---
title: Charmhub | Deploy Authentik LDAP Outpost Operator using Charmhub - The Open
  Operator Collection
description: Deploy the latest version of Authentik LDAP Outpost Operator as a Kubernetes
  Operator on any cloud.
url: https://charmhub.io/authentik-ldap-outpost/configurations
---

# Authentik LDAP Outpost Operator

[prod-identity-charmhub-bot-2](https://charmhub.io/publisher/prod-identity-charmhub-bot-2 "View all packages from prod-identity-charmhub-bot-2")

* [prod-identity-charmhub-bot-2](https://charmhub.io/publisher/prod-identity-charmhub-bot-2 "View all packages from prod-identity-charmhub-bot-2")

Platform:

stable 23

```
juju deploy authentik-ldap-outpost
```

[Learn to deploy on juju >](https://juju.is/docs/juju/manage-applications)

* [base\_dn](https://charmhub.io/authentik-ldap-outpost/configurations#base_dn)
* [bind\_mode](https://charmhub.io/authentik-ldap-outpost/configurations#bind_mode)
* [cpu](https://charmhub.io/authentik-ldap-outpost/configurations#cpu)
* [expose\_ldap\_ingress](https://charmhub.io/authentik-ldap-outpost/configurations#expose_ldap_ingress)
* [http\_proxy](https://charmhub.io/authentik-ldap-outpost/configurations#http_proxy)
* [https\_proxy](https://charmhub.io/authentik-ldap-outpost/configurations#https_proxy)
* [ingress\_domain](https://charmhub.io/authentik-ldap-outpost/configurations#ingress_domain)
* [log\_level](https://charmhub.io/authentik-ldap-outpost/configurations#log_level)
* [memory](https://charmhub.io/authentik-ldap-outpost/configurations#memory)
* [mfa\_support](https://charmhub.io/authentik-ldap-outpost/configurations#mfa_support)
* [no\_proxy](https://charmhub.io/authentik-ldap-outpost/configurations#no_proxy)
* [search\_mode](https://charmhub.io/authentik-ldap-outpost/configurations#search_mode)

[Learn about configurations >](https://juju.is/docs/juju/configuration#heading--application-configuration)

* base\_dn | string

  Default: dc=ldap,dc=goauthentik,dc=io

  Base DN under which LDAP objects are accessible.
* bind\_mode | string

  Default: cached

  LDAP bind mode: direct or cached.
* cpu | string

  K8s cpu resource limit, e.g. "1" or "500m". Default is unset (no limit). This value is used
  for the "limits" portion of the resource requirements (the "requests" portion is
  automatically deduced from it).
  See https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/
* expose\_ldap\_ingress | boolean

  Enable exposing the plain LDAP endpoint (Port 389/3389) via Traefik.

  WARNING: Plain LDAP does not encrypt connection traffic. Use this option
  only if your Traefik instance is internal/private and your legacy clients
  do not support LDAPS.

  Note: Since cleartext TCP traffic lacks TLS/SNI, Traefik routes this
  via HostSNI(`*`). If multiple charms/outposts try to enable this on the
  same Traefik instance, a port/routing conflict will occur.
* http\_proxy | string

  URL of the HTTP proxy eg http://proxy.internal:6666, it will set the HTTP\_PROXY var in the workload environment
* https\_proxy | string

  URL of the HTTPS proxy eg http://proxy.internal:6666, it will set the HTTPS\_PROXY var in the workload environment
* ingress\_domain | string

  The custom domain name to use for the external ingress route (e.g. "outpost.example.com").
  If unset, the route rule defaults to "HostSNI(`*`)" to match all incoming TLS traffic on port 636.
* log\_level | string

  Default: info

  Configures the log level.

  Acceptable values are: "info", "debug", "warning", "error" and "critical"
* memory | string

  K8s memory resource limit, e.g. "1Gi". Default is unset (no limit). This value is used
  for the "limits" portion of the resource requirements (the "requests" portion is
  automatically deduced from it).
  See https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/
* mfa\_support | boolean

  Enable/disable multi-factor authentication support via password-appending.
* no\_proxy | string

  Domains that need to be excluded from proxying no\_proxy="test.com,test.co.uk", it is a comma separate list
* search\_mode | string

  Default: cached

  LDAP search mode: direct or cached.
