Skip to content

Configuration values

Redirecting alpstack to your domain, cluster and cloud is largely a matter of setting a handful of values in values/global.yaml — the file every ArgoCD Application already includes as a value source — rather than editing dozens of charts.

What's a global, and what isn't

cluster.name, cluster.rootCA, dns.baseDomain, dns.appsDomain, realm, git.* and notifications.adminEmail are driven from values/global.yaml across all three GitOps repos — set them and the whole domain / realm / CA surface follows. What's left to touch is only genuinely per-site facts (IPs, NodePorts, S3 buckets); see what you still edit by hand.

The global.yaml you set

Each repo's values/global.yaml carries the keys that repo actually consumes:

global:
  # ArgoCD wiring
  sourceRepo:
    url: https://codeberg.org/<you>/platform-argocd.git
    revision: main
  server: https://kubernetes.default.svc
  namePrefix: platform            # platform | addons | opendesk (per repo)

  # Cluster identity. The cert-manager CA + ClusterIssuer derive from this as
  # <name>-ca / <name>-issuer; it's also the clusters/<name>/ overlay dir name.
  cluster:
    name: mycluster               # example: coeurli
    # The cluster's own internal root CA (PEM). Trusted by workloads that must reach
    # internally-issued TLS — ArgoCD's Dex OIDC, headlamp. One copy for every consumer.
    rootCA: |
      -----BEGIN CERTIFICATE-----
      ...your cluster CA...
      -----END CERTIFICATE-----

  # DNS. baseDomain = the public apex; appsDomain = the internal wildcard for
  # the platform's own admin UIs.
  dns:
    baseDomain: example.com            # example: coeur.li
    appsDomain: apps.int.example.com   # example: apps.int.coeur.li

  # Keycloak realm slug backing SSO (addons + openDesk). Every OIDC issuer is
  # https://id.<dns.baseDomain>/realms/<realm>.  (addons-argocd)
  realm: opendesk

  # Git host for Renovate + the cluster-digest bot (platform-argocd only)
  git:
    owner: <you>                  # example: alpstack
    platform: forgejo             # forgejo | github | gitlab
    endpoint: https://codeberg.org

  # Notifications — ACME registration email + digest recipient (platform-argocd only)
  notifications:
    adminEmail: admin@example.com # example: admin@coeur.li

  # Backup object storage — the shared S3-compatible provider host + region every backup
  # track uses. Bare host; consumers that need a URL prepend the scheme. (all repos)
  backup:
    s3:
      endpoint: s3.example.com     # example: sos-ch-dk-2.exo.io
      region: your-region          # example: ch-dk-2

What each global controls

Value Controls Repos
sourceRepo.* / server / namePrefix ArgoCD repo + deploy wiring all
cluster.name VMRule name prefixes + cluster-digest report (platform); the cert-manager <name>-ca / <name>-issuer, internal-gateway, garage S3 Ingress issuer; each ArgoCD instance's <name>-argocd UI domain platform, opendesk, addons
cluster.rootCA the CA cert ArgoCD's Dex OIDC (oidc.config rootCA) and headlamp's CA mount trust — one copy for every consumer platform, opendesk, addons
dns.baseDomain the whole openDesk public cert-SAN set (21 hosts), netbird/vaultwarden certs, the NetBird DNS-zone, garage's S3 host, coturn realm + dnsName opendesk, addons
dns.appsDomain internal HTTPRoutes, the internal-gateway wildcard, ops-proxy (11 hosts + its OIDC config), imapsync, each ArgoCD Dex issuer + oauth2-proxy/grafana/headlamp OIDC platform, opendesk, addons
realm the Keycloak realm slug in every OIDC issuer URL — https://id.<baseDomain>/realms/<realm> (netbird, vaultwarden) addons
git.owner / platform / endpoint Renovate repo list + cluster-digest API / issue repo platform
notifications.adminEmail cert-manager ACME registration + cluster-digest recipient + Alertmanager to platform
backup.s3.endpoint / region the S3 endpoint + region for every backup track — longhorn, garage, postgres, mariadb, vaultwarden (per-store bucket names stay per-chart) all

The templates read global.<key> directly (or, for values Helm can't template in a subchart values.yaml, via the app-of-apps Application's inline helm.values), so setting any of these in values/global.yaml redirects every chart that references it.

What you still edit by hand

Only genuinely per-site facts need a manual edit; the domain / realm / CA surface is entirely global-driven.

Subchart values are global-driven too

Some domain / realm / CA values are consumed by an upstream subchart's static values.yaml, which Helm never templates. They come from global.yaml through the app-of-apps Application's inline helm.values string, so they need no manual edit either. Each such key carries a # [set-in-template] breadcrumb in the chart's values.yaml pointing back to global.yaml.

Genuinely per-site facts (no shared default exists)

  • Physical network — LAN/WAN CIDRs, the LB IP pool, HAProxy publish IPs, etcd scrape targets, and the NodePort contract.
  • NetBird management.config in addons-argocd — the pinned ClusterIPs, hand-rolled EndpointSlices and server-assigned Network UUID (danger note), plus the OIDC issuer URLs embedded in the same per-site JSON blob. Re-pin / re-set per cluster.
  • Backup S3 buckets — the per-store bucket names (postgres / mariadb / garage / longhorn / vaultwarden). Set per chart; the shared endpoint + region are global.backup.s3.*.
  • The openDesk application content (13 DB/user names, the realm, Matrix server_name) — entwined with the upstream render; change via the render inputs.
  • Secrets — never in values at all; see Secrets.

Next: Secrets →