varie
This commit is contained in:
@@ -0,0 +1,87 @@
|
||||
# values.yaml — Langflow IDE, personalizzato per un namespace-tenant
|
||||
# Uso: helm install langflow-ide langflow/langflow-ide -f values.yaml -n <namespace>
|
||||
|
||||
langflow:
|
||||
backend:
|
||||
image:
|
||||
repository: langflowai/langflow
|
||||
tag: "1.10.0" # fissa una versione esplicita, evita 'latest' in produzione
|
||||
|
||||
resources:
|
||||
requests:
|
||||
cpu: 250m
|
||||
memory: 512Mi
|
||||
limits:
|
||||
cpu: "1"
|
||||
memory: 2Gi
|
||||
|
||||
# Variabili LLM/DB — usa Secret, mai valori in chiaro qui
|
||||
env:
|
||||
- name: LANGFLOW_DATABASE_URL
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: langflow-db-secret
|
||||
key: connection-string
|
||||
- name: LANGFLOW_SUPERUSER
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: langflow-admin-secret
|
||||
key: username
|
||||
- name: LANGFLOW_SUPERUSER_PASSWORD
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: langflow-admin-secret
|
||||
key: password
|
||||
# Rimuove automaticamente eventuali API key salvate nei flow prima
|
||||
# di persisterli a DB — best practice di sicurezza, seconda linea
|
||||
# di difesa oltre alle Global Variable qui sotto
|
||||
- name: LANGFLOW_REMOVE_API_KEYS
|
||||
value: "true"
|
||||
|
||||
# --- Pre-caricamento credenziali LLM come Global Variable ---
|
||||
# Riusa lo stesso Secret 'llm-credentials' già previsto per kagent
|
||||
# in fase di onboarding del team (vedi golden path Backstage).
|
||||
# I developer trovano le chiavi già pronte nel dropdown Global
|
||||
# Variable, senza mai vederne il valore reale.
|
||||
- name: LANGFLOW_STORE_ENVIRONMENT_VARIABLES
|
||||
value: "true"
|
||||
- name: LANGFLOW_VARIABLES_TO_GET_FROM_ENVIRONMENT
|
||||
value: "OPENAI_API_KEY,ANTHROPIC_API_KEY"
|
||||
- name: OPENAI_API_KEY
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: llm-credentials
|
||||
key: openai-api-key
|
||||
optional: true # non tutti i team useranno tutti i provider
|
||||
- name: ANTHROPIC_API_KEY
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: llm-credentials
|
||||
key: anthropic-api-key
|
||||
optional: true
|
||||
|
||||
frontend:
|
||||
image:
|
||||
repository: langflowai/langflow
|
||||
tag: "1.10.0"
|
||||
resources:
|
||||
requests:
|
||||
cpu: 100m
|
||||
memory: 256Mi
|
||||
limits:
|
||||
cpu: 500m
|
||||
memory: 512Mi
|
||||
|
||||
# Ingress classico DISABILITATO — l'esposizione avviene via Gateway API
|
||||
# (nginx Gateway Fabric), vedi manifest separato langflow-httproute.yaml
|
||||
ingress:
|
||||
enabled: false
|
||||
|
||||
# Il Service del frontend resta ClusterIP (default del chart), sarà
|
||||
# l'HTTPRoute a instradare il traffico dal Gateway verso questo Service
|
||||
|
||||
# Persistenza dei flow salvati (altrimenti persi al riavvio del pod)
|
||||
persistence:
|
||||
enabled: true
|
||||
size: 5Gi
|
||||
storageClassName: standard # adatta alla tua StorageClass
|
||||
Reference in New Issue
Block a user