Files
teleport/examples/chart/tbot
Dan UptonandCyril Gaudin d398156437 [buddy] tbot: Support templating annotations in kubernetes/argo-cd output (#62668)
* tbot: Support templating annotations in kubernetes/argo-cd output

like it's done for labels (cf https://github.com/gravitational/teleport/pull/61804)

Our use case:
We need to set some of the Teleport cluster labels in the Kubernetes
secret's annotations (instead of secret labels) because the label's
value contains unsupported character (cf https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/#syntax-and-character-set)

For example we store some cluster URLs (e.g. Docker registry URL) but
secret's labels cannot contain a `/` in the value.

Signed-off-by: Dan Upton <daniel.upton@goteleport.com>

* Add annotation templating to Helm chart docs

---------

Signed-off-by: Dan Upton <daniel.upton@goteleport.com>
Co-authored-by: Cyril Gaudin <cyril.gaudin@camunda.com>
2026-01-08 16:00:50 +00:00
..

TBot Chart

This chart deploys an instance of the Machine ID agent, TBot, into your Kubernetes cluster.

To use it, you will need to know:

By default, this chart is designed to use the kubernetes join method but it can be customised to use any delegated join method. We do not recommend that you use the token join method with this chart.

How To

Basic configuration

This basic configuration will write a Teleport identity file to a secret in the deployment namespace called <helm-release-name>-out. For example tbot-out.

clusterName: "test.teleport.sh"
teleportProxyAddress: "test.teleport.sh:443"
token: "my-token"

Customization

When customizing the configuration of tbot using this chart, you can either choose to leverage the more granular values or use the tbotConfig value to inject custom configuration into any field. We recommend using the granular values where possible to better benefit from changes we may introduce in future updates.

Contributing to the chart

Please read CONTRIBUTING.md before raising a pull request to this chart.