Parameters
The parameter types a blueprint template can declare, their attributes, how secrets are generated and derived, and how the deploy wizard shows each one.
Attributes
Each entry in a template's parameters list has:
| Attribute | Content |
|---|---|
name |
Required and unique in the template. Tokens refer to it as [%<name>%], and a Secret parameter is stored in the vault under this name |
type |
One of the types below |
label |
The field's label in the wizard |
description |
Help text under the field |
default |
The value used when the deployer leaves the field empty. May contain tokens |
options |
Select only: the values offered |
advanced |
true puts the field under Advanced settings, collapsed |
generate, generateLength, generateSpec, generateClaims |
Generate the value when none is given — see Generated values |
derived |
Compose the value from other parameters — see Derived values |
capability |
DeploymentSource only, and required there: ImagePull |
documentation |
A URL about this parameter |
required |
Marks the field as required in the wizard |
validation |
pattern, a regular expression, and message |
Neither required nor validation is enforced when a blueprint is deployed today: the portal
marks a required field but submits without it, and the pattern is stored but never checked. Give a
parameter a working default rather than relying on them.
Types
Every value is passed as a string.
| Type | Holds | In the wizard |
|---|---|---|
String |
Text | A text field; the placeholder shows the default with the instance name filled in |
Secret |
A sensitive value. Written to the instance vault, and read by containers through secretRef |
A masked field; with generate, empty means generated, and Generate creates a value in the browser |
Boolean |
true or false |
A switch |
Select |
One of options |
A drop-down, with the default marked (recommended) |
DataSize |
A size, such as 10Gi |
A size field |
Annotations |
Text | A plain text field; the type has no field of its own |
DeploymentSource |
The id of a private registry connected to the boundary, or empty for a public image. Used as a container's sourceRef |
A picker of the boundary's private registries, with Public image — no credentials needed |
Generated values
With generate: true, a parameter left empty gets a value on deploy:
generateSpec |
Value |
|---|---|
| absent | generateLength random letters and digits, 32 by default |
base64 |
generateLength random bytes, 32 by default, base64-encoded |
jwt |
A JSON Web Token signed with HS256, carrying the generateClaims plus iat and an exp ten years ahead. It is signed with the value of the parameter named jwt_secret — declare that one first, with generate: true — or with a random key when there is none |
Generation is meant for Secret parameters. A plain generated secret appears under Advanced
settings, where the deployer may type their own value; one with a generateSpec is not shown in
the wizard at all.
Derived values
derived composes a value from other parameters once they are all known, generated ones included:
- name: db_url
type: Secret
label: Postgres URL
derived: "postgresql://postgres:[%db_password_urlencoded%]@[%name%]-postgres:5432/postgres"A derived value always replaces anything the deployer sent, and the wizard does not show it. Give it
type: Secret when it embeds a secret: only Secret parameters are written to the vault.
Where values end up
- Every parameter can be used as a token in the instance and its managed resources.
- Every
Secretparameter with a value — entered, generated or derived — is written to the instance vault under its name, and a container reads it withsecretRef: { vault: "[%instance_vault%]", key: <name> }, the name written out. - The wizard counts the parameters it does not show — generated with a
generateSpec, or derived — and tells the deployer that they are generated on deploy and stored in the vault.