# Enable SSO for Kubernetes deployment

You can use [JetBrains Hub](https://www.jetbrains.com.cn/en-us/help/hub/Introduction-to-HUB.html) (further in the article referred to as Hub) for user authentication and user management in Datalore. Hub supports most popular [identity providers](https://www.jetbrains.com.cn/en-us/help/hub/Managing-Auth-Modules.html).

This article explains how to enable Hub for Datalore On-Premises installed [using Kubernetes](install-datalore-on-premises-using-kubernetes-helm.html). If your Datalore deployment is done with Docker, see [Enable SSO for Docker deployment](use-hub-for-docker-installation.html).

## Prerequisites

Define a base URL for the Hub installation and make sure that Kubernetes cluster used for this installation is capable of providing Ingress resource. For that, an [Ingress controller](https://kubernetes.io/docs/concepts/services-networking/ingress-controllers/) should be installed and configured prior to the Hub installation.

In this article, we will use hub.example.com as base URL and [Nginx](https://github.com/kubernetes/ingress-nginx) as an ingress controller.

## Install and configure Hub

Procedure: Install Hub

> **Note:**
> If you have Hub already installed, you can skip this step and go to [Configure the Datalore service in Hub](#configure-the-datalore-service).

1. Create a `hub.values.yaml` file, using the below example as reference:

```YAML
volumeClaimTemplates:
  - metadata:
      name: hub
    spec:
      accessModes:
        - ReadWriteOnce
      resources:
        requests:
          storage: 10Gi

volumeMounts:
  - name: hub
    mountPath: /opt/hub/data
    subPath: data
  - name: hub
    mountPath: /opt/hub/conf
    subPath: conf
  - name: hub
    mountPath: /opt/hub/logs
    subPath: logs
  - name: hub
    mountPath: /opt/hub/backups
    subPath: backups

ingress:
  enabled: true
  hosts:
    - host: hub.example.com
      paths:
        - path: /
          pathType: Prefix
  annotations:
    kubernetes.io/ingress.class: "nginx"
```

> **Tip:**
> This example does not include TLS certificate configuration for the Hub installation.
>
>
>
> TLS certificates can be configured in the same way, as for Datalore installation. For more information, see [this article.](datalore-on-premises-security-considerations.html#configure-tls-certificates-for-datalore)

> **Tip:**
> For more explanation about the storage allocation of the Hub deployment, see the [Hub installation guide.](https://www.jetbrains.com.cn/en-us/help/hub/docker-installation.html#create-and-configure-directories)

2. Install the Hub Helm chart and wait, until Hub's pod is in Ready state.

```
helm install -f hub.values.yaml hub datalore/hub --version 0.2.45
```

```
kubectl wait --for=condition=Ready pod/hub-0
```

3. Check the pod logs (using the `kubectl logs service/hub` command) for a `wizard_token`. The output should have a line like this:

```PLAINTEXT
JetBrains Hub 2025.1 Configuration Wizard will listen inside container on {0.0.0.0:8080}/ after start
and can be accessed by this URL: [http://<put-your-docker-HOST-name-here>:<put-host-port-mapped-to-container-port-8080-here>/?wizard_token=pPXTShp4NXceXqGYzeAq].
```

Copy the `wizard_token` value to the clipboard - this value is required during the Hub bootstrapping procedure.

4. Open the Hub's base URL in your browser and insert the `wizard_token` into the Token field.

5. Click the Log in button.

6. Click the Set Up link.

> **Note:**
> On the next screen, you will be asked whether Hub should be deployed in HTTP or HTTPS mode.
>
>
>
> If the TLS termination is handled by your ingress controller, or you do not have TLS termination configured at all — the HTTP option should be chosen on a Confirm Settings page, as Hub receives plain HTTP traffic in this case.
>
>
>
> In case you want the TLS termination to happen on the Hub side, then the HTTPS tab should be chosen. You may refer to [this page](https://www.jetbrains.com.cn/en-us/help/hub/docker-installation.html#configure-new-instance) for more details.

7. In Base URL, enter specify a Hub public URL (referred to as `HUB_ROOT_URL` later). Do not change the Application Listen Port setting.

> **Warning:**
> The URL must be accessible from the browser (by the end users of your Datalore installation).

8. Click the Next button.

9. Configure the admin account by setting the admin password.

10. Click the Next button.

11. Click the Finish button and wait for Hub to start.

Procedure: Configure the Datalore service in Hub

> **Tip:**
> The term Datalore base URL is used in this chapter.
>
>
>
> This term refers to the URL that is used to access Datalore in the browser and is set in the `DATALORE_PUBLIC_URL` [configuration option](server-configuration.html).

1. Go to Services (click the gear icon in the right upper side of the screen, then Services) and click the New service button.

Use the name `datalore` and provide the Datalore base URL.

2. Copy the ID field value and save it somewhere temporarily. It will be required later to configure Datalore.

3. Click the Change... button next to the Secret label.

4. Copy the generated secret and save it somewhere temporarily: it will be used when configuring Datalore (`$HUB_DATALORE_SERVICE_SECRET` property). Click the Change secret button to confirm the selection.

5. Enter the Datalore base URL in the Base URLs field.

6. Enter the line `/api/hub/openid/login` in the Redirect URIs field.

7. Click the Trust Service button in the upper right corner.

8. Click the Save button.

## Enabling Hub in Datalore

To enable Hub, the following configuration variables must [be defined](server-configuration.html#server_configuration_how_to_apply) (and the server should be [restarted](restart-shutdown.html) once changes are applied):

* `HUB_PUBLIC_BASE_URL`: Hub public URL (the one you specified in the Base URL field during the Hub installation).

* `HUB_DATALORE_SERVICE_ID`: ID of the Datalore service in Hub (the one you created in the [Configure the Datalore service in Hub](#configure-the-datalore-service) step).

* `HUB_DATALORE_SERVICE_SECRET`: Token of the Datalore service in Hub (the one you created in the [Configure the Datalore service in Hub](#configure-the-datalore-service) step).

> **Warning:**
> If your installation does not have an outgoing mail configured, we advise to set the `HUB_FORCE_EMAIL_VERIFICATION` parameter to `false`.

For the full list of available configuration options, see the [Single sign-on (Hub) configuration](server-configuration.html#server_configuration_sso) section.

## Optional procedures

Procedure: Enable additional auth modules

Authentication modules are used to verify the identity of users before granting them access to resources in Hub.

1. Click the gear icon in the right upper side of the Hub admin panel, then go to Auth Modules.

2. Add or remove auth modules (for example, Google Auth, GitHub Auth, LDAP, and so on).

> **Note:**
> You can find more details and the full list of supported auth modules [here.](https://www.jetbrains.com.cn/en-us/help/hub/Managing-Auth-Modules.html)

Procedure: Force email verification

Datalore uses user emails from Hub; so it is recommended to force email verification in Hub. When this option is enabled, users with unverified emails will not be able to use Datalore.

1. Configure the SMTP server:

* Click the gear icon in the right upper side of the Hub admin panel, then go to SMTP

* Click the Configure SMTP server... button.

* Configure your SMTP server parameters.

* Click the Save button.

* Click the Enable notifications button.

* (Optional) To make sure your configuration is working, click the Send Test message button.

2. Enable email verification:

* Click the gear icon in the right upper side of the Hub admin panel, then go to Auth Modules.

* Open the Common settings page.

* Enable the Email verification option.

* Click the Save button.

3. Set and verify an admin user email:

* Click the gear icon in the right upper side of the Hub admin panel, then go to Users.

* Click your admin username.

* Set an email in the Email field.

* Click the Save button.

* Click the Send verification email link.

* Find the verification email in your inbox and click the Verify email address button.

> **Note:**
> Changing a user's email in Hub updates the respective user's email in Datalore.

