Skip to main content

Run Casdoor on Kubernetes with Helm

This guide explains how to install Casdoor on a Kubernetes cluster with the official Helm chart, expose it outside the cluster, and upgrade or remove the release.


Learning outcomes​

  • Install the Casdoor Helm chart.
  • Override chart values, including the database connection.
  • Expose Casdoor with Ingress or the Gateway API.
  • Keep organizations, applications, and users in the values file.
  • Upgrade and uninstall the release.

What you need​

  • A Kubernetes cluster, version 1.19 or later
  • Helm 3.8 or later
  • For the Gateway API option: the Gateway API CRDs and a Gateway controller in the cluster

Don't want to run it yourself?

Casdoor Cloud gives you a dedicated Casdoor instance that we host and keep upgraded for you, from $25/month with no per-user fees.

Install the chart​

The chart is published as an OCI artifact on GitHub Container Registry. It is listed on Artifact Hub, and its source is in the Casdoor repository.

  1. Install the chart. Replace <version> with a chart version from Artifact Hub.

    helm install casdoor oci://ghcr.io/casdoor/helm-charts/casdoor --version <version>

    To override values, pass your own values file:

    helm install casdoor oci://ghcr.io/casdoor/helm-charts/casdoor      --version <version>      -f my-values.yaml
  2. Open Casdoor at the URL of the casdoor service in your cluster. With the default values, the service is of type ClusterIP on port 8000, so it is reachable only inside the cluster until you expose it.

Customize the deployment​

Override the values of values.yaml in your own values file. The main values are:

ParameterDescriptionDefault
replicaCountNumber of replicas of the Casdoor application to run.1
image.repositoryRepository for the Casdoor Docker image.casbin
image.nameName of the Casdoor Docker image.casdoor
image.pullPolicyPull policy for the Casdoor Docker image.IfNotPresent
image.tagTag for the Casdoor Docker image.""
configConfiguration settings for the Casdoor application.See values.yaml
database.driverDatabase driver to use (mysql, postgres, cockroachdb, sqlite).sqlite
database.userDatabase username.""
database.passwordDatabase password.""
database.hostDatabase host.""
database.portDatabase port.""
database.databaseNameName of the database used by Casdoor.casdoor
database.sslModeSSL mode for the database connection.disable
service.typeType of Kubernetes service (ClusterIP, NodePort, LoadBalancer).ClusterIP
service.portPort number for the Casdoor service.8000
ingress.enabledWhether to enable Ingress for Casdoor.false
ingress.annotationsAnnotations for the Ingress resource.{}
ingress.hostsHostnames for the Ingress resource.[]
resourcesResource requests and limits for the Casdoor container.{}
autoscaling.enabledWhether to enable Horizontal Pod Autoscaler for Casdoor.false
autoscaling.minReplicasMinimum number of replicas for HPA.1
autoscaling.maxReplicasMaximum number of replicas for HPA.100
autoscaling.targetCPUUtilizationPercentageTarget CPU utilization percentage for HPA.80
nodeSelectorNode labels for pod assignment.{}
tolerationsToleration labels for pod assignment.[]
affinityAffinity settings for pod assignment.{}
extraContainersEnabledWhether to enable additional sidecar containers.false
extraContainersAdditional sidecar containers.""
extraVolumeMountsAdditional volume mounts for the Casdoor container.[]
extraVolumesAdditional volumes for the Casdoor container.[]
envFromSecretEnvironment variables from individual Secret keys.[]
envFromConfigmapEnvironment variables from individual ConfigMap keys.[]
envFromEnvironment variables from entire Secrets or ConfigMaps.[]

Expose Casdoor​

Choose Ingress or the Gateway API.

Expose Casdoor with Ingress​

Enable Ingress in your values file:

ingress:
enabled: true
className: nginx
annotations:
cert-manager.io/cluster-issuer: letsencrypt-prod
hosts:
- host: casdoor.example.com
paths:
- path: /
pathType: Prefix
tls:
- secretName: casdoor-tls
hosts:
- casdoor.example.com

Expose Casdoor with the Gateway API​

The Kubernetes Gateway API is the successor to Ingress. Istio, Envoy Gateway, Cilium, Kong, NGINX Gateway Fabric, and other controllers support it.

Before you enable this option, install the Gateway API CRDs and make sure that a compatible Gateway controller runs in the cluster:

kubectl apply -f https://github.com/kubernetes-sigs/gateway-api/releases/download/v1.2.0/standard-install.yaml

Then use one of the following configurations.

Attach to an existing Gateway​

If the cluster already has a Gateway, point the HTTPRoute at it:

gatewayApi:
enabled: true
parentRefs:
- name: my-gateway
namespace: gateway-system
sectionName: https
hostnames:
- casdoor.example.com

Create a Gateway​

Let the chart create a Gateway together with the HTTPRoute. This example uses Istio:

gatewayApi:
enabled: true
createGateway: true
hostnames:
- casdoor.example.com
gateway:
gatewayClassName: istio
listeners:
- name: http
protocol: HTTP
port: 80
allowedRoutes:
namespaces:
from: Same

Create a Gateway that redirects HTTP to HTTPS​

Terminate TLS at the Gateway and redirect HTTP requests to HTTPS:

gatewayApi:
enabled: true
createGateway: true
hostnames:
- casdoor.example.com
gateway:
gatewayClassName: istio
listeners:
- name: http
protocol: HTTP
port: 80
allowedRoutes:
namespaces:
from: Same
- name: https
protocol: HTTPS
port: 443
tls:
certificateRefs:
- name: casdoor-tls
kind: Secret
allowedRoutes:
namespaces:
from: Same
httpsRedirect:
enabled: true

Gateway API values​

ParameterDescriptionDefault
gatewayApi.enabledEnable HTTPRoute creationfalse
gatewayApi.createGatewayAlso create a Gateway resourcefalse
gatewayApi.annotationsAnnotations for the HTTPRoute{}
gatewayApi.labelsExtra labels for the HTTPRoute{}
gatewayApi.parentRefsParent Gateway references[]
gatewayApi.hostnamesHostnames to match (Host header)[]
gatewayApi.rulesRouting rules (matches, filters, backendRefs)PathPrefix /
gatewayApi.gateway.nameGateway name (defaults to chart fullname)""
gatewayApi.gateway.gatewayClassNameGatewayClass name (required when createGateway=true)""
gatewayApi.gateway.listenersGateway listenersHTTP:80
gatewayApi.httpsRedirect.enabledEnable HTTP→HTTPS redirect HTTPRoutefalse
gatewayApi.httpsRedirect.statusCodeRedirect response code301
gatewayApi.httpsRedirect.hostnamesHostnames for redirect route[]
gatewayApi.httpsRedirect.parentRefsOverride parentRefs for redirect route[]

Manage Casdoor objects in the values file​

You can keep organizations, applications, users, providers, roles, and permissions in the values file, next to the rest of the deployment. Casdoor applies them at startup and checks them for changes every 30 seconds. A helm upgrade that changes them takes effect without restarting the pods.

initData:
enabled: true
data:
organizations:
- owner: admin
name: acme
displayName: Acme
passwordType: bcrypt
applications:
- owner: admin
name: app-acme
organization: acme
displayName: Acme Portal
redirectUris:
- https://portal.acme.example.com/callback

An existing object receives only the fields that you write here. Its other fields keep the values that were set in the admin console.

The chart stores the data in a Secret. To keep the data out of the values file, create the Secret yourself and set initData.existingSecret.

ParameterDescriptionDefault
initData.enabledApply initData.data (or initData.existingSecret)false
initData.mergeUpdate existing objects with the given fields only; when false, they are deleted and re-created on every applytrue
initData.watchIntervalSeconds between the checks for changes, 0 applies the data only at startup30
initData.existingSecretExisting Secret holding the data, instead of initData.data""
initData.existingSecretKeyKey of the file in existingSecret, .yaml/.yml keys are read as YAMLinit_data.yaml
initData.dataThe objects to apply, in the init data format{}

Upgrade the release​

helm upgrade casdoor oci://ghcr.io/casdoor/helm-charts/casdoor --version <version>
note

Charts up to version 4.15.0 were published as oci://registry-1.docker.io/casbin/casdoor-helm-charts. That location still receives every release. To move an existing release to the new location, run the helm upgrade command above. Resource names stay the same.

Uninstall the release​

helm uninstall casdoor

See also​