mirror of
https://github.com/kerberos-io/helm-charts.git
synced 2026-08-23 15:18:33 +00:00
Compare commits
143 Commits
hub-0.101.
...
main
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
f834d9b8f5 | ||
|
|
eefe96c679 | ||
|
|
93888e2855 | ||
|
|
759ac8dbf8 | ||
|
|
4aaa70f121 | ||
|
|
ad7ef4ac12 | ||
|
|
5ad56f9730 | ||
|
|
91eb64a2f3 | ||
|
|
55ae6cdd3e | ||
|
|
f492c14336 | ||
|
|
d4a13a4cff | ||
|
|
98cc8d4f2d | ||
|
|
a5125eee69 | ||
|
|
b2ff3e2e20 | ||
|
|
277ddde3b4 | ||
|
|
7878be79d6 | ||
|
|
123bde292e | ||
|
|
e76311872e | ||
|
|
0f2176822a | ||
|
|
8ca4c402f8 | ||
|
|
8d9b943100 | ||
|
|
3e10489251 | ||
|
|
a7fd8d394f | ||
|
|
c29647ec62 | ||
|
|
685b92e9cc | ||
|
|
01d1e6866a | ||
|
|
8cf73bcf1d | ||
|
|
57f6ab6f3b | ||
|
|
2ed7829391 | ||
|
|
0c9726f21b | ||
|
|
9ae2e1fc86 | ||
|
|
f3a9886053 | ||
|
|
933fedc080 | ||
|
|
2c7f6a89a3 | ||
|
|
5af0ffab6c | ||
|
|
0a3cf69c80 | ||
|
|
b8499c97e2 | ||
|
|
641dc7510c | ||
|
|
20f4fa24ba | ||
|
|
b793014f89 | ||
|
|
348bab8f2b | ||
|
|
8a71bd2a05 | ||
|
|
611ddec1f1 | ||
|
|
34a285666e | ||
|
|
59cf74ba66 | ||
|
|
020f2d969d | ||
|
|
eeb29e8cac | ||
|
|
1ec2be4cc7 | ||
|
|
b9166ea1ed | ||
|
|
be2290075c | ||
|
|
cb47ad3f12 | ||
|
|
42bd87d16d | ||
|
|
0ed38add2e | ||
|
|
c8c070d51e | ||
|
|
0e21755bb8 | ||
|
|
8781ede494 | ||
|
|
82e3da78dd | ||
|
|
30bbd97b6d | ||
|
|
b78a2246ee | ||
|
|
33b41cee0e | ||
|
|
3a464eeb8e | ||
|
|
d599befeaf | ||
|
|
9ea9016bfa | ||
|
|
895c190e20 | ||
|
|
f4051f7e6a | ||
|
|
807369ef01 | ||
|
|
19cf677a56 | ||
|
|
7b39949e5b | ||
|
|
3752c0396e | ||
|
|
0d55fa5d2f | ||
|
|
2949db0a03 | ||
|
|
662a2c6a67 | ||
|
|
7cf273911e | ||
|
|
20f1de461d | ||
|
|
a237f7b4d6 | ||
|
|
fae8b028ad | ||
|
|
31ec7cb6af | ||
|
|
424053f2ce | ||
|
|
7c17a99240 | ||
|
|
dafba78c94 | ||
|
|
dc48269807 | ||
|
|
eff71c4e24 | ||
|
|
642676fcf7 | ||
|
|
25bb6d5fdc | ||
|
|
20b92ffddd | ||
|
|
bb4cc53d90 | ||
|
|
7b920c3f0e | ||
|
|
52757a66ae | ||
|
|
e664e78d01 | ||
|
|
14508d3ebf | ||
|
|
5b15104951 | ||
|
|
daa17bb623 | ||
|
|
cf4b475ad0 | ||
|
|
262a572302 | ||
|
|
0800e56f00 | ||
|
|
398ddc0a15 | ||
|
|
9d51b0ef48 | ||
|
|
c47bb70777 | ||
|
|
250a3aa124 | ||
|
|
9524f43157 | ||
|
|
d85758389a | ||
|
|
8ce56a0fbd | ||
|
|
932ded63a1 | ||
|
|
ca30ebfd3c | ||
|
|
ea5705c03c | ||
|
|
acac39eccd | ||
|
|
029f288f4d | ||
|
|
376819719f | ||
|
|
0b2a4fb8a9 | ||
|
|
12cf8218c3 | ||
|
|
3767a430fc | ||
|
|
5061ba014a | ||
|
|
3e54eef0d3 | ||
|
|
291ac48102 | ||
|
|
88ff3e9e33 | ||
|
|
58e8f2d8d9 | ||
|
|
555b69c15a | ||
|
|
6f82740be8 | ||
|
|
8a739069d9 | ||
|
|
6c52794509 | ||
|
|
f07230406a | ||
|
|
f5b45a5e0d | ||
|
|
5bf9f4cefa | ||
|
|
05c2a0d04d | ||
|
|
e7b90f5953 | ||
|
|
ae7cf770e8 | ||
|
|
078b64d474 | ||
|
|
4e160c4b9d | ||
|
|
e7aeacae17 | ||
|
|
a307e6a3f2 | ||
|
|
0878453ed9 | ||
|
|
52f3124ee7 | ||
|
|
ea3186cdaa | ||
|
|
e25e63c841 | ||
|
|
1d70aaf527 | ||
|
|
8d713da9c9 | ||
|
|
9b9f671525 | ||
|
|
fa76f00094 | ||
|
|
2e247fbc90 | ||
|
|
3b4525a47d | ||
|
|
fa56f11b7b | ||
|
|
5ae77dccc8 | ||
|
|
d5a76a46f9 |
31
.github/workflows/workflows-queue-consistency.yaml
vendored
Normal file
31
.github/workflows/workflows-queue-consistency.yaml
vendored
Normal file
@@ -0,0 +1,31 @@
|
||||
name: Workflows queue consistency
|
||||
|
||||
# Fails the build if the analysis producer, the workflows engine and the stage
|
||||
# workers would render onto different WORKFLOWS_QUEUE names — the silent
|
||||
# producer/consumer queue-name drift that leaves runs piling up with no
|
||||
# consumer. Pure `helm template` render check, no cluster required.
|
||||
on:
|
||||
workflow_dispatch:
|
||||
pull_request:
|
||||
paths:
|
||||
- 'charts/hub/**'
|
||||
- 'scripts/check-workflows-queue-consistency.sh'
|
||||
- '.github/workflows/workflows-queue-consistency.yaml'
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
jobs:
|
||||
check:
|
||||
runs-on: ubuntu-24.04
|
||||
steps:
|
||||
- name: Checkout repository
|
||||
uses: actions/checkout@v4
|
||||
|
||||
- name: Set up Helm
|
||||
uses: azure/setup-helm@v4
|
||||
with:
|
||||
version: v3.16.2
|
||||
|
||||
- name: Check WORKFLOWS_QUEUE consistency
|
||||
run: ./scripts/check-workflows-queue-consistency.sh charts/hub
|
||||
@@ -16,7 +16,7 @@ type: application
|
||||
# This is the chart version. This version number should be incremented each time you make changes
|
||||
# to the chart and its templates, including the app version.
|
||||
# Versions are expected to follow Semantic Versioning (https://semver.org/)
|
||||
version: 0.101.0
|
||||
version: 0.130.0
|
||||
|
||||
# This is the version number of the application being deployed. This version number should be
|
||||
# incremented each time you make changes to the application. Versions are not expected to
|
||||
|
||||
@@ -37,114 +37,123 @@ Below all configuration options and parameters are listed.
|
||||
|
||||
| Name | Description | Value |
|
||||
| ------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------- | ----- |
|
||||
| `license` | The license key you received from support@kerberos.io. If not available request one. | `""` |
|
||||
| `license` | The license key you received from support@kerberos.io. If not available request one. | `"L/+DAwEBB2xpY2Vuc2UB/4QAAQIBB1BheWxvYWQBCgABCVNpZ25hdHVyZQEKAAAA/gMk/4QB/gEZ/8sQACxnaXRodWIuY29tL3V1Zy1haS9odWItbGljZW5zZS9tb2RlbHMuTGljZW5zZX8DAQEHTGljZW5zZQH/gAABDAECSWQB/4IAAQNLZXkBDAABB0NvbXBhbnkBDAABB0V4cFRpbWUBBAABBERheXMBBAABB0NhbWVyYXMBBAABBVNpdGVzAQQAAQZWYXVsdHMBBAABCk1lZGlhTGltaXQBBAABCVBlcnBldHVhbAECAAEGQWN0aXZlAQIAAQlJcEFkZHJlc3MBDAAAABj/gQEBAQhPYmplY3RJRAH/ggABBgEYAAAy/4AvAQwAAAAAAAAAAAAAAAACDGZyZWUtbGljZW5zZQH81iZi6gH+AtoBEAEUARQDAQAB/gIAfeXxQb6kaPfAgOWeSAE6qEiQviFD6sciNmNfMel1mEL53FeV0GQe4cYBip9wyJag35az8A1yppxSymZD5V4my2FckyN2zmEW4E2sO/v+8eKepiAGYEzrKtfNCLxdWLmrHd0zjYQ3qk+PNfoPyzCOefeulw3aFsqBlzg9wDkF8cRx6tUW0qNTzki6sFGOuLoxS49cWqsftAvZmt+CRWa8u0VArIAjOpywN0RIZCkEYzp5RYF3LSVyWYEyvVhjE19DDnevzpJyCHRsIHTRcpTQkhboeapOdlEz8cx+PaOvxktN8hBWceTAH+nw96FARG7y6Cpjw3xo+NV1xb0tvRXGaGoK77JnErKLhd/haXji98rGvMakDt18WSbQfTVS84+Fw+/gKGsW3uS3fROAaZw1kZj4PgsEPZDvbVkCVyuS0O87UoYqpxH8S4by8cTF3wDP7FwyIRZbEbYjN2wzHSmlADYOBtdsdb1VGm7wvtB85vML9n7ZSlIpJdqfci06mGks102mDyG2LRMhUEvpUW3D/weErIvj2WiAwf6r0EUj+LO8VmAsYkME9da7FXEN6Vg/5f1u485LOpYki332RaDOhDn2eMG9DVb/HnmQSFagX+XXc/QwfsWiehCgKYGk4jQpyklTqoGu8BAt6Sm8CaoH8ngZ3cHLQT5DcZElV36/N/wA"` |
|
||||
| `licenseServer.url` | The license server for validating the license of your Kerberos Hub, by default `'"https://license.kerberos.io/verify"'`. | `""` |
|
||||
| `licenseServer.token` | The license server API token to sign the license validation by default `'214%ˆ#ddfsf@#3rfdsgl_)23sffeqasSwefDSFNBM'`. | `""` |
|
||||
| `environment` | A colored banner will be shown on top of the application to illustrate a non-production environment: `staging`, `demo`, .. | `""` |
|
||||
| `isPrivate` | Global StorageClass for Persistent Volume(s) | `""` |
|
||||
| `readOnly` | This will stop any write process to mongodb or any processing done in the Kerberos Hub pipeline. | `""` |
|
||||
| `environment` | A colored banner will be shown on top of the application to illustrate a non-production environment: `staging`, `demo`, .. | `"production"` |
|
||||
| `isPrivate` | Global StorageClass for Persistent Volume(s) | `true` |
|
||||
| `readOnly` | This will stop any write process to mongodb or any processing done in the Kerberos Hub pipeline. | `false` |
|
||||
| `mode` | Deployment mode: `all`, `pipeline`, or `ui`. `all` renders everything, `pipeline` only pipeline services, `ui` only hub services. | `"all"` |
|
||||
| `global.imageRegistry` | Global container registry override used for all images. | `""` |
|
||||
| `ingress` | The ingress being used for `kerberoshub.api.url` and `kerberoshub.frontend.url`. | `""` |
|
||||
| `mongodb.host` | MongoDB hostname (`'mongodb:27017'`) or mongodb replicas (`'mongodb-0:27017,mongodb-1:27017'`). | `""` |
|
||||
| `mongodb.adminDatabase` | MongoDB admin database, this is named `admin` by default. | `""` |
|
||||
| `mongodb.authenticationMechanism` | MongoDB authentication mechanism (for example `SCRAM-SHA-256`). | `""` |
|
||||
| `mongodb.username` | MongoDB user account, we are using in the hub installation `'root'`. | `""` |
|
||||
| `mongodb.password` | MongoDB user password, by default `'yourmongodbpassword'` | `""` |
|
||||
| `mongodb.retryWrites` | Enable or disable MongoDB retryable writes. | `""` |
|
||||
| `mqtt.host` | MQTT (Vernemq) hostname. | `""` |
|
||||
| `mqtt.port` | MQTT (Vernemq) port for WSS (secure sockets), by default `'8443'`. | `""` |
|
||||
| `mqtt.protocol` | MQTT (Vernemq) protocol, by default `'wss'`. | `""` |
|
||||
| `mqtt.username` | MQTT (Vernemq) username, by default `'yourusername'`. | `""` |
|
||||
| `mqtt.password` | MQTT (Vernemq) password, by default `'yourpassword'`. | `""` |
|
||||
| `ingress` | The ingress being used for `kerberoshub.api.url` and `kerberoshub.frontend.url`. | `"nginx"` |
|
||||
| `mongodb.host` | MongoDB hostname (`'mongodb:27017'`) or mongodb replicas (`'mongodb-0:27017,mongodb-1:27017'`). | `"mongodb.mongodb"` |
|
||||
| `mongodb.adminDatabase` | MongoDB admin database, this is named `admin` by default. | `"admin"` |
|
||||
| `mongodb.authenticationMechanism` | MongoDB authentication mechanism (for example `SCRAM-SHA-256`). | `"SCRAM-SHA-256"` |
|
||||
| `mongodb.username` | MongoDB user account, we are using in the hub installation `'root'`. | `"yourusername"` |
|
||||
| `mongodb.password` | MongoDB user password, by default `'yourmongodbpassword'` | `"yourpassword"` |
|
||||
| `mongodb.retryWrites` | Enable or disable MongoDB retryable writes. | `"true"` |
|
||||
| `mongodb.flavor` | Backend engine flavor: `"mongodb"` (native MongoDB / Atlas) or `"documentdb"` (AWS DocumentDB). The `documentdb` flavor disables features DocumentDB does not support (geospatial queries/indexes, complex `$lookup` pipelines). When set to `documentdb`, also set `mongodb.retryWrites: "false"`. | `"mongodb"` |
|
||||
| `mongodb.tls.enabled` | Enable TLS for MongoDB connections. When `mongodb.uri` is set, the chart appends missing `tls=true` and `tlsCAFile` query parameters. | `false` |
|
||||
| `mongodb.tls.existingSecret` | Existing Kubernetes Secret containing the MongoDB CA bundle. The Secret is mounted into every workload that consumes `mongodb-config`. | `""` |
|
||||
| `mongodb.tls.caFileName` | Key and filename of the CA bundle in `mongodb.tls.existingSecret` (for AWS DocumentDB, typically `global-bundle.pem`). | `""` |
|
||||
| `mongodb.tls.mountPath` | Read-only directory where the MongoDB CA Secret is mounted. | `"/etc/mongodb/tls"` |
|
||||
| `mongodb.tls.insecureSkipVerify` | Skip MongoDB certificate and hostname verification. This is insecure and intended only for local testing. | `false` |
|
||||
| `mqtt.host` | MQTT (Vernemq) hostname. | `"mqtt.yourdomain.com"` |
|
||||
| `mqtt.port` | MQTT (Vernemq) port for WSS (secure sockets), by default `'8443'`. | `"8443"` |
|
||||
| `mqtt.protocol` | MQTT (Vernemq) protocol, by default `'wss'`. | `"wss"` |
|
||||
| `mqtt.username` | MQTT (Vernemq) username, by default `'yourusername'`. | `"yourusername"` |
|
||||
| `mqtt.password` | MQTT (Vernemq) password, by default `'yourpassword'`. | `"yourpassword"` |
|
||||
| `mqtt.legacy.host` | Legacy MQTT broker host used for backward-compatible clients. | `""` |
|
||||
| `mqtt.legacy.port` | Legacy MQTT broker port used for backward-compatible clients. | `""` |
|
||||
| `queueProvider` | The queue we are using for the [pipeline](https://doc.kerberos.io/hub/pipeline/): 'SQS', 'KAFKA' or `RABBITMQ`. | `""` |
|
||||
| `queueName` | The event queue which is propagating messages in the [Kerberos Hub pipeline](https://doc.kerberos.io/hub/pipeline/). | `""` |
|
||||
| `rabbitmq.host` | RabbitMQ host, by default `'rabbitmq.yourdomain.com:5671'` | `""` |
|
||||
| `rabbitmq.username` | RabbitMQ username, by default `'yourusername'` | `""` |
|
||||
| `rabbitmq.password` | RabbitMQ password, by default `'yourpassword'` | `""` |
|
||||
| `queueProvider` | The queue we are using for the [pipeline](https://doc.kerberos.io/hub/pipeline/): 'SQS', 'KAFKA' or `RABBITMQ`. | `"RABBITMQ"` |
|
||||
| `queueName` | The event queue which is propagating messages in the [Kerberos Hub pipeline](https://doc.kerberos.io/hub/pipeline/). | `"kcloud-event-queue"` |
|
||||
| `rabbitmq.host` | RabbitMQ host, by default `'rabbitmq.yourdomain.com:5671'` | `"rabbitmq.rabbitmq:5672"` |
|
||||
| `rabbitmq.username` | RabbitMQ username, by default `'yourusername'` | `"yourusername"` |
|
||||
| `rabbitmq.password` | RabbitMQ password, by default `'yourpassword'` | `"yourpassword"` |
|
||||
| `rabbitmq.exchange` | RabbitMQ exchange, by default `''` | `""` |
|
||||
| `kafka.broker` | Kafka brokers, by default `'kafka1.yourdomain.com:9094,kafka2.yourdomain.com:9094'` | `""` |
|
||||
| `kafka.username` | Kafka username, by default `'yourusername'` | `""` |
|
||||
| `kafka.password` | Kafka password, by default `'yourpassword'` | `""` |
|
||||
| `kafka.mechanism` | Kafka mechanism, by default `'PLAIN'` | `""` |
|
||||
| `kafka.security` | Kafka security, by default `'SASL_PLAINTEXT'` | `""` |
|
||||
| `turn.host` | TURN/STUN hostname, by default `'turn:turn.yourdomain.com:8443'` | `""` |
|
||||
| `turn.username` | TURN/STUN username, by default `'username1'` | `""` |
|
||||
| `turn.password` | TURN/STUN password, by default `'password1'` | `""` |
|
||||
| `opentelemetry.enabled` | Enable or disable OpenTelemetry instrumentation. | `""` |
|
||||
| `opentelemetry.routingEnabled` | Enable or disable OpenTelemetry routing/export behavior. | `""` |
|
||||
| `opentelemetry.collector.endpoint` | OpenTelemetry collector endpoint used for trace export. | `""` |
|
||||
| `openai.enabled` | Enable or disable OpenAI-backed semantic features. | `""` |
|
||||
| `openai.apikey` | OpenAI API key used when OpenAI integration is enabled. | `""` |
|
||||
| `kerberosvault.uri` | The default Kerberos Vault uri (you can add multiple within the app), by default `'https://api.storage.yourdomain.com'` | `""` |
|
||||
| `kerberosvault.provider` | The default Kerberos Vault provider`'a-provider'` | `""` |
|
||||
| `kerberosvault.accesskey` | The default Kerberos Vault access key, by default `'xxx'` | `""` |
|
||||
| `kerberosvault.secretkey` | The default Kerberos Vault secret key, by default `'xxx'` | `""` |
|
||||
| `kerberosvault.archive.provider` | When a task is created, the relevant recording is moved to this provider `'an-archive-provider'` | `""` |
|
||||
| `kerberosvault.archive.accesskey` | When a task is created, the relevant recording is moved to another provider, using this access key `'xxx'` | `""` |
|
||||
| `kerberosvault.archive.secretkey` | When a task is created, the relevant recording is moved to another provider, using this secret key`'xxx'` | `""` |
|
||||
| `kerberosvault.thumbnail.provider` | Configuration value for `kerberosvault.thumbnail.provider`. | `""` |
|
||||
| `kerberosvault.thumbnail.accessKey` | Access key for `kerberosvault.thumbnail`. | `""` |
|
||||
| `kerberosvault.thumbnail.secretKey` | Secret key for `kerberosvault.thumbnail`. | `""` |
|
||||
| `kerberosvault.sprite.provider` | Configuration value for `kerberosvault.sprite.provider`. | `""` |
|
||||
| `kerberosvault.sprite.accessKey` | Access key for `kerberosvault.sprite`. | `""` |
|
||||
| `kerberosvault.sprite.secretKey` | Secret key for `kerberosvault.sprite`. | `""` |
|
||||
| `admin.repository` | Container image repository for `admin`. | `""` |
|
||||
| `admin.pullPolicy` | Image pull policy for `admin`. | `""` |
|
||||
| `admin.tag` | Container image tag/version for `admin`. | `""` |
|
||||
| `admin.replicas` | Number of replicas for `admin`. | `""` |
|
||||
| `admin.logLevel` | Log verbosity level for `admin`. | `""` |
|
||||
| `admin.resources.requests.memory` | Memory request for `admin`. | `""` |
|
||||
| `admin.resources.requests.cpu` | CPU request for `admin`. | `""` |
|
||||
| `admin.url` | URL for `admin`. | `""` |
|
||||
| `kafka.broker` | Kafka brokers, by default `'kafka1.yourdomain.com:9094,kafka2.yourdomain.com:9094'` | `"kafka1.yourdomain.com:9094"` |
|
||||
| `kafka.username` | Kafka username, by default `'yourusername'` | `"yourusername"` |
|
||||
| `kafka.password` | Kafka password, by default `'yourpassword'` | `"yourpassword"` |
|
||||
| `kafka.mechanism` | Kafka mechanism, by default `'PLAIN'` | `"PLAIN"` |
|
||||
| `kafka.security` | Kafka security, by default `'SASL_PLAINTEXT'` | `"SASL_PLAINTEXT"` |
|
||||
| `turn.host` | TURN/STUN hostname, by default `'turn:turn.yourdomain.com:8443'` | `"turn:turn.yourdomain.com:8443"` |
|
||||
| `turn.username` | TURN/STUN username, by default `'username1'` | `"username1"` |
|
||||
| `turn.password` | TURN/STUN password, by default `'password1'` | `"password1"` |
|
||||
| `opentelemetry.enabled` | Enable or disable OpenTelemetry instrumentation. | `false` |
|
||||
| `opentelemetry.routingEnabled` | Enable or disable OpenTelemetry routing/export behavior. | `false` |
|
||||
| `opentelemetry.collector.endpoint` | OpenTelemetry collector endpoint used for trace export. | `"http://otel-collector:4317"` |
|
||||
| `openai.enabled` | Enable or disable OpenAI-backed semantic features. | `false` |
|
||||
| `openai.apikey` | OpenAI API key used when OpenAI integration is enabled. | `"xxx"` |
|
||||
| `kerberosvault.uri` | The default Kerberos Vault uri (you can add multiple within the app), by default `'https://api.storage.yourdomain.com'` | `"https://api.vault.yourdomain.com"` |
|
||||
| `kerberosvault.provider` | The default Kerberos Vault provider`'a-provider'` | `"a-provider"` |
|
||||
| `kerberosvault.accesskey` | The default Kerberos Vault access key, by default `'xxx'` | `"xxx"` |
|
||||
| `kerberosvault.secretkey` | The default Kerberos Vault secret key, by default `'xxx'` | `"xxx"` |
|
||||
| `kerberosvault.archive.provider` | When a task is created, the relevant recording is moved to this provider `'an-archive-provider'` | `"an-archive-provider"` |
|
||||
| `kerberosvault.archive.accesskey` | When a task is created, the relevant recording is moved to another provider, using this access key `'xxx'` | `"xxx"` |
|
||||
| `kerberosvault.archive.secretkey` | When a task is created, the relevant recording is moved to another provider, using this secret key`'xxx'` | `"xxx"` |
|
||||
| `kerberosvault.thumbnail.provider` | Configuration value for `kerberosvault.thumbnail.provider`. | `"a-thumbnail-provider"` |
|
||||
| `kerberosvault.thumbnail.accessKey` | Access key for `kerberosvault.thumbnail`. | `"xxx"` |
|
||||
| `kerberosvault.thumbnail.secretKey` | Secret key for `kerberosvault.thumbnail`. | `"xxx"` |
|
||||
| `kerberosvault.sprite.provider` | Configuration value for `kerberosvault.sprite.provider`. | `"a-sprite-provider"` |
|
||||
| `kerberosvault.sprite.accessKey` | Access key for `kerberosvault.sprite`. | `"xxx"` |
|
||||
| `kerberosvault.sprite.secretKey` | Secret key for `kerberosvault.sprite`. | `"xxx"` |
|
||||
| `admin.repository` | Container image repository for `admin`. | `"uugai/admin"` |
|
||||
| `admin.pullPolicy` | Image pull policy for `admin`. | `"IfNotPresent"` |
|
||||
| `admin.tag` | Container image tag/version for `admin`. | `"v1.3.0"` |
|
||||
| `admin.replicas` | Number of replicas for `admin`. | `2` |
|
||||
| `admin.logLevel` | Log verbosity level for `admin`. | `"info"` |
|
||||
| `admin.resources.requests.memory` | Memory request for `admin`. | `"100Mi"` |
|
||||
| `admin.resources.requests.cpu` | CPU request for `admin`. | `"250m"` |
|
||||
| `admin.url` | URL for `admin`. | `"admin.yourdomain.com"` |
|
||||
| `admin.tls.secretName` | Kubernetes Secret name used by `admin.tls`. | `""` |
|
||||
| `admin.oauth2Proxy.enabled` | Enable or disable `admin.oauth2Proxy`. | `""` |
|
||||
| `admin.oauth2Proxy.github.clientId` | Client ID used by `admin.oauth2Proxy.github`. | `""` |
|
||||
| `admin.oauth2Proxy.github.clientSecret` | Client secret used by `admin.oauth2Proxy.github`. | `""` |
|
||||
| `admin.oauth2Proxy.github.cookieSecret` | Cookie secret used by `admin.oauth2Proxy.github`. | `""` |
|
||||
| `admin.oauth2Proxy.github.organization` | Organization value used by `admin.oauth2Proxy.github`. | `""` |
|
||||
| `admin.oauth2Proxy.github.team` | Team value used by `admin.oauth2Proxy.github`. | `""` |
|
||||
| `kerberoshub.extraEnv` | Additional environment variables injected into Kerberos Hub pods. | `""` |
|
||||
| `kerberoshub.serviceAccount.create` | Create or manage `kerberoshub.serviceAccount` resources. | `""` |
|
||||
| `admin.oauth2Proxy.enabled` | Enable or disable `admin.oauth2Proxy`. | `false` |
|
||||
| `admin.oauth2Proxy.github.clientId` | Client ID used by `admin.oauth2Proxy.github`. | `"github-client-id"` |
|
||||
| `admin.oauth2Proxy.github.clientSecret` | Client secret used by `admin.oauth2Proxy.github`. | `"github-client-secret"` |
|
||||
| `admin.oauth2Proxy.github.cookieSecret` | Cookie secret used by `admin.oauth2Proxy.github`. | `"generate-a-random-cookie-secret"` |
|
||||
| `admin.oauth2Proxy.github.organization` | Organization value used by `admin.oauth2Proxy.github`. | `"github-organization"` |
|
||||
| `admin.oauth2Proxy.github.team` | Team value used by `admin.oauth2Proxy.github`. | `"github-team"` |
|
||||
| `kerberoshub.extraEnv` | Additional environment variables injected into Kerberos Hub pods. | `[]` |
|
||||
| `kerberoshub.serviceAccount.create` | Create or manage `kerberoshub.serviceAccount` resources. | `false` |
|
||||
| `kerberoshub.serviceAccount.name` | Name value for `kerberoshub.serviceAccount`. | `""` |
|
||||
| `kerberoshub.serviceAccount.annotations` | Annotations applied to `kerberoshub.serviceAccount` resources. | `""` |
|
||||
| `kerberoshub.serviceAccount.labels` | Labels applied to `kerberoshub.serviceAccount` resources. | `""` |
|
||||
| `kerberoshub.api.repository` | The Docker registry where the Kerberos Hub API container is hosted. | `""` |
|
||||
| `kerberoshub.api.pullPolicy` | The Docker registry pull policy. | `""` |
|
||||
| `kerberoshub.api.tag` | The Docker image tag/version. | `""` |
|
||||
| `kerberoshub.api.replicas` | The number of pods/replicas running for the Kerberos Hub API deployment. | `""` |
|
||||
| `kerberoshub.api.logLevel` | Log verbosity level for `kerberoshub.api`. | `""` |
|
||||
| `kerberoshub.api.jwtSecret` | A secret that is for generating JWT tokens. | `""` |
|
||||
| `kerberoshub.api.schema` | The protocol to serve the Kerberos Hub API, `'http'` or `'https'`. | `""` |
|
||||
| `kerberoshub.api.url` | The Kerberos Hub API ingress to access the API. | `""` |
|
||||
| `kerberoshub.api.resources.requests.memory` | Memory request for `kerberoshub.api`. | `""` |
|
||||
| `kerberoshub.api.resources.requests.cpu` | CPU request for `kerberoshub.api`. | `""` |
|
||||
| `kerberoshub.api.serverTLS.enabled` | Enable or disable `kerberoshub.api.serverTLS`. | `""` |
|
||||
| `kerberoshub.api.repository` | The Docker registry where the Kerberos Hub API container is hosted. | `"ghcr.io/uug-ai/hub-api"` |
|
||||
| `kerberoshub.api.pullPolicy` | The Docker registry pull policy. | `"IfNotPresent"` |
|
||||
| `kerberoshub.api.tag` | The Docker image tag/version. | `"v1.9.8"` |
|
||||
| `kerberoshub.api.replicas` | The number of pods/replicas running for the Kerberos Hub API deployment. | `2` |
|
||||
| `kerberoshub.api.logLevel` | Log verbosity level for `kerberoshub.api`. | `"info"` |
|
||||
| `kerberoshub.api.jwtSecret` | A secret that is for generating JWT tokens. | `"this-is-a-secret-please-change-to-random-string"` |
|
||||
| `kerberoshub.api.schema` | The protocol to serve the Kerberos Hub API, `'http'` or `'https'`. | `"https"` |
|
||||
| `kerberoshub.api.url` | The Kerberos Hub API ingress to access the API. | `"api.yourdomain.com"` |
|
||||
| `kerberoshub.api.resources.requests.memory` | Memory request for `kerberoshub.api`. | `"100Mi"` |
|
||||
| `kerberoshub.api.resources.requests.cpu` | CPU request for `kerberoshub.api`. | `"250m"` |
|
||||
| `kerberoshub.api.resources.limits.memory` | Memory limit for `kerberoshub.api`. | `"100Mi"` |
|
||||
| `kerberoshub.api.resources.limits.cpu` | CPU limit for `kerberoshub.api`. | `"250m"` |
|
||||
| `kerberoshub.api.serverTLS.enabled` | Enable or disable `kerberoshub.api.serverTLS`. | `false` |
|
||||
| `kerberoshub.api.serverTLS.secretName` | Kubernetes Secret name used by `kerberoshub.api.serverTLS`. | `""` |
|
||||
| `kerberoshub.api.serverTLS.mountPath` | Filesystem path where the Hub API TLS secret is mounted. | `""` |
|
||||
| `kerberoshub.api.serverTLS.certFile` | Path to the TLS certificate file used by Hub API server-side TLS. | `""` |
|
||||
| `kerberoshub.api.serverTLS.keyFile` | Path to the TLS private key file used by Hub API server-side TLS. | `""` |
|
||||
| `kerberoshub.api.mfaIssuer` | When enabling the MFA access, this is the name that will be shown in the MFA app. | `""` |
|
||||
| `kerberoshub.api.apiKey` | API key for `kerberoshub.api`. | `""` |
|
||||
| `kerberoshub.api.tls` | Bring your own TLS certificates for Kerberos Hub API ingress. | `""` |
|
||||
| `kerberoshub.api.serverTLS.mountPath` | Filesystem path where the Hub API TLS secret is mounted. | `"/etc/hub-api/tls"` |
|
||||
| `kerberoshub.api.serverTLS.certFile` | Path to the TLS certificate file used by Hub API server-side TLS. | `"/etc/hub-api/tls/tls.crt"` |
|
||||
| `kerberoshub.api.serverTLS.keyFile` | Path to the TLS private key file used by Hub API server-side TLS. | `"/etc/hub-api/tls/tls.key"` |
|
||||
| `kerberoshub.api.mfaIssuer` | When enabling the MFA access, this is the name that will be shown in the MFA app. | `"yourdomain.com"` |
|
||||
| `kerberoshub.api.apiKey` | API key for `kerberoshub.api`. | `"a-random-admin-api-key"` |
|
||||
| `kerberoshub.api.defaultTaskRetentionDays` | Default retention (in days) applied to tasks without an explicit `retention_days`. New tasks are stamped with this value. Set to `"0"` or a negative value to keep tasks indefinitely. Must match `kerberoshub.cleanup.defaultTaskRetentionDays`. | `"0"` |
|
||||
| `kerberoshub.api.tls` | Bring your own TLS certificates for Kerberos Hub API ingress. | `<list>` |
|
||||
| `kerberoshub.api.tls.secretName` | Kubernetes Secret name used by `kerberoshub.api.tls`. | `""` |
|
||||
| `kerberoshub.api.language` | The language of Kerberos Hub API responses, error messages will be communicated in the specified language. | `""` |
|
||||
| `kerberoshub.api.fallbackLanguage` | The fallback language, if a specific translation is not available. | `""` |
|
||||
| `kerberoshub.api.aws.region` | AWS region used by the Hub API legacy S3 integration. | `""` |
|
||||
| `kerberoshub.api.aws.bucket` | AWS S3 bucket used by the Hub API legacy S3 integration. | `""` |
|
||||
| `kerberoshub.api.aws.accessKey` | Access key for `kerberoshub.api.aws`. | `""` |
|
||||
| `kerberoshub.api.aws.secretKey` | Secret key for `kerberoshub.api.aws`. | `""` |
|
||||
| `kerberoshub.api.stripe.privateKey` | Private key for `kerberoshub.api.stripe`. | `""` |
|
||||
| `kerberoshub.api.slack.enabled` | Slack integration for sending events and notifications coming from the Kerberos Hub API, `'true'` or `'false'`. | `""` |
|
||||
| `kerberoshub.api.slack.hook` | Slack integration hook url. | `""` |
|
||||
| `kerberoshub.api.slack.username` | Slack integration username. | `""` |
|
||||
| `kerberoshub.api.elasticsearch.enabled` | Elasticsearch for storing events coming from the Kerberos Hub API, `'true'` or `'false'` | `""` |
|
||||
| `kerberoshub.api.elasticsearch.protocol` | Elasticsearch protocol, `'http'` or `'https'`. | `""` |
|
||||
| `kerberoshub.api.elasticsearch.host` | Elasticsearch host. | `""` |
|
||||
| `kerberoshub.api.elasticsearch.port` | Elasticsearch port. | `""` |
|
||||
| `kerberoshub.api.elasticsearch.index` | Elasticsearch index which is used to store the events. | `""` |
|
||||
| `kerberoshub.api.language` | The language of Kerberos Hub API responses, error messages will be communicated in the specified language. | `"english"` |
|
||||
| `kerberoshub.api.fallbackLanguage` | The fallback language, if a specific translation is not available. | `"english"` |
|
||||
| `kerberoshub.api.aws.region` | AWS region used by the Hub API legacy S3 integration. | `"xxx"` |
|
||||
| `kerberoshub.api.aws.bucket` | AWS S3 bucket used by the Hub API legacy S3 integration. | `"xxx"` |
|
||||
| `kerberoshub.api.aws.accessKey` | Access key for `kerberoshub.api.aws`. | `"xxx"` |
|
||||
| `kerberoshub.api.aws.secretKey` | Secret key for `kerberoshub.api.aws`. | `"xxx"` |
|
||||
| `kerberoshub.api.stripe.privateKey` | Private key for `kerberoshub.api.stripe`. | `"xxx"` |
|
||||
| `kerberoshub.api.slack.enabled` | Slack integration for sending events and notifications coming from the Kerberos Hub API, `'true'` or `'false'`. | `"true"` |
|
||||
| `kerberoshub.api.slack.hook` | Slack integration hook url. | `"yourslackhook"` |
|
||||
| `kerberoshub.api.slack.username` | Slack integration username. | `"Kerberos Hub"` |
|
||||
| `kerberoshub.api.elasticsearch.enabled` | Elasticsearch for storing events coming from the Kerberos Hub API, `'true'` or `'false'` | `"false"` |
|
||||
| `kerberoshub.api.elasticsearch.protocol` | Elasticsearch protocol, `'http'` or `'https'`. | `"http"` |
|
||||
| `kerberoshub.api.elasticsearch.host` | Elasticsearch host. | `"yourelasticsearchinstance.com"` |
|
||||
| `kerberoshub.api.elasticsearch.port` | Elasticsearch port. | `"9200"` |
|
||||
| `kerberoshub.api.elasticsearch.index` | Elasticsearch index which is used to store the events. | `"kerberos-cloud"` |
|
||||
| `kerberoshub.api.elasticsearch.username` | Elasticsearch username. | `""` |
|
||||
| `kerberoshub.api.elasticsearch.password` | Elasticsearch password. | `""` |
|
||||
| `kerberoshub.api.sso.redirectUrl` | The OIC redirectUrl, once the authentication is validated. | `""` |
|
||||
@@ -156,55 +165,30 @@ Below all configuration options and parameters are listed.
|
||||
| `kerberoshub.api.sso.clientVerificationId` | Optional client verification ID used for SSO chaining scenarios. | `""` |
|
||||
| `kerberoshub.api.sso.extraHeaders` | Additional headers appended to outbound SSO provider requests. | `""` |
|
||||
| `kerberoshub.api.sso.extraHeaders.value` | Header value for each configured SSO extra header entry. | `""` |
|
||||
| `kerberoshub.frontend.repository` | The Docker registry where the Kerberos Hub frontend is hosted. | `""` |
|
||||
| `kerberoshub.frontend.pullPolicy` | The Docker registry pull policy. | `""` |
|
||||
| `kerberoshub.frontend.tag` | The Docker image tag/version. | `""` |
|
||||
| `kerberoshub.frontend.replicas` | The number of pods/replicas running for the Kerberos Hub frontend deployment. | `""` |
|
||||
| `kerberoshub.frontend.logLevel` | Log verbosity level for `kerberoshub.frontend`. | `""` |
|
||||
| `kerberoshub.frontend.schema` | The protocol to serve the Kerberos Hub frontend, `'http'` or `'https'`. | `""` |
|
||||
| `kerberoshub.frontend.url` | The Kerberos Hub frontend ingress to access the frontend. | `""` |
|
||||
| `kerberoshub.frontend.resources.requests.memory` | Memory request for `kerberoshub.frontend`. | `""` |
|
||||
| `kerberoshub.frontend.resources.requests.cpu` | CPU request for `kerberoshub.frontend`. | `""` |
|
||||
| `kerberoshub.frontend.tls` | Bring your own TLS certificates for Kerberos Hub frontend ingress. | `""` |
|
||||
| `kerberoshub.frontend.repository` | The Docker registry where the Kerberos Hub frontend is hosted. | `"ghcr.io/uug-ai/hub-frontend"` |
|
||||
| `kerberoshub.frontend.pullPolicy` | The Docker registry pull policy. | `"IfNotPresent"` |
|
||||
| `kerberoshub.frontend.tag` | The Docker image tag/version. | `"v1.9.11"` |
|
||||
| `kerberoshub.frontend.replicas` | The number of pods/replicas running for the Kerberos Hub frontend deployment. | `2` |
|
||||
| `kerberoshub.frontend.logLevel` | Log verbosity level for `kerberoshub.frontend`. | `"info"` |
|
||||
| `kerberoshub.frontend.schema` | The protocol to serve the Kerberos Hub frontend, `'http'` or `'https'`. | `"https"` |
|
||||
| `kerberoshub.frontend.url` | The Kerberos Hub frontend ingress to access the frontend. | `"yourdomain.com"` |
|
||||
| `kerberoshub.frontend.resources.requests.memory` | Memory request for `kerberoshub.frontend`. | `"50Mi"` |
|
||||
| `kerberoshub.frontend.resources.requests.cpu` | CPU request for `kerberoshub.frontend`. | `"50m"` |
|
||||
| `kerberoshub.frontend.resources.limits.memory` | Memory limit for `kerberoshub.frontend`. | `"50Mi"` |
|
||||
| `kerberoshub.frontend.resources.limits.cpu` | CPU limit for `kerberoshub.frontend`. | `"50m"` |
|
||||
| `kerberoshub.frontend.tls` | Bring your own TLS certificates for Kerberos Hub frontend ingress. | `<list>` |
|
||||
| `kerberoshub.frontend.tls.secretName` | Kubernetes Secret name used by `kerberoshub.frontend.tls`. | `""` |
|
||||
| `kerberoshub.frontend.mixpanel.apikey` | No longer used. | `""` |
|
||||
| `kerberoshub.frontend.sentry.url` | No longer used. | `""` |
|
||||
| `kerberoshub.frontend.mixpanel.apikey` | No longer used. | `"xxx"` |
|
||||
| `kerberoshub.frontend.sentry.url` | No longer used. | `"https://xxx@sentry.io/xxx"` |
|
||||
| `kerberoshub.frontend.stripe.publicKey` | Public key for `kerberoshub.frontend.stripe`. | `""` |
|
||||
| `kerberoshub.frontend.googlemaps.apikey` | Within Kerberos Hub frontend a couple of maps are being used, the google maps is leveraged for that. | `""` |
|
||||
| `kerberoshub.frontend.zendesk.url` | No longer used. | `""` |
|
||||
| `kerberoshub.frontend.posthog.key` | The API key retrieved from the Posthog instance. | `""` |
|
||||
| `kerberoshub.frontend.posthog.url` | Posthog's endpoint (http/https). | `""` |
|
||||
| `kerberoshub.frontend.hideAddAgent` | Configuration value for `kerberoshub.frontend.hideAddAgent`. | `""` |
|
||||
| `kerberoshub.frontend.multiTenant` | Configuration value for `kerberoshub.frontend.multiTenant`. | `""` |
|
||||
| `kerberoshub.frontend.title` | Title text used for `kerberoshub.frontend`. | `""` |
|
||||
| `kerberoshub.frontend.logo` | The logo being used in the Kerberos Hub frontend, set to 'custom' if you want to mount your own stylesheet. | `""` |
|
||||
| `kerberoshub.frontend.floorPlanName` | Configuration value for `kerberoshub.frontend.floorPlanName`. | `""` |
|
||||
| `kerberoshub.frontend.sitesName` | Configuration value for `kerberoshub.frontend.sitesName`. | `""` |
|
||||
| `kerberoshub.frontend.sitesDescription` | Custom description text for `sites` in the frontend UI. | `""` |
|
||||
| `kerberoshub.frontend.groupsName` | Configuration value for `kerberoshub.frontend.groupsName`. | `""` |
|
||||
| `kerberoshub.frontend.groupsDescription` | Custom description text for `groups` in the frontend UI. | `""` |
|
||||
| `kerberoshub.frontend.siteGroupName` | Configuration value for `kerberoshub.frontend.siteGroupName`. | `""` |
|
||||
| `kerberoshub.frontend.siteGroupDescription` | Custom description text for `site group` in the frontend UI. | `""` |
|
||||
| `kerberoshub.frontend.deviceGroupName` | Configuration value for `kerberoshub.frontend.deviceGroupName`. | `""` |
|
||||
| `kerberoshub.frontend.deviceGroupDescription` | Custom description text for `device group` in the frontend UI. | `""` |
|
||||
| `kerberoshub.frontend.markersName` | Configuration value for `kerberoshub.frontend.markersName`. | `""` |
|
||||
| `kerberoshub.frontend.eventsName` | Configuration value for `kerberoshub.frontend.eventsName`. | `""` |
|
||||
| `kerberoshub.frontend.loginDescription` | Custom description text for `login` in the frontend UI. | `""` |
|
||||
| `kerberoshub.frontend.loginCopyright` | Configuration value for `kerberoshub.frontend.loginCopyright`. | `""` |
|
||||
| `kerberoshub.frontend.dashboardTitle` | Custom title text for `dashboard` in the frontend UI. | `""` |
|
||||
| `kerberoshub.frontend.dashboardSubTitle` | Custom title text for `dashboard sub` in the frontend UI. | `""` |
|
||||
| `kerberoshub.frontend.latestEventsTitle` | Custom title text for `latest events` in the frontend UI. | `""` |
|
||||
| `kerberoshub.frontend.latestEventsSubTitle` | Custom title text for `latest events sub` in the frontend UI. | `""` |
|
||||
| `kerberoshub.frontend.dayTitle` | Custom title text for `day` in the frontend UI. | `""` |
|
||||
| `kerberoshub.frontend.daySubTitle` | Custom title text for `day sub` in the frontend UI. | `""` |
|
||||
| `kerberoshub.frontend.livestreamTitle` | Custom title text for `livestream` in the frontend UI. | `""` |
|
||||
| `kerberoshub.frontend.livestreamSubTitle` | Custom title text for `livestream sub` in the frontend UI. | `""` |
|
||||
| `kerberoshub.frontend.mediaTitle` | Custom title text for `media` in the frontend UI. | `""` |
|
||||
| `kerberoshub.frontend.mediaSubTitle` | Custom title text for `media sub` in the frontend UI. | `""` |
|
||||
| `kerberoshub.frontend.cpuUsageDescription` | Custom description text for `cpu usage` in the frontend UI. | `""` |
|
||||
| `kerberoshub.frontend.framesPerSecondDescription` | Custom description text for `frames per second` in the frontend UI. | `""` |
|
||||
| `kerberoshub.frontend.mlaUtilizationDescription` | Custom description text for `mla utilization` in the frontend UI. | `""` |
|
||||
| `kerberoshub.frontend.objectsDetectedDescription` | Custom description text for `objects detected` in the frontend UI. | `""` |
|
||||
| `kerberoshub.frontend.googlemaps.apikey` | Within Kerberos Hub frontend a couple of maps are being used, the google maps is leveraged for that. | `"xxxx"` |
|
||||
| `kerberoshub.frontend.zendesk.url` | No longer used. | `"yourdomain.zendesk.com"` |
|
||||
| `kerberoshub.frontend.posthog.key` | The API key retrieved from the Posthog instance. | `"xxx"` |
|
||||
| `kerberoshub.frontend.posthog.url` | Posthog's endpoint (http/https). | `"https://posthog.domain.com"` |
|
||||
| `kerberoshub.frontend.hideAddAgent` | Configuration value for `kerberoshub.frontend.hideAddAgent`. | `"false"` |
|
||||
| `kerberoshub.frontend.multiTenant` | Configuration value for `kerberoshub.frontend.multiTenant`. | `false` |
|
||||
| `kerberoshub.frontend.title` | Title text used for `kerberoshub.frontend`. | `"Kerberos Hub - Video surveillance as it should be"` |
|
||||
| `kerberoshub.frontend.logo` | The logo being used in the Kerberos Hub frontend, set to 'custom' if you want to mount your own stylesheet. | `"custom"` |
|
||||
| `kerberoshub.frontend.navigationLinkTitle1` | Custom navigation item (title 1) | `""` |
|
||||
| `kerberoshub.frontend.navigationLinkUrl1` | Custom navigation item (url 1) | `""` |
|
||||
| `kerberoshub.frontend.navigationLinkTitle2` | Custom navigation item (title 2) | `""` |
|
||||
@@ -215,202 +199,242 @@ Below all configuration options and parameters are listed.
|
||||
| `kerberoshub.frontend.navigationLinkUrl4` | Custom navigation item (url 4) | `""` |
|
||||
| `kerberoshub.frontend.navigationLinkTitle5` | Custom navigation item (title 5) | `""` |
|
||||
| `kerberoshub.frontend.navigationLinkUrl5` | Custom navigation item (url 5) | `""` |
|
||||
| `kerberoshub.frontend.caseFilterAssigneesDefault` | Default assignee filter behavior for cases in the frontend. | `""` |
|
||||
| `kerberoshub.frontend.features.case.enabled` | Enable or disable the case feature in the frontend. | `""` |
|
||||
| `kerberoshub.frontend.features.darkModeEnabled` | Enable or disable dark mode in the frontend. | `""` |
|
||||
| `kerberoshub.frontend.features.landingPage` | Frontend landing page configuration. | `""` |
|
||||
| `kerberoshub.frontend.features.map.tileUrlLight` | Tile URL used by the map in light mode. | `""` |
|
||||
| `kerberoshub.frontend.features.map.tileUrlDark` | Tile URL used by the map in dark mode. | `""` |
|
||||
| `kerberoshub.frontend.features.map.attribution` | Attribution text displayed on the map tiles. | `""` |
|
||||
| `kerberoshub.frontend.features.liveview.defaultStreamMode` | Liveview behavior setting: `defaultStreamMode`. | `""` |
|
||||
| `kerberoshub.frontend.features.liveview.paginationEnabled` | Liveview behavior setting: `paginationEnabled`. | `""` |
|
||||
| `kerberoshub.frontend.features.liveview.emptyByDefault` | Liveview behavior setting: `emptyByDefault`. | `""` |
|
||||
| `kerberoshub.frontend.features.liveview.maxStreams` | Liveview behavior setting: `maxStreams`. | `""` |
|
||||
| `kerberoshub.frontend.features.devices.hideAgent` | Hide agent controls in the devices section of the frontend. | `""` |
|
||||
| `kerberoshub.frontend.features.media.filter.date.enabled` | Enable or disable `kerberoshub.frontend.features.media.filter.date`. | `""` |
|
||||
| `kerberoshub.frontend.features.media.filter.sites.enabled` | Enable or disable `kerberoshub.frontend.features.media.filter.sites`. | `""` |
|
||||
| `kerberoshub.frontend.features.media.filter.groups.enabled` | Enable or disable `kerberoshub.frontend.features.media.filter.groups`. | `""` |
|
||||
| `kerberoshub.frontend.features.media.filter.devices.enabled` | Enable or disable `kerberoshub.frontend.features.media.filter.devices`. | `""` |
|
||||
| `kerberoshub.frontend.features.media.filter.objectDetection.enabled` | Enable or disable `kerberoshub.frontend.features.media.filter.objectDetection`. | `""` |
|
||||
| `kerberoshub.frontend.features.media.filter.star.enabled` | Enable or disable `kerberoshub.frontend.features.media.filter.star`. | `""` |
|
||||
| `kerberoshub.frontend.features.media.filter.region.enabled` | Enable or disable `kerberoshub.frontend.features.media.filter.region`. | `""` |
|
||||
| `kerberoshub.frontend.features.media.filter.sort.enabled` | Enable or disable `kerberoshub.frontend.features.media.filter.sort`. | `""` |
|
||||
| `kerberoshub.frontend.features.media.filter.category.enabled` | Enable or disable `kerberoshub.frontend.features.media.filter.category`. | `""` |
|
||||
| `kerberoshub.frontend.features.media.filter.markers.enabled` | Enable or disable `kerberoshub.frontend.features.media.filter.markers`. | `""` |
|
||||
| `kerberoshub.frontend.features.media.filter.events.enabled` | Enable or disable `kerberoshub.frontend.features.media.filter.events`. | `""` |
|
||||
| `kerberoshub.frontend.features.media.filter.tags.enabled` | Enable or disable `kerberoshub.frontend.features.media.filter.tags`. | `""` |
|
||||
| `kerberoshub.frontend.features.floorplan.enabled` | Enable or disable `kerberoshub.frontend.features.floorplan`. | `""` |
|
||||
| `kerberoshub.frontend.features.floorplan.colorDeviceActive` | Color customization for `floorplan` in the frontend. | `""` |
|
||||
| `kerberoshub.frontend.features.floorplan.colorDeviceInactive` | Color customization for `floorplan` in the frontend. | `""` |
|
||||
| `kerberoshub.frontend.features.floorplan.colorDeviceIdle` | Color customization for `floorplan` in the frontend. | `""` |
|
||||
| `kerberoshub.frontend.features.floorplan.colorDeviceMotion` | Color customization for `floorplan` in the frontend. | `""` |
|
||||
| `kerberoshub.frontend.features.floorplan.colorLiveViewControlActive` | Color customization for `floorplan` in the frontend. | `""` |
|
||||
| `kerberoshub.frontend.features.floorplan.colorLiveViewControlMotion` | Color customization for `floorplan` in the frontend. | `""` |
|
||||
| `kerberoshub.frontend.features.floorplan.colorFloorPlanLabelText` | Color customization for `floorplan` in the frontend. | `""` |
|
||||
| `kerberoshub.frontend.features.floorplan.colorFloorPlanLabelBackground` | Color customization for `floorplan` in the frontend. | `""` |
|
||||
| `kerberoshub.frontend.features.floorplan.colorDeviceMarkerBorder` | Color customization for `floorplan` in the frontend. | `""` |
|
||||
| `kerberoshub.frontend.features.floorplan.colorTrackBox` | Color customization for `floorplan` in the frontend. | `""` |
|
||||
| `kerberoshub.frontend.features.floorplan.colorTrackBoxHover` | Color customization for `floorplan` in the frontend. | `""` |
|
||||
| `kerberoshub.frontend.features.floorplan.colorTrackBoxDrawing` | Color customization for `floorplan` in the frontend. | `""` |
|
||||
| `kerberoshub.frontend.features.floorplan.colorTrackBoxControlsDelete` | Color customization for `floorplan` in the frontend. | `""` |
|
||||
| `kerberoshub.frontend.features.faceRedaction.enabled` | Enable or disable `kerberoshub.frontend.features.faceRedaction`. | `""` |
|
||||
| `kerberoshub.support.enabled` | Enable or disable in-app support features. | `""` |
|
||||
| `kerberoshub.oauth2Proxy.enabled` | Enable or disable `kerberoshub.oauth2Proxy`. | `""` |
|
||||
| `kerberoshub.oauth2Proxy.github.clientId` | Client ID used by `kerberoshub.oauth2Proxy.github`. | `""` |
|
||||
| `kerberoshub.oauth2Proxy.github.clientSecret` | Client secret used by `kerberoshub.oauth2Proxy.github`. | `""` |
|
||||
| `kerberoshub.oauth2Proxy.github.cookieSecret` | Cookie secret used by `kerberoshub.oauth2Proxy.github`. | `""` |
|
||||
| `kerberoshub.oauth2Proxy.github.organization` | Organization value used by `kerberoshub.oauth2Proxy.github`. | `""` |
|
||||
| `kerberoshub.oauth2Proxy.github.team` | Team value used by `kerberoshub.oauth2Proxy.github`. | `""` |
|
||||
| `kerberoshub.cleanup.repository` | The Docker container that is responsible for cleaning up the Kerberos Hub API content and related MongoDB collections. | `""` |
|
||||
| `kerberoshub.cleanup.pullPolicy` | The Docker registry pull policy. | `""` |
|
||||
| `kerberoshub.cleanup.tag` | The Docker image tag/version. | `""` |
|
||||
| `kerberoshub.cleanup.replicas` | Number of replicas for `kerberoshub.cleanup`. | `""` |
|
||||
| `kerberoshub.cleanup.logLevel` | Log verbosity level for `kerberoshub.cleanup`. | `""` |
|
||||
| `kerberoshub.cleanup.maxDays` | Maximum age (in days) of data retained by the cleanup process. | `""` |
|
||||
| `kerberoshub.cleanup.resources.requests.memory` | Memory request for `kerberoshub.cleanup`. | `""` |
|
||||
| `kerberoshub.cleanup.resources.requests.cpu` | CPU request for `kerberoshub.cleanup`. | `""` |
|
||||
| `kerberoshub.monitordevice.repository` | The monitoring microservice, following up the status of your cameras and Kerberos Agents. | `""` |
|
||||
| `kerberoshub.monitordevice.pullPolicy` | The Docker registry pull policy. | `""` |
|
||||
| `kerberoshub.monitordevice.tag` | The Docker image tag/version. | `""` |
|
||||
| `kerberoshub.monitordevice.replicas` | Number of replicas for `kerberoshub.monitordevice`. | `""` |
|
||||
| `kerberoshub.monitordevice.logLevel` | Log verbosity level for `kerberoshub.monitordevice`. | `""` |
|
||||
| `kerberoshub.monitordevice.resources.requests.memory` | Memory request for `kerberoshub.monitordevice`. | `""` |
|
||||
| `kerberoshub.monitordevice.resources.requests.cpu` | CPU request for `kerberoshub.monitordevice`. | `""` |
|
||||
| `kerberoshub.reactivate.repository` | Container image repository for `kerberoshub.reactivate`. | `""` |
|
||||
| `kerberoshub.reactivate.pullPolicy` | Image pull policy for `kerberoshub.reactivate`. | `""` |
|
||||
| `kerberoshub.reactivate.tag` | Container image tag/version for `kerberoshub.reactivate`. | `""` |
|
||||
| `kerberoshub.reactivate.replicas` | Number of replicas for `kerberoshub.reactivate`. | `""` |
|
||||
| `kerberoshub.reactivate.logLevel` | Log verbosity level for `kerberoshub.reactivate`. | `""` |
|
||||
| `kerberoshub.reactivate.resources.requests.memory` | Memory request for `kerberoshub.reactivate`. | `""` |
|
||||
| `kerberoshub.reactivate.resources.requests.cpu` | CPU request for `kerberoshub.reactivate`. | `""` |
|
||||
| `kerberoshub.forwarder.enabled` | Enable or disable the Hub forwarder component. | `""` |
|
||||
| `kerberoshub.proxy.repository` | Container image repository for `kerberoshub.proxy`. | `""` |
|
||||
| `kerberoshub.proxy.pullPolicy` | Image pull policy for `kerberoshub.proxy`. | `""` |
|
||||
| `kerberoshub.proxy.tag` | Container image tag/version for `kerberoshub.proxy`. | `""` |
|
||||
| `kerberoshub.proxy.replicas` | Number of replicas for `kerberoshub.proxy`. | `""` |
|
||||
| `kerberoshub.proxy.logLevel` | Log verbosity level for `kerberoshub.proxy`. | `""` |
|
||||
| `kerberoshub.proxy.resources.requests.memory` | Memory request for `kerberoshub.proxy`. | `""` |
|
||||
| `kerberoshub.proxy.resources.requests.cpu` | CPU request for `kerberoshub.proxy`. | `""` |
|
||||
| `kerberospipeline.event.repository` | The [event orchestration](https://doc.kerberos.io/hub/pipeline/#orchestrator) microservice. | `""` |
|
||||
| `kerberospipeline.event.pullPolicy` | The Docker registry pull policy. | `""` |
|
||||
| `kerberospipeline.event.tag` | The Docker image tag/version. | `""` |
|
||||
| `kerberospipeline.event.replicas` | Number of replicas for `kerberospipeline.event`. | `""` |
|
||||
| `kerberospipeline.event.logLevel` | Log verbosity level for `kerberospipeline.event`. | `""` |
|
||||
| `kerberospipeline.event.resources.requests.memory` | Memory request for `kerberospipeline.event`. | `""` |
|
||||
| `kerberospipeline.event.resources.requests.cpu` | CPU request for `kerberospipeline.event`. | `""` |
|
||||
| `kerberospipeline.monitor.repository` | The [monitoring microservice](https://doc.kerberos.io/hub/pipeline/#monitoring), calculating metrics of incoming messages. | `""` |
|
||||
| `kerberospipeline.monitor.pullPolicy` | The Docker registry pull policy. | `""` |
|
||||
| `kerberospipeline.monitor.tag` | The Docker image tag/version. | `""` |
|
||||
| `kerberospipeline.monitor.replicas` | Number of replicas for `kerberospipeline.monitor`. | `""` |
|
||||
| `kerberospipeline.monitor.resources.requests.memory` | Memory request for `kerberospipeline.monitor`. | `""` |
|
||||
| `kerberospipeline.monitor.resources.requests.cpu` | CPU request for `kerberospipeline.monitor`. | `""` |
|
||||
| `kerberospipeline.sequence.repository` | The [sequencer microservice](https://doc.kerberos.io/hub/pipeline/#sequencer), grouping recordings in chunks/groups. | `""` |
|
||||
| `kerberospipeline.sequence.pullPolicy` | The Docker registry pull policy. | `""` |
|
||||
| `kerberospipeline.sequence.tag` | The Docker image tag/version. | `""` |
|
||||
| `kerberospipeline.sequence.replicas` | Number of replicas for `kerberospipeline.sequence`. | `""` |
|
||||
| `kerberospipeline.sequence.resources.requests.memory` | Memory request for `kerberospipeline.sequence`. | `""` |
|
||||
| `kerberospipeline.sequence.resources.requests.cpu` | CPU request for `kerberospipeline.sequence`. | `""` |
|
||||
| `kerberospipeline.throttler.repository` | The [throttler microservice](https://doc.kerberos.io/hub/pipeline/#throttler), throttling events. | `""` |
|
||||
| `kerberospipeline.throttler.pullPolicy` | The Docker registry pull policy. | `""` |
|
||||
| `kerberospipeline.throttler.tag` | The Docker image tag/version. | `""` |
|
||||
| `kerberospipeline.throttler.replicas` | Number of replicas for `kerberospipeline.throttler`. | `""` |
|
||||
| `kerberospipeline.throttler.logLevel` | Log verbosity level for `kerberospipeline.throttler`. | `""` |
|
||||
| `kerberospipeline.throttler.resources.requests.memory` | Memory request for `kerberospipeline.throttler`. | `""` |
|
||||
| `kerberospipeline.throttler.resources.requests.cpu` | CPU request for `kerberospipeline.throttler`. | `""` |
|
||||
| `kerberospipeline.notify.repository` | The [notification microservice](https://doc.kerberos.io/hub/pipeline/#notification), sending notifications on events. | `""` |
|
||||
| `kerberospipeline.notify.pullPolicy` | The Docker registry pull policy. | `""` |
|
||||
| `kerberospipeline.notify.tag` | The Docker image tag/version. | `""` |
|
||||
| `kerberospipeline.notify.replicas` | Number of replicas for `kerberospipeline.notify`. | `""` |
|
||||
| `kerberospipeline.notify.logLevel` | Log verbosity level for `kerberospipeline.notify`. | `""` |
|
||||
| `kerberospipeline.notify.resources.requests.memory` | Memory request for `kerberospipeline.notify`. | `""` |
|
||||
| `kerberospipeline.notify.resources.requests.cpu` | CPU request for `kerberospipeline.notify`. | `""` |
|
||||
| `kerberospipeline.notifyTest.repository` | The notification service for testing, the different channels. | `""` |
|
||||
| `kerberospipeline.notifyTest.pullPolicy` | The Docker registry pull policy. | `""` |
|
||||
| `kerberospipeline.notifyTest.tag` | The Docker image tag/version. | `""` |
|
||||
| `kerberospipeline.notifyTest.replicas` | Number of replicas for `kerberospipeline.notifyTest`. | `""` |
|
||||
| `kerberospipeline.notifyTest.resources.requests.memory` | Memory request for `kerberospipeline.notifyTest`. | `""` |
|
||||
| `kerberospipeline.notifyTest.resources.requests.cpu` | CPU request for `kerberospipeline.notifyTest`. | `""` |
|
||||
| `kerberospipeline.analysis.repository` | The [analysis microservices](https://doc.kerberos.io/hub/pipeline/#analyser) which executed specific analysis in parallel. | `""` |
|
||||
| `kerberospipeline.analysis.pullPolicy` | The Docker registry pull policy. | `""` |
|
||||
| `kerberospipeline.analysis.tag` | The Docker image tag/version. | `""` |
|
||||
| `kerberospipeline.analysis.replicas` | Number of replicas for `kerberospipeline.analysis`. | `""` |
|
||||
| `kerberospipeline.analysis.logLevel` | Log verbosity level for `kerberospipeline.analysis`. | `""` |
|
||||
| `kerberospipeline.analysis.resources.requests.memory` | Memory request for `kerberospipeline.analysis`. | `""` |
|
||||
| `kerberospipeline.analysis.resources.requests.cpu` | CPU request for `kerberospipeline.analysis`. | `""` |
|
||||
| `kerberospipeline.dominantColor.repository` | The dominant color microservices is computing a top 3 color histogram. | `""` |
|
||||
| `kerberospipeline.dominantColor.pullPolicy` | The Docker registry pull policy. | `""` |
|
||||
| `kerberospipeline.dominantColor.tag` | The Docker image tag/version. | `""` |
|
||||
| `kerberospipeline.dominantColor.replicas` | Number of replicas for `kerberospipeline.dominantColor`. | `""` |
|
||||
| `kerberospipeline.dominantColor.logLevel` | Log verbosity level for `kerberospipeline.dominantColor`. | `""` |
|
||||
| `kerberospipeline.dominantColor.resources.requests.memory` | Memory request for `kerberospipeline.dominantColor`. | `""` |
|
||||
| `kerberospipeline.dominantColor.resources.requests.cpu` | CPU request for `kerberospipeline.dominantColor`. | `""` |
|
||||
| `kerberospipeline.dominantColor.resources.limits.memory` | Memory limit for `kerberospipeline.dominantColor`. | `""` |
|
||||
| `kerberospipeline.dominantColor.resources.limits.cpu` | CPU limit for `kerberospipeline.dominantColor`. | `""` |
|
||||
| `kerberospipeline.thumbnail.repository` | The thumbnail microservices generated a thumbnail for a recordings. | `""` |
|
||||
| `kerberospipeline.thumbnail.pullPolicy` | The Docker registry pull policy. | `""` |
|
||||
| `kerberospipeline.thumbnail.tag` | The Docker image tag/version. | `""` |
|
||||
| `kerberospipeline.thumbnail.replicas` | Number of replicas for `kerberospipeline.thumbnail`. | `""` |
|
||||
| `kerberospipeline.thumbnail.logLevel` | Log verbosity level for `kerberospipeline.thumbnail`. | `""` |
|
||||
| `kerberospipeline.thumbnail.quality` | Configuration value for `kerberospipeline.thumbnail.quality`. | `""` |
|
||||
| `kerberospipeline.thumbnail.width` | Configuration value for `kerberospipeline.thumbnail.width`. | `""` |
|
||||
| `kerberospipeline.thumbnail.height` | Configuration value for `kerberospipeline.thumbnail.height`. | `""` |
|
||||
| `kerberospipeline.thumbnail.kerberosvault.enabled` | Enable or disable `kerberospipeline.thumbnail.kerberosvault`. | `""` |
|
||||
| `kerberospipeline.thumbnail.resources.requests.memory` | Memory request for `kerberospipeline.thumbnail`. | `""` |
|
||||
| `kerberospipeline.thumbnail.resources.requests.cpu` | CPU request for `kerberospipeline.thumbnail`. | `""` |
|
||||
| `kerberospipeline.thumbnail.resources.limits.memory` | Memory limit for `kerberospipeline.thumbnail`. | `""` |
|
||||
| `kerberospipeline.thumbnail.resources.limits.cpu` | CPU limit for `kerberospipeline.thumbnail`. | `""` |
|
||||
| `kerberospipeline.counting.repository` | The counting microservices computes objects passing different line segments. | `""` |
|
||||
| `kerberospipeline.counting.pullPolicy` | The Docker registry pull policy. | `""` |
|
||||
| `kerberospipeline.counting.tag` | The Docker image tag/version. | `""` |
|
||||
| `kerberospipeline.counting.replicas` | Number of replicas for `kerberospipeline.counting`. | `""` |
|
||||
| `kerberospipeline.counting.logLevel` | Log verbosity level for `kerberospipeline.counting`. | `""` |
|
||||
| `kerberospipeline.counting.resources.requests.memory` | Memory request for `kerberospipeline.counting`. | `""` |
|
||||
| `kerberospipeline.counting.resources.requests.cpu` | CPU request for `kerberospipeline.counting`. | `""` |
|
||||
| `kerberospipeline.sprite.enabled` | Enable or disable `kerberospipeline.sprite`. | `""` |
|
||||
| `kerberospipeline.sprite.repository` | Container image repository for `kerberospipeline.sprite`. | `""` |
|
||||
| `kerberospipeline.sprite.pullPolicy` | Image pull policy for `kerberospipeline.sprite`. | `""` |
|
||||
| `kerberospipeline.sprite.tag` | Container image tag/version for `kerberospipeline.sprite`. | `""` |
|
||||
| `kerberospipeline.sprite.replicas` | Number of replicas for `kerberospipeline.sprite`. | `""` |
|
||||
| `kerberospipeline.sprite.logLevel` | Log verbosity level for `kerberospipeline.sprite`. | `""` |
|
||||
| `kerberospipeline.sprite.interval` | Configuration value for `kerberospipeline.sprite.interval`. | `""` |
|
||||
| `kerberospipeline.sprite.width` | Configuration value for `kerberospipeline.sprite.width`. | `""` |
|
||||
| `kerberospipeline.sprite.height` | Configuration value for `kerberospipeline.sprite.height`. | `""` |
|
||||
| `kerberospipeline.sprite.resources.requests.memory` | Memory request for `kerberospipeline.sprite`. | `""` |
|
||||
| `kerberospipeline.sprite.resources.requests.cpu` | CPU request for `kerberospipeline.sprite`. | `""` |
|
||||
| `kerberospipeline.sprite.resources.limits.memory` | Memory limit for `kerberospipeline.sprite`. | `""` |
|
||||
| `kerberospipeline.sprite.resources.limits.cpu` | CPU limit for `kerberospipeline.sprite`. | `""` |
|
||||
| `kerberospipeline.export.repository` | Container image repository for `kerberospipeline.export`. | `""` |
|
||||
| `kerberospipeline.export.pullPolicy` | Image pull policy for `kerberospipeline.export`. | `""` |
|
||||
| `kerberospipeline.export.tag` | Container image tag/version for `kerberospipeline.export`. | `""` |
|
||||
| `kerberospipeline.export.replicas` | Number of replicas for `kerberospipeline.export`. | `""` |
|
||||
| `kerberospipeline.export.logLevel` | Log verbosity level for `kerberospipeline.export`. | `""` |
|
||||
| `kerberospipeline.export.resources.requests.memory` | Memory request for `kerberospipeline.export`. | `""` |
|
||||
| `kerberospipeline.export.resources.requests.cpu` | CPU request for `kerberospipeline.export`. | `""` |
|
||||
| `email.provider` | The email service provider for sending out messages over email , use `'mailgun'` or `'smtp'`. | `""` |
|
||||
| `email.from` | The email address that is sending messages in name of, by default `'support@yourdomain.com'`. | `""` |
|
||||
| `email.displayName` | The display name that is sending messages in name of, by default `'yourdomain.com'` | `""` |
|
||||
| `email.mailgun.domain` | While using `mailgun` as email service provider, you will need to provide your Mailgun domain. | `""` |
|
||||
| `email.mailgun.apikey` | Mailgun API key (lowercase variant) used when provider is `mailgun`. | `""` |
|
||||
| `email.smtp.server` | While using `smtp` as email service provider, use the SMTP server. | `""` |
|
||||
| `email.smtp.port` | SMTP port specified by your SMTP server, by default `'456'`. | `""` |
|
||||
| `email.smtp.username` | SMTP username. | `""` |
|
||||
| `email.smtp.password` | SMTP password. | `""` |
|
||||
| `email.templates.welcome` | The template which is send when a new user registered on the platform (`IS_PRIVATE='false'`), by default `'disabled'`. | `""` |
|
||||
| `email.templates.welcomeTitle` | The welcome title use in the subject of the email. | `""` |
|
||||
| `email.templates.activate` | The template which is send when a user is required to activate his account , by default `'activate'`. | `""` |
|
||||
| `email.templates.activateTitle` | The activation title use in the subject of the email. | `""` |
|
||||
| `email.templates.forgot` | The template which is send when an account is requesting a forgot password, by default `'forgot'`. | `""` |
|
||||
| `email.templates.forgotTitle` | The forgot title use in the subject of the email. | `""` |
|
||||
| `email.templates.share` | Email template name/key for `share` notifications. | `""` |
|
||||
| `email.templates.shareTitle` | Email subject title for the `share` template. | `""` |
|
||||
| `email.templates.assignTask` | Email template name/key for `assign task` notifications. | `""` |
|
||||
| `email.templates.assignTaskTitle` | Email subject title for the `assign task` template. | `""` |
|
||||
| `email.templates.detection` | We use templates to send notifications, this allow you to bring your own `Mailgun` templates, by default `'detection'`. | `""` |
|
||||
| `email.templates.disabled` | The template which is send when an account is disabled due to reaching its upload limit, by default `'disabled'`. | `""` |
|
||||
| `email.templates.highupload` | The template which is send when an account is reaching a specific upload threshold, by default `'threshold'`. | `""` |
|
||||
| `email.templates.device` | The template which is send when a camera goes online or offline, by default `'device'`. | `""` |
|
||||
| `email.templates.alertTitle` | Email subject title for the `alert` template. | `""` |
|
||||
| `email.templates.deviceTitle` | Email subject title for the `device` template. | `""` |
|
||||
| `kerberoshub.frontend.caseFilterAssigneesDefault` | Default assignee filter behavior for cases in the frontend. | `"false"` |
|
||||
| `kerberoshub.frontend.features.case.enabled` | Enable or disable the case feature in the frontend. | `"true"` |
|
||||
| `kerberoshub.frontend.features.darkModeEnabled` | Enable or disable dark mode in the frontend. | `"true"` |
|
||||
| `kerberoshub.frontend.features.splashScreen.enabled` | Enable or disable the pre-bootstrap splash screen and reveal delay. | `"true"` |
|
||||
| `kerberoshub.frontend.features.landingPage` | Frontend landing page configuration. | `"/dashboard"` |
|
||||
| `kerberoshub.frontend.features.i18n.enabled` | Enable or disable the runtime language switcher in the front-end. When `"false"`, `defaultLanguage` is forced and users cannot change it. | `"true"` |
|
||||
| `kerberoshub.frontend.features.i18n.defaultLanguage` | Default language code used by the front-end (e.g. `en`, `nl`, `pl`, `tr`, `fr`, `sv`, `de`). | `"en"` |
|
||||
| `kerberoshub.frontend.features.workflows.enabled` | Enable or disable the workflows feature in the frontend. | `"false"` |
|
||||
| `kerberoshub.frontend.features.organisations.enabled` | Enable or disable all organisation feature flags. When empty, the child settings apply independently. | `""` |
|
||||
| `kerberoshub.frontend.features.organisations.switcherEnabled` | Enable or disable the organisation dropdown and switching. The current organisation remains visible when disabled. | `"false"` |
|
||||
| `kerberoshub.frontend.features.organisations.creationEnabled` | Enable or disable organisation creation. Requires organisation switching to be enabled. | `"false"` |
|
||||
| `kerberoshub.frontend.features.organisations.settingsEnabled` | Enable or disable the organisation identity link to organisation settings. | `"false"` |
|
||||
| `kerberoshub.frontend.features.projects.enabled` | Enable or disable all project feature flags. When empty, the child settings apply independently. | `""` |
|
||||
| `kerberoshub.frontend.features.projects.switcherEnabled` | Enable or disable the read-only project dropdown. | `"false"` |
|
||||
| `kerberoshub.frontend.features.projects.creationEnabled` | Reserved for the project creation UI. | `"false"` |
|
||||
| `kerberoshub.frontend.features.projects.settingsEnabled` | Reserved for the project settings UI. | `"false"` |
|
||||
| `kerberoshub.frontend.features.map.tileUrlLight` | Tile URL used by the map in light mode. | `"https://{s}.basemaps.cartocdn.com/rastertiles/voyager/{z}/{x}/{y}{r}.png"` |
|
||||
| `kerberoshub.frontend.features.map.tileUrlDark` | Tile URL used by the map in dark mode. | `"https://{s}.basemaps.cartocdn.com/dark_all/{z}/{x}/{y}{r}.png"` |
|
||||
| `kerberoshub.frontend.features.map.attribution` | Attribution text displayed on the map tiles. | `"© <a href='https://www.openstreetmap.org/copyright' target='_blank'>OpenStreetMap</a>"` |
|
||||
| `kerberoshub.frontend.features.liveview.defaultStreamMode` | Liveview behavior setting: `defaultStreamMode`. | `"SD"` |
|
||||
| `kerberoshub.frontend.features.liveview.liveStreamMode` | Transport backing LIVE mode: `webrtc`, `hls`, or `moq`. | `"webrtc"` |
|
||||
| `kerberoshub.frontend.features.liveview.hlsEnabled` | Offer HLS as a selectable LIVE transport. | `"true"` |
|
||||
| `kerberoshub.frontend.features.liveview.moqEnabled` | Offer MoQ as a selectable LIVE transport. | `"false"` |
|
||||
| `kerberoshub.frontend.features.liveview.moqRelayUrl` | WebTransport URL of the MoQ relay. | `"https://relay.uug.ai/anon"` |
|
||||
| `kerberoshub.frontend.features.liveview.moqBroadcastPrefix` | Prefix used to build MoQ broadcast names. | `"devices"` |
|
||||
| `kerberoshub.frontend.features.liveview.paginationMode` | Liveview behavior setting: `paginationMode` (`scroll`, `numbered` or `maxStreams`). | `"scroll"` |
|
||||
| `kerberoshub.frontend.features.liveview.pageSize` | Liveview behavior setting: `pageSize` (max streams shown per page in `numbered` mode). | `"6"` |
|
||||
| `kerberoshub.frontend.features.liveview.maxStreams` | Liveview behavior setting: `maxStreams`. | `"-1"` |
|
||||
| `kerberoshub.frontend.features.chart.colorChartSelectionFill` | Fill color for chart selection regions. | `"rgba(132, 86, 159, 0.07)"` |
|
||||
| `kerberoshub.frontend.features.chart.colorChartSelectionStroke` | Stroke color for chart selection regions. | `"rgba(132, 86, 159, 0.4)"` |
|
||||
| `kerberoshub.frontend.features.chart.colorChartGridStroke` | Stroke color for chart grid lines. | `"rgba(0, 106, 255, 0.18)"` |
|
||||
| `kerberoshub.frontend.features.devices.hideAgent` | Hide agent controls in the devices section of the frontend. | `"false"` |
|
||||
| `kerberoshub.frontend.features.media.filter.date.enabled` | Enable or disable `kerberoshub.frontend.features.media.filter.date`. | `"true"` |
|
||||
| `kerberoshub.frontend.features.media.filter.sites.enabled` | Enable or disable `kerberoshub.frontend.features.media.filter.sites`. | `"true"` |
|
||||
| `kerberoshub.frontend.features.media.filter.groups.enabled` | Enable or disable `kerberoshub.frontend.features.media.filter.groups`. | `"true"` |
|
||||
| `kerberoshub.frontend.features.media.filter.devices.enabled` | Enable or disable `kerberoshub.frontend.features.media.filter.devices`. | `"true"` |
|
||||
| `kerberoshub.frontend.features.media.filter.objectDetection.enabled` | Enable or disable `kerberoshub.frontend.features.media.filter.objectDetection`. | `"true"` |
|
||||
| `kerberoshub.frontend.features.media.filter.star.enabled` | Enable or disable `kerberoshub.frontend.features.media.filter.star`. | `"true"` |
|
||||
| `kerberoshub.frontend.features.media.filter.region.enabled` | Enable or disable `kerberoshub.frontend.features.media.filter.region`. | `"true"` |
|
||||
| `kerberoshub.frontend.features.media.filter.sort.enabled` | Enable or disable `kerberoshub.frontend.features.media.filter.sort`. | `"true"` |
|
||||
| `kerberoshub.frontend.features.media.filter.category.enabled` | Enable or disable `kerberoshub.frontend.features.media.filter.category`. | `"true"` |
|
||||
| `kerberoshub.frontend.features.media.filter.markers.enabled` | Enable or disable `kerberoshub.frontend.features.media.filter.markers`. | `"true"` |
|
||||
| `kerberoshub.frontend.features.media.filter.events.enabled` | Enable or disable `kerberoshub.frontend.features.media.filter.events`. | `"true"` |
|
||||
| `kerberoshub.frontend.features.liveview.defaultStreamMode` | Default live stream mode: `SD` or `HD`. | `"SD"` |lter.tags`. | `"true"` |
|
||||
| `kerberoshub.frontend.features.media.filter.defaultView` | Default view for the media page: `timeline` or `grid`. | `"timeline"` |
|
||||
| `kerberoshub.frontend.features.floorplan.enabled` | Enable or disable `kerberoshub.frontend.features.floorplan`. | `"true"` |
|
||||
| `kerberoshub.frontend.features.floorplan.colorDeviceActive` | Color customization for `floorplan` in the frontend. | `"hsla(131, 31%, 52%, 1)"` |
|
||||
| `kerberoshub.frontend.features.floorplan.colorDeviceInactive` | Color customization for `floorplan` in the frontend. | `"hsla(0, 3%, 41%, 1)"` |
|
||||
| `kerberoshub.frontend.features.floorplan.colorDeviceIdle` | Color customization for `floorplan` in the frontend. | `"hsla(47, 86%, 47%, 1)"` |
|
||||
| `kerberoshub.frontend.features.floorplan.colorDeviceMotion` | Color customization for `floorplan` in the frontend. | `"hsla(2, 58%, 48%, 1)"` |
|
||||
| `kerberoshub.frontend.features.floorplan.colorLiveViewControlActive` | Color customization for `floorplan` in the frontend. | `"hsla(131, 31%, 52%, 1)"` |
|
||||
| `kerberoshub.frontend.features.floorplan.colorLiveViewControlMotion` | Color customization for `floorplan` in the frontend. | `"hsla(2, 58%, 48%, 1)"` |
|
||||
| `kerberoshub.frontend.features.floorplan.colorFloorPlanLabelText` | Color customization for `floorplan` in the frontend. | `"hsla(0, 0%, 100%, 1)"` |
|
||||
| `kerberoshub.frontend.features.floorplan.colorFloorPlanLabelBackground` | Color customization for `floorplan` in the frontend. | `"hsla(0, 0%, 0%, 0.8)"` |
|
||||
| `kerberoshub.frontend.features.floorplan.colorDeviceMarkerBorder` | Color customization for `floorplan` in the frontend. | `"hsla(0, 0%, 100%, 1)"` |
|
||||
| `kerberoshub.frontend.features.floorplan.colorTrackBox` | Color customization for `floorplan` in the frontend. | `"hsla(278, 30%, 48%, 1)"` |
|
||||
| `kerberoshub.frontend.features.floorplan.colorTrackBoxHover` | Color customization for `floorplan` in the frontend. | `"hsla(47, 86%, 47%, 1)"` |
|
||||
| `kerberoshub.frontend.features.floorplan.colorTrackBoxDrawing` | Color customization for `floorplan` in the frontend. | `"hsla(204, 100%, 50%, 1)"` |
|
||||
| `kerberoshub.frontend.features.floorplan.colorTrackBoxControlsDelete` | Color customization for `floorplan` in the frontend. | `"hsla(219, 100%, 94%, 1)"` |
|
||||
| `kerberoshub.frontend.features.faceRedaction.enabled` | Enable or disable `kerberoshub.frontend.features.faceRedaction`. | `"false"` |
|
||||
| `kerberoshub.frontend.features.faceRedaction.classifierTracksEnabled` | Make classifier-generated tracks available in the redaction modal. | `"true"` |
|
||||
| `kerberoshub.support.enabled` | Enable or disable in-app support features. | `false` |
|
||||
| `kerberoshub.oauth2Proxy.enabled` | Enable or disable `kerberoshub.oauth2Proxy`. | `false` |
|
||||
| `kerberoshub.oauth2Proxy.github.clientId` | Client ID used by `kerberoshub.oauth2Proxy.github`. | `"github-client-id"` |
|
||||
| `kerberoshub.oauth2Proxy.github.clientSecret` | Client secret used by `kerberoshub.oauth2Proxy.github`. | `"github-client-secret"` |
|
||||
| `kerberoshub.oauth2Proxy.github.cookieSecret` | Cookie secret used by `kerberoshub.oauth2Proxy.github`. | `"generate-a-random-cookie-secret"` |
|
||||
| `kerberoshub.oauth2Proxy.github.organization` | Organization value used by `kerberoshub.oauth2Proxy.github`. | `"github-organization"` |
|
||||
| `kerberoshub.oauth2Proxy.github.team` | Team value used by `kerberoshub.oauth2Proxy.github`. | `"github-team"` |
|
||||
| `kerberoshub.cleanup.repository` | The Docker container that is responsible for cleaning up the Kerberos Hub API content and related MongoDB collections. | `"ghcr.io/uug-ai/hub-cleanup"` |
|
||||
| `kerberoshub.cleanup.pullPolicy` | The Docker registry pull policy. | `"IfNotPresent"` |
|
||||
| `kerberoshub.cleanup.tag` | The Docker image tag/version. | `"v1.4.13"` |
|
||||
| `kerberoshub.cleanup.replicas` | Number of replicas for `kerberoshub.cleanup`. | `1` |
|
||||
| `kerberoshub.cleanup.mode` | Cleanup service mode: `serve`, `dry-run`, or `version`. | `"serve"` |
|
||||
| `kerberoshub.cleanup.logLevel` | Log verbosity level for `kerberoshub.cleanup`. | `"info"` |
|
||||
| `kerberoshub.cleanup.maxDays` | Hard maximum age (in days) used by the optional global cleanup pass. | `"365"` |
|
||||
| `kerberoshub.cleanup.runIntervalMinutes` | Minutes between cleanup cycles. | `"10"` |
|
||||
| `kerberoshub.cleanup.cleanupUsernames` | Optional comma-separated usernames to target. | `""` |
|
||||
| `kerberoshub.cleanup.batchSize` | Delete batch size per collection operation. | `"250"` |
|
||||
| `kerberoshub.cleanup.userBatchSize` | Number of users processed per inner batch. | `"100"` |
|
||||
| `kerberoshub.cleanup.maxUsersPerRun` | Maximum users processed per run. | `"100"` |
|
||||
| `kerberoshub.cleanup.progressEvery` | Print progress every N processed users. | `"100"` |
|
||||
| `kerberoshub.cleanup.activeUserRescanHours` | Rescan interval for active users. | `"6"` |
|
||||
| `kerberoshub.cleanup.inactiveUserRescanHours` | Rescan interval for inactive users. | `"24"` |
|
||||
| `kerberoshub.cleanup.readTimeoutSeconds` | Timeout for MongoDB read operations. | `"30"` |
|
||||
| `kerberoshub.cleanup.deleteTimeoutSeconds` | Timeout for delete operations. | `"120"` |
|
||||
| `kerberoshub.cleanup.reportIncludeStats` | Include richer per-user dry-run summary stats. | `"false"` |
|
||||
| `kerberoshub.cleanup.dryRun` | Force dry-run behavior through env var. | `"false"` |
|
||||
| `kerberoshub.cleanup.debug` | Enable extra cleanup debug logging. | `"false"` |
|
||||
| `kerberoshub.cleanup.globalPassEnabled` | Enable optional global orphan cleanup pass. | `"false"` |
|
||||
| `kerberoshub.cleanup.globalPassIntervalHours` | Minimum hours between global cleanup passes. | `"0"` |
|
||||
| `kerberoshub.cleanup.globalPassDeleteBudget` | Max documents deleted during a global pass. | `"0"` |
|
||||
| `kerberoshub.cleanup.defaultTaskRetentionDays` | Default retention (in days) applied to tasks without an explicit `retention_days`. Tasks older than this (anchored on `creation_date`) are deleted with their `case_media` rows. Set to `"0"` or a negative value to keep tasks forever. Must match `kerberoshub.api.defaultTaskRetentionDays`. | `"0"` |
|
||||
| `kerberoshub.cleanup.resources.requests.memory` | Memory request for `kerberoshub.cleanup`. | `"10Mi"` |
|
||||
| `kerberoshub.cleanup.resources.requests.cpu` | CPU request for `kerberoshub.cleanup`. | `"10m"` |
|
||||
| `kerberoshub.monitordevice.repository` | The monitoring microservice, following up the status of your cameras and Kerberos Agents. | `"ghcr.io/uug-ai/hub-monitor-device"` |
|
||||
| `kerberoshub.monitordevice.pullPolicy` | The Docker registry pull policy. | `"IfNotPresent"` |
|
||||
| `kerberoshub.monitordevice.tag` | The Docker image tag/version. | `"v1.4.0"` |
|
||||
| `kerberoshub.monitordevice.replicas` | Number of replicas for `kerberoshub.monitordevice`. | `1` |
|
||||
| `kerberoshub.monitordevice.logLevel` | Log verbosity level for `kerberoshub.monitordevice`. | `"info"` |
|
||||
| `kerberoshub.monitordevice.resources.requests.memory` | Memory request for `kerberoshub.monitordevice`. | `"10Mi"` |
|
||||
| `kerberoshub.monitordevice.resources.requests.cpu` | CPU request for `kerberoshub.monitordevice`. | `"10m"` |
|
||||
| `kerberoshub.reactivate.repository` | Container image repository for `kerberoshub.reactivate`. | `"uugai/hub-reactivatesubscriptions"` |
|
||||
| `kerberoshub.reactivate.pullPolicy` | Image pull policy for `kerberoshub.reactivate`. | `"IfNotPresent"` |
|
||||
| `kerberoshub.reactivate.tag` | Container image tag/version for `kerberoshub.reactivate`. | `"v1.0.2"` |
|
||||
| `kerberoshub.reactivate.replicas` | Number of replicas for `kerberoshub.reactivate`. Set to `0` to disable. | `0` |
|
||||
| `kerberoshub.reactivate.logLevel` | Log verbosity level for `kerberoshub.reactivate`. | `"info"` |
|
||||
| `kerberoshub.reactivate.resources.requests.memory` | Memory request for `kerberoshub.reactivate`. | `"10Mi"` |
|
||||
| `kerberoshub.reactivate.resources.requests.cpu` | CPU request for `kerberoshub.reactivate`. | `"10m"` |
|
||||
| `kerberoshub.forwarder.enabled` | Enable or disable the Hub forwarder component. | `false` |
|
||||
| `kerberoshub.proxy.repository` | Container image repository for `kerberoshub.proxy`. | `"uugai/hub-proxy"` |
|
||||
| `kerberoshub.proxy.pullPolicy` | Image pull policy for `kerberoshub.proxy`. | `"IfNotPresent"` |
|
||||
| `kerberoshub.proxy.tag` | Container image tag/version for `kerberoshub.proxy`. | `"v1.0.0"` |
|
||||
| `kerberoshub.proxy.replicas` | Number of replicas for `kerberoshub.proxy`. Set to `0` to disable. | `0` |
|
||||
| `kerberoshub.proxy.logLevel` | Log verbosity level for `kerberoshub.proxy`. | `"info"` |
|
||||
| `kerberoshub.proxy.resources.requests.memory` | Memory request for `kerberoshub.proxy`. | `"10Mi"` |
|
||||
| `kerberoshub.proxy.resources.requests.cpu` | CPU request for `kerberoshub.proxy`. | `"10m"` |
|
||||
| `kerberospipeline.event.repository` | The [event orchestration](https://doc.kerberos.io/hub/pipeline/#orchestrator) microservice. | `"ghcr.io/uug-ai/hub-pipeline-event"` |
|
||||
| `kerberospipeline.event.pullPolicy` | The Docker registry pull policy. | `"IfNotPresent"` |
|
||||
| `kerberospipeline.event.tag` | The Docker image tag/version. | `"v1.3.0"` |
|
||||
| `kerberospipeline.event.replicas` | Number of replicas for `kerberospipeline.event`. | `1` |
|
||||
| `kerberospipeline.event.logLevel` | Log verbosity level for `kerberospipeline.event`. | `"info"` |
|
||||
| `kerberospipeline.event.resources.requests.memory` | Memory request for `kerberospipeline.event`. | `"10Mi"` |
|
||||
| `kerberospipeline.event.resources.requests.cpu` | CPU request for `kerberospipeline.event`. | `"10m"` |
|
||||
| `kerberospipeline.monitor.repository` | The [monitoring microservice](https://doc.kerberos.io/hub/pipeline/#monitoring), calculating metrics of incoming messages. | `"ghcr.io/uug-ai/hub-pipeline-monitor"` |
|
||||
| `kerberospipeline.monitor.pullPolicy` | The Docker registry pull policy. | `"IfNotPresent"` |
|
||||
| `kerberospipeline.monitor.tag` | The Docker image tag/version. | `"v1.3.9"` |
|
||||
| `kerberospipeline.monitor.replicas` | Number of replicas for `kerberospipeline.monitor`. | `1` |
|
||||
| `kerberospipeline.monitor.resources.requests.memory` | Memory request for `kerberospipeline.monitor`. | `"10Mi"` |
|
||||
| `kerberospipeline.monitor.resources.requests.cpu` | CPU request for `kerberospipeline.monitor`. | `"10m"` |
|
||||
| `kerberospipeline.sequence.repository` | The [sequencer microservice](https://doc.kerberos.io/hub/pipeline/#sequencer), grouping recordings in chunks/groups. | `"ghcr.io/uug-ai/hub-pipeline-sequence"` |
|
||||
| `kerberospipeline.sequence.pullPolicy` | The Docker registry pull policy. | `"IfNotPresent"` |
|
||||
| `kerberospipeline.sequence.tag` | The Docker image tag/version. | `"v1.6.18"` |
|
||||
| `kerberospipeline.sequence.replicas` | Number of replicas for `kerberospipeline.sequence`. | `1` |
|
||||
| `kerberospipeline.sequence.resources.requests.memory` | Memory request for `kerberospipeline.sequence`. | `"10Mi"` |
|
||||
| `kerberospipeline.sequence.resources.requests.cpu` | CPU request for `kerberospipeline.sequence`. | `"10m"` |
|
||||
| `kerberospipeline.throttler.repository` | The [throttler microservice](https://doc.kerberos.io/hub/pipeline/#throttler), throttling events. | `"uugai/hub-pipeline-throttler"` |
|
||||
| `kerberospipeline.throttler.pullPolicy` | The Docker registry pull policy. | `"IfNotPresent"` |
|
||||
| `kerberospipeline.throttler.tag` | The Docker image tag/version. | `"v1.2.0"` |
|
||||
| `kerberospipeline.throttler.replicas` | Number of replicas for `kerberospipeline.throttler`. | `1` |
|
||||
| `kerberospipeline.throttler.logLevel` | Log verbosity level for `kerberospipeline.throttler`. | `"info"` |
|
||||
| `kerberospipeline.throttler.resources.requests.memory` | Memory request for `kerberospipeline.throttler`. | `"10Mi"` |
|
||||
| `kerberospipeline.throttler.resources.requests.cpu` | CPU request for `kerberospipeline.throttler`. | `"10m"` |
|
||||
| `kerberospipeline.notify.repository` | The [notification microservice](https://doc.kerberos.io/hub/pipeline/#notification), sending notifications on events. | `"ghcr.io/uug-ai/hub-pipeline-notification"` |
|
||||
| `kerberospipeline.notify.pullPolicy` | The Docker registry pull policy. | `"IfNotPresent"` |
|
||||
| `kerberospipeline.notify.tag` | The Docker image tag/version. | `"v1.3.9"` |
|
||||
| `kerberospipeline.notify.replicas` | Number of replicas for `kerberospipeline.notify`. | `1` |
|
||||
| `kerberospipeline.notify.logLevel` | Log verbosity level for `kerberospipeline.notify`. | `"info"` |
|
||||
| `kerberospipeline.notify.resources.requests.memory` | Memory request for `kerberospipeline.notify`. | `"10Mi"` |
|
||||
| `kerberospipeline.notify.resources.requests.cpu` | CPU request for `kerberospipeline.notify`. | `"10m"` |
|
||||
| `kerberospipeline.notifyTest.repository` | The notification service for testing, the different channels. | `"uugai/hub-pipeline-notification-test"` |
|
||||
| `kerberospipeline.notifyTest.pullPolicy` | The Docker registry pull policy. | `"IfNotPresent"` |
|
||||
| `kerberospipeline.notifyTest.tag` | The Docker image tag/version. | `"v1.2.1"` |
|
||||
| `kerberospipeline.notifyTest.replicas` | Number of replicas for `kerberospipeline.notifyTest`. | `1` |
|
||||
| `kerberospipeline.notifyTest.resources.requests.memory` | Memory request for `kerberospipeline.notifyTest`. | `"10Mi"` |
|
||||
| `kerberospipeline.notifyTest.resources.requests.cpu` | CPU request for `kerberospipeline.notifyTest`. | `"10m"` |
|
||||
| `kerberospipeline.analysis.repository` | The [analysis microservices](https://doc.kerberos.io/hub/pipeline/#analyser) which executed specific analysis in parallel. | `"ghcr.io/uug-ai/hub-pipeline-analysis"` |
|
||||
| `kerberospipeline.analysis.pullPolicy` | The Docker registry pull policy. | `"IfNotPresent"` |
|
||||
| `kerberospipeline.analysis.tag` | The Docker image tag/version. | `"v1.7.8"` |
|
||||
| `kerberospipeline.analysis.replicas` | Number of replicas for `kerberospipeline.analysis`. | `1` |
|
||||
| `kerberospipeline.analysis.logLevel` | Log verbosity level for `kerberospipeline.analysis`. | `"info"` |
|
||||
| `kerberospipeline.analysis.resources.requests.memory` | Memory request for `kerberospipeline.analysis`. | `"10Mi"` |
|
||||
| `kerberospipeline.analysis.resources.requests.cpu` | CPU request for `kerberospipeline.analysis`. | `"10m"` |
|
||||
| `kerberospipeline.dominantColor.repository` | The dominant color microservices is computing a top 3 color histogram. | `"ghcr.io/uug-ai/hub-pipeline-dominantcolors"` |
|
||||
| `kerberospipeline.dominantColor.pullPolicy` | The Docker registry pull policy. | `"IfNotPresent"` |
|
||||
| `kerberospipeline.dominantColor.tag` | The Docker image tag/version. | `"v2.0.2"` |
|
||||
| `kerberospipeline.dominantColor.replicas` | Number of replicas for `kerberospipeline.dominantColor`. | `3` |
|
||||
| `kerberospipeline.dominantColor.logLevel` | Log verbosity level for `kerberospipeline.dominantColor`. | `"info"` |
|
||||
| `kerberospipeline.dominantColor.resources.requests.memory` | Memory request for `kerberospipeline.dominantColor`. | `"512Mi"` |
|
||||
| `kerberospipeline.dominantColor.resources.requests.cpu` | CPU request for `kerberospipeline.dominantColor`. | `"500m"` |
|
||||
| `kerberospipeline.dominantColor.resources.limits.memory` | Memory limit for `kerberospipeline.dominantColor`. | `"2Gi"` |
|
||||
| `kerberospipeline.dominantColor.resources.limits.cpu` | CPU limit for `kerberospipeline.dominantColor`. | `"1000m"` |
|
||||
| `kerberospipeline.thumbnail.repository` | The thumbnail microservices generated a thumbnail for a recordings. | `"ghcr.io/uug-ai/hub-pipeline-thumbnail"` |
|
||||
| `kerberospipeline.thumbnail.pullPolicy` | The Docker registry pull policy. | `"IfNotPresent"` |
|
||||
| `kerberospipeline.thumbnail.tag` | The Docker image tag/version. | `"v1.3.4"` |
|
||||
| `kerberospipeline.thumbnail.replicas` | Number of replicas for `kerberospipeline.thumbnail`. | `2` |
|
||||
| `kerberospipeline.thumbnail.logLevel` | Log verbosity level for `kerberospipeline.thumbnail`. | `"info"` |
|
||||
| `kerberospipeline.thumbnail.quality` | Configuration value for `kerberospipeline.thumbnail.quality`. | `"1"` |
|
||||
| `kerberospipeline.thumbnail.width` | Configuration value for `kerberospipeline.thumbnail.width`. | `"600"` |
|
||||
| `kerberospipeline.thumbnail.height` | Configuration value for `kerberospipeline.thumbnail.height`. | `"-1"` |
|
||||
| `kerberospipeline.thumbnail.kerberosvault.enabled` | Enable or disable `kerberospipeline.thumbnail.kerberosvault`. | `true` |
|
||||
| `kerberospipeline.thumbnail.resources.requests.memory` | Memory request for `kerberospipeline.thumbnail`. | `"512Mi"` |
|
||||
| `kerberospipeline.thumbnail.resources.requests.cpu` | CPU request for `kerberospipeline.thumbnail`. | `"500m"` |
|
||||
| `kerberospipeline.thumbnail.resources.limits.memory` | Memory limit for `kerberospipeline.thumbnail`. | `"2Gi"` |
|
||||
| `kerberospipeline.thumbnail.resources.limits.cpu` | CPU limit for `kerberospipeline.thumbnail`. | `"1000m"` |
|
||||
| `kerberospipeline.counting.repository` | The counting microservices computes objects passing different line segments. | `"uugai/hub-pipeline-counting"` |
|
||||
| `kerberospipeline.counting.pullPolicy` | The Docker registry pull policy. | `"IfNotPresent"` |
|
||||
| `kerberospipeline.counting.tag` | The Docker image tag/version. | `"v1.6.3"` |
|
||||
| `kerberospipeline.counting.replicas` | Number of replicas for `kerberospipeline.counting`. | `1` |
|
||||
| `kerberospipeline.counting.logLevel` | Log verbosity level for `kerberospipeline.counting`. | `"info"` |
|
||||
| `kerberospipeline.counting.resources.requests.memory` | Memory request for `kerberospipeline.counting`. | `"10Mi"` |
|
||||
| `kerberospipeline.counting.resources.requests.cpu` | CPU request for `kerberospipeline.counting`. | `"10m"` |
|
||||
| `kerberospipeline.sprite.enabled` | Enable or disable `kerberospipeline.sprite`. | `false` |
|
||||
| `kerberospipeline.sprite.repository` | Container image repository for `kerberospipeline.sprite`. | `"ghcr.io/uug-ai/hub-pipeline-sprite"` |
|
||||
| `kerberospipeline.sprite.pullPolicy` | Image pull policy for `kerberospipeline.sprite`. | `"IfNotPresent"` |
|
||||
| `kerberospipeline.sprite.tag` | Container image tag/version for `kerberospipeline.sprite`. | `"v1.1.12"` |
|
||||
| `kerberospipeline.sprite.replicas` | Number of replicas for `kerberospipeline.sprite`. | `5` |
|
||||
| `kerberospipeline.sprite.logLevel` | Log verbosity level for `kerberospipeline.sprite`. | `"info"` |
|
||||
| `kerberospipeline.sprite.interval` | Configuration value for `kerberospipeline.sprite.interval`. | `"1"` |
|
||||
| `kerberospipeline.sprite.width` | Configuration value for `kerberospipeline.sprite.width`. | `"240"` |
|
||||
| `kerberospipeline.sprite.height` | Configuration value for `kerberospipeline.sprite.height`. | `"135"` |
|
||||
| `kerberospipeline.sprite.resources.requests.memory` | Memory request for `kerberospipeline.sprite`. | `"512Mi"` |
|
||||
| `kerberospipeline.sprite.resources.requests.cpu` | CPU request for `kerberospipeline.sprite`. | `"500m"` |
|
||||
| `kerberospipeline.sprite.resources.limits.memory` | Memory limit for `kerberospipeline.sprite`. | `"2Gi"` |
|
||||
| `kerberospipeline.sprite.resources.limits.cpu` | CPU limit for `kerberospipeline.sprite`. | `"1000m"` |
|
||||
| `kerberospipeline.export.repository` | Container image repository for `kerberospipeline.export`. | `"ghcr.io/uug-ai/hub-pipeline-export"` |
|
||||
| `kerberospipeline.export.pullPolicy` | Image pull policy for `kerberospipeline.export`. | `"IfNotPresent"` |
|
||||
| `kerberospipeline.export.tag` | Container image tag/version for `kerberospipeline.export`. | `"v1.2.4"` |
|
||||
| `kerberospipeline.export.replicas` | Number of replicas for `kerberospipeline.export`. | `2` |
|
||||
| `kerberospipeline.export.logLevel` | Log verbosity level for `kerberospipeline.export`. | `"info"` |
|
||||
| `kerberospipeline.export.resources.requests.memory` | Memory request for `kerberospipeline.export`. | `"10Mi"` |
|
||||
| `kerberospipeline.export.resources.requests.cpu` | CPU request for `kerberospipeline.export`. | `"10m"` |
|
||||
| `email.provider` | The email service provider for sending out messages over email , use `'mailgun'` or `'smtp'`. | `"mailgun"` |
|
||||
| `email.from` | The email address that is sending messages in name of, by default `'support@yourdomain.com'`. | `"support@yourdomain.com"` |
|
||||
| `email.displayName` | The display name that is sending messages in name of, by default `'yourdomain.com'` | `"yourdomain.com"` |
|
||||
| `email.mailgun.domain` | While using `mailgun` as email service provider, you will need to provide your Mailgun domain. | `"mg.yourdomain.com"` |
|
||||
| `email.mailgun.apikey` | Mailgun API key (lowercase variant) used when provider is `mailgun`. | `"xxxx"` |
|
||||
| `email.smtp.server` | While using `smtp` as email service provider, use the SMTP server. | `"smtp.yourdomain.com"` |
|
||||
| `email.smtp.port` | SMTP port specified by your SMTP server, by default `'456'`. | `"465"` |
|
||||
| `email.smtp.username` | SMTP username. | `"yourusername"` |
|
||||
| `email.smtp.password` | SMTP password. | `"yourpassword"` |
|
||||
| `email.templates.welcome` | The template which is send when a new user registered on the platform (`IS_PRIVATE='false'`), by default `'disabled'`. | `"welcome"` |
|
||||
| `email.templates.welcomeTitle` | The welcome title use in the subject of the email. | `"Welcome to Kerberos Hub"` |
|
||||
| `email.templates.activate` | The template which is send when a user is required to activate his account , by default `'activate'`. | `"activate"` |
|
||||
| `email.templates.activateTitle` | The activation title use in the subject of the email. | `"Wonderful! Your Kerberos Hub is now active"` |
|
||||
| `email.templates.forgot` | The template which is send when an account is requesting a forgot password, by default `'forgot'`. | `"forgot"` |
|
||||
| `email.templates.forgotTitle` | The forgot title use in the subject of the email. | `"Password reset Kerberos Hub. You forgot your password"` |
|
||||
| `email.templates.share` | Email template name/key for `share` notifications. | `"share"` |
|
||||
| `email.templates.shareTitle` | Email subject title for the `share` template. | `"[Action] You received a recording from Kerberos Hub"` |
|
||||
| `email.templates.assignTask` | Email template name/key for `assign task` notifications. | `"assign_task"` |
|
||||
| `email.templates.assignTaskTitle` | Email subject title for the `assign task` template. | `"[Action] You've been assigned to a task"` |
|
||||
| `email.templates.detection` | We use templates to send notifications, this allow you to bring your own `Mailgun` templates, by default `'detection'`. | `"detection"` |
|
||||
| `email.templates.disabled` | The template which is send when an account is disabled due to reaching its upload limit, by default `'disabled'`. | `"disabled"` |
|
||||
| `email.templates.highupload` | The template which is send when an account is reaching a specific upload threshold, by default `'threshold'`. | `"highupload"` |
|
||||
| `email.templates.device` | The template which is send when a camera goes online or offline, by default `'device'`. | `"device"` |
|
||||
| `email.templates.alertTitle` | Email subject title for the `alert` template. | `"[Alert] Kerberos Hub detected something an event"` |
|
||||
| `email.templates.deviceTitle` | Email subject title for the `device` template. | `"[Device] A Kerberos Agent's status has been changed"` |
|
||||
| `email.mailgun.apiKey` | The Mailgun API key linked to your Mailgun domain. | `""` |
|
||||
| `imagePullSecrets.name` | Docker registry secret name, which is also granted with the license. This allows you to download the Docker images. | `""` |
|
||||
| `kerberoshub.forwarder.pullPolicy` | The Docker registry pull policy. | `""` |
|
||||
@@ -474,6 +498,7 @@ Following indexes should be executed on the MongoDB database (Kerberos) to impro
|
||||
#### Analysis collection
|
||||
|
||||
db.getCollection("analysis").createIndex({start:1})
|
||||
db.getCollection("analysis").createIndex({organisationId:1, projectId:1, key:1}, {name:"analysis_org_project_key"})
|
||||
db.getCollection("analysis").createIndex({userid:1, key:1})
|
||||
db.getCollection("analysis").createIndex({userid:1, start:1})
|
||||
|
||||
|
||||
11
charts/hub/custom-layout/i18n-custom/custom-i18n-claim.yaml
Normal file
11
charts/hub/custom-layout/i18n-custom/custom-i18n-claim.yaml
Normal file
@@ -0,0 +1,11 @@
|
||||
apiVersion: v1
|
||||
kind: PersistentVolumeClaim
|
||||
metadata:
|
||||
name: custom-i18n-claim
|
||||
spec:
|
||||
accessModes:
|
||||
- ReadWriteMany
|
||||
storageClassName: azurefile-premium
|
||||
resources:
|
||||
requests:
|
||||
storage: 25Mi
|
||||
9
charts/hub/custom-layout/i18n-custom/en.json
Normal file
9
charts/hub/custom-layout/i18n-custom/en.json
Normal file
@@ -0,0 +1,9 @@
|
||||
{
|
||||
"nav": {
|
||||
"cases": "Investigations",
|
||||
"dashboard": "Home"
|
||||
},
|
||||
"login": {
|
||||
"signInTo": "Sign in to {{domain}} \u2014 Acme Security"
|
||||
}
|
||||
}
|
||||
2997
charts/hub/custom-layout/i18n/en.json
Normal file
2997
charts/hub/custom-layout/i18n/en.json
Normal file
File diff suppressed because it is too large
Load Diff
@@ -926,6 +926,13 @@
|
||||
<path fill-rule="evenodd" clip-rule="evenodd" d="M9 4C9.55228 4 10 4.44772 10 5V13C10 13.5523 9.55228 14 9 14C8.44772 14 8 13.5523 8 13V5C8 4.44772 8.44772 4 9 4Z" fill="currentColor"/>
|
||||
</svg>`
|
||||
|
||||
/* Invoice */
|
||||
window["env"]["svg"]["invoice"] = `<svg class="icon icon-invoice" width="18" height="18" viewBox="0 0 18 18" fill="none" xmlns="http://www.w3.org/2000/svg">
|
||||
<path fill-rule="evenodd" clip-rule="evenodd" d="M5.9453 5.54295C6.58555 5.11611 7.47538 5 8.5 5H11C11.5523 5 12 5.44772 12 6C12 6.55228 11.5523 7 11 7H8.5C7.52462 7 7.16445 7.13389 7.0547 7.20705C7.03426 7.22067 7.03361 7.22365 7.03297 7.22658C7.03285 7.22715 7.03272 7.22772 7.03245 7.22837C7.02311 7.2508 7 7.32539 7 7.5C7 7.65149 7.01759 7.7156 7.02407 7.734C7.02962 7.73847 7.04039 7.74633 7.05864 7.75676C7.24508 7.8633 7.75279 8 9 8C10.2528 8 11.2451 8.1133 11.9336 8.50676C12.3184 8.72663 12.6117 9.03408 12.7919 9.4271C12.9615 9.79718 13 10.1769 13 10.5C13 10.8231 12.9615 11.2028 12.7919 11.5729C12.6117 11.9659 12.3184 12.2734 11.9336 12.4932C11.2451 12.8867 10.2528 13 9 13H7C6.44772 13 6 12.5523 6 12C6 11.4477 6.44772 11 7 11H9C10.2472 11 10.7549 10.8633 10.9414 10.7568C10.9596 10.7463 10.9704 10.7385 10.9759 10.734C10.9824 10.7156 11 10.6515 11 10.5C11 10.3485 10.9824 10.2844 10.9759 10.266C10.9704 10.2615 10.9596 10.2537 10.9414 10.2432C10.7549 10.1367 10.2472 10 9 10C7.74721 10 6.75492 9.8867 6.06636 9.49324C5.68159 9.27337 5.38825 8.96592 5.20812 8.5729C5.0385 8.20282 5 7.82305 5 7.5C5 6.82469 5.18169 6.05202 5.9453 5.54295Z" fill="currentColor"/>
|
||||
<path fill-rule="evenodd" clip-rule="evenodd" d="M9 4C9.55228 4 10 4.44772 10 5V13C10 13.5523 9.55228 14 9 14C8.44772 14 8 13.5523 8 13V5C8 4.44772 8.44772 4 9 4Z" fill="currentColor"/>
|
||||
<path fill-rule="evenodd" clip-rule="evenodd" d="M1 2C1 0.89543 1.89543 0 3 0H15C16.1046 0 17 0.89543 17 2V17C17 17.3214 16.8455 17.6233 16.5847 17.8112C16.3239 17.9992 15.9887 18.0503 15.6838 17.9487L13.0767 17.0797L11.4472 17.8944C11.1657 18.0352 10.8343 18.0352 10.5528 17.8944L9 17.118L7.44721 17.8944C7.16569 18.0352 6.83431 18.0352 6.55279 17.8944L4.92327 17.0797L2.31623 17.9487C2.01128 18.0503 1.67606 17.9992 1.41529 17.8112C1.15452 17.6233 1 17.3214 1 17V2ZM15 2H3V15.6126L4.68377 15.0513C4.93538 14.9674 5.21 14.987 5.44721 15.1056L7 15.882L8.55279 15.1056C8.83431 14.9648 9.16569 14.9648 9.44721 15.1056L11 15.882L12.5528 15.1056C12.79 14.987 13.0646 14.9674 13.3162 15.0513L15 15.6126V2Z" fill="currentColor"/>
|
||||
</svg>`
|
||||
|
||||
/* Suitcase (detection classification) */
|
||||
window["env"]["svg"]["suitcase"] = `<svg class="icon icon-suitcase" width="18" height="18" viewBox="0 0 18 18" fill="none" xmlns="http://www.w3.org/2000/svg">
|
||||
<path fill-rule="evenodd" clip-rule="evenodd" d="M1 4C1 3.44772 1.44772 3 2 3H16C16.5523 3 17 3.44772 17 4V17C17 17.5523 16.5523 18 16 18H2C1.44772 18 1 17.5523 1 17V4ZM3 5V16H15V5H3Z" fill="currentColor"/>
|
||||
|
||||
418
charts/hub/custom-layout/templates/share_case.html
Normal file
418
charts/hub/custom-layout/templates/share_case.html
Normal file
@@ -0,0 +1,418 @@
|
||||
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
|
||||
<html xmlns="http://www.w3.org/1999/xhtml">
|
||||
<head>
|
||||
|
||||
<meta http-equiv="X-UA-Compatible" content="IE=edge" />
|
||||
<meta http-equiv="Content-Type" content="text/html; charset=utf-8" />
|
||||
<meta
|
||||
name="viewport"
|
||||
content="width=device-width, initial-scale=1, minimum-scale=1, maximum-scale=1"
|
||||
/>
|
||||
<meta name="description" content="Kerberos.io Mailing">
|
||||
<style type="text/css">
|
||||
|
||||
@font-face {
|
||||
font-family: 'Inter';
|
||||
font-style: normal;
|
||||
font-weight: 400;
|
||||
font-display: swap;
|
||||
src: url("https://kerberos.io/dist/fonts/Inter-Regular.woff?v=/dist/fonts/Inter-Regular.woff2?v=3.183.18") format("woff2"),
|
||||
url("https://kerberos.io/dist/fonts/Inter-Regular.woff?v=/dist/fonts/Inter-Regular.woff2?v=3.183.18") format("woff");
|
||||
}
|
||||
|
||||
@font-face {
|
||||
font-family: 'Inter';
|
||||
font-style: normal;
|
||||
font-weight: 500;
|
||||
font-display: swap;
|
||||
src: url("https://kerberos.io/dist/fonts/Inter-Medium.woff2?v=3.18") format("woff2"),
|
||||
url("https://kerberos.io/dist/fonts/Inter-Medium.woff?v=3.18") format("woff");
|
||||
}
|
||||
|
||||
@font-face {
|
||||
font-family: 'Inter';
|
||||
font-style: normal;
|
||||
font-weight: 600;
|
||||
font-display: swap;
|
||||
src: url("https://kerberos.io/dist/fonts/Inter-SemiBold.woff2?v=3.18") format("woff2"),
|
||||
url("https://kerberos.io/dist/fonts/Inter-SemiBold.woff?v=3.18") format("woff");
|
||||
}
|
||||
|
||||
@font-face {
|
||||
font-family: 'Inter var';
|
||||
font-weight: 100 900;
|
||||
font-display: swap;
|
||||
font-style: normal;
|
||||
font-named-instance: 'Regular';
|
||||
src: url("https://kerberos.io/dist/fonts/Inter-roman.var.woff2?v=3.18") format("woff2");
|
||||
}
|
||||
|
||||
body{
|
||||
background: #E5E5E5;
|
||||
margin-top:0;
|
||||
margin-bottom: 0;
|
||||
margin-right: 0;
|
||||
margin-left: 0;
|
||||
padding-top: 0;
|
||||
padding-left: 0;
|
||||
padding-right: 0;
|
||||
padding-bottom: 0;
|
||||
font-family: 'Inter';
|
||||
}
|
||||
a, a:hover, a:active {
|
||||
color: #262424;
|
||||
text-decoration: none;
|
||||
}
|
||||
|
||||
.corner-td{
|
||||
width: 60px;
|
||||
}
|
||||
|
||||
table {border-collapse:separate;max-width: 850px; margin: 0 auto; width: 100%;}
|
||||
.ExternalClass p, .ExternalClass span, .ExternalClass font, .ExternalClass td {line-height: 100%;}
|
||||
.ExternalClass {width: 100%;}
|
||||
@media screen and (max-width:500px){
|
||||
.tab-td{
|
||||
padding-left: 10px!important;
|
||||
}
|
||||
.tab-td a h4{
|
||||
font-size: 14px!important;
|
||||
}
|
||||
.corner-td{
|
||||
width: 20px!important;
|
||||
}
|
||||
.company-name-td h3{
|
||||
font-size: 16px!important;
|
||||
}
|
||||
table.header-table{
|
||||
padding-top: 8px!important;
|
||||
padding-right: 0px!important;
|
||||
padding-bottom: 24px!important;
|
||||
padding-left: 0px!important;
|
||||
}
|
||||
.colored-card-td h4{
|
||||
font-size: 14px!important;
|
||||
}
|
||||
.colored-card-td h2{
|
||||
font-size: 20px!important;
|
||||
}
|
||||
.colored-card-td a p{
|
||||
font-size: 12px!important;
|
||||
width: 143px!important;
|
||||
}
|
||||
.colored-card-td{
|
||||
padding-top: 24px!important;
|
||||
padding-right: 24px!important;
|
||||
padding-bottom: 24px!important;
|
||||
padding-left: 24px!important;
|
||||
}
|
||||
.colorless-card-td{
|
||||
padding-top: 24px!important;
|
||||
padding-right: 24px!important;
|
||||
padding-bottom: 24px!important;
|
||||
padding-left: 24px!important;
|
||||
}
|
||||
.colorless-card-td h3{
|
||||
font-size: 18px!important;
|
||||
}
|
||||
.colorless-card-td p{
|
||||
font-size: 14px!important;
|
||||
}
|
||||
.colorless-card-table{
|
||||
margin-left: 0px!important;
|
||||
margin-right: 0px!important;
|
||||
margin-top: 24px!important;
|
||||
margin-bottom: 24px!important;
|
||||
}
|
||||
.footer-td{
|
||||
display: table-row!important;
|
||||
}
|
||||
}
|
||||
@media screen and (max-width:600px) {
|
||||
.footer-td{
|
||||
display: table-row!important;
|
||||
}
|
||||
}
|
||||
@media screen and (max-width:650px) {
|
||||
.footer-table{
|
||||
margin-left: 0px!important;
|
||||
margin-right: 0px!important;
|
||||
margin-top: 0px!important;
|
||||
margin-bottom: 36px!important;
|
||||
}
|
||||
}
|
||||
</style>
|
||||
</head>
|
||||
<body height="100%" width="100%">
|
||||
<table border="0" cellpadding="0" cellspacing="0" width="100%" bgcolor="E5E5E5" style="border-collaps:collaps; mso-table-lspace:0pt; mso-table-rspace:0pt;">
|
||||
<tr>
|
||||
<td bgcolor="E5E5E5">
|
||||
<table border="0" cellpadding="0" cellspacing="0" width="100%" height="36" class="header-table" style="padding-top: 36px ;padding-right: 0;padding-bottom: 36px;padding-left: 0;border-collaps:collaps; mso-table-lspace:0pt; mso-table-rspace:0pt;">
|
||||
<tbody>
|
||||
<tr>
|
||||
<td class="corner-td" align="left"></td>
|
||||
<td width="48" height="36" align="left"><img alt="Kerberos.io" width="36" height="36" src="https://kerberos.io/images/email/kerberos.png"/></td>
|
||||
<td height="36" align="left" class="company-name-td">
|
||||
<h3 width="36" height="36" style=" font-family: Inter;
|
||||
font-size: 20px;
|
||||
font-style: normal;
|
||||
font-weight: 600;
|
||||
line-height: 24px;
|
||||
mso-line-height-rule:exactly;
|
||||
letter-spacing: 0em;
|
||||
text-align: left;
|
||||
color: #262424;">Kerberos.io</h3>
|
||||
</td>
|
||||
<td height="36" width="36" style="padding-left: 36px;" class="tab-td" align="right">
|
||||
<a style="text-decoration: none;color: none;" href={{tab1_href}}>
|
||||
<h4 style="font-family: Inter;
|
||||
font-size: 16px;
|
||||
font-style: normal;
|
||||
font-weight: 500;
|
||||
line-height: 36px;
|
||||
mso-line-height-rule:exactly;
|
||||
letter-spacing: 0em;
|
||||
text-align: right;
|
||||
color: #6D6666;">{{tab1_title}}</h4>
|
||||
</a>
|
||||
</td>
|
||||
<td height="36" width="36" style="padding-left: 36px;" class="tab-td" align="right" >
|
||||
<a style="text-decoration: none;color: none;" href={{tab2_href}}>
|
||||
<h4 style="font-family: Inter;
|
||||
font-size: 16px;
|
||||
font-style: normal;
|
||||
font-weight: 500;
|
||||
line-height: 36px;
|
||||
mso-line-height-rule:exactly;
|
||||
letter-spacing: 0em;
|
||||
text-align: right;
|
||||
color: #6D6666;">{{tab2_title}}</h4>
|
||||
</a>
|
||||
</td>
|
||||
<td class="corner-td" align="right"></td>
|
||||
</tr>
|
||||
</tbody>
|
||||
</table>
|
||||
</td>
|
||||
</tr>
|
||||
</table>
|
||||
<table border="0" cellpadding="0" cellspacing="0" width="100%" bgcolor="E5E5E5" style="border-collaps:collaps; mso-table-lspace:0pt; mso-table-rspace:0pt;">
|
||||
<tr>
|
||||
<td bgcolor="E5E5E5">
|
||||
<table border="0" cellpadding="0" cellspacing="0" width="100%" style="border-collaps:collaps; mso-table-lspace:0pt; mso-table-rspace:0pt;" >
|
||||
<tbody>
|
||||
<tr>
|
||||
<td class="corner-td" align="left"></td>
|
||||
<td class="colored-card-td" bgcolor="#57356B" style="padding-left: 48px;padding-right: 48px;padding-top: 48px;padding-bottom: 48px;border-radius: 4px;background-color:#57356B;">
|
||||
<h2 style=" font-family: Inter;
|
||||
font-size: 24px;
|
||||
font-style: normal;
|
||||
font-weight: 600;
|
||||
line-height: 36px;
|
||||
mso-line-height-rule:exactly;
|
||||
letter-spacing: 0em;
|
||||
text-align: left;
|
||||
color:#FFFFFF;
|
||||
padding-top: 12px;
|
||||
margin-bottom: 0;
|
||||
padding-bottom: 0;
|
||||
padding-left: 0;
|
||||
padding-right: 0;">A case has been shared with you</h2>
|
||||
<h4 style="font-family: Inter;
|
||||
font-size: 16px;
|
||||
font-style: normal;
|
||||
font-weight: 400;
|
||||
line-height: 24px;
|
||||
mso-line-height-rule:exactly;
|
||||
letter-spacing: 0em;
|
||||
text-align: left;
|
||||
color:#b09fb9;">{{user}} shared a case with you</h4>
|
||||
</td>
|
||||
<td class="corner-td" align="right"></td>
|
||||
</tr>
|
||||
</tbody>
|
||||
</table>
|
||||
</td>
|
||||
</tr>
|
||||
</table>
|
||||
<table border="0" cellpadding="0" cellspacing="0" width="100%" bgcolor="E5E5E5" style="border-collaps:collaps; mso-table-lspace:0pt; mso-table-rspace:0pt;">
|
||||
<tr>
|
||||
<td bgcolor="E5E5E5">
|
||||
<table border="0" cellpadding="0" cellspacing="0" width="100%" class="colorless-card-table" style="margin-top: 36px;margin-bottom: 36px;margin-left: 0;margin-right: 0;border-collaps:collaps; mso-table-lspace:0pt; mso-table-rspace:0pt;" >
|
||||
<tbody>
|
||||
<tr>
|
||||
<td class="corner-td" align="left"></td>
|
||||
<td class="colorless-card-td" bgcolor="#FFFFFF" style="background-color:#FFFFFF;padding-top: 36px;padding-right: 43px;padding-bottom: 25px;padding-left: 43px;border-radius: 4px;">
|
||||
<h3 style=" font-family: Inter;
|
||||
font-size: 20px;
|
||||
font-style: normal;
|
||||
font-weight: 600;
|
||||
line-height: 36px;
|
||||
mso-line-height-rule:exactly;
|
||||
letter-spacing: 0em;
|
||||
text-align: left;
|
||||
color: #262424;
|
||||
width: 280px">Open the shared case</h3>
|
||||
<p style=" font-family: Inter;
|
||||
font-size: 14px;
|
||||
font-style: normal;
|
||||
font-weight: 400;
|
||||
line-height: 24px;
|
||||
mso-line-height-rule:exactly;
|
||||
letter-spacing: 0em;
|
||||
text-align: left;
|
||||
color: #6D6666;
|
||||
margin-top: 12px;">{{user}} has shared a case with you. Click the button below to open it. You'll be asked to request a one-time verification code from the share page itself.<br/><br/>This link will expire in {{expiry}}.</p>
|
||||
|
||||
|
||||
<a style="text-decoration: none;color: none;" href="{{url}}">
|
||||
<p style="font-family: Inter;
|
||||
font-size: 14px;
|
||||
font-style: normal;
|
||||
line-height: 24px;
|
||||
mso-line-height-rule:exactly;
|
||||
letter-spacing: 0em;
|
||||
text-align: left;
|
||||
color:#FFFFFF;
|
||||
background-color: #84559F;
|
||||
padding-top: 6px;
|
||||
padding-bottom: 6px;
|
||||
padding-right: 16px;
|
||||
padding-left: 16px;
|
||||
width: 130px;
|
||||
border-radius: 4px;
|
||||
text-align: center;
|
||||
cursor: pointer;">Open case -></p>
|
||||
</a>
|
||||
</td>
|
||||
<td class="corner-td" align="right"></td>
|
||||
</tr>
|
||||
</tbody>
|
||||
</table>
|
||||
</td>
|
||||
</tr>
|
||||
</table>
|
||||
<table border="0" cellpadding="0" cellspacing="0" width="100%" bgcolor="E5E5E5" style="border-collaps:collaps; mso-table-lspace:0pt; mso-table-rspace:0pt;">
|
||||
<tr>
|
||||
<td bgcolor="E5E5E5">
|
||||
<table border="0" cellpadding="0" cellspacing="0" width="100%" class="footer-table" style="margin-top: 0;border-collaps:collaps; mso-table-lspace:0pt; mso-table-rspace:0pt;" >
|
||||
<tbody>
|
||||
<tr>
|
||||
<td class="corner-td" align="left"></td>
|
||||
<!--[if mso | IE]>
|
||||
<table role="presentation" border="0" cellpadding="0" cellspacing="0"><tr><td style="vertical-align:top;display:table-row !important">
|
||||
<![endif]-->
|
||||
<td height="146" width="190" class="footer-td" style="margin-bottom: 12px;" valign="top" align="left">
|
||||
<table style="border-collaps:collaps; mso-table-lspace:0pt; mso-table-rspace:0pt;">
|
||||
<tbody>
|
||||
<tr>
|
||||
<td>
|
||||
<h4 style=" font-family: Inter;
|
||||
font-size: 16px;
|
||||
font-style: normal;
|
||||
font-weight: 600;
|
||||
line-height: 36px;
|
||||
mso-line-height-rule:exactly;
|
||||
letter-spacing: 0em;
|
||||
text-align: left;
|
||||
color:#6D6666;">Get in touch</h4>
|
||||
<a style="text-decoration: none;color: none;" href="mailto:support@kerberos.io">
|
||||
<p style=" font-family: Inter;
|
||||
font-size: 14px;
|
||||
font-style: normal;
|
||||
font-weight: 400;
|
||||
line-height: 16px;
|
||||
mso-line-height-rule:exactly;
|
||||
letter-spacing: 0em;
|
||||
text-align: left;
|
||||
color: #A69D9D;">support@kerberos.io</p>
|
||||
</a>
|
||||
<p style=" font-family: Inter;
|
||||
font-size: 14px;
|
||||
font-style: normal;
|
||||
font-weight: 400;
|
||||
line-height: 16px;
|
||||
mso-line-height-rule:exactly;
|
||||
letter-spacing: 0em;
|
||||
text-align: left;
|
||||
color: #A69D9D;">9000 Ghent, BE</p>
|
||||
|
||||
<a style="text-decoration: none;color: none;" href="https://kerberos.io/">
|
||||
<p style=" font-family: Inter;
|
||||
font-size: 14px;
|
||||
font-style: normal;
|
||||
font-weight: 400;
|
||||
line-height: 24px;
|
||||
mso-line-height-rule:exactly;
|
||||
letter-spacing: 0em;
|
||||
text-align: left;
|
||||
color: #A69D9D;">https://kerberos.io</p>
|
||||
</a>
|
||||
</td>
|
||||
</tr>
|
||||
</tbody>
|
||||
</table>
|
||||
</td>
|
||||
<!--[if mso | IE]>
|
||||
<table role="presentation" border="0" cellpadding="0" cellspacing="0"><tr><td style="vertical-align:top;display:table-row !important">
|
||||
<![endif]-->
|
||||
<td class="footer-td" style="border-radius: 4px;padding-left: 0;padding-right: 0;padding-top: 0;padding-bottom: 0; margin-bottom: 12px;" valign="top" align="left">
|
||||
<table style="border-collaps:collaps; mso-table-lspace:0pt; mso-table-rspace:0pt;">
|
||||
<tbody>
|
||||
<tr>
|
||||
<td>
|
||||
<h4 style=" font-family: Inter;
|
||||
font-size: 16px;
|
||||
font-style: normal;
|
||||
font-weight: 600;
|
||||
line-height: 36px;
|
||||
mso-line-height-rule:exactly;
|
||||
letter-spacing: 0em;
|
||||
text-align: left;
|
||||
color:#6D6666;">About Kerberos</h4>
|
||||
<p style=" font-family: Inter;
|
||||
font-size: 14px;
|
||||
font-style: normal;
|
||||
font-weight: 400;
|
||||
line-height: 24px;
|
||||
mso-line-height-rule:exactly;
|
||||
letter-spacing: 0em;
|
||||
text-align: left;
|
||||
color: #A69D9D;">Welcome to the revolutionary video analytics and video management platform. Open, modular, and extensible for everyone, anywhere.</p>
|
||||
|
||||
|
||||
<p style="margin-top: 12px;">
|
||||
<a href="https://twitter.com/kerberosio" style="text-decoration: none;color: none;">
|
||||
<img width="24" height="24" alt="Twitter" src="https://kerberos.io/images/email/twitter.png"/>
|
||||
</a>
|
||||
<a href="https://reddit.com/r/kerberos_io" style="text-decoration: none;color: none;">
|
||||
<img g width="24" height="24" alt="Reddit" src="https://kerberos.io/images/email/reddit.png"/>
|
||||
</a>
|
||||
<a href="https://www.youtube.com/channel/UCnd9q7iRNNw4W95eQwQuECA" style="text-decoration: none;color: none;">
|
||||
<img g width="24" height="24" alt="Youtube" src="https://kerberos.io/images/email/youtube.png"/>
|
||||
</a>
|
||||
<a href="https://github.com/kerberos-io" style="text-decoration: none;color: none;">
|
||||
<img g width="24" height="24" alt="Github" src="https://kerberos.io/images/email/github.png"/>
|
||||
</a>
|
||||
</p>
|
||||
</td>
|
||||
</tr>
|
||||
</tbody>
|
||||
</table>
|
||||
</td>
|
||||
<td class="corner-td" align="right"></td>
|
||||
</tr>
|
||||
</tbody>
|
||||
</table>
|
||||
<table style="border-collaps:collaps; mso-table-lspace:0pt; mso-table-rspace:0pt;">
|
||||
<tbody>
|
||||
<tr style="height: 50px">
|
||||
<td></td>
|
||||
</tr>
|
||||
</tbody>
|
||||
</table>
|
||||
</td>
|
||||
</tr>
|
||||
</table>
|
||||
</body>
|
||||
</html>
|
||||
21
charts/hub/custom-layout/templates/share_case.txt
Normal file
21
charts/hub/custom-layout/templates/share_case.txt
Normal file
@@ -0,0 +1,21 @@
|
||||
Kerberos.io
|
||||
------------
|
||||
|
||||
A case has been shared with you
|
||||
{{user}} shared a case with you
|
||||
|
||||
Open the shared case
|
||||
{{user}} has shared a case with you. Open the link below to access it — you'll be asked to request a one-time verification code from the share page.
|
||||
{{url}}
|
||||
|
||||
This link will expire in {{expiry}}.
|
||||
|
||||
Get in touch
|
||||
------------
|
||||
support@kerberos.io
|
||||
9000 Ghent, BE
|
||||
https://kerberos.io
|
||||
|
||||
About Kerberos
|
||||
------------
|
||||
Welcome to the revolutionary video analytics and video management platform. Open, modular, and extensible for everyone, anywhere.
|
||||
425
charts/hub/custom-layout/templates/share_case_otp.html
Normal file
425
charts/hub/custom-layout/templates/share_case_otp.html
Normal file
@@ -0,0 +1,425 @@
|
||||
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
|
||||
<html xmlns="http://www.w3.org/1999/xhtml">
|
||||
<head>
|
||||
|
||||
<meta http-equiv="X-UA-Compatible" content="IE=edge" />
|
||||
<meta http-equiv="Content-Type" content="text/html; charset=utf-8" />
|
||||
<meta
|
||||
name="viewport"
|
||||
content="width=device-width, initial-scale=1, minimum-scale=1, maximum-scale=1"
|
||||
/>
|
||||
<meta name="description" content="Kerberos.io Mailing">
|
||||
<style type="text/css">
|
||||
|
||||
@font-face {
|
||||
font-family: 'Inter';
|
||||
font-style: normal;
|
||||
font-weight: 400;
|
||||
font-display: swap;
|
||||
src: url("https://kerberos.io/dist/fonts/Inter-Regular.woff?v=/dist/fonts/Inter-Regular.woff2?v=3.183.18") format("woff2"),
|
||||
url("https://kerberos.io/dist/fonts/Inter-Regular.woff?v=/dist/fonts/Inter-Regular.woff2?v=3.183.18") format("woff");
|
||||
}
|
||||
|
||||
@font-face {
|
||||
font-family: 'Inter';
|
||||
font-style: normal;
|
||||
font-weight: 500;
|
||||
font-display: swap;
|
||||
src: url("https://kerberos.io/dist/fonts/Inter-Medium.woff2?v=3.18") format("woff2"),
|
||||
url("https://kerberos.io/dist/fonts/Inter-Medium.woff?v=3.18") format("woff");
|
||||
}
|
||||
|
||||
@font-face {
|
||||
font-family: 'Inter';
|
||||
font-style: normal;
|
||||
font-weight: 600;
|
||||
font-display: swap;
|
||||
src: url("https://kerberos.io/dist/fonts/Inter-SemiBold.woff2?v=3.18") format("woff2"),
|
||||
url("https://kerberos.io/dist/fonts/Inter-SemiBold.woff?v=3.18") format("woff");
|
||||
}
|
||||
|
||||
@font-face {
|
||||
font-family: 'Inter var';
|
||||
font-weight: 100 900;
|
||||
font-display: swap;
|
||||
font-style: normal;
|
||||
font-named-instance: 'Regular';
|
||||
src: url("https://kerberos.io/dist/fonts/Inter-roman.var.woff2?v=3.18") format("woff2");
|
||||
}
|
||||
|
||||
body{
|
||||
background: #E5E5E5;
|
||||
margin-top:0;
|
||||
margin-bottom: 0;
|
||||
margin-right: 0;
|
||||
margin-left: 0;
|
||||
padding-top: 0;
|
||||
padding-left: 0;
|
||||
padding-right: 0;
|
||||
padding-bottom: 0;
|
||||
font-family: 'Inter';
|
||||
}
|
||||
a, a:hover, a:active {
|
||||
color: #262424;
|
||||
text-decoration: none;
|
||||
}
|
||||
|
||||
.corner-td{
|
||||
width: 60px;
|
||||
}
|
||||
|
||||
table {border-collapse:separate;max-width: 850px; margin: 0 auto; width: 100%;}
|
||||
.ExternalClass p, .ExternalClass span, .ExternalClass font, .ExternalClass td {line-height: 100%;}
|
||||
.ExternalClass {width: 100%;}
|
||||
@media screen and (max-width:500px){
|
||||
.tab-td{
|
||||
padding-left: 10px!important;
|
||||
}
|
||||
.tab-td a h4{
|
||||
font-size: 14px!important;
|
||||
}
|
||||
.corner-td{
|
||||
width: 20px!important;
|
||||
}
|
||||
.company-name-td h3{
|
||||
font-size: 16px!important;
|
||||
}
|
||||
table.header-table{
|
||||
padding-top: 8px!important;
|
||||
padding-right: 0px!important;
|
||||
padding-bottom: 24px!important;
|
||||
padding-left: 0px!important;
|
||||
}
|
||||
.colored-card-td h4{
|
||||
font-size: 14px!important;
|
||||
}
|
||||
.colored-card-td h2{
|
||||
font-size: 20px!important;
|
||||
}
|
||||
.colored-card-td a p{
|
||||
font-size: 12px!important;
|
||||
width: 143px!important;
|
||||
}
|
||||
.colored-card-td{
|
||||
padding-top: 24px!important;
|
||||
padding-right: 24px!important;
|
||||
padding-bottom: 24px!important;
|
||||
padding-left: 24px!important;
|
||||
}
|
||||
.colorless-card-td{
|
||||
padding-top: 24px!important;
|
||||
padding-right: 24px!important;
|
||||
padding-bottom: 24px!important;
|
||||
padding-left: 24px!important;
|
||||
}
|
||||
.colorless-card-td h3{
|
||||
font-size: 18px!important;
|
||||
}
|
||||
.colorless-card-td p{
|
||||
font-size: 14px!important;
|
||||
}
|
||||
.colorless-card-table{
|
||||
margin-left: 0px!important;
|
||||
margin-right: 0px!important;
|
||||
margin-top: 24px!important;
|
||||
margin-bottom: 24px!important;
|
||||
}
|
||||
.footer-td{
|
||||
display: table-row!important;
|
||||
}
|
||||
}
|
||||
@media screen and (max-width:600px) {
|
||||
.footer-td{
|
||||
display: table-row!important;
|
||||
}
|
||||
}
|
||||
@media screen and (max-width:650px) {
|
||||
.footer-table{
|
||||
margin-left: 0px!important;
|
||||
margin-right: 0px!important;
|
||||
margin-top: 0px!important;
|
||||
margin-bottom: 36px!important;
|
||||
}
|
||||
}
|
||||
</style>
|
||||
</head>
|
||||
<body height="100%" width="100%">
|
||||
<table border="0" cellpadding="0" cellspacing="0" width="100%" bgcolor="E5E5E5" style="border-collaps:collaps; mso-table-lspace:0pt; mso-table-rspace:0pt;">
|
||||
<tr>
|
||||
<td bgcolor="E5E5E5">
|
||||
<table border="0" cellpadding="0" cellspacing="0" width="100%" height="36" class="header-table" style="padding-top: 36px ;padding-right: 0;padding-bottom: 36px;padding-left: 0;border-collaps:collaps; mso-table-lspace:0pt; mso-table-rspace:0pt;">
|
||||
<tbody>
|
||||
<tr>
|
||||
<td class="corner-td" align="left"></td>
|
||||
<td width="48" height="36" align="left"><img alt="Kerberos.io" width="36" height="36" src="https://kerberos.io/images/email/kerberos.png"/></td>
|
||||
<td height="36" align="left" class="company-name-td">
|
||||
<h3 width="36" height="36" style=" font-family: Inter;
|
||||
font-size: 20px;
|
||||
font-style: normal;
|
||||
font-weight: 600;
|
||||
line-height: 24px;
|
||||
mso-line-height-rule:exactly;
|
||||
letter-spacing: 0em;
|
||||
text-align: left;
|
||||
color: #262424;">Kerberos.io</h3>
|
||||
</td>
|
||||
<td height="36" width="36" style="padding-left: 36px;" class="tab-td" align="right">
|
||||
<a style="text-decoration: none;color: none;" href={{tab1_href}}>
|
||||
<h4 style="font-family: Inter;
|
||||
font-size: 16px;
|
||||
font-style: normal;
|
||||
font-weight: 500;
|
||||
line-height: 36px;
|
||||
mso-line-height-rule:exactly;
|
||||
letter-spacing: 0em;
|
||||
text-align: right;
|
||||
color: #6D6666;">{{tab1_title}}</h4>
|
||||
</a>
|
||||
</td>
|
||||
<td height="36" width="36" style="padding-left: 36px;" class="tab-td" align="right" >
|
||||
<a style="text-decoration: none;color: none;" href={{tab2_href}}>
|
||||
<h4 style="font-family: Inter;
|
||||
font-size: 16px;
|
||||
font-style: normal;
|
||||
font-weight: 500;
|
||||
line-height: 36px;
|
||||
mso-line-height-rule:exactly;
|
||||
letter-spacing: 0em;
|
||||
text-align: right;
|
||||
color: #6D6666;">{{tab2_title}}</h4>
|
||||
</a>
|
||||
</td>
|
||||
<td class="corner-td" align="right"></td>
|
||||
</tr>
|
||||
</tbody>
|
||||
</table>
|
||||
</td>
|
||||
</tr>
|
||||
</table>
|
||||
<table border="0" cellpadding="0" cellspacing="0" width="100%" bgcolor="E5E5E5" style="border-collaps:collaps; mso-table-lspace:0pt; mso-table-rspace:0pt;">
|
||||
<tr>
|
||||
<td bgcolor="E5E5E5">
|
||||
<table border="0" cellpadding="0" cellspacing="0" width="100%" style="border-collaps:collaps; mso-table-lspace:0pt; mso-table-rspace:0pt;" >
|
||||
<tbody>
|
||||
<tr>
|
||||
<td class="corner-td" align="left"></td>
|
||||
<td class="colored-card-td" bgcolor="#57356B" style="padding-left: 48px;padding-right: 48px;padding-top: 48px;padding-bottom: 48px;border-radius: 4px;background-color:#57356B;">
|
||||
<h2 style=" font-family: Inter;
|
||||
font-size: 24px;
|
||||
font-style: normal;
|
||||
font-weight: 600;
|
||||
line-height: 36px;
|
||||
mso-line-height-rule:exactly;
|
||||
letter-spacing: 0em;
|
||||
text-align: left;
|
||||
color:#FFFFFF;
|
||||
padding-top: 12px;
|
||||
margin-bottom: 0;
|
||||
padding-bottom: 0;
|
||||
padding-left: 0;
|
||||
padding-right: 0;">Verify your access</h2>
|
||||
<h4 style="font-family: Inter;
|
||||
font-size: 16px;
|
||||
font-style: normal;
|
||||
font-weight: 400;
|
||||
line-height: 24px;
|
||||
mso-line-height-rule:exactly;
|
||||
letter-spacing: 0em;
|
||||
text-align: left;
|
||||
color:#b09fb9;">Use the code below to open the shared case</h4>
|
||||
</td>
|
||||
<td class="corner-td" align="right"></td>
|
||||
</tr>
|
||||
</tbody>
|
||||
</table>
|
||||
</td>
|
||||
</tr>
|
||||
</table>
|
||||
<table border="0" cellpadding="0" cellspacing="0" width="100%" bgcolor="E5E5E5" style="border-collaps:collaps; mso-table-lspace:0pt; mso-table-rspace:0pt;">
|
||||
<tr>
|
||||
<td bgcolor="E5E5E5">
|
||||
<table border="0" cellpadding="0" cellspacing="0" width="100%" class="colorless-card-table" style="margin-top: 36px;margin-bottom: 36px;margin-left: 0;margin-right: 0;border-collaps:collaps; mso-table-lspace:0pt; mso-table-rspace:0pt;" >
|
||||
<tbody>
|
||||
<tr>
|
||||
<td class="corner-td" align="left"></td>
|
||||
<td class="colorless-card-td" bgcolor="#FFFFFF" style="background-color:#FFFFFF;padding-top: 36px;padding-right: 43px;padding-bottom: 25px;padding-left: 43px;border-radius: 4px;">
|
||||
<h3 style=" font-family: Inter;
|
||||
font-size: 20px;
|
||||
font-style: normal;
|
||||
font-weight: 600;
|
||||
line-height: 36px;
|
||||
mso-line-height-rule:exactly;
|
||||
letter-spacing: 0em;
|
||||
text-align: left;
|
||||
color: #262424;
|
||||
width: 280px">Your verification code</h3>
|
||||
<p style=" font-family: Inter;
|
||||
font-size: 14px;
|
||||
font-style: normal;
|
||||
font-weight: 400;
|
||||
line-height: 24px;
|
||||
mso-line-height-rule:exactly;
|
||||
letter-spacing: 0em;
|
||||
text-align: left;
|
||||
color: #6D6666;
|
||||
margin-top: 12px;">Enter the code below on the share page to access the case.</p>
|
||||
|
||||
<p style="font-family: 'Courier New', Courier, monospace;
|
||||
font-size: 32px;
|
||||
font-style: normal;
|
||||
font-weight: 600;
|
||||
line-height: 40px;
|
||||
mso-line-height-rule:exactly;
|
||||
letter-spacing: 8px;
|
||||
text-align: center;
|
||||
color:#262424;
|
||||
background-color: #F2F0F4;
|
||||
padding-top: 16px;
|
||||
padding-bottom: 16px;
|
||||
padding-right: 16px;
|
||||
padding-left: 16px;
|
||||
margin-top: 16px;
|
||||
margin-bottom: 16px;
|
||||
border-radius: 4px;">{{code}}</p>
|
||||
|
||||
<p style=" font-family: Inter;
|
||||
font-size: 14px;
|
||||
font-style: normal;
|
||||
font-weight: 400;
|
||||
line-height: 24px;
|
||||
mso-line-height-rule:exactly;
|
||||
letter-spacing: 0em;
|
||||
text-align: left;
|
||||
color: #6D6666;">This code expires in {{expiry}}. If you didn't request this, you can safely ignore this email.</p>
|
||||
</td>
|
||||
<td class="corner-td" align="right"></td>
|
||||
</tr>
|
||||
</tbody>
|
||||
</table>
|
||||
</td>
|
||||
</tr>
|
||||
</table>
|
||||
<table border="0" cellpadding="0" cellspacing="0" width="100%" bgcolor="E5E5E5" style="border-collaps:collaps; mso-table-lspace:0pt; mso-table-rspace:0pt;">
|
||||
<tr>
|
||||
<td bgcolor="E5E5E5">
|
||||
<table border="0" cellpadding="0" cellspacing="0" width="100%" class="footer-table" style="margin-top: 0;border-collaps:collaps; mso-table-lspace:0pt; mso-table-rspace:0pt;" >
|
||||
<tbody>
|
||||
<tr>
|
||||
<td class="corner-td" align="left"></td>
|
||||
<!--[if mso | IE]>
|
||||
<table role="presentation" border="0" cellpadding="0" cellspacing="0"><tr><td style="vertical-align:top;display:table-row !important">
|
||||
<![endif]-->
|
||||
<td height="146" width="190" class="footer-td" style="margin-bottom: 12px;" valign="top" align="left">
|
||||
<table style="border-collaps:collaps; mso-table-lspace:0pt; mso-table-rspace:0pt;">
|
||||
<tbody>
|
||||
<tr>
|
||||
<td>
|
||||
<h4 style=" font-family: Inter;
|
||||
font-size: 16px;
|
||||
font-style: normal;
|
||||
font-weight: 600;
|
||||
line-height: 36px;
|
||||
mso-line-height-rule:exactly;
|
||||
letter-spacing: 0em;
|
||||
text-align: left;
|
||||
color:#6D6666;">Get in touch</h4>
|
||||
<a style="text-decoration: none;color: none;" href="mailto:support@kerberos.io">
|
||||
<p style=" font-family: Inter;
|
||||
font-size: 14px;
|
||||
font-style: normal;
|
||||
font-weight: 400;
|
||||
line-height: 16px;
|
||||
mso-line-height-rule:exactly;
|
||||
letter-spacing: 0em;
|
||||
text-align: left;
|
||||
color: #A69D9D;">support@kerberos.io</p>
|
||||
</a>
|
||||
<p style=" font-family: Inter;
|
||||
font-size: 14px;
|
||||
font-style: normal;
|
||||
font-weight: 400;
|
||||
line-height: 16px;
|
||||
mso-line-height-rule:exactly;
|
||||
letter-spacing: 0em;
|
||||
text-align: left;
|
||||
color: #A69D9D;">9000 Ghent, BE</p>
|
||||
|
||||
<a style="text-decoration: none;color: none;" href="https://kerberos.io/">
|
||||
<p style=" font-family: Inter;
|
||||
font-size: 14px;
|
||||
font-style: normal;
|
||||
font-weight: 400;
|
||||
line-height: 24px;
|
||||
mso-line-height-rule:exactly;
|
||||
letter-spacing: 0em;
|
||||
text-align: left;
|
||||
color: #A69D9D;">https://kerberos.io</p>
|
||||
</a>
|
||||
</td>
|
||||
</tr>
|
||||
</tbody>
|
||||
</table>
|
||||
</td>
|
||||
<!--[if mso | IE]>
|
||||
<table role="presentation" border="0" cellpadding="0" cellspacing="0"><tr><td style="vertical-align:top;display:table-row !important">
|
||||
<![endif]-->
|
||||
<td class="footer-td" style="border-radius: 4px;padding-left: 0;padding-right: 0;padding-top: 0;padding-bottom: 0; margin-bottom: 12px;" valign="top" align="left">
|
||||
<table style="border-collaps:collaps; mso-table-lspace:0pt; mso-table-rspace:0pt;">
|
||||
<tbody>
|
||||
<tr>
|
||||
<td>
|
||||
<h4 style=" font-family: Inter;
|
||||
font-size: 16px;
|
||||
font-style: normal;
|
||||
font-weight: 600;
|
||||
line-height: 36px;
|
||||
mso-line-height-rule:exactly;
|
||||
letter-spacing: 0em;
|
||||
text-align: left;
|
||||
color:#6D6666;">About Kerberos</h4>
|
||||
<p style=" font-family: Inter;
|
||||
font-size: 14px;
|
||||
font-style: normal;
|
||||
font-weight: 400;
|
||||
line-height: 24px;
|
||||
mso-line-height-rule:exactly;
|
||||
letter-spacing: 0em;
|
||||
text-align: left;
|
||||
color: #A69D9D;">Welcome to the revolutionary video analytics and video management platform. Open, modular, and extensible for everyone, anywhere.</p>
|
||||
|
||||
|
||||
<p style="margin-top: 12px;">
|
||||
<a href="https://twitter.com/kerberosio" style="text-decoration: none;color: none;">
|
||||
<img width="24" height="24" alt="Twitter" src="https://kerberos.io/images/email/twitter.png"/>
|
||||
</a>
|
||||
<a href="https://reddit.com/r/kerberos_io" style="text-decoration: none;color: none;">
|
||||
<img g width="24" height="24" alt="Reddit" src="https://kerberos.io/images/email/reddit.png"/>
|
||||
</a>
|
||||
<a href="https://www.youtube.com/channel/UCnd9q7iRNNw4W95eQwQuECA" style="text-decoration: none;color: none;">
|
||||
<img g width="24" height="24" alt="Youtube" src="https://kerberos.io/images/email/youtube.png"/>
|
||||
</a>
|
||||
<a href="https://github.com/kerberos-io" style="text-decoration: none;color: none;">
|
||||
<img g width="24" height="24" alt="Github" src="https://kerberos.io/images/email/github.png"/>
|
||||
</a>
|
||||
</p>
|
||||
</td>
|
||||
</tr>
|
||||
</tbody>
|
||||
</table>
|
||||
</td>
|
||||
<td class="corner-td" align="right"></td>
|
||||
</tr>
|
||||
</tbody>
|
||||
</table>
|
||||
<table style="border-collaps:collaps; mso-table-lspace:0pt; mso-table-rspace:0pt;">
|
||||
<tbody>
|
||||
<tr style="height: 50px">
|
||||
<td></td>
|
||||
</tr>
|
||||
</tbody>
|
||||
</table>
|
||||
</td>
|
||||
</tr>
|
||||
</table>
|
||||
</body>
|
||||
</html>
|
||||
21
charts/hub/custom-layout/templates/share_case_otp.txt
Normal file
21
charts/hub/custom-layout/templates/share_case_otp.txt
Normal file
@@ -0,0 +1,21 @@
|
||||
Kerberos.io
|
||||
------------
|
||||
|
||||
Verify your access
|
||||
Use the code below to open the shared case
|
||||
|
||||
Your verification code
|
||||
{{code}}
|
||||
|
||||
Enter this code on the share page to access the case. This code expires in {{expiry}}.
|
||||
If you didn't request this, you can safely ignore this email.
|
||||
|
||||
Get in touch
|
||||
------------
|
||||
support@kerberos.io
|
||||
9000 Ghent, BE
|
||||
https://kerberos.io
|
||||
|
||||
About Kerberos
|
||||
------------
|
||||
Welcome to the revolutionary video analytics and video management platform. Open, modular, and extensible for everyone, anywhere.
|
||||
48
charts/hub/templates/_helpers.tpl
Normal file
48
charts/hub/templates/_helpers.tpl
Normal file
@@ -0,0 +1,48 @@
|
||||
{{/* Build the path to the configured MongoDB CA bundle. */}}
|
||||
{{- define "hub.mongodb.tlsCAFile" -}}
|
||||
{{- if and .Values.mongodb.tls.enabled .Values.mongodb.tls.existingSecret .Values.mongodb.tls.caFileName -}}
|
||||
{{- printf "%s/%s" .Values.mongodb.tls.mountPath .Values.mongodb.tls.caFileName | clean -}}
|
||||
{{- end -}}
|
||||
{{- end -}}
|
||||
|
||||
{{/* Add TLS options to a configured MongoDB URI unless they are already present. */}}
|
||||
{{- define "hub.mongodb.uri" -}}
|
||||
{{- $uri := .Values.mongodb.uri | default "" -}}
|
||||
{{- if and .Values.mongodb.tls.enabled $uri -}}
|
||||
{{- if not (regexMatch "(?i)(^|[?&])tls=" $uri) -}}
|
||||
{{- $separator := "?" -}}
|
||||
{{- if contains "?" $uri -}}
|
||||
{{- $separator = "&" -}}
|
||||
{{- end -}}
|
||||
{{- if or (hasSuffix "?" $uri) (hasSuffix "&" $uri) -}}
|
||||
{{- $separator = "" -}}
|
||||
{{- end -}}
|
||||
{{- $uri = printf "%s%stls=true" $uri $separator -}}
|
||||
{{- end -}}
|
||||
{{- $caFile := include "hub.mongodb.tlsCAFile" . -}}
|
||||
{{- if and $caFile (not (regexMatch "(?i)(^|[?&])tlsCAFile=" $uri)) -}}
|
||||
{{- $separator := "&" -}}
|
||||
{{- if not (contains "?" $uri) -}}
|
||||
{{- $separator = "?" -}}
|
||||
{{- else if or (hasSuffix "?" $uri) (hasSuffix "&" $uri) -}}
|
||||
{{- $separator = "" -}}
|
||||
{{- end -}}
|
||||
{{- $uri = printf "%s%stlsCAFile=%s" $uri $separator $caFile -}}
|
||||
{{- end -}}
|
||||
{{- end -}}
|
||||
{{- $uri -}}
|
||||
{{- end -}}
|
||||
|
||||
{{/* Render the shared MongoDB CA Secret volume. */}}
|
||||
{{- define "hub.mongodb.tlsVolume" -}}
|
||||
- name: mongodb-tls
|
||||
secret:
|
||||
secretName: {{ .Values.mongodb.tls.existingSecret }}
|
||||
{{- end -}}
|
||||
|
||||
{{/* Render the shared MongoDB CA volume mount. */}}
|
||||
{{- define "hub.mongodb.tlsVolumeMount" -}}
|
||||
- name: mongodb-tls
|
||||
mountPath: {{ .Values.mongodb.tls.mountPath }}
|
||||
readOnly: true
|
||||
{{- end -}}
|
||||
@@ -14,6 +14,14 @@ spec:
|
||||
labels:
|
||||
app: admin
|
||||
spec:
|
||||
{{- with .Values.admin.volumes }}
|
||||
volumes:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- with .Values.admin.topologySpreadConstraints }}
|
||||
topologySpreadConstraints:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
containers:
|
||||
- name: admin
|
||||
image: "{{ .Values.global.imageRegistry }}{{ .Values.admin.repository }}:{{ .Values.admin.tag }}"
|
||||
@@ -22,6 +30,10 @@ spec:
|
||||
resources:
|
||||
{{- toYaml . | nindent 12 }}
|
||||
{{- end }}
|
||||
{{- with .Values.admin.volumeMounts }}
|
||||
volumeMounts:
|
||||
{{- toYaml . | nindent 12 }}
|
||||
{{- end }}
|
||||
ports:
|
||||
- name: http
|
||||
containerPort: 80
|
||||
|
||||
@@ -46,6 +46,14 @@ spec:
|
||||
labels:
|
||||
k8s-app: oauth2-proxy-admin
|
||||
spec:
|
||||
{{- with .Values.admin.oauth2Proxy.volumes }}
|
||||
volumes:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- with .Values.admin.oauth2Proxy.topologySpreadConstraints }}
|
||||
topologySpreadConstraints:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
containers:
|
||||
- args:
|
||||
- --provider=github
|
||||
@@ -53,6 +61,10 @@ spec:
|
||||
- --upstream=file:///dev/null
|
||||
- --http-address=0.0.0.0:4180
|
||||
- --skip-auth-preflight=true
|
||||
{{- with .Values.admin.oauth2Proxy.volumeMounts }}
|
||||
volumeMounts:
|
||||
{{- toYaml . | nindent 12 }}
|
||||
{{- end }}
|
||||
env:
|
||||
- name: OAUTH2_PROXY_CLIENT_ID
|
||||
value: "{{ .Values.admin.oauth2Proxy.github.clientId }}"
|
||||
|
||||
@@ -4,11 +4,15 @@ metadata:
|
||||
name: mongodb-config
|
||||
namespace: {{ .Release.Namespace }}
|
||||
data:
|
||||
MONGODB_URI: "{{ .Values.mongodb.uri }}"
|
||||
MONGODB_URI: {{ include "hub.mongodb.uri" . | quote }}
|
||||
MONGODB_HOST: "{{ .Values.mongodb.host }}"
|
||||
MONGODB_AUTHENTICATION_MECHANISM: "{{ .Values.mongodb.authenticationMechanism }}"
|
||||
MONGODB_DATABASE_CREDENTIALS: "{{ .Values.mongodb.adminDatabase }}"
|
||||
MONGODB_USERNAME: "{{ .Values.mongodb.username }}"
|
||||
MONGODB_PASSWORD: "{{ .Values.mongodb.password }}"
|
||||
MONGODB_RETRY_WRITES: "{{ .Values.mongodb.retryWrites }}"
|
||||
MONGODB_FLAVOR: "{{ .Values.mongodb.flavor | default "mongodb" }}"
|
||||
MONGODB_TLS: "{{ .Values.mongodb.tls.enabled }}"
|
||||
MONGODB_TLS_CA_FILE: {{ include "hub.mongodb.tlsCAFile" . | quote }}
|
||||
MONGODB_TLS_INSECURE_SKIP_VERIFY: "{{ .Values.mongodb.tls.insecureSkipVerify }}"
|
||||
MONGODB_DATABASE_CLOUD: "Kerberos"
|
||||
|
||||
@@ -1,4 +1,5 @@
|
||||
{{- if or (eq .Values.mode "all") (eq .Values.mode "ui") -}}
|
||||
{{- if .Values.kerberoshub.api.serviceEnabled }}
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
@@ -18,6 +19,7 @@ spec:
|
||||
protocol: TCP
|
||||
selector:
|
||||
app: hub-api
|
||||
{{- end }}
|
||||
{{ if ne .Values.ingress "" }}
|
||||
---
|
||||
{{ if .Capabilities.APIVersions.Has "networking.k8s.io/v1" }}
|
||||
@@ -129,7 +131,8 @@ spec:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- $serverTLS := .Values.kerberoshub.api.serverTLS }}
|
||||
{{- if or .Values.kerberoshub.api.volumes (and $serverTLS.enabled $serverTLS.secretName) }}
|
||||
{{- $mongodbTLS := .Values.mongodb.tls }}
|
||||
{{- if or .Values.kerberoshub.api.volumes (and $serverTLS.enabled $serverTLS.secretName) (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
|
||||
volumes:
|
||||
{{- with .Values.kerberoshub.api.volumes }}
|
||||
{{- toYaml . | nindent 8 }}
|
||||
@@ -139,6 +142,13 @@ spec:
|
||||
secret:
|
||||
secretName: {{ $serverTLS.secretName }}
|
||||
{{- end }}
|
||||
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
|
||||
{{- include "hub.mongodb.tlsVolume" . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- with .Values.kerberoshub.api.topologySpreadConstraints }}
|
||||
topologySpreadConstraints:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
containers:
|
||||
- name: hub-api
|
||||
@@ -151,7 +161,7 @@ spec:
|
||||
ports:
|
||||
- containerPort: 80
|
||||
name: http
|
||||
{{- if or .Values.kerberoshub.api.volumeMounts (and $serverTLS.enabled $serverTLS.secretName) }}
|
||||
{{- if or .Values.kerberoshub.api.volumeMounts (and $serverTLS.enabled $serverTLS.secretName) (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
|
||||
volumeMounts:
|
||||
{{- with .Values.kerberoshub.api.volumeMounts}}
|
||||
{{- toYaml . | nindent 12 }}
|
||||
@@ -161,6 +171,9 @@ spec:
|
||||
mountPath: {{ $serverTLS.mountPath }}
|
||||
readOnly: true
|
||||
{{- end }}
|
||||
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
|
||||
{{- include "hub.mongodb.tlsVolumeMount" . | nindent 12 }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
# Mongodb - loaded from ConfigMap
|
||||
envFrom:
|
||||
@@ -181,6 +194,23 @@ spec:
|
||||
value: "{{ .Values.kerberoshub.api.schema }}://{{ .Values.kerberoshub.api.url }}"
|
||||
- name: PUBLIC_URL
|
||||
value: "{{ .Values.kerberoshub.frontend.schema }}://{{ .Values.kerberoshub.frontend.url }}"
|
||||
- name: REFRESH_COOKIE_SECURE
|
||||
value: {{ eq .Values.kerberoshub.api.schema "https" | quote }}
|
||||
{{- $corsOrigins := list (printf "%s://%s" .Values.kerberoshub.frontend.schema .Values.kerberoshub.frontend.url) }}
|
||||
{{- with .Values.kerberoshub.frontend.legacyUrl }}
|
||||
{{- $corsOrigins = append $corsOrigins (printf "%s://%s" $.Values.kerberoshub.frontend.schema .) }}
|
||||
{{- end }}
|
||||
{{- range .Values.kerberoshub.frontend.domains }}
|
||||
{{- $corsOrigins = append $corsOrigins (printf "%s://%s" $.Values.kerberoshub.frontend.schema .) }}
|
||||
{{- end }}
|
||||
{{- if and .Values.kerberoshub.frontend.multiTenant .Values.kerberoshub.frontend.tenantBaseDomain }}
|
||||
{{- $corsOrigins = append $corsOrigins (printf "%s://*.%s" .Values.kerberoshub.frontend.schema .Values.kerberoshub.frontend.tenantBaseDomain) }}
|
||||
{{- end }}
|
||||
{{- if and .Values.kerberoshub.frontend.demoEnabled .Values.kerberoshub.frontend.demoUrl }}
|
||||
{{- $corsOrigins = append $corsOrigins (printf "%s://%s" .Values.kerberoshub.frontend.schema .Values.kerberoshub.frontend.demoUrl) }}
|
||||
{{- end }}
|
||||
- name: CORS_ALLOWED_ORIGINS
|
||||
value: {{ join "," $corsOrigins | quote }}
|
||||
{{ if .Values.isPrivate }}
|
||||
- name: KERBEROS_PRIVATE_CLOUD
|
||||
value: "true"
|
||||
@@ -194,6 +224,20 @@ spec:
|
||||
value: "{{ .Values.kerberoshub.api.fallbackLanguage }}"
|
||||
- name: API_KEY
|
||||
value: "{{ .Values.kerberoshub.api.apiKey }}"
|
||||
|
||||
# MQTT credentials (served via /runtime/config to authenticated
|
||||
# frontend clients; no longer exposed in the public env.js).
|
||||
- name: MQTT_USERNAME
|
||||
value: "{{ .Values.mqtt.username }}"
|
||||
- name: MQTT_PASSWORD
|
||||
value: "{{ .Values.mqtt.password }}"
|
||||
|
||||
# TURN credentials (served via /runtime/config to authenticated
|
||||
# frontend clients; no longer exposed in the public env.js).
|
||||
- name: TURN_USERNAME
|
||||
value: "{{ .Values.turn.username }}"
|
||||
- name: TURN_PASSWORD
|
||||
value: "{{ .Values.turn.password }}"
|
||||
{{- if .Values.kerberoshub.api.serverTLS.enabled }}
|
||||
- name: TLS_CERT_FILE
|
||||
value: "{{ .Values.kerberoshub.api.serverTLS.certFile }}"
|
||||
@@ -239,6 +283,19 @@ spec:
|
||||
- name: QUEUE_NAME
|
||||
value: "{{ .Values.queueName }}"
|
||||
|
||||
# Deployment-global workflow definitions (WORKFLOW_DEFINITIONS): the
|
||||
# SAME set the workflows engine consumes, assembled from the enabled
|
||||
# definitions under kerberoshub.workflows.definitions (see
|
||||
# kerberos-pipeline/_workflows-helpers.tpl). hub-api reads these
|
||||
# read-only to surface config workflows alongside the user workflows
|
||||
# it stores in the database; the config workflows are never persisted.
|
||||
- name: WORKFLOW_DEFINITIONS
|
||||
value: {{ include "kerberoshub.workflows.workflowDefinitions" . | quote }}
|
||||
# Deployment service routing catalog used by API-owned embedded
|
||||
# workflows (for example the one-stage case redaction modal flow).
|
||||
- name: WORKFLOW_STAGE_QUEUES
|
||||
value: {{ include "kerberoshub.workflows.stageQueues" . | quote }}
|
||||
|
||||
# Stripe for billing
|
||||
- name: STRIPE_KEY
|
||||
value: "{{ .Values.kerberoshub.api.stripe.privateKey }}"
|
||||
@@ -333,10 +390,22 @@ spec:
|
||||
value: "{{ .Values.email.templates.share }}"
|
||||
- name: SHARE_TITLE
|
||||
value: "{{ .Values.email.templates.shareTitle }}"
|
||||
- name: CASE_SHARE_TEMPLATE
|
||||
value: "{{ .Values.email.templates.caseShare }}"
|
||||
- name: CASE_SHARE_TITLE
|
||||
value: "{{ .Values.email.templates.caseShareTitle }}"
|
||||
- name: CASE_SHARE_OTP_TEMPLATE
|
||||
value: "{{ .Values.email.templates.caseShareOtp }}"
|
||||
- name: CASE_SHARE_OTP_TITLE
|
||||
value: "{{ .Values.email.templates.caseShareOtpTitle }}"
|
||||
- name: ASSIGN_TASK_TEMPLATE
|
||||
value: "{{ .Values.email.templates.assignTask }}"
|
||||
- name: ASSIGN_TASK_TITLE
|
||||
value: "{{ .Values.email.templates.assignTaskTitle }}"
|
||||
- name: DEFAULT_TASK_RETENTION_DAYS
|
||||
value: "{{ .Values.kerberoshub.api.defaultTaskRetentionDays }}"
|
||||
- name: CASES_MAX_RETENTION_DAYS
|
||||
value: "{{ .Values.kerberoshub.api.casesMaxRetentionDays }}"
|
||||
|
||||
# SMTP
|
||||
- name: SMTP_SERVER
|
||||
@@ -384,6 +453,7 @@ spec:
|
||||
{{- toYaml .Values.kerberoshub.extraEnv | nindent 12 }}
|
||||
{{- end }}
|
||||
|
||||
{{- if .Values.opentelemetry.enabled }}
|
||||
# Open Telemetry tracing
|
||||
- name: OTEL_EXPORTED_OTLP_ENABLED
|
||||
value: "{{ .Values.opentelemetry.enabled }}"
|
||||
@@ -391,4 +461,5 @@ spec:
|
||||
value: "{{ .Values.opentelemetry.routingEnabled }}"
|
||||
- name: OTEL_EXPORTER_OTLP_ENDPOINT
|
||||
value: "{{ .Values.opentelemetry.collector.endpoint }}"
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
|
||||
@@ -0,0 +1,18 @@
|
||||
{{- if or (eq .Values.mode "all") (eq .Values.mode "ui") -}}
|
||||
apiVersion: monitoring.coreos.com/v1
|
||||
kind: ServiceMonitor
|
||||
metadata:
|
||||
name: hub-cleanup-servicemonitor
|
||||
namespace: {{ .Release.Namespace }}
|
||||
labels:
|
||||
service: hub-cleanup
|
||||
release: prometheus
|
||||
spec:
|
||||
selector:
|
||||
matchLabels:
|
||||
service: hub-cleanup
|
||||
endpoints:
|
||||
- port: hub-metrics
|
||||
interval: 15s
|
||||
path: /metrics
|
||||
{{- end }}
|
||||
@@ -29,6 +29,20 @@ spec:
|
||||
imagePullSecrets:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- $mongodbTLS := .Values.mongodb.tls }}
|
||||
{{- if or .Values.kerberoshub.cleanup.volumes (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
|
||||
volumes:
|
||||
{{- with .Values.kerberoshub.cleanup.volumes }}
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
|
||||
{{- include "hub.mongodb.tlsVolume" . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- with .Values.kerberoshub.cleanup.topologySpreadConstraints }}
|
||||
topologySpreadConstraints:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
containers:
|
||||
- name: hub-cleanup
|
||||
image: "{{ .Values.global.imageRegistry }}{{ .Values.kerberoshub.cleanup.repository }}:{{ .Values.kerberoshub.cleanup.tag }}"
|
||||
@@ -37,17 +51,81 @@ spec:
|
||||
resources:
|
||||
{{- toYaml . | nindent 12 }}
|
||||
{{- end }}
|
||||
{{- if or .Values.kerberoshub.cleanup.volumeMounts (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
|
||||
volumeMounts:
|
||||
{{- with .Values.kerberoshub.cleanup.volumeMounts }}
|
||||
{{- toYaml . | nindent 12 }}
|
||||
{{- end }}
|
||||
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
|
||||
{{- include "hub.mongodb.tlsVolumeMount" . | nindent 12 }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
envFrom:
|
||||
- configMapRef:
|
||||
name: mongodb-config
|
||||
ports:
|
||||
- containerPort: 8080
|
||||
env:
|
||||
- name: MODE
|
||||
value: "{{ .Values.kerberoshub.cleanup.mode }}"
|
||||
- name: LOG_LEVEL
|
||||
value: "{{ .Values.kerberoshub.cleanup.logLevel }}"
|
||||
- name: RUN_INTERVAL_MINUTES
|
||||
value: "{{ .Values.kerberoshub.cleanup.runIntervalMinutes }}"
|
||||
- name: CLEANUP_USERNAMES
|
||||
value: "{{ .Values.kerberoshub.cleanup.cleanupUsernames }}"
|
||||
- name: READ_ONLY
|
||||
value: "{{ .Values.readonly }}"
|
||||
value: "{{ .Values.readOnly }}"
|
||||
- name: MAX_DAYS
|
||||
value: "{{ .Values.kerberoshub.cleanup.maxDays }}"
|
||||
- name: BATCH_SIZE
|
||||
value: "{{ .Values.kerberoshub.cleanup.batchSize }}"
|
||||
- name: USER_BATCH_SIZE
|
||||
value: "{{ .Values.kerberoshub.cleanup.userBatchSize }}"
|
||||
- name: MAX_USERS_PER_RUN
|
||||
value: "{{ .Values.kerberoshub.cleanup.maxUsersPerRun }}"
|
||||
- name: PROGRESS_EVERY
|
||||
value: "{{ .Values.kerberoshub.cleanup.progressEvery }}"
|
||||
- name: ACTIVE_USER_RESCAN_HOURS
|
||||
value: "{{ .Values.kerberoshub.cleanup.activeUserRescanHours }}"
|
||||
- name: INACTIVE_USER_RESCAN_HOURS
|
||||
value: "{{ .Values.kerberoshub.cleanup.inactiveUserRescanHours }}"
|
||||
- name: READ_TIMEOUT_SECONDS
|
||||
value: "{{ .Values.kerberoshub.cleanup.readTimeoutSeconds }}"
|
||||
- name: DELETE_TIMEOUT_SECONDS
|
||||
value: "{{ .Values.kerberoshub.cleanup.deleteTimeoutSeconds }}"
|
||||
- name: REPORT_INCLUDE_STATS
|
||||
value: "{{ .Values.kerberoshub.cleanup.reportIncludeStats }}"
|
||||
- name: DRY_RUN
|
||||
value: "{{ .Values.kerberoshub.cleanup.dryRun }}"
|
||||
- name: DEBUG
|
||||
value: "{{ .Values.kerberoshub.cleanup.debug }}"
|
||||
- name: GLOBAL_PASS_ENABLED
|
||||
value: "{{ .Values.kerberoshub.cleanup.globalPassEnabled }}"
|
||||
- name: GLOBAL_PASS_INTERVAL_HOURS
|
||||
value: "{{ .Values.kerberoshub.cleanup.globalPassIntervalHours }}"
|
||||
- name: GLOBAL_PASS_DELETE_BUDGET
|
||||
value: "{{ .Values.kerberoshub.cleanup.globalPassDeleteBudget }}"
|
||||
- name: DEFAULT_TASK_RETENTION_DAYS
|
||||
value: "{{ .Values.kerberoshub.cleanup.defaultTaskRetentionDays }}"
|
||||
{{- if .Values.kerberoshub.extraEnv }}
|
||||
{{- toYaml .Values.kerberoshub.extraEnv | nindent 12 }}
|
||||
{{- end }}
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: hub-cleanup
|
||||
namespace: {{ .Release.Namespace }}
|
||||
labels:
|
||||
app: hub-cleanup
|
||||
service: hub-cleanup
|
||||
spec:
|
||||
ports:
|
||||
- name: hub-metrics
|
||||
port: 8080
|
||||
targetPort: 8080
|
||||
protocol: TCP
|
||||
selector:
|
||||
app: hub-cleanup
|
||||
{{- end }}
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
{{- if or (eq .Values.mode "all") (eq .Values.mode "ui") -}}
|
||||
{{- if and (or (eq .Values.mode "all") (eq .Values.mode "ui")) .Values.kerberoshub.frontend.demoEnabled -}}
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
@@ -93,6 +93,10 @@ spec:
|
||||
volumes:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- with .Values.kerberoshub.frontend.topologySpreadConstraints }}
|
||||
topologySpreadConstraints:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
containers:
|
||||
- name: hub-frontend-demo
|
||||
image: "{{ .Values.global.imageRegistry }}{{ .Values.kerberoshub.frontend.repository }}:{{ .Values.kerberoshub.frontend.tag }}"
|
||||
@@ -148,10 +152,9 @@ spec:
|
||||
value: "{{ .Values.mqtt.host }}"
|
||||
- name: MQTT_PORT
|
||||
value: "{{ .Values.mqtt.port }}"
|
||||
- name: MQTT_USERNAME
|
||||
value: "{{ .Values.mqtt.username }}"
|
||||
- name: MQTT_PASSWORD
|
||||
value: "{{ .Values.mqtt.password }}"
|
||||
# MQTT_USERNAME / MQTT_PASSWORD are intentionally not exposed to the
|
||||
# frontend. They are fetched from the authenticated hub-api endpoint
|
||||
# /runtime/config after login. See hub-api deployment.
|
||||
- name: MQTT_LEGACY_SERVER
|
||||
value: "{{ .Values.mqtt.legacy.host }}"
|
||||
- name: MQTT_LEGACY_PORT
|
||||
@@ -164,10 +167,9 @@ spec:
|
||||
# Turn (Pion)
|
||||
- name: TURN_SERVER
|
||||
value: "{{ .Values.turn.host }}"
|
||||
- name: TURN_USERNAME
|
||||
value: "{{ .Values.turn.username }}"
|
||||
- name: TURN_PASSWORD
|
||||
value: "{{ .Values.turn.password }}"
|
||||
# TURN_USERNAME / TURN_PASSWORD are intentionally not exposed to the
|
||||
# frontend. They are fetched from the authenticated hub-api endpoint
|
||||
# /runtime/config after login. See hub-api deployment.
|
||||
|
||||
# Mixpanel for monitoring
|
||||
- name: MIXPANEL_KEY
|
||||
@@ -195,39 +197,6 @@ spec:
|
||||
- name: ZENDESK_URL
|
||||
value: "{{ .Values.kerberoshub.frontend.zendesk.url }}"
|
||||
|
||||
# Titles and descriptions on pages
|
||||
- name: LOGIN_DESCRIPTION
|
||||
value: "{{ .Values.kerberoshub.frontend.loginDescription }}"
|
||||
- name: LOGIN_COPYRIGHT
|
||||
value: "{{ .Values.kerberoshub.frontend.loginCopyright }}"
|
||||
- name: PAGE_DASHBOARD_TITLE
|
||||
value: "{{ .Values.kerberoshub.frontend.dashboardTitle }}"
|
||||
- name: PAGE_DASHBOARD_SUB_TITLE
|
||||
value: "{{ .Values.kerberoshub.frontend.dashboardSubTitle }}"
|
||||
- name: PAGE_LATESTEVENTS_TITLE
|
||||
value: "{{ .Values.kerberoshub.frontend.latestEventsTitle }}"
|
||||
- name: PAGE_LATESTEVENTS_SUB_TITLE
|
||||
value: "{{ .Values.kerberoshub.frontend.latestEventsSubTitle }}"
|
||||
- name: PAGE_LIVESTREAM_TITLE
|
||||
value: "{{ .Values.kerberoshub.frontend.livestreamTitle }}"
|
||||
- name: PAGE_LIVESTREAM_SUB_TITLE
|
||||
value: "{{ .Values.kerberoshub.frontend.livestreamSubTitle }}"
|
||||
- name: PAGE_MEDIA_TITLE
|
||||
value: "{{ .Values.kerberoshub.frontend.mediaTitle }}"
|
||||
- name: PAGE_MEDIA_SUB_TITLE
|
||||
value: "{{ .Values.kerberoshub.frontend.mediaSubTitle }}"
|
||||
- name: PAGE_DAY_TITLE
|
||||
value: "{{ .Values.kerberoshub.frontend.dayTitle }}"
|
||||
- name: PAGE_DAY_SUB_TITLE
|
||||
value: "{{ .Values.kerberoshub.frontend.daySubTitle }}"
|
||||
- name: PAGE_DASHBOARD_CPU_USAGE
|
||||
value: "{{ .Values.kerberoshub.frontend.cpuUsageDescription }}"
|
||||
- name: PAGE_DASHBOARD_FPS
|
||||
value: "{{ .Values.kerberoshub.frontend.framesPerSecondDescription }}"
|
||||
- name: PAGE_DASHBOARD_MLA
|
||||
value: "{{ .Values.kerberoshub.frontend.mlaUtilizationDescription }}"
|
||||
- name: PAGE_DASHBOARD_OBJECTS
|
||||
value: "{{ .Values.kerberoshub.frontend.objectsDetectedDescription }}"
|
||||
- name: HIDE_ADD_AGENT
|
||||
value: "{{ .Values.kerberoshub.frontend.hideAddAgent }}"
|
||||
|
||||
@@ -258,16 +227,36 @@ spec:
|
||||
# features > general
|
||||
- name: FEATURE_CASE_ENABLED
|
||||
value: "{{ .Values.kerberoshub.frontend.features.case.enabled }}"
|
||||
- name: FEATURE_WORKFLOWS_ENABLED
|
||||
value: "{{ .Values.kerberoshub.frontend.features.workflows.enabled }}"
|
||||
- name: FEATURE_DARK_MODE
|
||||
value: "{{ .Values.kerberoshub.frontend.features.darkMode }}"
|
||||
- name: FEATURE_SPLASH_SCREEN_ENABLED
|
||||
value: "{{ .Values.kerberoshub.frontend.features.splashScreen.enabled }}"
|
||||
- name: FEATURE_LANDING_PAGE
|
||||
value: "{{ .Values.kerberoshub.frontend.features.landingPage }}"
|
||||
|
||||
# features > internationalization (i18n)
|
||||
- name: FEATURE_I18N_ENABLED
|
||||
value: "{{ .Values.kerberoshub.frontend.features.i18n.enabled }}"
|
||||
- name: DEFAULT_LANGUAGE
|
||||
value: "{{ .Values.kerberoshub.frontend.features.i18n.defaultLanguage }}"
|
||||
|
||||
# features > liveview
|
||||
- name: FEATURE_LIVEVIEW_PAGINATION_ENABLED
|
||||
value: "{{ .Values.kerberoshub.frontend.features.liveview.paginationEnabled }}"
|
||||
- name: FEATURE_LIVEVIEW_EMPTY_BY_DEFAULT
|
||||
value: "{{ .Values.kerberoshub.frontend.features.liveview.emptyByDefault }}"
|
||||
- name: FEATURE_LIVE_STREAM_MODE
|
||||
value: "{{ .Values.kerberoshub.frontend.features.liveview.liveStreamMode }}"
|
||||
- name: FEATURE_HLS_ENABLED
|
||||
value: "{{ .Values.kerberoshub.frontend.features.liveview.hlsEnabled }}"
|
||||
- name: FEATURE_MOQ_ENABLED
|
||||
value: "{{ .Values.kerberoshub.frontend.features.liveview.moqEnabled }}"
|
||||
- name: MOQ_RELAY_URL
|
||||
value: "{{ .Values.kerberoshub.frontend.features.liveview.moqRelayUrl }}"
|
||||
- name: MOQ_BROADCAST_PREFIX
|
||||
value: "{{ .Values.kerberoshub.frontend.features.liveview.moqBroadcastPrefix }}"
|
||||
- name: FEATURE_LIVEVIEW_PAGINATION_MODE
|
||||
value: "{{ .Values.kerberoshub.frontend.features.liveview.paginationMode }}"
|
||||
- name: FEATURE_LIVEVIEW_PAGE_SIZE
|
||||
value: "{{ .Values.kerberoshub.frontend.features.liveview.pageSize }}"
|
||||
- name: FEATURE_LIVEVIEW_MAX_STREAMS
|
||||
value: "{{ .Values.kerberoshub.frontend.features.liveview.maxStreams }}"
|
||||
|
||||
@@ -305,9 +294,15 @@ spec:
|
||||
- name: COLOR_DEVICE_MARKER_BORDER
|
||||
value: "{{ .Values.kerberoshub.frontend.colorDeviceMarkerBorder }}"
|
||||
|
||||
# features > video edits
|
||||
- name: FEATURE_VIDEO_EDITS_ENABLED
|
||||
value: "{{ .Values.kerberoshub.frontend.features.videoEdits.enabled }}"
|
||||
|
||||
# features > face redaction
|
||||
- name: FEATURE_FACE_REDACTION_ENABLED
|
||||
value: "{{ .Values.kerberoshub.frontend.features.faceRedaction.enabled }}"
|
||||
value: "{{ .Values.kerberoshub.frontend.features.faceRedaction.enabled }}"
|
||||
- name: FEATURE_FACE_REDACTION_CLASSIFIER_TRACKS_ENABLED
|
||||
value: "{{ .Values.kerberoshub.frontend.features.faceRedaction.classifierTracksEnabled }}"
|
||||
|
||||
# features > media
|
||||
- name: FEATURE_MEDIA_FILTER_DATE_ENABLED
|
||||
@@ -326,7 +321,7 @@ spec:
|
||||
value: "{{ .Values.kerberoshub.frontend.features.media.filter.region.enabled }}"
|
||||
- name: FEATURE_MEDIA_FILTER_SORT_ENABLED
|
||||
value: "{{ .Values.kerberoshub.frontend.features.media.filter.sort.enabled }}"
|
||||
- name: FEATURE_MEDIA_FILTER_CATEGORY_ENABLED
|
||||
- name: FEATURE_MEDIA_FILTER_CATEGORIES_ENABLED
|
||||
value: "{{ .Values.kerberoshub.frontend.features.media.filter.category.enabled }}"
|
||||
- name: FEATURE_MEDIA_FILTER_MARKERS_ENABLED
|
||||
value: "{{ .Values.kerberoshub.frontend.features.media.filter.markers.enabled }}"
|
||||
@@ -335,30 +330,6 @@ spec:
|
||||
- name: FEATURE_MEDIA_FILTER_TAGS_ENABLED
|
||||
value: "{{ .Values.kerberoshub.frontend.features.media.filter.tags.enabled }}"
|
||||
|
||||
|
||||
- name: MARKERS_NAME
|
||||
value: "{{ .Values.kerberoshub.frontend.markersName }}"
|
||||
- name: EVENTS_NAME
|
||||
value: "{{ .Values.kerberoshub.frontend.eventsName }}"
|
||||
- name: FLOOR_PLAN_NAME
|
||||
value: "{{ .Values.kerberoshub.frontend.floorPlanName }}"
|
||||
- name: SITES_NAME
|
||||
value: "{{ .Values.kerberoshub.frontend.sitesName }}"
|
||||
- name: SITES_DESCRIPTION
|
||||
value: "{{ .Values.kerberoshub.frontend.sitesDescription }}"
|
||||
- name: GROUPS_NAME
|
||||
value: "{{ .Values.kerberoshub.frontend.groupsName }}"
|
||||
- name: GROUPS_DESCRIPTION
|
||||
value: "{{ .Values.kerberoshub.frontend.groupsDescription }}"
|
||||
- name: SITE_GROUP_NAME
|
||||
value: "{{ .Values.kerberoshub.frontend.siteGroupName }}"
|
||||
- name: SITE_GROUP_DESCRIPTION
|
||||
value: "{{ .Values.kerberoshub.frontend.siteGroupDescription }}"
|
||||
- name: DEVICE_GROUP_NAME
|
||||
value: "{{ .Values.kerberoshub.frontend.deviceGroupName }}"
|
||||
- name: DEVICE_GROUP_DESCRIPTION
|
||||
value: "{{ .Values.kerberoshub.frontend.deviceGroupDescription }}"
|
||||
|
||||
{{- if .Values.kerberoshub.extraEnv }}
|
||||
{{- toYaml .Values.kerberoshub.extraEnv | nindent 8 }}
|
||||
{{- end }}
|
||||
|
||||
@@ -1,4 +1,5 @@
|
||||
{{- if or (eq .Values.mode "all") (eq .Values.mode "ui") -}}
|
||||
{{- if .Values.kerberoshub.frontend.serviceEnabled }}
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
@@ -14,6 +15,7 @@ spec:
|
||||
name: http
|
||||
selector:
|
||||
app: hub-frontend
|
||||
{{- end }}
|
||||
{{ if ne .Values.ingress "" }}
|
||||
---
|
||||
{{- if .Capabilities.APIVersions.Has "networking.k8s.io/v1" }}
|
||||
@@ -172,6 +174,10 @@ spec:
|
||||
volumes:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- with .Values.kerberoshub.frontend.topologySpreadConstraints }}
|
||||
topologySpreadConstraints:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
containers:
|
||||
- name: hub-frontend
|
||||
image: "{{ .Values.global.imageRegistry }}{{ .Values.kerberoshub.frontend.repository }}:{{ .Values.kerberoshub.frontend.tag }}"
|
||||
@@ -229,10 +235,9 @@ spec:
|
||||
value: "{{ .Values.mqtt.host }}"
|
||||
- name: MQTT_PORT
|
||||
value: "{{ .Values.mqtt.port }}"
|
||||
- name: MQTT_USERNAME
|
||||
value: "{{ .Values.mqtt.username }}"
|
||||
- name: MQTT_PASSWORD
|
||||
value: "{{ .Values.mqtt.password }}"
|
||||
# MQTT_USERNAME / MQTT_PASSWORD are intentionally not exposed to the
|
||||
# frontend. They are fetched from the authenticated hub-api endpoint
|
||||
# /runtime/config after login. See hub-api deployment.
|
||||
- name: MQTT_LEGACY_SERVER
|
||||
value: "{{ .Values.mqtt.legacy.host }}"
|
||||
- name: MQTT_LEGACY_PORT
|
||||
@@ -245,10 +250,9 @@ spec:
|
||||
# Turn (Pion)
|
||||
- name: TURN_SERVER
|
||||
value: "{{ .Values.turn.host }}"
|
||||
- name: TURN_USERNAME
|
||||
value: "{{ .Values.turn.username }}"
|
||||
- name: TURN_PASSWORD
|
||||
value: "{{ .Values.turn.password }}"
|
||||
# TURN_USERNAME / TURN_PASSWORD are intentionally not exposed to the
|
||||
# frontend. They are fetched from the authenticated hub-api endpoint
|
||||
# /runtime/config after login. See hub-api deployment.
|
||||
|
||||
# Mixpanel for monitoring
|
||||
- name: MIXPANEL_KEY
|
||||
@@ -276,39 +280,6 @@ spec:
|
||||
- name: ZENDESK_URL
|
||||
value: "{{ .Values.kerberoshub.frontend.zendesk.url }}"
|
||||
|
||||
# Titles and descriptions on pages
|
||||
- name: LOGIN_DESCRIPTION
|
||||
value: "{{ .Values.kerberoshub.frontend.loginDescription }}"
|
||||
- name: LOGIN_COPYRIGHT
|
||||
value: "{{ .Values.kerberoshub.frontend.loginCopyright }}"
|
||||
- name: PAGE_DASHBOARD_TITLE
|
||||
value: "{{ .Values.kerberoshub.frontend.dashboardTitle }}"
|
||||
- name: PAGE_DASHBOARD_SUB_TITLE
|
||||
value: "{{ .Values.kerberoshub.frontend.dashboardSubTitle }}"
|
||||
- name: PAGE_LATESTEVENTS_TITLE
|
||||
value: "{{ .Values.kerberoshub.frontend.latestEventsTitle }}"
|
||||
- name: PAGE_LATESTEVENTS_SUB_TITLE
|
||||
value: "{{ .Values.kerberoshub.frontend.latestEventsSubTitle }}"
|
||||
- name: PAGE_LIVESTREAM_TITLE
|
||||
value: "{{ .Values.kerberoshub.frontend.livestreamTitle }}"
|
||||
- name: PAGE_LIVESTREAM_SUB_TITLE
|
||||
value: "{{ .Values.kerberoshub.frontend.livestreamSubTitle }}"
|
||||
- name: PAGE_MEDIA_TITLE
|
||||
value: "{{ .Values.kerberoshub.frontend.mediaTitle }}"
|
||||
- name: PAGE_MEDIA_SUB_TITLE
|
||||
value: "{{ .Values.kerberoshub.frontend.mediaSubTitle }}"
|
||||
- name: PAGE_DAY_TITLE
|
||||
value: "{{ .Values.kerberoshub.frontend.dayTitle }}"
|
||||
- name: PAGE_DAY_SUB_TITLE
|
||||
value: "{{ .Values.kerberoshub.frontend.daySubTitle }}"
|
||||
- name: PAGE_DASHBOARD_CPU_USAGE
|
||||
value: "{{ .Values.kerberoshub.frontend.cpuUsageDescription }}"
|
||||
- name: PAGE_DASHBOARD_FPS
|
||||
value: "{{ .Values.kerberoshub.frontend.framesPerSecondDescription }}"
|
||||
- name: PAGE_DASHBOARD_MLA
|
||||
value: "{{ .Values.kerberoshub.frontend.mlaUtilizationDescription }}"
|
||||
- name: PAGE_DASHBOARD_OBJECTS
|
||||
value: "{{ .Values.kerberoshub.frontend.objectsDetectedDescription }}"
|
||||
- name: HIDE_ADD_AGENT
|
||||
value: "{{ .Values.kerberoshub.frontend.hideAddAgent }}"
|
||||
|
||||
@@ -339,18 +310,54 @@ spec:
|
||||
# features > general
|
||||
- name: FEATURE_CASE_ENABLED
|
||||
value: "{{ .Values.kerberoshub.frontend.features.case.enabled }}"
|
||||
- name: FEATURE_WORKFLOWS_ENABLED
|
||||
value: "{{ .Values.kerberoshub.frontend.features.workflows.enabled }}"
|
||||
- name: FEATURE_ORGANISATIONS_ENABLED
|
||||
value: "{{ .Values.kerberoshub.frontend.features.organisations.enabled }}"
|
||||
- name: FEATURE_ORGANISATION_SWITCHER_ENABLED
|
||||
value: "{{ .Values.kerberoshub.frontend.features.organisations.switcherEnabled }}"
|
||||
- name: FEATURE_ORGANISATION_CREATION_ENABLED
|
||||
value: "{{ .Values.kerberoshub.frontend.features.organisations.creationEnabled }}"
|
||||
- name: FEATURE_ORGANISATION_SETTINGS_ENABLED
|
||||
value: "{{ .Values.kerberoshub.frontend.features.organisations.settingsEnabled }}"
|
||||
- name: FEATURE_PROJECTS_ENABLED
|
||||
value: "{{ .Values.kerberoshub.frontend.features.projects.enabled }}"
|
||||
- name: FEATURE_PROJECT_SWITCHER_ENABLED
|
||||
value: "{{ .Values.kerberoshub.frontend.features.projects.switcherEnabled }}"
|
||||
- name: FEATURE_PROJECT_CREATION_ENABLED
|
||||
value: "{{ .Values.kerberoshub.frontend.features.projects.creationEnabled }}"
|
||||
- name: FEATURE_PROJECT_SETTINGS_ENABLED
|
||||
value: "{{ .Values.kerberoshub.frontend.features.projects.settingsEnabled }}"
|
||||
- name: FEATURE_DARK_MODE
|
||||
value: "{{ .Values.kerberoshub.frontend.features.darkModeEnabled }}"
|
||||
- name: FEATURE_SPLASH_SCREEN_ENABLED
|
||||
value: "{{ .Values.kerberoshub.frontend.features.splashScreen.enabled }}"
|
||||
- name: FEATURE_LANDING_PAGE
|
||||
value: "{{ .Values.kerberoshub.frontend.features.landingPage }}"
|
||||
|
||||
# features > internationalization (i18n)
|
||||
- name: FEATURE_I18N_ENABLED
|
||||
value: "{{ .Values.kerberoshub.frontend.features.i18n.enabled }}"
|
||||
- name: DEFAULT_LANGUAGE
|
||||
value: "{{ .Values.kerberoshub.frontend.features.i18n.defaultLanguage }}"
|
||||
|
||||
# features > liveview
|
||||
- name: FEATURE_DEFAULT_STREAM_MODE
|
||||
value: "{{ .Values.kerberoshub.frontend.features.liveview.defaultStreamMode }}"
|
||||
- name: FEATURE_LIVEVIEW_PAGINATION_ENABLED
|
||||
value: "{{ .Values.kerberoshub.frontend.features.liveview.paginationEnabled }}"
|
||||
- name: FEATURE_LIVEVIEW_EMPTY_BY_DEFAULT
|
||||
value: "{{ .Values.kerberoshub.frontend.features.liveview.emptyByDefault }}"
|
||||
- name: FEATURE_LIVE_STREAM_MODE
|
||||
value: "{{ .Values.kerberoshub.frontend.features.liveview.liveStreamMode }}"
|
||||
- name: FEATURE_HLS_ENABLED
|
||||
value: "{{ .Values.kerberoshub.frontend.features.liveview.hlsEnabled }}"
|
||||
- name: FEATURE_MOQ_ENABLED
|
||||
value: "{{ .Values.kerberoshub.frontend.features.liveview.moqEnabled }}"
|
||||
- name: MOQ_RELAY_URL
|
||||
value: "{{ .Values.kerberoshub.frontend.features.liveview.moqRelayUrl }}"
|
||||
- name: MOQ_BROADCAST_PREFIX
|
||||
value: "{{ .Values.kerberoshub.frontend.features.liveview.moqBroadcastPrefix }}"
|
||||
- name: FEATURE_LIVEVIEW_PAGINATION_MODE
|
||||
value: "{{ .Values.kerberoshub.frontend.features.liveview.paginationMode }}"
|
||||
- name: FEATURE_LIVEVIEW_PAGE_SIZE
|
||||
value: "{{ .Values.kerberoshub.frontend.features.liveview.pageSize }}"
|
||||
- name: FEATURE_LIVEVIEW_MAX_STREAMS
|
||||
value: "{{ .Values.kerberoshub.frontend.features.liveview.maxStreams }}"
|
||||
|
||||
@@ -405,9 +412,15 @@ spec:
|
||||
- name: COLOR_CHART_GRID_STROKE
|
||||
value: "{{ .Values.kerberoshub.frontend.features.chart.colorChartGridStroke }}"
|
||||
|
||||
# features > video edits
|
||||
- name: FEATURE_VIDEO_EDITS_ENABLED
|
||||
value: "{{ .Values.kerberoshub.frontend.features.videoEdits.enabled }}"
|
||||
|
||||
# features > face redaction
|
||||
- name: FEATURE_FACE_REDACTION_ENABLED
|
||||
value: "{{ .Values.kerberoshub.frontend.features.faceRedaction.enabled }}"
|
||||
value: "{{ .Values.kerberoshub.frontend.features.faceRedaction.enabled }}"
|
||||
- name: FEATURE_FACE_REDACTION_CLASSIFIER_TRACKS_ENABLED
|
||||
value: "{{ .Values.kerberoshub.frontend.features.faceRedaction.classifierTracksEnabled }}"
|
||||
|
||||
# features > media
|
||||
- name: FEATURE_MEDIA_FILTER_DATE_ENABLED
|
||||
@@ -426,7 +439,7 @@ spec:
|
||||
value: "{{ .Values.kerberoshub.frontend.features.media.filter.region.enabled }}"
|
||||
- name: FEATURE_MEDIA_FILTER_SORT_ENABLED
|
||||
value: "{{ .Values.kerberoshub.frontend.features.media.filter.sort.enabled }}"
|
||||
- name: FEATURE_MEDIA_FILTER_CATEGORY_ENABLED
|
||||
- name: FEATURE_MEDIA_FILTER_CATEGORIES_ENABLED
|
||||
value: "{{ .Values.kerberoshub.frontend.features.media.filter.category.enabled }}"
|
||||
- name: FEATURE_MEDIA_FILTER_MARKERS_ENABLED
|
||||
value: "{{ .Values.kerberoshub.frontend.features.media.filter.markers.enabled }}"
|
||||
@@ -438,29 +451,6 @@ spec:
|
||||
value: "{{ .Values.kerberoshub.frontend.features.media.filter.tags.enabled }}"
|
||||
|
||||
|
||||
- name: MARKERS_NAME
|
||||
value: "{{ .Values.kerberoshub.frontend.markersName }}"
|
||||
- name: EVENTS_NAME
|
||||
value: "{{ .Values.kerberoshub.frontend.eventsName }}"
|
||||
- name: FLOOR_PLAN_NAME
|
||||
value: "{{ .Values.kerberoshub.frontend.floorPlanName }}"
|
||||
- name: SITES_NAME
|
||||
value: "{{ .Values.kerberoshub.frontend.sitesName }}"
|
||||
- name: SITES_DESCRIPTION
|
||||
value: "{{ .Values.kerberoshub.frontend.sitesDescription }}"
|
||||
- name: GROUPS_NAME
|
||||
value: "{{ .Values.kerberoshub.frontend.groupsName }}"
|
||||
- name: GROUPS_DESCRIPTION
|
||||
value: "{{ .Values.kerberoshub.frontend.groupsDescription }}"
|
||||
- name: SITE_GROUP_NAME
|
||||
value: "{{ .Values.kerberoshub.frontend.siteGroupName }}"
|
||||
- name: SITE_GROUP_DESCRIPTION
|
||||
value: "{{ .Values.kerberoshub.frontend.siteGroupDescription }}"
|
||||
- name: DEVICE_GROUP_NAME
|
||||
value: "{{ .Values.kerberoshub.frontend.deviceGroupName }}"
|
||||
- name: DEVICE_GROUP_DESCRIPTION
|
||||
value: "{{ .Values.kerberoshub.frontend.deviceGroupDescription }}"
|
||||
|
||||
{{- if .Values.kerberoshub.extraEnv }}
|
||||
{{- toYaml .Values.kerberoshub.extraEnv | nindent 8 }}
|
||||
{{- end }}
|
||||
|
||||
@@ -29,8 +29,18 @@ spec:
|
||||
imagePullSecrets:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- with .Values.kerberoshub.monitordevice.volumes }}
|
||||
{{- $mongodbTLS := .Values.mongodb.tls }}
|
||||
{{- if or .Values.kerberoshub.monitordevice.volumes (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
|
||||
volumes:
|
||||
{{- with .Values.kerberoshub.monitordevice.volumes }}
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
|
||||
{{- include "hub.mongodb.tlsVolume" . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- with .Values.kerberoshub.monitordevice.topologySpreadConstraints }}
|
||||
topologySpreadConstraints:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
containers:
|
||||
@@ -41,10 +51,15 @@ spec:
|
||||
resources:
|
||||
{{- toYaml . | nindent 12 }}
|
||||
{{- end }}
|
||||
{{- with .Values.kerberoshub.monitordevice.volumeMounts}}
|
||||
{{- if or .Values.kerberoshub.monitordevice.volumeMounts (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
|
||||
volumeMounts:
|
||||
{{- with .Values.kerberoshub.monitordevice.volumeMounts}}
|
||||
{{- toYaml . | nindent 12 }}
|
||||
{{- end }}
|
||||
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
|
||||
{{- include "hub.mongodb.tlsVolumeMount" . | nindent 12 }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
envFrom:
|
||||
- configMapRef:
|
||||
name: mongodb-config
|
||||
|
||||
@@ -16,6 +16,14 @@ spec:
|
||||
labels:
|
||||
k8s-app: oauth2-proxy
|
||||
spec:
|
||||
{{- with .Values.kerberoshub.oauth2Proxy.volumes }}
|
||||
volumes:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- with .Values.kerberoshub.oauth2Proxy.topologySpreadConstraints }}
|
||||
topologySpreadConstraints:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
containers:
|
||||
- args:
|
||||
- --provider=github
|
||||
@@ -23,6 +31,10 @@ spec:
|
||||
- --upstream=file:///dev/null
|
||||
- --http-address=0.0.0.0:4180
|
||||
- --skip-auth-preflight=true
|
||||
{{- with .Values.kerberoshub.oauth2Proxy.volumeMounts }}
|
||||
volumeMounts:
|
||||
{{- toYaml . | nindent 12 }}
|
||||
{{- end }}
|
||||
env:
|
||||
- name: OAUTH2_PROXY_CLIENT_ID
|
||||
value: "{{ .Values.kerberoshub.oauth2Proxy.github.clientId }}"
|
||||
|
||||
@@ -26,10 +26,33 @@ spec:
|
||||
imagePullSecrets:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- $mongodbTLS := .Values.mongodb.tls }}
|
||||
{{- if or .Values.kerberoshub.reactivate.volumes (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
|
||||
volumes:
|
||||
{{- with .Values.kerberoshub.reactivate.volumes }}
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
|
||||
{{- include "hub.mongodb.tlsVolume" . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- with .Values.kerberoshub.reactivate.topologySpreadConstraints }}
|
||||
topologySpreadConstraints:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
containers:
|
||||
- name: hub-reactivate-subscription
|
||||
image: "{{ .Values.global.imageRegistry }}{{ .Values.kerberoshub.reactivate.repository }}:{{ .Values.kerberoshub.reactivate.tag }}"
|
||||
imagePullPolicy: {{ .Values.kerberoshub.reactivate.pullPolicy }}
|
||||
{{- if or .Values.kerberoshub.reactivate.volumeMounts (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
|
||||
volumeMounts:
|
||||
{{- with .Values.kerberoshub.reactivate.volumeMounts }}
|
||||
{{- toYaml . | nindent 12 }}
|
||||
{{- end }}
|
||||
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
|
||||
{{- include "hub.mongodb.tlsVolumeMount" . | nindent 12 }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
envFrom:
|
||||
- configMapRef:
|
||||
name: mongodb-config
|
||||
|
||||
@@ -0,0 +1,67 @@
|
||||
{{/*
|
||||
Assemble the deployment-global workflow definitions (WORKFLOW_DEFINITIONS) as a
|
||||
JSON array from every *enabled* workflow under kerberoshub.workflows.definitions.
|
||||
This is the engine's boot-loaded configuration source and deployment stage
|
||||
catalog: several distinct config workflows can run over one recording — each
|
||||
opens its own run and dispatches only its own stages. Organisation-scoped
|
||||
database workflows are discovered separately at runtime.
|
||||
|
||||
Each enabled definition contributes one workflow object:
|
||||
name the map key (the workflow's human-readable name; also its identity —
|
||||
the engine derives a stable id from it when the definition carries
|
||||
no explicit id).
|
||||
enabled always true here (a disabled definition is skipped entirely).
|
||||
source "config" — provenance marking a Helm-defined, deployment-global,
|
||||
ops-managed workflow (read-only in the API, no owning organisation).
|
||||
triggers how a run OPENS. Defaults to a single bare automatic trigger
|
||||
(opens for every recording); narrow with device/schedule triggers.
|
||||
Per-stage `needs` (below) decide which stages then FIRE.
|
||||
stages the executable stage set, each contributing the same routing
|
||||
descriptor the stageRegistry emits:
|
||||
operation the stage's operation (unique within the workflow).
|
||||
dispatch "always" (default) | "conditional".
|
||||
queue from the matching services.<operation>.queue
|
||||
(authoritative; omitted when unset so the engine
|
||||
derives "kcloud-<operation>-queue.fifo").
|
||||
needs conditional stages only: upstream dependencies, each
|
||||
{operation?, condition?}, carried through verbatim.
|
||||
needsMode conditional stages: "any" (default) | "all".
|
||||
*/}}
|
||||
{{- define "kerberoshub.workflows.workflowDefinitions" -}}
|
||||
{{- $defs := list -}}
|
||||
{{- $services := .Values.kerberoshub.services | default dict -}}
|
||||
{{- range $name, $wf := .Values.kerberoshub.workflows.definitions -}}
|
||||
{{- if $wf.enabled -}}
|
||||
{{- $stages := list -}}
|
||||
{{- range $stage := $wf.stages -}}
|
||||
{{- $op := $stage.operation -}}
|
||||
{{- $entry := dict "operation" $op "dispatch" (default "always" $stage.dispatch) -}}
|
||||
{{- $service := index $services $op -}}
|
||||
{{- if $service }}{{- with $service.queue }}{{- $_ := set $entry "queue" . -}}{{- end }}{{- end }}
|
||||
{{- with $stage.needs }}{{- $_ := set $entry "needs" . -}}{{- end }}
|
||||
{{- with $stage.needsMode }}{{- $_ := set $entry "needsMode" . -}}{{- end }}
|
||||
{{- $stages = append $stages $entry -}}
|
||||
{{- end -}}
|
||||
{{- $def := dict "name" $name "enabled" true "source" "config" "triggers" (default (list (dict "type" "automatic")) $wf.triggers) "stages" $stages -}}
|
||||
{{- $defs = append $defs $def -}}
|
||||
{{- end -}}
|
||||
{{- end -}}
|
||||
{{- $defs | toJson -}}
|
||||
{{- end -}}
|
||||
|
||||
{{/*
|
||||
Expose the deployment's operation→queue catalog to API producers that seed
|
||||
embedded WorkflowRuns. Unlike WORKFLOW_DEFINITIONS this includes services that
|
||||
are enabled for internal flows but are absent from user-visible workflow
|
||||
definitions. The workflows engine remains authoritative for dispatch; producers
|
||||
use this only to embed the same queue on a synthetic stage.
|
||||
*/}}
|
||||
{{- define "kerberoshub.workflows.stageQueues" -}}
|
||||
{{- $queues := dict -}}
|
||||
{{- range $operation, $service := (.Values.kerberoshub.services | default dict) -}}
|
||||
{{- with $service.queue -}}
|
||||
{{- $_ := set $queues $operation . -}}
|
||||
{{- end -}}
|
||||
{{- end -}}
|
||||
{{- $queues | toJson -}}
|
||||
{{- end -}}
|
||||
145
charts/hub/templates/kerberos-pipeline/hub-stage.yaml
Normal file
145
charts/hub/templates/kerberos-pipeline/hub-stage.yaml
Normal file
@@ -0,0 +1,145 @@
|
||||
{{- /*
|
||||
Generic workflow-stage worker.
|
||||
|
||||
Renders a Deployment + Service for every enabled worker under
|
||||
kerberoshub.services.<name> other than the `workflows` engine itself. A custom
|
||||
stage joins the pipeline by values alone — declare its worker here and route to
|
||||
it from a kerberoshub.workflows.definitions stage of the same operation; no
|
||||
per-stage template is needed.
|
||||
|
||||
Every stage worker receives the same connection contract; the only value that
|
||||
varies by stage is the consume-queue variable name, <NAME>_QUEUE (a worker
|
||||
named "loitering" gets LOITERING_QUEUE, "my-stage" gets MY_STAGE_QUEUE). To run
|
||||
a worker outside the chart instead, leave services.<name>.enabled unset (or
|
||||
false) and point its workflow stage at the queue you publish.
|
||||
|
||||
All stages receive the Vault read credentials (KERBEROS_STORAGE_URI /
|
||||
ACCESS_KEY / SECRET). A stage that also writes an artefact back to Vault (e.g.
|
||||
redaction) declares its destination provider with the named field
|
||||
services.<name>.storageProvider, rendered as KERBEROS_STORAGE_PROVIDER; a
|
||||
read-only stage omits it and gets no provider env.
|
||||
*/ -}}
|
||||
{{- if and (or (eq .Values.mode "all") (eq .Values.mode "pipeline")) .Values.kerberoshub.workflows.enabled -}}
|
||||
{{- $root := . -}}
|
||||
{{- $services := .Values.kerberoshub.services | default dict -}}
|
||||
{{- range $name, $svc := $services -}}
|
||||
{{- if and (ne $name "workflows") $svc $svc.enabled -}}
|
||||
{{- $queueEnv := printf "%s_QUEUE" ($name | upper | replace "-" "_") -}}
|
||||
---
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: hub-{{ $name }}
|
||||
namespace: {{ $root.Release.Namespace }}
|
||||
spec:
|
||||
replicas: {{ $svc.replicas | default 1 }}
|
||||
selector:
|
||||
matchLabels:
|
||||
app: hub-{{ $name }}
|
||||
minReadySeconds: 10
|
||||
strategy:
|
||||
type: RollingUpdate
|
||||
rollingUpdate:
|
||||
maxUnavailable: 1
|
||||
maxSurge: 1
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
app: hub-{{ $name }}
|
||||
spec:
|
||||
{{- if $root.Values.kerberoshub.serviceAccount.create }}
|
||||
serviceAccountName: {{ default (printf "%s-%s-sa" $root.Release.Name $root.Chart.Name | trunc 63 | trimSuffix "-") $root.Values.kerberoshub.serviceAccount.name }}
|
||||
{{- end }}
|
||||
{{- with $root.Values.imagePullSecrets }}
|
||||
imagePullSecrets:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- with $svc.volumes }}
|
||||
volumes:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- with $svc.topologySpreadConstraints }}
|
||||
topologySpreadConstraints:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
containers:
|
||||
- name: hub-{{ $name }}
|
||||
image: "{{ $root.Values.global.imageRegistry }}{{ $svc.repository }}:{{ $svc.tag }}"
|
||||
imagePullPolicy: {{ $svc.pullPolicy | default "IfNotPresent" }}
|
||||
{{- with $svc.resources }}
|
||||
resources:
|
||||
{{- toYaml . | nindent 12 }}
|
||||
{{- end }}
|
||||
{{- with $svc.volumeMounts }}
|
||||
volumeMounts:
|
||||
{{- toYaml . | nindent 12 }}
|
||||
{{- end }}
|
||||
env:
|
||||
- name: LOG_LEVEL
|
||||
value: "{{ $svc.logLevel | default "info" }}"
|
||||
- name: QUEUE_SYSTEM
|
||||
value: "{{ $root.Values.queueProvider }}"
|
||||
|
||||
# The queue this stage worker consumes dispatched "{{ $name }}" stages
|
||||
# from ({{ $queueEnv }}) and the workflows engine queue it routes its
|
||||
# result back to (WORKFLOWS_QUEUE, so the run records the resolution and
|
||||
# any stage that needs "{{ $name }}" can fire).
|
||||
- name: {{ $queueEnv }}
|
||||
value: "{{ $svc.queue }}"
|
||||
- name: WORKFLOWS_QUEUE
|
||||
value: "{{ $root.Values.kerberoshub.services.workflows.queue }}"
|
||||
|
||||
# RabbitMQ settings
|
||||
- name: RABBITMQ_HOST
|
||||
value: "{{ $root.Values.rabbitmq.host }}"
|
||||
- name: RABBITMQ_EXCHANGE
|
||||
value: "{{ $root.Values.rabbitmq.exchange }}"
|
||||
- name: RABBITMQ_USERNAME
|
||||
value: "{{ $root.Values.rabbitmq.username }}"
|
||||
- name: RABBITMQ_PASSWORD
|
||||
value: "{{ $root.Values.rabbitmq.password }}"
|
||||
|
||||
# Kerberos Vault — global storage credentials this stage uses to fetch
|
||||
# the media it operates on.
|
||||
- name: KERBEROS_STORAGE_URI
|
||||
value: "{{ $root.Values.kerberosvault.uri }}"
|
||||
- name: KERBEROS_STORAGE_ACCESS_KEY
|
||||
value: "{{ $root.Values.kerberosvault.accesskey }}"
|
||||
- name: KERBEROS_STORAGE_SECRET
|
||||
value: "{{ $root.Values.kerberosvault.secretkey }}"
|
||||
{{- with $svc.storageProvider }}
|
||||
# Destination Vault provider (KERBEROS_STORAGE_PROVIDER) — only stages
|
||||
# that write an artefact back (e.g. redaction) set services.<name>.
|
||||
# storageProvider; read-only stages omit it and get no provider env.
|
||||
- name: KERBEROS_STORAGE_PROVIDER
|
||||
value: {{ . | quote }}
|
||||
{{- end }}
|
||||
|
||||
# Per-stage tuning knobs. Any key/value under services.<name>.env is
|
||||
# rendered verbatim as container env, so a worker can be tuned from
|
||||
# values without a per-stage template. These override the image's own
|
||||
# ENV defaults; the fixed contract env above is not overridable here.
|
||||
{{- range $key, $value := $svc.env }}
|
||||
- name: {{ $key }}
|
||||
value: {{ $value | quote }}
|
||||
{{- end }}
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: hub-{{ $name }}
|
||||
namespace: {{ $root.Release.Namespace }}
|
||||
labels:
|
||||
app: hub-{{ $name }}
|
||||
service: pipe
|
||||
spec:
|
||||
ports:
|
||||
- name: hub-metrics
|
||||
port: 8080
|
||||
targetPort: 8080
|
||||
protocol: TCP
|
||||
selector:
|
||||
app: hub-{{ $name }}
|
||||
{{ end -}}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
131
charts/hub/templates/kerberos-pipeline/hub-workflows.yaml
Normal file
131
charts/hub/templates/kerberos-pipeline/hub-workflows.yaml
Normal file
@@ -0,0 +1,131 @@
|
||||
{{- if and (or (eq .Values.mode "all") (eq .Values.mode "pipeline")) .Values.kerberoshub.workflows.enabled -}}
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: hub-workflows
|
||||
namespace: {{ .Release.Namespace }}
|
||||
spec:
|
||||
replicas: {{ .Values.kerberoshub.services.workflows.replicas }}
|
||||
selector:
|
||||
matchLabels:
|
||||
app: hub-workflows
|
||||
minReadySeconds: 10
|
||||
strategy:
|
||||
type: RollingUpdate
|
||||
rollingUpdate:
|
||||
maxUnavailable: 1
|
||||
maxSurge: 1
|
||||
template:
|
||||
metadata:
|
||||
annotations:
|
||||
checksum/config: {{ include (print $.Template.BasePath "/configmap-mongodb.yaml") . | sha256sum }}
|
||||
labels:
|
||||
app: hub-workflows
|
||||
spec:
|
||||
{{- if .Values.kerberoshub.serviceAccount.create }}
|
||||
serviceAccountName: {{ default (printf "%s-%s-sa" .Release.Name .Chart.Name | trunc 63 | trimSuffix "-") .Values.kerberoshub.serviceAccount.name }}
|
||||
{{- end }}
|
||||
{{- with .Values.imagePullSecrets }}
|
||||
imagePullSecrets:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- $mongodbTLS := .Values.mongodb.tls }}
|
||||
{{- if or .Values.kerberoshub.services.workflows.volumes (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
|
||||
volumes:
|
||||
{{- with .Values.kerberoshub.services.workflows.volumes }}
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
|
||||
{{- include "hub.mongodb.tlsVolume" . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- with .Values.kerberoshub.services.workflows.topologySpreadConstraints }}
|
||||
topologySpreadConstraints:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
containers:
|
||||
- name: hub-workflows
|
||||
image: "{{ .Values.global.imageRegistry }}{{ .Values.kerberoshub.services.workflows.repository }}:{{ .Values.kerberoshub.services.workflows.tag }}"
|
||||
imagePullPolicy: {{ .Values.kerberoshub.services.workflows.pullPolicy }}
|
||||
{{- with .Values.kerberoshub.services.workflows.resources }}
|
||||
resources:
|
||||
{{- toYaml . | nindent 12 }}
|
||||
{{- end }}
|
||||
{{- if or .Values.kerberoshub.services.workflows.volumeMounts (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
|
||||
volumeMounts:
|
||||
{{- with .Values.kerberoshub.services.workflows.volumeMounts }}
|
||||
{{- toYaml . | nindent 12 }}
|
||||
{{- end }}
|
||||
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
|
||||
{{- include "hub.mongodb.tlsVolumeMount" . | nindent 12 }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
envFrom:
|
||||
- configMapRef:
|
||||
name: mongodb-config
|
||||
env:
|
||||
- name: LOG_LEVEL
|
||||
value: "{{ .Values.kerberoshub.services.workflows.logLevel }}"
|
||||
- name: QUEUE_SYSTEM
|
||||
value: "{{ .Values.queueProvider }}"
|
||||
|
||||
# Queue this service consumes from (WORKFLOWS_QUEUE) and the set of
|
||||
# named workflows it runs (WORKFLOW_DEFINITIONS): each with its own
|
||||
# trigger and executable stages, assembled from the enabled definitions
|
||||
# under kerberoshub.workflows.definitions (see _workflows-helpers.tpl).
|
||||
# Definitions are the engine's boot-loaded config source and deployment
|
||||
# stage catalog. Organisation-scoped database workflows are read per
|
||||
# recording; an in-cluster engine still requires at least one config
|
||||
# definition so an empty catalog cannot silently drop traffic.
|
||||
- name: WORKFLOWS_QUEUE
|
||||
value: "{{ .Values.kerberoshub.services.workflows.queue }}"
|
||||
- name: WORKFLOW_DEFINITIONS
|
||||
value: {{ include "kerberoshub.workflows.workflowDefinitions" . | quote }}
|
||||
|
||||
# RabbitMQ settings
|
||||
- name: RABBITMQ_HOST
|
||||
value: "{{ .Values.rabbitmq.host }}"
|
||||
- name: RABBITMQ_EXCHANGE
|
||||
value: "{{ .Values.rabbitmq.exchange }}"
|
||||
- name: RABBITMQ_USERNAME
|
||||
value: "{{ .Values.rabbitmq.username }}"
|
||||
- name: RABBITMQ_PASSWORD
|
||||
value: "{{ .Values.rabbitmq.password }}"
|
||||
|
||||
# Kerberos Vault — global storage credentials a dispatched stage worker
|
||||
# uses to fetch the media. Per-recording vault overrides (site/account)
|
||||
# are resolved at dispatch time from the database.
|
||||
- name: KERBEROS_STORAGE_URI
|
||||
value: "{{ .Values.kerberosvault.uri }}"
|
||||
- name: KERBEROS_STORAGE_ACCESS_KEY
|
||||
value: "{{ .Values.kerberosvault.accesskey }}"
|
||||
- name: KERBEROS_STORAGE_SECRET
|
||||
value: "{{ .Values.kerberosvault.secretkey }}"
|
||||
|
||||
{{- if .Values.opentelemetry.enabled }}
|
||||
# Open Telemetry tracing
|
||||
- name: OTEL_EXPORTED_OTLP_ENABLED
|
||||
value: "{{ .Values.opentelemetry.enabled }}"
|
||||
- name: OTEL_EXPORTED_OTLP_ROUTING_ENABLED
|
||||
value: "{{ .Values.opentelemetry.routingEnabled }}"
|
||||
- name: OTEL_EXPORTER_OTLP_ENDPOINT
|
||||
value: "{{ .Values.opentelemetry.collector.endpoint }}"
|
||||
{{- end }}
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: hub-workflows
|
||||
namespace: {{ .Release.Namespace }}
|
||||
labels:
|
||||
app: hub-workflows
|
||||
service: pipe
|
||||
spec:
|
||||
ports:
|
||||
- name: hub-metrics
|
||||
port: 8080
|
||||
targetPort: 8080
|
||||
protocol: TCP
|
||||
selector:
|
||||
app: hub-workflows
|
||||
{{- end }}
|
||||
@@ -29,6 +29,20 @@ spec:
|
||||
imagePullSecrets:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- $mongodbTLS := .Values.mongodb.tls }}
|
||||
{{- if or .Values.kerberospipeline.analysis.volumes (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
|
||||
volumes:
|
||||
{{- with .Values.kerberospipeline.analysis.volumes }}
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
|
||||
{{- include "hub.mongodb.tlsVolume" . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- with .Values.kerberospipeline.analysis.topologySpreadConstraints }}
|
||||
topologySpreadConstraints:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
containers:
|
||||
- name: pipe-analysis
|
||||
image: "{{ .Values.global.imageRegistry }}{{ .Values.kerberospipeline.analysis.repository }}:{{ .Values.kerberospipeline.analysis.tag }}"
|
||||
@@ -37,6 +51,15 @@ spec:
|
||||
resources:
|
||||
{{- toYaml . | nindent 12 }}
|
||||
{{- end }}
|
||||
{{- if or .Values.kerberospipeline.analysis.volumeMounts (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
|
||||
volumeMounts:
|
||||
{{- with .Values.kerberospipeline.analysis.volumeMounts }}
|
||||
{{- toYaml . | nindent 12 }}
|
||||
{{- end }}
|
||||
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
|
||||
{{- include "hub.mongodb.tlsVolumeMount" . | nindent 12 }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
envFrom:
|
||||
- configMapRef:
|
||||
name: mongodb-config
|
||||
@@ -69,6 +92,18 @@ spec:
|
||||
value: "{{ .Values.rabbitmq.username }}"
|
||||
- name: RABBITMQ_PASSWORD
|
||||
value: "{{ .Values.rabbitmq.password }}"
|
||||
|
||||
# When true, analysis tees the classify result to the hub-workflows
|
||||
# service in parallel with the throttler/notification tail (which still
|
||||
# runs unchanged). Kept in sync with whether the workflows service runs.
|
||||
- name: WORKFLOWS_ENABLED
|
||||
value: "{{ .Values.kerberoshub.workflows.enabled }}"
|
||||
|
||||
# Queue analysis publishes opened workflow runs to (WORKFLOWS_QUEUE),
|
||||
# taken from the workflows service's queue so analysis and the engine
|
||||
# always agree on the queue name (no drift).
|
||||
- name: WORKFLOWS_QUEUE
|
||||
value: "{{ .Values.kerberoshub.services.workflows.queue }}"
|
||||
|
||||
# Kerberos Vault
|
||||
- name: KERBEROS_STORAGE_URI
|
||||
@@ -82,6 +117,7 @@ spec:
|
||||
- name: SPRITE_ENABLED
|
||||
value: "{{ .Values.kerberospipeline.sprite.enabled }}"
|
||||
|
||||
{{- if .Values.opentelemetry.enabled }}
|
||||
# Open Telemetry tracing
|
||||
- name: OTEL_EXPORTED_OTLP_ENABLED
|
||||
value: "{{ .Values.opentelemetry.enabled }}"
|
||||
@@ -89,6 +125,7 @@ spec:
|
||||
value: "{{ .Values.opentelemetry.routingEnabled }}"
|
||||
- name: OTEL_EXPORTER_OTLP_ENDPOINT
|
||||
value: "{{ .Values.opentelemetry.collector.endpoint }}"
|
||||
{{- end }}
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
|
||||
@@ -27,6 +27,14 @@ spec:
|
||||
imagePullSecrets:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- with .Values.kerberospipeline.counting.volumes }}
|
||||
volumes:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- with .Values.kerberospipeline.counting.topologySpreadConstraints }}
|
||||
topologySpreadConstraints:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
containers:
|
||||
- name: pipe-counting
|
||||
image: "{{ .Values.global.imageRegistry }}{{ .Values.kerberospipeline.counting.repository }}:{{ .Values.kerberospipeline.counting.tag }}"
|
||||
@@ -35,6 +43,10 @@ spec:
|
||||
resources:
|
||||
{{- toYaml . | nindent 12 }}
|
||||
{{- end }}
|
||||
{{- with .Values.kerberospipeline.counting.volumeMounts }}
|
||||
volumeMounts:
|
||||
{{- toYaml . | nindent 12 }}
|
||||
{{- end }}
|
||||
env:
|
||||
- name: LOG_LEVEL
|
||||
value: "{{ .Values.kerberospipeline.counting.logLevel }}"
|
||||
@@ -65,14 +77,15 @@ spec:
|
||||
- name: RABBITMQ_PASSWORD
|
||||
value: "{{ .Values.rabbitmq.password }}"
|
||||
|
||||
{{- if .Values.opentelemetry.enabled }}
|
||||
# Open Telemetry tracing
|
||||
- name: OTEL_EXPORTED_OTLP_ENABLED
|
||||
value: "{{ .Values.opentelemetry.enabled }}"
|
||||
- name: OTEL_EXPORTED_OTLP_ROUTING_ENABLED
|
||||
value: "{{ .Values.opentelemetry.routingEnabled }}"
|
||||
{{- end }}
|
||||
- name: OTEL_EXPORTER_OTLP_ENDPOINT
|
||||
value: "{{ .Values.opentelemetry.collector.endpoint }}"
|
||||
{{- end }}
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
@@ -89,4 +102,5 @@ spec:
|
||||
targetPort: 8080
|
||||
protocol: TCP
|
||||
selector:
|
||||
app: pipe-counting
|
||||
app: pipe-counting
|
||||
{{- end }}
|
||||
@@ -27,6 +27,14 @@ spec:
|
||||
imagePullSecrets:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- with .Values.kerberospipeline.dominantColor.volumes }}
|
||||
volumes:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- with .Values.kerberospipeline.dominantColor.topologySpreadConstraints }}
|
||||
topologySpreadConstraints:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
containers:
|
||||
- name: pipe-dominantcolor
|
||||
image: "{{ .Values.global.imageRegistry }}{{ .Values.kerberospipeline.dominantColor.repository }}:{{ .Values.kerberospipeline.dominantColor.tag }}"
|
||||
@@ -35,6 +43,10 @@ spec:
|
||||
resources:
|
||||
{{- toYaml . | nindent 12 }}
|
||||
{{- end }}
|
||||
{{- with .Values.kerberospipeline.dominantColor.volumeMounts }}
|
||||
volumeMounts:
|
||||
{{- toYaml . | nindent 12 }}
|
||||
{{- end }}
|
||||
env:
|
||||
- name: LOG_LEVEL
|
||||
value: "{{ .Values.kerberospipeline.dominantColor.logLevel }}"
|
||||
@@ -65,14 +77,15 @@ spec:
|
||||
- name: RABBITMQ_PASSWORD
|
||||
value: "{{ .Values.rabbitmq.password }}"
|
||||
|
||||
{{- if .Values.opentelemetry.enabled }}
|
||||
# Open Telemetry tracing
|
||||
- name: OTEL_EXPORTED_OTLP_ENABLED
|
||||
value: "{{ .Values.opentelemetry.enabled }}"
|
||||
- name: OTEL_EXPORTED_OTLP_ROUTING_ENABLED
|
||||
value: "{{ .Values.opentelemetry.routingEnabled }}"
|
||||
{{- end }}
|
||||
- name: OTEL_EXPORTER_OTLP_ENDPOINT
|
||||
value: "{{ .Values.opentelemetry.collector.endpoint }}"
|
||||
{{- end }}
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
@@ -89,4 +102,5 @@ spec:
|
||||
targetPort: 8080
|
||||
protocol: TCP
|
||||
selector:
|
||||
app: pipe-dominantcolor
|
||||
app: pipe-dominantcolor
|
||||
{{- end }}
|
||||
@@ -29,6 +29,20 @@ spec:
|
||||
imagePullSecrets:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- $mongodbTLS := .Values.mongodb.tls }}
|
||||
{{- if or .Values.kerberospipeline.event.volumes (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
|
||||
volumes:
|
||||
{{- with .Values.kerberospipeline.event.volumes }}
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
|
||||
{{- include "hub.mongodb.tlsVolume" . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- with .Values.kerberospipeline.event.topologySpreadConstraints }}
|
||||
topologySpreadConstraints:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
containers:
|
||||
- name: pipe-event
|
||||
image: "{{ .Values.global.imageRegistry }}{{ .Values.kerberospipeline.event.repository }}:{{ .Values.kerberospipeline.event.tag }}"
|
||||
@@ -37,6 +51,15 @@ spec:
|
||||
resources:
|
||||
{{- toYaml . | nindent 12 }}
|
||||
{{- end }}
|
||||
{{- if or .Values.kerberospipeline.event.volumeMounts (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
|
||||
volumeMounts:
|
||||
{{- with .Values.kerberospipeline.event.volumeMounts }}
|
||||
{{- toYaml . | nindent 12 }}
|
||||
{{- end }}
|
||||
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
|
||||
{{- include "hub.mongodb.tlsVolumeMount" . | nindent 12 }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
ports:
|
||||
- containerPort: 8080
|
||||
envFrom:
|
||||
@@ -74,14 +97,15 @@ spec:
|
||||
- name: RABBITMQ_PASSWORD
|
||||
value: "{{ .Values.rabbitmq.password }}"
|
||||
|
||||
{{- if .Values.opentelemetry.enabled }}
|
||||
# Open Telemetry tracing
|
||||
- name: OTEL_EXPORTED_OTLP_ENABLED
|
||||
value: "{{ .Values.opentelemetry.enabled }}"
|
||||
- name: OTEL_EXPORTED_OTLP_ROUTING_ENABLED
|
||||
value: "{{ .Values.opentelemetry.routingEnabled }}"
|
||||
{{- end }}
|
||||
- name: OTEL_EXPORTER_OTLP_ENDPOINT
|
||||
value: "{{ .Values.opentelemetry.collector.endpoint }}"
|
||||
{{- end }}
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
@@ -99,3 +123,4 @@ spec:
|
||||
protocol: TCP
|
||||
selector:
|
||||
app: pipe-event
|
||||
{{- end }}
|
||||
|
||||
@@ -29,6 +29,20 @@ spec:
|
||||
imagePullSecrets:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- $mongodbTLS := .Values.mongodb.tls }}
|
||||
{{- if or .Values.kerberospipeline.export.volumes (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
|
||||
volumes:
|
||||
{{- with .Values.kerberospipeline.export.volumes }}
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
|
||||
{{- include "hub.mongodb.tlsVolume" . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- with .Values.kerberospipeline.export.topologySpreadConstraints }}
|
||||
topologySpreadConstraints:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
containers:
|
||||
- name: pipe-export
|
||||
image: "{{ .Values.global.imageRegistry }}{{ .Values.kerberospipeline.export.repository }}:{{ .Values.kerberospipeline.export.tag }}"
|
||||
@@ -37,12 +51,25 @@ spec:
|
||||
resources:
|
||||
{{- toYaml . | nindent 12 }}
|
||||
{{- end }}
|
||||
{{- if or .Values.kerberospipeline.export.volumeMounts (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
|
||||
volumeMounts:
|
||||
{{- with .Values.kerberospipeline.export.volumeMounts }}
|
||||
{{- toYaml . | nindent 12 }}
|
||||
{{- end }}
|
||||
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
|
||||
{{- include "hub.mongodb.tlsVolumeMount" . | nindent 12 }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
envFrom:
|
||||
- configMapRef:
|
||||
name: mongodb-config
|
||||
env:
|
||||
- name: LOG_LEVEL
|
||||
value: "{{ .Values.kerberospipeline.export.logLevel }}"
|
||||
{{- if .Values.kerberospipeline.export.playerAssetsPath }}
|
||||
- name: PLAYER_ASSETS_PATH
|
||||
value: "{{ .Values.kerberospipeline.export.playerAssetsPath }}"
|
||||
{{- end }}
|
||||
- name: CLOUD_PROVIDER
|
||||
value: "{{ .Values.cloudProvider }}"
|
||||
- name: QUEUE_SYSTEM
|
||||
@@ -106,14 +133,15 @@ spec:
|
||||
- name: VAULT_THUMBNAIL_SECRET_KEY
|
||||
value: "{{ .Values.kerberosvault.thumbnail.secretKey }}"
|
||||
|
||||
{{- if .Values.opentelemetry.enabled }}
|
||||
# Open Telemetry tracing
|
||||
- name: OTEL_EXPORTED_OTLP_ENABLED
|
||||
value: "{{ .Values.opentelemetry.enabled }}"
|
||||
- name: OTEL_EXPORTED_OTLP_ROUTING_ENABLED
|
||||
value: "{{ .Values.opentelemetry.routingEnabled }}"
|
||||
{{- end }}
|
||||
- name: OTEL_EXPORTER_OTLP_ENDPOINT
|
||||
value: "{{ .Values.opentelemetry.collector.endpoint }}"
|
||||
{{- end }}
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
@@ -130,4 +158,5 @@ spec:
|
||||
targetPort: 8080
|
||||
protocol: TCP
|
||||
selector:
|
||||
app: pipe-export
|
||||
app: pipe-export
|
||||
{{- end }}
|
||||
@@ -29,6 +29,20 @@ spec:
|
||||
imagePullSecrets:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- $mongodbTLS := .Values.mongodb.tls }}
|
||||
{{- if or .Values.kerberospipeline.monitor.volumes (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
|
||||
volumes:
|
||||
{{- with .Values.kerberospipeline.monitor.volumes }}
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
|
||||
{{- include "hub.mongodb.tlsVolume" . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- with .Values.kerberospipeline.monitor.topologySpreadConstraints }}
|
||||
topologySpreadConstraints:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
containers:
|
||||
- name: pipe-monitor
|
||||
image: "{{ .Values.global.imageRegistry }}{{ .Values.kerberospipeline.monitor.repository }}:{{ .Values.kerberospipeline.monitor.tag }}"
|
||||
@@ -37,6 +51,15 @@ spec:
|
||||
resources:
|
||||
{{- toYaml . | nindent 12 }}
|
||||
{{- end }}
|
||||
{{- if or .Values.kerberospipeline.monitor.volumeMounts (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
|
||||
volumeMounts:
|
||||
{{- with .Values.kerberospipeline.monitor.volumeMounts }}
|
||||
{{- toYaml . | nindent 12 }}
|
||||
{{- end }}
|
||||
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
|
||||
{{- include "hub.mongodb.tlsVolumeMount" . | nindent 12 }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
envFrom:
|
||||
- configMapRef:
|
||||
name: mongodb-config
|
||||
@@ -91,14 +114,15 @@ spec:
|
||||
- name: SMTP_PASSWORD
|
||||
value: "{{ .Values.email.smtp.password }}"
|
||||
|
||||
{{- if .Values.opentelemetry.enabled }}
|
||||
# Open Telemetry tracing
|
||||
- name: OTEL_EXPORTED_OTLP_ENABLED
|
||||
value: "{{ .Values.opentelemetry.enabled }}"
|
||||
- name: OTEL_EXPORTED_OTLP_ROUTING_ENABLED
|
||||
value: "{{ .Values.opentelemetry.routingEnabled }}"
|
||||
{{- end }}
|
||||
- name: OTEL_EXPORTER_OTLP_ENDPOINT
|
||||
value: "{{ .Values.opentelemetry.collector.endpoint }}"
|
||||
{{- end }}
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
@@ -115,4 +139,5 @@ spec:
|
||||
targetPort: 8080
|
||||
protocol: TCP
|
||||
selector:
|
||||
app: pipe-monitor
|
||||
app: pipe-monitor
|
||||
{{- end }}
|
||||
@@ -29,8 +29,18 @@ spec:
|
||||
imagePullSecrets:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- with .Values.kerberospipeline.notifyTest.volumes }}
|
||||
{{- $mongodbTLS := .Values.mongodb.tls }}
|
||||
{{- if or .Values.kerberospipeline.notifyTest.volumes (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
|
||||
volumes:
|
||||
{{- with .Values.kerberospipeline.notifyTest.volumes }}
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
|
||||
{{- include "hub.mongodb.tlsVolume" . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- with .Values.kerberospipeline.notifyTest.topologySpreadConstraints }}
|
||||
topologySpreadConstraints:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
containers:
|
||||
@@ -41,10 +51,15 @@ spec:
|
||||
resources:
|
||||
{{- toYaml . | nindent 12 }}
|
||||
{{- end }}
|
||||
{{- with .Values.kerberospipeline.notifyTest.volumeMounts}}
|
||||
{{- if or .Values.kerberospipeline.notifyTest.volumeMounts (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
|
||||
volumeMounts:
|
||||
{{- with .Values.kerberospipeline.notifyTest.volumeMounts}}
|
||||
{{- toYaml . | nindent 12 }}
|
||||
{{- end }}
|
||||
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
|
||||
{{- include "hub.mongodb.tlsVolumeMount" . | nindent 12 }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
envFrom:
|
||||
- configMapRef:
|
||||
name: mongodb-config
|
||||
@@ -89,6 +104,8 @@ spec:
|
||||
value: "{{ .Values.email.from }}"
|
||||
- name: EMAIL_FROM_DISPLAYNAME
|
||||
value: "{{ .Values.email.displayName }}"
|
||||
- name: PUBLIC_URL
|
||||
value: "{{ .Values.kerberoshub.frontend.schema }}://{{ .Values.kerberoshub.frontend.url }}"
|
||||
|
||||
# Mail templates
|
||||
- name: DETECT_TEMPLATE
|
||||
@@ -104,14 +121,15 @@ spec:
|
||||
- name: SMTP_PASSWORD
|
||||
value: "{{ .Values.email.smtp.password }}"
|
||||
|
||||
{{- if .Values.opentelemetry.enabled }}
|
||||
# Open Telemetry tracing
|
||||
- name: OTEL_EXPORTED_OTLP_ENABLED
|
||||
value: "{{ .Values.opentelemetry.enabled }}"
|
||||
- name: OTEL_EXPORTED_OTLP_ROUTING_ENABLED
|
||||
value: "{{ .Values.opentelemetry.routingEnabled }}"
|
||||
{{- end }}
|
||||
- name: OTEL_EXPORTER_OTLP_ENDPOINT
|
||||
value: "{{ .Values.opentelemetry.collector.endpoint }}"
|
||||
{{- end }}
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
@@ -128,4 +146,5 @@ spec:
|
||||
targetPort: 8080
|
||||
protocol: TCP
|
||||
selector:
|
||||
app: pipe-notify-test
|
||||
app: pipe-notify-test
|
||||
{{- end }}
|
||||
|
||||
@@ -29,8 +29,18 @@ spec:
|
||||
imagePullSecrets:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- with .Values.kerberospipeline.notify.volumes }}
|
||||
{{- $mongodbTLS := .Values.mongodb.tls }}
|
||||
{{- if or .Values.kerberospipeline.notify.volumes (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
|
||||
volumes:
|
||||
{{- with .Values.kerberospipeline.notify.volumes }}
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
|
||||
{{- include "hub.mongodb.tlsVolume" . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- with .Values.kerberospipeline.notify.topologySpreadConstraints }}
|
||||
topologySpreadConstraints:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
containers:
|
||||
@@ -41,10 +51,15 @@ spec:
|
||||
resources:
|
||||
{{- toYaml . | nindent 12 }}
|
||||
{{- end }}
|
||||
{{- with .Values.kerberospipeline.notify.volumeMounts}}
|
||||
{{- if or .Values.kerberospipeline.notify.volumeMounts (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
|
||||
volumeMounts:
|
||||
{{- with .Values.kerberospipeline.notify.volumeMounts}}
|
||||
{{- toYaml . | nindent 12 }}
|
||||
{{- end }}
|
||||
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
|
||||
{{- include "hub.mongodb.tlsVolumeMount" . | nindent 12 }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
envFrom:
|
||||
- configMapRef:
|
||||
name: mongodb-config
|
||||
@@ -92,6 +107,8 @@ spec:
|
||||
value: "{{ .Values.email.from }}"
|
||||
- name: EMAIL_FROM_DISPLAYNAME
|
||||
value: "{{ .Values.email.displayName }}"
|
||||
- name: PUBLIC_URL
|
||||
value: "{{ .Values.kerberoshub.frontend.schema }}://{{ .Values.kerberoshub.frontend.url }}"
|
||||
|
||||
# Mail templates
|
||||
- name: DETECT_TEMPLATE
|
||||
@@ -136,14 +153,15 @@ spec:
|
||||
- name: VAULT_SPRITE_SECRET_KEY
|
||||
value: "{{ .Values.kerberosvault.sprite.secretKey }}"
|
||||
|
||||
{{- if .Values.opentelemetry.enabled }}
|
||||
# Open Telemetry tracing
|
||||
- name: OTEL_EXPORTED_OTLP_ENABLED
|
||||
value: "{{ .Values.opentelemetry.enabled }}"
|
||||
- name: OTEL_EXPORTED_OTLP_ROUTING_ENABLED
|
||||
value: "{{ .Values.opentelemetry.routingEnabled }}"
|
||||
{{- end }}
|
||||
- name: OTEL_EXPORTER_OTLP_ENDPOINT
|
||||
value: "{{ .Values.opentelemetry.collector.endpoint }}"
|
||||
{{- end }}
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
@@ -160,4 +178,5 @@ spec:
|
||||
targetPort: 8080
|
||||
protocol: TCP
|
||||
selector:
|
||||
app: pipe-notify
|
||||
app: pipe-notify
|
||||
{{- end }}
|
||||
|
||||
@@ -29,6 +29,20 @@ spec:
|
||||
imagePullSecrets:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- $mongodbTLS := .Values.mongodb.tls }}
|
||||
{{- if or .Values.kerberospipeline.sequence.volumes (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
|
||||
volumes:
|
||||
{{- with .Values.kerberospipeline.sequence.volumes }}
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
|
||||
{{- include "hub.mongodb.tlsVolume" . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- with .Values.kerberospipeline.sequence.topologySpreadConstraints }}
|
||||
topologySpreadConstraints:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
containers:
|
||||
- name: pipe-sequence
|
||||
image: "{{ .Values.global.imageRegistry }}{{ .Values.kerberospipeline.sequence.repository }}:{{ .Values.kerberospipeline.sequence.tag }}"
|
||||
@@ -37,6 +51,15 @@ spec:
|
||||
resources:
|
||||
{{- toYaml . | nindent 12 }}
|
||||
{{- end }}
|
||||
{{- if or .Values.kerberospipeline.sequence.volumeMounts (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
|
||||
volumeMounts:
|
||||
{{- with .Values.kerberospipeline.sequence.volumeMounts }}
|
||||
{{- toYaml . | nindent 12 }}
|
||||
{{- end }}
|
||||
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
|
||||
{{- include "hub.mongodb.tlsVolumeMount" . | nindent 12 }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
envFrom:
|
||||
- configMapRef:
|
||||
name: mongodb-config
|
||||
@@ -68,14 +91,15 @@ spec:
|
||||
- name: RABBITMQ_PASSWORD
|
||||
value: "{{ .Values.rabbitmq.password }}"
|
||||
|
||||
{{- if .Values.opentelemetry.enabled }}
|
||||
# Open Telemetry tracing
|
||||
- name: OTEL_EXPORTED_OTLP_ENABLED
|
||||
value: "{{ .Values.opentelemetry.enabled }}"
|
||||
- name: OTEL_EXPORTED_OTLP_ROUTING_ENABLED
|
||||
value: "{{ .Values.opentelemetry.routingEnabled }}"
|
||||
{{- end }}
|
||||
- name: OTEL_EXPORTER_OTLP_ENDPOINT
|
||||
value: "{{ .Values.opentelemetry.collector.endpoint }}"
|
||||
{{- end }}
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
@@ -92,4 +116,5 @@ spec:
|
||||
targetPort: 8080
|
||||
protocol: TCP
|
||||
selector:
|
||||
app: pipe-sequence
|
||||
app: pipe-sequence
|
||||
{{- end }}
|
||||
@@ -27,6 +27,14 @@ spec:
|
||||
imagePullSecrets:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- with .Values.kerberospipeline.sprite.volumes }}
|
||||
volumes:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- with .Values.kerberospipeline.sprite.topologySpreadConstraints }}
|
||||
topologySpreadConstraints:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
containers:
|
||||
- name: pipe-sprite
|
||||
image: "{{ .Values.global.imageRegistry }}{{ .Values.kerberospipeline.sprite.repository }}:{{ .Values.kerberospipeline.sprite.tag }}"
|
||||
@@ -35,6 +43,10 @@ spec:
|
||||
resources:
|
||||
{{- toYaml . | nindent 12 }}
|
||||
{{- end }}
|
||||
{{- with .Values.kerberospipeline.sprite.volumeMounts }}
|
||||
volumeMounts:
|
||||
{{- toYaml . | nindent 12 }}
|
||||
{{- end }}
|
||||
env:
|
||||
- name: LOG_LEVEL
|
||||
value: "{{ .Values.kerberospipeline.sprite.logLevel }}"
|
||||
@@ -88,6 +100,7 @@ spec:
|
||||
- name: VAULT_SPRITE_HEIGHT
|
||||
value: "{{ .Values.kerberospipeline.sprite.height }}"
|
||||
|
||||
{{- if .Values.opentelemetry.enabled }}
|
||||
# Open Telemetry tracing
|
||||
- name: OTEL_EXPORTED_OTLP_ENABLED
|
||||
value: "{{ .Values.opentelemetry.enabled }}"
|
||||
@@ -95,6 +108,7 @@ spec:
|
||||
value: "{{ .Values.opentelemetry.routingEnabled }}"
|
||||
- name: OTEL_EXPORTER_OTLP_ENDPOINT
|
||||
value: "{{ .Values.opentelemetry.collector.endpoint }}"
|
||||
{{- end }}
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
|
||||
@@ -29,6 +29,20 @@ spec:
|
||||
imagePullSecrets:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- $mongodbTLS := .Values.mongodb.tls }}
|
||||
{{- if or .Values.kerberospipeline.throttler.volumes (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
|
||||
volumes:
|
||||
{{- with .Values.kerberospipeline.throttler.volumes }}
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
|
||||
{{- include "hub.mongodb.tlsVolume" . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- with .Values.kerberospipeline.throttler.topologySpreadConstraints }}
|
||||
topologySpreadConstraints:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
containers:
|
||||
- name: pipe-throttler
|
||||
image: "{{ .Values.global.imageRegistry }}{{ .Values.kerberospipeline.throttler.repository }}:{{ .Values.kerberospipeline.throttler.tag }}"
|
||||
@@ -37,6 +51,15 @@ spec:
|
||||
resources:
|
||||
{{- toYaml . | nindent 12 }}
|
||||
{{- end }}
|
||||
{{- if or .Values.kerberospipeline.throttler.volumeMounts (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
|
||||
volumeMounts:
|
||||
{{- with .Values.kerberospipeline.throttler.volumeMounts }}
|
||||
{{- toYaml . | nindent 12 }}
|
||||
{{- end }}
|
||||
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
|
||||
{{- include "hub.mongodb.tlsVolumeMount" . | nindent 12 }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
envFrom:
|
||||
- configMapRef:
|
||||
name: mongodb-config
|
||||
@@ -70,14 +93,15 @@ spec:
|
||||
- name: RABBITMQ_PASSWORD
|
||||
value: "{{ .Values.rabbitmq.password }}"
|
||||
|
||||
{{- if .Values.opentelemetry.enabled }}
|
||||
# Open Telemetry tracing
|
||||
- name: OTEL_EXPORTED_OTLP_ENABLED
|
||||
value: "{{ .Values.opentelemetry.enabled }}"
|
||||
- name: OTEL_EXPORTED_OTLP_ROUTING_ENABLED
|
||||
value: "{{ .Values.opentelemetry.routingEnabled }}"
|
||||
{{- end }}
|
||||
- name: OTEL_EXPORTER_OTLP_ENDPOINT
|
||||
value: "{{ .Values.opentelemetry.collector.endpoint }}"
|
||||
{{- end }}
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
@@ -94,4 +118,5 @@ spec:
|
||||
targetPort: 8080
|
||||
protocol: TCP
|
||||
selector:
|
||||
app: pipe-throttler
|
||||
app: pipe-throttler
|
||||
{{- end }}
|
||||
@@ -27,6 +27,14 @@ spec:
|
||||
imagePullSecrets:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- with .Values.kerberospipeline.thumbnail.volumes }}
|
||||
volumes:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- with .Values.kerberospipeline.thumbnail.topologySpreadConstraints }}
|
||||
topologySpreadConstraints:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
containers:
|
||||
- name: pipe-thumbnail
|
||||
image: "{{ .Values.global.imageRegistry }}{{ .Values.kerberospipeline.thumbnail.repository }}:{{ .Values.kerberospipeline.thumbnail.tag }}"
|
||||
@@ -35,6 +43,10 @@ spec:
|
||||
resources:
|
||||
{{- toYaml . | nindent 12 }}
|
||||
{{- end }}
|
||||
{{- with .Values.kerberospipeline.thumbnail.volumeMounts }}
|
||||
volumeMounts:
|
||||
{{- toYaml . | nindent 12 }}
|
||||
{{- end }}
|
||||
env:
|
||||
- name: LOG_LEVEL
|
||||
value: "{{ .Values.kerberospipeline.thumbnail.logLevel }}"
|
||||
@@ -91,14 +103,15 @@ spec:
|
||||
- name: VAULT_THUMBNAIL_SECRET_KEY
|
||||
value: "{{ .Values.kerberosvault.thumbnail.secretKey }}"
|
||||
|
||||
{{- if .Values.opentelemetry.enabled }}
|
||||
# Open Telemetry tracing
|
||||
- name: OTEL_EXPORTED_OTLP_ENABLED
|
||||
value: "{{ .Values.opentelemetry.enabled }}"
|
||||
- name: OTEL_EXPORTED_OTLP_ROUTING_ENABLED
|
||||
value: "{{ .Values.opentelemetry.routingEnabled }}"
|
||||
{{- end }}
|
||||
- name: OTEL_EXPORTER_OTLP_ENDPOINT
|
||||
value: "{{ .Values.opentelemetry.collector.endpoint }}"
|
||||
{{- end }}
|
||||
|
||||
---
|
||||
apiVersion: v1
|
||||
@@ -116,4 +129,5 @@ spec:
|
||||
targetPort: 8080
|
||||
protocol: TCP
|
||||
selector:
|
||||
app: pipe-thumbnail
|
||||
app: pipe-thumbnail
|
||||
{{- end }}
|
||||
@@ -27,6 +27,20 @@ spec:
|
||||
imagePullSecrets:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- $mongodbTLS := .Values.mongodb.tls }}
|
||||
{{- if or .Values.kerberoshub.forwarder.volumes (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
|
||||
volumes:
|
||||
{{- with .Values.kerberoshub.forwarder.volumes }}
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
|
||||
{{- include "hub.mongodb.tlsVolume" . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
{{- with .Values.kerberoshub.forwarder.topologySpreadConstraints }}
|
||||
topologySpreadConstraints:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
containers:
|
||||
- name: vault-forwarder
|
||||
image: "{{ .Values.global.imageRegistry }}{{ .Values.kerberoshub.forwarder.repository }}:{{ .Values.kerberoshub.forwarder.tag }}"
|
||||
@@ -35,6 +49,15 @@ spec:
|
||||
requests:
|
||||
memory: 10Mi
|
||||
cpu: 10m
|
||||
{{- if or .Values.kerberoshub.forwarder.volumeMounts (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
|
||||
volumeMounts:
|
||||
{{- with .Values.kerberoshub.forwarder.volumeMounts }}
|
||||
{{- toYaml . | nindent 12 }}
|
||||
{{- end }}
|
||||
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
|
||||
{{- include "hub.mongodb.tlsVolumeMount" . | nindent 12 }}
|
||||
{{- end }}
|
||||
{{- end }}
|
||||
envFrom:
|
||||
- configMapRef:
|
||||
name: mongodb-config
|
||||
|
||||
@@ -24,10 +24,22 @@ spec:
|
||||
imagePullSecrets:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- with .Values.kerberoshub.proxy.volumes }}
|
||||
volumes:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
{{- with .Values.kerberoshub.proxy.topologySpreadConstraints }}
|
||||
topologySpreadConstraints:
|
||||
{{- toYaml . | nindent 8 }}
|
||||
{{- end }}
|
||||
containers:
|
||||
- name: vault-proxy
|
||||
image: "{{ .Values.global.imageRegistry }}{{ .Values.kerberoshub.proxy.repository }}:{{ .Values.kerberoshub.proxy.tag }}"
|
||||
imagePullPolicy: {{ .Values.kerberoshub.proxy.pullPolicy }}
|
||||
{{- with .Values.kerberoshub.proxy.volumeMounts }}
|
||||
volumeMounts:
|
||||
{{- toYaml . | nindent 12 }}
|
||||
{{- end }}
|
||||
ports:
|
||||
- containerPort: 8080
|
||||
name: http
|
||||
|
||||
@@ -19,14 +19,12 @@ licenseServer:
|
||||
environment: "production"
|
||||
isPrivate: true # Set to 'true' if this is a private deployment.
|
||||
readOnly: false # Set to 'true' to halt all write operations to the database (e.g. migration, etc).
|
||||
|
||||
###################################################################
|
||||
# Deployment mode: all | pipeline | ui
|
||||
# - all: Hub services + pipeline + vault
|
||||
# - pipeline: pipeline only
|
||||
# - ui: Hub services only
|
||||
mode: "all"
|
||||
|
||||
###########################################################################
|
||||
# Global configuration
|
||||
###########################################################################
|
||||
@@ -56,6 +54,21 @@ mongodb:
|
||||
username: yourusername
|
||||
password: "yourpassword"
|
||||
retryWrites: "true"
|
||||
# Backend engine flavor. Use "mongodb" for native MongoDB / Atlas (default)
|
||||
# or "documentdb" for AWS DocumentDB. The "documentdb" flavor makes the
|
||||
# hub-api disable features DocumentDB does not support (geospatial queries
|
||||
# and indexes, complex $lookup pipelines, etc.). When using DocumentDB you
|
||||
# should also set retryWrites: "false".
|
||||
flavor: "mongodb"
|
||||
# TLS for MongoDB-compatible backends. When uri is set, missing TLS query
|
||||
# parameters are appended automatically. AWS DocumentDB requires TLS and a
|
||||
# trusted RDS CA bundle, typically stored in an existing Kubernetes Secret.
|
||||
tls:
|
||||
enabled: false
|
||||
existingSecret: ""
|
||||
caFileName: ""
|
||||
mountPath: "/etc/mongodb/tls"
|
||||
insecureSkipVerify: false
|
||||
###################################################
|
||||
# MQTT configuration (bi-directional communication)
|
||||
###################################################
|
||||
@@ -117,7 +130,12 @@ opentelemetry:
|
||||
enabled: false
|
||||
routingEnabled: false
|
||||
collector:
|
||||
endpoint: "http://otel-collector:4317"
|
||||
# NOTE: the services use the OTLP *HTTP* exporter, so this must be the
|
||||
# collector's HTTP port (4318) and must include the scheme. Use http://
|
||||
# for a plaintext in-cluster collector (e.g. Jaeger) and https:// only if
|
||||
# the collector terminates TLS. A scheme-less value defaults to TLS and
|
||||
# fails against a plaintext collector ("server gave HTTP response to HTTPS client").
|
||||
endpoint: "http://otel-collector:4318"
|
||||
############################################
|
||||
# OpenAI configuration (semantic search)
|
||||
#
|
||||
@@ -159,6 +177,23 @@ admin:
|
||||
pullPolicy: IfNotPresent
|
||||
tag: "v1.3.0"
|
||||
replicas: 2
|
||||
# Optional pod topology spread constraints for this deployment. Empty by
|
||||
# default. Example:
|
||||
# topologySpreadConstraints:
|
||||
# - maxSkew: 1
|
||||
# topologyKey: kubernetes.io/hostname
|
||||
# whenUnsatisfiable: ScheduleAnyway
|
||||
# labelSelector:
|
||||
# matchLabels:
|
||||
# app: admin
|
||||
topologySpreadConstraints: []
|
||||
# Optional extra volumes / volumeMounts for this deployment (empty = none).
|
||||
#volumes:
|
||||
# - name: extra
|
||||
# emptyDir: {}
|
||||
#volumeMounts:
|
||||
# - name: extra
|
||||
# mountPath: /data
|
||||
logLevel: "info" # possible values: trace, debug, info, warn, error
|
||||
resources:
|
||||
requests:
|
||||
@@ -171,13 +206,20 @@ admin:
|
||||
secretName: admin
|
||||
oauth2Proxy:
|
||||
enabled: false
|
||||
topologySpreadConstraints: [] # Optional pod topology spread constraints (empty = none).
|
||||
# Optional extra volumes / volumeMounts for this deployment (empty = none).
|
||||
#volumes:
|
||||
# - name: extra
|
||||
# emptyDir: {}
|
||||
#volumeMounts:
|
||||
# - name: extra
|
||||
# mountPath: /data
|
||||
github:
|
||||
clientId: "github-client-id"
|
||||
clientSecret: "github-client-secret"
|
||||
cookieSecret: "generate-a-random-cookie-secret"
|
||||
organization: "github-organization"
|
||||
team: "github-team"
|
||||
|
||||
###########################################################################
|
||||
# Following are all the different deployments needed to make
|
||||
# Hub properly working.
|
||||
@@ -198,8 +240,12 @@ kerberoshub:
|
||||
api:
|
||||
repository: ghcr.io/uug-ai/hub-api
|
||||
pullPolicy: IfNotPresent
|
||||
tag: "v1.8.20"
|
||||
tag: "v1.9.51"
|
||||
replicas: 2
|
||||
topologySpreadConstraints: [] # Optional pod topology spread constraints (empty = none).
|
||||
# Set to false to skip rendering the hub-api Service (e.g. when an
|
||||
# external/shared Service is managed elsewhere).
|
||||
serviceEnabled: true
|
||||
logLevel: "info" # possible values: trace, debug, info, warn, error
|
||||
jwtSecret: "this-is-a-secret-please-change-to-random-string" # change to a random value, this is for generating JWT tokens.
|
||||
schema: "https"
|
||||
@@ -229,7 +275,6 @@ kerberoshub:
|
||||
mountPath: "/etc/hub-api/tls"
|
||||
certFile: "/etc/hub-api/tls/tls.crt"
|
||||
keyFile: "/etc/hub-api/tls/tls.key"
|
||||
|
||||
# When migrating to another url, this might help migrating.
|
||||
#legacyUrl: "api.legacy.yourdomain.com"
|
||||
|
||||
@@ -238,6 +283,18 @@ kerberoshub:
|
||||
# Admin API's are made available for automation of Kerberos Hub.
|
||||
# To access those API's (e.g. creation of owner users), an API key needs to be provided.
|
||||
apiKey: "a-random-admin-api-key"
|
||||
# Default retention (in days) applied to tasks that do not have an
|
||||
# explicit `retention_days` set. New tasks created without a custom
|
||||
# retention are stamped with this value. Set to "0" (or a negative
|
||||
# value) to disable the default retention (tasks are kept indefinitely
|
||||
# unless an explicit value is provided). Must match the value used by
|
||||
# `kerberoshub.cleanup.defaultTaskRetentionDays`.
|
||||
defaultTaskRetentionDays: "0"
|
||||
# Maximum retention (in days) allowed on a task. When a caller
|
||||
# supplies an `expires_at` (or the default retention above resolves)
|
||||
# beyond this cap, the value is clamped down to `now + casesMaxRetentionDays`.
|
||||
# Set to "0" (or a negative value) to disable the cap (no maximum).
|
||||
casesMaxRetentionDays: "0"
|
||||
## Certificates
|
||||
tls:
|
||||
- hosts:
|
||||
@@ -296,8 +353,12 @@ kerberoshub:
|
||||
frontend:
|
||||
repository: ghcr.io/uug-ai/hub-frontend
|
||||
pullPolicy: IfNotPresent
|
||||
tag: "v1.8.11"
|
||||
tag: "v1.13.9"
|
||||
replicas: 2
|
||||
topologySpreadConstraints: [] # Optional pod topology spread constraints (empty = none).
|
||||
# Set to false to skip rendering the hub-frontend Service (e.g. when an
|
||||
# external/shared Service is managed elsewhere).
|
||||
serviceEnabled: true
|
||||
logLevel: "info" # possible values: trace, debug, info, warn, error
|
||||
schema: "https"
|
||||
url: "yourdomain.com"
|
||||
@@ -308,7 +369,9 @@ kerberoshub:
|
||||
limits:
|
||||
memory: 50Mi
|
||||
cpu: 50m
|
||||
# The front-end but in read-only mode
|
||||
# The front-end but in read-only mode. Set demoEnabled to true to deploy
|
||||
# the demo front-end (service, ingress and deployment).
|
||||
demoEnabled: false
|
||||
#demoUrl: "demo.yourdomain.com"
|
||||
# When migrating to another url, this might help migrating.
|
||||
#legacyUrl: "legacy.yourdomain.com"
|
||||
@@ -340,14 +403,34 @@ kerberoshub:
|
||||
# 2. you bring your own logo (set logo to 'custom'), and mount the css file and favicons.
|
||||
# we will need to include your logo in the Docker image, so please reach out to us.
|
||||
logo: "custom"
|
||||
# Custom layout: override css
|
||||
# By providing a style.css file in the custom folder
|
||||
# this file will override any css styling.
|
||||
# Custom layout: override css, favicons and translations (i18n)
|
||||
# By providing a style.css file in the custom folder this file will override
|
||||
# any css styling. Favicons are mounted into the favicon folder.
|
||||
#
|
||||
# Translations (i18n): for each language the served strings are
|
||||
# deepMerge(assets/i18n/<lang>.json, assets/i18n-custom/<lang>.json)
|
||||
# — your optional overrides layered on top of the shipped base file. To
|
||||
# customise, mount a volume at assets/i18n-custom holding <lang>.json files
|
||||
# with the keys you want to change. Any key you omit falls back to the shipped
|
||||
# value, so keys added in future releases always render a real string (never a
|
||||
# raw key) and you only maintain your diffs. Put as little or as much here as
|
||||
# you like — even a complete file — but mounting at this overlay layer is
|
||||
# always the safe choice, because missing keys can never leak into the UI.
|
||||
# You only need files for the languages you actually customise. A partial
|
||||
# example lives in custom-layout/i18n-custom/en.json; the matching complete
|
||||
# files (handy to copy keys from) are published as hub-frontend release assets
|
||||
# (en.json / i18n-<tag>.zip) and ship in the image at assets/i18n.
|
||||
#
|
||||
# (Backward compatibility: deployments that instead mount complete files over
|
||||
# assets/i18n keep working, but that layer has no fallback — any key you do
|
||||
# not supply shows as a raw key — so prefer assets/i18n-custom for new setups.)
|
||||
#volumeMounts:
|
||||
# - name: custom-layout
|
||||
# mountPath: /usr/share/nginx/html/assets/custom
|
||||
# - name: custom-favicon
|
||||
# mountPath: /usr/share/nginx/html/assets/favicon
|
||||
# - name: custom-i18n
|
||||
# mountPath: /usr/share/nginx/html/assets/i18n-custom
|
||||
#volumes:
|
||||
# - name: custom-layout
|
||||
# persistentVolumeClaim:
|
||||
@@ -355,44 +438,13 @@ kerberoshub:
|
||||
# - name: custom-favicon
|
||||
# persistentVolumeClaim:
|
||||
# claimName: custom-favicon-claim
|
||||
# - name: custom-i18n
|
||||
# persistentVolumeClaim:
|
||||
# claimName: custom-i18n-claim
|
||||
|
||||
# Override naming conventions within the front-end.
|
||||
floorPlanName: "map" # The name of the 'floor plan' feature to use in the front-end.
|
||||
sitesName: "site" # The name of the 'sites' feature to use in the front-end.
|
||||
sitesDescription: "" # The description of the 'sites' feature to use in the front-end.
|
||||
groupsName: "group" # The name of the 'groups' feature to use in the front-end.
|
||||
groupsDescription: "" # The description of the 'groups' feature to use in the front-end.
|
||||
siteGroupName: "site Group" # The name of the 'site groups' feature to use in the front-end.
|
||||
siteGroupDescription: "" # The description of the 'site groups' feature to use in the front-end.
|
||||
deviceGroupName: "device Group" # The name of the 'device groups' feature to use in the front-end.
|
||||
deviceGroupDescription: "" # The description of the 'device groups' feature to use in the front-end.
|
||||
markersName: "marker" # The name of the 'markers' feature to use in the front-end.
|
||||
eventsName: "event" # The name of the 'events' feature to use in the front-end.
|
||||
# By specifying the below environments variables, you can tweak the
|
||||
# headings and paragraphs of Kerberos Hub front-end.
|
||||
# Login page
|
||||
loginDescription: ""
|
||||
loginCopyright: ""
|
||||
# Dashboard page
|
||||
dashboardTitle: ""
|
||||
dashboardSubTitle: ""
|
||||
# Latest events page
|
||||
latestEventsTitle: ""
|
||||
latestEventsSubTitle: ""
|
||||
# Day title
|
||||
dayTitle: ""
|
||||
daySubTitle: ""
|
||||
# Livestream/view page
|
||||
livestreamTitle: ""
|
||||
livestreamSubTitle: ""
|
||||
# Media page
|
||||
mediaTitle: ""
|
||||
mediaSubTitle: ""
|
||||
# Optional - for custom page.
|
||||
cpuUsageDescription: ""
|
||||
framesPerSecondDescription: ""
|
||||
mlaUtilizationDescription: ""
|
||||
objectsDetectedDescription: ""
|
||||
# Note: Front-end naming/labelling and page headings are sourced from the
|
||||
# built-in internationalization files (assets/i18n/*.json) and are no
|
||||
# longer configurable via the Helm chart.
|
||||
# You can add custom links to the navigation bar.
|
||||
navigationLinkTitle1: ""
|
||||
navigationLinkUrl1: ""
|
||||
@@ -410,10 +462,32 @@ kerberoshub:
|
||||
features:
|
||||
# General
|
||||
darkModeEnabled: "true" # Enable or disable dark mode toggle 'true' or 'false'
|
||||
splashScreen:
|
||||
enabled: "true" # Enable or disable the pre-bootstrap splash screen 'true' or 'false'
|
||||
landingPage: "/dashboard" # Landing page after login '/dashboard', '/liveview', '/media', '/devices', '/sites', '/groups'
|
||||
# Internationalization (i18n): controls the runtime language behaviour
|
||||
# of the front-end. When `enabled` is "false" the language switcher is
|
||||
# hidden and `defaultLanguage` is always forced; users cannot change it.
|
||||
i18n:
|
||||
enabled: "true" # Enable or disable the language switcher 'true' or 'false'
|
||||
defaultLanguage: "en" # Default language code: en, nl, pl, tr, fr, sv, de
|
||||
# Case management is a feature that allows you to create cases, and link recordings, devices, sites, groups, markers and events to those cases.
|
||||
case:
|
||||
enabled: "true" # Enable or disable case management feature 'true' or 'false'
|
||||
# Workflows allow you to define automated processes and actions in the front-end.
|
||||
workflows:
|
||||
enabled: "false" # Enable or disable workflows feature 'true' or 'false'
|
||||
# Organisation controls remain visible as a read-only current organisation when switching is disabled.
|
||||
organisations:
|
||||
enabled: "" # Enable or disable all organisation feature flags; when empty, the child settings apply independently
|
||||
switcherEnabled: "false" # Enable or disable organisation switching 'true' or 'false'
|
||||
creationEnabled: "false" # Enable or disable organisation creation; requires switcherEnabled 'true' or 'false'
|
||||
settingsEnabled: "false" # Enable or disable the organisation settings link 'true' or 'false'
|
||||
projects:
|
||||
enabled: "" # Enable or disable all project feature flags; when empty, the child settings apply independently
|
||||
switcherEnabled: "false" # Enable or disable the read-only project dropdown 'true' or 'false'
|
||||
creationEnabled: "false" # Reserved for project creation UI 'true' or 'false'
|
||||
settingsEnabled: "false" # Reserved for project settings UI 'true' or 'false'
|
||||
# Map tile configuration
|
||||
map:
|
||||
tileUrlLight: "https://{s}.basemaps.cartocdn.com/rastertiles/voyager/{z}/{x}/{y}{r}.png" # Map tile URL for light mode
|
||||
@@ -422,8 +496,13 @@ kerberoshub:
|
||||
# Live view page
|
||||
liveview:
|
||||
defaultStreamMode: "SD" # Default stream mode 'SD' or 'HD' (will be migrated to 'preview' or 'live')
|
||||
paginationEnabled: "false" # Enable or disable pagination in live view 'true' or 'false'
|
||||
emptyByDefault: "false" # Show empty live view when there are no active devices 'true' or 'false'
|
||||
liveStreamMode: "webrtc" # Transport backing the LIVE (HD) mode: 'webrtc' (default), 'hls' or 'moq'
|
||||
hlsEnabled: "true" # Offer HLS as a selectable LIVE transport 'true' or 'false'. When 'false' the HLS option is removed from the front-end and streams use webrtc
|
||||
moqEnabled: "false" # Offer MoQ as a selectable LIVE transport 'true' or 'false'
|
||||
moqRelayUrl: "https://relay.uug.ai/anon" # WebTransport URL of the MoQ relay
|
||||
moqBroadcastPrefix: "devices" # Prefix used to build devices/<deviceKey>/live.hang broadcast names
|
||||
paginationMode: "scroll" # Pagination mode in live view 'scroll', 'numbered' or 'maxStreams'
|
||||
pageSize: "6" # Max streams shown per page when paginationMode is 'numbered' (4, 8, 12, 16 or 25)
|
||||
maxStreams: "-1" # Maximum number of live streams to show in live view, -1 for unlimited
|
||||
# Device page
|
||||
devices:
|
||||
@@ -479,10 +558,13 @@ kerberoshub:
|
||||
colorTrackBoxHover: "hsla(47, 86%, 47%, 1)" # Boxes while hovering over the associated track
|
||||
colorTrackBoxDrawing: "hsla(204, 100%, 50%, 1)" # New box while drawing
|
||||
colorTrackBoxControlsDelete: "hsla(219, 100%, 94%, 1)" # Delete icon top right of the box while editing
|
||||
# Video edits feature (umbrella flag for in-app video editing tools, e.g. face redaction)
|
||||
videoEdits:
|
||||
enabled: "false" # Enable or disable video edit tools 'true' or 'false'
|
||||
# Face redaction feature
|
||||
faceRedaction:
|
||||
enabled: "false" # Enable or disable face redaction 'true' or 'false'
|
||||
|
||||
classifierTracksEnabled: "true" # Make classifier-generated tracks available in the redaction modal
|
||||
# Optional integrations
|
||||
mixpanel: # We can keep track logging in Mixpanel as well
|
||||
apikey: "xxx"
|
||||
@@ -501,6 +583,14 @@ kerberoshub:
|
||||
enabled: false
|
||||
oauth2Proxy:
|
||||
enabled: false
|
||||
topologySpreadConstraints: [] # Optional pod topology spread constraints (empty = none).
|
||||
# Optional extra volumes / volumeMounts for this deployment (empty = none).
|
||||
#volumes:
|
||||
# - name: extra
|
||||
# emptyDir: {}
|
||||
#volumeMounts:
|
||||
# - name: extra
|
||||
# mountPath: /data
|
||||
github:
|
||||
clientId: "github-client-id"
|
||||
clientSecret: "github-client-secret"
|
||||
@@ -508,21 +598,208 @@ kerberoshub:
|
||||
organization: "github-organization"
|
||||
team: "github-team"
|
||||
cleanup:
|
||||
repository: uugai/hub-cleanup
|
||||
repository: ghcr.io/uug-ai/hub-cleanup
|
||||
pullPolicy: IfNotPresent
|
||||
tag: "v1.4.1"
|
||||
tag: "v1.4.19"
|
||||
replicas: 1 # Number of pods for the service.
|
||||
topologySpreadConstraints: [] # Optional pod topology spread constraints (empty = none).
|
||||
# Optional extra volumes / volumeMounts for this deployment (empty = none).
|
||||
#volumes:
|
||||
# - name: extra
|
||||
# emptyDir: {}
|
||||
#volumeMounts:
|
||||
# - name: extra
|
||||
# mountPath: /data
|
||||
mode: "serve" # The mode the cleanup service operates in: serve | dry-run | version
|
||||
logLevel: "info" # possible values: trace, debug, info, warn, error
|
||||
maxDays: "365" # The maximum number of days to keep orphaned recordings.
|
||||
maxDays: "365" # Hard maximum age (days) for global orphan cleanup.
|
||||
runIntervalMinutes: "10" # Minutes between cleanup cycles.
|
||||
cleanupUsernames: "" # Optional comma-separated usernames to target.
|
||||
batchSize: "250" # Delete batch size per collection operation.
|
||||
userBatchSize: "100" # Users processed per in-memory batch.
|
||||
maxUsersPerRun: "100" # Hard cap of users processed each run.
|
||||
progressEvery: "100" # Print progress every N processed users.
|
||||
activeUserRescanHours: "6" # Next scan delay for active subscriptions.
|
||||
inactiveUserRescanHours: "24" # Next scan delay for inactive users.
|
||||
readTimeoutSeconds: "30" # Read/find/count timeout.
|
||||
deleteTimeoutSeconds: "120" # Delete timeout.
|
||||
reportIncludeStats: "false" # Include richer dry-run/user summary stats.
|
||||
dryRun: "false" # Force dry-run behavior without using mode=dry-run.
|
||||
debug: "false" # Extra per-user/global debug logging.
|
||||
globalPassEnabled: "false" # Enable post-user global cleanup pass.
|
||||
globalPassIntervalHours: "0" # 0 = every cycle when enabled.
|
||||
globalPassDeleteBudget: "0" # 0 = unlimited deletes during global pass.
|
||||
# Default retention (in days) applied to tasks without an explicit
|
||||
# `retention_days`. Tasks older than this (anchored on `creation_date`)
|
||||
# are deleted along with their `case_media` rows. Set to "0" (or a
|
||||
# negative value) to keep tasks without an explicit retention forever.
|
||||
# Tasks with `legal_hold=true` are never deleted. Must match the value
|
||||
# used by `kerberoshub.api.defaultTaskRetentionDays`.
|
||||
defaultTaskRetentionDays: "0"
|
||||
resources:
|
||||
requests:
|
||||
memory: 10Mi
|
||||
cpu: 10m
|
||||
# hub-workflows is the standalone, queue-driven workflow engine. It consumes
|
||||
# pipeline events and dispatches the stages declared in its workflow
|
||||
# definitions, tracking each run in its own `workflow_runs` collection. It shares events
|
||||
# (not a document) with the analysis pipeline and is meant to grow into the
|
||||
# primary orchestrator. See https://github.com/uug-ai/hub-workflows.
|
||||
workflows:
|
||||
# Disabled by default. When enabled, the analysis service tees each
|
||||
# classify result to this service (via WORKFLOWS_ENABLED on pipe-analysis)
|
||||
# in parallel with the normal throttler/notification tail, which still runs
|
||||
# unchanged. Flip to true to run the workflows engine.
|
||||
enabled: false
|
||||
# This block is purely behaviour: the master switch above plus the workflow
|
||||
# definitions below. The engine's own deployment (image/tag/replicas/queue/
|
||||
# resources) lives under kerberoshub.services.workflows, in the same uniform
|
||||
# shape as the stage workers it dispatches to.
|
||||
#
|
||||
# -----------------------------------------------------------------------
|
||||
# Global workflow definitions — the named workflows the engine runs.
|
||||
#
|
||||
# `definitions` is the engine's deployment-global configuration source and
|
||||
# stage catalog: several distinct workflows can run over one recording, each
|
||||
# opening its own run and dispatching only its own stages. Database-backed
|
||||
# organisation workflows, when present, are read separately per recording.
|
||||
# This is a MAP keyed by workflow name (names are unique and merge cleanly
|
||||
# across -f / --set overrides). Ships empty; the commented block is a worked
|
||||
# example of an object-tracking + loitering pipeline. Add more keys to run
|
||||
# more config workflows.
|
||||
#
|
||||
# Each definition:
|
||||
# enabled include this workflow (soft-delete toggle).
|
||||
# source always rendered as "config" (a Helm-defined, ops-managed,
|
||||
# deployment-global workflow — read-only in the API).
|
||||
# triggers how a run OPENS. Omit for a single bare automatic trigger
|
||||
# (opens for every recording); the per-stage `needs` then decide
|
||||
# which stages FIRE. Narrow with device/schedule triggers, e.g.
|
||||
# `- {type: automatic, devices: [{key: <device-key>}]}`.
|
||||
# stages the executable stages, each {operation, dispatch?, needs?,
|
||||
# needsMode?}. dispatch is "always" (default) or "conditional";
|
||||
# a conditional stage's `needs` are upstream dependencies, each
|
||||
# {operation?, condition?} — operation is the readiness GATE (the
|
||||
# upstream op whose data must be present before the condition is
|
||||
# read; omit for a check on the run root itself), condition is
|
||||
# {path, op, value} where path is ABSOLUTE from the run root;
|
||||
# a `*` segment fans out across array elements. needsMode combines
|
||||
# multiple needs: "any" (default;
|
||||
# fire on the first match) or "all" (a join; fire once every need
|
||||
# has resolved and matched). The queue is taken from the matching
|
||||
# services.<operation> entry, so dispatch and consume cannot drift.
|
||||
#
|
||||
# Every stage `operation` must have a deployed worker under
|
||||
# kerberoshub.services.<operation> (deploy the objecttracking / loitering
|
||||
# workers below).
|
||||
definitions: {}
|
||||
#tracking-workflow:
|
||||
# enabled: true
|
||||
# triggers:
|
||||
# - type: automatic
|
||||
# stages:
|
||||
# - operation: objecttracking
|
||||
# dispatch: always
|
||||
# - operation: loitering
|
||||
# dispatch: conditional
|
||||
# # Fire loitering once objecttracking has resolved — a readiness join
|
||||
# # (no condition ⇒ gate on the upstream's presence, not a value).
|
||||
# needs:
|
||||
# - operation: objecttracking
|
||||
# Workflow deployments. Every workflows-subsystem Deployment's image/tag/
|
||||
# replicas/resources/queue lives here in a single, uniform shape:
|
||||
# - `workflows` is the engine itself (the orchestrator). It is deployed
|
||||
# whenever kerberoshub.workflows.enabled is true and has no `enabled` of
|
||||
# its own — the master switch already gates the whole subsystem.
|
||||
# - every other entry is a stage worker the engine dispatches to. A worker
|
||||
# consumes its own queue and routes its result back to the engine queue.
|
||||
# Deploying a worker (services.<name>.enabled) is independent from routing
|
||||
# to it (a workflows.definitions stage of the same operation) — it runs only
|
||||
# when its own `enabled` is true AND the workflows engine is enabled.
|
||||
services:
|
||||
# hub-workflows — the workflows engine (orchestrator). Consumes the engine
|
||||
# queue, evaluates the boot-loaded config workflows (WORKFLOW_DEFINITIONS)
|
||||
# plus organisation-scoped database workflows, and dispatches to the stage
|
||||
# workers below. Deployed when workflows.enabled is true; it has no separate
|
||||
# `enabled` here.
|
||||
workflows:
|
||||
repository: ghcr.io/uug-ai/hub-workflows
|
||||
pullPolicy: IfNotPresent
|
||||
tag: "v1.0.0"
|
||||
replicas: 1 # Number of pods for the service.
|
||||
topologySpreadConstraints: [] # Optional pod topology spread constraints (empty = none).
|
||||
# Optional extra volumes / volumeMounts for this deployment (empty = none).
|
||||
#volumes:
|
||||
# - name: extra
|
||||
# emptyDir: {}
|
||||
#volumeMounts:
|
||||
# - name: extra
|
||||
# mountPath: /data
|
||||
logLevel: "info" # possible values: trace, debug, info, warn, error
|
||||
# Queue this service consumes ingest events and upstream results from
|
||||
# (WORKFLOWS_QUEUE). Must be fed the same messages the analysis service sees.
|
||||
queue: "hub-workflows-queue"
|
||||
resources:
|
||||
requests:
|
||||
memory: 10Mi
|
||||
cpu: 10m
|
||||
# ---------------------------------------------------------------------
|
||||
# EXAMPLE custom stage worker (commented out) — hub-loitering.
|
||||
#
|
||||
# Companion deployment for the workflows.definitions example above (the
|
||||
# loitering stage of tracking-workflow). Uncomment to deploy the demo
|
||||
# worker. It ships as its own repository/module.
|
||||
# See https://github.com/uug-ai/hub-loitering.
|
||||
#loitering:
|
||||
# # Deploy the hub-loitering worker.
|
||||
# enabled: true
|
||||
# repository: ghcr.io/uug-ai/hub-loitering
|
||||
# pullPolicy: IfNotPresent
|
||||
# tag: "v1.0.0"
|
||||
# replicas: 1 # Number of pods for the worker.
|
||||
# topologySpreadConstraints: [] # Optional pod topology spread constraints (empty = none).
|
||||
# #volumes:
|
||||
# # - name: extra
|
||||
# # emptyDir: {}
|
||||
# #volumeMounts:
|
||||
# # - name: extra
|
||||
# # mountPath: /data
|
||||
# logLevel: "info" # possible values: trace, debug, info, warn, error
|
||||
# # Queue this worker consumes dispatched messages from (LOITERING_QUEUE). This
|
||||
# # same value is taken into the matching workflows.definitions stage, so the
|
||||
# # engine dispatches and the worker consumes the same queue with no drift.
|
||||
# # Convention: "kcloud-<operation>-queue.fifo".
|
||||
# queue: "kcloud-loitering-queue.fifo"
|
||||
# resources:
|
||||
# requests:
|
||||
# memory: 10Mi
|
||||
# cpu: 10m
|
||||
# ---------------------------------------------------------------------
|
||||
# EXAMPLE stage worker (commented out) for the workflows.definitions example
|
||||
# above — hub-objecttracking. Uncomment the worker whose operation a
|
||||
# definition references, so the engine dispatches and the worker consumes the
|
||||
# same queue with no drift.
|
||||
#objecttracking:
|
||||
# # Deploy the object-tracking worker (operation "objecttracking").
|
||||
# enabled: true
|
||||
# repository: ghcr.io/uug-ai/hub-objecttracking
|
||||
# pullPolicy: IfNotPresent
|
||||
# tag: "v1.0.0"
|
||||
# replicas: 1 # Number of pods for the worker.
|
||||
# topologySpreadConstraints: [] # Optional pod topology spread constraints (empty = none).
|
||||
# logLevel: "info" # possible values: trace, debug, info, warn, error
|
||||
# # Queue this worker consumes dispatched messages from (OBJECTTRACKING_QUEUE).
|
||||
# queue: "kcloud-objecttracking-queue.fifo"
|
||||
# resources:
|
||||
# requests:
|
||||
# memory: 10Mi
|
||||
# cpu: 10m
|
||||
monitordevice:
|
||||
repository: uugai/hub-monitor-device
|
||||
repository: ghcr.io/uug-ai/hub-monitor-device
|
||||
pullPolicy: IfNotPresent
|
||||
tag: "v1.3.0"
|
||||
tag: "v1.4.2"
|
||||
replicas: 1 # Number of pods for the service.
|
||||
topologySpreadConstraints: [] # Optional pod topology spread constraints (empty = none).
|
||||
logLevel: "info" # possible values: trace, debug, info, warn, error
|
||||
resources:
|
||||
requests:
|
||||
@@ -540,7 +817,15 @@ kerberoshub:
|
||||
repository: uugai/hub-reactivatesubscriptions
|
||||
pullPolicy: IfNotPresent
|
||||
tag: "v1.0.2"
|
||||
replicas: 1 # Number of pods for the service.
|
||||
replicas: 0 # Number of pods for the service. Set to 0 to disable.
|
||||
topologySpreadConstraints: [] # Optional pod topology spread constraints (empty = none).
|
||||
# Optional extra volumes / volumeMounts for this deployment (empty = none).
|
||||
#volumes:
|
||||
# - name: extra
|
||||
# emptyDir: {}
|
||||
#volumeMounts:
|
||||
# - name: extra
|
||||
# mountPath: /data
|
||||
logLevel: "info" # possible values: trace, debug, info, warn, error
|
||||
resources:
|
||||
requests:
|
||||
@@ -548,6 +833,14 @@ kerberoshub:
|
||||
cpu: 10m
|
||||
forwarder:
|
||||
enabled: false
|
||||
topologySpreadConstraints: [] # Optional pod topology spread constraints (empty = none).
|
||||
# Optional extra volumes / volumeMounts for this deployment (empty = none).
|
||||
#volumes:
|
||||
# - name: extra
|
||||
# emptyDir: {}
|
||||
#volumeMounts:
|
||||
# - name: extra
|
||||
# mountPath: /data
|
||||
#repository: kerberos/vault-forwarder
|
||||
#pullPolicy: IfNotPresent
|
||||
#tag: "1.0.2732389692"
|
||||
@@ -560,7 +853,15 @@ kerberoshub:
|
||||
repository: uugai/hub-proxy
|
||||
pullPolicy: IfNotPresent
|
||||
tag: "v1.0.0"
|
||||
replicas: 1 # Number of pods for the service.
|
||||
replicas: 0 # Number of pods for the service. Set to 0 to disable.
|
||||
topologySpreadConstraints: [] # Optional pod topology spread constraints (empty = none).
|
||||
# Optional extra volumes / volumeMounts for this deployment (empty = none).
|
||||
#volumes:
|
||||
# - name: extra
|
||||
# emptyDir: {}
|
||||
#volumeMounts:
|
||||
# - name: extra
|
||||
# mountPath: /data
|
||||
logLevel: "info" # possible values: trace, debug, info, warn, error
|
||||
resources:
|
||||
requests:
|
||||
@@ -572,10 +873,18 @@ kerberoshub:
|
||||
# The pipeline is a critical component of Kerberos Hub, and should be monitored closely.
|
||||
kerberospipeline:
|
||||
event:
|
||||
repository: uugai/hub-pipeline-event
|
||||
repository: ghcr.io/uug-ai/hub-pipeline-event
|
||||
pullPolicy: IfNotPresent
|
||||
tag: "v1.2.0"
|
||||
tag: "v1.3.1"
|
||||
replicas: 1 # Number of pods for the service.
|
||||
topologySpreadConstraints: [] # Optional pod topology spread constraints (empty = none).
|
||||
# Optional extra volumes / volumeMounts for this deployment (empty = none).
|
||||
#volumes:
|
||||
# - name: extra
|
||||
# emptyDir: {}
|
||||
#volumeMounts:
|
||||
# - name: extra
|
||||
# mountPath: /data
|
||||
logLevel: "info" # possible values: trace, debug, info, warn, error
|
||||
resources:
|
||||
requests:
|
||||
@@ -584,8 +893,16 @@ kerberospipeline:
|
||||
monitor:
|
||||
repository: ghcr.io/uug-ai/hub-pipeline-monitor
|
||||
pullPolicy: IfNotPresent
|
||||
tag: "v1.3.9"
|
||||
tag: "v1.3.13"
|
||||
replicas: 1 # Number of pods for the service.
|
||||
topologySpreadConstraints: [] # Optional pod topology spread constraints (empty = none).
|
||||
# Optional extra volumes / volumeMounts for this deployment (empty = none).
|
||||
#volumes:
|
||||
# - name: extra
|
||||
# emptyDir: {}
|
||||
#volumeMounts:
|
||||
# - name: extra
|
||||
# mountPath: /data
|
||||
resources:
|
||||
requests:
|
||||
memory: 10Mi
|
||||
@@ -593,8 +910,16 @@ kerberospipeline:
|
||||
sequence:
|
||||
repository: ghcr.io/uug-ai/hub-pipeline-sequence
|
||||
pullPolicy: IfNotPresent
|
||||
tag: "v1.6.11"
|
||||
tag: "v1.6.26"
|
||||
replicas: 1 # Number of pods for the service.
|
||||
topologySpreadConstraints: [] # Optional pod topology spread constraints (empty = none).
|
||||
# Optional extra volumes / volumeMounts for this deployment (empty = none).
|
||||
#volumes:
|
||||
# - name: extra
|
||||
# emptyDir: {}
|
||||
#volumeMounts:
|
||||
# - name: extra
|
||||
# mountPath: /data
|
||||
resources:
|
||||
requests:
|
||||
memory: 10Mi
|
||||
@@ -602,8 +927,16 @@ kerberospipeline:
|
||||
throttler:
|
||||
repository: uugai/hub-pipeline-throttler
|
||||
pullPolicy: IfNotPresent
|
||||
tag: "v1.2.0"
|
||||
tag: "v1.2.1"
|
||||
replicas: 1 # Number of pods for the service.
|
||||
topologySpreadConstraints: [] # Optional pod topology spread constraints (empty = none).
|
||||
# Optional extra volumes / volumeMounts for this deployment (empty = none).
|
||||
#volumes:
|
||||
# - name: extra
|
||||
# emptyDir: {}
|
||||
#volumeMounts:
|
||||
# - name: extra
|
||||
# mountPath: /data
|
||||
logLevel: "info" # possible values: trace, debug, info, warn, error
|
||||
resources:
|
||||
requests:
|
||||
@@ -612,8 +945,9 @@ kerberospipeline:
|
||||
notify:
|
||||
repository: ghcr.io/uug-ai/hub-pipeline-notification
|
||||
pullPolicy: IfNotPresent
|
||||
tag: "v1.3.1"
|
||||
tag: "v1.3.18"
|
||||
replicas: 1 # Number of pods for the service.
|
||||
topologySpreadConstraints: [] # Optional pod topology spread constraints (empty = none).
|
||||
logLevel: "info" # possible values: trace, debug, info, warn, error
|
||||
resources:
|
||||
requests:
|
||||
@@ -630,8 +964,9 @@ kerberospipeline:
|
||||
notifyTest:
|
||||
repository: uugai/hub-pipeline-notification-test
|
||||
pullPolicy: IfNotPresent
|
||||
tag: "v1.2.1"
|
||||
tag: "v1.2.2"
|
||||
replicas: 1 # Number of pods for the service.
|
||||
topologySpreadConstraints: [] # Optional pod topology spread constraints (empty = none).
|
||||
resources:
|
||||
requests:
|
||||
memory: 10Mi
|
||||
@@ -647,8 +982,16 @@ kerberospipeline:
|
||||
analysis:
|
||||
repository: ghcr.io/uug-ai/hub-pipeline-analysis
|
||||
pullPolicy: IfNotPresent
|
||||
tag: "v1.7.8"
|
||||
tag: "v1.8.5"
|
||||
replicas: 1 # Number of pods for the service.
|
||||
topologySpreadConstraints: [] # Optional pod topology spread constraints (empty = none).
|
||||
# Optional extra volumes / volumeMounts for this deployment (empty = none).
|
||||
#volumes:
|
||||
# - name: extra
|
||||
# emptyDir: {}
|
||||
#volumeMounts:
|
||||
# - name: extra
|
||||
# mountPath: /data
|
||||
logLevel: "info" # possible values: trace, debug, info, warn, error
|
||||
resources:
|
||||
requests:
|
||||
@@ -657,8 +1000,16 @@ kerberospipeline:
|
||||
dominantColor:
|
||||
repository: ghcr.io/uug-ai/hub-pipeline-dominantcolors
|
||||
pullPolicy: IfNotPresent
|
||||
tag: "v2.0.2"
|
||||
tag: "v2.0.3"
|
||||
replicas: 3 # Number of pods for the service.
|
||||
topologySpreadConstraints: [] # Optional pod topology spread constraints (empty = none).
|
||||
# Optional extra volumes / volumeMounts for this deployment (empty = none).
|
||||
#volumes:
|
||||
# - name: extra
|
||||
# emptyDir: {}
|
||||
#volumeMounts:
|
||||
# - name: extra
|
||||
# mountPath: /data
|
||||
logLevel: "info" # possible values: trace, debug, info, warn,
|
||||
resources:
|
||||
requests:
|
||||
@@ -670,8 +1021,16 @@ kerberospipeline:
|
||||
thumbnail:
|
||||
repository: ghcr.io/uug-ai/hub-pipeline-thumbnail
|
||||
pullPolicy: IfNotPresent
|
||||
tag: "v1.3.1"
|
||||
tag: "v1.3.10"
|
||||
replicas: 2 # Number of pods for the service.
|
||||
topologySpreadConstraints: [] # Optional pod topology spread constraints (empty = none).
|
||||
# Optional extra volumes / volumeMounts for this deployment (empty = none).
|
||||
#volumes:
|
||||
# - name: extra
|
||||
# emptyDir: {}
|
||||
#volumeMounts:
|
||||
# - name: extra
|
||||
# mountPath: /data
|
||||
logLevel: "info" # possible values: trace, debug, info, warn, error
|
||||
quality: "1" # 1 (best) - 31 (worst)
|
||||
width: "600"
|
||||
@@ -688,8 +1047,16 @@ kerberospipeline:
|
||||
counting:
|
||||
repository: uugai/hub-pipeline-counting
|
||||
pullPolicy: IfNotPresent
|
||||
tag: "v1.6.3"
|
||||
tag: "v2.0.0"
|
||||
replicas: 1 # Number of pods for the service.
|
||||
topologySpreadConstraints: [] # Optional pod topology spread constraints (empty = none).
|
||||
# Optional extra volumes / volumeMounts for this deployment (empty = none).
|
||||
#volumes:
|
||||
# - name: extra
|
||||
# emptyDir: {}
|
||||
#volumeMounts:
|
||||
# - name: extra
|
||||
# mountPath: /data
|
||||
logLevel: "info" # possible values: trace, debug, info, warn,
|
||||
resources:
|
||||
requests:
|
||||
@@ -699,8 +1066,16 @@ kerberospipeline:
|
||||
enabled: false # Enable or disable the sprite generation 'true' or 'false
|
||||
repository: ghcr.io/uug-ai/hub-pipeline-sprite
|
||||
pullPolicy: IfNotPresent
|
||||
tag: "v1.1.5"
|
||||
tag: "v1.1.16"
|
||||
replicas: 5 # Number of pods for the service.
|
||||
topologySpreadConstraints: [] # Optional pod topology spread constraints (empty = none).
|
||||
# Optional extra volumes / volumeMounts for this deployment (empty = none).
|
||||
#volumes:
|
||||
# - name: extra
|
||||
# emptyDir: {}
|
||||
#volumeMounts:
|
||||
# - name: extra
|
||||
# mountPath: /data
|
||||
logLevel: "info" # possible values: trace, debug, info, warn,
|
||||
interval: "1" # Number of secondes between each thumbnail in the sprite
|
||||
width: "240" # Should not be changed for the moment (hard coded in UI)
|
||||
@@ -715,9 +1090,18 @@ kerberospipeline:
|
||||
export:
|
||||
repository: ghcr.io/uug-ai/hub-pipeline-export
|
||||
pullPolicy: IfNotPresent
|
||||
tag: "v1.1.3"
|
||||
tag: "v1.2.10"
|
||||
replicas: 2 # Number of pods for the service.
|
||||
topologySpreadConstraints: [] # Optional pod topology spread constraints (empty = none).
|
||||
logLevel: "info" # possible values: trace, debug, info, warn, error
|
||||
# playerAssetsPath: "/custom/player-assets/" # Path to custom player.html template (overrides the embedded default)
|
||||
# volumeMounts:
|
||||
# - name: custom-player-assets
|
||||
# mountPath: /custom/player-assets
|
||||
# volumes:
|
||||
# - name: custom-player-assets
|
||||
# configMap:
|
||||
# name: custom-player-html
|
||||
resources:
|
||||
requests:
|
||||
memory: 10Mi
|
||||
@@ -749,10 +1133,14 @@ email:
|
||||
forgotTitle: "Password reset Kerberos Hub. You forgot your password"
|
||||
share: "share"
|
||||
shareTitle: "[Action] You received a recording from Kerberos Hub"
|
||||
caseShare: "share_case"
|
||||
caseShareTitle: "[Action] A case has been shared with you on Kerberos Hub"
|
||||
caseShareOtp: "share_case_otp"
|
||||
caseShareOtpTitle: "Your Kerberos Hub verification code"
|
||||
assignTask: "assign_task"
|
||||
assignTaskTitle: "[Action] You've been assigned to a task"
|
||||
detection: "detection"
|
||||
disabled: "disabled"
|
||||
disabled: "disable"
|
||||
highupload: "highupload"
|
||||
device: "device"
|
||||
alertTitle: "[Alert] Kerberos Hub detected something an event"
|
||||
|
||||
97
scripts/check-workflows-queue-consistency.sh
Executable file
97
scripts/check-workflows-queue-consistency.sh
Executable file
@@ -0,0 +1,97 @@
|
||||
#!/usr/bin/env bash
|
||||
#
|
||||
# Render the hub chart and assert that every deployment which carries the
|
||||
# workflows hand-off queue (the WORKFLOWS_QUEUE env var) resolves to the SAME,
|
||||
# non-empty value.
|
||||
#
|
||||
# Why: the analysis pipeline (pipe-analysis) publishes opened workflow runs to
|
||||
# WORKFLOWS_QUEUE, the workflows engine (hub-workflows) consumes it, and every
|
||||
# stage worker (hub-stage) routes its result back to it. All three templates
|
||||
# read the single key `kerberoshub.services.workflows.queue`. If a future edit
|
||||
# hardcodes a value, reads the wrong key, or drops the env on one of them, the
|
||||
# producer and consumer silently drift onto different queue names and messages
|
||||
# pile up with no consumer. This check fails the build before that can ship.
|
||||
#
|
||||
# Usage: scripts/check-workflows-queue-consistency.sh [chart-dir]
|
||||
# (chart-dir defaults to charts/hub, relative to the repo root)
|
||||
|
||||
set -euo pipefail
|
||||
|
||||
CHART_DIR="${1:-charts/hub}"
|
||||
PROBE="drift-probe-queue-name"
|
||||
|
||||
# Flags that force all three deployment kinds (analysis, engine and one stage
|
||||
# worker) to render, so the check actually has something to compare. The chart
|
||||
# ships NO enabled stage worker by default (custom stages are values-only and
|
||||
# opt-in), so we synthesise a throwaway stage purely to exercise the generic
|
||||
# hub-stage path. The name is a neutral fixture ("queuecheck") on purpose: any
|
||||
# arbitrary stage key must render the same way, so the check must not depend on
|
||||
# a specific bundled worker.
|
||||
STAGE="queuecheck"
|
||||
RENDER_FLAGS=(
|
||||
--set mode=all
|
||||
--set kerberoshub.workflows.enabled=true
|
||||
--set "kerberoshub.workflows.stages.${STAGE}.enabled=true"
|
||||
--set "kerberoshub.services.${STAGE}.enabled=true"
|
||||
--set "kerberoshub.services.${STAGE}.repository=example.invalid/queuecheck"
|
||||
--set "kerberoshub.services.${STAGE}.tag=test"
|
||||
--set "kerberoshub.services.${STAGE}.queue=queuecheck-fixture-queue"
|
||||
)
|
||||
|
||||
# Read `helm template` output on stdin and print one WORKFLOWS_QUEUE value per
|
||||
# line. Matches the `- name: WORKFLOWS_QUEUE` env entry and captures the value
|
||||
# from the following `value:` line, skipping blank/comment lines in between.
|
||||
extract_workflows_queue() {
|
||||
awk '
|
||||
/^[[:space:]]*-[[:space:]]*name:[[:space:]]*WORKFLOWS_QUEUE[[:space:]]*$/ { want=1; next }
|
||||
want==1 {
|
||||
if ($0 ~ /^[[:space:]]*#/ || $0 ~ /^[[:space:]]*$/) next
|
||||
v=$0
|
||||
sub(/^[[:space:]]*value:[[:space:]]*/, "", v)
|
||||
sub(/^"/, "", v); sub(/"[[:space:]]*$/, "", v)
|
||||
sub(/[[:space:]]+$/, "", v)
|
||||
print v
|
||||
want=0
|
||||
}
|
||||
'
|
||||
}
|
||||
|
||||
assert_all_equal() {
|
||||
local expected="$1"; shift
|
||||
local label="$1"; shift
|
||||
local -a vals=("$@")
|
||||
|
||||
if [ "${#vals[@]}" -lt 2 ]; then
|
||||
echo "FAIL (${label}): expected at least 2 WORKFLOWS_QUEUE values (analysis + engine), found ${#vals[@]}" >&2
|
||||
return 1
|
||||
fi
|
||||
|
||||
local v
|
||||
for v in "${vals[@]}"; do
|
||||
if [ -z "${v}" ]; then
|
||||
echo "FAIL (${label}): a deployment rendered an empty WORKFLOWS_QUEUE value" >&2
|
||||
return 1
|
||||
fi
|
||||
if [ "${v}" != "${expected}" ]; then
|
||||
echo "FAIL (${label}): WORKFLOWS_QUEUE drift detected — expected '${expected}' but a deployment rendered '${v}'" >&2
|
||||
printf ' rendered values: %s\n' "${vals[*]}" >&2
|
||||
return 1
|
||||
fi
|
||||
done
|
||||
|
||||
echo "OK (${label}): ${#vals[@]} deployments all use WORKFLOWS_QUEUE='${expected}'"
|
||||
}
|
||||
|
||||
echo "== Rendering ${CHART_DIR} with the chart's default workflows queue =="
|
||||
default_out="$(helm template hub "${CHART_DIR}" "${RENDER_FLAGS[@]}")"
|
||||
mapfile -t default_vals < <(printf '%s\n' "${default_out}" | extract_workflows_queue)
|
||||
default_queue="${default_vals[0]:-}"
|
||||
assert_all_equal "${default_queue}" "default values" "${default_vals[@]}" || exit 1
|
||||
|
||||
echo "== Rendering ${CHART_DIR} with an overridden workflows queue (-> ${PROBE}) =="
|
||||
probe_out="$(helm template hub "${CHART_DIR}" "${RENDER_FLAGS[@]}" \
|
||||
--set kerberoshub.services.workflows.queue="${PROBE}")"
|
||||
mapfile -t probe_vals < <(printf '%s\n' "${probe_out}" | extract_workflows_queue)
|
||||
assert_all_equal "${PROBE}" "override probe" "${probe_vals[@]}" || exit 1
|
||||
|
||||
echo "All WORKFLOWS_QUEUE consistency checks passed."
|
||||
Reference in New Issue
Block a user