Install on Kubernetes
Install the license server and admin console with Helm.
This page installs the license server and the admin console on Kubernetes or OpenShift. Complete the requirements first.
Create the namespace and pull secret
kubectl create namespace license
kubectl create secret docker-registry registry-pull-secret \
--docker-server=us-docker.pkg.dev \
--docker-username=_json_key \
--docker-password="$(cat key.json)" \
--docker-email=admin@example.com \
-n license
cat key.json | helm registry login -u _json_key --password-stdin us-docker.pkg.devStore key.json securely or delete it afterwards.
Generate keys and secrets
Generate these once and store them in a secrets vault. If the key pair is lost, existing licenses cannot be verified.
openssl genpkey -algorithm RSA -pkeyopt rsa_keygen_bits:2048 -out private.pem
openssl pkey -in private.pem -pubout -out public.pem
openssl rand -base64 48
openssl rand -base64 16The first rand value is the session secret. The second is the initial administrator password.
Create TLS secrets
Choose one option.
Confirm your issuer exists with kubectl get clusterissuer. You set it in the next step.
Configure
Create values-secrets.yaml and replace every placeholder.
server:
env:
PGHOST: <postgres-host>
PGPORT: "5432"
PGSSL: "true"
PGSSL_REJECT_UNAUTHORIZED: "true"
CORS_ORIGIN: https://<admin-host>
secret:
values:
PGPASSWORD: <postgres-password>
JWT_SECRET: <session secret from step 2>
PRIVATE_KEY_B64: <output of: base64 -i private.pem | tr -d '\n'>
PUBLIC_KEY_B64: <output of: base64 -i public.pem | tr -d '\n'>
ADMIN_BOOTSTRAP_USERNAME: admin
ADMIN_BOOTSTRAP_PASSWORD: <administrator password from step 2>
admin:
env:
LICENSE_SERVER_URL: https://<api-host>/api/v1
ingress:
enabled: true
className: <ingress-class>
annotations: {}
admin:
host: <admin-host>
tls:
enabled: true
secretName: soniccloud-admin-tls
server:
host: <api-host>
tls:
enabled: true
secretName: soniccloud-server-tls
networkPolicy:
enabled: true
ingressControllerLabels:
<label-key>: <label-value>
egress:
externalPostgresCIDR: <postgres-ip>/32If you use cert-manager, set your issuer under ingress.annotations:
ingress:
annotations:
cert-manager.io/cluster-issuer: <your-cluster-issuer>Protect this file
It contains secrets. Keep it in a vault, never in source control, and use different values in each environment.
Install
helm install soniccloud oci://us-docker.pkg.dev/instant-matter-739/soniccloud-license/soniccloud-license \
--version 0.3.0 \
-f values-secrets.yaml \
--set 'imagePullSecrets[0].name=registry-pull-secret' \
-n licenseThe database is prepared automatically on first start.
Next: Verify the installation.
