nora-onprem Helm chart deploys the same five services as Docker Compose onto a Kubernetes cluster. The chart lives at infra/onprem/helm/nora-onprem in the platform repo.
Install
postgres.password is the only required value on a fresh install.
Common overrides
Enable ingress and TLS
ingress.tlsSecret auto-enables NORA_COOKIE_SECURE=1 — browsers require the Secure attribute on session cookies over TLS.
Point at a private registry (air-gapped)
Load the tarball images into your own registry (see Air-gap tarball), then override each repository:Turn on the air-gap boot probe
1.1.1.1:443) is still reachable — a smoke test for the operator’s egress isolation.
Attach an offline license
/etc/nora/license.json and sets NORA_LICENSE_FILE for the server.
Switch to Qdrant for retrieval
pgvector (bundled with the Postgres pod). Flip to qdrant when you want vector search on a dedicated pod.
What the chart creates
Not in scope yet
- Multi-replica server. LLM subprocess HOME isolation hasn’t landed, so server pods run at
concurrency=1. - HPA and autoscaling. Waits on the above.
- Backup and restore jobs. Use standard Postgres tooling against the StatefulSet’s PVC.
- Cert-manager Issuer wiring. Bring your own Issuer; the chart just consumes a
Secretyou pointingress.tlsSecretat.
Upgrade
NORA_RUN_MIGRATIONS=1).
Uninstall
helm uninstall alone keeps the PVCs, so your data survives an accidental delete. Drop the namespace when you’re sure.
Related
Docker Compose
The same five services on a single host.
Air-gap tarball
Building the images you’d push into your private registry.