Sample catalog
The repository ships several config/samples/ directories covering progressively more complex deployments. Apply them directly — each directory is self-contained and namespace-scoped.
Available samples
| Directory | Contents | What it demonstrates |
|---|---|---|
minimal/ | PalenaGateway only | The smallest useful deployment — gateway with managed CNPG + Redis. |
with-ui/ | Gateway + Model + UI | Adds LibreChat on top of the minimal gateway. |
with-observability/ | Gateway + Model + Observability | Adds Langfuse tracing. |
with-mcp/ | Standalone PalenaMCPServer | Deploys the websearch MCP server with all sidecars. No gateway required. |
full/ | All five CRDs | Production-ish example: gateway + two models + UI with MCP refs + Langfuse + websearch. |
Minimal
apiVersion: operator.palena.ai/v1alpha1
kind: PalenaGateway
metadata:
name: production
namespace: palena
spec:
database:
managed:
instances: 1
storageSize: 10Gi
redis:
managed:
replicas: 1
storageSize: 5Gi
gateway:
replicas: 1
masterKey: { name: litellm-keys, key: master }
saltKey: { name: litellm-keys, key: salt }With observability
apiVersion: operator.palena.ai/v1alpha1
kind: PalenaObservability
metadata:
name: obs
namespace: palena
spec:
gatewayRef:
name: production
langfuse:
web:
replicas: 1
worker:
replicas: 1
clickhouse:
managed:
replicas: 1
storageSize: 50Gi
blobStorage:
provider: s3
s3:
region: us-east-1
bucket: palena-langfuse-traces
credentials:
name: s3-credentials
keys:
accessKeyId: AWS_ACCESS_KEY_ID
secretAccessKey: AWS_SECRET_ACCESS_KEY
ingress:
enabled: true
host: langfuse.example.com
className: nginxOnce applied, every request flowing through the gateway is automatically traced — Palena wires the Langfuse callback into the LiteLLMInstance and stores the seeded API keys in a generated Secret.
With MCP servers
A standalone websearch MCP server with all sidecars:
apiVersion: operator.palena.ai/v1alpha1
kind: PalenaMCPServer
metadata:
name: websearch
namespace: palena
spec:
type: websearch
replicas: 1
websearch:
searxng:
replicas: 1
engines: [duckduckgo, bing, wikipedia]
scraper:
chromiumEnabled: true
chromiumReplicas: 1
maxConcurrency: 10
presidio:
enabled: true
mode: redact
reranker:
provider: flashrankRegister it from a PalenaUI:
apiVersion: operator.palena.ai/v1alpha1
kind: PalenaUI
metadata:
name: chat
spec:
gatewayRef: { name: production }
mcpServerRefs:
- name: websearch
# ... rest of specLibreChat's librechat.yaml will be auto-regenerated with the MCP endpoint, and the Deployment rolls because the ConfigMap's SHA-256 is attached as a pod annotation.
Full stack
See config/samples/full/full.yaml in the repo — it wires all five CRDs together with realistic production settings (TLS via cert-manager, NetworkPolicies enabled, autoscaling, multiple models).