---
title: Charmhub | Deploy Jaime K8S using Charmhub - The Open Operator Collection
description: Deploy the latest version of Jaime K8S on any cloud.
url: https://charmhub.io/jaime-k8s/configurations
---

# Jaime K8S

[Gaetan Gouzi](https://charmhub.io/publisher/ggouzi "View all packages from Gaetan Gouzi")

* [Gaetan Gouzi](https://charmhub.io/publisher/ggouzi "View all packages from Gaetan Gouzi")

Platform:

26.04

24.04

22.04

edge 19

```
juju deploy jaime-k8s --channel edge
```

[Learn to deploy on juju >](https://juju.is/docs/juju/manage-applications)

* [api-token](https://charmhub.io/jaime-k8s/configurations#api-token)
* [audit-log-path](https://charmhub.io/jaime-k8s/configurations#audit-log-path)
* [cooldown-minutes](https://charmhub.io/jaime-k8s/configurations#cooldown-minutes)
* [diagnostics](https://charmhub.io/jaime-k8s/configurations#diagnostics)
* [failure-timeout-minutes](https://charmhub.io/jaime-k8s/configurations#failure-timeout-minutes)
* [juju-api-password](https://charmhub.io/jaime-k8s/configurations#juju-api-password)
* [juju-api-user](https://charmhub.io/jaime-k8s/configurations#juju-api-user)
* [log-window-minutes](https://charmhub.io/jaime-k8s/configurations#log-window-minutes)
* [max-context-lines](https://charmhub.io/jaime-k8s/configurations#max-context-lines)
* [mode](https://charmhub.io/jaime-k8s/configurations#mode)
* [model](https://charmhub.io/jaime-k8s/configurations#model)
* [provider](https://charmhub.io/jaime-k8s/configurations#provider)
* [report-dir](https://charmhub.io/jaime-k8s/configurations#report-dir)
* [watch-applications](https://charmhub.io/jaime-k8s/configurations#watch-applications)
* [watch-statuses](https://charmhub.io/jaime-k8s/configurations#watch-statuses)

[Learn about configurations >](https://juju.is/docs/juju/configuration#heading--application-configuration)

* api-token | string

  API token for the configured AI provider. Accepts either a Juju secret URI (`secret:<id>`, recommended) or a plain token string (for development only). When a secret URI is provided, Jaime reads the `token` field from the secret content. The token is never logged. To use a secret: run `juju add-secret jaime-token token=<value>`, grant it to the application, then set this field to the returned secret URI.
* audit-log-path | string

  Default: /var/log/jaime/events.jsonl

  Path to the structured JSONL audit log.
* cooldown-minutes | int

  Default: 30

  Minimum time before generating another report for the same unresolved incident.
* diagnostics | string

  JSON diagnostics plan keyed by application name. Each application's value may set 'containers', 'log\_patterns', 'env\_variables' and 'ports' to check the pod against what the Kubernetes API can observe without exec. Empty means no plan and the fixed pod collection is used. An invalid plan blocks the unit. See the k8s schema in jaime-package/jaime/diagnostics.py.
* failure-timeout-minutes | int

  Default: 5

  How long a watched status must persist before a report is generated.
* juju-api-password | string

  Password for the juju-api-user. Accepts either a Juju secret URI (`secret:<id>`, recommended) or a plain string (development only). When a secret URI is provided, Jaime reads the `password` field from the secret content.
* juju-api-user | string

  Name of a Juju user with 'read' permission on this model, used to fetch workload statuses from the controller API. A unit's own agent identity does not have this permission. Create with:
  juju add-user jaime-observer
  juju grant jaime-observer read <model-name>
* log-window-minutes | int

  Default: 30

  How far back Jaime should collect recent logs (minutes).
* max-context-lines | int

  Default: 500

  Per-item cap on collected lines. Some sections apply a tighter cap (for example socket statistics and firewall rules). This is not a report or prompt total.
* mode | string

  Default: observe

  Operating mode. 'observe': collect context and generate reports only. 'suggest': like observe, plus calls the AI provider to append diagnosis
  and safe manual remediation suggestions to the report. Nothing is executed.
  'act': NOT YET IMPLEMENTED. Setting mode to 'act' puts the charm in
  blocked state until command allowlisting is implemented.
* model | string

  AI model to use with the selected provider (optional). Any model the provider supports is accepted. When empty, a provider default is used: 'gemini-2.5-flash' for gemini and '~deepseek/deepseek-v4-flash-latest' for openrouter. Ignored when provider is 'none'.
* provider | string

  Default: none

  AI provider to use for optional report generation. Allowed values: 'none' (no provider; the charm always produces a non-AI report), 'gemini', or 'openrouter'.
* report-dir | string

  Default: /var/log/jaime/reports

  Directory where Markdown report artifacts are written.
* watch-applications | string

  Comma-separated list of application names to monitor (e.g. "postgresql-k8s,mysql-k8s"). Monitoring is opt-in: empty or unset means no applications are monitored. You must explicitly list each application you want Jaime to watch.
* watch-statuses | string

  Default: error,blocked

  Comma-separated unit workload statuses that should open an incident.
