This commit is contained in:
Glen Messenger 2026-10-01 02:22:07 +08:00 • committed by GitHub
commit 4cd2bdcc17
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
6 changed files with 58 additions and 3 deletions

View file

@ -5,5 +5,8 @@ dependencies:
- name: redis
repository: oci://registry-1.docker.io/bitnamicharts
version: 18.19.1
digest: sha256:38962e231f6596b93f82a8412bbe4cf5de696caecf5775dfbbd163383eb1c009
generated: "2026-07-28T10:21:22.511401-07:00"
- name: k8s-aibom
repository: oci://ghcr.io/googlecloudplatform/charts
version: 1.5.1
digest: sha256:d4621c5d49e4bb7a107e67a5272056fbd4037c262495d8c31abc150de5198cb4
generated: "2026-09-29T16:54:10.796253-07:00"

View file

@ -18,7 +18,7 @@ type: application
# This is the chart version. This version number should be incremented each time you make changes
# to the chart and its templates, including the app version.
# Versions are expected to follow Semantic Versioning (https://semver.org/)
version: 1.1.3
version: 1.1.4
# This is the version number of the application being deployed. This version number should be
# incremented each time you make changes to the application. Versions are not expected to
@ -39,3 +39,7 @@ dependencies:
version: "18.19.1"
repository: oci://registry-1.docker.io/bitnamicharts
condition: redis.enabled
- name: k8s-aibom
version: "1.5.1"
repository: oci://ghcr.io/googlecloudplatform/charts
condition: k8s-aibom.enabled

View file

@ -132,6 +132,8 @@ Set `billingMetrics.caSecretName` only when the collector is a private or test o
| `postgresql.auth.*` | If `db.deployStandalone` is `true`, care should be taken to ensure the default `password` and `postgres-password` values are **NOT** used. | `NoTaGrEaTpAsSwOrD` |
| `postgresql.image.*` | If `db.deployStandalone` is `true`, the image for the bundled Postgres. Pinned to a `docker.io/bitnamilegacy` build because Bitnami retired the versioned tags under `docker.io/bitnami`. | `bitnamilegacy/postgresql:16.2.0-debian-12-r6` |
| `redis.image.*` | If `redis.enabled` is `true`, the image for the bundled Redis. Pinned to a `docker.io/bitnamilegacy` build for the same reason. | `bitnamilegacy/redis:7.2.4-debian-12-r9` |
| `k8s-aibom.enabled` | Install [k8s-aibom](https://github.com/GoogleCloudPlatform/k8s-aibom), an unprivileged controller that generates a CycloneDX 1.6 ML-BOM per AI workload at runtime (model, runtime, image digests, each with evidence and a confidence tier). Namespace opt-in: also label the namespace `aibom.k8saibom.dev/enabled=true`. | `false` |
| `k8s-aibom.*` | If `k8s-aibom.enabled` is `true`, configuration passed to the k8s-aibom chart. See its [values](https://github.com/GoogleCloudPlatform/k8s-aibom/blob/main/charts/k8s-aibom/values.yaml). | See k8s-aibom [values.yaml](https://github.com/GoogleCloudPlatform/k8s-aibom/blob/main/charts/k8s-aibom/values.yaml) |
#### Bundled Postgres image

Binary file not shown.

View file

@ -0,0 +1,37 @@
# The k8s-aibom subchart is condition-gated (k8s-aibom.enabled, default
# false). helm-unittest does not load a disabled dependency's templates at
# all, so the default-off path cannot be asserted here as "zero documents";
# it is covered by every other suite rendering with default values. These
# tests exercise the enabled configuration end to end.
suite: k8s-aibom optional subchart (enabled)
templates:
- charts/k8s-aibom/templates/deployment.yaml
- charts/k8s-aibom/templates/clusterrole.yaml
- charts/k8s-aibom/templates/controllerconfig.yaml
set:
k8s-aibom.enabled: true
tests:
- it: renders the k8s-aibom controller Deployment when enabled
template: charts/k8s-aibom/templates/deployment.yaml
asserts:
- hasDocuments:
count: 1
- isKind:
of: Deployment
- equal:
path: spec.template.spec.containers[0].name
value: manager
- it: renders the k8s-aibom ClusterRole when enabled
template: charts/k8s-aibom/templates/clusterrole.yaml
asserts:
- hasDocuments:
count: 1
- isKind:
of: ClusterRole
- it: renders the default AIBOMControllerConfig when enabled
template: charts/k8s-aibom/templates/controllerconfig.yaml
asserts:
- hasDocuments:
count: 1
- isKind:
of: AIBOMControllerConfig

View file

@ -635,3 +635,12 @@ serviceMonitor:
namespaceSelector:
matchNames: []
# - test-namespace
# Optional runtime AI inventory (k8s-aibom). When enabled, an unprivileged
# controller generates a CycloneDX 1.6 ML-BOM for AI workloads in namespaces
# labeled aibom.k8saibom.dev/enabled=true — including the LiteLLM proxy
# this chart deploys (detected as the `litellm` runtime). Disabled by
# default; nothing is inventoried without both this flag and the namespace
# opt-in label.
k8s-aibom:
enabled: false