Lichen Helm Chart #
Quickstart #
Prerequisites: a k3s (or k8s) cluster with helm installed.
# Install
helm install lichen ./charts/lichen \
--set dashboardDomain=lichen.example.com
# Get admin password
kubectl get secret lichen-admin-password -o jsonpath='{.data.password}' | base64 -d
Point your DNS (both lichen.example.com and *.example.com) to the server. Visit https://lichen.example.com and log in with username admin and the password above.
Upgrading #
helm upgrade lichen ./charts/lichen \
--set dashboardDomain=lichen.example.com
The admin password is preserved across upgrades.
Configuration #
Dashboard Domain #
--set dashboardDomain=lichen.example.com
Sets the domain for the management dashboard. Lichen uses this for routing: requests to this domain go to the dashboard, requests to other domains serve sites.
TLS with Caddy #
Caddy is enabled by default as a reverse proxy with on-demand TLS. It automatically obtains Let's Encrypt certificates for any domain pointed at the server. No cert-manager or ingress controller needed.
# Disable Caddy (e.g., if using your own ingress controller)
--set caddy.enabled=false
Auth #
Auth is enabled by default with file and atproto providers.
# Disable auth
--set auth.enabled=false
# File auth only
--set 'auth.providers={file}'
# All providers
--set 'auth.providers={file,atproto,oidc}'
Admin User #
An admin user is auto-created on first deploy with a random password stored in a Kubernetes Secret.
# Custom username
--set auth.adminUser.username=myuser
# Specific password instead of random
--set auth.adminUser.password=mysecretpassword
# Disable auto-creation
--set auth.adminUser.enabled=false
Retrieve the password:
kubectl get secret lichen-admin-password -o jsonpath='{.data.password}' | base64 -d
Ingress (alternative to Caddy) #
If you prefer to use an existing ingress controller instead of Caddy:
helm install lichen ./charts/lichen \
--set ingress.enabled=true \
--set ingress.className=nginx \
--set 'ingress.hosts[0].host=lichen.example.com' \
--set 'ingress.hosts[0].paths[0].path=/' \
--set 'ingress.hosts[0].paths[0].pathType=Prefix'
Extra Environment Variables #
Pass additional LM_ environment variables to the lichen container:
--set env.LM_DEVELOPMENT_MODE=true
Persistence #
--set persistence.size=10Gi
--set persistence.storageClass=local-path
Data is stored at /data/lichen on the PVC.
Architecture #
Internet -> Caddy (:443, on-demand TLS) -> lichen Service (:80) -> lichen Pod (:9000)
- Caddy runs with
hostNetworkon ports 80/443 and auto-issues TLS certs via Let's Encrypt for any domain - lichen runs in multi-site mode with persistent storage and auth
- Init container writes
lichen.tomlconfig and creates the admin user on first deploy