Skip to content
Browse Gluu Flex 5.16.0

Helm values reference

Read from each chart’s own values.yaml at 5.16.0, so every key is listed — including the ones the generated chart README leaves out.

1029 options

admin-ui (60)
KeyTypeDefaultDescription
admin-uiobject—Admin GUI for configuration of the auth-server
admin-ui.additionalAnnotationsobject{}Additional annotations that will be added across the gateway in the format of {cert-manager.io/issuer: "letsencrypt-prod"}
admin-ui.additionalLabelsobject{}Additional labels that will be added across the gateway in the format of {mylabel: "myapp"}
admin-ui.customCommandlist[]Add custom pod's command. If passed, it will override the default conditional command.
admin-ui.customScriptslist[]Add custom scripts that have been mounted to run before the entrypoint.
- /tmp/custom.sh
- /tmp/custom2.sh
admin-ui.dnsConfigobject{}Add custom dns config
admin-ui.dnsPolicystring""Add custom dns policy
admin-ui.hpaobject—Configure the HorizontalPodAutoscaler
admin-ui.hpa.behaviorobject{}Scaling Policies
admin-ui.hpa.enabledbooltrueNo description upstream
admin-ui.hpa.maxReplicasint10No description upstream
admin-ui.hpa.metricslist[]metrics if targetCPUUtilizationPercentage is not set
admin-ui.hpa.minReplicasint1No description upstream
admin-ui.hpa.targetCPUUtilizationPercentageint50No description upstream
admin-ui.imageobject—No description upstream
admin-ui.image.pullPolicystring"IfNotPresent"Image pullPolicy to use for deploying.
admin-ui.image.pullSecretslist[]Image Pull Secrets
admin-ui.image.repositorystring"ghcr.io/gluufederation/flex/admin-ui"Image to use for deploying.
admin-ui.image.tagstring"5.16.0-1"Image tag to use for deploying.
admin-ui.lifecycleobject{}No description upstream
admin-ui.livenessProbeobject—Configure the liveness healthcheck for the admin ui if needed.
admin-ui.livenessProbe.failureThresholdint20No description upstream
admin-ui.livenessProbe.initialDelaySecondsint60No description upstream
admin-ui.livenessProbe.periodSecondsint25No description upstream
admin-ui.livenessProbe.tcpSocketobject—No description upstream
admin-ui.livenessProbe.tcpSocket.portint8080No description upstream
admin-ui.livenessProbe.timeoutSecondsint5No description upstream
admin-ui.nodeSelectorobject{}Add nodeSelector (see https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#nodeselector)
admin-ui.pdbobject—Configure the PodDisruptionBudget
admin-ui.pdb.enabledbooltrueNo description upstream
admin-ui.pdb.maxUnavailablestring"90%"No description upstream
admin-ui.readinessProbeobject—Configure the readiness healthcheck for the admin ui if needed.
admin-ui.readinessProbe.failureThresholdint20No description upstream
admin-ui.readinessProbe.initialDelaySecondsint60No description upstream
admin-ui.readinessProbe.periodSecondsint25No description upstream
admin-ui.readinessProbe.tcpSocketobject—No description upstream
admin-ui.readinessProbe.tcpSocket.portint8080No description upstream
admin-ui.readinessProbe.timeoutSecondsint5No description upstream
admin-ui.replicasint1Service replica number.
admin-ui.resourcesobject—Resource specs.
admin-ui.resources.limitsobject—No description upstream
admin-ui.resources.limits.cpustring"2000m"CPU limit.
admin-ui.resources.limits.memorystring"2000Mi"Memory limit.
admin-ui.resources.requestsobject—No description upstream
admin-ui.resources.requests.cpustring"2000m"CPU request.
admin-ui.resources.requests.memorystring"2000Mi"Memory request.
admin-ui.serviceadmin-uiobject—No description upstream
admin-ui.service.nameadmin-uistring"http-admin-ui"The name of the admin ui port within the admin service. Please keep it as default.
admin-ui.service.portadmin-uiint8080Port of the admin ui service. Please keep it as default.
admin-ui.service.sessionAffinityadmin-uistring"None"Default set to None If you want to make sure that connections from a particular client are passed to the same Pod each time, you can select the session affinity based on the client's IP addresses by setting this to ClientIP
admin-ui.service.sessionAffinityConfigadmin-uiobject—the maximum session sticky time if sessionAffinity is ClientIP
admin-ui.service.sessionAffinityConfig.clientIPadmin-uiobject—No description upstream
admin-ui.service.sessionAffinityConfig.clientIP.timeoutSecondsadmin-uiint10800No description upstream
admin-ui.tolerationslist[]Add tolerations for the pods
admin-ui.topologySpreadConstraintsobject{}Configure the topology spread constraints. Notice this is a map NOT a list as in the upstream API https://kubernetes.io/docs/concepts/scheduling-eviction/topology-spread-constraints/
admin-ui.usrEnvsobject—Add custom normal and secret envs to the service
admin-ui.usrEnvs.normalobject{}Add custom normal envs to the service
variable1: value1
admin-ui.usrEnvs.secretobject{}Add custom secret envs to the service
variable1: value1
admin-ui.volumeMountslist[]Configure any additional volumesMounts that need to be attached to the containers
admin-ui.volumeslist[]Configure any additional volumes that need to be attached to the pod
auth-server (58)
KeyTypeDefaultDescription
auth-serverobject—OAuth Authorization Server, the OpenID Connect Provider, the UMA Authorization Server--this is the main Internet facing component of Gluu. It's the service that returns tokens, JWT's and identity assertions. This service must be Internet facing.
auth-server.additionalAnnotationsobject{}Additional annotations that will be added across the gateway in the format of {cert-manager.io/issuer: "letsencrypt-prod"}
auth-server.additionalLabelsobject{}Additional labels that will be added across the gateway in the format of {mylabel: "myapp"}
auth-server.customCommandlist[]Add custom pod's command. If passed, it will override the default conditional command.
auth-server.customScriptslist[]Add custom scripts that have been mounted to run before the entrypoint.
- /tmp/custom.sh
- /tmp/custom2.sh
auth-server.dnsConfigobject{}Add custom dns config
auth-server.dnsPolicystring""Add custom dns policy
auth-server.hpaobject—Configure the HorizontalPodAutoscaler
auth-server.hpa.behaviorobject{}Scaling Policies
auth-server.hpa.enabledbooltrueNo description upstream
auth-server.hpa.maxReplicasint10No description upstream
auth-server.hpa.metricslist[]metrics if targetCPUUtilizationPercentage is not set
auth-server.hpa.minReplicasint1No description upstream
auth-server.hpa.targetCPUUtilizationPercentageint50No description upstream
auth-server.imageobject—No description upstream
auth-server.image.pullPolicystring"IfNotPresent"Image pullPolicy to use for deploying.
auth-server.image.pullSecretslist[]Image Pull Secrets
auth-server.image.repositorystring"ghcr.io/janssenproject/jans/auth-server"Image to use for deploying.
auth-server.image.tagstring"1.16.0-1"Image tag to use for deploying.
auth-server.lifecycleobject{}No description upstream
auth-server.livenessProbeobject—Configure the liveness healthcheck for the auth server if needed.
auth-server.livenessProbe.execobject—Executes the python3 healthcheck. https://github.com/JanssenProject/docker-jans-auth-server/blob/master/scripts/healthcheck.py
auth-server.livenessProbe.exec.commandlist[]No description upstream
auth-server.livenessProbe.initialDelaySecondsint30No description upstream
auth-server.livenessProbe.periodSecondsint30No description upstream
auth-server.livenessProbe.timeoutSecondsint5No description upstream
auth-server.nodeSelectorobject{}Add nodeSelector (see https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#nodeselector)
auth-server.pdbobject—Configure the PodDisruptionBudget
auth-server.pdb.enabledbooltrueNo description upstream
auth-server.pdb.maxUnavailablestring"90%"No description upstream
auth-server.readinessProbeobject—Configure the readiness healthcheck for the auth server if needed. https://github.com/JanssenProject/docker-jans-auth-server/blob/master/scripts/healthcheck.py
auth-server.readinessProbe.execobject—No description upstream
auth-server.readinessProbe.exec.commandlist[]No description upstream
auth-server.readinessProbe.initialDelaySecondsint25No description upstream
auth-server.readinessProbe.periodSecondsint25No description upstream
auth-server.readinessProbe.timeoutSecondsint5No description upstream
auth-server.replicasint1Service replica number.
auth-server.resourcesobject—Resource specs.
auth-server.resources.limitsobject—No description upstream
auth-server.resources.limits.cpustring"2500m"CPU limit.
auth-server.resources.limits.memorystring"2500Mi"Memory limit. This value is used to calculate memory allocation for Java. Currently it only supports `Mi`. Please refrain from using other units.
auth-server.resources.requestsobject—No description upstream
auth-server.resources.requests.cpustring"2500m"CPU request.
auth-server.resources.requests.memorystring"2500Mi"Memory request.
auth-server.serviceauth-serverobject—No description upstream
auth-server.service.nameauth-serverstring"http-auth"The name of the oxauth port within the oxauth service. Please keep it as default.
auth-server.service.portauth-serverint8080Port of the oxauth service. Please keep it as default.
auth-server.service.sessionAffinityauth-serverstring"None"Default set to None If you want to make sure that connections from a particular client are passed to the same Pod each time, you can select the session affinity based on the client's IP addresses by setting this to ClientIP
auth-server.service.sessionAffinityConfigauth-serverobject—the maximum session sticky time if sessionAffinity is ClientIP
auth-server.service.sessionAffinityConfig.clientIPauth-serverobject—No description upstream
auth-server.service.sessionAffinityConfig.clientIP.timeoutSecondsauth-serverint10800No description upstream
auth-server.tolerationslist[]Add tolerations for the pods
auth-server.topologySpreadConstraintsobject{}Configure the topology spread constraints. Notice this is a map NOT a list as in the upstream API https://kubernetes.io/docs/concepts/scheduling-eviction/topology-spread-constraints/
auth-server.usrEnvsobject—Add custom normal and secret envs to the service
auth-server.usrEnvs.normalobject{}Add custom normal envs to the service
variable1: value1
auth-server.usrEnvs.secretobject{}Add custom secret envs to the service
variable1: value1
auth-server.volumeMountslist[]Configure any additional volumesMounts that need to be attached to the containers
auth-server.volumeslist[]Configure any additional volumes that need to be attached to the pod
auth-server-key-rotation (33)
KeyTypeDefaultDescription
auth-server-key-rotationobject—Responsible for regenerating auth-keys per x hours
auth-server-key-rotation.additionalAnnotationsobject{}Additional annotations that will be added across the gateway in the format of {cert-manager.io/issuer: "letsencrypt-prod"}
auth-server-key-rotation.additionalLabelsobject{}Additional labels that will be added across the gateway in the format of {mylabel: "myapp"}
auth-server-key-rotation.affinityauth-server-key-rotationobject{}No description upstream
auth-server-key-rotation.cronJobSchedulestring""Auth server key rotation job schedule. It accepts any Cron syntax supported by Kubernetes. If empty, the schedule will run based on keysLife value.
auth-server-key-rotation.customCommandlist[]Add custom job's command. If passed, it will override the default conditional command.
auth-server-key-rotation.customScriptslist[]Add custom scripts that have been mounted to run before the entrypoint.
- /tmp/custom.sh
- /tmp/custom2.sh
auth-server-key-rotation.dnsConfigobject{}Add custom dns config
auth-server-key-rotation.dnsPolicystring""Add custom dns policy
auth-server-key-rotation.imageobject—No description upstream
auth-server-key-rotation.image.pullPolicystring"IfNotPresent"Image pullPolicy to use for deploying.
auth-server-key-rotation.image.pullSecretslist[]Image Pull Secrets
auth-server-key-rotation.image.repositorystring"ghcr.io/janssenproject/jans/cloudtools"Image to use for deploying.
auth-server-key-rotation.image.tagstring"1.16.0-1"Image tag to use for deploying.
auth-server-key-rotation.keysLifeint48Auth server key rotation keys life in hours
auth-server-key-rotation.keysPushDelayint0Delay (in seconds) before pushing private keys to Auth server
auth-server-key-rotation.keysPushStrategystring"NEWER"Set key selection strategy after pushing private keys to Auth server (only takes effect when keysPushDelay value is greater than 0)
auth-server-key-rotation.keysStrategystring"NEWER"Set key selection strategy used by Auth server
auth-server-key-rotation.lifecycleobject{}No description upstream
auth-server-key-rotation.nodeSelectorobject{}Add nodeSelector (see https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#nodeselector)
auth-server-key-rotation.resourcesobject—Resource specs.
auth-server-key-rotation.resources.limitsobject—No description upstream
auth-server-key-rotation.resources.limits.cpustring"300m"CPU limit.
auth-server-key-rotation.resources.limits.memorystring"300Mi"Memory limit.
auth-server-key-rotation.resources.requestsobject—No description upstream
auth-server-key-rotation.resources.requests.cpustring"300m"CPU request.
auth-server-key-rotation.resources.requests.memorystring"300Mi"Memory request.
auth-server-key-rotation.tolerationslist[]Add tolerations for the pods
auth-server-key-rotation.usrEnvsobject—Add custom normal and secret envs to the service
auth-server-key-rotation.usrEnvs.normalobject{}Add custom normal envs to the service
variable1: value1
auth-server-key-rotation.usrEnvs.secretobject{}Add custom secret envs to the service
variable1: value1
auth-server-key-rotation.volumeMountslist[]Configure any additional volumesMounts that need to be attached to the containers
auth-server-key-rotation.volumeslist[]Configure any additional volumes that need to be attached to the pod
casa (64)
KeyTypeDefaultDescription
casaobject—Janssen Casa ("Casa") is a self-service web portal for end-users to manage authentication and authorization preferences for their account in a Janssen Auth Server.
casa.additionalAnnotationsobject{}Additional annotations that will be added across the gateway in the format of {cert-manager.io/issuer: "letsencrypt-prod"}
casa.additionalLabelsobject{}Additional labels that will be added across the gateway in the format of {mylabel: "myapp"}
casa.customCommandlist[]Add custom pod's command. If passed, it will override the default conditional command.
casa.customScriptslist[]Add custom scripts that have been mounted to run before the entrypoint.
- /tmp/custom.sh
- /tmp/custom2.sh
casa.dnsConfigobject{}Add custom dns config
casa.dnsPolicystring""Add custom dns policy
casa.fullnameOverridecasastring""No description upstream
casa.hpaobject—Configure the HorizontalPodAutoscaler
casa.hpa.behaviorobject{}Scaling Policies
casa.hpa.enabledbooltrueNo description upstream
casa.hpa.maxReplicasint10No description upstream
casa.hpa.metricslist[]metrics if targetCPUUtilizationPercentage is not set
casa.hpa.minReplicasint1No description upstream
casa.hpa.targetCPUUtilizationPercentageint50No description upstream
casa.imageobject—No description upstream
casa.image.pullPolicystring"IfNotPresent"Image pullPolicy to use for deploying.
casa.image.pullSecretslist[]Image Pull Secrets
casa.image.repositorystring"ghcr.io/janssenproject/jans/casa"Image to use for deploying.
casa.image.tagstring"1.16.0-1"Image tag to use for deploying.
casa.lifecycleobject{}No description upstream
casa.livenessProbeobject—Configure the liveness healthcheck for casa if needed.
casa.livenessProbe.httpGetobject—No description upstream
casa.livenessProbe.httpGet.pathstring"/jans-casa/health-check"http liveness probe endpoint
casa.livenessProbe.httpGet.portstring"http-casa"No description upstream
casa.livenessProbe.initialDelaySecondsint25No description upstream
casa.livenessProbe.periodSecondsint25No description upstream
casa.livenessProbe.timeoutSecondsint5No description upstream
casa.nameOverridecasastring""No description upstream
casa.nodeSelectorobject{}Add nodeSelector (see https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#nodeselector)
casa.pdbobject—Configure the PodDisruptionBudget
casa.pdb.enabledbooltrueNo description upstream
casa.pdb.maxUnavailablestring"90%"No description upstream
casa.podSecurityContextcasaobject{}No description upstream
casa.readinessProbeobject—Configure the readiness healthcheck for the casa if needed.
casa.readinessProbe.httpGetobject—No description upstream
casa.readinessProbe.httpGet.pathstring"/jans-casa/health-check"http readiness probe endpoint
casa.readinessProbe.httpGet.portstring"http-casa"No description upstream
casa.readinessProbe.initialDelaySecondsint30No description upstream
casa.readinessProbe.periodSecondsint30No description upstream
casa.readinessProbe.timeoutSecondsint5No description upstream
casa.replicasint1Service replica number.
casa.resourcesobject—Resource specs.
casa.resources.limitsobject—No description upstream
casa.resources.limits.cpustring"500m"CPU limit.
casa.resources.limits.memorystring"500Mi"Memory limit. This value is used to calculate memory allocation for Java. Currently it only supports `Mi`. Please refrain from using other units.
casa.resources.requestsobject—No description upstream
casa.resources.requests.cpustring"500m"CPU request.
casa.resources.requests.memorystring"500Mi"Memory request.
casa.securityContextcasaobject{}No description upstream
casa.servicecasaobject—No description upstream
casa.service.namecasastring"http-casa"The name of the casa port within the casa service. Please keep it as default.
casa.service.portcasaint8080Port of the casa service. Please keep it as default.
casa.service.sessionAffinitycasastring"None"Default set to None If you want to make sure that connections from a particular client are passed to the same Pod each time, you can select the session affinity based on the client's IP addresses by setting this to ClientIP
casa.service.sessionAffinityConfigcasaobject—the maximum session sticky time if sessionAffinity is ClientIP
casa.service.sessionAffinityConfig.clientIPcasaobject—No description upstream
casa.service.sessionAffinityConfig.clientIP.timeoutSecondscasaint10800No description upstream
casa.tolerationslist[]Add tolerations for the pods
casa.topologySpreadConstraintsobject{}Configure the topology spread constraints. Notice this is a map NOT a list as in the upstream API https://kubernetes.io/docs/concepts/scheduling-eviction/topology-spread-constraints/
casa.usrEnvsobject—Add custom normal and secret envs to the service
casa.usrEnvs.normalobject{}Add custom normal envs to the service
variable1: value1
casa.usrEnvs.secretobject{}Add custom secret envs to the service
variable1: value1
casa.volumeMountslist[]Configure any additional volumesMounts that need to be attached to the containers
casa.volumeslist[]Configure any additional volumes that need to be attached to the pod
cleanup (29)
KeyTypeDefaultDescription
cleanupobject—Cleanup expired entries in persistence
cleanup.additionalAnnotationsobject{}Additional annotations that will be added across the gateway in the format of {cert-manager.io/issuer: "letsencrypt-prod"}
cleanup.additionalLabelsobject{}Additional labels that will be added across the gateway in the format of {mylabel: "myapp"}
cleanup.customCommandlist[]Add custom job's command. If passed, it will override the default conditional command.
cleanup.customScriptslist[]Add custom scripts that have been mounted to run before the entrypoint.
- /tmp/custom.sh
- /tmp/custom2.sh
cleanup.dnsConfigobject{}Add custom dns config
cleanup.dnsPolicystring""Add custom dns policy
cleanup.imageobject—No description upstream
cleanup.image.pullPolicystring"IfNotPresent"Image pullPolicy to use for deploying.
cleanup.image.pullSecretslist[]Image Pull Secrets
cleanup.image.repositorystring"ghcr.io/janssenproject/jans/cloudtools"Image to use for deploying.
cleanup.image.tagstring"1.16.0-1"Image tag to use for deploying.
cleanup.intervalint60Interval of running the cleanup process (in minutes)
cleanup.lifecycleobject{}No description upstream
cleanup.limitint1000Max. numbers of entries to cleanup
cleanup.nodeSelectorobject{}Add nodeSelector (see https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#nodeselector)
cleanup.resourcesobject—Resource specs.
cleanup.resources.limitsobject—No description upstream
cleanup.resources.limits.cpustring"300m"CPU limit.
cleanup.resources.limits.memorystring"300Mi"Memory limit.
cleanup.resources.requestsobject—No description upstream
cleanup.resources.requests.cpustring"300m"CPU request.
cleanup.resources.requests.memorystring"300Mi"Memory request.
cleanup.tolerationslist[]Add tolerations for the pods
cleanup.usrEnvsobject—Add custom normal and secret envs to the service
cleanup.usrEnvs.normalobject{}Add custom normal envs to the service
variable1: value1
cleanup.usrEnvs.secretobject{}Add custom secret envs to the service
variable1: value1
cleanup.volumeMountslist[]Configure any additional volumesMounts that need to be attached to the containers
cleanup.volumeslist[]Configure any additional volumes that need to be attached to the pod
config (102)
KeyTypeDefaultDescription
configobject—Configuration parameters for setup and initial configuration secret and config layers used by Gluu services.
config.additionalAnnotationsobject{}Additional annotations that will be added across the gateway in the format of {cert-manager.io/issuer: "letsencrypt-prod"}
config.additionalLabelsobject{}Additional labels that will be added across the gateway in the format of {mylabel: "myapp"}
config.adminPasswordstring"Test1234#"Admin password to log in to the UI.
config.citystring"Austin"City. Used for certificate creation.
config.configmapobject—No description upstream
config.configmap.cnAwsAccessKeyIdstring""No description upstream
config.configmap.cnAwsDefaultRegionstring"us-west-1"No description upstream
config.configmap.cnAwsProfilestring"gluu"No description upstream
config.configmap.cnAwsSecretAccessKeystring""No description upstream
config.configmap.cnAwsSecretsEndpointUrlstring""No description upstream
config.configmap.cnAwsSecretsNamePrefixstring"gluu"No description upstream
config.configmap.cnAwsSecretsReplicaRegionslist[]No description upstream
config.configmap.cnCacheTypestring"NATIVE_PERSISTENCE"Cache type. `NATIVE_PERSISTENCE`, `REDIS`. or `IN_MEMORY`. Defaults to `NATIVE_PERSISTENCE` .
config.configmap.cnConfigKubernetesConfigMapstring"cn"The name of the Kubernetes ConfigMap that will hold the configuration layer
config.configmap.cnGoogleProjectIdstring"google-project-to-save-config-and-secrets-to"Project id of the Google project the secret manager belongs to. Used only when global.configAdapterName and global.configSecretAdapter is set to google.
config.configmap.cnGoogleSecretManagerServiceAccountstring"SWFtTm90YVNlcnZpY2VBY2NvdW50Q2hhbmdlTWV0b09uZQo="Service account with roles roles/secretmanager.admin base64 encoded string. This is used often inside the services to reach the configuration layer. Used only when global.configAdapterName and global.configSecretAdapter is set to google.
config.configmap.cnGoogleSecretNamePrefixstring"gluu"Prefix for Gluu secret in Google Secret Manager. Defaults to gluu. If left gluu-secret secret will be created. Used only when global.configAdapterName and global.configSecretAdapter is set to google.
config.configmap.cnGoogleSecretVersionIdstring"latest"Secret version to be used for secret configuration. Defaults to latest and should normally always stay that way. Used only when global.configAdapterName and global.configSecretAdapter is set to google.
config.configmap.cnJettyRequestHeaderSizeint8192Jetty header size in bytes in the auth server
config.configmap.cnMaxRamPercentstring"75.0"Value passed to Java option -XX:MaxRAMPercentage
config.configmap.cnMessageTypestring"DISABLED"Message type (one of POSTGRES, REDIS, or DISABLED)
config.configmap.cnPersistenceHybridMappingstring"{}"Specify data that should be saved in persistence (one of default, user, cache, site, token, or session; default to default). Note this environment only takes effect when `global.cnPersistenceType` is set to `hybrid`.
{
"default": "<sql>",
"user": "<sql>",
"site": "<sql>",
"cache": "<sql>",
"token": "<sql>",
"session": "<sql>",
}
config.configmap.cnRedisSentinelGroupstring""Redis Sentinel Group. Often set when `config.configmap.cnRedisType` is set to `SENTINEL`. Can be used when `config.configmap.cnCacheType` is set to `REDIS`.
config.configmap.cnRedisSslTruststorestring""Redis SSL truststore. Optional. Can be used when `config.configmap.cnCacheType` is set to `REDIS`.
config.configmap.cnRedisTypestring"STANDALONE"Redis service type. `STANDALONE` or `CLUSTER`. Can be used when `config.configmap.cnCacheType` is set to `REDIS`.
config.configmap.cnRedisUrlstring"redis.redis.svc.cluster.local:6379"Redis URL and port number <url>:<port>. Can be used when `config.configmap.cnCacheType` is set to `REDIS`.
config.configmap.cnRedisUseSslboolfalseBoolean to use SSL in Redis. Can be used when `config.configmap.cnCacheType` is set to `REDIS`.
config.configmap.cnScimProtectionModestring"OAUTH"SCIM protection mode OAUTH|TEST|UMA
config.configmap.cnSecretKubernetesSecretstring"cn"Kubernetes secret name holding configuration keys. Used when global.configSecretAdapter is set to kubernetes which is the default.
config.configmap.cnSqlDbDialectstring"mysql"SQL database dialect. `mysql` or `pgsql`
config.configmap.cnSqlDbHoststring"my-release-mysql.default.svc.cluster.local"SQL database host uri.
config.configmap.cnSqlDbNamestring"gluu"SQL database name.
config.configmap.cnSqlDbPortint3306SQL database port.
config.configmap.cnSqlDbSchemastring""Schema name used by SQL database (default to empty-string; if using MySQL, the schema name will be resolved as the database name, whereas in PostgreSQL the schema name will be resolved as `"public"`).
config.configmap.cnSqlDbTimezonestring"UTC"SQL database timezone.
config.configmap.cnSqlDbUserstring"gluu"SQL database username.
config.configmap.cnSqldbUserPasswordstring"Test1234#"SQL password injected the secrets .
config.configmap.cnSqlSslCaCertstring""Base64-encoded string of CA certificate used to sign client/server certificate of MySQL/PostgreSQL server. Required if using client cert authentication.
config.configmap.cnSqlSslClientCertstring""Base64-encoded string of client certificate signed by CA. Required if using client cert authentication.
config.configmap.cnSqlSslClientKeystring""Base64-encoded client private key corresponding to the client certificate. Required if using client cert authentication. We advise to not commit real private keys in values.yaml.
config.configmap.cnSqlSslEnabledboolfalseEnable SSL connection to SQL database.
config.configmap.cnSqlSslModestring""Mode used to connect to SQL database using SSL if cnSqlSslEnabled is set to true. If using MySQL, choose one of `PREFERRED`, `REQUIRED`, `VERIFY_CA`, or `VERIFY_IDENTITY`. If using PostgreSQL, choose one of `allow`, `prefer`, `require`, `verify-ca`, or `verify-full`.
config.configmap.cnVaultAddrstring"http://localhost:8200"Base URL of Vault.
config.configmap.cnVaultAppRolePathstring"approle"Path to Vault AppRole.
config.configmap.cnVaultKvPathstring"secret"Path to Vault KV secrets engine.
config.configmap.cnVaultNamespacestring""Vault namespace used to access the secrets.
config.configmap.cnVaultPrefixstring"jans"Base prefix name used to access secrets.
config.configmap.cnVaultRoleIdstring""Vault AppRole RoleID.
config.configmap.cnVaultRoleIdFilestring"/etc/certs/vault_role_id"Path to file contains Vault AppRole role ID.
config.configmap.cnVaultSecretIdstring""Vault AppRole SecretID.
config.configmap.cnVaultSecretIdFilestring"/etc/certs/vault_secret_id"Path to file contains Vault AppRole secret ID.
config.configmap.cnVaultVerifyboolfalseVerify connection to Vault.
config.configmap.containerMetadataNameconfigstring"kubernetes"No description upstream
config.configmap.kcAdminPasswordstring"Test1234#"Keycloak admin UI password
config.configmap.kcAdminUsernamestring"admin"Keycloak admin UI username
config.configmap.kcDbPasswordstring"Test1234#"Password for Keycloak database access
config.configmap.kcDbSchemastring"keycloak"Keycloak database schema name (note that PostgreSQL may be using "public" schema).
config.configmap.kcDbUrlDatabasestring"keycloak"Keycloak database name.
config.configmap.kcDbUrlHoststring"mysql.kc.svc.cluster.local"Keycloak database host uri
config.configmap.kcDbUrlPortint3306Keycloak database port (default to port 3306 for mysql).
config.configmap.kcDbUrlPropertiesstring"?useUnicode=true&characterEncoding=UTF-8&character_set_server=utf8mb4"Keycloak database connection properties. If using postgresql, the value can be set to empty string.
config.configmap.kcDbUsernamestring"keycloak"Keycloak database username
config.configmap.kcDbVendorstring"mysql"Keycloak database vendor name (default to MySQL server). To use PostgreSQL server, change the value to postgres.
config.configmap.kcLogLevelstring"INFO"Keycloak logging level
config.configmap.lbAddrstring""Load balancer address for AWS if the FQDN is not registered.
config.configmap.quarkusTransactionEnableRecoverybooltrueQuarkus transaction recovery. When using MySQL, there could be issue regarding XA_RECOVER_ADMIN; refer to https://dev.mysql.com/doc/refman/8.0/en/privileges-provided.html#priv_xa-recover-admin for details.
config.countryCodestring"US"Country code. Used for certificate creation.
config.customCommandlist[]Add custom job's command. If passed, it will override the default conditional command.
config.customScriptslist[]Add custom scripts that have been mounted to run before the entrypoint.
- /tmp/custom.sh
- /tmp/custom2.sh
config.dnsConfigobject{}Add custom dns config
config.dnsPolicystring""Add custom dns policy
config.emailstring"team@gluu.org"Email address of the administrator usually. Used for certificate creation.
config.fullNameOverrideconfigstring""No description upstream
config.imageobject—No description upstream
config.image.pullSecretslist[]Image Pull Secrets
config.image.repositorystring"ghcr.io/janssenproject/jans/configurator"Image to use for deploying.
config.image.tagstring"1.16.0-1"Image tag to use for deploying.
config.lifecycleobject{}No description upstream
config.migrationobject—CE to CN Migration section
config.migration.enabledboolfalseBoolean flag to enable migration from CE
config.migration.migrationDataFormatstring"ldif"migration data-format depending on persistence backend. Supported data formats are ldif, postgresql+json, and mysql+json.
config.migration.migrationDirstring"/ce-migration"Directory holding all migration files
config.nameOverrideconfigstring""No description upstream
config.nodeSelectorobject{}Add nodeSelector (see https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#nodeselector)
config.orgNamestring"Gluu"Organization name. Used for certificate creation.
config.redisPasswordstring"P@assw0rd"Redis admin password if `config.configmap.cnCacheType` is set to `REDIS`.
config.resourcesobject—Resource specs.
config.resources.limitsobject—No description upstream
config.resources.limits.cpustring"300m"CPU limit.
config.resources.limits.memorystring"300Mi"Memory limit.
config.resources.requestsobject—No description upstream
config.resources.requests.cpustring"300m"CPU request.
config.resources.requests.memorystring"300Mi"Memory request.
config.saltstring""Salt. Used for encoding/decoding sensitive data. If omitted or set to empty string, the value will be self-generated. Otherwise, a 24 alphanumeric characters are allowed as its value.
config.statestring"TX"State code. Used for certificate creation.
config.tolerationslist[]Add tolerations for the pods
config.usrEnvsobject—Add custom normal and secret envs to the service.
config.usrEnvs.normalobject{}Add custom normal envs to the service.
variable1: value1
config.usrEnvs.secretobject{}Add custom secret envs to the service.
variable1: value1
config.volumeMountslist[]Configure any additional volumesMounts that need to be attached to the containers
config.volumeslist[]Configure any additional volumes that need to be attached to the pod
config-api (62)
KeyTypeDefaultDescription
config-apiobject—Config Api endpoints can be used to configure the auth-server, which is an open-source OpenID Connect Provider (OP) and UMA Authorization Server (AS).
config-api.additionalAnnotationsobject{}Additional annotations that will be added across the gateway in the format of {cert-manager.io/issuer: "letsencrypt-prod"}
config-api.additionalLabelsobject{}Additional labels that will be added across the gateway in the format of {mylabel: "myapp"}
config-api.affinityconfig-apiobject{}No description upstream
config-api.customCommandlist[]Add custom pod's command. If passed, it will override the default conditional command.
config-api.customScriptslist[]Add custom scripts that have been mounted to run before the entrypoint.
- /tmp/custom.sh
- /tmp/custom2.sh
config-api.dnsConfigobject{}Add custom dns config
config-api.dnsPolicystring""Add custom dns policy
config-api.fullnameOverrideconfig-apistring""No description upstream
config-api.hpaobject—Configure the HorizontalPodAutoscaler
config-api.hpa.behaviorobject{}Scaling Policies
config-api.hpa.enabledbooltrueNo description upstream
config-api.hpa.maxReplicasint10No description upstream
config-api.hpa.metricslist[]metrics if targetCPUUtilizationPercentage is not set
config-api.hpa.minReplicasint1No description upstream
config-api.hpa.targetCPUUtilizationPercentageint50No description upstream
config-api.imageobject—No description upstream
config-api.image.pullPolicystring"IfNotPresent"Image pullPolicy to use for deploying.
config-api.image.pullSecretslist[]Image Pull Secrets
config-api.image.repositorystring"ghcr.io/janssenproject/jans/config-api"Image to use for deploying.
config-api.image.tagstring"1.16.0-1"Image tag to use for deploying.
config-api.lifecycleobject{}No description upstream
config-api.livenessProbeobject—Configure the liveness healthcheck for the auth server if needed.
config-api.livenessProbe.httpGetobject—http liveness probe endpoint
config-api.livenessProbe.httpGet.pathstring"/jans-config-api/api/v1/health/live"No description upstream
config-api.livenessProbe.httpGet.portint8074No description upstream
config-api.livenessProbe.initialDelaySecondsint30No description upstream
config-api.livenessProbe.periodSecondsint30No description upstream
config-api.livenessProbe.timeoutSecondsint5No description upstream
config-api.nameOverrideconfig-apistring""No description upstream
config-api.nodeSelectorobject{}Add nodeSelector (see https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#nodeselector)
config-api.pdbobject—Configure the PodDisruptionBudget
config-api.pdb.enabledbooltrueNo description upstream
config-api.pdb.maxUnavailablestring"90%"No description upstream
config-api.readinessProbeobject—No description upstream
config-api.readinessProbe.httpGetobject—http readiness probe endpoint
config-api.readinessProbe.httpGet.pathstring"jans-config-api/api/v1/health/ready"No description upstream
config-api.readinessProbe.httpGet.portint8074No description upstream
config-api.readinessProbe.initialDelaySecondsint25No description upstream
config-api.readinessProbe.periodSecondsint25No description upstream
config-api.readinessProbe.timeoutSecondsint5No description upstream
config-api.replicasint1Service replica number.
config-api.resourcesobject—Resource specs.
config-api.resources.limitsobject—No description upstream
config-api.resources.limits.cpustring"1000m"CPU limit.
config-api.resources.limits.memorystring"1200Mi"Memory limit. This value is used to calculate memory allocation for Java. Currently it only supports `Mi`. Please refrain from using other units.
config-api.resources.requestsobject—No description upstream
config-api.resources.requests.cpustring"1000m"CPU request.
config-api.resources.requests.memorystring"1200Mi"Memory request.
config-api.serviceconfig-apiobject—No description upstream
config-api.service.nameconfig-apistring"http-config-api"The name of the config-api port within the config-api service. Please keep it as default.
config-api.service.sessionAffinityconfig-apistring"None"Default set to None If you want to make sure that connections from a particular client are passed to the same Pod each time, you can select the session affinity based on the client's IP addresses by setting this to ClientIP
config-api.service.sessionAffinityConfigconfig-apiobject—the maximum session sticky time if sessionAffinity is ClientIP
config-api.service.sessionAffinityConfig.clientIPconfig-apiobject—No description upstream
config-api.service.sessionAffinityConfig.clientIP.timeoutSecondsconfig-apiint10800No description upstream
config-api.tolerationslist[]Add tolerations for the pods
config-api.topologySpreadConstraintsobject{}Configure the topology spread constraints. Notice this is a map NOT a list as in the upstream API https://kubernetes.io/docs/concepts/scheduling-eviction/topology-spread-constraints/
config-api.usrEnvsobject—Add custom normal and secret envs to the service
config-api.usrEnvs.normalobject{}Add custom normal envs to the service
variable1: value1
config-api.usrEnvs.secretobject{}Add custom secret envs to the service
variable1: value1
config-api.volumeMountslist[]Configure any additional volumesMounts that need to be attached to the containers
config-api.volumeslist[]Configure any additional volumes that need to be attached to the pod
fido2 (60)
KeyTypeDefaultDescription
fido2object—FIDO 2.0 (FIDO2) is an open authentication standard that enables leveraging common devices to authenticate to online services in both mobile and desktop environments.
fido2.additionalAnnotationsobject{}Additional annotations that will be added across the gateway in the format of {cert-manager.io/issuer: "letsencrypt-prod"}
fido2.additionalLabelsobject{}Additional labels that will be added across the gateway in the format of {mylabel: "myapp"}
fido2.customCommandlist[]Add custom pod's command. If passed, it will override the default conditional command.
fido2.customScriptslist[]Add custom scripts that have been mounted to run before the entrypoint.
- /tmp/custom.sh
- /tmp/custom2.sh
fido2.dnsConfigobject{}Add custom dns config
fido2.dnsPolicystring""Add custom dns policy
fido2.hpaobject—Configure the HorizontalPodAutoscaler
fido2.hpa.behaviorobject{}Scaling Policies
fido2.hpa.enabledbooltrueNo description upstream
fido2.hpa.maxReplicasint10No description upstream
fido2.hpa.metricslist[]metrics if targetCPUUtilizationPercentage is not set
fido2.hpa.minReplicasint1No description upstream
fido2.hpa.targetCPUUtilizationPercentageint50No description upstream
fido2.imageobject—No description upstream
fido2.image.pullPolicystring"IfNotPresent"Image pullPolicy to use for deploying.
fido2.image.pullSecretslist[]Image Pull Secrets
fido2.image.repositorystring"ghcr.io/janssenproject/jans/fido2"Image to use for deploying.
fido2.image.tagstring"1.16.0-1"Image tag to use for deploying.
fido2.lifecycleobject{}No description upstream
fido2.livenessProbeobject—Configure the liveness healthcheck for the fido2 if needed.
fido2.livenessProbe.httpGetobject—http liveness probe endpoint
fido2.livenessProbe.httpGet.pathstring"/jans-fido2/sys/health-check"No description upstream
fido2.livenessProbe.httpGet.portstring"http-fido2"No description upstream
fido2.livenessProbe.initialDelaySecondsint25No description upstream
fido2.livenessProbe.periodSecondsint25No description upstream
fido2.livenessProbe.timeoutSecondsint5No description upstream
fido2.nodeSelectorobject{}Add nodeSelector (see https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#nodeselector)
fido2.pdbobject—Configure the PodDisruptionBudget
fido2.pdb.enabledbooltrueNo description upstream
fido2.pdb.maxUnavailablestring"90%"No description upstream
fido2.readinessProbeobject—Configure the readiness healthcheck for the fido2 if needed.
fido2.readinessProbe.httpGetobject—No description upstream
fido2.readinessProbe.httpGet.pathstring"/jans-fido2/sys/health-check"No description upstream
fido2.readinessProbe.httpGet.portstring"http-fido2"No description upstream
fido2.readinessProbe.initialDelaySecondsint30No description upstream
fido2.readinessProbe.periodSecondsint30No description upstream
fido2.readinessProbe.timeoutSecondsint5No description upstream
fido2.replicasint1Service replica number.
fido2.resourcesobject—Resource specs.
fido2.resources.limitsobject—No description upstream
fido2.resources.limits.cpustring"500m"CPU limit.
fido2.resources.limits.memorystring"500Mi"Memory limit. This value is used to calculate memory allocation for Java. Currently it only supports `Mi`. Please refrain from using other units.
fido2.resources.requestsobject—No description upstream
fido2.resources.requests.cpustring"500m"CPU request.
fido2.resources.requests.memorystring"500Mi"Memory request.
fido2.serviceobject—No description upstream
fido2.service.namestring"http-fido2"The name of the fido2 port within the fido2 service. Please keep it as default.
fido2.service.portint8080Port of the fido2 service. Please keep it as default.
fido2.service.sessionAffinityfido2string"None"Default set to None If you want to make sure that connections from a particular client are passed to the same Pod each time, you can select the session affinity based on the client's IP addresses by setting this to ClientIP
fido2.service.sessionAffinityConfigfido2object—the maximum session sticky time if sessionAffinity is ClientIP
fido2.service.sessionAffinityConfig.clientIPfido2object—No description upstream
fido2.service.sessionAffinityConfig.clientIP.timeoutSecondsfido2int10800No description upstream
fido2.tolerationslist[]Add tolerations for the pods
fido2.topologySpreadConstraintsobject{}Configure the topology spread constraints. Notice this is a map NOT a list as in the upstream API https://kubernetes.io/docs/concepts/scheduling-eviction/topology-spread-constraints/
fido2.usrEnvsobject—Add custom normal and secret envs to the service
fido2.usrEnvs.normalobject{}Add custom normal envs to the service
variable1: value1
fido2.usrEnvs.secretobject{}Add custom secret envs to the service
variable1: value1
fido2.volumeMountslist[]Configure any additional volumesMounts that need to be attached to the containers
fido2.volumeslist[]Configure any additional volumes that need to be attached to the pod
gatewayApi (10)
KeyTypeDefaultDescription
gatewayApiobject—No description upstream
gatewayApi.gatewayAnnotationsobject{}Specific annotations for the Gateway resource
gatewayApi.gatewayClassNamestring"nginx"Set the gatewayClassName corresponding to your installed controller. We support all GA-conformant implementations(e.g., 'nginx', 'istio', 'cilium', 'traefik'). See https://gateway-api.sigs.k8s.io/implementations/#conformant
gatewayApi.gatewayLabelsobject{}Specific labels for the Gateway resource
gatewayApi.httpPortint80Gateway http port number
gatewayApi.httpsPortint443Gateway https port number
gatewayApi.namestring"gluu-gateway"The name of the Gateway resource to be created
gatewayApi.routeAnnotationsobject{}Specific annotations for the HTTPRoute resource
gatewayApi.routeLabelsobject{}Specific labels for the HTTPRoute resource
gatewayApi.tlsSecretNamestring"tls-certificate"Secret containing the TLS certificate for the Gateway
global (315)
KeyTypeDefaultDescription
globalobject—Parameters used globally across all services helm charts.
global.admin-uiobject—No description upstream
global.admin-ui.adminUiServiceNamestring"admin-ui"Name of the admin-ui service. Please keep it as default.
global.admin-ui.customAnnotationsobject—Add custom annotations for kubernetes resources for the service
global.admin-ui.customAnnotations.deploymentobject{}No description upstream
global.admin-ui.customAnnotations.destinationRuleobject{}No description upstream
global.admin-ui.customAnnotations.horizontalPodAutoscalerobject{}No description upstream
global.admin-ui.customAnnotations.podobject{}No description upstream
global.admin-ui.customAnnotations.podDisruptionBudgetobject{}No description upstream
global.admin-ui.customAnnotations.secretobject{}No description upstream
global.admin-ui.customAnnotations.serviceobject{}No description upstream
global.admin-ui.customAnnotations.virtualServiceobject{}No description upstream
global.admin-ui.enabledbooltrueBoolean flag to enable/disable the admin-ui chart and admin ui config api plugin.
global.admin-ui.ingressobject—No description upstream
global.admin-ui.ingress.adminUiAdditionalAnnotationsobject{}Admin UI ingress resource additional annotations.
global.admin-ui.ingress.adminUiEnabledbooltrueEnable Admin UI endpoints in either istio or nginx ingress depending on users choice
global.admin-ui.ingress.adminUiLabelsobject{}Admin UI ingress resource labels. key app is taken.
global.albobject—No description upstream
global.alb.ingressboolfalseActivates ALB ingress
global.auth-serverobject—No description upstream
global.auth-server-key-rotationobject—No description upstream
global.auth-server-key-rotation.customAnnotationsobject—Add custom annotations for kubernetes resources for the service
global.auth-server-key-rotation.customAnnotations.cronjobobject{}No description upstream
global.auth-server-key-rotation.customAnnotations.secretobject{}No description upstream
global.auth-server-key-rotation.customAnnotations.serviceobject{}No description upstream
global.auth-server-key-rotation.enabledbooltrueBoolean flag to enable/disable the auth-server-key rotation cronjob chart.
global.auth-server-key-rotation.initKeysLifeint48The initial auth server key rotation keys life in hours
global.auth-server.appLoggersobject—App loggers can be configured to define where the logs will be redirected to and the level of each in which it should be displayed.
global.auth-server.appLoggers.auditStatsLogLevelstring"INFO"jans-auth_audit.log level
global.auth-server.appLoggers.auditStatsLogTargetstring"FILE"jans-auth_script.log target
global.auth-server.appLoggers.authLogLevelstring"INFO"jans-auth.log level
global.auth-server.appLoggers.authLogTargetstring"STDOUT"jans-auth.log target
global.auth-server.appLoggers.enableStdoutLogPrefixstring"true"Enable log prefixing which enables prepending the STDOUT logs with the file name. i.e auth-server-script ===> 2022-12-20 17:49:55,744 INFO
global.auth-server.appLoggers.httpLogLevelstring"INFO"http_request_response.log level
global.auth-server.appLoggers.httpLogTargetstring"FILE"http_request_response.log target
global.auth-server.appLoggers.persistenceDurationLogLevelstring"INFO"jans-auth_persistence_duration.log level
global.auth-server.appLoggers.persistenceDurationLogTargetstring"FILE"jans-auth_persistence_duration.log target
global.auth-server.appLoggers.persistenceLogLevelstring"INFO"jans-auth_persistence.log level
global.auth-server.appLoggers.persistenceLogTargetstring"FILE"jans-auth_persistence.log target
global.auth-server.appLoggers.scriptLogLevelstring"INFO"jans-auth_script.log level
global.auth-server.appLoggers.scriptLogTargetstring"FILE"jans-auth_script.log target
global.auth-server.authEncKeysstring"RSA1_5 RSA-OAEP"space-separated key algorithm for encryption (default to `RSA1_5 RSA-OAEP`)
global.auth-server.authServerServiceNamestring"auth-server"Name of the auth-server service. Please keep it as default.
global.auth-server.authSigKeysstring"RS256 RS384 RS512 ES256 ES384 ES512 PS256 PS384 PS512"space-separated key algorithm for signing (default to `RS256 RS384 RS512 ES256 ES384 ES512 PS256 PS384 PS512`)
global.auth-server.cnCustomJavaOptionsstring""passing custom java options to auth-server. Notice you do not need to pass in any loggers options as they are introduced below in appLoggers. DO NOT PASS JAVA_OPTIONS in envs.
global.auth-server.customAnnotationsobject—Add custom annotations for kubernetes resources for the service
global.auth-server.customAnnotations.deploymentobject{}No description upstream
global.auth-server.customAnnotations.destinationRuleobject{}No description upstream
global.auth-server.customAnnotations.horizontalPodAutoscalerobject{}No description upstream
global.auth-server.customAnnotations.podobject{}No description upstream
global.auth-server.customAnnotations.podDisruptionBudgetobject{}No description upstream
global.auth-server.customAnnotations.secretobject{}No description upstream
global.auth-server.customAnnotations.serviceobject{}No description upstream
global.auth-server.customAnnotations.virtualServiceobject{}No description upstream
global.auth-server.enabledbooltrueBoolean flag to enable/disable auth-server chart. You should never set this to false.
global.auth-server.ingressobject—Enable endpoints in either istio or nginx ingress depending on users choice
global.auth-server.ingress.authServerAdditionalAnnotationsobject{}Auth server ingress resource additional annotations.
global.auth-server.ingress.authServerEnabledbooltrueEnable Auth server endpoints /jans-auth
global.auth-server.ingress.authServerLabelsobject{}Auth server ingress resource labels. key app is taken
global.auth-server.ingress.authServerProtectedRegisterboolfalseEnable mTLS on Auth server endpoint /jans-auth/restv1/register.
global.auth-server.ingress.authServerProtectedRegisterAdditionalAnnotationsobject{}Auth server protected register ingress resource additional annotations.
global.auth-server.ingress.authServerProtectedRegisterLabelsobject{}Auth server protected token ingress resource labels. key app is taken
global.auth-server.ingress.authServerProtectedTokenboolfalseEnable mTLS on Auth server endpoint /jans-auth/restv1/token.
global.auth-server.ingress.authServerProtectedTokenAdditionalAnnotationsobject{}Auth server protected token ingress resource additional annotations.
global.auth-server.ingress.authServerProtectedTokenLabelsobject{}Auth server protected token ingress resource labels. key app is taken
global.auth-server.ingress.authzenAdditionalAnnotationsobject{}authzen config ingress resource additional annotations.
global.auth-server.ingress.authzenConfigEnabledbooltrueEnable endpoint /.well-known/authzen-configuration
global.auth-server.ingress.authzenConfigLabelsobject{}authzen config ingress resource labels. key app is taken
global.auth-server.ingress.deviceCodeAdditionalAnnotationsobject{}device-code ingress resource additional annotations.
global.auth-server.ingress.deviceCodeEnabledbooltrueEnable endpoint /device-code
global.auth-server.ingress.deviceCodeLabelsobject{}device-code ingress resource labels. key app is taken
global.auth-server.ingress.firebaseMessagingAdditionalAnnotationsobject{}Firebase Messaging ingress resource additional annotations.
global.auth-server.ingress.firebaseMessagingEnabledbooltrueEnable endpoint /firebase-messaging-sw.js
global.auth-server.ingress.firebaseMessagingLabelsobject{}Firebase Messaging ingress resource labels. key app is taken
global.auth-server.ingress.lockAdditionalAnnotationsobject{}Lock ingress resource additional annotations.
global.auth-server.ingress.lockConfigAdditionalAnnotationsobject{}Lock config ingress resource additional annotations.
global.auth-server.ingress.lockConfigEnabledboolfalseEnable endpoint /.well-known/lock-server-configuration
global.auth-server.ingress.lockConfigLabelsobject{}Lock config ingress resource labels. key app is taken
global.auth-server.ingress.lockEnabledboolfalseEnable endpoint /jans-lock
global.auth-server.ingress.lockLabelsobject{}Lock ingress resource labels. key app is taken
global.auth-server.ingress.openidAdditionalAnnotationsobject{}openid-configuration ingress resource additional annotations.
global.auth-server.ingress.openidConfigEnabledbooltrueEnable endpoint /.well-known/openid-configuration
global.auth-server.ingress.openidConfigLabelsobject{}openid-configuration ingress resource labels. key app is taken
global.auth-server.ingress.u2fAdditionalAnnotationsobject{}u2f config ingress resource additional annotations.
global.auth-server.ingress.u2fConfigEnabledbooltrueEnable endpoint /.well-known/fido-configuration
global.auth-server.ingress.u2fConfigLabelsobject{}u2f config ingress resource labels. key app is taken
global.auth-server.ingress.uma2AdditionalAnnotationsobject{}uma2 config ingress resource additional annotations.
global.auth-server.ingress.uma2ConfigEnabledbooltrueEnable endpoint /.well-known/uma2-configuration
global.auth-server.ingress.uma2ConfigLabelsobject{}uma2 config ingress resource labels. key app is taken
global.auth-server.ingress.webdiscoveryAdditionalAnnotationsobject{}webdiscovery ingress resource additional annotations.
global.auth-server.ingress.webdiscoveryEnabledbooltrueEnable endpoint /.well-known/simple-web-discovery
global.auth-server.ingress.webdiscoveryLabelsobject{}webdiscovery ingress resource labels. key app is taken
global.auth-server.ingress.webfingerAdditionalAnnotationsobject{}webfinger ingress resource additional annotations.
global.auth-server.ingress.webfingerEnabledbooltrueEnable endpoint /.well-known/webfinger
global.auth-server.ingress.webfingerLabelsobject{}webfinger ingress resource labels. key app is taken
global.auth-server.lockEnabledboolfalseEnable jans-lock as service running inside auth-server
global.awsStorageTypestring"io1"Volume storage type if using AWS volumes.
global.azureStorageAccountTypestring"Standard_LRS"Volume storage type if using Azure disks.
global.azureStorageKindstring"Managed"Azure storage kind if using Azure disks
global.casaobject—No description upstream
global.casa.adminEnabledbooltrueBoolean flag to enable/disable the casa admin console.
global.casa.appLoggersobject—App loggers can be configured to define where the logs will be redirected to and the level of each in which it should be displayed.
global.casa.appLoggers.casaLogLevelstring"INFO"casa.log level
global.casa.appLoggers.casaLogTargetstring"STDOUT"casa.log target
global.casa.appLoggers.enableStdoutLogPrefixstring"true"Enable log prefixing which enables prepending the STDOUT logs with the file name. i.e casa ===> 2022-12-20 17:49:55,744 INFO
global.casa.appLoggers.timerLogLevelstring"INFO"casa timer log level
global.casa.appLoggers.timerLogTargetstring"FILE"casa timer log target
global.casa.casaServiceNamestring"casa"Name of the casa service. Please keep it as default.
global.casa.cnCustomJavaOptionsstring""passing custom java options to casa. Notice you do not need to pass in any loggers options as they are introduced below in appLoggers. DO NOT PASS JAVA_OPTIONS in envs.
global.casa.customAnnotationsobject—Add custom annotations for kubernetes resources for the service
global.casa.customAnnotations.deploymentobject{}No description upstream
global.casa.customAnnotations.destinationRuleobject{}No description upstream
global.casa.customAnnotations.horizontalPodAutoscalerobject{}No description upstream
global.casa.customAnnotations.podobject{}No description upstream
global.casa.customAnnotations.podDisruptionBudgetobject{}No description upstream
global.casa.customAnnotations.secretobject{}No description upstream
global.casa.customAnnotations.serviceobject{}No description upstream
global.casa.customAnnotations.virtualServiceobject{}No description upstream
global.casa.enabledbooltrueBoolean flag to enable/disable the casa chart.
global.casa.ingressobject—Enable endpoints in either istio or nginx ingress depending on users choice
global.casa.ingress.casaAdditionalAnnotationsobject{}Casa ingress resource additional annotations.
global.casa.ingress.casaEnabledboolfalseEnable casa endpoints /jans-casa
global.casa.ingress.casaLabelsobject{}Casa ingress resource labels. key app is taken
global.cleanupobject—Enable cleanup job
global.cleanup.enabledbooltrueBoolean flag to enable/disable the cleanup cronjob chart.
global.cloudobject—No description upstream
global.cloud.testEnviromentboolfalseBoolean flag if enabled will strip resources requests and limits from all services.
global.cnAwsConfigFilestring"/etc/jans/conf/aws_config_file"No description upstream
global.cnAwsSecretsReplicaRegionsFilestring"/etc/jans/conf/aws_secrets_replica_regions"No description upstream
global.cnAwsSharedCredentialsFilestring"/etc/jans/conf/aws_shared_credential_file"No description upstream
global.cnConfiguratorConfigurationFilestring"/etc/jans/conf/configuration.json"Path to configuration schema file
global.cnConfiguratorCustomSchemaobject—Use custom configuration schema in existing secrets. Note, the secrets has to contain the key configuration.json or any basename as specified in cnConfiguratorConfigurationFile.
global.cnConfiguratorCustomSchema.secretNamestring""The name of the secrets used for storing custom configuration schema.
global.cnConfiguratorDumpFilestring"/etc/jans/conf/configuration.out.json"Path to dumped configuration schema file
global.cnConfiguratorKeystring""Key to encrypt/decrypt configuration schema file using AES-256 CBC mode. Set the value to empty string to disable encryption/decryption, or 32 alphanumeric characters to enable it.
global.cnConfiguratorKeyFilestring"/etc/jans/conf/configuration.key"Path to the file that contains the key to encrypt/decrypt the configuration schema file.
global.cnDocumentStoreTypestring"DB"Document store type to use for shibboleth files DB.
global.cnGoogleApplicationCredentialsstring"/etc/jans/conf/google-credentials.json"Base64 encoded service account. The sa must have roles/secretmanager.admin to use Google secrets. Leave as this is a sensible default.
global.cnObExtSigningAliasstring""Open banking external signing AS Alias. This is a kid value.Used in SSA Validation, kid used while encoding a JWT sent to token URL i.e. XkwIzWy44xWSlcWnMiEc8iq9s2G
global.cnObExtSigningJwksCrtstring""Open banking external signing jwks AS certificate authority string. Used in SSA Validation. This must be encoded using base64.. Used when `.global.cnObExtSigningJwksUri` is set.
global.cnObExtSigningJwksKeystring""Open banking external signing jwks AS key string. Used in SSA Validation. This must be encoded using base64. Used when `.global.cnObExtSigningJwksUri` is set.
global.cnObExtSigningJwksKeyPassPhrasestring""Open banking external signing jwks AS key passphrase to unlock provided key. This must be encoded using base64. Used when `.global.cnObExtSigningJwksUri` is set.
global.cnObExtSigningJwksUristring""Open banking external signing jwks uri. Used in SSA Validation.
global.cnObStaticSigningKeyKidstring""Open banking signing AS kid to force the AS to use a specific signing key. i.e. Wy44xWSlcWnMiEc8iq9s2G
global.cnObTransportAliasstring""Open banking transport Alias used inside the JVM.
global.cnObTransportCrtstring""Open banking AS transport crt. Used in SSA Validation. This must be encoded using base64.
global.cnObTransportKeystring""Open banking AS transport key. Used in SSA Validation. This must be encoded using base64.
global.cnObTransportKeyPassPhrasestring""Open banking AS transport key passphrase to unlock AS transport key. This must be encoded using base64.
global.cnObTransportTrustStorestring""Open banking AS transport truststore crt. This is normally generated from the OB issuing CA, OB Root CA and Signing CA. Used when .global.cnObExtSigningJwksUri is set. Used in SSA Validation. This must be encoded using base64.
global.cnPersistenceTypestring"sql"Persistence backend to run Gluu with hybrid|sql.
global.cnPrometheusPortstring""Port used by Prometheus JMX agent (default to empty string). To enable Prometheus JMX agent, set the value to a number.
global.cnSqlPasswordFilestring"/etc/jans/conf/sql_password"Path to SQL password file
global.configobject—No description upstream
global.config-apiobject—No description upstream
global.config-api.adminUiAppLoggersobject—No description upstream
global.config-api.adminUiAppLoggers.adminUiAuditLogLevelstring"INFO"config-api admin-ui plugin audit log level
global.config-api.adminUiAppLoggers.adminUiAuditLogTargetstring"FILE"config-api admin-ui plugin audit log target
global.config-api.adminUiAppLoggers.adminUiLogLevelstring"INFO"config-api admin-ui plugin log target
global.config-api.adminUiAppLoggers.adminUiLogTargetstring"FILE"config-api admin-ui plugin log level
global.config-api.adminUiAppLoggers.enableStdoutLogPrefixstring"true"Enable log prefixing which enables prepending the STDOUT logs with the file name. i.e config-api_persistence ===> 2022-12-20 17:49:55,744 INFO
global.config-api.appLoggersobject—App loggers can be configured to define where the logs will be redirected to and the level of each in which it should be displayed.
global.config-api.appLoggers.configApiLogLevelstring"INFO"configapi.log level
global.config-api.appLoggers.configApiLogTargetstring"STDOUT"configapi.log target
global.config-api.appLoggers.enableStdoutLogPrefixstring"true"Enable log prefixing which enables prepending the STDOUT logs with the file name. i.e config-api_persistence ===> 2022-12-20 17:49:55,744 INFO
global.config-api.appLoggers.persistenceDurationLogLevelstring"INFO"config-api_persistence_duration.log level
global.config-api.appLoggers.persistenceDurationLogTargetstring"FILE"config-api_persistence_duration.log target
global.config-api.appLoggers.persistenceLogLevelstring"INFO"config-api_persistence.log level
global.config-api.appLoggers.persistenceLogTargetstring"FILE"config-api_persistence.log target
global.config-api.appLoggers.scriptLogLevelstring"INFO"config-api_script.log level
global.config-api.appLoggers.scriptLogTargetstring"FILE"config-api_script.log target
global.config-api.cnCustomJavaOptionsstring""passing custom java options to config-api. Notice you do not need to pass in any loggers options as they are introduced below in appLoggers. DO NOT PASS JAVA_OPTIONS in envs.
global.config-api.configApiServerServiceNamestring"config-api"Name of the config-api service. Please keep it as default.
global.config-api.customAnnotationsobject—Add custom annotations for kubernetes resources for the service
global.config-api.customAnnotations.deploymentobject{}No description upstream
global.config-api.customAnnotations.destinationRuleobject{}No description upstream
global.config-api.customAnnotations.horizontalPodAutoscalerobject{}No description upstream
global.config-api.customAnnotations.podobject{}No description upstream
global.config-api.customAnnotations.podDisruptionBudgetobject{}No description upstream
global.config-api.customAnnotations.serviceobject{}No description upstream
global.config-api.customAnnotations.virtualServiceobject{}No description upstream
global.config-api.enabledbooltrueBoolean flag to enable/disable the config-api chart.
global.config-api.ingressobject—Enable endpoints in either istio or nginx ingress depending on users choice
global.config-api.ingress.configApiAdditionalAnnotationsobject{}ConfigAPI ingress resource additional annotations.
global.config-api.ingress.configApiEnabledbooltrueNo description upstream
global.config-api.ingress.configApiLabelsobject{}configAPI ingress resource labels. key app is taken
global.config-api.pluginsstring"admin-ui,fido2,scim,user-mgt"Comma-separated values of enabled plugins (supported plugins are "admin-ui","fido2","scim","user-mgt", "kc-saml")
global.config.customAnnotationsobject—Add custom annotations for kubernetes resources for the service
global.config.customAnnotations.clusterRoleBindingobject{}No description upstream
global.config.customAnnotations.configMapobject{}No description upstream
global.config.customAnnotations.jobobject{}No description upstream
global.config.customAnnotations.roleobject{}No description upstream
global.config.customAnnotations.roleBindingobject{}No description upstream
global.config.customAnnotations.secretobject{}No description upstream
global.config.customAnnotations.serviceobject{}No description upstream
global.config.customAnnotations.serviceAccountobject{}No description upstream
global.config.enabledbooltrueBoolean flag to enable/disable the configuration chart. This normally should never be false
global.configAdapterNamestring"kubernetes"The config backend adapter that will hold Gluu configuration layer. aws|google|kubernetes
global.configSecretAdapterstring"kubernetes"The config backend adapter that will hold Gluu secret layer. vault|aws|google|kubernetes
global.distributionstring"default"Gluu distributions supported are: default|openbanking.
global.fido2object—No description upstream
global.fido2.appLoggersobject—App loggers can be configured to define where the logs will be redirected to and the level of each in which it should be displayed.
global.fido2.appLoggers.enableStdoutLogPrefixstring"true"Enable log prefixing which enables prepending the STDOUT logs with the file name. i.e fido2 ===> 2022-12-20 17:49:55,744 INFO
global.fido2.appLoggers.fido2LogLevelstring"INFO"fido2.log level
global.fido2.appLoggers.fido2LogTargetstring"STDOUT"fido2.log target
global.fido2.appLoggers.persistenceDurationLogLevelstring"INFO"fido2_persistence_duration.log level
global.fido2.appLoggers.persistenceDurationLogTargetstring"FILE"fido2_persistence_duration.log target
global.fido2.appLoggers.persistenceLogLevelstring"INFO"fido2_persistence.log level
global.fido2.appLoggers.persistenceLogTargetstring"FILE"fido2_persistence.log target
global.fido2.appLoggers.scriptLogLevelstring"INFO"fido2_script.log level
global.fido2.appLoggers.scriptLogTargetstring"FILE"fido2_script.log target
global.fido2.cnCustomJavaOptionsstring""passing custom java options to fido2. Notice you do not need to pass in any loggers options as they are introduced below in appLoggers. DO NOT PASS JAVA_OPTIONS in envs.
global.fido2.customAnnotationsobject—Add custom annotations for kubernetes resources for the service
global.fido2.customAnnotations.deploymentobject{}No description upstream
global.fido2.customAnnotations.destinationRuleobject{}No description upstream
global.fido2.customAnnotations.horizontalPodAutoscalerobject{}No description upstream
global.fido2.customAnnotations.podobject{}No description upstream
global.fido2.customAnnotations.podDisruptionBudgetobject{}No description upstream
global.fido2.customAnnotations.secretobject{}No description upstream
global.fido2.customAnnotations.serviceobject{}No description upstream
global.fido2.customAnnotations.virtualServiceobject{}No description upstream
global.fido2.enabledbooltrueBoolean flag to enable/disable the fido2 chart.
global.fido2.fido2ServiceNamestring"fido2"Name of the fido2 service. Please keep it as default.
global.fido2.ingressobject—Enable endpoints in either istio or nginx ingress depending on users choice
global.fido2.ingress.fido2AdditionalAnnotationsobject{}fido2 ingress resource additional annotations.
global.fido2.ingress.fido2ConfigAdditionalAnnotationsobject{}fido2 config ingress resource additional annotations.
global.fido2.ingress.fido2ConfigEnabledboolfalseEnable endpoint /.well-known/fido2-configuration
global.fido2.ingress.fido2ConfigLabelsobject{}fido2 config ingress resource labels. key app is taken
global.fido2.ingress.fido2EnabledboolfalseEnable endpoint /jans-fido2
global.fido2.ingress.fido2Labelsobject{}fido2 ingress resource labels. key app is taken
global.fido2.ingress.fido2WebauthnAdditionalAnnotationsobject{}fido2 webauthn ingress resource additional annotations.
global.fido2.ingress.fido2WebauthnEnabledboolfalseEnable endpoint /.well-known/webauthn
global.fido2.ingress.fido2WebauthnLabelsobject{}fido2 webauthn ingress resource labels. key app is taken
global.fqdnstring"demoexample.gluu.org"Fully qualified domain name to be used for Gluu installation. This address will be used to reach Gluu services.
global.gatewayApiobject—No description upstream
global.gatewayApi.enabledboolfalseBoolean flag to enable/disable the Kubernetes Gateway and HTTPRoute resources.
global.gcePdStorageTypestring"pd-standard"GCE storage kind if using Google disks
global.isFqdnRegisteredboolfalseBoolean flag to enable mapping global.lbIp to global.fqdn inside pods on clouds that provide static ip for load balancers. On cloud that provide only addresses to the LB this flag will enable a script to actively scan config.configmap.lbAddr and update the hosts file inside the pods automatically.
global.istioobject—No description upstream
global.istio.additionalAnnotationsobject{}Additional annotations that will be added across the gateway in the format of {cert-manager.io/issuer: "letsencrypt-prod"}
global.istio.additionalLabelsobject{}Additional labels that will be added across the gateway in the format of {mylabel: "myapp"}
global.istio.enabledboolfalseBoolean flag that enables using istio side-cars with Gluu services.
global.istio.gatewayslist[]Override the gateway that can be created by default. This is used when istio ingress has already been setup and the gateway exists.
global.istio.ingressboolfalseBoolean flag that enables using istio gateway for Gluu. This assumes istio ingress is installed and hence the LB is available.
global.istio.namespacestring"istio-system"The namespace istio is deployed in. The is normally istio-system.
global.jobTtlSecondsAfterFinishedint300https://kubernetes.io/docs/concepts/workloads/controllers/ttlafterfinished/
global.kc-schedulerobject—No description upstream
global.kc-scheduler.enabledboolfalseBoolean flag to enable/disable the kc-scheduler cronjob chart.
global.lbIpstring"22.22.22.22"The Loadbalancer IP created by nginx or istio on clouds that provide static IPs. This is not needed if `global.fqdn` is globally resolvable.
global.nginx-ingressobject—No description upstream
global.nginx-ingress.enabledbooltrueBoolean flag to enable/disable the nginx-ingress definitions chart.
global.persistenceobject—No description upstream
global.persistence.customAnnotationsobject—Add custom annotations for kubernetes resources for the service
global.persistence.customAnnotations.jobobject{}No description upstream
global.persistence.customAnnotations.secretobject{}No description upstream
global.persistence.customAnnotations.serviceobject{}No description upstream
global.persistence.enabledbooltrueBoolean flag to enable/disable the persistence chart.
global.samlobject—No description upstream
global.saml.cnCustomJavaOptionsstring""passing custom java options to saml. DO NOT PASS JAVA_OPTIONS in envs.
global.saml.customAnnotationsobject—Add custom annotations for kubernetes resources for the service
global.saml.customAnnotations.deploymentobject{}No description upstream
global.saml.customAnnotations.destinationRuleobject{}No description upstream
global.saml.customAnnotations.horizontalPodAutoscalerobject{}No description upstream
global.saml.customAnnotations.podobject{}No description upstream
global.saml.customAnnotations.podDisruptionBudgetobject{}No description upstream
global.saml.customAnnotations.secretobject{}No description upstream
global.saml.customAnnotations.serviceobject{}No description upstream
global.saml.customAnnotations.virtualServiceobject{}No description upstream
global.saml.enabledboolfalseBoolean flag to enable/disable the saml chart.
global.saml.ingressobject—Enable endpoints in either istio or nginx ingress depending on users choice
global.saml.ingress.samlAdditionalAnnotationsobject{}SAML ingress resource additional annotations.
global.saml.ingress.samlEnabledboolfalseNo description upstream
global.saml.ingress.samlLabelsobject{}SAML ingress resource labels. key app is taken
global.saml.samlServiceNamestring"saml"Name of the saml service. Please keep it as default.
global.scimobject—No description upstream
global.scim.appLoggersobject—App loggers can be configured to define where the logs will be redirected to and the level of each in which it should be displayed.
global.scim.appLoggers.enableStdoutLogPrefixstring"true"Enable log prefixing which enables prepending the STDOUT logs with the file name. i.e jans-scim ===> 2022-12-20 17:49:55,744 INFO
global.scim.appLoggers.persistenceDurationLogLevelstring"INFO"jans-scim_persistence_duration.log level
global.scim.appLoggers.persistenceDurationLogTargetstring"FILE"jans-scim_persistence_duration.log target
global.scim.appLoggers.persistenceLogLevelstring"INFO"jans-scim_persistence.log level
global.scim.appLoggers.persistenceLogTargetstring"FILE"jans-scim_persistence.log target
global.scim.appLoggers.scimLogLevelstring"INFO"jans-scim.log level
global.scim.appLoggers.scimLogTargetstring"STDOUT"jans-scim.log target
global.scim.appLoggers.scriptLogLevelstring"INFO"jans-scim_script.log level
global.scim.appLoggers.scriptLogTargetstring"FILE"jans-scim_script.log target
global.scim.cnCustomJavaOptionsstring""passing custom java options to scim. Notice you do not need to pass in any loggers options as they are introduced below in appLoggers. DO NOT PASS JAVA_OPTIONS in envs.
global.scim.customAnnotationsobject—Add custom annotations for kubernetes resources for the service
global.scim.customAnnotations.deploymentobject{}No description upstream
global.scim.customAnnotations.destinationRuleobject{}No description upstream
global.scim.customAnnotations.horizontalPodAutoscalerobject{}No description upstream
global.scim.customAnnotations.podobject{}No description upstream
global.scim.customAnnotations.podDisruptionBudgetobject{}No description upstream
global.scim.customAnnotations.secretobject{}No description upstream
global.scim.customAnnotations.serviceobject{}No description upstream
global.scim.customAnnotations.virtualServiceobject{}No description upstream
global.scim.enabledbooltrueBoolean flag to enable/disable the SCIM chart.
global.scim.ingressobject—Enable endpoints in either istio or nginx ingress depending on users choice
global.scim.ingress.scimAdditionalAnnotationsobject{}SCIM ingress resource additional annotations.
global.scim.ingress.scimConfigAdditionalAnnotationsobject{}SCIM config ingress resource additional annotations.
global.scim.ingress.scimConfigEnabledboolfalseEnable endpoint /.well-known/scim-configuration
global.scim.ingress.scimConfigLabelsobject{}SCIM config ingress resource labels. key app is taken
global.scim.ingress.scimEnabledboolfalseEnable SCIM endpoints /jans-scim
global.scim.ingress.scimLabelsobject{}SCIM ingress resource labels. key app is taken
global.scim.scimServiceNamestring"scim"Name of the scim service. Please keep it as default.
global.serviceAccountNamestring"default"service account used by Kubernetes resources
global.storageClassobject—StorageClass section. This is not currently used by the openbanking distribution. You may specify custom parameters as needed.
global.storageClass.allowedTopologieslist[]No description upstream
global.storageClass.allowVolumeExpansionbooltrueNo description upstream
global.storageClass.mountOptionslist[]No description upstream
global.storageClass.parametersobject{}No description upstream
global.storageClass.provisionerstring"microk8s.io/hostpath"No description upstream
global.storageClass.reclaimPolicystring"Retain"No description upstream
global.storageClass.volumeBindingModestring"WaitForFirstConsumer"No description upstream
global.usrEnvsobject—Add custom normal and secret envs to the service. Envs defined in global.userEnvs will be globally available to all services
global.usrEnvs.normalobject{}Add custom normal envs to the service.
variable1: value1
global.usrEnvs.secretobject{}Add custom secret envs to the service.
variable1: value1
installer-settings (36)
KeyTypeDefaultDescription
installer-settingsobject—Only used by the installer. These settings do not affect nor are used by the chart
installer-settings.acceptLicensestring""No description upstream
installer-settings.awsobject—No description upstream
installer-settings.aws.arnobject—No description upstream
installer-settings.aws.arn.arnAcmCertstring""No description upstream
installer-settings.aws.arn.enabledstring""No description upstream
installer-settings.aws.lbTypestring""No description upstream
installer-settings.aws.vpcCidrstring"0.0.0.0/0"No description upstream
installer-settings.confirmSettingsboolfalseNo description upstream
installer-settings.currentVersionstring""No description upstream
installer-settings.googleobject—No description upstream
installer-settings.google.useSecretManagerstring""No description upstream
installer-settings.imagesobject—No description upstream
installer-settings.images.editstring""No description upstream
installer-settings.namespacestring""No description upstream
installer-settings.nginxIngressobject—No description upstream
installer-settings.nginxIngress.namespacestring""No description upstream
installer-settings.nginxIngress.releaseNamestring""No description upstream
installer-settings.nodesobject—No description upstream
installer-settings.nodes.ipsstring""No description upstream
installer-settings.nodes.namesstring""No description upstream
installer-settings.nodes.zonesstring""No description upstream
installer-settings.openbankingobject—No description upstream
installer-settings.openbanking.cnObTransportTrustStoreP12passwordstring""No description upstream
installer-settings.openbanking.hasCnObTransportTrustStoreboolfalseNo description upstream
installer-settings.postgresobject—No description upstream
installer-settings.postgres.installstring""No description upstream
installer-settings.postgres.namespacestring""No description upstream
installer-settings.redisobject—No description upstream
installer-settings.redis.installstring""No description upstream
installer-settings.redis.namespacestring""No description upstream
installer-settings.releaseNamestring""No description upstream
installer-settings.sqlobject—No description upstream
installer-settings.sql.installstring""No description upstream
installer-settings.sql.namespacestring""No description upstream
installer-settings.volumeProvisionStrategystring""No description upstream
kc-scheduler (28)
KeyTypeDefaultDescription
kc-schedulerobject—Responsible for synchronizing Keycloak SAML clients
kc-scheduler.additionalAnnotationsobject{}Additional annotations that will be added across the gateway in the format of {cert-manager.io/issuer: "letsencrypt-prod"}
kc-scheduler.additionalLabelsobject{}Additional labels that will be added across the gateway in the format of {mylabel: "myapp"}
kc-scheduler.customCommandlist[]Add custom job's command. If passed, it will override the default conditional command.
kc-scheduler.customScriptslist[]Add custom scripts that have been mounted to run before the entrypoint.
- /tmp/custom.sh
- /tmp/custom2.sh
kc-scheduler.dnsConfigobject{}Add custom dns config
kc-scheduler.dnsPolicystring""Add custom dns policy
kc-scheduler.imageobject—No description upstream
kc-scheduler.image.pullPolicystring"IfNotPresent"Image pullPolicy to use for deploying.
kc-scheduler.image.pullSecretslist[]Image Pull Secrets
kc-scheduler.image.repositorystring"ghcr.io/janssenproject/jans/cloudtools"Image to use for deploying.
kc-scheduler.image.tagstring"1.16.0-1"Image tag to use for deploying.
kc-scheduler.intervalint10Interval of running the scheduler (in minutes)
kc-scheduler.lifecycleobject{}No description upstream
kc-scheduler.nodeSelectorobject{}Add nodeSelector (see https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#nodeselector)
kc-scheduler.resourcesobject—Resource specs.
kc-scheduler.resources.limitsobject—No description upstream
kc-scheduler.resources.limits.cpustring"300m"CPU limit.
kc-scheduler.resources.limits.memorystring"300Mi"Memory limit.
kc-scheduler.resources.requestsobject—No description upstream
kc-scheduler.resources.requests.cpustring"300m"CPU request.
kc-scheduler.resources.requests.memorystring"300Mi"Memory request.
kc-scheduler.tolerationslist[]Add tolerations for the pods
kc-scheduler.usrEnvsobject—Add custom normal and secret envs to the service
kc-scheduler.usrEnvs.normalobject{}Add custom normal envs to the service
variable1: value1
kc-scheduler.usrEnvs.secretobject{}Add custom secret envs to the service
variable1: value1
kc-scheduler.volumeMountslist[]Configure any additional volumesMounts that need to be attached to the containers
kc-scheduler.volumeslist[]Configure any additional volumes that need to be attached to the pod
nginx-ingress (18)
KeyTypeDefaultDescription
nginx-ingressobject—Nginx ingress definitions chart
nginx-ingress.certManagerobject—No description upstream
nginx-ingress.certManager.certificateobject—No description upstream
nginx-ingress.certManager.certificate.enabledboolfalseNo description upstream
nginx-ingress.certManager.certificate.issuerGroupstring"cert-manager.io"No description upstream
nginx-ingress.certManager.certificate.issuerKindstring"ClusterIssuer"No description upstream
nginx-ingress.certManager.certificate.issuerNamestring""No description upstream
nginx-ingress.fullnameOverridenginx-ingressstring""No description upstream
nginx-ingress.ingressobject—No description upstream
nginx-ingress.ingress.additionalAnnotationsobject{}Additional annotations that will be added across all ingress definitions in the format of {cert-manager.io/issuer: "letsencrypt-prod"} Enable client certificate authentication nginx.ingress.kubernetes.io/auth-tls-verify-client: "optional" Create the secret containing the trusted ca certificates nginx.ingress.kubernetes.io/auth-tls-secret: "gluu/tls-certificate" Specify the verification depth in the client certificates chain nginx.ingress.kubernetes.io/auth-tls-verify-depth: "1" Specify if certificates are passed to upstream server nginx.ingress.kubernetes.io/auth-tls-pass-certificate-to-upstream: "true"
nginx-ingress.ingress.additionalLabelsobject{}Additional labels that will be added across all ingress definitions in the format of {mylabel: "myapp"}
nginx-ingress.ingress.enablednginx-ingressbooltrueNo description upstream
nginx-ingress.ingress.hostslist[]No description upstream
nginx-ingress.ingress.ingressClassNamestring"nginx"No description upstream
nginx-ingress.ingress.legacynginx-ingressboolfalseEnable use of legacy API version networking.k8s.io/v1beta1 to support kubernetes 1.18. This flag should be removed next version release along with nginx-ingress/templates/ingress-legacy.yaml.
nginx-ingress.ingress.pathstring"/"No description upstream
nginx-ingress.ingress.tlslist[]No description upstream
nginx-ingress.nameOverridenginx-ingressstring""No description upstream
persistence (30)
KeyTypeDefaultDescription
persistenceobject—Job to generate data and initial config for Gluu Server persistence layer.
persistence.additionalAnnotationsobject{}Additional annotations that will be added across the gateway in the format of {cert-manager.io/issuer: "letsencrypt-prod"}
persistence.additionalLabelsobject{}Additional labels that will be added across the gateway in the format of {mylabel: "myapp"}
persistence.customCommandlist[]Add custom job's command. If passed, it will override the default conditional command.
persistence.customScriptslist[]Add custom scripts that have been mounted to run before the entrypoint.
- /tmp/custom.sh
- /tmp/custom2.sh
persistence.dnsConfigobject{}Add custom dns config
persistence.dnsPolicystring""Add custom dns policy
persistence.fullnameOverridepersistencestring""No description upstream
persistence.imageobject—No description upstream
persistence.image.pullPolicystring"IfNotPresent"Image pullPolicy to use for deploying.
persistence.image.pullSecretslist[]Image Pull Secrets
persistence.image.repositorystring"ghcr.io/gluufederation/flex/persistence-loader"Image to use for deploying.
persistence.image.tagstring"5.16.0-1"Image tag to use for deploying.
persistence.imagePullSecretspersistencelist[]No description upstream
persistence.lifecycleobject{}No description upstream
persistence.nameOverridepersistencestring""No description upstream
persistence.nodeSelectorobject{}Add nodeSelector (see https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#nodeselector)
persistence.resourcesobject—Resource specs.
persistence.resources.limitsobject—No description upstream
persistence.resources.limits.cpustring"300m"CPU limit
persistence.resources.limits.memorystring"300Mi"Memory limit.
persistence.resources.requestsobject—No description upstream
persistence.resources.requests.cpustring"300m"CPU request.
persistence.resources.requests.memorystring"300Mi"Memory request.
persistence.tolerationslist[]Add tolerations for the pods
persistence.usrEnvsobject—Add custom normal and secret envs to the service
persistence.usrEnvs.normalobject{}Add custom normal envs to the service
variable1: value1
persistence.usrEnvs.secretobject{}Add custom secret envs to the service
variable1: value1
persistence.volumeMountslist[]Configure any additional volumesMounts that need to be attached to the containers
persistence.volumeslist[]Configure any additional volumes that need to be attached to the pod
saml (64)
KeyTypeDefaultDescription
samlobject—SAML.
saml.additionalAnnotationsobject{}Additional annotations that will be added across the gateway in the format of {cert-manager.io/issuer: "letsencrypt-prod"}
saml.additionalLabelsobject{}Additional labels that will be added across the gateway in the format of {mylabel: "myapp"}
saml.customCommandlist[]Add custom pod's command. If passed, it will override the default conditional command.
saml.customScriptslist[]Add custom scripts that have been mounted to run before the entrypoint.
- /tmp/custom.sh
- /tmp/custom2.sh
saml.dnsConfigobject{}Add custom dns config
saml.dnsPolicystring""Add custom dns policy
saml.fullnameOverridesamlstring""No description upstream
saml.hpaobject—Configure the HorizontalPodAutoscaler
saml.hpa.behaviorobject{}Scaling Policies
saml.hpa.enabledbooltrueNo description upstream
saml.hpa.maxReplicasint10No description upstream
saml.hpa.metricslist[]metrics if targetCPUUtilizationPercentage is not set
saml.hpa.minReplicasint1No description upstream
saml.hpa.targetCPUUtilizationPercentageint50No description upstream
saml.imageobject—No description upstream
saml.image.pullPolicystring"IfNotPresent"Image pullPolicy to use for deploying.
saml.image.pullSecretslist[]Image Pull Secrets
saml.image.repositorystring"ghcr.io/janssenproject/jans/saml"Image to use for deploying.
saml.image.tagstring"1.16.0-1"Image tag to use for deploying.
saml.lifecycleobject{}No description upstream
saml.livenessProbeobject—Configure the liveness healthcheck for the auth server if needed.
saml.livenessProbe.execobject—http liveness probe endpoint
saml.livenessProbe.exec.commandlist[]No description upstream
saml.livenessProbe.failureThresholdint10No description upstream
saml.livenessProbe.initialDelaySecondsint30No description upstream
saml.livenessProbe.periodSecondsint30No description upstream
saml.livenessProbe.timeoutSecondsint5No description upstream
saml.nameOverridesamlstring""No description upstream
saml.nodeSelectorobject{}Add nodeSelector (see https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#nodeselector)
saml.pdbobject—Configure the PodDisruptionBudget
saml.pdb.enabledbooltrueNo description upstream
saml.pdb.maxUnavailablestring"90%"No description upstream
saml.podSecurityContextsamlobject{}No description upstream
saml.readinessProbeobject—No description upstream
saml.readinessProbe.execobject—http readiness probe endpoint
saml.readinessProbe.exec.commandlist[]No description upstream
saml.readinessProbe.failureThresholdint10No description upstream
saml.readinessProbe.initialDelaySecondsint25No description upstream
saml.readinessProbe.periodSecondsint25No description upstream
saml.readinessProbe.timeoutSecondsint5No description upstream
saml.replicasint1Service replica number.
saml.resourcesobject—Resource specs.
saml.resources.limitsobject—No description upstream
saml.resources.limits.cpustring"500m"CPU limit.
saml.resources.limits.memorystring"1200Mi"Memory limit. This value is used to calculate memory allocation for Java. Currently it only supports `Mi`. Please refrain from using other units.
saml.resources.requestsobject—No description upstream
saml.resources.requests.cpustring"500m"CPU request.
saml.resources.requests.memorystring"1200Mi"Memory request.
saml.securityContextsamlobject{}No description upstream
saml.servicesamlobject—No description upstream
saml.service.namesamlstring"http-saml"The name of the saml port within the saml service. Please keep it as default.
saml.service.portsamlint8083Port of the saml service. Please keep it as default.
saml.service.sessionAffinitysamlstring"None"Default set to None If you want to make sure that connections from a particular client are passed to the same Pod each time, you can select the session affinity based on the client's IP addresses by setting this to ClientIP
saml.service.sessionAffinityConfigsamlobject—the maximum session sticky time if sessionAffinity is ClientIP
saml.service.sessionAffinityConfig.clientIPsamlobject—No description upstream
saml.service.sessionAffinityConfig.clientIP.timeoutSecondssamlint10800No description upstream
saml.tolerationslist[]Add tolerations for the pods
saml.topologySpreadConstraintsobject{}Configure the topology spread constraints. Notice this is a map NOT a list as in the upstream API https://kubernetes.io/docs/concepts/scheduling-eviction/topology-spread-constraints/
saml.usrEnvsobject—Add custom normal and secret envs to the service
saml.usrEnvs.normalobject{}Add custom normal envs to the service
variable1: value1
saml.usrEnvs.secretobject{}Add custom secret envs to the service
variable1: value1
saml.volumeMountslist[]Configure any additional volumesMounts that need to be attached to the containers
saml.volumeslist[]Configure any additional volumes that need to be attached to the pod
scim (60)
KeyTypeDefaultDescription
scimobject—System for Cross-domain Identity Management (SCIM) version 2.0
scim.additionalAnnotationsobject{}Additional annotations that will be added across the gateway in the format of {cert-manager.io/issuer: "letsencrypt-prod"}
scim.additionalLabelsobject{}Additional labels that will be added across the gateway in the format of {mylabel: "myapp"}
scim.customCommandlist[]Add custom pod's command. If passed, it will override the default conditional command.
scim.customScriptslist[]Add custom scripts that have been mounted to run before the entrypoint.
- /tmp/custom.sh
- /tmp/custom2.sh
scim.dnsConfigobject{}Add custom dns config
scim.dnsPolicystring""Add custom dns policy
scim.hpaobject—Configure the HorizontalPodAutoscaler
scim.hpa.behaviorobject{}Scaling Policies
scim.hpa.enabledbooltrueNo description upstream
scim.hpa.maxReplicasint10No description upstream
scim.hpa.metricslist[]metrics if targetCPUUtilizationPercentage is not set
scim.hpa.minReplicasint1No description upstream
scim.hpa.targetCPUUtilizationPercentageint50No description upstream
scim.imageobject—No description upstream
scim.image.pullPolicystring"IfNotPresent"Image pullPolicy to use for deploying.
scim.image.pullSecretslist[]Image Pull Secrets
scim.image.repositorystring"ghcr.io/janssenproject/jans/scim"Image to use for deploying.
scim.image.tagstring"1.16.0-1"Image tag to use for deploying.
scim.lifecycleobject{}No description upstream
scim.livenessProbeobject—Configure the liveness healthcheck for SCIM if needed.
scim.livenessProbe.httpGetobject—No description upstream
scim.livenessProbe.httpGet.pathstring"/jans-scim/sys/health-check"http liveness probe endpoint
scim.livenessProbe.httpGet.portint8080No description upstream
scim.livenessProbe.initialDelaySecondsint30No description upstream
scim.livenessProbe.periodSecondsint30No description upstream
scim.livenessProbe.timeoutSecondsint5No description upstream
scim.nodeSelectorobject{}Add nodeSelector (see https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#nodeselector)
scim.pdbobject—Configure the PodDisruptionBudget
scim.pdb.enabledbooltrueNo description upstream
scim.pdb.maxUnavailablestring"90%"No description upstream
scim.readinessProbeobject—Configure the readiness healthcheck for the SCIM if needed.
scim.readinessProbe.httpGetobject—No description upstream
scim.readinessProbe.httpGet.pathstring"/jans-scim/sys/health-check"http readiness probe endpoint
scim.readinessProbe.httpGet.portint8080No description upstream
scim.readinessProbe.initialDelaySecondsint25No description upstream
scim.readinessProbe.periodSecondsint25No description upstream
scim.readinessProbe.timeoutSecondsint5No description upstream
scim.replicasint1Service replica number.
scim.resourcesobject—No description upstream
scim.resources.limitsobject—No description upstream
scim.resources.limits.cpustring"1000m"CPU limit.
scim.resources.limits.memorystring"1200Mi"Memory limit. This value is used to calculate memory allocation for Java. Currently it only supports `Mi`. Please refrain from using other units.
scim.resources.requestsobject—No description upstream
scim.resources.requests.cpustring"1000m"CPU request.
scim.resources.requests.memorystring"1200Mi"Memory request.
scim.serviceobject—No description upstream
scim.service.namestring"http-scim"The name of the scim port within the scim service. Please keep it as default.
scim.service.portint8080Port of the scim service. Please keep it as default.
scim.service.sessionAffinityscimstring"None"Default set to None If you want to make sure that connections from a particular client are passed to the same Pod each time, you can select the session affinity based on the client's IP addresses by setting this to ClientIP
scim.service.sessionAffinityConfigscimobject—the maximum session sticky time if sessionAffinity is ClientIP
scim.service.sessionAffinityConfig.clientIPscimobject—No description upstream
scim.service.sessionAffinityConfig.clientIP.timeoutSecondsscimint10800No description upstream
scim.tolerationslist[]Add tolerations for the pods
scim.topologySpreadConstraintsobject{}Configure the topology spread constraints. Notice this is a map NOT a list as in the upstream API https://kubernetes.io/docs/concepts/scheduling-eviction/topology-spread-constraints/
scim.usrEnvsobject—Add custom normal and secret envs to the service
scim.usrEnvs.normalobject{}Add custom normal envs to the service
variable1: value1
scim.usrEnvs.secretobject{}Add custom secret envs to the service
variable1: value1
scim.volumeMountslist[]Configure any additional volumesMounts that need to be attached to the containers
scim.volumeslist[]Configure any additional volumes that need to be attached to the pod

We use analytics cookies to measure which pages are useful, so we can improve them. They are only set if you accept. Essential cookies needed for the site to work are always on. See our privacy policy.