diff --git a/charts/infrastructure/templates/open-webui.yaml b/charts/infrastructure/templates/open-webui.yaml new file mode 100644 index 00000000..f3ca6d50 --- /dev/null +++ b/charts/infrastructure/templates/open-webui.yaml @@ -0,0 +1,71 @@ +apiVersion: argoproj.io/v1alpha1 +kind: Application +metadata: + name: open-webui + namespace: argocd + finalizers: + - resources-finalizer.argocd.argoproj.io +spec: + destination: + name: '' + namespace: open-webui + server: 'https://kubernetes.default.svc' + source: + path: charts/open-webui + repoURL: 'https://gitlab.com/deepcypher/dc-kc.git' + targetRevision: HEAD + #helm: + # values: | + #project: open-webui + project: default + syncPolicy: + automated: + prune: true + selfHeal: true + syncOptions: + - CreateNamespace=true + - ApplyOutOfSyncOnly=true +--- +apiVersion: argoproj.io/v1alpha1 +kind: AppProject +metadata: + name: open-webui + namespace: argocd + # Finalizer that ensures that project is not deleted until it is not referenced by any application + finalizers: + - resources-finalizer.argocd.argoproj.io +spec: + description: Infra-level project to isolate open-webui + # Allow manifests to deploy from any Git repos + sourceRepos: + - '*' + # Only permit applications to deploy to the guestbook namespace in the same cluster + destinations: + - namespace: open-webui + server: https://kubernetes.default.svc + # Deny all cluster-scoped resources from being created, except for Namespace + clusterResourceWhitelist: + - group: '' + kind: Namespace + # Allow all namespaced-scoped resources to be created, except for ResourceQuota, LimitRange, NetworkPolicy + namespaceResourceBlacklist: + - group: '' + kind: ResourceQuota + - group: '' + kind: LimitRange + #- group: '' + # kind: NetworkPolicy + # # Deny all namespaced-scoped resources from being created, except for Deployment and StatefulSet + # namespaceResourceWhitelist: + # - group: 'apps' + # kind: Deployment + # - group: 'apps' + # kind: StatefulSet + roles: + # A role which provides read-only access to all applications in the project + - name: read-only + description: Read-only privileges to open-webui + policies: + - p, proj:my-project:read-only, applications, get, open-webui/*, allow + groups: + - my-oidc-group diff --git a/charts/open-webui/.helmignore b/charts/open-webui/.helmignore new file mode 100644 index 00000000..0e8a0eb3 --- /dev/null +++ b/charts/open-webui/.helmignore @@ -0,0 +1,23 @@ +# Patterns to ignore when building packages. +# This supports shell glob matching, relative path matching, and +# negation (prefixed with !). Only one pattern per line. +.DS_Store +# Common VCS dirs +.git/ +.gitignore +.bzr/ +.bzrignore +.hg/ +.hgignore +.svn/ +# Common backup files +*.swp +*.bak +*.tmp +*.orig +*~ +# Various IDEs +.project +.idea/ +*.tmproj +.vscode/ diff --git a/charts/open-webui/Chart.yaml b/charts/open-webui/Chart.yaml new file mode 100644 index 00000000..2a8702d7 --- /dev/null +++ b/charts/open-webui/Chart.yaml @@ -0,0 +1,29 @@ +apiVersion: v2 +name: alloy +description: A Helm chart for Kubernetes + +# A chart can be either an 'application' or a 'library' chart. +# +# Application charts are a collection of templates that can be packaged into versioned archives +# to be deployed. +# +# Library charts provide useful utilities or functions for the chart developer. They're included as +# a dependency of application charts to inject those utilities and functions into the rendering +# pipeline. Library charts do not define any templates and therefore cannot be deployed. +type: application + +# This is the chart version. This version number should be incremented each time you make changes +# to the chart and its templates, including the app version. +# Versions are expected to follow Semantic Versioning (https://semver.org/) +version: 0.1.0 + +# This is the version number of the application being deployed. This version number should be +# incremented each time you make changes to the application. Versions are not expected to +# follow Semantic Versioning. They should reflect the version the application is using. +# It is recommended to use it with quotes. +appVersion: "4" + +dependencies: +- name: open-webui + version: 0.1.0 + repository: "https://gitlab.com/api/v4/projects/55284972/packages/helm/stable" diff --git a/charts/open-webui/values.yaml b/charts/open-webui/values.yaml new file mode 100644 index 00000000..aac5cfd6 --- /dev/null +++ b/charts/open-webui/values.yaml @@ -0,0 +1,10 @@ +open-webui: + persistence: + enabled: true + size: 50Gi + env: + - name: OLLAMA_BASE_URL + value: "http://ollama.ollama:11434" + netpol: + enabled: false +