Skip to content

PalenaObservability ​

A PalenaObservability deploys a LangfuseInstance tied to an existing PalenaGateway and wires a Langfuse callback into the gateway's LiteLLMInstance so every request is traced automatically.

Short name: pobsAPI group: operator.palena.ai/v1alpha1Scope: Namespaced

spec ​

FieldTypeRequiredDescription
gatewayRefLocalObjectReferenceYesTarget PalenaGateway.
langfuseLangfuseSpecYesLangfuse configuration.

LangfuseSpec ​

FieldTypeRequiredDescription
imageImageSpecNoLangfuse image override.
web.replicasint32NoWeb component replicas. Default 1.
web.resourcescorev1.ResourceRequirementsNoWeb resource requests/limits.
worker.replicasint32NoWorker replicas. Default 1.
worker.resourcescorev1.ResourceRequirementsNoWorker resources.
authLangfuseAuthSpecNoNextAuth / OIDC / seed user config.
databaseLangfuseDatabaseSpecNoPostgres backend. When nil, reuses the gateway's CNPG cluster.
clickhouseLangfuseClickHouseSpecYesClickHouse backend.
redisLangfuseRedisSpecNoRedis/Valkey backend. Defaults to managed.
blobStorageLangfuseBlobStorageSpecYesObject store for traces.
ingressIngressSpecNoIngress configuration.
routeRouteSpecNoOpenShift Route.

LangfuseAuthSpec ​

FieldTypeRequiredDescription
nextAuthUrlstringNoNextAuth canonical URL. Auto-derived from Ingress when empty.
disableSignupboolNoDisable public signups.
oidcOIDCSpecNoOIDC provider config.
initUser.emailstringWhen initUser setSeed admin email.
initUser.passwordSecretKeyRefWhen initUser setSeed admin password.
initUser.orgNamestring (default Default)NoSeed organization name.
initUser.projectNamestring (default Default)NoSeed project name.

LangfuseDatabaseSpec ​

Exactly one of cloudnativepg or external may be set. Omit entirely to reuse the gateway's CNPG cluster with database langfuse.

FieldTypeDefaultDescription
cloudnativepg.namestring—CNPG Cluster name.
cloudnativepg.namespacestringcurrent namespaceCNPG Cluster namespace.
cloudnativepg.databasestringlangfuseTarget database inside the cluster.
external.secretRefSecretKeysRef—Secret with connection parameter keys.

LangfuseClickHouseSpec ​

Exactly one of managed or external must be set.

FieldTypeDefaultDescription
managed.shardsint321Shard count.
managed.replicasint321Replica count.
managed.storageSizestring50GiPVC size.
managed.storageClassstring—Optional StorageClass.
external.secretRefSecretKeysRef—External ClickHouse credentials.

LangfuseBlobStorageSpec ​

provider must be one of s3, azure, gcs; exactly one matching sub-block must be set.

FieldTypeDescription
providerstrings3, azure, gcs.
s3.endpointstringCustom S3 endpoint (for MinIO etc.).
s3.regionstringAWS region.
s3.bucketstringRequired.
s3.forcePathStyleboolRequired for most non-AWS endpoints.
s3.credentialsSecretKeysRefMust include accessKeyId, secretAccessKey.
azure.storageAccountNamestringAzure storage account.
azure.containerNamestringAzure container.
azure.credentialsSecretKeysRefAccount credentials.
gcs.bucketNamestringGCS bucket.
gcs.projectIdstringGCP project ID.
gcs.credentialsSecretKeysRefService account key.

status ​

FieldTypeDescription
readyboolOverall readiness.
langfuseInstanceRefstringName of generated LangfuseInstance.
endpointstringPublic Langfuse URL.
callbackConfiguredboolTrue when the gateway's LiteLLMInstance has been patched.
conditions[]metav1.ConditionStandard conditions (PrerequisitesMet, GatewayReady, LangfuseReady, CallbackConfigured, Ready).

Ready, Callback, Endpoint, Age.

Example ​

yaml
apiVersion: operator.palena.ai/v1alpha1
kind: PalenaObservability
metadata:
  name: traces
  namespace: palena
spec:
  gatewayRef:
    name: production
  langfuse:
    web:
      replicas: 2
    worker:
      replicas: 1
    clickhouse:
      managed:
        shards: 1
        replicas: 2
        storageSize: 100Gi
    blobStorage:
      provider: s3
      s3:
        endpoint: https://minio.internal
        region: us-east-1
        bucket: langfuse-traces
        forcePathStyle: true
        credentials:
          name: langfuse-s3
          keys:
            accessKeyId: AWS_ACCESS_KEY_ID
            secretAccessKey: AWS_SECRET_ACCESS_KEY
    auth:
      disableSignup: true
      initUser:
        email: admin@example.com
        password:
          name: langfuse-admin
          key: password
    ingress:
      enabled: true
      host: langfuse.example.com
      className: nginx

Lifecycle notes ​

  • The controller adds a langfuse database to the gateway's existing CNPG cluster via managed.databases — it does not create a second Cluster.
  • Once the LangfuseInstance becomes Ready, the controller seeds an org/project and stores the generated API keys in a Secret named <obs-name>-langfuse-apikeys.
  • It then patches the gateway's LiteLLMInstance spec.callbacks.langfuse block. The deletion finalizer removes that callback block before allowing GC to proceed.

Released under the Apache 2.0 License. "Palena" is a trademark of bitkaio LLC.