depend in nebari app library chart - #38
Conversation
Rendered chart comparisonGenerated using these scripts authnebariapp:
# only for main
enabled: true
# only for main
hostname: "serve.example.com"
# only for main
auth:
enabled: true
enforceAtGateway: false
serve:
enabled: true
# only for PR
hostname: "serve.example.com"
# only for PR
auth:
enabled: true
enforceAtGateway: true
dashboard:
enabled: true
hostname: "dashboard.example.com"
# only for PR
auth:
enabled: true
enforceAtGateway: falseDiff
*** /tmp/sorted1.yaml 2026-08-28 14:59:17.887851053 +0200
--- /tmp/sorted2.yaml 2026-08-28 14:59:17.911851263 +0200
***************
*** 620,639 ****
app.kubernetes.io/managed-by: Helm
app.kubernetes.io/name: nebari-rayserve-pack
app.kubernetes.io/version: 2.43.0
helm.sh/chart: nebari-rayserve-pack-0.4.1
name: release-name-nebari-rayserve-pack
spec:
auth:
enabled: true
! provider: keycloak
! provisionClient: true
! redirectURI: /oauth2/callback
! scopes:
! - openid
! - profile
! - email
gateway: public
hostname: serve.example.com
routing:
routes:
- pathPrefix: /
--- 620,634 ----
app.kubernetes.io/managed-by: Helm
app.kubernetes.io/name: nebari-rayserve-pack
app.kubernetes.io/version: 2.43.0
helm.sh/chart: nebari-rayserve-pack-0.4.1
name: release-name-nebari-rayserve-pack
+ namespace: default
spec:
auth:
enabled: true
! enforceAtGateway: true
gateway: public
hostname: serve.example.com
routing:
routes:
- pathPrefix: /
***************
*** 652,671 ****
app.kubernetes.io/managed-by: Helm
app.kubernetes.io/name: nebari-rayserve-pack
app.kubernetes.io/version: 2.43.0
helm.sh/chart: nebari-rayserve-pack-0.4.1
name: release-name-nebari-rayserve-pack-dashboard
spec:
auth:
enabled: true
! provider: keycloak
! provisionClient: true
! redirectURI: /oauth2/callback
! scopes:
! - openid
! - profile
! - email
gateway: public
hostname: dashboard.example.com
landingPage:
category: Data Science
description: Monitor and manage Ray clusters and Serve deployments
--- 647,661 ----
app.kubernetes.io/managed-by: Helm
app.kubernetes.io/name: nebari-rayserve-pack
app.kubernetes.io/version: 2.43.0
helm.sh/chart: nebari-rayserve-pack-0.4.1
name: release-name-nebari-rayserve-pack-dashboard
+ namespace: default
spec:
auth:
enabled: true
! enforceAtGateway: false
gateway: public
hostname: dashboard.example.com
landingPage:
category: Data Science
description: Monitor and manage Ray clusters and Serve deploymentsbothnebariapp:
# only for main
enabled: true
# only for main
hostname: "serve.example.com"
serve:
enabled: true
# only for PR
hostname: "serve.example.com"
dashboard:
enabled: true
hostname: "dashboard.example.com"Diff
*** /tmp/sorted1.yaml 2026-08-28 14:59:17.939851507 +0200
--- /tmp/sorted2.yaml 2026-08-28 14:59:17.963851717 +0200
***************
*** 620,629 ****
--- 620,630 ----
app.kubernetes.io/managed-by: Helm
app.kubernetes.io/name: nebari-rayserve-pack
app.kubernetes.io/version: 2.43.0
helm.sh/chart: nebari-rayserve-pack-0.4.1
name: release-name-nebari-rayserve-pack
+ namespace: default
spec:
gateway: public
hostname: serve.example.com
routing:
routes:
***************
*** 643,652 ****
--- 644,654 ----
app.kubernetes.io/managed-by: Helm
app.kubernetes.io/name: nebari-rayserve-pack
app.kubernetes.io/version: 2.43.0
helm.sh/chart: nebari-rayserve-pack-0.4.1
name: release-name-nebari-rayserve-pack-dashboard
+ namespace: default
spec:
gateway: public
hostname: dashboard.example.com
landingPage:
category: Data Sciencedashboardnebariapp:
# only for main
enabled: true
serve:
enabled: false
dashboard:
enabled: true
hostname: "dashboard.example.com"Diff
*** /tmp/sorted1.yaml 2026-08-28 14:59:17.736849733 +0200
--- /tmp/sorted2.yaml 2026-08-28 14:59:17.760849943 +0200
***************
*** 620,629 ****
--- 620,630 ----
app.kubernetes.io/managed-by: Helm
app.kubernetes.io/name: nebari-rayserve-pack
app.kubernetes.io/version: 2.43.0
helm.sh/chart: nebari-rayserve-pack-0.4.1
name: release-name-nebari-rayserve-pack-dashboard
+ namespace: default
spec:
gateway: public
hostname: dashboard.example.com
landingPage:
category: Data Sciencereal-worldnebariapp:
enabled: true
# Keep the Serve endpoint internal-only (per upstream README's
# recommendation). Notebooks access it via cluster DNS at
# rayserve-pack-nebari-rayserve-serve-svc.ray.svc.cluster.local:8000.
serve:
enabled: false
dashboard:
enabled: true
hostname: ray-dashboard.atep-dev.openteams.local
landingPage:
enabled: true
# only for PR
auth:
enabled: true
provider: keycloak
provisionClient: true
redirectURI: /oauth2/callback
# only for main
auth:
enabled: true
provider: keycloak
provisionClient: true
redirectURI: /oauth2/callbackDiff
*** /tmp/sorted1.yaml 2026-08-28 14:59:17.787850179 +0200
--- /tmp/sorted2.yaml 2026-08-28 14:59:17.811850389 +0200
***************
*** 620,639 ****
app.kubernetes.io/managed-by: Helm
app.kubernetes.io/name: nebari-rayserve-pack
app.kubernetes.io/version: 2.43.0
helm.sh/chart: nebari-rayserve-pack-0.4.1
name: release-name-nebari-rayserve-pack-dashboard
spec:
auth:
enabled: true
provider: keycloak
provisionClient: true
redirectURI: /oauth2/callback
- scopes:
- - openid
- - profile
- - email
gateway: public
hostname: ray-dashboard.atep-dev.openteams.local
landingPage:
category: Data Science
description: Monitor and manage Ray clusters and Serve deployments
--- 620,636 ----
app.kubernetes.io/managed-by: Helm
app.kubernetes.io/name: nebari-rayserve-pack
app.kubernetes.io/version: 2.43.0
helm.sh/chart: nebari-rayserve-pack-0.4.1
name: release-name-nebari-rayserve-pack-dashboard
+ namespace: default
spec:
auth:
enabled: true
provider: keycloak
provisionClient: true
redirectURI: /oauth2/callback
gateway: public
hostname: ray-dashboard.atep-dev.openteams.local
landingPage:
category: Data Science
description: Monitor and manage Ray clusters and Serve deploymentsservenebariapp:
# only for main
enabled: true
# only for main
hostname: "serve.example.com"
serve:
enabled: true
# only for PR
hostname: "serve.example.com"
dashboard:
enabled: falseDiff
*** /tmp/sorted1.yaml 2026-08-28 14:59:17.837850616 +0200
--- /tmp/sorted2.yaml 2026-08-28 14:59:17.859850808 +0200
***************
*** 620,629 ****
--- 620,630 ----
app.kubernetes.io/managed-by: Helm
app.kubernetes.io/name: nebari-rayserve-pack
app.kubernetes.io/version: 2.43.0
helm.sh/chart: nebari-rayserve-pack-0.4.1
name: release-name-nebari-rayserve-pack
+ namespace: default
spec:
gateway: public
hostname: serve.example.com
routing:
routes: |
| # Set enabled: true when deploying on a Nebari cluster. | ||
| # Creates NebariApp CRs that configure routing, TLS, and auth via nebari-operator. | ||
| nebariapp: | ||
| enabled: false |
There was a problem hiding this comment.
- Why would we not deploy this on nebari given that this is a software pack?
- Even if there is such a use case, we still have switches for the individual pieces. Meaning, the global one is just convenience to begin with.
| # Creates a NebariApp CRD that configures routing, TLS, and auth via nebari-operator. | ||
| # Set enabled: true when deploying on a Nebari cluster. | ||
| # Creates NebariApp CRs that configure routing, TLS, and auth via nebari-operator. | ||
| nebariapp: |
There was a problem hiding this comment.
This whole struct is a mix of individual and common configuration. It is certainly not obvious how it works and is not aligned with what other software packs are doing. I basically moved all common fields into the components so they are now independent from each other. This is BC breaking. I'm going to call out the individual things in my comments below.
| # Creates NebariApp CRs that configure routing, TLS, and auth via nebari-operator. | ||
| nebariapp: | ||
| enabled: false | ||
| # hostname: rayserve.nebari.example.com # Required when serve.enabled is true |
There was a problem hiding this comment.
-
No longer on the top level, but rather
serve.hostnamename -
The comment says that it is required, but the template silently skips the NebariApp CR if enabled, but no hostname is available.
rayserve-pack/chart/templates/nebariapp.yaml
Lines 1 to 2 in 0040130
With this PR the hostname is now required if enabled as the comment states.
| service: | ||
| name: "" # Defaults to <release>-<chart>-serve-svc (serve) or -head-svc (dashboard) | ||
| servePort: 8000 | ||
| dashboardPort: 8265 |
There was a problem hiding this comment.
Moved into the components with servePort becoming serve.service.port and dashboardPort becoming dashboard.service.port.
| auth: | ||
| enabled: false | ||
| provider: keycloak | ||
| provisionClient: true | ||
| redirectURI: /oauth2/callback | ||
| scopes: | ||
| - openid | ||
| - profile | ||
There was a problem hiding this comment.
Removed as auth was disabled by default. We only need to put it back if the other values besides enabled are intentionally there or if they have been copied over from somewhere and will be user defined anyway.
| - profile | ||
|
|
||
| gateway: public |
There was a problem hiding this comment.
Moved into the components.
| routing: | ||
| routes: | ||
| - pathPrefix: / | ||
| pathType: PathPrefix |
There was a problem hiding this comment.
This block was hardcoded here and was moved into the values.
| The RayService controller manages the Ray cluster and Serve proxy. | ||
| Serve is pre-initialized with host 0.0.0.0 on port 8000. | ||
|
|
||
| {{- if .Values.nebariapp.enabled }} |
There was a problem hiding this comment.
Flag for myself: reinstate.
There was a problem hiding this comment.
I removed some of the tests as they don't provide much value. They only check if templating works and not what is produced.
There was a problem hiding this comment.
As mentioned in another comment, I'm questioning if we should have this workflow at all. Are we expecting this to be deployed anywhere but nebari?
| @@ -1,6 +1,5 @@ | |||
| # Helm | |||
| chart/charts/ | |||
| chart/Chart.lock | |||
There was a problem hiding this comment.
Not sure why we ignored the lock file. It is important for a reproducible deployment.
| appVersion: "2.43.0" | ||
| dependencies: | ||
| - name: nebari-app | ||
| repository: oci://quay.io/reiemp/charts |
Reference Issues or PRs
Fixes #13.
What does this implement/fix?
Put a
xin the boxes that applyTesting
Documentation
Access-centered content checklist
Text styling
H1or#in markdown).Non-text content
Any other comments?