Skip to content

PalenaGateway ​

A PalenaGateway is the cornerstone CR. One PalenaGateway produces one CloudNativePG Cluster, one Redis instance, and one LiteLLMInstance. Every other Palena CR (except PalenaMCPServer) references a PalenaGateway.

Short name: pgwAPI group: operator.palena.ai/v1alpha1Scope: Namespaced

spec ​

FieldTypeRequiredDefaultDescription
databaseDatabaseSpecYes—Select managed CNPG or external PostgreSQL.
redisRedisSpecYes—Select managed or external Redis.
gatewayGatewaySpecYes—LiteLLM gateway configuration.
securitySecuritySpecNo—NetworkPolicy / pod security toggles.
platformstringNoautoForce platform detection. Enum: auto, kubernetes, openshift.

DatabaseSpec ​

Exactly one of managed or external must be set.

FieldTypeDescription
managed.instancesint32 (≥1, default 1)CNPG cluster instance count.
managed.storageSizestring (default 10Gi)PVC size per instance.
managed.storageClassstringOptional StorageClass override.
managed.postgresql.parametersmap[string]stringPostgreSQL parameters passed through to CNPG.
managed.backup.enabledboolEnable Barman-based backups.
managed.backup.schedulestringCron schedule.
managed.backup.retentionPolicystringCNPG retention policy string.
managed.backup.barmanObjectStore.s3Credentials.secretRef.namestringSecret with S3 credentials.
external.connectionSecretRefSecretKeyRefSecret key holding a full postgres://… URL.

RedisSpec ​

Exactly one of managed or external must be set.

FieldTypeDefaultDescription
managed.replicasint321Redis replica count.
managed.storageSizestring5GiPVC size.
external.hoststring—Redis host (when using host+port).
external.portint326379Redis port.
external.passwordSecretRefSecretKeyRef—Optional password secret.
external.connectionSecretRefSecretKeyRef—Alternative: full redis://… URL.

GatewaySpec ​

FieldTypeRequiredDefaultDescription
replicasint32Yes1LiteLLM Deployment replicas.
imageImageSpecNo—Override LiteLLM image.
masterKeySecretKeyRefYes—Master API key secret.
saltKeySecretKeyRefNo—Salt secret (highly recommended).
configSyncConfigSyncSpecNo—LiteLLM bidirectional config sync.
autoscalingAutoscalingSpecNo—HPA configuration.
routerSettingsRouterSettingsSpecNo—LiteLLM routerSettings passthrough.
generalSettingsGeneralSettingsSpecNo—LiteLLM generalSettings passthrough.
ingressIngressSpecNo—Ingress configuration.
routeRouteSpecNo—OpenShift Route configuration.
resourcescorev1.ResourceRequirementsNo—Manager pod resource requests/limits.
podDisruptionBudgetPDBSpecNo—PDB for the LiteLLM Deployment.
extraEnvVars[]corev1.EnvVarNo—Extra env vars passed to LiteLLM pods.

ConfigSyncSpec ​

FieldTypeDefaultEnum
enabledbooltrue—
modestringbidirectionalbidirectional, gitops-only, ui-only
intervalstring30s—
unmanagedResourcePolicystringpreservepreserve, prune, adopt
conflictResolutionstringcrd-winscrd-wins, api-wins, manual
auditChangesboolfalse—

RouterSettingsSpec ​

FieldTypeEnum
routingStrategystringsimple-shuffle, least-busy, latency-based-routing, usage-based-routing
numRetriesint—
timeoutint (seconds)—
retryAfterint (seconds)—
allowedFailsint—
cooldownTimeint (seconds)—

SecuritySpec ​

FieldTypeDescription
networkPolicies.enabledboolGenerate default NetworkPolicies.
podSecurity.readOnlyRootFilesystemboolForce read-only root FS on workload pods.
podSecurity.runAsNonRootboolEnforce non-root UID.

status ​

FieldTypeDescription
phasestringPending, Provisioning, Running, Degraded, Error.
components.database.readyboolCNPG readiness.
components.redis.readyboolRedis readiness.
components.gateway.readyboolLiteLLMInstance readiness.
components.gateway.litellmInstanceRefstringName of the generated LiteLLMInstance.
components.gateway.endpointstringReachable gateway URL.
components.gateway.configSyncStatusstringStatus from upstream LiteLLM config sync.
prerequisites.cnpgboolIs CNPG CRD installed?
prerequisites.litellmboolIs LiteLLM CRD installed?
conditions[]metav1.ConditionStandard conditions (Ready, DatabaseReady, etc.).

Phase, Age.

Example ​

yaml
apiVersion: operator.palena.ai/v1alpha1
kind: PalenaGateway
metadata:
  name: production
  namespace: palena
spec:
  database:
    managed:
      instances: 1
      storageSize: 10Gi
      postgresql:
        parameters:
          shared_buffers: 256MB
  redis:
    managed:
      replicas: 1
      storageSize: 5Gi
  gateway:
    replicas: 2
    masterKey: { name: litellm-keys, key: master }
    saltKey:   { name: litellm-keys, key: salt }
    configSync:
      enabled: true
      mode: bidirectional
    routerSettings:
      routingStrategy: simple-shuffle
      numRetries: 2
      timeout: 60
    ingress:
      enabled: true
      host: llm.example.com
      className: nginx
      tls:
        enabled: true
        certManager:
          issuerRef:
            name: letsencrypt-prod
            kind: ClusterIssuer
  security:
    networkPolicies:
      enabled: true

Released under the Apache 2.0 License. "Palena" is a trademark of bitkaio LLC.