SonicCloud
Skip to content

Install on Kubernetes

Install the license server and admin console with Helm.

This page installs the license server and the admin console on Kubernetes or OpenShift. Complete the requirements first.

Create the namespace and pull secret

kubectl create namespace license

kubectl create secret docker-registry registry-pull-secret \
  --docker-server=us-docker.pkg.dev \
  --docker-username=_json_key \
  --docker-password="$(cat key.json)" \
  --docker-email=admin@example.com \
  -n license

cat key.json | helm registry login -u _json_key --password-stdin us-docker.pkg.dev

Store key.json securely or delete it afterwards.

Generate keys and secrets

Generate these once and store them in a secrets vault. If the key pair is lost, existing licenses cannot be verified.

openssl genpkey -algorithm RSA -pkeyopt rsa_keygen_bits:2048 -out private.pem
openssl pkey -in private.pem -pubout -out public.pem
openssl rand -base64 48
openssl rand -base64 16

The first rand value is the session secret. The second is the initial administrator password.

Create TLS secrets

Choose one option.

Confirm your issuer exists with kubectl get clusterissuer. You set it in the next step.

Configure

Create values-secrets.yaml and replace every placeholder.

server:
  env:
    PGHOST: <postgres-host>
    PGPORT: "5432"
    PGSSL: "true"
    PGSSL_REJECT_UNAUTHORIZED: "true"
    CORS_ORIGIN: https://<admin-host>
  secret:
    values:
      PGPASSWORD: <postgres-password>
      JWT_SECRET: <session secret from step 2>
      PRIVATE_KEY_B64: <output of: base64 -i private.pem | tr -d '\n'>
      PUBLIC_KEY_B64: <output of: base64 -i public.pem | tr -d '\n'>
      ADMIN_BOOTSTRAP_USERNAME: admin
      ADMIN_BOOTSTRAP_PASSWORD: <administrator password from step 2>

admin:
  env:
    LICENSE_SERVER_URL: https://<api-host>/api/v1

ingress:
  enabled: true
  className: <ingress-class>
  annotations: {}
  admin:
    host: <admin-host>
    tls:
      enabled: true
      secretName: soniccloud-admin-tls
  server:
    host: <api-host>
    tls:
      enabled: true
      secretName: soniccloud-server-tls

networkPolicy:
  enabled: true
  ingressControllerLabels:
    <label-key>: <label-value>
  egress:
    externalPostgresCIDR: <postgres-ip>/32

If you use cert-manager, set your issuer under ingress.annotations:

ingress:
  annotations:
    cert-manager.io/cluster-issuer: <your-cluster-issuer>

Protect this file

It contains secrets. Keep it in a vault, never in source control, and use different values in each environment.

Install

helm install soniccloud oci://us-docker.pkg.dev/instant-matter-739/soniccloud-license/soniccloud-license \
  --version 0.3.0 \
  -f values-secrets.yaml \
  --set 'imagePullSecrets[0].name=registry-pull-secret' \
  -n license

The database is prepared automatically on first start.

Next: Verify the installation.

On this page