> Section: [7. Running it](https://jaque.sh/docs/deployment/overview.md)
> Next: deployment/docker
> Index: https://jaque.sh/llms.txt


The Helm chart is released alongside the binary, so the two
have one release cadence and the chart never describes a flag the binary
does not have. One value, `deploymentMode`, selects between two shapes:
`standalone`, one `-target all` process with a local event log, and
`split`, one workload per role sharing an external log server. Everything
else in this page is what each shape reads from `values.yaml` and what the
chart refuses to render.

Status: the chart is published on every release; the registry is private
until distribution is decided. See [project status](https://jaque.sh/docs/project/status.md).

## 1. Install

```sh
helm install jaque oci://<registry>/jaque/charts/jaque --version <chart version>
```

The chart is published as an OCI artifact on every release; its `version`
equals the image tag with the leading `v` stripped, so a chart version and
a binary version always name the same release.

## 2. `deploymentMode`

`standalone` runs one pod with every role in it (`-target all`), a local
event log, and no external dependency. It is the shape for one site and a
few hundred checks; [Topologies](https://jaque.sh/docs/deployment/topologies.md), section
2.1, is where this shape is defined and what makes it enough.

`split` runs one workload per role -- `engine` as a StatefulSet, `worker`
as a Deployment, `ui`, and optionally `sink` and `notifier` -- all pointed
at the log server in `log.url`. It is the shape for several engines,
worker zones, or isolating the `ui` from the rest; see Topologies, section
2.2 and 2.3, for what splitting buys and how engine count is the second
axis on top of it.

## 3. Standalone values

`config` is the CUE mounted as a ConfigMap at `/etc/jaque/config.cue`; it
defaults to a single self-check ICMP against `127.0.0.1`, using the same
`hosts`/`check` idiom as the [Quickstart](https://jaque.sh/docs/get-started/quickstart.md).
`apiToken` and `existingApiTokenSecret` set the bearer token for the
command API, from a chart-managed Secret or one already in the cluster;
`telegramToken` and `existingTelegramTokenSecret` follow the same pattern
for `telegram` contacts.

`standalone.persistence.enabled` mounts a PVC at `/data` and points the
event log at `file:///data/eventlog`; without it the log lives in the pod
and a restart starts the projections over from an empty log, not from
where they left off. `standalone.livestatus.enabled` opens a second
Service port (`standalone.livestatus.port`, default 6557) so Thruk, NagVis
or WOCU connect over Livestatus without changes to their own config.

## 4. Split values

`log.url` is the log server every role shares, passed as `-eventlog` and
`-coordination`; it is required in split mode and the chart refuses to
render without it. `queue.url` is the work queue passed as `-queue`; it
defaults to `log.url` when unset.

`engine.replicas` sets how many `engine` StatefulSet pods share ownership
of the object set by rendezvous hashing; two survive a single pod loss.
`engine.heartbeatTTL` sets `-heartbeat-ttl` and is left to the binary's
default when empty.

`worker.zones` sets `-zones`, the list a worker serves; a check runs only
on a worker whose zones include its object's zone. `worker.netRaw` grants
the container `NET_RAW` so ICMP checks work from that pod.

`ui.ingress.enabled`, with `ui.ingress.className`, `ui.ingress.host`,
`ui.ingress.annotations` and `ui.ingress.tls`, renders an Ingress in front
of the `ui` Service; without it the dashboard is reached the same way as
in standalone, by port-forwarding the Service.

`sink.enabled` runs the sink role, which reads the CUE `sinks:` block
mounted into every pod; `sink.select` optionally narrows it to a subset of
the declared sinks (`-sinks`), the same way `worker.zones` narrows a
worker. `notifier.enabled` runs the
notifier role on its own workload; when it is true the `engine` and any
`sink` process are rendered with `-notify-delivery external` so delivery
happens on the notifier instead.

Every role block above also takes `resources`, `podAnnotations`,
`podLabels`, `podSecurityContext`, `containerSecurityContext`,
`nodeSelector`, `tolerations`, `affinity`,
`topologySpreadConstraints`, `priorityClassName`, `extraArgs`, `extraEnv`,
`extraVolumes`, `extraVolumeMounts` and `podDisruptionBudget` -- the same
scheduling and pod-shape knobs `standalone` exposes, one set per role
instead of one set for the whole pod.

## 5. What the chart refuses

The chart fails to render, rather than deploying something half-wired, in
three cases: `deploymentMode` outside `standalone`/`split`; `sink.enabled`
or `notifier.enabled` set while `deploymentMode` is `standalone`, since
neither role exists outside split; and `engine.replicas` below 1 in split
mode. Two more cases are rejected
by the values schema rather than a chart template: `split` mode with no
`log.url` at all, and any key not already documented above -- the schema
sets `additionalProperties: false` throughout, so a typo in a values file
fails validation instead of being silently ignored.

## 6. The image

`image.tag` defaults to the chart's `appVersion`, which every release sets
to the tag the image was built from; leaving it unset is what keeps the
chart and the binary it deploys on the same release. Overriding it pins a
binary the chart was not released with, decoupling the two.

## 7. Security considerations

The chart puts the API token and the Telegram token in Kubernetes Secrets
(`apiToken`/`existingApiTokenSecret`, `telegramToken`/
`existingTelegramTokenSecret`) and hands them to the pod as environment
variables, which is where jaque reads every secret from (see
[Security](https://jaque.sh/docs/deployment/security.md), section 2). `worker.netRaw` grants
`NET_RAW` only to the `worker` role's container; no other role's
`containerSecurityContext` carries it, so ICMP capability does not spread
to roles that never run a check. `ui.ingress.tls` is the only place the
chart terminates TLS; without it, and without an authenticating proxy in
front, the dashboard, `/metrics` and any exposed Livestatus port are
unauthenticated.
