Install on Kubernetes#
Download the v1.1.0 Helm chart, extract it, and use the resulting poc-factory/ directory for a managed deployment. The chart’s production values are an example to adapt for your cluster, registry, ingress, identity, database, and storage. The frontend should be the browser-facing service; it proxies API and progress traffic to the backend.
Prerequisites#
Prepare cluster access, identity, secrets, and storage before rendering the chart.
Obtain Kubernetes and Helm access, the
v1.1.0chart, and an NGC or approved-mirror image pull Secret.Prepare an HTTPS hostname, TLS certificate, and OAuth client when browser sign-in is enabled.
Prepare a Kubernetes Secret or external secret store for inference, encryption, authentication, and optional capability credentials.
Provision PostgreSQL and persistent storage for generated POCs, NAT job state, and any fine-tuning data you intend to retain.
The chart README lists Kubernetes 1.23+ and Helm 3.0+ as prerequisites. Use a single backend replica for the v1.1.0 production pattern unless shared job coordination and compatible storage are in place.
Prepare Images and Secrets#
Set up the namespace and references to approved image and application secrets.
Create the namespace and provide a registry pull Secret named by
global.imagePullSecrets:kubectl create namespace poc-factory kubectl get secret ngc-registry-secret -n poc-factory
If the Secret does not yet exist, create it through your approved secret workflow for
nvcr.ioor your registry mirror.Provide
poc-factory-secretsor changesecrets.existingSecretto the approved Secret name. Include a stableENCRYPTION_KEYand the credentials required by your chosen auth and inference modes. Keep secret values out of Helm values files.Confirm the backend, frontend, and GitHub MCP proxy image tags are
1.1.0in the rendered chart. The taggedvalues-production.yamlpins all three. Override their NGC organization together as shown below.
Configure Production Values#
Keep environment-owned overrides outside the tagged chart.
From the extracted chart directory, copy
poc-factory/values-production.yamlto an environment-owned file such asenvironment-values.yamland edit that copy.Set all three image organization values to the current NGC organization:
pocFactory: image: organization: "nvidia" frontend: image: organization: "nvidia" githubMcpProxy: image: organization: "nvidia"
Set the browser-facing ingress hostname and TLS Secret. Set
config.ngcEnvironment=production,config.secureCookies=true, and exact HTTPS values forconfig.security.allowedOrigins,allowedHosts, andallowedRedirectOrigins.Configure OAuth callback
https://<host>/api/auth/callbackwith your identity provider when OAuth is enabled. Use the browser-facing host, not the internal backend Service name.Choose managed PostgreSQL or the chart’s internal database. Configure its Secret and backup policy. Enable PVCs for
generatedPocsandjobStore; enablefineTuneArtifactsandfineTuneDatasetswhen those workflows are used.Keep
pocFactory.dockerSocket.enabled=falseandconfig.enableDeploymentValidation=falseandconfig.enableRuntimeValidation=falseunless the cluster intentionally supplies a secured, working Docker daemon.
When providing an administrator CURSOR_API_KEY, also set config.cursor.model=auto or a supported Cursor model identifier. For the full keys and default values, use the chart’s values.yaml and values-production.yaml from the v1.1.0 tag. The production example enables internal PostgreSQL; switch to an external managed database when that is your operating standard.
Render and Deploy#
Inspect the rendered resources before applying them to the cluster.
Lint and render the chart from the extracted v1.1.0 chart:
helm lint ./poc-factory -f environment-values.yaml helm template poc-factory ./poc-factory -n poc-factory -f environment-values.yaml > /tmp/poc-factory-rendered.yaml
Inspect
/tmp/poc-factory-rendered.yamlfor the three image references, pull Secret, ingress host, Secret references, PVCs, and validation flags.Deploy or update the release:
helm upgrade --install poc-factory ./poc-factory -n poc-factory --create-namespace -f environment-values.yaml kubectl get pods,svc,ingress,pvc -n poc-factory
Wait for the named Deployments to become Ready and review recent events:
kubectl get deployments -n poc-factory kubectl get events -n poc-factory --sort-by=.lastTimestamp
For GitOps, commit the chart version and environment values to the deployment repository, verify ExternalSecret health, inspect rendered images, and synchronize through the GitOps controller.
Next Steps#
Validate the deployment from the browser, then assign its operating owners.
Configure and validate the public URL, provider, workflow, and persistence.
Operate and restore the database and volumes as one service state.