4.4. Configuration for Nubus for Kubernetes#

Use this reference to configure the OX Connector on Nubus for Kubernetes. This page uses the published OX Connector Helm Chart to provide the Helm Chart values reference.

4.4.1. Configure a database#

Added in version v0.41.0: Add in OX Connector for Kubernetes version v.0.41.0.

To support the shared accounts feature, the OX Connector requires a PostgreSQL database to store account references. PostgreSQL is the only tested and supported database for the OX Connector. The database isn’t part of the OX App Suite packaged and the OX Connector integration. You need to provide it separately.

Before you install or upgrade to a version ≥ 0.41.0, ensure the following requirements for the database for the OX Connector in PostgreSQL:

  • You have created an empty database for the OX Connector.

  • You have created a dedicated database user for the OX Connector with the ALL PRIVILEGES privilege.

For information about how to configure the database connection, see openXchange.oxDbConnectionString in Prepare the OX Consumer configuration.

4.4.2. Helm Chart references values#

Name:

ox-connector

Version:

0.42.1

Description:

A Helm chart for the ox-connector

You find the configuration options for ox-connector in the following sections.

4.4.3. affinity#

affinity#

#Global values

Default value: {}

4.4.4. environment#

environment#

Default value: {}

4.4.5. extraVolumeMounts#

extraVolumeMounts#

Optionally specify an extra list of additional volumeMounts.

Default value: []

4.4.6. extraVolumes#

extraVolumes#

Optionally specify an extra list of additional volumes.

Default value: []

4.4.7. fullnameOverride#

fullnameOverride#

Default value: ""

4.4.8. global#

global.imagePullPolicy#

Define an ImagePullPolicy. # Ref.: https://kubernetes.io/docs/concepts/containers/images/#image-pull-policy # “IfNotPresent” => The image is pulled only if it is not already present locally. “Always” => Every time the kubelet launches a container, the kubelet queries the container image registry to resolve the name to an image digest. If the kubelet has a container image with that exact digest cached locally, the kubelet uses its cached image; otherwise, the kubelet pulls the image with the resolved digest, and uses that image to launch the container. “Never” => The kubelet does not try fetching the image. If the image is somehow already present locally, the kubelet attempts to start the container; otherwise, startup fails.

Default value: null

global.imagePullSecrets#

Credentials to fetch images from private registry. Ref: https://kubernetes.io/docs/tasks/configure-pod-container/pull-image-private-registry/ # imagePullSecrets: - “docker-registry”

Default value: []

global.imageRegistry#

Container registry address.

Default value:

"artifacts.software-univention.de"

4.4.9. nameOverride#

nameOverride#

Default value: ""

4.4.10. nodeSelector#

nodeSelector#

Default value: {}

4.4.11. openXchange#

openXchange.auth.existingSecret.keyMapping.password#

The key to retrieve the password from. Setting this value allows to use a key with a different name.

Default value: null

openXchange.auth.existingSecret.name#

The name of an existing Secret to use for retrieving the password for the ox admin password. # “oxConnector.auth.password” will be ignored if this value is set.

Default value: null

openXchange.auth.password#

OX Admin password

Default value: null

openXchange.auth.username#

OX Admin username (the OX Admin can create, modify, delete contexts; has to exist)

Default value: "oxadminmaster"

openXchange.domainName#

OX-Mail-Domain to generate OX-email-addresses

Default value: null

openXchange.logLevel#

OX Connector log level Chose from “DEBUG”, “INFO”, “WARNING” and “ERROR”.

Default value: "INFO"

openXchange.mappings.groupIdentifier#

UDM group property that is used as the unique group identifier for OX

Default value: "name"

openXchange.mappings.sharedAccountIdentifier#

UDM shared account property that is used as the unique account identifier for OX

Default value: "name"

openXchange.mappings.userIdentifier#

UDM user property that is used as the unique user identifier for OX

Default value: "username"

openXchange.oxDbConnectionString#

SQLAlchemy DB connection URL for the OX connector.

Default value: null

openXchange.oxDefaultContext#

Default context for users (has to exist)

Default value: "10"

openXchange.oxDeputyPermissions#

Ox Connector deputy permissions flag.

Default value: false

openXchange.oxImapServer#

Default IMAP server for new users (if not set explicitely there)

Default value: null

openXchange.oxLanguage#

Default language for new users

Default value: "de_DE"

openXchange.oxLocalTimezone#

Default timezone for new users

Default value: "Europe/Berlin"

openXchange.oxSharedAccount#

Ox Connector shared account flag.

Default value: true

openXchange.oxSmtpServer#

Default SMTP server for new users (if not set explicitely there)

Default value: null

openXchange.oxSoapServer#

The server where Open-Xchange is installed

Default value: null

4.4.12. oxConnector#

oxConnector.extraEnvVars#

Array with extra environment variables to add to containers. # extraEnvVars: - name: FOO value: “bar”

Default value: []

oxConnector.image.pullPolicy#

Default value: null

oxConnector.image.registry#

Default value: null

oxConnector.image.repository#

Default value:

"nubus/images/ox-connector-standalone"
oxConnector.image.tag#

Default value:

"0.42.1@sha256:16a17bf4d2ca2074d16ec708798012c9543091028cd3bc5a10e1c8be4fb14a64"

4.4.13. persistence#

persistence.size#

Specify PVCs size

Default value: "1Gi"

persistence.storageClass#

Specify storageClassName - Leave empty to use the default storage class

Default value: ""

4.4.14. podAnnotations#

podAnnotations#

Default value: {}

4.4.15. podSecurityContext#

podSecurityContext.fsGroup#

Default value: 1000

podSecurityContext.runAsGroup#

Default value: 1000

podSecurityContext.runAsNonRoot#

Default value: true

podSecurityContext.runAsUser#

Default value: 1000

podSecurityContext.seccompProfile.type#

Default value: "RuntimeDefault"

4.4.16. probes#

probes.liveness.exec.command#

Default value: ["/bin/sh", "-c", "exit 0\n"]

probes.liveness.failureThreshold#

Default value: 3

probes.liveness.initialDelaySeconds#

Default value: 120

probes.liveness.periodSeconds#

Default value: 30

probes.liveness.successThreshold#

Default value: 1

probes.liveness.timeoutSeconds#

Default value: 3

probes.readiness.exec.command#

Default value: ["/bin/sh", "-c", "exit 0\n"]

probes.readiness.failureThreshold#

Default value: 30

probes.readiness.initialDelaySeconds#

Default value: 30

probes.readiness.periodSeconds#

Default value: 15

probes.readiness.successThreshold#

Default value: 1

probes.readiness.timeoutSeconds#

Default value: 3

4.4.17. provisioningApi#

provisioningApi.auth.existingSecret.keyMapping.password#

The key to retrieve the password from. Setting this value allows to use a key with a different name.

Default value: null

provisioningApi.auth.existingSecret.name#

The name of an existing Secret to use for retrieving the password to authenticate with the Provisioning API. # “provisioningApi.auth.password” will be ignored if this value is set.

Default value: null

provisioningApi.auth.password#

The password to authenticate with.

Default value: null

provisioningApi.auth.username#

The username to authenticate with.

Default value: "ox-consumer"

provisioningApi.config.maxAcknowledgementRetries#

The maximum number of retries for acknowledging a message

Default value: 3

provisioningApi.connection.baseUrl#

The base URL the provisioning API is reachable at. (e.g. “https://provisioning-api”)

Default value: ""

provisioningApi.resync.auth.existingSecret.keyMapping.password#

The key to retrieve the password from. Setting this value allows to use a key with a different name.

Default value: null

provisioningApi.resync.auth.existingSecret.name#

The name of an existing Secret to use for retrieving the password to authenticate with the Provisioning API. # “provisioningApi.resync.auth.password” will be ignored if this value is set.

Default value: null

provisioningApi.resync.auth.password#

The admin password to authenticate with the Provisioning API.

Default value: null

provisioningApi.resync.auth.username#

The admin username to authenticate with the Provisioning API for recreating the ox-connector subscriber.

Default value: "admin"

provisioningApi.resync.enabled#

Enable the database resync on first startup only if database is empty.

Default value: true

4.4.18. replicaCount#

replicaCount#

Default value: 1

4.4.19. resources#

resources.limits.cpu#

Default value: "4"

resources.limits.memory#

Default value: "4Gi"

resources.requests.cpu#

Default value: "250m"

resources.requests.memory#

Default value: "512Mi"

4.4.20. resourcesWaitForDependency#

resourcesWaitForDependency.limits.cpu#

Default value: "200m"

resourcesWaitForDependency.limits.memory#

Default value: "128Mi"

resourcesWaitForDependency.requests.cpu#

Default value: "100m"

resourcesWaitForDependency.requests.memory#

Default value: "64Mi"

4.4.21. securityContext#

securityContext.allowPrivilegeEscalation#

Default value: false

securityContext.capabilities.drop#

Default value: ["ALL"]

securityContext.privileged#

Default value: false

securityContext.readOnlyRootFilesystem#

Default value: true

securityContext.runAsGroup#

Default value: 1000

securityContext.runAsNonRoot#

Default value: true

securityContext.runAsUser#

Default value: 1000

securityContext.seccompProfile.type#

Default value: "RuntimeDefault"

4.4.22. serviceAccount#

serviceAccount.annotations#

Annotations to add to the service account

Default value: {}

serviceAccount.automountServiceAccountToken#

#@param serviceAccount.automountServiceAccountToken Allows auto mount of ServiceAccountToken on the serviceAccount created #Can be set to false if pods using this serviceAccount do not need to use K8s API ##

Default value: false

serviceAccount.create#

Specifies whether a service account should be created

Default value: true

serviceAccount.labels#

Additional custom labels for the ServiceAccount.

Default value: {}

serviceAccount.name#

The name of the service account to use. If not set and create is true, a name is generated using the fullname template

Default value: ""

4.4.23. tolerations#

tolerations#

Default value: []

4.4.24. waitForDependency#

waitForDependency.image.pullPolicy#

Default value: null

waitForDependency.image.registry#

Default value: null

waitForDependency.image.repository#

Default value:

"nubus/images/wait-for-dependency"
waitForDependency.image.tag#

Default value:

"0.36.12@sha256:7150d72c8f342a05b945ce1b21464864aa91590d00f65ebe4b628571cce34efc"