Skip to content
Browse Gluu Flex 6.4.0

Helm values reference

Read from each chart’s own values.yaml at 6.4.0, so every key is listed — including the ones the generated chart README leaves out.

460 options

additionalAnnotations (1)
KeyTypeDefaultDescription
additionalAnnotationsobject{}Additional annotations that will be added across the gateway in the format of {cert-manager.io/issuer: "letsencrypt-prod"}
additionalLabels (1)
KeyTypeDefaultDescription
additionalLabelsobject{}Additional labels that will be added across the gateway in the format of {mylabel: "myapp"}
admin-ui (8)
KeyTypeDefaultDescription
admin-uiobject—Admin GUI for configuration of the auth-server
admin-ui.enabledbooltrueBoolean flag to enable/disable the admin-ui chart and admin ui config api plugin.
admin-ui.gatewayNamestring""Override Gateway name for Gateway API (defaults to gateway-api.gateway.name). The target Gateway must expose listeners named after gateway-api.gateway.httpSectionName and httpsSectionName.
admin-ui.gatewayNamespacestring""Override Gateway namespace for Gateway API (defaults to gateway-api.gateway.gatewayNamespace or release namespace). That Gateway's listeners must allow routes from this release's namespace via spec.listeners[].allowedRoutes.namespaces.
admin-ui.ingressobject—No description upstream
admin-ui.ingress.adminUiAdditionalAnnotationsobject{}Admin UI ingress resource additional annotations.
admin-ui.ingress.adminUiEnabledbooltrueEnable Admin UI endpoints in either istio or nginx ingress depending on users choice
admin-ui.ingress.adminUiLabelsobject{}Admin UI ingress resource labels. key app is taken.
adminPassword (1)
KeyTypeDefaultDescription
adminPasswordstring"Test1234#"Admin password to log in to the UI.
auth-server (60)
KeyTypeDefaultDescription
auth-serverobject—Parameters used globally across all services helm charts.
auth-server.appLoggersobject—App loggers can be configured to define where the logs will be redirected to and the level of each in which it should be displayed.
auth-server.appLoggers.auditStatsLogLevelstring"INFO"jans-auth_audit.log level
auth-server.appLoggers.auditStatsLogTargetstring"FILE"jans-auth_audit.log target
auth-server.appLoggers.authLogLevelstring"INFO"jans-auth.log level
auth-server.appLoggers.authLogTargetstring"STDOUT"jans-auth.log target
auth-server.appLoggers.enableStdoutLogPrefixstring"true"Enable log prefixing which enables prepending the STDOUT logs with the file name. i.e auth-server-script ===> 2022-12-20 17:49:55,744 INFO
auth-server.appLoggers.httpLogLevelstring"INFO"http_request_response.log level
auth-server.appLoggers.httpLogTargetstring"FILE"http_request_response.log target
auth-server.appLoggers.lockLogLevelstring"INFO"jans-lock.log level
auth-server.appLoggers.lockLogTargetstring"STDOUT"jans-lock.log target
auth-server.appLoggers.persistenceDurationLogLevelstring"INFO"jans-auth_persistence_duration.log level
auth-server.appLoggers.persistenceDurationLogTargetstring"FILE"jans-auth_persistence_duration.log target
auth-server.appLoggers.persistenceLogLevelstring"INFO"jans-auth_persistence.log level
auth-server.appLoggers.persistenceLogTargetstring"FILE"jans-auth_persistence.log target
auth-server.appLoggers.rootLogLevelstring"INFO"root log level
auth-server.appLoggers.rootLogTargetstring"STDOUT"root log target (if set to FILE, logs will be redirected to jans-auth.log)
auth-server.appLoggers.scriptLogLevelstring"INFO"jans-auth_script.log level
auth-server.appLoggers.scriptLogTargetstring"FILE"jans-auth_script.log target
auth-server.authEncKeysstring"RSA1_5 RSA-OAEP"space-separated key algorithm for encryption (default to `RSA1_5 RSA-OAEP`)
auth-server.authSigKeysstring"RS256 RS384 RS512 ES256 ES384 ES512 PS256 PS384 PS512"space-separated key algorithm for signing (default to `RS256 RS384 RS512 ES256 ES384 ES512 PS256 PS384 PS512`)
auth-server.cnCustomJavaOptionsstring""passing custom java options to auth-server. Notice you do not need to pass in any loggers options as they are introduced below in appLoggers. DO NOT PASS JAVA_OPTIONS in envs.
auth-server.enabledbooltrueBoolean flag to enable/disable auth-server chart. You should never set this to false.
auth-server.gatewayNamestring""Enable endpoints in either istio or nginx ingress depending on users choice -- Override Gateway name for Gateway API (defaults to gateway-api.gateway.name). The target Gateway must expose listeners named after gateway-api.gateway.httpSectionName and httpsSectionName.
auth-server.gatewayNamespacestring""Override Gateway namespace for Gateway API (defaults to gateway-api.gateway.gatewayNamespace or release namespace). That Gateway's listeners must allow routes from this release's namespace via spec.listeners[].allowedRoutes.namespaces.
auth-server.ingressobject—No description upstream
auth-server.ingress.authServerAdditionalAnnotationsobject{}Auth server ingress resource additional annotations.
auth-server.ingress.authServerEnabledbooltrueEnable Auth server endpoints /jans-auth
auth-server.ingress.authServerLabelsobject{}Auth server ingress resource labels. key app is taken
auth-server.ingress.authServerProtectedRegisterboolfalseEnable mTLS on Auth server endpoint /jans-auth/restv1/register.
auth-server.ingress.authServerProtectedRegisterAdditionalAnnotationsobject{}Auth server protected register ingress resource additional annotations.
auth-server.ingress.authServerProtectedRegisterLabelsobject{}Auth server protected token ingress resource labels. key app is taken
auth-server.ingress.authServerProtectedTokenboolfalseEnable mTLS on Auth server endpoint /jans-auth/restv1/token.
auth-server.ingress.authServerProtectedTokenAdditionalAnnotationsobject{}Auth server protected token ingress resource additional annotations.
auth-server.ingress.authServerProtectedTokenLabelsobject{}Auth server protected token ingress resource labels. key app is taken
auth-server.ingress.authzenAdditionalAnnotationsobject{}authzen config ingress resource additional annotations.
auth-server.ingress.authzenConfigEnabledbooltrueEnable endpoint /.well-known/authzen-configuration
auth-server.ingress.authzenConfigLabelsobject{}authzen config ingress resource labels. key app is taken
auth-server.ingress.deviceCodeAdditionalAnnotationsobject{}device-code ingress resource additional annotations.
auth-server.ingress.deviceCodeEnabledbooltrueEnable endpoint /device-code
auth-server.ingress.deviceCodeLabelsobject{}device-code ingress resource labels. key app is taken
auth-server.ingress.firebaseMessagingAdditionalAnnotationsobject{}Firebase Messaging ingress resource additional annotations.
auth-server.ingress.firebaseMessagingEnabledbooltrueEnable endpoint /firebase-messaging-sw.js
auth-server.ingress.firebaseMessagingLabelsobject{}Firebase Messaging ingress resource labels. key app is taken
auth-server.ingress.lockAdditionalAnnotationsobject{}Lock ingress resource additional annotations.
auth-server.ingress.lockAuditEnabledboolfalseEnable gRPC endpoint /io.jans.lock.audit.AuditService (if enabled, auth-server.lockEnabled must be enabled)
auth-server.ingress.lockConfigAdditionalAnnotationsobject{}Lock config ingress resource additional annotations.
auth-server.ingress.lockConfigEnabledboolfalseEnable endpoint /.well-known/lock-server-configuration (if enabled, auth-server.lockEnabled must be enabled)
auth-server.ingress.lockConfigLabelsobject{}Lock config ingress resource labels. key app is taken
auth-server.ingress.lockLabelsobject{}Lock ingress resource labels. key app is taken
auth-server.ingress.openidAdditionalAnnotationsobject{}openid-configuration ingress resource additional annotations.
auth-server.ingress.openidConfigEnabledbooltrueEnable endpoint /.well-known/openid-configuration
auth-server.ingress.openidConfigLabelsobject{}openid-configuration ingress resource labels. key app is taken
auth-server.ingress.uma2AdditionalAnnotationsobject{}uma2 config ingress resource additional annotations.
auth-server.ingress.uma2ConfigEnabledbooltrueEnable endpoint /.well-known/uma2-configuration
auth-server.ingress.uma2ConfigLabelsobject{}uma2 config ingress resource labels. key app is taken
auth-server.ingress.webfingerAdditionalAnnotationsobject{}webfinger ingress resource additional annotations.
auth-server.ingress.webfingerEnabledbooltrueEnable endpoint /.well-known/webfinger
auth-server.ingress.webfingerLabelsobject{}webfinger ingress resource labels. key app is taken
auth-server.lockEnabledboolfalseEnable jans-lock as service running inside auth-server
auth-server-key-rotation (33)
KeyTypeDefaultDescription
auth-server-key-rotationobject—Responsible for regenerating auth-keys per x hours
auth-server-key-rotation.additionalAnnotationsobject{}Additional annotations that will be added across the gateway in the format of {cert-manager.io/issuer: "letsencrypt-prod"}
auth-server-key-rotation.additionalLabelsobject{}Additional labels that will be added across the gateway in the format of {mylabel: "myapp"}
auth-server-key-rotation.cronJobSchedulestring""Auth server key rotation job schedule. It accepts any Cron syntax supported by Kubernetes. If empty, the schedule will run based on keysLife value.
auth-server-key-rotation.customCommandlist[]Add custom job's command. If passed, it will override the default conditional command.
auth-server-key-rotation.customScriptslist[]Add custom scripts that have been mounted to run before the entrypoint.
- /tmp/custom.sh
- /tmp/custom2.sh
auth-server-key-rotation.dnsConfigobject{}Add custom dns config
auth-server-key-rotation.dnsPolicystring""Add custom dns policy
auth-server-key-rotation.enabledbooltrueBoolean flag to enable/disable the auth-server-key rotation cronjob.
auth-server-key-rotation.imageobject—No description upstream
auth-server-key-rotation.image.pullPolicystring"IfNotPresent"Image pullPolicy to use for deploying.
auth-server-key-rotation.image.pullSecretslist[]Image Pull Secrets
auth-server-key-rotation.image.repositorystring"ghcr.io/janssenproject/jans/cloudtools"Image to use for deploying.
auth-server-key-rotation.image.tagstring"2.4.0-1"Image tag to use for deploying.
auth-server-key-rotation.initKeysLifeint48The initial auth server key rotation keys life in hours
auth-server-key-rotation.keysLifeint48Auth server key rotation keys life in hours
auth-server-key-rotation.keysPushDelayint0Delay (in seconds) before pushing private keys to Auth server
auth-server-key-rotation.keysPushStrategystring"NEWER"Set key selection strategy after pushing private keys to Auth server (only takes effect when keysPushDelay value is greater than 0)
auth-server-key-rotation.keysStrategystring"NEWER"Set key selection strategy used by Auth server
auth-server-key-rotation.lifecycleobject{}No description upstream
auth-server-key-rotation.nodeSelectorobject{}Add nodeSelector (see https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#nodeselector)
auth-server-key-rotation.resourcesobject—Resource specs.
auth-server-key-rotation.resources.limitsobject—No description upstream
auth-server-key-rotation.resources.limits.cpustring"300m"CPU limit.
auth-server-key-rotation.resources.limits.memorystring"300Mi"Memory limit.
auth-server-key-rotation.resources.requestsobject—No description upstream
auth-server-key-rotation.resources.requests.cpustring"300m"CPU request.
auth-server-key-rotation.resources.requests.memorystring"300Mi"Memory request.
auth-server-key-rotation.usrEnvsobject—Add custom normal and secret envs to the service
auth-server-key-rotation.usrEnvs.normalobject{}Add custom normal envs to the service
variable1: value1
auth-server-key-rotation.usrEnvs.secretobject{}Add custom secret envs to the service
variable1: value1
auth-server-key-rotation.volumeMountslist[]Configure any additional volumesMounts that need to be attached to the containers
auth-server-key-rotation.volumeslist[]Configure any additional volumes that need to be attached to the pod
casa (19)
KeyTypeDefaultDescription
casaobject—No description upstream
casa.adminEnabledbooltrueBoolean flag to enable/disable the casa admin console.
casa.appLoggersobject—App loggers can be configured to define where the logs will be redirected to and the level of each in which it should be displayed.
casa.appLoggers.casaLogLevelstring"INFO"casa.log level
casa.appLoggers.casaLogTargetstring"STDOUT"casa.log target
casa.appLoggers.enableStdoutLogPrefixstring"true"Enable log prefixing which enables prepending the STDOUT logs with the file name. i.e casa ===> 2022-12-20 17:49:55,744 INFO
casa.appLoggers.rootLogLevelstring"INFO"root log level
casa.appLoggers.rootLogTargetstring"STDOUT"root log target (if set to FILE, logs will be redirected to casa.log)
casa.appLoggers.timerLogLevelstring"INFO"casa timer log level
casa.appLoggers.timerLogTargetstring"FILE"casa timer log target
casa.casaServiceNamestring"casa"Name of the casa service. Please keep it as default.
casa.cnCustomJavaOptionsstring""passing custom java options to casa. Notice you do not need to pass in any loggers options as they are introduced below in appLoggers. DO NOT PASS JAVA_OPTIONS in envs.
casa.enabledbooltrueBoolean flag to enable/disable the casa chart.
casa.gatewayNamestring""Enable endpoints in either istio or nginx ingress depending on users choice -- Override Gateway name for Gateway API (defaults to gateway-api.gateway.name). The target Gateway must expose listeners named after gateway-api.gateway.httpSectionName and httpsSectionName.
casa.gatewayNamespacestring""Override Gateway namespace for Gateway API (defaults to gateway-api.gateway.gatewayNamespace or release namespace). That Gateway's listeners must allow routes from this release's namespace via spec.listeners[].allowedRoutes.namespaces.
casa.ingressobject—No description upstream
casa.ingress.casaAdditionalAnnotationsobject{}Casa ingress resource additional annotations.
casa.ingress.casaEnabledboolfalseEnable casa endpoints /jans-casa
casa.ingress.casaLabelsobject{}Casa ingress resource labels. key app is taken
certManager (7)
KeyTypeDefaultDescription
certManagerobject—No description upstream
certManager.certificateobject—No description upstream
certManager.certificate.enabledboolfalseNo description upstream
certManager.certificate.issuerGroupstring"cert-manager.io"No description upstream
certManager.certificate.issuerKindstring"ClusterIssuer"No description upstream
certManager.certificate.issuerNamestring""No description upstream
certManager.certificate.tlsSecretNamestring"tls-certificate"No description upstream
city (1)
KeyTypeDefaultDescription
citystring"Austin"City. Used for certificate creation.
cleanup (29)
KeyTypeDefaultDescription
cleanupobject—Cleanup expired entries in persistence
cleanup.additionalAnnotationsobject{}Additional annotations that will be added across the gateway in the format of {cert-manager.io/issuer: "letsencrypt-prod"}
cleanup.additionalLabelsobject{}Additional labels that will be added across the gateway in the format of {mylabel: "myapp"}
cleanup.customCommandlist[]Add custom job's command. If passed, it will override the default conditional command.
cleanup.customScriptslist[]Add custom scripts that have been mounted to run before the entrypoint.
- /tmp/custom.sh
- /tmp/custom2.sh
cleanup.dnsConfigobject{}Add custom dns config
cleanup.dnsPolicystring""Add custom dns policy
cleanup.enabledbooltrueBoolean flag to enable/disable the cleanup cronjob chart.
cleanup.imageobject—No description upstream
cleanup.image.pullPolicystring"IfNotPresent"Image pullPolicy to use for deploying.
cleanup.image.pullSecretslist[]Image Pull Secrets
cleanup.image.repositorystring"ghcr.io/janssenproject/jans/cloudtools"Image to use for deploying.
cleanup.image.tagstring"2.4.0-1"Image tag to use for deploying.
cleanup.intervalint60Interval of running the cleanup process (in minutes)
cleanup.lifecycleobject{}No description upstream
cleanup.limitint1000Max. numbers of entries to cleanup
cleanup.nodeSelectorobject{}Add nodeSelector (see https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#nodeselector)
cleanup.resourcesobject—Resource specs.
cleanup.resources.limitsobject—No description upstream
cleanup.resources.limits.cpustring"300m"CPU limit.
cleanup.resources.limits.memorystring"300Mi"Memory limit.
cleanup.resources.requestsobject—No description upstream
cleanup.resources.requests.cpustring"300m"CPU request.
cleanup.resources.requests.memorystring"300Mi"Memory request.
cleanup.usrEnvsobject—Add custom normal and secret envs to the service
cleanup.usrEnvs.normalobject{}Add custom normal envs to the service
variable1: value1
cleanup.usrEnvs.secretobject{}Add custom secret envs to the service
variable1: value1
cleanup.volumeMountslist[]Configure any additional volumesMounts that need to be attached to the containers
cleanup.volumeslist[]Configure any additional volumes that need to be attached to the pod
cnAwsConfigFile (1)
KeyTypeDefaultDescription
cnAwsConfigFilestring"/etc/jans/conf/aws_config_file"No description upstream
cnAwsSecretsReplicaRegionsFile (1)
KeyTypeDefaultDescription
cnAwsSecretsReplicaRegionsFilestring"/etc/jans/conf/aws_secrets_replica_regions"No description upstream
cnAwsSharedCredentialsFile (1)
KeyTypeDefaultDescription
cnAwsSharedCredentialsFilestring"/etc/jans/conf/aws_shared_credential_file"No description upstream
cnConfiguratorConfigurationFile (1)
KeyTypeDefaultDescription
cnConfiguratorConfigurationFilestring"/etc/jans/conf/configuration.json"Path to configuration schema file
cnConfiguratorCustomSchema (2)
KeyTypeDefaultDescription
cnConfiguratorCustomSchemaobject—Use custom configuration schema in existing secrets. Note, the secrets has to contain the key configuration.json or any basename as specified in cnConfiguratorConfigurationFile.
cnConfiguratorCustomSchema.secretNamestring""The name of the secrets used for storing custom configuration schema.
cnConfiguratorDumpFile (1)
KeyTypeDefaultDescription
cnConfiguratorDumpFilestring"/etc/jans/conf/configuration.out.json"Path to dumped configuration schema file
cnConfiguratorKey (1)
KeyTypeDefaultDescription
cnConfiguratorKeystring""Key to encrypt/decrypt configuration schema file using AES-256 CBC mode. Set the value to empty string to disable encryption/decryption, or 32 alphanumeric characters to enable it.
cnConfiguratorKeyFile (1)
KeyTypeDefaultDescription
cnConfiguratorKeyFilestring"/etc/jans/conf/configuration.key"Path to file contains key to encrypt/decrypt configuration schema file.
cnDocumentStoreType (1)
KeyTypeDefaultDescription
cnDocumentStoreTypestring"DB"Document store type to use for shibboleth files DB.
cnGoogleApplicationCredentials (1)
KeyTypeDefaultDescription
cnGoogleApplicationCredentialsstring"/etc/jans/conf/google-credentials.json"Base64 encoded service account. The sa must have roles/secretmanager.admin to use Google secrets. Leave as this is a sensible default.
cnPersistenceType (1)
KeyTypeDefaultDescription
cnPersistenceTypestring"sql"Persistence backend to run Gluu with hybrid|sql.
cnPrometheusPort (1)
KeyTypeDefaultDescription
cnPrometheusPortstring""Port used by Prometheus JMX agent (default to empty string). To enable Prometheus JMX agent, set the value to a number.
cnSqlPasswordFile (1)
KeyTypeDefaultDescription
cnSqlPasswordFilestring"/etc/jans/conf/sql_password"Path to SQL password file
config (2)
KeyTypeDefaultDescription
configobject—No description upstream
config.enabledbooltrueBoolean flag to enable/disable the configuration job. This normally should never be false
config-api (29)
KeyTypeDefaultDescription
config-apiobject—No description upstream
config-api.adminUiAppLoggersobject—No description upstream
config-api.adminUiAppLoggers.adminUiAuditLogLevelstring"INFO"config-api admin-ui plugin audit log level
config-api.adminUiAppLoggers.adminUiAuditLogTargetstring"FILE"config-api admin-ui plugin audit log target
config-api.adminUiAppLoggers.adminUiLogLevelstring"INFO"config-api admin-ui plugin log level
config-api.adminUiAppLoggers.adminUiLogTargetstring"FILE"config-api admin-ui plugin log target
config-api.adminUiAppLoggers.enableStdoutLogPrefixstring"true"Enable log prefixing which enables prepending the STDOUT logs with the file name. i.e config-api_persistence ===> 2022-12-20 17:49:55,744 INFO
config-api.appLoggersobject—App loggers can be configured to define where the logs will be redirected to and the level of each in which it should be displayed.
config-api.appLoggers.configApiLogLevelstring"INFO"configapi.log level
config-api.appLoggers.configApiLogTargetstring"STDOUT"configapi.log target
config-api.appLoggers.enableStdoutLogPrefixstring"true"Enable log prefixing which enables prepending the STDOUT logs with the file name. i.e config-api_persistence ===> 2022-12-20 17:49:55,744 INFO
config-api.appLoggers.persistenceDurationLogLevelstring"INFO"configapi_persistence_duration.log level
config-api.appLoggers.persistenceDurationLogTargetstring"FILE"configapi_persistence_duration.log target
config-api.appLoggers.persistenceLogLevelstring"INFO"configapi_persistence.log level
config-api.appLoggers.persistenceLogTargetstring"FILE"configapi_persistence.log target
config-api.appLoggers.rootLogLevelstring"INFO"root log level
config-api.appLoggers.rootLogTargetstring"STDOUT"root log target (if set to FILE, logs will be redirected to configapi.log)
config-api.appLoggers.scriptLogLevelstring"INFO"configapi_script.log level
config-api.appLoggers.scriptLogTargetstring"FILE"configapi_script.log target
config-api.cnCustomJavaOptionsstring""passing custom java options to config-api. Notice you do not need to pass in any loggers options as they are introduced below in appLoggers. DO NOT PASS JAVA_OPTIONS in envs.
config-api.configApiServerServiceNamestring"config-api"Name of the config-api service. Please keep it as default.
config-api.enabledbooltrueBoolean flag to enable/disable the config-api chart.
config-api.gatewayNamestring""Enable endpoints in either istio or nginx ingress depending on users choice -- Override Gateway name for Gateway API (defaults to gateway-api.gateway.name). The target Gateway must expose listeners named after gateway-api.gateway.httpSectionName and httpsSectionName.
config-api.gatewayNamespacestring""Override Gateway namespace for Gateway API (defaults to gateway-api.gateway.gatewayNamespace or release namespace). That Gateway's listeners must allow routes from this release's namespace via spec.listeners[].allowedRoutes.namespaces.
config-api.ingressobject—No description upstream
config-api.ingress.configApiAdditionalAnnotationsobject{}ConfigAPI ingress resource additional annotations.
config-api.ingress.configApiEnabledbooltrueNo description upstream
config-api.ingress.configApiLabelsobject{}configAPI ingress resource labels. key app is taken
config-api.pluginsstring"admin-ui,fido2,scim,user-mgt"Comma-separated values of enabled plugins (supported plugins are "admin-ui","fido2","scim","user-mgt")
configAdapterName (1)
KeyTypeDefaultDescription
configAdapterNamestring"kubernetes"The config backend adapter that will hold Gluu configuration layer. aws|google|kubernetes
configmap (49)
KeyTypeDefaultDescription
configmapobject—No description upstream
configmap.cnAwsAccessKeyIdstring""No description upstream
configmap.cnAwsDefaultRegionstring"us-west-1"No description upstream
configmap.cnAwsProfilestring"gluu"No description upstream
configmap.cnAwsSecretAccessKeystring""No description upstream
configmap.cnAwsSecretsEndpointUrlstring""No description upstream
configmap.cnAwsSecretsNamePrefixstring"gluu"No description upstream
configmap.cnAwsSecretsReplicaRegionslist[]No description upstream
configmap.cnCacheTypestring"NATIVE_PERSISTENCE"Cache type. `NATIVE_PERSISTENCE`, `REDIS`. or `IN_MEMORY`. Defaults to `NATIVE_PERSISTENCE` .
configmap.cnConfigKubernetesConfigMapstring"cn"The name of the Kubernetes ConfigMap that will hold the configuration layer
configmap.cnGoogleProjectIdstring"google-project-to-save-config-and-secrets-to"Project id of the Google project the secret manager belongs to. Used only when configAdapterName and configSecretAdapter is set to google.
configmap.cnGoogleSecretManagerServiceAccountstring"SWFtTm90YVNlcnZpY2VBY2NvdW50Q2hhbmdlTWV0b09uZQo="Service account with roles roles/secretmanager.admin base64 encoded string. This is used often inside the services to reach the configuration layer. Used only when configAdapterName and configSecretAdapter is set to google.
configmap.cnGoogleSecretNamePrefixstring"gluu"Prefix for Gluu secret in Google Secret Manager. Defaults to gluu. If left janssen-secret secret will be created. Used only when configAdapterName and configSecretAdapter is set to google.
configmap.cnGoogleSecretVersionIdstring"latest"Secret version to be used for secret configuration. Defaults to latest and should normally always stay that way. Used only when configAdapterName and configSecretAdapter is set to google.
configmap.cnJettyRequestHeaderSizeint8192Jetty header size in bytes in the auth server
configmap.cnMaxRamPercentstring"75.0"Value passed to Java option -XX:MaxRAMPercentage
configmap.cnMessageTypestring"DISABLED"Message type (one of POSTGRES, REDIS, or DISABLED)
configmap.cnRedisSentinelGroupstring""Redis Sentinel Group. Often set when `config.configmap.cnRedisType` is set to `SENTINEL`. Can be used when `config.configmap.cnCacheType` is set to `REDIS`.
configmap.cnRedisSslTruststorestring""Redis SSL truststore. Optional. Can be used when `config.configmap.cnCacheType` is set to `REDIS`.
configmap.cnRedisTypestring"STANDALONE"Redis service type. `STANDALONE` or `CLUSTER`. Can be used when `config.configmap.cnCacheType` is set to `REDIS`.
configmap.cnRedisUrlstring"redis.redis.svc.cluster.local:6379"Redis URL and port number <url>:<port>. Can be used when `config.configmap.cnCacheType` is set to `REDIS`.
configmap.cnRedisUseSslboolfalseBoolean to use SSL in Redis. Can be used when `config.configmap.cnCacheType` is set to `REDIS`.
configmap.cnScimProtectionModestring"OAUTH"SCIM protection mode OAUTH|TEST|UMA
configmap.cnSecretKubernetesSecretstring"cn"Kubernetes secret name holding configuration keys. Used when configSecretAdapter is set to kubernetes which is the default.
configmap.cnSqlDbDialectstring"mysql"SQL database dialect. `mysql` or `pgsql`
configmap.cnSqlDbHoststring"my-release-mysql.default.svc.cluster.local"SQL database host uri.
configmap.cnSqlDbNamestring"gluu"SQL database name.
configmap.cnSqlDbPortint3306SQL database port.
configmap.cnSqlDbSchemastring""Schema name used by SQL database (default to empty-string; if using MySQL, the schema name will be resolved as the database name, whereas in PostgreSQL the schema name will be resolved as `"public"`).
configmap.cnSqlDbTimezonestring"UTC"SQL database timezone.
configmap.cnSqlDbUserstring"gluu"SQL database username.
configmap.cnSqldbUserPasswordstring"Test1234#"SQL password injected the secrets .
configmap.cnSqlSslCaCertstring""Base64-encoded string of CA certificate used to sign client/server certificate of MySQL/PostgreSQL server. Required if using client cert authentication.
configmap.cnSqlSslClientCertstring""Base64-encoded string of client certificate signed by CA. Required if using client cert authentication.
configmap.cnSqlSslClientKeystring""Base64-encoded client private key corresponding to the client certificate. Required if using client cert authentication. We advise to not commit real private keys in values.yaml.
configmap.cnSqlSslEnabledboolfalseEnable SSL connection to SQL database.
configmap.cnSqlSslModestring""Mode used to connect to SQL database using SSL if cnSqlSslEnabled is set to true. If using MySQL, choose one of `PREFERRED`, `REQUIRED`, `VERIFY_CA`, or `VERIFY_IDENTITY`. If using PostgreSQL, choose one of `allow`, `prefer`, `require`, `verify-ca`, or `verify-full`.
configmap.cnVaultAddrstring"http://localhost:8200"Base URL of Vault.
configmap.cnVaultAppRolePathstring"approle"Path to Vault AppRole.
configmap.cnVaultKvPathstring"secret"Path to Vault KV secrets engine.
configmap.cnVaultNamespacestring""Vault namespace used to access the secrets.
configmap.cnVaultPrefixstring"jans"Base prefix name used to access secrets.
configmap.cnVaultRoleIdstring""Vault AppRole RoleID.
configmap.cnVaultRoleIdFilestring"/etc/certs/vault_role_id"Path to file contains Vault AppRole role ID.
configmap.cnVaultSecretIdstring""Vault AppRole SecretID.
configmap.cnVaultSecretIdFilestring"/etc/certs/vault_secret_id"Path to file contains Vault AppRole secret ID.
configmap.cnVaultVerifyboolfalseVerify connection to Vault.
configmap.containerMetadataNamestring"kubernetes"No description upstream
configmap.lbAddrstring""Load balancer address for AWS if the FQDN is not registered.
configSecretAdapter (1)
KeyTypeDefaultDescription
configSecretAdapterstring"kubernetes"The config backend adapter that will hold Gluu secret layer. vault|aws|google|kubernetes
countryCode (1)
KeyTypeDefaultDescription
countryCodestring"US"Country code. Used for certificate creation.
customAnnotations (13)
KeyTypeDefaultDescription
customAnnotationsobject—Add custom annotations for kubernetes resources for the service
customAnnotations.certificateobject{}No description upstream
customAnnotations.clusterRoleBindingobject{}No description upstream
customAnnotations.configMapobject{}No description upstream
customAnnotations.cronjobobject{}No description upstream
customAnnotations.deploymentobject{}No description upstream
customAnnotations.destinationRuleobject{}No description upstream
customAnnotations.horizontalPodAutoscalerobject{}No description upstream
customAnnotations.podobject{}No description upstream
customAnnotations.podDisruptionBudgetobject{}No description upstream
customAnnotations.roleobject{}No description upstream
customAnnotations.roleBindingobject{}No description upstream
customAnnotations.secretobject{}No description upstream
customCommand (1)
KeyTypeDefaultDescription
customCommandlist[]Add custom pod's command. If passed, it will override the default conditional command.
customScripts (1)
KeyTypeDefaultDescription
customScriptslist[]Add custom scripts that have been mounted to run before the entrypoint.
- /tmp/custom.sh
- /tmp/custom2.sh
dnsConfig (1)
KeyTypeDefaultDescription
dnsConfigobject{}Add custom dns config
dnsPolicy (1)
KeyTypeDefaultDescription
dnsPolicystring""Add custom dns policy
email (1)
KeyTypeDefaultDescription
emailstring"team@gluu.org"Email address of the administrator usually. Used for certificate creation.
fido2 (28)
KeyTypeDefaultDescription
fido2object—No description upstream
fido2.appLoggersobject—App loggers can be configured to define where the logs will be redirected to and the level of each in which it should be displayed.
fido2.appLoggers.enableStdoutLogPrefixstring"true"Enable log prefixing which enables prepending the STDOUT logs with the file name. i.e fido2 ===> 2022-12-20 17:49:55,744 INFO
fido2.appLoggers.fido2LogLevelstring"INFO"fido2.log level
fido2.appLoggers.fido2LogTargetstring"STDOUT"fido2.log target
fido2.appLoggers.persistenceDurationLogLevelstring"INFO"fido2_persistence_duration.log level
fido2.appLoggers.persistenceDurationLogTargetstring"FILE"fido2_persistence_duration.log target
fido2.appLoggers.persistenceLogLevelstring"INFO"fido2_persistence.log level
fido2.appLoggers.persistenceLogTargetstring"FILE"fido2_persistence.log target
fido2.appLoggers.rootLogLevelstring"INFO"root log level
fido2.appLoggers.rootLogTargetstring"STDOUT"root log target (if set to FILE, logs will be redirected to fido2.log)
fido2.appLoggers.scriptLogLevelstring"INFO"fido2_script.log level
fido2.appLoggers.scriptLogTargetstring"FILE"fido2_script.log target
fido2.cnCustomJavaOptionsstring""passing custom java options to fido2. Notice you do not need to pass in any loggers options as they are introduced below in appLoggers. DO NOT PASS JAVA_OPTIONS in envs.
fido2.enabledbooltrueBoolean flag to enable/disable the fido2 chart.
fido2.fido2ServiceNamestring"fido2"Name of the fido2 service. Please keep it as default.
fido2.gatewayNamestring""Enable endpoints in either istio or nginx ingress depending on users choice -- Override Gateway name for Gateway API (defaults to gateway-api.gateway.name). The target Gateway must expose listeners named after gateway-api.gateway.httpSectionName and httpsSectionName.
fido2.gatewayNamespacestring""Override Gateway namespace for Gateway API (defaults to gateway-api.gateway.gatewayNamespace or release namespace). That Gateway's listeners must allow routes from this release's namespace via spec.listeners[].allowedRoutes.namespaces.
fido2.ingressobject—No description upstream
fido2.ingress.fido2AdditionalAnnotationsobject{}fido2 ingress resource additional annotations.
fido2.ingress.fido2ConfigAdditionalAnnotationsobject{}fido2 config ingress resource additional annotations.
fido2.ingress.fido2ConfigEnabledboolfalseEnable endpoint /.well-known/fido2-configuration
fido2.ingress.fido2ConfigLabelsobject{}fido2 config ingress resource labels. key app is taken
fido2.ingress.fido2EnabledboolfalseEnable endpoint /jans-fido2
fido2.ingress.fido2Labelsobject{}fido2 ingress resource labels. key app is taken
fido2.ingress.fido2WebauthnAdditionalAnnotationsobject{}fido2 webauthn ingress resource additional annotations.
fido2.ingress.fido2WebauthnEnabledboolfalseEnable endpoint /.well-known/webauthn
fido2.ingress.fido2WebauthnLabelsobject{}fido2 webauthn ingress resource labels. key app is taken
fqdn (1)
KeyTypeDefaultDescription
fqdnstring"demoexample.gluu.org"Configuration parameters for setup and initial configuration secret and config layers used by Gluu services. -- Fully qualified domain name to be used for Gluu installation. This address will be used to reach Gluu services.
fullNameOverride (1)
KeyTypeDefaultDescription
fullNameOverridestring""No description upstream
gateway-api (52)
KeyTypeDefaultDescription
gateway-apiobject—Gateway API implementation. We support all GA-conformant implementations (e.g., 'nginx', 'istio', 'traefik'). See https://gateway-api.sigs.k8s.io/implementations/#conformant
gateway-api.additionalConfigobject—Additional configuration for Specific Gateway API implementation
gateway-api.additionalConfig.airlockobject—Configuration for Airlock Microgateway
gateway-api.additionalConfig.airlock.createLbServiceboolfalseCreate LoadBalancer service using GatewayParameters (by default airlock-microgateway doesn't create the service). See https://docs.airlock.com/microgateway/latest/index/api/crds/gateway-parameters/v1alpha1/ for details. The GatewayParameters will be attached to gateway.infrastructure.parametersRef only if it's empty.
gateway-api.additionalConfig.ciliumobject—Configuration for Cilium.
gateway-api.additionalConfig.cilium.ipPoolBlockslist[]Create Cilium IP pool with the specified blocks. See https://docs.cilium.io/en/stable/network/lb-ipam/ for details.
gateway-api.additionalConfig.envoyobject—Configuration for Envoy.
gateway-api.additionalConfig.envoy.createGatewayClassboolfalseCreate GatewayClass named `envoy` (by default Envoy doesn't create gatewayclass). The `envoy` name can be set as value of `gateway.className` attribute.
gateway-api.additionalConfig.istioobject{}Configuration for Istio.
gateway-api.additionalConfig.kgatewayobject{}Configuration for kgateway.
gateway-api.additionalConfig.nginxobject{}Configuration for NGINX Fabric.
gateway-api.additionalConfig.traefikobject{}Configuration for Traefik.
gateway-api.enabledboolfalseBoolean flag to enable/disable the Kubernetes Gateway and HTTPRoute resources.
gateway-api.gatewayobject—Configuration for Gateway resource
gateway-api.gateway.annotationsobject{}Specific annotations for the Gateway resource
gateway-api.gateway.attachLbIpboolfalseAttach global.lbIp to Gateway spec.addresses with IPAddress type (enable this if loadbalancer doesn't assign IP address to Gateway automatically)
gateway-api.gateway.classNamestring"nginx"Set the gatewayClassName corresponding to your installed controller.
gateway-api.gateway.enabledbooltrueEnable Gateway API and create a Gateway resource (if disabled, you will have to create and manage the Gateway resource externally). HTTPRoutes are still rendered so they can target the external Gateway.
gateway-api.gateway.gatewayNamespacestring""Namespace the Gateway resource resides in. Set this ONLY if the Gateway is externally managed in a different namespace than this Helm release. That Gateway's listeners must allow routes from this release's namespace via spec.listeners[].allowedRoutes.namespaces, otherwise the HTTPRoutes will not attach.
gateway-api.gateway.httpPortint80Gateway http port number
gateway-api.gateway.httpSectionNamestring"http"Names of the Gateway listeners the HTTPRoutes attach to. Only change these if your controller requires different listener names (e.g. some controllers require the listener name to be `default`). When the Gateway is externally managed (gateway.enabled=false), these must match the listener names on that Gateway.
gateway-api.gateway.httpsPortint443Gateway https port number
gateway-api.gateway.httpsSectionNamestring"https"No description upstream
gateway-api.gateway.infrastructureobject—Gateway spec.infrastructure
gateway-api.gateway.infrastructure.annotationsobject{}Specific annotations for the infrastructure
gateway-api.gateway.infrastructure.labelsobject{}Specific labels for the infrastructure
gateway-api.gateway.infrastructure.parametersRefobject{}Specific parametersRef for the infrastructure Some gateway implementation like `airlock-microgateway` may need to attach GatewayParameters to create Loadbalancer service automatically.
gateway-api.gateway.labelsobject{}Specific labels for the Gateway resource
gateway-api.gateway.namestring"gluu-gateway"The name of the Gateway resource to be created
gateway-api.gateway.tlsSecretNamestring"tls-certificate"Secret containing the TLS certificate for the Gateway
gateway-api.routesobject—Configuration for HTTPRoute and its related resources
gateway-api.routes.adminUiEnabledbooltrueEnable Admin UI endpoints /admin
gateway-api.routes.annotationsobject{}Specific annotations for the HTTPRoute resource
gateway-api.routes.authServerEnabledbooltrueEnable Auth server endpoints /jans-auth
gateway-api.routes.authServerProtectedRegisterboolfalseEnable mTLS on Auth server endpoint /jans-auth/restv1/register.
gateway-api.routes.authServerProtectedTokenboolfalseEnable mTLS on Auth server endpoint /jans-auth/restv1/token.
gateway-api.routes.authzenConfigEnabledbooltrueEnable endpoint /.well-known/authzen-configuration
gateway-api.routes.casaEnabledboolfalseEnable Casa endpoints /jans-casa
gateway-api.routes.configApiEnabledbooltrueEnable Config API endpoints /jans-config-api
gateway-api.routes.deviceCodeEnabledbooltrueEnable endpoint /device-code
gateway-api.routes.fido2ConfigEnabledboolfalseEnable endpoint /.well-known/fido2-configuration
gateway-api.routes.fido2EnabledboolfalseEnable all fido2 endpoints /jans-fido2
gateway-api.routes.fido2WebauthnEnabledboolfalseEnable endpoint /.well-known/webauthn
gateway-api.routes.firebaseMessagingEnabledbooltrueEnable endpoint /firebase-messaging-sw.js
gateway-api.routes.labelsobject{}Specific labels for the HTTPRoute resource
gateway-api.routes.lockAuditEnabledboolfalseEnable gRPC endpoint /io.jans.lock.audit.AuditService (if enabled, auth-server.lockEnabled must be enabled)
gateway-api.routes.lockConfigEnabledboolfalseEnable endpoint /.well-known/lock-server-configuration (if enabled, auth-server.lockEnabled must be enabled)
gateway-api.routes.openidConfigEnabledbooltrueEnable endpoint /.well-known/openid-configuration
gateway-api.routes.scimConfigEnabledboolfalseEnable endpoint /.well-known/scim-configuration
gateway-api.routes.scimEnabledboolfalseEnable SCIM endpoints /jans-scim
gateway-api.routes.uma2ConfigEnabledbooltrueEnable endpoint /.well-known/uma2-configuration
gateway-api.routes.webfingerEnabledbooltrueEnable endpoint /.well-known/webfinger
hpa (7)
KeyTypeDefaultDescription
hpaobject—Configure the HorizontalPodAutoscaler
hpa.behaviorobject{}Scaling Policies
hpa.enabledbooltrueNo description upstream
hpa.maxReplicasint10No description upstream
hpa.metricslist[]metrics if targetCPUUtilizationPercentage is not set
hpa.minReplicasint1No description upstream
hpa.targetCPUUtilizationPercentageint50No description upstream
image (5)
KeyTypeDefaultDescription
imageobject—No description upstream
image.pullPolicystring"IfNotPresent"Image pullPolicy to use for deploying.
image.pullSecretslist[]Image Pull Secrets
image.repositorystring"ghcr.io/gluufederation/flex/flex-all-in-one"Image to use for deploying.
image.tagstring"6.4.0-1"Image tag to use for deploying.
isFqdnRegistered (1)
KeyTypeDefaultDescription
isFqdnRegisteredboolfalseBoolean flag to enable mapping lbIp to fqdn inside pods on clouds that provide static ip for load balancers. On cloud that provide only addresses to the LB this flag will enable a script to actively scan config.configmap.lbAddr and update the hosts file inside the pods automatically.
istio (8)
KeyTypeDefaultDescription
istioobject—No description upstream
istio.additionalAnnotationsobject{}Additional annotations that will be added across the gateway in the format of {cert-manager.io/issuer: "letsencrypt-prod"}
istio.additionalLabelsobject{}Additional labels that will be added across the gateway in the format of {mylabel: "myapp"}
istio.enabledboolfalseBoolean flag that enables using istio side-cars with Gluu services.
istio.gatewayslist[]Override the gateway that can be created by default. This is used when istio ingress has already been setup and the gateway exists.
istio.ingressboolfalseBoolean flag that enables using istio gateway for Gluu. This assumes istio ingress is installed and hence the LB is available.
istio.namespacestring"istio-system"The namespace istio is deployed in. The is normally istio-system.
istio.tlsSecretNamestring"tls-certificate"No description upstream
lbIp (1)
KeyTypeDefaultDescription
lbIpstring"22.22.22.22"The Loadbalancer IP created by nginx or istio on clouds that provide static IPs. This is not needed if `fqdn` is globally resolvable.
lifecycle (1)
KeyTypeDefaultDescription
lifecycleobject{}No description upstream
livenessProbe (6)
KeyTypeDefaultDescription
livenessProbeobject—Configure the liveness healthcheck for the auth server if needed.
livenessProbe.execobject—Executes the python3 healthcheck. https://github.com/JanssenProject/docker-jans-auth-server/blob/master/scripts/healthcheck.py
livenessProbe.exec.commandlist[]No description upstream
livenessProbe.initialDelaySecondsint30No description upstream
livenessProbe.periodSecondsint30No description upstream
livenessProbe.timeoutSecondsint5No description upstream
nameOverride (1)
KeyTypeDefaultDescription
nameOverridestring""No description upstream
nginx-ingress (8)
KeyTypeDefaultDescription
nginx-ingressobject—No description upstream
nginx-ingress.enabledbooltrueBoolean flag to enable/disable the nginx-ingress definitions chart.
nginx-ingress.ingressobject—No description upstream
nginx-ingress.ingress.additionalAnnotationsobject{}Additional annotations that will be added across all ingress definitions in the format of {cert-manager.io/issuer: "letsencrypt-prod"} Enable client certificate authentication nginx.ingress.kubernetes.io/auth-tls-verify-client: "optional" Create the secret containing the trusted ca certificates nginx.ingress.kubernetes.io/auth-tls-secret: "janssen/tls-certificate" Specify the verification depth in the client certificates chain nginx.ingress.kubernetes.io/auth-tls-verify-depth: "1" Specify if certificates are passed to upstream server nginx.ingress.kubernetes.io/auth-tls-pass-certificate-to-upstream: "true"
nginx-ingress.ingress.additionalLabelsobject{}Additional labels that will be added across all ingress definitions in the format of {mylabel: "myapp"}
nginx-ingress.ingress.ingressClassNamestring"nginx"No description upstream
nginx-ingress.ingress.pathstring"/"No description upstream
nginx-ingress.ingress.tlsSecretNamestring"tls-certificate"Secrets holding HTTPS CA cert and key.
nodeSelector (1)
KeyTypeDefaultDescription
nodeSelectorobject{}Add nodeSelector (see https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#nodeselector)
orgName (1)
KeyTypeDefaultDescription
orgNamestring"Gluu"Organization name. Used for certificate creation.
pdb (3)
KeyTypeDefaultDescription
pdbobject—Configure the PodDisruptionBudget
pdb.enabledbooltrueNo description upstream
pdb.maxUnavailablestring"90%"No description upstream
persistence (2)
KeyTypeDefaultDescription
persistenceobject—No description upstream
persistence.enabledbooltrueBoolean flag to enable/disable the persistence job.
readinessProbe (6)
KeyTypeDefaultDescription
readinessProbeobject—Configure the readiness healthcheck for the auth server if needed. https://github.com/JanssenProject/docker-jans-auth-server/blob/master/scripts/healthcheck.py
readinessProbe.execobject—No description upstream
readinessProbe.exec.commandlist[]No description upstream
readinessProbe.initialDelaySecondsint25No description upstream
readinessProbe.periodSecondsint25No description upstream
readinessProbe.timeoutSecondsint5No description upstream
redisPassword (1)
KeyTypeDefaultDescription
redisPasswordstring"P@assw0rd"Redis admin password if `configmap.cnCacheType` is set to `REDIS`.
replicas (1)
KeyTypeDefaultDescription
replicasint1Service replica number.
resources (7)
KeyTypeDefaultDescription
resourcesobject—Resource specs.
resources.limitsobject—No description upstream
resources.limits.cpustring"16000m"CPU limit.
resources.limits.memorystring"16000Mi"Memory limit.
resources.requestsobject—No description upstream
resources.requests.cpustring"2500m"CPU request.
resources.requests.memorystring"2500Mi"Memory request.
salt (1)
KeyTypeDefaultDescription
saltstring""Salt. Used for encoding/decoding sensitive data. If omitted or set to empty string, the value will be self-generated. Otherwise, a 24 alphanumeric characters are allowed as its value.
scim (25)
KeyTypeDefaultDescription
scimobject—No description upstream
scim.appLoggersobject—App loggers can be configured to define where the logs will be redirected to and the level of each in which it should be displayed.
scim.appLoggers.enableStdoutLogPrefixstring"true"Enable log prefixing which enables prepending the STDOUT logs with the file name. i.e jans-scim ===> 2022-12-20 17:49:55,744 INFO
scim.appLoggers.persistenceDurationLogLevelstring"INFO"scim_persistence_duration.log level
scim.appLoggers.persistenceDurationLogTargetstring"FILE"scim_persistence_duration.log target
scim.appLoggers.persistenceLogLevelstring"INFO"scim_persistence.log level
scim.appLoggers.persistenceLogTargetstring"FILE"scim_persistence.log target
scim.appLoggers.rootLogLevelstring"INFO"root log level
scim.appLoggers.rootLogTargetstring"STDOUT"root log target (if set to FILE, logs will be redirected to scim.log)
scim.appLoggers.scimLogLevelstring"INFO"jans-scim.log level
scim.appLoggers.scimLogTargetstring"STDOUT"jans-scim.log target
scim.appLoggers.scriptLogLevelstring"INFO"scim_script.log level
scim.appLoggers.scriptLogTargetstring"FILE"scim_script.log target
scim.cnCustomJavaOptionsstring""passing custom java options to scim. Notice you do not need to pass in any loggers options as they are introduced below in appLoggers. DO NOT PASS JAVA_OPTIONS in envs.
scim.enabledbooltrueBoolean flag to enable/disable the SCIM chart.
scim.gatewayNamestring""Enable endpoints in either istio or nginx ingress depending on users choice -- Override Gateway name for Gateway API (defaults to gateway-api.gateway.name). The target Gateway must expose listeners named after gateway-api.gateway.httpSectionName and httpsSectionName.
scim.gatewayNamespacestring""Override Gateway namespace for Gateway API (defaults to gateway-api.gateway.gatewayNamespace or release namespace). That Gateway's listeners must allow routes from this release's namespace via spec.listeners[].allowedRoutes.namespaces.
scim.ingressobject—No description upstream
scim.ingress.scimAdditionalAnnotationsobject{}SCIM ingress resource additional annotations.
scim.ingress.scimConfigAdditionalAnnotationsobject{}SCIM config ingress resource additional annotations.
scim.ingress.scimConfigEnabledboolfalseEnable endpoint /.well-known/scim-configuration
scim.ingress.scimConfigLabelsobject{}SCIM config ingress resource labels. key app is taken
scim.ingress.scimEnabledboolfalseEnable SCIM endpoints /jans-scim
scim.ingress.scimLabelsobject{}SCIM ingress resource labels. key app is taken
scim.scimServiceNamestring"scim"Name of the scim service. Please keep it as default.
service (7)
KeyTypeDefaultDescription
serviceobject—No description upstream
service.namestring"http-aio"The name of the aio port within the aio service. Please keep it as default.
service.portint8080Port of the aio service. Please keep it as default.
service.sessionAffinitystring"None"Default set to None If you want to make sure that connections from a particular client are passed to the same Pod each time, you can select the session affinity based on the client's IP addresses by setting this to ClientIP
service.sessionAffinityConfigobject—the maximum session sticky time if sessionAffinity is ClientIP
service.sessionAffinityConfig.clientIPobject—No description upstream
service.sessionAffinityConfig.clientIP.timeoutSecondsint10800No description upstream
serviceAccountName (1)
KeyTypeDefaultDescription
serviceAccountNamestring"default"service account used by Kubernetes resources
state (1)
KeyTypeDefaultDescription
statestring"TX"Resource specs. -- State code. Used for certificate creation.
testEnvironment (1)
KeyTypeDefaultDescription
testEnvironmentboolfalseBoolean flag if enabled will strip resources requests and limits from all services.
tolerations (1)
KeyTypeDefaultDescription
tolerationslist[]Add tolerations for the pods
topologySpreadConstraints (1)
KeyTypeDefaultDescription
topologySpreadConstraintsobject{}Configure the topology spread constraints. Notice this is a map NOT a list as in the upstream API https://kubernetes.io/docs/concepts/scheduling-eviction/topology-spread-constraints/
usrEnvs (3)
KeyTypeDefaultDescription
usrEnvsobject—Add custom normal and secret envs to the service
usrEnvs.normalobject{}Add custom normal envs to the service
variable1: value1
usrEnvs.secretobject{}Add custom secret envs to the service
variable1: value1
volumeMounts (1)
KeyTypeDefaultDescription
volumeMountslist[]Configure any additional volumesMounts that need to be attached to the containers
volumes (1)
KeyTypeDefaultDescription
volumeslist[]Configure any additional volumes that need to be attached to the pod

We use analytics cookies to measure which pages are useful, so we can improve them. They are only set if you accept. Essential cookies needed for the site to work are always on. See our privacy policy.