global:
  existingSecret: loadouthq-runtime

# Commit this file to the customer's GitOps repository.
# Do not store credentials, registry tokens, or license files here.
config:
  appBaseUrl: https://loadouthq.example.com
  apiPublicUrl: https://loadouthq.example.com
  corsOrigin: https://loadouthq.example.com
  sessionCookieSecure: true
  # Trust the direct Ingress or Gateway proxy that terminates TLS.
  trustedProxyHops: 1
  platformAdminEmail: admin@example.com
  defaultOrgSlug: default
  defaultOrgName: Default Organization
  registrationEnabled: false
  orgCreationEnabled: false
  localAuthEnabled: true
  # Requires OPENAI_API_KEY in loadouthq-runtime. Leave empty to disable prompt checks.
  openAiValidationModel: ''
  openAiBaseUrl: https://api.openai.com/v1
  validationContextMaxBytes: 524288
  validationOpenAiTimeoutMs: 60000
  validationOpenAiMaxAttempts: 3
  validationCheckConcurrency: 3

license:
  # Leave empty for platform-admin upload. Set for operator-managed licensing.
  existingSecret: loadouthq-license
  secretKey: license.lhq-license

# External Valkey is the production default. See configuration.md before enabling the dependency.
valkey:
  enabled: false

imagePullSecrets:
  - name: loadouthq-registry

ingress:
  enabled: true
  className: nginx
  host: loadouthq.example.com
  tls:
    enabled: true
    secretName: loadouthq-tls

api:
  replicaCount: 2
  podDisruptionBudget:
    enabled: true

web:
  replicaCount: 2
  podDisruptionBudget:
    enabled: true
