From 44e79feb3e345cbf27d266599774702a93299e43 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Nicol=C3=B2=20Boschi?= Date: Wed, 10 Dec 2025 17:30:15 +0100 Subject: [PATCH] helm chart updates v1 --- docker/standalone/start-all.sh | 4 +- helm/INSTALL.txt | 135 ------------- helm/hindsight/Chart.lock | 6 + helm/hindsight/Chart.yaml | 2 +- helm/hindsight/README.md | 182 ++++++++++++++++++ helm/hindsight/templates/NOTES.txt | 73 +------ helm/hindsight/templates/_helpers.tpl | 2 +- helm/hindsight/templates/api-deployment.yaml | 30 +-- helm/hindsight/templates/configmap.yaml | 15 -- .../templates/controlplane-deployment.yaml | 30 ++- .../templates/postgresql-service.yaml | 19 ++ .../templates/postgresql-statefulset.yaml | 85 ++++++++ helm/hindsight/templates/secret.yaml | 12 +- helm/hindsight/values.yaml | 47 +++-- 14 files changed, 360 insertions(+), 282 deletions(-) delete mode 100644 helm/INSTALL.txt create mode 100644 helm/hindsight/Chart.lock create mode 100644 helm/hindsight/README.md delete mode 100644 helm/hindsight/templates/configmap.yaml create mode 100644 helm/hindsight/templates/postgresql-service.yaml create mode 100644 helm/hindsight/templates/postgresql-statefulset.yaml diff --git a/docker/standalone/start-all.sh b/docker/standalone/start-all.sh index 6b48853b..3af1fb45 100755 --- a/docker/standalone/start-all.sh +++ b/docker/standalone/start-all.sh @@ -26,7 +26,7 @@ PIDS=() # Start API if enabled if [ "$ENABLE_API" = "true" ]; then cd /app/api - hindsight-api 2>&1 | sed -u 's/^/[api] /' & + hindsight-api 2>&1 | sed 's/^/[api] /' & API_PID=$! PIDS+=($API_PID) @@ -47,7 +47,7 @@ fi if [ "$ENABLE_CP" = "true" ]; then echo "🎛️ Starting Control Plane..." cd /app/control-plane - PORT=9999 node server.js 2>&1 | grep -v -E "^[[:space:]]*(▲|✓|-|$)" | sed -u 's/^/[control-plane] /' & + PORT=9999 node server.js 2>&1 | grep -v -E "^[[:space:]]*(▲|✓|-|$)" | sed 's/^/[control-plane] /' & CP_PID=$! PIDS+=($CP_PID) else diff --git a/helm/INSTALL.txt b/helm/INSTALL.txt deleted file mode 100644 index 5f625a23..00000000 --- a/helm/INSTALL.txt +++ /dev/null @@ -1,135 +0,0 @@ -HINDSIGHT HELM CHART INSTALLATION GUIDE -===================================== - -PREREQUISITES -------------- -- Kubernetes cluster (1.19+) -- kubectl configured -- Helm 3.x installed -- PostgreSQL database with pgvector extension (if not using bundled PostgreSQL) - -BASIC INSTALLATION ------------------- - -1. Install with default values (requires external PostgreSQL): - - helm install hindsight ./hindsight \ - --set postgresql.external.host=your-postgres-host \ - --set postgresql.external.password=your-password \ - --set api.secrets.MEMORY_LLM_API_KEY=your-api-key - -2. Install with custom values file: - - helm install hindsight ./hindsight -f hindsight/values-production.yaml - -3. Install in a specific namespace: - - kubectl create namespace hindsight - helm install hindsight ./hindsight -n hindsight - -CONFIGURATION OPTIONS ---------------------- - -Development setup (using values-development.yaml): - helm install hindsight ./hindsight -f hindsight/values-development.yaml - -Production setup (using values-production.yaml): - helm install hindsight ./hindsight -f hindsight/values-production.yaml - -Custom LLM provider: - helm install hindsight ./hindsight \ - --set api.env.MEMORY_LLM_PROVIDER=openai \ - --set api.env.MEMORY_LLM_MODEL=gpt-4 \ - --set api.secrets.MEMORY_LLM_API_KEY=sk-your-key - -Enable ingress: - helm install hindsight ./hindsight \ - --set ingress.enabled=true \ - --set ingress.hosts[0].host=hindsight.example.com - -Enable autoscaling: - helm install hindsight ./hindsight \ - --set autoscaling.enabled=true \ - --set autoscaling.minReplicas=2 \ - --set autoscaling.maxReplicas=10 - -UPGRADE -------- - -Upgrade existing installation: - helm upgrade hindsight ./hindsight - -Upgrade with new values: - helm upgrade hindsight ./hindsight -f hindsight/values-production.yaml - -UNINSTALL ---------- - -Remove the Helm release: - helm uninstall hindsight - -Remove with namespace: - helm uninstall hindsight -n hindsight - -TESTING -------- - -Test the installation with dry-run: - helm install hindsight ./hindsight --dry-run --debug - -Validate templates: - helm template hindsight ./hindsight - -Lint the chart: - helm lint ./hindsight - -ACCESSING THE SERVICES ----------------------- - -Port-forward control plane: - kubectl port-forward svc/hindsight-control-plane 3000:3000 - -Port-forward API: - kubectl port-forward svc/hindsight-api 8888:8888 - -Get service URLs: - helm status hindsight - -DATABASE INITIALIZATION ------------------------ - -NOTE: Database migrations now run automatically when the API service starts. - You typically don't need to run migrations manually. - -If you want to pre-initialize the database before deploying (optional): - kubectl run hindsight-init --rm -it --restart=Never \ - --image=hindsight/api:latest \ - --env="DATABASE_URL=postgresql://user:pass@host:5432/hindsight" \ - -- python -c "from hindsight.migrations import run_migrations; run_migrations()" - -TROUBLESHOOTING ---------------- - -Check pod status: - kubectl get pods -l app.kubernetes.io/name=hindsight - -View logs for API: - kubectl logs -l app.kubernetes.io/component=api - -View logs for control plane: - kubectl logs -l app.kubernetes.io/component=control-plane - -Describe a pod: - kubectl describe pod - -Check configuration: - kubectl get configmap hindsight-config -o yaml - kubectl get secret hindsight-secret -o yaml - -NOTES ------ -- Make sure PostgreSQL has pgvector extension enabled -- Run database migrations before first use -- Configure proper resource limits for production -- Use external secrets management for production -- Enable TLS/SSL for production deployments diff --git a/helm/hindsight/Chart.lock b/helm/hindsight/Chart.lock new file mode 100644 index 00000000..68f77777 --- /dev/null +++ b/helm/hindsight/Chart.lock @@ -0,0 +1,6 @@ +dependencies: +- name: postgresql + repository: https://charts.bitnami.com/bitnami + version: 15.5.38 +digest: sha256:f67c7612736803ece8a669f8ca6b0555f3b78557bc0ecb732aa2e43f0df7750d +generated: "2025-12-10T17:20:57.058794+01:00" diff --git a/helm/hindsight/Chart.yaml b/helm/hindsight/Chart.yaml index a91cb8a3..6765e502 100644 --- a/helm/hindsight/Chart.yaml +++ b/helm/hindsight/Chart.yaml @@ -1,6 +1,6 @@ apiVersion: v2 name: hindsight -description: A Helm chart for Hindsight - temporal-semantic-entity memory system for AI agents +description: Hindsight helm chart type: application version: 0.1.0 appVersion: "0.1.0" diff --git a/helm/hindsight/README.md b/helm/hindsight/README.md new file mode 100644 index 00000000..d0c55b09 --- /dev/null +++ b/helm/hindsight/README.md @@ -0,0 +1,182 @@ +# Hindsight Helm Chart + +Helm chart for deploying Hindsight - a temporal-semantic-entity memory system for AI agents. + +## Prerequisites + +- Kubernetes 1.19+ +- Helm 3.0+ +- PostgreSQL database (external or bundled) + +## Quick Start + +```bash +# Update dependencies first +helm dependency update ./helm/hindsight + +# Install (PostgreSQL included by default) +export OPENAI_API_KEY="sk-your-openai-key" +helm upgrade hindsight --install ./helm/hindsight -n hindsight --create-namespace \ + --set api.secrets.HINDSIGHT_API_LLM_API_KEY="$OPENAI_API_KEY" +``` + +To use an external database instead: + +```bash +helm install hindsight ./helm/hindsight -n hindsight --create-namespace \ + --set api.secrets.HINDSIGHT_API_LLM_API_KEY="sk-your-openai-key" \ + --set postgresql.enabled=false \ + --set postgresql.external.host=my-postgres.example.com \ + --set postgresql.external.password=mypassword +``` + +## Installation + +### Add the repository (if published) + +```bash +helm repo add hindsight https://your-helm-repo.com +helm repo update +``` + +### Install with custom values file + +Create a `values-override.yaml`: + +```yaml +api: + secrets: + HINDSIGHT_API_LLM_API_KEY: "sk-your-openai-key" + +postgresql: + external: + host: "my-postgres.example.com" + password: "mypassword" +``` + +Then install: + +```bash +helm install hindsight ./helm/hindsight -n hindsight --create-namespace -f values-override.yaml +``` + +## Configuration + +### Key Values + +| Parameter | Description | Default | +|-----------|-------------|---------| +| `version` | Default image tag for all components | `0.1.0` | +| `api.enabled` | Enable the API component | `true` | +| `api.image.repository` | API image repository | `hindsight/api` | +| `api.image.tag` | API image tag (defaults to `version`) | - | +| `api.service.port` | API service port | `8888` | +| `controlPlane.enabled` | Enable the control plane | `true` | +| `controlPlane.image.repository` | Control plane image repository | `hindsight/control-plane` | +| `controlPlane.image.tag` | Control plane image tag (defaults to `version`) | - | +| `controlPlane.service.port` | Control plane service port | `3000` | +| `postgresql.enabled` | Deploy PostgreSQL as subchart | `true` | +| `postgresql.external.host` | External PostgreSQL host | `postgresql` | +| `postgresql.external.port` | External PostgreSQL port | `5432` | +| `postgresql.external.database` | Database name | `hindsight` | +| `postgresql.external.username` | Database username | `hindsight` | +| `ingress.enabled` | Enable ingress | `false` | +| `autoscaling.enabled` | Enable HPA | `false` | + +### Environment Variables + +All environment variables in `api.env` and `controlPlane.env` are automatically added to the respective pods. Sensitive values should go in `api.secrets` or `controlPlane.secrets`. + +```yaml +api: + env: + HINDSIGHT_API_LLM_PROVIDER: "openai" + HINDSIGHT_API_LLM_MODEL: "gpt-4" + secrets: + HINDSIGHT_API_LLM_API_KEY: "your-api-key" + HINDSIGHT_API_LLM_BASE_URL: "https://api.openai.com/v1" + +controlPlane: + env: + NODE_ENV: "production" + secrets: {} +``` + +### External Database + +To connect to an external PostgreSQL database: + +```yaml +postgresql: + enabled: false + external: + host: "my-postgres.example.com" + port: 5432 + database: "hindsight" + username: "hindsight" + password: "your-password" +``` + +### Ingress + +To expose the services via ingress: + +```yaml +ingress: + enabled: true + className: "nginx" + annotations: + cert-manager.io/cluster-issuer: "letsencrypt-prod" + hosts: + - host: hindsight.example.com + paths: + - path: / + pathType: Prefix + service: controlPlane + - path: /api + pathType: Prefix + service: api + tls: + - secretName: hindsight-tls + hosts: + - hindsight.example.com +``` + +## Upgrading + +```bash +helm upgrade hindsight ./helm/hindsight -n hindsight +``` + +## Uninstalling + +```bash +helm uninstall hindsight -n hindsight +``` + +## Components + +The chart deploys: + +- **API**: The main Hindsight API server for memory operations +- **Control Plane**: Web UI for managing agents and viewing memories + +## Development + +### Lint the chart + +```bash +helm lint ./helm/hindsight +``` + +### Template locally + +```bash +helm template hindsight ./helm/hindsight --debug +``` + +### Dry run installation + +```bash +helm install hindsight ./helm/hindsight --dry-run --debug +``` diff --git a/helm/hindsight/templates/NOTES.txt b/helm/hindsight/templates/NOTES.txt index fd9aec4a..d269305f 100644 --- a/helm/hindsight/templates/NOTES.txt +++ b/helm/hindsight/templates/NOTES.txt @@ -1,71 +1,2 @@ -Thank you for installing {{ .Chart.Name }}! - -Your release is named {{ .Release.Name }}. - -To learn more about the release, try: - - $ helm status {{ .Release.Name }} - $ helm get all {{ .Release.Name }} - -{{- if .Values.ingress.enabled }} - -The application is accessible via the following URL(s): -{{- range .Values.ingress.hosts }} - - http{{ if $.Values.ingress.tls }}s{{ end }}://{{ .host }} -{{- end }} - -{{- else }} - -1. Get the Control Plane URL by running these commands: -{{- if contains "NodePort" .Values.controlPlane.service.type }} - export NODE_PORT=$(kubectl get --namespace {{ .Release.Namespace }} -o jsonpath="{.spec.ports[0].nodePort}" services {{ include "hindsight.fullname" . }}-control-plane) - export NODE_IP=$(kubectl get nodes --namespace {{ .Release.Namespace }} -o jsonpath="{.items[0].status.addresses[0].address}") - echo "Control Plane URL: http://$NODE_IP:$NODE_PORT" -{{- else if contains "LoadBalancer" .Values.controlPlane.service.type }} - NOTE: It may take a few minutes for the LoadBalancer IP to be available. - You can watch the status by running 'kubectl get --namespace {{ .Release.Namespace }} svc -w {{ include "hindsight.fullname" . }}-control-plane' - export SERVICE_IP=$(kubectl get svc --namespace {{ .Release.Namespace }} {{ include "hindsight.fullname" . }}-control-plane --template "{{"{{ range (index .status.loadBalancer.ingress 0) }}{{.}}{{ end }}"}}") - echo "Control Plane URL: http://$SERVICE_IP:{{ .Values.controlPlane.service.port }}" -{{- else if contains "ClusterIP" .Values.controlPlane.service.type }} - export POD_NAME=$(kubectl get pods --namespace {{ .Release.Namespace }} -l "app.kubernetes.io/component=control-plane,app.kubernetes.io/instance={{ .Release.Name }}" -o jsonpath="{.items[0].metadata.name}") - export CONTAINER_PORT=$(kubectl get pod --namespace {{ .Release.Namespace }} $POD_NAME -o jsonpath="{.spec.containers[0].ports[0].containerPort}") - echo "Control Plane URL: http://127.0.0.1:3000" - kubectl --namespace {{ .Release.Namespace }} port-forward $POD_NAME 3000:$CONTAINER_PORT -{{- end }} - -2. Get the API URL by running these commands: -{{- if contains "NodePort" .Values.api.service.type }} - export NODE_PORT=$(kubectl get --namespace {{ .Release.Namespace }} -o jsonpath="{.spec.ports[0].nodePort}" services {{ include "hindsight.fullname" . }}-api) - export NODE_IP=$(kubectl get nodes --namespace {{ .Release.Namespace }} -o jsonpath="{.items[0].status.addresses[0].address}") - echo "API URL: http://$NODE_IP:$NODE_PORT" -{{- else if contains "LoadBalancer" .Values.api.service.type }} - NOTE: It may take a few minutes for the LoadBalancer IP to be available. - You can watch the status by running 'kubectl get --namespace {{ .Release.Namespace }} svc -w {{ include "hindsight.fullname" . }}-api' - export SERVICE_IP=$(kubectl get svc --namespace {{ .Release.Namespace }} {{ include "hindsight.fullname" . }}-api --template "{{"{{ range (index .status.loadBalancer.ingress 0) }}{{.}}{{ end }}"}}") - echo "API URL: http://$SERVICE_IP:{{ .Values.api.service.port }}" -{{- else if contains "ClusterIP" .Values.api.service.type }} - export POD_NAME=$(kubectl get pods --namespace {{ .Release.Namespace }} -l "app.kubernetes.io/component=api,app.kubernetes.io/instance={{ .Release.Name }}" -o jsonpath="{.items[0].metadata.name}") - export CONTAINER_PORT=$(kubectl get pod --namespace {{ .Release.Namespace }} $POD_NAME -o jsonpath="{.spec.containers[0].ports[0].containerPort}") - echo "API URL: http://127.0.0.1:8888" - kubectl --namespace {{ .Release.Namespace }} port-forward $POD_NAME 8888:$CONTAINER_PORT -{{- end }} - -{{- end }} - -{{- if not .Values.postgresql.enabled }} - -NOTE: You are using an external PostgreSQL database. -Please ensure that: - 1. The database is accessible from the cluster - 2. The pgvector extension is enabled - -Database migrations run automatically when the API service starts. - -If you want to pre-initialize the database before deploying (optional): - kubectl run --namespace {{ .Release.Namespace }} hindsight-init --rm -it --restart=Never \ - --image={{ .Values.api.image.repository }}:{{ .Values.api.image.tag }} \ - --env="DATABASE_URL={{ include "hindsight.databaseUrl" . }}" \ - -- python -c "from hindsight.migrations import run_migrations; run_migrations()" -{{- end }} - -For more information, visit: https://github.com/yourusername/hindsight +Hindsight installed. Access the control plane: + kubectl port-forward -n {{ .Release.Namespace }} svc/{{ include "hindsight.fullname" . }}-control-plane 3000:3000 diff --git a/helm/hindsight/templates/_helpers.tpl b/helm/hindsight/templates/_helpers.tpl index d28e1451..9b6efc8b 100644 --- a/helm/hindsight/templates/_helpers.tpl +++ b/helm/hindsight/templates/_helpers.tpl @@ -98,7 +98,7 @@ Generate database URL {{- if .Values.databaseUrl }} {{- .Values.databaseUrl }} {{- else if .Values.postgresql.enabled }} -{{- printf "postgresql://%s:%s@%s-postgresql:%d/%s" .Values.postgresql.auth.username .Values.postgresql.auth.password (include "hindsight.fullname" .) (.Values.postgresql.primary.service.port | int) .Values.postgresql.auth.database }} +{{- printf "postgresql://%s:%s@%s-postgresql:%d/%s" .Values.postgresql.auth.username .Values.postgresql.auth.password (include "hindsight.fullname" .) (.Values.postgresql.service.port | int) .Values.postgresql.auth.database }} {{- else }} {{- printf "postgresql://%s:$(POSTGRES_PASSWORD)@%s:%d/%s" .Values.postgresql.external.username .Values.postgresql.external.host (.Values.postgresql.external.port | int) .Values.postgresql.external.database }} {{- end }} diff --git a/helm/hindsight/templates/api-deployment.yaml b/helm/hindsight/templates/api-deployment.yaml index 441777c2..ad188e8d 100644 --- a/helm/hindsight/templates/api-deployment.yaml +++ b/helm/hindsight/templates/api-deployment.yaml @@ -15,7 +15,6 @@ spec: template: metadata: annotations: - checksum/config: {{ include (print $.Template.BasePath "/configmap.yaml") . | sha256sum }} checksum/secret: {{ include (print $.Template.BasePath "/secret.yaml") . | sha256sum }} {{- with .Values.podAnnotations }} {{- toYaml . | nindent 8 }} @@ -32,7 +31,7 @@ spec: - name: api securityContext: {{- toYaml .Values.securityContext | nindent 10 }} - image: "{{ .Values.api.image.repository }}:{{ .Values.api.image.tag }}" + image: "{{ .Values.api.image.repository }}:{{ .Values.api.image.tag | default .Values.version }}" imagePullPolicy: {{ .Values.api.image.pullPolicy }} ports: - name: http @@ -48,29 +47,16 @@ spec: name: {{ include "hindsight.fullname" . }}-secret key: postgres-password {{- end }} - - name: HINDSIGHT_API_LLM_PROVIDER - valueFrom: - configMapKeyRef: - name: {{ include "hindsight.fullname" . }}-config - key: llm-provider - - name: HINDSIGHT_API_LLM_MODEL - valueFrom: - configMapKeyRef: - name: {{ include "hindsight.fullname" . }}-config - key: llm-model - {{- if and .Values.api.secrets (hasKey .Values.api.secrets "HINDSIGHT_API_LLM_API_KEY") }} - - name: HINDSIGHT_API_LLM_API_KEY - valueFrom: - secretKeyRef: - name: {{ include "hindsight.fullname" . }}-secret - key: llm-api-key + {{- range $key, $value := .Values.api.env }} + - name: {{ $key }} + value: {{ $value | quote }} {{- end }} - {{- if and .Values.api.secrets (hasKey .Values.api.secrets "HINDSIGHT_API_LLM_BASE_URL") }} - - name: HINDSIGHT_API_LLM_BASE_URL + {{- range $key, $value := .Values.api.secrets }} + - name: {{ $key }} valueFrom: secretKeyRef: - name: {{ include "hindsight.fullname" . }}-secret - key: llm-base-url + name: {{ include "hindsight.fullname" $ }}-secret + key: {{ $key }} {{- end }} livenessProbe: {{- toYaml .Values.api.livenessProbe | nindent 10 }} diff --git a/helm/hindsight/templates/configmap.yaml b/helm/hindsight/templates/configmap.yaml deleted file mode 100644 index ccd20369..00000000 --- a/helm/hindsight/templates/configmap.yaml +++ /dev/null @@ -1,15 +0,0 @@ -apiVersion: v1 -kind: ConfigMap -metadata: - name: {{ include "hindsight.fullname" . }}-config - labels: - {{- include "hindsight.labels" . | nindent 4 }} -data: - # API configuration - llm-provider: {{ .Values.api.env.HINDSIGHT_API_LLM_PROVIDER | quote }} - llm-model: {{ .Values.api.env.HINDSIGHT_API_LLM_MODEL | quote }} - - # Control plane configuration - node-env: {{ .Values.controlPlane.env.NODE_ENV | quote }} - hostname: {{ .Values.controlPlane.env.HINDSIGHT_CP_HOSTNAME | quote }} - control-plane-port: {{ .Values.controlPlane.env.HINDSIGHT_CP_PORT | quote }} diff --git a/helm/hindsight/templates/controlplane-deployment.yaml b/helm/hindsight/templates/controlplane-deployment.yaml index d11616c1..1704330d 100644 --- a/helm/hindsight/templates/controlplane-deployment.yaml +++ b/helm/hindsight/templates/controlplane-deployment.yaml @@ -15,7 +15,7 @@ spec: template: metadata: annotations: - checksum/config: {{ include (print $.Template.BasePath "/configmap.yaml") . | sha256sum }} + checksum/secret: {{ include (print $.Template.BasePath "/secret.yaml") . | sha256sum }} {{- with .Values.podAnnotations }} {{- toYaml . | nindent 8 }} {{- end }} @@ -31,30 +31,26 @@ spec: - name: control-plane securityContext: {{- toYaml .Values.securityContext | nindent 10 }} - image: "{{ .Values.controlPlane.image.repository }}:{{ .Values.controlPlane.image.tag }}" + image: "{{ .Values.controlPlane.image.repository }}:{{ .Values.controlPlane.image.tag | default .Values.version }}" imagePullPolicy: {{ .Values.controlPlane.image.pullPolicy }} ports: - name: http containerPort: {{ .Values.controlPlane.service.targetPort }} protocol: TCP env: - - name: NODE_ENV - valueFrom: - configMapKeyRef: - name: {{ include "hindsight.fullname" . }}-config - key: node-env - - name: HINDSIGHT_CP_HOSTNAME - valueFrom: - configMapKeyRef: - name: {{ include "hindsight.fullname" . }}-config - key: hostname - - name: HINDSIGHT_CP_PORT - valueFrom: - configMapKeyRef: - name: {{ include "hindsight.fullname" . }}-config - key: control-plane-port - name: HINDSIGHT_CP_DATAPLANE_API_URL value: {{ include "hindsight.apiUrl" . | quote }} + {{- range $key, $value := .Values.controlPlane.env }} + - name: {{ $key }} + value: {{ $value | quote }} + {{- end }} + {{- range $key, $value := .Values.controlPlane.secrets }} + - name: {{ $key }} + valueFrom: + secretKeyRef: + name: {{ include "hindsight.fullname" $ }}-secret + key: {{ $key }} + {{- end }} livenessProbe: {{- toYaml .Values.controlPlane.livenessProbe | nindent 10 }} readinessProbe: diff --git a/helm/hindsight/templates/postgresql-service.yaml b/helm/hindsight/templates/postgresql-service.yaml new file mode 100644 index 00000000..f27d5e77 --- /dev/null +++ b/helm/hindsight/templates/postgresql-service.yaml @@ -0,0 +1,19 @@ +{{- if .Values.postgresql.enabled }} +apiVersion: v1 +kind: Service +metadata: + name: {{ include "hindsight.fullname" . }}-postgresql + labels: + {{- include "hindsight.labels" . | nindent 4 }} + app.kubernetes.io/component: postgresql +spec: + type: ClusterIP + ports: + - port: {{ .Values.postgresql.service.port }} + targetPort: postgresql + protocol: TCP + name: postgresql + selector: + {{- include "hindsight.selectorLabels" . | nindent 4 }} + app.kubernetes.io/component: postgresql +{{- end }} diff --git a/helm/hindsight/templates/postgresql-statefulset.yaml b/helm/hindsight/templates/postgresql-statefulset.yaml new file mode 100644 index 00000000..16db5286 --- /dev/null +++ b/helm/hindsight/templates/postgresql-statefulset.yaml @@ -0,0 +1,85 @@ +{{- if .Values.postgresql.enabled }} +apiVersion: apps/v1 +kind: StatefulSet +metadata: + name: {{ include "hindsight.fullname" . }}-postgresql + labels: + {{- include "hindsight.labels" . | nindent 4 }} + app.kubernetes.io/component: postgresql +spec: + serviceName: {{ include "hindsight.fullname" . }}-postgresql + replicas: 1 + selector: + matchLabels: + {{- include "hindsight.selectorLabels" . | nindent 6 }} + app.kubernetes.io/component: postgresql + template: + metadata: + labels: + {{- include "hindsight.selectorLabels" . | nindent 8 }} + app.kubernetes.io/component: postgresql + spec: + containers: + - name: postgresql + image: "{{ .Values.postgresql.image.repository }}:{{ .Values.postgresql.image.tag }}" + imagePullPolicy: {{ .Values.postgresql.image.pullPolicy }} + ports: + - name: postgresql + containerPort: 5432 + protocol: TCP + env: + - name: POSTGRES_USER + value: {{ .Values.postgresql.auth.username | quote }} + - name: POSTGRES_PASSWORD + value: {{ .Values.postgresql.auth.password | quote }} + - name: POSTGRES_DB + value: {{ .Values.postgresql.auth.database | quote }} + - name: PGDATA + value: /var/lib/postgresql/data/pgdata + livenessProbe: + exec: + command: + - pg_isready + - -U + - {{ .Values.postgresql.auth.username }} + - -d + - {{ .Values.postgresql.auth.database }} + initialDelaySeconds: 30 + periodSeconds: 10 + timeoutSeconds: 5 + failureThreshold: 3 + readinessProbe: + exec: + command: + - pg_isready + - -U + - {{ .Values.postgresql.auth.username }} + - -d + - {{ .Values.postgresql.auth.database }} + initialDelaySeconds: 5 + periodSeconds: 5 + timeoutSeconds: 3 + failureThreshold: 3 + resources: + {{- toYaml .Values.postgresql.resources | nindent 10 }} + volumeMounts: + - name: data + mountPath: /var/lib/postgresql/data + {{- if .Values.postgresql.persistence.enabled }} + volumeClaimTemplates: + - metadata: + name: data + spec: + accessModes: ["ReadWriteOnce"] + {{- if .Values.postgresql.persistence.storageClass }} + storageClassName: {{ .Values.postgresql.persistence.storageClass | quote }} + {{- end }} + resources: + requests: + storage: {{ .Values.postgresql.persistence.size }} + {{- else }} + volumes: + - name: data + emptyDir: {} + {{- end }} +{{- end }} diff --git a/helm/hindsight/templates/secret.yaml b/helm/hindsight/templates/secret.yaml index 243fe3b8..8cd6e800 100644 --- a/helm/hindsight/templates/secret.yaml +++ b/helm/hindsight/templates/secret.yaml @@ -6,14 +6,12 @@ metadata: {{- include "hindsight.labels" . | nindent 4 }} type: Opaque data: - {{- if and .Values.api.secrets (hasKey .Values.api.secrets "MEMORY_LLM_API_KEY") }} - llm-api-key: {{ .Values.api.secrets.MEMORY_LLM_API_KEY | b64enc | quote }} + {{- range $key, $value := .Values.api.secrets }} + {{ $key }}: {{ $value | b64enc | quote }} {{- end }} - {{- if and .Values.api.secrets (hasKey .Values.api.secrets "MEMORY_LLM_BASE_URL") }} - llm-base-url: {{ .Values.api.secrets.MEMORY_LLM_BASE_URL | b64enc | quote }} + {{- range $key, $value := .Values.controlPlane.secrets }} + {{ $key }}: {{ $value | b64enc | quote }} {{- end }} - {{- if not .Values.postgresql.enabled }} - {{- if .Values.postgresql.external.password }} + {{- if and (not .Values.postgresql.enabled) .Values.postgresql.external.password }} postgres-password: {{ .Values.postgresql.external.password | b64enc | quote }} {{- end }} - {{- end }} diff --git a/helm/hindsight/values.yaml b/helm/hindsight/values.yaml index 687ac84d..6a08716a 100644 --- a/helm/hindsight/values.yaml +++ b/helm/hindsight/values.yaml @@ -1,5 +1,8 @@ # Default values for hindsight +# Chart version - use this to set a consistent image tag across all components +version: "0.1.0" + # Global settings replicaCount: 1 @@ -8,9 +11,9 @@ api: enabled: true replicaCount: 1 image: - repository: hindsight/api + repository: ghcr.io/vectorize-io/hindsight-api pullPolicy: IfNotPresent - tag: "latest" + # tag defaults to .Values.version if not specified service: type: ClusterIP @@ -47,7 +50,7 @@ api: # Environment variables env: - HINDSIGHT_API_LLM_PROVIDER: "groq" + #HINDSIGHT_API_LLM_PROVIDER: "groq" HINDSIGHT_API_LLM_MODEL: "openai/gpt-oss-120b" # Secret environment variables @@ -60,9 +63,9 @@ controlPlane: enabled: true replicaCount: 1 image: - repository: hindsight/hindsight-control-plane + repository: ghcr.io/vectorize-io/hindsight-control-plane pullPolicy: IfNotPresent - tag: "latest" + # tag defaults to .Values.version if not specified service: type: ClusterIP @@ -106,21 +109,43 @@ controlPlane: # PostgreSQL configuration postgresql: # Set to true to deploy PostgreSQL as part of this chart - enabled: false + enabled: true + + image: + repository: ankane/pgvector + tag: latest + pullPolicy: IfNotPresent + + auth: + username: "hindsight" + password: "hindsight" + database: "hindsight" + + service: + port: 5432 + + persistence: + enabled: true + size: 8Gi + # storageClass: "" + + resources: + limits: + cpu: 1000m + memory: 1Gi + requests: + cpu: 250m + memory: 256Mi # External PostgreSQL connection details - # If postgresql.enabled is false, provide external database details + # Only used if postgresql.enabled is false external: host: "postgresql" port: 5432 database: "hindsight" username: "hindsight" - # Password should be provided via secret # password: "" -# Database URL (auto-generated from postgresql config if not provided) -# databaseUrl: "postgresql://user:pass@host:5432/database" - # Ingress configuration ingress: enabled: false