The chart renders byte-for-byte the same resources as the base manifests with default values
(the make helm-verify no-drift gate). Every production hardening is a values-gated dial defaulting to
off/dev, so turning one on renders the extra resources and leaving it off renders nothing extra. This
page is the values reference.
The fastest path to a correct production posture is the shipped overlay:
Terminal window
helmpulloci://ghcr.io/ctxmesh/charts/ctxmesh--version0.1.0-beta.8--untar# for values-production.yaml
production makes the HA invariants hard — helm templatefails unless the control plane is actually HA (state-layer proxy, BFF, run-worker all ≥2, dispatch on, no bundled dev data plane).
security.tenantLabelWebhook.enabled
true
The tenant-label ValidatingWebhook (forbids a non-controller principal from changing a namespace’s agents.ctxmesh.ai/tenant label). Boots its own in-process cert controller (no cert-manager).
security.tenantLabelEnforcement
""
Opt-out ack. To run production without the webhook, set to the exact string "unenforced-UNSAFE-acknowledged" so a reduced posture can’t ship silently. Ignored when the webhook is enabled or under the dev profile.
namespace
ctxmesh
Install namespace; must match the base manifests for no-drift.
Every workload’s CPU and memory come from values. The defaults are what the chart has always
shipped, so helm upgrade without setting any of these changes no limit on your cluster.
Value
Default
Meaning
bff.resources
500m/1Gi limits, 10m/192Mi requests
The console’s server-side layer.
controllerManager.resources
500m/128Mi, 10m/64Mi
The operator.
gateway.resources
2/1536Mi, 50m/512Mi
LiteLLM. The largest default in the chart — it holds provider clients and streams.
tokenService.resources
500m/128Mi, 10m/64Mi
Credential plane.
statelayerProxy.resources
500m/128Mi, 10m/64Mi
The memory/quota hop. Size this alongside statelayerProxy.replicas.
Serve the console SPA + /api. false = headless control plane.
bff.replicas
1
>1 requires bff.runStore.enabled (dispatch) — else in-process runs split across pods and are lost on a pod loss; the render fails on >1 without dispatch.
bff.image.repository / .tag
bff / ""
Signed image in production.
bff.runStore.enabled
false
Durable run store + HA run-worker: the BFF dispatches runs to a separate worker. Requires a Secret (dsnSecretName, key dsn) with the run-store Postgres DSN.
bff.runStore.dsnSecretName
run-store
The run-store DSN Secret name (create it with a managed-Postgres DSN).
bff.runExecTimeout
"" (10m)
How long one run advance may take — the agent’s whole managed loop for a turn. Raise it for long tool chains; empty uses the compiled default.
bff.runExecMaxTimeout
"" (60m)
The ceiling that kills a wedged run regardless of the above.
bff.runStore.worker.concurrency
4
Concurrent claim loops per worker pod.
bff.runStore.worker.minReplicaCount
1
KEDA min and the Deployment warm floor. 0 opts into scale-to-zero; production uses 2.
BYO-MCP register/discover. false (hardened) → the endpoints 404.
bff.mcp.requireApproval
false
true (hardened) → newly registered MCP tools are pending-approval.
bff.mcp.credentialNamespace
""
Set (e.g. ctxmesh-credentials) to render a locked platform namespace holding MCP grant Secrets so tenants can’t read each other’s OAuth tokens. Production should set this.
The OTel collector sidecar image, injected into every agent pod. Tagged with the chart’s appVersion unless you pin your own tag or digest. Empty ⇒ the controller’s dev.local default, which ImagePullBackOffs on a real cluster.
controllerManager.injectedImages.discovery
ghcr.io/ctxmesh/agent-discovery
The tool-discovery sidecar image, injected into every agent that has a tool binding. Same tagging and same dev.local caveat.
controllerManager.oboEgress.enabled
false
Gates OBO credential injection only — per-user tool calls. It does not gate sidecar injection and has not since M82: the egress sidecar is injected for every agent with ≥1 tool whatever this says.
controllerManager.oboEgress.sidecarImage
ghcr.io/ctxmesh/egress-sidecar
The egress sidecar image. Required by any install that uses tools, not only OBO ones, because the sidecar is the always-on tool-call chokepoint. Unlike the two above it has no fallback: an empty value makes Knative reject the agent’s Service with missing field(s): … containers[N].image.