diff --git a/helm/litellm-helm/Chart.lock b/helm/litellm-helm/Chart.lock index d626fbb472b..89cf3d2a7cc 100644 --- a/helm/litellm-helm/Chart.lock +++ b/helm/litellm-helm/Chart.lock @@ -5,5 +5,8 @@ dependencies: - name: redis repository: oci://registry-1.docker.io/bitnamicharts version: 18.19.1 -digest: sha256:38962e231f6596b93f82a8412bbe4cf5de696caecf5775dfbbd163383eb1c009 -generated: "2026-07-28T10:21:22.511401-07:00" +- name: k8s-aibom + repository: oci://ghcr.io/googlecloudplatform/charts + version: 1.5.1 +digest: sha256:d4621c5d49e4bb7a107e67a5272056fbd4037c262495d8c31abc150de5198cb4 +generated: "2026-09-29T16:54:10.796253-07:00" diff --git a/helm/litellm-helm/Chart.yaml b/helm/litellm-helm/Chart.yaml index a3cb388ffc6..6145fcb52d4 100644 --- a/helm/litellm-helm/Chart.yaml +++ b/helm/litellm-helm/Chart.yaml @@ -18,7 +18,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 1.1.3 +version: 1.1.4 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to @@ -39,3 +39,7 @@ dependencies: version: "18.19.1" repository: oci://registry-1.docker.io/bitnamicharts condition: redis.enabled + - name: k8s-aibom + version: "1.5.1" + repository: oci://ghcr.io/googlecloudplatform/charts + condition: k8s-aibom.enabled diff --git a/helm/litellm-helm/README.md b/helm/litellm-helm/README.md index bf4089404db..028b228a991 100644 --- a/helm/litellm-helm/README.md +++ b/helm/litellm-helm/README.md @@ -132,6 +132,8 @@ Set `billingMetrics.caSecretName` only when the collector is a private or test o | `postgresql.auth.*` | If `db.deployStandalone` is `true`, care should be taken to ensure the default `password` and `postgres-password` values are **NOT** used. | `NoTaGrEaTpAsSwOrD` | | `postgresql.image.*` | If `db.deployStandalone` is `true`, the image for the bundled Postgres. Pinned to a `docker.io/bitnamilegacy` build because Bitnami retired the versioned tags under `docker.io/bitnami`. | `bitnamilegacy/postgresql:16.2.0-debian-12-r6` | | `redis.image.*` | If `redis.enabled` is `true`, the image for the bundled Redis. Pinned to a `docker.io/bitnamilegacy` build for the same reason. | `bitnamilegacy/redis:7.2.4-debian-12-r9` | +| `k8s-aibom.enabled` | Install [k8s-aibom](https://github.com/GoogleCloudPlatform/k8s-aibom), an unprivileged controller that generates a CycloneDX 1.6 ML-BOM per AI workload at runtime (model, runtime, image digests, each with evidence and a confidence tier). Namespace opt-in: also label the namespace `aibom.k8saibom.dev/enabled=true`. | `false` | +| `k8s-aibom.*` | If `k8s-aibom.enabled` is `true`, configuration passed to the k8s-aibom chart. See its [values](https://github.com/GoogleCloudPlatform/k8s-aibom/blob/main/charts/k8s-aibom/values.yaml). | See k8s-aibom [values.yaml](https://github.com/GoogleCloudPlatform/k8s-aibom/blob/main/charts/k8s-aibom/values.yaml) | #### Bundled Postgres image diff --git a/helm/litellm-helm/charts/k8s-aibom-1.5.1.tgz b/helm/litellm-helm/charts/k8s-aibom-1.5.1.tgz new file mode 100644 index 00000000000..8445119b8ea Binary files /dev/null and b/helm/litellm-helm/charts/k8s-aibom-1.5.1.tgz differ diff --git a/helm/litellm-helm/tests/k8s_aibom_test.yaml b/helm/litellm-helm/tests/k8s_aibom_test.yaml new file mode 100644 index 00000000000..770a8a41ec0 --- /dev/null +++ b/helm/litellm-helm/tests/k8s_aibom_test.yaml @@ -0,0 +1,37 @@ +# The k8s-aibom subchart is condition-gated (k8s-aibom.enabled, default +# false). helm-unittest does not load a disabled dependency's templates at +# all, so the default-off path cannot be asserted here as "zero documents"; +# it is covered by every other suite rendering with default values. These +# tests exercise the enabled configuration end to end. +suite: k8s-aibom optional subchart (enabled) +templates: + - charts/k8s-aibom/templates/deployment.yaml + - charts/k8s-aibom/templates/clusterrole.yaml + - charts/k8s-aibom/templates/controllerconfig.yaml +set: + k8s-aibom.enabled: true +tests: + - it: renders the k8s-aibom controller Deployment when enabled + template: charts/k8s-aibom/templates/deployment.yaml + asserts: + - hasDocuments: + count: 1 + - isKind: + of: Deployment + - equal: + path: spec.template.spec.containers[0].name + value: manager + - it: renders the k8s-aibom ClusterRole when enabled + template: charts/k8s-aibom/templates/clusterrole.yaml + asserts: + - hasDocuments: + count: 1 + - isKind: + of: ClusterRole + - it: renders the default AIBOMControllerConfig when enabled + template: charts/k8s-aibom/templates/controllerconfig.yaml + asserts: + - hasDocuments: + count: 1 + - isKind: + of: AIBOMControllerConfig diff --git a/helm/litellm-helm/values.yaml b/helm/litellm-helm/values.yaml index fcee331a5aa..ef28798deae 100644 --- a/helm/litellm-helm/values.yaml +++ b/helm/litellm-helm/values.yaml @@ -635,3 +635,12 @@ serviceMonitor: namespaceSelector: matchNames: [] # - test-namespace + +# Optional runtime AI inventory (k8s-aibom). When enabled, an unprivileged +# controller generates a CycloneDX 1.6 ML-BOM for AI workloads in namespaces +# labeled aibom.k8saibom.dev/enabled=true — including the LiteLLM proxy +# this chart deploys (detected as the `litellm` runtime). Disabled by +# default; nothing is inventoried without both this flag and the namespace +# opt-in label. +k8s-aibom: + enabled: false