---
title: Charmhub | Deploy Kratos using Charmhub - The Open Operator Collection
description: Deploy the latest version of Kratos as a Kubernetes Operator on any cloud.
url: https://charmhub.io/kratos/configurations
---

# Kratos

[Identity Charmers](https://charmhub.io/publisher/identity-charmers "View all packages from Identity Charmers")

* [Identity Charmers](https://charmhub.io/publisher/identity-charmers "View all packages from Identity Charmers")

Platform:

stable 565

```
juju deploy kratos
```

[Learn to deploy on juju >](https://juju.is/docs/juju/manage-applications)

* [cpu](https://charmhub.io/kratos/configurations#cpu)
* [default\_identity\_schema\_id](https://charmhub.io/kratos/configurations#default_identity_schema_id)
* [dev](https://charmhub.io/kratos/configurations#dev)
* [enable\_local\_idp](https://charmhub.io/kratos/configurations#enable_local_idp)
* [enable\_oidc\_webauthn\_sequencing](https://charmhub.io/kratos/configurations#enable_oidc_webauthn_sequencing)
* [enable\_passwordless\_login\_method](https://charmhub.io/kratos/configurations#enable_passwordless_login_method)
* [enforce\_mfa](https://charmhub.io/kratos/configurations#enforce_mfa)
* [http\_proxy](https://charmhub.io/kratos/configurations#http_proxy)
* [https\_proxy](https://charmhub.io/kratos/configurations#https_proxy)
* [identity\_schemas](https://charmhub.io/kratos/configurations#identity_schemas)
* [log\_level](https://charmhub.io/kratos/configurations#log_level)
* [memory](https://charmhub.io/kratos/configurations#memory)
* [no\_proxy](https://charmhub.io/kratos/configurations#no_proxy)
* [recovery\_email\_template](https://charmhub.io/kratos/configurations#recovery_email_template)

[Learn about configurations >](https://juju.is/docs/juju/configuration#heading--application-configuration)

* cpu | string

  K8s cpu resource limit, e.g. "1" or "500m". Default is unset (no limit). This value is used
  for the "limits" portion of the resource requirements (the "requests" portion is
  automatically deduced from it).
  See https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/
* default\_identity\_schema\_id | string

  The default identity schema id, this option only works when `identity_schemas` is defined
* dev | boolean

  Run Kratos on dev mode, it is needed if HTTPS is not set up. This should only be used for development purposes.
* enable\_local\_idp | boolean

  Default: True

  Enable Kratos Identity Provider
* enable\_oidc\_webauthn\_sequencing | boolean

  Enforce setting up a WebAuthn key (e.g. with YubiKey or Google Password Manager on Android)
  after signing in with an external identity provider. Requires `enable_passwordless_login_method=False`.
  WARNING: Do not enable this option unless you are sure that this feature applies to your deployment.
* enable\_passwordless\_login\_method | boolean

  Enable passwordless authentication via webauthn. Requires `enable_local_idp=True`.
* enforce\_mfa | boolean

  Default: True

  Enforce users to set up and use multi factor authentication.
  Disabling this option will allow users to log in with password or webauthn without completing 2fa.
* http\_proxy | string

  URL of the HTTP proxy eg http://proxy.internal:6666, it will set the HTTP\_PROXY var in the workload environment
* https\_proxy | string

  URL of the HTTPS proxy eg http://proxy.internal:6666, it will set the HTTPS\_PROXY var in the workload environment
* identity\_schemas | string

  A mapping of schema\_id to identity schemas. For example:
  {
  "user\_v0": {
  "$id": "https://schemas.ory.sh/presets/kratos/quickstart/email-password/identity.schema.json",
  "$schema": "http://json-schema.org/draft-07/schema#",
  "title": "Person",
  "type": "object",
  "properties": {
  "traits": {
  "type": "object",
  "properties": {
  "email": {
  "type": "string",
  "format": "email",
  "title": "E-Mail",
  "minLength": 3,
  "ory.sh/kratos": {
  "verification": {
  "via": "email"
  }
  }
  },
  "name": {
  "type": "string"
  }
  }
  },
  "additionalProperties": true
  }
  }
  }
* log\_level | string

  Default: info

  The verbosity of logs produced by Kratos.
  Available values are: panic, fatal, error, warn, info, debug, and trace.
* memory | string

  K8s memory resource limit, e.g. "1Gi". Default is unset (no limit). This value is used
  for the "limits" portion of the resource requirements (the "requests" portion is
  automatically deduced from it).
  See https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/
* no\_proxy | string

  Domains that need to be excluded from proxying no\_proxy="test.com,test.co.uk", it is a comma separate list
* recovery\_email\_template | string

  The custom html template used to send emails with recovery codes. For example:

  Hi,
  Please enter the following code to recover your account:
  {{ .RecoveryCode }}
