Sign inSign up

bitnamicharts/memcached

Verified Publisher

By VMware

•Updated 2 days ago

Bitnami Helm chart for Memcached

Helm
Image
Artifact
Security
Databases & storage
Monitoring & observability
0

5M+

bitnamicharts/memcached repository overview

⁠Bitnami Secure Images Helm chart for Memcached

Memcached is an high-performance, distributed memory object caching system, generic in nature, but intended for use in speeding up dynamic web applications by alleviating database load.

Overview of Memcached⁠

Trademarks: This software listing is packaged by Bitnami. The respective trademarks mentioned in the offering are owned by the respective companies, and use of them does not imply any affiliation or endorsement.

⁠ TL;DR

helm install my-release oci://REGISTRY_NAME/REPOSITORY_NAME/memcached

Note: You need to substitute the placeholders REGISTRY_NAME and REPOSITORY_NAME with a reference to your Helm chart registry and repository.

⁠ Introduction

This chart bootstraps a Memcached⁠ deployment on a Kubernetes⁠ cluster using the Helm⁠ package manager.

⁠ Before you begin

  • Kubernetes 1.23+
  • Helm 3.8.0+
  • PV provisioner support in the underlying infrastructure

⁠ Installing the chart

First, log in to the OCI registry and create a secret with your registry credentials:

helm registry login REGISTRY_NAME
kubectl create secret docker-registry SECRET_NAME -n NAMESPACE \
  --docker-server REGISTRY_NAME \
  --docker-username "USER" \
  --docker-password "TOKEN"

Note Replace the placeholders in these commands (REGISTRY_NAME, SECRET_NAME, NAMESPACE, USER, and TOKEN) with your actual values.

Then install the chart with the release name my-release:

helm install my-release oci://REGISTRY_NAME/REPOSITORY_NAME/memcached --set "global.imagePullSecrets[0]=SECRET_NAME" -n NAMESPACE

Note Replace the placeholders in the helm install command (REGISTRY_NAME, REPOSITORY_NAME, SECRET_NAME, and NAMESPACE) with your actual values.

These commands deploy Memcached on the Kubernetes cluster in the default configuration. The Parameters⁠ section lists the parameters that can be configured during installation.

Note List all releases using helm list.

⁠ Configuration and installation details

This section describes resource settings, metrics, credentials, sidecars, and other options.

⁠ Resource requests and limits

Bitnami charts allow setting resource requests and limits for all containers inside the chart deployment. These are inside the resources value (check parameter table). Setting requests is essential for production workloads and these should be adapted to your specific use case.

To make this process easier, the chart contains the resourcesPreset values, which automatically sets the resources section according to different presets. Check these presets in the bitnami/common chart⁠. However, in production workloads using resourcesPreset is discouraged as it may not fully adapt to your specific needs. Find more information on container resource management in the official Kubernetes documentation⁠.

⁠ Prometheus metrics

This chart can be integrated with Prometheus by setting metrics.enabled to true. This will deploy a sidecar container with memcached_exporter⁠ in all pods and a metrics service, which can be configured under the metrics.service section. This metrics service will have the necessary annotations to be automatically scraped by Prometheus.

⁠Prometheus requirements

It is necessary to have a working installation of Prometheus or Prometheus Operator for the integration to work. Install the Bitnami Prometheus helm chart⁠ or the Bitnami Kube Prometheus helm chart⁠ to easily have a working Prometheus in your cluster.

⁠Integration with Prometheus Operator

The chart can deploy ServiceMonitor objects for integration with Prometheus Operator installations. To do so, set the value metrics.serviceMonitor.enabled=true. Ensure that the Prometheus Operator CustomResourceDefinitions are installed in the cluster or it will fail with the following error:

no matches for kind "ServiceMonitor" in version "monitoring.coreos.com/v1"

Install the Bitnami Kube Prometheus helm chart⁠ for having the necessary CRDs and the Prometheus Operator.

⁠ Rolling vs Immutable tags⁠

It is strongly recommended to use immutable tags in a production environment. This ensures your deployment does not change automatically if the same tag is updated with a different image.

Bitnami will release a new chart updating its containers if a new version of the main container, significant changes, or critical vulnerabilities exist.

⁠ Update credentials

The Bitnami Memcached chart, when upgrading, reuses the secret previously rendered by the chart or the one specified in auth.existingPasswordSecret. To update credentials, use one of the following:

  • Run helm upgrade specifying a new password in auth.password
  • Run helm upgrade specifying a new secret in auth.existingPasswordSecret
⁠ Use sidecars and init containers

If additional containers are needed in the same pod (such as additional metrics or logging exporters), they can be defined using the sidecars config parameter.

sidecars:
- name: your-image-name
  image: your-image
  imagePullPolicy: Always
  ports:
  - name: portname
    containerPort: 1234

If these sidecars export extra ports, extra port definitions can be added using the service.extraPorts parameter (where available), as shown in the example below:

service:
  extraPorts:
  - name: extraPort
    port: 11311
    targetPort: 11311

Note This Helm chart already includes sidecar containers for the Prometheus exporters (where applicable). These can be activated by adding the --enable-metrics=true parameter at deployment time. The sidecars parameter should therefore only be used for any extra sidecar containers.

If additional init containers are needed in the same pod, they can be defined using the initContainers parameter. Here is an example:

initContainers:
  - name: your-image-name
    image: your-image
    imagePullPolicy: Always
    ports:
      - name: portname
        containerPort: 1234

Learn more about sidecar containers⁠ and init containers⁠.

⁠ Set pod affinity

This chart allows you to set your custom affinity using the affinity parameter(s). Find more information about Pod affinity in the Kubernetes documentation⁠.

As an alternative, you can use the preset configurations for pod affinity, pod anti-affinity, and node affinity available at the bitnami/common⁠ chart. To do so, set the podAffinityPreset, podAntiAffinityPreset, or nodeAffinityPreset parameters.

⁠ Backup and restore

To back up and restore Helm chart deployments on Kubernetes, you need to back up the persistent volumes from the source deployment and attach them to a new deployment using Velero⁠, a Kubernetes backup/restore tool. Find the instructions for using Velero in this guide⁠.

⁠ FIPS parameters

The FIPS parameters only have effect if you are using images from the Bitnami Secure Images catalog⁠.

For more information on this new support, please refer to the FIPS Compliance section⁠.

⁠ Persistence

When using architecture: "high-availability" the Bitnami Memcached⁠ image stores the cache-state at the /cache-state path of the container if enabled.

Persistent Volume Claims (PVCs) are used to keep the data across deployments. This is known to work in GCE, AWS, and minikube.

See the Parameters⁠ section to configure the PVC or to disable persistence.

If you encounter errors when working with persistent volumes, refer to our troubleshooting guide for persistent volumes⁠.

⁠ Parameters

The following subsections list global, common, and component-specific parameters.

⁠ Global parameters
NameDescriptionValue
global.imageRegistryGlobal Docker image registry""
global.imagePullSecretsGlobal Docker registry secret names as an array[]
global.defaultStorageClassGlobal default StorageClass for Persistent Volume(s)""
global.storageClassDEPRECATED: use global.defaultStorageClass instead""
global.defaultFipsDefault value for the FIPS configuration (allowed values: '', restricted, relaxed, off). Can be overridden by the 'fips' objectrestricted
global.security.allowInsecureImagesAllows skipping image verificationfalse
global.compatibility.openshift.adaptSecurityContextAdapt the securityContext sections of the deployment to make them compatible with Openshift restricted-v2 SCC: remove runAsUser, runAsGroup and fsGroup and let the platform use their allowed default IDs. Possible values: auto (apply if the detected running cluster is Openshift), force (perform the adaptation always), disabled (do not perform adaptation)auto
⁠ Common parameters
NameDescriptionValue
kubeVersionOverride Kubernetes version""
nameOverrideString to partially override common.names.fullname template (will maintain the release name)""
fullnameOverrideString to fully override common.names.fullname template""
clusterDomainKubernetes Cluster Domaincluster.local
extraDeployExtra objects to deploy (evaluated as a template)[]
commonLabelsAdd labels to all the deployed resources{}
commonAnnotationsAdd annotations to all the deployed resources{}
diagnosticMode.enabledEnable diagnostic mode (all probes will be disabled and the command will be overridden)false
diagnosticMode.commandCommand to override all containers in the deployment/statefulset["sleep"]
diagnosticMode.argsArgs to override all containers in the deployment/statefulset["infinity"]
⁠ Memcached parameters
NameDescriptionValue
image.registryMemcached image registryREGISTRY_NAME
image.repositoryMemcached image repositoryREPOSITORY_NAME/memcached
image.digestMemcached image digest in the way sha256:aa.... Please note this parameter, if set, will override the tag""
image.pullPolicyMemcached image pull policyIfNotPresent
image.pullSecretsSpecify docker-registry secret names as an array[]
image.debugSpecify if debug values should be setfalse
architectureMemcached architecture. Allowed values: standalone or high-availabilitystandalone
auth.enabledEnable Memcached authenticationfalse
auth.usernameMemcached admin user""
auth.passwordMemcached admin password""
auth.existingPasswordSecretExisting secret with Memcached credentials (must contain a value for memcached-password key)""
auth.usePasswordFilesMount credentials as files instead of using environment variablestrue
⁠ TLS parameters
NameDescriptionValue
tls.enabledEnable TLS/SSL encryption for Memcached connectionsfalse
tls.existingSecretName of existing TLS Secret (must contain the key tls.certFilename and tls.certKeyFilename)""
tls.mountPathDirectory inside the container where the TLS Secret is mounted/certs/tls
tls.certFilenamePublic certificate filename inside the TLS Secrettls.crt
tls.certKeyFilenamePrivate key filename inside the TLS Secrettls.key
tls.certCAFilenameCA certificate filename inside the TLS Secret (optional; enables client certificate verification)ca.crt
tls.caPEM-encoded CA certificate. Used only when tls.autoGenerated.enabled is false and tls.existingSecret is empty.""
tls.certPEM-encoded TLS certificate. Used only when tls.autoGenerated.enabled is false and tls.existingSecret is empty.""
tls.keyPEM-encoded TLS private key. Used only when tls.autoGenerated.enabled is false and tls.existingSecret is empty.""
tls.verifyModeTLS peer certificate verification mode. Valid values: 0 (None), 1 (Request), 2 (Require), 3 (Once).0
tls.autoGenerated.enabledEnable chart-managed TLS (Helm self-signed Secret or cert-manager Certificate)true
tls.autoGenerated.engineMechanism to provision the TLS Secret. Allowed values: helm (self-signed) or cert-managerhelm
tls.autoGenerated.extraSANsExtra DNS SANs to include in the generated certificate[]
tls.autoGenerated.loopbackAdd loopback (localhost) to the generated certificate SANstrue
tls.autoGenerated.certManager.existingIssuerExisting Issuer or ClusterIssuer name (only for engine=cert-manager)""
tls.autoGenerated.certManager.existingIssuerKindKind of the existing issuer. Allowed values: Issuer or ClusterIssuerClusterIssuer
tls.autoGenerated.certManager.keyAlgorithmPrivate key algorithm (only for engine=cert-manager)RSA
tls.autoGenerated.certManager.keySizePrivate key size in bits (only for engine=cert-manager)2048
tls.autoGenerated.certManager.durationCertificate validity duration (only for engine=cert-manager)2160h
tls.autoGenerated.certManager.renewBeforeCertificate renew time before expiry (only for engine=cert-manager)360h
tls.autoGenerated.certManager.commonNameCertificate common name (defaults to <fullname>.<namespace>.svc.<clusterDomain>)""
commandOverride default container command (useful when using custom images)[]
argsOverride default container args (useful when using custom images)[]
extraEnvVarsArray with extra environment variables to add to Memcached nodes[]
extraEnvVarsCMName of existing ConfigMap containing extra env vars for Memcached nodes""
extraEnvVarsSecretName of existing Secret containing extra env vars for Memcached nodes""
⁠ Deployment/Statefulset parameters
NameDescriptionValue
replicaCountNumber of Memcached nodes1
containerPorts.memcachedMemcached container port11211
livenessProbe.enabledEnable livenessProbe on

Note: the README for this chart is longer than the DockerHub length limit of 25000, so it has been trimmed. The full README can be found at https://techdocs.broadcom.com/us/en/vmware-tanzu/bitnami-secure-images/bitnami-secure-images/services/bsi-app-doc/apps-charts-memcached-index.html⁠

Tag summary

Content type

Image

Digest

sha256:9b76192ea…

Size

7.8 kB

Last updated

2 days ago

docker pull bitnamicharts/memcached:sha256-d39bd454b67badb14b09af2514a73f9839d3ab5337dbbc9d5adbb220dcecd930

This week's pulls

Pulls:

81,971

Last week

Bitnami