Skip to main content
Version: 2.0

Configuration Guide

Every KubeOpera component — the dashboard and each backend service — is configured the same way: environment variables, supplied from a Kubernetes ConfigMap for ordinary settings and a Sealed Secret for sensitive ones. There's no central config file to keep in sync.

This guide shows you how to change configuration safely, explains the dashboard's settings, and tells you where to find each service's options.

Changing a setting​

Because every environment is managed with GitOps, configuration changes are commits:

  1. Find the service's overlay for your environment: fluxcd/apps/<service>/overlays/<env>/.
  2. Edit its ConfigMap patch (or re-seal its Secret — see Setup: secrets).
  3. Commit and push. Flux applies the change, and the service restarts with the new configuration.
# fluxcd/apps/analysis-agent-srv/overlays/production/config.yaml
apiVersion: v1
kind: ConfigMap
metadata:
name: analysis-agent-srv-config
data:
ANOMALY_Z_THRESHOLD_HIGH: "2.8"
INSIGHT_PUBLISH_MIN_RISK_SCORE: "10"
tip

Keep differences between environments in their overlays. If production needs a larger connection pool than development, that difference should be visible in Git — not set by hand on a running cluster.

Configuring the dashboard​

The dashboard (kubeopera-frontend) reads two kinds of variable:

  • Server-side variables are read when a request is handled. Change them and restart the pod.
  • NEXT_PUBLIC_* variables are compiled into the browser bundle when the image is built. Changing them requires a rebuild.

AUTH_APP_ID (server-side, authoritative) and NEXT_PUBLIC_AUTH_APP_ID (initial value shown in the browser) must match — set both, and rebuild after changing the public one.

Service URLs​

VariableDefaultService
NEXT_PUBLIC_AUTH_API_URLhttp://localhost:8082auth-service
KUBEOPERA_API_BASE_URLhttp://kubeopera-api:8090kubeopera-api
K8S_MONITOR_BASE_URLhttp://k8s-monitor:8085k8s-monitor
SECURITY_API_BASE_URLhttp://security-api:8086security-api
CICD_GATEWAY_BASE_URLhttp://cicd-gateway:8087cicd-gateway
ANOMALY_DETECTOR_BASE_URLhttp://anomaly-detector:8088anomaly-detector
PREDICTIVE_SCALER_BASE_URLhttp://predictive-scaler:8089predictive-scaler
INCIDENT_MANAGER_BASE_URLhttp://incident-manager:8090incident-manager
OBSERVABILITY_AGENT_SRV_BASE_URLhttp://observability-agent-srv:8092observability-agent
ANALYSIS_AGENT_SRV_BASE_URLhttp://analysis-agent-srv:8093analysis-agent
ACTION_AGENT_SRV_BASE_URLhttp://action-agent-srv:8094action-agent
FEEDBACK_AGENT_SRV_BASE_URLhttp://feedback-agent-srv:8095feedback-agent
RECOMMENDATION_AGENT_SRV_BASE_URLhttp://recommendation-agent-srv:8096recommendation-agent
AGENT_RUNTIME_BASE_URLhttp://agent-runtime:8111agent-runtime
K8S_OPTIMIZER_BASE_URLhttp://k8s-optimizer:8097k8s-optimizer
APP_INTERNAL_URLhttp://localhost:3000The dashboard itself, for server-side calls between its own routes.

Each service's hostname must also be on the dashboard's upstream allowlist. The defaults above are allowed out of the box; if you run a service under a different hostname, add it with ALLOWED_UPSTREAM_HOSTS (comma-separated).

Metrics and observability​

VariableDefaultDescription
METRICS_SOURCEkubernetesWhere the Dashboard's cluster metrics come from: kubernetes, prometheus, datadog, newrelic or mock.
PROMETHEUS_URLhttp://kube-prometheus-stack-prometheus.monitoring:9090Prometheus, used when METRICS_SOURCE=prometheus and always for latency, network and error-rate charts.

METRICS_SOURCE is an environment-wide choice made by operators, not a per-user setting.

AI​

VariableDescription
AI_CREDENTIAL_INTERNAL_API_KEYLets the dashboard's AI Chat resolve the caller's AI credential from auth-service.

The AI Chat uses the same credential resolution as the agents: a tenant's own provider key if configured, otherwise the platform key. Configure the platform key under Settings → AI Provider Key.

Configuring backend services​

Each Go service reads its environment at startup. Most need:

VariablePurpose
DATABASE_URLIts PostgreSQL schema.
RABBITMQ_URLThe message bus, for services that publish or consume events.
AUTH_JWT_ACCESS_SECRETValidates user access tokens.
<SERVICE>_BASE_URLThe address of each service it calls.
PORTIts HTTP port.

Services fail fast with a clear error if a required variable is missing, so misconfiguration shows up at deploy time rather than later. Each service's page under Core Services lists every variable it reads, its default and whether it's required.

Where secrets live​

SecretWhere it's storedWho manages it
Database passwords, signing keys, service API keysSealed Secrets in GitOperators, through GitOps.
Platform AI provider keyauth-service (encrypted)Platform administrators, in Settings → AI Provider Key.
A tenant's own AI provider keyauth-service (encrypted)Tenant administrators, in their settings.
Registry credentialsauth-service (encrypted)Tenants, when deploying private images.
Cloud credentials for provisioningauth-service (encrypted)Platform administrators, in Cluster Management.
Personal access tokensauth-service (hashed)Each user, in Settings → Access Tokens.

Credentials managed through the dashboard are encrypted at rest and never shown again after they're saved — only a label and the last four characters are displayed.

Next steps​