Property reference
Camunda Hub Self-Managed consists of two components: restapi and websocket.
Each component is configured separately as described below.
- The
restapicomponent is a Spring Boot application. Its configuration is stored in a YAML file (application.yml) by default. All Camunda Hub-specific settings are prefixed withcamunda.hub. - The
websocket(PHP/Laravel) component is configured via environment variables.
The two components support configuration through environment variables.
For the restapi component, environment variables can be used as an alternative to application.yml following Spring Boot conventions: convert the property to uppercase, remove any dashes, and replace any delimiters (.) with _.
For example, the property camunda.hub.clusters[0].name is represented by the environment variable CAMUNDA_HUB_CLUSTERS_0_NAME.
If you are using the Camunda 8 Helm chart, read more about the different configuration options in the chart's Helm chart values documentation.
You can pass environment variables to each component via camundaHub.restapi.env and camundaHub.websocket.env in your values.yaml.
For which settings belong in the chart and which belong here, see Helm and application configuration responsibilities. The recommended path for the properties on this page is camundaHub.restapi.extraConfiguration.
For a working example configuration showing how the components are correctly wired together, see the Docker Compose file for Camunda Hub.
Licensing
Camunda 8 Self-Managed onlyInstallations of Camunda 8 Self-Managed which require a license can provide their license key to the components as an environment variable:
| Environment variable | Description | Default value |
|---|---|---|
CAMUNDA_LICENSE_KEY | Your Camunda 8 license key, if your installation requires a license. | None |
For Helm installations, license keys can be configured globally in your values.yaml file. See the License key for more details.
Camunda 8 components without a valid license may display Non-Production License in the navigation bar and issue warnings in the logs. These warnings have no impact on startup or functionality.
Camunda Hub without a license: Camunda Hub is limited to five concurrent users when running without a valid enterprise license. This applies to Self-Managed installations used for testing or development purposes. To support additional users or for production use, obtain a Camunda Self-Managed Enterprise Edition license by visiting the Camunda Enterprise page.
Configuration of the restapi component
As a Spring Boot application, the restapi component supports any standard Spring configuration method.
The tables below list each setting in two formats:
- Application properties – the property names used in
application.yml, the native Spring Boot configuration file format. - Environment variables – suitable for Docker Compose or direct shell usage.
When running the restapi component in a container (Docker / Kubernetes), use the JAVA_TOOL_OPTIONS environment variable to pass JVM arguments, for example for trust store settings or proxy configuration.
General
- Application properties
- Environment variables
| Property | Description | Example value | Default value |
|---|---|---|---|
camunda.hub.server.url | URL at which users access Camunda Hub in the browser (used to construct redirect URLs in the client-side login flow as well as links in notification emails). | https://hub.example.com,https://example.com/hub | - |
server.servlet.context-path | [optional] Context path of the URL. Must be set if camunda.hub.server.url does not point to the root path of a (sub-)domain. | /hub | - |
camunda.hub.server.https-only | [optional] Enforce the usage of HTTPS when users access Camunda Hub (by redirecting from http:// to https://). | true | true |
| Environment variable | Description | Example value | Default value |
|---|---|---|---|
CAMUNDA_HUB_SERVER_URL | URL at which users access Camunda Hub in the browser (used to construct redirect URLs in the client-side login flow as well as links in notification emails). | https://hub.example.com,https://example.com/hub | - |
SERVER_SERVLET_CONTEXTPATH | [optional] Context path of the URL. Must be set if CAMUNDA_HUB_SERVER_URL does not point to the root path of a (sub-)domain. | /hub | - |
CAMUNDA_HUB_SERVER_HTTPSONLY | [optional] Enforce the usage of HTTPS when users access Camunda Hub (by redirecting from http:// to https://). | true | true |
Clusters
To show your Orchestration Clusters in Camunda Hub, use the following configuration options available from Camunda 8.10. If you're migrating from an older version of Camunda Self-Managed, refer to the deprecated legacy configurations and the migration guide.
The Camunda 8.10 Helm chart can deploy one Hub release with orchestration releases from supported chart versions:
| Hub chart | Orchestration chart | Topology mode |
|---|---|---|
| 8.10 | 8.10 | orchestration |
| 8.10 | 8.9 | orchestration |
| 8.10 | 8.8 | orchestration |
| 8.10 | 8.7 | orchestration |
Set global.topology.mode: orchestration in each orchestration release. The 8.7, 8.8, and 8.9 charts don't support Hub mode or global.topology.clusters; configure the Hub release and cluster inventory with the 8.10 chart.
An orchestration release must disable its local Management Identity and set global.identity.service.url to the Management Identity service in the Hub release. Chart 8.7 uses separate Zeebe, Operate, and Tasklist components, so its Hub inventory must use the legacy component endpoints rather than the unified Orchestration Cluster endpoints.
Management Identity cluster
If identity.enabled is true for a Hub release, the Helm chart automatically adds a management-cluster entry named Management Identity to camunda.hub.clusters, containing only the Hub's own Management Identity component. This entry appears in the Clusters pages alongside your Orchestration Cluster registrations so Console and DevOps role holders can manage the Hub's Management Identity instance. You don't need to configure this entry manually, and it isn't affected by dynamic cluster management.
Access to the cluster pages in Camunda Hub depends on the user's role: Console and DevOps role holders (users with the admin:clusters permission) get management access to the cluster pages, Hub admins (users with the admin:* permission) get full access, and other Hub members get read-only access.
- Application properties
- Environment variables
| Property | Description | Example value |
|---|---|---|
camunda.hub.clusters[0].id | An identifier for the cluster. | camunda-platform |
camunda.hub.clusters[0].name | A readable name for the cluster. | Camunda Platform |
camunda.hub.clusters[0].version | The cluster version. | 8.10.0 |
camunda.hub.clusters[0].tags | A list of tags. The tags appear on every environment of the cluster. Use prod to mark production. | ['dev', 'test'] |
camunda.hub.clusters[0].authentication | The authentication method. | BEARER_TOKEN |
camunda.hub.clusters[0].authorizations.enabled | Enables or disables authorizations for the cluster. If enabled, users see a hint when they deploy from Camunda Hub. | true |
camunda.hub.clusters[0].custom-properties | A list of custom properties. | See custom properties. |
camunda.hub.clusters[0].components | A list of components for the clusters. | See components. |
| Environment variable | Description | Example value |
|---|---|---|
CAMUNDA_HUB_CLUSTERS_0_ID | An identifier for the cluster. | camunda-platform |
CAMUNDA_HUB_CLUSTERS_0_NAME | A readable name for the cluster. | Camunda Platform |
CAMUNDA_HUB_CLUSTERS_0_VERSION | The cluster version. | 8.10.0 |
CAMUNDA_HUB_CLUSTERS_0_TAGS | A list of tags. The tags appear on every environment of the cluster. Use prod to mark production. | ['dev', 'test'] |
CAMUNDA_HUB_CLUSTERS_0_AUTHENTICATION | The authentication method. | BEARER_TOKEN |
CAMUNDA_HUB_CLUSTERS_0_AUTHORIZATIONS_ENABLED | Enables or disables authorizations for the cluster. If enabled, users see a hint when they deploy from Camunda Hub. | true |
CAMUNDA_HUB_CLUSTERS_0_CUSTOMPROPERTIES | A list of custom properties. | See custom properties. |
CAMUNDA_HUB_CLUSTERS_0_COMPONENTS | A list of components for the cluster. | See components. |
Available authentication methods
Clusters must be configured using the following options to access the cluster from within Camunda Hub:
| Method | Description | When to use? |
|---|---|---|
BEARER_TOKEN | Camunda Hub sends the authenticated user's token in the Authorization header with every request to the cluster. | Cluster version >= 8.8 The cluster uses OIDC authentication with the same identity provider as Camunda Hub. Note: You need to ensure that the cluster accepts Camunda Hub's token audience. |
BASIC | Camunda Hub sends a username and password with every request to the cluster. The credentials have to be provided by the user in the UI. | Cluster version >= 8.8 The cluster uses Basic authentication. Console limitation Console pages in Camunda Hub don't support clusters configured with Basic authentication. Console requests to the Orchestration Cluster are made automatically in the background, so there is no UI to collect credentials. Clusters using Basic authentication will not work correctly with Camunda Hub's Console functionality. |
NONE | Camunda Hub does not send any authentication information. | Cluster version >= 8.8 The cluster API is configured as unprotected and can be used without authentication. |
Custom properties
Use custom properties to include helpful links in the Clusters user interface:
- Application properties
- Environment variables
| Property | Description |
|---|---|
camunda.hub.clusters[0].custom-properties[0].description | A description of the custom property. |
camunda.hub.clusters[0].custom-properties[0].links | A list of links. |
camunda.hub.clusters[0].custom-properties[0].links[0].name | A name for the link. |
camunda.hub.clusters[0].custom-properties[0].links[0].url | The link's URL. |
Example configuration:
camunda:
hub:
clusters:
- id: camunda-platform
# other fields...
custom-properties:
- description: This is the integration environment for the Camunda platform.
links:
- name: Camunda
url: https://camunda.com/
- name: Documentation
url: https://docs.camunda.io/
| Environment variable | Description |
|---|---|
CAMUNDA_HUB_CLUSTERS_0_CUSTOMPROPERTIES_0_DESCRIPTION | A description of the custom property. |
CAMUNDA_HUB_CLUSTERS_0_CUSTOMPROPERTIES_0_LINKS_0_NAME | A name for the indexed link. |
CAMUNDA_HUB_CLUSTERS_0_CUSTOMPROPERTIES_0_LINKS_0_URL | The link's URL. |
Example configuration:
CAMUNDA_HUB_CLUSTERS_0_CUSTOMPROPERTIES_0_DESCRIPTION="This is the integration environment for the Camunda platform."
CAMUNDA_HUB_CLUSTERS_0_CUSTOMPROPERTIES_0_LINKS_0_NAME=Camunda
CAMUNDA_HUB_CLUSTERS_0_CUSTOMPROPERTIES_0_LINKS_0_URL=https://camunda.com/
Components
- Application properties
- Environment variables
Use components to set up components in the cluster:
| Property | Description |
|---|---|
camunda.hub.clusters[0].components[0].name | The component's name. |
camunda.hub.clusters[0].components[0].type | The component's type. |
camunda.hub.clusters[0].components[0].version | The component's version. |
camunda.hub.clusters[0].components[0].urls.webapp | The API base URL for all components with a web app: Admin, Management Identity, Optimize, Tasklist, Operate. |
camunda.hub.clusters[0].components[0].urls.rest | The REST API base URL for Connectors and the Orchestration Cluster. |
camunda.hub.clusters[0].components[0].urls.grpc | The address of the Zeebe gRPC API. |
camunda.hub.clusters[0].components[0].urls.readiness | The address of the health check endpoint. |
Use CAMUNDA_HUB_CLUSTERS_0_COMPONENTS to set up components in the cluster:
| Environment variable | Description |
|---|---|
CAMUNDA_HUB_CLUSTERS_0_COMPONENTS_0_NAME | The component's name. |
CAMUNDA_HUB_CLUSTERS_0_COMPONENTS_0_TYPE | The component's type. |
CAMUNDA_HUB_CLUSTERS_0_COMPONENTS_0_VERSION | The component's version. |
CAMUNDA_HUB_CLUSTERS_0_COMPONENTS_0_URLS_WEBAPP | The API base URL for all components with a web app: Admin, Management Identity, Optimize, Tasklist, Operate. |
CAMUNDA_HUB_CLUSTERS_0_COMPONENTS_0_URLS_REST | The REST API base URL for Connectors and the Orchestration Cluster. |
CAMUNDA_HUB_CLUSTERS_0_COMPONENTS_0_URLS_GRPC | The address of the Zeebe gRPC API. |
CAMUNDA_HUB_CLUSTERS_0_COMPONENTS_0_URLS_READINESS | The address of the health check endpoint. |
Available component types and requirements:
| Configuration value | Component | Requirements |
|---|---|---|
connectors | Connectors | REST URL |
identity | Management Identity | - |
hub | Camunda Hub | - |
operate | Operate | - |
optimize | Optimize | - |
orchestration | Orchestration Cluster | Cluster version >= 8.8, gRPC URL, and REST URL |
admin | Admin | - |
tasklist | Tasklist | - |
The old values webModelerWebApp (replaced by hub) and orchestrationIdentity (replaced by admin) are still accepted for backward compatibility.
Example configuration:
- Application properties
- Environment variables
camunda:
hub:
clusters:
- id: camunda-platform
# other fields...
components:
- name: "Orchestration Cluster"
type: "orchestration"
version: "8.10-SNAPSHOT"
urls:
grpc: "grpcs://camunda.example.com:26500"
rest: "https://camunda.example.com"
readiness: "https://camunda.example.com:9600/core/actuator/health/readiness"
- name: "Orchestration Admin"
type: "admin"
version: "8.10-SNAPSHOT"
urls:
webapp: "https://camunda.example.com"
readiness: "https://camunda.example.com:9600/core/actuator/health/readiness"
CAMUNDA_HUB_CLUSTERS_0_COMPONENTS_0_NAME='Orchestration Cluster'
CAMUNDA_HUB_CLUSTERS_0_COMPONENTS_0_TYPE=orchestration
CAMUNDA_HUB_CLUSTERS_0_COMPONENTS_0_VERSION=8.10-SNAPSHOT
CAMUNDA_HUB_CLUSTERS_0_COMPONENTS_0_URLS_GRPC=grpcs://camunda.example.com:26500
CAMUNDA_HUB_CLUSTERS_0_COMPONENTS_0_URLS_REST=https://camunda.example.com
CAMUNDA_HUB_CLUSTERS_0_COMPONENTS_0_URLS_READINESS=https://camunda.example.com:9600/core/actuator/health/readiness
CAMUNDA_HUB_CLUSTERS_0_COMPONENTS_1_NAME='Orchestration Admin'
CAMUNDA_HUB_CLUSTERS_0_COMPONENTS_1_TYPE=admin
CAMUNDA_HUB_CLUSTERS_0_COMPONENTS_1_VERSION=8.10-SNAPSHOT
CAMUNDA_HUB_CLUSTERS_0_COMPONENTS_1_URLS_WEBAPP=https://camunda.example.com
CAMUNDA_HUB_CLUSTERS_0_COMPONENTS_1_URLS_READINESS=https://camunda.example.com:9600/core/actuator/health/readiness
Mark a cluster as production
This step is optional. Tag a cluster with prod only if you want Camunda Hub to treat its environments as production environments. Camunda Hub treats an environment as a production environment if the tags of its cluster include prod. The match is exact and case-sensitive, so prod works but Prod and production don't. All Physical Tenants of a cluster tagged prod are production environments. See the project deployment settings.
camunda:
hub:
clusters:
- id: camunda-platform
# other fields...
tags: ["prod"]
Physical tenants
Declare the Physical Tenants of your clusters in the Camunda Hub configuration. Camunda Hub surfaces each declared Physical Tenant, and the default Physical Tenant of every cluster, as an environment that teams deploy to. An environment appears only if its cluster is in your configuration. Camunda Hub reads the cluster configuration once at startup on every instance, so after you change it, perform a rolling restart.
The version of the cluster decides which Physical Tenants Camunda Hub surfaces as environments:
| Cluster version | Environments |
|---|---|
| 8.10 or later | One for the default Physical Tenant, which always exists, plus one for each Physical Tenant you declare under physical-tenants. Camunda Hub names the default one after the cluster. |
| Earlier than 8.10 | One environment for the whole cluster, named after the cluster. |
If you declare physical-tenants on a cluster earlier than 8.10, Camunda Hub ignores them and logs a warning.
Declare physical tenants
Declare each additional Physical Tenant of a cluster with physical-tenants. Camunda Hub uses the ID of a tenant as the name of its environment, except for the default tenant.
| Property | Description | Required |
|---|---|---|
camunda.hub.clusters[0].physical-tenants[0].id | The ID of the Physical Tenant. Camunda Hub shows it as the environment name. | Yes |
camunda.hub.clusters[0].physical-tenants[0].components | The components that differ from the cluster for this tenant. Each component needs a type and a version. | No |
Example configuration:
camunda:
hub:
clusters:
- id: camunda-platform
# other fields...
physical-tenants:
- id: payments-prod
- id: lending-prod
Each Physical Tenant of a cluster shows the same tags as the cluster. The tenant inherits the web application addresses of the cluster, and Camunda Hub adds the /physical-tenants/<tenant ID> path for the tenants other than default.
Override components for a physical tenant
Use components on a Physical Tenant to point it at its own component instances. This is a partial override:
- Only the component types you list are replaced for the tenant. A listed component replaces the cluster entry completely, so set every address the tenant needs, such as
urls.webappandurls.readiness. - Every other component keeps using the configuration of the cluster, and follows later changes to it.
- A tenant other than
defaultnever inherits Optimize from the cluster, because Optimize needs its own instance for each Physical Tenant. Add anoptimizecomponent to the tenant to show Optimize. - If you remove the override and restart Camunda Hub, the component uses the configuration of the cluster again.
Example configuration that overrides only Optimize for the payments-prod tenant. The other components still come from the cluster:
camunda:
hub:
clusters:
- id: camunda-platform
# other fields...
physical-tenants:
- id: payments-prod
components:
- type: optimize
version: 8.10.0
urls:
webapp: https://optimize-payments-prod.example.com
readiness: https://optimize-payments-prod.example.com/api/readyz
If a cluster earlier than 8.10 declares components on a tenant, Camunda Hub fails to start with the message must not declare physical tenant 'components' if 'version' is lower than the minimum physical tenant version.
Environment status
Camunda Hub sends an HTTP request to the urls.readiness address of each component of an environment to determine its status. The status of the environment is the worst result of its components:
| Component response | Status |
|---|---|
A successful response, with no body or with a status of up or ready | Healthy |
An error response, or any other status | Unhealthy |
No readiness address, no response within five seconds, a redirect, or a body without a status field | Unknown |
A cluster that you configure with url instead of components has no readiness address, so its environments always have the status Unknown.
Not reported environments
If you remove a cluster or Physical Tenant from the configuration, but its environment is still assigned to a workspace, the environment stays in Camunda Hub with the status Not reported. It shows no live data, and you can't select it for a deployment. Remove the assignment from the workspace when you no longer need it.
Database
Camunda Hub currently supports PostgreSQL, Oracle, Microsoft SQL Server (MSSQL), MySQL, MariaDB, and H2 as persistent data storage.
- Application properties
- Environment variables
| Property | Description | Example value |
|---|---|---|
spring.datasource.url | JDBC URL of the database | jdbc:postgresql://postgres.example.com:5432/hub-db |
spring.datasource.username | Database user name | hub-user |
spring.datasource.password | Database user password | *** |
spring.datasource.driver-class-name | [optional] Java class name of the database driver | software.amazon.jdbc.Driver |
spring.datasource.hikari.schema | [optional; only supported for PostgreSQL] Database schema. Defaults to the default schema of the database user (usually public) if not set.Refer to the PostgreSQL documentation for naming restrictions. | custom_schema |
| Environment variable | Description | Example value |
|---|---|---|
SPRING_DATASOURCE_URL | JDBC URL of the database | jdbc:postgresql://postgres.example.com:5432/hub-db |
SPRING_DATASOURCE_USERNAME | Database user name | hub-user |
SPRING_DATASOURCE_PASSWORD | Database user password | *** |
SPRING_DATASOURCE_DRIVERCLASSNAME | [optional] Java class name of the database driver | software.amazon.jdbc.Driver |
SPRING_DATASOURCE_HIKARI_SCHEMA | [optional; only supported for PostgreSQL] Database schema. Defaults to the default schema of the database user (usually public) if not set.Refer to the PostgreSQL documentation for naming restrictions. | custom_schema |
Refer to the Advanced Database Configuration Guide for additional details on how to configure Camunda Hub's database connection.
SMTP / email
Camunda Hub requires an SMTP server to send notification emails to users.
- Application properties
- Environment variables
| Property | Description | Example value | Default value |
|---|---|---|---|
spring.mail.host | SMTP server host name | smtp.example.com | - |
spring.mail.port | SMTP server port | 587 | - |
spring.mail.username | [optional] SMTP user name | hub-user | - |
spring.mail.password | [optional] SMTP user password | *** | - |
spring.mail.properties.mail.smtp.auth | [optional] Set to true if you provide a user name and password. | true | true |
spring.mail.properties.mail.smtp.starttls.enable | [optional] Enable TLS encryption for SMTP connections (using STARTTLS). | true | true |
spring.mail.properties.mail.smtp.starttls.required | [optional] Enforce the use of STARTTLS (to prevent fallback to non-protected connections). | true | true |
camunda.hub.mail.from-address | Email address used as the sender of emails sent by Camunda Hub. | noreply@example.com | - |
camunda.hub.mail.from-name | [optional] Name displayed as the sender of emails sent by Camunda Hub. | Camunda | Camunda |
| Environment variable | Description | Example value | Default value |
|---|---|---|---|
SPRING_MAIL_HOST | SMTP server host name | smtp.example.com | - |
SPRING_MAIL_PORT | SMTP server port | 587 | - |
SPRING_MAIL_USERNAME | [optional] SMTP user name | hub-user | - |
SPRING_MAIL_PASSWORD | [optional] SMTP user password | *** | - |
SPRING_MAIL_PROPERTIES_MAIL_SMTP_AUTH | [optional] Set to true if you provide a user name and password. | true | true |
SPRING_MAIL_PROPERTIES_MAIL_SMTP_STARTTLS_ENABLE | [optional] Enable TLS encryption for SMTP connections (using STARTTLS). | true | true |
SPRING_MAIL_PROPERTIES_MAIL_SMTP_STARTTLS_REQUIRED | [optional] Enforce the use of STARTTLS (to prevent fallback to non-protected connections). | true | true |
CAMUNDA_HUB_MAIL_FROMADDRESS | Email address used as the sender of emails sent by Camunda Hub. | noreply@example.com | - |
CAMUNDA_HUB_MAIL_FROMNAME | [optional] Name displayed as the sender of emails sent by Camunda Hub. | Camunda | Camunda |
WebSocket
Camunda Hub uses a WebSocket server to send events (e.g. "file updated", "comment added", "user opened diagram") between the backend and the client application in the browser. This enables features like real-time notifications and immediate UI updates.
- Application properties
- Environment variables
| Property | Description | Example value | Default value |
|---|---|---|---|
camunda.hub.pusher.host | Internal host name of the WebSocket server. | hub-websockets | - |
camunda.hub.pusher.port | Internal port number of the WebSocket server. | 8060 | 8060 |
camunda.hub.pusher.app-id | must be the same as PUSHER_APP_ID | hub | - |
camunda.hub.pusher.key | must be the same as PUSHER_APP_KEY | *** | - |
camunda.hub.pusher.secret | must be the same as PUSHER_APP_SECRET | *** | - |
camunda.hub.pusher.client.host | External host name on which the Camunda Hub client accesses the WebSocket server from the browser. | ws.example.com | - |
camunda.hub.pusher.client.port | External port number on which the Camunda Hub client accesses the WebSocket server from the browser. | 443 | 80 |
camunda.hub.pusher.client.path | [optional] must be the same as PUSHER_APP_PATH | /hub-ws | / |
camunda.hub.pusher.client.force-tls | Enable TLS encryption for WebSocket connections initiated by the browser. | true | false |
| Environment variable | Description | Example value | Default value |
|---|---|---|---|
CAMUNDA_HUB_PUSHER_HOST | Internal host name of the WebSocket server. | hub-websockets | - |
CAMUNDA_HUB_PUSHER_PORT | Internal port number of the WebSocket server. | 8060 | 8060 |
CAMUNDA_HUB_PUSHER_APPID | must be the same as PUSHER_APP_ID | hub | - |
CAMUNDA_HUB_PUSHER_KEY | must be the same as PUSHER_APP_KEY | *** | - |
CAMUNDA_HUB_PUSHER_SECRET | must be the same as PUSHER_APP_SECRET | *** | - |
CAMUNDA_HUB_PUSHER_CLIENT_HOST | External host name on which the Camunda Hub client accesses the WebSocket server from the browser. | ws.example.com | - |
CAMUNDA_HUB_PUSHER_CLIENT_PORT | External port number on which the Camunda Hub client accesses the WebSocket server from the browser. | 443 | 80 |
CAMUNDA_HUB_PUSHER_CLIENT_PATH | [optional] must be the same as PUSHER_APP_PATH | hub-ws | / |
CAMUNDA_HUB_PUSHER_CLIENT_FORCETLS | Enable TLS encryption for WebSocket connections initiated by the browser. | true | false |
Identity / Keycloak
Camunda Hub uses Keycloak as the default authentication provider (using OAuth 2.0 + OpenID Connect) and integrates with Management Identity for user management and authorization (see Manage access and permissions).
Configure Camunda Hub authentication with the properties on this page, not with the Orchestration Cluster's camunda.security.authentication.oidc.* settings. The one exception is the claim that identifies a user: you can also set camunda.security.authentication.oidc.username-claim directly, as an alternative to CAMUNDA_HUB_OAUTH2_TOKEN_USERIDCLAIM (camunda.hub.oauth2.token.user-id-claim). This is unrelated to CAMUNDA_IDENTITY_USERNAMECLAIM (camunda.identity.username-claim), which only sets a user's display name.
See authentication for more details.
- Application properties
- Environment variables
| Property | Description | Example value | Default value |
|---|---|---|---|
camunda.identity.base-url | Internal base URL of the Identity API (used to fetch user data). | http://identity:8080 | - |
camunda.identity.username-claim | [optional] ID token claim used to assign usernames. | preferred_username | name |
camunda.hub.security.jwt.audience.internal-api | Expected value of the audience claim in user access tokens (used for JWT validation). | web-modeler-api | web-modeler-api |
camunda.hub.security.jwt.audience.public-api | Expected value of the audience claim in M2M access tokens required for Camunda Hub's API (used for JWT validation). | web-modeler-public-api | web-modeler-public-api |
camunda.identity.issuer-backend-url | [optional] Internal URL used to request Keycloak's OpenID Provider Configuration; if not set, spring.security.oauth2.resourceserver.jwt.issuer-uri is used. | http://keycloak:18080/auth/realms/camunda-platform | - |
spring.security.oauth2.resourceserver.jwt.issuer-uri | URL of the token issuer (used for JWT validation). | https://keycloak.example.com/auth/realms/camunda-platform | - |
spring.security.oauth2.resourceserver.jwt.jwk-set-uri | [optional] URL of the JWK Set endpoint (used for JWT validation). Only necessary if URL cannot be derived from the OIDC configuration endpoint. | https://keycloak.example.com/auth/realms/camunda-platform/protocol/openid-connect/certs | - |
spring.security.oauth2.resourceserver.jwt.jws-algorithms | [optional] List of trusted JWS algorithms used for JWT validation. Only necessary if the algorithms cannot be derived from the JWK Set response. | ES256 | - |
spring.security.oauth2.resourceserver.jwt.audiences | [optional] Comma-separated list of accepted audience claim values, validated in addition to camunda.hub.security.jwt.audience.internal-api and camunda.hub.security.jwt.audience.public-api. | web-modeler-api | - |
camunda.hub.oauth2.client-id | Client ID of the Camunda Hub application configured in Identity. | web-modeler | - |
camunda.hub.oauth2.client.scope | [optional] OIDC scopes requested during authentication, determining what user information is included in the token. | full | openid email profile |
camunda.hub.oauth2.client.fetch-request-credentials | [optional] Configuration whether credentials should be sent along with requests to the OIDC provider, see documentation. Use this if you are using a proxy that requires cookies. | include | - |
| Environment variable | Description | Example value | Default value |
|---|---|---|---|
CAMUNDA_IDENTITY_BASEURL | Internal base URL of the Identity API (used to fetch user data). | http://identity:8080 | - |
CAMUNDA_IDENTITY_USERNAMECLAIM | ID token claim used to assign usernames. | preferred_username | name |
CAMUNDA_HUB_SECURITY_JWT_AUDIENCE_INTERNALAPI | Expected value of the audience claim in user access tokens (used for JWT validation). | web-modeler-api | web-modeler-api |
CAMUNDA_HUB_SECURITY_JWT_AUDIENCE_PUBLICAPI | Expected value of the audience claim in M2M access tokens required for Camunda Hub's API (used for JWT validation). | web-modeler-public-api | web-modeler-public-api |
CAMUNDA_IDENTITY_ISSUERBACKENDURL | [optional] Internal URL used to request Keycloak's OpenID Provider Configuration; if not set, SPRING_SECURITY_OAUTH2_RESOURCESERVER_JWT_ISSUERURI is used. | http://keycloak:18080/auth/realms/camunda-platform | - |
SPRING_SECURITY_OAUTH2_RESOURCESERVER_JWT_ISSUERURI | URL of the token issuer (used for JWT validation). | https://keycloak.example.com/auth/realms/camunda-platform | - |
SPRING_SECURITY_OAUTH2_RESOURCESERVER_JWT_JWKSETURI | [optional] URL of the JWK Set endpoint (used for JWT validation). Only necessary if URL cannot be derived from the OIDC configuration endpoint. | https://keycloak.example.com/auth/realms/camunda-platform/protocol/openid-connect/certs | - |
SPRING_SECURITY_OAUTH2_RESOURCESERVER_JWT_JWSALGORITHMS | [optional] List of trusted JWS algorithms used for JWT validation. Only necessary if the algorithms cannot be derived from the JWK Set response. | ES256 | - |
SPRING_SECURITY_OAUTH2_RESOURCESERVER_JWT_AUDIENCES | [optional] Comma-separated list of accepted audience claim values, validated in addition to CAMUNDA_HUB_SECURITY_JWT_AUDIENCE_INTERNALAPI and CAMUNDA_HUB_SECURITY_JWT_AUDIENCE_PUBLICAPI. | web-modeler-api | - |
CAMUNDA_HUB_OAUTH2_CLIENTID | Client ID of the Camunda Hub application configured in Identity. | web-modeler | - |
CAMUNDA_HUB_OAUTH2_CLIENT_SCOPE | [optional] OIDC scopes requested during authentication, determining what user information is included in the token. | full | openid email profile |
CAMUNDA_HUB_OAUTH2_CLIENT_FETCHREQUESTCREDENTIALS | [optional] Configuration whether credentials should be sent along with requests to the OIDC provider, see documentation. Use this if you are using a proxy that requires cookies. | include | - |
The restapi component default for CAMUNDA_IDENTITY_USERNAMECLAIM is name.
In Helm-based setups, OIDC configuration commonly uses preferred_username, so usernames may appear as email-style identifiers unless you explicitly set CAMUNDA_IDENTITY_USERNAMECLAIM=name for the Camunda Hub restapi environment.
Refer to the authentication guide for additional details on how Camunda Hub authenticates users, and on how to connect a custom OpenID Connect (OIDC) authentication provider.
Camunda client
Camunda Hub uses the Camunda Java client to connect to Zeebe. To customize the client configuration, you can provide optional properties.
- Application properties
- Environment variables
| Property | Description | Example value | Default value |
|---|---|---|---|
camunda.ca-certificate-path | [optional] Path to a root CA certificate to be used instead of the certificate in the default store. | /path/to/certificate | - |
camunda.client.config-path | [optional] Path to a file used to cache the client's OAuth credentials on disk. When unset, credentials are cached in memory only. | /path/to/credentials/cache.txt | in-memory only |
camunda.client.request-timeout | [optional] The request timeout used when communicating with a target Zeebe cluster. | 60000 | 10000 |
camunda.auth.connect-timeout | [optional] The connection timeout for requests to the OAuth server. | 30000 | 5000 |
camunda.auth.read-timeout | [optional] The data read timeout for requests to the OAuth server. | 30000 | 5000 |
| Environment variable | Description | Example value | Default value |
|---|---|---|---|
CAMUNDA_CA_CERTIFICATE_PATH | [optional] Path to a root CA certificate to be used instead of the certificate in the default store. | /path/to/certificate | - |
CAMUNDA_CLIENT_CONFIG_PATH | [optional] Path to a file used to cache the client's OAuth credentials on disk. When unset, credentials are cached in memory only. | /path/to/credentials/cache.txt | in-memory only |
CAMUNDA_CLIENT_REQUESTTIMEOUT | [optional] The request timeout used when communicating with a target Zeebe cluster. | 60000 | 10000 |
CAMUNDA_AUTH_CONNECT_TIMEOUT | [optional] The connection timeout for requests to the OAuth server. | 30000 | 5000 |
CAMUNDA_AUTH_READ_TIMEOUT | [optional] The data read timeout for requests to the OAuth server. | 30000 | 5000 |
For more details, see the Zeebe connection troubleshooting section.
Logging
- Application properties
- Environment variables
| Property | Description | Example value | Default value |
|---|---|---|---|
logging.config | [optional] Path to custom Log4j2 configuration. | file:/full/path/to/custom-log4j2-spring.xml | - |
camunda.hub.client.logging.level | [optional] Log level for the client. | DEBUG | WARN |
The CAMUNDA_HUB_LOG_LEVEL, CAMUNDA_LOG_FILE_APPENDER_ENABLED, and CAMUNDA_HUB_LOG_APPENDER settings are only available as environment variables.
| Environment variable | Description | Example value | Default value |
|---|---|---|---|
LOGGING_CONFIG | [optional] Path to custom Log4j2 configuration. | file:/full/path/to/custom-log4j2-spring.xml | - |
CAMUNDA_HUB_LOG_LEVEL | [optional] Defines the log level for the Camunda Hub components. | DEBUG | INFO |
CAMUNDA_LOG_FILE_APPENDER_ENABLED | [optional] To enable logging to a file. | true | false |
CAMUNDA_HUB_LOG_APPENDER | [optional] Defines which appender to use for logging. | Stackdriver | Console |
CAMUNDA_HUB_CLIENT_LOGGING_LEVEL | [optional] Log level for the client. | DEBUG | WARN |
Refer to the advanced logging configuration guide for additional details on how to customize the restapi logging output.
- For log level options, see understanding log levels.
SSL
- Application properties
- Environment variables
| Property | Description | Example value | Default value |
|---|---|---|---|
server.ssl.enabled | [optional] Whether to enable SSL support. | true | false |
server.ssl.certificate | [optional] Path to a PEM-encoded SSL certificate file. | file:/full/path/to/certificate.pem | - |
server.ssl.certificate-private-key | [optional] Path to a PEM-encoded private key file for the SSL certificate. | file:/full/path/to/key.pem | - |
management.server.ssl.enabled | [optional] Whether to enable SSL support for the management server routes. | true | false |
management.server.ssl.certificate | [optional] Path to a PEM-encoded SSL certificate file. | file:/full/path/to/certificate.pem | - |
management.server.ssl.certificate-private-key | [optional] Path to a PEM-encoded private key file for the SSL certificate. | file:/full/path/to/key.pem | - |
camunda.hub.pusher.ssl-enabled | [optional] Whether to enable communication via SSL to the websocket component. | true | false |
| Environment variable | Description | Example value | Default value |
|---|---|---|---|
SERVER_SSL_ENABLED | [optional] Whether to enable SSL support. | true | false |
SERVER_SSL_CERTIFICATE | [optional] Path to a PEM-encoded SSL certificate file. | file:/full/path/to/certificate.pem | - |
SERVER_SSL_CERTIFICATEPRIVATEKEY | [optional] Path to a PEM-encoded private key file for the SSL certificate. | file:/full/path/to/key.pem | - |
MANAGEMENT_SERVER_SSL_ENABLED | [optional] Whether to enable SSL support for the management server routes. | true | false |
MANAGEMENT_SERVER_SSL_CERTIFICATE | [optional] Path to a PEM-encoded SSL certificate file. | file:/full/path/to/certificate.pem | - |
MANAGEMENT_SERVER_SSL_CERTIFICATEPRIVATEKEY | [optional] Path to a PEM-encoded private key file for the SSL certificate. | file:/full/path/to/key.pem | - |
CAMUNDA_HUB_PUSHER_SSLENABLED | [optional] Whether to enable communication via SSL to the websocket component. | true | false |
Refer to the advanced SSL configuration guide for additional details on how to set up secure connections (incoming & outgoing) to the Camunda Hub components.
Monitoring and health probes
The restapi component is a Spring Boot application that includes the Spring Boot Actuator, providing health check and metrics endpoints out of the box.
These endpoints are served on a separate management port (default: 8091).
By default, Camunda Hub uses the following actuator configuration:
- Application properties
- Environment variables
| Property | Description | Example value | Default value |
|---|---|---|---|
management.server.port | [optional] Port for the management server (health and metrics endpoints). | 8091 | 8091 |
management.endpoints.access.default | [optional] Default access level for all actuator endpoints. | read-only | none |
management.endpoints.web.exposure.include | [optional] Comma-separated list of actuator endpoints to expose over the web. | health, prometheus | health, info, prometheus, loggers |
management.endpoints.web.base-path | [optional] Base path for all web-exposed actuator endpoints. | /actuator | / |
management.endpoints.web.path-mapping.health | [optional] Custom path mapping for the health endpoint. | health | health |
management.endpoints.web.path-mapping.prometheus | [optional] Custom path mapping for the Prometheus endpoint. | prometheus | metrics |
management.endpoint.prometheus.access | [optional] Access level for the Prometheus endpoint. | unrestricted | read-only |
management.endpoint.health.access | [optional] Access level for the health endpoint. | unrestricted | read-only |
management.endpoint.health.probes.enabled | [optional] Whether Kubernetes-style readiness and liveness probes are enabled. | true | true |
management.endpoint.health.group.readiness.additional-path | [optional] Expose the readiness probe on an additional path (e.g. on the main server port). | server:/health | server:/health |
management.endpoint.info.access | [optional] Access level for the info endpoint. | unrestricted | read-only |
management.endpoint.loggers.access | [optional] Access level for the loggers endpoint. | read-only | unrestricted |
management.info.git.enabled | [optional] Whether Git info is exposed via the info endpoint. | true | false |
management.health.defaults.enabled | [optional] Whether default health indicators are enabled. | true | false |
management.metrics.distribution.percentiles[http.server.requests] | [optional] Comma-separated list of percentiles to publish for HTTP server request metrics. | 0.5, 0.9, 0.99 | 0.5, 0.9, 0.99 |
| Environment variable | Description | Example value | Default value |
|---|---|---|---|
MANAGEMENT_SERVER_PORT | [optional] Port for the management server (health and metrics endpoints). | 8091 | 8091 |
MANAGEMENT_ENDPOINTS_ACCESS_DEFAULT | [optional] Default access level for all actuator endpoints. | read-only | none |
MANAGEMENT_ENDPOINTS_WEB_EXPOSURE_INCLUDE | [optional] Comma-separated list of actuator endpoints to expose over the web. | health, prometheus | health, info, prometheus, loggers |
MANAGEMENT_ENDPOINTS_WEB_BASEPATH | [optional] Base path for all web-exposed actuator endpoints. | /actuator | / |
MANAGEMENT_ENDPOINTS_WEB_PATHMAPPING_HEALTH | [optional] Custom path mapping for the health endpoint. | health | health |
MANAGEMENT_ENDPOINTS_WEB_PATHMAPPING_PROMETHEUS | [optional] Custom path mapping for the Prometheus endpoint. | prometheus | metrics |
MANAGEMENT_ENDPOINT_PROMETHEUS_ACCESS | [optional] Access level for the Prometheus endpoint. | unrestricted | read-only |
MANAGEMENT_ENDPOINT_HEALTH_ACCESS | [optional] Access level for the health endpoint. | unrestricted | read-only |
MANAGEMENT_ENDPOINT_HEALTH_PROBES_ENABLED | [optional] Whether Kubernetes-style readiness and liveness probes are enabled. | true | true |
MANAGEMENT_ENDPOINT_HEALTH_GROUP_READINESS_ADDITIONALPATH | [optional] Expose the readiness probe on an additional path (e.g. on the main server port). | server:/health | server:/health |
MANAGEMENT_ENDPOINT_INFO_ACCESS | [optional] Access level for the info endpoint. | unrestricted | read-only |
MANAGEMENT_ENDPOINT_LOGGERS_ACCESS | [optional] Access level for the loggers endpoint. | read-only | unrestricted |
MANAGEMENT_INFO_GIT_ENABLED | [optional] Whether Git info is exposed via the info endpoint. | true | false |
MANAGEMENT_HEALTH_DEFAULTS_ENABLED | [optional] Whether default health indicators are enabled. | true | false |
MANAGEMENT_METRICS_DISTRIBUTION_PERCENTILES_HTTP_SERVER_REQUESTS | [optional] Comma-separated list of percentiles to publish for HTTP server request metrics. | 0.5, 0.9, 0.99 | 0.5, 0.9, 0.99 |
Available endpoints
| Endpoint | Description |
|---|---|
<server>:8091/metrics | Prometheus metrics |
<server>:8091/health/readiness | Readiness probe |
<server>:8091/health/liveness | Liveness probe |
For more details, including Kubernetes probe configuration examples and websocket health endpoints, see the Monitoring page.
Git Sync
Camunda Hub supports syncing files via Git Sync. Provide the base URL for your provider if you are using a self-hosted GitLab, GitHub, or Azure DevOps Server instance.
- Application properties
- Environment variables
| Provider | Property | Description | Default value |
|---|---|---|---|
| All providers | camunda.hub.git-sync.max-files | Maximum number of allowed files for sync operations. | 100 |
| All providers | camunda.hub.git-sync.max-in-memory-size | Maximum memory size that can be processed by calls to the Git provider. This limits the maximum file size that can be synced. | 4MB |
| GitHub | camunda.hub.git-sync.github.base-url | The base URL of your self-hosted GitHub instance. | https://api.github.com |
| GitLab | camunda.hub.git-sync.gitlab.base-url | The base URL of your self-hosted GitLab instance. | https://gitlab.com/api/v4 |
| Azure DevOps | camunda.hub.git-sync.azure.base-url | The base URL of your self-hosted Azure DevOps Server instance. | https://dev.azure.com |
| Azure DevOps | camunda.hub.git-sync.azure.api-version | The Azure DevOps API versions to use. | 7.1 |
| Azure DevOps | camunda.hub.git-sync.azure.authority-base-path | URL used to access authentication and authorization services for Microsoft cloud identities. | https://login.microsoftonline.com |
| Azure DevOps | camunda.hub.git-sync.azure.scope | OAuth scope requested for Azure DevOps authentication. | https://app.vssps.visualstudio.com/.default |
| Bitbucket | camunda.hub.git-sync.bitbucket.base-url | The base URL of Bitbucket Cloud. | https://api.bitbucket.org/2.0/repositories |
| Provider | Environment variable | Description | Default value |
|---|---|---|---|
| All providers | CAMUNDA_HUB_GITSYNC_MAXFILES | Maximum number of allowed files for sync operations. | 100 |
| All providers | CAMUNDA_HUB_GITSYNC_MAXINMEMORYSIZE | Maximum memory size that can be processed by calls to the Git provider. This limits the maximum file size that can be synced. | 4MB |
| GitHub | CAMUNDA_HUB_GITSYNC_GITHUB_BASEURL | The base URL of your self-hosted GitHub instance. | https://api.github.com |
| GitLab | CAMUNDA_HUB_GITSYNC_GITLAB_BASEURL | The base URL of your self-hosted GitLab instance. | https://gitlab.com/api/v4 |
| Azure DevOps | CAMUNDA_HUB_GITSYNC_AZURE_BASEURL | The base URL of your self-hosted Azure DevOps Server instance. | https://dev.azure.com |
| Azure DevOps | CAMUNDA_HUB_GITSYNC_AZURE_APIVERSION | The Azure DevOps API versions to use. | 7.1 |
| Azure DevOps | CAMUNDA_HUB_GITSYNC_AZURE_AUTHORITYBASEPATH | URL used to access authentication and authorization services for Microsoft cloud identities. | https://login.microsoftonline.com |
| Azure DevOps | CAMUNDA_HUB_GITSYNC_AZURE_SCOPE | OAuth scope requested for Azure DevOps authentication. | https://app.vssps.visualstudio.com/.default |
| Bitbucket | CAMUNDA_HUB_GITSYNC_BITBUCKET_BASEURL | The base URL of Bitbucket Cloud. | https://api.bitbucket.org/2.0/repositories |
Feature flags
- Application properties
- Environment variables
| Property | Description | Example value | Default value |
|---|---|---|---|
camunda.hub.feature.test-mode-enabled | [optional] Enables the Test mode in the BPMN editor, allowing users to test processes in a playground environment. | false | true |
camunda.hub.feature.bpmn-deployment-enabled | [optional] Enables the Deploy and Run actions in the BPMN editor. When disabled, it prevents users from deploying and starting instances of processes via the UI. | false | true |
camunda.hub.feature.dmn-deployment-enabled | [optional] Enables the Deploy action in the DMN editor. When disabled, it prevents users from deploying decisions via the UI. | false | true |
camunda.hub.feature.dynamic-cluster-management-enabled | [optional] Enables dynamic cluster management. | true | false |
camunda.hub.feature.ui-user-invite-enabled | [optional] Enables the Add members button on the workspace Members page for users who aren't Organization admins. Organization admins always see the button, regardless of this setting. Adding members through the Hub API is unaffected. | false | true |
camunda.hub.feature.runtime-connection-enabled | [optional] Enables the runtime connection selector in the BPMN editor. When disabled, task testing uses its own cluster selection and connector credentials aren't offered in the properties panel. | false | true |
camunda.hub.feature.credentials-enabled | [optional] Enables credentials in Camunda Hub. Offering connector credentials in the properties panel of the BPMN editor also requires camunda.hub.feature.runtime-connection-enabled. | false | true |
camunda.hub.feature.marketplace-enabled | [optional] Enables the integration of the Camunda Marketplace. If enabled, users can browse the Marketplace and download resources directly inside Camunda Hub. | false | true |
| Environment variable | Description | Example value | Default value |
|---|---|---|---|
CAMUNDA_HUB_FEATURE_TESTMODEENABLED | [optional] Enables the Test mode in the BPMN editor, allowing users to test processes in a playground environment. | false | true |
CAMUNDA_HUB_FEATURE_BPMNDEPLOYMENTENABLED | [optional] Enables the Deploy and Run actions in the BPMN editor. When disabled, it prevents users from deploying and starting instances of processes via the UI. | false | true |
CAMUNDA_HUB_FEATURE_DMNDEPLOYMENTENABLED | [optional] Enables the Deploy action in the DMN editor. When disabled, it prevents users from deploying decisions via the UI. | false | true |
CAMUNDA_HUB_FEATURE_DYNAMICCLUSTERMANAGEMENTENABLED | [optional] Enables dynamic cluster management. | true | false |
CAMUNDA_HUB_FEATURE_UIUSERINVITEENABLED | [optional] Enables the button for inviting members to a workspace. | false | true |
CAMUNDA_HUB_FEATURE_RUNTIMECONNECTIONENABLED | [optional] Enables the runtime connection selector in the BPMN editor. When disabled, task testing uses its own cluster selection and connector credentials aren't offered in the properties panel. | false | true |
CAMUNDA_HUB_FEATURE_CREDENTIALSENABLED | [optional] Enables credentials in Camunda Hub. Offering connector credentials in the properties panel of the BPMN editor also requires CAMUNDA_HUB_FEATURE_RUNTIMECONNECTIONENABLED. | false | true |
CAMUNDA_HUB_FEATURE_MARKETPLACEENABLED | [optional] Enables the integration of the Camunda Marketplace. If enabled, users can browse the Marketplace and download resources directly inside Camunda Hub. | false | true |
Dynamic cluster management
Use dynamic cluster management to automatically register your clusters with Camunda Hub.
By default, clusters shown in Camunda Hub are strictly managed by your configuration. Cluster registrations are created, updated, and deleted when you change your cluster configuration values.
Dynamic cluster management changes this to a hybrid model. Camunda Hub uses your cluster configuration—if you provide one—alongside the following API endpoints, which are only exposed when dynamic cluster management is enabled:
| Name | Path |
|---|---|
| Create or update a cluster registration | POST /api/v2/clusters |
| Remove a cluster registration | DELETE /api/v2/clusters/{clusterId} |
In this mode, you:
- Configure your Orchestration Clusters to send license information directly to the create or update a cluster registration endpoint. If you didn't define the clusters in your configuration, this call registers them with minimal information and no management functionality in the Camunda Hub interface.
- Remove stale cluster registrations from Camunda Hub using the remove a cluster registration endpoint.
You can still define new clusters in your configuration, though it's not required. When you do, Camunda Hub automatically registers them with all available settings and full management functionality in the interface.
With dynamic cluster management enabled, don't call the create or update cluster registration endpoint manually—only let your cluster configuration do it. The endpoint doesn't yet support creating clusters with all configurable settings.
Hide add members button
Hide the Add members button on the workspace Members page (which is displayed by default):
- Application properties
- Environment variables
camunda:
hub:
feature:
ui-user-invite-enabled: false
CAMUNDA_HUB_FEATURE_UIUSERINVITEENABLED=false
Organization admins always see the button, regardless of this setting. Other users will not see the button. Instead, they must add members with the Camunda Hub API.
Unstable configuration options
These are unstable options that are not officially supported and may be removed without deprecation in future releases. They are intended for testing and feedback purposes only.
- Application properties
- Environment variables
| Property | Description | Example value | Default value |
|---|---|---|---|
camunda.hub.resource-import.allow-private-ip-address | Allow importing resources from a host that resolves to a private IP address. Enabling this option weakens server-side request forgery (SSRF) protections and can significantly increase security exposure. | true | false |
| Environment variable | Description | Example value | Default value |
|---|---|---|---|
CAMUNDA_HUB_RESOURCEIMPORT_ALLOWPRIVATEIPADDRESS | Allow importing resources from a host that resolves to a private IP address. Enabling this option weakens server-side request forgery (SSRF) protections and can significantly increase security exposure. | true | false |
Configuration of the websocket component
The WebSocket server shipped with Camunda Hub Self-Managed is based on the laravel-websockets open source package and implements the Pusher Channels Protocol.
The websocket component is configured via environment variables.
When using the Camunda Helm chart, you can pass these variables via camundaHub.websocket.env in your values.yaml.
See the Helm chart values docs for all available configuration options.
| Environment variable | Description | Example value | Default value |
|---|---|---|---|
PUSHER_APP_ID | ID of the single application/tenant configured for Camunda Hub. | hub | - |
PUSHER_APP_KEY | A unique key used for authentication. Provide a random alphanumeric string of at least 20 characters. | *** | - |
PUSHER_APP_SECRET | A unique secret used for authentication. Provide a random alphanumeric string of at least 20 characters. | *** | - |
PUSHER_APP_PATH | [optional] Base path of the WebSocket endpoint. Can be used to expose the endpoint on a sub path instead of the domain root (e.g. https://example.com/hub-ws). | /hub-ws | / |
Logging
| Environment variable | Description | Example value | Default value |
|---|---|---|---|
LOG_CHANNEL | [optional] Log channel driver, see Laravel documentation | single | stack |
Refer to the Advanced Logging Configuration Guide for additional details on how to customize the websocket logging output.
SSL
| Environment variable | Description | Example value | Default value |
|---|---|---|---|
PUSHER_SSL_CERT | [optional] Path to a PEM-encoded SSL certificate file. | /full/path/to/certificate.pem | - |
PUSHER_SSL_KEY | [optional] Path to a PEM-encoded private key file for the SSL certificate. | /full/path/to/key.pem | - |
PUSHER_SSL_PASSPHRASE | [optional] Passphrase for the private key file. | change-me | - |
Refer to the advanced SSL configuration guide for additional details on how to set up secure connections (incoming & outgoing) to the Camunda Hub components.
Notes on host names and port numbers
- Internal refers to host names and port numbers that are only used inside a Docker Compose network or Kubernetes cluster for backend-to-backend communication.
- External refers to host names and port numbers that are exposed to the outside and can be reached from a web browser.