Install on Kubernetes (Helm)
Data Security for Dell AI Infrastructure can run entirely inside your Kubernetes cluster, installed with its Helm chart. Everything runs as pods in one namespace:
- The console.
- PostgreSQL, through the CloudNativePG operator.
- ClickHouse, through the Altinity operator.
- The pipeline agents (extraction, linguistic coherence, and classify).
Both operators are bundled with the chart. To run the console as a VMware appliance instead, see Install on VMware (OVA).
The chart is validated on RKE2 (openSUSE), kubeadm (Ubuntu 24.04), and OKD / OpenShift. The chart package includes a step-by-step guide and an example values file for each platform under examples/.
Before you begin
- Kubernetes: v1.31 to v1.37. See Product Prerequisites.
- Helm: 3.18.6 or newer. The chart refuses to install with an older version.
- kubectl: cluster-admin access or equivalent. The install creates custom resource definitions and cluster-wide roles for the bundled operators.
- Ingress controller: the chart has presets for ingress-nginx, HAProxy, and the OpenShift router. The console works only over HTTPS on port 443. Its session cookie is always marked Secure, so login fails with 403 through an ingress on any other port. A plain NodePort or LoadBalancer service without TLS in front is not supported.
- Storage: by default the chart creates a
local-path-retainStorageClass, which needs the Rancherlocal-path-provisionerrunning on the cluster. K3s includes it. RKE2, kubeadm, and OpenShift do not, so install it first. The kubeadm example guide has the commands. Without it, every volume staysPending. Alternatively, setstorage.createStorageClass: falseand setstorage.classNameto any class that providesReadWriteOncevolumes. - Capacity: see the sizing table in Product Prerequisites.
- Registry access: the chart and the product images are on a public registry, so no pull secret is needed. The cluster must be able to reach it. Air-gapped installs are not supported on Kubernetes. For an air-gapped site, use the VMware appliance (see Install on VMware (OVA)).
- DNS name: a name for the console that resolves to your ingress controller.
Get the chart
Pull and unpack the chart:
helm pull oci://northamerica-northeast2-docker.pkg.dev/superna-579/oci/aisecurity/charts/aisec \
--version <version> --untar
<version> is the chart version of the release you are deploying. The command creates an aisec/ directory that holds the chart, its install guide (K8S-INSTALL-GUIDE.md), and the per-platform examples.
Prepare the values file
Copy the example values file for your platform:
aisec/examples/rke2-opensuse/values-rke2.yamlaisec/examples/kubeadm-ubuntu/values-kubeadm.yamlaisec/examples/okd/values-okd.yaml
Then set the following values:
| Value | Setting |
|---|---|
ingress.host | The DNS name of the console. |
ingress.className | Your ingress class. Each example sets the class for its platform. |
console.image.tag and pipeline.stages.<stage>.image.tag | The release you are deploying, for the stages extraction, lc, and classify. The example files leave the tags empty, and an empty tag means latest. |
| Resources, replica count, storage class | Optional. Set them per component. |
Leave the database passwords empty. The chart generates them on the first install and keeps them across upgrades. The TLS certificate of the console is self-signed by default.
Install
On a cluster that does not already run the CloudNativePG and Altinity operators, install in two phases. The custom resource definitions of the operators must be registered before the databases that use them are created. On a fresh cluster, a single install can lose that race and fail with no matches for kind "Cluster".
-
Install the operators and their definitions only:
helm install aisec ./aisec -n aisec --create-namespace -f my-values.yaml \
--set postgres.enabled=false --set clickhouse.enabled=false --timeout 15m -
Wait until both definitions exist:
kubectl get crd clusters.postgresql.cnpg.io clickhouseinstallations.clickhouse.altinity.com -
Apply your full values, databases included:
helm upgrade aisec ./aisec -n aisec -f my-values.yaml --timeout 15m
If both operators already run on your cluster, set operators.cnpg.install: false and operators.clickhouse.install: false in your values. The example files set both to true. A single helm install is then enough. The install guide in the chart covers this case as Scenario B.
On OpenShift:
- Create the project first with
oc new-project aisec. - Grant the security context constraints that the OKD guide lists.
- Leave out
--create-namespace.
Verify the installation
Check the pods and the database resources:
kubectl get pods -n aisec
kubectl get cluster -n aisec
kubectl get chi -n aisec
Confirm the following:
- All pods reach
Running. - The PostgreSQL cluster reports Cluster in healthy state.
- The ClickHouse installation reports Completed.
- Each pipeline agent log shows
Registration response: {'ok': Trueonce the agent has registered with the console.
The console-0 pod stays in Init until both databases are reachable. This is expected.
Log in for the first time
- Point the DNS name at your ingress controller.
- Browse to
https://<ingress.host>/and accept the self-signed certificate warning. - On the first visit, the console asks you to create its administrator account. Enter a username and a password of at least 8 characters.
- Continue with the Quick Start Setup Guide.
Pipeline agents on Kubernetes
Each pipeline stage runs as a StatefulSet in the release namespace, and its agents register with the console on their own. To scale a stage, set pipeline.stages.<stage>.replicas in your values and run helm upgrade.
Because the chart manages the agents, System Operations > Fleet Management > Agent Installation, System Operations > Fleet Management > Agents Upgrade, and Settings > Software Update are disabled on a Kubernetes install.
Upgrade
-
Set the image tags of the new release in your values.
-
Upgrade to the new chart version directly from the registry:
helm upgrade aisec oci://northamerica-northeast2-docker.pkg.dev/superna-579/oci/aisecurity/charts/aisec \
--version <new-version> -n aisec -f my-values.yaml --timeout 15m
To work from a local copy instead, pull the new version into its own directory and upgrade from there:
helm pull oci://northamerica-northeast2-docker.pkg.dev/superna-579/oci/aisecurity/charts/aisec \
--version <new-version> --untar --untardir ./aisec-<new-version>
helm upgrade aisec ./aisec-<new-version>/aisec -n aisec -f my-values.yaml --timeout 15m
Upgrading from the aisec/ directory you installed from re-applies the old chart.
Restart and roll back
- To restart the pods when nothing in the values changed, add
--set deployTimestamp=$(date +%s). - To list the revisions, run
helm history aisec -n aisec. - To return to a revision, run
helm rollback aisec <revision> -n aisec.
Roll back only to a revision that was installed with your full values. Revision 1 of the two-phase install has both databases turned off, and rolling back to it removes them. Keep the database image versions that the chart pins.
Uninstall
helm uninstall aisec -n aisec
The generated database and enrollment secrets are kept, so a later install into the same namespace reuses them.
Platform notes
- RKE2: ships ingress-nginx. Install the local-path provisioner yourself.
- kubeadm: install the local-path provisioner (as the default StorageClass) and ingress-nginx yourself. Run ingress-nginx on the host network on port 443, because login fails behind a NodePort.
- OKD / OpenShift:
- The local-path provisioner needs extra permissions and SELinux labelling.
- The service accounts of the console need the
nonroot-v2security context constraint. - Expose the console through the OpenShift router (
ingress.className: openshift-default) or a Route (route.enabled: true).
The guides under aisec/examples/ give the exact commands for each platform.
Troubleshooting
| Symptom | Cause and fix |
|---|---|
| Login fails with 403 | The console is reached on a port other than 443. Put the ingress on 443. |
console-0 stays in Init | PostgreSQL or ClickHouse is not ready yet. Check kubectl get cluster -n aisec and kubectl get chi -n aisec. |
The first install fails with no matches for kind "Cluster" | The definitions of the operators were not registered yet. Use the two-phase install. |