deployment templates for lichen
README.md

Lichen Helm Chart #

Quickstart #

Prerequisites: a k3s (or k8s) cluster with helm installed.

# Install
helm install lichen ./charts/lichen \
  --set dashboardDomain=lichen.example.com

# Get admin password
kubectl get secret lichen-admin-password -o jsonpath='{.data.password}' | base64 -d

Point your DNS (both lichen.example.com and *.example.com) to the server. Visit https://lichen.example.com and log in with username admin and the password above.

Upgrading #

helm upgrade lichen ./charts/lichen \
  --set dashboardDomain=lichen.example.com

The admin password is preserved across upgrades.

Configuration #

Dashboard Domain #

--set dashboardDomain=lichen.example.com

Sets the domain for the management dashboard. Lichen uses this for routing: requests to this domain go to the dashboard, requests to other domains serve sites.

TLS with Caddy #

Caddy is enabled by default as a reverse proxy with on-demand TLS. It automatically obtains Let's Encrypt certificates for any domain pointed at the server. No cert-manager or ingress controller needed.

# Disable Caddy (e.g., if using your own ingress controller)
--set caddy.enabled=false

Auth #

Auth is enabled by default with file and atproto providers.

# Disable auth
--set auth.enabled=false

# File auth only
--set 'auth.providers={file}'

# All providers
--set 'auth.providers={file,atproto,oidc}'

Admin User #

An admin user is auto-created on first deploy with a random password stored in a Kubernetes Secret.

# Custom username
--set auth.adminUser.username=myuser

# Specific password instead of random
--set auth.adminUser.password=mysecretpassword

# Disable auto-creation
--set auth.adminUser.enabled=false

Retrieve the password:

kubectl get secret lichen-admin-password -o jsonpath='{.data.password}' | base64 -d

Ingress (alternative to Caddy) #

If you prefer to use an existing ingress controller instead of Caddy:

helm install lichen ./charts/lichen \
  --set ingress.enabled=true \
  --set ingress.className=nginx \
  --set 'ingress.hosts[0].host=lichen.example.com' \
  --set 'ingress.hosts[0].paths[0].path=/' \
  --set 'ingress.hosts[0].paths[0].pathType=Prefix'

Extra Environment Variables #

Pass additional LM_ environment variables to the lichen container:

--set env.LM_DEVELOPMENT_MODE=true

Persistence #

--set persistence.size=10Gi
--set persistence.storageClass=local-path

Data is stored at /data/lichen on the PVC.

Architecture #

Internet -> Caddy (:443, on-demand TLS) -> lichen Service (:80) -> lichen Pod (:9000)
  • Caddy runs with hostNetwork on ports 80/443 and auto-issues TLS certs via Let's Encrypt for any domain
  • lichen runs in multi-site mode with persistent storage and auth
  • Init container writes lichen.toml config and creates the admin user on first deploy