Skip to main content
The nora-onprem Helm chart deploys the same five services as Docker Compose onto a Kubernetes cluster. The chart lives at infra/onprem/helm/nora-onprem in the platform repo.

Install

postgres.password is the only required value on a fresh install.
The chart provisions Deployments, StatefulSets, and Services under the release name. See What the chart creates for the exact resource list.

Common overrides

Enable ingress and TLS

Setting ingress.tlsSecret auto-enables NORA_COOKIE_SECURE=1 — browsers require the Secure attribute on session cookies over TLS.

Point at a private registry (air-gapped)

Load the tarball images into your own registry (see Air-gap tarball), then override each repository:

Turn on the air-gap boot probe

The server exits with code 78 at boot if the probe target (default 1.1.1.1:443) is still reachable — a smoke test for the operator’s egress isolation.

Attach an offline license

The chart mounts the secret at /etc/nora/license.json and sets NORA_LICENSE_FILE for the server.

Switch to Qdrant for retrieval

The default is pgvector (bundled with the Postgres pod). Flip to qdrant when you want vector search on a dedicated pod.

What the chart creates

Not in scope yet

  • Multi-replica server. LLM subprocess HOME isolation hasn’t landed, so server pods run at concurrency=1.
  • HPA and autoscaling. Waits on the above.
  • Backup and restore jobs. Use standard Postgres tooling against the StatefulSet’s PVC.
  • Cert-manager Issuer wiring. Bring your own Issuer; the chart just consumes a Secret you point ingress.tlsSecret at.

Upgrade

Migrations run automatically on the first new server pod (NORA_RUN_MIGRATIONS=1).
Migrations are additive-only. Pin a matching database snapshot before downgrading across a schema advance.

Uninstall

helm uninstall alone keeps the PVCs, so your data survives an accidental delete. Drop the namespace when you’re sure.

Docker Compose

The same five services on a single host.

Air-gap tarball

Building the images you’d push into your private registry.