Compare commits

...

366 Commits

Author SHA1 Message Date
Cédric Verstraeten
f834d9b8f5 Merge pull request #143 from kerberos-io/public-release-1786904956
A new public release - 1786904956
2026-08-21 17:36:29 +02:00
Kilian
eefe96c679 Merge pull request #147 from kerberos-io/detection-source-flags
detection source flags
2026-08-21 17:32:59 +02:00
Kilian
93888e2855 Merge pull request #144 from kerberos-io/feature/add-org-feature-flags
add-org-feature-flags
2026-08-21 17:29:48 +02:00
Kilian Boute
759ac8dbf8 detection source flags 2026-08-21 17:28:25 +02:00
Cédric Verstraeten
4aaa70f121 Merge pull request #146 from kerberos-io/fix/cors-origin
fix/cors-origin
2026-08-20 22:10:48 +02:00
Cédric Verstraeten
ad7ef4ac12 Add frontend URL to Hub API CORS
Initialize CORS origins with the primary frontend URL while retaining support for the legacy frontend URL. Bump the Hub chart to 0.130.0.
2026-08-20 22:09:19 +02:00
Cédric Verstraeten
5ad56f9730 Merge pull request #145 from kerberos-io/feature/add-refresh-tokens-config
feature/add-refresh-tokens-config
2026-08-20 21:44:32 +02:00
Cédric Verstraeten
91eb64a2f3 Update Chart.yaml 2026-08-20 21:35:04 +02:00
Cédric Verstraeten
55ae6cdd3e Add dynamic CORS origins and secure refresh cookie
Update the hub API Helm template to set `REFRESH_COOKIE_SECURE` automatically when the API schema is HTTPS, and generate `CORS_ALLOWED_ORIGINS` from configured frontend URLs (legacy URL, domain list, tenant wildcard domain, and demo URL). This keeps cookie behavior and CORS config aligned with deployment settings.
2026-08-20 21:33:32 +02:00
Kilian Boute
f492c14336 add flags 2026-08-20 18:01:19 +02:00
uug4ai
d4a13a4cff A new public release - 1786904956 2026-08-16 18:29:18 +00:00
Kilian
98cc8d4f2d Merge pull request #142 from kerberos-io/docs/workflow-source-alignment
docs(workflows): clarify config and database sources
2026-08-13 12:48:11 +02:00
Kilian Boute
a5125eee69 docs(workflows): clarify definition sources 2026-08-13 10:23:21 +00:00
Cédric Verstraeten
b2ff3e2e20 Merge pull request #141 from kerberos-io/fix/allow-replicas-proxy-default-to-zero
fix/allow-replicas-proxy-default-to-zero
2026-08-11 22:01:40 +02:00
Cédric Verstraeten
277ddde3b4 Disable proxy and reactivation services by default
Default replicas for the hub proxy and reactivation subscriptions services are now set to 0, allowing them to be disabled unless explicitly enabled. This updates the chart metadata and docs to reflect the new default behavior.
2026-08-11 21:51:37 +02:00
Cédric Verstraeten
7878be79d6 Merge pull request #140 from kerberos-io/feature/add-mongodb-tls-support
feature/add-mongodb-tls-support
2026-08-11 14:14:35 +02:00
Cédric Verstraeten
123bde292e Merge pull request #136 from kerberos-io/public-release-1786356403
A new public release - 1786356403
2026-08-11 14:09:02 +02:00
Cédric Verstraeten
e76311872e feat(hub): update chart version to 0.127.0 and add MongoDB TLS configuration options 2026-08-11 12:06:27 +00:00
Cédric Verstraeten
0f2176822a feat(hub): add TLS support for MongoDB configuration 2026-08-11 12:05:43 +00:00
Kilian
8ca4c402f8 Merge pull request #139 from kerberos-io/feat/organisation-feature-flags
chore(hub): bump chart version to 0.126.2
2026-08-10 12:36:29 +02:00
Kilian
8d9b943100 chore(hub): bump chart version to 0.126.2 2026-08-10 10:34:08 +00:00
Kilian
3e10489251 Merge pull request #137 from kerberos-io/feat/organisation-feature-flags
Add organisation frontend feature flags
2026-08-10 12:26:01 +02:00
Kilian
a7fd8d394f feat(hub): add organisation frontend flags
Expose disabled-by-default Helm values for organisation switching and creation, and map them to the Hub frontend runtime environment.
2026-08-10 10:17:59 +00:00
uug4ai
c29647ec62 A new public release - 1786356403 2026-08-10 10:06:45 +00:00
Cédric Verstraeten
685b92e9cc Merge pull request #135 from kerberos-io/feature/add-mock-support
feature/add-mock-support
2026-08-05 22:42:36 +02:00
Cédric Verstraeten
01d1e6866a Bump chart version to 0.126.1 and add MoQ support in live view configuration 2026-08-05 20:31:28 +00:00
Kilian
8cf73bcf1d Merge pull request #134 from kerberos-io/KilianBoute-patch-2
Bump chart version to 0.126.0
2026-08-05 18:07:10 +02:00
Kilian
57f6ab6f3b Bump chart version to 0.126.0 2026-08-05 18:06:58 +02:00
Kilian
2ed7829391 Merge pull request #133 from kerberos-io/feat/workflow-stage-queue-catalog
workflow-stage-queue-catalog?
2026-08-05 17:50:44 +02:00
Kilian Boute
0c9726f21b changer 2026-08-05 17:50:18 +02:00
Kilian
9ae2e1fc86 Merge pull request #131 from kerberos-io/feat/workflow-stage-queue-catalog
Expose workflow stage queues to Hub API
2026-08-05 13:03:48 +02:00
Kilian Boute
f3a9886053 feat: expose workflow stage queues to API 2026-08-03 13:59:09 +00:00
Cédric Verstraeten
933fedc080 Merge pull request #130 from kerberos-io/feature/splash-screen-feature-flag
feature/splash-screen-feature-flag
2026-07-31 15:35:02 +02:00
Cédric Verstraeten
2c7f6a89a3 Bump chart version to 0.124.0 2026-07-31 13:28:55 +00:00
Cédric Verstraeten
5af0ffab6c Add splash screen feature flag to frontend configuration 2026-07-31 13:18:06 +00:00
Kilian
0a3cf69c80 Merge pull request #129 from kerberos-io/chore/remove-private-redaction-service
chore(hub): remove private redaction service from public chart
2026-07-31 15:09:19 +02:00
Kilian Boute
b8499c97e2 chore(hub): remove private redaction service from public chart
hub-pipeline-redaction is a private, client-specific worker. Remove its Deployment/Service template and the kerberospipeline.redaction values block (plus the generated README rows) from the public chart. Deployment is now documented in the private hub-pipeline-redaction repo.
2026-07-29 14:12:13 +00:00
Cédric Verstraeten
641dc7510c Merge pull request #128 from kerberos-io/fix/hide-frontend-categories
fix/hide-frontend-categories
2026-07-16 11:29:21 +02:00
Cédric Verstraeten
20f4fa24ba Bump chart version to 0.123.1 2026-07-16 09:24:21 +00:00
Cédric Verstraeten
b793014f89 Rename media filter category feature environment variable to plural form 2026-07-16 09:23:46 +00:00
Kilian
348bab8f2b Merge pull request #127 from kerberos-io/KilianBoute-patch-2
Bump chart version to 0.123.0
2026-07-10 19:22:23 +02:00
Kilian
8a71bd2a05 Bump chart version to 0.123.0 2026-07-10 19:22:05 +02:00
Kilian
611ddec1f1 Merge pull request #126 from kerberos-io/KilianBoute-patch-2
Bump chart version to 0.122.0
2026-07-10 19:20:23 +02:00
Kilian
34a285666e Bump chart version to 0.122.0 2026-07-10 19:20:09 +02:00
Kilian
59cf74ba66 Merge pull request #125 from kerberos-io/feat/hub-i18n-run-workflow-redact
feat(i18n): add Run workflow and Redact faces case UI strings
2026-07-10 19:10:52 +02:00
Kilian Boute
020f2d969d feat(i18n): add Run workflow and Redact faces case UI strings
Adds the en.json translations for the case Run-workflow dialog
(title/subtitle/labels/empty/submit and the runWorkflow menu item)
and the Redact faces attachment action (k14).
2026-07-10 17:10:14 +00:00
Kilian
eeb29e8cac Merge pull request #124 from kerberos-io/feat/hub-api-workflow-definitions-env
feat(hub-api): inject WORKFLOW_DEFINITIONS env so config workflows surface in the API
2026-07-10 19:09:13 +02:00
Kilian Boute
1ec2be4cc7 feat(hub-api): inject WORKFLOW_DEFINITIONS env so config workflows surface in the API
hub-api reads WORKFLOW_DEFINITIONS (the same enabled definition set the
workflows engine consumes, assembled via kerberoshub.workflows.workflowDefinitions)
read-only to surface config workflows alongside DB/user workflows. Previously
only the engine received this env, so hub-api returned an empty config-workflow
list and manual/on-demand config workflows never appeared in GET /workflows.
2026-07-10 17:06:41 +00:00
Kilian
b9166ea1ed Merge pull request #123 from kerberos-io/fix/hub-stage-service-separator
fix(hub-stage): render valid YAML when multiple stage workers are enabled
2026-07-08 15:05:56 +02:00
Kilian Boute
be2290075c fix(hub-stage): add newline before doc separator so multiple stage workers render valid YAML
The generic stage-worker loop in templates/kerberos-pipeline/hub-stage.yaml
closed each iteration with `{{- end }}`, whose left-trim stripped the newline
after the Service's final line (`app: hub-<name>`). With a single enabled stage
worker this was latent, but with two or more the next worker's `---` separator
was glued onto the previous Service's last line (e.g. `app: hub-loitering---`),
merging two resources into one malformed document.

In production this surfaced as ArgoCD "one or more synchronization tasks are not
valid" once objecttracking was enabled alongside anpr and loitering (3 stage
workers -> 2 glued boundaries: anpr->loitering and loitering->objecttracking).

Fix: emit a trailing newline before the next document separator by using
`{{ end -}}` for the per-service if-close. Rendering the hub chart with the
production values now yields 58 valid documents (previously 56, of which 2 were
Service+Deployment glued together) and 0 malformed separators. Bump chart to
0.121.1 so the fix can be published to charts.kerberos.io.
2026-07-08 12:59:28 +00:00
Kilian
cb47ad3f12 Merge pull request #122 from kerberos-io/feat/workflow-definitions-rendering
feat(hub): render WORKFLOW_DEFINITIONS for the workflows engine
2026-07-07 15:09:54 +02:00
Kilian Boute
42bd87d16d feat(hub): render WORKFLOW_DEFINITIONS for the workflows engine
Replace the flat PIPELINE_STAGE_REGISTRY with per-workflow
WORKFLOW_DEFINITIONS, matching hub-workflows' definitions engine:

- _workflows-helpers.tpl: stageRegistry -> workflowDefinitions. Emits a
  JSON array of named workflow objects (name, enabled, source=config,
  triggers defaulting to a bare automatic trigger, and the executable
  stages), one per enabled kerberoshub.workflows.definitions entry. Each
  stage's queue is still taken from the matching services.<operation> so
  dispatch and consume cannot drift.
- hub-workflows.yaml: set WORKFLOW_DEFINITIONS instead of
  PIPELINE_STAGE_REGISTRY.
- hub-stage.yaml: render a worker for every enabled services.<name> other
  than the engine itself (decoupled from routing), and pass through any
  services.<name>.env as container env for per-worker tuning.
- values.yaml: workflows.stages -> workflows.definitions (map keyed by
  workflow name) with an object-tracking + loitering worked example and
  updated docs.

Chart 0.120.0 -> 0.121.0. helm lint + template validated.
2026-07-07 13:05:20 +00:00
Kilian
0ed38add2e Merge pull request #121 from kerberos-io/feat/hls-live-transport-toggle
feat(hub): add hlsEnabled toggle; replace anpr example with loitering
2026-06-25 18:43:14 +02:00
Kilian
c8c070d51e chore(hub): bump chart version to 0.120.0 2026-06-25 16:36:52 +00:00
Kilian
0e21755bb8 feat(hub): add hlsEnabled toggle; replace anpr example with loitering
- Add kerberoshub.frontend.features.liveview.hlsEnabled (default true) and
  wire it as FEATURE_HLS_ENABLED on hub-frontend and hub-frontend-demo. When
  'false' the front-end removes the HLS live-transport option.
- Replace the bundled anpr example stage/worker with a commented-out
  hub-loitering example; the chart now ships no enabled custom stage by
  default (stages are values-only, opt-in).
- Update the generic hub-stage comment to the loitering example.
- Make the queue-consistency check self-contained: it synthesises a neutral
  throwaway stage ('queuecheck') via --set instead of relying on a bundled
  example worker.

NOTE: Chart.yaml version intentionally not bumped — repo version/tag state is
already inconsistent (Chart.yaml 0.117.0 vs tags up to hub-0.119.0); pick the
next version at release time.
2026-06-25 16:33:16 +00:00
Kilian
8781ede494 Merge pull request #120 from kerberos-io/fix/disable-email-template-value
fix(hub): align disabled email template value with module name
2026-06-24 13:42:24 +02:00
Kilian Boute
82e3da78dd fix(hub): align disabled email template value with module name
The notification module's GetTemplate only recognizes the template name "disable" (disable.go / disable template file), but email.templates.disabled was set to "disabled". A consumer passing DISABLED_TEMPLATE to GetTemplate would get an empty body. Set the value to "disable" so it resolves correctly.
2026-06-24 11:24:34 +00:00
Kilian
30bbd97b6d Merge pull request #119 from kerberos-io/feat/case-share-email-template
feat(hub): add case-share email template + env wiring
2026-06-24 11:02:21 +02:00
Kilian
b78a2246ee Apply suggestions from code review
Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
2026-06-24 10:09:06 +02:00
Kilian Boute
33b41cee0e otp share template 2026-06-23 17:13:18 +02:00
Kilian Boute
3a464eeb8e feat(hub): add case-share email template + env wiring
Adds CASE_SHARE_TEMPLATE/CASE_SHARE_TITLE env on hub-api (driven by
email.templates.caseShare/caseShareTitle), the matching values defaults, and
the share_case custom-layout template (html/txt) so the case-share invitation
renders with its dedicated white-label template.
2026-06-23 13:46:54 +00:00
Kilian
d599befeaf Merge pull request #118 from kerberos-io/fix/otel-gating-and-workflows-queue
Gate OTel env vars behind opentelemetry.enabled and align workflows queue name
2026-06-19 13:00:21 +02:00
Kilian Boute
9ea9016bfa Gate OTel env vars behind opentelemetry.enabled and align workflows queue name
- Wrap OpenTelemetry tracing env vars in '{{- if .Values.opentelemetry.enabled }}' across hub-api and all pipeline templates so disabled tracing injects no OTEL_* vars.

- Fix the OTLP collector endpoint default to the HTTP port (http://otel-collector:4318); the services use the OTLP HTTP exporter, and a scheme-less/4317 value defaults to TLS and fails against a plaintext collector.

- Rename the workflows queue from 'kcloud-workflows-queue' to 'hub-workflows-queue' and pass WORKFLOWS_QUEUE to the analysis pipeline so analysis and the workflows engine always agree on the queue name.
2026-06-18 15:50:59 +00:00
Kilian
895c190e20 Merge pull request #117 from kerberos-io/workflows->-remove-kind
Remove 'kind' attribute from workflows and update related comments fo…
2026-06-17 12:22:51 +02:00
Kilian Boute
f4051f7e6a Remove 'kind' attribute from workflows and update related comments for clarity 2026-06-17 10:07:25 +00:00
Cédric Verstraeten
807369ef01 Merge pull request #116 from kerberos-io/feature/live-view-mode
feature/live-view-mode
2026-06-17 11:56:33 +02:00
Cédric Verstraeten
19cf677a56 Bump hub chart version to 0.117.0
Increment charts/hub Chart.yaml version from 0.116.0 to 0.117.0 to reflect an updated chart release. This follows semantic versioning for chart/template changes.
2026-06-16 17:46:58 +02:00
Cédric Verstraeten
7b39949e5b Add live stream mode env and default value
Expose FEATURE_LIVE_STREAM_MODE environment variable in both hub-frontend and hub-frontend-demo templates, sourcing from .Values.kerberoshub.frontend.features.liveview.liveStreamMode. Add a new liveStreamMode default in charts/hub/values.yaml ("webrtc") to control the transport for LIVE (HD) mode (options: "webrtc" (default) or "hls"). This enables configuring live stream transport without modifying templates.
2026-06-16 17:09:54 +02:00
Kilian
3752c0396e Merge pull request #115 from kerberos-io/default-i18n-en.json-file
Add default i18n en.json file
2026-06-16 09:57:38 +02:00
Kilian
0d55fa5d2f Add default i18n en.json file 2026-06-16 09:49:33 +02:00
Cédric Verstraeten
2949db0a03 Merge pull request #114 from kerberos-io/public-release-1781595581
A new public release - 1781595581
2026-06-16 09:48:31 +02:00
uug4ai
662a2c6a67 A new public release - 1781595581 2026-06-16 07:39:43 +00:00
Cédric Verstraeten
7cf273911e Merge pull request #113 from kerberos-io/KilianBoute-patch-2
Bump chart version to 0.116.0
2026-06-16 09:39:40 +02:00
Kilian
20f1de461d Bump chart version to 0.116.0 2026-06-15 21:26:40 +02:00
Kilian
a237f7b4d6 Merge pull request #112 from kerberos-io/KilianBoute-patch-2
Bump chart version from 0.113.0 to 0.115.0
2026-06-15 18:29:07 +02:00
Kilian
fae8b028ad Bump chart version from 0.113.0 to 0.115.0 2026-06-15 18:28:54 +02:00
Kilian
31ec7cb6af Merge pull request #111 from kerberos-io/translation-overriding
Translation override support
2026-06-15 18:26:36 +02:00
Kilian Boute
424053f2ce add translation file override support 2026-06-15 13:39:23 +00:00
Kilian Boute
7c17a99240 add translation file override support 2026-06-15 13:39:10 +00:00
Kilian
dafba78c94 Merge pull request #110 from kerberos-io/Workflows->-standalone-setup
Refactor workflows configuration to use services structure in hub-sta…
2026-06-12 16:58:48 +02:00
Kilian Boute
dc48269807 Refactor workflows configuration to use services structure in hub-stage and hub-workflows templates; update values.yaml for consistency 2026-06-12 14:50:38 +00:00
Kilian
eff71c4e24 Merge pull request #109 from kerberos-io/Workflows->-standalone-setup
Workflows > standalone setup
2026-06-12 15:17:20 +02:00
Kilian Boute
642676fcf7 Remove deprecated pipe-anpr and pipe-workflows templates; add generic hub-stage and hub-workflows templates for improved workflow management 2026-06-12 11:51:28 +00:00
Kilian Boute
25bb6d5fdc Enhance workflow stage configuration with needsMode and kind attributes in helpers and values.yaml 2026-06-11 15:34:59 +00:00
Kilian Boute
20b92ffddd Update comments for workflows integration in pipe-analysis and values.yaml 2026-06-09 15:00:02 +00:00
Kilian Boute
bb4cc53d90 Add workflows support to pipe-analysis and create pipe-workflows template 2026-06-08 16:20:38 +00:00
Kilian Boute
7b920c3f0e Add hub-workflows configuration to values.yaml 2026-06-08 12:26:15 +00:00
Cédric Verstraeten
52757a66ae Merge pull request #108 from kerberos-io/feature/optional-disable-frontend-demo
feature/optional-disable-frontend-demo
2026-06-02 20:40:36 +02:00
Cédric Verstraeten
e664e78d01 Add topology/volume hooks and bump chart
Bump chart version to 0.113.0 and add optional pod topologySpreadConstraints, volumes and volumeMounts hooks across many templates (admin, oauth2-proxy, kerberoshub services, kerberospipeline components, and vault components). Add conditionals to control rendering of hub-api and hub-frontend Services and make the demo front-end conditional on demoEnabled. Update values.yaml with new defaults (empty arrays) and commented examples for topologySpreadConstraints, volumes and volumeMounts for each relevant component.
2026-06-02 20:36:50 +02:00
Cédric Verstraeten
14508d3ebf Merge pull request #107 from kerberos-io/feature/override-translation-file
feature/override-translation-file
2026-06-01 09:50:05 +02:00
Cédric Verstraeten
5b15104951 Refactor code structure for improved readability and maintainability 2026-06-01 07:42:20 +00:00
Kilian
daa17bb623 Merge pull request #106 from kerberos-io/KilianBoute-patch-1
Bump chart version to 0.111.0
2026-05-29 17:02:53 +02:00
Kilian
cf4b475ad0 Bump chart version to 0.111.0 2026-05-29 17:02:40 +02:00
Kilian
262a572302 Merge pull request #105 from kerberos-io/feature/cases-max-retention-days
feat(hub): add casesMaxRetentionDays cap
2026-05-29 16:54:44 +02:00
Kilian Boute
0800e56f00 feat(hub): add video edits feature toggle in values.yaml and templates 2026-05-29 14:53:29 +00:00
Kilian
398ddc0a15 feat(hub): add casesMaxRetentionDays cap
New optional value kerberoshub.api.casesMaxRetentionDays exposed to the
hub-api container as CASES_MAX_RETENTION_DAYS. Acts as a hard ceiling
on a task's expires_at; "0" (the default) disables the cap and
preserves existing behavior. Mirrors the existing
defaultTaskRetentionDays plumbing.
2026-05-29 10:51:21 +00:00
Cédric Verstraeten
9d51b0ef48 Merge pull request #104 from kerberos-io/feature/add-mongodb-flavor-variable
feature/add-mongodb-flavor-variable
2026-05-26 15:21:00 +02:00
Cédric Verstraeten
c47bb70777 Bump chart version to 0.110.0 2026-05-26 13:16:17 +00:00
Cédric Verstraeten
250a3aa124 Merge branch 'main' into feature/add-mongodb-flavor-variable 2026-05-26 15:13:33 +02:00
Cédric Verstraeten
9524f43157 Merge pull request #103 from kerberos-io/feature/move-credentials-to-api
feature/move-credentials-to-api
2026-05-26 15:13:10 +02:00
Cédric Verstraeten
d85758389a Bump chart version to 0.109.0 2026-05-26 13:12:35 +00:00
Cédric Verstraeten
8ce56a0fbd Add MongoDB flavor variable to configuration options 2026-05-26 12:58:57 +00:00
Cédric Verstraeten
932ded63a1 Bump chart version to 0.109.0 2026-05-26 11:32:39 +00:00
Cédric Verstraeten
ca30ebfd3c Move MQTT and TURN credentials to hub-api for enhanced security 2026-05-26 06:50:39 +00:00
Cédric Verstraeten
ea5705c03c Merge pull request #102 from kerberos-io/feature/update-readme
Feature/update readme
2026-05-25 21:53:51 +02:00
Cédric Verstraeten
acac39eccd Update README.md to include default live stream mode parameter 2026-05-25 19:45:01 +00:00
Cédric Verstraeten
029f288f4d Update README.md 2026-05-25 21:39:48 +02:00
Cédric Verstraeten
376819719f Merge pull request #101 from kerberos-io/feature/add-pagination-feature-flag
feature/add-pagination-feature-flag
2026-05-25 21:26:02 +02:00
Cédric Verstraeten
0b2a4fb8a9 Bump chart version to 0.108.0 for release 2026-05-25 19:23:09 +00:00
Cédric Verstraeten
12cf8218c3 Remove deprecated front-end configuration options and update documentation for internationalization 2026-05-25 19:16:57 +00:00
Cédric Verstraeten
3767a430fc Add pagination feature for live view in hub charts 2026-05-25 17:10:33 +00:00
Cédric Verstraeten
5061ba014a Merge pull request #100 from kerberos-io/feature/add-task-retention-add-internalization
feature/add-task-retention-add-internalization
2026-05-22 16:35:48 +02:00
Cédric Verstraeten
3e54eef0d3 Bump hub chart and set retention to 0
Update Chart.yaml version to 0.107.0 and change kerberoshub.defaultTaskRetentionDays in values.yaml from "365" to "0". This adjusts the chart version and updates the default task retention value (used by kerberoshub.api.defaultTaskRetentionDays).
2026-05-22 16:31:28 +02:00
Cédric Verstraeten
291ac48102 Add task retention and internationalization features to hub charts 2026-05-22 13:00:47 +00:00
Kilian
88ff3e9e33 Merge pull request #98 from kerberos-io/KilianBoute-bump-chart-version
Bump chart version to 0.106.0
2026-05-13 12:04:14 +02:00
Kilian
58e8f2d8d9 Merge pull request #99 from kerberos-io/add-redaction-template
redaction template
2026-05-13 12:03:59 +02:00
Kilian
555b69c15a redaction template 2026-05-13 11:58:46 +02:00
Kilian
6f82740be8 Bump chart version to 0.106.0 2026-05-13 11:44:20 +02:00
Kilian
8a739069d9 Merge pull request #97 from kerberos-io/Add-redaction-service
Add redaction service configuration to values.yaml
2026-05-13 10:41:26 +02:00
Kilian
6c52794509 Add redaction service configuration to values.yaml
Added configuration for redaction service including repository, pull policy, tag, replicas, log level, and resource requests/limits.
2026-05-13 10:37:09 +02:00
Kilian
f07230406a Merge pull request #95 from kerberos-io/Export-Add-player.html-path
Add-player.html-path
2026-05-08 11:27:25 +02:00
Cédric Verstraeten
f5b45a5e0d Merge pull request #96 from kerberos-io/feature/add-workflow-enabled
feature/add-workflow-enabled
2026-05-06 20:48:47 +02:00
Cédric Verstraeten
5bf9f4cefa Add workflows feature flag and bump chart version
Expose a WORKFLOWS feature flag to the frontend by adding FEATURE_WORKFLOWS_ENABLED to both hub-frontend and hub-frontend-demo deployment templates. Add a default `kerberoshub.frontend.features.workflows.enabled: "false"` in values.yaml so the feature is off by default. Bump chart version from 0.104.0 to 0.105.0 to reflect the changes.
2026-05-06 20:42:00 +02:00
Kilian
05c2a0d04d Add-player.html-path 2026-05-06 15:39:32 +02:00
Cédric Verstraeten
e7b90f5953 Merge pull request #94 from kerberos-io/public-release-1777896450
A new public release - 1777896450
2026-05-04 14:08:57 +02:00
uug4ai
ae7cf770e8 A new public release - 1777896450 2026-05-04 12:07:32 +00:00
Cédric Verstraeten
078b64d474 Merge pull request #93 from kerberos-io/public-release-1776688403
A new public release - 1776688403
2026-04-20 14:47:37 +02:00
uug4ai
4e160c4b9d A new public release - 1776688403 2026-04-20 12:33:25 +00:00
Cédric Verstraeten
e7aeacae17 Merge pull request #92 from kerberos-io/cedricve-patch-3
Add invoice and suitcase SVG icons to icons.js
2026-04-16 17:24:24 +02:00
Cédric Verstraeten
a307e6a3f2 Add invoice and suitcase SVG icons to icons.js 2026-04-16 17:20:33 +02:00
Kilian
0878453ed9 Merge pull request #91 from kerberos-io/Add-cleanup-fields
Add cleanup fields
2026-04-10 16:48:52 +02:00
Kilian
52f3124ee7 Add configurable options for hub-cleanup service in values.yaml and update README 2026-04-10 16:45:22 +02:00
Kilian
ea3186cdaa Add configurable options for hub-cleanup service in values.yaml and update README 2026-04-10 16:44:38 +02:00
Cédric Verstraeten
e25e63c841 Merge pull request #90 from kerberos-io/feature/update-values-yaml
feature/update-values-yaml
2026-04-03 10:06:24 +02:00
Cédric Verstraeten
1d70aaf527 Bump chart version to 0.104.0 2026-04-03 10:05:27 +02:00
Cédric Verstraeten
8d713da9c9 Add configurable mode for hub-cleanup service in values.yaml 2026-04-03 10:04:07 +02:00
Cédric Verstraeten
9b9f671525 Merge pull request #89 from kerberos-io/public-release-1775203225
A new public release - 1775203225
2026-04-03 10:01:40 +02:00
uug4ai
fa76f00094 A new public release - 1775203225 2026-04-03 08:00:26 +00:00
Cédric Verstraeten
2e247fbc90 Merge pull request #88 from kerberos-io/feature/add-service-monitor-to-hub-cleanup
feature/add-service-monitor-to-hub-cleanup
2026-04-03 09:55:08 +02:00
Cédric Verstraeten
3b4525a47d Bump chart version to 0.103.0 and add ServiceMonitor for hub-cleanup 2026-04-03 07:51:01 +00:00
Cédric Verstraeten
fa56f11b7b Merge pull request #87 from kerberos-io/feature/allow-pipeline-only-deployment
feature/allow-pipeline-only-deployment
2026-03-28 12:34:06 +01:00
Cédric Verstraeten
5ae77dccc8 Bump chart version to 0.102.0 for Helm chart updates 2026-03-28 11:33:02 +00:00
Cédric Verstraeten
d5a76a46f9 Fix indentation and ensure proper template rendering in multiple pipeline YAML files 2026-03-28 11:32:41 +00:00
Cédric Verstraeten
05e1da44b6 Merge pull request #86 from kerberos-io/feature/allow-pipeline-only-deployment
feature/allow-pipeline-only-deployment
2026-03-28 12:11:49 +01:00
Cédric Verstraeten
fb92df3f7a Bump chart version to 0.101.0 for Helm chart updates 2026-03-28 11:05:17 +00:00
Cédric Verstraeten
a87c5b753d Fix indentation and remove unnecessary end statement in pipe-analysis.yaml 2026-03-28 11:04:38 +00:00
Cédric Verstraeten
3743294f44 Merge pull request #85 from kerberos-io/feature/allow-pipeline-only-deployment
feature/allow-pipeline-only-deployment
2026-03-28 11:56:06 +01:00
Cédric Verstraeten
c08eabbcf5 Bump chart version to 0.100.0 for Helm chart updates 2026-03-28 10:50:12 +00:00
Cédric Verstraeten
8dd347238d Add deployment mode parameter to README.md for Helm chart configuration 2026-03-28 10:49:55 +00:00
Cédric Verstraeten
818c886bb1 Fix indentation in ingress.yaml to ensure proper template rendering 2026-03-28 10:42:37 +00:00
Cédric Verstraeten
8c05be9408 Add deployment mode options and resource limits to values.yaml 2026-03-28 10:38:22 +00:00
Cédric Verstraeten
383491e8c3 Add support for deployment modes in Helm charts 2026-03-28 10:37:18 +00:00
Cédric Verstraeten
50f2880c38 Merge pull request #84 from kerberos-io/feature/add-chart-colors-default-view
feature/add-chart-colors-default-view
2026-03-23 09:40:05 +01:00
Cédric Verstraeten
c529fdad70 Bump chart version to 0.99.0 and add color configuration for chart features 2026-03-23 09:35:17 +01:00
Cédric Verstraeten
1125cb7fdb Merge pull request #83 from kerberos-io/cedricve-patch-3
feature/update-icons-js
2026-03-09 13:15:59 +01:00
Cédric Verstraeten
07ee0f77ae Update print statement from 'Hello' to 'Goodbye' 2026-03-09 13:11:04 +01:00
Cédric Verstraeten
f19ef4b850 Merge pull request #82 from kerberos-io/feature/add-case-enabled
feature/add-case-enabled
2026-03-07 22:07:34 +01:00
Cédric Verstraeten
da1f6fa03b Bump chart version to 0.98.0 for release 2026-03-07 21:02:55 +00:00
Cédric Verstraeten
a2c700ccee Re-enable case management feature in values.yaml configuration 2026-03-07 21:02:39 +00:00
Cédric Verstraeten
b620009891 Add case management feature toggle to frontend configuration 2026-03-07 20:59:25 +00:00
Cédric Verstraeten
cf7e84742e Merge pull request #81 from kerberos-io/documentation/update-readme
documentation/update-readme
2026-03-07 21:49:31 +01:00
Cédric Verstraeten
3dbf7ee66c Implement feature X to enhance user experience and optimize performance 2026-03-07 20:45:52 +00:00
Cédric Verstraeten
db1aedd0b1 Merge pull request #80 from kerberos-io/feature/add-tls-certificate
feature/add-tls-certificate
2026-03-07 21:29:43 +01:00
Cédric Verstraeten
a9c9bf662e Add support for server-side TLS in hub-api with configuration options 2026-03-07 20:25:17 +00:00
Cédric Verstraeten
6092c4274d Merge pull request #79 from kerberos-io/feature/add-devcontainer
feature/add-devcontainer
2026-03-07 20:44:37 +01:00
Cédric Verstraeten
4373e7cafe Refactor service account name assignment to use a default format in multiple YAML templates 2026-03-07 19:23:24 +00:00
Cédric Verstraeten
b6f7b14c80 Merge branch 'main' into feature/add-devcontainer 2026-03-07 20:12:25 +01:00
Cédric Verstraeten
2ce9c5bc0c Update devcontainer for Go and cloud tooling
Switch base image to the Go 1.25 Bookworm devcontainer and rework container tooling installs. Remove explicit apt/pip installs from the old image and instead remove the expired Yarn repo key, install Azure CLI, Helm, kubectl, Argo CD CLI, and Google Cloud SDK (including GKE auth plugin). Update devcontainer metadata: change container name, add --privileged to runArgs, and refresh the VS Code extensions list to include Go/Helm/AKS/Azure tooling and Copilot.
2026-03-07 20:04:16 +01:00
Cédric Verstraeten
f0504ab96d Add devcontainer configuration with Dockerfile and devcontainer.json 2026-03-07 19:59:04 +01:00
Cédric Verstraeten
e5f5ad7073 Merge pull request #70 from zisito/feature/service-account
Feature/service account for Kerberos Hub services
2026-03-07 19:58:08 +01:00
Cédric Verstraeten
791f8014ec Merge pull request #78 from kerberos-io/public-release-1772868774
A new public release - 1772868774
2026-03-07 09:36:32 +01:00
uug4ai
a0af4edfff A new public release - 1772868774 2026-03-07 07:32:56 +00:00
Cédric Verstraeten
376e46526d Merge pull request #77 from kerberos-io/cedricve-patch-3
Change defaultStreamMode value to 'SD'
2026-03-02 13:17:42 +01:00
Cédric Verstraeten
9044f39087 Change defaultStreamMode value to 'SD' 2026-03-02 13:17:31 +01:00
Cédric Verstraeten
297b236e7a Merge pull request #76 from kerberos-io/cedricve-patch-3
Enhance defaultStreamMode description in values.yaml
2026-03-02 12:05:45 +01:00
Cédric Verstraeten
a40f273698 Enhance defaultStreamMode description in values.yaml
Updated defaultStreamMode description to include future migration plans.
2026-03-02 12:05:34 +01:00
Cédric Verstraeten
bee9e8e6d2 Merge pull request #74 from kerberos-io/public-release-1772208444
A new public release - 1772208444
2026-03-02 12:02:27 +01:00
Cédric Verstraeten
f469286262 Merge pull request #75 from kerberos-io/upgrade/helm-chart-variables
upgrade/helm-chart-variables
2026-03-02 11:58:29 +01:00
Cédric Verstraeten
a03682735c Bump chart version to 0.97.0 2026-03-02 11:56:14 +01:00
Cédric Verstraeten
ef023a9266 Update frontend feature flags and add map tile configuration 2026-03-02 11:56:02 +01:00
uug4ai
fc8d735812 A new public release - 1772208444 2026-02-27 16:07:26 +00:00
Cédric Verstraeten
feab5be07c Merge pull request #73 from kerberos-io/public-release-1771807234
A new public release - 1771807234
2026-02-23 01:42:20 +01:00
uug4ai
a006191050 A new public release - 1771807234 2026-02-23 00:40:36 +00:00
Cédric Verstraeten
22a1ba3fcd Merge pull request #72 from kerberos-io/feature/fix-workflows
feature/fix-workflows
2026-02-07 07:53:17 +01:00
cedricve
27f9182516 Update release workflow to trigger on Chart.yaml changes 2026-02-07 07:52:36 +01:00
Cédric Verstraeten
e00829e575 Merge pull request #71 from kerberos-io/public-release-1770446130
A new public release - 1770446130
2026-02-07 07:48:36 +01:00
uug4ai
749f65d278 A new public release - 1770446130 2026-02-07 06:35:33 +00:00
zisito
b5ebcc270f Fix admin version 2026-01-05 16:37:45 +01:00
zisito
b9ddc8d8e5 Service account implementation 2026-01-05 16:33:36 +01:00
Cédric Verstraeten
343547d92c Merge pull request #69 from kerberos-io/cedricve-patch-3
feature/upgrade-admin-panel-version-v1.3.0
2025-12-31 14:27:13 +01:00
Cédric Verstraeten
8c6703d70c Update values.yaml 2025-12-31 14:00:41 +01:00
Cédric Verstraeten
588dec2c8b Merge pull request #68 from kerberos-io/feature/add-loglevel
feature/add-loglevel
2025-12-12 16:42:40 +01:00
cedricve
2a90049939 Bump chart version to 0.96.0 2025-12-12 16:42:19 +01:00
cedricve
c0a1cfabeb Add log level environment variable to various deployments and services 2025-12-12 16:37:33 +01:00
cedricve
59a75220e6 Add logLevel and replicas to service configurations
Introduces a configurable logLevel (with possible values: trace, debug, info, warn, error) and explicit replicas count for multiple services in values.yaml. This enhances control over logging verbosity and pod scaling for each service.
2025-12-12 15:58:40 +01:00
Cédric Verstraeten
6a62ad5c6f Merge pull request #67 from kerberos-io/feature/add-feature-flags
feature/add-feature-flags
2025-12-09 17:07:10 +01:00
Cédric Verstraeten
504ebd096c Update release workflow to trigger on push to main and downgrade chart-releaser action version 2025-12-09 17:06:31 +01:00
Cédric Verstraeten
503ae2907b Merge pull request #66 from kerberos-io/feature/add-feature-flags
feature/add-feature-flags
2025-12-09 17:00:25 +01:00
Cédric Verstraeten
23ec876e9f Remove tag push trigger from release workflow and enable manual dispatch 2025-12-09 16:59:53 +01:00
Cédric Verstraeten
248fcd177d Merge pull request #65 from kerberos-io/feature/add-feature-flags
feature/add-feature-flags
2025-12-09 16:58:13 +01:00
Cédric Verstraeten
a08a9a5061 Update release-create.yaml 2025-12-09 16:57:21 +01:00
Cédric Verstraeten
775751e295 Merge pull request #64 from kerberos-io/feature/add-feature-flags
feature/add-feature-flags
2025-12-09 16:55:27 +01:00
Cédric Verstraeten
599ea56529 Update release workflow to trigger on version tag pushes and upgrade dependencies 2025-12-09 16:53:05 +01:00
Cédric Verstraeten
762075ac18 Merge pull request #63 from kerberos-io/feature/add-feature-flags
feature/add-feature-flags
2025-12-09 14:22:50 +01:00
Cédric Verstraeten
c4feed4b57 Update API and frontend image tags to v1.7.2 and v1.7.3 respectively 2025-12-09 14:18:28 +01:00
Cédric Verstraeten
3bc22577c8 Bump chart version to 0.95.0
Updated the Chart.yaml version from 0.94.0 to 0.95.0 to reflect new changes in the chart.
2025-12-09 14:17:44 +01:00
Cédric Verstraeten
52de354e90 Add granular frontend feature toggles and env vars
Introduces detailed feature flags for the frontend in values.yaml, including dark mode, landing page, liveview, devices, and media filters. Updates hub-frontend and hub-frontend-demo templates to set new environment variables for these features, multi-tenancy, MQTT legacy, OpenAI, and additional page titles. This enables more flexible configuration and control over frontend behavior.
2025-12-09 14:17:33 +01:00
Cédric Verstraeten
f22afbdce9 Merge pull request #62 from kerberos-io/feature/add-feature-flags
feature/add-feature-flags
2025-12-05 14:03:00 +01:00
Cédric Verstraeten
da21dd8875 Merge branch 'feature/add-feature-flags' of github.com:kerberos-io/helm-charts into feature/add-feature-flags 2025-12-05 08:57:12 +01:00
Cédric Verstraeten
3d4a785d43 Refactor floorplan feature colors in values.yaml 2025-12-05 08:56:55 +01:00
cedricve
75b2e58d73 Update license key in hub values.yaml
Replaces the existing license key with a new value in charts/hub/values.yaml. No other configuration changes were made.
2025-12-04 22:35:45 +01:00
Cédric Verstraeten
52236cabda Add feature flags for floorplan options in frontend configuration 2025-12-04 17:36:11 +01:00
Cédric Verstraeten
05b2af6058 Fix typo in deviceGroupDescription environment variable value 2025-12-04 13:46:12 +01:00
Cédric Verstraeten
4dd9399903 Enable object detection, star, and region filters in media configuration 2025-12-04 13:44:36 +01:00
Cédric Verstraeten
0e04f3bf4c Add feature flags for floorplan and media filters in frontend configuration 2025-12-04 13:43:45 +01:00
cedricve
bf4f927d01 Bump chart version to 0.94.0 2025-12-04 10:58:48 +01:00
cedricve
e94b6c301e Refactor features config and add floorplan options
Reorganized the features section in values.yaml to use nested objects for faceRedaction and media filters. Added configuration options for the new floorplan feature, including color settings and enable flags. Updated comments and variable names for clarity.
2025-12-04 10:57:58 +01:00
Cédric Verstraeten
5d802a90c7 Merge pull request #61 from kerberos-io/fix/update-release-workflow
fix/update-release-workflow
2025-11-27 12:25:16 +01:00
Cédric Verstraeten
bb8b1b1143 Fix indentation in release workflow YAML 2025-11-27 12:23:41 +01:00
Cédric Verstraeten
4405685b63 Merge pull request #60 from kerberos-io/fix/hub-api-env-from
fix/hub-api-env-from
2025-11-27 12:17:40 +01:00
Cédric Verstraeten
f77d69b742 Merge pull request #59 from kerberos-io/public-release-1764168026
A new public release - 1764168032
2025-11-27 12:09:55 +01:00
Cédric Verstraeten
0208ff3fa8 Remove redundant deployment wait commands from k3d, kind, and microk8s workflows 2025-11-27 12:09:12 +01:00
Cédric Verstraeten
69f81a4209 Add release workflow for creating new chart releases 2025-11-27 11:55:54 +01:00
Cédric Verstraeten
33b296f7f0 Bump chart version to 0.93.0 2025-11-27 11:53:13 +01:00
Cédric Verstraeten
7343a5282d Remove OpenEBS and storage class installation steps from k3d, kind, and microk8s workflows 2025-11-27 11:51:19 +01:00
Cédric Verstraeten
505b9c81dc Refactor CI workflows: consolidate deployment steps for microk8s, k3d, and kind; add Slack notifications for success and failure 2025-11-27 11:48:37 +01:00
Cédric Verstraeten
b281b5a170 Move MongoDB envFrom to main container spec
Relocated the envFrom section referencing the mongodb-config ConfigMap from a lower position to immediately after volumeMounts in the container spec. This improves organization and ensures environment variables are loaded earlier in the container definition.
2025-11-27 10:24:44 +01:00
uug4ai
39b10f6d1a A new public release - 1764168032 2025-11-26 14:40:32 +00:00
Cédric Verstraeten
a3b2b8a604 Merge pull request #58 from kerberos-io/feature/add-retry-writes-option
feature/add-retry-writes-option
2025-11-26 13:53:39 +01:00
cedricve
1821d45ee9 Add mongodb-config reference to multiple deployments 2025-11-26 13:34:16 +01:00
cedricve
c5bef07bf5 Add ConfigMap for MongoDB configuration and update deployments to use it 2025-11-26 13:28:37 +01:00
cedricve
377877b563 Bump chart version to 0.92.0 and add MONGODB_RETRY_WRITES environment variable to multiple deployments 2025-11-26 13:13:41 +01:00
Kilian
7b6df5f996 Merge pull request #57 from kerberos-io/enhancement/update-icons
enhancement/update-icons
2025-11-07 11:06:40 +01:00
Kilian
b860b0cbb1 Add new SVG icons for plus, play, pause, back, and forward actions 2025-11-07 10:51:44 +01:00
Cédric Verstraeten
53999dc00a Merge pull request #56 from kerberos-io/feature/add-faceredaction-variables
feature/add-faceredaction-variables
2025-10-03 07:37:33 +02:00
cedricve
b6b56980d2 Bump chart version to 0.91.0 2025-10-03 07:32:03 +02:00
cedricve
bf36516238 Update values.yaml to disable multi-tenancy and add descriptions for site and group features 2025-10-02 23:25:54 +02:00
cedricve
512fc70f24 Add environment variables for frontend features and update values.yaml 2025-10-02 23:23:32 +02:00
Cédric Verstraeten
d893b2db87 Merge pull request #54 from kerberos-io/feature/add-open-telemetry-integration
feature/add-open-telemetry-integration
2025-08-29 14:43:38 +02:00
Cédric Verstraeten
c42d59667b Bump chart version to 0.90.0 2025-08-29 14:33:27 +02:00
Cédric Verstraeten
e14954d70d Add OpenTelemetry configuration to pipeline templates and update values.yaml 2025-08-29 14:27:56 +02:00
Kilian
0ea8b81035 Merge pull request #53 from kerberos-io/maps-update-value-0.89.0
Bump chart version to 0.89.0
2025-08-12 13:35:42 +02:00
Kilian
8b8fa2105f Bump chart version to 0.89.0 2025-08-12 11:09:37 +02:00
Kilian
7d734bcdc7 Merge pull request #52 from kerberos-io/maps-live-view-control-colors
maps-live-view-control-colors
2025-08-12 11:06:53 +02:00
Kilian
3bc915f1bb Merge branch 'main' into maps-live-view-control-colors 2025-08-12 11:06:30 +02:00
Kilian
e5d096dfc9 Add colors for live view control icons in values.yaml 2025-08-12 09:40:44 +02:00
Cédric Verstraeten
3387bfc104 Merge pull request #51 from kerberos-io/public-release-1754552209
A new public release - 1754552215
2025-08-12 07:03:44 +02:00
Kilian
230ea56d75 Update hub-frontend.yaml 2025-08-11 15:36:22 +02:00
Cédric Verstraeten
9e43c26a53 Merge pull request #50 from kerberos-io/cedricve-patch-2
Update icons.js
2025-08-07 09:44:44 +02:00
uug4ai
2f46a59c53 A new public release - 1754552215 2025-08-07 07:36:55 +00:00
Cédric Verstraeten
41cfd49aa2 Update icons.js 2025-08-05 09:49:27 +02:00
Cédric Verstraeten
71c60dcd83 Merge pull request #49 from kerberos-io/feature/expanding-custom-naming-conventions
feature/expanding-custom-naming-conventions
2025-08-04 14:46:45 +02:00
Cédric Verstraeten
11b52303b2 Bump chart version to 0.88.0 and add new environment variables for frontend configuration 2025-08-04 14:38:44 +02:00
Cédric Verstraeten
45b29d2979 Merge pull request #48 from kerberos-io/public-release-1753886181
A new public release - 1753886187
2025-07-30 16:37:19 +02:00
uug4ai
6d2d6fb66d A new public release - 1753886187 2025-07-30 14:36:28 +00:00
Kilian
34235282db Merge pull request #47 from kerberos-io/feature/hub-frontend-v1.2.6
feature/hub-frontend-v1.2.6
2025-07-08 09:41:27 +02:00
Kilian
d562294719 Bump chart version to 0.87.0 and add floor plan name configuration for frontend 2025-07-07 16:47:37 +02:00
Kilian
4c4a6c042f Merge pull request #46 from kerberos-io/feature/hub-frontend-v1.2.5
feature/hub-frontend-v1.2.5
2025-07-04 13:13:31 +02:00
Kilian
eaaaef12fb Bump chart version to 0.86.0 2025-07-04 13:12:27 +02:00
Kilian
acdff2898e Add custom color configurations for device icons and floor plans 2025-07-04 13:03:16 +02:00
Cédric Verstraeten
4b377e6641 Merge pull request #45 from kerberos-io/upgrade/version-0.85.0
version: 0.85.0
2025-06-24 07:59:30 +02:00
Cédric Verstraeten
261e43ea05 version: 0.85.0 2025-06-24 07:59:18 +02:00
Cédric Verstraeten
8e971275be Merge pull request #44 from kerberos-io/feature/sso-callback-headers+otel-integration
Add environment variables for Open Telemetry and SSO extra headers in…
2025-06-24 07:58:39 +02:00
cedricve
79a0e0e9b0 Add environment variables for Open Telemetry and SSO extra headers in hub API 2025-06-23 23:45:10 +02:00
Cédric Verstraeten
c5d867a4df Merge pull request #43 from kerberos-io/public-release-1747736737
A new public release - 1747736741
2025-05-20 12:33:43 +02:00
uug4ai
f03f1ed88d A new public release - 1747736741 2025-05-20 10:25:41 +00:00
Cédric Verstraeten
0fc0cdd53f Merge pull request #41 from kerberos-io/public-release-1743746495
A new public release - 1743746499
2025-05-13 12:08:55 +02:00
Cédric Verstraeten
ebd04792b2 Merge pull request #42 from kerberos-io/feature/add-case-filter-assignee-default
Bump chart version to 0.84.0 and add default case filter assignees value
2025-04-29 14:12:53 +02:00
Cédric Verstraeten
eba5b323b7 Bump chart version to 0.84.0 and add default case filter assignees value 2025-04-29 14:08:09 +02:00
uug4ai
8722f017f0 A new public release - 1743746499 2025-04-04 06:01:39 +00:00
Cédric Verstraeten
d4d98e3e1e Merge pull request #39 from kerberos-io/public-release-1742908520
A new public release - 1742908524
2025-03-25 14:18:11 +01:00
uug4ai
8680df206b A new public release - 1742908524 2025-03-25 13:15:24 +00:00
Cédric Verstraeten
8e18cdaad3 Merge pull request #38 from kerberos-io/cedricve-patch-2
Upgrade version to 0.83.0
2025-03-25 12:29:02 +01:00
Cédric Verstraeten
42243102ba Upgrade version to 0.83.0 2025-03-25 12:28:00 +01:00
Cédric Verstraeten
75039605c8 Merge pull request #37 from Jalhd/feature/add-envvars-kerberos-hub
Add extraEnv value for kerberos-hub
2025-03-25 12:27:31 +01:00
t0254280
5efdb0fce9 Add extraEnv value for kerberos-hub 2025-03-25 11:15:43 +01:00
Cédric Verstraeten
6f708b5cc6 Merge pull request #36 from kerberos-io/fix/enable-oauth-proxy
Upgrade to 0.82.0
2025-03-07 17:29:12 +01:00
Cedric Verstraeten
3143384c1f upgrade to 0.82.0 2025-03-07 17:27:08 +01:00
Cédric Verstraeten
6fd5430d66 Merge pull request #35 from kerberos-io/fix/enable-oauth-proxy
Enable oauth proxy with admin
2025-03-07 17:14:08 +01:00
Cedric Verstraeten
0cee9420cc enable oauth proxy 2025-03-07 17:05:13 +01:00
Cédric Verstraeten
e92fa41437 Merge pull request #34 from kerberos-io/fix/admin-service-reference
Upgrade to 0.80.0 and change reference
2025-03-07 14:18:53 +01:00
Cedric Verstraeten
08b06d5ba0 upgrade to 0.80.0 and change reference 2025-03-07 14:07:57 +01:00
Cédric Verstraeten
63fcb3e0a4 Merge pull request #33 from kerberos-io/feature/add-admin-panel
Feature/add admin panel
2025-03-07 13:42:59 +01:00
Cedric Verstraeten
28087cb072 Update Chart.yaml 2025-03-07 13:42:27 +01:00
Cedric Verstraeten
39fb2a11f2 fix service.yaml 2025-03-07 13:29:20 +01:00
Cedric Verstraeten
0a26eb00b3 fix ingress templating 2025-03-07 12:23:36 +01:00
Cedric Verstraeten
9afc0e7e97 add admin deployment, ingress, service, and oauth2-proxy templates 2025-03-07 11:25:27 +01:00
Cedric Verstraeten
764c580962 add admin panel to helm chart + cleanup values.yaml 2025-03-07 11:22:51 +01:00
Cédric Verstraeten
f0d544c009 Merge pull request #32 from kerberos-io/feature/add-authentication-mechanism
Add authentication mechanism
2025-03-06 13:13:14 +01:00
Cédric Verstraeten
903bf847af Merge pull request #31 from kerberos-io/public-release-1740815636
A new public release - 1740815640
2025-03-06 13:06:14 +01:00
Cedric Verstraeten
926c59ac48 add authentication mechanism 2025-03-06 12:59:21 +01:00
uug4ai
57881d35c2 A new public release - 1740815640 2025-03-01 07:54:00 +00:00
Cédric Verstraeten
6964daed46 Merge pull request #30 from kerberos-io/public-release-1740756659
A new public release - 1740756663
2025-02-28 16:37:50 +01:00
Cédric Verstraeten
818bad12c7 Merge pull request #29 from kerberos-io/cedricve-patch-1
Add dark and light mode icon
2025-02-28 16:35:55 +01:00
uug4ai
ed003dfb13 A new public release - 1740756663 2025-02-28 15:31:03 +00:00
Cédric Verstraeten
ba5d74e719 add dark and light mode icon 2025-02-19 14:42:09 +01:00
Cédric Verstraeten
2c10d6eace Merge pull request #28 from kerberos-io/public-release-1739963582
A new public release - 1739963586
2025-02-19 14:40:29 +01:00
uug4ai
b19aa8af9f A new public release - 1739963586 2025-02-19 11:13:06 +00:00
Cédric Verstraeten
17fb252380 Merge pull request #27 from kerberos-io/public-release-1739395154
A new public release - 1739395158
2025-02-12 22:21:03 +01:00
uug4ai
794f424fe2 A new public release - 1739395158 2025-02-12 21:19:18 +00:00
Cédric Verstraeten
9ba5d83501 Merge pull request #26 from kerberos-io/fix/make-orphaned-deletion-configurable
Allow editing of orphaned day limit
2024-12-02 12:56:56 +01:00
Cedric Verstraeten
1f089fba28 Update Chart.yaml 2024-12-02 12:56:42 +01:00
Cedric Verstraeten
a07ddeb0e4 allow editing of orphaned day limit 2024-12-02 12:45:34 +01:00
Cédric Verstraeten
df4d848105 Merge pull request #25 from kerberos-io/feature/inject-namespace-required-for-kustomize
Improvement / Missed some namespaces on several resources
2024-12-02 11:42:10 +01:00
Cedric Verstraeten
054d3d6079 Update Chart.yaml 2024-12-02 11:33:08 +01:00
Cedric Verstraeten
bdd07d3936 missed some namespaces 2024-12-02 11:33:00 +01:00
Cédric Verstraeten
4a774420c2 Merge pull request #24 from kerberos-io/feature/inject-namespace-required-for-kustomize
Feature/inject namespace required for kustomize
2024-12-02 11:22:53 +01:00
Cédric Verstraeten
121ea686a2 Merge pull request #23 from kerberos-io/cedricve-patch-1
set kerberosvault to true (thumbnails)
2024-12-02 11:22:41 +01:00
Cedric Verstraeten
e7f90babc2 use spec.ingressClassName instead of kubernetes.io/ingress.class 2024-12-02 11:13:30 +01:00
Cedric Verstraeten
e6cbe866fd Update servicemonitor.yaml 2024-12-02 11:06:44 +01:00
Cedric Verstraeten
eb75a46972 replace with other variable (official helm variable) 2024-12-02 11:02:56 +01:00
Cedric Verstraeten
24ef6047f8 Update README.md 2024-12-02 10:56:13 +01:00
Cedric Verstraeten
d93a5d228c change templates to include namespace 2024-12-02 10:54:19 +01:00
Cédric Verstraeten
8b016ca2f8 set kerberosvault to true (thumbnails) 2024-11-29 13:42:08 +01:00
Cédric Verstraeten
d8a29e37ec Merge pull request #22 from kerberos-io/feature/turn-on-off-ingress-add-workflows
Add possibility to turn on/off ingress
2024-11-27 14:24:38 +01:00
Cedric Verstraeten
14c6737f5c Update values.yaml 2024-11-27 14:06:12 +01:00
Cedric Verstraeten
c71eadd28a add prometheus 2024-11-27 13:49:46 +01:00
Cedric Verstraeten
90c892eb12 update chart reference 2024-11-27 13:31:19 +01:00
Cedric Verstraeten
19399a01ca update references helm chart values.yaml 2024-11-27 13:28:58 +01:00
Cedric Verstraeten
a75358affb change values.yaml file. 2024-11-27 13:26:40 +01:00
Cedric Verstraeten
9b8050a7f6 add files 2024-11-27 13:24:15 +01:00
Cédric Verstraeten
99b6f71971 Merge pull request #21 from kerberos-io/feature/add-assign-task-template
Add asign task template
2024-11-27 11:14:38 +01:00
Cedric Verstraeten
39bb5a5f60 add assign_task templates 2024-11-27 11:11:25 +01:00
Cédric Verstraeten
3a68cf38d5 Merge pull request #20 from kerberos-io/feature/add-assign-task-template
Add Assign Task details
2024-11-26 16:54:17 +01:00
Cedric Verstraeten
84d40e805e add assign_task parameters 2024-11-26 16:52:33 +01:00
Cédric Verstraeten
98daf4eb31 Merge pull request #19 from kerberos-io/cedricve-patch-1
Update license
2024-11-22 14:41:45 +01:00
Cédric Verstraeten
f6817864ba Update values.yaml 2024-11-22 14:39:54 +01:00
Cédric Verstraeten
b62360f72f Merge pull request #18 from kerberos-io/feature/add-global-image-registry
Add image registry option
2024-11-20 15:15:17 +01:00
Cedric Verstraeten
465b6d91b2 add image registry 2024-11-20 15:12:41 +01:00
Cédric Verstraeten
db96c2a203 Merge pull request #16 from kerberos-io/public-release-1731600351
A new public release - 1731600354
2024-11-14 17:06:48 +01:00
uug4ai
1a816be11e A new public release - 1731600354 2024-11-14 16:05:54 +00:00
Cédric Verstraeten
41957b69d6 Merge pull request #15 from kerberos-io/public-release-1730577950
A new public release - 1730577953
2024-11-02 21:15:25 +01:00
uug4ai
b19eb7f640 A new public release - 1730577953 2024-11-02 20:05:53 +00:00
Cédric Verstraeten
d3390d519d Merge pull request #14 from kerberos-io/feature/add-oauth-to-api
revert oauth to frontend + upgrade 0.71.0
2024-10-31 16:42:36 +01:00
Cedric Verstraeten
aa73e9585c revert oauth to frontend + upgrade 0.71.0 2024-10-31 16:40:01 +01:00
Cédric Verstraeten
c70cf7f222 Merge pull request #13 from kerberos-io/feature/add-oauth-to-api
try out --skip-auth-preflight=true
2024-10-31 16:01:10 +01:00
Cedric Verstraeten
d30b7446c0 try out --skip-auth-preflight=true 2024-10-31 16:00:18 +01:00
Cédric Verstraeten
d816910742 Merge pull request #12 from kerberos-io/feature/add-oauth-to-api
preflight cors fix
2024-10-31 12:56:49 +01:00
Cedric Verstraeten
7a3fde3b4c preflight cors fix 2024-10-31 12:53:12 +01:00
Cédric Verstraeten
19d3f0c448 Merge pull request #11 from kerberos-io/feature/add-oauth-to-api
upgrade to 0.68.0
2024-10-30 22:31:28 +01:00
Cedric Verstraeten
a935bed9e4 upgrade to 0.68.0 2024-10-30 22:30:42 +01:00
Cédric Verstraeten
d72e7aecf5 Merge pull request #10 from kerberos-io/feature/add-oauth-to-api
convert to string + upgrade to 0.67.0
2024-10-30 22:22:51 +01:00
Cedric Verstraeten
4dfad6497e convert to string + upgrade to 0.67.0 2024-10-30 22:21:32 +01:00
Cédric Verstraeten
93ba207017 Merge pull request #9 from kerberos-io/feature/add-oauth-to-api
add cors to ingress + upgrade to 0.66.0
2024-10-30 22:16:50 +01:00
Cedric Verstraeten
bebfc33aa5 add cors to ingress + upgrade to 0.66.0 2024-10-30 22:15:53 +01:00
Cédric Verstraeten
fb9c0d1a03 Merge pull request #8 from kerberos-io/feature/add-oauth-to-api
oauth for api + upgrade to 0.65.0
2024-10-30 22:05:32 +01:00
Cedric Verstraeten
95a431f46d oauth for api + upgrade to 0.65.0 2024-10-30 22:01:12 +01:00
Cédric Verstraeten
7631b10aeb Merge pull request #7 from kerberos-io/feature/add-oauth-to-api
update to 0.64.0 + change ingress names
2024-10-30 21:47:14 +01:00
Cedric Verstraeten
2ef457d2da update to 0.64.0 + change ingress names 2024-10-30 21:46:06 +01:00
Cédric Verstraeten
60f5eb7b0d Merge pull request #6 from kerberos-io/feature/add-oauth-to-api
upgrade to 0.63.0 - missing ingress
2024-10-30 21:43:25 +01:00
Cedric Verstraeten
a48d866036 upgrade to 0.63.0 - missing ingress 2024-10-30 21:42:25 +01:00
Cédric Verstraeten
4da81e158f Merge pull request #5 from kerberos-io/feature/add-oauth-to-api
Enable oauth on hub api as well
2024-10-30 21:26:28 +01:00
Cedric Verstraeten
6d542eadef enable oauth on hub api as well 2024-10-30 21:24:36 +01:00
Cédric Verstraeten
ecfaf23499 Merge pull request #4 from kerberos-io/public-release-1728500577
A new public release - 1728500581
2024-10-09 21:03:46 +02:00
uug4ai
e6449b761f A new public release - 1728500581 2024-10-09 19:03:01 +00:00
Cédric Verstraeten
90cf8a2f36 Merge pull request #3 from kerberos-io/public-release-1728491349
A new public release - 1728491354
2024-10-09 18:31:12 +02:00
uug4ai
f0c88c6b62 A new public release - 1728491354 2024-10-09 16:29:14 +00:00
Cedric Verstraeten
aebd16d510 upgrade to 0.61.0 2024-10-04 22:37:01 +02:00
Cedric Verstraeten
79faf46156 align attributes 2024-10-04 21:12:21 +02:00
Cédric Verstraeten
d23dd5fa42 Merge pull request #2 from kerberos-io/feature/add-support-for-oauth2-proxy
Upgrade to 0.58.0
2024-10-04 19:54:11 +02:00
Cedric Verstraeten
f65a75ae33 upgrade to 0.58.0 2024-10-04 19:52:05 +02:00
Cédric Verstraeten
5a506cfe6a Merge pull request #1 from kerberos-io/feature/add-support-for-oauth2-proxy
Feature/add support for oauth2 proxy
2024-10-04 14:26:04 +02:00
Cedric Verstraeten
ea3c96b4f9 Update Chart.yaml 2024-10-04 14:24:58 +02:00
Cedric Verstraeten
95ca1689dc Create pr-description.yml 2024-10-04 08:58:59 +02:00
Cedric Verstraeten
601147a3d5 add support for oauth2-proxy 2024-10-04 08:53:01 +02:00
Cedric Verstraeten
3478d42681 possibility to enable support mode on the api 2024-10-03 09:40:05 +02:00
56 changed files with 8341 additions and 741 deletions

28
.devcontainer/Dockerfile Normal file
View File

@@ -0,0 +1,28 @@
FROM mcr.microsoft.com/devcontainers/go:1.25-bookworm
# Remove expired Yarn GPG key from base image
RUN sudo rm -f /etc/apt/sources.list.d/yarn.list
# Remove expired Yarn repository key (inherited from base image)
RUN sudo rm -f /etc/apt/sources.list.d/yarn.list
# Install AZURE CLI
RUN curl -sL https://aka.ms/InstallAzureCLIDeb | sudo bash
# Install helm and kubectl
RUN curl https://raw.githubusercontent.com/helm/helm/master/scripts/get-helm-3 | bash
RUN curl -LO "https://dl.k8s.io/release/$(curl -L -s https://dl.k8s.io/release/stable.txt)/bin/linux/amd64/kubectl" \
&& chmod +x ./kubectl \
&& sudo mv ./kubectl /usr/local/bin/kubectl
# Install Argocd CLI
RUN VERSION=$(curl -L -s https://raw.githubusercontent.com/argoproj/argo-cd/stable/VERSION)
RUN curl -sSL -o argocd-linux-amd64 https://github.com/argoproj/argo-cd/releases/download/v$VERSION/argocd-linux-amd64
RUN sudo install -m 555 argocd-linux-amd64 /usr/local/bin/argocd
RUN rm argocd-linux-amd64
# Install google-cloud-sdk
RUN echo "deb [signed-by=/usr/share/keyrings/cloud.google.gpg] http://packages.cloud.google.com/apt cloud-sdk main" | sudo tee -a /etc/apt/sources.list.d/google-cloud-sdk.list
RUN curl https://packages.cloud.google.com/apt/doc/apt-key.gpg | sudo gpg --dearmor -o /usr/share/keyrings/cloud.google.gpg
RUN sudo apt-get update && sudo apt-get install -y google-cloud-cli
RUN sudo apt-get install google-cloud-cli-gke-gcloud-auth-plugin

View File

@@ -0,0 +1,23 @@
{
"name": "go:1.25-bookworm",
"dockerFile": "Dockerfile",
"runArgs": [
"--name=helm-charts",
"--network=host",
"--privileged"
],
"customizations": {
"vscode": {
"extensions": [
"ms-kubernetes-tools.vscode-kubernetes-tools",
"redhat.vscode-yaml",
"Tim-Koehler.helm-intellisense",
"ms-vscode.azurecli",
"ms-vscode-remote.remote-containers",
"GitHub.copilot",
"ms-kubernetes-tools.vscode-aks-tools",
"fabiospampinato.vscode-diff"
]
}
}
}

56
.github/workflows/k3d.yaml vendored Normal file
View File

@@ -0,0 +1,56 @@
name: Deploy on k3d
on:
workflow_dispatch:
pull_request:
jobs:
deploy:
runs-on: ${{ matrix.os }}
strategy:
matrix:
os: [ubuntu-22.04, ubuntu-24.04]
k3d: [v5.7.5]
steps:
- name: Checkout repository
uses: actions/checkout@v4
- name: "Create single cluster"
uses: AbsaOSS/k3d-action@v2
with:
k3d-version: ${{ matrix.k3d }}
cluster-name: "k3d-cluster"
- name: Print Kubernetes Version
run: |
kubectl version
- name: Test k3d
run: |
echo "Sleeping for 120 seconds, give time for the cluster to be ready" && sleep 120
kubectl get no
kubectl get pods -A -o wide
kubectl get sc
- name: Checkout repository
uses: actions/checkout@v2
- name: Install Prometheus operator
id: install-prometheus-operator
run: |
kubectl apply -f https://raw.githubusercontent.com/prometheus-operator/prometheus-operator/v0.48.1/bundle.yaml
kubectl wait --for=condition=available deployment/prometheus-operator -n default --timeout=300s
kubectl get crd
kubectl get po -A -o wide
- name: Install Hub Helm chart
id: install-hub
run: |
helm repo add kerberos https://charts.kerberos.io
kubectl create namespace kerberos-hub
helm install hub ./charts/hub --values charts/hub/values.yaml -n kerberos-hub --create-namespace
kubectl get pods -A -o wide
- name: Send Slack Notification on Success
if: success()
env:
SLACK_WEBHOOK_URL: ${{ secrets.SLACK_WEBHOOK_URL }}
run: |
curl -X POST -H 'Content-type: application/json' --data "{\"text\": \"✅ K3d deployment successful on ${{ matrix.os }} (${{ matrix.k3d }}) - triggered by ${{ github.actor }}\"}" $SLACK_WEBHOOK_URL
- name: Send Slack Notification on Failure
if: failure()
env:
SLACK_WEBHOOK_URL: ${{ secrets.SLACK_WEBHOOK_URL }}
run: |
curl -X POST -H 'Content-type: application/json' --data "{\"text\": \"❌ K3d deployment failed on ${{ matrix.os }} (${{ matrix.k3d }}) - <${{ github.server_url }}/${{ github.repository }}/actions/runs/${{ github.run_id }}|View logs>\"}" $SLACK_WEBHOOK_URL

52
.github/workflows/kind.yaml vendored Normal file
View File

@@ -0,0 +1,52 @@
name: Deploy on kind
on:
workflow_dispatch:
pull_request:
jobs:
deploy:
runs-on: ${{ matrix.os }}
strategy:
matrix:
os: [ubuntu-22.04, ubuntu-24.04]
kind: [v0.25.0]
steps:
- name: Create kind
uses: helm/kind-action@v1
with:
version: ${{ matrix.kind }}
- name: Print Kubernetes Version
run: |
kubectl version
- name: Test kind
run: |
kubectl get no
kubectl get pods -A -o wide
kubectl get sc
- name: Checkout repository
uses: actions/checkout@v2
- name: Install Prometheus operator
id: install-prometheus-operator
run: |
kubectl apply -f https://raw.githubusercontent.com/prometheus-operator/prometheus-operator/v0.48.1/bundle.yaml
kubectl wait --for=condition=available deployment/prometheus-operator -n default --timeout=300s
kubectl get crd
kubectl get po -A -o wide
- name: Install Hub Helm chart
id: install-hub
run: |
helm repo add kerberos https://charts.kerberos.io
kubectl create namespace kerberos-hub
helm install hub ./charts/hub --values charts/hub/values.yaml -n kerberos-hub --create-namespace
kubectl get pods -A -o wide
- name: Send Slack Notification on Success
if: success()
env:
SLACK_WEBHOOK_URL: ${{ secrets.SLACK_WEBHOOK_URL }}
run: |
curl -X POST -H 'Content-type: application/json' --data "{\"text\": \"✅ Kind deployment successful on ${{ matrix.os }} (${{ matrix.kind }}) - triggered by ${{ github.actor }}\"}" $SLACK_WEBHOOK_URL
- name: Send Slack Notification on Failure
if: failure()
env:
SLACK_WEBHOOK_URL: ${{ secrets.SLACK_WEBHOOK_URL }}
run: |
curl -X POST -H 'Content-type: application/json' --data "{\"text\": \"❌ Kind deployment failed on ${{ matrix.os }} (${{ matrix.kind }}) - <${{ github.server_url }}/${{ github.repository }}/actions/runs/${{ github.run_id }}|View logs>\"}" $SLACK_WEBHOOK_URL

53
.github/workflows/microk8s.yaml vendored Normal file
View File

@@ -0,0 +1,53 @@
name: Deploy on microk8s
on:
workflow_dispatch:
pull_request:
jobs:
deploy:
runs-on: ${{ matrix.os }}
strategy:
matrix:
os: [ubuntu-22.04, ubuntu-24.04]
microk8s: [1.32/stable]
steps:
- uses: balchua/microk8s-actions@v0.4.3
with:
channel: ${{ matrix.microk8s }}
addons: '["dns", "dashboard", "hostpath-storage", "nvidia"]'
- name: Set permissions
run: |
sudo chown -f -R $USER $HOME/.kube $HOME/.config
- name: Test microk8s
id: list-pods
run: |
kubectl get no
kubectl get pods -A -o wide
- name: Checkout repository
uses: actions/checkout@v2
- name: Install Prometheus operator
id: install-prometheus-operator
run: |
kubectl apply -f https://raw.githubusercontent.com/prometheus-operator/prometheus-operator/v0.48.1/bundle.yaml
kubectl wait --for=condition=available deployment/prometheus-operator -n default --timeout=300s
kubectl get crd
kubectl get po -A -o wide
- name: Install Hub Helm chart
id: install-hub
run: |
helm repo add kerberos https://charts.kerberos.io
kubectl create namespace kerberos-hub
helm install hub ./charts/hub --values charts/hub/values.yaml -n kerberos-hub --create-namespace
kubectl get pods -A -o wide
- name: Send Slack Notification on Success
if: success()
env:
SLACK_WEBHOOK_URL: ${{ secrets.SLACK_WEBHOOK_URL }}
run: |
curl -X POST -H 'Content-type: application/json' --data "{\"text\": \"✅ MicroK8s deployment successful on ${{ matrix.os }} (${{ matrix.microk8s }}) - triggered by ${{ github.actor }}\"}" $SLACK_WEBHOOK_URL
- name: Send Slack Notification on Failure
if: failure()
env:
SLACK_WEBHOOK_URL: ${{ secrets.SLACK_WEBHOOK_URL }}
run: |
curl -X POST -H 'Content-type: application/json' --data "{\"text\": \"❌ MicroK8s deployment failed on ${{ matrix.os }} (${{ matrix.microk8s }}) - <${{ github.server_url }}/${{ github.repository }}/actions/runs/${{ github.run_id }}|View logs>\"}" $SLACK_WEBHOOK_URL

View File

@@ -1,9 +1,11 @@
name: Release Charts
name: Create a new release
on:
push:
branches:
- main
paths:
- 'charts/**/Chart.yaml'
jobs:
release:

View File

@@ -0,0 +1,31 @@
name: Workflows queue consistency
# Fails the build if the analysis producer, the workflows engine and the stage
# workers would render onto different WORKFLOWS_QUEUE names — the silent
# producer/consumer queue-name drift that leaves runs piling up with no
# consumer. Pure `helm template` render check, no cluster required.
on:
workflow_dispatch:
pull_request:
paths:
- 'charts/hub/**'
- 'scripts/check-workflows-queue-consistency.sh'
- '.github/workflows/workflows-queue-consistency.yaml'
permissions:
contents: read
jobs:
check:
runs-on: ubuntu-24.04
steps:
- name: Checkout repository
uses: actions/checkout@v4
- name: Set up Helm
uses: azure/setup-helm@v4
with:
version: v3.16.2
- name: Check WORKFLOWS_QUEUE consistency
run: ./scripts/check-workflows-queue-consistency.sh charts/hub

View File

@@ -2,7 +2,7 @@
Kerberos.io ecosystem can be deployed through Helm charts. Use one of the following charts to boost the installation:
- [Hub](https://github.com/kerberos-io/helm-charts/tree/main/charts/hub) chart
- [Hub](https://github.com/kerberos-io/helm-charts/tree/main/charts/hub)
## Prerequisite

View File

@@ -16,10 +16,10 @@ type: application
# This is the chart version. This version number should be incremented each time you make changes
# to the chart and its templates, including the app version.
# Versions are expected to follow Semantic Versioning (https://semver.org/)
version: 0.55.0
version: 0.130.0
# This is the version number of the application being deployed. This version number should be
# incremented each time you make changes to the application. Versions are not expected to
# follow Semantic Versioning. They should reflect the version the application is using.
# It is recommended to use it with quotes.
appVersion: "1.3.0"
appVersion: "3.3.0"

View File

@@ -37,154 +37,411 @@ Below all configuration options and parameters are listed.
| Name | Description | Value |
| ------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------- | ----- |
| `license` | The license key you received from support@kerberos.io. If not available request one. | `""` |
| `licenseServer.url` | The license server for validating the license of your Kerberos Hub, by default `'"https://license.kerberos.io/verify"'`. | `""` |
| `licenseServer.token` | The license server API token to sign the license validation by default `'214%ˆ#ddfsf@#3rfdsgl_)23sffeqasSwefDSFNBM'`. | `""` |
| `imagePullSecrets.name` | Docker registry secret name, which is also granted with the license. This allows you to download the Docker images. | `""` |
| `isPrivate` | Global StorageClass for Persistent Volume(s) | `""` |
| `environment` | A colored banner will be shown on top of the application to illustrate a non-production environment: `staging`, `demo`, .. | `""` |
| `readOnly` | This will stop any write process to mongodb or any processing done in the Kerberos Hub pipeline. | `""` |
| `ingress` | The ingress being used for `kerberoshub.api.url` and `kerberoshub.frontend.url`. | `""` |
| `mongodb.host` | MongoDB hostname (`'mongodb:27017'`) or mongodb replicas (`'mongodb-0:27017,mongodb-1:27017'`). | `""` |
| `mongodb.adminDatabase` | MongoDB admin database, this is named `admin` by default. | `""` |
| `mongodb.username` | MongoDB user account, we are using in the hub installation `'root'`. | `""` |
| `mongodb.password` | MongoDB user password, by default `'yourmongodbpassword'` | `""` |
| `mqtt.host` | MQTT (Vernemq) hostname. | `""` |
| `mqtt.port` | MQTT (Vernemq) port for WSS (secure sockets), by default `'8443'`. | `""` |
| `mqtt.protocol` | MQTT (Vernemq) protocol, by default `'wss'`. | `""` |
| `mqtt.username` | MQTT (Vernemq) username, by default `'yourusername'`. | `""` |
| `mqtt.password` | MQTT (Vernemq) password, by default `'yourpassword'`. | `""` |
| `queueProvider` | The queue we are using for the [pipeline](https://doc.kerberos.io/hub/pipeline/): 'SQS', 'KAFKA' or `RABBITMQ`. | `""` |
| `queueName` | The event queue which is propagating messages in the [Kerberos Hub pipeline](https://doc.kerberos.io/hub/pipeline/). | `""` |
| `kafka.broker` | Kafka brokers, by default `'kafka1.yourdomain.com:9094,kafka2.yourdomain.com:9094'` | `""` |
| `kafka.username` | Kafka username, by default `'yourusername'` | `""` |
| `kafka.password` | Kafka password, by default `'yourpassword'` | `""` |
| `kafka.mechanism` | Kafka mechanism, by default `'PLAIN'` | `""` |
| `kafka.security` | Kafka security, by default `'SASL_PLAINTEXT'` | `""` |
| `rabbitmq.host` | RabbitMQ host, by default `'rabbitmq.yourdomain.com:5671'` | `""` |
| `rabbitmq.username` | RabbitMQ username, by default `'yourusername'` | `""` |
| `rabbitmq.password` | RabbitMQ password, by default `'yourpassword'` | `""` |
| `rabbitmq.exchange` | RabbitMQ exchange, by default `''` | `""` |
| `turn.host` | TURN/STUN hostname, by default `'turn:turn.yourdomain.com:8443'` | `""` |
| `turn.username` | TURN/STUN username, by default `'username1'` | `""` |
| `turn.password` | TURN/STUN password, by default `'password1'` | `""` |
| `kerberosvault.uri` | The default Kerberos Vault uri (you can add multiple within the app), by default `'https://api.storage.yourdomain.com'` | `""` |
| `kerberosvault.accesskey` | The default Kerberos Vault access key, by default `'xxx'` | `""` |
| `kerberosvault.secretkey` | The default Kerberos Vault secret key, by default `'xxx'` | `""` |
| `kerberosvault.provider` | The default Kerberos Vault provider`'a-provider'` | `""` |
| `kerberosvault.archive.accesskey` | When a task is created, the relevant recording is moved to another provider, using this access key `'xxx'` | `""` |
| `kerberosvault.archive.secretkey` | When a task is created, the relevant recording is moved to another provider, using this secret key`'xxx'` | `""` |
| `kerberosvault.archive.provider` | When a task is created, the relevant recording is moved to this provider `'an-archive-provider'` | `""` |
| `email.provider` | The email service provider for sending out messages over email , use `'mailgun'` or `'smtp'`. | `""` |
| `email.from` | The email address that is sending messages in name of, by default `'support@yourdomain.com'`. | `""` |
| `email.displayName` | The display name that is sending messages in name of, by default `'yourdomain.com'` | `""` |
| `email.mailgun.domain` | While using `mailgun` as email service provider, you will need to provide your Mailgun domain. | `""` |
| `email.mailgun.apiKey` | The Mailgun API key linked to your Mailgun domain. | `""` |
| `email.smtp.server` | While using `smtp` as email service provider, use the SMTP server. | `""` |
| `email.smtp.port` | SMTP port specified by your SMTP server, by default `'456'`. | `""` |
| `email.smtp.username` | SMTP username. | `""` |
| `email.smtp.password` | SMTP password. | `""` |
| `email.templates.detection` | We use templates to send notifications, this allow you to bring your own `Mailgun` templates, by default `'detection'`. | `""` |
| `email.templates.disabled` | The template which is send when an account is disabled due to reaching its upload limit, by default `'disabled'`. | `""` |
| `email.templates.highupload` | The template which is send when an account is reaching a specific upload threshold, by default `'threshold'`. | `""` |
| `email.templates.device` | The template which is send when a camera goes online or offline, by default `'device'`. | `""` |
| `email.templates.welcome` | The template which is send when a new user registered on the platform (`IS_PRIVATE='false'`), by default `'disabled'`. | `""` |
| `email.templates.welcomeTitle` | The welcome title use in the subject of the email. | `""` |
| `email.templates.activate` | The template which is send when a user is required to activate his account , by default `'activate'`. | `""` |
| `email.templates.activateTitle` | The activation title use in the subject of the email. | `""` |
| `email.templates.forgot` | The template which is send when an account is requesting a forgot password, by default `'forgot'`. | `""` |
| `email.templates.forgotTitle` | The forgot title use in the subject of the email. | `""` |
| `kerberoshub.api.repository` | The Docker registry where the Kerberos Hub API container is hosted. | `""` |
| `kerberoshub.api.pullPolicy` | The Docker registry pull policy. | `""` |
| `kerberoshub.api.tag` | The Docker image tag/version. | `""` |
| `kerberoshub.api.replicas` | The number of pods/replicas running for the Kerberos Hub API deployment. | `""` |
| `kerberoshub.api.jwtSecret` | A secret that is for generating JWT tokens. | `""` |
| `kerberoshub.api.schema` | The protocol to serve the Kerberos Hub API, `'http'` or `'https'`. | `""` |
| `kerberoshub.api.url` | The Kerberos Hub API ingress to access the API. | `""` |
| `kerberoshub.api.mfaIssuer` | When enabling the MFA access, this is the name that will be shown in the MFA app. | `""` |
| `kerberoshub.api.tls` | Bring your own TLS certificates for Kerberos Hub API ingress. | `""` |
| `kerberoshub.api.language` | The language of Kerberos Hub API responses, error messages will be communicated in the specified language. | `""` |
| `kerberoshub.api.fallbackLanguage` | The fallback language, if a specific translation is not available. | `""` |
| `kerberoshub.api.slack.enabled` | Slack integration for sending events and notifications coming from the Kerberos Hub API, `'true'` or `'false'`. | `""` |
| `kerberoshub.api.slack.hook` | Slack integration hook url. | `""` |
| `kerberoshub.api.slack.username` | Slack integration username. | `""` |
| `kerberoshub.api.elasticsearch.enabled` | Elasticsearch for storing events coming from the Kerberos Hub API, `'true'` or `'false'` | `""` |
| `kerberoshub.api.elasticsearch.protocol` | Elasticsearch protocol, `'http'` or `'https'`. | `""` |
| `kerberoshub.api.elasticsearch.host` | Elasticsearch host. | `""` |
| `kerberoshub.api.elasticsearch.port` | Elasticsearch port. | `""` |
| `kerberoshub.api.elasticsearch.index` | Elasticsearch index which is used to store the events. | `""` |
| `kerberoshub.api.elasticsearch.username` | Elasticsearch username. | `""` |
| `kerberoshub.api.elasticsearch.password` | Elasticsearch password. | `""` |
| `kerberoshub.api.sso.issuer` | Kerberos Hub can be linked to OpenID Connect for SSO. Specify the OIC issuer. | `""` |
| `kerberoshub.api.sso.clientId` | The OIC client id. | `""` |
| `kerberoshub.api.sso.clientSecret` | The OIC client secret. | `""` |
| `kerberoshub.api.sso.redirectUrl` | The OIC redirectUrl, once the authentication is validated. | `""` |
| `kerberoshub.frontend.repository` | The Docker registry where the Kerberos Hub frontend is hosted. | `""` |
| `kerberoshub.frontend.pullPolicy` | The Docker registry pull policy. | `""` |
| `kerberoshub.frontend.tag` | The Docker image tag/version. | `""` |
| `kerberoshub.frontend.replicas` | The number of pods/replicas running for the Kerberos Hub frontend deployment. | `""` |
| `kerberoshub.frontend.schema` | The protocol to serve the Kerberos Hub frontend, `'http'` or `'https'`. | `""` |
| `kerberoshub.frontend.url` | The Kerberos Hub frontend ingress to access the frontend. | `""` |
| `kerberoshub.frontend.tls` | Bring your own TLS certificates for Kerberos Hub frontend ingress. | `""` |
| `kerberoshub.frontend.ssoDomain` | The domain that's being used to activate SSO from the login page. | `""` |
| `kerberoshub.frontend.logo` | The logo being used in the Kerberos Hub frontend, set to 'custom' if you want to mount your own stylesheet. | `""` |
| `kerberoshub.frontend.mixpanel.apikey` | No longer used. | `""` |
| `kerberoshub.frontend.sentry.url` | No longer used. | `""` |
| `kerberoshub.frontend.posthog.key` | The API key retrieved from the Posthog instance. | `""` |
| `kerberoshub.frontend.posthog.url` | Posthog's endpoint (http/https). | `""` |
| `kerberoshub.frontend.stripe.apikey` | If using the public version, `stripe` can be used for automated billing and subscriptions. | `""` |
| `kerberoshub.frontend.googlemaps.apikey` | Within Kerberos Hub frontend a couple of maps are being used, the google maps is leveraged for that. | `""` |
| `kerberoshub.frontend.zendesk.url` | No longer used. | `""` |
| `kerberoshub.frontend.zendesk.url` | No longer used. | `""` |
| `kerberoshub.frontend.navigationLinkTitle1` | Custom navigation item (title 1) | `""` |
| `kerberoshub.frontend.navigationLinkUrl1` | Custom navigation item (url 1) | `""` |
| `kerberoshub.frontend.navigationLinkTitle2` | Custom navigation item (title 2) | `""` |
| `kerberoshub.frontend.navigationLinkUrl2` | Custom navigation item (url 2) | `""` |
| `kerberoshub.frontend.navigationLinkTitle3` | Custom navigation item (title 3) | `""` |
| `kerberoshub.frontend.navigationLinkUrl3` | Custom navigation item (url 3) | `""` |
| `kerberoshub.frontend.navigationLinkTitle4` | Custom navigation item (title 4) | `""` |
| `kerberoshub.frontend.navigationLinkUrl4` | Custom navigation item (url 4) | `""` |
| `kerberoshub.frontend.navigationLinkTitle5` | Custom navigation item (title 5) | `""` |
| `kerberoshub.frontend.navigationLinkUrl5` | Custom navigation item (url 5) | `""` |
| `kerberoshub.cleanup.repository` | The Docker container that is responsible for cleaning up the Kerberos Hub API content and related MongoDB collections. | `""` |
| `kerberoshub.cleanup.pullPolicy` | The Docker registry pull policy. | `""` |
| `kerberoshub.cleanup.tag` | The Docker image tag/version. | `""` |
| `kerberoshub.forwarder.repository` | The Docker container which orchestrates forwarding coming from different Kerberos Vaults. | `""` |
| `kerberoshub.forwarder.pullPolicy` | The Docker registry pull policy. | `""` |
| `kerberoshub.forwarder.tag` | The Docker image tag/version. | `""` |
| `kerberoshub.monitordevice.repository` | The monitoring microservice, following up the status of your cameras and Kerberos Agents. | `""` |
| `kerberoshub.monitordevice.pullPolicy` | The Docker registry pull policy. | `""` |
| `kerberoshub.monitordevice.tag` | The Docker image tag/version. | `""` |
| `kerberospipeline.event.repository` | The [event orchestration](https://doc.kerberos.io/hub/pipeline/#orchestrator) microservice. | `""` |
| `kerberospipeline.event.pullPolicy` | The Docker registry pull policy. | `""` |
| `kerberospipeline.event.tag` | The Docker image tag/version. | `""` |
| `kerberospipeline.monitor.repository` | The [monitoring microservice](https://doc.kerberos.io/hub/pipeline/#monitoring), calculating metrics of incoming messages. | `""` |
| `kerberospipeline.monitor.pullPolicy` | The Docker registry pull policy. | `""` |
| `kerberospipeline.monitor.tag` | The Docker image tag/version. | `""` |
| `kerberospipeline.sequence.repository` | The [sequencer microservice](https://doc.kerberos.io/hub/pipeline/#sequencer), grouping recordings in chunks/groups. | `""` |
| `kerberospipeline.sequence.pullPolicy` | The Docker registry pull policy. | `""` |
| `kerberospipeline.sequence.tag` | The Docker image tag/version. | `""` |
| `kerberospipeline.throttler.repository` | The [throttler microservice](https://doc.kerberos.io/hub/pipeline/#throttler), throttling events. | `""` |
| `kerberospipeline.throttler.pullPolicy` | The Docker registry pull policy. | `""` |
| `kerberospipeline.throttler.tag` | The Docker image tag/version. | `""` |
| `kerberospipeline.notify.repository` | The [notification microservice](https://doc.kerberos.io/hub/pipeline/#notification), sending notifications on events. | `""` |
| `kerberospipeline.notify.pullPolicy` | The Docker registry pull policy. | `""` |
| `kerberospipeline.notify.tag` | The Docker image tag/version. | `""` |
| `kerberospipeline.notifyTest.repository` | The notification service for testing, the different channels. | `""` |
| `kerberospipeline.notifyTest.pullPolicy` | The Docker registry pull policy. | `""` |
| `kerberospipeline.notifyTest.tag` | The Docker image tag/version. | `""` |
| `kerberospipeline.analysis.repository` | The [analysis microservices](https://doc.kerberos.io/hub/pipeline/#analyser) which executed specific analysis in parallel. | `""` |
| `kerberospipeline.analysis.pullPolicy` | The Docker registry pull policy. | `""` |
| `kerberospipeline.analysis.tag` | The Docker image tag/version. | `""` |
| `kerberospipeline.dominantColor.repository` | The dominant color microservices is computing a top 3 color histogram. | `""` |
| `kerberospipeline.dominantColor.pullPolicy` | The Docker registry pull policy. | `""` |
| `kerberospipeline.dominantColor.tag` | The Docker image tag/version. | `""` |
| `kerberospipeline.thumbnail.repository` | The thumbnail microservices generated a thumbnail for a recordings. | `""` |
| `kerberospipeline.thumbnail.pullPolicy` | The Docker registry pull policy. | `""` |
| `kerberospipeline.thumbnail.tag` | The Docker image tag/version. | `""` |
| `kerberospipeline.counting.repository` | The counting microservices computes objects passing different line segments. | `""` |
| `kerberospipeline.counting.pullPolicy` | The Docker registry pull policy. | `""` |
| `kerberospipeline.counting.tag` | The Docker image tag/version. | `""` |
| `license` | The license key you received from support@kerberos.io. If not available request one. | `"L/+DAwEBB2xpY2Vuc2UB/4QAAQIBB1BheWxvYWQBCgABCVNpZ25hdHVyZQEKAAAA/gMk/4QB/gEZ/8sQACxnaXRodWIuY29tL3V1Zy1haS9odWItbGljZW5zZS9tb2RlbHMuTGljZW5zZX8DAQEHTGljZW5zZQH/gAABDAECSWQB/4IAAQNLZXkBDAABB0NvbXBhbnkBDAABB0V4cFRpbWUBBAABBERheXMBBAABB0NhbWVyYXMBBAABBVNpdGVzAQQAAQZWYXVsdHMBBAABCk1lZGlhTGltaXQBBAABCVBlcnBldHVhbAECAAEGQWN0aXZlAQIAAQlJcEFkZHJlc3MBDAAAABj/gQEBAQhPYmplY3RJRAH/ggABBgEYAAAy/4AvAQwAAAAAAAAAAAAAAAACDGZyZWUtbGljZW5zZQH81iZi6gH+AtoBEAEUARQDAQAB/gIAfeXxQb6kaPfAgOWeSAE6qEiQviFD6sciNmNfMel1mEL53FeV0GQe4cYBip9wyJag35az8A1yppxSymZD5V4my2FckyN2zmEW4E2sO/v+8eKepiAGYEzrKtfNCLxdWLmrHd0zjYQ3qk+PNfoPyzCOefeulw3aFsqBlzg9wDkF8cRx6tUW0qNTzki6sFGOuLoxS49cWqsftAvZmt+CRWa8u0VArIAjOpywN0RIZCkEYzp5RYF3LSVyWYEyvVhjE19DDnevzpJyCHRsIHTRcpTQkhboeapOdlEz8cx+PaOvxktN8hBWceTAH+nw96FARG7y6Cpjw3xo+NV1xb0tvRXGaGoK77JnErKLhd/haXji98rGvMakDt18WSbQfTVS84+Fw+/gKGsW3uS3fROAaZw1kZj4PgsEPZDvbVkCVyuS0O87UoYqpxH8S4by8cTF3wDP7FwyIRZbEbYjN2wzHSmlADYOBtdsdb1VGm7wvtB85vML9n7ZSlIpJdqfci06mGks102mDyG2LRMhUEvpUW3D/weErIvj2WiAwf6r0EUj+LO8VmAsYkME9da7FXEN6Vg/5f1u485LOpYki332RaDOhDn2eMG9DVb/HnmQSFagX+XXc/QwfsWiehCgKYGk4jQpyklTqoGu8BAt6Sm8CaoH8ngZ3cHLQT5DcZElV36/N/wA"` |
| `licenseServer.url` | The license server for validating the license of your Kerberos Hub, by default `'"https://license.kerberos.io/verify"'`. | `""` |
| `licenseServer.token` | The license server API token to sign the license validation by default `'214%ˆ#ddfsf@#3rfdsgl_)23sffeqasSwefDSFNBM'`. | `""` |
| `environment` | A colored banner will be shown on top of the application to illustrate a non-production environment: `staging`, `demo`, .. | `"production"` |
| `isPrivate` | Global StorageClass for Persistent Volume(s) | `true` |
| `readOnly` | This will stop any write process to mongodb or any processing done in the Kerberos Hub pipeline. | `false` |
| `mode` | Deployment mode: `all`, `pipeline`, or `ui`. `all` renders everything, `pipeline` only pipeline services, `ui` only hub services. | `"all"` |
| `global.imageRegistry` | Global container registry override used for all images. | `""` |
| `ingress` | The ingress being used for `kerberoshub.api.url` and `kerberoshub.frontend.url`. | `"nginx"` |
| `mongodb.host` | MongoDB hostname (`'mongodb:27017'`) or mongodb replicas (`'mongodb-0:27017,mongodb-1:27017'`). | `"mongodb.mongodb"` |
| `mongodb.adminDatabase` | MongoDB admin database, this is named `admin` by default. | `"admin"` |
| `mongodb.authenticationMechanism` | MongoDB authentication mechanism (for example `SCRAM-SHA-256`). | `"SCRAM-SHA-256"` |
| `mongodb.username` | MongoDB user account, we are using in the hub installation `'root'`. | `"yourusername"` |
| `mongodb.password` | MongoDB user password, by default `'yourmongodbpassword'` | `"yourpassword"` |
| `mongodb.retryWrites` | Enable or disable MongoDB retryable writes. | `"true"` |
| `mongodb.flavor` | Backend engine flavor: `"mongodb"` (native MongoDB / Atlas) or `"documentdb"` (AWS DocumentDB). The `documentdb` flavor disables features DocumentDB does not support (geospatial queries/indexes, complex `$lookup` pipelines). When set to `documentdb`, also set `mongodb.retryWrites: "false"`. | `"mongodb"` |
| `mongodb.tls.enabled` | Enable TLS for MongoDB connections. When `mongodb.uri` is set, the chart appends missing `tls=true` and `tlsCAFile` query parameters. | `false` |
| `mongodb.tls.existingSecret` | Existing Kubernetes Secret containing the MongoDB CA bundle. The Secret is mounted into every workload that consumes `mongodb-config`. | `""` |
| `mongodb.tls.caFileName` | Key and filename of the CA bundle in `mongodb.tls.existingSecret` (for AWS DocumentDB, typically `global-bundle.pem`). | `""` |
| `mongodb.tls.mountPath` | Read-only directory where the MongoDB CA Secret is mounted. | `"/etc/mongodb/tls"` |
| `mongodb.tls.insecureSkipVerify` | Skip MongoDB certificate and hostname verification. This is insecure and intended only for local testing. | `false` |
| `mqtt.host` | MQTT (Vernemq) hostname. | `"mqtt.yourdomain.com"` |
| `mqtt.port` | MQTT (Vernemq) port for WSS (secure sockets), by default `'8443'`. | `"8443"` |
| `mqtt.protocol` | MQTT (Vernemq) protocol, by default `'wss'`. | `"wss"` |
| `mqtt.username` | MQTT (Vernemq) username, by default `'yourusername'`. | `"yourusername"` |
| `mqtt.password` | MQTT (Vernemq) password, by default `'yourpassword'`. | `"yourpassword"` |
| `mqtt.legacy.host` | Legacy MQTT broker host used for backward-compatible clients. | `""` |
| `mqtt.legacy.port` | Legacy MQTT broker port used for backward-compatible clients. | `""` |
| `queueProvider` | The queue we are using for the [pipeline](https://doc.kerberos.io/hub/pipeline/): 'SQS', 'KAFKA' or `RABBITMQ`. | `"RABBITMQ"` |
| `queueName` | The event queue which is propagating messages in the [Kerberos Hub pipeline](https://doc.kerberos.io/hub/pipeline/). | `"kcloud-event-queue"` |
| `rabbitmq.host` | RabbitMQ host, by default `'rabbitmq.yourdomain.com:5671'` | `"rabbitmq.rabbitmq:5672"` |
| `rabbitmq.username` | RabbitMQ username, by default `'yourusername'` | `"yourusername"` |
| `rabbitmq.password` | RabbitMQ password, by default `'yourpassword'` | `"yourpassword"` |
| `rabbitmq.exchange` | RabbitMQ exchange, by default `''` | `""` |
| `kafka.broker` | Kafka brokers, by default `'kafka1.yourdomain.com:9094,kafka2.yourdomain.com:9094'` | `"kafka1.yourdomain.com:9094"` |
| `kafka.username` | Kafka username, by default `'yourusername'` | `"yourusername"` |
| `kafka.password` | Kafka password, by default `'yourpassword'` | `"yourpassword"` |
| `kafka.mechanism` | Kafka mechanism, by default `'PLAIN'` | `"PLAIN"` |
| `kafka.security` | Kafka security, by default `'SASL_PLAINTEXT'` | `"SASL_PLAINTEXT"` |
| `turn.host` | TURN/STUN hostname, by default `'turn:turn.yourdomain.com:8443'` | `"turn:turn.yourdomain.com:8443"` |
| `turn.username` | TURN/STUN username, by default `'username1'` | `"username1"` |
| `turn.password` | TURN/STUN password, by default `'password1'` | `"password1"` |
| `opentelemetry.enabled` | Enable or disable OpenTelemetry instrumentation. | `false` |
| `opentelemetry.routingEnabled` | Enable or disable OpenTelemetry routing/export behavior. | `false` |
| `opentelemetry.collector.endpoint` | OpenTelemetry collector endpoint used for trace export. | `"http://otel-collector:4317"` |
| `openai.enabled` | Enable or disable OpenAI-backed semantic features. | `false` |
| `openai.apikey` | OpenAI API key used when OpenAI integration is enabled. | `"xxx"` |
| `kerberosvault.uri` | The default Kerberos Vault uri (you can add multiple within the app), by default `'https://api.storage.yourdomain.com'` | `"https://api.vault.yourdomain.com"` |
| `kerberosvault.provider` | The default Kerberos Vault provider`'a-provider'` | `"a-provider"` |
| `kerberosvault.accesskey` | The default Kerberos Vault access key, by default `'xxx'` | `"xxx"` |
| `kerberosvault.secretkey` | The default Kerberos Vault secret key, by default `'xxx'` | `"xxx"` |
| `kerberosvault.archive.provider` | When a task is created, the relevant recording is moved to this provider `'an-archive-provider'` | `"an-archive-provider"` |
| `kerberosvault.archive.accesskey` | When a task is created, the relevant recording is moved to another provider, using this access key `'xxx'` | `"xxx"` |
| `kerberosvault.archive.secretkey` | When a task is created, the relevant recording is moved to another provider, using this secret key`'xxx'` | `"xxx"` |
| `kerberosvault.thumbnail.provider` | Configuration value for `kerberosvault.thumbnail.provider`. | `"a-thumbnail-provider"` |
| `kerberosvault.thumbnail.accessKey` | Access key for `kerberosvault.thumbnail`. | `"xxx"` |
| `kerberosvault.thumbnail.secretKey` | Secret key for `kerberosvault.thumbnail`. | `"xxx"` |
| `kerberosvault.sprite.provider` | Configuration value for `kerberosvault.sprite.provider`. | `"a-sprite-provider"` |
| `kerberosvault.sprite.accessKey` | Access key for `kerberosvault.sprite`. | `"xxx"` |
| `kerberosvault.sprite.secretKey` | Secret key for `kerberosvault.sprite`. | `"xxx"` |
| `admin.repository` | Container image repository for `admin`. | `"uugai/admin"` |
| `admin.pullPolicy` | Image pull policy for `admin`. | `"IfNotPresent"` |
| `admin.tag` | Container image tag/version for `admin`. | `"v1.3.0"` |
| `admin.replicas` | Number of replicas for `admin`. | `2` |
| `admin.logLevel` | Log verbosity level for `admin`. | `"info"` |
| `admin.resources.requests.memory` | Memory request for `admin`. | `"100Mi"` |
| `admin.resources.requests.cpu` | CPU request for `admin`. | `"250m"` |
| `admin.url` | URL for `admin`. | `"admin.yourdomain.com"` |
| `admin.tls.secretName` | Kubernetes Secret name used by `admin.tls`. | `""` |
| `admin.oauth2Proxy.enabled` | Enable or disable `admin.oauth2Proxy`. | `false` |
| `admin.oauth2Proxy.github.clientId` | Client ID used by `admin.oauth2Proxy.github`. | `"github-client-id"` |
| `admin.oauth2Proxy.github.clientSecret` | Client secret used by `admin.oauth2Proxy.github`. | `"github-client-secret"` |
| `admin.oauth2Proxy.github.cookieSecret` | Cookie secret used by `admin.oauth2Proxy.github`. | `"generate-a-random-cookie-secret"` |
| `admin.oauth2Proxy.github.organization` | Organization value used by `admin.oauth2Proxy.github`. | `"github-organization"` |
| `admin.oauth2Proxy.github.team` | Team value used by `admin.oauth2Proxy.github`. | `"github-team"` |
| `kerberoshub.extraEnv` | Additional environment variables injected into Kerberos Hub pods. | `[]` |
| `kerberoshub.serviceAccount.create` | Create or manage `kerberoshub.serviceAccount` resources. | `false` |
| `kerberoshub.serviceAccount.name` | Name value for `kerberoshub.serviceAccount`. | `""` |
| `kerberoshub.serviceAccount.annotations` | Annotations applied to `kerberoshub.serviceAccount` resources. | `""` |
| `kerberoshub.serviceAccount.labels` | Labels applied to `kerberoshub.serviceAccount` resources. | `""` |
| `kerberoshub.api.repository` | The Docker registry where the Kerberos Hub API container is hosted. | `"ghcr.io/uug-ai/hub-api"` |
| `kerberoshub.api.pullPolicy` | The Docker registry pull policy. | `"IfNotPresent"` |
| `kerberoshub.api.tag` | The Docker image tag/version. | `"v1.9.8"` |
| `kerberoshub.api.replicas` | The number of pods/replicas running for the Kerberos Hub API deployment. | `2` |
| `kerberoshub.api.logLevel` | Log verbosity level for `kerberoshub.api`. | `"info"` |
| `kerberoshub.api.jwtSecret` | A secret that is for generating JWT tokens. | `"this-is-a-secret-please-change-to-random-string"` |
| `kerberoshub.api.schema` | The protocol to serve the Kerberos Hub API, `'http'` or `'https'`. | `"https"` |
| `kerberoshub.api.url` | The Kerberos Hub API ingress to access the API. | `"api.yourdomain.com"` |
| `kerberoshub.api.resources.requests.memory` | Memory request for `kerberoshub.api`. | `"100Mi"` |
| `kerberoshub.api.resources.requests.cpu` | CPU request for `kerberoshub.api`. | `"250m"` |
| `kerberoshub.api.resources.limits.memory` | Memory limit for `kerberoshub.api`. | `"100Mi"` |
| `kerberoshub.api.resources.limits.cpu` | CPU limit for `kerberoshub.api`. | `"250m"` |
| `kerberoshub.api.serverTLS.enabled` | Enable or disable `kerberoshub.api.serverTLS`. | `false` |
| `kerberoshub.api.serverTLS.secretName` | Kubernetes Secret name used by `kerberoshub.api.serverTLS`. | `""` |
| `kerberoshub.api.serverTLS.mountPath` | Filesystem path where the Hub API TLS secret is mounted. | `"/etc/hub-api/tls"` |
| `kerberoshub.api.serverTLS.certFile` | Path to the TLS certificate file used by Hub API server-side TLS. | `"/etc/hub-api/tls/tls.crt"` |
| `kerberoshub.api.serverTLS.keyFile` | Path to the TLS private key file used by Hub API server-side TLS. | `"/etc/hub-api/tls/tls.key"` |
| `kerberoshub.api.mfaIssuer` | When enabling the MFA access, this is the name that will be shown in the MFA app. | `"yourdomain.com"` |
| `kerberoshub.api.apiKey` | API key for `kerberoshub.api`. | `"a-random-admin-api-key"` |
| `kerberoshub.api.defaultTaskRetentionDays` | Default retention (in days) applied to tasks without an explicit `retention_days`. New tasks are stamped with this value. Set to `"0"` or a negative value to keep tasks indefinitely. Must match `kerberoshub.cleanup.defaultTaskRetentionDays`. | `"0"` |
| `kerberoshub.api.tls` | Bring your own TLS certificates for Kerberos Hub API ingress. | `<list>` |
| `kerberoshub.api.tls.secretName` | Kubernetes Secret name used by `kerberoshub.api.tls`. | `""` |
| `kerberoshub.api.language` | The language of Kerberos Hub API responses, error messages will be communicated in the specified language. | `"english"` |
| `kerberoshub.api.fallbackLanguage` | The fallback language, if a specific translation is not available. | `"english"` |
| `kerberoshub.api.aws.region` | AWS region used by the Hub API legacy S3 integration. | `"xxx"` |
| `kerberoshub.api.aws.bucket` | AWS S3 bucket used by the Hub API legacy S3 integration. | `"xxx"` |
| `kerberoshub.api.aws.accessKey` | Access key for `kerberoshub.api.aws`. | `"xxx"` |
| `kerberoshub.api.aws.secretKey` | Secret key for `kerberoshub.api.aws`. | `"xxx"` |
| `kerberoshub.api.stripe.privateKey` | Private key for `kerberoshub.api.stripe`. | `"xxx"` |
| `kerberoshub.api.slack.enabled` | Slack integration for sending events and notifications coming from the Kerberos Hub API, `'true'` or `'false'`. | `"true"` |
| `kerberoshub.api.slack.hook` | Slack integration hook url. | `"yourslackhook"` |
| `kerberoshub.api.slack.username` | Slack integration username. | `"Kerberos Hub"` |
| `kerberoshub.api.elasticsearch.enabled` | Elasticsearch for storing events coming from the Kerberos Hub API, `'true'` or `'false'` | `"false"` |
| `kerberoshub.api.elasticsearch.protocol` | Elasticsearch protocol, `'http'` or `'https'`. | `"http"` |
| `kerberoshub.api.elasticsearch.host` | Elasticsearch host. | `"yourelasticsearchinstance.com"` |
| `kerberoshub.api.elasticsearch.port` | Elasticsearch port. | `"9200"` |
| `kerberoshub.api.elasticsearch.index` | Elasticsearch index which is used to store the events. | `"kerberos-cloud"` |
| `kerberoshub.api.elasticsearch.username` | Elasticsearch username. | `""` |
| `kerberoshub.api.elasticsearch.password` | Elasticsearch password. | `""` |
| `kerberoshub.api.sso.redirectUrl` | The OIC redirectUrl, once the authentication is validated. | `""` |
| `kerberoshub.api.sso.forceSSO` | Force SSO login for users of the configured domain. | `""` |
| `kerberoshub.api.sso.issuer` | Kerberos Hub can be linked to OpenID Connect for SSO. Specify the OIC issuer. | `""` |
| `kerberoshub.api.sso.claimId` | OIDC claim used to uniquely identify the authenticated user. | `""` |
| `kerberoshub.api.sso.clientId` | The OIC client id. | `""` |
| `kerberoshub.api.sso.clientSecret` | The OIC client secret. | `""` |
| `kerberoshub.api.sso.clientVerificationId` | Optional client verification ID used for SSO chaining scenarios. | `""` |
| `kerberoshub.api.sso.extraHeaders` | Additional headers appended to outbound SSO provider requests. | `""` |
| `kerberoshub.api.sso.extraHeaders.value` | Header value for each configured SSO extra header entry. | `""` |
| `kerberoshub.frontend.repository` | The Docker registry where the Kerberos Hub frontend is hosted. | `"ghcr.io/uug-ai/hub-frontend"` |
| `kerberoshub.frontend.pullPolicy` | The Docker registry pull policy. | `"IfNotPresent"` |
| `kerberoshub.frontend.tag` | The Docker image tag/version. | `"v1.9.11"` |
| `kerberoshub.frontend.replicas` | The number of pods/replicas running for the Kerberos Hub frontend deployment. | `2` |
| `kerberoshub.frontend.logLevel` | Log verbosity level for `kerberoshub.frontend`. | `"info"` |
| `kerberoshub.frontend.schema` | The protocol to serve the Kerberos Hub frontend, `'http'` or `'https'`. | `"https"` |
| `kerberoshub.frontend.url` | The Kerberos Hub frontend ingress to access the frontend. | `"yourdomain.com"` |
| `kerberoshub.frontend.resources.requests.memory` | Memory request for `kerberoshub.frontend`. | `"50Mi"` |
| `kerberoshub.frontend.resources.requests.cpu` | CPU request for `kerberoshub.frontend`. | `"50m"` |
| `kerberoshub.frontend.resources.limits.memory` | Memory limit for `kerberoshub.frontend`. | `"50Mi"` |
| `kerberoshub.frontend.resources.limits.cpu` | CPU limit for `kerberoshub.frontend`. | `"50m"` |
| `kerberoshub.frontend.tls` | Bring your own TLS certificates for Kerberos Hub frontend ingress. | `<list>` |
| `kerberoshub.frontend.tls.secretName` | Kubernetes Secret name used by `kerberoshub.frontend.tls`. | `""` |
| `kerberoshub.frontend.mixpanel.apikey` | No longer used. | `"xxx"` |
| `kerberoshub.frontend.sentry.url` | No longer used. | `"https://xxx@sentry.io/xxx"` |
| `kerberoshub.frontend.stripe.publicKey` | Public key for `kerberoshub.frontend.stripe`. | `""` |
| `kerberoshub.frontend.googlemaps.apikey` | Within Kerberos Hub frontend a couple of maps are being used, the google maps is leveraged for that. | `"xxxx"` |
| `kerberoshub.frontend.zendesk.url` | No longer used. | `"yourdomain.zendesk.com"` |
| `kerberoshub.frontend.posthog.key` | The API key retrieved from the Posthog instance. | `"xxx"` |
| `kerberoshub.frontend.posthog.url` | Posthog's endpoint (http/https). | `"https://posthog.domain.com"` |
| `kerberoshub.frontend.hideAddAgent` | Configuration value for `kerberoshub.frontend.hideAddAgent`. | `"false"` |
| `kerberoshub.frontend.multiTenant` | Configuration value for `kerberoshub.frontend.multiTenant`. | `false` |
| `kerberoshub.frontend.title` | Title text used for `kerberoshub.frontend`. | `"Kerberos Hub - Video surveillance as it should be"` |
| `kerberoshub.frontend.logo` | The logo being used in the Kerberos Hub frontend, set to 'custom' if you want to mount your own stylesheet. | `"custom"` |
| `kerberoshub.frontend.navigationLinkTitle1` | Custom navigation item (title 1) | `""` |
| `kerberoshub.frontend.navigationLinkUrl1` | Custom navigation item (url 1) | `""` |
| `kerberoshub.frontend.navigationLinkTitle2` | Custom navigation item (title 2) | `""` |
| `kerberoshub.frontend.navigationLinkUrl2` | Custom navigation item (url 2) | `""` |
| `kerberoshub.frontend.navigationLinkTitle3` | Custom navigation item (title 3) | `""` |
| `kerberoshub.frontend.navigationLinkUrl3` | Custom navigation item (url 3) | `""` |
| `kerberoshub.frontend.navigationLinkTitle4` | Custom navigation item (title 4) | `""` |
| `kerberoshub.frontend.navigationLinkUrl4` | Custom navigation item (url 4) | `""` |
| `kerberoshub.frontend.navigationLinkTitle5` | Custom navigation item (title 5) | `""` |
| `kerberoshub.frontend.navigationLinkUrl5` | Custom navigation item (url 5) | `""` |
| `kerberoshub.frontend.caseFilterAssigneesDefault` | Default assignee filter behavior for cases in the frontend. | `"false"` |
| `kerberoshub.frontend.features.case.enabled` | Enable or disable the case feature in the frontend. | `"true"` |
| `kerberoshub.frontend.features.darkModeEnabled` | Enable or disable dark mode in the frontend. | `"true"` |
| `kerberoshub.frontend.features.splashScreen.enabled` | Enable or disable the pre-bootstrap splash screen and reveal delay. | `"true"` |
| `kerberoshub.frontend.features.landingPage` | Frontend landing page configuration. | `"/dashboard"` |
| `kerberoshub.frontend.features.i18n.enabled` | Enable or disable the runtime language switcher in the front-end. When `"false"`, `defaultLanguage` is forced and users cannot change it. | `"true"` |
| `kerberoshub.frontend.features.i18n.defaultLanguage` | Default language code used by the front-end (e.g. `en`, `nl`, `pl`, `tr`, `fr`, `sv`, `de`). | `"en"` |
| `kerberoshub.frontend.features.workflows.enabled` | Enable or disable the workflows feature in the frontend. | `"false"` |
| `kerberoshub.frontend.features.organisations.enabled` | Enable or disable all organisation feature flags. When empty, the child settings apply independently. | `""` |
| `kerberoshub.frontend.features.organisations.switcherEnabled` | Enable or disable the organisation dropdown and switching. The current organisation remains visible when disabled. | `"false"` |
| `kerberoshub.frontend.features.organisations.creationEnabled` | Enable or disable organisation creation. Requires organisation switching to be enabled. | `"false"` |
| `kerberoshub.frontend.features.organisations.settingsEnabled` | Enable or disable the organisation identity link to organisation settings. | `"false"` |
| `kerberoshub.frontend.features.projects.enabled` | Enable or disable all project feature flags. When empty, the child settings apply independently. | `""` |
| `kerberoshub.frontend.features.projects.switcherEnabled` | Enable or disable the read-only project dropdown. | `"false"` |
| `kerberoshub.frontend.features.projects.creationEnabled` | Reserved for the project creation UI. | `"false"` |
| `kerberoshub.frontend.features.projects.settingsEnabled` | Reserved for the project settings UI. | `"false"` |
| `kerberoshub.frontend.features.map.tileUrlLight` | Tile URL used by the map in light mode. | `"https://{s}.basemaps.cartocdn.com/rastertiles/voyager/{z}/{x}/{y}{r}.png"` |
| `kerberoshub.frontend.features.map.tileUrlDark` | Tile URL used by the map in dark mode. | `"https://{s}.basemaps.cartocdn.com/dark_all/{z}/{x}/{y}{r}.png"` |
| `kerberoshub.frontend.features.map.attribution` | Attribution text displayed on the map tiles. | `"&copy; <a href='https://www.openstreetmap.org/copyright' target='_blank'>OpenStreetMap</a>"` |
| `kerberoshub.frontend.features.liveview.defaultStreamMode` | Liveview behavior setting: `defaultStreamMode`. | `"SD"` |
| `kerberoshub.frontend.features.liveview.liveStreamMode` | Transport backing LIVE mode: `webrtc`, `hls`, or `moq`. | `"webrtc"` |
| `kerberoshub.frontend.features.liveview.hlsEnabled` | Offer HLS as a selectable LIVE transport. | `"true"` |
| `kerberoshub.frontend.features.liveview.moqEnabled` | Offer MoQ as a selectable LIVE transport. | `"false"` |
| `kerberoshub.frontend.features.liveview.moqRelayUrl` | WebTransport URL of the MoQ relay. | `"https://relay.uug.ai/anon"` |
| `kerberoshub.frontend.features.liveview.moqBroadcastPrefix` | Prefix used to build MoQ broadcast names. | `"devices"` |
| `kerberoshub.frontend.features.liveview.paginationMode` | Liveview behavior setting: `paginationMode` (`scroll`, `numbered` or `maxStreams`). | `"scroll"` |
| `kerberoshub.frontend.features.liveview.pageSize` | Liveview behavior setting: `pageSize` (max streams shown per page in `numbered` mode). | `"6"` |
| `kerberoshub.frontend.features.liveview.maxStreams` | Liveview behavior setting: `maxStreams`. | `"-1"` |
| `kerberoshub.frontend.features.chart.colorChartSelectionFill` | Fill color for chart selection regions. | `"rgba(132, 86, 159, 0.07)"` |
| `kerberoshub.frontend.features.chart.colorChartSelectionStroke` | Stroke color for chart selection regions. | `"rgba(132, 86, 159, 0.4)"` |
| `kerberoshub.frontend.features.chart.colorChartGridStroke` | Stroke color for chart grid lines. | `"rgba(0, 106, 255, 0.18)"` |
| `kerberoshub.frontend.features.devices.hideAgent` | Hide agent controls in the devices section of the frontend. | `"false"` |
| `kerberoshub.frontend.features.media.filter.date.enabled` | Enable or disable `kerberoshub.frontend.features.media.filter.date`. | `"true"` |
| `kerberoshub.frontend.features.media.filter.sites.enabled` | Enable or disable `kerberoshub.frontend.features.media.filter.sites`. | `"true"` |
| `kerberoshub.frontend.features.media.filter.groups.enabled` | Enable or disable `kerberoshub.frontend.features.media.filter.groups`. | `"true"` |
| `kerberoshub.frontend.features.media.filter.devices.enabled` | Enable or disable `kerberoshub.frontend.features.media.filter.devices`. | `"true"` |
| `kerberoshub.frontend.features.media.filter.objectDetection.enabled` | Enable or disable `kerberoshub.frontend.features.media.filter.objectDetection`. | `"true"` |
| `kerberoshub.frontend.features.media.filter.star.enabled` | Enable or disable `kerberoshub.frontend.features.media.filter.star`. | `"true"` |
| `kerberoshub.frontend.features.media.filter.region.enabled` | Enable or disable `kerberoshub.frontend.features.media.filter.region`. | `"true"` |
| `kerberoshub.frontend.features.media.filter.sort.enabled` | Enable or disable `kerberoshub.frontend.features.media.filter.sort`. | `"true"` |
| `kerberoshub.frontend.features.media.filter.category.enabled` | Enable or disable `kerberoshub.frontend.features.media.filter.category`. | `"true"` |
| `kerberoshub.frontend.features.media.filter.markers.enabled` | Enable or disable `kerberoshub.frontend.features.media.filter.markers`. | `"true"` |
| `kerberoshub.frontend.features.media.filter.events.enabled` | Enable or disable `kerberoshub.frontend.features.media.filter.events`. | `"true"` |
| `kerberoshub.frontend.features.liveview.defaultStreamMode` | Default live stream mode: `SD` or `HD`. | `"SD"` |lter.tags`. | `"true"` |
| `kerberoshub.frontend.features.media.filter.defaultView` | Default view for the media page: `timeline` or `grid`. | `"timeline"` |
| `kerberoshub.frontend.features.floorplan.enabled` | Enable or disable `kerberoshub.frontend.features.floorplan`. | `"true"` |
| `kerberoshub.frontend.features.floorplan.colorDeviceActive` | Color customization for `floorplan` in the frontend. | `"hsla(131, 31%, 52%, 1)"` |
| `kerberoshub.frontend.features.floorplan.colorDeviceInactive` | Color customization for `floorplan` in the frontend. | `"hsla(0, 3%, 41%, 1)"` |
| `kerberoshub.frontend.features.floorplan.colorDeviceIdle` | Color customization for `floorplan` in the frontend. | `"hsla(47, 86%, 47%, 1)"` |
| `kerberoshub.frontend.features.floorplan.colorDeviceMotion` | Color customization for `floorplan` in the frontend. | `"hsla(2, 58%, 48%, 1)"` |
| `kerberoshub.frontend.features.floorplan.colorLiveViewControlActive` | Color customization for `floorplan` in the frontend. | `"hsla(131, 31%, 52%, 1)"` |
| `kerberoshub.frontend.features.floorplan.colorLiveViewControlMotion` | Color customization for `floorplan` in the frontend. | `"hsla(2, 58%, 48%, 1)"` |
| `kerberoshub.frontend.features.floorplan.colorFloorPlanLabelText` | Color customization for `floorplan` in the frontend. | `"hsla(0, 0%, 100%, 1)"` |
| `kerberoshub.frontend.features.floorplan.colorFloorPlanLabelBackground` | Color customization for `floorplan` in the frontend. | `"hsla(0, 0%, 0%, 0.8)"` |
| `kerberoshub.frontend.features.floorplan.colorDeviceMarkerBorder` | Color customization for `floorplan` in the frontend. | `"hsla(0, 0%, 100%, 1)"` |
| `kerberoshub.frontend.features.floorplan.colorTrackBox` | Color customization for `floorplan` in the frontend. | `"hsla(278, 30%, 48%, 1)"` |
| `kerberoshub.frontend.features.floorplan.colorTrackBoxHover` | Color customization for `floorplan` in the frontend. | `"hsla(47, 86%, 47%, 1)"` |
| `kerberoshub.frontend.features.floorplan.colorTrackBoxDrawing` | Color customization for `floorplan` in the frontend. | `"hsla(204, 100%, 50%, 1)"` |
| `kerberoshub.frontend.features.floorplan.colorTrackBoxControlsDelete` | Color customization for `floorplan` in the frontend. | `"hsla(219, 100%, 94%, 1)"` |
| `kerberoshub.frontend.features.faceRedaction.enabled` | Enable or disable `kerberoshub.frontend.features.faceRedaction`. | `"false"` |
| `kerberoshub.frontend.features.faceRedaction.classifierTracksEnabled` | Make classifier-generated tracks available in the redaction modal. | `"true"` |
| `kerberoshub.support.enabled` | Enable or disable in-app support features. | `false` |
| `kerberoshub.oauth2Proxy.enabled` | Enable or disable `kerberoshub.oauth2Proxy`. | `false` |
| `kerberoshub.oauth2Proxy.github.clientId` | Client ID used by `kerberoshub.oauth2Proxy.github`. | `"github-client-id"` |
| `kerberoshub.oauth2Proxy.github.clientSecret` | Client secret used by `kerberoshub.oauth2Proxy.github`. | `"github-client-secret"` |
| `kerberoshub.oauth2Proxy.github.cookieSecret` | Cookie secret used by `kerberoshub.oauth2Proxy.github`. | `"generate-a-random-cookie-secret"` |
| `kerberoshub.oauth2Proxy.github.organization` | Organization value used by `kerberoshub.oauth2Proxy.github`. | `"github-organization"` |
| `kerberoshub.oauth2Proxy.github.team` | Team value used by `kerberoshub.oauth2Proxy.github`. | `"github-team"` |
| `kerberoshub.cleanup.repository` | The Docker container that is responsible for cleaning up the Kerberos Hub API content and related MongoDB collections. | `"ghcr.io/uug-ai/hub-cleanup"` |
| `kerberoshub.cleanup.pullPolicy` | The Docker registry pull policy. | `"IfNotPresent"` |
| `kerberoshub.cleanup.tag` | The Docker image tag/version. | `"v1.4.13"` |
| `kerberoshub.cleanup.replicas` | Number of replicas for `kerberoshub.cleanup`. | `1` |
| `kerberoshub.cleanup.mode` | Cleanup service mode: `serve`, `dry-run`, or `version`. | `"serve"` |
| `kerberoshub.cleanup.logLevel` | Log verbosity level for `kerberoshub.cleanup`. | `"info"` |
| `kerberoshub.cleanup.maxDays` | Hard maximum age (in days) used by the optional global cleanup pass. | `"365"` |
| `kerberoshub.cleanup.runIntervalMinutes` | Minutes between cleanup cycles. | `"10"` |
| `kerberoshub.cleanup.cleanupUsernames` | Optional comma-separated usernames to target. | `""` |
| `kerberoshub.cleanup.batchSize` | Delete batch size per collection operation. | `"250"` |
| `kerberoshub.cleanup.userBatchSize` | Number of users processed per inner batch. | `"100"` |
| `kerberoshub.cleanup.maxUsersPerRun` | Maximum users processed per run. | `"100"` |
| `kerberoshub.cleanup.progressEvery` | Print progress every N processed users. | `"100"` |
| `kerberoshub.cleanup.activeUserRescanHours` | Rescan interval for active users. | `"6"` |
| `kerberoshub.cleanup.inactiveUserRescanHours` | Rescan interval for inactive users. | `"24"` |
| `kerberoshub.cleanup.readTimeoutSeconds` | Timeout for MongoDB read operations. | `"30"` |
| `kerberoshub.cleanup.deleteTimeoutSeconds` | Timeout for delete operations. | `"120"` |
| `kerberoshub.cleanup.reportIncludeStats` | Include richer per-user dry-run summary stats. | `"false"` |
| `kerberoshub.cleanup.dryRun` | Force dry-run behavior through env var. | `"false"` |
| `kerberoshub.cleanup.debug` | Enable extra cleanup debug logging. | `"false"` |
| `kerberoshub.cleanup.globalPassEnabled` | Enable optional global orphan cleanup pass. | `"false"` |
| `kerberoshub.cleanup.globalPassIntervalHours` | Minimum hours between global cleanup passes. | `"0"` |
| `kerberoshub.cleanup.globalPassDeleteBudget` | Max documents deleted during a global pass. | `"0"` |
| `kerberoshub.cleanup.defaultTaskRetentionDays` | Default retention (in days) applied to tasks without an explicit `retention_days`. Tasks older than this (anchored on `creation_date`) are deleted with their `case_media` rows. Set to `"0"` or a negative value to keep tasks forever. Must match `kerberoshub.api.defaultTaskRetentionDays`. | `"0"` |
| `kerberoshub.cleanup.resources.requests.memory` | Memory request for `kerberoshub.cleanup`. | `"10Mi"` |
| `kerberoshub.cleanup.resources.requests.cpu` | CPU request for `kerberoshub.cleanup`. | `"10m"` |
| `kerberoshub.monitordevice.repository` | The monitoring microservice, following up the status of your cameras and Kerberos Agents. | `"ghcr.io/uug-ai/hub-monitor-device"` |
| `kerberoshub.monitordevice.pullPolicy` | The Docker registry pull policy. | `"IfNotPresent"` |
| `kerberoshub.monitordevice.tag` | The Docker image tag/version. | `"v1.4.0"` |
| `kerberoshub.monitordevice.replicas` | Number of replicas for `kerberoshub.monitordevice`. | `1` |
| `kerberoshub.monitordevice.logLevel` | Log verbosity level for `kerberoshub.monitordevice`. | `"info"` |
| `kerberoshub.monitordevice.resources.requests.memory` | Memory request for `kerberoshub.monitordevice`. | `"10Mi"` |
| `kerberoshub.monitordevice.resources.requests.cpu` | CPU request for `kerberoshub.monitordevice`. | `"10m"` |
| `kerberoshub.reactivate.repository` | Container image repository for `kerberoshub.reactivate`. | `"uugai/hub-reactivatesubscriptions"` |
| `kerberoshub.reactivate.pullPolicy` | Image pull policy for `kerberoshub.reactivate`. | `"IfNotPresent"` |
| `kerberoshub.reactivate.tag` | Container image tag/version for `kerberoshub.reactivate`. | `"v1.0.2"` |
| `kerberoshub.reactivate.replicas` | Number of replicas for `kerberoshub.reactivate`. Set to `0` to disable. | `0` |
| `kerberoshub.reactivate.logLevel` | Log verbosity level for `kerberoshub.reactivate`. | `"info"` |
| `kerberoshub.reactivate.resources.requests.memory` | Memory request for `kerberoshub.reactivate`. | `"10Mi"` |
| `kerberoshub.reactivate.resources.requests.cpu` | CPU request for `kerberoshub.reactivate`. | `"10m"` |
| `kerberoshub.forwarder.enabled` | Enable or disable the Hub forwarder component. | `false` |
| `kerberoshub.proxy.repository` | Container image repository for `kerberoshub.proxy`. | `"uugai/hub-proxy"` |
| `kerberoshub.proxy.pullPolicy` | Image pull policy for `kerberoshub.proxy`. | `"IfNotPresent"` |
| `kerberoshub.proxy.tag` | Container image tag/version for `kerberoshub.proxy`. | `"v1.0.0"` |
| `kerberoshub.proxy.replicas` | Number of replicas for `kerberoshub.proxy`. Set to `0` to disable. | `0` |
| `kerberoshub.proxy.logLevel` | Log verbosity level for `kerberoshub.proxy`. | `"info"` |
| `kerberoshub.proxy.resources.requests.memory` | Memory request for `kerberoshub.proxy`. | `"10Mi"` |
| `kerberoshub.proxy.resources.requests.cpu` | CPU request for `kerberoshub.proxy`. | `"10m"` |
| `kerberospipeline.event.repository` | The [event orchestration](https://doc.kerberos.io/hub/pipeline/#orchestrator) microservice. | `"ghcr.io/uug-ai/hub-pipeline-event"` |
| `kerberospipeline.event.pullPolicy` | The Docker registry pull policy. | `"IfNotPresent"` |
| `kerberospipeline.event.tag` | The Docker image tag/version. | `"v1.3.0"` |
| `kerberospipeline.event.replicas` | Number of replicas for `kerberospipeline.event`. | `1` |
| `kerberospipeline.event.logLevel` | Log verbosity level for `kerberospipeline.event`. | `"info"` |
| `kerberospipeline.event.resources.requests.memory` | Memory request for `kerberospipeline.event`. | `"10Mi"` |
| `kerberospipeline.event.resources.requests.cpu` | CPU request for `kerberospipeline.event`. | `"10m"` |
| `kerberospipeline.monitor.repository` | The [monitoring microservice](https://doc.kerberos.io/hub/pipeline/#monitoring), calculating metrics of incoming messages. | `"ghcr.io/uug-ai/hub-pipeline-monitor"` |
| `kerberospipeline.monitor.pullPolicy` | The Docker registry pull policy. | `"IfNotPresent"` |
| `kerberospipeline.monitor.tag` | The Docker image tag/version. | `"v1.3.9"` |
| `kerberospipeline.monitor.replicas` | Number of replicas for `kerberospipeline.monitor`. | `1` |
| `kerberospipeline.monitor.resources.requests.memory` | Memory request for `kerberospipeline.monitor`. | `"10Mi"` |
| `kerberospipeline.monitor.resources.requests.cpu` | CPU request for `kerberospipeline.monitor`. | `"10m"` |
| `kerberospipeline.sequence.repository` | The [sequencer microservice](https://doc.kerberos.io/hub/pipeline/#sequencer), grouping recordings in chunks/groups. | `"ghcr.io/uug-ai/hub-pipeline-sequence"` |
| `kerberospipeline.sequence.pullPolicy` | The Docker registry pull policy. | `"IfNotPresent"` |
| `kerberospipeline.sequence.tag` | The Docker image tag/version. | `"v1.6.18"` |
| `kerberospipeline.sequence.replicas` | Number of replicas for `kerberospipeline.sequence`. | `1` |
| `kerberospipeline.sequence.resources.requests.memory` | Memory request for `kerberospipeline.sequence`. | `"10Mi"` |
| `kerberospipeline.sequence.resources.requests.cpu` | CPU request for `kerberospipeline.sequence`. | `"10m"` |
| `kerberospipeline.throttler.repository` | The [throttler microservice](https://doc.kerberos.io/hub/pipeline/#throttler), throttling events. | `"uugai/hub-pipeline-throttler"` |
| `kerberospipeline.throttler.pullPolicy` | The Docker registry pull policy. | `"IfNotPresent"` |
| `kerberospipeline.throttler.tag` | The Docker image tag/version. | `"v1.2.0"` |
| `kerberospipeline.throttler.replicas` | Number of replicas for `kerberospipeline.throttler`. | `1` |
| `kerberospipeline.throttler.logLevel` | Log verbosity level for `kerberospipeline.throttler`. | `"info"` |
| `kerberospipeline.throttler.resources.requests.memory` | Memory request for `kerberospipeline.throttler`. | `"10Mi"` |
| `kerberospipeline.throttler.resources.requests.cpu` | CPU request for `kerberospipeline.throttler`. | `"10m"` |
| `kerberospipeline.notify.repository` | The [notification microservice](https://doc.kerberos.io/hub/pipeline/#notification), sending notifications on events. | `"ghcr.io/uug-ai/hub-pipeline-notification"` |
| `kerberospipeline.notify.pullPolicy` | The Docker registry pull policy. | `"IfNotPresent"` |
| `kerberospipeline.notify.tag` | The Docker image tag/version. | `"v1.3.9"` |
| `kerberospipeline.notify.replicas` | Number of replicas for `kerberospipeline.notify`. | `1` |
| `kerberospipeline.notify.logLevel` | Log verbosity level for `kerberospipeline.notify`. | `"info"` |
| `kerberospipeline.notify.resources.requests.memory` | Memory request for `kerberospipeline.notify`. | `"10Mi"` |
| `kerberospipeline.notify.resources.requests.cpu` | CPU request for `kerberospipeline.notify`. | `"10m"` |
| `kerberospipeline.notifyTest.repository` | The notification service for testing, the different channels. | `"uugai/hub-pipeline-notification-test"` |
| `kerberospipeline.notifyTest.pullPolicy` | The Docker registry pull policy. | `"IfNotPresent"` |
| `kerberospipeline.notifyTest.tag` | The Docker image tag/version. | `"v1.2.1"` |
| `kerberospipeline.notifyTest.replicas` | Number of replicas for `kerberospipeline.notifyTest`. | `1` |
| `kerberospipeline.notifyTest.resources.requests.memory` | Memory request for `kerberospipeline.notifyTest`. | `"10Mi"` |
| `kerberospipeline.notifyTest.resources.requests.cpu` | CPU request for `kerberospipeline.notifyTest`. | `"10m"` |
| `kerberospipeline.analysis.repository` | The [analysis microservices](https://doc.kerberos.io/hub/pipeline/#analyser) which executed specific analysis in parallel. | `"ghcr.io/uug-ai/hub-pipeline-analysis"` |
| `kerberospipeline.analysis.pullPolicy` | The Docker registry pull policy. | `"IfNotPresent"` |
| `kerberospipeline.analysis.tag` | The Docker image tag/version. | `"v1.7.8"` |
| `kerberospipeline.analysis.replicas` | Number of replicas for `kerberospipeline.analysis`. | `1` |
| `kerberospipeline.analysis.logLevel` | Log verbosity level for `kerberospipeline.analysis`. | `"info"` |
| `kerberospipeline.analysis.resources.requests.memory` | Memory request for `kerberospipeline.analysis`. | `"10Mi"` |
| `kerberospipeline.analysis.resources.requests.cpu` | CPU request for `kerberospipeline.analysis`. | `"10m"` |
| `kerberospipeline.dominantColor.repository` | The dominant color microservices is computing a top 3 color histogram. | `"ghcr.io/uug-ai/hub-pipeline-dominantcolors"` |
| `kerberospipeline.dominantColor.pullPolicy` | The Docker registry pull policy. | `"IfNotPresent"` |
| `kerberospipeline.dominantColor.tag` | The Docker image tag/version. | `"v2.0.2"` |
| `kerberospipeline.dominantColor.replicas` | Number of replicas for `kerberospipeline.dominantColor`. | `3` |
| `kerberospipeline.dominantColor.logLevel` | Log verbosity level for `kerberospipeline.dominantColor`. | `"info"` |
| `kerberospipeline.dominantColor.resources.requests.memory` | Memory request for `kerberospipeline.dominantColor`. | `"512Mi"` |
| `kerberospipeline.dominantColor.resources.requests.cpu` | CPU request for `kerberospipeline.dominantColor`. | `"500m"` |
| `kerberospipeline.dominantColor.resources.limits.memory` | Memory limit for `kerberospipeline.dominantColor`. | `"2Gi"` |
| `kerberospipeline.dominantColor.resources.limits.cpu` | CPU limit for `kerberospipeline.dominantColor`. | `"1000m"` |
| `kerberospipeline.thumbnail.repository` | The thumbnail microservices generated a thumbnail for a recordings. | `"ghcr.io/uug-ai/hub-pipeline-thumbnail"` |
| `kerberospipeline.thumbnail.pullPolicy` | The Docker registry pull policy. | `"IfNotPresent"` |
| `kerberospipeline.thumbnail.tag` | The Docker image tag/version. | `"v1.3.4"` |
| `kerberospipeline.thumbnail.replicas` | Number of replicas for `kerberospipeline.thumbnail`. | `2` |
| `kerberospipeline.thumbnail.logLevel` | Log verbosity level for `kerberospipeline.thumbnail`. | `"info"` |
| `kerberospipeline.thumbnail.quality` | Configuration value for `kerberospipeline.thumbnail.quality`. | `"1"` |
| `kerberospipeline.thumbnail.width` | Configuration value for `kerberospipeline.thumbnail.width`. | `"600"` |
| `kerberospipeline.thumbnail.height` | Configuration value for `kerberospipeline.thumbnail.height`. | `"-1"` |
| `kerberospipeline.thumbnail.kerberosvault.enabled` | Enable or disable `kerberospipeline.thumbnail.kerberosvault`. | `true` |
| `kerberospipeline.thumbnail.resources.requests.memory` | Memory request for `kerberospipeline.thumbnail`. | `"512Mi"` |
| `kerberospipeline.thumbnail.resources.requests.cpu` | CPU request for `kerberospipeline.thumbnail`. | `"500m"` |
| `kerberospipeline.thumbnail.resources.limits.memory` | Memory limit for `kerberospipeline.thumbnail`. | `"2Gi"` |
| `kerberospipeline.thumbnail.resources.limits.cpu` | CPU limit for `kerberospipeline.thumbnail`. | `"1000m"` |
| `kerberospipeline.counting.repository` | The counting microservices computes objects passing different line segments. | `"uugai/hub-pipeline-counting"` |
| `kerberospipeline.counting.pullPolicy` | The Docker registry pull policy. | `"IfNotPresent"` |
| `kerberospipeline.counting.tag` | The Docker image tag/version. | `"v1.6.3"` |
| `kerberospipeline.counting.replicas` | Number of replicas for `kerberospipeline.counting`. | `1` |
| `kerberospipeline.counting.logLevel` | Log verbosity level for `kerberospipeline.counting`. | `"info"` |
| `kerberospipeline.counting.resources.requests.memory` | Memory request for `kerberospipeline.counting`. | `"10Mi"` |
| `kerberospipeline.counting.resources.requests.cpu` | CPU request for `kerberospipeline.counting`. | `"10m"` |
| `kerberospipeline.sprite.enabled` | Enable or disable `kerberospipeline.sprite`. | `false` |
| `kerberospipeline.sprite.repository` | Container image repository for `kerberospipeline.sprite`. | `"ghcr.io/uug-ai/hub-pipeline-sprite"` |
| `kerberospipeline.sprite.pullPolicy` | Image pull policy for `kerberospipeline.sprite`. | `"IfNotPresent"` |
| `kerberospipeline.sprite.tag` | Container image tag/version for `kerberospipeline.sprite`. | `"v1.1.12"` |
| `kerberospipeline.sprite.replicas` | Number of replicas for `kerberospipeline.sprite`. | `5` |
| `kerberospipeline.sprite.logLevel` | Log verbosity level for `kerberospipeline.sprite`. | `"info"` |
| `kerberospipeline.sprite.interval` | Configuration value for `kerberospipeline.sprite.interval`. | `"1"` |
| `kerberospipeline.sprite.width` | Configuration value for `kerberospipeline.sprite.width`. | `"240"` |
| `kerberospipeline.sprite.height` | Configuration value for `kerberospipeline.sprite.height`. | `"135"` |
| `kerberospipeline.sprite.resources.requests.memory` | Memory request for `kerberospipeline.sprite`. | `"512Mi"` |
| `kerberospipeline.sprite.resources.requests.cpu` | CPU request for `kerberospipeline.sprite`. | `"500m"` |
| `kerberospipeline.sprite.resources.limits.memory` | Memory limit for `kerberospipeline.sprite`. | `"2Gi"` |
| `kerberospipeline.sprite.resources.limits.cpu` | CPU limit for `kerberospipeline.sprite`. | `"1000m"` |
| `kerberospipeline.export.repository` | Container image repository for `kerberospipeline.export`. | `"ghcr.io/uug-ai/hub-pipeline-export"` |
| `kerberospipeline.export.pullPolicy` | Image pull policy for `kerberospipeline.export`. | `"IfNotPresent"` |
| `kerberospipeline.export.tag` | Container image tag/version for `kerberospipeline.export`. | `"v1.2.4"` |
| `kerberospipeline.export.replicas` | Number of replicas for `kerberospipeline.export`. | `2` |
| `kerberospipeline.export.logLevel` | Log verbosity level for `kerberospipeline.export`. | `"info"` |
| `kerberospipeline.export.resources.requests.memory` | Memory request for `kerberospipeline.export`. | `"10Mi"` |
| `kerberospipeline.export.resources.requests.cpu` | CPU request for `kerberospipeline.export`. | `"10m"` |
| `email.provider` | The email service provider for sending out messages over email , use `'mailgun'` or `'smtp'`. | `"mailgun"` |
| `email.from` | The email address that is sending messages in name of, by default `'support@yourdomain.com'`. | `"support@yourdomain.com"` |
| `email.displayName` | The display name that is sending messages in name of, by default `'yourdomain.com'` | `"yourdomain.com"` |
| `email.mailgun.domain` | While using `mailgun` as email service provider, you will need to provide your Mailgun domain. | `"mg.yourdomain.com"` |
| `email.mailgun.apikey` | Mailgun API key (lowercase variant) used when provider is `mailgun`. | `"xxxx"` |
| `email.smtp.server` | While using `smtp` as email service provider, use the SMTP server. | `"smtp.yourdomain.com"` |
| `email.smtp.port` | SMTP port specified by your SMTP server, by default `'456'`. | `"465"` |
| `email.smtp.username` | SMTP username. | `"yourusername"` |
| `email.smtp.password` | SMTP password. | `"yourpassword"` |
| `email.templates.welcome` | The template which is send when a new user registered on the platform (`IS_PRIVATE='false'`), by default `'disabled'`. | `"welcome"` |
| `email.templates.welcomeTitle` | The welcome title use in the subject of the email. | `"Welcome to Kerberos Hub"` |
| `email.templates.activate` | The template which is send when a user is required to activate his account , by default `'activate'`. | `"activate"` |
| `email.templates.activateTitle` | The activation title use in the subject of the email. | `"Wonderful! Your Kerberos Hub is now active"` |
| `email.templates.forgot` | The template which is send when an account is requesting a forgot password, by default `'forgot'`. | `"forgot"` |
| `email.templates.forgotTitle` | The forgot title use in the subject of the email. | `"Password reset Kerberos Hub. You forgot your password"` |
| `email.templates.share` | Email template name/key for `share` notifications. | `"share"` |
| `email.templates.shareTitle` | Email subject title for the `share` template. | `"[Action] You received a recording from Kerberos Hub"` |
| `email.templates.assignTask` | Email template name/key for `assign task` notifications. | `"assign_task"` |
| `email.templates.assignTaskTitle` | Email subject title for the `assign task` template. | `"[Action] You've been assigned to a task"` |
| `email.templates.detection` | We use templates to send notifications, this allow you to bring your own `Mailgun` templates, by default `'detection'`. | `"detection"` |
| `email.templates.disabled` | The template which is send when an account is disabled due to reaching its upload limit, by default `'disabled'`. | `"disabled"` |
| `email.templates.highupload` | The template which is send when an account is reaching a specific upload threshold, by default `'threshold'`. | `"highupload"` |
| `email.templates.device` | The template which is send when a camera goes online or offline, by default `'device'`. | `"device"` |
| `email.templates.alertTitle` | Email subject title for the `alert` template. | `"[Alert] Kerberos Hub detected something an event"` |
| `email.templates.deviceTitle` | Email subject title for the `device` template. | `"[Device] A Kerberos Agent's status has been changed"` |
| `email.mailgun.apiKey` | The Mailgun API key linked to your Mailgun domain. | `""` |
| `imagePullSecrets.name` | Docker registry secret name, which is also granted with the license. This allows you to download the Docker images. | `""` |
| `kerberoshub.forwarder.pullPolicy` | The Docker registry pull policy. | `""` |
| `kerberoshub.forwarder.repository` | The Docker container which orchestrates forwarding coming from different Kerberos Vaults. | `""` |
| `kerberoshub.forwarder.tag` | The Docker image tag/version. | `""` |
| `kerberoshub.frontend.ssoDomain` | The domain that's being used to activate SSO from the login page. | `""` |
| `kerberoshub.frontend.stripe.apikey` | If using the public version, `stripe` can be used for automated billing and subscriptions. | `""` |
### Post installation
@@ -241,6 +498,7 @@ Following indexes should be executed on the MongoDB database (Kerberos) to impro
#### Analysis collection
db.getCollection("analysis").createIndex({start:1})
db.getCollection("analysis").createIndex({organisationId:1, projectId:1, key:1}, {name:"analysis_org_project_key"})
db.getCollection("analysis").createIndex({userid:1, key:1})
db.getCollection("analysis").createIndex({userid:1, start:1})

View File

@@ -0,0 +1,11 @@
apiVersion: v1
kind: PersistentVolumeClaim
metadata:
name: custom-i18n-claim
spec:
accessModes:
- ReadWriteMany
storageClassName: azurefile-premium
resources:
requests:
storage: 25Mi

View File

@@ -0,0 +1,9 @@
{
"nav": {
"cases": "Investigations",
"dashboard": "Home"
},
"login": {
"signInTo": "Sign in to {{domain}} \u2014 Acme Security"
}
}

File diff suppressed because it is too large Load Diff

View File

@@ -13,6 +13,12 @@
<path fill-rule="evenodd" clip-rule="evenodd" d="M9.92677 0.00271038C10.4021 -0.03219 10.836 0.273183 10.9635 0.732382L13.094 8.40217L13.4453 8.16798C13.6096 8.05846 13.8026 8.00003 14 8.00003H17C17.5523 8.00003 18 8.44774 18 9.00003C18 9.55231 17.5523 10 17 10H14.3028L13.0547 10.8321C12.7879 11.0099 12.4521 11.0491 12.1515 10.9374C11.851 10.8256 11.6223 10.5766 11.5365 10.2677L10.3729 6.07887L8.99228 17.1241C8.93316 17.597 8.54854 17.9624 8.07323 17.9973C7.59793 18.0322 7.16404 17.7269 7.03648 17.2677L4.90599 9.59789L4.5547 9.83208C4.39043 9.94159 4.19742 10 4 10H1C0.447715 10 0 9.55231 0 9.00003C0 8.44774 0.447715 8.00003 1 8.00003H3.69722L4.9453 7.16797C5.21207 6.99013 5.54794 6.95098 5.84846 7.0627C6.14898 7.17442 6.37771 7.42346 6.46352 7.73238L7.62707 11.9212L9.00772 0.875991C9.06684 0.403086 9.45146 0.0376109 9.92677 0.00271038Z" fill="currentColor"/>
</svg>`
/* Task activity log */
window["env"]["svg"]["activity-task"] = `<svg width="18" height="18" viewBox="0 0 18 18" fill="none" xmlns="http://www.w3.org/2000/svg">
<path fill-rule="evenodd" clip-rule="evenodd" d="M0 2.25C0 2.01379 0.223858 1.75 0.5 1.75H2.5C2.77614 1.75 3 2.01379 3 2.25C3 2.48621 2.77614 2.75 2.5 2.75H0.5C0.223858 2.75 0 2.48621 0 2.25ZM4 2.25C4 2.01379 4.22386 1.75 4.5 1.75H14.5C14.7761 1.75 15 2.01379 15 2.25C15 2.48621 14.7761 2.75 14.5 2.75H4.5C4.22386 2.75 4 2.48621 4 2.25ZM4 5.25C4 5.01379 4.22386 4.75 4.5 4.75H11.5C11.7761 4.75 12 5.01379 12 5.25C12 5.48621 11.7761 5.75 11.5 5.75H4.5C4.22386 5.75 4 5.48621 4 5.25ZM0 8.25C0 8.01379 0.223858 7.75 0.5 7.75H2.5C2.77614 7.75 3 8.01379 3 8.25C3 8.48621 2.77614 8.75 2.5 8.75H0.5C0.223858 8.75 0 8.48621 0 8.25ZM4 8.25C4 8.01379 4.22386 7.75 4.5 7.75H14.5C14.7761 7.75 15 8.01379 15 8.25C15 8.48621 14.7761 8.75 14.5 8.75H4.5C4.22386 8.75 4 8.48621 4 8.25ZM4 11.25C4 11.0138 4.22386 10.75 4.5 10.75H11.5C11.7761 10.75 12 11.0138 12 11.25C12 11.4862 11.7761 11.75 11.5 11.75H4.5C4.22386 11.75 4 11.4862 4 11.25ZM0 14.25C0 14.0138 0.223858 13.75 0.5 13.75H2.5C2.77614 13.75 3 14.0138 3 14.25C3 14.4862 2.77614 14.75 2.5 14.75H0.5C0.223858 14.75 0 14.4862 0 14.25ZM4 14.25C4 14.0138 4.22386 13.75 4.5 13.75H14.5C14.7761 13.75 15 14.0138 15 14.25C15 14.4862 14.7761 14.75 14.5 14.75H4.5C4.22386 14.75 4 14.4862 4 14.25Z" fill="#A69D9D"/>
</svg>`
/* Alerts */
window["env"]["svg"]["alerts"] = `<svg class="icon icon-alerts" width="18" height="18" viewBox="0 0 18 18" fill="none" xmlns="http://www.w3.org/2000/svg">
<path fill-rule="evenodd" clip-rule="evenodd" d="M9 4C6.79086 4 5 5.79086 5 8V12H13V8C13 5.79086 11.2091 4 9 4ZM3 8C3 4.68629 5.68629 2 9 2C12.3137 2 15 4.68629 15 8V14H3V8Z" fill="currentColor"/>
@@ -93,6 +99,66 @@
<path fill-rule="evenodd" clip-rule="evenodd" d="M9 6C9.55228 6 10 5.55228 10 5C10 4.44772 9.55228 4 9 4C8.44772 4 8 4.44772 8 5C8 5.55228 8.44772 6 9 6ZM9 7C10.1046 7 11 6.10457 11 5C11 3.89543 10.1046 3 9 3C7.89543 3 7 3.89543 7 5C7 6.10457 7.89543 7 9 7Z" fill="currentColor"/>
</svg>`
/* Device group */
window["env"]["svg"]["deviceGroup"] = `<svg width="18" height="18" viewBox="0 0 18 18" fill="none" xmlns="http://www.w3.org/2000/svg">
<g clip-path="url(#clip0_1_20)">
<g clip-path="url(#clip1_1_20)">
<path fill-rule="evenodd" clip-rule="evenodd" d="M12.4802 6H15V5.11364C15 4.64235 14.9043 4.1751 14.7178 3.73836C14.5312 3.30157 14.257 2.90316 13.9099 2.56651C13.5626 2.2298 13.1492 1.96154 12.6925 1.77812C12.2359 1.59469 11.7456 1.5 11.25 1.5C10.7544 1.5 10.2642 1.59469 9.80746 1.77812C9.52217 1.89271 9.25373 2.04042 9.00778 2.21724L7.32179 1.72093C7.39394 1.64168 7.46868 1.56454 7.5459 1.48966C8.03441 1.01595 8.61311 0.64137 9.24838 0.386204C9.88362 0.131052 10.5637 5.99978e-08 11.25 0C11.9363 -5.99977e-08 12.6163 0.131052 13.2516 0.386204C13.8869 0.64137 14.4655 1.01595 14.9541 1.48966C15.4426 1.9634 15.8314 2.52708 16.0972 3.14913C16.3629 3.77123 16.5 4.43885 16.5 5.11364V6.75C16.5 6.94892 16.4209 7.13968 16.2803 7.28033C16.1397 7.42098 15.9489 7.5 15.75 7.5H13.6903L12.4802 6Z" fill="currentColor"/>
<path fill-rule="evenodd" clip-rule="evenodd" d="M13.5686 7.5H15V8.25H13.9865L14.179 9.75H15.75C16.1642 9.75 16.5 9.41423 16.5 9V6.75C16.5 6.33579 16.1642 6 15.75 6H12.5131L13.5686 7.5Z" fill="currentColor"/>
<path fill-rule="evenodd" clip-rule="evenodd" d="M16.5 12H13.0178V13.5H17.25C17.6642 13.5 18 13.1642 18 12.75V9.75C18 8.92155 17.3285 8.25 16.5 8.25H14.0031L14.2502 9.75H16.5V12Z" fill="currentColor"/>
<path fill-rule="evenodd" clip-rule="evenodd" d="M11.6761 5.18862C12.297 5.00501 12.75 4.43041 12.75 3.75C12.75 2.92157 12.0785 2.25 11.25 2.25C10.8002 2.25 10.3966 2.44801 10.1217 2.76162L10.6799 3.26263C10.8175 3.10188 11.0218 3 11.25 3C11.6642 3 12 3.33579 12 3.75C12 4.09028 11.7734 4.37763 11.4628 4.46937L11.6761 5.18862Z" fill="currentColor"/>
</g>
<path fill-rule="evenodd" clip-rule="evenodd" d="M11.8206 5.27212C11.7697 5.10777 11.6651 4.80819 11.5972 4.64915C11.3314 4.0271 10.9426 3.46342 10.4541 2.98967C9.96555 2.51597 9.38692 2.14138 8.7516 1.88622C8.11635 1.63107 7.43629 1.50002 6.75 1.50002C6.0637 1.50002 5.38363 1.63107 4.74838 1.88622C4.11311 2.14139 3.53441 2.51597 3.04591 2.98967C2.55736 3.46342 2.16854 4.0271 1.90283 4.64915C1.63709 5.27125 1.5 5.93886 1.5 6.61366V8.25002C1.5 8.66423 1.83579 9.00002 2.25 9.00002H4.99591L5.55615 7.50002H3V6.61366C3 6.14237 3.0957 5.67512 3.28225 5.23838C3.46883 4.80158 3.74296 4.40318 4.09013 4.06652C4.43735 3.72982 4.85081 3.46156 5.30746 3.27814C5.76415 3.0947 6.25439 3.00002 6.75 3.00002C7.24561 3.00002 7.73587 3.0947 8.19255 3.27814C8.64922 3.46156 9.06262 3.72982 9.40987 4.06652C9.65998 4.30905 9.87217 4.58362 10.041 4.8815L11.8206 5.27212Z" fill="currentColor"/>
<path fill-rule="evenodd" clip-rule="evenodd" d="M4.99564 9H3V9.75H4.89629L4.87556 11.25H2.25C1.83579 11.25 1.5 10.9142 1.5 10.5V8.25C1.5 7.83579 1.83579 7.5 2.25 7.5H5.55093L4.99564 9Z" fill="currentColor"/>
<path fill-rule="evenodd" clip-rule="evenodd" d="M5.0625 11.25H1.5V13.5H3.90234L3.375 15H0.75C0.335786 15 0 14.6642 0 14.25V11.25C0 10.4215 0.671573 9.75 1.5 9.75H5.0625V11.25Z" fill="currentColor"/>
<path fill-rule="evenodd" clip-rule="evenodd" d="M7.38875 4.85676C7.25667 4.64269 7.02 4.50002 6.75 4.50002C6.33579 4.50002 6 4.83581 6 5.25002C6 5.34965 6.01943 5.44474 6.0547 5.53172L5.44733 5.99421C5.32177 5.7749 5.25 5.52084 5.25 5.25002C5.25 4.42159 5.92157 3.75002 6.75 3.75002C7.37642 3.75002 7.91313 4.13398 8.13765 4.67938L7.38875 4.85676Z" fill="currentColor"/>
<path fill-rule="evenodd" clip-rule="evenodd" d="M14.1044 11.7803C13.9638 11.921 13.773 12 13.5741 12H4.57407C4.15986 12 3.82407 11.6642 3.82407 11.25V9.61364C3.82407 8.93885 3.96116 8.27123 4.2269 7.64913C4.49261 7.02709 4.88142 6.4634 5.36997 5.98966C5.85848 5.51595 6.43718 5.14137 7.07245 4.8862C7.70769 4.63105 8.38777 4.5 9.07407 4.5C9.76035 4.5 10.4404 4.63105 11.0757 4.8862C11.711 5.14137 12.2896 5.51595 12.7782 5.98966C13.2667 6.4634 13.6555 7.02708 13.9212 7.64913C14.187 8.27123 14.3241 8.93885 14.3241 9.61364V11.25C14.3241 11.4489 14.245 11.6397 14.1044 11.7803ZM12.8241 10.5V9.61364C12.8241 9.14235 12.7284 8.6751 12.5418 8.23836C12.3552 7.80157 12.0811 7.40316 11.7339 7.06651C11.3867 6.7298 10.9733 6.46154 10.5166 6.27812C10.0599 6.09469 9.56967 6 9.07407 6C8.57846 6 8.08822 6.09469 7.63153 6.27812C7.17488 6.46154 6.76142 6.7298 6.4142 7.06651C6.06702 7.40316 5.7929 7.80157 5.60632 8.23836C5.41977 8.6751 5.32407 9.14235 5.32407 9.61364V10.5H12.8241Z" fill="currentColor"/>
<path fill-rule="evenodd" clip-rule="evenodd" d="M3.82407 11.25C3.82407 10.8358 4.15986 10.5 4.57407 10.5H13.5741C13.9883 10.5 14.3241 10.8358 14.3241 11.25V13.5C14.3241 13.9142 13.9883 14.25 13.5741 14.25H4.57407C4.15986 14.25 3.82407 13.9142 3.82407 13.5V11.25ZM5.32407 12V12.75H12.8241V12H5.32407Z" fill="currentColor"/>
<path fill-rule="evenodd" clip-rule="evenodd" d="M2.32407 14.25C2.32407 13.4215 2.99564 12.75 3.82407 12.75H14.3241C15.1525 12.75 15.8241 13.4215 15.8241 14.25V17.25C15.8241 17.6642 15.4883 18 15.0741 18H3.07407C2.65985 18 2.32407 17.6642 2.32407 17.25V14.25ZM14.3241 14.25H3.82407V16.5H14.3241V14.25Z" fill="currentColor"/>
<path fill-rule="evenodd" clip-rule="evenodd" d="M9.07406 9C9.48827 9 9.82406 8.66421 9.82406 8.25C9.82406 7.83579 9.48827 7.5 9.07406 7.5C8.65985 7.5 8.32406 7.83579 8.32406 8.25C8.32406 8.66421 8.65985 9 9.07406 9ZM9.07406 9.75C9.90251 9.75 10.5741 9.07843 10.5741 8.25C10.5741 7.42157 9.90251 6.75 9.07406 6.75C8.24563 6.75 7.57406 7.42157 7.57406 8.25C7.57406 9.07843 8.24563 9.75 9.07406 9.75Z" fill="currentColor"/>
</g>
<defs>
<clipPath id="clip0_1_20">
<rect width="18" height="18" fill="white"/>
</clipPath>
<clipPath id="clip1_1_20">
<rect width="13.5" height="13.5" fill="white" transform="translate(4.5)"/>
</clipPath>
</defs>
</svg>`
/* Active devices */
window["env"]["svg"]["deviceActive"] = `<svg class="icon icon-camera" width="18" height="18" viewBox="0 0 18 18" fill="none" xmlns="http://www.w3.org/2000/svg">
<path fill-rule="evenodd" clip-rule="evenodd" d="M15.7071 9.70711C15.5196 9.89464 15.2652 10 15 10L3 10C2.44772 10 2 9.55228 2 9L2 6.81819C2 5.91846 2.18279 5.02831 2.53711 4.19884C2.89139 3.36945 3.40981 2.61787 4.06121 1.98621C4.71255 1.3546 5.48415 0.85516 6.33118 0.514938C7.17817 0.174736 8.08494 -2.61718e-07 9 -3.41715e-07C9.91505 -4.21712e-07 10.8218 0.174736 11.6688 0.514938C12.5159 0.855159 13.2874 1.3546 13.9388 1.98621C14.5902 2.61787 15.1086 3.36944 15.4629 4.19884C15.8172 5.02831 16 5.91846 16 6.81819L16 9C16 9.26522 15.8946 9.51957 15.7071 9.70711ZM14 8L14 6.81819C14 6.1898 13.8724 5.5668 13.6237 4.98448C13.3749 4.40209 13.0094 3.87088 12.5465 3.42201C12.0835 2.97307 11.5323 2.61539 10.9234 2.37083C10.3145 2.12625 9.66081 2 9 2C8.33919 2 7.68554 2.12625 7.07662 2.37083C6.46775 2.61539 5.91647 2.97307 5.45351 3.42201C4.99061 3.87088 4.62511 4.40209 4.37634 4.98448C4.1276 5.5668 4 6.1898 4 6.81819L4 8L14 8Z" fill="#5E8F6E"/>
<path fill-rule="evenodd" clip-rule="evenodd" d="M2 9C2 8.44772 2.44772 8 3 8H15C15.5523 8 16 8.44772 16 9V12C16 12.5523 15.5523 13 15 13H3C2.44772 13 2 12.5523 2 12V9ZM4 10V11H14V10H4Z" fill="#5E8F6E"/>
<path fill-rule="evenodd" clip-rule="evenodd" d="M0 13C0 11.8954 0.895431 11 2 11H16C17.1046 11 18 11.8954 18 13V17C18 17.5523 17.5523 18 17 18H1C0.447715 18 0 17.5523 0 17V13ZM16 13H2V16H16V13Z" fill="#5E8F6E"/>
<path fill-rule="evenodd" clip-rule="evenodd" d="M9 6C9.55228 6 10 5.55228 10 5C10 4.44772 9.55228 4 9 4C8.44772 4 8 4.44772 8 5C8 5.55228 8.44772 6 9 6ZM9 7C10.1046 7 11 6.10457 11 5C11 3.89543 10.1046 3 9 3C7.89543 3 7 3.89543 7 5C7 6.10457 7.89543 7 9 7Z" fill="#5E8F6E"/>
</svg>`
/* inactive devices */
window["env"]["svg"]["deviceInactive"] = `<svg class="icon icon-camera" width="18" height="18" viewBox="0 0 18 18" fill="none" xmlns="http://www.w3.org/2000/svg">
<path fill-rule="evenodd" clip-rule="evenodd" d="M15.7071 9.70711C15.5196 9.89464 15.2652 10 15 10L3 10C2.44772 10 2 9.55228 2 9L2 6.81819C2 5.91846 2.18279 5.02831 2.53711 4.19884C2.89139 3.36945 3.40981 2.61787 4.06121 1.98621C4.71255 1.3546 5.48415 0.85516 6.33118 0.514938C7.17817 0.174736 8.08494 -2.61718e-07 9 -3.41715e-07C9.91505 -4.21712e-07 10.8218 0.174736 11.6688 0.514938C12.5159 0.855159 13.2874 1.3546 13.9388 1.98621C14.5902 2.61787 15.1086 3.36944 15.4629 4.19884C15.8172 5.02831 16 5.91846 16 6.81819L16 9C16 9.26522 15.8946 9.51957 15.7071 9.70711ZM14 8L14 6.81819C14 6.1898 13.8724 5.5668 13.6237 4.98448C13.3749 4.40209 13.0094 3.87088 12.5465 3.42201C12.0835 2.97307 11.5323 2.61539 10.9234 2.37083C10.3145 2.12625 9.66081 2 9 2C8.33919 2 7.68554 2.12625 7.07662 2.37083C6.46775 2.61539 5.91647 2.97307 5.45351 3.42201C4.99061 3.87088 4.62511 4.40209 4.37634 4.98448C4.1276 5.5668 4 6.1898 4 6.81819L4 8L14 8Z" fill="#696969"/>
<path fill-rule="evenodd" clip-rule="evenodd" d="M2 9C2 8.44772 2.44772 8 3 8H15C15.5523 8 16 8.44772 16 9V12C16 12.5523 15.5523 13 15 13H3C2.44772 13 2 12.5523 2 12V9ZM4 10V11H14V10H4Z" fill="#696969"/>
<path fill-rule="evenodd" clip-rule="evenodd" d="M0 13C0 11.8954 0.895431 11 2 11H16C17.1046 11 18 11.8954 18 13V17C18 17.5523 17.5523 18 17 18H1C0.447715 18 0 17.5523 0 17V13ZM16 13H2V16H16V13Z" fill="#696969"/>
<path fill-rule="evenodd" clip-rule="evenodd" d="M9 6C9.55228 6 10 5.55228 10 5C10 4.44772 9.55228 4 9 4C8.44772 4 8 4.44772 8 5C8 5.55228 8.44772 6 9 6ZM9 7C10.1046 7 11 6.10457 11 5C11 3.89543 10.1046 3 9 3C7.89543 3 7 3.89543 7 5C7 6.10457 7.89543 7 9 7Z" fill="#696969"/>
</svg>`
/* Idle devices */
window["env"]["svg"]["deviceIdle"] = `<svg class="icon icon-camera" width="18" height="18" viewBox="0 0 18 18" fill="none" xmlns="http://www.w3.org/2000/svg">
<path fill-rule="evenodd" clip-rule="evenodd" d="M15.7071 9.70711C15.5196 9.89464 15.2652 10 15 10L3 10C2.44772 10 2 9.55228 2 9L2 6.81819C2 5.91846 2.18279 5.02831 2.53711 4.19884C2.89139 3.36945 3.40981 2.61787 4.06121 1.98621C4.71255 1.3546 5.48415 0.85516 6.33118 0.514938C7.17817 0.174736 8.08494 -2.61718e-07 9 -3.41715e-07C9.91505 -4.21712e-07 10.8218 0.174736 11.6688 0.514938C12.5159 0.855159 13.2874 1.3546 13.9388 1.98621C14.5902 2.61787 15.1086 3.36944 15.4629 4.19884C15.8172 5.02831 16 5.91846 16 6.81819L16 9C16 9.26522 15.8946 9.51957 15.7071 9.70711ZM14 8L14 6.81819C14 6.1898 13.8724 5.5668 13.6237 4.98448C13.3749 4.40209 13.0094 3.87088 12.5465 3.42201C12.0835 2.97307 11.5323 2.61539 10.9234 2.37083C10.3145 2.12625 9.66081 2 9 2C8.33919 2 7.68554 2.12625 7.07662 2.37083C6.46775 2.61539 5.91647 2.97307 5.45351 3.42201C4.99061 3.87088 4.62511 4.40209 4.37634 4.98448C4.1276 5.5668 4 6.1898 4 6.81819L4 8L14 8Z" fill="#D1A91E"/>
<path fill-rule="evenodd" clip-rule="evenodd" d="M2 9C2 8.44772 2.44772 8 3 8H15C15.5523 8 16 8.44772 16 9V12C16 12.5523 15.5523 13 15 13H3C2.44772 13 2 12.5523 2 12V9ZM4 10V11H14V10H4Z" fill="#D1A91E"/>
<path fill-rule="evenodd" clip-rule="evenodd" d="M0 13C0 11.8954 0.895431 11 2 11H16C17.1046 11 18 11.8954 18 13V17C18 17.5523 17.5523 18 17 18H1C0.447715 18 0 17.5523 0 17V13ZM16 13H2V16H16V13Z" fill="#D1A91E"/>
<path fill-rule="evenodd" clip-rule="evenodd" d="M9 6C9.55228 6 10 5.55228 10 5C10 4.44772 9.55228 4 9 4C8.44772 4 8 4.44772 8 5C8 5.55228 8.44772 6 9 6ZM9 7C10.1046 7 11 6.10457 11 5C11 3.89543 10.1046 3 9 3C7.89543 3 7 3.89543 7 5C7 6.10457 7.89543 7 9 7Z" fill="#D1A91E"/>
</svg>`
/* Motion devices */
window["env"]["svg"]["deviceMotion"] = `<svg class="icon icon-camera" width="18" height="18" viewBox="0 0 18 18" fill="none" xmlns="http://www.w3.org/2000/svg">
<path fill-rule="evenodd" clip-rule="evenodd" d="M15.7071 9.70711C15.5196 9.89464 15.2652 10 15 10L3 10C2.44772 10 2 9.55228 2 9L2 6.81819C2 5.91846 2.18279 5.02831 2.53711 4.19884C2.89139 3.36945 3.40981 2.61787 4.06121 1.98621C4.71255 1.3546 5.48415 0.85516 6.33118 0.514938C7.17817 0.174736 8.08494 -2.61718e-07 9 -3.41715e-07C9.91505 -4.21712e-07 10.8218 0.174736 11.6688 0.514938C12.5159 0.855159 13.2874 1.3546 13.9388 1.98621C14.5902 2.61787 15.1086 3.36944 15.4629 4.19884C15.8172 5.02831 16 5.91846 16 6.81819L16 9C16 9.26522 15.8946 9.51957 15.7071 9.70711ZM14 8L14 6.81819C14 6.1898 13.8724 5.5668 13.6237 4.98448C13.3749 4.40209 13.0094 3.87088 12.5465 3.42201C12.0835 2.97307 11.5323 2.61539 10.9234 2.37083C10.3145 2.12625 9.66081 2 9 2C8.33919 2 7.68554 2.12625 7.07662 2.37083C6.46775 2.61539 5.91647 2.97307 5.45351 3.42201C4.99061 3.87088 4.62511 4.40209 4.37634 4.98448C4.1276 5.5668 4 6.1898 4 6.81819L4 8L14 8Z" fill="#B83E3E"/>
<path fill-rule="evenodd" clip-rule="evenodd" d="M2 9C2 8.44772 2.44772 8 3 8H15C15.5523 8 16 8.44772 16 9V12C16 12.5523 15.5523 13 15 13H3C2.44772 13 2 12.5523 2 12V9ZM4 10V11H14V10H4Z" fill="#B83E3E"/>
<path fill-rule="evenodd" clip-rule="evenodd" d="M0 13C0 11.8954 0.895431 11 2 11H16C17.1046 11 18 11.8954 18 13V17C18 17.5523 17.5523 18 17 18H1C0.447715 18 0 17.5523 0 17V13ZM16 13H2V16H16V13Z" fill="#B83E3E"/>
<path fill-rule="evenodd" clip-rule="evenodd" d="M9 6C9.55228 6 10 5.55228 10 5C10 4.44772 9.55228 4 9 4C8.44772 4 8 4.44772 8 5C8 5.55228 8.44772 6 9 6ZM9 7C10.1046 7 11 6.10457 11 5C11 3.89543 10.1046 3 9 3C7.89543 3 7 3.89543 7 5C7 6.10457 7.89543 7 9 7Z" fill="#B83E3E"/>
</svg>`
/* Cellphone */
window["env"]["svg"]["cell phone"] = `<svg class="icon icon-cell phone" width="18" height="18" viewBox="0 0 18 18" fill="none" xmlns="http://www.w3.org/2000/svg">
<path fill-rule="evenodd" clip-rule="evenodd" d="M0 3C0 1.34315 1.34315 0 3 0H15C16.6569 0 18 1.34315 18 3V15C18 16.6569 16.6569 18 15 18H3C1.34315 18 0 16.6569 0 15V3ZM3 2C2.44772 2 2 2.44772 2 3V15C2 15.5523 2.44772 16 3 16H15C15.5523 16 16 15.5523 16 15V3C16 2.44772 15.5523 2 15 2H3Z" fill="#A69D9D"/>
@@ -167,6 +233,15 @@
<path fill-rule="evenodd" clip-rule="evenodd" d="M7.27473 7.03849C7.80577 7.19021 8.11326 7.7437 7.96154 8.27473L6.96154 11.7747C6.80981 12.3058 6.25633 12.6133 5.72529 12.4615C5.19426 12.3098 4.88677 11.7563 5.03849 11.2253L6.03849 7.72529C6.19021 7.19426 6.7437 6.88677 7.27473 7.03849Z" fill="currentColor"/>
</svg>`
/* Motorcycle (Alerts > Detections, detection classification) */
window["env"]["svg"]["motorcycle"] = `<svg class="icon icon-cyclist" width="18" height="18" viewBox="0 0 18 18" fill="none" xmlns="http://www.w3.org/2000/svg">
<path fill-rule="evenodd" clip-rule="evenodd" d="M4 12C2.89543 12 2 12.8954 2 14C2 15.1046 2.89543 16 4 16C5.10457 16 6 15.1046 6 14C6 12.8954 5.10457 12 4 12ZM0 14C0 11.7909 1.79086 10 4 10C6.20914 10 8 11.7909 8 14C8 16.2091 6.20914 18 4 18C1.79086 18 0 16.2091 0 14Z" fill="currentColor"/>
<path fill-rule="evenodd" clip-rule="evenodd" d="M11.5 2C11.2239 2 11 2.22386 11 2.5C11 2.77614 11.2239 3 11.5 3C11.7761 3 12 2.77614 12 2.5C12 2.22386 11.7761 2 11.5 2ZM9 2.5C9 1.11929 10.1193 0 11.5 0C12.8807 0 14 1.11929 14 2.5C14 3.88071 12.8807 5 11.5 5C10.1193 5 9 3.88071 9 2.5Z" fill="currentColor"/>
<path fill-rule="evenodd" clip-rule="evenodd" d="M14 12C12.8954 12 12 12.8954 12 14C12 15.1046 12.8954 16 14 16C15.1046 16 16 15.1046 16 14C16 12.8954 15.1046 12 14 12ZM10 14C10 11.7909 11.7909 10 14 10C16.2091 10 18 11.7909 18 14C18 16.2091 16.2091 18 14 18C11.7909 18 10 16.2091 10 14Z" fill="currentColor"/>
<path fill-rule="evenodd" clip-rule="evenodd" d="M16 8C16 8.55228 15.5523 9 15 9L12 9C11.7729 9 11.5526 8.92272 11.3753 8.78087L9.5 7.28062L8.49713 8.08292L10.7071 10.2929C11.0976 10.6834 11.0976 11.3166 10.7071 11.7071L7.70711 14.7071C7.31658 15.0976 6.68342 15.0976 6.29289 14.7071C5.90237 14.3166 5.90237 13.6834 6.29289 13.2929L8.58579 11L6.29289 8.70711C6.09176 8.50597 5.9858 8.22871 6.00153 7.9447C6.01726 7.66069 6.15319 7.39682 6.37531 7.21913L8.87531 5.21913C9.24052 4.92696 9.75948 4.92696 10.1247 5.21913L12.3508 7L15 7C15.5523 7 16 7.44771 16 8Z" fill="currentColor"/>
<path fill-rule="evenodd" clip-rule="evenodd" d="M7.27473 7.03849C7.80577 7.19021 8.11326 7.7437 7.96154 8.27473L6.96154 11.7747C6.80981 12.3058 6.25633 12.6133 5.72529 12.4615C5.19426 12.3098 4.88677 11.7563 5.03849 11.2253L6.03849 7.72529C6.19021 7.19426 6.7437 6.88677 7.27473 7.03849Z" fill="currentColor"/>
</svg>`
/* Credit card (Subscriptions > Billing) */
window["env"]["svg"]["credit-card"] = `<svg class="icon icon-credit-card" width="18" height="18" viewBox="0 0 18 18" fill="none" xmlns="http://www.w3.org/2000/svg">
<path fill-rule="evenodd" clip-rule="evenodd" d="M0 7C0 6.44772 0.447715 6 1 6H17C17.5523 6 18 6.44772 18 7C18 7.55228 17.5523 8 17 8H1C0.447715 8 0 7.55228 0 7Z" fill="currentColor"/>
@@ -192,6 +267,13 @@
<path fill-rule="evenodd" clip-rule="evenodd" d="M9 2C5.13401 2 2 5.13401 2 9C2 12.866 5.13401 16 9 16C12.866 16 16 12.866 16 9C16 5.13401 12.866 2 9 2ZM0 9C0 4.02944 4.02944 0 9 0C13.9706 0 18 4.02944 18 9C18 13.9706 13.9706 18 9 18C4.02944 18 0 13.9706 0 9Z" fill="currentColor"/>
</svg>`
window["env"]["svg"]["cross-light-small"] = `
<svg width="12" height="12" viewBox="0 0 12 12" fill="none" xmlns="http://www.w3.org/2000/svg">
<path fill-rule="evenodd" clip-rule="evenodd" d="M0.195262 0.195262C0.455612 -0.0650874 0.877722 -0.0650874 1.13807 0.195262L11.8047 10.8619C12.0651 11.1223 12.0651 11.5444 11.8047 11.8047C11.5444 12.0651 11.1223 12.0651 10.8619 11.8047L0.195262 1.13807C-0.0650874 0.877722 -0.0650874 0.455612 0.195262 0.195262Z" fill="#A69D9D"/>
<path fill-rule="evenodd" clip-rule="evenodd" d="M0.195262 11.8047C-0.0650874 11.5444 -0.0650874 11.1223 0.195262 10.8619L10.8619 0.19526C11.1223 -0.0650897 11.5444 -0.0650897 11.8047 0.19526C12.0651 0.455611 12.0651 0.877719 11.8047 1.13807L1.13807 11.8047C0.877722 12.0651 0.455612 12.0651 0.195262 11.8047Z" fill="#A69D9D"/>
</svg>
`
/* Dashboard */
window["env"]["svg"]["dashboard"] = `<svg class="icon icon-dashboard" width="18" height="18" viewBox="0 0 18 18" fill="none" xmlns="http://www.w3.org/2000/svg">
<path fill-rule="evenodd" clip-rule="evenodd" d="M0 1C0 0.447715 0.447715 0 1 0H5C5.55228 0 6 0.447715 6 1V7C6 7.55228 5.55228 8 5 8H1C0.447715 8 0 7.55228 0 7V1ZM2 2V6H4V2H2Z" fill="currentColor"/>
@@ -303,7 +385,7 @@
<path d="M11 17H16C16.5523 17 17 16.5523 17 16V11" stroke="currentColor" stroke-width="2"/>
<path d="M7 17H2C1.44772 17 1 16.5523 1 16V11" stroke="currentColor" stroke-width="2"/>
</svg>`
/* Fullscreen close */
window["env"]["svg"]["fullscreen-close"] = `<svg class="icon icon-fullscreen-close" <svg width="16" height="16" viewBox="0 0 16 16" fill="none" xmlns="http://www.w3.org/2000/svg">
@@ -631,17 +713,35 @@
<path fill-rule="evenodd" clip-rule="evenodd" d="M11.6464 2.64645C11.8417 2.45118 12.1583 2.45118 12.3536 2.64645L15.3536 5.64645C15.5488 5.84171 15.5488 6.15829 15.3536 6.35355C15.1583 6.54882 14.8417 6.54882 14.6464 6.35355L11.6464 3.35355C11.4512 3.15829 11.4512 2.84171 11.6464 2.64645Z" fill="currentColor"/>
</svg>`
/* Plus */
window["env"]["svg"]["plus"] = `<svg class="icon icon-plus" width="18" height="18" viewBox="0 0 18 18" fill="none" xmlns="http://www.w3.org/2000/svg">
<path fill-rule="evenodd" clip-rule="evenodd" d="M9 13C9.55228 13 10 12.5523 10 12V6C10 5.44772 9.55228 5 9 5C8.44772 5 8 5.44772 8 6V12C8 12.5523 8.44772 13 9 13Z" fill="currentColor"/>
<path fill-rule="evenodd" clip-rule="evenodd" d="M13 9C13 8.44772 12.5523 8 12 8L6 8C5.44772 8 5 8.44772 5 9C5 9.55229 5.44772 10 6 10L12 10C12.5523 10 13 9.55228 13 9Z" fill="currentColor"/>
</svg>`
/* Plus circle ("add" button) */
window["env"]["svg"]["plus-circle"] = `<svg class="icon icon-plus-circle" width="18" height="18" viewBox="0 0 18 18" fill="none" xmlns="http://www.w3.org/2000/svg">
<path fill-rule="evenodd" clip-rule="evenodd" d="M9 16C5.13401 16 2 12.866 2 9C2 5.13401 5.13401 2 9 2C12.866 2 16 5.13401 16 9C16 12.866 12.866 16 9 16ZM0 9C0 13.9706 4.02944 18 9 18C13.9706 18 18 13.9706 18 9C18 4.02944 13.9706 0 9 0C4.02944 0 0 4.02944 0 9Z" fill="currentColor"/>
<path fill-rule="evenodd" clip-rule="evenodd" d="M9 13C9.55228 13 10 12.5523 10 12V6C10 5.44772 9.55228 5 9 5C8.44772 5 8 5.44772 8 6V12C8 12.5523 8.44772 13 9 13Z" fill="currentColor"/>
<path fill-rule="evenodd" clip-rule="evenodd" d="M13 9C13 8.44772 12.5523 8 12 8L6 8C5.44772 8 5 8.44772 5 9C5 9.55229 5.44772 10 6 10L12 10C12.5523 10 13 9.55228 13 9Z" fill="currentColor"/>
</svg>`
/* Plus circle ("add" button) */
window["env"]["svg"]["play-circle"] = `<svg class="icon icon-play-circle" width="18" height="18" viewBox="0 0 18 18" fill="none" xmlns="http://www.w3.org/2000/svg">
<path fill-rule="evenodd" clip-rule="evenodd" d="M18 9C18 13.9706 13.9706 18 9 18C4.02944 18 0 13.9706 0 9C0 4.02944 4.02944 0 9 0C13.9706 0 18 4.02944 18 9ZM7.27038 13.0048C6.93762 13.2187 6.5 12.9798 6.5 12.5842V5.41586C6.5 5.02027 6.93762 4.78135 7.27038 4.99527L12.8457 8.57943C13.1519 8.77625 13.1519 9.22379 12.8457 9.42061L7.27038 13.0048Z" fill="#fff"/>
<path fill-rule="evenodd" clip-rule="evenodd" d="M18 9C18 13.9706 13.9706 18 9 18C4.02944 18 0 13.9706 0 9C0 4.02944 4.02944 0 9 0C13.9706 0 18 4.02944 18 9ZM7.27038 13.0048C6.93762 13.2187 6.5 12.9798 6.5 12.5842V5.41586C6.5 5.02027 6.93762 4.78135 7.27038 4.99527L12.8457 8.57943C13.1519 8.77625 13.1519 9.22379 12.8457 9.42061L7.27038 13.0048Z" fill="currentColor"/>
</svg>`
/* Play */
window["env"]["svg"]["play"] = `<svg class="icon icon-play" width="18" height="18" viewBox="0 0 18 18" fill="none" xmlns="http://www.w3.org/2000/svg">
<path d="M6 4L14 9L6 14V4Z" fill="currentColor"/>
</svg>`
/* Pause */
window["env"]["svg"]["pause"] = `<svg class="icon icon-pause" width="18" height="18" viewBox="0 0 18 18" fill="none" xmlns="http://www.w3.org/2000/svg">
<rect x="5" y="4" width="3" height="10" rx="0.5" fill="currentColor"/>
<rect x="10" y="4" width="3" height="10" rx="0.5" fill="currentColor"/>
</svg>`
/* Preferences */
@@ -673,12 +773,32 @@
<path fill-rule="evenodd" clip-rule="evenodd" d="M3.29289 11.7071C2.90237 11.3166 2.90237 10.6834 3.29289 10.2929L8.29289 5.29289C8.68342 4.90237 9.31658 4.90237 9.70711 5.29289L14.7071 10.2929C15.0976 10.6834 15.0976 11.3166 14.7071 11.7071C14.3166 12.0976 13.6834 12.0976 13.2929 11.7071L9 7.41421L4.70711 11.7071C4.31658 12.0976 3.68342 12.0976 3.29289 11.7071Z" fill="white"/>
</svg>`
/* PTZ Center */
window["env"]["svg"]["ptz-center"] = `<svg class="icon icon-ptz-center" svg width="18" height="18" viewBox="0 0 18 18" fill="none" xmlns="http://www.w3.org/2000/svg">
window["env"]["svg"]["ptz-center"] = `<svg class="icon icon-ptz-center" width="18" height="18" viewBox="0 0 18 18" fill="none" xmlns="http://www.w3.org/2000/svg">
<path d="M7 1H2C1.44772 1 1 1.44772 1 2V7" stroke="currentColor" stroke-width="2"/>
<path d="M11 1H16C16.5523 1 17 1.44772 17 2V7" stroke="currentColor" stroke-width="2"/>
<path d="M11 17H16C16.5523 17 17 16.5523 17 16V11" stroke="currentColor" stroke-width="2"/>
<path d="M7 17H2C1.44772 17 1 16.5523 1 16V11" stroke="currentColor" stroke-width="2"/>
<path fill-rule="evenodd" clip-rule="evenodd" d="M9.2 12.0667C7.39587 12.0667 5.93333 10.6041 5.93333 8.8C5.93333 6.99587 7.39587 5.53333 9.2 5.53333C11.0041 5.53333 12.4667 6.99587 12.4667 8.8C12.4667 10.6041 11.0041 12.0667 9.2 12.0667ZM5 8.8C5 11.1196 6.8804 13 9.2 13C11.5196 13 13.4 11.1196 13.4 8.8C13.4 6.4804 11.5196 4.6 9.2 4.6C6.8804 4.6 5 6.4804 5 8.8Z" fill="white" stroke="currentColor"/>
<circle cx="9" cy="9" r="3" stroke="currentColor" stroke-width="2"/>
</svg>`
/* PTZ Zoom In */
window["env"]["svg"]["ptz-zoom-in"] = `<svg class="icon icon-ptz-zoom-in" width="18" height="18" viewBox="0 0 18 18" fill="none" xmlns="http://www.w3.org/2000/svg">
<path fill-rule="evenodd" clip-rule="evenodd" d="M9 3C9.55228 3 10 3.44772 10 4V8H14C14.5523 8 15 8.44772 15 9C15 9.55228 14.5523 10 14 10H10V14C10 14.5523 9.55228 15 9 15C8.44772 15 8 14.5523 8 14V10H4C3.44772 10 3 9.55228 3 9C3 8.44772 3.44772 8 4 8H8V4C8 3.44772 8.44772 3 9 3Z" fill="white"/>
</svg>`
/* PTZ Zoom Out */
window["env"]["svg"]["ptz-zoom-out"] = `<svg class="icon icon-ptz-zoom-out" width="18" height="18" viewBox="0 0 18 18" fill="none" xmlns="http://www.w3.org/2000/svg">
<path fill-rule="evenodd" clip-rule="evenodd" d="M3 9C3 8.44772 3.44772 8 4 8H14C14.5523 8 15 8.44772 15 9C15 9.55228 14.5523 10 14 10H4C3.44772 10 3 9.55228 3 9Z" fill="white"/>
</svg>`
/* Drag handle */
window["env"]["svg"]["drag"] = `<svg class="icon icon-drag" width="18" height="18" viewBox="0 0 18 18" fill="none" xmlns="http://www.w3.org/2000/svg">
<circle cx="6" cy="4" r="1.5" fill="currentColor"/>
<circle cx="12" cy="4" r="1.5" fill="currentColor"/>
<circle cx="6" cy="9" r="1.5" fill="currentColor"/>
<circle cx="12" cy="9" r="1.5" fill="currentColor"/>
<circle cx="6" cy="14" r="1.5" fill="currentColor"/>
<circle cx="12" cy="14" r="1.5" fill="currentColor"/>
</svg>`
/* Queue */
@@ -739,6 +859,14 @@
<path fill-rule="evenodd" clip-rule="evenodd" d="M8.98547 7.85756L3.98547 4.85756L5.01447 3.14258L10.0145 6.14258L8.98547 7.85756Z" fill="currentColor"/>
</svg>`
/* Link / Hyperlink */
window["env"]["svg"]["link"] = `<svg class="icon icon-link" width="18" height="18" viewBox="12 12 16 16" fill="none" xmlns="http://www.w3.org/2000/svg">
<path d="M16.5 27.5C15.4 27.5 14.4 27.1 13.6 26.3C12.8 25.5 12.4 24.5 12.4 23.4C12.4 22.3 12.8 21.3 13.6 20.5L15.5 18.6C15.7 18.4 16 18.4 16.2 18.6C16.4 18.8 16.4 19.1 16.2 19.3L14.3 21.2C13.7 21.8 13.4 22.5 13.4 23.4C13.4 24.3 13.7 25 14.3 25.6C15.5 26.8 17.5 26.8 18.6 25.6L20.5 23.7C20.7 23.5 21 23.5 21.2 23.7C21.4 23.9 21.4 24.2 21.2 24.4L19.3 26.3C18.6 27.1 17.6 27.5 16.5 27.5Z" fill="currentColor" stroke="currentColor" stroke-width="1" stroke-linejoin="round"/>
<path d="M24.1 21.4C24 21.4 23.8 21.4 23.7 21.3C23.5 21.1 23.5 20.8 23.7 20.6L25.6 18.7C26.8 17.5 26.8 15.6 25.6 14.4C24.4 13.2 22.5 13.2 21.3 14.4L19.4 16.3C19.2 16.5 18.9 16.5 18.7 16.3C18.5 16.1 18.5 15.8 18.7 15.6L20.6 13.7C22.2 12.1 24.7 12.1 26.3 13.7C27.9 15.3 27.9 17.8 26.3 19.4L24.4 21.3C24.4 21.4 24.2 21.4 24.1 21.4Z" fill="currentColor" stroke="currentColor" stroke-width="1" stroke-linejoin="round"/>
<path d="M16.5 24C16.4 24 16.2 24 16.1 23.9C15.9 23.7 15.9 23.4 16.1 23.2L23 16.3C23.2 16.1 23.5 16.1 23.7 16.3C23.9 16.5 23.9 16.8 23.7 17L16.8 23.9C16.8 23.9 16.6 24 16.5 24Z" fill="currentColor" stroke="currentColor" stroke-width="1" stroke-linejoin="round"/>
</svg>`
window["env"]["svg"]["hyperlink"] = window["env"]["svg"]["link"]
/* Shield check ("verify") */
window["env"]["svg"]["shield-check"] = `<svg class="icon icon-shield-check" width="18" height="18" viewBox="0 0 18 18" fill="none" xmlns="http://www.w3.org/2000/svg">
<path fill-rule="evenodd" clip-rule="evenodd" d="M6.04289 7.79289C6.43342 7.40237 7.06658 7.40237 7.45711 7.79289L8.25 8.58579L10.5429 6.29289C10.9334 5.90237 11.5666 5.90237 11.9571 6.29289C12.3476 6.68342 12.3476 7.31658 11.9571 7.70711L8.95711 10.7071C8.56658 11.0976 7.93342 11.0976 7.54289 10.7071L6.04289 9.20711C5.65237 8.81658 5.65237 8.18342 6.04289 7.79289Z" fill="currentColor"/>
@@ -798,12 +926,26 @@
<path fill-rule="evenodd" clip-rule="evenodd" d="M9 4C9.55228 4 10 4.44772 10 5V13C10 13.5523 9.55228 14 9 14C8.44772 14 8 13.5523 8 13V5C8 4.44772 8.44772 4 9 4Z" fill="currentColor"/>
</svg>`
/* Invoice */
window["env"]["svg"]["invoice"] = `<svg class="icon icon-invoice" width="18" height="18" viewBox="0 0 18 18" fill="none" xmlns="http://www.w3.org/2000/svg">
<path fill-rule="evenodd" clip-rule="evenodd" d="M5.9453 5.54295C6.58555 5.11611 7.47538 5 8.5 5H11C11.5523 5 12 5.44772 12 6C12 6.55228 11.5523 7 11 7H8.5C7.52462 7 7.16445 7.13389 7.0547 7.20705C7.03426 7.22067 7.03361 7.22365 7.03297 7.22658C7.03285 7.22715 7.03272 7.22772 7.03245 7.22837C7.02311 7.2508 7 7.32539 7 7.5C7 7.65149 7.01759 7.7156 7.02407 7.734C7.02962 7.73847 7.04039 7.74633 7.05864 7.75676C7.24508 7.8633 7.75279 8 9 8C10.2528 8 11.2451 8.1133 11.9336 8.50676C12.3184 8.72663 12.6117 9.03408 12.7919 9.4271C12.9615 9.79718 13 10.1769 13 10.5C13 10.8231 12.9615 11.2028 12.7919 11.5729C12.6117 11.9659 12.3184 12.2734 11.9336 12.4932C11.2451 12.8867 10.2528 13 9 13H7C6.44772 13 6 12.5523 6 12C6 11.4477 6.44772 11 7 11H9C10.2472 11 10.7549 10.8633 10.9414 10.7568C10.9596 10.7463 10.9704 10.7385 10.9759 10.734C10.9824 10.7156 11 10.6515 11 10.5C11 10.3485 10.9824 10.2844 10.9759 10.266C10.9704 10.2615 10.9596 10.2537 10.9414 10.2432C10.7549 10.1367 10.2472 10 9 10C7.74721 10 6.75492 9.8867 6.06636 9.49324C5.68159 9.27337 5.38825 8.96592 5.20812 8.5729C5.0385 8.20282 5 7.82305 5 7.5C5 6.82469 5.18169 6.05202 5.9453 5.54295Z" fill="currentColor"/>
<path fill-rule="evenodd" clip-rule="evenodd" d="M9 4C9.55228 4 10 4.44772 10 5V13C10 13.5523 9.55228 14 9 14C8.44772 14 8 13.5523 8 13V5C8 4.44772 8.44772 4 9 4Z" fill="currentColor"/>
<path fill-rule="evenodd" clip-rule="evenodd" d="M1 2C1 0.89543 1.89543 0 3 0H15C16.1046 0 17 0.89543 17 2V17C17 17.3214 16.8455 17.6233 16.5847 17.8112C16.3239 17.9992 15.9887 18.0503 15.6838 17.9487L13.0767 17.0797L11.4472 17.8944C11.1657 18.0352 10.8343 18.0352 10.5528 17.8944L9 17.118L7.44721 17.8944C7.16569 18.0352 6.83431 18.0352 6.55279 17.8944L4.92327 17.0797L2.31623 17.9487C2.01128 18.0503 1.67606 17.9992 1.41529 17.8112C1.15452 17.6233 1 17.3214 1 17V2ZM15 2H3V15.6126L4.68377 15.0513C4.93538 14.9674 5.21 14.987 5.44721 15.1056L7 15.882L8.55279 15.1056C8.83431 14.9648 9.16569 14.9648 9.44721 15.1056L11 15.882L12.5528 15.1056C12.79 14.987 13.0646 14.9674 13.3162 15.0513L15 15.6126V2Z" fill="currentColor"/>
</svg>`
/* Suitcase (detection classification) */
window["env"]["svg"]["suitcase"] = `<svg class="icon icon-suitcase" width="18" height="18" viewBox="0 0 18 18" fill="none" xmlns="http://www.w3.org/2000/svg">
<path fill-rule="evenodd" clip-rule="evenodd" d="M1 4C1 3.44772 1.44772 3 2 3H16C16.5523 3 17 3.44772 17 4V17C17 17.5523 16.5523 18 16 18H2C1.44772 18 1 17.5523 1 17V4ZM3 5V16H15V5H3Z" fill="currentColor"/>
<path fill-rule="evenodd" clip-rule="evenodd" d="M7.44781 0.328888C7.93778 0.112406 8.46542 0 9 0C9.53458 0 10.0622 0.112406 10.5522 0.328888C11.042 0.545285 11.4826 0.860547 11.8509 1.25332C12.219 1.64595 12.5078 2.10863 12.7038 2.61342C12.8998 3.11815 13 3.65709 13 4.2V5C13 5.55228 12.5523 6 12 6C11.4477 6 11 5.55228 11 5V4.2C11 3.90245 10.945 3.60916 10.8395 3.3374C10.734 3.06571 10.5808 2.82286 10.3918 2.6212C10.2029 2.41967 9.98209 2.26352 9.74391 2.15828C9.50593 2.05313 9.25335 2 9 2C8.74665 2 8.49407 2.05313 8.25609 2.15828C8.01791 2.26352 7.79715 2.41967 7.60822 2.6212C7.41916 2.82286 7.26605 3.06571 7.16054 3.3374C7.05501 3.60916 7 3.90245 7 4.2V5C7 5.55228 6.55228 6 6 6C5.44772 6 5 5.55228 5 5V4.2C5 3.65709 5.10018 3.11815 5.29618 2.61342C5.4922 2.10863 5.78105 1.64595 6.14914 1.25332C6.51736 0.860547 6.95803 0.545285 7.44781 0.328888Z" fill="currentColor"/>
</svg>`
/* Tag (Media > Filter) */
window["env"]["svg"]["tag"] = `<svg class="icon small icon-tag" width="18" height="18" viewBox="0 0 18 18" fill="none" xmlns="http://www.w3.org/2000/svg">
<path fill-rule="evenodd" clip-rule="evenodd" d="M0 0.999756C0 0.447471 0.447715 -0.000244141 1 -0.000244141H7C7.26522 -0.000244141 7.51957 0.105113 7.70711 0.292649L17.7071 10.2926C18.0976 10.6832 18.0976 11.3163 17.7071 11.7069L11.7071 17.7069C11.3166 18.0974 10.6834 18.0974 10.2929 17.7069L0.292893 7.70686C0.105357 7.51933 0 7.26497 0 6.99976V0.999756ZM2 1.99976V6.58554L11 15.5855L15.5858 10.9998L6.58579 1.99976H2Z" fill="currentColor"/>
<path fill-rule="evenodd" clip-rule="evenodd" d="M4.5 4.99976C4.77614 4.99976 5 4.7759 5 4.49976C5 4.22361 4.77614 3.99976 4.5 3.99976C4.22386 3.99976 4 4.22361 4 4.49976C4 4.7759 4.22386 4.99976 4.5 4.99976ZM4.5 5.99976C5.32843 5.99976 6 5.32818 6 4.49976C6 3.67133 5.32843 2.99976 4.5 2.99976C3.67157 2.99976 3 3.67133 3 4.49976C3 5.32818 3.67157 5.99976 4.5 5.99976Z" fill="currentColor"/>
</svg>`
/* Tag (Media > tagged sequence) */
window["env"]["svg"]["tag-small"] = `<svg class="icon small icon-tag-small" width="12" height="12" viewBox="0 0 12 12" fill="none" xmlns="http://www.w3.org/2000/svg">
<path fill-rule="evenodd" clip-rule="evenodd" d="M0 1.03575V3.71398C0 3.98868 0.109124 4.25213 0.303365 4.44637L7.55363 11.6966C7.95811 12.1011 8.61392 12.1011 9.0184 11.6966L11.6966 9.0184C12.1011 8.61391 12.1011 7.95811 11.6966 7.55363L4.44637 0.303364C4.25213 0.109123 3.98868 0 3.71398 0H1.03575C0.463722 0 0 0.463722 0 1.03575ZM2.0715 3.10726C2.64353 3.10726 3.10726 2.64353 3.10726 2.0715C3.10726 1.49947 2.64353 1.03575 2.0715 1.03575C1.49947 1.03575 1.03575 1.49947 1.03575 2.0715C1.03575 2.64353 1.49947 3.10726 2.0715 3.10726Z" fill="white"/>
@@ -880,10 +1022,228 @@
<rect x="-448.5" y="-610.5" width="1860" height="1045" stroke="currentColor" stroke-width="3"/>
</svg>`
/* Video wall (navigation) */
window["env"]["svg"]["videowall"] = `<svg class="icon icon-videowall" width="18" height="18" viewBox="0 0 18 18" fill="none" xmlns="http://www.w3.org/2000/svg">
<path fill-rule="evenodd" clip-rule="evenodd" d="M0 1C0 0.447715 0.447715 0 1 0H7C7.55228 0 8 0.447715 8 1V7C8 7.55228 7.55228 8 7 8H1C0.447715 8 0 7.55228 0 7V1ZM2 2V6H6V2H2Z" fill="currentColor"/>
<path fill-rule="evenodd" clip-rule="evenodd" d="M0 11C0 10.4477 0.447715 10 1 10H7C7.55228 10 8 10.4477 8 11V17C8 17.5523 7.55228 18 7 18H1C0.447715 18 0 17.5523 0 17V11ZM2 12V16H6V12H2Z" fill="currentColor"/>
<path fill-rule="evenodd" clip-rule="evenodd" d="M10 1C10 0.447715 10.4477 0 11 0H17C17.5523 0 18 0.447715 18 1V7C18 7.55228 17.5523 8 17 8H11C10.4477 8 10 7.55228 10 7V1ZM12 2V6H16V2H12Z" fill="currentColor"/>
<path fill-rule="evenodd" clip-rule="evenodd" d="M10 11C10 10.4477 10.4477 10 11 10H17C17.5523 10 18 10.4477 18 11V17C18 17.5523 17.5523 18 17 18H11C10.4477 18 10 17.5523 10 17V11ZM12 12V16H16V12H12Z" fill="currentColor"/>
<path fill-rule="evenodd" clip-rule="evenodd" d="M17 4C17 5.65685 15.6569 7 14 7C12.3431 7 11 5.65685 11 4C11 2.34315 12.3431 1 14 1C15.6569 1 17 2.34315 17 4ZM13.4234 5.33486C13.3125 5.40617 13.1667 5.32653 13.1667 5.19467V2.80522C13.1667 2.67336 13.3125 2.59372 13.4234 2.66502L15.2819 3.85975C15.384 3.92535 15.384 4.07453 15.2819 4.14014L13.4234 5.33486Z" fill="currentColor"/>
<path fill-rule="evenodd" clip-rule="evenodd" d="M17 14C17 15.6569 15.6569 17 14 17C12.3431 17 11 15.6569 11 14C11 12.3431 12.3431 11 14 11C15.6569 11 17 12.3431 17 14ZM13.4234 15.3349C13.3125 15.4062 13.1667 15.3265 13.1667 15.1947V12.8052C13.1667 12.6734 13.3125 12.5937 13.4234 12.665L15.2819 13.8597C15.384 13.9254 15.384 14.0745 15.2819 14.1401L13.4234 15.3349Z" fill="currentColor"/>
<path fill-rule="evenodd" clip-rule="evenodd" d="M7 4C7 5.65685 5.65685 7 4 7C2.34315 7 1 5.65685 1 4C1 2.34315 2.34315 1 4 1C5.65685 1 7 2.34315 7 4ZM3.42344 5.33486C3.31252 5.40617 3.16665 5.32653 3.16665 5.19467V2.80522C3.16665 2.67336 3.31252 2.59372 3.42344 2.66502L5.2819 3.85975C5.38395 3.92535 5.38395 4.07453 5.2819 4.14014L3.42344 5.33486Z" fill="currentColor"/>
<path fill-rule="evenodd" clip-rule="evenodd" d="M7 14C7 15.6569 5.65685 17 4 17C2.34315 17 1 15.6569 1 14C1 12.3431 2.34315 11 4 11C5.65685 11 7 12.3431 7 14ZM3.42344 15.3349C3.31252 15.4062 3.16665 15.3265 3.16665 15.1947V12.8052C3.16665 12.6734 3.31252 12.5937 3.42344 12.665L5.2819 13.8597C5.38395 13.9254 5.38395 14.0745 5.2819 14.1401L3.42344 15.3349Z" fill="currentColor"/>
</svg>`
/* User (Profile > Edit profile) */
window["env"]["svg"]["user"] = `<svg class="icon icon-user" width="18" height="18" viewBox="0 0 18 18" fill="none" xmlns="http://www.w3.org/2000/svg">
<path fill-rule="evenodd" clip-rule="evenodd" d="M9 2C7.89543 2 7 2.89543 7 4C7 5.10457 7.89543 6 9 6C10.1046 6 11 5.10457 11 4C11 2.89543 10.1046 2 9 2ZM5 4C5 1.79086 6.79086 0 9 0C11.2091 0 13 1.79086 13 4C13 6.20914 11.2091 8 9 8C6.79086 8 5 6.20914 5 4Z" fill="currentColor"/>
<path fill-rule="evenodd" clip-rule="evenodd" d="M3.9981 11.3995C5.29471 9.88675 7.08937 9 9 9C10.9106 9 12.7053 9.88675 14.0019 11.3995C15.2944 12.9074 16 14.9238 16 17C16 17.5523 15.5523 18 15 18L3 18C2.44772 18 2 17.5523 2 17C2 14.9238 2.70558 12.9074 3.9981 11.3995ZM9 11C7.72803 11 6.47044 11.5882 5.51662 12.701C4.75666 13.5877 4.24797 14.743 4.07017 16L13.9298 16C13.752 14.743 13.2433 13.5877 12.4834 12.701C11.5296 11.5882 10.272 11 9 11Z" fill="currentColor"/>
</svg>`
})(this);
/* Comments */
window["env"]["svg"]["comments"] = `<svg width="18" height="18" viewBox="0 0 18 18" fill="none" xmlns="http://www.w3.org/2000/svg">
<path clip-rule="evenodd" fill="#A69D9D" d="M9 17.25a1 1 0 0 1-1-1v-2.25H5.25a2 2 0 0 1-2-2V5.25a2 2 0 0 1 2-2h10.5a2 2 0 0 1 2 2v6.75a2 2 0 0 1-2 2h-3.075l-2.775 2.782c-.2.19-.45.293-.675.293zm.75-4.5v2.31L12.06 12.75h3.94V5.25H5.25v7.5zM2.25 11.25H.75V2.25a2 2 0 0 1 2-2h12V2.25H2.25z"/>
</svg>`
/* Details */
window["env"]["svg"]["details"] = `<svg width="18" height="18" viewBox="0 0 18 18" fill="none" xmlns="http://www.w3.org/2000/svg">
<path fill="#A69D9D" d="M16 2.25H2a1 1 0 0 0-1 1v11.5a1 1 0 0 0 1 1h14a1 1 0 0 0 1-1V3.25a1 1 0 0 0-1-1zm0 12.5H2V3.25h14v11.5z"/>
<path fill="#A69D9D" d="M4.5 8.25h9a.75.75 0 0 0 0-1.5h-9a.75.75 0 0 0 0 1.5zM4.5 10.25h9a.75.75 0 0 0 0-1.5h-9a.75.75 0 0 0 0 1.5zM4.5 12.25h5a.75.75 0 0 0 0-1.5h-5a.75.75 0 0 0 0 1.5z"/>
</svg>`;
/* Dots */
window["env"]["svg"]["dots"] = `<svg width="18" height="18" viewBox="0 0 18 18" fill="none" xmlns="http://www.w3.org/2000/svg">
<path d="M3.75 7.5C2.925 7.5 2.25 8.175 2.25 9C2.25 9.825 2.925 10.5 3.75 10.5C4.575 10.5 5.25 9.825 5.25 9C5.25 8.175 4.575 7.5 3.75 7.5ZM14.25 7.5C13.425 7.5 12.75 8.175 12.75 9C12.75 9.825 13.425 10.5 14.25 10.5C15.075 10.5 15.75 9.825 15.75 9C15.75 8.175 15.075 7.5 14.25 7.5ZM9 7.5C8.175 7.5 7.5 8.175 7.5 9C7.5 9.825 8.175 10.5 9 10.5C9.825 10.5 10.5 9.825 10.5 9C10.5 8.175 9.825 7.5 9 7.5Z" fill="black"/>
</svg>`;
/* Label */
window["env"]["svg"]["label"] = `<svg fill="#A69D9D" width="20" height="16" viewBox="0 0 20 16" fill="none" xmlns="http://www.w3.org/2000/svg">
<path d="M2 16C1.45 16 0.979333 15.8043 0.588 15.413C0.196667 15.0217 0.000666667 14.5507 0 14V2C0 1.45 0.196 0.979333 0.588 0.588C0.98 0.196666 1.45067 0.000666667 2 0H13C13.3167 0 13.6167 0.0709998 13.9 0.213C14.1833 0.355 14.4167 0.550667 14.6 0.8L20 8L14.6 15.2C14.4167 15.45 14.1833 15.646 13.9 15.788C13.6167 15.93 13.3167 16.0007 13 16H7.5H2ZM2 14H13L17.5 8L13 2H2V14Z"/>
</svg>`;
/* Settings */
window["env"]["svg"]["settings"] = `<svg width="18" height="18" viewBox="0 0 18 18" fill="none" xmlns="http://www.w3.org/2000/svg">
<path fill="currentColor" d="M14.5726 9.73502C14.6026 9.49502 14.6251 9.25502 14.6251 9.00002C14.6251 8.74502 14.6026 8.50502 14.5726 8.26502L16.1551 7.02752C16.2976 6.91502 16.3351 6.71252 16.2451
6.54752L14.7451 3.95252C14.7009 3.87514 14.6306 3.81603 14.5467 3.7858C14.4629 3.75556 14.371 3.75617 14.2876 3.78752L12.4201 4.53752C12.0301 4.23752 11.6101 3.99002 11.1526 3.80252L10.8676 1.81502C10.8549 1.72691 10.8106
1.64641 10.7431 1.58847C10.6755 1.53054 10.5891 1.49911 10.5001 1.50002H7.50012C7.31262 1.50002 7.15512 1.63502 7.13262 1.81502L6.84762 3.80252C6.39012 3.99002 5.97012 4.24502 5.58012 4.53752L3.71262 3.78752C3.66903 3.77318
3.62351 3.76559 3.57762 3.76502C3.45012 3.76502 3.32262 3.83252 3.25512 3.95252L1.75512 6.54752C1.65762 6.71252 1.70262 6.91502 1.84512 7.02752L3.42762 8.26502C3.39762 8.50502 3.37512 8.75252 3.37512 9.00002C3.37512 9.24752
3.39762 9.49502 3.42762 9.73502L1.84512 10.9725C1.70262 11.085 1.66512 11.2875 1.75512 11.4525L3.25512 14.0475C3.29934 14.1249 3.36966 14.184 3.4535 14.2142C3.53733 14.2445 3.6292 14.2439 3.71262 14.2125L5.58012 13.4625C5.97012
13.7625 6.39012 14.01 6.84762 14.1975L7.13262 16.185C7.15512 16.365 7.31262 16.5 7.50012 16.5H10.5001C10.6876 16.5 10.8451 16.365 10.8676 16.185L11.1526 14.1975C11.6101 14.01 12.0301 13.755 12.4201 13.4625L14.2876 14.2125C14.3326
14.2275 14.3776 14.235 14.4226 14.235C14.5501 14.235 14.6776 14.1675 14.7451 14.0475L16.2451 11.4525C16.3351 11.2875 16.2976 11.085 16.1551 10.9725L14.5726 9.73502ZM13.0876 8.45252C13.1176 8.68502 13.1251 8.84252 13.1251 9.00002C13.1251
9.15752 13.1101 9.32252 13.0876 9.54752L12.9826 10.395L13.6501 10.92L14.4601 11.55L13.9351 12.4575L12.9826 12.075L12.2026 11.76L11.5276 12.27C11.2051 12.51 10.8976 12.69 10.5901 12.8175L9.79512 13.14L9.67512 13.9875L9.52512 15H8.47512L8.33262
13.9875L8.21262 13.14L7.41762 12.8175C7.09512 12.6825 6.79512 12.51 6.49512 12.285L5.81262 11.76L5.01762 12.0825L4.06512 12.465L3.54012 11.5575L4.35012 10.9275L5.01762 10.4025L4.91262 9.55502C4.89012 9.32252 4.87512 9.15002 4.87512 9.00002C4.87512
8.85002 4.89012 8.67752 4.91262 8.45252L5.01762 7.60502L4.35012 7.08002L3.54012 6.45002L4.06512 5.54252L5.01762 5.92502L5.79762 6.24002L6.47262 5.73002C6.79512 5.49002 7.10262 5.31002 7.41012 5.18252L8.20512 4.86002L8.32512 4.01252L8.47512 3.00002H9.51762L9.66012
4.01252L9.78012 4.86002L10.5751 5.18252C10.8976 5.31752 11.1976 5.49002 11.4976 5.71502L12.1801 6.24002L12.9751 5.91752L13.9276 5.53502L14.4526 6.44252L13.6501 7.08002L12.9826 7.60502L13.0876 8.45252ZM9.00012 6.00002C7.34262 6.00002 6.00012 7.34252 6.00012 9.00002C6.00012
10.6575 7.34262 12 9.00012 12C10.6576 12 12.0001 10.6575 12.0001 9.00002C12.0001 7.34252 10.6576 6.00002 9.00012 6.00002ZM9.00012 10.5C8.17512 10.5 7.50012 9.82502 7.50012 9.00002C7.50012 8.17502 8.17512 7.50002 9.00012 7.50002C9.82512 7.50002 10.5001 8.17502 10.5001 9.00002C10.5001 9.82502 9.82512 10.5 9.00012 10.5Z"/>
</svg>`
/* Clock */
window["env"]["svg"]["clock"] = `<svg width="18" height="18" viewBox="0 0 18 18" fill="none" xmlns="http://www.w3.org/2000/svg">
<path fill="currentColor" d="M9 15C10.5913 15 12.1174 14.3679 13.2426 13.2426C14.3679 12.1174 15 10.5913 15 9C15 7.4087 14.3679 5.88258 13.2426 4.75736C12.1174 3.63214 10.5913 3 9 3C7.4087 3 5.88258 3.63214 4.75736 4.75736C3.63214 5.88258 3 7.4087 3 9C3 10.5913 3.63214 12.1174 4.75736 13.2426C5.88258 14.3679 7.4087 15 9 15ZM9 1.5C9.98491 1.5 10.9602 1.69399 11.8701 2.0709C12.7801 2.44781 13.6069 3.00026 14.3033 3.6967C14.9997 4.39314 15.5522 5.21993 15.9291 6.12987C16.306 7.03982 16.5 8.01509 16.5 9C16.5 10.9891 15.7098 12.8968 14.3033 14.3033C12.8968 15.7098 10.9891 16.5 9 16.5C4.8525 16.5 1.5 13.125 1.5 9C1.5 7.01088 2.29018 5.10322 3.6967 3.6967C5.10322 2.29018 7.01088 1.5 9 1.5ZM9.375 5.25V9.1875L12.75 11.19L12.1875 12.1125L8.25 9.75V5.25H9.375Z"/>
</svg>`;
/* Light mode */
window["env"]["svg"]["lightmode"] = `<svg width="18" height="18" viewBox="0 0 18 18" fill="none" xmlns="http://www.w3.org/2000/svg">
<path fill="currentColor" d="M8 12C10.2091 12 12 10.2091 12 8C12 5.79086 10.2091 4 8 4C5.79086 4 4 5.79086 4 8C4 10.2091 5.79086 12 8 12Z" stroke="currentColor" stroke-linecap="round" stroke-linejoin="round"/>
<path fill="currentColor" d="M14.667 8H15.3337" stroke="currentColor" stroke-linecap="round" stroke-linejoin="round"/>
<path fill="currentColor" d="M8 1.33268V0.666016" stroke="currentColor" stroke-linecap="round" stroke-linejoin="round"/>
<path fill="currentColor" d="M8 15.3327V14.666" stroke="currentColor" stroke-linecap="round" stroke-linejoin="round"/>
<path fill="currentColor" d="M13.3337 13.3327L12.667 12.666" stroke="currentColor" stroke-linecap="round" stroke-linejoin="round"/>
<path fill="currentColor" d="M13.3337 2.66602L12.667 3.33268" stroke="currentColor" stroke-linecap="round" stroke-linejoin="round"/>
<path fill="currentColor" d="M2.66699 13.3327L3.33366 12.666" stroke="currentColor" stroke-linecap="round" stroke-linejoin="round"/>
<path fill="currentColor" d="M2.66699 2.66602L3.33366 3.33268" stroke="currentColor" stroke-linecap="round" stroke-linejoin="round"/>
<path fill="currentColor" d="M0.666992 8H1.33366" stroke="black" stroke-linecap="currentColor" stroke-linejoin="round"/>
</svg>`;
/* Dark mode */
window["env"]["svg"]["darkmode"] = `<svg width="18" height="18" viewBox="0 0 18 18" fill="none" xmlns="http://www.w3.org/2000/svg">
<path fill="currentColor" d="M2 7.67107C2 11.1665 4.83356 14 8.32893 14C10.8139 14 12.9644 12.5679 14 10.4839C8.32893 10.4839 5.51607 7.67107 5.51607 2C3.43214 3.03563 2 5.1861 2 7.67107Z" stroke="currentColor" stroke-linecap="round" stroke-linejoin="round"/>
</svg>`;
/* Counting line */
window["env"]["svg"]["counting"] = `<svg width="18" height="18" viewBox="0 0 18 18" fill="none" xmlns="http://www.w3.org/2000/svg">
<path d="M4.5 14H13.5" stroke="currentColor" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"/>
<path d="M9 11V2M9 2L11.625 4.625M9 2L6.375 4.625" stroke="currentColor" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"/>
</svg>`;
/* Counting line in */
window["env"]["svg"]["countingIn"] = `<svg width="18" height="18" viewBox="0 0 18 18" fill="none" xmlns="http://www.w3.org/2000/svg">
<path d="M3.06836 13.5L3.06836 4.5" stroke="currentColor" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"/>
<path d="M15.1689 9H6.16895M6.16895 9L8.79395 6.375M6.16895 9L8.79395 11.625" stroke="currentColor" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"/>
</svg>`;
/* Counting line out */
window["env"]["svg"]["countingOut"] = `<svg width="18" height="18" viewBox="0 0 18 18" fill="none" xmlns="http://www.w3.org/2000/svg">
<path d="M4 4.5L4 13.5" stroke="currentColor" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"/>
<path d="M7 9H16M16 9L13.375 11.625M16 9L13.375 6.375" stroke="currentColor" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"/>
</svg>`;
/* Counting Region */
window["env"]["svg"]["countingRegion"] = `<svg class="icon icon-group" width="18" height="18" viewBox="0 0 18 18" fill="none" xmlns="http://www.w3.org/2000/svg">
<path fill-rule="evenodd" clip-rule="evenodd" d="M0 1C0 0.447715 0.447715 0 1 0H5C5.55228 0 6 0.447715 6 1V5C6 5.55228 5.55228 6 5 6H1C0.447715 6 0 5.55228 0 5V1ZM2 2V4H4V2H2Z" fill="currentColor"/>
<path fill-rule="evenodd" clip-rule="evenodd" d="M0 13C0 12.4477 0.447715 12 1 12H5C5.55228 12 6 12.4477 6 13V17C6 17.5523 5.55228 18 5 18H1C0.447715 18 0 17.5523 0 17V13ZM2 14V16H4V14H2Z" fill="currentColor"/>
<path fill-rule="evenodd" clip-rule="evenodd" d="M12 1C12 0.447715 12.4477 0 13 0H17C17.5523 0 18 0.447715 18 1V5C18 5.55228 17.5523 6 17 6H13C12.4477 6 12 5.55228 12 5V1ZM14 2V4H16V2H14Z" fill="currentColor"/>
<path fill-rule="evenodd" clip-rule="evenodd" d="M12 13C12 12.4477 12.4477 12 13 12H17C17.5523 12 18 12.4477 18 13V17C18 17.5523 17.5523 18 17 18H13C12.4477 18 12 17.5523 12 17V13ZM14 14V16H16V14H14Z" fill="currentColor"/>
<path fill-rule="evenodd" clip-rule="evenodd" d="M2 13V5H4V13H2Z" fill="currentColor"/>
<path fill-rule="evenodd" clip-rule="evenodd" d="M13 16L5 16L5 14L13 14L13 16Z" fill="currentColor"/>
<path fill-rule="evenodd" clip-rule="evenodd" d="M14 13V5H16V13H14Z" fill="currentColor"/>
<path fill-rule="evenodd" clip-rule="evenodd" d="M13 4L5 4L5 2L13 2L13 4Z" fill="currentColor"/>
</svg>`
/* Load more */
window["env"]["svg"]["loadMore"] = ` <svg width="12" height="18" viewBox="0 0 12 18" fill="none" xmlns="http://www.w3.org/2000/svg">
<g opacity="0.5">
<path fill-rule="evenodd" clip-rule="evenodd" d="M11.7071 11.2929C12.0976 11.6834 12.0976 12.3166 11.7071 12.7071L6.70711 17.7071C6.31658 18.0976 5.68342 18.0976 5.29289 17.7071L0.292893 12.7071C-0.0976315 12.3166 -0.0976315 11.6834 0.292893 11.2929C0.683417 10.9024 1.31658 10.9024 1.70711 11.2929L6 15.5858L10.2929 11.2929C10.6834 10.9024 11.3166 10.9024 11.7071 11.2929Z" fill="white"/>
<path fill-rule="evenodd" clip-rule="evenodd" d="M6 18C6.55228 18 7 17.5523 7 17L7 1C7 0.447716 6.55228 -5.33895e-09 6 -1.19249e-08C5.44772 -1.85108e-08 5 0.447716 5 1L5 17C5 17.5523 5.44772 18 6 18Z" fill="white"/>
</g>
</svg>`;
/* Loading */
window["env"]["svg"]["loading"] = `<svg width="18" height="18" viewBox="0 0 18 18" fill="none" xmlns="http://www.w3.org/2000/svg">
<g id="loading">
<animateTransform
attributeName="transform"
type="rotate"
values="0 9 9; 60 9 9; 120 9 9; 180 9 9; 240 9 9; 300 9 9"
dur="0.75s"
repeatCount="indefinite"
calcMode="discrete" />
<circle cx="9" cy="3" r="3" fill="currentColor"/>
<path d="M6.33155 6.00218C6.33155 7.38289 5.21226 8.50218 3.83155 8.50218C2.45084 8.50218 1.33155 7.38289 1.33155 6.00218C1.33155 4.62147 2.45084 3.50218 3.83155 3.50218C5.21226 3.50218 6.33155 4.62147 6.33155 6.00218Z" fill="currentColor"/>
<path d="M5.79858 12.0042C5.79858 13.1087 4.90315 14.0042 3.79858 14.0042C2.69401 14.0042 1.79858 13.1087 1.79858 12.0042C1.79858 10.8996 2.69401 10.0042 3.79858 10.0042C4.90315 10.0042 5.79858 10.8996 5.79858 12.0042Z" fill="currentColor"/>
<path d="M10.5 15C10.5 15.8284 9.82843 16.5 9 16.5C8.17157 16.5 7.5 15.8284 7.5 15C7.5 14.1716 8.17157 13.5 9 13.5C9.82843 13.5 10.5 14.1716 10.5 15Z" fill="currentColor"/>
<path d="M15.1843 12.0012C15.1843 12.5535 14.7366 13.0012 14.1843 13.0012C13.632 13.0012 13.1843 12.5535 13.1843 12.0012C13.1843 11.4489 13.632 11.0012 14.1843 11.0012C14.7366 11.0012 15.1843 11.4489 15.1843 12.0012Z" fill="currentColor"/>
</g>
</svg>`;
window["env"]["svg"]["timeline"] = `
<svg width="18" height="18" viewBox="0 0 18 18" fill="none" xmlns="http://www.w3.org/2000/svg">
<path fill-rule="evenodd" clip-rule="evenodd" d="M3 2C2.44772 2 2 2.44772 2 3C2 3.55228 2.44772 4 3 4C3.55228 4 4 3.55228 4 3C4 2.44772 3.55228 2 3 2ZM0 3C0 1.34315 1.34315 0 3 0C4.65685 0 6 1.34315 6 3C6 4.65685 4.65685 6 3 6C1.34315 6 0 4.65685 0 3Z" fill="currentColor"/>
<path fill-rule="evenodd" clip-rule="evenodd" d="M7 2C6.44772 2 6 2.44772 6 3C6 3.55228 6.44772 4 7 4C7.55228 4 8 3.55228 8 3C8 2.44772 7.55228 2 7 2ZM4 3C4 1.34315 5.34315 0 7 0C8.65685 0 10 1.34315 10 3C10 4.65685 8.65685 6 7 6C5.34315 6 4 4.65685 4 3Z" fill="currentColor"/>
<path fill-rule="evenodd" clip-rule="evenodd" d="M11 2C10.4477 2 10 2.44772 10 3C10 3.55228 10.4477 4 11 4C11.5523 4 12 3.55228 12 3C12 2.44772 11.5523 2 11 2ZM8 3C8 1.34315 9.34315 0 11 0C12.6569 0 14 1.34315 14 3C14 4.65685 12.6569 6 11 6C9.34315 6 8 4.65685 8 3Z" fill="currentColor"/>
<path fill-rule="evenodd" clip-rule="evenodd" d="M15 10C14.4477 10 14 10.4477 14 11C14 11.5523 14.4477 12 15 12C15.5523 12 16 11.5523 16 11C16 10.4477 15.5523 10 15 10ZM12 11C12 9.34315 13.3431 8 15 8C16.6569 8 18 9.34315 18 11C18 12.6569 16.6569 14 15 14C13.3431 14 12 12.6569 12 11Z" fill="currentColor"/>
<path fill-rule="evenodd" clip-rule="evenodd" d="M3 10C2.44772 10 2 10.4477 2 11C2 11.5523 2.44772 12 3 12C3.55228 12 4 11.5523 4 11C4 10.4477 3.55228 10 3 10ZM0 11C0 9.34315 1.34315 8 3 8C4.65685 8 6 9.34315 6 11C6 12.6569 4.65685 14 3 14C1.34315 14 0 12.6569 0 11Z" fill="currentColor"/>
<path fill-rule="evenodd" clip-rule="evenodd" d="M11 10C10.4477 10 10 10.4477 10 11C10 11.5523 10.4477 12 11 12C11.5523 12 12 11.5523 12 11C12 10.4477 11.5523 10 11 10ZM8 11C8 9.34315 9.34315 8 11 8C12.6569 8 14 9.34315 14 11C14 12.6569 12.6569 14 11 14C9.34315 14 8 12.6569 8 11Z" fill="currentColor"/>
<path fill-rule="evenodd" clip-rule="evenodd" d="M12 3C12 2.44772 12.4477 2 13 2H17C17.5523 2 18 2.44772 18 3C18 3.55228 17.5523 4 17 4H13C12.4477 4 12 3.55228 12 3Z" fill="currentColor"/>
<path fill-rule="evenodd" clip-rule="evenodd" d="M4 11C4 10.4477 4.44772 10 5 10H9C9.55228 10 10 10.4477 10 11C10 11.5523 9.55228 12 9 12H5C4.44772 12 4 11.5523 4 11Z" fill="currentColor"/>
</svg>
`
/* Hide right sidebar */
window["env"]["svg"]["hideRightSidebar"] = `<svg xmlns="http://www.w3.org/2000/svg" width="18px" height="18px" viewBox="0 0 24 24">
<path fill="currentColor" d="M7.22 14.47L9.69 12L7.22 9.53a.749.749 0 0 1 .326-1.275a.75.75 0 0 1 .734.215l3 3a.75.75 0 0 1 0 1.06l-3 3a.75.75 0 0 1-1.042-.018a.75.75 0 0 1-.018-1.042" />
<path fill="currentColor" d="M3.75 2h16.5c.966 0 1.75.784 1.75 1.75v16.5A1.75 1.75 0 0 1 20.25 22H3.75A1.75 1.75 0 0 1 2 20.25V3.75C2 2.784 2.784 2 3.75 2M3.5 3.75v16.5c0 .138.112.25.25.25H15v-17H3.75a.25.25 0 0 0-.25.25m13 16.75h3.75a.25.25 0 0 0 .25-.25V3.75a.25.25 0 0 0-.25-.25H16.5Z" />
</svg>`;
/* Show right sidebar */
window["env"]["svg"]["showRightSidebar"] = `<svg xmlns="http://www.w3.org/2000/svg" width="18px" height="18px" viewBox="0 0 24 24">
<path fill="currentColor" d="M11.28 9.53L8.81 12l2.47 2.47a.749.749 0 0 1-.326 1.275a.75.75 0 0 1-.734-.215l-3-3a.75.75 0 0 1 0-1.06l3-3a.749.749 0 0 1 1.275.326a.75.75 0 0 1-.215.734" />
<path fill="currentColor" d="M3.75 2h16.5c.966 0 1.75.784 1.75 1.75v16.5A1.75 1.75 0 0 1 20.25 22H3.75A1.75 1.75 0 0 1 2 20.25V3.75C2 2.784 2.784 2 3.75 2M3.5 3.75v16.5c0 .138.112.25.25.25H15v-17H3.75a.25.25 0 0 0-.25.25m13 16.75h3.75a.25.25 0 0 0 .25-.25V3.75a.25.25 0 0 0-.25-.25H16.5Z" />
</svg>`;
/* Back single */
window["env"]["svg"]["backSingle"] = `<svg class="icon icon-chevron-left" width="18" height="18" viewBox="0 0 18 18" fill="none" xmlns="http://www.w3.org/2000/svg">
<path d="M11.5 4.5L6.5 9L11.5 13.5" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"/>
</svg>`;
/* Back double */
window["env"]["svg"]["backDouble"] = `<svg class="icon icon-double-chevron-left-spaced" width="18" height="18" viewBox="0 0 18 18" fill="none" xmlns="http://www.w3.org/2000/svg">
<path d="M13.5 4.5L8.5 9L13.5 13.5" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"/>
<path d="M8 4.5L3 9L8 13.5" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"/>
</svg>`;
/* Forward single */
window["env"]["svg"]["forwardSingle"] = `<svg class="icon icon-chevron-right" width="18" height="18" viewBox="0 0 18 18" fill="none" xmlns="http://www.w3.org/2000/svg">
<path d="M6.5 4.5L11.5 9L6.5 13.5" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"/>
</svg>`;
/* Forward double */
window["env"]["svg"]["forwardDouble"] = `<svg class="icon icon-double-chevron-right-spaced" width="18" height="18" viewBox="0 0 18 18" fill="none" xmlns="http://www.w3.org/2000/svg">
<path d="M4.5 4.5L9.5 9L4.5 13.5" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"/>
<path d="M10 4.5L15 9L10 13.5" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"/>
</svg>`;
/* Marker */
window["env"]["svg"]["marker"] = `<svg width="18" height="18" viewBox="0 0 18 18" fill="none" xmlns="http://www.w3.org/2000/svg">
<g clip-path="url(#clip0_6_89)">
<path d="M16.6918 4.01166L14.074 1.31671C13.6638 0.894431 12.9964 0.894431 12.5862 1.31671L8.05873 5.97762L3.53129 10.6385L3.93802 11.0573L3.20337 11.8136L3.24617 11.9644C3.34893 12.3266 3.35504 12.7124 3.2638 13.08C3.17241 13.4465 2.98659 13.7818 2.72646 14.0496L2.10155 14.6929L2.27067 14.867L1 16.1751L2.71678 17L3.52971 16.1631L3.69883 16.3372L4.32369 15.6939C4.85375 15.1483 5.62995 14.9433 6.3494 15.1589L6.49581 15.2028L7.23039 14.4466L7.63697 14.8652L16.6918 5.54333C16.8905 5.33881 17 5.0668 17 4.77752C17 4.48823 16.8905 4.21622 16.6918 4.01166ZM2.60765 16.3622L1.88456 16.0148L2.63507 15.2421L2.90025 15.515L3.16542 15.788L2.60765 16.3622ZM6.3433 14.6096C5.48675 14.4095 4.58567 14.6741 3.95933 15.3188L3.69883 15.587L3.26457 15.14L2.83032 14.6929L3.09089 14.4247C3.41624 14.0898 3.64863 13.6704 3.76305 13.2116C3.86426 12.8037 3.86964 12.3778 3.7798 11.9704L4.30246 11.4324L6.86606 14.0715L6.3433 14.6096ZM16.3274 5.16823L7.63689 14.115L4.25998 10.6385L12.9505 1.69177C13.1598 1.4763 13.5003 1.4763 13.7097 1.69177L16.3274 4.38673C16.4288 4.49111 16.4847 4.62986 16.4847 4.77748C16.4847 4.92509 16.4288 5.06385 16.3274 5.16823Z" fill="currentColor" stroke="currentColor"/>
</g>
<defs>
<clipPath id="clip0_6_89">
<rect width="18" height="18" fill="white"/>
</clipPath>
</defs>
</svg>`;
/* Event */
window["env"]["svg"]["event"] = `<svg width="18" height="18" viewBox="0 0 18 18" fill="none" xmlns="http://www.w3.org/2000/svg">
<path d="M6 15.75V12M6 12V2.68281C6 2.33024 6.38707 2.11461 6.68686 2.30019L13.2796 6.3814C13.5581 6.55386 13.565 6.9567 13.2923 7.13844L6 12Z" stroke="currentColor" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"/>
</svg>`;
/* Category */
window["env"]["svg"]["category"] = `<svg width="18" height="18" viewBox="0 0 18 18" fill="none" xmlns="http://www.w3.org/2000/svg">
<g clip-path="url(#clip0_7_135)">
<path d="M5.25 4.5H12.75" stroke="" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"/>
<path d="M5.25 6.75H12.75" stroke="currentColor" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"/>
<path d="M6.75 12.75H11.25" stroke="currentColor" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"/>
<path d="M2.25 9H1.95C1.70147 9 1.5 9.20145 1.5 9.45V16.05C1.5 16.2986 1.70147 16.5 1.95 16.5H16.05C16.2986 16.5 16.5 16.2986 16.5 16.05V9.45C16.5 9.20145 16.2986 9 16.05 9H15.75M2.25 9V1.95C2.25 1.70147 2.45147 1.5 2.7 1.5H15.3C15.5486 1.5 15.75 1.70147 15.75 1.95V9M2.25 9H15.75" stroke="currentColor" stroke-width="1.5"/>
</g>
</svg>`;
/* Pin */
window["env"]["svg"]["pin"] = `<svg class="icon icon-pin" width="18" height="18" viewBox="0 0 24 24" fill="none" xmlns="http://www.w3.org/2000/svg">
<path d="M9.5 14.5L3 21" stroke="currentColor" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"/>
<path d="M5.00007 9.48528L14.1925 18.6777L15.8895 16.9806L15.4974 13.1944L21.0065 8.5211L15.1568 2.67141L10.4834 8.18034L6.69713 7.78823L5.00007 9.48528Z" stroke="currentColor" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"/>
</svg>`;
/* Unpin */
window["env"]["svg"]["unpin"] = `<svg class="icon icon-unpin" width="18" height="18" viewBox="0 0 24 24" fill="none" xmlns="http://www.w3.org/2000/svg">
<path d="M9.5 14.5L3 21" stroke="currentColor" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"/>
<path d="M7.67602 7.8896L6.69713 7.78823L5.00007 9.48528L14.1925 18.6777L15.8895 16.9806L15.7879 16M11.4847 7L15.1568 2.67141L21.0065 8.5211L16.6991 12.175" stroke="currentColor" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"/>
<path d="M3 3L21 21" stroke="currentColor" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"/>
</svg>`;
})(this);

View File

@@ -0,0 +1,409 @@
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="X-UA-Compatible" content="IE=edge" />
<meta http-equiv="Content-Type" content="text/html; charset=utf-8" />
<meta
name="viewport"
content="width=device-width, initial-scale=1, minimum-scale=1, maximum-scale=1"
/>
<meta name="description" content="Kerberos.io Mailing">
<style type="text/css">
@font-face {
font-family: 'Inter';
font-style: normal;
font-weight: 400;
font-display: swap;
src: url("https://kerberos.io/dist/fonts/Inter-Regular.woff?v=/dist/fonts/Inter-Regular.woff2?v=3.183.18") format("woff2"),
url("https://kerberos.io/dist/fonts/Inter-Regular.woff?v=/dist/fonts/Inter-Regular.woff2?v=3.183.18") format("woff");
}
@font-face {
font-family: 'Inter';
font-style: normal;
font-weight: 500;
font-display: swap;
src: url("https://kerberos.io/dist/fonts/Inter-Medium.woff2?v=3.18") format("woff2"),
url("https://kerberos.io/dist/fonts/Inter-Medium.woff?v=3.18") format("woff");
}
@font-face {
font-family: 'Inter';
font-style: normal;
font-weight: 600;
font-display: swap;
src: url("https://kerberos.io/dist/fonts/Inter-SemiBold.woff2?v=3.18") format("woff2"),
url("https://kerberos.io/dist/fonts/Inter-SemiBold.woff?v=3.18") format("woff");
}
@font-face {
font-family: 'Inter var';
font-weight: 100 900;
font-display: swap;
font-style: normal;
font-named-instance: 'Regular';
src: url("https://kerberos.io/dist/fonts/Inter-roman.var.woff2?v=3.18") format("woff2");
}
body{
background: #E5E5E5;
margin-top:0;
margin-bottom: 0;
margin-right: 0;
margin-left: 0;
padding-top: 0;
padding-left: 0;
padding-right: 0;
padding-bottom: 0;
font-family: 'Inter';
}
a, a:hover, a:active {
color: #262424;
text-decoration: none;
}
.corner-td{
width: 60px;
}
table {border-collapse:separate;max-width: 850px; margin: 0 auto; width: 100%;}
.ExternalClass p, .ExternalClass span, .ExternalClass font, .ExternalClass td {line-height: 100%;}
.ExternalClass {width: 100%;}
@media screen and (max-width:500px){
.tab-td{
padding-left: 10px!important;
}
.tab-td a h4{
font-size: 14px!important;
}
.corner-td{
width: 20px!important;
}
.company-name-td h3{
font-size: 16px!important;
}
table.header-table{
padding-top: 8px!important;
padding-right: 0px!important;
padding-bottom: 24px!important;
padding-left: 0px!important;
}
.colored-card-td h4{
font-size: 14px!important;
}
.colored-card-td h2{
font-size: 20px!important;
}
.colored-card-td a p{
font-size: 12px!important;
width: 143px!important;
}
.colored-card-td{
padding-top: 24px!important;
padding-right: 24px!important;
padding-bottom: 24px!important;
padding-left: 24px!important;
}
.colorless-card-td{
padding-top: 24px!important;
padding-right: 24px!important;
padding-bottom: 24px!important;
padding-left: 24px!important;
}
.colorless-card-td h3{
font-size: 18px!important;
}
.colorless-card-td p{
font-size: 14px!important;
}
.colorless-card-table{
margin-left: 0px!important;
margin-right: 0px!important;
margin-top: 24px!important;
margin-bottom: 24px!important;
}
.footer-td{
display: table-row!important;
}
}
@media screen and (max-width:600px) {
.footer-td{
display: table-row!important;
}
}
@media screen and (max-width:650px) {
.footer-table{
margin-left: 0px!important;
margin-right: 0px!important;
margin-top: 0px!important;
margin-bottom: 36px!important;
}
}
</style>
</head>
<body height="100%" width="100%">
<table border="0" cellpadding="0" cellspacing="0" width="100%" bgcolor="E5E5E5" style="border-collaps:collaps; mso-table-lspace:0pt; mso-table-rspace:0pt;">
<tr>
<td bgcolor="E5E5E5">
<table border="0" cellpadding="0" cellspacing="0" width="100%" height="36" class="header-table" style="padding-top: 36px ;padding-right: 0;padding-bottom: 36px;padding-left: 0;border-collaps:collaps; mso-table-lspace:0pt; mso-table-rspace:0pt;">
<tbody>
<tr>
<td class="corner-td" align="left"></td>
<td width="48" height="36" align="left"><img alt="Kerberos.io" width="36" height="36" src="https://kerberos.io/images/email/kerberos.png"/></td>
<td height="36" align="left" class="company-name-td">
<h3 width="36" height="36" style=" font-family: Inter;
font-size: 20px;
font-style: normal;
font-weight: 600;
line-height: 24px;
mso-line-height-rule:exactly;
letter-spacing: 0em;
text-align: left;
color: #262424;">Kerberos.io</h3>
</td>
<td height="36" width="36" style="padding-left: 36px;" class="tab-td" align="right">
<a style="text-decoration: none;color: none;" href={{tab1_href}}>
<h4 style="font-family: Inter;
font-size: 16px;
font-style: normal;
font-weight: 500;
line-height: 36px;
mso-line-height-rule:exactly;
letter-spacing: 0em;
text-align: right;
color: #6D6666;">{{tab1_title}}</h4>
</a>
</td>
<td height="36" width="36" style="padding-left: 36px;" class="tab-td" align="right" >
<a style="text-decoration: none;color: none;" href={{tab2_href}}>
<h4 style="font-family: Inter;
font-size: 16px;
font-style: normal;
font-weight: 500;
line-height: 36px;
mso-line-height-rule:exactly;
letter-spacing: 0em;
text-align: right;
color: #6D6666;">{{tab2_title}}</h4>
</a>
</td>
<td class="corner-td" align="right"></td>
</tr>
</tbody>
</table>
</td>
</tr>
</table>
<table border="0" cellpadding="0" cellspacing="0" width="100%" bgcolor="E5E5E5" style="border-collaps:collaps; mso-table-lspace:0pt; mso-table-rspace:0pt;">
<tr>
<td bgcolor="E5E5E5">
<table border="0" cellpadding="0" cellspacing="0" width="100%" style="border-collaps:collaps; mso-table-lspace:0pt; mso-table-rspace:0pt;" >
<tbody>
<tr>
<td class="corner-td" align="left"></td>
<td class="colored-card-td" bgcolor="#57356B" style="padding-left: 48px;padding-right: 48px;padding-top: 48px;padding-bottom: 48px;border-radius: 4px;background-color:#57356B;">
<h4 style="font-family: Inter;
font-size: 16px;
font-style: normal;
font-weight: 400;
line-height: 24px;
mso-line-height-rule:exactly;
letter-spacing: 0em;
text-align: left;
color:#b09fb9;">Hey, {{assignee}}</h4>
<h2 style=" font-family: Inter;
font-size: 24px;
font-style: normal;
font-weight: 600;
line-height: 36px;
mso-line-height-rule:exactly;
letter-spacing: 0em;
text-align: left;
color:#FFFFFF;
padding-top: 12px;
padding-bottom: 24px;
padding-left: 0;
padding-right: 0;">You have been assigned to a task</h2>
<p style="font-family: Inter;
font-size: 18px;
font-style: normal;
font-weight: 600;
line-height: 24px;
mso-line-height-rule:exactly;
letter-spacing: 0em;
text-align: left;
color:#FFFFFF;
padding-top: 0;
padding-bottom: 0;
padding-left: 0;
padding-right: 0;
">Task Details:</p>
<ul style="font-family: Inter;
font-size: 14px;
font-style: normal;
font-weight: 600;
line-height: 24px;
mso-line-height-rule:exactly;
letter-spacing: 0em;
text-align: left;
color:#FFFFFF;
padding-top: 0;
padding-bottom: 12px;
padding-left: 0;
padding-right: 0;
margin-left: 12px">
<li>Task Name: {{task_name}}</li>
<li>Assigned By: {{user}}</li>
</ul>
<a style="text-decoration: none;color: none;" href="{{link}}">
<p style="font-family: Inter;
font-size: 14px;
font-style: normal;
line-height: 20px;
mso-line-height-rule:exactly;
letter-spacing: 0em;
text-align: left;
color:#FFFFFF;
background-color: #84559F;
padding-top: 6px;
padding-bottom: 6px;
padding-right: 16px;
padding-left: 16px;
width: 166px;
border-radius: 4px;
cursor: pointer;">View task on kerberos hub</p>
</a>
</td>
<td class="corner-td" align="right"></td>
</tr>
</tbody>
</table>
</td>
</tr>
</table>
<table border="0" cellpadding="0" cellspacing="0" width="100%" bgcolor="E5E5E5" style="border-collaps:collaps; mso-table-lspace:0pt; mso-table-rspace:0pt;">
<tr>
<td bgcolor="E5E5E5">
<table border="0" cellpadding="0" cellspacing="0" width="100%" class="footer-table" style="margin-top: 0;border-collaps:collaps; mso-table-lspace:0pt; mso-table-rspace:0pt;" >
<tbody>
<tr>
<td class="corner-td" align="left"></td>
<!--[if mso | IE]>
<table role="presentation" border="0" cellpadding="0" cellspacing="0"><tr><td style="vertical-align:top;display:table-row !important">
<![endif]-->
<td height="146" width="190" class="footer-td" style="margin-bottom: 12px;" valign="top" align="left">
<table style="border-collaps:collaps; mso-table-lspace:0pt; mso-table-rspace:0pt;">
<tbody>
<tr>
<td>
<h4 style=" font-family: Inter;
font-size: 16px;
font-style: normal;
font-weight: 600;
line-height: 36px;
mso-line-height-rule:exactly;
letter-spacing: 0em;
text-align: left;
color:#6D6666;">Get in touch</h4>
<a style="text-decoration: none;color: none;" href="mailto:support@verstraeten.io">
<p style=" font-family: Inter;
font-size: 14px;
font-style: normal;
font-weight: 400;
line-height: 16px;
mso-line-height-rule:exactly;
letter-spacing: 0em;
text-align: left;
color: #A69D9D;">support@kerberos.io</p>
</a>
<p style=" font-family: Inter;
font-size: 14px;
font-style: normal;
font-weight: 400;
line-height: 16px;
mso-line-height-rule:exactly;
letter-spacing: 0em;
text-align: left;
color: #A69D9D;">9000 Ghent, BE</p>
<a style="text-decoration: none;color: none;" href="https://kerberos.io/">
<p style=" font-family: Inter;
font-size: 14px;
font-style: normal;
font-weight: 400;
line-height: 24px;
mso-line-height-rule:exactly;
letter-spacing: 0em;
text-align: left;
color: #A69D9D;">https://kerberos.io</p>
</a>
</td>
</tr>
</tbody>
</table>
</td>
<!--[if mso | IE]>
<table role="presentation" border="0" cellpadding="0" cellspacing="0"><tr><td style="vertical-align:top;display:table-row !important">
<![endif]-->
<td class="footer-td" style="border-radius: 4px;padding-left: 0;padding-right: 0;padding-top: 0;padding-bottom: 0; margin-bottom: 12px;" valign="top" align="left">
<table style="border-collaps:collaps; mso-table-lspace:0pt; mso-table-rspace:0pt;">
<tbody>
<tr>
<td>
<h4 style=" font-family: Inter;
font-size: 16px;
font-style: normal;
font-weight: 600;
line-height: 36px;
mso-line-height-rule:exactly;
letter-spacing: 0em;
text-align: left;
color:#6D6666;">About Kerberos</h4>
<p style=" font-family: Inter;
font-size: 14px;
font-style: normal;
font-weight: 400;
line-height: 24px;
mso-line-height-rule:exactly;
letter-spacing: 0em;
text-align: left;
color: #A69D9D;">Welcome to the revolutionary video analytics and video management platform. Open, modular, and extensible for everyone, anywhere.</p>
<p style="margin-top: 12px;">
<a href="https://twitter.com/kerberosio" style="text-decoration: none;color: none;">
<img width="24" height="24" alt="Twitter" src="https://kerberos.io/images/email/twitter.png"/>
</a>
<a href="https://reddit.com/r/kerberos_io" style="text-decoration: none;color: none;">
<img g width="24" height="24" alt="Reddit" src="https://kerberos.io/images/email/reddit.png"/>
</a>
<a href="https://www.youtube.com/channel/UCnd9q7iRNNw4W95eQwQuECA" style="text-decoration: none;color: none;">
<img g width="24" height="24" alt="Youtube" src="https://kerberos.io/images/email/youtube.png"/>
</a>
<a href="https://github.com/kerberos-io" style="text-decoration: none;color: none;">
<img g width="24" height="24" alt="Github" src="https://kerberos.io/images/email/github.png"/>
</a>
</p>
</td>
</tr>
</tbody>
</table>
</td>
<td class="corner-td" align="right"></td>
</tr>
</tbody>
</table>
<table style="border-collaps:collaps; mso-table-lspace:0pt; mso-table-rspace:0pt;">
<tbody>
<tr style="height: 50px">
<td></td>
</tr>
</tbody>
</table>
</td>
</tr>
</table>
</body>
</html>

View File

@@ -0,0 +1,19 @@
Kerberos.io
------------
Hey, {{assignee}}
You have been assigned to a new task on Kerberos Hub.
Task Details:
- Task Name: {{task_name}}
- Assigned By: {{user}}
- Link: {{link}}
Get in touch
------------
support@kerberos.io
9000 Ghent, BE
https://kerberos.io
About Kerberos
------------
Welcome to the revolutionary video analytics and video management platform. Open, modular, and extensible for everyone, anywhere.

View File

@@ -0,0 +1,418 @@
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="X-UA-Compatible" content="IE=edge" />
<meta http-equiv="Content-Type" content="text/html; charset=utf-8" />
<meta
name="viewport"
content="width=device-width, initial-scale=1, minimum-scale=1, maximum-scale=1"
/>
<meta name="description" content="Kerberos.io Mailing">
<style type="text/css">
@font-face {
font-family: 'Inter';
font-style: normal;
font-weight: 400;
font-display: swap;
src: url("https://kerberos.io/dist/fonts/Inter-Regular.woff?v=/dist/fonts/Inter-Regular.woff2?v=3.183.18") format("woff2"),
url("https://kerberos.io/dist/fonts/Inter-Regular.woff?v=/dist/fonts/Inter-Regular.woff2?v=3.183.18") format("woff");
}
@font-face {
font-family: 'Inter';
font-style: normal;
font-weight: 500;
font-display: swap;
src: url("https://kerberos.io/dist/fonts/Inter-Medium.woff2?v=3.18") format("woff2"),
url("https://kerberos.io/dist/fonts/Inter-Medium.woff?v=3.18") format("woff");
}
@font-face {
font-family: 'Inter';
font-style: normal;
font-weight: 600;
font-display: swap;
src: url("https://kerberos.io/dist/fonts/Inter-SemiBold.woff2?v=3.18") format("woff2"),
url("https://kerberos.io/dist/fonts/Inter-SemiBold.woff?v=3.18") format("woff");
}
@font-face {
font-family: 'Inter var';
font-weight: 100 900;
font-display: swap;
font-style: normal;
font-named-instance: 'Regular';
src: url("https://kerberos.io/dist/fonts/Inter-roman.var.woff2?v=3.18") format("woff2");
}
body{
background: #E5E5E5;
margin-top:0;
margin-bottom: 0;
margin-right: 0;
margin-left: 0;
padding-top: 0;
padding-left: 0;
padding-right: 0;
padding-bottom: 0;
font-family: 'Inter';
}
a, a:hover, a:active {
color: #262424;
text-decoration: none;
}
.corner-td{
width: 60px;
}
table {border-collapse:separate;max-width: 850px; margin: 0 auto; width: 100%;}
.ExternalClass p, .ExternalClass span, .ExternalClass font, .ExternalClass td {line-height: 100%;}
.ExternalClass {width: 100%;}
@media screen and (max-width:500px){
.tab-td{
padding-left: 10px!important;
}
.tab-td a h4{
font-size: 14px!important;
}
.corner-td{
width: 20px!important;
}
.company-name-td h3{
font-size: 16px!important;
}
table.header-table{
padding-top: 8px!important;
padding-right: 0px!important;
padding-bottom: 24px!important;
padding-left: 0px!important;
}
.colored-card-td h4{
font-size: 14px!important;
}
.colored-card-td h2{
font-size: 20px!important;
}
.colored-card-td a p{
font-size: 12px!important;
width: 143px!important;
}
.colored-card-td{
padding-top: 24px!important;
padding-right: 24px!important;
padding-bottom: 24px!important;
padding-left: 24px!important;
}
.colorless-card-td{
padding-top: 24px!important;
padding-right: 24px!important;
padding-bottom: 24px!important;
padding-left: 24px!important;
}
.colorless-card-td h3{
font-size: 18px!important;
}
.colorless-card-td p{
font-size: 14px!important;
}
.colorless-card-table{
margin-left: 0px!important;
margin-right: 0px!important;
margin-top: 24px!important;
margin-bottom: 24px!important;
}
.footer-td{
display: table-row!important;
}
}
@media screen and (max-width:600px) {
.footer-td{
display: table-row!important;
}
}
@media screen and (max-width:650px) {
.footer-table{
margin-left: 0px!important;
margin-right: 0px!important;
margin-top: 0px!important;
margin-bottom: 36px!important;
}
}
</style>
</head>
<body height="100%" width="100%">
<table border="0" cellpadding="0" cellspacing="0" width="100%" bgcolor="E5E5E5" style="border-collaps:collaps; mso-table-lspace:0pt; mso-table-rspace:0pt;">
<tr>
<td bgcolor="E5E5E5">
<table border="0" cellpadding="0" cellspacing="0" width="100%" height="36" class="header-table" style="padding-top: 36px ;padding-right: 0;padding-bottom: 36px;padding-left: 0;border-collaps:collaps; mso-table-lspace:0pt; mso-table-rspace:0pt;">
<tbody>
<tr>
<td class="corner-td" align="left"></td>
<td width="48" height="36" align="left"><img alt="Kerberos.io" width="36" height="36" src="https://kerberos.io/images/email/kerberos.png"/></td>
<td height="36" align="left" class="company-name-td">
<h3 width="36" height="36" style=" font-family: Inter;
font-size: 20px;
font-style: normal;
font-weight: 600;
line-height: 24px;
mso-line-height-rule:exactly;
letter-spacing: 0em;
text-align: left;
color: #262424;">Kerberos.io</h3>
</td>
<td height="36" width="36" style="padding-left: 36px;" class="tab-td" align="right">
<a style="text-decoration: none;color: none;" href={{tab1_href}}>
<h4 style="font-family: Inter;
font-size: 16px;
font-style: normal;
font-weight: 500;
line-height: 36px;
mso-line-height-rule:exactly;
letter-spacing: 0em;
text-align: right;
color: #6D6666;">{{tab1_title}}</h4>
</a>
</td>
<td height="36" width="36" style="padding-left: 36px;" class="tab-td" align="right" >
<a style="text-decoration: none;color: none;" href={{tab2_href}}>
<h4 style="font-family: Inter;
font-size: 16px;
font-style: normal;
font-weight: 500;
line-height: 36px;
mso-line-height-rule:exactly;
letter-spacing: 0em;
text-align: right;
color: #6D6666;">{{tab2_title}}</h4>
</a>
</td>
<td class="corner-td" align="right"></td>
</tr>
</tbody>
</table>
</td>
</tr>
</table>
<table border="0" cellpadding="0" cellspacing="0" width="100%" bgcolor="E5E5E5" style="border-collaps:collaps; mso-table-lspace:0pt; mso-table-rspace:0pt;">
<tr>
<td bgcolor="E5E5E5">
<table border="0" cellpadding="0" cellspacing="0" width="100%" style="border-collaps:collaps; mso-table-lspace:0pt; mso-table-rspace:0pt;" >
<tbody>
<tr>
<td class="corner-td" align="left"></td>
<td class="colored-card-td" bgcolor="#57356B" style="padding-left: 48px;padding-right: 48px;padding-top: 48px;padding-bottom: 48px;border-radius: 4px;background-color:#57356B;">
<h2 style=" font-family: Inter;
font-size: 24px;
font-style: normal;
font-weight: 600;
line-height: 36px;
mso-line-height-rule:exactly;
letter-spacing: 0em;
text-align: left;
color:#FFFFFF;
padding-top: 12px;
margin-bottom: 0;
padding-bottom: 0;
padding-left: 0;
padding-right: 0;">A case has been shared with you</h2>
<h4 style="font-family: Inter;
font-size: 16px;
font-style: normal;
font-weight: 400;
line-height: 24px;
mso-line-height-rule:exactly;
letter-spacing: 0em;
text-align: left;
color:#b09fb9;">{{user}} shared a case with you</h4>
</td>
<td class="corner-td" align="right"></td>
</tr>
</tbody>
</table>
</td>
</tr>
</table>
<table border="0" cellpadding="0" cellspacing="0" width="100%" bgcolor="E5E5E5" style="border-collaps:collaps; mso-table-lspace:0pt; mso-table-rspace:0pt;">
<tr>
<td bgcolor="E5E5E5">
<table border="0" cellpadding="0" cellspacing="0" width="100%" class="colorless-card-table" style="margin-top: 36px;margin-bottom: 36px;margin-left: 0;margin-right: 0;border-collaps:collaps; mso-table-lspace:0pt; mso-table-rspace:0pt;" >
<tbody>
<tr>
<td class="corner-td" align="left"></td>
<td class="colorless-card-td" bgcolor="#FFFFFF" style="background-color:#FFFFFF;padding-top: 36px;padding-right: 43px;padding-bottom: 25px;padding-left: 43px;border-radius: 4px;">
<h3 style=" font-family: Inter;
font-size: 20px;
font-style: normal;
font-weight: 600;
line-height: 36px;
mso-line-height-rule:exactly;
letter-spacing: 0em;
text-align: left;
color: #262424;
width: 280px">Open the shared case</h3>
<p style=" font-family: Inter;
font-size: 14px;
font-style: normal;
font-weight: 400;
line-height: 24px;
mso-line-height-rule:exactly;
letter-spacing: 0em;
text-align: left;
color: #6D6666;
margin-top: 12px;">{{user}} has shared a case with you. Click the button below to open it. You'll be asked to request a one-time verification code from the share page itself.<br/><br/>This link will expire in {{expiry}}.</p>
<a style="text-decoration: none;color: none;" href="{{url}}">
<p style="font-family: Inter;
font-size: 14px;
font-style: normal;
line-height: 24px;
mso-line-height-rule:exactly;
letter-spacing: 0em;
text-align: left;
color:#FFFFFF;
background-color: #84559F;
padding-top: 6px;
padding-bottom: 6px;
padding-right: 16px;
padding-left: 16px;
width: 130px;
border-radius: 4px;
text-align: center;
cursor: pointer;">Open case -></p>
</a>
</td>
<td class="corner-td" align="right"></td>
</tr>
</tbody>
</table>
</td>
</tr>
</table>
<table border="0" cellpadding="0" cellspacing="0" width="100%" bgcolor="E5E5E5" style="border-collaps:collaps; mso-table-lspace:0pt; mso-table-rspace:0pt;">
<tr>
<td bgcolor="E5E5E5">
<table border="0" cellpadding="0" cellspacing="0" width="100%" class="footer-table" style="margin-top: 0;border-collaps:collaps; mso-table-lspace:0pt; mso-table-rspace:0pt;" >
<tbody>
<tr>
<td class="corner-td" align="left"></td>
<!--[if mso | IE]>
<table role="presentation" border="0" cellpadding="0" cellspacing="0"><tr><td style="vertical-align:top;display:table-row !important">
<![endif]-->
<td height="146" width="190" class="footer-td" style="margin-bottom: 12px;" valign="top" align="left">
<table style="border-collaps:collaps; mso-table-lspace:0pt; mso-table-rspace:0pt;">
<tbody>
<tr>
<td>
<h4 style=" font-family: Inter;
font-size: 16px;
font-style: normal;
font-weight: 600;
line-height: 36px;
mso-line-height-rule:exactly;
letter-spacing: 0em;
text-align: left;
color:#6D6666;">Get in touch</h4>
<a style="text-decoration: none;color: none;" href="mailto:support@kerberos.io">
<p style=" font-family: Inter;
font-size: 14px;
font-style: normal;
font-weight: 400;
line-height: 16px;
mso-line-height-rule:exactly;
letter-spacing: 0em;
text-align: left;
color: #A69D9D;">support@kerberos.io</p>
</a>
<p style=" font-family: Inter;
font-size: 14px;
font-style: normal;
font-weight: 400;
line-height: 16px;
mso-line-height-rule:exactly;
letter-spacing: 0em;
text-align: left;
color: #A69D9D;">9000 Ghent, BE</p>
<a style="text-decoration: none;color: none;" href="https://kerberos.io/">
<p style=" font-family: Inter;
font-size: 14px;
font-style: normal;
font-weight: 400;
line-height: 24px;
mso-line-height-rule:exactly;
letter-spacing: 0em;
text-align: left;
color: #A69D9D;">https://kerberos.io</p>
</a>
</td>
</tr>
</tbody>
</table>
</td>
<!--[if mso | IE]>
<table role="presentation" border="0" cellpadding="0" cellspacing="0"><tr><td style="vertical-align:top;display:table-row !important">
<![endif]-->
<td class="footer-td" style="border-radius: 4px;padding-left: 0;padding-right: 0;padding-top: 0;padding-bottom: 0; margin-bottom: 12px;" valign="top" align="left">
<table style="border-collaps:collaps; mso-table-lspace:0pt; mso-table-rspace:0pt;">
<tbody>
<tr>
<td>
<h4 style=" font-family: Inter;
font-size: 16px;
font-style: normal;
font-weight: 600;
line-height: 36px;
mso-line-height-rule:exactly;
letter-spacing: 0em;
text-align: left;
color:#6D6666;">About Kerberos</h4>
<p style=" font-family: Inter;
font-size: 14px;
font-style: normal;
font-weight: 400;
line-height: 24px;
mso-line-height-rule:exactly;
letter-spacing: 0em;
text-align: left;
color: #A69D9D;">Welcome to the revolutionary video analytics and video management platform. Open, modular, and extensible for everyone, anywhere.</p>
<p style="margin-top: 12px;">
<a href="https://twitter.com/kerberosio" style="text-decoration: none;color: none;">
<img width="24" height="24" alt="Twitter" src="https://kerberos.io/images/email/twitter.png"/>
</a>
<a href="https://reddit.com/r/kerberos_io" style="text-decoration: none;color: none;">
<img g width="24" height="24" alt="Reddit" src="https://kerberos.io/images/email/reddit.png"/>
</a>
<a href="https://www.youtube.com/channel/UCnd9q7iRNNw4W95eQwQuECA" style="text-decoration: none;color: none;">
<img g width="24" height="24" alt="Youtube" src="https://kerberos.io/images/email/youtube.png"/>
</a>
<a href="https://github.com/kerberos-io" style="text-decoration: none;color: none;">
<img g width="24" height="24" alt="Github" src="https://kerberos.io/images/email/github.png"/>
</a>
</p>
</td>
</tr>
</tbody>
</table>
</td>
<td class="corner-td" align="right"></td>
</tr>
</tbody>
</table>
<table style="border-collaps:collaps; mso-table-lspace:0pt; mso-table-rspace:0pt;">
<tbody>
<tr style="height: 50px">
<td></td>
</tr>
</tbody>
</table>
</td>
</tr>
</table>
</body>
</html>

View File

@@ -0,0 +1,21 @@
Kerberos.io
------------
A case has been shared with you
{{user}} shared a case with you
Open the shared case
{{user}} has shared a case with you. Open the link below to access it — you'll be asked to request a one-time verification code from the share page.
{{url}}
This link will expire in {{expiry}}.
Get in touch
------------
support@kerberos.io
9000 Ghent, BE
https://kerberos.io
About Kerberos
------------
Welcome to the revolutionary video analytics and video management platform. Open, modular, and extensible for everyone, anywhere.

View File

@@ -0,0 +1,425 @@
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="X-UA-Compatible" content="IE=edge" />
<meta http-equiv="Content-Type" content="text/html; charset=utf-8" />
<meta
name="viewport"
content="width=device-width, initial-scale=1, minimum-scale=1, maximum-scale=1"
/>
<meta name="description" content="Kerberos.io Mailing">
<style type="text/css">
@font-face {
font-family: 'Inter';
font-style: normal;
font-weight: 400;
font-display: swap;
src: url("https://kerberos.io/dist/fonts/Inter-Regular.woff?v=/dist/fonts/Inter-Regular.woff2?v=3.183.18") format("woff2"),
url("https://kerberos.io/dist/fonts/Inter-Regular.woff?v=/dist/fonts/Inter-Regular.woff2?v=3.183.18") format("woff");
}
@font-face {
font-family: 'Inter';
font-style: normal;
font-weight: 500;
font-display: swap;
src: url("https://kerberos.io/dist/fonts/Inter-Medium.woff2?v=3.18") format("woff2"),
url("https://kerberos.io/dist/fonts/Inter-Medium.woff?v=3.18") format("woff");
}
@font-face {
font-family: 'Inter';
font-style: normal;
font-weight: 600;
font-display: swap;
src: url("https://kerberos.io/dist/fonts/Inter-SemiBold.woff2?v=3.18") format("woff2"),
url("https://kerberos.io/dist/fonts/Inter-SemiBold.woff?v=3.18") format("woff");
}
@font-face {
font-family: 'Inter var';
font-weight: 100 900;
font-display: swap;
font-style: normal;
font-named-instance: 'Regular';
src: url("https://kerberos.io/dist/fonts/Inter-roman.var.woff2?v=3.18") format("woff2");
}
body{
background: #E5E5E5;
margin-top:0;
margin-bottom: 0;
margin-right: 0;
margin-left: 0;
padding-top: 0;
padding-left: 0;
padding-right: 0;
padding-bottom: 0;
font-family: 'Inter';
}
a, a:hover, a:active {
color: #262424;
text-decoration: none;
}
.corner-td{
width: 60px;
}
table {border-collapse:separate;max-width: 850px; margin: 0 auto; width: 100%;}
.ExternalClass p, .ExternalClass span, .ExternalClass font, .ExternalClass td {line-height: 100%;}
.ExternalClass {width: 100%;}
@media screen and (max-width:500px){
.tab-td{
padding-left: 10px!important;
}
.tab-td a h4{
font-size: 14px!important;
}
.corner-td{
width: 20px!important;
}
.company-name-td h3{
font-size: 16px!important;
}
table.header-table{
padding-top: 8px!important;
padding-right: 0px!important;
padding-bottom: 24px!important;
padding-left: 0px!important;
}
.colored-card-td h4{
font-size: 14px!important;
}
.colored-card-td h2{
font-size: 20px!important;
}
.colored-card-td a p{
font-size: 12px!important;
width: 143px!important;
}
.colored-card-td{
padding-top: 24px!important;
padding-right: 24px!important;
padding-bottom: 24px!important;
padding-left: 24px!important;
}
.colorless-card-td{
padding-top: 24px!important;
padding-right: 24px!important;
padding-bottom: 24px!important;
padding-left: 24px!important;
}
.colorless-card-td h3{
font-size: 18px!important;
}
.colorless-card-td p{
font-size: 14px!important;
}
.colorless-card-table{
margin-left: 0px!important;
margin-right: 0px!important;
margin-top: 24px!important;
margin-bottom: 24px!important;
}
.footer-td{
display: table-row!important;
}
}
@media screen and (max-width:600px) {
.footer-td{
display: table-row!important;
}
}
@media screen and (max-width:650px) {
.footer-table{
margin-left: 0px!important;
margin-right: 0px!important;
margin-top: 0px!important;
margin-bottom: 36px!important;
}
}
</style>
</head>
<body height="100%" width="100%">
<table border="0" cellpadding="0" cellspacing="0" width="100%" bgcolor="E5E5E5" style="border-collaps:collaps; mso-table-lspace:0pt; mso-table-rspace:0pt;">
<tr>
<td bgcolor="E5E5E5">
<table border="0" cellpadding="0" cellspacing="0" width="100%" height="36" class="header-table" style="padding-top: 36px ;padding-right: 0;padding-bottom: 36px;padding-left: 0;border-collaps:collaps; mso-table-lspace:0pt; mso-table-rspace:0pt;">
<tbody>
<tr>
<td class="corner-td" align="left"></td>
<td width="48" height="36" align="left"><img alt="Kerberos.io" width="36" height="36" src="https://kerberos.io/images/email/kerberos.png"/></td>
<td height="36" align="left" class="company-name-td">
<h3 width="36" height="36" style=" font-family: Inter;
font-size: 20px;
font-style: normal;
font-weight: 600;
line-height: 24px;
mso-line-height-rule:exactly;
letter-spacing: 0em;
text-align: left;
color: #262424;">Kerberos.io</h3>
</td>
<td height="36" width="36" style="padding-left: 36px;" class="tab-td" align="right">
<a style="text-decoration: none;color: none;" href={{tab1_href}}>
<h4 style="font-family: Inter;
font-size: 16px;
font-style: normal;
font-weight: 500;
line-height: 36px;
mso-line-height-rule:exactly;
letter-spacing: 0em;
text-align: right;
color: #6D6666;">{{tab1_title}}</h4>
</a>
</td>
<td height="36" width="36" style="padding-left: 36px;" class="tab-td" align="right" >
<a style="text-decoration: none;color: none;" href={{tab2_href}}>
<h4 style="font-family: Inter;
font-size: 16px;
font-style: normal;
font-weight: 500;
line-height: 36px;
mso-line-height-rule:exactly;
letter-spacing: 0em;
text-align: right;
color: #6D6666;">{{tab2_title}}</h4>
</a>
</td>
<td class="corner-td" align="right"></td>
</tr>
</tbody>
</table>
</td>
</tr>
</table>
<table border="0" cellpadding="0" cellspacing="0" width="100%" bgcolor="E5E5E5" style="border-collaps:collaps; mso-table-lspace:0pt; mso-table-rspace:0pt;">
<tr>
<td bgcolor="E5E5E5">
<table border="0" cellpadding="0" cellspacing="0" width="100%" style="border-collaps:collaps; mso-table-lspace:0pt; mso-table-rspace:0pt;" >
<tbody>
<tr>
<td class="corner-td" align="left"></td>
<td class="colored-card-td" bgcolor="#57356B" style="padding-left: 48px;padding-right: 48px;padding-top: 48px;padding-bottom: 48px;border-radius: 4px;background-color:#57356B;">
<h2 style=" font-family: Inter;
font-size: 24px;
font-style: normal;
font-weight: 600;
line-height: 36px;
mso-line-height-rule:exactly;
letter-spacing: 0em;
text-align: left;
color:#FFFFFF;
padding-top: 12px;
margin-bottom: 0;
padding-bottom: 0;
padding-left: 0;
padding-right: 0;">Verify your access</h2>
<h4 style="font-family: Inter;
font-size: 16px;
font-style: normal;
font-weight: 400;
line-height: 24px;
mso-line-height-rule:exactly;
letter-spacing: 0em;
text-align: left;
color:#b09fb9;">Use the code below to open the shared case</h4>
</td>
<td class="corner-td" align="right"></td>
</tr>
</tbody>
</table>
</td>
</tr>
</table>
<table border="0" cellpadding="0" cellspacing="0" width="100%" bgcolor="E5E5E5" style="border-collaps:collaps; mso-table-lspace:0pt; mso-table-rspace:0pt;">
<tr>
<td bgcolor="E5E5E5">
<table border="0" cellpadding="0" cellspacing="0" width="100%" class="colorless-card-table" style="margin-top: 36px;margin-bottom: 36px;margin-left: 0;margin-right: 0;border-collaps:collaps; mso-table-lspace:0pt; mso-table-rspace:0pt;" >
<tbody>
<tr>
<td class="corner-td" align="left"></td>
<td class="colorless-card-td" bgcolor="#FFFFFF" style="background-color:#FFFFFF;padding-top: 36px;padding-right: 43px;padding-bottom: 25px;padding-left: 43px;border-radius: 4px;">
<h3 style=" font-family: Inter;
font-size: 20px;
font-style: normal;
font-weight: 600;
line-height: 36px;
mso-line-height-rule:exactly;
letter-spacing: 0em;
text-align: left;
color: #262424;
width: 280px">Your verification code</h3>
<p style=" font-family: Inter;
font-size: 14px;
font-style: normal;
font-weight: 400;
line-height: 24px;
mso-line-height-rule:exactly;
letter-spacing: 0em;
text-align: left;
color: #6D6666;
margin-top: 12px;">Enter the code below on the share page to access the case.</p>
<p style="font-family: 'Courier New', Courier, monospace;
font-size: 32px;
font-style: normal;
font-weight: 600;
line-height: 40px;
mso-line-height-rule:exactly;
letter-spacing: 8px;
text-align: center;
color:#262424;
background-color: #F2F0F4;
padding-top: 16px;
padding-bottom: 16px;
padding-right: 16px;
padding-left: 16px;
margin-top: 16px;
margin-bottom: 16px;
border-radius: 4px;">{{code}}</p>
<p style=" font-family: Inter;
font-size: 14px;
font-style: normal;
font-weight: 400;
line-height: 24px;
mso-line-height-rule:exactly;
letter-spacing: 0em;
text-align: left;
color: #6D6666;">This code expires in {{expiry}}. If you didn't request this, you can safely ignore this email.</p>
</td>
<td class="corner-td" align="right"></td>
</tr>
</tbody>
</table>
</td>
</tr>
</table>
<table border="0" cellpadding="0" cellspacing="0" width="100%" bgcolor="E5E5E5" style="border-collaps:collaps; mso-table-lspace:0pt; mso-table-rspace:0pt;">
<tr>
<td bgcolor="E5E5E5">
<table border="0" cellpadding="0" cellspacing="0" width="100%" class="footer-table" style="margin-top: 0;border-collaps:collaps; mso-table-lspace:0pt; mso-table-rspace:0pt;" >
<tbody>
<tr>
<td class="corner-td" align="left"></td>
<!--[if mso | IE]>
<table role="presentation" border="0" cellpadding="0" cellspacing="0"><tr><td style="vertical-align:top;display:table-row !important">
<![endif]-->
<td height="146" width="190" class="footer-td" style="margin-bottom: 12px;" valign="top" align="left">
<table style="border-collaps:collaps; mso-table-lspace:0pt; mso-table-rspace:0pt;">
<tbody>
<tr>
<td>
<h4 style=" font-family: Inter;
font-size: 16px;
font-style: normal;
font-weight: 600;
line-height: 36px;
mso-line-height-rule:exactly;
letter-spacing: 0em;
text-align: left;
color:#6D6666;">Get in touch</h4>
<a style="text-decoration: none;color: none;" href="mailto:support@kerberos.io">
<p style=" font-family: Inter;
font-size: 14px;
font-style: normal;
font-weight: 400;
line-height: 16px;
mso-line-height-rule:exactly;
letter-spacing: 0em;
text-align: left;
color: #A69D9D;">support@kerberos.io</p>
</a>
<p style=" font-family: Inter;
font-size: 14px;
font-style: normal;
font-weight: 400;
line-height: 16px;
mso-line-height-rule:exactly;
letter-spacing: 0em;
text-align: left;
color: #A69D9D;">9000 Ghent, BE</p>
<a style="text-decoration: none;color: none;" href="https://kerberos.io/">
<p style=" font-family: Inter;
font-size: 14px;
font-style: normal;
font-weight: 400;
line-height: 24px;
mso-line-height-rule:exactly;
letter-spacing: 0em;
text-align: left;
color: #A69D9D;">https://kerberos.io</p>
</a>
</td>
</tr>
</tbody>
</table>
</td>
<!--[if mso | IE]>
<table role="presentation" border="0" cellpadding="0" cellspacing="0"><tr><td style="vertical-align:top;display:table-row !important">
<![endif]-->
<td class="footer-td" style="border-radius: 4px;padding-left: 0;padding-right: 0;padding-top: 0;padding-bottom: 0; margin-bottom: 12px;" valign="top" align="left">
<table style="border-collaps:collaps; mso-table-lspace:0pt; mso-table-rspace:0pt;">
<tbody>
<tr>
<td>
<h4 style=" font-family: Inter;
font-size: 16px;
font-style: normal;
font-weight: 600;
line-height: 36px;
mso-line-height-rule:exactly;
letter-spacing: 0em;
text-align: left;
color:#6D6666;">About Kerberos</h4>
<p style=" font-family: Inter;
font-size: 14px;
font-style: normal;
font-weight: 400;
line-height: 24px;
mso-line-height-rule:exactly;
letter-spacing: 0em;
text-align: left;
color: #A69D9D;">Welcome to the revolutionary video analytics and video management platform. Open, modular, and extensible for everyone, anywhere.</p>
<p style="margin-top: 12px;">
<a href="https://twitter.com/kerberosio" style="text-decoration: none;color: none;">
<img width="24" height="24" alt="Twitter" src="https://kerberos.io/images/email/twitter.png"/>
</a>
<a href="https://reddit.com/r/kerberos_io" style="text-decoration: none;color: none;">
<img g width="24" height="24" alt="Reddit" src="https://kerberos.io/images/email/reddit.png"/>
</a>
<a href="https://www.youtube.com/channel/UCnd9q7iRNNw4W95eQwQuECA" style="text-decoration: none;color: none;">
<img g width="24" height="24" alt="Youtube" src="https://kerberos.io/images/email/youtube.png"/>
</a>
<a href="https://github.com/kerberos-io" style="text-decoration: none;color: none;">
<img g width="24" height="24" alt="Github" src="https://kerberos.io/images/email/github.png"/>
</a>
</p>
</td>
</tr>
</tbody>
</table>
</td>
<td class="corner-td" align="right"></td>
</tr>
</tbody>
</table>
<table style="border-collaps:collaps; mso-table-lspace:0pt; mso-table-rspace:0pt;">
<tbody>
<tr style="height: 50px">
<td></td>
</tr>
</tbody>
</table>
</td>
</tr>
</table>
</body>
</html>

View File

@@ -0,0 +1,21 @@
Kerberos.io
------------
Verify your access
Use the code below to open the shared case
Your verification code
{{code}}
Enter this code on the share page to access the case. This code expires in {{expiry}}.
If you didn't request this, you can safely ignore this email.
Get in touch
------------
support@kerberos.io
9000 Ghent, BE
https://kerberos.io
About Kerberos
------------
Welcome to the revolutionary video analytics and video management platform. Open, modular, and extensible for everyone, anywhere.

View File

@@ -0,0 +1,17 @@
apiVersion: v1
kind: Secret
metadata:
name: hub-api-server-tls
namespace: kerberos-hub
type: kubernetes.io/tls
stringData:
# Paste your PEM certificate chain here (e.g., fullchain.pem)
tls.crt: |
-----BEGIN CERTIFICATE-----
REPLACE_WITH_YOUR_CERTIFICATE
-----END CERTIFICATE-----
# Paste your PEM private key here (e.g., privkey.pem)
tls.key: |
-----BEGIN PRIVATE KEY-----
REPLACE_WITH_YOUR_PRIVATE_KEY
-----END PRIVATE KEY-----

View File

@@ -0,0 +1,48 @@
{{/* Build the path to the configured MongoDB CA bundle. */}}
{{- define "hub.mongodb.tlsCAFile" -}}
{{- if and .Values.mongodb.tls.enabled .Values.mongodb.tls.existingSecret .Values.mongodb.tls.caFileName -}}
{{- printf "%s/%s" .Values.mongodb.tls.mountPath .Values.mongodb.tls.caFileName | clean -}}
{{- end -}}
{{- end -}}
{{/* Add TLS options to a configured MongoDB URI unless they are already present. */}}
{{- define "hub.mongodb.uri" -}}
{{- $uri := .Values.mongodb.uri | default "" -}}
{{- if and .Values.mongodb.tls.enabled $uri -}}
{{- if not (regexMatch "(?i)(^|[?&])tls=" $uri) -}}
{{- $separator := "?" -}}
{{- if contains "?" $uri -}}
{{- $separator = "&" -}}
{{- end -}}
{{- if or (hasSuffix "?" $uri) (hasSuffix "&" $uri) -}}
{{- $separator = "" -}}
{{- end -}}
{{- $uri = printf "%s%stls=true" $uri $separator -}}
{{- end -}}
{{- $caFile := include "hub.mongodb.tlsCAFile" . -}}
{{- if and $caFile (not (regexMatch "(?i)(^|[?&])tlsCAFile=" $uri)) -}}
{{- $separator := "&" -}}
{{- if not (contains "?" $uri) -}}
{{- $separator = "?" -}}
{{- else if or (hasSuffix "?" $uri) (hasSuffix "&" $uri) -}}
{{- $separator = "" -}}
{{- end -}}
{{- $uri = printf "%s%stlsCAFile=%s" $uri $separator $caFile -}}
{{- end -}}
{{- end -}}
{{- $uri -}}
{{- end -}}
{{/* Render the shared MongoDB CA Secret volume. */}}
{{- define "hub.mongodb.tlsVolume" -}}
- name: mongodb-tls
secret:
secretName: {{ .Values.mongodb.tls.existingSecret }}
{{- end -}}
{{/* Render the shared MongoDB CA volume mount. */}}
{{- define "hub.mongodb.tlsVolumeMount" -}}
- name: mongodb-tls
mountPath: {{ .Values.mongodb.tls.mountPath }}
readOnly: true
{{- end -}}

View File

@@ -0,0 +1,57 @@
{{- if or (eq .Values.mode "all") (eq .Values.mode "ui") -}}
apiVersion: apps/v1
kind: Deployment
metadata:
name: admin
namespace: {{ .Release.Namespace }}
spec:
replicas: {{ .Values.admin.replicas }}
selector:
matchLabels:
app: admin
template:
metadata:
labels:
app: admin
spec:
{{- with .Values.admin.volumes }}
volumes:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- with .Values.admin.topologySpreadConstraints }}
topologySpreadConstraints:
{{- toYaml . | nindent 8 }}
{{- end }}
containers:
- name: admin
image: "{{ .Values.global.imageRegistry }}{{ .Values.admin.repository }}:{{ .Values.admin.tag }}"
imagePullPolicy: {{ .Values.admin.pullPolicy }}
{{- with .Values.admin.resources }}
resources:
{{- toYaml . | nindent 12 }}
{{- end }}
{{- with .Values.admin.volumeMounts }}
volumeMounts:
{{- toYaml . | nindent 12 }}
{{- end }}
ports:
- name: http
containerPort: 80
protocol: TCP
env:
- name: LOG_LEVEL
value: "{{ .Values.admin.logLevel }}"
- name: API_URL
value: "{{ .Values.kerberoshub.api.schema }}://{{ .Values.kerberoshub.api.url }}"
- name: TITLE
value: Hub Admin | Scale for everyone, anywhere
- name: LOGO_NAME
- name: ENVIRONMENT
value: staging
- name: PRIVATE_EDITION
value: "false"
- name: PRODUCTION
value: "true"
- name: DEMO
value: "false"
{{- end }}

View File

@@ -0,0 +1,52 @@
{{- if or (eq .Values.mode "all") (eq .Values.mode "ui") -}}
{{ if ne .Values.ingress "" }}
{{- if .Capabilities.APIVersions.Has "networking.k8s.io/v1" }}
apiVersion: networking.k8s.io/v1
{{- else }}
apiVersion: networking.k8s.io/v1beta1
{{- end }}
kind: Ingress
metadata:
name: admin-ingress
namespace: {{ .Release.Namespace }}
annotations:
{{- if eq .Values.admin.oauth2Proxy.enabled true }}
nginx.ingress.kubernetes.io/auth-url: "https://$host/oauth2/auth"
nginx.ingress.kubernetes.io/auth-signin: "https://$host/oauth2/start?rd=$escaped_request_uri"
{{- end }}
{{- if eq .Values.ingress "nginx" }}
kubernetes.io/tls-acme: "true"
nginx.ingress.kubernetes.io/ssl-redirect: "true"
cert-manager.io/cluster-issuer: "letsencrypt-prod"
{{- end }}
spec:
ingressClassName: {{ .Values.ingress }}
{{- with .Values.admin.tls }}
tls:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- if .Capabilities.APIVersions.Has "networking.k8s.io/v1" }}
rules:
- host: "{{ .Values.admin.url }}"
http:
paths:
- path: /
pathType: Prefix
backend:
service:
name: admin-svc
port:
number: 80
{{- else }}
rules:
- host: "{{ .Values.admin.url }}"
http:
paths:
- path: /
backend:
serviceName: admin-svc
servicePort: 80
{{- end }}
{{- end }}
{{- end }}

View File

@@ -0,0 +1,108 @@
{{- if and (or (eq .Values.mode "all") (eq .Values.mode "ui")) (eq .Values.admin.oauth2Proxy.enabled true) }}
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
name: oauth2-proxy-admin
namespace: kube-system
annotations:
{{- if eq .Values.ingress "nginx" }}
cert-manager.io/cluster-issuer: letsencrypt-prod
kubernetes.io/tls-acme: "true"
nginx.ingress.kubernetes.io/ssl-redirect: "true"
nginx.ingress.kubernetes.io/enable-cors: "true"
{{- end }}
spec:
ingressClassName: {{ .Values.ingress }}
rules:
- host: "{{ .Values.admin.url }}"
http:
paths:
- path: /oauth2
pathType: Prefix
backend:
service:
name: oauth2-proxy-admin
port:
number: 4180
tls:
- hosts:
- "{{ .Values.admin.url }}"
secretName:
---
apiVersion: apps/v1
kind: Deployment
metadata:
name: oauth2-proxy-admin
namespace: kube-system
labels:
k8s-app: oauth2-proxy-admin
spec:
replicas: 1
selector:
matchLabels:
k8s-app: oauth2-proxy-admin
template:
metadata:
labels:
k8s-app: oauth2-proxy-admin
spec:
{{- with .Values.admin.oauth2Proxy.volumes }}
volumes:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- with .Values.admin.oauth2Proxy.topologySpreadConstraints }}
topologySpreadConstraints:
{{- toYaml . | nindent 8 }}
{{- end }}
containers:
- args:
- --provider=github
- --email-domain=*
- --upstream=file:///dev/null
- --http-address=0.0.0.0:4180
- --skip-auth-preflight=true
{{- with .Values.admin.oauth2Proxy.volumeMounts }}
volumeMounts:
{{- toYaml . | nindent 12 }}
{{- end }}
env:
- name: OAUTH2_PROXY_CLIENT_ID
value: "{{ .Values.admin.oauth2Proxy.github.clientId }}"
- name: OAUTH2_PROXY_CLIENT_SECRET
value: "{{ .Values.admin.oauth2Proxy.github.clientSecret }}"
- name: OAUTH2_PROXY_COOKIE_SECRET
value: "{{ .Values.admin.oauth2Proxy.github.cookieSecret }}"
- name: OAUTH2_PROXY_GITHUB_ORG
value: "{{ .Values.admin.oauth2Proxy.github.organization }}"
- name: OAUTH2_PROXY_GITHUB_TEAM
value: "{{ .Values.admin.oauth2Proxy.github.team }}"
image: quay.io/oauth2-proxy/oauth2-proxy:latest
imagePullPolicy: Always
name: oauth2-proxy
ports:
- containerPort: 4180
protocol: TCP
resources:
limits:
cpu: 100m
memory: 50Mi
requests:
cpu: 100m
memory: 50Mi
---
apiVersion: v1
kind: Service
metadata:
labels:
k8s-app: oauth2-proxy-admin
name: oauth2-proxy-admin
namespace: kube-system
spec:
ports:
- name: http
port: 4180
protocol: TCP
targetPort: 4180
selector:
k8s-app: oauth2-proxy-admin
{{- end -}}

View File

@@ -0,0 +1,17 @@
{{- if or (eq .Values.mode "all") (eq .Values.mode "ui") -}}
apiVersion: v1
kind: Service
metadata:
name: admin-svc
namespace: {{ .Release.Namespace }}
labels:
app: admin-svc
spec:
ports:
- protocol: TCP
port: 80
targetPort: 80
name: http
selector:
app: admin
{{- end }}

View File

@@ -0,0 +1,18 @@
apiVersion: v1
kind: ConfigMap
metadata:
name: mongodb-config
namespace: {{ .Release.Namespace }}
data:
MONGODB_URI: {{ include "hub.mongodb.uri" . | quote }}
MONGODB_HOST: "{{ .Values.mongodb.host }}"
MONGODB_AUTHENTICATION_MECHANISM: "{{ .Values.mongodb.authenticationMechanism }}"
MONGODB_DATABASE_CREDENTIALS: "{{ .Values.mongodb.adminDatabase }}"
MONGODB_USERNAME: "{{ .Values.mongodb.username }}"
MONGODB_PASSWORD: "{{ .Values.mongodb.password }}"
MONGODB_RETRY_WRITES: "{{ .Values.mongodb.retryWrites }}"
MONGODB_FLAVOR: "{{ .Values.mongodb.flavor | default "mongodb" }}"
MONGODB_TLS: "{{ .Values.mongodb.tls.enabled }}"
MONGODB_TLS_CA_FILE: {{ include "hub.mongodb.tlsCAFile" . | quote }}
MONGODB_TLS_INSECURE_SKIP_VERIFY: "{{ .Values.mongodb.tls.insecureSkipVerify }}"
MONGODB_DATABASE_CLOUD: "Kerberos"

View File

@@ -1,7 +1,10 @@
{{- if or (eq .Values.mode "all") (eq .Values.mode "ui") -}}
{{- if .Values.kerberoshub.api.serviceEnabled }}
apiVersion: v1
kind: Service
metadata:
name: hub-api-svc
namespace: {{ .Release.Namespace }}
labels:
app: hub-api-svc
spec:
@@ -16,6 +19,8 @@ spec:
protocol: TCP
selector:
app: hub-api
{{- end }}
{{ if ne .Values.ingress "" }}
---
{{ if .Capabilities.APIVersions.Has "networking.k8s.io/v1" }}
apiVersion: networking.k8s.io/v1
@@ -25,8 +30,8 @@ apiVersion: networking.k8s.io/v1beta1
kind: Ingress
metadata:
name: hub-api-ingress
namespace: {{ .Release.Namespace }}
annotations:
kubernetes.io/ingress.class: {{ .Values.ingress }}
{{- if eq .Values.ingress "nginx" }}
kubernetes.io/tls-acme: "true"
nginx.ingress.kubernetes.io/ssl-redirect: "true"
@@ -34,6 +39,7 @@ metadata:
cert-manager.io/cluster-issuer: "letsencrypt-prod"
{{- end }}
spec:
ingressClassName: {{ .Values.ingress }}
{{- with .Values.kerberoshub.api.tls }}
tls:
{{- toYaml . | nindent 8 }}
@@ -92,11 +98,13 @@ spec:
servicePort: 8081
{{- end }}
{{ end }}
{{- end }}
---
apiVersion: apps/v1
kind: Deployment
metadata:
name: hub-api
namespace: {{ .Release.Namespace }}
spec:
replicas: {{ .Values.kerberoshub.api.replicas }}
selector:
@@ -110,20 +118,41 @@ spec:
maxSurge: 1
template:
metadata:
annotations:
checksum/config-mongodb: {{ include (print $.Template.BasePath "/configmap-mongodb.yaml") . | sha256sum }}
labels:
app: hub-api
spec:
{{- if .Values.kerberoshub.serviceAccount.create }}
serviceAccountName: {{ default (printf "%s-%s-sa" .Release.Name .Chart.Name | trunc 63 | trimSuffix "-") .Values.kerberoshub.serviceAccount.name }}
{{- end }}
{{- with .Values.imagePullSecrets }}
imagePullSecrets:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- with .Values.kerberoshub.api.volumes }}
{{- $serverTLS := .Values.kerberoshub.api.serverTLS }}
{{- $mongodbTLS := .Values.mongodb.tls }}
{{- if or .Values.kerberoshub.api.volumes (and $serverTLS.enabled $serverTLS.secretName) (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
volumes:
{{- with .Values.kerberoshub.api.volumes }}
{{- toYaml . | nindent 8 }}
{{- end }}
{{- if and $serverTLS.enabled $serverTLS.secretName }}
- name: hub-api-server-tls
secret:
secretName: {{ $serverTLS.secretName }}
{{- end }}
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
{{- include "hub.mongodb.tlsVolume" . | nindent 8 }}
{{- end }}
{{- end }}
{{- with .Values.kerberoshub.api.topologySpreadConstraints }}
topologySpreadConstraints:
{{- toYaml . | nindent 8 }}
{{- end }}
containers:
- name: hub-api
image: "{{ .Values.kerberoshub.api.repository }}:{{ .Values.kerberoshub.api.tag }}"
image: "{{ .Values.global.imageRegistry }}{{ .Values.kerberoshub.api.repository }}:{{ .Values.kerberoshub.api.tag }}"
imagePullPolicy: {{ .Values.kerberoshub.api.pullPolicy }}
{{- with .Values.kerberoshub.api.resources }}
resources:
@@ -131,20 +160,57 @@ spec:
{{- end }}
ports:
- containerPort: 80
name: http
{{- with .Values.kerberoshub.api.volumeMounts}}
name: http
{{- if or .Values.kerberoshub.api.volumeMounts (and $serverTLS.enabled $serverTLS.secretName) (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
volumeMounts:
{{- with .Values.kerberoshub.api.volumeMounts}}
{{- toYaml . | nindent 12 }}
{{- end }}
{{- if and $serverTLS.enabled $serverTLS.secretName }}
- name: hub-api-server-tls
mountPath: {{ $serverTLS.mountPath }}
readOnly: true
{{- end }}
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
{{- include "hub.mongodb.tlsVolumeMount" . | nindent 12 }}
{{- end }}
{{- end }}
# Mongodb - loaded from ConfigMap
envFrom:
- configMapRef:
name: mongodb-config
env:
- name: ENVIRONMENT
value: "{{ .Values.environment }}"
- name: READ_ONLY
value: "{{ .Values.readonly }}"
value: "{{ .Values.readOnly }}"
- name: LOG_LEVEL
value: "{{ .Values.kerberoshub.api.logLevel }}"
- name: SUPPORT_ENABLED
value: "{{ .Values.kerberoshub.support.enabled }}"
- name: CLOUD_API_URL
value: "{{ .Values.kerberoshub.api.url }}"
- name: API_URL
value: "{{ .Values.kerberoshub.api.schema }}://{{ .Values.kerberoshub.api.url }}"
- name: PUBLIC_URL
value: "{{ .Values.kerberoshub.frontend.schema }}://{{ .Values.kerberoshub.frontend.url }}"
- name: REFRESH_COOKIE_SECURE
value: {{ eq .Values.kerberoshub.api.schema "https" | quote }}
{{- $corsOrigins := list (printf "%s://%s" .Values.kerberoshub.frontend.schema .Values.kerberoshub.frontend.url) }}
{{- with .Values.kerberoshub.frontend.legacyUrl }}
{{- $corsOrigins = append $corsOrigins (printf "%s://%s" $.Values.kerberoshub.frontend.schema .) }}
{{- end }}
{{- range .Values.kerberoshub.frontend.domains }}
{{- $corsOrigins = append $corsOrigins (printf "%s://%s" $.Values.kerberoshub.frontend.schema .) }}
{{- end }}
{{- if and .Values.kerberoshub.frontend.multiTenant .Values.kerberoshub.frontend.tenantBaseDomain }}
{{- $corsOrigins = append $corsOrigins (printf "%s://*.%s" .Values.kerberoshub.frontend.schema .Values.kerberoshub.frontend.tenantBaseDomain) }}
{{- end }}
{{- if and .Values.kerberoshub.frontend.demoEnabled .Values.kerberoshub.frontend.demoUrl }}
{{- $corsOrigins = append $corsOrigins (printf "%s://%s" .Values.kerberoshub.frontend.schema .Values.kerberoshub.frontend.demoUrl) }}
{{- end }}
- name: CORS_ALLOWED_ORIGINS
value: {{ join "," $corsOrigins | quote }}
{{ if .Values.isPrivate }}
- name: KERBEROS_PRIVATE_CLOUD
value: "true"
@@ -159,6 +225,26 @@ spec:
- name: API_KEY
value: "{{ .Values.kerberoshub.api.apiKey }}"
# MQTT credentials (served via /runtime/config to authenticated
# frontend clients; no longer exposed in the public env.js).
- name: MQTT_USERNAME
value: "{{ .Values.mqtt.username }}"
- name: MQTT_PASSWORD
value: "{{ .Values.mqtt.password }}"
# TURN credentials (served via /runtime/config to authenticated
# frontend clients; no longer exposed in the public env.js).
- name: TURN_USERNAME
value: "{{ .Values.turn.username }}"
- name: TURN_PASSWORD
value: "{{ .Values.turn.password }}"
{{- if .Values.kerberoshub.api.serverTLS.enabled }}
- name: TLS_CERT_FILE
value: "{{ .Values.kerberoshub.api.serverTLS.certFile }}"
- name: TLS_KEY_FILE
value: "{{ .Values.kerberoshub.api.serverTLS.keyFile }}"
{{- end }}
# Kerberos Hub
- name: LICENSE_KEY
value: "{{ .Values.license }}"
@@ -166,11 +252,11 @@ spec:
value: "{{ .Values.licenseServer.url }}"
- name: LICENSE_PUBLIC_API_TOKEN
value: "{{ .Values.licenseServer.token }}"
# Authorization - Authentication secret
- name: KERBEROS_JWT_SECRET
value: "{{ .Values.kerberoshub.api.jwtSecret }}"
# SSO (OIDC) setup
- name: SSO_DOMAINS
value: "{{- range .Values.kerberoshub.api.sso }}{{ .domain }};{{- end }}"
@@ -188,6 +274,8 @@ spec:
value: "{{- range .Values.kerberoshub.api.sso }}{{ .clientVerificationId }};{{- end }}"
- name: SSO_FORCE_SSO
value: "{{- range .Values.kerberoshub.api.sso }}{{ .forceSSO }};{{- end }}"
- name: SSO_EXTRA_HEADERS
value: "{{- range .Values.kerberoshub.api.sso }}{{- if .extraHeaders }}{{- range .extraHeaders }}{{ .name }}:{{ .value }};{{- end }}{{- else }}{{- end }}*{{- end }}"
# Kerberos pipeline
- name: QUEUE_SYSTEM
@@ -195,6 +283,19 @@ spec:
- name: QUEUE_NAME
value: "{{ .Values.queueName }}"
# Deployment-global workflow definitions (WORKFLOW_DEFINITIONS): the
# SAME set the workflows engine consumes, assembled from the enabled
# definitions under kerberoshub.workflows.definitions (see
# kerberos-pipeline/_workflows-helpers.tpl). hub-api reads these
# read-only to surface config workflows alongside the user workflows
# it stores in the database; the config workflows are never persisted.
- name: WORKFLOW_DEFINITIONS
value: {{ include "kerberoshub.workflows.workflowDefinitions" . | quote }}
# Deployment service routing catalog used by API-owned embedded
# workflows (for example the one-stage case redaction modal flow).
- name: WORKFLOW_STAGE_QUEUES
value: {{ include "kerberoshub.workflows.stageQueues" . | quote }}
# Stripe for billing
- name: STRIPE_KEY
value: "{{ .Values.kerberoshub.api.stripe.privateKey }}"
@@ -256,20 +357,6 @@ spec:
- name: RABBITMQ_PASSWORD
value: "{{ .Values.rabbitmq.password }}"
# Mongodb
- name: MONGODB_DATABASE_CLOUD
value: "Kerberos"
- name: MONGODB_URI
value: "{{ .Values.mongodb.uri }}"
- name: MONGODB_HOST
value: "{{ .Values.mongodb.host }}"
- name: MONGODB_DATABASE_CREDENTIALS
value: "{{ .Values.mongodb.adminDatabase }}"
- name: MONGODB_USERNAME
value: "{{ .Values.mongodb.username }}"
- name: MONGODB_PASSWORD
value: "{{ .Values.mongodb.password }}"
# Slack notifications (this will send events/logs to a specific channel).
- name: SLACK_ENABLED
value: "{{ .Values.kerberoshub.api.slack.enabled }}"
@@ -278,22 +365,6 @@ spec:
- name: SLACK_USERNAME
value: "{{ .Values.kerberoshub.api.slack.username }}"
# Elastic search - Kibana
- name: LOGGING_ELASTICSEARCH
value: "{{ .Values.kerberoshub.api.elasticsearch.enabled }}"
- name: LOGGING_ELASTICSEARCH_PROTOCOL
value: "{{ .Values.kerberoshub.api.elasticsearch.protocol }}"
- name: LOGGING_ELASTICSEARCH_HOST
value: "{{ .Values.kerberoshub.api.elasticsearch.host }}"
- name: LOGGING_ELASTICSEARCH_PORT
value: "{{ .Values.kerberoshub.api.elasticsearch.port }}"
- name: LOGGING_ELASTICSEARCH_INDEX
value: "{{ .Values.kerberoshub.api.elasticsearch.index }}"
- name: LOGGING_ELASTICSEARCH_USERNAME
value: "{{ .Values.kerberoshub.api.elasticsearch.username }}"
- name: LOGGING_ELASTICSEARCH_PASSWORD
value: "{{ .Values.kerberoshub.api.elasticsearch.password }}"
# Mail settings
- name: MAIL_PROVIDER
value: "{{ .Values.email.provider }}"
@@ -301,7 +372,7 @@ spec:
value: "{{ .Values.email.from }}"
- name: EMAIL_FROM_DISPLAYNAME
value: "{{ .Values.email.displayName }}"
# Mail templates
- name: WELCOME_TEMPLATE
value: "{{ .Values.email.templates.welcome }}"
@@ -319,6 +390,22 @@ spec:
value: "{{ .Values.email.templates.share }}"
- name: SHARE_TITLE
value: "{{ .Values.email.templates.shareTitle }}"
- name: CASE_SHARE_TEMPLATE
value: "{{ .Values.email.templates.caseShare }}"
- name: CASE_SHARE_TITLE
value: "{{ .Values.email.templates.caseShareTitle }}"
- name: CASE_SHARE_OTP_TEMPLATE
value: "{{ .Values.email.templates.caseShareOtp }}"
- name: CASE_SHARE_OTP_TITLE
value: "{{ .Values.email.templates.caseShareOtpTitle }}"
- name: ASSIGN_TASK_TEMPLATE
value: "{{ .Values.email.templates.assignTask }}"
- name: ASSIGN_TASK_TITLE
value: "{{ .Values.email.templates.assignTaskTitle }}"
- name: DEFAULT_TASK_RETENTION_DAYS
value: "{{ .Values.kerberoshub.api.defaultTaskRetentionDays }}"
- name: CASES_MAX_RETENTION_DAYS
value: "{{ .Values.kerberoshub.api.casesMaxRetentionDays }}"
# SMTP
- name: SMTP_SERVER
@@ -329,7 +416,7 @@ spec:
value: "{{ .Values.email.smtp.username }}"
- name: SMTP_PASSWORD
value: "{{ .Values.email.smtp.password }}"
# Mailgun
- name: MAILGUN_DOMAIN
value: "{{ .Values.email.mailgun.domain }}"
@@ -362,3 +449,17 @@ spec:
value: "{{ .Values.kerberosvault.sprite.width }}"
- name: VAULT_SPRITE_HEIGHT
value: "{{ .Values.kerberosvault.sprite.height }}"
{{- if .Values.kerberoshub.extraEnv }}
{{- toYaml .Values.kerberoshub.extraEnv | nindent 12 }}
{{- end }}
{{- if .Values.opentelemetry.enabled }}
# Open Telemetry tracing
- name: OTEL_EXPORTED_OTLP_ENABLED
value: "{{ .Values.opentelemetry.enabled }}"
- name: OTEL_EXPORTED_OTLP_ROUTING_ENABLED
value: "{{ .Values.opentelemetry.routingEnabled }}"
- name: OTEL_EXPORTER_OTLP_ENDPOINT
value: "{{ .Values.opentelemetry.collector.endpoint }}"
{{- end }}
{{- end }}

View File

@@ -0,0 +1,18 @@
{{- if or (eq .Values.mode "all") (eq .Values.mode "ui") -}}
apiVersion: monitoring.coreos.com/v1
kind: ServiceMonitor
metadata:
name: hub-cleanup-servicemonitor
namespace: {{ .Release.Namespace }}
labels:
service: hub-cleanup
release: prometheus
spec:
selector:
matchLabels:
service: hub-cleanup
endpoints:
- port: hub-metrics
interval: 15s
path: /metrics
{{- end }}

View File

@@ -1,9 +1,11 @@
{{- if or (eq .Values.mode "all") (eq .Values.mode "ui") -}}
apiVersion: apps/v1
kind: Deployment
metadata:
name: hub-cleanup
namespace: {{ .Release.Namespace }}
spec:
replicas: 1
replicas: {{ .Values.kerberoshub.cleanup.replicas }}
selector:
matchLabels:
app: hub-cleanup
@@ -15,36 +17,115 @@ spec:
maxSurge: 1
template:
metadata:
annotations:
checksum/config: {{ include (print $.Template.BasePath "/configmap-mongodb.yaml") . | sha256sum }}
labels:
app: hub-cleanup
spec:
{{- if .Values.kerberoshub.serviceAccount.create }}
serviceAccountName: {{ default (printf "%s-%s-sa" .Release.Name .Chart.Name | trunc 63 | trimSuffix "-") .Values.kerberoshub.serviceAccount.name }}
{{- end }}
{{- with .Values.imagePullSecrets }}
imagePullSecrets:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- $mongodbTLS := .Values.mongodb.tls }}
{{- if or .Values.kerberoshub.cleanup.volumes (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
volumes:
{{- with .Values.kerberoshub.cleanup.volumes }}
{{- toYaml . | nindent 8 }}
{{- end }}
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
{{- include "hub.mongodb.tlsVolume" . | nindent 8 }}
{{- end }}
{{- end }}
{{- with .Values.kerberoshub.cleanup.topologySpreadConstraints }}
topologySpreadConstraints:
{{- toYaml . | nindent 8 }}
{{- end }}
containers:
- name: hub-cleanup
image: "{{ .Values.kerberoshub.cleanup.repository }}:{{ .Values.kerberoshub.cleanup.tag }}"
image: "{{ .Values.global.imageRegistry }}{{ .Values.kerberoshub.cleanup.repository }}:{{ .Values.kerberoshub.cleanup.tag }}"
imagePullPolicy: {{ .Values.kerberoshub.cleanup.pullPolicy }}
{{- with .Values.kerberoshub.cleanup.resources }}
resources:
{{- toYaml . | nindent 12 }}
{{- end }}
{{- if or .Values.kerberoshub.cleanup.volumeMounts (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
volumeMounts:
{{- with .Values.kerberoshub.cleanup.volumeMounts }}
{{- toYaml . | nindent 12 }}
{{- end }}
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
{{- include "hub.mongodb.tlsVolumeMount" . | nindent 12 }}
{{- end }}
{{- end }}
envFrom:
- configMapRef:
name: mongodb-config
ports:
- containerPort: 8080
env:
- name: MODE
value: "{{ .Values.kerberoshub.cleanup.mode }}"
- name: LOG_LEVEL
value: "{{ .Values.kerberoshub.cleanup.logLevel }}"
- name: RUN_INTERVAL_MINUTES
value: "{{ .Values.kerberoshub.cleanup.runIntervalMinutes }}"
- name: CLEANUP_USERNAMES
value: "{{ .Values.kerberoshub.cleanup.cleanupUsernames }}"
- name: READ_ONLY
value: "{{ .Values.readonly }}"
value: "{{ .Values.readOnly }}"
- name: MAX_DAYS
value: "30"
- name: MONGODB_DATABASE_CLOUD
value: "Kerberos"
- name: MONGODB_URI
value: "{{ .Values.mongodb.uri }}"
- name: MONGODB_HOST
value: "{{ .Values.mongodb.host }}"
- name: MONGODB_DATABASE_CREDENTIALS
value: "{{ .Values.mongodb.adminDatabase }}"
- name: MONGODB_USERNAME
value: "{{ .Values.mongodb.username }}"
- name: MONGODB_PASSWORD
value: "{{ .Values.mongodb.password }}"
value: "{{ .Values.kerberoshub.cleanup.maxDays }}"
- name: BATCH_SIZE
value: "{{ .Values.kerberoshub.cleanup.batchSize }}"
- name: USER_BATCH_SIZE
value: "{{ .Values.kerberoshub.cleanup.userBatchSize }}"
- name: MAX_USERS_PER_RUN
value: "{{ .Values.kerberoshub.cleanup.maxUsersPerRun }}"
- name: PROGRESS_EVERY
value: "{{ .Values.kerberoshub.cleanup.progressEvery }}"
- name: ACTIVE_USER_RESCAN_HOURS
value: "{{ .Values.kerberoshub.cleanup.activeUserRescanHours }}"
- name: INACTIVE_USER_RESCAN_HOURS
value: "{{ .Values.kerberoshub.cleanup.inactiveUserRescanHours }}"
- name: READ_TIMEOUT_SECONDS
value: "{{ .Values.kerberoshub.cleanup.readTimeoutSeconds }}"
- name: DELETE_TIMEOUT_SECONDS
value: "{{ .Values.kerberoshub.cleanup.deleteTimeoutSeconds }}"
- name: REPORT_INCLUDE_STATS
value: "{{ .Values.kerberoshub.cleanup.reportIncludeStats }}"
- name: DRY_RUN
value: "{{ .Values.kerberoshub.cleanup.dryRun }}"
- name: DEBUG
value: "{{ .Values.kerberoshub.cleanup.debug }}"
- name: GLOBAL_PASS_ENABLED
value: "{{ .Values.kerberoshub.cleanup.globalPassEnabled }}"
- name: GLOBAL_PASS_INTERVAL_HOURS
value: "{{ .Values.kerberoshub.cleanup.globalPassIntervalHours }}"
- name: GLOBAL_PASS_DELETE_BUDGET
value: "{{ .Values.kerberoshub.cleanup.globalPassDeleteBudget }}"
- name: DEFAULT_TASK_RETENTION_DAYS
value: "{{ .Values.kerberoshub.cleanup.defaultTaskRetentionDays }}"
{{- if .Values.kerberoshub.extraEnv }}
{{- toYaml .Values.kerberoshub.extraEnv | nindent 12 }}
{{- end }}
---
apiVersion: v1
kind: Service
metadata:
name: hub-cleanup
namespace: {{ .Release.Namespace }}
labels:
app: hub-cleanup
service: hub-cleanup
spec:
ports:
- name: hub-metrics
port: 8080
targetPort: 8080
protocol: TCP
selector:
app: hub-cleanup
{{- end }}

View File

@@ -1,7 +1,9 @@
{{- if and (or (eq .Values.mode "all") (eq .Values.mode "ui")) .Values.kerberoshub.frontend.demoEnabled -}}
apiVersion: v1
kind: Service
metadata:
name: hub-frontend-demo-svc
namespace: {{ .Release.Namespace }}
labels:
app: hub-frontend-demo-svc
spec:
@@ -12,6 +14,7 @@ spec:
name: http
selector:
app: hub-frontend-demo
{{ if ne .Values.ingress "" }}
---
{{ if .Capabilities.APIVersions.Has "networking.k8s.io/v1" }}
apiVersion: networking.k8s.io/v1
@@ -21,22 +24,19 @@ apiVersion: networking.k8s.io/v1beta1
kind: Ingress
metadata:
name: hub-frontend-demo-ingress
namespace: {{ .Release.Namespace }}
annotations:
kubernetes.io/ingress.class: {{ .Values.ingress }}
{{- if eq .Values.ingress "nginx" }}
kubernetes.io/tls-acme: "true"
nginx.ingress.kubernetes.io/ssl-redirect: "true"
cert-manager.io/cluster-issuer: "letsencrypt-prod"
{{- end }}
spec:
ingressClassName: {{ .Values.ingress }}
{{- with .Values.kerberoshub.frontend.demoTls }}
tls:
{{- toYaml . | nindent 8 }}
{{- end }}
{{ if .Capabilities.APIVersions.Has "networking.k8s.io/v1" }}
rules:
- host: "{{ .Values.kerberoshub.frontend.demoUrl }}"
@@ -59,11 +59,13 @@ spec:
serviceName: hub-frontend-demo-svc
servicePort: 80
{{ end }}
{{ end }}
---
apiVersion: apps/v1
kind: Deployment
metadata:
name: hub-frontend-demo
namespace: {{ .Release.Namespace }}
spec:
replicas: {{ .Values.kerberoshub.frontend.replicas }}
selector:
@@ -80,6 +82,9 @@ spec:
labels:
app: hub-frontend-demo
spec:
{{- if .Values.kerberoshub.serviceAccount.create }}
serviceAccountName: {{ default (printf "%s-%s-sa" .Release.Name .Chart.Name | trunc 63 | trimSuffix "-") .Values.kerberoshub.serviceAccount.name }}
{{- end }}
{{- with .Values.imagePullSecrets }}
imagePullSecrets:
{{- toYaml . | nindent 8 }}
@@ -88,9 +93,13 @@ spec:
volumes:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- with .Values.kerberoshub.frontend.topologySpreadConstraints }}
topologySpreadConstraints:
{{- toYaml . | nindent 8 }}
{{- end }}
containers:
- name: hub-frontend-demo
image: "{{ .Values.kerberoshub.frontend.repository }}:{{ .Values.kerberoshub.frontend.tag }}"
image: "{{ .Values.global.imageRegistry }}{{ .Values.kerberoshub.frontend.repository }}:{{ .Values.kerberoshub.frontend.tag }}"
imagePullPolicy: {{ .Values.kerberoshub.frontend.pullPolicy }}
{{- with .Values.kerberoshub.frontend.resources }}
resources:
@@ -104,8 +113,12 @@ spec:
{{- toYaml . | nindent 8 }}
{{- end }}
env:
- name: SSO_DOMAIN
value: "{{ .Values.kerberoshub.frontend.ssoDomain }}"
- name: SSO_DOMAINS
# get the domain attribute from the list of sso domains
value: "{{- range .Values.kerberoshub.api.sso }}{{ .domain }};{{- end }}"
- name: SSO_FORCE_DOMAINS
# get the domain attribute from the list of sso domains
value: "{{- range .Values.kerberoshub.api.sso }}{{ .forceSSO }};{{- end }}"
- name: TITLE
value: "{{ .Values.kerberoshub.frontend.title }}"
- name: LOGO_NAME
@@ -127,6 +140,10 @@ spec:
value: "true"
- name: DEMO
value: "true"
- name: MULTI_TENANT
value: "{{ .Values.kerberoshub.frontend.multiTenant }}"
- name: TENANT_BASE_DOMAIN
value: "{{ .Values.kerberoshub.frontend.tenantBaseDomain }}"
# Mqtt (VERNEMQ)
- name: MQTT_PROTOCOL
@@ -135,18 +152,24 @@ spec:
value: "{{ .Values.mqtt.host }}"
- name: MQTT_PORT
value: "{{ .Values.mqtt.port }}"
- name: MQTT_USERNAME
value: "{{ .Values.mqtt.username }}"
- name: MQTT_PASSWORD
value: "{{ .Values.mqtt.password }}"
# MQTT_USERNAME / MQTT_PASSWORD are intentionally not exposed to the
# frontend. They are fetched from the authenticated hub-api endpoint
# /runtime/config after login. See hub-api deployment.
- name: MQTT_LEGACY_SERVER
value: "{{ .Values.mqtt.legacy.host }}"
- name: MQTT_LEGACY_PORT
value: "{{ .Values.mqtt.legacy.port }}"
# OpenAI
- name: OPENAI_ENABLED
value: "{{ .Values.openai.enabled }}"
# Turn (Pion)
- name: TURN_SERVER
value: "{{ .Values.turn.host }}"
- name: TURN_USERNAME
value: "{{ .Values.turn.username }}"
- name: TURN_PASSWORD
value: "{{ .Values.turn.password }}"
# TURN_USERNAME / TURN_PASSWORD are intentionally not exposed to the
# frontend. They are fetched from the authenticated hub-api endpoint
# /runtime/config after login. See hub-api deployment.
# Mixpanel for monitoring
- name: MIXPANEL_KEY
@@ -174,35 +197,6 @@ spec:
- name: ZENDESK_URL
value: "{{ .Values.kerberoshub.frontend.zendesk.url }}"
# Titles and descriptions on pages
- name: LOGIN_DESCRIPTION
value: "{{ .Values.kerberoshub.frontend.loginDescription }}"
- name: LOGIN_COPYRIGHT
value: "{{ .Values.kerberoshub.frontend.loginCopyright }}"
- name: PAGE_DASHBOARD_TITLE
value: "{{ .Values.kerberoshub.frontend.dashboardTitle }}"
- name: PAGE_DASHBOARD_SUB_TITLE
value: "{{ .Values.kerberoshub.frontend.dashboardSubTitle }}"
- name: PAGE_LATESTEVENTS_TITLE
value: "{{ .Values.kerberoshub.frontend.latestEventsTitle }}"
- name: PAGE_LATESTEVENTS_SUB_TITLE
value: "{{ .Values.kerberoshub.frontend.latestEventsSubTitle }}"
- name: PAGE_LIVESTREAM_TITLE
value: "{{ .Values.kerberoshub.frontend.livestreamTitle }}"
- name: PAGE_LIVESTREAM_SUB_TITLE
value: "{{ .Values.kerberoshub.frontend.livestreamSubTitle }}"
- name: PAGE_MEDIA_TITLE
value: "{{ .Values.kerberoshub.frontend.mediaTitle }}"
- name: PAGE_MEDIA_SUB_TITLE
value: "{{ .Values.kerberoshub.frontend.mediaSubTitle }}"
- name: PAGE_DASHBOARD_CPU_USAGE
value: "{{ .Values.kerberoshub.frontend.cpuUsageDescription }}"
- name: PAGE_DASHBOARD_FPS
value: "{{ .Values.kerberoshub.frontend.framesPerSecondDescription }}"
- name: PAGE_DASHBOARD_MLA
value: "{{ .Values.kerberoshub.frontend.mlaUtilizationDescription }}"
- name: PAGE_DASHBOARD_OBJECTS
value: "{{ .Values.kerberoshub.frontend.objectsDetectedDescription }}"
- name: HIDE_ADD_AGENT
value: "{{ .Values.kerberoshub.frontend.hideAddAgent }}"
@@ -225,6 +219,118 @@ spec:
value: "{{ .Values.kerberoshub.frontend.navigationLinkUrl4 }}"
- name: NAVIGATION_LINK_TITLE_5
value: "{{ .Values.kerberoshub.frontend.navigationLinkTitle5 }}"
- name: NAVIGATION_LINK_URL_5
- name: NAVIGATION_LINK_URL_5
value: "{{ .Values.kerberoshub.frontend.navigationLinkUrl5 }}"
- name: CASE_FILTER_ASSIGNEES_DEFAULT
value: "{{ .Values.kerberoshub.frontend.caseFilterAssigneesDefault }}"
# features > general
- name: FEATURE_CASE_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.case.enabled }}"
- name: FEATURE_WORKFLOWS_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.workflows.enabled }}"
- name: FEATURE_DARK_MODE
value: "{{ .Values.kerberoshub.frontend.features.darkMode }}"
- name: FEATURE_SPLASH_SCREEN_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.splashScreen.enabled }}"
- name: FEATURE_LANDING_PAGE
value: "{{ .Values.kerberoshub.frontend.features.landingPage }}"
# features > internationalization (i18n)
- name: FEATURE_I18N_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.i18n.enabled }}"
- name: DEFAULT_LANGUAGE
value: "{{ .Values.kerberoshub.frontend.features.i18n.defaultLanguage }}"
# features > liveview
- name: FEATURE_LIVE_STREAM_MODE
value: "{{ .Values.kerberoshub.frontend.features.liveview.liveStreamMode }}"
- name: FEATURE_HLS_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.liveview.hlsEnabled }}"
- name: FEATURE_MOQ_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.liveview.moqEnabled }}"
- name: MOQ_RELAY_URL
value: "{{ .Values.kerberoshub.frontend.features.liveview.moqRelayUrl }}"
- name: MOQ_BROADCAST_PREFIX
value: "{{ .Values.kerberoshub.frontend.features.liveview.moqBroadcastPrefix }}"
- name: FEATURE_LIVEVIEW_PAGINATION_MODE
value: "{{ .Values.kerberoshub.frontend.features.liveview.paginationMode }}"
- name: FEATURE_LIVEVIEW_PAGE_SIZE
value: "{{ .Values.kerberoshub.frontend.features.liveview.pageSize }}"
- name: FEATURE_LIVEVIEW_MAX_STREAMS
value: "{{ .Values.kerberoshub.frontend.features.liveview.maxStreams }}"
# features > devices
- name: FEATURE_DEVICES_HIDE_AGENT
value: "{{ .Values.kerberoshub.frontend.features.devices.hideAgent }}"
# features > floorplan
- name: FEATURE_FLOORPLAN_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.floorplan.enabled }}"
- name: COLOR_TRACK_BOX
value: "{{ .Values.kerberoshub.frontend.features.floorplan.colorTrackBox }}"
- name: COLOR_TRACK_BOX_HOVER
value: "{{ .Values.kerberoshub.frontend.features.floorplan.colorTrackBoxHover }}"
- name: COLOR_TRACK_BOX_DRAWING
value: "{{ .Values.kerberoshub.frontend.features.floorplan.colorTrackBoxDrawing }}"
- name: COLOR_TRACK_BOX_CONTROLS_DELETE
value: "{{ .Values.kerberoshub.frontend.features.floorplan.colorTrackBoxControlsDelete }}"
- name: COLOR_DEVICE_ACTIVE
value: "{{ .Values.kerberoshub.frontend.colorDeviceActive }}"
- name: COLOR_DEVICE_INACTIVE
value: "{{ .Values.kerberoshub.frontend.colorDeviceInactive }}"
- name: COLOR_DEVICE_IDLE
value: "{{ .Values.kerberoshub.frontend.colorDeviceIdle }}"
- name: COLOR_DEVICE_MOTION
value: "{{ .Values.kerberoshub.frontend.colorDeviceMotion }}"
- name: COLOR_LIVE_VIEW_CONTROL_ACTIVE
value: "{{ .Values.kerberoshub.frontend.colorLiveViewControlActive }}"
- name: COLOR_LIVE_VIEW_CONTROL_MOTION
value: "{{ .Values.kerberoshub.frontend.colorLiveViewControlMotion }}"
- name: COLOR_FLOOR_PLAN_LABEL_TEXT
value: "{{ .Values.kerberoshub.frontend.colorFloorPlanLabelText }}"
- name: COLOR_FLOOR_PLAN_LABEL_BACKGROUND
value: "{{ .Values.kerberoshub.frontend.colorFloorPlanLabelBackground }}"
- name: COLOR_DEVICE_MARKER_BORDER
value: "{{ .Values.kerberoshub.frontend.colorDeviceMarkerBorder }}"
# features > video edits
- name: FEATURE_VIDEO_EDITS_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.videoEdits.enabled }}"
# features > face redaction
- name: FEATURE_FACE_REDACTION_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.faceRedaction.enabled }}"
- name: FEATURE_FACE_REDACTION_CLASSIFIER_TRACKS_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.faceRedaction.classifierTracksEnabled }}"
# features > media
- name: FEATURE_MEDIA_FILTER_DATE_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.media.filter.date.enabled }}"
- name: FEATURE_MEDIA_FILTER_SITES_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.media.filter.sites.enabled }}"
- name: FEATURE_MEDIA_FILTER_GROUPS_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.media.filter.groups.enabled }}"
- name: FEATURE_MEDIA_FILTER_DEVICES_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.media.filter.devices.enabled }}"
- name: FEATURE_MEDIA_FILTER_OBJECT_DETECTION_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.media.filter.objectDetection.enabled }}"
- name: FEATURE_MEDIA_FILTER_STAR_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.media.filter.star.enabled }}"
- name: FEATURE_MEDIA_FILTER_REGION_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.media.filter.region.enabled }}"
- name: FEATURE_MEDIA_FILTER_SORT_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.media.filter.sort.enabled }}"
- name: FEATURE_MEDIA_FILTER_CATEGORIES_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.media.filter.category.enabled }}"
- name: FEATURE_MEDIA_FILTER_MARKERS_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.media.filter.markers.enabled }}"
- name: FEATURE_MEDIA_FILTER_EVENTS_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.media.filter.events.enabled }}"
- name: FEATURE_MEDIA_FILTER_TAGS_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.media.filter.tags.enabled }}"
{{- if .Values.kerberoshub.extraEnv }}
{{- toYaml .Values.kerberoshub.extraEnv | nindent 8 }}
{{- end }}
{{- end }}

View File

@@ -1,7 +1,10 @@
{{- if or (eq .Values.mode "all") (eq .Values.mode "ui") -}}
{{- if .Values.kerberoshub.frontend.serviceEnabled }}
apiVersion: v1
kind: Service
metadata:
name: hub-frontend-svc
namespace: {{ .Release.Namespace }}
labels:
app: hub-frontend-svc
spec:
@@ -12,29 +15,35 @@ spec:
name: http
selector:
app: hub-frontend
{{- end }}
{{ if ne .Values.ingress "" }}
---
{{ if .Capabilities.APIVersions.Has "networking.k8s.io/v1" }}
{{- if .Capabilities.APIVersions.Has "networking.k8s.io/v1" }}
apiVersion: networking.k8s.io/v1
{{ else }}
{{- else }}
apiVersion: networking.k8s.io/v1beta1
{{ end }}
{{- end }}
kind: Ingress
metadata:
name: hub-frontend-ingress
namespace: {{ .Release.Namespace }}
annotations:
kubernetes.io/ingress.class: {{ .Values.ingress }}
{{- if eq .Values.kerberoshub.oauth2Proxy.enabled true }}
nginx.ingress.kubernetes.io/auth-url: "https://$host/oauth2/auth"
nginx.ingress.kubernetes.io/auth-signin: "https://$host/oauth2/start?rd=$escaped_request_uri"
{{- end }}
{{- if eq .Values.ingress "nginx" }}
kubernetes.io/tls-acme: "true"
nginx.ingress.kubernetes.io/ssl-redirect: "true"
cert-manager.io/cluster-issuer: "letsencrypt-prod"
{{- end }}
spec:
ingressClassName: {{ .Values.ingress }}
{{- with .Values.kerberoshub.frontend.tls }}
tls:
{{- toYaml . | nindent 8 }}
{{- end }}
{{ if .Capabilities.APIVersions.Has "networking.k8s.io/v1" }}
{{- if .Capabilities.APIVersions.Has "networking.k8s.io/v1" }}
rules:
- host: "{{ .Values.kerberoshub.frontend.url }}"
http:
@@ -70,8 +79,8 @@ spec:
port:
number: 80
{{- end }}
{{ else }}
{{- else }}
rules:
- host: "{{ .Values.kerberoshub.frontend.url }}"
http:
@@ -98,12 +107,46 @@ spec:
serviceName: hub-frontend-svc
servicePort: 80
{{- end }}
{{ end }}
{{- end }}
{{- end }}
{{- if eq .Values.kerberoshub.oauth2Proxy.enabled true }}
---
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
name: oauth2-proxy-frontend
namespace: kube-system
annotations:
{{- if eq .Values.ingress "nginx" }}
cert-manager.io/cluster-issuer: letsencrypt-prod
kubernetes.io/tls-acme: "true"
nginx.ingress.kubernetes.io/ssl-redirect: "true"
nginx.ingress.kubernetes.io/enable-cors: "true"
{{- end }}
spec:
ingressClassName: {{ .Values.ingress }}
rules:
- host: "{{ .Values.kerberoshub.frontend.url }}"
http:
paths:
- path: /oauth2
pathType: Prefix
backend:
service:
name: oauth2-proxy
port:
number: 4180
tls:
- hosts:
- "{{ .Values.kerberoshub.frontend.url }}"
secretName:
{{- end }}
---
apiVersion: apps/v1
kind: Deployment
metadata:
name: hub-frontend
namespace: {{ .Release.Namespace }}
spec:
replicas: {{ .Values.kerberoshub.frontend.replicas }}
selector:
@@ -120,6 +163,9 @@ spec:
labels:
app: hub-frontend
spec:
{{- if .Values.kerberoshub.serviceAccount.create }}
serviceAccountName: {{ default (printf "%s-%s-sa" .Release.Name .Chart.Name | trunc 63 | trimSuffix "-") .Values.kerberoshub.serviceAccount.name }}
{{- end }}
{{- with .Values.imagePullSecrets }}
imagePullSecrets:
{{- toYaml . | nindent 8 }}
@@ -128,9 +174,13 @@ spec:
volumes:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- with .Values.kerberoshub.frontend.topologySpreadConstraints }}
topologySpreadConstraints:
{{- toYaml . | nindent 8 }}
{{- end }}
containers:
- name: hub-frontend
image: "{{ .Values.kerberoshub.frontend.repository }}:{{ .Values.kerberoshub.frontend.tag }}"
image: "{{ .Values.global.imageRegistry }}{{ .Values.kerberoshub.frontend.repository }}:{{ .Values.kerberoshub.frontend.tag }}"
imagePullPolicy: {{ .Values.kerberoshub.frontend.pullPolicy }}
{{- with .Values.kerberoshub.frontend.resources }}
resources:
@@ -144,6 +194,8 @@ spec:
{{- toYaml . | nindent 8 }}
{{- end }}
env:
- name: LOG_LEVEL
value: "{{ .Values.kerberoshub.frontend.logLevel }}"
- name: SSO_DOMAINS
# get the domain attribute from the list of sso domains
value: "{{- range .Values.kerberoshub.api.sso }}{{ .domain }};{{- end }}"
@@ -183,10 +235,9 @@ spec:
value: "{{ .Values.mqtt.host }}"
- name: MQTT_PORT
value: "{{ .Values.mqtt.port }}"
- name: MQTT_USERNAME
value: "{{ .Values.mqtt.username }}"
- name: MQTT_PASSWORD
value: "{{ .Values.mqtt.password }}"
# MQTT_USERNAME / MQTT_PASSWORD are intentionally not exposed to the
# frontend. They are fetched from the authenticated hub-api endpoint
# /runtime/config after login. See hub-api deployment.
- name: MQTT_LEGACY_SERVER
value: "{{ .Values.mqtt.legacy.host }}"
- name: MQTT_LEGACY_PORT
@@ -199,10 +250,9 @@ spec:
# Turn (Pion)
- name: TURN_SERVER
value: "{{ .Values.turn.host }}"
- name: TURN_USERNAME
value: "{{ .Values.turn.username }}"
- name: TURN_PASSWORD
value: "{{ .Values.turn.password }}"
# TURN_USERNAME / TURN_PASSWORD are intentionally not exposed to the
# frontend. They are fetched from the authenticated hub-api endpoint
# /runtime/config after login. See hub-api deployment.
# Mixpanel for monitoring
- name: MIXPANEL_KEY
@@ -230,39 +280,6 @@ spec:
- name: ZENDESK_URL
value: "{{ .Values.kerberoshub.frontend.zendesk.url }}"
# Titles and descriptions on pages
- name: LOGIN_DESCRIPTION
value: "{{ .Values.kerberoshub.frontend.loginDescription }}"
- name: LOGIN_COPYRIGHT
value: "{{ .Values.kerberoshub.frontend.loginCopyright }}"
- name: PAGE_DASHBOARD_TITLE
value: "{{ .Values.kerberoshub.frontend.dashboardTitle }}"
- name: PAGE_DASHBOARD_SUB_TITLE
value: "{{ .Values.kerberoshub.frontend.dashboardSubTitle }}"
- name: PAGE_LATESTEVENTS_TITLE
value: "{{ .Values.kerberoshub.frontend.latestEventsTitle }}"
- name: PAGE_LATESTEVENTS_SUB_TITLE
value: "{{ .Values.kerberoshub.frontend.latestEventsSubTitle }}"
- name: PAGE_LIVESTREAM_TITLE
value: "{{ .Values.kerberoshub.frontend.livestreamTitle }}"
- name: PAGE_LIVESTREAM_SUB_TITLE
value: "{{ .Values.kerberoshub.frontend.livestreamSubTitle }}"
- name: PAGE_MEDIA_TITLE
value: "{{ .Values.kerberoshub.frontend.mediaTitle }}"
- name: PAGE_MEDIA_SUB_TITLE
value: "{{ .Values.kerberoshub.frontend.mediaSubTitle }}"
- name: PAGE_DAY_TITLE
value: "{{ .Values.kerberoshub.frontend.dayTitle }}"
- name: PAGE_DAY_SUB_TITLE
value: "{{ .Values.kerberoshub.frontend.daySubTitle }}"
- name: PAGE_DASHBOARD_CPU_USAGE
value: "{{ .Values.kerberoshub.frontend.cpuUsageDescription }}"
- name: PAGE_DASHBOARD_FPS
value: "{{ .Values.kerberoshub.frontend.framesPerSecondDescription }}"
- name: PAGE_DASHBOARD_MLA
value: "{{ .Values.kerberoshub.frontend.mlaUtilizationDescription }}"
- name: PAGE_DASHBOARD_OBJECTS
value: "{{ .Values.kerberoshub.frontend.objectsDetectedDescription }}"
- name: HIDE_ADD_AGENT
value: "{{ .Values.kerberoshub.frontend.hideAddAgent }}"
@@ -285,5 +302,156 @@ spec:
value: "{{ .Values.kerberoshub.frontend.navigationLinkUrl4 }}"
- name: NAVIGATION_LINK_TITLE_5
value: "{{ .Values.kerberoshub.frontend.navigationLinkTitle5 }}"
- name: NAVIGATION_LINK_URL_5
- name: NAVIGATION_LINK_URL_5
value: "{{ .Values.kerberoshub.frontend.navigationLinkUrl5 }}"
- name: CASE_FILTER_ASSIGNEES_DEFAULT
value: "{{ .Values.kerberoshub.frontend.caseFilterAssigneesDefault }}"
# features > general
- name: FEATURE_CASE_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.case.enabled }}"
- name: FEATURE_WORKFLOWS_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.workflows.enabled }}"
- name: FEATURE_ORGANISATIONS_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.organisations.enabled }}"
- name: FEATURE_ORGANISATION_SWITCHER_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.organisations.switcherEnabled }}"
- name: FEATURE_ORGANISATION_CREATION_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.organisations.creationEnabled }}"
- name: FEATURE_ORGANISATION_SETTINGS_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.organisations.settingsEnabled }}"
- name: FEATURE_PROJECTS_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.projects.enabled }}"
- name: FEATURE_PROJECT_SWITCHER_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.projects.switcherEnabled }}"
- name: FEATURE_PROJECT_CREATION_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.projects.creationEnabled }}"
- name: FEATURE_PROJECT_SETTINGS_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.projects.settingsEnabled }}"
- name: FEATURE_DARK_MODE
value: "{{ .Values.kerberoshub.frontend.features.darkModeEnabled }}"
- name: FEATURE_SPLASH_SCREEN_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.splashScreen.enabled }}"
- name: FEATURE_LANDING_PAGE
value: "{{ .Values.kerberoshub.frontend.features.landingPage }}"
# features > internationalization (i18n)
- name: FEATURE_I18N_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.i18n.enabled }}"
- name: DEFAULT_LANGUAGE
value: "{{ .Values.kerberoshub.frontend.features.i18n.defaultLanguage }}"
# features > liveview
- name: FEATURE_DEFAULT_STREAM_MODE
value: "{{ .Values.kerberoshub.frontend.features.liveview.defaultStreamMode }}"
- name: FEATURE_LIVE_STREAM_MODE
value: "{{ .Values.kerberoshub.frontend.features.liveview.liveStreamMode }}"
- name: FEATURE_HLS_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.liveview.hlsEnabled }}"
- name: FEATURE_MOQ_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.liveview.moqEnabled }}"
- name: MOQ_RELAY_URL
value: "{{ .Values.kerberoshub.frontend.features.liveview.moqRelayUrl }}"
- name: MOQ_BROADCAST_PREFIX
value: "{{ .Values.kerberoshub.frontend.features.liveview.moqBroadcastPrefix }}"
- name: FEATURE_LIVEVIEW_PAGINATION_MODE
value: "{{ .Values.kerberoshub.frontend.features.liveview.paginationMode }}"
- name: FEATURE_LIVEVIEW_PAGE_SIZE
value: "{{ .Values.kerberoshub.frontend.features.liveview.pageSize }}"
- name: FEATURE_LIVEVIEW_MAX_STREAMS
value: "{{ .Values.kerberoshub.frontend.features.liveview.maxStreams }}"
# features > devices
- name: FEATURE_DEVICES_HIDE_AGENT
value: "{{ .Values.kerberoshub.frontend.features.devices.hideAgent }}"
# features > floorplan
- name: FEATURE_FLOORPLAN_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.floorplan.enabled }}"
# features > map
- name: MAP_TILE_URL_LIGHT
value: "{{ .Values.kerberoshub.frontend.features.map.tileUrlLight }}"
- name: MAP_TILE_URL_DARK
value: "{{ .Values.kerberoshub.frontend.features.map.tileUrlDark }}"
- name: MAP_ATTRIBUTION
value: "{{ .Values.kerberoshub.frontend.features.map.attribution }}"
- name: COLOR_TRACK_BOX
value: "{{ .Values.kerberoshub.frontend.features.floorplan.colorTrackBox }}"
- name: COLOR_TRACK_BOX_HOVER
value: "{{ .Values.kerberoshub.frontend.features.floorplan.colorTrackBoxHover }}"
- name: COLOR_TRACK_BOX_DRAWING
value: "{{ .Values.kerberoshub.frontend.features.floorplan.colorTrackBoxDrawing }}"
- name: COLOR_TRACK_BOX_CONTROLS_DELETE
value: "{{ .Values.kerberoshub.frontend.features.floorplan.colorTrackBoxControlsDelete }}"
- name: COLOR_DEVICE_ACTIVE
value: "{{ .Values.kerberoshub.frontend.colorDeviceActive }}"
- name: COLOR_DEVICE_INACTIVE
value: "{{ .Values.kerberoshub.frontend.colorDeviceInactive }}"
- name: COLOR_DEVICE_IDLE
value: "{{ .Values.kerberoshub.frontend.colorDeviceIdle }}"
- name: COLOR_DEVICE_MOTION
value: "{{ .Values.kerberoshub.frontend.colorDeviceMotion }}"
- name: COLOR_LIVE_VIEW_CONTROL_ACTIVE
value: "{{ .Values.kerberoshub.frontend.colorLiveViewControlActive }}"
- name: COLOR_LIVE_VIEW_CONTROL_MOTION
value: "{{ .Values.kerberoshub.frontend.colorLiveViewControlMotion }}"
- name: COLOR_FLOOR_PLAN_LABEL_TEXT
value: "{{ .Values.kerberoshub.frontend.colorFloorPlanLabelText }}"
- name: COLOR_FLOOR_PLAN_LABEL_BACKGROUND
value: "{{ .Values.kerberoshub.frontend.colorFloorPlanLabelBackground }}"
- name: COLOR_DEVICE_MARKER_BORDER
value: "{{ .Values.kerberoshub.frontend.colorDeviceMarkerBorder }}"
# features > chart
- name: COLOR_CHART_SELECTION_FILL
value: "{{ .Values.kerberoshub.frontend.features.chart.colorChartSelectionFill }}"
- name: COLOR_CHART_SELECTION_STROKE
value: "{{ .Values.kerberoshub.frontend.features.chart.colorChartSelectionStroke }}"
- name: COLOR_CHART_GRID_STROKE
value: "{{ .Values.kerberoshub.frontend.features.chart.colorChartGridStroke }}"
# features > video edits
- name: FEATURE_VIDEO_EDITS_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.videoEdits.enabled }}"
# features > face redaction
- name: FEATURE_FACE_REDACTION_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.faceRedaction.enabled }}"
- name: FEATURE_FACE_REDACTION_CLASSIFIER_TRACKS_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.faceRedaction.classifierTracksEnabled }}"
# features > media
- name: FEATURE_MEDIA_FILTER_DATE_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.media.filter.date.enabled }}"
- name: FEATURE_MEDIA_FILTER_SITES_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.media.filter.sites.enabled }}"
- name: FEATURE_MEDIA_FILTER_GROUPS_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.media.filter.groups.enabled }}"
- name: FEATURE_MEDIA_FILTER_DEVICES_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.media.filter.devices.enabled }}"
- name: FEATURE_MEDIA_FILTER_OBJECT_DETECTION_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.media.filter.objectDetection.enabled }}"
- name: FEATURE_MEDIA_FILTER_STAR_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.media.filter.star.enabled }}"
- name: FEATURE_MEDIA_FILTER_REGION_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.media.filter.region.enabled }}"
- name: FEATURE_MEDIA_FILTER_SORT_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.media.filter.sort.enabled }}"
- name: FEATURE_MEDIA_FILTER_CATEGORIES_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.media.filter.category.enabled }}"
- name: FEATURE_MEDIA_FILTER_MARKERS_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.media.filter.markers.enabled }}"
- name: FEATURE_MEDIA_FILTER_DEFAULT_VIEW
value: "{{ .Values.kerberoshub.frontend.features.media.filter.defaultView }}"
- name: FEATURE_MEDIA_FILTER_EVENTS_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.media.filter.events.enabled }}"
- name: FEATURE_MEDIA_FILTER_TAGS_ENABLED
value: "{{ .Values.kerberoshub.frontend.features.media.filter.tags.enabled }}"
{{- if .Values.kerberoshub.extraEnv }}
{{- toYaml .Values.kerberoshub.extraEnv | nindent 8 }}
{{- end }}
{{- end }}

View File

@@ -1,9 +1,11 @@
{{- if or (eq .Values.mode "all") (eq .Values.mode "ui") -}}
apiVersion: apps/v1
kind: Deployment
metadata:
name: hub-monitor-device
namespace: {{ .Release.Namespace }}
spec:
replicas: 1
replicas: {{ .Values.kerberoshub.monitordevice.replicas }}
selector:
matchLabels:
app: hub-monitor-device
@@ -15,46 +17,57 @@ spec:
maxSurge: 1
template:
metadata:
annotations:
checksum/config: {{ include (print $.Template.BasePath "/configmap-mongodb.yaml") . | sha256sum }}
labels:
app: hub-monitor-device
spec:
{{- if .Values.kerberoshub.serviceAccount.create }}
serviceAccountName: {{ default (printf "%s-%s-sa" .Release.Name .Chart.Name | trunc 63 | trimSuffix "-") .Values.kerberoshub.serviceAccount.name }}
{{- end }}
{{- with .Values.imagePullSecrets }}
imagePullSecrets:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- with .Values.kerberoshub.monitordevice.volumes }}
{{- $mongodbTLS := .Values.mongodb.tls }}
{{- if or .Values.kerberoshub.monitordevice.volumes (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
volumes:
{{- with .Values.kerberoshub.monitordevice.volumes }}
{{- toYaml . | nindent 8 }}
{{- end }}
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
{{- include "hub.mongodb.tlsVolume" . | nindent 8 }}
{{- end }}
{{- end }}
{{- with .Values.kerberoshub.monitordevice.topologySpreadConstraints }}
topologySpreadConstraints:
{{- toYaml . | nindent 8 }}
{{- end }}
containers:
- name: hub-monitor-device
image: "{{ .Values.kerberoshub.monitordevice.repository }}:{{ .Values.kerberoshub.monitordevice.tag }}"
image: "{{ .Values.global.imageRegistry }}{{ .Values.kerberoshub.monitordevice.repository }}:{{ .Values.kerberoshub.monitordevice.tag }}"
imagePullPolicy: {{ .Values.kerberoshub.monitordevice.pullPolicy }}
{{- with .Values.kerberoshub.monitordevice.resources }}
resources:
{{- toYaml . | nindent 12 }}
{{- end }}
{{- with .Values.kerberoshub.monitordevice.volumeMounts}}
{{- if or .Values.kerberoshub.monitordevice.volumeMounts (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
volumeMounts:
{{- with .Values.kerberoshub.monitordevice.volumeMounts}}
{{- toYaml . | nindent 12 }}
{{- end }}
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
{{- include "hub.mongodb.tlsVolumeMount" . | nindent 12 }}
{{- end }}
{{- end }}
envFrom:
- configMapRef:
name: mongodb-config
env:
- name: LOG_LEVEL
value: "{{ .Values.kerberoshub.monitordevice.logLevel }}"
- name: READ_ONLY
value: "{{ .Values.readonly }}"
# Mongodb
- name: MONGODB_DATABASE_CLOUD
value: "Kerberos"
- name: MONGODB_URI
value: "{{ .Values.mongodb.uri }}"
- name: MONGODB_HOST
value: "{{ .Values.mongodb.host }}"
- name: MONGODB_DATABASE_CREDENTIALS
value: "{{ .Values.mongodb.adminDatabase }}"
- name: MONGODB_USERNAME
value: "{{ .Values.mongodb.username }}"
- name: MONGODB_PASSWORD
value: "{{ .Values.mongodb.password }}"
# Mail settings
- name: MAIL_PROVIDER
value: "{{ .Values.email.provider }}"
@@ -62,13 +75,13 @@ spec:
value: "{{ .Values.email.from }}"
- name: EMAIL_FROM_DISPLAYNAME
value: "{{ .Values.email.displayName }}"
# Mail templates
- name: DEVICE_TEMPLATE
value: "{{ .Values.email.templates.device }}"
- name: DEVICE_TITLE
value: "{{ .Values.email.templates.deviceTitle }}"
# - Plain SMTP
- name: SMTP_SERVER
value: "{{ .Values.email.smtp.server }}"
@@ -78,10 +91,13 @@ spec:
value: "{{ .Values.email.smtp.username }}"
- name: SMTP_PASSWORD
value: "{{ .Values.email.smtp.password }}"
# Mailgun
- name: MAILGUN_DOMAIN
value: "{{ .Values.email.mailgun.domain }}"
- name: MAILGUN_API_KEY
value: "{{ .Values.email.mailgun.apikey }}"
{{- if .Values.kerberoshub.extraEnv }}
{{- toYaml .Values.kerberoshub.extraEnv | nindent 12 }}
{{- end }}
{{- end }}

View File

@@ -0,0 +1,81 @@
{{- if and (or (eq .Values.mode "all") (eq .Values.mode "ui")) .Values.kerberoshub.oauth2Proxy.enabled -}}
apiVersion: apps/v1
kind: Deployment
metadata:
name: oauth2-proxy
namespace: kube-system
labels:
k8s-app: oauth2-proxy
spec:
replicas: 1
selector:
matchLabels:
k8s-app: oauth2-proxy
template:
metadata:
labels:
k8s-app: oauth2-proxy
spec:
{{- with .Values.kerberoshub.oauth2Proxy.volumes }}
volumes:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- with .Values.kerberoshub.oauth2Proxy.topologySpreadConstraints }}
topologySpreadConstraints:
{{- toYaml . | nindent 8 }}
{{- end }}
containers:
- args:
- --provider=github
- --email-domain=*
- --upstream=file:///dev/null
- --http-address=0.0.0.0:4180
- --skip-auth-preflight=true
{{- with .Values.kerberoshub.oauth2Proxy.volumeMounts }}
volumeMounts:
{{- toYaml . | nindent 12 }}
{{- end }}
env:
- name: OAUTH2_PROXY_CLIENT_ID
value: "{{ .Values.kerberoshub.oauth2Proxy.github.clientId }}"
- name: OAUTH2_PROXY_CLIENT_SECRET
value: "{{ .Values.kerberoshub.oauth2Proxy.github.clientSecret }}"
- name: OAUTH2_PROXY_COOKIE_SECRET
value: "{{ .Values.kerberoshub.oauth2Proxy.github.cookieSecret }}"
- name: OAUTH2_PROXY_GITHUB_ORG
value: "{{ .Values.kerberoshub.oauth2Proxy.github.organization }}"
- name: OAUTH2_PROXY_GITHUB_TEAM
value: "{{ .Values.kerberoshub.oauth2Proxy.github.team }}"
{{- if .Values.kerberoshub.extraEnv }}
{{- toYaml .Values.kerberoshub.extraEnv | nindent 12 }}
{{- end }}
image: quay.io/oauth2-proxy/oauth2-proxy:latest
imagePullPolicy: Always
name: oauth2-proxy
ports:
- containerPort: 4180
protocol: TCP
resources:
limits:
cpu: 100m
memory: 50Mi
requests:
cpu: 100m
memory: 50Mi
---
apiVersion: v1
kind: Service
metadata:
labels:
k8s-app: oauth2-proxy
name: oauth2-proxy
namespace: kube-system
spec:
ports:
- name: http
port: 4180
protocol: TCP
targetPort: 4180
selector:
k8s-app: oauth2-proxy
{{- end -}}

View File

@@ -1,9 +1,11 @@
{{- if or (eq .Values.mode "all") (eq .Values.mode "ui") -}}
apiVersion: apps/v1
kind: Deployment
metadata:
name: hub-reactivate-subscription
namespace: {{ .Release.Namespace }}
spec:
replicas: 1
replicas: {{ .Values.kerberoshub.reactivate.replicas }}
selector:
matchLabels:
app: hub-reactivate-subscription
@@ -15,6 +17,8 @@ spec:
maxSurge: 1
template:
metadata:
annotations:
checksum/config: {{ include (print $.Template.BasePath "/configmap-mongodb.yaml") . | sha256sum }}
labels:
app: hub-reactivate-subscription
spec:
@@ -22,24 +26,46 @@ spec:
imagePullSecrets:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- $mongodbTLS := .Values.mongodb.tls }}
{{- if or .Values.kerberoshub.reactivate.volumes (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
volumes:
{{- with .Values.kerberoshub.reactivate.volumes }}
{{- toYaml . | nindent 8 }}
{{- end }}
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
{{- include "hub.mongodb.tlsVolume" . | nindent 8 }}
{{- end }}
{{- end }}
{{- with .Values.kerberoshub.reactivate.topologySpreadConstraints }}
topologySpreadConstraints:
{{- toYaml . | nindent 8 }}
{{- end }}
containers:
- name: hub-reactivate-subscription
image: "{{ .Values.kerberoshub.reactivate.repository }}:{{ .Values.kerberoshub.reactivate.tag }}"
image: "{{ .Values.global.imageRegistry }}{{ .Values.kerberoshub.reactivate.repository }}:{{ .Values.kerberoshub.reactivate.tag }}"
imagePullPolicy: {{ .Values.kerberoshub.reactivate.pullPolicy }}
{{- if or .Values.kerberoshub.reactivate.volumeMounts (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
volumeMounts:
{{- with .Values.kerberoshub.reactivate.volumeMounts }}
{{- toYaml . | nindent 12 }}
{{- end }}
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
{{- include "hub.mongodb.tlsVolumeMount" . | nindent 12 }}
{{- end }}
{{- end }}
envFrom:
- configMapRef:
name: mongodb-config
env:
- name: LOG_LEVEL
value: "{{ .Values.kerberoshub.reactivate.logLevel }}"
- name: READ_ONLY
value: "{{ .Values.readonly }}"
- name: MONGODB_URI
value: "{{ .Values.mongodb.uri }}"
- name: MONGODB_HOST
value: "{{ .Values.mongodb.host }}"
- name: MONGODB_DATABASE_CREDENTIALS
value: "{{ .Values.mongodb.adminDatabase }}"
- name: MONGODB_USERNAME
value: "{{ .Values.mongodb.username }}"
- name: MONGODB_PASSWORD
value: "{{ .Values.mongodb.password }}"
- name: AWS_ACCESS_KEY_ID
value: "{{ .Values.kerberoshub.api.aws.accessKey }}"
- name: AWS_SECRET_ACCESS_KEY
value: "{{ .Values.kerberoshub.api.aws.secretKey }}"
{{- if .Values.kerberoshub.extraEnv }}
{{- toYaml .Values.kerberoshub.extraEnv | nindent 12 }}
{{- end }}
{{- end }}

View File

@@ -0,0 +1,13 @@
{{- if and (or (eq .Values.mode "all") (eq .Values.mode "ui") (eq .Values.mode "pipeline")) .Values.kerberoshub.serviceAccount.create }}
apiVersion: v1
kind: ServiceAccount
metadata:
name: {{ default (printf "%s-%s-sa" .Release.Name .Chart.Name | trunc 63 | trimSuffix "-") .Values.kerberoshub.serviceAccount.name }}
namespace: {{ .Release.Namespace }}
annotations:
{{- toYaml .Values.kerberoshub.serviceAccount.annotations | nindent 4 }}
{{- with .Values.kerberoshub.serviceAccount.labels }}
labels:
{{- toYaml . | nindent 4 }}
{{- end }}
{{- end }}

View File

@@ -0,0 +1,67 @@
{{/*
Assemble the deployment-global workflow definitions (WORKFLOW_DEFINITIONS) as a
JSON array from every *enabled* workflow under kerberoshub.workflows.definitions.
This is the engine's boot-loaded configuration source and deployment stage
catalog: several distinct config workflows can run over one recording — each
opens its own run and dispatches only its own stages. Organisation-scoped
database workflows are discovered separately at runtime.
Each enabled definition contributes one workflow object:
name the map key (the workflow's human-readable name; also its identity
the engine derives a stable id from it when the definition carries
no explicit id).
enabled always true here (a disabled definition is skipped entirely).
source "config" provenance marking a Helm-defined, deployment-global,
ops-managed workflow (read-only in the API, no owning organisation).
triggers how a run OPENS. Defaults to a single bare automatic trigger
(opens for every recording); narrow with device/schedule triggers.
Per-stage `needs` (below) decide which stages then FIRE.
stages the executable stage set, each contributing the same routing
descriptor the stageRegistry emits:
operation the stage's operation (unique within the workflow).
dispatch "always" (default) | "conditional".
queue from the matching services.<operation>.queue
(authoritative; omitted when unset so the engine
derives "kcloud-<operation>-queue.fifo").
needs conditional stages only: upstream dependencies, each
{operation?, condition?}, carried through verbatim.
needsMode conditional stages: "any" (default) | "all".
*/}}
{{- define "kerberoshub.workflows.workflowDefinitions" -}}
{{- $defs := list -}}
{{- $services := .Values.kerberoshub.services | default dict -}}
{{- range $name, $wf := .Values.kerberoshub.workflows.definitions -}}
{{- if $wf.enabled -}}
{{- $stages := list -}}
{{- range $stage := $wf.stages -}}
{{- $op := $stage.operation -}}
{{- $entry := dict "operation" $op "dispatch" (default "always" $stage.dispatch) -}}
{{- $service := index $services $op -}}
{{- if $service }}{{- with $service.queue }}{{- $_ := set $entry "queue" . -}}{{- end }}{{- end }}
{{- with $stage.needs }}{{- $_ := set $entry "needs" . -}}{{- end }}
{{- with $stage.needsMode }}{{- $_ := set $entry "needsMode" . -}}{{- end }}
{{- $stages = append $stages $entry -}}
{{- end -}}
{{- $def := dict "name" $name "enabled" true "source" "config" "triggers" (default (list (dict "type" "automatic")) $wf.triggers) "stages" $stages -}}
{{- $defs = append $defs $def -}}
{{- end -}}
{{- end -}}
{{- $defs | toJson -}}
{{- end -}}
{{/*
Expose the deployment's operationqueue catalog to API producers that seed
embedded WorkflowRuns. Unlike WORKFLOW_DEFINITIONS this includes services that
are enabled for internal flows but are absent from user-visible workflow
definitions. The workflows engine remains authoritative for dispatch; producers
use this only to embed the same queue on a synthetic stage.
*/}}
{{- define "kerberoshub.workflows.stageQueues" -}}
{{- $queues := dict -}}
{{- range $operation, $service := (.Values.kerberoshub.services | default dict) -}}
{{- with $service.queue -}}
{{- $_ := set $queues $operation . -}}
{{- end -}}
{{- end -}}
{{- $queues | toJson -}}
{{- end -}}

View File

@@ -0,0 +1,145 @@
{{- /*
Generic workflow-stage worker.
Renders a Deployment + Service for every enabled worker under
kerberoshub.services.<name> other than the `workflows` engine itself. A custom
stage joins the pipeline by values alone — declare its worker here and route to
it from a kerberoshub.workflows.definitions stage of the same operation; no
per-stage template is needed.
Every stage worker receives the same connection contract; the only value that
varies by stage is the consume-queue variable name, <NAME>_QUEUE (a worker
named "loitering" gets LOITERING_QUEUE, "my-stage" gets MY_STAGE_QUEUE). To run
a worker outside the chart instead, leave services.<name>.enabled unset (or
false) and point its workflow stage at the queue you publish.
All stages receive the Vault read credentials (KERBEROS_STORAGE_URI /
ACCESS_KEY / SECRET). A stage that also writes an artefact back to Vault (e.g.
redaction) declares its destination provider with the named field
services.<name>.storageProvider, rendered as KERBEROS_STORAGE_PROVIDER; a
read-only stage omits it and gets no provider env.
*/ -}}
{{- if and (or (eq .Values.mode "all") (eq .Values.mode "pipeline")) .Values.kerberoshub.workflows.enabled -}}
{{- $root := . -}}
{{- $services := .Values.kerberoshub.services | default dict -}}
{{- range $name, $svc := $services -}}
{{- if and (ne $name "workflows") $svc $svc.enabled -}}
{{- $queueEnv := printf "%s_QUEUE" ($name | upper | replace "-" "_") -}}
---
apiVersion: apps/v1
kind: Deployment
metadata:
name: hub-{{ $name }}
namespace: {{ $root.Release.Namespace }}
spec:
replicas: {{ $svc.replicas | default 1 }}
selector:
matchLabels:
app: hub-{{ $name }}
minReadySeconds: 10
strategy:
type: RollingUpdate
rollingUpdate:
maxUnavailable: 1
maxSurge: 1
template:
metadata:
labels:
app: hub-{{ $name }}
spec:
{{- if $root.Values.kerberoshub.serviceAccount.create }}
serviceAccountName: {{ default (printf "%s-%s-sa" $root.Release.Name $root.Chart.Name | trunc 63 | trimSuffix "-") $root.Values.kerberoshub.serviceAccount.name }}
{{- end }}
{{- with $root.Values.imagePullSecrets }}
imagePullSecrets:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- with $svc.volumes }}
volumes:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- with $svc.topologySpreadConstraints }}
topologySpreadConstraints:
{{- toYaml . | nindent 8 }}
{{- end }}
containers:
- name: hub-{{ $name }}
image: "{{ $root.Values.global.imageRegistry }}{{ $svc.repository }}:{{ $svc.tag }}"
imagePullPolicy: {{ $svc.pullPolicy | default "IfNotPresent" }}
{{- with $svc.resources }}
resources:
{{- toYaml . | nindent 12 }}
{{- end }}
{{- with $svc.volumeMounts }}
volumeMounts:
{{- toYaml . | nindent 12 }}
{{- end }}
env:
- name: LOG_LEVEL
value: "{{ $svc.logLevel | default "info" }}"
- name: QUEUE_SYSTEM
value: "{{ $root.Values.queueProvider }}"
# The queue this stage worker consumes dispatched "{{ $name }}" stages
# from ({{ $queueEnv }}) and the workflows engine queue it routes its
# result back to (WORKFLOWS_QUEUE, so the run records the resolution and
# any stage that needs "{{ $name }}" can fire).
- name: {{ $queueEnv }}
value: "{{ $svc.queue }}"
- name: WORKFLOWS_QUEUE
value: "{{ $root.Values.kerberoshub.services.workflows.queue }}"
# RabbitMQ settings
- name: RABBITMQ_HOST
value: "{{ $root.Values.rabbitmq.host }}"
- name: RABBITMQ_EXCHANGE
value: "{{ $root.Values.rabbitmq.exchange }}"
- name: RABBITMQ_USERNAME
value: "{{ $root.Values.rabbitmq.username }}"
- name: RABBITMQ_PASSWORD
value: "{{ $root.Values.rabbitmq.password }}"
# Kerberos Vault — global storage credentials this stage uses to fetch
# the media it operates on.
- name: KERBEROS_STORAGE_URI
value: "{{ $root.Values.kerberosvault.uri }}"
- name: KERBEROS_STORAGE_ACCESS_KEY
value: "{{ $root.Values.kerberosvault.accesskey }}"
- name: KERBEROS_STORAGE_SECRET
value: "{{ $root.Values.kerberosvault.secretkey }}"
{{- with $svc.storageProvider }}
# Destination Vault provider (KERBEROS_STORAGE_PROVIDER) — only stages
# that write an artefact back (e.g. redaction) set services.<name>.
# storageProvider; read-only stages omit it and get no provider env.
- name: KERBEROS_STORAGE_PROVIDER
value: {{ . | quote }}
{{- end }}
# Per-stage tuning knobs. Any key/value under services.<name>.env is
# rendered verbatim as container env, so a worker can be tuned from
# values without a per-stage template. These override the image's own
# ENV defaults; the fixed contract env above is not overridable here.
{{- range $key, $value := $svc.env }}
- name: {{ $key }}
value: {{ $value | quote }}
{{- end }}
---
apiVersion: v1
kind: Service
metadata:
name: hub-{{ $name }}
namespace: {{ $root.Release.Namespace }}
labels:
app: hub-{{ $name }}
service: pipe
spec:
ports:
- name: hub-metrics
port: 8080
targetPort: 8080
protocol: TCP
selector:
app: hub-{{ $name }}
{{ end -}}
{{- end }}
{{- end }}

View File

@@ -0,0 +1,131 @@
{{- if and (or (eq .Values.mode "all") (eq .Values.mode "pipeline")) .Values.kerberoshub.workflows.enabled -}}
apiVersion: apps/v1
kind: Deployment
metadata:
name: hub-workflows
namespace: {{ .Release.Namespace }}
spec:
replicas: {{ .Values.kerberoshub.services.workflows.replicas }}
selector:
matchLabels:
app: hub-workflows
minReadySeconds: 10
strategy:
type: RollingUpdate
rollingUpdate:
maxUnavailable: 1
maxSurge: 1
template:
metadata:
annotations:
checksum/config: {{ include (print $.Template.BasePath "/configmap-mongodb.yaml") . | sha256sum }}
labels:
app: hub-workflows
spec:
{{- if .Values.kerberoshub.serviceAccount.create }}
serviceAccountName: {{ default (printf "%s-%s-sa" .Release.Name .Chart.Name | trunc 63 | trimSuffix "-") .Values.kerberoshub.serviceAccount.name }}
{{- end }}
{{- with .Values.imagePullSecrets }}
imagePullSecrets:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- $mongodbTLS := .Values.mongodb.tls }}
{{- if or .Values.kerberoshub.services.workflows.volumes (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
volumes:
{{- with .Values.kerberoshub.services.workflows.volumes }}
{{- toYaml . | nindent 8 }}
{{- end }}
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
{{- include "hub.mongodb.tlsVolume" . | nindent 8 }}
{{- end }}
{{- end }}
{{- with .Values.kerberoshub.services.workflows.topologySpreadConstraints }}
topologySpreadConstraints:
{{- toYaml . | nindent 8 }}
{{- end }}
containers:
- name: hub-workflows
image: "{{ .Values.global.imageRegistry }}{{ .Values.kerberoshub.services.workflows.repository }}:{{ .Values.kerberoshub.services.workflows.tag }}"
imagePullPolicy: {{ .Values.kerberoshub.services.workflows.pullPolicy }}
{{- with .Values.kerberoshub.services.workflows.resources }}
resources:
{{- toYaml . | nindent 12 }}
{{- end }}
{{- if or .Values.kerberoshub.services.workflows.volumeMounts (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
volumeMounts:
{{- with .Values.kerberoshub.services.workflows.volumeMounts }}
{{- toYaml . | nindent 12 }}
{{- end }}
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
{{- include "hub.mongodb.tlsVolumeMount" . | nindent 12 }}
{{- end }}
{{- end }}
envFrom:
- configMapRef:
name: mongodb-config
env:
- name: LOG_LEVEL
value: "{{ .Values.kerberoshub.services.workflows.logLevel }}"
- name: QUEUE_SYSTEM
value: "{{ .Values.queueProvider }}"
# Queue this service consumes from (WORKFLOWS_QUEUE) and the set of
# named workflows it runs (WORKFLOW_DEFINITIONS): each with its own
# trigger and executable stages, assembled from the enabled definitions
# under kerberoshub.workflows.definitions (see _workflows-helpers.tpl).
# Definitions are the engine's boot-loaded config source and deployment
# stage catalog. Organisation-scoped database workflows are read per
# recording; an in-cluster engine still requires at least one config
# definition so an empty catalog cannot silently drop traffic.
- name: WORKFLOWS_QUEUE
value: "{{ .Values.kerberoshub.services.workflows.queue }}"
- name: WORKFLOW_DEFINITIONS
value: {{ include "kerberoshub.workflows.workflowDefinitions" . | quote }}
# RabbitMQ settings
- name: RABBITMQ_HOST
value: "{{ .Values.rabbitmq.host }}"
- name: RABBITMQ_EXCHANGE
value: "{{ .Values.rabbitmq.exchange }}"
- name: RABBITMQ_USERNAME
value: "{{ .Values.rabbitmq.username }}"
- name: RABBITMQ_PASSWORD
value: "{{ .Values.rabbitmq.password }}"
# Kerberos Vault — global storage credentials a dispatched stage worker
# uses to fetch the media. Per-recording vault overrides (site/account)
# are resolved at dispatch time from the database.
- name: KERBEROS_STORAGE_URI
value: "{{ .Values.kerberosvault.uri }}"
- name: KERBEROS_STORAGE_ACCESS_KEY
value: "{{ .Values.kerberosvault.accesskey }}"
- name: KERBEROS_STORAGE_SECRET
value: "{{ .Values.kerberosvault.secretkey }}"
{{- if .Values.opentelemetry.enabled }}
# Open Telemetry tracing
- name: OTEL_EXPORTED_OTLP_ENABLED
value: "{{ .Values.opentelemetry.enabled }}"
- name: OTEL_EXPORTED_OTLP_ROUTING_ENABLED
value: "{{ .Values.opentelemetry.routingEnabled }}"
- name: OTEL_EXPORTER_OTLP_ENDPOINT
value: "{{ .Values.opentelemetry.collector.endpoint }}"
{{- end }}
---
apiVersion: v1
kind: Service
metadata:
name: hub-workflows
namespace: {{ .Release.Namespace }}
labels:
app: hub-workflows
service: pipe
spec:
ports:
- name: hub-metrics
port: 8080
targetPort: 8080
protocol: TCP
selector:
app: hub-workflows
{{- end }}

View File

@@ -1,7 +1,9 @@
{{- if or (eq .Values.mode "all") (eq .Values.mode "pipeline") -}}
apiVersion: apps/v1
kind: Deployment
metadata:
name: pipe-analysis
namespace: {{ .Release.Namespace }}
spec:
replicas: {{ .Values.kerberospipeline.analysis.replicas }}
selector:
@@ -15,39 +17,60 @@ spec:
maxSurge: 1
template:
metadata:
annotations:
checksum/config: {{ include (print $.Template.BasePath "/configmap-mongodb.yaml") . | sha256sum }}
labels:
app: pipe-analysis
spec:
{{- if .Values.kerberoshub.serviceAccount.create }}
serviceAccountName: {{ default (printf "%s-%s-sa" .Release.Name .Chart.Name | trunc 63 | trimSuffix "-") .Values.kerberoshub.serviceAccount.name }}
{{- end }}
{{- with .Values.imagePullSecrets }}
imagePullSecrets:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- $mongodbTLS := .Values.mongodb.tls }}
{{- if or .Values.kerberospipeline.analysis.volumes (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
volumes:
{{- with .Values.kerberospipeline.analysis.volumes }}
{{- toYaml . | nindent 8 }}
{{- end }}
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
{{- include "hub.mongodb.tlsVolume" . | nindent 8 }}
{{- end }}
{{- end }}
{{- with .Values.kerberospipeline.analysis.topologySpreadConstraints }}
topologySpreadConstraints:
{{- toYaml . | nindent 8 }}
{{- end }}
containers:
- name: pipe-analysis
image: "{{ .Values.kerberospipeline.analysis.repository }}:{{ .Values.kerberospipeline.analysis.tag }}"
image: "{{ .Values.global.imageRegistry }}{{ .Values.kerberospipeline.analysis.repository }}:{{ .Values.kerberospipeline.analysis.tag }}"
imagePullPolicy: {{ .Values.kerberospipeline.analysis.pullPolicy }}
{{- with .Values.kerberospipeline.analysis.resources }}
resources:
{{- toYaml . | nindent 12 }}
{{- end }}
{{- if or .Values.kerberospipeline.analysis.volumeMounts (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
volumeMounts:
{{- with .Values.kerberospipeline.analysis.volumeMounts }}
{{- toYaml . | nindent 12 }}
{{- end }}
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
{{- include "hub.mongodb.tlsVolumeMount" . | nindent 12 }}
{{- end }}
{{- end }}
envFrom:
- configMapRef:
name: mongodb-config
env:
- name: LOG_LEVEL
value: "{{ .Values.kerberospipeline.analysis.logLevel }}"
- name: CLOUD_PROVIDER
value: "{{ .Values.cloudProvider }}"
- name: QUEUE_SYSTEM
value: "{{ .Values.queueProvider }}"
# Database
- name: MONGODB_URI
value: "{{ .Values.mongodb.uri }}"
- name: MONGODB_HOST
value: "{{ .Values.mongodb.host }}"
- name: MONGODB_DATABASE_CREDENTIALS
value: "{{ .Values.mongodb.adminDatabase }}"
- name: MONGODB_USERNAME
value: "{{ .Values.mongodb.username }}"
- name: MONGODB_PASSWORD
value: "{{ .Values.mongodb.password }}"
# Kafka settings
- name: KAFKA_BROKER
value: "{{ .Values.kafka.broker }}"
@@ -69,6 +92,18 @@ spec:
value: "{{ .Values.rabbitmq.username }}"
- name: RABBITMQ_PASSWORD
value: "{{ .Values.rabbitmq.password }}"
# When true, analysis tees the classify result to the hub-workflows
# service in parallel with the throttler/notification tail (which still
# runs unchanged). Kept in sync with whether the workflows service runs.
- name: WORKFLOWS_ENABLED
value: "{{ .Values.kerberoshub.workflows.enabled }}"
# Queue analysis publishes opened workflow runs to (WORKFLOWS_QUEUE),
# taken from the workflows service's queue so analysis and the engine
# always agree on the queue name (no drift).
- name: WORKFLOWS_QUEUE
value: "{{ .Values.kerberoshub.services.workflows.queue }}"
# Kerberos Vault
- name: KERBEROS_STORAGE_URI
@@ -81,14 +116,25 @@ spec:
# Sprites
- name: SPRITE_ENABLED
value: "{{ .Values.kerberospipeline.sprite.enabled }}"
{{- if .Values.opentelemetry.enabled }}
# Open Telemetry tracing
- name: OTEL_EXPORTED_OTLP_ENABLED
value: "{{ .Values.opentelemetry.enabled }}"
- name: OTEL_EXPORTED_OTLP_ROUTING_ENABLED
value: "{{ .Values.opentelemetry.routingEnabled }}"
- name: OTEL_EXPORTER_OTLP_ENDPOINT
value: "{{ .Values.opentelemetry.collector.endpoint }}"
{{- end }}
---
apiVersion: v1
kind: Service
metadata:
name: pipe-analysis
namespace: {{ .Release.Namespace }}
labels:
app: pipe-analysis
service: pipe
name: pipe-analysis
spec:
ports:
- name: hub-metrics
@@ -96,4 +142,5 @@ spec:
targetPort: 8080
protocol: TCP
selector:
app: pipe-analysis
app: pipe-analysis
{{- end }}

View File

@@ -1,7 +1,9 @@
{{- if or (eq .Values.mode "all") (eq .Values.mode "pipeline") -}}
apiVersion: apps/v1
kind: Deployment
metadata:
name: pipe-counting
namespace: {{ .Release.Namespace }}
spec:
replicas: {{ .Values.kerberospipeline.counting.replicas }}
selector:
@@ -18,19 +20,36 @@ spec:
labels:
app: pipe-counting
spec:
{{- if .Values.kerberoshub.serviceAccount.create }}
serviceAccountName: {{ default (printf "%s-%s-sa" .Release.Name .Chart.Name | trunc 63 | trimSuffix "-") .Values.kerberoshub.serviceAccount.name }}
{{- end }}
{{- with .Values.imagePullSecrets }}
imagePullSecrets:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- with .Values.kerberospipeline.counting.volumes }}
volumes:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- with .Values.kerberospipeline.counting.topologySpreadConstraints }}
topologySpreadConstraints:
{{- toYaml . | nindent 8 }}
{{- end }}
containers:
- name: pipe-counting
image: "{{ .Values.kerberospipeline.counting.repository }}:{{ .Values.kerberospipeline.counting.tag }}"
image: "{{ .Values.global.imageRegistry }}{{ .Values.kerberospipeline.counting.repository }}:{{ .Values.kerberospipeline.counting.tag }}"
imagePullPolicy: {{ .Values.kerberospipeline.counting.pullPolicy }}
{{- with .Values.kerberospipeline.counting.resources }}
resources:
{{- toYaml . | nindent 12 }}
{{- end }}
{{- with .Values.kerberospipeline.counting.volumeMounts }}
volumeMounts:
{{- toYaml . | nindent 12 }}
{{- end }}
env:
- name: LOG_LEVEL
value: "{{ .Values.kerberospipeline.counting.logLevel }}"
- name: CLOUD_PROVIDER
value: "{{ .Values.cloudProvider }}"
- name: QUEUE_SYSTEM
@@ -57,14 +76,25 @@ spec:
value: "{{ .Values.rabbitmq.username }}"
- name: RABBITMQ_PASSWORD
value: "{{ .Values.rabbitmq.password }}"
{{- if .Values.opentelemetry.enabled }}
# Open Telemetry tracing
- name: OTEL_EXPORTED_OTLP_ENABLED
value: "{{ .Values.opentelemetry.enabled }}"
- name: OTEL_EXPORTED_OTLP_ROUTING_ENABLED
value: "{{ .Values.opentelemetry.routingEnabled }}"
- name: OTEL_EXPORTER_OTLP_ENDPOINT
value: "{{ .Values.opentelemetry.collector.endpoint }}"
{{- end }}
---
apiVersion: v1
kind: Service
metadata:
name: pipe-counting
namespace: {{ .Release.Namespace }}
labels:
app: pipe-counting
service: pipe
name: pipe-counting
spec:
ports:
- name: hub-metrics
@@ -72,4 +102,5 @@ spec:
targetPort: 8080
protocol: TCP
selector:
app: pipe-counting
app: pipe-counting
{{- end }}

View File

@@ -1,7 +1,9 @@
{{- if or (eq .Values.mode "all") (eq .Values.mode "pipeline") -}}
apiVersion: apps/v1
kind: Deployment
metadata:
name: pipe-dominantcolor
namespace: {{ .Release.Namespace }}
spec:
replicas: {{ .Values.kerberospipeline.dominantColor.replicas }}
selector:
@@ -18,19 +20,36 @@ spec:
labels:
app: pipe-dominantcolor
spec:
{{- if .Values.kerberoshub.serviceAccount.create }}
serviceAccountName: {{ default (printf "%s-%s-sa" .Release.Name .Chart.Name | trunc 63 | trimSuffix "-") .Values.kerberoshub.serviceAccount.name }}
{{- end }}
{{- with .Values.imagePullSecrets }}
imagePullSecrets:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- with .Values.kerberospipeline.dominantColor.volumes }}
volumes:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- with .Values.kerberospipeline.dominantColor.topologySpreadConstraints }}
topologySpreadConstraints:
{{- toYaml . | nindent 8 }}
{{- end }}
containers:
- name: pipe-dominantcolor
image: "{{ .Values.kerberospipeline.dominantColor.repository }}:{{ .Values.kerberospipeline.dominantColor.tag }}"
image: "{{ .Values.global.imageRegistry }}{{ .Values.kerberospipeline.dominantColor.repository }}:{{ .Values.kerberospipeline.dominantColor.tag }}"
imagePullPolicy: {{ .Values.kerberospipeline.dominantColor.pullPolicy }}
{{- with .Values.kerberospipeline.dominantColor.resources }}
resources:
{{- toYaml . | nindent 12 }}
{{- end }}
{{- with .Values.kerberospipeline.dominantColor.volumeMounts }}
volumeMounts:
{{- toYaml . | nindent 12 }}
{{- end }}
env:
- name: LOG_LEVEL
value: "{{ .Values.kerberospipeline.dominantColor.logLevel }}"
- name: CLOUD_PROVIDER
value: "{{ .Values.cloudProvider }}"
- name: QUEUE_SYSTEM
@@ -57,14 +76,25 @@ spec:
value: "{{ .Values.rabbitmq.username }}"
- name: RABBITMQ_PASSWORD
value: "{{ .Values.rabbitmq.password }}"
{{- if .Values.opentelemetry.enabled }}
# Open Telemetry tracing
- name: OTEL_EXPORTED_OTLP_ENABLED
value: "{{ .Values.opentelemetry.enabled }}"
- name: OTEL_EXPORTED_OTLP_ROUTING_ENABLED
value: "{{ .Values.opentelemetry.routingEnabled }}"
- name: OTEL_EXPORTER_OTLP_ENDPOINT
value: "{{ .Values.opentelemetry.collector.endpoint }}"
{{- end }}
---
apiVersion: v1
kind: Service
metadata:
name: pipe-dominantcolor
namespace: {{ .Release.Namespace }}
labels:
app: pipe-dominantcolor
service: pipe
name: pipe-dominantcolor
spec:
ports:
- name: hub-metrics
@@ -72,4 +102,5 @@ spec:
targetPort: 8080
protocol: TCP
selector:
app: pipe-dominantcolor
app: pipe-dominantcolor
{{- end }}

View File

@@ -1,7 +1,9 @@
{{- if or (eq .Values.mode "all") (eq .Values.mode "pipeline") -}}
apiVersion: apps/v1
kind: Deployment
metadata:
name: pipe-event
namespace: {{ .Release.Namespace }}
spec:
replicas: {{ .Values.kerberospipeline.event.replicas }}
selector:
@@ -15,24 +17,57 @@ spec:
maxSurge: 1
template:
metadata:
annotations:
checksum/config: {{ include (print $.Template.BasePath "/configmap-mongodb.yaml") . | sha256sum }}
labels:
app: pipe-event
spec:
{{- if .Values.kerberoshub.serviceAccount.create }}
serviceAccountName: {{ default (printf "%s-%s-sa" .Release.Name .Chart.Name | trunc 63 | trimSuffix "-") .Values.kerberoshub.serviceAccount.name }}
{{- end }}
{{- with .Values.imagePullSecrets }}
imagePullSecrets:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- $mongodbTLS := .Values.mongodb.tls }}
{{- if or .Values.kerberospipeline.event.volumes (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
volumes:
{{- with .Values.kerberospipeline.event.volumes }}
{{- toYaml . | nindent 8 }}
{{- end }}
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
{{- include "hub.mongodb.tlsVolume" . | nindent 8 }}
{{- end }}
{{- end }}
{{- with .Values.kerberospipeline.event.topologySpreadConstraints }}
topologySpreadConstraints:
{{- toYaml . | nindent 8 }}
{{- end }}
containers:
- name: pipe-event
image: "{{ .Values.kerberospipeline.event.repository }}:{{ .Values.kerberospipeline.event.tag }}"
image: "{{ .Values.global.imageRegistry }}{{ .Values.kerberospipeline.event.repository }}:{{ .Values.kerberospipeline.event.tag }}"
imagePullPolicy: {{ .Values.kerberospipeline.event.pullPolicy }}
{{- with .Values.kerberospipeline.event.resources }}
resources:
{{- toYaml . | nindent 12 }}
{{- end }}
{{- if or .Values.kerberospipeline.event.volumeMounts (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
volumeMounts:
{{- with .Values.kerberospipeline.event.volumeMounts }}
{{- toYaml . | nindent 12 }}
{{- end }}
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
{{- include "hub.mongodb.tlsVolumeMount" . | nindent 12 }}
{{- end }}
{{- end }}
ports:
- containerPort: 8080
envFrom:
- configMapRef:
name: mongodb-config
env:
- name: LOG_LEVEL
value: "{{ .Values.kerberospipeline.event.logLevel }}"
- name: READ_ONLY
value: "{{ .Values.readonly }}"
- name: CLOUD_PROVIDER
@@ -40,18 +75,6 @@ spec:
- name: QUEUE_SYSTEM
value: "{{ .Values.queueProvider }}"
# Database
- name: MONGODB_URI
value: "{{ .Values.mongodb.uri }}"
- name: MONGODB_HOST
value: "{{ .Values.mongodb.host }}"
- name: MONGODB_DATABASE_CREDENTIALS
value: "{{ .Values.mongodb.adminDatabase }}"
- name: MONGODB_USERNAME
value: "{{ .Values.mongodb.username }}"
- name: MONGODB_PASSWORD
value: "{{ .Values.mongodb.password }}"
# Kafka settings
- name: KAFKA_BROKER
value: "{{ .Values.kafka.broker }}"
@@ -73,14 +96,25 @@ spec:
value: "{{ .Values.rabbitmq.username }}"
- name: RABBITMQ_PASSWORD
value: "{{ .Values.rabbitmq.password }}"
{{- if .Values.opentelemetry.enabled }}
# Open Telemetry tracing
- name: OTEL_EXPORTED_OTLP_ENABLED
value: "{{ .Values.opentelemetry.enabled }}"
- name: OTEL_EXPORTED_OTLP_ROUTING_ENABLED
value: "{{ .Values.opentelemetry.routingEnabled }}"
- name: OTEL_EXPORTER_OTLP_ENDPOINT
value: "{{ .Values.opentelemetry.collector.endpoint }}"
{{- end }}
---
apiVersion: v1
kind: Service
metadata:
name: pipe-event
namespace: {{ .Release.Namespace }}
labels:
app: pipe-event
service: pipe
name: pipe-event
spec:
ports:
- name: hub-metrics
@@ -89,3 +123,4 @@ spec:
protocol: TCP
selector:
app: pipe-event
{{- end }}

View File

@@ -1,7 +1,9 @@
{{- if or (eq .Values.mode "all") (eq .Values.mode "pipeline") -}}
apiVersion: apps/v1
kind: Deployment
metadata:
name: pipe-export
namespace: {{ .Release.Namespace }}
spec:
replicas: {{ .Values.kerberospipeline.export.replicas }}
selector:
@@ -15,41 +17,64 @@ spec:
maxSurge: 1
template:
metadata:
annotations:
checksum/config: {{ include (print $.Template.BasePath "/configmap-mongodb.yaml") . | sha256sum }}
labels:
app: pipe-export
spec:
{{- if .Values.kerberoshub.serviceAccount.create }}
serviceAccountName: {{ default (printf "%s-%s-sa" .Release.Name .Chart.Name | trunc 63 | trimSuffix "-") .Values.kerberoshub.serviceAccount.name }}
{{- end }}
{{- with .Values.imagePullSecrets }}
imagePullSecrets:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- $mongodbTLS := .Values.mongodb.tls }}
{{- if or .Values.kerberospipeline.export.volumes (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
volumes:
{{- with .Values.kerberospipeline.export.volumes }}
{{- toYaml . | nindent 8 }}
{{- end }}
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
{{- include "hub.mongodb.tlsVolume" . | nindent 8 }}
{{- end }}
{{- end }}
{{- with .Values.kerberospipeline.export.topologySpreadConstraints }}
topologySpreadConstraints:
{{- toYaml . | nindent 8 }}
{{- end }}
containers:
- name: pipe-export
image: "{{ .Values.kerberospipeline.export.repository }}:{{ .Values.kerberospipeline.export.tag }}"
image: "{{ .Values.global.imageRegistry }}{{ .Values.kerberospipeline.export.repository }}:{{ .Values.kerberospipeline.export.tag }}"
imagePullPolicy: {{ .Values.kerberospipeline.export.pullPolicy }}
{{- with .Values.kerberospipeline.export.resources }}
resources:
{{- toYaml . | nindent 12 }}
{{- end }}
{{- if or .Values.kerberospipeline.export.volumeMounts (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
volumeMounts:
{{- with .Values.kerberospipeline.export.volumeMounts }}
{{- toYaml . | nindent 12 }}
{{- end }}
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
{{- include "hub.mongodb.tlsVolumeMount" . | nindent 12 }}
{{- end }}
{{- end }}
envFrom:
- configMapRef:
name: mongodb-config
env:
- name: LOG_LEVEL
value: "{{ .Values.kerberospipeline.export.logLevel }}"
{{- if .Values.kerberospipeline.export.playerAssetsPath }}
- name: PLAYER_ASSETS_PATH
value: "{{ .Values.kerberospipeline.export.playerAssetsPath }}"
{{- end }}
- name: CLOUD_PROVIDER
value: "{{ .Values.cloudProvider }}"
- name: QUEUE_SYSTEM
value: "{{ .Values.queueProvider }}"
# Database
- name: MONGODB_DATABASE_CLOUD
value: "Kerberos"
- name: MONGODB_URI
value: "{{ .Values.mongodb.uri }}"
- name: MONGODB_HOST
value: "{{ .Values.mongodb.host }}"
- name: MONGODB_DATABASE_CREDENTIALS
value: "{{ .Values.mongodb.adminDatabase }}"
- name: MONGODB_USERNAME
value: "{{ .Values.mongodb.username }}"
- name: MONGODB_PASSWORD
value: "{{ .Values.mongodb.password }}"
# Kafka settings
- name: KAFKA_BROKER
value: "{{ .Values.kafka.broker }}"
@@ -107,14 +132,25 @@ spec:
value: "{{ .Values.kerberosvault.thumbnail.accessKey }}"
- name: VAULT_THUMBNAIL_SECRET_KEY
value: "{{ .Values.kerberosvault.thumbnail.secretKey }}"
{{- if .Values.opentelemetry.enabled }}
# Open Telemetry tracing
- name: OTEL_EXPORTED_OTLP_ENABLED
value: "{{ .Values.opentelemetry.enabled }}"
- name: OTEL_EXPORTED_OTLP_ROUTING_ENABLED
value: "{{ .Values.opentelemetry.routingEnabled }}"
- name: OTEL_EXPORTER_OTLP_ENDPOINT
value: "{{ .Values.opentelemetry.collector.endpoint }}"
{{- end }}
---
apiVersion: v1
kind: Service
metadata:
name: pipe-export
namespace: {{ .Release.Namespace }}
labels:
app: pipe-export
service: pipe
name: pipe-export
spec:
ports:
- name: hub-metrics
@@ -122,4 +158,5 @@ spec:
targetPort: 8080
protocol: TCP
selector:
app: pipe-export
app: pipe-export
{{- end }}

View File

@@ -1,7 +1,9 @@
{{- if or (eq .Values.mode "all") (eq .Values.mode "pipeline") -}}
apiVersion: apps/v1
kind: Deployment
metadata:
name: pipe-monitor
namespace: {{ .Release.Namespace }}
spec:
replicas: {{ .Values.kerberospipeline.monitor.replicas }}
selector:
@@ -15,34 +17,53 @@ spec:
maxSurge: 1
template:
metadata:
annotations:
checksum/config: {{ include (print $.Template.BasePath "/configmap-mongodb.yaml") . | sha256sum }}
labels:
app: pipe-monitor
spec:
{{- if .Values.kerberoshub.serviceAccount.create }}
serviceAccountName: {{ default (printf "%s-%s-sa" .Release.Name .Chart.Name | trunc 63 | trimSuffix "-") .Values.kerberoshub.serviceAccount.name }}
{{- end }}
{{- with .Values.imagePullSecrets }}
imagePullSecrets:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- $mongodbTLS := .Values.mongodb.tls }}
{{- if or .Values.kerberospipeline.monitor.volumes (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
volumes:
{{- with .Values.kerberospipeline.monitor.volumes }}
{{- toYaml . | nindent 8 }}
{{- end }}
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
{{- include "hub.mongodb.tlsVolume" . | nindent 8 }}
{{- end }}
{{- end }}
{{- with .Values.kerberospipeline.monitor.topologySpreadConstraints }}
topologySpreadConstraints:
{{- toYaml . | nindent 8 }}
{{- end }}
containers:
- name: pipe-monitor
image: "{{ .Values.kerberospipeline.monitor.repository }}:{{ .Values.kerberospipeline.monitor.tag }}"
image: "{{ .Values.global.imageRegistry }}{{ .Values.kerberospipeline.monitor.repository }}:{{ .Values.kerberospipeline.monitor.tag }}"
imagePullPolicy: {{ .Values.kerberospipeline.monitor.pullPolicy }}
{{- with .Values.kerberospipeline.monitor.resources }}
resources:
{{- toYaml . | nindent 12 }}
{{- end }}
{{- if or .Values.kerberospipeline.monitor.volumeMounts (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
volumeMounts:
{{- with .Values.kerberospipeline.monitor.volumeMounts }}
{{- toYaml . | nindent 12 }}
{{- end }}
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
{{- include "hub.mongodb.tlsVolumeMount" . | nindent 12 }}
{{- end }}
{{- end }}
envFrom:
- configMapRef:
name: mongodb-config
env:
# Database
- name: MONGODB_URI
value: "{{ .Values.mongodb.uri }}"
- name: MONGODB_HOST
value: "{{ .Values.mongodb.host }}"
- name: MONGODB_DATABASE_CREDENTIALS
value: "{{ .Values.mongodb.adminDatabase }}"
- name: MONGODB_USERNAME
value: "{{ .Values.mongodb.username }}"
- name: MONGODB_PASSWORD
value: "{{ .Values.mongodb.password }}"
# Queue
- name: QUEUE_SYSTEM
value: "{{ .Values.queueProvider }}"
@@ -92,14 +113,25 @@ spec:
value: "{{ .Values.email.smtp.username }}"
- name: SMTP_PASSWORD
value: "{{ .Values.email.smtp.password }}"
{{- if .Values.opentelemetry.enabled }}
# Open Telemetry tracing
- name: OTEL_EXPORTED_OTLP_ENABLED
value: "{{ .Values.opentelemetry.enabled }}"
- name: OTEL_EXPORTED_OTLP_ROUTING_ENABLED
value: "{{ .Values.opentelemetry.routingEnabled }}"
- name: OTEL_EXPORTER_OTLP_ENDPOINT
value: "{{ .Values.opentelemetry.collector.endpoint }}"
{{- end }}
---
apiVersion: v1
kind: Service
metadata:
name: pipe-monitor
namespace: {{ .Release.Namespace }}
labels:
app: pipe-monitor
service: pipe
name: pipe-monitor
spec:
ports:
- name: hub-metrics
@@ -107,4 +139,5 @@ spec:
targetPort: 8080
protocol: TCP
selector:
app: pipe-monitor
app: pipe-monitor
{{- end }}

View File

@@ -1,7 +1,9 @@
{{- if or (eq .Values.mode "all") (eq .Values.mode "pipeline") -}}
apiVersion: apps/v1
kind: Deployment
metadata:
name: pipe-notify-test
namespace: {{ .Release.Namespace }}
spec:
replicas: {{ .Values.kerberospipeline.notifyTest.replicas }}
selector:
@@ -15,45 +17,56 @@ spec:
maxSurge: 1
template:
metadata:
annotations:
checksum/config: {{ include (print $.Template.BasePath "/configmap-mongodb.yaml") . | sha256sum }}
labels:
app: pipe-notify-test
spec:
{{- if .Values.kerberoshub.serviceAccount.create }}
serviceAccountName: {{ default (printf "%s-%s-sa" .Release.Name .Chart.Name | trunc 63 | trimSuffix "-") .Values.kerberoshub.serviceAccount.name }}
{{- end }}
{{- with .Values.imagePullSecrets }}
imagePullSecrets:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- with .Values.kerberospipeline.notifyTest.volumes }}
{{- $mongodbTLS := .Values.mongodb.tls }}
{{- if or .Values.kerberospipeline.notifyTest.volumes (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
volumes:
{{- with .Values.kerberospipeline.notifyTest.volumes }}
{{- toYaml . | nindent 8 }}
{{- end }}
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
{{- include "hub.mongodb.tlsVolume" . | nindent 8 }}
{{- end }}
{{- end }}
{{- with .Values.kerberospipeline.notifyTest.topologySpreadConstraints }}
topologySpreadConstraints:
{{- toYaml . | nindent 8 }}
{{- end }}
containers:
- name: pipe-notify-test
image: "{{ .Values.kerberospipeline.notifyTest.repository }}:{{ .Values.kerberospipeline.notifyTest.tag }}"
image: "{{ .Values.global.imageRegistry }}{{ .Values.kerberospipeline.notifyTest.repository }}:{{ .Values.kerberospipeline.notifyTest.tag }}"
imagePullPolicy: {{ .Values.kerberospipeline.notifyTest.pullPolicy }}
{{- with .Values.kerberospipeline.notifyTest.resources }}
resources:
{{- toYaml . | nindent 12 }}
{{- end }}
{{- with .Values.kerberospipeline.notifyTest.volumeMounts}}
{{- if or .Values.kerberospipeline.notifyTest.volumeMounts (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
volumeMounts:
{{- with .Values.kerberospipeline.notifyTest.volumeMounts}}
{{- toYaml . | nindent 12 }}
{{- end }}
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
{{- include "hub.mongodb.tlsVolumeMount" . | nindent 12 }}
{{- end }}
{{- end }}
envFrom:
- configMapRef:
name: mongodb-config
env:
- name: QUEUE_SYSTEM
value: "{{ .Values.queueProvider }}"
# Database
- name: MONGODB_URI
value: "{{ .Values.mongodb.uri }}"
- name: MONGODB_HOST
value: "{{ .Values.mongodb.host }}"
- name: MONGODB_DATABASE_CREDENTIALS
value: "{{ .Values.mongodb.adminDatabase }}"
- name: MONGODB_USERNAME
value: "{{ .Values.mongodb.username }}"
- name: MONGODB_PASSWORD
value: "{{ .Values.mongodb.password }}"
# Kerberos Vault
- name: STORAGE_URI
value: "{{ .Values.kerberosvault.uri }}"
@@ -91,6 +104,8 @@ spec:
value: "{{ .Values.email.from }}"
- name: EMAIL_FROM_DISPLAYNAME
value: "{{ .Values.email.displayName }}"
- name: PUBLIC_URL
value: "{{ .Values.kerberoshub.frontend.schema }}://{{ .Values.kerberoshub.frontend.url }}"
# Mail templates
- name: DETECT_TEMPLATE
@@ -105,14 +120,25 @@ spec:
value: "{{ .Values.email.smtp.username }}"
- name: SMTP_PASSWORD
value: "{{ .Values.email.smtp.password }}"
{{- if .Values.opentelemetry.enabled }}
# Open Telemetry tracing
- name: OTEL_EXPORTED_OTLP_ENABLED
value: "{{ .Values.opentelemetry.enabled }}"
- name: OTEL_EXPORTED_OTLP_ROUTING_ENABLED
value: "{{ .Values.opentelemetry.routingEnabled }}"
- name: OTEL_EXPORTER_OTLP_ENDPOINT
value: "{{ .Values.opentelemetry.collector.endpoint }}"
{{- end }}
---
apiVersion: v1
kind: Service
metadata:
name: pipe-notify-test
namespace: {{ .Release.Namespace }}
labels:
app: pipe-notify-test
service: pipe
name: pipe-notify-test
spec:
ports:
- name: hub-metrics
@@ -120,4 +146,5 @@ spec:
targetPort: 8080
protocol: TCP
selector:
app: pipe-notify-test
app: pipe-notify-test
{{- end }}

View File

@@ -1,7 +1,9 @@
{{- if or (eq .Values.mode "all") (eq .Values.mode "pipeline") -}}
apiVersion: apps/v1
kind: Deployment
metadata:
name: pipe-notify
namespace: {{ .Release.Namespace }}
spec:
replicas: {{ .Values.kerberospipeline.notify.replicas }}
selector:
@@ -15,42 +17,55 @@ spec:
maxSurge: 1
template:
metadata:
annotations:
checksum/config: {{ include (print $.Template.BasePath "/configmap-mongodb.yaml") . | sha256sum }}
labels:
app: pipe-notify
spec:
{{- if .Values.kerberoshub.serviceAccount.create }}
serviceAccountName: {{ default (printf "%s-%s-sa" .Release.Name .Chart.Name | trunc 63 | trimSuffix "-") .Values.kerberoshub.serviceAccount.name }}
{{- end }}
{{- with .Values.imagePullSecrets }}
imagePullSecrets:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- with .Values.kerberospipeline.notify.volumes }}
{{- $mongodbTLS := .Values.mongodb.tls }}
{{- if or .Values.kerberospipeline.notify.volumes (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
volumes:
{{- with .Values.kerberospipeline.notify.volumes }}
{{- toYaml . | nindent 8 }}
{{- end }}
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
{{- include "hub.mongodb.tlsVolume" . | nindent 8 }}
{{- end }}
{{- end }}
{{- with .Values.kerberospipeline.notify.topologySpreadConstraints }}
topologySpreadConstraints:
{{- toYaml . | nindent 8 }}
{{- end }}
containers:
- name: pipe-notify
image: "{{ .Values.kerberospipeline.notify.repository }}:{{ .Values.kerberospipeline.notify.tag }}"
image: "{{ .Values.global.imageRegistry }}{{ .Values.kerberospipeline.notify.repository }}:{{ .Values.kerberospipeline.notify.tag }}"
imagePullPolicy: {{ .Values.kerberospipeline.notify.pullPolicy }}
{{- with .Values.kerberospipeline.notify.resources }}
resources:
{{- toYaml . | nindent 12 }}
{{- end }}
{{- with .Values.kerberospipeline.notify.volumeMounts}}
{{- if or .Values.kerberospipeline.notify.volumeMounts (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
volumeMounts:
{{- with .Values.kerberospipeline.notify.volumeMounts}}
{{- toYaml . | nindent 12 }}
{{- end }}
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
{{- include "hub.mongodb.tlsVolumeMount" . | nindent 12 }}
{{- end }}
{{- end }}
envFrom:
- configMapRef:
name: mongodb-config
env:
# Database
- name: MONGODB_URI
value: "{{ .Values.mongodb.uri }}"
- name: MONGODB_HOST
value: "{{ .Values.mongodb.host }}"
- name: MONGODB_DATABASE_CREDENTIALS
value: "{{ .Values.mongodb.adminDatabase }}"
- name: MONGODB_USERNAME
value: "{{ .Values.mongodb.username }}"
- name: MONGODB_PASSWORD
value: "{{ .Values.mongodb.password }}"
- name: LOG_LEVEL
value: "{{ .Values.kerberospipeline.notify.logLevel }}"
# Queue
- name: QUEUE_SYSTEM
value: "{{ .Values.queueProvider }}"
@@ -92,6 +107,8 @@ spec:
value: "{{ .Values.email.from }}"
- name: EMAIL_FROM_DISPLAYNAME
value: "{{ .Values.email.displayName }}"
- name: PUBLIC_URL
value: "{{ .Values.kerberoshub.frontend.schema }}://{{ .Values.kerberoshub.frontend.url }}"
# Mail templates
- name: DETECT_TEMPLATE
@@ -135,14 +152,25 @@ spec:
value: "{{ .Values.kerberosvault.sprite.accessKey }}"
- name: VAULT_SPRITE_SECRET_KEY
value: "{{ .Values.kerberosvault.sprite.secretKey }}"
{{- if .Values.opentelemetry.enabled }}
# Open Telemetry tracing
- name: OTEL_EXPORTED_OTLP_ENABLED
value: "{{ .Values.opentelemetry.enabled }}"
- name: OTEL_EXPORTED_OTLP_ROUTING_ENABLED
value: "{{ .Values.opentelemetry.routingEnabled }}"
- name: OTEL_EXPORTER_OTLP_ENDPOINT
value: "{{ .Values.opentelemetry.collector.endpoint }}"
{{- end }}
---
apiVersion: v1
kind: Service
metadata:
name: pipe-notify
namespace: {{ .Release.Namespace }}
labels:
app: pipe-notify
service: pipe
name: pipe-notify
spec:
ports:
- name: hub-metrics
@@ -150,4 +178,5 @@ spec:
targetPort: 8080
protocol: TCP
selector:
app: pipe-notify
app: pipe-notify
{{- end }}

View File

@@ -1,7 +1,9 @@
{{- if or (eq .Values.mode "all") (eq .Values.mode "pipeline") -}}
apiVersion: apps/v1
kind: Deployment
metadata:
name: pipe-sequence
namespace: {{ .Release.Namespace }}
spec:
replicas: {{ .Values.kerberospipeline.sequence.replicas }}
selector:
@@ -15,39 +17,58 @@ spec:
maxSurge: 1
template:
metadata:
annotations:
checksum/config: {{ include (print $.Template.BasePath "/configmap-mongodb.yaml") . | sha256sum }}
labels:
app: pipe-sequence
spec:
{{- if .Values.kerberoshub.serviceAccount.create }}
serviceAccountName: {{ default (printf "%s-%s-sa" .Release.Name .Chart.Name | trunc 63 | trimSuffix "-") .Values.kerberoshub.serviceAccount.name }}
{{- end }}
{{- with .Values.imagePullSecrets }}
imagePullSecrets:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- $mongodbTLS := .Values.mongodb.tls }}
{{- if or .Values.kerberospipeline.sequence.volumes (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
volumes:
{{- with .Values.kerberospipeline.sequence.volumes }}
{{- toYaml . | nindent 8 }}
{{- end }}
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
{{- include "hub.mongodb.tlsVolume" . | nindent 8 }}
{{- end }}
{{- end }}
{{- with .Values.kerberospipeline.sequence.topologySpreadConstraints }}
topologySpreadConstraints:
{{- toYaml . | nindent 8 }}
{{- end }}
containers:
- name: pipe-sequence
image: "{{ .Values.kerberospipeline.sequence.repository }}:{{ .Values.kerberospipeline.sequence.tag }}"
image: "{{ .Values.global.imageRegistry }}{{ .Values.kerberospipeline.sequence.repository }}:{{ .Values.kerberospipeline.sequence.tag }}"
imagePullPolicy: {{ .Values.kerberospipeline.sequence.pullPolicy }}
{{- with .Values.kerberospipeline.sequence.resources }}
resources:
{{- toYaml . | nindent 12 }}
{{- end }}
{{- if or .Values.kerberospipeline.sequence.volumeMounts (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
volumeMounts:
{{- with .Values.kerberospipeline.sequence.volumeMounts }}
{{- toYaml . | nindent 12 }}
{{- end }}
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
{{- include "hub.mongodb.tlsVolumeMount" . | nindent 12 }}
{{- end }}
{{- end }}
envFrom:
- configMapRef:
name: mongodb-config
env:
- name: CLOUD_PROVIDER
value: "{{ .Values.cloudProvider }}"
- name: QUEUE_SYSTEM
value: "{{ .Values.queueProvider }}"
# Database
- name: MONGODB_URI
value: "{{ .Values.mongodb.uri }}"
- name: MONGODB_HOST
value: "{{ .Values.mongodb.host }}"
- name: MONGODB_DATABASE_CREDENTIALS
value: "{{ .Values.mongodb.adminDatabase }}"
- name: MONGODB_USERNAME
value: "{{ .Values.mongodb.username }}"
- name: MONGODB_PASSWORD
value: "{{ .Values.mongodb.password }}"
# Kafka settings
- name: KAFKA_BROKER
value: "{{ .Values.kafka.broker }}"
@@ -69,14 +90,25 @@ spec:
value: "{{ .Values.rabbitmq.username }}"
- name: RABBITMQ_PASSWORD
value: "{{ .Values.rabbitmq.password }}"
{{- if .Values.opentelemetry.enabled }}
# Open Telemetry tracing
- name: OTEL_EXPORTED_OTLP_ENABLED
value: "{{ .Values.opentelemetry.enabled }}"
- name: OTEL_EXPORTED_OTLP_ROUTING_ENABLED
value: "{{ .Values.opentelemetry.routingEnabled }}"
- name: OTEL_EXPORTER_OTLP_ENDPOINT
value: "{{ .Values.opentelemetry.collector.endpoint }}"
{{- end }}
---
apiVersion: v1
kind: Service
metadata:
name: pipe-sequence
namespace: {{ .Release.Namespace }}
labels:
app: pipe-sequence
service: pipe
name: pipe-sequence
spec:
ports:
- name: hub-metrics
@@ -84,4 +116,5 @@ spec:
targetPort: 8080
protocol: TCP
selector:
app: pipe-sequence
app: pipe-sequence
{{- end }}

View File

@@ -1,8 +1,9 @@
{{ if eq .Values.kerberospipeline.sprite.enabled true }}
{{- if and (or (eq .Values.mode "all") (eq .Values.mode "pipeline")) (eq .Values.kerberospipeline.sprite.enabled true) }}
apiVersion: apps/v1
kind: Deployment
metadata:
name: pipe-sprite
namespace: {{ .Release.Namespace }}
spec:
replicas: {{ .Values.kerberospipeline.sprite.replicas }}
selector:
@@ -19,19 +20,36 @@ spec:
labels:
app: pipe-sprite
spec:
{{- if .Values.kerberoshub.serviceAccount.create }}
serviceAccountName: {{ default (printf "%s-%s-sa" .Release.Name .Chart.Name | trunc 63 | trimSuffix "-") .Values.kerberoshub.serviceAccount.name }}
{{- end }}
{{- with .Values.imagePullSecrets }}
imagePullSecrets:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- with .Values.kerberospipeline.sprite.volumes }}
volumes:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- with .Values.kerberospipeline.sprite.topologySpreadConstraints }}
topologySpreadConstraints:
{{- toYaml . | nindent 8 }}
{{- end }}
containers:
- name: pipe-sprite
image: "{{ .Values.kerberospipeline.sprite.repository }}:{{ .Values.kerberospipeline.sprite.tag }}"
image: "{{ .Values.global.imageRegistry }}{{ .Values.kerberospipeline.sprite.repository }}:{{ .Values.kerberospipeline.sprite.tag }}"
imagePullPolicy: {{ .Values.kerberospipeline.sprite.pullPolicy }}
{{- with .Values.kerberospipeline.sprite.resources }}
resources:
{{- toYaml . | nindent 12 }}
{{- end }}
{{- with .Values.kerberospipeline.sprite.volumeMounts }}
volumeMounts:
{{- toYaml . | nindent 12 }}
{{- end }}
env:
- name: LOG_LEVEL
value: "{{ .Values.kerberospipeline.sprite.logLevel }}"
{{ if .Values.isPrivate }}
- name: KERBEROS_PRIVATE_CLOUD
value: "true"
@@ -81,14 +99,25 @@ spec:
value: "{{ .Values.kerberospipeline.sprite.width }}"
- name: VAULT_SPRITE_HEIGHT
value: "{{ .Values.kerberospipeline.sprite.height }}"
{{- if .Values.opentelemetry.enabled }}
# Open Telemetry tracing
- name: OTEL_EXPORTED_OTLP_ENABLED
value: "{{ .Values.opentelemetry.enabled }}"
- name: OTEL_EXPORTED_OTLP_ROUTING_ENABLED
value: "{{ .Values.opentelemetry.routingEnabled }}"
- name: OTEL_EXPORTER_OTLP_ENDPOINT
value: "{{ .Values.opentelemetry.collector.endpoint }}"
{{- end }}
---
apiVersion: v1
kind: Service
metadata:
name: pipe-sprite
namespace: {{ .Release.Namespace }}
labels:
app: pipe-sprite
service: pipe
name: pipe-sprite
spec:
ports:
- name: hub-metrics

View File

@@ -1,7 +1,9 @@
{{- if or (eq .Values.mode "all") (eq .Values.mode "pipeline") -}}
apiVersion: apps/v1
kind: Deployment
metadata:
name: pipe-throttler
namespace: {{ .Release.Namespace }}
spec:
replicas: {{ .Values.kerberospipeline.throttler.replicas }}
selector:
@@ -15,39 +17,60 @@ spec:
maxSurge: 1
template:
metadata:
annotations:
checksum/config: {{ include (print $.Template.BasePath "/configmap-mongodb.yaml") . | sha256sum }}
labels:
app: pipe-throttler
spec:
{{- if .Values.kerberoshub.serviceAccount.create }}
serviceAccountName: {{ default (printf "%s-%s-sa" .Release.Name .Chart.Name | trunc 63 | trimSuffix "-") .Values.kerberoshub.serviceAccount.name }}
{{- end }}
{{- with .Values.imagePullSecrets }}
imagePullSecrets:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- $mongodbTLS := .Values.mongodb.tls }}
{{- if or .Values.kerberospipeline.throttler.volumes (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
volumes:
{{- with .Values.kerberospipeline.throttler.volumes }}
{{- toYaml . | nindent 8 }}
{{- end }}
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
{{- include "hub.mongodb.tlsVolume" . | nindent 8 }}
{{- end }}
{{- end }}
{{- with .Values.kerberospipeline.throttler.topologySpreadConstraints }}
topologySpreadConstraints:
{{- toYaml . | nindent 8 }}
{{- end }}
containers:
- name: pipe-throttler
image: "{{ .Values.kerberospipeline.throttler.repository }}:{{ .Values.kerberospipeline.throttler.tag }}"
image: "{{ .Values.global.imageRegistry }}{{ .Values.kerberospipeline.throttler.repository }}:{{ .Values.kerberospipeline.throttler.tag }}"
imagePullPolicy: {{ .Values.kerberospipeline.throttler.pullPolicy }}
{{- with .Values.kerberospipeline.throttler.resources }}
resources:
{{- toYaml . | nindent 12 }}
{{- end }}
{{- if or .Values.kerberospipeline.throttler.volumeMounts (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
volumeMounts:
{{- with .Values.kerberospipeline.throttler.volumeMounts }}
{{- toYaml . | nindent 12 }}
{{- end }}
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
{{- include "hub.mongodb.tlsVolumeMount" . | nindent 12 }}
{{- end }}
{{- end }}
envFrom:
- configMapRef:
name: mongodb-config
env:
- name: LOG_LEVEL
value: "{{ .Values.kerberospipeline.throttler.logLevel }}"
- name: CLOUD_PROVIDER
value: "{{ .Values.cloudProvider }}"
- name: QUEUE_SYSTEM
value: "{{ .Values.queueProvider }}"
# Database
- name: MONGODB_URI
value: "{{ .Values.mongodb.uri }}"
- name: MONGODB_HOST
value: "{{ .Values.mongodb.host }}"
- name: MONGODB_DATABASE_CREDENTIALS
value: "{{ .Values.mongodb.adminDatabase }}"
- name: MONGODB_USERNAME
value: "{{ .Values.mongodb.username }}"
- name: MONGODB_PASSWORD
value: "{{ .Values.mongodb.password }}"
# Kafka settings
- name: KAFKA_BROKER
value: "{{ .Values.kafka.broker }}"
@@ -69,14 +92,25 @@ spec:
value: "{{ .Values.rabbitmq.username }}"
- name: RABBITMQ_PASSWORD
value: "{{ .Values.rabbitmq.password }}"
{{- if .Values.opentelemetry.enabled }}
# Open Telemetry tracing
- name: OTEL_EXPORTED_OTLP_ENABLED
value: "{{ .Values.opentelemetry.enabled }}"
- name: OTEL_EXPORTED_OTLP_ROUTING_ENABLED
value: "{{ .Values.opentelemetry.routingEnabled }}"
- name: OTEL_EXPORTER_OTLP_ENDPOINT
value: "{{ .Values.opentelemetry.collector.endpoint }}"
{{- end }}
---
apiVersion: v1
kind: Service
metadata:
name: pipe-throttler
namespace: {{ .Release.Namespace }}
labels:
app: pipe-throttler
service: pipe
name: pipe-throttler
spec:
ports:
- name: hub-metrics
@@ -84,4 +118,5 @@ spec:
targetPort: 8080
protocol: TCP
selector:
app: pipe-throttler
app: pipe-throttler
{{- end }}

View File

@@ -1,7 +1,9 @@
{{- if or (eq .Values.mode "all") (eq .Values.mode "pipeline") -}}
apiVersion: apps/v1
kind: Deployment
metadata:
name: pipe-thumbnail
namespace: {{ .Release.Namespace }}
spec:
replicas: {{ .Values.kerberospipeline.thumbnail.replicas }}
selector:
@@ -18,19 +20,36 @@ spec:
labels:
app: pipe-thumbnail
spec:
{{- if .Values.kerberoshub.serviceAccount.create }}
serviceAccountName: {{ default (printf "%s-%s-sa" .Release.Name .Chart.Name | trunc 63 | trimSuffix "-") .Values.kerberoshub.serviceAccount.name }}
{{- end }}
{{- with .Values.imagePullSecrets }}
imagePullSecrets:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- with .Values.kerberospipeline.thumbnail.volumes }}
volumes:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- with .Values.kerberospipeline.thumbnail.topologySpreadConstraints }}
topologySpreadConstraints:
{{- toYaml . | nindent 8 }}
{{- end }}
containers:
- name: pipe-thumbnail
image: "{{ .Values.kerberospipeline.thumbnail.repository }}:{{ .Values.kerberospipeline.thumbnail.tag }}"
image: "{{ .Values.global.imageRegistry }}{{ .Values.kerberospipeline.thumbnail.repository }}:{{ .Values.kerberospipeline.thumbnail.tag }}"
imagePullPolicy: {{ .Values.kerberospipeline.thumbnail.pullPolicy }}
{{- with .Values.kerberospipeline.thumbnail.resources }}
resources:
{{- toYaml . | nindent 12 }}
{{- end }}
{{- with .Values.kerberospipeline.thumbnail.volumeMounts }}
volumeMounts:
{{- toYaml . | nindent 12 }}
{{- end }}
env:
- name: LOG_LEVEL
value: "{{ .Values.kerberospipeline.thumbnail.logLevel }}"
{{ if .Values.isPrivate }}
- name: KERBEROS_PRIVATE_CLOUD
value: "true"
@@ -83,14 +102,26 @@ spec:
value: "{{ .Values.kerberosvault.thumbnail.accessKey }}"
- name: VAULT_THUMBNAIL_SECRET_KEY
value: "{{ .Values.kerberosvault.thumbnail.secretKey }}"
{{- if .Values.opentelemetry.enabled }}
# Open Telemetry tracing
- name: OTEL_EXPORTED_OTLP_ENABLED
value: "{{ .Values.opentelemetry.enabled }}"
- name: OTEL_EXPORTED_OTLP_ROUTING_ENABLED
value: "{{ .Values.opentelemetry.routingEnabled }}"
- name: OTEL_EXPORTER_OTLP_ENDPOINT
value: "{{ .Values.opentelemetry.collector.endpoint }}"
{{- end }}
---
apiVersion: v1
kind: Service
metadata:
name: pipe-thumbnail
namespace: {{ .Release.Namespace }}
labels:
app: pipe-thumbnail
service: pipe
name: pipe-thumbnail
spec:
ports:
- name: hub-metrics
@@ -98,4 +129,5 @@ spec:
targetPort: 8080
protocol: TCP
selector:
app: pipe-thumbnail
app: pipe-thumbnail
{{- end }}

View File

@@ -1,7 +1,9 @@
{{- if or (eq .Values.mode "all") (eq .Values.mode "pipeline") -}}
apiVersion: monitoring.coreos.com/v1
kind: ServiceMonitor
metadata:
name: hub-metrics-servicemonitor
namespace: {{ .Release.Namespace }}
labels:
service: pipe
release: prometheus
@@ -13,3 +15,4 @@ spec:
- port: hub-metrics
interval: 15s
path: /metrics
{{- end }}

View File

@@ -1,9 +1,10 @@
# If .Values.kerberoshub.forwarder.enabled is set to true
{{- if .Values.kerberoshub.forwarder.enabled }}
{{- if and (eq .Values.mode "all") .Values.kerberoshub.forwarder.enabled }}
apiVersion: apps/v1
kind: Deployment
metadata:
name: vault-forwarder
namespace: {{ .Release.Namespace }}
spec:
replicas: 1
selector:
@@ -17,6 +18,8 @@ spec:
maxSurge: 1
template:
metadata:
annotations:
checksum/config: {{ include (print $.Template.BasePath "/configmap-mongodb.yaml") . | sha256sum }}
labels:
app: vault-forwarder
spec:
@@ -24,38 +27,49 @@ spec:
imagePullSecrets:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- $mongodbTLS := .Values.mongodb.tls }}
{{- if or .Values.kerberoshub.forwarder.volumes (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
volumes:
{{- with .Values.kerberoshub.forwarder.volumes }}
{{- toYaml . | nindent 8 }}
{{- end }}
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
{{- include "hub.mongodb.tlsVolume" . | nindent 8 }}
{{- end }}
{{- end }}
{{- with .Values.kerberoshub.forwarder.topologySpreadConstraints }}
topologySpreadConstraints:
{{- toYaml . | nindent 8 }}
{{- end }}
containers:
- name: vault-forwarder
image: "{{ .Values.kerberoshub.forwarder.repository }}:{{ .Values.kerberoshub.forwarder.tag }}"
image: "{{ .Values.global.imageRegistry }}{{ .Values.kerberoshub.forwarder.repository }}:{{ .Values.kerberoshub.forwarder.tag }}"
imagePullPolicy: {{ .Values.kerberoshub.forwarder.pullPolicy }}
resources:
requests:
memory: 10Mi
cpu: 10m
{{- if or .Values.kerberoshub.forwarder.volumeMounts (and $mongodbTLS.enabled $mongodbTLS.existingSecret) }}
volumeMounts:
{{- with .Values.kerberoshub.forwarder.volumeMounts }}
{{- toYaml . | nindent 12 }}
{{- end }}
{{- if and $mongodbTLS.enabled $mongodbTLS.existingSecret }}
{{- include "hub.mongodb.tlsVolumeMount" . | nindent 12 }}
{{- end }}
{{- end }}
envFrom:
- configMapRef:
name: mongodb-config
env:
- name: ITERATION_SPEED
value: "5"
- name: BUFFER_TIME
value: "3"
# Mongodb
- name: MONGODB_URI
value: "{{ .Values.mongodb.uri }}"
- name: MONGODB_DATABASE_CLOUD
value: "Kerberos"
- name: MONGODB_HOST
value: "{{ .Values.mongodb.host }}"
- name: MONGODB_DATABASE_CREDENTIALS
value: "{{ .Values.mongodb.adminDatabase }}"
- name: MONGODB_USERNAME
value: "{{ .Values.mongodb.username }}"
- name: MONGODB_PASSWORD
value: "{{ .Values.mongodb.password }}"
# Mqtt (VERNEMQ)
- name: MQTT_URI
value: "{{ .Values.mqtt.host }}"
- name: MQTT_USERNAME
value: "{{ .Values.mqtt.username }}"
- name: MQTT_PASSWORD
value: "{{ .Values.mqtt.password }}"
- name: ITERATION_SPEED
value: "5"
- name: BUFFER_TIME
value: "3"
- name: MQTT_URI
value: "{{ .Values.mqtt.host }}"
- name: MQTT_USERNAME
value: "{{ .Values.mqtt.username }}"
- name: MQTT_PASSWORD
value: "{{ .Values.mqtt.password }}"
{{- end }}

View File

@@ -1,9 +1,11 @@
{{- if eq .Values.mode "all" -}}
apiVersion: apps/v1
kind: Deployment
metadata:
name: vault-proxy
namespace: {{ .Release.Namespace }}
spec:
replicas: 3
replicas: {{ .Values.kerberoshub.proxy.replicas }}
selector:
matchLabels:
app: vault-proxy
@@ -22,14 +24,28 @@ spec:
imagePullSecrets:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- with .Values.kerberoshub.proxy.volumes }}
volumes:
{{- toYaml . | nindent 8 }}
{{- end }}
{{- with .Values.kerberoshub.proxy.topologySpreadConstraints }}
topologySpreadConstraints:
{{- toYaml . | nindent 8 }}
{{- end }}
containers:
- name: vault-proxy
image: "{{ .Values.kerberoshub.proxy.repository }}:{{ .Values.kerberoshub.proxy.tag }}"
image: "{{ .Values.global.imageRegistry }}{{ .Values.kerberoshub.proxy.repository }}:{{ .Values.kerberoshub.proxy.tag }}"
imagePullPolicy: {{ .Values.kerberoshub.proxy.pullPolicy }}
{{- with .Values.kerberoshub.proxy.volumeMounts }}
volumeMounts:
{{- toYaml . | nindent 12 }}
{{- end }}
ports:
- containerPort: 8080
name: http
env:
- name: LOG_LEVEL
value: "{{ .Values.kerberoshub.proxy.logLevel }}"
# Kerberos Hub API
- name: KERBEROS_API_CHECK_SUBSCRIPTION
value: "{{ .Values.kerberoshub.api.schema }}://{{ .Values.kerberoshub.api.url }}/user/has-subscription"
@@ -47,6 +63,7 @@ apiVersion: v1
kind: Service
metadata:
name: vault-proxy-svc
namespace: {{ .Release.Namespace }}
labels:
app: vault-proxy-svc
spec:
@@ -58,3 +75,4 @@ spec:
name: http
selector:
app: vault-proxy
{{- end }}

File diff suppressed because it is too large Load Diff

View File

@@ -0,0 +1,97 @@
#!/usr/bin/env bash
#
# Render the hub chart and assert that every deployment which carries the
# workflows hand-off queue (the WORKFLOWS_QUEUE env var) resolves to the SAME,
# non-empty value.
#
# Why: the analysis pipeline (pipe-analysis) publishes opened workflow runs to
# WORKFLOWS_QUEUE, the workflows engine (hub-workflows) consumes it, and every
# stage worker (hub-stage) routes its result back to it. All three templates
# read the single key `kerberoshub.services.workflows.queue`. If a future edit
# hardcodes a value, reads the wrong key, or drops the env on one of them, the
# producer and consumer silently drift onto different queue names and messages
# pile up with no consumer. This check fails the build before that can ship.
#
# Usage: scripts/check-workflows-queue-consistency.sh [chart-dir]
# (chart-dir defaults to charts/hub, relative to the repo root)
set -euo pipefail
CHART_DIR="${1:-charts/hub}"
PROBE="drift-probe-queue-name"
# Flags that force all three deployment kinds (analysis, engine and one stage
# worker) to render, so the check actually has something to compare. The chart
# ships NO enabled stage worker by default (custom stages are values-only and
# opt-in), so we synthesise a throwaway stage purely to exercise the generic
# hub-stage path. The name is a neutral fixture ("queuecheck") on purpose: any
# arbitrary stage key must render the same way, so the check must not depend on
# a specific bundled worker.
STAGE="queuecheck"
RENDER_FLAGS=(
--set mode=all
--set kerberoshub.workflows.enabled=true
--set "kerberoshub.workflows.stages.${STAGE}.enabled=true"
--set "kerberoshub.services.${STAGE}.enabled=true"
--set "kerberoshub.services.${STAGE}.repository=example.invalid/queuecheck"
--set "kerberoshub.services.${STAGE}.tag=test"
--set "kerberoshub.services.${STAGE}.queue=queuecheck-fixture-queue"
)
# Read `helm template` output on stdin and print one WORKFLOWS_QUEUE value per
# line. Matches the `- name: WORKFLOWS_QUEUE` env entry and captures the value
# from the following `value:` line, skipping blank/comment lines in between.
extract_workflows_queue() {
awk '
/^[[:space:]]*-[[:space:]]*name:[[:space:]]*WORKFLOWS_QUEUE[[:space:]]*$/ { want=1; next }
want==1 {
if ($0 ~ /^[[:space:]]*#/ || $0 ~ /^[[:space:]]*$/) next
v=$0
sub(/^[[:space:]]*value:[[:space:]]*/, "", v)
sub(/^"/, "", v); sub(/"[[:space:]]*$/, "", v)
sub(/[[:space:]]+$/, "", v)
print v
want=0
}
'
}
assert_all_equal() {
local expected="$1"; shift
local label="$1"; shift
local -a vals=("$@")
if [ "${#vals[@]}" -lt 2 ]; then
echo "FAIL (${label}): expected at least 2 WORKFLOWS_QUEUE values (analysis + engine), found ${#vals[@]}" >&2
return 1
fi
local v
for v in "${vals[@]}"; do
if [ -z "${v}" ]; then
echo "FAIL (${label}): a deployment rendered an empty WORKFLOWS_QUEUE value" >&2
return 1
fi
if [ "${v}" != "${expected}" ]; then
echo "FAIL (${label}): WORKFLOWS_QUEUE drift detected — expected '${expected}' but a deployment rendered '${v}'" >&2
printf ' rendered values: %s\n' "${vals[*]}" >&2
return 1
fi
done
echo "OK (${label}): ${#vals[@]} deployments all use WORKFLOWS_QUEUE='${expected}'"
}
echo "== Rendering ${CHART_DIR} with the chart's default workflows queue =="
default_out="$(helm template hub "${CHART_DIR}" "${RENDER_FLAGS[@]}")"
mapfile -t default_vals < <(printf '%s\n' "${default_out}" | extract_workflows_queue)
default_queue="${default_vals[0]:-}"
assert_all_equal "${default_queue}" "default values" "${default_vals[@]}" || exit 1
echo "== Rendering ${CHART_DIR} with an overridden workflows queue (-> ${PROBE}) =="
probe_out="$(helm template hub "${CHART_DIR}" "${RENDER_FLAGS[@]}" \
--set kerberoshub.services.workflows.queue="${PROBE}")"
mapfile -t probe_vals < <(printf '%s\n' "${probe_out}" | extract_workflows_queue)
assert_all_equal "${PROBE}" "override probe" "${probe_vals[@]}" || exit 1
echo "All WORKFLOWS_QUEUE consistency checks passed."