This document covers installation parameters as presented to users, and includes how the puppet-based foreman-installer parameters will map to new parameters.
- Using a single parameter when there are multiple variables that should have the same value
- Aim for minimal configuration values for the user
Parameters are split into either mapped or unmapped groupings per category.
Mapped: Parameters the new installer will have and are mapped to a parameter from the foreman-installer.
Unmapped: Parameters from foreman-installer that appear in the official foreman-documentation that are unmapped into the new installer.
These are parameters that are related to the install and operation of the Foreman server and plugins.
There are multiple use cases from the users perspective that dictate what parameters need to be available for user input.
- The user has deployed an external database and needs to specify connection details such as host and port.
- The user wishes to manage passwords externally to the installer and needs to specify rather than use the default randomly generated password.
- The user has deployed an external database configured with TLS and needs to specify the CA certificate.
- The user has to customize the database name and user connecting to each of the databases.
- The user is encountering database pool exhaustion errors and needs to tune the value.
| Parameter | Description | foreman-installer Parameters |
|---|---|---|
--database-mode |
Denotes if the database is internally or externally managed | --foreman-db-manage--katello-candlepin-db-manage--foreman-proxy-content-pulpcore-manage-postgresql |
--database-host |
Hostname application containers use to reach PostgreSQL (postgresql internal; remote host external) |
--foreman-db-host--katello-candlepin-db-host--foreman-proxy-content-pulpcore-postgresql-host |
--database-port |
Port to connect to the database | --foreman-db-port--katello-candlepin-db-port--foreman-proxy-content-pulpcore-postgresql-port |
--database-ssl-mode |
SSL verification mode to use | --foreman-db-sslmode --katello-candlepin-db-ssl-verify --katello-candlepin-db-ssl --foreman-proxy-content-pulpcore-postgresql-ssl |
--database-ssl-ca |
Path to the database CA certificate | --foreman-db-root-cert --katello-candlepin-db-ssl-ca --foreman-proxy-content-pulpcore-db-ssl-root-ca |
--foreman-database-name |
Name of the Foreman database | --foreman-db-database |
--foreman-database-user |
Owner of the Foreman database | --foreman-db-username |
--foreman-database-password |
Password for Foreman database | --foreman-db-password |
--foreman-database-pool |
Tunes the database pool for Foreman | --foreman-db-pool |
--candlepin-database-name |
Name of the Candlepin database | --katello-candlepin-db-name |
--candlepin-database-user |
Owner of the Candlepin database | --katello-candlepin-db-user |
--candlepin-database-password |
Password for Candlepin database | --katello-candlepin-db-password |
--pulp-database-name |
Name of the Pulp database | --foreman-proxy-content-pulpcore-postgresql-db-name |
--pulp-database-user |
Owner of the Pulp database | --foreman-proxy-content-pulpcore-postgresql-user |
--pulp-database-password |
Password for Pulp database | --foreman-proxy-content-pulpcore-postgresql-password |
--initial-admin-username |
Initial username for the admin user | --foreman-initial-admin-username |
--initial-admin-password |
Initial password for the admin user | --foreman-initial-admin-password |
--initial-organization |
Name of an initial organization | --foreman-initial-organization |
--initial-location |
Name of an initial location | --foreman-initial-location |
--foreman-puma-workers |
Number of workers for Puma | --foreman-foreman-service-puma-workers |
--pulp-worker-count |
Number of pulp workers | --foreman-proxy-content-pulpcore-worker-count |
--tuning |
Sets the tuning profile | --tuning |
--air-gapped |
Enables air-gapped deployment using preloaded container images. | |
--content-import-path |
Extra file path that Pulp can use for content imports | --foreman-proxy-content-pulpcore-additional-import-paths |
--content-export-path |
Extra file path that Pulp can use for content exports | |
--external-authentication={ipa,ipa_with_api} |
Enable configuration for external authentication via IPA for web UI (or webUI and API for ipa_with_api), expects the target machine to be enrolled into FreeIPA/IDM |
--foreman-ipa-authentication--foreman-ipa-authentication-api |
--external-authentication-pam-service |
PAM service used for host-based access control in IPA | --foreman-pam-service |
--foreman-trusted-proxy |
Add an IPv4/IPv6 address or CIDR that Foreman trusts for X-Forwarded-For (for example a Foreman Proxy or load balancer in front of Foreman). Invalid hostnames and malformed values are rejected at the CLI. May be specified multiple times; values are persisted in parameters.yaml. Localhost ranges (127.0.0.0/8 and ::1) are always included in Foreman settings and are not controlled by this flag. Example: --foreman-trusted-proxy 10.10.10.20. |
--foreman-trusted-proxies |
--foreman-trusted-proxy-remove |
Remove an IPv4/IPv6 address or CIDR from the persisted trusted proxy list (same format as --foreman-trusted-proxy). May be specified multiple times. Does not remove the localhost ranges 127.0.0.0/8 and ::1. |
|
--reset-foreman-trusted-proxy |
Clear the entire persisted trusted proxy list for this deployment (Obsah reset flag; hidden from the main option list—see foremanctl deploy --help epilog). Use with repeated --foreman-trusted-proxy to replace the list, for example: foremanctl deploy --reset-foreman-trusted-proxy --foreman-trusted-proxy 10.0.0.1 --foreman-trusted-proxy 10.0.0.2. |
| Parameter | Description |
|---|---|
--certificate-source={default,custom_server} |
Defines from where certificates are coming from, whether foremanctl generates its own CA/server certificates (default) or a custom server certificate is supplied (custom_server). |
--certificate-ca-validity-days |
Lifetime of the generated CA certificate, in days. |
--certificate-validity-days |
Lifetime of the generated server and client certificates, in days. |
--certificate-renew |
Regenerate server and client certificates previously generated by foremanctl. Does not regenerate the CA. |
--certificate-ca-renew |
Regenerate the CA certificate. Does not apply to custom certificates. |
| Parameter | Description | foreman-installer Parameter |
|---|---|---|
--server-alias (on deploy) |
Allows defining additional DNS names (SANs) for the main server's certificate | --certs-cname |
--proxy-alias (on auth-bundle) |
Allows defining additional DNS names (SANs) for a secondary system's certificate, e.g. a load-balanced proxy | --foreman-proxy-cname |
--certificate-server-certificate |
Path to a custom server certificate to use instead of the auto-generated one. Requires --certificate-source=custom_server on deploy. |
--certs-server-cert |
--certificate-server-key |
Path to the private key for the custom server certificate. | --certs-server-key |
--certificate-server-ca-certificate (on deploy) |
Path to the CA certificate that signed the custom server certificate. | --certs-server-ca-cert |
| foreman-installer Parameter | Description | Reason |
|---|
| Parameter | Description |
|---|---|
--log-level |
Default log level for all services, unless overridden by the service-specific parameters. Accepted values: debug, info, warn, error, fatal. Defaults to info. |
--valkey-log-level |
Log level for Valkey. Uses Valkey's native levels. Overrides --log-level. Accepted values: debug, verbose, notice, warning & nothing. Defaults to notice. |
--pulp-log-level |
Log level for Pulp. Overrides --log-level for Pulp only. Accepted values: debug, info, warning, error & critical |
| Parameter | Description | foreman-installer Parameters |
|---|---|---|
--foreman-log-level |
Log level for Foreman. Overrides --log-level for Foreman only. |
--foreman-logging-level |
--foreman-proxy-log-level |
Log level for Foreman Proxy. Overrides --log-level for Foreman Proxy only. |
--foreman-proxy-log-level |
| foreman-installer Parameter | Description | Reason |
|---|---|---|
--foreman-loggers |
Enable or disable specific loggers, e.g. {"sql" => true} | No longer supported |
--foreman-logging-layout |
Logging layout of the Foreman application | No longer supported |
--foreman-logging-type |
Logging type of the Foreman application | No longer supported |
--foreman-proxy-log |
Foreman proxy log file | No longer supported |
| foreman-installer Parameter | Description | Module | Puppet Parameter | Keep |
|---|---|---|---|---|
--foreman-foreman-service-puma-threads-min |
foreman | foreman_service_puma_threads_min | --foreman-puma-threads-min |
|
--foreman-foreman-service-puma-threads-max |
foreman | foreman_service_puma_threads_max | --foreman-puma-threads-max |
|
--foreman-dynflow-worker-instances |
foreman | dynflow_worker_instances | ||
--foreman-dynflow-worker-concurrency |
foreman | dynflow_worker_concurrency | ||
--foreman-plugin-tasks-cron-line |
foreman::plugin::tasks | cron_line | ||
--foreman-plugin-tasks-automatic-cleanup |
foreman::plugin::tasks | automatic_cleanup | ||
--foreman-keycloak |
||||
--foreman-keycloak-app-name |
||||
--foreman-keycloak-realm |
||||
--foreman-oauth-map-users |
||||
--foreman-plugin-remote-execution-cockpit-ensure |
||||
--foreman-telemetry-prometheus-enabled |
| Parameter | Description | foreman-installer Parameters |
|---|---|---|
--foreman-fqdn |
FQDN of the Foreman server this proxy connects to | --foreman-proxy-foreman-base-url |
--auth-bundle |
Path to the auth bundle tar file (generated by foremanctl auth-bundle) to be used by proxy |
--certs-tar-file |
--add-feature bmc |
Enable BMC feature | --foreman-proxy-bmc |
--add-feature content/ostree |
Enable OSTree content type | --foreman-proxy-content-enable-ostree |
--bmc-ipmi-implementation |
IPMI implementation to use for BMC | --foreman-proxy-bmc-default-provider |
--bmc-redfish-verify-ssl |
Verify SSL certificates for Redfish BMC connections | --foreman-proxy-bmc-redfish-verify-ssl |
--add-feature templates |
Enable Templates feature on Smart Proxy | --foreman-proxy-templates |
--templates-url |
URL that hosts will use to contact the proxy for provisioning templates | --foreman-proxy-templates-url |
--add-feature registration |
Enable Registration feature | --foreman-proxy-registration |
--registration-url |
URL that hosts use to reach the registration endpoint | --foreman-proxy-registration-url |
| foreman-installer Parameter | Description | Reason |
|---|---|---|
--foreman-proxy-oauth-consumer-key |
OAuth consumer key for Smart Proxy | Not required(Managed automatically via auth bundle) |
--foreman-proxy-oauth-consumer-secret |
OAuth consumer secret for Smart Proxy | Not required(Managed automatically via auth bundle) |
--foreman-proxy-templates-listen-on |
Templates proxy to listen on https, http, or both | No longer supported |
| Installer Parameter | Description | Module | Puppet Parameter |
|---|---|---|---|
--foreman-proxy-fqdn |
FQDN of the foreman proxy | foreman_proxy | fqdn |
--foreman-proxy-register-in-foreman |
foreman_proxy | register_in_foreman | |
--foreman-proxy-trusted-hosts |
foreman_proxy | trusted_hosts | |
--foreman-proxy-dhcp |
Enables DHCP feature in smart-proxy | foreman_proxy | dhcp |
--foreman-proxy-dhcp-provider |
foreman_proxy | dhcp_provider | |
--foreman-proxy-dhcp-subnets |
foreman_proxy | dhcp_subnets | |
--foreman-proxy-dhcp-key-name |
foreman_proxy | dhcp_key_name | |
--foreman-proxy-dhcp-key-secret |
foreman_proxy | dhcp_key_secret | |
--foreman-proxy-dhcp-ipxefilename |
foreman_proxy | dhcp_ipxefilename | |
--foreman-proxy-dhcp-ipxe-bootstrap |
foreman_proxy | dhcp_ipxe_bootstrap | |
--foreman-proxy-dhcp-server |
foreman_proxy | dhcp_server | |
--foreman-proxy-libvirt-network |
foreman_proxy | libvirt_network | |
--foreman-proxy-libvirt-url |
foreman_proxy | libvirt_url | |
--foreman-proxy-dns |
foreman_proxy | dns | |
--foreman-proxy-dns-managed |
foreman_proxy | dns_managed | |
--foreman-proxy-dns-provider |
foreman_proxy | foreman_proxy::dns_provider | |
--foreman-proxy-dns-server |
foreman_proxy | foreman_proxy::dns_server | |
--foreman-proxy-keyfile |
foreman_proxy | foreman_proxy::keyfile | |
--foreman-proxy-plugin-dns-powerdns-rest-api-key |
foreman_proxy::plugin::dns_powerdns | rest_api_key | |
--foreman-proxy-plugin-dns-powerdns-rest-url |
foreman_proxy::plugin::dns_powerdns | rest_url | |
--foreman-proxy-plugin-dns-route53-aws-access-key |
foreman_proxy::plugin::dns_route53 | aws_access_key | |
--foreman-proxy-plugin-dns-route53-aws-secret-key |
foreman_proxy::plugin::dns_route53 | aws_secret_key | |
--foreman-proxy-httpboot |
foreman_proxy | httpboot | |
--foreman-proxy-tftp |
foreman_proxy | tftp | |
--foreman-proxy-tftp-servername |
foreman_proxy | tftp_servername | |
--foreman-proxy-tftp-managed |
foreman_proxy | tftp_managed | |
--foreman-proxy-tftp-root |
foreman_proxy | tftp_root | |
--foreman-proxy-plugin-dhcp-remote-isc-dhcp-config |
foreman_proxy::plugin::dhcp_remote_isc | config | |
--foreman-proxy-plugin-dhcp-remote-isc-dhcp-leases |
foreman_proxy::plugin::dhcp_remote_isc | dhcp_config | |
--foreman-proxy-plugin-dhcp-remote-isc-key-name |
foreman_proxy::plugin::dhcp_remote_isc | key_name | |
--foreman-proxy-plugin-dhcp-remote-isc-key-secret |
foreman_proxy::plugin::dhcp_remote_isc | key_secret | |
--foreman-proxy-plugin-dhcp-remote-isc-omapi-port |
foreman_proxy::plugin::dhcp_remote_isc | omapi_port | |
--foreman-proxy-plugin-remote-execution-script-mqtt-rate-limit |
foreman_proxy::plugin::remote_execution_script | mqtt_rate_limit | |
--foreman-proxy-plugin-remote-execution-script-mqtt-resend-interval |
foreman_proxy::plugin::remote_execution_script | mqtt_resend_interval | |
--foreman-proxy-plugin-remote-execution-script-mqtt-ttl |
foreman_proxy::plugin::remote_execution_script | ttl | |
--foreman-proxy-plugin-remote-execution-script-remote-working-dir |
foreman_proxy::plugin::remote_execution_script | remote_working_dir | |
--foreman-proxy-puppet |
foreman_proxy | puppet | |
--foreman-proxy-puppetca |
foreman_proxy | puppetca | |
--foreman-proxy-plugin-remote-execution-script-mode |
foreman_proxy::plugin::remote_execution_script | mode | |
--foreman-proxy-plugin-openscap-ansible-module |
foreman_proxy::plugin::openscap | ansible_module | |
--foreman-proxy-plugin-openscap-puppet-module |
foreman_proxy::plugin::openscap | puppet_module | |
--foreman-proxy-http |
|||
--foreman-proxy-plugin-ansible-working-dir |
|||
--foreman-proxy-plugin-dhcp-infoblox-dns-view |
|||
--foreman-proxy-plugin-dhcp-infoblox-network-view |
|||
--foreman-proxy-plugin-dhcp-infoblox-password |
|||
--foreman-proxy-plugin-dhcp-infoblox-record-type |
|||
--foreman-proxy-plugin-dhcp-infoblox-username |
|||
--foreman-proxy-plugin-discovery-install-images |
|||
--foreman-proxy-plugin-discovery-source-url |
|||
--foreman-proxy-plugin-dns-infoblox-dns-server |
|||
--foreman-proxy-plugin-dns-infoblox-dns-view |
|||
--foreman-proxy-plugin-dns-infoblox-password |
|||
--foreman-proxy-plugin-dns-infoblox-username |
|||
--foreman-proxy-plugin-remote-execution-script-cockpit-integration |
|||
--foreman-proxy-plugin-remote-execution-script-ssh-kerberos-auth |
|||
--foreman-proxy-realm |
|||
--foreman-proxy-realm-keytab |
|||
--foreman-proxy-realm-principal |
|||
--foreman-proxy-realm-provider |
|||
--puppet-server |
puppet | server | |
--puppet-server-ca |
puppet | server_ca | |
--puppet-dns-alt-names |
puppet | dns_alt_names | |
--puppet-ca-server |
puppet | ca_server |