Skip to content

The environment file

coming This page describes a settled design that is not in a released version yet.

Several features need to know which products make up an environment: the provisioner applying product content, and the app switcher linking each console to the others. The environment file answers that once, in Git.

apiVersion: tinyblox.ai/v1alpha1
kind: Environment
metadata:
name: production
spec:
identity: # the issuer every product trusts
product: tinyguard
issuer: https://guard.example.com/auth/v1
components:
- product: tinyguard
url: http://tinyguard.tinyblox.svc.cluster.local:8080
audience: tinyguard
console:
publicUrl: https://guard.example.com/admin/
display: { name: TinyGuard, order: 30 }
access: { roles: [guard-admin] }
- product: tinyvault
url: https://tinyvault.tinyblox.svc.cluster.local:8443
audience: tinyvault
ca: { configMap: tinyblox-ca }
console:
publicUrl: https://vault.example.com/
display: { name: TinyVault, order: 20 }
- product: tinyconductor
url: http://tinyconductor.tinyblox.svc.cluster.local:8080
audience: tinyconductor
console:
publicUrl: https://conductor.example.com/
display: { name: TinyConductor, order: 10 }
access: { roles: [conductor-admin, conductor-designer], groups: [operators] }
Field Meaning
identity.issuer The identity provider every product trusts.
components[].url Where the product is reached from inside the cluster.
components[].audience The token audience the product accepts.
components[].ca The certificate authority of a product reached over TLS (see Connections).
components[].console.publicUrl Where a browser opens the product’s console.
components[].console.display Name and order in the app switcher; shown: false hides it.
components[].console.access Who may open the console: any of these roles or groups. Left out, the product’s own default applies.
  • The file says which products exist and where. The running products say what they are (release, what they can be given) each time the provisioner runs.
  • A product listed in the file that does not answer fails the run, naming it.
  • The provisioner warns about a TinyBlox product running in the namespace that the file does not list.
  • Without a Git repository, provision environment discover writes a first file from the products installed in the namespace.