Install on Kubernetes#

Download the v1.1.0 Helm chart, extract it, and use the resulting poc-factory/ directory for a managed deployment. The chart’s production values are an example to adapt for your cluster, registry, ingress, identity, database, and storage. The frontend should be the browser-facing service; it proxies API and progress traffic to the backend.

Prerequisites#

Prepare cluster access, identity, secrets, and storage before rendering the chart.

  1. Obtain Kubernetes and Helm access, the v1.1.0 chart, and an NGC or approved-mirror image pull Secret.

  2. Prepare an HTTPS hostname, TLS certificate, and OAuth client when browser sign-in is enabled.

  3. Prepare a Kubernetes Secret or external secret store for inference, encryption, authentication, and optional capability credentials.

  4. Provision PostgreSQL and persistent storage for generated POCs, NAT job state, and any fine-tuning data you intend to retain.

The chart README lists Kubernetes 1.23+ and Helm 3.0+ as prerequisites. Use a single backend replica for the v1.1.0 production pattern unless shared job coordination and compatible storage are in place.

Prepare Images and Secrets#

Set up the namespace and references to approved image and application secrets.

  1. Create the namespace and provide a registry pull Secret named by global.imagePullSecrets:

    kubectl create namespace poc-factory
    kubectl get secret ngc-registry-secret -n poc-factory
    

    If the Secret does not yet exist, create it through your approved secret workflow for nvcr.io or your registry mirror.

  2. Provide poc-factory-secrets or change secrets.existingSecret to the approved Secret name. Include a stable ENCRYPTION_KEY and the credentials required by your chosen auth and inference modes. Keep secret values out of Helm values files.

  3. Confirm the backend, frontend, and GitHub MCP proxy image tags are 1.1.0 in the rendered chart. The tagged values-production.yaml pins all three. Override their NGC organization together as shown below.

Configure Production Values#

Keep environment-owned overrides outside the tagged chart.

  1. From the extracted chart directory, copy poc-factory/values-production.yaml to an environment-owned file such as environment-values.yaml and edit that copy.

  2. Set all three image organization values to the current NGC organization:

    pocFactory:
      image:
        organization: "nvidia"
    frontend:
      image:
        organization: "nvidia"
    githubMcpProxy:
      image:
        organization: "nvidia"
    
  3. Set the browser-facing ingress hostname and TLS Secret. Set config.ngcEnvironment=production, config.secureCookies=true, and exact HTTPS values for config.security.allowedOrigins, allowedHosts, and allowedRedirectOrigins.

  4. Configure OAuth callback https://<host>/api/auth/callback with your identity provider when OAuth is enabled. Use the browser-facing host, not the internal backend Service name.

  5. Choose managed PostgreSQL or the chart’s internal database. Configure its Secret and backup policy. Enable PVCs for generatedPocs and jobStore; enable fineTuneArtifacts and fineTuneDatasets when those workflows are used.

  6. Keep pocFactory.dockerSocket.enabled=false and config.enableDeploymentValidation=false and config.enableRuntimeValidation=false unless the cluster intentionally supplies a secured, working Docker daemon.

When providing an administrator CURSOR_API_KEY, also set config.cursor.model=auto or a supported Cursor model identifier. For the full keys and default values, use the chart’s values.yaml and values-production.yaml from the v1.1.0 tag. The production example enables internal PostgreSQL; switch to an external managed database when that is your operating standard.

Render and Deploy#

Inspect the rendered resources before applying them to the cluster.

  1. Lint and render the chart from the extracted v1.1.0 chart:

    helm lint ./poc-factory -f environment-values.yaml
    helm template poc-factory ./poc-factory -n poc-factory -f environment-values.yaml > /tmp/poc-factory-rendered.yaml
    
  2. Inspect /tmp/poc-factory-rendered.yaml for the three image references, pull Secret, ingress host, Secret references, PVCs, and validation flags.

  3. Deploy or update the release:

    helm upgrade --install poc-factory ./poc-factory -n poc-factory --create-namespace -f environment-values.yaml
    kubectl get pods,svc,ingress,pvc -n poc-factory
    
  4. Wait for the named Deployments to become Ready and review recent events:

    kubectl get deployments -n poc-factory
    kubectl get events -n poc-factory --sort-by=.lastTimestamp
    

For GitOps, commit the chart version and environment values to the deployment repository, verify ExternalSecret health, inspect rendered images, and synchronize through the GitOps controller.

Next Steps#

Validate the deployment from the browser, then assign its operating owners.