# yaml-language-server: $schema=values.schema.json # Default values for mlflow. # This is a YAML-formatted file. # Declare variables to be passed into your templates. # -- (int) Numbers of replicas replicaCount: 1 # -- Image of mlflow image: # -- The docker image repository to use repository: paasup/mlflow # -- The docker image pull policy pullPolicy: IfNotPresent # -- The docker image tag to use. Default app version tag: "v3.11.1-oidc" # -- mlflow init images initImages: # -- dbchecker init container image configuration dbchecker: # -- dbchecker init container image repository to use repository: busybox # -- dbchecker init container image pull policy pullPolicy: IfNotPresent # -- dbchecker init container image tag to use tag: "1.37" # -- mlflow-db-migration init container image configuration mlflowDbMigration: # -- mlflow-db-migration init container image repository to use. repository: paasup/mlflow # -- mlflow-db-migration init container image pull policy. pullPolicy: IfNotPresent # -- mlflow-db-migration init container image tag to use. Default app version tag: "v3.11.1-oidc" # -- ini-file-initializer init container image configuration iniFileInitializer: # -- ini-file-initializer init container image repository to use repository: busybox # -- ini-file-initializer init container image pull policy pullPolicy: IfNotPresent # -- ini-file-initializer init container image tag to use tag: "1.37" # -- This will set the deployment strategy more information can be found here: https://kubernetes.io/docs/concepts/workloads/controllers/deployment/#strategy strategy: type: "RollingUpdate" rollingUpdate: maxSurge: "100%" maxUnavailable: 0 # -- Image pull secrets for private docker registry usages imagePullSecrets: [] # -- String to override the default generated name nameOverride: "" # -- String to override the default generated fullname fullnameOverride: "" serviceAccount: # -- Specifies whether a ServiceAccount should be created create: true # -- Automatically mount a ServiceAccount's API credentials? automount: true # -- Annotations to add to the service account. AWS EKS users can assign role arn from here. # Please find more information from here: # https://docs.aws.amazon.com/eks/latest/userguide/associate-service-account-role.html annotations: {} # eks.amazonaws.com/role-arn: "" # -- The name of the ServiceAccount to use. # If not set and create is true, a name is generated using the fullname template name: "" # -- Annotations for the pod podAnnotations: {} # -- Extra labels for the pod extraPodLabels: {} # -- This is for setting Security Context to a Pod. For more information checkout: https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ podSecurityContext: fsGroup: 1001 fsGroupChangePolicy: "OnRootMismatch" # -- This is for setting Security Context to a Container. For more information checkout: https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ securityContext: allowPrivilegeEscalation: false capabilities: drop: - ALL readOnlyRootFilesystem: false runAsNonRoot: true privileged: false runAsUser: 1001 runAsGroup: 1001 # -- This is for setting up a service more information can be found here: https://kubernetes.io/docs/concepts/services-networking/service/ service: # -- Specifies if you want to create a service enabled: true # -- This sets the service type more information can be found here: https://kubernetes.io/docs/concepts/services-networking/service/#publishing-services-service-types type: ClusterIP # -- This sets the ports more information can be found here: https://kubernetes.io/docs/concepts/services-networking/service/#field-spec-ports port: 80 # -- Default Service name name: http # -- Default container port containerPort: 5000 # -- Default container port name containerPortName: mlflow # -- Additional service annotations annotations: {} # -- Mlflow logging settings log: # -- Specifies if you want to enable mlflow logging. enabled: true # -- Mlflow logging level. level: info # -- Mlflow Usage Tracking settings. More information can be found here: https://mlflow.org/docs/latest/community/usage-tracking/ telemetry: # -- Specifies if you want to enable collecting anonymized usage data about how core features of the platform are used. enabled: false # -- Mlflow database connection settings backendStore: # -- Specifies if you want to run database migration databaseMigration: false # -- Add an additional init container, which checks for database availability databaseConnectionCheck: false # -- Specifies the default sqlite path defaultSqlitePath: ":memory:" postgres: # -- Specifies if you want to use postgres backend storage enabled: false # -- Postgres host address. e.g. your RDS or Azure Postgres Service endpoint host: "" # required # -- Postgres service port port: 5432 # required # -- mlflow database name created before in the postgres instance database: "" # required # -- postgres database user name which can access to mlflow database user: "" # required # -- postgres database user password which can access to mlflow database password: "" # required # -- postgres database connection driver. e.g.: "psycopg2" driver: "" mysql: # -- Specifies if you want to use mysql backend storage enabled: false # -- MySQL host address. e.g. your Amazon RDS for MySQL host: "" # required # -- MySQL service port port: 3306 # required # -- mlflow database name created before in the mysql instance database: "" # required # -- mysql database user name which can access to mlflow database user: "" # required # -- mysql database user password which can access to mlflow database password: "" # required # -- mysql database connection driver. e.g.: "pymysql" driver: "pymysql" mssql: # -- Specifies if you want to use mssql backend storage enabled: false # -- mssql host address host: "" # required # -- mssql service port port: 1433 # required # -- mlflow database name created before in the mssql instance database: "" # required # -- mssql database user name which can access to mlflow database user: "" # required # -- mssql database user password which can access to mlflow database password: "" # required # -- mssql database connection driver. e.g.: "pymssql" driver: "pymssql" # -- Specifies if you want to use an existing database secret. existingDatabaseSecret: # -- The name of the existing database secret. name: "" # -- The key of the username in the existing database secret. usernameKey: "username" # -- The key of the password in the existing database secret. passwordKey: "password" # -- Bitnami PostgreSQL configuration. For more information checkout: https://github.com/bitnami/charts/tree/main/bitnami/postgresql postgresql: # -- Enable postgresql enabled: false architecture: standalone image: repository: bitnamilegacy/postgresql primary: service: ports: postgresql: 5432 persistence: enabled: true existingClaim: "" auth: username: "" password: "" # -- The name of the PostgreSQL database. database: "mlflow" # -- Bitnami MySQL configuration. For more information checkout: https://github.com/bitnami/charts/tree/main/bitnami/mysql mysql: # -- Enable mysql enabled: false architecture: standalone image: repository: bitnamilegacy/mysql primary: service: ports: mysql: 3306 persistence: enabled: true existingClaim: "" auth: username: "" password: "" # -- The name of the MySQL database. database: "mlflow" # Mlflow blob storage settings artifactRoot: # -- Specifies if you want to enable proxied artifact storage access proxiedArtifactStorage: false # -- Specifies the default artifact root. defaultArtifactRoot: "./mlruns" # -- Specifies the default artifacts destination defaultArtifactsDestination: "./mlartifacts" # -- Specifies if you want to use Azure Blob Storage Mlflow Artifact Root azureBlob: # -- Specifies if you want to use Azure Blob Storage Mlflow Artifact Root enabled: false # -- Azure blob container name container: "" # required # -- Azure storage account name storageAccount: "" # required # -- Azure blob container folder. If you want to use root level, please don't set anything. path: "" # optional # -- Azure Cloud Connection String for the container. Only connectionString or accessKey required connectionString: "" # connectionString or accessKey required # -- Azure Cloud Storage Account Access Key for the container accessKey: "" # connectionString or accessKey required. Only connectionString or accessKey required # -- Specifies if you want to use AWS S3 Mlflow Artifact Root s3: # -- Specifies if you want to use AWS S3 Mlflow Artifact Root enabled: false # -- S3 bucket name bucket: "" # required # -- S3 bucket folder. If you want to use root level, please don't set anything. path: "" # optional # -- AWS IAM user AWS_ACCESS_KEY_ID which has attached policy for access to the S3 bucket awsAccessKeyId: "" # (awsAccessKeyId and awsSecretAccessKey) or roleArn serviceaccount annotation required # -- AWS IAM user AWS_SECRET_ACCESS_KEY which has attached policy for access to the S3 bucket awsSecretAccessKey: "" # (awsAccessKeyId and awsSecretAccessKey) or roleArn serviceaccount annotation required # -- Existing secret for AWS IAM user AWS_ACCESS_KEY_ID and AWS_SECRET_ACCESS_KEY secrets. existingSecret: # -- This is for setting up the AWS IAM user secrets existing secret name. name: "" # -- This is for setting up the key for AWS_ACCESS_KEY_ID secret. If it's set, awsAccessKeyId will be ignored. keyOfAccessKeyId: "" # -- This is for setting up the key for AWS_SECRET_ACCESS_KEY secret. If it's set, awsSecretAccessKey will be ignored. keyOfSecretAccessKey: "" # -- Specifies if you want to use Google Cloud Storage Mlflow Artifact Root gcs: # -- Specifies if you want to use Google Cloud Storage Mlflow Artifact Root enabled: false # -- Google Cloud Storage bucket name bucket: "" # required # -- Google Cloud Storage bucket folder. If you want to use root level, please don't set anything. path: "" # optional # -- Mlflow Flask Server Secret Key. Default: Will be auto generated. flaskServerSecretKey: "" # -- Mlflow authentication settings auth: # -- Specifies if you want to enable mlflow authentication. auth and ldapAuth can't be enabled at same time. enabled: false # -- Mlflow admin user username adminUsername: "" # -- Mlflow admin user password adminPassword: "" # -- Specifies if you want to use an existing admin credentials secret for auth. If it's set, adminUsername and adminPassword will be ignored. existingAdminSecret: # -- The name of the existing admin credentials secret. name: "" # -- The key of the admin username in the existing admin credentials secret. usernameKey: "username" # -- The key of the admin password in the existing admin credentials secret. passwordKey: "password" # -- Default permission for all users. More details: https://mlflow.org/docs/latest/auth/index.html#permissions defaultPermission: READ # -- Default registered authentication app name. If you want to use your custom authentication function, please look at: https://mlflow.org/docs/latest/auth/index.html#custom-authentication appName: "basic-auth" # -- Default authentication function authorizationFunction: "mlflow.server.auth:authenticate_request_basic_auth" # -- SQLite database file sqliteFile: "basic_auth.db" # -- SQLite database folder. Default is user home directory. sqliteFullPath: "" # -- Mlflow authentication INI configuration file path. configPath: "/etc/mlflow/auth/" # -- Mlflow authentication INI file configFile: "basic_auth.ini" # -- PostgreSQL based centrilised authentication database postgres: # -- Specifies if you want to use postgres auth backend storage enabled: false # -- Postgres host address. e.g. your RDS or Azure Postgres Service endpoint host: "" # required # -- Postgres service port port: 5432 # required # -- mlflow authorization database name created before in the postgres instance database: "" # required # -- postgres database user name which can access to mlflow authorization database user: "" # required # -- postgres database user password which can access to mlflow authorization database password: "" # required # -- postgres database connection driver. e.g.: "psycopg2" driver: "" # -- Specifies if you want to use an existing database secret for auth. If it's set, user and password will be ignored. existingSecret: # -- The name of the existing database secret. name: "" # -- The key of the username in the existing database secret. usernameKey: "username" # -- The key of the password in the existing database secret. passwordKey: "password" # -- Basic Authentication with LDAP backend ldapAuth: # -- Specifies if you want to enable mlflow LDAP authentication. auth and ldapAuth can't be enabled at same time. enabled: false # -- LDAP URI. e.g.: "ldap://lldap:3890/dc=mlflow,dc=test" uri: "" # -- TLS verification mode. Options: required, optional, none tlsVerification: required # -- LDAP Loopup Bind. e.g.: "uid=%s,ou=people,dc=mlflow,dc=test" lookupBind: "" # -- LDAP group attribute. groupAttribute: "dn" # -- Optional group attribute key for Active Directory users. e.g.: "attributes" groupAttributeKey: "" # -- LDAP base DN for the search. e.g.: "ou=groups,dc=mlflow,dc=test" searchBaseDistinguishedName: "" # -- LDAP query filter for search searchFilter: "(&(objectclass=groupOfUniqueNames)(uniquemember=%s))" # -- LDAP DN for the admin group. e.g.: "cn=test-admin,ou=groups,dc=mlflow,dc=test" adminGroupDistinguishedName: "" # -- LDAP DN for the user group. e.g.: "cn=test-user,ou=groups,dc=mlflow,dc=test" userGroupDistinguishedName: "" # -- Base64 encoded trusted CA certificate for LDAP server connection. encodedTrustedCACertificate: "" # -- External secret name for trusted CA certificate for LDAP server connection. externalSecretForTrustedCACertificate: "" # -- Autoscaling settings. Can be enabled only when backendStore is not sqlite and artifactRoot is one of blob storage systems. autoscaling: # -- If true, the number of replicas will be automatically scaled based on default metrics. On default, it will scale based on CPU and memory. For more information can be found here: https://kubernetes.io/docs/concepts/workloads/autoscaling/" enabled: false # -- The minimum number of replicas. minReplicas: 1 # -- The maximum number of replicas. maxReplicas: 5 # -- The metrics to use for autoscaling. metrics: - type: Resource resource: name: memory target: type: Utilization averageUtilization: 80 - type: Resource resource: name: cpu target: type: Utilization averageUtilization: 80 # -- The behavior of the autoscaler. Only supported on K8s 1.18.0 or later. behavior: {} # -- A map of arguments and values to pass to the `mlflow server` command. Keys must be camelcase. Helm will turn them to kebabcase style. extraArgs: {} # workers: TEXT # staticPrefix: TEXT # gunicornOpts: TEXT # waitressOpts: TEXT # -- A list of flags to pass to `mlflow server` command. Items must be camelcase. Helm will turn them to kebabcase style. extraFlags: [] # serveArtifacts # artifactsOnly # -- Extra environment variables extraEnvVars: {} # MLFLOW_S3_IGNORE_TLS: true # MLFLOW_S3_ENDPOINT_URL: http://1.2.3.4:9000 # AWS_DEFAULT_REGION: my_region # -- Extra secrets for environment variables extraSecretNamesForEnvFrom: [] ingress: # -- Specifies if you want to create an ingress access enabled: false # -- New style ingress class name. Only possible if you use K8s 1.18.0 or later version className: "" # -- Additional ingress annotations annotations: {} hosts: - host: chart-example.local paths: - path: / # -- Ingress path type pathType: ImplementationSpecific # -- Ingress tls configuration for https access tls: [] # -- This block is for setting up the resource management for the pod more information can be found here: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/ resources: {} serviceMonitor: # -- When set true then use a ServiceMonitor to configure scraping enabled: false # -- When set true then use a service port. On default use a pod port. useServicePort: false # -- Set the namespace the ServiceMonitor should be deployed namespace: monitoring # -- Set how frequently Prometheus should scrape interval: 30s # -- Set path to mlflow telemetry-path telemetryPath: /metrics # -- Set labels for the ServiceMonitor, use this to define your scrape label for Prometheus Operator labels: release: prometheus # -- Set timeout for scrape timeout: 10s # -- Set of labels to transfer on the Kubernetes Service onto the target. targetLabels: [] # -- Set of rules to relabel your exist metric labels metricRelabelings: [] # -- For more information checkout: https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#nodeselector nodeSelector: {} # -- For more information checkout: https://kubernetes.io/docs/concepts/scheduling-eviction/taint-and-toleration/ tolerations: [] # -- For more information checkout: https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#affinity-and-anti-affinity affinity: {} # -- Init Containers for Mlflow Pod initContainers: [] # -- Extra containers for the mlflow pod extraContainers: [] # -- Extra Volumes for the pod extraVolumes: [] # -- Extra Volume Mounts for the mlflow container extraVolumeMounts: [] # -- Liveness probe configurations. Please look to [here](https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-startup-probes/#configure-probes). livenessProbe: initialDelaySeconds: 10 periodSeconds: 30 timeoutSeconds: 3 failureThreshold: 5 # -- Readiness probe configurations. Please look to [here](https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-startup-probes/#configure-probes). readinessProbe: initialDelaySeconds: 10 periodSeconds: 30 timeoutSeconds: 3 failureThreshold: 5