You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Gluu Access and Identity Management All-in-One Chart. This chart deploys the selected janssen microservice all in one deployment.
6
6
@@ -35,7 +35,7 @@ Kubernetes: `>=v1.23.0-0`
35
35
| adminPassword | string |`"Test1234#"`| Admin password to log in to the UI. |
36
36
| alb.ingress | bool |`false`| switches the service to Nodeport for ALB ingress |
37
37
| auth-server | object | `{"appLoggers":{"auditStatsLogLevel":"INFO","auditStatsLogTarget":"FILE","authLogLevel":"INFO","authLogTarget":"STDOUT","enableStdoutLogPrefix":"true","httpLogLevel":"INFO","httpLogTarget":"FILE","persistenceDurationLogLevel":"INFO","persistenceDurationLogTarget":"FILE","persistenceLogLevel":"INFO","persistenceLogTarget":"FILE","scriptLogLevel":"INFO","scriptLogTarget":"FILE"},"authEncKeys":"RSA1_5 RSA-OAEP","authSigKeys":"RS256 RS384 RS512 ES256 ES384 ES512 PS256 PS384 PS512","cnCustomJavaOptions":"","enabled":true,"ingress":{"authServerAdditionalAnnotations":{},"authServerEnabled":true,"authServerLabels":{},"authServerProtectedRegister":false,"authServerProtectedRegisterAdditionalAnnotations":{},"authServerProtectedRegisterLabels":{},"authServerProtectedToken":false,"authServerProtectedTokenAdditionalAnnotations":{},"authServerProtectedTokenLabels":{},"authzenAdditionalAnnotations":{},"authzenConfigEnabled":true,"authzenConfigLabels":{},"deviceCodeAdditionalAnnotations":{},"deviceCodeEnabled":true,"deviceCodeLabels":{},"firebaseMessagingAdditionalAnnotations":{},"firebaseMessagingEnabled":true,"firebaseMessagingLabels":{},"lockAdditionalAnnotations":{},"lockConfigAdditionalAnnotations":{},"lockConfigEnabled":false,"lockConfigLabels":{},"lockEnabled":false,"lockLabels":{},"openidAdditionalAnnotations":{},"openidConfigEnabled":true,"openidConfigLabels":{},"u2fAdditionalAnnotations":{},"u2fConfigEnabled":true,"u2fConfigLabels":{},"uma2AdditionalAnnotations":{},"uma2ConfigEnabled":true,"uma2ConfigLabels":{},"webdiscoveryAdditionalAnnotations":{},"webdiscoveryEnabled":true,"webdiscoveryLabels":{},"webfingerAdditionalAnnotations":{},"webfingerEnabled":true,"webfingerLabels":{}},"lockEnabled":false}` | Parameters used globally across all services helm charts. |
38
-
| auth-server-key-rotation | object |`{"additionalAnnotations":{},"additionalLabels":{},"cronJobSchedule":"","customCommand":[],"customScripts":[],"dnsConfig":{},"dnsPolicy":"","enabled":true,"image":{"pullPolicy":"IfNotPresent","pullSecrets":[],"repository":"ghcr.io/janssenproject/jans/cloudtools","tag":"0.0.0-nightly"},"initKeysLife":48,"keysLife":48,"keysPushDelay":0,"keysPushStrategy":"NEWER","keysStrategy":"NEWER","lifecycle":{},"nodeSelector":{},"resources":{"limits":{"cpu":"300m","memory":"300Mi"},"requests":{"cpu":"300m","memory":"300Mi"}},"usrEnvs":{"normal":{},"secret":{}},"volumeMounts":[],"volumes":[]}`| Responsible for regenerating auth-keys per x hours |
38
+
| auth-server-key-rotation | object |`{"additionalAnnotations":{},"additionalLabels":{},"cronJobSchedule":"","customCommand":[],"customScripts":[],"dnsConfig":{},"dnsPolicy":"","enabled":true,"image":{"pullPolicy":"IfNotPresent","pullSecrets":[],"repository":"ghcr.io/janssenproject/jans/cloudtools","tag":"1.14.0-1"},"initKeysLife":48,"keysLife":48,"keysPushDelay":0,"keysPushStrategy":"NEWER","keysStrategy":"NEWER","lifecycle":{},"nodeSelector":{},"resources":{"limits":{"cpu":"300m","memory":"300Mi"},"requests":{"cpu":"300m","memory":"300Mi"}},"usrEnvs":{"normal":{},"secret":{}},"volumeMounts":[],"volumes":[]}`| Responsible for regenerating auth-keys per x hours |
39
39
| auth-server-key-rotation.additionalAnnotations | object |`{}`| Additional annotations that will be added across the gateway in the format of {cert-manager.io/issuer: "letsencrypt-prod"} |
40
40
| auth-server-key-rotation.additionalLabels | object |`{}`| Additional labels that will be added across the gateway in the format of {mylabel: "myapp"} |
41
41
| auth-server-key-rotation.cronJobSchedule | string |`""`| Auth server key rotation job schedule. It accepts any Cron syntax supported by Kubernetes. If empty, the schedule will run based on keysLife value. |
@@ -47,7 +47,7 @@ Kubernetes: `>=v1.23.0-0`
47
47
| auth-server-key-rotation.image.pullPolicy | string |`"IfNotPresent"`| Image pullPolicy to use for deploying. |
48
48
| auth-server-key-rotation.image.pullSecrets | list |`[]`| Image Pull Secrets |
49
49
| auth-server-key-rotation.image.repository | string |`"ghcr.io/janssenproject/jans/cloudtools"`| Image to use for deploying. |
50
-
| auth-server-key-rotation.image.tag | string |`"0.0.0-nightly"`| Image tag to use for deploying. |
50
+
| auth-server-key-rotation.image.tag | string |`"1.14.0-1"`| Image tag to use for deploying. |
51
51
| auth-server-key-rotation.initKeysLife | int |`48`| The initial auth server key rotation keys life in hours |
52
52
| auth-server-key-rotation.keysLife | int |`48`| Auth server key rotation keys life in hours |
53
53
| auth-server-key-rotation.keysPushDelay | int |`0`| Delay (in seconds) before pushing private keys to Auth server |
| cleanup.additionalAnnotations | object |`{}`| Additional annotations that will be added across the gateway in the format of {cert-manager.io/issuer: "letsencrypt-prod"} |
147
147
| cleanup.additionalLabels | object |`{}`| Additional labels that will be added across the gateway in the format of {mylabel: "myapp"} |
148
148
| cleanup.customCommand | list |`[]`| Add custom job's command. If passed, it will override the default conditional command. |
@@ -153,7 +153,7 @@ Kubernetes: `>=v1.23.0-0`
153
153
| cleanup.image.pullPolicy | string |`"IfNotPresent"`| Image pullPolicy to use for deploying. |
154
154
| cleanup.image.pullSecrets | list |`[]`| Image Pull Secrets |
155
155
| cleanup.image.repository | string |`"ghcr.io/janssenproject/jans/cloudtools"`| Image to use for deploying. |
156
-
| cleanup.image.tag | string |`"0.0.0-nightly"`| Image tag to use for deploying. |
156
+
| cleanup.image.tag | string |`"1.14.0-1"`| Image tag to use for deploying. |
157
157
| cleanup.interval | int |`60`| Interval of running the cleanup process (in minutes) |
158
158
| cleanup.limit | int |`1000`| Max. numbers of entries to cleanup |
159
159
| cleanup.nodeSelector | object |`{}`| Add nodeSelector (see https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#nodeselector)|
@@ -315,7 +315,7 @@ Kubernetes: `>=v1.23.0-0`
315
315
| image.pullPolicy | string |`"IfNotPresent"`| Image pullPolicy to use for deploying. |
316
316
| image.pullSecrets | list |`[]`| Image Pull Secrets |
317
317
| image.repository | string |`"ghcr.io/gluufederation/flex/flex-all-in-one"`| Image to use for deploying. |
318
-
| image.tag | string |`"0.0.0-nightly"`| Image tag to use for deploying. |
318
+
| image.tag | string |`"5.14.0-1"`| Image tag to use for deploying. |
319
319
| isFqdnRegistered | bool |`false`| Boolean flag to enable mapping lbIp to fqdn inside pods on clouds that provide static ip for load balancers. On cloud that provide only addresses to the LB this flag will enable a script to actively scan config.configmap.lbAddr and update the hosts file inside the pods automatically. |
320
320
| istio.additionalAnnotations | object |`{}`| Additional annotations that will be added across the gateway in the format of {cert-manager.io/issuer: "letsencrypt-prod"} |
321
321
| istio.additionalLabels | object |`{}`| Additional labels that will be added across the gateway in the format of {mylabel: "myapp"} |
@@ -324,7 +324,7 @@ Kubernetes: `>=v1.23.0-0`
324
324
| istio.ingress | bool |`false`| Boolean flag that enables using istio gateway for Gluu. This assumes istio ingress is installed and hence the LB is available. |
325
325
| istio.namespace | string |`"istio-system"`| The namespace istio is deployed in. The is normally istio-system. |
| kc-scheduler.additionalAnnotations | object |`{}`| Additional annotations that will be added across the gateway in the format of {cert-manager.io/issuer: "letsencrypt-prod"} |
329
329
| kc-scheduler.additionalLabels | object |`{}`| Additional labels that will be added across the gateway in the format of {mylabel: "myapp"} |
330
330
| kc-scheduler.customCommand | list |`[]`| Add custom job's command. If passed, it will override the default conditional command. |
@@ -335,7 +335,7 @@ Kubernetes: `>=v1.23.0-0`
335
335
| kc-scheduler.image.pullPolicy | string |`"IfNotPresent"`| Image pullPolicy to use for deploying. |
336
336
| kc-scheduler.image.pullSecrets | list |`[]`| Image Pull Secrets |
337
337
| kc-scheduler.image.repository | string |`"ghcr.io/janssenproject/jans/cloudtools"`| Image to use for deploying. |
338
-
| kc-scheduler.image.tag | string |`"0.0.0-nightly"`| Image tag to use for deploying. |
338
+
| kc-scheduler.image.tag | string |`"1.14.0-1"`| Image tag to use for deploying. |
339
339
| kc-scheduler.interval | int |`10`| Interval of running the scheduler (in minutes) |
340
340
| kc-scheduler.nodeSelector | object |`{}`| Add nodeSelector (see https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#nodeselector)|
# -- Auth server key rotation job schedule. It accepts any Cron syntax supported by Kubernetes. If empty, the schedule will run based on keysLife value.
0 commit comments