Configuration reference¶
This page lists the configuration of the Penpot deployment.
The source of truth is dp-infra/penpot/config.yaml.
Every change requires pnpm run build and a commit of the regenerated manifests/.
Deployment configuration¶
dp-infra/penpot/config.yaml holds all non-secret configuration.
Key |
Value |
Notes |
|---|---|---|
|
|
|
|
|
CNAME to |
|
|
Renovate-annotated, helm datasource |
|
|
Applied to all five component image tags |
|
|
|
|
|
Pinned through the CNPG |
|
see below |
Passed as |
|
|
Comma-separated list of email domains |
|
|
CNPG cron format, seconds first |
Feature flags¶
The flags value is passed verbatim as PENPOT_FLAGS.
Flag |
Effect |
|---|---|
|
Password authentication |
|
Outgoing mail through Mailjet |
|
Renders the MCP deployment and its nginx routes |
|
Renders the admin console deployment and its nginx route |
Penpot ignores unknown flag tokens without an error, so a typo silently disables a feature. The MCP and admin console deployments exist only while their flags are present.
You must not add disable-registration.
Penpot validates the registration flag before it reads an invitation token, so that flag prevents invited people from creating an account at all.
Email verification stays enabled, because disable-email-verification is absent.
Storage¶
Bucket |
Region |
ProviderConfig |
Contents |
|---|---|---|---|
|
hel1 |
|
Design assets, hot path |
|
fsn1 |
|
CNPG base backups and WAL |
Both buckets use deletionPolicy: Orphan, so deleting the Crossplane resource keeps the data.
The Longhorn footprint is the 10Gi PostgreSQL volume and the 1Gi Valkey volume.
The assets PVC is disabled (persistence.assets.enabled: false).
Secrets¶
Source secrets live in the application-secrets namespace and are projected by External Secrets Operator.
Target secret |
Keys |
Source |
|---|---|---|
|
|
|
|
|
|
|
|
cluster-wide |
|
|
Generated by CloudNativePG |
Create the source secrets with dp-infra/penpot/scripts/bootstrap-secrets.sh.
The script reuses the fleet Mailjet credentials from solidtime-smtp-secrets unless you set MAILJET_SOURCE_SECRET.
Warning
Never rotate PENPOT_SECRET_KEY.
It signs persistent sessions, so rotating it logs out every user and breaks the admin console pairing.
You must write refreshInterval as 1h0m0s in every ExternalSecret.
The API server normalizes 1h to 1h0m0s, which ArgoCD reports as a permanent difference and self-heal then re-applies in a loop.
Resources¶
Component |
Requests |
Limits |
|---|---|---|
Frontend |
50m / 64Mi |
500m / 256Mi |
Backend |
250m / 1Gi |
1500m / 2Gi |
Exporter |
100m / 512Mi |
1000m / 2Gi |
MCP |
50m / 256Mi |
500m / 512Mi |
Admin console |
50m / 256Mi |
500m / 512Mi |
PostgreSQL |
100m / 256Mi |
500m / 1Gi |
Valkey |
100m / 128Mi |
500m / 512Mi |
Pod disruption budgets are disabled for every component (pdb.enabled: false).
A budget on a single-replica deployment deadlocks node drains.
The chart names that key pdb, and its values.schema.json rejects unknown keys.
Writing podDisruptionBudget fails schema validation before templating, and the release never installs.
nginx configuration¶
dp-infra/penpot/files/nginx.conf is a copy of the frontend image’s /etc/nginx/nginx.conf with two changes.
Directive |
Image |
Deployment |
|---|---|---|
|
|
|
|
|
|
The file is mounted over the image’s own copy through a ConfigMap.
Re-extract it after a Penpot upgrade:
kubectl -n penpot exec deploy/penpot-frontend -- cat /etc/nginx/nginx.conf
Sync waves¶
Wave |
Objects |
|---|---|
0 |
Namespace, |
1 |
Three |
2 |
Crossplane buckets, barman |
3 |
CNPG cluster, |
4 |
|