Standalone (self-hosted)
The default. You operate the cluster; the cell mints its own tokens,
enforces policy in-process, and orchestrates its own runs. The
opendome-system namespace never exists — a CI gate enforces it.
Everything installs into a single tenant namespace (tenant-<id>); there is
no control-plane chart in the open-source tree. Standalone is the default
profile in every values.yaml — a plain helm install of
charts/standard-tenant brings up a working tenant with no external control
plane and no phone-home. The charts live in the
platform repository.
Standalone (self-hosted)
The default. You operate the cluster; the cell mints its own tokens,
enforces policy in-process, and orchestrates its own runs. The
opendome-system namespace never exists — a CI gate enforces it.
OpenDome-operated
The commercial tier deploys the same charts with values-managed.yaml
overlays (standard-tenant, tenant-mgmt-api, tenant-semantic-api,
lakehouse): a central control plane provisions and upgrades many cells and
fronts them with the console. Nothing in the cell’s data model changes.
standard-tenant — installed first: namespace, deny-all
NetworkPolicy (plus the apiServerEgress allowlist CNPG needs),
ResourceQuota, LimitRange, the tenant-object-storage Secret and — in the
standalone profile — a bundled in-namespace RustFS (S3) and CNPG
Postgres. Parameterised by tenant. All other charts install alongside it
in the same namespace.| Chart | What it deploys |
|---|---|
tenant-semantic-api |
The OSL engine — the single data-consumption surface (POST /osl/query). Creates the HS256 signing Secret tenant-semantic-api-jwt the other cells verify bearer tokens against. |
tenant-mgmt-api |
Tenant management: connectors, policies, the PDP, runs and the runner-Job launcher. Its dagster.enabled toggle (default false) deploys the in-cell Dagster — Dagster is a toggle inside this chart, not a separate chart. |
tenant-catalog-api |
Internal Iceberg raw/curated discovery + allowlisted previews (console asset catalog); governed SQL consumption lives in the OSL. |
tenant-config |
Config API and store (allowlist, pipeline, discovery) in the tenant namespace. |
connector-runner — Job template for a connector sync (Meltano +
Singer). createJob: false by default; the per-cell orchestrator renders it
per run.dbt-runner — Job template for dbt runs (raw → curated), same pattern.lakehouse — Nessie + Trino + Iceberg per tenant (Helm dependencies;
run helm dependency build before templating). Trino is an internal
engine — it exposes no public endpoint; consumption goes through OSL.observability — Prometheus, Grafana, Loki, Tempo (OSS umbrella chart).values.yaml is always the standalone/self-hoster default. Additional files,
only where they exist:
values-managed.yaml — the OpenDome-operated overlay (standard-tenant,
tenant-mgmt-api, tenant-semantic-api, lakehouse).values-local.yaml — kind/dev only; not for self-hosted installs.values-staging.yaml / values-prod.yaml — lakehouse/observability only.Released charts pin every image — the API/runner image: blocks and the
tenant-mgmt-api runnerImages.* the cell launches Jobs with — to the
released CalVer tag and its immutable sha256 digest. Checking out a
release tag means pulling verifiable images; see
Security posture for verification and
Releases & versioning for how releases are cut.
standard-tenant and tenant-mgmt-api print post-install notes
(NOTES.txt) — credential recovery and the Dagster/run-launcher wiring
respectively.