---
title: Charmhub | Deploy Iam using Charmhub - The Open Operator Collection
description: Deploy the latest version of Iam as a Kubernetes Operator on any cloud.
url: https://charmhub.io/iam/configurations/kratos-external-idp-integrator
---

##### We've discontinued the registration of new Bundles

New Bundle registrations are no longer accepted. Existing bundles remain functional. We recommend using the Juju Terraform Provider for new deployments.

[Learn more](https://discourse.charmhub.io/t/discontinuing-new-charmhub-bundle-registrations/15344)

# Iam

[Identity Charmers](https://charmhub.io/publisher/identity-charmers "View all packages from Identity Charmers")
| bundle

* [Identity Charmers](https://charmhub.io/publisher/identity-charmers "View all packages from Identity Charmers")
  | bundle

Platform:

edge 8

```
juju deploy iam --channel edge
```

[Learn to deploy on juju >](https://juju.is/docs/juju/manage-applications)

* [Hydra](https://charmhub.io/iam/configurations/hydra)
* [Identity Platform Login Ui Operator](https://charmhub.io/iam/configurations/identity-platform-login-ui-operator)
* [Kratos](https://charmhub.io/iam/configurations/kratos)
* [Kratos External Idp Integrator](https://charmhub.io/iam/configurations/kratos-external-idp-integrator)
* [Postgresql K8S](https://charmhub.io/iam/configurations/postgresql-k8s)
* [Tls Certificates Operator](https://charmhub.io/iam/configurations/tls-certificates-operator)
* [Traefik K8S](https://charmhub.io/iam/configurations/traefik-k8s)
* [Traefik K8S](https://charmhub.io/iam/configurations/traefik-k8s)

[Learn about configurations >](https://juju.is/docs/juju/configuration#heading--application-configuration)

* apple\_private\_key | string

  The private key downloaded from Apple. To be used only with Apple providers.
* apple\_private\_key\_id | string

  The private key identifier generated by Apple. To be used only with Apple providers.
* apple\_team\_id | string

  The Team ID provided by Apple. To be used only with Apple providers.
* client\_id | string

  The registered client\_id
* client\_secret | string

  The registered client\_secret
* enabled | boolean

  Default: True

  Controls whether the provider is enabled.
* issuer\_url | string

  The issuer\_url, this value is only used when provider is "generic" or "auth0"
* jsonnet\_mapper | string

  The jsonnet mapper that will be used for mapping the external idp claims to kratos attributes.
  For example:
  local claims = {
  email\_verified: false,
  } + std.extVar('claims');
  {
  identity: {
  traits: {
  [if 'email' in claims && claims.email\_verified then 'email' else null]: claims.email,
  [if 'name' in claims then 'name' else null]: claims.name,
  [if 'given\_name' in claims then 'given\_name' else null]: claims.given\_name,
  [if 'family\_name' in claims then 'family\_name' else null]: claims.family\_name,
  },
  },
  }
  For more info see https://www.ory.sh/docs/kratos/reference/jsonnet.
* label | string

  The text that will be shown to the user when asked to choose a provider, defaults to the provider type
* microsoft\_tenant\_id | string

  The Microsoft tenant\_id. To be used only with Microsoft providers.
* provider | string

  Default: generic

  The provider name, must be one of the following:
  ["generic", "google", "facebook", "microsoft", "github",
  "apple", "gitlab", "auth0", "slack", "spotify", "discord",
  "twitch", "netid", "yandex", "vk", "dingtalk"].
  Defaults to "generic"
* provider\_id | string

  The provider's ID to be used in Kratos. The redirect\_uri is generated based on this.
  You must not have 2 providers with the same ID registered in Kratos.
* scope | string

  Space separated list of allowed scopes for the provider.
* secret\_backend | string

  Default: relation

  The backend to use for passing sensitive information to Kratos.
