nplus-component-web#

nscale Web, providing a modern Web UI to nscale users

tls / https#

nscale Web is not automatically enabling tls / https and also does currently not automatically generate a certificate for tls.

However, the nplus Web Chart does, and stores it in conf/keystore.jks. Additionally, if there is no server.xml in the conf directory, nplus copies a custom server.xml to conf, that has tls enabled and references conf/keystore.jks.

If you already have a running web componenent, and want to use tls with web, you will need to edit this file manually. See ITSMSD-8772.

nplus-component-web Chart Configuration#

You can customize / configure nplus-component-web by setting configuration values on the command line or in values files, that you can pass to helm. Please see the samples directory for details.

In case there is no value set, the key will not be used in the manifest, resulting in values taken from the config files of the component.

Template Functions#

You can use template functions in the values files. If you do so, make sure you quote correctly (single quotes, if you have double quotes in the template, or escaped quotes).

Global Values#

All values can be set per component, per instance or globally per environment.

Example: global.ingress.domain sets the domain on instance level. You can still set a different domain on a component, such as administrator. In that case, simply set ingress.domain for the administrator chart and that setting will have priority:

  • Prio 1 - Component Level: ingress.domain
  • Prio 2 - Instance Level: global.ingress.domain
  • Prio 3 - Environment Level: global.environment.ingress.domain

Using Values in Templates#

As it would be a lot of typing to write .Values.ingress.domain | default .Values.global.ingress.domain | default .Values.global.environment.ingress.domainin your template code, this is automatically done by nplus. You can simply type .this.ingress.domain and you will get a condensed and defaulted version of your Values.

So an example in your values.yaml would be:

administrator:
  waitFor:
    - '-service {{ .component.prefix }}nappljobs.{{ .Release.Namespace }}.svc.cluster.local:\{{ .this.nappl.port }} -timeout 600'

This example shows .this.nappl.port which might come from a component, instance or global setting. You do not need to care. The .Release.Namespace is set by helm. You have access to all Release and Chart Metadata, just like in your chart code.

The .component.prefix is calculated by nplus and gives you some handy shortcuts to internal variables:

  • .component.chartName The name of the chart as in .Chart.Name, but with override by .Values.nameOverride

  • .component.shortChartName A shorter Version of the name - nappl instead of nplus-component-nappl

  • .component.prefix The instance Prefix used to name the resources including -. This prefix is dropped, if the .Release.Name equals .Release.Namespace for those of you that only run one nplus Instance per namespace

  • .component.name The name of the component, including .Values.nameOverride and some logic

  • .component.fullName The fullName inlcuding .Values.fullnameOverride and some logic

  • .component.chart Mainly the Chart.Name and Chart.Version

  • .component.storagePath The path where the component config is stored in the conf PVC

  • .component.handler The handler (either helm, argoCD or manual)

  • .instance.name The name of the instance, but with override by .Values.instanceOverride

  • .instance.group The group, this instance belongs to. Override by .Values.groupOverride

  • .instance.version The nscale version (mostly taken from Application Layer), this instance is deploying.

  • .environment.name The name of the environment, but with override by .Values.environmentNameOverride

Keys#

You can set any of the following values for this component:

KeyDescriptionDefault
authTypeSet the authentication type login, basic, negotiate, implicit ntlmv2, kerberos
customizingModeIf this setting is enabled, layouts will update immediately when changes are made. It is no longer necessary to re-register or restart the service. If this setting is not activated, the automatic update of the metamodel is turned off. We recommend not using this setting in productive systems because it reduces system performance.
disableUsernamePasswordsurpresses the login dialog
envSets additional environment variables for the configuration.
envMapSets the name of a configMap, which holds additional environment variables for the configuration. It is added as envFrom configMap to the container.
envSecretSets the name of a secret, which holds additional environment variables for the configuration. It is added as envFrom secretRef to the container.
fullnameOverrideThis overrides the output of the internal fullname function
image​.namethe name of the image to use"application-layer-web"
image​.pullSecretsyou can provide your own pullSecrets, in case you use a private repo.["nscale-cr", "nplus-cr"]
image​.repoif you use a private repo, feel free to set it here"ceyoniq.azurecr.io/release/nscale"
image​.tagthe tag of the image to use"latest"
immediateFederatedLogindirectly log in via identity providers
ingress​.annotationsAdds extra Annotations to the ingress
ingress​.backendsets the ingress controller backend template behavior (nginx or traefik)nginx
ingress​.backendProtocolOverrides the default backend protocol. The default is http, unless in zeroTrust Mode, then it is switched to https automatically.http
https in zero trust mode
ingress​.classThe ingressclass to use for this ingress. Most likely, this is provided globally by the instance, but you are free to override it here if this component should use a different class e.g. if you have separated ingress controllers, like a public and an internal onepublic
ingress​.contextPathThe default service context path for this ingress. Some components allow to change this (e.g. SharePoint), for the most though this is only a constant used in the scripts."/nscale_web"
ingress​.cookieon component level, set cookie affinity for the ingress example: XtConLoadBalancerSession for nscale Web"XtConLoadBalancerSession"
ingress​.createSelfSignedCertificateGenerates a self signed certificate when no issuer is set. Within an instance or an environment the umbrella chart owns the certificate; a component deployed on its own renders it itself, so that its ingress does not point at a secret nobody creates. The certificate is regenerated on every render.true
ingress​.denydeny is used to exclude specific paths from public access, such as administrative paths. For Example, in nappl, webc ist the hessian protocol, webb is the burlap protocol. The configuration service is the endpoint used by the Admin client.
ingress​.domainSets the domain to be used. This domain should be provided by the instance globally for all components, but you are free to override it here
ingress​.enabledYou can toggle the ingress on wether you’d like this component to be reachable through an ingress or not.true
ingress​.labelsAdds extra labels to everything the ingress path creates - the Ingress itself as well as the Traefik CRs (IngressRoute, Middleware, ServersTransport) and the Gateway API objects (Gateway, HTTPRoute). Needed where an admission policy enforces labels on these objects, for example traefik-scope: internal
ingress​.namespaceSpecify the namespace in which the ingress controller runs. This sets the firewall rule / networkPolicy to allow traffic from this namespace to our pods. This may be a comma separated list“ingress, kube-system, ingress-nginx, nginx-gateway”
ingress​.providerset the provider to ingress, traefik or gateway, depending on what type you prefer. ingress renders a classic Ingress object per component, traefik renders ONE central IngressRoute per instance with shared middlewares (see the instance chart), gateway renders Gateway API HTTPRoutes.ingress
ingress​.proxyReadTimeoutSets the annotation nginx.ingress.kubernetes.io/proxy-read-timeout on the ingress object, if set. This is an annotation for nginx, so won’t work with other ingress controllers, like Traefik.
ingress​.sameSiteon component level, if you set cookie affinity, you can also set the sameSite setting (to strict, lax or none)
ingress​.secretSets the name of the tls secret to be used for this ingress, that contains the private and public key. These secrets can optionally be provided by the instance{{ .this.ingress.domain }}-tls
ingress​.traefik​.cors​.addVaryHeaderadds the Vary: Origin response headertrue
ingress​.traefik​.cors​.allowCredentialswhether credentials are allowedtrue
ingress​.traefik​.cors​.allowHeaderslist of allowed request headersAuthorization, Content-Type
ingress​.traefik​.cors​.allowMethodslist of allowed methodsGET, POST, PUT, DELETE, OPTIONS
ingress​.traefik​.cors​.allowOriginslist of allowed origins, e.g. - https://apps.example.com
ingress​.traefik​.cors​.enabledmaster switch for the CORS middleware of this component
ingress​.traefik​.cors​.maxAgebrowser preflight cache duration in seconds600
ingress​.traefik​.maxRequestBodyBytesComponent override for the request body limit in bytes. Renders a dedicated buffering middleware for this component, in addition to a possible instance wide limit (global.ingress.traefik.maxRequestBodyBytes)
ingress​.traefik​.middlewaresAttaches additional existing middlewares to this component’s route. A list of name (+ optional namespace) refs, so you can bring your own middlewares without disabling the nplus routing
ingress​.traefik​.rateLimit​.averageallowed average requests per period100
ingress​.traefik​.rateLimit​.burstallowed burst200
ingress​.traefik​.rateLimit​.enabledmaster switch for the rate limit middleware of this component
ingress​.traefik​.rateLimit​.periodthe period the average applies to1s
ingress​.traefik​.responseHeaderTimeoutComponent override for the upstream response header timeout. Renders a dedicated ServersTransport for this component instead of the shared instance wide one (global.ingress.traefik.responseHeaderTimeout)
ingress​.traefik​.stickyAdditional sticky cookie settings, merged over the defaults derived from ingress.cookie and ingress.sameSite. Accepts any field of the traefik sticky cookie, e.g. maxAge: 86400 or path: /nscale_web
ingress​.whitelistoptionally sets a whitelist of ip ranges (CIDR format, comma separated) from which ingress is allowed. This is an annotation for nginx, so won’t work with other ingress controllers
initContainersOptional hook to add your own init containers to any of the components. Will be omitted if empty. Example: initContainers: - name: myInit image: myImage command: [ “/startup.sh” ]{}
javaOpts​.javaMaxMemset the maximum memory, java will consume. Attention: This is NOT the real maximum and it does not include any non Java memory. Please read google, as this is highly discussed
javaOpts​.javaMaxRamPercentageset the percentage of RAM, Java will use of the total. The total amount is the amount installed in the K8s Cluster Node, OR the Memory Limit set (see resources), if any.
javaOpts​.javaMinMemset the minimum memory, java will consume
javaOpts​.javaMiscAny misc Java Options that need to be passed to the container
meta​.languageSets the language of the main service (in the service container). This is used for instance if you turn OpenTelemetry on, to know which Agent to inject into the container."java"
meta​.ports​.httpThe http port this component uses (if any). In zero trust mode, this will be disabled.
this is a constant value of the component and should not be changed.
info only, do not change
8090
meta​.ports​.httpsThe tls / https port, this component uses (if any)
this is a constant value of the component and should not be changed.
info only, do not change
8453
meta​.providersets provider (partner, reseller) information to be able to invoice per use in a cloud environment
meta​.serviceContainerThe container name of the main service for this component. This is used to define where to inject the telemetry agents, if any"web-client"
meta​.stageA optional parameter to indicate the stage (DEV, QA, PROD, …) this component, instance or environment runs in. This can be used in template functions to add the stage to for instance the service name of telemetry services like open telemetry. (see telemetry example)
meta​.tenantsets tenant information to be able to invoice per use in a cloud environment
meta​.typethe type of the component. You should not change this value, except if you use a pipeliner in core mode. In core mode, it should be core, else pipeliner This type is used to create cluster communication for nappl and nstl and potentially group multiple replicaSets into one service."web"
meta​.waveSets the wave in which this component should be deployed within an ArgoCD deployment if unset, it uses the default wave thus all components are installed in one wave, then relying on correct wait settings just like in a helm installation
metamodelModeRefreshes the metamodel mode
minReplicaCountif you set minReplicaCount, a podDesruptionBudget will be created with this value as minAvailable, using the full component as selector. This is useful for components, that are using multiple replicas.
minReplicaCountTypeif you set minReplicaCountType, a podDesruptionBudget will be created with this value as minAvailable, using the component type as selector. This is useful for components, that are spread across multiple replicaSets, like sharepoint or storage layer
mounts​.caCerts​.configMapAlternative 2: the name of the configMap to use. The Key has to be the File Name used in the path setting
mounts​.caCerts​.secretAlternative 1: the name of the secret to use. The Key has to be the File Name used in the path setting
mounts​.componentCerts​.configMapAlternative 2: the name of the configMap to use. The Key has to be the File Name used in the path setting
mounts​.componentCerts​.secretAlternative 1: the name of the secret to use. The Key has to be the File Name used in the path setting
mounts​.conf​.pathSets the path to the conf files
do not change this value
info only, do not change
"/opt/ceyoniq/nscale-server/application-layer-web/conf"
mounts​.data​.classSets the class of the data disk
mounts​.data​.sizeSets the size of the data disk
mounts​.data​.volumeNameIf you do not want to have a Volume created by the provisioner, you can set the name of your volume here to attach to this pre-existing one
mounts​.defaultConfigSets a configMap with default configuration files that get copied to a new and empty container just before the template folder gets copied. Existing files are not overwritten."{{ .component.fullName }}-defaultconfig"
mounts​.disk​.classSets the class of the disk
mounts​.disk​.enabledenables the use of the second data disk. If enabled, all paths defined will end up on this disk. In case of the (default) disabled, the paths will be added to the primaty data disk.false
mounts​.disk​.migrationEnables the migration init container. This will copy the data in paths from the primary data disk to the newly enabled secondary disk. This is done only once and only if there is legacy data at all. No files are overwritten!false
mounts​.disk​.sizeSets the size of the disk
mounts​.disk​.volumeNameIf you do not want to have a Volume created by the provisioner, you can set the name of your volume here to attach to this pre-existing one
mounts​.file​.classSets the class of the shared disk
mounts​.file​.sizeSets the size of the shared disk
mounts​.file​.volumeNameIf you do not want to have a Volume created by the provisioner, you can set the name of your volume here to attach to this pre-existing one
mounts​.genericAllows to define generic mounts of pre-provisioned PVs into any container. This can be used e.g. to mount migration nfs, cifs / samba shares into a pipeliner container.
mounts​.logs​.mediumthe medium for the emptyDisk volume if you unset it, it drops it from the manifest
mounts​.logs​.pathSets the path to the log files
do not change this value
info only, do not change
"/opt/ceyoniq/nscale-server/application-layer-web/apache/logs/"
mounts​.logs​.sizeSets the size of the log disk (all paths)"5Gi"
mounts​.temp​.mediumSets the medium of the temporary disk (all paths) optionally to Memory, which will create an in-memory tmpfs volume. This is useful for very fast temporary storage, but be aware that the data will be lost when the pod terminates and that it will consume memory resources of the node.
mounts​.temp​.pathsSets a list of paths to the temporary files
do not change this value
info only, do not change
["/opt/ceyoniq/nscale-server/application-layer-web/apache/work/Catalina/localhost", "/opt/ceyoniq/nscale-server/application-layer-web/apache/conf/Catalina/localhost", "/opt/ceyoniq/nscale-server/application-layer-web/apache/webapps", "/opt/ceyoniq/nscale-server/application-layer-web/apache/temp"]
mounts​.temp​.sizeSets the size of the temporary disk (all paths)"1Gi"
nameOverrideThis overrides the output of the internal name function
nappl​.accountThe technical account to login with
nappl​.domainThe domain of the technical account
nappl​.hostnappl host name
nappl​.instanceinstance of the Application Layer, likely instance1
nappl​.passwordThe password of the technical accunt (if not set by secret)
nappl​.portnappl port (http 8080 or https 8443)
nappl​.secretAn optional secret that holds the credentials (the keys must be account and password)
nappl​.sslsets the Advanced Connect to tls
nodeSelectorselect specific nodes for this component
oauthDomainsOAuth nscale domains
priority​.classNameSet the priority class for the Application Layer deployment if desired
priority​.createClassCreates an individual PriorityClass for this instance
priority​.valueSets the priorityValue1000000
probesOptional means to override the default probes of the main container of the component
replicaCountSets the number of replicas in this replicaSet. Some Components (like nstl or sharepoint) only allow a count of 1.1
resources​.limits​.cpuThe maximum allowed CPU for the container
resources​.limits​.memoryThe maximum allowed RAM for the container
resources​.requests​.cpuSet the share of guaranteed CPU to the container.
resources​.requests​.memorySet the share of guaranteed RAM to the container
revisionHistoryLimitThe revisionHistoryLimit sets the number of old revisions to keep in the deployment history for rollbacks of the deployment. K8s default is 10. Leave this empty to use the default.
sameSitenscale SameSite Cookie Header
samlDomainsSAML nscale domains
security​.containerSecurityContext​.allowPrivilegeEscalationSome functionality may need the possibility to allow privilege escalation. This should be very restrictive
you should not change this
info only, do not change
false
security​.containerSecurityContext​.readOnlyRootFilesystemsets the container root file system to read only. This should be the case in production environment
you should not change this
info only, do not change
true
security​.podSecurityContext​.fsGroupThe file system group as which new files are created
there is normally no need to change this
info only, do not change
1001
security​.podSecurityContext​.fsGroupChangePolicyUnder which condition should the fsGroup be changed
there is normally no need to change this
info only, do not change
"OnRootMismatch"
security​.podSecurityContext​.runAsUserThe user under which the container ist run. Avoid 0 / root. The container should run in a non-root context for security
there is normally no need to change this
info only, do not change
1001
security​.zeroTrustturns on Zero Trust Mode, disabling all http communication, even the internal http probesfalse
service​.annotationsadds extra Annotations to the service
service​.enabledenables the service to be consumed by group components and a potential ingress Disabling the service also disables the ingress.true
service​.selectorThe selector can be component or type component selects only pods that are in the replicaset. type selects any pod that has the given type"component"
smartCrossgradeEnable Crossgrade for Smart Layouts
telemetry​.openTelemetryturns Open Telemetry on
telemetry​.serviceNameSets the service name for the telemetry service to more convenient identify the displayed component Example: “{{ .this.meta.type }}-{{ .instance.name }}”
template​.annotationsset additional annotations for pods
template​.labelsset additional labels for pods
terminationGracePeriodSecondsSets the terminationGracePeriodSeconds for the component If not set, it uses the Kubernetes defaults
timezoneset the time zone for this component to make sure log output has a specific timestamp, internal dates and times are correct (like the creationDate in nappl) etc.Europe/Berlin
tolerationsSet tolerations for this component
updateStrategythe update Strategy for this component. Normally, you can update all components rolling, except for nappl, where you need to follow the documented update procedures.
utils​.debugTurn debugging on will give you stack trace etc. Please check out the Chart Developer Guidefalse
utils​.disableWaitin case you use the argoCD Wave feature, you might think about switching off the waitFor mechanism, that makes sure PODs are only started after pre-requisites are fulfilled. You can disable the starndard wait mechanism, but at your own risk, as this might start components even if they are not intended to run yet.false
utils​.disableWaveIf you use argoCD, you most likely want to use the argo Wave Feature as well, making sure the components of an instance are deployed ordered. However, in DEV you might want to disable this to allow live changing components while previous waves are not finished yet.false
utils​.includeNamespaceBy default, the namespace is rendered into the manifest. However, if you want to use helm template and store manifests for later applying them to multiple namespaces, you might want to turn this false to be able to use kubectl apply -n <namespace> -f template.yaml latertrue
utils​.maintenancein Maintenance Mode, all waitFor actions will be skipped, the Health Checks are ignored and the pods will start in idle, not starting the service at all. This will allow you to gain access to the container to perform recovery and maintenance tasks while having the real container up.false
utils​.renderCommentsYou can turn Comment rendering on to get descriptive information inside the manifests. It will also fail on depricated functions and keys, so it is recommended to only switch it off in PRODtrue
waitForDefines a list of conditions that need to be met before this components starts. The condition must be a network port that opens, when the master component is ready. Mostly, this will be a service, since a component is only added to a service if the probes succeed.