diff --git a/helm/litellm-helm/Chart.lock b/helm/litellm-helm/Chart.lock index d626fbb472b..89cf3d2a7cc 100644 --- a/helm/litellm-helm/Chart.lock +++ b/helm/litellm-helm/Chart.lock @@ -5,5 +5,8 @@ dependencies: - name: redis repository: oci://registry-1.docker.io/bitnamicharts version: 18.19.1 -digest: sha256:38962e231f6596b93f82a8412bbe4cf5de696caecf5775dfbbd163383eb1c009 -generated: "2026-07-28T10:21:22.511401-07:00" +- name: k8s-aibom + repository: oci://ghcr.io/googlecloudplatform/charts + version: 1.5.1 +digest: sha256:d4621c5d49e4bb7a107e67a5272056fbd4037c262495d8c31abc150de5198cb4 +generated: "2026-09-29T16:54:10.796253-07:00" diff --git a/helm/litellm-helm/Chart.yaml b/helm/litellm-helm/Chart.yaml index a3cb388ffc6..3421e8f619a 100644 --- a/helm/litellm-helm/Chart.yaml +++ b/helm/litellm-helm/Chart.yaml @@ -39,3 +39,7 @@ dependencies: version: "18.19.1" repository: oci://registry-1.docker.io/bitnamicharts condition: redis.enabled + - name: k8s-aibom + version: "1.5.1" + repository: oci://ghcr.io/googlecloudplatform/charts + condition: k8s-aibom.enabled diff --git a/helm/litellm-helm/README.md b/helm/litellm-helm/README.md index bf4089404db..028b228a991 100644 --- a/helm/litellm-helm/README.md +++ b/helm/litellm-helm/README.md @@ -132,6 +132,8 @@ Set `billingMetrics.caSecretName` only when the collector is a private or test o | `postgresql.auth.*` | If `db.deployStandalone` is `true`, care should be taken to ensure the default `password` and `postgres-password` values are **NOT** used. | `NoTaGrEaTpAsSwOrD` | | `postgresql.image.*` | If `db.deployStandalone` is `true`, the image for the bundled Postgres. Pinned to a `docker.io/bitnamilegacy` build because Bitnami retired the versioned tags under `docker.io/bitnami`. | `bitnamilegacy/postgresql:16.2.0-debian-12-r6` | | `redis.image.*` | If `redis.enabled` is `true`, the image for the bundled Redis. Pinned to a `docker.io/bitnamilegacy` build for the same reason. | `bitnamilegacy/redis:7.2.4-debian-12-r9` | +| `k8s-aibom.enabled` | Install [k8s-aibom](https://github.com/GoogleCloudPlatform/k8s-aibom), an unprivileged controller that generates a CycloneDX 1.6 ML-BOM per AI workload at runtime (model, runtime, image digests, each with evidence and a confidence tier). Namespace opt-in: also label the namespace `aibom.k8saibom.dev/enabled=true`. | `false` | +| `k8s-aibom.*` | If `k8s-aibom.enabled` is `true`, configuration passed to the k8s-aibom chart. See its [values](https://github.com/GoogleCloudPlatform/k8s-aibom/blob/main/charts/k8s-aibom/values.yaml). | See k8s-aibom [values.yaml](https://github.com/GoogleCloudPlatform/k8s-aibom/blob/main/charts/k8s-aibom/values.yaml) | #### Bundled Postgres image diff --git a/helm/litellm-helm/charts/k8s-aibom-1.5.1.tgz b/helm/litellm-helm/charts/k8s-aibom-1.5.1.tgz new file mode 100644 index 00000000000..8445119b8ea Binary files /dev/null and b/helm/litellm-helm/charts/k8s-aibom-1.5.1.tgz differ diff --git a/helm/litellm-helm/values.yaml b/helm/litellm-helm/values.yaml index fcee331a5aa..ef28798deae 100644 --- a/helm/litellm-helm/values.yaml +++ b/helm/litellm-helm/values.yaml @@ -635,3 +635,12 @@ serviceMonitor: namespaceSelector: matchNames: [] # - test-namespace + +# Optional runtime AI inventory (k8s-aibom). When enabled, an unprivileged +# controller generates a CycloneDX 1.6 ML-BOM for AI workloads in namespaces +# labeled aibom.k8saibom.dev/enabled=true — including the LiteLLM proxy +# this chart deploys (detected as the `litellm` runtime). Disabled by +# default; nothing is inventoried without both this flag and the namespace +# opt-in label. +k8s-aibom: + enabled: false