litellm/helm
Yassin Kortam 46f8fabb07
feat(helm): add pod-hardening and migration-Job knobs to the componentized chart (#35489)
The componentized chart exposed no pod-hardening surface, so values that
operators of hardened clusters routinely set (podSecurityContext,
securityContext, extraContainers, podLabels, lifecycle,
terminationGracePeriodSeconds) rendered nothing at all. Helm does not error
on unknown values, so the deploy went green with none of the hardening
applied.

Adds those six knobs to gateway, backend, and ui, plus volumes,
volumeMounts, podLabels, podSecurityContext, and securityContext on the
migrations Job.

Also fixes a first-install failure: the migrations Job is a
pre-install/pre-upgrade hook, so borrowing the backend ServiceAccount name
while the chart creates that account references an account that does not
exist yet, and the Job pod is rejected as forbidden. The Job now resolves
its own name through migrationJob.serviceAccountName, falling back to the
namespace default account when the chart creates the backend one and
keeping today's shared name otherwise.
2026-08-01 14:10:55 -07:00
..
litellm feat(helm): add pod-hardening and migration-Job knobs to the componentized chart (#35489) 2026-08-01 14:10:55 -07:00
litellm-helm fix(helm): render pod-level securityContext on the migration Job (#35482) 2026-08-01 13:03:32 -07:00