Skip to content

Configuration

Updated 3 min read

The chart owns three value trees — nebariapp, security, and the name overrides — and passes everything under mlflow to the community MLflow chart (version 1.8.1).

KeyOwner
nebariapp.*this chart
security.*this chart
nameOverride, fullnameOverridethis chart
mlflow.*the mlflow subchart
ValueDefaultPurpose
nebariapp.enabledtrueRender the NebariApp. False for standalone.
nebariapp.hostname—Required when enabled. External hostname.
nebariapp.keycloakHostname—Unused — see the note below.
nebariapp.keycloakRealmnebariUnused — see the note below.
nebariapp.service.name<release>Backend service — see the note below.
nebariapp.service.port80Backend port (container port is 5000).
nebariapp.routing.routes[{pathPrefix: /}]MLflow owns the whole host.
ValueDefaultPurpose
auth.enabledtrueProvision a Keycloak client and enforce OIDC.
auth.providerkeycloakIdentity provider.
auth.provisionClienttrueLet the operator create the client. False + clientSecretRef to bring your own.
auth.enforceAtGatewaytrueEnvoy enforces OIDC in front of MLflow.
auth.redirectURI/oauth2/callbackWhere Keycloak sends the authorization code.
auth.scopesopenid, profile, email, groupsRequested scopes.
auth.groupsunsetGroups created in Keycloak; restricts access when set.
auth.keycloakConfigunsetGroup membership and protocol mappers.

enforceAtGateway: true is right for MLflow — it has no OIDC support of its own, so the gateway does the whole handshake and MLflow sees an already-authenticated request. (Compare lgtm-pack, where Grafana runs its own flow and gateway enforcement is off.)

The full handshake, cookie names, and JWT claims are in Authentication flow.

Not present in values.yaml, so no tile by default. The template passes through enabled, displayName, description, icon, category, priority, externalUrl, and healthCheck if you add it. (The CRD also has iconLight, iconDark, and healthCheck.port; this chart’s template drops those.)

nebariapp:
landingPage:
enabled: true
displayName: MLflow
description: Experiment tracking and model registry
category: "Machine Learning"
healthCheck:
enabled: true
path: /health

Field semantics are in the NebariApp CRD reference.

ValueDefaultPurpose
security.additionalAllowedHosts[]Extra entries for MLFLOW_SERVER_ALLOWED_HOSTS.

The NebariApp hostname and the in-cluster service DNS name are added automatically. See Allowed hosts.

Defaults worth understanding before you override them.

ValueSet toWhy
mlflow.image.tag3.7.0Pinned to the chart’s appVersion.
mlflow.service.typeClusterIPRouting is the NebariApp’s job.
mlflow.log.enabledfalseKeeps the server on uvicorn. Gunicorn cannot accept MLflow 3.x’s security-middleware flags — see Allowed hosts.
mlflow.extraSecretNamesForEnvFrom[nebari-mlflow-allowed-hosts]Injects the computed host list.
mlflow.backendStore.databaseMigrationtrueMigrates the schema at startup.
mlflow.backendStore.databaseConnectionChecktrueWaits for PostgreSQL before starting.
mlflow.postgresql.enabledtrueThe default alternative is SQLite that loses everything on restart.
mlflow.postgresql.image.tag17.5.0Bundled PostgreSQL.
mlflow.postgresql.auth.username / .databasemlflow—
mlflow.postgresql.primary.persistenceenabled, 8GiMetadata only; models live in the artifact store.
ValueDefaultPurpose
nameOverride""Overrides the chart name in labels and helpers.
fullnameOverride""Overrides the full name.

Both change the NebariApp name, not the MLflow service name — the service comes from the subchart’s own helper. If you set either, re-check that nebariapp.service.name still points at a service that exists.

nebariapp:
hostname: mlflow.example.com
auth:
groups: [data-science-team]
mlflow:
postgresql:
auth:
existingSecret: mlflow-pack-postgresql
primary:
persistence:
size: 20Gi
storageClass: fast-ssd
artifactRoot:
proxiedArtifactStorage: true
s3:
enabled: true
bucket: my-mlflow-artifacts
existingSecret:
name: mlflow-s3-credentials
keyOfAccessKeyId: AWS_ACCESS_KEY_ID
keyOfSecretAccessKey: AWS_SECRET_ACCESS_KEY
resources:
requests: { cpu: 250m, memory: 512Mi }
limits: { memory: 2Gi }
Terminal window
helm template mlflow-pack . --set nebariapp.hostname=mlflow.example.com | less
helm -n mlflow get values mlflow-pack # what you overrode
helm -n mlflow get values mlflow-pack --all # everything

Redact before sharing — the output can contain an inline password.