- Description
-
Red Hat {product-title} Lightspeed instance. OLSConfig is the Schema for the olsconfigs API
- Type
-
object - Required
-
-
spec
-
| Property | Type | Description |
|---|---|---|
|
|
APIVersion defines the versioned schema of this representation of an object. Servers should convert recognized schemas to the latest internal value, and might reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources |
|
|
Kind is a string value representing the REST resource this object represents. Servers might infer this from the endpoint the client submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds |
|
|
Standard object’s metadata. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata |
|
|
OLSConfigSpec defines the desired state of OLSConfig |
- Description
-
Standard object’s metadata. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
- Type
-
object
- Description
-
OLSConfigSpec defines the desired state of OLSConfig
- Type
-
object - Required
-
-
llm -
ols
-
| Property | Type | Description |
|---|---|---|
|
|
Feature Gates holds list of features to be enabled explicitly, otherwise they are disabled by default. possible values: MCPServer |
|
|
LLMSpec defines the desired state of the large language model (LLM). |
|
|
MCP Server settings |
|
|
OLSSpec defines the desired state of OLS deployment. |
|
|
OLSDataCollectorSpec defines allowed OLS data collector configuration. |
|
|
ToolsApprovalConfig defines the configuration for tool execution approvals. |
- Description
-
LLMSpec defines the desired state of the large language model (LLM).
- Type
-
object - Required
-
-
providers
-
| Property | Type | Description |
|---|---|---|
|
|
- Description
-
ProviderSpec defines the desired state of LLM provider.
- Type
-
object - Required
-
-
credentialsSecretRef -
models -
name -
type
-
| Property | Type | Description |
|---|---|---|
|
|
API Version for Azure OpenAI provider |
|
|
The name of the secret object that stores API provider credentials |
|
|
Azure OpenAI deployment name |
|
|
List of models from the provider |
|
|
Provider name |
|
|
Watsonx Project ID |
|
|
TLS Security Profile used by connection to provider |
|
|
Provider type |
|
|
Provider API URL |
- Description
-
The name of the secret object that stores API provider credentials
- Type
-
object
| Property | Type | Description |
|---|---|---|
|
|
Name of the referent. This field is effectively required, but due to backwards compatibility is allowed to be empty. Instances of this type with an empty value here are almost certainly wrong. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names |
- Description
-
ModelSpec defines the LLM model to use and its parameters.
- Type
-
object - Required
-
-
name
-
| Property | Type | Description |
|---|---|---|
|
|
Defines the model’s context window size, in tokens. The default is 128k tokens. |
|
|
Model name |
|
|
Model API parameters |
|
|
Model API URL |
- Description
-
Model API parameters
- Type
-
object
| Property | Type | Description |
|---|---|---|
|
|
Max tokens for response. The default is 2048 tokens. |
- Description
-
TLS Security Profile used by connection to provider
- Type
-
object
| Property | Type | Description |
|---|---|---|
|
`` |
custom is a user-defined TLS security profile. Be extremely careful using a custom profile as invalid configurations can be catastrophic. An example custom profile looks like this: ciphers: - ECDHE-ECDSA-CHACHA20-POLY1305 - ECDHE-RSA-CHACHA20-POLY1305 - ECDHE-RSA-AES128-GCM-SHA256 - ECDHE-ECDSA-AES128-GCM-SHA256 minTLSVersion: VersionTLS11 |
|
`` |
intermediate is a TLS security profile based on: https://wiki.mozilla.org/Security/Server_Side_TLS#Intermediate_compatibility_.28recommended.29 and looks like this (yaml): ciphers: - TLS_AES_128_GCM_SHA256 - TLS_AES_256_GCM_SHA384 - TLS_CHACHA20_POLY1305_SHA256 - ECDHE-ECDSA-AES128-GCM-SHA256 - ECDHE-RSA-AES128-GCM-SHA256 - ECDHE-ECDSA-AES256-GCM-SHA384 - ECDHE-RSA-AES256-GCM-SHA384 - ECDHE-ECDSA-CHACHA20-POLY1305 - ECDHE-RSA-CHACHA20-POLY1305 - DHE-RSA-AES128-GCM-SHA256 - DHE-RSA-AES256-GCM-SHA384 minTLSVersion: VersionTLS12 |
|
`` |
modern is a TLS security profile based on: https://wiki.mozilla.org/Security/Server_Side_TLS#Modern_compatibility and looks like this (yaml): ciphers: - TLS_AES_128_GCM_SHA256 - TLS_AES_256_GCM_SHA384 - TLS_CHACHA20_POLY1305_SHA256 minTLSVersion: VersionTLS13 |
|
`` |
old is a TLS security profile based on: https://wiki.mozilla.org/Security/Server_Side_TLS#Old_backward_compatibility and looks like this (yaml): ciphers: - TLS_AES_128_GCM_SHA256 - TLS_AES_256_GCM_SHA384 - TLS_CHACHA20_POLY1305_SHA256 - ECDHE-ECDSA-AES128-GCM-SHA256 - ECDHE-RSA-AES128-GCM-SHA256 - ECDHE-ECDSA-AES256-GCM-SHA384 - ECDHE-RSA-AES256-GCM-SHA384 - ECDHE-ECDSA-CHACHA20-POLY1305 - ECDHE-RSA-CHACHA20-POLY1305 - DHE-RSA-AES128-GCM-SHA256 - DHE-RSA-AES256-GCM-SHA384 - DHE-RSA-CHACHA20-POLY1305 - ECDHE-ECDSA-AES128-SHA256 - ECDHE-RSA-AES128-SHA256 - ECDHE-ECDSA-AES128-SHA - ECDHE-RSA-AES128-SHA - ECDHE-ECDSA-AES256-SHA384 - ECDHE-RSA-AES256-SHA384 - ECDHE-ECDSA-AES256-SHA - ECDHE-RSA-AES256-SHA - DHE-RSA-AES128-SHA256 - DHE-RSA-AES256-SHA256 - AES128-GCM-SHA256 - AES256-GCM-SHA384 - AES128-SHA256 - AES256-SHA256 - AES128-SHA - AES256-SHA - DES-CBC3-SHA minTLSVersion: VersionTLS10 |
|
|
type is one of Old, Intermediate, Modern or Custom. Custom provides the ability to specify individual TLS security profile parameters. Old, Intermediate and Modern are TLS security profiles based on: https://wiki.mozilla.org/Security/Server_Side_TLS#Recommended_configurations The profiles are intent based, so they might change over time as new ciphers are developed and existing ciphers are found to be insecure. Depending on precisely which ciphers are available to a process, the list might be reduced. Note that the Modern profile is currently not supported because it is not yet well adopted by common software libraries. |
- Description
-
MCP Server settings
- Type
-
arrayNoteThe
introspectionEnabledfield in theOLSConfigcustom resource (CR) istrueby default. You do not need to specify this field to use the built-in {k8s} MCP server. To disable the built-in {k8s} MCP server, you must setintrospectionEnabledtofalse.ImportantThe operator does not support direct modifications to the managed MCP server configuration. To customize this configuration, you must set the operator to an unmanaged state by adding the
operator.openshift.io/managementState: Unmanagedannotation to theOLSConfigcustom resource. Alternatively, you can deploy a standalone MCP server instance.
- Description
-
MCPServer defines the settings for a single MCP server.
- Type
-
object - Required
-
-
name
-
| Property | Type | Description |
|---|---|---|
|
|
Custom arguments passed to the MCP server during initialization. |
|
|
Name of the MCP server. |
|
|
Streamable HTTP Transport settings. |
|
|
(Optional) Configures the source type and reference parameters used for header authentication with the MCP server. |
|
|
(Required if |
|
|
(Optional) Specifies the name of the {k8s} secret that contains the required token. This parameter applies only when the |
The following configuration examples demonstrate how to map header authentication tokens through the valueFrom specification block.
Example of configuring authentication using a Kubernetes secret:
valueFrom:
type: secret
secretRef:
name: mcp-server-tokenExample of configuring authentication using a service account token:
valueFrom:
type: kubernetes- Description
-
Custom arguments passed directly to the MCP server process initialization command.
- Type
-
array (string)
- Description
-
OLSSpec defines the desired state of OLS deployment.
- Type
-
object - Required
-
-
defaultModel -
defaultProvider
-
| Property | Type | Description |
|---|---|---|
|
|
Additional CA certificates for TLS communication between OLS service and LLM Provider |
|
|
Only use BYOK RAG sources, ignore the {product-title} documentation RAG |
|
|
Conversation cache settings |
|
|
Default model for usage |
|
|
Default provider for usage |
|
|
OLS deployment settings |
|
|
Enable introspection features |
|
|
Log level. Valid options are DEBUG, INFO, WARNING, ERROR and CRITICAL. Default: "INFO". |
|
|
Proxy settings for connecting to external servers, such as LLM providers. |
|
|
Query filters |
|
|
LLM Token Quota Configuration |
|
|
RAG databases |
|
|
Persistent Storage Configuration |
|
|
TLS configuration of the Lightspeed backend’s HTTPS endpoint |
|
|
TLS Security Profile used by API endpoints |
|
|
User data collection switches |
- Description
-
Additional CA certificates for TLS communication between OLS service and LLM Provider
- Type
-
object
| Property | Type | Description |
|---|---|---|
|
|
Name of the referent. This field is effectively required, but due to backwards compatibility is allowed to be empty. Instances of this type with an empty value here are almost certainly wrong. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names |
- Description
-
Conversation cache settings
- Type
-
object
| Property | Type | Description |
|---|---|---|
|
|
PostgresSpec defines the desired state of Postgres. |
|
|
Conversation cache type. Default: "postgres" |
- Description
-
PostgresSpec defines the desired state of Postgres.
- Type
-
object
| Property | Type | Description |
|---|---|---|
|
|
Secret that holds postgres credentials |
|
|
Postgres database name |
|
|
Postgres maxconnections. Default: "2000" |
|
|
Postgres sharedbuffers |
|
|
Postgres user name |
- Description
-
OLS deployment settings
- Type
-
object
| Property | Type | Description |
|---|---|---|
|
|
API container settings. |
|
|
Console container settings. |
|
|
Data Collector container settings. |
|
|
Database container settings. |
|
|
MCP server container settings. |
|
|
Defines the number of desired OLS pods. Default: "1" |
- Description
-
API container settings.
- Type
-
object
| Property | Type | Description |
|---|---|---|
|
|
|
|
|
ResourceRequirements describes the compute resource requirements. |
|
|
- Description
-
ResourceRequirements describes the compute resource requirements.
- Type
-
object
| Property | Type | Description |
|---|---|---|
|
|
Claims lists the names of resources, defined in spec.resourceClaims, that are used by this container. This is an alpha field and requires enabling the DynamicResourceAllocation feature gate. This field is immutable. It can only be set for containers. |
|
|
Limits describes the maximum amount of compute resources allowed. More info: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/ |
|
|
Requests describes the minimum amount of compute resources required. If Requests is omitted for a container, it defaults to Limits if that is explicitly specified, otherwise to an implementation-defined value. Requests cannot exceed Limits. More info: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/ |
- Description
-
Claims lists the names of resources, defined in spec.resourceClaims, that are used by this container.
This is an alpha field and requires enabling the DynamicResourceAllocation feature gate.
This field is immutable. It can only be set for containers.
- Type
-
array
- Description
-
ResourceClaim references one entry in PodSpec.ResourceClaims.
- Type
-
object - Required
-
-
name
-
| Property | Type | Description |
|---|---|---|
|
|
Name must match the name of one entry in pod.spec.resourceClaims of the Pod where this field is used. It makes that resource available inside a container. |
|
|
Request is the name chosen for a request in the referenced claim. If empty, everything from the claim is made available, otherwise only the result of this request. |
- Description
-
The pod this Toleration is attached to tolerates any taint that matches the triple <key,value,effect> using the matching operator <operator>.
- Type
-
object
| Property | Type | Description |
|---|---|---|
|
|
Effect indicates the taint effect to match. Empty means match all taint effects. When specified, allowed values are NoSchedule, PreferNoSchedule and NoExecute. |
|
|
Key is the taint key that the toleration applies to. Empty means match all taint keys. If the key is empty, operator must be Exists; this combination means to match all values and all keys. |
|
|
Operator represents a key’s relationship to the value. Valid operators are Exists and Equal. Defaults to Equal. Exists is equivalent to wildcard for value, so that a pod can tolerate all taints of a particular category. |
|
|
TolerationSeconds represents the period of time the toleration (which must be of effect NoExecute, otherwise this field is ignored) tolerates the taint. By default, it is not set, which means tolerate the taint forever (do not evict). Zero and negative values will be treated as 0 (evict immediately) by the system. |
|
|
Value is the taint value the toleration matches to. If the operator is Exists, the value should be empty, otherwise just a regular string. |
- Description
-
Console container settings.
- Type
-
object
| Property | Type | Description |
|---|---|---|
|
|
Certificate Authority (CA) certificate used by the console proxy endpoint. |
|
|
|
|
|
Defines the number of desired Console pods. Default: "1" |
|
|
ResourceRequirements describes the compute resource requirements. |
|
|
- Description
-
ResourceRequirements describes the compute resource requirements.
- Type
-
object
| Property | Type | Description |
|---|---|---|
|
|
Claims lists the names of resources, defined in spec.resourceClaims, that are used by this container. This is an alpha field and requires enabling the DynamicResourceAllocation feature gate. This field is immutable. It can only be set for containers. |
|
|
Limits describes the maximum amount of compute resources allowed. More info: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/ |
|
|
Requests describes the minimum amount of compute resources required. If Requests is omitted for a container, it defaults to Limits if that is explicitly specified, otherwise to an implementation-defined value. Requests cannot exceed Limits. More info: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/ |
- Description
-
Claims lists the names of resources, defined in spec.resourceClaims, that are used by this container.
This is an alpha field and requires enabling the DynamicResourceAllocation feature gate.
This field is immutable. It can only be set for containers.
- Type
-
array
- Description
-
ResourceClaim references one entry in PodSpec.ResourceClaims.
- Type
-
object - Required
-
-
name
-
| Property | Type | Description |
|---|---|---|
|
|
Name must match the name of one entry in pod.spec.resourceClaims of the Pod where this field is used. It makes that resource available inside a container. |
|
|
Request is the name chosen for a request in the referenced claim. If empty, everything from the claim is made available, otherwise only the result of this request. |
- Description
-
The pod this Toleration is attached to tolerates any taint that matches the triple <key,value,effect> using the matching operator <operator>.
- Type
-
object
| Property | Type | Description |
|---|---|---|
|
|
Effect indicates the taint effect to match. Empty means match all taint effects. When specified, allowed values are NoSchedule, PreferNoSchedule and NoExecute. |
|
|
Key is the taint key that the toleration applies to. Empty means match all taint keys. If the key is empty, operator must be Exists; this combination means to match all values and all keys. |
|
|
Operator represents a key’s relationship to the value. Valid operators are Exists and Equal. Defaults to Equal. Exists is equivalent to wildcard for value, so that a pod can tolerate all taints of a particular category. |
|
|
TolerationSeconds represents the period of time the toleration (which must be of effect NoExecute, otherwise this field is ignored) tolerates the taint. By default, it is not set, which means tolerate the taint forever (do not evict). Zero and negative values will be treated as 0 (evict immediately) by the system. |
|
|
Value is the taint value the toleration matches to. If the operator is Exists, the value should be empty, otherwise just a regular string. |
- Description
-
Data Collector container settings.
- Type
-
object
| Property | Type | Description |
|---|---|---|
|
|
ResourceRequirements describes the compute resource requirements. |
- Description
-
ResourceRequirements describes the compute resource requirements.
- Type
-
object
| Property | Type | Description |
|---|---|---|
|
|
Claims lists the names of resources, defined in spec.resourceClaims, that are used by this container. This is an alpha field and requires enabling the DynamicResourceAllocation feature gate. This field is immutable. It can only be set for containers. |
|
|
Limits describes the maximum amount of compute resources allowed. More info: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/ |
|
|
Requests describes the minimum amount of compute resources required. If Requests is omitted for a container, it defaults to Limits if that is explicitly specified, otherwise to an implementation-defined value. Requests cannot exceed Limits. More info: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/ |
- Description
-
Claims lists the names of resources, defined in spec.resourceClaims, that are used by this container.
This is an alpha field and requires enabling the DynamicResourceAllocation feature gate.
This field is immutable. It can only be set for containers.
- Type
-
array
- Description
-
ResourceClaim references one entry in PodSpec.ResourceClaims.
- Type
-
object - Required
-
-
name
-
| Property | Type | Description |
|---|---|---|
|
|
Name must match the name of one entry in pod.spec.resourceClaims of the Pod where this field is used. It makes that resource available inside a container. |
|
|
Request is the name chosen for a request in the referenced claim. If empty, everything from the claim is made available, otherwise only the result of this request. |
- Description
-
Database container settings.
- Type
-
object
| Property | Type | Description |
|---|---|---|
|
|
|
|
|
ResourceRequirements describes the compute resource requirements. |
|
|
- Description
-
ResourceRequirements describes the compute resource requirements.
- Type
-
object
| Property | Type | Description |
|---|---|---|
|
|
Claims lists the names of resources, defined in spec.resourceClaims, that are used by this container. This is an alpha field and requires enabling the DynamicResourceAllocation feature gate. This field is immutable. It can only be set for containers. |
|
|
Limits describes the maximum amount of compute resources allowed. More info: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/ |
|
|
Requests describes the minimum amount of compute resources required. If Requests is omitted for a container, it defaults to Limits if that is explicitly specified, otherwise to an implementation-defined value. Requests cannot exceed Limits. More info: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/ |
- Description
-
Claims lists the names of resources, defined in spec.resourceClaims, that are used by this container.
This is an alpha field and requires enabling the DynamicResourceAllocation feature gate.
This field is immutable. It can only be set for containers.
- Type
-
array
- Description
-
ResourceClaim references one entry in PodSpec.ResourceClaims.
- Type
-
object - Required
-
-
name
-
| Property | Type | Description |
|---|---|---|
|
|
Name must match the name of one entry in pod.spec.resourceClaims of the Pod where this field is used. It makes that resource available inside a container. |
|
|
Request is the name chosen for a request in the referenced claim. If empty, everything from the claim is made available, otherwise only the result of this request. |
- Description
-
The pod this Toleration is attached to tolerates any taint that matches the triple <key,value,effect> using the matching operator <operator>.
- Type
-
object
| Property | Type | Description |
|---|---|---|
|
|
Effect indicates the taint effect to match. Empty means match all taint effects. When specified, allowed values are NoSchedule, PreferNoSchedule and NoExecute. |
|
|
Key is the taint key that the toleration applies to. Empty means match all taint keys. If the key is empty, operator must be Exists; this combination means to match all values and all keys. |
|
|
Operator represents a key’s relationship to the value. Valid operators are Exists and Equal. Defaults to Equal. Exists is equivalent to wildcard for value, so that a pod can tolerate all taints of a particular category. |
|
|
TolerationSeconds represents the period of time the toleration (which must be of effect NoExecute, otherwise this field is ignored) tolerates the taint. By default, it is not set, which means tolerate the taint forever (do not evict). Zero and negative values will be treated as 0 (evict immediately) by the system. |
|
|
Value is the taint value the toleration matches to. If the operator is Exists, the value should be empty, otherwise just a regular string. |
- Description
-
MCP server container settings.
- Type
-
object
| Property | Type | Description |
|---|---|---|
|
|
ResourceRequirements describes the compute resource requirements. |
- Description
-
ResourceRequirements describes the compute resource requirements.
- Type
-
object
| Property | Type | Description |
|---|---|---|
|
|
Claims lists the names of resources, defined in spec.resourceClaims, that are used by this container. This is an alpha field and requires enabling the DynamicResourceAllocation feature gate. This field is immutable. It can only be set for containers. |
|
|
Limits describes the maximum amount of compute resources allowed. More info: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/ |
|
|
Requests describes the minimum amount of compute resources required. If Requests is omitted for a container, it defaults to Limits if that is explicitly specified, otherwise to an implementation-defined value. Requests cannot exceed Limits. More info: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/ |
- Description
-
Claims lists the names of resources, defined in spec.resourceClaims, that are used by this container.
This is an alpha field and requires enabling the DynamicResourceAllocation feature gate.
This field is immutable. It can only be set for containers.
- Type
-
array
- Description
-
ResourceClaim references one entry in PodSpec.ResourceClaims.
- Type
-
object - Required
-
-
name
-
| Property | Type | Description |
|---|---|---|
|
|
Name must match the name of one entry in pod.spec.resourceClaims of the Pod where this field is used. It makes that resource available inside a container. |
|
|
Request is the name chosen for a request in the referenced claim. If empty, everything from the claim is made available, otherwise only the result of this request. |
- Description
-
Proxy settings for connecting to external servers, such as LLM providers.
- Type
-
object
| Property | Type | Description |
|---|---|---|
|
|
The configmap holding proxy CA certificate |
|
|
Proxy URL, e.g. https://proxy.example.com:8080 If not specified, the cluster wide proxy will be used, though env var "https_proxy". |
- Description
-
The configmap holding proxy CA certificate
- Type
-
object
| Property | Type | Description |
|---|---|---|
|
|
Name of the referent. This field is effectively required, but due to backwards compatibility is allowed to be empty. Instances of this type with an empty value here are almost certainly wrong. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names |
- Description
-
QueryFiltersSpec defines filters to manipulate questions/queries.
- Type
-
object
| Property | Type | Description |
|---|---|---|
|
|
Filter name. |
|
|
Filter pattern. |
|
|
Replacement for the matched pattern. |
- Description
-
LLM Token Quota Configuration
- Type
-
object
| Property | Type | Description |
|---|---|---|
|
|
Enable token history |
|
|
Token quota limiters |
- Description
-
LimiterConfig defines settings for a token quota limiter
- Type
-
object - Required
-
-
initialQuota -
name -
period -
quotaIncrease -
type
-
| Property | Type | Description |
|---|---|---|
|
|
Initial value of the token quota |
|
|
Name of the limiter |
|
|
Period of time the token quota is for |
|
|
Token quota increase step |
|
|
Type of the limiter |
- Description
-
RAGSpec defines how to retrieve a RAG databases.
- Type
-
object - Required
-
-
image
-
| Property | Type | Description |
|---|---|---|
|
|
The URL of the container image to use as a RAG source |
|
|
The Index ID of the RAG database |
|
|
The path to the RAG database inside of the container image |
- Description
-
Persistent Storage Configuration
- Type
-
object
| Property | Type | Description |
|---|---|---|
|
|
Storage class of the requested volume |
|
|
Size of the requested volume |
- Description
-
TLS configuration of the Lightspeed backend’s HTTPS endpoint
- Type
-
object
| Property | Type | Description |
|---|---|---|
|
|
KeySecretRef is the secret that holds the TLS key. |
- Description
-
KeySecretRef is the secret that holds the TLS key.
- Type
-
object
| Property | Type | Description |
|---|---|---|
|
|
Name of the referent. This field is effectively required, but due to backwards compatibility is allowed to be empty. Instances of this type with an empty value here are almost certainly wrong. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names |
- Description
-
TLS Security Profile used by API endpoints
- Type
-
object
| Property | Type | Description |
|---|---|---|
|
`` |
custom is a user-defined TLS security profile. Be extremely careful using a custom profile as invalid configurations can be catastrophic. An example custom profile looks like this: ciphers: - ECDHE-ECDSA-CHACHA20-POLY1305 - ECDHE-RSA-CHACHA20-POLY1305 - ECDHE-RSA-AES128-GCM-SHA256 - ECDHE-ECDSA-AES128-GCM-SHA256 minTLSVersion: VersionTLS11 |
|
`` |
intermediate is a TLS security profile based on: https://wiki.mozilla.org/Security/Server_Side_TLS#Intermediate_compatibility_.28recommended.29 and looks like this (yaml): ciphers: - TLS_AES_128_GCM_SHA256 - TLS_AES_256_GCM_SHA384 - TLS_CHACHA20_POLY1305_SHA256 - ECDHE-ECDSA-AES128-GCM-SHA256 - ECDHE-RSA-AES128-GCM-SHA256 - ECDHE-ECDSA-AES256-GCM-SHA384 - ECDHE-RSA-AES256-GCM-SHA384 - ECDHE-ECDSA-CHACHA20-POLY1305 - ECDHE-RSA-CHACHA20-POLY1305 - DHE-RSA-AES128-GCM-SHA256 - DHE-RSA-AES256-GCM-SHA384 minTLSVersion: VersionTLS12 |
|
`` |
modern is a TLS security profile based on: https://wiki.mozilla.org/Security/Server_Side_TLS#Modern_compatibility and looks like this (yaml): ciphers: - TLS_AES_128_GCM_SHA256 - TLS_AES_256_GCM_SHA384 - TLS_CHACHA20_POLY1305_SHA256 minTLSVersion: VersionTLS13 |
|
`` |
old is a TLS security profile based on: https://wiki.mozilla.org/Security/Server_Side_TLS#Old_backward_compatibility and looks like this (yaml): ciphers: - TLS_AES_128_GCM_SHA256 - TLS_AES_256_GCM_SHA384 - TLS_CHACHA20_POLY1305_SHA256 - ECDHE-ECDSA-AES128-GCM-SHA256 - ECDHE-RSA-AES128-GCM-SHA256 - ECDHE-ECDSA-AES256-GCM-SHA384 - ECDHE-RSA-AES256-GCM-SHA384 - ECDHE-ECDSA-CHACHA20-POLY1305 - ECDHE-RSA-CHACHA20-POLY1305 - DHE-RSA-AES128-GCM-SHA256 - DHE-RSA-AES256-GCM-SHA384 - DHE-RSA-CHACHA20-POLY1305 - ECDHE-ECDSA-AES128-SHA256 - ECDHE-RSA-AES128-SHA256 - ECDHE-ECDSA-AES128-SHA - ECDHE-RSA-AES128-SHA - ECDHE-ECDSA-AES256-SHA384 - ECDHE-RSA-AES256-SHA384 - ECDHE-ECDSA-AES256-SHA - ECDHE-RSA-AES256-SHA - DHE-RSA-AES128-SHA256 - DHE-RSA-AES256-SHA256 - AES128-GCM-SHA256 - AES256-GCM-SHA384 - AES128-SHA256 - AES256-SHA256 - AES128-SHA - AES256-SHA - DES-CBC3-SHA minTLSVersion: VersionTLS10 |
|
|
type is one of Old, Intermediate, Modern or Custom. Custom provides the ability to specify individual TLS security profile parameters. Old, Intermediate and Modern are TLS security profiles based on: https://wiki.mozilla.org/Security/Server_Side_TLS#Recommended_configurations The profiles are intent based, so they might change over time as new ciphers are developed and existing ciphers are found to be insecure. Depending on precisely which ciphers are available to a process, the list might be reduced. Note that the Modern profile is currently not supported because it is not yet well adopted by common software libraries. |
- Description
-
User data collection switches
- Type
-
object
| Property | Type | Description |
|---|---|---|
|
|
|
|
|