Dalet Flex Variables

Here's an exhaustive list of Dalet Flex public API variables.

All listed variables are meant to be overridable by platform specifics.

dalet_flex_release

Defines the Flex release to be used.

dalet_flex_release: x.y.z

Platform Settings

The following variables are meant to tune platform settings.

dalet_flex_platform_id

Defines a friendly name identifier for the platform.

The variable is to be re-used internally in multiple places to defines various cluster identifiers.

WARNING: This variable is meant to be immutable. Do NOT change it post initial platform deployment.

dalet_flex_platform_id: ""

dalet_flex_platform_private_fqdn

Defines the private DNS domain for Flex services.

All server instances will be part of this domain.

This is usually something like flex.company.internal or <platform_id>.company.internal.

dalet_flex_platform_private_fqdn: ""

dalet_flex_platform_private_subnet_cidr

Defines the private subnet CIDR for the hosted platform.

This allows various services to restrict some services access to whitelisted instances only.

dalet_flex_platform_private_subnet_cidr: 10.0.0.0/8

dalet_flex_platform_public_fqdn

Defines the public DNS domain for Flex services (if Internet exposed).

Defaults to private DNS domain if unspecified.

This is usually something like flex.company.com or <platform_id>.company.com.

NOTE: Assimilated to private FQDN if unspecified.

dalet_flex_platform_public_fqdn: ""

dalet_flex_platform_lbaas_enabled

Do we use Load-Balancer (LB) as-a-service (e.g. AWS ALB) or manual-setup (including high-availability) ?

dalet_flex_platform_lbaas_enabled: true

dalet_flex_platform_dbaas_enabled

Do we use Database (DB) as-a-service (e.g. AWS RDS) or manual-setup (including replication) ?

dalet_flex_platform_dbaas_enabled: true

dalet_flex_platform_region_name

Defines the Cloud provider region name (when applicable)

dalet_flex_platform_region_name: us-east-1

dalet_flex_platform_kubernetes_addon_enabled

Whether we use Kubernetes for FSP/FMP deployment and auto-scaling

dalet_flex_platform_kubernetes_addon_enabled: false

Flex Multi-Tenancy

dalet_flex_tenant_master_name

Define name of the primary Flex tenant, to be accessed through https://<TENANT>.<FQDN>

dalet_flex_tenant_master_name: master

dalet_flex_tenant_master_admin_user

Username for primary Flex tenant's admin account (defaults to masteruser).

dalet_flex_tenant_master_admin_user: masteruser

dalet_flex_tenant_master_admin_password

Password for primary Flex tenant's admin account.

SENSITIVE: It is highly recommended for password to be encrypted with Vault/SOPS.

Defaults to a vault-encrypted vault_dalet_flex_tenant_master_admin_password secret variable, if unspecified.

dalet_flex_tenant_master_admin_password: ""

Site Properties

Flex always consists of a main site (a.k.a hub) where core processing happens.

Additional satellite sites can be associated, connected to main hub, processing specific workload.

dalet_flex_hub_id

Defines the main hub's Consul cluster identifier.

dalet_flex_hub_id: dc1

dalet_flex_hub_fqdn

Optional public address of the hub's Consul cluster, for satellite nodes to connect to (e.g. consul.hub.acme.com).

Only required when managing satellite sites.

dalet_flex_hub_fqdn: "consul.{{ dalet_flex_platform_public_fqdn }}"

dalet_flex_site_id

Optionally defines local site's Consul cluster identifier.

Leave unchanged if no satellite is being used, override with satellite-specific identifier otherwise.

Defaults to Flex Hub identifier if unspecified.

dalet_flex_site_id: ""

A standard hub + satellite(s) deployment would be configured as:

hub:
  dalet_flex_hub_id: "hub"
satellite1:
  dalet_flex_hub_id: "hub"
  dalet_flex_hub_fqdn: "consul.hub.acme.com"
  dalet_flex_site_id: "sat1"
satellite2:
  dalet_flex_hub_id: "hub"
  dalet_flex_hub_fqdn: "consul.hub.acme.com"
  dalet_flex_site_id: "sat2"

Container Image Registry

dalet_flex_application_registry

Defines container registry where to pull images from.

dalet_flex_application_registry: registry.services.ooflex.net

dalet_flex_application_registry_user

Defines the username to be used to log into private container registry.

If using Harbor, it usually consists of some robot account formatted as robot_.

dalet_flex_application_registry_user: ""

dalet_flex_application_registry_password

Defines the password to be used to log into private container registry.

SENSITIVE: It is highly recommended for password to be encrypted with Vault/SOPS.

Defaults to a vault-encrypted vault_dalet_flex_application_registry_password secret variable, if unspecified.

dalet_flex_application_registry_password: "{{ vault_dalet_flex_application_registry_password }}"

Storage and Data Management

dalet_flex_storage_global_data_dir

Defines a global endpoint prefix location for all persistent data storage (e.g. databases)

dalet_flex_storage_global_data_dir: /flex

WARNING: Note that Flex will mount various path from the provided remote network filesystem. It is mandatory that these directories are created before (manually or programmatically, e.g. with Terraform) before trying for the remote filesystem to be mounted.

dalet_flex_storage_nfs_host

Optional NFS server endpoint to be used to mount network shared storage.

Can be either an FQDN or an IP address.

dalet_flex_storage_nfs_host: ""

dalet_flex_storage_nfs_path

Optional NFS server path location to be used to mount network shared storage.

Formated as UNIX style, e.g. /path.

dalet_flex_storage_nfs_path: ""

dalet_flex_storage_nfs_version

Optional NFS protocol version to use when mounting NFS shares.

Defaults to the baseos automount_nfs_version_default value (4.1) when not set.

dalet_flex_storage_nfs_version: "4.1"

dalet_flex_storage_cifs_host

Optional Samba/CIFS server endpoint to be used to mount network shared storage.

Can be either an FQDN or an IP address.

dalet_flex_storage_cifs_host: ""

dalet_flex_storage_cifs_share

Optional Samba/CIFS share name to be used to mount network shared storage.

Formated as UNIX style, e.g. /share.

dalet_flex_storage_cifs_share: ""

dalet_flex_storage_cifs_user

Optional Samba/CIFS username to be used to mount network shared storage.

dalet_flex_storage_cifs_user: ""

dalet_flex_storage_cifs_password

Optional Samba/CIFS password to be used to mount network shared storage.

SENSITIVE: It is highly recommended for password to be encrypted with Vault/SOPS.

Defaults to a vault-encrypted vault_dalet_flex_storage_cifs_password secret variable, if unspecified.

dalet_flex_storage_cifs_password: ""

dalet_flex_storage_aws_efs_id

Optional AWS Elastic File System (EFS) identifier to be used to mount network shared storage.

Defined as raw identifier, without trailing .efs.AWS_REGION.amazonaws.com suffix.

dalet_flex_storage_aws_efs_id: ""

dalet_flex_storage_aws_efs_iam_enabled

Optionally specify if AWS EFS volume must be mounted IAM identity policy for authorization.

Refer to AWS IAM documentation for additional details.

dalet_flex_storage_aws_efs_iam_enabled: false

dalet_flex_storage_aws_efs_bootstrap

Optionally trigger the creation of EFS subdirectories on the remote filesystem. Useful on fresh deployments where the expected directories do not exist yet.

dalet_flex_storage_aws_efs_bootstrap: false

dalet_flex_storage_azure_files_account

Optional MS Azure Files account name to be used to mount network shared storage.

Defined as a raw identifier, without trailing .file.core.windows.net suffix.

dalet_flex_storage_azure_files_account: ""

dalet_flex_storage_azure_files_share

Optional MS Azure Files share name to be used to mount network shared storage.

Formated as UNIX style, e.g. /share.

dalet_flex_storage_azure_files_share: ""

dalet_flex_storage_azure_files_password

Optional MS Azure Files password to be used to mount network shared storage.

SENSITIVE: It is highly recommended for password to be encrypted with Vault/SOPS.

Defaults to a vault-encrypted vault_dalet_flex_storage_azure_files_password secret variable, if unspecified.

dalet_flex_storage_azure_files_password: ""

dalet_flex_storage_ephemeral_volume

Optional local disk volume to be mounted at boot time.

This can be handy with some volatile volume on Cloud-based platforms, where some disks may not survive reboot.

On AWS, this is most likely a device like /dev/nvme1n1.

dalet_flex_storage_ephemeral_volume: ""

dalet_flex_storage_ephemeral_volume_mount_point

Optional local mount point to be used to mount the specified ephemeral volume, if any.

dalet_flex_storage_ephemeral_volume_mount_point: /mnt/ephemeral

Load-Balancer Settings

The followings settings are only used when dalet_flex_platform_lbaas_enabled option is disabled, i.e. when using a self-managed load-balancer cluster.

dalet_flex_lb_private_address

Defines load-balancer private endpoint.

Load-balancer operates in an active/passive mode and uses a virtual IP (VIP) for service redundancy.

WARNING: Ensure the selected IPv4 address is not already used in the private LAN.

dalet_flex_lb_private_address: ""

dalet_flex_lb_private_virtual_router_id

Defines the virtual router identifier (VRID) to be used by the load-balancer VRRP group to assign VIP address.

Only peers with the same VRID are able to failover IP address altogether.

WARNING: VRID must be unique across a network L2-segment (range: from 1 to 255).

dalet_flex_lb_private_virtual_router_id: 50

dalet_flex_lb_private_interface

Defines the network interface to be used to bind the load-balancer VIP address.

Defaults to (auto-detected) private network adapter if unspecified.

WARNING When using both db and lb failover, it is not supported to run db and lb containers on the same hosts.

dalet_flex_lb_private_interface: ''

dalet_flex_lb_private_control_interface

Defines the network interface to be used to exchange VRRP packets between peers.

Defaults to (auto-detected) private network adapter if unspecified.

dalet_flex_lb_private_control_interface: ""

dalet_flex_lb_use_bfd

Enables BFD (Bidirectional Forwarding Detection) for faster failover detection in load balancer Keepalived configuration.

dalet_flex_lb_use_bfd: false

dalet_flex_lb_use_unicast

Enables unicast mode instead of multicast for load balancer Keepalived VRRP communication.

dalet_flex_lb_use_unicast: true

dalet_flex_lb_use_vmac

Enables Virtual MAC address for load balancer VIP. When enabled, the VIP uses a dedicated MAC address.

dalet_flex_lb_use_vmac: false

dalet_flex_lb_http_enabled

Defines whether load-balancer should explicitly listen to (unsecure) HTTP port (80).

When enabled in association with dalet_flex_lb_https_enabled variable, all unsecure HTTP connections will be redirected to secure HTTPS ones.

This is mostly for used for convenience and URL compatibility.

WARNING: This is required when using Let's Encrypt automatic certificate issuance with HTTP challenge.

dalet_flex_lb_http_enabled: true

dalet_flex_lb_https_enabled

Defines whether load-balancer should explicitly listen to secure HTTPS port (443).

This is default browser policy.

dalet_flex_lb_https_enabled: true

dalet_flex_lb_alpn_enabled

Defines whether support for Application-Layer Protocol Negotiation (ALPN) should be enabled.

ALPN is a TLS extension that allows the application layer to negotiate which protocol should be performed over a secure connection in a manner that avoids additional round trips and which is independent of the application-layer protocols. It is used to establish HTTP/2 connections without additional round trips.

dalet_flex_lb_alpn_enabled: true

dalet_flex_lb_tls_min_version

Defines the minimal TLS version to be supported by load-balancer.

TLS is a cryptogrtaphic protocol designed to provide communications security over network (e.g. HTTPS).

TLS versions prior to 1.2 are currently considered as weak and should not be used.

WARNING: Enabling support for old versions put security at risk and should only be done if legacy clients are used.

dalet_flex_lb_tls_min_version: "1.3"

dalet_flex_lb_tls_certificate_issuer

Defines whether TLS certificate(s) should be issued automatically (using Let's Encrypt certificate of authority) or if they have been already generated.

Possible options are auto for Let's Encrypt and custom for customer-provided certificate.

NOTE: Automatically issued certificates are also automatically renewed, preventing any expiry issue.

dalet_flex_lb_tls_certificate_issuer: auto

dalet_flex_lb_tls_certificate_issuer_auto_subdomains

List of public DNS domain prefixes to request TLS certificates for.

Default is to request a wildcard certificate ('*') to all public sub-domains will match TLS certificate.

One can define a list of Subject Alternative Name (SAN) entries instead.

List must be formatted as a list of sub-domain where <SUBDOMAIN>.<dalet_flex_platform_public_fqdn>.

WARNING: DNS entries must be valid and have been created before trying to issue TLS certificate(s).

dalet_flex_lb_tls_certificate_issuer_auto_subdomains: ['*']

dalet_flex_lb_tls_certificate_issuer_auto_challenge

Defines which challenge is to be used by Let's Encrypt to verify domain ownership when issuing TLS certificates.

Possible options are:

  • dns-route53 (default) when domain's DNS is managed over AWS Route53
  • http for domains not managed over AWS Route53
dalet_flex_lb_tls_certificate_issuer_auto_challenge: dns-route53

dalet_flex_lb_tls_certificate_issuer_auto_route53_access_key_id

Defines AWS Route53 Access Key identifier to be used to perform TLS issuance challenge.

NOTE: Only useful when AWS Route53 challenge backend is being used.

dalet_flex_lb_tls_certificate_issuer_auto_route53_access_key_id: ''

dalet_flex_lb_tls_certificate_issuer_auto_route53_secret_access_key

Defines AWS Route53 Secret Access Key to be used to perform TLS issuance challenge.

NOTE: Only useful when AWS Route53 challenge backend is being used.

SENSITIVE: It is highly recommended for secret to be encrypted with Vault/SOPS.

Defaults to a vault-encrypted vault_dalet_flex_lb_tls_certificate_issuer_auto_route53_secret_access_key secret variable, if unspecified.

dalet_flex_lb_tls_certificate_issuer_auto_route53_secret_access_key: ""

dalet_flex_lb_tls_certificate_issuer_auto_http_port

Defines HTTP port to connect to perform TLS issuance challenge.

NOTE: Only useful when HTTP challenge backend is being used.

WARNING: Specified port must be opened (TCP) on firewall.

dalet_flex_lb_tls_certificate_issuer_auto_http_port: 8888

dalet_flex_lb_tls_certificate_issuer_custom_cert_file

When custom TLS certificate issuer is chosen (i.e. customer-provided certificates), provides a the filename of PEM-formatted certificates to be exposed by load-balancer.

WARNING: Load-Balancer expects certificates to be in fullchain format, i.e.

  1. The certificate for your domain
  2. The The intermediates in ascending order to the Root CA
  3. A Root CA, if any (usually none)
  4. Private Key

Example:

$ cat certificate.crt intermediates.pem private.key > cert.pem

WARNING: Certificate MUST be present in Ansible's platform files/ folder.

SENSITIVE: It is highly recommended for certificates to be encrypted with Vault/SOPS (contains private key).

dalet_flex_lb_tls_certificate_issuer_custom_cert_file: cert.pem

dalet_flex_lb_admin_user

Defines the username used to access htaccess-protected resources offered by HAProxy (defaults to admin).

dalet_flex_lb_admin_user: admin

dalet_flex_lb_admin_password

Password for HAProxy admin account credentials.

SENSITIVE: It is highly recommended for password to be encrypted with Vault/SOPS.

Defaults to a vault-encrypted vault_dalet_flex_lb_admin_password secret variable, if unspecified.

dalet_flex_lb_admin_password: ""

dalet_flex_lb_stats_user

Username for HAProxy statistics page access (defaults to admin).

dalet_flex_lb_stats_user: admin

dalet_flex_lb_stats_password

Password for HAProxy statistics page access.

SENSITIVE: It is highly recommended for password to be encrypted with Vault/SOPS.

Defaults to a vault-encrypted vault_dalet_flex_lb)stats_password secret variable, if unspecified.

dalet_flex_lb_stats_password: ""

dalet_flex_lb_tuning_extra_config

When set, this allows extending HAProxy configuration with custom global settings.

dalet_flex_lb_tuning_extra_config: ''

Refer to HAProxy documentation for syntax format and details

Example:

dalet_flex_lb_tuning_extra_config: |
  http-response replace-header Content-Disposition (.*)filename=(.*) \1filename=\"\2\"

dalet_flex_lb_tuning_extra_frontend

When set, this allows extending HAProxy configuration with custom frontend settings.

dalet_flex_lb_tuning_extra_frontend: ''

Refer to HAProxy documentation for syntax format and details

Example:

dalet_flex_lb_tuning_extra_frontend: |
  frontend frontend_example
    bind *:<port>
    mode tcp
    timeout client 15s
    default_backend backend_example

dalet_flex_lb_tuning_extra_backend

When set, this allows extending HAProxy configuration with custom backend settings.

dalet_flex_lb_tuning_extra_backend: ''

Refer to HAProxy documentation for syntax format and details

Example:

dalet_flex_lb_tuning_extra_backend: |
  backend backend_example
    mode tcp
    balance roundrobin
    server example 10.0.0.1:<port> ssl verify none check
    timeout connect 3s
    timeout queue 3s
    timeout server 3s

Database(s) Settings - MySQL

dalet_flex_db_mysql_host

Defines MySQL server endpoint.

Can be either an FQDN for DBaaS (such as AWS RDS) or an IP address (virtual IP in master/slave replication mode).

dalet_flex_db_mysql_host: ""

dalet_flex_db_mysql_port

Port for MySQL server endpoint (defaults to standard 3306).

dalet_flex_db_mysql_port: 3306

dalet_flex_db_mysql_private_virtual_router_id

Defines the virtual router identifier (VRID) to be used by the MySQL VRRP group to assign VIP address.

Only peers with the same VRID are able to failover IP address altogether.

NOTE: This setting is used with self-managed database (i.e. when not dalet_flex_platform_dbaas_enabled).

WARNING: VRID must be unique across a network L2-segment (range: from 1 to 255).

dalet_flex_db_mysql_private_virtual_router_id: 60

dalet_flex_db_mysql_private_interface

Defines the network interface to be used to bind the MySQL VIP address.

Defaults to (auto-detected) private network adapter if unspecified.

NOTE: This setting is used with self-managed database (i.e. when not dalet_flex_platform_dbaas_enabled).

WARNING When using both db and lb failover, it is not supported to run db and lb containers on the same hosts.

dalet_flex_db_mysql_private_interface: ''

dalet_flex_db_mysql_private_address

Defines the network address to be used to bind the MySQL VIP address.

NOTE: This setting is used with self-managed database (i.e. when not dalet_flex_platform_dbaas_enabled).

dalet_flex_db_mysql_private_address: ''

dalet_flex_db_mysql_use_bfd

Enables BFD (Bidirectional Forwarding Detection) for faster failover detection in MySQL Keepalived configuration.

NOTE: This setting is used with self-managed database (i.e. when not dalet_flex_platform_dbaas_enabled).

dalet_flex_db_mysql_use_bfd: false

dalet_flex_db_mysql_use_unicast

Enables unicast mode instead of multicast for MySQL Keepalived VRRP communication.

NOTE: This setting is used with self-managed database (i.e. when not dalet_flex_platform_dbaas_enabled).

dalet_flex_db_mysql_use_unicast: true

dalet_flex_db_mysql_use_vmac

Enables Virtual MAC address for MySQL VIP. When enabled, the VIP uses a dedicated MAC address.

NOTE: This setting is used with self-managed database (i.e. when not dalet_flex_platform_dbaas_enabled).

dalet_flex_db_mysql_use_vmac: false

dalet_flex_db_mysql_private_control_interface

Defines the network interface to be used to exchange VRRP packets between peers.

Defaults to (auto-detected) private network adapter if unspecified.

NOTE: This setting is used with self-managed database (i.e. when not dalet_flex_platform_dbaas_enabled).

dalet_flex_db_mysql_private_control_interface: ""

dalet_flex_db_mysql_allowed_hosts_rw

Defines a list of extra hosts (or networks) allowed to connect with Read/Write privileges to MySQL database.

Defaults already includes localhost and all IP addresses from private LAN.

Uses % as wildcard character (e.g. '192.168.%' means 192.168.0.0/16 CIDR)

dalet_flex_db_mysql_allowed_hosts_rw: []

dalet_flex_db_mysql_allowed_hosts_ro

Defines a list of extra hosts (or networks) allowed to connect with Read-Only privileges to MySQL database.

Defaults already includes localhost and all IP addresses from private LAN.

Uses % as wildcard character (e.g. '192.168.%' means 192.168.0.0/16 CIDR)

dalet_flex_db_mysql_allowed_hosts_ro: []

dalet_flex_db_mysql_admin_user

Username for MySQL admin account (defaults to root).

dalet_flex_db_mysql_admin_user: root

dalet_flex_db_mysql_admin_password

Password for MySQL admin account.

SENSITIVE: It is highly recommended for password to be encrypted with Vault/SOPS.

Defaults to a vault-encrypted vault_dalet_flex_db_mysql_admin_password secret variable, if unspecified.

dalet_flex_db_mysql_admin_password: ""

dalet_flex_db_mysql_exporter_user

Username for MySQL metrics exporter account (defaults to mysqldexporter).

dalet_flex_db_mysql_exporter_user: mysqldexporter

dalet_flex_db_mysql_exporter_password

Password for MySQL metrics exporter account.

SENSITIVE: It is highly recommended for password to be encrypted with Vault/SOPS.

Defaults to a vault-encrypted vault_dalet_flex_db_mysql_exporter_password secret variable, if unspecified.

dalet_flex_db_mysql_exporter_password: ""

dalet_flex_db_mysql_replication_user

Username for MySQL replication account (defaults to repl).

dalet_flex_db_mysql_replication_user: repl

dalet_flex_db_mysql_replication_password

Password for MySQL replication account.

SENSITIVE: It is highly recommended for password to be encrypted with Vault/SOPS.

Defaults to a vault-encrypted vault_dalet_flex_db_mysql_replication_password secret variable, if unspecified.

dalet_flex_db_mysql_replication_password: ""

dalet_flex_db_mysql_db_flex_enterprise_user

Username for MySQL flex-enterprise database service account (defaults to flex-enterprise).

dalet_flex_db_mysql_db_flex_enterprise_user: flex-enterprise

dalet_flex_db_mysql_db_flex_enterprise_password

Password for MySQL flex-enterprise database service account.

SENSITIVE: It is highly recommended for password to be encrypted with Vault/SOPS.

Defaults to a vault-encrypted vault_dalet_flex_db_mysql_db_flex_enterprise_password secret variable, if unspecified.

dalet_flex_db_mysql_db_flex_enterprise_password: ""

dalet_flex_db_mysql_db_flex_authentication_user

Username for MySQL flex-authentication database service account (defaults to flex-authentication).

dalet_flex_db_mysql_db_flex_authentication_user: flex-authentication

dalet_flex_db_mysql_db_flex_authentication_password

Password for MySQL flex-authentication database service account.

SENSITIVE: It is highly recommended for password to be encrypted with Vault/SOPS.

Defaults to a vault-encrypted vault_dalet_flex_db_mysql_db_flex_authentication_password secret variable, if unspecified.

dalet_flex_db_mysql_db_flex_authentication_password: ""

dalet_flex_db_mysql_db_flex_metadata_user

Username for MySQL flex-metadata database service account (defaults to flex-metadata).

dalet_flex_db_mysql_db_flex_metadata_user: flex-metadata

dalet_flex_db_mysql_db_flex_metadata_password

Password for MySQL flex-metadata database service account.

SENSITIVE: It is highly recommended for password to be encrypted with Vault/SOPS.

Defaults to a vault-encrypted vault_dalet_flex_db_mysql_db_flex_metadata_password secret variable, if unspecified.

dalet_flex_db_mysql_db_flex_metadata_password: ""

dalet_flex_db_mysql_db_flex_webtransfer_user

Username for MySQL flex-web-transfer database service account (defaults to flexwebtransferuser).

dalet_flex_db_mysql_db_flex_webtransfer_user: flexwebtransferuser

dalet_flex_db_mysql_db_flex_webtransfer_password

Password for MySQL flex-web-transfer database service account.

SENSITIVE: It is highly recommended for password to be encrypted with Vault/SOPS.

Defaults to a vault-encrypted vault_dalet_flex_db_mysql_db_flex_webtransfer_password secret variable, if unspecified.

dalet_flex_db_mysql_db_flex_webtransfer_password: ""

dalet_flex_db_mysql_db_flex_usage_user

Username for MySQL flex-rate-cards and flex-usage-coordinator usage databases service account (defaults to flexusageuser).

dalet_flex_db_mysql_db_flex_usage_user: flexusageuser

dalet_flex_db_mysql_db_flex_usage_password

Username for MySQL flex-rate-cards and flex-usage-coordinator usage databases service account.

SENSITIVE: It is highly recommended for password to be encrypted with Vault/SOPS.

Defaults to a vault-encrypted vault_dalet_flex_db_mysql_db_flex_usafe_password secret variable, if unspecified.

dalet_flex_db_mysql_db_flex_usage_password: ""

Database(s) Settings - ArangoDB

dalet_flex_db_arangodb_admin_password

Password for ArangoDB admin account.

SENSITIVE: It is highly recommended for password to be encrypted with Vault/SOPS.

Defaults to a vault-encrypted vault_dalet_flex_db_arangodb_admin_password secret variable, if unspecified.

dalet_flex_db_arangodb_admin_password: ""

dalet_flex_db_arangodb_service_user

Username for ArangoDB service account (defaults to flex).

dalet_flex_db_arangodb_service_user: flex

dalet_flex_db_arangodb_service_password

Password for ArangoDB service account.

SENSITIVE: It is highly recommended for password to be encrypted with Vault/SOPS.

Defaults to a vault-encrypted vault_dalet_flex_db_arangodb_service_password secret variable, if unspecified.

dalet_flex_db_arangodb_service_password: ""

dalet_flex_db_arangodb_jwt_secret_key

Defines a secure secret key used server-side to encrypt issued JWT tokens (recommended: 64+ characters string).

WARNING: API authentication becomes vulnerable if key is compromised.

SENSITIVE: It is highly recommended for password to be encrypted with Vault/SOPS.

Defaults to a vault-encrypted vault_dalet_flex_db_arangodb_jwt_secret_key secret variable, if unspecified.

dalet_flex_db_arangodb_jwt_secret_key: ""

Database(s) Settings - MongoDB

dalet_flex_db_mongodb_upgrade_automation_rollout

Enables or disables the automated rolling upgrade process for the MongoDB cluster.

WARNING: When set to true, the playbook will perform automated service restarts and data migrations. Ensure you have a valid backup and have verified the maintenance window before enabling.

  • Type: boolean
  • Default: false
dalet_flex_db_mongodb_upgrade_automation_rollout: false

dalet_flex_db_mongodb_replicaset_name

Defines MongoDB ReplicaSet name/identifier.

WARNING: Must be unique across your network, all server instance with this name with belong to the same cluster.

Defaults to Flex platform identifier if unspecified.

dalet_flex_db_mongodb_replicaset_name: ""

dalet_flex_db_mongodb_replicaset_secret

Secret key for MongoDB ReplicaSet cluster.

All server instances from the replica set must share the same key to reach the cluster as members.

SENSITIVE: It is highly recommended for password to be encrypted with Vault/SOPS.

Defaults to a vault-encrypted vault_dalet_flex_db_mongodb_replicaset_secret secret variable, if unspecified.

dalet_flex_db_mongodb_replicaset_secret: ""

dalet_flex_db_mongodb_admin_user

Username for MongoDB admin account (defaults to root).

dalet_flex_db_mongodb_admin_user: root

dalet_flex_db_mongodb_admin_password

Password for MongoDB admin account.

SENSITIVE: It is highly recommended for password to be encrypted with Vault/SOPS.

Defaults to a vault-encrypted vault_dalet_flex_db_mongodb_admin_password secret variable, if unspecified.

dalet_flex_db_mongodb_admin_password: ""

dalet_flex_db_mongodb_service_user

Username for MongoDB service account (defaults to flex).

dalet_flex_db_mongodb_service_user: flex

dalet_flex_db_mongodb_service_password

Password for MongoDB service account.

SENSITIVE: It is highly recommended for password to be encrypted with Vault/SOPS.

Defaults to a vault-encrypted vault_dalet_flex_db_mongodb_service_password secret variable, if unspecified.

dalet_flex_db_mongodb_service_password: ""

Database(s) Settings - Redis

dalet_flex_db_redis_admin_password

Password for Redis admin account.

SENSITIVE: It is highly recommended for password to be encrypted with Vault/SOPS.

Defaults to a vault-encrypted vault_dalet_flex_db_redis_admin_password secret variable, if unspecified.

dalet_flex_db_redis_admin_password: ""

Database(s) Settings - RabbitMQ

dalet_flex_db_rabbitmq_service_user

Username for RabbitMQ service account (defaults to guest).

dalet_flex_db_rabbitmq_service_user: guest

dalet_flex_db_rabbitmq_service_password

Password for RabbitMQ service account (optional, defaults to guest).

SENSITIVE: It is highly recommended for password to be encrypted with Vault/SOPS.

Defaults to a vault-encrypted vault_dalet_flex_db_rabbitmq_service_password secret variable, if unspecified.

dalet_flex_db_rabbitmq_service_password: ""

dalet_flex_db_rabbitmq_tls_enabled

Define whether RabbitMQ API must be exposed over secure HTTPS endpoint.

NOTE: TLS exposure is recommended when Flex <-> Pyramid Unified Search federation is expected.

dalet_flex_db_rabbitmq_tls_enabled: false

dalet_flex_db_rabbitmq_tls_port

Defines RabbitMQ TLS-exposed port to be used, when enabled.

dalet_flex_db_rabbitmq_tls_port: 5671

dalet_flex_db_rabbitmq_tls_ca_cert_file

When Rabbit TLS support is enabled, provides a the filename of PEM-formatted CA public certificate

WARNING: Certificate MUST be present in Ansible's platform files/ folder.

dalet_flex_db_rabbitmq_tls_ca_cert_file: rabbitmq-ca-cert.pem

dalet_flex_db_rabbitmq_tls_server_cert_file

When Rabbit TLS support is enabled, provides a the filename of PEM-formatted server public certificate

WARNING: Certificate MUST be present in Ansible's platform files folder.

dalet_flex_db_rabbitmq_tls_server_cert_file: rabbitmq-server-cert.pem

dalet_flex_db_rabbitmq_tls_server_key_file

When Rabbit TLS support is enabled, provides a the filename of PEM-formatted server public certificate

WARNING: Certificate MUST be present in Ansible's platform files/ folder.

SENSITIVE: It is highly recommended for certificate to be encrypted with Vault/SOPS (contains private key).

dalet_flex_db_rabbitmq_tls_server_key_file: rabbitmq-server-key.pem

dalet_flex_db_rabbitmq_federation_enabled

Enables RabbitMQ federation.

This is required for Flex <-> Pyramid Unified Search capability.

Whenever an asset is created, updated or deleted on the Flex side, the Flex-Indexer service, in addition to updating the local Flex search index (OpenSearch), sends a message to the Pyramid system. This message contains the same update, which will be applied to the local Pyramid index. This enables a Pyramid user to search both its local assets as well as the (remote) Flex assets.

dalet_flex_db_rabbitmq_federation_enabled: false

dalet_flex_db_rabbitmq_federation_user

Username for RabbitMQ federation account (defaults to flex-pyramid-user).

dalet_flex_db_rabbitmq_federation_user: flex-pyramid-user

dalet_flex_db_rabbitmq_federation_password

Password for RabbitMQ federation account

SENSITIVE: It is highly recommended for password to be encrypted with Vault/SOPS.

Defaults to a vault-encrypted vault_dalet_flex_db_rabbitmq_federation_password secret variable, if unspecified.

dalet_flex_db_rabbitmq_federation_password: ""

dalet_flex_db_rabbitmq_federation_vhost

Defines the RabbitMQ virtual host the federation user to read/write permissions on.

dalet_flex_db_rabbitmq_federation_vhost: "/"

dalet_flex_db_rabbitmq_federation_topics

Defines the list of RabbitMQ topics where federation user has read/write permissions on.

dalet_flex_db_rabbitmq_federation_topics:
  - "flex.events.exchange"
  - "flex.indexelastic.replication.dl.exchange"
  - "flex.indexelastic.replication.exchange"

Flex Authentication

dalet_flex_auth_jwt_secret_key

Defines a secure secret key used server-side to encrypt issued JWT tokens (32+ characters string).

WARNING: API authentication becomes vulnerable if key is compromised.

SENSITIVE: It is highly recommended for password to be encrypted with Vault/SOPS.

Defaults to a vault-encrypted vault_dalet_flex_auth_jwt_secret_key secret variable, if unspecified.

dalet_flex_auth_jwt_secret_key: ""

dalet_flex_auth_oauth_app_registration_key

Defines a secure unique OAuth 2.0 application registration key (32+ characters string).

Its scope is system-wide and may be sent communicated to third-party service and application developers.

SENSITIVE: It is highly recommended for password to be encrypted with Vault/SOPS.

Defaults to a vault-encrypted vault_dalet_flex_auth_oauth_app_registration_key secret variable, if unspecified.

dalet_flex_auth_oauth_app_registration_key: ""

dalet_flex_auth_oauth_signing_key

Defines a secure signing key used for signing OAuth 2.0 tokens (32+ characters string).

SENSITIVE: It is highly recommended for password to be encrypted with Vault/SOPS.

Defaults to a vault-encrypted vault_dalet_flex_auth_oauth_signing_key secret variable, if unspecified.

dalet_flex_auth_oauth_signing_key: ""

dalet_flex_auth_ad_fqdn

Optional ActiveDirectoy (LDAP) endpoint FQDN used for user authentication (e.g. ldap.acme.com).

WARNING: Do NOT prefix it with protocol (ldap:// or ldaps://).

dalet_flex_auth_ad_fqdn: ''

dalet_flex_auth_ad_domain

Optional ActiveDirectory (LDAP) local domain used for user authentication (e.g. acme.local).

dalet_flex_auth_ad_domain: ''

dalet_flex_auth_ad_search_base

Optional ActiveDirectory (LDAP) search domain used for user authentication (e.g. OU=users,DC=acme,DC=local).

dalet_flex_auth_ad_search_base: ''

Flex Secrets Management

dalet_flex_secrets_encryption_key

Defines the encryption key used by Flex Secrets service to securely store persistent information for Flex VFS location objects (secrets, keys, username ...).

Credentials are consequently stored in an encrypted format in exchange for a token that can be used to retrieve the secret.

WARNING: Must be a 16+ characters string.

SENSITIVE: It is highly recommended for password to be encrypted with Vault/SOPS.

Defaults to a vault-encrypted vault_dalet_flex_secrets_encryption_key secret variable, if unspecified.

dalet_flex_secrets_encryption_key: ""

dalet_flex_secrets_encryption_iv

Defines the secrets encryption initialization vector (16+ characters string).

Defaults to a vault-encrypted vault_dalet_flex_secrets_encryption_iv secret variable, if unspecified.

dalet_flex_secrets_encryption_iv: ""

SMTP Settings

Flex services are unconditionally using a local SMTP relay to send emails, i.e.:

Services -> Local SMTP Relay -> Upstream SMTP Server

The variables below are all meant to instruct the local SMTP relay how to reach out the upstream SMTP server.

Upstream SMTP server can be either a Cloud-based service or a corporate private one, as long as relay can reach it.

dalet_flex_smtp_server_host

Defines the SMTP server address to be used to send emails.

Example: smtp.office365.com for O365 or email-smtp.{REGION}.amazonaws.com for AWS SES

dalet_flex_smtp_server_host: ""

dalet_flex_smtp_server_port

Defines the STMP server's port.

Usually 25 (unsecure), 465 (implicit SSL), 587 (StartTLS, default) or 2525 (StartTLS alternative).

dalet_flex_smtp_server_port: 587

dalet_flex_smtp_domain

Defines the SMTP email domain allowed to send emails from.

Defaults to platform's public FQDN, if unspecified.

dalet_flex_smtp_domain: ""

dalet_flex_smtp_user

Defines the service account username to connect to SMTP server.

This is optional. Some corporate SMTP servers might be configured to allow unauthenticated connections.

Leave it blank if no authentication is required.

dalet_flex_smtp_user: ""

dalet_flex_smtp_password

Defines the service account password to connect to SMTP server.

SENSITIVE: It is highly recommended for password to be encrypted with Vault/SOPS.

Defaults to a vault-encrypted vault_dalet_flex_smtp_password secret variable, if unspecified.

dalet_flex_smtp_password: ""

dalet_flex_postfix_relay_maps

List of custom Postfix relay map entries to configure outbound email routing.

If defined and non-empty, dalet_flex_postfix_relay_maps overrides the default relay configuration.

Each entry must include:

  • sender: the sender pattern (e.g., @domain.com)
  • relayhost: the SMTP relay host and port
  • username: the SMTP username
  • password: the SMTP password

If not defined or empty, the default configuration uses platform-wide SMTP settings:

postfix_relay_maps_default:
  - sender: '@{{ dalet_flex_smtp_domain }}'
    relayhost: '[{{ dalet_flex_smtp_server_host }}]:{{ dalet_flex_smtp_server_port }}'
    username: '{{ dalet_flex_smtp_user }}'
    password: '{{ dalet_flex_smtp_password }}'

Observability

Defines which metrics subsystem to be used.

Supported options are: **prometheus** and **victoriametrics** (default)

```yaml
dalet_flex_metrics_subsystem: victoriametrics
```

</div>
</details>


<details id="admonition-dalet_flex_metrics_alerting_enabled" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_metrics_alerting_enabled-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_metrics_alerting_enabled-title">

dalet_flex_metrics_alerting_enabled

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_metrics_alerting_enabled"></a>
</summary>
<div>

Defines whether local alerting rules must be enabled or not.

Local alerting is explictly disabled if streaming to Dalet Control Tower is enabled as to prevent dual-alerting rules.

```yaml
dalet_flex_metrics_alerting_enabled: "{{ not dalet_baseos_monitoring_control_tower_enabled }}"
```

</div>
</details>


<details id="admonition-dalet_flex_metrics_alerting_email_enabled" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_metrics_alerting_email_enabled-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_metrics_alerting_email_enabled-title">

dalet_flex_metrics_alerting_email_enabled

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_metrics_alerting_email_enabled"></a>
</summary>
<div>

Defines whether local alerts notifications should be sent by email.

```yaml
dalet_flex_metrics_alerting_email_enabled: false
```

</div>
</details>


<details id="admonition-dalet_flex_metrics_alerting_email_sender" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_metrics_alerting_email_sender-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_metrics_alerting_email_sender-title">

dalet_flex_metrics_alerting_email_sender

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_metrics_alerting_email_sender"></a>
</summary>
<div>

Defines the sender email address to send local alerts notifications from.

```yaml
dalet_flex_metrics_alerting_email_sender: "alerts@{{ dalet_flex_smtp_domain }}"
```

</div>
</details>


<details id="admonition-dalet_flex_metrics_alerting_email_recipients" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_metrics_alerting_email_recipients-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_metrics_alerting_email_recipients-title">

dalet_flex_metrics_alerting_email_recipients

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_metrics_alerting_email_recipients"></a>
</summary>
<div>

Defines the recipients email addresses to send local alerts notifications from.

```yaml
dalet_flex_metrics_alerting_email_recipients: ""
```

</div>
</details>


<details id="admonition-dalet_flex_metrics_alerting_email_severity" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_metrics_alerting_email_severity-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_metrics_alerting_email_severity-title">

dalet_flex_metrics_alerting_email_severity

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_metrics_alerting_email_severity"></a>
</summary>
<div>

Defines the local alerts severity threshold to trigger email notifications.

Eligible severity levels are: **critical**, **error**, **warning**, **info** (decreasing severity order)

Multiple severity levels can comnbined through a pipe.

```yaml
dalet_flex_metrics_alerting_email_severity: "critical|error"
```

</div>
</details>


<details id="admonition-dalet_flex_metrics_alerting_slack_enabled" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_metrics_alerting_slack_enabled-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_metrics_alerting_slack_enabled-title">

dalet_flex_metrics_alerting_slack_enabled

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_metrics_alerting_slack_enabled"></a>
</summary>
<div>

Defines whether local alerts notifications should be sent to Slack channel.

```yaml
dalet_flex_metrics_alerting_slack_enabled: false
```

</div>
</details>


<details id="admonition-dalet_flex_metrics_alerting_slack_api_url" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_metrics_alerting_slack_api_url-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_metrics_alerting_slack_api_url-title">

dalet_flex_metrics_alerting_slack_api_url

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_metrics_alerting_slack_api_url"></a>
</summary>
<div>

Slack notifications can be sent via [incoming webhooks](https://api.slack.com/messaging/webhooks).

```yaml
dalet_flex_metrics_alerting_slack_api_url: ""
```

</div>
</details>


<details id="admonition-dalet_flex_metrics_alerting_slack_channel" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_metrics_alerting_slack_channel-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_metrics_alerting_slack_channel-title">

dalet_flex_metrics_alerting_slack_channel

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_metrics_alerting_slack_channel"></a>
</summary>
<div>

Defines the Slack channel to send local alerts notifications to (the # prefix is optional).

```yaml
dalet_flex_metrics_alerting_slack_channel: ""
```

</div>
</details>


<details id="admonition-dalet_flex_metrics_alerting_slack_severity" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_metrics_alerting_slack_severity-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_metrics_alerting_slack_severity-title">

dalet_flex_metrics_alerting_slack_severity

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_metrics_alerting_slack_severity"></a>
</summary>
<div>

Defines the local alerts severity threshold to trigger Slack notifications.

Eligible severity levels are: **critical**, **error**, **warning**, **info** (decreasing severity order)

Multiple severity levels can comnbined through a pipe.

```yaml
dalet_flex_metrics_alerting_slack_severity: "critical|error|warning"
```

</div>
</details>


<details id="admonition-dalet_flex_metrics_alerting_msteams_enabled" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_metrics_alerting_msteams_enabled-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_metrics_alerting_msteams_enabled-title">

dalet_flex_metrics_alerting_msteams_enabled

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_metrics_alerting_msteams_enabled"></a>
</summary>
<div>

Defines whether local alerts notifications should be sent to MS Teams channel.

```yaml
dalet_flex_metrics_alerting_msteams_enabled: false
```

</div>
</details>


<details id="admonition-dalet_flex_metrics_alerting_msteams_webhook_url" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_metrics_alerting_msteams_webhook_url-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_metrics_alerting_msteams_webhook_url-title">

dalet_flex_metrics_alerting_msteams_webhook_url

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_metrics_alerting_msteams_webhook_url"></a>
</summary>
<div>

MS Teams notifications can be sent via [incoming webhooks](https://support.microsoft.com/en-gb/office/create-incoming-webhooks-with-workflows-for-microsoft-teams-8ae491c7-0394-4861-ba59-055e33f75498).

```yaml
dalet_flex_metrics_alerting_msteams_webhook_url: ""
```

</div>
</details>


<details id="admonition-dalet_flex_metrics_alerting_msteams_severity" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_metrics_alerting_msteams_severity-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_metrics_alerting_msteams_severity-title">

dalet_flex_metrics_alerting_msteams_severity

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_metrics_alerting_msteams_severity"></a>
</summary>
<div>

Defines the local alerts severity threshold to trigger MS Teams notifications.

Eligible severity levels are: **critical**, **error**, **warning**, **info** (decreasing severity order)

Multiple severity levels can comnbined through a pipe.
```yaml
dalet_flex_metrics_alerting_msteams_severity: "critical|error|warning"
```

</div>
</details>


<details id="admonition-dalet_flex_metrics_alerting_pagerduty_enabled" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_metrics_alerting_pagerduty_enabled-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_metrics_alerting_pagerduty_enabled-title">

dalet_flex_metrics_alerting_pagerduty_enabled

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_metrics_alerting_pagerduty_enabled"></a>
</summary>
<div>

Defines whether local alerts notifications should be sent to PagerDuty.

```yaml
dalet_flex_metrics_alerting_pagerduty_enabled: false
```

</div>
</details>


<details id="admonition-dalet_flex_metrics_alerting_pagerduty_events_api_key" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_metrics_alerting_pagerduty_events_api_key-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_metrics_alerting_pagerduty_events_api_key-title">

dalet_flex_metrics_alerting_pagerduty_events_api_key

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_metrics_alerting_pagerduty_events_api_key"></a>
</summary>
<div>

PagerDuty notifications can be sent via [Events API v2](https://www.pagerduty.com/docs/guides/prometheus-integration-guide/).

```yaml
dalet_flex_metrics_alerting_pagerduty_events_api_key: ""
```

</div>
</details>


<details id="admonition-dalet_flex_metrics_alerting_pagerduty_severity" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_metrics_alerting_pagerduty_severity-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_metrics_alerting_pagerduty_severity-title">

dalet_flex_metrics_alerting_pagerduty_severity

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_metrics_alerting_pagerduty_severity"></a>
</summary>
<div>

Defines the local alerts severity threshold to trigger PagerDuty notifications.

Eligible severity levels are: **critical**, **error**, **warning**, **info** (decreasing severity order)

Multiple severity levels can comnbined through a pipe.

```yaml
dalet_flex_metrics_alerting_pagerduty_severity: "critical|error"
```

</div>
</details>


<details id="admonition-dalet_flex_metrics_alerting_webhooks" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_metrics_alerting_webhooks-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_metrics_alerting_webhooks-title">

dalet_flex_metrics_alerting_webhooks

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_metrics_alerting_webhooks"></a>
</summary>
<div>

Optional list of custom webhook URLs to send local alert notifications to.

List items are formatted as:

```yaml
  - name: "custom"
    url: "https://webhooks.acme.com"
    severity: "critical|warning"
```

```yaml
dalet_flex_metrics_alerting_webhooks: []
```

</div>
</details>


<details id="admonition-dalet_flex_metrics_alerting_thresholds_custom" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_metrics_alerting_thresholds_custom-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_metrics_alerting_thresholds_custom-title">

dalet_flex_metrics_alerting_thresholds_custom

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_metrics_alerting_thresholds_custom"></a>
</summary>
<div>

Flex local alerts default thresholds can be tuned in, by overriding specific variables.

Dictionary format is expressed as 'key: value'

**Example**:

```
{
  jvm_high_heap_usage: 98
  logstash_pipeline_duration: 45m
}
```

```yaml
dalet_flex_metrics_alerting_thresholds_custom: {}
```

</div>
</details>


<details id="admonition-dalet_flex_metrics_excluded_services" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_metrics_excluded_services-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_metrics_excluded_services-title">

dalet_flex_metrics_excluded_services

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_metrics_excluded_services"></a>
</summary>
<div>

Defines a list of internal Flex services to be ignored from monitoring sub-system.

```yaml
dalet_flex_metrics_excluded_services: []
```

</div>
</details>


<details id="admonition-dalet_flex_metrics_retention_period" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_metrics_retention_period-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_metrics_retention_period-title">

dalet_flex_metrics_retention_period

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_metrics_retention_period"></a>
</summary>
<div>

Defines how-long should collected metrics be stored in local TSDB (TimeSeries database) storage.

Metrics older than specified threshold will be automatically pruned.

**WARNING**: Increasing retention period will lead to increased disk usage.

**Format**: **\<VALUE\>\<UNIT\>** where support units are: **y**, **w**, **d**, **h**, **m**, **s**, **ms**.

```yaml
dalet_flex_metrics_retention_period: 30d
```

</div>
</details>


<details id="admonition-dalet_flex_metrics_scrape_interval" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_metrics_scrape_interval-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_metrics_scrape_interval-title">

dalet_flex_metrics_scrape_interval

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_metrics_scrape_interval"></a>
</summary>
<div>

Defines frequency to poll from various system and application metrics.

Gathered metrics are to be considered as a snapshot of a given timeframe.

A long interval decreases resources consumption but might obfuscate events, leading to lesser observability.

A short interval improves accuracy while increasing resources consumption (disk, CPU, memory).

```yaml
dalet_flex_metrics_scrape_interval: 15s
```

</div>
</details>


<details id="admonition-dalet_flex_metrics_scrape_web_targets_custom" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_metrics_scrape_web_targets_custom-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_metrics_scrape_web_targets_custom-title">

dalet_flex_metrics_scrape_web_targets_custom

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_metrics_scrape_web_targets_custom"></a>
</summary>
<div>

Flex monitored Web targets default behavior can be tuned in, by overriding specific variables.

A Web target is defined as:

```yaml
  - name: string          # Target's name
    enabled: bool         # Define if the target should be monitored (defaults to true).
    url: string           # Optional, URL of the Web resource to be monitored
    kv: string            # Optional, key from service registry to retrieve URL from.
                          # At least one of 'url' or 'kv' field must be defined.
    url_path: string      # Optional: specific path to append the URL to be monitored.
    expect: string|int    # Optional: expected HTTP code(s) for monitor probe to consider successful.
                          # Must be either an integer (e.g. 200) or a pipe-separated string for multiple codes
                          # (e.g. '302|401'). Defaults to 2xx codes if unspecified.
```

```yaml
dalet_flex_metrics_scrape_web_targets_custom: []
```

When overriding values, specified list is merged with default one so that only parts to be overriden need to be specified, e.g:

```yaml
dalet_flex_metrics_scrape_web_targets_custom:
  - name: fmp
    enabled: false
```

</div>
</details>


<details id="admonition-dalet_flex_metrics_scrape_api_targets_custom" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_metrics_scrape_api_targets_custom-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_metrics_scrape_api_targets_custom-title">

dalet_flex_metrics_scrape_api_targets_custom

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_metrics_scrape_api_targets_custom"></a>
</summary>
<div>

Flex monitored API targets default behavior can be tuned in, by overriding specific variables.

An API target is defined as:

```yaml
  - name: string           # Target's name
    hostname: string       # Hostname of the server or service instance to perform API query from.
    enabled: bool          # Define if the target should be monitored (defaults to true).
    address: string        # IP address of the server instance to perform API query from.
    port: int              # Port of the service instance to perform API query from.
    url_path: string       # Specific API path to query from.
    jq: string             # Specific JSON post-process filtering (jq syntax) to apply to query result.
                           # See https://jqlang.org/ for specifications.
    headers: string        # Optional: HTTP headers to be added to API query (format: 'HEADER: VALUE').
    user: string           # Optional: user name to be used for API query.
    pass: string           # Optional: associated password to be used for API query.
```

```yaml
dalet_flex_metrics_scrape_api_targets_custom: []
```

When overriding values, specified list is merged with default one so that only parts to be overriden need to be specified, e.g:

```yaml
dalet_flex_metrics_scrape_api_targets_custom:
  - name: LongRunningJobs
    enabled: false
```

</div>
</details>


<details id="admonition-dalet_flex_metrics_grafana_admin_user" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_metrics_grafana_admin_user-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_metrics_grafana_admin_user-title">

dalet_flex_metrics_grafana_admin_user

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_metrics_grafana_admin_user"></a>
</summary>
<div>

Username for Grafana admin account (defaults to **admin**).

```yaml
dalet_flex_metrics_grafana_admin_user: admin
```

</div>
</details>


<details id="admonition-dalet_flex_metrics_grafana_admin_password" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_metrics_grafana_admin_password-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_metrics_grafana_admin_password-title">

dalet_flex_metrics_grafana_admin_password

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_metrics_grafana_admin_password"></a>
</summary>
<div>

Password for Grafana admin account.

**SENSITIVE**: It is highly recommended for password to be encrypted with Vault/SOPS.

Defaults to a vault-encrypted **vault\_dalet\_flex\_metrics\_grafana\_admin\_password** secret variable, if unspecified.

```yaml
dalet_flex_metrics_grafana_admin_password: ""
```

</div>
</details>


<details id="admonition-dalet_flex_metrics_grafana_extra_users" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_metrics_grafana_extra_users-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_metrics_grafana_extra_users-title">

dalet_flex_metrics_grafana_extra_users

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_metrics_grafana_extra_users"></a>
</summary>
<div>

Optional list of additional Grafana user accounts with **Viewer** (read/only) privileges, allowed to access metrics and dashboards.

Item format is:

```yaml
  - username: USER_NAME
    password: USER_PASSWORD
    email:    USER_EMAIL
```

```yaml
dalet_flex_metrics_grafana_extra_users: []
```

</div>
</details>


<details id="admonition-dalet_flex_metrics_grafana_okta_enabled" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_metrics_grafana_okta_enabled-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_metrics_grafana_okta_enabled-title">

dalet_flex_metrics_grafana_okta_enabled

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_metrics_grafana_okta_enabled"></a>
</summary>
<div>

Defines whether to use centralized Okta-based identity provider for users management instead of Grafana built-in user authentication base.

**WARNING**: Enabling OAuth 2.0 Okta login will disable default logging form.

```yaml
dalet_flex_metrics_grafana_okta_enabled: false
```

</div>
</details>


<details id="admonition-dalet_flex_metrics_grafana_okta_client_id" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_metrics_grafana_okta_client_id-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_metrics_grafana_okta_client_id-title">

dalet_flex_metrics_grafana_okta_client_id

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_metrics_grafana_okta_client_id"></a>
</summary>
<div>

Defines Okta client application identifier to connect to Grafana.

Please refer to your company's IT to register a new Okta application and gets credentials from.

```yaml
dalet_flex_metrics_grafana_okta_client_id: ''
```

</div>
</details>


<details id="admonition-dalet_flex_metrics_grafana_okta_client_secret" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_metrics_grafana_okta_client_secret-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_metrics_grafana_okta_client_secret-title">

dalet_flex_metrics_grafana_okta_client_secret

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_metrics_grafana_okta_client_secret"></a>
</summary>
<div>

Defines Okta client application secret to connect to Grafana.

Please refer to your company's IT to register a new Okta application and gets credentials from.

**SENSITIVE**: It is highly recommended for password to be encrypted with Vault/SOPS.

Defaults to a vault-encrypted **vault\_dalet\_flex\_metrics\_grafana\_okta\_client\_secret** secret variable, if unspecified.

```yaml
dalet_flex_metrics_grafana_okta_client_secret: ""
```

</div>
</details>


<details id="admonition-dalet_flex_metrics_grafana_okta_tenant_id" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_metrics_grafana_okta_tenant_id-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_metrics_grafana_okta_tenant_id-title">

dalet_flex_metrics_grafana_okta_tenant_id

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_metrics_grafana_okta_tenant_id"></a>
</summary>
<div>

Defines Okta tenant identifier to connect to Grafana.

Tenant identifier is usually something as **\<TENANT_ID\>.okta.com**.

```yaml
dalet_flex_metrics_grafana_okta_tenant_id: ''
```

</div>
</details>


<details id="admonition-dalet_flex_metrics_grafana_okta_allowed_domains" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_metrics_grafana_okta_allowed_domains-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_metrics_grafana_okta_allowed_domains-title">

dalet_flex_metrics_grafana_okta_allowed_domains

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_metrics_grafana_okta_allowed_domains"></a>
</summary>
<div>

Optional list of domain names (e.g. **acme.com**) which email addresses are allowed to log into Grafana.

```yaml
dalet_flex_metrics_grafana_okta_allowed_domains: []
```

</div>
</details>


<details id="admonition-dalet_flex_metrics_grafana_okta_allowed_groups" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_metrics_grafana_okta_allowed_groups-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_metrics_grafana_okta_allowed_groups-title">

dalet_flex_metrics_grafana_okta_allowed_groups

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_metrics_grafana_okta_allowed_groups"></a>
</summary>
<div>

Optional list of Okta user group with associated Grafana privileges.

If unspecified, all users will be restricted to **Viewer** (read/only) privilege.

**Example**:

```yaml
  - { id: OKTA_ADMINS_GROUP,   org_role: 'GrafanaAdmin'                   }
  - { id: OKTA_EDITORS_GROUP,  org_role: 'Editor'                         }
  - { id: OKTA_USERS_GROUP,    org_role: 'Viewer',         default: true  }
```

```yaml
dalet_flex_metrics_grafana_okta_allowed_groups: []
```

</div>
</details>


<details id="admonition-dalet_flex_metrics_grafana_email_enabled" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_metrics_grafana_email_enabled-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_metrics_grafana_email_enabled-title">

dalet_flex_metrics_grafana_email_enabled

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_metrics_grafana_email_enabled"></a>
</summary>
<div>

Defines whether Grafana is allowed to send email notifications to registered users.

```yaml
dalet_flex_metrics_grafana_email_enabled: false
```

</div>
</details>


<details id="admonition-dalet_flex_metrics_grafana_email_sender" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_metrics_grafana_email_sender-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_metrics_grafana_email_sender-title">

dalet_flex_metrics_grafana_email_sender

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_metrics_grafana_email_sender"></a>
</summary>
<div>

Defines the email address to be used to send Grafana email notifications from.

```yaml
dalet_flex_metrics_grafana_email_sender: "grafana@{{ dalet_flex_smtp_domain }}"
```

</div>
</details>


<details id="admonition-dalet_flex_metrics_grafana_anonymous_auth_enabled" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_metrics_grafana_anonymous_auth_enabled-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_metrics_grafana_anonymous_auth_enabled-title">

dalet_flex_metrics_grafana_anonymous_auth_enabled

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_metrics_grafana_anonymous_auth_enabled"></a>
</summary>
<div>

When true, we allow to share dashboards externally. Default is `false`

```yaml
dalet_flex_metrics_grafana_anonymous_auth_enabled: false
```

</div>
</details>


<details id="admonition-dalet_flex_metrics_grafana_email_sender-1" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_metrics_grafana_email_sender-1-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_metrics_grafana_email_sender-1-title">

dalet_flex_metrics_grafana_email_sender

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_metrics_grafana_email_sender-1"></a>
</summary>
<div>

When false, the HTTP header X-Frame-Options: deny is set in Grafana HTTP responses which instructs browsers to not allow rendering Grafana in a `iframe`

```yaml
dalet_flex_metrics_grafana_allow_embedding: false
```

</div>
</details>


<details id="admonition-dalet_flex_logs_retention_period" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_logs_retention_period-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_logs_retention_period-title">

dalet_flex_logs_retention_period

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_logs_retention_period"></a>
</summary>
<div>

Defines how-long should collected logs be stored in local ELK storage.

Logs older than specified threshold will be automatically pruned.

**WARNING**: Increasing retention period will lead to increased disk usage.

Format is expressed in DAYS.

```yaml
dalet_flex_logs_retention_period: 31
```

</div>
</details>


<details id="admonition-dalet_flex_logs_index_max_size" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_logs_index_max_size-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_logs_index_max_size-title">

dalet_flex_logs_index_max_size

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_logs_index_max_size"></a>
</summary>
<div>

Defines how big ELK log index can grow before rollover happens.

A rollover background operation allows ELK to create a new index, improving search results performance.

```yaml
dalet_flex_logs_index_max_size: 1gb
```

</div>
</details>


<details id="admonition-dalet_flex_logs_index_max_age" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_logs_index_max_age-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_logs_index_max_age-title">

dalet_flex_logs_index_max_age

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_logs_index_max_age"></a>
</summary>
<div>

Defines how old ELK log index can get before rollover happens.

A rollover background operation is triggered when max_size or max_age limits are hit, whicheer comes first.

Format is expressed in DAYS.

```yaml
dalet_flex_logs_index_max_age: 1
```

</div>
</details>


<details id="admonition-dalet_flex_logs_index_replica_count" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_logs_index_replica_count-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_logs_index_replica_count-title">

dalet_flex_logs_index_replica_count

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_logs_index_replica_count"></a>
</summary>
<div>

Defines how many times a given ELK index should be replicated (i.e. extra copied).

Only useful is ELK is configured as a cluster, where data retention and reliability is paramount.

Increasing value on a single-node cluster will only duplicates storage consumption.

Defaults to 0 (single copy).

```yaml
dalet_flex_logs_index_replica_count: 0
```

</div>
</details>


<details id="admonition-dalet_flex_logs_index_shard_count" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_logs_index_shard_count-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_logs_index_shard_count-title">

dalet_flex_logs_index_shard_count

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_logs_index_shard_count"></a>
</summary>
<div>

Defines how many shards (i.e. fragments) should be used for data indexing.

Increasing shards allows for wider data placement and improved search results performance by querying multiple servers.

Only useful if ELK is configured as a cluster. Useless on single-node instance.

Defaults to 1 (single shard).

```yaml
dalet_flex_logs_index_shard_count: 1
```

</div>
</details>


<details id="admonition-dalet_flex_logs_index_disk_watermark_low" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_logs_index_disk_watermark_low-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_logs_index_disk_watermark_low-title">

dalet_flex_logs_index_disk_watermark_low

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_logs_index_disk_watermark_low"></a>
</summary>
<div>

Defines ELK low disk watermark threshold.

ELK uses 3 distinct watermark stages (low, high, flood) related to local disk storage usage.

The disk-based shard allocator ensures that all nodes have enough disk space without performing more shard movements than necessary. Its primary goal is to ensure that no node exceeds the high watermark, or at least that any such overage is only temporary.

If a node exceeds the high watermark then ELK will solve this by moving some of its shards onto other nodes in the cluster.

Once this threshold is passed, the cluster will then block writing to all indexes that have one shard (primary or eplica) on the node which has passed the watermark. Reads (searches) will still be possible.

Remediation can happen by deleting old indexes, removing documents from existing indexes, reducing the number of replicas, increase disk space on all nodes or adding new nodes to the cluster.

**This setting should generally not be changed.**

```yaml
dalet_flex_logs_index_disk_watermark_low: 85%
```

</div>
</details>


<details id="admonition-dalet_flex_logs_index_disk_watermark_high" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_logs_index_disk_watermark_high-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_logs_index_disk_watermark_high-title">

dalet_flex_logs_index_disk_watermark_high

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_logs_index_disk_watermark_high"></a>
</summary>
<div>

Defines ELK low disk watermark threshold.

**This setting should generally not be changed.**

```yaml
dalet_flex_logs_index_disk_watermark_high: 90%
```

</div>
</details>


<details id="admonition-dalet_flex_logs_index_disk_watermark_flood" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_logs_index_disk_watermark_flood-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_logs_index_disk_watermark_flood-title">

dalet_flex_logs_index_disk_watermark_flood

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_logs_index_disk_watermark_flood"></a>
</summary>
<div>

Defines ELK low disk watermark threshold.

**This setting should generally not be changed.**

```yaml
dalet_flex_logs_index_disk_watermark_flood: 95%
```

</div>
</details>


<details id="admonition-dalet_flex_logs_memory_max_size" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_logs_memory_max_size-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_logs_memory_max_size-title">

dalet_flex_logs_memory_max_size

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_logs_memory_max_size"></a>
</summary>
<div>

Defines ELK maximum memory heap space (defaults: 2g).

**WARNING**: Minimum heap space is set to 2GB, max can't go below this value.

```yaml
dalet_flex_logs_memory_max_size: 2g
```

</div>
</details>


<details id="admonition-dalet_flex_logs_admin_user" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_logs_admin_user-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_logs_admin_user-title">

dalet_flex_logs_admin_user

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_logs_admin_user"></a>
</summary>
<div>

Username for ELK admin account (defaults to **admin**).

```yaml
dalet_flex_logs_admin_user: admin
```

</div>
</details>


<details id="admonition-dalet_flex_logs_admin_password" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_logs_admin_password-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_logs_admin_password-title">

dalet_flex_logs_admin_password

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_logs_admin_password"></a>
</summary>
<div>

Password for ELK admin account.

**SENSITIVE**: It is highly recommended for password to be encrypted with Vault/SOPS.

Defaults to a vault-encrypted **vault\_dalet\_flex\_logs\_admin\_password** secret variable, if unspecified.

```yaml
dalet_flex_logs_admin_password: ""
```

</div>
</details>


<details id="admonition-dalet_flex_logs_logstash_service_user" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_logs_logstash_service_user-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_logs_logstash_service_user-title">

dalet_flex_logs_logstash_service_user

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_logs_logstash_service_user"></a>
</summary>
<div>

Username for ELK logstash service account (defaults to **logstash**).

```yaml
dalet_flex_logs_logstash_service_user: logstash
```

</div>
</details>


<details id="admonition-dalet_flex_logs_logstash_service_password" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_logs_logstash_service_password-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_logs_logstash_service_password-title">

dalet_flex_logs_logstash_service_password

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_logs_logstash_service_password"></a>
</summary>
<div>

Password for ELK logstash service account.

**SENSITIVE**: It is highly recommended for password to be encrypted with Vault/SOPS.

Defaults to a vault-encrypted **vault\_dalet\_flex\_logs\_logstash\_service\_password** secret variable, if unspecified.

```yaml
dalet_flex_logs_logstash_service_password: ""
```

</div>
</details>


<details id="admonition-dalet_flex_logs_extra_users" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_logs_extra_users-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_logs_extra_users-title">

dalet_flex_logs_extra_users

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_logs_extra_users"></a>
</summary>
<div>

Optional list of additional ELK service/user accounts with read/only rights, allowed to access logs.

Item format is:

```yaml
  - username: USER_NAME
    password: USER_PASSWORD
```

```yaml
dalet_flex_logs_extra_users: []
```

</div>
</details>


<details id="admonition-dalet_flex_logs_satellite_nodes" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_logs_satellite_nodes-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_logs_satellite_nodes-title">

dalet_flex_logs_satellite_nodes

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_logs_satellite_nodes"></a>
</summary>
<div>

Optional list of ELK nodes from satellite sites (i.e. not main hub) to collect logs from.

**WARNING**: Hub pulls from satellite, remote nodes must be accessible from a network perspective.

Item format is:

```yaml
  - host: 10.20.30.40   # Elasticsearch host (port defaults to 9300)
    name: SITE_ID       # Free string, recommended to be satellite site_id for consistency.
```

```yaml
dalet_flex_logs_satellite_nodes: []
```

</div>
</details>


<details id="admonition-dalet_flex_alertmanager_web_external_url" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_alertmanager_web_external_url-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_alertmanager_web_external_url-title">

dalet_flex_alertmanager_web_external_url

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_alertmanager_web_external_url"></a>
</summary>
<div>

URL used to access AlertManager service externally
Defaults to `alertmanager_web_external_url_default`

Item format is:

```yaml
dalet_flex_alertmanager_web_external_url: ""
```

</div>
</details>


<details id="admonition-dalet_flex_grafana_web_external_url" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_grafana_web_external_url-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_grafana_web_external_url-title">

dalet_flex_grafana_web_external_url

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_grafana_web_external_url"></a>
</summary>
<div>

URL used to access Grafana service externally
Defaults to `grafana_web_external_url_default`

Item format is:

```yaml
dalet_flex_grafana_web_external_url: ""
```

</div>
</details>


<details id="admonition-dalet_flex_prometheus_web_external_url" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_prometheus_web_external_url-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_prometheus_web_external_url-title">

dalet_flex_prometheus_web_external_url

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_prometheus_web_external_url"></a>
</summary>
<div>

URL used to access Prometheus / VictoriaMetrics service externally
Defaults to `prometheus_web_external_url_default`

Item format is:
```yaml
dalet_flex_prometheus_web_external_url: ""
```

</div>
</details>


<details id="admonition-dalet_baseos_monitoring_remote_targets" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_baseos_monitoring_remote_targets-title">
<summary class="admonition-title">
<div id="admonition-dalet_baseos_monitoring_remote_targets-title">

dalet_baseos_monitoring_remote_targets

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_baseos_monitoring_remote_targets"></a>
</summary>
<div>

Optional list of additional remote targets for shipping metrics, used in the Alloy configuration.
Useful for satellite sites

Item format is:
```yaml
dalet_baseos_monitoring_remote_targets: []
```
**Example**
```yaml
dalet_baseos_monitoring_remote_targets:
  - name: hub
    enabled: true
    prometheus:
      endpoint: "http://10.10.10.10:8428"
      path: "/api/v1/write"
```

</div>
</details>

## Services


<details id="admonition-dalet_flex_services_enterprise_custom_base_dir" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_services_enterprise_custom_base_dir-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_services_enterprise_custom_base_dir-title">

dalet_flex_services_enterprise_custom_base_dir

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_services_enterprise_custom_base_dir"></a>
</summary>
<div>

Defines the host base directory from which storage, temp, and data subdirectories are derived and mounted into enterprise containers (master & job).

```yaml
dalet_flex_services_enterprise_custom_base_dir: ""
```

</div>
</details>


<details id="admonition-dalet_flex_services_openapi_doc_enabled" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_services_openapi_doc_enabled-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_services_openapi_doc_enabled-title">

dalet_flex_services_openapi_doc_enabled

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_services_openapi_doc_enabled"></a>
</summary>
<div>

Defines whether OpenAPI (Swagger) interactive documentation should be available.

Once enabled, each micro-service endpoint will feature an extra URI to browse (and execute) dynamic API calls.

```yaml
dalet_flex_services_openapi_doc_enabled: false
```

</div>
</details>


<details id="admonition-dalet_flex_services_springboot_jemalloc_enabled" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_services_springboot_jemalloc_enabled-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_services_springboot_jemalloc_enabled-title">

dalet_flex_services_springboot_jemalloc_enabled

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_services_springboot_jemalloc_enabled"></a>
</summary>
<div>

Defines if Jemalloc memory allocator should be used for Springboot-based services.

Enabling it will override any per-service custom configuration one could set in **dalet\_flex\_services\_custom** map.

```yaml
dalet_flex_services_springboot_jemalloc_enabled: false
```

</div>
</details>


<details id="admonition-dalet_flex_services_logging_enabled" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_services_logging_enabled-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_services_logging_enabled-title">

dalet_flex_services_logging_enabled

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_services_logging_enabled"></a>
</summary>
<div>

Defines whether logging Flex services output to file should be enabled (default behavior).

If unset, services output will be purely discarded.

```yaml
dalet_flex_services_logging_enabled: true
```

</div>
</details>


<details id="admonition-dalet_flex_services_secure_endpoints" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_services_secure_endpoints-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_services_secure_endpoints-title">

dalet_flex_services_secure_endpoints

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_services_secure_endpoints"></a>
</summary>
<div>

Defines whether Flex services endpoints are secured through JWT authentication.

This is default (and always recommended) behavior.

Disabling JWT authentication might be useful in some rare Pyramid <-> Flex integration uses-cases.

```yaml
dalet_flex_services_secure_endpoints: true
```

</div>
</details>


<details id="admonition-dalet_flex_services_custom" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_services_custom-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_services_custom-title">

dalet_flex_services_custom

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_services_custom"></a>
</summary>
<div>

Flex services default behavior can be tuned in, by overriding specific variables.

A given service is formatted as below:

```yaml
SERVICE_NAME:                  # string, used as service identifier
  type: TYPE                   # string, used for pre-defined service composition templating. One of:
                                 # custom:       Flex services requiring their own template (FSP, publish).
                                 # enterprise:   Master and Job enterprise services.
                                 # brio:         Brio scheduler services, next to Flex.
                                 # generic:      Generic Linux service.
                                 # nginx:        NGinx Proxy (warning: ports cannot be overriden).
                                 # nodejs:       Standard Flex services based on Node.JS.
                                 # springboot:   Standard Flex services based on Java SpringBoot.
                                 # oneshot:      One-time execution container. Not be considered as a remaining service.
                                 # system:       No templating. Only used to store system applications settings.
  group: string                # Ansible inventory group name where the service is meant to be deployed
  ports: DICT                  # A map of key/value ports definitions the service is binding
    KEY: PORT_NUMBER             # Key/Value portmap, e.g. api: 8080, metrics: 9000
  memory:                      # Service container memory limits, e.g. 1024m
  registry: string             # optional, URI to a service-specific registry to pull container image from
  volumes: ARRAY               # optional, list of extra volumes required to be mounted within runtime container
    - host_volume: string        # filesystem path on host to be mounted in service's container
      container_volume: string   # mount point in service's container to mount host volume to
  links: ARRAY(string)         # optional, list of container services to be linked together from network perspective
  heap:                        # optional (when applicable, e.g. Java services) - memory heap setting, e.g. 2g
  max_old_space:               # optional (when applicable, e.g. nodejs services) - memory max old space setting, e.g. 2 (in MB)
  jemalloc: bool               # optional, whether to use jemalloc memory allocator (default: false)
  loglevel: string             # optional, enforce service log level to a specific threshold (default: none)
  debug: bool                  # optional, whether to enable debugging information (default: false)
  environment: DICT            # optional, a map of environment variables to be passed to service container
    KEY: string                  # Key/Value environment variable name and value, e.g. HOME: /root
  args: string                 # optional, extra command line arguments to be passed to service container
  version: string              # optional, pinned container image version to override release's default
  lb:                          # optional, configuration settings when service is exposed through load-balancer
    hosts: ARRAY(string)       # optional, list of domain prefix to be used as matching ACL (e.g. SERVICE.acme.com)
    paths: ARRAY(string)       # optional, list of URL path to be used as matching ACL (e.g. /workflow/)
    healthcheck_path: string   # optional, URL path to specific endpoint to be queried by load-balancer for check
    http_check_code: int       # optional, expected backend HTTP code for healthchecks (defaults to 200)
    stickiness: bool           # optional, instruct load-balancer to use session cookies to alwasy route
                                 requests from a given client to the same backend (when healthy). Defaults to false.
```

```yaml
dalet_flex_services_custom: {}
```

When overriding values, specified dictionary is merged with default one so that only parts to be overriden need to be specified, e.g:

```yaml
dalet_flex_services_custom:
  flex-whatever-service:
    registry: acme.com/flex
    args: 'my own command-line'
```

</div>
</details>


<details id="admonition-dalet_flex_services_settings_custom" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_services_settings_custom-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_services_settings_custom-title">

dalet_flex_services_settings_custom

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_services_settings_custom"></a>
</summary>
<div>

Flex services configuration can be fully modified and/or extended by settings proper key/values.

Internal services rely on Consul service discovery features to retrieve their respective configuration at runtime.

It is possible to tune Flex's configuration per platform by setting custom properties.

A given service setting is formatted as below:

```yaml
  - key: "yet/another/key/name"  # Consul key, refer to Flex's documentation for list of available keys.
    value: VALUE                 # Free type string value.
    when: CONDITION              # optional (defaults to true).
```

If using file lookup to load content for custom KV from the environment **files/** directory, use the following notation:

```yaml
  - key: "...key"
    value:  "{{ lookup('file', flex_platform_dir ~ '/files/<file_name>') }}"
```

```yaml
dalet_flex_services_settings_custom: []
```

</div>
</details>


<details id="admonition-dalet_flex_services_discovery_endpoint" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_services_discovery_endpoint-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_services_discovery_endpoint-title">

dalet_flex_services_discovery_endpoint

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_services_discovery_endpoint"></a>
</summary>
<div>

Defines the public endpoint to reach Consul service discovery platform.

Endpoint can be either a public or private FQDN, as long as all hosts are capable to reach it.

It is highly recommended to use a DNS entry, providing resilient high-availability features.

If DNS is not supported or running on a single instance, this variable can be set ton Consul IP address instead.

```yaml
dalet_flex_services_discovery_endpoint: "consul.{{ dalet_flex_platform_private_fqdn }}"
```

</div>
</details>


<details id="admonition-dalet_flex_services_discovery_cluster_min_size" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_services_discovery_cluster_min_size-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_services_discovery_cluster_min_size-title">

dalet_flex_services_discovery_cluster_min_size

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_services_discovery_cluster_min_size"></a>
</summary>
<div>

Defines the minimum nodes members required to boostrap the Consul cluster.

Consul uses the Raft consensus protocol, requiring an odd number of participants.

Unless single-instance non highly-available setup is expected, it is recommended to set it to **3** (default).

```yaml
dalet_flex_services_discovery_cluster_min_size: 3
```

</div>
</details>


<details id="admonition-dalet_flex_services_discovery_dns_enabled" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_services_discovery_dns_enabled-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_services_discovery_dns_enabled-title">

dalet_flex_services_discovery_dns_enabled

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_services_discovery_dns_enabled"></a>
</summary>
<div>

Defines whether Consul should run as a DNS authoritative server.

Enabling Consul DNS allows you to look up for services and nodes registered with Consul using terminal commands instead of making HTTP API requests.

**WARNING**: Consul will bind port 53, make sure that your local systemd-resolved service is disabled.

```yaml
dalet_flex_services_discovery_dns_enabled: false
```

</div>
</details>


<details id="admonition-dalet_flex_services_discovery_dns_recursor" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_services_discovery_dns_recursor-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_services_discovery_dns_recursor-title">

dalet_flex_services_discovery_dns_recursor

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_services_discovery_dns_recursor"></a>
</summary>
<div>

Defines an upstream DNS recursor to forward DNS requests to.

Only useful if Consul DNS has been enabled through **dalet\_flex\_services\_discovery\_dns\_enabled** variable.

```yaml
dalet_flex_services_discovery_dns_recursor: "8.8.8.8"
```

</div>
</details>


<details id="admonition-dalet_flex_services_discovery_acl_token_master" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_services_discovery_acl_token_master-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_services_discovery_acl_token_master-title">

dalet_flex_services_discovery_acl_token_master

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_services_discovery_acl_token_master"></a>
</summary>
<div>

Flex Service Discovery features relies on Consul and uses Access Control List (ACL) to manage permissions.

Consul ACL relies on a secret token for authentication and authorization.

Defines the Consul ACL secret token for **master** identity (UUID format).

**SENSITIVE**: It is highly recommended for secrets to be encrypted with Vault/SOPS.

Defaults to a vault-encrypted **vault\_dalet\_flex\_services\_discovery\_acl\_token\_master** secret variable, if unspecified.

```yaml
dalet_flex_services_discovery_acl_token_master: ""
```

</div>
</details>


<details id="admonition-dalet_flex_services_discovery_acl_token_agent" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_services_discovery_acl_token_agent-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_services_discovery_acl_token_agent-title">

dalet_flex_services_discovery_acl_token_agent

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_services_discovery_acl_token_agent"></a>
</summary>
<div>

Defines the Consul ACL secret token for **agent** identity (UUID format).

**SENSITIVE**: It is highly recommended for secrets to be encrypted with Vault/SOPS.

Defaults to a vault-encrypted **vault\_dalet\_flex\_services\_discovery\_acl\_token\_agent** secret variable, if unspecified.

```yaml
dalet_flex_services_discovery_acl_token_agent: ""
```

</div>
</details>


<details id="admonition-dalet_flex_services_discovery_acl_token_dns" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_services_discovery_acl_token_dns-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_services_discovery_acl_token_dns-title">

dalet_flex_services_discovery_acl_token_dns

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_services_discovery_acl_token_dns"></a>
</summary>
<div>

Defines the Consul ACL secret token for **dns** identity (UUID format).

**SENSITIVE**: It is highly recommended for secrets to be encrypted with Vault/SOPS.

Defaults to a vault-encrypted **vault\_dalet\_flex\_services\_discovery\_acl\_token\_dns** secret variable, if unspecified.

```yaml
dalet_flex_services_discovery_acl_token_dns: ""
```

</div>
</details>


<details id="admonition-dalet_flex_services_discovery_acl_token_observability" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_services_discovery_acl_token_observability-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_services_discovery_acl_token_observability-title">

dalet_flex_services_discovery_acl_token_observability

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_services_discovery_acl_token_observability"></a>
</summary>
<div>

Defines the Consul ACL secret token for **monitoring** identity (UUID format).

**SENSITIVE**: It is highly recommended for secrets to be encrypted with Vault/SOPS.

Defaults to a vault-encrypted **vault\_dalet\_flex\_services\_discovery\_acl\_token\_observability** secret variable, if unspecified.

```yaml
dalet_flex_services_discovery_acl_token_observability: ""
```

</div>
</details>


<details id="admonition-dalet_flex_services_discovery_acl_token_services" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_services_discovery_acl_token_services-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_services_discovery_acl_token_services-title">

dalet_flex_services_discovery_acl_token_services

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_services_discovery_acl_token_services"></a>
</summary>
<div>

Defines the Consul ACL secret token for **services** identity (UUID format).

**SENSITIVE**: It is highly recommended for secrets to be encrypted with Vault/SOPS.

Defaults to a vault-encrypted **vault\_dalet\_flex\_services\_discovery\_acl\_token\_services** secret variable, if unspecified.

```yaml
dalet_flex_services_discovery_acl_token_services: ""
```

</div>
</details>


<details id="admonition-dalet_flex_services_discovery_acl_token_readonly" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_services_discovery_acl_token_readonly-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_services_discovery_acl_token_readonly-title">

dalet_flex_services_discovery_acl_token_readonly

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_services_discovery_acl_token_readonly"></a>
</summary>
<div>

Defines the Consul ACL secret token for **readonly** identity (UUID format).

**SENSITIVE**: It is highly recommended for secrets to be encrypted with Vault/SOPS.

Defaults to a vault-encrypted **vault\_dalet\_flex\_services\_discovery\_acl\_token\_readonly** secret variable, if unspecified.

```yaml
dalet_flex_services_discovery_acl_token_readonly: ""
```

</div>
</details>


<details id="admonition-dalet_flex_services_discovery_acl_token_brio" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_services_discovery_acl_token_brio-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_services_discovery_acl_token_brio-title">

dalet_flex_services_discovery_acl_token_brio

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_services_discovery_acl_token_brio"></a>
</summary>
<div>

Defines the Consul ACL secret token for **brio** identity (UUID format).

**SENSITIVE**: It is highly recommended for secrets to be encrypted with Vault/SOPS.

Defaults to a vault-encrypted **vault\_dalet\_flex\_services\_discovery\_acl\_token\_brio** secret variable, if unspecified.

```yaml
dalet_flex_services_discovery_acl_token_brio: ""
```

</div>
</details>


<details id="admonition-dalet_flex_services_ftp_user" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_services_ftp_user-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_services_ftp_user-title">

dalet_flex_services_ftp_user

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_services_ftp_user"></a>
</summary>
<div>

Username for FTP service account (defaults to **ftpadmin**), when enabled.

```yaml
dalet_flex_services_ftp_user: ftpadmin
```

</div>
</details>


<details id="admonition-dalet_flex_services_ftp_password" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_services_ftp_password-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_services_ftp_password-title">

dalet_flex_services_ftp_password

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_services_ftp_password"></a>
</summary>
<div>

Password for FTP service account, when enabled.

**SENSITIVE**: It is highly recommended for password to be encrypted with Vault/SOPS.

Defaults to a vault-encrypted **vault\_dalet\_flex\_services\_ftp\_password** secret variable, if unspecified.

```yaml
dalet_flex_services_ftp_password: ""
```

</div>
</details>


<details id="admonition-dalet_flex_services_fsp_host_instance_count" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_services_fsp_host_instance_count-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_services_fsp_host_instance_count-title">

dalet_flex_services_fsp_host_instance_count

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_services_fsp_host_instance_count"></a>
</summary>
<div>

Defines how many instances of Flex Stream Processor (FSP) service are to be executed on a given host.

The more instances, the faster one host can process jobs, unless oversized.

Must be adapted based on hardware characteristics and horsepower.

```yaml
dalet_flex_services_fsp_host_instance_count: 1
```

</div>
</details>


<details id="admonition-dalet_flex_services_fsp_host_instance_concurrent_job_count" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_services_fsp_host_instance_concurrent_job_count-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_services_fsp_host_instance_concurrent_job_count-title">

dalet_flex_services_fsp_host_instance_concurrent_job_count

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_services_fsp_host_instance_concurrent_job_count"></a>
</summary>
<div>

Defines how many concurrent jobs each instance of Flex Stream Processor (FSP) service can handle simultaneously.

This value sets a global value for all type of FSP jobs.

Per-job value can be tuned in by appropriately setting values of **flex/flex-streamprocessor-service/*JobConcurrency** keys through **dalet\_flex\_services\_settings\_custom** variable.

```yaml
dalet_flex_services_fsp_host_instance_concurrent_job_count: 1
```

</div>
</details>


<details id="admonition-dalet_flex_services_fsp_host_cpu_affinity_enabled" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_services_fsp_host_cpu_affinity_enabled-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_services_fsp_host_cpu_affinity_enabled-title">

dalet_flex_services_fsp_host_cpu_affinity_enabled

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_services_fsp_host_cpu_affinity_enabled"></a>
</summary>
<div>

Defines whether CPU (cores) affinity should be enabled for Flex Stream Processor (FSP) instances.

Enabling CPU affinity ensures that a given FSP instance is being dedicated to a given CPU core, preventing kernel processes context-switches and maximizing performances.

The drawback is that reserved CPU cores can't be used by any other FSP instance, should some be idle.

```yaml
dalet_flex_services_fsp_host_cpu_affinity_enabled: false
```

</div>
</details>


<details id="admonition-dalet_flex_services_fsp_host_cpu_affinity_count" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_services_fsp_host_cpu_affinity_count-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_services_fsp_host_cpu_affinity_count-title">

dalet_flex_services_fsp_host_cpu_affinity_count

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_services_fsp_host_cpu_affinity_count"></a>
</summary>
<div>

Defines the maximum number of cores/threads that should be reserved for FSP services CPU affinity pinning.

Value is bounded by number of host's vCPUs (usually means count of hyper-threaded cores).

```yaml
dalet_flex_services_fsp_host_cpu_affinity_count: 0
```

</div>
</details>


<details id="admonition-dalet_flex_services_fsp_host_cpu_affinity_first" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_services_fsp_host_cpu_affinity_first-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_services_fsp_host_cpu_affinity_first-title">

dalet_flex_services_fsp_host_cpu_affinity_first

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_services_fsp_host_cpu_affinity_first"></a>
</summary>
<div>

Defines the core/thread identifying number to be used to start FSP services CPU affinity reservation from.

A value of **0** (default), implies using all possible hardware cores/threads resources.

In some cases, it might be advisable to start for second core/thread (i.e. 1), so that first core (0) remain used for all operating system's other processes.

```yaml
dalet_flex_services_fsp_host_cpu_affinity_first: 0
```

</div>
</details>


<details id="admonition-dalet_flex_services_fsp_host_volumes" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_services_fsp_host_volumes-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_services_fsp_host_volumes-title">

dalet_flex_services_fsp_host_volumes

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_services_fsp_host_volumes"></a>
</summary>
<div>

Optional list of extra volumes for Flex Stream Processor (FSP) service's container.

A local host volume would be consequently mapped/mounted into local container instance.

Volume format is defined as:

```yaml
  - host_volume: '/my/host/dir'
    container_volume: '/my/container/dir'
```

```yaml
dalet_flex_services_fsp_host_volumes: []
```

</div>
</details>


<details id="admonition-dalet_flex_services_ffp_host_volumes" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_services_ffp_host_volumes-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_services_ffp_host_volumes-title">

dalet_flex_services_ffp_host_volumes

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_services_ffp_host_volumes"></a>
</summary>
<div>

Optional list of extra volumes for Flex File Processor (FFP) service's container.

A local host volume would be consequently mapped/mounted into local container instance.

Volume format is defined as:

```yaml
  - host_volume: '/my/host/dir'
    container_volume: '/my/container/dir'
```

```yaml
dalet_flex_services_ffp_host_volumes: []
```

</div>
</details>


<details id="admonition-dalet_flex_services_master_host_volumes" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_services_master_host_volumes-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_services_master_host_volumes-title">

dalet_flex_services_master_host_volumes

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_services_master_host_volumes"></a>
</summary>
<div>

Optional list of extra volumes for Flex Master service's container.

A local host volume would be consequently mapped/mounted into local container instance.

Volume format is defined as:

```yaml
  - host_volume: '/my/host/dir'
    container_volume: '/my/container/dir'
```

```yaml
dalet_flex_services_master_host_volumes: []
```

</div>
</details>


<details id="admonition-dalet_flex_services_job_host_volumes" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_services_job_host_volumes-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_services_job_host_volumes-title">

dalet_flex_services_job_host_volumes

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_services_job_host_volumes"></a>
</summary>
<div>

Optional list of extra volumes for Flex Job service's container.

A local host volume would be consequently mapped/mounted into local container instance.

Volume format is defined as:

```yaml
  - host_volume: '/my/host/dir'
    container_volume: '/my/container/dir'
```

```yaml
dalet_flex_services_job_host_volumes: []
```

</div>
</details>


<details id="admonition-dalet_flex_services_publish_indexer_host_volumes" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_services_publish_indexer_host_volumes-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_services_publish_indexer_host_volumes-title">

dalet_flex_services_publish_indexer_host_volumes

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_services_publish_indexer_host_volumes"></a>
</summary>
<div>

Optional list of extra volumes for Flex Publish Indexer service's container.

A local host volume would be consequently mapped/mounted into local container instance.

Volume format is defined as:

```yaml
  - host_volume: '/my/host/dir'
    container_volume: '/my/container/dir'
```

```yaml
dalet_flex_services_publish_indexer_host_volumes: []
```

</div>
</details>


<details id="admonition-dalet_flex_services_video_proxy_host_volumes" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_services_video_proxy_host_volumes-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_services_video_proxy_host_volumes-title">

dalet_flex_services_video_proxy_host_volumes

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_services_video_proxy_host_volumes"></a>
</summary>
<div>

Optional list of extra volumes for Flex Video Proxy service's container.

A local host volume would be consequently mapped/mounted into local container instance.

Volume format is defined as:

```yaml
  - host_volume: '/my/host/dir'
    container_volume: '/my/container/dir'
```

```yaml
dalet_flex_services_video_proxy_host_volumes: []
```

</div>
</details>


<details id="admonition-dalet_flex_services_image_proxy_host_volumes" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_services_image_proxy_host_volumes-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_services_image_proxy_host_volumes-title">

dalet_flex_services_image_proxy_host_volumes

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_services_image_proxy_host_volumes"></a>
</summary>
<div>

Optional list of extra volumes for Flex Image Proxy service's container.

A local host volume would be consequently mapped/mounted into local container instance.

Volume format is defined as:

```yaml
  - host_volume: '/my/host/dir'
    container_volume: '/my/container/dir'
```

```yaml
dalet_flex_services_image_proxy_host_volumes: []
```

</div>
</details>


<details id="admonition-dalet_flex_services_jobasyncexecutor_host_volumes" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_services_jobasyncexecutor_host_volumes-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_services_jobasyncexecutor_host_volumes-title">

dalet_flex_services_jobasyncexecutor_host_volumes

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_services_jobasyncexecutor_host_volumes"></a>
</summary>
<div>

Optional list of extra volumes for Flex Job Asynchronous Executor service's container.

A local host volume would be consequently mapped/mounted into local container instance.

Volume format is defined as:

```yaml
  - host_volume: '/my/host/dir'
    container_volume: '/my/container/dir'
```

```yaml
dalet_flex_services_jobasyncexecutor_host_volumes: []
```

</div>
</details>


<details id="admonition-dalet_flex_services_webtransfer_host_volumes" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_services_webtransfer_host_volumes-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_services_webtransfer_host_volumes-title">

dalet_flex_services_webtransfer_host_volumes

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_services_webtransfer_host_volumes"></a>
</summary>
<div>

Optional list of extra volumes for Flex Web Transfer service's container.

A local host volume would be consequently mapped/mounted into local container instance.

Volume format is defined as:

```yaml
  - host_volume: '/my/host/dir'
    container_volume: '/my/container/dir'
```

```yaml
dalet_flex_services_webtransfer_host_volumes: []
```

</div>
</details>


<details id="admonition-dalet_flex_services_fileaccess_host_volumes" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_services_fileaccess_host_volumes-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_services_fileaccess_host_volumes-title">

dalet_flex_services_fileaccess_host_volumes

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_services_fileaccess_host_volumes"></a>
</summary>
<div>

Optional list of extra volumes for Flex File Access service's container.

A local host volume would be consequently mapped/mounted into local container instance.

Volume format is defined as:

```yaml
  - host_volume: '/my/host/dir'
    container_volume: '/my/container/dir'
```

```yaml
dalet_flex_services_fileaccess_host_volumes: []
```

</div>
</details>


<details id="admonition-dalet_flex_services_hotfolder_host_volumes" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_services_hotfolder_host_volumes-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_services_hotfolder_host_volumes-title">

dalet_flex_services_hotfolder_host_volumes

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_services_hotfolder_host_volumes"></a>
</summary>
<div>

Optional list of extra volumes for Flex Hot Folder service's container.

A local host volume would be consequently mapped/mounted into local container instance.

Volume format is defined as:

```yaml
  - host_volume: '/my/host/dir'
    container_volume: '/my/container/dir'
```

```yaml
dalet_flex_services_hotfolder_host_volumes: []
```

</div>
</details>


<details id="admonition-dalet_flex_services_publish_host_volumes" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_services_publish_host_volumes-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_services_publish_host_volumes-title">

dalet_flex_services_publish_host_volumes

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_services_publish_host_volumes"></a>
</summary>
<div>

Optional list of extra volumes for Flex Publish service's container.

A local host volume would be consequently mapped/mounted into local container instance.

Volume format is defined as:

```yaml
  - host_volume: '/my/host/dir'
    container_volume: '/my/container/dir'
```

```yaml
dalet_flex_services_publish_host_volumes: []
```

</div>
</details>


<details id="admonition-dalet_flex_services_custom_ca_certs" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_services_custom_ca_certs-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_services_custom_ca_certs-title">

dalet_flex_services_custom_ca_certs

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_services_custom_ca_certs"></a>
</summary>
<div>

Optional certificate file(s) to mount into the Flex service container

Can be a single file path or list of file paths

Files are mounted to the container's `/flex/certificate` directory

```yaml
dalet_flex_services_custom_ca_certs: []
```

</div>
</details>


<details id="admonition-dalet_flex_services_packaging_enabled" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_services_packaging_enabled-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_services_packaging_enabled-title">

dalet_flex_services_packaging_enabled

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_services_packaging_enabled"></a>
</summary>
<div>

Allows enabling Flex solution package deployment.

```yaml
dalet_flex_services_packaging_enabled: false
```

</div>
</details>

## Brio Scheduler Settings


<details id="admonition-dalet_flex_brio_enabled" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_brio_enabled-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_brio_enabled-title">

dalet_flex_brio_enabled

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_brio_enabled"></a>
</summary>
<div>

Defines whether Brio Ingest Scheduler should be deployed next to Flex services.

```yaml
dalet_flex_brio_enabled: false
```

</div>
</details>


<details id="admonition-dalet_flex_brio_gateway_fqdn" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_brio_gateway_fqdn-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_brio_gateway_fqdn-title">

dalet_flex_brio_gateway_fqdn

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_brio_gateway_fqdn"></a>
</summary>
<div>

Defines the public endpoint to reach Brio Flex Gateway.

Endpoint can be either a public or private FQDN, as long as all hosts are capable to reach it.

```yaml
dalet_flex_brio_gateway_fqdn: "brio.{{ dalet_flex_platform_public_fqdn }}"
```

</div>
</details>


<details id="admonition-dalet_flex_brio_gateway_variant_type" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_brio_gateway_variant_type-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_brio_gateway_variant_type-title">

dalet_flex_brio_gateway_variant_type

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_brio_gateway_variant_type"></a>
</summary>
<div>

Defines the Brio Flex Gateway variant type.

Free string, as configured in Flex (usually something like **Live**, **Media**, **Video** ...)

```yaml
dalet_flex_brio_gateway_variant_type: Video
```

</div>
</details>


<details id="admonition-dalet_flex_brio_gateway_deletion_action_id" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_brio_gateway_deletion_action_id-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_brio_gateway_deletion_action_id-title">

dalet_flex_brio_gateway_deletion_action_id

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_brio_gateway_deletion_action_id"></a>
</summary>
<div>

Defines the Brio Flex Gateway deletion action identifier.

Integer value, as configured in Flex.

```yaml
dalet_flex_brio_gateway_deletion_action_id: 0
```

</div>
</details>


<details id="admonition-dalet_flex_brio_gateway_user" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_brio_gateway_user-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_brio_gateway_user-title">

dalet_flex_brio_gateway_user

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_brio_gateway_user"></a>
</summary>
<div>

Username for Brio Flex Gateway service account.

```yaml
dalet_flex_brio_gateway_user: ""
```

</div>
</details>


<details id="admonition-dalet_flex_brio_gateway_password" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_brio_gateway_password-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_brio_gateway_password-title">

dalet_flex_brio_gateway_password

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_brio_gateway_password"></a>
</summary>
<div>

Password for Brio Flex Gateway service account.

**SENSITIVE**: It is highly recommended for password to be encrypted with Vault/SOPS.

Defaults to a vault-encrypted **vault\_dalet\_flex\_brio\_gateway\_password** secret variable, if unspecified.

```yaml
dalet_flex_brio_gateway_password: ""
```

</div>
</details>


<details id="admonition-dalet_flex_brio_gateway_account_id" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_brio_gateway_account_id-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_brio_gateway_account_id-title">

dalet_flex_brio_gateway_account_id

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_brio_gateway_account_id"></a>
</summary>
<div>

Defines the Brio Flex Gateway account identifier.

Integer value, as configured in Flex.

```yaml
dalet_flex_brio_gateway_account_id: 0
```

</div>
</details>


<details id="admonition-dalet_flex_brio_gateway_job_queue" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_brio_gateway_job_queue-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_brio_gateway_job_queue-title">

dalet_flex_brio_gateway_job_queue

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_brio_gateway_job_queue"></a>
</summary>
<div>

Defines the Brio Flex Gateway job queue name.

Free string, as configured in Flex (defaults to **Brio4Jobs**).

```yaml
dalet_flex_brio_gateway_job_queue: Brio4Jobs
```

</div>
</details>


<details id="admonition-dalet_flex_brio_gateway_allow_unsecure" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_brio_gateway_allow_unsecure-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_brio_gateway_allow_unsecure-title">

dalet_flex_brio_gateway_allow_unsecure

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_brio_gateway_allow_unsecure"></a>
</summary>
<div>

Defines if Brio Flex Gateway should bypass TLS verification (i.e. no certificate validation).

**WARNING**: Should not be enabled unless understanding the risks.

```yaml
dalet_flex_brio_gateway_allow_unsecure: false
```

</div>
</details>


<details id="admonition-dalet_flex_brio_psql_host" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_brio_psql_host-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_brio_psql_host-title">

dalet_flex_brio_psql_host

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_brio_psql_host"></a>
</summary>
<div>

Defines Brio PostgreSQL server endpoint.

Can be either an FQDN for DBaaS (such as AWS RDS) or an IP address (virtual IP in master/slave replication mode).

```yaml
dalet_flex_brio_psql_host: ""
```

</div>
</details>


<details id="admonition-dalet_flex_brio_psql_port" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_brio_psql_port-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_brio_psql_port-title">

dalet_flex_brio_psql_port

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_brio_psql_port"></a>
</summary>
<div>

Port for Brio PostgreSQL server endpoint (defaults to standard **5432**).

```yaml
dalet_flex_brio_psql_port: 5432
```

</div>
</details>


<details id="admonition-dalet_flex_brio_psql_admin_user" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_brio_psql_admin_user-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_brio_psql_admin_user-title">

dalet_flex_brio_psql_admin_user

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_brio_psql_admin_user"></a>
</summary>
<div>

Username for Brio PostgreSQL admin account (defaults to **postgres**).

```yaml
dalet_flex_brio_psql_admin_user: postgres
```

</div>
</details>


<details id="admonition-dalet_flex_brio_psql_admin_password" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_brio_psql_admin_password-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_brio_psql_admin_password-title">

dalet_flex_brio_psql_admin_password

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_brio_psql_admin_password"></a>
</summary>
<div>

Password for Brio PostgreSQL admin account.

**SENSITIVE**: It is highly recommended for password to be encrypted with Vault/SOPS.

Defaults to a vault-encrypted **vault\_dalet\_flex\_brio\_psql\_admin\_password** secret variable, if unspecified.

```yaml
dalet_flex_brio_psql_admin_password: ""
```

</div>
</details>

## GPU Enablement Settings


<details id="admonition-dalet_flex_gpu_enabled" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_gpu_enabled-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_gpu_enabled-title">

dalet_flex_gpu_enabled

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_gpu_enabled"></a>
</summary>
<div>

Defines whether GPU usage is enabled for `dalet-ai-service` and triggers docker-compose templating

Enabling GPU requires a maintenance window and execution of infra playbook with `drivers` tag

```yaml
dalet_flex_gpu_enabled: false
```

</div>
</details>

## Usage Metering


<details id="admonition-dalet_flex_usage_metering_enabled" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_usage_metering_enabled-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_usage_metering_enabled-title">

dalet_flex_usage_metering_enabled

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_usage_metering_enabled"></a>
</summary>
<div>

Defines whether Flex usage tracker and metering sub-system should be enabled.

Metering is used to compute business analytical and statistical reports on resources and storage usage.

```yaml
dalet_flex_usage_metering_enabled: false
```

</div>
</details>


<details id="admonition-dalet_flex_usage_metering_cron_schedule" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_usage_metering_cron_schedule-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_usage_metering_cron_schedule-title">

dalet_flex_usage_metering_cron_schedule

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_usage_metering_cron_schedule"></a>
</summary>
<div>

Define the local metering probe running frequency (cron format).

Track records are pushed to Dalet Cloud-based metering system.

```yaml
dalet_flex_usage_metering_cron_schedule: "30 6 * * *"
```

</div>
</details>


<details id="admonition-dalet_flex_usage_metering_tenant_id" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_usage_metering_tenant_id-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_usage_metering_tenant_id-title">

dalet_flex_usage_metering_tenant_id

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_usage_metering_tenant_id"></a>
</summary>
<div>

Defines the metering sub-system Unique tenant identifier.

```yaml
dalet_flex_usage_metering_tenant_id: 1000
```

</div>
</details>


<details id="admonition-dalet_flex_usage_metering_mysql_host" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_usage_metering_mysql_host-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_usage_metering_mysql_host-title">

dalet_flex_usage_metering_mysql_host

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_usage_metering_mysql_host"></a>
</summary>
<div>

Defines usage metering MySQL server endpoint.

Can be either an FQDN for DBaaS (such as AWS RDS) or an IP address (virtual IP in master/slave replication mode).

**WARNING**: The associated host requires being publicly exposed, as to be accessible by Tableau Cloud instance.

```yaml
dalet_flex_usage_metering_mysql_host: ""
```

</div>
</details>


<details id="admonition-dalet_flex_usage_metering_mysql_port" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_usage_metering_mysql_port-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_usage_metering_mysql_port-title">

dalet_flex_usage_metering_mysql_port

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_usage_metering_mysql_port"></a>
</summary>
<div>

Port for usage metering MySQL server endpoint (defaults to standard **3306**).

```yaml
dalet_flex_usage_metering_mysql_port: 3306
```

</div>
</details>


<details id="admonition-dalet_flex_usage_metering_mysql_admin_user" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_usage_metering_mysql_admin_user-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_usage_metering_mysql_admin_user-title">

dalet_flex_usage_metering_mysql_admin_user

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_usage_metering_mysql_admin_user"></a>
</summary>
<div>

Username for usage metering MySQL admin account (defaults to **root**).

```yaml
dalet_flex_usage_metering_mysql_admin_user: root
```

</div>
</details>


<details id="admonition-dalet_flex_usage_metering_mysql_admin_password" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_usage_metering_mysql_admin_password-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_usage_metering_mysql_admin_password-title">

dalet_flex_usage_metering_mysql_admin_password

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_usage_metering_mysql_admin_password"></a>
</summary>
<div>

Password for usage metering MySQL admin account.

**SENSITIVE**: It is highly recommended for password to be encrypted with Vault/SOPS.

Defaults to a vault-encrypted **vault\_dalet\_flex\_usage\_metering\_mysql\_admin\_password** secret variable, if unspecified.

```yaml
dalet_flex_usage_metering_mysql_admin_password: ""
```

</div>
</details>


<details id="admonition-dalet_flex_usage_metering_mysql_service_rw_user" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_usage_metering_mysql_service_rw_user-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_usage_metering_mysql_service_rw_user-title">

dalet_flex_usage_metering_mysql_service_rw_user

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_usage_metering_mysql_service_rw_user"></a>
</summary>
<div>

Username for usage metering MySQL R/W service account (defaults to **flextableaupublisher**).

```yaml
dalet_flex_usage_metering_mysql_service_rw_user: flextableaupublisher
```

</div>
</details>


<details id="admonition-dalet_flex_usage_metering_mysql_service_rw_password" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_usage_metering_mysql_service_rw_password-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_usage_metering_mysql_service_rw_password-title">

dalet_flex_usage_metering_mysql_service_rw_password

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_usage_metering_mysql_service_rw_password"></a>
</summary>
<div>

Password for usage metering MySQL R/W service account.

**SENSITIVE**: It is highly recommended for password to be encrypted with Vault/SOPS.

Defaults to a vault-encrypted **vault\_dalet\_flex\_usage\_metering\_mysql\_service\_rw\_password** secret variable, if unspecified.

```yaml
dalet_flex_usage_metering_mysql_service_rw_password: ""
```

</div>
</details>


<details id="admonition-dalet_flex_usage_metering_mysql_service_ro_user" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_usage_metering_mysql_service_ro_user-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_usage_metering_mysql_service_ro_user-title">

dalet_flex_usage_metering_mysql_service_ro_user

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_usage_metering_mysql_service_ro_user"></a>
</summary>
<div>

Username for usage metering MySQL R/O service account (defaults to **flextableaucloud**).

```yaml
dalet_flex_usage_metering_mysql_service_ro_user: flextableaucloud
```

</div>
</details>


<details id="admonition-dalet_flex_usage_metering_mysql_service_ro_password" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_usage_metering_mysql_service_ro_password-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_usage_metering_mysql_service_ro_password-title">

dalet_flex_usage_metering_mysql_service_ro_password

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_usage_metering_mysql_service_ro_password"></a>
</summary>
<div>

Password for usage metering MySQL R/O service account.

**SENSITIVE**: It is highly recommended for password to be encrypted with Vault/SOPS.

Defaults to a vault-encrypted **vault\_dalet\_flex\_usage\_metering\_mysql\_service\_ro\_password** secret variable, if unspecified.

```yaml
dalet_flex_usage_metering_mysql_service_ro_password: ""
```

</div>
</details>

## Operations


<details id="admonition-dalet_flex_ops_assertions_enabled" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_ops_assertions_enabled-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_ops_assertions_enabled-title">

dalet_flex_ops_assertions_enabled

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_ops_assertions_enabled"></a>
</summary>
<div>

Enable deployment assertions checks.

Assertions checks adds additional execution time but ensure properly set and defined settings, leading to a consistent platform deployment.

**WARNING**: Should not be disabled unless understanding the risks.

```yaml
dalet_flex_ops_assertions_enabled: true
```

</div>
</details>


<details id="admonition-dalet_flex_ops_services_healthcheck_enabled" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_ops_services_healthcheck_enabled-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_ops_services_healthcheck_enabled-title">

dalet_flex_ops_services_healthcheck_enabled

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_ops_services_healthcheck_enabled"></a>
</summary>
<div>

Enable post-deployment services healthchecks.

This ensure all expected services are running and alive, for Flex system to be fully operational.

Disabling this option speeds up deployment and can be useful for deployment debugging purposes where system's liveness is optional.

**WARNING**: Should not be disabled unless understanding the risks.

```yaml
dalet_flex_ops_services_healthcheck_enabled: true
```

</div>
</details>


<details id="admonition-dalet_flex_ops_services_healthcheck_retries" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_ops_services_healthcheck_retries-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_ops_services_healthcheck_retries-title">

dalet_flex_ops_services_healthcheck_retries

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_ops_services_healthcheck_retries"></a>
</summary>
<div>

Defines how many healthcheck occurences we should apply before considering services as down.

```yaml
dalet_flex_ops_services_healthcheck_retries: 60
```

</div>
</details>


<details id="admonition-dalet_flex_ops_services_healthcheck_delay" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_ops_services_healthcheck_delay-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_ops_services_healthcheck_delay-title">

dalet_flex_ops_services_healthcheck_delay

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_ops_services_healthcheck_delay"></a>
</summary>
<div>

Defines how long to wait (seconds) between 2 healthcheck tries.

```yaml
dalet_flex_ops_services_healthcheck_delay: 5
```

</div>
</details>


<details id="admonition-dalet_flex_ops_ssl_certificates_check_enabled" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_ops_ssl_certificates_check_enabled-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_ops_ssl_certificates_check_enabled-title">

dalet_flex_ops_ssl_certificates_check_enabled

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_ops_ssl_certificates_check_enabled"></a>
</summary>
<div>

Enable SSL certificate verification on Flex public endpoint.

Should be disabled if Flex is exposed via self-signed or private-CA-signed SSL certificate.

```yaml
dalet_flex_ops_ssl_certificates_check_enabled: true
```

</div>
</details>


<details id="admonition-dalet_flex_ops_compose_template_backup_enabled" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_ops_compose_template_backup_enabled-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_ops_compose_template_backup_enabled-title">

dalet_flex_ops_compose_template_backup_enabled

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_ops_compose_template_backup_enabled"></a>
</summary>
<div>

Defines whether to keep backup of docker-compose files when changes are applied.

```yaml
dalet_flex_ops_compose_template_backup_enabled: true
```

</div>
</details>


<details id="admonition-dalet_flex_ops_container_lifecycle_automatic_restart_enabled" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_ops_container_lifecycle_automatic_restart_enabled-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_ops_container_lifecycle_automatic_restart_enabled-title">

dalet_flex_ops_container_lifecycle_automatic_restart_enabled

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_ops_container_lifecycle_automatic_restart_enabled"></a>
</summary>
<div>

Defines containerized services lifecycle policy.

By default (**true**), all containers are automatically restarted in case of accidental shutdown or failure.

Turning it off prevents automatic (or on-boot) restart sequence, mostly for troubleshooting purposes.

**WARNING**: Should not be disabled unless understanding the risks.

```yaml
dalet_flex_ops_container_lifecycle_automatic_restart_enabled: true
```

</div>
</details>


<details id="admonition-dalet_flex_ops_container_lifecycle_stop_grace_period" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_ops_container_lifecycle_stop_grace_period-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_ops_container_lifecycle_stop_grace_period-title">

dalet_flex_ops_container_lifecycle_stop_grace_period

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_ops_container_lifecycle_stop_grace_period"></a>
</summary>
<div>

Defines containerized services default stop grace period.

This value provides containers the necessary time to gracefully shutdown instead of being instantly killed.

```yaml
dalet_flex_ops_container_lifecycle_stop_grace_period: 60s
```

</div>
</details>


<details id="admonition-dalet_flex_ops_container_network_bridge_enabled" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_ops_container_network_bridge_enabled-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_ops_container_network_bridge_enabled-title">

dalet_flex_ops_container_network_bridge_enabled

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_ops_container_network_bridge_enabled"></a>
</summary>
<div>

Defines whether containerized services should be able to communicate with each other through a shared bridged network segment (default: **false**, preserves isolation).

```yaml
dalet_flex_ops_container_network_bridge_enabled: false
```

</div>
</details>


<details id="admonition-dalet_flex_ops_container_pruning_enabled" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_ops_container_pruning_enabled-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_ops_container_pruning_enabled-title">

dalet_flex_ops_container_pruning_enabled

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_ops_container_pruning_enabled"></a>
</summary>
<div>

Defines whether dangling container images and volumes should be removed from system (allows reclaiming disk space).
When enabled, it does prune all docker images of stopped Flex environment before pulling and starting them.
It's not recomended to enable it in production environments as it slows down the deployment.

```yaml
dalet_flex_ops_container_pruning_enabled: false
```

</div>
</details>


<details id="admonition-dalet_flex_ops_container_orphans_removal_enabled" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_ops_container_orphans_removal_enabled-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_ops_container_orphans_removal_enabled-title">

dalet_flex_ops_container_orphans_removal_enabled

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_ops_container_orphans_removal_enabled"></a>
</summary>
<div>

Defines whether undefined services should be removed from system.

```yaml
dalet_flex_ops_container_orphans_removal_enabled: true
```

</div>
</details>


<details id="admonition-dalet_flex_ops_service_uninstall_enabled" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_ops_service_uninstall_enabled-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_ops_service_uninstall_enabled-title">

dalet_flex_ops_service_uninstall_enabled

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_ops_service_uninstall_enabled"></a>
</summary>
<div>

Defines whether internal services 'garbage-collector' should be enabled.

This provides proper un-installation and cleanup of various resources if specific services are temporarily enabled/disabled or migrated from one server to another.

**WARNING**: Un-installation checks delay regular deployment execution and may remove data (default: **false**)

```yaml
dalet_flex_ops_service_uninstall_enabled: false
```

</div>
</details>


<details id="admonition-dalet_flex_ops_dbpruner_enabled" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_ops_dbpruner_enabled-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_ops_dbpruner_enabled-title">

dalet_flex_ops_dbpruner_enabled

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_ops_dbpruner_enabled"></a>
</summary>
<div>

Define whether DBPruner must be enabled (default: **true**)

DBPruner performs one-off pruning of a batch of old entries (workflow, job, and event instances) from Flex's MariaDB and MongoDB databases and runs at scheduled regular intervals.

```yaml
dalet_flex_ops_dbpruner_enabled: true
```

</div>
</details>


<details id="admonition-dalet_flex_ops_dbpruner_scope" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_ops_dbpruner_scope-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_ops_dbpruner_scope-title">

dalet_flex_ops_dbpruner_scope

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_ops_dbpruner_scope"></a>
</summary>
<div>

Defines which kind of objects are to be processed by DBPruner operations.

Allowed values: **event**, **jobwf** (jobs and workflows) or **all**

```yaml
dalet_flex_ops_dbpruner_scope: all
```

</div>
</details>


<details id="admonition-dalet_flex_ops_dbpruner_cron_schedule" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_ops_dbpruner_cron_schedule-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_ops_dbpruner_cron_schedule-title">

dalet_flex_ops_dbpruner_cron_schedule

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_ops_dbpruner_cron_schedule"></a>
</summary>
<div>

Define the DBPruner running frequency (cron format)

```yaml
dalet_flex_ops_dbpruner_cron_schedule: "*/15 * * * *"
```

</div>
</details>


<details id="admonition-dalet_flex_ops_dbpruner_max_operation_time" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_ops_dbpruner_max_operation_time-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_ops_dbpruner_max_operation_time-title">

dalet_flex_ops_dbpruner_max_operation_time

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_ops_dbpruner_max_operation_time"></a>
</summary>
<div>

Defines the Maximum time a pruning operation can run for (in seconds) before DBPruner starts automatically applying scaling factors to the configured batch sizes.

**WARNING**: This value should only be changed for the duration of a maintenance window, as increasing it has the potential to disrupt other database clients.

```yaml
dalet_flex_ops_dbpruner_max_operation_time: 30
```

</div>
</details>


<details id="admonition-dalet_flex_ops_dbpruner_pause_duration" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_ops_dbpruner_pause_duration-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_ops_dbpruner_pause_duration-title">

dalet_flex_ops_dbpruner_pause_duration

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_ops_dbpruner_pause_duration"></a>
</summary>
<div>

Defines the pause duration (in seconds) between the individual operations within a single pruning run.

```yaml
dalet_flex_ops_dbpruner_pause_duration: 60
```

</div>
</details>


<details id="admonition-dalet_flex_ops_dbpruner_event_batchsize" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_ops_dbpruner_event_batchsize-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_ops_dbpruner_event_batchsize-title">

dalet_flex_ops_dbpruner_event_batchsize

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_ops_dbpruner_event_batchsize"></a>
</summary>
<div>

Defines the maximum number of events to be deleted in a single event pruning operation.

```yaml
dalet_flex_ops_dbpruner_event_batchsize: 25000
```

</div>
</details>


<details id="admonition-dalet_flex_ops_dbpruner_event_retention" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_ops_dbpruner_event_retention-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_ops_dbpruner_event_retention-title">

dalet_flex_ops_dbpruner_event_retention

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_ops_dbpruner_event_retention"></a>
</summary>
<div>

Defines DBPruner event data retention period (in days). Items older than this will be pruned.

```yaml
dalet_flex_ops_dbpruner_event_retention: 90
```

</div>
</details>


<details id="admonition-dalet_flex_ops_dbpruner_jobwf_batchsize" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_ops_dbpruner_jobwf_batchsize-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_ops_dbpruner_jobwf_batchsize-title">

dalet_flex_ops_dbpruner_jobwf_batchsize

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_ops_dbpruner_jobwf_batchsize"></a>
</summary>
<div>

Defines the maximum number of top-level items to be deleted in a single job/workflow DB pruning operation.

```yaml
dalet_flex_ops_dbpruner_jobwf_batchsize: 1000
```

</div>
</details>


<details id="admonition-dalet_flex_ops_dbpruner_job_states" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_ops_dbpruner_job_states-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_ops_dbpruner_job_states-title">

dalet_flex_ops_dbpruner_job_states

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_ops_dbpruner_job_states"></a>
</summary>
<div>

Defines DBPruner optional list job related states.

State entries are defined as:

```yaml
  - state: string              # one of 'cancelled', 'completed', 'failed'
    retention: int             # optional, job|workflow retention period in days (defaults to 90 if unspecified).
    starte_date: 'YYYY-MM-DD'  # optional, only used in case some data older than a threshold should not be pruned.
                               #  (defaults to 10y if unspecified)
```

```yaml
dalet_flex_ops_dbpruner_job_states: []
```

</div>
</details>


<details id="admonition-dalet_flex_ops_dbpruner_workflow_states" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_ops_dbpruner_workflow_states-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_ops_dbpruner_workflow_states-title">

dalet_flex_ops_dbpruner_workflow_states

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_ops_dbpruner_workflow_states"></a>
</summary>
<div>

Defines DBPruner optional list workflow related states.

State entries are defined as:

```yaml
  - state: string              # one of 'cancelled', 'completed', 'failed'
    retention: int             # optional, job|workflow retention period in days (defaults to 90 if unspecified).
    starte_date: 'YYYY-MM-DD'  # optional, only used in case some data older than a threshold should not be pruned.
                               #  (defaults to 10y if unspecified)
```

```yaml
dalet_flex_ops_dbpruner_workflow_states: []
```

</div>
</details>


<details id="admonition-dalet_flex_ops_no_log_enabled" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_ops_no_log_enabled-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_ops_no_log_enabled-title">

dalet_flex_ops_no_log_enabled

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_ops_no_log_enabled"></a>
</summary>
<div>

Hide/display sensitive ansible output during ansible collection run.

**WARNING**: Should remain 'true' to preserve sensible data to be shown on screen during collection execution.

```yaml
dalet_flex_ops_no_log_enabled: true
```

</div>
</details>


<details id="admonition-dalet_flex_solution_packages_registration_wait_for_completion" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_solution_packages_registration_wait_for_completion-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_solution_packages_registration_wait_for_completion-title">

dalet_flex_solution_packages_registration_wait_for_completion

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_solution_packages_registration_wait_for_completion"></a>
</summary>
<div>

Wait for the **flex-solution-packages-registration** deployment completion?

```yaml
dalet_flex_solution_packages_registration_wait_for_completion: false
```

</div>
</details>


<details id="admonition-dalet_flex_ops_git_bitbucket_endpoint" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_ops_git_bitbucket_endpoint-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_ops_git_bitbucket_endpoint-title">

dalet_flex_ops_git_bitbucket_endpoint

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_ops_git_bitbucket_endpoint"></a>
</summary>
<div>

Git / Bitbucket endpoint to pull git repos, default being over SSH. you can change it to `https://bitbucket.org` or `https://[USERNAME]@bitbucket.org` if needed

```yaml
dalet_flex_ops_git_bitbucket_endpoint: "ssh://git@bitbucket.org"
```

</div>
</details>


<details id="admonition-dalet_flex_backup_arangodb_enabled" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_backup_arangodb_enabled-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_backup_arangodb_enabled-title">

dalet_flex_backup_arangodb_enabled

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_backup_arangodb_enabled"></a>
</summary>
<div>

Do we perform ArangoDB backup

```yaml
dalet_flex_backup_arangodb_enabled: true
```

</div>
</details>


<details id="admonition-dalet_flex_backup_mongodb_enabled" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_backup_mongodb_enabled-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_backup_mongodb_enabled-title">

dalet_flex_backup_mongodb_enabled

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_backup_mongodb_enabled"></a>
</summary>
<div>

Do we perform MongoDB backup

```yaml
dalet_flex_backup_mongodb_enabled: true
```

</div>
</details>


<details id="admonition-dalet_flex_backup_mariadb_enabled" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_backup_mariadb_enabled-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_backup_mariadb_enabled-title">

dalet_flex_backup_mariadb_enabled

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_backup_mariadb_enabled"></a>
</summary>
<div>

Do we perform MariaDB backup

```yaml
dalet_flex_backup_mariadb_enabled: true
```

</div>
</details>


<details id="admonition-dalet_flex_backup_postgresql_enabled" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_backup_postgresql_enabled-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_backup_postgresql_enabled-title">

dalet_flex_backup_postgresql_enabled

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_backup_postgresql_enabled"></a>
</summary>
<div>

Do we perform postgresql backup (only applies when we also deploy the brio ingest scheduler)

```yaml
dalet_flex_backup_postgresql_enabled: false
```

</div>
</details>


<details id="admonition-dalet_flex_backup_arangodb_retention" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_backup_arangodb_retention-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_backup_arangodb_retention-title">

dalet_flex_backup_arangodb_retention

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_backup_arangodb_retention"></a>
</summary>
<div>

ArangoDB backup retention in days
```yaml
dalet_flex_backup_arangodb_retention: 90
```

</div>
</details>


<details id="admonition-dalet_flex_backup_mongodb_retention" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_backup_mongodb_retention-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_backup_mongodb_retention-title">

dalet_flex_backup_mongodb_retention

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_backup_mongodb_retention"></a>
</summary>
<div>

MongoDB backup retention in days
```yaml
dalet_flex_backup_mongodb_retention: 90
```

</div>
</details>


<details id="admonition-dalet_flex_backup_mariadb_retention" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_backup_mariadb_retention-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_backup_mariadb_retention-title">

dalet_flex_backup_mariadb_retention

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_backup_mariadb_retention"></a>
</summary>
<div>

MariaDB backup retention in days
```yaml
dalet_flex_backup_mariadb_retention: 90
```

</div>
</details>


<details id="admonition-dalet_flex_backup_postgresql_retention" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_backup_postgresql_retention-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_backup_postgresql_retention-title">

dalet_flex_backup_postgresql_retention

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_backup_postgresql_retention"></a>
</summary>
<div>

Postgresql backup retention in days
```yaml
dalet_flex_backup_postgresql_retention: 90
```

</div>
</details>


<details id="admonition-dalet_flex_backup_mariadb_host" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_backup_mariadb_host-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_backup_mariadb_host-title">

dalet_flex_backup_mariadb_host

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_backup_mariadb_host"></a>
</summary>
<div>

Which MariaDB host will be used for the backup. Setup a secondary server when using HA to avoid any lock
```yaml
dalet_flex_backup_mariadb_host: "{{ dalet_flex_db_mysql_host }}"
```

</div>
</details>


<details id="admonition-dalet_flex_backup_mariadb_backup_user" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_backup_mariadb_backup_user-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_backup_mariadb_backup_user-title">

dalet_flex_backup_mariadb_backup_user

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_backup_mariadb_backup_user"></a>
</summary>
<div>

Backup username we will set for MariaDB. Will be created by script.
```yaml
dalet_flex_backup_mariadb_backup_user: "backup"
```

</div>
</details>


<details id="admonition-dalet_flex_backup_mariadb_backup_password" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_backup_mariadb_backup_password-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_backup_mariadb_backup_password-title">

dalet_flex_backup_mariadb_backup_password

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_backup_mariadb_backup_password"></a>
</summary>
<div>

Backup password we will set for MariaDB backup user.
```yaml
dalet_flex_backup_mariadb_backup_password: "{{ vault_dalet_flex_backup_mariadb_backup_password }}"
```

</div>
</details>


<details id="admonition-dalet_flex_backup_postgresql_host" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_backup_postgresql_host-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_backup_postgresql_host-title">

dalet_flex_backup_postgresql_host

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_backup_postgresql_host"></a>
</summary>
<div>

Which postgresql host will we used for the backup. Setup a secondary server when using ha to avoid any lock. Default uses the first one from inventory
```yaml
dalet_flex_backup_postgresql_host: "{{ groups['dbaas'][0] | default('') }}"
```

</div>
</details>


<details id="admonition-dalet_flex_backup_cronjob_minute" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_backup_cronjob_minute-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_backup_cronjob_minute-title">

dalet_flex_backup_cronjob_minute

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_backup_cronjob_minute"></a>
</summary>
<div>

Backup cronjob: on which minute(s) do we start
```yaml
dalet_flex_backup_cronjob_minute: 0
```

</div>
</details>


<details id="admonition-dalet_flex_backup_cronjob_hour" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_backup_cronjob_hour-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_backup_cronjob_hour-title">

dalet_flex_backup_cronjob_hour

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_backup_cronjob_hour"></a>
</summary>
<div>

Backup cronjob: on which hour(s) do we start
```yaml
dalet_flex_backup_cronjob_hour: 5
```

</div>
</details>


<details id="admonition-dalet_flex_backup_cronjob_day" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_backup_cronjob_day-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_backup_cronjob_day-title">

dalet_flex_backup_cronjob_day

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_backup_cronjob_day"></a>
</summary>
<div>

Backup cronjob: on which day(s) do we start
```yaml
dalet_flex_backup_cronjob_day: "*"
```

</div>
</details>


<details id="admonition-dalet_flex_backup_cronjob_month" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_backup_cronjob_month-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_backup_cronjob_month-title">

dalet_flex_backup_cronjob_month

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_backup_cronjob_month"></a>
</summary>
<div>

Backup cronjob: on which month(s) do we start
```yaml
dalet_flex_backup_cronjob_month: "*"
```

</div>
</details>


<details id="admonition-dalet_flex_backup_cronjob_weekday" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_backup_cronjob_weekday-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_backup_cronjob_weekday-title">

dalet_flex_backup_cronjob_weekday

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_backup_cronjob_weekday"></a>
</summary>
<div>

Backup cronjob: on which weekday(s) do we start
```yaml
dalet_flex_backup_cronjob_weekday: "*"
```

</div>
</details>


<details id="admonition-dalet_flex_backup_aws_s3_bucket" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_backup_aws_s3_bucket-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_backup_aws_s3_bucket-title">

dalet_flex_backup_aws_s3_bucket

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_backup_aws_s3_bucket"></a>
</summary>
<div>

AWS S3 bucket we want to store the backup when available. Note the bucket must be created and reachable by the backup server through instance profile
```yaml
dalet_flex_backup_aws_s3_bucket: ~
```

</div>
</details>


<details id="admonition-dalet_flex_backup_oss_bucket" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_backup_oss_bucket-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_backup_oss_bucket-title">

dalet_flex_backup_oss_bucket

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_backup_oss_bucket"></a>
</summary>
<div>

Alicloud S3 bucket we want to store the backup when available. Note the bucket must be created and reachable by the backup server through instance profile
```yaml
dalet_flex_backup_oss_bucket: ~
```

</div>
</details>


<details id="admonition-dalet_flex_backup_oss_copy_part_size" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_backup_oss_copy_part_size-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_backup_oss_copy_part_size-title">

dalet_flex_backup_oss_copy_part_size

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_backup_oss_copy_part_size"></a>
</summary>
<div>

Alicloud: setup part size on alicloud bucket copy
```yaml
dalet_flex_backup_oss_copy_part_size: 51200000
```

</div>
</details>


<details id="admonition-dalet_flex_backup_oss_endpoint" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_backup_oss_endpoint-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_backup_oss_endpoint-title">

dalet_flex_backup_oss_endpoint

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_backup_oss_endpoint"></a>
</summary>
<div>

Alicloud: bucket endpoint
```yaml
dalet_flex_backup_oss_endpoint: ~
```

</div>
</details>


<details id="admonition-dalet_flex_backup_extra_s3" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_backup_extra_s3-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_backup_extra_s3-title">

dalet_flex_backup_extra_s3

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_backup_extra_s3"></a>
</summary>
<div>

Extra S3 endpoint backup need to be copied to.
Profile name is open text that will be added to a .aws/credentials file with the remaining configuration items
```yaml
dalet_flex_backup_extra_s3:
  - bucket: ""
  - endpoint: ""
  - user_secret: ""
  - user_key: ""
  - profile: extra-s3
  - region: your-region
```

</div>
</details>


<details id="admonition-dalet_flex_storage_backup_cifs_host" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_storage_backup_cifs_host-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_storage_backup_cifs_host-title">

dalet_flex_storage_backup_cifs_host

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_storage_backup_cifs_host"></a>
</summary>
<div>

CIFS host to use to mount a backup storage. Will be used to store databases backups
```yaml
dalet_flex_storage_backup_cifs_host: ""
```

</div>
</details>


<details id="admonition-dalet_flex_storage_backup_cifs_share" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_storage_backup_cifs_share-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_storage_backup_cifs_share-title">

dalet_flex_storage_backup_cifs_share

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_storage_backup_cifs_share"></a>
</summary>
<div>

CIFS host to use to mount a backup storage. Will be used to store databases backups
```yaml
dalet_flex_storage_backup_cifs_share: ""
```

</div>
</details>


<details id="admonition-dalet_flex_storage_backup_cifs_user" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_storage_backup_cifs_user-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_storage_backup_cifs_user-title">

dalet_flex_storage_backup_cifs_user

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_storage_backup_cifs_user"></a>
</summary>
<div>

CIFS user to use to mount a backup storage. Will be used to store databases backups
```yaml
dalet_flex_storage_backup_cifs_user: ""
```

</div>
</details>


<details id="admonition-dalet_flex_storage_backup_cifs_password" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_storage_backup_cifs_password-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_storage_backup_cifs_password-title">

dalet_flex_storage_backup_cifs_password

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_storage_backup_cifs_password"></a>
</summary>
<div>

CIFS password to use to mount a backup storage. Will be used to store databases backups
```yaml
dalet_flex_storage_backup_cifs_password: ""
```

</div>
</details>


<details id="admonition-dalet_flex_backup_aws_efs_mount" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_backup_aws_efs_mount-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_backup_aws_efs_mount-title">

dalet_flex_backup_aws_efs_mount

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_backup_aws_efs_mount"></a>
</summary>
<div>

Mount AWS EFS storage to store the backup files. Enable/Disable
```yaml
dalet_flex_backup_aws_efs_mount: "{{ dalet_flex_storage_backup_efs_share:='' }}"
```

</div>
</details>


<details id="admonition-dalet_flex_storage_backup_efs_id" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_storage_backup_efs_id-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_storage_backup_efs_id-title">

dalet_flex_storage_backup_efs_id

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_storage_backup_efs_id"></a>
</summary>
<div>

EFS id to use to mount a backup storage. Will be used to store databases backups
```yaml
dalet_flex_storage_backup_efs_id: ""
```

</div>
</details>


<details id="admonition-dalet_flex_storage_backup_efs_region" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_storage_backup_efs_region-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_storage_backup_efs_region-title">

dalet_flex_storage_backup_efs_region

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_storage_backup_efs_region"></a>
</summary>
<div>

EFS region to use to mount a backup storage. Will be used to store databases backups
```yaml
dalet_flex_storage_backup_efs_region: ""
```

</div>
</details>


<details id="admonition-dalet_flex_storage_backup_efs_share" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_storage_backup_efs_share-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_storage_backup_efs_share-title">

dalet_flex_storage_backup_efs_share

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_storage_backup_efs_share"></a>
</summary>
<div>

EFS share to use to mount a backup storage. Will be used to store databases backups
```yaml
dalet_flex_storage_backup_efs_share: ""
```

</div>
</details>


<details id="admonition-dalet_flex_storage_backup_efs_iam" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_storage_backup_efs_iam-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_storage_backup_efs_iam-title">

dalet_flex_storage_backup_efs_iam

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_storage_backup_efs_iam"></a>
</summary>
<div>

EFS iam profile to use to mount a backup storage. Will be used to store databases backups
```yaml
dalet_flex_storage_backup_efs_iam: ""
```

</div>
</details>


<details id="admonition-dalet_flex_storage_backup_azure_account" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_storage_backup_azure_account-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_storage_backup_azure_account-title">

dalet_flex_storage_backup_azure_account

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_storage_backup_azure_account"></a>
</summary>
<div>

Azure account to use to mount a backup storage. Will be used to store databases backups
```yaml
dalet_flex_storage_backup_azure_account: ""
```

</div>
</details>


<details id="admonition-dalet_flex_storage_backup_azure_share" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_storage_backup_azure_share-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_storage_backup_azure_share-title">

dalet_flex_storage_backup_azure_share

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_storage_backup_azure_share"></a>
</summary>
<div>

Azure share to use to mount a backup storage. Will be used to store databases backups
```yaml
dalet_flex_storage_backup_azure_share: ""
```

</div>
</details>


<details id="admonition-dalet_flex_storage_backup_azure_user" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_storage_backup_azure_user-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_storage_backup_azure_user-title">

dalet_flex_storage_backup_azure_user

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_storage_backup_azure_user"></a>
</summary>
<div>

Azure user to use to mount a backup storage. Will be used to store databases backups
```yaml
dalet_flex_storage_backup_azure_user: ""
```

</div>
</details>


<details id="admonition-dalet_flex_storage_backup_azure_password" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_storage_backup_azure_password-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_storage_backup_azure_password-title">

dalet_flex_storage_backup_azure_password

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_storage_backup_azure_password"></a>
</summary>
<div>

Azure password to use to mount a backup storage. Will be used to store databases backups
```yaml
dalet_flex_storage_backup_azure_password: ""
```

</div>
</details>


<details id="admonition-dalet_flex_storage_backup_nfs_host" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_storage_backup_nfs_host-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_storage_backup_nfs_host-title">

dalet_flex_storage_backup_nfs_host

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_storage_backup_nfs_host"></a>
</summary>
<div>

NFS host to use to mount a backup storage. Will be used to store databases backups
```yaml
dalet_flex_storage_backup_nfs_host: ""
```

</div>
</details>


<details id="admonition-dalet_flex_storage_backup_nfs_path" class="admonition admonish-flex" role="note" aria-labelledby="admonition-dalet_flex_storage_backup_nfs_path-title">
<summary class="admonition-title">
<div id="admonition-dalet_flex_storage_backup_nfs_path-title">

dalet_flex_storage_backup_nfs_path

</div>
<a class="admonition-anchor-link" href="#admonition-dalet_flex_storage_backup_nfs_path"></a>
</summary>
<div>

NFS path to use to mount a backup storage. Will be used to store databases backups
```yaml
dalet_flex_storage_backup_nfs_path: ""
```

</div>
</details>