All templates

Outline

A team wiki with a fast editor. Needs an OpenID Connect provider to sign in, so pair it with Keycloak.

Added by LeafdTK, 28 Sept 2026 v1.0.0 BUSL-1.1 docs #wiki#docs#knowledge base#oidc

Resources

Outline

LeafdTK2 deployments1 database1 domainv1.0.0

4
  • db

    postgres

    Ready

  • cache

    valkey/valkey:8-alpine

    Running

  • app

    outlinewiki/outline:latest

    Running

  • ingress

    wiki.example.com

    Live

Parameters

YAML

outline.yaml v1.0.0
apiVersion: leaf/v1
kind: Template
metadata:
  name: outline
  displayName: 'Outline'
  description: 'A team wiki with a fast editor. Needs an OpenID Connect provider to sign in, so pair it with Keycloak.'
  icon: https://github.com/outline.png?size=256
  version: '1.0.0'
  category: docs
  tags: ['wiki', 'docs', 'knowledge base', 'oidc']
  keywords: ['notion', 'confluence', 'documentation', 'team wiki', 'markdown']
  homepage: https://www.getoutline.com
  license: BUSL-1.1

parameters:
  - name: appName
    displayName: 'App Name'
    type: string
    default: 'outline'
    required: true
    validation:
      pattern: '^[a-z][a-z0-9-]{1,58}[a-z0-9]$'
      message: 'Must be lowercase alphanumeric with hyphens, 3-60 chars'
  - name: domain
    displayName: 'Domain'
    type: string
    required: true
    placeholder: 'wiki.example.com'
  - name: secretKey
    displayName: 'Secret key'
    description: 'Generated if left empty'
    type: secret
    validation:
      min: 64
  - name: utilsSecret
    displayName: 'Utils secret'
    description: 'Generated if left empty'
    type: secret
    validation:
      min: 64
  - name: oidcClientId
    displayName: 'OIDC client id'
    type: string
    required: true
    placeholder: 'outline'
  - name: oidcClientSecret
    displayName: 'OIDC client secret'
    type: string
    required: true
    placeholder: 'from your identity provider'
  - name: oidcAuthUri
    displayName: 'OIDC authorization URL'
    type: string
    required: true
    placeholder: 'https://auth.example.com/realms/main/protocol/openid-connect/auth'
  - name: oidcTokenUri
    displayName: 'OIDC token URL'
    type: string
    required: true
    placeholder: 'https://auth.example.com/realms/main/protocol/openid-connect/token'
  - name: oidcUserinfoUri
    displayName: 'OIDC userinfo URL'
    type: string
    required: true
    placeholder: 'https://auth.example.com/realms/main/protocol/openid-connect/userinfo'
  - name: oidcLogoutUri
    displayName: 'OIDC logout URL'
    type: string
    default: ''
    placeholder: 'https://auth.example.com/realms/main/protocol/openid-connect/logout'
  - name: oidcDisplayName
    displayName: 'Sign-in button label'
    type: string
    default: 'Keycloak'
  - name: defaultLanguage
    displayName: 'Default language'
    type: select
    default: 'en_US'
    options:
      - label: 'en_US'
        value: 'en_US'
      - label: 'de_DE'
        value: 'de_DE'
      - label: 'es_ES'
        value: 'es_ES'
      - label: 'fr_FR'
        value: 'fr_FR'
      - label: 'it_IT'
        value: 'it_IT'
      - label: 'ja_JP'
        value: 'ja_JP'
      - label: 'ko_KR'
        value: 'ko_KR'
      - label: 'pt_BR'
        value: 'pt_BR'
      - label: 'zh_CN'
        value: 'zh_CN'
  - name: uploadMaxMb
    displayName: 'Max upload (MB)'
    type: number
    default: 250
    validation:
      min: 1
  - name: rateLimiter
    displayName: 'Rate limiter'
    type: boolean
    default: true
  - name: enableUpdates
    displayName: 'Check for updates'
    type: boolean
    default: false
  - name: fileStorage
    displayName: 'File storage'
    type: select
    default: 'local'
    options:
      - label: 'local'
        value: 'local'
      - label: 's3'
        value: 's3'
  - name: s3Endpoint
    displayName: 'S3 endpoint'
    description: 'Leave the S3 fields empty to keep files on the volume'
    type: string
    default: ''
    placeholder: 'https://s3.example.com'
  - name: s3Bucket
    displayName: 'S3 bucket'
    type: string
    default: ''
    placeholder: 'uploads'
  - name: s3Region
    displayName: 'S3 region'
    type: string
    default: 'us-east-1'
  - name: s3AccessKey
    displayName: 'S3 access key'
    type: string
    default: ''
  - name: s3SecretKey
    displayName: 'S3 secret key'
    type: string
    default: ''
  - name: smtpHost
    displayName: 'SMTP host'
    description: 'Outgoing mail for invites and notifications. Optional.'
    type: string
    default: ''
    placeholder: 'smtp.example.com'
  - name: smtpPort
    displayName: 'SMTP port'
    type: number
    default: 587
  - name: smtpUser
    displayName: 'SMTP username'
    type: string
    default: ''
    placeholder: '[email protected]'
  - name: smtpPassword
    displayName: 'SMTP password'
    type: string
    default: ''
    placeholder: 'app password'
  - name: mailFrom
    displayName: 'From address'
    type: string
    default: ''
    placeholder: '[email protected]'
  - name: storage
    displayName: 'Storage'
    description: 'Volume for uploaded files'
    type: string
    default: '10Gi'
  - name: enableTls
    displayName: 'Enable HTTPS'
    type: boolean
    default: true

resources:
  - name: db
    type: database
    config:
      name: '{{ params.appName }}-db'

  - name: cache
    type: deployment
    config:
      name: '{{ params.appName }}-cache'
      image: valkey/valkey:8-alpine
      replicas: 1
      ports:
        - name: valkey
          containerPort: 6379
          servicePort: 6379
          protocol: TCP

  - name: app
    type: deployment
    config:
      name: '{{ params.appName }}'
      image: outlinewiki/outline:latest
      replicas: 1
      ports:
        - name: http
          containerPort: 3000
          servicePort: 3000
          protocol: TCP
      volumes:
        - name: data
          type: pvc
          mountPath: /var/lib/outline/data
          storageSize: '{{ params.storage }}'
      env:
        - key: NODE_ENV
          value: production
        - key: URL
          value: 'https://{{ params.domain }}'
        - key: PORT
          value: '3000'
        - key: SECRET_KEY
          value: '{{ params.secretKey }}'
          secret: true
        - key: UTILS_SECRET
          value: '{{ params.utilsSecret }}'
          secret: true
        - key: DATABASE_URL
          value: '{{ resources.db.connectionString }}'
          secret: true
        - key: PGSSLMODE
          value: disable
        - key: REDIS_URL
          value: 'redis://{{ resources.cache.serviceName }}:6379'
        - key: FILE_STORAGE
          value: '{{ params.fileStorage }}'
        - key: FILE_STORAGE_LOCAL_ROOT_DIR
          value: /var/lib/outline/data
        - key: FILE_STORAGE_UPLOAD_MAX_SIZE
          value: '{{ params.uploadMaxMb }}000000'
        - key: AWS_S3_UPLOAD_BUCKET_URL
          value: '{{ params.s3Endpoint }}'
        - key: AWS_S3_UPLOAD_BUCKET_NAME
          value: '{{ params.s3Bucket }}'
        - key: AWS_REGION
          value: '{{ params.s3Region }}'
        - key: AWS_ACCESS_KEY_ID
          value: '{{ params.s3AccessKey }}'
        - key: AWS_SECRET_ACCESS_KEY
          value: '{{ params.s3SecretKey }}'
          secret: true
        - key: AWS_S3_FORCE_PATH_STYLE
          value: 'true'
        - key: FORCE_HTTPS
          value: 'false'
        - key: DEFAULT_LANGUAGE
          value: '{{ params.defaultLanguage }}'
        - key: RATE_LIMITER_ENABLED
          value: '{{ params.rateLimiter }}'
        - key: ENABLE_UPDATES
          value: '{{ params.enableUpdates }}'
        - key: OIDC_CLIENT_ID
          value: '{{ params.oidcClientId }}'
        - key: OIDC_CLIENT_SECRET
          value: '{{ params.oidcClientSecret }}'
          secret: true
        - key: OIDC_AUTH_URI
          value: '{{ params.oidcAuthUri }}'
        - key: OIDC_TOKEN_URI
          value: '{{ params.oidcTokenUri }}'
        - key: OIDC_USERINFO_URI
          value: '{{ params.oidcUserinfoUri }}'
        - key: OIDC_LOGOUT_URI
          value: '{{ params.oidcLogoutUri }}'
        - key: OIDC_DISPLAY_NAME
          value: '{{ params.oidcDisplayName }}'
        - key: OIDC_SCOPES
          value: 'openid profile email'
        - key: SMTP_SERVICE
          value: ''
        - key: SMTP_HOST
          value: '{{ params.smtpHost }}'
        - key: SMTP_PORT
          value: '{{ params.smtpPort }}'
        - key: SMTP_USERNAME
          value: '{{ params.smtpUser }}'
        - key: SMTP_PASSWORD
          value: '{{ params.smtpPassword }}'
          secret: true
        - key: SMTP_FROM_EMAIL
          value: '{{ params.mailFrom }}'
        - key: SMTP_SECURE
          value: 'false'

  - name: ingress
    type: ingress
    config:
      host: '{{ params.domain }}'
      tlsEnabled: '{{ params.enableTls }}'
      routes:
        - path: /
          serviceName: '{{ resources.app.serviceName }}'
          servicePort: 3000

your own cloud, in one click.

Free and open source. Runs on any Linux box.

Install Orchard