From 4202d571fe5a94d86e1d318fb6ae2b04b2fd2149 Mon Sep 17 00:00:00 2001 From: katarzyna_koltun Date: Wed, 30 Sep 2026 14:38:42 +0200 Subject: [PATCH 01/12] PMP fixes --- .../en/docs/private-platform/quickstart/pmp-quickstart-helm.md | 1 + 1 file changed, 1 insertion(+) diff --git a/content/en/docs/private-platform/quickstart/pmp-quickstart-helm.md b/content/en/docs/private-platform/quickstart/pmp-quickstart-helm.md index de024c18b88..d06bd5341e4 100644 --- a/content/en/docs/private-platform/quickstart/pmp-quickstart-helm.md +++ b/content/en/docs/private-platform/quickstart/pmp-quickstart-helm.md @@ -903,6 +903,7 @@ mx-privatecloud: Workload Identity and Secret Provider Class are different approaches for database credentials management. | Feature | Workload Identity (IAM Authentication) | Secret Provider Class | +| --- | --- | --- | | Purpose | Passwordless database connection at runtime | Inject all secrets from vault during installation | | What it secures | Database passwords only | Database credentials and all other secrets | | Configuration | `awsIRSA.enable: true` or azureWorkloadIdentity.enable: true` and empty passwords | `secretProviderclass.enable: true` | From 3c6c0efbdf917c09df23b3ce6768bc1e15aed08e Mon Sep 17 00:00:00 2001 From: katarzyna_koltun Date: Wed, 30 Sep 2026 14:43:13 +0200 Subject: [PATCH 02/12] removed info about exclusive credentials --- .../private-platform/quickstart/pmp-quickstart-helm.md | 8 ++------ 1 file changed, 2 insertions(+), 6 deletions(-) diff --git a/content/en/docs/private-platform/quickstart/pmp-quickstart-helm.md b/content/en/docs/private-platform/quickstart/pmp-quickstart-helm.md index d06bd5341e4..f0ab9c0090d 100644 --- a/content/en/docs/private-platform/quickstart/pmp-quickstart-helm.md +++ b/content/en/docs/private-platform/quickstart/pmp-quickstart-helm.md @@ -909,7 +909,6 @@ Workload Identity and Secret Provider Class are different approaches for databas | Configuration | `awsIRSA.enable: true` or azureWorkloadIdentity.enable: true` and empty passwords | `secretProviderclass.enable: true` | | Works with | AWS RDS IAM authentication or Azure Database Managed Identity authentication | AWS Secrets Manager, Azure Key Vault, HashiCorp Vault | | Credential type | Temporary cloud tokens (auto-rotated) | Static secrets from vault | -| Can it be combined? | No - mutually exclusive with Secret Provider Class | No - mutually exclusive with Workload Identity | ##### Key Differences @@ -956,7 +955,7 @@ Mendix Operator automatically performs the following tasks: {{% alert color="info" %}} When `UseStoragePlanwithIRSA` is set to `true`, the Mendix Operator creates the ServiceAccount, not the Helm chart. This causes the following limitations: -* Chart-level `azureWorkloadIdentity` configuration does NOT work for mxplatform +* Chart-level `azureWorkloadIdentity` configuration is not supported for mxplatform. * The chart cannot add `azure.workload.identity/client-id` annotation. The Service account will be created by the Operator. {{% /alert %}} @@ -1037,7 +1036,6 @@ Workload Identity and Secret Provider Class are different approaches for databas | Credentials | Temporary cloud tokens (auto-rotated by AWS or Azure) | Static secrets from vault | | Configuration | In StoragePlan CRDs and `UseStoragePlanwithIRSA: true` | `secretProviderclass.enable: true` | | ServiceAccount | Created by Mendix Operator (based on StoragePlan) | Created by Helm chart | -| Can it be combined? | No - mutually exclusive with Secret Provider Class | No - mutually exclusive with Workload Identity | ##### Key Differences @@ -1060,9 +1058,7 @@ Use Secret Provider Class when: * You need multi-cloud secret management (AWS Secrets Manager, Azure Key Vault, HashiCorp Vault). * You want centralized secret management across all Private Mendix Platform components (mx-privatecloud, svix-server, mxplatform). * You are using HashiCorp Vault or managing secrets across multiple cloud providers. -* Example scenario: *I want to store all Private Mendix Platform installation secrets (PCLM password, admin password, database credentials) in Azure Key Vault and inject them during Helm installation. - -The two solutions cannot be used together. They are mutually exclusive for `mxplatform`. +* Example scenario: *I want to store all Private Mendix Platform installation secrets (PCLM password, admin password, database credentials) in Azure Key Vault and inject them during Helm installation.* If `UseStoragePlanwithIRSA` is set to `true`, the Operator creates the ServiceAccount with database and storage identity. The chart then cannot use Secret Provider Class for that ServiceAccount. From d764ca91ceb57f18631d9598e381295446569435 Mon Sep 17 00:00:00 2001 From: katarzyna_koltun Date: Wed, 30 Sep 2026 14:49:40 +0200 Subject: [PATCH 03/12] Helmfile updates --- .../private-platform/quickstart/pmp-quickstart-helm.md | 10 +++++++++- 1 file changed, 9 insertions(+), 1 deletion(-) diff --git a/content/en/docs/private-platform/quickstart/pmp-quickstart-helm.md b/content/en/docs/private-platform/quickstart/pmp-quickstart-helm.md index f0ab9c0090d..a0dc79fdfa4 100644 --- a/content/en/docs/private-platform/quickstart/pmp-quickstart-helm.md +++ b/content/en/docs/private-platform/quickstart/pmp-quickstart-helm.md @@ -569,7 +569,7 @@ To use the Secret Provider class, you must fulfill the following requirements: 3. Grant vault access permissions to the identity. 4. Store secrets in the vault with the correct key names. -5. Enable `secretProviderclass` in hHelmfile configuration. +5. Enable `secretProviderclass` in Helmfile configuration. 6. Inject credentials from external secret management systems (AWS Secrets Manager, Azure Key Vault, HashiCorp Vault). {{% alert color="info" %}} @@ -902,6 +902,10 @@ mx-privatecloud: Workload Identity and Secret Provider Class are different approaches for database credentials management. +{{% alert color="info" %}} +You can combine Secret Provider Class with Workload Identity. Use Secret Provider Class for certain configurations, and Workload Identity with automated Managed Identity, or vice versa. +{{% /alert %}} + | Feature | Workload Identity (IAM Authentication) | Secret Provider Class | | --- | --- | --- | | Purpose | Passwordless database connection at runtime | Inject all secrets from vault during installation | @@ -1044,6 +1048,10 @@ Workload Identity and Secret Provider Class are different approaches for databas ##### Decision Matrix +{{% alert color="info" %}} +You can combine Secret Provider Class with Workload Identity. Use Secret Provider Class for certain configurations, and Workload Identity with automated Managed Identity, or vice versa. +{{% /alert %}} + Use Workload Identity (StoragePlan) when: * You want passwordless database and storage access for your running Mendix application. From df5732e7aaffc08a93380edec089a9fd71dedb92 Mon Sep 17 00:00:00 2001 From: katarzyna_koltun Date: Wed, 30 Sep 2026 14:51:43 +0200 Subject: [PATCH 04/12] prereq updates --- content/en/docs/private-platform/pmp-prerequisites.md | 4 ---- 1 file changed, 4 deletions(-) diff --git a/content/en/docs/private-platform/pmp-prerequisites.md b/content/en/docs/private-platform/pmp-prerequisites.md index 7b684126dd5..811b88b5c31 100644 --- a/content/en/docs/private-platform/pmp-prerequisites.md +++ b/content/en/docs/private-platform/pmp-prerequisites.md @@ -90,10 +90,6 @@ Your Mendix app will be deployed with and run by the Private Mendix Platform Ope | Prometheus | 3.7.3 | | Loki | 2.6.1 | -{{% alert color="info" %}} -Currently, Private Mendix Platform only supports Grafana configurations with a single Loki and a single Prometheus data source. Configurations using a central Grafana instance with multiple Loki or Prometheus datasources are not supported. -{{% /alert %}} - #### Supported Cluster Types{#supported-clusters} We currently support deploying to the following Kubernetes cluster types: From 16d31d7fe9a1d30db61a0f8a32cebe032647e2d9 Mon Sep 17 00:00:00 2001 From: katarzyna_koltun Date: Wed, 30 Sep 2026 15:16:10 +0200 Subject: [PATCH 05/12] sme review --- .../quickstart/pmp-quickstart-helm.md | 12 ++++-------- 1 file changed, 4 insertions(+), 8 deletions(-) diff --git a/content/en/docs/private-platform/quickstart/pmp-quickstart-helm.md b/content/en/docs/private-platform/quickstart/pmp-quickstart-helm.md index a0dc79fdfa4..bbfc7b312f7 100644 --- a/content/en/docs/private-platform/quickstart/pmp-quickstart-helm.md +++ b/content/en/docs/private-platform/quickstart/pmp-quickstart-helm.md @@ -902,10 +902,6 @@ mx-privatecloud: Workload Identity and Secret Provider Class are different approaches for database credentials management. -{{% alert color="info" %}} -You can combine Secret Provider Class with Workload Identity. Use Secret Provider Class for certain configurations, and Workload Identity with automated Managed Identity, or vice versa. -{{% /alert %}} - | Feature | Workload Identity (IAM Authentication) | Secret Provider Class | | --- | --- | --- | | Purpose | Passwordless database connection at runtime | Inject all secrets from vault during installation | @@ -913,6 +909,7 @@ You can combine Secret Provider Class with Workload Identity. Use Secret Provide | Configuration | `awsIRSA.enable: true` or azureWorkloadIdentity.enable: true` and empty passwords | `secretProviderclass.enable: true` | | Works with | AWS RDS IAM authentication or Azure Database Managed Identity authentication | AWS Secrets Manager, Azure Key Vault, HashiCorp Vault | | Credential type | Temporary cloud tokens (auto-rotated) | Static secrets from vault | +| Can it be combined? | No - mutually exclusive with Secret Provider Class | No - mutually exclusive with Workload Identity | ##### Key Differences @@ -1040,6 +1037,7 @@ Workload Identity and Secret Provider Class are different approaches for databas | Credentials | Temporary cloud tokens (auto-rotated by AWS or Azure) | Static secrets from vault | | Configuration | In StoragePlan CRDs and `UseStoragePlanwithIRSA: true` | `secretProviderclass.enable: true` | | ServiceAccount | Created by Mendix Operator (based on StoragePlan) | Created by Helm chart | +| Can it be combined? | No - mutually exclusive with Secret Provider Class | No - mutually exclusive with Workload Identity | ##### Key Differences @@ -1048,10 +1046,6 @@ Workload Identity and Secret Provider Class are different approaches for databas ##### Decision Matrix -{{% alert color="info" %}} -You can combine Secret Provider Class with Workload Identity. Use Secret Provider Class for certain configurations, and Workload Identity with automated Managed Identity, or vice versa. -{{% /alert %}} - Use Workload Identity (StoragePlan) when: * You want passwordless database and storage access for your running Mendix application. @@ -1068,6 +1062,8 @@ Use Secret Provider Class when: * You are using HashiCorp Vault or managing secrets across multiple cloud providers. * Example scenario: *I want to store all Private Mendix Platform installation secrets (PCLM password, admin password, database credentials) in Azure Key Vault and inject them during Helm installation.* +The two solutions cannot be used together. They are mutually exclusive for `mxplatform`. + If `UseStoragePlanwithIRSA` is set to `true`, the Operator creates the ServiceAccount with database and storage identity. The chart then cannot use Secret Provider Class for that ServiceAccount. If `secretProviderclass.enable` is set to `true`, the chart creates the ServiceAccount with vault access. The chart cannot then use StoragePlan with Workload Identity for database or storage. From 40285d6c208d785ebd2437080cd02d95e1e7f544 Mon Sep 17 00:00:00 2001 From: katarzyna_koltun Date: Wed, 30 Sep 2026 15:20:45 +0200 Subject: [PATCH 06/12] sme review --- .../quickstart/pmp-quickstart-helm.md | 16 ++++++++++++---- 1 file changed, 12 insertions(+), 4 deletions(-) diff --git a/content/en/docs/private-platform/quickstart/pmp-quickstart-helm.md b/content/en/docs/private-platform/quickstart/pmp-quickstart-helm.md index bbfc7b312f7..c40b6eecb83 100644 --- a/content/en/docs/private-platform/quickstart/pmp-quickstart-helm.md +++ b/content/en/docs/private-platform/quickstart/pmp-quickstart-helm.md @@ -554,13 +554,17 @@ global: - name: acr-secret # Must exist in EACH namespace ``` -## Secret Management Using the Secret Provider Class +## Secret Management Using the SecretProviderClass -The Secret Provider class allows you to store all sensitive credentials (passwords, connection strings, API keys) in a centralized vault (Azure Key Vault, AWS Secrets Manager, or HashiCorp Vault) instead of hardcoding them in configuration files. +The SecretProviderClass allows you to store all sensitive credentials (passwords, connection strings, API keys) in a centralized vault (Azure Key Vault, AWS Secrets Manager, or HashiCorp Vault) instead of hardcoding them in configuration files. + +{{% alert color="info" %}} +You cannot combine SecretProviderClass with Workload Identity secret management. The two solutions are mutually exclusive. +{{% /alert %}} ### Requirements -To use the Secret Provider class, you must fulfill the following requirements: +To use the SecretProviderClass, you must fulfill the following requirements: 1. Install the CSI Secrets Store Driver with a provider plugin. 2. Configure identity authentication (Azure Workload Identity or AWS IRSA). @@ -711,6 +715,10 @@ This method is upgrade-safe. Existing credentials are preserved through lookup. Workload Identity enables components to connect to cloud resources without passwords. Instead of storing passwords and access keys in configuration files, components use cloud-native identity (AWS IAM or Azure Managed Identity) to authenticate. +{{% alert color="info" %}} +You cannot combine Workload Identity with SecretProviderClass secret management. The two solutions are mutually exclusive. +{{% /alert %}} + ### Supported Components * `mx-privatecloud-license-manager` - Passwordless database connections for the PCLM service @@ -1194,7 +1202,7 @@ If you encounter database connection failures, perform the following actions: * If `dbssl` is set to `true`, verify the CA certificate. * If using Secret Provider, verify that the CSI driver is installed. -### Secret Provider Class issues +### Secret Provider Class Issues If you encounter Secret Provider Class issues, perform the following actions: From fdf5f1ff891ed049c952b8964e7ba2f56d143e71 Mon Sep 17 00:00:00 2001 From: katarzyna_koltun Date: Wed, 30 Sep 2026 17:46:38 +0200 Subject: [PATCH 07/12] updates from Guido --- .../quickstart/pmp-quickstart-artifacts.md | 4 +- .../quickstart/pmp-quickstart-helm.md | 80 +++++++------------ 2 files changed, 32 insertions(+), 52 deletions(-) diff --git a/content/en/docs/private-platform/quickstart/pmp-quickstart-artifacts.md b/content/en/docs/private-platform/quickstart/pmp-quickstart-artifacts.md index ba82594fe6c..b909cc45455 100644 --- a/content/en/docs/private-platform/quickstart/pmp-quickstart-artifacts.md +++ b/content/en/docs/private-platform/quickstart/pmp-quickstart-artifacts.md @@ -822,7 +822,7 @@ svix-server: useRedis: true ``` -##### With Azure Key Vault +##### With Azure Key Vault {#svix-key-vault} ```text svix-server: @@ -924,7 +924,7 @@ mxplatform: dtapMode: "P" ``` -##### With Secret Provider +##### With Secret Provider {#secret-provider-key} ```text mxplatform: diff --git a/content/en/docs/private-platform/quickstart/pmp-quickstart-helm.md b/content/en/docs/private-platform/quickstart/pmp-quickstart-helm.md index c40b6eecb83..bc8b9df3d5d 100644 --- a/content/en/docs/private-platform/quickstart/pmp-quickstart-helm.md +++ b/content/en/docs/private-platform/quickstart/pmp-quickstart-helm.md @@ -25,6 +25,7 @@ Before running Helmfile, ensure you have the following tools installed: | **helm-diff plugin** | 3.0.0+ | Required for helmfile diff and helmfile apply | `helm plugin install https://github.com/databus23/helm-diff` | | **kubectl** | 1.24.0+ | Kubernetes command-line tool | [Installation Guide](https://kubernetes.io/docs/tasks/tools/) | | **bash** | 4.0+ | Shell for running hooks | Linux and macOS: pre-installed; Windows: [Git Bash](https://git-scm.com/download/win) | +| **oras** | 1.3+ | Tool for working with OCI artifacts | See [Installation](https://oras.land/docs/installation) in ORAS documentation | {{% alert color="info" %}} `Helm-diff` is required for `helmfile apply` and `helmfile diff` commands. If you only use `helmfile sync` (which forces synchronization without using `diff`), it is optional. @@ -176,33 +177,7 @@ GET https://privateplatform.mendix.com/rest/pmpreleaseservice/v1/versions/{versi ## Helmfile Components -Helmfile manages multiple Helm releases with dependency ordering, ensuring components are installed in the correct sequence. - -| Component | Description | Namespace | Required | ServiceAccount | -| --- | --- | --- | --- | --- | -| `mx-privatecloud-license-manager` | Private Cloud License Manager (PCLM) | Private Mendix Platform namespace | Required | `mendix-pclm` (created by Operator) | -| `mx-privatecloud` | Private Cloud services (authenticator, collector, interactor, bridge) | Private Mendix Platform namespace | Optional | `mx-privatecloud` (created by chart) | -| `maia-appgen` | Maia AI AppGen service | Private Mendix Platform namespace | Optional | `maia-appgen` (created by chart) | -| `maia-llm-gateway` | Maia LLM Gateway service for routing LLM requests | Private Mendix Platform namespace | Optional | `maia-llm-gateway` (created by chart) | -| `svix-server` | Webhook delivery service | Private Mendix Platform namespace | Optional | `svix` (created by chart) | -| `mxplatform` | Mendix Platform application (MendixApp CR) | Private Mendix Platform namespace | Optional | `mxplatform` (created by chart or Operator) | -| `mxplatform-kube-agent` | Build agent for mxplatform | Independent | Optional | `mxplatform-kube-agent` (created by chart) | -| `mx-private-document-generation` | PDF document generation service | Independent | Optional | `mx-private-document-generation` (created by chart) | - -ServiceAccount creation depends on the value of the **UseStoragePlanwithIRSA** field. If set to **false**, Chart creates the ServiceAccount with workload identity annotations. If set to **true**, Mendix Operator creates ServiceAccount based on StoragePlan configuration. - -### Dependency and Install Order - -The following components are installed in parallel during the first phase of the Helmfile installation: - -* `mx-privatecloud` -* `maia-appgen` -* `svix-server` -* `maia-llm-gateway` -* `mxplatform-kube-agent` -* `mx-private-document-generation` - -The `mxplatform` component is installed during the second phase, with configurations depending on which components were enabled during the first phase. +For more information about the Helmfile components, see [Installation Reference](/private-mendix-platform/installation-reference/). ## Quick Start @@ -558,35 +533,30 @@ global: The SecretProviderClass allows you to store all sensitive credentials (passwords, connection strings, API keys) in a centralized vault (Azure Key Vault, AWS Secrets Manager, or HashiCorp Vault) instead of hardcoding them in configuration files. -{{% alert color="info" %}} -You cannot combine SecretProviderClass with Workload Identity secret management. The two solutions are mutually exclusive. +{{% alert color="warning" %}} +Secret Management for mxplatform is not compatible with Azure Managed Identity-based Storage Plans. {{% /alert %}} ### Requirements To use the SecretProviderClass, you must fulfill the following requirements: -1. Install the CSI Secrets Store Driver with a provider plugin. -2. Configure identity authentication (Azure Workload Identity or AWS IRSA). +1. Install the CSI Secrets Store Driver with a provider plugin. The CSI driver uses the ServiceAccount's identity to authenticate to the vault and retrieve secrets. +2. Create a keyvault per component, for example: `pmp-install-kv` or `svix-kv` +3. Configure identity authentication (Azure Workload Identity or AWS IRSA). This step is mandatory because the CSI driver uses your ServiceAccount's cloud identity to authenticate to the vault and retrieve secrets. - This step is mandatory because the CSI driver uses your ServiceAccount's cloud identity to authenticate to the vault and retrieve secrets. + * For Azure WI, configure the Federated Credential. -3. Grant vault access permissions to the identity. -4. Store secrets in the vault with the correct key names. -5. Enable `secretProviderclass` in Helmfile configuration. -6. Inject credentials from external secret management systems (AWS Secrets Manager, Azure Key Vault, HashiCorp Vault). +4. Grant vault access permissions to the identity to the keyvault created in step 2. +5. Store secrets in the vault with the correct key names: -{{% alert color="info" %}} -Secret Provider Class requires workload identity authentication to access the secret vault: + * [For svix](/private-mendix-platform/installation-reference/#svix-key-vault) + * [For mxplatform](/private-mendix-platform/installation-reference/#secret-provider-key) -* Azure Key Vault requires Azure Workload Identity (`azureWorkloadIdentity.enable` set to `true`). -* AWS Secrets Manager requires AWS IRSA (`awsIRSA.enable` set to `true`) -* HashiCorp Vault requires Kubernetes Auth configured in Vault. - -The CSI driver uses the ServiceAccount's identity to authenticate to the vault and retrieve secrets. -{{% /alert %}} +6. Enable `secretProviderclass` in Helmfile configuration. +7. Grant RBAC per namespace for the CSI driver's ServiceAccount. -### Example +### Example - Install CSI Driver {#example} {{% alert color="warning" %}} The code samples are intended to show the range of available options. No rights can be derived from them, as they are presented as examples only, and may require significant adaptation to work in your own environment. It is your responsibility to interpret and adjust them to fit real-world scenarios. @@ -613,21 +583,19 @@ helm install vault-csi-provider hashicorp/vault-csi-provider --namespace kube-sy | `svix-server` | PostgreSQL and Redis connection strings | | `mxplatform` | PCLM credentials, admin passwords, database credentials, storage credentials | -{{% alert color="warning" %}} -The code samples are intended to show the range of available options. No rights can be derived from them, as they are presented as examples only, and may require significant adaptation to work in your own environment. It is your responsibility to interpret and adjust them to fit real-world scenarios. -{{% /alert %}} +Secret Management for mxplatform is not compatible with Azure Managed Identity-based Storage Plans. #### Configuration Pattern When configuring secret management, keep in mind the following key points: -* The Secret Provider class will not work without proper identity authentication configured. +* The SecretProviderClass and SA annotations are performed by the Helmfile installation. * For Azure, you must enable `azureWorkloadIdentity` and configure Managed Identity with Key Vault access. * For AWS, you must enable `awsIRSA` and configure IAM role with Secrets Manager access. * For Vault, you must configure the Kubernetes Auth method in Vault and grant the policy access. ```text -{component}: +{component}: # Step 1: Configure identity authentication (REQUIRED) # For Azure Key Vault - MUST configure Workload Identity azureWorkloadIdentity: @@ -656,6 +624,18 @@ When configuring secret management, keep in mind the following key points: role: "my-role" secretName: "my-secret" version: "v2" # Optional: v1 or v2 + svix-server: + azureWorkloadIdentity: + enable: true + clientID: "xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx" + tenantID: "yyyyyyyy-yyyy-yyyy-yyyy-yyyyyyyyyyyy" + secretProviderclass: + enable: true + provider: "azure" + azureparameters: + keyvaultName: "my-svix-keyvault" + # clientID and tenantID inherited from azureWorkloadIdentity + # postgres ignored when using Secret Provider ``` #### Global vs Component Configuration From 8008b2ae2b07332131381f0480ef60b0a57fcdd7 Mon Sep 17 00:00:00 2001 From: katarzyna_koltun Date: Wed, 30 Sep 2026 17:57:04 +0200 Subject: [PATCH 08/12] sme review --- .../pmp-configure-azure-key-vault.md | 20 ++++++++++++++++++- 1 file changed, 19 insertions(+), 1 deletion(-) diff --git a/content/en/docs/private-platform/secret-management/pmp-configure-azure-key-vault.md b/content/en/docs/private-platform/secret-management/pmp-configure-azure-key-vault.md index b84653b0139..a5e904abac2 100644 --- a/content/en/docs/private-platform/secret-management/pmp-configure-azure-key-vault.md +++ b/content/en/docs/private-platform/secret-management/pmp-configure-azure-key-vault.md @@ -156,8 +156,14 @@ When creating the JSON structure for your secret, you must use a flat key-value Private Mendix Platform uses Azure AD Workload Identity to securely access Azure Key Vault without storing credentials. This requires creating a User-Assigned Managed Identity, granting it permissions to the Key Vault, and linking it to the Kubernetes Service Account used by the Private Mendix Platform. +If your Managed Identity was already created by Mendix Operator, you only need to perform the steps described in [Grant the Managed Identity Access to Key Vault](#grant-key-vault-access). The other steps are not necessary. + #### Creating a User-Assigned Managed Identity +{{% alert color="info" %}} +The steps in this section are not necessary if .your Managed Identity was already created by Mendix Operator. +{{% /alert %}} + To create a User-Assigned Managed Identity, perform the following steps: 1. In the Azure Portal, search for and select **Managed Identities**. @@ -169,7 +175,7 @@ To create a User-Assigned Managed Identity, perform the following steps: 7. Once deployed, navigate to the new identity. 8. From the **Overview** page, make note of the **Client ID**. This will be needed later to configure the service account. -#### Grant the Managed Identity Access to Key Vault +#### Grant the Managed Identity Access to Key Vault {#grant-key-vault-access} To grant the Managed Identity access to the Key Vault, perform the following steps: @@ -184,6 +190,10 @@ To grant the Managed Identity access to the Key Vault, perform the following ste #### Configuring the Federated Identity +{{% alert color="info" %}} +The steps in this section are not necessary if .your Managed Identity was already created by Mendix Operator. +{{% /alert %}} + To configure the federated identity, perform the following steps: 1. Navigate back to your User-Assigned Managed Identity (for example, **PMP-KeyVault-Identity**) in the Azure Portal. @@ -200,6 +210,10 @@ Click **Add**. #### Modifying the Operation Configuration +{{% alert color="info" %}} +The steps in this section are not necessary if .your Managed Identity was already created by Mendix Operator. +{{% /alert %}} + For more information about advanced configuration settings, see [Advanced Operator Configuration](/developerportal/deploy/private-cloud-cluster/#advanced-operator-configuration). To modify the configuration, perform the following steps: @@ -234,6 +248,10 @@ To modify the configuration, perform the following steps: #### Configuring the Kubernetes Service Account +{{% alert color="info" %}} +The steps in this section are not necessary if .your Managed Identity was already created by Mendix Operator. +{{% /alert %}} + To enable Azure AD Workload Identity, the Kubernetes Service Account used by your Private Mendix Platform application needs specific annotations to link it to the Azure User-Assigned Managed Identity. You have two options: use a dedicated custom Service Account or use the existing default Service Account in your application's namespace. Using a Custom Service Account is recommended for better isolation. This involves creating a new Service Account specifically for your Mendix application to access secrets. The default service account already exists in every Kubernetes namespace. It's simpler but provides less isolation if other applications in the same namespace also use the default Service Account. From bdf8c45027068aa6f688e5529d47a16a05b9b7e9 Mon Sep 17 00:00:00 2001 From: katarzyna-koltun-mx <108737161+katarzyna-koltun-mx@users.noreply.github.com> Date: Thu, 1 Oct 2026 09:23:50 +0200 Subject: [PATCH 09/12] Fix typo in quickstart Helm installation steps --- .../docs/private-platform/quickstart/pmp-quickstart-helm.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/content/en/docs/private-platform/quickstart/pmp-quickstart-helm.md b/content/en/docs/private-platform/quickstart/pmp-quickstart-helm.md index bc8b9df3d5d..31aa97c19ac 100644 --- a/content/en/docs/private-platform/quickstart/pmp-quickstart-helm.md +++ b/content/en/docs/private-platform/quickstart/pmp-quickstart-helm.md @@ -38,8 +38,8 @@ The installation process consists of the following high-level steps. For more in 1. Retrieve the manifest of image and charts version through the Download Portal GUI or API. 2. Pull the images and charts marked **Required**, as well as any optional components your deployment needs. For a list of required and optional components, see [Installation Reference](/private-mendix-platform/installation-reference/). 3. Install the Operator charts. -4. Install Priave Mendix Platform charts using Helm. -5. Configure the PCLM host name, user name and password in the ` Date: Thu, 1 Oct 2026 09:35:17 +0200 Subject: [PATCH 10/12] Update installation steps for Private Mendix Platform Added note about applying 'mx-privatecloud-operator-crd' charts first. --- .../en/docs/private-platform/quickstart/pmp-quickstart-helm.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/content/en/docs/private-platform/quickstart/pmp-quickstart-helm.md b/content/en/docs/private-platform/quickstart/pmp-quickstart-helm.md index 31aa97c19ac..ff7cdb7c691 100644 --- a/content/en/docs/private-platform/quickstart/pmp-quickstart-helm.md +++ b/content/en/docs/private-platform/quickstart/pmp-quickstart-helm.md @@ -36,7 +36,7 @@ Before running Helmfile, ensure you have the following tools installed: The installation process consists of the following high-level steps. For more information, refer to the sections below. 1. Retrieve the manifest of image and charts version through the Download Portal GUI or API. -2. Pull the images and charts marked **Required**, as well as any optional components your deployment needs. For a list of required and optional components, see [Installation Reference](/private-mendix-platform/installation-reference/). +2. Pull the images and charts marked **Required**, as well as any optional components your deployment needs. For a list of required and optional components, see [Installation Reference](/private-mendix-platform/installation-reference/). The `mx-privatecloud-operator-crd` charts must be applied first. 3. Install the Operator charts. 4. Install Private Mendix Platform charts using Helm. 5. Configure the PCLM host name, user name and password in the *operator-generated-values.yaml* file and re-apply the Mendix Operator chart. From 37444633c44cd3aaed31d1fceceb51a22df3f019 Mon Sep 17 00:00:00 2001 From: katarzyna-koltun-mx <108737161+katarzyna-koltun-mx@users.noreply.github.com> Date: Thu, 1 Oct 2026 09:41:46 +0200 Subject: [PATCH 11/12] Update pmp-quickstart-helm.md --- .../private-platform/quickstart/pmp-quickstart-helm.md | 9 +++++---- 1 file changed, 5 insertions(+), 4 deletions(-) diff --git a/content/en/docs/private-platform/quickstart/pmp-quickstart-helm.md b/content/en/docs/private-platform/quickstart/pmp-quickstart-helm.md index ff7cdb7c691..420573f2836 100644 --- a/content/en/docs/private-platform/quickstart/pmp-quickstart-helm.md +++ b/content/en/docs/private-platform/quickstart/pmp-quickstart-helm.md @@ -36,10 +36,11 @@ Before running Helmfile, ensure you have the following tools installed: The installation process consists of the following high-level steps. For more information, refer to the sections below. 1. Retrieve the manifest of image and charts version through the Download Portal GUI or API. -2. Pull the images and charts marked **Required**, as well as any optional components your deployment needs. For a list of required and optional components, see [Installation Reference](/private-mendix-platform/installation-reference/). The `mx-privatecloud-operator-crd` charts must be applied first. -3. Install the Operator charts. -4. Install Private Mendix Platform charts using Helm. -5. Configure the PCLM host name, user name and password in the *operator-generated-values.yaml* file and re-apply the Mendix Operator chart. +2. Pull the images and charts marked **Required**, as well as any optional components your deployment needs. For a list of required and optional components, see [Installation Reference](/private-mendix-platform/installation-reference/). +3. Install the `mx-privatecloud-operator-crd` charts. +4. Install the `mx-privatecloud-operator-installer` charts. +5. Install Private Mendix Platform charts using Helm. +6. Configure the PCLM host name, user name and password in the *operator-generated-values.yaml* file and re-apply the Mendix Operator chart. ## Platform-Specific Installation Notes From 533c3393857d0d2c74db31104f8a3b9bf9a86942 Mon Sep 17 00:00:00 2001 From: katarzyna-koltun-mx <108737161+katarzyna-koltun-mx@users.noreply.github.com> Date: Thu, 1 Oct 2026 09:51:53 +0200 Subject: [PATCH 12/12] Update pmp-quickstart-helm.md --- .../private-platform/quickstart/pmp-quickstart-helm.md | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/content/en/docs/private-platform/quickstart/pmp-quickstart-helm.md b/content/en/docs/private-platform/quickstart/pmp-quickstart-helm.md index 420573f2836..93100b31dd7 100644 --- a/content/en/docs/private-platform/quickstart/pmp-quickstart-helm.md +++ b/content/en/docs/private-platform/quickstart/pmp-quickstart-helm.md @@ -39,7 +39,12 @@ The installation process consists of the following high-level steps. For more in 2. Pull the images and charts marked **Required**, as well as any optional components your deployment needs. For a list of required and optional components, see [Installation Reference](/private-mendix-platform/installation-reference/). 3. Install the `mx-privatecloud-operator-crd` charts. 4. Install the `mx-privatecloud-operator-installer` charts. -5. Install Private Mendix Platform charts using Helm. +5. Install Private Mendix Platform charts using Helm by performing the following steps: + + 1. Pull the `installer-helmfile` image. + 2. A *targ.gz* file should be installed in *oras-artifact*. Unzipp the file and find the sample *values.yaml* files in the folder. + 3. Use these samples files as a reference for applying the Private Mendix Platform charts. + 6. Configure the PCLM host name, user name and password in the *operator-generated-values.yaml* file and re-apply the Mendix Operator chart. ## Platform-Specific Installation Notes