nublado Helm values reference¶
Helm values reference table for the nublado application.
| Key | Type | Default | Description | 
|---|---|---|---|
| cloudsql.affinity | object | 
 | Affinity rules for the Cloud SQL Auth Proxy pod | 
| cloudsql.enabled | bool | 
 | Enable the Cloud SQL Auth Proxy, used with Cloud SQL databases on Google Cloud | 
| cloudsql.image.pullPolicy | string | 
 | Pull policy for Cloud SQL Auth Proxy images | 
| cloudsql.image.repository | string | 
 | Cloud SQL Auth Proxy image to use | 
| cloudsql.image.tag | string | 
 | Cloud SQL Auth Proxy tag to use | 
| cloudsql.instanceConnectionName | string | None, must be set if Cloud SQL Auth Proxy is enabled | Instance connection name for a Cloud SQL PostgreSQL instance | 
| cloudsql.nodeSelector | object | 
 | Node selection rules for the Cloud SQL Auth Proxy pod | 
| cloudsql.podAnnotations | object | 
 | Annotations for the Cloud SQL Auth Proxy pod | 
| cloudsql.resources | object | See  | Resource limits and requests for the Cloud SQL Proxy pod | 
| cloudsql.serviceAccount | string | None, must be set if Cloud SQL Auth Proxy is enabled | The Google service account that has an IAM binding to the  | 
| cloudsql.tolerations | list | 
 | Tolerations for the Cloud SQL Auth Proxy pod | 
| controller.affinity | object | 
 | Affinity rules for the Nublado controller | 
| controller.config.fileserver.affinity | object | 
 | Affinity rules for user file server pods | 
| controller.config.fileserver.application | string | 
 | Argo CD application in which to collect user file servers | 
| controller.config.fileserver.creationTimeout | string | 
 | Timeout to wait for Kubernetes to create file servers, in Safir  | 
| controller.config.fileserver.deleteTimeout | string | 
 | Timeout for deleting a user’s file server from Kubernetes, in Safir  | 
| controller.config.fileserver.enabled | bool | 
 | Enable user file servers | 
| controller.config.fileserver.idleTimeout | string | 
 | Timeout for idle user fileservers, in Safir  | 
| controller.config.fileserver.image.pullPolicy | string | 
 | Pull policy for file server image | 
| controller.config.fileserver.image.repository | string | 
 | File server image to use | 
| controller.config.fileserver.image.tag | string | 
 | Tag of file server image to use | 
| controller.config.fileserver.namespace | string | 
 | Namespace for user file servers | 
| controller.config.fileserver.nodeSelector | object | 
 | Node selector rules for user file server pods | 
| controller.config.fileserver.pathPrefix | string | 
 | Path prefix for user file servers | 
| controller.config.fileserver.reconcileInterval | string | 
 | How frequently to reconcile file server state against Kubernetes to catch deletions from outside Nublado, in Safir  | 
| controller.config.fileserver.resources | object | See  | Resource requests and limits for user file servers | 
| controller.config.fileserver.tolerations | list | 
 | Tolerations for user file server pods | 
| controller.config.fileserver.volumeMounts | list | 
 | Volumes that should be made available via WebDAV | 
| controller.config.images.aliasTags | list | 
 | Additional tags besides  | 
| controller.config.images.cycle | string | 
 | Restrict images to this SAL cycle, if given. | 
| controller.config.images.numDailies | int | 
 | Number of most-recent dailies to prepull. | 
| controller.config.images.numReleases | int | 
 | Number of most-recent releases to prepull. | 
| controller.config.images.numWeeklies | int | 
 | Number of most-recent weeklies to prepull. | 
| controller.config.images.pin | list | 
 | List of additional image tags to prepull. Listing the image tagged as recommended here is recommended when using a Docker image source to ensure its name can be expanded properly in the menu. | 
| controller.config.images.recommendedTag | string | 
 | Tag marking the recommended image (shown first in the menu) | 
| controller.config.images.refreshInterval | string | 
 | How frequently to refresh the list of available images and compare it to the cached images on nodes to prepull new images, in Safir  | 
| controller.config.images.source | object | None, must be specified | Source for prepulled images. For Docker, set  | 
| controller.config.lab.activityInterval | string | 
 | How frequently the lab should report activity to JupyterHub in Safir  | 
| controller.config.lab.affinity | object | 
 | Affinity rules for user lab pods | 
| controller.config.lab.application | string | 
 | Argo CD application in which to collect user lab objects | 
| controller.config.lab.defaultSize | string | 
 | Default size selected on the spawner form. This must be either  | 
| controller.config.lab.deleteTimeout | string | 
 | Timeout for deleting a user’s lab resources from Kubernetes in Safir  | 
| controller.config.lab.env | object | See  | Environment variables to set for every user lab | 
| controller.config.lab.extraAnnotations | object | 
 | Extra annotations to add to user lab pods | 
| controller.config.lab.files | object | See  | Files to be mounted as ConfigMaps inside the user lab pod.  | 
| controller.config.lab.homedirPrefix | string | 
 | Prefix of home directory path to add before the username. This is the path inside the container, not the path of the volume. | 
| controller.config.lab.homedirSchema | string | 
 | Schema for home directory construction. Choose between  | 
| controller.config.lab.homedirSuffix | string | 
 | Portion of the home directory path after the username. This is intended for environments that want the JupyterLab home directory to be a subdirectory of the user’s home directory in some external environment. | 
| controller.config.lab.initContainers | list | 
 | Containers run as init containers with each user pod. Each should set  | 
| controller.config.lab.jupyterlabConfigDir | string | 
 | Path inside the lab container where custom JupyterLab configuration is stored | 
| controller.config.lab.labStartCommand | list | 
 | Command executed in the container to start the lab | 
| controller.config.lab.namespacePrefix | string | 
 | Prefix for namespaces for user labs. To this will be added a dash ( | 
| controller.config.lab.nodeSelector | object | 
 | Node selector rules for user lab pods | 
| controller.config.lab.nss.baseGroup | string | See  | Base  | 
| controller.config.lab.nss.basePasswd | string | See  | Base  | 
| controller.config.lab.pullSecret | string | Do not use a pull secret | Pull secret to use for labs. Set to the string  | 
| controller.config.lab.reconcileInterval | string | 
 | How frequently to reconcile lab state against Kubernetes to catch deletions from outside Nublado, in Safir  | 
| controller.config.lab.runtimeMountsDir | string | 
 | Directory in the lab under which runtime information such as tokens, environment variables, and container information will be mounted | 
| controller.config.lab.secrets | list | 
 | Secrets to set in the user pods. Each should have a  | 
| controller.config.lab.sizes | list | See  | Available lab sizes. Sizes must be chosen from  | 
| controller.config.lab.spawnTimeout | int | 
 | How long to wait for Kubernetes to spawn a lab in seconds. This should generally be shorter than the spawn timeout set in JupyterHub. | 
| controller.config.lab.tmpSource | string | 
 | Select where  | 
| controller.config.lab.tolerations | list | 
 | Tolerations for user lab pods | 
| controller.config.lab.volumeMounts | list | 
 | Volumes that should be mounted in lab pods. | 
| controller.config.lab.volumes | list | 
 | Volumes that will be in lab pods or init containers. This supports NFS, HostPath, and PVC volume types (differentiated in source.type). | 
| controller.config.logLevel | string | 
 | Level of Python logging | 
| controller.config.metrics.application | string | 
 | Name under which to log metrics. Generally there is no reason to change this. | 
| controller.config.metrics.enabled | bool | 
 | Whether to enable sending metrics | 
| controller.config.metrics.events.topicPrefix | string | 
 | Topic prefix for events. It may sometimes be useful to change this in development environments. | 
| controller.config.metrics.schemaManager.registryUrl | string | Sasquatch in the local cluster | URL of the Confluent-compatible schema registry server | 
| controller.config.metrics.schemaManager.suffix | string | 
 | Suffix to add to all registered subjects. This is sometimes useful for experimentation during development. | 
| controller.config.pathPrefix | string | 
 | Path prefix that will be routed to the controller | 
| controller.googleServiceAccount | string | None, must be set when using Google Artifact Registry | If Google Artifact Registry is used as the image source, the Google service account that has an IAM binding to the  | 
| controller.image.pullPolicy | string | 
 | Pull policy for the controller image | 
| controller.image.repository | string | 
 | Nublado controller image to use | 
| controller.image.tag | string | The appVersion of the chart | Tag of Nublado controller image to use | 
| controller.ingress.annotations | object | 
 | Additional annotations to add for the Nublado controller ingress | 
| controller.nodeSelector | object | 
 | Node selector rules for the Nublado controller | 
| controller.podAnnotations | object | 
 | Annotations for the Nublado controller | 
| controller.resources | object | See  | Resource limits and requests for the Nublado controller | 
| controller.slackAlerts | bool | 
 | Whether to enable Slack alerts. If set to true,  | 
| controller.tolerations | list | 
 | Tolerations for the Nublado controller | 
| cronjob.affinity | object | 
 | Affinity rules for the cloning cronjob(s). | 
| cronjob.artifacts.enabled | bool | 
 | Clone the artifacts? | 
| cronjob.artifacts.gid | int | 
 | GID for the cloning cronjob(s) | 
| cronjob.artifacts.gitBranch | string | 
 | Branch of repository to clone | 
| cronjob.artifacts.gitSource | string | 
 | Source for Tutorials binary artifact repository to clone | 
| cronjob.artifacts.gitTarget | string | 
 | Target where Tutorial artifacts repository should land | 
| cronjob.artifacts.schedule | string | 
 | Schedule for the cloning cronjob(s). | 
| cronjob.artifacts.targetVolume | object | See  | Repository volume definition | 
| cronjob.artifacts.targetVolume.mountPath | string | 
 | Where volume will be mounted in the container | 
| cronjob.artifacts.targetVolume.volumeName | string | None, must be set for each environment | Name of volume to mount (from controller.lab.config.volumes) | 
| cronjob.artifacts.targetVolumePath | string | 
 | Where repository volume should be mounted | 
| cronjob.artifacts.uid | int | 
 | UID for the cloning cronjob(s) | 
| cronjob.image.pullPolicy | string | 
 | Pull policy for the repo cloner image | 
| cronjob.image.repository | string | 
 | Repository cloner image to use | 
| cronjob.image.tag | string | 
 | Tag of repo cloner image to use | 
| cronjob.resources | object | See  | Resource limits and requests for the cloning cronjob(s) | 
| cronjob.tolerations | list | 
 | Tolerations for the cloning cronjob(s). | 
| cronjob.tutorials.enabled | bool | 
 | Clone the notebooks? | 
| cronjob.tutorials.gid | int | 
 | GID for the cloning cronjob(s) | 
| cronjob.tutorials.gitBranch | string | 
 | Branch of repository to clone | 
| cronjob.tutorials.gitSource | string | 
 | Source for Tutorials repository to clone | 
| cronjob.tutorials.gitTarget | string | 
 | Target where Tutorials repository should land | 
| cronjob.tutorials.schedule | string | 
 | Schedule for the cloning cronjob(s). | 
| cronjob.tutorials.targetVolume | object | See  | Repository volume definition | 
| cronjob.tutorials.targetVolume.mountPath | string | 
 | Where volume will be mounted in the container | 
| cronjob.tutorials.targetVolume.volumeName | string | None, must be set for each environment | Name of volume to mount (from controller.lab.config.volumes) | 
| cronjob.tutorials.targetVolumePath | string | 
 | Where repository volume should be mounted | 
| cronjob.tutorials.uid | int | 
 | UID for the cloning cronjob(s) | 
| global.baseUrl | string | Set by Argo CD | Base URL for the environment | 
| global.host | string | Set by Argo CD | Host name for ingress | 
| global.vaultSecretsPath | string | Set by Argo CD | Base path for Vault secrets | 
| hub.internalDatabase | bool | 
 | Whether to use the cluster-internal PostgreSQL server instead of an external server. This is not used directly by the Nublado chart, but controls how the database password is managed. | 
| hub.landingPage | string | 
 | Default spawn page. Usually ‘/lab’, but can be overridden in order to specify a custom landing page. | 
| hub.minimumTokenLifetime | string | 
 | Minimum remaining token lifetime when spawning a lab. The token cannot be renewed, so it should ideally live as long as the lab does. If the token has less remaining lifetime, the user will be redirected to reauthenticate before spawning a lab. | 
| hub.resources | object | See  | Resource limits and requests for the Hub | 
| hub.timeout.startup | int | 
 | Timeout for JupyterLab to start in seconds. Currently this sometimes takes over 60 seconds for reasons we don’t understand. | 
| hub.useSubdomains | bool | 
 | Whether to put each user’s lab in a separate domain. This is strongly recommended for security, but requires wildcard DNS and cert-manager support and requires subdomain support be enabled in Gafaelfawr. | 
| jupyterhub.cull.enabled | bool | 
 | Enable the lab culler. | 
| jupyterhub.cull.every | int | 3600 (1 hour) | How frequently to check for idle labs in seconds | 
| jupyterhub.cull.maxAge | int | 2160000 (25 days) | Maximum age of a lab regardless of activity | 
| jupyterhub.cull.removeNamedServers | bool | 
 | Whether to remove named servers when culling their lab | 
| jupyterhub.cull.timeout | int | 432000 (5 days) | Default idle timeout before the lab is automatically deleted in seconds | 
| jupyterhub.cull.users | bool | 
 | Whether to log out the user (from JupyterHub) when culling their lab | 
| jupyterhub.hub.authenticatePrometheus | bool | 
 | Whether to require metrics requests to be authenticated | 
| jupyterhub.hub.baseUrl | string | 
 | Base URL on which JupyterHub listens | 
| jupyterhub.hub.containerSecurityContext | object | See  | Security context for JupyterHub container | 
| jupyterhub.hub.db.password | string | Comes from nublado-secret | Database password (not used) | 
| jupyterhub.hub.db.type | string | 
 | Type of database to use | 
| jupyterhub.hub.db.upgrade | bool | 
 | Whether to automatically update DB schema at Hub start | 
| jupyterhub.hub.db.url | string | Use the in-cluster PostgreSQL installed by Phalanx | URL of PostgreSQL server | 
| jupyterhub.hub.existingSecret | string | 
 | Existing secret to use for private keys | 
| jupyterhub.hub.extraEnv | object | Gets  | Additional environment variables to set | 
| jupyterhub.hub.extraVolumeMounts | list | 
 | Additional volume mounts for JupyterHub | 
| jupyterhub.hub.extraVolumes | list | The  | Additional volumes to make available to JupyterHub | 
| string | 
 | Image to use for JupyterHub | |
| jupyterhub.hub.image.tag | string | 
 | Tag of image to use for JupyterHub | 
| jupyterhub.hub.loadRoles.server.scopes | list | See  | Default scopes for the user’s lab, overridden to allow the lab to delete itself (which we use for our added menu items) | 
| jupyterhub.hub.networkPolicy.enabled | bool | 
 | Whether to enable the default  | 
| jupyterhub.hub.resources | object | See  | Resource limits and requests | 
| jupyterhub.ingress.enabled | bool | 
 | Whether to enable the default ingress. Should always be disabled since we install our own  | 
| jupyterhub.prePuller.continuous.enabled | bool | 
 | Whether to run the JupyterHub continuous prepuller (the Nublado controller does its own prepulling) | 
| jupyterhub.prePuller.hook.enabled | bool | 
 | Whether to run the JupyterHub hook prepuller (the Nublado controller does its own prepulling) | 
| jupyterhub.proxy.chp.extraCommandLineFlags | list | 
 | Extra CLI options to pass to the proxy. The most up-to-date list is here (not the docs, unfortunately) | 
| jupyterhub.proxy.chp.networkPolicy.interNamespaceAccessLabels | string | 
 | Enable access to the proxy from other namespaces, since we put each user’s lab environment in its own namespace | 
| jupyterhub.proxy.chp.resources | object | See  | Resource limits and requests for proxy pod | 
| jupyterhub.proxy.service.type | string | 
 | Only expose the proxy to the cluster, overriding the default of exposing the proxy directly to the Internet | 
| jupyterhub.scheduling.userPlaceholder.enabled | bool | 
 | Whether to spawn placeholder pods representing fake users to force autoscaling in advance of running out of resources | 
| jupyterhub.scheduling.userScheduler.enabled | bool | 
 | Whether the user scheduler should be enabled | 
| proxy.ingress.annotations | object | See  | Additional annotations to add to the proxy ingress (also used to talk to JupyterHub and all user labs) | 
| purger.affinity | object | 
 | Affinity rules for purger | 
| purger.config.dryRun | bool | 
 | Report only; do not purge | 
| purger.config.logging.addTimestamps | bool | 
 | Add timestamps to log lines | 
| purger.config.logging.log_level | string | 
 | Level at which to log | 
| purger.config.logging.profile | string | 
 | “production” (JSON logs) or “development” (human-friendly) | 
| purger.config.policyFile | string | 
 | File holding purge policy | 
| purger.enabled | bool | 
 | Purge scratch space? | 
| purger.image.pullPolicy | string | 
 | Pull policy for the purger image | 
| purger.image.repository | string | 
 | purger image to use | 
| purger.image.tag | string | The appVersion of the chart | Tag of purger image to use | 
| purger.nodeSelector | object | 
 | Node selector rules for purger | 
| purger.podAnnotations | object | 
 | Annotations for the purger pod | 
| purger.policy.directories[0].intervals | object | see  | If any of these times are older than specified, remove the file. Zero means “never remove”. | 
| purger.policy.directories[0].path | string | 
 | |
| purger.policy.directories[0].threshold | string | 
 | Files this large or larger will be subject to the “large” interval set | 
| purger.resources | object | See  | Resource limits and requests for the filesystem purger | 
| purger.schedule | string | 
 | Crontab entry for when to run. | 
| purger.tolerations | list | 
 | Tolerations for purger | 
| purger.volumeName | string | None, must be set for each environment | Name of volume to purge (from controller.lab.config.volumes) | 
| secrets.templateSecrets | bool | 
 | Whether to use the new secrets management mechanism. If enabled, the Vault nublado secret will be split into a nublado secret for JupyterHub and a nublado-lab-secret secret used as a source for secret values for the user’s lab. |