Skip to content

Helm Values Reference ​

Chart: charts/zelkor-platform. Authoritative defaults: values.yaml. Install-time validation: values.schema.json.

New to Zelkor? Start with Local Quickstart, then use this page when you overlay GitOps values.

Helm rejects unknown keys under documented objects (additionalProperties: false). Typos fail at helm install / helm template with a schema path.

V2 intent namespaces ​

Customer-facing configuration is grouped into three layers. Templates compile these onto an internal flat tree at render; do not set removed V1 roots (aiGateway, auth, langfuse, aegra, guardrails, mcp, logging) — render fails with a migration message.

NamespaceOwnerPurpose
platform.*Platform adminTenants, JWT/SSO, telemetry (Langfuse), logging level/format, Enterprise mTLS knob
workspace.*AI engineering leadModels (AI Gateway providers), guardrail policies, MCP tool servers and extra backends
workload.*Agent developerPlatform Aegra worker settings, default route attachment, MCP inject, per-run intent (Pro approval)

platform ​

PathRole
platform.tenants.jwtIssuer, audiences, JWKS ConfigMap or remote URI, tenant claims
platform.tenants.sso.enabledPro — fails on CE chart without entitlement
platform.tenants.orgMappingsMap org ids to tenant ids on the Aegra worker
platform.telemetry.level / formatProcess log level and JSON/text
platform.telemetry.langfuseLangfuse Deployment, init keys, surfaces
platform.telemetry.aegraOtelTargetsOTEL export targets copied to platform Aegra
platform.mTLS.enabledEnterprise — fails on CE

workspace ​

PathRole
workspace.models.enabledAI Gateway route generation
workspace.models.consumerKeyShared /v1 bearer key for agents
workspace.models.defaultModelDefault model id when unset on the worker
workspace.models.providers.*Named LLM backends — see Add LLM providers
workspace.models.providers.openaiCompat[]Generic OpenAI-schema hosts (Groq, Mistral, …)
workspace.policies.nemoNeMo Guardrails intercept and model
workspace.policies.llamaGuardEnterprise
workspace.policies.presidioEnterprise
workspace.tools.enabledUnified MCP gateway and native MCP Deployments
workspace.tools.extraBackends[]BYO MCP registration — see Register extra MCP backends
workspace.tools.postgresMCP / qdrantMCP / sandboxMCP / aigatewayMCPNative MCP settings

workload ​

PathRole
workload.agents.enabledPlatform Aegra Deployment
workload.agents.imagePlatform runtime image tag/digest
workload.agents.attachDefaultRouteCatch-all HTTPRoute to platform Aegra
workload.agents.mcpInject.enabledMode B tool binding in the runtime image
workload.agents.graphs / workersEmpty in CE default — customer agents are separate releases
workload.intentTimeout, max tokens; approval Pro only

Substrate keys (root level) ​

Infrastructure the chart owns outside the three intent layers:

KeyRole
global.tieross on CE; other values require Pro/Ent umbrella
global.imagePullSecretsCopied to agent releases by zelkor deploy
gateway.*Gateway API / Envoy Gateway, gateway.hosts.* HTTP hostnames
databases.modein-cluster-basic vs operator-backed modes
postgresql, valkey, clickhouse, qdrant, seaweedfsDatastore pins and URLs
security.networkPoliciesAgent default-deny egress; gateway allow lists for extra MCP
security.sandboxgVisor runtime class for sandbox workers
highAvailability, observabilityReplicas and monitoring hooks

extraManifests ​

Top-level array of extra Kubernetes objects (maps or templated YAML strings). Rendered after generated manifests. User objects without labels receive zelkor.io/intent: extraManifests. Generated resources carry zelkor.io/intent: <values path>.

Community Edition install-time gates ​

Setting these on the CE chart alone fails render with an upgrade pointer to Install on an Existing Cluster:

Values pathTier
platform.tenants.sso.enabled: truePro
platform.mTLS.enabled: trueEnterprise
workspace.policies.llamaGuardEnterprise
workspace.policies.presidioEnterprise
global.tier ≠ ossPro/Ent umbrella
workload.intent.approval.enabledPro

V1 migration ​

Supplying a non-empty removed root (for example --set aiGateway.providers.openai.apiKey=...) fails before render. Use workspace.models.providers.openai.apiKey instead. Message links: Add LLM providers, Helm install, Register extra MCP.

Schema-only stubs ​

values.v1-intent-stubs.yaml lists removed keys for diagnosable schema errors only; it is not merged into chart defaults.