Skip to content
Stackship documentation Svenska

BlueprintsUsers

Parameters

The parameter types a blueprint template can declare, their attributes, how secrets are generated and derived, and how the deploy wizard shows each one.

Attributes

Each entry in a template's parameters list has:

Attribute Content
name Required and unique in the template. Tokens refer to it as [%<name>%], and a Secret parameter is stored in the vault under this name
type One of the types below
label The field's label in the wizard
description Help text under the field
default The value used when the deployer leaves the field empty. May contain tokens
options Select only: the values offered
advanced true puts the field under Advanced settings, collapsed
generate, generateLength, generateSpec, generateClaims Generate the value when none is given — see Generated values
derived Compose the value from other parameters — see Derived values
capability DeploymentSource only, and required there: ImagePull
documentation A URL about this parameter
required Marks the field as required in the wizard
validation pattern, a regular expression, and message

Neither required nor validation is enforced when a blueprint is deployed today: the portal marks a required field but submits without it, and the pattern is stored but never checked. Give a parameter a working default rather than relying on them.

Types

Every value is passed as a string.

Type Holds In the wizard
String Text A text field; the placeholder shows the default with the instance name filled in
Secret A sensitive value. Written to the instance vault, and read by containers through secretRef A masked field; with generate, empty means generated, and Generate creates a value in the browser
Boolean true or false A switch
Select One of options A drop-down, with the default marked (recommended)
DataSize A size, such as 10Gi A size field
Annotations Text A plain text field; the type has no field of its own
DeploymentSource The id of a private registry connected to the boundary, or empty for a public image. Used as a container's sourceRef A picker of the boundary's private registries, with Public image — no credentials needed

Generated values

With generate: true, a parameter left empty gets a value on deploy:

generateSpec Value
absent generateLength random letters and digits, 32 by default
base64 generateLength random bytes, 32 by default, base64-encoded
jwt A JSON Web Token signed with HS256, carrying the generateClaims plus iat and an exp ten years ahead. It is signed with the value of the parameter named jwt_secret — declare that one first, with generate: true — or with a random key when there is none

Generation is meant for Secret parameters. A plain generated secret appears under Advanced settings, where the deployer may type their own value; one with a generateSpec is not shown in the wizard at all.

Derived values

derived composes a value from other parameters once they are all known, generated ones included:

yaml
- name: db_url
  type: Secret
  label: Postgres URL
  derived: "postgresql://postgres:[%db_password_urlencoded%]@[%name%]-postgres:5432/postgres"

A derived value always replaces anything the deployer sent, and the wizard does not show it. Give it type: Secret when it embeds a secret: only Secret parameters are written to the vault.

Where values end up

  • Every parameter can be used as a token in the instance and its managed resources.
  • Every Secret parameter with a value — entered, generated or derived — is written to the instance vault under its name, and a container reads it with secretRef: { vault: "[%instance_vault%]", key: <name> }, the name written out.
  • The wizard counts the parameters it does not show — generated with a generateSpec, or derived — and tells the deployer that they are generated on deploy and stored in the vault.