mirror of
https://github.com/kerberos-io/helm-charts.git
synced 2026-09-13 11:46:45 +00:00
Compare commits
55 Commits
KilianBout
...
main
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
cb7e51e2e3 | ||
|
|
293ae4699c | ||
|
|
142e7d5c54 | ||
|
|
07fd4c345d | ||
|
|
0ed38b82f7 | ||
|
|
2c17f5a579 | ||
|
|
ae3d1d26fb | ||
|
|
dae3d663b4 | ||
|
|
3d5c0ecd3e | ||
|
|
6454e8fa33 | ||
|
|
fbffe917bb | ||
|
|
5c1d233c45 | ||
|
|
f9de70fce4 | ||
|
|
6c50f1d359 | ||
|
|
9badb35126 | ||
|
|
fb26c6b755 | ||
|
|
3719ec0bbe | ||
|
|
c262433aa1 | ||
|
|
f70aedc5d5 | ||
|
|
2d75d84509 | ||
|
|
c5231ca3cf | ||
|
|
776599cd30 | ||
|
|
8629c701a1 | ||
|
|
e3a38a007d | ||
|
|
f097916ceb | ||
|
|
678d4d84ea | ||
|
|
0deaf41420 | ||
|
|
813b008955 | ||
|
|
32b71a82ca | ||
|
|
7bbf4ae78c | ||
|
|
6f34bd4735 | ||
|
|
24918922fd | ||
|
|
0fadcb74d0 | ||
|
|
f834d9b8f5 | ||
|
|
eefe96c679 | ||
|
|
93888e2855 | ||
|
|
759ac8dbf8 | ||
|
|
4aaa70f121 | ||
|
|
ad7ef4ac12 | ||
|
|
5ad56f9730 | ||
|
|
91eb64a2f3 | ||
|
|
55ae6cdd3e | ||
|
|
f492c14336 | ||
|
|
d4a13a4cff | ||
|
|
98cc8d4f2d | ||
|
|
a5125eee69 | ||
|
|
b2ff3e2e20 | ||
|
|
277ddde3b4 | ||
|
|
7878be79d6 | ||
|
|
123bde292e | ||
|
|
e76311872e | ||
|
|
0f2176822a | ||
|
|
8ca4c402f8 | ||
|
|
8d9b943100 | ||
|
|
c29647ec62 |
@@ -16,7 +16,7 @@ type: application
|
||||
# This is the chart version. This version number should be incremented each time you make changes
|
||||
# to the chart and its templates, including the app version.
|
||||
# Versions are expected to follow Semantic Versioning (https://semver.org/)
|
||||
version: 0.126.1
|
||||
version: 0.138.0
|
||||
|
||||
# This is the version number of the application being deployed. This version number should be
|
||||
# incremented each time you make changes to the application. Versions are not expected to
|
||||
|
||||
@@ -53,6 +53,11 @@ Below all configuration options and parameters are listed.
|
||||
| `mongodb.password` | MongoDB user password, by default `'yourmongodbpassword'` | `"yourpassword"` |
|
||||
| `mongodb.retryWrites` | Enable or disable MongoDB retryable writes. | `"true"` |
|
||||
| `mongodb.flavor` | Backend engine flavor: `"mongodb"` (native MongoDB / Atlas) or `"documentdb"` (AWS DocumentDB). The `documentdb` flavor disables features DocumentDB does not support (geospatial queries/indexes, complex `$lookup` pipelines). When set to `documentdb`, also set `mongodb.retryWrites: "false"`. | `"mongodb"` |
|
||||
| `mongodb.tls.enabled` | Enable TLS for MongoDB connections. When `mongodb.uri` is set, the chart appends missing `tls=true` and `tlsCAFile` query parameters. | `false` |
|
||||
| `mongodb.tls.existingSecret` | Existing Kubernetes Secret containing the MongoDB CA bundle. The Secret is mounted into every workload that consumes `mongodb-config`. | `""` |
|
||||
| `mongodb.tls.caFileName` | Key and filename of the CA bundle in `mongodb.tls.existingSecret` (for AWS DocumentDB, typically `global-bundle.pem`). | `""` |
|
||||
| `mongodb.tls.mountPath` | Read-only directory where the MongoDB CA Secret is mounted. | `"/etc/mongodb/tls"` |
|
||||
| `mongodb.tls.insecureSkipVerify` | Skip MongoDB certificate and hostname verification. This is insecure and intended only for local testing. | `false` |
|
||||
| `mqtt.host` | MQTT (Vernemq) hostname. | `"mqtt.yourdomain.com"` |
|
||||
| `mqtt.port` | MQTT (Vernemq) port for WSS (secure sockets), by default `'8443'`. | `"8443"` |
|
||||
| `mqtt.protocol` | MQTT (Vernemq) protocol, by default `'wss'`. | `"wss"` |
|
||||
@@ -202,24 +207,41 @@ Below all configuration options and parameters are listed.
|
||||
| `kerberoshub.frontend.features.i18n.enabled` | Enable or disable the runtime language switcher in the front-end. When `"false"`, `defaultLanguage` is forced and users cannot change it. | `"true"` |
|
||||
| `kerberoshub.frontend.features.i18n.defaultLanguage` | Default language code used by the front-end (e.g. `en`, `nl`, `pl`, `tr`, `fr`, `sv`, `de`). | `"en"` |
|
||||
| `kerberoshub.frontend.features.workflows.enabled` | Enable or disable the workflows feature in the frontend. | `"false"` |
|
||||
| `kerberoshub.frontend.features.audit.enabled` | Enable or disable the owner/admin Audit events page and navigation link. | `"true"` |
|
||||
| `kerberoshub.frontend.features.organisations.enabled` | Enable or disable the organisation feature family, including projects. When empty, child groups apply independently. | `""` |
|
||||
| `kerberoshub.frontend.features.organisations.switcherEnabled` | Enable or disable the organisation dropdown and switching. The current organisation remains visible when disabled. | `"false"` |
|
||||
| `kerberoshub.frontend.features.organisations.creationEnabled` | Enable or disable organisation creation. Requires organisation switching to be enabled. | `"false"` |
|
||||
| `kerberoshub.frontend.features.organisations.settingsEnabled` | Enable or disable the organisation identity link to organisation settings. | `"false"` |
|
||||
| `kerberoshub.frontend.features.projects.enabled` | Fallback project group switch used when the organisations umbrella is unset. | `""` |
|
||||
| `kerberoshub.frontend.features.projects.switcherEnabled` | Enable or disable the read-only project dropdown. | `"false"` |
|
||||
| `kerberoshub.frontend.features.projects.creationEnabled` | Reserved for the project creation UI. | `"false"` |
|
||||
| `kerberoshub.frontend.features.projects.settingsEnabled` | Reserved for the project settings UI. | `"false"` |
|
||||
| `kerberoshub.frontend.features.map.tileUrlLight` | Tile URL used by the map in light mode. | `"https://{s}.basemaps.cartocdn.com/rastertiles/voyager/{z}/{x}/{y}{r}.png"` |
|
||||
| `kerberoshub.frontend.features.map.tileUrlDark` | Tile URL used by the map in dark mode. | `"https://{s}.basemaps.cartocdn.com/dark_all/{z}/{x}/{y}{r}.png"` |
|
||||
| `kerberoshub.frontend.features.map.attribution` | Attribution text displayed on the map tiles. | `"© <a href='https://www.openstreetmap.org/copyright' target='_blank'>OpenStreetMap</a>"` |
|
||||
| `kerberoshub.frontend.features.map.overlayTileUrl` | Optional XYZ overlay URL supporting `{z}`, `{x}`, `{y}`, and `{apiKey}`. Empty disables the overlay. | `""` |
|
||||
| `kerberoshub.frontend.features.map.overlayApiKey` | Optional browser-visible API key substituted for `{apiKey}` in the overlay URL. | `""` |
|
||||
| `kerberoshub.frontend.features.map.overlayAttribution` | Attribution text displayed when the overlay is enabled. | `""` |
|
||||
| `kerberoshub.frontend.features.map.overlayMinZoom` | Minimum zoom level for overlay tiles. | `"0"` |
|
||||
| `kerberoshub.frontend.features.map.overlayMaxZoom` | Maximum zoom level for overlay tiles. | `"19"` |
|
||||
| `kerberoshub.frontend.features.map.overlayOpacity` | Overlay opacity from `0` to `1`. | `"1"` |
|
||||
| `kerberoshub.frontend.features.liveview.defaultStreamMode` | Liveview behavior setting: `defaultStreamMode`. | `"SD"` |
|
||||
| `kerberoshub.frontend.features.liveview.liveStreamMode` | Transport backing LIVE mode: `webrtc`, `hls`, or `moq`. | `"webrtc"` |
|
||||
| `kerberoshub.frontend.features.liveview.hlsEnabled` | Offer HLS as a selectable LIVE transport. | `"true"` |
|
||||
| `kerberoshub.frontend.features.liveview.moqEnabled` | Offer MoQ as a selectable LIVE transport. | `"false"` |
|
||||
| `kerberoshub.frontend.features.liveview.remoteRecordingEnabled` | Show the manual REC control in live views. | `"true"` |
|
||||
| `kerberoshub.frontend.features.liveview.moqRelayUrl` | WebTransport URL of the MoQ relay. | `"https://relay.uug.ai/anon"` |
|
||||
| `kerberoshub.frontend.features.liveview.moqBroadcastPrefix` | Prefix used to build MoQ broadcast names. | `"devices"` |
|
||||
| `kerberoshub.frontend.features.liveview.paginationMode` | Liveview behavior setting: `paginationMode` (`scroll`, `numbered` or `maxStreams`). | `"scroll"` |
|
||||
| `kerberoshub.frontend.features.liveview.pageSize` | Liveview behavior setting: `pageSize` (max streams shown per page in `numbered` mode). | `"6"` |
|
||||
| `kerberoshub.frontend.features.liveview.maxStreams` | Liveview behavior setting: `maxStreams`. | `"-1"` |
|
||||
| `kerberoshub.frontend.features.chart.colors` | Ordered colors shared by chart series and marker detection overlays. | `["#84569f", "#3ba7ff", "#ff5c8a", "#4ad991", "#ffb84d", "#ff7043"]` |
|
||||
| `kerberoshub.frontend.features.chart.colorChartSelectionFill` | Fill color for chart selection regions. | `"rgba(132, 86, 159, 0.07)"` |
|
||||
| `kerberoshub.frontend.features.chart.colorChartSelectionStroke` | Stroke color for chart selection regions. | `"rgba(132, 86, 159, 0.4)"` |
|
||||
| `kerberoshub.frontend.features.chart.colorChartGridStroke` | Stroke color for chart grid lines. | `"rgba(0, 106, 255, 0.18)"` |
|
||||
| `kerberoshub.frontend.features.devices.hideAgent` | Hide agent controls in the devices section of the frontend. | `"false"` |
|
||||
| `kerberoshub.frontend.features.devices.analyticsEnabled` | Enable or disable the Analytics tab on device detail pages. | `"true"` |
|
||||
| `kerberoshub.frontend.features.dashboard.sitesFullscreenEnabled` | Enable or disable the fullscreen Sites map on the Dashboard. | `"true"` |
|
||||
| `kerberoshub.frontend.features.media.filter.date.enabled` | Enable or disable `kerberoshub.frontend.features.media.filter.date`. | `"true"` |
|
||||
| `kerberoshub.frontend.features.media.filter.sites.enabled` | Enable or disable `kerberoshub.frontend.features.media.filter.sites`. | `"true"` |
|
||||
| `kerberoshub.frontend.features.media.filter.groups.enabled` | Enable or disable `kerberoshub.frontend.features.media.filter.groups`. | `"true"` |
|
||||
@@ -230,8 +252,9 @@ Below all configuration options and parameters are listed.
|
||||
| `kerberoshub.frontend.features.media.filter.sort.enabled` | Enable or disable `kerberoshub.frontend.features.media.filter.sort`. | `"true"` |
|
||||
| `kerberoshub.frontend.features.media.filter.category.enabled` | Enable or disable `kerberoshub.frontend.features.media.filter.category`. | `"true"` |
|
||||
| `kerberoshub.frontend.features.media.filter.markers.enabled` | Enable or disable `kerberoshub.frontend.features.media.filter.markers`. | `"true"` |
|
||||
| `kerberoshub.frontend.features.media.filter.markerOptionsByDate.enabled` | Limit marker, category, event, and tag filter options to the selected recordings day. | `"false"` |
|
||||
| `kerberoshub.frontend.features.media.filter.events.enabled` | Enable or disable `kerberoshub.frontend.features.media.filter.events`. | `"true"` |
|
||||
| `kerberoshub.frontend.features.liveview.defaultStreamMode` | Default live stream mode: `SD` or `HD`. | `"SD"` |lter.tags`. | `"true"` |
|
||||
| `kerberoshub.frontend.features.media.filter.tags.enabled` | Enable or disable `kerberoshub.frontend.features.media.filter.tags`. | `"true"` |
|
||||
| `kerberoshub.frontend.features.media.filter.defaultView` | Default view for the media page: `timeline` or `grid`. | `"timeline"` |
|
||||
| `kerberoshub.frontend.features.floorplan.enabled` | Enable or disable `kerberoshub.frontend.features.floorplan`. | `"true"` |
|
||||
| `kerberoshub.frontend.features.floorplan.colorDeviceActive` | Color customization for `floorplan` in the frontend. | `"hsla(131, 31%, 52%, 1)"` |
|
||||
@@ -248,6 +271,7 @@ Below all configuration options and parameters are listed.
|
||||
| `kerberoshub.frontend.features.floorplan.colorTrackBoxDrawing` | Color customization for `floorplan` in the frontend. | `"hsla(204, 100%, 50%, 1)"` |
|
||||
| `kerberoshub.frontend.features.floorplan.colorTrackBoxControlsDelete` | Color customization for `floorplan` in the frontend. | `"hsla(219, 100%, 94%, 1)"` |
|
||||
| `kerberoshub.frontend.features.faceRedaction.enabled` | Enable or disable `kerberoshub.frontend.features.faceRedaction`. | `"false"` |
|
||||
| `kerberoshub.frontend.features.faceRedaction.classifierTracksEnabled` | Make classifier-generated tracks available in the redaction modal. | `"true"` |
|
||||
| `kerberoshub.support.enabled` | Enable or disable in-app support features. | `false` |
|
||||
| `kerberoshub.oauth2Proxy.enabled` | Enable or disable `kerberoshub.oauth2Proxy`. | `false` |
|
||||
| `kerberoshub.oauth2Proxy.github.clientId` | Client ID used by `kerberoshub.oauth2Proxy.github`. | `"github-client-id"` |
|
||||
@@ -279,8 +303,23 @@ Below all configuration options and parameters are listed.
|
||||
| `kerberoshub.cleanup.globalPassIntervalHours` | Minimum hours between global cleanup passes. | `"0"` |
|
||||
| `kerberoshub.cleanup.globalPassDeleteBudget` | Max documents deleted during a global pass. | `"0"` |
|
||||
| `kerberoshub.cleanup.defaultTaskRetentionDays` | Default retention (in days) applied to tasks without an explicit `retention_days`. Tasks older than this (anchored on `creation_date`) are deleted with their `case_media` rows. Set to `"0"` or a negative value to keep tasks forever. Must match `kerberoshub.api.defaultTaskRetentionDays`. | `"0"` |
|
||||
| `kerberoshub.cleanup.auditEventRetentionDays` | Deployment-wide audit-event retention in days, independent of recording plans, inactive-account cleanup, and the optional global pass. Set to `"0"` or a negative value to keep audit events indefinitely. | `"400"` |
|
||||
| `kerberoshub.cleanup.resources.requests.memory` | Memory request for `kerberoshub.cleanup`. | `"10Mi"` |
|
||||
| `kerberoshub.cleanup.resources.requests.cpu` | CPU request for `kerberoshub.cleanup`. | `"10m"` |
|
||||
| `kerberoshub.audit.enabled` | Deploy the Hub audit service. Its first responsibility is forwarding canonical MongoDB `audit_events` to configured destinations. | `false` |
|
||||
| `kerberoshub.audit.repository` | Hub audit service container image repository. | `"ghcr.io/uug-ai/hub-audit"` |
|
||||
| `kerberoshub.audit.pullPolicy` | Hub audit service image pull policy. | `"IfNotPresent"` |
|
||||
| `kerberoshub.audit.tag` | Hub audit service image tag. | `"v1.0.0"` |
|
||||
| `kerberoshub.audit.replicas` | Number of audit service replicas. Per-destination MongoDB leases prevent concurrent delivery. | `1` |
|
||||
| `kerberoshub.audit.dispatchInterval` | How often the mounted destination configuration is reloaded and eligible destinations are polled. | `"5s"` |
|
||||
| `kerberoshub.audit.leaseDuration` | Per-destination lease duration. It must exceed every destination timeout by at least 30 seconds. | `"2m"` |
|
||||
| `kerberoshub.audit.terminationGracePeriodSeconds` | Pod termination grace period. Keep this longer than `leaseDuration` so an in-flight cycle can finish. | `150` |
|
||||
| `kerberoshub.audit.destinations` | Webhook destinations. Each entry supports `id`, `enabled`, `url`, delivery limits, filters, public `headers`, `bearerTokenSecret`, and arbitrary `secretHeaders`. Destination IDs retain independent checkpoints. | `[]` |
|
||||
| `kerberoshub.audit.serviceMonitor.enabled` | Create a Prometheus `ServiceMonitor` for audit service metrics. | `true` |
|
||||
| `kerberoshub.audit.serviceMonitor.interval` | Audit service metrics scrape interval. | `"15s"` |
|
||||
| `kerberoshub.audit.volumes` | Additional pod volumes, for example a private webhook CA bundle. | `[]` |
|
||||
| `kerberoshub.audit.volumeMounts` | Additional audit service container volume mounts. | `[]` |
|
||||
| `kerberoshub.audit.extraEnv` | Additional audit service environment variables. | `[]` |
|
||||
| `kerberoshub.monitordevice.repository` | The monitoring microservice, following up the status of your cameras and Kerberos Agents. | `"ghcr.io/uug-ai/hub-monitor-device"` |
|
||||
| `kerberoshub.monitordevice.pullPolicy` | The Docker registry pull policy. | `"IfNotPresent"` |
|
||||
| `kerberoshub.monitordevice.tag` | The Docker image tag/version. | `"v1.4.0"` |
|
||||
@@ -291,15 +330,16 @@ Below all configuration options and parameters are listed.
|
||||
| `kerberoshub.reactivate.repository` | Container image repository for `kerberoshub.reactivate`. | `"uugai/hub-reactivatesubscriptions"` |
|
||||
| `kerberoshub.reactivate.pullPolicy` | Image pull policy for `kerberoshub.reactivate`. | `"IfNotPresent"` |
|
||||
| `kerberoshub.reactivate.tag` | Container image tag/version for `kerberoshub.reactivate`. | `"v1.0.2"` |
|
||||
| `kerberoshub.reactivate.replicas` | Number of replicas for `kerberoshub.reactivate`. | `1` |
|
||||
| `kerberoshub.reactivate.replicas` | Number of replicas for `kerberoshub.reactivate`. Set to `0` to disable. | `0` |
|
||||
| `kerberoshub.reactivate.logLevel` | Log verbosity level for `kerberoshub.reactivate`. | `"info"` |
|
||||
| `kerberoshub.reactivate.resources.requests.memory` | Memory request for `kerberoshub.reactivate`. | `"10Mi"` |
|
||||
| `kerberoshub.reactivate.resources.requests.cpu` | CPU request for `kerberoshub.reactivate`. | `"10m"` |
|
||||
| `kerberoshub.forwarder.enabled` | Enable or disable the Hub forwarder component. | `false` |
|
||||
| `kerberoshub.proxy.enabled` | Enable or disable the legacy Hub proxy Deployment and LoadBalancer Service. | `false` |
|
||||
| `kerberoshub.proxy.repository` | Container image repository for `kerberoshub.proxy`. | `"uugai/hub-proxy"` |
|
||||
| `kerberoshub.proxy.pullPolicy` | Image pull policy for `kerberoshub.proxy`. | `"IfNotPresent"` |
|
||||
| `kerberoshub.proxy.tag` | Container image tag/version for `kerberoshub.proxy`. | `"v1.0.0"` |
|
||||
| `kerberoshub.proxy.replicas` | Number of replicas for `kerberoshub.proxy`. | `1` |
|
||||
| `kerberoshub.proxy.replicas` | Number of replicas for `kerberoshub.proxy` when enabled. | `0` |
|
||||
| `kerberoshub.proxy.logLevel` | Log verbosity level for `kerberoshub.proxy`. | `"info"` |
|
||||
| `kerberoshub.proxy.resources.requests.memory` | Memory request for `kerberoshub.proxy`. | `"10Mi"` |
|
||||
| `kerberoshub.proxy.resources.requests.cpu` | CPU request for `kerberoshub.proxy`. | `"10m"` |
|
||||
@@ -314,6 +354,7 @@ Below all configuration options and parameters are listed.
|
||||
| `kerberospipeline.monitor.pullPolicy` | The Docker registry pull policy. | `"IfNotPresent"` |
|
||||
| `kerberospipeline.monitor.tag` | The Docker image tag/version. | `"v1.3.9"` |
|
||||
| `kerberospipeline.monitor.replicas` | Number of replicas for `kerberospipeline.monitor`. | `1` |
|
||||
| `kerberospipeline.monitor.logLevel` | Monitor log level. Set to `debug` for per-event processing checkpoints. | `"info"` |
|
||||
| `kerberospipeline.monitor.resources.requests.memory` | Memory request for `kerberospipeline.monitor`. | `"10Mi"` |
|
||||
| `kerberospipeline.monitor.resources.requests.cpu` | CPU request for `kerberospipeline.monitor`. | `"10m"` |
|
||||
| `kerberospipeline.sequence.repository` | The [sequencer microservice](https://doc.kerberos.io/hub/pipeline/#sequencer), grouping recordings in chunks/groups. | `"ghcr.io/uug-ai/hub-pipeline-sequence"` |
|
||||
@@ -334,6 +375,7 @@ Below all configuration options and parameters are listed.
|
||||
| `kerberospipeline.notify.tag` | The Docker image tag/version. | `"v1.3.9"` |
|
||||
| `kerberospipeline.notify.replicas` | Number of replicas for `kerberospipeline.notify`. | `1` |
|
||||
| `kerberospipeline.notify.logLevel` | Log verbosity level for `kerberospipeline.notify`. | `"info"` |
|
||||
| `kerberospipeline.notify.notificationExpiryMinutes` | Maximum recording age in minutes before notification delivery. Set to `"0"` to disable the freshness cutoff. | `"15"` |
|
||||
| `kerberospipeline.notify.resources.requests.memory` | Memory request for `kerberospipeline.notify`. | `"10Mi"` |
|
||||
| `kerberospipeline.notify.resources.requests.cpu` | CPU request for `kerberospipeline.notify`. | `"10m"` |
|
||||
| `kerberospipeline.notifyTest.repository` | The notification service for testing, the different channels. | `"uugai/hub-pipeline-notification-test"` |
|
||||
@@ -466,6 +508,20 @@ As mentioned during the Post installation step, you'll import some `.nosql` file
|
||||
|
||||
Within the Kerberos Hub front-end you'll see the option to filter through classifications. This filtered is stored in the `settings` collection. By changing the entries of the `classifications` object, you can add, edit or remove items from the filters.
|
||||
|
||||
New deployments should define the shared classification list through
|
||||
`classificationCatalog`. Each entry contains the stable classifier output
|
||||
`key`, the user-facing `label`, and an `icon` key. Hub API exposes this catalog
|
||||
to alerts and filters. When the mounted catalog is unavailable, compatible Hub
|
||||
API versions fall back to the legacy `settings` document and then the built-in
|
||||
classification list.
|
||||
|
||||
```yaml
|
||||
classificationCatalog:
|
||||
- key: forklift
|
||||
label: Forklift
|
||||
icon: vehicle
|
||||
```
|
||||
|
||||
### Indexing
|
||||
|
||||
Following indexes should be executed on the MongoDB database (Kerberos) to improve future performance. Within Kerberos Hub several queries are executed, following indexes will improve the loading times. If not applied you might experience application timeouts or reduced performance when storing lots of data.
|
||||
@@ -486,6 +542,7 @@ Following indexes should be executed on the MongoDB database (Kerberos) to impro
|
||||
#### Analysis collection
|
||||
|
||||
db.getCollection("analysis").createIndex({start:1})
|
||||
db.getCollection("analysis").createIndex({organisationId:1, projectId:1, key:1}, {name:"analysis_org_project_key"})
|
||||
db.getCollection("analysis").createIndex({userid:1, key:1})
|
||||
db.getCollection("analysis").createIndex({userid:1, start:1})
|
||||
|
||||
|
||||
@@ -1702,7 +1702,9 @@
|
||||
"k14": "fps",
|
||||
"k15": "Detection run",
|
||||
"k16": "Select a detection run",
|
||||
"k17": "No detections"
|
||||
"k17": "No detections",
|
||||
"k18": "Automatic tracks unavailable",
|
||||
"k19": "Automatic face tracks are disabled. You can still draw redaction boxes manually on the player and submit."
|
||||
}
|
||||
},
|
||||
"motionmap": {
|
||||
|
||||
48
charts/hub/templates/_helpers.tpl
Normal file
48
charts/hub/templates/_helpers.tpl
Normal file
@@ -0,0 +1,48 @@
|
||||
{{/* Build the path to the configured MongoDB CA bundle. */}}
|
||||
{{- define "hub.mongodb.tlsCAFile" -}}
|
||||
{{- if and .Values.mongodb.tls.enabled .Values.mongodb.tls.existingSecret .Values.mongodb.tls.caFileName -}}
|
||||
{{- printf "%s/%s" .Values.mongodb.tls.mountPath .Values.mongodb.tls.caFileName | clean -}}
|
||||
{{- end -}}
|
||||
{{- end -}}
|
||||
|
||||
{{/* Add TLS options to a configured MongoDB URI unless they are already present. */}}
|
||||
{{- define "hub.mongodb.uri" -}}
|
||||
{{- $uri := .Values.mongodb.uri | default "" -}}
|
||||
{{- if and .Values.mongodb.tls.enabled $uri -}}
|
||||
{{- if not (regexMatch "(?i)(^|[?&])tls=" $uri) -}}
|
||||
{{- $separator := "?" -}}
|
||||
{{- if contains "?" $uri -}}
|
||||
{{- $separator = "&" -}}
|
||||
{{- end -}}
|
||||
{{- if or (hasSuffix "?" $uri) (hasSuffix "&" $uri) -}}
|
||||
{{- $separator = "" -}}
|
||||
{{- end -}}
|
||||
{{- $uri = printf "%s%stls=true" $uri $separator -}}
|
||||
{{- end -}}
|
||||
{{- $caFile := include "hub.mongodb.tlsCAFile" . -}}
|
||||
{{- if and $caFile (not (regexMatch "(?i)(^|[?&])tlsCAFile=" $uri)) -}}
|
||||
{{- $separator := "&" -}}
|
||||
{{- if not (contains "?" $uri) -}}
|
||||
{{- $separator = "?" -}}
|
||||
{{- else if or (hasSuffix "?" $uri) (hasSuffix "&" $uri) -}}
|
||||
{{- $separator = "" -}}
|
||||
{{- end -}}
|
||||
{{- $uri = printf "%s%stlsCAFile=%s" $uri $separator $caFile -}}
|
||||
{{- end -}}
|
||||
{{- end -}}
|
||||
{{- $uri -}}
|
||||
{{- end -}}
|
||||
|
||||
{{/* Render the shared MongoDB CA Secret volume. */}}
|
||||
{{- define "hub.mongodb.tlsVolume" -}}
|
||||
- name: mongodb-tls
|
||||
secret:
|
||||
secretName: {{ .Values.mongodb.tls.existingSecret }}
|
||||
{{- end -}}
|
||||
|
||||
{{/* Render the shared MongoDB CA volume mount. */}}
|
||||
{{- define "hub.mongodb.tlsVolumeMount" -}}
|
||||
- name: mongodb-tls
|
||||
mountPath: {{ .Values.mongodb.tls.mountPath }}
|
||||
readOnly: true
|
||||
{{- end -}}
|
||||
@@ -0,0 +1,8 @@
|
||||
apiVersion: v1
|
||||
kind: ConfigMap
|
||||
metadata:
|
||||
name: classification-catalog
|
||||
namespace: {{ .Release.Namespace }}
|
||||
data:
|
||||
classifications.json: |-
|
||||
{{- toPrettyJson .Values.classificationCatalog | nindent 4 }}
|
||||
51
charts/hub/templates/configmap-hub-audit.yaml
Normal file
51
charts/hub/templates/configmap-hub-audit.yaml
Normal file
@@ -0,0 +1,51 @@
|
||||
{{- if and (or (eq .Values.mode "all") (eq .Values.mode "ui")) .Values.kerberoshub.audit.enabled -}}
|
||||
{{- $destinations := list -}}
|
||||
{{- $destinationIDs := dict -}}
|
||||
{{- range $index, $destination := .Values.kerberoshub.audit.destinations -}}
|
||||
{{- $id := required (printf "id is required for audit destination %d" $index) $destination.id -}}
|
||||
{{- if not (regexMatch "^[a-z][a-z0-9-]{0,62}$" $id) -}}
|
||||
{{- fail (printf "audit destination id %q must match ^[a-z][a-z0-9-]{0,62}$" $id) -}}
|
||||
{{- end -}}
|
||||
{{- if hasKey $destinationIDs $id -}}
|
||||
{{- fail (printf "duplicate audit destination id %q" $id) -}}
|
||||
{{- end -}}
|
||||
{{- $_ := set $destinationIDs $id true -}}
|
||||
{{- $url := required (printf "url is required for audit destination %s" $id) $destination.url -}}
|
||||
{{- $entry := dict
|
||||
"id" $id
|
||||
"type" (default "webhook" $destination.type)
|
||||
"enabled" $destination.enabled
|
||||
"url" $url
|
||||
"timeoutSeconds" (default 10 $destination.timeoutSeconds)
|
||||
"batchSize" (default 100 $destination.batchSize)
|
||||
"maxAttempts" (default 10 $destination.maxAttempts)
|
||||
"startAt" (default "latest" $destination.startAt)
|
||||
"headers" (default dict $destination.headers)
|
||||
"filters" (default dict $destination.filters) -}}
|
||||
{{- $secretRoot := printf "/var/run/secrets/audit-destinations/%s" $id -}}
|
||||
{{- $bearer := default dict $destination.bearerTokenSecret -}}
|
||||
{{- if gt (len $bearer) 0 -}}
|
||||
{{- $secretName := required (printf "bearerTokenSecret.name is required for destination %s" $id) $bearer.name -}}
|
||||
{{- $secretKey := default "token" $bearer.key -}}
|
||||
{{- $_ := set $entry "bearerTokenFile" (printf "%s/bearer-%s" $secretRoot (sha256sum (printf "%s:%s" $secretName $secretKey) | trunc 12)) -}}
|
||||
{{- end -}}
|
||||
{{- $headerFiles := dict -}}
|
||||
{{- range $headerName, $secret := (default dict $destination.secretHeaders) -}}
|
||||
{{- $secretName := required (printf "secretName is required for destination %s header %s" $id $headerName) $secret.secretName -}}
|
||||
{{- $secretKey := required (printf "secretKey is required for destination %s header %s" $id $headerName) $secret.secretKey -}}
|
||||
{{- $_ := set $headerFiles $headerName (printf "%s/header-%s" $secretRoot (sha256sum (printf "%s:%s:%s" $headerName $secretName $secretKey) | trunc 12)) -}}
|
||||
{{- end -}}
|
||||
{{- if gt (len $headerFiles) 0 -}}
|
||||
{{- $_ := set $entry "headerFiles" $headerFiles -}}
|
||||
{{- end -}}
|
||||
{{- $destinations = append $destinations $entry -}}
|
||||
{{- end -}}
|
||||
apiVersion: v1
|
||||
kind: ConfigMap
|
||||
metadata:
|
||||
name: hub-audit
|
||||
namespace: {{ .Release.Namespace }}
|
||||
data:
|
||||
destinations.json: |
|
||||
{{ dict "version" 1 "destinations" $destinations | toPrettyJson | nindent 4 }}
|
||||
{{- end }}
|
||||
@@ -4,7 +4,7 @@ metadata:
|
||||
name: mongodb-config
|
||||
namespace: {{ .Release.Namespace }}
|
||||
data:
|
||||
MONGODB_URI: "{{ .Values.mongodb.uri }}"
|
||||
MONGODB_URI: {{ include "hub.mongodb.uri" . | quote }}
|
||||
MONGODB_HOST: "{{ .Values.mongodb.host }}"
|
||||
MONGODB_AUTHENTICATION_MECHANISM: "{{ .Values.mongodb.authenticationMechanism }}"
|
||||
MONGODB_DATABASE_CREDENTIALS: "{{ .Values.mongodb.adminDatabase }}"
|
||||
@@ -12,4 +12,7 @@ data:
|
||||
MONGODB_PASSWORD: "{{ .Values.mongodb.password }}"
|
||||
MONGODB_RETRY_WRITES: "{{ .Values.mongodb.retryWrites }}"
|
||||
MONGODB_FLAVOR: "{{ .Values.mongodb.flavor | default "mongodb" }}"
|
||||
MONGODB_TLS: "{{ .Values.mongodb.tls.enabled }}"
|
||||
MONGODB_TLS_CA_FILE: {{ include "hub.mongodb.tlsCAFile" . | quote }}
|
||||
MONGODB_TLS_INSECURE_SKIP_VERIFY: "{{ .Values.mongodb.tls.insecureSkipVerify }}"
|
||||
MONGODB_DATABASE_CLOUD: "Kerberos"
|
||||
|
||||
@@ -120,6 +120,7 @@ spec:
|
||||
metadata:
|
||||
annotations:
|
||||
checksum/config-mongodb: {{ include (print $.Template.BasePath "/configmap-mongodb.yaml") . | sha256sum }}
|
||||
checksum/classification-catalog: {{ include (print $.Template.BasePath "/configmap-classification-catalog.yaml") . | sha256sum }}
|
||||
labels:
|
||||
app: hub-api
|
||||
spec:
|
||||
@@ -131,8 +132,11 @@ spec:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- $serverTLS := .Values.kerberoshub.api.serverTLS }}
|
||||
{{- if or .Values.kerberoshub.api.volumes (and $serverTLS.enabled $serverTLS.secretName) }}
|
||||
{{- $mongodbTLS := .Values.mongodb.tls }}
|
||||
volumes:
|
||||
- name: classification-catalog
|
||||
configMap:
|
||||
name: classification-catalog
|
||||
{{- with .Values.kerberoshub.api.volumes }}
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
@@ -141,6 +145,8 @@ spec:
|
||||
secret:
|
||||
secretName: {{ $serverTLS.secretName }}
|
||||
{{- end }}
|
||||
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
|
||||
{{- include "hub.mongodb.tlsVolume" . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- with .Values.kerberoshub.api.topologySpreadConstraints }}
|
||||
topologySpreadConstraints:
|
||||
@@ -157,8 +163,10 @@ spec:
|
||||
ports:
|
||||
- containerPort: 80
|
||||
name: http
|
||||
{{- if or .Values.kerberoshub.api.volumeMounts (and $serverTLS.enabled $serverTLS.secretName) }}
|
||||
volumeMounts:
|
||||
- name: classification-catalog
|
||||
mountPath: /etc/kerberos/classifications
|
||||
readOnly: true
|
||||
{{- with .Values.kerberoshub.api.volumeMounts}}
|
||||
{{- toYaml . | nindent 12 }}
|
||||
{{- end }}
|
||||
@@ -167,12 +175,16 @@ spec:
|
||||
mountPath: {{ $serverTLS.mountPath }}
|
||||
readOnly: true
|
||||
{{- end }}
|
||||
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
|
||||
{{- include "hub.mongodb.tlsVolumeMount" . | nindent 12 }}
|
||||
{{- end }}
|
||||
# Mongodb - loaded from ConfigMap
|
||||
envFrom:
|
||||
- configMapRef:
|
||||
name: mongodb-config
|
||||
env:
|
||||
- name: CLASSIFICATION_CATALOG_FILE
|
||||
value: /etc/kerberos/classifications/classifications.json
|
||||
- name: ENVIRONMENT
|
||||
value: "{{ .Values.environment }}"
|
||||
- name: READ_ONLY
|
||||
@@ -187,6 +199,23 @@ spec:
|
||||
value: "{{ .Values.kerberoshub.api.schema }}://{{ .Values.kerberoshub.api.url }}"
|
||||
- name: PUBLIC_URL
|
||||
value: "{{ .Values.kerberoshub.frontend.schema }}://{{ .Values.kerberoshub.frontend.url }}"
|
||||
- name: REFRESH_COOKIE_SECURE
|
||||
value: {{ eq .Values.kerberoshub.api.schema "https" | quote }}
|
||||
{{- $corsOrigins := list (printf "%s://%s" .Values.kerberoshub.frontend.schema .Values.kerberoshub.frontend.url) }}
|
||||
{{- with .Values.kerberoshub.frontend.legacyUrl }}
|
||||
{{- $corsOrigins = append $corsOrigins (printf "%s://%s" $.Values.kerberoshub.frontend.schema .) }}
|
||||
{{- end }}
|
||||
{{- range .Values.kerberoshub.frontend.domains }}
|
||||
{{- $corsOrigins = append $corsOrigins (printf "%s://%s" $.Values.kerberoshub.frontend.schema .) }}
|
||||
{{- end }}
|
||||
{{- if and .Values.kerberoshub.frontend.multiTenant .Values.kerberoshub.frontend.tenantBaseDomain }}
|
||||
{{- $corsOrigins = append $corsOrigins (printf "%s://*.%s" .Values.kerberoshub.frontend.schema .Values.kerberoshub.frontend.tenantBaseDomain) }}
|
||||
{{- end }}
|
||||
{{- if and .Values.kerberoshub.frontend.demoEnabled .Values.kerberoshub.frontend.demoUrl }}
|
||||
{{- $corsOrigins = append $corsOrigins (printf "%s://%s" .Values.kerberoshub.frontend.schema .Values.kerberoshub.frontend.demoUrl) }}
|
||||
{{- end }}
|
||||
- name: CORS_ALLOWED_ORIGINS
|
||||
value: {{ join "," $corsOrigins | quote }}
|
||||
{{ if .Values.isPrivate }}
|
||||
- name: KERBEROS_PRIVATE_CLOUD
|
||||
value: "true"
|
||||
|
||||
@@ -0,0 +1,18 @@
|
||||
{{- if and (or (eq .Values.mode "all") (eq .Values.mode "ui")) .Values.kerberoshub.audit.enabled .Values.kerberoshub.audit.serviceMonitor.enabled -}}
|
||||
apiVersion: monitoring.coreos.com/v1
|
||||
kind: ServiceMonitor
|
||||
metadata:
|
||||
name: hub-audit-servicemonitor
|
||||
namespace: {{ .Release.Namespace }}
|
||||
labels:
|
||||
service: hub-audit
|
||||
release: prometheus
|
||||
spec:
|
||||
selector:
|
||||
matchLabels:
|
||||
service: hub-audit
|
||||
endpoints:
|
||||
- port: metrics
|
||||
interval: {{ .Values.kerberoshub.audit.serviceMonitor.interval }}
|
||||
path: /metrics
|
||||
{{- end }}
|
||||
145
charts/hub/templates/kerberos-hub/hub-audit.yaml
Normal file
145
charts/hub/templates/kerberos-hub/hub-audit.yaml
Normal file
@@ -0,0 +1,145 @@
|
||||
{{- if and (or (eq .Values.mode "all") (eq .Values.mode "ui")) .Values.kerberoshub.audit.enabled -}}
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: hub-audit
|
||||
namespace: {{ .Release.Namespace }}
|
||||
spec:
|
||||
replicas: {{ .Values.kerberoshub.audit.replicas }}
|
||||
selector:
|
||||
matchLabels:
|
||||
app: hub-audit
|
||||
minReadySeconds: 10
|
||||
strategy:
|
||||
type: RollingUpdate
|
||||
rollingUpdate:
|
||||
maxUnavailable: 1
|
||||
maxSurge: 1
|
||||
template:
|
||||
metadata:
|
||||
annotations:
|
||||
checksum/config-mongodb: {{ include (print $.Template.BasePath "/configmap-mongodb.yaml") . | sha256sum }}
|
||||
labels:
|
||||
app: hub-audit
|
||||
spec:
|
||||
terminationGracePeriodSeconds: {{ .Values.kerberoshub.audit.terminationGracePeriodSeconds }}
|
||||
{{- if .Values.kerberoshub.serviceAccount.create }}
|
||||
serviceAccountName: {{ default (printf "%s-%s-sa" .Release.Name .Chart.Name | trunc 63 | trimSuffix "-") .Values.kerberoshub.serviceAccount.name }}
|
||||
{{- end }}
|
||||
{{- with .Values.imagePullSecrets }}
|
||||
imagePullSecrets:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- $mongodbTLS := .Values.mongodb.tls }}
|
||||
volumes:
|
||||
- name: destinations
|
||||
configMap:
|
||||
name: hub-audit
|
||||
{{- range $index, $destination := .Values.kerberoshub.audit.destinations }}
|
||||
{{- $bearer := default dict $destination.bearerTokenSecret }}
|
||||
{{- $secretHeaders := default dict $destination.secretHeaders }}
|
||||
{{- if or (gt (len $bearer) 0) (gt (len $secretHeaders) 0) }}
|
||||
- name: audit-dest-{{ sha256sum $destination.id | trunc 12 }}
|
||||
projected:
|
||||
sources:
|
||||
{{- if gt (len $bearer) 0 }}
|
||||
- secret:
|
||||
name: {{ required (printf "bearerTokenSecret.name is required for destination %s" $destination.id) $bearer.name | quote }}
|
||||
items:
|
||||
- key: {{ default "token" $bearer.key | quote }}
|
||||
path: bearer-{{ sha256sum (printf "%s:%s" $bearer.name (default "token" $bearer.key)) | trunc 12 }}
|
||||
{{- end }}
|
||||
{{- range $headerName, $secret := $secretHeaders }}
|
||||
- secret:
|
||||
name: {{ required (printf "secretName is required for destination %s header %s" $destination.id $headerName) $secret.secretName | quote }}
|
||||
items:
|
||||
- key: {{ required (printf "secretKey is required for destination %s header %s" $destination.id $headerName) $secret.secretKey | quote }}
|
||||
path: header-{{ sha256sum (printf "%s:%s:%s" $headerName $secret.secretName $secret.secretKey) | trunc 12 }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- with .Values.kerberoshub.audit.volumes }}
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
|
||||
{{- include "hub.mongodb.tlsVolume" . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- with .Values.kerberoshub.audit.topologySpreadConstraints }}
|
||||
topologySpreadConstraints:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
containers:
|
||||
- name: hub-audit
|
||||
image: "{{ .Values.global.imageRegistry }}{{ .Values.kerberoshub.audit.repository }}:{{ .Values.kerberoshub.audit.tag }}"
|
||||
imagePullPolicy: {{ .Values.kerberoshub.audit.pullPolicy }}
|
||||
{{- with .Values.kerberoshub.audit.resources }}
|
||||
resources:
|
||||
{{- toYaml . | nindent 12 }}
|
||||
{{- end }}
|
||||
ports:
|
||||
- name: metrics
|
||||
containerPort: 2112
|
||||
protocol: TCP
|
||||
readinessProbe:
|
||||
httpGet:
|
||||
path: /healthz
|
||||
port: metrics
|
||||
livenessProbe:
|
||||
httpGet:
|
||||
path: /healthz
|
||||
port: metrics
|
||||
volumeMounts:
|
||||
- name: destinations
|
||||
mountPath: /etc/hub-audit
|
||||
readOnly: true
|
||||
{{- range $index, $destination := .Values.kerberoshub.audit.destinations }}
|
||||
{{- $bearer := default dict $destination.bearerTokenSecret }}
|
||||
{{- $secretHeaders := default dict $destination.secretHeaders }}
|
||||
{{- if or (gt (len $bearer) 0) (gt (len $secretHeaders) 0) }}
|
||||
- name: audit-dest-{{ sha256sum $destination.id | trunc 12 }}
|
||||
mountPath: /var/run/secrets/audit-destinations/{{ $destination.id }}
|
||||
readOnly: true
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- with .Values.kerberoshub.audit.volumeMounts }}
|
||||
{{- toYaml . | nindent 12 }}
|
||||
{{- end }}
|
||||
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
|
||||
{{- include "hub.mongodb.tlsVolumeMount" . | nindent 12 }}
|
||||
{{- end }}
|
||||
envFrom:
|
||||
- configMapRef:
|
||||
name: mongodb-config
|
||||
env:
|
||||
- name: DISPATCH_INTERVAL
|
||||
value: {{ .Values.kerberoshub.audit.dispatchInterval | quote }}
|
||||
- name: LEASE_DURATION
|
||||
value: {{ .Values.kerberoshub.audit.leaseDuration | quote }}
|
||||
- name: POD_NAME
|
||||
valueFrom:
|
||||
fieldRef:
|
||||
fieldPath: metadata.name
|
||||
{{- with .Values.kerberoshub.audit.extraEnv }}
|
||||
{{- toYaml . | nindent 12 }}
|
||||
{{- end }}
|
||||
{{- with .Values.kerberoshub.extraEnv }}
|
||||
{{- toYaml . | nindent 12 }}
|
||||
{{- end }}
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: hub-audit
|
||||
namespace: {{ .Release.Namespace }}
|
||||
labels:
|
||||
app: hub-audit
|
||||
service: hub-audit
|
||||
spec:
|
||||
ports:
|
||||
- name: metrics
|
||||
port: 2112
|
||||
targetPort: metrics
|
||||
protocol: TCP
|
||||
selector:
|
||||
app: hub-audit
|
||||
{{- end }}
|
||||
@@ -29,10 +29,16 @@ spec:
|
||||
imagePullSecrets:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- with .Values.kerberoshub.cleanup.volumes }}
|
||||
{{- $mongodbTLS := .Values.mongodb.tls }}
|
||||
{{- if or .Values.kerberoshub.cleanup.volumes (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
|
||||
volumes:
|
||||
{{- with .Values.kerberoshub.cleanup.volumes }}
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
|
||||
{{- include "hub.mongodb.tlsVolume" . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- with .Values.kerberoshub.cleanup.topologySpreadConstraints }}
|
||||
topologySpreadConstraints:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
@@ -45,10 +51,15 @@ spec:
|
||||
resources:
|
||||
{{- toYaml . | nindent 12 }}
|
||||
{{- end }}
|
||||
{{- with .Values.kerberoshub.cleanup.volumeMounts }}
|
||||
{{- if or .Values.kerberoshub.cleanup.volumeMounts (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
|
||||
volumeMounts:
|
||||
{{- with .Values.kerberoshub.cleanup.volumeMounts }}
|
||||
{{- toYaml . | nindent 12 }}
|
||||
{{- end }}
|
||||
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
|
||||
{{- include "hub.mongodb.tlsVolumeMount" . | nindent 12 }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
envFrom:
|
||||
- configMapRef:
|
||||
name: mongodb-config
|
||||
@@ -97,6 +108,8 @@ spec:
|
||||
value: "{{ .Values.kerberoshub.cleanup.globalPassDeleteBudget }}"
|
||||
- name: DEFAULT_TASK_RETENTION_DAYS
|
||||
value: "{{ .Values.kerberoshub.cleanup.defaultTaskRetentionDays }}"
|
||||
- name: AUDIT_EVENT_RETENTION_DAYS
|
||||
value: "{{ .Values.kerberoshub.cleanup.auditEventRetentionDays }}"
|
||||
{{- if .Values.kerberoshub.extraEnv }}
|
||||
{{- toYaml .Values.kerberoshub.extraEnv | nindent 12 }}
|
||||
{{- end }}
|
||||
|
||||
@@ -193,6 +193,10 @@ spec:
|
||||
- name: GOOGLEMAPS_KEY
|
||||
value: "{{ .Values.kerberoshub.frontend.googlemaps.apikey }}"
|
||||
|
||||
# features > chart
|
||||
- name: CHART_COLORS
|
||||
value: {{ .Values.kerberoshub.frontend.features.chart.colors | toJson | quote }}
|
||||
|
||||
# Zendesk for support
|
||||
- name: ZENDESK_URL
|
||||
value: "{{ .Values.kerberoshub.frontend.zendesk.url }}"
|
||||
@@ -229,6 +233,28 @@ spec:
|
||||
value: "{{ .Values.kerberoshub.frontend.features.case.enabled }}"
|
||||
- name: FEATURE_WORKFLOWS_ENABLED
|
||||
value: "{{ .Values.kerberoshub.frontend.features.workflows.enabled }}"
|
||||
- name: FEATURE_AUDIT_ENABLED
|
||||
value: "{{ .Values.kerberoshub.frontend.features.audit.enabled }}"
|
||||
- name: FEATURE_DEVICE_ANALYTICS_ENABLED
|
||||
value: "{{ .Values.kerberoshub.frontend.features.devices.analyticsEnabled }}"
|
||||
- name: FEATURE_DASHBOARD_SITES_FULLSCREEN_ENABLED
|
||||
value: "{{ .Values.kerberoshub.frontend.features.dashboard.sitesFullscreenEnabled }}"
|
||||
- name: FEATURE_ORGANISATIONS_ENABLED
|
||||
value: "{{ .Values.kerberoshub.frontend.features.organisations.enabled }}"
|
||||
- name: FEATURE_ORGANISATION_SWITCHER_ENABLED
|
||||
value: "{{ .Values.kerberoshub.frontend.features.organisations.switcherEnabled }}"
|
||||
- name: FEATURE_ORGANISATION_CREATION_ENABLED
|
||||
value: "{{ .Values.kerberoshub.frontend.features.organisations.creationEnabled }}"
|
||||
- name: FEATURE_ORGANISATION_SETTINGS_ENABLED
|
||||
value: "{{ .Values.kerberoshub.frontend.features.organisations.settingsEnabled }}"
|
||||
- name: FEATURE_PROJECTS_ENABLED
|
||||
value: "{{ .Values.kerberoshub.frontend.features.projects.enabled }}"
|
||||
- name: FEATURE_PROJECT_SWITCHER_ENABLED
|
||||
value: "{{ .Values.kerberoshub.frontend.features.projects.switcherEnabled }}"
|
||||
- name: FEATURE_PROJECT_CREATION_ENABLED
|
||||
value: "{{ .Values.kerberoshub.frontend.features.projects.creationEnabled }}"
|
||||
- name: FEATURE_PROJECT_SETTINGS_ENABLED
|
||||
value: "{{ .Values.kerberoshub.frontend.features.projects.settingsEnabled }}"
|
||||
- name: FEATURE_DARK_MODE
|
||||
value: "{{ .Values.kerberoshub.frontend.features.darkMode }}"
|
||||
- name: FEATURE_SPLASH_SCREEN_ENABLED
|
||||
@@ -249,6 +275,8 @@ spec:
|
||||
value: "{{ .Values.kerberoshub.frontend.features.liveview.hlsEnabled }}"
|
||||
- name: FEATURE_MOQ_ENABLED
|
||||
value: "{{ .Values.kerberoshub.frontend.features.liveview.moqEnabled }}"
|
||||
- name: FEATURE_REMOTE_RECORDING_ENABLED
|
||||
value: "{{ .Values.kerberoshub.frontend.features.liveview.remoteRecordingEnabled }}"
|
||||
- name: MOQ_RELAY_URL
|
||||
value: "{{ .Values.kerberoshub.frontend.features.liveview.moqRelayUrl }}"
|
||||
- name: MOQ_BROADCAST_PREFIX
|
||||
@@ -267,6 +295,26 @@ spec:
|
||||
# features > floorplan
|
||||
- name: FEATURE_FLOORPLAN_ENABLED
|
||||
value: "{{ .Values.kerberoshub.frontend.features.floorplan.enabled }}"
|
||||
# features > map
|
||||
- name: MAP_TILE_URL_LIGHT
|
||||
value: "{{ .Values.kerberoshub.frontend.features.map.tileUrlLight }}"
|
||||
- name: MAP_TILE_URL_DARK
|
||||
value: "{{ .Values.kerberoshub.frontend.features.map.tileUrlDark }}"
|
||||
- name: MAP_ATTRIBUTION
|
||||
value: "{{ .Values.kerberoshub.frontend.features.map.attribution }}"
|
||||
- name: MAP_OVERLAY_TILE_URL
|
||||
value: "{{ .Values.kerberoshub.frontend.features.map.overlayTileUrl }}"
|
||||
- name: MAP_OVERLAY_API_KEY
|
||||
value: "{{ .Values.kerberoshub.frontend.features.map.overlayApiKey }}"
|
||||
- name: MAP_OVERLAY_ATTRIBUTION
|
||||
value: "{{ .Values.kerberoshub.frontend.features.map.overlayAttribution }}"
|
||||
- name: MAP_OVERLAY_MIN_ZOOM
|
||||
value: "{{ .Values.kerberoshub.frontend.features.map.overlayMinZoom }}"
|
||||
- name: MAP_OVERLAY_MAX_ZOOM
|
||||
value: "{{ .Values.kerberoshub.frontend.features.map.overlayMaxZoom }}"
|
||||
- name: MAP_OVERLAY_OPACITY
|
||||
value: "{{ .Values.kerberoshub.frontend.features.map.overlayOpacity }}"
|
||||
|
||||
- name: COLOR_TRACK_BOX
|
||||
value: "{{ .Values.kerberoshub.frontend.features.floorplan.colorTrackBox }}"
|
||||
- name: COLOR_TRACK_BOX_HOVER
|
||||
@@ -300,7 +348,9 @@ spec:
|
||||
|
||||
# features > face redaction
|
||||
- name: FEATURE_FACE_REDACTION_ENABLED
|
||||
value: "{{ .Values.kerberoshub.frontend.features.faceRedaction.enabled }}"
|
||||
value: "{{ .Values.kerberoshub.frontend.features.faceRedaction.enabled }}"
|
||||
- name: FEATURE_FACE_REDACTION_CLASSIFIER_TRACKS_ENABLED
|
||||
value: "{{ .Values.kerberoshub.frontend.features.faceRedaction.classifierTracksEnabled }}"
|
||||
|
||||
# features > media
|
||||
- name: FEATURE_MEDIA_FILTER_DATE_ENABLED
|
||||
@@ -323,6 +373,8 @@ spec:
|
||||
value: "{{ .Values.kerberoshub.frontend.features.media.filter.category.enabled }}"
|
||||
- name: FEATURE_MEDIA_FILTER_MARKERS_ENABLED
|
||||
value: "{{ .Values.kerberoshub.frontend.features.media.filter.markers.enabled }}"
|
||||
- name: FEATURE_MEDIA_FILTER_MARKER_OPTIONS_BY_DATE_ENABLED
|
||||
value: "{{ .Values.kerberoshub.frontend.features.media.filter.markerOptionsByDate.enabled }}"
|
||||
- name: FEATURE_MEDIA_FILTER_EVENTS_ENABLED
|
||||
value: "{{ .Values.kerberoshub.frontend.features.media.filter.events.enabled }}"
|
||||
- name: FEATURE_MEDIA_FILTER_TAGS_ENABLED
|
||||
|
||||
@@ -312,10 +312,28 @@ spec:
|
||||
value: "{{ .Values.kerberoshub.frontend.features.case.enabled }}"
|
||||
- name: FEATURE_WORKFLOWS_ENABLED
|
||||
value: "{{ .Values.kerberoshub.frontend.features.workflows.enabled }}"
|
||||
- name: FEATURE_AUDIT_ENABLED
|
||||
value: "{{ .Values.kerberoshub.frontend.features.audit.enabled }}"
|
||||
- name: FEATURE_DEVICE_ANALYTICS_ENABLED
|
||||
value: "{{ .Values.kerberoshub.frontend.features.devices.analyticsEnabled }}"
|
||||
- name: FEATURE_DASHBOARD_SITES_FULLSCREEN_ENABLED
|
||||
value: "{{ .Values.kerberoshub.frontend.features.dashboard.sitesFullscreenEnabled }}"
|
||||
- name: FEATURE_ORGANISATIONS_ENABLED
|
||||
value: "{{ .Values.kerberoshub.frontend.features.organisations.enabled }}"
|
||||
- name: FEATURE_ORGANISATION_SWITCHER_ENABLED
|
||||
value: "{{ .Values.kerberoshub.frontend.features.organisations.switcherEnabled }}"
|
||||
- name: FEATURE_ORGANISATION_CREATION_ENABLED
|
||||
value: "{{ .Values.kerberoshub.frontend.features.organisations.creationEnabled }}"
|
||||
- name: FEATURE_ORGANISATION_SETTINGS_ENABLED
|
||||
value: "{{ .Values.kerberoshub.frontend.features.organisations.settingsEnabled }}"
|
||||
- name: FEATURE_PROJECTS_ENABLED
|
||||
value: "{{ .Values.kerberoshub.frontend.features.projects.enabled }}"
|
||||
- name: FEATURE_PROJECT_SWITCHER_ENABLED
|
||||
value: "{{ .Values.kerberoshub.frontend.features.projects.switcherEnabled }}"
|
||||
- name: FEATURE_PROJECT_CREATION_ENABLED
|
||||
value: "{{ .Values.kerberoshub.frontend.features.projects.creationEnabled }}"
|
||||
- name: FEATURE_PROJECT_SETTINGS_ENABLED
|
||||
value: "{{ .Values.kerberoshub.frontend.features.projects.settingsEnabled }}"
|
||||
- name: FEATURE_DARK_MODE
|
||||
value: "{{ .Values.kerberoshub.frontend.features.darkModeEnabled }}"
|
||||
- name: FEATURE_SPLASH_SCREEN_ENABLED
|
||||
@@ -338,6 +356,8 @@ spec:
|
||||
value: "{{ .Values.kerberoshub.frontend.features.liveview.hlsEnabled }}"
|
||||
- name: FEATURE_MOQ_ENABLED
|
||||
value: "{{ .Values.kerberoshub.frontend.features.liveview.moqEnabled }}"
|
||||
- name: FEATURE_REMOTE_RECORDING_ENABLED
|
||||
value: "{{ .Values.kerberoshub.frontend.features.liveview.remoteRecordingEnabled }}"
|
||||
- name: MOQ_RELAY_URL
|
||||
value: "{{ .Values.kerberoshub.frontend.features.liveview.moqRelayUrl }}"
|
||||
- name: MOQ_BROADCAST_PREFIX
|
||||
@@ -364,6 +384,18 @@ spec:
|
||||
value: "{{ .Values.kerberoshub.frontend.features.map.tileUrlDark }}"
|
||||
- name: MAP_ATTRIBUTION
|
||||
value: "{{ .Values.kerberoshub.frontend.features.map.attribution }}"
|
||||
- name: MAP_OVERLAY_TILE_URL
|
||||
value: "{{ .Values.kerberoshub.frontend.features.map.overlayTileUrl }}"
|
||||
- name: MAP_OVERLAY_API_KEY
|
||||
value: "{{ .Values.kerberoshub.frontend.features.map.overlayApiKey }}"
|
||||
- name: MAP_OVERLAY_ATTRIBUTION
|
||||
value: "{{ .Values.kerberoshub.frontend.features.map.overlayAttribution }}"
|
||||
- name: MAP_OVERLAY_MIN_ZOOM
|
||||
value: "{{ .Values.kerberoshub.frontend.features.map.overlayMinZoom }}"
|
||||
- name: MAP_OVERLAY_MAX_ZOOM
|
||||
value: "{{ .Values.kerberoshub.frontend.features.map.overlayMaxZoom }}"
|
||||
- name: MAP_OVERLAY_OPACITY
|
||||
value: "{{ .Values.kerberoshub.frontend.features.map.overlayOpacity }}"
|
||||
|
||||
- name: COLOR_TRACK_BOX
|
||||
value: "{{ .Values.kerberoshub.frontend.features.floorplan.colorTrackBox }}"
|
||||
@@ -393,6 +425,8 @@ spec:
|
||||
value: "{{ .Values.kerberoshub.frontend.colorDeviceMarkerBorder }}"
|
||||
|
||||
# features > chart
|
||||
- name: CHART_COLORS
|
||||
value: {{ .Values.kerberoshub.frontend.features.chart.colors | toJson | quote }}
|
||||
- name: COLOR_CHART_SELECTION_FILL
|
||||
value: "{{ .Values.kerberoshub.frontend.features.chart.colorChartSelectionFill }}"
|
||||
- name: COLOR_CHART_SELECTION_STROKE
|
||||
@@ -406,7 +440,9 @@ spec:
|
||||
|
||||
# features > face redaction
|
||||
- name: FEATURE_FACE_REDACTION_ENABLED
|
||||
value: "{{ .Values.kerberoshub.frontend.features.faceRedaction.enabled }}"
|
||||
value: "{{ .Values.kerberoshub.frontend.features.faceRedaction.enabled }}"
|
||||
- name: FEATURE_FACE_REDACTION_CLASSIFIER_TRACKS_ENABLED
|
||||
value: "{{ .Values.kerberoshub.frontend.features.faceRedaction.classifierTracksEnabled }}"
|
||||
|
||||
# features > media
|
||||
- name: FEATURE_MEDIA_FILTER_DATE_ENABLED
|
||||
@@ -429,6 +465,8 @@ spec:
|
||||
value: "{{ .Values.kerberoshub.frontend.features.media.filter.category.enabled }}"
|
||||
- name: FEATURE_MEDIA_FILTER_MARKERS_ENABLED
|
||||
value: "{{ .Values.kerberoshub.frontend.features.media.filter.markers.enabled }}"
|
||||
- name: FEATURE_MEDIA_FILTER_MARKER_OPTIONS_BY_DATE_ENABLED
|
||||
value: "{{ .Values.kerberoshub.frontend.features.media.filter.markerOptionsByDate.enabled }}"
|
||||
- name: FEATURE_MEDIA_FILTER_DEFAULT_VIEW
|
||||
value: "{{ .Values.kerberoshub.frontend.features.media.filter.defaultView }}"
|
||||
- name: FEATURE_MEDIA_FILTER_EVENTS_ENABLED
|
||||
|
||||
@@ -29,10 +29,16 @@ spec:
|
||||
imagePullSecrets:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- with .Values.kerberoshub.monitordevice.volumes }}
|
||||
{{- $mongodbTLS := .Values.mongodb.tls }}
|
||||
{{- if or .Values.kerberoshub.monitordevice.volumes (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
|
||||
volumes:
|
||||
{{- with .Values.kerberoshub.monitordevice.volumes }}
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
|
||||
{{- include "hub.mongodb.tlsVolume" . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- with .Values.kerberoshub.monitordevice.topologySpreadConstraints }}
|
||||
topologySpreadConstraints:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
@@ -45,10 +51,15 @@ spec:
|
||||
resources:
|
||||
{{- toYaml . | nindent 12 }}
|
||||
{{- end }}
|
||||
{{- with .Values.kerberoshub.monitordevice.volumeMounts}}
|
||||
{{- if or .Values.kerberoshub.monitordevice.volumeMounts (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
|
||||
volumeMounts:
|
||||
{{- with .Values.kerberoshub.monitordevice.volumeMounts}}
|
||||
{{- toYaml . | nindent 12 }}
|
||||
{{- end }}
|
||||
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
|
||||
{{- include "hub.mongodb.tlsVolumeMount" . | nindent 12 }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
envFrom:
|
||||
- configMapRef:
|
||||
name: mongodb-config
|
||||
|
||||
@@ -26,10 +26,16 @@ spec:
|
||||
imagePullSecrets:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- with .Values.kerberoshub.reactivate.volumes }}
|
||||
{{- $mongodbTLS := .Values.mongodb.tls }}
|
||||
{{- if or .Values.kerberoshub.reactivate.volumes (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
|
||||
volumes:
|
||||
{{- with .Values.kerberoshub.reactivate.volumes }}
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
|
||||
{{- include "hub.mongodb.tlsVolume" . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- with .Values.kerberoshub.reactivate.topologySpreadConstraints }}
|
||||
topologySpreadConstraints:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
@@ -38,10 +44,15 @@ spec:
|
||||
- name: hub-reactivate-subscription
|
||||
image: "{{ .Values.global.imageRegistry }}{{ .Values.kerberoshub.reactivate.repository }}:{{ .Values.kerberoshub.reactivate.tag }}"
|
||||
imagePullPolicy: {{ .Values.kerberoshub.reactivate.pullPolicy }}
|
||||
{{- with .Values.kerberoshub.reactivate.volumeMounts }}
|
||||
{{- if or .Values.kerberoshub.reactivate.volumeMounts (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
|
||||
volumeMounts:
|
||||
{{- with .Values.kerberoshub.reactivate.volumeMounts }}
|
||||
{{- toYaml . | nindent 12 }}
|
||||
{{- end }}
|
||||
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
|
||||
{{- include "hub.mongodb.tlsVolumeMount" . | nindent 12 }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
envFrom:
|
||||
- configMapRef:
|
||||
name: mongodb-config
|
||||
|
||||
@@ -1,15 +1,17 @@
|
||||
{{/*
|
||||
Assemble the deployment-global workflow definitions (WORKFLOW_DEFINITIONS) as a
|
||||
JSON array from every *enabled* workflow under kerberoshub.workflows.definitions.
|
||||
This is the engine's single routing source: several distinct workflows can run
|
||||
over one recording — each opens its own run and dispatches only its own stages.
|
||||
This is the engine's boot-loaded configuration source and deployment stage
|
||||
catalog: several distinct config workflows can run over one recording — each
|
||||
opens its own run and dispatches only its own stages. Organisation-scoped
|
||||
database workflows are discovered separately at runtime.
|
||||
|
||||
Each enabled definition contributes one workflow object:
|
||||
name the map key (the workflow's human-readable name; also its identity —
|
||||
the engine derives a stable id from it when the definition carries
|
||||
no explicit id).
|
||||
enabled always true here (a disabled definition is skipped entirely).
|
||||
source "config" — provenance marking a Helm-seeded, deployment-global,
|
||||
source "config" — provenance marking a Helm-defined, deployment-global,
|
||||
ops-managed workflow (read-only in the API, no owning organisation).
|
||||
triggers how a run OPENS. Defaults to a single bare automatic trigger
|
||||
(opens for every recording); narrow with device/schedule triggers.
|
||||
|
||||
@@ -29,10 +29,16 @@ spec:
|
||||
imagePullSecrets:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- with .Values.kerberoshub.services.workflows.volumes }}
|
||||
{{- $mongodbTLS := .Values.mongodb.tls }}
|
||||
{{- if or .Values.kerberoshub.services.workflows.volumes (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
|
||||
volumes:
|
||||
{{- with .Values.kerberoshub.services.workflows.volumes }}
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
|
||||
{{- include "hub.mongodb.tlsVolume" . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- with .Values.kerberoshub.services.workflows.topologySpreadConstraints }}
|
||||
topologySpreadConstraints:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
@@ -45,10 +51,15 @@ spec:
|
||||
resources:
|
||||
{{- toYaml . | nindent 12 }}
|
||||
{{- end }}
|
||||
{{- with .Values.kerberoshub.services.workflows.volumeMounts }}
|
||||
{{- if or .Values.kerberoshub.services.workflows.volumeMounts (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
|
||||
volumeMounts:
|
||||
{{- with .Values.kerberoshub.services.workflows.volumeMounts }}
|
||||
{{- toYaml . | nindent 12 }}
|
||||
{{- end }}
|
||||
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
|
||||
{{- include "hub.mongodb.tlsVolumeMount" . | nindent 12 }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
envFrom:
|
||||
- configMapRef:
|
||||
name: mongodb-config
|
||||
@@ -62,8 +73,10 @@ spec:
|
||||
# named workflows it runs (WORKFLOW_DEFINITIONS): each with its own
|
||||
# trigger and executable stages, assembled from the enabled definitions
|
||||
# under kerberoshub.workflows.definitions (see _workflows-helpers.tpl).
|
||||
# Definitions are the engine's single routing source; empty means no
|
||||
# workflows run.
|
||||
# Definitions are the engine's boot-loaded config source and deployment
|
||||
# stage catalog. Organisation-scoped database workflows are read per
|
||||
# recording; an in-cluster engine still requires at least one config
|
||||
# definition so an empty catalog cannot silently drop traffic.
|
||||
- name: WORKFLOWS_QUEUE
|
||||
value: "{{ .Values.kerberoshub.services.workflows.queue }}"
|
||||
- name: WORKFLOW_DEFINITIONS
|
||||
|
||||
@@ -29,10 +29,16 @@ spec:
|
||||
imagePullSecrets:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- with .Values.kerberospipeline.analysis.volumes }}
|
||||
{{- $mongodbTLS := .Values.mongodb.tls }}
|
||||
{{- if or .Values.kerberospipeline.analysis.volumes (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
|
||||
volumes:
|
||||
{{- with .Values.kerberospipeline.analysis.volumes }}
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
|
||||
{{- include "hub.mongodb.tlsVolume" . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- with .Values.kerberospipeline.analysis.topologySpreadConstraints }}
|
||||
topologySpreadConstraints:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
@@ -45,10 +51,15 @@ spec:
|
||||
resources:
|
||||
{{- toYaml . | nindent 12 }}
|
||||
{{- end }}
|
||||
{{- with .Values.kerberospipeline.analysis.volumeMounts }}
|
||||
{{- if or .Values.kerberospipeline.analysis.volumeMounts (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
|
||||
volumeMounts:
|
||||
{{- with .Values.kerberospipeline.analysis.volumeMounts }}
|
||||
{{- toYaml . | nindent 12 }}
|
||||
{{- end }}
|
||||
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
|
||||
{{- include "hub.mongodb.tlsVolumeMount" . | nindent 12 }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
envFrom:
|
||||
- configMapRef:
|
||||
name: mongodb-config
|
||||
|
||||
@@ -29,10 +29,16 @@ spec:
|
||||
imagePullSecrets:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- with .Values.kerberospipeline.event.volumes }}
|
||||
{{- $mongodbTLS := .Values.mongodb.tls }}
|
||||
{{- if or .Values.kerberospipeline.event.volumes (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
|
||||
volumes:
|
||||
{{- with .Values.kerberospipeline.event.volumes }}
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
|
||||
{{- include "hub.mongodb.tlsVolume" . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- with .Values.kerberospipeline.event.topologySpreadConstraints }}
|
||||
topologySpreadConstraints:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
@@ -45,10 +51,15 @@ spec:
|
||||
resources:
|
||||
{{- toYaml . | nindent 12 }}
|
||||
{{- end }}
|
||||
{{- with .Values.kerberospipeline.event.volumeMounts }}
|
||||
{{- if or .Values.kerberospipeline.event.volumeMounts (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
|
||||
volumeMounts:
|
||||
{{- with .Values.kerberospipeline.event.volumeMounts }}
|
||||
{{- toYaml . | nindent 12 }}
|
||||
{{- end }}
|
||||
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
|
||||
{{- include "hub.mongodb.tlsVolumeMount" . | nindent 12 }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
ports:
|
||||
- containerPort: 8080
|
||||
envFrom:
|
||||
|
||||
@@ -29,10 +29,16 @@ spec:
|
||||
imagePullSecrets:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- with .Values.kerberospipeline.export.volumes }}
|
||||
{{- $mongodbTLS := .Values.mongodb.tls }}
|
||||
{{- if or .Values.kerberospipeline.export.volumes (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
|
||||
volumes:
|
||||
{{- with .Values.kerberospipeline.export.volumes }}
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
|
||||
{{- include "hub.mongodb.tlsVolume" . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- with .Values.kerberospipeline.export.topologySpreadConstraints }}
|
||||
topologySpreadConstraints:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
@@ -45,10 +51,15 @@ spec:
|
||||
resources:
|
||||
{{- toYaml . | nindent 12 }}
|
||||
{{- end }}
|
||||
{{- with .Values.kerberospipeline.export.volumeMounts }}
|
||||
{{- if or .Values.kerberospipeline.export.volumeMounts (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
|
||||
volumeMounts:
|
||||
{{- with .Values.kerberospipeline.export.volumeMounts }}
|
||||
{{- toYaml . | nindent 12 }}
|
||||
{{- end }}
|
||||
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
|
||||
{{- include "hub.mongodb.tlsVolumeMount" . | nindent 12 }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
envFrom:
|
||||
- configMapRef:
|
||||
name: mongodb-config
|
||||
|
||||
@@ -29,10 +29,16 @@ spec:
|
||||
imagePullSecrets:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- with .Values.kerberospipeline.monitor.volumes }}
|
||||
{{- $mongodbTLS := .Values.mongodb.tls }}
|
||||
{{- if or .Values.kerberospipeline.monitor.volumes (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
|
||||
volumes:
|
||||
{{- with .Values.kerberospipeline.monitor.volumes }}
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
|
||||
{{- include "hub.mongodb.tlsVolume" . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- with .Values.kerberospipeline.monitor.topologySpreadConstraints }}
|
||||
topologySpreadConstraints:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
@@ -45,14 +51,23 @@ spec:
|
||||
resources:
|
||||
{{- toYaml . | nindent 12 }}
|
||||
{{- end }}
|
||||
{{- with .Values.kerberospipeline.monitor.volumeMounts }}
|
||||
{{- if or .Values.kerberospipeline.monitor.volumeMounts (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
|
||||
volumeMounts:
|
||||
{{- with .Values.kerberospipeline.monitor.volumeMounts }}
|
||||
{{- toYaml . | nindent 12 }}
|
||||
{{- end }}
|
||||
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
|
||||
{{- include "hub.mongodb.tlsVolumeMount" . | nindent 12 }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
envFrom:
|
||||
- configMapRef:
|
||||
name: mongodb-config
|
||||
env:
|
||||
# Application
|
||||
- name: LOG_LEVEL
|
||||
value: "{{ .Values.kerberospipeline.monitor.logLevel }}"
|
||||
|
||||
# Queue
|
||||
- name: QUEUE_SYSTEM
|
||||
value: "{{ .Values.queueProvider }}"
|
||||
|
||||
@@ -29,10 +29,16 @@ spec:
|
||||
imagePullSecrets:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- with .Values.kerberospipeline.notifyTest.volumes }}
|
||||
{{- $mongodbTLS := .Values.mongodb.tls }}
|
||||
{{- if or .Values.kerberospipeline.notifyTest.volumes (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
|
||||
volumes:
|
||||
{{- with .Values.kerberospipeline.notifyTest.volumes }}
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
|
||||
{{- include "hub.mongodb.tlsVolume" . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- with .Values.kerberospipeline.notifyTest.topologySpreadConstraints }}
|
||||
topologySpreadConstraints:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
@@ -45,10 +51,15 @@ spec:
|
||||
resources:
|
||||
{{- toYaml . | nindent 12 }}
|
||||
{{- end }}
|
||||
{{- with .Values.kerberospipeline.notifyTest.volumeMounts}}
|
||||
{{- if or .Values.kerberospipeline.notifyTest.volumeMounts (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
|
||||
volumeMounts:
|
||||
{{- with .Values.kerberospipeline.notifyTest.volumeMounts}}
|
||||
{{- toYaml . | nindent 12 }}
|
||||
{{- end }}
|
||||
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
|
||||
{{- include "hub.mongodb.tlsVolumeMount" . | nindent 12 }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
envFrom:
|
||||
- configMapRef:
|
||||
name: mongodb-config
|
||||
|
||||
@@ -29,10 +29,16 @@ spec:
|
||||
imagePullSecrets:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- with .Values.kerberospipeline.notify.volumes }}
|
||||
{{- $mongodbTLS := .Values.mongodb.tls }}
|
||||
{{- if or .Values.kerberospipeline.notify.volumes (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
|
||||
volumes:
|
||||
{{- with .Values.kerberospipeline.notify.volumes }}
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
|
||||
{{- include "hub.mongodb.tlsVolume" . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- with .Values.kerberospipeline.notify.topologySpreadConstraints }}
|
||||
topologySpreadConstraints:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
@@ -45,16 +51,23 @@ spec:
|
||||
resources:
|
||||
{{- toYaml . | nindent 12 }}
|
||||
{{- end }}
|
||||
{{- with .Values.kerberospipeline.notify.volumeMounts}}
|
||||
{{- if or .Values.kerberospipeline.notify.volumeMounts (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
|
||||
volumeMounts:
|
||||
{{- with .Values.kerberospipeline.notify.volumeMounts}}
|
||||
{{- toYaml . | nindent 12 }}
|
||||
{{- end }}
|
||||
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
|
||||
{{- include "hub.mongodb.tlsVolumeMount" . | nindent 12 }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
envFrom:
|
||||
- configMapRef:
|
||||
name: mongodb-config
|
||||
env:
|
||||
- name: LOG_LEVEL
|
||||
value: "{{ .Values.kerberospipeline.notify.logLevel }}"
|
||||
- name: NOTIFICATION_EXPIRY_MINUTES
|
||||
value: "{{ .Values.kerberospipeline.notify.notificationExpiryMinutes }}"
|
||||
# Queue
|
||||
- name: QUEUE_SYSTEM
|
||||
value: "{{ .Values.queueProvider }}"
|
||||
|
||||
@@ -29,10 +29,16 @@ spec:
|
||||
imagePullSecrets:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- with .Values.kerberospipeline.sequence.volumes }}
|
||||
{{- $mongodbTLS := .Values.mongodb.tls }}
|
||||
{{- if or .Values.kerberospipeline.sequence.volumes (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
|
||||
volumes:
|
||||
{{- with .Values.kerberospipeline.sequence.volumes }}
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
|
||||
{{- include "hub.mongodb.tlsVolume" . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- with .Values.kerberospipeline.sequence.topologySpreadConstraints }}
|
||||
topologySpreadConstraints:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
@@ -45,10 +51,15 @@ spec:
|
||||
resources:
|
||||
{{- toYaml . | nindent 12 }}
|
||||
{{- end }}
|
||||
{{- with .Values.kerberospipeline.sequence.volumeMounts }}
|
||||
{{- if or .Values.kerberospipeline.sequence.volumeMounts (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
|
||||
volumeMounts:
|
||||
{{- with .Values.kerberospipeline.sequence.volumeMounts }}
|
||||
{{- toYaml . | nindent 12 }}
|
||||
{{- end }}
|
||||
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
|
||||
{{- include "hub.mongodb.tlsVolumeMount" . | nindent 12 }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
envFrom:
|
||||
- configMapRef:
|
||||
name: mongodb-config
|
||||
|
||||
@@ -29,10 +29,16 @@ spec:
|
||||
imagePullSecrets:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- with .Values.kerberospipeline.throttler.volumes }}
|
||||
{{- $mongodbTLS := .Values.mongodb.tls }}
|
||||
{{- if or .Values.kerberospipeline.throttler.volumes (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
|
||||
volumes:
|
||||
{{- with .Values.kerberospipeline.throttler.volumes }}
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
|
||||
{{- include "hub.mongodb.tlsVolume" . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- with .Values.kerberospipeline.throttler.topologySpreadConstraints }}
|
||||
topologySpreadConstraints:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
@@ -45,10 +51,15 @@ spec:
|
||||
resources:
|
||||
{{- toYaml . | nindent 12 }}
|
||||
{{- end }}
|
||||
{{- with .Values.kerberospipeline.throttler.volumeMounts }}
|
||||
{{- if or .Values.kerberospipeline.throttler.volumeMounts (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
|
||||
volumeMounts:
|
||||
{{- with .Values.kerberospipeline.throttler.volumeMounts }}
|
||||
{{- toYaml . | nindent 12 }}
|
||||
{{- end }}
|
||||
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
|
||||
{{- include "hub.mongodb.tlsVolumeMount" . | nindent 12 }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
envFrom:
|
||||
- configMapRef:
|
||||
name: mongodb-config
|
||||
|
||||
@@ -27,10 +27,16 @@ spec:
|
||||
imagePullSecrets:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- with .Values.kerberoshub.forwarder.volumes }}
|
||||
{{- $mongodbTLS := .Values.mongodb.tls }}
|
||||
{{- if or .Values.kerberoshub.forwarder.volumes (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
|
||||
volumes:
|
||||
{{- with .Values.kerberoshub.forwarder.volumes }}
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
|
||||
{{- include "hub.mongodb.tlsVolume" . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- with .Values.kerberoshub.forwarder.topologySpreadConstraints }}
|
||||
topologySpreadConstraints:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
@@ -43,10 +49,15 @@ spec:
|
||||
requests:
|
||||
memory: 10Mi
|
||||
cpu: 10m
|
||||
{{- with .Values.kerberoshub.forwarder.volumeMounts }}
|
||||
{{- if or .Values.kerberoshub.forwarder.volumeMounts (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
|
||||
volumeMounts:
|
||||
{{- with .Values.kerberoshub.forwarder.volumeMounts }}
|
||||
{{- toYaml . | nindent 12 }}
|
||||
{{- end }}
|
||||
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
|
||||
{{- include "hub.mongodb.tlsVolumeMount" . | nindent 12 }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
envFrom:
|
||||
- configMapRef:
|
||||
name: mongodb-config
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
{{- if eq .Values.mode "all" -}}
|
||||
{{- if and (eq .Values.mode "all") .Values.kerberoshub.proxy.enabled -}}
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
|
||||
@@ -60,6 +60,46 @@ mongodb:
|
||||
# and indexes, complex $lookup pipelines, etc.). When using DocumentDB you
|
||||
# should also set retryWrites: "false".
|
||||
flavor: "mongodb"
|
||||
# TLS for MongoDB-compatible backends. When uri is set, missing TLS query
|
||||
# parameters are appended automatically. AWS DocumentDB requires TLS and a
|
||||
# trusted RDS CA bundle, typically stored in an existing Kubernetes Secret.
|
||||
tls:
|
||||
enabled: false
|
||||
existingSecret: ""
|
||||
caFileName: ""
|
||||
mountPath: "/etc/mongodb/tls"
|
||||
insecureSkipVerify: false
|
||||
|
||||
# Classifications supported by Hub filters, alerts, markers, and other
|
||||
# downstream processing. Classifier output keys must match these values.
|
||||
classificationCatalog:
|
||||
- key: animal
|
||||
label: Animal
|
||||
icon: animal
|
||||
- key: pedestrian
|
||||
label: Pedestrian
|
||||
icon: pedestrian
|
||||
- key: cyclist
|
||||
label: Cyclist
|
||||
icon: cyclist
|
||||
- key: motorbike
|
||||
label: Motorbike
|
||||
icon: motorbike
|
||||
- key: lorry
|
||||
label: Lorry
|
||||
icon: lorry
|
||||
- key: car
|
||||
label: Car
|
||||
icon: car
|
||||
- key: handbag
|
||||
label: Handbag
|
||||
icon: handbag
|
||||
- key: suitcase
|
||||
label: Suitcase
|
||||
icon: suitcase
|
||||
- key: cell phone
|
||||
label: Cell phone
|
||||
icon: cell phone
|
||||
###################################################
|
||||
# MQTT configuration (bi-directional communication)
|
||||
###################################################
|
||||
@@ -231,7 +271,7 @@ kerberoshub:
|
||||
api:
|
||||
repository: ghcr.io/uug-ai/hub-api
|
||||
pullPolicy: IfNotPresent
|
||||
tag: "v1.9.29"
|
||||
tag: "v1.9.51"
|
||||
replicas: 2
|
||||
topologySpreadConstraints: [] # Optional pod topology spread constraints (empty = none).
|
||||
# Set to false to skip rendering the hub-api Service (e.g. when an
|
||||
@@ -344,7 +384,7 @@ kerberoshub:
|
||||
frontend:
|
||||
repository: ghcr.io/uug-ai/hub-frontend
|
||||
pullPolicy: IfNotPresent
|
||||
tag: "v1.9.32"
|
||||
tag: "v1.13.9"
|
||||
replicas: 2
|
||||
topologySpreadConstraints: [] # Optional pod topology spread constraints (empty = none).
|
||||
# Set to false to skip rendering the hub-frontend Service (e.g. when an
|
||||
@@ -468,21 +508,38 @@ kerberoshub:
|
||||
# Workflows allow you to define automated processes and actions in the front-end.
|
||||
workflows:
|
||||
enabled: "false" # Enable or disable workflows feature 'true' or 'false'
|
||||
# Audit events are visible to owner/admin users when enabled.
|
||||
audit:
|
||||
enabled: "true" # Enable or disable the Audit events page and navigation link 'true' or 'false'
|
||||
# Organisation controls remain visible as a read-only current organisation when switching is disabled.
|
||||
organisations:
|
||||
enabled: "" # Enable or disable the organisation feature family, including projects; when empty, child groups apply independently
|
||||
switcherEnabled: "false" # Enable or disable organisation switching 'true' or 'false'
|
||||
creationEnabled: "false" # Enable or disable organisation creation; requires switcherEnabled 'true' or 'false'
|
||||
settingsEnabled: "false" # Enable or disable the organisation settings link 'true' or 'false'
|
||||
projects:
|
||||
enabled: "" # Fallback project group switch used only when organisations.enabled is empty
|
||||
switcherEnabled: "false" # Enable or disable the read-only project dropdown 'true' or 'false'
|
||||
creationEnabled: "false" # Reserved for project creation UI 'true' or 'false'
|
||||
settingsEnabled: "false" # Reserved for project settings UI 'true' or 'false'
|
||||
# Map tile configuration
|
||||
map:
|
||||
tileUrlLight: "https://{s}.basemaps.cartocdn.com/rastertiles/voyager/{z}/{x}/{y}{r}.png" # Map tile URL for light mode
|
||||
tileUrlDark: "https://{s}.basemaps.cartocdn.com/dark_all/{z}/{x}/{y}{r}.png" # Map tile URL for dark mode
|
||||
attribution: "© <a href='https://www.openstreetmap.org/copyright' target='_blank'>OpenStreetMap</a>" # Map attribution
|
||||
overlayTileUrl: "" # Optional XYZ overlay URL; supports {z}, {x}, {y}, and {apiKey}
|
||||
overlayApiKey: "" # Optional browser-visible API key substituted into overlayTileUrl
|
||||
overlayAttribution: "" # Attribution displayed when the overlay is enabled
|
||||
overlayMinZoom: "0" # Minimum overlay zoom level
|
||||
overlayMaxZoom: "19" # Maximum overlay zoom level
|
||||
overlayOpacity: "1" # Overlay opacity from 0 to 1
|
||||
# Live view page
|
||||
liveview:
|
||||
defaultStreamMode: "SD" # Default stream mode 'SD' or 'HD' (will be migrated to 'preview' or 'live')
|
||||
liveStreamMode: "webrtc" # Transport backing the LIVE (HD) mode: 'webrtc' (default), 'hls' or 'moq'
|
||||
hlsEnabled: "true" # Offer HLS as a selectable LIVE transport 'true' or 'false'. When 'false' the HLS option is removed from the front-end and streams use webrtc
|
||||
moqEnabled: "false" # Offer MoQ as a selectable LIVE transport 'true' or 'false'
|
||||
remoteRecordingEnabled: "true" # Show the manual REC control in live views
|
||||
moqRelayUrl: "https://relay.uug.ai/anon" # WebTransport URL of the MoQ relay
|
||||
moqBroadcastPrefix: "devices" # Prefix used to build devices/<deviceKey>/live.hang broadcast names
|
||||
paginationMode: "scroll" # Pagination mode in live view 'scroll', 'numbered' or 'maxStreams'
|
||||
@@ -491,6 +548,10 @@ kerberoshub:
|
||||
# Device page
|
||||
devices:
|
||||
hideAgent: "false" # Hide the 'add agent' button in the front-end
|
||||
analyticsEnabled: "true" # Enable or disable the Analytics tab on device detail pages 'true' or 'false'
|
||||
# Dashboard page
|
||||
dashboard:
|
||||
sitesFullscreenEnabled: "true" # Enable or disable the fullscreen Sites map 'true' or 'false'
|
||||
# Media page
|
||||
media:
|
||||
filter:
|
||||
@@ -514,6 +575,8 @@ kerberoshub:
|
||||
enabled: "true" # Enable or disable category filter in media 'true' or 'false'
|
||||
markers:
|
||||
enabled: "true" # Enable or disable markers filter in media 'true' or 'false'
|
||||
markerOptionsByDate:
|
||||
enabled: "false" # Limit marker-related filter options to the selected recording day
|
||||
events:
|
||||
enabled: "true" # Enable or disable events filter in media 'true' or 'false'
|
||||
tags:
|
||||
@@ -521,6 +584,13 @@ kerberoshub:
|
||||
defaultView: "timeline" # Default view for media page 'timeline' or 'grid'
|
||||
# Chart feature
|
||||
chart:
|
||||
colors:
|
||||
- "#84569f"
|
||||
- "#3ba7ff"
|
||||
- "#ff5c8a"
|
||||
- "#4ad991"
|
||||
- "#ffb84d"
|
||||
- "#ff7043"
|
||||
colorChartSelectionFill: "rgba(132, 86, 159, 0.07)"
|
||||
colorChartSelectionStroke: "rgba(132, 86, 159, 0.4)"
|
||||
colorChartGridStroke: "rgba(0, 106, 255, 0.18)"
|
||||
@@ -548,6 +618,7 @@ kerberoshub:
|
||||
# Face redaction feature
|
||||
faceRedaction:
|
||||
enabled: "false" # Enable or disable face redaction 'true' or 'false'
|
||||
classifierTracksEnabled: "true" # Make classifier-generated tracks available in the redaction modal
|
||||
# Optional integrations
|
||||
mixpanel: # We can keep track logging in Mixpanel as well
|
||||
apikey: "xxx"
|
||||
@@ -583,7 +654,7 @@ kerberoshub:
|
||||
cleanup:
|
||||
repository: ghcr.io/uug-ai/hub-cleanup
|
||||
pullPolicy: IfNotPresent
|
||||
tag: "v1.4.16"
|
||||
tag: "v1.4.19"
|
||||
replicas: 1 # Number of pods for the service.
|
||||
topologySpreadConstraints: [] # Optional pod topology spread constraints (empty = none).
|
||||
# Optional extra volumes / volumeMounts for this deployment (empty = none).
|
||||
@@ -619,10 +690,60 @@ kerberoshub:
|
||||
# Tasks with `legal_hold=true` are never deleted. Must match the value
|
||||
# used by `kerberoshub.api.defaultTaskRetentionDays`.
|
||||
defaultTaskRetentionDays: "0"
|
||||
# Deployment-wide retention for audit events. This is independent from
|
||||
# recording plans, inactive-account cleanup, and the optional global pass.
|
||||
# Set to "0" or a negative value to retain audit events indefinitely.
|
||||
auditEventRetentionDays: "400"
|
||||
resources:
|
||||
requests:
|
||||
memory: 10Mi
|
||||
cpu: 10m
|
||||
# Dispatches canonical audit_events to one or more external webhook sinks.
|
||||
# Credentials are always read from existing Secrets and never stored here.
|
||||
audit:
|
||||
enabled: false
|
||||
repository: ghcr.io/uug-ai/hub-audit
|
||||
pullPolicy: IfNotPresent
|
||||
tag: "v1.0.0"
|
||||
replicas: 1
|
||||
dispatchInterval: "5s"
|
||||
leaseDuration: "2m"
|
||||
terminationGracePeriodSeconds: 150 # Keep above leaseDuration so an in-flight cycle can finish.
|
||||
topologySpreadConstraints: []
|
||||
volumes: []
|
||||
volumeMounts: []
|
||||
extraEnv: []
|
||||
serviceMonitor:
|
||||
enabled: true
|
||||
interval: 15s
|
||||
destinations: []
|
||||
# - id: primary-siem
|
||||
# type: webhook
|
||||
# enabled: true
|
||||
# url: https://siem.example.com/api/audit
|
||||
# timeoutSeconds: 10
|
||||
# batchSize: 100
|
||||
# maxAttempts: 10
|
||||
# startAt: latest # latest | beginning, applied only on first creation
|
||||
# headers:
|
||||
# X-Source: kerberos-hub
|
||||
# bearerTokenSecret:
|
||||
# name: audit-primary-siem
|
||||
# key: token
|
||||
# secretHeaders:
|
||||
# X-Api-Key:
|
||||
# secretName: audit-primary-siem
|
||||
# secretKey: api-key
|
||||
# filters:
|
||||
# organisationIds: []
|
||||
# projectIds: []
|
||||
# actions: []
|
||||
# categories: []
|
||||
# outcomes: [] # success | failure
|
||||
# resources:
|
||||
# requests:
|
||||
# memory: 32Mi
|
||||
# cpu: 10m
|
||||
# hub-workflows is the standalone, queue-driven workflow engine. It consumes
|
||||
# pipeline events and dispatches the stages declared in its workflow
|
||||
# definitions, tracking each run in its own `workflow_runs` collection. It shares events
|
||||
@@ -642,16 +763,18 @@ kerberoshub:
|
||||
# -----------------------------------------------------------------------
|
||||
# Global workflow definitions — the named workflows the engine runs.
|
||||
#
|
||||
# `definitions` is the engine's single routing source: several distinct
|
||||
# workflows can run over one recording, each opening its own run and
|
||||
# dispatching only its own stages. It is a MAP keyed by workflow name (names
|
||||
# are unique and merge cleanly across -f / --set overrides). Ships empty; the
|
||||
# commented block is a worked example of an object-tracking + loitering
|
||||
# pipeline. Add more keys to run more workflows.
|
||||
# `definitions` is the engine's deployment-global configuration source and
|
||||
# stage catalog: several distinct workflows can run over one recording, each
|
||||
# opening its own run and dispatching only its own stages. Database-backed
|
||||
# organisation workflows, when present, are read separately per recording.
|
||||
# This is a MAP keyed by workflow name (names are unique and merge cleanly
|
||||
# across -f / --set overrides). Ships empty; the commented block is a worked
|
||||
# example of an object-tracking + loitering pipeline. Add more keys to run
|
||||
# more config workflows.
|
||||
#
|
||||
# Each definition:
|
||||
# enabled include this workflow (soft-delete toggle).
|
||||
# source always rendered as "config" (a Helm-seeded, ops-managed,
|
||||
# source always rendered as "config" (a Helm-defined, ops-managed,
|
||||
# deployment-global workflow — read-only in the API).
|
||||
# triggers how a run OPENS. Omit for a single bare automatic trigger
|
||||
# (opens for every recording); the per-stage `needs` then decide
|
||||
@@ -663,9 +786,9 @@ kerberoshub:
|
||||
# {operation?, condition?} — operation is the readiness GATE (the
|
||||
# upstream op whose data must be present before the condition is
|
||||
# read; omit for a check on the run root itself), condition is
|
||||
# {path, op, value} where path is ABSOLUTE from the run root and
|
||||
# resolves through string-keyed maps only (it cannot index into
|
||||
# arrays). needsMode combines multiple needs: "any" (default;
|
||||
# {path, op, value} where path is ABSOLUTE from the run root;
|
||||
# a `*` segment fans out across array elements. needsMode combines
|
||||
# multiple needs: "any" (default;
|
||||
# fire on the first match) or "all" (a join; fire once every need
|
||||
# has resolved and matched). The queue is taken from the matching
|
||||
# services.<operation> entry, so dispatch and consume cannot drift.
|
||||
@@ -674,19 +797,19 @@ kerberoshub:
|
||||
# kerberoshub.services.<operation> (deploy the objecttracking / loitering
|
||||
# workers below).
|
||||
definitions: {}
|
||||
#tracking-workflow:
|
||||
# enabled: true
|
||||
# triggers:
|
||||
# - type: automatic
|
||||
# stages:
|
||||
# - operation: objecttracking
|
||||
# dispatch: always
|
||||
# - operation: loitering
|
||||
# dispatch: conditional
|
||||
# # Fire loitering once objecttracking has resolved — a readiness join
|
||||
# # (no condition ⇒ gate on the upstream's presence, not a value).
|
||||
# needs:
|
||||
# - operation: objecttracking
|
||||
#tracking-workflow:
|
||||
# enabled: true
|
||||
# triggers:
|
||||
# - type: automatic
|
||||
# stages:
|
||||
# - operation: objecttracking
|
||||
# dispatch: always
|
||||
# - operation: loitering
|
||||
# dispatch: conditional
|
||||
# # Fire loitering once objecttracking has resolved — a readiness join
|
||||
# # (no condition ⇒ gate on the upstream's presence, not a value).
|
||||
# needs:
|
||||
# - operation: objecttracking
|
||||
# Workflow deployments. Every workflows-subsystem Deployment's image/tag/
|
||||
# replicas/resources/queue lives here in a single, uniform shape:
|
||||
# - `workflows` is the engine itself (the orchestrator). It is deployed
|
||||
@@ -699,9 +822,10 @@ kerberoshub:
|
||||
# when its own `enabled` is true AND the workflows engine is enabled.
|
||||
services:
|
||||
# hub-workflows — the workflows engine (orchestrator). Consumes the engine
|
||||
# queue, evaluates the workflow definitions (WORKFLOW_DEFINITIONS) and
|
||||
# dispatches to the stage workers below. Deployed when workflows.enabled is
|
||||
# true; it has no separate `enabled` here.
|
||||
# queue, evaluates the boot-loaded config workflows (WORKFLOW_DEFINITIONS)
|
||||
# plus organisation-scoped database workflows, and dispatches to the stage
|
||||
# workers below. Deployed when workflows.enabled is true; it has no separate
|
||||
# `enabled` here.
|
||||
workflows:
|
||||
repository: ghcr.io/uug-ai/hub-workflows
|
||||
pullPolicy: IfNotPresent
|
||||
@@ -723,61 +847,61 @@ kerberoshub:
|
||||
requests:
|
||||
memory: 10Mi
|
||||
cpu: 10m
|
||||
# ---------------------------------------------------------------------
|
||||
# EXAMPLE custom stage worker (commented out) — hub-loitering.
|
||||
#
|
||||
# Companion deployment for the workflows.definitions example above (the
|
||||
# loitering stage of tracking-workflow). Uncomment to deploy the demo
|
||||
# worker. It ships as its own repository/module.
|
||||
# See https://github.com/uug-ai/hub-loitering.
|
||||
#loitering:
|
||||
# # Deploy the hub-loitering worker.
|
||||
# enabled: true
|
||||
# repository: ghcr.io/uug-ai/hub-loitering
|
||||
# pullPolicy: IfNotPresent
|
||||
# tag: "v1.0.0"
|
||||
# replicas: 1 # Number of pods for the worker.
|
||||
# topologySpreadConstraints: [] # Optional pod topology spread constraints (empty = none).
|
||||
# #volumes:
|
||||
# # - name: extra
|
||||
# # emptyDir: {}
|
||||
# #volumeMounts:
|
||||
# # - name: extra
|
||||
# # mountPath: /data
|
||||
# logLevel: "info" # possible values: trace, debug, info, warn, error
|
||||
# # Queue this worker consumes dispatched messages from (LOITERING_QUEUE). This
|
||||
# # same value is taken into the matching workflows.definitions stage, so the
|
||||
# # engine dispatches and the worker consumes the same queue with no drift.
|
||||
# # Convention: "kcloud-<operation>-queue.fifo".
|
||||
# queue: "kcloud-loitering-queue.fifo"
|
||||
# resources:
|
||||
# requests:
|
||||
# memory: 10Mi
|
||||
# cpu: 10m
|
||||
# ---------------------------------------------------------------------
|
||||
# EXAMPLE stage worker (commented out) for the workflows.definitions example
|
||||
# above — hub-objecttracking. Uncomment the worker whose operation a
|
||||
# definition references, so the engine dispatches and the worker consumes the
|
||||
# same queue with no drift.
|
||||
#objecttracking:
|
||||
# # Deploy the object-tracking worker (operation "objecttracking").
|
||||
# enabled: true
|
||||
# repository: ghcr.io/uug-ai/hub-objecttracking
|
||||
# pullPolicy: IfNotPresent
|
||||
# tag: "v1.0.0"
|
||||
# replicas: 1 # Number of pods for the worker.
|
||||
# topologySpreadConstraints: [] # Optional pod topology spread constraints (empty = none).
|
||||
# logLevel: "info" # possible values: trace, debug, info, warn, error
|
||||
# # Queue this worker consumes dispatched messages from (OBJECTTRACKING_QUEUE).
|
||||
# queue: "kcloud-objecttracking-queue.fifo"
|
||||
# resources:
|
||||
# requests:
|
||||
# memory: 10Mi
|
||||
# cpu: 10m
|
||||
# ---------------------------------------------------------------------
|
||||
# EXAMPLE custom stage worker (commented out) — hub-loitering.
|
||||
#
|
||||
# Companion deployment for the workflows.definitions example above (the
|
||||
# loitering stage of tracking-workflow). Uncomment to deploy the demo
|
||||
# worker. It ships as its own repository/module.
|
||||
# See https://github.com/uug-ai/hub-loitering.
|
||||
#loitering:
|
||||
# # Deploy the hub-loitering worker.
|
||||
# enabled: true
|
||||
# repository: ghcr.io/uug-ai/hub-loitering
|
||||
# pullPolicy: IfNotPresent
|
||||
# tag: "v1.0.0"
|
||||
# replicas: 1 # Number of pods for the worker.
|
||||
# topologySpreadConstraints: [] # Optional pod topology spread constraints (empty = none).
|
||||
# #volumes:
|
||||
# # - name: extra
|
||||
# # emptyDir: {}
|
||||
# #volumeMounts:
|
||||
# # - name: extra
|
||||
# # mountPath: /data
|
||||
# logLevel: "info" # possible values: trace, debug, info, warn, error
|
||||
# # Queue this worker consumes dispatched messages from (LOITERING_QUEUE). This
|
||||
# # same value is taken into the matching workflows.definitions stage, so the
|
||||
# # engine dispatches and the worker consumes the same queue with no drift.
|
||||
# # Convention: "kcloud-<operation>-queue.fifo".
|
||||
# queue: "kcloud-loitering-queue.fifo"
|
||||
# resources:
|
||||
# requests:
|
||||
# memory: 10Mi
|
||||
# cpu: 10m
|
||||
# ---------------------------------------------------------------------
|
||||
# EXAMPLE stage worker (commented out) for the workflows.definitions example
|
||||
# above — hub-objecttracking. Uncomment the worker whose operation a
|
||||
# definition references, so the engine dispatches and the worker consumes the
|
||||
# same queue with no drift.
|
||||
#objecttracking:
|
||||
# # Deploy the object-tracking worker (operation "objecttracking").
|
||||
# enabled: true
|
||||
# repository: ghcr.io/uug-ai/hub-objecttracking
|
||||
# pullPolicy: IfNotPresent
|
||||
# tag: "v1.0.0"
|
||||
# replicas: 1 # Number of pods for the worker.
|
||||
# topologySpreadConstraints: [] # Optional pod topology spread constraints (empty = none).
|
||||
# logLevel: "info" # possible values: trace, debug, info, warn, error
|
||||
# # Queue this worker consumes dispatched messages from (OBJECTTRACKING_QUEUE).
|
||||
# queue: "kcloud-objecttracking-queue.fifo"
|
||||
# resources:
|
||||
# requests:
|
||||
# memory: 10Mi
|
||||
# cpu: 10m
|
||||
monitordevice:
|
||||
repository: ghcr.io/uug-ai/hub-monitor-device
|
||||
pullPolicy: IfNotPresent
|
||||
tag: "v1.4.0"
|
||||
tag: "v1.4.2"
|
||||
replicas: 1 # Number of pods for the service.
|
||||
topologySpreadConstraints: [] # Optional pod topology spread constraints (empty = none).
|
||||
logLevel: "info" # possible values: trace, debug, info, warn, error
|
||||
@@ -797,7 +921,7 @@ kerberoshub:
|
||||
repository: uugai/hub-reactivatesubscriptions
|
||||
pullPolicy: IfNotPresent
|
||||
tag: "v1.0.2"
|
||||
replicas: 1 # Number of pods for the service.
|
||||
replicas: 0 # Number of pods for the service. Set to 0 to disable.
|
||||
topologySpreadConstraints: [] # Optional pod topology spread constraints (empty = none).
|
||||
# Optional extra volumes / volumeMounts for this deployment (empty = none).
|
||||
#volumes:
|
||||
@@ -830,10 +954,11 @@ kerberoshub:
|
||||
# cpu: 10m
|
||||
# This proxy is legacy for the old agent, will be migrated in the new Hub API.
|
||||
proxy:
|
||||
enabled: false
|
||||
repository: uugai/hub-proxy
|
||||
pullPolicy: IfNotPresent
|
||||
tag: "v1.0.0"
|
||||
replicas: 1 # Number of pods for the service.
|
||||
replicas: 0 # Number of pods for the service when enabled.
|
||||
topologySpreadConstraints: [] # Optional pod topology spread constraints (empty = none).
|
||||
# Optional extra volumes / volumeMounts for this deployment (empty = none).
|
||||
#volumes:
|
||||
@@ -855,7 +980,7 @@ kerberospipeline:
|
||||
event:
|
||||
repository: ghcr.io/uug-ai/hub-pipeline-event
|
||||
pullPolicy: IfNotPresent
|
||||
tag: "v1.3.0"
|
||||
tag: "v1.3.1"
|
||||
replicas: 1 # Number of pods for the service.
|
||||
topologySpreadConstraints: [] # Optional pod topology spread constraints (empty = none).
|
||||
# Optional extra volumes / volumeMounts for this deployment (empty = none).
|
||||
@@ -873,7 +998,7 @@ kerberospipeline:
|
||||
monitor:
|
||||
repository: ghcr.io/uug-ai/hub-pipeline-monitor
|
||||
pullPolicy: IfNotPresent
|
||||
tag: "v1.3.10"
|
||||
tag: "v1.3.13"
|
||||
replicas: 1 # Number of pods for the service.
|
||||
topologySpreadConstraints: [] # Optional pod topology spread constraints (empty = none).
|
||||
# Optional extra volumes / volumeMounts for this deployment (empty = none).
|
||||
@@ -883,6 +1008,7 @@ kerberospipeline:
|
||||
#volumeMounts:
|
||||
# - name: extra
|
||||
# mountPath: /data
|
||||
logLevel: "info" # possible values: debug, info, warn, error
|
||||
resources:
|
||||
requests:
|
||||
memory: 10Mi
|
||||
@@ -890,7 +1016,7 @@ kerberospipeline:
|
||||
sequence:
|
||||
repository: ghcr.io/uug-ai/hub-pipeline-sequence
|
||||
pullPolicy: IfNotPresent
|
||||
tag: "v1.6.18"
|
||||
tag: "v1.6.26"
|
||||
replicas: 1 # Number of pods for the service.
|
||||
topologySpreadConstraints: [] # Optional pod topology spread constraints (empty = none).
|
||||
# Optional extra volumes / volumeMounts for this deployment (empty = none).
|
||||
@@ -907,7 +1033,7 @@ kerberospipeline:
|
||||
throttler:
|
||||
repository: uugai/hub-pipeline-throttler
|
||||
pullPolicy: IfNotPresent
|
||||
tag: "v1.2.0"
|
||||
tag: "v1.2.1"
|
||||
replicas: 1 # Number of pods for the service.
|
||||
topologySpreadConstraints: [] # Optional pod topology spread constraints (empty = none).
|
||||
# Optional extra volumes / volumeMounts for this deployment (empty = none).
|
||||
@@ -925,10 +1051,11 @@ kerberospipeline:
|
||||
notify:
|
||||
repository: ghcr.io/uug-ai/hub-pipeline-notification
|
||||
pullPolicy: IfNotPresent
|
||||
tag: "v1.3.9"
|
||||
tag: "v1.3.18"
|
||||
replicas: 1 # Number of pods for the service.
|
||||
topologySpreadConstraints: [] # Optional pod topology spread constraints (empty = none).
|
||||
logLevel: "info" # possible values: trace, debug, info, warn, error
|
||||
notificationExpiryMinutes: "15" # Maximum recording age before notification delivery; 0 disables expiry.
|
||||
resources:
|
||||
requests:
|
||||
memory: 10Mi
|
||||
@@ -944,7 +1071,7 @@ kerberospipeline:
|
||||
notifyTest:
|
||||
repository: uugai/hub-pipeline-notification-test
|
||||
pullPolicy: IfNotPresent
|
||||
tag: "v1.2.1"
|
||||
tag: "v1.2.2"
|
||||
replicas: 1 # Number of pods for the service.
|
||||
topologySpreadConstraints: [] # Optional pod topology spread constraints (empty = none).
|
||||
resources:
|
||||
@@ -962,7 +1089,7 @@ kerberospipeline:
|
||||
analysis:
|
||||
repository: ghcr.io/uug-ai/hub-pipeline-analysis
|
||||
pullPolicy: IfNotPresent
|
||||
tag: "v1.7.17"
|
||||
tag: "v1.8.5"
|
||||
replicas: 1 # Number of pods for the service.
|
||||
topologySpreadConstraints: [] # Optional pod topology spread constraints (empty = none).
|
||||
# Optional extra volumes / volumeMounts for this deployment (empty = none).
|
||||
@@ -980,7 +1107,7 @@ kerberospipeline:
|
||||
dominantColor:
|
||||
repository: ghcr.io/uug-ai/hub-pipeline-dominantcolors
|
||||
pullPolicy: IfNotPresent
|
||||
tag: "v2.0.2"
|
||||
tag: "v2.0.3"
|
||||
replicas: 3 # Number of pods for the service.
|
||||
topologySpreadConstraints: [] # Optional pod topology spread constraints (empty = none).
|
||||
# Optional extra volumes / volumeMounts for this deployment (empty = none).
|
||||
@@ -1001,7 +1128,7 @@ kerberospipeline:
|
||||
thumbnail:
|
||||
repository: ghcr.io/uug-ai/hub-pipeline-thumbnail
|
||||
pullPolicy: IfNotPresent
|
||||
tag: "v1.3.6"
|
||||
tag: "v1.3.10"
|
||||
replicas: 2 # Number of pods for the service.
|
||||
topologySpreadConstraints: [] # Optional pod topology spread constraints (empty = none).
|
||||
# Optional extra volumes / volumeMounts for this deployment (empty = none).
|
||||
@@ -1027,7 +1154,7 @@ kerberospipeline:
|
||||
counting:
|
||||
repository: uugai/hub-pipeline-counting
|
||||
pullPolicy: IfNotPresent
|
||||
tag: "v1.6.3"
|
||||
tag: "v2.0.0"
|
||||
replicas: 1 # Number of pods for the service.
|
||||
topologySpreadConstraints: [] # Optional pod topology spread constraints (empty = none).
|
||||
# Optional extra volumes / volumeMounts for this deployment (empty = none).
|
||||
@@ -1046,7 +1173,7 @@ kerberospipeline:
|
||||
enabled: false # Enable or disable the sprite generation 'true' or 'false
|
||||
repository: ghcr.io/uug-ai/hub-pipeline-sprite
|
||||
pullPolicy: IfNotPresent
|
||||
tag: "v1.1.14"
|
||||
tag: "v1.1.16"
|
||||
replicas: 5 # Number of pods for the service.
|
||||
topologySpreadConstraints: [] # Optional pod topology spread constraints (empty = none).
|
||||
# Optional extra volumes / volumeMounts for this deployment (empty = none).
|
||||
@@ -1070,7 +1197,7 @@ kerberospipeline:
|
||||
export:
|
||||
repository: ghcr.io/uug-ai/hub-pipeline-export
|
||||
pullPolicy: IfNotPresent
|
||||
tag: "v1.2.8"
|
||||
tag: "v1.2.10"
|
||||
replicas: 2 # Number of pods for the service.
|
||||
topologySpreadConstraints: [] # Optional pod topology spread constraints (empty = none).
|
||||
logLevel: "info" # possible values: trace, debug, info, warn, error
|
||||
|
||||
Reference in New Issue
Block a user