---
title: Charmhub | Deploy Tigera Secure EE using Charmhub - The Open Operator Collection
description: Deploy the latest version of Tigera Secure EE on any cloud.
url: https://charmhub.io/tigera-secure-ee/configurations
---

# Tigera Secure EE

[Canonical Kubernetes](https://charmhub.io/publisher/containers "View all packages from Canonical Kubernetes")

* [Canonical Kubernetes](https://charmhub.io/publisher/containers "View all packages from Canonical Kubernetes")

Platform:

22.04

20.04

18.04

16.04

stable 1b90254

```
juju deploy tigera-secure-ee
```

[Learn to deploy on juju >](https://juju.is/docs/juju/manage-applications)

* [calico-node-image](https://charmhub.io/tigera-secure-ee/configurations#calico-node-image)
* [calicoctl-image](https://charmhub.io/tigera-secure-ee/configurations#calicoctl-image)
* [enable-elasticsearch-operator](https://charmhub.io/tigera-secure-ee/configurations#enable-elasticsearch-operator)
* [ignore-loose-rpf](https://charmhub.io/tigera-secure-ee/configurations#ignore-loose-rpf)
* [ipip](https://charmhub.io/tigera-secure-ee/configurations#ipip)
* [license-key](https://charmhub.io/tigera-secure-ee/configurations#license-key)
* [nat-outgoing](https://charmhub.io/tigera-secure-ee/configurations#nat-outgoing)
* [registry](https://charmhub.io/tigera-secure-ee/configurations#registry)
* [registry-credentials](https://charmhub.io/tigera-secure-ee/configurations#registry-credentials)

[Learn about configurations >](https://juju.is/docs/juju/configuration#heading--application-configuration)

* calico-node-image | string

  Default: tigera/cnx-node:v2.3.0

  The image id to use for cnx node.
* calicoctl-image | string

  Default: tigera/calicoctl:v2.3.0

  The image id to use for calicoctl.
* enable-elasticsearch-operator | boolean

  Default: True

  Enable deployment of elasticsearch-operator into Kubernetes. This
  provides a monitoring and metrics solution for use with Tigera EE that
  is suitable for proof-of-concept purposes, but is not recommended for
  production use.
* ignore-loose-rpf | boolean

  Enable or disable IgnoreLooseRPF for Calico Felix. This is only used
  when rp\_filter is set to a value of 2.
* ipip | string

  Default: Never

  IPIP mode. Must be one of "Always", "CrossSubnet", or "Never".
* license-key | string

  Tigera EE license key, base64-encoded. Example:

  juju config tigera-secure-ee license-key=$(base64 -w0 license.yaml)
* nat-outgoing | boolean

  Default: True

  NAT outgoing traffic
* registry | string

  Registry to use for images. If unspecified, defaults will be used:
  docker.io, quay.io, docker.elastic.co
* registry-credentials | string

  Private docker registry credentials, in the form of a base64-encoded
  docker config.json file. Example:

  juju config tigera-secure-ee registry-credentials=$(base64 -w0 config.json)
