To manage the runtime configuration settings in a Kubernetes deployment, edit the Helm Chart Values YAML file in the CDT Working Directory at {HOME}/.nn/cdt/helm/nns3_values.yaml. These parameters must be set before Step 2. Deploy the Nok Nok Server. If you later update these settings in the nns3_values.yaml file, perform an upgrade.
Global Parameters
Example nns3_values.yaml file:
image:
registryAuthority: "nns3-registry.noknokeval.com:50443"
pullPolicy: Always
pullSecrets: []
version: "{{NN_VERSION}}_{{NN_CDT_VERSION}}"
labels:
nns3.version: "{{NN_VERSION}}"
The registryAuthority parameter is set to point to the Private Container Registry. If you are not using the Private Container Registry included in CDT, change this to your Registry’s hostname and port.
When you install the Nok Nok Kubernetes CDT, the default pull policy is set to Always. This setting is appropriate for development because it guarantees that you get the most up-to-date image from the repository. In a production deployment, change the pull policy to IfNotPresent to get the image from the cache to avoid a lengthy download.
The global Kubernetes labels are added to all Nok Nok S3 Pods. The value of this parameter is a YAML map, set to an empty map {} by default. You need to remove the curly braces and add one or more attribute/value pairs by following the general Kubernetes labels conventions.
The global Kubernetes annotations are added to all Nok Nok S3 Pods. The value of this parameter is a YAML map, set to an empty map {} by default. You need to remove the curly braces and add one or more attribute/value pairs by following the general Kubernetes annotations conventions.
Server Component Parameters
The Helm Chart Values YAML file nns3_values.yaml has portions that are specific to various Nok Nok S3 server components. These are identified by their top level YAML keys. For example, the Authentication Server is represented by the authServer YAML key. This section describes the categories of parameters that can be changed for the various Nok Nok S3 Server components.
Component YAML Key | Description |
|---|---|
authServer | |
apiServer | Parameters for the API Server Pods |
adminServer | |
CLI | |
dbInit | Parameters for the the database initialization job |
authDB | Operational database connectivity parameters |
Log4j2 Parameters
apiServer:
...
logs:
level: error
target: stdout
layout: text
datetimeFormat: "{ISO8601}{UTC}"
enableAccessLog: false
accessLogReqHeaderFilter:
include:
userName: false
sessionData: false
message: false
request: false
response: false
externalAuthCredential: false
authServer:
...
logs:
level: error
target: stdout
layout: text
datetimeFormat: "{ISO8601}{UTC}"
enableAccessLog: false
accessLogReqHeaderFilter:For descriptions of the logs parameters, see Install on Linux.
JRE and Tomcat Parameters
authServer:
...
javaOpts: ""
catalinaOpts: ""
catalinaJMXPort: 8081Resource Request and Limit Parameters
authServer:
...
resources:
requests:
cpu: '750m'
memory: '1Gi'
ephemeral-storage: '1Gi'
limits:
cpu: '750m'
memory: '1Gi'
ephemeral-storage: '1Gi'Parameters for System Properties
authServer:
...
policyCacheExpiryTimeSeconds: ""
policyCacheMaxSize: ""
policyUpdatePollIntervalSeconds: ""
OOBListAuthEnabled: ""
SMTPHostAllowlist: "\"email-smtp.test.com\",\"smtp.host.com\""Additional Environment Variables
authServer:
...
extraEnv:
MY_ENV1: "value1"
MY_ENV2: "value2"Additional Volumes
The Nok Nok values YAML file, nns3_values.yaml, can be modified to mount additional Kubernetes volumes in the Nok Nok pods. Refer to the Volumes and volumeMounts configurations in the Kubernetes Volumes documentation for more information.
authServer:
extraVolumes:
....
extraVolumeMounts:
...Container Image Parameters
authServer:
...
image:
repository: "noknok/auth-server"
tag: "9.3.0.321_5.234"
digest: "sha256:f443a6bea44....38e3f650a21ead75e21"Where the digest parameter sets the digest to pin the image in production deployments. The tag parameter is an example build number. Find your actual build number in the Nok Nok Cloud Deployment Toolkit Release Notes.
TIP: To get the SHA256 digests after the images are pushed to the Private Container Registry, run the docker image ls --digests command from the CDT Host System terminal.
Startup, Readiness, and Liveness Parameters
Use these parameters to monitor the health and status of containers that run the Auth Server, the Admin Server and the API Server. Each probe serves a specific purpose.
startupProbe: Confirms that the application within a container has started successfully.
readinessProbe: Determines if a container is ready to accept traffic.
livenessProbe: Checks if the container is still running.
Example showing the default values for the Auth Server:
authServer:
...
startupProbe:
enabled: true
initialDelaySeconds: 60
timeoutSeconds: 4
periodSeconds: 5
failureThreshold: 60
checkScript: true
curlConnectTimeoutSeconds: 2
curlMaxTimeoutSeconds: 2
readinessProbe:
enabled: true
initialDelaySeconds: 60
timeoutSeconds: 4
periodSeconds: 5
failureThreshold: 10
checkScript: true
curlConnectTimeoutSeconds: 2
curlMaxTimeoutSeconds: 2
livenessProbe:
enabled: true
initialDelaySeconds: 60
timeoutSeconds: 4
periodSeconds: 10
failureThreshold: 15
checkScript: true
curlConnectTimeoutSeconds: 2
curlMaxTimeoutSeconds: 2"Ingress Parameters
The Nok Nok CDT deployment includes support for the NGINX Ingress Controller to direct requests to the Nok Nok API and Admin servers. This Ingress Controller is enabled by default. It is pre-configured to work with the TLS certificate made available in the CDT Working Directory at ${HOME}/.nn/cdt/tls.
ingress:
enabled: true
configureTLS: true
tlsSecretName: 'nn-tls'
class: nginx
annotations:
ingress.kubernetes.io/force-ssl-redirect: "true"
nginx.ingress.kubernetes.io/backend-protocol: "HTTP"
nginx.ingress.kubernetes.io/rewrite-target: "/"
nginx.ingress.kubernetes.io/ssl-passthrough: "false"If you need to use a different Ingress Controller, set enabled to false and define your own Kubernetes Ingress artifact.
Database Connectivity Parameters
authDB:
type: "mysql"
host: nn-mysql-authdb
port: 3306
name: nnauthdb
user: nnauthdbuser
# jndiJDBCUrl: ""