Repository for dip
You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
 
 
 
 
 
 

4.7 KiB

langfuse 배포

1. 배포 방법

git clone https://github.com/paasup/dip-catalog.git
cd charts/langfuse
helm upgrade langfuse ./ -f custom-values.yaml  --install -n langfuse --create-namespace

2.custom-values.yaml 설명

  • custom-values.yaml에 정의된 값에 대한 설명이다.

1) Langfuse 설정

  • salt.value, encryptionKey.value, nextauth.secret.value에 각각 openssl을 사용한 랜덤값을 생성 필요
  • nextauth.url에 ingress에서 사용할 domain으로 설정 변경
logging:
    level: info

  salt:
    value: "Hshs64NHaE0Sw4kfLa/uEcGjyqVQS7U+NdeoF6/6xyM=" # openssl rand -base64 32
  
  encryptionKey:
    value: "7bcbf030457b00cca6300809233adda0abbee55bc71802519a9720ab2f2c6629"   # openssl rand -hex 32

  # Web deployment configuration
  web:
    image:
      repository: langfuse/langfuse
    resources: {}
    replicas: 1

  # Worker deployment configuration
  worker:
    image:
      repository: langfuse/langfuse-worker
    resources: {}
    replicas: 1

  # NextAuth configuration
  nextauth:
    url: http://langfuse.example.org
    
    secret:
      value: "L/mKkKmVBAs5Dwc54PiTpmjGrA/KRhdDJ2jLFcCDm4Y="  # openssl rand -base64 32

2) Ingress 설정

2.1) tls 시크릿 직접 생성

  • Rancher에서 ingress 사용을 위해서는 다음과 같이 설정할 수 있다.

    langfuse:
      ingress:
        enabled: true
        hosts:
        - host: langfuse.example.org
          paths:
          - path: /
            pathType: Prefix
            servicePort: 6333
        tls: 
        -  hosts:
          - langfuse.example.org
          secretName: langfuse-tls
    
  • ingress 사용을 위해서는 인증서를 secret으로 제공해야한다. 로컬 파일을 이용해 secret을 생성하는 방법은 다음과 같다.

    kubectl create secret tls langfuse-tls --cert=<path-to-cert-file> --key=<path-to-key-file> -n <namespace>
    

2.2) cert-manager를 이용한 자동 생성

  • cert manager를 통해 인증서 자동 생성 시 custom-values.yaml 수정한다.

  • ingress.annotations.cert-manager.io/cluster-issuer에 미리 배포된 Cluster Issuer의 이름으로 변경한다.

    ingress:
      enabled: true
      annotations:
        cert-manager.io/cluster-issuer: "selfsigned-issuer" 
        cert-manager.io/duration: 8760h  
        cert-manager.io/renew-before: 720h
      hosts:
      - host: langfuse.example.org
        paths:
        - path: /
          pathType: Prefix
          servicePort: 6333
      tls: 
      -  hosts:
         - langfuse.example.org
         secretName: langfuse-tls
    

3. Postgresql 설정

  • auth.password의 변경 필요
postgresql:
  auth:
    username: "postgres"
    password: "postgres"
    
  persistence:
    enabled: true
    storageClass: ""
    size: 5Gi

4. Redis 설정

  • auth.password의 변경 필요
redis:
  auth:
    password: "password"
  primary:
    persistence:
      enabled: true
      storageClass: ""
      size: 5Gi

5. ClickHouse 설정

  • auth.password를 사용할 값으로 변경.
  • 사용량에 따라 persistence.size의 조정이 필요.
clickhouse:  
  auth:
    username: default
    password: "password"  # 설정할 password 설정
    
  shards: 1 # 해당 값을 1로 고정
  persistence: 
    enabled: true
    storageClass: ""
    size: 10Gi

6. s3 설정

  • s3(minio)의 endpoint 및 사용할 bucket, region 설정이 필요.
  • s3 접근을 위한 access key, secret key가 필요.
s3:
  deploy: false # true 시 minio를 배포
  bucket: "langfuse"
  region: "auto"
  endpoint: "http://minio-api.example.org"

  accessKeyId:
    value: "CHaRLr736nSqaNEu4oGz"
  secretAccessKey:
    value: "HoZQwXDjZW6ytvTo5DHEfHmuiXykv7xoB9sr8VZo"

7. Keycloak Oauth 연동 설정

  • 다음은 keycloak 연동을 위해 설정.
langfuse:
  # NextAuth configuration
  nextauth:
    url: http://langfuse.example.org
    secret:
      value: "L/mKkKmVBAs5Dwc54PiTpmjGrA/KRhdDJ2jLFcCDm4Y=" # openssl rand -base64 32
  additionalEnv:
    # email/password 로그인 비활성화
    - name: AUTH_DISABLE_USERNAME_PASSWORD
      value: "true"
    # keycloak 연동
    - name: AUTH_KEYCLOAK_CLIENT_ID
      value: "langfuse"
    - name: "AUTH_KEYCLOAK_CLIENT_SECRET"
      value: "J5xyEzbDcc7VQ89S7yBXRbaM8TYryILI"
    - name: "AUTH_KEYCLOAK_ISSUER"
      value: "https://keycloak.example.org/auth/realms/paasup"
    # keycloak 인증서 등록 - 사설 인증서 사용시 필요
    - name: "NODE_EXTRA_CA_CERTS"
      value: /etc/ssl/certs/ca.crt

# keycloak 인증서 secret을 마운트
extraVolumes:
  - name: keycloak-tls
    secret:
      secretName: keycloak-tls
extraVolumeMounts:
  - name: keycloak-tls
    mountPath: /etc/ssl/certs/ca.crt
    subPath: ca.crt