---
title: Charmhub | Deploy Iam using Charmhub - The Open Operator Collection
description: Deploy the latest version of Iam as a Kubernetes Operator on any cloud.
url: https://charmhub.io/iam/configurations/hydra
---

##### We've discontinued the registration of new Bundles

New Bundle registrations are no longer accepted. Existing bundles remain functional. We recommend using the Juju Terraform Provider for new deployments.

[Learn more](https://discourse.charmhub.io/t/discontinuing-new-charmhub-bundle-registrations/15344)

# Iam

[Identity Charmers](https://charmhub.io/publisher/identity-charmers "View all packages from Identity Charmers")
| bundle

* [Identity Charmers](https://charmhub.io/publisher/identity-charmers "View all packages from Identity Charmers")
  | bundle

Platform:

edge 8

```
juju deploy iam --channel edge
```

[Learn to deploy on juju >](https://juju.is/docs/juju/manage-applications)

* [Hydra](https://charmhub.io/iam/configurations/hydra)
* [Identity Platform Login Ui Operator](https://charmhub.io/iam/configurations/identity-platform-login-ui-operator)
* [Kratos](https://charmhub.io/iam/configurations/kratos)
* [Kratos External Idp Integrator](https://charmhub.io/iam/configurations/kratos-external-idp-integrator)
* [Postgresql K8S](https://charmhub.io/iam/configurations/postgresql-k8s)
* [Tls Certificates Operator](https://charmhub.io/iam/configurations/tls-certificates-operator)
* [Traefik K8S](https://charmhub.io/iam/configurations/traefik-k8s)
* [Traefik K8S](https://charmhub.io/iam/configurations/traefik-k8s)

[Learn about configurations >](https://juju.is/docs/juju/configuration#heading--application-configuration)

* cpu | string

  K8s cpu resource limit, e.g. "1" or "500m". Default is unset (no limit). This value is used
  for the "limits" portion of the resource requirements (the "requests" portion is
  automatically deduced from it).
  See https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/
* dev | boolean

  Run Hydra in dev mode, it is needed if HTTPS is not set up. This should only be used for development purposes.
* initial\_cookie\_secret\_id | secret

  Juju secret id containing the cookie secret key used to encrypt the hydra cookies.
  This config is only used when the application is deployed the first time. On an existing deployment, you
  need to use the `add-secret-key` action.
  All the values from the secret will be used as keys sorted, with the last one being used for both
  encryption and decryption. E.g:
  {
  "1": <secret-1>,
  "2": <secret-2>,
  "3": <secret-3>,
  }
  The length of the secrets must be >16 characters
* initial\_system\_secret\_id | secret

  Juju secret id containing the system secret key used to encrypt database entries.
  This config is only used when the application is deployed the first time. On an existing deployment, you
  need to use the `add-secret-key` action.
  All the values from the secret will be used as keys sorted, with the last one being used for both
  encryption and decryption. E.g:
  {
  "1": <secret-1>,
  "2": <secret-2>,
  "3": <secret-3>,
  }
  The length of the secrets must be >16 characters
* jwt\_access\_tokens | boolean

  Default: True

  Issue JWT access tokens, defaults to True. If set to False, access tokens will be opaque.
* log\_level | string

  Default: info

  The verbosity of logs produced by Hydra.
  Available values are: panic, fatal, error, warn, info, debug, and trace.
* memory | string

  K8s memory resource limit, e.g. "1Gi". Default is unset (no limit). This value is used
  for the "limits" portion of the resource requirements (the "requests" portion is
  automatically deduced from it).
  See https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/
