-attest-agent-image | string | Attest-agent image (init container that redeems attested releases + renewer sidecar). | <release-registry>/maqpna-attest-agent:latest |
-attest-response-pubkey-file | string | PEM Ed25519 public key of maqpna-attest's -response-signing-key; injected into attest-agent containers so they reject unsigned or forged attest responses. | none |
-attest-tsm-host-path | string | If set, hostPath mounted at /sys/kernel/config/tsm into the attest-agent containers (configfs-tsm). | none |
-attest-url | string | Attestation service base URL (POST /v1/releases). | http://maqpna-attest.maqpna-system.svc:8082 |
-bootstrap-audience | string | Audience warm-pool SandboxTemplates must project their ServiceAccount token for (identity broker /v1/bootstrap). | maqpna-bootstrap |
-bootstrap-port | int | Identity broker bootstrap port (SandboxClaim-mode NetworkPolicy egress). | 8083 |
-broker-url | string | Identity broker base URL (POST /v1/token). | http://maqpna-identity.maqpna-system.svc:8081 |
-browser-image | string | Image of the browser profile sidecars (Chromium + maqpna-egress-relay). | <release-registry>/maqpna-browser:latest |
-code-interpreter-image | string | Image of the codeInterpreter profile exec sidecar (maqpna-exec). | <release-registry>/maqpna-code-interpreter:latest |
-default-session-ttl | duration | Session TTL when neither the session nor any cap sets one. | 1h0m0s |
-gateway-namespace | string | Namespace of gateway/attest pods and the policies/models ConfigMaps. | maqpna-system |
-gateway-url | string | Gateway URL injected into sandboxes. | http://maqpna-gateway.maqpna-system.svc:8080 |
-health-probe-bind-address | string | Address the health probe endpoint binds to. | :8081 |
-kube-api-burst | int | Client-side burst towards the API server. | 100 |
-kube-api-qps | float | Client-side QPS limit towards the API server. | 50 |
-kubeconfig | string | Paths to a kubeconfig. Only required if out-of-cluster. | none |
-leader-elect | switch | Enable leader election for the controller manager. | none |
-license-file | string | Installed MAQPNA licence (Secret of Helm license.secretRef, mounted optional); missing = Community. Only switches paid features on, never affects sessions. | none |
-mcpserver-shared-namespaces | string | Comma-separated namespaces whose MCPServers may set shared: true (empty = any namespace). | none |
-metrics-bind-address | string | Address the metrics endpoint binds to (0 disables). | :8080 |
-model-credentials-dir | string | Gateway mount path of Secret maqpna-model-credentials; models.json apiKeyFile paths point into it. | /var/run/maqpna-model-credentials |
-node-count-interval | duration | How often billable nodes (nodes running agent sandbox pods) are sampled into ConfigMap maqpna-usage-nodes; 0 disables. | 1m0s |
-principal-binding | string | Principal-binding admission mode installed with the chart (off|requester|trustedCreators); recorded in status.principal.verifiedBy and the maqpna_principal_verified claim. | off |
-sandbox-api-version | string | agent-sandbox API version (v1beta1 for agent-sandbox >= v1.0, v1alpha1 for <= v0.5). | v1beta1 |
-sandbox-snapshot-api | string | Upstream pod-snapshot API <group>/<version> for the SandboxSnapshot strategy (e.g. podsnapshot.gke.io/v1); empty = VolumeSnapshot only. | none |
-session-workers | int | AgentSessions reconciled in parallel (quota admission stays serialized). | 8 |
-spire-trust-domain | string | Fallback SPIFFE trust domain of sandbox SVIDs (the identity broker's --trust-domain) for sessions whose SPIFFE ID is not minted yet (attestation-gated); the minted SPIFFE ID (token subject, tenant trust domain under F-27) always wins. | none |
-spire-workload-registration | switch | Label and annotate sandbox pods (maqpna.com/spiffe, maqpna.com/spiffe-id) for a SPIRE ClusterSPIFFEID. | none |
-tenant-trust-domain-suffix | string | Default Tenant trust domain is <tenant>.<suffix>. | maqpna.local |
-token-ttl | duration | Maximum lifetime of minted session tokens (refreshed at 80%). | 15m0s |
-upstream-credential-resync | duration | How often MCPServer credential Secrets and Agent model apiKeySecretRef Secrets are re-read to pick up rotation. | 1m0s |
-usage-report-token-file | string | Projected ServiceAccount token (gateway sandboxUsage.audience) presented with usage reports. | /var/run/secrets/maqpna/usage/token |
-usage-report-url | string | Gateway endpoint for finished sessions' sandbox time (e.g. http://maqpna-gateway.maqpna-system.svc:8080/v1/usage/sandbox); empty disables reporting. | none |
-user-oidc-audience | string | Required audience (client id) of user ID tokens. | none |
-user-oidc-groups-claim | string | Claim holding the user's groups. | groups |
-user-oidc-issuer | string | OIDC issuer for AgentSession spec.userAssertionRef ID tokens (empty disables userAssertionRef). | none |
-user-oidc-jwks | string | JWKS URL of the user OIDC issuer (default: discovery). | none |
-user-oidc-username-claim | string | Claim compared with spec.user (default: email, preferred_username or sub). | none |
-warmpool-namespace | string | Default namespace for tier SandboxWarmPools. | default |
-watch-sandboxes | switch | Watch upstream Sandbox/SandboxClaim/SandboxWarmPool objects (requires agent-sandbox CRDs installed). | true |
-workspace-size | string | Default size of the codeInterpreter session workspace PVC. | 1Gi |
-zap-devel | switch | Development Mode defaults(encoder=consoleEncoder,logLevel=Debug,stackTraceLevel=Warn). Production Mode defaults(encoder=jsonEncoder,logLevel=Info,stackTraceLevel=Error) | none |
-zap-encoder | value | Zap log encoding (one of 'json' or 'console') | none |
-zap-log-level | value | Zap Level to configure the verbosity of logging. Can be one of 'debug', 'info', 'error', 'panic' or any integer value > 0 which corresponds to custom debug levels of increasing verbosity | none |
-zap-stacktrace-level | value | Zap Level at and above which stacktraces are captured (one of 'info', 'error', 'panic'). | none |
-zap-time-encoding | value | Zap time encoding (one of 'epoch', 'millis', 'nano', 'iso8601', 'rfc3339' or 'rfc3339nano'). Defaults to 'epoch'. | none |