# TeamClaw cloud deployment values. image: registry: ghcr.io/teamclaw tag: latest pullPolicy: IfNotPresent server: replicas: 1 autoscaling: enabled: false min: 1 max: 5 targetCPU: 70 resources: requests: { cpu: 250m, memory: 256Mi } limits: { cpu: "1", memory: 512Mi } broker: resources: requests: { cpu: 50m, memory: 64Mi } limits: { cpu: 250m, memory: 128Mi } # Master key Secret (key: broker.key); create it before install and BACK # IT UP — secrets are unrecoverable without it. keySecretName: teamclaw-broker-key frontend: replicas: 1 resources: requests: { cpu: 100m, memory: 128Mi } limits: { cpu: 500m, memory: 256Mi } database: # External/managed Postgres connection string Secret (key: url). urlSecretName: teamclaw-database llm: # anthropic | openai_compat | scripted provider: anthropic model: claude-sonnet-4-6 baseUrl: "" # Secret holding ANTHROPIC_API_KEY (key: api-key) for the anthropic provider. apiKeySecretName: teamclaw-llm storage: # local (PVC) | s3 backend: local dataDir: /var/lib/teamclaw pvcSize: 10Gi s3: endpoint: "" bucket: "" credentialsSecretName: teamclaw-s3 auth: # local | oidc | clerk (clerk: issuerUrl is the instance Frontend API, # https://.clerk.accounts.dev) mode: oidc issuerUrl: "" clientId: teamclaw # clerk mode: Secret with keys publishable-key + secret-key. clerkSecretName: teamclaw-clerk oauth: issuerUrl: "" clientId: teamclaw clientSecretName: teamclaw-oauth redirectBase: "" sandbox: # runtimeDefault | localhost (localhost installs the strict allowlist # profile onto every node via a DaemonSet and runs sandbox pods under it) seccomp: runtimeDefault ingress: enabled: true className: nginx host: teamclaw.example.com tlsSecretName: ""