Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions docs.json
Original file line number Diff line number Diff line change
Expand Up @@ -612,6 +612,7 @@
},
"enterprise/integrations/slack",
"enterprise/integrations/external-llm-gateways",
"enterprise/integrations/google-llm-gateway",
"enterprise/integrations/observability-platforms"
]
},
Expand Down
300 changes: 300 additions & 0 deletions enterprise/integrations/google-llm-gateway.mdx
Original file line number Diff line number Diff line change
@@ -0,0 +1,300 @@
---
title: Google LLM Gateway
description: Connect Google AI Studio and Vertex AI models through the OpenHands Enterprise LLM gateway.
icon: google
---

OpenHands Enterprise connects to Google models through its bundled LiteLLM
gateway. These configurations apply whether OpenHands runs on GKE or another
supported Kubernetes platform. The Helm examples configure Google credentials
on the bundled gateway. Replicated also provides Vertex credentials to sandbox
environments, as described below.

Choose your installation method:

- **Replicated**: configure the gateway in the Admin Console.
- **Helm**: configure the gateway through your installation values.

## Choose the Provider Route

Choose the route that matches your Google credentials:

| Route | Google Authentication | LiteLLM Model Prefix |
| --- | --- | --- |
| Google AI Studio (Gemini API) | Gemini API key | `gemini/` |
| Google Cloud Platform (Vertex AI) | Google Cloud project, location, and service account | `vertex_ai/` |

These are separate APIs, even when both serve a model named
`gemini-2.5-flash`. In Replicated, the Admin Console selects one Google API
type. A Helm installation can expose both as different gateway aliases.

## Configure the Gateway

<Tabs>
<Tab title="Replicated">

1. Open the [Admin Console LLM configuration](/enterprise/vm-install/admin-console-configuration#llm-configuration)
and select `Google` as the provider.
2. Under `Google API Type`, choose one route:
- `Google AI Studio (Gemini API)`: enter the `Google Gemini API Key` from
[Google AI Studio](https://ai.google.dev/gemini-api/docs/api-key). In
`Gemini Models`, enter one model ID per line.
- `Google Cloud Platform (Vertex AI)`: enter the `Google Cloud Project ID`
and `Google Cloud Location`, then upload the `Google Cloud Service Account
JSON file`. In `Vertex AI Models`, enter one model ID per line. Enable the
Vertex AI API in the project and grant the service account the
[Vertex AI User role](https://docs.cloud.google.com/iam/docs/roles-permissions/aiplatform)
or equivalent model-inference permissions.
3. Enter the raw model IDs, without a `gemini/` or `vertex_ai/` prefix. For
example, the Vertex field can contain:

```text
gemini-2.5-flash
gemini-2.5-pro
```

The Admin Console creates one bundled-gateway route per line, and the first
line becomes the installation default. Confirm that each model is available
to your account and, for Vertex, in your selected location.
4. Save the configuration and deploy the updated version.

The uploaded service-account file is used by the bundled gateway. Replicated
also passes its JSON contents into sandbox environments as
`VERTEXAI_CREDENTIALS`, together with the configured project and location. Scope
that service account for this deployment behavior; do not assume its credential
is available only to the gateway. Keep the file out of source control. The `Allow users to configure their own LLM providers
(BYOK)` checkbox is separate from these administrator-managed models.

</Tab>
<Tab title="Helm">

### Prerequisites

- A working [OpenHands Enterprise Helm installation](/enterprise/k8s-install/installation).
- A Google model that supports tool use and is available through your chosen
API. The examples use `gemini-2.5-flash`.
- HTTPS access from the bundled LiteLLM pod to `generativelanguage.googleapis.com`
for Gemini API, or your Vertex API endpoint and `oauth2.googleapis.com` for Vertex.
- For Vertex, a project with billing and the Vertex AI API enabled, a supported
model/location, and service-account inference permissions.
- Enough model quota for agent prompts and tool definitions.

Choose either route below, or add both to your **complete** installation
`values.yaml`. Keep your existing `litellm-helm.proxy_config.model_list`,
`environmentSecrets`, `volumes`, and `volumeMounts` entries when adding new
ones: Helm replaces lists when applying overrides. Use distinct `model_name`
aliases when both routes expose the same Google model ID.

### Google AI Studio (Gemini API)

Create a Kubernetes Secret from a private file containing your
[Gemini API key](https://ai.google.dev/gemini-api/docs/api-key):

```bash
kubectl -n openhands create secret generic google-ai-studio-gateway \
--from-file=GOOGLE_API_KEY=/path/to/private/gemini-api-key
```

Add that Secret to the gateway's existing `environmentSecrets` list and append
one route per model to `model_list`:

```yaml
litellm-helm:
environmentSecrets:
- litellm-env-secrets
- google-ai-studio-gateway
proxy_config:
model_list:
# Retain your existing model entries here.
- model_name: google-ai-studio-flash
litellm_params:
model: gemini/gemini-2.5-flash
api_key: os.environ/GOOGLE_API_KEY
```

The API key belongs to the LiteLLM gateway. It is separate from an OpenHands
API key for conversations or automations.

Check warning on line 116 in enterprise/integrations/google-llm-gateway.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai) - vale-spellcheck

enterprise/integrations/google-llm-gateway.mdx#L116

Did you really mean 'automations'?

### Google Cloud Platform (Vertex AI)

Enable Vertex AI in your Google Cloud project. Grant a dedicated service
account the `roles/aiplatform.user` role or equivalent model-inference
permissions, and confirm that `gemini-2.5-flash` is available in your chosen
location. This example uses a service-account JSON file, matching the
Replicated Admin Console path. Follow your organization's policy for
[service-account key creation and rotation](https://cloud.google.com/iam/docs/keys-create-delete).
A workstation `gcloud` login does not supply credentials to the LiteLLM pod.
Create the Secret from a private file:

```bash
kubectl -n openhands create secret generic google-vertex-gateway \
--from-file=credentials.json=/path/to/private/service-account.json
```

Mount that Secret only in the bundled LiteLLM pod. Add one gateway route per
model. Replace the project ID and location with your own:

```yaml
litellm-helm:
volumes:
# Retain any existing volumes here.
- name: google-vertex-credentials
secret:
secretName: google-vertex-gateway
volumeMounts:
# Retain any existing volume mounts here.
- name: google-vertex-credentials
mountPath: /etc/gcloud/vertex-credentials.json
subPath: credentials.json
readOnly: true
envVars:
GOOGLE_APPLICATION_CREDENTIALS: /etc/gcloud/vertex-credentials.json
proxy_config:
model_list:
# Retain your existing model entries here.
- model_name: google-vertex-flash
litellm_params:
model: vertex_ai/gemini-2.5-flash
vertex_project: <google-cloud-project-id>
vertex_location: us-central1
```

The credentials file, project, and location are used by LiteLLM to call
Vertex AI. OpenHands and its sandboxes use the gateway alias; they do not
need this file mounted into their pods.

### Apply the Updated Values

Use the licensed chart URL and version from your installation, then confirm
the bundled gateway is ready:

```bash
helm upgrade openhands "$OPENHANDS_CHART_URL" \
--namespace openhands \
--version "$OPENHANDS_CHART_VERSION" \
--values values.yaml \
--wait --timeout 10m

kubectl -n openhands rollout status deployment/openhands-litellm
```

Adjust the namespace, release name, and Deployment name if they differ in your

Check warning on line 181 in enterprise/integrations/google-llm-gateway.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai) - vale-spellcheck

enterprise/integrations/google-llm-gateway.mdx#L181

Did you really mean 'namespace'?
installation. To make one of these aliases the installation default, set
`env.LITELLM_DEFAULT_MODEL` to `litellm_proxy/<alias>` in the same values file.

</Tab>
</Tabs>

## Select the Model in OpenHands

For Replicated, select the Google models in the Admin Console and deploy the
configuration. Users do not need to open LiteLLM or enter the Google credential.

For Helm, set the desired gateway alias as the installation default in your
complete values file before upgrading. For the Vertex example:

```yaml
env:
LITELLM_DEFAULT_MODEL: litellm_proxy/google-vertex-flash
```

For the Gemini API example, use `litellm_proxy/google-ai-studio-flash` instead.
Users do not need a personal Google key to use an administrator-managed route.
Configure the provider credential through your installation's Helm values or
Admin Console; the Replicated credential distribution described above still applies.

On the tested chart `0.74.0` / OpenHands `1.67.0`, a fresh user's `Default`
profile resolved to `openhands/google-vertex-flash` with the internal gateway
base URL `http://openhands-litellm.openhands.svc.cluster.local:4000`. No user
profile override or provider key entry was required. Existing users may retain
previously selected profiles; confirm the model selected for the new conversation.

To offer both Helm aliases as administrator-managed profiles, open the
organization's **Language Model (LLM)** defaults at `/settings/org-defaults`.
Choose **Add LLM Profile → Advanced** and use the internal gateway URL:


| Field | Vertex AI | Gemini API |
| --- | --- | --- |
| Name (Optional) | `Google-Vertex-Flash` | `Google-Gemini-Flash` |
| Custom Model | `openhands/google-vertex-flash` | `openhands/google-ai-studio-flash` |
| Base URL | `http://openhands-litellm.openhands.svc.cluster.local:4000` | `http://openhands-litellm.openhands.svc.cluster.local:4000` |

OpenHands supplies the managed gateway credential, so no key entry is required.
On OpenHands `1.67.0`, saving on this page also makes the profile the
organization's active default. Re-activate the intended default after testing.

Use your actual gateway Service name and namespace. The selected model points to

Check warning on line 227 in enterprise/integrations/google-llm-gateway.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai) - vale-spellcheck

enterprise/integrations/google-llm-gateway.mdx#L227

Did you really mean 'namespace'?
the bundled gateway alias; configure its provider route through Helm values
or the Replicated Admin Console.

The Helm gateway calls Vertex AI. The sandbox calls the gateway, so this path does
not require mounting Google credentials into the sandbox or rebuilding the
agent-server image with `ENABLE_VERTEX=1`. That build flag applies when the
agent-server calls `vertex_ai/*` directly; see
[Vertex AI dependencies](/openhands/usage/llms/google-llms#vertex-ai-dependencies).

## Start Using the Model

1. Sign in and confirm the conversation UI loads without an additional backend
URL or API-key prompt. If it prompts, check the Canvas configuration in the
[Helm installation guide](/enterprise/k8s-install/installation).
2. Start a new conversation using the installation's `Default` profile.
3. Ask the agent to run `pwd`, create a small workspace file and read it back.
4. Confirm the sandbox reaches `READY`, tool results contain the expected path
and file contents, and the agent completes its response. A successful direct
gateway request alone does not validate the OpenHands conversation path.

<Note>
The Vertex route passed end-to-end tests on GKE with Helm chart `0.74.0`,
OpenHands `1.67.0`, agent-server `1.49.6-python`, and `gemini-2.5-flash` in
`us-central1`. The unmodified agent-server image ran terminal and file tools
and completed the conversation. A fresh conversation using a named organization
profile also passed terminal file operations through the OpenHands API on this
release. The organization defaults UI also saved the named Vertex profile with the
expected URL. Fresh startup for that UI-created profile remains unvalidated. On Replicated release `0.74.0`, the Admin

Check warning on line 255 in enterprise/integrations/google-llm-gateway.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai) - vale-spellcheck

enterprise/integrations/google-llm-gateway.mdx#L255

Did you really mean 'unvalidated'?
Console Vertex configuration also passed GitHub login, terminal file operations
and a read-only repository conversation. The Gemini API examples were checked
against the provider and chart configuration; they have not yet been validated
with an end-to-end conversation in this evaluation.
</Note>

## Troubleshooting

<AccordionGroup>
<Accordion title="Google AI Studio authentication error">
Check the Gemini API key in the Kubernetes Secret and confirm that it can use
the selected model. The model route must use `gemini/`, not `vertex_ai/`.
</Accordion>
<Accordion title="Vertex AI permission or credential error">
Check that Vertex AI is enabled, the service account can call the model, the
Secret contains a valid JSON file, and the LiteLLM pod mounts it at the path
in `GOOGLE_APPLICATION_CREDENTIALS`.
</Accordion>
<Accordion title="Model not found or unavailable">
Check the model ID and the Google API type. For Vertex AI, also check the
project and location. Model availability can differ between Google AI Studio
and Vertex AI and across locations.
</Accordion>
<Accordion title="The profile cannot reach the gateway">
Check the internal LiteLLM Service DNS name, namespace, and selected model alias.

Check warning on line 280 in enterprise/integrations/google-llm-gateway.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai) - vale-spellcheck

enterprise/integrations/google-llm-gateway.mdx#L280

Did you really mean 'namespace'?
Confirm the LiteLLM Deployment is ready.
</Accordion>
<Accordion title="Google `429` or repeated retries">
Check request and token quotas, billing, and model capacity for the chosen API.
A small direct completion can succeed while a larger agent prompt is rate limited.
</Accordion>
<Accordion title="Sandbox cannot start">
Check runtime registration, pod readiness and Kubernetes events using the
[Troubleshooting guide](/enterprise/troubleshooting). For GKE, verify your Sysbox

Check warning on line 289 in enterprise/integrations/google-llm-gateway.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai) - vale-spellcheck

enterprise/integrations/google-llm-gateway.mdx#L289

Did you really mean 'Sysbox'?
installation. A runtime startup failure does not by itself establish a Google
credential problem.
</Accordion>
</AccordionGroup>

For provider-specific configuration, see LiteLLM's
[Google AI Studio](https://docs.litellm.ai/docs/providers/gemini) and
[Vertex AI](https://docs.litellm.ai/docs/providers/vertex) references.

If your organization uses an existing external gateway, follow
[External LLM Gateways](/enterprise/integrations/external-llm-gateways).
3 changes: 3 additions & 0 deletions enterprise/integrations/overview.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -15,7 +15,7 @@
| -------------- | ---------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------- |
| Purpose | Purpose-built integrations for OpenHands Enterprise | Extend agent access to external systems through MCP servers |
| Data flow | Bidirectional (outbound and event-driven) | Unidirectional (outbound only) |
| Integrations | Git and ticketing providers: GitHub, GitLab, Bitbucket Cloud, Bitbucket Data Center, Azure DevOps, Jira Cloud, Jira Data Center, Slack | Large MCP catalog across multiple integration categories |

Check warning on line 18 in enterprise/integrations/overview.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai) - vale-spellcheck

enterprise/integrations/overview.mdx#L18

Did you really mean 'Jira'?

Check warning on line 18 in enterprise/integrations/overview.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai) - vale-spellcheck

enterprise/integrations/overview.mdx#L18

Did you really mean 'Jira'?
| Authentication | OAuth | OAuth or bearer token |
| Administration | Super admins enable or disable specific integrations and configure their OAuth app IDs, client IDs, and client secrets | End users manage their own MCP connections |
| Navigation | `Settings > Integrations` | `Customize > MCP Servers` |
Expand Down Expand Up @@ -55,7 +55,7 @@
Configure Bitbucket Data Center sign-in and repository webhooks.
</Card>
<Card title="Azure DevOps" icon="microsoft" href="/enterprise/integrations/azure-devops">
Connect Azure Repos and Azure Boards with Microsoft Entra ID sign-in.

Check warning on line 58 in enterprise/integrations/overview.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai) - vale-spellcheck

enterprise/integrations/overview.mdx#L58

Did you really mean 'Repos'?

Check warning on line 58 in enterprise/integrations/overview.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai) - vale-spellcheck

enterprise/integrations/overview.mdx#L58

Did you really mean 'Entra'?
</Card>
</CardGroup>

Expand All @@ -66,10 +66,10 @@

<CardGroup cols={2}>
<Card title="Jira Cloud" icon="jira" href="/enterprise/integrations/jira-cloud">
Start OpenHands from Jira Cloud issues with a mention or label.

Check warning on line 69 in enterprise/integrations/overview.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai) - vale-spellcheck

enterprise/integrations/overview.mdx#L69

Did you really mean 'Jira'?
</Card>
<Card title="Jira Data Center" icon="jira" href="/enterprise/integrations/jira-data-center">
Start OpenHands from Jira Data Center issues with a mention or label.

Check warning on line 72 in enterprise/integrations/overview.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai) - vale-spellcheck

enterprise/integrations/overview.mdx#L72

Did you really mean 'Jira'?
</Card>
</CardGroup>

Expand All @@ -91,7 +91,7 @@

<CardGroup cols={2}>
<Card title="SAML SSO" icon="user-shield" href="/enterprise/integrations/saml-sso">
Let users sign in with Okta, Microsoft Entra ID, Google Workspace, ADFS, or Authentik.

Check warning on line 94 in enterprise/integrations/overview.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai) - vale-spellcheck

enterprise/integrations/overview.mdx#L94

Did you really mean 'Okta'?

Check warning on line 94 in enterprise/integrations/overview.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai) - vale-spellcheck

enterprise/integrations/overview.mdx#L94

Did you really mean 'Entra'?

Check warning on line 94 in enterprise/integrations/overview.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai) - vale-spellcheck

enterprise/integrations/overview.mdx#L94

Did you really mean 'Authentik'?
</Card>
</CardGroup>

Expand All @@ -102,31 +102,31 @@

### Integration Coverage

- **Fetch repos**: Fetch and clone repositories (Git providers only).

Check warning on line 105 in enterprise/integrations/overview.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai) - vale-spellcheck

enterprise/integrations/overview.mdx#L105

Did you really mean 'repos'?
- **Resolver**: Use OpenHands in conversations, issues, and pull requests.
- **Auth IdP**: Sign in to OpenHands Enterprise through the integration.

| Integration | Fetch repos | Resolver | Auth IdP |

Check warning on line 109 in enterprise/integrations/overview.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai) - vale-spellcheck

enterprise/integrations/overview.mdx#L109

Did you really mean 'repos'?
| ------------------------------------------------------------------------------------------------------------ | --------------- | ------------------------------------------------------------------------------------------------------------------------- | ------------------------------ |
| [GitHub](/enterprise/integrations/github) | ✅ | ✅ | ✅ GitHub App sign-in |
| [GitLab](/enterprise/integrations/gitlab) (SaaS and self-managed) | ✅ | ✅ | ✅ |
| [Bitbucket Data Center](/enterprise/integrations/bitbucket-data-center) | ✅ | ✅ | ✅ |
| [Bitbucket Cloud](/openhands/usage/cloud/bitbucket-installation) | ✅ | ❌ | ❌ |
| [Azure DevOps](/enterprise/integrations/azure-devops) | ✅ Azure Repos | Supported, but requires an [event-based automation](/enterprise/integrations/azure-devops#trigger-openhands-from-azure-devops) | ✅ Microsoft Entra ID |

Check warning on line 115 in enterprise/integrations/overview.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai) - vale-spellcheck

enterprise/integrations/overview.mdx#L115

Did you really mean 'Repos'?

Check warning on line 115 in enterprise/integrations/overview.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai) - vale-spellcheck

enterprise/integrations/overview.mdx#L115

Did you really mean 'Entra'?
| [Jira Cloud](/enterprise/integrations/jira-cloud) | N/A | ✅ | ❌ |
| [Jira Data Center](/enterprise/integrations/jira-data-center) | N/A | ✅ | ❌ |
| [Slack](/enterprise/integrations/slack) | N/A | ✅ | N/A |
| [SAML SSO](/enterprise/integrations/saml-sso) (Okta, Entra ID, Google Workspace, ADFS, Authentik) | N/A | N/A | ✅ Recommended sign-in method |

Check warning on line 119 in enterprise/integrations/overview.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai) - vale-spellcheck

enterprise/integrations/overview.mdx#L119

Did you really mean 'Okta'?

Check warning on line 119 in enterprise/integrations/overview.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai) - vale-spellcheck

enterprise/integrations/overview.mdx#L119

Did you really mean 'Entra'?

Check warning on line 119 in enterprise/integrations/overview.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai) - vale-spellcheck

enterprise/integrations/overview.mdx#L119

Did you really mean 'Authentik'?

## MCP Server Integrations

MCP server integrations provide additional ways for users to connect external systems to OpenHands. They support
multiple server types, including SSE, streamable HTTP (SHTTP), and stdio, as well as authentication methods such as

Check warning on line 124 in enterprise/integrations/overview.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai) - vale-spellcheck

enterprise/integrations/overview.mdx#L124

Did you really mean 'streamable'?
bearer tokens and OAuth.

Examples include:

- **OAuth-enabled**: Atlassian Rovo, GitLab, Granola

Check warning on line 129 in enterprise/integrations/overview.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai) - vale-spellcheck

enterprise/integrations/overview.mdx#L129

Did you really mean 'Atlassian'?

Check warning on line 129 in enterprise/integrations/overview.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai) - vale-spellcheck

enterprise/integrations/overview.mdx#L129

Did you really mean 'Rovo'?
- **Token-enabled**: Linear, Notion

Unlike built-in integrations, MCP servers are **unidirectional**: the OpenHands agent calls the MCP server to access data,
Expand All @@ -134,13 +134,16 @@

See [MCP Settings](/openhands/usage/settings/mcp-settings) to add and configure MCP servers.

## Agentic Infrastructure

Check warning on line 137 in enterprise/integrations/overview.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai) - vale-spellcheck

enterprise/integrations/overview.mdx#L137

Did you really mean 'Agentic'?

<CardGroup cols={2}>
<Card title="External LLM Gateways" icon="network-wired" href="/enterprise/integrations/external-llm-gateways">
Route LLM traffic through your existing LiteLLM or Bifrost gateway for routing, cost tracking, and audit.
</Card>
<Card title="Google Models" icon="google" href="/enterprise/integrations/google-llm-gateway">
Connect Vertex AI and Gemini API models through the bundled gateway on Replicated or Helm.
</Card>
<Card title="External Observability Platforms" icon="chart-line" href="/enterprise/integrations/observability-platforms">
Send conversation traces to your own OTLP-compatible platform, such as Langfuse, Honeycomb, or Tempo.

Check warning on line 147 in enterprise/integrations/overview.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai) - vale-spellcheck

enterprise/integrations/overview.mdx#L147

Did you really mean 'Langfuse'?
</Card>
</CardGroup>
3 changes: 3 additions & 0 deletions enterprise/k8s-install/installation.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -33,7 +33,7 @@
`app.openhands.example.com` (application), `auth.openhands.example.com`
(login), `runtime-api.openhands.example.com`, and
`<id>-runtime.openhands.example.com` for the per-session sandboxes. Every
hostname sits one label under the base domain, so a single **wildcard**

Check warning on line 36 in enterprise/k8s-install/installation.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai) - vale-spellcheck

enterprise/k8s-install/installation.mdx#L36

Did you really mean 'hostname'?
record `*.openhands.example.com` pointing at your cluster's ingress covers
all of them; see [DNS and TLS](/enterprise/k8s-install/dns-and-tls).
- A **wildcard TLS certificate** for `*.openhands.example.com`, which you provide.
Expand All @@ -54,12 +54,12 @@
unset OH_LICENSE_ID
```

## Step 2: Create the namespaces and secrets

Check warning on line 57 in enterprise/k8s-install/installation.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai) - vale-spellcheck

enterprise/k8s-install/installation.mdx#L57

Did you really mean 'namespaces'?

We recommend running agent sandboxes in a namespace separate from the

Check warning on line 59 in enterprise/k8s-install/installation.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai) - vale-spellcheck

enterprise/k8s-install/installation.mdx#L59

Did you really mean 'namespace'?
application. Sandboxes run agent-authored code, so a dedicated namespace keeps

Check warning on line 60 in enterprise/k8s-install/installation.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai) - vale-spellcheck

enterprise/k8s-install/installation.mdx#L60

Did you really mean 'namespace'?
them isolated from the application, database, and secrets. Create both
namespaces now:

Check warning on line 62 in enterprise/k8s-install/installation.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai) - vale-spellcheck

enterprise/k8s-install/installation.mdx#L62

Did you really mean 'namespaces'?

```bash
kubectl create namespace openhands
Expand All @@ -67,7 +67,7 @@
```

The chart references several Kubernetes secrets that you create ahead of
installation, all in the `openhands` namespace:

Check warning on line 70 in enterprise/k8s-install/installation.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai) - vale-spellcheck

enterprise/k8s-install/installation.mdx#L70

Did you really mean 'namespace'?

```bash
kubectl -n openhands create secret generic jwt-secret \
Expand Down Expand Up @@ -162,7 +162,7 @@
data.
</Warning>

The example below uses Traefik, the chart's default ingress class; set

Check warning on line 165 in enterprise/k8s-install/installation.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai) - vale-spellcheck

enterprise/k8s-install/installation.mdx#L165

Did you really mean 'Traefik'?
`ingress.class` and the annotations to match your controller.

```yaml
Expand Down Expand Up @@ -312,7 +312,7 @@
```

<Tip>
The `preflight` and `support-bundle` CLIs are both part of

Check warning on line 315 in enterprise/k8s-install/installation.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai) - vale-spellcheck

enterprise/k8s-install/installation.mdx#L315

Did you really mean 'CLIs'?
[Troubleshoot](https://troubleshoot.sh/docs/#installation). Install them with:

```bash
Expand All @@ -321,7 +321,7 @@
```
</Tip>

Then confirm the application is reachable at your configured hostname and log

Check warning on line 324 in enterprise/k8s-install/installation.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai) - vale-spellcheck

enterprise/k8s-install/installation.mdx#L324

Did you really mean 'hostname'?
in. A complete first-use check goes beyond Ready pods and preflight:

1. Open `https://app.openhands.example.com` and sign in through your configured
Expand Down Expand Up @@ -358,6 +358,9 @@
<Card title="Analytics" icon="chart-line" href="/enterprise/analytics">
Enable conversation analytics with Laminar.
</Card>
<Card title="Google Models" icon="google" href="/enterprise/integrations/google-llm-gateway">
Configure Vertex AI or Gemini API routes in the bundled gateway.
</Card>
<Card title="Automations" icon="clock" href="/enterprise/k8s-install/automations">
Run scheduled or event-triggered tasks on a Helm installation.
</Card>
Expand Down
1 change: 1 addition & 0 deletions enterprise/vm-install/admin-console-configuration.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -36,14 +36,14 @@

### Recommended: Simple

Use the default `Simple` mode unless your organization requires a custom hostname for each service.

Check warning on line 39 in enterprise/vm-install/admin-console-configuration.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai) - vale-spellcheck

enterprise/vm-install/admin-console-configuration.mdx#L39

Did you really mean 'hostname'?

1. Leave `Hostname Configuration Mode` set to `Simple (default)`.
2. Enter your `Base Domain`, such as `openhands.example.com`.

Every hostname sits one subdomain under the base domain, so a single wildcard DNS record and TLS certificate for `*.openhands.example.com` cover all of them:

Check warning on line 44 in enterprise/vm-install/admin-console-configuration.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai) - vale-spellcheck

enterprise/vm-install/admin-console-configuration.mdx#L44

Did you really mean 'hostname'?

| Service | Hostname |

Check warning on line 46 in enterprise/vm-install/admin-console-configuration.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai) - vale-spellcheck

enterprise/vm-install/admin-console-configuration.mdx#L46

Did you really mean 'Hostname'?
|---|---|
| Admin Console | `admin.openhands.example.com:30000` |
| OpenHands application | `app.openhands.example.com` |
Expand All @@ -54,7 +54,7 @@
| Sandboxes | `<id>-runtime.openhands.example.com` |

<Note>
Installations created before the Simple layout run in `Legacy` mode, which nests some hostnames deeper (`auth.app.<base>`, `*.runtime.<base>`). Keep existing installs on Legacy; their certificates and OAuth callbacks were issued for those hostnames.

Check warning on line 57 in enterprise/vm-install/admin-console-configuration.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai) - vale-spellcheck

enterprise/vm-install/admin-console-configuration.mdx#L57

Did you really mean 'hostnames'?

Check warning on line 57 in enterprise/vm-install/admin-console-configuration.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai) - vale-spellcheck

enterprise/vm-install/admin-console-configuration.mdx#L57

Did you really mean 'hostnames'?
</Note>

<Accordion title="Customize every hostname">
Expand All @@ -62,19 +62,19 @@

| Field | Description |
|---|---|
| `Application Hostname` | Hostname for the OpenHands application. |

Check warning on line 65 in enterprise/vm-install/admin-console-configuration.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai) - vale-spellcheck

enterprise/vm-install/admin-console-configuration.mdx#L65

Did you really mean 'Hostname'?
| `Analytics Hostname` | Hostname for the analytics service. |

Check warning on line 66 in enterprise/vm-install/admin-console-configuration.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai) - vale-spellcheck

enterprise/vm-install/admin-console-configuration.mdx#L66

Did you really mean 'Hostname'?
| `Authentication Hostname` | Hostname for Keycloak. |

Check warning on line 67 in enterprise/vm-install/admin-console-configuration.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai) - vale-spellcheck

enterprise/vm-install/admin-console-configuration.mdx#L67

Did you really mean 'Hostname'?

Check warning on line 67 in enterprise/vm-install/admin-console-configuration.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai) - vale-spellcheck

enterprise/vm-install/admin-console-configuration.mdx#L67

Did you really mean 'Keycloak'?
| `LLM Proxy Hostname` | Hostname for the bundled LiteLLM proxy. |

Check warning on line 68 in enterprise/vm-install/admin-console-configuration.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai) - vale-spellcheck

enterprise/vm-install/admin-console-configuration.mdx#L68

Did you really mean 'Hostname'?
| `Runtime API Hostname` | Hostname for the Runtime API. |

Check warning on line 69 in enterprise/vm-install/admin-console-configuration.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai) - vale-spellcheck

enterprise/vm-install/admin-console-configuration.mdx#L69

Did you really mean 'Hostname'?
| `Runtime Base Hostname` | Base hostname used to create sandbox routes. |

Check warning on line 70 in enterprise/vm-install/admin-console-configuration.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai) - vale-spellcheck

enterprise/vm-install/admin-console-configuration.mdx#L70

Did you really mean 'hostname'?

You must create DNS records, issue certificates, and configure external OAuth and webhook callbacks for the complete custom hostname set.

Check warning on line 72 in enterprise/vm-install/admin-console-configuration.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai) - vale-spellcheck

enterprise/vm-install/admin-console-configuration.mdx#L72

Did you really mean 'hostname'?
</Accordion>

### Additional CORS Origins

`Additional Permitted CORS Origins` is optional in either hostname mode. Enter a comma-separated list of browser origins, including the scheme and host with no path or trailing slash. The OpenHands application origin is always allowed automatically.

Check warning on line 77 in enterprise/vm-install/admin-console-configuration.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai) - vale-spellcheck

enterprise/vm-install/admin-console-configuration.mdx#L77

Did you really mean 'hostname'?

## Certificate Configuration

Expand All @@ -99,7 +99,7 @@
| `Google` | Google AI Studio API key, or Vertex AI project, location, service-account file, and model IDs |
| `DeepSeek` | API key |
| `Mistral AI` | API key |
| `Azure` | Authentication method, endpoint, API version, deployment names, and either an API key or Microsoft Entra service-principal credentials |

Check warning on line 102 in enterprise/vm-install/admin-console-configuration.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai) - vale-spellcheck

enterprise/vm-install/admin-console-configuration.mdx#L102

Did you really mean 'Entra'?
| `Groq` | API key |
| `OpenRouter` | API key |
| `AWS Bedrock` | Authentication method, AWS Region, model IDs, and optionally an access-key pair |
Expand All @@ -111,6 +111,7 @@
- For AWS Bedrock, use an EC2 instance profile where possible. Pods must be able to reach the instance metadata service, and the role needs model invocation permissions.
- For custom OpenAI-compatible endpoints, prefix model names with `openai/`.
- Model lists accept one model per line.
- For Google, see [Google LLM Gateway](/enterprise/integrations/google-llm-gateway) for Vertex AI and Gemini API configuration and verification.

### Bring Your Own Key

Expand Down Expand Up @@ -142,11 +143,11 @@

### Azure DevOps Authentication

Configure the Microsoft Entra tenant, Azure DevOps organization, client ID, and client secret. See [Azure DevOps](/enterprise/integrations/azure-devops).

Check warning on line 146 in enterprise/vm-install/admin-console-configuration.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai) - vale-spellcheck

enterprise/vm-install/admin-console-configuration.mdx#L146

Did you really mean 'Entra'?

### Jira Data Center Integration

Check warning on line 148 in enterprise/vm-install/admin-console-configuration.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai) - vale-spellcheck

enterprise/vm-install/admin-console-configuration.mdx#L148

Did you really mean 'Jira'?

Configure the Jira base URL, account-linking method, and either OAuth or service-account credentials. See [Jira Data Center](/enterprise/integrations/jira-data-center).

Check warning on line 150 in enterprise/vm-install/admin-console-configuration.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai) - vale-spellcheck

enterprise/vm-install/admin-console-configuration.mdx#L150

Did you really mean 'Jira'?

### GitHub Authentication

Expand All @@ -163,7 +164,7 @@

### GitLab Authentication

Provide the GitLab host and OAuth client credentials. Leave the host at `gitlab.com` for GitLab SaaS, or enter the hostname of your self-managed GitLab instance.

Check warning on line 167 in enterprise/vm-install/admin-console-configuration.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai) - vale-spellcheck

enterprise/vm-install/admin-console-configuration.mdx#L167

Did you really mean 'hostname'?

### Slack

Expand All @@ -175,7 +176,7 @@

| Field | Description |
|---|---|
| `SMTP Host` | SMTP server hostname. |

Check warning on line 179 in enterprise/vm-install/admin-console-configuration.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai) - vale-spellcheck

enterprise/vm-install/admin-console-configuration.mdx#L179

Did you really mean 'hostname'?
| `SMTP Port` | SMTP server port. The default is `587`. |
| `SMTP From Email` | Sender address for OpenHands notifications. |
| `Use SMTP SSL` | Uses implicit TLS/SMTPS. |
Expand All @@ -195,7 +196,7 @@
- SSL mode
- Username and password
- Whether OpenHands should create databases automatically
- Database names for OpenHands, Keycloak, LiteLLM, Runtime API, and Automations

Check warning on line 199 in enterprise/vm-install/admin-console-configuration.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai) - vale-spellcheck

enterprise/vm-install/admin-console-configuration.mdx#L199

Did you really mean 'Keycloak'?

Check warning on line 199 in enterprise/vm-install/admin-console-configuration.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai) - vale-spellcheck

enterprise/vm-install/admin-console-configuration.mdx#L199

Did you really mean 'Automations'?

See [External PostgreSQL](/enterprise/external-postgres) for version, encoding, privilege, and database requirements.

Expand Down Expand Up @@ -244,7 +245,7 @@
|---|---|
| `HTTP_PROXY` | Proxy URL for HTTP traffic. |
| `HTTPS_PROXY` | Proxy URL for HTTPS traffic. |
| `NO_PROXY` | Additional comma-separated hosts that bypass the proxy. OpenHands adds internal services and configured deployment hostnames automatically. |

Check warning on line 248 in enterprise/vm-install/admin-console-configuration.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai) - vale-spellcheck

enterprise/vm-install/admin-console-configuration.mdx#L248

Did you really mean 'hostnames'?
| `SSL Verification` | Verifies outbound TLS certificates. Keep enabled unless a trusted proxy configuration requires otherwise. |

Prefer adding the proxy CA under `Additional Trusted CA Certificates` instead of disabling TLS verification.
Expand All @@ -268,11 +269,11 @@

See [Analytics](/enterprise/analytics) for the complete setup and verification flow.

## Automations

Check warning on line 272 in enterprise/vm-install/admin-console-configuration.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai) - vale-spellcheck

enterprise/vm-install/admin-console-configuration.mdx#L272

Did you really mean 'Automations'?

`Enable Automations` deploys the Automations UI and backend.

Check warning on line 274 in enterprise/vm-install/admin-console-configuration.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai) - vale-spellcheck

enterprise/vm-install/admin-console-configuration.mdx#L274

Did you really mean 'Automations'?

If you use external PostgreSQL, create and grant access to the Automations database before enabling this option.

Check warning on line 276 in enterprise/vm-install/admin-console-configuration.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai) - vale-spellcheck

enterprise/vm-install/admin-console-configuration.mdx#L276

Did you really mean 'Automations'?

## Advanced Options

Expand All @@ -290,10 +291,10 @@

## Installer-Managed Secrets

Replicated generates internal PostgreSQL, Redis, JWT, Keycloak, LiteLLM, sandbox, plugin-directory, and Automations secrets during installation. These values are intentionally hidden from the configuration screen.

Check warning on line 294 in enterprise/vm-install/admin-console-configuration.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai) - vale-spellcheck

enterprise/vm-install/admin-console-configuration.mdx#L294

Did you really mean 'Keycloak'?

Check warning on line 294 in enterprise/vm-install/admin-console-configuration.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai) - vale-spellcheck

enterprise/vm-install/admin-console-configuration.mdx#L294

Did you really mean 'Automations'?

<Warning>
Do not rotate installer-managed secrets manually unless OpenHands Support provides a component-specific procedure. In particular, changing the LiteLLM salt key makes provider credentials already stored by LiteLLM undecryptable.

Check warning on line 297 in enterprise/vm-install/admin-console-configuration.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai) - vale-spellcheck

enterprise/vm-install/admin-console-configuration.mdx#L297

Did you really mean 'undecryptable'?
</Warning>

## Related Guides
Expand Down
Loading