Prerequisites
Before deploying CIVITAS/CORE V2, ensure that your Kubernetes cluster is configured and all required tools are installed.
Cluster Requirements
A Kubernetes cluster with the following properties is required to deploy CIVITAS/CORE V2.
- K8s cluster with non-EOL version and x86_64 architecture. (ARM64 support is planned)
- 3 nodes and at least 8 Cores and 32GiB RAM per node or a single node for no high-availability
- Cluster-wide admin rights to deploy CRDs
- The following subdomain entries of a domain pointing to your ingress controller:
api.domain.exampleidm.domain.exampleportal.domain.exampledashboard.domain.example
Required Cluster Components
- A working Storage Class with
RWOsupport for persistent storage - Any Ingress Controller such as nginx or traefik to route HTTP(S) traffic
- cert-manager with a working
ClusterIssuerto automatically provision TLS certificates
No separate internal/external domain.
CIVITAS/CORE exposes multiple subdomains (e.g. idm, portal, api) under a single base domain.
That base domain is used both inside and outside the cluster, separate internal and external base domains are not supported.
If you require a different domain for cluster-internal communication (e.g. via a reverse proxy or split DNS) CIVITAS/CORE cannot be deployed into that environment.
This is planned to be supported in the future.
No proxy support. CIVITAS/CORE has no supported way to route a component's outbound traffic through a proxy. If your network policy requires all outbound internet traffic to go through a proxy, components that need internet access will be unable to reach it. Proxy support is planned for a future release.
Optional Cluster Components
- Kyverno: for runtime policies, integration is enabled by default.
- Linkerd: for mTLS, integration is enabled by default.
- metrics-server for autoscaling support
While Linkerd is not strictly required, it is highly recommended to use it for its secure service-to-service communication (mTLS) and observability features. Any other service mesh could be used as well, but must be externally configured and tested to ensure compatibility with CIVITAS/CORE V2. We chose Linkerd for the reference deployment due to its simplicity, high performance and low resource usage.
When using Linkerd, check the installation and make sure that proxy.nativeSidecar=true is set in the deployment configuration to increase reliability by using native sidecar injection, especially with init jobs (linkerd documentation).
Tools
The following tools need to be available where you want to perform the installation from.
- kubectl
- Helm version
3.18>=or4 - Helm Diff Plugin
- helmfile
- git
2.0+