---
title: Charmhub | Deploy OAuth2 Proxy using Charmhub - The Open Operator Collection
description: Deploy the latest version of OAuth2 Proxy as a Kubernetes Operator on
  any cloud.
url: https://charmhub.io/oauth2-proxy-k8s/configurations
---

# OAuth2 Proxy

[Identity Charmers](https://charmhub.io/publisher/identity-charmers "View all packages from Identity Charmers")

* [Identity Charmers](https://charmhub.io/publisher/identity-charmers "View all packages from Identity Charmers")

Platform:

stable 26

```
juju deploy oauth2-proxy-k8s
```

[Learn to deploy on juju >](https://juju.is/docs/juju/manage-applications)

* [cpu](https://charmhub.io/oauth2-proxy-k8s/configurations#cpu)
* [dev](https://charmhub.io/oauth2-proxy-k8s/configurations#dev)
* [enable\_jwt\_bearer\_tokens](https://charmhub.io/oauth2-proxy-k8s/configurations#enable_jwt_bearer_tokens)
* [memory](https://charmhub.io/oauth2-proxy-k8s/configurations#memory)
* [set\_authorization\_header](https://charmhub.io/oauth2-proxy-k8s/configurations#set_authorization_header)

[Learn about configurations >](https://juju.is/docs/juju/configuration#heading--application-configuration)

* cpu | string

  K8s cpu resource limit, e.g. "1" or "500m". Default is unset (no limit). This value is used
  for the "limits" portion of the resource requirements (the "requests" portion is
  automatically deduced from it).
  See https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/
* dev | boolean

  Run OAuth2 Proxy in dev mode. If enabled, it will skip validation of certificates presented when using HTTPS providers.
  This should only be used for development purposes.
* enable\_jwt\_bearer\_tokens | boolean

  If set to `True`, OAuth2 Proxy will allow requests that have verified JWT bearer tokens.
* memory | string

  K8s memory resource limit, e.g. "1Gi". Default is unset (no limit). This value is used
  for the "limits" portion of the resource requirements (the "requests" portion is
  automatically deduced from it).
  See https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/
* set\_authorization\_header | boolean

  If set to `True`, OAuth2 Proxy will inject the id\_token as `Authorization: Bearer <jwt>`
  in the ext\_authz allow response. This enables downstream components (e.g. Istio's
  RequestAuthentication) to validate JWT claims from the Authorization header.
