To manage the runtime configuration settings in a Kubernetes deployment, edit the Helm Chart Values YAML file in the CDT Working Directory at {HOME}/.nn/cdt/helm/nns3_values.yaml. These parameters must be set before Step 2. Deploy the Digipass S3 Server. If you later update these settings in the nns3_values.yaml file, perform an upgrade.
Global Parameters
Example nns3_values.yaml file:
image:
registryAuthority: "nns3-registry.noknokeval.com:50443"
pullPolicy: Always
pullSecrets: []
version: "{{NN_VERSION}}_{{NN_CDT_VERSION}}"
labels:
nns3.version: "{{NN_VERSION}}"
The registryAuthority parameter is set to point to the Private Container Registry. If you are not using the Private Container Registry included in CDT, change this to your Registry’s hostname and port.
When you install the Digipass S3 Kubernetes CDT, the default pull policy is set to Always. This setting is appropriate for development because it guarantees that you get the most up-to-date image from the repository. In a production deployment, change the pull policy to IfNotPresent to get the image from the cache to avoid a lengthy download.
The global Kubernetes labels are added to all Digipass S3 Pods. The value of this parameter is a YAML map, set to an empty map {} by default. You need to remove the curly braces and add one or more attribute/value pairs by following the general Kubernetes labels conventions.
The global Kubernetes annotations are added to all Digipass S3 Pods. The value of this parameter is a YAML map, set to an empty map {} by default. You need to remove the curly braces and add one or more attribute/value pairs by following the general Kubernetes annotations conventions.
Server Component Parameters
The Helm Chart Values YAML file nns3_values.yaml has portions that are specific to various Digipass S3 server components. These are identified by their top level YAML keys. For example, the Authentication Server is represented by the authServer YAML key. This section describes the categories of parameters that can be changed for the various Digipass S3 Server components.
Component YAML Key | Description |
|---|---|
authServer | Parameters for the Authentication Server pods |
apiServer | Parameters for the API Server pods |
adminServer | Parameters for the Admin Server pods |
CLI | Parameters for the CLI pod |
dbInit | Parameters for the the database initialization job |
authDB | Operational database connectivity parameters |
Log4j2 Parameters
apiServer:
...
logs:
level: error
target: stdout
layout: text
datetimeFormat: "{ISO8601}{UTC}"
enableAccessLog: false
accessLogReqHeaderFilter:
include:
userName: false
sessionData: false
message: false
request: false
response: false
externalAuthCredential: false
authServer:
...
logs:
level: error
target: stdout
layout: text
datetimeFormat: "{ISO8601}{UTC}"
enableAccessLog: false
accessLogReqHeaderFilter:For descriptions of the logs parameters, see Install on Linux.
JRE and Tomcat Parameters
authServer:
...
javaOpts: ""
catalinaOpts: ""
catalinaJMXPort: 8081Resource Request and Limit Parameters
authServer:
...
resources:
requests:
cpu: '750m'
memory: '1Gi'
ephemeral-storage: '1Gi'
limits:
cpu: '750m'
memory: '1Gi'
ephemeral-storage: '1Gi'Parameters for System Properties
authServer:
...
policyCacheExpiryTimeSeconds: ""
policyCacheMaxSize: ""
policyUpdatePollIntervalSeconds: ""
OOBListAuthEnabled: ""
SMTPHostAllowlist: "\"email-smtp.test.com\",\"smtp.host.com\""Additional Environment Variables
authServer:
...
extraEnv:
MY_ENV1: "value1"
MY_ENV2: "value2"Additional Volumes
The Digipass S3 values YAML file, nns3_values.yaml, can be modified to mount additional Kubernetes volumes in the Digipass S3 pods. Refer to the Volumes and volumeMounts configurations in the Kubernetes Volumes documentation for more information.
authServer:
extraVolumes:
....
extraVolumeMounts:
...Container Image Parameters
authServer:
...
image:
repository: "noknok/auth-server"
tag: "9.3.0.321_5.234"
digest: "sha256:f443a6bea44....38e3f650a21ead75e21"Where the digest parameter sets the digest to pin the image in production deployments. The tag parameter is an example build number. Find your actual build number in the Digipass S3 Cloud Deployment Toolkit Release Notes.
TIP: To get the SHA256 digests after the images are pushed to the Private Container Registry, run the docker image ls --digests command from the CDT Host System terminal.
Startup, Readiness, and Liveness Parameters
Use these parameters to monitor the health and status of containers that run the Auth Server, the Admin Server and the API Server. Each probe serves a specific purpose.
startupProbe: Confirms that the application within a container has started successfully.
readinessProbe: Determines if a container is ready to accept traffic.
livenessProbe: Checks if the container is still running.
Example showing the default values for the Auth Server:
authServer:
...
startupProbe:
enabled: true
initialDelaySeconds: 60
timeoutSeconds: 4
periodSeconds: 5
failureThreshold: 60
checkScript: true
curlConnectTimeoutSeconds: 2
curlMaxTimeoutSeconds: 2
readinessProbe:
enabled: true
initialDelaySeconds: 60
timeoutSeconds: 4
periodSeconds: 5
failureThreshold: 10
checkScript: true
curlConnectTimeoutSeconds: 2
curlMaxTimeoutSeconds: 2
livenessProbe:
enabled: true
initialDelaySeconds: 60
timeoutSeconds: 4
periodSeconds: 10
failureThreshold: 15
checkScript: true
curlConnectTimeoutSeconds: 2
curlMaxTimeoutSeconds: 2"Ingress Parameters
The Digipass S3 CDT deployment includes support for the NGINX Ingress Controller to direct requests to the Digipass S3 API server and the Digipass S3 Admin server. This Ingress Controller is enabled by default. It is pre-configured to work with the TLS certificate made available in the CDT Working Directory at ${HOME}/.nn/cdt/tls.
ingress:
enabled: true
configureTLS: true
tlsSecretName: 'nn-tls'
class: nginx
annotations:
ingress.kubernetes.io/force-ssl-redirect: "true"
nginx.ingress.kubernetes.io/backend-protocol: "HTTP"
nginx.ingress.kubernetes.io/rewrite-target: "/"
nginx.ingress.kubernetes.io/ssl-passthrough: "false"If you need to use a different Ingress Controller, set enabled to false and define your own Kubernetes Ingress artifact.
Note: Kubernetes Nginx Ingress is retired, but for convenience you can use Nginx Ingress for development deployments only. For production deployments, use a vendor-specific Kubernetes provider API gateway/load balancer. See Kubernetes documentation for details.
The CDT’s values.yaml file enables Nginx Ingress by default. Use this default configuration for development deployments only. For production deployments, edit the ingress: section at the end of the file nn_cdt/helm/charts/nns3/values.yaml and set enabled: to false.
Database Connectivity Parameters
authDB:
type: "mysql"
host: nn-mysql-authdb
port: 3306
name: nnauthdb
user: nnauthdbuser
# jndiJDBCUrl: ""