Skip to content
Browse Gluu Flex 6.3.0

Flex Helm Chart

Version: 6.3.0 AppVersion: 6.3.0

Gluu Access and Identity Management

Homepage: https://www.gluu.org

#Maintainers

NameEmailUrl
moabuteam@gluu.org

#Source Code

#Requirements

Kubernetes: >=v1.23.0-0

RepositoryNameVersion
admin-ui6.3.0
auth-server6.3.0
auth-server-key-rotation6.3.0
casa6.3.0
cleanup6.3.0
cn-istio-ingress6.3.0
config6.3.0
config-api6.3.0
fido26.3.0
gateway-api6.3.0
nginx-ingress6.3.0
persistence6.3.0
scim6.3.0

#Values

KeyTypeDefaultDescription
admin-uiobject{"additionalAnnotations":{},"additionalLabels":{},"customCommand":[],"customScripts":[],"dnsConfig":{},"dnsPolicy":"","hpa":{"behavior":{},"enabled":true,"maxReplicas":10,"metrics":[],"minReplicas":1,"targetCPUUtilizationPercentage":50},"image":{"pullPolicy":"IfNotPresent","pullSecrets":[],"repository":"ghcr.io/gluufederation/flex/admin-ui","tag":"6.3.0"},"lifecycle":{},"livenessProbe":{"failureThreshold":20,"initialDelaySeconds":60,"periodSeconds":25,"tcpSocket":{"port":8080},"timeoutSeconds":5},"nodeSelector":{},"pdb":{"enabled":true,"maxUnavailable":"90%"},"readinessProbe":{"failureThreshold":20,"initialDelaySeconds":60,"periodSeconds":25,"tcpSocket":{"port":8080},"timeoutSeconds":5},"replicas":1,"resources":{"limits":{"cpu":"2000m","memory":"2000Mi"},"requests":{"cpu":"2000m","memory":"2000Mi"}},"tolerations":[],"topologySpreadConstraints":{},"usrEnvs":{"normal":{},"secret":{}},"volumeMounts":[],"volumes":[]}Admin GUI for configuration of the auth-server
admin-ui.additionalAnnotationsobject{}Additional annotations that will be added across the gateway in the format of {cert-manager.io/issuer: "letsencrypt-prod"}
admin-ui.additionalLabelsobject{}Additional labels that will be added across the gateway in the format of {mylabel: "myapp"}
admin-ui.customCommandlist[]Add custom pod's command. If passed, it will override the default conditional command.
admin-ui.customScriptslist[]Add custom scripts that have been mounted to run before the entrypoint. - /tmp/custom.sh - /tmp/custom2.sh
admin-ui.dnsConfigobject{}Add custom dns config
admin-ui.dnsPolicystring""Add custom dns policy
admin-ui.hpaobject{"behavior":{},"enabled":true,"maxReplicas":10,"metrics":[],"minReplicas":1,"targetCPUUtilizationPercentage":50}Configure the HorizontalPodAutoscaler
admin-ui.hpa.behaviorobject{}Scaling Policies
admin-ui.hpa.metricslist[]metrics if targetCPUUtilizationPercentage is not set
admin-ui.image.pullPolicystring"IfNotPresent"Image pullPolicy to use for deploying.
admin-ui.image.pullSecretslist[]Image Pull Secrets
admin-ui.image.repositorystring"ghcr.io/gluufederation/flex/admin-ui"Image to use for deploying.
admin-ui.image.tagstring"6.3.0"Image tag to use for deploying.
admin-ui.livenessProbeobject{"failureThreshold":20,"initialDelaySeconds":60,"periodSeconds":25,"tcpSocket":{"port":8080},"timeoutSeconds":5}Configure the liveness healthcheck for the admin ui if needed.
admin-ui.nodeSelectorobject{}Add nodeSelector (see https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#nodeselector)
admin-ui.pdbobject{"enabled":true,"maxUnavailable":"90%"}Configure the PodDisruptionBudget
admin-ui.readinessProbeobject{"failureThreshold":20,"initialDelaySeconds":60,"periodSeconds":25,"tcpSocket":{"port":8080},"timeoutSeconds":5}Configure the readiness healthcheck for the admin ui if needed.
admin-ui.replicasint1Service replica number.
admin-ui.resourcesobject{"limits":{"cpu":"2000m","memory":"2000Mi"},"requests":{"cpu":"2000m","memory":"2000Mi"}}Resource specs.
admin-ui.resources.limits.cpustring"2000m"CPU limit.
admin-ui.resources.limits.memorystring"2000Mi"Memory limit.
admin-ui.resources.requests.cpustring"2000m"CPU request.
admin-ui.resources.requests.memorystring"2000Mi"Memory request.
admin-ui.tolerationslist[]Add tolerations for the pods
admin-ui.topologySpreadConstraintsobject{}Configure the topology spread constraints. Notice this is a map NOT a list as in the upstream API https://kubernetes.io/docs/concepts/scheduling-eviction/topology-spread-constraints/
admin-ui.usrEnvsobject{"normal":{},"secret":{}}Add custom normal and secret envs to the service
admin-ui.usrEnvs.normalobject{}Add custom normal envs to the service variable1: value1
admin-ui.usrEnvs.secretobject{}Add custom secret envs to the service variable1: value1
admin-ui.volumeMountslist[]Configure any additional volumesMounts that need to be attached to the containers
admin-ui.volumeslist[]Configure any additional volumes that need to be attached to the pod
auth-serverobject{"additionalAnnotations":{},"additionalLabels":{},"customCommand":[],"customScripts":[],"dnsConfig":{},"dnsPolicy":"","hpa":{"behavior":{},"enabled":true,"maxReplicas":10,"metrics":[],"minReplicas":1,"targetCPUUtilizationPercentage":50},"image":{"pullPolicy":"IfNotPresent","pullSecrets":[],"repository":"ghcr.io/janssenproject/jans/auth-server","tag":"6.3.0"},"lifecycle":{},"livenessProbe":{"exec":{"command":["python3","/app/scripts/healthcheck.py"]},"initialDelaySeconds":30,"periodSeconds":30,"timeoutSeconds":5},"nodeSelector":{},"pdb":{"enabled":true,"maxUnavailable":"90%"},"readinessProbe":{"exec":{"command":["python3","/app/scripts/healthcheck.py"]},"initialDelaySeconds":25,"periodSeconds":25,"timeoutSeconds":5},"replicas":1,"resources":{"limits":{"cpu":"2500m","memory":"2500Mi"},"requests":{"cpu":"2500m","memory":"2500Mi"}},"tolerations":[],"topologySpreadConstraints":{},"usrEnvs":{"normal":{},"secret":{}},"volumeMounts":[],"volumes":[]}OAuth Authorization Server, the OpenID Connect Provider, the UMA Authorization Server--this is the main Internet facing component of Gluu. It's the service that returns tokens, JWT's and identity assertions. This service must be Internet facing.
auth-server-key-rotationobject{"additionalAnnotations":{},"additionalLabels":{},"cronJobSchedule":"","customCommand":[],"customScripts":[],"dnsConfig":{},"dnsPolicy":"","image":{"pullPolicy":"IfNotPresent","pullSecrets":[],"repository":"ghcr.io/janssenproject/jans/cloudtools","tag":"6.3.0"},"keysLife":48,"keysPushDelay":0,"keysPushStrategy":"NEWER","keysStrategy":"NEWER","lifecycle":{},"nodeSelector":{},"resources":{"limits":{"cpu":"300m","memory":"300Mi"},"requests":{"cpu":"300m","memory":"300Mi"}},"tolerations":[],"usrEnvs":{"normal":{},"secret":{}},"volumeMounts":[],"volumes":[]}Responsible for regenerating auth-keys per x hours
auth-server-key-rotation.additionalAnnotationsobject{}Additional annotations that will be added across the gateway in the format of {cert-manager.io/issuer: "letsencrypt-prod"}
auth-server-key-rotation.additionalLabelsobject{}Additional labels that will be added across the gateway in the format of {mylabel: "myapp"}
auth-server-key-rotation.cronJobSchedulestring""Auth server key rotation job schedule. It accepts any Cron syntax supported by Kubernetes. If empty, the schedule will run based on keysLife value.
auth-server-key-rotation.customCommandlist[]Add custom job's command. If passed, it will override the default conditional command.
auth-server-key-rotation.customScriptslist[]Add custom scripts that have been mounted to run before the entrypoint. - /tmp/custom.sh - /tmp/custom2.sh
auth-server-key-rotation.dnsConfigobject{}Add custom dns config
auth-server-key-rotation.dnsPolicystring""Add custom dns policy
auth-server-key-rotation.image.pullPolicystring"IfNotPresent"Image pullPolicy to use for deploying.
auth-server-key-rotation.image.pullSecretslist[]Image Pull Secrets
auth-server-key-rotation.image.repositorystring"ghcr.io/janssenproject/jans/cloudtools"Image to use for deploying.
auth-server-key-rotation.image.tagstring"6.3.0"Image tag to use for deploying.
auth-server-key-rotation.keysLifeint48Auth server key rotation keys life in hours
auth-server-key-rotation.keysPushDelayint0Delay (in seconds) before pushing private keys to Auth server
auth-server-key-rotation.keysPushStrategystring"NEWER"Set key selection strategy after pushing private keys to Auth server (only takes effect when keysPushDelay value is greater than 0)
auth-server-key-rotation.keysStrategystring"NEWER"Set key selection strategy used by Auth server
auth-server-key-rotation.nodeSelectorobject{}Add nodeSelector (see https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#nodeselector)
auth-server-key-rotation.resourcesobject{"limits":{"cpu":"300m","memory":"300Mi"},"requests":{"cpu":"300m","memory":"300Mi"}}Resource specs.
auth-server-key-rotation.resources.limits.cpustring"300m"CPU limit.
auth-server-key-rotation.resources.limits.memorystring"300Mi"Memory limit.
auth-server-key-rotation.resources.requests.cpustring"300m"CPU request.
auth-server-key-rotation.resources.requests.memorystring"300Mi"Memory request.
auth-server-key-rotation.tolerationslist[]Add tolerations for the pods
auth-server-key-rotation.usrEnvsobject{"normal":{},"secret":{}}Add custom normal and secret envs to the service
auth-server-key-rotation.usrEnvs.normalobject{}Add custom normal envs to the service variable1: value1
auth-server-key-rotation.usrEnvs.secretobject{}Add custom secret envs to the service variable1: value1
auth-server-key-rotation.volumeMountslist[]Configure any additional volumesMounts that need to be attached to the containers
auth-server-key-rotation.volumeslist[]Configure any additional volumes that need to be attached to the pod
auth-server.additionalAnnotationsobject{}Additional annotations that will be added across the gateway in the format of {cert-manager.io/issuer: "letsencrypt-prod"}
auth-server.additionalLabelsobject{}Additional labels that will be added across the gateway in the format of {mylabel: "myapp"}
auth-server.customCommandlist[]Add custom pod's command. If passed, it will override the default conditional command.
auth-server.customScriptslist[]Add custom scripts that have been mounted to run before the entrypoint. - /tmp/custom.sh - /tmp/custom2.sh
auth-server.dnsConfigobject{}Add custom dns config
auth-server.dnsPolicystring""Add custom dns policy
auth-server.hpaobject{"behavior":{},"enabled":true,"maxReplicas":10,"metrics":[],"minReplicas":1,"targetCPUUtilizationPercentage":50}Configure the HorizontalPodAutoscaler
auth-server.hpa.behaviorobject{}Scaling Policies
auth-server.hpa.metricslist[]metrics if targetCPUUtilizationPercentage is not set
auth-server.image.pullPolicystring"IfNotPresent"Image pullPolicy to use for deploying.
auth-server.image.pullSecretslist[]Image Pull Secrets
auth-server.image.repositorystring"ghcr.io/janssenproject/jans/auth-server"Image to use for deploying.
auth-server.image.tagstring"6.3.0"Image tag to use for deploying.
auth-server.livenessProbeobject{"exec":{"command":["python3","/app/scripts/healthcheck.py"]},"initialDelaySeconds":30,"periodSeconds":30,"timeoutSeconds":5}Configure the liveness healthcheck for the auth server if needed.
auth-server.livenessProbe.execobject{"command":["python3","/app/scripts/healthcheck.py"]}Executes the python3 healthcheck. https://github.com/JanssenProject/docker-jans-auth-server/blob/master/scripts/healthcheck.py
auth-server.nodeSelectorobject{}Add nodeSelector (see https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#nodeselector)
auth-server.pdbobject{"enabled":true,"maxUnavailable":"90%"}Configure the PodDisruptionBudget
auth-server.readinessProbeobject{"exec":{"command":["python3","/app/scripts/healthcheck.py"]},"initialDelaySeconds":25,"periodSeconds":25,"timeoutSeconds":5}Configure the readiness healthcheck for the auth server if needed. https://github.com/JanssenProject/docker-jans-auth-server/blob/master/scripts/healthcheck.py
auth-server.replicasint1Service replica number.
auth-server.resourcesobject{"limits":{"cpu":"2500m","memory":"2500Mi"},"requests":{"cpu":"2500m","memory":"2500Mi"}}Resource specs.
auth-server.resources.limits.cpustring"2500m"CPU limit.
auth-server.resources.limits.memorystring"2500Mi"Memory limit. This value is used to calculate memory allocation for Java. Currently it only supports Mi. Please refrain from using other units.
auth-server.resources.requests.cpustring"2500m"CPU request.
auth-server.resources.requests.memorystring"2500Mi"Memory request.
auth-server.tolerationslist[]Add tolerations for the pods
auth-server.topologySpreadConstraintsobject{}Configure the topology spread constraints. Notice this is a map NOT a list as in the upstream API https://kubernetes.io/docs/concepts/scheduling-eviction/topology-spread-constraints/
auth-server.usrEnvsobject{"normal":{},"secret":{}}Add custom normal and secret envs to the service
auth-server.usrEnvs.normalobject{}Add custom normal envs to the service variable1: value1
auth-server.usrEnvs.secretobject{}Add custom secret envs to the service variable1: value1
auth-server.volumeMountslist[]Configure any additional volumesMounts that need to be attached to the containers
auth-server.volumeslist[]Configure any additional volumes that need to be attached to the pod
casaobject{"additionalAnnotations":{},"additionalLabels":{},"customCommand":[],"customScripts":[],"dnsConfig":{},"dnsPolicy":"","hpa":{"behavior":{},"enabled":true,"maxReplicas":10,"metrics":[],"minReplicas":1,"targetCPUUtilizationPercentage":50},"image":{"pullPolicy":"IfNotPresent","pullSecrets":[],"repository":"ghcr.io/janssenproject/jans/casa","tag":"6.3.0"},"lifecycle":{},"livenessProbe":{"httpGet":{"path":"/jans-casa/health-check","port":"http-casa"},"initialDelaySeconds":25,"periodSeconds":25,"timeoutSeconds":5},"nodeSelector":{},"pdb":{"enabled":true,"maxUnavailable":"90%"},"readinessProbe":{"httpGet":{"path":"/jans-casa/health-check","port":"http-casa"},"initialDelaySeconds":30,"periodSeconds":30,"timeoutSeconds":5},"replicas":1,"resources":{"limits":{"cpu":"500m","memory":"500Mi"},"requests":{"cpu":"500m","memory":"500Mi"}},"tolerations":[],"topologySpreadConstraints":{},"usrEnvs":{"normal":{},"secret":{}},"volumeMounts":[],"volumes":[]}Janssen Casa ("Casa") is a self-service web portal for end-users to manage authentication and authorization preferences for their account in a Janssen Auth Server.
casa.additionalAnnotationsobject{}Additional annotations that will be added across the gateway in the format of {cert-manager.io/issuer: "letsencrypt-prod"}
casa.additionalLabelsobject{}Additional labels that will be added across the gateway in the format of {mylabel: "myapp"}
casa.customCommandlist[]Add custom pod's command. If passed, it will override the default conditional command.
casa.customScriptslist[]Add custom scripts that have been mounted to run before the entrypoint. - /tmp/custom.sh - /tmp/custom2.sh
casa.dnsConfigobject{}Add custom dns config
casa.dnsPolicystring""Add custom dns policy
casa.hpaobject{"behavior":{},"enabled":true,"maxReplicas":10,"metrics":[],"minReplicas":1,"targetCPUUtilizationPercentage":50}Configure the HorizontalPodAutoscaler
casa.hpa.behaviorobject{}Scaling Policies
casa.hpa.metricslist[]metrics if targetCPUUtilizationPercentage is not set
casa.image.pullPolicystring"IfNotPresent"Image pullPolicy to use for deploying.
casa.image.pullSecretslist[]Image Pull Secrets
casa.image.repositorystring"ghcr.io/janssenproject/jans/casa"Image to use for deploying.
casa.image.tagstring"6.3.0"Image tag to use for deploying.
casa.livenessProbeobject{"httpGet":{"path":"/jans-casa/health-check","port":"http-casa"},"initialDelaySeconds":25,"periodSeconds":25,"timeoutSeconds":5}Configure the liveness healthcheck for casa if needed.
casa.livenessProbe.httpGet.pathstring"/jans-casa/health-check"http liveness probe endpoint
casa.nodeSelectorobject{}Add nodeSelector (see https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#nodeselector)
casa.pdbobject{"enabled":true,"maxUnavailable":"90%"}Configure the PodDisruptionBudget
casa.readinessProbeobject{"httpGet":{"path":"/jans-casa/health-check","port":"http-casa"},"initialDelaySeconds":30,"periodSeconds":30,"timeoutSeconds":5}Configure the readiness healthcheck for the casa if needed.
casa.readinessProbe.httpGet.pathstring"/jans-casa/health-check"http readiness probe endpoint
casa.replicasint1Service replica number.
casa.resourcesobject{"limits":{"cpu":"500m","memory":"500Mi"},"requests":{"cpu":"500m","memory":"500Mi"}}Resource specs.
casa.resources.limits.cpustring"500m"CPU limit.
casa.resources.limits.memorystring"500Mi"Memory limit. This value is used to calculate memory allocation for Java. Currently it only supports Mi. Please refrain from using other units.
casa.resources.requests.cpustring"500m"CPU request.
casa.resources.requests.memorystring"500Mi"Memory request.
casa.tolerationslist[]Add tolerations for the pods
casa.topologySpreadConstraintsobject{}Configure the topology spread constraints. Notice this is a map NOT a list as in the upstream API https://kubernetes.io/docs/concepts/scheduling-eviction/topology-spread-constraints/
casa.usrEnvsobject{"normal":{},"secret":{}}Add custom normal and secret envs to the service
casa.usrEnvs.normalobject{}Add custom normal envs to the service variable1: value1
casa.usrEnvs.secretobject{}Add custom secret envs to the service variable1: value1
casa.volumeMountslist[]Configure any additional volumesMounts that need to be attached to the containers
casa.volumeslist[]Configure any additional volumes that need to be attached to the pod
cleanupobject{"additionalAnnotations":{},"additionalLabels":{},"customCommand":[],"customScripts":[],"dnsConfig":{},"dnsPolicy":"","image":{"pullPolicy":"IfNotPresent","pullSecrets":[],"repository":"ghcr.io/janssenproject/jans/cloudtools","tag":"6.3.0"},"interval":60,"lifecycle":{},"limit":1000,"nodeSelector":{},"resources":{"limits":{"cpu":"300m","memory":"300Mi"},"requests":{"cpu":"300m","memory":"300Mi"}},"tolerations":[],"usrEnvs":{"normal":{},"secret":{}},"volumeMounts":[],"volumes":[]}Cleanup expired entries in persistence
cleanup.additionalAnnotationsobject{}Additional annotations that will be added across the gateway in the format of {cert-manager.io/issuer: "letsencrypt-prod"}
cleanup.additionalLabelsobject{}Additional labels that will be added across the gateway in the format of {mylabel: "myapp"}
cleanup.customCommandlist[]Add custom job's command. If passed, it will override the default conditional command.
cleanup.customScriptslist[]Add custom scripts that have been mounted to run before the entrypoint. - /tmp/custom.sh - /tmp/custom2.sh
cleanup.dnsConfigobject{}Add custom dns config
cleanup.dnsPolicystring""Add custom dns policy
cleanup.image.pullPolicystring"IfNotPresent"Image pullPolicy to use for deploying.
cleanup.image.pullSecretslist[]Image Pull Secrets
cleanup.image.repositorystring"ghcr.io/janssenproject/jans/cloudtools"Image to use for deploying.
cleanup.image.tagstring"6.3.0"Image tag to use for deploying.
cleanup.intervalint60Interval of running the cleanup process (in minutes)
cleanup.limitint1000Max. numbers of entries to cleanup
cleanup.nodeSelectorobject{}Add nodeSelector (see https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#nodeselector)
cleanup.resourcesobject{"limits":{"cpu":"300m","memory":"300Mi"},"requests":{"cpu":"300m","memory":"300Mi"}}Resource specs.
cleanup.resources.limits.cpustring"300m"CPU limit.
cleanup.resources.limits.memorystring"300Mi"Memory limit.
cleanup.resources.requests.cpustring"300m"CPU request.
cleanup.resources.requests.memorystring"300Mi"Memory request.
cleanup.tolerationslist[]Add tolerations for the pods
cleanup.usrEnvsobject{"normal":{},"secret":{}}Add custom normal and secret envs to the service
cleanup.usrEnvs.normalobject{}Add custom normal envs to the service variable1: value1
cleanup.usrEnvs.secretobject{}Add custom secret envs to the service variable1: value1
cleanup.volumeMountslist[]Configure any additional volumesMounts that need to be attached to the containers
cleanup.volumeslist[]Configure any additional volumes that need to be attached to the pod
configobject{"additionalAnnotations":{},"additionalLabels":{},"adminPassword":"Test1234#","city":"Austin","configmap":{"cnAwsAccessKeyId":"","cnAwsDefaultRegion":"us-west-1","cnAwsProfile":"gluu","cnAwsSecretAccessKey":"","cnAwsSecretsEndpointUrl":"","cnAwsSecretsNamePrefix":"gluu","cnAwsSecretsReplicaRegions":[],"cnCacheType":"NATIVE_PERSISTENCE","cnConfigKubernetesConfigMap":"cn","cnGoogleProjectId":"google-project-to-save-config-and-secrets-to","cnGoogleSecretManagerServiceAccount":"SWFtTm90YVNlcnZpY2VBY2NvdW50Q2hhbmdlTWV0b09uZQo=","cnGoogleSecretNamePrefix":"gluu","cnGoogleSecretVersionId":"latest","cnJettyRequestHeaderSize":8192,"cnMaxRamPercent":"75.0","cnMessageType":"DISABLED","cnPersistenceHybridMapping":"{}","cnRedisSentinelGroup":"","cnRedisSslTruststore":"","cnRedisType":"STANDALONE","cnRedisUrl":"redis.redis.svc.cluster.local:6379","cnRedisUseSsl":false,"cnScimProtectionMode":"OAUTH","cnSecretKubernetesSecret":"cn","cnSqlDbDialect":"mysql","cnSqlDbHost":"my-release-mysql.default.svc.cluster.local","cnSqlDbName":"gluu","cnSqlDbPort":3306,"cnSqlDbSchema":"","cnSqlDbTimezone":"UTC","cnSqlDbUser":"gluu","cnSqlSslCaCert":"","cnSqlSslClientCert":"","cnSqlSslClientKey":"","cnSqlSslEnabled":false,"cnSqlSslMode":"","cnSqldbUserPassword":"Test1234#","cnVaultAddr":"http://localhost:8200","cnVaultAppRolePath":"approle","cnVaultKvPath":"secret","cnVaultNamespace":"","cnVaultPrefix":"jans","cnVaultRoleId":"","cnVaultRoleIdFile":"/etc/certs/vault_role_id","cnVaultSecretId":"","cnVaultSecretIdFile":"/etc/certs/vault_secret_id","cnVaultVerify":false,"lbAddr":""},"countryCode":"US","customCommand":[],"customScripts":[],"dnsConfig":{},"dnsPolicy":"","email":"team@gluu.org","image":{"pullSecrets":[],"repository":"ghcr.io/janssenproject/jans/configurator","tag":"6.3.0"},"lifecycle":{},"migration":{"enabled":false,"migrationDataFormat":"ldif","migrationDir":"/ce-migration"},"nodeSelector":{},"orgName":"Gluu","redisPassword":"P@assw0rd","resources":{"limits":{"cpu":"300m","memory":"300Mi"},"requests":{"cpu":"300m","memory":"300Mi"}},"salt":"","state":"TX","tolerations":[],"usrEnvs":{"normal":{},"secret":{}},"volumeMounts":[],"volumes":[]}Configuration parameters for setup and initial configuration secret and config layers used by Gluu services.
config-apiobject{"additionalAnnotations":{},"additionalLabels":{},"customCommand":[],"customScripts":[],"dnsConfig":{},"dnsPolicy":"","hpa":{"behavior":{},"enabled":true,"maxReplicas":10,"metrics":[],"minReplicas":1,"targetCPUUtilizationPercentage":50},"image":{"pullPolicy":"IfNotPresent","pullSecrets":[],"repository":"ghcr.io/janssenproject/jans/config-api","tag":"6.3.0"},"lifecycle":{},"livenessProbe":{"httpGet":{"path":"/jans-config-api/api/v1/health/live","port":8074},"initialDelaySeconds":30,"periodSeconds":30,"timeoutSeconds":5},"nodeSelector":{},"pdb":{"enabled":true,"maxUnavailable":"90%"},"readinessProbe":{"httpGet":{"path":"/jans-config-api/api/v1/health/ready","port":8074},"initialDelaySeconds":25,"periodSeconds":25,"timeoutSeconds":5},"replicas":1,"resources":{"limits":{"cpu":"1000m","memory":"1200Mi"},"requests":{"cpu":"1000m","memory":"1200Mi"}},"tolerations":[],"topologySpreadConstraints":{},"usrEnvs":{"normal":{},"secret":{}},"volumeMounts":[],"volumes":[]}Config Api endpoints can be used to configure the auth-server, which is an open-source OpenID Connect Provider (OP) and UMA Authorization Server (AS).
config-api.additionalAnnotationsobject{}Additional annotations that will be added across the gateway in the format of {cert-manager.io/issuer: "letsencrypt-prod"}
config-api.additionalLabelsobject{}Additional labels that will be added across the gateway in the format of {mylabel: "myapp"}
config-api.customCommandlist[]Add custom pod's command. If passed, it will override the default conditional command.
config-api.customScriptslist[]Add custom scripts that have been mounted to run before the entrypoint. - /tmp/custom.sh - /tmp/custom2.sh
config-api.dnsConfigobject{}Add custom dns config
config-api.dnsPolicystring""Add custom dns policy
config-api.hpaobject{"behavior":{},"enabled":true,"maxReplicas":10,"metrics":[],"minReplicas":1,"targetCPUUtilizationPercentage":50}Configure the HorizontalPodAutoscaler
config-api.hpa.behaviorobject{}Scaling Policies
config-api.hpa.metricslist[]metrics if targetCPUUtilizationPercentage is not set
config-api.image.pullPolicystring"IfNotPresent"Image pullPolicy to use for deploying.
config-api.image.pullSecretslist[]Image Pull Secrets
config-api.image.repositorystring"ghcr.io/janssenproject/jans/config-api"Image to use for deploying.
config-api.image.tagstring"6.3.0"Image tag to use for deploying.
config-api.livenessProbeobject{"httpGet":{"path":"/jans-config-api/api/v1/health/live","port":8074},"initialDelaySeconds":30,"periodSeconds":30,"timeoutSeconds":5}Configure the liveness healthcheck for the auth server if needed.
config-api.livenessProbe.httpGetobject{"path":"/jans-config-api/api/v1/health/live","port":8074}http liveness probe endpoint
config-api.nodeSelectorobject{}Add nodeSelector (see https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#nodeselector)
config-api.pdbobject{"enabled":true,"maxUnavailable":"90%"}Configure the PodDisruptionBudget
config-api.readinessProbe.httpGetobject{"path":"/jans-config-api/api/v1/health/ready","port":8074}http readiness probe endpoint
config-api.replicasint1Service replica number.
config-api.resourcesobject{"limits":{"cpu":"1000m","memory":"1200Mi"},"requests":{"cpu":"1000m","memory":"1200Mi"}}Resource specs.
config-api.resources.limits.cpustring"1000m"CPU limit.
config-api.resources.limits.memorystring"1200Mi"Memory limit. This value is used to calculate memory allocation for Java. Currently it only supports Mi. Please refrain from using other units.
config-api.resources.requests.cpustring"1000m"CPU request.
config-api.resources.requests.memorystring"1200Mi"Memory request.
config-api.tolerationslist[]Add tolerations for the pods
config-api.topologySpreadConstraintsobject{}Configure the topology spread constraints. Notice this is a map NOT a list as in the upstream API https://kubernetes.io/docs/concepts/scheduling-eviction/topology-spread-constraints/
config-api.usrEnvsobject{"normal":{},"secret":{}}Add custom normal and secret envs to the service
config-api.usrEnvs.normalobject{}Add custom normal envs to the service variable1: value1
config-api.usrEnvs.secretobject{}Add custom secret envs to the service variable1: value1
config-api.volumeMountslist[]Configure any additional volumesMounts that need to be attached to the containers
config-api.volumeslist[]Configure any additional volumes that need to be attached to the pod
config.additionalAnnotationsobject{}Additional annotations that will be added across the gateway in the format of {cert-manager.io/issuer: "letsencrypt-prod"}
config.additionalLabelsobject{}Additional labels that will be added across the gateway in the format of {mylabel: "myapp"}
config.adminPasswordstring"Test1234#"Admin password to log in to the UI.
config.citystring"Austin"City. Used for certificate creation.
config.configmap.cnCacheTypestring"NATIVE_PERSISTENCE"Cache type. NATIVE_PERSISTENCE, REDIS. or IN_MEMORY. Defaults to NATIVE_PERSISTENCE .
config.configmap.cnConfigKubernetesConfigMapstring"cn"The name of the Kubernetes ConfigMap that will hold the configuration layer
config.configmap.cnGoogleProjectIdstring"google-project-to-save-config-and-secrets-to"Project id of the Google project the secret manager belongs to. Used only when global.configAdapterName and global.configSecretAdapter is set to google.
config.configmap.cnGoogleSecretManagerServiceAccountstring"SWFtTm90YVNlcnZpY2VBY2NvdW50Q2hhbmdlTWV0b09uZQo="Service account with roles roles/secretmanager.admin base64 encoded string. This is used often inside the services to reach the configuration layer. Used only when global.configAdapterName and global.configSecretAdapter is set to google.
config.configmap.cnGoogleSecretNamePrefixstring"gluu"Prefix for Gluu secret in Google Secret Manager. Defaults to gluu. If left gluu-secret secret will be created. Used only when global.configAdapterName and global.configSecretAdapter is set to google.
config.configmap.cnGoogleSecretVersionIdstring"latest"Secret version to be used for secret configuration. Defaults to latest and should normally always stay that way. Used only when global.configAdapterName and global.configSecretAdapter is set to google.
config.configmap.cnJettyRequestHeaderSizeint8192Jetty header size in bytes in the auth server
config.configmap.cnMaxRamPercentstring"75.0"Value passed to Java option -XX:MaxRAMPercentage
config.configmap.cnMessageTypestring"DISABLED"Message type (one of POSTGRES, REDIS, or DISABLED)
config.configmap.cnPersistenceHybridMappingstring"{}"Specify data that should be saved in persistence (one of default, user, cache, site, token, or session; default to default). Note this environment only takes effect when global.cnPersistenceType is set to hybrid. { "default": "<sql>", "user": "<sql>", "site": "<sql>", "cache": "<sql>", "token": "<sql>", "session": "<sql>", }
config.configmap.cnRedisSentinelGroupstring""Redis Sentinel Group. Often set when config.configmap.cnRedisType is set to SENTINEL. Can be used when config.configmap.cnCacheType is set to REDIS.
config.configmap.cnRedisSslTruststorestring""Redis SSL truststore. Optional. Can be used when config.configmap.cnCacheType is set to REDIS.
config.configmap.cnRedisTypestring"STANDALONE"Redis service type. STANDALONE or CLUSTER. Can be used when config.configmap.cnCacheType is set to REDIS.
config.configmap.cnRedisUrlstring"redis.redis.svc.cluster.local:6379"Redis URL and port number <url>:<port>. Can be used when config.configmap.cnCacheType is set to REDIS.
config.configmap.cnRedisUseSslboolfalseBoolean to use SSL in Redis. Can be used when config.configmap.cnCacheType is set to REDIS.
config.configmap.cnScimProtectionModestring"OAUTH"SCIM protection mode OAUTH
config.configmap.cnSecretKubernetesSecretstring"cn"Kubernetes secret name holding configuration keys. Used when global.configSecretAdapter is set to kubernetes which is the default.
config.configmap.cnSqlDbDialectstring"mysql"SQL database dialect. mysql or pgsql
config.configmap.cnSqlDbHoststring"my-release-mysql.default.svc.cluster.local"SQL database host uri.
config.configmap.cnSqlDbNamestring"gluu"SQL database name.
config.configmap.cnSqlDbPortint3306SQL database port.
config.configmap.cnSqlDbSchemastring""Schema name used by SQL database (default to empty-string; if using MySQL, the schema name will be resolved as the database name, whereas in PostgreSQL the schema name will be resolved as "public").
config.configmap.cnSqlDbTimezonestring"UTC"SQL database timezone.
config.configmap.cnSqlDbUserstring"gluu"SQL database username.
config.configmap.cnSqlSslCaCertstring""Base64-encoded string of CA certificate used to sign client/server certificate of MySQL/PostgreSQL server. Required if using client cert authentication.
config.configmap.cnSqlSslClientCertstring""Base64-encoded string of client certificate signed by CA. Required if using client cert authentication.
config.configmap.cnSqlSslClientKeystring""Base64-encoded client private key corresponding to the client certificate. Required if using client cert authentication. We advise to not commit real private keys in values.yaml.
config.configmap.cnSqlSslEnabledboolfalseEnable SSL connection to SQL database.
config.configmap.cnSqlSslModestring""Mode used to connect to SQL database using SSL if cnSqlSslEnabled is set to true. If using MySQL, choose one of PREFERRED, REQUIRED, VERIFY_CA, or VERIFY_IDENTITY. If using PostgreSQL, choose one of allow, prefer, require, verify-ca, or verify-full.
config.configmap.cnSqldbUserPasswordstring"Test1234#"SQL password injected the secrets .
config.configmap.cnVaultAddrstring"http://localhost:8200"Base URL of Vault.
config.configmap.cnVaultAppRolePathstring"approle"Path to Vault AppRole.
config.configmap.cnVaultKvPathstring"secret"Path to Vault KV secrets engine.
config.configmap.cnVaultNamespacestring""Vault namespace used to access the secrets.
config.configmap.cnVaultPrefixstring"jans"Base prefix name used to access secrets.
config.configmap.cnVaultRoleIdstring""Vault AppRole RoleID.
config.configmap.cnVaultRoleIdFilestring"/etc/certs/vault_role_id"Path to file contains Vault AppRole role ID.
config.configmap.cnVaultSecretIdstring""Vault AppRole SecretID.
config.configmap.cnVaultSecretIdFilestring"/etc/certs/vault_secret_id"Path to file contains Vault AppRole secret ID.
config.configmap.cnVaultVerifyboolfalseVerify connection to Vault.
config.configmap.lbAddrstring""Load balancer address for AWS if the FQDN is not registered.
config.countryCodestring"US"Country code. Used for certificate creation.
config.customCommandlist[]Add custom job's command. If passed, it will override the default conditional command.
config.customScriptslist[]Add custom scripts that have been mounted to run before the entrypoint. - /tmp/custom.sh - /tmp/custom2.sh
config.dnsConfigobject{}Add custom dns config
config.dnsPolicystring""Add custom dns policy
config.emailstring"team@gluu.org"Email address of the administrator usually. Used for certificate creation.
config.image.pullSecretslist[]Image Pull Secrets
config.image.repositorystring"ghcr.io/janssenproject/jans/configurator"Image to use for deploying.
config.image.tagstring"6.3.0"Image tag to use for deploying.
config.migrationobject{"enabled":false,"migrationDataFormat":"ldif","migrationDir":"/ce-migration"}CE to CN Migration section
config.migration.enabledboolfalseBoolean flag to enable migration from CE
config.migration.migrationDataFormatstring"ldif"migration data-format depending on persistence backend. Supported data formats are ldif, postgresql+json, and mysql+json.
config.migration.migrationDirstring"/ce-migration"Directory holding all migration files
config.nodeSelectorobject{}Add nodeSelector (see https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#nodeselector)
config.orgNamestring"Gluu"Organization name. Used for certificate creation.
config.redisPasswordstring"P@assw0rd"Redis admin password if config.configmap.cnCacheType is set to REDIS.
config.resourcesobject{"limits":{"cpu":"300m","memory":"300Mi"},"requests":{"cpu":"300m","memory":"300Mi"}}Resource specs.
config.resources.limits.cpustring"300m"CPU limit.
config.resources.limits.memorystring"300Mi"Memory limit.
config.resources.requests.cpustring"300m"CPU request.
config.resources.requests.memorystring"300Mi"Memory request.
config.saltstring""Salt. Used for encoding/decoding sensitive data. If omitted or set to empty string, the value will be self-generated. Otherwise, a 24 alphanumeric characters are allowed as its value.
config.statestring"TX"State code. Used for certificate creation.
config.tolerationslist[]Add tolerations for the pods
config.usrEnvsobject{"normal":{},"secret":{}}Add custom normal and secret envs to the service.
config.usrEnvs.normalobject{}Add custom normal envs to the service. variable1: value1
config.usrEnvs.secretobject{}Add custom secret envs to the service. variable1: value1
config.volumeMountslist[]Configure any additional volumesMounts that need to be attached to the containers
config.volumeslist[]Configure any additional volumes that need to be attached to the pod
fido2object{"additionalAnnotations":{},"additionalLabels":{},"customCommand":[],"customScripts":[],"dnsConfig":{},"dnsPolicy":"","hpa":{"behavior":{},"enabled":true,"maxReplicas":10,"metrics":[],"minReplicas":1,"targetCPUUtilizationPercentage":50},"image":{"pullPolicy":"IfNotPresent","pullSecrets":[],"repository":"ghcr.io/janssenproject/jans/fido2","tag":"6.3.0"},"lifecycle":{},"livenessProbe":{"httpGet":{"path":"/jans-fido2/sys/health-check","port":"http-fido2"},"initialDelaySeconds":25,"periodSeconds":25,"timeoutSeconds":5},"nodeSelector":{},"pdb":{"enabled":true,"maxUnavailable":"90%"},"readinessProbe":{"httpGet":{"path":"/jans-fido2/sys/health-check","port":"http-fido2"},"initialDelaySeconds":30,"periodSeconds":30,"timeoutSeconds":5},"replicas":1,"resources":{"limits":{"cpu":"500m","memory":"500Mi"},"requests":{"cpu":"500m","memory":"500Mi"}},"service":{"name":"http-fido2","port":8080},"tolerations":[],"topologySpreadConstraints":{},"usrEnvs":{"normal":{},"secret":{}},"volumeMounts":[],"volumes":[]}FIDO 2.0 (FIDO2) is an open authentication standard that enables leveraging common devices to authenticate to online services in both mobile and desktop environments.
fido2.additionalAnnotationsobject{}Additional annotations that will be added across the gateway in the format of {cert-manager.io/issuer: "letsencrypt-prod"}
fido2.additionalLabelsobject{}Additional labels that will be added across the gateway in the format of {mylabel: "myapp"}
fido2.customCommandlist[]Add custom pod's command. If passed, it will override the default conditional command.
fido2.customScriptslist[]Add custom scripts that have been mounted to run before the entrypoint. - /tmp/custom.sh - /tmp/custom2.sh
fido2.dnsConfigobject{}Add custom dns config
fido2.dnsPolicystring""Add custom dns policy
fido2.hpaobject{"behavior":{},"enabled":true,"maxReplicas":10,"metrics":[],"minReplicas":1,"targetCPUUtilizationPercentage":50}Configure the HorizontalPodAutoscaler
fido2.hpa.behaviorobject{}Scaling Policies
fido2.hpa.metricslist[]metrics if targetCPUUtilizationPercentage is not set
fido2.image.pullPolicystring"IfNotPresent"Image pullPolicy to use for deploying.
fido2.image.pullSecretslist[]Image Pull Secrets
fido2.image.repositorystring"ghcr.io/janssenproject/jans/fido2"Image to use for deploying.
fido2.image.tagstring"6.3.0"Image tag to use for deploying.
fido2.livenessProbeobject{"httpGet":{"path":"/jans-fido2/sys/health-check","port":"http-fido2"},"initialDelaySeconds":25,"periodSeconds":25,"timeoutSeconds":5}Configure the liveness healthcheck for the fido2 if needed.
fido2.livenessProbe.httpGetobject{"path":"/jans-fido2/sys/health-check","port":"http-fido2"}http liveness probe endpoint
fido2.nodeSelectorobject{}Add nodeSelector (see https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#nodeselector)
fido2.pdbobject{"enabled":true,"maxUnavailable":"90%"}Configure the PodDisruptionBudget
fido2.readinessProbeobject{"httpGet":{"path":"/jans-fido2/sys/health-check","port":"http-fido2"},"initialDelaySeconds":30,"periodSeconds":30,"timeoutSeconds":5}Configure the readiness healthcheck for the fido2 if needed.
fido2.replicasint1Service replica number.
fido2.resourcesobject{"limits":{"cpu":"500m","memory":"500Mi"},"requests":{"cpu":"500m","memory":"500Mi"}}Resource specs.
fido2.resources.limits.cpustring"500m"CPU limit.
fido2.resources.limits.memorystring"500Mi"Memory limit. This value is used to calculate memory allocation for Java. Currently it only supports Mi. Please refrain from using other units.
fido2.resources.requests.cpustring"500m"CPU request.
fido2.resources.requests.memorystring"500Mi"Memory request.
fido2.service.namestring"http-fido2"The name of the fido2 port within the fido2 service. Please keep it as default.
fido2.service.portint8080Port of the fido2 service. Please keep it as default.
fido2.tolerationslist[]Add tolerations for the pods
fido2.topologySpreadConstraintsobject{}Configure the topology spread constraints. Notice this is a map NOT a list as in the upstream API https://kubernetes.io/docs/concepts/scheduling-eviction/topology-spread-constraints/
fido2.usrEnvsobject{"normal":{},"secret":{}}Add custom normal and secret envs to the service
fido2.usrEnvs.normalobject{}Add custom normal envs to the service variable1: value1
fido2.usrEnvs.secretobject{}Add custom secret envs to the service variable1: value1
fido2.volumeMountslist[]Configure any additional volumesMounts that need to be attached to the containers
fido2.volumeslist[]Configure any additional volumes that need to be attached to the pod
gateway-apiobject{"additionalConfig":{"airlock":{"createLbService":false},"cilium":{"ipPoolBlocks":[]},"envoy":{"createGatewayClass":false},"istio":{},"kgateway":{},"nginx":{"enableAuditGrpcRewriteSnippets":false,"enableClientCertSnippets":false},"traefik":{}},"gateway":{"annotations":{},"attachLbIp":false,"caCert":"","className":"nginx","enabled":true,"httpPort":80,"httpsPort":443,"infrastructure":{"annotations":{},"labels":{},"parametersRef":{}},"labels":{},"name":"gluu-gateway","tlsSecretName":"tls-certificate","verifyClientCertProtection":false},"routes":{"annotations":{},"gatewayNamespace":"","httpSectionName":"http","httpsSectionName":"https","labels":{}}}Gateway API implementation. We support all GA-conformant implementations (e.g., 'nginx', 'istio', 'traefik'). See https://gateway-api.sigs.k8s.io/implementations/#conformant
gateway-api.additionalConfigobject{"airlock":{"createLbService":false},"cilium":{"ipPoolBlocks":[]},"envoy":{"createGatewayClass":false},"istio":{},"kgateway":{},"nginx":{"enableAuditGrpcRewriteSnippets":false,"enableClientCertSnippets":false},"traefik":{}}Additional configuration for Specific Gateway API implementation
gateway-api.additionalConfig.airlockobject{"createLbService":false}Configuration for Airlock Microgateway
gateway-api.additionalConfig.airlock.createLbServiceboolfalseCreate LoadBalancer service using GatewayParameters (by default airlock-microgateway doesn't create the service). See https://docs.airlock.com/microgateway/latest/index/api/crds/gateway-parameters/v1alpha1/ for details. The GatewayParameters will be attached to gateway.infrastructure.parametersRef only if it's empty.
gateway-api.additionalConfig.ciliumobject{"ipPoolBlocks":[]}Configuration for Cilium.
gateway-api.additionalConfig.cilium.ipPoolBlockslist[]Create Cilium IP pool with the specified blocks. See https://docs.cilium.io/en/stable/network/lb-ipam/ for details.
gateway-api.additionalConfig.envoyobject{"createGatewayClass":false}Configuration for Envoy.
gateway-api.additionalConfig.envoy.createGatewayClassboolfalseCreate GatewayClass named envoy (by default Envoy doesn't create gatewayclass). The envoy name can be set as value of gateway.className attribute.
gateway-api.additionalConfig.istioobject{}Configuration for Istio.
gateway-api.additionalConfig.kgatewayobject{}Configuration for kgateway.
gateway-api.additionalConfig.nginxobject{"enableAuditGrpcRewriteSnippets":false,"enableClientCertSnippets":false}Configuration for NGINX Fabric.
gateway-api.additionalConfig.nginx.enableAuditGrpcRewriteSnippetsboolfalseEnable URL rewrite to forward audit gRPC requests /io.jans.lock.audit.AuditService to /jans-auth/io.jans.lock.audit.AuditService. Snippet support must be enabled during NGINX installation (otherwise endpoints will return HTTP status code 500). See https://docs.nginx.com/nginx-gateway-fabric/traffic-management/snippets#setup.
gateway-api.additionalConfig.nginx.enableClientCertSnippetsboolfalseEnable client certificate verification using Snippets and NginxProxy. Snippet support must be enabled during NGINX installation (otherwise endpoints will return HTTP status code 500). See https://docs.nginx.com/nginx-gateway-fabric/traffic-management/snippets#setup The NginxProxy will be attached to gateway.infrastructure.parametersRef only if it's empty.
gateway-api.additionalConfig.traefikobject{}Configuration for Traefik.
gateway-api.gatewayobject{"annotations":{},"attachLbIp":false,"caCert":"","className":"nginx","enabled":true,"httpPort":80,"httpsPort":443,"infrastructure":{"annotations":{},"labels":{},"parametersRef":{}},"labels":{},"name":"gluu-gateway","tlsSecretName":"tls-certificate","verifyClientCertProtection":false}Configuration for Gateway resource
gateway-api.gateway.annotationsobject{}Specific annotations for the Gateway resource
gateway-api.gateway.attachLbIpboolfalseAttach global.lbIp to Gateway spec.addresses with IPAddress type (enable this if loadbalancer doesn't assign IP address to Gateway automatically)
gateway-api.gateway.caCertstring""Base64-encoded string of CA certificate used to sign client/server certificate. Required if using client cert authentication.
gateway-api.gateway.classNamestring"nginx"Set the gatewayClassName corresponding to your installed controller.
gateway-api.gateway.enabledbooltrueEnable Gateway API and create a Gateway resource (if disabled, you will have to create and manage the Gateway resource externally).
gateway-api.gateway.httpPortint80Gateway http port number
gateway-api.gateway.httpsPortint443Gateway https port number
gateway-api.gateway.infrastructureobject{"annotations":{},"labels":{},"parametersRef":{}}Gateway spec.infrastructure
gateway-api.gateway.infrastructure.annotationsobject{}Specific annotations for the infrastructure
gateway-api.gateway.infrastructure.labelsobject{}Specific labels for the infrastructure
gateway-api.gateway.infrastructure.parametersRefobject{}Specific parametersRef for the infrastructure
gateway-api.gateway.labelsobject{}Specific labels for the Gateway resource
gateway-api.gateway.namestring"gluu-gateway"The name of the Gateway resource to be created
gateway-api.gateway.tlsSecretNamestring"tls-certificate"Secret containing the TLS certificate for the Gateway
gateway-api.gateway.verifyClientCertProtectionboolfalseVerify client certificate for protected endpoints (if enabled, caCert must be set). See additionalConfig for implementation-wise configuration (if any).
gateway-api.routesobject{"annotations":{},"gatewayNamespace":"","httpSectionName":"http","httpsSectionName":"https","labels":{}}Configuration for HTTPRoute and its related resources
gateway-api.routes.annotationsobject{}Specific annotations for the HTTPRoute resource
gateway-api.routes.gatewayNamespacestring""Namespace where the Gateway resource resides. Set this ONLY if the Gateway is externally managed in a different namespace than this Helm release. If set, ensure the target namespace exists and your Gateway controller has the required cross-namespace RBAC permissions.
gateway-api.routes.httpSectionNamestring"http"Only set the httpSectionName and httpsSectionName if it doesn't work with the default values, according to your installed controller (e.g. some controller may require the listener name to be default).
gateway-api.routes.labelsobject{}Specific labels for the HTTPRoute resource
globalobject{"admin-ui":{"adminUiServiceName":"admin-ui","customAnnotations":{"deployment":{},"destinationRule":{},"horizontalPodAutoscaler":{},"pod":{},"podDisruptionBudget":{},"secret":{},"service":{},"virtualService":{}},"enabled":true,"ingress":{"adminUiAdditionalAnnotations":{},"adminUiEnabled":true,"adminUiLabels":{}}},"auth-server":{"appLoggers":{"auditStatsLogLevel":"INFO","auditStatsLogTarget":"FILE","authLogLevel":"INFO","authLogTarget":"STDOUT","enableStdoutLogPrefix":"true","httpLogLevel":"INFO","httpLogTarget":"FILE","lockLogLevel":"INFO","lockLogTarget":"STDOUT","persistenceDurationLogLevel":"INFO","persistenceDurationLogTarget":"FILE","persistenceLogLevel":"INFO","persistenceLogTarget":"FILE","rootLogLevel":"INFO","rootLogTarget":"STDOUT","scriptLogLevel":"INFO","scriptLogTarget":"FILE"},"authEncKeys":"RSA1_5 RSA-OAEP","authServerServiceName":"auth-server","authSigKeys":"RS256 RS384 RS512 ES256 ES384 ES512 PS256 PS384 PS512","cnCustomJavaOptions":"","customAnnotations":{"deployment":{},"destinationRule":{},"horizontalPodAutoscaler":{},"pod":{},"podDisruptionBudget":{},"secret":{},"service":{},"virtualService":{}},"enabled":true,"ingress":{"authServerAdditionalAnnotations":{},"authServerEnabled":true,"authServerLabels":{},"authServerProtectedRegister":false,"authServerProtectedRegisterAdditionalAnnotations":{},"authServerProtectedRegisterLabels":{},"authServerProtectedToken":false,"authServerProtectedTokenAdditionalAnnotations":{},"authServerProtectedTokenLabels":{},"authzenAdditionalAnnotations":{},"authzenConfigEnabled":true,"authzenConfigLabels":{},"deviceCodeAdditionalAnnotations":{},"deviceCodeEnabled":true,"deviceCodeLabels":{},"firebaseMessagingAdditionalAnnotations":{},"firebaseMessagingEnabled":true,"firebaseMessagingLabels":{},"lockAdditionalAnnotations":{},"lockAuditEnabled":false,"lockConfigAdditionalAnnotations":{},"lockConfigEnabled":false,"lockConfigLabels":{},"lockLabels":{},"openidAdditionalAnnotations":{},"openidConfigEnabled":true,"openidConfigLabels":{},"uma2AdditionalAnnotations":{},"uma2ConfigEnabled":true,"uma2ConfigLabels":{},"webfingerAdditionalAnnotations":{},"webfingerEnabled":true,"webfingerLabels":{}},"lockEnabled":false},"auth-server-key-rotation":{"customAnnotations":{"cronjob":{},"secret":{},"service":{}},"enabled":true,"initKeysLife":48},"awsStorageType":"io1","azureStorageAccountType":"Standard_LRS","azureStorageKind":"Managed","casa":{"adminEnabled":true,"appLoggers":{"casaLogLevel":"INFO","casaLogTarget":"STDOUT","enableStdoutLogPrefix":"true","rootLogLevel":"INFO","rootLogTarget":"STDOUT","timerLogLevel":"INFO","timerLogTarget":"FILE"},"casaServiceName":"casa","cnCustomJavaOptions":"","customAnnotations":{"deployment":{},"destinationRule":{},"horizontalPodAutoscaler":{},"pod":{},"podDisruptionBudget":{},"secret":{},"service":{},"virtualService":{}},"enabled":true,"ingress":{"casaAdditionalAnnotations":{},"casaEnabled":false,"casaLabels":{}}},"cleanup":{"enabled":true},"cloud":{"testEnviroment":false},"cnAwsConfigFile":"/etc/jans/conf/aws_config_file","cnAwsSecretsReplicaRegionsFile":"/etc/jans/conf/aws_secrets_replica_regions","cnAwsSharedCredentialsFile":"/etc/jans/conf/aws_shared_credential_file","cnConfiguratorConfigurationFile":"/etc/jans/conf/configuration.json","cnConfiguratorCustomSchema":{"secretName":""},"cnConfiguratorDumpFile":"/etc/jans/conf/configuration.out.json","cnConfiguratorKey":"","cnConfiguratorKeyFile":"/etc/jans/conf/configuration.key","cnDocumentStoreType":"DB","cnGoogleApplicationCredentials":"/etc/jans/conf/google-credentials.json","cnObExtSigningJwksCrt":"","cnObExtSigningJwksKey":"","cnObExtSigningJwksKeyPassPhrase":"","cnObExtSigningJwksUri":"https://mykeystore.openbanking.wow/xxxxx/xxxxx.jwks","cnObInternalSigningAlias":"XkwIzWy44xWSlcWnMiEc8iq9s2G","cnObStaticSigningKeyKid":"XkwIzWy44xWSlcWnMiEc8iq9s2G","cnObTransportAlias":"","cnObTransportCrt":"","cnObTransportKey":"","cnObTransportKeyPassPhrase":"","cnObTransportTrustStore":"","cnPersistenceType":"sql","cnPrometheusPort":"","cnSqlPasswordFile":"/etc/jans/conf/sql_password","config":{"customAnnotations":{"clusterRoleBinding":{},"configMap":{},"job":{},"role":{},"roleBinding":{},"secret":{},"service":{},"serviceAccount":{}},"enabled":true},"config-api":{"adminUiAppLoggers":{"adminUiAuditLogLevel":"INFO","adminUiAuditLogTarget":"FILE","adminUiLogLevel":"INFO","adminUiLogTarget":"FILE","enableStdoutLogPrefix":"true"},"appLoggers":{"configApiLogLevel":"INFO","configApiLogTarget":"STDOUT","enableStdoutLogPrefix":"true","persistenceDurationLogLevel":"INFO","persistenceDurationLogTarget":"FILE","persistenceLogLevel":"INFO","persistenceLogTarget":"FILE","rootLogLevel":"INFO","rootLogTarget":"STDOUT","scriptLogLevel":"INFO","scriptLogTarget":"FILE"},"cnCustomJavaOptions":"","configApiServerServiceName":"config-api","customAnnotations":{"deployment":{},"destinationRule":{},"horizontalPodAutoscaler":{},"pod":{},"podDisruptionBudget":{},"service":{},"virtualService":{}},"enabled":true,"ingress":{"configApiAdditionalAnnotations":{},"configApiEnabled":true,"configApiLabels":{}},"plugins":"admin-ui,fido2,scim,user-mgt"},"configAdapterName":"kubernetes","configSecretAdapter":"kubernetes","distribution":"default","fido2":{"appLoggers":{"enableStdoutLogPrefix":"true","fido2LogLevel":"INFO","fido2LogTarget":"STDOUT","persistenceDurationLogLevel":"INFO","persistenceDurationLogTarget":"FILE","persistenceLogLevel":"INFO","persistenceLogTarget":"FILE","rootLogLevel":"INFO","rootLogTarget":"STDOUT","scriptLogLevel":"INFO","scriptLogTarget":"FILE"},"cnCustomJavaOptions":"","customAnnotations":{"deployment":{},"destinationRule":{},"horizontalPodAutoscaler":{},"pod":{},"podDisruptionBudget":{},"secret":{},"service":{},"virtualService":{}},"enabled":true,"fido2ServiceName":"fido2","ingress":{"fido2AdditionalAnnotations":{},"fido2ConfigAdditionalAnnotations":{},"fido2ConfigEnabled":false,"fido2ConfigLabels":{},"fido2Enabled":false,"fido2Labels":{},"fido2WebauthnAdditionalAnnotations":{},"fido2WebauthnEnabled":false,"fido2WebauthnLabels":{}}},"fqdn":"demoexample.gluu.org","gateway-api":{"enabled":false},"gcePdStorageType":"pd-standard","isFqdnRegistered":false,"istio":{"additionalAnnotations":{},"additionalLabels":{},"enabled":false,"gateways":[],"ingress":false,"namespace":"istio-system"},"jobTtlSecondsAfterFinished":300,"lbIp":"22.22.22.22","nginx-ingress":{"enabled":true},"persistence":{"customAnnotations":{"job":{},"secret":{},"service":{}},"enabled":true},"scim":{"appLoggers":{"enableStdoutLogPrefix":"true","persistenceDurationLogLevel":"INFO","persistenceDurationLogTarget":"FILE","persistenceLogLevel":"INFO","persistenceLogTarget":"FILE","rootLogLevel":"INFO","rootLogTarget":"STDOUT","scimLogLevel":"INFO","scimLogTarget":"STDOUT","scriptLogLevel":"INFO","scriptLogTarget":"FILE"},"cnCustomJavaOptions":"","customAnnotations":{"deployment":{},"destinationRule":{},"horizontalPodAutoscaler":{},"pod":{},"podDisruptionBudget":{},"secret":{},"service":{},"virtualService":{}},"enabled":true,"ingress":{"scimAdditionalAnnotations":{},"scimConfigAdditionalAnnotations":{},"scimConfigEnabled":false,"scimConfigLabels":{},"scimEnabled":false,"scimLabels":{}},"scimServiceName":"scim"},"serviceAccountName":"default","storageClass":{"allowVolumeExpansion":true,"allowedTopologies":[],"mountOptions":["debug"],"parameters":{},"provisioner":"microk8s.io/hostpath","reclaimPolicy":"Retain","volumeBindingMode":"WaitForFirstConsumer"},"usrEnvs":{"normal":{},"secret":{}}}Parameters used globally across all services helm charts.
global.admin-ui.adminUiServiceNamestring"admin-ui"Name of the admin-ui service. Please keep it as default.
global.admin-ui.enabledbooltrueBoolean flag to enable/disable the admin-ui chart and admin ui config api plugin.
global.admin-ui.ingress.adminUiAdditionalAnnotationsobject{}Admin UI ingress resource additional annotations.
global.admin-ui.ingress.adminUiEnabledbooltrueEnable Admin UI endpoints in either istio or nginx ingress depending on users choice
global.admin-ui.ingress.adminUiLabelsobject{}Admin UI ingress resource labels. key app is taken.
global.auth-server-key-rotation.enabledbooltrueBoolean flag to enable/disable the auth-server-key rotation cronjob chart.
global.auth-server-key-rotation.initKeysLifeint48The initial auth server key rotation keys life in hours
global.auth-server.appLoggersobject{"auditStatsLogLevel":"INFO","auditStatsLogTarget":"FILE","authLogLevel":"INFO","authLogTarget":"STDOUT","enableStdoutLogPrefix":"true","httpLogLevel":"INFO","httpLogTarget":"FILE","lockLogLevel":"INFO","lockLogTarget":"STDOUT","persistenceDurationLogLevel":"INFO","persistenceDurationLogTarget":"FILE","persistenceLogLevel":"INFO","persistenceLogTarget":"FILE","rootLogLevel":"INFO","rootLogTarget":"STDOUT","scriptLogLevel":"INFO","scriptLogTarget":"FILE"}App loggers can be configured to define where the logs will be redirected to and the level of each in which it should be displayed.
global.auth-server.appLoggers.auditStatsLogLevelstring"INFO"jans-auth_audit.log level
global.auth-server.appLoggers.auditStatsLogTargetstring"FILE"jans-auth_audit.log target
global.auth-server.appLoggers.authLogLevelstring"INFO"jans-auth.log level
global.auth-server.appLoggers.authLogTargetstring"STDOUT"jans-auth.log target
global.auth-server.appLoggers.enableStdoutLogPrefixstring"true"Enable log prefixing which enables prepending the STDOUT logs with the file name. i.e auth-server-script ===> 2022-12-20 17:49:55,744 INFO
global.auth-server.appLoggers.httpLogLevelstring"INFO"http_request_response.log level
global.auth-server.appLoggers.httpLogTargetstring"FILE"http_request_response.log target
global.auth-server.appLoggers.lockLogLevelstring"INFO"jans-lock.log level
global.auth-server.appLoggers.lockLogTargetstring"STDOUT"jans-lock.log target
global.auth-server.appLoggers.persistenceDurationLogLevelstring"INFO"jans-auth_persistence_duration.log level
global.auth-server.appLoggers.persistenceDurationLogTargetstring"FILE"jans-auth_persistence_duration.log target
global.auth-server.appLoggers.persistenceLogLevelstring"INFO"jans-auth_persistence.log level
global.auth-server.appLoggers.persistenceLogTargetstring"FILE"jans-auth_persistence.log target
global.auth-server.appLoggers.rootLogLevelstring"INFO"root log level
global.auth-server.appLoggers.rootLogTargetstring"STDOUT"root log target (if set to FILE, logs will be redirected to jans-auth.log)
global.auth-server.appLoggers.scriptLogLevelstring"INFO"jans-auth_script.log level
global.auth-server.appLoggers.scriptLogTargetstring"FILE"jans-auth_script.log target
global.auth-server.authEncKeysstring"RSA1_5 RSA-OAEP"space-separated key algorithm for encryption (default to RSA1_5 RSA-OAEP)
global.auth-server.authServerServiceNamestring"auth-server"Name of the auth-server service. Please keep it as default.
global.auth-server.authSigKeysstring"RS256 RS384 RS512 ES256 ES384 ES512 PS256 PS384 PS512"space-separated key algorithm for signing (default to RS256 RS384 RS512 ES256 ES384 ES512 PS256 PS384 PS512)
global.auth-server.cnCustomJavaOptionsstring""passing custom java options to auth-server. Notice you do not need to pass in any loggers options as they are introduced below in appLoggers. DO NOT PASS JAVA_OPTIONS in envs.
global.auth-server.enabledbooltrueBoolean flag to enable/disable auth-server chart. You should never set this to false.
global.auth-server.ingressobject{"authServerAdditionalAnnotations":{},"authServerEnabled":true,"authServerLabels":{},"authServerProtectedRegister":false,"authServerProtectedRegisterAdditionalAnnotations":{},"authServerProtectedRegisterLabels":{},"authServerProtectedToken":false,"authServerProtectedTokenAdditionalAnnotations":{},"authServerProtectedTokenLabels":{},"authzenAdditionalAnnotations":{},"authzenConfigEnabled":true,"authzenConfigLabels":{},"deviceCodeAdditionalAnnotations":{},"deviceCodeEnabled":true,"deviceCodeLabels":{},"firebaseMessagingAdditionalAnnotations":{},"firebaseMessagingEnabled":true,"firebaseMessagingLabels":{},"lockAdditionalAnnotations":{},"lockAuditEnabled":false,"lockConfigAdditionalAnnotations":{},"lockConfigEnabled":false,"lockConfigLabels":{},"lockLabels":{},"openidAdditionalAnnotations":{},"openidConfigEnabled":true,"openidConfigLabels":{},"uma2AdditionalAnnotations":{},"uma2ConfigEnabled":true,"uma2ConfigLabels":{},"webfingerAdditionalAnnotations":{},"webfingerEnabled":true,"webfingerLabels":{}}Enable endpoints in either istio or nginx ingress depending on users choice
global.auth-server.ingress.authServerAdditionalAnnotationsobject{}Auth server ingress resource additional annotations.
global.auth-server.ingress.authServerEnabledbooltrueEnable Auth server endpoints /jans-auth
global.auth-server.ingress.authServerLabelsobject{}Auth server ingress resource labels. key app is taken
global.auth-server.ingress.authServerProtectedRegisterboolfalseEnable mTLS on Auth server endpoint /jans-auth/restv1/register.
global.auth-server.ingress.authServerProtectedRegisterAdditionalAnnotationsobject{}Auth server protected register ingress resource additional annotations.
global.auth-server.ingress.authServerProtectedRegisterLabelsobject{}Auth server protected token ingress resource labels. key app is taken
global.auth-server.ingress.authServerProtectedTokenboolfalseEnable mTLS on Auth server endpoint /jans-auth/restv1/token.
global.auth-server.ingress.authServerProtectedTokenAdditionalAnnotationsobject{}Auth server protected token ingress resource additional annotations.
global.auth-server.ingress.authServerProtectedTokenLabelsobject{}Auth server protected token ingress resource labels. key app is taken
global.auth-server.ingress.authzenAdditionalAnnotationsobject{}authzen config ingress resource additional annotations.
global.auth-server.ingress.authzenConfigEnabledbooltrueEnable endpoint /.well-known/authzen-configuration
global.auth-server.ingress.authzenConfigLabelsobject{}authzen config ingress resource labels. key app is taken
global.auth-server.ingress.deviceCodeAdditionalAnnotationsobject{}device-code ingress resource additional annotations.
global.auth-server.ingress.deviceCodeEnabledbooltrueEnable endpoint /device-code
global.auth-server.ingress.deviceCodeLabelsobject{}device-code ingress resource labels. key app is taken
global.auth-server.ingress.firebaseMessagingAdditionalAnnotationsobject{}Firebase Messaging ingress resource additional annotations.
global.auth-server.ingress.firebaseMessagingEnabledbooltrueEnable endpoint /firebase-messaging-sw.js
global.auth-server.ingress.firebaseMessagingLabelsobject{}Firebase Messaging ingress resource labels. key app is taken
global.auth-server.ingress.lockAdditionalAnnotationsobject{}Lock ingress resource additional annotations.
global.auth-server.ingress.lockAuditEnabledboolfalseEnable gRPC endpoint /io.jans.lock.audit.AuditService (if enabled, global.auth-server.lockEnabled must be enabled)
global.auth-server.ingress.lockConfigAdditionalAnnotationsobject{}Lock config ingress resource additional annotations.
global.auth-server.ingress.lockConfigEnabledboolfalseEnable endpoint /.well-known/lock-server-configuration (if enabled, global.auth-server.lockEnabled must be enabled)
global.auth-server.ingress.lockConfigLabelsobject{}Lock config ingress resource labels. key app is taken
global.auth-server.ingress.lockLabelsobject{}Lock ingress resource labels. key app is taken
global.auth-server.ingress.openidAdditionalAnnotationsobject{}openid-configuration ingress resource additional annotations.
global.auth-server.ingress.openidConfigEnabledbooltrueEnable endpoint /.well-known/openid-configuration
global.auth-server.ingress.openidConfigLabelsobject{}openid-configuration ingress resource labels. key app is taken
global.auth-server.ingress.uma2AdditionalAnnotationsobject{}uma2 config ingress resource additional annotations.
global.auth-server.ingress.uma2ConfigEnabledbooltrueEnable endpoint /.well-known/uma2-configuration
global.auth-server.ingress.uma2ConfigLabelsobject{}uma2 config ingress resource labels. key app is taken
global.auth-server.ingress.webfingerAdditionalAnnotationsobject{}webfinger ingress resource additional annotations.
global.auth-server.ingress.webfingerEnabledbooltrueEnable endpoint /.well-known/webfinger
global.auth-server.ingress.webfingerLabelsobject{}webfinger ingress resource labels. key app is taken
global.auth-server.lockEnabledboolfalseEnable jans-lock as service running inside auth-server
global.awsStorageTypestring"io1"Volume storage type if using AWS volumes.
global.azureStorageAccountTypestring"Standard_LRS"Volume storage type if using Azure disks.
global.azureStorageKindstring"Managed"Azure storage kind if using Azure disks
global.casa.adminEnabledbooltrueBoolean flag to enable/disable the casa admin console.
global.casa.appLoggersobject{"casaLogLevel":"INFO","casaLogTarget":"STDOUT","enableStdoutLogPrefix":"true","rootLogLevel":"INFO","rootLogTarget":"STDOUT","timerLogLevel":"INFO","timerLogTarget":"FILE"}App loggers can be configured to define where the logs will be redirected to and the level of each in which it should be displayed.
global.casa.appLoggers.casaLogLevelstring"INFO"casa.log level
global.casa.appLoggers.casaLogTargetstring"STDOUT"casa.log target
global.casa.appLoggers.enableStdoutLogPrefixstring"true"Enable log prefixing which enables prepending the STDOUT logs with the file name. i.e casa ===> 2022-12-20 17:49:55,744 INFO
global.casa.appLoggers.rootLogLevelstring"INFO"root log level
global.casa.appLoggers.rootLogTargetstring"STDOUT"root log target (if set to FILE, logs will be redirected to casa.log)
global.casa.appLoggers.timerLogLevelstring"INFO"casa timer log level
global.casa.appLoggers.timerLogTargetstring"FILE"casa timer log target
global.casa.casaServiceNamestring"casa"Name of the casa service. Please keep it as default.
global.casa.cnCustomJavaOptionsstring""passing custom java options to casa. Notice you do not need to pass in any loggers options as they are introduced below in appLoggers. DO NOT PASS JAVA_OPTIONS in envs.
global.casa.enabledbooltrueBoolean flag to enable/disable the casa chart.
global.casa.ingressobject{"casaAdditionalAnnotations":{},"casaEnabled":false,"casaLabels":{}}Enable endpoints in either istio or nginx ingress depending on users choice
global.casa.ingress.casaAdditionalAnnotationsobject{}Casa ingress resource additional annotations.
global.casa.ingress.casaEnabledboolfalseEnable casa endpoints /jans-casa
global.casa.ingress.casaLabelsobject{}Casa ingress resource labels. key app is taken
global.cleanupobject{"enabled":true}Enable cleanup job
global.cleanup.enabledbooltrueBoolean flag to enable/disable the cleanup cronjob chart.
global.cloud.testEnviromentboolfalseBoolean flag if enabled will strip resources requests and limits from all services.
global.cnConfiguratorConfigurationFilestring"/etc/jans/conf/configuration.json"Path to configuration schema file
global.cnConfiguratorCustomSchemaobject{"secretName":""}Use custom configuration schema in existing secrets. Note, the secrets has to contain the key configuration.json or any basename as specified in cnConfiguratorConfigurationFile.
global.cnConfiguratorCustomSchema.secretNamestring""The name of the secrets used for storing custom configuration schema.
global.cnConfiguratorDumpFilestring"/etc/jans/conf/configuration.out.json"Path to dumped configuration schema file
global.cnConfiguratorKeystring""Key to encrypt/decrypt configuration schema file using AES-256 CBC mode. Set the value to empty string to disable encryption/decryption, or 32 alphanumeric characters to enable it.
global.cnConfiguratorKeyFilestring"/etc/jans/conf/configuration.key"Path to the file that contains the key to encrypt/decrypt the configuration schema file.
global.cnDocumentStoreTypestring"DB"Document store type to use for shibboleth files DB.
global.cnGoogleApplicationCredentialsstring"/etc/jans/conf/google-credentials.json"Base64 encoded service account. The sa must have roles/secretmanager.admin to use Google secrets. Leave as this is a sensible default.
global.cnObExtSigningJwksCrtstring""Open banking external signing jwks AS certificate authority string. Used in SSA Validation. This must be encoded using base64. Used when .global.cnObExtSigningJwksUri is set.
global.cnObExtSigningJwksKeystring""Open banking external signing jwks AS key string. Used in SSA Validation. This must be encoded using base64. Used when .global.cnObExtSigningJwksUri is set.
global.cnObExtSigningJwksKeyPassPhrasestring""Open banking external signing jwks AS key passphrase to unlock provided key. This must be encoded using base64. Used when .global.cnObExtSigningJwksUri is set.
global.cnObExtSigningJwksUristring"https://mykeystore.openbanking.wow/xxxxx/xxxxx.jwks"Open banking external signing jwks uri. Used in SSA Validation.
global.cnObInternalSigningAliasstring"XkwIzWy44xWSlcWnMiEc8iq9s2G"Internal Java Keystore (JKS) alias used to locate the Open Banking private signing key. To ensure correct internal mapping, this string must identically match your 'cnObStaticSigningKeyKid'.
global.cnObStaticSigningKeyKidstring"XkwIzWy44xWSlcWnMiEc8iq9s2G"External Key ID (kid) stamped onto the header of outgoing JWTs. This tells receiving parties which public key to fetch from your JWKS URI to verify the signature.
global.cnObTransportAliasstring""Open banking transport Alias used inside the JVM.
global.cnObTransportCrtstring""Open banking AS transport crt. Used in SSA Validation. This must be encoded using base64.
global.cnObTransportKeystring""Open banking AS transport key. Used in SSA Validation. This must be encoded using base64.
global.cnObTransportKeyPassPhrasestring""Open banking AS transport key passphrase to unlock AS transport key. This must be encoded using base64.
global.cnObTransportTrustStorestring""Open banking AS transport truststore crt. This is normally generated from the OB issuing CA, OB Root CA and Signing CA. Used when .global.cnObExtSigningJwksUri is set. Used in SSA Validation. This must be encoded using base64.
global.cnPersistenceTypestring"sql"Persistence backend to run Gluu with hybrid
global.cnPrometheusPortstring""Port used by Prometheus JMX agent (default to empty string). To enable Prometheus JMX agent, set the value to a number.
global.cnSqlPasswordFilestring"/etc/jans/conf/sql_password"Path to SQL password file
global.config-api.adminUiAppLoggers.adminUiAuditLogLevelstring"INFO"config-api admin-ui plugin audit log level
global.config-api.adminUiAppLoggers.adminUiAuditLogTargetstring"FILE"config-api admin-ui plugin audit log target
global.config-api.adminUiAppLoggers.adminUiLogLevelstring"INFO"config-api admin-ui plugin log target
global.config-api.adminUiAppLoggers.adminUiLogTargetstring"FILE"config-api admin-ui plugin log level
global.config-api.adminUiAppLoggers.enableStdoutLogPrefixstring"true"Enable log prefixing which enables prepending the STDOUT logs with the file name. i.e config-api_persistence ===> 2022-12-20 17:49:55,744 INFO
global.config-api.appLoggersobject{"configApiLogLevel":"INFO","configApiLogTarget":"STDOUT","enableStdoutLogPrefix":"true","persistenceDurationLogLevel":"INFO","persistenceDurationLogTarget":"FILE","persistenceLogLevel":"INFO","persistenceLogTarget":"FILE","rootLogLevel":"INFO","rootLogTarget":"STDOUT","scriptLogLevel":"INFO","scriptLogTarget":"FILE"}App loggers can be configured to define where the logs will be redirected to and the level of each in which it should be displayed.
global.config-api.appLoggers.configApiLogLevelstring"INFO"configapi.log level
global.config-api.appLoggers.configApiLogTargetstring"STDOUT"configapi.log target
global.config-api.appLoggers.enableStdoutLogPrefixstring"true"Enable log prefixing which enables prepending the STDOUT logs with the file name. i.e config-api_persistence ===> 2022-12-20 17:49:55,744 INFO
global.config-api.appLoggers.persistenceDurationLogLevelstring"INFO"configapi_persistence_duration.log level
global.config-api.appLoggers.persistenceDurationLogTargetstring"FILE"configapi_persistence_duration.log target
global.config-api.appLoggers.persistenceLogLevelstring"INFO"configapi_persistence.log level
global.config-api.appLoggers.persistenceLogTargetstring"FILE"configapi_persistence.log target
global.config-api.appLoggers.rootLogLevelstring"INFO"root log level
global.config-api.appLoggers.rootLogTargetstring"STDOUT"root log target (if set to FILE, logs will be redirected to configapi.log)
global.config-api.appLoggers.scriptLogLevelstring"INFO"configapi_script.log level
global.config-api.appLoggers.scriptLogTargetstring"FILE"configapi_script.log target
global.config-api.cnCustomJavaOptionsstring""passing custom java options to config-api. Notice you do not need to pass in any loggers options as they are introduced below in appLoggers. DO NOT PASS JAVA_OPTIONS in envs.
global.config-api.configApiServerServiceNamestring"config-api"Name of the config-api service. Please keep it as default.
global.config-api.enabledbooltrueBoolean flag to enable/disable the config-api chart.
global.config-api.ingressobject{"configApiAdditionalAnnotations":{},"configApiEnabled":true,"configApiLabels":{}}Enable endpoints in either istio or nginx ingress depending on users choice
global.config-api.ingress.configApiAdditionalAnnotationsobject{}ConfigAPI ingress resource additional annotations.
global.config-api.ingress.configApiLabelsobject{}configAPI ingress resource labels. key app is taken
global.config-api.pluginsstring"admin-ui,fido2,scim,user-mgt"Comma-separated values of enabled plugins (supported plugins are "admin-ui","fido2","scim","user-mgt")
global.config.enabledbooltrueBoolean flag to enable/disable the configuration chart. This normally should never be false
global.configAdapterNamestring"kubernetes"The config backend adapter that will hold Gluu configuration layer. aws
global.configSecretAdapterstring"kubernetes"The config backend adapter that will hold Gluu secret layer. vault
global.distributionstring"default"Gluu distributions supported are: default
global.fido2.appLoggersobject{"enableStdoutLogPrefix":"true","fido2LogLevel":"INFO","fido2LogTarget":"STDOUT","persistenceDurationLogLevel":"INFO","persistenceDurationLogTarget":"FILE","persistenceLogLevel":"INFO","persistenceLogTarget":"FILE","rootLogLevel":"INFO","rootLogTarget":"STDOUT","scriptLogLevel":"INFO","scriptLogTarget":"FILE"}App loggers can be configured to define where the logs will be redirected to and the level of each in which it should be displayed.
global.fido2.appLoggers.enableStdoutLogPrefixstring"true"Enable log prefixing which enables prepending the STDOUT logs with the file name. i.e fido2 ===> 2022-12-20 17:49:55,744 INFO
global.fido2.appLoggers.fido2LogLevelstring"INFO"fido2.log level
global.fido2.appLoggers.fido2LogTargetstring"STDOUT"fido2.log target
global.fido2.appLoggers.persistenceDurationLogLevelstring"INFO"fido2_persistence_duration.log level
global.fido2.appLoggers.persistenceDurationLogTargetstring"FILE"fido2_persistence_duration.log target
global.fido2.appLoggers.persistenceLogLevelstring"INFO"fido2_persistence.log level
global.fido2.appLoggers.persistenceLogTargetstring"FILE"fido2_persistence.log target
global.fido2.appLoggers.rootLogLevelstring"INFO"root log level
global.fido2.appLoggers.rootLogTargetstring"STDOUT"root log target (if set to FILE, logs will be redirected to fido2.log)
global.fido2.appLoggers.scriptLogLevelstring"INFO"fido2_script.log level
global.fido2.appLoggers.scriptLogTargetstring"FILE"fido2_script.log target
global.fido2.cnCustomJavaOptionsstring""passing custom java options to fido2. Notice you do not need to pass in any loggers options as they are introduced below in appLoggers. DO NOT PASS JAVA_OPTIONS in envs.
global.fido2.enabledbooltrueBoolean flag to enable/disable the fido2 chart.
global.fido2.fido2ServiceNamestring"fido2"Name of the fido2 service. Please keep it as default.
global.fido2.ingressobject{"fido2AdditionalAnnotations":{},"fido2ConfigAdditionalAnnotations":{},"fido2ConfigEnabled":false,"fido2ConfigLabels":{},"fido2Enabled":false,"fido2Labels":{},"fido2WebauthnAdditionalAnnotations":{},"fido2WebauthnEnabled":false,"fido2WebauthnLabels":{}}Enable endpoints in either istio or nginx ingress depending on users choice
global.fido2.ingress.fido2AdditionalAnnotationsobject{}fido2 ingress resource additional annotations.
global.fido2.ingress.fido2ConfigAdditionalAnnotationsobject{}fido2 config ingress resource additional annotations.
global.fido2.ingress.fido2ConfigEnabledboolfalseEnable endpoint /.well-known/fido2-configuration
global.fido2.ingress.fido2ConfigLabelsobject{}fido2 config ingress resource labels. key app is taken
global.fido2.ingress.fido2EnabledboolfalseEnable endpoint /jans-fido2
global.fido2.ingress.fido2Labelsobject{}fido2 ingress resource labels. key app is taken
global.fido2.ingress.fido2WebauthnAdditionalAnnotationsobject{}fido2 webauthn ingress resource additional annotations.
global.fido2.ingress.fido2WebauthnEnabledboolfalseEnable endpoint /.well-known/webauthn
global.fido2.ingress.fido2WebauthnLabelsobject{}fido2 webauthn ingress resource labels. key app is taken
global.fqdnstring"demoexample.gluu.org"Fully qualified domain name to be used for Gluu installation. This address will be used to reach Gluu services.
global.gateway-api.enabledboolfalseBoolean flag to enable/disable the Kubernetes Gateway and HTTPRoute resources.
global.gcePdStorageTypestring"pd-standard"GCE storage kind if using Google disks
global.isFqdnRegisteredboolfalseBoolean flag to enable mapping global.lbIp to global.fqdn inside pods on clouds that provide static ip for load balancers. On cloud that provide only addresses to the LB this flag will enable a script to actively scan config.configmap.lbAddr and update the hosts file inside the pods automatically.
global.istio.additionalAnnotationsobject{}Additional annotations that will be added across the gateway in the format of {cert-manager.io/issuer: "letsencrypt-prod"}
global.istio.additionalLabelsobject{}Additional labels that will be added across the gateway in the format of {mylabel: "myapp"}
global.istio.enabledboolfalseBoolean flag that enables using istio side-cars with Gluu services.
global.istio.gatewayslist[]Override the gateway that can be created by default. This is used when istio ingress has already been setup and the gateway exists.
global.istio.ingressboolfalseBoolean flag that enables using istio gateway for Gluu. This assumes istio ingress is installed and hence the LB is available.
global.istio.namespacestring"istio-system"The namespace istio is deployed in. The is normally istio-system.
global.jobTtlSecondsAfterFinishedint300https://kubernetes.io/docs/concepts/workloads/controllers/ttlafterfinished/
global.lbIpstring"22.22.22.22"The Loadbalancer IP created by nginx or istio on clouds that provide static IPs. This is not needed if global.fqdn is globally resolvable.
global.nginx-ingress.enabledbooltrueBoolean flag to enable/disable the nginx-ingress definitions chart.
global.persistence.enabledbooltrueBoolean flag to enable/disable the persistence chart.
global.scim.appLoggersobject{"enableStdoutLogPrefix":"true","persistenceDurationLogLevel":"INFO","persistenceDurationLogTarget":"FILE","persistenceLogLevel":"INFO","persistenceLogTarget":"FILE","rootLogLevel":"INFO","rootLogTarget":"STDOUT","scimLogLevel":"INFO","scimLogTarget":"STDOUT","scriptLogLevel":"INFO","scriptLogTarget":"FILE"}App loggers can be configured to define where the logs will be redirected to and the level of each in which it should be displayed.
global.scim.appLoggers.enableStdoutLogPrefixstring"true"Enable log prefixing which enables prepending the STDOUT logs with the file name. i.e jans-scim ===> 2022-12-20 17:49:55,744 INFO
global.scim.appLoggers.persistenceDurationLogLevelstring"INFO"scim_persistence_duration.log level
global.scim.appLoggers.persistenceDurationLogTargetstring"FILE"scim_persistence_duration.log target
global.scim.appLoggers.persistenceLogLevelstring"INFO"scim_persistence.log level
global.scim.appLoggers.persistenceLogTargetstring"FILE"scim_persistence.log target
global.scim.appLoggers.rootLogLevelstring"INFO"root log level
global.scim.appLoggers.rootLogTargetstring"STDOUT"root log target (if set to FILE, logs will be redirected to scim.log)
global.scim.appLoggers.scimLogLevelstring"INFO"scim.log level
global.scim.appLoggers.scimLogTargetstring"STDOUT"scim.log target
global.scim.appLoggers.scriptLogLevelstring"INFO"scim_script.log level
global.scim.appLoggers.scriptLogTargetstring"FILE"scim_script.log target
global.scim.cnCustomJavaOptionsstring""passing custom java options to scim. Notice you do not need to pass in any loggers options as they are introduced below in appLoggers. DO NOT PASS JAVA_OPTIONS in envs.
global.scim.enabledbooltrueBoolean flag to enable/disable the SCIM chart.
global.scim.ingressobject{"scimAdditionalAnnotations":{},"scimConfigAdditionalAnnotations":{},"scimConfigEnabled":false,"scimConfigLabels":{},"scimEnabled":false,"scimLabels":{}}Enable endpoints in either istio or nginx ingress depending on users choice
global.scim.ingress.scimAdditionalAnnotationsobject{}SCIM ingress resource additional annotations.
global.scim.ingress.scimConfigAdditionalAnnotationsobject{}SCIM config ingress resource additional annotations.
global.scim.ingress.scimConfigEnabledboolfalseEnable endpoint /.well-known/scim-configuration
global.scim.ingress.scimConfigLabelsobject{}SCIM config ingress resource labels. key app is taken
global.scim.ingress.scimEnabledboolfalseEnable SCIM endpoints /jans-scim
global.scim.ingress.scimLabelsobject{}SCIM ingress resource labels. key app is taken
global.scim.scimServiceNamestring"scim"Name of the scim service. Please keep it as default.
global.serviceAccountNamestring"default"service account used by Kubernetes resources
global.storageClassobject{"allowVolumeExpansion":true,"allowedTopologies":[],"mountOptions":["debug"],"parameters":{},"provisioner":"microk8s.io/hostpath","reclaimPolicy":"Retain","volumeBindingMode":"WaitForFirstConsumer"}StorageClass section. This is not currently used by the openbanking distribution. You may specify custom parameters as needed.
global.storageClass.parametersobject{}parameters: fsType: "" kind: "" pool: "" storageAccountType: "" type: ""
global.usrEnvsobject{"normal":{},"secret":{}}Add custom normal and secret envs to the service. Envs defined in global.userEnvs will be globally available to all services
global.usrEnvs.normalobject{}Add custom normal envs to the service. variable1: value1
global.usrEnvs.secretobject{}Add custom secret envs to the service. variable1: value1
installer-settingsobject{"acceptLicense":"","aws":{"arn":{"arnAcmCert":"","enabled":""},"lbType":"","vpcCidr":"0.0.0.0/0"},"confirmSettings":false,"currentVersion":"","google":{"useSecretManager":""},"images":{"edit":""},"namespace":"","nginxIngress":{"namespace":"","releaseName":""},"nodes":{"ips":"","names":"","zones":""},"openbanking":{"cnObTransportTrustStoreP12password":"","hasCnObTransportTrustStore":false},"postgres":{"install":"","namespace":""},"redis":{"install":"","namespace":""},"releaseName":"","sql":{"install":"","namespace":""},"volumeProvisionStrategy":""}Only used by the installer. These settings do not affect nor are used by the chart
nginx-ingressobject{"certManager":{"certificate":{"enabled":false,"issuerGroup":"cert-manager.io","issuerKind":"ClusterIssuer","issuerName":""}},"ingress":{"additionalAnnotations":{},"additionalLabels":{},"hosts":["demoexample.gluu.org"],"ingressClassName":"nginx","path":"/","tls":[{"hosts":["demoexample.gluu.org"],"secretName":"tls-certificate"}]}}Nginx ingress definitions chart
nginx-ingress.ingress.additionalAnnotationsobject{}Additional annotations that will be added across all ingress definitions in the format of {cert-manager.io/issuer: "letsencrypt-prod"} Enable client certificate authentication nginx.ingress.kubernetes.io/auth-tls-verify-client: "optional" Create the secret containing the trusted ca certificates nginx.ingress.kubernetes.io/auth-tls-secret: "gluu/tls-certificate" Specify the verification depth in the client certificates chain nginx.ingress.kubernetes.io/auth-tls-verify-depth: "1" Specify if certificates are passed to upstream server nginx.ingress.kubernetes.io/auth-tls-pass-certificate-to-upstream: "true"
nginx-ingress.ingress.additionalLabelsobject{}Additional labels that will be added across all ingress definitions in the format of {mylabel: "myapp"}
nginx-ingress.ingress.tlslist[{"hosts":["demoexample.gluu.org"],"secretName":"tls-certificate"}]Secrets holding HTTPS CA cert and key.
persistenceobject{"additionalAnnotations":{},"additionalLabels":{},"customCommand":[],"customScripts":[],"dnsConfig":{},"dnsPolicy":"","image":{"pullPolicy":"IfNotPresent","pullSecrets":[],"repository":"ghcr.io/gluufederation/flex/persistence-loader","tag":"6.3.0"},"lifecycle":{},"nodeSelector":{},"resources":{"limits":{"cpu":"300m","memory":"300Mi"},"requests":{"cpu":"300m","memory":"300Mi"}},"tolerations":[],"usrEnvs":{"normal":{},"secret":{}},"volumeMounts":[],"volumes":[]}Job to generate data and initial config for Gluu Server persistence layer.
persistence.additionalAnnotationsobject{}Additional annotations that will be added across the gateway in the format of {cert-manager.io/issuer: "letsencrypt-prod"}
persistence.additionalLabelsobject{}Additional labels that will be added across the gateway in the format of {mylabel: "myapp"}
persistence.customCommandlist[]Add custom job's command. If passed, it will override the default conditional command.
persistence.customScriptslist[]Add custom scripts that have been mounted to run before the entrypoint. - /tmp/custom.sh - /tmp/custom2.sh
persistence.dnsConfigobject{}Add custom dns config
persistence.dnsPolicystring""Add custom dns policy
persistence.image.pullPolicystring"IfNotPresent"Image pullPolicy to use for deploying.
persistence.image.pullSecretslist[]Image Pull Secrets
persistence.image.repositorystring"ghcr.io/gluufederation/flex/persistence-loader"Image to use for deploying.
persistence.image.tagstring"6.3.0"Image tag to use for deploying.
persistence.nodeSelectorobject{}Add nodeSelector (see https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#nodeselector)
persistence.resourcesobject{"limits":{"cpu":"300m","memory":"300Mi"},"requests":{"cpu":"300m","memory":"300Mi"}}Resource specs.
persistence.resources.limits.cpustring"300m"CPU limit
persistence.resources.limits.memorystring"300Mi"Memory limit.
persistence.resources.requests.cpustring"300m"CPU request.
persistence.resources.requests.memorystring"300Mi"Memory request.
persistence.tolerationslist[]Add tolerations for the pods
persistence.usrEnvsobject{"normal":{},"secret":{}}Add custom normal and secret envs to the service
persistence.usrEnvs.normalobject{}Add custom normal envs to the service variable1: value1
persistence.usrEnvs.secretobject{}Add custom secret envs to the service variable1: value1
persistence.volumeMountslist[]Configure any additional volumesMounts that need to be attached to the containers
persistence.volumeslist[]Configure any additional volumes that need to be attached to the pod
scimobject{"additionalAnnotations":{},"additionalLabels":{},"customCommand":[],"customScripts":[],"dnsConfig":{},"dnsPolicy":"","hpa":{"behavior":{},"enabled":true,"maxReplicas":10,"metrics":[],"minReplicas":1,"targetCPUUtilizationPercentage":50},"image":{"pullPolicy":"IfNotPresent","pullSecrets":[],"repository":"ghcr.io/janssenproject/jans/scim","tag":"6.3.0"},"lifecycle":{},"livenessProbe":{"httpGet":{"path":"/jans-scim/sys/health-check","port":8080},"initialDelaySeconds":30,"periodSeconds":30,"timeoutSeconds":5},"nodeSelector":{},"pdb":{"enabled":true,"maxUnavailable":"90%"},"readinessProbe":{"httpGet":{"path":"/jans-scim/sys/health-check","port":8080},"initialDelaySeconds":25,"periodSeconds":25,"timeoutSeconds":5},"replicas":1,"resources":{"limits":{"cpu":"1000m","memory":"1200Mi"},"requests":{"cpu":"1000m","memory":"1200Mi"}},"service":{"name":"http-scim","port":8080},"tolerations":[],"topologySpreadConstraints":{},"usrEnvs":{"normal":{},"secret":{}},"volumeMounts":[],"volumes":[]}System for Cross-domain Identity Management (SCIM) version 2.0
scim.additionalAnnotationsobject{}Additional annotations that will be added across the gateway in the format of {cert-manager.io/issuer: "letsencrypt-prod"}
scim.additionalLabelsobject{}Additional labels that will be added across the gateway in the format of {mylabel: "myapp"}
scim.customCommandlist[]Add custom pod's command. If passed, it will override the default conditional command.
scim.customScriptslist[]Add custom scripts that have been mounted to run before the entrypoint. - /tmp/custom.sh - /tmp/custom2.sh
scim.dnsConfigobject{}Add custom dns config
scim.dnsPolicystring""Add custom dns policy
scim.hpaobject{"behavior":{},"enabled":true,"maxReplicas":10,"metrics":[],"minReplicas":1,"targetCPUUtilizationPercentage":50}Configure the HorizontalPodAutoscaler
scim.hpa.behaviorobject{}Scaling Policies
scim.hpa.metricslist[]metrics if targetCPUUtilizationPercentage is not set
scim.image.pullPolicystring"IfNotPresent"Image pullPolicy to use for deploying.
scim.image.pullSecretslist[]Image Pull Secrets
scim.image.repositorystring"ghcr.io/janssenproject/jans/scim"Image to use for deploying.
scim.image.tagstring"6.3.0"Image tag to use for deploying.
scim.livenessProbeobject{"httpGet":{"path":"/jans-scim/sys/health-check","port":8080},"initialDelaySeconds":30,"periodSeconds":30,"timeoutSeconds":5}Configure the liveness healthcheck for SCIM if needed.
scim.livenessProbe.httpGet.pathstring"/jans-scim/sys/health-check"http liveness probe endpoint
scim.nodeSelectorobject{}Add nodeSelector (see https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#nodeselector)
scim.pdbobject{"enabled":true,"maxUnavailable":"90%"}Configure the PodDisruptionBudget
scim.readinessProbeobject{"httpGet":{"path":"/jans-scim/sys/health-check","port":8080},"initialDelaySeconds":25,"periodSeconds":25,"timeoutSeconds":5}Configure the readiness healthcheck for the SCIM if needed.
scim.readinessProbe.httpGet.pathstring"/jans-scim/sys/health-check"http readiness probe endpoint
scim.replicasint1Service replica number.
scim.resources.limits.cpustring"1000m"CPU limit.
scim.resources.limits.memorystring"1200Mi"Memory limit. This value is used to calculate memory allocation for Java. Currently it only supports Mi. Please refrain from using other units.
scim.resources.requests.cpustring"1000m"CPU request.
scim.resources.requests.memorystring"1200Mi"Memory request.
scim.service.namestring"http-scim"The name of the scim port within the scim service. Please keep it as default.
scim.service.portint8080Port of the scim service. Please keep it as default.
scim.tolerationslist[]Add tolerations for the pods
scim.topologySpreadConstraintsobject{}Configure the topology spread constraints. Notice this is a map NOT a list as in the upstream API https://kubernetes.io/docs/concepts/scheduling-eviction/topology-spread-constraints/
scim.usrEnvsobject{"normal":{},"secret":{}}Add custom normal and secret envs to the service
scim.usrEnvs.normalobject{}Add custom normal envs to the service variable1: value1
scim.usrEnvs.secretobject{}Add custom secret envs to the service variable1: value1
scim.volumeMountslist[]Configure any additional volumesMounts that need to be attached to the containers
scim.volumeslist[]Configure any additional volumes that need to be attached to the pod

We use analytics cookies to measure which pages are useful, so we can improve them. They are only set if you accept. Essential cookies needed for the site to work are always on. See our privacy policy.