Categories

Versions

You are viewing the RapidMiner Hub documentation for version 10.2 - Check here for latest version

Kubernetes deployment with Helm

Following some internal experiments at RapidMiner, we have attempted to reduce the complexity of Kubernetes configuration by introducing Helm Charts, but the results are still not what you would call “plug and play”.

Nevertheless, in the interest of progress, knowing that some of our users are already experienced with Kubernetes, we have decided to release some skeletal documentation – “skeletal” in the sense that it is not complete, but perhaps adequate for experienced users who know how to fill in the gaps.

For a simpler, single-host deployment of RapidMiner AI Hub, see Docker-compose deployment or the cloud images.

We tested our example configuration with the following Kubernetes services:

To deploy RapidMiner AI Hub with Kubernetes / Helm:

All versions: [10.0.0] - [10.0.1] - [10.1.0] - [10.1.2] - [10.1.3] - [10.2.0]

Table of contents

Before you begin

To deploy the Helm chart, you need basic Kubernetes infrastructure. This documentation will not explain Kubernetes infrastructure setup. The links below are intended as hints for getting started.

  1. Create Kubernetes infrastructure.

  2. As part of your Kubernetes setup, create NFS storage with a root folder:

    whose name we recommend you set to <NAMESPACE-PLACEHOLDER>, the same as your namespace, so that you can support multiple deployments on the same cluster, with the same NFS storage -- see productNS and nfsPath in values.yaml. To enable non-root container users to read and write files in this folder that is dedicated to your RapidMiner stack, set the following permissions:

     chown -R 2011.root <NAMESPACE-PLACEHOLDER>
     chmod g+w <NAMESPACE-PLACEHOLDER>
    
  3. Create a namespace, also with name <NAMESPACE-PLACEHOLDER>.

  4. Have your server certificate ready. Alternatively, use the built-in Let's Encrypt.

Introduction to Helm

Helm is a package manager for Kubernetes. A Helm Chart bundles the Kubernetes YAML files as templates, which you then configure via the file values.yaml. The details of this configuration depend on the details of your Kubernetes deployment. You and I may share the same templates, but our configurations (values.yaml) will differ. A typical Chart is a folder resembling the following:

mychart/
  Chart.yaml
  values.yaml
  charts/
  templates/
Chart.yaml
The Chart.yaml file contains a description of the chart. You can access it from within a template.
values.yaml
The file that defines your configuration, it contains the default values for a chart. These values may be overridden during helm install or helm upgrade.
charts/
The charts/ directory may contain other charts, called subcharts.
templates/
This folder contains the Kubernetes YAML files, as templates. When Helm evaluates a chart, it will send all of the files in the templates/ directory through the template rendering engine. It then collects the results of those templates and sends them on to Kubernetes. The placeholders in the YAML files are defined by values.yaml.

Read more:

Introductory videos:

Instructions

To simplify the configuration of the Kubernetes YAML files, we use Helm, the package manager for Kubernetes.

  1. Make sure that your Kubernetes infrastructure is in place, including Helm.

  2. Download the Helm archive, and extract values.yaml, renaming it to custom-values.yaml:

     helm show values ./rapidminer-aihub-10.2.0.tgz > custom-values.yaml
    
  3. Edit custom-values.yaml and define your configuration by setting the appropriate values.

  4. Then apply the following command to the Kubernetes cluster:

helm upgrade -n <NAMESPACE-PLACEHOLDER> --install rapidminer-aihub --values custom-values.yaml ./rapidminer-aihub-10.2.0.tgz

Note that the value <NAMESPACE-PLACEHOLDER> is the same as the one you gave in custom-values.yaml for the key productNS.

EBS volumes are sensitive to multi-attach errors during rolling updates. It is best to scale down all the deployments before the update.

The HELM configuration file (values.yaml)

common:
# This value is necessary only if you plan to use the certbot client in the letsencrypt container
  domain: "<FQDN-PLACEHOLDER>"
  deploymentPort: "443"
  deploymentProtocol: "https"
# The public facing URL of your deployment
# If you need to obtain LetsEncrypt certificate first, please temporarly change the protocol to http://
  publicUrl: "https://<FQDN-PLACEHOLDER>"
# The public facing domain of your deployment's Keycloak service
  ssoDomain: "<FQDN-PLACEHOLDER>"
# The public facing URL of your deployment's Keycloak service
  ssoPublicUrl: "https://<FQDN-PLACEHOLDER>"
# The namespace of the deployment
  productNS: "<NAMESPACE-PLACEHOLDER>"
# The docker image tag
  mainVersion: "10.2.0"
# The docker image tag for Coding Environment Storage
  cesVersion: "10.2.0"
# Docker registry prefix rapidminer/ references our public docker registry, but that can be changed to the fqdn of your internal registry
  dockerURL: "rapidminer/"
# The TZ database name of the deployment's timezone, for example "America/New_York"
# See: https://en.wikipedia.org/wiki/List_of_tz_database_time_zones
  timeZone: "<TIMEZONE-PLACEHOLDER>"

##############################################################################
#                                                                            #
# Custom CA config block                                                     #
#                                                                            #
##############################################################################
  customCA:
    enabled: False
    tlsSecretName: customca

#
# DO NOT MODIFY THE PATHS
#
  jdkCACertPath: "/mnt/cacerts"
  debCertPath: "/etc/ssl/certs"
##############################################################################
#
# platform related Values, please choose one from:
# "OpenShift" : OpenShift related security and other infrastructure settings
# "EKS" : Amazon Elastic Kubernetes related security and other infrastructure settings
# 'AKS' : Azure Kubernetes related security and other infrastructure settings
# 'Other' : Other (like on-prem installations)
  platform: "EKS"
# Platform Specifications
  platformSpec:
    openshift:
      createRoute: True
# With the nodeSelectors you can instruct the kubernetes scheduer to start your pods on nodes having the provided labels.
# Any label of the worker nodes can be used, if there are no matching nodes, the pod will remain in Pending state
#  nodeSelector:
#    <NODE-LABEL-1-NAME-PLACEHOLDER>: "<NODE-LABEL-1-VALUE-PLACEHOLDER>"
#    <NODE-LABEL-2-NAME-PLACEHOLDER>: "<NODE-LABEL-2-VALUE-PLACEHOLDER>"
  nodeSelector: {}
# If not empthy, this image pull secret name will be referenced at the deployments
# creating the secret itself is out of scope of this chart, it shall be created manually
  imagePullSecret: []

# This will be the initial user, which will have admin permission in the deployment.
  initialUser: "admin"
# Initial password for the initial user
  initialPass: "<ADMIN-PASS-PLACEHOLDER>"
# The built in OIDC server realm, this realm will be used by the components in the SSO communication (KeyCloak)
  defaultSSORealm: "master"
# Default SSL requirement to access KeyCloak SSO
  ssoSSL: "external"
# Default velero backup label is not activated\
# It requires the velero is installed and managed on the Kubernates cluster
  velero:
    restic: "false"

license:
  # Possible values are 'altair_unit' and 'rapidminer'
  # Use 'altair_unit' to enable Altair Unit Licensing
  # Use 'rapidminer' to use a legacy Rapidminer license
  type: "altair_unit"
  # Configurations for 'altair_unit' license type
  altair:
    # Possible values are 'on_prem' and 'altair_one'
    # Use 'on_prem' to connect to an Altair License Manager installed on-prem
    # Use 'altair_one' to connect to public Altair One
    mode: "on_prem"
    # Configurations for 'on_prem' mode
    onPrem:
      # Altair Lincense Manager endpoint host and port
      host: "<ALTAIR-LICENSE-MANAGER-HOST-PLACEHOLDER>"
      port: "<ALTAIR-LICENSE-MANAGER-PORT-PLACEHOLDER>"
    # Configurations for 'altair_one' mode
    altairOne:
      # Authentication type for communicating with license server
      # possible values are 'credentials', 'auth_code' and 'static_token'
      authType: 'credentials'
      credentials:
        # Altair One username
        username: "<ALTAIR-ONE-USERNAME-PLACEHOLDER>"
        # Altair One password
        password: "<ALTAIR-ONE-PASSWORD-PLACEHOLDER>"
        # When mode is 'altair_one', resets any stored auth code when 'credentials' already persisted a valid auth token
        resetAuthToken: false
      staticToken:
        # License Server access token
        token: <ACCESS-TOKEN-PLACEHOLDER>
      authCode:
        code: <AUTH_CODE-PLACEHOLDER>
  # Configurations for 'rapidminer' license type
  rapidminer:
    # The value of the legacy license
    licenseValue: "<AIHUB-LICENSE-PLACEHOLDER>"
    # The name of the kubernetes secret, which contains the legacy RapidMiner License (only matters if 'enableAltairUnitLicense' is false)
    licenseSecretName: "aihub-license"
    # The key of the legacy license in the Kubernetes secret, default value is "LICENSE_LICENSE" (only matters if 'enableAltairUnitLicense' is false)
    licenseSecretKey: "LICENSE_LICENSE"

storage:
# To disable PVC creation set this to false
# (requires pre-provisioned PVCs)
  createPVCs: "true"
# Default storageclass, for one POD (single mount)
  defaultStorageClassRWO: "<STORAGECLASS-PLACEHOLDER_RWO>"
# Default storageclass, for serveral PODS (multiple mounts)
  defaultStorageClassRWX: "<STORAGECLASS-PLACEHOLDER_RWX>"

proxy:
  serviceName: "proxy-svc-pub"
# You can overwrite the Docker registry prefix rapidminer/ if you have on own repository, but that can be changed to the fqdn of your internal registry
# repoName: "<registry.example.com/> or <customedockerhubreponame/>"
  imageName: "rapidminer-proxy"
# You can overwrite the mainVersion value for this component
# version: "10.2.0"
  configName: "proxy-config"
  unprivilegedPorts: "true"
  dataUploadLimit: "10240MB"
  metrics:
    authBasic:
      user: "admin"
      password: "changit"
  https:
    crtPath: /etc/nginx/ssl/tls.crt
    keyPath: /etc/nginx/ssl/tls.key
    keyPasswordPath: /etc/nginx/ssl/password.txt
    dhPath: /etc/nginx/ssl/dhparam.pem
# You can overwrite the defaultStorageClassRBX value for this component
# dhparamStorageClass: "<STORAGECLASS-PLACEHOLDER_RWX>"
  dhparamStorageSize: "100M"
# You can overwrite the defaultStorageClassRWO value for this component
# storageClass: "<STORAGECLASS-PLACEHOLDER_RWO>"
  pvcName: "proxy-pvc"
  # initialdelayseconds + failurethreshold * (periodseconds + timeoutseconds)
  readinessprobe:
    failurethreshold: 3
    initialdelayseconds: 60
    periodseconds: 60
    timeoutseconds: 1
  storageSize: "10Gi"
  debug: "false"
  resources:
    requests:
      memory: "256M"
      cpu: "0.5"
    limits:
      memory: "256M"
      cpu: "0.5"
  securityContext:
    fsGroup: 0

letsEncrypt:
# You can overwrite the Docker registry prefix rapidminer/ if you have on own repository, but that can be changed to the fqdn of your internal registry
# repoName: "<registry.example.com/> or <customedockerhubreponame/>"
  imageName: "rm-letsencrypt-client"
# You can overwrite the mainVersion value for this component
# version: "10.2.0"
  configName: "letsencrypt-client-config"
  allowLetsEncrypt: "true"
  certsHome: "/certificates/"
  readinessprobe:
    failurethreshold: 3
    initialdelayseconds: 60
    periodseconds: 60
    timeoutseconds: 1
  webMasterEmail: "<WEBMASTER-EMAIL-PLACEHOLDER>"
  resources:
    requests:
      memory: "128M"
      cpu: "0.2"
    limits:
      memory: "128M"
      cpu: "0.2"

landingPage:
  serviceName: "landing-page-svc"
# You can overwrite the Docker registry prefix rapidminer/ if you have on own repository, but that can be changed to the fqdn of your internal registry
# repoName: "<registry.example.com/> or <customedockerhubreponame/>"
  imageName: "rapidminer-deployment-landing-page"
# You can overwrite the mainVersion value for this component
# version: "10.2.0"
  configName: "landing-page-config"
# You can overwrite the defaultstorageClass value for this component
# storageClass: "<STORAGECLASS-PLACEHOLDER_RWO>"
  pvcName: "landing-page-uploaded-pvc"
  storageSize: "100M"
  ssoClientId: "landing-page"
# keycloak client secrets can be generated with the uuidgen command from the uuid package or
# with using openssl library: echo "$(openssl rand -hex 4)-$(openssl rand -hex 2)-$(openssl rand -hex 2)-$(openssl rand -hex 2)-$(openssl rand -hex 6)"
  ssoClientSecret: "<LANDING-PAGE-OIDC-CLIENT-SECRET-PLACEHOLDER>"
  readinessprobe:
    failurethreshold: 6
    initialdelayseconds: 30
    periodseconds: 60
    timeoutseconds: 1
  debug: "false"
  resources:
    requests:
      memory: "128M"
      cpu: "0.2"
    limits:
      memory: "128M"
      cpu: "0.5"
  securityContext:
    fsGroup: 33

aihubDB:
  serviceName: "aihub-db-svc"
# You can overwrite the Docker registry prefix rapidminer/ if you have on own repository, but that can be changed to the fqdn of your internal registry
# repoName: "<registry.example.com/> or <customedockerhubreponame/>"
  imageName: "postgres-14"
# You can overwrite the mainVersion value for this component
# version: "10.2.0"
  configName: "aihub-db-config"
# You can overwrite the defaultstorageClass value for this component
# storageClass: "<STORAGECLASS-PLACEHOLDER_RWO>"
  pvcName: "aihub-db-pvc"
  storageSize: "10Gi"
  dbName: "<SERVER-DB-NAME-PLACEHOLDER>"
  dbUser: "<SERVER-DB-USER-PLACEHOLDER>"
  dbPass: "<SERVER-DB-PASS-PLACEHOLDER>"
# dataDirectory shall be mountDirectory/data
  dataDirectory: '/rapidminer/data'
  mountDirectory: '/rapidminer'
# Postgres initdb args
# The last parameter is the DB container mountPath
  initdbArgs: "--encoding UTF8 --locale=C /rapidminer/data"
  readinessprobe:
    failurethreshold: 2
    initialdelayseconds: 30
    periodseconds: 60
    timeoutseconds: 1
  resources:
    requests:
      memory: "256M"
      cpu: "0.5"
    limits:
      memory: "256M"
      cpu: "0.5"
  securityContext:
    fsGroup: 0

aihubFrontend:
  serviceName: "aihub-frontend-svc"
  # You can overwrite the Docker registry prefix rapidminer/ if you have on own repository, but that can be changed to the fqdn of your internal registry
  # repoName: "<registry.example.com/> or <customedockerhubreponame/>"
  imageName: "rapidminer-aihub-ui"
  # You can overwrite the mainVersion value for this component
  # version: "10.2.0"
  configName: "aihub-frontend-config"
  nginxPort: "1080"
  ssoClientId: "aihub-frontend"
  keycloakOnLoad: "login-required"
  readinessprobe:
    failurethreshold: 6
    initialdelayseconds: 30
    periodseconds: 60
    timeoutseconds: 1
  resources:
    requests:
      memory: "2G"
      cpu: "1"
    limits:
      memory: "2G"
      cpu: "1"
  securityContext:
    fsGroup: 0

activemq:
  serviceName: "activemq-svc"
# You can overwrite the Docker registry prefix rapidminer/ if you have on own repository, but that can be changed to the fqdn of your internal registry
# repoName: "<registry.example.com/> or <customedockerhubreponame/>"
  imageName: "rapidminer-activemq-artemis"
# You can overwrite the mainVersion value for this component
# version: "10.2.0"
  configName: "activemq-config"
  pvcName: "activemq-artemis-pvc"
  storageSize: "10Gi"
  readinessprobe:
    failurethreshold: 2
    initialdelayseconds: 20
    periodseconds: 60
    timeoutseconds: 1
  broker:
    port: 61616
    username: "<SERVER-AMQ-USER-NAME-PLACEHOLDER>"
    password: "<SERVER-AMQ-PASS-PLACEHOLDER>"
  resources:
    requests:
      memory: "4G"
      cpu: "2"
    limits:
      memory: "4G"
      cpu: "2"
  securityContext:
    fsGroup: 0

aihubBackendInit:
# You can overwrite the Docker registry prefix rapidminer/ if you have on own repository, but that can be changed to the fqdn of your internal registry
# repoName: "<registry.example.com/> or <customedockerhubreponame/>"
  imageName: "aihub-backend-init-container"
# You can overwrite the mainVersion value for this component
# version: "10.2.0"
  configName: "aihub-backend-config"
  resources:
    requests:
      memory: "256M"
      cpu: "0.5"
    limits:
      memory: "256M"
      cpu: "0.5"
  securityContext:
    fsGroup: 0

aihubBackend:
  serviceName: "aihub-backend-svc"
# You can overwrite the Docker registry prefix rapidminer/ if you have on own repository, but that can be changed to the fqdn of your internal registry
# repoName: "<registry.example.com/> or <customedockerhubreponame/>"
  imageName: "rapidminer-aihub"
# You can overwrite the mainVersion value for this component
# version: "10.2.0"
  configName: "aihub-backend-config"
# You can overwrite the defaultstorageClass value for this component
# storageClass: "<STORAGECLASS-PLACEHOLDER_RWO>"
  pvcName: "aihub-home-pvc"
  storageSize: "500Gi"
  ssoClientId: "aihub-backend"
# keycloak client secrets can be generated with the uuidgen command from the uuid package or
# with using openssl library: echo "$(openssl rand -hex 4)-$(openssl rand -hex 2)-$(openssl rand -hex 2)-$(openssl rand -hex 2)-$(openssl rand -hex 6)"
  ssoClientSecret: "<SERVER-OIDC-CLIENT-SECRET-PLACEHOLDER>"
  memLimit: "2048M"
  logLevel: "INFO"
  readinessprobe:
    failurethreshold: 2
    initialdelayseconds: 80
    periodseconds: 60
    timeoutseconds: 1
  platformAdminSyncDebug: "False"
  legacyRESTBasicAuth: "false"
  loadUserCertificates: "false"
  resources:
    requests:
      memory: "4G"
      cpu: "2"
    limits:
      memory: "4G"
      cpu: "2"
  securityContext:
    fsGroup: 0
    runAsUser: 2011

jobagent:
# You can overwrite the Docker registry prefix rapidminer/ if you have on own repository, but that can be changed to the fqdn of your internal registry
# repoName: "<registry.example.com/> or <customedockerhubreponame/>"
  imageName: "rapidminer-jobagent"
# You can overwrite the mainVersion value for this component
# version: "10.2.0"
  configName: "job-agents-config"
# You can overwrite the SC where JA store its config
# configStorageClass: "<STORAGECLASS-PLACEHOLDER_RWO>"
  homeStorageSize: "10Gi"
  homePvcName: "jobagent-home-pvc"
  name: "JOBAGENT-1" # TODO make this dynamic with the StatefulSet
  ssoClientId: "aihub-jobagent"
  ssoClientSecret: "<JOBAGENT-OIDC-CLIENT-SECRET-PLACEHOLDER>"
  logLevel: "INFO"
  jobQueue: "DEFAULT"
  containerCount: "1"
  containerMemLimit: "2048"
  initSharedCondaSettings: "true"
  containerJavaOpts: ""
  javaOpts: "-Djobagent.container.jvmCustomProperties=Dlogging.level.com.rapidminer=INFO"
  resources:
    requests:
      memory: "4G"
      cpu: "2"
    limits:
      memory: "4G"
      cpu: "2"
  securityContext:
    fsGroup: 0

keycloak:
# You can overwrite the Docker registry prefix rapidminer/ if you have on own repository, but that can be changed to the fqdn of your internal registry
# repoName: "<registry.example.com/> or <customedockerhubreponame/>"
  serviceName: "keycloak-svc"
  imageName: "rapidminer-keycloak"
# You can overwrite the mainVersion value for this component
# version: "10.2.0"
  configName: "keycloak-config"
  logLevel: "info"
  # proxyAddrForward: "true"
  features: "token-exchange,upload_scripts"
  hostname:
    strict: "false"
    strictBackchannel: "false"
    strictHttps: "false"
  proxy: "edge"
  httpEnabled: "true"
  readinessprobe:
    failurethreshold: 2
    initialdelayseconds: 35
    periodseconds: 60
    timeoutseconds: 1
  resources:
    requests:
      memory: "1G"
      cpu: "0.5"
    limits:
      memory: "1G"
      cpu: "0.5"
  securityContext:
    fsGroup: 0

keycloakDB:
# You can overwrite the Docker registry prefix rapidminer/ if you have on own repository, but that can be changed to the fqdn of your internal registry
# repoName: "<registry.example.com/> or <customedockerhubreponame/>"
  serviceName: "keycloak-db-svc"
  imageName: "postgres-14"
# You can overwrite the mainVersion value for this component
# version: "10.2.0"
  configName: "keycloak-db-config"
# You can overwrite the defaultstorageClass value for this component
# storageClass: "<STORAGECLASS-PLACEHOLDER_RWO>"
  pvcName: "keycloak-db-pvc"
  storageSize: "10Gi"
  vendor: "postgres"
  dbName: "<KEYCLOAK-DB-NAME-PLACEHOLDER>"
  dbUser: "<KEYCLOAK-DB-USER-PLACEHOLDER>"
  dbPass: "<KEYCLOAK-DB-PASS-PLACEHOLDER>"
# dataDirectory shall be mountDirectory/data
  dataDirectory: '/rapidminer/data'
  mountDirectory: '/rapidminer'
# Postgres initdb args
# The last parameter is the DB container mountPath
  initdbArgs: "--encoding UTF8 --locale=C /rapidminer/data"
  dbSchema: "public"
  readinessprobe:
    failurethreshold: 2
    initialdelayseconds: 15
    periodseconds: 60
    timeoutseconds: 1
  resources:
    requests:
      memory: "256M"
      cpu: "0.5"
    limits:
      memory: "256M"
      cpu: "0.5"
  securityContext:
    fsGroup: 0

licenseProxy:
  # You can overwrite the Docker registry prefix rapidminer/ if you have on own repository, but that can be changed to the fqdn of your internal registry
# repoName: "<registry.example.com/> or <customedockerhubreponame/>"
  serviceName: "license-proxy-svc"
  port: "9898"
  imageName: "rapidminer-licenseproxy"
# You can overwrite the mainVersion value for this component
# version: "10.2.0"
  configName: "license-proxy-config"
# You can overwrite the defaultstorageClass value for this component
# storageClass: "<STORAGECLASS-PLACEHOLDER_RWO>"
  pvcName: "license-proxy-pvc"
  storageSize: "1Gi"
  debug: "false"
  secretName: "license-proxy-secret"
  readinessprobe:
    failurethreshold: 3
    initialdelayseconds: 60
    periodseconds: 60
    timeoutseconds: 1
  resources:
    requests:
      memory: "512M"
      cpu: "0.5"
    limits:
      memory: "512M"
      cpu: "0.5"
  securityContext:
    fsGroup: 0

deploymentInit:
# You can overwrite the Docker registry prefix rapidminer/ if you have on own repository, but that can be changed to the fqdn of your internal registry
# repoName: "<registry.example.com/> or <customedockerhubreponame/>"
  imageName: "rapidminer-deployment-init"
# You can overwrite the mainVersion value for this component
# version: "10.2.0"
  configName: "deployment-init-config"
# You can overwrite the defaultstorageClass value for this component
# storageClass: "<STORAGECLASS-PLACEHOLDER_RWO>"
  pvcName: "deployment-init-pvc"
  storageSize: "100M"
  debug: "false"
  resources:
    requests:
      memory: "256M"
      cpu: "0.5"
    limits:
      memory: "256M"
      cpu: "0.5"
  securityContext:
    fsGroup: 0

platformAdmin:
# You can overwrite the Docker registry prefix rapidminer/ if you have on own repository, but that can be changed to the fqdn of your internal registry
# repoName: "<registry.example.com/> or <customedockerhubreponame/>"
  serviceName: "platform-admin-webui-svc"
  imageName: "rapidminer-platform-admin-webui"
# You can overwrite the mainVersion value for this component
# version: "10.2.0"
  configName: "platform-admin-webui-config"
# You can overwrite the defaultstorageClass value for this component
# storageClass: "<STORAGECLASS-PLACEHOLDER_RWO>"
  pvcName: "platform-admin-webui-uploaded-pvc"
  storageSize: "10Gi"
  readinessprobe:
    failurethreshold: 2
    initialdelayseconds: 10
    periodseconds: 60
    timeoutseconds: 1
  proxyURLSuffix: "/platform-admin"
  proxyRTSWebUISuffix: "/rts-admin"
  ssoClientId: "platform-admin"
# keycloak client secrets can be generated with the uuidgen command from the uuid package or
# with using openssl library: echo "$(openssl rand -hex 4)-$(openssl rand -hex 2)-$(openssl rand -hex 2)-$(openssl rand -hex 2)-$(openssl rand -hex 6)"
  ssoClientSecret: "<PLATFORM-ADMIN-OIDC-CLIENT-SECRET-PLACEHOLDER>"
  disablePython: "false"
  disableRTS: "false"
  debug: "false"
  resources:
    requests:
      memory: "256M"
      cpu: "0.5"
    limits:
      memory: "256M"
      cpu: "0.5"
  securityContext:
    fsGroup: 0

ces:
# You can overwrite the Docker registry prefix rapidminer/ if you have on own repository, but that can be changed to the fqdn of your internal registry
# repoName: "<registry.example.com/> or <customedockerhubreponame/>"
  imageName: "rapidminer-coding-environment-storage"
# You can overwrite the mainVersion value for this component
# version: "10.2.0"
  configName: "rapidminer-coding-environment-storage-config"
  pythonPackageLink: "git+https://github.com/rapidminer/python-rapidminer.git@9.10.0.0"
  pvcName: "coding-environment-storage"
  pvcSubPath: "coding-shared"
  storageSize: 250Gi
  #sharedStorageClass: "<STORAGECLASS-PLACEHOLDER_RWX>"
  ubuntuUid: "9999"
  ubuntuGid: "9999"
  debug: "False"
  disableDefaultChannels: "False"
  rapidMinerUser: "rapidminer"
  resources:
    requests:
      memory: "256M"
      cpu: "0.1"
    limits:
      memory: "5G"
      cpu: "1"
  securityContext:
    fsGroup: 0

scoringAgent:
# You can overwrite the Docker registry prefix rapidminer/ if you have on own repository, but that can be changed to the fqdn of your internal registry
# repoName: "<registry.example.com/> or <customedockerhubreponame/>"
  serviceName: "scoring-agent-svc"
  imageName: "rapidminer-scoringagent"
# This is the last version of scoring agent, please migrate to webapi
  version: "10.1.3"
  configName: "scoring-agent-config"
# You can overwrite the defaultstorageClass value for this component
# storageClass: "<STORAGECLASS-PLACEHOLDER_RWX>"
  pvcName: "scoring-home-pvc"
  storageSize: "10Gi"
  licensesPvcName: "scoring-licenses-pvc"
  ssoClientId: "aihub-scoringagent"
# keycloak client secrets can be generated with the uuidgen command from the uuid package or
# with using openssl library: echo "$(openssl rand -hex 4)-$(openssl rand -hex 2)-$(openssl rand -hex 2)-$(openssl rand -hex 2)-$(openssl rand -hex 6)"
  ssoClientSecret: "<SCORING-AGENT-OIDC-CLIENT-SECRET-PLACEHOLDER>"
  proxyURLSuffix: "/rts"
  waitForLicenses: "1"
  basicAuth:
    enabled: "true"
    user: "admin"
    password: "changeit"
  rtsServerLicense: "true"
  readinessprobe:
    failurethreshold: 6
    initialdelayseconds: 30
    periodseconds: 60
    timeoutseconds: 1
  resources:
    requests:
      memory: "1G"
      cpu: "1"
    limits:
      memory: "4G"
      cpu: "2"
  securityContext:
    fsGroup: 0

jupyterDB:
# You can overwrite the Docker registry prefix rapidminer/ if you have on own repository, but that can be changed to the fqdn of your internal registry
# repoName: "<registry.example.com/> or <customedockerhubreponame/>"
# Keep the serviceName: "jupyterhub-db" or the sample notebook content may fail to connect
  serviceName: "jupyterhub-db"
  imageName: "rapidminer-jupyterhub-postgres"
# You can overwrite the mainVersion value for this component
# version: "10.2.0"
  configName: "jupyterhub-db-config"
# You can overwrite the defaultstorageClass value for this component
# storageClass: "<STORAGECLASS-PLACEHOLDER_RWO>"
  pvcName: "jupyterhub-db-pvc"
  storageSize: "10Gi"
  vendor: "POSTGRES"
  dbName: "<JUPYTERHUB-DB-NAME-PLACEHOLDER>"
  dbUser: "<JUPYTERHUB-DB-USER-PLACEHOLDER>"
  dbPass: "<JUPYTERHUB-DB-PASS-PLACEHOLDER>"
# dataDirectory shall be mountDirectory/data
  dataDirectory: '/rapidminer/data'
  mountDirectory: '/rapidminer'
  # Postgres initdb args
  # The last parameter is the DB container mountPath
  initdbArgs: "--encoding UTF8 --locale=C /rapidminer/data"
  readinessprobe:
    failurethreshold: 2
    initialdelayseconds: 35
    periodseconds: 60
    timeoutseconds: 1
  resources:
    requests:
      memory: "256M"
      cpu: "0.5"
    limits:
      memory: "256M"
      cpu: "0.5"
  securityContext:
    fsGroup: 0

jupyterHub:
# You can overwrite the Docker registry prefix rapidminer/ if you have on own repository, but that can be changed to the fqdn of your internal registry
# repoName: "<registry.example.com/> or <customedockerhubreponame/>"
  proxyServiceName: "jupyterhub-proxy-svc-priv"
  proxyAPIServiceName: "jupyterhub-proxy-api-svc-priv"
  serviceName: "jupyterhub-hub-svc-priv"
  imageName: "rapidminer-jupyterhub-jupyterhub"
# You can overwrite the mainVersion value for this component
# version: "10.2.0"
  configName: "jupyterhub-config"
  createServiceAccount: "true"
  initRBAC: "true"
# You can overwrite the defaultstorageClass value for this component
# storageClass: "<STORAGECLASS-PLACEHOLDER_RWO>"
  proxyURLSuffix: "/jupyter"
# Jupyterhub crypt key can be generated with the command: openssl rand -hex 32
  cryptKey: "<JUPYTERHUB-CRYPT-KEY-PLACEHOLDER>"
  debug: "False"
  tokenDebug: "False"
  proxyDebug: "False"
  dbDebug: "False"
  spawnerDebug: "False"
  stackName: "default"
  ssoClientId: "jupyterhub"
# keycloak client secrets can be generated with the uuidgen command from the uuid package or
# with using openssl library: echo "$(openssl rand -hex 4)-$(openssl rand -hex 2)-$(openssl rand -hex 2)-$(openssl rand -hex 2)-$(openssl rand -hex 6)"
  ssoClientSecret: "<JUPYTERHUB-OIDC-CLIENT-SECRET-PLACEHOLDER>"
  ssoUserNameKey: "preferred_username"
  ssoResourceAccKey: "resource_access"
  spawner: "kubespawner"
  apiProtocol: "http"
  k8sCMD: "/entrypoint.sh"
  k8sArgs: "[]"
  proxyPort: "8000"
  apiPort: "8001"
  appPort: "8081"
  envVolumeName: "coding-shared-vol"
  readinessprobe:
    failurethreshold: 1
    initialdelayseconds: 35
    periodseconds: 60
    timeoutseconds: 1
  resources:
    requests:
      memory: "256M"
      cpu: "0.5"
    limits:
      memory: "256M"
      cpu: "0.5"
  securityContext:
    fsGroup: 0

jupyterNoteBook:
# You can overwrite the Docker registry prefix rapidminer/ if you have on own repository, but that can be changed to the fqdn of your internal registry
# repoName: "<registry.example.com/> or <customedockerhubreponame/>"
  imageName: "rapidminer-jupyter_notebook"
# You can overwrite the mainVersion value for this component
# version: "10.2.0"
  memLimit: "2G"
  cpuLimit: "100"
  ssoUidKey: "X_NB_UID"
  ssoGidKey: "X_NB_GID"
  ssoCustomBindMountsKey: "X_NB_CUSTOM_BIND_MOUNTS"
  customBindMounts: ""
  storageAccessMode: "ReadWriteOnce"
  storageSize: "5Gi"
# You can overwrite the defaultstorageClass value for this component
# storageClass: "<STORAGECLASS-PLACEHOLDER_RWO>"
# For kubernetes environments imagePullAtStartup shall be false
  imagePullAtStartup: "False"
#  nodeSelector:
#    key: "<NODE-LABEL-1-NAME-PLACEHOLDER>"
#    value: "<NODE-LABEL-1-VALUE-PLACEHOLDER>"
  nodeSelector: {}

grafanaProxy:
# You can overwrite the Docker registry prefix rapidminer/ if you have on own repository, but that can be changed to the fqdn of your internal registry
# repoName: "<registry.example.com/> or <customedockerhubreponame/>"
  protocol: "http"
  serviceName: "grafana-proxy-svc"
  port: "5000"
  imageName: "rapidminer-grafana-proxy"
# You can overwrite the mainVersion value for this component
# version: "10.2.0"
# Possible values: NOTSET, DEBUG, INFO, WARNING, ERROR, CRITICAL
  logLevel: "INFO"
  logResponseData: "False"
  configName: "grafana-proxy-config"
  readinessprobe:
    failurethreshold: 2
    initialdelayseconds: 15
    periodseconds: 60
    timeoutseconds: 1
  resources:
    requests:
      memory: "256M"
      cpu: "0.5"
    limits:
      memory: "256M"
      cpu: "1"
  securityContext:
    fsGroup: 0

grafanaAnonProxy:
# You can overwrite the Docker registry prefix rapidminer/ if you have on own repository, but that can be changed to the fqdn of your internal registry
# repoName: "<registry.example.com/> or <customedockerhubreponame/>"
  serviceName: "grafana-anonymous-proxy-svc"
  imageName: "rapidminer-grafana-proxy"
# You can overwrite the mainVersion value for this component
# version: "10.2.0"
# Possible values: NOTSET, DEBUG, INFO, WARNING, ERROR, CRITICAL
  logLevel: "INFO"
  logResponseData: "False"
  configName: "grafana-anonymous-proxy-config"
  readinessprobe:
    failurethreshold: 2
    initialdelayseconds: 15
    periodseconds: 60
    timeoutseconds: 1
  resources:
    requests:
      memory: "256M"
      cpu: "0.5"
    limits:
      memory: "256M"
      cpu: "1"
  securityContext:
    fsGroup: 0

grafanaInit:
# You can overwrite the Docker registry prefix rapidminer/ if you have on own repository, but that can be changed to the fqdn of your internal registry
# repoName: "<registry.example.com/> or <customedockerhubreponame/>"
  imageName: "rapidminer-grafana-init"
# You can overwrite the mainVersion value for this component
# version: "10.2.0"
  configName: "grafana-init-config"
  resources:
    requests:
      memory: "256M"
      cpu: "0.5"
    limits:
      memory: "256M"
      cpu: "0.5"
  securityContext:
    runAsUser: 472
    runAsGroup: 472
    fsGroup: 472

grafana:
# You can overwrite the Docker registry prefix rapidminer/ if you have on own repository, but that can be changed to the fqdn of your internal registry
  repoName: "grafana/"
  serviceName: "grafana-svc"
  imageName: "grafana"
# You can overwrite the mainVersion value for this component
# This is the version of the official Grafana docker image
  staticVersion: "10.0.3-ubuntu"
  configName: "grafana-config"
# You can overwrite the defaultstorageClass value for this component
# storageClass: "<STORAGECLASS-PLACEHOLDER_RWO>"
  homePvcName: "grafana-home-pvc"
  homeStorageSize: "10Gi"
  provisioningPvcName: "grafana-provisioning-pvc"
  provisioningStorageSize: "10Gi"
  readinessprobe:
    failurethreshold: 2
    initialdelayseconds: 30
    periodseconds: 60
    timeoutseconds: 1
  env:
    paths:
      data: /var/lib/grafana/aihub
      plugins: /var/lib/grafana/aihub/plugins
    auth:
      basic:
        enabled: "false"
      oauth:
        autoLogin: "true"
        enabled: "true"
        allowSignUp: "true"
        role:
          attributePath: "contains(grafana_roles[*], 'admin') && 'Admin' || contains(grafana_roles[*], 'editor') && 'Editor' || 'Viewer'"
        scopes: "email,openid"
      disableLoginForm: "true"
    server:
      serveFromSubPath: "true"
    users:
      defaultTheme: "light"
      externalManageLinkName: "false"
    panels:
      disableSanitizeHtml: "true"
    plugins:
      allowLoadingUnsignedPlugins: "rapidminer-aihub-datasource"
  proxyURLSuffix: "/grafana"
  ssoClientId: "grafana"
# keycloak client secrets can be generated with the uuidgen command from the uuid package or
# with using openssl library: echo "$(openssl rand -hex 4)-$(openssl rand -hex 2)-$(openssl rand -hex 2)-$(openssl rand -hex 2)-$(openssl rand -hex 6)"
  ssoClientSecret: "<GRAFANA-OIDC-CLIENT-SECRET-PLACEHOLDER>"
  resources:
    requests:
      memory: "256M"
      cpu: "1"
    limits:
      memory: "2048M"
      cpu: "2"
  securityContext:
    fsGroup: 0

tokenTool:
# You can overwrite the Docker registry prefix rapidminer/ if you have on own repository, but that can be changed to the fqdn of your internal registry
# repoName: "<registry.example.com/> or <customedockerhubreponame/>"
  serviceName: "token-tool-svc"
  imageName: "rapidminer-deployment-landing-page"
# You can overwrite the mainVersion value for this component
# version: "10.2.0"
  configName: "token-tool-config"
# You can overwrite the defaultstorageClass value for this component
# storageClass: "<STORAGECLASS-PLACEHOLDER_RWO>"
  pvcName: "token-tool-uploaded-pvc"
  storageSize: "100M"
  proxyURLSuffix: "/get-token"
  ssoClientId: "token-tool"
# keycloak client secrets can be generated with the uuidgen command from the uuid package or
# with using openssl library: echo "$(openssl rand -hex 4)-$(openssl rand -hex 2)-$(openssl rand -hex 2)-$(openssl rand -hex 2)-$(openssl rand -hex 6)"
  ssoClientSecret: "<TOKEN-TOOL-OIDC-CLIENT-SECRET-PLACEHOLDER>"
  ssoCustomScope: "openid offline_access"
  customContent: "get-token"
  debug: "false"
  readinessprobe:
    failurethreshold: 6
    initialdelayseconds: 30
    periodseconds: 60
    timeoutseconds: 1
  resources:
    requests:
      memory: "128M"
      cpu: "0.2"
    limits:
      memory: "128M"
      cpu: "0.5"
  securityContext:
    fsGroup: 0

webApiGateway:
  # You can overwrite the Docker registry prefix rapidminer/ if you have on own repository, but that can be changed to the fqdn of your internal registry
  # repoName: "<registry.example.com/> or <customedockerhubreponame/>"
  imageName: rapidminer-webapi-gateway
  configName: "webapi-gateway-config"
  serviceName: "webapi-gateway"
  debugEnabled: False
  resources:
    requests:
      memory: "1G"
      cpu: "1"
    limits:
      memory: "4G"
      cpu: "2"  
  readinessprobe:
    failurethreshold: 6
    initialdelayseconds: 30
    periodseconds: 60
    timeoutseconds: 1
  webapiRegistryUsername: "<WEBAPI-REGISTRY-USERNAME-PLACEHOLDER>"
  webapiRegistryPassword: "<>WEBAPI-REGISTRY-PASSWORD-PLACEHOLDER"
  securityContext:
    fsGroup: 0

webApiAgent:
# You can overwrite the Docker registry prefix rapidminer/ if you have on own repository, but that can be changed to the fqdn of your internal registry
# repoName: "<registry.example.com/> or <customedockerhubreponame/>"
  imageName: "rapidminer-scoringagent"
# You can overwrite the mainVersion value for this component
# version: "10.2.0"
  configName: "webapi-agent-config"
# You can overwrite the defaultstorageClass value for this component
# storageClass: "<STORAGECLASS-PLACEHOLDER_RWX>"
  pvcName: "webapi-agent-home-pvc"
  ssoClientId: "aihub-webapiagent"
# keycloak client secrets can be generated with the uuidgen command from the uuid package or
# with using openssl library: echo "$(openssl rand -hex 4)-$(openssl rand -hex 2)-$(openssl rand -hex 2)-$(openssl rand -hex 2)-$(openssl rand -hex 6)"
  ssoClientSecret: "<SCORING-AGENT-OIDC-CLIENT-SECRET-PLACEHOLDER>"

  storageSize: "10Gi"
  replicasNumber: "2"
  aihubConnectionProtocol: "http"
  aihubConnectionPort: "8080"
  eurekaInstanceHostname: "webapi-agents"
  eurekaInstancePreferIPAddress: "true"
  licensesPvcName: "scoring-licenses-pvc"
  debugEnabled: False
  rapidminerScoringAgentOpts: "-Xmx4g"
  readinessprobe:
    failurethreshold: 6
    initialdelayseconds: 30
    periodseconds: 60
    timeoutseconds: 1
  resources:
    requests:
      memory: "1G"
      cpu: "1"
    limits:
      memory: "5G"
      cpu: "2"
  securityContext:
    fsGroup: 0

panopticonVizapp:
  # You can overwrite the Docker registry prefix rapidminer/ if you have on own repository, but that can be changed to the fqdn of your internal registry
  # repoName: "<registry.example.com/> or <customedockerhubreponame/>"
  imageName: panopticonviz
  # You can overwrite the mainVersion value for this component
  # version: "10.2.0"
  replicas: "1"
  serviceName: "panopticon-vizapp"
  #xsmall
  catalinaOpts: "-Xms900m -Xmx1900m"
  lmxUseEpoll: '1'
  license:
    hosted: "false"
    hostedAuthorization:
      password: ""
      username: ""
      token: ""
    uri: ""
    mode: HWU
  ssoClientId: "panopticon"
# keycloak client secrets can be generated with the uuidgen command from the uuid package or
# with using openssl library: echo "$(openssl rand -hex 4)-$(openssl rand -hex 2)-$(openssl rand -hex 2)-$(openssl rand -hex 2)-$(openssl rand -hex 6)"
  ssoClientSecret: "<PANOPTICON-CLIENT-SECRET-PLACEHOLDER>"
  # You can overwrite these values:
  # storageClass: "<STORAGECLASS-PLACEHOLDER_RWX>"
  # sharedStorageClass: "<STORAGECLASS-PLACEHOLDER_RWX>"
  # pvcName:
  # sharedPvcName:
  # sharedPvcAccessMode: [ ReadWriteMany, ReadWriteOnce ]
  # diskSize: 4Gi
  # sharedDiskSize:
  resources:
    requests:
      cpu: "500m"
      memory: 1Gi
    limits:
      cpu: "1000m"
      memory: 2Gi
  securityContext:
    fsGroup: 0

panopticonVizappPython:
  # You can overwrite the Docker registry prefix rapidminer/ if you have on own repository, but that can be changed to the fqdn of your internal registry
  # repoName: "<registry.example.com/> or <customedockerhubreponame/>"
  imageName: panopticon-pythonsetup
  # You can overwrite the mainVersion value for this component
  # version: "10.2.0"
  replicas: "1"
  serviceName: "panopticon-vizapp-python"
  #xsmall
  # You can overwrite these values:
  # storageClass: "<STORAGECLASS-PLACEHOLDER_RWX>"
  # pvcName: ""
  # pvcAccessMode: [ ReadWriteMany, ReadWriteOnce ]
  # diskSize: 500Mi
  resources:
    requests:
      cpu: "100m"
      memory: 250Mi
    limits:
      cpu: "500m"
      memory: 500Mi

panopticonRserve:
  # You can overwrite the Docker registry prefix rapidminer/ if you have on own repository, but that can be changed to the fqdn of your internal registry
  # repoName: "<registry.example.com/> or <customedockerhubreponame/>"
  imageName: panopticon-rserve
  # You can overwrite the mainVersion value for this component
  # version: "10.2.0"
  replicas: "1"
  serviceName: "panopticon-rserve"
  # You can overwrite these values:
  # storageClass: "<STORAGECLASS-PLACEHOLDER_RWO>"
  # pvcName: "panopticon-rserve-pvc"
  # diskSize: 500Mi
  resources:
    requests:
      cpu: "100m"
      memory: 250Mi
    limits:
      cpu: "500m"
      memory: 500Mi 

panopticonMonetDB:
  # You can overwrite the Docker registry prefix rapidminer/ if you have on own repository, but that can be changed to the fqdn of your internal registry
  # repoName: "<registry.example.com/> or <customedockerhubreponame/>"
  imageName: panopticon-monetdb
  deploy: true
  # You can overwrite the mainVersion value for this component
  # version: "10.2.0"
  serviceName: "panopticon-monetdb"
  adminPass: "<ADMIN_PASSWORD_PLACEHOLDER>"
  # You can overwrite these values:
  # storageClass: "<STORAGECLASS-PLACEHOLDER_RWO>"
  # pvcName: "panopticon-monetdb-pvc"
  # diskSize: 4Gi

  ## Resources section is not compatible with monetdb, it complains about memory issues in the logs.
  # resources:
  #   requests:
  #     cpu: "750m"
  #     memory: 1Gi
  #   limits:
  #     cpu: "1500m"
  #     memory: 2Gi