Skip to main content
The Helm chart sets these from its values. They’re for running the image another way, such as with Docker, and for the few settings the chart has no value for, which you can set with extraEnv. Lumovi reads them when it starts, and checks most of them: one that doesn’t make sense stops it, and its log says which and why. A few aren’t checked. LUMOVI_READ_ONLY and LUMOVI_ALLOW_PRIVATE_CHARTS are on only when they’re exactly true or 1, and anything else leaves them off. LUMOVI_MAX_LIST_ITEMS and LUMOVI_REQUEST_TIMEOUT_MS keep their defaults when they aren’t numbers. LUMOVI_HELM and LUMOVI_ARTIFACT_HUB_URL are used as they are, so a wrong one shows up only when someone uses Helm.

Set by the chart itself

The chart sets two of these without a value of its own: LUMOVI_PORT to 8080, the port its Service, probes and network policy point at, and LUMOVI_VIEWS_DIR to /etc/lumovi/views, where it mounts the views everyone sees. Leave both out of extraEnv. The chart puts extraEnv after its own variables. When two have the same name, Kubernetes uses the last, so a variable repeated in extraEnv wins over the chart’s. For the two above, that breaks Lumovi: it listens on a port nothing sends to, or reads views from a folder the chart doesn’t mount. For the others, set the chart’s value instead. The chart builds more than the variable on its values, like the permission to impersonate for auth.mode, or the probes and the ingress path for basePath, while a variable in extraEnv changes only Lumovi.

Where it runs

number
default:"8080"
The port to listen on, from 0 to 65535. 0 picks any free port, and the log says which. The chart sets it to 8080 itself.
string
The address to listen on: every interface unless set.
string
The address people open it at, like https://lumovi.example.com: an http or https URL. Single sign-on needs it. With https:, cookies are sent over HTTPS only.It’s also an origin Lumovi accepts sign-ins, sign-outs and pages’ connections from, besides the host each request is sent to. Set it when a proxy in front of Lumovi changes the Host header. See Security.
string
default:"/"
Where it is below that address, like /lumovi. Each part of the path can have letters, digits, _, ., ~ and -.

The cluster it shows

string
What it calls the cluster: in-cluster (or the kubeconfig’s context) unless set.
string
A kubeconfig to show a cluster from, instead of the cluster Lumovi runs in.
string
The kubeconfig’s context to show: its current context unless set. A context the kubeconfig doesn’t have stops Lumovi.
string
default:"/var/run/secrets/kubernetes.io/serviceaccount"
Where the pod’s service account token and CA certificate are, inside a cluster. Lumovi needs the token there even when people sign in with their own tokens, and stops without it. The chart always mounts it.
string
Where the API server is, inside a cluster, with KUBERNETES_SERVICE_PORT. Kubernetes sets both in every pod: you don’t. Without KUBERNETES_SERVICE_HOST or KUBECONFIG, Lumovi stops, saying it isn’t running in a cluster.

Sign-in

string
default:"token"
token, oidc or proxy. See Ways to sign in.
string
The OpenID Connect provider’s issuer URL, http or https. Required with oidc.
string
Lumovi’s client ID at the provider. Required with oidc.
string
The client’s secret. Unset for a public client.
string
default:"openid email profile"
The scopes to ask for, separated by spaces.
string
default:"email"
The ID token claim that names people.
string
default:"groups"
The ID token claim that lists their groups.
string
default:"single sign-on"
The provider’s name on the sign-in button: Sign in with this.
string
id or access: pass people’s own token on (the API server must trust the provider) instead of impersonating them. The token must be a JWT that says when it expires.
string
default:"X-Forwarded-User"
The header a proxy names people in. Upper and lower case don’t matter.
string
default:"X-Forwarded-Groups"
The header a proxy lists their groups in, separated by commas.
string
Where signing out of the proxy is: an http or https URL.
string
Put before impersonated users’ names.
string
Put before impersonated groups’ names.
number
default:"12"
How long sessions last, in hours: more than 0, at most 168, a week.
number
default:"30"
How often pages’ connections are checked, in seconds, at most 3600. Keep it shorter than the idle timeout of the proxies in front of Lumovi.

What people can do

boolean
default:"false"
true or 1: nobody changes anything through Lumovi. Anything else leaves changes on.
string
default:"auto"
Where usage history comes from unless people choose: auto, off, or namespace/service:port, with a path after it for vmselect (vm/vmselect:8481/select/0/prometheus).
boolean
default:"false"
true or 1: charts may come from private network addresses.
string
default:"https://artifacthub.io"
Where to search for charts.
string
default:"/etc/lumovi/views"
Where the views and add-ons everyone sees are. The chart sets it itself, to the folder it mounts its views value at.
string
default:"helm"
The helm to run: helm on the PATH unless set. The image sets it to /usr/local/bin/helm, the helm it comes with.

Large clusters and slow API servers

These work the same as in the desktop app, and the chart has no values for them: set them with extraEnv.
number
default:"5000"
The most objects a list loads. Lists are fetched in chunks of 500.
number
default:"20000"
How long the API server has to answer, in milliseconds.
values.yaml

Addresses it answers

All of these are below the base path. Whatever stands in front of Lumovi must pass them all through. Any other address below the base path is Lumovi’s page or one of its files, for GET and HEAD. Other methods get 405, and other addresses under api/ and auth/ get 404. Addresses outside the base path get 404, with a note saying where Lumovi is. The base path without its trailing slash, like /lumovi, leads to /lumovi/.

Helm values

The chart’s settings, which set these for you.

Run it with Docker

Use these to run the image outside Kubernetes.