Platform Manager Chart Values Reference
This reference lists the Platform Manager values the Axual Governance Helm chart exposes: the image and pull secrets, the TLS keystore Secrets, the application configuration and the credentials Secret, the Spring datasource, the governance Vault, and the Axual Connect and connector Vault settings.
Type |
Reference |
Goal |
Look up a Platform Manager chart value while writing the Axual Governance values file. |
Audience |
Platform Operator deploying the Platform Manager that backs Self-Service. |
When to use |
While configuring Platform Manager, alongside the procedure that installs Axual Governance. |
About Platform Manager
Platform Manager is the core component of the Axual Platform, and it manages every Self-Service resource. It is built on Spring Boot 3.x.
Platform Manager Configuration
Platform Manager talks to every other component of the Axual Platform, so most of its values name an endpoint or a credential for one of them. Replace every <VALUE> placeholder with your own value before installing.
For the full list of configuration options, see the Configuration section of the Platform Manager page.
Platform Manager Repository Configuration
You can override registry, tag, and pullPolicy for the Platform Manager pod. By default these values come from the Axual Governance chart. You can also override imagePullSecrets; if you leave it unset, the Platform Manager pod uses global.imagePullSecrets.
platform-manager:
image:
registry: "registry.axual.io"
pullPolicy: "Always"
tag: "13.0.0"
imagePullSecrets:
- name: axualdockercred
TLS Configuration
You can name the Secrets holding the Privacy Enhanced Mail (PEM) certificates the chart generates the keystores from:
-
Server keypair
-
Client keypair
-
Truststore
The example below sets all three.
platform-manager:
tls:
# -- Enables keystore generation
enabled: true
# -- Creates server keypair from PEM
createServerKeypairSecret: true
# -- PEM used to generate the server keypair if `createServerKeypairSecret` is true
serverCertificatePem: <server-certificate>
# -- PEM used to generate the server keypair if `createServerKeypairSecret` is true
serverKeyPem: <server-key>
# -- Creates client keypair from PEM
createClientKeypairSecret: true
# -- PEM used to generate the client keypair if `createClientKeypairSecret` is true
clientCertificatePem: <client-certificate>
# -- PEM used to generate the client keypair if `createClientKeypairSecret` is true
clientKeyPem: <client-key>
# -- Creates truststore from PEMs
createTruststoreCaSecret: true
# -- Set of PEMs used to generate the truststore if `createTruststoreCaSecret` is true
caCerts:
ca_one.crt: <first-cert>
ca_two.crt: <second-cert>
For the shape each of these Secrets takes, see Secret formats.
Application Configuration
Platform Manager is a Spring Boot application, so it reads its settings from an application.yml file. Whatever you put under config is injected into a ConfigMap and mounted as that file.
platform-manager:
config: {}
Credentials Secret: secrets and existingSecretName
Platform Manager reads a second configuration file, secrets.yml, from a Kubernetes Secret. It takes the same structure as config, is loaded after it, and overrides any key the two share. Map entries merge, so one Tenant-Instance entry can hold its URI in config and its password in the Secret. One Secret holds every credential; the chart has no per-credential or per-Tenant-Instance Secret name.
| Key | Type | Default | Description |
|---|---|---|---|
|
string |
|
Name of an existing Secret in the release namespace, holding a |
|
object |
|
Configuration the chart writes to its own Secret as |
The Platform Manager credential keys that belong in secrets.yml are:
-
spring.datasource.usernameandspring.datasource.password -
governance.vault.roleIdandgovernance.vault.secretId -
axual.connect.instanceConnectCredentials.<TENANT>-<INSTANCE>.usernameand.password -
connectorVault.instances.<TENANT>-<INSTANCE>.roleId,.secretId,.keyStorePassword,.keyPasswordand.truststorePassword -
vault.role-idandvault.secret-id, for a single connector Vault that serves every Tenant-Instance -
axual.organization-manager.keycloak.password -
axual.application-management.apicurio.clientSecretSalt -
axual.application-deployment.connect.log-viewer.password -
ksml-provisioner.password -
spring.mail.password
platform-manager:
existingSecretName: "platform-manager-credentials"
For the procedure, see How to Store Component Credentials in a Kubernetes Secret.
Spring Datasource Configuration
Platform Manager persists Self-Service resources in a database, which it reaches through the standard Spring spring.datasource properties.
platform-manager:
config:
spring:
# Spring Datasource
datasource:
# -- Datasource Name
name: "platform-manager"
# -- Datasource Url with Database
url: "jdbc:mysql://platform-manager-mysql:3306/selfservice-db"
# -- Datasource Username
username: "platform-manager-username"
# -- Datasource Password
password: "<PLATFORM_MANAGER_DB_PASSWORD>"
# -- Datasource Driver Class Name
driver-class-name: "com.mysql.cj.jdbc.Driver"
# Spring JPA
jpa:
# -- Database Platform
database-platform: "org.hibernate.dialect.MySQLDialect"
# Flyway Configuration
flyway:
# -- Flyway Script Location (`mariadb` or `mysql`)
# locations: "classpath:db/migration/mariadb"
locations: "classpath:db/migration/mysql"
Axual and Governance Configuration
The axual and governance entries hold the settings for the Axual services Platform Manager talks to. The example below reads the governance secrets from HashiCorp Vault.
platform-manager:
config:
# Governance Vault Configuration
governance:
vault:
enabled: true
# -- Define the URI of the Vault
uri: "http://platform-manager-vault:8200"
# -- Define the path of the KV Secret in the Vault
path: "governance"
# -- RoleID of the platform-manager policy to access the KV Secret
roleId: "<governance-vault-role-id>"
# -- SecretID of the platform-manager policy to access the KV Secret
secretId: "<governance-vault-secret-id>"
# -- (Optional) The Namespace of the Vault
# namespace: "<governance-vault-namespace>"
Connect Configuration
The axual.connect entry tells Platform Manager how to authenticate against Axual Connect. Define one instance-connect-credentials entry per <tenant>-<instance> pair.
platform-manager:
config:
# Axual Platform Manager
axual:
# Connect Configuration
connect:
# -- Enable Connect Support
available: true
# -- Connect Instance Credentials for each Tenant-Instance
instanceConnectCredentials:
tenant-instance1:
authorizer: basic
username: "<connect-username>"
password: "<connect-password>"
tenant-instance2:
authorizer: basic
username: "<connect-username-2>"
password: "<connect-password-2>"
| Platform Manager reads the Axual Connect URL from the Instance definition in Self-Service. |
Connect Vault Configuration
Each Axual Connect stores its connectors secrets in a HashiCorp Vault, and two Axual Connect installations can use different Vaults, so Platform Manager keeps a separate entry per Tenant-Instance.
platform-manager:
config:
# Connectors Vault Configuration
connectorVault:
# -- Enable Connect Support
enabled: true
# -- Vault Instance for each Tenant-Instance
instances:
tenant-instance1:
# -- The URI of the Vault for the Tenant-Instance
uri: "http://vault-instance:8200"
# -- (Optional) The Namespace of the Vault for the Tenant-Instance
namespace: "<connect-vault-namespace>"
# -- The path of the `connectors` KV secrets defined for the Tenant-Instance
connectorsPath: "connectors"
# -- The RoleID of the Vault policy to access the `connectors` KV secrets for this Tenant-Instance
roleId: "<connect-vault-role-id>"
# -- The SecretID of the Vault policy to access the `connectors` KV secrets for this Tenant-Instance
secretId: "<connect-vault-secret-id>"
# -- The Name identifying the `private.key` of the Connector for the Tenant-Instance
privateKeyName: "private.key"
# -- The Name identifying the `certificate.chain` of the Connector for the Tenant-Instance
certChainKeyName: "certificate.chain"
tenant-instance2:
uri: "http://vault-instance2:8200"
connectorsPath: "connectors"
roleId: "<connect-vault-role-id-2>"
secretId: "<connect-vault-secret-id-2>"
privateKeyName: "private.key"
certChainKeyName: "certificate.chain"
Configuration documented in the Platform Manager Readme
Two configuration areas are generated from the chart and documented in the readme rather than here:
-
Notifications Service Configuration lists the Simple Mail Transfer Protocol (SMTP) settings the notifications service needs.
-
Event Publication Completion Mode Configuration describes the completion modes and their trade-offs.