    RETENTION_POLICY_IS_ENABLED: true\n    # The maximum number of builds to delete by a single Cron job. To avoid database issues, especially when there are large numbers of old builds, we recommend deleting them in small chunks. You can gradually increase the number after verifying that performance is not affected.\n    RETENTION_POLICY_BUILDS_TO_DELETE: 50\n    # The number of days for which to retain builds. Builds older than the defined retention period are deleted.\n    RETENTION_POLICY_DAYS: 180\n```\n\n### Retention policy for builds and logs\n\u003e Configuration for Codefresh On-Prem \u003e= 2.x\n\n\u003e Previous configuration example (i.e. `RETENTION_POLICY_IS_ENABLED=true` ) is also supported in Codefresh On-Prem \u003e= 2.x\n\n**For existing environments, for the retention mechanism to work, you must first drop the `created ` index in `workflowprocesses` collection. This requires a maintenance window that depends on the number of builds.**\n\n```yaml\ncfapi:\n  env:\n    # Determines if automatic build deletion is enabled.\n    TTL_RETENTION_POLICY_IS_ENABLED: true\n    # The number of days for which to retain builds, and can be between 30 (minimum) and 365 (maximum). Builds older than the defined retention period are deleted.\n    TTL_RETENTION_POLICY_IN_DAYS: 180\n```\n\n### Projects pipelines limit\n\n```yaml\npipeline-manager:\n  env:\n    # Determines project's pipelines limit (default: 500)\n    PROJECT_PIPELINES_LIMIT: 500\n```\n\n### Enable session cookie\n\n```yaml\ncfapi:\n  env:\n    # Generate a unique session cookie (cf-uuid) on each login\n    DISABLE_CONCURRENT_SESSIONS: true\n    # Customize cookie domain\n    CF_UUID_COOKIE_DOMAIN: .mydomain.com\n```\n\n\u003e **Note!** Ingress host for [gitops-runtime](https://artifacthub.io/packages/helm/codefresh-gitops-runtime/gitops-runtime) and ingress host for control plane must share the same root domain (i.e. `onprem.mydomain.com` and `runtime.mydomain.com`)\n\n### X-Frame-Options response header\n\n```yaml\ncfapi:\n  env:\n    # Set value to the `X-Frame-Options` response header. Control the restrictions of embedding Codefresh page into the iframes.\n    # Possible values: sameorigin(default) / deny\n    FRAME_OPTIONS: sameorigin\n\ncfui:\n  env:\n    FRAME_OPTIONS: sameorigin\n```\n\nRead more about header at https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/X-Frame-Options.\n\n### Configure CSP (Content Security Policy)\n\n`CONTENT_SECURITY_POLICY` is the string describing content policies. Use semi-colons to separate between policies. `CONTENT_SECURITY_POLICY_REPORT_TO` is a comma-separated list of JSON objects. Each object must have a name and an array of endpoints that receive the incoming CSP reports.\n\nFor detailed information, see the [Content Security Policy article on MDN](https://developer.mozilla.org/en-US/docs/Web/HTTP/CSP).\n\n```yaml\ncfui:\n  env:\n    CONTENT_SECURITY_POLICY: \"\u003cYOUR SECURITY POLICIES\u003e\"\n    CONTENT_SECURITY_POLICY_REPORT_ONLY: \"default-src 'self'; font-src 'self'\n      https://fonts.gstatic.com; script-src 'self' https://unpkg.com https://js.stripe.com;\n      style-src 'self' https://fonts.googleapis.com; 'unsafe-eval' 'unsafe-inline'\"\n    CONTENT_SECURITY_POLICY_REPORT_TO: \"\u003cLIST OF ENDPOINTS AS JSON OBJECTS\u003e\"\n```\n\n### x-hub-signature-256 signature for GitHub AE\n\nFor detailed information, see the [Securing your webhooks](https://docs.github.com/en/developers/webhooks-and-events/webhooks/securing-your-webhooks) and [Webhooks](https://docs.github.com/en/github-ae@latest/rest/webhooks).\n\n```\ncfapi:\n  env:\n    USE_SHA256_GITHUB_SIGNATURE: \"true\"\n```\n\n### Image digests in containers\n\nIn Codefresh On-Prem 2.6.x all Codefresh owner microservices include image digests in the default subchart values.\n\nFor example, default values for `cfapi` might look like this:\n\n```yaml\ncontainer:\n  image:\n    registry: us-docker.pkg.dev/codefresh-enterprise/gcr.io\n    repository: codefresh/cf-api\n    tag: 21.268.1\n    digest: \"sha256:bae42f8efc18facc2bf93690fce4ab03ef9607cec4443fada48292d1be12f5f8\"\n    pullPolicy: IfNotPresent\n```\n\nthis resulting in the following image reference in the pod spec:\n\n```yaml\nspec:\n  containers:\n    - name: cfapi\n      image: us-docker.pkg.dev/codefresh-enterprise/gcr.io/codefresh/cf-api:21.268.1@sha256:bae42f8efc18facc2bf93690fce4ab03ef9607cec4443fada48292d1be12f5f8\n```\n\n\u003e **Note!** When the `digest` is providerd, the `tag` is ignored! You can omit digest and use tag only like the following `values.yaml` example:\n\n```yaml\ncfapi:\n  container:\n    image:\n      tag: 21.268.1\n      # -- Set empty tag for digest\n      digest: \"\"\n```\n\n### Hermes configuration\n\n\u003e **Note!** Unlike other services, `Hermes` requires Redis with persistent storage. ⚠️  **Thus, ElastiCache is not supported for Hermes!** It's recommended to deploy in-cluster Redis with persistence enabled (e.g. [bitnami/redis](https://github.com/bitnami/charts/tree/main/bitnami/redis) or [redis-ha](https://github.com/DandyDeveloper/charts/blob/master/charts/redis-ha/Chart.yaml)) and update the `REDIS_HOST` and `REDIS_PASSWORD` accordingly for `hermes` subchart.\n\n```yaml\nhermes:\n  container:\n    env:\n      REDIS_HOST: redis-ha-haproxy\n      REDIS_PASSWORD:\n        valueFrom:\n          secretKeyRef:\n            name: redis\n            key: REDIS_PASSWORD\n```\n\n## Configuring OIDC Provider\n\nOpenID Connect (OIDC) allows Codefresh Builds to access resources in your cloud provider (such as AWS, Azure, GCP), without needing to store cloud credentials as long-lived pipeline secret variables.\n\n### Enabling the OIDC Provider in Codefresh On-Prem\n\n#### Prerequisites:\n\n- DNS name for OIDC Provider\n- Valid TLS certificates for Ingress\n- K8S secret containing JWKS (JSON Web Key Sets). Can be generated at [mkjwk.org](https://mkjwk.org/)\n- K8S secret containing Cliend ID (public identifier for app) and Client Secret (application password; cryptographically strong random string)\n\n\u003e **NOTE!** In production usage use [External Secrets Operator](https://external-secrets.io/latest/) or [HashiCorp Vault](https://developer.hashicorp.com/vault/docs/platform/k8s) to create secrets. The following example uses `kubectl` for brevity.\n\nFor JWKS use **Public and Private Keypair Set** (if generated at [mkjwk.org](https://mkjwk.org/)), for example:\n\n`cf-oidc-provider-jwks.json`:\n```json\n{\n    \"keys\": [\n        {\n            \"p\": \"...\",\n            \"kty\": \"RSA\",\n            \"q\": \"...\",\n            \"d\": \"...\",\n            \"e\": \"AQAB\",\n            \"use\": \"sig\",\n            \"qi\": \"...\",\n            \"dp\": \"...\",\n            \"alg\": \"RS256\",\n            \"dq\": \"...\",\n            \"n\": \"...\"\n        }\n    ]\n}\n```\n\n```console\n# Creating secret containing JWKS.\n# The secret KEY is `cf-oidc-provider-jwks.json`. It then referenced in `OIDC_JWKS_PRIVATE_KEYS_PATH` environment variable in `cf-oidc-provider`.\n# The secret NAME is referenced in `.volumes.jwks-file.nameOverride` (volumeMount is configured in the chart already)\nkubectl create secret generic cf-oidc-provider-jwks \\\n  --from-file=cf-oidc-provider-jwks.json \\\n  -n $NAMESPACE\n\n# Creating secret containing Client ID and Client Secret\n# Secret NAME is `cf-oidc-provider-client-secret`.\n# It then referenced in `OIDC_CF_PLATFORM_CLIENT_ID` and `OIDC_CF_PLATFORM_CLIENT_SECRET` environment variables in `cf-oidc-provider`\n# and in `OIDC_PROVIDER_CLIENT_ID` and `OIDC_PROVIDER_CLIENT_SECRET` in `cfapi`.\nkubectl create secret generic cf-oidc-provider-client-secret \\\n  --from-literal=client-id=codefresh \\\n  --from-literal=client-secret='verysecureclientsecret' \\\n  -n $NAMESPACE\n```\n\n`values.yaml`\n```yaml\nglobal:\n  # -- Set OIDC Provider URL\n  oidcProviderService: \"oidc.mydomain.com\"\n  # -- Default OIDC Provider service client ID in plain text.\n  # Optional! If specified here, no need to specify CLIENT_ID/CLIENT_SECRET env vars in cfapi and cf-oidc-provider below.\n  oidcProviderClientId: null\n  # -- Default OIDC Provider service client secret in plain text.\n  # Optional! If specified here, no need to specify CLIENT_ID/CLIENT_SECRET env vars in cfapi and cf-oidc-provider below.\n  oidcProviderClientSecret: null\n\ncfapi:\n  # -- Set additional variables for cfapi\n  # Reference a secret containing Client ID and Client Secret\n  env:\n    OIDC_PROVIDER_CLIENT_ID:\n      valueFrom:\n        secretKeyRef:\n          name: cf-oidc-provider-client-secret\n          key: client-id\n    OIDC_PROVIDER_CLIENT_SECRET:\n      valueFrom:\n        secretKeyRef:\n          name: cf-oidc-provider-client-secret\n          key: client-secret\n\ncf-oidc-provider:\n  # -- Enable OIDC Provider\n  enabled: true\n\n  container:\n    env:\n      OIDC_JWKS_PRIVATE_KEYS_PATH: /secrets/jwks/cf-oidc-provider-jwks.json\n      # -- Reference a secret containing Client ID and Client Secret\n      OIDC_CF_PLATFORM_CLIENT_ID:\n        valueFrom:\n          secretKeyRef:\n            name: cf-oidc-provider-client-secret\n            key: client-id\n      OIDC_CF_PLATFORM_CLIENT_SECRET:\n        valueFrom:\n          secretKeyRef:\n            name: cf-oidc-provider-client-secret\n            key: client-secret\n\n  volumes:\n    jwks-file:\n      enabled: true\n      type: secret\n      # -- Secret name containing JWKS\n      nameOverride: \"cf-oidc-provider-jwks\"\n      optional: false\n\n  ingress:\n    main:\n      # -- Enable ingress for OIDC Provider\n      enabled: true\n      annotations: {}\n      # -- Set ingress class name\n      ingressClassName: \"\"\n      hosts:\n        # -- Set OIDC Provider URL\n      - host: \"oidc.mydomain.com\"\n        paths:\n        - path: /\n        # For ALB (Application Load Balancer) /* asterisk is required in path\n        # e.g.\n        # - path: /*\n      tls: []\n```\n\nDeploy HELM chart with new `values.yaml`\n\nUse https://oidc.mydomain.com/.well-known/openid-configuration to verify OIDC Provider configuration\n\n### Adding the identity provider in AWS\n\nTo add Codefresh OIDC provider to IAM, see the [AWS documentation](https://docs.aws.amazon.com/IAM/latest/UserGuide/id_roles_providers_create_oidc.html)\n- For the **provider URL**: Use `.Values.global.oidcProviderService` value with `https://` prefix (i.e. https://oidc.mydomain.com)\n- For the **Audienece**: Use `.Values.global.appUrl` value with `https://` prefix (i.e. https://onprem.mydomain.com)\n\n#### Configuring the role and trust policy\n\nTo configure the role and trust in IAM, see [AWS documentation](https://docs.aws.amazon.com/IAM/latest/UserGuide/id_roles_create_for-idp_oidc.html)\n\nEdit the trust policy to add the sub field to the validation conditions. For example, use `StringLike` to allow only builds from specific pipeline to assume a role in AWS.\n```json\n{\n    \"Version\": \"2012-10-17\",\n    \"Statement\": [\n        {\n            \"Effect\": \"Allow\",\n            \"Principal\": {\n                \"Federated\": \"arn:aws:iam::\u003cACCOUNT_ID\u003e:oidc-provider/oidc.mydomain.com\"\n            },\n            \"Action\": \"sts:AssumeRoleWithWebIdentity\",\n            \"Condition\": {\n                \"StringEquals\": {\n                    \"oidc.mydomain.com:aud\": \"https://onprem.mydomain.com\"\n                },\n                \"StringLike\": {\n                    \"oidc.mydomain.com:sub\": \"account:64884faac2751b77ca7ab324:pipeline:64f7232ab698cfcb95d93cef:*\"\n                }\n            }\n        }\n    ]\n}\n```\n\nTo see all the claims supported by Codefresh OIDC provider, see `claims_supported` entries at https://oidc.mydomain.com/.well-known/openid-configuration\n```json\n\"claims_supported\": [\n  \"sub\",\n  \"account_id\",\n  \"account_name\",\n  \"pipeline_id\",\n  \"pipeline_name\",\n  \"workflow_id\",\n  \"initiator\",\n  \"scm_user_name\",\n  \"scm_repo_url\",\n  \"scm_ref\",\n  \"scm_pull_request_target_branch\",\n  \"sid\",\n  \"auth_time\",\n  \"iss\"\n]\n```\n\n#### Using OIDC in Codefresh Builds\n\nUse [obtain-oidc-id-token](https://github.com/codefresh-io/steps/blob/822afc0a9a128384e76459c6573628020a2cf404/incubating/obtain-oidc-id-token/step.yaml#L27-L58) and [aws-sts-assume-role-with-web-identity](https://github.com/codefresh-io/steps/blob/822afc0a9a128384e76459c6573628020a2cf404/incubating/aws-sts-assume-role-with-web-identity/step.yaml#L29-L63) steps to exchange the OIDC token (JWT) for a cloud access token.\n\n## Maintaining MongoDB Indexes\n\nSometimes, in new releases of Codefresh On-Prem, index requirements change. When this happens, it's mentioned in the [Upgrading section](#upgrading) for the specific release.\n\n\u003e [!TIP]\n\u003e If you're upgrading from version `X` to version `Y`, and index requirements were updated in any of the intermediate versions, you only need to align your indexes with the index requirements of version `Y`. To do that, follow [Index alignment](#index-alignment) instructions.\n\n### Index alignment\n\nThe required index definitions for each release can be found at the following resources:\n\n- `2.6` \u003chttps://github.com/codefresh-io/codefresh-onprem-helm/tree/release-2.6/indexes\u003e\n- `2.7` \u003chttps://github.com/codefresh-io/codefresh-onprem-helm/tree/release-2.7/indexes\u003e\n- `2.8` \u003chttps://github.com/codefresh-io/codefresh-onprem-helm/tree/release-2.8/indexes\u003e\n- `2.9` \u003chttps://github.com/codefresh-io/codefresh-onprem-helm/tree/release-2.9/indexes\u003e\n- `2.10` \u003chttps://github.com/codefresh-io/codefresh-onprem-helm/tree/release-2.10/indexes\u003e\n\nThe indexes specifications are stored in JSON files. The directory structure is:\n\n```console\nindexes\n├── \u003cDB_NAME\u003e # MongoDB database name\n│   ├── \u003cCOLLECTION_NAME\u003e.json # MongoDB indexes for the specified collection\n```\n\n**Overview of the index alignment process:**\n\n1. Identify the differences between the indexes in your MongoDB instance and the required index definitions.\n2. Create any missing indexes.\n3. Perform the upgrade of Codefresh On-Prem installation.\n4. Then remove any unnecessary indexes.\n\n\u003e [!IMPORTANT]\n\u003e Any changes to indexes should be performed during a defined maintenance window or during periods of lowest traffic to MongoDB.**\n\u003e\n\u003e Building indexes during time periods where the target collection is under heavy write load can result in reduced write performance and longer index builds. ([*Source: MongoDB official documentation*](https://www.mongodb.com/docs/manual/core/index-creation/#index-build-impact-on-database-performance))\n\u003e\n\u003e Even minor changes to indexes (e.g., index removal) can cause brief but noticeable performance degradation ([*Source: MongoDB official documentation*](https://www.mongodb.com/docs/manual/core/query-plans/#plan-cache-flushes))\n\n#### Self-hosted MongoDB\n\nFor self-hosted MongoDB, follow the instructions below:\n\n- Connect to the MongoDB server using the [mongosh](https://www.mongodb.com/docs/mongodb-shell/install/) shell. Open your terminal or command prompt and run the following command, replacing `\u003cconnection_string\u003e` with the appropriate MongoDB connection string for your server:\n\n```shell\nmongosh \"\u003cconnection_string\u003e\"\n```\n\n- Retrieve the list of indexes for a specific collection:\n\n```js\ndb.getSiblingDB('\u003cdb_name\u003e').getCollection('\u003ccollection_name\u003e').getIndexes()\n```\n\n- Compare your indexes with the required indexes for the target release, and adjust them by creating any missing indexes or removing any unnecessary ones.\n\n**Index creation**\n\n- To create an indexes, we recommend using the `createIndexes` command ([ref](https://www.mongodb.com/docs/manual/reference/command/createIndexes/)):\n\n\u003e [!IMPORTANT]\n\u003e We recommend to create indexes in batches of 3 indexes at a time.\n\u003e However, it's highly recommended before creating indexes in production DB to test performance impact on a staging instance with prod-like amount of data.\n\u003e\n\u003e Previous command should be completed before starting the next batch.\n\n```js\ndb.getSiblingDB('\u003cdb_name\u003e').runCommand(\n  {\n    createIndexes: '\u003ccollection_name\u003e',\n    indexes: [\n        { ... },  // Index definition from the doc above\n        { ... },  // Index definition from the doc above\n        { ... }   // Index definition from the doc above\n    ],\n  }\n)\n```\n\nAfter executing the command, you should see a result indicating that the indexes were created successfully.\n\n**Index removal**\n\n- To remove an index, use the `dropIndex()` method with `\u003cindex_name\u003e`:\n\n```js\ndb.getSiblingDB('\u003cdb_name\u003e').getCollection('\u003ccollection_name\u003e').dropIndex('\u003cindex_name\u003e')\n```\n\n#### Atlas Database\n\nIf you're hosting MongoDB on [Atlas](https://www.mongodb.com/atlas/database), use the following [Manage Indexes](https://www.mongodb.com/docs/atlas/atlas-ui/indexes/) guide to View, Create or Remove indexes.\n\n\u003e [!IMPORTANT]\n\u003e In Atlas, for production environments, it may be recommended to use rolling index builds by enabling the \"Build index via rolling process\" checkbox. ([*MongoDB official documentation*](https://www.mongodb.com/docs/v7.0/tutorial/build-indexes-on-replica-sets/))\n\n## Upgrading\n\n### To 2-0-0\n\nThis major chart version change (v1.4.X -\u003e v2.0.0) contains some **incompatible breaking change needing manual actions**.\n\n**Before applying the upgrade, read through this section!**\n\n#### ⚠️ New Services\n\nCodefesh 2.0 chart includes additional dependent microservices (charts):\n- `argo-platform`: Main Codefresh GitOps module.\n- `internal-gateway`: NGINX that proxies requests to the correct components (api-graphql, api-events, ui).\n- `argo-hub-platform`: Service for Argo Workflow templates.\n- `platform-analytics` and `etl-starter`: Service for [Pipelines dasboard](https://codefresh.io/docs/docs/dashboards/home-dashboard/#pipelines-dashboard)\n\nThese services require additional databases in MongoDB (`audit`/`read-models`/`platform-analytics-postgres`) and in Postgresql (`analytics` and `analytics_pre_aggregations`)\nThe helm chart is configured to re-run seed jobs to create necessary databases and users during the upgrade.\n\n```yaml\nseed:\n  # -- Enable all seed jobs\n  enabled: true\n```\n\n#### ⚠️ New MongoDB Indexes\n\nStarting from version 2.0.0, two new MongoDB indexes have been added that are vital for optimizing database queries and enhancing overall system performance. It is crucial to create these indexes before performing the upgrade to avoid any potential performance degradation.\n\n- `account_1_annotations.key_1_annotations.value_1` (db: `codefresh`; collection: `annotations`)\n```json\n{\n    \"account\" : 1,\n    \"annotations.key\" : 1,\n    \"annotations.value\" : 1\n}\n```\n\n- `accountId_1_entityType_1_entityId_1` (db: `codefresh`; collection: `workflowprocesses`)\n\n```json\n{\n    \"accountId\" : 1,\n    \"entityType\" : 1,\n    \"entityId\" : 1\n}\n```\n\nTo prevent potential performance degradation during the upgrade, it is important to schedule a maintenance window during a period of low activity or minimal user impact and create the indexes mentioned above before initiating the upgrade process. By proactively creating these indexes, you can avoid the application automatically creating them during the upgrade and ensure a smooth transition with optimized performance.\n\n**Index Creation**\n\nIf you're hosting MongoDB on [Atlas](https://www.mongodb.com/atlas/database), use the following [Create, View, Drop, and Hide Indexes](https://www.mongodb.com/docs/atlas/atlas-ui/indexes/) guide to create indexes mentioned above. It's important to create them in a rolling fashion (i.e. **Build index via rolling process** checkbox enabled) in produciton environment.\n\nFor self-hosted MongoDB, see the following instruction:\n\n- Connect to the MongoDB server using the [mongosh](https://www.mongodb.com/docs/mongodb-shell/install/) shell. Open your terminal or command prompt and run the following command, replacing \u003cconnection_string\u003e with the appropriate MongoDB connection string for your server:\n```console\nmongosh \"\u003cconnection_string\u003e\"\n```\n\n- Once connected, switch to the `codefresh` database where the index will be located using the `use` command.\n```console\nuse codefresh\n```\n\n- To create the indexes, use the createIndex() method. The createIndex() method should be executed on the db object.\n```console\ndb.workflowprocesses.createIndex({ account: 1, 'annotations.key': 1, 'annotations.value': 1 }, { name: 'account_1_annotations.key_1_annotations.value_1', sparse: true, background: true })\n```\n\n```console\ndb.annotations.createIndex({ accountId: 1, entityType: 1, entityId: 1 }, { name: 'accountId_1_entityType_1_entityId_1', background: true })\n```\nAfter executing the createIndex() command, you should see a result indicating the successful creation of the index.\n\n#### ⚠️ [Kcfi](https://github.com/codefresh-io/kcfi) Deprecation\n\nThis major release deprecates [kcfi](https://github.com/codefresh-io/kcfi) installer. The recommended way to install Codefresh On-Prem is **Helm**.\nDue to that, Kcfi `config.yaml` will not be compatible for Helm-based installation.\nYou still can reuse the same `config.yaml` for the Helm chart, but you need to remove (or update) the following sections.\n\n* `.Values.metadata` is deprecated. Remove it from `config.yaml`\n\n*1.4.x `config.yaml`*\n```yaml\nmetadata:\n  kind: codefresh\n  installer:\n    type: helm\n    helm:\n      chart: codefresh\n      repoUrl: http://chartmuseum.codefresh.io/codefresh\n      version: 1.4.x\n```\n\n* `.Values.kubernetes` is deprecated. Remove it from `config.yaml`\n\n*1.4.x `config.yaml`*\n```yaml\nkubernetes:\n  namespace: codefresh\n  context: context-name\n```\n\n* `.Values.tls` (`.Values.webTLS`) is moved under `.Values.ingress.tls`. Remove `.Values.tls` from `config.yaml` afterwards.\n\n  See full [values.yaml](./values.yaml#L92).\n\n*1.4.x `config.yaml`*\n```yaml\ntls:\n  selfSigned: false\n  cert: certs/certificate.crt\n  key: certs/private.key\n```\n\n*2.0.0 `config.yaml`*\n```yaml\n# -- Ingress\ningress:\n  # -- Enable the Ingress\n  enabled: true\n  # -- Set the ingressClass that is used for the ingress.\n  ingressClassName: nginx-codefresh\n  tls:\n    # -- Enable TLS\n    enabled: true\n    # -- Default secret name to be created with provided `cert` and `key` below\n    secretName: \"star.codefresh.io\"\n    # -- Certificate (base64 encoded)\n    cert: \"LS0tLS1CRUdJTiBDRVJ....\"\n    # -- Private key (base64 encoded)\n    key: \"LS0tLS1CRUdJTiBSU0E...\"\n    # -- Existing `kubernetes.io/tls` type secret with TLS certificates (keys: `tls.crt`, `tls.key`)\n    existingSecret: \"\"\n```\n\n* `.Values.images` is deprecated.  Remove `.Values.images` from `config.yaml`.\n\n  - `.Values.images.codefreshRegistrySa` is changed to `.Values.imageCredentials`\n\n  - `.Values.privateRegistry.address` is changed to `.Values.global.imageRegistry` (no trailing slash `/` at the end)\n\n  See full `values.yaml` [here](./values.yaml#L2) and [here](./values.yaml#L143).\n\n*1.4.x `config.yaml`*\n```yaml\nimages:\n  codefreshRegistrySa: sa.json\n  usePrivateRegistry: true\n  privateRegistry:\n    address: myprivateregistry.domain\n    username: username\n    password: password\n```\n\n*2.0.0 `config.yaml`*\n```yaml\n# -- Credentials for Image Pull Secret object\nimageCredentials: {}\n# Pass sa.json (as a single line). Obtain GCR Service Account JSON (sa.json) at support@codefresh.io\n# E.g.:\n# imageCredentials:\n#   registry: gcr.io\n#   username: _json_key\n#   password: '{ \"type\": \"service_account\", \"project_id\": \"codefresh-enterprise\", \"private_key_id\": ... }'\n```\n\n*2.0.0 `config.yaml`*\n```yaml\nglobal:\n  # -- Global Docker image registry\n  imageRegistry: \"myprivateregistry.domain\"\n```\n\n* `.Values.dbinfra` is deprecated. Remove it from `config.yaml`\n\n*1.4.x `config.yaml`*\n```yaml\ndbinfra:\n  enabled: false\n```\n\n* `.Values.firebaseUrl` and `.Values.firebaseSecret` is moved under `.Values.global`\n\n*1.4.x `config.yaml`*\n```yaml\nfirebaseUrl: \u003curl\u003e\nfirebaseSecret: \u003csecret\u003e\nnewrelicLicenseKey: \u003ckey\u003e\n```\n\n*2.0.0 `config.yaml`*\n```yaml\nglobal:\n  # -- Firebase URL for logs streaming.\n  firebaseUrl: \"\"\n  # -- Firebase Secret.\n  firebaseSecret: \"\"\n  # -- New Relic Key\n  newrelicLicenseKey: \"\"\n```\n\n* `.Values.global.certsJobs` and `.Values.global.seedJobs` is deprecated. Use `.Values.seed.mongoSeedJob` and `.Values.seed.postgresSeedJob`.\n\n  See full [values.yaml](./values.yaml#L42).\n\n*1.4.x `config.yaml`*\n```yaml\nglobal:\n  certsJobs: true\n  seedJobs: true\n```\n\n*2.0.0 `config.yaml`*\n```yaml\nseed:\n  # -- Enable all seed jobs\n  enabled: true\n  # -- Mongo Seed Job. Required at first install. Seeds the required data (default idp/user/account), creates cfuser and required databases.\n  # @default -- See below\n  mongoSeedJob:\n    enabled: true\n  # -- Postgres Seed Job. Required at first install. Creates required user and databases.\n  # @default -- See below\n  postgresSeedJob:\n    enabled: true\n```\n\n#### ⚠️ Migration to [Library Charts](https://helm.sh/docs/topics/library_charts/)\n\nAll Codefresh subchart templates (i.e. `cfapi`, `cfui`, `pipeline-manager`, `context-manager`, etc) have been migrated to use Helm [library charts](https://helm.sh/docs/topics/library_charts/).\nThat allows unifying the values structure across all Codefresh-owned charts. However, there are some **immutable** fields in the old charts which cannot be upgraded during a regular `helm upgrade`, and require additional manual actions.\n\nRun the following commands before appying the upgrade.\n\n* Delete `cf-runner` and `cf-builder` stateful sets.\n\n```console\nkubectl delete sts cf-runner --namespace $NAMESPACE\nkubectl delete sts cf-builder --namespace $NAMESPACE\n```\n\n* Delete all jobs\n\n```console\nkubectl delete job --namespace $NAMESPACE -l release=cf\n```\n\n* In `values.yaml`/`config.yaml` remove `.Values.nomios.ingress` section if you have it\n\n```yaml\nnomios:\n  # Remove ingress section\n  ingress:\n    ...\n```\n\n### To 2-0-12\n\n#### ⚠️ Legacy ChartMuseum subchart deprecation\n\nDue to deprecation of legacy ChartMuseum subchart in favor of upstream [chartmuseum](https://github.com/chartmuseum/charts/tree/main/src/chartmuseum), you need to remove the old deployment before the upgrade due to **immutable** `matchLabels` field change in the deployment spec.\n\n```console\nkubectl delete deploy cf-chartmuseum --namespace $NAMESPACE\n```\n\n#### ⚠️ Affected values\n\n- If you have `.persistence.enabled=true` defined and NOT `.persistence.existingClaim` like:\n\n```yaml\nhelm-repo-manager:\n  chartmuseum:\n    persistence:\n      enabled: true\n```\nthen you **have to backup** the content of old PVC (mounted as `/storage` in the old deployment) **before the upgrade**!\n\n```shell\nPOD_NAME=$(kubectl get pod -l app=chartmuseum -n $NAMESPACE --no-headers -o custom-columns=\":metadata.name\")\nkubectl cp -n $NAMESPACE $POD_NAME:/storage $(pwd)/storage\n```\n\n**After the upgrade**, restore the content into new deployment:\n```shell\nPOD_NAME=$(kubectl get pod -l app.kubernetes.io/name=chartmuseum -n $NAMESPACE --no-headers -o custom-columns=\":metadata.name\")\nkubectl cp -n $NAMESPACE $(pwd)/storage $POD_NAME:/storage\n```\n\n- If you have `.persistence.existingClaim` defined, you can keep it as is:\n```yaml\nhelm-repo-manager:\n  chartmuseum:\n    existingClaim: my-claim-name\n```\n\n- If you have `.Values.global.imageRegistry` specified, it **won't be** applied for the new chartmuseum subchart. Add image registry explicitly for the subchart as follows\n\n```yaml\nglobal:\n  imageRegistry: myregistry.domain.com\n\nhelm-repo-manager:\n  chartmuseum:\n    image:\n      repository: myregistry.domain.com/codefresh/chartmuseum\n```\n\n### To 2-0-17\n\n#### ⚠️ Affected values\n\nValues structure for argo-platform images has been changed.\nAdded `registry` to align with the rest of the services.\n\n\u003e values for \u003c= v2.0.16\n```yaml\nargo-platform:\n  api-graphql:\n    image:\n      repository: gcr.io/codefresh-enterprise/codefresh-io/argo-platform-api-graphql\n  abac:\n    image:\n      repository: gcr.io/codefresh-enterprise/codefresh-io/argo-platform-abac\n  analytics-reporter:\n    image:\n      repository: gcr.io/codefresh-enterprise/codefresh-io/argo-platform-analytics-reporter\n  api-events:\n    image:\n      repository: gcr.io/codefresh-enterprise/codefresh-io/argo-platform-api-events\n  audit:\n    image:\n      repository: gcr.io/codefresh-enterprise/codefresh-io/argo-platform-audit\n  cron-executor:\n    image:\n      repository: gcr.io/codefresh-enterprise/codefresh-io/argo-platform-cron-executor\n  event-handler:\n    image:\n      repository: gcr.io/codefresh-enterprise/codefresh-io/argo-platform-event-handler\n  ui:\n    image:\n      repository: gcr.io/codefresh-enterprise/codefresh-io/argo-platform-ui\n```\n\n\u003e values for \u003e= v2.0.17\n\n```yaml\nargo-platform:\n  api-graphql:\n    image:\n      registry: gcr.io/codefresh-enterprise\n      repository: codefresh-io/argo-platform-api-graphql\n  abac:\n    image:\n      registry: gcr.io/codefresh-enterprise\n      repository: codefresh-io/argo-platform-abac\n  analytics-reporter:\n    image:\n      registry: gcr.io/codefresh-enterprise\n      repository: codefresh-io/argo-platform-analytics-reporter\n  api-events:\n    image:\n      registry: gcr.io/codefresh-enterprise\n      repository: codefresh-io/argo-platform-api-events\n  audit:\n    image:\n      registry: gcr.io/codefresh-enterprise\n      repository: codefresh-io/argo-platform-audit\n  cron-executor:\n    image:\n      registry: gcr.io/codefresh-enterprise\n      repository: codefresh-io/argo-platform-cron-executor\n  event-handler:\n    image:\n      registry: gcr.io/codefresh-enterprise\n      repository: codefresh-io/argo-platform-event-handler\n  ui:\n    image:\n      registry: gcr.io/codefresh-enterprise\n      repository: codefresh-io/argo-platform-ui\n```\n\n### To 2-1-0\n\n### [What's new in 2.1.x](https://codefresh.io/docs/docs/whats-new/on-prem-release-notes/#on-premises-version-21)\n\n#### Affected values:\n\n- [Legacy ChartMuseum subchart deprecation](#to-2-0-12)\n- [Argo-Platform images values structure change](#to-2-0-17)\n- **Changed** default ingress paths. All paths point to `internal-gateway` now. **Remove any overrides at `.Values.ingress.services`!** (updated example for ALB)\n- **Deprecated** `global.mongoURI`. **Supported for backward compatibility!**\n- **Added** `global.mongodbProtocol` / `global.mongodbUser` / `global.mongodbPassword` / `global.mongodbHost` / `global.mongodbOptions`\n- **Added** `global.mongodbUserSecretKeyRef` / `global.mongodbPasswordSecretKeyRef` / `global.mongodbHostSecretKeyRef`\n- **Added** `seed.mongoSeedJob.mongodbRootUserSecretKeyRef` / `seed.mongoSeedJob.mongodbRootPasswordSecretKeyRef`\n- **Added** `seed.postgresSeedJob.postgresUserSecretKeyRef` / `seed.postgresSeedJob.postgresPasswordSecretKeyRef`\n- **Added** `global.firebaseUrlSecretKeyRef` / `global.firebaseSecretSecretKeyRef`\n- **Added** `global.postgresUserSecretKeyRef` / `global.postgresPasswordSecretKeyRef` / `global.postgresHostnameSecretKeyRef`\n- **Added** `global.rabbitmqUsernameSecretKeyRef` / `global.rabbitmqPasswordSecretKeyRef` / `global.rabbitmqHostnameSecretKeyRef`\n- **Added** `global.redisPasswordSecretKeyRef` / `global.redisUrlSecretKeyRef`\n\n- **Removed** `global.runtimeMongoURI` (defaults to `global.mongoURI` or `global.mongodbHost`/`global.mongodbHostSecretKeyRef`/etc like values)\n- **Removed** `global.runtimeMongoDb` (defaults to `global.mongodbDatabase`)\n- **Removed** `global.runtimeRedisHost` (defaults to `global.redisUrl`/`global.redisUrlSecretKeyRef` or `global.redisService`)\n- **Removed** `global.runtimeRedisPort` (defaults to `global.redisPort`)\n- **Removed** `global.runtimeRedisPassword` (defaults to `global.redisPassword`/`global.redisPasswordSecretKeyRef`)\n- **Removed** `global.runtimeRedisDb` (defaults to values below)\n\n```yaml\ncfapi:\n  env:\n    RUNTIME_REDIS_DB: 0\n\ncf-broadcaster:\n  env:\n    REDIS_DB: 0\n```\n\n### To 2-1-7\n\n⚠️⚠️⚠️\n\u003e Since version 2.1.7 chart is pushed **only** to OCI registry at `oci://quay.io/codefresh/codefresh`\n\n\u003e Versions prior to 2.1.7 are still available in ChartMuseum at `http://chartmuseum.codefresh.io/codefresh`\n\n### To 2-2-0\n\n### [What's new in 2.2.x](https://codefresh.io/docs/docs/whats-new/on-prem-release-notes/#on-premises-version-22)\n\n#### MongoDB 5.x\n\nCodefresh On-Prem 2.2.x uses MongoDB 5.x (4.x is still supported). If you run external MongoDB, it is **highly** recommended to upgrade it to 5.x after upgrading Codefresh On-Prem to 2.2.x.\n\n#### Redis HA\n\n\u003e If you run external Redis, this is not applicable to you.\n\nCodefresh On-Prem 2.2.x adds (not replaces!) an **optional** Redis-HA (master/slave configuration with Sentinel sidecars for failover management) instead of a single Redis instance.\nTo enable it, see the following values:\n\n```yaml\nglobal:\n  redisUrl: cf-redis-ha-haproxy # Replace `cf` with your Helm release name\n\n# -- Disable standalone Redis instance\nredis:\n  enabled: false\n\n# -- Enable Redis HA\nredis-ha:\n  enabled: true\n```\n\n### To 2-3-0\n\n### [What's new in 2.3.x](https://codefresh.io/docs/docs/whats-new/on-prem-release-notes/#on-premises-version-23)\n\n⚠️ This major release changes default registry for Codefresh **private** images from GCR (`gcr.io`) to GAR (`us-docker.pkg.dev`)\n\nUpdate `.Values.imageCredentials.registry` to `us-docker.pkg.dev` if it's explicitly set to `gcr.io` in your values file.\n\nDefault `.Values.imageCredentials` for Onprem **v2.2.x and below**\n```yaml\nimageCredentials:\n  registry: gcr.io\n  username: _json_key\n  password: \u003cYOUR_SERVICE_ACCOUNT_JSON_HERE\u003e\n```\n\nDefault `.Values.imageCredentials` for Onprem **v2.3.x and above**\n```yaml\nimageCredentials:\n  registry: us-docker.pkg.dev\n  username: _json_key\n  password: \u003cYOUR_SERVICE_ACCOUNT_JSON_HERE\u003e\n```\n\n## Rollback\n\nUse `helm history` to determine which release has worked, then use `helm rollback` to perform a rollback\n\n\u003e When rollback from 2.x prune these resources due to immutabled fields changes\n\n```console\nkubectl delete sts cf-runner --namespace $NAMESPACE\nkubectl delete sts cf-builder --namespace $NAMESPACE\nkubectl delete deploy cf-chartmuseum --namespace $NAMESPACE\nkubectl delete job --namespace $NAMESPACE -l release=$RELEASE_NAME\n```\n\n```console\nhelm rollback $RELEASE_NAME $RELEASE_NUMBER \\\n    --namespace $NAMESPACE \\\n    --debug \\\n    --wait\n```\n\n### To 2-4-0\n\n### [What's new in 2.4.x](https://codefresh.io/docs/docs/whats-new/on-prem-release-notes/#on-premises-version-24)\n\n#### New cfapi-auth role\n\nNew `cfapi-auth` role is introduced in 2.4.x.\n\nIf you run onprem with [multi-role cfapi configuration](#configuration-with-multi-role-cf-api), make sure to **enable** `cfapi-auth` role:\n\n```yaml\ncfapi-auth:\n  \u003c\u003c: *cf-api\n  enabled: true\n```\n\n#### Default SYSTEM_TYPE for acccounts\n\nSince 2.4.x, `SYSTEM_TYPE` is changed to `PROJECT_ONE` by default.\n\nIf you want to preserve original `CLASSIC` values, update cfapi environment variables:\n\n```yaml\ncfapi:\n  container:\n    env:\n      DEFAULT_SYSTEM_TYPE: CLASSIC\n```\n\n### To 2-5-0\n\n### [What's new in 2.5.x](https://codefresh.io/docs/docs/whats-new/on-prem-release-notes/#on-premises-version-25)\n\n### To 2-6-0\n\n\u003e ⚠️ **WARNING! MongoDB indexes changed!**\n\u003e\n\u003e Please, follow [Maintaining MongoDB indexes](#maintaining-mongodb-indexes) guide to meet index requirements **BEFORE** the upgrade process.\n\n### [What's new in 2.6.x](https://codefresh.io/docs/docs/whats-new/on-prem-release-notes/#on-premises-version-26)\n\n#### Affected values\n\n[Image digests in containers](#image-digests-in-containers)\n\n### To 2-7-0\n\n\u003e ⚠️ **WARNING! MongoDB indexes changed!**\n\u003e\n\u003e Please, follow [Maintaining MongoDB indexes](#maintaining-mongodb-indexes) guide to meet index requirements **BEFORE** the upgrade process.\n\n### [What's new in 2.7.x](https://codefresh.io/docs/docs/whats-new/on-prem-release-notes/#on-premises-version-27)\n\n#### Affected values\n\n- Added option to provide global `tolerations`/`nodeSelector`/`affinity` for all Codefresh subcharts\n\u003e **Note!** These global settings will not be applied to Bitnami subcharts (e.g. `mongodb`, `redis`, `rabbitmq`, `postgres`. etc)\n\n```yaml\nglobal:\n  tolerations:\n    - key: \"key\"\n      operator: \"Equal\"\n      value: \"value\"\n      effect: \"NoSchedule\"\n\n  nodeSelector:\n    key: \"value\"\n\n  affinity:\n    nodeAffinity:\n      requiredDuringSchedulingIgnoredDuringExecution:\n        nodeSelectorTerms:\n          - matchExpressions:\n              - key: \"key\"\n                operator: \"In\"\n                values:\n                  - \"value\"\n```\n\n### To 2-8-0\n\n\u003e ⚠️ **WARNING! MongoDB indexes changed!**\n\u003e\n\u003e Please, follow [Maintaining MongoDB indexes](#maintaining-mongodb-indexes) guide to meet index requirements **BEFORE** the upgrade process.\n\n### [What's new in 2.8.x](https://codefresh.io/docs/docs/whats-new/on-prem-release-notes/#on-premises-version-28)\n\n### ⚠️ ⚠️ ⚠️ Breaking changes. Read before upgrading!\n\n### MongoDB update\n\nDefault MongoDB image is changed from 6.x to 7.x.\n\nIf you run external MongoDB (i.e. [Atlas](https://cloud.mongodb.com)), it is **required** to upgrade it to 7.x after upgrading Codefresh On-Prem to 2.8.x.\n\n- **Before the upgrade**, for backward compatibility (in case you need to rollback to 6.x), you should set [`featureCompatibilityVersion`](https://www.mongodb.com/docs/v6.0/reference/command/setFeatureCompatibilityVersion/) to `6.0` in your values file.\n\n```yaml\nmongodb:\n  migration:\n    enabled: true\n    featureCompatibilityVersion: \"6.0\"\n```\n\n- Perform Codefresh On-Prem upgrade to 2.8.x. Make sure all systems are up and running.\n\n- **After the upgrade**, if all system are stable, you need to set `featureCompatibilityVersion` to `7.0` in your values file and re-deploy the chart.\n\n```yaml\nmongodb:\n  migration:\n    enabled: true\n    featureCompatibilityVersion: \"7.0\"\n```\n\n⚠️ ⚠️ ⚠️ If FCV (FeatureCompatibilityVersion) is managed by MongoDB itself (i.e. Atlas), you can disable it completely (that is default value in Helm chart)\n\n```yaml\nmongodb:\n  migration:\n    enabled: false\n```\n\n### PostgreSQL update\n\nDefault PostgreSQL image is changed from 13.x to 17.x\n\nIf you run external PostgreSQL, follow the [official instructions](https://www.postgresql.org/docs/17/upgrading.html) to upgrade to 17.x.\n\n\u003e ⚠️ **Important!**\u003cbr /\u003e\n\u003e The default SSL configuration may change on your provider's side when you upgrade.\u003cbr /\u003e\n\u003e Please read the following section before the upgrade: [Using SSL with a PostgreSQL](#using-ssl-with-a-postgresql)\n\n⚠️ ⚠️ ⚠️  16.x version is also supported (17.x version of PostgreSQL is still in preview on multiple cloud providers)\n\n⚠️ ⚠️ ⚠️ If you run built-in PostgreSQL `bitnami/postgresql` subchart, direct upgrade is not supported due to **incompatible breaking changes** in the database files. You will see the following error in the logs:\n```\npostgresql 17:36:28.41 INFO  ==\u003e ** Starting PostgreSQL **\n2025-05-21 17:36:28.432 GMT [1] FATAL:  database files are incompatible with server\n2025-05-21 17:36:28.432 GMT [1] DETAIL:  The data directory was initialized by PostgreSQL version 13, which is not compatible with this version 17.2.\n```\nYou need to backup your data, delete the old PostgreSQL StatefulSet with PVCs and restore the data into a new PostgreSQL StatefulSet.\n\n- **Before the upgrade**, backup your data on a separate PVC\n\n- Create PVC with the same or bigger size as your current PostgreSQL PVC:\n\n```yaml\napiVersion: v1\nkind: PersistentVolumeClaim\nmetadata:\n  name: postgresql-dump\nspec:\n  storageClassName: \u003cSTORAGE_CLASS\u003e\n  resources:\n    requests:\n      storage: \u003cPVC_SIZE\u003e\n  volumeMode: Filesystem\n  accessModes:\n    - ReadWriteOnce\n```\n\n- Create a job to dump the data from the old PostgreSQL StatefulSet into the new PVC:\n\n```yaml\napiVersion: batch/v1\nkind: Job\nmetadata:\n  name: postgresql-dump\nspec:\n  ttlSecondsAfterFinished: 300\n  template:\n    spec:\n      containers:\n      - name: postgresql-dump\n        image: quay.io/codefresh/postgresql:17\n        resources:\n          requests:\n            memory: \"128Mi\"\n            cpu: \"100m\"\n          limits:\n            memory: \"1Gi\"\n            cpu: \"1\"\n        env:\n          - name: PGUSER\n            value: \"\u003cPOSTGRES_USER\u003e\"\n          - name: PGPASSWORD\n            value: \"\u003cPOSTGRES_PASSWORD\u003e\"\n          - name: PGHOST\n            value: \"\u003cPOSTGRES_HOST\u003e\"\n          - name: PGPORT\n            value: \"\u003cPOSTGRES_PORT\u003e\"\n        command:\n          - \"/bin/bash\"\n          - \"-c\"\n          - |\n            pg_dumpall --verbose \u003e /opt/postgresql-dump/dump.sql\n        volumeMounts:\n          - name: postgresql-dump\n            mountPath: /opt/postgresql-dump\n      securityContext:\n        runAsUser: 0\n        fsGroup: 0\n      volumes:\n        - name: postgresql-dump\n          persistentVolumeClaim:\n            claimName: postgresql-dump\n      restartPolicy: Never\n```\n\n- Delete old PostgreSQL StatefulSet and PVC\n\n```console\nSTS_NAME=$(kubectl get sts -n $NAMESPACE -l app.kubernetes.io/instance=$RELEASE_NAME -l app.kubernetes.io/name=postgresql -o jsonpath='{.items[0].metadata.name}')\nPVC_NAME=$(kubectl get pvc -n $NAMESPACE -l app.kubernetes.io/instance=$RELEASE_NAME -l app.kubernetes.io/name=postgresql -o jsonpath='{.items[0].metadata.name}')\n\nkubectl delete sts $STS_NAME -n $NAMESPACE\nkubectl delete pvc $PVC_NAME -n $NAMESPACE\n```\n\n- Peform the upgrade to 2.8.x with PostgreSQL seed job enabled to re-create users and databases\n\n```yaml\nseed:\n  postgresSeedJob:\n    enabled: true\n```\n\n- Create a job to restore the data from the new PVC into the new PostgreSQL StatefulSet:\n\n```yaml\napiVersion: batch/v1\nkind: Job\nmetadata:\n  name: postgresql-restore\nspec:\n  ttlSecondsAfterFinished: 300\n  template:\n    spec:\n      containers:\n      - name: postgresql-restore\n        image: quay.io/codefresh/postgresql:17\n        resources:\n          requests:\n            memory: \"128Mi\"\n            cpu: \"100m\"\n          limits:\n            memory: \"1Gi\"\n            cpu: \"1\"\n        env:\n          - name: PGUSER\n            value: \"\u003cPOSTGRES_USER\u003e\"\n          - name: PGPASSWORD\n            value: \"\u003cPOSTGRES_PASSWORD\u003e\"\n          - name: PGHOST\n            value: \"\u003cPOSTGRES_HOST\u003e\"\n          - name: PGPORT\n            value: \"\u003cPOSTGRES_PORT\u003e\"\n        command:\n          - \"/bin/bash\"\n          - \"-c\"\n          - |\n            psql -f /opt/postgresql-dump/dump.sql\n        volumeMounts:\n          - name: postgresql-dump\n            mountPath: /opt/postgresql-dump\n      securityContext:\n        runAsUser: 0\n        fsGroup: 0\n      volumes:\n        - name: postgresql-dump\n          persistentVolumeClaim:\n            claimName: postgresql-dump\n      restartPolicy: Never\n```\n\n### RabbitMQ update\n\nDefault RabbitMQ image is changed from 3.x to 4.0\n\nIf you run external RabbitMQ, follow the [official instructions](https://www.rabbitmq.com/docs/upgrade) to upgrade to 4.0\n\nFor built-in RabbitMQ `bitnami/rabbitmq` subchart, pre-upgrade hook was added to enable all stable feature flags.\n\n####  Affected values\n\n- Added option to provide `.Values.global.tolerations`/`.Values.global.nodeSelector`/`.Values.global.affinity` for all Codefresh subcharts\n\n- Changed default location for public images from `quay.io/codefresh` to `us-docker.pkg.dev/codefresh-inc/public-gcr-io/codefresh`\n\n- `.Values.hooks` was splitted into `.Values.hooks.mongodb` and `.Values.hooks.consul`\n\n### To 2-9-0\n\n\u003e [!WARNING]\n\u003e **BREAKING CHANGES**\n\u003e\n\u003e Default DinD image has been upgraded to 28.x, which removes support for pushing and pulling with legacy image manifest v2 schema 1 ([ref](https://docs.docker.com/engine/deprecated/#pushing-and-pulling-with-image-manifest-v2-schema-1)).\n\u003e\n\u003e Before upgrading Codefresh, please follow the instruction in [this doc](https://codefresh.io/docs/docs/kb/articles/upgrade-deprecated-docker-images/) to identify deprecated images, upgrade them, and then proceed with upgrading the platform.\n\n### To 2-9-9\n\n\u003e **BREAKING CHANGES in Default Runtime**\n\u003e\n\u003e Default Runtime (`system/default`) drops support for Kubernetes versions older than 1.32 in `deploy` step ([docs](https://codefresh.io/docs/docs/pipelines/steps/deploy/)). Supported versions are: 1.34, 1.33, 1.32.\n\n####  Affected values\n\n- `.Values.runner` is removed\n\n#### Changes in MongoDB schema\n\nChanges in indexes: follow [Maintaining MongoDB indexes](#maintaining-mongodb-indexes) guide to meet index requirements *before* the upgrade process.\n\nChanges in collections: following collections can be safely dropped *after* the upgrade to 2.9.x if they exist. These collections are no longer used and should be removed to maintain optimal database performance and prevent the accumulation of obsolete data.\n\n- `read-models.application-tree`\n- `read-models.\u003centity\u003e-history` — every collection with `~-history` suffix, such as `read-models.applications-history`, `read-models.services-history`, etc.\n\n## Troubleshooting\n\n### Error: Failed to validate connection to Docker daemon; caused by Error: certificate has expired\n\nBuilds are stuck in pending with `Error: Failed to validate connection to Docker daemon; caused by Error: certificate has expired`\n\n**Reason:** Runtime certificates have expiried.\n\nTo check if runtime internal CA expired:\n\n```console\nkubectl -n $NAMESPACE get secret/cf-codefresh-certs-client -o jsonpath=\"{.data['ca\\.pem']}\" | base64 -d | openssl x509 -enddate -noout\n```\n\n**Resolution:** Replace internal CA and re-issue dind certs for runtime\n\n- Delete k8s secret with expired certificate\n```console\nkubectl -n $NAMESPACE delete secret cf-codefresh-certs-client\n```\n\n- Set `.Values.global.gencerts.enabled=true` (`.Values.global.certsJob=true` for onprem \u003c 2.x version)\n\n```yaml\n# -- Job to generate internal runtime secrets.\n# @default -- See below\ngencerts:\n  enabled: true\n```\n\n- Upgrade Codefresh On-Prem Helm release. It will recreate `cf-codefresh-certs-client` secret\n```console\nhelm upgrade --install cf codefresh/codefresh \\\n    -f cf-values.yaml \\\n    --namespace codefresh \\\n    --create-namespace \\\n    --debug \\\n    --wait \\\n    --timeout 15m\n```\n\n- Restart `cfapi` and `cfsign` deployments\n\n```console\nkubectl -n $NAMESPACE rollout restart deployment/cf-cfapi\nkubectl -n $NAMESPACE rollout restart deployment/cf-cfsign\n```\n\n**Case A:** Codefresh Runner installed with HELM chart ([charts/cf-runtime](https://github.com/codefresh-io/venona/tree/release-1.0/charts/cf-runtime))\n\nRe-apply the `cf-runtime` helm chart. Post-upgrade `gencerts-dind` helm hook will regenerate the dind certificates using a new CA.\n\n**Case B:** Codefresh Runner installed with legacy CLI ([codefresh runner init](https://codefresh-io.github.io/cli/runner/init/))\n\nDelete `codefresh-certs-server` k8s secret and run [./configure-dind-certs.sh](https://github.com/codefresh-io/venona/blob/release-1.0/charts/cf-runtime/files/configure-dind-certs.sh) in your runtime namespace.\n\n```console\nkubectl -n $NAMESPACE delete secret codefresh-certs-server\n./configure-dind-certs.sh -n $RUNTIME_NAMESPACE https://$CODEFRESH_HOST $CODEFRESH_API_TOKEN\n```\n\n### Consul Error: Refusing to rejoin cluster because the server has been offline for more than the configured server_rejoin_age_max\n\nAfter platform upgrade, Consul fails with the error `refusing to rejoin cluster because the server has been offline for more than the configured server_rejoin_age_max - consider wiping your data dir`. There is [known issue](https://github.com/hashicorp/consul/issues/20722) of **hashicorp/consul** behaviour. Try to wipe out or delete the consul PV with config data and restart Consul StatefulSet.\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fcodefresh-io%2Fcodefresh-onprem-helm","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fcodefresh-io%2Fcodefresh-onprem-helm","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fcodefresh-io%2Fcodefresh-onprem-helm/lists"}