Skip to content

Environment Variables ​

Complete reference of all environment variables used by the package.

These are optional but commonly set to control deployment behavior:

VariableDescriptionExampleDefault
RHDH_VERSIONRHDH version to deploy"1.5""next"
INSTALLATION_METHODDeployment method"helm" or "operator""helm"

Auto-Generated Variables ​

These are set automatically during deployment:

VariableDescriptionSet By
K8S_CLUSTER_ROUTER_BASEOpenShift ingress domainGlobal setup
RHDH_BASE_URLFull RHDH URLRHDHDeployment

Playwright Variables ​

VariableDescriptionDefault
PLAYWRIGHT_WORKERSNumber of parallel workers (e.g., "4", "50%")"50%"
PLAYWRIGHT_RETRIESNumber of test retries on failure0

Local Secret Execution ​

VariableDescriptionRequired
BW_SESSIONSession from an already unlocked local bw CLI installationFor rhdh-e2e-secrets
RHDH_E2E_SECRET_FDInternal child marker for the opt-in secret stream on FD 3Set by the CLI

Export BW_SESSION in the invoking shell before running rhdh-e2e-secrets exec, create, update, or delete. The wrapper uses it to retrieve or update selected Bitwarden items and removes it from child test processes. The describe and list commands query GSM only and do not need BW_SESSION.

Normal rhdh-e2e-secrets exec execution remains environment-based. To opt in to the stream transport, run rhdh-e2e-secrets exec --stream-secrets -- <command>. The CLI removes the selected secret names from the child environment, sends their {name,value} entries over inherited file descriptor 3, and sets RHDH_E2E_SECRET_FD=3. This marker is not a secret value or a user-configured credential. The child's stdin remains inherited, and a consumer must decode the stream and close FD 3 immediately afterward.

GSM secret operations use the cached OpenShift CI wrapper. Run rhdh-e2e-secrets gsm-login once before the first GSM operation; use rhdh-e2e-secrets gsm-clean to remove its cached credentials. The wrapper honors its existing CONTAINER_ENGINE and SECRET_MANAGER_IMAGE variables. SECRET_MANAGER_IMAGE must refer to the quay.io/openshift/ci-public repository; the wrapper and image follow the upstream moving release channel and are not version-pinned. The package verifies the download URL and wrapper structure, but this remains an explicit trust boundary on OpenShift CI's GitHub and Quay repositories. The wrapper cache defaults to ~/.cache/rhdh-e2e-secrets/gsm and mutation locks default to ~/.local/state/rhdh-e2e-secrets; XDG_CACHE_HOME and XDG_STATE_HOME override those locations when set to absolute paths. For corporate network setups, start Node with NODE_USE_ENV_PROXY=1 to use HTTP_PROXY/HTTPS_PROXY, and use NODE_EXTRA_CA_CERTS for an additional trusted CA.

Secret mutation files are created below os.tmpdir()/rhdh-e2e-secrets with 0700 directories and 0600 files. They are removed after each mutation operation completes, and abandoned directories from processes that no longer exist are removed before the next operation that creates a temporary secret. Read-only commands and dry runs do not trigger this cleanup. The operating system's temporary-file cleanup is only a final fallback after an ungraceful termination such as SIGKILL. See Temporary secret files for the cleanup and manual recovery procedures.

Optional Variables ​

VariableDescriptionDefault
CIEnables auto-cleanup-
CHART_URLCustom Helm chart URLoci://quay.io/rhdh/chart
SKIP_KEYCLOAK_DEPLOYMENTSkip Keycloak auto-deployfalse
SKIP_OPERATOR_INSTALLATIONSkip operator installation in global setup-
RHDH_SKIP_PLUGIN_METADATA_INJECTIONDisable plugin metadata injection (local only, ignored in CI)-

Plugin Metadata Variables ​

These control automatic plugin configuration injection from metadata files.

DPDY refers to dynamic-plugins.default.yaml in the catalog index image shipped with RHDH. The list of DPDY packages is defined in default.packages.yaml.

VariableDescriptionEffect
GIT_PR_NUMBERPR number (set by OpenShift CI)Enables OCI URL generation for PR builds
E2E_NIGHTLY_MODEWhen "true", activates nightly modePlugins in default.packages.yaml with OCI metadata use (RHDH resolves both OCI tag and config from DPDY); other OCI plugins use full metadata refs with config injection
RHDH_SKIP_PLUGIN_METADATA_INJECTIONWhen "true", disables metadata injectionLocal-only opt-out (ignored when CI=true)
RELEASE_BRANCH_NAMERelease branch (set by OpenShift CI step registry)Used to fetch default.packages.yaml for DPDY resolution in nightly mode. Required in CI, defaults to main locally
NIGHTLY_DPDY_OCI_REGISTRYOCI registry for refsOverrides default registry.access.redhat.com/rhdh for all plugins using in nightly mode
NIGHTLY_DPDY_OCI_REGISTRY_MAPJSON: {"registry": ["pkg1", "pkg2"]}Per-plugin registry override for refs (takes precedence over NIGHTLY_DPDY_OCI_REGISTRY)
JOB_NAMECI job name (set by OpenShift CI/Prow)If contains periodic-, nightly mode is activated
JOB_MODECI-only: nightly or pr-check (set by step registry)Informational

The package defaults include the current RHDH frontend plugins. Override their OCI references in your workspace tests/config/dynamic-plugins.yaml using the same pattern as any other plugin; workspace values are merged after package defaults.

OCI URL Generation ​

When GIT_PR_NUMBER is set, the package replaces local plugin paths with OCI URLs:

yaml
# Before
- package: ./dynamic-plugins/dist/my-plugin

# After (with GIT_PR_NUMBER=1234)
- package: oci://ghcr.io/redhat-developer/rhdh-plugin-export-overlays/my-plugin:pr_1234__1.0.0

See Plugin Metadata for complete details.

Keycloak Variables ​

Required when using auth: "keycloak":

VariableDescription
KEYCLOAK_BASE_URLKeycloak instance URL
KEYCLOAK_REALMRealm name
KEYCLOAK_CLIENT_IDOIDC client ID
KEYCLOAK_CLIENT_SECRETOIDC client secret
KEYCLOAK_METADATA_URLOIDC discovery URL
KEYCLOAK_LOGIN_REALMLogin realm name
KEYCLOAK_USER_NAMEDefault test username
KEYCLOAK_USER_PASSWORDDefault test password

These are automatically set by KeycloakHelper.configureForRHDH().

GitHub Variables ​

For GitHub integration:

VariableDescriptionRequired
VAULT_GITHUB_USER_TOKENGitHub personal access tokenFor API/auth
VAULT_GH_USER_IDGitHub usernameFor login
VAULT_GH_USER_PASSGitHub passwordFor login
VAULT_GH_2FA_SECRET2FA secret for OTPFor login

Custom Variables ​

Use in configuration files:

yaml
# tests/config/app-config-rhdh.yaml
myPlugin:
  apiUrl: ${MY_PLUGIN_API_URL}
  apiKey: ${MY_PLUGIN_API_KEY:-default-key}
yaml
# tests/config/rhdh-secrets.yaml
stringData:
  MY_PLUGIN_API_KEY: ${MY_PLUGIN_API_KEY}

Setting Variables ​

.env File ​

Create .env in your project root:

bash
RHDH_VERSION="1.5"
INSTALLATION_METHOD="helm"
SKIP_KEYCLOAK_DEPLOYMENT=false

# Secrets
GITHUB_TOKEN=ghp_xxxxx
MY_API_KEY=secret-value

The .env file is automatically loaded by global setup. During local runs, .env values override inherited values, including values supplied by the local secret wrapper. In CI, inherited environment values take priority and .env only fills missing values.

CI/CD ​

Set in your CI pipeline:

yaml
# GitHub Actions
env:
  RHDH_VERSION: "1.5"
  INSTALLATION_METHOD: "helm"
  GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}

Runtime ​

Set programmatically:

typescript
test.beforeAll(async ({ rhdh }) => {
  process.env.MY_CUSTOM_URL = await rhdh.k8sClient.getRouteLocation(
    rhdh.deploymentConfig.namespace,
    "my-service",
  );

  await rhdh.deploy();
});

Variable Precedence ​

During global setup:

  • Local runs: .env > inherited environment > default values
  • CI runs: inherited environment > .env > default values

Values assigned to process.env after global setup override both sources.

Released under the Apache-2.0 License.