Skip to content
Stackship documentation Svenska

Access controlAdministrators

Configuration reference

Configuration keys of the rbac module: sections, environment variables, types and defaults.

Generated from the module's code when its image was built — do not edit. Each key can be set as an environment variable on the module's deployment in namespace stackship-system; a double underscore separates the levels. An environment variable overrides the module's shipped appsettings. Values that could be credentials are not shown.

Auth

Bound to StackshipAuthOptions.

Key Environment variable Type Default
Auth:InternalUrl Auth__InternalUrl string ""
Auth:Module:Audience Auth__Module__Audience string
Auth:Module:ClientId Auth__Module__ClientId string ""
Auth:Module:ClientSecret Auth__Module__ClientSecret string (not shown)
Auth:Realm Auth__Realm string ""
Auth:Stackship:Audience Auth__Stackship__Audience string
Auth:Stackship:ClientId Auth__Stackship__ClientId string ""
Auth:Stackship:ClientSecret Auth__Stackship__ClientSecret string (not shown)
Auth:Url Auth__Url string ""

Auth:Admin

Bound to KeycloakIdentityAdminOptions.

Key Environment variable Type Default
Auth:Admin:Audience Auth__Admin__Audience string stackship-kubernetes-client
Auth:Admin:ClientId Auth__Admin__ClientId string ""
Auth:Admin:ClientSecret Auth__Admin__ClientSecret string (not shown)

Auth:Admin

Bound to KeycloakAdminOptions.

Key Environment variable Type Default
Auth:Admin:ClientId Auth__Admin__ClientId string ""
Auth:Admin:ClientSecret Auth__Admin__ClientSecret string (not shown)

ChangePassword

Bound to PasswordChangeOptions.

Key Environment variable Type Default
ChangePassword:PortalBaseUrl ChangePassword__PortalBaseUrl string http://localhost:5173
ChangePassword:ReauthWindowMinutes ChangePassword__ReauthWindowMinutes integer 5
ChangePassword:SupportEmail ChangePassword__SupportEmail string support@stackship.se

Invitations

Bound to InvitationOptions.

Key Environment variable Type Default
Invitations:DefaultExpiryDays Invitations__DefaultExpiryDays integer 7
Invitations:ExpirySweepIntervalMinutes Invitations__ExpirySweepIntervalMinutes integer 60
Invitations:MaxResendsPer24h Invitations__MaxResendsPer24h integer 3
Invitations:PortalBaseUrl Invitations__PortalBaseUrl string http://localhost:5173
Invitations:SupportEmail Invitations__SupportEmail string support@stackship.se

PasswordReset

Bound to PasswordResetOptions.

Key Environment variable Type Default
PasswordReset:ExpirySweepIntervalMinutes PasswordReset__ExpirySweepIntervalMinutes integer 15
PasswordReset:IpRateLimitPermits PasswordReset__IpRateLimitPermits integer 10
PasswordReset:IpRateLimitWindowMinutes PasswordReset__IpRateLimitWindowMinutes integer 15
PasswordReset:MaxRequestsPer24h PasswordReset__MaxRequestsPer24h integer 3
PasswordReset:PortalBaseUrl PasswordReset__PortalBaseUrl string http://localhost:5173
PasswordReset:SupportEmail PasswordReset__SupportEmail string support@stackship.se
PasswordReset:TokenLifetimeMinutes PasswordReset__TokenLifetimeMinutes integer 60

Rbac:Organizations

Bound to OrganizationsOptions.

Key Environment variable Type Default
Rbac:Organizations:Enabled Rbac__Organizations__Enabled boolean false
Rbac:Organizations:SweepInterval Rbac__Organizations__SweepInterval duration 00:15:00

Rbac:Reconciler

Bound to ReconcilerOptions.

Key Environment variable Type Default
Rbac:Reconciler:EnableDebugRoute Rbac__Reconciler__EnableDebugRoute boolean false
Rbac:Reconciler:OidcGroupsPrefix Rbac__Reconciler__OidcGroupsPrefix string ""
Rbac:Reconciler:OidcUsernamePrefix Rbac__Reconciler__OidcUsernamePrefix string oidc:
Rbac:Reconciler:ResourceGroupNamespacePrefix Rbac__Reconciler__ResourceGroupNamespacePrefix string rg-
Rbac:Reconciler:SweepInterval Rbac__Reconciler__SweepInterval duration 00:05:00

Stackship

Bound to StackshipModuleOptions.

Key Environment variable Type Default
Stackship:AutoUnregisterOnShutdown Stackship__AutoUnregisterOnShutdown boolean true
Stackship:BackendBaseUrl Stackship__BackendBaseUrl string ""
Stackship:BaseUrl Stackship__BaseUrl string ""
Stackship:CustomResourceDefinitions:{index}:Group Stackship__CustomResourceDefinitions__{index}__Group string
Stackship:CustomResourceDefinitions:{index}:Plural Stackship__CustomResourceDefinitions__{index}__Plural string
Stackship:CustomResourceDefinitions:{index}:ReadAction Stackship__CustomResourceDefinitions__{index}__ReadAction string
Stackship:CustomResourceDefinitions:{index}:ResourceName Stackship__CustomResourceDefinitions__{index}__ResourceName string
Stackship:CustomResourceDefinitions:{index}:StatusSource Stackship__CustomResourceDefinitions__{index}__StatusSource string
Stackship:CustomResourceDefinitions:{index}:UserManagedResource Stackship__CustomResourceDefinitions__{index}__UserManagedResource boolean
Stackship:CustomResourceDefinitions:{index}:Version Stackship__CustomResourceDefinitions__{index}__Version string
Stackship:DisplayName Stackship__DisplayName string ""
Stackship:HeartbeatInterval Stackship__HeartbeatInterval duration 00:00:30
Stackship:HeartbeatTimeout Stackship__HeartbeatTimeout duration
Stackship:HttpTimeout Stackship__HttpTimeout duration 00:00:15
Stackship:Key Stackship__Key string (not shown)
Stackship:RegistrationRetryInterval Stackship__RegistrationRetryInterval duration 00:00:05
Stackship:UseGrpcRegistration Stackship__UseGrpcRegistration boolean false

Read at startup

Keys the module reads directly while it starts, outside an options section. The value column shows what the module's appsettings ships.

Key Environment variable Type Shipped value
SkipDatabaseMigrations SkipDatabaseMigrations

Other shipped settings

Keys the module's appsettings sets that no options section above covers.

Key Environment variable Type Shipped value
Compute:Ingress:Class Compute__Ingress__Class nginx
Compute:Storage:Classes:Premium Compute__Storage__Classes__Premium vsphere-block
Compute:Storage:Classes:Standard Compute__Storage__Classes__Standard vsphere-block
ConnectionStrings:Postgres ConnectionStrings__Postgres (not shown)
Rbac:TestSeed:AllowedClientId Rbac__TestSeed__AllowedClientId
Rbac:TestSeed:Enabled Rbac__TestSeed__Enabled False