openapi: 3.2.0 info: title: Red Hat Ansible Automation Platform Settings API version: '1.0' description: 'Operations tagged settings across 2 of this provider''s published API definitions: red-hat-ansible-automation-platform-automation-controller-openapi.json, red-hat-ansible-automation-platform-platform-gateway-openapi.json. Each path carries the servers of the definition it was published in.' tags: - name: Settings paths: /api/v2/settings/: get: operationId: settings_list parameters: - name: page required: false in: query description: A page number within the paginated result set. schema: type: integer - name: page_size required: false in: query description: Number of results to return per page. schema: type: integer tags: - Settings responses: '200': content: application/json: schema: $ref: '#/components/schemas/PaginatedSettingCategoryList' description: '' x-ai-description: Returns a paginated list of Controller setting categories. summary: Settings list x-summary-source: derived /api/v2/settings/{category_slug}/: get: operationId: settings_retrieve parameters: - in: path name: category_slug schema: type: string pattern: ^[a-z0-9-]+$ required: true tags: - Settings responses: '200': content: application/json: schema: $ref: '#/components/schemas/SettingSingleton' description: '' x-ai-description: Returns Controller settings for a specific category by slug. summary: Settings retrieve x-summary-source: derived put: operationId: settings_update parameters: - in: path name: category_slug schema: type: string pattern: ^[a-z0-9-]+$ required: true tags: - Settings requestBody: content: application/json: schema: $ref: '#/components/schemas/SettingSingletonRequest' responses: '200': content: application/json: schema: $ref: '#/components/schemas/SettingSingleton' description: '' x-ai-description: Update existing setting summary: Settings update x-summary-source: derived patch: operationId: settings_partial_update parameters: - in: path name: category_slug schema: type: string pattern: ^[a-z0-9-]+$ required: true tags: - Settings requestBody: content: application/json: schema: $ref: '#/components/schemas/PatchedSettingSingletonRequest' responses: '200': content: application/json: schema: $ref: '#/components/schemas/SettingSingleton' description: '' x-ai-description: Update system settings. summary: Settings partial update x-summary-source: derived delete: operationId: settings_destroy parameters: - in: path name: category_slug schema: type: string pattern: ^[a-z0-9-]+$ required: true tags: - Settings responses: '204': description: No response body x-ai-description: Delete existing setting summary: Settings destroy x-summary-source: derived /api/v2/settings/logging/test/: post: operationId: settings_logging_test_create tags: - Settings requestBody: content: application/json: schema: $ref: '#/components/schemas/SettingSingletonRequest' responses: '200': content: application/json: schema: $ref: '#/components/schemas/SettingSingleton' description: '' x-ai-description: Create new settings logging test summary: Settings logging test create x-summary-source: derived /api/gateway/v1/settings/: get: operationId: getApiGatewayV1Settings description: 'A view class for managing and displaying all section of settings, with their urls and names Endpoint: ''/api/gateway/v1/settings/''' parameters: - name: page required: false in: query description: A page number within the paginated result set. schema: type: integer - name: page_size required: false in: query description: Number of results to return per page. schema: type: integer tags: - Settings security: - OAuth2_Authentication: [] - SessionAuthentication: [] - Basic_Authentication: [] responses: '200': content: application/json: schema: $ref: '#/components/schemas/PaginatedSettingSectionListList' description: '' x-ai-description: List setting categories grouping related Gateway configuration preferences summary: Settings list x-summary-source: derived x-operation-id-source: normalized x-operation-id-original: settings_list /api/gateway/v1/settings/{category_slug}/: get: operationId: settings_getter description: 'A view class for managing and displaying a group of settings for a specific category. Endpoint: ''/api/gateway/v1/settings//'' Parameters: - category_slug: The category of the setting (e.g., ''proxy'', ''configuration'').' parameters: - in: path name: category_slug schema: type: string pattern: ^[a-z0-9_]+$ required: true tags: - Settings security: - OAuth2_Authentication: [] - SessionAuthentication: [] - Basic_Authentication: [] responses: '200': content: application/json: schema: $ref: '#/components/schemas/SettingSection' description: '' x-ai-description: Get Gateway preferences for a category, or 'all' for all categories summary: Settings getter x-summary-source: derived put: operationId: putApiGatewayV1SettingsByCategorySlug description: 'A view class for managing and displaying a group of settings for a specific category. Endpoint: ''/api/gateway/v1/settings//'' Parameters: - category_slug: The category of the setting (e.g., ''proxy'', ''configuration'').' parameters: - in: path name: category_slug schema: type: string pattern: ^[a-z0-9_]+$ required: true tags: - Settings requestBody: content: application/json: schema: $ref: '#/components/schemas/SettingSection' application/x-www-form-urlencoded: schema: $ref: '#/components/schemas/SettingSection' multipart/form-data: schema: $ref: '#/components/schemas/SettingSection' security: - OAuth2_Authentication: [] - SessionAuthentication: [] - Basic_Authentication: [] responses: '200': content: application/json: schema: $ref: '#/components/schemas/SettingSection' description: '' x-ai-description: Update Gateway preferences within a category summary: Settings update x-summary-source: derived x-operation-id-source: normalized x-operation-id-original: settings_update delete: operationId: settings_destroyer description: 'Revert all preferences in the current category to their default values except for read_only or encrypted settings' parameters: - in: path name: category_slug schema: type: string pattern: ^[a-z0-9_]+$ required: true tags: - Settings security: - OAuth2_Authentication: [] - SessionAuthentication: [] - Basic_Authentication: [] responses: '204': description: No response body x-ai-description: Revert Gateway category preferences to defaults, excluding read-only and encrypted settings summary: Settings destroyer x-summary-source: derived /api/gateway/v1/settings/{category_slug}/{preference_name}/: get: operationId: getApiGatewayV1SettingsByCategorySlugByPreferenceName description: 'A view class for managing and displaying a single setting information for a specified category. URL pattern: ''/api/gateway/v1/settings///'' Parameters: - category_slug: The category of the setting (e.g., ''proxy'', ''configuration''). - preference_name: The name of the specific setting (e.g., ''request_timeout'', ''default_page_size'').' parameters: - in: path name: category_slug schema: type: string pattern: ^[a-z0-9_]+$ required: true - in: path name: preference_name schema: type: string pattern: ^[a-zA-Z0-9_]+$ required: true tags: - Settings security: - OAuth2_Authentication: [] - SessionAuthentication: [] - Basic_Authentication: [] responses: '200': content: application/json: schema: $ref: '#/components/schemas/SettingPreference' description: '' x-ai-description: Get a single Gateway preference by category and name summary: Settings retrieve x-summary-source: derived x-operation-id-source: normalized x-operation-id-original: settings_retrieve delete: operationId: deleteApiGatewayV1SettingsByCategorySlugByPreferenceName description: 'revert the setting `preference_name` in section `category_slug` to its default value. The `category_slug` parameter must be specified (i.e., cannot be ''all'') because Preference only guarantees uniqueness for the tuple (section, preference_name). Therefore, thus can be multiple settings with the same name in different sections.' parameters: - in: path name: category_slug schema: type: string pattern: ^[a-z0-9_]+$ required: true - in: path name: preference_name schema: type: string pattern: ^[a-zA-Z0-9_]+$ required: true tags: - Settings security: - OAuth2_Authentication: [] - SessionAuthentication: [] - Basic_Authentication: [] responses: '204': description: No response body x-ai-description: Revert a single Gateway preference to default, excluding read-only and encrypted settings summary: Settings destroy x-summary-source: derived x-operation-id-source: normalized x-operation-id-original: settings_destroy components: schemas: PaginatedSettingCategoryList: type: object required: - count - results properties: count: type: integer example: 123 next: type: - string - 'null' format: uri example: http://api.example.org/accounts/?page=4 previous: type: - string - 'null' format: uri example: http://api.example.org/accounts/?page=2 results: type: array items: $ref: '#/components/schemas/SettingCategory' PatchedSettingSingletonRequest: type: object description: Present a group of settings (by category) as a single object. properties: ACTIVITY_STREAM_ENABLED: type: boolean default: true title: Enable Activity Stream description: Enable capturing activity for the activity stream. ACTIVITY_STREAM_ENABLED_FOR_INVENTORY_SYNC: type: boolean default: false title: Enable Activity Stream for Inventory Sync description: Enable capturing activity for the activity stream when running inventory sync. ORG_ADMINS_CAN_SEE_ALL_USERS: type: boolean default: true title: All Users Visible to Organization Admins description: Controls whether any Organization Admin can view all users and teams, even those not associated with their Organization. MANAGE_ORGANIZATION_AUTH: type: boolean default: true title: Organization Admins Can Manage Users and Teams description: Controls whether any Organization Admin has the privileges to create and manage users and teams. TOWER_URL_BASE: type: string minLength: 1 default: https://platformhost title: Base URL of the service description: This setting is used by services like notifications to render a valid url to the service. format: uri REMOTE_HOST_HEADERS: type: array items: type: string minLength: 1 default: - REMOTE_ADDR - REMOTE_HOST description: HTTP headers and meta keys to search to determine remote host name or IP. Add additional items to this list, such as "HTTP_X_FORWARDED_FOR", if behind a reverse proxy. See the "Proxy Support" section of the AAP Installation guide for more details. PROXY_IP_ALLOWED_LIST: type: array items: type: string minLength: 1 default: [] description: If the service is behind a reverse proxy/load balancer, use this setting to configure the proxy IP addresses from which the service should trust custom REMOTE_HOST_HEADERS header values. If this setting is an empty list (the default), the headers specified by REMOTE_HOST_HEADERS will be trusted unconditionally') CSRF_TRUSTED_ORIGINS: type: array items: type: string minLength: 1 default: [] title: CSRF Trusted Origins List description: 'If the service is behind a reverse proxy/load balancer, use this setting to configure the schema://addresses from which the service should trust Origin header values. ' REDHAT_USERNAME: type: string default: '' title: Red Hat Client ID for Analytics description: Client ID used to send data to Automation Analytics REDHAT_PASSWORD: type: string default: '' title: Red Hat Client Secret for Analytics description: Client secret used to send data to Automation Analytics SUBSCRIPTIONS_USERNAME: type: string default: '' title: Red Hat Username for Subscriptions description: Username used to retrieve subscription and content information SUBSCRIPTIONS_PASSWORD: type: string default: '' title: Red Hat Password for Subscriptions description: Password used to retrieve subscription and content information SUBSCRIPTIONS_CLIENT_ID: type: string default: '' title: Red Hat Client ID for Subscriptions description: Client ID used to retrieve subscription and content information SUBSCRIPTIONS_CLIENT_SECRET: type: string default: '' title: Red Hat Client Secret for Subscriptions description: Client secret used to retrieve subscription and content information AUTOMATION_ANALYTICS_URL: type: string minLength: 1 default: https://example.com title: Automation Analytics upload URL description: This setting is used to to configure the upload URL for data collection for Automation Analytics. format: uri AWX_ANALYTICS_CANDLEPIN_CA: type: string default: /etc/rhsm/ca/redhat-uep.pem title: Candlepin CA Certificate Path description: Path to the CA certificate file for verifying TLS connections to Candlepin. Leave blank to use system certificates. AWX_ANALYTICS_CANDLEPIN_RENEWAL_THRESHOLD_DAYS: type: integer minimum: 1 default: 90 title: Candlepin Certificate Renewal Threshold description: Number of days before certificate expiry to trigger automatic renewal of Candlepin identity certificates. AWX_ANALYTICS_CANDLEPIN_PROXY_URL: type: string default: '' title: Candlepin Proxy URL description: HTTP/HTTPS proxy URL for Candlepin API requests (e.g., http://proxy.example.com:8080). Leave blank for no proxy. DEFAULT_EXECUTION_ENVIRONMENT: type: - integer - 'null' title: Global default execution environment description: The Execution Environment to be used when one has not been configured for a job template. CUSTOM_VENV_PATHS: type: array items: type: string minLength: 1 default: [] title: Custom virtual environment paths description: Paths where Tower will look for custom virtual environments (in addition to /var/lib/awx/venv/). Enter one path per line. AD_HOC_COMMANDS: type: array items: type: string minLength: 1 default: - command - shell - yum - apt - apt_key - apt_repository - apt_rpm - service - group - user - mount - ping - selinux - setup - win_ping - win_service - win_updates - win_group - win_user title: Ansible Modules Allowed for Ad Hoc Jobs description: List of modules allowed to be used by ad-hoc jobs. ALLOW_JINJA_IN_EXTRA_VARS: enum: - always - never - template type: string x-spec-enum-id: 28bae37cee4f4fdb default: template title: When can extra variables contain Jinja templates? description: 'Ansible allows variable substitution via the Jinja2 templating language for --extra-vars. This poses a potential security risk where users with the ability to specify extra vars at job launch time can use Jinja2 templates to run arbitrary Python. It is recommended that this value be set to "template" or "never". * `always` - Always * `never` - Never * `template` - Only On Job Template Definitions' INCLUDE_DEPRECATED_AWX_VAR_PREFIX: type: boolean default: true title: Include Deprecated AWX Variable Prefix description: When enabled (default), auto-generated job variables are emitted with both the tower_ prefix and the deprecated awx_ prefix for backward compatibility. Disable to emit only tower_ prefixed variables and eliminate duplicates. The awx_ prefix is deprecated and this setting will default to False in a future release. AWX_ISOLATION_BASE_PATH: type: string minLength: 1 default: /tmp title: Job execution path description: The directory in which the service will create new temporary directories for job execution and isolation (such as credential files). AWX_ISOLATION_SHOW_PATHS: type: array items: type: string minLength: 1 default: [] title: Paths to expose to isolated jobs description: 'List of paths that would otherwise be hidden to expose to isolated jobs. Enter one path per line. Volumes will be mounted from the execution node to the container. The supported format is HOST-DIR[:CONTAINER-DIR[:OPTIONS]]. ' AWX_TASK_ENV: type: object additionalProperties: type: string minLength: 1 default: {} title: Extra Environment Variables description: Additional environment variables set for playbook runs, inventory updates, project updates, and notification sending. AWX_RUNNER_KEEPALIVE_SECONDS: type: integer default: 0 title: K8S Ansible Runner Keep-Alive Message Interval description: Only applies to jobs running in a Container Group. If not 0, send a message every so-many seconds to keep connection open. GALAXY_TASK_ENV: type: object additionalProperties: type: string minLength: 1 default: ANSIBLE_FORCE_COLOR: 'false' GIT_SSH_COMMAND: ssh -o StrictHostKeyChecking=no title: Environment Variables for Galaxy Commands description: Additional environment variables set for invocations of ansible-galaxy within project updates. Useful if you must use a proxy server for ansible-galaxy but not git. INSIGHTS_TRACKING_STATE: type: boolean default: false title: Gather data for Automation Analytics description: Enables the service to gather data on automation and send it to Automation Analytics. PROJECT_UPDATE_VVV: type: boolean default: false title: Run Project Updates With Higher Verbosity description: Adds the CLI -vvv flag to ansible-playbook runs of project_update.yml used for project updates. AWX_ROLES_ENABLED: type: boolean default: true title: Enable Role Download description: Allows roles to be dynamically downloaded from a requirements.yml file for SCM projects. AWX_COLLECTIONS_ENABLED: type: boolean default: true title: Enable Collection(s) Download description: Allows collections to be dynamically downloaded from a requirements.yml file for SCM projects. AWX_SHOW_PLAYBOOK_LINKS: type: boolean default: false title: Follow symlinks description: Follow symbolic links when scanning for playbooks. Be aware that setting this to True can lead to infinite recursion if a link points to a parent directory of itself. AWX_MOUNT_ISOLATED_PATHS_ON_K8S: type: boolean default: false title: Expose host paths for Container Groups description: 'Expose paths via hostPath for the Pods created by a Container Group. HostPath volumes present many security risks, and it is a best practice to avoid the use of HostPaths when possible. ' GALAXY_IGNORE_CERTS: type: boolean default: false title: Ignore Ansible Galaxy SSL Certificate Verification description: If set to true, certificate validation will not be done when installing content from any Galaxy server. STDOUT_MAX_BYTES_DISPLAY: type: integer minimum: 0 default: 1048576 title: Standard Output Maximum Display Size description: Maximum Size of Standard Output in bytes to display before requiring the output be downloaded. EVENT_STDOUT_MAX_BYTES_DISPLAY: type: integer minimum: 0 default: 1024 title: Job Event Standard Output Maximum Display Size description: Maximum Size of Standard Output in bytes to display for a single job or ad hoc command event. `stdout` will end with `…` when truncated. MAX_WEBSOCKET_EVENT_RATE: type: integer minimum: 0 default: 30 title: Job Event Maximum Websocket Messages Per Second description: Maximum number of messages to update the UI live job output with per second. Value of 0 means no limit. SCHEDULE_MAX_JOBS: type: integer minimum: 1 default: 10 title: Maximum Scheduled Jobs description: Maximum number of the same job template that can be waiting to run when launching from a schedule before no more are created. AWX_ANSIBLE_CALLBACK_PLUGINS: type: array items: type: string minLength: 1 default: [] title: Ansible Callback Plugins description: List of paths to search for extra callback plugins to be used when running jobs. Enter one path per line. DEFAULT_JOB_TIMEOUT: type: integer minimum: 0 default: 0 description: Maximum time in seconds to allow jobs to run. Use value of 0 to indicate that no timeout should be imposed. A timeout set on an individual job template will override this. DEFAULT_JOB_IDLE_TIMEOUT: type: integer minimum: 0 default: 0 description: If no output is detected from ansible in this number of seconds the execution will be terminated. Use value of 0 to indicate that no idle timeout should be imposed. DEFAULT_INVENTORY_UPDATE_TIMEOUT: type: integer minimum: 0 default: 0 description: Maximum time in seconds to allow inventory updates to run. Use value of 0 to indicate that no timeout should be imposed. A timeout set on an individual inventory source will override this. DEFAULT_PROJECT_UPDATE_TIMEOUT: type: integer minimum: 0 default: 0 description: Maximum time in seconds to allow project updates to run. Use value of 0 to indicate that no timeout should be imposed. A timeout set on an individual project will override this. ANSIBLE_FACT_CACHE_TIMEOUT: type: integer minimum: 0 default: 0 title: Per-Host Ansible Fact Cache Timeout description: Maximum time, in seconds, that stored Ansible facts are considered valid since the last time they were modified. Only valid, non-stale, facts will be accessible by a playbook. Note, this does not influence the deletion of ansible_facts from the database. Use a value of 0 to indicate that no timeout should be imposed. MAX_FORKS: type: integer default: 200 title: Maximum number of forks per job description: Saving a Job Template with more than this number of forks will result in an error. When set to 0, no limit is applied. LOG_AGGREGATOR_HOST: type: - string - 'null' minLength: 1 title: Logging Aggregator description: Hostname/IP where external logs will be sent to. LOG_AGGREGATOR_PORT: type: - integer - 'null' title: Logging Aggregator Port description: Port on Logging Aggregator to send logs to (if required and not provided in Logging Aggregator). LOG_AGGREGATOR_TYPE: enum: - logstash - splunk - loggly - sumologic - other - null type: - string - 'null' x-spec-enum-id: f7f9aae80827f128 title: Logging Aggregator Type description: 'Format messages for the chosen log aggregator. * `logstash` - logstash * `splunk` - splunk * `loggly` - loggly * `sumologic` - sumologic * `other` - other' LOG_AGGREGATOR_USERNAME: type: string default: '' title: Logging Aggregator Username description: Username for external log aggregator (if required; HTTP/s only). LOG_AGGREGATOR_PASSWORD: type: string default: '' title: Logging Aggregator Password/Token description: Password or authentication token for external log aggregator (if required; HTTP/s only). LOG_AGGREGATOR_LOGGERS: type: array items: type: string minLength: 1 default: - awx - activity_stream - job_events - system_tracking - broadcast_websocket - job_lifecycle title: Loggers Sending Data to Log Aggregator Form description: "List of loggers that will send HTTP logs to the collector, these can include any or all of: \nawx - service logs\nactivity_stream - activity stream records\njob_events - callback data from Ansible job events\nsystem_tracking - facts gathered from scan jobs\nbroadcast_websocket - errors pertaining to websockets broadcast metrics\njob_lifecycle - logs related to processing of a job\n" LOG_AGGREGATOR_INDIVIDUAL_FACTS: type: boolean default: false title: Log System Tracking Facts Individually description: If set, system tracking facts will be sent for each package, service, or other item found in a scan, allowing for greater search query granularity. If unset, facts will be sent as a single dictionary, allowing for greater efficiency in fact processing. LOG_AGGREGATOR_ENABLED: type: boolean default: false title: Enable External Logging description: Enable sending logs to external log aggregator. LOG_AGGREGATOR_TOWER_UUID: type: string default: '' title: Cluster-wide unique identifier. description: Useful to uniquely identify instances. LOG_AGGREGATOR_PROTOCOL: enum: - https - tcp - udp type: string x-spec-enum-id: 7d0c803b90b97cde default: https title: Logging Aggregator Protocol description: 'Protocol used to communicate with log aggregator. HTTPS/HTTP assumes HTTPS unless http:// is explicitly used in the Logging Aggregator hostname. * `https` - HTTPS/HTTP * `tcp` - TCP * `udp` - UDP' LOG_AGGREGATOR_TCP_TIMEOUT: type: integer default: 5 title: TCP Connection Timeout description: Number of seconds for a TCP connection to external log aggregator to timeout. Applies to HTTPS and TCP log aggregator protocols. LOG_AGGREGATOR_VERIFY_CERT: type: boolean default: true title: Enable/disable HTTPS certificate verification description: Flag to control enable/disable of certificate verification when LOG_AGGREGATOR_PROTOCOL is "https". If enabled, the log handler will verify certificate sent by external log aggregator before establishing connection. LOG_AGGREGATOR_LEVEL: enum: - DEBUG - INFO - WARNING - ERROR - CRITICAL type: string x-spec-enum-id: 337bdbe45a1d1410 default: INFO title: Logging Aggregator Level Threshold description: 'Level threshold used by log handler. Severities from lowest to highest are DEBUG, INFO, WARNING, ERROR, CRITICAL. Messages less severe than the threshold will be ignored by log handler. (messages under category awx.anlytics ignore this setting) * `DEBUG` - DEBUG * `INFO` - INFO * `WARNING` - WARNING * `ERROR` - ERROR * `CRITICAL` - CRITICAL' LOG_AGGREGATOR_ACTION_QUEUE_SIZE: type: integer minimum: 1 default: 131072 title: Maximum number of messages that can be stored in the log action queue description: Defines how large the rsyslog action queue can grow in number of messages stored. This can have an impact on memory utilization. When the queue reaches 75% of this number, the queue will start writing to disk (queue.highWatermark in rsyslog). When it reaches 90%, NOTICE, INFO, and DEBUG messages will start to be discarded (queue.discardMark with queue.discardSeverity=5). LOG_AGGREGATOR_ACTION_MAX_DISK_USAGE_GB: type: integer minimum: 1 default: 1 title: Maximum disk persistence for rsyslogd action queuing (in GB) description: Amount of data to store (in gigabytes) if an rsyslog action takes time to process an incoming message (defaults to 1). Equivalent to the rsyslogd queue.maxdiskspace setting on the action (e.g. omhttp). It stores files in the directory specified by LOG_AGGREGATOR_MAX_DISK_USAGE_PATH. LOG_AGGREGATOR_MAX_DISK_USAGE_PATH: type: string minLength: 1 default: /var/lib/awx title: File system location for rsyslogd disk persistence description: Location to persist logs that should be retried after an outage of the external log aggregator (defaults to /var/lib/awx). Equivalent to the rsyslogd queue.spoolDirectory setting. LOG_AGGREGATOR_RSYSLOGD_DEBUG: type: boolean default: false title: Enable rsyslogd debugging description: Enabled high verbosity debugging for rsyslogd. Useful for debugging connection issues for external log aggregation. API_400_ERROR_LOG_FORMAT: type: string minLength: 1 default: status {status_code} received by user {user_name} attempting to access {url_path} from {remote_addr} title: Log Format For API 4XX Errors description: "The format of logged messages when an API 4XX error occurs, the following variables will be substituted: \nstatus_code - The HTTP status code of the error\nuser_name - The user name attempting to use the API\nurl_path - The URL path to the API endpoint called\nremote_addr - The remote address seen for the user\nerror - The error set by the api endpoint\nVariables need to be in the format {}." AUTOMATION_ANALYTICS_LAST_GATHER: type: - string - 'null' format: date-time title: Last gather date for Automation Analytics. AUTOMATION_ANALYTICS_LAST_ENTRIES: type: string default: '' title: Last gathered entries from the data collection service of Automation Analytics AUTOMATION_ANALYTICS_GATHER_INTERVAL: type: integer minimum: 1800 default: 14400 description: Interval (in seconds) between data gathering. CANDLEPIN_CONSUMER_UUID: type: string default: '' description: UUID of the registered Candlepin consumer for this AAP instance. CANDLEPIN_CERT_PEM: type: string default: '' title: Candlepin Identity Certificate description: PEM-encoded Candlepin identity certificate for mTLS authentication. CANDLEPIN_KEY_PEM: type: string default: '' title: Candlepin Identity Key description: PEM-encoded private key for Candlepin identity certificate. CANDLEPIN_SERIAL_NUMBER: type: string default: '' title: Candlepin Certificate Serial Number description: Serial number of the Candlepin identity certificate for tracking. BULK_JOB_MAX_LAUNCH: type: integer default: 100 title: Max jobs to allow bulk jobs to launch description: Max jobs to allow bulk jobs to launch BULK_HOST_MAX_CREATE: type: integer default: 100 title: Max number of hosts to allow to be created in a single bulk action description: Max number of hosts to allow to be created in a single bulk action BULK_HOST_MAX_DELETE: type: integer default: 250 title: Max number of hosts to allow to be deleted in a single bulk action description: Max number of hosts to allow to be deleted in a single bulk action SUBSCRIPTION_USAGE_MODEL: enum: - '' - unique_managed_hosts type: string description: '* `` - No subscription. Deletion of host_metrics will not be considered for purposes of managed host counting * `unique_managed_hosts` - Usage based on unique managed nodes in a large historical time frame and delete functionality for no longer used managed nodes' x-spec-enum-id: f0cccba4fe8d04cb default: '' title: Defines subscription usage model and shows Host Metrics CLEANUP_HOST_METRICS_LAST_TS: type: - string - 'null' format: date-time title: Last cleanup date for HostMetrics HOST_METRIC_SUMMARY_TASK_LAST_TS: type: - string - 'null' format: date-time title: Last computing date of HostMetricSummaryMonthly AWX_CLEANUP_PATHS: type: boolean default: true title: Enable or Disable tmp dir cleanup description: Enable or Disable TMP Dir cleanup AWX_REQUEST_PROFILE: type: boolean default: false title: Debug Web Requests description: Debug web request python timing DEFAULT_CONTAINER_RUN_OPTIONS: type: array items: type: string minLength: 1 default: - --network - slirp4netns:enable_ipv6=true title: Container Run Options description: 'List of options to pass to podman run example: [''--network'', ''slirp4netns:enable_ipv6=true'', ''--log-level'', ''debug'']' RECEPTOR_RELEASE_WORK: type: boolean default: true title: Release Receptor Work description: Release receptor work RECEPTOR_KEEP_WORK_ON_ERROR: type: boolean default: false title: Keep receptor work on error description: Prevent receptor work from being released on when error is detected OPA_HOST: type: string default: '' title: OPA server hostname description: The hostname used to connect to the OPA server. If empty, policy enforcement will be disabled. OPA_PORT: type: integer default: 8181 title: OPA server port description: The port used to connect to the OPA server. Defaults to 8181. OPA_SSL: type: boolean default: false title: Use SSL for OPA connection description: Enable or disable the use of SSL to connect to the OPA server. Defaults to false. OPA_AUTH_TYPE: enum: - None - Token - Certificate type: string x-spec-enum-id: 831ccaccafb11069 default: None title: OPA authentication type description: 'The authentication type that will be used to connect to the OPA server: "None", "Token", or "Certificate". * `None` - None * `Token` - Token * `Certificate` - Certificate' OPA_AUTH_TOKEN: type: string default: '' title: OPA authentication token description: The token for authentication to the OPA server. Required when OPA_AUTH_TYPE is "Token". If an authorization header is defined in OPA_AUTH_CUSTOM_HEADERS, it will be overridden by OPA_AUTH_TOKEN. OPA_AUTH_CLIENT_CERT: type: string default: '' title: OPA client certificate content description: The content of the client certificate file for mTLS authentication to the OPA server. Required when OPA_AUTH_TYPE is "Certificate". OPA_AUTH_CLIENT_KEY: type: string default: '' title: OPA client key content description: The content of the client key for mTLS authentication to the OPA server. Required when OPA_AUTH_TYPE is "Certificate". OPA_AUTH_CA_CERT: type: string default: '' title: OPA CA certificate content description: The content of the CA certificate for mTLS authentication to the OPA server. Required when OPA_AUTH_TYPE is "Certificate". OPA_AUTH_CUSTOM_HEADERS: type: object additionalProperties: {} default: {} title: OPA custom authentication headers description: Optional custom headers included in requests to the OPA server. Defaults to empty dictionary ({}). OPA_REQUEST_TIMEOUT: type: number format: double default: 1.5 description: The number of seconds after which the connection to the OPA server will time out. Defaults to 1.5 seconds. OPA_REQUEST_RETRIES: type: integer default: 2 title: OPA request retry count description: The number of retry attempts for connecting to the OPA server. Default is 2. SESSION_COOKIE_AGE: type: integer maximum: 30000000000 minimum: 60 format: int64 default: 1800 title: Idle Time Force Log Out description: Number of seconds that a user is inactive before they will need to login again. SESSIONS_PER_USER: type: integer minimum: -1 default: -1 title: Maximum number of simultaneous logged in sessions description: Maximum number of simultaneous logged in sessions a user may have. To disable enter -1. DISABLE_LOCAL_AUTH: type: boolean default: false title: Disable the built-in authentication system description: 'Controls whether users are prevented from using the built-in authentication system. ' AUTH_BASIC_ENABLED: type: boolean default: true title: Enable HTTP Basic Auth description: Enable HTTP Basic Auth for the API Browser. LOGIN_REDIRECT_OVERRIDE: type: string default: '' title: Login redirect override URL description: URL to which unauthorized users will be redirected to log in. If blank, users will be sent to the login page. ALLOW_METRICS_FOR_ANONYMOUS_USERS: type: boolean default: false title: Allow anonymous users to poll metrics description: If true, anonymous users are allowed to poll metrics. CUSTOM_LOGIN_INFO: type: string default: '' description: If needed, you can add specific information (such as a legal notice or a disclaimer) to a text box in the login modal using this setting. Any content added must be in plain text or an HTML fragment, as other markup languages are not supported. CUSTOM_LOGO: type: string default: '' description: To set up a custom logo, provide a file that you create. For the custom logo to look its best, use a .png file with a transparent background. GIF, PNG and JPEG formats are supported. MAX_UI_JOB_EVENTS: type: integer minimum: 100 default: 4000 title: Max Job Events Retrieved by UI description: Maximum number of job events for the UI to retrieve within a single request. UI_LIVE_UPDATES_ENABLED: type: boolean default: true title: Enable Live Updates in the UI description: If disabled, the page will not refresh when events are received. Reloading the page will be required to get the latest details. SettingCategory: type: object description: Serialize setting category properties: url: type: string readOnly: true slug: type: string readOnly: true name: type: string readOnly: true SettingSingleton: type: object description: Present a group of settings (by category) as a single object. properties: ACTIVITY_STREAM_ENABLED: type: boolean default: true title: Enable Activity Stream description: Enable capturing activity for the activity stream. ACTIVITY_STREAM_ENABLED_FOR_INVENTORY_SYNC: type: boolean default: false title: Enable Activity Stream for Inventory Sync description: Enable capturing activity for the activity stream when running inventory sync. ORG_ADMINS_CAN_SEE_ALL_USERS: type: boolean default: true title: All Users Visible to Organization Admins description: Controls whether any Organization Admin can view all users and teams, even those not associated with their Organization. MANAGE_ORGANIZATION_AUTH: type: boolean default: true title: Organization Admins Can Manage Users and Teams description: Controls whether any Organization Admin has the privileges to create and manage users and teams. TOWER_URL_BASE: type: string default: https://platformhost title: Base URL of the service description: This setting is used by services like notifications to render a valid url to the service. format: uri REMOTE_HOST_HEADERS: type: array items: type: string default: - REMOTE_ADDR - REMOTE_HOST description: HTTP headers and meta keys to search to determine remote host name or IP. Add additional items to this list, such as "HTTP_X_FORWARDED_FOR", if behind a reverse proxy. See the "Proxy Support" section of the AAP Installation guide for more details. PROXY_IP_ALLOWED_LIST: type: array items: type: string default: [] description: If the service is behind a reverse proxy/load balancer, use this setting to configure the proxy IP addresses from which the service should trust custom REMOTE_HOST_HEADERS header values. If this setting is an empty list (the default), the headers specified by REMOTE_HOST_HEADERS will be trusted unconditionally') CSRF_TRUSTED_ORIGINS: type: array items: type: string default: [] title: CSRF Trusted Origins List description: 'If the service is behind a reverse proxy/load balancer, use this setting to configure the schema://addresses from which the service should trust Origin header values. ' LICENSE: type: object additionalProperties: {} readOnly: true description: The license controls which features and functionality are enabled. Use /api/v2/config/ to update or change the license. REDHAT_USERNAME: type: string default: '' title: Red Hat Client ID for Analytics description: Client ID used to send data to Automation Analytics REDHAT_PASSWORD: type: string default: '' title: Red Hat Client Secret for Analytics description: Client secret used to send data to Automation Analytics SUBSCRIPTIONS_USERNAME: type: string default: '' title: Red Hat Username for Subscriptions description: Username used to retrieve subscription and content information SUBSCRIPTIONS_PASSWORD: type: string default: '' title: Red Hat Password for Subscriptions description: Password used to retrieve subscription and content information SUBSCRIPTIONS_CLIENT_ID: type: string default: '' title: Red Hat Client ID for Subscriptions description: Client ID used to retrieve subscription and content information SUBSCRIPTIONS_CLIENT_SECRET: type: string default: '' title: Red Hat Client Secret for Subscriptions description: Client secret used to retrieve subscription and content information AUTOMATION_ANALYTICS_URL: type: string default: https://example.com title: Automation Analytics upload URL description: This setting is used to to configure the upload URL for data collection for Automation Analytics. format: uri AWX_ANALYTICS_CANDLEPIN_CA: type: string default: /etc/rhsm/ca/redhat-uep.pem title: Candlepin CA Certificate Path description: Path to the CA certificate file for verifying TLS connections to Candlepin. Leave blank to use system certificates. AWX_ANALYTICS_CANDLEPIN_RENEWAL_THRESHOLD_DAYS: type: integer minimum: 1 default: 90 title: Candlepin Certificate Renewal Threshold description: Number of days before certificate expiry to trigger automatic renewal of Candlepin identity certificates. AWX_ANALYTICS_CANDLEPIN_PROXY_URL: type: string default: '' title: Candlepin Proxy URL description: HTTP/HTTPS proxy URL for Candlepin API requests (e.g., http://proxy.example.com:8080). Leave blank for no proxy. INSTALL_UUID: type: string readOnly: true default: 00000000-0000-0000-0000-000000000000 title: Unique identifier for an installation DEFAULT_CONTROL_PLANE_QUEUE_NAME: type: string readOnly: true default: controlplane title: The instance group where control plane tasks run DEFAULT_EXECUTION_QUEUE_NAME: type: string readOnly: true default: default title: The instance group where user jobs run (currently only on non-VM installs) DEFAULT_EXECUTION_ENVIRONMENT: type: - integer - 'null' title: Global default execution environment description: The Execution Environment to be used when one has not been configured for a job template. CUSTOM_VENV_PATHS: type: array items: type: string default: [] title: Custom virtual environment paths description: Paths where Tower will look for custom virtual environments (in addition to /var/lib/awx/venv/). Enter one path per line. AD_HOC_COMMANDS: type: array items: type: string default: - command - shell - yum - apt - apt_key - apt_repository - apt_rpm - service - group - user - mount - ping - selinux - setup - win_ping - win_service - win_updates - win_group - win_user title: Ansible Modules Allowed for Ad Hoc Jobs description: List of modules allowed to be used by ad-hoc jobs. ALLOW_JINJA_IN_EXTRA_VARS: enum: - always - never - template type: string x-spec-enum-id: 28bae37cee4f4fdb default: template title: When can extra variables contain Jinja templates? description: 'Ansible allows variable substitution via the Jinja2 templating language for --extra-vars. This poses a potential security risk where users with the ability to specify extra vars at job launch time can use Jinja2 templates to run arbitrary Python. It is recommended that this value be set to "template" or "never". * `always` - Always * `never` - Never * `template` - Only On Job Template Definitions' INCLUDE_DEPRECATED_AWX_VAR_PREFIX: type: boolean default: true title: Include Deprecated AWX Variable Prefix description: When enabled (default), auto-generated job variables are emitted with both the tower_ prefix and the deprecated awx_ prefix for backward compatibility. Disable to emit only tower_ prefixed variables and eliminate duplicates. The awx_ prefix is deprecated and this setting will default to False in a future release. AWX_ISOLATION_BASE_PATH: type: string default: /tmp title: Job execution path description: The directory in which the service will create new temporary directories for job execution and isolation (such as credential files). AWX_ISOLATION_SHOW_PATHS: type: array items: type: string default: [] title: Paths to expose to isolated jobs description: 'List of paths that would otherwise be hidden to expose to isolated jobs. Enter one path per line. Volumes will be mounted from the execution node to the container. The supported format is HOST-DIR[:CONTAINER-DIR[:OPTIONS]]. ' AWX_TASK_ENV: type: object additionalProperties: type: string default: {} title: Extra Environment Variables description: Additional environment variables set for playbook runs, inventory updates, project updates, and notification sending. AWX_RUNNER_KEEPALIVE_SECONDS: type: integer default: 0 title: K8S Ansible Runner Keep-Alive Message Interval description: Only applies to jobs running in a Container Group. If not 0, send a message every so-many seconds to keep connection open. GALAXY_TASK_ENV: type: object additionalProperties: type: string default: ANSIBLE_FORCE_COLOR: 'false' GIT_SSH_COMMAND: ssh -o StrictHostKeyChecking=no title: Environment Variables for Galaxy Commands description: Additional environment variables set for invocations of ansible-galaxy within project updates. Useful if you must use a proxy server for ansible-galaxy but not git. INSIGHTS_TRACKING_STATE: type: boolean default: false title: Gather data for Automation Analytics description: Enables the service to gather data on automation and send it to Automation Analytics. PROJECT_UPDATE_VVV: type: boolean default: false title: Run Project Updates With Higher Verbosity description: Adds the CLI -vvv flag to ansible-playbook runs of project_update.yml used for project updates. AWX_ROLES_ENABLED: type: boolean default: true title: Enable Role Download description: Allows roles to be dynamically downloaded from a requirements.yml file for SCM projects. AWX_COLLECTIONS_ENABLED: type: boolean default: true title: Enable Collection(s) Download description: Allows collections to be dynamically downloaded from a requirements.yml file for SCM projects. AWX_SHOW_PLAYBOOK_LINKS: type: boolean default: false title: Follow symlinks description: Follow symbolic links when scanning for playbooks. Be aware that setting this to True can lead to infinite recursion if a link points to a parent directory of itself. AWX_MOUNT_ISOLATED_PATHS_ON_K8S: type: boolean default: false title: Expose host paths for Container Groups description: 'Expose paths via hostPath for the Pods created by a Container Group. HostPath volumes present many security risks, and it is a best practice to avoid the use of HostPaths when possible. ' GALAXY_IGNORE_CERTS: type: boolean default: false title: Ignore Ansible Galaxy SSL Certificate Verification description: If set to true, certificate validation will not be done when installing content from any Galaxy server. STDOUT_MAX_BYTES_DISPLAY: type: integer minimum: 0 default: 1048576 title: Standard Output Maximum Display Size description: Maximum Size of Standard Output in bytes to display before requiring the output be downloaded. EVENT_STDOUT_MAX_BYTES_DISPLAY: type: integer minimum: 0 default: 1024 title: Job Event Standard Output Maximum Display Size description: Maximum Size of Standard Output in bytes to display for a single job or ad hoc command event. `stdout` will end with `…` when truncated. MAX_WEBSOCKET_EVENT_RATE: type: integer minimum: 0 default: 30 title: Job Event Maximum Websocket Messages Per Second description: Maximum number of messages to update the UI live job output with per second. Value of 0 means no limit. SCHEDULE_MAX_JOBS: type: integer minimum: 1 default: 10 title: Maximum Scheduled Jobs description: Maximum number of the same job template that can be waiting to run when launching from a schedule before no more are created. AWX_ANSIBLE_CALLBACK_PLUGINS: type: array items: type: string default: [] title: Ansible Callback Plugins description: List of paths to search for extra callback plugins to be used when running jobs. Enter one path per line. DEFAULT_JOB_TIMEOUT: type: integer minimum: 0 default: 0 description: Maximum time in seconds to allow jobs to run. Use value of 0 to indicate that no timeout should be imposed. A timeout set on an individual job template will override this. DEFAULT_JOB_IDLE_TIMEOUT: type: integer minimum: 0 default: 0 description: If no output is detected from ansible in this number of seconds the execution will be terminated. Use value of 0 to indicate that no idle timeout should be imposed. DEFAULT_INVENTORY_UPDATE_TIMEOUT: type: integer minimum: 0 default: 0 description: Maximum time in seconds to allow inventory updates to run. Use value of 0 to indicate that no timeout should be imposed. A timeout set on an individual inventory source will override this. DEFAULT_PROJECT_UPDATE_TIMEOUT: type: integer minimum: 0 default: 0 description: Maximum time in seconds to allow project updates to run. Use value of 0 to indicate that no timeout should be imposed. A timeout set on an individual project will override this. ANSIBLE_FACT_CACHE_TIMEOUT: type: integer minimum: 0 default: 0 title: Per-Host Ansible Fact Cache Timeout description: Maximum time, in seconds, that stored Ansible facts are considered valid since the last time they were modified. Only valid, non-stale, facts will be accessible by a playbook. Note, this does not influence the deletion of ansible_facts from the database. Use a value of 0 to indicate that no timeout should be imposed. MAX_FORKS: type: integer default: 200 title: Maximum number of forks per job description: Saving a Job Template with more than this number of forks will result in an error. When set to 0, no limit is applied. LOG_AGGREGATOR_HOST: type: - string - 'null' title: Logging Aggregator description: Hostname/IP where external logs will be sent to. LOG_AGGREGATOR_PORT: type: - integer - 'null' title: Logging Aggregator Port description: Port on Logging Aggregator to send logs to (if required and not provided in Logging Aggregator). LOG_AGGREGATOR_TYPE: enum: - logstash - splunk - loggly - sumologic - other - null type: - string - 'null' x-spec-enum-id: f7f9aae80827f128 title: Logging Aggregator Type description: 'Format messages for the chosen log aggregator. * `logstash` - logstash * `splunk` - splunk * `loggly` - loggly * `sumologic` - sumologic * `other` - other' LOG_AGGREGATOR_USERNAME: type: string default: '' title: Logging Aggregator Username description: Username for external log aggregator (if required; HTTP/s only). LOG_AGGREGATOR_PASSWORD: type: string default: '' title: Logging Aggregator Password/Token description: Password or authentication token for external log aggregator (if required; HTTP/s only). LOG_AGGREGATOR_LOGGERS: type: array items: type: string default: - awx - activity_stream - job_events - system_tracking - broadcast_websocket - job_lifecycle title: Loggers Sending Data to Log Aggregator Form description: "List of loggers that will send HTTP logs to the collector, these can include any or all of: \nawx - service logs\nactivity_stream - activity stream records\njob_events - callback data from Ansible job events\nsystem_tracking - facts gathered from scan jobs\nbroadcast_websocket - errors pertaining to websockets broadcast metrics\njob_lifecycle - logs related to processing of a job\n" LOG_AGGREGATOR_INDIVIDUAL_FACTS: type: boolean default: false title: Log System Tracking Facts Individually description: If set, system tracking facts will be sent for each package, service, or other item found in a scan, allowing for greater search query granularity. If unset, facts will be sent as a single dictionary, allowing for greater efficiency in fact processing. LOG_AGGREGATOR_ENABLED: type: boolean default: false title: Enable External Logging description: Enable sending logs to external log aggregator. LOG_AGGREGATOR_TOWER_UUID: type: string default: '' title: Cluster-wide unique identifier. description: Useful to uniquely identify instances. LOG_AGGREGATOR_PROTOCOL: enum: - https - tcp - udp type: string x-spec-enum-id: 7d0c803b90b97cde default: https title: Logging Aggregator Protocol description: 'Protocol used to communicate with log aggregator. HTTPS/HTTP assumes HTTPS unless http:// is explicitly used in the Logging Aggregator hostname. * `https` - HTTPS/HTTP * `tcp` - TCP * `udp` - UDP' LOG_AGGREGATOR_TCP_TIMEOUT: type: integer default: 5 title: TCP Connection Timeout description: Number of seconds for a TCP connection to external log aggregator to timeout. Applies to HTTPS and TCP log aggregator protocols. LOG_AGGREGATOR_VERIFY_CERT: type: boolean default: true title: Enable/disable HTTPS certificate verification description: Flag to control enable/disable of certificate verification when LOG_AGGREGATOR_PROTOCOL is "https". If enabled, the log handler will verify certificate sent by external log aggregator before establishing connection. LOG_AGGREGATOR_LEVEL: enum: - DEBUG - INFO - WARNING - ERROR - CRITICAL type: string x-spec-enum-id: 337bdbe45a1d1410 default: INFO title: Logging Aggregator Level Threshold description: 'Level threshold used by log handler. Severities from lowest to highest are DEBUG, INFO, WARNING, ERROR, CRITICAL. Messages less severe than the threshold will be ignored by log handler. (messages under category awx.anlytics ignore this setting) * `DEBUG` - DEBUG * `INFO` - INFO * `WARNING` - WARNING * `ERROR` - ERROR * `CRITICAL` - CRITICAL' LOG_AGGREGATOR_ACTION_QUEUE_SIZE: type: integer minimum: 1 default: 131072 title: Maximum number of messages that can be stored in the log action queue description: Defines how large the rsyslog action queue can grow in number of messages stored. This can have an impact on memory utilization. When the queue reaches 75% of this number, the queue will start writing to disk (queue.highWatermark in rsyslog). When it reaches 90%, NOTICE, INFO, and DEBUG messages will start to be discarded (queue.discardMark with queue.discardSeverity=5). LOG_AGGREGATOR_ACTION_MAX_DISK_USAGE_GB: type: integer minimum: 1 default: 1 title: Maximum disk persistence for rsyslogd action queuing (in GB) description: Amount of data to store (in gigabytes) if an rsyslog action takes time to process an incoming message (defaults to 1). Equivalent to the rsyslogd queue.maxdiskspace setting on the action (e.g. omhttp). It stores files in the directory specified by LOG_AGGREGATOR_MAX_DISK_USAGE_PATH. LOG_AGGREGATOR_MAX_DISK_USAGE_PATH: type: string default: /var/lib/awx title: File system location for rsyslogd disk persistence description: Location to persist logs that should be retried after an outage of the external log aggregator (defaults to /var/lib/awx). Equivalent to the rsyslogd queue.spoolDirectory setting. LOG_AGGREGATOR_RSYSLOGD_DEBUG: type: boolean default: false title: Enable rsyslogd debugging description: Enabled high verbosity debugging for rsyslogd. Useful for debugging connection issues for external log aggregation. API_400_ERROR_LOG_FORMAT: type: string default: status {status_code} received by user {user_name} attempting to access {url_path} from {remote_addr} title: Log Format For API 4XX Errors description: "The format of logged messages when an API 4XX error occurs, the following variables will be substituted: \nstatus_code - The HTTP status code of the error\nuser_name - The user name attempting to use the API\nurl_path - The URL path to the API endpoint called\nremote_addr - The remote address seen for the user\nerror - The error set by the api endpoint\nVariables need to be in the format {}." AUTOMATION_ANALYTICS_LAST_GATHER: type: - string - 'null' format: date-time title: Last gather date for Automation Analytics. AUTOMATION_ANALYTICS_LAST_ENTRIES: type: string default: '' title: Last gathered entries from the data collection service of Automation Analytics AUTOMATION_ANALYTICS_GATHER_INTERVAL: type: integer minimum: 1800 default: 14400 description: Interval (in seconds) between data gathering. CANDLEPIN_CONSUMER_UUID: type: string default: '' description: UUID of the registered Candlepin consumer for this AAP instance. CANDLEPIN_CERT_PEM: type: string default: '' title: Candlepin Identity Certificate description: PEM-encoded Candlepin identity certificate for mTLS authentication. CANDLEPIN_KEY_PEM: type: string default: '' title: Candlepin Identity Key description: PEM-encoded private key for Candlepin identity certificate. CANDLEPIN_SERIAL_NUMBER: type: string default: '' title: Candlepin Certificate Serial Number description: Serial number of the Candlepin identity certificate for tracking. IS_K8S: type: boolean readOnly: true default: false description: Indicates whether the instance is part of a kubernetes-based deployment. BULK_JOB_MAX_LAUNCH: type: integer default: 100 title: Max jobs to allow bulk jobs to launch description: Max jobs to allow bulk jobs to launch BULK_HOST_MAX_CREATE: type: integer default: 100 title: Max number of hosts to allow to be created in a single bulk action description: Max number of hosts to allow to be created in a single bulk action BULK_HOST_MAX_DELETE: type: integer default: 250 title: Max number of hosts to allow to be deleted in a single bulk action description: Max number of hosts to allow to be deleted in a single bulk action SUBSCRIPTION_USAGE_MODEL: enum: - '' - unique_managed_hosts type: string description: '* `` - No subscription. Deletion of host_metrics will not be considered for purposes of managed host counting * `unique_managed_hosts` - Usage based on unique managed nodes in a large historical time frame and delete functionality for no longer used managed nodes' x-spec-enum-id: f0cccba4fe8d04cb default: '' title: Defines subscription usage model and shows Host Metrics CLEANUP_HOST_METRICS_LAST_TS: type: - string - 'null' format: date-time title: Last cleanup date for HostMetrics HOST_METRIC_SUMMARY_TASK_LAST_TS: type: - string - 'null' format: date-time title: Last computing date of HostMetricSummaryMonthly AWX_CLEANUP_PATHS: type: boolean default: true title: Enable or Disable tmp dir cleanup description: Enable or Disable TMP Dir cleanup AWX_REQUEST_PROFILE: type: boolean default: false title: Debug Web Requests description: Debug web request python timing DEFAULT_CONTAINER_RUN_OPTIONS: type: array items: type: string default: - --network - slirp4netns:enable_ipv6=true title: Container Run Options description: 'List of options to pass to podman run example: [''--network'', ''slirp4netns:enable_ipv6=true'', ''--log-level'', ''debug'']' RECEPTOR_RELEASE_WORK: type: boolean default: true title: Release Receptor Work description: Release receptor work RECEPTOR_KEEP_WORK_ON_ERROR: type: boolean default: false title: Keep receptor work on error description: Prevent receptor work from being released on when error is detected OPA_HOST: type: string default: '' title: OPA server hostname description: The hostname used to connect to the OPA server. If empty, policy enforcement will be disabled. OPA_PORT: type: integer default: 8181 title: OPA server port description: The port used to connect to the OPA server. Defaults to 8181. OPA_SSL: type: boolean default: false title: Use SSL for OPA connection description: Enable or disable the use of SSL to connect to the OPA server. Defaults to false. OPA_AUTH_TYPE: enum: - None - Token - Certificate type: string x-spec-enum-id: 831ccaccafb11069 default: None title: OPA authentication type description: 'The authentication type that will be used to connect to the OPA server: "None", "Token", or "Certificate". * `None` - None * `Token` - Token * `Certificate` - Certificate' OPA_AUTH_TOKEN: type: string default: '' title: OPA authentication token description: The token for authentication to the OPA server. Required when OPA_AUTH_TYPE is "Token". If an authorization header is defined in OPA_AUTH_CUSTOM_HEADERS, it will be overridden by OPA_AUTH_TOKEN. OPA_AUTH_CLIENT_CERT: type: string default: '' title: OPA client certificate content description: The content of the client certificate file for mTLS authentication to the OPA server. Required when OPA_AUTH_TYPE is "Certificate". OPA_AUTH_CLIENT_KEY: type: string default: '' title: OPA client key content description: The content of the client key for mTLS authentication to the OPA server. Required when OPA_AUTH_TYPE is "Certificate". OPA_AUTH_CA_CERT: type: string default: '' title: OPA CA certificate content description: The content of the CA certificate for mTLS authentication to the OPA server. Required when OPA_AUTH_TYPE is "Certificate". OPA_AUTH_CUSTOM_HEADERS: type: object additionalProperties: {} default: {} title: OPA custom authentication headers description: Optional custom headers included in requests to the OPA server. Defaults to empty dictionary ({}). OPA_REQUEST_TIMEOUT: type: number format: double default: 1.5 description: The number of seconds after which the connection to the OPA server will time out. Defaults to 1.5 seconds. OPA_REQUEST_RETRIES: type: integer default: 2 title: OPA request retry count description: The number of retry attempts for connecting to the OPA server. Default is 2. SESSION_COOKIE_AGE: type: integer maximum: 30000000000 minimum: 60 format: int64 default: 1800 title: Idle Time Force Log Out description: Number of seconds that a user is inactive before they will need to login again. SESSIONS_PER_USER: type: integer minimum: -1 default: -1 title: Maximum number of simultaneous logged in sessions description: Maximum number of simultaneous logged in sessions a user may have. To disable enter -1. DISABLE_LOCAL_AUTH: type: boolean default: false title: Disable the built-in authentication system description: 'Controls whether users are prevented from using the built-in authentication system. ' AUTH_BASIC_ENABLED: type: boolean default: true title: Enable HTTP Basic Auth description: Enable HTTP Basic Auth for the API Browser. LOGIN_REDIRECT_OVERRIDE: type: string default: '' title: Login redirect override URL description: URL to which unauthorized users will be redirected to log in. If blank, users will be sent to the login page. ALLOW_METRICS_FOR_ANONYMOUS_USERS: type: boolean default: false title: Allow anonymous users to poll metrics description: If true, anonymous users are allowed to poll metrics. PENDO_TRACKING_STATE: enum: - 'off' - anonymous - detailed type: string x-spec-enum-id: ba14e559ac551020 readOnly: true default: 'off' title: User Analytics Tracking State description: 'Enable or Disable User Analytics Tracking. * `off` - Off * `anonymous` - Anonymous * `detailed` - Detailed' CUSTOM_LOGIN_INFO: type: string default: '' description: If needed, you can add specific information (such as a legal notice or a disclaimer) to a text box in the login modal using this setting. Any content added must be in plain text or an HTML fragment, as other markup languages are not supported. CUSTOM_LOGO: type: string default: '' description: To set up a custom logo, provide a file that you create. For the custom logo to look its best, use a .png file with a transparent background. GIF, PNG and JPEG formats are supported. MAX_UI_JOB_EVENTS: type: integer minimum: 100 default: 4000 title: Max Job Events Retrieved by UI description: Maximum number of job events for the UI to retrieve within a single request. UI_LIVE_UPDATES_ENABLED: type: boolean default: true title: Enable Live Updates in the UI description: If disabled, the page will not refresh when events are received. Reloading the page will be required to get the latest details. NAMED_URL_FORMATS: type: object additionalProperties: {} readOnly: true default: execution_environments: organizations: teams: ++ credential_types: + credentials: +++++ notification_templates: ++ job_templates: ++ projects: ++ inventories: ++ hosts: ++++ groups: ++++ inventory_sources: ++++ instance_groups: workflow_job_templates: ++ workflow_job_template_nodes: ++++ labels: ++ users: instances: title: Formats of all available named urls description: Read-only list of key-value pairs that shows the standard format of all available named URLs. NAMED_URL_GRAPH_NODES: type: object additionalProperties: {} readOnly: true default: execution_environments: fields: - name adj_list: [] organizations: fields: - name adj_list: [] teams: fields: - name adj_list: - - organization - organizations credential_types: fields: - name - kind adj_list: [] credentials: fields: - name adj_list: - - credential_type - credential_types - - organization - organizations notification_templates: fields: - name adj_list: - - organization - organizations job_templates: fields: - name adj_list: - - organization - organizations projects: fields: - name adj_list: - - organization - organizations inventories: fields: - name adj_list: - - organization - organizations hosts: fields: - name adj_list: - - inventory - inventories groups: fields: - name adj_list: - - inventory - inventories inventory_sources: fields: - name adj_list: - - inventory - inventories instance_groups: fields: - name adj_list: [] workflow_job_templates: fields: - name adj_list: - - organization - organizations workflow_job_template_nodes: fields: - identifier adj_list: - - workflow_job_template - workflow_job_templates labels: fields: - name adj_list: - - organization - organizations users: fields: - username adj_list: [] instances: fields: - hostname adj_list: [] title: List of all named url graph nodes. description: Read-only list of key-value pairs that exposes named URL graph topology. Use this list to programmatically generate named URLs for resources SettingSingletonRequest: type: object description: Present a group of settings (by category) as a single object. properties: ACTIVITY_STREAM_ENABLED: type: boolean default: true title: Enable Activity Stream description: Enable capturing activity for the activity stream. ACTIVITY_STREAM_ENABLED_FOR_INVENTORY_SYNC: type: boolean default: false title: Enable Activity Stream for Inventory Sync description: Enable capturing activity for the activity stream when running inventory sync. ORG_ADMINS_CAN_SEE_ALL_USERS: type: boolean default: true title: All Users Visible to Organization Admins description: Controls whether any Organization Admin can view all users and teams, even those not associated with their Organization. MANAGE_ORGANIZATION_AUTH: type: boolean default: true title: Organization Admins Can Manage Users and Teams description: Controls whether any Organization Admin has the privileges to create and manage users and teams. TOWER_URL_BASE: type: string minLength: 1 default: https://platformhost title: Base URL of the service description: This setting is used by services like notifications to render a valid url to the service. format: uri REMOTE_HOST_HEADERS: type: array items: type: string minLength: 1 default: - REMOTE_ADDR - REMOTE_HOST description: HTTP headers and meta keys to search to determine remote host name or IP. Add additional items to this list, such as "HTTP_X_FORWARDED_FOR", if behind a reverse proxy. See the "Proxy Support" section of the AAP Installation guide for more details. PROXY_IP_ALLOWED_LIST: type: array items: type: string minLength: 1 default: [] description: If the service is behind a reverse proxy/load balancer, use this setting to configure the proxy IP addresses from which the service should trust custom REMOTE_HOST_HEADERS header values. If this setting is an empty list (the default), the headers specified by REMOTE_HOST_HEADERS will be trusted unconditionally') CSRF_TRUSTED_ORIGINS: type: array items: type: string minLength: 1 default: [] title: CSRF Trusted Origins List description: 'If the service is behind a reverse proxy/load balancer, use this setting to configure the schema://addresses from which the service should trust Origin header values. ' REDHAT_USERNAME: type: string default: '' title: Red Hat Client ID for Analytics description: Client ID used to send data to Automation Analytics REDHAT_PASSWORD: type: string default: '' title: Red Hat Client Secret for Analytics description: Client secret used to send data to Automation Analytics SUBSCRIPTIONS_USERNAME: type: string default: '' title: Red Hat Username for Subscriptions description: Username used to retrieve subscription and content information SUBSCRIPTIONS_PASSWORD: type: string default: '' title: Red Hat Password for Subscriptions description: Password used to retrieve subscription and content information SUBSCRIPTIONS_CLIENT_ID: type: string default: '' title: Red Hat Client ID for Subscriptions description: Client ID used to retrieve subscription and content information SUBSCRIPTIONS_CLIENT_SECRET: type: string default: '' title: Red Hat Client Secret for Subscriptions description: Client secret used to retrieve subscription and content information AUTOMATION_ANALYTICS_URL: type: string minLength: 1 default: https://example.com title: Automation Analytics upload URL description: This setting is used to to configure the upload URL for data collection for Automation Analytics. format: uri AWX_ANALYTICS_CANDLEPIN_CA: type: string default: /etc/rhsm/ca/redhat-uep.pem title: Candlepin CA Certificate Path description: Path to the CA certificate file for verifying TLS connections to Candlepin. Leave blank to use system certificates. AWX_ANALYTICS_CANDLEPIN_RENEWAL_THRESHOLD_DAYS: type: integer minimum: 1 default: 90 title: Candlepin Certificate Renewal Threshold description: Number of days before certificate expiry to trigger automatic renewal of Candlepin identity certificates. AWX_ANALYTICS_CANDLEPIN_PROXY_URL: type: string default: '' title: Candlepin Proxy URL description: HTTP/HTTPS proxy URL for Candlepin API requests (e.g., http://proxy.example.com:8080). Leave blank for no proxy. DEFAULT_EXECUTION_ENVIRONMENT: type: - integer - 'null' title: Global default execution environment description: The Execution Environment to be used when one has not been configured for a job template. CUSTOM_VENV_PATHS: type: array items: type: string minLength: 1 default: [] title: Custom virtual environment paths description: Paths where Tower will look for custom virtual environments (in addition to /var/lib/awx/venv/). Enter one path per line. AD_HOC_COMMANDS: type: array items: type: string minLength: 1 default: - command - shell - yum - apt - apt_key - apt_repository - apt_rpm - service - group - user - mount - ping - selinux - setup - win_ping - win_service - win_updates - win_group - win_user title: Ansible Modules Allowed for Ad Hoc Jobs description: List of modules allowed to be used by ad-hoc jobs. ALLOW_JINJA_IN_EXTRA_VARS: enum: - always - never - template type: string x-spec-enum-id: 28bae37cee4f4fdb default: template title: When can extra variables contain Jinja templates? description: 'Ansible allows variable substitution via the Jinja2 templating language for --extra-vars. This poses a potential security risk where users with the ability to specify extra vars at job launch time can use Jinja2 templates to run arbitrary Python. It is recommended that this value be set to "template" or "never". * `always` - Always * `never` - Never * `template` - Only On Job Template Definitions' INCLUDE_DEPRECATED_AWX_VAR_PREFIX: type: boolean default: true title: Include Deprecated AWX Variable Prefix description: When enabled (default), auto-generated job variables are emitted with both the tower_ prefix and the deprecated awx_ prefix for backward compatibility. Disable to emit only tower_ prefixed variables and eliminate duplicates. The awx_ prefix is deprecated and this setting will default to False in a future release. AWX_ISOLATION_BASE_PATH: type: string minLength: 1 default: /tmp title: Job execution path description: The directory in which the service will create new temporary directories for job execution and isolation (such as credential files). AWX_ISOLATION_SHOW_PATHS: type: array items: type: string minLength: 1 default: [] title: Paths to expose to isolated jobs description: 'List of paths that would otherwise be hidden to expose to isolated jobs. Enter one path per line. Volumes will be mounted from the execution node to the container. The supported format is HOST-DIR[:CONTAINER-DIR[:OPTIONS]]. ' AWX_TASK_ENV: type: object additionalProperties: type: string minLength: 1 default: {} title: Extra Environment Variables description: Additional environment variables set for playbook runs, inventory updates, project updates, and notification sending. AWX_RUNNER_KEEPALIVE_SECONDS: type: integer default: 0 title: K8S Ansible Runner Keep-Alive Message Interval description: Only applies to jobs running in a Container Group. If not 0, send a message every so-many seconds to keep connection open. GALAXY_TASK_ENV: type: object additionalProperties: type: string minLength: 1 default: ANSIBLE_FORCE_COLOR: 'false' GIT_SSH_COMMAND: ssh -o StrictHostKeyChecking=no title: Environment Variables for Galaxy Commands description: Additional environment variables set for invocations of ansible-galaxy within project updates. Useful if you must use a proxy server for ansible-galaxy but not git. INSIGHTS_TRACKING_STATE: type: boolean default: false title: Gather data for Automation Analytics description: Enables the service to gather data on automation and send it to Automation Analytics. PROJECT_UPDATE_VVV: type: boolean default: false title: Run Project Updates With Higher Verbosity description: Adds the CLI -vvv flag to ansible-playbook runs of project_update.yml used for project updates. AWX_ROLES_ENABLED: type: boolean default: true title: Enable Role Download description: Allows roles to be dynamically downloaded from a requirements.yml file for SCM projects. AWX_COLLECTIONS_ENABLED: type: boolean default: true title: Enable Collection(s) Download description: Allows collections to be dynamically downloaded from a requirements.yml file for SCM projects. AWX_SHOW_PLAYBOOK_LINKS: type: boolean default: false title: Follow symlinks description: Follow symbolic links when scanning for playbooks. Be aware that setting this to True can lead to infinite recursion if a link points to a parent directory of itself. AWX_MOUNT_ISOLATED_PATHS_ON_K8S: type: boolean default: false title: Expose host paths for Container Groups description: 'Expose paths via hostPath for the Pods created by a Container Group. HostPath volumes present many security risks, and it is a best practice to avoid the use of HostPaths when possible. ' GALAXY_IGNORE_CERTS: type: boolean default: false title: Ignore Ansible Galaxy SSL Certificate Verification description: If set to true, certificate validation will not be done when installing content from any Galaxy server. STDOUT_MAX_BYTES_DISPLAY: type: integer minimum: 0 default: 1048576 title: Standard Output Maximum Display Size description: Maximum Size of Standard Output in bytes to display before requiring the output be downloaded. EVENT_STDOUT_MAX_BYTES_DISPLAY: type: integer minimum: 0 default: 1024 title: Job Event Standard Output Maximum Display Size description: Maximum Size of Standard Output in bytes to display for a single job or ad hoc command event. `stdout` will end with `…` when truncated. MAX_WEBSOCKET_EVENT_RATE: type: integer minimum: 0 default: 30 title: Job Event Maximum Websocket Messages Per Second description: Maximum number of messages to update the UI live job output with per second. Value of 0 means no limit. SCHEDULE_MAX_JOBS: type: integer minimum: 1 default: 10 title: Maximum Scheduled Jobs description: Maximum number of the same job template that can be waiting to run when launching from a schedule before no more are created. AWX_ANSIBLE_CALLBACK_PLUGINS: type: array items: type: string minLength: 1 default: [] title: Ansible Callback Plugins description: List of paths to search for extra callback plugins to be used when running jobs. Enter one path per line. DEFAULT_JOB_TIMEOUT: type: integer minimum: 0 default: 0 description: Maximum time in seconds to allow jobs to run. Use value of 0 to indicate that no timeout should be imposed. A timeout set on an individual job template will override this. DEFAULT_JOB_IDLE_TIMEOUT: type: integer minimum: 0 default: 0 description: If no output is detected from ansible in this number of seconds the execution will be terminated. Use value of 0 to indicate that no idle timeout should be imposed. DEFAULT_INVENTORY_UPDATE_TIMEOUT: type: integer minimum: 0 default: 0 description: Maximum time in seconds to allow inventory updates to run. Use value of 0 to indicate that no timeout should be imposed. A timeout set on an individual inventory source will override this. DEFAULT_PROJECT_UPDATE_TIMEOUT: type: integer minimum: 0 default: 0 description: Maximum time in seconds to allow project updates to run. Use value of 0 to indicate that no timeout should be imposed. A timeout set on an individual project will override this. ANSIBLE_FACT_CACHE_TIMEOUT: type: integer minimum: 0 default: 0 title: Per-Host Ansible Fact Cache Timeout description: Maximum time, in seconds, that stored Ansible facts are considered valid since the last time they were modified. Only valid, non-stale, facts will be accessible by a playbook. Note, this does not influence the deletion of ansible_facts from the database. Use a value of 0 to indicate that no timeout should be imposed. MAX_FORKS: type: integer default: 200 title: Maximum number of forks per job description: Saving a Job Template with more than this number of forks will result in an error. When set to 0, no limit is applied. LOG_AGGREGATOR_HOST: type: - string - 'null' minLength: 1 title: Logging Aggregator description: Hostname/IP where external logs will be sent to. LOG_AGGREGATOR_PORT: type: - integer - 'null' title: Logging Aggregator Port description: Port on Logging Aggregator to send logs to (if required and not provided in Logging Aggregator). LOG_AGGREGATOR_TYPE: enum: - logstash - splunk - loggly - sumologic - other - null type: - string - 'null' x-spec-enum-id: f7f9aae80827f128 title: Logging Aggregator Type description: 'Format messages for the chosen log aggregator. * `logstash` - logstash * `splunk` - splunk * `loggly` - loggly * `sumologic` - sumologic * `other` - other' LOG_AGGREGATOR_USERNAME: type: string default: '' title: Logging Aggregator Username description: Username for external log aggregator (if required; HTTP/s only). LOG_AGGREGATOR_PASSWORD: type: string default: '' title: Logging Aggregator Password/Token description: Password or authentication token for external log aggregator (if required; HTTP/s only). LOG_AGGREGATOR_LOGGERS: type: array items: type: string minLength: 1 default: - awx - activity_stream - job_events - system_tracking - broadcast_websocket - job_lifecycle title: Loggers Sending Data to Log Aggregator Form description: "List of loggers that will send HTTP logs to the collector, these can include any or all of: \nawx - service logs\nactivity_stream - activity stream records\njob_events - callback data from Ansible job events\nsystem_tracking - facts gathered from scan jobs\nbroadcast_websocket - errors pertaining to websockets broadcast metrics\njob_lifecycle - logs related to processing of a job\n" LOG_AGGREGATOR_INDIVIDUAL_FACTS: type: boolean default: false title: Log System Tracking Facts Individually description: If set, system tracking facts will be sent for each package, service, or other item found in a scan, allowing for greater search query granularity. If unset, facts will be sent as a single dictionary, allowing for greater efficiency in fact processing. LOG_AGGREGATOR_ENABLED: type: boolean default: false title: Enable External Logging description: Enable sending logs to external log aggregator. LOG_AGGREGATOR_TOWER_UUID: type: string default: '' title: Cluster-wide unique identifier. description: Useful to uniquely identify instances. LOG_AGGREGATOR_PROTOCOL: enum: - https - tcp - udp type: string x-spec-enum-id: 7d0c803b90b97cde default: https title: Logging Aggregator Protocol description: 'Protocol used to communicate with log aggregator. HTTPS/HTTP assumes HTTPS unless http:// is explicitly used in the Logging Aggregator hostname. * `https` - HTTPS/HTTP * `tcp` - TCP * `udp` - UDP' LOG_AGGREGATOR_TCP_TIMEOUT: type: integer default: 5 title: TCP Connection Timeout description: Number of seconds for a TCP connection to external log aggregator to timeout. Applies to HTTPS and TCP log aggregator protocols. LOG_AGGREGATOR_VERIFY_CERT: type: boolean default: true title: Enable/disable HTTPS certificate verification description: Flag to control enable/disable of certificate verification when LOG_AGGREGATOR_PROTOCOL is "https". If enabled, the log handler will verify certificate sent by external log aggregator before establishing connection. LOG_AGGREGATOR_LEVEL: enum: - DEBUG - INFO - WARNING - ERROR - CRITICAL type: string x-spec-enum-id: 337bdbe45a1d1410 default: INFO title: Logging Aggregator Level Threshold description: 'Level threshold used by log handler. Severities from lowest to highest are DEBUG, INFO, WARNING, ERROR, CRITICAL. Messages less severe than the threshold will be ignored by log handler. (messages under category awx.anlytics ignore this setting) * `DEBUG` - DEBUG * `INFO` - INFO * `WARNING` - WARNING * `ERROR` - ERROR * `CRITICAL` - CRITICAL' LOG_AGGREGATOR_ACTION_QUEUE_SIZE: type: integer minimum: 1 default: 131072 title: Maximum number of messages that can be stored in the log action queue description: Defines how large the rsyslog action queue can grow in number of messages stored. This can have an impact on memory utilization. When the queue reaches 75% of this number, the queue will start writing to disk (queue.highWatermark in rsyslog). When it reaches 90%, NOTICE, INFO, and DEBUG messages will start to be discarded (queue.discardMark with queue.discardSeverity=5). LOG_AGGREGATOR_ACTION_MAX_DISK_USAGE_GB: type: integer minimum: 1 default: 1 title: Maximum disk persistence for rsyslogd action queuing (in GB) description: Amount of data to store (in gigabytes) if an rsyslog action takes time to process an incoming message (defaults to 1). Equivalent to the rsyslogd queue.maxdiskspace setting on the action (e.g. omhttp). It stores files in the directory specified by LOG_AGGREGATOR_MAX_DISK_USAGE_PATH. LOG_AGGREGATOR_MAX_DISK_USAGE_PATH: type: string minLength: 1 default: /var/lib/awx title: File system location for rsyslogd disk persistence description: Location to persist logs that should be retried after an outage of the external log aggregator (defaults to /var/lib/awx). Equivalent to the rsyslogd queue.spoolDirectory setting. LOG_AGGREGATOR_RSYSLOGD_DEBUG: type: boolean default: false title: Enable rsyslogd debugging description: Enabled high verbosity debugging for rsyslogd. Useful for debugging connection issues for external log aggregation. API_400_ERROR_LOG_FORMAT: type: string minLength: 1 default: status {status_code} received by user {user_name} attempting to access {url_path} from {remote_addr} title: Log Format For API 4XX Errors description: "The format of logged messages when an API 4XX error occurs, the following variables will be substituted: \nstatus_code - The HTTP status code of the error\nuser_name - The user name attempting to use the API\nurl_path - The URL path to the API endpoint called\nremote_addr - The remote address seen for the user\nerror - The error set by the api endpoint\nVariables need to be in the format {}." AUTOMATION_ANALYTICS_LAST_GATHER: type: - string - 'null' format: date-time title: Last gather date for Automation Analytics. AUTOMATION_ANALYTICS_LAST_ENTRIES: type: string default: '' title: Last gathered entries from the data collection service of Automation Analytics AUTOMATION_ANALYTICS_GATHER_INTERVAL: type: integer minimum: 1800 default: 14400 description: Interval (in seconds) between data gathering. CANDLEPIN_CONSUMER_UUID: type: string default: '' description: UUID of the registered Candlepin consumer for this AAP instance. CANDLEPIN_CERT_PEM: type: string default: '' title: Candlepin Identity Certificate description: PEM-encoded Candlepin identity certificate for mTLS authentication. CANDLEPIN_KEY_PEM: type: string default: '' title: Candlepin Identity Key description: PEM-encoded private key for Candlepin identity certificate. CANDLEPIN_SERIAL_NUMBER: type: string default: '' title: Candlepin Certificate Serial Number description: Serial number of the Candlepin identity certificate for tracking. BULK_JOB_MAX_LAUNCH: type: integer default: 100 title: Max jobs to allow bulk jobs to launch description: Max jobs to allow bulk jobs to launch BULK_HOST_MAX_CREATE: type: integer default: 100 title: Max number of hosts to allow to be created in a single bulk action description: Max number of hosts to allow to be created in a single bulk action BULK_HOST_MAX_DELETE: type: integer default: 250 title: Max number of hosts to allow to be deleted in a single bulk action description: Max number of hosts to allow to be deleted in a single bulk action SUBSCRIPTION_USAGE_MODEL: enum: - '' - unique_managed_hosts type: string description: '* `` - No subscription. Deletion of host_metrics will not be considered for purposes of managed host counting * `unique_managed_hosts` - Usage based on unique managed nodes in a large historical time frame and delete functionality for no longer used managed nodes' x-spec-enum-id: f0cccba4fe8d04cb default: '' title: Defines subscription usage model and shows Host Metrics CLEANUP_HOST_METRICS_LAST_TS: type: - string - 'null' format: date-time title: Last cleanup date for HostMetrics HOST_METRIC_SUMMARY_TASK_LAST_TS: type: - string - 'null' format: date-time title: Last computing date of HostMetricSummaryMonthly AWX_CLEANUP_PATHS: type: boolean default: true title: Enable or Disable tmp dir cleanup description: Enable or Disable TMP Dir cleanup AWX_REQUEST_PROFILE: type: boolean default: false title: Debug Web Requests description: Debug web request python timing DEFAULT_CONTAINER_RUN_OPTIONS: type: array items: type: string minLength: 1 default: - --network - slirp4netns:enable_ipv6=true title: Container Run Options description: 'List of options to pass to podman run example: [''--network'', ''slirp4netns:enable_ipv6=true'', ''--log-level'', ''debug'']' RECEPTOR_RELEASE_WORK: type: boolean default: true title: Release Receptor Work description: Release receptor work RECEPTOR_KEEP_WORK_ON_ERROR: type: boolean default: false title: Keep receptor work on error description: Prevent receptor work from being released on when error is detected OPA_HOST: type: string default: '' title: OPA server hostname description: The hostname used to connect to the OPA server. If empty, policy enforcement will be disabled. OPA_PORT: type: integer default: 8181 title: OPA server port description: The port used to connect to the OPA server. Defaults to 8181. OPA_SSL: type: boolean default: false title: Use SSL for OPA connection description: Enable or disable the use of SSL to connect to the OPA server. Defaults to false. OPA_AUTH_TYPE: enum: - None - Token - Certificate type: string x-spec-enum-id: 831ccaccafb11069 default: None title: OPA authentication type description: 'The authentication type that will be used to connect to the OPA server: "None", "Token", or "Certificate". * `None` - None * `Token` - Token * `Certificate` - Certificate' OPA_AUTH_TOKEN: type: string default: '' title: OPA authentication token description: The token for authentication to the OPA server. Required when OPA_AUTH_TYPE is "Token". If an authorization header is defined in OPA_AUTH_CUSTOM_HEADERS, it will be overridden by OPA_AUTH_TOKEN. OPA_AUTH_CLIENT_CERT: type: string default: '' title: OPA client certificate content description: The content of the client certificate file for mTLS authentication to the OPA server. Required when OPA_AUTH_TYPE is "Certificate". OPA_AUTH_CLIENT_KEY: type: string default: '' title: OPA client key content description: The content of the client key for mTLS authentication to the OPA server. Required when OPA_AUTH_TYPE is "Certificate". OPA_AUTH_CA_CERT: type: string default: '' title: OPA CA certificate content description: The content of the CA certificate for mTLS authentication to the OPA server. Required when OPA_AUTH_TYPE is "Certificate". OPA_AUTH_CUSTOM_HEADERS: type: object additionalProperties: {} default: {} title: OPA custom authentication headers description: Optional custom headers included in requests to the OPA server. Defaults to empty dictionary ({}). OPA_REQUEST_TIMEOUT: type: number format: double default: 1.5 description: The number of seconds after which the connection to the OPA server will time out. Defaults to 1.5 seconds. OPA_REQUEST_RETRIES: type: integer default: 2 title: OPA request retry count description: The number of retry attempts for connecting to the OPA server. Default is 2. SESSION_COOKIE_AGE: type: integer maximum: 30000000000 minimum: 60 format: int64 default: 1800 title: Idle Time Force Log Out description: Number of seconds that a user is inactive before they will need to login again. SESSIONS_PER_USER: type: integer minimum: -1 default: -1 title: Maximum number of simultaneous logged in sessions description: Maximum number of simultaneous logged in sessions a user may have. To disable enter -1. DISABLE_LOCAL_AUTH: type: boolean default: false title: Disable the built-in authentication system description: 'Controls whether users are prevented from using the built-in authentication system. ' AUTH_BASIC_ENABLED: type: boolean default: true title: Enable HTTP Basic Auth description: Enable HTTP Basic Auth for the API Browser. LOGIN_REDIRECT_OVERRIDE: type: string default: '' title: Login redirect override URL description: URL to which unauthorized users will be redirected to log in. If blank, users will be sent to the login page. ALLOW_METRICS_FOR_ANONYMOUS_USERS: type: boolean default: false title: Allow anonymous users to poll metrics description: If true, anonymous users are allowed to poll metrics. CUSTOM_LOGIN_INFO: type: string default: '' description: If needed, you can add specific information (such as a legal notice or a disclaimer) to a text box in the login modal using this setting. Any content added must be in plain text or an HTML fragment, as other markup languages are not supported. CUSTOM_LOGO: type: string default: '' description: To set up a custom logo, provide a file that you create. For the custom logo to look its best, use a .png file with a transparent background. GIF, PNG and JPEG formats are supported. MAX_UI_JOB_EVENTS: type: integer minimum: 100 default: 4000 title: Max Job Events Retrieved by UI description: Maximum number of job events for the UI to retrieve within a single request. UI_LIVE_UPDATES_ENABLED: type: boolean default: true title: Enable Live Updates in the UI description: If disabled, the page will not refresh when events are received. Reloading the page will be required to get the latest details. PaginatedSettingSectionListList: type: object required: - count - results properties: count: type: integer example: 123 next: type: - string - 'null' format: uri example: http://api.example.org/accounts/?page=4 previous: type: - string - 'null' format: uri example: http://api.example.org/accounts/?page=2 results: type: array items: $ref: '#/components/schemas/SettingSectionList' SettingPreference: type: object properties: section: type: - string - 'null' title: Section Name maxLength: 150 name: type: string maxLength: 150 value: description: 'Given the *incoming* primitive data, return the value for this field that should be validated and transformed to a native value.' readOnly: true required: - name SettingSection: type: object properties: gateway_token_name: type: string default: X-DAB-JW-TOKEN description: 'The header name to push from the proxy to the backend service. WARNING: if this is changed, backends must be updated to compensate!' gateway_access_token_expiration: type: integer default: 600 description: How long the access tokens are valid for. jwt_expiration_buffer_in_seconds: type: integer default: 15 description: Time, in seconds, prior to token expiration time when the token will be removed from cache. Smaller numbers will increase how long the tokens are kept in cache however it can increase the chance the token would expire while being used. gateway_basic_auth_enabled: type: boolean default: true description: Enable basic auth to the gateway API. gateway_proxy_url: type: string format: uri default: https://localhost:9080 description: The URL to the gateway proxy layer. gateway_proxy_url_ignore_cert: type: boolean default: false title: Gateway Proxy URL Ignore Certificate description: Ignore certificate to the gateway proxy layer. jwt_private_key: type: string default: '' description: The JWT private key. jwt_public_key: type: string readOnly: true default: '' description: The JWT public key (read-only). status_endpoint_backend_timeout_seconds: type: integer default: 5 title: Status Endpoint Backend Timeout in Seconds description: The timeout (in seconds) for the status endpoint to wait when trying to connect to a backend. status_endpoint_backend_verify: type: boolean default: true description: Should SSL certificates of the services be verified when calling individual nodes for statuses. resource_client_request_timeout: type: number format: double minimum: 0.0 default: 10.0 description: The timeout (in seconds) before the resource client will drop requests after forming connections. request_timeout: type: integer default: 30 description: The timeout (in seconds) before the proxy will report a timeout and generate a 504. idle_timeout: type: integer default: 15 description: The idle timeout in seconds for proxied connections. Connections with no data transmitted within this period are closed. Individual routes may extend this value but cannot reduce it. trusted_header_timeout: type: integer maximum: 10000 minimum: 100 default: 1000 description: The validity period (in milliseconds) for the trusted header. password_min_length: type: integer maximum: 100 minimum: 0 default: 0 title: Minimum number of characters in local password description: How long does a local password have to be. password_min_digits: type: integer maximum: 100 minimum: 0 default: 0 title: Minimum number of numerical digits in local password description: How many numerical characters need to be in a local password. password_min_upper: type: integer maximum: 100 minimum: 0 default: 0 title: Minimum number of uppercase characters in local password description: How many upper case characters need to be in a local password. password_min_special: type: integer maximum: 100 minimum: 0 default: 0 title: Minimum number of special characters in local password description: How many special characters need to be in a local password. allow_admins_to_set_insecure: type: boolean default: false title: Allow Platform Admins to Set Insecure User Passwords description: Can a superuser account save an insecure password. LOGIN_REDIRECT_OVERRIDE: type: string format: uri default: '' title: Login redirect override URL description: The URL or absolute path to which unauthorized users will be redirected to log in. If blank, users will be sent to the login page. custom_login_info: type: string default: '' title: Custom Login Information description: Provide specific information (such as a legal notice or a disclaimer) to a text box in the login modal. custom_logo: type: string default: '' description: Provide an image file for setting up a custom logo (must be a data URL with a base64-encoded GIF, PNG or JPEG image). SOCIAL_AUTH_USERNAME_IS_FULL_EMAIL: type: boolean default: false title: Use Email address for usernames description: Enabling this setting will tell social auth to use the full email as username instead of the full name. SESSION_COOKIE_AGE: type: integer maximum: 30000000000 minimum: 60 format: int64 default: 900 description: The time in seconds before a session expires. DEFAULT_PAGE_SIZE: type: integer default: 50 description: The default number of items to show on a list page. MAX_PAGE_SIZE: type: integer default: 200 title: Maximum Page Size description: The maximum number of items allowed on a list page. CSRF_TRUSTED_ORIGINS: type: array items: type: string default: [] title: CSRF Trusted Origins List description: List of CSRF trusted origin URLs. Note, if there are values in Djangos CSRF_TRUSTED_ORIGIN, they will always appear in this list. AAP_DEPLOYMENT_TYPE: type: string readOnly: true default: self-managed description: The deployment type for this AAP instance. MANAGE_ORGANIZATION_AUTH: type: boolean default: true title: Organization Admins Can Manage Users and Teams description: Controls whether any Organization Admin has the privileges to create and manage users and teams. You may want to disable this ability if you are using an LDAP or SAML integration. ORG_ADMINS_CAN_SEE_ALL_USERS: type: boolean default: true title: All Teams and Users Visible to Organization Admins description: Controls whether any Organization Admin can view all users and teams, even those not associated with their Organization. When enabled, organization admins can view all users and teams, even users and teams not associated with their organizations. When disabled, organization admins can only see users and teams from their own organizations. ALLOW_OAUTH2_FOR_EXTERNAL_USERS: type: boolean default: false title: Allow External Users to Create OAuth2 Tokens description: 'Enabling this feature allows users who log in via an external provider (e.g., LDAP, SAML) to create OAuth 2.0 tokens for use with the gateway API. A token’s lifecycle is managed independently from the external authentication session. ' INSIGHTS_TRACKING_STATE: type: boolean default: true title: Gather Insights data for Automation Analytics description: Enables the service to gather data on automation and send it to Automation Analytics. RED_HAT_CONSOLE_URL: type: string format: uri default: https://console.redhat.com title: Automation Analytics upload URL description: This setting is used to to configure the upload URL for data collection for Automation Analytics. REDHAT_USERNAME: type: string default: '' title: Red Hat Hybrid Cloud Console Username description: This username is used to send data to Automation Analytics/ REDHAT_PASSWORD: type: string default: '' title: Red Hat Hybrid Cloud Console Password description: This password is used to send data to Automation Analytics.' SUBSCRIPTIONS_USERNAME: type: string default: '' description: This username is used to retrieve subscription and content information. SUBSCRIPTIONS_PASSWORD: type: string default: '' description: This password is used to retrieve subscription and content information.' AUTOMATION_ANALYTICS_GATHER_INTERVAL: type: integer maximum: 30000000000 minimum: 1800 format: int64 default: 14400 description: The maximum number of items allowed on a list page NOTIFICATION_RSS_FEED_URL: type: string readOnly: true default: https://announcements.ansiblecloud.redhat.com/feed.atom description: URL for RSS feeds from which to load user notifications NOTIFICATION_RSS_FEED_ENABLED: type: boolean default: true description: Enable or disable user notifications RUNTIME_FEATURE_FLAGS: type: boolean readOnly: true default: false title: Runtime Feature Flag Toggling description: Controls whether toggling of runtime flags is allowed. This is currently set through settings. If you'd like to change this please update the RUNTIME_FEATURE_FLAGS setting in your configuration. RUNTIME_FEATURE_FLAGS_UI: type: boolean readOnly: true default: false title: Feature Flags UI Page description: Controls whether the feature flags UI page is displayed. This is currently set through settings. If you'd like to change this please update the RUNTIME_FEATURE_FLAGS_UI setting in your configuration. SettingSectionList: type: object description: Serialize list of settings category properties: url: type: string readOnly: true name: type: string readOnly: true securitySchemes: Basic_Authentication: type: http scheme: basic OAuth2_Authentication: type: oauth2 flows: authorizationCode: authorizationUrl: /o/authorize/ tokenUrl: /o/token/ scopes: read: Read access to resources write: Write access to resources (includes read) password: tokenUrl: /o/token/ scopes: read: Read access to resources write: Write access to resources (includes read) SessionAuthentication: type: apiKey in: cookie name: gateway_sessionid x-refined-from: - red-hat-ansible-automation-platform-automation-controller-openapi.json - red-hat-ansible-automation-platform-platform-gateway-openapi.json