Introduction
The Nebari MLflow Pack deploys MLflow on a Nebari cluster: experiment tracking and a model registry behind Keycloak SSO, with a PostgreSQL backend store and TLS provisioned for you.
It wraps the community MLflow chart
and adds three things that chart cannot know about: a NebariApp for routing and auth, a
MLFLOW_SERVER_ALLOWED_HOSTS secret derived from that hostname, and defaults chosen so the
combination actually works.
browser ──► Envoy Gateway ──► MLflow ──► PostgreSQL │ svc :80 (bundled) OIDC filter pod :5000 │ Keycloak
JupyterHub notebooks ──────► MLflow (in-cluster, no auth hop) MLFLOW_TRACKING_URI svc :80Two ways in, deliberately. Humans arrive through the gateway and authenticate against Keycloak; notebooks talk to the ClusterIP service directly, bypassing the OIDC filter because the MLflow Python client has no way through it. See Connecting JupyterHub.
What ships
Section titled “What ships”- MLflow 3.7.0, served by uvicorn so the 3.x security-middleware flags are available.
- PostgreSQL 17.5 as the backend store, with an 8Gi PVC and schema migration on startup. On by default — the alternative is SQLite that loses every experiment on pod restart.
- A
NebariAppproducing an HTTPRoute, a cert-manager certificate, a Keycloak client, and an EnvoySecurityPolicyenforcing OIDC at the gateway. - An allowed-hosts Secret computed from the NebariApp hostname plus the in-cluster
service DNS name, injected via
envFrom.
Know this before you deploy
Section titled “Know this before you deploy”Two defaults surprise people, and both are covered in full below.
- Artifacts are ephemeral out of the box. The backend store is durable; the artifact store defaults to a path inside the pod’s filesystem, so logged models and files vanish on restart. See Artifact storage.
- The PostgreSQL secret must exist first, and its name must be exactly
<release-name>-postgresql. See Getting started.
In this guide
Section titled “In this guide”- Getting started — the credentials secret, install, first check
- Deploying on Nebari — the Argo CD
Application, DNS, and certificates - Connecting JupyterHub — tracking URI, the NetworkPolicy port trap, and verifying from a notebook
- Standalone deployment — running without Nebari, and locally
Guides
Section titled “Guides”- PostgreSQL backend — the secret contract, sizing, and the SQLite fallback
- Artifact storage — why the default is ephemeral, and how to point it at a bucket
- Allowed hosts — MLflow’s security middleware and the Host header
- Troubleshooting — symptoms, causes, and the commands that distinguish them
Reference
Section titled “Reference”- Configuration — every value this chart owns
- Authentication flow — the OIDC handshake, cookie format, and JWT claims
- NebariApp CRD — field-by-field reference