diff --git a/manifests/applicationset/openmetadata/1.12.1/dip-values.yaml b/manifests/applicationset/openmetadata/1.12.1/dip-values.yaml new file mode 100644 index 0000000..0f1e7c0 --- /dev/null +++ b/manifests/applicationset/openmetadata/1.12.1/dip-values.yaml @@ -0,0 +1,146 @@ +airflow: + workers: + replicas: 2 + resources: {} + scheduler: + resources: {} + webserver: + resources: {} + apiServer: + resources: {} + triggerer: + resources: {} + dags: + persistence: + enabled: true + storageClassName: "nfs-client" + accessMode: ReadWriteMany + size: 1Gi + logs: + persistence: + enabled: true + storageClassName: "nfs-client" + size: 1Gi + data: + metadataConnection: + pass: "$airflow.mysql.password" + +opensearch: + opensearchJavaOpts: "-Xmx1g -Xms1g" + persistence: + size: 30Gi + resources: + requests: + cpu: "100m" + memory: "256M" + limits: + cpu: "2000m" + memory: "2048M" + +mysql: + enabled: true + primary: + resources: + requests: + cpu: "500m" + memory: "512Mi" + limits: + cpu: "750m" + memory: "768Mi" + persistence: + size: 50Gi + initdbScripts: + init_openmetadata_db_scripts.sql: | + CREATE DATABASE openmetadata_db; + CREATE USER 'openmetadata_user'@'%' IDENTIFIED BY '$openmetadata.mysql.password'; + GRANT ALL PRIVILEGES ON openmetadata_db.* TO 'openmetadata_user'@'%' WITH GRANT OPTION; + commit; + init_airflow_db_scripts.sql: | + CREATE DATABASE airflow_db CHARACTER SET utf8mb4 COLLATE utf8mb4_unicode_ci; + CREATE USER 'airflow_user'@'%' IDENTIFIED BY '$airflow.mysql.password'; + GRANT ALL PRIVILEGES ON airflow_db.* TO 'airflow_user'@'%' WITH GRANT OPTION; + commit; + +--- + +openmetadata: + config: + authorizer: + className: "org.openmetadata.service.security.DefaultAuthorizer" + containerRequestFilter: "org.openmetadata.service.security.JwtFilter" + initialAdmins: + - "admin" + - "dwshin" + - "{{ .Username }}" + - "service-account-$KEYCLOAK_CLIENT_ID" + principalDomain: "paasup.io" + + authentication: + clientType: confidential + provider: "custom-oidc" + authority: "$KEYCLOAK_URL/realms/$KEYCLOAK_REALM" + publicKeys: + - "https://{{ .Name }}.{{ .Domain }}/api/v1/system/config/jwks" + - "$KEYCLOAK_URL/realms/$KEYCLOAK_REALM/protocol/openid-connect/certs" + clientId: "open-metadata" + callbackUrl: "https://{{ .Name }}.{{ .Domain }}/callback" + jwtPrincipalClaims: + - "email" + - "preferred_username" + - "sub" + oidcConfiguration: + enabled: true + oidcType: "Keycloak" + clientId: + secretRef: oidc-secrets + secretKey: openmetadata-oidc-client-id + clientSecret: + secretRef: oidc-secrets + secretKey: openmetadata-oidc-client-secret + discoveryUri: "$KEYCLOAK_URL/realms/$KEYCLOAK_REALM/.well-known/openid-configuration" + serverUrl: "https://{{ .Name }}.{{ .Domain }}" + callbackUrl: "https://{{ .Name }}.{{ .Domain }}/callback" + tokenValidity: "3600" + sessionExpiry: "604800" + maxAge: "300" + pipelineServiceClientConfig: + metadataApiEndpoint: "http://{{ .Name }}:8585/api" + airflow: + apiEndpoint: "http://{{ .Namespace }}-dependencies-api-server:8080" + +ingress: + enabled: true + className: "kong" + annotations: + cert-manager.io/cluster-issuer: letsencrypt-prod + cert-manager.io/duration: 8760h + cert-manager.io/renew-before: 720h + konghq.com/protocols: https + konghq.com/https-redirect-status-code: "301" + hosts: + - host: "{{ .Name }}.{{ .Domain }}" + paths: + - path: / + pathType: ImplementationSpecific + tls: + - secretName: openmetadata-tls + hosts: + - "{{ .Name }}.{{ .Domain }}" + +extraVolumes: + - name: java-truststore + secret: + secretName: java-truststore + +extraVolumeMounts: + - name: java-truststore + mountPath: /etc/ssl/java + readOnly: true + +resources: {} + +extraEnvs: + - name: LOG_LEVEL + value: "INFO" + - name: "OPENMETADATA_PUBLIC_URL" + value: "https://{{ .Name }}.{{ .Domain }}" \ No newline at end of file diff --git a/manifests/directory/kafka-connector/1.0.0/dip-values.yaml b/manifests/directory/kafka-connector/1.0.0/dip-values.yaml new file mode 100644 index 0000000..8c1f118 --- /dev/null +++ b/manifests/directory/kafka-connector/1.0.0/dip-values.yaml @@ -0,0 +1,126 @@ +{{if .ShowIf}} +{{if eq (index .ShowIf "postgresql.source") "true"}} +--- +apiVersion: kafka.strimzi.io/v1beta2 +kind: KafkaConnector +metadata: + name: "{{ .Name }}-kafka-postgresql" + namespace: $kafka_cluster_namespace + labels: + strimzi.io/cluster: $kafka_cluster_namespace +spec: + class: io.debezium.connector.postgresql.PostgresConnector + tasksMax: 6 + config: + database.hostname: "$database.host" + database.port: "5432" + database.user: "$database.user" + database.password: "$database.password" + database.dbname: "$database.db" + table.include.list: "$database.table.include" + plugin.name: pgoutput + snapshot.mode: "initial" + slot.name: "$database.slot" + publication.autocreate.mode: filtered + topic.prefix: "{{ .ClusterProjectName }}" + producer.override.security.protocol: "SASL_PLAINTEXT" + producer.override.sasl.mechanism: "OAUTHBEARER" + producer.override.sasl.jaas.config: | + org.apache.kafka.common.security.oauthbearer.OAuthBearerLoginModule required + oauth.token.endpoint.uri="$KEYCLOAK_URL/realms/$KEYCLOAK_REALM/protocol/openid-connect/token" + oauth.client.id="$KAFKA_CLIENT_ID" + oauth.client.secret="$KAFKA_CLIENT_SECRET" + oauth.ssl.truststore.location="/mnt/truststore/truststore.jks" + oauth.ssl.truststore.password="kafka"; +{{end}} + +{{if eq (index .ShowIf "s3.target") "true"}} +--- +apiVersion: kafka.strimzi.io/v1beta2 +kind: KafkaConnector +metadata: + name: "{{ .Name }}-kafka-s3" + namespace: $kafka_cluster_namespace + labels: + strimzi.io/cluster: $kafka_cluster_namespace +spec: + class: io.confluent.connect.s3.S3SinkConnector + tasksMax: 6 + config: + topics: "{{ .ClusterProjectName }}.$config.topics" + store.url: "$s3.url" + s3.region: us-east-1 + aws.access.key.id: "$s3.accesskey" + aws.secret.access.key: "$s3.secretkey" + s3.bucket.name: "$s3.bucket" + s3.part.size: 5242880 + flush.size: 3 + format.class: io.confluent.connect.s3.format.json.JsonFormat + storage.class: io.confluent.connect.s3.storage.S3Storage + schema.compatibility: NONE + consumer.override.security.protocol: "SASL_PLAINTEXT" + consumer.override.sasl.mechanism: "OAUTHBEARER" + consumer.override.sasl.jaas.config: | + org.apache.kafka.common.security.oauthbearer.OAuthBearerLoginModule required + oauth.token.endpoint.uri="$KEYCLOAK_URL/realms/$KEYCLOAK_REALM/protocol/openid-connect/token" + oauth.client.id="$KAFKA_CLIENT_ID" + oauth.client.secret="$KAFKA_CLIENT_SECRET" + oauth.ssl.truststore.location="/mnt/truststore/truststore.jks" + oauth.ssl.truststore.password="kafka"; +{{end}} + +{{if eq (index .ShowIf "star.target") "true"}} +--- +apiVersion: kafka.strimzi.io/v1beta2 +kind: KafkaConnector +metadata: + name: "{{ .Name }}-kafka-starrocks" + namespace: $kafka_cluster_namespace + labels: + strimzi.io/cluster: $kafka_cluster_namespace +spec: + class: com.starrocks.connector.kafka.StarRocksSinkConnector + tasksMax: 6 + config: + topics: "{{ .ClusterProjectName }}.$star.config.topics" + starrocks.http.url: kube-starrocks-fe-service.$star.namespace.svc.cluster.local:8030 + starrocks.database.name: "$star.database.name" + starrocks.username: "$star.username" + starrocks.password: "$star.password" + sink.properties.strip_outer_array: true + connect.timeoutms: "30000" + starrocks.topic2table.map: "$star.topic2table" + transforms: addfield,unwrap + transforms.addfield.type: com.starrocks.connector.kafka.transforms.AddOpFieldForDebeziumRecord + transforms.unwrap.type: io.debezium.transforms.ExtractNewRecordState + transforms.unwarp.drop.tombstones: true + transforms.unwarp.delete.handling.mode: rewrite +{{end}} + +{{if eq (index .ShowIf "starjson.target") "true"}} +--- +apiVersion: kafka.strimzi.io/v1beta2 +kind: KafkaConnector +metadata: + name: "{{ .Name }}-kafka-starrocks" + namespace: $kafka_cluster_namespace + labels: + strimzi.io/cluster: $kafka_cluster_namespace +spec: + class: com.starrocks.connector.kafka.StarRocksSinkConnector + tasksMax: 6 + config: + topics: "{{ .ClusterProjectName }}.$starjson.config.topics" + starrocks.http.url: kube-starrocks-fe-service.$starjson.namespace.svc.cluster.local:8030 + starrocks.database.name: "$starjson.database.name" + starrocks.username: "$starjson.username" + starrocks.password: "$starjson.password" + sink.properties.strip_outer_array: true + connect.timeoutms: "30000" + starrocks.topic2table.map: "$starjson.topic2table" + key.converter: "org.apache.kafka.connect.json.JsonConverter" + value.converter: "org.apache.kafka.connect.json.JsonConverter" + key.converter.schemas.enable: "true" + value.converter.schemas.enable: "false" +{{end}} +{{end}} \ No newline at end of file diff --git a/manifests/directory/kafka/1.0.0/dip-values.yaml b/manifests/directory/kafka/1.0.0/dip-values.yaml new file mode 100644 index 0000000..4d892e9 --- /dev/null +++ b/manifests/directory/kafka/1.0.0/dip-values.yaml @@ -0,0 +1,47 @@ +apiVersion: kafka.strimzi.io/v1beta2 +kind: KafkaUser +metadata: + name: "service-account-{{ .ClusterName }}-{{ .ClusterProjectName }}-kafka-common" + labels: + strimzi.io/cluster: $kafka_cluster_namespace +spec: + authorization: + type: simple + acls: + - resource: + type: topic + name: "{{ .ClusterProjectName }}." + patternType: prefix + operations: + - Read + - Describe + - DescribeConfigs + - Write + - resource: + type: group + name: "{{ .ClusterProjectName }}-" + patternType: prefix + operations: + - Read + - Write + - Describe + +{{- $clusterCatalog := . -}} +{{range index .QuestionsMap "$topicName"}} +--- +apiVersion: kafka.strimzi.io/v1beta2 +kind: KafkaTopic +metadata: + labels: + strimzi.io/cluster: $kafka_cluster_namespace + name: "{{replaceDotUnderToHypen .}}" + namespace: $kafka_cluster_namespace +spec: + partitions: $topic.partition + replicas: 3 + topicName: "{{ $clusterCatalog.ClusterProjectName }}.{{.}}" + config: + cleanup.policy: compact + retention.bytes: "$topic.retention" + segment.bytes: "$topic.segment" +{{end}} \ No newline at end of file diff --git a/manifests/directory/kubeflow/1.10.0/dip-values.yaml b/manifests/directory/kubeflow/1.10.0/dip-values.yaml new file mode 100644 index 0000000..a3ad3c0 --- /dev/null +++ b/manifests/directory/kubeflow/1.10.0/dip-values.yaml @@ -0,0 +1,13 @@ +apiVersion: kubeflow.org/v1 +kind: Profile +metadata: + name: "{{ .Name }}" +spec: + owner: + kind: User + name: "{{ .Email }}" + resourceQuotaSpec: + hard: + cpu: "16" + memory: 32Gi + persistentvolumeclaims: "12" \ No newline at end of file diff --git a/manifests/helm/airflow/1.16.0/dip-values.yaml b/manifests/helm/airflow/1.16.0/dip-values.yaml new file mode 100644 index 0000000..3652c1c --- /dev/null +++ b/manifests/helm/airflow/1.16.0/dip-values.yaml @@ -0,0 +1,91 @@ +ingress: + web: + enabled: true + annotations: + cert-manager.io/cluster-issuer: "root-ca-issuer" + cert-manager.io/duration: 8760h + cert-manager.io/renew-before: 720h + k8s.apisix.apache.org/plugin-config-name: oidc-keycloak-authz + ingressClassName: "apisix" + pathType: "Prefix" + hosts: + - name: "{{ .Name }}.{{ .Domain }}" + tls: + enabled: true + secretName: "{{ .Name }}-tls-secret" + +executor: "KubernetesExecutor" + +config: + core: + executor: KubernetesExecutor + default_timezone: kst + logging: + colored_console_log: "False" + logging_level: "INFO" + webserver: + enable_proxy_fix: "True" + rbac: "True" + default_ui_timezone: kst + +scheduler: + replicas: 1 + +dags: + persistence: + enabled: true + size: 5Gi + storageClassName: longhorn + accessMode: ReadWriteMany + gitSync: + enabled: true + repo: "$dags.gitSync.repo" + branch: master + rev: HEAD + depth: 1 + subPath: "" + credentialsSecret: "$INFISICAL_SECRET" + env: + - name: GIT_SSL_NO_VERIFY + value: "true" + +webserver: + defaultUser: + enabled: true + password: "$webserver.defaultUser.password" + livenessProbe: + initialDelaySeconds: 120 + readinessProbe: + initialDelaySeconds: 120 + startupProbe: + initialDelaySeconds: 30 + webserverConfig: | + AUTH_ROLE_PUBLIC = 'User' + +logs: + persistence: + enabled: true + size: 5Gi + storageClassName: longhorn + +statsd: + enabled: false + +postgresql: + enabled: true + auth: + username: "postgres" + existingSecret: "$INFISICAL_SECRET" + secretKeys: + userPasswordKey: "postgres-password" + primary: + persistence: + enabled: true + size: 8Gi + storageClass: "" + +migrateDatabaseJob: + useHelmHooks: false + +data: + metadataSecretName: "$INFISICAL_SECRET" \ No newline at end of file diff --git a/manifests/helm/cloudbeaver/1.1.4/dip-values.yaml b/manifests/helm/cloudbeaver/1.1.4/dip-values.yaml new file mode 100644 index 0000000..88c061d --- /dev/null +++ b/manifests/helm/cloudbeaver/1.1.4/dip-values.yaml @@ -0,0 +1,51 @@ +image: + registry: docker.io + repository: dbeaver/cloudbeaver + tag: "26.0.1" + pullPolicy: IfNotPresent + +service: + type: ClusterIP + ports: + http: 8978 + +ingress: + enabled: true + ingressClassName: "apisix" + pathType: Prefix + hostname: "{{ .Name }}.{{ .Domain }}" + annotations: + cert-manager.io/cluster-issuer: root-ca-issuer + cert-manager.io/duration: 8760h + cert-manager.io/renew-before: 720h + k8s.apisix.apache.org/plugin-config-name: https-redirect + tls: true + +persistence: + enabled: true + storageClass: "" + mountPath: /opt/cloudbeaver/workspace + accessModes: + - ReadWriteOnce + size: 5Gi + +resources: + requests: + cpu: 500m + memory: 512Mi + limits: + cpu: 750m + memory: 768Mi + +podSecurityContext: + enabled: true + fsGroup: 8978 + +containerSecurityContext: + enabled: true + runAsUser: 8978 + runAsGroup: 8978 + runAsNonRoot: true + allowPrivilegeEscalation: false + capabilities: + drop: ["ALL"] \ No newline at end of file diff --git a/manifests/helm/flink-cdc-job/0.1.0/dip-values.yaml b/manifests/helm/flink-cdc-job/0.1.0/dip-values.yaml new file mode 100644 index 0000000..792a60f --- /dev/null +++ b/manifests/helm/flink-cdc-job/0.1.0/dip-values.yaml @@ -0,0 +1,31 @@ +sessionCluster: + restAddress: "$flink_cdc_session_namespace-session-rest" + restPort: 8081 + +postgres: + hostname: "$postgres.hostname" + port: 5432 + username: "$postgres.username" + password: "$postgres.password" + slotName: "$postgres.slotName" + decodingPlugin: pgoutput + tables: "$postgres.tables" + +pipeline: + name: "{{ .Name }}-cdc-pipeline" + parallelism: 2 + checkpointInterval: 60s + +sink: + catalog: + uri: "$sink.catalog.uri" + warehouse: "$sink.catalog.warehouse" + s3Endpoint: "$sink.catalog.s3Endpoint" + s3PathStyleAccess: "true" + oauth2Uri: "$KEYCLOAK_URL/realms/$KEYCLOAK_REALM/protocol/openid-connect/token" + credential: "$LAKEKEEPER_CLIENT_ID:$LAKEKEEPER_CLIENT_SECRET" + scope: lakekeeper + +route: + - sourceTable: "$route.sourceTable" + sinkTable: "$route.sinkTable" \ No newline at end of file diff --git a/manifests/helm/flink-cdc-session/0.1.0/dip-values.yaml b/manifests/helm/flink-cdc-session/0.1.0/dip-values.yaml new file mode 100644 index 0000000..888ebbf --- /dev/null +++ b/manifests/helm/flink-cdc-session/0.1.0/dip-values.yaml @@ -0,0 +1,25 @@ +checkpointStorage: + storageType: s3 + checkpointDir: "s3://$checkpointStorage.checkpointDir" + savepointDir: "s3://$checkpointStorage.savepointDir" + s3: + endpoint: "$checkpointStorage.s3.endpoint" + pathStyleAccess: "true" + existingSecret: "$INFISICAL_SECRET" + +ingress: + enabled: true + host: "{{ .Name }}.{{ .Domain }}" + className: apisix + annotations: + cert-manager.io/cluster-issuer: root-ca-issuer + cert-manager.io/duration: 8760h + cert-manager.io/renew-before: 720h + k8s.apisix.apache.org/plugin-config-name: oidc-keycloak-authz + +truststore: + enabled: true + secretName: flink-truststore + +job: + enabled: false \ No newline at end of file diff --git a/manifests/helm/flink-kubernetes-operator/1.13.0/dip-values.yaml b/manifests/helm/flink-kubernetes-operator/1.13.0/dip-values.yaml new file mode 100644 index 0000000..f5c3d5c --- /dev/null +++ b/manifests/helm/flink-kubernetes-operator/1.13.0/dip-values.yaml @@ -0,0 +1,67 @@ +watchNamespaces: [] + +image: + repository: ghcr.io/apache/flink-kubernetes-operator + pullPolicy: IfNotPresent + tag: "b40c553" + digest: "" + +imagePullSecrets: [] + +replicas: 1 + +strategy: + type: Recreate + +operatorPod: + nodeSelector: {} + affinity: {} + tolerations: [] + topologySpreadConstraints: [] + + resources: + limits: + cpu: "200m" + memory: "512Mi" + requests: + cpu: "100m" + memory: "256Mi" + webhook: + resources: + limits: + cpu: "100m" + memory: "256Mi" + requests: + cpu: "50m" + memory: "128Mi" + +defaultConfiguration: + create: true + append: true + flink-conf.yaml: |+ + # Flink Config Overrides + kubernetes.operator.metrics.reporter.slf4j.factory.class: org.apache.flink.metrics.slf4j.Slf4jReporterFactory + kubernetes.operator.metrics.reporter.slf4j.interval: 5 MINUTE + + kubernetes.operator.reconcile.interval: 15 s + kubernetes.operator.observer.progress-check.interval: 5 s + log4j-operator.properties: |+ + # Flink Operator Logging Overrides + # rootLogger.level = DEBUG + # logger.operator.name= org.apache.flink.kubernetes.operator + # logger.operator.level = DEBUG + log4j-console.properties: |+ + # Flink Deployment Logging Overrides + # rootLogger.level = DEBUG + +jvmArgs: + webhook: "" + operator: "" + logConfig: "-Dlog4j.configurationFile=/opt/flink/conf/log4j-operator.properties" + +tls: + create: false + secretName: flink-operator-cert + secretKeyRef: + name: operator-certificate-password + key: password \ No newline at end of file diff --git a/manifests/helm/flink-sql-gateway/0.1.0/dip-values.yaml b/manifests/helm/flink-sql-gateway/0.1.0/dip-values.yaml new file mode 100644 index 0000000..6fbdf14 --- /dev/null +++ b/manifests/helm/flink-sql-gateway/0.1.0/dip-values.yaml @@ -0,0 +1,78 @@ +global: + namespace: "{{ .Namespace }}" + image: + repository: paasup/flink-sql + tag: 2.0.1 + pullPolicy: IfNotPresent + + +sessionCluster: + flinkVersion: v2_0 + flinkConfiguration: + taskmanager.numberOfTaskSlots: "4" + env.java.opts.jobmanager: "-Djavax.net.ssl.trustStore=/opt/flink/certs/ca.p12 -Djavax.net.ssl.trustStoreType=PKCS12 -Djavax.net.ssl.trustStorePassword=YOUR_TRUSTSTORE_PASSWORD" + env.java.opts.taskmanager: "-Djavax.net.ssl.trustStore=/opt/flink/certs/ca.p12 -Djavax.net.ssl.trustStoreType=PKCS12 -Djavax.net.ssl.trustStorePassword=YOUR_TRUSTSTORE_PASSWORD" + table.exec.resource.default-parallelism: "2" + + fs.s3.impl: org.apache.hadoop.fs.s3a.S3AFileSystem + fs.s3a.impl: org.apache.hadoop.fs.s3a.S3AFileSystem + + fs.s3a.endpoint: "$sessioncluster.s3a.endpoint" + fs.s3a.path.style.access: "true" + + env: + - name: TRUSTSTORE_PASSWORD + valueFrom: + secretKeyRef: + name: truststore-secret + key: ca.password + volumeMounts: + - name: truststore-certs + mountPath: /opt/flink/certs + readOnly: true + volumes: + - name: truststore-certs + secret: + secretName: truststore-secret + +sqlGateway: + resources: + requests: + memory: 1Gi + cpu: 0.5 + limits: + memory: 2Gi + cpu: 1 + flinkConfiguration: + env.java.opts: "-Djavax.net.ssl.trustStore=/opt/flink/certs/ca.p12 -Djavax.net.ssl.trustStoreType=PKCS12 -Djavax.net.ssl.trustStorePassword=YOUR_TRUSTSTORE_PASSWORD" + env: + - name: TRUSTSTORE_PASSWORD + valueFrom: + secretKeyRef: + name: truststore-secret + key: ca.password + volumeMounts: + - name: truststore-certs + mountPath: /opt/flink/certs + readOnly: true + volumes: + - name: truststore-certs + secret: + secretName: truststore-secret + +sqlClient: + enabled: true + env: + - name: TRUSTSTORE_PASSWORD + valueFrom: + secretKeyRef: + name: truststore-secret + key: ca.password + volumeMounts: + - name: truststore-certs + mountPath: /opt/flink/certs + readOnly: true + volumes: + - name: truststore-certs + secret: + secretName: truststore-secret \ No newline at end of file diff --git a/manifests/helm/flowise/6.0.0/dip-values.yaml b/manifests/helm/flowise/6.0.0/dip-values.yaml new file mode 100644 index 0000000..3e24253 --- /dev/null +++ b/manifests/helm/flowise/6.0.0/dip-values.yaml @@ -0,0 +1,46 @@ +global: + storageClass: "longhorn" + +image: + registry: docker.io + +persistence: + enabled: true + size: 1Gi + storageClass: longhorn + +resources: {} + +worker: + enabled: true + replicaCount: 1 + resources: {} + +ingress: + enabled: true + ingressClassName: "apisix" + pathType: Prefix + annotations: + cert-manager.io/cluster-issuer: "root-ca-issuer" + cert-manager.io/duration: 8760h + cert-manager.io/renew-before: 720h + hosts: + - host: "{{ .Name }}.{{ .Domain }}" + paths: + - / + tls: + - hosts: + - "{{ .Name }}.{{ .Domain }}" + secretName: "{{ .Name }}-tls-secret" + +postgresql: + enabled: true + auth: + existingSecret: "$INFISICAL_SECRET" + primary: + persistence: + enabled: true + size: 8Gi + +redis: + enabled: true \ No newline at end of file diff --git a/manifests/helm/gitea/12.4.0/dip-values.yaml b/manifests/helm/gitea/12.4.0/dip-values.yaml new file mode 100644 index 0000000..3b67617 --- /dev/null +++ b/manifests/helm/gitea/12.4.0/dip-values.yaml @@ -0,0 +1,106 @@ +global: + imageRegistry: "" + +ingress: + enabled: true + className: apisix + annotations: + k8s.apisix.apache.org/plugin-config-name: https-redirect + cert-manager.io/cluster-issuer: "root-ca-issuer" + cert-manager.io/duration: 8760h + cert-manager.io/renew-before: 720h + hosts: + - host: "{{ .Name }}.{{ .Domain }}" + paths: + - path: / + pathType: Prefix + tls: + - hosts: + host: "{{ .Name }}.{{ .Domain }}" + secretName: "{{ .Name }}-tls-secret" + +extraVolumes: + - name: keycloak-tls + secret: + secretName: keycloak-tls + + +extraContainerVolumeMounts: + - name: keycloak-tls + mountPath: /etc/ssl/certs/ca.crt + subPath: ca.crt + +extraInitVolumeMounts: + - name: keycloak-tls + mountPath: /etc/ssl/certs/ca.crt + subPath: ca.crt + +replicaCount: 1 + +resources: + requests: + cpu: 100m + memory: 300Mi + limits: + cpu: 300m + memory: 500Mi + +persistence: + enabled: true + size: 10Gi + storageClass: "longhorn" + +gitea: + admin: + username: sudouser + password: "" + email: "gitea@local.domain" + existingSecret: "$INFISICAL_SECRET" + config: + APP_NAME: paasup git + RUN_MODE: prod + server: + ROOT_URL: "https://{{ .Name }}.{{ .Domain }}" + database: + DB_TYPE: postgres + HOST: "{{ .Name }}-postgresql:5432" + NAME: gitea + USER: gitea + PASSWD: gitea + CHARSET: utf8 + SSL_MODE: disable + session: + PROVIDER: postgres + PROVIDER_CONFIG: user=gitea password=gitea host={{ .Name }}-postgresql port=5432 dbname=gitea sslmode=disable + COOKIE_NAME: i_hate_gitea + service: + DEFAULT_ALLOW_CREATE_ORGANIZATION: true + repository: + DEFAULT_BRANCH: master + oauth: + - name: keycloak + provider: "openidConnect" + key: "$KEYCLOAK_CLIENT_ID" + secret: "$KEYCLOAK_CLIENT_SECRET" + autoDiscoverUrl: "$KEYCLOAK_URL/realms/$KEYCLOAK_REALM/.well-known/openid-configuration" + +postgresql-ha: + enabled: false +valkey: + enabled: false +valkey-cluster: + enabled: false +postgresql: + enabled: true + global: + postgresql: + auth: + password: gitea + database: gitea + username: gitea + service: + ports: + postgresql: 5432 + primary: + persistence: + size: 10Gi \ No newline at end of file diff --git a/manifests/helm/jupyterlab/1.0.0/dip-values.yaml b/manifests/helm/jupyterlab/1.0.0/dip-values.yaml new file mode 100644 index 0000000..de60283 --- /dev/null +++ b/manifests/helm/jupyterlab/1.0.0/dip-values.yaml @@ -0,0 +1,43 @@ +image: + registry: "quay.io" + repository: "$image.repository" + tag: "" + +resources: + limits: + cpu: "2000m" + memory: "4096Mi" + requests: + cpu: "500m" + memory: "1024Mi" + gpu: "" + +jupyterConfig: + token: "$jupyterConfig.token" + +ingress: + enabled: true + ingressClassName: "apisix" + annotations: + cert-manager.io/cluster-issuer: "root-ca-issuer" + cert-manager.io/duration: "8760h" + cert-manager.io/renew-before: "720h" + k8s.apisix.apache.org/plugin-config-name: oidc-keycloak-authz + hosts: + - host: "{{ .Name }}.{{ .Domain }}" + paths: + - / + tls: + - hosts: + - "{{ .Name }}.{{ .Domain }}" + secretName: "{{ .Name }}-tls-secret" + +homeVolume: + enabled: $homeVolume.enabled + size: "5Gi" + storageClassName: "" + +dataVolume: + enabled: $dataVolume.enabled + size: "5Gi" + storageClassName: "" \ No newline at end of file diff --git a/manifests/helm/kafka-cluster/1.0.0/dip-values.yaml b/manifests/helm/kafka-cluster/1.0.0/dip-values.yaml new file mode 100644 index 0000000..5a3778f --- /dev/null +++ b/manifests/helm/kafka-cluster/1.0.0/dip-values.yaml @@ -0,0 +1,89 @@ +kafka: + version: "4.0.0" + metadataVersion: "4.0" + timezone: "Asia/Seoul" + +controller: + replicas: 3 + storage: + size: 50Gi + class: longhorn + resources: + requests: + cpu: 500m + memory: 1Gi + limits: + cpu: 1 + memory: 2Gi + +broker: + replicas: 3 + storage: + size: 50Gi + class: longhorn + resources: + requests: + cpu: 500m + memory: 1Gi + limits: + cpu: 1 + memory: 2Gi + +config: + offsetsTopicReplicationFactor: 3 + transactionStateLogReplicationFactor: 3 + transactionStateLogMinIsr: 2 + defaultReplicationFactor: 3 + minInsyncReplicas: 2 + autoCreateTopicsEnable: false + numPartitions: 3 + deleteTopicEnable: true + +internalListener: + enabled: true + port: 9094 + tls: true + +oauth: + enabled: true + keycloakUrl: "$KEYCLOAK_URL" + keycloakRealm: "$KEYCLOAK_REALM" + keycloakClientId: "$KEYCLOAK_CLIENT_ID" + tlsSecretName: "keycloak-tls" + +kafkaConnect: + enabled: true + image: paasup/kafka-connect:0.2 + replicas: 1 + +entityOperator: + topicOperator: + resources: + requests: + memory: 128Mi + cpu: 100m + limits: + memory: 256Mi + cpu: 200m + userOperator: + resources: + requests: + memory: 128Mi + cpu: 100m + limits: + memory: 256Mi + cpu: 200m + +connectTopics: + partitions: 1 + replicas: 3 + config: + cleanupPolicy: compact + retentionMs: 604800000 + segmentBytes: 1073741824 + +logging: + kafka: + rootLoggerLevel: INFO + connect: + rootLoggerLevel: INFO \ No newline at end of file diff --git a/manifests/helm/kafka-ui/1.5.1/dip-values.yaml b/manifests/helm/kafka-ui/1.5.1/dip-values.yaml new file mode 100644 index 0000000..0d9e2cc --- /dev/null +++ b/manifests/helm/kafka-ui/1.5.1/dip-values.yaml @@ -0,0 +1,52 @@ +image: + registry: docker.io + repository: wbsong111/kafka-ui + tag: "v1.3.0" + pullPolicy: IfNotPresent +yamlApplicationConfig: + kafka: + clusters: + - name: kafka-cluster + bootstrapServers: SASL_PLAINTEXT://kafka-cluster-kafka-tls-bootstrap.$kafka_cluster_namespace.svc.cluster.local:9093 + properties: + security.protocol: SASL_PLAINTEXT + sasl.mechanism: OAUTHBEARER + sasl.jaas.config: | + org.apache.kafka.common.security.oauthbearer.OAuthBearerLoginModule required + oauth.token.endpoint.uri="$KEYCLOAK_URL/realms/$KEYCLOAK_REALM/protocol/openid-connect/token" + oauth.client.id="$KAFKA_CLIENT_ID" + oauth.client.secret="$KAFKA_CLIENT_SECRET" + oauth.ssl.truststore.location="/etc/kafka/secrets/truststore.jks" + oauth.ssl.truststore.password="kafka"; + sasl.login.callback.handler.class: "io.strimzi.kafka.oauth.client.JaasClientOauthLoginCallbackHandler" + auth: + type: disabled + + management: + health: + ldap: + enabled: false + +volumes: + - name: truststore + secret: + secretName: truststore + +volumeMounts: + - name: truststore + mountPath: /etc/kafka/secrets + readOnly: true + +ingress: + enabled: true + ingressClassName: "apisix" + annotations: + cert-manager.io/cluster-issuer: "root-ca-issuer" + cert-manager.io/duration: 8760h + cert-manager.io/renew-before: 720h + kubernetes.io/ingress.class: apisix + k8s.apisix.apache.org/plugin-config-name: oidc-keycloak-authz + host: "{{ .Name }}.{{ .Domain }}" + tls: + enabled: true + secretName: "{{ .Name }}-tls-secret" \ No newline at end of file diff --git a/manifests/helm/kserve/0.1.0/dip-values.yaml b/manifests/helm/kserve/0.1.0/dip-values.yaml new file mode 100644 index 0000000..1ac84f2 --- /dev/null +++ b/manifests/helm/kserve/0.1.0/dip-values.yaml @@ -0,0 +1,27 @@ +inferenceService: + name: "{{ .Name }}" + + model: + args: + - --backend=vllm + - --model_name=$model.name + - --dtype=float16 + storageUri: "$model.volume" + + resources: + limits: + cpu: "8" + memory: 16Gi + nvidia.com/gpu: "1" + requests: + cpu: "4" + memory: 8Gi + nvidia.com/gpu: "1" + +ingress: + annotations: + cert-manager.io/cluster-issuer: "root-ca-issuer" + hosts: + - host: "{{ .Name }}-kserve.{{ .Namespace }}.{{ .Domain }}" + tls: + secretName: "{{ .Name }}-tls-secret" \ No newline at end of file diff --git a/manifests/helm/lakekeeper/0.8.1/dip-values.yaml b/manifests/helm/lakekeeper/0.8.1/dip-values.yaml new file mode 100644 index 0000000..73b314f --- /dev/null +++ b/manifests/helm/lakekeeper/0.8.1/dip-values.yaml @@ -0,0 +1 @@ +--- \ No newline at end of file diff --git a/manifests/helm/langflow-ide/0.1.0/dip-values.yaml b/manifests/helm/langflow-ide/0.1.0/dip-values.yaml new file mode 100644 index 0000000..861cd5b --- /dev/null +++ b/manifests/helm/langflow-ide/0.1.0/dip-values.yaml @@ -0,0 +1,91 @@ +langflow: + backend: + replicaCount: 1 + image: + repository: langflowai/langflow-backend + tag: "v1.1.1" + resources: + requests: + cpu: 0.5 + memory: 1Gi + nodeSelector: {} + tolerations: [] + backendOnly: true + env: + - name: LANGFLOW_PORT + value: "7860" + - name: LANGFLOW_LOG_LEVEL + value: "info" + - name: LANGFLOW_AUTO_LOGIN + value: "True" + - name: LANGFLOW_SUPERUSER + value: "$langflow.backend.env.username" + - name: LANGFLOW_SUPERUSER_PASSWORD + value: "$langflow.backend.env.password" + externalDatabase: + enabled: true + driver: + value: "postgresql" + host: + value: "{{ .Name }}-ide-postgresql-service" + port: + value: "5432" + database: + value: "langflow-db" + user: + value: "langflow" + password: + valueFrom: + secretKeyRef: + key: "password" + name: "$INFISICAL_SECRET" + sqlite: + enabled: false + probe: + failureThreshold: 3 + periodSeconds: 10 + timeoutSeconds: 5 + initialDelaySeconds: 5 + frontend: + enabled: true + replicaCount: 1 + image: + repository: langflowai/langflow-frontend + tag: "v1.1.1" + resources: + requests: + cpu: 0.3 + memory: 512Mi + nodeSelector: {} + tolerations: [] + +ingress: + enabled: true + annotations: + cert-manager.io/cluster-issuer: "root-ca-issuer" + cert-manager.io/duration: 8760h + cert-manager.io/renew-before: 720h + k8s.apisix.apache.org/plugin-config-name: oidc-keycloak-authz + hosts: + - host: "{{ .Name }}.{{ .Domain }}" + paths: + - path: / + pathType: Prefix + servicePort: 7860 + tls: + - hosts: + - "{{ .Name }}.{{ .Domain }}" + secretName: "{{ .Name }}-tls-secret" + +postgresql: + enabled: true + fullnameOverride: "{{ .Name }}-ide-postgresql-service" + auth: + username: "langflow" + password: "" + database: "langflow-db" + existingSecret: "$INFISICAL_SECRET" + primary: + persistence: + size: 5Gi + storageClass: "" \ No newline at end of file diff --git a/manifests/helm/langfuse/1.0.0-rc.2/dip-values.yaml b/manifests/helm/langfuse/1.0.0-rc.2/dip-values.yaml new file mode 100644 index 0000000..471b41d --- /dev/null +++ b/manifests/helm/langfuse/1.0.0-rc.2/dip-values.yaml @@ -0,0 +1,100 @@ +global: + security: + allowInsecureImages: true + +langfuse: + logging: + level: info + salt: + value: "$langfuse.salt.value" + encryptionKey: + value: "$langfuse.encryptionKey.value" + + ingress: + enabled: true + annotations: + cert-manager.io/cluster-issuer: "root-ca-issuer" + hosts: + - host: "{{ .Name }}.{{ .Domain }}" + paths: + - path: / + pathType: Prefix + tls: + enabled: true + secretName: "{{ .Name }}-tls-secret" + web: + image: + repository: langfuse/langfuse + resources: {} + replicas: 1 + worker: + image: + repository: langfuse/langfuse-worker + resources: {} + replicas: 1 + + nextauth: + url: "https://{{ .Name }}.{{ .Domain }}" + secret: + value: "$langfuse.nextauth.secret.value" + additionalEnv: + - name: AUTH_DISABLE_USERNAME_PASSWORD + value: "true" + - name: AUTH_KEYCLOAK_CLIENT_ID + value: "$KEYCLOAK_CLIENT_ID" + - name: "AUTH_KEYCLOAK_CLIENT_SECRET" + value: "$KEYCLOAK_CLIENT_SECRET" + - name: "AUTH_KEYCLOAK_ISSUER" + value: "$KEYCLOAK_URL/realms/$KEYCLOAK_REALM" + - name: NODE_TLS_REJECT_UNAUTHORIZED + value: "0" + +postgresql: + auth: + username: "postgres" + existingSecret: "$INFISICAL_SECRET" + secretKeys: + userPasswordKey: "postgres-password" + + migration: + autoMigrate: true + + persistence: + enabled: true + storageClass: "" + size: 5Gi + +redis: + auth: + enabled: true + existingSecret: "$INFISICAL_SECRET" + existingSecretPasswordKey: "valkey-password" + primary: + persistence: + enabled: true + storageClass: "" + size: 5Gi + +clickhouse: + deploy: true + auth: + username: default + password: "" + existingSecret: "$INFISICAL_SECRET" + existingSecretKey: "admin-password" + + shards: 1 + persistence: + enabled: true + storageClass: "" + size: 10Gi + +s3: + deploy: false + bucket: "$s3.bucket" + region: "auto" + endpoint: "https://$s3.endpoint" + accessKeyId: + value: "$s3.accessKeyId.value" + secretAccessKey: + value: "$s3.secretAccessKey.value" \ No newline at end of file diff --git a/manifests/helm/litellm/0.4.4/dip-values.yaml b/manifests/helm/litellm/0.4.4/dip-values.yaml new file mode 100644 index 0000000..d350c4a --- /dev/null +++ b/manifests/helm/litellm/0.4.4/dip-values.yaml @@ -0,0 +1,24 @@ +masterkey: "$masterkey" + +proxy_config: + model_list: [] + +ingress: + enabled: true + className: "apisix" + annotations: + cert-manager.io/cluster-issuer: "root-ca-issuer" + cert-manager.io/duration: 8760h + cert-manager.io/renew-before: 720h + hosts: + - host: "{{ .Name }}.{{ .Domain }}" + paths: + - path: / + pathType: Prefix + tls: + - secretName: "{{ .Name }}-tls-secret" + hosts: + - "{{ .Name }}.{{ .Domain }}" + +dip: + mainPath: ui \ No newline at end of file diff --git a/manifests/helm/mlflow/1.9.0/dip-values.yaml b/manifests/helm/mlflow/1.9.0/dip-values.yaml new file mode 100644 index 0000000..28bf7a8 --- /dev/null +++ b/manifests/helm/mlflow/1.9.0/dip-values.yaml @@ -0,0 +1,142 @@ +image: + repository: paasup/mlflow + tag: "v3.11.1-oidc" + +initImages: + dbchecker: + tag: "1.37" + iniFileInitializer: + tag: "1.37" + mlflowDbMigration: + repository: paasup/mlflow + tag: "v3.11.1-oidc" + +fullnameOverride: "{{ .Name }}" + +backendStore: + databaseMigration: true + databaseConnectionCheck: true + +postgresql: + enabled: true + auth: + username: mlflow + password: "$postgresql.auth.password" + database: mlflow + image: + repository: bitnamilegacy/postgresql + primary: + persistence: + enabled: true + +artifactRoot: + proxiedArtifactStorage: true + defaultArtifactsDestination: "s3://mlflow/artifacts" + s3: + enabled: true + bucket: mlflow + path: artifacts + awsAccessKeyId: "$artifactRoot.s3.awsAccessKeyId" + awsSecretAccessKey: "$artifactRoot.s3.awsSecretAccessKey" + + +extraEnvVars: + MLFLOW_S3_ENDPOINT_URL: "$extraEnvVars.s3endpoint" + MLFLOW_S3_IGNORE_TLS: "true" + SSL_CERT_FILE: "/etc/ssl/certs/custom-ca.crt" + REQUESTS_CA_BUNDLE: "/etc/ssl/certs/custom-ca.crt" + HTTPX_CA_BUNDLE: "/etc/ssl/certs/custom-ca.crt" + + OIDC_CLIENT_ID: "$KEYCLOAK_CLIENT_ID" + OIDC_DISCOVERY_URL: "$KEYCLOAK_URL/realms/$KEYCLOAK_REALM/.well-known/openid-configuration" + OIDC_REDIRECT_URI: "https://{{ .Name }}.{{ .Domain }}/callback" + OIDC_SCOPE: "openid email profile" + OIDC_GROUPS_ATTRIBUTE: "mlflow-groups" + OIDC_GROUP_NAME: "paasup" + OIDC_ADMIN_GROUP_NAME: "mlflow-admin" + OIDC_USERS_DB_URI: "postgresql://mlflow:$postgresql.auth.password@{{ .Name }}-postgresql:5432/mlflow" + DEFAULT_MLFLOW_PERMISSION: "READ" + AUTOMATIC_LOGIN_REDIRECT: "true" + OIDC_ALEMBIC_VERSION_TABLE: "mlflow_oidc_alembic_version" + + MLFLOW_ENABLE_WORKSPACES: "true" + OIDC_WORKSPACE_DEFAULT_PERMISSION: "EDIT" + OIDC_WORKSPACE_DETECTION_PLUGIN: "mlflow_workspace_detector" + PYTHONPATH: "/opt/mlflow-plugins" + WORKSPACE_CACHE_MAX_SIZE: "1024" + WORKSPACE_CACHE_TTL_SECONDS: "300" + PERMISSION_SOURCE_ORDER: "user,group,regex,group-regex" + MLFLOW_LOGGING_LEVEL: "DEBUG" + +extraSecretNamesForEnvFrom: + - mlflow-oidc-secret + +auth: + enabled: false + +log: + enabled: false + +extraArgs: + appName: "oidc-auth" + uvicornOpts: "--timeout-keep-alive 600" + allowedHosts: "{{ .Name }}.{{ .Domain }}" + corsAllowedOrigins: "https://{{ .Name }}.{{ .Domain }}" + +service: + type: ClusterIP + port: 80 + +ingress: + enabled: true + className: "apisix" + annotations: + cert-manager.io/cluster-issuer: "root-ca-issuer" + cert-manager.io/duration: 8760h + cert-manager.io/renew-before: 720h + hosts: + - host: "{{ .Name }}.{{ .Domain }}" + paths: + - path: / + pathType: Prefix + tls: + - secretName: "{{ .Name }}-tls-secret" + hosts: + - "{{ .Name }}.{{ .Domain }}" + +resources: + limits: + cpu: 1000m + memory: 2Gi + requests: + cpu: 500m + memory: 1Gi + +extraVolumes: + - name: keycloak-tls + secret: + secretName: keycloak-tls + - name: workspace-plugin + configMap: + name: mlflow-workspace-plugin + - name: hooks-patch + configMap: + name: mlflow-hooks-patch + +extraVolumeMounts: + - name: keycloak-tls + mountPath: /etc/ssl/certs/custom-ca.crt + subPath: ca.crt + readOnly: true + - name: workspace-plugin + mountPath: /opt/mlflow-plugins + - name: hooks-patch + mountPath: /usr/local/lib/python3.10/site-packages/mlflow_oidc_auth/hooks/before_request.py + subPath: before_request.py + readOnly: true + +serviceMonitor: + enabled: false + namespace: monitoring + labels: + release: prometheus \ No newline at end of file diff --git a/manifests/helm/nemo/25.4.0/dip-values.yaml b/manifests/helm/nemo/25.4.0/dip-values.yaml new file mode 100644 index 0000000..f2eda2a --- /dev/null +++ b/manifests/helm/nemo/25.4.0/dip-values.yaml @@ -0,0 +1,77 @@ +ngcAPIKey: "$ngcAPIKey" + +imagePullSecrets: + - name: nvcrimagepullsecret + registry: nvcr.io + username: "$oauthtoken" + password: "$ngcAPIKey" + +data-store: + enabled: true + external: + rootUrl: "https://nemo-datastore-{{ .Name }}.{{ .Domain }}" + domain: "nemo-datastore-{{ .Name }}.{{ .Domain }}" + +customizer: + enabled: true + customizerConfig: + meta/llama-3.2-1b-instruct: + enabled: true + +nim: + enabled: false + +evaluator: + enabled: true + argoWorkflows: + enabled: true + crds: + install: false + +guardrails: + enabled: true + +nemo-operator: + enabled: true + +nim-operator: + enabled: true + +dgxc-admission-controller: + enabled: false + +entity-store: + enabled: true + +volcano: + enabled: true + +deployment-management: + enabled: true + deployments: + defaultStorageClass: "longhorn" + +nim-proxy: + enabled: true + +ingress: + enabled: true + annotations: + cert-manager.io/cluster-issuer: root-ca-issuer + cert-manager.io/duration: 8760h + cert-manager.io/renew-before: 720h + className: "apisix" + tls: + - hosts: + - "nemo-{{ .Name }}.{{ .Domain }}" + secretName: "{{ .Name }}-tls-secret" + hosts: + default: + name: "nemo-{{ .Name }}.{{ .Domain }}" + nimProxy: + name: "nim-{{ .Name }}.{{ .Domain }}" + dataStore: + name: "data-store-{{ .Name }}.{{ .Domain }}" + +virtualService: + enabled: false \ No newline at end of file diff --git a/manifests/helm/nim/25.4.0/dip-values.yaml b/manifests/helm/nim/25.4.0/dip-values.yaml new file mode 100644 index 0000000..87399a1 --- /dev/null +++ b/manifests/helm/nim/25.4.0/dip-values.yaml @@ -0,0 +1,25 @@ +nimService: + name: "{{ .Name }}" + existingAuthSecret: "$INFISICAL_SECRET" + existingPVC: "" + + env: + - name: NIM_PEFT_SOURCE + value: http://nemo-entity-store.nemo:8000 + - name: NIM_SERVED_MODEL_NAME + value: "$nimService.modelName" + - name: NIM_MODEL_NAME + value: "$nimService.modelName" + - name: NIM_PEFT_REFRESH_INTERVAL + value: "30" + +image: + repository: "$image.repository" + pullPolicy: IfNotPresent + tag: "$image.tag" + +imagePullSecrets: + - name: nvcrimagepullsecret + registry: nvcr.io + username: "$oauthtoken" + password: "$imagePullSecrets.password" \ No newline at end of file diff --git a/manifests/helm/ollama/1.1.2/dip-values.yaml b/manifests/helm/ollama/1.1.2/dip-values.yaml new file mode 100644 index 0000000..facc8c8 --- /dev/null +++ b/manifests/helm/ollama/1.1.2/dip-values.yaml @@ -0,0 +1,51 @@ +image: + repository: ollama/ollama + tag: 0.5.4 + +runtimeClassName: nvidia + +persistentVolume: + enabled: true + size: "30Gi" + storageClass: longhorn + +resources: + requests: + memory: 4096Mi + cpu: 2000m + limits: + memory: 8192Mi + cpu: 4000m + +ollama: + gpu: + enabled: ture + type: "nvidia" + number: 1 + + models: + pull: + - mistral + #- benedict/linkbricks-mistral-nemo-korean:12b + #- benedict/linkbricks-gemma2-korean:27b + #- qwen2.5-coder:32b + #- codeqwen:7b-chat + # - llama3 + +ingress: + enabled: true + className: "apisix" + annotations: + cert-manager.io/cluster-issuer: "root-ca-issuer" + cert-manager.io/duration: 8760h + cert-manager.io/renew-before: 720h + k8s.apisix.apache.org/plugin-config-name: oidc-keycloak-authz + hosts: + - host: "{{ .Name }}.{{ .Domain }}" + paths: + - path: / + pathType: Prefix + tls: + - hosts: + - "{{ .Name }}.{{ .Domain }}" + secretName: "{{ .Name }}-tls-secret" \ No newline at end of file diff --git a/manifests/helm/open-webui/5.4.0/dip-values.yaml b/manifests/helm/open-webui/5.4.0/dip-values.yaml new file mode 100644 index 0000000..6785664 --- /dev/null +++ b/manifests/helm/open-webui/5.4.0/dip-values.yaml @@ -0,0 +1,64 @@ +ollama: + enabled: false +tika: + enabled: false +websocket: + enabled: false +redis-cluster: + enabled: false +ingress: + enabled: true + class: "apisix" + annotations: + cert-manager.io/cluster-issuer: "root-ca-issuer" + cert-manager.io/duration: 8760h + cert-manager.io/renew-before: 720h + host: "{{ .Name }}.{{ .Domain }}" + tls: true + existingSecret: "{{ .Name }}-tls-secret" +persistence: + enabled: true + size: 2Gi + existingClaim: "" + subPath: "" + accessModes: + - ReadWriteOnce + storageClass: "" + selector: {} + annotations: {} +extraEnvVars: + - name: OPENAI_API_KEY + value: "$extraEnvVars" + - name: OAUTH_CLIENT_ID + value: $KEYCLOAK_CLIENT_ID + - name: OAUTH_CLIENT_SECRET + value: $KEYCLOAK_CLIENT_SECRET + - name: OPENID_PROVIDER_URL + value: $KEYCLOAK_URL/realms/$KEYCLOAK_REALM/.well-known/openid-configuration + - name: OAUTH_PROVIDER_NAME + value: paasup + - name: OAUTH_SCOPES + value: "openid email profile" + - name: ENABLE_LOGIN_FORM + value: "true" + - name: SSL_CERT_FILE + value: "/etc/ssl/certs/keycloak/ca.crt" + - name: ENABLE_OAUTH_SIGNUP + value: "true" + - name: OAUTH_MERGE_ACCOUNTS_BY_EMAIL + value: "true" + - name: DEFAULT_USER_ROLE + value: user + - name: ENV + value: prod + +volumeMounts: + initContainer: [] + container: + - name: "keycloak-tls" + mountPath: "/etc/ssl/certs/keycloak" + +volumes: + - name: "keycloak-tls" + secret: + secretName: keycloak-tls \ No newline at end of file diff --git a/manifests/helm/postgresql-ha/11.9.4/dip-values.yaml b/manifests/helm/postgresql-ha/11.9.4/dip-values.yaml new file mode 100644 index 0000000..7ea6a14 --- /dev/null +++ b/manifests/helm/postgresql-ha/11.9.4/dip-values.yaml @@ -0,0 +1,47 @@ +global: + imageRegistry: "" + +postgresql: + username: postgres + existingSecret: "$INFISICAL_SECRET" + + maxConnections: "200" + sharedPreloadLibraries: "repmgr, pgaudit, pg_stat_statements, pgoutput" + + extendedConf: |- + wal_level = logical + max_replication_slots = 4 + max_wal_senders = 4 + + replicaCount: 1 + + extraEnvVars: + - name: TZ + value: Asia/Seoul + + resources: + requests: + cpu: 100m + memory: 512Mi + limits: + cpu: 500m + memory: 1024Mi + + tolerations: [] + + nodeSelector: {} + +pgpool: + existingSecret: "$INFISICAL_SECRET" + + replicaCount: 0 + +persistence: + enabled: true + storageClass: "" + size: 1Gi + +volumePermissions: + enabled: true + podSecurityContext: + runAsUser: 0 \ No newline at end of file diff --git a/manifests/helm/qdrant/1.12.4/dip-values.yaml b/manifests/helm/qdrant/1.12.4/dip-values.yaml new file mode 100644 index 0000000..af4665e --- /dev/null +++ b/manifests/helm/qdrant/1.12.4/dip-values.yaml @@ -0,0 +1,48 @@ +images: + repository: docker.io/qdrant/qdrant + tag: v1.12.4 + +replicaCount: 1 + +nodeSelector: {} +tolerations: [] +resources: {} + +persistence: + accessModes: ["ReadWriteOnce"] + size: 10Gi + storageClassName: "" + +config: + log_level: INFO + cluster: + enabled: true + p2p: + port: 6335 + consensus: + tick_period_ms: 100 + +apiKey: false +readOnlyApiKey: false + +ingress: + enabled: true + ingressClassName: "apisix" + annotations: + cert-manager.io/cluster-issuer: "root-ca-issuer" + cert-manager.io/duration: 8760h + cert-manager.io/renew-before: 720h + k8s.apisix.apache.org/plugin-config-name: oidc-keycloak-authz + hosts: + - host: "{{ .Name }}.{{ .Domain }}" + paths: + - path: / + pathType: Prefix + servicePort: 6333 + tls: + - hosts: + - "{{ .Name }}.{{ .Domain }}" + secretName: "{{ .Name }}-tls-secret" + +dip: + mainPath: dashboard \ No newline at end of file diff --git a/manifests/helm/ragflow/0.1.0/dip-values.yaml b/manifests/helm/ragflow/0.1.0/dip-values.yaml new file mode 100644 index 0000000..d6ee6f5 --- /dev/null +++ b/manifests/helm/ragflow/0.1.0/dip-values.yaml @@ -0,0 +1,131 @@ +fullnameOverride: "{{ .Name }}" + +env: + DOC_ENGINE: infinity + + MYSQL_PASSWORD: "$env.mysqlPassword" + MYSQL_DBNAME: rag_flow + + MINIO_ROOT_USER: rag_flow + MINIO_PASSWORD: "$env.minioPassword" + + REDIS_PASSWORD: "$env.redisPassword" + + RAGFLOW_IMAGE: infiniflow/ragflow:v0.20.1-slim + + TIMEZONE: "Asia/Seoul" + + DOC_BULK_SIZE: 4 + + EMBEDDING_BATCH_SIZE: 16 + + REQUESTS_CA_BUNDLE: /tmp/ca.crt + SSL_CERT_FILE: /tmp/ca.crt + +ragflow: + + service_conf: + oauth: + oidc: + display_name: "KEYCLOAK" + client_id: "$KEYCLOAK_CLIENT_ID" + client_secret: "$KEYCLOAK_CLIENT_SECRET" + issuer: "$KEYCLOAK_URL/realms/$KEYCLOAK_REALM" + scope: "openid email profile" + redirect_uri: "https://{{ .Name }}.{{ .Domain }}/v1/user/oauth/callback/oidc" + + llm_factories: + + volumes: + - name: keycloak-tls + secret: + secretName: keycloak-tls + + volumeMounts: + - name: keycloak-tls + mountPath: /tmp/ca.crt + subPath: ca.crt + readOnly: true + + deployment: + strategy: + resources: + service: + type: ClusterIP + api: + service: + enabled: true + type: ClusterIP + +infinity: + image: + repository: infiniflow/infinity + tag: v0.6.0-dev5 + storage: + className: + capacity: 5Gi + deployment: + strategy: + resources: + service: + type: ClusterIP + +minio: + image: + repository: quay.io/minio/minio + tag: RELEASE.2023-12-20T01-00-02Z + storage: + className: + capacity: 5Gi + deployment: + strategy: + resources: + service: + type: ClusterIP + +mysql: + image: + repository: mysql + tag: 8.0.39 + storage: + className: + capacity: 5Gi + deployment: + strategy: + resources: + service: + type: ClusterIP + +redis: + image: + repository: valkey/valkey + tag: 8 + storage: + className: + capacity: 5Gi + persistence: + enabled: true + deployment: + strategy: + resources: + service: + type: ClusterIP + + +ingress: + enabled: true + className: "apisix" + annotations: + cert-manager.io/cluster-issuer: root-ca-issuer + cert-manager.io/duration: 8760h + cert-manager.io/renew-before: 720h + k8s.apisix.apache.org/plugin-config-name: https-redirect + hosts: + - host: "{{ .Name }}.{{ .Domain }}" + paths: + - path: / + pathType: Prefix + tls: + - secretName: "{{ .Name }}-tls-secret" + hosts: + - "{{ .Name }}.{{ .Domain }}" \ No newline at end of file diff --git a/manifests/helm/spark-operator/2.0.2/dip-values.yaml b/manifests/helm/spark-operator/2.0.2/dip-values.yaml new file mode 100644 index 0000000..cb83acc --- /dev/null +++ b/manifests/helm/spark-operator/2.0.2/dip-values.yaml @@ -0,0 +1,42 @@ +image: + registry: docker.io + repository: kubeflow/spark-operator + tag: "2.0.2" + +controller: + workers: 10 + + logLevel: info + + uiService: + enable: true + uiIngress: + enable: true + urlFormat: "{{ .Name }}.{{ .Domain }}/{{`{{$appNamespace}}`}}/{{`{{$appName}}`}}" + + resources: + limits: + cpu: 100m + memory: 300Mi + requests: + cpu: 100m + memory: 300Mi + + workqueueRateLimiter: + bucketQPS: 50 + bucketSize: 500 + maxDelay: + enable: true + duration: 6h + +webhook: + resources: + limits: + cpu: 100m + memory: 300Mi + requests: + cpu: 100m + memory: 300Mi + +spark: + jobNamespaces: [] \ No newline at end of file diff --git a/manifests/helm/starrocks-operator/1.11.3/dip-values.yaml b/manifests/helm/starrocks-operator/1.11.3/dip-values.yaml new file mode 100644 index 0000000..f0e95d4 --- /dev/null +++ b/manifests/helm/starrocks-operator/1.11.3/dip-values.yaml @@ -0,0 +1,33 @@ +timeZone: Asia/Seoul + +image: + repository: starrocks/operator + tag: "v1.11.0" + pullPolicy: IfNotPresent + +resources: + limits: + cpu: 500m + memory: 512Mi + requests: + cpu: 500m + memory: 400Mi + +nodeSelector: + kubernetes.io/os: linux + +tolerations: [] + +affinity: {} + +webhook: + enabled: true + port: 9443 + certManager: + enabled: false + +metrics: + enabled: true + port: 8080 + serviceMonitor: + enabled: false \ No newline at end of file diff --git a/manifests/helm/starrocks/1.11.3-4.0.0/dip-values.yaml b/manifests/helm/starrocks/1.11.3-4.0.0/dip-values.yaml new file mode 100644 index 0000000..fb65754 --- /dev/null +++ b/manifests/helm/starrocks/1.11.3-4.0.0/dip-values.yaml @@ -0,0 +1,74 @@ +initPassword: + enabled: true + password: "" + passwordSecret: "$INFISICAL_SECRET" + +timeZone: Asia/Seoul + +starrocksCluster: + enabledBe: false + enabledCn: true + +starrocksFESpec: + replicas: 3 + runAsNonRoot: "false" + service: + type: ClusterIP + resources: + requests: + cpu: 300m + memory: 1Gi + limits: + cpu: 2 + memory: 4Gi + storageSpec: + name: fe + storageClassName: "longhorn" + storageSize: 10Gi + logStorageSize: 5Gi + + nodeSelector: {} + affinity: {} + tolerations: [] + + config: | + run_mode = shared_data + cloud_native_storage_type = S3 + aws_s3_endpoint = $starrocksFESpec.config.endpoint + + aws_s3_path = $starrocksFESpec.config.path + + aws_s3_access_key = $starrocksFESpec.config.accesskey + aws_s3_secret_key = $starrocksFESpec.config.secretkey + aws_s3_use_instance_profile = false + aws_s3_use_aws_sdk_default_behavior = false + + enable_load_volume_from_conf = true + + +starrocksCnSpec: + replicas: 3 + runAsNonRoot: "false" + resources: + requests: + cpu: 300m + memory: 2Gi + limits: + cpu: 2 + memory: 4Gi + storageSpec: + name: be + storageClassName: "longhorn" + storageSize: 15Gi + logStorageSize: 10Gi + nodeSelector: {} + affinity: {} + tolerations: [] + autoScalingPolicy: {} + + +starrocksFeProxySpec: + enabled: true + resolver: "kube-dns.kube-system.svc.cluster.local" + service: + type: ClusterIP \ No newline at end of file diff --git a/manifests/helm/strimzi-kafka-operator/0.47.0/dip-values.yaml b/manifests/helm/strimzi-kafka-operator/0.47.0/dip-values.yaml new file mode 100644 index 0000000..b76e4da --- /dev/null +++ b/manifests/helm/strimzi-kafka-operator/0.47.0/dip-values.yaml @@ -0,0 +1,23 @@ +defaultImageRegistry: "quay.io" +defaultImageRepository: "strimzi" +defaultImageTag: "0.47.0" + +replicas: 1 +watchNamespaces: [] +watchAnyNamespace: true + +logLevel: INFO +logConfiguration: "" + +fullReconciliationIntervalMs: 120000 +operationTimeoutMs: 300000 + +resources: + limits: + memory: 384Mi + cpu: 1000m + requests: + memory: 384Mi + cpu: 200m + +extraEnvs: [] \ No newline at end of file diff --git a/manifests/helm/superset/0.13.5/dip-values.yaml b/manifests/helm/superset/0.13.5/dip-values.yaml new file mode 100644 index 0000000..1a21d91 --- /dev/null +++ b/manifests/helm/superset/0.13.5/dip-values.yaml @@ -0,0 +1,191 @@ +configOverrides: + mapbox: | + MAPBOX_API_KEY = '$configOverrides.mapbox' + ENABLE_PROXY_FIX = True + FEATURE_FLAGS = { + "DYNAMIC_PLUGINS": True + } + secret: | + SECRET_KEY = '$configOverrides.secret' + my_override: | + FEATURE_FLAGS = { + "ENABLE_TEMPLATE_REMOVE_FILTERS" : True, + "ENABLE_TEMPLATE_PROCESSING": True, + "DASHBOARD_NATIVE_FILTERS" : True, + "DASHBOARD_NATIVE_FILTERS_SET": True + } + enable_oauth: | + from flask_appbuilder.security.manager import (AUTH_DB, AUTH_OAUTH) + from superset.security import SupersetSecurityManager + from flask import request + + import requests + import logging + + class CustomSsoSecurityManager(SupersetSecurityManager): + def oauth_user_info(self, provider, response=None): + me = self.appbuilder.sm.oauth_remotes[provider].get("openid-connect/userinfo") + me.raise_for_status() + data = me.json() + + logging.debug("User info from Keycloak: %s", data) + + role = [] + username = data.get("preferred_username", "") + host = request.host + dip_api_url = "http://dip-api.platform.svc.cluster.local:8087" + + url = f"{dip_api_url}/gwapi/v1/projectusers/{username}" + request_data = {"url": f"https://{host}"} + response = requests.post(url, json=request_data, headers={"Content-Type": "application/json"}, verify=False) + + if response.status_code == 200: + logging.info(f"API 요청 성공: {response.status_code}, {response.text}") + role.append(response.json().get("roleName","")) + else: + logging.info(f"API 요청 실패: {response.status_code}, {response.text}") + role.append("") + + return { + "username": data.get("preferred_username", ""), + "first_name": data.get("given_name", ""), + "last_name": data.get("family_name", ""), + "email": data.get("email", ""), + "role_keys": role, + } + + AUTH_TYPE = AUTH_OAUTH + AUTH_USER_REGISTRATION = True + AUTH_USER_REGISTRATION_ROLE = "Public" + AUTH_ROLES_SYNC_AT_LOGIN = True + CUSTOM_SECURITY_MANAGER = CustomSsoSecurityManager + + OAUTH_PROVIDERS = [ + { + "name": "keycloak", + "icon": "fa-key", + "token_key": "access_token", + "remote_app": { + "client_id": "$KEYCLOAK_CLIENT_ID", + "client_secret": "$KEYCLOAK_CLIENT_SECRET", + "client_kwargs": { + "scope": "openid email profile", + 'verify': False + }, + 'server_metadata_url': '$KEYCLOAK_URL/realms/$KEYCLOAK_REALM/.well-known/openid-configuration', + 'api_base_url': '$KEYCLOAK_URL/realms/$KEYCLOAK_REALM/protocol/' + } + } + ] + + AUTH_ROLES_MAPPING = { + 'root': ['Admin'], + 'admin': ['Admin'], + 'manager': ['Admin'], + 'member': ['Alpha'], + } + +bootstrapScript: | + #!/bin/bash + apt update + apt install -y pkg-config build-essential default-libmysqlclient-dev libpq-dev + pip install sqlalchemy-drill psycopg2-binary Authlib + pip install mysqlclient + +image: + repository: apachesuperset.docker.scarf.sh/apache/superset + tag: ~ + pullPolicy: IfNotPresent +resources: {} +nodeSelector: {} +tolerations: [] + +ingress: + enabled: true + ingressClassName: "apisix" + annotations: + cert-manager.io/cluster-issuer: "root-ca-issuer" + cert-manager.io/duration: 8760h + cert-manager.io/renew-before: 720h + path: / + pathType: Prefix + hosts: + - "{{ .Name }}.{{ .Domain }}" + tls: + - hosts: + - "{{ .Name }}.{{ .Domain }}" + secretName: "{{ .Name }}-tls-secret" + +supersetNode: + replicas: + enabled: true + replicaCount: 1 + + connections: + redis_host: "{{ .Name }}-redis-headless" + redis_port: "6379" + redis_user: "" + redis_cache_db: "1" + redis_celery_db: "0" + redis_ssl: + enabled: false + ssl_cert_reqs: CERT_NONE + db_host: "{{ .Name }}-postgresql" + db_port: "5432" + db_user: superset + db_pass: "$supersetNode.connections.db_pass" + db_name: superset + resources: {} + +supersetWorker: + replicas: + enabled: true + replicaCount: 1 + resources: {} + +supersetCeleryBeat: + enabled: false + resources: {} + +supersetCeleryFlower: + enabled: false + replicaCount: 1 + resources: {} + +postgresql: + enabled: true + auth: + username: superset + password: "" + database: superset + existingSecret: "$INFISICAL_SECRET" + image: + registry: docker.io + primary: + resources: + limits: {} + requests: + memory: 256Mi + cpu: 250m + persistence: + enabled: true + storageClass: "" + size: 8Gi + +redis: + enabled: true + architecture: standalone + auth: + enabled: false + existingSecret: "" + existingSecretPasswordKey: "" + image: + registry: docker.io + master: + resources: + limits: {} + requests: {} + persistence: + enabled: true + storageClass: "" + size: 8Gi \ No newline at end of file