PalenaGateway
A PalenaGateway is the cornerstone CR. One PalenaGateway produces one CloudNativePG Cluster, one Redis instance, and one LiteLLMInstance. Every other Palena CR (except PalenaMCPServer) references a PalenaGateway.
Short name: pgwAPI group: operator.palena.ai/v1alpha1Scope: Namespaced
spec
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
database | DatabaseSpec | Yes | — | Select managed CNPG or external PostgreSQL. |
redis | RedisSpec | Yes | — | Select managed or external Redis. |
gateway | GatewaySpec | Yes | — | LiteLLM gateway configuration. |
security | SecuritySpec | No | — | NetworkPolicy / pod security toggles. |
platform | string | No | auto | Force platform detection. Enum: auto, kubernetes, openshift. |
DatabaseSpec
Exactly one of managed or external must be set.
| Field | Type | Description |
|---|---|---|
managed.instances | int32 (≥1, default 1) | CNPG cluster instance count. |
managed.storageSize | string (default 10Gi) | PVC size per instance. |
managed.storageClass | string | Optional StorageClass override. |
managed.postgresql.parameters | map[string]string | PostgreSQL parameters passed through to CNPG. |
managed.backup.enabled | bool | Enable Barman-based backups. |
managed.backup.schedule | string | Cron schedule. |
managed.backup.retentionPolicy | string | CNPG retention policy string. |
managed.backup.barmanObjectStore.s3Credentials.secretRef.name | string | Secret with S3 credentials. |
external.connectionSecretRef | SecretKeyRef | Secret key holding a full postgres://… URL. |
RedisSpec
Exactly one of managed or external must be set.
| Field | Type | Default | Description |
|---|---|---|---|
managed.replicas | int32 | 1 | Redis replica count. |
managed.storageSize | string | 5Gi | PVC size. |
external.host | string | — | Redis host (when using host+port). |
external.port | int32 | 6379 | Redis port. |
external.passwordSecretRef | SecretKeyRef | — | Optional password secret. |
external.connectionSecretRef | SecretKeyRef | — | Alternative: full redis://… URL. |
GatewaySpec
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
replicas | int32 | Yes | 1 | LiteLLM Deployment replicas. |
image | ImageSpec | No | — | Override LiteLLM image. |
masterKey | SecretKeyRef | Yes | — | Master API key secret. |
saltKey | SecretKeyRef | No | — | Salt secret (highly recommended). |
configSync | ConfigSyncSpec | No | — | LiteLLM bidirectional config sync. |
autoscaling | AutoscalingSpec | No | — | HPA configuration. |
routerSettings | RouterSettingsSpec | No | — | LiteLLM routerSettings passthrough. |
generalSettings | GeneralSettingsSpec | No | — | LiteLLM generalSettings passthrough. |
ingress | IngressSpec | No | — | Ingress configuration. |
route | RouteSpec | No | — | OpenShift Route configuration. |
resources | corev1.ResourceRequirements | No | — | Manager pod resource requests/limits. |
podDisruptionBudget | PDBSpec | No | — | PDB for the LiteLLM Deployment. |
extraEnvVars | []corev1.EnvVar | No | — | Extra env vars passed to LiteLLM pods. |
ConfigSyncSpec
| Field | Type | Default | Enum |
|---|---|---|---|
enabled | bool | true | — |
mode | string | bidirectional | bidirectional, gitops-only, ui-only |
interval | string | 30s | — |
unmanagedResourcePolicy | string | preserve | preserve, prune, adopt |
conflictResolution | string | crd-wins | crd-wins, api-wins, manual |
auditChanges | bool | false | — |
RouterSettingsSpec
| Field | Type | Enum |
|---|---|---|
routingStrategy | string | simple-shuffle, least-busy, latency-based-routing, usage-based-routing |
numRetries | int | — |
timeout | int (seconds) | — |
retryAfter | int (seconds) | — |
allowedFails | int | — |
cooldownTime | int (seconds) | — |
SecuritySpec
| Field | Type | Description |
|---|---|---|
networkPolicies.enabled | bool | Generate default NetworkPolicies. |
podSecurity.readOnlyRootFilesystem | bool | Force read-only root FS on workload pods. |
podSecurity.runAsNonRoot | bool | Enforce non-root UID. |
status
| Field | Type | Description |
|---|---|---|
phase | string | Pending, Provisioning, Running, Degraded, Error. |
components.database.ready | bool | CNPG readiness. |
components.redis.ready | bool | Redis readiness. |
components.gateway.ready | bool | LiteLLMInstance readiness. |
components.gateway.litellmInstanceRef | string | Name of the generated LiteLLMInstance. |
components.gateway.endpoint | string | Reachable gateway URL. |
components.gateway.configSyncStatus | string | Status from upstream LiteLLM config sync. |
prerequisites.cnpg | bool | Is CNPG CRD installed? |
prerequisites.litellm | bool | Is LiteLLM CRD installed? |
conditions | []metav1.Condition | Standard conditions (Ready, DatabaseReady, etc.). |
Print columns
Phase, Age.
Example
yaml
apiVersion: operator.palena.ai/v1alpha1
kind: PalenaGateway
metadata:
name: production
namespace: palena
spec:
database:
managed:
instances: 1
storageSize: 10Gi
postgresql:
parameters:
shared_buffers: 256MB
redis:
managed:
replicas: 1
storageSize: 5Gi
gateway:
replicas: 2
masterKey: { name: litellm-keys, key: master }
saltKey: { name: litellm-keys, key: salt }
configSync:
enabled: true
mode: bidirectional
routerSettings:
routingStrategy: simple-shuffle
numRetries: 2
timeout: 60
ingress:
enabled: true
host: llm.example.com
className: nginx
tls:
enabled: true
certManager:
issuerRef:
name: letsencrypt-prod
kind: ClusterIssuer
security:
networkPolicies:
enabled: true