# Helm values for a self-hosted deployment on Azure AKS.
# Requires application version 3.1.4 or later.
#
# Complete every REPLACE_ME before you install; a value you cannot fill in is
# a prerequisite that is not ready yet. Keep this file: you reuse it for
# upgrades. Everything not set here is a chart default, tuned for the
# supported 32 vCPU / 128 GiB node.

# Your hostname from Step 1 as https://<hostname>: scheme, host, and an
# optional port, with no path. The chart derives every URL the platform
# needs about itself from it: the sign-in callback, the allowed browser
# origin, and the webhook callback URLs. The URLs you registered in your
# identity provider in Step 2 are built from the same hostname, and
# httpRoute.hostnames below repeats it. Each derived URL has an explicit
# override; see Advanced configuration.
applicationUrl: https://REPLACE_ME

# The Kubernetes service account that gives the application access to Azure
# resources. Create it in the application namespace, annotate it with the
# client ID of the user-assigned managed identity
# (azure.workload.identity/client-id), and federate the identity with it.
serviceAccount:
  create: false
  name: REPLACE_ME

# The application database and its three roles, created before the install
# (see "Create the database and its roles" in the AKS guide).
postgres:
  host: REPLACE_ME
  database: REPLACE_ME
  appRole: REPLACE_ME
  appPassword: REPLACE_ME
  definerRole: REPLACE_ME
  migratorRole: REPLACE_ME
  migratorPassword: REPLACE_ME

# The Azure resources from the bill of materials, in one block. From these the
# chart derives everything Azure-shaped:
#   - object storage at abfss://<container>@<account>.dfs.core.windows.net,
#     plus the optional prefix, reached as the managed identity federated with
#     the service account above (no account keys);
#   - a Premium SSD StorageClass on the Azure Disk CSI driver, encrypted at
#     rest with platform-managed keys, and the data root claimed from it as a
#     raw block volume on the node (100 GiB by default; raise
#     vfs.dataRoot.size later and upgrade, the filesystem grows without a
#     restart);
#   - the sandbox wiring for AKS: the Kata runtime you installed before the
#     platform, reached through the node's containerd, with the release
#     installing no Kata of its own;
#   - no Ingress: the application is served through the HTTPRoute below.
# Anything set explicitly elsewhere in this file wins over a derived value.
infrastructure:
  platform: azure
  azure:
    # The storage account name only: 3 to 24 lowercase letters and digits.
    storageAccountName: REPLACE_ME
    # The container name only. The optional key prefix keeps several
    # deployments apart in one container.
    blobContainerName: REPLACE_ME
    # blobKeyPrefix: ""
    # Identifier of the RSA key in Key Vault reserved for envelope encryption
    # of secrets at rest, as https://<vault>.vault.azure.net/keys/<name>. The
    # chart requires it. Leave the version off to follow the key's rotation.
    # The key must permit encrypt, decrypt, wrap key, and unwrap key, and the
    # managed identity needs Key Vault Crypto User on it.
    keyVaultKeyUrl: REPLACE_ME

api:
  config:
    # Encryption keys, yours to generate and to keep. Generate a long random
    # string for each, for example with `openssl rand -hex 32`.
    # secretsKeys encrypts the credentials the platform stores in its
    # database: model platform keys, integration and OAuth tokens. The
    # database outlives the cluster, and without the exact key its encrypted
    # contents cannot be decrypted; the database may become unusable.
    # projectPortabilityKeys protects exported project archives the same
    # way. Keep this file backed up somewhere safe outside the cluster.
    secretsKeys: '{"v1":"REPLACE_ME"}'
    projectPortabilityKeys: '{"active":"REPLACE_ME"}'

    # The OIDC application you registered against your hostname in Step 2.
    auth:
      oidc:
        server: REPLACE_ME # your provider's discovery URL; the bare issuer URL also works
        clientId: REPLACE_ME
        clientSecret: REPLACE_ME

# Routing through the Gateway you created in Step 3, on the AKS application
# routing add-on's Gateway API implementation. The chart renders an HTTPRoute
# for the application's paths and attaches it to the Gateway's HTTPS
# listener, where TLS terminates with your certificate from Key Vault.
httpRoute:
  enabled: true
  parentRefs:
    - name: REPLACE_ME # the Gateway's name
      namespace: REPLACE_ME # the Gateway's namespace
      sectionName: https # the listener's name
  hostnames:
    # Your hostname from Step 1, as on the Gateway's listener.
    - REPLACE_ME
