Configuration
Every ITOPS_* environment variable a customer sets, what production mode forces, and the GitOps directories the chart mounts.
The core reads its configuration from environment variables prefixed ITOPS_, with _ standing for . in the internal key (ITOPS_SECURITY_CORS_ALLOWED_ORIGINS is security.cors.allowed_origins). A config.yaml in /etc/itops/ is also read, but the Helm chart uses environment variables throughout and so does this page. In the chart, plain values go under env:, secrets under secretEnv: or secretRefs:.
Must set
| Variable | Default | What it does |
|---|---|---|
ITOPS_SERVER_ENVIRONMENT |
development |
Set to production. See what production mode forces. |
ITOPS_JWT_SECRET |
a placeholder | Signs user sessions (HS256). Change it, at least 32 random bytes. |
ITOPS_SECURITY_OPERATOR_API_KEY |
empty | The X-API-Key agents and scripts send. Empty disables authentication on the agent and push endpoints and logs a warning. |
ITOPS_SECURITY_CORS_ALLOWED_ORIGINS |
http://localhost:*,http://127.0.0.1:* |
The UI's origin, comma-separated if several. |
ITOPS_DATABASE_HOST / _PORT / _USER / _PASSWORD |
localhost / 5432 / itops / itops |
PostgreSQL. The chart fills these in for the bundled database. |
ITOPS_DATABASE_NAME |
itops |
Database name. ITOPS_DATABASE_DATABASE is the same setting. |
ITOPS_DATABASE_SSLMODE |
prefer |
disable in production logs a security warning. |
ITOPS_LICENSE_KEY |
empty | The Ed25519 JWT that activates plugins. See Licence and plugins. |
Commonly set
| Variable | Default | What it does |
|---|---|---|
ITOPS_SECURITY_TRUST_PROXY |
false |
Read the client IP from X-Real-IP. Correct only behind a proxy that sets it honestly; see Install. |
ITOPS_SLA_PORTAL_URL |
empty | In-cluster URL of the public status page. The daily report is pushed here. |
ITOPS_SLA_PORTAL_API_KEY |
empty | Must equal the portal's apiKey. |
ITOPS_SECURITY_RATE_LIMIT_ENABLED |
false (forced on in production) |
Per-IP token bucket. |
ITOPS_SECURITY_RATE_LIMIT_REQUESTS_PER_SECOND |
10 |
|
ITOPS_SECURITY_RATE_LIMIT_BURST_SIZE |
20 |
|
ITOPS_SECURITY_WEBHOOK_HOST_ALLOWLIST |
empty | If set, outgoing webhooks may only target these hosts. |
ITOPS_SECURITY_ALLOW_PRIVATE_WEBHOOKS |
false |
Lets webhooks reach private addresses. Development only; it reopens the SSRF hole the validator closes. |
ITOPS_SECURITY_WEBSOCKET_ALLOWED_ORIGINS |
same as CORS | Origins allowed to open /graphql/ws. |
ITOPS_LICENSE_PUBLIC_KEY |
built in | Override the licence verification key. |
ITOPS_JWT_ACCESS_TOKEN_EXPIRY |
15m |
Access token lifetime. |
ITOPS_JWT_REFRESH_TOKEN_EXPIRY |
168h |
Refresh token lifetime, seven days. |
ITOPS_LOGGING_LEVEL |
info |
debug, info, warn, error. |
ITOPS_LOGGING_FORMAT |
json |
json or console. |
ITOPS_COMPANY_TIMEZONE |
Europe/Budapest |
Default calendar for business-hours SLAs. |
ITOPS_COMPANY_LANGUAGE |
hu |
Default UI language for new users. |
ITOPS_FEATURES_LOCAL_AUTH |
true |
Username and password sign-in. |
ITOPS_FEATURES_LDAP_AUTH |
false |
LDAP / Active Directory sign-in; configure it in users/ldap.yaml. |
ITOPS_AUTH_BOOTSTRAP_PATH |
/etc/itops/users |
Where the provider YAML is read from. |
ITOPS_AUTH_LDAP_SECRET_PATH |
/etc/itops/auth/ldap-secret |
Where the LDAP bind password is mounted. |
ITOPS_TICKETING_CONFIG_PATH |
/etc/itops/ticketing |
Workflows, catalogue and organisation YAML. |
ITOPS_PLUGINS_TICKETING_ENABLED / ITOPS_PLUGINS_SLA_ENABLED |
true |
Can only switch a licensed plugin off. Outside production they can also switch one on without a licence, for development. |
Server and database tuning
| Variable | Default |
|---|---|
ITOPS_SERVER_PORT / ITOPS_SERVER_HOST |
8080 / 0.0.0.0 |
ITOPS_SERVER_READ_TIMEOUT / _WRITE_TIMEOUT / _IDLE_TIMEOUT |
30s / 30s / 120s |
ITOPS_SERVER_MAX_HEADER_BYTES |
1 MiB |
ITOPS_DATABASE_MAX_OPEN_CONNS / _MAX_IDLE_CONNS / _CONN_MAX_LIFETIME |
25 / 5 / 5m |
ITOPS_SECURITY_GRAPHQL_MAX_QUERY_DEPTH |
15 |
ITOPS_SECURITY_GRAPHQL_MAX_BODY_SIZE_KB |
256 |
ITOPS_SECURITY_GRAPHQL_INTROSPECTION_ENABLED |
true in development, forced false in production |
Password policy for local accounts
| Variable | Default |
|---|---|
ITOPS_DEFAULTS_PASSWORD_MIN_LENGTH |
12 |
ITOPS_DEFAULTS_PASSWORD_REQUIRE_UPPERCASE / _LOWERCASE / _NUMBER / _SPECIAL |
true |
ITOPS_DEFAULTS_PASSWORD_EXPIRY_DAYS |
90 |
ITOPS_DEFAULTS_SESSION_TIMEOUT |
480 minutes |
The chart's users/local.yaml sets the same policy in YAML, with requireSymbol: false and a history of five; the YAML wins for the local provider when both are present.
What production mode forces
With ITOPS_SERVER_ENVIRONMENT=production the following are on regardless of their own variables:
- security headers:
X-Content-Type-Options: nosniff,X-Frame-Options: DENY,Referrer-Policy: strict-origin-when-cross-origin, aContent-Security-Policyofdefault-src 'self', and HSTS for two years including subdomains; - per-IP rate limiting;
- GraphQL introspection off;
- plugins activate through the licence only.
The /api/v1/dev/* test endpoints are compiled out of release images entirely; they exist only in development builds.
The GitOps directories
The chart mounts three directories into the core. There is no admin UI for any of them; the way to change them is to change the YAML and helm upgrade. That is deliberate: configuration that lives in Git cannot drift away from what is in Git.
| Mount | Source in the chart | Read |
|---|---|---|
/etc/itops/users/ |
users/*.yaml |
at every start: the sign-in providers and their settings |
/etc/itops/groups/ |
groups/*.yaml |
at every start: groups are upserted into the database by name |
/etc/itops/ticketing/ |
ticketing/workflows/, ticketing/catalog/, ticketing/org.yaml |
at start and on reload, only when the ticketing plugin is enabled |
Users are deliberately not in YAML. Passwords, sessions and login history are runtime data; create people in the UI or let them arrive through LDAP. See Users, groups and roles and Ticketing configuration.
What is not there
- There is no Redis and no message broker. Configuration keys for Redis still exist in the defaults and do nothing.
- MFA is declared as a feature flag but not implemented. Turning
ITOPS_FEATURES_MFAon makes every password login fail rather than pretend. - SSO providers other than LDAP (Entra ID, Okta, SAML and so on) are listed in the provider catalogue but return "not yet implemented" at sign-in.