Skip to main content
The Helm chart sets these from its values. They’re for running the image another way, such as with Docker, and for the few settings the chart has no value for, which you can set with extraEnv. KubeStacks reads them when it starts. One that doesn’t make sense stops it, and its log says which and why.

Where it runs

number
default:"8080"
The port to listen on. 0 picks any free port, and the log says which.
string
The address to listen on: every interface unless set.
string
The address people open it at, like https://kubestacks.example.com. Single sign-on needs it. With https:, cookies are sent over HTTPS only.
string
default:"/"
Where it is below that address, like /kubestacks.

The cluster it shows

string
What it calls the cluster: in-cluster (or the kubeconfig’s context) unless set.
string
A kubeconfig to show a cluster from, instead of the cluster KubeStacks runs in.
string
The kubeconfig’s context to show: its current context unless set.
string
default:"/var/run/secrets/kubernetes.io/serviceaccount"
Where the pod’s service account token and CA certificate are, inside a cluster.

Sign-in

string
default:"token"
token, oidc or proxy. See Ways to sign in.
string
The OpenID Connect provider’s issuer URL. Required with oidc.
string
KubeStacks’ client ID at the provider. Required with oidc.
string
The client’s secret. Unset for a public client.
string
default:"openid email profile"
The scopes to ask for, separated by spaces.
string
default:"email"
The ID token claim that names people.
string
default:"groups"
The ID token claim that lists their groups.
string
default:"single sign-on"
The provider’s name on the sign-in button: Sign in with this.
string
id or access: pass people’s own token on (the API server must trust the provider) instead of impersonating them.
string
default:"X-Forwarded-User"
The header a proxy names people in.
string
default:"X-Forwarded-Groups"
The header a proxy lists their groups in, separated by commas.
string
Where signing out of the proxy is.
string
Put before impersonated users’ names.
string
Put before impersonated groups’ names.
number
default:"12"
How long sessions last, in hours: at most 168, a week.
number
default:"30"
How often pages’ connections are checked, in seconds, at most 3600. Keep it shorter than the idle timeout of the proxies in front of KubeStacks.

What people can do

boolean
default:"false"
true or 1: nobody changes anything through KubeStacks.
string
default:"auto"
Where usage history comes from unless people choose: auto, off, or namespace/service:port, with a path after it for vmselect (vm/vmselect:8481/select/0/prometheus).
boolean
default:"false"
true or 1: charts may come from private network addresses.
string
default:"https://artifacthub.io"
Where to search for charts.
string
default:"/etc/kubestacks/views"
Where the views everyone sees are.
string
default:"/usr/local/bin/helm"
The helm to run: the one in the image unless set.

Large clusters and slow API servers

These work the same as in the desktop app, and the chart has no values for them: set them with extraEnv.
number
default:"5000"
The most objects a list loads. Lists are fetched in chunks of 500.
number
default:"20000"
How long the API server has to answer, in milliseconds.
values.yaml

Addresses it answers

All of these are below the base path. Every other address is KubeStacks’ page and its files.

Helm values

The chart’s settings, which set these for you.

Run it with Docker

Use these to run the image outside Kubernetes.