---
title: Charmhub | Deploy Canonical Livepatch Server K8S using Charmhub - The Open
  Operator Collection
description: Deploy the latest version of Canonical Livepatch Server K8S as a Kubernetes
  Operator on any cloud.
url: https://charmhub.io/canonical-livepatch-server-k8s/configurations
---

# Canonical Livepatch Server K8S

[Commercial Systems](https://charmhub.io/publisher/commercial-systems "View all packages from Commercial Systems")

* [Commercial Systems](https://charmhub.io/publisher/commercial-systems "View all packages from Commercial Systems")

Platform:

stable v2.3.0

```
juju deploy canonical-livepatch-server-k8s
```

[Learn to deploy on juju >](https://juju.is/docs/juju/manage-applications)

* [auth.basic.enabled](https://charmhub.io/canonical-livepatch-server-k8s/configurations#auth.basic.enabled)
* [auth.basic.users](https://charmhub.io/canonical-livepatch-server-k8s/configurations#auth.basic.users)
* [auth.oauth.allowed-cidp-groups](https://charmhub.io/canonical-livepatch-server-k8s/configurations#auth.oauth.allowed-cidp-groups)
* [auth.oauth.audience](https://charmhub.io/canonical-livepatch-server-k8s/configurations#auth.oauth.audience)
* [auth.oauth.enabled](https://charmhub.io/canonical-livepatch-server-k8s/configurations#auth.oauth.enabled)
* [auth.oauth.issuer](https://charmhub.io/canonical-livepatch-server-k8s/configurations#auth.oauth.issuer)
* [auth.oauth.jwks.refresh-interval](https://charmhub.io/canonical-livepatch-server-k8s/configurations#auth.oauth.jwks.refresh-interval)
* [auth.oauth.jwks.refresh-unknown-kid](https://charmhub.io/canonical-livepatch-server-k8s/configurations#auth.oauth.jwks.refresh-unknown-kid)
* [auth.oauth.jwks.refresh-unknown-kid-limit](https://charmhub.io/canonical-livepatch-server-k8s/configurations#auth.oauth.jwks.refresh-unknown-kid-limit)
* [auth.oauth.jwks.refresh-unknown-kid-max-wait](https://charmhub.io/canonical-livepatch-server-k8s/configurations#auth.oauth.jwks.refresh-unknown-kid-max-wait)
* [auth.oauth.jwks.url](https://charmhub.io/canonical-livepatch-server-k8s/configurations#auth.oauth.jwks.url)
* [auth.oauth.proxy.enabled](https://charmhub.io/canonical-livepatch-server-k8s/configurations#auth.oauth.proxy.enabled)
* [auth.oauth.proxy.http](https://charmhub.io/canonical-livepatch-server-k8s/configurations#auth.oauth.proxy.http)
* [auth.oauth.proxy.https](https://charmhub.io/canonical-livepatch-server-k8s/configurations#auth.oauth.proxy.https)
* [auth.oauth.proxy.no-proxy](https://charmhub.io/canonical-livepatch-server-k8s/configurations#auth.oauth.proxy.no-proxy)
* [auth.oauth.sig-algs](https://charmhub.io/canonical-livepatch-server-k8s/configurations#auth.oauth.sig-algs)
* [auth.sso.enabled](https://charmhub.io/canonical-livepatch-server-k8s/configurations#auth.sso.enabled)
* [auth.sso.public-key](https://charmhub.io/canonical-livepatch-server-k8s/configurations#auth.sso.public-key)
* [auth.sso.teams](https://charmhub.io/canonical-livepatch-server-k8s/configurations#auth.sso.teams)
* [auth.sso.url](https://charmhub.io/canonical-livepatch-server-k8s/configurations#auth.sso.url)
* [cloud\_delay.default\_delay\_hours](https://charmhub.io/canonical-livepatch-server-k8s/configurations#cloud_delay.default_delay_hours)
* [cloud\_delay.enabled](https://charmhub.io/canonical-livepatch-server-k8s/configurations#cloud_delay.enabled)
* [contracts.ca](https://charmhub.io/canonical-livepatch-server-k8s/configurations#contracts.ca)
* [contracts.enabled](https://charmhub.io/canonical-livepatch-server-k8s/configurations#contracts.enabled)
* [contracts.password](https://charmhub.io/canonical-livepatch-server-k8s/configurations#contracts.password)
* [contracts.url](https://charmhub.io/canonical-livepatch-server-k8s/configurations#contracts.url)
* [contracts.user](https://charmhub.io/canonical-livepatch-server-k8s/configurations#contracts.user)
* [cve-lookup.auth-required](https://charmhub.io/canonical-livepatch-server-k8s/configurations#cve-lookup.auth-required)
* [cve-lookup.enabled](https://charmhub.io/canonical-livepatch-server-k8s/configurations#cve-lookup.enabled)
* [cve-sync.enabled](https://charmhub.io/canonical-livepatch-server-k8s/configurations#cve-sync.enabled)
* [cve-sync.interval](https://charmhub.io/canonical-livepatch-server-k8s/configurations#cve-sync.interval)
* [cve-sync.proxy.enabled](https://charmhub.io/canonical-livepatch-server-k8s/configurations#cve-sync.proxy.enabled)
* [cve-sync.proxy.http](https://charmhub.io/canonical-livepatch-server-k8s/configurations#cve-sync.proxy.http)
* [cve-sync.proxy.https](https://charmhub.io/canonical-livepatch-server-k8s/configurations#cve-sync.proxy.https)
* [cve-sync.proxy.no-proxy](https://charmhub.io/canonical-livepatch-server-k8s/configurations#cve-sync.proxy.no-proxy)
* [cve-sync.source-url](https://charmhub.io/canonical-livepatch-server-k8s/configurations#cve-sync.source-url)
* [cve-sync.timeout](https://charmhub.io/canonical-livepatch-server-k8s/configurations#cve-sync.timeout)
* [database.connection-lifetime-max](https://charmhub.io/canonical-livepatch-server-k8s/configurations#database.connection-lifetime-max)
* [database.connection-pool-max](https://charmhub.io/canonical-livepatch-server-k8s/configurations#database.connection-pool-max)
* [database.work\_mem](https://charmhub.io/canonical-livepatch-server-k8s/configurations#database.work_mem)
* [influx.bucket](https://charmhub.io/canonical-livepatch-server-k8s/configurations#influx.bucket)
* [influx.enabled](https://charmhub.io/canonical-livepatch-server-k8s/configurations#influx.enabled)
* [influx.organization](https://charmhub.io/canonical-livepatch-server-k8s/configurations#influx.organization)
* [influx.ping\_bucket](https://charmhub.io/canonical-livepatch-server-k8s/configurations#influx.ping_bucket)
* [influx.token](https://charmhub.io/canonical-livepatch-server-k8s/configurations#influx.token)
* [influx.url](https://charmhub.io/canonical-livepatch-server-k8s/configurations#influx.url)
* [ingress-interface](https://charmhub.io/canonical-livepatch-server-k8s/configurations#ingress-interface)
* [kpi-reports.enabled](https://charmhub.io/canonical-livepatch-server-k8s/configurations#kpi-reports.enabled)
* [kpi-reports.interval](https://charmhub.io/canonical-livepatch-server-k8s/configurations#kpi-reports.interval)
* [lsn-sync.enabled](https://charmhub.io/canonical-livepatch-server-k8s/configurations#lsn-sync.enabled)
* [lsn-sync.interval](https://charmhub.io/canonical-livepatch-server-k8s/configurations#lsn-sync.interval)
* [lsn-sync.proxy.enabled](https://charmhub.io/canonical-livepatch-server-k8s/configurations#lsn-sync.proxy.enabled)
* [lsn-sync.proxy.http](https://charmhub.io/canonical-livepatch-server-k8s/configurations#lsn-sync.proxy.http)
* [lsn-sync.proxy.https](https://charmhub.io/canonical-livepatch-server-k8s/configurations#lsn-sync.proxy.https)
* [lsn-sync.proxy.no-proxy](https://charmhub.io/canonical-livepatch-server-k8s/configurations#lsn-sync.proxy.no-proxy)
* [lsn-sync.source-url](https://charmhub.io/canonical-livepatch-server-k8s/configurations#lsn-sync.source-url)
* [lsn-sync.timeout](https://charmhub.io/canonical-livepatch-server-k8s/configurations#lsn-sync.timeout)
* [machine-reports.database.cleanup-interval](https://charmhub.io/canonical-livepatch-server-k8s/configurations#machine-reports.database.cleanup-interval)
* [machine-reports.database.cleanup-row-limit](https://charmhub.io/canonical-livepatch-server-k8s/configurations#machine-reports.database.cleanup-row-limit)
* [machine-reports.database.enabled](https://charmhub.io/canonical-livepatch-server-k8s/configurations#machine-reports.database.enabled)
* [machine-reports.database.retention-days](https://charmhub.io/canonical-livepatch-server-k8s/configurations#machine-reports.database.retention-days)
* [otel-metrics.enabled](https://charmhub.io/canonical-livepatch-server-k8s/configurations#otel-metrics.enabled)
* [otel-metrics.export-interval](https://charmhub.io/canonical-livepatch-server-k8s/configurations#otel-metrics.export-interval)
* [otel-metrics.export-timeout](https://charmhub.io/canonical-livepatch-server-k8s/configurations#otel-metrics.export-timeout)
* [otel-metrics.service-name](https://charmhub.io/canonical-livepatch-server-k8s/configurations#otel-metrics.service-name)
* [patch-blocklist.enabled](https://charmhub.io/canonical-livepatch-server-k8s/configurations#patch-blocklist.enabled)
* [patch-blocklist.refresh-interval](https://charmhub.io/canonical-livepatch-server-k8s/configurations#patch-blocklist.refresh-interval)
* [patch-cache.cache-size](https://charmhub.io/canonical-livepatch-server-k8s/configurations#patch-cache.cache-size)
* [patch-cache.cache-ttl](https://charmhub.io/canonical-livepatch-server-k8s/configurations#patch-cache.cache-ttl)
* [patch-cache.enabled](https://charmhub.io/canonical-livepatch-server-k8s/configurations#patch-cache.enabled)
* [patch-storage.azure-account-key](https://charmhub.io/canonical-livepatch-server-k8s/configurations#patch-storage.azure-account-key)
* [patch-storage.azure-account-name](https://charmhub.io/canonical-livepatch-server-k8s/configurations#patch-storage.azure-account-name)
* [patch-storage.azure-client-id](https://charmhub.io/canonical-livepatch-server-k8s/configurations#patch-storage.azure-client-id)
* [patch-storage.azure-client-secret](https://charmhub.io/canonical-livepatch-server-k8s/configurations#patch-storage.azure-client-secret)
* [patch-storage.azure-connection-string](https://charmhub.io/canonical-livepatch-server-k8s/configurations#patch-storage.azure-connection-string)
* [patch-storage.azure-container](https://charmhub.io/canonical-livepatch-server-k8s/configurations#patch-storage.azure-container)
* [patch-storage.azure-managed-identity-client-id](https://charmhub.io/canonical-livepatch-server-k8s/configurations#patch-storage.azure-managed-identity-client-id)
* [patch-storage.azure-tenant-id](https://charmhub.io/canonical-livepatch-server-k8s/configurations#patch-storage.azure-tenant-id)
* [patch-storage.filesystem-path](https://charmhub.io/canonical-livepatch-server-k8s/configurations#patch-storage.filesystem-path)
* [patch-storage.gcs-bucket](https://charmhub.io/canonical-livepatch-server-k8s/configurations#patch-storage.gcs-bucket)
* [patch-storage.gcs-credentials-file](https://charmhub.io/canonical-livepatch-server-k8s/configurations#patch-storage.gcs-credentials-file)
* [patch-storage.gcs-credentials-json](https://charmhub.io/canonical-livepatch-server-k8s/configurations#patch-storage.gcs-credentials-json)
* [patch-storage.gcs-impersonate-service-account](https://charmhub.io/canonical-livepatch-server-k8s/configurations#patch-storage.gcs-impersonate-service-account)
* [patch-storage.ibm-api-key](https://charmhub.io/canonical-livepatch-server-k8s/configurations#patch-storage.ibm-api-key)
* [patch-storage.ibm-bucket](https://charmhub.io/canonical-livepatch-server-k8s/configurations#patch-storage.ibm-bucket)
* [patch-storage.ibm-endpoint](https://charmhub.io/canonical-livepatch-server-k8s/configurations#patch-storage.ibm-endpoint)
* [patch-storage.ibm-region](https://charmhub.io/canonical-livepatch-server-k8s/configurations#patch-storage.ibm-region)
* [patch-storage.ibm-service-instance-id](https://charmhub.io/canonical-livepatch-server-k8s/configurations#patch-storage.ibm-service-instance-id)
* [patch-storage.ibm-trusted-profile-id](https://charmhub.io/canonical-livepatch-server-k8s/configurations#patch-storage.ibm-trusted-profile-id)
* [patch-storage.oracle-bucket](https://charmhub.io/canonical-livepatch-server-k8s/configurations#patch-storage.oracle-bucket)
* [patch-storage.oracle-config-file](https://charmhub.io/canonical-livepatch-server-k8s/configurations#patch-storage.oracle-config-file)
* [patch-storage.oracle-namespace](https://charmhub.io/canonical-livepatch-server-k8s/configurations#patch-storage.oracle-namespace)
* [patch-storage.oracle-profile](https://charmhub.io/canonical-livepatch-server-k8s/configurations#patch-storage.oracle-profile)
* [patch-storage.oracle-region](https://charmhub.io/canonical-livepatch-server-k8s/configurations#patch-storage.oracle-region)
* [patch-storage.postgres-connection-string](https://charmhub.io/canonical-livepatch-server-k8s/configurations#patch-storage.postgres-connection-string)
* [patch-storage.s3-access-key](https://charmhub.io/canonical-livepatch-server-k8s/configurations#patch-storage.s3-access-key)
* [patch-storage.s3-assume-role-arn](https://charmhub.io/canonical-livepatch-server-k8s/configurations#patch-storage.s3-assume-role-arn)
* [patch-storage.s3-bucket](https://charmhub.io/canonical-livepatch-server-k8s/configurations#patch-storage.s3-bucket)
* [patch-storage.s3-endpoint](https://charmhub.io/canonical-livepatch-server-k8s/configurations#patch-storage.s3-endpoint)
* [patch-storage.s3-region](https://charmhub.io/canonical-livepatch-server-k8s/configurations#patch-storage.s3-region)
* [patch-storage.s3-secret-key](https://charmhub.io/canonical-livepatch-server-k8s/configurations#patch-storage.s3-secret-key)
* [patch-storage.s3-secure](https://charmhub.io/canonical-livepatch-server-k8s/configurations#patch-storage.s3-secure)
* [patch-storage.s3-use-path-style](https://charmhub.io/canonical-livepatch-server-k8s/configurations#patch-storage.s3-use-path-style)
* [patch-storage.swift-api-key](https://charmhub.io/canonical-livepatch-server-k8s/configurations#patch-storage.swift-api-key)
* [patch-storage.swift-auth-url](https://charmhub.io/canonical-livepatch-server-k8s/configurations#patch-storage.swift-auth-url)
* [patch-storage.swift-container](https://charmhub.io/canonical-livepatch-server-k8s/configurations#patch-storage.swift-container)
* [patch-storage.swift-domain](https://charmhub.io/canonical-livepatch-server-k8s/configurations#patch-storage.swift-domain)
* [patch-storage.swift-region](https://charmhub.io/canonical-livepatch-server-k8s/configurations#patch-storage.swift-region)
* [patch-storage.swift-tenant](https://charmhub.io/canonical-livepatch-server-k8s/configurations#patch-storage.swift-tenant)
* [patch-storage.swift-username](https://charmhub.io/canonical-livepatch-server-k8s/configurations#patch-storage.swift-username)
* [patch-storage.type](https://charmhub.io/canonical-livepatch-server-k8s/configurations#patch-storage.type)
* [patch-sync.architectures](https://charmhub.io/canonical-livepatch-server-k8s/configurations#patch-sync.architectures)
* [patch-sync.enabled](https://charmhub.io/canonical-livepatch-server-k8s/configurations#patch-sync.enabled)
* [patch-sync.flavors](https://charmhub.io/canonical-livepatch-server-k8s/configurations#patch-sync.flavors)
* [patch-sync.interval](https://charmhub.io/canonical-livepatch-server-k8s/configurations#patch-sync.interval)
* [patch-sync.machine-count-strategy](https://charmhub.io/canonical-livepatch-server-k8s/configurations#patch-sync.machine-count-strategy)
* [patch-sync.minimum-kernel-version](https://charmhub.io/canonical-livepatch-server-k8s/configurations#patch-sync.minimum-kernel-version)
* [patch-sync.proxy.enabled](https://charmhub.io/canonical-livepatch-server-k8s/configurations#patch-sync.proxy.enabled)
* [patch-sync.proxy.http](https://charmhub.io/canonical-livepatch-server-k8s/configurations#patch-sync.proxy.http)
* [patch-sync.proxy.https](https://charmhub.io/canonical-livepatch-server-k8s/configurations#patch-sync.proxy.https)
* [patch-sync.proxy.no-proxy](https://charmhub.io/canonical-livepatch-server-k8s/configurations#patch-sync.proxy.no-proxy)
* [patch-sync.send-machine-reports](https://charmhub.io/canonical-livepatch-server-k8s/configurations#patch-sync.send-machine-reports)
* [patch-sync.sync-tiers](https://charmhub.io/canonical-livepatch-server-k8s/configurations#patch-sync.sync-tiers)
* [patch-sync.token](https://charmhub.io/canonical-livepatch-server-k8s/configurations#patch-sync.token)
* [patch-sync.upstream-url](https://charmhub.io/canonical-livepatch-server-k8s/configurations#patch-sync.upstream-url)
* [profiler.block\_profile\_rate](https://charmhub.io/canonical-livepatch-server-k8s/configurations#profiler.block_profile_rate)
* [profiler.enabled](https://charmhub.io/canonical-livepatch-server-k8s/configurations#profiler.enabled)
* [profiler.hostname](https://charmhub.io/canonical-livepatch-server-k8s/configurations#profiler.hostname)
* [profiler.mutex\_profile\_fraction](https://charmhub.io/canonical-livepatch-server-k8s/configurations#profiler.mutex_profile_fraction)
* [profiler.profile\_allocations](https://charmhub.io/canonical-livepatch-server-k8s/configurations#profiler.profile_allocations)
* [profiler.profile\_blocks](https://charmhub.io/canonical-livepatch-server-k8s/configurations#profiler.profile_blocks)
* [profiler.profile\_goroutines](https://charmhub.io/canonical-livepatch-server-k8s/configurations#profiler.profile_goroutines)
* [profiler.profile\_inuse](https://charmhub.io/canonical-livepatch-server-k8s/configurations#profiler.profile_inuse)
* [profiler.profile\_mutexes](https://charmhub.io/canonical-livepatch-server-k8s/configurations#profiler.profile_mutexes)
* [profiler.sample\_rate](https://charmhub.io/canonical-livepatch-server-k8s/configurations#profiler.sample_rate)
* [profiler.server\_address](https://charmhub.io/canonical-livepatch-server-k8s/configurations#profiler.server_address)
* [profiler.upload\_rate](https://charmhub.io/canonical-livepatch-server-k8s/configurations#profiler.upload_rate)
* [server.burst-limit](https://charmhub.io/canonical-livepatch-server-k8s/configurations#server.burst-limit)
* [server.concurrency-limit](https://charmhub.io/canonical-livepatch-server-k8s/configurations#server.concurrency-limit)
* [server.is-hosted](https://charmhub.io/canonical-livepatch-server-k8s/configurations#server.is-hosted)
* [server.log-level](https://charmhub.io/canonical-livepatch-server-k8s/configurations#server.log-level)
* [server.redirect-downloads](https://charmhub.io/canonical-livepatch-server-k8s/configurations#server.redirect-downloads)
* [server.url-template](https://charmhub.io/canonical-livepatch-server-k8s/configurations#server.url-template)
* [timescale\_db.connection\_lifetime\_max](https://charmhub.io/canonical-livepatch-server-k8s/configurations#timescale_db.connection_lifetime_max)
* [timescale\_db.connection\_pool\_max](https://charmhub.io/canonical-livepatch-server-k8s/configurations#timescale_db.connection_pool_max)
* [timescale\_db.enabled](https://charmhub.io/canonical-livepatch-server-k8s/configurations#timescale_db.enabled)
* [timescale\_db.flush\_timeout](https://charmhub.io/canonical-livepatch-server-k8s/configurations#timescale_db.flush_timeout)
* [timescale\_db.work\_mem](https://charmhub.io/canonical-livepatch-server-k8s/configurations#timescale_db.work_mem)
* [tracing.enabled](https://charmhub.io/canonical-livepatch-server-k8s/configurations#tracing.enabled)
* [tracing.sample-rate](https://charmhub.io/canonical-livepatch-server-k8s/configurations#tracing.sample-rate)
* [tracing.service-name](https://charmhub.io/canonical-livepatch-server-k8s/configurations#tracing.service-name)

[Learn about configurations >](https://juju.is/docs/juju/configuration#heading--application-configuration)

* auth.basic.enabled | boolean

  Whether basic auth should be used.
* auth.basic.users | string

  A comma separated list of "user:password" pairs used for authentication.
* auth.oauth.allowed-cidp-groups | string

  Comma separated list of CIdP group names allowed to access the admin API when OAuth is enabled.
* auth.oauth.audience | string

  Expected JWT audience claim value for OAuth authentication.
* auth.oauth.enabled | boolean

  Whether OAuth 2.0 bearer token authentication backed by Canonical IdP should be enabled for admin API access.
* auth.oauth.issuer | string

  Expected JWT issuer claim value for OAuth authentication.
* auth.oauth.jwks.refresh-interval | string

  Default: 1h

  Interval for refreshing the JWKS key set.
* auth.oauth.jwks.refresh-unknown-kid | boolean

  Default: True

  Refresh JWKS on-demand when a token contains an unknown key ID (kid).
* auth.oauth.jwks.refresh-unknown-kid-limit | string

  Default: 10m

  Minimum interval between on-demand JWKS refresh attempts for unknown key IDs.
* auth.oauth.jwks.refresh-unknown-kid-max-wait | string

  Default: 1m

  Maximum time to wait for an in-flight on-demand JWKS refresh.
* auth.oauth.jwks.url | string

  URL of the JWKS endpoint used to fetch signing keys for JWT verification.
* auth.oauth.proxy.enabled | boolean

  Whether or not to use proxy for requests to OAuth provider.
* auth.oauth.proxy.http | string

  A comma separated list HTTP proxies to query the OAuth provider.
* auth.oauth.proxy.https | string

  A comma separated list HTTPS proxies to query the OAuth provider.
* auth.oauth.proxy.no-proxy | string

  A comma separated list of domains, IP CIDRs and/or ports to block when querying the OAuth provider.
* auth.oauth.sig-algs | string

  Default: RS256

  Comma separated list of accepted JWT signature algorithms.
  Supported values: RS256, RS384, RS512, ES256, ES384, ES512.
* auth.sso.enabled | boolean

  Note: Currently not available for on-prem users!

  Whether or not OIDCSSO authentication should be enabled.
* auth.sso.public-key | string

  Public key for the auth server
* auth.sso.teams | string

  Note: Currently not available for on-prem users!

  A list of comma separated launchpad teams that are allowed access
  when connecting to the admin tool by SSO authentication.
* auth.sso.url | string

  URL to access for SSO auth.
* cloud\_delay.default\_delay\_hours | int

  [DEPRECATED] Default delay hours for clouds/regions/azs without predefined delay hours. The cloud delay feature is deprecated and is no longer supported.
* cloud\_delay.enabled | boolean

  [DEPRECATED] Whether to enable the delayed roll-out of patches based on a client's cloud. The cloud delay feature is deprecated and is no longer supported.
* contracts.ca | string

  A certificate of the CA that issued the certificate of the contracts service.
  Use 'include-base64://' in a bundle to include a certificate. Otherwise,
  pass a base64-encoded certificate (base64 of "-----BEGIN" to "-----END")
  as a config option in a Juju CLI invocation.
* contracts.enabled | boolean

  Whether use of the contracts service is enabled.
* contracts.password | string

  Password to authenticate with backend contracts service.
* contracts.url | string

  Default: https://contracts.canonical.com

  URL to hit for the contracts service
* contracts.user | string

  Username to authenticate with backend contracts service.
* cve-lookup.auth-required | boolean

  Whether or not requests to retrieve fixed CVEs should be authenticated.
* cve-lookup.enabled | boolean

  Whether or not if this instance of Livepatch Server should lookup fixed CVEs in response to client requests.
* cve-sync.enabled | boolean

  Whether or not if this instance of Livepatch Server should sync fixed CVEs data.
* cve-sync.interval | string

  Default: 1h

  Period between automatic refreshing of fixed CVE data.
* cve-sync.proxy.enabled | boolean

  Whether or not to proxy fixed CVE data syncs.
* cve-sync.proxy.http | string

  A comma separated list HTTP proxies to query fixed CVE data.
* cve-sync.proxy.https | string

  A comma separated list HTTPS proxies to query fixed CVE data.
* cve-sync.proxy.no-proxy | string

  A comma separated list of domains, IP CIDRs and/or ports to block when querying fixed CVE data.
* cve-sync.source-url | string

  Address of Livepatch CVE service to sync fixed CVEs data from.
* cve-sync.timeout | string

  Default: 5m

  Timeout for the CVE sync client. The CVE sync will timeout if the CVE service
  takes longer than the timeout defined, to send the CVE data.
* database.connection-lifetime-max | string

  Default: 10m

  The lifespan of an idle PostgreSQL connection.
* database.connection-pool-max | int

  Default: 10

  The maximum pool of connections to PostgreSQL.
* database.work\_mem | int

  The PostgreSQL work\_mem parameter for connections with the database.
  The value is specified as an integer number of MegaBytes (MB), matching the
  unit semantics of PostgreSQL's work\_mem setting.
  This option is optional: when left unset, the charm does not override
  PostgreSQL's work\_mem, and the server's own default value is used.
* influx.bucket | string

  InfluxDB bucket to write general metrics data to.
* influx.enabled | boolean

  Whether to enable InfluxDB support for time-series metrics reporting.
* influx.organization | string

  InfluxDB organization name.
* influx.ping\_bucket | string

  InfluxDB bucket for ping data (may use a different retention policy).
* influx.token | string

  Authentication token for InfluxDB.
* influx.url | string

  URL of the InfluxDB instance to connect to.
* ingress-interface | string

  Default: legacy-nginx-route

  Select the ingress integration. Defaults to "legacy-nginx-route" for
  backward compatibility. Use "ingress" for new deployments.
* kpi-reports.enabled | string

  Note: Currently not available for on-prem users!

  Key performance index: Metrics. Enables KPI worker - sends metrics to Influx.
* kpi-reports.interval | string

  Default: 5m

  Note: Currently not available for on-prem users!

  Specifies KPI worker frequency.
* lsn-sync.enabled | boolean

  Whether or not if this instance of Livepatch Server should sync LSN data.
* lsn-sync.interval | string

  Default: 1h

  Period between automatic refreshing of LSN data.
* lsn-sync.proxy.enabled | boolean

  Whether or not to proxy LSN data syncs.
* lsn-sync.proxy.http | string

  A comma separated list HTTP proxies to query LSN data.
* lsn-sync.proxy.https | string

  A comma separated list HTTPS proxies to query LSN data.
* lsn-sync.proxy.no-proxy | string

  A comma separated list of domains, IP CIDRs and/or ports to block when querying LSN data.
* lsn-sync.source-url | string

  Address of Livepatch CVE service to sync LSN data from.
* lsn-sync.timeout | string

  Default: 5m

  Timeout for the LSN sync client. The LSN sync will timeout if the CVE service
  takes longer than the timeout defined, to send the LSN data.
* machine-reports.database.cleanup-interval | string

  Default: 6h

  Time between report cleanup runs.
* machine-reports.database.cleanup-row-limit | int

  Default: 1000

  Maximum number of rows to remove in a single report cleanup run.
* machine-reports.database.enabled | boolean

  Whether or not to enabled machine reports writes to PostgreSQL.
* machine-reports.database.retention-days | int

  Default: 10

  Number of days to retain machine reports in the database before cleanup.
* otel-metrics.enabled | boolean

  Whether to enable OpenTelemetry metrics export. This is a manual toggle and is independent of any charm relation.
* otel-metrics.export-interval | string

  Default: 60s

  How often metrics are exported (e.g. "60s", "1m").
* otel-metrics.export-timeout | string

  Default: 30s

  Timeout for each metrics export attempt (e.g. "30s").
* otel-metrics.service-name | string

  Default: livepatch-server

  Service name reported in OTLP metrics.
* patch-blocklist.enabled | boolean

  Whether or not to enable patch blocklist functionality for the admin tool.
* patch-blocklist.refresh-interval | string

  Default: 5m

  How often to check for new blocklist entries.
* patch-cache.cache-size | int

  Default: 128

  The size of the cache in patches.
* patch-cache.cache-ttl | string

  Default: 10m

  How long to persist a patch in cache whilst it has not been actively retrieved.
* patch-cache.enabled | boolean

  Whether or not to cache patches.
* patch-storage.azure-account-key | string

  The Azure Storage account key, used together with patch-storage.azure-account-name for
  shared key authentication.
* patch-storage.azure-account-name | string

  The Azure Storage account name. Required unless patch-storage.azure-connection-string
  is set, which already carries the account name and key.
* patch-storage.azure-client-id | string

  The Entra ID (Azure AD) service principal's client ID.
* patch-storage.azure-client-secret | string

  The Entra ID (Azure AD) service principal's client secret.
* patch-storage.azure-connection-string | string

  An Azure Storage connection string. When set, this is used instead of
  patch-storage.azure-account-name/patch-storage.azure-account-key for authentication.
* patch-storage.azure-container | string

  The Azure Blob Storage container to store patches within.
* patch-storage.azure-managed-identity-client-id | string

  When patch-storage.azure-account-name, patch-storage.azure-connection-string, and the
  service principal fields are all omitted, a managed identity is used instead. Note that
  this workload runs in a pod, not a VM, so a VM-bound managed identity is not available
  unless Entra Workload ID federation has been configured separately for the workload's
  service account; this option then selects the user-assigned identity's client ID to use.
* patch-storage.azure-tenant-id | string

  The Entra ID (Azure AD) tenant ID, used together with patch-storage.azure-client-id and
  patch-storage.azure-client-secret for service principal authentication.
* patch-storage.filesystem-path | string

  Default: /var/lib/livepatch/patches

  The filesystem path to store patches.
* patch-storage.gcs-bucket | string

  The Google Cloud Storage bucket to store patches within.
* patch-storage.gcs-credentials-file | string

  Path to a Google Cloud service account credentials JSON file. When omitted (along with
  patch-storage.gcs-credentials-json), Application Default Credentials are used instead.
  Note that this workload runs in a pod, not a VM, so ambient credentials (e.g. the GCE
  metadata service) are not available unless GKE Workload Identity has been configured
  separately for the workload's service account; otherwise, credentials must be set.
* patch-storage.gcs-credentials-json | string

  Google Cloud service account credentials, as a JSON string. When omitted (along with
  patch-storage.gcs-credentials-file), Application Default Credentials are used instead.
* patch-storage.gcs-impersonate-service-account | string

  An optional service account email to impersonate. When set, the resolved credentials
  are used to impersonate this service account instead of being used directly.
* patch-storage.ibm-api-key | string

  IAM API key. Must be set together with patch-storage.ibm-service-instance-id.
* patch-storage.ibm-bucket | string

  The IBM Cloud Object Storage bucket to store patches within.
* patch-storage.ibm-endpoint | string

  The IBM Cloud Object Storage API endpoint.
* patch-storage.ibm-region | string

  The IBM Cloud region for this Object Storage instance.
* patch-storage.ibm-service-instance-id | string

  IBM Cloud service instance ID, used together with patch-storage.ibm-api-key.
* patch-storage.ibm-trusted-profile-id | string

  When an IAM API key is not configured, the ambient VPC Instance Metadata Service is
  used instead. Note that this workload runs in a pod, not a VM, so this ambient service
  is not available unless a Trusted Profile bound to the underlying compute resource
  has been configured separately; this option then selects which profile to assume.
* patch-storage.oracle-bucket | string

  The Oracle Cloud Infrastructure Object Storage bucket to store patches within.
* patch-storage.oracle-config-file | string

  Path to an OCI config file for authentication. When omitted (along with
  patch-storage.oracle-profile), instance principal authentication is used instead,
  bound to the OCI compute instance the server runs on.
* patch-storage.oracle-namespace | string

  The Oracle Cloud Infrastructure Object Storage namespace.
* patch-storage.oracle-profile | string

  The profile name to use from the OCI config file.
* patch-storage.oracle-region | string

  The Oracle Cloud Infrastructure region for this Object Storage instance.
* patch-storage.postgres-connection-string | string

  A connection string URI to a PostgreSQL database for patch storage.

  When set to an empty string, it is handled by relation and uses the same
  database cluster that livepatch server uses for state. The database name is 'livepatch'.

  If this is to be changed, it is expected that the database you wish to connect to is
  created manually.
* patch-storage.s3-access-key | string

  AWS programmatic API access key. Must be set together with patch-storage.s3-secret-key.
  When both are omitted, the AWS SDK's default credential chain is used instead. Note that
  this workload runs in a pod, not a VM, so ambient credentials (e.g. an EC2 instance role)
  are not available unless IAM Roles for Service Accounts (IRSA) has been configured
  separately for the workload's service account; otherwise, these keys must be set.
* patch-storage.s3-assume-role-arn | string

  An optional IAM role ARN to assume via STS. When set, the resolved AWS credentials
  are used to assume this role via STS instead of being used directly.
* patch-storage.s3-bucket | string

  The S3 bucket to store patches within.
* patch-storage.s3-endpoint | string

  The S3 API presigned endpoint.
* patch-storage.s3-region | string

  The AWS region for this S3 storage.
* patch-storage.s3-secret-key | string

  AWS programmatic API secret key, used together with patch-storage.s3-access-key.
* patch-storage.s3-secure | boolean

  Whether or not to perform TLS.
* patch-storage.s3-use-path-style | boolean

  Whether to use path-style S3 URLs (https://s3.amazonaws.com/BUCKET/KEY) instead of
  virtual-hosted-style URLs (https://BUCKET.s3.amazonaws.com/KEY). Required for some
  S3-compatible services (e.g. MinIO), and not needed for AWS S3.
* patch-storage.swift-api-key | string

  An authorisation API key for swift.
* patch-storage.swift-auth-url | string

  The authorisation URL for swift.
* patch-storage.swift-container | string

  The swift blob storage location for storing patches.
* patch-storage.swift-domain | string

  The domain the containers reside under in swift for storing patches.
* patch-storage.swift-region | string

  The region assigned to this domain and tenant.
* patch-storage.swift-tenant | string

  The tenant account name for your container and API service user to connect under.
* patch-storage.swift-username | string

  The Swift username to login against when using API key authorisation.
* patch-storage.type | string

  Default: filesystem

  The storage backend type for patches. Available options are:

  + filesystem
  + swift
  + postgres
  + s3
  + gcs
  + azure
  + ibm
  + oracle

  When using "postgres" for storage, the charm uses the database relation
  automatically with the default database name "livepatch". A custom
  database may be specified via patch-storage.postgres-connection-string
  but must be created manually.

  When using "filesystem", patches are stored at the path configured in
  patch-storage.filesystem-path.
* patch-sync.architectures | string

  Comma-separated list of architectures to download patches for. When no value is present, all are synced. If this field is empty, the patch sync will gather all architectures.
* patch-sync.enabled | boolean

  Whether or not if this instance of Livepatch Server should sync patches from another instance.

  A sync is effectively a "shared" storage, having access to the same pool of patches as the upstream
  services patch storage.
* patch-sync.flavors | string

  Default: generic,lowlatency,aws

  A comma separated list of kernel flavors to download patches for. If this field is empty, the patch sync will gather all flavors.
* patch-sync.interval | string

  Default: 1h

  Period between automatic patch snapshot downloads.
* patch-sync.machine-count-strategy | string

  Default: bucket

  The strategy to use when counting machines in a set.
* patch-sync.minimum-kernel-version | string

  A minimum kernel version of format "0.0.0" denoting the lowest kernel version to download patches for. When no value is present, all are synced. For example, "5.4.0" will sync "5.4.0" and up.
* patch-sync.proxy.enabled | boolean

  Whether or not to proxy patch syncs.
* patch-sync.proxy.http | string

  A comma separated list HTTP proxies to query for patches.
* patch-sync.proxy.https | string

  A comma separated list HTTPS proxies to query for patches.
* patch-sync.proxy.no-proxy | string

  A comma separated list of domains, IP CIDRs and/or ports to block.
* patch-sync.send-machine-reports | boolean

  Enable sending reports from local machines during patch synchronisation.
* patch-sync.sync-tiers | boolean

  Mirror patch tier information from the upstream server. WARNING: Enabling this feature will modify existing tier information in order to match the upstream server's tier structure. Avoid this if you already have tiers setup.
* patch-sync.token | string

  Token generated from the admin-tool to authenticate machine to machine.
* patch-sync.upstream-url | string

  Default: https://livepatch.canonical.com

  Livepatch server to download patch snapshots from.
* profiler.block\_profile\_rate | int

  Default: 50000

  this is the sampling average of one blocking event per `BlockProfileRate` nanoseconds spent blocked. For example, set rate to 1000000000 (aka int(time.Second.Nanoseconds())) to record one sample per second a goroutine is blocked. It is recommended to set this to values greater than 10,000. For more info, visit this: https://github.com/DataDog/go-profiler-notes/blob/main/block.md#benchmarks
* profiler.enabled | boolean

  Whether to enable or disable continuous profiling on the server or not.
* profiler.hostname | string

  the hostname of the server the profiler is running on. This is used as a tag to group metrics by the server it is running on.
* profiler.mutex\_profile\_fraction | int

  Default: 5

  this turns on mutex profiles with rate indicating the fraction of mutex contention events reported in the mutex profile. On average, 1/rate events are reported. Setting an aggressive rate can hurt performance. ProfileMutexes must be True
* profiler.profile\_allocations | boolean

  this will profile the memory for allocated space as well as allocated objects
* profiler.profile\_blocks | boolean

  would profile blocking events (channels, select, etc) with the BlockProfileRate frequency.
* profiler.profile\_goroutines | boolean

  would profile separate concurrent running gorountines.
* profiler.profile\_inuse | boolean

  this will profile the overall used memory as well as the memory used by objects
* profiler.profile\_mutexes | boolean

  this turns on profiling for mutexes
* profiler.sample\_rate | int

  Default: 100

  sample rate for the profiler in Hz. 100 means reading 100 times per second.
* profiler.server\_address | string

  The pyroscope server address to send the metrics to.
* profiler.upload\_rate | int

  The frequency of upload to the profiling server
* server.burst-limit | int

  Default: 500

  The maximum number of concurrently incoming requests.

  After this limit, requests are queued according to the following:
  concurrency-limit - burst\_limit

  For defaults, this is:
  1000 - 500 = 500 (Maximum queue).

  Once the queue is reached, subsequent requests are rejected.
* server.concurrency-limit | int

  Default: 1000

  Maximum number of API requests being served concurrently.
* server.is-hosted | boolean

  Defines whether the server will act as an on-prem server
  (i.e. fetching patches from the hosted server), or will act as a
  hosted server.
* server.log-level | string

  Default: info

  The server's log level (e.g., debug, info, warning, error).
* server.redirect-downloads | boolean

  When true, the server will redirect downloads directed at its /v1/patches/{filename}
  endpoint to the endpoint defined in the server.url-template config option. This is
  useful if you want patch downloads to be redirected to a fileserver fronting patches.
  Note: Do not enable this option if the server.url-template is configured as the
  Livepatch-server as this will result in a redirect loop.
* server.url-template | string

  Template string to use when making URLs for giving back to the client.

  e.g. https://livepatch-hosting.com/v1/patches/{filename}

  This will need to be configured once the url or ip address of the service
  is known.
* timescale\_db.connection\_lifetime\_max | string

  Default: 10m

  The lifespan of an idle TimescaleDB connection.
* timescale\_db.connection\_pool\_max | int

  Default: 10

  The maximum pool of connections to TimescaleDB.
* timescale\_db.enabled | boolean

  Whether or not to enable TimescaleDB for time series data storage.
* timescale\_db.flush\_timeout | string

  Default: 1m

  The maximum time to wait for a flush to complete when flushing time series data to TimescaleDB.
* timescale\_db.work\_mem | int

  Default: 16

  The PostgreSQL work\_mem parameter (in MB) for connections with TimescaleDB.
* tracing.enabled | boolean

  Whether to enable OpenTelemetry tracing. This is a manual toggle and is independent of any charm relation.
* tracing.sample-rate | float

  Default: 1.0

  Fraction of traces to sample (0.0 to 1.0).
* tracing.service-name | string

  Default: livepatch-server

  Service name reported in traces.
