This commit is contained in:
alessandro barucci
2026-09-20 19:26:05 +02:00
parent 48f3f1ff22
commit 63649a642a
11 changed files with 578 additions and 45 deletions
@@ -0,0 +1,7 @@
# crea secret con langflow-secrets-setup.sh
# Poi installa con i valori personalizzati
helm install langflow-ide langflow/langflow-ide \
-f langflow-values.yaml \
-n langflow-team-alpha --create-namespace
@@ -0,0 +1,61 @@
# HTTPRoute (Gateway API) per Langflow IDE
# Presuppone un Gateway nginx già esistente nel cluster (nginx Gateway
# Fabric), referenziato come parentRef qui sotto.
apiVersion: gateway.networking.k8s.io/v1
kind: HTTPRoute
metadata:
name: langflow-team-alpha
namespace: langflow-team-alpha
spec:
parentRefs:
- name: nginx-gateway # nome del Gateway condiviso — verifica con:
namespace: nginx-gateway # kubectl get gateway -A
sectionName: https # nome del listener HTTPS sul Gateway
hostnames:
- "langflow-team-alpha.pigreco66.it"
rules:
# UI/editor visuale (frontend) — porta 8080 come da doc Langflow
- matches:
- path:
type: PathPrefix
value: /
backendRefs:
- name: langflow-ide-frontend # verifica nome esatto: kubectl get svc -n langflow-team-alpha
port: 8080
# API backend, se vuoi esporla separatamente (es. per invocazione
# programmatica di un flow senza passare dall'editor) — porta 7860
- matches:
- path:
type: PathPrefix
value: /api
backendRefs:
- name: langflow-ide-backend # verifica nome esatto: kubectl get svc -n langflow-team-alpha
port: 7860
---
# TLS: con Gateway API il certificato si referenzia sul Gateway stesso
# (non sull'HTTPRoute). Se il Gateway condiviso non ha già un listener
# per questo hostname, serve aggiungerlo lì, es.:
#
# apiVersion: gateway.networking.k8s.io/v1
# kind: Gateway
# metadata:
# name: nginx-gateway
# namespace: nginx-gateway
# spec:
# gatewayClassName: nginx
# listeners:
# - name: https
# protocol: HTTPS
# port: 443
# hostname: "*.pigreco66.it"
# tls:
# mode: Terminate
# certificateRefs:
# - name: wildcard-pigreco66-it-tls
# allowedRoutes:
# namespaces:
# from: All
@@ -0,0 +1,35 @@
# Creazione dei Secret richiesti da langflow-values.yaml
# Namespace di esempio: langflow-team-alpha (adatta al tuo tenant)
# 1. Secret connessione database Postgres
kubectl create secret generic langflow-db-secret \
-n langflow-team-alpha \
--from-literal=connection-string="postgresql://user:pass@host:5432/langflow"
# 2. Secret credenziali admin (superuser Langflow)
kubectl create secret generic langflow-admin-secret \
-n langflow-team-alpha \
--from-literal=username="admin" \
--from-literal=password="<password-sicura>"
# 3. Secret credenziali LLM — STESSO Secret già usato per kagent nel
# golden path di onboarding-team: se lo hai già creato per kagent
# in questo namespace, questo passaggio è già fatto, verifica solo
# che contenga le chiavi coi nomi attesi (vedi sotto).
#
# Se non esiste ancora, crealo così (aggiungi/rimuovi provider a
# seconda di cosa serve al team):
kubectl create secret generic llm-credentials \
-n langflow-team-alpha \
--from-literal=openai-api-key="sk-..." \
--from-literal=anthropic-api-key="sk-ant-..."
# Se il Secret esiste già (es. creato per kagent) e vuoi solo
# aggiungere/aggiornare una chiave senza ricrearlo da zero:
kubectl patch secret llm-credentials -n langflow-team-alpha \
--type=json \
-p='[{"op":"add","path":"/data/openai-api-key","value":"'$(echo -n "sk-..." | base64)'"}]'
# 4. Verifica che tutti i Secret siano presenti prima di installare/
# aggiornare la release Helm
kubectl get secrets -n langflow-team-alpha
@@ -0,0 +1,87 @@
# values.yaml — Langflow IDE, personalizzato per un namespace-tenant
# Uso: helm install langflow-ide langflow/langflow-ide -f values.yaml -n <namespace>
langflow:
backend:
image:
repository: langflowai/langflow
tag: "1.10.0" # fissa una versione esplicita, evita 'latest' in produzione
resources:
requests:
cpu: 250m
memory: 512Mi
limits:
cpu: "1"
memory: 2Gi
# Variabili LLM/DB — usa Secret, mai valori in chiaro qui
env:
- name: LANGFLOW_DATABASE_URL
valueFrom:
secretKeyRef:
name: langflow-db-secret
key: connection-string
- name: LANGFLOW_SUPERUSER
valueFrom:
secretKeyRef:
name: langflow-admin-secret
key: username
- name: LANGFLOW_SUPERUSER_PASSWORD
valueFrom:
secretKeyRef:
name: langflow-admin-secret
key: password
# Rimuove automaticamente eventuali API key salvate nei flow prima
# di persisterli a DB — best practice di sicurezza, seconda linea
# di difesa oltre alle Global Variable qui sotto
- name: LANGFLOW_REMOVE_API_KEYS
value: "true"
# --- Pre-caricamento credenziali LLM come Global Variable ---
# Riusa lo stesso Secret 'llm-credentials' già previsto per kagent
# in fase di onboarding del team (vedi golden path Backstage).
# I developer trovano le chiavi già pronte nel dropdown Global
# Variable, senza mai vederne il valore reale.
- name: LANGFLOW_STORE_ENVIRONMENT_VARIABLES
value: "true"
- name: LANGFLOW_VARIABLES_TO_GET_FROM_ENVIRONMENT
value: "OPENAI_API_KEY,ANTHROPIC_API_KEY"
- name: OPENAI_API_KEY
valueFrom:
secretKeyRef:
name: llm-credentials
key: openai-api-key
optional: true # non tutti i team useranno tutti i provider
- name: ANTHROPIC_API_KEY
valueFrom:
secretKeyRef:
name: llm-credentials
key: anthropic-api-key
optional: true
frontend:
image:
repository: langflowai/langflow
tag: "1.10.0"
resources:
requests:
cpu: 100m
memory: 256Mi
limits:
cpu: 500m
memory: 512Mi
# Ingress classico DISABILITATO — l'esposizione avviene via Gateway API
# (nginx Gateway Fabric), vedi manifest separato langflow-httproute.yaml
ingress:
enabled: false
# Il Service del frontend resta ClusterIP (default del chart), sarà
# l'HTTPRoute a instradare il traffico dal Gateway verso questo Service
# Persistenza dei flow salvati (altrimenti persi al riavvio del pod)
persistence:
enabled: true
size: 5Gi
storageClassName: standard # adatta alla tua StorageClass