You can not select more than 25 topics
Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
5.8 KiB
5.8 KiB
custom-values.yaml 사용 가이드
이 문서는 custom-values.yaml을 작성하고 배포에 적용하는 방법을 설명합니다.
Helm Values Merge 동작 방식
Helm은 --values 플래그로 전달된 파일을 기본 values.yaml에 deep merge 방식으로 적용합니다.
custom-values.yaml에 명시된 키는values.yaml기본값을 덮어씁니다- 명시하지 않은 키는
values.yaml기본값이 그대로 유지됩니다 - 중첩 객체(
resources,ingress등)도 키 단위로 병합됩니다
values.yaml (기본값)
+
custom-values.yaml (override)
=
최종 적용값
custom-values.yaml 필드 설명
image
image:
registry: "quay.io" # 레지스트리 주소. 비워두면 Docker Hub 사용
# tag는 생략 가능. repository에 태그를 포함하면 tag 필드는 무시됨.
# 방법1: repository에 태그 포함 (tag 불필요)
repository: "jupyter/scipy-notebook:ubuntu-22.04"
# 방법2: repository + tag 분리
# repository: "jupyter/scipy-notebook"
# tag: "latest"
tag: "latest" # repository에 ":"가 있으면 이 값은 무시됨
| 입력 | 결과 이미지 |
|---|---|
repository: "repo:ubuntu-22.04", tag: "latest" |
quay.io/repo:ubuntu-22.04 (tag 무시) |
repository: "repo", tag: "latest" |
quay.io/repo:latest |
repository: "repo", tag: "" |
quay.io/repo |
image.pullPolicy는 custom-values에 없으므로values.yaml기본값IfNotPresent적용
resources
resources:
limits:
cpu: "2000m" # 최대 2 vCPU
memory: "4096Mi" # 최대 4 GiB
requests:
cpu: "500m" # 예약 0.5 vCPU
memory: "1024Mi" # 예약 1 GiB
gpu: "" # GPU 사용 시: "1" (nvidia.com/gpu limits/requests에 동일하게 설정됨)
jupyterConfig
jupyterConfig:
token: "" # 비어 있으면 토큰 인증 비활성화
# 값 설정 시 SHA-256으로 해시되어 ServerApp.password에 적용
ingress
ingress:
enabled: true
ingressClassName: "kong"
annotations:
cert-manager.io/cluster-issuer: "root-ca-issuer"
cert-manager.io/duration: "8760h"
cert-manager.io/renew-before: "720h"
konghq.com/https-redirect-status-code: "301"
konghq.com/protocols: "https"
hosts:
- host: "jupyter.example.com" # 실제 도메인으로 변경 필수
paths:
- /
tls:
- hosts:
- "jupyter.example.com"
secretName: "jupyter-tls-secret"
homeVolume / dataVolume
homeVolume:
enabled: false # true로 설정 시 /home/jovyan에 PVC 마운트
size: "5Gi"
storageClassName: "" # 클러스터 기본 StorageClass 사용
accessMode: "ReadWriteOnce"
# mountPath: "" # custom-values에 없음 → 기본값 /home/jovyan 적용
dataVolume:
enabled: false # true로 설정 시 /home/jovyan/data에 PVC 마운트
size: "5Gi"
storageClassName: ""
accessMode: "ReadWriteOnce"
# mountPath: "" # custom-values에 없음 → 기본값 "data" 적용
groupVolumes
groupVolumes: []
# 공유 PVC 마운트 예시:
# groupVolumes:
# - claimName: "pvc-shared-data"
# mountPath: "/group_data"
# - claimName: "pvc-team-models"
# mountPath: "/models"
custom-values.yaml 미포함 필드 (values.yaml 기본값 적용)
| 필드 | 기본값 | 비고 |
|---|---|---|
image.pullPolicy |
IfNotPresent |
|
replicas |
1 |
0으로 설정하면 Pod 중지 |
homeVolume.mountPath |
"" → /home/jovyan |
|
dataVolume.mountPath |
"" → data |
|
imagePullSecrets |
[] |
Private 레지스트리 사용 시 추가 필요 |
배포 명령어
# 렌더링 미리보기 (실제 배포 없음)
helm template my-jupyter ./manifests/helm/jupyterlab/1.0.0 \
-f ./manifests/helm/jupyterlab/1.0.0/custom-values.yaml
# 신규 설치
helm install my-jupyter ./manifests/helm/jupyterlab/1.0.0 \
--namespace jupyter \
--create-namespace \
-f ./manifests/helm/jupyterlab/1.0.0/custom-values.yaml
# 업그레이드
helm upgrade my-jupyter ./manifests/helm/jupyterlab/1.0.0 \
-n jupyter \
-f ./manifests/helm/jupyterlab/1.0.0/custom-values.yaml
# 변경 사항 확인 (helm-diff 플러그인 필요)
helm diff upgrade my-jupyter ./manifests/helm/jupyterlab/1.0.0 \
-n jupyter \
-f ./manifests/helm/jupyterlab/1.0.0/custom-values.yaml
환경별 설정 예시
개발 환경 (최소 리소스, 인증 없음)
image:
repository: "jupyter/scipy-notebook"
tag: "latest"
resources:
limits:
cpu: "500m"
memory: "1024Mi"
requests:
cpu: "100m"
memory: "256Mi"
gpu: ""
jupyterConfig:
token: ""
ingress:
enabled: true
ingressClassName: "kong"
hosts:
- host: "jupyter-dev.example.com"
paths: [/]
tls:
- hosts: ["jupyter-dev.example.com"]
secretName: "jupyter-dev-tls"
운영 환경 (토큰 인증, PVC, GPU)
image:
# repository에 태그 포함 방식 (권장 - 버전 고정)
repository: "jupyter/scipy-notebook:2024-01-15"
# 또는 분리 방식:
# repository: "jupyter/scipy-notebook"
# tag: "2024-01-15"
resources:
limits:
cpu: "4000m"
memory: "8192Mi"
requests:
cpu: "1000m"
memory: "2048Mi"
gpu: "1" # NVIDIA GPU 1개
jupyterConfig:
token: "my-secure-token"
ingress:
enabled: true
ingressClassName: "kong"
hosts:
- host: "jupyter.example.com"
paths: [/]
tls:
- hosts: ["jupyter.example.com"]
secretName: "jupyter-prod-tls"
homeVolume:
enabled: true
size: "20Gi"
storageClassName: "fast-ssd"
accessMode: "ReadWriteOnce"
dataVolume:
enabled: true
size: "100Gi"
storageClassName: "fast-ssd"
accessMode: "ReadWriteOnce"
groupVolumes:
- claimName: "pvc-shared-datasets"
mountPath: "/datasets"