Skip to content
Browse Gluu Server 4.5

Release

Kubernetes

#Getting Started with Kubernetes

The Kubernetes deployment of the Gluu Server, also called Cloud Native (CN) Edition, requires some special considerations compared to other deployments. This page details the installation and initial configuration of a CN deployment. More advanced configuration details are available on the appropriate pages throughout the Gluu documentation. For convenience, links to those documents follow:

#Requirements for accessing docker images and assets

  1. Contact sales@gluu.org for credentials (username and password/token) to access and pull our docker images. Existing customers should have received the credentials already.

  2. Create secrets to access and pull images from Docker hub repo. The secrets must lives in the same namespace (create the namespace if doesn't exist yet).

    kubectl create namespace <namespace>

    If you're planning to use istio, set the label as well:

    kubectl label namespace <namespace> istio-injection=enabled

    Afterwards, create the required secrets (in this example, regcred is the name of the secret):

    kubectl -n <namespace> create secret docker-registry regcred --docker-server=https://index.docker.io/v1/ --docker-username=<username> --docker-password=<password/token>
  3. If you are using pygluu-kubernetes.pyz the tool that parses values.yaml you can skip the next steps. We recommend using helm manually.

  4. Inject the secret name in your values.yaml at image.pullSecrets for each service. For example:

    ...
    ...
    oxauth:
      image:
        # -- Image pullPolicy to use for deploying.
        pullPolicy: IfNotPresent
        # -- Image to use for deploying.
        repository: gluufederation/oxauth
        # -- Image  tag to use for deploying.
        tag: 4.5.13-1
        # -- Image Pull Secrets
        pullSecrets:
          - name: regcred

#System Requirements for cloud deployments

Please calculate the minimum required resources as per the services deployed. The following table contains the default recommended resources to start with. Depending on the use of each service the resources may be increased or decreased.

ServiceCPU UnitRAMDisk SpaceProcessor TypeRequired
oxAuth2.52.5GBN/A64 BitYes
LDAP1.52GB10GB64 Bitif using hybrid or LDAP for persistence
Couchbase----If using hybrid or couchbase for persistence
FIDO20.50.5GBN/A64 BitNo
SCIM1.01.0GBN/A64 BitNo
config - job0.50.5GBN/A64 BitYes on fresh installs
Jackrabbit1.51GB10GB64 BitYes
persistence - job0.50.5GBN/A64 BitYes on fresh installs
oxTrust1.01.0GBN/A64 BitNo
oxShibboleth1.01.0GBN/A64 BitNo
oxPassport0.70.9GBN/A64 BitNo
oxd-server10.4GBN/A64 BitNo
NGINX11GBN/A64 BitYes if not ALB
key-rotation0.30.3GBN/A64 BitNo
cr-rotate0.20.2GBN/A64 BitNo
CASA0.50.5GBN/A64 BitNo
  1. Configure cloud or local kubernetes cluster:

#Amazon Web Services (AWS) - EKS

#Setup Cluster

  • Follow this guide to install a cluster with worker nodes. Please make sure that you have all the IAM policies for the AWS user that will be creating the cluster and volumes.

  • To be able to attach volumes to your pod, you need to install the Amazon EBS CSI driver

#Requirements

  • The above guide should also walk you through installing kubectl, aws-iam-authenticator and aws cli on the VM you will be managing your cluster and nodes from. Check to make sure.

    aws-iam-authenticator help
    aws-cli
    kubectl version
    
  • Optional[alpha]: If using Istio please install it prior to installing Gluu. You may choose to use any installation method Istio supports. If you have installed istio ingress, a loadbalancer will have been created. Please save the address of the loadbalancer for use later during installation.

#GCE (Google Cloud Engine) - GKE

#Setup Cluster

  1. Install gcloud

  2. Install kubectl using gcloud components install kubectl command

  3. Create a cluster using a command such as the following example:

    gcloud container clusters create exploringgluu --num-nodes 2 --machine-type e2-highcpu-8 --zone us-west1-a

    where CLUSTER_NAME is the name you choose for the cluster and ZONE_NAME is the name of zone where the cluster resources live in.

  4. Configure kubectl to use the cluster:

    gcloud container clusters get-credentials CLUSTER_NAME --zone ZONE_NAME

    where CLUSTER_NAME is the name you choose for the cluster and ZONE_NAME is the name of zone where the cluster resources live in.

  5. Afterwards, run kubectl cluster-info to check whether kubectl is ready to interact with the cluster. Make sure you are authenticated by using one of the several ways

  • Optional[alpha]: If using Istio please install it prior to installing Gluu. You may choose to use any installation method Istio supports. If you have installed istio ingress, a loadbalancer will have been created. Please save the ip of loadbalancer for use later during installation.

#DigitalOcean Kubernetes (DOKS)

#Setup Cluster

  • Follow this guide to create a digital ocean kubernetes service cluster and connect to it.

  • Optional[alpha]: If using Istio please install it prior to installing Gluu. You may choose to use any installation method Istio supports. If you have installed istio ingress, a loadbalancer will have been created. Please save the ip of loadbalancer for use later during installation.

#Azure - AKS

#Requirements

  • Follow this guide to install Azure CLI on the VM that will be managing the cluster and nodes. Check to make sure.

  • Follow this section to create the resource group for the AKS setup.

  • Follow this section to create the AKS cluster

  • Follow this section to connect to the AKS cluster

  • Optional[alpha]: If using Istio please install it prior to installing Gluu. You may choose to use any installation method Istio supports. If you have installed istio ingress, a loadbalancer will have been created. Please save the ip of loadbalancer for use later during installation.

#Minikube

#Requirements

  1. Install minikube.

  2. Install kubectl.

  3. Create cluster:

    minikube start
  4. Configure kubectl to use the cluster:

     kubectl config use-context minikube
    
  5. Enable ingress on minikube

    minikube addons enable ingress
  6. Optional[alpha]: If using Istio please install it prior to installing Gluu. You may choose to use any installation method Istio supports. Please note that at the moment Istio ingress is not supported with Minikube.

#MicroK8s

#Requirements

  1. Install MicroK8s

  2. Make sure all ports are open for microk8s

  3. Enable helm3, hostpath-storage, and dns:

    sudo microk8s.enable dns
    sudo microk8s.enable hostpath-storage
    sudo microk8s.enable helm3 

    Make aliases for kubectl and helm3:

    sudo snap alias microk8s.kubectl kubectl
    sudo snap alias microk8s.helm3 helm
  4. Optional: If using nginx ingress, please enable it.

    sudo microk8s.enable ingress
  5. Optional[alpha]: If using Istio please enable it.

    sudo microk8s.enable community
    sudo microk8s.enable istio
  1. Install using one of the following :

#Install Gluu using Helm

#Prerequisites

  • Kubernetes >=1.19x
  • Persistent volume provisioner support in the underlying infrastructure
  • Install Helm

#Quickstart

  1. Download pygluu-kubernetes.pyz. This package can be built manually.

  2. Optional: If using couchbase as the persistence backend. Download the couchbase kubernetes operator package for Linux and place it in the same directory as pygluu-kubernetes.pyz

  3. Run :

./pygluu-kubernetes.pyz helm-install

#Installing Gluu using Helm manually

  1. Optional if not using Istio ingress: Install NGINX-Ingress Helm Chart.

    helm repo add ingress-nginx https://kubernetes.github.io/ingress-nginx
    helm repo add stable https://charts.helm.sh/stable
    helm repo update
    helm install <nginx-release-name> ingress-nginx/ingress-nginx --namespace=<nginx-namespace>
    • If the FQDN for gluu i.e. demoexample.gluu.org is registered and globally resolvable, forward it to the loadbalancer address created in the previous step by NGINX-Ingress. A record can be added on most cloud providers to forward the domain to the loadbalancer. For example, on AWS assign a CNAME record for the LoadBalancer DNS name, or use Amazon Route 53 to create a hosted zone. More details in this AWS guide. Another example on GCE.

    • If the FQDN is not registered acquire the loadbalancer ip if on GCE, or Azure using kubectl get svc <release-name>-nginx-ingress-controller --output jsonpath='{.status.loadBalancer.ingress[0].ip}' and if on AWS get the loadbalancer addresss using kubectl -n ingress-nginx get svc ingress-nginx \--output jsonpath='{.status.loadBalancer.ingress[0].hostname}'.

    • If deploying on the cloud make sure to take a look at the Helm cloud-specific notes before continuing.

    • If deploying locally make sure to take a look at the helm-specific notes below before continuing.

  2. Optional: If using PostgreSQL as the persistence backend. In a production environment, a production-grade PostgreSQL server should be used such as Cloud SQL in GCP or Amazon RDS in AWS.

    For testing purposes, you can deploy it on your Kubernetes cluster using the following commands:

    wget https://raw.githubusercontent.com/GluuFederation/flex/nightly/automation/pgsql.yaml
    kubectl apply -f pgsql.yaml

    Add the following yaml snippet to your override.yaml file:

    global:
      gluuPersistenceType: sql
    config:
      configmap:
        cnSqlDbName: gluu
        cnSqlDbPort: 5432
        cnSqlDbDialect: pgsql
        cnSqlDbHost: postgresql.gluu.svc
        cnSqlDbUser: postgres
        cnSqlDbTimezone: UTC
        cnSqldbUserPassword: Test1234#
  3. Optional: If using MySQL as the persistence backend. In a production environment, a production grade MySQL server should be used such as Cloud SQL in GCP or Amazon RDS in AWS.

    For testing purposes, you can deploy it on your Kubernetes cluster using the following commands:

    wget https://raw.githubusercontent.com/GluuFederation/flex/nightly/automation/mysql.yaml
    kubectl apply -f mysql.yaml

    Add the following yaml snippet to your override.yaml file:

    global:
      gluuPersistenceType: sql
    config:
      configmap:
        cnSqlDbName: gluu
        cnSqlDbPort: 3306
        cnSqlDbDialect: mysql
        cnSqlDbHost: mysql.gluu.svc
        cnSqlDbUser: root
        cnSqlDbTimezone: UTC
        cnSqldbUserPassword: Test1234#
  4. Optional: If using couchbase as the persistence backend.

    1. Download pygluu-kubernetes.pyz. This package can be built manually.

    2. Download the couchbase kubernetes operator package for Linux and place it in the same directory as pygluu-kubernetes.pyz

    3. Run:

    ./pygluu-kubernetes.pyz couchbase-install
    1. Open the settings.json file generated from the previous step and copy over the values of COUCHBASE_URL and COUCHBASE_USER to global.gluuCouchbaseUrl and global.gluuCouchbaseUser in values.yaml respectively.
  5. Create your override-values.yaml and execute:


 helm repo add gluu https://gluufederation.github.io/gluu4/pygluu/kubernetes/templates/helm
 helm repo update
 helm install gluu gluu/gluu -n <namespace> --version=1.8.x -f override-values.yaml

#EKS Helm notes

#Required changes to the values.yaml

Inside the global values.yaml change the marked keys with CHANGE-THIS to the appropriate values :

#global values to be used across charts
global:
  storageClass:
    provisioner: kubernetes.io/aws-ebs
  domain: demoexample.gluu.org #CHANGE-THIS to the FQDN used for Gluu
  isDomainRegistered: "false" # CHANGE-THIS  "true" or "false" to specify if the domain above is registered or not.    
nginx-ingress:
  ingress:
    enabled: true
    path: /
    hosts:
      - demoexample.gluu.org #CHANGE-THIS to the FQDN used for Gluu
    tls:
      - secretName: tls-certificate
        hosts:
          - demoexample.gluu.org #CHANGE-THIS to the FQDN used for Gluu
config:
  configmap:
    lbAddr: "" #CHANGE-THIS to the address received in the previous step axx-109xx52.us-west-2.elb.amazonaws.com 

Tweak the optional parameters in values.yaml to fit the setup needed.

#GKE Helm notes

#Required changes to the values.yaml

Inside the global values.yaml change the marked keys with CHANGE-THIS to the appropriate values :

#global values to be used across charts
global:
  storageClass:
    provisioner: kubernetes.io/gce-pd
  domain: demoexample.gluu.org #CHANGE-THIS to the FQDN used for Gluu
  # Networking configs
  lbIp: "" #CHANGE-THIS  to the IP received from the previous step
  isDomainRegistered: "false" # CHANGE-THIS  "true" or "false" to specify if the domain above is registered or not.
nginx-ingress:
  ingress:
    enabled: true
    path: /
    hosts:
      - demoexample.gluu.org #CHANGE-THIS to the FQDN used for Gluu
    tls:
      - secretName: tls-certificate
        hosts:
          - demoexample.gluu.org #CHANGE-THIS to the FQDN used for Gluu

Tweak the optional parameters in values.yaml to fit the setup needed.

#Minikube Helm notes

#Required changes to the values.yaml

Inside the global values.yaml change the marked keys with CHANGE-THIS to the appropriate values :

#global values to be used across charts
global:
  storageClass:
    provisioner: k8s.io/minikube-hostpath
  domain: demoexample.gluu.org #CHANGE-THIS to the FQDN used for Gluu
  lbIp: "" #CHANGE-THIS  to the IP of minikube <minikube ip>

nginx-ingress:
  ingress:
    enabled: true
    path: /
    hosts:
      - demoexample.gluu.org #CHANGE-THIS to the FQDN used for Gluu
    tls:
      - secretName: tls-certificate
        hosts:
          - demoexample.gluu.org #CHANGE-THIS to the FQDN used for Gluu

Tweak the optional parameters in values.yaml to fit the setup needed.

  • Map gluu's FQDN at /etc/hosts file to the minikube IP as shown below.

    ##
    # Host Database
    #
    # localhost is used to configure the loopback interface
    # when the system is booting.  Do not change this entry.
    ##
    192.168.99.100    demoexample.gluu.org #minikube IP and example domain
    127.0.0.1    localhost
    255.255.255.255    broadcasthost
    ::1             localhost

#Microk8s helm notes

#Required changes to the values.yaml

Inside the global values.yaml change the marked keys with CHANGE-THIS to the appropriate values :

#global values to be used across charts
global:
  storageClass:
    provisioner: microk8s.io/hostpath
  domain: demoexample.gluu.org #CHANGE-THIS to the FQDN used for Gluu
  lbIp: "" #CHANGE-THIS  to the IP of the microk8s VM

nginx-ingress:
  ingress:
    enabled: true
    path: /
    hosts:
      - demoexample.gluu.org #CHANGE-THIS to the FQDN used for Gluu
    tls:
      - secretName: tls-certificate
        hosts:
          - demoexample.gluu.org #CHANGE-THIS to the FQDN used for Gluu

Tweak the optional parameters in values.yaml to fit the setup needed.

  • Map gluu's FQDN at /etc/hosts file to the microk8s VM IP as shown below.

    ##
    # Host Database
    #
    # localhost is used to configure the loopback interface
    # when the system is booting.  Do not change this entry.
    ##
    192.168.99.100    demoexample.gluu.org #microk8s IP and example domain
    127.0.0.1    localhost
    255.255.255.255    broadcasthost
    ::1             localhost

#Uninstalling the Chart

To uninstall/delete my-release deployment:

helm delete <my-release>

If during installation the release was not defined, the release name is checked by running $ helm ls then deleted using the previous command and the default release name.

#Configuration

KeyTypeDefaultDescription
globalobject{"alb":{"ingress":{"additionalAnnotations":{"alb.ingress.kubernetes.io/auth-session-cookie":"custom-cookie","alb.ingress.kubernetes.io/certificate-arn":"arn:aws:acm:us-west-2:xxxx:certificate/xxxxxx","alb.ingress.kubernetes.io/scheme":"internet-facing","kubernetes.io/ingress.class":"alb"},"additionalLabels":{},"adminUiEnabled":true,"authServerEnabled":true,"casaEnabled":false,"enabled":false,"fido2ConfigEnabled":false,"fido2Enabled":false,"openidConfigEnabled":true,"passportEnabled":false,"scimConfigEnabled":false,"scimEnabled":false,"shibEnabled":false,"u2fConfigEnabled":true,"uma2ConfigEnabled":true,"webdiscoveryEnabled":true,"webfingerEnabled":true}},"azureStorageAccountType":"Standard_LRS","azureStorageKind":"Managed","cloud":{"testEnviroment":false},"cnGoogleApplicationCredentials":"/etc/gluu/conf/google-credentials.json","config":{"enabled":true},"configAdapterName":"kubernetes","configSecretAdapter":"kubernetes","cr-rotate":{"enabled":false},"domain":"demoexample.gluu.org","fido2":{"appLoggers":{"fido2LogLevel":"INFO","fido2LogTarget":"STDOUT","persistenceLogLevel":"INFO","persistenceLogTarget":"FILE"},"enabled":false},"gcePdStorageType":"pd-standard","gluuJackrabbitCluster":"true","gluuPersistenceType":"couchbase","isDomainRegistered":"false","istio":{"additionalAnnotations":{},"additionalLabels":{},"enabled":false,"ingress":false,"namespace":"istio-system"},"jackrabbit":{"enabled":true},"lbIp":"","ldapServiceName":"opendj","nginx-ingress":{"enabled":true},"opendj":{"enabled":true},"oxauth":{"appLoggers":{"auditStatsLogLevel":"INFO","auditStatsLogTarget":"FILE","authLogLevel":"INFO","authLogTarget":"STDOUT","cleanerLogLevel":"INFO","cleanerLogTarget":"FILE","httpLogLevel":"INFO","httpLogTarget":"FILE","ldapStatsLogLevel":"INFO","ldapStatsLogTarget":"FILE","persistenceDurationLogLevel":"INFO","persistenceDurationLogTarget":"FILE","persistenceLogLevel":"INFO","persistenceLogTarget":"FILE","scriptLogLevel":"INFO","scriptLogTarget":"FILE"},"enabled":true},"oxauth-key-rotation":{"enabled":false},"oxd-server":{"appLoggers":{"oxdServerLogLevel":"INFO","oxdServerLogTarget":"STDOUT"},"enabled":false},"oxshibboleth":{"appLoggers":{"auditStatsLogLevel":"INFO","auditStatsLogTarget":"FILE","consentAuditLogLevel":"INFO","consentAuditLogTarget":"FILE","idpLogLevel":"INFO","idpLogTarget":"STDOUT","scriptLogLevel":"INFO","scriptLogTarget":"FILE"},"enabled":false},"oxtrust":{"appLoggers":{"apachehcLogLevel":"INFO","apachehcLogTarget":"FILE","auditStatsLogLevel":"INFO","auditStatsLogTarget":"FILE","cacheRefreshLogLevel":"INFO","cacheRefreshLogTarget":"FILE","cacheRefreshPythonLogLevel":"INFO","cacheRefreshPythonLogTarget":"FILE","cleanerLogLevel":"INFO","cleanerLogTarget":"FILE","httpLogLevel":"INFO","httpLogTarget":"FILE","ldapStatsLogLevel":"INFO","ldapStatsLogTarget":"FILE","oxtrustLogLevel":"INFO","oxtrustLogTarget":"STDOUT","persistenceDurationLogLevel":"INFO","persistenceDurationLogTarget":"FILE","persistenceLogLevel":"INFO","persistenceLogTarget":"FILE","scriptLogLevel":"INFO","scriptLogTarget":"FILE","velocityLogLevel":"INFO","velocityLogTarget":"FILE"},"enabled":true},"persistence":{"enabled":true},"scim":{"appLoggers":{"persistenceDurationLogLevel":"INFO","persistenceDurationLogTarget":"FILE","persistenceLogLevel":"INFO","persistenceLogTarget":"FILE","scimLogLevel":"INFO","scimLogTarget":"STDOUT","scriptLogLevel":"INFO","scriptLogTarget":"FILE"},"enabled":false},"storageClass":{"allowVolumeExpansion":true,"allowedTopologies":[],"mountOptions":["debug"],"parameters":{},"provisioner":"microk8s.io/hostpath","reclaimPolicy":"Retain","volumeBindingMode":"WaitForFirstConsumer"},"upgrade":{"enabled":false,"image":{"repository":"gluufederation/upgrade","tag":"4.4.0-1"},"sourceVersion":"4.4","targetVersion":"4.4"},"usrEnvs":{"normal":{},"secret":{}}}Parameters used globally across all services helm charts.
global.alb.ingress.additionalAnnotationsobject{"alb.ingress.kubernetes.io/auth-session-cookie":"custom-cookie","alb.ingress.kubernetes.io/certificate-arn":"arn:aws:acm:us-west-2:xxxx:certificate/xxxxxx","alb.ingress.kubernetes.io/scheme":"internet-facing","kubernetes.io/ingress.class":"alb"}Additional annotations that will be added across all ingress definitions in the format of {cert-manager.io/issuer: "letsencrypt-prod"}
global.alb.ingress.additionalLabelsobject{}Additional labels that will be added across all ingress definitions in the format of {mylabel: "myapp"}
global.alb.ingress.adminUiEnabledbooltrueEnable Admin UI endpoints /identity
global.alb.ingress.authServerEnabledbooltrueEnable Auth server endpoints /oxauth
global.alb.ingress.casaEnabledboolfalseEnable casa endpoints /casa
global.alb.ingress.fido2ConfigEnabledboolfalseEnable endpoint /.well-known/fido2-configuration
global.alb.ingress.fido2EnabledboolfalseEnable all fido2 endpoints /fido2
global.alb.ingress.openidConfigEnabledbooltrueEnable endpoint /.well-known/openid-configuration
global.alb.ingress.passportEnabledboolfalseEnable passport /passport
global.alb.ingress.scimConfigEnabledboolfalseEnable endpoint /.well-known/scim-configuration
global.alb.ingress.scimEnabledboolfalseEnable SCIM endpoints /scim
global.alb.ingress.shibEnabledboolfalseEnable oxshibboleth endpoints /idp
global.alb.ingress.u2fConfigEnabledbooltrueEnable endpoint /.well-known/fido-configuration
global.alb.ingress.uma2ConfigEnabledbooltrueEnable endpoint /.well-known/uma2-configuration
global.alb.ingress.webdiscoveryEnabledbooltrueEnable endpoint /.well-known/simple-web-discovery
global.alb.ingress.webfingerEnabledbooltrueEnable endpoint /.well-known/webfinger
global.azureStorageAccountTypestring"Standard_LRS"Volume storage type if using Azure disks.
global.azureStorageKindstring"Managed"Azure storage kind if using Azure disks
global.cloud.testEnviromentboolfalseBoolean flag if enabled will strip resources requests and limits from all services.
global.cnGoogleApplicationCredentialsstring"/etc/gluu/conf/google-credentials.json"Base64 encoded service account. The sa must have roles/secretmanager.admin to use Google secrets and roles/spanner.databaseUser to use Spanner.
global.config.enabledbooltrueBoolean flag to enable/disable the configuration chart. This normally should never be false
global.configAdapterNamestring"kubernetes"The config backend adapter that will hold Gluu configuration layer. google
global.configSecretAdapterstring"kubernetes"The config backend adapter that will hold Gluu secret layer. google
global.cr-rotate.enabledboolfalseBoolean flag to enable/disable the cr-rotate chart.
global.domainstring"demoexample.gluu.org"Fully qualified domain name to be used for Gluu installation. This address will be used to reach Gluu services.
global.fido2.appLoggersobject{"fido2LogLevel":"INFO","fido2LogTarget":"STDOUT","persistenceLogLevel":"INFO","persistenceLogTarget":"FILE"}App loggers can be configured to define where the logs will be redirected to and the level of each in which it should be displayed. log levels are "OFF", "FATAL", "ERROR", "WARN", "INFO", "DEBUG", "TRACE" Targets are "STDOUT" and "FILE"
global.fido2.appLoggers.fido2LogLevelstring"INFO"fido2.log level
global.fido2.appLoggers.fido2LogTargetstring"STDOUT"fido2.log target
global.fido2.appLoggers.persistenceLogLevelstring"INFO"fido2_persistence.log level
global.fido2.appLoggers.persistenceLogTargetstring"FILE"fido2_persistence.log target
global.fido2.enabledboolfalseBoolean flag to enable/disable the fido2 chart.
global.gcePdStorageTypestring"pd-standard"GCE storage kind if using Google disks
global.gluuJackrabbitClusterstring"true"Boolean flag if enabled will enable jackrabbit in cluster mode with Postgres.
global.gluuPersistenceTypestring"couchbase"Persistence backend to run Gluu with ldap
global.isDomainRegisteredstring"false"Boolean flag to enable mapping global.lbIp to global.fqdn inside pods on clouds that provide static ip for loadbalancer. On cloud that provide only addresses to the LB this flag will enable a script to actively scan config.configmap.lbAddr and update the hosts file inside the pods automatically.
global.istio.additionalAnnotationsobject{}Additional annotations that will be added across the gateway in the format of {cert-manager.io/issuer: "letsencrypt-prod"}
global.istio.additionalLabelsobject{}Additional labels that will be added across the gateway in the format of {mylabel: "myapp"}
global.istio.enabledboolfalseBoolean flag that enables using istio gateway for Gluu. This assumes istio ingress is installed and hence the LB is available.
global.istio.ingressboolfalseBoolean flag that enables using istio side cars with Gluu services.
global.istio.namespacestring"istio-system"The namespace istio is deployed in. The is normally istio-system.
global.jackrabbit.enabledbooltrueBoolean flag to enable/disable the jackrabbit chart. For more information on how it is used inside Gluu /docs/gluu-4/installation-guide/install-kubernetes#working-with-jackrabbit. If disabled oxShibboleth cannot be run.
global.lbIpstring""The Loadbalancer IP created by nginx or istio on clouds that provide static IPs. This is not needed if global.domain is globally resolvable.
global.ldapServiceNamestring"opendj"Name of the OpenDJ service. Please keep it as default.
global.nginx-ingress.enabledbooltrueBoolean flag to enable/disable the nginx-ingress definitions chart.
global.opendj.enabledbooltrueBoolean flag to enable/disable the OpenDJ chart.
global.oxauth-key-rotation.enabledboolfalseBoolean flag to enable/disable the oxauth-server-key rotation cronjob chart.
global.oxauth.appLoggersobject{"auditStatsLogLevel":"INFO","auditStatsLogTarget":"FILE","authLogLevel":"INFO","authLogTarget":"STDOUT","cleanerLogLevel":"INFO","cleanerLogTarget":"FILE","httpLogLevel":"INFO","httpLogTarget":"FILE","ldapStatsLogLevel":"INFO","ldapStatsLogTarget":"FILE","persistenceDurationLogLevel":"INFO","persistenceDurationLogTarget":"FILE","persistenceLogLevel":"INFO","persistenceLogTarget":"FILE","scriptLogLevel":"INFO","scriptLogTarget":"FILE"}App loggers can be configured to define where the logs will be redirected to and the level of each in which it should be displayed. log levels are "OFF", "FATAL", "ERROR", "WARN", "INFO", "DEBUG", "TRACE" Targets are "STDOUT" and "FILE"
global.oxauth.appLoggers.auditStatsLogLevelstring"INFO"oxauth_audit.log level
global.oxauth.appLoggers.auditStatsLogTargetstring"FILE"oxauth_script.log target
global.oxauth.appLoggers.authLogLevelstring"INFO"oxauth.log level
global.oxauth.appLoggers.authLogTargetstring"STDOUT"oxauth.log target
global.oxauth.appLoggers.cleanerLogLevelstring"INFO"cleaner log level
global.oxauth.appLoggers.cleanerLogTargetstring"FILE"cleaner log target
global.oxauth.appLoggers.httpLogLevelstring"INFO"http_request_response.log level
global.oxauth.appLoggers.httpLogTargetstring"FILE"http_request_response.log target
global.oxauth.appLoggers.ldapStatsLogLevelstring"INFO"oxauth_persistence_ldap_statistics.log level
global.oxauth.appLoggers.ldapStatsLogTargetstring"FILE"oxauth_persistence_ldap_statistics.log target
global.oxauth.appLoggers.persistenceDurationLogLevelstring"INFO"oxauth_persistence_duration.log level
global.oxauth.appLoggers.persistenceDurationLogTargetstring"FILE"oxauth_persistence_duration.log target
global.oxauth.appLoggers.persistenceLogLevelstring"INFO"oxauth_persistence.log level
global.oxauth.appLoggers.persistenceLogTargetstring"FILE"oxauth_persistence.log target
global.oxauth.appLoggers.scriptLogLevelstring"INFO"oxauth_script.log level
global.oxauth.appLoggers.scriptLogTargetstring"FILE"oxauth_script.log target
global.oxauth.enabledbooltrueBoolean flag to enable/disable oxauth chart. You should never set this to false.
global.oxd-server.appLoggersobject{"oxdServerLogLevel":"INFO","oxdServerLogTarget":"STDOUT"}App loggers can be configured to define where the logs will be redirected to and the level of each in which it should be displayed. log levels are "OFF", "FATAL", "ERROR", "WARN", "INFO", "DEBUG", "TRACE" Targets are "STDOUT" and "FILE"
global.oxd-server.appLoggers.oxdServerLogLevelstring"INFO"oxd-server.log level
global.oxd-server.appLoggers.oxdServerLogTargetstring"STDOUT"oxd-server.log target
global.oxd-server.enabledboolfalseBoolean flag to enable/disable the oxd-server chart.
global.oxshibboleth.appLoggersobject{"auditStatsLogLevel":"INFO","auditStatsLogTarget":"FILE","consentAuditLogLevel":"INFO","consentAuditLogTarget":"FILE","idpLogLevel":"INFO","idpLogTarget":"STDOUT","scriptLogLevel":"INFO","scriptLogTarget":"FILE"}App loggers can be configured to define where the logs will be redirected to and the level of each in which it should be displayed. log levels are "OFF", "FATAL", "ERROR", "WARN", "INFO", "DEBUG", "TRACE" Targets are "STDOUT" and "FILE"
global.oxshibboleth.appLoggers.auditStatsLogLevelstring"INFO"idp-audit.log level
global.oxshibboleth.appLoggers.auditStatsLogTargetstring"FILE"idp-audit.log target
global.oxshibboleth.appLoggers.consentAuditLogLevelstring"INFO"idp-consent-audit.log level
global.oxshibboleth.appLoggers.consentAuditLogTargetstring"FILE"idp-consent-audit.log target
global.oxshibboleth.appLoggers.idpLogLevelstring"INFO"idp-process.log level
global.oxshibboleth.appLoggers.idpLogTargetstring"STDOUT"idp-process.log target
global.oxshibboleth.appLoggers.scriptLogLevelstring"INFO"idp script.log level
global.oxshibboleth.appLoggers.scriptLogTargetstring"FILE"idp script.log target
global.oxshibboleth.enabledboolfalseBoolean flag to enable/disable the oxShibbboleth chart.
global.oxtrust.appLoggersobject{"apachehcLogLevel":"INFO","apachehcLogTarget":"FILE","auditStatsLogLevel":"INFO","auditStatsLogTarget":"FILE","cacheRefreshLogLevel":"INFO","cacheRefreshLogTarget":"FILE","cacheRefreshPythonLogLevel":"INFO","cacheRefreshPythonLogTarget":"FILE","cleanerLogLevel":"INFO","cleanerLogTarget":"FILE","httpLogLevel":"INFO","httpLogTarget":"FILE","ldapStatsLogLevel":"INFO","ldapStatsLogTarget":"FILE","oxtrustLogLevel":"INFO","oxtrustLogTarget":"STDOUT","persistenceDurationLogLevel":"INFO","persistenceDurationLogTarget":"FILE","persistenceLogLevel":"INFO","persistenceLogTarget":"FILE","scriptLogLevel":"INFO","scriptLogTarget":"FILE","velocityLogLevel":"INFO","velocityLogTarget":"FILE"}App loggers can be configured to define where the logs will be redirected to and the level of each in which it should be displayed. log levels are "OFF", "FATAL", "ERROR", "WARN", "INFO", "DEBUG", "TRACE" Targets are "STDOUT" and "FILE"
global.oxtrust.appLoggers.apachehcLogLevelstring"INFO"apachehc log level
global.oxtrust.appLoggers.apachehcLogTargetstring"FILE"apachehc log target
global.oxtrust.appLoggers.auditStatsLogLevelstring"INFO"oxtrust_audit.log level
global.oxtrust.appLoggers.auditStatsLogTargetstring"FILE"oxtrust_script.log target
global.oxtrust.appLoggers.cacheRefreshLogLevelstring"INFO"cache refresh log level
global.oxtrust.appLoggers.cacheRefreshLogTargetstring"FILE"cache refresh log target
global.oxtrust.appLoggers.cacheRefreshPythonLogLevelstring"INFO"cleaner log level
global.oxtrust.appLoggers.cacheRefreshPythonLogTargetstring"FILE"cache refresh python log target
global.oxtrust.appLoggers.cleanerLogLevelstring"INFO"cleaner log target
global.oxtrust.appLoggers.cleanerLogTargetstring"FILE"cleaner log target
global.oxtrust.appLoggers.httpLogLevelstring"INFO"http_request_response.log level
global.oxtrust.appLoggers.httpLogTargetstring"FILE"http_request_response.log target
global.oxtrust.appLoggers.ldapStatsLogLevelstring"INFO"oxtrust_persistence_ldap_statistics.log level
global.oxtrust.appLoggers.ldapStatsLogTargetstring"FILE"oxtrust_persistence_ldap_statistics.log target
global.oxtrust.appLoggers.oxtrustLogLevelstring"INFO"oxtrust.log level
global.oxtrust.appLoggers.oxtrustLogTargetstring"STDOUT"oxtrust.log target
global.oxtrust.appLoggers.persistenceDurationLogLevelstring"INFO"oxtrust_persistence_duration.log level
global.oxtrust.appLoggers.persistenceDurationLogTargetstring"FILE"oxtrust_persistence_duration.log target
global.oxtrust.appLoggers.persistenceLogLevelstring"INFO"oxtrust_persistence.log level
global.oxtrust.appLoggers.persistenceLogTargetstring"FILE"oxtrust_persistence.log target
global.oxtrust.appLoggers.scriptLogLevelstring"INFO"oxtrust_script.log level
global.oxtrust.appLoggers.scriptLogTargetstring"FILE"oxtrust_script.log target
global.oxtrust.appLoggers.velocityLogLevelstring"INFO"velocity log level
global.oxtrust.appLoggers.velocityLogTargetstring"FILE"velocity log target
global.oxtrust.enabledbooltrueBoolean flag to enable/disable the oxtrust chart.
global.persistence.enabledbooltrueBoolean flag to enable/disable the persistence chart.
global.scim.appLoggersobject{"persistenceDurationLogLevel":"INFO","persistenceDurationLogTarget":"FILE","persistenceLogLevel":"INFO","persistenceLogTarget":"FILE","scimLogLevel":"INFO","scimLogTarget":"STDOUT","scriptLogLevel":"INFO","scriptLogTarget":"FILE"}App loggers can be configured to define where the logs will be redirected to and the level of each in which it should be displayed. log levels are "OFF", "FATAL", "ERROR", "WARN", "INFO", "DEBUG", "TRACE" Targets are "STDOUT" and "FILE"
global.scim.appLoggers.persistenceDurationLogLevelstring"INFO"scim_persistence_duration.log level
global.scim.appLoggers.persistenceDurationLogTargetstring"FILE"scim_persistence_duration.log target
global.scim.appLoggers.persistenceLogLevelstring"INFO"scim_persistence.log level
global.scim.appLoggers.persistenceLogTargetstring"FILE"scim_persistence.log target
global.scim.appLoggers.scimLogLevelstring"INFO"scim.log level
global.scim.appLoggers.scimLogTargetstring"STDOUT"scim.log target
global.scim.appLoggers.scriptLogLevelstring"INFO"scim_script.log level
global.scim.appLoggers.scriptLogTargetstring"FILE"scim_script.log target
global.scim.enabledboolfalseBoolean flag to enable/disable the SCIM chart.
global.storageClassobject{"allowVolumeExpansion":true,"allowedTopologies":[],"mountOptions":["debug"],"parameters":{},"provisioner":"microk8s.io/hostpath","reclaimPolicy":"Retain","volumeBindingMode":"WaitForFirstConsumer"}StorageClass section for Jackrabbit and OpenDJ charts. This is not currently used by the openbanking distribution. You may specify custom parameters as needed.
global.storageClass.parametersobject{}parameters:
global.upgrade.enabledboolfalseBoolean flag used when running upgrading through versions command.
global.upgrade.image.repositorystring"gluufederation/upgrade"Image to use for deploying.
global.upgrade.image.tagstring"4.4.0-1"Image tag to use for deploying.
global.upgrade.sourceVersionstring"4.4"Source version currently running. This is normally one minor version down. The step should only be one minor version per upgrade
global.upgrade.targetVersionstring"4.4"Target version currently running. This is normally one minor version up. The step should only be one minor version per upgrade
global.usrEnvsobject{"normal":{},"secret":{}}Add custom normal and secret envs to the service. Envs defined in global.userEnvs will be globally available to all services
global.usrEnvs.normalobject{}Add custom normal envs to the service. variable1: value1
global.usrEnvs.secretobject{}Add custom secret envs to the service. variable1: value1
KeyTypeDefaultDescription
configobject{"additionalAnnotations":{},"additionalLabels":{},"adminPass":"P@ssw0rd","city":"Austin","configmap":{"cnConfigGoogleSecretNamePrefix":"gluu","cnConfigGoogleSecretVersionId":"latest","cnGoogleProjectId":"google-project-to-save-config-and-secrets-to","cnGoogleSecretManagerPassPhrase":"Test1234#","cnGoogleServiceAccount":"SWFtTm90YVNlcnZpY2VBY2NvdW50Q2hhbmdlTWV0b09uZQo=","cnGoogleSpannerDatabaseId":"","cnGoogleSpannerInstanceId":"","cnSecretGoogleSecretNamePrefix":"gluu","cnSecretGoogleSecretVersionId":"latest","cnSqlDbDialect":"mysql","cnSqlDbHost":"my-release-mysql.default.svc.cluster.local","cnSqlDbName":"gluu","cnSqlDbPort":3306,"cnSqlDbTimezone":"UTC","cnSqlDbUser":"gluu","cnSqlPasswordFile":"/etc/gluu/conf/sql_password","cnSqldbUserPassword":"Test1234#","containerMetadataName":"kubernetes","gluuCacheType":"NATIVE_PERSISTENCE","gluuCasaEnabled":false,"gluuCouchbaseBucketPrefix":"gluu","gluuCouchbaseCertFile":"/etc/certs/couchbase.crt","gluuCouchbaseCrt":"LS0tLS1CRUdJTiBDRVJUSUZJQ0FURS0tLS0tCk1JSURlakNDQW1LZ0F3SUJBZ0lKQUwyem5UWlREUHFNTUEwR0NTcUdTSWIzRFFFQkN3VUFNQzB4S3pBcEJnTlYKQkFNTUlpb3VZMkpuYkhWMUxtUmxabUYxYkhRdWMzWmpMbU5zZFhOMFpYSXViRzlqWVd3d0hoY05NakF3TWpBMQpNRGt4T1RVeFdoY05NekF3TWpBeU1Ea3hPVFV4V2pBdE1Tc3dLUVlEVlFRRERDSXFMbU5pWjJ4MWRTNWtaV1poCmRXeDBMbk4yWXk1amJIVnpkR1Z5TG14dlkyRnNNSUlCSWpBTkJna3Foa2lHOXcwQkFRRUZBQU9DQVE4QU1JSUIKQ2dLQ0FRRUFycmQ5T3lvSnRsVzhnNW5nWlJtL2FKWjJ2eUtubGU3dVFIUEw4Q2RJa1RNdjB0eHZhR1B5UkNQQgo3RE00RTFkLzhMaU5takdZZk41QjZjWjlRUmNCaG1VNmFyUDRKZUZ3c0x0cTFGT3MxaDlmWGo3d3NzcTYrYmlkCjV6Umw3UEE0YmdvOXVkUVRzU1UrWDJUUVRDc0dxVVVPWExrZ3NCMjI0RDNsdkFCbmZOeHcvYnFQa2ZCQTFxVzYKVXpxellMdHN6WE5GY0dQMFhtU3c4WjJuaFhhUGlva2pPT2dyMkMrbVFZK0htQ2xGUWRpd2g2ZjBYR0V0STMrKwoyMStTejdXRkF6RlFBVUp2MHIvZnk4TDRXZzh1YysvalgwTGQrc2NoQTlNQjh3YmJORUp2ZjNMOGZ5QjZ0cTd2CjF4b0FnL0g0S1dJaHdqSEN0dFVnWU1oU0xWV3UrUUlEQVFBQm80R2NNSUdaTUIwR0ExVWREZ1FXQkJTWmQxWU0KVGNIRVZjSENNUmp6ejczZitEVmxxREJkQmdOVkhTTUVWakJVZ0JTWmQxWU1UY0hFVmNIQ01Sanp6NzNmK0RWbApxS0V4cEM4d0xURXJNQ2tHQTFVRUF3d2lLaTVqWW1kc2RYVXVaR1ZtWVhWc2RDNXpkbU11WTJ4MWMzUmxjaTVzCmIyTmhiSUlKQUwyem5UWlREUHFNTUF3R0ExVWRFd1FGTUFNQkFmOHdDd1lEVlIwUEJBUURBZ0VHTUEwR0NTcUcKU0liM0RRRUJDd1VBQTRJQkFRQk9meTVWSHlKZCtWUTBXaUQ1aSs2cmhidGNpSmtFN0YwWVVVZnJ6UFN2YWVFWQp2NElVWStWOC9UNnE4Mk9vVWU1eCtvS2dzbFBsL01nZEg2SW9CRnVtaUFqek14RTdUYUhHcXJ5dk13Qk5IKzB5CnhadG9mSnFXQzhGeUlwTVFHTEs0RVBGd3VHRlJnazZMRGR2ZEN5NVdxWW1MQWdBZVh5VWNaNnlHYkdMTjRPUDUKZTFiaEFiLzRXWXRxRHVydFJrWjNEejlZcis4VWNCVTRLT005OHBZN05aaXFmKzlCZVkvOEhZaVQ2Q0RRWWgyTgoyK0VWRFBHcFE4UkVsRThhN1ZLL29MemlOaXFyRjllNDV1OU1KdjM1ZktmNUJjK2FKdWduTGcwaUZUYmNaT1prCkpuYkUvUENIUDZFWmxLaEFiZUdnendtS1dDbTZTL3g0TklRK2JtMmoKLS0tLS1FTkQgQ0VSVElGSUNBVEUtLS0tLQo=","gluuCouchbaseIndexNumReplica":0,"gluuCouchbasePass":"P@ssw0rd","gluuCouchbasePassFile":"/etc/gluu/conf/couchbase_password","gluuCouchbaseSuperUser":"admin","gluuCouchbaseSuperUserPass":"P@ssw0rd","gluuCouchbaseSuperUserPassFile":"/etc/gluu/conf/couchbase_superuser_password","gluuCouchbaseUrl":"cbgluu.default.svc.cluster.local","gluuCouchbaseUser":"gluu","gluuDocumentStoreType":"DB","gluuJackrabbitAdminId":"admin","gluuJackrabbitAdminIdFile":"/etc/gluu/conf/jackrabbit_admin_id","gluuJackrabbitAdminPassFile":"/etc/gluu/conf/jackrabbit_admin_password","gluuJackrabbitPostgresDatabaseName":"jackrabbit","gluuJackrabbitPostgresHost":"postgresql.postgres.svc.cluster.local","gluuJackrabbitPostgresPasswordFile":"/etc/gluu/conf/postgres_password","gluuJackrabbitPostgresPort":5432,"gluuJackrabbitPostgresUser":"jackrabbit","gluuJackrabbitSyncInterval":300,"gluuJackrabbitUrl":"http://jackrabbit:8080","gluuLdapUrl":"opendj:1636","gluuMaxRamPercent":"75.0","gluuOxauthBackend":"oxauth:8080","gluuOxdAdminCertCn":"oxd-server","gluuOxdApplicationCertCn":"oxd-server","gluuOxdBindIpAddresses":"*","gluuOxdServerUrl":"oxd-server:8443","gluuOxtrustApiEnabled":false,"gluuOxtrustApiTestMode":false,"gluuOxtrustBackend":"oxtrust:8080","gluuOxtrustConfigGeneration":true,"gluuPassportEnabled":false,"gluuPassportFailureRedirectUrl":"","gluuPersistenceLdapMapping":"default","gluuRedisSentinelGroup":"","gluuRedisSslTruststore":"","gluuRedisType":"STANDALONE","gluuRedisUrl":"redis:6379","gluuRedisUseSsl":"false","gluuSamlEnabled":false,"gluuScimProtectionMode":"OAUTH","gluuSyncCasaManifests":false,"gluuSyncShibManifests":false,"lbAddr":""},"countryCode":"US","dnsConfig":{},"dnsPolicy":"","email":"support@gluu.com","image":{"pullSecrets":[],"repository":"gluufederation/config-init","tag":"4.4.0-1"},"ldapPass":"P@ssw0rd","migration":{"enabled":false,"migrationDataFormat":"ldif","migrationDir":"/ce-migration"},"orgName":"Gluu","redisPass":"P@assw0rd","resources":{"limits":{"cpu":"300m","memory":"300Mi"},"requests":{"cpu":"300m","memory":"300Mi"}},"state":"TX","usrEnvs":{"normal":{},"secret":{}},"volumeMounts":[],"volumes":[]}Configuration parameters for setup and initial configuration secret and config layers used by Gluu services.
config.additionalAnnotationsobject{}Additional annotations that will be added across all resources in the format of {cert-manager.io/issuer: "letsencrypt-prod"}. key app is taken
config.additionalLabelsobject{}Additional labels that will be added across all resources definitions in the format of {mylabel: "myapp"}
config.adminPassstring"P@ssw0rd"Admin password to log in to the UI.
config.citystring"Austin"City. Used for certificate creation.
config.configmap.cnConfigGoogleSecretNamePrefixstring"gluu"Prefix for Gluu configuration secret in Google Secret Manager. Defaults to gluu. If left intact gluu-configuration secret will be created. Used only when global.configAdapterName and global.configSecretAdapter is set to google.
config.configmap.cnConfigGoogleSecretVersionIdstring"latest"Secret version to be used for configuration. Defaults to latest and should normally always stay that way. Used only when global.configAdapterName and global.configSecretAdapter is set to google. Used only when global.configAdapterName and global.configSecretAdapter is set to google.
config.configmap.cnGoogleProjectIdstring"google-project-to-save-config-and-secrets-to"Project id of the google project the secret manager belongs to. Used only when global.configAdapterName and global.configSecretAdapter is set to google.
config.configmap.cnGoogleSecretManagerPassPhrasestring"Test1234#"Passphrase for Gluu secret in Google Secret Manager. This is used for encrypting and decrypting data from the Google Secret Manager. Used only when global.configAdapterName and global.configSecretAdapter is set to google.
config.configmap.cnGoogleServiceAccountstring"SWFtTm90YVNlcnZpY2VBY2NvdW50Q2hhbmdlTWV0b09uZQo="Service account with roles roles/secretmanager.admin base64 encoded string. This is used often inside the services to reach the configuration layer. Used only when global.configAdapterName and global.configSecretAdapter is set to google.
config.configmap.cnGoogleSpannerDatabaseIdstring""Google Spanner Database ID. Used only when global.gluuPersistenceType is spanner.
config.configmap.cnGoogleSpannerInstanceIdstring""Google Spanner ID. Used only when global.gluuPersistenceType is spanner.
config.configmap.cnSecretGoogleSecretNamePrefixstring"gluu"Prefix for Gluu secret in Google Secret Manager. Defaults to gluu. If left gluu-secret secret will be created. Used only when global.configAdapterName and global.configSecretAdapter is set to google.
config.configmap.cnSecretGoogleSecretVersionIdstring"latest"Secret version to be used for secret configuration. Defaults to latest and should normally always stay that way. Used only when global.configAdapterName and global.configSecretAdapter is set to google.
config.configmap.cnSqlDbDialectstring"mysql"SQL database dialect. mysql or pgsql
config.configmap.cnSqlDbHoststring"my-release-mysql.default.svc.cluster.local"SQL database host uri.
config.configmap.cnSqlDbNamestring"gluu"SQL database username.
config.configmap.cnSqlDbPortint3306SQL database port.
config.configmap.cnSqlDbTimezonestring"UTC"SQL database timezone.
config.configmap.cnSqlDbUserstring"gluu"SQL database username.
config.configmap.cnSqlPasswordFilestring"/etc/gluu/conf/sql_password"SQL password file holding password from config.configmap.cnSqldbUserPassword .
config.configmap.cnSqldbUserPasswordstring"Test1234#"SQL password injected as config.configmap.cnSqlPasswordFile .
config.configmap.gluuCacheTypestring"NATIVE_PERSISTENCE"Cache type. NATIVE_PERSISTENCE, REDIS. or IN_MEMORY. Defaults to NATIVE_PERSISTENCE .
config.configmap.gluuCasaEnabledboolfalseEnable Casa flag .
config.configmap.gluuCouchbaseBucketPrefixstring"gluu"The prefix of couchbase buckets. This helps with separation in between different environments and allows for the same couchbase cluster to be used by different setups of Gluu.
config.configmap.gluuCouchbaseCertFilestring"/etc/certs/couchbase.crt"Location of couchbase.crt used by Couchbase SDK for tls termination. The file path must end with couchbase.crt. In mTLS setups this is not required.
config.configmap.gluuCouchbaseCrtstring"LS0tLS1CRUdJTiBDRVJUSUZJQ0FURS0tLS0tCk1JSURlakNDQW1LZ0F3SUJBZ0lKQUwyem5UWlREUHFNTUEwR0NTcUdTSWIzRFFFQkN3VUFNQzB4S3pBcEJnTlYKQkFNTUlpb3VZMkpuYkhWMUxtUmxabUYxYkhRdWMzWmpMbU5zZFhOMFpYSXViRzlqWVd3d0hoY05NakF3TWpBMQpNRGt4T1RVeFdoY05NekF3TWpBeU1Ea3hPVFV4V2pBdE1Tc3dLUVlEVlFRRERDSXFMbU5pWjJ4MWRTNWtaV1poCmRXeDBMbk4yWXk1amJIVnpkR1Z5TG14dlkyRnNNSUlCSWpBTkJna3Foa2lHOXcwQkFRRUZBQU9DQVE4QU1JSUIKQ2dLQ0FRRUFycmQ5T3lvSnRsVzhnNW5nWlJtL2FKWjJ2eUtubGU3dVFIUEw4Q2RJa1RNdjB0eHZhR1B5UkNQQgo3RE00RTFkLzhMaU5takdZZk41QjZjWjlRUmNCaG1VNmFyUDRKZUZ3c0x0cTFGT3MxaDlmWGo3d3NzcTYrYmlkCjV6Umw3UEE0YmdvOXVkUVRzU1UrWDJUUVRDc0dxVVVPWExrZ3NCMjI0RDNsdkFCbmZOeHcvYnFQa2ZCQTFxVzYKVXpxellMdHN6WE5GY0dQMFhtU3c4WjJuaFhhUGlva2pPT2dyMkMrbVFZK0htQ2xGUWRpd2g2ZjBYR0V0STMrKwoyMStTejdXRkF6RlFBVUp2MHIvZnk4TDRXZzh1YysvalgwTGQrc2NoQTlNQjh3YmJORUp2ZjNMOGZ5QjZ0cTd2CjF4b0FnL0g0S1dJaHdqSEN0dFVnWU1oU0xWV3UrUUlEQVFBQm80R2NNSUdaTUIwR0ExVWREZ1FXQkJTWmQxWU0KVGNIRVZjSENNUmp6ejczZitEVmxxREJkQmdOVkhTTUVWakJVZ0JTWmQxWU1UY0hFVmNIQ01Sanp6NzNmK0RWbApxS0V4cEM4d0xURXJNQ2tHQTFVRUF3d2lLaTVqWW1kc2RYVXVaR1ZtWVhWc2RDNXpkbU11WTJ4MWMzUmxjaTVzCmIyTmhiSUlKQUwyem5UWlREUHFNTUF3R0ExVWRFd1FGTUFNQkFmOHdDd1lEVlIwUEJBUURBZ0VHTUEwR0NTcUcKU0liM0RRRUJDd1VBQTRJQkFRQk9meTVWSHlKZCtWUTBXaUQ1aSs2cmhidGNpSmtFN0YwWVVVZnJ6UFN2YWVFWQp2NElVWStWOC9UNnE4Mk9vVWU1eCtvS2dzbFBsL01nZEg2SW9CRnVtaUFqek14RTdUYUhHcXJ5dk13Qk5IKzB5CnhadG9mSnFXQzhGeUlwTVFHTEs0RVBGd3VHRlJnazZMRGR2ZEN5NVdxWW1MQWdBZVh5VWNaNnlHYkdMTjRPUDUKZTFiaEFiLzRXWXRxRHVydFJrWjNEejlZcis4VWNCVTRLT005OHBZN05aaXFmKzlCZVkvOEhZaVQ2Q0RRWWgyTgoyK0VWRFBHcFE4UkVsRThhN1ZLL29MemlOaXFyRjllNDV1OU1KdjM1ZktmNUJjK2FKdWduTGcwaUZUYmNaT1prCkpuYkUvUENIUDZFWmxLaEFiZUdnendtS1dDbTZTL3g0TklRK2JtMmoKLS0tLS1FTkQgQ0VSVElGSUNBVEUtLS0tLQo="Couchbase certificate authority string. This must be encoded using base64. This can also be found in your couchbase UI Security > Root Certificate. In mTLS setups this is not required.
config.configmap.gluuCouchbaseIndexNumReplicaint0The number of replicas per index created. Please note that the number of index nodes must be one greater than the number of index replicas. That means if your couchbase cluster only has 2 index nodes you cannot place the number of replicas to be higher than 1.
config.configmap.gluuCouchbasePassstring"P@ssw0rd"Couchbase password for the restricted user config.configmap.gluuCouchbaseUser that is often used inside the services. The password must contain one digit, one uppercase letter, one lower case letter and one symbol .
config.configmap.gluuCouchbasePassFilestring"/etc/gluu/conf/couchbase_password"The location of the Couchbase restricted user config.configmap.gluuCouchbaseUser password. The file path must end with couchbase_password
config.configmap.gluuCouchbaseSuperUserstring"admin"The Couchbase super user (admin) user name. This user is used during initialization only.
config.configmap.gluuCouchbaseSuperUserPassstring"P@ssw0rd"Couchbase password for the super user config.configmap.gluuCouchbaseSuperUser that is used during the initialization process. The password must contain one digit, one uppercase letter, one lower case letter and one symbol
config.configmap.gluuCouchbaseSuperUserPassFilestring"/etc/gluu/conf/couchbase_superuser_password"The location of the Couchbase restricted user config.configmap.gluuCouchbaseSuperUser password. The file path must end with couchbase_superuser_password.
config.configmap.gluuCouchbaseUrlstring"cbgluu.default.svc.cluster.local"Couchbase URL. Used only when global.gluuPersistenceType is hybrid or couchbase. This should be in FQDN format for either remote or local Couchbase clusters. The address can be an internal address inside the kubernetes cluster
config.configmap.gluuCouchbaseUserstring"gluu"Couchbase restricted user. Used only when global.gluuPersistenceType is hybrid or couchbase.
config.configmap.gluuDocumentStoreTypestring"DB"Document store type to use for shibboleth files JCA or LOCAL. Note that if JCA is selected Apache Jackrabbit will be used. Jackrabbit also enables loading custom files across all services easily.
config.configmap.gluuJackrabbitAdminIdstring"admin"Jackrabbit admin uid.
config.configmap.gluuJackrabbitAdminIdFilestring"/etc/gluu/conf/jackrabbit_admin_id"The location of the Jackrabbit admin uid config.gluuJackrabbitAdminId. The file path must end with jackrabbit_admin_id.
config.configmap.gluuJackrabbitAdminPassFilestring"/etc/gluu/conf/jackrabbit_admin_password"The location of the Jackrabbit admin password jackrabbit.secrets.gluuJackrabbitAdminPassword. The file path must end with jackrabbit_admin_password.
config.configmap.gluuJackrabbitPostgresDatabaseNamestring"jackrabbit"Jackrabbit postgres database name.
config.configmap.gluuJackrabbitPostgresHoststring"postgresql.postgres.svc.cluster.local"Postgres url
config.configmap.gluuJackrabbitPostgresPasswordFilestring"/etc/gluu/conf/postgres_password"The location of the Jackrabbit postgres password file jackrabbit.secrets.gluuJackrabbitPostgresPassword. The file path must end with postgres_password.
config.configmap.gluuJackrabbitPostgresPortint5432Jackrabbit Postgres port
config.configmap.gluuJackrabbitPostgresUserstring"jackrabbit"Jackrabbit Postgres uid
config.configmap.gluuJackrabbitSyncIntervalint300Interval between files sync (default to 300 seconds).
config.configmap.gluuJackrabbitUrlstring"http://jackrabbit:8080"Jackrabbit internal url. Normally left as default.
config.configmap.gluuLdapUrlstring"opendj:1636"OpenDJ internal address. Leave as default. Used when global.gluuPersistenceType is set to ldap.
config.configmap.gluuMaxRamPercentstring"75.0"Value passed to Java option -XX:MaxRAMPercentage
config.configmap.gluuOxauthBackendstring"oxauth:8080"oxAuth internal address. Leave as default.
config.configmap.gluuOxdAdminCertCnstring"oxd-server"OXD serve OAuth client admin certificate common name. This should be left to the default value client-api .
config.configmap.gluuOxdApplicationCertCnstring"oxd-server"OXD server OAuth client application certificate common name. This should be left to the default value client-api.
config.configmap.gluuOxdBindIpAddressesstring"*"OXD server bind address. This limits what ip ranges can access the client-api. This should be left as * and controlled by a NetworkPolicy
config.configmap.gluuOxdServerUrlstring"oxd-server:8443"OXD server Oauth client address. This should be left intact in kubernetes as it uses the internal address format.
config.configmap.gluuOxtrustApiEnabledboolfalseEnable oxTrust API
config.configmap.gluuOxtrustApiTestModeboolfalseEnable oxTrust API testmode
config.configmap.gluuOxtrustBackendstring"oxtrust:8080"oxTrust internal address. Leave as default.
config.configmap.gluuOxtrustConfigGenerationbooltrueWhether to generate oxShibboleth configuration or not (default to true).
config.configmap.gluuPassportEnabledboolfalseBoolean flag to enable/disable passport chart
config.configmap.gluuPassportFailureRedirectUrlstring""Allows passport failure redirect url to be specified.
config.configmap.gluuPersistenceLdapMappingstring"default"Specify data that should be saved in LDAP (one of default, user, cache, site, token, or session; default to default). Note this environment only takes effect when global.gluuPersistenceType is set to hybrid.
config.configmap.gluuRedisSentinelGroupstring""Redis Sentinel Group. Often set when config.configmap.gluuRedisType is set to SENTINEL. Can be used when config.configmap.gluuCacheType is set to REDIS.
config.configmap.gluuRedisSslTruststorestring""Redis SSL truststore. Optional. Can be used when config.configmap.gluuCacheType is set to REDIS.
config.configmap.gluuRedisTypestring"STANDALONE"Redis service type. STANDALONE or CLUSTER. Can be used when config.configmap.gluuCacheType is set to REDIS.
config.configmap.gluuRedisUrlstring"redis:6379"Redis URL and port number <url>:<port>. Can be used when config.configmap.gluuCacheType is set to REDIS.
config.configmap.gluuRedisUseSslstring"false"Boolean to use SSL in Redis. Can be used when config.configmap.gluuCacheType is set to REDIS.
config.configmap.gluuSamlEnabledboolfalseEnable SAML-related features; UI menu, etc.
config.configmap.gluuScimProtectionModestring"OAUTH"SCIM protection mode OAUTH
config.configmap.gluuSyncCasaManifestsboolfalseActivate manual Casa files sync - depreciated
config.configmap.gluuSyncShibManifestsboolfalseActivate manual Shib files sync - depreciated
config.configmap.lbAddrstring""Loadbalancer address for AWS if the FQDN is not registered.
config.countryCodestring"US"Country code. Used for certificate creation.
config.dnsConfigobject{}Add custom dns config
config.dnsPolicystring""Add custom dns policy
config.emailstring"support@gluu.com"Email address of the administrator usually. Used for certificate creation.
config.image.pullSecretslist[]Image Pull Secrets
config.image.repositorystring"gluufederation/config-init"Image to use for deploying.
config.image.tagstring"4.4.0-1"Image tag to use for deploying.
config.ldapPassstring"P@ssw0rd"LDAP admin password if OpennDJ is used for persistence.
config.migrationobject{"enabled":false,"migrationDataFormat":"ldif","migrationDir":"/ce-migration"}CE to CN Migration section
config.migration.enabledboolfalseBoolean flag to enable migration from CE
config.migration.migrationDataFormatstring"ldif"migration data-format depending on persistence backend. Supported data formats are ldif, couchbase+json, spanner+avro, postgresql+json, and mysql+json.
config.migration.migrationDirstring"/ce-migration"Directory holding all migration files
config.orgNamestring"Gluu"Organization name. Used for certificate creation.
config.redisPassstring"P@assw0rd"Redis admin password if config.configmap.gluuCacheType is set to REDIS.
config.resourcesobject{"limits":{"cpu":"300m","memory":"300Mi"},"requests":{"cpu":"300m","memory":"300Mi"}}Resource specs.
config.resources.limits.cpustring"300m"CPU limit.
config.resources.limits.memorystring"300Mi"Memory limit.
config.resources.requests.cpustring"300m"CPU request.
config.resources.requests.memorystring"300Mi"Memory request.
config.statestring"TX"State code. Used for certificate creation.
config.usrEnvsobject{"normal":{},"secret":{}}Add custom normal and secret envs to the service.
config.usrEnvs.normalobject{}Add custom normal envs to the service. variable1: value1
config.usrEnvs.secretobject{}Add custom secret envs to the service. variable1: value1
config.volumeMountslist[]Configure any additional volumesMounts that need to be attached to the containers
config.volumeslist[]Configure any additional volumes that need to be attached to the pod
KeyTypeDefaultDescription
nginx-ingressobject{"certManager":{"certificate":{"enabled":false,"issuerGroup":"cert-manager.io","issuerKind":"ClusterIssuer","issuerName":""}},"ingress":{"additionalAnnotations":{"kubernetes.io/ingress.class":"nginx"},"additionalLabels":{},"adminUiAdditionalAnnotations":{},"adminUiEnabled":true,"adminUiLabels":{},"authServerAdditionalAnnotations":{},"authServerEnabled":true,"authServerLabels":{},"casaAdditionalAnnotations":{},"casaEnabled":false,"casaLabels":{},"deviceCodeAdditionalAnnotations":{},"deviceCodeEnabled":true,"deviceCodeLabels":{},"enabled":true,"fido2ConfigAdditionalAnnotations":{},"fido2ConfigEnabled":false,"fido2ConfigLabels":{},"fido2Enabled":false,"fido2Labels":{},"firebaseMessagingAdditionalAnnotations":{},"firebaseMessagingEnabled":true,"firebaseMessagingLabels":{},"hosts":["demoexample.gluu.org"],"legacy":false,"openidAdditionalAnnotations":{},"openidConfigEnabled":true,"openidConfigLabels":{},"passportAdditionalAnnotations":{},"passportEnabled":false,"passportLabels":{},"path":"/","scimAdditionalAnnotations":{},"scimConfigAdditionalAnnotations":{},"scimConfigEnabled":false,"scimConfigLabels":{},"scimEnabled":false,"scimLabels":{},"shibAdditionalAnnotations":{},"shibEnabled":false,"shibLabels":{},"tls":[{"hosts":["demoexample.gluu.org"],"secretName":"tls-certificate"}],"u2fAdditionalAnnotations":{},"u2fConfigEnabled":true,"u2fConfigLabels":{},"uma2AdditionalAnnotations":{},"uma2ConfigEnabled":true,"uma2ConfigLabels":{},"webdiscoveryAdditionalAnnotations":{},"webdiscoveryEnabled":true,"webdiscoveryLabels":{},"webfingerAdditionalAnnotations":{},"webfingerEnabled":true,"webfingerLabels":{}}}Nginx ingress definitions chart
nginx-ingress.ingress.additionalAnnotationsobject{"kubernetes.io/ingress.class":"nginx"}Additional annotations that will be added across all ingress definitions in the format of {cert-manager.io/issuer: "letsencrypt-prod"}. key app is taken Enable client certificate authentication nginx.ingress.kubernetes.io/auth-tls-verify-client: "optional" Create the secret containing the trusted ca certificates nginx.ingress.kubernetes.io/auth-tls-secret: "gluu/tls-certificate" Specify the verification depth in the client certificates chain nginx.ingress.kubernetes.io/auth-tls-verify-depth: "1" Specify if certificates are passed to upstream server nginx.ingress.kubernetes.io/auth-tls-pass-certificate-to-upstream: "true"
nginx-ingress.ingress.additionalAnnotations."kubernetes.io/ingress.class"string"nginx"Required annotation below. Use kubernetes.io/ingress.class: "public" for microk8s.
nginx-ingress.ingress.additionalLabelsobject{}Additional labels that will be added across all ingress definitions in the format of {mylabel: "myapp"}
nginx-ingress.ingress.adminUiAdditionalAnnotationsobject{}Admin UI ingress resource additional annotations.
nginx-ingress.ingress.adminUiEnabledbooltrueEnable Admin UI endpoints /identity
nginx-ingress.ingress.adminUiLabelsobject{}Admin UI ingress resource labels. key app is taken.
nginx-ingress.ingress.authServerAdditionalAnnotationsobject{}Auth server ingress resource additional annotations.
nginx-ingress.ingress.authServerEnabledbooltrueEnable Auth server endpoints /oxauth
nginx-ingress.ingress.authServerLabelsobject{}Auth server config ingress resource labels. key app is taken
nginx-ingress.ingress.casaAdditionalAnnotationsobject{}Casa ingress resource additional annotations.
nginx-ingress.ingress.casaEnabledboolfalseEnable casa endpoints /casa
nginx-ingress.ingress.casaLabelsobject{}Casa ingress resource labels. key app is taken
nginx-ingress.ingress.deviceCodeAdditionalAnnotationsobject{}device-code ingress resource additional annotations.
nginx-ingress.ingress.deviceCodeEnabledbooltrueEnable endpoint /device-code
nginx-ingress.ingress.deviceCodeLabelsobject{}device-code ingress resource labels. key app is taken
nginx-ingress.ingress.fido2ConfigAdditionalAnnotationsobject{}fido2 config ingress resource additional annotations.
nginx-ingress.ingress.fido2ConfigEnabledboolfalseEnable endpoint /.well-known/fido2-configuration
nginx-ingress.ingress.fido2ConfigLabelsobject{}fido2 config ingress resource labels. key app is taken
nginx-ingress.ingress.fido2EnabledboolfalseEnable all fido2 endpoints
nginx-ingress.ingress.fido2Labelsobject{}fido2 ingress resource labels. key app is taken
nginx-ingress.ingress.firebaseMessagingAdditionalAnnotationsobject{}Firebase Messaging ingress resource additional annotations.
nginx-ingress.ingress.firebaseMessagingEnabledbooltrueEnable endpoint /firebase-messaging-sw.js
nginx-ingress.ingress.firebaseMessagingLabelsobject{}Firebase Messaging ingress resource labels. key app is taken
nginx-ingress.ingress.legacyboolfalseEnable use of legacy API version networking.k8s.io/v1beta1 to support kubernetes 1.18. This flag should be removed next version release along with nginx-ingress/templates/ingress-legacy.yaml.
nginx-ingress.ingress.openidAdditionalAnnotationsobject{}openid-configuration ingress resource additional annotations.
nginx-ingress.ingress.openidConfigEnabledbooltrueEnable endpoint /.well-known/openid-configuration
nginx-ingress.ingress.openidConfigLabelsobject{}openid-configuration ingress resource labels. key app is taken
nginx-ingress.ingress.passportAdditionalAnnotationsobject{}passport ingress resource additional annotations.
nginx-ingress.ingress.passportEnabledboolfalseEnable passport endpoints /idp
nginx-ingress.ingress.passportLabelsobject{}passport ingress resource labels. key app is taken.
nginx-ingress.ingress.scimAdditionalAnnotationsobject{}SCIM ingress resource additional annotations.
nginx-ingress.ingress.scimConfigAdditionalAnnotationsobject{}SCIM config ingress resource additional annotations.
nginx-ingress.ingress.scimConfigEnabledboolfalseEnable endpoint /.well-known/scim-configuration
nginx-ingress.ingress.scimConfigLabelsobject{}webdiscovery ingress resource labels. key app is taken
nginx-ingress.ingress.scimEnabledboolfalseEnable SCIM endpoints /scim
nginx-ingress.ingress.scimLabelsobject{}scim config ingress resource labels. key app is taken
nginx-ingress.ingress.shibAdditionalAnnotationsobject{}shibboleth ingress resource additional annotations.
nginx-ingress.ingress.shibEnabledboolfalseEnable shibboleth endpoints /idp
nginx-ingress.ingress.shibLabelsobject{}shibboleth ingress resource labels. key app is taken.
nginx-ingress.ingress.u2fAdditionalAnnotationsobject{}u2f config ingress resource additional annotations.
nginx-ingress.ingress.u2fConfigEnabledbooltrueEnable endpoint /.well-known/fido-configuration
nginx-ingress.ingress.u2fConfigLabelsobject{}u2f config ingress resource labels. key app is taken
nginx-ingress.ingress.uma2AdditionalAnnotationsobject{}uma2 config ingress resource additional annotations.
nginx-ingress.ingress.uma2ConfigEnabledbooltrueEnable endpoint /.well-known/uma2-configuration
nginx-ingress.ingress.uma2ConfigLabelsobject{}uma 2 config ingress resource labels. key app is taken
nginx-ingress.ingress.webdiscoveryAdditionalAnnotationsobject{}webdiscovery ingress resource additional annotations.
nginx-ingress.ingress.webdiscoveryEnabledbooltrueEnable endpoint /.well-known/simple-web-discovery
nginx-ingress.ingress.webdiscoveryLabelsobject{}webdiscovery ingress resource labels. key app is taken
nginx-ingress.ingress.webfingerAdditionalAnnotationsobject{}webfinger ingress resource additional annotations.
nginx-ingress.ingress.webfingerEnabledbooltrueEnable endpoint /.well-known/webfinger
nginx-ingress.ingress.webfingerLabelsobject{}webfinger ingress resource labels. key app is taken
KeyTypeDefaultDescription
jackrabbitobject{"additionalAnnotations":{},"additionalLabels":{},"clusterId":"","dnsConfig":{},"dnsPolicy":"","hpa":{"behavior":{},"enabled":true,"maxReplicas":10,"metrics":[],"minReplicas":1,"targetCPUUtilizationPercentage":50},"image":{"pullPolicy":"IfNotPresent","pullSecrets":[],"repository":"gluufederation/jackrabbit","tag":"4.4.0-1"},"livenessProbe":{"initialDelaySeconds":25,"periodSeconds":25,"tcpSocket":{"port":"http-jackrabbit"},"timeoutSeconds":5},"readinessProbe":{"initialDelaySeconds":30,"periodSeconds":30,"tcpSocket":{"port":"http-jackrabbit"},"timeoutSeconds":5},"replicas":1,"resources":{"limits":{"cpu":"1500m","memory":"1000Mi"},"requests":{"cpu":"1500m","memory":"1000Mi"}},"secrets":{"gluuJackrabbitAdminPass":"Test1234#","gluuJackrabbitPostgresPass":"P@ssw0rd"},"service":{"jackRabbitServiceName":"jackrabbit","name":"http-jackrabbit","port":8080},"storage":{"size":"5Gi"},"usrEnvs":{"normal":{},"secret":{}},"volumeMounts":[],"volumes":[]}Jackrabbit Oak is a complementary implementation of the JCR specification. It is an effort to implement a scalable and performant hierarchical content repository for use as the foundation of modern world-class web sites and other demanding content applications https://jackrabbit.apache.org/jcr/index.html
jackrabbit.additionalAnnotationsobject{}Additional annotations that will be added across the gateway in the format of {cert-manager.io/issuer: "letsencrypt-prod"}
jackrabbit.additionalLabelsobject{}Additional labels that will be added across the gateway in the format of {mylabel: "myapp"}
jackrabbit.clusterIdstring""This id needs to be unique to each kubernetes cluster in a multi cluster setup west, east, south, north, region ...etc If left empty it will be randomly generated.
jackrabbit.dnsConfigobject{}Add custom dns config
jackrabbit.dnsPolicystring""Add custom dns policy
jackrabbit.hpaobject{"behavior":{},"enabled":true,"maxReplicas":10,"metrics":[],"minReplicas":1,"targetCPUUtilizationPercentage":50}Configure the HorizontalPodAutoscaler
jackrabbit.hpa.behaviorobject{}Scaling Policies
jackrabbit.hpa.metricslist[]metrics if targetCPUUtilizationPercentage is not set
jackrabbit.image.pullPolicystring"IfNotPresent"Image pullPolicy to use for deploying.
jackrabbit.image.pullSecretslist[]Image Pull Secrets
jackrabbit.image.repositorystring"gluufederation/jackrabbit"Image to use for deploying.
jackrabbit.image.tagstring"4.4.0-1"Image tag to use for deploying.
jackrabbit.livenessProbeobject{"initialDelaySeconds":25,"periodSeconds":25,"tcpSocket":{"port":"http-jackrabbit"},"timeoutSeconds":5}Configure the liveness healthcheck for the Jackrabbit if needed.
jackrabbit.livenessProbe.tcpSocketobject{"port":"http-jackrabbit"}Executes tcp healthcheck.
jackrabbit.readinessProbeobject{"initialDelaySeconds":30,"periodSeconds":30,"tcpSocket":{"port":"http-jackrabbit"},"timeoutSeconds":5}Configure the readiness healthcheck for the Jackrabbit if needed.
jackrabbit.readinessProbe.tcpSocketobject{"port":"http-jackrabbit"}Executes tcp healthcheck.
jackrabbit.replicasint1Service replica number.
jackrabbit.resourcesobject{"limits":{"cpu":"1500m","memory":"1000Mi"},"requests":{"cpu":"1500m","memory":"1000Mi"}}Resource specs.
jackrabbit.resources.limits.cpustring"1500m"CPU limit.
jackrabbit.resources.limits.memorystring"1000Mi"Memory limit.
jackrabbit.resources.requests.cpustring"1500m"CPU request.
jackrabbit.resources.requests.memorystring"1000Mi"Memory request.
jackrabbit.secrets.gluuJackrabbitAdminPassstring"Test1234#"Jackrabbit admin uid password
jackrabbit.secrets.gluuJackrabbitPostgresPassstring"P@ssw0rd"Jackrabbit Postgres uid password
jackrabbit.service.jackRabbitServiceNamestring"jackrabbit"Name of the Jackrabbit service. Please keep it as default.
jackrabbit.service.namestring"http-jackrabbit"The name of the jackrabbit port within the jackrabbit service. Please keep it as default.
jackrabbit.service.portint8080Port of the jackrabbit service. Please keep it as default.
jackrabbit.storage.sizestring"5Gi"Jackrabbit volume size
jackrabbit.usrEnvsobject{"normal":{},"secret":{}}Add custom normal and secret envs to the service
jackrabbit.usrEnvs.normalobject{}Add custom normal envs to the service variable1: value1
jackrabbit.usrEnvs.secretobject{}Add custom secret envs to the service variable1: value1
jackrabbit.volumeMountslist[]Configure any additional volumesMounts that need to be attached to the containers
jackrabbit.volumeslist[]Configure any additional volumes that need to be attached to the pod
KeyTypeDefaultDescription
opendjobject{"additionalAnnotations":{},"additionalLabels":{},"backup":{"cronJobSchedule":"*/59 * * * *","enabled":true},"dnsConfig":{},"dnsPolicy":"","hpa":{"behavior":{},"enabled":true,"maxReplicas":10,"metrics":[],"minReplicas":1,"targetCPUUtilizationPercentage":50},"image":{"pullPolicy":"IfNotPresent","pullSecrets":[],"repository":"gluufederation/opendj","tag":"4.4.0-1"},"livenessProbe":{"exec":{"command":["python3","/app/scripts/healthcheck.py"]},"failureThreshold":20,"initialDelaySeconds":30,"periodSeconds":30,"timeoutSeconds":5},"multiCluster":{"clusterId":"","enabled":false,"namespaceIntId":0,"replicaCount":1,"serfAdvertiseAddrSuffix":"regional.gluu.org","serfKey":"Z51b6PgKU1MZ75NCZOTGGoc0LP2OF3qvF6sjxHyQCYk=","serfPeers":["gluu-opendj-regional-0-regional.gluu.org:30946","gluu-opendj-regional-0-regional.gluu.org:31946"]},"persistence":{"size":"5Gi"},"ports":{"tcp-admin":{"nodePort":"","port":4444,"protocol":"TCP","targetPort":4444},"tcp-ldap":{"nodePort":"","port":1389,"protocol":"TCP","targetPort":1389},"tcp-ldaps":{"nodePort":"","port":1636,"protocol":"TCP","targetPort":1636},"tcp-repl":{"nodePort":"","port":8989,"protocol":"TCP","targetPort":8989},"tcp-serf":{"nodePort":"","port":7946,"protocol":"TCP","targetPort":7946},"udp-serf":{"nodePort":"","port":7946,"protocol":"UDP","targetPort":7946}},"readinessProbe":{"failureThreshold":20,"initialDelaySeconds":60,"periodSeconds":25,"tcpSocket":{"port":1636},"timeoutSeconds":5},"replicas":1,"resources":{"limits":{"cpu":"1500m","memory":"2000Mi"},"requests":{"cpu":"1500m","memory":"2000Mi"}},"usrEnvs":{"normal":{},"secret":{}},"volumeMounts":[],"volumes":[]}OpenDJ is a directory server which implements a wide range of Lightweight Directory Access Protocol and related standards, including full compliance with LDAPv3 but also support for Directory Service Markup Language (DSMLv2).Written in Java, OpenDJ offers multi-master replication, access control, and many extensions.
opendj.additionalAnnotationsobject{}Additional annotations that will be added across all resources in the format of {cert-manager.io/issuer: "letsencrypt-prod"}. key app is taken
opendj.additionalLabelsobject{}Additional labels that will be added across all resources definitions in the format of {mylabel: "myapp"}
opendj.backupobject{"cronJobSchedule":"*/59 * * * *","enabled":true}Configure ldap backup cronjob
opendj.dnsConfigobject{}Add custom dns config
opendj.dnsPolicystring""Add custom dns policy
opendj.hpaobject{"behavior":{},"enabled":true,"maxReplicas":10,"metrics":[],"minReplicas":1,"targetCPUUtilizationPercentage":50}Configure the HorizontalPodAutoscaler
opendj.hpa.behaviorobject{}Scaling Policies
opendj.hpa.metricslist[]metrics if targetCPUUtilizationPercentage is not set
opendj.image.pullPolicystring"IfNotPresent"Image pullPolicy to use for deploying.
opendj.image.pullSecretslist[]Image Pull Secrets
opendj.image.repositorystring"gluufederation/opendj"Image to use for deploying.
opendj.image.tagstring"4.4.0-1"Image tag to use for deploying.
opendj.livenessProbeobject{"exec":{"command":["python3","/app/scripts/healthcheck.py"]},"failureThreshold":20,"initialDelaySeconds":30,"periodSeconds":30,"timeoutSeconds":5}Configure the liveness healthcheck for OpenDJ if needed. https://github.com/GluuFederation/docker-opendj/blob/4.4/scripts/healthcheck.py
opendj.livenessProbe.execobject{"command":["python3","/app/scripts/healthcheck.py"]}Executes the python3 healthcheck.
opendj.multiCluster.clusterIdstring""This id needs to be unique to each kubernetes cluster in a multi cluster setup west, east, south, north, region ...etc If left empty it will be randomly generated.
opendj.multiCluster.enabledboolfalseEnable OpenDJ multiCluster mode. This flag enables loading keys under opendj.multiCluster
opendj.multiCluster.namespaceIntIdint0Namespace int id. This id needs to be a unique number 0-9 per gluu installation per namespace. Used when gluu is installed in the same kubernetes cluster more than once.
opendj.multiCluster.replicaCountint1The number of opendj non scalabble statefulsets to create. Each pod created must be resolvable as it follows the patterm RELEASE-NAME-opendj-regional-{{statefulset pod number}}-{{ $.Values.multiCluster.serfAdvertiseAddrSuffix }} If set to 1, with a release name of gluu, the address of the pod would be gluu-opendj-regional-0-regional.gluu.org
opendj.multiCluster.serfAdvertiseAddrSuffixstring"regional.gluu.org"OpenDJ Serf advertise address for the cluster
opendj.multiCluster.serfKeystring"Z51b6PgKU1MZ75NCZOTGGoc0LP2OF3qvF6sjxHyQCYk="Serf key. This key will automatically sync across clusters.
opendj.multiCluster.serfPeerslist["gluu-opendj-regional-0-regional.gluu.org:30946","gluu-opendj-regional-0-regional.gluu.org:31946"]Serf peer addresses. One per cluster.
opendj.persistence.sizestring"5Gi"OpenDJ volume size
opendj.portsobject{"tcp-admin":{"nodePort":"","port":4444,"protocol":"TCP","targetPort":4444},"tcp-ldap":{"nodePort":"","port":1389,"protocol":"TCP","targetPort":1389},"tcp-ldaps":{"nodePort":"","port":1636,"protocol":"TCP","targetPort":1636},"tcp-repl":{"nodePort":"","port":8989,"protocol":"TCP","targetPort":8989},"tcp-serf":{"nodePort":"","port":7946,"protocol":"TCP","targetPort":7946},"udp-serf":{"nodePort":"","port":7946,"protocol":"UDP","targetPort":7946}}servicePorts values used in StatefulSet container
opendj.readinessProbeobject{"failureThreshold":20,"initialDelaySeconds":60,"periodSeconds":25,"tcpSocket":{"port":1636},"timeoutSeconds":5}Configure the readiness healthcheck for OpenDJ if needed. https://github.com/GluuFederation/docker-opendj/blob/4.4/scripts/healthcheck.py
opendj.replicasint1Service replica number.
opendj.resourcesobject{"limits":{"cpu":"1500m","memory":"2000Mi"},"requests":{"cpu":"1500m","memory":"2000Mi"}}Resource specs.
opendj.resources.limits.cpustring"1500m"CPU limit.
opendj.resources.limits.memorystring"2000Mi"Memory limit.
opendj.resources.requests.cpustring"1500m"CPU request.
opendj.resources.requests.memorystring"2000Mi"Memory request.
opendj.usrEnvsobject{"normal":{},"secret":{}}Add custom normal and secret envs to the service
opendj.usrEnvs.normalobject{}Add custom normal envs to the service variable1: value1
opendj.usrEnvs.secretobject{}Add custom secret envs to the service variable1: value1
opendj.volumeMountslist[]Configure any additional volumesMounts that need to be attached to the containers
opendj.volumeslist[]Configure any additional volumes that need to be attached to the pod
KeyTypeDefaultDescription
persistenceobject{"additionalAnnotations":{},"additionalLabels":{},"dnsConfig":{},"dnsPolicy":"","image":{"pullPolicy":"IfNotPresent","pullSecrets":[],"repository":"gluufederation/persistence","tag":"4.4.0-1"},"resources":{"limits":{"cpu":"300m","memory":"300Mi"},"requests":{"cpu":"300m","memory":"300Mi"}},"usrEnvs":{"normal":{},"secret":{}},"volumeMounts":[],"volumes":[]}Job to generate data and initial config for Gluu Server persistence layer.
persistence.additionalAnnotationsobject{}Additional annotations that will be added across all resources in the format of {cert-manager.io/issuer: "letsencrypt-prod"}. key app is taken
persistence.additionalLabelsobject{}Additional labels that will be added across all resources definitions in the format of {mylabel: "myapp"}
persistence.dnsConfigobject{}Add custom dns config
persistence.dnsPolicystring""Add custom dns policy
persistence.image.pullPolicystring"IfNotPresent"Image pullPolicy to use for deploying.
persistence.image.pullSecretslist[]Image Pull Secrets
persistence.image.repositorystring"gluufederation/persistence"Image to use for deploying.
persistence.image.tagstring"4.4.0-1"Image tag to use for deploying.
persistence.resourcesobject{"limits":{"cpu":"300m","memory":"300Mi"},"requests":{"cpu":"300m","memory":"300Mi"}}Resource specs.
persistence.resources.limits.cpustring"300m"CPU limit
persistence.resources.limits.memorystring"300Mi"Memory limit.
persistence.resources.requests.cpustring"300m"CPU request.
persistence.resources.requests.memorystring"300Mi"Memory request.
persistence.usrEnvsobject{"normal":{},"secret":{}}Add custom normal and secret envs to the service
persistence.usrEnvs.normalobject{}Add custom normal envs to the service variable1: value1
persistence.usrEnvs.secretobject{}Add custom secret envs to the service variable1: value1
persistence.volumeMountslist[]Configure any additional volumesMounts that need to be attached to the containers
persistence.volumeslist[]Configure any additional volumes that need to be attached to the pod
KeyTypeDefaultDescription
oxauthobject{"additionalAnnotations":{},"additionalLabels":{},"dnsConfig":{},"dnsPolicy":"","hpa":{"behavior":{},"enabled":true,"maxReplicas":10,"metrics":[],"minReplicas":1,"targetCPUUtilizationPercentage":50},"image":{"pullPolicy":"IfNotPresent","pullSecrets":[],"repository":"gluufederation/oxauth","tag":"4.4.0-1"},"livenessProbe":{"exec":{"command":["python3","/app/scripts/healthcheck.py"]},"initialDelaySeconds":30,"periodSeconds":30,"timeoutSeconds":5},"readinessProbe":{"exec":{"command":["python3","/app/scripts/healthcheck.py"]},"initialDelaySeconds":25,"periodSeconds":25,"timeoutSeconds":5},"replicas":1,"resources":{"limits":{"cpu":"2500m","memory":"2500Mi"},"requests":{"cpu":"2500m","memory":"2500Mi"}},"service":{"name":"http-oxauth","oxAuthServiceName":"oxauth","port":8080},"usrEnvs":{"normal":{},"secret":{}},"volumeMounts":[],"volumes":[]}OAuth Authorization Server, the OpenID Connect Provider, the UMA Authorization Server--this is the main Internet facing component of Gluu. It's the service that returns tokens, JWT's and identity assertions. This service must be Internet facing.
oxauth-key-rotationobject{"additionalAnnotations":{},"additionalLabels":{},"dnsConfig":{},"dnsPolicy":"","image":{"pullPolicy":"IfNotPresent","pullSecrets":[],"repository":"gluufederation/certmanager","tag":"4.4.0-1"},"keysLife":48,"resources":{"limits":{"cpu":"300m","memory":"300Mi"},"requests":{"cpu":"300m","memory":"300Mi"}},"usrEnvs":{"normal":{},"secret":{}},"volumeMounts":[],"volumes":[]}Responsible for regenerating auth-keys per x hours
oxauth-key-rotation.additionalAnnotationsobject{}Additional annotations that will be added across all resources in the format of {cert-manager.io/issuer: "letsencrypt-prod"}. key app is taken
oxauth-key-rotation.additionalLabelsobject{}Additional labels that will be added across all resources definitions in the format of {mylabel: "myapp"}
oxauth-key-rotation.dnsConfigobject{}Add custom dns config
oxauth-key-rotation.dnsPolicystring""Add custom dns policy
oxauth-key-rotation.image.pullPolicystring"IfNotPresent"Image pullPolicy to use for deploying.
oxauth-key-rotation.image.pullSecretslist[]Image Pull Secrets
oxauth-key-rotation.image.repositorystring"gluufederation/certmanager"Image to use for deploying.
oxauth-key-rotation.image.tagstring"4.4.0-1"Image tag to use for deploying.
oxauth-key-rotation.keysLifeint48Auth server key rotation keys life in hours
oxauth-key-rotation.resourcesobject{"limits":{"cpu":"300m","memory":"300Mi"},"requests":{"cpu":"300m","memory":"300Mi"}}Resource specs.
oxauth-key-rotation.resources.limits.cpustring"300m"CPU limit.
oxauth-key-rotation.resources.limits.memorystring"300Mi"Memory limit.
oxauth-key-rotation.resources.requests.cpustring"300m"CPU request.
oxauth-key-rotation.resources.requests.memorystring"300Mi"Memory request.
oxauth-key-rotation.usrEnvsobject{"normal":{},"secret":{}}Add custom normal and secret envs to the service
oxauth-key-rotation.usrEnvs.normalobject{}Add custom normal envs to the service variable1: value1
oxauth-key-rotation.usrEnvs.secretobject{}Add custom secret envs to the service variable1: value1
oxauth-key-rotation.volumeMountslist[]Configure any additional volumesMounts that need to be attached to the containers
oxauth-key-rotation.volumeslist[]Configure any additional volumes that need to be attached to the pod
oxauth.additionalAnnotationsobject{}Additional annotations that will be added across all resources in the format of {cert-manager.io/issuer: "letsencrypt-prod"}. key app is taken
oxauth.additionalLabelsobject{}Additional labels that will be added across all resources definitions in the format of {mylabel: "myapp"}
oxauth.dnsConfigobject{}Add custom dns config
oxauth.dnsPolicystring""Add custom dns policy
oxauth.hpaobject{"behavior":{},"enabled":true,"maxReplicas":10,"metrics":[],"minReplicas":1,"targetCPUUtilizationPercentage":50}Configure the HorizontalPodAutoscaler
oxauth.hpa.behaviorobject{}Scaling Policies
oxauth.hpa.metricslist[]metrics if targetCPUUtilizationPercentage is not set
oxauth.image.pullPolicystring"IfNotPresent"Image pullPolicy to use for deploying.
oxauth.image.pullSecretslist[]Image Pull Secrets
oxauth.image.repositorystring"gluufederation/oxauth"Image to use for deploying.
oxauth.image.tagstring"4.4.0-1"Image tag to use for deploying.
oxauth.livenessProbeobject{"exec":{"command":["python3","/app/scripts/healthcheck.py"]},"initialDelaySeconds":30,"periodSeconds":30,"timeoutSeconds":5}Configure the liveness healthcheck for the auth server if needed.
oxauth.livenessProbe.execobject{"command":["python3","/app/scripts/healthcheck.py"]}Executes the python3 healthcheck. https://github.com/GluuFederation/docker-oxauth/blob/4.4/scripts/healthcheck.py
oxauth.readinessProbeobject{"exec":{"command":["python3","/app/scripts/healthcheck.py"]},"initialDelaySeconds":25,"periodSeconds":25,"timeoutSeconds":5}Configure the readiness healthcheck for the auth server if needed. https://github.com/GluuFederation/docker-oxauth/blob/4.4/scripts/healthcheck.py
oxauth.replicasint1Service replica number.
oxauth.resourcesobject{"limits":{"cpu":"2500m","memory":"2500Mi"},"requests":{"cpu":"2500m","memory":"2500Mi"}}Resource specs.
oxauth.resources.limits.cpustring"2500m"CPU limit.
oxauth.resources.limits.memorystring"2500Mi"Memory limit.
oxauth.resources.requests.cpustring"2500m"CPU request.
oxauth.resources.requests.memorystring"2500Mi"Memory request.
oxauth.service.namestring"http-oxauth"The name of the oxauth port within the oxauth service. Please keep it as default.
oxauth.service.oxAuthServiceNamestring"oxauth"Name of the oxauth service. Please keep it as default.
oxauth.service.portint8080Port of the oxauth service. Please keep it as default.
oxauth.usrEnvsobject{"normal":{},"secret":{}}Add custom normal and secret envs to the service
oxauth.usrEnvs.normalobject{}Add custom normal envs to the service variable1: value1
oxauth.usrEnvs.secretobject{}Add custom secret envs to the service variable1: value1
oxauth.volumeMountslist[]Configure any additional volumesMounts that need to be attached to the containers
oxauth.volumeslist[]Configure any additional volumes that need to be attached to the pod
KeyTypeDefaultDescription
oxtrustobject{"additionalAnnotations":{},"additionalLabels":{},"dnsConfig":{},"dnsPolicy":"","hpa":{"behavior":{},"enabled":true,"maxReplicas":10,"metrics":[],"minReplicas":1,"targetCPUUtilizationPercentage":50},"image":{"pullPolicy":"IfNotPresent","pullSecrets":[],"repository":"gluufederation/oxtrust","tag":"4.4.0-1"},"livenessProbe":{"exec":{"command":["python3","/app/scripts/healthcheck.py"]},"initialDelaySeconds":30,"periodSeconds":30,"timeoutSeconds":5},"readinessProbe":{"exec":{"command":["python3","/app/scripts/healthcheck.py"]},"initialDelaySeconds":25,"periodSeconds":25,"timeoutSeconds":5},"replicas":1,"resources":{"limits":{"cpu":"2500m","memory":"2500Mi"},"requests":{"cpu":"2500m","memory":"2500Mi"}},"service":{"clusterIp":"None","name":"http-oxtrust","oxTrustServiceName":"oxtrust","port":8080},"usrEnvs":{"normal":{},"secret":{}},"volumeMounts":[],"volumes":[]}Gluu Admin UI. This shouldn't be internet facing.
oxtrust.additionalAnnotationsobject{}Additional annotations that will be added across all resources in the format of {cert-manager.io/issuer: "letsencrypt-prod"}. key app is taken
oxtrust.additionalLabelsobject{}Additional labels that will be added across all resources definitions in the format of {mylabel: "myapp"}
oxtrust.dnsConfigobject{}Add custom dns config
oxtrust.dnsPolicystring""Add custom dns policy
oxtrust.hpaobject{"behavior":{},"enabled":true,"maxReplicas":10,"metrics":[],"minReplicas":1,"targetCPUUtilizationPercentage":50}Configure the HorizontalPodAutoscaler
oxtrust.hpa.behaviorobject{}Scaling Policies
oxtrust.hpa.metricslist[]metrics if targetCPUUtilizationPercentage is not set
oxtrust.image.pullPolicystring"IfNotPresent"Image pullPolicy to use for deploying.
oxtrust.image.pullSecretslist[]Image Pull Secrets
oxtrust.image.repositorystring"gluufederation/oxtrust"Image to use for deploying.
oxtrust.image.tagstring"4.4.0-1"Image tag to use for deploying.
oxtrust.livenessProbeobject{"exec":{"command":["python3","/app/scripts/healthcheck.py"]},"initialDelaySeconds":30,"periodSeconds":30,"timeoutSeconds":5}Configure the liveness healthcheck for the auth server if needed.
oxtrust.livenessProbe.execobject{"command":["python3","/app/scripts/healthcheck.py"]}Executes the python3 healthcheck. https://github.com/GluuFederation/docker-oxauth/blob/4.4/scripts/healthcheck.py
oxtrust.readinessProbeobject{"exec":{"command":["python3","/app/scripts/healthcheck.py"]},"initialDelaySeconds":25,"periodSeconds":25,"timeoutSeconds":5}Configure the readiness healthcheck for the auth server if needed. https://github.com/GluuFederation/docker-oxauth/blob/4.4/scripts/healthcheck.py
oxtrust.replicasint1Service replica number.
oxtrust.resourcesobject{"limits":{"cpu":"2500m","memory":"2500Mi"},"requests":{"cpu":"2500m","memory":"2500Mi"}}Resource specs.
oxtrust.resources.limits.cpustring"2500m"CPU limit.
oxtrust.resources.limits.memorystring"2500Mi"Memory limit.
oxtrust.resources.requests.cpustring"2500m"CPU request.
oxtrust.resources.requests.memorystring"2500Mi"Memory request.
oxtrust.service.namestring"http-oxtrust"The name of the oxtrust port within the oxtrust service. Please keep it as default.
oxtrust.service.oxTrustServiceNamestring"oxtrust"Name of the oxtrust service. Please keep it as default.
oxtrust.service.portint8080Port of the oxtrust service. Please keep it as default.
oxtrust.usrEnvsobject{"normal":{},"secret":{}}Add custom normal and secret envs to the service
oxtrust.usrEnvs.normalobject{}Add custom normal envs to the service variable1: value1
oxtrust.usrEnvs.secretobject{}Add custom secret envs to the service variable1: value1
oxtrust.volumeMountslist[]Configure any additional volumesMounts that need to be attached to the containers
oxtrust.volumeslist[]Configure any additional volumes that need to be attached to the pod
KeyTypeDefaultDescription
fido2object{"additionalAnnotations":{},"additionalLabels":{},"dnsConfig":{},"dnsPolicy":"","hpa":{"behavior":{},"enabled":true,"maxReplicas":10,"metrics":[],"minReplicas":1,"targetCPUUtilizationPercentage":50},"image":{"pullPolicy":"IfNotPresent","pullSecrets":[],"repository":"gluufederation/fido2","tag":"4.4.0-1"},"livenessProbe":{"httpGet":{"path":"/fido2/restv1/configuration","port":"http-fido2"},"initialDelaySeconds":25,"periodSeconds":25,"timeoutSeconds":5},"readinessProbe":{"httpGet":{"path":"/fido2/restv1/configuration","port":"http-fido2"},"initialDelaySeconds":30,"periodSeconds":30,"timeoutSeconds":5},"replicas":1,"resources":{"limits":{"cpu":"500m","memory":"500Mi"},"requests":{"cpu":"500m","memory":"500Mi"}},"service":{"fido2ServiceName":"fido2","name":"http-fido2","port":8080},"usrEnvs":{"normal":{},"secret":{}},"volumeMounts":[],"volumes":[]}FIDO 2.0 (FIDO2) is an open authentication standard that enables leveraging common devices to authenticate to online services in both mobile and desktop environments.
fido2.additionalAnnotationsobject{}Additional annotations that will be added across all resources in the format of {cert-manager.io/issuer: "letsencrypt-prod"}. key app is taken
fido2.additionalLabelsobject{}Additional labels that will be added across all resources definitions in the format of {mylabel: "myapp"}
fido2.dnsConfigobject{}Add custom dns config
fido2.dnsPolicystring""Add custom dns policy
fido2.hpaobject{"behavior":{},"enabled":true,"maxReplicas":10,"metrics":[],"minReplicas":1,"targetCPUUtilizationPercentage":50}Configure the HorizontalPodAutoscaler
fido2.hpa.behaviorobject{}Scaling Policies
fido2.hpa.metricslist[]metrics if targetCPUUtilizationPercentage is not set
fido2.image.pullPolicystring"IfNotPresent"Image pullPolicy to use for deploying.
fido2.image.pullSecretslist[]Image Pull Secrets
fido2.image.repositorystring"gluufederation/fido2"Image to use for deploying.
fido2.image.tagstring"4.4.0-1"Image tag to use for deploying.
fido2.livenessProbeobject{"httpGet":{"path":"/fido2/restv1/configuration","port":"http-fido2"},"initialDelaySeconds":25,"periodSeconds":25,"timeoutSeconds":5}Configure the liveness healthcheck for the fido2 if needed.
fido2.livenessProbe.httpGetobject{"path":"/fido2/restv1/configuration","port":"http-fido2"}http liveness probe endpoint
fido2.readinessProbeobject{"httpGet":{"path":"/fido2/restv1/configuration","port":"http-fido2"},"initialDelaySeconds":30,"periodSeconds":30,"timeoutSeconds":5}Configure the readiness healthcheck for the fido2 if needed.
fido2.replicasint1Service replica number.
fido2.resourcesobject{"limits":{"cpu":"500m","memory":"500Mi"},"requests":{"cpu":"500m","memory":"500Mi"}}Resource specs.
fido2.resources.limits.cpustring"500m"CPU limit.
fido2.resources.limits.memorystring"500Mi"Memory limit.
fido2.resources.requests.cpustring"500m"CPU request.
fido2.resources.requests.memorystring"500Mi"Memory request.
fido2.service.fido2ServiceNamestring"fido2"Name of the fido2 service. Please keep it as default.
fido2.service.namestring"http-fido2"The name of the fido2 port within the fido2 service. Please keep it as default.
fido2.service.portint8080Port of the fido2 service. Please keep it as default.
fido2.usrEnvsobject{"normal":{},"secret":{}}Add custom normal and secret envs to the service
fido2.usrEnvs.normalobject{}Add custom normal envs to the service variable1: value1
fido2.usrEnvs.secretobject{}Add custom secret envs to the service variable1: value1
fido2.volumeMountslist[]Configure any additional volumesMounts that need to be attached to the containers
fido2.volumeslist[]Configure any additional volumes that need to be attached to the pod
KeyTypeDefaultDescription
scimobject{"additionalAnnotations":{},"additionalLabels":{},"dnsConfig":{},"dnsPolicy":"","hpa":{"behavior":{},"enabled":true,"maxReplicas":10,"metrics":[],"minReplicas":1,"targetCPUUtilizationPercentage":50},"image":{"pullPolicy":"IfNotPresent","pullSecrets":[],"repository":"gluufederation/scim","tag":"4.4.0-1"},"livenessProbe":{"httpGet":{"path":"/scim/restv1/scim/v2/ServiceProviderConfig","port":8080},"initialDelaySeconds":30,"periodSeconds":30,"timeoutSeconds":5},"readinessProbe":{"httpGet":{"path":"/scim/restv1/scim/v2/ServiceProviderConfig","port":8080},"initialDelaySeconds":25,"periodSeconds":25,"timeoutSeconds":5},"replicas":1,"resources":{"limits":{"cpu":"1000m","memory":"1000Mi"},"requests":{"cpu":"1000m","memory":"1000Mi"}},"service":{"name":"http-scim","port":8080,"scimServiceName":"scim"},"usrEnvs":{"normal":{},"secret":{}},"volumeMounts":[],"volumes":[]}System for Cross-domain Identity Management (SCIM) version 2.0
scim.additionalAnnotationsobject{}Additional annotations that will be added across all resources in the format of {cert-manager.io/issuer: "letsencrypt-prod"}. key app is taken
scim.additionalLabelsobject{}Additional labels that will be added across all resources definitions in the format of {mylabel: "myapp"}
scim.dnsConfigobject{}Add custom dns config
scim.dnsPolicystring""Add custom dns policy
scim.hpaobject{"behavior":{},"enabled":true,"maxReplicas":10,"metrics":[],"minReplicas":1,"targetCPUUtilizationPercentage":50}Configure the HorizontalPodAutoscaler
scim.hpa.behaviorobject{}Scaling Policies
scim.hpa.metricslist[]metrics if targetCPUUtilizationPercentage is not set
scim.image.pullPolicystring"IfNotPresent"Image pullPolicy to use for deploying.
scim.image.pullSecretslist[]Image Pull Secrets
scim.image.repositorystring"gluufederation/scim"Image to use for deploying.
scim.image.tagstring"4.4.0-1"Image tag to use for deploying.
scim.livenessProbeobject{"httpGet":{"path":"/scim/restv1/scim/v2/ServiceProviderConfig","port":8080},"initialDelaySeconds":30,"periodSeconds":30,"timeoutSeconds":5}Configure the liveness healthcheck for SCIM if needed.
scim.livenessProbe.httpGet.pathstring"/scim/restv1/scim/v2/ServiceProviderConfig"http liveness probe endpoint
scim.readinessProbeobject{"httpGet":{"path":"/scim/restv1/scim/v2/ServiceProviderConfig","port":8080},"initialDelaySeconds":25,"periodSeconds":25,"timeoutSeconds":5}Configure the readiness healthcheck for the SCIM if needed.
scim.readinessProbe.httpGet.pathstring"/scim/restv1/scim/v2/ServiceProviderConfig"http readiness probe endpoint
scim.replicasint1Service replica number.
scim.resources.limits.cpustring"1000m"CPU limit.
scim.resources.limits.memorystring"1000Mi"Memory limit.
scim.resources.requests.cpustring"1000m"CPU request.
scim.resources.requests.memorystring"1000Mi"Memory request.
scim.service.namestring"http-scim"The name of the scim port within the scim service. Please keep it as default.
scim.service.portint8080Port of the scim service. Please keep it as default.
scim.service.scimServiceNamestring"scim"Name of the scim service. Please keep it as default.
scim.usrEnvsobject{"normal":{},"secret":{}}Add custom normal and secret envs to the service
scim.usrEnvs.normalobject{}Add custom normal envs to the service variable1: value1
scim.usrEnvs.secretobject{}Add custom secret envs to the service variable1: value1
scim.volumeMountslist[]Configure any additional volumesMounts that need to be attached to the containers
scim.volumeslist[]Configure any additional volumes that need to be attached to the pod
KeyTypeDefaultDescription
oxd-serverobject{"additionalAnnotations":{},"additionalLabels":{},"dnsConfig":{},"dnsPolicy":"","hpa":{"behavior":{},"enabled":true,"maxReplicas":10,"metrics":[],"minReplicas":1,"targetCPUUtilizationPercentage":50},"image":{"pullPolicy":"IfNotPresent","pullSecrets":[],"repository":"gluufederation/oxd-server","tag":"4.4.0-1"},"livenessProbe":{"exec":{"command":["curl","-k","https://localhost:8443/health-check"]},"initialDelaySeconds":30,"periodSeconds":30,"timeoutSeconds":5},"readinessProbe":{"exec":{"command":["curl","-k","https://localhost:8443/health-check"]},"initialDelaySeconds":25,"periodSeconds":25,"timeoutSeconds":5},"replicas":1,"resources":{"limits":{"cpu":"1000m","memory":"400Mi"},"requests":{"cpu":"1000m","memory":"400Mi"}},"service":{"oxdServerServiceName":"oxd-server"},"usrEnvs":{"normal":{},"secret":{}},"volumeMounts":[],"volumes":[]}Middleware API to help application developers call an OAuth, OpenID or UMA server. You may wonder why this is necessary. It makes it easier for client developers to use OpenID signing and encryption features, without becoming crypto experts. This API provides some high level endpoints to do some of the heavy lifting.
oxd-server.additionalAnnotationsobject{}Additional annotations that will be added across all resources in the format of {cert-manager.io/issuer: "letsencrypt-prod"}. key app is taken
oxd-server.additionalLabelsobject{}Additional labels that will be added across all resources definitions in the format of {mylabel: "myapp"}
oxd-server.dnsConfigobject{}Add custom dns config
oxd-server.dnsPolicystring""Add custom dns policy
oxd-server.hpaobject{"behavior":{},"enabled":true,"maxReplicas":10,"metrics":[],"minReplicas":1,"targetCPUUtilizationPercentage":50}Configure the HorizontalPodAutoscaler
oxd-server.hpa.behaviorobject{}Scaling Policies
oxd-server.hpa.metricslist[]metrics if targetCPUUtilizationPercentage is not set
oxd-server.image.pullPolicystring"IfNotPresent"Image pullPolicy to use for deploying.
oxd-server.image.pullSecretslist[]Image Pull Secrets
oxd-server.image.repositorystring"gluufederation/oxd-server"Image to use for deploying.
oxd-server.image.tagstring"4.4.0-1"Image tag to use for deploying.
oxd-server.livenessProbeobject{"exec":{"command":["curl","-k","https://localhost:8443/health-check"]},"initialDelaySeconds":30,"periodSeconds":30,"timeoutSeconds":5}Configure the liveness healthcheck for the auth server if needed.
oxd-server.livenessProbe.execobject{"command":["curl","-k","https://localhost:8443/health-check"]}Executes the python3 healthcheck.
oxd-server.readinessProbeobject{"exec":{"command":["curl","-k","https://localhost:8443/health-check"]},"initialDelaySeconds":25,"periodSeconds":25,"timeoutSeconds":5}Configure the readiness healthcheck for the auth server if needed.
oxd-server.replicasint1Service replica number.
oxd-server.resourcesobject{"limits":{"cpu":"1000m","memory":"400Mi"},"requests":{"cpu":"1000m","memory":"400Mi"}}Resource specs.
oxd-server.resources.limits.cpustring"1000m"CPU limit.
oxd-server.resources.limits.memorystring"400Mi"Memory limit.
oxd-server.resources.requests.cpustring"1000m"CPU request.
oxd-server.resources.requests.memorystring"400Mi"Memory request.
oxd-server.service.oxdServerServiceNamestring"oxd-server"Name of the OXD server service. This must match config.configMap.gluuOxdApplicationCertCn. Please keep it as default.
oxd-server.usrEnvsobject{"normal":{},"secret":{}}Add custom normal and secret envs to the service
oxd-server.usrEnvs.normalobject{}Add custom normal envs to the service variable1: value1
oxd-server.usrEnvs.secretobject{}Add custom secret envs to the service variable1: value1
oxd-server.volumeMountslist[]Configure any additional volumesMounts that need to be attached to the containers
oxd-server.volumeslist[]Configure any additional volumes that need to be attached to the pod
KeyTypeDefaultDescription
casaobject{"additionalAnnotations":{},"additionalLabels":{},"dnsConfig":{},"dnsPolicy":"","hpa":{"behavior":{},"enabled":true,"maxReplicas":10,"metrics":[],"minReplicas":1,"targetCPUUtilizationPercentage":50},"image":{"pullPolicy":"IfNotPresent","pullSecrets":[],"repository":"gluufederation/casa","tag":"4.4.0-1"},"livenessProbe":{"httpGet":{"path":"/casa/health-check","port":"http-casa"},"initialDelaySeconds":25,"periodSeconds":25,"timeoutSeconds":5},"readinessProbe":{"httpGet":{"path":"/casa/health-check","port":"http-casa"},"initialDelaySeconds":30,"periodSeconds":30,"timeoutSeconds":5},"replicas":1,"resources":{"limits":{"cpu":"500m","memory":"500Mi"},"requests":{"cpu":"500m","memory":"500Mi"}},"service":{"casaServiceName":"casa","name":"http-casa","port":8080},"usrEnvs":{"normal":{},"secret":{}},"volumeMounts":[],"volumes":[]}Gluu Casa ("Casa") is a self-service web portal for end-users to manage authentication and authorization preferences for their account in a Gluu Server.
casa.additionalAnnotationsobject{}Additional annotations that will be added across all resources in the format of {cert-manager.io/issuer: "letsencrypt-prod"}. key app is taken
casa.additionalLabelsobject{}Additional labels that will be added across all resources definitions in the format of {mylabel: "myapp"}
casa.dnsConfigobject{}Add custom dns config
casa.dnsPolicystring""Add custom dns policy
casa.hpaobject{"behavior":{},"enabled":true,"maxReplicas":10,"metrics":[],"minReplicas":1,"targetCPUUtilizationPercentage":50}Configure the HorizontalPodAutoscaler
casa.hpa.behaviorobject{}Scaling Policies
casa.hpa.metricslist[]metrics if targetCPUUtilizationPercentage is not set
casa.image.pullPolicystring"IfNotPresent"Image pullPolicy to use for deploying.
casa.image.pullSecretslist[]Image Pull Secrets
casa.image.repositorystring"gluufederation/casa"Image to use for deploying.
casa.image.tagstring"4.4.0-1"Image tag to use for deploying.
casa.livenessProbeobject{"httpGet":{"path":"/casa/health-check","port":"http-casa"},"initialDelaySeconds":25,"periodSeconds":25,"timeoutSeconds":5}Configure the liveness healthcheck for casa if needed.
casa.livenessProbe.httpGet.pathstring"/casa/health-check"http liveness probe endpoint
casa.readinessProbeobject{"httpGet":{"path":"/casa/health-check","port":"http-casa"},"initialDelaySeconds":30,"periodSeconds":30,"timeoutSeconds":5}Configure the readiness healthcheck for the casa if needed.
casa.readinessProbe.httpGet.pathstring"/casa/health-check"http readiness probe endpoint
casa.replicasint1Service replica number.
casa.resourcesobject{"limits":{"cpu":"500m","memory":"500Mi"},"requests":{"cpu":"500m","memory":"500Mi"}}Resource specs.
casa.resources.limits.cpustring"500m"CPU limit.
casa.resources.limits.memorystring"500Mi"Memory limit.
casa.resources.requests.cpustring"500m"CPU request.
casa.resources.requests.memorystring"500Mi"Memory request.
casa.service.casaServiceNamestring"casa"Name of the casa service. Please keep it as default.
casa.service.namestring"http-casa"The name of the casa port within the casa service. Please keep it as default.
casa.service.portint8080Port of the casa service. Please keep it as default.
casa.usrEnvsobject{"normal":{},"secret":{}}Add custom normal and secret envs to the service
casa.usrEnvs.normalobject{}Add custom normal envs to the service variable1: value1
casa.usrEnvs.secretobject{}Add custom secret envs to the service variable1: value1
casa.volumeMountslist[]Configure any additional volumesMounts that need to be attached to the containers
casa.volumeslist[]Configure any additional volumes that need to be attached to the pod
KeyTypeDefaultDescription
oxpassportobject{"additionalAnnotations":{},"additionalLabels":{},"dnsConfig":{},"dnsPolicy":"","hpa":{"behavior":{},"enabled":true,"maxReplicas":10,"metrics":[],"minReplicas":1,"targetCPUUtilizationPercentage":50},"image":{"pullPolicy":"IfNotPresent","pullSecrets":[],"repository":"gluufederation/oxpassport","tag":"4.4.0-1"},"livenessProbe":{"failureThreshold":20,"httpGet":{"path":"/passport/health-check","port":"http-passport"},"initialDelaySeconds":30,"periodSeconds":30,"timeoutSeconds":5},"readinessProbe":{"failureThreshold":20,"httpGet":{"path":"/passport/health-check","port":"http-passport"},"initialDelaySeconds":25,"periodSeconds":25,"timeoutSeconds":5},"replicas":1,"resources":{"limits":{"cpu":"700m","memory":"900Mi"},"requests":{"cpu":"700m","memory":"900Mi"}},"service":{"name":"http-passport","oxPassportServiceName":"oxpassport","port":8090},"usrEnvs":{"normal":{},"secret":{}},"volumeMounts":[],"volumes":[]}Gluu interface to Passport.js to support social login and inbound identity.
oxpassport.additionalAnnotationsobject{}Additional annotations that will be added across all resources in the format of {cert-manager.io/issuer: "letsencrypt-prod"}. key app is taken
oxpassport.additionalLabelsobject{}Additional labels that will be added across all resources definitions in the format of {mylabel: "myapp"}
oxpassport.dnsConfigobject{}Add custom dns config
oxpassport.dnsPolicystring""Add custom dns policy
oxpassport.hpaobject{"behavior":{},"enabled":true,"maxReplicas":10,"metrics":[],"minReplicas":1,"targetCPUUtilizationPercentage":50}Configure the HorizontalPodAutoscaler
oxpassport.hpa.behaviorobject{}Scaling Policies
oxpassport.hpa.metricslist[]metrics if targetCPUUtilizationPercentage is not set
oxpassport.image.pullPolicystring"IfNotPresent"Image pullPolicy to use for deploying.
oxpassport.image.pullSecretslist[]Image Pull Secrets
oxpassport.image.repositorystring"gluufederation/oxpassport"Image to use for deploying.
oxpassport.image.tagstring"4.4.0-1"Image tag to use for deploying.
oxpassport.livenessProbeobject{"failureThreshold":20,"httpGet":{"path":"/passport/health-check","port":"http-passport"},"initialDelaySeconds":30,"periodSeconds":30,"timeoutSeconds":5}Configure the liveness healthcheck for oxPassport if needed.
oxpassport.livenessProbe.httpGet.pathstring"/passport/health-check"http liveness probe endpoint
oxpassport.readinessProbeobject{"failureThreshold":20,"httpGet":{"path":"/passport/health-check","port":"http-passport"},"initialDelaySeconds":25,"periodSeconds":25,"timeoutSeconds":5}Configure the readiness healthcheck for the oxPassport if needed.
oxpassport.readinessProbe.httpGet.pathstring"/passport/health-check"http readiness probe endpoint
oxpassport.replicasint1Service replica number
oxpassport.resourcesobject{"limits":{"cpu":"700m","memory":"900Mi"},"requests":{"cpu":"700m","memory":"900Mi"}}Resource specs.
oxpassport.resources.limits.cpustring"700m"CPU limit.
oxpassport.resources.limits.memorystring"900Mi"Memory limit.
oxpassport.resources.requests.cpustring"700m"CPU request.
oxpassport.resources.requests.memorystring"900Mi"Memory request.
oxpassport.service.namestring"http-passport"The name of the oxPassport port within the oxPassport service. Please keep it as default.
oxpassport.service.oxPassportServiceNamestring"oxpassport"Name of the oxPassport service. Please keep it as default.
oxpassport.service.portint8090Port of the oxPassport service. Please keep it as default.
oxpassport.usrEnvsobject{"normal":{},"secret":{}}Add custom normal and secret envs to the service
oxpassport.usrEnvs.normalobject{}Add custom normal envs to the service variable1: value1
oxpassport.usrEnvs.secretobject{}Add custom secret envs to the service variable1: value1
oxpassport.volumeMountslist[]Configure any additional volumesMounts that need to be attached to the containers
oxpassport.volumeslist[]Configure any additional volumes that need to be attached to the pod
KeyTypeDefaultDescription
oxshibbolethobject{"additionalAnnotations":{},"additionalLabels":{},"dnsConfig":{},"dnsPolicy":"","hpa":{"behavior":{},"enabled":true,"maxReplicas":10,"metrics":[],"minReplicas":1,"targetCPUUtilizationPercentage":50},"image":{"pullPolicy":"IfNotPresent","pullSecrets":[],"repository":"gluufederation/oxshibboleth","tag":"4.4.0-1"},"livenessProbe":{"httpGet":{"path":"/idp","port":"http-oxshib"},"initialDelaySeconds":30,"periodSeconds":30,"timeoutSeconds":5},"readinessProbe":{"httpGet":{"path":"/idp","port":"http-oxshib"},"initialDelaySeconds":25,"periodSeconds":25,"timeoutSeconds":5},"replicas":1,"resources":{"limits":{"cpu":"1000m","memory":"1000Mi"},"requests":{"cpu":"1000m","memory":"1000Mi"}},"service":{"name":"http-oxshib","oxShibbolethServiceName":"oxshibboleth","port":8080},"usrEnvs":{"normal":{},"secret":{}},"volumeMounts":[],"volumes":[]}Shibboleth project for the Gluu Server's SAML IDP functionality.
oxshibboleth.additionalAnnotationsobject{}Additional annotations that will be added across all resources in the format of {cert-manager.io/issuer: "letsencrypt-prod"}. key app is taken
oxshibboleth.additionalLabelsobject{}Additional labels that will be added across all resources definitions in the format of {mylabel: "myapp"}
oxshibboleth.dnsConfigobject{}Add custom dns config
oxshibboleth.dnsPolicystring""Add custom dns policy
oxshibboleth.hpaobject{"behavior":{},"enabled":true,"maxReplicas":10,"metrics":[],"minReplicas":1,"targetCPUUtilizationPercentage":50}Configure the HorizontalPodAutoscaler
oxshibboleth.hpa.behaviorobject{}Scaling Policies
oxshibboleth.hpa.metricslist[]metrics if targetCPUUtilizationPercentage is not set
oxshibboleth.image.pullPolicystring"IfNotPresent"Image pullPolicy to use for deploying.
oxshibboleth.image.pullSecretslist[]Image Pull Secrets
oxshibboleth.image.repositorystring"gluufederation/oxshibboleth"Image to use for deploying.
oxshibboleth.image.tagstring"4.4.0-1"Image tag to use for deploying.
oxshibboleth.livenessProbeobject{"httpGet":{"path":"/idp","port":"http-oxshib"},"initialDelaySeconds":30,"periodSeconds":30,"timeoutSeconds":5}Configure the liveness healthcheck for the oxShibboleth if needed.
oxshibboleth.livenessProbe.httpGet.pathstring"/idp"http liveness probe endpoint
oxshibboleth.readinessProbeobject{"httpGet":{"path":"/idp","port":"http-oxshib"},"initialDelaySeconds":25,"periodSeconds":25,"timeoutSeconds":5}Configure the readiness healthcheck for the casa if needed.
oxshibboleth.readinessProbe.httpGet.pathstring"/idp"http liveness probe endpoint
oxshibboleth.replicasint1Service replica number.
oxshibboleth.resourcesobject{"limits":{"cpu":"1000m","memory":"1000Mi"},"requests":{"cpu":"1000m","memory":"1000Mi"}}Resource specs.
oxshibboleth.resources.limits.cpustring"1000m"CPU limit.
oxshibboleth.resources.limits.memorystring"1000Mi"Memory limit.
oxshibboleth.resources.requests.cpustring"1000m"CPU request.
oxshibboleth.resources.requests.memorystring"1000Mi"Memory request.
oxshibboleth.service.namestring"http-oxshib"Port of the oxShibboleth service. Please keep it as default.
oxshibboleth.service.oxShibbolethServiceNamestring"oxshibboleth"Name of the oxShibboleth service. Please keep it as default.
oxshibboleth.service.portint8080The name of the oxPassport port within the oxPassport service. Please keep it as default.
oxshibboleth.usrEnvsobject{"normal":{},"secret":{}}Add custom normal and secret envs to the service
oxshibboleth.usrEnvs.normalobject{}Add custom normal envs to the service variable1: value1
oxshibboleth.usrEnvs.secretobject{}Add custom secret envs to the service variable1: value1
oxshibboleth.volumeMountslist[]Configure any additional volumesMounts that need to be attached to the containers
oxshibboleth.volumeslist[]Configure any additional volumes that need to be attached to the pod
KeyTypeDefaultDescription
cr-rotateobject{"additionalAnnotations":{},"additionalLabels":{},"dnsConfig":{},"dnsPolicy":"","image":{"pullPolicy":"IfNotPresent","pullSecrets":[],"repository":"gluufederation/cr-rotate","tag":"4.4.0-1"},"resources":{"limits":{"cpu":"200m","memory":"200Mi"},"requests":{"cpu":"200m","memory":"200Mi"}},"service":{"crRotateServiceName":"cr-rotate","name":"http-cr-rotate","port":8084},"usrEnvs":{"normal":{},"secret":{}},"volumeMounts":[],"volumes":[]}CacheRefreshRotation is a special container to monitor cache refresh on oxTrust containers. This may be depreciated.
cr-rotate.additionalAnnotationsobject{}Additional annotations that will be added across all resources in the format of {cert-manager.io/issuer: "letsencrypt-prod"}. key app is taken
cr-rotate.additionalLabelsobject{}Additional labels that will be added across all resources definitions in the format of {mylabel: "myapp"}
cr-rotate.dnsConfigobject{}Add custom dns config
cr-rotate.dnsPolicystring""Add custom dns policy
cr-rotate.image.pullPolicystring"IfNotPresent"Image pullPolicy to use for deploying.
cr-rotate.image.pullSecretslist[]Image Pull Secrets
cr-rotate.image.repositorystring"gluufederation/cr-rotate"Image to use for deploying.
cr-rotate.image.tagstring"4.4.0-1"Image tag to use for deploying.
cr-rotate.resourcesobject{"limits":{"cpu":"200m","memory":"200Mi"},"requests":{"cpu":"200m","memory":"200Mi"}}Resource specs.
cr-rotate.resources.limits.cpustring"200m"CPU limit.
cr-rotate.resources.limits.memorystring"200Mi"Memory limit.
cr-rotate.resources.requests.cpustring"200m"CPU request.
cr-rotate.resources.requests.memorystring"200Mi"Memory request.
cr-rotate.service.crRotateServiceNamestring"cr-rotate"Name of the cr-rotate service. Please keep it as default.
cr-rotate.service.namestring"http-cr-rotate"The name of the cr-rotate port within the cr-rotate service. Please keep it as default.
cr-rotate.service.portint8084Port of the casa service. Please keep it as default.
cr-rotate.usrEnvsobject{"normal":{},"secret":{}}Add custom normal and secret envs to the service
cr-rotate.usrEnvs.normalobject{}Add custom normal envs to the service variable1: value1
cr-rotate.usrEnvs.secretobject{}Add custom secret envs to the service variable1: value1
cr-rotate.volumeMountslist[]Configure any additional volumesMounts that need to be attached to the containers
cr-rotate.volumeslist[]Configure any additional volumes that need to be attached to the pod
KeyTypeDefaultDescription
oxauth-key-rotationobject{"additionalAnnotations":{},"additionalLabels":{},"dnsConfig":{},"dnsPolicy":"","image":{"pullPolicy":"IfNotPresent","pullSecrets":[],"repository":"gluufederation/certmanager","tag":"4.4.0-1"},"keysLife":48,"resources":{"limits":{"cpu":"300m","memory":"300Mi"},"requests":{"cpu":"300m","memory":"300Mi"}},"usrEnvs":{"normal":{},"secret":{}},"volumeMounts":[],"volumes":[]}Responsible for regenerating auth-keys per x hours
oxauth-key-rotation.additionalAnnotationsobject{}Additional annotations that will be added across all resources in the format of {cert-manager.io/issuer: "letsencrypt-prod"}. key app is taken
oxauth-key-rotation.additionalLabelsobject{}Additional labels that will be added across all resources definitions in the format of {mylabel: "myapp"}
oxauth-key-rotation.dnsConfigobject{}Add custom dns config
oxauth-key-rotation.dnsPolicystring""Add custom dns policy
oxauth-key-rotation.image.pullPolicystring"IfNotPresent"Image pullPolicy to use for deploying.
oxauth-key-rotation.image.pullSecretslist[]Image Pull Secrets
oxauth-key-rotation.image.repositorystring"gluufederation/certmanager"Image to use for deploying.
oxauth-key-rotation.image.tagstring"4.4.0-1"Image tag to use for deploying.
oxauth-key-rotation.keysLifeint48Auth server key rotation keys life in hours
oxauth-key-rotation.resourcesobject{"limits":{"cpu":"300m","memory":"300Mi"},"requests":{"cpu":"300m","memory":"300Mi"}}Resource specs.
oxauth-key-rotation.resources.limits.cpustring"300m"CPU limit.
oxauth-key-rotation.resources.limits.memorystring"300Mi"Memory limit.
oxauth-key-rotation.resources.requests.cpustring"300m"CPU request.
oxauth-key-rotation.resources.requests.memorystring"300Mi"Memory request.
oxauth-key-rotation.usrEnvsobject{"normal":{},"secret":{}}Add custom normal and secret envs to the service
oxauth-key-rotation.usrEnvs.normalobject{}Add custom normal envs to the service variable1: value1
oxauth-key-rotation.usrEnvs.secretobject{}Add custom secret envs to the service variable1: value1
oxauth-key-rotation.volumeMountslist[]Configure any additional volumesMounts that need to be attached to the containers
oxauth-key-rotation.volumeslist[]Configure any additional volumes that need to be attached to the pod

#Instructions on how to install different services

Enabling the following services automatically install the corresponding associated chart. To enable/disable them set true or false in the persistence configs as shown below.

config:
  configmap:
    # Auto install other services. If enabled the respective service chart will be installed
    gluuPassportEnabled: false
    gluuCasaEnabled: false
    gluuRadiusEnabled: false
    gluuSamlEnabled: false

#CASA

  • CASA is dependant on oxd-server. To install it oxd-server must be enabled.

#Other optional services

Other optional services like key-rotation, and cr-rotation, are enabled by setting their corresponding values to true under the global block.

For example, to enable cr-rotate set

global:
  cr-rotate:
    enabled: true

#Install Gluu using the gui installer

  1. Create the GUI installer job

    cat <<EOF | kubectl apply -f -
    apiVersion: batch/v1
    kind: Job
    metadata:
      name: cloud-native-installer
      labels:
        APP_NAME: cloud-native-installer
    spec:
      template:
        metadata:
          labels:
            APP_NAME: cloud-native-installer
        spec:
          restartPolicy: Never
          containers:
            - name: cloud-native-installer
              image: gluufederation/cloud-native:4.4.0_dev
    ---
    kind: Service
    apiVersion: v1
    metadata:
      name: cloud-native-installer
    spec:
      type: LoadBalancer
      selector:
        app: cloud-native-installer
      ports:
        - name: http
          port: 80
          targetPort: 5000           
    EOF
  2. Grab the Loadbalancer address , ip or Nodeport and follow installation setup.

    kubectl -n default get svc cloud-native-installer --output jsonpath='{.status.loadBalancer.ingress[0].hostname}'
    kubectl -n default get svc cloud-native-installer --output jsonpath='{.status.loadBalancer.ingress[0].ip}'
    kubectl -n default get svc cloud-native-installer --output jsonpath='{.status.loadBalancer.ingress[0].ip}'
    kubectl -n default get svc cloud-native-installer --output jsonpath='{.status.loadBalancer.ingress[0].ip}'
    1. Get ip of microk8s vm

    2. Get NodePort of the GUI installer service

      kubectl -n default get svc cloud-native-installer
    1. Get ip of minikube vm

      minikube ip
    2. Get NodePort of the GUI installer service

      kubectl -n default get svc cloud-native-installer
  3. Head to the address from previous step to start the installation.

#settings.json parameters file contents

This is the main parameter file used with the pygluu-kubernetes.pyz cloud native edition installer.

ParameterDescriptionOptions
ACCEPT_GLUU_LICENSEAccept the License"Y" or "N"
TEST_ENVIRONMENTAllows installation with no resources limits and requests defined."Y" or "N"
ADMIN_PWPassword of oxTrust 6 chars min: 1 capital, 1 small, 1 digit and 1 special char"P@ssw0rd"
GLUU_VERSIONGluu version to be installed"4.2"
GLUU_UPGRADE_TARGET_VERSIONGluu upgrade version"4.2"
GLUU_HELM_RELEASE_NAMEGluu Helm release name"<name>"
NGINX_INGRESS_NAMESPACENginx namespace"<name>"
NGINX_INGRESS_RELEASE_NAMENginx Helm release name"<name>"
USE_ISTIOEnable use of Istio. This will inject sidecars in Gluu pods."Y" or "N"
USE_ISTIO_INGRESSEnable Istio ingress."Y" or "N"
ISTIO_SYSTEM_NAMESPACEIstio system namespace"<name>"
POSTGRES_NAMESPACEPostgres namespace - Gluu Gateway"<name>"
POSTGRES_URLPostgres URL ( Can be local or remote) - Gluu Gatewayi.e "<servicename>.<namespace>.svc.cluster.local"
NODES_IPSList of kubernetes cluster node ips["<ip>", "<ip2>", "<ip3>"]
NODES_ZONESList of kubernetes cluster node zones["<node1_zone>", "<node2_zone>", "<node3_zone>"]
NODES_NAMESList of kubernetes cluster node names["<node1_name>", "<node2_name>", "<node3_name>"]
NODE_SSH_KEYnodes ssh key path location"<pathtosshkey>"
HOST_EXT_IPMinikube or Microk8s vm ip"<ip>"
VERIFY_EXT_IPVerify the Minikube or Microk8s vm ip placed"Y" or "N"
AWS_LB_TYPEAWS loadbalancer type"" , "clb" or "nlb"
USE_ARNUse ssl provided from ACM AWS"", "Y" or "N"
VPC_CIDRVPC CIDR in use for the Kubernetes cluster"", i.e 192.168.1.116
ARN_AWS_IAMThe arn string"" or "<arn:aws:acm:us-west-2:XXXXXXXX:certificate/XXXXXX-XXXXXXX-XXXXXXX-XXXXXXXX>"
LB_ADDAWS loadbalancer address"<loadbalancer_address>"
DEPLOYMENT_ARCHDeployment architecture"microk8s", "minikube", "eks", "gke", "aks", "do" or "local"
PERSISTENCE_BACKENDBackend persistence type"ldap", "couchbase" or "hybrid"
REDIS_URLRedis url with port. Used when Redis is deployed for Cache.i.e "redis:6379", "clustercfg.testing-redis.icrbdv.euc1.cache.amazonaws.com:6379"
REDIS_TYPEType of Redis deployed"SHARDED", "STANDALONE", "CLUSTER", or "SENTINEL"
REDIS_PWRedis Password if used. This may be empty. If not choose a long password.i.e "", "LS0tLS1CRUdJTiBDRVJUSUZJQ0FURS0tLS0tCk1JSURUakNDQWphZ0F3SUJBZ0lVV2Y0TExEb"
REDIS_USE_SSLRedis SSL use"false" or "true"
REDIS_SSL_TRUSTSTORERedis SSL truststore. If using cloud provider services this is left empty.i.e "", "/etc/myredis.pem"
REDIS_SENTINEL_GROUPRedis Sentinel groupi.e ""
REDIS_NAMESPACERedis Namespace if Redis is to be installedi.e "gluu-redis-cluster"
INSTALL_REDISInstall Redis"Y" or "N"
INSTALL_POSTGRESInstall postgres used by Jackrabbit. This option is used in test mode."Y" or "N"
INSTALL_JACKRABBITInstall Jackrabbit"Y" or "N"
JACKRABBIT_STORAGE_SIZEJackrabbit volume storage size"" i.e "4Gi"
JACKRABBIT_URLhttp:// url for Jackrabbiti.e "http://jackrabbit:8080"
JACKRABBIT_ADMIN_IDJackrabbit admin IDi.e "admin"
JACKRABBIT_ADMIN_PASSWORDJackrabbit admin passwordi.e "admin"
JACKRABBIT_CLUSTERJackrabbit Cluster mode"N" or "Y"
JACKRABBIT_PG_USERJackrabbit postgres usernamei.e "jackrabbit"
JACKRABBIT_PG_PASSWORDJackrabbit postgres passwordi.e "jackrabbbit"
JACKRABBIT_DATABASEJackrabbit postgres database namei.e "jackrabbit"
INSTALL_COUCHBASEInstall couchbase"Y" or "N"
COUCHBASE_NAMESPACECouchbase namespace"<name>"
COUCHBASE_VOLUME_TYPEPersistence Volume type"io1","ps-ssd", "Premium_LRS"
COUCHBASE_CLUSTER_NAMECouchbase cluster name"<name>"
COUCHBASE_URLCouchbase internal address to the cluster"" or i.e "<clustername>.<namespace>.svc.cluster.local"
COUCHBASE_USERCouchbase username"" or i.e "gluu"
COUCHBASE_BUCKET_PREFIXPrefix for Couchbase bucketsgluu
COUCHBASE_PASSWORDPassword of Couchbase 6 characters min: 1 capital, 1 small, 1 digit and 1 special character"P@ssw0rd"
COUCHBASE_SUPERUSERCouchbase superuser username"" or i.e "admin"
COUCHBASE_SUPERUSER_PASSWORDPassword of Couchbase 6 characters min: 1 capital, 1 small, 1 digit and 1 special character"P@ssw0rd"
COUCHBASE_CRTCouchbase CA certification"" or i.e <crt content not encoded>
COUCHBASE_CNCouchbase certificate common name""
COUCHBASE_INDEX_NUM_REPLICACouchbase number of replicas per index0
COUCHBASE_SUBJECT_ALT_NAMECouchbase SAN"" or i.e "cb.gluu.org"
COUCHBASE_CLUSTER_FILE_OVERRIDEOverride couchbase-cluster.yaml with a custom couchbase-cluster.yaml"Y" or "N"
COUCHBASE_USE_LOW_RESOURCESUse very low resources for Couchbase deployment. For demo purposes"Y" or "N"
COUCHBASE_DATA_NODESNumber of Couchbase data nodes"" or i.e "4"
COUCHBASE_QUERY_NODESNumber of Couchbase query nodes"" or i.e "3"
COUCHBASE_INDEX_NODESNumber of Couchbase index nodes"" or i.e "3"
COUCHBASE_SEARCH_EVENTING_ANALYTICS_NODESNumber of Couchbase search, eventing and analytics nodes"" or i.e "2"
COUCHBASE_GENERAL_STORAGECouchbase general storage size"" or i.e "2"
COUCHBASE_DATA_STORAGECouchbase data storage size"" or i.e "5Gi"
COUCHBASE_INDEX_STORAGECouchbase index storage size"" or i.e "5Gi"
COUCHBASE_QUERY_STORAGECouchbase query storage size"" or i.e "5Gi"
COUCHBASE_ANALYTICS_STORAGECouchbase search, eventing and analytics storage size"" or i.e "5Gi"
COUCHBASE_INCR_BACKUP_SCHEDULECouchbase incremental backup schedulei.e "*/30 * * * *"
COUCHBASE_FULL_BACKUP_SCHEDULECouchbase full backup schedulei.e "0 2 * * 6"
COUCHBASE_BACKUP_RETENTION_TIMECouchbase time to retain backups in s,m or hi.e "168h
COUCHBASE_BACKUP_STORAGE_SIZECouchbase backup storage sizei.e "20Gi"
NUMBER_OF_EXPECTED_USERSNumber of expected users [couchbase-resource-calc-alpha]"" or i.e "1000000"
EXPECTED_TRANSACTIONS_PER_SECExpected transactions per second [couchbase-resource-calc-alpha]"" or i.e "2000"
USING_CODE_FLOWIf using code flow [couchbase-resource-calc-alpha]"", "Y" or "N"
USING_SCIM_FLOWIf using SCIM flow [couchbase-resource-calc-alpha]"", "Y" or "N"
USING_RESOURCE_OWNER_PASSWORD_CRED_GRANT_FLOWIf using password flow [couchbase-resource-calc-alpha]"", "Y" or "N"
DEPLOY_MULTI_CLUSTERDeploying a Multi-cluster [alpha]"Y" or "N"
HYBRID_LDAP_HELD_DATAType of data to be held in LDAP with a hybrid installation of couchbase and LDAP"", "default", "user", "site", "cache" or "token"
LDAP_JACKRABBIT_VOLUMELDAP/Jackrabbit Volume type"", "io1","ps-ssd", "Premium_LRS"
APP_VOLUME_TYPEVolume type for LDAP persistenceoptions
LDAP_STATIC_VOLUME_IDLDAP static volume id (AWS EKS)"" or "<static-volume-id>"
LDAP_STATIC_DISK_URILDAP static disk uri (GCE GKE or Azure)"" or "<disk-uri>"
LDAP_BACKUP_SCHEDULELDAP back up cron job frequencyi.e "*/30 * * * *"
GLUU_CACHE_TYPECache type to be used"IN_MEMORY", "REDIS" or "NATIVE_PERSISTENCE"
GLUU_NAMESPACENamespace to deploy Gluu in"<name>"
GLUU_FQDNGluu FQDN"<FQDN>" i.e "demoexample.gluu.org"
COUNTRY_CODEGluu country code"<country code>" i.e "US"
STATEGluu state"<state>" i.e "TX"
EMAILGluu email"<email>" i.e "support@gluu.org"
CITYGluu city"<city>" i.e "Austin"
ORG_NAMEGluu organization name"<org-name>" i.e "Gluu"
LDAP_PWPassword of LDAP 6 characters min: 1 capital, 1 small, 1 digit and 1 special character"P@ssw0rd"
GMAIL_ACCOUNTGmail account for GKE installation"" or"<gmail>" i.e
GOOGLE_NODE_HOME_DIRUser node home directory, used if the hosts volume is used"Y" or "N"
IS_GLUU_FQDN_REGISTEREDIs Gluu FQDN globally resolvable"Y" or "N"
OXD_APPLICATION_KEYSTORE_CNOXD application keystore common name"<name>" i.e "oxd_server"
OXD_ADMIN_KEYSTORE_CNOXD admin keystore common name"<name>" i.e "oxd_server"
LDAP_STORAGE_SIZELDAP volume storage size"" i.e "4Gi"
OXAUTH_KEYS_LIFEoxAuth Key life span in hours48
FIDO2_REPLICASNumber of FIDO2 replicasmin "1"
SCIM_REPLICASNumber of SCIM replicasmin "1"
OXAUTH_REPLICASNumber of oxAuth replicasmin "1"
OXTRUST_REPLICASNumber of oxTrust replicasmin "1"
LDAP_REPLICASNumber of LDAP replicasmin "1"
OXSHIBBOLETH_REPLICASNumber of oxShibboleth replicasmin "1"
OXPASSPORT_REPLICASNumber of oxPassport replicasmin "1"
OXD_SERVER_REPLICASNumber of oxdServer replicasmin "1"
CASA_REPLICASNumber of Casa replicasmin "1"
ENABLE_OXTRUST_APIEnable oxTrust-api"Y" or "N"
ENABLE_OXTRUST_TEST_MODEEnable oxTrust Test Mode"Y" or "N"
ENABLE_CACHE_REFRESHEnable cache refresh rotate installation"Y" or "N"
ENABLE_OXDEnable oxd server installation"Y" or "N"
ENABLE_OXPASSPORTEnable oxPassport installation"Y" or "N"
ENABLE_OXSHIBBOLETHEnable oxShibboleth installation"Y" or "N"
ENABLE_CASAEnable Casa installation"Y" or "N"
ENABLE_FIDO2Enable Fido2 installation"Y" or "N"
ENABLE_SCIMEnable SCIM installation"Y" or "N"
ENABLE_OXAUTH_KEY_ROTATEEnable key rotate installation"Y" or "N"
ENABLE_OXTRUST_API_BOOLEANUsed by pygluu-kubernetes"false"
ENABLE_OXTRUST_TEST_MODE_BOOLEANUsed by pygluu-kubernetes"false"
ENABLE_RADIUS_BOOLEANUsed by pygluu-kubernetes"false"
ENABLE_OXPASSPORT_BOOLEANUsed by pygluu-kubernetes"false"
ENABLE_CASA_BOOLEANUsed by pygluu-kubernetes"false"
ENABLE_SAML_BOOLEANUsed by pygluu-kubernetes"false"
ENABLED_SERVICES_LISTUsed by pygluu-kubernetes. List of all enabled services"[]"
EDIT_IMAGE_NAMES_TAGSManually place the image source and tag"Y" or "N"
JACKRABBIT_IMAGE_NAMEJackrabbit image repository namei.e "gluufederation/jackrabbit"
JACKRABBIT_IMAGE_TAGJackrabbit image tagi.e "4.4.0-1"
CASA_IMAGE_NAMECasa image repository namei.e "gluufederation/casa"
CASA_IMAGE_TAGCasa image tagi.e "4.4.0-1"
CONFIG_IMAGE_NAMEConfig image repository namei.e "gluufederation/config-init"
CONFIG_IMAGE_TAGConfig image tagi.e "4.4.0-1"
CACHE_REFRESH_ROTATE_IMAGE_NAMECache refresh image repository namei.e "gluufederation/cr-rotate"
CACHE_REFRESH_ROTATE_IMAGE_TAGCache refresh image tagi.e "4.4.0-1"
CERT_MANAGER_IMAGE_NAMEGluu's Certificate management image repository namei.e "gluufederation/certmanager"
CERT_MANAGER_IMAGE_TAGGluu's Certificate management image tagi.e "4.4.0-1"
LDAP_IMAGE_NAMELDAP image repository namei.e "gluufederation/opendj"
LDAP_IMAGE_TAGLDAP image tagi.e "4.4.0-1"
OXAUTH_IMAGE_NAMEoxAuth image repository namei.e "gluufederation/oxauth"
OXAUTH_IMAGE_TAGoxAuth image tagi.e "4.4.0-1"
OXD_IMAGE_NAMEoxd image repository namei.e "gluufederation/oxd-server"
OXD_IMAGE_TAGoxd image tagi.e "4.4.0-1"
OXPASSPORT_IMAGE_NAMEoxPassport image repository namei.e "gluufederation/oxpassport"
OXPASSPORT_IMAGE_TAGoxPassport image tagi.e "4.4.0-1"
FIDO2_IMAGE_NAMEFIDO2 image repository namei.e "gluufederation/oxpassport"
FIDO2_IMAGE_TAGFIDO2 image tagi.e "4.4.0-1"
SCIM_IMAGE_NAMESCIM image repository namei.e "gluufederation/oxpassport"
SCIM_IMAGE_TAGSCIM image tagi.e "4.4.0-1"
OXSHIBBOLETH_IMAGE_NAMEoxShibboleth image repository namei.e "gluufederation/oxshibboleth"
OXSHIBBOLETH_IMAGE_TAGoxShibboleth image tagi.e "4.4.0-1"
OXTRUST_IMAGE_NAMEoxTrust image repository namei.e "gluufederation/oxtrust"
OXTRUST_IMAGE_TAGoxTrust image tagi.e "4.4.0-1"
PERSISTENCE_IMAGE_NAMEPersistence image repository namei.e "gluufederation/persistence"
PERSISTENCE_IMAGE_TAGPersistence image tagi.e "4.4.0-1"
UPGRADE_IMAGE_NAMEGluu upgrade image repository namei.e "gluufederation/upgrade"
UPGRADE_IMAGE_TAGGluu upgrade image tagi.e "4.4.0-1"
CONFIRM_PARAMSConfirm using above options"Y" or "N"
GLUU_LDAP_MULTI_CLUSTERHELM-ALPHA-FEATURE-DEPRECIATED: Enable LDAP multi cluster environment"Y" or "N"
GLUU_LDAP_SERF_PORTHELM-ALPHA-FEATURE-DEPRECIATED: Serf UDP and TCP porti.e 30946
GLUU_LDAP_ADVERTISE_ADDRESSHELM-ALPHA-FEATURE-DEPRECIATED: LDAP pod advertise addressi.e demoexample.gluu.org:30946"
GLUU_LDAP_ADVERTISE_ADMIN_PORTHELM-ALPHA-FEATURE-DEPRECIATED: LDAP serf advertise admin porti.e 30444
GLUU_LDAP_ADVERTISE_LDAPS_PORTHELM-ALPHA-FEATURE-DEPRECIATED: LDAP serf advertise LDAPS porti.e 30636
GLUU_LDAP_ADVERTISE_REPLICATION_PORTHELM-ALPHA-FEATURE-DEPRECIATED: LDAP serf advertise replication porti.e 30989
GLUU_LDAP_SECONDARY_CLUSTERHELM-ALPHA-FEATURE-DEPRECIATED: Is this the first kubernetes cluster or not"Y" or "N"
GLUU_LDAP_SERF_PEERSHELM-ALPHA-FEATURE-DEPRECIATED: All opendj serf advertised addresses. This must be resolvable["firstldap.gluu.org:30946", "secondldap.gluu.org:31946"]
GLUU_INSTALL_SQLInstall the SQL server dialect locally. Used in test mode. In production connect to a production SQL server."Y" or "N"
GLUU_SQL_DB_DIALECTMySql or postgres"mysql" or "pgsql"
GLUU_SQL_DB_NAMESPACEThe namespace the sql server was installed into"<name>"
GLUU_SQL_DB_HOSTSQL database host uri."" or i.e "<service>.<namespace>.svc.cluster.local" or cloud url
GLUU_SQL_DB_PORTSQL database port."" i.e 3306
GLUU_SQL_DB_NAMESQL database name.i.e "gluu"
GLUU_SQL_DB_USERSQL database username.i.e "gluu"
GLUU_SQL_DB_PASSWORDSQL passwordi.e "P@ssw0rd"
GOOGLE_SERVICE_ACCOUNT_BASE64Base64 encoded service account. The sa must have roles/secretmanager.admin to use Google secrets and roles/spanner.databaseUser to use Spanner.i.e "SWFtTm90YVNlcnZpY2VBY2NvdW50Q2hhbmdlTWV0b09uZQo="
USE_GOOGLE_SECRET_MANAGERUse Google Secret Manager as the secret and config layer instead of kubernetes Secrets and ConfigMap"Y" or "N"
GOOGLE_SPANNER_INSTANCE_IDGoogle Spanner Instance IDi.e ""
GOOGLE_SPANNER_DATABASE_IDGoogle Spanner Database IDi.e ""
GOOGLE_PROJECT_IDProject id of the google project the secret manager and/or spanner instance belongs toi.e "google-project-to-save-config-and-secrets-to"
MIGRATION_ENABLEDBoolean flag to enable migration from CE"Y" or "N"
MIGRATION_DIRDirectory holding all migration files"/ce-migration"
MIGRATION_DATA_FORMATmigration data-format depending on persistence backend."ldif", "couchbase+json", "spanner+avro", "postgresql+json", "mysql+json"
GLUU_SCIM_PROTECTION_MODESCIM protection mode OAUTH,TEST,UMA"OAUTH", "TEST", "UMA"

#APP_VOLUME_TYPE-options

APP_VOLUME_TYPE="" but if PERSISTENCE_BACKEND is OpenDJ options are :

OptionsDeployemnt ArchitectureVolume Type
1Microk8svolumes on host
2Minikubevolumes on host
6EKSvolumes on host
7EKSEBS volumes dynamically provisioned
8EKSEBS volumes statically provisioned
11GKEvolumes on host
12GKEPersistent Disk dynamically provisioned
13GKEPersistent Disk statically provisioned
16Azurevolumes on host
17AzurePersistent Disk dynamically provisioned
18AzurePersistent Disk statically provisioned
21Digital Oceanvolumes on host
22Digital OceanPersistent Disk dynamically provisioned
23Digital OceanPersistent Disk statically provisioned

#Use Couchbase solely as the persistence layer

#Requirements

  • If you are installing on microk8s or minikube please ignore the below notes as a low resource couchbase-cluster.yaml will be applied automatically, however the VM being used must at least have 8GB RAM and 2 CPU available.

  • An m5.xlarge EKS cluster with 3 nodes at the minimum or n2-standard-4 GKE cluster with 3 nodes. We advise contacting Gluu regarding production setups.

  • Install couchbase Operator Linux version 2.1.0 is recommended but version 2.0.3 is also supported. Place the tar.gz file inside the same directory as the pygluu-kubernetes.pyz.

  • A modified couchbase/couchbase-cluster.yaml will be generated, but in production it is likely that this file will be modified.

    • To override the couchbase-cluster.yaml place the file inside /couchbase folder after running ./pygluu-kubernetes.pyz. More information on the properties couchbase-cluster.yaml.

If you wish to get started fast just change the values of spec.servers.name and spec.servers.serverGroups inside couchbase/couchbase-cluster.yaml to the zones of your EKS nodes and continue.

  • Run ./pygluu-kubernetes.pyz install-couchbase and follow the prompts to install couchbase solely with Gluu.

#Use remote Couchbase as the persistence layer

  • Install couchbase version 6.x.

  • Obtain the Public DNS or FQDN of the couchbase node.

  • Head to the FQDN of the couchbase node to setup your Couchbase cluster. When setting up please use the FQDN as the hostname of the new cluster.

  • Couchbase URL base , user, and password will be needed for installation when running pygluu-kubernetes.pyz

#How to expand EBS volumes

  1. Make sure the StorageClass used in your deployment has the allowVolumeExpansion set to true. If you have used our EBS volume deployment strategy then you will find that this property has already been set for you.

  2. Edit your persistent volume claim using kubectl edit pvc <claim-name> -n <namespace> and increase the value found for storage: to the value needed. Make sure the volumes expand by checking the kubectl get pvc <claim-name> -n <namespace> .

  3. Restart the associated services

#Scaling pods

To scale pods, run the following command:

kubectl scale --replicas=<number> <resource> <name>

In this case, <resource> could be Deployment or Statefulset and <name> is the resource name.

Examples:

  • Scaling oxAuth:

    kubectl scale --replicas=2 deployment oxauth
  • Scaling oxTrust:

    kubectl scale --replicas=2 statefulset oxtrust

#Working with Jackrabbit

ServicesFolder / FileJackrabbit RepositoryMethod
oxAuth/opt/gluu/jetty/oxauth/custom/repository/default/opt/gluu/jetty/oxauth/customPULL from Jackrabbit
oxTrust/opt/gluu/jetty/identity/custom/repository/default/opt/gluu/jetty/identity/customPULL from Jackrabbit
Casa/opt/gluu/jetty/casa/repository/default/opt/gluu/jetty/casaPULL from Jackrabbit

The above means that Jackrabbit will maintain the source folder on all replicas of a service. If one pushed a custom file to /opt/gluu/jetty/oxauth/custom at one replica all other replicas would have this file.

#oxTrust --> Jackrabbit --> oxShibboleth

ServicesFolder / FileJackrabbit RepositoryMethod
oxTrust/opt/shibboleth-idp/repository/default/opt/shibboleth-idpPUSH to Jackrabbit
oxShibboleth/opt/shibboleth-idp/repository/default/opt/shibboleth-idpPULL from Jackrabbit

#oxAuth --> Jackrabbit --> Casa

ServicesFolder / FileJackrabbit RepositoryMethod
oxAuth /etc/certs/otp_configuration.jsonN/APUSH to secrets
oxAuth /etc/certs/super_gluu_creds.jsonN/APUSH to secrets
Casa/etc/certs/otp_configuration.jsonN/APULL from secrets
Casa/etc/certs/super_gluu_creds.jsonN/APULL from secrets

svg

  1. Port forward Jackrabbit at localhost on port 8080

        kubectl port-forward jackrabbit-0 --namespace gluu 8080:8080
  2. Optional: If your managing VM is in the cloud you must forward the connection to the Mac, Linux or Windows computer you are working from.

        ssh -i <key.pem> -L 8080:localhost:8080 user-of-managing-vm@ip-of-managing-vm
  3. Use any filemanager to connect to Jackrabbit. Here are some examples:

    Open file manager which maybe Nautilus and find Connect to Server place the address which should be dav://localhost:8080/repository/default. By default, the username and password are admin if not changed in /etc/gluu/conf/jackrabbit_admin_password inside the pod.

    Install a WebDav client such as WinSCP. Connect using the jackrabbit address which should be http://localhost:8080/repository/default. By default, the username and password are admin if not changed in /etc/gluu/conf/jackrabbit_admmin_password inside the pod.

    Open Finder , Go then Connect to Server and place the address which should be http://localhost:8080/repository/default. By default, the username and password are admin if not changed in /etc/gluu/conf/jackrabbit_admin_password inside the pod.

  1. Login to the Jackrabbit container, for example: kubectl -n gluu exec -ti jackrabbit-0 -- sh.

  2. Go to /opt/webdav directory; create any files or directory under this directory.

  3. Run python3 /app/scripts/jca_sync.py.

#Working with Persistence Document Store

One of the main purposes of DB document store is to replace Jackrabbit (JCA) for distributing files across the pods, i.e. copying Shibboleth files generated by oxTrust to oxShibboleth (see the table below):

#oxTrust --> persistence --> oxShibboleth

ServicesFolder / FileMethod
oxTrust/opt/shibboleth-idpPUSH to persistence
oxShibboleth/opt/shibboleth-idpPULL from persistence

#Migrating from Jackrabbit

Steps to migrate from Jackrabbit (JCA) to Persistence (DB) document store in existing installation:

  1. Change the value of gluuDocumentStoreType in values.yaml, for example:

    config:
      configmap:
        # previously set to JCA
        gluuDocumentStoreType: DB

    Afterwards, upgrade the Helm chart to newest version, for example: helm -n <namespace> upgrade <release-name> gluu/gluu -f values.yaml --version <version>.

  2. Check GLUU_DOCUMENT_STORE_TYPE env var in configmaps:

    kubectl -n <namespace> get cm <release-name>-config-cm --template={{.data.GLUU_DOCUMENT_STORE_TYPE}}

    If the value is set to JCA, change it to DB by running the following command:

    kubectl -n <namespace> patch cm <release-name>-config-cm --type json --patch '[{"op": "replace", "path": "/data/GLUU_DOCUMENT_STORE_TYPE", "value": "DB"}]'
  3. Check selected document store in oxTrust UI by navigating to Configuration > JSON Configuration > Store Provider Configuration page. Change the value of Document store Type form field from JCA to DB if needed and save configuration.

  4. Rollout restart all deployments/statefulsets to force updates.

#Build pygluu-kubernetes installer

#Overview

pygluu-kubernetes.pyz is periodically released and does not need to be built manually. However, the process of building the installer package is listed below.

#Build pygluu-kubernetes.pyz manually

#Prerequisites

  1. Python 3.6+.
  2. Python pip3 package.

#Installation

#Standard Python package

  1. Create a virtual environment and activate:

    python3 -m venv .venv
    source .venv/bin/activate
  2. Install the package:

    make install

    This command will install an executable called pygluu-kubernetes available in the virtual environment PATH.

#Python zipapp

  1. Install shiv using pip3:

    pip3 install shiv
  2. Install the package:

    make zipapp

    This command will generate an executable called pygluu-kubernetes.pyz under the same directory.

#Architectural diagram of all Gluu services

svg

#Network traffic between Gluu services

  1. Database Access: all Gluu services require access to the database.

  2. Pod-2-Pod Communication: Gluu services communicate with each other as depicted.

  3. External/Internet Communication:

    • Oxauth: should be publically accessible.

    • Rest of the pods: We recommend to only keep the .well-known endpoints public and protect the rest.

#Architectural diagram of oxPassport

svg

#Architectural diagram of Casa

svg

#Architectural diagram of SCIM

svg

#Minimum Couchbase System Requirements for cloud deployments

NAME# of nodesRAM(GiB)Disk SpaceCPUTotal RAM(GiB)Total CPU
Couchbase Index135Gi131
Couchbase Query1-5Gi1-1
Couchbase Data135Gi131
Couchbase Search, Eventing and Analytics125Gi121
Grand Total7-8 GB (if query pod is allocated 1 GB)20Gi4