You are viewing documentation for a legacy Rasa product. If you want to get started building assistants with Rasa please check out our latest [documentation here](/content/docs/index.html).

This page contains information about configuring a Rasa Enterprise deployment installed using
`rasactl`.

## Configuring Values in a Deployment

You can start a deployment with a predefined configuration by using
the `--values-file` flag to pass a file with configuration, e.g. `rasactl start --values-file values.yaml`.

### Configurable Values

`rasactl` uses the [Rasa Enterprise Helm chart](https://github.com/RasaHQ/rasa-x-helm/blob/main/charts/rasa-x/values.yaml) to deploy Rasa Enterprise.
Therefore the same values that apply to a [Helm chart installation](https://legacy-docs-enterprise.rasa.com/docs/rasa-enterprise/1.1.x/installation-and-setup/deploy-tools/rasa-ephemeral-installer/install/helm-chart-installation/installation.mdx) apply to a `rasactl` installation.

### Applying Changes

To change values for an existing Rasa Enterprise deployment:

1. Set the relevant values in `values.yml`.
2. Upgrade the deployment:
```bash
rasactl upgrade --values-file values.yml
```

If you have multiple deployments, specify the deployment that you want to customize:
```bash
rasactl upgrade deployment-name --values-file values.yml
```

To list all available deployments use the `rasactl list` command.

## Common Customizations

### Use a Specific Rasa Enterprise Version

You can configure a Rasa Enterprise deployment to use a specific Rasa Enterprise version.

1. Create a `values.yaml` file with the following content:
```yaml
rasax:
  tag: "1.1.0"
eventService:
  tag: "1.1.0"
dbMigrationService:
  tag: "1.1.0"
```
2. Apply the values to the deployment:
```bash
rasactl upgrade --values-file values.yml
```

### Deploy Rasa Enterprise with a Defined Password

By default, the password for a Rasa Enterprise user (the `admin` user) is `rasaxlocal`.
You can use the `--rasa-x-password` flag to define the user password while creating a new deployment.
You can use the `--rasa-x-password-stdin` flag if you want to read the password from `STDIN`.
```bash
rasactl start --rasa-x-password my-password
```

### Enable TLS

#### Requirements

- Your deployment must be available at a hostname (not a bare IP address). If you started your deployment using `rasactl start` on your local machine, you can use the `URL` returned by `rasactl status`. If you use a VM with a dynamic external IP address, use a static one to avoid IP address rotation and assign a hostname to it.
- Your deployment must be accessible on ports `80` and `443`.

#### Steps

1. Install [cert-manager](https://cert-manager.io/) via helm.
```bash
helm repo add jetstack https://charts.jetstack.io
helm repo update
helm install \
    cert-manager jetstack/cert-manager \
    --namespace cert-manager \
    --create-namespace \
    --version v1.5.3 \
    --set installCRDs=true
```

2. Create a [Basic ACME Issuer](https://cert-manager.io/docs/configuration/acme/).
   You will need to create a `cluster-issuer.yaml` file that contains a specification for the cluster issuer.
   In the example below [Let's Encrypt](https://letsencrypt.org/) is used as the certificate issuer.
```yaml
apiVersion: cert-manager.io/v1
kind: ClusterIssuer
metadata:
  name: letsencrypt
spec:
  acme:
    # You must replace this email address with your own.
    # Let's Encrypt will use this to contact you about expiring
    # certificates, and issues related to your account.
    email: user@example.com
    server: https://acme-v02.api.letsencrypt.org/directory
    privateKeySecretRef:
      # Secret resource that will be used to store the account's private key.
      name: example-issuer-account-key
    # Add a single challenge solver, HTTP01 using nginx
    solvers:
      - http01:
          ingress:
            class: nginx
```

Then create the `ClusterIssuer` resource:
```bash
kubectl create -f cluster-issuer.yaml
```

3. Configure your Rasa Enterprise deployment
   You will need to upgrade your deployment so that a new TLS certificate can be issued for your domain.
   First, update your deployments values to include configuration for an `Ingress` resource.
```yaml
ingress:
  enabled: true
  annotations:
    # add an annotation indicating the issuer to use.
    cert-manager.io/cluster-issuer: letsencrypt
  hosts:
    - host: your-domain.com
      paths:
        - /
tls:
  # a secret name that is created automatically by cert-manager
  secretName: rasa-x-tls
  hosts:
    - your-domain.com
# Disable NGINX which is not needed longer.
nginx:
  enabled: false
```

Then apply the changes by upgrading your deployment:
```bash
rasactl upgrade --values-file values.yaml
```

After the configuration is applied, you should be able to access your deployment over HTTPS.
You can execute the `rasactl status` command to check a URL and if HTTPS is enabled.
```bash
$ rasactl status
Name: quirky-jang
Status: Running
URL: https://rasa-x.example.com
Version: 1.1.3
Enterprise: inactive
Rasa production version: 0.0.0
Rasa worker version: 0.0.0
Project path: not defined
```

## Share your bot running locally

To [share your bot](https://legacy-docs-enterprise.rasa.com/docs/rasa-enterprise/1.1.x/user-guide/share-assistant#share-your-bot) you’ll need to make your locally running
Rasa Enterprise server available to external traffic. You can do this using [ngrok](https://ngrok.com/product).
  
You can [download and install](https://ngrok.com/download) ngrok for free.
Once it is installed, open a new terminal window and run:

1. Determine URL for your deployment by executing the `rasactl status` command.
```bash
$ rasactl status
Name: inspiring-albattani
Status: Running
URL: http://inspiring-albattani.rasactl.localhost
Version: 1.1.3
Enterprise: inactive
Rasa production version: 0.0.0
Rasa worker version: 0.0.0
Project path: not defined
```

2. Run `ngrok`.
```bash
ngrok http -host-header=inspiring-albattani.rasactl.localhost inspiring-albattani.rasactl.localhost
```

This will create a public HTTPS url for your locally running Rasa Enterprise server, given that
it is running at the default port (if not, change the command above).

### Note

You can use the `-region` flag along with the `ngrok http` command to set region; default is `us`.

## Accessing Secrets

This section describes how to retrieve secrets from your running deployment. The following secrets are created by default

| description | default secret name |
| --- | --- |
| PostgreSQL database password | `postgresql` |
| Redis lock store and cache password | `redis` |
| RabbitMQ event broker password | `rabbit` |

To view the plaintext value of a secret, run the following, replacing `<your deployment name>` and `<your release name>` with your deployment and the name of your release:
```bash
secret=<secret name>
namespace=<your deployment name>
release_name=<your release name>

kubectl --namespace ${namespace} \
get secret ${release_name}-${secret} -o yaml |\
awk -F ': ' '/password/{print $2}' | base64 -d; echo
```

For example, if you want to see the value of the `redis` secret for a release called `rasa-x` in the `local` namespace:
```bash
$ secret=redis
$ namespace=local
$ release_name=rasa-x
$ kubectl --namespace ${namespace} \
get secret ${release_name}-${secret} -o yaml |\
awk -F ': ' '/password/{print $2}' | base64 -d; echo
redis-password
```

### Note

If you’re not sure what deployment name or release name your deployment runs under, you can use the following commands to find out. To list the available deployments, run:
```bash
rasactl list
```

And to list the releases under a particular deployment, run:
```bash
rasactl status <deployment-name> --details
```

The release name can be found in the `Helm release` field.
