Platform Manager Chart Values Reference

This reference lists the Platform Manager values the Axual Governance Helm chart exposes: the image and pull secrets, the TLS keystore Secrets, the application configuration and the credentials Secret, the Spring datasource, the governance Vault, and the Axual Connect and connector Vault settings.

Type

Reference

Goal

Look up a Platform Manager chart value while writing the Axual Governance values file.

Audience

Platform Operator deploying the Platform Manager that backs Self-Service.

When to use

While configuring Platform Manager, alongside the procedure that installs Axual Governance.

Contents

The sections below cover each area in this reference:

About Platform Manager

Platform Manager is the core component of the Axual Platform, and it manages every Self-Service resource. It is built on Spring Boot 3.x.

Platform Manager Configuration

Platform Manager talks to every other component of the Axual Platform, so most of its values name an endpoint or a credential for one of them. Replace every <VALUE> placeholder with your own value before installing.

For the full list of configuration options, see the Configuration section of the Platform Manager page.

Platform Manager Repository Configuration

You can override registry, tag, and pullPolicy for the Platform Manager pod. By default these values come from the Axual Governance chart. You can also override imagePullSecrets; if you leave it unset, the Platform Manager pod uses global.imagePullSecrets.

values.yaml
platform-manager:

  image:
    registry: "registry.axual.io"
    pullPolicy: "Always"
    tag: "13.0.0"

  imagePullSecrets:
    - name: axualdockercred

TLS Configuration

You can name the Secrets holding the Privacy Enhanced Mail (PEM) certificates the chart generates the keystores from:

  • Server keypair

  • Client keypair

  • Truststore

The example below sets all three.

values.yaml
platform-manager:

  tls:
    # -- Enables keystore generation
    enabled: true
    # -- Creates server keypair from PEM
    createServerKeypairSecret: true
    # -- PEM used to generate the server keypair if `createServerKeypairSecret` is true
    serverCertificatePem: <server-certificate>
    # -- PEM used to generate the server keypair if `createServerKeypairSecret` is true
    serverKeyPem: <server-key>

    # -- Creates client keypair from PEM
    createClientKeypairSecret: true
    # -- PEM used to generate the client keypair if `createClientKeypairSecret` is true
    clientCertificatePem: <client-certificate>
    # -- PEM used to generate the client keypair if `createClientKeypairSecret` is true
    clientKeyPem: <client-key>

    # -- Creates truststore from PEMs
    createTruststoreCaSecret: true
    # -- Set of PEMs used to generate the truststore if `createTruststoreCaSecret` is true
    caCerts:
      ca_one.crt:  <first-cert>
      ca_two.crt: <second-cert>

For the shape each of these Secrets takes, see Secret formats.

Application Configuration

Platform Manager is a Spring Boot application, so it reads its settings from an application.yml file. Whatever you put under config is injected into a ConfigMap and mounted as that file.

values.yaml
platform-manager:

  config: {}

Credentials Secret: secrets and existingSecretName

Platform Manager reads a second configuration file, secrets.yml, from a Kubernetes Secret. It takes the same structure as config, is loaded after it, and overrides any key the two share. Map entries merge, so one Tenant-Instance entry can hold its URI in config and its password in the Secret. One Secret holds every credential; the chart has no per-credential or per-Tenant-Instance Secret name.

Key Type Default Description

existingSecretName

string

""

Name of an existing Secret in the release namespace, holding a secrets.yml key. When set, Platform Manager reads this Secret instead of the chart-created one.

secrets

object

{}

Configuration the chart writes to its own Secret as secrets.yml. Platform Manager reads it only when existingSecretName is "". The values sit in the values file.

The Platform Manager credential keys that belong in secrets.yml are:

  • spring.datasource.username and spring.datasource.password

  • governance.vault.roleId and governance.vault.secretId

  • axual.connect.instanceConnectCredentials.<TENANT>-<INSTANCE>.username and .password

  • connectorVault.instances.<TENANT>-<INSTANCE>.roleId, .secretId, .keyStorePassword, .keyPassword and .truststorePassword

  • vault.role-id and vault.secret-id, for a single connector Vault that serves every Tenant-Instance

  • axual.organization-manager.keycloak.password

  • axual.application-management.apicurio.clientSecretSalt

  • axual.application-deployment.connect.log-viewer.password

  • ksml-provisioner.password

  • spring.mail.password

values.yaml
platform-manager:

  existingSecretName: "platform-manager-credentials"

Spring Datasource Configuration

Platform Manager persists Self-Service resources in a database, which it reaches through the standard Spring spring.datasource properties.

values.yaml
platform-manager:

  config:
    spring:
      # Spring Datasource
      datasource:
        # -- Datasource Name
        name: "platform-manager"
        # -- Datasource Url with Database
        url: "jdbc:mysql://platform-manager-mysql:3306/selfservice-db"
        # -- Datasource Username
        username: "platform-manager-username"
        # -- Datasource Password
        password: "<PLATFORM_MANAGER_DB_PASSWORD>"
        # -- Datasource Driver Class Name
        driver-class-name: "com.mysql.cj.jdbc.Driver"
      # Spring JPA
      jpa:
        # -- Database Platform
        database-platform: "org.hibernate.dialect.MySQLDialect"
      # Flyway Configuration
      flyway:
        # -- Flyway Script Location (`mariadb` or `mysql`)
#        locations: "classpath:db/migration/mariadb"
        locations: "classpath:db/migration/mysql"

Axual and Governance Configuration

The axual and governance entries hold the settings for the Axual services Platform Manager talks to. The example below reads the governance secrets from HashiCorp Vault.

values.yaml
platform-manager:

  config:
    # Governance Vault Configuration
    governance:
      vault:
        enabled: true
        # -- Define the URI of the Vault
        uri: "http://platform-manager-vault:8200"
        # -- Define the path of the KV Secret in the Vault
        path: "governance"
        # -- RoleID of the platform-manager policy to access the KV Secret
        roleId: "<governance-vault-role-id>"
        # -- SecretID of the platform-manager policy to access the KV Secret
        secretId: "<governance-vault-secret-id>"
        # -- (Optional) The Namespace of the Vault
        # namespace: "<governance-vault-namespace>"

Connect Configuration

The axual.connect entry tells Platform Manager how to authenticate against Axual Connect. Define one instance-connect-credentials entry per <tenant>-<instance> pair.

values.yaml
platform-manager:

  config:
    # Axual Platform Manager
    axual:
      # Connect Configuration
      connect:
        # -- Enable Connect Support
        available: true
        # -- Connect Instance Credentials for each Tenant-Instance
        instanceConnectCredentials:
          tenant-instance1:
            authorizer: basic
            username: "<connect-username>"
            password: "<connect-password>"
          tenant-instance2:
            authorizer: basic
            username: "<connect-username-2>"
            password: "<connect-password-2>"
Platform Manager reads the Axual Connect URL from the Instance definition in Self-Service.

Connect Vault Configuration

Each Axual Connect stores its connectors secrets in a HashiCorp Vault, and two Axual Connect installations can use different Vaults, so Platform Manager keeps a separate entry per Tenant-Instance.

values.yaml
platform-manager:

  config:
    # Connectors Vault Configuration
    connectorVault:
      # -- Enable Connect Support
      enabled: true
      # -- Vault Instance for each Tenant-Instance
      instances:
        tenant-instance1:
          # -- The URI of the Vault for the Tenant-Instance
          uri: "http://vault-instance:8200"
          # -- (Optional) The Namespace of the Vault for the Tenant-Instance
          namespace: "<connect-vault-namespace>"
          # -- The path of the `connectors` KV secrets defined for the Tenant-Instance
          connectorsPath: "connectors"
          # -- The RoleID of the Vault policy to access the `connectors` KV secrets for this Tenant-Instance
          roleId: "<connect-vault-role-id>"
          # -- The SecretID of the Vault policy to access the `connectors` KV secrets for this Tenant-Instance
          secretId: "<connect-vault-secret-id>"
          # -- The Name identifying the `private.key` of the Connector for the Tenant-Instance
          privateKeyName: "private.key"
          # -- The Name identifying the `certificate.chain` of the Connector for the Tenant-Instance
          certChainKeyName: "certificate.chain"
        tenant-instance2:
          uri: "http://vault-instance2:8200"
          connectorsPath: "connectors"
          roleId: "<connect-vault-role-id-2>"
          secretId: "<connect-vault-secret-id-2>"
          privateKeyName: "private.key"
          certChainKeyName: "certificate.chain"

Configuration documented in the Platform Manager Readme

Two configuration areas are generated from the chart and documented in the readme rather than here: