Skip to main content
Set these in a values file, and install or upgrade with --values values.yaml. The chart checks them against its schema, and refuses settings that don’t make sense before anything is installed.
The schema checks the values below, not the names in your file. A misspelt key, like readonly: true instead of readOnly: true, is ignored without a word, and the setting keeps its default. Check your keys against the names on this page, or in helm show values.
To see the defaults, with a comment on each:

The cluster and its address

string
default:"in-cluster"
What Lumovi calls the cluster: in its pages, their addresses and titles. No slashes or spaces.
string
The address people open Lumovi at, like https://lumovi.example.com. Single sign-on needs it, as the provider sends people back there. With https:, cookies are sent over HTTPS only. And Lumovi accepts sign-ins and connections from pages at this address even when a proxy in front of it changes the Host header. See Security.
string
default:"/"
Where Lumovi is below that address, when it shares a host with other apps: /lumovi, say. The ingress path and health checks follow it. See Give Lumovi an address.

Sign-in

string
default:"token"
How people sign in: token, oidc or proxy.
  • token: with a token the cluster accepts. Each person’s requests carry their own token, and Lumovi’s service account needs no permissions. See Tokens.
  • oidc: with an OpenID Connect provider. Lumovi impersonates whoever signs in, unless auth.oidc.forwardToken is set. See Single sign-on.
  • proxy: behind an authenticating proxy that names people in request headers. Lumovi impersonates them. See Authenticating proxy.
string
The provider’s issuer URL, where /.well-known/openid-configuration is. Required with oidc.
string
Lumovi’s client ID at the provider. Required with oidc.
string
The client’s secret, from which the chart makes a Secret. Leave it empty for a public client, or use existingSecret instead.
string
A Secret in Lumovi’s namespace with the client’s secret under the key client-secret. Takes the place of clientSecret.
string
default:"openid email profile"
The scopes Lumovi asks for, separated by spaces. Add groups if your provider needs it to put groups in the ID token, and offline_access for refresh tokens when passing tokens on.
string
default:"email"
The ID token claim that names people.
string
default:"groups"
The ID token claim that lists their groups.
string
The provider’s name on the sign-in button: Okta makes it Sign in with Okta. Unset, the button says Sign in with single sign-on.
string
id or access: the token people’s requests carry, when the API server trusts the provider itself (its --oidc-* flags, a structured authentication configuration, EKS’s OIDC identity providers…). Lumovi then needs no permissions, and renews tokens with refresh tokens. Unset, it impersonates people. See When the API server trusts the provider.
string
default:"X-Forwarded-User"
The request header in which the proxy names people.
string
default:"X-Forwarded-Groups"
The request header in which the proxy lists their groups, separated by commas.
string
Where signing out of the proxy is, like https://lumovi.example.com/oauth2/sign_out.
string
Put before the names of the users Lumovi impersonates, like the API server’s --oidc-username-prefix: oidc: makes alice@example.com oidc:alice@example.com in RBAC.
string
Put before the names of their groups.
number
default:"12"
How long a session lasts, in hours: more than 0, at most 168 (a week). Sessions live in Lumovi’s memory, so a restart signs people out sooner.

What people can do

boolean
default:"false"
When true, nobody changes anything through Lumovi, whatever their RBAC allows. Each person can also make it read-only for themselves. See Read-only mode.
string
default:"auto"
Where usage history comes from, unless people choose another source in their browser:
  • auto: Lumovi looks for Prometheus or VictoriaMetrics among the cluster’s services.
  • off: no usage history.
  • A service, as namespace/service:port: monitoring/prometheus-operated:9090. For vmselect, with its path after the port: vm/vmselect:8481/select/0/prometheus.
See Usage history.
boolean
default:"false"
When true, charts may come from addresses inside private networks, such as a ChartMuseum or Harbor in your network. When false, Lumovi fetches charts only from public addresses. See Security.
string
default:"https://artifacthub.io"
The Artifact Hub Lumovi searches for charts to install.
object
default:"{}"
Views and add-ons everyone sees, by file name: each key is a file name ending in .yaml or .yml, and its value the file’s contents. See Views for everyone.

Kubernetes objects

boolean
default:"true"
Whether the chart makes Lumovi’s service account.
string
The service account’s name: the release’s full name unless set. Required when serviceAccount.create is false.
object
default:"{}"
Annotations for the service account.
boolean
default:"true"
Whether the chart lets Lumovi’s service account impersonate users and groups, which it needs with oidc (unless tokens are passed on) and proxy. In other modes, the chart makes no RBAC objects either way. Set it to false to manage that permission yourself.
integer
default:"1"
How many Lumovi pods to run. Sessions live in each pod’s memory, and single sign-on has to finish on the pod it started on: more than one needs sticky sessions.
string
default:"ClusterIP"
ClusterIP, NodePort or LoadBalancer.
integer
default:"80"
The Service’s port. Lumovi itself listens on 8080.
object
default:"{}"
Annotations for the Service.
boolean
default:"false"
Whether the chart makes an Ingress for Lumovi.
string
The Ingress’ class, like nginx.
string[]
default:"[lumovi.example.com]"
The hosts to serve Lumovi at, each with one rule for basePath.
object[]
default:"[]"
The Ingress’ tls, as it is: [{ secretName: lumovi-tls, hosts: [lumovi.example.com] }].
object
default:"{}"
Annotations for the Ingress. Pages keep a WebSocket open, so give the ingress controller a long read timeout, like nginx.ingress.kubernetes.io/proxy-read-timeout: "3600".
boolean
default:"false"
Whether the chart makes a NetworkPolicy that only lets in what networkPolicy.from allows, on Lumovi’s port. Behind a proxy, use it to let in only the proxy.
object[]
default:"[]"
The NetworkPolicy’s from: who may reach Lumovi. Empty, anything may, on Lumovi’s port. A podSelector on its own matches pods in Lumovi’s namespace only: for pods in another namespace, add a namespaceSelector to the same entry, as in A proxy in another namespace.

The pod

string
default:"ghcr.io/lumovi/lumovi"
The image to run.
string
The image’s tag: the chart’s appVersion unless set. Each chart is released with Lumovi, and its version and appVersion are the same, so the chart installs the image of its own version.
string
default:"IfNotPresent"
Always, IfNotPresent or Never.
object[]
default:"[]"
Secrets for pulling the image, for a copy in a private registry.
object
The container’s resources. By default it requests 50m of CPU and 128Mi of memory, and is limited to 512Mi of memory.
object
The pod’s security context. By default: non-root, as user and group 65532, with fsGroup 65532 too, and the RuntimeDefault seccomp profile.
object
The container’s security context. By default: no privilege escalation, a read-only root filesystem, and every capability dropped.
object[]
default:"[]"
More environment variables, as a container’s env. See Configuration for the ones Lumovi reads. They come after the chart’s own, and Kubernetes uses the last of two with the same name, so leave out LUMOVI_PORT and LUMOVI_VIEWS_DIR: see Set by the chart itself.
object
default:"{}"
Annotations for the pod.
object
default:"{}"
Labels for the pod.
object
default:"{}"
The pod’s node selector.
object[]
default:"[]"
The pod’s tolerations.
object
default:"{}"
The pod’s affinity.
string
The pod’s priority class.
string
Replaces the chart’s name in the objects’ names.
string
Replaces the objects’ full name. Installed as lumovi, they’re all called lumovi.

Configuration

The environment variables the chart sets, for running the image another way.

Install

Install or upgrade with a values file.