Compare commits

...

34 Commits

Author SHA1 Message Date
Kilian Boute
5445e8b7e9 docs(hub): refresh i18n examples 2026-08-31 14:29:05 +00:00
Kilian
8629c701a1 Merge pull request #152 from kerberos-io/fix/remote-recording-default-enabled
fix(frontend): enable remote recording by default
2026-08-28 17:18:37 +02:00
Kilian Boute
e3a38a007d fix(frontend): enable remote recording by default
Change the chart default to true, update the values reference, and bump the Hub chart to 0.134.0.
2026-08-28 14:53:01 +00:00
Kilian
f097916ceb Merge pull request #151 from kerberos-io/feat/map-tile-overlay-config
Expose frontend map tile overlays
2026-08-28 16:12:52 +02:00
Kilian Boute
678d4d84ea feat(frontend): expose remote recording flag
Add a default-disabled live-view remote recording value, render it into normal and demo frontend Deployments, and document the chart option.
2026-08-28 14:02:42 +00:00
Kilian Boute
0deaf41420 feat(frontend): expose map tile overlays
Add optional XYZ overlay URL, API key, attribution, zoom, and opacity values to normal and demo frontend deployments and bump the Hub chart to 0.133.0.
2026-08-28 13:15:56 +00:00
Cédric Verstraeten
813b008955 Merge pull request #150 from kerberos-io/feature/add-monitor-log-level
feature/add-monitor-log-level
2026-08-28 13:55:55 +02:00
Cédric Verstraeten
32b71a82ca feat(monitor): add log level configuration for monitor 2026-08-28 11:51:46 +00:00
Kilian
7bbf4ae78c Merge pull request #149 from kerberos-io/fix/nest-projects-under-organisations
fix(frontend): align context feature flags
2026-08-24 13:02:18 +02:00
Kilian Boute
6f34bd4735 fix(frontend): align context feature flags
Inject organisation and project feature flags into the demo frontend deployment, document the nested hierarchy, and bump the chart to 0.132.0.
2026-08-24 10:51:20 +00:00
Kilian
24918922fd Merge pull request #148 from kerberos-io/bump-chart
bump-release
2026-08-24 11:28:29 +02:00
Kilian Boute
0fadcb74d0 bump-release 2026-08-21 17:38:54 +02:00
Cédric Verstraeten
f834d9b8f5 Merge pull request #143 from kerberos-io/public-release-1786904956
A new public release - 1786904956
2026-08-21 17:36:29 +02:00
Kilian
eefe96c679 Merge pull request #147 from kerberos-io/detection-source-flags
detection source flags
2026-08-21 17:32:59 +02:00
Kilian
93888e2855 Merge pull request #144 from kerberos-io/feature/add-org-feature-flags
add-org-feature-flags
2026-08-21 17:29:48 +02:00
Kilian Boute
759ac8dbf8 detection source flags 2026-08-21 17:28:25 +02:00
Cédric Verstraeten
4aaa70f121 Merge pull request #146 from kerberos-io/fix/cors-origin
fix/cors-origin
2026-08-20 22:10:48 +02:00
Cédric Verstraeten
ad7ef4ac12 Add frontend URL to Hub API CORS
Initialize CORS origins with the primary frontend URL while retaining support for the legacy frontend URL. Bump the Hub chart to 0.130.0.
2026-08-20 22:09:19 +02:00
Cédric Verstraeten
5ad56f9730 Merge pull request #145 from kerberos-io/feature/add-refresh-tokens-config
feature/add-refresh-tokens-config
2026-08-20 21:44:32 +02:00
Cédric Verstraeten
91eb64a2f3 Update Chart.yaml 2026-08-20 21:35:04 +02:00
Cédric Verstraeten
55ae6cdd3e Add dynamic CORS origins and secure refresh cookie
Update the hub API Helm template to set `REFRESH_COOKIE_SECURE` automatically when the API schema is HTTPS, and generate `CORS_ALLOWED_ORIGINS` from configured frontend URLs (legacy URL, domain list, tenant wildcard domain, and demo URL). This keeps cookie behavior and CORS config aligned with deployment settings.
2026-08-20 21:33:32 +02:00
Kilian Boute
f492c14336 add flags 2026-08-20 18:01:19 +02:00
uug4ai
d4a13a4cff A new public release - 1786904956 2026-08-16 18:29:18 +00:00
Kilian
98cc8d4f2d Merge pull request #142 from kerberos-io/docs/workflow-source-alignment
docs(workflows): clarify config and database sources
2026-08-13 12:48:11 +02:00
Kilian Boute
a5125eee69 docs(workflows): clarify definition sources 2026-08-13 10:23:21 +00:00
Cédric Verstraeten
b2ff3e2e20 Merge pull request #141 from kerberos-io/fix/allow-replicas-proxy-default-to-zero
fix/allow-replicas-proxy-default-to-zero
2026-08-11 22:01:40 +02:00
Cédric Verstraeten
277ddde3b4 Disable proxy and reactivation services by default
Default replicas for the hub proxy and reactivation subscriptions services are now set to 0, allowing them to be disabled unless explicitly enabled. This updates the chart metadata and docs to reflect the new default behavior.
2026-08-11 21:51:37 +02:00
Cédric Verstraeten
7878be79d6 Merge pull request #140 from kerberos-io/feature/add-mongodb-tls-support
feature/add-mongodb-tls-support
2026-08-11 14:14:35 +02:00
Cédric Verstraeten
123bde292e Merge pull request #136 from kerberos-io/public-release-1786356403
A new public release - 1786356403
2026-08-11 14:09:02 +02:00
Cédric Verstraeten
e76311872e feat(hub): update chart version to 0.127.0 and add MongoDB TLS configuration options 2026-08-11 12:06:27 +00:00
Cédric Verstraeten
0f2176822a feat(hub): add TLS support for MongoDB configuration 2026-08-11 12:05:43 +00:00
Kilian
8ca4c402f8 Merge pull request #139 from kerberos-io/feat/organisation-feature-flags
chore(hub): bump chart version to 0.126.2
2026-08-10 12:36:29 +02:00
Kilian
8d9b943100 chore(hub): bump chart version to 0.126.2 2026-08-10 10:34:08 +00:00
uug4ai
c29647ec62 A new public release - 1786356403 2026-08-10 10:06:45 +00:00
24 changed files with 491 additions and 138 deletions

View File

@@ -16,7 +16,7 @@ type: application
# This is the chart version. This version number should be incremented each time you make changes
# to the chart and its templates, including the app version.
# Versions are expected to follow Semantic Versioning (https://semver.org/)
version: 0.126.1
version: 0.134.0
# This is the version number of the application being deployed. This version number should be
# incremented each time you make changes to the application. Versions are not expected to

View File

@@ -53,6 +53,11 @@ Below all configuration options and parameters are listed.
| `mongodb.password` | MongoDB user password, by default `'yourmongodbpassword'` | `"yourpassword"` |
| `mongodb.retryWrites` | Enable or disable MongoDB retryable writes. | `"true"` |
| `mongodb.flavor` | Backend engine flavor: `"mongodb"` (native MongoDB / Atlas) or `"documentdb"` (AWS DocumentDB). The `documentdb` flavor disables features DocumentDB does not support (geospatial queries/indexes, complex `$lookup` pipelines). When set to `documentdb`, also set `mongodb.retryWrites: "false"`. | `"mongodb"` |
| `mongodb.tls.enabled` | Enable TLS for MongoDB connections. When `mongodb.uri` is set, the chart appends missing `tls=true` and `tlsCAFile` query parameters. | `false` |
| `mongodb.tls.existingSecret` | Existing Kubernetes Secret containing the MongoDB CA bundle. The Secret is mounted into every workload that consumes `mongodb-config`. | `""` |
| `mongodb.tls.caFileName` | Key and filename of the CA bundle in `mongodb.tls.existingSecret` (for AWS DocumentDB, typically `global-bundle.pem`). | `""` |
| `mongodb.tls.mountPath` | Read-only directory where the MongoDB CA Secret is mounted. | `"/etc/mongodb/tls"` |
| `mongodb.tls.insecureSkipVerify` | Skip MongoDB certificate and hostname verification. This is insecure and intended only for local testing. | `false` |
| `mqtt.host` | MQTT (Vernemq) hostname. | `"mqtt.yourdomain.com"` |
| `mqtt.port` | MQTT (Vernemq) port for WSS (secure sockets), by default `'8443'`. | `"8443"` |
| `mqtt.protocol` | MQTT (Vernemq) protocol, by default `'wss'`. | `"wss"` |
@@ -200,17 +205,30 @@ Below all configuration options and parameters are listed.
| `kerberoshub.frontend.features.splashScreen.enabled` | Enable or disable the pre-bootstrap splash screen and reveal delay. | `"true"` |
| `kerberoshub.frontend.features.landingPage` | Frontend landing page configuration. | `"/dashboard"` |
| `kerberoshub.frontend.features.i18n.enabled` | Enable or disable the runtime language switcher in the front-end. When `"false"`, `defaultLanguage` is forced and users cannot change it. | `"true"` |
| `kerberoshub.frontend.features.i18n.defaultLanguage` | Default language code used by the front-end (e.g. `en`, `nl`, `pl`, `tr`, `fr`, `sv`, `de`). | `"en"` |
| `kerberoshub.frontend.features.i18n.defaultLanguage` | Default language code used by the front-end (`en`, `nl`, `pl`, `pt`, `it`, `tr`, `fr`, `sv`, `de`). | `"en"` |
| `kerberoshub.frontend.features.workflows.enabled` | Enable or disable the workflows feature in the frontend. | `"false"` |
| `kerberoshub.frontend.features.organisations.enabled` | Enable or disable the organisation feature family, including projects. When empty, child groups apply independently. | `""` |
| `kerberoshub.frontend.features.organisations.switcherEnabled` | Enable or disable the organisation dropdown and switching. The current organisation remains visible when disabled. | `"false"` |
| `kerberoshub.frontend.features.organisations.creationEnabled` | Enable or disable organisation creation. Requires organisation switching to be enabled. | `"false"` |
| `kerberoshub.frontend.features.organisations.settingsEnabled` | Enable or disable the organisation identity link to organisation settings. | `"false"` |
| `kerberoshub.frontend.features.projects.enabled` | Fallback project group switch used when the organisations umbrella is unset. | `""` |
| `kerberoshub.frontend.features.projects.switcherEnabled` | Enable or disable the read-only project dropdown. | `"false"` |
| `kerberoshub.frontend.features.projects.creationEnabled` | Reserved for the project creation UI. | `"false"` |
| `kerberoshub.frontend.features.projects.settingsEnabled` | Reserved for the project settings UI. | `"false"` |
| `kerberoshub.frontend.features.map.tileUrlLight` | Tile URL used by the map in light mode. | `"https://{s}.basemaps.cartocdn.com/rastertiles/voyager/{z}/{x}/{y}{r}.png"` |
| `kerberoshub.frontend.features.map.tileUrlDark` | Tile URL used by the map in dark mode. | `"https://{s}.basemaps.cartocdn.com/dark_all/{z}/{x}/{y}{r}.png"` |
| `kerberoshub.frontend.features.map.attribution` | Attribution text displayed on the map tiles. | `"&copy; <a href='https://www.openstreetmap.org/copyright' target='_blank'>OpenStreetMap</a>"` |
| `kerberoshub.frontend.features.map.overlayTileUrl` | Optional XYZ overlay URL supporting `{z}`, `{x}`, `{y}`, and `{apiKey}`. Empty disables the overlay. | `""` |
| `kerberoshub.frontend.features.map.overlayApiKey` | Optional browser-visible API key substituted for `{apiKey}` in the overlay URL. | `""` |
| `kerberoshub.frontend.features.map.overlayAttribution` | Attribution text displayed when the overlay is enabled. | `""` |
| `kerberoshub.frontend.features.map.overlayMinZoom` | Minimum zoom level for overlay tiles. | `"0"` |
| `kerberoshub.frontend.features.map.overlayMaxZoom` | Maximum zoom level for overlay tiles. | `"19"` |
| `kerberoshub.frontend.features.map.overlayOpacity` | Overlay opacity from `0` to `1`. | `"1"` |
| `kerberoshub.frontend.features.liveview.defaultStreamMode` | Liveview behavior setting: `defaultStreamMode`. | `"SD"` |
| `kerberoshub.frontend.features.liveview.liveStreamMode` | Transport backing LIVE mode: `webrtc`, `hls`, or `moq`. | `"webrtc"` |
| `kerberoshub.frontend.features.liveview.hlsEnabled` | Offer HLS as a selectable LIVE transport. | `"true"` |
| `kerberoshub.frontend.features.liveview.moqEnabled` | Offer MoQ as a selectable LIVE transport. | `"false"` |
| `kerberoshub.frontend.features.liveview.remoteRecordingEnabled` | Show the manual REC control in live views. | `"true"` |
| `kerberoshub.frontend.features.liveview.moqRelayUrl` | WebTransport URL of the MoQ relay. | `"https://relay.uug.ai/anon"` |
| `kerberoshub.frontend.features.liveview.moqBroadcastPrefix` | Prefix used to build MoQ broadcast names. | `"devices"` |
| `kerberoshub.frontend.features.liveview.paginationMode` | Liveview behavior setting: `paginationMode` (`scroll`, `numbered` or `maxStreams`). | `"scroll"` |
@@ -248,6 +266,7 @@ Below all configuration options and parameters are listed.
| `kerberoshub.frontend.features.floorplan.colorTrackBoxDrawing` | Color customization for `floorplan` in the frontend. | `"hsla(204, 100%, 50%, 1)"` |
| `kerberoshub.frontend.features.floorplan.colorTrackBoxControlsDelete` | Color customization for `floorplan` in the frontend. | `"hsla(219, 100%, 94%, 1)"` |
| `kerberoshub.frontend.features.faceRedaction.enabled` | Enable or disable `kerberoshub.frontend.features.faceRedaction`. | `"false"` |
| `kerberoshub.frontend.features.faceRedaction.classifierTracksEnabled` | Make classifier-generated tracks available in the redaction modal. | `"true"` |
| `kerberoshub.support.enabled` | Enable or disable in-app support features. | `false` |
| `kerberoshub.oauth2Proxy.enabled` | Enable or disable `kerberoshub.oauth2Proxy`. | `false` |
| `kerberoshub.oauth2Proxy.github.clientId` | Client ID used by `kerberoshub.oauth2Proxy.github`. | `"github-client-id"` |
@@ -291,7 +310,7 @@ Below all configuration options and parameters are listed.
| `kerberoshub.reactivate.repository` | Container image repository for `kerberoshub.reactivate`. | `"uugai/hub-reactivatesubscriptions"` |
| `kerberoshub.reactivate.pullPolicy` | Image pull policy for `kerberoshub.reactivate`. | `"IfNotPresent"` |
| `kerberoshub.reactivate.tag` | Container image tag/version for `kerberoshub.reactivate`. | `"v1.0.2"` |
| `kerberoshub.reactivate.replicas` | Number of replicas for `kerberoshub.reactivate`. | `1` |
| `kerberoshub.reactivate.replicas` | Number of replicas for `kerberoshub.reactivate`. Set to `0` to disable. | `0` |
| `kerberoshub.reactivate.logLevel` | Log verbosity level for `kerberoshub.reactivate`. | `"info"` |
| `kerberoshub.reactivate.resources.requests.memory` | Memory request for `kerberoshub.reactivate`. | `"10Mi"` |
| `kerberoshub.reactivate.resources.requests.cpu` | CPU request for `kerberoshub.reactivate`. | `"10m"` |
@@ -299,7 +318,7 @@ Below all configuration options and parameters are listed.
| `kerberoshub.proxy.repository` | Container image repository for `kerberoshub.proxy`. | `"uugai/hub-proxy"` |
| `kerberoshub.proxy.pullPolicy` | Image pull policy for `kerberoshub.proxy`. | `"IfNotPresent"` |
| `kerberoshub.proxy.tag` | Container image tag/version for `kerberoshub.proxy`. | `"v1.0.0"` |
| `kerberoshub.proxy.replicas` | Number of replicas for `kerberoshub.proxy`. | `1` |
| `kerberoshub.proxy.replicas` | Number of replicas for `kerberoshub.proxy`. Set to `0` to disable. | `0` |
| `kerberoshub.proxy.logLevel` | Log verbosity level for `kerberoshub.proxy`. | `"info"` |
| `kerberoshub.proxy.resources.requests.memory` | Memory request for `kerberoshub.proxy`. | `"10Mi"` |
| `kerberoshub.proxy.resources.requests.cpu` | CPU request for `kerberoshub.proxy`. | `"10m"` |
@@ -314,6 +333,7 @@ Below all configuration options and parameters are listed.
| `kerberospipeline.monitor.pullPolicy` | The Docker registry pull policy. | `"IfNotPresent"` |
| `kerberospipeline.monitor.tag` | The Docker image tag/version. | `"v1.3.9"` |
| `kerberospipeline.monitor.replicas` | Number of replicas for `kerberospipeline.monitor`. | `1` |
| `kerberospipeline.monitor.logLevel` | Monitor log level. Set to `debug` for per-event processing checkpoints. | `"info"` |
| `kerberospipeline.monitor.resources.requests.memory` | Memory request for `kerberospipeline.monitor`. | `"10Mi"` |
| `kerberospipeline.monitor.resources.requests.cpu` | CPU request for `kerberospipeline.monitor`. | `"10m"` |
| `kerberospipeline.sequence.repository` | The [sequencer microservice](https://doc.kerberos.io/hub/pipeline/#sequencer), grouping recordings in chunks/groups. | `"ghcr.io/uug-ai/hub-pipeline-sequence"` |
@@ -486,6 +506,7 @@ Following indexes should be executed on the MongoDB database (Kerberos) to impro
#### Analysis collection
db.getCollection("analysis").createIndex({start:1})
db.getCollection("analysis").createIndex({organisationId:1, projectId:1, key:1}, {name:"analysis_org_project_key"})
db.getCollection("analysis").createIndex({userid:1, key:1})
db.getCollection("analysis").createIndex({userid:1, start:1})

View File

@@ -1,7 +1,15 @@
{
"nav": {
"cases": "Investigations",
"dashboard": "Home"
"dashboard": "Home",
"context": {
"label": "Tenant",
"title": "Switch tenant",
"open": "Choose tenant and project"
}
},
"projects": {
"current": "Active project"
},
"login": {
"signInTo": "Sign in to {{domain}} \u2014 Acme Security"

View File

@@ -1702,7 +1702,9 @@
"k14": "fps",
"k15": "Detection run",
"k16": "Select a detection run",
"k17": "No detections"
"k17": "No detections",
"k18": "Automatic tracks unavailable",
"k19": "Automatic face tracks are disabled. You can still draw redaction boxes manually on the player and submit."
}
},
"motionmap": {

View File

@@ -0,0 +1,48 @@
{{/* Build the path to the configured MongoDB CA bundle. */}}
{{- define "hub.mongodb.tlsCAFile" -}}
{{- if and .Values.mongodb.tls.enabled .Values.mongodb.tls.existingSecret .Values.mongodb.tls.caFileName -}}
{{- printf "%s/%s" .Values.mongodb.tls.mountPath .Values.mongodb.tls.caFileName | clean -}}
{{- end -}}
{{- end -}}
{{/* Add TLS options to a configured MongoDB URI unless they are already present. */}}
{{- define "hub.mongodb.uri" -}}
{{- $uri := .Values.mongodb.uri | default "" -}}
{{- if and .Values.mongodb.tls.enabled $uri -}}
{{- if not (regexMatch "(?i)(^|[?&])tls=" $uri) -}}
{{- $separator := "?" -}}
{{- if contains "?" $uri -}}
{{- $separator = "&" -}}
{{- end -}}
{{- if or (hasSuffix "?" $uri) (hasSuffix "&" $uri) -}}
{{- $separator = "" -}}
{{- end -}}
{{- $uri = printf "%s%stls=true" $uri $separator -}}
{{- end -}}
{{- $caFile := include "hub.mongodb.tlsCAFile" . -}}
{{- if and $caFile (not (regexMatch "(?i)(^|[?&])tlsCAFile=" $uri)) -}}
{{- $separator := "&" -}}
{{- if not (contains "?" $uri) -}}
{{- $separator = "?" -}}
{{- else if or (hasSuffix "?" $uri) (hasSuffix "&" $uri) -}}
{{- $separator = "" -}}
{{- end -}}
{{- $uri = printf "%s%stlsCAFile=%s" $uri $separator $caFile -}}
{{- end -}}
{{- end -}}
{{- $uri -}}
{{- end -}}
{{/* Render the shared MongoDB CA Secret volume. */}}
{{- define "hub.mongodb.tlsVolume" -}}
- name: mongodb-tls
secret:
secretName: {{ .Values.mongodb.tls.existingSecret }}
{{- end -}}
{{/* Render the shared MongoDB CA volume mount. */}}
{{- define "hub.mongodb.tlsVolumeMount" -}}
- name: mongodb-tls
mountPath: {{ .Values.mongodb.tls.mountPath }}
readOnly: true
{{- end -}}

View File

@@ -4,7 +4,7 @@ metadata:
name: mongodb-config
namespace: {{ .Release.Namespace }}
data:
MONGODB_URI: "{{ .Values.mongodb.uri }}"
MONGODB_URI: {{ include "hub.mongodb.uri" . | quote }}
MONGODB_HOST: "{{ .Values.mongodb.host }}"
MONGODB_AUTHENTICATION_MECHANISM: "{{ .Values.mongodb.authenticationMechanism }}"
MONGODB_DATABASE_CREDENTIALS: "{{ .Values.mongodb.adminDatabase }}"
@@ -12,4 +12,7 @@ data:
MONGODB_PASSWORD: "{{ .Values.mongodb.password }}"
MONGODB_RETRY_WRITES: "{{ .Values.mongodb.retryWrites }}"
MONGODB_FLAVOR: "{{ .Values.mongodb.flavor | default "mongodb" }}"
MONGODB_TLS: "{{ .Values.mongodb.tls.enabled }}"
MONGODB_TLS_CA_FILE: {{ include "hub.mongodb.tlsCAFile" . | quote }}
MONGODB_TLS_INSECURE_SKIP_VERIFY: "{{ .Values.mongodb.tls.insecureSkipVerify }}"
MONGODB_DATABASE_CLOUD: "Kerberos"

View File

@@ -131,7 +131,8 @@ spec:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- $serverTLS := .Values.kerberoshub.api.serverTLS }}
{{- if or .Values.kerberoshub.api.volumes (and $serverTLS.enabled $serverTLS.secretName) }}
{{- $mongodbTLS := .Values.mongodb.tls }}
{{- if or .Values.kerberoshub.api.volumes (and $serverTLS.enabled $serverTLS.secretName) (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
volumes:
{{- with .Values.kerberoshub.api.volumes }}
{{- toYaml . | nindent 8 }}
@@ -141,6 +142,9 @@ spec:
secret:
secretName: {{ $serverTLS.secretName }}
{{- end }}
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
{{- include "hub.mongodb.tlsVolume" . | nindent 8 }}
{{- end }}
{{- end }}
{{- with .Values.kerberoshub.api.topologySpreadConstraints }}
topologySpreadConstraints:
@@ -157,7 +161,7 @@ spec:
ports:
- containerPort: 80
name: http
{{- if or .Values.kerberoshub.api.volumeMounts (and $serverTLS.enabled $serverTLS.secretName) }}
{{- if or .Values.kerberoshub.api.volumeMounts (and $serverTLS.enabled $serverTLS.secretName) (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
volumeMounts:
{{- with .Values.kerberoshub.api.volumeMounts}}
{{- toYaml . | nindent 12 }}
@@ -167,6 +171,9 @@ spec:
mountPath: {{ $serverTLS.mountPath }}
readOnly: true
{{- end }}
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
{{- include "hub.mongodb.tlsVolumeMount" . | nindent 12 }}
{{- end }}
{{- end }}
# Mongodb - loaded from ConfigMap
envFrom:
@@ -187,6 +194,23 @@ spec:
value: "{{ .Values.kerberoshub.api.schema }}://{{ .Values.kerberoshub.api.url }}"
- name: PUBLIC_URL
value: "{{ .Values.kerberoshub.frontend.schema }}://{{ .Values.kerberoshub.frontend.url }}"
- name: REFRESH_COOKIE_SECURE
value: {{ eq .Values.kerberoshub.api.schema "https" | quote }}
{{- $corsOrigins := list (printf "%s://%s" .Values.kerberoshub.frontend.schema .Values.kerberoshub.frontend.url) }}
{{- with .Values.kerberoshub.frontend.legacyUrl }}
{{- $corsOrigins = append $corsOrigins (printf "%s://%s" $.Values.kerberoshub.frontend.schema .) }}
{{- end }}
{{- range .Values.kerberoshub.frontend.domains }}
{{- $corsOrigins = append $corsOrigins (printf "%s://%s" $.Values.kerberoshub.frontend.schema .) }}
{{- end }}
{{- if and .Values.kerberoshub.frontend.multiTenant .Values.kerberoshub.frontend.tenantBaseDomain }}
{{- $corsOrigins = append $corsOrigins (printf "%s://*.%s" .Values.kerberoshub.frontend.schema .Values.kerberoshub.frontend.tenantBaseDomain) }}
{{- end }}
{{- if and .Values.kerberoshub.frontend.demoEnabled .Values.kerberoshub.frontend.demoUrl }}
{{- $corsOrigins = append $corsOrigins (printf "%s://%s" .Values.kerberoshub.frontend.schema .Values.kerberoshub.frontend.demoUrl) }}
{{- end }}
- name: CORS_ALLOWED_ORIGINS
value: {{ join "," $corsOrigins | quote }}
{{ if .Values.isPrivate }}
- name: KERBEROS_PRIVATE_CLOUD
value: "true"

View File

@@ -29,10 +29,16 @@ spec:
imagePullSecrets:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- with .Values.kerberoshub.cleanup.volumes }}
{{- $mongodbTLS := .Values.mongodb.tls }}
{{- if or .Values.kerberoshub.cleanup.volumes (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
volumes:
{{- with .Values.kerberoshub.cleanup.volumes }}
{{- toYaml . | nindent 8 }}
{{- end }}
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
{{- include "hub.mongodb.tlsVolume" . | nindent 8 }}
{{- end }}
{{- end }}
{{- with .Values.kerberoshub.cleanup.topologySpreadConstraints }}
topologySpreadConstraints:
{{- toYaml . | nindent 8 }}
@@ -45,10 +51,15 @@ spec:
resources:
{{- toYaml . | nindent 12 }}
{{- end }}
{{- with .Values.kerberoshub.cleanup.volumeMounts }}
{{- if or .Values.kerberoshub.cleanup.volumeMounts (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
volumeMounts:
{{- with .Values.kerberoshub.cleanup.volumeMounts }}
{{- toYaml . | nindent 12 }}
{{- end }}
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
{{- include "hub.mongodb.tlsVolumeMount" . | nindent 12 }}
{{- end }}
{{- end }}
envFrom:
- configMapRef:
name: mongodb-config

View File

@@ -229,6 +229,22 @@ spec:
value: "{{ .Values.kerberoshub.frontend.features.case.enabled }}"
- name: FEATURE_WORKFLOWS_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.workflows.enabled }}"
- name: FEATURE_ORGANISATIONS_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.organisations.enabled }}"
- name: FEATURE_ORGANISATION_SWITCHER_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.organisations.switcherEnabled }}"
- name: FEATURE_ORGANISATION_CREATION_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.organisations.creationEnabled }}"
- name: FEATURE_ORGANISATION_SETTINGS_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.organisations.settingsEnabled }}"
- name: FEATURE_PROJECTS_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.projects.enabled }}"
- name: FEATURE_PROJECT_SWITCHER_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.projects.switcherEnabled }}"
- name: FEATURE_PROJECT_CREATION_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.projects.creationEnabled }}"
- name: FEATURE_PROJECT_SETTINGS_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.projects.settingsEnabled }}"
- name: FEATURE_DARK_MODE
value: "{{ .Values.kerberoshub.frontend.features.darkMode }}"
- name: FEATURE_SPLASH_SCREEN_ENABLED
@@ -249,6 +265,8 @@ spec:
value: "{{ .Values.kerberoshub.frontend.features.liveview.hlsEnabled }}"
- name: FEATURE_MOQ_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.liveview.moqEnabled }}"
- name: FEATURE_REMOTE_RECORDING_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.liveview.remoteRecordingEnabled }}"
- name: MOQ_RELAY_URL
value: "{{ .Values.kerberoshub.frontend.features.liveview.moqRelayUrl }}"
- name: MOQ_BROADCAST_PREFIX
@@ -267,6 +285,26 @@ spec:
# features > floorplan
- name: FEATURE_FLOORPLAN_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.floorplan.enabled }}"
# features > map
- name: MAP_TILE_URL_LIGHT
value: "{{ .Values.kerberoshub.frontend.features.map.tileUrlLight }}"
- name: MAP_TILE_URL_DARK
value: "{{ .Values.kerberoshub.frontend.features.map.tileUrlDark }}"
- name: MAP_ATTRIBUTION
value: "{{ .Values.kerberoshub.frontend.features.map.attribution }}"
- name: MAP_OVERLAY_TILE_URL
value: "{{ .Values.kerberoshub.frontend.features.map.overlayTileUrl }}"
- name: MAP_OVERLAY_API_KEY
value: "{{ .Values.kerberoshub.frontend.features.map.overlayApiKey }}"
- name: MAP_OVERLAY_ATTRIBUTION
value: "{{ .Values.kerberoshub.frontend.features.map.overlayAttribution }}"
- name: MAP_OVERLAY_MIN_ZOOM
value: "{{ .Values.kerberoshub.frontend.features.map.overlayMinZoom }}"
- name: MAP_OVERLAY_MAX_ZOOM
value: "{{ .Values.kerberoshub.frontend.features.map.overlayMaxZoom }}"
- name: MAP_OVERLAY_OPACITY
value: "{{ .Values.kerberoshub.frontend.features.map.overlayOpacity }}"
- name: COLOR_TRACK_BOX
value: "{{ .Values.kerberoshub.frontend.features.floorplan.colorTrackBox }}"
- name: COLOR_TRACK_BOX_HOVER
@@ -300,7 +338,9 @@ spec:
# features > face redaction
- name: FEATURE_FACE_REDACTION_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.faceRedaction.enabled }}"
value: "{{ .Values.kerberoshub.frontend.features.faceRedaction.enabled }}"
- name: FEATURE_FACE_REDACTION_CLASSIFIER_TRACKS_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.faceRedaction.classifierTracksEnabled }}"
# features > media
- name: FEATURE_MEDIA_FILTER_DATE_ENABLED

View File

@@ -312,10 +312,22 @@ spec:
value: "{{ .Values.kerberoshub.frontend.features.case.enabled }}"
- name: FEATURE_WORKFLOWS_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.workflows.enabled }}"
- name: FEATURE_ORGANISATIONS_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.organisations.enabled }}"
- name: FEATURE_ORGANISATION_SWITCHER_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.organisations.switcherEnabled }}"
- name: FEATURE_ORGANISATION_CREATION_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.organisations.creationEnabled }}"
- name: FEATURE_ORGANISATION_SETTINGS_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.organisations.settingsEnabled }}"
- name: FEATURE_PROJECTS_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.projects.enabled }}"
- name: FEATURE_PROJECT_SWITCHER_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.projects.switcherEnabled }}"
- name: FEATURE_PROJECT_CREATION_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.projects.creationEnabled }}"
- name: FEATURE_PROJECT_SETTINGS_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.projects.settingsEnabled }}"
- name: FEATURE_DARK_MODE
value: "{{ .Values.kerberoshub.frontend.features.darkModeEnabled }}"
- name: FEATURE_SPLASH_SCREEN_ENABLED
@@ -338,6 +350,8 @@ spec:
value: "{{ .Values.kerberoshub.frontend.features.liveview.hlsEnabled }}"
- name: FEATURE_MOQ_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.liveview.moqEnabled }}"
- name: FEATURE_REMOTE_RECORDING_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.liveview.remoteRecordingEnabled }}"
- name: MOQ_RELAY_URL
value: "{{ .Values.kerberoshub.frontend.features.liveview.moqRelayUrl }}"
- name: MOQ_BROADCAST_PREFIX
@@ -364,6 +378,18 @@ spec:
value: "{{ .Values.kerberoshub.frontend.features.map.tileUrlDark }}"
- name: MAP_ATTRIBUTION
value: "{{ .Values.kerberoshub.frontend.features.map.attribution }}"
- name: MAP_OVERLAY_TILE_URL
value: "{{ .Values.kerberoshub.frontend.features.map.overlayTileUrl }}"
- name: MAP_OVERLAY_API_KEY
value: "{{ .Values.kerberoshub.frontend.features.map.overlayApiKey }}"
- name: MAP_OVERLAY_ATTRIBUTION
value: "{{ .Values.kerberoshub.frontend.features.map.overlayAttribution }}"
- name: MAP_OVERLAY_MIN_ZOOM
value: "{{ .Values.kerberoshub.frontend.features.map.overlayMinZoom }}"
- name: MAP_OVERLAY_MAX_ZOOM
value: "{{ .Values.kerberoshub.frontend.features.map.overlayMaxZoom }}"
- name: MAP_OVERLAY_OPACITY
value: "{{ .Values.kerberoshub.frontend.features.map.overlayOpacity }}"
- name: COLOR_TRACK_BOX
value: "{{ .Values.kerberoshub.frontend.features.floorplan.colorTrackBox }}"
@@ -406,7 +432,9 @@ spec:
# features > face redaction
- name: FEATURE_FACE_REDACTION_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.faceRedaction.enabled }}"
value: "{{ .Values.kerberoshub.frontend.features.faceRedaction.enabled }}"
- name: FEATURE_FACE_REDACTION_CLASSIFIER_TRACKS_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.faceRedaction.classifierTracksEnabled }}"
# features > media
- name: FEATURE_MEDIA_FILTER_DATE_ENABLED

View File

@@ -29,10 +29,16 @@ spec:
imagePullSecrets:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- with .Values.kerberoshub.monitordevice.volumes }}
{{- $mongodbTLS := .Values.mongodb.tls }}
{{- if or .Values.kerberoshub.monitordevice.volumes (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
volumes:
{{- with .Values.kerberoshub.monitordevice.volumes }}
{{- toYaml . | nindent 8 }}
{{- end }}
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
{{- include "hub.mongodb.tlsVolume" . | nindent 8 }}
{{- end }}
{{- end }}
{{- with .Values.kerberoshub.monitordevice.topologySpreadConstraints }}
topologySpreadConstraints:
{{- toYaml . | nindent 8 }}
@@ -45,10 +51,15 @@ spec:
resources:
{{- toYaml . | nindent 12 }}
{{- end }}
{{- with .Values.kerberoshub.monitordevice.volumeMounts}}
{{- if or .Values.kerberoshub.monitordevice.volumeMounts (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
volumeMounts:
{{- with .Values.kerberoshub.monitordevice.volumeMounts}}
{{- toYaml . | nindent 12 }}
{{- end }}
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
{{- include "hub.mongodb.tlsVolumeMount" . | nindent 12 }}
{{- end }}
{{- end }}
envFrom:
- configMapRef:
name: mongodb-config

View File

@@ -26,10 +26,16 @@ spec:
imagePullSecrets:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- with .Values.kerberoshub.reactivate.volumes }}
{{- $mongodbTLS := .Values.mongodb.tls }}
{{- if or .Values.kerberoshub.reactivate.volumes (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
volumes:
{{- with .Values.kerberoshub.reactivate.volumes }}
{{- toYaml . | nindent 8 }}
{{- end }}
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
{{- include "hub.mongodb.tlsVolume" . | nindent 8 }}
{{- end }}
{{- end }}
{{- with .Values.kerberoshub.reactivate.topologySpreadConstraints }}
topologySpreadConstraints:
{{- toYaml . | nindent 8 }}
@@ -38,10 +44,15 @@ spec:
- name: hub-reactivate-subscription
image: "{{ .Values.global.imageRegistry }}{{ .Values.kerberoshub.reactivate.repository }}:{{ .Values.kerberoshub.reactivate.tag }}"
imagePullPolicy: {{ .Values.kerberoshub.reactivate.pullPolicy }}
{{- with .Values.kerberoshub.reactivate.volumeMounts }}
{{- if or .Values.kerberoshub.reactivate.volumeMounts (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
volumeMounts:
{{- with .Values.kerberoshub.reactivate.volumeMounts }}
{{- toYaml . | nindent 12 }}
{{- end }}
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
{{- include "hub.mongodb.tlsVolumeMount" . | nindent 12 }}
{{- end }}
{{- end }}
envFrom:
- configMapRef:
name: mongodb-config

View File

@@ -1,15 +1,17 @@
{{/*
Assemble the deployment-global workflow definitions (WORKFLOW_DEFINITIONS) as a
JSON array from every *enabled* workflow under kerberoshub.workflows.definitions.
This is the engine's single routing source: several distinct workflows can run
over one recording — each opens its own run and dispatches only its own stages.
This is the engine's boot-loaded configuration source and deployment stage
catalog: several distinct config workflows can run over one recording — each
opens its own run and dispatches only its own stages. Organisation-scoped
database workflows are discovered separately at runtime.
Each enabled definition contributes one workflow object:
name the map key (the workflow's human-readable name; also its identity
the engine derives a stable id from it when the definition carries
no explicit id).
enabled always true here (a disabled definition is skipped entirely).
source "config" provenance marking a Helm-seeded, deployment-global,
source "config" provenance marking a Helm-defined, deployment-global,
ops-managed workflow (read-only in the API, no owning organisation).
triggers how a run OPENS. Defaults to a single bare automatic trigger
(opens for every recording); narrow with device/schedule triggers.

View File

@@ -29,10 +29,16 @@ spec:
imagePullSecrets:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- with .Values.kerberoshub.services.workflows.volumes }}
{{- $mongodbTLS := .Values.mongodb.tls }}
{{- if or .Values.kerberoshub.services.workflows.volumes (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
volumes:
{{- with .Values.kerberoshub.services.workflows.volumes }}
{{- toYaml . | nindent 8 }}
{{- end }}
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
{{- include "hub.mongodb.tlsVolume" . | nindent 8 }}
{{- end }}
{{- end }}
{{- with .Values.kerberoshub.services.workflows.topologySpreadConstraints }}
topologySpreadConstraints:
{{- toYaml . | nindent 8 }}
@@ -45,10 +51,15 @@ spec:
resources:
{{- toYaml . | nindent 12 }}
{{- end }}
{{- with .Values.kerberoshub.services.workflows.volumeMounts }}
{{- if or .Values.kerberoshub.services.workflows.volumeMounts (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
volumeMounts:
{{- with .Values.kerberoshub.services.workflows.volumeMounts }}
{{- toYaml . | nindent 12 }}
{{- end }}
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
{{- include "hub.mongodb.tlsVolumeMount" . | nindent 12 }}
{{- end }}
{{- end }}
envFrom:
- configMapRef:
name: mongodb-config
@@ -62,8 +73,10 @@ spec:
# named workflows it runs (WORKFLOW_DEFINITIONS): each with its own
# trigger and executable stages, assembled from the enabled definitions
# under kerberoshub.workflows.definitions (see _workflows-helpers.tpl).
# Definitions are the engine's single routing source; empty means no
# workflows run.
# Definitions are the engine's boot-loaded config source and deployment
# stage catalog. Organisation-scoped database workflows are read per
# recording; an in-cluster engine still requires at least one config
# definition so an empty catalog cannot silently drop traffic.
- name: WORKFLOWS_QUEUE
value: "{{ .Values.kerberoshub.services.workflows.queue }}"
- name: WORKFLOW_DEFINITIONS

View File

@@ -29,10 +29,16 @@ spec:
imagePullSecrets:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- with .Values.kerberospipeline.analysis.volumes }}
{{- $mongodbTLS := .Values.mongodb.tls }}
{{- if or .Values.kerberospipeline.analysis.volumes (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
volumes:
{{- with .Values.kerberospipeline.analysis.volumes }}
{{- toYaml . | nindent 8 }}
{{- end }}
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
{{- include "hub.mongodb.tlsVolume" . | nindent 8 }}
{{- end }}
{{- end }}
{{- with .Values.kerberospipeline.analysis.topologySpreadConstraints }}
topologySpreadConstraints:
{{- toYaml . | nindent 8 }}
@@ -45,10 +51,15 @@ spec:
resources:
{{- toYaml . | nindent 12 }}
{{- end }}
{{- with .Values.kerberospipeline.analysis.volumeMounts }}
{{- if or .Values.kerberospipeline.analysis.volumeMounts (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
volumeMounts:
{{- with .Values.kerberospipeline.analysis.volumeMounts }}
{{- toYaml . | nindent 12 }}
{{- end }}
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
{{- include "hub.mongodb.tlsVolumeMount" . | nindent 12 }}
{{- end }}
{{- end }}
envFrom:
- configMapRef:
name: mongodb-config

View File

@@ -29,10 +29,16 @@ spec:
imagePullSecrets:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- with .Values.kerberospipeline.event.volumes }}
{{- $mongodbTLS := .Values.mongodb.tls }}
{{- if or .Values.kerberospipeline.event.volumes (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
volumes:
{{- with .Values.kerberospipeline.event.volumes }}
{{- toYaml . | nindent 8 }}
{{- end }}
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
{{- include "hub.mongodb.tlsVolume" . | nindent 8 }}
{{- end }}
{{- end }}
{{- with .Values.kerberospipeline.event.topologySpreadConstraints }}
topologySpreadConstraints:
{{- toYaml . | nindent 8 }}
@@ -45,10 +51,15 @@ spec:
resources:
{{- toYaml . | nindent 12 }}
{{- end }}
{{- with .Values.kerberospipeline.event.volumeMounts }}
{{- if or .Values.kerberospipeline.event.volumeMounts (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
volumeMounts:
{{- with .Values.kerberospipeline.event.volumeMounts }}
{{- toYaml . | nindent 12 }}
{{- end }}
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
{{- include "hub.mongodb.tlsVolumeMount" . | nindent 12 }}
{{- end }}
{{- end }}
ports:
- containerPort: 8080
envFrom:

View File

@@ -29,10 +29,16 @@ spec:
imagePullSecrets:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- with .Values.kerberospipeline.export.volumes }}
{{- $mongodbTLS := .Values.mongodb.tls }}
{{- if or .Values.kerberospipeline.export.volumes (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
volumes:
{{- with .Values.kerberospipeline.export.volumes }}
{{- toYaml . | nindent 8 }}
{{- end }}
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
{{- include "hub.mongodb.tlsVolume" . | nindent 8 }}
{{- end }}
{{- end }}
{{- with .Values.kerberospipeline.export.topologySpreadConstraints }}
topologySpreadConstraints:
{{- toYaml . | nindent 8 }}
@@ -45,10 +51,15 @@ spec:
resources:
{{- toYaml . | nindent 12 }}
{{- end }}
{{- with .Values.kerberospipeline.export.volumeMounts }}
{{- if or .Values.kerberospipeline.export.volumeMounts (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
volumeMounts:
{{- with .Values.kerberospipeline.export.volumeMounts }}
{{- toYaml . | nindent 12 }}
{{- end }}
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
{{- include "hub.mongodb.tlsVolumeMount" . | nindent 12 }}
{{- end }}
{{- end }}
envFrom:
- configMapRef:
name: mongodb-config

View File

@@ -29,10 +29,16 @@ spec:
imagePullSecrets:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- with .Values.kerberospipeline.monitor.volumes }}
{{- $mongodbTLS := .Values.mongodb.tls }}
{{- if or .Values.kerberospipeline.monitor.volumes (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
volumes:
{{- with .Values.kerberospipeline.monitor.volumes }}
{{- toYaml . | nindent 8 }}
{{- end }}
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
{{- include "hub.mongodb.tlsVolume" . | nindent 8 }}
{{- end }}
{{- end }}
{{- with .Values.kerberospipeline.monitor.topologySpreadConstraints }}
topologySpreadConstraints:
{{- toYaml . | nindent 8 }}
@@ -45,14 +51,23 @@ spec:
resources:
{{- toYaml . | nindent 12 }}
{{- end }}
{{- with .Values.kerberospipeline.monitor.volumeMounts }}
{{- if or .Values.kerberospipeline.monitor.volumeMounts (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
volumeMounts:
{{- with .Values.kerberospipeline.monitor.volumeMounts }}
{{- toYaml . | nindent 12 }}
{{- end }}
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
{{- include "hub.mongodb.tlsVolumeMount" . | nindent 12 }}
{{- end }}
{{- end }}
envFrom:
- configMapRef:
name: mongodb-config
env:
# Application
- name: LOG_LEVEL
value: "{{ .Values.kerberospipeline.monitor.logLevel }}"
# Queue
- name: QUEUE_SYSTEM
value: "{{ .Values.queueProvider }}"

View File

@@ -29,10 +29,16 @@ spec:
imagePullSecrets:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- with .Values.kerberospipeline.notifyTest.volumes }}
{{- $mongodbTLS := .Values.mongodb.tls }}
{{- if or .Values.kerberospipeline.notifyTest.volumes (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
volumes:
{{- with .Values.kerberospipeline.notifyTest.volumes }}
{{- toYaml . | nindent 8 }}
{{- end }}
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
{{- include "hub.mongodb.tlsVolume" . | nindent 8 }}
{{- end }}
{{- end }}
{{- with .Values.kerberospipeline.notifyTest.topologySpreadConstraints }}
topologySpreadConstraints:
{{- toYaml . | nindent 8 }}
@@ -45,10 +51,15 @@ spec:
resources:
{{- toYaml . | nindent 12 }}
{{- end }}
{{- with .Values.kerberospipeline.notifyTest.volumeMounts}}
{{- if or .Values.kerberospipeline.notifyTest.volumeMounts (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
volumeMounts:
{{- with .Values.kerberospipeline.notifyTest.volumeMounts}}
{{- toYaml . | nindent 12 }}
{{- end }}
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
{{- include "hub.mongodb.tlsVolumeMount" . | nindent 12 }}
{{- end }}
{{- end }}
envFrom:
- configMapRef:
name: mongodb-config

View File

@@ -29,10 +29,16 @@ spec:
imagePullSecrets:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- with .Values.kerberospipeline.notify.volumes }}
{{- $mongodbTLS := .Values.mongodb.tls }}
{{- if or .Values.kerberospipeline.notify.volumes (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
volumes:
{{- with .Values.kerberospipeline.notify.volumes }}
{{- toYaml . | nindent 8 }}
{{- end }}
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
{{- include "hub.mongodb.tlsVolume" . | nindent 8 }}
{{- end }}
{{- end }}
{{- with .Values.kerberospipeline.notify.topologySpreadConstraints }}
topologySpreadConstraints:
{{- toYaml . | nindent 8 }}
@@ -45,10 +51,15 @@ spec:
resources:
{{- toYaml . | nindent 12 }}
{{- end }}
{{- with .Values.kerberospipeline.notify.volumeMounts}}
{{- if or .Values.kerberospipeline.notify.volumeMounts (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
volumeMounts:
{{- with .Values.kerberospipeline.notify.volumeMounts}}
{{- toYaml . | nindent 12 }}
{{- end }}
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
{{- include "hub.mongodb.tlsVolumeMount" . | nindent 12 }}
{{- end }}
{{- end }}
envFrom:
- configMapRef:
name: mongodb-config

View File

@@ -29,10 +29,16 @@ spec:
imagePullSecrets:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- with .Values.kerberospipeline.sequence.volumes }}
{{- $mongodbTLS := .Values.mongodb.tls }}
{{- if or .Values.kerberospipeline.sequence.volumes (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
volumes:
{{- with .Values.kerberospipeline.sequence.volumes }}
{{- toYaml . | nindent 8 }}
{{- end }}
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
{{- include "hub.mongodb.tlsVolume" . | nindent 8 }}
{{- end }}
{{- end }}
{{- with .Values.kerberospipeline.sequence.topologySpreadConstraints }}
topologySpreadConstraints:
{{- toYaml . | nindent 8 }}
@@ -45,10 +51,15 @@ spec:
resources:
{{- toYaml . | nindent 12 }}
{{- end }}
{{- with .Values.kerberospipeline.sequence.volumeMounts }}
{{- if or .Values.kerberospipeline.sequence.volumeMounts (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
volumeMounts:
{{- with .Values.kerberospipeline.sequence.volumeMounts }}
{{- toYaml . | nindent 12 }}
{{- end }}
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
{{- include "hub.mongodb.tlsVolumeMount" . | nindent 12 }}
{{- end }}
{{- end }}
envFrom:
- configMapRef:
name: mongodb-config

View File

@@ -29,10 +29,16 @@ spec:
imagePullSecrets:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- with .Values.kerberospipeline.throttler.volumes }}
{{- $mongodbTLS := .Values.mongodb.tls }}
{{- if or .Values.kerberospipeline.throttler.volumes (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
volumes:
{{- with .Values.kerberospipeline.throttler.volumes }}
{{- toYaml . | nindent 8 }}
{{- end }}
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
{{- include "hub.mongodb.tlsVolume" . | nindent 8 }}
{{- end }}
{{- end }}
{{- with .Values.kerberospipeline.throttler.topologySpreadConstraints }}
topologySpreadConstraints:
{{- toYaml . | nindent 8 }}
@@ -45,10 +51,15 @@ spec:
resources:
{{- toYaml . | nindent 12 }}
{{- end }}
{{- with .Values.kerberospipeline.throttler.volumeMounts }}
{{- if or .Values.kerberospipeline.throttler.volumeMounts (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
volumeMounts:
{{- with .Values.kerberospipeline.throttler.volumeMounts }}
{{- toYaml . | nindent 12 }}
{{- end }}
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
{{- include "hub.mongodb.tlsVolumeMount" . | nindent 12 }}
{{- end }}
{{- end }}
envFrom:
- configMapRef:
name: mongodb-config

View File

@@ -27,10 +27,16 @@ spec:
imagePullSecrets:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- with .Values.kerberoshub.forwarder.volumes }}
{{- $mongodbTLS := .Values.mongodb.tls }}
{{- if or .Values.kerberoshub.forwarder.volumes (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
volumes:
{{- with .Values.kerberoshub.forwarder.volumes }}
{{- toYaml . | nindent 8 }}
{{- end }}
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
{{- include "hub.mongodb.tlsVolume" . | nindent 8 }}
{{- end }}
{{- end }}
{{- with .Values.kerberoshub.forwarder.topologySpreadConstraints }}
topologySpreadConstraints:
{{- toYaml . | nindent 8 }}
@@ -43,10 +49,15 @@ spec:
requests:
memory: 10Mi
cpu: 10m
{{- with .Values.kerberoshub.forwarder.volumeMounts }}
{{- if or .Values.kerberoshub.forwarder.volumeMounts (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
volumeMounts:
{{- with .Values.kerberoshub.forwarder.volumeMounts }}
{{- toYaml . | nindent 12 }}
{{- end }}
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
{{- include "hub.mongodb.tlsVolumeMount" . | nindent 12 }}
{{- end }}
{{- end }}
envFrom:
- configMapRef:
name: mongodb-config

View File

@@ -60,6 +60,15 @@ mongodb:
# and indexes, complex $lookup pipelines, etc.). When using DocumentDB you
# should also set retryWrites: "false".
flavor: "mongodb"
# TLS for MongoDB-compatible backends. When uri is set, missing TLS query
# parameters are appended automatically. AWS DocumentDB requires TLS and a
# trusted RDS CA bundle, typically stored in an existing Kubernetes Secret.
tls:
enabled: false
existingSecret: ""
caFileName: ""
mountPath: "/etc/mongodb/tls"
insecureSkipVerify: false
###################################################
# MQTT configuration (bi-directional communication)
###################################################
@@ -231,7 +240,7 @@ kerberoshub:
api:
repository: ghcr.io/uug-ai/hub-api
pullPolicy: IfNotPresent
tag: "v1.9.29"
tag: "v1.9.51"
replicas: 2
topologySpreadConstraints: [] # Optional pod topology spread constraints (empty = none).
# Set to false to skip rendering the hub-api Service (e.g. when an
@@ -344,7 +353,7 @@ kerberoshub:
frontend:
repository: ghcr.io/uug-ai/hub-frontend
pullPolicy: IfNotPresent
tag: "v1.9.32"
tag: "v1.13.9"
replicas: 2
topologySpreadConstraints: [] # Optional pod topology spread constraints (empty = none).
# Set to false to skip rendering the hub-frontend Service (e.g. when an
@@ -461,7 +470,7 @@ kerberoshub:
# hidden and `defaultLanguage` is always forced; users cannot change it.
i18n:
enabled: "true" # Enable or disable the language switcher 'true' or 'false'
defaultLanguage: "en" # Default language code: en, nl, pl, tr, fr, sv, de
defaultLanguage: "en" # Default language code: en, nl, pl, pt, it, tr, fr, sv, de
# Case management is a feature that allows you to create cases, and link recordings, devices, sites, groups, markers and events to those cases.
case:
enabled: "true" # Enable or disable case management feature 'true' or 'false'
@@ -470,19 +479,33 @@ kerberoshub:
enabled: "false" # Enable or disable workflows feature 'true' or 'false'
# Organisation controls remain visible as a read-only current organisation when switching is disabled.
organisations:
enabled: "" # Enable or disable the organisation feature family, including projects; when empty, child groups apply independently
switcherEnabled: "false" # Enable or disable organisation switching 'true' or 'false'
creationEnabled: "false" # Enable or disable organisation creation; requires switcherEnabled 'true' or 'false'
settingsEnabled: "false" # Enable or disable the organisation settings link 'true' or 'false'
projects:
enabled: "" # Fallback project group switch used only when organisations.enabled is empty
switcherEnabled: "false" # Enable or disable the read-only project dropdown 'true' or 'false'
creationEnabled: "false" # Reserved for project creation UI 'true' or 'false'
settingsEnabled: "false" # Reserved for project settings UI 'true' or 'false'
# Map tile configuration
map:
tileUrlLight: "https://{s}.basemaps.cartocdn.com/rastertiles/voyager/{z}/{x}/{y}{r}.png" # Map tile URL for light mode
tileUrlDark: "https://{s}.basemaps.cartocdn.com/dark_all/{z}/{x}/{y}{r}.png" # Map tile URL for dark mode
attribution: "&copy; <a href='https://www.openstreetmap.org/copyright' target='_blank'>OpenStreetMap</a>" # Map attribution
overlayTileUrl: "" # Optional XYZ overlay URL; supports {z}, {x}, {y}, and {apiKey}
overlayApiKey: "" # Optional browser-visible API key substituted into overlayTileUrl
overlayAttribution: "" # Attribution displayed when the overlay is enabled
overlayMinZoom: "0" # Minimum overlay zoom level
overlayMaxZoom: "19" # Maximum overlay zoom level
overlayOpacity: "1" # Overlay opacity from 0 to 1
# Live view page
liveview:
defaultStreamMode: "SD" # Default stream mode 'SD' or 'HD' (will be migrated to 'preview' or 'live')
liveStreamMode: "webrtc" # Transport backing the LIVE (HD) mode: 'webrtc' (default), 'hls' or 'moq'
hlsEnabled: "true" # Offer HLS as a selectable LIVE transport 'true' or 'false'. When 'false' the HLS option is removed from the front-end and streams use webrtc
moqEnabled: "false" # Offer MoQ as a selectable LIVE transport 'true' or 'false'
remoteRecordingEnabled: "true" # Show the manual REC control in live views
moqRelayUrl: "https://relay.uug.ai/anon" # WebTransport URL of the MoQ relay
moqBroadcastPrefix: "devices" # Prefix used to build devices/<deviceKey>/live.hang broadcast names
paginationMode: "scroll" # Pagination mode in live view 'scroll', 'numbered' or 'maxStreams'
@@ -548,6 +571,7 @@ kerberoshub:
# Face redaction feature
faceRedaction:
enabled: "false" # Enable or disable face redaction 'true' or 'false'
classifierTracksEnabled: "true" # Make classifier-generated tracks available in the redaction modal
# Optional integrations
mixpanel: # We can keep track logging in Mixpanel as well
apikey: "xxx"
@@ -583,7 +607,7 @@ kerberoshub:
cleanup:
repository: ghcr.io/uug-ai/hub-cleanup
pullPolicy: IfNotPresent
tag: "v1.4.16"
tag: "v1.4.19"
replicas: 1 # Number of pods for the service.
topologySpreadConstraints: [] # Optional pod topology spread constraints (empty = none).
# Optional extra volumes / volumeMounts for this deployment (empty = none).
@@ -642,16 +666,18 @@ kerberoshub:
# -----------------------------------------------------------------------
# Global workflow definitions — the named workflows the engine runs.
#
# `definitions` is the engine's single routing source: several distinct
# workflows can run over one recording, each opening its own run and
# dispatching only its own stages. It is a MAP keyed by workflow name (names
# are unique and merge cleanly across -f / --set overrides). Ships empty; the
# commented block is a worked example of an object-tracking + loitering
# pipeline. Add more keys to run more workflows.
# `definitions` is the engine's deployment-global configuration source and
# stage catalog: several distinct workflows can run over one recording, each
# opening its own run and dispatching only its own stages. Database-backed
# organisation workflows, when present, are read separately per recording.
# This is a MAP keyed by workflow name (names are unique and merge cleanly
# across -f / --set overrides). Ships empty; the commented block is a worked
# example of an object-tracking + loitering pipeline. Add more keys to run
# more config workflows.
#
# Each definition:
# enabled include this workflow (soft-delete toggle).
# source always rendered as "config" (a Helm-seeded, ops-managed,
# source always rendered as "config" (a Helm-defined, ops-managed,
# deployment-global workflow — read-only in the API).
# triggers how a run OPENS. Omit for a single bare automatic trigger
# (opens for every recording); the per-stage `needs` then decide
@@ -663,9 +689,9 @@ kerberoshub:
# {operation?, condition?} — operation is the readiness GATE (the
# upstream op whose data must be present before the condition is
# read; omit for a check on the run root itself), condition is
# {path, op, value} where path is ABSOLUTE from the run root and
# resolves through string-keyed maps only (it cannot index into
# arrays). needsMode combines multiple needs: "any" (default;
# {path, op, value} where path is ABSOLUTE from the run root;
# a `*` segment fans out across array elements. needsMode combines
# multiple needs: "any" (default;
# fire on the first match) or "all" (a join; fire once every need
# has resolved and matched). The queue is taken from the matching
# services.<operation> entry, so dispatch and consume cannot drift.
@@ -674,19 +700,19 @@ kerberoshub:
# kerberoshub.services.<operation> (deploy the objecttracking / loitering
# workers below).
definitions: {}
#tracking-workflow:
# enabled: true
# triggers:
# - type: automatic
# stages:
# - operation: objecttracking
# dispatch: always
# - operation: loitering
# dispatch: conditional
# # Fire loitering once objecttracking has resolved — a readiness join
# # (no condition ⇒ gate on the upstream's presence, not a value).
# needs:
# - operation: objecttracking
#tracking-workflow:
# enabled: true
# triggers:
# - type: automatic
# stages:
# - operation: objecttracking
# dispatch: always
# - operation: loitering
# dispatch: conditional
# # Fire loitering once objecttracking has resolved — a readiness join
# # (no condition ⇒ gate on the upstream's presence, not a value).
# needs:
# - operation: objecttracking
# Workflow deployments. Every workflows-subsystem Deployment's image/tag/
# replicas/resources/queue lives here in a single, uniform shape:
# - `workflows` is the engine itself (the orchestrator). It is deployed
@@ -699,9 +725,10 @@ kerberoshub:
# when its own `enabled` is true AND the workflows engine is enabled.
services:
# hub-workflows — the workflows engine (orchestrator). Consumes the engine
# queue, evaluates the workflow definitions (WORKFLOW_DEFINITIONS) and
# dispatches to the stage workers below. Deployed when workflows.enabled is
# true; it has no separate `enabled` here.
# queue, evaluates the boot-loaded config workflows (WORKFLOW_DEFINITIONS)
# plus organisation-scoped database workflows, and dispatches to the stage
# workers below. Deployed when workflows.enabled is true; it has no separate
# `enabled` here.
workflows:
repository: ghcr.io/uug-ai/hub-workflows
pullPolicy: IfNotPresent
@@ -723,61 +750,61 @@ kerberoshub:
requests:
memory: 10Mi
cpu: 10m
# ---------------------------------------------------------------------
# EXAMPLE custom stage worker (commented out) — hub-loitering.
#
# Companion deployment for the workflows.definitions example above (the
# loitering stage of tracking-workflow). Uncomment to deploy the demo
# worker. It ships as its own repository/module.
# See https://github.com/uug-ai/hub-loitering.
#loitering:
# # Deploy the hub-loitering worker.
# enabled: true
# repository: ghcr.io/uug-ai/hub-loitering
# pullPolicy: IfNotPresent
# tag: "v1.0.0"
# replicas: 1 # Number of pods for the worker.
# topologySpreadConstraints: [] # Optional pod topology spread constraints (empty = none).
# #volumes:
# # - name: extra
# # emptyDir: {}
# #volumeMounts:
# # - name: extra
# # mountPath: /data
# logLevel: "info" # possible values: trace, debug, info, warn, error
# # Queue this worker consumes dispatched messages from (LOITERING_QUEUE). This
# # same value is taken into the matching workflows.definitions stage, so the
# # engine dispatches and the worker consumes the same queue with no drift.
# # Convention: "kcloud-<operation>-queue.fifo".
# queue: "kcloud-loitering-queue.fifo"
# resources:
# requests:
# memory: 10Mi
# cpu: 10m
# ---------------------------------------------------------------------
# EXAMPLE stage worker (commented out) for the workflows.definitions example
# above — hub-objecttracking. Uncomment the worker whose operation a
# definition references, so the engine dispatches and the worker consumes the
# same queue with no drift.
#objecttracking:
# # Deploy the object-tracking worker (operation "objecttracking").
# enabled: true
# repository: ghcr.io/uug-ai/hub-objecttracking
# pullPolicy: IfNotPresent
# tag: "v1.0.0"
# replicas: 1 # Number of pods for the worker.
# topologySpreadConstraints: [] # Optional pod topology spread constraints (empty = none).
# logLevel: "info" # possible values: trace, debug, info, warn, error
# # Queue this worker consumes dispatched messages from (OBJECTTRACKING_QUEUE).
# queue: "kcloud-objecttracking-queue.fifo"
# resources:
# requests:
# memory: 10Mi
# cpu: 10m
# ---------------------------------------------------------------------
# EXAMPLE custom stage worker (commented out) — hub-loitering.
#
# Companion deployment for the workflows.definitions example above (the
# loitering stage of tracking-workflow). Uncomment to deploy the demo
# worker. It ships as its own repository/module.
# See https://github.com/uug-ai/hub-loitering.
#loitering:
# # Deploy the hub-loitering worker.
# enabled: true
# repository: ghcr.io/uug-ai/hub-loitering
# pullPolicy: IfNotPresent
# tag: "v1.0.0"
# replicas: 1 # Number of pods for the worker.
# topologySpreadConstraints: [] # Optional pod topology spread constraints (empty = none).
# #volumes:
# # - name: extra
# # emptyDir: {}
# #volumeMounts:
# # - name: extra
# # mountPath: /data
# logLevel: "info" # possible values: trace, debug, info, warn, error
# # Queue this worker consumes dispatched messages from (LOITERING_QUEUE). This
# # same value is taken into the matching workflows.definitions stage, so the
# # engine dispatches and the worker consumes the same queue with no drift.
# # Convention: "kcloud-<operation>-queue.fifo".
# queue: "kcloud-loitering-queue.fifo"
# resources:
# requests:
# memory: 10Mi
# cpu: 10m
# ---------------------------------------------------------------------
# EXAMPLE stage worker (commented out) for the workflows.definitions example
# above — hub-objecttracking. Uncomment the worker whose operation a
# definition references, so the engine dispatches and the worker consumes the
# same queue with no drift.
#objecttracking:
# # Deploy the object-tracking worker (operation "objecttracking").
# enabled: true
# repository: ghcr.io/uug-ai/hub-objecttracking
# pullPolicy: IfNotPresent
# tag: "v1.0.0"
# replicas: 1 # Number of pods for the worker.
# topologySpreadConstraints: [] # Optional pod topology spread constraints (empty = none).
# logLevel: "info" # possible values: trace, debug, info, warn, error
# # Queue this worker consumes dispatched messages from (OBJECTTRACKING_QUEUE).
# queue: "kcloud-objecttracking-queue.fifo"
# resources:
# requests:
# memory: 10Mi
# cpu: 10m
monitordevice:
repository: ghcr.io/uug-ai/hub-monitor-device
pullPolicy: IfNotPresent
tag: "v1.4.0"
tag: "v1.4.2"
replicas: 1 # Number of pods for the service.
topologySpreadConstraints: [] # Optional pod topology spread constraints (empty = none).
logLevel: "info" # possible values: trace, debug, info, warn, error
@@ -797,7 +824,7 @@ kerberoshub:
repository: uugai/hub-reactivatesubscriptions
pullPolicy: IfNotPresent
tag: "v1.0.2"
replicas: 1 # Number of pods for the service.
replicas: 0 # Number of pods for the service. Set to 0 to disable.
topologySpreadConstraints: [] # Optional pod topology spread constraints (empty = none).
# Optional extra volumes / volumeMounts for this deployment (empty = none).
#volumes:
@@ -833,7 +860,7 @@ kerberoshub:
repository: uugai/hub-proxy
pullPolicy: IfNotPresent
tag: "v1.0.0"
replicas: 1 # Number of pods for the service.
replicas: 0 # Number of pods for the service. Set to 0 to disable.
topologySpreadConstraints: [] # Optional pod topology spread constraints (empty = none).
# Optional extra volumes / volumeMounts for this deployment (empty = none).
#volumes:
@@ -855,7 +882,7 @@ kerberospipeline:
event:
repository: ghcr.io/uug-ai/hub-pipeline-event
pullPolicy: IfNotPresent
tag: "v1.3.0"
tag: "v1.3.1"
replicas: 1 # Number of pods for the service.
topologySpreadConstraints: [] # Optional pod topology spread constraints (empty = none).
# Optional extra volumes / volumeMounts for this deployment (empty = none).
@@ -873,7 +900,7 @@ kerberospipeline:
monitor:
repository: ghcr.io/uug-ai/hub-pipeline-monitor
pullPolicy: IfNotPresent
tag: "v1.3.10"
tag: "v1.3.13"
replicas: 1 # Number of pods for the service.
topologySpreadConstraints: [] # Optional pod topology spread constraints (empty = none).
# Optional extra volumes / volumeMounts for this deployment (empty = none).
@@ -883,6 +910,7 @@ kerberospipeline:
#volumeMounts:
# - name: extra
# mountPath: /data
logLevel: "info" # possible values: debug, info, warn, error
resources:
requests:
memory: 10Mi
@@ -890,7 +918,7 @@ kerberospipeline:
sequence:
repository: ghcr.io/uug-ai/hub-pipeline-sequence
pullPolicy: IfNotPresent
tag: "v1.6.18"
tag: "v1.6.26"
replicas: 1 # Number of pods for the service.
topologySpreadConstraints: [] # Optional pod topology spread constraints (empty = none).
# Optional extra volumes / volumeMounts for this deployment (empty = none).
@@ -907,7 +935,7 @@ kerberospipeline:
throttler:
repository: uugai/hub-pipeline-throttler
pullPolicy: IfNotPresent
tag: "v1.2.0"
tag: "v1.2.1"
replicas: 1 # Number of pods for the service.
topologySpreadConstraints: [] # Optional pod topology spread constraints (empty = none).
# Optional extra volumes / volumeMounts for this deployment (empty = none).
@@ -925,7 +953,7 @@ kerberospipeline:
notify:
repository: ghcr.io/uug-ai/hub-pipeline-notification
pullPolicy: IfNotPresent
tag: "v1.3.9"
tag: "v1.3.18"
replicas: 1 # Number of pods for the service.
topologySpreadConstraints: [] # Optional pod topology spread constraints (empty = none).
logLevel: "info" # possible values: trace, debug, info, warn, error
@@ -944,7 +972,7 @@ kerberospipeline:
notifyTest:
repository: uugai/hub-pipeline-notification-test
pullPolicy: IfNotPresent
tag: "v1.2.1"
tag: "v1.2.2"
replicas: 1 # Number of pods for the service.
topologySpreadConstraints: [] # Optional pod topology spread constraints (empty = none).
resources:
@@ -962,7 +990,7 @@ kerberospipeline:
analysis:
repository: ghcr.io/uug-ai/hub-pipeline-analysis
pullPolicy: IfNotPresent
tag: "v1.7.17"
tag: "v1.8.5"
replicas: 1 # Number of pods for the service.
topologySpreadConstraints: [] # Optional pod topology spread constraints (empty = none).
# Optional extra volumes / volumeMounts for this deployment (empty = none).
@@ -980,7 +1008,7 @@ kerberospipeline:
dominantColor:
repository: ghcr.io/uug-ai/hub-pipeline-dominantcolors
pullPolicy: IfNotPresent
tag: "v2.0.2"
tag: "v2.0.3"
replicas: 3 # Number of pods for the service.
topologySpreadConstraints: [] # Optional pod topology spread constraints (empty = none).
# Optional extra volumes / volumeMounts for this deployment (empty = none).
@@ -1001,7 +1029,7 @@ kerberospipeline:
thumbnail:
repository: ghcr.io/uug-ai/hub-pipeline-thumbnail
pullPolicy: IfNotPresent
tag: "v1.3.6"
tag: "v1.3.10"
replicas: 2 # Number of pods for the service.
topologySpreadConstraints: [] # Optional pod topology spread constraints (empty = none).
# Optional extra volumes / volumeMounts for this deployment (empty = none).
@@ -1027,7 +1055,7 @@ kerberospipeline:
counting:
repository: uugai/hub-pipeline-counting
pullPolicy: IfNotPresent
tag: "v1.6.3"
tag: "v2.0.0"
replicas: 1 # Number of pods for the service.
topologySpreadConstraints: [] # Optional pod topology spread constraints (empty = none).
# Optional extra volumes / volumeMounts for this deployment (empty = none).
@@ -1046,7 +1074,7 @@ kerberospipeline:
enabled: false # Enable or disable the sprite generation 'true' or 'false
repository: ghcr.io/uug-ai/hub-pipeline-sprite
pullPolicy: IfNotPresent
tag: "v1.1.14"
tag: "v1.1.16"
replicas: 5 # Number of pods for the service.
topologySpreadConstraints: [] # Optional pod topology spread constraints (empty = none).
# Optional extra volumes / volumeMounts for this deployment (empty = none).
@@ -1070,7 +1098,7 @@ kerberospipeline:
export:
repository: ghcr.io/uug-ai/hub-pipeline-export
pullPolicy: IfNotPresent
tag: "v1.2.8"
tag: "v1.2.10"
replicas: 2 # Number of pods for the service.
topologySpreadConstraints: [] # Optional pod topology spread constraints (empty = none).
logLevel: "info" # possible values: trace, debug, info, warn, error