Skip to content

Configuration values

Describes Hibernator chart 0.12.44

Key Type Default Description
affinity object {} Affinity rules
branding.accentColor string "" The brand’s accent colour as #RRGGBB, used by the exported Help deck as a slide background behind white text and as text on white. Pick one with a contrast of at least 4.5:1 against white. Empty means the product blue #1976d2
branding.logo.dark string "" The logo for dark backgrounds such as the app bar, as SVG text: --set-file branding.logo.dark=logo-dark.svg. The rules of branding.logo.light apply, and a dark logo that breaks one voids the whole brand. Empty means the light logo
branding.logo.light string "" The logo for light backgrounds, as SVG text: --set-file branding.logo.light=logo.svg. An SVG document with a viewBox, at most 64 KiB, that runs no script and loads nothing from outside itself. See the Branding page for every rule. Required for a brand, together with branding.name
branding.name string "" The brand name, plain text of 1 to 64 characters, used as the logo’s alt text. Required for a brand, together with branding.logo.light. The API judges every branding value: a brand that breaks a rule is ignored as a whole, the product logo shows, and the API logs one warning naming the value and the rule
config.allowInsecureExternalUrl bool false Allow non-HTTPS external URLs. Only for local development without TLS; never in production
config.api.kubernetesBurst int 200 Kubernetes API burst limit for every client the API builds
config.api.kubernetesQPS int 150 Kubernetes API QPS limit (queries per second) for every client the API builds
config.api.shutdownTimeout string "30s" Graceful shutdown timeout
config.auth.adminUsers list [] List of admin user emails
config.auth.allowedEmailDomains list [] Allowed email domains (empty = all)
config.auth.privacy.anonymizeLogsEnabled bool true
config.auth.privacy.domains list [] Email domains whose addresses are anonymized. Empty means addresses are logged and stored unchanged, so list at least your own domain
config.auth.refreshExpiry string "168h" Refresh token expiry (7 days)
config.auth.tokenExpiry string "24h" JWT token expiry
config.auth.webauthn.displayName string "" Name shown in the browser’s passkey prompt. Defaults to config.clusterName, or “Hibernator” when that is empty
config.auth.webauthn.enabled bool false Enable passwordless login with FIDO2 security keys and passkeys. Users opt in individually and the emailed one-time code never goes away. See the Passkeys page
config.auth.webauthn.rpId string "" Relying Party ID. Defaults to the host of the RP origin (config.internalUrl when set, else config.externalUrl). Override only to use a registrable parent domain of that host
config.awsCosts.cacheTTL string "1h" Ignored. Cost data refreshes daily at refreshTimeUTC
config.awsCosts.costMetric string "NetUnblendedCost" Cost metric: UnblendedCost, BlendedCost, AmortizedCost, NetUnblendedCost, NetAmortizedCost
config.awsCosts.enabled bool false Disabled by default
config.awsCosts.hourlyGranularity bool true Enable hourly Cost Explorer data for accurate rate derivation (requires AWS account opt-in)
config.awsCosts.profile string "" AWS profile (optional, uses default credential chain)
config.awsCosts.proxyURL string "" HTTP proxy for the Cost Explorer API. Overrides config.proxyURL. Example: http://proxy:8080
config.awsCosts.refreshTimeUTC string "05:50" Time of day (HH:MM UTC) to refresh cost data daily (avoid full hours when hibernation/wake runs). The database rate refresh runs on the same clock; a value that is not HH:MM fails the configuration
config.awsCosts.region string "us-east-1" AWS region (Cost Explorer always uses us-east-1)
config.awsCosts.resourceTags object {} AWS resource tags applied to SSM Parameter Store parameters (requires ssm:AddTagsToResource IAM permission)
config.awsCosts.statsRegion string "" AWS region for Parameter Store (hibernation stats). Falls back to region if empty.
config.awsCosts.tagKey string "aws:eks:cluster-name" AWS-managed EKS cost allocation tag
config.awsCosts.tagValue string "" Required if enabled: EKS cluster name (e.g., “my-cluster”)
config.clusterName string "" The name of this cluster in the UI, in notifications and in external wake requests. Required: the install fails without it. Examples: “production-eu-central-1”, “staging-us-east-1”, “dev-eu-west-1”
config.controller.hibernateTierTimeout string "5m" Fallback wait timeout for a hibernate tier without its own timeout
config.controller.kubernetesBurst int 200 Kubernetes API burst limit
config.controller.kubernetesQPS int 150 Kubernetes API QPS limit (queries per second) for every client the controller builds
config.controller.maxConcurrentOperations int 50 Maximum concurrent scaling operations
config.controller.reconcileInterval string "1h" Backup/drift detection (smart scheduler handles precision)
config.controller.wakeBarrierTimeout string "5m" Fallback barrier timeout for a wake tier without its own timeout
config.controller.workloadSettleTimeout string "10m" How long a workload that declares no startupProbe of its own gets before a wake stops waiting for it
config.dashboardApi.corsOrigins list [] Origins whose browser pages may read the dashboard endpoints (CORS), for example ["https://dashboard.example.com"]
config.dashboardApi.enabled bool false Serve GET /api/v1/public/dashboard-status, the status endpoint for an external dashboard, with no sign-in. While AWS costs or Sustainability are on, their dashboard endpoints answer too
config.databases object {} Managed RDS databases, stopped and started with the schedule. Off while empty.
config.externalDependencies list [] On a dependent cluster: the resources on hosting clusters that a wake of this cluster wakes too. See the External wake page
config.externalUrl string "" Examples: https://www.example.com/hibernator/, https://hibernator.example.com/
config.externalWake.clusters list [] List of authorized clusters
config.externalWake.enabled bool false Enable to accept external wake requests
config.externalWake.excludedNamespaces list [] Namespaces that an external wake never wakes
config.externalWake.localClusterName string "" This cluster’s identity in external wake requests (required if enabled)
config.externalWake.quotas.maxConcurrentWakes int 5
config.externalWake.quotas.maxWakeDuration string "8h"
config.externalWake.quotas.maxWakesPerHour int 20
config.global.enabled bool true Set to false to stand Hibernator down. It wakes everything it scaled down, resumes the CronJobs it suspended, starts the databases it stopped and removes its satellites. Then it stops scaling until you set the value to true again. Use dry run to stop Hibernator without a change to the cluster.
config.hibernateOrdering object {} Hibernate tier list. Everything goes down in one pass while empty.
config.holidays object {"regions":[]} Public holidays shown in the calendar view. The country and state codes are those of the date-holidays package: https://www.npmjs.com/package/date-holidays
config.holidays.regions list [] Holiday regions shown in the calendar. Empty shows none
config.insights.cpuWattsPerVCPU.amd64 float 2.3
config.insights.cpuWattsPerVCPU.arm64 float 1.084
config.insights.defaultCPUCores float 0.25 Fallback when container has no CPU request
config.insights.defaultMemoryGB float 0.5 Fallback when container has no memory request
config.insights.enabled bool true
config.insights.gridIntensityGCO2ePerKWh int 298 Grid carbon intensity, eu-central-1 (DE, Jun25-May26 avg)
config.insights.memoryWattsPerGB float 0.392 CCF memory power coefficient
config.insights.pue float 1.14 Power Usage Effectiveness (AWS 2025 disclosure)
config.internalUrl string "" Second own address of this instance, exempt from the satellite redirect. When non-empty it must carry a scheme and a host; a scheme-less value parses entirely as a path and would drop the exemption silently. While config.auth.webauthn.enabled is true it must be a bare host: it is also the WebAuthn RP origin, which refuses a path, and the chart rejects one. Example: https://hibernator.internal.example.com/
config.notifications.channels object {"email":{"enabled":false,"recipients":[]},"teams":{"enabled":false,"webhooks":[]}} Notification channels
config.notifications.deduplication object {"windowSeconds":300} Deduplication configuration. It suppresses a repeated condition alert – a workload that will not scale, an oversized ConfigMap, a schedule that will not parse – which hibernator re-detects on every reconcile pass. Reports of one thing that happened, a completed wake or hibernation above all, are exempt and always sent.
config.notifications.enabled bool false Master switch for all notifications
config.notifications.events object {"confirmationWindowSeconds":300} The default event keys for every recipient and webhook, and confirmationWindowSeconds. A destination’s own events map wins for each key that it sets. See the Notifications page
config.notifications.queue object {"bufferSize":20} Queue configuration (buffering for async processing)
config.notifications.retry object {"backoffSeconds":2,"maxAttempts":3,"timeoutSeconds":30} Retry configuration (for failed notification deliveries)
config.operations.devMode bool false Development mode - enables debug features. With logLevel: debug, it adds AWS request and response bodies and request signing to the AWS SDK logs, with credentials redacted
config.operations.dryRun bool false If true, no actual changes are made
config.operations.enableApiAccessLogs bool false Enable API access logging (Caddy already provides access logs)
config.operations.logLevel string "info" Log level: debug, info, warn, error
config.proxyURL string "" HTTP proxy for outbound requests: Cost Explorer, the managed databases, Teams webhooks and URL readiness checks. A feature’s own proxyURL overrides it. Example: http://proxy.example.com:8080
config.resourceRules object {"neverScale":[]} Each entry is a ResourceSelector with: namespace (required), type, name, labels, annotations, reason
config.serviceRedirection object {"enabled":false,"services":[]} A satellite in place of each service you name while it hibernates, so a caller reaches the Hibernator wake page and not a refused connection. Off by default. See the Service redirection page
config.smtp.enabled bool true
config.smtp.from string "noreply@hibernator.local" From address
config.smtp.host string "" SMTP server host
config.smtp.port int 1025 SMTP server port
config.targeting object {"namespaces":{"exclude":[{"pattern":"kube-*"},{"exact":"hibernator"}]}} Resource targeting configuration
config.urlReadinessCheck.consecutiveThreshold int 3 Consecutive successful responses required before declaring ready (1-30)
config.urlReadinessCheck.enabled bool false Disabled by default
config.urlReadinessCheck.intervalSeconds int 5 Seconds between readiness check attempts (1-60)
config.urlReadinessCheck.proxyURL string "" HTTP proxy for outbound GET requests (e.g., http://proxy:8080)
config.urlReadinessCheck.whitelist list [] Allowed hostname patterns (supports wildcards, empty = all non-private)
config.wakeOrdering object {} Wake tier list. Unordered single pass while empty.
config.workingHours object {"schedule":{"friday":"08:00-20:00","monday":"08:00-20:00","saturday":"off","sunday":"off","thursday":"08:00-20:00","tuesday":"08:00-20:00","wednesday":"08:00-20:00"},"timezone":"Europe/Berlin"} When workloads are up: a timezone and one entry per day. An entry is off, or HH:MM-HH:MM ranges with leading zeros, separated by commas: “08:00-20:00”, “09:00-17:00,18:00-22:00”. “8:00-20:00” and “08:00-25:00” fail the install. See the Schedule page
deploymentAnnotations.app object {}
deploymentAnnotations.controller object {}
deploymentLabels.app object {}
deploymentLabels.controller object {}
externalWakeSecrets.create bool false Set to true to create secrets via Helm (false = use existing secrets created externally)
externalWakeSecrets.secrets list [] HMAC secrets the chart creates when create is true. A secret can serve one cluster or be shared by several
extraEnvVars list [] Extra environment variables
extraVolumeMounts list []
extraVolumes list []
frontend.trustedProxies list [] Proxy hops the frontend’s Caddy may believe when it reads X-Forwarded-For, as CIDRs or Caddy’s private_ranges keyword. Empty – the default – trusts none, so Caddy discards the header the caller sent and replaces it with its own view of the remote host. Behind an ingress that view is the ingress’s address, so every per-IP limit in the API collapses onto one address. What is safe to trust depends on your topology and is your decision; see the Trusted proxies page.
fullnameOverride string "" Override the full name. The only value the chart accepts is hibernator: set it when the release has a different name, and leave it empty otherwise. The controller and the API find their ConfigMap and their Service by that name
global.imagePullSecrets list [] Global image pull secrets (array of secret names)
image.api.repository string "api"
image.controller.repository string "controller" Will be combined with repositoryPrefix
image.frontend.repository string "frontend"
image.pullPolicy string "IfNotPresent"
image.registry string "registry.gitlab.com" Common settings for all images
image.repositoryPrefix string "cirriton/hibernator"
image.satellite.repository string "satellite"
image.tag string "" Defaults to Chart.appVersion
imagePullSecrets.create bool false Whether to create a new pull secret
imagePullSecrets.existingSecret string "" Name of an existing secret to use
imagePullSecrets.password string "" Registry password (required if create=true)
imagePullSecrets.registry string "registry.gitlab.com" Registry URL
imagePullSecrets.secretName string "" Name for the created secret (auto-generated if not specified)
imagePullSecrets.username string "" Registry username (required if create=true)
license string "" The license file, whole and unchanged: --set-file license=HL-XXXXXXXX.license, or a block scalar. When set, the chart renders it into the ConfigMap hibernator-license (key license), and a change restarts no pod. Leave it empty if you create that ConfigMap yourself; setting both makes Helm fail on ownership. The schema accepts only the text from the -----BEGIN HIBERNATOR LICENSE----- line to the -----END HIBERNATOR LICENSE----- line, whitespace around them, and does not check the signature. See the License page for installing, replacing and checking a license
livenessProbe.enabled bool true
livenessProbe.failureThreshold int 3
livenessProbe.initialDelaySeconds int 15
livenessProbe.periodSeconds int 20
livenessProbe.timeoutSeconds int 5
metrics.grafanaDashboard.annotations object {} Additional annotations on the dashboard ConfigMap
metrics.grafanaDashboard.enabled bool false
metrics.grafanaDashboard.extraLabels object {} Additional labels on the dashboard ConfigMap
metrics.grafanaDashboard.folder string "Hibernator" Target folder in Grafana (requires foldersFromFilesStructure in Grafana provisioning)
metrics.grafanaDashboard.sidecarLabel string "grafana_dashboard" Sidecar label used by Grafana to discover dashboard ConfigMaps
metrics.grafanaDashboard.sidecarLabelValue string "1"
metrics.prometheusRule.additionalLabels object {} Additional labels on the PrometheusRule resource (e.g., for operator discovery)
metrics.prometheusRule.alertExtraAnnotations object {} Extra annotations added to every alert rule
metrics.prometheusRule.alertExtraLabels object {} Extra labels added to every alert rule
metrics.prometheusRule.alerts.apiErrorRate.enabled bool true
metrics.prometheusRule.alerts.apiErrorRate.for string "5m"
metrics.prometheusRule.alerts.apiErrorRate.severity string "warning"
metrics.prometheusRule.alerts.apiErrorRate.thresholdPercent float 0.05
metrics.prometheusRule.alerts.configMapSizeCritical.enabled bool true
metrics.prometheusRule.alerts.configMapSizeCritical.for string "10m"
metrics.prometheusRule.alerts.configMapSizeCritical.severity string "critical"
metrics.prometheusRule.alerts.configMapSizeCritical.thresholdBytes int 900000
metrics.prometheusRule.alerts.configMapSizeWarning.enabled bool true
metrics.prometheusRule.alerts.configMapSizeWarning.for string "15m"
metrics.prometheusRule.alerts.configMapSizeWarning.severity string "warning"
metrics.prometheusRule.alerts.configMapSizeWarning.thresholdBytes int 819200
metrics.prometheusRule.alerts.licenseExpiring.enabled bool true HibernatorLicenseExpiring: the license expires within 30 days.
metrics.prometheusRule.alerts.licenseExpiring.for string "5m"
metrics.prometheusRule.alerts.licenseExpiring.severity string "warning"
metrics.prometheusRule.alerts.licenseUnverified.enabled bool true HibernatorLicenseUnverified: the license check cannot tell, and Hibernator still acts until the stop date in the alert’s description. It waits until a day after the last licensed check, as the UI and the notifications do: a check that succeeds at least once a day is no news.
metrics.prometheusRule.alerts.licenseUnverified.for string "5m"
metrics.prometheusRule.alerts.licenseUnverified.severity string "warning"
metrics.prometheusRule.alerts.notActing.enabled bool true HibernatorNotActing: no license verdict lets Hibernator act, so it is not scaling.
metrics.prometheusRule.alerts.notActing.for string "5m"
metrics.prometheusRule.alerts.notActing.severity string "warning"
metrics.prometheusRule.alerts.parameterStoreSizeCritical.enabled bool true
metrics.prometheusRule.alerts.parameterStoreSizeCritical.for string "10m"
metrics.prometheusRule.alerts.parameterStoreSizeCritical.severity string "critical"
metrics.prometheusRule.alerts.parameterStoreSizeCritical.thresholdBytes int 3900
metrics.prometheusRule.alerts.parameterStoreSizeWarning.enabled bool true
metrics.prometheusRule.alerts.parameterStoreSizeWarning.for string "15m"
metrics.prometheusRule.alerts.parameterStoreSizeWarning.severity string "warning"
metrics.prometheusRule.alerts.parameterStoreSizeWarning.thresholdBytes int 3500
metrics.prometheusRule.alerts.passkeyStoreSizeWarning.enabled bool true
metrics.prometheusRule.alerts.passkeyStoreSizeWarning.for string "15m"
metrics.prometheusRule.alerts.passkeyStoreSizeWarning.severity string "warning"
metrics.prometheusRule.alerts.passkeyStoreSizeWarning.thresholdBytes int 600000
metrics.prometheusRule.alerts.reconciliationStalled.enabled bool true
metrics.prometheusRule.alerts.reconciliationStalled.for string "5m"
metrics.prometheusRule.alerts.reconciliationStalled.severity string "warning"
metrics.prometheusRule.alerts.reconciliationStalled.thresholdSeconds int 7200 Seconds without a completed reconciliation pass before the alert fires. A pass skipped because a stand-down or the license check has stopped Hibernator counts as completed. The alert also fires when the release namespace has no controller series at all.
metrics.prometheusRule.alerts.scalingFailures.enabled bool true
metrics.prometheusRule.alerts.scalingFailures.for string "5m"
metrics.prometheusRule.alerts.scalingFailures.severity string "critical"
metrics.prometheusRule.enabled bool false
metrics.serviceMonitor.additionalLabels object {} Additional labels on the ServiceMonitor resources, for example release: kube-prometheus-stack so that the Prometheus Operator finds them
metrics.serviceMonitor.enabled bool false Create ServiceMonitor resources for Prometheus Operator auto-discovery
metrics.serviceMonitor.interval string "" Override the Prometheus scrape interval (defaults to Prometheus global setting)
metrics.serviceMonitor.namespace string "" Namespace for the ServiceMonitor resources. Empty means the release namespace
metrics.serviceMonitor.scrapeTimeout string "" Override the Prometheus scrape timeout (defaults to Prometheus global setting)
nameOverride string "" Override the name. Unless fullnameOverride is set, the full name is built from it, and the chart accepts only the full name hibernator: when you set this value, also set fullnameOverride: hibernator
namespace.create bool false Whether to create the namespace (false if it already exists)
namespace.name string "" Name of the namespace (defaults to Release.Namespace)
nodeSelector object {} Node selector
podAnnotations object {}
podLabels object {}
podSecurityContext.fsGroup int 1000
rbac.create bool true Whether to create RBAC resources
readinessProbe.enabled bool true
readinessProbe.failureThreshold int 3
readinessProbe.initialDelaySeconds int 10
readinessProbe.periodSeconds int 10
readinessProbe.timeoutSeconds int 3
replicaCount.app int 1 Number of app (API+Frontend) pods
resources.api.limits.memory string "128Mi"
resources.api.requests.cpu string "10m"
resources.api.requests.memory string "128Mi"
resources.controller.limits.memory string "128Mi"
resources.controller.requests.cpu string "10m"
resources.controller.requests.memory string "128Mi"
resources.frontend.limits.memory string "128Mi"
resources.frontend.requests.cpu string "10m"
resources.frontend.requests.memory string "128Mi"
secrets.existingSecret string "" A Secret in the release namespace that you manage, for example through External Secrets Operator. It holds the keys jwt-secret and internal-api-secret, and smtp-user and smtp-password when the mail server needs a sign-in. When it is set, the chart renders no Secret of its own and ignores the other secrets values
secrets.internalApiSecret string "" Secret the controller authenticates to the API with. Required without existingSecret: the install fails without it. Generate one with openssl rand -base64 32
secrets.jwtSecret string "" JWT signing secret. Required without existingSecret: the install fails without it. Generate one with openssl rand -base64 32. A new value logs every user out
secrets.smtp object {"password":"","user":""} SMTP authentication
securityContext.api.allowPrivilegeEscalation bool false
securityContext.api.capabilities.drop[0] string "ALL"
securityContext.api.runAsNonRoot bool true
securityContext.api.runAsUser int 1000
securityContext.controller.allowPrivilegeEscalation bool false
securityContext.controller.capabilities.drop[0] string "ALL"
securityContext.controller.readOnlyRootFilesystem bool true
securityContext.controller.runAsNonRoot bool true
securityContext.controller.runAsUser int 1000
securityContext.frontend.allowPrivilegeEscalation bool false
securityContext.frontend.capabilities.drop[0] string "ALL"
securityContext.frontend.runAsNonRoot bool true
securityContext.frontend.runAsUser int 65532
service.annotations object {}
service.api object {"healthPort":8081,"port":8080} API service ports
service.controller object {"healthPort":8081,"metricsPort":9090} Controller service ports
service.frontend object {"httpsPort":443,"port":80} Frontend service ports
service.type string "ClusterIP"
serviceAccount.api.annotations object {} Annotations to add to the service account
serviceAccount.api.create bool true Whether to create the service account
serviceAccount.api.name string "" Name of the service account (auto-generated if not specified)
serviceAccount.controller.annotations object {} Annotations to add to the service account
serviceAccount.controller.create bool true Whether to create the service account
serviceAccount.controller.name string "" Name of the service account (auto-generated if not specified)
startupProbe.enabled bool true
startupProbe.failureThreshold int 90
startupProbe.initialDelaySeconds int 0
startupProbe.periodSeconds int 10
startupProbe.timeoutSeconds int 5
tls.enabled bool false Mount the certificate from tls.secretName for the frontend’s HTTPS port (3443). The port also serves HTTPS without it: the internal CA of Caddy then issues a certificate for hibernator.internal. Only a caller that does not verify the certificate accepts it.
tls.secretName string "" Name of the secret containing TLS certificates
tolerations list [] Tolerations