blob: e1ab39490f193454e39b9384b1f8017709ac852a [file]
#
# Licensed to the Apache Software Foundation (ASF) under one
# or more contributor license agreements. See the NOTICE file
# distributed with this work for additional information
# regarding copyright ownership. The ASF licenses this file
# to you under the Apache License, Version 2.0 (the
# "License"); you may not use this file except in compliance
# with the License. You may obtain a copy of the License at
#
# http://www.apache.org/licenses/LICENSE-2.0
#
# Unless required by applicable law or agreed to in writing,
# software distributed under the License is distributed on an
# "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
# KIND, either express or implied. See the License for the
# specific language governing permissions and limitations
# under the License.
#
auth:
authentication:
enabled: true
jwt:
# Enable JWT authentication
enabled: true
# The token is generated from an asymmetric private key, so set usingSecretKey to false.
# (Set it to true when signing tokens with a symmetric secret key.)
usingSecretKey: false
# Generate the RSA signing key pair and one token per superuser in-chart, via a
# pre-install/pre-upgrade hook job. This removes the need to run
# prepare_helm_release.sh (or any out-of-band script) before installing, so a
# fully-authenticated cluster can be deployed with a single `helm install`.
# See https://github.com/apache/pulsar-helm-chart#in-chart-jwt-secret-generation
generateSecrets:
enabled: true
authorization:
enabled: true
superUsers:
# broker to broker communication
broker: "broker-admin"
# proxy to broker communication
proxy: "proxy-admin"
# pulsar-admin client to broker/proxy communication
client: "admin"