---
title: Charmhub | Deploy Mattermost using Charmhub - The Open Operator Collection
description: Deploy the latest version of Mattermost as a Kubernetes Operator on any
  cloud.
url: https://charmhub.io/mattermost-k8s/configurations
---

# Mattermost

[Canonical IS DevOps](https://charmhub.io/publisher/canonical-is-devops "View all packages from Canonical IS DevOps")

* [Canonical IS DevOps](https://charmhub.io/publisher/canonical-is-devops "View all packages from Canonical IS DevOps")

Platform:

stable 18

```
juju deploy mattermost-k8s
```

[Learn to deploy on juju >](https://juju.is/docs/juju/manage-applications)

* [clustering](https://charmhub.io/mattermost-k8s/configurations#clustering)
* [debug](https://charmhub.io/mattermost-k8s/configurations#debug)
* [image\_proxy\_enabled](https://charmhub.io/mattermost-k8s/configurations#image_proxy_enabled)
* [ingress\_whitelist\_source\_range](https://charmhub.io/mattermost-k8s/configurations#ingress_whitelist_source_range)
* [licence](https://charmhub.io/mattermost-k8s/configurations#licence)
* [max\_file\_size](https://charmhub.io/mattermost-k8s/configurations#max_file_size)
* [outbound\_proxy](https://charmhub.io/mattermost-k8s/configurations#outbound_proxy)
* [outbound\_proxy\_exceptions](https://charmhub.io/mattermost-k8s/configurations#outbound_proxy_exceptions)
* [performance\_monitoring\_enabled](https://charmhub.io/mattermost-k8s/configurations#performance_monitoring_enabled)
* [primary\_team](https://charmhub.io/mattermost-k8s/configurations#primary_team)
* [push\_notification\_server](https://charmhub.io/mattermost-k8s/configurations#push_notification_server)
* [push\_notifications\_include\_message\_snippet](https://charmhub.io/mattermost-k8s/configurations#push_notifications_include_message_snippet)
* [s3\_access\_key\_id](https://charmhub.io/mattermost-k8s/configurations#s3_access_key_id)
* [s3\_bucket](https://charmhub.io/mattermost-k8s/configurations#s3_bucket)
* [s3\_enabled](https://charmhub.io/mattermost-k8s/configurations#s3_enabled)
* [s3\_endpoint](https://charmhub.io/mattermost-k8s/configurations#s3_endpoint)
* [s3\_region](https://charmhub.io/mattermost-k8s/configurations#s3_region)
* [s3\_secret\_access\_key](https://charmhub.io/mattermost-k8s/configurations#s3_secret_access_key)
* [s3\_server\_side\_encryption](https://charmhub.io/mattermost-k8s/configurations#s3_server_side_encryption)
* [site\_url](https://charmhub.io/mattermost-k8s/configurations#site_url)
* [smtp\_host](https://charmhub.io/mattermost-k8s/configurations#smtp_host)
* [sso](https://charmhub.io/mattermost-k8s/configurations#sso)
* [tls\_secret\_name](https://charmhub.io/mattermost-k8s/configurations#tls_secret_name)
* [use\_enterprise\_defaults](https://charmhub.io/mattermost-k8s/configurations#use_enterprise_defaults)
* [use\_experimental\_saml\_library](https://charmhub.io/mattermost-k8s/configurations#use_experimental_saml_library)

[Learn about configurations >](https://juju.is/docs/juju/configuration#heading--application-configuration)

* clustering | boolean

  Enable clustering.

  This feature requires a Mattermost Enterprise Edition licence.
* debug | boolean

  Set the Mattermost log level to DEBUG, otherwise INFO.
* image\_proxy\_enabled | boolean

  The image proxy is used by the Mattermost apps to prevent them from connecting directly to remote servers.

  This anonymizes their connections and prevents them from accessing insecure content.

  Currently only the "local" image proxy type is supported.
* ingress\_whitelist\_source\_range | string

  A comma-separated list of CIDRs to store in the ingress.kubernetes.io/whitelist-source-range annotation.

  This can be used to lock down access to Mattermost based on source IP address.
* licence | string

  The contents of the licence file as supplied by Mattermost.

  Some features are not available without a licence. For more
  information, consult the Mattermost documentation.
* max\_file\_size | int

  Default: 5

  The maximum file size, in megabytes.

  If there is a reverse proxy in front of Mattermost, it may
  need to be configured to handle the requested size.

  For more information, see the Mattermost documentation.
* outbound\_proxy | string

  The proxy to use for outbound requests.
* outbound\_proxy\_exceptions | string

  A list of destinations for which the outbound proxy will not
  be used.

  This can be configured as a set of comma-separated IP
  addresses (e.g. "1.2.3.4"), IP address ranges specified in
  CIDR notation (e.g. "1.2.3.4/8"), or domain names. An IP
  address or domain name can also include a port number.

  When a domain name is specified, the domain and all of its
  subdomains are matched. However, a domain name with a
  leading "." only matches the subdomains. For example,
  "example.com" matches both "example.com" and "sub.example.com"
  while ".example.com" only matches the latter.
* performance\_monitoring\_enabled | boolean

  When set, Prometheus metrics are exposed via HTTP on port 8067 at the path "/metrics".

  For more information, see https://docs.mattermost.com/deployment/metrics.html

  This feature requires a Mattermost Enterprise Edition licence.
* primary\_team | string

  The primary team of which users on the server are members.

  When a primary team is set, the options to join other teams or leave the primary team are disabled.

  If the team URL of the primary team is "https://example.mattermost.com/myteam/", then set the value to "myteam".
* push\_notification\_server | string

  The push notification server to use.

  Use of Mattermost's Hosted Push Notification Service requires an Enterprise Edition licence.
* push\_notifications\_include\_message\_snippet | boolean

  If enabled, push notification payloads include the sender, the
  channel, and a snippet of the message itself, which may
  include confidential information.

  If disabled, push notification payloads include the sender,
  the channel, and an ID to let the client retrieve the message
  directly from Mattermost.
* s3\_access\_key\_id | string

  The S3 access key ID to use.
* s3\_bucket | string

  The S3 bucket to use.
* s3\_enabled | boolean

  Store files and attachments in an S3-compatible object storage service instead of a local directory.
* s3\_endpoint | string

  Default: s3.amazonaws.com

  The S3 endpoint to use. This may be a non-Amazon S3-compatible endpoint.

  For more information, see the Mattermost documentation.
* s3\_region | string

  The S3 region to use.
* s3\_secret\_access\_key | string

  The S3 secret key to use.
* s3\_server\_side\_encryption | boolean

  Whether to use S3 Server-Side Encryption.

  This requires configuration on the S3 side, as well as a suitable Mattermost licence.
* site\_url | string

  The URL by which the site is reached. This must be set for all of Mattermost's features to work correctly.

  For more information, see https://docs.mattermost.com/administration/config-settings.html#site-url
* smtp\_host | string

  The hostname or IP address of the outgoing SMTP relay host.
* sso | boolean

  Whether to use Ubuntu SSO to log in.

  This will not work unless the administrators of login.ubuntu.com have created a suitable SAML config first.

  This feature requires a Mattermost Enterprise Edition licence.
* tls\_secret\_name | string

  The name of the Kubernetes secret to be associated with the ingress resource.

  This setting is ignored unless site\_url begins with "https".
* use\_enterprise\_defaults | boolean

  If set, apply miscellaneous Mattermost settings as used in an Enterprise deployment.
* use\_experimental\_saml\_library | boolean

  Default: True

  If set, use the built-in Mattermost SAML library. Otherwise, use xmlsec1 to verify logins.
