Prerequisites
Palena delegates database, gateway, and tracing lifecycles to upstream operators. Install the ones you need before creating Palena resources — otherwise the reconciler will sit in phase: Error with prerequisites.cnpg = false (or similar).
Required
CloudNativePG
Palena uses CNPG to provision managed PostgreSQL clusters for both LiteLLM and Langfuse.
- CRDs used:
clusters.postgresql.cnpg.io - Install docs: cloudnative-pg.io
- Required when:
PalenaGateway.spec.database.managedis set (the typical path).
kubectl apply --server-side -f \
https://raw.githubusercontent.com/cloudnative-pg/cloudnative-pg/release-1.24/releases/cnpg-1.24.1.yamlLiteLLM Operator
Palena creates LiteLLMInstance and LiteLLMModel CRs that the LiteLLM Operator reconciles into actual LiteLLM deployments.
- CRDs used:
litellminstances.litellm.palena.ai,litellmmodels.litellm.palena.ai - Required when: Always (every
PalenaGatewayneeds this).
Conditional
Langfuse Operator
Required only when you create a PalenaObservability CR.
- CRDs used:
langfuseinstances.langfuse.palena.ai - Source: PalenaAI/langfuse-operator
cert-manager
Optional. Required only when you want Palena to request TLS certificates for Ingress via cert-manager's certmanager.k8s.io/cluster-issuer annotations instead of supplying a tls.secretName directly.
- CRDs used:
certificates.cert-manager.io - Install: cert-manager.io
Ingress controller
Optional but recommended. Any Kubernetes-compatible Ingress controller works (ingress-nginx, HAProxy, Traefik, etc.). On OpenShift, use spec.route instead of spec.ingress.
Cluster size guidance
The minimal working stack (gateway + one model) fits comfortably on a small cluster:
| Component | CPU request | Memory request |
|---|---|---|
| palena-operator | 100m | 128Mi |
| CNPG Cluster (1 instance) | 100m | 256Mi |
| Redis | 100m | 128Mi |
| LiteLLMInstance | 250m | 512Mi |
| Baseline total | ~550m | ~1Gi |
Adding PalenaUI adds ~500m CPU / 1Gi RAM (LibreChat + MongoDB + MeiliSearch). Langfuse + ClickHouse is the heaviest addition — budget at least 2 CPU / 4Gi RAM for PalenaObservability. The full websearch MCP (with Chromium) wants 1 CPU / 2Gi RAM on its own.
Verifying prerequisites
Palena's controller continuously checks for upstream CRDs via the RESTMapper and reports the result in status:
kubectl get palenagateway production \
-o jsonpath='{.status.prerequisites}{"\n"}'
# {"cnpg":true,"litellm":true}If either is false, install the missing operator and the reconciler will pick up automatically within 30 seconds.