Kubernetes
Install AnsibleForms and its MySQL database with the Helm chart
- Prerequisites
- 1. Get the chart values
- 2. Configure the storage
- 3. Set the credentials
- 4. Install the chart
- 5. Check the install
- 6. Open AnsibleForms
- 7. Sign in
- Next steps
The Helm chart deploys AnsibleForms with MySQL (see the values reference).
Prerequisites
Before you start, you need:
- Kubernetes cluster : with
kubectlconfigured to reach it - Helm 3 : to install and upgrade the chart
- Storage : a StorageClass for dynamic provisioning, or pre-created PersistentVolumes
- Ingress controller : only if you want to expose AnsibleForms through an ingress
1. Get the chart values
Fetch the chart’s default values into a file of your own, from the chart repository or from the OCI registry:
helm repo add ansibleforms https://ansibleforms.com/helm-charts/
helm repo update
helm show values ansibleforms/ansibleforms > my_values.yaml
No repository to add: the chart is pulled from the GitHub Container Registry.
helm show values oci://ghcr.io/ansibleforms/charts/ansibleforms > my_values.yaml
2. Configure the storage
Both AnsibleForms and MySQL store their data on a persistent volume. Set the StorageClass and size of each:
storages:
server:
className: longhorn
size: 5Gi
accessMode: ReadWriteOnce
mysql:
className: longhorn
size: 5Gi
accessMode: ReadWriteOnce
An empty className uses the cluster’s default StorageClass. The access mode defaults to ReadWriteMany, which many storage classes do not offer; ReadWriteOnce is fine with a single replica. For pre-created PersistentVolumes, see the chart’s README.
3. Set the credentials
AnsibleForms needs an admin account, a database password and an ENCRYPTION_SECRET, the key that encrypts the credentials stored in AnsibleForms. Never change that key once data exists. Supply them in one of three ways:
Set them in my_values.yaml. The chart stores them in a Secret named <release>-secrets:
applications:
server:
env:
ADMIN_USERNAME: admin
ADMIN_PASSWORD: a-strong-password
ENCRYPTION_SECRET: a-random-string-of-32-characters
mysql:
password: a-strong-database-password
Let the chart generate whatever you do not supply, on the first install. It keeps the same values on every upgrade afterwards:
--set secrets.generate=true
This does not work with Argo CD or Flux, which render the chart without access to the cluster. The generated Secret survives helm uninstall; back it up, because ENCRYPTION_SECRET cannot be recovered.
Point the chart at a Secret you manage, for example with External Secrets, Sealed Secrets or SOPS. The chart then creates none:
secrets:
existingSecret: ansibleforms-credentials
The Secret must hold DB_USER, DB_PASSWORD, ENCRYPTION_SECRET, ADMIN_USERNAME and ADMIN_PASSWORD.
4. Install the chart
Install the chart into its own namespace with your values:
helm upgrade --install ansibleforms ansibleforms/ansibleforms \
--namespace ansibleforms --create-namespace \
--values my_values.yaml
With the OCI registry, use oci://ghcr.io/ansibleforms/charts/ansibleforms as the chart. In anything that runs unattended, pin the chart version with --version, so that a new release is never installed on its own.
5. Check the install
The chart includes a test that checks both the web server and the database connection:
helm test ansibleforms --namespace ansibleforms --logs
The test ends with OK when AnsibleForms answers and its database accepts connections.
6. Open AnsibleForms
How you reach AnsibleForms depends on how the server is exposed:
With the default ClusterIP service and no ingress, nothing is exposed outside the cluster. Forward a local port to have a look:
kubectl -n ansibleforms port-forward svc/ansibleforms-server 8080:80
Then open http://127.0.0.1:8080/.
Set services.server.type: LoadBalancer (optionally with a fixed address in services.server.loadbalancer.ip), then wait for the service to get its address:
kubectl -n ansibleforms get svc ansibleforms-server -w
Enable the ingress and set the host name that routes to your ingress controller:
ingress:
enabled: true
className: nginx
hostname: ansibleforms.example.com
tls:
enabled: true
The chart’s README covers TLS behind an ingress, including the backend setting that HTTPS on the server needs.
7. Sign in
Sign in as the admin user, admin by default. To read the password from the Secret:
kubectl -n ansibleforms get secret ansibleforms-secrets \
-o jsonpath='{.data.ADMIN_PASSWORD}' | base64 -d
With secrets.existingSecret, read it from your own Secret instead.
Next steps
The chart’s README covers the rest of the configuration:
- Your own database : set
mysql.enabled: falseand point AnsibleForms at an existing MySQL server - Forms from ConfigMaps : provide
config.yamland the form files through ConfigMaps - HTTPS behind an ingress, resources, node placement and private registries
To move to a newer release, see Upgrading on Kubernetes.