extraEnv.
KubeStacks reads them when it starts. One that doesn’t make sense stops it, and its log says which and why.
Where it runs
number
default:"8080"
The port to listen on.
0 picks any free port, and the log says which.string
The address to listen on: every interface unless set.
string
The address people open it at, like
https://kubestacks.example.com. Single sign-on needs it. With https:, cookies are sent over HTTPS only.string
default:"/"
Where it is below that address, like
/kubestacks.The cluster it shows
string
What it calls the cluster:
in-cluster (or the kubeconfig’s context) unless set.string
A kubeconfig to show a cluster from, instead of the cluster KubeStacks runs in.
string
The kubeconfig’s context to show: its current context unless set.
string
default:"/var/run/secrets/kubernetes.io/serviceaccount"
Where the pod’s service account token and CA certificate are, inside a cluster.
Sign-in
string
default:"token"
token, oidc or proxy. See Ways to sign in.string
The OpenID Connect provider’s issuer URL. Required with
oidc.string
KubeStacks’ client ID at the provider. Required with
oidc.string
The client’s secret. Unset for a public client.
string
default:"openid email profile"
The scopes to ask for, separated by spaces.
string
default:"email"
The ID token claim that names people.
string
default:"groups"
The ID token claim that lists their groups.
string
default:"single sign-on"
The provider’s name on the sign-in button: Sign in with this.
string
id or access: pass people’s own token on (the API server must trust the provider) instead of impersonating them.string
default:"X-Forwarded-User"
The header a proxy names people in.
string
default:"X-Forwarded-Groups"
The header a proxy lists their groups in, separated by commas.
string
Where signing out of the proxy is.
string
Put before impersonated users’ names.
string
Put before impersonated groups’ names.
number
default:"12"
How long sessions last, in hours: at most 168, a week.
number
default:"30"
How often pages’ connections are checked, in seconds, at most 3600. Keep it shorter than the idle timeout of the proxies in front of KubeStacks.
What people can do
boolean
default:"false"
true or 1: nobody changes anything through KubeStacks.string
default:"auto"
Where usage history comes from unless people choose:
auto, off, or namespace/service:port, with a path after it for vmselect (vm/vmselect:8481/select/0/prometheus).boolean
default:"false"
true or 1: charts may come from private network addresses.string
default:"https://artifacthub.io"
Where to search for charts.
string
default:"/etc/kubestacks/views"
Where the views everyone sees are.
string
default:"/usr/local/bin/helm"
The helm to run: the one in the image unless set.
Large clusters and slow API servers
These work the same as in the desktop app, and the chart has no values for them: set them withextraEnv.
number
default:"5000"
The most objects a list loads. Lists are fetched in chunks of 500.
number
default:"20000"
How long the API server has to answer, in milliseconds.
values.yaml
Addresses it answers
All of these are below the base path.
Every other address is KubeStacks’ page and its files.
Helm values
The chart’s settings, which set these for you.
Run it with Docker
Use these to run the image outside Kubernetes.