Lamassu IoT Docs

Fastlane

Bootstrap a complete Lamassu evaluation or lab environment on an existing Kubernetes cluster.

Deploy with Fastlane

Fastlane is the automated path for evaluations, demos, CI and small lab clusters. It installs PostgreSQL, Keycloak, RabbitMQ, Envoy Gateway and Lamassu, then configures them to work together.

For production, use Helm so database, identity, credentials, certificates, storage and upgrades remain explicit.

What Fastlane adds

Fastlane closes some of the gaps intentionally left by the application chart:

Fastlane installs or configuresYou still provide
PostgreSQL, RabbitMQ and Keycloak instances for evaluationThe Kubernetes cluster, nodes and persistent storage
Envoy Gateway 1.8 and the eg GatewayClasscert-manager, external network reachability, DNS and firewall/NAT rules
A self-signed Lamassu certificate flow, generated dependency credentials and an initial userClient trust for the self-signed CA, or a trusted certificate passed to the script
Optional observability and lab HSM componentsProduction monitoring retention, backups, HA and a production HSM/key service

Fastlane does not turn the resulting stack into a production service: it does not create the cluster, public DNS, firewall rules, backups, high availability or a trusted public certificate.

Before you begin

You need:

  • an existing Kubernetes cluster
  • kubectl and Helm, or the MicroK8s CLI
  • yq
  • cert-manager
  • jq only when using --sample-data
  • free external ports 80 and 443 on a single-node K3s host

Fastlane detects MicroK8s, K3s, kind or a standard kubeconfig. Use --context when the intended cluster is not the current context.

Know which cluster is selected

Fastlane installs several components and creates credentials. Check kubectl config current-context or pass --context before running it.

Quick start

Run the script from a clone of the Helm repository:

git clone https://github.com/lamassuiot/lamassu-helm.git
cd lamassu-helm

./scripts/lamassu-fast-lane.sh \
  --non-interactive \
  --namespace lamassu-dev \
  --domain pki.example.com \
  --local-chart-path ./charts/lamassu

Create a DNS record for the chosen domain before testing from another machine. For a small VM, point it at the VM or load-balancer address that actually receives ports 80 and 443.

Gateway address selection

By default, Fastlane runs hostname -I and writes the returned addresses to gateway.addresses and to the self-signed certificate's IP SANs.

On a single-homed lab VM this can select the expected node address. On hosts with Docker, VPN, WireGuard or several interfaces it can also select addresses clients cannot reach. Override the result explicitly:

./scripts/lamassu-fast-lane.sh \
  --non-interactive \
  --domain pki.example.com \
  --gateway-ip 192.168.1.50

The value must be an address handled on the Kubernetes side of the traffic path. If a public EC2 address forwards through WireGuard to the cluster, pass the reachable cluster/VM address, not the EC2 public address.

See Expose the Gateway for K3s port conflicts, VIPs, external NAT and multi-Gateway designs.

Command-line options

OptionDefaultPurpose
-h, --help—Show help
-c, --contextcurrent contextSelect the kubeconfig context for kubectl and Helm
-n, --non-interactivefalseSkip prompts and generate dependency credentials
-ns, --namespacelamassu-devNamespace for the installation
-d, --domaindev.lamassu.ioDomain used by the UI, OIDC and certificate
-v, --versionlatestLamassu chart version
--https-port443Gateway HTTPS listener port
--http-port80Gateway HTTP listener port
--tls-crt—PEM certificate for downstream TLS
--tls-key—PEM private key for downstream TLS
-l, --local-chart-pathrepository chartUse an unpacked local Lamassu chart
-ip, --gateway-ipauto-detectedOverride the address written to gateway.addresses
--otelfalseInstall Victoria Logs, VictoriaTraces, Jaeger and an OpenTelemetry Collector
--sample-datafalseCreate sample CAs, profiles, certificates, DMS data and devices
--with-hsmfalseInstall lab HSM components and configure KMS for PKCS#11
--softhsm-chart-path./charts/softhsmUse a different local SoftHSM chart

Fastlane does not provide an offline mode. Use the manual Helm workflow and a prepared registry/chart mirror for disconnected environments.

What the script configures

Fastlane:

  1. validates local tools and the selected cluster
  2. installs or upgrades Envoy Gateway 1.8 and creates the eg GatewayClass
  3. creates the namespace
  4. installs PostgreSQL and creates the required databases
  5. installs Keycloak and creates the lamassu realm, frontend client, admin role and initial user
  6. installs RabbitMQ
  7. optionally installs observability and lab HSM components
  8. generates lamassu.yaml and installs the Lamassu chart
  9. optionally loads sample data

The generated configuration exposes Keycloak at /auth through the same Gateway and bootstraps the initial lamassu user as a Lamassu super administrator.

TLS behavior

With both --tls-crt and --tls-key, Fastlane creates the downstream-provided-crt Secret and configures tls.type: external.

Without them, it configures cert-manager with a self-signed issuer. This is suitable for a lab but will not be trusted by clients until you distribute the CA. Use Helm when you need a corporate Issuer, public ACME issuer or an existing Secret managed by another system.

Credentials and generated files

Non-interactive mode generates random PostgreSQL, RabbitMQ and Keycloak administrator passwords. The initial Lamassu login is lamassu / lamassu and requires a password change on first use.

Fastlane writes lamassu.yaml in the current directory and injects credentials into it.

Fastlane is a bootstrap tool

Protect the generated values file, record the generated credentials in an appropriate secret store and do not reuse the evaluation identity setup in production.

Verify the installation

kubectl get pods -n lamassu-dev
kubectl get gateway,httproute -n lamassu-dev
kubectl get service -A
helm test lamassu -n lamassu-dev --logs

Then open https://pki.example.com and sign in with the initial user. If the Gateway is programmed but the URL is unreachable, follow the checks in Expose the Gateway.

On this page