docs / Install

Configuration

Every ITOPS_* environment variable a customer sets, what production mode forces, and the GitOps directories the chart mounts.

The core reads its configuration from environment variables prefixed ITOPS_, with _ standing for . in the internal key (ITOPS_SECURITY_CORS_ALLOWED_ORIGINS is security.cors.allowed_origins). A config.yaml in /etc/itops/ is also read, but the Helm chart uses environment variables throughout and so does this page. In the chart, plain values go under env:, secrets under secretEnv: or secretRefs:.

Must set

Variable Default What it does
ITOPS_SERVER_ENVIRONMENT development Set to production. See what production mode forces.
ITOPS_JWT_SECRET a placeholder Signs user sessions (HS256). Change it, at least 32 random bytes.
ITOPS_SECURITY_OPERATOR_API_KEY empty The X-API-Key agents and scripts send. Empty disables authentication on the agent and push endpoints and logs a warning.
ITOPS_SECURITY_CORS_ALLOWED_ORIGINS http://localhost:*,http://127.0.0.1:* The UI's origin, comma-separated if several.
ITOPS_DATABASE_HOST / _PORT / _USER / _PASSWORD localhost / 5432 / itops / itops PostgreSQL. The chart fills these in for the bundled database.
ITOPS_DATABASE_NAME itops Database name. ITOPS_DATABASE_DATABASE is the same setting.
ITOPS_DATABASE_SSLMODE prefer disable in production logs a security warning.
ITOPS_LICENSE_KEY empty The Ed25519 JWT that activates plugins. See Licence and plugins.

Commonly set

Variable Default What it does
ITOPS_SECURITY_TRUST_PROXY false Read the client IP from X-Real-IP. Correct only behind a proxy that sets it honestly; see Install.
ITOPS_SLA_PORTAL_URL empty In-cluster URL of the public status page. The daily report is pushed here.
ITOPS_SLA_PORTAL_API_KEY empty Must equal the portal's apiKey.
ITOPS_SECURITY_RATE_LIMIT_ENABLED false (forced on in production) Per-IP token bucket.
ITOPS_SECURITY_RATE_LIMIT_REQUESTS_PER_SECOND 10
ITOPS_SECURITY_RATE_LIMIT_BURST_SIZE 20
ITOPS_SECURITY_WEBHOOK_HOST_ALLOWLIST empty If set, outgoing webhooks may only target these hosts.
ITOPS_SECURITY_ALLOW_PRIVATE_WEBHOOKS false Lets webhooks reach private addresses. Development only; it reopens the SSRF hole the validator closes.
ITOPS_SECURITY_WEBSOCKET_ALLOWED_ORIGINS same as CORS Origins allowed to open /graphql/ws.
ITOPS_LICENSE_PUBLIC_KEY built in Override the licence verification key.
ITOPS_JWT_ACCESS_TOKEN_EXPIRY 15m Access token lifetime.
ITOPS_JWT_REFRESH_TOKEN_EXPIRY 168h Refresh token lifetime, seven days.
ITOPS_LOGGING_LEVEL info debug, info, warn, error.
ITOPS_LOGGING_FORMAT json json or console.
ITOPS_COMPANY_TIMEZONE Europe/Budapest Default calendar for business-hours SLAs.
ITOPS_COMPANY_LANGUAGE hu Default UI language for new users.
ITOPS_FEATURES_LOCAL_AUTH true Username and password sign-in.
ITOPS_FEATURES_LDAP_AUTH false LDAP / Active Directory sign-in; configure it in users/ldap.yaml.
ITOPS_AUTH_BOOTSTRAP_PATH /etc/itops/users Where the provider YAML is read from.
ITOPS_AUTH_LDAP_SECRET_PATH /etc/itops/auth/ldap-secret Where the LDAP bind password is mounted.
ITOPS_TICKETING_CONFIG_PATH /etc/itops/ticketing Workflows, catalogue and organisation YAML.
ITOPS_PLUGINS_TICKETING_ENABLED / ITOPS_PLUGINS_SLA_ENABLED true Can only switch a licensed plugin off. Outside production they can also switch one on without a licence, for development.

Server and database tuning

Variable Default
ITOPS_SERVER_PORT / ITOPS_SERVER_HOST 8080 / 0.0.0.0
ITOPS_SERVER_READ_TIMEOUT / _WRITE_TIMEOUT / _IDLE_TIMEOUT 30s / 30s / 120s
ITOPS_SERVER_MAX_HEADER_BYTES 1 MiB
ITOPS_DATABASE_MAX_OPEN_CONNS / _MAX_IDLE_CONNS / _CONN_MAX_LIFETIME 25 / 5 / 5m
ITOPS_SECURITY_GRAPHQL_MAX_QUERY_DEPTH 15
ITOPS_SECURITY_GRAPHQL_MAX_BODY_SIZE_KB 256
ITOPS_SECURITY_GRAPHQL_INTROSPECTION_ENABLED true in development, forced false in production

Password policy for local accounts

Variable Default
ITOPS_DEFAULTS_PASSWORD_MIN_LENGTH 12
ITOPS_DEFAULTS_PASSWORD_REQUIRE_UPPERCASE / _LOWERCASE / _NUMBER / _SPECIAL true
ITOPS_DEFAULTS_PASSWORD_EXPIRY_DAYS 90
ITOPS_DEFAULTS_SESSION_TIMEOUT 480 minutes

The chart's users/local.yaml sets the same policy in YAML, with requireSymbol: false and a history of five; the YAML wins for the local provider when both are present.

What production mode forces

With ITOPS_SERVER_ENVIRONMENT=production the following are on regardless of their own variables:

  • security headers: X-Content-Type-Options: nosniff, X-Frame-Options: DENY, Referrer-Policy: strict-origin-when-cross-origin, a Content-Security-Policy of default-src 'self', and HSTS for two years including subdomains;
  • per-IP rate limiting;
  • GraphQL introspection off;
  • plugins activate through the licence only.

The /api/v1/dev/* test endpoints are compiled out of release images entirely; they exist only in development builds.

The GitOps directories

The chart mounts three directories into the core. There is no admin UI for any of them; the way to change them is to change the YAML and helm upgrade. That is deliberate: configuration that lives in Git cannot drift away from what is in Git.

Mount Source in the chart Read
/etc/itops/users/ users/*.yaml at every start: the sign-in providers and their settings
/etc/itops/groups/ groups/*.yaml at every start: groups are upserted into the database by name
/etc/itops/ticketing/ ticketing/workflows/, ticketing/catalog/, ticketing/org.yaml at start and on reload, only when the ticketing plugin is enabled

Users are deliberately not in YAML. Passwords, sessions and login history are runtime data; create people in the UI or let them arrive through LDAP. See Users, groups and roles and Ticketing configuration.

What is not there

  • There is no Redis and no message broker. Configuration keys for Redis still exist in the defaults and do nothing.
  • MFA is declared as a feature flag but not implemented. Turning ITOPS_FEATURES_MFA on makes every password login fail rather than pretend.
  • SSO providers other than LDAP (Entra ID, Okta, SAML and so on) are listed in the provider catalogue but return "not yet implemented" at sign-in.
Documentation for ITOps 4.2 · charts itops 2.0.0, sla-portal 1.4.0 · rendered 2026-09-11