Configuration reference

This page lists the configuration of the Penpot deployment. The source of truth is dp-infra/penpot/config.yaml. Every change requires pnpm run build and a commit of the regenerated manifests/.

Deployment configuration

dp-infra/penpot/config.yaml holds all non-secret configuration.

Key

Value

Notes

namespace

penpot

domain

penpot.kup.tirol

CNAME to lb.kup6s.net

versions.helmChart

1.10.0

Renovate-annotated, helm datasource

versions.penpot

2.18.0

Applied to all five component image tags

versions.valkey

9-alpine

versions.postgresMajor

16

Pinned through the CNPG imageName

flags

see below

Passed as PENPOT_FLAGS

registrationDomainWhitelist

kleinundpartner.at

Comma-separated list of email domains

backupSchedule

0 45 2 * * *

CNPG cron format, seconds first

Feature flags

The flags value is passed verbatim as PENPOT_FLAGS.

Flag

Effect

enable-login-with-password

Password authentication

enable-smtp

Outgoing mail through Mailjet

enable-mcp

Renders the MCP deployment and its nginx routes

enable-admin-console

Renders the admin console deployment and its nginx route

Penpot ignores unknown flag tokens without an error, so a typo silently disables a feature. The MCP and admin console deployments exist only while their flags are present.

You must not add disable-registration. Penpot validates the registration flag before it reads an invitation token, so that flag prevents invited people from creating an account at all.

Email verification stays enabled, because disable-email-verification is absent.

Storage

Bucket

Region

ProviderConfig

Contents

assets-penpot-kup6s

hel1

hetzner-s3-hel1

Design assets, hot path

backups-penpot-kup6s

fsn1

hetzner-s3

CNPG base backups and WAL

Both buckets use deletionPolicy: Orphan, so deleting the Crossplane resource keeps the data.

The Longhorn footprint is the 10Gi PostgreSQL volume and the 1Gi Valkey volume. The assets PVC is disabled (persistence.assets.enabled: false).

Secrets

Source secrets live in the application-secrets namespace and are projected by External Secrets Operator.

Target secret

Keys

Source

penpot-app-secrets

api-secret-key

penpot-app-secrets/PENPOT_SECRET_KEY

penpot-smtp-secrets

username, password

penpot-smtp-secrets/SMTP_USERNAME, SMTP_PASSWORD

penpot-s3-credentials

AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY

cluster-wide hetzner-s3-creds-standard

penpot-postgres-app

username, password

Generated by CloudNativePG

Create the source secrets with dp-infra/penpot/scripts/bootstrap-secrets.sh. The script reuses the fleet Mailjet credentials from solidtime-smtp-secrets unless you set MAILJET_SOURCE_SECRET.

Warning

Never rotate PENPOT_SECRET_KEY. It signs persistent sessions, so rotating it logs out every user and breaks the admin console pairing.

You must write refreshInterval as 1h0m0s in every ExternalSecret. The API server normalizes 1h to 1h0m0s, which ArgoCD reports as a permanent difference and self-heal then re-applies in a loop.

Resources

Component

Requests

Limits

Frontend

50m / 64Mi

500m / 256Mi

Backend

250m / 1Gi

1500m / 2Gi

Exporter

100m / 512Mi

1000m / 2Gi

MCP

50m / 256Mi

500m / 512Mi

Admin console

50m / 256Mi

500m / 512Mi

PostgreSQL

100m / 256Mi

500m / 1Gi

Valkey

100m / 128Mi

500m / 512Mi

Pod disruption budgets are disabled for every component (pdb.enabled: false). A budget on a single-replica deployment deadlocks node drains.

The chart names that key pdb, and its values.schema.json rejects unknown keys. Writing podDisruptionBudget fails schema validation before templating, and the release never installs.

nginx configuration

dp-infra/penpot/files/nginx.conf is a copy of the frontend image’s /etc/nginx/nginx.conf with two changes.

Directive

Image

Deployment

worker_processes

auto

2

worker_connections

65535

4096

The file is mounted over the image’s own copy through a ConfigMap. Re-extract it after a Penpot upgrade:

kubectl -n penpot exec deploy/penpot-frontend -- cat /etc/nginx/nginx.conf

Sync waves

Wave

Objects

0

Namespace, ClusterSecretStore

1

Three ExternalSecret resources

2

Crossplane buckets, barman ObjectStore, Valkey

3

CNPG cluster, ScheduledBackup, nginx ConfigMap

4

HelmChart