Templated Kubernetes deployment for ForgeFlow. Equivalent to the manifests
in ../../k8s/ but parameterized, with helm hooks for
schema migration and per-environment value overrides.
# Add namespace + dry-run to verify the rendered manifests
kubectl create namespace forgeflow
helm install ff ./helm/forgeflow -n forgeflow --dry-run --debug
# Real install — edit values.yaml first or override on the CLI
helm install ff ./helm/forgeflow -n forgeflow \
--set image.tag=0.1.0 \
--set secrets.values.OPENAI_API_KEY=sk-...helm upgrade ff ./helm/forgeflow -n forgeflow -f my-values.yamlThe migrate job runs as a pre-upgrade hook, so alembic catches any
new revisions before the new pods roll out.
See values.yaml for the full set with comments. Key
sections:
image.*— registry + tag (override per environment)config.*— non-secret runtime configuration (ConfigMap)secrets.values— inline secret values for dev. For production setsecrets.existingSecret: my-external-secret-nameinstead.postgres.enabled— set tofalsewhen using managed RDS / Cloud SQLapi.autoscaling.*,mcp.autoscaling.*— HPA tuningingress.*— host names + TLSnetworkPolicy.enabled— set tofalseon clusters without a CNI that enforces NetworkPolicy
-
image.tagpinned to a specific version (notlatest) -
secrets.existingSecretreferences an external secret store -
postgres.enabled: false+ managed-DB connection string inconfig.postgresUrl/config.postgresSyncUrl -
ingress.tls.enabled: trueand cert-manager wired up -
networkPolicy.enabled: trueand the cluster's CNI enforces them -
image.pullSecretsconfigured if your registry isn't public -
nodeSelector/tolerations/affinityset to your node pool - Resource requests + limits tuned to your workload (defaults are conservative for dev clusters)
helm uninstall ff -n forgeflow
# Persistent volumes survive uninstall — delete the PVC if you want
# the database wiped:
kubectl -n forgeflow delete pvc -l app.kubernetes.io/component=postgres