Platforms
Each ticked platform gets its own section in the env file, and each section declares that platform. A file declaring more than one needs
--platform on every command. Blank fields everywhere mean the CLI default; the placeholder shows it.e.g. Asia/Singapore. Applies to every platform.
Image
A version number, not latest: the health check needs one to prove 10.26+.
Prefixed to the broker image and the operator image, e.g. registry.example.com:5000.
With both a user and a password, Kubernetes gets a pull Secret built from them (and the operator a regcred); docker and podman log in.
Redundancy
The node table is read by docker and podman only, and is identical in the env file on all three hosts. Standalone needs no name: the host's own hostname is used.
Mandatory for docker/podman HA:
openssl rand -base64 32, the same value on all three hosts. Optional on Kubernetes (the operator generates one), where it needs the admin password.Credentials
Mandatory on docker/podman. On Kubernetes it builds the admin Secret; left out, the CR references kubernetes.adminSecret or the operator generates one.
Additional CLI users
A name starts with a letter or
_, at most 32 characters; on Kubernetes only letters, digits and _. Name, level and password reach the broker at boot on every platform.TLS
The paths go into the env file. The file pickers only feed the Secret preview: a browser cannot read a path.
CA chain, presented after the certificate, in this order
The Kubernetes CRD has no field for it, so a Kubernetes run refuses one.
Scaling
The tier fixes the broker's cpu and defaults its memory on every platform. Solace resource calculator
Broker operations
Applied by
broker configure product-keys.Domain certificates
Directories walked one level deep
A name is letters, digits,
_ . -, at most 64 characters. Loaded by broker configure domain-certs.Replication
This block is byte-identical at both sites: each broker finds itself by router name, and the other entry is its mate.
Replicated message VPNs
Kubernetes: cluster and broker
A DNS label, at most 48 characters.
kubectl or oc, plus arguments (e.g.
kubectl --kubeconfig /path). Anything else, such as microk8s kubectl, needs --allow-command on each run.Kubernetes: Secret names
Leave a name blank to derive it when this file supplies the material (
<name>-admin, -tls, -image-pull). A name with no material behind it references a Secret someone else made.Kubernetes: storage and memory
Provisions a volume. Cannot be combined with the existing claims below.
Mandatory unless every node mounts an existing claim.
A Kubernetes quantity. CPU has no field: the tier fixes it.
Existing PersistentVolumeClaims (never created or deleted by this tool)
Kubernetes: operator
Without a registry: image.registry is prefixed.
Unticked with no list watches every namespace.
operator deploy merges this with what a running operator already watches; the preview shows operator generate.Kubernetes: security context
Every id is optional and plain decimal;
0 means the operator's default (1000001/1000002), or on OpenShift an id the SCC assigns. The operator itself pins privileged off, all capabilities dropped and no privilege escalation. A read-only root filesystem is not supported.Kubernetes: pod metadata
Kubernetes: placement
Node affinity: preferred terms (expressions one per line:
key Operator v1,v2)Operators: In, NotIn, Exists, DoesNotExist, Gt, Lt. In, NotIn, Gt and Lt need values.
Pod affinity terms (weight 1-100 prefers; blank or 0 requires)
Pod anti-affinity terms, after the broker-spread term
Kubernetes: load balancer
Kubernetes: service ports
Name (a DNS label, at most 15 characters), container port, service port, protocol. Left empty, the CR carries no ports and the operator's own default list applies (shown, commented out, by
solace-util examples); a list you add replaces that default whole.Docker / Podman: engines
Docker
docker, docker-compose or nerdctl first.
docker-compose for the standalone v1 binary.
Podman
Set only so deploy/remove delete a certificate file an earlier build wrote there.
Docker / Podman: container
Written to every ticked container platform. The artifacts always run with privileged off, every capability dropped and no-new-privileges.
0:0 is host root on docker and rootful podman.
Absolute. Bind-mounted at /var/lib/solace.
b, k, m or g suffix, not Mi/Gi.
Which cpus: exactly the tier's count.
-1 or bytes; 0 keeps none on disk.
Docker / Podman: health check
Docker / Podman: network
bridge publishes the list below and nothing else -- nothing at all when it is empty. host is an opt-in widening: every listener binds on every host interface.
An HA member also publishes 8300-8302, 8741 and 55555, and SEMP (8080, or 1943 with TLS) for its mate.
Env file
solace-util operator generate
solace-util broker generate