Skip to content

Charts & topologies

Everything installs into a single tenant namespace (tenant-<id>); there is no control-plane chart in the open-source tree. Standalone is the default profile in every values.yaml — a plain helm install of charts/standard-tenant brings up a working tenant with no external control plane and no phone-home. The charts live in the platform repository.

Standalone (self-hosted)

The default. You operate the cluster; the cell mints its own tokens, enforces policy in-process, and orchestrates its own runs. The opendome-system namespace never exists — a CI gate enforces it.

OpenDome-operated

The commercial tier deploys the same charts with values-managed.yaml overlays (standard-tenant, tenant-mgmt-api, tenant-semantic-api, lakehouse): a central control plane provisions and upgrades many cells and fronts them with the console. Nothing in the cell’s data model changes.

  • standard-tenant — installed first: namespace, deny-all NetworkPolicy (plus the apiServerEgress allowlist CNPG needs), ResourceQuota, LimitRange, the tenant-object-storage Secret and — in the standalone profile — a bundled in-namespace RustFS (S3) and CNPG Postgres. Parameterised by tenant. All other charts install alongside it in the same namespace.
Chart What it deploys
tenant-semantic-api The OSL engine — the single data-consumption surface (POST /osl/query). Creates the HS256 signing Secret tenant-semantic-api-jwt the other cells verify bearer tokens against.
tenant-mgmt-api Tenant management: connectors, policies, the PDP, runs and the runner-Job launcher. Its dagster.enabled toggle (default false) deploys the in-cell Dagster — Dagster is a toggle inside this chart, not a separate chart.
tenant-catalog-api Internal Iceberg raw/curated discovery + allowlisted previews (console asset catalog); governed SQL consumption lives in the OSL.
tenant-config Config API and store (allowlist, pipeline, discovery) in the tenant namespace.
  • connector-runner — Job template for a connector sync (Meltano + Singer). createJob: false by default; the per-cell orchestrator renders it per run.
  • dbt-runner — Job template for dbt runs (raw → curated), same pattern.
  • lakehouse — Nessie + Trino + Iceberg per tenant (Helm dependencies; run helm dependency build before templating). Trino is an internal engine — it exposes no public endpoint; consumption goes through OSL.
  • observability — Prometheus, Grafana, Loki, Tempo (OSS umbrella chart).

values.yaml is always the standalone/self-hoster default. Additional files, only where they exist:

  • values-managed.yaml — the OpenDome-operated overlay (standard-tenant, tenant-mgmt-api, tenant-semantic-api, lakehouse).
  • values-local.yaml — kind/dev only; not for self-hosted installs.
  • values-staging.yaml / values-prod.yaml — lakehouse/observability only.

Released charts pin every image — the API/runner image: blocks and the tenant-mgmt-api runnerImages.* the cell launches Jobs with — to the released CalVer tag and its immutable sha256 digest. Checking out a release tag means pulling verifiable images; see Security posture for verification and Releases & versioning for how releases are cut.

standard-tenant and tenant-mgmt-api print post-install notes (NOTES.txt) — credential recovery and the Dagster/run-launcher wiring respectively.