Run Casdoor on Kubernetes with Helm
This guide explains how to install Casdoor on a Kubernetes cluster with the official Helm chart, expose it outside the cluster, and upgrade or remove the release.
Learning outcomes
- Install the Casdoor Helm chart.
- Override chart values, including the database connection.
- Expose Casdoor with Ingress or the Gateway API.
- Keep organizations, applications, and users in the values file.
- Upgrade and uninstall the release.
What you need
- A Kubernetes cluster, version 1.19 or later
- Helm 3.8 or later
- For the Gateway API option: the Gateway API CRDs and a Gateway controller in the cluster
Don't want to run it yourself? Casdoor Cloud gives you a dedicated Casdoor instance that we host and keep upgraded for you, from $25/month with no per-user fees.
Install the chart
The chart is published as an OCI artifact on GitHub Container Registry. It is listed on Artifact Hub, and its source is in the Casdoor repository.
-
Install the chart. Replace
<version>with a chart version from Artifact Hub.helm install casdoor oci://ghcr.io/casdoor/helm-charts/casdoor --version <version>To override values, pass your own values file:
helm install casdoor oci://ghcr.io/casdoor/helm-charts/casdoor --version <version> -f my-values.yaml -
Open Casdoor at the URL of the
casdoorservice in your cluster. With the default values, the service is of typeClusterIPon port 8000, so it is reachable only inside the cluster until you expose it.
Customize the deployment
Override the values of values.yaml in your own values file. The main values are:
| 参数 | 描述 | 默认值 |
|---|---|---|
replicaCount | 运行 Casdoor 应用的副本数量。 | 1 |
image.repository | Casdoor Docker 图像的仓库。 | casbin |
image.name | Casdoor Docker 图像的名称。 | casdoor |
image.pullPolicy | Casdoor Docker 图像的拉取策略。 | IfNotPresent |
image.tag | Casdoor Docker 图像的标签。 | "" |
config | Casdoor 应用的配置设置。 | See values.yaml |
database.driver | 要使用的数据库驱动程序(mysql、postgres、cockroachdb、sqlite)。 | sqlite |
database.user | 数据库用户名。 | "" |
database.password | 数据库密码。 | "" |
database.host | 数据库主机。 | "" |
database.port | 数据库端口。 | "" |
database.databaseName | Casdoor 使用的数据库名称。 | casdoor |
database.sslMode | 数据库连接的 SSL 模式。 | disable |
service.type | Kubernetes服务类型(ClusterIP、NodePort、LoadBalancer)。 | ClusterIP |
service.port | Casdoor 服务的端 口号。 | 8000 |
ingress.enabled | 是否启用 Casdoor 的 Ingress。 | false |
ingress.annotations | Ingress 资源的注解。 | {} |
ingress.hosts | Ingress 资源的主机名。 | [] |
resources | Casdoor 容器的资源请求和限制。 | {} |
autoscaling.enabled | 是否启用 Casdoor 的水平 Pod 自动扩展。 | false |
autoscaling.minReplicas | HPA 的最小副本数。 | 1 |
autoscaling.maxReplicas | HPA 的最大副本数。 | 100 |
autoscaling.targetCPUUtilizationPercentage | HPA 的目标 CPU 利用率百分比。 | 80 |
nodeSelector | Pod 分配的节点标签。 | {} |
tolerations | Pod 分配的容忍标签。 | [] |
affinity | Pod 分配的亲和性设置。 | {} |
extraContainersEnabled | 是否启用额外的边车容器。 | false |
extraContainers | 额外的边车容器。 | "" |
extraVolumeMounts | Casdoor 容器的额外卷挂载。 | [] |
extraVolumes | Casdoor 容器的额外卷。 | [] |
envFromSecret | 来自单个Secret密钥的环境变量。 | [] |
envFromConfigmap | 来自单个ConfigMap密钥的环境变量。 | [] |
envFrom |