You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Gluu Access and Identity Management All-in-One Chart. This chart deploys the selected janssen microservice all in one deployment.
6
6
@@ -35,7 +35,7 @@ Kubernetes: `>=v1.23.0-0`
35
35
| adminPassword | string |`"Test1234#"`| Admin password to log in to the UI. |
36
36
| alb.ingress | bool |`false`| switches the service to Nodeport for ALB ingress |
37
37
| auth-server | object | `{"appLoggers":{"auditStatsLogLevel":"INFO","auditStatsLogTarget":"FILE","authLogLevel":"INFO","authLogTarget":"STDOUT","enableStdoutLogPrefix":"true","httpLogLevel":"INFO","httpLogTarget":"FILE","persistenceDurationLogLevel":"INFO","persistenceDurationLogTarget":"FILE","persistenceLogLevel":"INFO","persistenceLogTarget":"FILE","scriptLogLevel":"INFO","scriptLogTarget":"FILE"},"authEncKeys":"RSA1_5 RSA-OAEP","authSigKeys":"RS256 RS384 RS512 ES256 ES384 ES512 PS256 PS384 PS512","cnCustomJavaOptions":"","enabled":true,"ingress":{"authServerAdditionalAnnotations":{},"authServerEnabled":true,"authServerLabels":{},"authServerProtectedRegister":false,"authServerProtectedRegisterAdditionalAnnotations":{},"authServerProtectedRegisterLabels":{},"authServerProtectedToken":false,"authServerProtectedTokenAdditionalAnnotations":{},"authServerProtectedTokenLabels":{},"authzenAdditionalAnnotations":{},"authzenConfigEnabled":true,"authzenConfigLabels":{},"deviceCodeAdditionalAnnotations":{},"deviceCodeEnabled":true,"deviceCodeLabels":{},"firebaseMessagingAdditionalAnnotations":{},"firebaseMessagingEnabled":true,"firebaseMessagingLabels":{},"lockAdditionalAnnotations":{},"lockConfigAdditionalAnnotations":{},"lockConfigEnabled":false,"lockConfigLabels":{},"lockEnabled":false,"lockLabels":{},"openidAdditionalAnnotations":{},"openidConfigEnabled":true,"openidConfigLabels":{},"u2fAdditionalAnnotations":{},"u2fConfigEnabled":true,"u2fConfigLabels":{},"uma2AdditionalAnnotations":{},"uma2ConfigEnabled":true,"uma2ConfigLabels":{},"webdiscoveryAdditionalAnnotations":{},"webdiscoveryEnabled":true,"webdiscoveryLabels":{},"webfingerAdditionalAnnotations":{},"webfingerEnabled":true,"webfingerLabels":{}},"lockEnabled":false}` | Parameters used globally across all services helm charts. |
38
-
| auth-server-key-rotation | object |`{"additionalAnnotations":{},"additionalLabels":{},"cronJobSchedule":"","customCommand":[],"customScripts":[],"dnsConfig":{},"dnsPolicy":"","enabled":true,"image":{"pullPolicy":"IfNotPresent","pullSecrets":[],"repository":"ghcr.io/janssenproject/jans/cloudtools","tag":"0.0.0-nightly"},"initKeysLife":48,"keysLife":48,"keysPushDelay":0,"keysPushStrategy":"NEWER","keysStrategy":"NEWER","lifecycle":{},"nodeSelector":{},"resources":{"limits":{"cpu":"300m","memory":"300Mi"},"requests":{"cpu":"300m","memory":"300Mi"}},"usrEnvs":{"normal":{},"secret":{}},"volumeMounts":[],"volumes":[]}`| Responsible for regenerating auth-keys per x hours |
38
+
| auth-server-key-rotation | object |`{"additionalAnnotations":{},"additionalLabels":{},"cronJobSchedule":"","customCommand":[],"customScripts":[],"dnsConfig":{},"dnsPolicy":"","enabled":true,"image":{"pullPolicy":"IfNotPresent","pullSecrets":[],"repository":"ghcr.io/janssenproject/jans/cloudtools","tag":"1.15.0-1"},"initKeysLife":48,"keysLife":48,"keysPushDelay":0,"keysPushStrategy":"NEWER","keysStrategy":"NEWER","lifecycle":{},"nodeSelector":{},"resources":{"limits":{"cpu":"300m","memory":"300Mi"},"requests":{"cpu":"300m","memory":"300Mi"}},"usrEnvs":{"normal":{},"secret":{}},"volumeMounts":[],"volumes":[]}`| Responsible for regenerating auth-keys per x hours |
39
39
| auth-server-key-rotation.additionalAnnotations | object |`{}`| Additional annotations that will be added across the gateway in the format of {cert-manager.io/issuer: "letsencrypt-prod"} |
40
40
| auth-server-key-rotation.additionalLabels | object |`{}`| Additional labels that will be added across the gateway in the format of {mylabel: "myapp"} |
41
41
| auth-server-key-rotation.cronJobSchedule | string |`""`| Auth server key rotation job schedule. It accepts any Cron syntax supported by Kubernetes. If empty, the schedule will run based on keysLife value. |
@@ -47,7 +47,7 @@ Kubernetes: `>=v1.23.0-0`
47
47
| auth-server-key-rotation.image.pullPolicy | string |`"IfNotPresent"`| Image pullPolicy to use for deploying. |
48
48
| auth-server-key-rotation.image.pullSecrets | list |`[]`| Image Pull Secrets |
49
49
| auth-server-key-rotation.image.repository | string |`"ghcr.io/janssenproject/jans/cloudtools"`| Image to use for deploying. |
50
-
| auth-server-key-rotation.image.tag | string |`"0.0.0-nightly"`| Image tag to use for deploying. |
50
+
| auth-server-key-rotation.image.tag | string |`"1.15.0-1"`| Image tag to use for deploying. |
51
51
| auth-server-key-rotation.initKeysLife | int |`48`| The initial auth server key rotation keys life in hours |
52
52
| auth-server-key-rotation.keysLife | int |`48`| Auth server key rotation keys life in hours |
53
53
| auth-server-key-rotation.keysPushDelay | int |`0`| Delay (in seconds) before pushing private keys to Auth server |
| cleanup.additionalAnnotations | object |`{}`| Additional annotations that will be added across the gateway in the format of {cert-manager.io/issuer: "letsencrypt-prod"} |
148
148
| cleanup.additionalLabels | object |`{}`| Additional labels that will be added across the gateway in the format of {mylabel: "myapp"} |
149
149
| cleanup.customCommand | list |`[]`| Add custom job's command. If passed, it will override the default conditional command. |
@@ -154,7 +154,7 @@ Kubernetes: `>=v1.23.0-0`
154
154
| cleanup.image.pullPolicy | string |`"IfNotPresent"`| Image pullPolicy to use for deploying. |
155
155
| cleanup.image.pullSecrets | list |`[]`| Image Pull Secrets |
156
156
| cleanup.image.repository | string |`"ghcr.io/janssenproject/jans/cloudtools"`| Image to use for deploying. |
157
-
| cleanup.image.tag | string |`"0.0.0-nightly"`| Image tag to use for deploying. |
157
+
| cleanup.image.tag | string |`"1.15.0-1"`| Image tag to use for deploying. |
158
158
| cleanup.interval | int |`60`| Interval of running the cleanup process (in minutes) |
159
159
| cleanup.limit | int |`1000`| Max. numbers of entries to cleanup |
160
160
| cleanup.nodeSelector | object |`{}`| Add nodeSelector (see https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#nodeselector)|
@@ -316,7 +316,7 @@ Kubernetes: `>=v1.23.0-0`
316
316
| image.pullPolicy | string |`"IfNotPresent"`| Image pullPolicy to use for deploying. |
317
317
| image.pullSecrets | list |`[]`| Image Pull Secrets |
318
318
| image.repository | string |`"ghcr.io/gluufederation/flex/flex-all-in-one"`| Image to use for deploying. |
319
-
| image.tag | string |`"0.0.0-nightly"`| Image tag to use for deploying. |
319
+
| image.tag | string |`"5.15.0-1"`| Image tag to use for deploying. |
320
320
| isFqdnRegistered | bool |`false`| Boolean flag to enable mapping lbIp to fqdn inside pods on clouds that provide static ip for load balancers. On cloud that provide only addresses to the LB this flag will enable a script to actively scan config.configmap.lbAddr and update the hosts file inside the pods automatically. |
321
321
| istio.additionalAnnotations | object |`{}`| Additional annotations that will be added across the gateway in the format of {cert-manager.io/issuer: "letsencrypt-prod"} |
322
322
| istio.additionalLabels | object |`{}`| Additional labels that will be added across the gateway in the format of {mylabel: "myapp"} |
@@ -325,7 +325,7 @@ Kubernetes: `>=v1.23.0-0`
325
325
| istio.ingress | bool |`false`| Boolean flag that enables using istio gateway for Gluu. This assumes istio ingress is installed and hence the LB is available. |
326
326
| istio.namespace | string |`"istio-system"`| The namespace istio is deployed in. The is normally istio-system. |
| kc-scheduler.additionalAnnotations | object |`{}`| Additional annotations that will be added across the gateway in the format of {cert-manager.io/issuer: "letsencrypt-prod"} |
330
330
| kc-scheduler.additionalLabels | object |`{}`| Additional labels that will be added across the gateway in the format of {mylabel: "myapp"} |
331
331
| kc-scheduler.customCommand | list |`[]`| Add custom job's command. If passed, it will override the default conditional command. |
@@ -336,7 +336,7 @@ Kubernetes: `>=v1.23.0-0`
336
336
| kc-scheduler.image.pullPolicy | string |`"IfNotPresent"`| Image pullPolicy to use for deploying. |
337
337
| kc-scheduler.image.pullSecrets | list |`[]`| Image Pull Secrets |
338
338
| kc-scheduler.image.repository | string |`"ghcr.io/janssenproject/jans/cloudtools"`| Image to use for deploying. |
339
-
| kc-scheduler.image.tag | string |`"0.0.0-nightly"`| Image tag to use for deploying. |
339
+
| kc-scheduler.image.tag | string |`"1.15.0-1"`| Image tag to use for deploying. |
340
340
| kc-scheduler.interval | int |`10`| Interval of running the scheduler (in minutes) |
341
341
| kc-scheduler.nodeSelector | object |`{}`| Add nodeSelector (see https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#nodeselector)|
# -- Auth server key rotation job schedule. It accepts any Cron syntax supported by Kubernetes. If empty, the schedule will run based on keysLife value.
0 commit comments