Digipass S3 is now DigipassONE. This section is currently being updated to reflect our new name.

Appendix C: Helm Chart Values YAML

Prev Next

To manage the runtime configuration settings in a Kubernetes deployment, edit the Helm Chart Values YAML file in the CDT Working Directory at {HOME}/.nn/cdt/helm/nns3_values.yaml. These parameters must be set before Step 2. Deploy the Nok Nok Server. If you later update these settings in the nns3_values.yaml file, perform an upgrade.

Global Parameters

Example nns3_values.yaml file:

image:
  registryAuthority: "nns3-registry.noknokeval.com:50443"
  pullPolicy: Always
  pullSecrets: []
version: "{{NN_VERSION}}_{{NN_CDT_VERSION}}"
labels:
  nns3.version: "{{NN_VERSION}}"

  • The registryAuthority parameter is set to point to the Private Container Registry. If you are not using the Private Container Registry included in CDT, change this to your Registry’s hostname and port.

  • When you install the Nok Nok Kubernetes CDT, the default pull policy is set to Always. This setting is appropriate for development because it guarantees that you get the most up-to-date image from the repository. In a production deployment, change the pull policy to IfNotPresent to get the image from the cache to avoid a lengthy download.

  • The global Kubernetes labels are added to all Nok Nok S3 Pods. The value of this parameter is a YAML map, set to an empty map {} by default. You need to remove the curly braces and add one or more attribute/value pairs by following the general Kubernetes labels conventions.

  • The global Kubernetes annotations are added to all Nok Nok S3 Pods. The value of this parameter is a YAML map, set to an empty map {} by default. You need to remove the curly braces and add one or more attribute/value pairs by following the general Kubernetes annotations conventions.

Server Component Parameters

The Helm Chart Values YAML file nns3_values.yaml has portions that are specific to various Nok Nok S3 server components. These are identified by their top level YAML keys. For example, the Authentication Server is represented by the authServer YAML key. This section describes the categories of parameters that can be changed for the various Nok Nok S3 Server components.

Component YAML Key

Description

authServer

Parameters for the Authentication Server Pods

apiServer

Parameters for the API Server Pods

adminServer

Parameters for the Admin Server Pods

CLI

Parameters for the CLI Pod

dbInit

Parameters for the the database initialization job

authDB

Operational database connectivity parameters

Log4j2 Parameters

apiServer:
  ...
  logs:
    level: error
    target: stdout
    layout: text
    datetimeFormat: "{ISO8601}{UTC}"
    enableAccessLog: false
    accessLogReqHeaderFilter:
    include:
      userName: false
      sessionData: false
      message: false
      request: false
      response: false
      externalAuthCredential: false
authServer:
  ...
  logs:
    level: error
    target: stdout
    layout: text
    datetimeFormat: "{ISO8601}{UTC}"
    enableAccessLog: false
    accessLogReqHeaderFilter:

For descriptions of the logs parameters, see Install on Linux.

JRE and Tomcat Parameters

authServer:
  ...
  javaOpts: ""
  catalinaOpts: ""
  catalinaJMXPort: 8081

Resource Request and Limit Parameters

authServer:
  ...
  resources:
    requests:
      cpu: '750m'
      memory: '1Gi'
      ephemeral-storage: '1Gi'
    limits:
      cpu: '750m'
      memory: '1Gi'
      ephemeral-storage: '1Gi'

Parameters for System Properties

authServer:
  ...
  policyCacheExpiryTimeSeconds: ""
  policyCacheMaxSize: ""
  policyUpdatePollIntervalSeconds: ""
  OOBListAuthEnabled: ""
  SMTPHostAllowlist: "\"email-smtp.test.com\",\"smtp.host.com\""

Additional Environment Variables

authServer:
  ...
  extraEnv:
    MY_ENV1: "value1"
    MY_ENV2: "value2"

Additional Volumes

The Nok Nok values YAML file, nns3_values.yaml, can be modified to mount additional Kubernetes volumes in the Nok Nok pods. Refer to the Volumes and volumeMounts configurations in the Kubernetes Volumes documentation for more information.

authServer:
  extraVolumes:
    ....
  extraVolumeMounts:
    ...

Container Image Parameters

authServer:
  ...
  image:
    repository: "noknok/auth-server"
    tag: "9.3.0.321_5.234"
    digest: "sha256:f443a6bea44....38e3f650a21ead75e21"

Where the digest parameter sets the digest to pin the image in production deployments. The tag parameter is an example build number. Find your actual build number in the Nok Nok Cloud Deployment Toolkit Release Notes.

TIP: To get the SHA256 digests after the images are pushed to the Private Container Registry, run the docker image ls --digests command from the CDT Host System terminal.

Startup, Readiness, and Liveness Parameters

Use these parameters to monitor the health and status of containers that run the Auth Server, the Admin Server and the API Server. Each probe serves a specific purpose.

  • startupProbe: Confirms that the application within a container has started successfully.

  • readinessProbe: Determines if a container is ready to accept traffic.

  • livenessProbe: Checks if the container is still running.

Example showing the default values for the Auth Server:

authServer:
  ...
  startupProbe:
    enabled: true
    initialDelaySeconds: 60
    timeoutSeconds: 4
    periodSeconds: 5
    failureThreshold: 60
    checkScript: true
    curlConnectTimeoutSeconds: 2
    curlMaxTimeoutSeconds: 2
  readinessProbe:
    enabled: true
    initialDelaySeconds: 60
    timeoutSeconds: 4
    periodSeconds: 5
    failureThreshold: 10
    checkScript: true
    curlConnectTimeoutSeconds: 2
    curlMaxTimeoutSeconds: 2
  livenessProbe:
    enabled: true
    initialDelaySeconds: 60
    timeoutSeconds: 4
    periodSeconds: 10
    failureThreshold: 15
    checkScript: true
    curlConnectTimeoutSeconds: 2
    curlMaxTimeoutSeconds: 2"

Ingress Parameters

The Nok Nok CDT deployment includes support for the NGINX Ingress Controller to direct requests to the Nok Nok API and Admin servers. This Ingress Controller is enabled by default. It is pre-configured to work with the TLS certificate made available in the CDT Working Directory at ${HOME}/.nn/cdt/tls.

ingress:
  enabled: true
  configureTLS: true
  tlsSecretName: 'nn-tls'
  class: nginx
  annotations:
    ingress.kubernetes.io/force-ssl-redirect: "true"
    nginx.ingress.kubernetes.io/backend-protocol: "HTTP"
    nginx.ingress.kubernetes.io/rewrite-target: "/"
    nginx.ingress.kubernetes.io/ssl-passthrough: "false"

If you need to use a different Ingress Controller, set enabled to false and define your own Kubernetes Ingress artifact.

Database Connectivity Parameters

authDB:
  type: "mysql"
  host: nn-mysql-authdb
  port: 3306
  name: nnauthdb
  user: nnauthdbuser
  # jndiJDBCUrl: ""