Self-hosted AIOE
Helm values
Every value of the aioe Helm chart, with its default and what it sets.
The values of the aioe chart, version 0.1.0. Set them in your own values.yaml and pass it with -f. The chart deploys the API and the console only; PostgreSQL and Redis are yours to provide. How to use the chart is in Install with Helm.
Images
| Value | Default | What it sets |
|---|---|---|
image.registry | ghcr.io/mojo-up | Registry both images are pulled from. |
image.api | aioe-api | Name of the API image. |
image.console | aioe-console | Name of the console image. |
image.tag | 0.1.0 | Tag of both images. |
image.pullPolicy | IfNotPresent | Kubernetes pull policy for both. |
API
| Value | Default | What it sets |
|---|---|---|
api.replicas | 2 | Number of API pods. More than one needs REDIS_URL and a shared AIOE_SIGNING_KEY in the secret. |
api.publicUrl | https://aioe.example.com | PUBLIC_URL: the address workbenches, nodes and phones use for the API. |
api.consoleUrl | https://console.aioe.example.com | CONSOLE_URL: the console's address, used in the links the API hands out (such as the enrolment page). |
api.store | postgres | STORE. Keep postgres; memory loses everything on restart. |
api.env | { AIOE_ENVIRONMENT: production } | Extra plain environment variables for the API, as a map. Use it for OTEL_EXPORTER_OTLP_ENDPOINT and other non-secret settings from Environment variables. |
api.existingSecret | aioe-api | Name of an existing Secret whose every key becomes an environment variable of the API: DATABASE_URL, REDIS_URL, and keys such as AIOE_SIGNING_KEY and AIOE_SECRETS_KEY. Optional: the pod starts without it, but then has no database. |
api.resources.requests | cpu: 100m, memory: 256Mi | API pod requests. |
api.resources.limits | cpu: "1", memory: 512Mi | API pod limits. |
The chart always sets PORT=3001 on the API.
Console
| Value | Default | What it sets |
|---|---|---|
console.replicas | 2 | Number of console pods. |
console.resources.requests | cpu: 50m, memory: 64Mi | Console pod requests. |
console.resources.limits | cpu: 200m, memory: 128Mi | Console pod limits. |
The console takes no runtime settings: the API's address is built into its image.
Your organisation
These become the AIOE_BOOTSTRAP_* variables, applied each time the API starts. See Connect your identity provider.
| Value | Default | What it sets |
|---|---|---|
bootstrapTenant.enabled | true | Whether to set the variables below at all. |
bootstrapTenant.slug | mojoup | AIOE_BOOTSTRAP_TENANT: your organisation's short name. |
bootstrapTenant.organisation | Mojo Up | AIOE_BOOTSTRAP_ORGANISATION: its display name. |
bootstrapTenant.domains | mojoup.com.au | AIOE_BOOTSTRAP_DOMAINS: your email domains, comma separated, plus the API's host name if it is not under one of them. |
bootstrapTenant.oidcIssuer | Mojo Up's Entra issuer | AIOE_BOOTSTRAP_OIDC_ISSUER. |
bootstrapTenant.oidcAudience | Mojo Up's API registration | AIOE_BOOTSTRAP_OIDC_AUDIENCE. |
bootstrapTenant.oidcClientId | Mojo Up's client registration | AIOE_BOOTSTRAP_OIDC_CLIENT_ID. |
bootstrapTenant.apiScope | api://aioe.mojoup.com.au/access | AIOE_BOOTSTRAP_API_SCOPE. |
The defaults are Mojo Up's own organisation and app registrations. Set every bootstrapTenant value to your own.
Ingress
| Value | Default | What it sets |
|---|---|---|
ingress.enabled | true | Whether to create the Ingress. |
ingress.className | nginx | ingressClassName. |
ingress.annotations | nginx.ingress.kubernetes.io/proxy-read-timeout: "3600", nginx.ingress.kubernetes.io/proxy-buffering: "off" | Annotations on the Ingress. These keep the relay's streams open and unbuffered; set the equivalent for another controller. |
ingress.apiHost | aioe.example.com | Host routed to the API. |
ingress.consoleHost | console.aioe.example.com | Host routed to the console. |
ingress.tls | one entry, secret aioe-tls, both hosts | The Ingress tls block, as is. |
Fixed by the chart
| Setting | Value |
|---|---|
| API container port | 3001, named http |
| Console container port | 8080, named http |
| Service ports | 80, to the container's http port |
| API readiness probe | GET /readyz, every 10 s |
| API liveness probe | GET /healthz, every 30 s |
| Console readiness probe | GET /healthz, every 10 s |
| API pod security | non-root, RuntimeDefault seccomp, no privilege escalation, read-only root file system, all capabilities dropped |
| Labels | app.kubernetes.io/name, instance, version (the chart's app version) and managed-by |