Skip to content

Commit 215c2fb

Browse files
committed
fix(helm): document image requirement for DNS bypass
1 parent b6cda06 commit 215c2fb

2 files changed

Lines changed: 6 additions & 1 deletion

File tree

‎apps/docs/content/docs/platform/enterprise/verified-domains.mdx‎

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -90,14 +90,18 @@ For a deployment where the operator trusts every organization owner and admin to
9090
SSO_SKIP_DOMAIN_VERIFICATION=true
9191
```
9292

93-
For Helm deployments, set it in your values file:
93+
For Helm deployments, use an application image built from a revision that includes this setting. Upgrading the chart alone does not make an older application image support the variable. Override `app.image.tag` with a compatible released image or a build you publish yourself; set `app.image.repository` as well for a custom repository:
9494

9595
```yaml
9696
app:
97+
image:
98+
tag: "<image-tag-with-domain-verification-bypass>"
9799
env:
98100
SSO_SKIP_DOMAIN_VERIFICATION: "true"
99101
```
100102
103+
If `app.image.digest` is set, replace it with a compatible image digest instead — it takes precedence over the tag.
104+
101105
Add the domain under **Domains**, then click **Verify**. No TXT record or DNS access is needed. The domain is recorded as verified for SSO account linking and SCIM provisioning, and another organization still cannot claim the same domain. Existing pending domains can be verified the same way.
102106

103107
<Callout type="warn">

‎helm/sim/values.yaml‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -255,6 +255,7 @@ app:
255255
SSO_ENABLED: "" # Enable SSO authentication ("true" to enable)
256256
NEXT_PUBLIC_SSO_ENABLED: "" # Show SSO login button in UI ("true" to enable)
257257
# Self-hosted only: trust every organization owner/admin to verify domains without DNS proof.
258+
# Requires a compatible app image; see https://docs.sim.ai/platform/enterprise/verified-domains#skip-dns-verification
258259
SSO_SKIP_DOMAIN_VERIFICATION: "" # Opt in with "true"; unset/"false" requires DNS
259260
# SSO_TRUSTED_PROVIDER_IDS: comma-separated SSO provider IDs to trust for automatic account linking when a
260261
# user signs in via SSO and an account with the same email already exists. Only needed for IdPs that do NOT

0 commit comments

Comments
 (0)