Key prefix in the bucket/container (e.g. snapshots/)
""
tap.snapshots.cloud.configMaps
Names of pre-existing ConfigMaps with cloud storage env vars. Alternative to inline s3/azblob values below.
[]
tap.snapshots.cloud.secrets
Names of pre-existing Secrets with cloud storage credentials. Alternative to inline s3/azblob values below.
[]
tap.snapshots.cloud.s3.bucket
S3 bucket name. Auto-creates a ConfigMap with SNAPSHOT_AWS_BUCKET.
""
tap.snapshots.cloud.s3.region
AWS region for the S3 bucket
""
tap.snapshots.cloud.s3.accessKey
AWS access key ID. Auto-creates a Secret with SNAPSHOT_AWS_ACCESS_KEY.
""
tap.snapshots.cloud.s3.secretKey
AWS secret access key. Auto-creates a Secret with SNAPSHOT_AWS_SECRET_KEY.
""
tap.snapshots.cloud.s3.roleArn
IAM role ARN to assume via STS for cross-account S3 access
""
tap.snapshots.cloud.s3.externalId
External ID for the STS AssumeRole call
""
tap.snapshots.cloud.azblob.storageAccount
Azure storage account name. Auto-creates a ConfigMap with SNAPSHOT_AZBLOB_STORAGE_ACCOUNT.
""
tap.snapshots.cloud.azblob.container
Azure blob container name
""
tap.snapshots.cloud.azblob.storageKey
Azure storage account access key. Auto-creates a Secret with SNAPSHOT_AZBLOB_STORAGE_KEY.
""
Resources
Hub
Parameter
Description
Default
tap.resources.hub.limits.cpu
CPU limit
"" (unlimited)
tap.resources.hub.limits.memory
Memory limit
5Gi
tap.resources.hub.requests.cpu
CPU request
50m
tap.resources.hub.requests.memory
Memory request
50Mi
Sniffer (Worker)
Parameter
Description
Default
tap.resources.sniffer.limits.cpu
CPU limit
"" (unlimited)
tap.resources.sniffer.limits.memory
Memory limit
5Gi
tap.resources.sniffer.requests.cpu
CPU request
50m
tap.resources.sniffer.requests.memory
Memory request
50Mi
Tracer
Parameter
Description
Default
tap.resources.tracer.limits.cpu
CPU limit
"" (unlimited)
tap.resources.tracer.limits.memory
Memory limit
5Gi
tap.resources.tracer.requests.cpu
CPU request
50m
tap.resources.tracer.requests.memory
Memory request
50Mi
Traffic Sampling
Parameter
Description
Default
tap.packetCapture
Packet capture backend: best, af_packet, or pf_ring
best
tap.misc.trafficSampleRate
Percentage of traffic to process (0-100)
100
tap.misc.tcpStreamChannelTimeoutMs
Timeout in milliseconds for TCP stream channel
10000
Networking
Ports
Parameter
Description
Default
tap.proxy.hub.srvPort
Hub server port
8898
tap.proxy.worker.srvPort
Worker server port
48999
tap.proxy.front.port
Front-end port
8899
tap.proxy.host
Proxy host address
127.0.0.1
Network Settings
Parameter
Description
Default
tap.ipv6
Enable IPv6 support
true
tap.hostNetwork
Enable host network for workers
true
DNS
Parameter
Description
Default
tap.dns.nameservers
Custom nameservers
[]
tap.dns.searches
DNS search domains
[]
tap.dns.options
DNS options
[]
Ingress
Parameter
Description
Default
tap.ingress.enabled
Enable Ingress
false
tap.ingress.className
Ingress class name
""
tap.ingress.host
Ingress hostname
ks.svc.cluster.local
tap.ingress.tls
TLS configuration
[]
tap.ingress.annotations
Ingress annotations
{}
Routing
Parameter
Description
Default
tap.routing.front.basePath
Base path for front-end
""
Authentication
General
Parameter
Description
Default
tap.auth.enabled
Identify callers through an identity provider. When false nobody logs in, but tap.auth.defaultRole is still applied and enforced — a deployment can be read-only without configuring an identity provider.
false
tap.auth.type
Auth backend: saml, oidc (generic OIDC — Dex, Okta, Auth0, Keycloak, Azure AD, Google), dex (permanent alias of oidc), descope, default (also Descope). Rendered verbatim — no value rewrites this at runtime.
saml
The chart validates the pair: type: saml without tap.auth.saml.idpMetadataUrl, and type: oidc / dex without an issuer, fail the render rather than installing a Hub that authenticates nobody.
Roles & Authorization
The role configuration is shared by both SAML and OIDC backends — admins maintain a single set of definitions and switch backends without rewriting them. See Roles & Permissions for the full model (built-in roles, capability vocabulary, custom roles, namespace scope, license-side feature ceiling).
Parameter
Description
Default
tap.auth.rolesClaim
JWT claim name (OIDC) or SAML attribute name carrying the user’s group / role memberships.
groups
tap.auth.defaultRole
Built-in role (kubeshark-admin / kubeshark-realtime / kubeshark-snapshot / kubeshark-viewer) or custom role applied when a caller has no recognized claim value. Respected whether or not tap.auth.enabled is set: with authentication off it is the role every caller gets, so kubeshark-viewer yields a read-only deployment with no login. With authentication on, an empty string means strict-deny; with it off, an empty or unrecognized value falls back to kubeshark-admin so an installation that never configured authorization keeps working.
kubeshark-admin
tap.auth.groupMapping
Map of SSO group / attribute value → role name. Values may reference one of the four built-in roles or a custom role declared under tap.auth.roles. Built-in role names also identity-match without an entry here.
{}
tap.auth.roles
Operator-defined custom roles, keyed by role name. Each role declares capabilities (closed vocabulary — see Roles & Permissions) and namespaces (comma list with * and glob support: "" deny, "*" allow-all, "foo" literal, "foo,bar" OR, "foo-*" glob). Names starting with kubeshark- are reserved and rejected at hub startup.
{}
tap.auth.cli.enabled
Create the kubeshark-cli ServiceAccount and its token-minter Role so the CLI (and its mcp subcommand) can authenticate to a gated Hub with a short-lived ServiceAccount token. Adds <namespace>:kubeshark-cli to the Hub’s AUTH_CLI_SERVICE_ACCOUNTS allowlist. kubeshark-cli is not a built-in role name, so map it through tap.auth.groupMapping if you narrow tap.auth.defaultRole. See CLI & headless credentials.
false
tap.auth.cli.subjects
RBAC subjects (users / groups / ServiceAccounts) permitted to mint the kubeshark-cli token — i.e. who may use the CLI against a gated Hub. Bound to the token-minter Role via a RoleBinding.
[]
Breaking changes since the unified-roles rollout:
Per-role action flags (canDownloadPCAP, canUseScripting, scriptingPermissions, etc.) are replaced by a closed capabilities vocabulary. See Roles & Permissions.
Legacy tap.auth.saml.roles and tap.auth.saml.roleAttribute are no longer read; migrate to the top-level keys above.
Per-role filter (raw KFL string) is replaced by namespaces (comma list). Configs carrying filter: are ignored at unmarshal — migrate.
tap.auth.defaultFilter is removed; per-role namespaces: "" is the explicit deny-default.
Breaking change:tap.auth.type=oidc now routes to the generic OIDC middleware. Earlier releases routed oidc to Descope. If you were using oidc to mean Descope, switch to tap.auth.type=descope (or default). The dex label remains a permanent alias of oidc.
Scheduling
Node Selection
Parameter
Description
Default
tap.nodeSelectorTerms.workers
Worker node selectors
Linux only
tap.nodeSelectorTerms.hub
Hub node selectors
Linux only
tap.nodeSelectorTerms.front
Front-end node selectors
Linux only
Tolerations
Parameter
Description
Default
tap.tolerations.workers
Worker tolerations
[{"operator": "Exists", "effect": "NoExecute"}]
tap.tolerations.hub
Hub tolerations
[]
tap.tolerations.front
Front-end tolerations
[]
Other
Parameter
Description
Default
tap.priorityClass
Priority class name
""
Docker Registry
Parameter
Description
Default
tap.docker.registry
Docker registry
docker.io/kubeshark
tap.docker.tag
Image tag
latest
tap.docker.tagLocked
Lock tags (prevent upgrades)
true
tap.docker.imagePullPolicy
Pull policy
Always
tap.docker.imagePullSecrets
Pull secrets
[]
tap.docker.overrideImage
Override image names
""
tap.docker.overrideTag
Override image tags
""
Health Probes
Hub
Parameter
Description
Default
tap.probes.hub.initialDelaySeconds
Initial delay
5
tap.probes.hub.periodSeconds
Check period
5
tap.probes.hub.successThreshold
Success threshold
1
tap.probes.hub.failureThreshold
Failure threshold
3
Sniffer
Parameter
Description
Default
tap.probes.sniffer.initialDelaySeconds
Initial delay
5
tap.probes.sniffer.periodSeconds
Check period
5
tap.probes.sniffer.successThreshold
Success threshold
1
tap.probes.sniffer.failureThreshold
Failure threshold
3
Monitoring
Parameter
Description
Default
tap.metrics.port
Prometheus metrics port
49100
tap.telemetry.enabled
Usage statistics
true
tap.sentry.enabled
Sentry error logging
false
tap.sentry.environment
Sentry environment
production
Metadata
Parameter
Description
Default
tap.labels
Labels for all resources
{}
tap.annotations
Annotations for resources
{}
Scripting
Parameter
Description
Default
scripting.enabled
Enable scripting. Gates the scripting API as well as the UI: with it false the Hub answers /scripts, /scripts/exec, /jobs and the AI assistant with 409, and the dashboard hides the scripting UI. Scripting is deployment-wide rather than a per-role capability, so this is the only switch that closes it.
Scripts to activate on startup, by title (rendered into SCRIPTING_ACTIVE_SCRIPTS)
[]
scripting.watchScripts
Watch mode for scripts
true
PCAP Recording
Parameter
Description
Default
pcapdump.enabled
Enable PCAP recording
false
pcapdump.maxTime
Time window for stored traffic
2h
pcapdump.maxSize
Max PCAP storage
500MB
General
Parameter
Description
Default
license
License key (Community, Pro, or Enterprise)
""
timezone
IANA time zone
"" (local)
headless
Headless mode
false
internetConnectivity
Allow internet requests
true
supportChatEnabled
Intercom support chat
false
Kubernetes
Parameter
Description
Default
kube.configPath
Path to kubeconfig
""
kube.context
Kubernetes context
""
Logging
Parameter
Description
Default
logs.file
Log file path
""
dumpLogs
Enable log dumping
false
Debug
Parameter
Description
Default
tap.dryRun
Preview pods without tapping
false
tap.debug
Debug mode
false
tap.mountBpf
Mount BPF filesystem
true
Advanced
Parameter
Description
Default
tap.resourceGuard.enabled
Resource usage monitoring
false
tap.networkPolicies.enabled
Expose the Hub’s network-policy routes, which create and remove Kubernetes NetworkPolicy objects and compute pod-reachability impact. Off by default: the feature acts outside Kubeshark’s own data and no role grants it, so whether a deployment offers it at all is an operator decision rather than a permission. When false those routes answer 409.