image: repository: paasup/mlflow tag: "v3.11.1-oidc" initImages: dbchecker: tag: "1.37" iniFileInitializer: tag: "1.37" mlflowDbMigration: repository: paasup/mlflow tag: "v3.11.1-oidc" backendStore: databaseMigration: true databaseConnectionCheck: true postgresql: enabled: true auth: username: mlflow password: mlflow1234 database: mlflow image: repository: bitnamilegacy/postgresql primary: persistence: enabled: true artifactRoot: proxiedArtifactStorage: true defaultArtifactsDestination: "s3://mlflow/artifacts" s3: enabled: true bucket: mlflow path: artifacts awsAccessKeyId: "adminuser" # 직접 입력하거나 existingSecret 사용 awsSecretAccessKey: "adminuser" # existingSecret: # name: mlflow-s3-secret # keyOfAccessKeyId: AWS_ACCESS_KEY_ID # keyOfSecretAccessKey: AWS_SECRET_ACCESS_KEY extraEnvVars: # --- 기본 설정 --- MLFLOW_S3_ENDPOINT_URL: "http://rustfs-svc.rustfs.svc.cluster.local:9000" MLFLOW_S3_IGNORE_TLS: "true" SSL_CERT_FILE: "/etc/ssl/certs/custom-ca.crt" # --- OIDC 설정 --- OIDC_CLIENT_ID: "mlflow" OIDC_DISCOVERY_URL: "https://keycloak.example.org/realms/paasup/.well-known/openid-configuration" OIDC_REDIRECT_URI: "https://mlflow.example.org/callback" OIDC_SCOPE: "openid email profile" OIDC_GROUPS_ATTRIBUTE: "groups" OIDC_GROUP_NAME: "mlflow" OIDC_ADMIN_GROUP_NAME: "mlflow-admin" OIDC_USERS_DB_URI: "postgresql://mlflow:mlflow1234@mlflow-postgresql:5432/mlflow" DEFAULT_MLFLOW_PERMISSION: "READ" AUTOMATIC_LOGIN_REDIRECT: "true" OIDC_ALEMBIC_VERSION_TABLE: "mlflow_oidc_alembic_version" # --- Workspace 설정 --- MLFLOW_ENABLE_WORKSPACES: "true" OIDC_WORKSPACE_DEFAULT_PERMISSION: "EDIT" OIDC_WORKSPACE_DETECTION_PLUGIN: "mlflow_workspace_detector" PYTHONPATH: "/opt/mlflow-plugins" WORKSPACE_CACHE_MAX_SIZE: "1024" WORKSPACE_CACHE_TTL_SECONDS: "300" PERMISSION_SOURCE_ORDER: "user,group,regex,group-regex" MLFLOW_LOGGING_LEVEL: "DEBUG" extraSecretNamesForEnvFrom: - mlflow-oidc-secret auth: enabled: false log: enabled: false extraArgs: appName: "oidc-auth" uvicornOpts: "--timeout-keep-alive 600" allowedHosts: "mlflow.example.org" corsAllowedOrigins: "https://mlflow.example.org" service: type: ClusterIP port: 80 ingress: enabled: true className: "apisix" annotations: # root-ca-issuer 사용: selfsigned-issuer 는 subject 가 빈 자체서명 인증서를 발급하여 # APISIX ingress controller 가 SSL 오브젝트로 동기화하지 않는다(TLS handshake 실패). # 클러스터의 다른 ingress 와 동일하게 CA 서명 issuer 를 사용한다. cert-manager.io/cluster-issuer: "root-ca-issuer" cert-manager.io/duration: 8760h cert-manager.io/renew-before: 720h # APISIX: http→https redirect 를 ApisixPluginConfig 로 처리 (files/mlflow-apisix-redirect.yaml) # CORS 는 mlflow 앱 네이티브(extraArgs.corsAllowedOrigins)로 처리 k8s.apisix.apache.org/plugin-config-name: https-redirect hosts: - host: mlflow.example.org paths: - path: / pathType: ImplementationSpecific tls: - secretName: mlflow-tls-secret hosts: - mlflow.example.org resources: limits: cpu: 1000m memory: 2Gi requests: cpu: 500m memory: 1Gi extraVolumes: - name: keycloak-ca-cert configMap: name: keycloak-ca-cert - name: workspace-plugin configMap: name: mlflow-workspace-plugin - name: hooks-patch configMap: name: mlflow-hooks-patch extraVolumeMounts: - name: keycloak-ca-cert mountPath: /etc/ssl/certs/custom-ca.crt subPath: ca.crt readOnly: true - name: workspace-plugin mountPath: /opt/mlflow-plugins - name: hooks-patch mountPath: /usr/local/lib/python3.10/site-packages/mlflow_oidc_auth/hooks/before_request.py subPath: before_request.py readOnly: true serviceMonitor: enabled: false namespace: monitoring labels: release: prometheus