App Suite Releases
  • 8.47
  • 8.35
  • 7.10.6
Imprint
  • 8.47
  • 8.35
  • 7.10.6
Imprint
  • Release 8.54Upcoming
    • Noteworthy Changes
      • Important Changes
      • App Suite Middleware
    • Changelogs
      • App Suite UI
      • App Suite Middleware
      • Additional Components
        • AI Service
        • Booking Service
        • OX Guard UI
        • Switchboard
        • UI Service
    • Helm Charts
      • AI-Service documentation
      • App Suite Stack Chart
      • Booking
      • Helm Chart core-cacheservice
      • Helm Chart core-documentconverter
      • Helm Chart core-imageconverter
      • core-mw
      • UI Service
      • Switchboard
  • Release 8.53
  • Release 8.52
  • Release 8.51
  • Release 8.50
  • Release 8.49
Maintained. Older releases are best effort.
Upcoming
Not released yet
LTS
Long-term support branch

core-mw

Version: 6.25.24 Type: application AppVersion: 8.54.0

App Suite Middleware Core Helm Chart

Maintainers

NameEmailUrl
Open-Xchange GmbHinfo@open-xchange.com

Source Code

  • https://github.com/open-xchange/appsuite-middleware

Requirements

RepositoryNameVersion
oci://registry.open-xchange.com/appsuite-core-internal/charts/3rdpartycollabora-online1.3.0
oci://registry.open-xchange.com/appsuite-core-internal/charts/3rdpartygotenberg1.22.0
oci://registry.open-xchange.com/appsuite-core-internal/chartsox-common1.0.49

Additional informations

4.0.0

  • This version introduces new configuration.redis and configuration.sessiond section which adds support for Redis. Please refer to the documentation in values.yaml.
  • Changed the default service type from NodePort to ClusterIP for http-api, sync and admin service.
  • Removed all ingress configuration settings.
  • Removed services.documentconverterHost, services.imageconverterHost and services.spellcheckHost. Not necessary anymore but it's possible to override them e.g. via .Values.global.dc.serviceName
  • Renamed environment variables
    • OX_IMAGECONVERTER_URL → IC_SERVER_URL
    • OX_SPELLCHECK_URL → SPELLCHECK_SERVER_URL
    • OX_DOCUMENTCONVERTER_URL → DC_SERVER_URL
  • Partially or fully override ox-common.names.fullname via nameOverride or fullnameOverride.

5.10.1

  • This version introduces new configuration.redis.cache section which adds support for a separate cache for volatile data. Please refer to the documentation in values.yaml.

6.0.1

  • Hazelcast is now required for OX Documents only.
  • Disabled packages open-xchange-documents-backend and open-xchange-hazelcast per default.
  • Introduced a new role documents that enables packages open-xchange-documents-backend and open-xchange-hazelcast and adds necessary HZ_* env variables to containers. The role has been added to the defaultScaling.
  • Removed packages.minimalWhitelist as it was not used anymore
  • Removed role hazelcast-data-holding and hazelcast-lite-member

6.4.0

  • Whether to use TLS to connect to the Redis endpoint can now be configured using redis.tls.enabled and redis.cache.tls.enabled.

6.19.5

  • Added support for PodDisruptionBudget (PDB) via the new pdb configuration section.
  • This version adds a new middleware.open-xchange.com/type label to pods. Upgrading to this version will trigger a rolling restart of all pods due to the label change.

6.21.0

Third-party Java agent support

The chart supports injecting third-party Java agents (e.g. Elastic APM) into the middleware pod via extraInitContainers. A typical setup uses an init container to copy the agent JAR into a shared volume, which is then mounted into the middleware container and activated via javaOpts.other.

Support scope: OX supports the Helm injection mechanism (extraInitContainers, extraVolumes, extraMounts, javaOpts.other). The internal behavior of third-party agents is outside OX support scope.

Example: Elastic APM agent
extraInitContainers:
  - name: elastic-apm-init
    image: docker.elastic.co/apm/apm-agent-java:1.52.0
    command: ["cp", "/usr/agent/elastic-apm-agent.jar", "/apm-agent/"]
    volumeMounts:
      - name: apm-agent
        mountPath: /apm-agent

extraVolumes:
  - name: apm-agent
    emptyDir: {}

extraMounts:
  - name: apm-agent
    mountPath: /opt/apm-agent
    readOnly: true

javaOpts:
  other: "-javaagent:/opt/apm-agent/elastic-apm-agent.jar"

Upgrading

To 6.0.1

If you are using custom node definitions (scaling.nodes) in your Helm values, please make sure to remove roles hazelcast-data-holding and hazelcast-lite-member. Beside of that, a new role called documents has been introduced. The role needs to be added to every node definition that contains the http-api role and should run OX Documents. Furthermore, it ensures that a Hazelcast headless service is still deployed for OX Documents.

Please consider the following scaling.nodes definition:

core-mw:
  scaling:
    nodes:
      groupware:
        replicas: 2
        roles:
          - admin
          - http-api
          - hazelcast-data-holding
      sync:
        replicas: 1
        roles:
          - sync
          - businessmobility
          - hazelcast-lite-member

A migrated version could look like this:

core-mw:
  scaling:
    nodes:
      groupware:
        replicas: 2
        roles:
          - admin
          - http-api
          - documents
      sync:
        replicas: 1
        roles:
          - sync
          - businessmobility

Warning

Nodes that do not have the role documents will not be deployed as a StatefulSet anymore. Instead they will be deployed as a Deployment. Upgrading a StatefulSet to a Deployment is not easily possible without some preparation. Simply upgrading via Helm would remove all pods of the StatefulSet before starting the first pod of the new Deployment. This would result in a short downtime for endusers.

Example

Take a look at the following migrated example:

core-mw:
  scaling:
    nodes:
      groupware-without-docs:
        replicas: 2
        roles:
          - admin
          - http-api
      sync:
        replicas: 1
        roles:
          - sync
          - businessmobility

Nodes groupware-without-docs will not run OX Documents and roles hazelcast-data-holding and hazelcast-lite-member have been removed, too. Prior 6.0.1, those nodes were deployed as a StatefulSet. After the upgrade, they will be deployed as Deployment. If downtime is not feasible, you need to do the following before the upgrade:

  1. Remove the StatefulSet without removing the pods with:
kubectl delete statefulset appsuite-core-mw-groupware-without-docs --cascade=orphan
  1. Upgrade via Helm

If you're low on resources, you should scale replicas to 0 in your values.yaml. Otherwise, you will end up with the two pods from the StatefulSet and another two pods for the Deployment:

core-mw:
  scaling:
    nodes:
      groupware-without-docs:
        replicas: 0
        [...]

You can now upgrade the deployment via Helm:

helm upgrade [...]

After the upgrade, you can manually delete the StatefulSet pods and scale up the Deployment:

kubectl delete pod appsuite-core-mw-groupware-without-docs-1
kubectl scale deployment appsuite-core-mw-groupware-without-docs --replicas=1
kubectl delete pod appsuite-core-mw-groupware-without-docs-0
kubectl scale deployment appsuite-core-mw-groupware-without-docs --replicas=2

This process needs to be followed for all node definitions that previously had the hazelcast-data-holding role without having the documents role after the migration.

Don't forget to scale up the replicas in your values.yaml again.

Using existing*Secret values

The existing*Secret values let you supply configuration from Secrets you create and manage yourself (for example via Vault, sealed-secrets or external-secrets) instead of placing sensitive data directly in values.yaml. The chart only references these Secrets, so each one must already exist in the release namespace before you install or upgrade.

There are two behaviors. Know which one applies to the value you are setting:

  • Additive – your Secret is mounted alongside the chart-rendered configuration; both apply.
  • Replace – your Secret replaces the chart-rendered equivalent, and the corresponding plain values.yaml settings are then ignored.
ValueBehaviorCombines with / replaces
existingPropertiesSecretAdditiveproperties, secretProperties, propertiesFiles, secretPropertiesFiles
existingUISettingsSecretAdditiveuiSettings, secretUISettings, uiSettingsFiles, secretUISettingsFiles
existingMetaSecretAdditivemeta
existingContextSetsSecretAdditivecontextSets, secretContextSets
existingETCFilesSecretAdditiveetcFiles, secretETCFiles
existingETCBinariesSecretAdditiveetcBinaries, secretETCBinaries
existingYAMLFilesSecretAdditiveyamlFiles, secretYAMLFiles
existingASConfigSecretReplaceasConfig
existingEnvSecretAdditive (env)container environment (envFrom)
existing*Secrets (plural)Additivethe matching singular value; any number of further Secrets, see below
redis.existingSecretReplacechart-generated Redis properties secret
mysql.existingSecretReplacechart-generated configdb credentials secret
provisioningGateway.tls.existingSecretRequirednothing – the chart generates no certificate

What each Secret must contain

Every Secret below is one you create and manage yourself, in the release namespace, with the name you put into the corresponding value. The chart never generates them and never validates them: a missing or misspelled key is not a template error, it surfaces later as a failed database connection, a missing configuration file or a wrong password.

Two rules apply throughout:

  • Use stringData for text and data for anything binary. Keys under stringData are stored verbatim; keys under data must be base64-encoded and are decoded before they reach the container.
  • A Secret key becomes a file name. Kubernetes forbids / in Secret keys, so none of these Secrets can place a file into a sub-directory. Where a chart value accepts a nested path (yamlFiles, secretYAMLFiles), the existing*Secret equivalent does not.

Database credentials — mysql.existingSecret

Replaces the whole configdb Secret the chart would otherwise render, and is consumed as environment variables. Because it is a full replacement, supply all sixteen keys the chart's own Secret would define — a key you leave out is not a template error, it is an unset environment variable that surfaces much later. On a single-server setup, point the _WRITE_ and _READ_ keys at the same host as the plain ones.

apiVersion: v1
kind: Secret
metadata:
  name: my-db-creds
type: Opaque
stringData:
  MYSQL_HOST: "mysql-master"
  MYSQL_PORT: "3306"
  MYSQL_DATABASE: "configdb"
  MYSQL_USER: "openexchange"
  MYSQL_PASSWORD: "secret"
  MYSQL_ROOT_PASSWORD: "supersecret"
  MYSQL_WRITE_HOST: "mysql-master"
  MYSQL_WRITE_PORT: "3306"
  MYSQL_WRITE_DATABASE: "configdb"
  MYSQL_WRITE_USER: "openexchange"
  MYSQL_WRITE_PASSWORD: "writePassword"
  MYSQL_READ_HOST: "mysql-replica"
  MYSQL_READ_PORT: "3306"
  MYSQL_READ_DATABASE: "configdb"
  MYSQL_READ_USER: "openexchange"
  MYSQL_READ_PASSWORD: "readPassword"

One Secret serves every node type, referenced under exactly the name you give. The exception is a node type that overrides mysql in its own scaling.nodes.<type>.values block: the chart then looks for <name>-<typeName> instead, and since it is not generating the Secret either, those pods fail to start with CreateContainerConfigError. Do not combine mysql.existingSecret with a per-type mysql override.

global.mysql.existingSecret does the same thing across sub-charts and takes precedence over mysql.existingSecret when both are set. Note that this Secret is not covered by the checksums.existingSecrets annotation, so editing it does not roll the pods — restart the deployment yourself.

Redis credentials — redis.existingSecret

This one is easy to get wrong: it is not a redis-password key. It replaces the chart's generated Redis properties file, so its value must be a middleware configuration document — a YAML file whose top-level key is a configuration scope (anywhere unless you know you need a narrower one) holding com.openexchange.redis.* properties. Give it the same 1000_ prefix the chart's own file uses: it lands in the same directory as the property files and is applied in file-name order, so an unprefixed name would sort after — and silently outrank — an existingPropertiesSecret file you prefixed 1001_.

apiVersion: v1
kind: Secret
metadata:
  name: my-redis-props
type: Opaque
stringData:
  1000_redis-properties.yaml: |
    anywhere:
      com.openexchange.redis.mode: "sentinel"
      com.openexchange.redis.hosts: "redis-sentinel.example.svc.cluster.local:26379"
      com.openexchange.redis.sentinel.masterId: "mymaster"
      com.openexchange.redis.username: ""
      com.openexchange.redis.password: "redisPassword"
      com.openexchange.redis.ssl: "false"
      com.openexchange.redis.cache.enabled: "true"
      com.openexchange.redis.cache.mode: "cluster"
      com.openexchange.redis.cache.hosts: "redis-cache.example.svc.cluster.local:6379"
      com.openexchange.redis.cache.username: ""
      com.openexchange.redis.cache.password: "cachePassword"
      com.openexchange.redis.cache.ssl: "false"

For standalone or cluster mode drop the sentinel.masterId property and list the Redis nodes in hosts. Quote every value — the middleware expects strings, and an unquoted false or 6379 is parsed as a boolean or integer. Setting this value makes the chart ignore redis.auth and redis.mode, so anything you leave out of the Secret is simply absent rather than defaulted.

Keep populating redis.hosts regardless. That value has a second consumer the Secret does not replace: when the list is empty the chart deploys its own single-node Redis alongside the middleware, and that decision does not look at redis.existingSecret. Leaving it at the default gets you an in-cluster Redis that nothing connects to.

Environment variables — existingEnvSecret

Keys are environment-variable names, added to the containers via envFrom. Include only the variables you actually want to override; unlike the two above, this Secret is additive, so anything you omit keeps the value the chart generates. These are the credential-bearing variables worth putting here:

apiVersion: v1
kind: Secret
metadata:
  name: my-env
type: Opaque
stringData:
  MASTER_ADMIN_USER: "oxadminmaster"
  MASTER_ADMIN_PW: "masterPassword"
  OX_BASIC_AUTH_LOGIN: "basicAuthUser"
  OX_BASIC_AUTH_PASSWORD: "basicAuthPassword"
  JOLOKIA_LOGIN: "jolokiaUser"
  JOLOKIA_PASSWORD: "jolokiaPassword"
  CREDSTORAGE_PASSCRYPT: "credStoragePassphrase"

Mind the caveat described under Override precedence: this changes the container environment only, and the chart's own templating still reads the plain masterAdmin / masterPassword values.

Provisioning gateway certificate — provisioningGateway.tls.existingSecret

Required as soon as provisioningGateway.tls.enabled is true: the chart generates no certificate, and rendering fails with a required error if the value is empty. It is an ordinary kubernetes.io/tls Secret, so the two keys are fixed and cannot be renamed — the gateway reads them from tls.crt and tls.key under provisioningGateway.tls.mountPath.

apiVersion: v1
kind: Secret
metadata:
  name: my-gateway-tls
type: kubernetes.io/tls
data:
  tls.crt: <base64-encoded PEM certificate>
  tls.key: <base64-encoded PEM private key>

Like mysql.existingSecret, this one is not folded into the checksums.existingSecrets annotation, so rotating the certificate does not restart the gateway on its own.

Configuration files

The remaining existing*Secret values all work the same way — each key becomes a file, and where that file lands is what differs. The .yaml/.yml/.txt names below are examples except where called out.

ValueKey isEnds up asConstraint on the key
existingPropertiesSecreta properties document/configuration/<key>numeric prefix >= 1001 to win over the chart
existingUISettingsSecreta UI settings document/configuration/<key>numeric prefix >= 2001 to win over the chart
existingMetaSecreta meta document/opt/open-xchange/etc/meta/<key>—
existingContextSetsSecreta context sets document/opt/open-xchange/etc/contextSets/<key>—
existingASConfigSecretthe as-config document/opt/open-xchange/etc/<key>must be named as-config.yml
existingETCFilesSecretany text file/opt/open-xchange/etc/<key>—
existingETCBinariesSecretany binary file/opt/open-xchange/etc/<key>put it under data, not stringData
existingYAMLFilesSecretany YAML file/opt/open-xchange/etc/<key>no sub-directories

existingPropertiesSecret and existingUISettingsSecret share the single /configuration/ directory, so give their keys distinct names — the same key in both means one silently overwrites the other.

Several Secrets per value

Every additive existing*Secret value has a plural twin that takes a list of further Secret names: existingPropertiesSecrets, existingUISettingsSecrets, existingMetaSecrets, existingContextSetsSecrets, existingETCFilesSecrets, existingETCBinariesSecrets, existingYAMLFilesSecrets and existingEnvSecrets. Use them when the sensitive data comes from several sources, for example one ExternalSecret per credential. The singular value stays supported and comes first; a name given twice is used once.

For the file-based values all listed Secrets are projected into the same directory as the singular one, so the rule about distinct keys applies across the whole set. Which value wins on a duplicate property is still decided by the numeric file-name prefix, not by the order of the list.

For existingEnvSecrets each entry becomes one more envFrom source after existingEnvSecret, so on a duplicate key a later entry wins over an earlier one, and extraEnv still wins over all of them.

The Replace values (existingASConfigSecret, redis.existingSecret, mysql.existingSecret) and the gateway TLS Secret have no plural form: each stands in for exactly one chart-generated resource.

existingPropertiesSecret: my-extra-props    # still supported, mounted first
existingPropertiesSecrets:
  - my-ldap-credentials                     # key 1002_ldap.yaml
  - my-smtp-credentials                     # key 1003_smtp.yaml
existingEnvSecrets:
  - my-s3-env
  - my-oauth-env                            # wins over my-s3-env on a duplicate key

Override precedence

For the additive property/UI-settings secrets, configuration is applied in numeric file-name order. To make your file win over the chart-generated configuration, prefix it with a number higher than the chart's:

  • properties: use a prefix >= 1001 (the chart uses <= 1000)
  • UI settings: use a prefix >= 2001 (the chart uses <= 2000)
# stringData of the secret named by existingPropertiesSecret
1001_existing.yaml: |
  anywhere:
    com.openexchange.foobar: "true"

existingEnvSecret is added after the common-env and chart-generated env secrets and before any existingEnvSecrets entry, so on a duplicate key it overrides those two but neither a later existingEnvSecrets entry nor extraEnv. For example, a MASTER_ADMIN_USER key in your secret wins over the MASTER_ADMIN_USER the chart generates from masterAdmin.

This override happens only at the container-environment level. The chart's own templating still reads the plain masterAdmin / masterPassword values (it does not look at existingEnvSecret) when it generates other resources. So to change the master admin everywhere, set masterAdmin / masterPassword rather than only overriding the env var through existingEnvSecret.

Rolling restarts on content change

With checksums.existingSecrets: true (the default), the checksum of each referenced Secret's contents is folded into a pod annotation, so editing a Secret triggers a rolling restart. mysql.existingSecret is intentionally excluded (connection details rarely change).

Example

existingPropertiesSecret: my-extra-props   # additive; file prefixed 1001_ to override chart props
existingPropertiesSecrets: [my-ldap, my-smtp] # additive; every existing*Secret above has such a plural list
existingASConfigSecret: my-as-config       # replaces asConfig entirely
existingEnvSecret: my-env                  # extra environment variables, last-wins on duplicate keys

Configuration

The following table lists the configurable parameters of the App Suite Middleware Core chart and their default values.

KeyTypeDefaultDescription
affinityobject{}Affinity for pod assignment
asConfig.default.hoststring"all"
basicAuthLoginstring""The user name used for HTTP basic auth.
basicAuthPasswordstring""The password used for HTTP basic auth.
checksumsobject{"commonEnv":true,"config":true,"existingSecrets":true}Configures the checksum annotation used to trigger rolling updates.
checksums.commonEnvbooltrueDetect changes in the shared App Suite secret. It does not detect changes in the Secret defined by existingEnvSecret. Please use checksum.existingSecrets for this.
checksums.configbooltrueDetect config changes in ConfigMaps and Secrets that are created by this chart.
checksums.existingSecretsbooltrueDetect changes in Secrets defined by existing* values (e.g. existingPropertiesSecret or existingContextSetsSecret).
collabora-online.enabledboolfalseWhether Collabora should be enabled or not.
collabora-online.image.repositorystring"registry.open-xchange.com/appsuite-core-internal/3rdparty/collabora-online"
collabora-online.image.tagstring"26.04.2.3.1"
configurationobject{"businessmobility":{"logging":{"debug":{"enabled":false,"logPath":""}}},"languages":[],"logging":{"debug":true,"file":{"maxFileSize":"2MB","maxIndex":99,"minIndex":0,"name":"/var/log/open-xchange/open-xchange.log.0","pattern":"/var/log/open-xchange/open-xchange.log.%i"},"json":{"prettyPrint":false},"logger":[{"level":"WARN","name":"org.apache.cxf"},{"level":"WARN","name":"com.openexchange.soap.cxf.logger"}],"logstash":{"host":"localhost","port":31337},"queueSize":2048,"root":{"file":false,"json":true,"level":"INFO","logstash":false},"syslog":{"facility":"USER","host":"localhost","port":514}}}Configuration
configuration.businessmobility.logging.debug.enabledboolfalseWhether debug log is enabled or not
configuration.businessmobility.logging.debug.logPathstring""The path of the log file @default /var/log/open-xchange
configuration.languageslist[]List of languages which should be enabled. The default set of languages is de_DE, en_US, es_ES, fr_FR and it_IT.
Example for enabling a couple of languages: [ nl_NL, fi_FI, pl_PL ] or for all available languages [ all ]
configuration.logging.debugbooltrueEnables logback's debug mode
configuration.logging.json.prettyPrintboolfalseWhether PrettyPrint is enabled
configuration.logging.loggerlist[{"level":"WARN","name":"org.apache.cxf"},{"level":"WARN","name":"com.openexchange.soap.cxf.logger"}]List of named logger
configuration.logging.logstashobject{"host":"localhost","port":31337}Logstash configuration
configuration.logging.queueSizeint2048The number of logging events to retain for delivery
configuration.logging.root.fileboolfalseWhether File logging is enabled
configuration.logging.root.jsonbooltrueWhether JSON logging is enabled
configuration.logging.root.levelstring"INFO"Sets the log level of the root logger
configuration.logging.root.logstashboolfalseWhether logging to logstash is enabled
configuration.logging.syslogobject{"facility":"USER","host":"localhost","port":514}Syslog configuration
containerPortslist[{"containerPort":8009,"name":"http"}]Container ports
contextSetsobject{}Context sets
createCommonEnvbooltrueWhether to create a shared secret containing common properties as environment variables (e.g. SESSIOND_ENCRYPTION_KEY)
credstoragePasscryptstring""Key to encrypt/decrypt the password held in credential storage.
defaultRegistrystring"registry.open-xchange.com"The default registry
defaultScaling.nodes.default.roles[0]string"http-api"
defaultScaling.nodes.default.roles[1]string"sync"
defaultScaling.nodes.default.roles[2]string"admin"
defaultScaling.nodes.default.roles[3]string"businessmobility"
defaultScaling.nodes.default.roles[4]string"request-analyzer"
defaultScaling.nodes.default.roles[5]string"documents"
documentConverterClient.cache.remoteCacheobject{}
enableDBConnectionCheckbooltrueWhether to wait for configdb.
enableInitializationboolfalseWhether initial bootstraping is enabled or not.
etcBinarieslist[]etc files
etcFilesobject{}etc files
existingASConfigSecretstring""Name of an existing, self-managed secret (in the release namespace) holding as-config.yml. When set, this replaces the chart-rendered asConfig entirely (the asConfig value is then ignored). Content changes trigger a rolling restart when checksums.existingSecrets is enabled.
existingContextSetsSecretstring""Name of an existing, self-managed secret (in the release namespace) holding additional context sets. Mounted in addition to contextSets/secretContextSets. Content changes trigger a rolling restart when checksums.existingSecrets is enabled.
existingContextSetsSecretslist[]Names of further existing, self-managed secrets (in the release namespace) holding additional context sets. Same content format and mount location as existingContextSetsSecret, which stays supported and is mounted first. All listed secrets share one directory, so their keys must be distinct. Content changes trigger a rolling restart when checksums.existingSecrets is enabled.
existingETCBinariesSecretstring""Name of an existing, self-managed secret (in the release namespace) holding additional binary etc files. Mounted in addition to etcBinaries/secretETCBinaries. Content changes trigger a rolling restart when checksums.existingSecrets is enabled.
existingETCBinariesSecretslist[]Names of further existing, self-managed secrets (in the release namespace) holding additional binary etc files. Same content format and mount location as existingETCBinariesSecret, which stays supported and is mounted first. All listed secrets share one directory, so their keys must be distinct. Content changes trigger a rolling restart when checksums.existingSecrets is enabled.
existingETCFilesSecretstring""Name of an existing, self-managed secret (in the release namespace) holding additional etc files. Mounted in addition to etcFiles/secretETCFiles. Content changes trigger a rolling restart when checksums.existingSecrets is enabled.
existingETCFilesSecretslist[]Names of further existing, self-managed secrets (in the release namespace) holding additional etc files. Same content format and mount location as existingETCFilesSecret, which stays supported and is mounted first. All listed secrets share one directory, so their keys must be distinct. Content changes trigger a rolling restart when checksums.existingSecrets is enabled.
existingEnvSecretstring""Name of an existing, self-managed secret (in the release namespace) whose keys are added as environment variables to the containers (via envFrom). It is mounted after the common-env and chart-generated env secrets and before any existingEnvSecrets entry, so on a duplicate key it takes precedence over those two, but neither over a later existingEnvSecrets entry nor over extraEnv. Note: this only affects the container environment; values the chart reads internally (e.g. masterAdmin) are not changed by it. Content changes trigger a rolling restart when checksums.existingSecrets is enabled.
existingEnvSecretslist[]Names of further existing, self-managed secrets (in the release namespace) whose keys are added as environment variables, after existingEnvSecret, which stays supported. Later entries win on duplicate keys, and extraEnv still wins over all of them. Content changes trigger a rolling restart when checksums.existingSecrets is enabled.
existingMetaSecretstring""Name of an existing, self-managed secret (in the release namespace) holding additional meta settings. Mounted in addition to meta. Content changes trigger a rolling restart when checksums.existingSecrets is enabled.
existingMetaSecretslist[]Names of further existing, self-managed secrets (in the release namespace) holding additional meta settings. Same content format and mount location as existingMetaSecret, which stays supported and is mounted first. All listed secrets share one directory, so their keys must be distinct. Content changes trigger a rolling restart when checksums.existingSecrets is enabled.
existingPropertiesSecretstring""Name of an existing, self-managed secret (in the release namespace) holding additional properties. Mounted in addition to properties/secretProperties/propertiesFiles/secretPropertiesFiles. Content changes trigger a rolling restart when checksums.existingSecrets is enabled.
existingPropertiesSecretslist[]Names of further existing, self-managed secrets (in the release namespace) holding additional properties. Same content format and mount location as existingPropertiesSecret, which stays supported and is mounted first. All listed secrets share one directory, so their keys must be distinct; precedence is decided by the numeric file-name prefix, not by list order. Content changes trigger a rolling restart when checksums.existingSecrets is enabled.
existingUISettingsSecretstring""Name of an existing, self-managed secret (in the release namespace) holding additional UI settings. Mounted in addition to uiSettings/secretUISettings/uiSettingsFiles/secretUISettingsFiles. Content changes trigger a rolling restart when checksums.existingSecrets is enabled.
existingUISettingsSecretslist[]Names of further existing, self-managed secrets (in the release namespace) holding additional UI settings. Same content format and mount location as existingUISettingsSecret, which stays supported and is mounted first. All listed secrets share one directory, so their keys must be distinct; precedence is decided by the numeric file-name prefix, not by list order. Content changes trigger a rolling restart when checksums.existingSecrets is enabled.
existingYAMLFilesSecretstring""Name of an existing, self-managed secret (in the release namespace) holding additional YAML files. Mounted in addition to yamlFiles/secretYAMLFiles. Content changes trigger a rolling restart when checksums.existingSecrets is enabled.
existingYAMLFilesSecretslist[]Names of further existing, self-managed secrets (in the release namespace) holding additional YAML files. Same content format and mount location as existingYAMLFilesSecret, which stays supported and is mounted first. All listed secrets share one directory, so their keys must be distinct. Content changes trigger a rolling restart when checksums.existingSecrets is enabled.
extraContainerslist[]List of extra sidecar containers
extraEnvlist[]List of extra environment variables
extraInitContainerslist[]List of extra init containers injected into spec.initContainers. Use this to prepare volumes or run setup tasks before the middleware starts (e.g. copying a Java agent JAR). OX supports the Helm injection mechanism; the behavior of third-party agents is outside OX support scope.
extraMountslist[]List of extra mounts
extraPodSpecobject{}Extra PodSpec definitions
extraStatefulSetPropertiesobject{}List of extra StatefulSet properties
extraVolumeslist[]List of extra volumes
extras.monitoring.alerts.enabledboolfalseWhether to create a PrometheusRule with alerts, e.g. on refused live change streams. Needs monitoring enabled and the Prometheus Operator.
extras.monitoring.alerts.labelsobject{}Additional labels of the PrometheusRule, e.g. the one the Prometheus instance selects rules by.
extras.monitoring.enabledboolfalseWhether monitoring resources should be created, e.g. a ConfigMap containing the Grafana dashboards.
featuresobject{"definitions":{"admin":["open-xchange-admin","open-xchange-admin-contextrestore","open-xchange-admin-soap","open-xchange-admin-soap-usercopy","open-xchange-admin-user-copy"],"documents":["open-xchange-documents-backend","open-xchange-hazelcast"],"guard":["open-xchange-guard","open-xchange-guard-backend-plugin","open-xchange-guard-file-storage","open-xchange-guard-s3-storage"],"guard-admin":["open-xchange-guard-admin"],"mcp":["open-xchange-mcp"],"mobile-api":["open-xchange-mobile-api"],"omf-source":["open-xchange-omf-source","open-xchange-omf-source-dualprovisioning","open-xchange-omf-source-dualprovisioning-cloudplugins","open-xchange-omf-source-guard","open-xchange-omf-source-mailfilter"],"plugins":["open-xchange-plugins-antiphishing","open-xchange-plugins-antiphishing-vadesecure","open-xchange-plugins-blackwhitelist","open-xchange-plugins-blackwhitelist-sieve","open-xchange-plugins-contact-storage-group","open-xchange-plugins-contact-storage-provider","open-xchange-plugins-contact-whitelist-sync","open-xchange-plugins-mx-checker","open-xchange-plugins-onboarding-maillogin","open-xchange-plugins-trustedidentity","open-xchange-plugins-unsubscribe","open-xchange-plugins-unsubscribe-vadesecure"],"reseller":["open-xchange-admin-reseller","open-xchange-admin-soap-reseller"],"scim":["open-xchange-scim"],"usm-eas":["open-xchange-usm","open-xchange-eas"],"weakforced":["open-xchange-weakforced"]},"status":{"documents":"disabled","mcp":"disabled","mobile-api":"disabled","omf-source":"disabled","plugins":"disabled","reseller":"disabled","scim":"disabled","usm-eas":"disabled","weakforced":"disabled"}}Feature definition
features.definitions.adminlistsee values.yamlAdmin definitions
features.definitions.documentslistsee values.yamlDocuments definitions
features.definitions.guardlistsee values.yamlGuard definitions
features.definitions.mcplistsee values.yamlMCP server definitions. Disabled by default; the endpoint also needs com.openexchange.mcp.enabled.
features.definitions.mobile-apilistsee values.yamlMobile API definitions. Disabled by default; the API also needs com.openexchange.mobile.api.enabled.
features.definitions.omf-sourcelistsee values.yamlOX2OX Migration Framework Source definitions
features.definitions.pluginslistsee values.yamlPlugins definitions
features.definitions.resellerlistsee values.yamlReseller definitions
features.definitions.scimlistsee values.yamlSCIM service provider definitions. Enabled on the admin role only; see roles.admin.values.
features.definitions.usm-easlistsee values.yamlUSM EAS sync definitions
features.statusobjectsee values.yamlChoose whether to enable or disable features.
fullnameOverridestring""Fully override of the ox-common.names.fullname template
global.extras.monitoring.enabledboolfalse
global.imageRegistrystring""Sets the image registry globally
global.mysql.existingSecretstring""
gotenberg.chromium.disableJavaScriptbooltrue
gotenberg.enabledboolfalseWhether Gotenberg should be enabled or not.
gotenberg.extraEnv[0].namestring"XDG_DATA_HOME"
gotenberg.extraEnv[0].valuestring"/tmp/.data"
gotenberg.extraEnv[1].namestring"XDG_CONFIG_HOME"
gotenberg.extraEnv[1].valuestring"/tmp/.config"
gotenberg.extraEnv[2].namestring"XDG_CACHE_HOME"
gotenberg.extraEnv[2].valuestring"/tmp/.cache"
gotenberg.image.repositorystring"registry.open-xchange.com/appsuite-core-internal/3rdparty/gotenberg"
gotenberg.image.tagstring"8.34.0"
gotenberg.livenessProbeobject{"failureThreshold":3,"httpGet":{"path":"/health","port":"http"},"periodSeconds":10,"successThreshold":1,"timeoutSeconds":1}Liveness probe of the Gotenberg container. The timing fields spell out the Kubernetes defaults, which cluster policies may require to be set explicitly.
gotenberg.readinessProbeobject{"failureThreshold":3,"httpGet":{"path":"/health","port":"http"},"periodSeconds":10,"successThreshold":1,"timeoutSeconds":1}Readiness probe of the Gotenberg container. See gotenberg.livenessProbe.
gotenberg.securityContext.readOnlyRootFilesystembooltrue
gotenberg.volumeMounts[0].mountPathstring"/tmp"
gotenberg.volumeMounts[0].namestring"tmp-volume"
gotenberg.volumes[0].emptyDir.mediumstring"Memory"
gotenberg.volumes[0].emptyDir.sizeLimitstring"256Mi"
gotenberg.volumes[0].namestring"tmp-volume"
hooks.beforeApplyobject{}
hooks.beforeAppsuiteStartobject{}
hooks.startobject{}
hpaobject{"behavior":{},"create":false,"maxReplicas":4,"metrics":[],"minReplicas":1,"targetCPUUtilizationPercentage":80,"targetMemoryUtilizationPercentage":""}Horizontal Pod Autoscaler configuration. Rendered per scaling type. When enabled for a type, the Deployment's static replicas field is omitted so the HPA owns the replica count. Can be overridden per role/type like any other value.
hpa.behaviorobject{}Raw spec.behavior block (scale-up/scale-down policies), rendered verbatim. Leave empty to omit.
hpa.createboolfalseWhether a HorizontalPodAutoscaler should be created for the type
hpa.maxReplicasint4Upper bound for the number of replicas
hpa.metricslist[]Raw list of additional spec.metrics entries (verbatim). Use for custom/external metrics.
hpa.minReplicasint1Lower bound for the number of replicas
hpa.targetCPUUtilizationPercentageint80Target average CPU utilization (percentage). Leave empty to omit the CPU metric.
hpa.targetMemoryUtilizationPercentagestring""Target average memory utilization (percentage). Leave empty to omit the memory metric.
hzGroupNamestring""The Hazelcast group name.
image.pullPolicystring"IfNotPresent"Image pull policy
image.repositorystring"appsuite-core/middleware"Image repository
image.tagstring""Image tag
imagePullSecretslist[]Reference to one or more secrets to be used when pulling images
initContainerobject{}
initWaitobject{"dbTimeout":300,"middlewareTimeout":300}Bounded readiness waits performed by the init container.
initWait.dbTimeoutint300How long to wait, in seconds, for the configdb to accept connections before failing the init container.
initWait.middlewareTimeoutint300How long to wait, in seconds, for the middleware to come up during initial bootstrapping before failing the init container.
istio.compression.enabledboolfalseWhether to enable HTTP compression (gzip, deflate, etc.).
istio.injection.enabledboolfalseWhether to enable sidecar injection or not.
istio.virtualServices.destinationPortint80The virtual service destination port
javaOpts.compactObjectHeadersbooltrueEnables Compact Object Headers (appends -XX:+UseCompactObjectHeaders, JEP 519): 8-byte object headers → less live heap and GC pressure. Applied even when other is overridden; not appended again if other already mentions the flag (e.g. an explicit -XX:-UseCompactObjectHeaders opt-out is left untouched).
javaOpts.debug.gcLogs.enabledboolfalseEnables Java Garbage Collector logging
javaOpts.debug.heapdump.customobject{}The definition of a custom volume excluding its name which shall be used instead of a hostpath volume.
javaOpts.debug.heapdump.enabledboolfalseEnables Java Heap Dump creation in OOM situations
javaOpts.debug.heapdump.hostPath.dirstring"/mnt/appsuite-heap-dumps"hostPath directory on the k8s worker nodes, which needs to be created manually by the k8s admin. The directory will be mounted inside the core-mw container as '/heapdump'.
javaOpts.mallocArenaMaxstring"2"Caps glibc malloc arenas via the MALLOC_ARENA_MAX env var to bound native memory. The many-threaded (virtual-thread) middleware otherwise retains ~1.2G in per-thread malloc arenas; "2" cuts that back — bringing ZGC's non-heap native down to G1 level and letting ZGC fit a 6G limit at a 4G heap (vs 8G uncapped). Benefits G1 too. Set to "" for the glibc default. Minor malloc-contention trade-off at very high concurrency. See SCR-1723.
javaOpts.memory.maxHeapSizestring"2048M"Sets -XX:MaxHeapSize. Ignored if maxRAMPercentage is set.
javaOpts.memory.maxRAMPercentagestring""Sets -XX:MaxRAMPercentage instead of maxHeapSize. Takes precedence over maxHeapSize when set.
javaOpts.networkstring""
javaOpts.otherstring""Extra JVM options appended verbatim (env JAVA_OPTS_OTHER). (For Compact Object Headers or ZGC, prefer the compactObjectHeaders/zgc toggles below — not this field.)
javaOpts.serverstring""
javaOpts.zgcboolfalseUse generational ZGC instead of the default G1 (appends -XX:+UseZGC; not appended again if other already mentions the flag). Opt-in: ZGC gives sub-ms, near-constant GC pauses, well-suited to the virtual-thread worker pool, but needs substantial native-memory headroom beyond the heap (off-heap generational structures plus socket/NIO direct buffers). Too little does NOT surface as an OOM — it shows up as failures to open IMAP/SMTP connections under load. A ~50% heap ratio alone is not enough at small limits: in CI, 4G heap on a 6G limit and 3G heap on a 6G limit both failed, while 4G heap on an 8G limit (~3-4G free) passed cleanly. Before enabling, size heap ≤ ~50% of resources.limits.memory AND leave several GB free (e.g. a 4G heap wants an ≥8G limit). Validate under load before rollout.
javaOpts.zgcUncommitDelaystring""ZGC only (ignored unless zgc: true): seconds of idle before unused heap is uncommitted to the OS (-XX:ZUncommitDelay; uncommit is on by default). Lower returns idle memory faster, at a page-fault cost on reload — useful for "pay per used memory" hosting. Empty = JVM default (300). e.g. "60". Note: this returns heap only, not glibc malloc arenas (see mallocArenaMax). See SCR-1723.
jolokiaLoginstring""User used for authentication with HTTP Basic Authentication.
jolokiaPasswordstring""Password used for authentification with HTTP Basic Authentication.
masterAdminstring""The name of the master admin.
masterPasswordstring""The password of the master admin.
metaobject{}Meta
mysql.auth.passwordstring""The database password. (read/write connection)
mysql.auth.readPasswordstring""The database password. (read connection)
mysql.auth.readUserstring""The database user name. (read connection)
mysql.auth.rootPasswordstring""The MySQL root password.
mysql.auth.userstring""The database user name. (read/write connection)
mysql.auth.writePasswordstring""The database password. (write connection)
mysql.auth.writeUserstring""The database user name. (write connection)
mysql.databasestring""The database/schema name. (read/write connection)
mysql.existingSecretstring""Name of an existing, self-managed secret (in the release namespace) holding the configdb connection credentials. When set, the chart does not render its own MySQL secret and references this one instead. Unlike the other existing* secrets, this is not tracked by the checksums.existingSecrets annotation.
mysql.hoststring""The database host. (read/write connection)
mysql.portstring""The database port. (read/write connection)
mysql.readDatabasestring""The database/schema name. (read connection)
mysql.readHoststring""The database host. (read connection)
mysql.readPortstring""The database port. (read connection)
mysql.writeDatabasestring""The database/schema name. (write connection)
mysql.writeHoststring""The database host. (write connection)
mysql.writePortstring""The database port. (write connection)
nameOverridestring""Partially override of the ox-common.names.fullname template
NOTE: Preserves the release name.
nodeSelectorobject{}Tolerations for pod assignment
packagesobject{"status":{"open-xchange-admin-autocontextid":"disabled","open-xchange-authentication-imap":"disabled","open-xchange-authentication-ldap":"disabled","open-xchange-authentication-masterpassword":"disabled","open-xchange-authentication-oauth":"disabled","open-xchange-cassandra":"disabled","open-xchange-dataretention-csv":"disabled","open-xchange-drive-client-windows":"disabled","open-xchange-eas-provisioning":"disabled","open-xchange-eas-provisioning-mail":"disabled","open-xchange-eas-provisioning-sms":"disabled","open-xchange-hostname-config-cascade":"disabled","open-xchange-hostname-ldap":"disabled","open-xchange-multifactor":"disabled","open-xchange-parallels":"disabled","open-xchange-passwordchange-script":"disabled","open-xchange-saml-core":"disabled","open-xchange-sms-sipgate":"disabled","open-xchange-sms-twilio":"disabled","open-xchange-spamhandler-parallels":"disabled","open-xchange-sso":"disabled"},"whitelist":[]}Packages By default, all packages will be enabled. If a package is defined within a feature and that feature is disabled, the package will not be started UNLESS it is explicitly reactivated in this section. All disabled packages will be written into the environment variable OX_BLACKLISTED_PACKAGES.
packages.statusobjectsee values.yamlChoose whether to enable or disable packages.
packages.whitelistlist[]Whitelist The whitelist stands in contrast to the blacklist approach. Packages listed here are added to the OX_WHITELISTED_PACKAGES variable. This variable takes precedence over OX_BLACKLISTED_PACKAGES, causing the blacklist to be ignored.
pdbobject{"create":false,"maxUnavailable":"","minAvailable":"","unhealthyPodEvictionPolicy":""}Pod Disruption Budget configuration
pdb.createboolfalseWhether a PodDisruptionBudget should be created
pdb.maxUnavailablestring""Maximum number or percentage of pods that can be unavailable. Mutually exclusive with minAvailable. Examples: 1, "25%"
pdb.minAvailablestring""Minimum number or percentage of pods that must be available. Mutually exclusive with maxUnavailable. Examples: 1, "50%"
pdb.unhealthyPodEvictionPolicystring""Policy for evicting unhealthy (not yet Ready) pods, rendered as spec.unhealthyPodEvictionPolicy (GA since Kubernetes 1.31). Leave empty to omit. Examples: "IfHealthyBudget", "AlwaysAllow"
podAnnotationsobject{"logging.open-xchange.com/format":"appsuite-json"}Annotations to add to the pod
podSecurityContextobject{}The pod security context
priorityClassNamestring""The priority class for pods
probe.liveness.enabledbooltrueEnable the liveness probe
probe.liveness.failureThresholdint15The liveness probe failure threshold
probe.liveness.httpGetobject{"path":"/live","port":8016,"scheme":"HTTP"}Specifies the HTTP request to perform
probe.liveness.httpGet.pathstring"/live"Path to access on the HTTP server
probe.liveness.httpGet.portint8016Name or number of the port to access on the container. Number must be in the range 1 to 65535.
probe.liveness.httpGet.schemestring"HTTP"Scheme to use for connecting to the host (HTTP or HTTPS). Defaults to "HTTP".
probe.liveness.periodSecondsint10The liveness probe period (in seconds)
probe.readiness.enabledbooltrueEnable the readiness probe
probe.readiness.failureThresholdint2The readiness probe failure threshold
probe.readiness.httpGetobject{"path":"/ready","port":8009,"scheme":"HTTP"}Specifies the HTTP request to perform
probe.readiness.httpGet.pathstring"/ready"Path to access on the HTTP server
probe.readiness.httpGet.portint8009Name or number of the port to access on the container. Number must be in the range 1 to 65535.
probe.readiness.httpGet.schemestring"HTTP"Scheme to use for connecting to the host (HTTP or HTTPS). Defaults to "HTTP".
probe.readiness.initialDelaySecondsint30The readiness probe initial delay (in seconds)
probe.readiness.periodSecondsint5The readiness probe period (in seconds)
probe.readiness.timeoutSecondsint5The readiness probe timeout (in seconds)
probe.startup.enabledbooltrueEnable the startup probe
probe.startup.failureThresholdint30The startup probe failure threshold
probe.startup.httpGetobject{"path":"/health","port":8009,"scheme":"HTTP"}Specifies the HTTP request to perform
probe.startup.httpGet.pathstring"/health"Path to access on the HTTP server
probe.startup.httpGet.portint8009Name or number of the port to access on the container. Number must be in the range 1 to 65535.
probe.startup.httpGet.schemestring"HTTP"Scheme to use for connecting to the host (HTTP or HTTPS). Defaults to "HTTP".
probe.startup.initialDelaySecondsint30The startup probe initial delay (in seconds)
probe.startup.periodSecondsint10The startup probe period (in seconds)
probeHeaderslist[]
propertiesobjectsee values.yamlProperties
propertiesFilesobject{}Properties files
provisioningGateway.adminPortint9901Port of Envoy's own admin interface. Bound to loopback only.
provisioningGateway.descriptorMountPathstring"/etc/provisioning"Where the descriptor set is mounted into the gateway container.
provisioningGateway.enabledboolfalseWhether to run the provisioning HTTP/JSON gateway.
provisioningGateway.grpcPortint8066Port the middleware's gRPC server listens on, i.e. com.openexchange.grpc.server.port.
provisioningGateway.image.pullPolicystring"IfNotPresent"
provisioningGateway.image.repositorystring"envoyproxy/envoy"
provisioningGateway.image.tagstring"v1.31.9"A fixed tag on purpose. A floating one (v1.31-latest) makes the gateway a different binary from one pod restart to the next, which is not something to discover during an incident. Bump deliberately.
provisioningGateway.portint8080Port the gateway listens on inside the pod.
provisioningGateway.resources.limits.memorystring"256Mi"
provisioningGateway.resources.requests.cpustring"50m"
provisioningGateway.resources.requests.memorystring"64Mi"
provisioningGateway.rolestring"admin"The role whose pods carry the gateway. It talks to the middleware over the pod's loopback interface, so it has to sit next to a middleware that serves provisioning.
provisioningGateway.service.portint80Service port. Set this to 443 when the gateway terminates TLS.
provisioningGateway.service.typestring"ClusterIP"Service type for the gateway.
provisioningGateway.serviceslist["com.openexchange.grpc.provisioning.ContextService","com.openexchange.grpc.provisioning.UserService","com.openexchange.grpc.provisioning.GroupService","com.openexchange.grpc.provisioning.ResourceService","com.openexchange.grpc.provisioning.SharedAccountService","com.openexchange.grpc.provisioning.SecondaryAccountService","com.openexchange.grpc.provisioning.ResellerService","com.openexchange.grpc.provisioning.DeputyPermissionService","com.openexchange.grpc.provisioning.UtilService","com.openexchange.grpc.provisioning.JobService","com.openexchange.grpc.provisioning.UserCopyService","com.openexchange.grpc.provisioning.SessiondService","com.openexchange.grpc.provisioning.ProvisioningTokenService","com.openexchange.grpc.provisioning.ChronosService"]The gRPC services to expose. Only services listed here are reachable over HTTP, so this list is also the gateway's attack surface. The default is the set the SOAP provisioning interface already offers, so a caller can move off SOAP without losing an operation it had. Everything beyond that stays opt-in - notably the cluster maintenance services (ExtendedUpdateTaskService, DBMigrationService, SchemaService, ContextRestoreService, ConsistencyService and friends), which are not what a provisioning client needs and which include operations such as starting an update run.
provisioningGateway.timeoutstring"600s"How long a call may take before the gateway gives up and answers 504. Giving up does not stop the call: the middleware completes it anyway, the caller just never learns the outcome. Some calls, deleting a context with much data for instance, run long, hence the generous default. Whatever sits in front of the gateway needs at least the same timeout. 0s disables it.
provisioningGateway.tls.enabledboolfalseWhether the gateway terminates TLS itself. The endpoint carries administrative credentials in an HTTP basic header, so plain text is only defensible on a trusted, non-routable network.
provisioningGateway.tls.existingSecretstring""Name of an existing kubernetes.io/tls secret holding tls.crt and tls.key. Required when TLS is enabled; the chart does not generate a certificate.
provisioningGateway.tls.mountPathstring"/etc/provisioning-tls"Where the certificate and key are mounted into the gateway container.
rbac.createbooltrueWhether Role-Based Access Control (RBAC) resources should be created
rbac.ruleslist[]Custom RBAC rules
redis.affinityobject{}Affinity for pod assignment
redis.auth.passwordstring""The Redis password.
redis.auth.usernamestring""The Redis username.
redis.cacheobject{"auth":{"password":"","username":""},"enabled":false,"hosts":[],"mode":"","sentinelMasterId":"","tls":{"enabled":false}}Configuration for a separate cache for volatile data.
redis.cache.auth.passwordstring""The Redis password.
redis.cache.auth.usernamestring""The Redis username.
redis.cache.enabledboolfalseWhether a separate cache for volatile data is enabled or not, which is highly recommended in production.
redis.cache.hostslist[]List of Redis hosts:
Example for redis: [ <redis_host>:<redis_port> ]
Example for redis+sentinel: [ <sentinel1_host>:<sentinel1_port>,<sentinel2_host>:<sentinel2_port>,<sentinel3_host>:<sentinel3_port> ]
> Note: If hosts is empty or null, then an internal redis-standalone instance will be deployed.
redis.cache.modestring""Redis operation mode (standalone, cluster, sentinel).
redis.cache.sentinelMasterIdstring""Name of the sentinel masterSet, if operation mode is set to sentinel.
redis.cache.tlsobject{"enabled":false}Redis TLS configuration.
redis.cache.tls.enabledboolfalseWhether to use TLS to connect to Redis end-point or not.
redis.existingSecretstring""Name of an existing, self-managed secret (in the release namespace) holding Redis properties. When set, this replaces the chart-generated Redis properties secret. Content changes trigger a rolling restart when checksums.existingSecrets is enabled.
redis.extraEnvVarslist[]List of extra environment variables
redis.hostslist[]List of Redis hosts:
Example for redis: [ <redis_host>:<redis_port> ]
Example for redis+sentinel: [ <sentinel1_host>:<sentinel1_port>,<sentinel2_host>:<sentinel2_port>,<sentinel3_host>:<sentinel3_port> ]
> Note: If hosts is empty or null, then an internal redis-standalone instance will be deployed.
redis.image.repositorystring"redis"Redis image repository
redis.image.tagstring"7-alpine"Redis image tag
redis.modestring""Redis operation mode (standalone, cluster, sentinel)
redis.nodeSelectorobject{}Node labels for pod assignment
redis.sentinelMasterIdstring""Name of the sentinel masterSet, if operation mode is set to sentinel.
redis.tlsobject{"enabled":false}Redis TLS configuration.
redis.tls.enabledboolfalseWhether to use TLS to connect to Redis end-point or not.
redis.tolerationslist[]Tolerations for pod assignment
remoteDebug.enabledboolfalseWhether Java Remote Debugging is enabled.
remoteDebug.nodePortstringnilThe node port (default range: 30000-32767)
remoteDebug.portint8102The Java Remote Debug port.
replicasint1Number of nodes
resourcesobject{"limits":{"memory":"4096Mi"},"requests":{"cpu":"1000m","memory":"4096Mi"}}CPU/Memory resource requests/limits
restricted.drive.enabledbooltrueIf enabled tries to mount drive restricted configuration
roles.admin.services[0].ports[0].namestring"http"
roles.admin.services[0].ports[0].portint80
roles.admin.services[0].ports[0].protocolstring"TCP"
roles.admin.services[0].ports[0].targetPortstring"http"
roles.admin.services[0].typestring"ClusterIP"
roles.admin.values.features.status.scimstring"enabled"
roles.businessmobility.services[0].ports[0].namestring"http"
roles.businessmobility.services[0].ports[0].portint80
roles.businessmobility.services[0].ports[0].protocolstring"TCP"
roles.businessmobility.services[0].ports[0].targetPortstring"http"
roles.businessmobility.services[0].typestring"ClusterIP"
roles.businessmobility.values.features.status.usm-easstring"enabled"
roles.businessmobility.values.properties."com.openexchange.usm.ox.url"string"http://localhost:8009/appsuite/api/"
roles.documents.controllerstring"StatefulSet"
roles.documents.services[0].headlessbooltrue
roles.documents.services[0].namestring"hazelcast-headless"
roles.documents.services[0].ports[0].namestring"tcp-hazelcast"
roles.documents.services[0].ports[0].portint5701
roles.documents.statefulSetServiceNamestring"hazelcast-headless"
roles.documents.values.features.status.documentsstring"enabled"
roles.http-api.services[0].ports[0].namestring"http"
roles.http-api.services[0].ports[0].portint80
roles.http-api.services[0].ports[0].protocolstring"TCP"
roles.http-api.services[0].ports[0].targetPortstring"http"
roles.http-api.services[0].typestring"ClusterIP"
roles.request-analyzer.services[0].ports[0].namestring"http"
roles.request-analyzer.services[0].ports[0].portint80
roles.request-analyzer.services[0].ports[0].protocolstring"TCP"
roles.request-analyzer.services[0].ports[0].targetPortstring"http"
roles.request-analyzer.services[0].typestring"ClusterIP"
roles.sync.services[0].ports[0].namestring"http"
roles.sync.services[0].ports[0].portint80
roles.sync.services[0].ports[0].protocolstring"TCP"
roles.sync.services[0].ports[0].targetPortstring"http"
roles.sync.services[0].typestring"ClusterIP"
secretContextSetsobject{}Secret Context sets
secretETCBinarieslist[]Secret etc files
secretETCFilesobject{}Secret etc files
secretPropertiesobject{}Secret properties
secretPropertiesFilesobject{}Secret properties files
secretUISettingsobject{}Secret UI settings
secretUISettingsFilesobject{}Secret UI settings files
secretYAMLFilesobject{}Secret YAML files
securityContextobject{"allowPrivilegeEscalation":false}The security context
serverNamestring"server"The server name.
serviceAccount.annotationsobject{}Annotations to add to the service account
serviceAccount.createbooltrueWhether a service account should be created
serviceAccount.namestring""The name of the service account to use. If not set and create is true, a name is generated using the fullname template
terminationGracePeriodSecondsint60Duration in seconds the pod waits to terminate gracefully.
tolerationslist[]Tolerations for pod assignment
topologySpreadConstraintslist[]Topology spread constraints for pod assignment, rendered as spec.topologySpreadConstraints. Use to guarantee even pod spread across zones/nodes where preferred anti-affinity cannot. Example: topologySpreadConstraints: - maxSkew: 1 topologyKey: topology.kubernetes.io/zone whenUnsatisfiable: DoNotSchedule labelSelector: matchLabels: app.kubernetes.io/name: core-mw
uiSettingsobject{}UI settings
uiSettingsFilesobject{}UI settings files
update.enabledboolfalseWhether an update task job for the specified database schemata is created or not
update.jobobject{"automountServiceAccountToken":false,"ttlSecondsAfterFinished":86400}Job object settings
update.job.automountServiceAccountTokenboolfalseWhether the update job pod mounts the Kubernetes API token. The job does not call the Kubernetes API, so it defaults to false (CIS 5.1.6). Set to true only if a custom container needs API access.
update.job.ttlSecondsAfterFinishedint86400The number of seconds after which a job is deleted automatically
update.schematastring""Database schemata to update. If empty, all schemata will be updated.
update.typeslist[]Filter for which types the update tasks are triggered. Every type with an unique bundle set will create a container in the update job. All containers (except one) are configured as init containers to ensure they run sequentially.
update.valuesobject{}Override type sepcific update values
useLegacyBashScriptsbooltrueWhether to use the old bash style init scripts. This is necessary if you want to use bash style hooks instead of go binaries.
yamlFilesobject{}YAML files
Prev
Helm Chart core-imageconverter
Next
UI Service