Mojo UpDocs
Self-hosted AIOE

Helm values

Every value of the aioe Helm chart, with its default and what it sets.

The values of the aioe chart, version 0.1.0. Set them in your own values.yaml and pass it with -f. The chart deploys the API and the console only; PostgreSQL and Redis are yours to provide. How to use the chart is in Install with Helm.

Images

ValueDefaultWhat it sets
image.registryghcr.io/mojo-upRegistry both images are pulled from.
image.apiaioe-apiName of the API image.
image.consoleaioe-consoleName of the console image.
image.tag0.1.0Tag of both images.
image.pullPolicyIfNotPresentKubernetes pull policy for both.

API

ValueDefaultWhat it sets
api.replicas2Number of API pods. More than one needs REDIS_URL and a shared AIOE_SIGNING_KEY in the secret.
api.publicUrlhttps://aioe.example.comPUBLIC_URL: the address workbenches, nodes and phones use for the API.
api.consoleUrlhttps://console.aioe.example.comCONSOLE_URL: the console's address, used in the links the API hands out (such as the enrolment page).
api.storepostgresSTORE. Keep postgres; memory loses everything on restart.
api.env{ AIOE_ENVIRONMENT: production }Extra plain environment variables for the API, as a map. Use it for OTEL_EXPORTER_OTLP_ENDPOINT and other non-secret settings from Environment variables.
api.existingSecretaioe-apiName of an existing Secret whose every key becomes an environment variable of the API: DATABASE_URL, REDIS_URL, and keys such as AIOE_SIGNING_KEY and AIOE_SECRETS_KEY. Optional: the pod starts without it, but then has no database.
api.resources.requestscpu: 100m, memory: 256MiAPI pod requests.
api.resources.limitscpu: "1", memory: 512MiAPI pod limits.

The chart always sets PORT=3001 on the API.

Console

ValueDefaultWhat it sets
console.replicas2Number of console pods.
console.resources.requestscpu: 50m, memory: 64MiConsole pod requests.
console.resources.limitscpu: 200m, memory: 128MiConsole pod limits.

The console takes no runtime settings: the API's address is built into its image.

Your organisation

These become the AIOE_BOOTSTRAP_* variables, applied each time the API starts. See Connect your identity provider.

ValueDefaultWhat it sets
bootstrapTenant.enabledtrueWhether to set the variables below at all.
bootstrapTenant.slugmojoupAIOE_BOOTSTRAP_TENANT: your organisation's short name.
bootstrapTenant.organisationMojo UpAIOE_BOOTSTRAP_ORGANISATION: its display name.
bootstrapTenant.domainsmojoup.com.auAIOE_BOOTSTRAP_DOMAINS: your email domains, comma separated, plus the API's host name if it is not under one of them.
bootstrapTenant.oidcIssuerMojo Up's Entra issuerAIOE_BOOTSTRAP_OIDC_ISSUER.
bootstrapTenant.oidcAudienceMojo Up's API registrationAIOE_BOOTSTRAP_OIDC_AUDIENCE.
bootstrapTenant.oidcClientIdMojo Up's client registrationAIOE_BOOTSTRAP_OIDC_CLIENT_ID.
bootstrapTenant.apiScopeapi://aioe.mojoup.com.au/accessAIOE_BOOTSTRAP_API_SCOPE.

The defaults are Mojo Up's own organisation and app registrations. Set every bootstrapTenant value to your own.

Ingress

ValueDefaultWhat it sets
ingress.enabledtrueWhether to create the Ingress.
ingress.classNamenginxingressClassName.
ingress.annotationsnginx.ingress.kubernetes.io/proxy-read-timeout: "3600", nginx.ingress.kubernetes.io/proxy-buffering: "off"Annotations on the Ingress. These keep the relay's streams open and unbuffered; set the equivalent for another controller.
ingress.apiHostaioe.example.comHost routed to the API.
ingress.consoleHostconsole.aioe.example.comHost routed to the console.
ingress.tlsone entry, secret aioe-tls, both hostsThe Ingress tls block, as is.

Fixed by the chart

SettingValue
API container port3001, named http
Console container port8080, named http
Service ports80, to the container's http port
API readiness probeGET /readyz, every 10 s
API liveness probeGET /healthz, every 30 s
Console readiness probeGET /healthz, every 10 s
API pod securitynon-root, RuntimeDefault seccomp, no privilege escalation, read-only root file system, all capabilities dropped
Labelsapp.kubernetes.io/name, instance, version (the chart's app version) and managed-by

On this page