Compare commits

...

89 Commits

Author SHA1 Message Date
Cédric Verstraeten
f834d9b8f5 Merge pull request #143 from kerberos-io/public-release-1786904956
A new public release - 1786904956
2026-08-21 17:36:29 +02:00
Kilian
eefe96c679 Merge pull request #147 from kerberos-io/detection-source-flags
detection source flags
2026-08-21 17:32:59 +02:00
Kilian
93888e2855 Merge pull request #144 from kerberos-io/feature/add-org-feature-flags
add-org-feature-flags
2026-08-21 17:29:48 +02:00
Kilian Boute
759ac8dbf8 detection source flags 2026-08-21 17:28:25 +02:00
Cédric Verstraeten
4aaa70f121 Merge pull request #146 from kerberos-io/fix/cors-origin
fix/cors-origin
2026-08-20 22:10:48 +02:00
Cédric Verstraeten
ad7ef4ac12 Add frontend URL to Hub API CORS
Initialize CORS origins with the primary frontend URL while retaining support for the legacy frontend URL. Bump the Hub chart to 0.130.0.
2026-08-20 22:09:19 +02:00
Cédric Verstraeten
5ad56f9730 Merge pull request #145 from kerberos-io/feature/add-refresh-tokens-config
feature/add-refresh-tokens-config
2026-08-20 21:44:32 +02:00
Cédric Verstraeten
91eb64a2f3 Update Chart.yaml 2026-08-20 21:35:04 +02:00
Cédric Verstraeten
55ae6cdd3e Add dynamic CORS origins and secure refresh cookie
Update the hub API Helm template to set `REFRESH_COOKIE_SECURE` automatically when the API schema is HTTPS, and generate `CORS_ALLOWED_ORIGINS` from configured frontend URLs (legacy URL, domain list, tenant wildcard domain, and demo URL). This keeps cookie behavior and CORS config aligned with deployment settings.
2026-08-20 21:33:32 +02:00
Kilian Boute
f492c14336 add flags 2026-08-20 18:01:19 +02:00
uug4ai
d4a13a4cff A new public release - 1786904956 2026-08-16 18:29:18 +00:00
Kilian
98cc8d4f2d Merge pull request #142 from kerberos-io/docs/workflow-source-alignment
docs(workflows): clarify config and database sources
2026-08-13 12:48:11 +02:00
Kilian Boute
a5125eee69 docs(workflows): clarify definition sources 2026-08-13 10:23:21 +00:00
Cédric Verstraeten
b2ff3e2e20 Merge pull request #141 from kerberos-io/fix/allow-replicas-proxy-default-to-zero
fix/allow-replicas-proxy-default-to-zero
2026-08-11 22:01:40 +02:00
Cédric Verstraeten
277ddde3b4 Disable proxy and reactivation services by default
Default replicas for the hub proxy and reactivation subscriptions services are now set to 0, allowing them to be disabled unless explicitly enabled. This updates the chart metadata and docs to reflect the new default behavior.
2026-08-11 21:51:37 +02:00
Cédric Verstraeten
7878be79d6 Merge pull request #140 from kerberos-io/feature/add-mongodb-tls-support
feature/add-mongodb-tls-support
2026-08-11 14:14:35 +02:00
Cédric Verstraeten
123bde292e Merge pull request #136 from kerberos-io/public-release-1786356403
A new public release - 1786356403
2026-08-11 14:09:02 +02:00
Cédric Verstraeten
e76311872e feat(hub): update chart version to 0.127.0 and add MongoDB TLS configuration options 2026-08-11 12:06:27 +00:00
Cédric Verstraeten
0f2176822a feat(hub): add TLS support for MongoDB configuration 2026-08-11 12:05:43 +00:00
Kilian
8ca4c402f8 Merge pull request #139 from kerberos-io/feat/organisation-feature-flags
chore(hub): bump chart version to 0.126.2
2026-08-10 12:36:29 +02:00
Kilian
8d9b943100 chore(hub): bump chart version to 0.126.2 2026-08-10 10:34:08 +00:00
Kilian
3e10489251 Merge pull request #137 from kerberos-io/feat/organisation-feature-flags
Add organisation frontend feature flags
2026-08-10 12:26:01 +02:00
Kilian
a7fd8d394f feat(hub): add organisation frontend flags
Expose disabled-by-default Helm values for organisation switching and creation, and map them to the Hub frontend runtime environment.
2026-08-10 10:17:59 +00:00
uug4ai
c29647ec62 A new public release - 1786356403 2026-08-10 10:06:45 +00:00
Cédric Verstraeten
685b92e9cc Merge pull request #135 from kerberos-io/feature/add-mock-support
feature/add-mock-support
2026-08-05 22:42:36 +02:00
Cédric Verstraeten
01d1e6866a Bump chart version to 0.126.1 and add MoQ support in live view configuration 2026-08-05 20:31:28 +00:00
Kilian
8cf73bcf1d Merge pull request #134 from kerberos-io/KilianBoute-patch-2
Bump chart version to 0.126.0
2026-08-05 18:07:10 +02:00
Kilian
57f6ab6f3b Bump chart version to 0.126.0 2026-08-05 18:06:58 +02:00
Kilian
2ed7829391 Merge pull request #133 from kerberos-io/feat/workflow-stage-queue-catalog
workflow-stage-queue-catalog?
2026-08-05 17:50:44 +02:00
Kilian Boute
0c9726f21b changer 2026-08-05 17:50:18 +02:00
Kilian
9ae2e1fc86 Merge pull request #131 from kerberos-io/feat/workflow-stage-queue-catalog
Expose workflow stage queues to Hub API
2026-08-05 13:03:48 +02:00
Kilian Boute
f3a9886053 feat: expose workflow stage queues to API 2026-08-03 13:59:09 +00:00
Cédric Verstraeten
933fedc080 Merge pull request #130 from kerberos-io/feature/splash-screen-feature-flag
feature/splash-screen-feature-flag
2026-07-31 15:35:02 +02:00
Cédric Verstraeten
2c7f6a89a3 Bump chart version to 0.124.0 2026-07-31 13:28:55 +00:00
Cédric Verstraeten
5af0ffab6c Add splash screen feature flag to frontend configuration 2026-07-31 13:18:06 +00:00
Kilian
0a3cf69c80 Merge pull request #129 from kerberos-io/chore/remove-private-redaction-service
chore(hub): remove private redaction service from public chart
2026-07-31 15:09:19 +02:00
Kilian Boute
b8499c97e2 chore(hub): remove private redaction service from public chart
hub-pipeline-redaction is a private, client-specific worker. Remove its Deployment/Service template and the kerberospipeline.redaction values block (plus the generated README rows) from the public chart. Deployment is now documented in the private hub-pipeline-redaction repo.
2026-07-29 14:12:13 +00:00
Cédric Verstraeten
641dc7510c Merge pull request #128 from kerberos-io/fix/hide-frontend-categories
fix/hide-frontend-categories
2026-07-16 11:29:21 +02:00
Cédric Verstraeten
20f4fa24ba Bump chart version to 0.123.1 2026-07-16 09:24:21 +00:00
Cédric Verstraeten
b793014f89 Rename media filter category feature environment variable to plural form 2026-07-16 09:23:46 +00:00
Kilian
348bab8f2b Merge pull request #127 from kerberos-io/KilianBoute-patch-2
Bump chart version to 0.123.0
2026-07-10 19:22:23 +02:00
Kilian
8a71bd2a05 Bump chart version to 0.123.0 2026-07-10 19:22:05 +02:00
Kilian
611ddec1f1 Merge pull request #126 from kerberos-io/KilianBoute-patch-2
Bump chart version to 0.122.0
2026-07-10 19:20:23 +02:00
Kilian
34a285666e Bump chart version to 0.122.0 2026-07-10 19:20:09 +02:00
Kilian
59cf74ba66 Merge pull request #125 from kerberos-io/feat/hub-i18n-run-workflow-redact
feat(i18n): add Run workflow and Redact faces case UI strings
2026-07-10 19:10:52 +02:00
Kilian Boute
020f2d969d feat(i18n): add Run workflow and Redact faces case UI strings
Adds the en.json translations for the case Run-workflow dialog
(title/subtitle/labels/empty/submit and the runWorkflow menu item)
and the Redact faces attachment action (k14).
2026-07-10 17:10:14 +00:00
Kilian
eeb29e8cac Merge pull request #124 from kerberos-io/feat/hub-api-workflow-definitions-env
feat(hub-api): inject WORKFLOW_DEFINITIONS env so config workflows surface in the API
2026-07-10 19:09:13 +02:00
Kilian Boute
1ec2be4cc7 feat(hub-api): inject WORKFLOW_DEFINITIONS env so config workflows surface in the API
hub-api reads WORKFLOW_DEFINITIONS (the same enabled definition set the
workflows engine consumes, assembled via kerberoshub.workflows.workflowDefinitions)
read-only to surface config workflows alongside DB/user workflows. Previously
only the engine received this env, so hub-api returned an empty config-workflow
list and manual/on-demand config workflows never appeared in GET /workflows.
2026-07-10 17:06:41 +00:00
Kilian
b9166ea1ed Merge pull request #123 from kerberos-io/fix/hub-stage-service-separator
fix(hub-stage): render valid YAML when multiple stage workers are enabled
2026-07-08 15:05:56 +02:00
Kilian Boute
be2290075c fix(hub-stage): add newline before doc separator so multiple stage workers render valid YAML
The generic stage-worker loop in templates/kerberos-pipeline/hub-stage.yaml
closed each iteration with `{{- end }}`, whose left-trim stripped the newline
after the Service's final line (`app: hub-<name>`). With a single enabled stage
worker this was latent, but with two or more the next worker's `---` separator
was glued onto the previous Service's last line (e.g. `app: hub-loitering---`),
merging two resources into one malformed document.

In production this surfaced as ArgoCD "one or more synchronization tasks are not
valid" once objecttracking was enabled alongside anpr and loitering (3 stage
workers -> 2 glued boundaries: anpr->loitering and loitering->objecttracking).

Fix: emit a trailing newline before the next document separator by using
`{{ end -}}` for the per-service if-close. Rendering the hub chart with the
production values now yields 58 valid documents (previously 56, of which 2 were
Service+Deployment glued together) and 0 malformed separators. Bump chart to
0.121.1 so the fix can be published to charts.kerberos.io.
2026-07-08 12:59:28 +00:00
Kilian
cb47ad3f12 Merge pull request #122 from kerberos-io/feat/workflow-definitions-rendering
feat(hub): render WORKFLOW_DEFINITIONS for the workflows engine
2026-07-07 15:09:54 +02:00
Kilian Boute
42bd87d16d feat(hub): render WORKFLOW_DEFINITIONS for the workflows engine
Replace the flat PIPELINE_STAGE_REGISTRY with per-workflow
WORKFLOW_DEFINITIONS, matching hub-workflows' definitions engine:

- _workflows-helpers.tpl: stageRegistry -> workflowDefinitions. Emits a
  JSON array of named workflow objects (name, enabled, source=config,
  triggers defaulting to a bare automatic trigger, and the executable
  stages), one per enabled kerberoshub.workflows.definitions entry. Each
  stage's queue is still taken from the matching services.<operation> so
  dispatch and consume cannot drift.
- hub-workflows.yaml: set WORKFLOW_DEFINITIONS instead of
  PIPELINE_STAGE_REGISTRY.
- hub-stage.yaml: render a worker for every enabled services.<name> other
  than the engine itself (decoupled from routing), and pass through any
  services.<name>.env as container env for per-worker tuning.
- values.yaml: workflows.stages -> workflows.definitions (map keyed by
  workflow name) with an object-tracking + loitering worked example and
  updated docs.

Chart 0.120.0 -> 0.121.0. helm lint + template validated.
2026-07-07 13:05:20 +00:00
Kilian
0ed38add2e Merge pull request #121 from kerberos-io/feat/hls-live-transport-toggle
feat(hub): add hlsEnabled toggle; replace anpr example with loitering
2026-06-25 18:43:14 +02:00
Kilian
c8c070d51e chore(hub): bump chart version to 0.120.0 2026-06-25 16:36:52 +00:00
Kilian
0e21755bb8 feat(hub): add hlsEnabled toggle; replace anpr example with loitering
- Add kerberoshub.frontend.features.liveview.hlsEnabled (default true) and
  wire it as FEATURE_HLS_ENABLED on hub-frontend and hub-frontend-demo. When
  'false' the front-end removes the HLS live-transport option.
- Replace the bundled anpr example stage/worker with a commented-out
  hub-loitering example; the chart now ships no enabled custom stage by
  default (stages are values-only, opt-in).
- Update the generic hub-stage comment to the loitering example.
- Make the queue-consistency check self-contained: it synthesises a neutral
  throwaway stage ('queuecheck') via --set instead of relying on a bundled
  example worker.

NOTE: Chart.yaml version intentionally not bumped — repo version/tag state is
already inconsistent (Chart.yaml 0.117.0 vs tags up to hub-0.119.0); pick the
next version at release time.
2026-06-25 16:33:16 +00:00
Kilian
8781ede494 Merge pull request #120 from kerberos-io/fix/disable-email-template-value
fix(hub): align disabled email template value with module name
2026-06-24 13:42:24 +02:00
Kilian Boute
82e3da78dd fix(hub): align disabled email template value with module name
The notification module's GetTemplate only recognizes the template name "disable" (disable.go / disable template file), but email.templates.disabled was set to "disabled". A consumer passing DISABLED_TEMPLATE to GetTemplate would get an empty body. Set the value to "disable" so it resolves correctly.
2026-06-24 11:24:34 +00:00
Kilian
30bbd97b6d Merge pull request #119 from kerberos-io/feat/case-share-email-template
feat(hub): add case-share email template + env wiring
2026-06-24 11:02:21 +02:00
Kilian
b78a2246ee Apply suggestions from code review
Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
2026-06-24 10:09:06 +02:00
Kilian Boute
33b41cee0e otp share template 2026-06-23 17:13:18 +02:00
Kilian Boute
3a464eeb8e feat(hub): add case-share email template + env wiring
Adds CASE_SHARE_TEMPLATE/CASE_SHARE_TITLE env on hub-api (driven by
email.templates.caseShare/caseShareTitle), the matching values defaults, and
the share_case custom-layout template (html/txt) so the case-share invitation
renders with its dedicated white-label template.
2026-06-23 13:46:54 +00:00
Kilian
d599befeaf Merge pull request #118 from kerberos-io/fix/otel-gating-and-workflows-queue
Gate OTel env vars behind opentelemetry.enabled and align workflows queue name
2026-06-19 13:00:21 +02:00
Kilian Boute
9ea9016bfa Gate OTel env vars behind opentelemetry.enabled and align workflows queue name
- Wrap OpenTelemetry tracing env vars in '{{- if .Values.opentelemetry.enabled }}' across hub-api and all pipeline templates so disabled tracing injects no OTEL_* vars.

- Fix the OTLP collector endpoint default to the HTTP port (http://otel-collector:4318); the services use the OTLP HTTP exporter, and a scheme-less/4317 value defaults to TLS and fails against a plaintext collector.

- Rename the workflows queue from 'kcloud-workflows-queue' to 'hub-workflows-queue' and pass WORKFLOWS_QUEUE to the analysis pipeline so analysis and the workflows engine always agree on the queue name.
2026-06-18 15:50:59 +00:00
Kilian
895c190e20 Merge pull request #117 from kerberos-io/workflows->-remove-kind
Remove 'kind' attribute from workflows and update related comments fo…
2026-06-17 12:22:51 +02:00
Kilian Boute
f4051f7e6a Remove 'kind' attribute from workflows and update related comments for clarity 2026-06-17 10:07:25 +00:00
Cédric Verstraeten
807369ef01 Merge pull request #116 from kerberos-io/feature/live-view-mode
feature/live-view-mode
2026-06-17 11:56:33 +02:00
Cédric Verstraeten
19cf677a56 Bump hub chart version to 0.117.0
Increment charts/hub Chart.yaml version from 0.116.0 to 0.117.0 to reflect an updated chart release. This follows semantic versioning for chart/template changes.
2026-06-16 17:46:58 +02:00
Cédric Verstraeten
7b39949e5b Add live stream mode env and default value
Expose FEATURE_LIVE_STREAM_MODE environment variable in both hub-frontend and hub-frontend-demo templates, sourcing from .Values.kerberoshub.frontend.features.liveview.liveStreamMode. Add a new liveStreamMode default in charts/hub/values.yaml ("webrtc") to control the transport for LIVE (HD) mode (options: "webrtc" (default) or "hls"). This enables configuring live stream transport without modifying templates.
2026-06-16 17:09:54 +02:00
Kilian
3752c0396e Merge pull request #115 from kerberos-io/default-i18n-en.json-file
Add default i18n en.json file
2026-06-16 09:57:38 +02:00
Kilian
0d55fa5d2f Add default i18n en.json file 2026-06-16 09:49:33 +02:00
Cédric Verstraeten
2949db0a03 Merge pull request #114 from kerberos-io/public-release-1781595581
A new public release - 1781595581
2026-06-16 09:48:31 +02:00
uug4ai
662a2c6a67 A new public release - 1781595581 2026-06-16 07:39:43 +00:00
Cédric Verstraeten
7cf273911e Merge pull request #113 from kerberos-io/KilianBoute-patch-2
Bump chart version to 0.116.0
2026-06-16 09:39:40 +02:00
Kilian
20f1de461d Bump chart version to 0.116.0 2026-06-15 21:26:40 +02:00
Kilian
a237f7b4d6 Merge pull request #112 from kerberos-io/KilianBoute-patch-2
Bump chart version from 0.113.0 to 0.115.0
2026-06-15 18:29:07 +02:00
Kilian
fae8b028ad Bump chart version from 0.113.0 to 0.115.0 2026-06-15 18:28:54 +02:00
Kilian
31ec7cb6af Merge pull request #111 from kerberos-io/translation-overriding
Translation override support
2026-06-15 18:26:36 +02:00
Kilian Boute
424053f2ce add translation file override support 2026-06-15 13:39:23 +00:00
Kilian Boute
7c17a99240 add translation file override support 2026-06-15 13:39:10 +00:00
Kilian
dafba78c94 Merge pull request #110 from kerberos-io/Workflows->-standalone-setup
Refactor workflows configuration to use services structure in hub-sta…
2026-06-12 16:58:48 +02:00
Kilian Boute
dc48269807 Refactor workflows configuration to use services structure in hub-stage and hub-workflows templates; update values.yaml for consistency 2026-06-12 14:50:38 +00:00
Kilian
eff71c4e24 Merge pull request #109 from kerberos-io/Workflows->-standalone-setup
Workflows > standalone setup
2026-06-12 15:17:20 +02:00
Kilian Boute
642676fcf7 Remove deprecated pipe-anpr and pipe-workflows templates; add generic hub-stage and hub-workflows templates for improved workflow management 2026-06-12 11:51:28 +00:00
Kilian Boute
25bb6d5fdc Enhance workflow stage configuration with needsMode and kind attributes in helpers and values.yaml 2026-06-11 15:34:59 +00:00
Kilian Boute
20b92ffddd Update comments for workflows integration in pipe-analysis and values.yaml 2026-06-09 15:00:02 +00:00
Kilian Boute
bb4cc53d90 Add workflows support to pipe-analysis and create pipe-workflows template 2026-06-08 16:20:38 +00:00
Kilian Boute
7b920c3f0e Add hub-workflows configuration to values.yaml 2026-06-08 12:26:15 +00:00
Cédric Verstraeten
52757a66ae Merge pull request #108 from kerberos-io/feature/optional-disable-frontend-demo
feature/optional-disable-frontend-demo
2026-06-02 20:40:36 +02:00
Cédric Verstraeten
e664e78d01 Add topology/volume hooks and bump chart
Bump chart version to 0.113.0 and add optional pod topologySpreadConstraints, volumes and volumeMounts hooks across many templates (admin, oauth2-proxy, kerberoshub services, kerberospipeline components, and vault components). Add conditionals to control rendering of hub-api and hub-frontend Services and make the demo front-end conditional on demoEnabled. Update values.yaml with new defaults (empty arrays) and commented examples for topologySpreadConstraints, volumes and volumeMounts for each relevant component.
2026-06-02 20:36:50 +02:00
41 changed files with 2364 additions and 172 deletions

View File

@@ -0,0 +1,31 @@
name: Workflows queue consistency
# Fails the build if the analysis producer, the workflows engine and the stage
# workers would render onto different WORKFLOWS_QUEUE names — the silent
# producer/consumer queue-name drift that leaves runs piling up with no
# consumer. Pure `helm template` render check, no cluster required.
on:
workflow_dispatch:
pull_request:
paths:
- 'charts/hub/**'
- 'scripts/check-workflows-queue-consistency.sh'
- '.github/workflows/workflows-queue-consistency.yaml'
permissions:
contents: read
jobs:
check:
runs-on: ubuntu-24.04
steps:
- name: Checkout repository
uses: actions/checkout@v4
- name: Set up Helm
uses: azure/setup-helm@v4
with:
version: v3.16.2
- name: Check WORKFLOWS_QUEUE consistency
run: ./scripts/check-workflows-queue-consistency.sh charts/hub

View File

@@ -16,7 +16,7 @@ type: application
# This is the chart version. This version number should be incremented each time you make changes
# to the chart and its templates, including the app version.
# Versions are expected to follow Semantic Versioning (https://semver.org/)
version: 0.112.0
version: 0.130.0
# This is the version number of the application being deployed. This version number should be
# incremented each time you make changes to the application. Versions are not expected to

View File

@@ -53,6 +53,11 @@ Below all configuration options and parameters are listed.
| `mongodb.password` | MongoDB user password, by default `'yourmongodbpassword'` | `"yourpassword"` |
| `mongodb.retryWrites` | Enable or disable MongoDB retryable writes. | `"true"` |
| `mongodb.flavor` | Backend engine flavor: `"mongodb"` (native MongoDB / Atlas) or `"documentdb"` (AWS DocumentDB). The `documentdb` flavor disables features DocumentDB does not support (geospatial queries/indexes, complex `$lookup` pipelines). When set to `documentdb`, also set `mongodb.retryWrites: "false"`. | `"mongodb"` |
| `mongodb.tls.enabled` | Enable TLS for MongoDB connections. When `mongodb.uri` is set, the chart appends missing `tls=true` and `tlsCAFile` query parameters. | `false` |
| `mongodb.tls.existingSecret` | Existing Kubernetes Secret containing the MongoDB CA bundle. The Secret is mounted into every workload that consumes `mongodb-config`. | `""` |
| `mongodb.tls.caFileName` | Key and filename of the CA bundle in `mongodb.tls.existingSecret` (for AWS DocumentDB, typically `global-bundle.pem`). | `""` |
| `mongodb.tls.mountPath` | Read-only directory where the MongoDB CA Secret is mounted. | `"/etc/mongodb/tls"` |
| `mongodb.tls.insecureSkipVerify` | Skip MongoDB certificate and hostname verification. This is insecure and intended only for local testing. | `false` |
| `mqtt.host` | MQTT (Vernemq) hostname. | `"mqtt.yourdomain.com"` |
| `mqtt.port` | MQTT (Vernemq) port for WSS (secure sockets), by default `'8443'`. | `"8443"` |
| `mqtt.protocol` | MQTT (Vernemq) protocol, by default `'wss'`. | `"wss"` |
@@ -197,14 +202,28 @@ Below all configuration options and parameters are listed.
| `kerberoshub.frontend.caseFilterAssigneesDefault` | Default assignee filter behavior for cases in the frontend. | `"false"` |
| `kerberoshub.frontend.features.case.enabled` | Enable or disable the case feature in the frontend. | `"true"` |
| `kerberoshub.frontend.features.darkModeEnabled` | Enable or disable dark mode in the frontend. | `"true"` |
| `kerberoshub.frontend.features.splashScreen.enabled` | Enable or disable the pre-bootstrap splash screen and reveal delay. | `"true"` |
| `kerberoshub.frontend.features.landingPage` | Frontend landing page configuration. | `"/dashboard"` |
| `kerberoshub.frontend.features.i18n.enabled` | Enable or disable the runtime language switcher in the front-end. When `"false"`, `defaultLanguage` is forced and users cannot change it. | `"true"` |
| `kerberoshub.frontend.features.i18n.defaultLanguage` | Default language code used by the front-end (e.g. `en`, `nl`, `pl`, `tr`, `fr`, `sv`, `de`). | `"en"` |
| `kerberoshub.frontend.features.workflows.enabled` | Enable or disable the workflows feature in the frontend. | `"false"` |
| `kerberoshub.frontend.features.organisations.enabled` | Enable or disable all organisation feature flags. When empty, the child settings apply independently. | `""` |
| `kerberoshub.frontend.features.organisations.switcherEnabled` | Enable or disable the organisation dropdown and switching. The current organisation remains visible when disabled. | `"false"` |
| `kerberoshub.frontend.features.organisations.creationEnabled` | Enable or disable organisation creation. Requires organisation switching to be enabled. | `"false"` |
| `kerberoshub.frontend.features.organisations.settingsEnabled` | Enable or disable the organisation identity link to organisation settings. | `"false"` |
| `kerberoshub.frontend.features.projects.enabled` | Enable or disable all project feature flags. When empty, the child settings apply independently. | `""` |
| `kerberoshub.frontend.features.projects.switcherEnabled` | Enable or disable the read-only project dropdown. | `"false"` |
| `kerberoshub.frontend.features.projects.creationEnabled` | Reserved for the project creation UI. | `"false"` |
| `kerberoshub.frontend.features.projects.settingsEnabled` | Reserved for the project settings UI. | `"false"` |
| `kerberoshub.frontend.features.map.tileUrlLight` | Tile URL used by the map in light mode. | `"https://{s}.basemaps.cartocdn.com/rastertiles/voyager/{z}/{x}/{y}{r}.png"` |
| `kerberoshub.frontend.features.map.tileUrlDark` | Tile URL used by the map in dark mode. | `"https://{s}.basemaps.cartocdn.com/dark_all/{z}/{x}/{y}{r}.png"` |
| `kerberoshub.frontend.features.map.attribution` | Attribution text displayed on the map tiles. | `"&copy; <a href='https://www.openstreetmap.org/copyright' target='_blank'>OpenStreetMap</a>"` |
| `kerberoshub.frontend.features.liveview.defaultStreamMode` | Liveview behavior setting: `defaultStreamMode`. | `"SD"` |
| `kerberoshub.frontend.features.liveview.liveStreamMode` | Transport backing LIVE mode: `webrtc`, `hls`, or `moq`. | `"webrtc"` |
| `kerberoshub.frontend.features.liveview.hlsEnabled` | Offer HLS as a selectable LIVE transport. | `"true"` |
| `kerberoshub.frontend.features.liveview.moqEnabled` | Offer MoQ as a selectable LIVE transport. | `"false"` |
| `kerberoshub.frontend.features.liveview.moqRelayUrl` | WebTransport URL of the MoQ relay. | `"https://relay.uug.ai/anon"` |
| `kerberoshub.frontend.features.liveview.moqBroadcastPrefix` | Prefix used to build MoQ broadcast names. | `"devices"` |
| `kerberoshub.frontend.features.liveview.paginationMode` | Liveview behavior setting: `paginationMode` (`scroll`, `numbered` or `maxStreams`). | `"scroll"` |
| `kerberoshub.frontend.features.liveview.pageSize` | Liveview behavior setting: `pageSize` (max streams shown per page in `numbered` mode). | `"6"` |
| `kerberoshub.frontend.features.liveview.maxStreams` | Liveview behavior setting: `maxStreams`. | `"-1"` |
@@ -240,6 +259,7 @@ Below all configuration options and parameters are listed.
| `kerberoshub.frontend.features.floorplan.colorTrackBoxDrawing` | Color customization for `floorplan` in the frontend. | `"hsla(204, 100%, 50%, 1)"` |
| `kerberoshub.frontend.features.floorplan.colorTrackBoxControlsDelete` | Color customization for `floorplan` in the frontend. | `"hsla(219, 100%, 94%, 1)"` |
| `kerberoshub.frontend.features.faceRedaction.enabled` | Enable or disable `kerberoshub.frontend.features.faceRedaction`. | `"false"` |
| `kerberoshub.frontend.features.faceRedaction.classifierTracksEnabled` | Make classifier-generated tracks available in the redaction modal. | `"true"` |
| `kerberoshub.support.enabled` | Enable or disable in-app support features. | `false` |
| `kerberoshub.oauth2Proxy.enabled` | Enable or disable `kerberoshub.oauth2Proxy`. | `false` |
| `kerberoshub.oauth2Proxy.github.clientId` | Client ID used by `kerberoshub.oauth2Proxy.github`. | `"github-client-id"` |
@@ -283,7 +303,7 @@ Below all configuration options and parameters are listed.
| `kerberoshub.reactivate.repository` | Container image repository for `kerberoshub.reactivate`. | `"uugai/hub-reactivatesubscriptions"` |
| `kerberoshub.reactivate.pullPolicy` | Image pull policy for `kerberoshub.reactivate`. | `"IfNotPresent"` |
| `kerberoshub.reactivate.tag` | Container image tag/version for `kerberoshub.reactivate`. | `"v1.0.2"` |
| `kerberoshub.reactivate.replicas` | Number of replicas for `kerberoshub.reactivate`. | `1` |
| `kerberoshub.reactivate.replicas` | Number of replicas for `kerberoshub.reactivate`. Set to `0` to disable. | `0` |
| `kerberoshub.reactivate.logLevel` | Log verbosity level for `kerberoshub.reactivate`. | `"info"` |
| `kerberoshub.reactivate.resources.requests.memory` | Memory request for `kerberoshub.reactivate`. | `"10Mi"` |
| `kerberoshub.reactivate.resources.requests.cpu` | CPU request for `kerberoshub.reactivate`. | `"10m"` |
@@ -291,7 +311,7 @@ Below all configuration options and parameters are listed.
| `kerberoshub.proxy.repository` | Container image repository for `kerberoshub.proxy`. | `"uugai/hub-proxy"` |
| `kerberoshub.proxy.pullPolicy` | Image pull policy for `kerberoshub.proxy`. | `"IfNotPresent"` |
| `kerberoshub.proxy.tag` | Container image tag/version for `kerberoshub.proxy`. | `"v1.0.0"` |
| `kerberoshub.proxy.replicas` | Number of replicas for `kerberoshub.proxy`. | `1` |
| `kerberoshub.proxy.replicas` | Number of replicas for `kerberoshub.proxy`. Set to `0` to disable. | `0` |
| `kerberoshub.proxy.logLevel` | Log verbosity level for `kerberoshub.proxy`. | `"info"` |
| `kerberoshub.proxy.resources.requests.memory` | Memory request for `kerberoshub.proxy`. | `"10Mi"` |
| `kerberoshub.proxy.resources.requests.cpu` | CPU request for `kerberoshub.proxy`. | `"10m"` |
@@ -390,15 +410,6 @@ Below all configuration options and parameters are listed.
| `kerberospipeline.export.logLevel` | Log verbosity level for `kerberospipeline.export`. | `"info"` |
| `kerberospipeline.export.resources.requests.memory` | Memory request for `kerberospipeline.export`. | `"10Mi"` |
| `kerberospipeline.export.resources.requests.cpu` | CPU request for `kerberospipeline.export`. | `"10m"` |
| `kerberospipeline.redaction.repository` | Container image repository for `kerberospipeline.redaction`. | `"ghcr.io/uug-ai/hub-pipeline-redaction"` |
| `kerberospipeline.redaction.pullPolicy` | Image pull policy for `kerberospipeline.redaction`. | `"IfNotPresent"` |
| `kerberospipeline.redaction.tag` | Container image tag/version for `kerberospipeline.redaction`. | `"v1.0.0"` |
| `kerberospipeline.redaction.replicas` | Number of replicas for `kerberospipeline.redaction`. | `2` |
| `kerberospipeline.redaction.logLevel` | Log verbosity level for `kerberospipeline.redaction`. | `"info"` |
| `kerberospipeline.redaction.resources.requests.memory` | Memory request for `kerberospipeline.redaction`. | `"512Mi"` |
| `kerberospipeline.redaction.resources.requests.cpu` | CPU request for `kerberospipeline.redaction`. | `"500m"` |
| `kerberospipeline.redaction.resources.limits.memory` | Memory limit for `kerberospipeline.redaction`. | `"2Gi"` |
| `kerberospipeline.redaction.resources.limits.cpu` | CPU limit for `kerberospipeline.redaction`. | `"1000m"` |
| `email.provider` | The email service provider for sending out messages over email , use `'mailgun'` or `'smtp'`. | `"mailgun"` |
| `email.from` | The email address that is sending messages in name of, by default `'support@yourdomain.com'`. | `"support@yourdomain.com"` |
| `email.displayName` | The display name that is sending messages in name of, by default `'yourdomain.com'` | `"yourdomain.com"` |
@@ -487,6 +498,7 @@ Following indexes should be executed on the MongoDB database (Kerberos) to impro
#### Analysis collection
db.getCollection("analysis").createIndex({start:1})
db.getCollection("analysis").createIndex({organisationId:1, projectId:1, key:1}, {name:"analysis_org_project_key"})
db.getCollection("analysis").createIndex({userid:1, key:1})
db.getCollection("analysis").createIndex({userid:1, start:1})

View File

@@ -0,0 +1,11 @@
apiVersion: v1
kind: PersistentVolumeClaim
metadata:
name: custom-i18n-claim
spec:
accessModes:
- ReadWriteMany
storageClassName: azurefile-premium
resources:
requests:
storage: 25Mi

View File

@@ -0,0 +1,9 @@
{
"nav": {
"cases": "Investigations",
"dashboard": "Home"
},
"login": {
"signInTo": "Sign in to {{domain}} \u2014 Acme Security"
}
}

View File

@@ -351,11 +351,23 @@
"generateExport": "Generate export",
"regenerateExport": "Generate export",
"exportInProgress": "Generating export…",
"exportStuck": "Export stuck — Retry",
"exportStuckTitle": "Export hasn't reported progress for over 2 minutes. Click to force a retry.",
"exportRetryConfirmTitle": "Force retry export?",
"exportRetryConfirmText": "This export hasn't reported progress for more than two minutes. Forcing a retry will discard the current run and start a new one.",
"exportRetryConfirmButton": "Force retry",
"exportRetryCancelButton": "Cancel",
"exportStatusGenerating": "Generating export…",
"exportStatusUnresponsive": "Export not responding",
"exportStatusFailed": "Export failed",
"exportStatusStale": "Export out of date",
"exportStatusReady": "Export ready",
"shareCase": "Share case",
"deleteCase": "Delete case",
"download": "Download",
"delete": "Delete",
"openDetail": "Open detail"
"openDetail": "Open detail",
"runWorkflow": "Run workflow"
},
"exportSelection": {
"title": "Export selection",
@@ -367,6 +379,16 @@
"emptyAttachments": "This case has no attachments yet.",
"attachmentsHeading": "Attachments"
},
"runWorkflow": {
"title": "Run workflow",
"subtitle": "Launch a workflow over selected media on this case.",
"workflowLabel": "Workflow",
"loading": "Loading workflows…",
"noWorkflows": "No workflows are available to run on cases.",
"attachmentsSelected": "attachments selected",
"attachmentBadge": "Attachment",
"submit": "Run workflow"
},
"filter": {
"assignees": "Assignees",
"labels": "Labels",
@@ -1603,7 +1625,8 @@
"k10": "or use the upload button below",
"k11": "Delete attachment",
"k12": "Are you sure you want to delete this attachment? This action cannot be undone.",
"k13": "Yes, delete"
"k13": "Yes, delete",
"k14": "Redact faces"
}
},
"media": {
@@ -1676,7 +1699,12 @@
"k11": "Forward 1 second",
"k12": "Frames per second for redaction",
"k13": "Frames per second",
"k14": "fps"
"k14": "fps",
"k15": "Detection run",
"k16": "Select a detection run",
"k17": "No detections",
"k18": "Automatic tracks unavailable",
"k19": "Automatic face tracks are disabled. You can still draw redaction boxes manually on the player and submit."
}
},
"motionmap": {

View File

@@ -0,0 +1,418 @@
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="X-UA-Compatible" content="IE=edge" />
<meta http-equiv="Content-Type" content="text/html; charset=utf-8" />
<meta
name="viewport"
content="width=device-width, initial-scale=1, minimum-scale=1, maximum-scale=1"
/>
<meta name="description" content="Kerberos.io Mailing">
<style type="text/css">
@font-face {
font-family: 'Inter';
font-style: normal;
font-weight: 400;
font-display: swap;
src: url("https://kerberos.io/dist/fonts/Inter-Regular.woff?v=/dist/fonts/Inter-Regular.woff2?v=3.183.18") format("woff2"),
url("https://kerberos.io/dist/fonts/Inter-Regular.woff?v=/dist/fonts/Inter-Regular.woff2?v=3.183.18") format("woff");
}
@font-face {
font-family: 'Inter';
font-style: normal;
font-weight: 500;
font-display: swap;
src: url("https://kerberos.io/dist/fonts/Inter-Medium.woff2?v=3.18") format("woff2"),
url("https://kerberos.io/dist/fonts/Inter-Medium.woff?v=3.18") format("woff");
}
@font-face {
font-family: 'Inter';
font-style: normal;
font-weight: 600;
font-display: swap;
src: url("https://kerberos.io/dist/fonts/Inter-SemiBold.woff2?v=3.18") format("woff2"),
url("https://kerberos.io/dist/fonts/Inter-SemiBold.woff?v=3.18") format("woff");
}
@font-face {
font-family: 'Inter var';
font-weight: 100 900;
font-display: swap;
font-style: normal;
font-named-instance: 'Regular';
src: url("https://kerberos.io/dist/fonts/Inter-roman.var.woff2?v=3.18") format("woff2");
}
body{
background: #E5E5E5;
margin-top:0;
margin-bottom: 0;
margin-right: 0;
margin-left: 0;
padding-top: 0;
padding-left: 0;
padding-right: 0;
padding-bottom: 0;
font-family: 'Inter';
}
a, a:hover, a:active {
color: #262424;
text-decoration: none;
}
.corner-td{
width: 60px;
}
table {border-collapse:separate;max-width: 850px; margin: 0 auto; width: 100%;}
.ExternalClass p, .ExternalClass span, .ExternalClass font, .ExternalClass td {line-height: 100%;}
.ExternalClass {width: 100%;}
@media screen and (max-width:500px){
.tab-td{
padding-left: 10px!important;
}
.tab-td a h4{
font-size: 14px!important;
}
.corner-td{
width: 20px!important;
}
.company-name-td h3{
font-size: 16px!important;
}
table.header-table{
padding-top: 8px!important;
padding-right: 0px!important;
padding-bottom: 24px!important;
padding-left: 0px!important;
}
.colored-card-td h4{
font-size: 14px!important;
}
.colored-card-td h2{
font-size: 20px!important;
}
.colored-card-td a p{
font-size: 12px!important;
width: 143px!important;
}
.colored-card-td{
padding-top: 24px!important;
padding-right: 24px!important;
padding-bottom: 24px!important;
padding-left: 24px!important;
}
.colorless-card-td{
padding-top: 24px!important;
padding-right: 24px!important;
padding-bottom: 24px!important;
padding-left: 24px!important;
}
.colorless-card-td h3{
font-size: 18px!important;
}
.colorless-card-td p{
font-size: 14px!important;
}
.colorless-card-table{
margin-left: 0px!important;
margin-right: 0px!important;
margin-top: 24px!important;
margin-bottom: 24px!important;
}
.footer-td{
display: table-row!important;
}
}
@media screen and (max-width:600px) {
.footer-td{
display: table-row!important;
}
}
@media screen and (max-width:650px) {
.footer-table{
margin-left: 0px!important;
margin-right: 0px!important;
margin-top: 0px!important;
margin-bottom: 36px!important;
}
}
</style>
</head>
<body height="100%" width="100%">
<table border="0" cellpadding="0" cellspacing="0" width="100%" bgcolor="E5E5E5" style="border-collaps:collaps; mso-table-lspace:0pt; mso-table-rspace:0pt;">
<tr>
<td bgcolor="E5E5E5">
<table border="0" cellpadding="0" cellspacing="0" width="100%" height="36" class="header-table" style="padding-top: 36px ;padding-right: 0;padding-bottom: 36px;padding-left: 0;border-collaps:collaps; mso-table-lspace:0pt; mso-table-rspace:0pt;">
<tbody>
<tr>
<td class="corner-td" align="left"></td>
<td width="48" height="36" align="left"><img alt="Kerberos.io" width="36" height="36" src="https://kerberos.io/images/email/kerberos.png"/></td>
<td height="36" align="left" class="company-name-td">
<h3 width="36" height="36" style=" font-family: Inter;
font-size: 20px;
font-style: normal;
font-weight: 600;
line-height: 24px;
mso-line-height-rule:exactly;
letter-spacing: 0em;
text-align: left;
color: #262424;">Kerberos.io</h3>
</td>
<td height="36" width="36" style="padding-left: 36px;" class="tab-td" align="right">
<a style="text-decoration: none;color: none;" href={{tab1_href}}>
<h4 style="font-family: Inter;
font-size: 16px;
font-style: normal;
font-weight: 500;
line-height: 36px;
mso-line-height-rule:exactly;
letter-spacing: 0em;
text-align: right;
color: #6D6666;">{{tab1_title}}</h4>
</a>
</td>
<td height="36" width="36" style="padding-left: 36px;" class="tab-td" align="right" >
<a style="text-decoration: none;color: none;" href={{tab2_href}}>
<h4 style="font-family: Inter;
font-size: 16px;
font-style: normal;
font-weight: 500;
line-height: 36px;
mso-line-height-rule:exactly;
letter-spacing: 0em;
text-align: right;
color: #6D6666;">{{tab2_title}}</h4>
</a>
</td>
<td class="corner-td" align="right"></td>
</tr>
</tbody>
</table>
</td>
</tr>
</table>
<table border="0" cellpadding="0" cellspacing="0" width="100%" bgcolor="E5E5E5" style="border-collaps:collaps; mso-table-lspace:0pt; mso-table-rspace:0pt;">
<tr>
<td bgcolor="E5E5E5">
<table border="0" cellpadding="0" cellspacing="0" width="100%" style="border-collaps:collaps; mso-table-lspace:0pt; mso-table-rspace:0pt;" >
<tbody>
<tr>
<td class="corner-td" align="left"></td>
<td class="colored-card-td" bgcolor="#57356B" style="padding-left: 48px;padding-right: 48px;padding-top: 48px;padding-bottom: 48px;border-radius: 4px;background-color:#57356B;">
<h2 style=" font-family: Inter;
font-size: 24px;
font-style: normal;
font-weight: 600;
line-height: 36px;
mso-line-height-rule:exactly;
letter-spacing: 0em;
text-align: left;
color:#FFFFFF;
padding-top: 12px;
margin-bottom: 0;
padding-bottom: 0;
padding-left: 0;
padding-right: 0;">A case has been shared with you</h2>
<h4 style="font-family: Inter;
font-size: 16px;
font-style: normal;
font-weight: 400;
line-height: 24px;
mso-line-height-rule:exactly;
letter-spacing: 0em;
text-align: left;
color:#b09fb9;">{{user}} shared a case with you</h4>
</td>
<td class="corner-td" align="right"></td>
</tr>
</tbody>
</table>
</td>
</tr>
</table>
<table border="0" cellpadding="0" cellspacing="0" width="100%" bgcolor="E5E5E5" style="border-collaps:collaps; mso-table-lspace:0pt; mso-table-rspace:0pt;">
<tr>
<td bgcolor="E5E5E5">
<table border="0" cellpadding="0" cellspacing="0" width="100%" class="colorless-card-table" style="margin-top: 36px;margin-bottom: 36px;margin-left: 0;margin-right: 0;border-collaps:collaps; mso-table-lspace:0pt; mso-table-rspace:0pt;" >
<tbody>
<tr>
<td class="corner-td" align="left"></td>
<td class="colorless-card-td" bgcolor="#FFFFFF" style="background-color:#FFFFFF;padding-top: 36px;padding-right: 43px;padding-bottom: 25px;padding-left: 43px;border-radius: 4px;">
<h3 style=" font-family: Inter;
font-size: 20px;
font-style: normal;
font-weight: 600;
line-height: 36px;
mso-line-height-rule:exactly;
letter-spacing: 0em;
text-align: left;
color: #262424;
width: 280px">Open the shared case</h3>
<p style=" font-family: Inter;
font-size: 14px;
font-style: normal;
font-weight: 400;
line-height: 24px;
mso-line-height-rule:exactly;
letter-spacing: 0em;
text-align: left;
color: #6D6666;
margin-top: 12px;">{{user}} has shared a case with you. Click the button below to open it. You'll be asked to request a one-time verification code from the share page itself.<br/><br/>This link will expire in {{expiry}}.</p>
<a style="text-decoration: none;color: none;" href="{{url}}">
<p style="font-family: Inter;
font-size: 14px;
font-style: normal;
line-height: 24px;
mso-line-height-rule:exactly;
letter-spacing: 0em;
text-align: left;
color:#FFFFFF;
background-color: #84559F;
padding-top: 6px;
padding-bottom: 6px;
padding-right: 16px;
padding-left: 16px;
width: 130px;
border-radius: 4px;
text-align: center;
cursor: pointer;">Open case -></p>
</a>
</td>
<td class="corner-td" align="right"></td>
</tr>
</tbody>
</table>
</td>
</tr>
</table>
<table border="0" cellpadding="0" cellspacing="0" width="100%" bgcolor="E5E5E5" style="border-collaps:collaps; mso-table-lspace:0pt; mso-table-rspace:0pt;">
<tr>
<td bgcolor="E5E5E5">
<table border="0" cellpadding="0" cellspacing="0" width="100%" class="footer-table" style="margin-top: 0;border-collaps:collaps; mso-table-lspace:0pt; mso-table-rspace:0pt;" >
<tbody>
<tr>
<td class="corner-td" align="left"></td>
<!--[if mso | IE]>
<table role="presentation" border="0" cellpadding="0" cellspacing="0"><tr><td style="vertical-align:top;display:table-row !important">
<![endif]-->
<td height="146" width="190" class="footer-td" style="margin-bottom: 12px;" valign="top" align="left">
<table style="border-collaps:collaps; mso-table-lspace:0pt; mso-table-rspace:0pt;">
<tbody>
<tr>
<td>
<h4 style=" font-family: Inter;
font-size: 16px;
font-style: normal;
font-weight: 600;
line-height: 36px;
mso-line-height-rule:exactly;
letter-spacing: 0em;
text-align: left;
color:#6D6666;">Get in touch</h4>
<a style="text-decoration: none;color: none;" href="mailto:support@kerberos.io">
<p style=" font-family: Inter;
font-size: 14px;
font-style: normal;
font-weight: 400;
line-height: 16px;
mso-line-height-rule:exactly;
letter-spacing: 0em;
text-align: left;
color: #A69D9D;">support@kerberos.io</p>
</a>
<p style=" font-family: Inter;
font-size: 14px;
font-style: normal;
font-weight: 400;
line-height: 16px;
mso-line-height-rule:exactly;
letter-spacing: 0em;
text-align: left;
color: #A69D9D;">9000 Ghent, BE</p>
<a style="text-decoration: none;color: none;" href="https://kerberos.io/">
<p style=" font-family: Inter;
font-size: 14px;
font-style: normal;
font-weight: 400;
line-height: 24px;
mso-line-height-rule:exactly;
letter-spacing: 0em;
text-align: left;
color: #A69D9D;">https://kerberos.io</p>
</a>
</td>
</tr>
</tbody>
</table>
</td>
<!--[if mso | IE]>
<table role="presentation" border="0" cellpadding="0" cellspacing="0"><tr><td style="vertical-align:top;display:table-row !important">
<![endif]-->
<td class="footer-td" style="border-radius: 4px;padding-left: 0;padding-right: 0;padding-top: 0;padding-bottom: 0; margin-bottom: 12px;" valign="top" align="left">
<table style="border-collaps:collaps; mso-table-lspace:0pt; mso-table-rspace:0pt;">
<tbody>
<tr>
<td>
<h4 style=" font-family: Inter;
font-size: 16px;
font-style: normal;
font-weight: 600;
line-height: 36px;
mso-line-height-rule:exactly;
letter-spacing: 0em;
text-align: left;
color:#6D6666;">About Kerberos</h4>
<p style=" font-family: Inter;
font-size: 14px;
font-style: normal;
font-weight: 400;
line-height: 24px;
mso-line-height-rule:exactly;
letter-spacing: 0em;
text-align: left;
color: #A69D9D;">Welcome to the revolutionary video analytics and video management platform. Open, modular, and extensible for everyone, anywhere.</p>
<p style="margin-top: 12px;">
<a href="https://twitter.com/kerberosio" style="text-decoration: none;color: none;">
<img width="24" height="24" alt="Twitter" src="https://kerberos.io/images/email/twitter.png"/>
</a>
<a href="https://reddit.com/r/kerberos_io" style="text-decoration: none;color: none;">
<img g width="24" height="24" alt="Reddit" src="https://kerberos.io/images/email/reddit.png"/>
</a>
<a href="https://www.youtube.com/channel/UCnd9q7iRNNw4W95eQwQuECA" style="text-decoration: none;color: none;">
<img g width="24" height="24" alt="Youtube" src="https://kerberos.io/images/email/youtube.png"/>
</a>
<a href="https://github.com/kerberos-io" style="text-decoration: none;color: none;">
<img g width="24" height="24" alt="Github" src="https://kerberos.io/images/email/github.png"/>
</a>
</p>
</td>
</tr>
</tbody>
</table>
</td>
<td class="corner-td" align="right"></td>
</tr>
</tbody>
</table>
<table style="border-collaps:collaps; mso-table-lspace:0pt; mso-table-rspace:0pt;">
<tbody>
<tr style="height: 50px">
<td></td>
</tr>
</tbody>
</table>
</td>
</tr>
</table>
</body>
</html>

View File

@@ -0,0 +1,21 @@
Kerberos.io
------------
A case has been shared with you
{{user}} shared a case with you
Open the shared case
{{user}} has shared a case with you. Open the link below to access it — you'll be asked to request a one-time verification code from the share page.
{{url}}
This link will expire in {{expiry}}.
Get in touch
------------
support@kerberos.io
9000 Ghent, BE
https://kerberos.io
About Kerberos
------------
Welcome to the revolutionary video analytics and video management platform. Open, modular, and extensible for everyone, anywhere.

View File

@@ -0,0 +1,425 @@
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="X-UA-Compatible" content="IE=edge" />
<meta http-equiv="Content-Type" content="text/html; charset=utf-8" />
<meta
name="viewport"
content="width=device-width, initial-scale=1, minimum-scale=1, maximum-scale=1"
/>
<meta name="description" content="Kerberos.io Mailing">
<style type="text/css">
@font-face {
font-family: 'Inter';
font-style: normal;
font-weight: 400;
font-display: swap;
src: url("https://kerberos.io/dist/fonts/Inter-Regular.woff?v=/dist/fonts/Inter-Regular.woff2?v=3.183.18") format("woff2"),
url("https://kerberos.io/dist/fonts/Inter-Regular.woff?v=/dist/fonts/Inter-Regular.woff2?v=3.183.18") format("woff");
}
@font-face {
font-family: 'Inter';
font-style: normal;
font-weight: 500;
font-display: swap;
src: url("https://kerberos.io/dist/fonts/Inter-Medium.woff2?v=3.18") format("woff2"),
url("https://kerberos.io/dist/fonts/Inter-Medium.woff?v=3.18") format("woff");
}
@font-face {
font-family: 'Inter';
font-style: normal;
font-weight: 600;
font-display: swap;
src: url("https://kerberos.io/dist/fonts/Inter-SemiBold.woff2?v=3.18") format("woff2"),
url("https://kerberos.io/dist/fonts/Inter-SemiBold.woff?v=3.18") format("woff");
}
@font-face {
font-family: 'Inter var';
font-weight: 100 900;
font-display: swap;
font-style: normal;
font-named-instance: 'Regular';
src: url("https://kerberos.io/dist/fonts/Inter-roman.var.woff2?v=3.18") format("woff2");
}
body{
background: #E5E5E5;
margin-top:0;
margin-bottom: 0;
margin-right: 0;
margin-left: 0;
padding-top: 0;
padding-left: 0;
padding-right: 0;
padding-bottom: 0;
font-family: 'Inter';
}
a, a:hover, a:active {
color: #262424;
text-decoration: none;
}
.corner-td{
width: 60px;
}
table {border-collapse:separate;max-width: 850px; margin: 0 auto; width: 100%;}
.ExternalClass p, .ExternalClass span, .ExternalClass font, .ExternalClass td {line-height: 100%;}
.ExternalClass {width: 100%;}
@media screen and (max-width:500px){
.tab-td{
padding-left: 10px!important;
}
.tab-td a h4{
font-size: 14px!important;
}
.corner-td{
width: 20px!important;
}
.company-name-td h3{
font-size: 16px!important;
}
table.header-table{
padding-top: 8px!important;
padding-right: 0px!important;
padding-bottom: 24px!important;
padding-left: 0px!important;
}
.colored-card-td h4{
font-size: 14px!important;
}
.colored-card-td h2{
font-size: 20px!important;
}
.colored-card-td a p{
font-size: 12px!important;
width: 143px!important;
}
.colored-card-td{
padding-top: 24px!important;
padding-right: 24px!important;
padding-bottom: 24px!important;
padding-left: 24px!important;
}
.colorless-card-td{
padding-top: 24px!important;
padding-right: 24px!important;
padding-bottom: 24px!important;
padding-left: 24px!important;
}
.colorless-card-td h3{
font-size: 18px!important;
}
.colorless-card-td p{
font-size: 14px!important;
}
.colorless-card-table{
margin-left: 0px!important;
margin-right: 0px!important;
margin-top: 24px!important;
margin-bottom: 24px!important;
}
.footer-td{
display: table-row!important;
}
}
@media screen and (max-width:600px) {
.footer-td{
display: table-row!important;
}
}
@media screen and (max-width:650px) {
.footer-table{
margin-left: 0px!important;
margin-right: 0px!important;
margin-top: 0px!important;
margin-bottom: 36px!important;
}
}
</style>
</head>
<body height="100%" width="100%">
<table border="0" cellpadding="0" cellspacing="0" width="100%" bgcolor="E5E5E5" style="border-collaps:collaps; mso-table-lspace:0pt; mso-table-rspace:0pt;">
<tr>
<td bgcolor="E5E5E5">
<table border="0" cellpadding="0" cellspacing="0" width="100%" height="36" class="header-table" style="padding-top: 36px ;padding-right: 0;padding-bottom: 36px;padding-left: 0;border-collaps:collaps; mso-table-lspace:0pt; mso-table-rspace:0pt;">
<tbody>
<tr>
<td class="corner-td" align="left"></td>
<td width="48" height="36" align="left"><img alt="Kerberos.io" width="36" height="36" src="https://kerberos.io/images/email/kerberos.png"/></td>
<td height="36" align="left" class="company-name-td">
<h3 width="36" height="36" style=" font-family: Inter;
font-size: 20px;
font-style: normal;
font-weight: 600;
line-height: 24px;
mso-line-height-rule:exactly;
letter-spacing: 0em;
text-align: left;
color: #262424;">Kerberos.io</h3>
</td>
<td height="36" width="36" style="padding-left: 36px;" class="tab-td" align="right">
<a style="text-decoration: none;color: none;" href={{tab1_href}}>
<h4 style="font-family: Inter;
font-size: 16px;
font-style: normal;
font-weight: 500;
line-height: 36px;
mso-line-height-rule:exactly;
letter-spacing: 0em;
text-align: right;
color: #6D6666;">{{tab1_title}}</h4>
</a>
</td>
<td height="36" width="36" style="padding-left: 36px;" class="tab-td" align="right" >
<a style="text-decoration: none;color: none;" href={{tab2_href}}>
<h4 style="font-family: Inter;
font-size: 16px;
font-style: normal;
font-weight: 500;
line-height: 36px;
mso-line-height-rule:exactly;
letter-spacing: 0em;
text-align: right;
color: #6D6666;">{{tab2_title}}</h4>
</a>
</td>
<td class="corner-td" align="right"></td>
</tr>
</tbody>
</table>
</td>
</tr>
</table>
<table border="0" cellpadding="0" cellspacing="0" width="100%" bgcolor="E5E5E5" style="border-collaps:collaps; mso-table-lspace:0pt; mso-table-rspace:0pt;">
<tr>
<td bgcolor="E5E5E5">
<table border="0" cellpadding="0" cellspacing="0" width="100%" style="border-collaps:collaps; mso-table-lspace:0pt; mso-table-rspace:0pt;" >
<tbody>
<tr>
<td class="corner-td" align="left"></td>
<td class="colored-card-td" bgcolor="#57356B" style="padding-left: 48px;padding-right: 48px;padding-top: 48px;padding-bottom: 48px;border-radius: 4px;background-color:#57356B;">
<h2 style=" font-family: Inter;
font-size: 24px;
font-style: normal;
font-weight: 600;
line-height: 36px;
mso-line-height-rule:exactly;
letter-spacing: 0em;
text-align: left;
color:#FFFFFF;
padding-top: 12px;
margin-bottom: 0;
padding-bottom: 0;
padding-left: 0;
padding-right: 0;">Verify your access</h2>
<h4 style="font-family: Inter;
font-size: 16px;
font-style: normal;
font-weight: 400;
line-height: 24px;
mso-line-height-rule:exactly;
letter-spacing: 0em;
text-align: left;
color:#b09fb9;">Use the code below to open the shared case</h4>
</td>
<td class="corner-td" align="right"></td>
</tr>
</tbody>
</table>
</td>
</tr>
</table>
<table border="0" cellpadding="0" cellspacing="0" width="100%" bgcolor="E5E5E5" style="border-collaps:collaps; mso-table-lspace:0pt; mso-table-rspace:0pt;">
<tr>
<td bgcolor="E5E5E5">
<table border="0" cellpadding="0" cellspacing="0" width="100%" class="colorless-card-table" style="margin-top: 36px;margin-bottom: 36px;margin-left: 0;margin-right: 0;border-collaps:collaps; mso-table-lspace:0pt; mso-table-rspace:0pt;" >
<tbody>
<tr>
<td class="corner-td" align="left"></td>
<td class="colorless-card-td" bgcolor="#FFFFFF" style="background-color:#FFFFFF;padding-top: 36px;padding-right: 43px;padding-bottom: 25px;padding-left: 43px;border-radius: 4px;">
<h3 style=" font-family: Inter;
font-size: 20px;
font-style: normal;
font-weight: 600;
line-height: 36px;
mso-line-height-rule:exactly;
letter-spacing: 0em;
text-align: left;
color: #262424;
width: 280px">Your verification code</h3>
<p style=" font-family: Inter;
font-size: 14px;
font-style: normal;
font-weight: 400;
line-height: 24px;
mso-line-height-rule:exactly;
letter-spacing: 0em;
text-align: left;
color: #6D6666;
margin-top: 12px;">Enter the code below on the share page to access the case.</p>
<p style="font-family: 'Courier New', Courier, monospace;
font-size: 32px;
font-style: normal;
font-weight: 600;
line-height: 40px;
mso-line-height-rule:exactly;
letter-spacing: 8px;
text-align: center;
color:#262424;
background-color: #F2F0F4;
padding-top: 16px;
padding-bottom: 16px;
padding-right: 16px;
padding-left: 16px;
margin-top: 16px;
margin-bottom: 16px;
border-radius: 4px;">{{code}}</p>
<p style=" font-family: Inter;
font-size: 14px;
font-style: normal;
font-weight: 400;
line-height: 24px;
mso-line-height-rule:exactly;
letter-spacing: 0em;
text-align: left;
color: #6D6666;">This code expires in {{expiry}}. If you didn't request this, you can safely ignore this email.</p>
</td>
<td class="corner-td" align="right"></td>
</tr>
</tbody>
</table>
</td>
</tr>
</table>
<table border="0" cellpadding="0" cellspacing="0" width="100%" bgcolor="E5E5E5" style="border-collaps:collaps; mso-table-lspace:0pt; mso-table-rspace:0pt;">
<tr>
<td bgcolor="E5E5E5">
<table border="0" cellpadding="0" cellspacing="0" width="100%" class="footer-table" style="margin-top: 0;border-collaps:collaps; mso-table-lspace:0pt; mso-table-rspace:0pt;" >
<tbody>
<tr>
<td class="corner-td" align="left"></td>
<!--[if mso | IE]>
<table role="presentation" border="0" cellpadding="0" cellspacing="0"><tr><td style="vertical-align:top;display:table-row !important">
<![endif]-->
<td height="146" width="190" class="footer-td" style="margin-bottom: 12px;" valign="top" align="left">
<table style="border-collaps:collaps; mso-table-lspace:0pt; mso-table-rspace:0pt;">
<tbody>
<tr>
<td>
<h4 style=" font-family: Inter;
font-size: 16px;
font-style: normal;
font-weight: 600;
line-height: 36px;
mso-line-height-rule:exactly;
letter-spacing: 0em;
text-align: left;
color:#6D6666;">Get in touch</h4>
<a style="text-decoration: none;color: none;" href="mailto:support@kerberos.io">
<p style=" font-family: Inter;
font-size: 14px;
font-style: normal;
font-weight: 400;
line-height: 16px;
mso-line-height-rule:exactly;
letter-spacing: 0em;
text-align: left;
color: #A69D9D;">support@kerberos.io</p>
</a>
<p style=" font-family: Inter;
font-size: 14px;
font-style: normal;
font-weight: 400;
line-height: 16px;
mso-line-height-rule:exactly;
letter-spacing: 0em;
text-align: left;
color: #A69D9D;">9000 Ghent, BE</p>
<a style="text-decoration: none;color: none;" href="https://kerberos.io/">
<p style=" font-family: Inter;
font-size: 14px;
font-style: normal;
font-weight: 400;
line-height: 24px;
mso-line-height-rule:exactly;
letter-spacing: 0em;
text-align: left;
color: #A69D9D;">https://kerberos.io</p>
</a>
</td>
</tr>
</tbody>
</table>
</td>
<!--[if mso | IE]>
<table role="presentation" border="0" cellpadding="0" cellspacing="0"><tr><td style="vertical-align:top;display:table-row !important">
<![endif]-->
<td class="footer-td" style="border-radius: 4px;padding-left: 0;padding-right: 0;padding-top: 0;padding-bottom: 0; margin-bottom: 12px;" valign="top" align="left">
<table style="border-collaps:collaps; mso-table-lspace:0pt; mso-table-rspace:0pt;">
<tbody>
<tr>
<td>
<h4 style=" font-family: Inter;
font-size: 16px;
font-style: normal;
font-weight: 600;
line-height: 36px;
mso-line-height-rule:exactly;
letter-spacing: 0em;
text-align: left;
color:#6D6666;">About Kerberos</h4>
<p style=" font-family: Inter;
font-size: 14px;
font-style: normal;
font-weight: 400;
line-height: 24px;
mso-line-height-rule:exactly;
letter-spacing: 0em;
text-align: left;
color: #A69D9D;">Welcome to the revolutionary video analytics and video management platform. Open, modular, and extensible for everyone, anywhere.</p>
<p style="margin-top: 12px;">
<a href="https://twitter.com/kerberosio" style="text-decoration: none;color: none;">
<img width="24" height="24" alt="Twitter" src="https://kerberos.io/images/email/twitter.png"/>
</a>
<a href="https://reddit.com/r/kerberos_io" style="text-decoration: none;color: none;">
<img g width="24" height="24" alt="Reddit" src="https://kerberos.io/images/email/reddit.png"/>
</a>
<a href="https://www.youtube.com/channel/UCnd9q7iRNNw4W95eQwQuECA" style="text-decoration: none;color: none;">
<img g width="24" height="24" alt="Youtube" src="https://kerberos.io/images/email/youtube.png"/>
</a>
<a href="https://github.com/kerberos-io" style="text-decoration: none;color: none;">
<img g width="24" height="24" alt="Github" src="https://kerberos.io/images/email/github.png"/>
</a>
</p>
</td>
</tr>
</tbody>
</table>
</td>
<td class="corner-td" align="right"></td>
</tr>
</tbody>
</table>
<table style="border-collaps:collaps; mso-table-lspace:0pt; mso-table-rspace:0pt;">
<tbody>
<tr style="height: 50px">
<td></td>
</tr>
</tbody>
</table>
</td>
</tr>
</table>
</body>
</html>

View File

@@ -0,0 +1,21 @@
Kerberos.io
------------
Verify your access
Use the code below to open the shared case
Your verification code
{{code}}
Enter this code on the share page to access the case. This code expires in {{expiry}}.
If you didn't request this, you can safely ignore this email.
Get in touch
------------
support@kerberos.io
9000 Ghent, BE
https://kerberos.io
About Kerberos
------------
Welcome to the revolutionary video analytics and video management platform. Open, modular, and extensible for everyone, anywhere.

View File

@@ -0,0 +1,48 @@
{{/* Build the path to the configured MongoDB CA bundle. */}}
{{- define "hub.mongodb.tlsCAFile" -}}
{{- if and .Values.mongodb.tls.enabled .Values.mongodb.tls.existingSecret .Values.mongodb.tls.caFileName -}}
{{- printf "%s/%s" .Values.mongodb.tls.mountPath .Values.mongodb.tls.caFileName | clean -}}
{{- end -}}
{{- end -}}
{{/* Add TLS options to a configured MongoDB URI unless they are already present. */}}
{{- define "hub.mongodb.uri" -}}
{{- $uri := .Values.mongodb.uri | default "" -}}
{{- if and .Values.mongodb.tls.enabled $uri -}}
{{- if not (regexMatch "(?i)(^|[?&])tls=" $uri) -}}
{{- $separator := "?" -}}
{{- if contains "?" $uri -}}
{{- $separator = "&" -}}
{{- end -}}
{{- if or (hasSuffix "?" $uri) (hasSuffix "&" $uri) -}}
{{- $separator = "" -}}
{{- end -}}
{{- $uri = printf "%s%stls=true" $uri $separator -}}
{{- end -}}
{{- $caFile := include "hub.mongodb.tlsCAFile" . -}}
{{- if and $caFile (not (regexMatch "(?i)(^|[?&])tlsCAFile=" $uri)) -}}
{{- $separator := "&" -}}
{{- if not (contains "?" $uri) -}}
{{- $separator = "?" -}}
{{- else if or (hasSuffix "?" $uri) (hasSuffix "&" $uri) -}}
{{- $separator = "" -}}
{{- end -}}
{{- $uri = printf "%s%stlsCAFile=%s" $uri $separator $caFile -}}
{{- end -}}
{{- end -}}
{{- $uri -}}
{{- end -}}
{{/* Render the shared MongoDB CA Secret volume. */}}
{{- define "hub.mongodb.tlsVolume" -}}
- name: mongodb-tls
secret:
secretName: {{ .Values.mongodb.tls.existingSecret }}
{{- end -}}
{{/* Render the shared MongoDB CA volume mount. */}}
{{- define "hub.mongodb.tlsVolumeMount" -}}
- name: mongodb-tls
mountPath: {{ .Values.mongodb.tls.mountPath }}
readOnly: true
{{- end -}}

View File

@@ -14,6 +14,14 @@ spec:
labels:
app: admin
spec:
{{- with .Values.admin.volumes }}
volumes:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- with .Values.admin.topologySpreadConstraints }}
topologySpreadConstraints:
{{- toYaml . | nindent 8 }}
{{- end }}
containers:
- name: admin
image: "{{ .Values.global.imageRegistry }}{{ .Values.admin.repository }}:{{ .Values.admin.tag }}"
@@ -22,6 +30,10 @@ spec:
resources:
{{- toYaml . | nindent 12 }}
{{- end }}
{{- with .Values.admin.volumeMounts }}
volumeMounts:
{{- toYaml . | nindent 12 }}
{{- end }}
ports:
- name: http
containerPort: 80

View File

@@ -46,6 +46,14 @@ spec:
labels:
k8s-app: oauth2-proxy-admin
spec:
{{- with .Values.admin.oauth2Proxy.volumes }}
volumes:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- with .Values.admin.oauth2Proxy.topologySpreadConstraints }}
topologySpreadConstraints:
{{- toYaml . | nindent 8 }}
{{- end }}
containers:
- args:
- --provider=github
@@ -53,6 +61,10 @@ spec:
- --upstream=file:///dev/null
- --http-address=0.0.0.0:4180
- --skip-auth-preflight=true
{{- with .Values.admin.oauth2Proxy.volumeMounts }}
volumeMounts:
{{- toYaml . | nindent 12 }}
{{- end }}
env:
- name: OAUTH2_PROXY_CLIENT_ID
value: "{{ .Values.admin.oauth2Proxy.github.clientId }}"

View File

@@ -4,7 +4,7 @@ metadata:
name: mongodb-config
namespace: {{ .Release.Namespace }}
data:
MONGODB_URI: "{{ .Values.mongodb.uri }}"
MONGODB_URI: {{ include "hub.mongodb.uri" . | quote }}
MONGODB_HOST: "{{ .Values.mongodb.host }}"
MONGODB_AUTHENTICATION_MECHANISM: "{{ .Values.mongodb.authenticationMechanism }}"
MONGODB_DATABASE_CREDENTIALS: "{{ .Values.mongodb.adminDatabase }}"
@@ -12,4 +12,7 @@ data:
MONGODB_PASSWORD: "{{ .Values.mongodb.password }}"
MONGODB_RETRY_WRITES: "{{ .Values.mongodb.retryWrites }}"
MONGODB_FLAVOR: "{{ .Values.mongodb.flavor | default "mongodb" }}"
MONGODB_TLS: "{{ .Values.mongodb.tls.enabled }}"
MONGODB_TLS_CA_FILE: {{ include "hub.mongodb.tlsCAFile" . | quote }}
MONGODB_TLS_INSECURE_SKIP_VERIFY: "{{ .Values.mongodb.tls.insecureSkipVerify }}"
MONGODB_DATABASE_CLOUD: "Kerberos"

View File

@@ -1,4 +1,5 @@
{{- if or (eq .Values.mode "all") (eq .Values.mode "ui") -}}
{{- if .Values.kerberoshub.api.serviceEnabled }}
apiVersion: v1
kind: Service
metadata:
@@ -18,6 +19,7 @@ spec:
protocol: TCP
selector:
app: hub-api
{{- end }}
{{ if ne .Values.ingress "" }}
---
{{ if .Capabilities.APIVersions.Has "networking.k8s.io/v1" }}
@@ -129,7 +131,8 @@ spec:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- $serverTLS := .Values.kerberoshub.api.serverTLS }}
{{- if or .Values.kerberoshub.api.volumes (and $serverTLS.enabled $serverTLS.secretName) }}
{{- $mongodbTLS := .Values.mongodb.tls }}
{{- if or .Values.kerberoshub.api.volumes (and $serverTLS.enabled $serverTLS.secretName) (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
volumes:
{{- with .Values.kerberoshub.api.volumes }}
{{- toYaml . | nindent 8 }}
@@ -139,6 +142,13 @@ spec:
secret:
secretName: {{ $serverTLS.secretName }}
{{- end }}
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
{{- include "hub.mongodb.tlsVolume" . | nindent 8 }}
{{- end }}
{{- end }}
{{- with .Values.kerberoshub.api.topologySpreadConstraints }}
topologySpreadConstraints:
{{- toYaml . | nindent 8 }}
{{- end }}
containers:
- name: hub-api
@@ -151,7 +161,7 @@ spec:
ports:
- containerPort: 80
name: http
{{- if or .Values.kerberoshub.api.volumeMounts (and $serverTLS.enabled $serverTLS.secretName) }}
{{- if or .Values.kerberoshub.api.volumeMounts (and $serverTLS.enabled $serverTLS.secretName) (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
volumeMounts:
{{- with .Values.kerberoshub.api.volumeMounts}}
{{- toYaml . | nindent 12 }}
@@ -161,6 +171,9 @@ spec:
mountPath: {{ $serverTLS.mountPath }}
readOnly: true
{{- end }}
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
{{- include "hub.mongodb.tlsVolumeMount" . | nindent 12 }}
{{- end }}
{{- end }}
# Mongodb - loaded from ConfigMap
envFrom:
@@ -181,6 +194,23 @@ spec:
value: "{{ .Values.kerberoshub.api.schema }}://{{ .Values.kerberoshub.api.url }}"
- name: PUBLIC_URL
value: "{{ .Values.kerberoshub.frontend.schema }}://{{ .Values.kerberoshub.frontend.url }}"
- name: REFRESH_COOKIE_SECURE
value: {{ eq .Values.kerberoshub.api.schema "https" | quote }}
{{- $corsOrigins := list (printf "%s://%s" .Values.kerberoshub.frontend.schema .Values.kerberoshub.frontend.url) }}
{{- with .Values.kerberoshub.frontend.legacyUrl }}
{{- $corsOrigins = append $corsOrigins (printf "%s://%s" $.Values.kerberoshub.frontend.schema .) }}
{{- end }}
{{- range .Values.kerberoshub.frontend.domains }}
{{- $corsOrigins = append $corsOrigins (printf "%s://%s" $.Values.kerberoshub.frontend.schema .) }}
{{- end }}
{{- if and .Values.kerberoshub.frontend.multiTenant .Values.kerberoshub.frontend.tenantBaseDomain }}
{{- $corsOrigins = append $corsOrigins (printf "%s://*.%s" .Values.kerberoshub.frontend.schema .Values.kerberoshub.frontend.tenantBaseDomain) }}
{{- end }}
{{- if and .Values.kerberoshub.frontend.demoEnabled .Values.kerberoshub.frontend.demoUrl }}
{{- $corsOrigins = append $corsOrigins (printf "%s://%s" .Values.kerberoshub.frontend.schema .Values.kerberoshub.frontend.demoUrl) }}
{{- end }}
- name: CORS_ALLOWED_ORIGINS
value: {{ join "," $corsOrigins | quote }}
{{ if .Values.isPrivate }}
- name: KERBEROS_PRIVATE_CLOUD
value: "true"
@@ -253,6 +283,19 @@ spec:
- name: QUEUE_NAME
value: "{{ .Values.queueName }}"
# Deployment-global workflow definitions (WORKFLOW_DEFINITIONS): the
# SAME set the workflows engine consumes, assembled from the enabled
# definitions under kerberoshub.workflows.definitions (see
# kerberos-pipeline/_workflows-helpers.tpl). hub-api reads these
# read-only to surface config workflows alongside the user workflows
# it stores in the database; the config workflows are never persisted.
- name: WORKFLOW_DEFINITIONS
value: {{ include "kerberoshub.workflows.workflowDefinitions" . | quote }}
# Deployment service routing catalog used by API-owned embedded
# workflows (for example the one-stage case redaction modal flow).
- name: WORKFLOW_STAGE_QUEUES
value: {{ include "kerberoshub.workflows.stageQueues" . | quote }}
# Stripe for billing
- name: STRIPE_KEY
value: "{{ .Values.kerberoshub.api.stripe.privateKey }}"
@@ -347,6 +390,14 @@ spec:
value: "{{ .Values.email.templates.share }}"
- name: SHARE_TITLE
value: "{{ .Values.email.templates.shareTitle }}"
- name: CASE_SHARE_TEMPLATE
value: "{{ .Values.email.templates.caseShare }}"
- name: CASE_SHARE_TITLE
value: "{{ .Values.email.templates.caseShareTitle }}"
- name: CASE_SHARE_OTP_TEMPLATE
value: "{{ .Values.email.templates.caseShareOtp }}"
- name: CASE_SHARE_OTP_TITLE
value: "{{ .Values.email.templates.caseShareOtpTitle }}"
- name: ASSIGN_TASK_TEMPLATE
value: "{{ .Values.email.templates.assignTask }}"
- name: ASSIGN_TASK_TITLE
@@ -402,6 +453,7 @@ spec:
{{- toYaml .Values.kerberoshub.extraEnv | nindent 12 }}
{{- end }}
{{- if .Values.opentelemetry.enabled }}
# Open Telemetry tracing
- name: OTEL_EXPORTED_OTLP_ENABLED
value: "{{ .Values.opentelemetry.enabled }}"
@@ -409,4 +461,5 @@ spec:
value: "{{ .Values.opentelemetry.routingEnabled }}"
- name: OTEL_EXPORTER_OTLP_ENDPOINT
value: "{{ .Values.opentelemetry.collector.endpoint }}"
{{- end }}
{{- end }}

View File

@@ -29,6 +29,20 @@ spec:
imagePullSecrets:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- $mongodbTLS := .Values.mongodb.tls }}
{{- if or .Values.kerberoshub.cleanup.volumes (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
volumes:
{{- with .Values.kerberoshub.cleanup.volumes }}
{{- toYaml . | nindent 8 }}
{{- end }}
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
{{- include "hub.mongodb.tlsVolume" . | nindent 8 }}
{{- end }}
{{- end }}
{{- with .Values.kerberoshub.cleanup.topologySpreadConstraints }}
topologySpreadConstraints:
{{- toYaml . | nindent 8 }}
{{- end }}
containers:
- name: hub-cleanup
image: "{{ .Values.global.imageRegistry }}{{ .Values.kerberoshub.cleanup.repository }}:{{ .Values.kerberoshub.cleanup.tag }}"
@@ -37,6 +51,15 @@ spec:
resources:
{{- toYaml . | nindent 12 }}
{{- end }}
{{- if or .Values.kerberoshub.cleanup.volumeMounts (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
volumeMounts:
{{- with .Values.kerberoshub.cleanup.volumeMounts }}
{{- toYaml . | nindent 12 }}
{{- end }}
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
{{- include "hub.mongodb.tlsVolumeMount" . | nindent 12 }}
{{- end }}
{{- end }}
envFrom:
- configMapRef:
name: mongodb-config

View File

@@ -1,4 +1,4 @@
{{- if or (eq .Values.mode "all") (eq .Values.mode "ui") -}}
{{- if and (or (eq .Values.mode "all") (eq .Values.mode "ui")) .Values.kerberoshub.frontend.demoEnabled -}}
apiVersion: v1
kind: Service
metadata:
@@ -93,6 +93,10 @@ spec:
volumes:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- with .Values.kerberoshub.frontend.topologySpreadConstraints }}
topologySpreadConstraints:
{{- toYaml . | nindent 8 }}
{{- end }}
containers:
- name: hub-frontend-demo
image: "{{ .Values.global.imageRegistry }}{{ .Values.kerberoshub.frontend.repository }}:{{ .Values.kerberoshub.frontend.tag }}"
@@ -227,6 +231,8 @@ spec:
value: "{{ .Values.kerberoshub.frontend.features.workflows.enabled }}"
- name: FEATURE_DARK_MODE
value: "{{ .Values.kerberoshub.frontend.features.darkMode }}"
- name: FEATURE_SPLASH_SCREEN_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.splashScreen.enabled }}"
- name: FEATURE_LANDING_PAGE
value: "{{ .Values.kerberoshub.frontend.features.landingPage }}"
@@ -237,6 +243,16 @@ spec:
value: "{{ .Values.kerberoshub.frontend.features.i18n.defaultLanguage }}"
# features > liveview
- name: FEATURE_LIVE_STREAM_MODE
value: "{{ .Values.kerberoshub.frontend.features.liveview.liveStreamMode }}"
- name: FEATURE_HLS_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.liveview.hlsEnabled }}"
- name: FEATURE_MOQ_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.liveview.moqEnabled }}"
- name: MOQ_RELAY_URL
value: "{{ .Values.kerberoshub.frontend.features.liveview.moqRelayUrl }}"
- name: MOQ_BROADCAST_PREFIX
value: "{{ .Values.kerberoshub.frontend.features.liveview.moqBroadcastPrefix }}"
- name: FEATURE_LIVEVIEW_PAGINATION_MODE
value: "{{ .Values.kerberoshub.frontend.features.liveview.paginationMode }}"
- name: FEATURE_LIVEVIEW_PAGE_SIZE
@@ -284,7 +300,9 @@ spec:
# features > face redaction
- name: FEATURE_FACE_REDACTION_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.faceRedaction.enabled }}"
value: "{{ .Values.kerberoshub.frontend.features.faceRedaction.enabled }}"
- name: FEATURE_FACE_REDACTION_CLASSIFIER_TRACKS_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.faceRedaction.classifierTracksEnabled }}"
# features > media
- name: FEATURE_MEDIA_FILTER_DATE_ENABLED
@@ -303,7 +321,7 @@ spec:
value: "{{ .Values.kerberoshub.frontend.features.media.filter.region.enabled }}"
- name: FEATURE_MEDIA_FILTER_SORT_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.media.filter.sort.enabled }}"
- name: FEATURE_MEDIA_FILTER_CATEGORY_ENABLED
- name: FEATURE_MEDIA_FILTER_CATEGORIES_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.media.filter.category.enabled }}"
- name: FEATURE_MEDIA_FILTER_MARKERS_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.media.filter.markers.enabled }}"

View File

@@ -1,4 +1,5 @@
{{- if or (eq .Values.mode "all") (eq .Values.mode "ui") -}}
{{- if .Values.kerberoshub.frontend.serviceEnabled }}
apiVersion: v1
kind: Service
metadata:
@@ -14,6 +15,7 @@ spec:
name: http
selector:
app: hub-frontend
{{- end }}
{{ if ne .Values.ingress "" }}
---
{{- if .Capabilities.APIVersions.Has "networking.k8s.io/v1" }}
@@ -172,6 +174,10 @@ spec:
volumes:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- with .Values.kerberoshub.frontend.topologySpreadConstraints }}
topologySpreadConstraints:
{{- toYaml . | nindent 8 }}
{{- end }}
containers:
- name: hub-frontend
image: "{{ .Values.global.imageRegistry }}{{ .Values.kerberoshub.frontend.repository }}:{{ .Values.kerberoshub.frontend.tag }}"
@@ -306,8 +312,26 @@ spec:
value: "{{ .Values.kerberoshub.frontend.features.case.enabled }}"
- name: FEATURE_WORKFLOWS_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.workflows.enabled }}"
- name: FEATURE_ORGANISATIONS_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.organisations.enabled }}"
- name: FEATURE_ORGANISATION_SWITCHER_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.organisations.switcherEnabled }}"
- name: FEATURE_ORGANISATION_CREATION_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.organisations.creationEnabled }}"
- name: FEATURE_ORGANISATION_SETTINGS_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.organisations.settingsEnabled }}"
- name: FEATURE_PROJECTS_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.projects.enabled }}"
- name: FEATURE_PROJECT_SWITCHER_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.projects.switcherEnabled }}"
- name: FEATURE_PROJECT_CREATION_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.projects.creationEnabled }}"
- name: FEATURE_PROJECT_SETTINGS_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.projects.settingsEnabled }}"
- name: FEATURE_DARK_MODE
value: "{{ .Values.kerberoshub.frontend.features.darkModeEnabled }}"
- name: FEATURE_SPLASH_SCREEN_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.splashScreen.enabled }}"
- name: FEATURE_LANDING_PAGE
value: "{{ .Values.kerberoshub.frontend.features.landingPage }}"
@@ -320,6 +344,16 @@ spec:
# features > liveview
- name: FEATURE_DEFAULT_STREAM_MODE
value: "{{ .Values.kerberoshub.frontend.features.liveview.defaultStreamMode }}"
- name: FEATURE_LIVE_STREAM_MODE
value: "{{ .Values.kerberoshub.frontend.features.liveview.liveStreamMode }}"
- name: FEATURE_HLS_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.liveview.hlsEnabled }}"
- name: FEATURE_MOQ_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.liveview.moqEnabled }}"
- name: MOQ_RELAY_URL
value: "{{ .Values.kerberoshub.frontend.features.liveview.moqRelayUrl }}"
- name: MOQ_BROADCAST_PREFIX
value: "{{ .Values.kerberoshub.frontend.features.liveview.moqBroadcastPrefix }}"
- name: FEATURE_LIVEVIEW_PAGINATION_MODE
value: "{{ .Values.kerberoshub.frontend.features.liveview.paginationMode }}"
- name: FEATURE_LIVEVIEW_PAGE_SIZE
@@ -384,7 +418,9 @@ spec:
# features > face redaction
- name: FEATURE_FACE_REDACTION_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.faceRedaction.enabled }}"
value: "{{ .Values.kerberoshub.frontend.features.faceRedaction.enabled }}"
- name: FEATURE_FACE_REDACTION_CLASSIFIER_TRACKS_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.faceRedaction.classifierTracksEnabled }}"
# features > media
- name: FEATURE_MEDIA_FILTER_DATE_ENABLED
@@ -403,7 +439,7 @@ spec:
value: "{{ .Values.kerberoshub.frontend.features.media.filter.region.enabled }}"
- name: FEATURE_MEDIA_FILTER_SORT_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.media.filter.sort.enabled }}"
- name: FEATURE_MEDIA_FILTER_CATEGORY_ENABLED
- name: FEATURE_MEDIA_FILTER_CATEGORIES_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.media.filter.category.enabled }}"
- name: FEATURE_MEDIA_FILTER_MARKERS_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.media.filter.markers.enabled }}"

View File

@@ -29,8 +29,18 @@ spec:
imagePullSecrets:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- with .Values.kerberoshub.monitordevice.volumes }}
{{- $mongodbTLS := .Values.mongodb.tls }}
{{- if or .Values.kerberoshub.monitordevice.volumes (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
volumes:
{{- with .Values.kerberoshub.monitordevice.volumes }}
{{- toYaml . | nindent 8 }}
{{- end }}
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
{{- include "hub.mongodb.tlsVolume" . | nindent 8 }}
{{- end }}
{{- end }}
{{- with .Values.kerberoshub.monitordevice.topologySpreadConstraints }}
topologySpreadConstraints:
{{- toYaml . | nindent 8 }}
{{- end }}
containers:
@@ -41,10 +51,15 @@ spec:
resources:
{{- toYaml . | nindent 12 }}
{{- end }}
{{- with .Values.kerberoshub.monitordevice.volumeMounts}}
{{- if or .Values.kerberoshub.monitordevice.volumeMounts (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
volumeMounts:
{{- with .Values.kerberoshub.monitordevice.volumeMounts}}
{{- toYaml . | nindent 12 }}
{{- end }}
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
{{- include "hub.mongodb.tlsVolumeMount" . | nindent 12 }}
{{- end }}
{{- end }}
envFrom:
- configMapRef:
name: mongodb-config

View File

@@ -16,6 +16,14 @@ spec:
labels:
k8s-app: oauth2-proxy
spec:
{{- with .Values.kerberoshub.oauth2Proxy.volumes }}
volumes:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- with .Values.kerberoshub.oauth2Proxy.topologySpreadConstraints }}
topologySpreadConstraints:
{{- toYaml . | nindent 8 }}
{{- end }}
containers:
- args:
- --provider=github
@@ -23,6 +31,10 @@ spec:
- --upstream=file:///dev/null
- --http-address=0.0.0.0:4180
- --skip-auth-preflight=true
{{- with .Values.kerberoshub.oauth2Proxy.volumeMounts }}
volumeMounts:
{{- toYaml . | nindent 12 }}
{{- end }}
env:
- name: OAUTH2_PROXY_CLIENT_ID
value: "{{ .Values.kerberoshub.oauth2Proxy.github.clientId }}"

View File

@@ -26,10 +26,33 @@ spec:
imagePullSecrets:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- $mongodbTLS := .Values.mongodb.tls }}
{{- if or .Values.kerberoshub.reactivate.volumes (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
volumes:
{{- with .Values.kerberoshub.reactivate.volumes }}
{{- toYaml . | nindent 8 }}
{{- end }}
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
{{- include "hub.mongodb.tlsVolume" . | nindent 8 }}
{{- end }}
{{- end }}
{{- with .Values.kerberoshub.reactivate.topologySpreadConstraints }}
topologySpreadConstraints:
{{- toYaml . | nindent 8 }}
{{- end }}
containers:
- name: hub-reactivate-subscription
image: "{{ .Values.global.imageRegistry }}{{ .Values.kerberoshub.reactivate.repository }}:{{ .Values.kerberoshub.reactivate.tag }}"
imagePullPolicy: {{ .Values.kerberoshub.reactivate.pullPolicy }}
{{- if or .Values.kerberoshub.reactivate.volumeMounts (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
volumeMounts:
{{- with .Values.kerberoshub.reactivate.volumeMounts }}
{{- toYaml . | nindent 12 }}
{{- end }}
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
{{- include "hub.mongodb.tlsVolumeMount" . | nindent 12 }}
{{- end }}
{{- end }}
envFrom:
- configMapRef:
name: mongodb-config

View File

@@ -0,0 +1,67 @@
{{/*
Assemble the deployment-global workflow definitions (WORKFLOW_DEFINITIONS) as a
JSON array from every *enabled* workflow under kerberoshub.workflows.definitions.
This is the engine's boot-loaded configuration source and deployment stage
catalog: several distinct config workflows can run over one recording — each
opens its own run and dispatches only its own stages. Organisation-scoped
database workflows are discovered separately at runtime.
Each enabled definition contributes one workflow object:
name the map key (the workflow's human-readable name; also its identity
the engine derives a stable id from it when the definition carries
no explicit id).
enabled always true here (a disabled definition is skipped entirely).
source "config" provenance marking a Helm-defined, deployment-global,
ops-managed workflow (read-only in the API, no owning organisation).
triggers how a run OPENS. Defaults to a single bare automatic trigger
(opens for every recording); narrow with device/schedule triggers.
Per-stage `needs` (below) decide which stages then FIRE.
stages the executable stage set, each contributing the same routing
descriptor the stageRegistry emits:
operation the stage's operation (unique within the workflow).
dispatch "always" (default) | "conditional".
queue from the matching services.<operation>.queue
(authoritative; omitted when unset so the engine
derives "kcloud-<operation>-queue.fifo").
needs conditional stages only: upstream dependencies, each
{operation?, condition?}, carried through verbatim.
needsMode conditional stages: "any" (default) | "all".
*/}}
{{- define "kerberoshub.workflows.workflowDefinitions" -}}
{{- $defs := list -}}
{{- $services := .Values.kerberoshub.services | default dict -}}
{{- range $name, $wf := .Values.kerberoshub.workflows.definitions -}}
{{- if $wf.enabled -}}
{{- $stages := list -}}
{{- range $stage := $wf.stages -}}
{{- $op := $stage.operation -}}
{{- $entry := dict "operation" $op "dispatch" (default "always" $stage.dispatch) -}}
{{- $service := index $services $op -}}
{{- if $service }}{{- with $service.queue }}{{- $_ := set $entry "queue" . -}}{{- end }}{{- end }}
{{- with $stage.needs }}{{- $_ := set $entry "needs" . -}}{{- end }}
{{- with $stage.needsMode }}{{- $_ := set $entry "needsMode" . -}}{{- end }}
{{- $stages = append $stages $entry -}}
{{- end -}}
{{- $def := dict "name" $name "enabled" true "source" "config" "triggers" (default (list (dict "type" "automatic")) $wf.triggers) "stages" $stages -}}
{{- $defs = append $defs $def -}}
{{- end -}}
{{- end -}}
{{- $defs | toJson -}}
{{- end -}}
{{/*
Expose the deployment's operationqueue catalog to API producers that seed
embedded WorkflowRuns. Unlike WORKFLOW_DEFINITIONS this includes services that
are enabled for internal flows but are absent from user-visible workflow
definitions. The workflows engine remains authoritative for dispatch; producers
use this only to embed the same queue on a synthetic stage.
*/}}
{{- define "kerberoshub.workflows.stageQueues" -}}
{{- $queues := dict -}}
{{- range $operation, $service := (.Values.kerberoshub.services | default dict) -}}
{{- with $service.queue -}}
{{- $_ := set $queues $operation . -}}
{{- end -}}
{{- end -}}
{{- $queues | toJson -}}
{{- end -}}

View File

@@ -0,0 +1,145 @@
{{- /*
Generic workflow-stage worker.
Renders a Deployment + Service for every enabled worker under
kerberoshub.services.<name> other than the `workflows` engine itself. A custom
stage joins the pipeline by values alone — declare its worker here and route to
it from a kerberoshub.workflows.definitions stage of the same operation; no
per-stage template is needed.
Every stage worker receives the same connection contract; the only value that
varies by stage is the consume-queue variable name, <NAME>_QUEUE (a worker
named "loitering" gets LOITERING_QUEUE, "my-stage" gets MY_STAGE_QUEUE). To run
a worker outside the chart instead, leave services.<name>.enabled unset (or
false) and point its workflow stage at the queue you publish.
All stages receive the Vault read credentials (KERBEROS_STORAGE_URI /
ACCESS_KEY / SECRET). A stage that also writes an artefact back to Vault (e.g.
redaction) declares its destination provider with the named field
services.<name>.storageProvider, rendered as KERBEROS_STORAGE_PROVIDER; a
read-only stage omits it and gets no provider env.
*/ -}}
{{- if and (or (eq .Values.mode "all") (eq .Values.mode "pipeline")) .Values.kerberoshub.workflows.enabled -}}
{{- $root := . -}}
{{- $services := .Values.kerberoshub.services | default dict -}}
{{- range $name, $svc := $services -}}
{{- if and (ne $name "workflows") $svc $svc.enabled -}}
{{- $queueEnv := printf "%s_QUEUE" ($name | upper | replace "-" "_") -}}
---
apiVersion: apps/v1
kind: Deployment
metadata:
name: hub-{{ $name }}
namespace: {{ $root.Release.Namespace }}
spec:
replicas: {{ $svc.replicas | default 1 }}
selector:
matchLabels:
app: hub-{{ $name }}
minReadySeconds: 10
strategy:
type: RollingUpdate
rollingUpdate:
maxUnavailable: 1
maxSurge: 1
template:
metadata:
labels:
app: hub-{{ $name }}
spec:
{{- if $root.Values.kerberoshub.serviceAccount.create }}
serviceAccountName: {{ default (printf "%s-%s-sa" $root.Release.Name $root.Chart.Name | trunc 63 | trimSuffix "-") $root.Values.kerberoshub.serviceAccount.name }}
{{- end }}
{{- with $root.Values.imagePullSecrets }}
imagePullSecrets:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- with $svc.volumes }}
volumes:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- with $svc.topologySpreadConstraints }}
topologySpreadConstraints:
{{- toYaml . | nindent 8 }}
{{- end }}
containers:
- name: hub-{{ $name }}
image: "{{ $root.Values.global.imageRegistry }}{{ $svc.repository }}:{{ $svc.tag }}"
imagePullPolicy: {{ $svc.pullPolicy | default "IfNotPresent" }}
{{- with $svc.resources }}
resources:
{{- toYaml . | nindent 12 }}
{{- end }}
{{- with $svc.volumeMounts }}
volumeMounts:
{{- toYaml . | nindent 12 }}
{{- end }}
env:
- name: LOG_LEVEL
value: "{{ $svc.logLevel | default "info" }}"
- name: QUEUE_SYSTEM
value: "{{ $root.Values.queueProvider }}"
# The queue this stage worker consumes dispatched "{{ $name }}" stages
# from ({{ $queueEnv }}) and the workflows engine queue it routes its
# result back to (WORKFLOWS_QUEUE, so the run records the resolution and
# any stage that needs "{{ $name }}" can fire).
- name: {{ $queueEnv }}
value: "{{ $svc.queue }}"
- name: WORKFLOWS_QUEUE
value: "{{ $root.Values.kerberoshub.services.workflows.queue }}"
# RabbitMQ settings
- name: RABBITMQ_HOST
value: "{{ $root.Values.rabbitmq.host }}"
- name: RABBITMQ_EXCHANGE
value: "{{ $root.Values.rabbitmq.exchange }}"
- name: RABBITMQ_USERNAME
value: "{{ $root.Values.rabbitmq.username }}"
- name: RABBITMQ_PASSWORD
value: "{{ $root.Values.rabbitmq.password }}"
# Kerberos Vault — global storage credentials this stage uses to fetch
# the media it operates on.
- name: KERBEROS_STORAGE_URI
value: "{{ $root.Values.kerberosvault.uri }}"
- name: KERBEROS_STORAGE_ACCESS_KEY
value: "{{ $root.Values.kerberosvault.accesskey }}"
- name: KERBEROS_STORAGE_SECRET
value: "{{ $root.Values.kerberosvault.secretkey }}"
{{- with $svc.storageProvider }}
# Destination Vault provider (KERBEROS_STORAGE_PROVIDER) — only stages
# that write an artefact back (e.g. redaction) set services.<name>.
# storageProvider; read-only stages omit it and get no provider env.
- name: KERBEROS_STORAGE_PROVIDER
value: {{ . | quote }}
{{- end }}
# Per-stage tuning knobs. Any key/value under services.<name>.env is
# rendered verbatim as container env, so a worker can be tuned from
# values without a per-stage template. These override the image's own
# ENV defaults; the fixed contract env above is not overridable here.
{{- range $key, $value := $svc.env }}
- name: {{ $key }}
value: {{ $value | quote }}
{{- end }}
---
apiVersion: v1
kind: Service
metadata:
name: hub-{{ $name }}
namespace: {{ $root.Release.Namespace }}
labels:
app: hub-{{ $name }}
service: pipe
spec:
ports:
- name: hub-metrics
port: 8080
targetPort: 8080
protocol: TCP
selector:
app: hub-{{ $name }}
{{ end -}}
{{- end }}
{{- end }}

View File

@@ -0,0 +1,131 @@
{{- if and (or (eq .Values.mode "all") (eq .Values.mode "pipeline")) .Values.kerberoshub.workflows.enabled -}}
apiVersion: apps/v1
kind: Deployment
metadata:
name: hub-workflows
namespace: {{ .Release.Namespace }}
spec:
replicas: {{ .Values.kerberoshub.services.workflows.replicas }}
selector:
matchLabels:
app: hub-workflows
minReadySeconds: 10
strategy:
type: RollingUpdate
rollingUpdate:
maxUnavailable: 1
maxSurge: 1
template:
metadata:
annotations:
checksum/config: {{ include (print $.Template.BasePath "/configmap-mongodb.yaml") . | sha256sum }}
labels:
app: hub-workflows
spec:
{{- if .Values.kerberoshub.serviceAccount.create }}
serviceAccountName: {{ default (printf "%s-%s-sa" .Release.Name .Chart.Name | trunc 63 | trimSuffix "-") .Values.kerberoshub.serviceAccount.name }}
{{- end }}
{{- with .Values.imagePullSecrets }}
imagePullSecrets:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- $mongodbTLS := .Values.mongodb.tls }}
{{- if or .Values.kerberoshub.services.workflows.volumes (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
volumes:
{{- with .Values.kerberoshub.services.workflows.volumes }}
{{- toYaml . | nindent 8 }}
{{- end }}
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
{{- include "hub.mongodb.tlsVolume" . | nindent 8 }}
{{- end }}
{{- end }}
{{- with .Values.kerberoshub.services.workflows.topologySpreadConstraints }}
topologySpreadConstraints:
{{- toYaml . | nindent 8 }}
{{- end }}
containers:
- name: hub-workflows
image: "{{ .Values.global.imageRegistry }}{{ .Values.kerberoshub.services.workflows.repository }}:{{ .Values.kerberoshub.services.workflows.tag }}"
imagePullPolicy: {{ .Values.kerberoshub.services.workflows.pullPolicy }}
{{- with .Values.kerberoshub.services.workflows.resources }}
resources:
{{- toYaml . | nindent 12 }}
{{- end }}
{{- if or .Values.kerberoshub.services.workflows.volumeMounts (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
volumeMounts:
{{- with .Values.kerberoshub.services.workflows.volumeMounts }}
{{- toYaml . | nindent 12 }}
{{- end }}
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
{{- include "hub.mongodb.tlsVolumeMount" . | nindent 12 }}
{{- end }}
{{- end }}
envFrom:
- configMapRef:
name: mongodb-config
env:
- name: LOG_LEVEL
value: "{{ .Values.kerberoshub.services.workflows.logLevel }}"
- name: QUEUE_SYSTEM
value: "{{ .Values.queueProvider }}"
# Queue this service consumes from (WORKFLOWS_QUEUE) and the set of
# named workflows it runs (WORKFLOW_DEFINITIONS): each with its own
# trigger and executable stages, assembled from the enabled definitions
# under kerberoshub.workflows.definitions (see _workflows-helpers.tpl).
# Definitions are the engine's boot-loaded config source and deployment
# stage catalog. Organisation-scoped database workflows are read per
# recording; an in-cluster engine still requires at least one config
# definition so an empty catalog cannot silently drop traffic.
- name: WORKFLOWS_QUEUE
value: "{{ .Values.kerberoshub.services.workflows.queue }}"
- name: WORKFLOW_DEFINITIONS
value: {{ include "kerberoshub.workflows.workflowDefinitions" . | quote }}
# RabbitMQ settings
- name: RABBITMQ_HOST
value: "{{ .Values.rabbitmq.host }}"
- name: RABBITMQ_EXCHANGE
value: "{{ .Values.rabbitmq.exchange }}"
- name: RABBITMQ_USERNAME
value: "{{ .Values.rabbitmq.username }}"
- name: RABBITMQ_PASSWORD
value: "{{ .Values.rabbitmq.password }}"
# Kerberos Vault — global storage credentials a dispatched stage worker
# uses to fetch the media. Per-recording vault overrides (site/account)
# are resolved at dispatch time from the database.
- name: KERBEROS_STORAGE_URI
value: "{{ .Values.kerberosvault.uri }}"
- name: KERBEROS_STORAGE_ACCESS_KEY
value: "{{ .Values.kerberosvault.accesskey }}"
- name: KERBEROS_STORAGE_SECRET
value: "{{ .Values.kerberosvault.secretkey }}"
{{- if .Values.opentelemetry.enabled }}
# Open Telemetry tracing
- name: OTEL_EXPORTED_OTLP_ENABLED
value: "{{ .Values.opentelemetry.enabled }}"
- name: OTEL_EXPORTED_OTLP_ROUTING_ENABLED
value: "{{ .Values.opentelemetry.routingEnabled }}"
- name: OTEL_EXPORTER_OTLP_ENDPOINT
value: "{{ .Values.opentelemetry.collector.endpoint }}"
{{- end }}
---
apiVersion: v1
kind: Service
metadata:
name: hub-workflows
namespace: {{ .Release.Namespace }}
labels:
app: hub-workflows
service: pipe
spec:
ports:
- name: hub-metrics
port: 8080
targetPort: 8080
protocol: TCP
selector:
app: hub-workflows
{{- end }}

View File

@@ -29,6 +29,20 @@ spec:
imagePullSecrets:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- $mongodbTLS := .Values.mongodb.tls }}
{{- if or .Values.kerberospipeline.analysis.volumes (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
volumes:
{{- with .Values.kerberospipeline.analysis.volumes }}
{{- toYaml . | nindent 8 }}
{{- end }}
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
{{- include "hub.mongodb.tlsVolume" . | nindent 8 }}
{{- end }}
{{- end }}
{{- with .Values.kerberospipeline.analysis.topologySpreadConstraints }}
topologySpreadConstraints:
{{- toYaml . | nindent 8 }}
{{- end }}
containers:
- name: pipe-analysis
image: "{{ .Values.global.imageRegistry }}{{ .Values.kerberospipeline.analysis.repository }}:{{ .Values.kerberospipeline.analysis.tag }}"
@@ -37,6 +51,15 @@ spec:
resources:
{{- toYaml . | nindent 12 }}
{{- end }}
{{- if or .Values.kerberospipeline.analysis.volumeMounts (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
volumeMounts:
{{- with .Values.kerberospipeline.analysis.volumeMounts }}
{{- toYaml . | nindent 12 }}
{{- end }}
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
{{- include "hub.mongodb.tlsVolumeMount" . | nindent 12 }}
{{- end }}
{{- end }}
envFrom:
- configMapRef:
name: mongodb-config
@@ -69,6 +92,18 @@ spec:
value: "{{ .Values.rabbitmq.username }}"
- name: RABBITMQ_PASSWORD
value: "{{ .Values.rabbitmq.password }}"
# When true, analysis tees the classify result to the hub-workflows
# service in parallel with the throttler/notification tail (which still
# runs unchanged). Kept in sync with whether the workflows service runs.
- name: WORKFLOWS_ENABLED
value: "{{ .Values.kerberoshub.workflows.enabled }}"
# Queue analysis publishes opened workflow runs to (WORKFLOWS_QUEUE),
# taken from the workflows service's queue so analysis and the engine
# always agree on the queue name (no drift).
- name: WORKFLOWS_QUEUE
value: "{{ .Values.kerberoshub.services.workflows.queue }}"
# Kerberos Vault
- name: KERBEROS_STORAGE_URI
@@ -82,6 +117,7 @@ spec:
- name: SPRITE_ENABLED
value: "{{ .Values.kerberospipeline.sprite.enabled }}"
{{- if .Values.opentelemetry.enabled }}
# Open Telemetry tracing
- name: OTEL_EXPORTED_OTLP_ENABLED
value: "{{ .Values.opentelemetry.enabled }}"
@@ -89,6 +125,7 @@ spec:
value: "{{ .Values.opentelemetry.routingEnabled }}"
- name: OTEL_EXPORTER_OTLP_ENDPOINT
value: "{{ .Values.opentelemetry.collector.endpoint }}"
{{- end }}
---
apiVersion: v1
kind: Service

View File

@@ -27,6 +27,14 @@ spec:
imagePullSecrets:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- with .Values.kerberospipeline.counting.volumes }}
volumes:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- with .Values.kerberospipeline.counting.topologySpreadConstraints }}
topologySpreadConstraints:
{{- toYaml . | nindent 8 }}
{{- end }}
containers:
- name: pipe-counting
image: "{{ .Values.global.imageRegistry }}{{ .Values.kerberospipeline.counting.repository }}:{{ .Values.kerberospipeline.counting.tag }}"
@@ -35,6 +43,10 @@ spec:
resources:
{{- toYaml . | nindent 12 }}
{{- end }}
{{- with .Values.kerberospipeline.counting.volumeMounts }}
volumeMounts:
{{- toYaml . | nindent 12 }}
{{- end }}
env:
- name: LOG_LEVEL
value: "{{ .Values.kerberospipeline.counting.logLevel }}"
@@ -65,6 +77,7 @@ spec:
- name: RABBITMQ_PASSWORD
value: "{{ .Values.rabbitmq.password }}"
{{- if .Values.opentelemetry.enabled }}
# Open Telemetry tracing
- name: OTEL_EXPORTED_OTLP_ENABLED
value: "{{ .Values.opentelemetry.enabled }}"
@@ -72,6 +85,7 @@ spec:
value: "{{ .Values.opentelemetry.routingEnabled }}"
- name: OTEL_EXPORTER_OTLP_ENDPOINT
value: "{{ .Values.opentelemetry.collector.endpoint }}"
{{- end }}
---
apiVersion: v1
kind: Service

View File

@@ -27,6 +27,14 @@ spec:
imagePullSecrets:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- with .Values.kerberospipeline.dominantColor.volumes }}
volumes:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- with .Values.kerberospipeline.dominantColor.topologySpreadConstraints }}
topologySpreadConstraints:
{{- toYaml . | nindent 8 }}
{{- end }}
containers:
- name: pipe-dominantcolor
image: "{{ .Values.global.imageRegistry }}{{ .Values.kerberospipeline.dominantColor.repository }}:{{ .Values.kerberospipeline.dominantColor.tag }}"
@@ -35,6 +43,10 @@ spec:
resources:
{{- toYaml . | nindent 12 }}
{{- end }}
{{- with .Values.kerberospipeline.dominantColor.volumeMounts }}
volumeMounts:
{{- toYaml . | nindent 12 }}
{{- end }}
env:
- name: LOG_LEVEL
value: "{{ .Values.kerberospipeline.dominantColor.logLevel }}"
@@ -65,6 +77,7 @@ spec:
- name: RABBITMQ_PASSWORD
value: "{{ .Values.rabbitmq.password }}"
{{- if .Values.opentelemetry.enabled }}
# Open Telemetry tracing
- name: OTEL_EXPORTED_OTLP_ENABLED
value: "{{ .Values.opentelemetry.enabled }}"
@@ -72,6 +85,7 @@ spec:
value: "{{ .Values.opentelemetry.routingEnabled }}"
- name: OTEL_EXPORTER_OTLP_ENDPOINT
value: "{{ .Values.opentelemetry.collector.endpoint }}"
{{- end }}
---
apiVersion: v1
kind: Service

View File

@@ -29,6 +29,20 @@ spec:
imagePullSecrets:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- $mongodbTLS := .Values.mongodb.tls }}
{{- if or .Values.kerberospipeline.event.volumes (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
volumes:
{{- with .Values.kerberospipeline.event.volumes }}
{{- toYaml . | nindent 8 }}
{{- end }}
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
{{- include "hub.mongodb.tlsVolume" . | nindent 8 }}
{{- end }}
{{- end }}
{{- with .Values.kerberospipeline.event.topologySpreadConstraints }}
topologySpreadConstraints:
{{- toYaml . | nindent 8 }}
{{- end }}
containers:
- name: pipe-event
image: "{{ .Values.global.imageRegistry }}{{ .Values.kerberospipeline.event.repository }}:{{ .Values.kerberospipeline.event.tag }}"
@@ -37,6 +51,15 @@ spec:
resources:
{{- toYaml . | nindent 12 }}
{{- end }}
{{- if or .Values.kerberospipeline.event.volumeMounts (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
volumeMounts:
{{- with .Values.kerberospipeline.event.volumeMounts }}
{{- toYaml . | nindent 12 }}
{{- end }}
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
{{- include "hub.mongodb.tlsVolumeMount" . | nindent 12 }}
{{- end }}
{{- end }}
ports:
- containerPort: 8080
envFrom:
@@ -74,6 +97,7 @@ spec:
- name: RABBITMQ_PASSWORD
value: "{{ .Values.rabbitmq.password }}"
{{- if .Values.opentelemetry.enabled }}
# Open Telemetry tracing
- name: OTEL_EXPORTED_OTLP_ENABLED
value: "{{ .Values.opentelemetry.enabled }}"
@@ -81,6 +105,7 @@ spec:
value: "{{ .Values.opentelemetry.routingEnabled }}"
- name: OTEL_EXPORTER_OTLP_ENDPOINT
value: "{{ .Values.opentelemetry.collector.endpoint }}"
{{- end }}
---
apiVersion: v1
kind: Service

View File

@@ -29,8 +29,18 @@ spec:
imagePullSecrets:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- with .Values.kerberospipeline.export.volumes }}
{{- $mongodbTLS := .Values.mongodb.tls }}
{{- if or .Values.kerberospipeline.export.volumes (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
volumes:
{{- with .Values.kerberospipeline.export.volumes }}
{{- toYaml . | nindent 8 }}
{{- end }}
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
{{- include "hub.mongodb.tlsVolume" . | nindent 8 }}
{{- end }}
{{- end }}
{{- with .Values.kerberospipeline.export.topologySpreadConstraints }}
topologySpreadConstraints:
{{- toYaml . | nindent 8 }}
{{- end }}
containers:
@@ -41,10 +51,15 @@ spec:
resources:
{{- toYaml . | nindent 12 }}
{{- end }}
{{- with .Values.kerberospipeline.export.volumeMounts }}
{{- if or .Values.kerberospipeline.export.volumeMounts (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
volumeMounts:
{{- with .Values.kerberospipeline.export.volumeMounts }}
{{- toYaml . | nindent 12 }}
{{- end }}
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
{{- include "hub.mongodb.tlsVolumeMount" . | nindent 12 }}
{{- end }}
{{- end }}
envFrom:
- configMapRef:
name: mongodb-config
@@ -118,6 +133,7 @@ spec:
- name: VAULT_THUMBNAIL_SECRET_KEY
value: "{{ .Values.kerberosvault.thumbnail.secretKey }}"
{{- if .Values.opentelemetry.enabled }}
# Open Telemetry tracing
- name: OTEL_EXPORTED_OTLP_ENABLED
value: "{{ .Values.opentelemetry.enabled }}"
@@ -125,6 +141,7 @@ spec:
value: "{{ .Values.opentelemetry.routingEnabled }}"
- name: OTEL_EXPORTER_OTLP_ENDPOINT
value: "{{ .Values.opentelemetry.collector.endpoint }}"
{{- end }}
---
apiVersion: v1
kind: Service

View File

@@ -29,6 +29,20 @@ spec:
imagePullSecrets:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- $mongodbTLS := .Values.mongodb.tls }}
{{- if or .Values.kerberospipeline.monitor.volumes (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
volumes:
{{- with .Values.kerberospipeline.monitor.volumes }}
{{- toYaml . | nindent 8 }}
{{- end }}
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
{{- include "hub.mongodb.tlsVolume" . | nindent 8 }}
{{- end }}
{{- end }}
{{- with .Values.kerberospipeline.monitor.topologySpreadConstraints }}
topologySpreadConstraints:
{{- toYaml . | nindent 8 }}
{{- end }}
containers:
- name: pipe-monitor
image: "{{ .Values.global.imageRegistry }}{{ .Values.kerberospipeline.monitor.repository }}:{{ .Values.kerberospipeline.monitor.tag }}"
@@ -37,6 +51,15 @@ spec:
resources:
{{- toYaml . | nindent 12 }}
{{- end }}
{{- if or .Values.kerberospipeline.monitor.volumeMounts (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
volumeMounts:
{{- with .Values.kerberospipeline.monitor.volumeMounts }}
{{- toYaml . | nindent 12 }}
{{- end }}
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
{{- include "hub.mongodb.tlsVolumeMount" . | nindent 12 }}
{{- end }}
{{- end }}
envFrom:
- configMapRef:
name: mongodb-config
@@ -91,6 +114,7 @@ spec:
- name: SMTP_PASSWORD
value: "{{ .Values.email.smtp.password }}"
{{- if .Values.opentelemetry.enabled }}
# Open Telemetry tracing
- name: OTEL_EXPORTED_OTLP_ENABLED
value: "{{ .Values.opentelemetry.enabled }}"
@@ -98,6 +122,7 @@ spec:
value: "{{ .Values.opentelemetry.routingEnabled }}"
- name: OTEL_EXPORTER_OTLP_ENDPOINT
value: "{{ .Values.opentelemetry.collector.endpoint }}"
{{- end }}
---
apiVersion: v1
kind: Service

View File

@@ -29,8 +29,18 @@ spec:
imagePullSecrets:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- with .Values.kerberospipeline.notifyTest.volumes }}
{{- $mongodbTLS := .Values.mongodb.tls }}
{{- if or .Values.kerberospipeline.notifyTest.volumes (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
volumes:
{{- with .Values.kerberospipeline.notifyTest.volumes }}
{{- toYaml . | nindent 8 }}
{{- end }}
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
{{- include "hub.mongodb.tlsVolume" . | nindent 8 }}
{{- end }}
{{- end }}
{{- with .Values.kerberospipeline.notifyTest.topologySpreadConstraints }}
topologySpreadConstraints:
{{- toYaml . | nindent 8 }}
{{- end }}
containers:
@@ -41,10 +51,15 @@ spec:
resources:
{{- toYaml . | nindent 12 }}
{{- end }}
{{- with .Values.kerberospipeline.notifyTest.volumeMounts}}
{{- if or .Values.kerberospipeline.notifyTest.volumeMounts (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
volumeMounts:
{{- with .Values.kerberospipeline.notifyTest.volumeMounts}}
{{- toYaml . | nindent 12 }}
{{- end }}
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
{{- include "hub.mongodb.tlsVolumeMount" . | nindent 12 }}
{{- end }}
{{- end }}
envFrom:
- configMapRef:
name: mongodb-config
@@ -106,6 +121,7 @@ spec:
- name: SMTP_PASSWORD
value: "{{ .Values.email.smtp.password }}"
{{- if .Values.opentelemetry.enabled }}
# Open Telemetry tracing
- name: OTEL_EXPORTED_OTLP_ENABLED
value: "{{ .Values.opentelemetry.enabled }}"
@@ -113,6 +129,7 @@ spec:
value: "{{ .Values.opentelemetry.routingEnabled }}"
- name: OTEL_EXPORTER_OTLP_ENDPOINT
value: "{{ .Values.opentelemetry.collector.endpoint }}"
{{- end }}
---
apiVersion: v1
kind: Service

View File

@@ -29,8 +29,18 @@ spec:
imagePullSecrets:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- with .Values.kerberospipeline.notify.volumes }}
{{- $mongodbTLS := .Values.mongodb.tls }}
{{- if or .Values.kerberospipeline.notify.volumes (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
volumes:
{{- with .Values.kerberospipeline.notify.volumes }}
{{- toYaml . | nindent 8 }}
{{- end }}
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
{{- include "hub.mongodb.tlsVolume" . | nindent 8 }}
{{- end }}
{{- end }}
{{- with .Values.kerberospipeline.notify.topologySpreadConstraints }}
topologySpreadConstraints:
{{- toYaml . | nindent 8 }}
{{- end }}
containers:
@@ -41,10 +51,15 @@ spec:
resources:
{{- toYaml . | nindent 12 }}
{{- end }}
{{- with .Values.kerberospipeline.notify.volumeMounts}}
{{- if or .Values.kerberospipeline.notify.volumeMounts (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
volumeMounts:
{{- with .Values.kerberospipeline.notify.volumeMounts}}
{{- toYaml . | nindent 12 }}
{{- end }}
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
{{- include "hub.mongodb.tlsVolumeMount" . | nindent 12 }}
{{- end }}
{{- end }}
envFrom:
- configMapRef:
name: mongodb-config
@@ -138,6 +153,7 @@ spec:
- name: VAULT_SPRITE_SECRET_KEY
value: "{{ .Values.kerberosvault.sprite.secretKey }}"
{{- if .Values.opentelemetry.enabled }}
# Open Telemetry tracing
- name: OTEL_EXPORTED_OTLP_ENABLED
value: "{{ .Values.opentelemetry.enabled }}"
@@ -145,6 +161,7 @@ spec:
value: "{{ .Values.opentelemetry.routingEnabled }}"
- name: OTEL_EXPORTER_OTLP_ENDPOINT
value: "{{ .Values.opentelemetry.collector.endpoint }}"
{{- end }}
---
apiVersion: v1
kind: Service

View File

@@ -1,102 +0,0 @@
{{- if or (eq .Values.mode "all") (eq .Values.mode "pipeline") -}}
apiVersion: apps/v1
kind: Deployment
metadata:
name: pipe-redaction
namespace: {{ .Release.Namespace }}
spec:
replicas: {{ .Values.kerberospipeline.redaction.replicas }}
selector:
matchLabels:
app: pipe-redaction
minReadySeconds: 10
strategy:
type: RollingUpdate
rollingUpdate:
maxUnavailable: 1
maxSurge: 1
template:
metadata:
labels:
app: pipe-redaction
spec:
{{- if .Values.kerberoshub.serviceAccount.create }}
serviceAccountName: {{ default (printf "%s-%s-sa" .Release.Name .Chart.Name | trunc 63 | trimSuffix "-") .Values.kerberoshub.serviceAccount.name }}
{{- end }}
{{- with .Values.imagePullSecrets }}
imagePullSecrets:
{{- toYaml . | nindent 8 }}
{{- end }}
containers:
- name: pipe-redaction
image: "{{ .Values.global.imageRegistry }}{{ .Values.kerberospipeline.redaction.repository }}:{{ .Values.kerberospipeline.redaction.tag }}"
imagePullPolicy: {{ .Values.kerberospipeline.redaction.pullPolicy }}
{{- with .Values.kerberospipeline.redaction.resources }}
resources:
{{- toYaml . | nindent 12 }}
{{- end }}
env:
- name: LOG_LEVEL
value: "{{ .Values.kerberospipeline.redaction.logLevel }}"
- name: CLOUD_PROVIDER
value: "{{ .Values.cloudProvider }}"
- name: QUEUE_SYSTEM
value: "{{ .Values.queueProvider }}"
# Kafka settings
- name: KAFKA_BROKER
value: "{{ .Values.kafka.broker }}"
- name: KAFKA_USERNAME
value: "{{ .Values.kafka.username }}"
- name: KAFKA_PASSWORD
value: "{{ .Values.kafka.password }}"
- name: KAFKA_MECHANISM
value: "{{ .Values.kafka.mechanism }}"
- name: KAFKA_SECURITY
value: "{{ .Values.kafka.security }}"
# RabbitMQ settings
- name: RABBITMQ_HOST
value: "{{ .Values.rabbitmq.host }}"
- name: RABBITMQ_EXCHANGE
value: "{{ .Values.rabbitmq.exchange }}"
- name: RABBITMQ_USERNAME
value: "{{ .Values.rabbitmq.username }}"
- name: RABBITMQ_PASSWORD
value: "{{ .Values.rabbitmq.password }}"
# Kerberos Vault (used to download the source media and upload the redacted artifact).
- name: KERBEROS_STORAGE_URI
value: "{{ .Values.kerberosvault.uri }}"
- name: KERBEROS_STORAGE_PROVIDER
value: "{{ .Values.kerberosvault.provider }}"
- name: KERBEROS_STORAGE_ACCESS_KEY
value: "{{ .Values.kerberosvault.accesskey }}"
- name: KERBEROS_STORAGE_SECRET
value: "{{ .Values.kerberosvault.secretkey }}"
# Open Telemetry tracing
- name: OTEL_EXPORTED_OTLP_ENABLED
value: "{{ .Values.opentelemetry.enabled }}"
- name: OTEL_EXPORTED_OTLP_ROUTING_ENABLED
value: "{{ .Values.opentelemetry.routingEnabled }}"
- name: OTEL_EXPORTER_OTLP_ENDPOINT
value: "{{ .Values.opentelemetry.collector.endpoint }}"
---
apiVersion: v1
kind: Service
metadata:
name: pipe-redaction
namespace: {{ .Release.Namespace }}
labels:
app: pipe-redaction
service: pipe
spec:
ports:
- name: hub-metrics
port: 8080
targetPort: 8080
protocol: TCP
selector:
app: pipe-redaction
{{- end }}

View File

@@ -29,6 +29,20 @@ spec:
imagePullSecrets:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- $mongodbTLS := .Values.mongodb.tls }}
{{- if or .Values.kerberospipeline.sequence.volumes (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
volumes:
{{- with .Values.kerberospipeline.sequence.volumes }}
{{- toYaml . | nindent 8 }}
{{- end }}
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
{{- include "hub.mongodb.tlsVolume" . | nindent 8 }}
{{- end }}
{{- end }}
{{- with .Values.kerberospipeline.sequence.topologySpreadConstraints }}
topologySpreadConstraints:
{{- toYaml . | nindent 8 }}
{{- end }}
containers:
- name: pipe-sequence
image: "{{ .Values.global.imageRegistry }}{{ .Values.kerberospipeline.sequence.repository }}:{{ .Values.kerberospipeline.sequence.tag }}"
@@ -37,6 +51,15 @@ spec:
resources:
{{- toYaml . | nindent 12 }}
{{- end }}
{{- if or .Values.kerberospipeline.sequence.volumeMounts (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
volumeMounts:
{{- with .Values.kerberospipeline.sequence.volumeMounts }}
{{- toYaml . | nindent 12 }}
{{- end }}
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
{{- include "hub.mongodb.tlsVolumeMount" . | nindent 12 }}
{{- end }}
{{- end }}
envFrom:
- configMapRef:
name: mongodb-config
@@ -68,6 +91,7 @@ spec:
- name: RABBITMQ_PASSWORD
value: "{{ .Values.rabbitmq.password }}"
{{- if .Values.opentelemetry.enabled }}
# Open Telemetry tracing
- name: OTEL_EXPORTED_OTLP_ENABLED
value: "{{ .Values.opentelemetry.enabled }}"
@@ -75,6 +99,7 @@ spec:
value: "{{ .Values.opentelemetry.routingEnabled }}"
- name: OTEL_EXPORTER_OTLP_ENDPOINT
value: "{{ .Values.opentelemetry.collector.endpoint }}"
{{- end }}
---
apiVersion: v1
kind: Service

View File

@@ -27,6 +27,14 @@ spec:
imagePullSecrets:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- with .Values.kerberospipeline.sprite.volumes }}
volumes:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- with .Values.kerberospipeline.sprite.topologySpreadConstraints }}
topologySpreadConstraints:
{{- toYaml . | nindent 8 }}
{{- end }}
containers:
- name: pipe-sprite
image: "{{ .Values.global.imageRegistry }}{{ .Values.kerberospipeline.sprite.repository }}:{{ .Values.kerberospipeline.sprite.tag }}"
@@ -35,6 +43,10 @@ spec:
resources:
{{- toYaml . | nindent 12 }}
{{- end }}
{{- with .Values.kerberospipeline.sprite.volumeMounts }}
volumeMounts:
{{- toYaml . | nindent 12 }}
{{- end }}
env:
- name: LOG_LEVEL
value: "{{ .Values.kerberospipeline.sprite.logLevel }}"
@@ -88,6 +100,7 @@ spec:
- name: VAULT_SPRITE_HEIGHT
value: "{{ .Values.kerberospipeline.sprite.height }}"
{{- if .Values.opentelemetry.enabled }}
# Open Telemetry tracing
- name: OTEL_EXPORTED_OTLP_ENABLED
value: "{{ .Values.opentelemetry.enabled }}"
@@ -95,6 +108,7 @@ spec:
value: "{{ .Values.opentelemetry.routingEnabled }}"
- name: OTEL_EXPORTER_OTLP_ENDPOINT
value: "{{ .Values.opentelemetry.collector.endpoint }}"
{{- end }}
---
apiVersion: v1
kind: Service

View File

@@ -29,6 +29,20 @@ spec:
imagePullSecrets:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- $mongodbTLS := .Values.mongodb.tls }}
{{- if or .Values.kerberospipeline.throttler.volumes (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
volumes:
{{- with .Values.kerberospipeline.throttler.volumes }}
{{- toYaml . | nindent 8 }}
{{- end }}
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
{{- include "hub.mongodb.tlsVolume" . | nindent 8 }}
{{- end }}
{{- end }}
{{- with .Values.kerberospipeline.throttler.topologySpreadConstraints }}
topologySpreadConstraints:
{{- toYaml . | nindent 8 }}
{{- end }}
containers:
- name: pipe-throttler
image: "{{ .Values.global.imageRegistry }}{{ .Values.kerberospipeline.throttler.repository }}:{{ .Values.kerberospipeline.throttler.tag }}"
@@ -37,6 +51,15 @@ spec:
resources:
{{- toYaml . | nindent 12 }}
{{- end }}
{{- if or .Values.kerberospipeline.throttler.volumeMounts (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
volumeMounts:
{{- with .Values.kerberospipeline.throttler.volumeMounts }}
{{- toYaml . | nindent 12 }}
{{- end }}
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
{{- include "hub.mongodb.tlsVolumeMount" . | nindent 12 }}
{{- end }}
{{- end }}
envFrom:
- configMapRef:
name: mongodb-config
@@ -70,6 +93,7 @@ spec:
- name: RABBITMQ_PASSWORD
value: "{{ .Values.rabbitmq.password }}"
{{- if .Values.opentelemetry.enabled }}
# Open Telemetry tracing
- name: OTEL_EXPORTED_OTLP_ENABLED
value: "{{ .Values.opentelemetry.enabled }}"
@@ -77,6 +101,7 @@ spec:
value: "{{ .Values.opentelemetry.routingEnabled }}"
- name: OTEL_EXPORTER_OTLP_ENDPOINT
value: "{{ .Values.opentelemetry.collector.endpoint }}"
{{- end }}
---
apiVersion: v1
kind: Service

View File

@@ -27,6 +27,14 @@ spec:
imagePullSecrets:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- with .Values.kerberospipeline.thumbnail.volumes }}
volumes:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- with .Values.kerberospipeline.thumbnail.topologySpreadConstraints }}
topologySpreadConstraints:
{{- toYaml . | nindent 8 }}
{{- end }}
containers:
- name: pipe-thumbnail
image: "{{ .Values.global.imageRegistry }}{{ .Values.kerberospipeline.thumbnail.repository }}:{{ .Values.kerberospipeline.thumbnail.tag }}"
@@ -35,6 +43,10 @@ spec:
resources:
{{- toYaml . | nindent 12 }}
{{- end }}
{{- with .Values.kerberospipeline.thumbnail.volumeMounts }}
volumeMounts:
{{- toYaml . | nindent 12 }}
{{- end }}
env:
- name: LOG_LEVEL
value: "{{ .Values.kerberospipeline.thumbnail.logLevel }}"
@@ -91,6 +103,7 @@ spec:
- name: VAULT_THUMBNAIL_SECRET_KEY
value: "{{ .Values.kerberosvault.thumbnail.secretKey }}"
{{- if .Values.opentelemetry.enabled }}
# Open Telemetry tracing
- name: OTEL_EXPORTED_OTLP_ENABLED
value: "{{ .Values.opentelemetry.enabled }}"
@@ -98,6 +111,7 @@ spec:
value: "{{ .Values.opentelemetry.routingEnabled }}"
- name: OTEL_EXPORTER_OTLP_ENDPOINT
value: "{{ .Values.opentelemetry.collector.endpoint }}"
{{- end }}
---
apiVersion: v1

View File

@@ -27,6 +27,20 @@ spec:
imagePullSecrets:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- $mongodbTLS := .Values.mongodb.tls }}
{{- if or .Values.kerberoshub.forwarder.volumes (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
volumes:
{{- with .Values.kerberoshub.forwarder.volumes }}
{{- toYaml . | nindent 8 }}
{{- end }}
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
{{- include "hub.mongodb.tlsVolume" . | nindent 8 }}
{{- end }}
{{- end }}
{{- with .Values.kerberoshub.forwarder.topologySpreadConstraints }}
topologySpreadConstraints:
{{- toYaml . | nindent 8 }}
{{- end }}
containers:
- name: vault-forwarder
image: "{{ .Values.global.imageRegistry }}{{ .Values.kerberoshub.forwarder.repository }}:{{ .Values.kerberoshub.forwarder.tag }}"
@@ -35,6 +49,15 @@ spec:
requests:
memory: 10Mi
cpu: 10m
{{- if or .Values.kerberoshub.forwarder.volumeMounts (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
volumeMounts:
{{- with .Values.kerberoshub.forwarder.volumeMounts }}
{{- toYaml . | nindent 12 }}
{{- end }}
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
{{- include "hub.mongodb.tlsVolumeMount" . | nindent 12 }}
{{- end }}
{{- end }}
envFrom:
- configMapRef:
name: mongodb-config

View File

@@ -24,10 +24,22 @@ spec:
imagePullSecrets:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- with .Values.kerberoshub.proxy.volumes }}
volumes:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- with .Values.kerberoshub.proxy.topologySpreadConstraints }}
topologySpreadConstraints:
{{- toYaml . | nindent 8 }}
{{- end }}
containers:
- name: vault-proxy
image: "{{ .Values.global.imageRegistry }}{{ .Values.kerberoshub.proxy.repository }}:{{ .Values.kerberoshub.proxy.tag }}"
imagePullPolicy: {{ .Values.kerberoshub.proxy.pullPolicy }}
{{- with .Values.kerberoshub.proxy.volumeMounts }}
volumeMounts:
{{- toYaml . | nindent 12 }}
{{- end }}
ports:
- containerPort: 8080
name: http

View File

@@ -60,6 +60,15 @@ mongodb:
# and indexes, complex $lookup pipelines, etc.). When using DocumentDB you
# should also set retryWrites: "false".
flavor: "mongodb"
# TLS for MongoDB-compatible backends. When uri is set, missing TLS query
# parameters are appended automatically. AWS DocumentDB requires TLS and a
# trusted RDS CA bundle, typically stored in an existing Kubernetes Secret.
tls:
enabled: false
existingSecret: ""
caFileName: ""
mountPath: "/etc/mongodb/tls"
insecureSkipVerify: false
###################################################
# MQTT configuration (bi-directional communication)
###################################################
@@ -121,7 +130,12 @@ opentelemetry:
enabled: false
routingEnabled: false
collector:
endpoint: "http://otel-collector:4317"
# NOTE: the services use the OTLP *HTTP* exporter, so this must be the
# collector's HTTP port (4318) and must include the scheme. Use http://
# for a plaintext in-cluster collector (e.g. Jaeger) and https:// only if
# the collector terminates TLS. A scheme-less value defaults to TLS and
# fails against a plaintext collector ("server gave HTTP response to HTTPS client").
endpoint: "http://otel-collector:4318"
############################################
# OpenAI configuration (semantic search)
#
@@ -163,6 +177,23 @@ admin:
pullPolicy: IfNotPresent
tag: "v1.3.0"
replicas: 2
# Optional pod topology spread constraints for this deployment. Empty by
# default. Example:
# topologySpreadConstraints:
# - maxSkew: 1
# topologyKey: kubernetes.io/hostname
# whenUnsatisfiable: ScheduleAnyway
# labelSelector:
# matchLabels:
# app: admin
topologySpreadConstraints: []
# Optional extra volumes / volumeMounts for this deployment (empty = none).
#volumes:
# - name: extra
# emptyDir: {}
#volumeMounts:
# - name: extra
# mountPath: /data
logLevel: "info" # possible values: trace, debug, info, warn, error
resources:
requests:
@@ -175,6 +206,14 @@ admin:
secretName: admin
oauth2Proxy:
enabled: false
topologySpreadConstraints: [] # Optional pod topology spread constraints (empty = none).
# Optional extra volumes / volumeMounts for this deployment (empty = none).
#volumes:
# - name: extra
# emptyDir: {}
#volumeMounts:
# - name: extra
# mountPath: /data
github:
clientId: "github-client-id"
clientSecret: "github-client-secret"
@@ -201,8 +240,12 @@ kerberoshub:
api:
repository: ghcr.io/uug-ai/hub-api
pullPolicy: IfNotPresent
tag: "v1.9.8"
tag: "v1.9.51"
replicas: 2
topologySpreadConstraints: [] # Optional pod topology spread constraints (empty = none).
# Set to false to skip rendering the hub-api Service (e.g. when an
# external/shared Service is managed elsewhere).
serviceEnabled: true
logLevel: "info" # possible values: trace, debug, info, warn, error
jwtSecret: "this-is-a-secret-please-change-to-random-string" # change to a random value, this is for generating JWT tokens.
schema: "https"
@@ -310,8 +353,12 @@ kerberoshub:
frontend:
repository: ghcr.io/uug-ai/hub-frontend
pullPolicy: IfNotPresent
tag: "v1.9.11"
tag: "v1.13.9"
replicas: 2
topologySpreadConstraints: [] # Optional pod topology spread constraints (empty = none).
# Set to false to skip rendering the hub-frontend Service (e.g. when an
# external/shared Service is managed elsewhere).
serviceEnabled: true
logLevel: "info" # possible values: trace, debug, info, warn, error
schema: "https"
url: "yourdomain.com"
@@ -322,7 +369,9 @@ kerberoshub:
limits:
memory: 50Mi
cpu: 50m
# The front-end but in read-only mode
# The front-end but in read-only mode. Set demoEnabled to true to deploy
# the demo front-end (service, ingress and deployment).
demoEnabled: false
#demoUrl: "demo.yourdomain.com"
# When migrating to another url, this might help migrating.
#legacyUrl: "legacy.yourdomain.com"
@@ -356,17 +405,32 @@ kerberoshub:
logo: "custom"
# Custom layout: override css, favicons and translations (i18n)
# By providing a style.css file in the custom folder this file will override
# any css styling. Favicons are mounted into the favicon folder. Custom
# translation files (e.g. en.json, nl.json, ...) can be mounted into the
# i18n folder to override the built-in translations shipped in the image.
# An example translation file can be found in custom-layout/i18n/en.json.
# any css styling. Favicons are mounted into the favicon folder.
#
# Translations (i18n): for each language the served strings are
# deepMerge(assets/i18n/<lang>.json, assets/i18n-custom/<lang>.json)
# — your optional overrides layered on top of the shipped base file. To
# customise, mount a volume at assets/i18n-custom holding <lang>.json files
# with the keys you want to change. Any key you omit falls back to the shipped
# value, so keys added in future releases always render a real string (never a
# raw key) and you only maintain your diffs. Put as little or as much here as
# you like — even a complete file — but mounting at this overlay layer is
# always the safe choice, because missing keys can never leak into the UI.
# You only need files for the languages you actually customise. A partial
# example lives in custom-layout/i18n-custom/en.json; the matching complete
# files (handy to copy keys from) are published as hub-frontend release assets
# (en.json / i18n-<tag>.zip) and ship in the image at assets/i18n.
#
# (Backward compatibility: deployments that instead mount complete files over
# assets/i18n keep working, but that layer has no fallback — any key you do
# not supply shows as a raw key — so prefer assets/i18n-custom for new setups.)
#volumeMounts:
# - name: custom-layout
# mountPath: /usr/share/nginx/html/assets/custom
# - name: custom-favicon
# mountPath: /usr/share/nginx/html/assets/favicon
# - name: custom-i18n
# mountPath: /usr/share/nginx/html/assets/i18n
# mountPath: /usr/share/nginx/html/assets/i18n-custom
#volumes:
# - name: custom-layout
# persistentVolumeClaim:
@@ -398,6 +462,8 @@ kerberoshub:
features:
# General
darkModeEnabled: "true" # Enable or disable dark mode toggle 'true' or 'false'
splashScreen:
enabled: "true" # Enable or disable the pre-bootstrap splash screen 'true' or 'false'
landingPage: "/dashboard" # Landing page after login '/dashboard', '/liveview', '/media', '/devices', '/sites', '/groups'
# Internationalization (i18n): controls the runtime language behaviour
# of the front-end. When `enabled` is "false" the language switcher is
@@ -411,6 +477,17 @@ kerberoshub:
# Workflows allow you to define automated processes and actions in the front-end.
workflows:
enabled: "false" # Enable or disable workflows feature 'true' or 'false'
# Organisation controls remain visible as a read-only current organisation when switching is disabled.
organisations:
enabled: "" # Enable or disable all organisation feature flags; when empty, the child settings apply independently
switcherEnabled: "false" # Enable or disable organisation switching 'true' or 'false'
creationEnabled: "false" # Enable or disable organisation creation; requires switcherEnabled 'true' or 'false'
settingsEnabled: "false" # Enable or disable the organisation settings link 'true' or 'false'
projects:
enabled: "" # Enable or disable all project feature flags; when empty, the child settings apply independently
switcherEnabled: "false" # Enable or disable the read-only project dropdown 'true' or 'false'
creationEnabled: "false" # Reserved for project creation UI 'true' or 'false'
settingsEnabled: "false" # Reserved for project settings UI 'true' or 'false'
# Map tile configuration
map:
tileUrlLight: "https://{s}.basemaps.cartocdn.com/rastertiles/voyager/{z}/{x}/{y}{r}.png" # Map tile URL for light mode
@@ -419,6 +496,11 @@ kerberoshub:
# Live view page
liveview:
defaultStreamMode: "SD" # Default stream mode 'SD' or 'HD' (will be migrated to 'preview' or 'live')
liveStreamMode: "webrtc" # Transport backing the LIVE (HD) mode: 'webrtc' (default), 'hls' or 'moq'
hlsEnabled: "true" # Offer HLS as a selectable LIVE transport 'true' or 'false'. When 'false' the HLS option is removed from the front-end and streams use webrtc
moqEnabled: "false" # Offer MoQ as a selectable LIVE transport 'true' or 'false'
moqRelayUrl: "https://relay.uug.ai/anon" # WebTransport URL of the MoQ relay
moqBroadcastPrefix: "devices" # Prefix used to build devices/<deviceKey>/live.hang broadcast names
paginationMode: "scroll" # Pagination mode in live view 'scroll', 'numbered' or 'maxStreams'
pageSize: "6" # Max streams shown per page when paginationMode is 'numbered' (4, 8, 12, 16 or 25)
maxStreams: "-1" # Maximum number of live streams to show in live view, -1 for unlimited
@@ -482,6 +564,7 @@ kerberoshub:
# Face redaction feature
faceRedaction:
enabled: "false" # Enable or disable face redaction 'true' or 'false'
classifierTracksEnabled: "true" # Make classifier-generated tracks available in the redaction modal
# Optional integrations
mixpanel: # We can keep track logging in Mixpanel as well
apikey: "xxx"
@@ -500,6 +583,14 @@ kerberoshub:
enabled: false
oauth2Proxy:
enabled: false
topologySpreadConstraints: [] # Optional pod topology spread constraints (empty = none).
# Optional extra volumes / volumeMounts for this deployment (empty = none).
#volumes:
# - name: extra
# emptyDir: {}
#volumeMounts:
# - name: extra
# mountPath: /data
github:
clientId: "github-client-id"
clientSecret: "github-client-secret"
@@ -509,8 +600,16 @@ kerberoshub:
cleanup:
repository: ghcr.io/uug-ai/hub-cleanup
pullPolicy: IfNotPresent
tag: "v1.4.13"
tag: "v1.4.19"
replicas: 1 # Number of pods for the service.
topologySpreadConstraints: [] # Optional pod topology spread constraints (empty = none).
# Optional extra volumes / volumeMounts for this deployment (empty = none).
#volumes:
# - name: extra
# emptyDir: {}
#volumeMounts:
# - name: extra
# mountPath: /data
mode: "serve" # The mode the cleanup service operates in: serve | dry-run | version
logLevel: "info" # possible values: trace, debug, info, warn, error
maxDays: "365" # Hard maximum age (days) for global orphan cleanup.
@@ -541,11 +640,166 @@ kerberoshub:
requests:
memory: 10Mi
cpu: 10m
# hub-workflows is the standalone, queue-driven workflow engine. It consumes
# pipeline events and dispatches the stages declared in its workflow
# definitions, tracking each run in its own `workflow_runs` collection. It shares events
# (not a document) with the analysis pipeline and is meant to grow into the
# primary orchestrator. See https://github.com/uug-ai/hub-workflows.
workflows:
# Disabled by default. When enabled, the analysis service tees each
# classify result to this service (via WORKFLOWS_ENABLED on pipe-analysis)
# in parallel with the normal throttler/notification tail, which still runs
# unchanged. Flip to true to run the workflows engine.
enabled: false
# This block is purely behaviour: the master switch above plus the workflow
# definitions below. The engine's own deployment (image/tag/replicas/queue/
# resources) lives under kerberoshub.services.workflows, in the same uniform
# shape as the stage workers it dispatches to.
#
# -----------------------------------------------------------------------
# Global workflow definitions — the named workflows the engine runs.
#
# `definitions` is the engine's deployment-global configuration source and
# stage catalog: several distinct workflows can run over one recording, each
# opening its own run and dispatching only its own stages. Database-backed
# organisation workflows, when present, are read separately per recording.
# This is a MAP keyed by workflow name (names are unique and merge cleanly
# across -f / --set overrides). Ships empty; the commented block is a worked
# example of an object-tracking + loitering pipeline. Add more keys to run
# more config workflows.
#
# Each definition:
# enabled include this workflow (soft-delete toggle).
# source always rendered as "config" (a Helm-defined, ops-managed,
# deployment-global workflow — read-only in the API).
# triggers how a run OPENS. Omit for a single bare automatic trigger
# (opens for every recording); the per-stage `needs` then decide
# which stages FIRE. Narrow with device/schedule triggers, e.g.
# `- {type: automatic, devices: [{key: <device-key>}]}`.
# stages the executable stages, each {operation, dispatch?, needs?,
# needsMode?}. dispatch is "always" (default) or "conditional";
# a conditional stage's `needs` are upstream dependencies, each
# {operation?, condition?} — operation is the readiness GATE (the
# upstream op whose data must be present before the condition is
# read; omit for a check on the run root itself), condition is
# {path, op, value} where path is ABSOLUTE from the run root;
# a `*` segment fans out across array elements. needsMode combines
# multiple needs: "any" (default;
# fire on the first match) or "all" (a join; fire once every need
# has resolved and matched). The queue is taken from the matching
# services.<operation> entry, so dispatch and consume cannot drift.
#
# Every stage `operation` must have a deployed worker under
# kerberoshub.services.<operation> (deploy the objecttracking / loitering
# workers below).
definitions: {}
#tracking-workflow:
# enabled: true
# triggers:
# - type: automatic
# stages:
# - operation: objecttracking
# dispatch: always
# - operation: loitering
# dispatch: conditional
# # Fire loitering once objecttracking has resolved — a readiness join
# # (no condition ⇒ gate on the upstream's presence, not a value).
# needs:
# - operation: objecttracking
# Workflow deployments. Every workflows-subsystem Deployment's image/tag/
# replicas/resources/queue lives here in a single, uniform shape:
# - `workflows` is the engine itself (the orchestrator). It is deployed
# whenever kerberoshub.workflows.enabled is true and has no `enabled` of
# its own — the master switch already gates the whole subsystem.
# - every other entry is a stage worker the engine dispatches to. A worker
# consumes its own queue and routes its result back to the engine queue.
# Deploying a worker (services.<name>.enabled) is independent from routing
# to it (a workflows.definitions stage of the same operation) — it runs only
# when its own `enabled` is true AND the workflows engine is enabled.
services:
# hub-workflows — the workflows engine (orchestrator). Consumes the engine
# queue, evaluates the boot-loaded config workflows (WORKFLOW_DEFINITIONS)
# plus organisation-scoped database workflows, and dispatches to the stage
# workers below. Deployed when workflows.enabled is true; it has no separate
# `enabled` here.
workflows:
repository: ghcr.io/uug-ai/hub-workflows
pullPolicy: IfNotPresent
tag: "v1.0.0"
replicas: 1 # Number of pods for the service.
topologySpreadConstraints: [] # Optional pod topology spread constraints (empty = none).
# Optional extra volumes / volumeMounts for this deployment (empty = none).
#volumes:
# - name: extra
# emptyDir: {}
#volumeMounts:
# - name: extra
# mountPath: /data
logLevel: "info" # possible values: trace, debug, info, warn, error
# Queue this service consumes ingest events and upstream results from
# (WORKFLOWS_QUEUE). Must be fed the same messages the analysis service sees.
queue: "hub-workflows-queue"
resources:
requests:
memory: 10Mi
cpu: 10m
# ---------------------------------------------------------------------
# EXAMPLE custom stage worker (commented out) — hub-loitering.
#
# Companion deployment for the workflows.definitions example above (the
# loitering stage of tracking-workflow). Uncomment to deploy the demo
# worker. It ships as its own repository/module.
# See https://github.com/uug-ai/hub-loitering.
#loitering:
# # Deploy the hub-loitering worker.
# enabled: true
# repository: ghcr.io/uug-ai/hub-loitering
# pullPolicy: IfNotPresent
# tag: "v1.0.0"
# replicas: 1 # Number of pods for the worker.
# topologySpreadConstraints: [] # Optional pod topology spread constraints (empty = none).
# #volumes:
# # - name: extra
# # emptyDir: {}
# #volumeMounts:
# # - name: extra
# # mountPath: /data
# logLevel: "info" # possible values: trace, debug, info, warn, error
# # Queue this worker consumes dispatched messages from (LOITERING_QUEUE). This
# # same value is taken into the matching workflows.definitions stage, so the
# # engine dispatches and the worker consumes the same queue with no drift.
# # Convention: "kcloud-<operation>-queue.fifo".
# queue: "kcloud-loitering-queue.fifo"
# resources:
# requests:
# memory: 10Mi
# cpu: 10m
# ---------------------------------------------------------------------
# EXAMPLE stage worker (commented out) for the workflows.definitions example
# above — hub-objecttracking. Uncomment the worker whose operation a
# definition references, so the engine dispatches and the worker consumes the
# same queue with no drift.
#objecttracking:
# # Deploy the object-tracking worker (operation "objecttracking").
# enabled: true
# repository: ghcr.io/uug-ai/hub-objecttracking
# pullPolicy: IfNotPresent
# tag: "v1.0.0"
# replicas: 1 # Number of pods for the worker.
# topologySpreadConstraints: [] # Optional pod topology spread constraints (empty = none).
# logLevel: "info" # possible values: trace, debug, info, warn, error
# # Queue this worker consumes dispatched messages from (OBJECTTRACKING_QUEUE).
# queue: "kcloud-objecttracking-queue.fifo"
# resources:
# requests:
# memory: 10Mi
# cpu: 10m
monitordevice:
repository: ghcr.io/uug-ai/hub-monitor-device
pullPolicy: IfNotPresent
tag: "v1.4.0"
tag: "v1.4.2"
replicas: 1 # Number of pods for the service.
topologySpreadConstraints: [] # Optional pod topology spread constraints (empty = none).
logLevel: "info" # possible values: trace, debug, info, warn, error
resources:
requests:
@@ -563,7 +817,15 @@ kerberoshub:
repository: uugai/hub-reactivatesubscriptions
pullPolicy: IfNotPresent
tag: "v1.0.2"
replicas: 1 # Number of pods for the service.
replicas: 0 # Number of pods for the service. Set to 0 to disable.
topologySpreadConstraints: [] # Optional pod topology spread constraints (empty = none).
# Optional extra volumes / volumeMounts for this deployment (empty = none).
#volumes:
# - name: extra
# emptyDir: {}
#volumeMounts:
# - name: extra
# mountPath: /data
logLevel: "info" # possible values: trace, debug, info, warn, error
resources:
requests:
@@ -571,6 +833,14 @@ kerberoshub:
cpu: 10m
forwarder:
enabled: false
topologySpreadConstraints: [] # Optional pod topology spread constraints (empty = none).
# Optional extra volumes / volumeMounts for this deployment (empty = none).
#volumes:
# - name: extra
# emptyDir: {}
#volumeMounts:
# - name: extra
# mountPath: /data
#repository: kerberos/vault-forwarder
#pullPolicy: IfNotPresent
#tag: "1.0.2732389692"
@@ -583,7 +853,15 @@ kerberoshub:
repository: uugai/hub-proxy
pullPolicy: IfNotPresent
tag: "v1.0.0"
replicas: 1 # Number of pods for the service.
replicas: 0 # Number of pods for the service. Set to 0 to disable.
topologySpreadConstraints: [] # Optional pod topology spread constraints (empty = none).
# Optional extra volumes / volumeMounts for this deployment (empty = none).
#volumes:
# - name: extra
# emptyDir: {}
#volumeMounts:
# - name: extra
# mountPath: /data
logLevel: "info" # possible values: trace, debug, info, warn, error
resources:
requests:
@@ -597,8 +875,16 @@ kerberospipeline:
event:
repository: ghcr.io/uug-ai/hub-pipeline-event
pullPolicy: IfNotPresent
tag: "v1.3.0"
tag: "v1.3.1"
replicas: 1 # Number of pods for the service.
topologySpreadConstraints: [] # Optional pod topology spread constraints (empty = none).
# Optional extra volumes / volumeMounts for this deployment (empty = none).
#volumes:
# - name: extra
# emptyDir: {}
#volumeMounts:
# - name: extra
# mountPath: /data
logLevel: "info" # possible values: trace, debug, info, warn, error
resources:
requests:
@@ -607,8 +893,16 @@ kerberospipeline:
monitor:
repository: ghcr.io/uug-ai/hub-pipeline-monitor
pullPolicy: IfNotPresent
tag: "v1.3.9"
tag: "v1.3.13"
replicas: 1 # Number of pods for the service.
topologySpreadConstraints: [] # Optional pod topology spread constraints (empty = none).
# Optional extra volumes / volumeMounts for this deployment (empty = none).
#volumes:
# - name: extra
# emptyDir: {}
#volumeMounts:
# - name: extra
# mountPath: /data
resources:
requests:
memory: 10Mi
@@ -616,8 +910,16 @@ kerberospipeline:
sequence:
repository: ghcr.io/uug-ai/hub-pipeline-sequence
pullPolicy: IfNotPresent
tag: "v1.6.18"
tag: "v1.6.26"
replicas: 1 # Number of pods for the service.
topologySpreadConstraints: [] # Optional pod topology spread constraints (empty = none).
# Optional extra volumes / volumeMounts for this deployment (empty = none).
#volumes:
# - name: extra
# emptyDir: {}
#volumeMounts:
# - name: extra
# mountPath: /data
resources:
requests:
memory: 10Mi
@@ -625,8 +927,16 @@ kerberospipeline:
throttler:
repository: uugai/hub-pipeline-throttler
pullPolicy: IfNotPresent
tag: "v1.2.0"
tag: "v1.2.1"
replicas: 1 # Number of pods for the service.
topologySpreadConstraints: [] # Optional pod topology spread constraints (empty = none).
# Optional extra volumes / volumeMounts for this deployment (empty = none).
#volumes:
# - name: extra
# emptyDir: {}
#volumeMounts:
# - name: extra
# mountPath: /data
logLevel: "info" # possible values: trace, debug, info, warn, error
resources:
requests:
@@ -635,8 +945,9 @@ kerberospipeline:
notify:
repository: ghcr.io/uug-ai/hub-pipeline-notification
pullPolicy: IfNotPresent
tag: "v1.3.9"
tag: "v1.3.18"
replicas: 1 # Number of pods for the service.
topologySpreadConstraints: [] # Optional pod topology spread constraints (empty = none).
logLevel: "info" # possible values: trace, debug, info, warn, error
resources:
requests:
@@ -653,8 +964,9 @@ kerberospipeline:
notifyTest:
repository: uugai/hub-pipeline-notification-test
pullPolicy: IfNotPresent
tag: "v1.2.1"
tag: "v1.2.2"
replicas: 1 # Number of pods for the service.
topologySpreadConstraints: [] # Optional pod topology spread constraints (empty = none).
resources:
requests:
memory: 10Mi
@@ -670,8 +982,16 @@ kerberospipeline:
analysis:
repository: ghcr.io/uug-ai/hub-pipeline-analysis
pullPolicy: IfNotPresent
tag: "v1.7.8"
tag: "v1.8.5"
replicas: 1 # Number of pods for the service.
topologySpreadConstraints: [] # Optional pod topology spread constraints (empty = none).
# Optional extra volumes / volumeMounts for this deployment (empty = none).
#volumes:
# - name: extra
# emptyDir: {}
#volumeMounts:
# - name: extra
# mountPath: /data
logLevel: "info" # possible values: trace, debug, info, warn, error
resources:
requests:
@@ -680,8 +1000,16 @@ kerberospipeline:
dominantColor:
repository: ghcr.io/uug-ai/hub-pipeline-dominantcolors
pullPolicy: IfNotPresent
tag: "v2.0.2"
tag: "v2.0.3"
replicas: 3 # Number of pods for the service.
topologySpreadConstraints: [] # Optional pod topology spread constraints (empty = none).
# Optional extra volumes / volumeMounts for this deployment (empty = none).
#volumes:
# - name: extra
# emptyDir: {}
#volumeMounts:
# - name: extra
# mountPath: /data
logLevel: "info" # possible values: trace, debug, info, warn,
resources:
requests:
@@ -693,8 +1021,16 @@ kerberospipeline:
thumbnail:
repository: ghcr.io/uug-ai/hub-pipeline-thumbnail
pullPolicy: IfNotPresent
tag: "v1.3.4"
tag: "v1.3.10"
replicas: 2 # Number of pods for the service.
topologySpreadConstraints: [] # Optional pod topology spread constraints (empty = none).
# Optional extra volumes / volumeMounts for this deployment (empty = none).
#volumes:
# - name: extra
# emptyDir: {}
#volumeMounts:
# - name: extra
# mountPath: /data
logLevel: "info" # possible values: trace, debug, info, warn, error
quality: "1" # 1 (best) - 31 (worst)
width: "600"
@@ -711,8 +1047,16 @@ kerberospipeline:
counting:
repository: uugai/hub-pipeline-counting
pullPolicy: IfNotPresent
tag: "v1.6.3"
tag: "v2.0.0"
replicas: 1 # Number of pods for the service.
topologySpreadConstraints: [] # Optional pod topology spread constraints (empty = none).
# Optional extra volumes / volumeMounts for this deployment (empty = none).
#volumes:
# - name: extra
# emptyDir: {}
#volumeMounts:
# - name: extra
# mountPath: /data
logLevel: "info" # possible values: trace, debug, info, warn,
resources:
requests:
@@ -722,8 +1066,16 @@ kerberospipeline:
enabled: false # Enable or disable the sprite generation 'true' or 'false
repository: ghcr.io/uug-ai/hub-pipeline-sprite
pullPolicy: IfNotPresent
tag: "v1.1.12"
tag: "v1.1.16"
replicas: 5 # Number of pods for the service.
topologySpreadConstraints: [] # Optional pod topology spread constraints (empty = none).
# Optional extra volumes / volumeMounts for this deployment (empty = none).
#volumes:
# - name: extra
# emptyDir: {}
#volumeMounts:
# - name: extra
# mountPath: /data
logLevel: "info" # possible values: trace, debug, info, warn,
interval: "1" # Number of secondes between each thumbnail in the sprite
width: "240" # Should not be changed for the moment (hard coded in UI)
@@ -738,8 +1090,9 @@ kerberospipeline:
export:
repository: ghcr.io/uug-ai/hub-pipeline-export
pullPolicy: IfNotPresent
tag: "v1.2.4"
tag: "v1.2.10"
replicas: 2 # Number of pods for the service.
topologySpreadConstraints: [] # Optional pod topology spread constraints (empty = none).
logLevel: "info" # possible values: trace, debug, info, warn, error
# playerAssetsPath: "/custom/player-assets/" # Path to custom player.html template (overrides the embedded default)
# volumeMounts:
@@ -753,19 +1106,6 @@ kerberospipeline:
requests:
memory: 10Mi
cpu: 10m
redaction:
repository: ghcr.io/uug-ai/hub-pipeline-redaction
pullPolicy: IfNotPresent
tag: "v1.0.0"
replicas: 2 # Number of pods for the service.
logLevel: "info" # possible values: trace, debug, info, warn, error
resources:
requests:
memory: 512Mi
cpu: 500m
limits:
memory: 2Gi
cpu: 1000m
###########################################################################
# Email configuration
#
@@ -793,10 +1133,14 @@ email:
forgotTitle: "Password reset Kerberos Hub. You forgot your password"
share: "share"
shareTitle: "[Action] You received a recording from Kerberos Hub"
caseShare: "share_case"
caseShareTitle: "[Action] A case has been shared with you on Kerberos Hub"
caseShareOtp: "share_case_otp"
caseShareOtpTitle: "Your Kerberos Hub verification code"
assignTask: "assign_task"
assignTaskTitle: "[Action] You've been assigned to a task"
detection: "detection"
disabled: "disabled"
disabled: "disable"
highupload: "highupload"
device: "device"
alertTitle: "[Alert] Kerberos Hub detected something an event"

View File

@@ -0,0 +1,97 @@
#!/usr/bin/env bash
#
# Render the hub chart and assert that every deployment which carries the
# workflows hand-off queue (the WORKFLOWS_QUEUE env var) resolves to the SAME,
# non-empty value.
#
# Why: the analysis pipeline (pipe-analysis) publishes opened workflow runs to
# WORKFLOWS_QUEUE, the workflows engine (hub-workflows) consumes it, and every
# stage worker (hub-stage) routes its result back to it. All three templates
# read the single key `kerberoshub.services.workflows.queue`. If a future edit
# hardcodes a value, reads the wrong key, or drops the env on one of them, the
# producer and consumer silently drift onto different queue names and messages
# pile up with no consumer. This check fails the build before that can ship.
#
# Usage: scripts/check-workflows-queue-consistency.sh [chart-dir]
# (chart-dir defaults to charts/hub, relative to the repo root)
set -euo pipefail
CHART_DIR="${1:-charts/hub}"
PROBE="drift-probe-queue-name"
# Flags that force all three deployment kinds (analysis, engine and one stage
# worker) to render, so the check actually has something to compare. The chart
# ships NO enabled stage worker by default (custom stages are values-only and
# opt-in), so we synthesise a throwaway stage purely to exercise the generic
# hub-stage path. The name is a neutral fixture ("queuecheck") on purpose: any
# arbitrary stage key must render the same way, so the check must not depend on
# a specific bundled worker.
STAGE="queuecheck"
RENDER_FLAGS=(
--set mode=all
--set kerberoshub.workflows.enabled=true
--set "kerberoshub.workflows.stages.${STAGE}.enabled=true"
--set "kerberoshub.services.${STAGE}.enabled=true"
--set "kerberoshub.services.${STAGE}.repository=example.invalid/queuecheck"
--set "kerberoshub.services.${STAGE}.tag=test"
--set "kerberoshub.services.${STAGE}.queue=queuecheck-fixture-queue"
)
# Read `helm template` output on stdin and print one WORKFLOWS_QUEUE value per
# line. Matches the `- name: WORKFLOWS_QUEUE` env entry and captures the value
# from the following `value:` line, skipping blank/comment lines in between.
extract_workflows_queue() {
awk '
/^[[:space:]]*-[[:space:]]*name:[[:space:]]*WORKFLOWS_QUEUE[[:space:]]*$/ { want=1; next }
want==1 {
if ($0 ~ /^[[:space:]]*#/ || $0 ~ /^[[:space:]]*$/) next
v=$0
sub(/^[[:space:]]*value:[[:space:]]*/, "", v)
sub(/^"/, "", v); sub(/"[[:space:]]*$/, "", v)
sub(/[[:space:]]+$/, "", v)
print v
want=0
}
'
}
assert_all_equal() {
local expected="$1"; shift
local label="$1"; shift
local -a vals=("$@")
if [ "${#vals[@]}" -lt 2 ]; then
echo "FAIL (${label}): expected at least 2 WORKFLOWS_QUEUE values (analysis + engine), found ${#vals[@]}" >&2
return 1
fi
local v
for v in "${vals[@]}"; do
if [ -z "${v}" ]; then
echo "FAIL (${label}): a deployment rendered an empty WORKFLOWS_QUEUE value" >&2
return 1
fi
if [ "${v}" != "${expected}" ]; then
echo "FAIL (${label}): WORKFLOWS_QUEUE drift detected — expected '${expected}' but a deployment rendered '${v}'" >&2
printf ' rendered values: %s\n' "${vals[*]}" >&2
return 1
fi
done
echo "OK (${label}): ${#vals[@]} deployments all use WORKFLOWS_QUEUE='${expected}'"
}
echo "== Rendering ${CHART_DIR} with the chart's default workflows queue =="
default_out="$(helm template hub "${CHART_DIR}" "${RENDER_FLAGS[@]}")"
mapfile -t default_vals < <(printf '%s\n' "${default_out}" | extract_workflows_queue)
default_queue="${default_vals[0]:-}"
assert_all_equal "${default_queue}" "default values" "${default_vals[@]}" || exit 1
echo "== Rendering ${CHART_DIR} with an overridden workflows queue (-> ${PROBE}) =="
probe_out="$(helm template hub "${CHART_DIR}" "${RENDER_FLAGS[@]}" \
--set kerberoshub.services.workflows.queue="${PROBE}")"
mapfile -t probe_vals < <(printf '%s\n' "${probe_out}" | extract_workflows_queue)
assert_all_equal "${PROBE}" "override probe" "${probe_vals[@]}" || exit 1
echo "All WORKFLOWS_QUEUE consistency checks passed."