4.4. Configuration for Nubus for Kubernetes#
Use this reference to configure the OX Connector on Nubus for Kubernetes. This page uses the published OX Connector Helm Chart to provide the Helm Chart values reference.
4.4.1. Configure a database#
Added in version v0.41.0: Add in OX Connector for Kubernetes version v.0.41.0.
To support the shared accounts feature, the OX Connector requires a PostgreSQL database to store account references. PostgreSQL is the only tested and supported database for the OX Connector. The database isn’t part of the OX App Suite packaged and the OX Connector integration. You need to provide it separately.
Before you install or upgrade to a version ≥ 0.41.0, ensure the following requirements for the database for the OX Connector in PostgreSQL:
You have created an empty database for the OX Connector.
You have created a dedicated database user for the OX Connector with the
ALL PRIVILEGESprivilege.
For information about how to configure the database connection,
see openXchange.oxDbConnectionString in Prepare the OX Consumer configuration.
4.4.2. Helm Chart references values#
- Name:
ox-connector- Version:
0.42.1- Description:
A Helm chart for the ox-connector
You find the configuration options for ox-connector in the following sections.
4.4.3. affinity#
- affinity#
#Global values
Default value:
{}
4.4.4. environment#
- environment#
Default value:
{}
4.4.5. extraVolumeMounts#
- extraVolumeMounts#
Optionally specify an extra list of additional volumeMounts.
Default value:
[]
4.4.6. extraVolumes#
- extraVolumes#
Optionally specify an extra list of additional volumes.
Default value:
[]
4.4.7. fullnameOverride#
- fullnameOverride#
Default value:
""
4.4.8. global#
- global.imagePullPolicy#
Define an ImagePullPolicy. # Ref.: https://kubernetes.io/docs/concepts/containers/images/#image-pull-policy # “IfNotPresent” => The image is pulled only if it is not already present locally. “Always” => Every time the kubelet launches a container, the kubelet queries the container image registry to resolve the name to an image digest. If the kubelet has a container image with that exact digest cached locally, the kubelet uses its cached image; otherwise, the kubelet pulls the image with the resolved digest, and uses that image to launch the container. “Never” => The kubelet does not try fetching the image. If the image is somehow already present locally, the kubelet attempts to start the container; otherwise, startup fails.
Default value:
null
- global.imagePullSecrets#
Credentials to fetch images from private registry. Ref: https://kubernetes.io/docs/tasks/configure-pod-container/pull-image-private-registry/ # imagePullSecrets: - “docker-registry”
Default value:
[]
- global.imageRegistry#
Container registry address.
Default value:
"artifacts.software-univention.de"
4.4.9. nameOverride#
- nameOverride#
Default value:
""
4.4.10. nodeSelector#
- nodeSelector#
Default value:
{}
4.4.11. openXchange#
- openXchange.auth.existingSecret.keyMapping.password#
The key to retrieve the password from. Setting this value allows to use a key with a different name.
Default value:
null
- openXchange.auth.existingSecret.name#
The name of an existing Secret to use for retrieving the password for the ox admin password. # “oxConnector.auth.password” will be ignored if this value is set.
Default value:
null
- openXchange.auth.password#
OX Admin password
Default value:
null
- openXchange.auth.username#
OX Admin username (the OX Admin can create, modify, delete contexts; has to exist)
Default value:
"oxadminmaster"
- openXchange.domainName#
OX-Mail-Domain to generate OX-email-addresses
Default value:
null
- openXchange.logLevel#
OX Connector log level Chose from “DEBUG”, “INFO”, “WARNING” and “ERROR”.
Default value:
"INFO"
- openXchange.mappings.groupIdentifier#
UDM group property that is used as the unique group identifier for OX
Default value:
"name"
UDM shared account property that is used as the unique account identifier for OX
Default value:
"name"
- openXchange.mappings.userIdentifier#
UDM user property that is used as the unique user identifier for OX
Default value:
"username"
- openXchange.oxDbConnectionString#
SQLAlchemy DB connection URL for the OX connector.
Default value:
null
- openXchange.oxDefaultContext#
Default context for users (has to exist)
Default value:
"10"
- openXchange.oxDeputyPermissions#
Ox Connector deputy permissions flag.
Default value:
false
- openXchange.oxImapServer#
Default IMAP server for new users (if not set explicitely there)
Default value:
null
- openXchange.oxLanguage#
Default language for new users
Default value:
"de_DE"
- openXchange.oxLocalTimezone#
Default timezone for new users
Default value:
"Europe/Berlin"
Ox Connector shared account flag.
Default value:
true
- openXchange.oxSmtpServer#
Default SMTP server for new users (if not set explicitely there)
Default value:
null
- openXchange.oxSoapServer#
The server where Open-Xchange is installed
Default value:
null
4.4.12. oxConnector#
- oxConnector.extraEnvVars#
Array with extra environment variables to add to containers. # extraEnvVars: - name: FOO value: “bar”
Default value:
[]
- oxConnector.image.pullPolicy#
Default value:
null
- oxConnector.image.registry#
Default value:
null
- oxConnector.image.repository#
Default value:
"nubus/images/ox-connector-standalone"
- oxConnector.image.tag#
Default value:
"0.42.1@sha256:16a17bf4d2ca2074d16ec708798012c9543091028cd3bc5a10e1c8be4fb14a64"
4.4.13. persistence#
- persistence.size#
Specify PVCs size
Default value:
"1Gi"
- persistence.storageClass#
Specify storageClassName - Leave empty to use the default storage class
Default value:
""
4.4.14. podAnnotations#
- podAnnotations#
Default value:
{}
4.4.15. podSecurityContext#
- podSecurityContext.fsGroup#
Default value:
1000
- podSecurityContext.runAsGroup#
Default value:
1000
- podSecurityContext.runAsNonRoot#
Default value:
true
- podSecurityContext.runAsUser#
Default value:
1000
- podSecurityContext.seccompProfile.type#
Default value:
"RuntimeDefault"
4.4.16. probes#
- probes.liveness.exec.command#
Default value:
["/bin/sh", "-c", "exit 0\n"]
- probes.liveness.failureThreshold#
Default value:
3
- probes.liveness.initialDelaySeconds#
Default value:
120
- probes.liveness.periodSeconds#
Default value:
30
- probes.liveness.successThreshold#
Default value:
1
- probes.liveness.timeoutSeconds#
Default value:
3
- probes.readiness.exec.command#
Default value:
["/bin/sh", "-c", "exit 0\n"]
- probes.readiness.failureThreshold#
Default value:
30
- probes.readiness.initialDelaySeconds#
Default value:
30
- probes.readiness.periodSeconds#
Default value:
15
- probes.readiness.successThreshold#
Default value:
1
- probes.readiness.timeoutSeconds#
Default value:
3
4.4.17. provisioningApi#
- provisioningApi.auth.existingSecret.keyMapping.password#
The key to retrieve the password from. Setting this value allows to use a key with a different name.
Default value:
null
- provisioningApi.auth.existingSecret.name#
The name of an existing Secret to use for retrieving the password to authenticate with the Provisioning API. # “provisioningApi.auth.password” will be ignored if this value is set.
Default value:
null
- provisioningApi.auth.password#
The password to authenticate with.
Default value:
null
- provisioningApi.auth.username#
The username to authenticate with.
Default value:
"ox-consumer"
- provisioningApi.config.maxAcknowledgementRetries#
The maximum number of retries for acknowledging a message
Default value:
3
- provisioningApi.connection.baseUrl#
The base URL the provisioning API is reachable at. (e.g. “https://provisioning-api”)
Default value:
""
- provisioningApi.resync.auth.existingSecret.keyMapping.password#
The key to retrieve the password from. Setting this value allows to use a key with a different name.
Default value:
null
- provisioningApi.resync.auth.existingSecret.name#
The name of an existing Secret to use for retrieving the password to authenticate with the Provisioning API. # “provisioningApi.resync.auth.password” will be ignored if this value is set.
Default value:
null
- provisioningApi.resync.auth.password#
The admin password to authenticate with the Provisioning API.
Default value:
null
- provisioningApi.resync.auth.username#
The admin username to authenticate with the Provisioning API for recreating the ox-connector subscriber.
Default value:
"admin"
- provisioningApi.resync.enabled#
Enable the database resync on first startup only if database is empty.
Default value:
true
4.4.18. replicaCount#
- replicaCount#
Default value:
1
4.4.19. resources#
- resources.limits.cpu#
Default value:
"4"
- resources.limits.memory#
Default value:
"4Gi"
- resources.requests.cpu#
Default value:
"250m"
- resources.requests.memory#
Default value:
"512Mi"
4.4.20. resourcesWaitForDependency#
- resourcesWaitForDependency.limits.cpu#
Default value:
"200m"
- resourcesWaitForDependency.limits.memory#
Default value:
"128Mi"
- resourcesWaitForDependency.requests.cpu#
Default value:
"100m"
- resourcesWaitForDependency.requests.memory#
Default value:
"64Mi"
4.4.21. securityContext#
- securityContext.allowPrivilegeEscalation#
Default value:
false
- securityContext.capabilities.drop#
Default value:
["ALL"]
- securityContext.privileged#
Default value:
false
- securityContext.readOnlyRootFilesystem#
Default value:
true
- securityContext.runAsGroup#
Default value:
1000
- securityContext.runAsNonRoot#
Default value:
true
- securityContext.runAsUser#
Default value:
1000
- securityContext.seccompProfile.type#
Default value:
"RuntimeDefault"
4.4.22. serviceAccount#
- serviceAccount.annotations#
Annotations to add to the service account
Default value:
{}
- serviceAccount.automountServiceAccountToken#
#@param serviceAccount.automountServiceAccountToken Allows auto mount of ServiceAccountToken on the serviceAccount created #Can be set to false if pods using this serviceAccount do not need to use K8s API ##
Default value:
false
- serviceAccount.create#
Specifies whether a service account should be created
Default value:
true
- serviceAccount.labels#
Additional custom labels for the ServiceAccount.
Default value:
{}
- serviceAccount.name#
The name of the service account to use. If not set and create is true, a name is generated using the fullname template
Default value:
""
4.4.23. tolerations#
- tolerations#
Default value:
[]
4.4.24. waitForDependency#
- waitForDependency.image.pullPolicy#
Default value:
null
- waitForDependency.image.registry#
Default value:
null
- waitForDependency.image.repository#
Default value:
"nubus/images/wait-for-dependency"
- waitForDependency.image.tag#
Default value:
"0.36.12@sha256:7150d72c8f342a05b945ce1b21464864aa91590d00f65ebe4b628571cce34efc"