Skip to main content
Set these in a values file, and install or upgrade with --values values.yaml. The chart checks them against its schema, and refuses settings that don’t make sense before anything is installed. To see the defaults, with a comment on each:

The cluster and its address

string
default:"in-cluster"
What KubeStacks calls the cluster: in its pages, their addresses and titles. No slashes or spaces.
string
The address people open KubeStacks at, like https://kubestacks.example.com. Single sign-on needs it, as the provider sends people back there. With https:, cookies are sent over HTTPS only.
string
default:"/"
Where KubeStacks is below that address, when it shares a host with other apps: /kubestacks, say. The ingress path and health checks follow it. See Give KubeStacks an address.

Sign-in

string
default:"token"
How people sign in: token, oidc or proxy.
  • token: with a token the cluster accepts. Each person’s requests carry their own token, and KubeStacks’ service account needs no permissions. See Tokens.
  • oidc: with an OpenID Connect provider. KubeStacks impersonates whoever signs in, unless auth.oidc.forwardToken is set. See Single sign-on.
  • proxy: behind an authenticating proxy that names people in request headers. KubeStacks impersonates them. See Authenticating proxy.
string
The provider’s issuer URL, where /.well-known/openid-configuration is. Required with oidc.
string
KubeStacks’ client ID at the provider. Required with oidc.
string
The client’s secret, from which the chart makes a Secret. Leave it empty for a public client, or use existingSecret instead.
string
A Secret in KubeStacks’ namespace with the client’s secret under the key client-secret. Takes the place of clientSecret.
string
default:"openid email profile"
The scopes KubeStacks asks for, separated by spaces. Add groups if your provider needs it to put groups in the ID token, and offline_access for refresh tokens when passing tokens on.
string
default:"email"
The ID token claim that names people.
string
default:"groups"
The ID token claim that lists their groups.
string
The provider’s name on the sign-in button: Okta makes it Sign in with Okta. Unset, the button says Sign in with single sign-on.
string
id or access: the token people’s requests carry, when the API server trusts the provider itself (its --oidc-* flags, a structured authentication configuration, EKS’s OIDC identity providers…). KubeStacks then needs no permissions, and renews tokens with refresh tokens. Unset, it impersonates people. See When the API server trusts the provider.
string
default:"X-Forwarded-User"
The request header in which the proxy names people.
string
default:"X-Forwarded-Groups"
The request header in which the proxy lists their groups, separated by commas.
string
Where signing out of the proxy is, like https://kubestacks.example.com/oauth2/sign_out.
string
Put before the names of the users KubeStacks impersonates, like the API server’s --oidc-username-prefix: oidc: makes [email protected] oidc:[email protected] in RBAC.
string
Put before the names of their groups.
number
default:"12"
How long a session lasts, in hours: more than 0, at most 168 (a week). Sessions live in KubeStacks’ memory, so a restart signs people out sooner.

What people can do

boolean
default:"false"
When true, nobody changes anything through KubeStacks, whatever their RBAC allows. Each person can also make it read-only for themselves. See Read-only mode.
string
default:"auto"
Where usage history comes from, unless people choose another source in their browser:
  • auto: KubeStacks looks for Prometheus or VictoriaMetrics among the cluster’s services.
  • off: no usage history.
  • A service, as namespace/service:port: monitoring/prometheus-operated:9090. For vmselect, with its path after the port: vm/vmselect:8481/select/0/prometheus.
See Usage history.
boolean
default:"false"
When true, charts may come from addresses inside private networks, such as a ChartMuseum or Harbor in your network. When false, KubeStacks fetches charts only from public addresses. See Security.
string
default:"https://artifacthub.io"
The Artifact Hub KubeStacks searches for charts to install.
object
default:"{}"
Views everyone sees, by file name: each key is a file name ending in .yaml or .yml, and its value the file’s contents. See Views for everyone.

Kubernetes objects

boolean
default:"true"
Whether the chart makes KubeStacks’ service account.
string
The service account’s name: the release’s full name unless set. Required when serviceAccount.create is false.
object
default:"{}"
Annotations for the service account.
boolean
default:"true"
Whether the chart lets KubeStacks’ service account impersonate users and groups, which it needs with oidc (unless tokens are passed on) and proxy. In other modes, the chart makes no RBAC objects either way. Set it to false to manage that permission yourself.
integer
default:"1"
How many KubeStacks pods to run. Sessions live in each pod’s memory: more than one needs sticky sessions.
string
default:"ClusterIP"
ClusterIP, NodePort or LoadBalancer.
integer
default:"80"
The Service’s port. KubeStacks itself listens on 8080.
object
default:"{}"
Annotations for the Service.
boolean
default:"false"
Whether the chart makes an Ingress for KubeStacks.
string
The Ingress’ class, like nginx.
string[]
default:"[kubestacks.example.com]"
The hosts to serve KubeStacks at, each with one rule for basePath.
object[]
default:"[]"
The Ingress’ tls, as it is: [{ secretName: kubestacks-tls, hosts: [kubestacks.example.com] }].
object
default:"{}"
Annotations for the Ingress. Pages keep a WebSocket open, so give the ingress controller a long read timeout, like nginx.ingress.kubernetes.io/proxy-read-timeout: "3600".
boolean
default:"false"
Whether the chart makes a NetworkPolicy that only lets in what networkPolicy.from allows, on KubeStacks’ port. Behind a proxy, use it to let in only the proxy.
object[]
default:"[]"
The NetworkPolicy’s from: who may reach KubeStacks. Empty, anything may, on KubeStacks’ port.

The pod

string
default:"ghcr.io/kubestacks/kubestacks"
The image to run.
string
The image’s tag: the chart’s version unless set.
string
default:"IfNotPresent"
Always, IfNotPresent or Never.
object[]
default:"[]"
Secrets for pulling the image, for a copy in a private registry.
object
The container’s resources. By default it requests 50m of CPU and 128Mi of memory, and is limited to 512Mi of memory.
object
The pod’s security context. By default: non-root, as user and group 65532, with the RuntimeDefault seccomp profile.
object
The container’s security context. By default: no privilege escalation, a read-only root filesystem, and every capability dropped.
object[]
default:"[]"
More environment variables, as a container’s env. See Configuration for the ones KubeStacks reads.
object
default:"{}"
Annotations for the pod.
object
default:"{}"
Labels for the pod.
object
default:"{}"
The pod’s node selector.
object[]
default:"[]"
The pod’s tolerations.
object
default:"{}"
The pod’s affinity.
string
The pod’s priority class.
string
Replaces the chart’s name in the objects’ names.
string
Replaces the objects’ full name. Installed as kubestacks, they’re all called kubestacks.

Configuration

The environment variables the chart sets, for running the image another way.

Install

Install or upgrade with a values file.