Install Konfidence
Install the Konfidence operator and API server from one Helm chart. After verifying these services, publish the dashboard and API, choose a deployer, and configure registry access.
These steps are for the administrator of the Kubernetes installation. Review System architecture and Plan for high availability before choosing your configuration.
For a local test cluster, use the Quickstart instead. It sets up a kind cluster with everything installed.
Prerequisites
A Kubernetes cluster and
kubectlaccess with permission to install charts and their cluster-scoped resources. Check connectivity withkubectl cluster-info; it prints the Kubernetes control plane address.Helm with OCI registry support, version 3.8 or later. Check:
helm versionprints 3.8 or higher.The Gateway API CRDs, version 1.4.1. Check:
kubectl get crd gateways.gateway.networking.k8s.iofinds the CRD. Install:bashkubectl apply --server-side -f https://github.com/kubernetes-sigs/gateway-api/releases/download/v1.4.1/standard-install.yamlFlux with its source controller. Check:
kubectl get deployment source-controller -n flux-systemshows one available replica. Install:bashkubectl apply -f https://github.com/fluxcd/flux2/releases/latest/download/install.yaml kubectl wait deployment/source-controller \ --namespace flux-system \ --for=condition=Available \ --timeout=180s
Install the Konfidence services
Set the Konfidence version and target namespace:
export KONFIDENCE_VERSION=0.0.1-alpha.1
export KONFIDENCE_NAMESPACE=konfidence-systemInstall the chart:
helm upgrade --install konfidence oci://ghcr.io/konfidence-project/charts/konfidence \
--version "$KONFIDENCE_VERSION" \
--namespace "$KONFIDENCE_NAMESPACE" \
--create-namespace \
--set image.repository=ghcr.io/konfidence-project/konfidence-operator \
--set image.tag="$KONFIDENCE_VERSION" \
--set api.oidc.enabled=false \
--set webhook.enabled=false \
--waitThe two enabled=false flags keep the first install self-contained. With the chart defaults, the API server refuses to start without an OIDC issuer URL. The admission webhook needs a TLS Secret named konfidence-webhook-server-cert. Give teams access to the dashboard and API turns OIDC on. Enable the admission webhook with cert-manager below creates the Secret. Every chart value is listed in the Helm values reference.
Verify the installation
kubectl get deployments -n "$KONFIDENCE_NAMESPACE"You see konfidence and konfidence-api with all replicas available.
Enable the admission webhook with cert-manager
The webhook validates Project, Landscape, and DeploymentTarget resources before the API server stores them. It serves TLS from the Secret konfidence-webhook-server-cert, and the Kubernetes API server must trust the certificate's CA. cert-manager issues the certificate and injects the CA into the webhook configuration.
Prerequisite: cert-manager runs in the cluster. Check: kubectl get crd certificates.cert-manager.io finds the CRD.
Create a self-signed issuer and the certificate in the Konfidence namespace. Save the following as webhook-cert.yaml:
apiVersion: cert-manager.io/v1
kind: Issuer
metadata:
name: konfidence-webhook-selfsigned
namespace: konfidence-system
spec:
selfSigned: {}
---
apiVersion: cert-manager.io/v1
kind: Certificate
metadata:
name: konfidence-webhook-server-cert
namespace: konfidence-system
spec:
secretName: konfidence-webhook-server-cert
issuerRef:
name: konfidence-webhook-selfsigned
dnsNames:
- konfidence-webhook-service.konfidence-system.svc
- konfidence-webhook-service.konfidence-system.svc.cluster.localApply it and wait for the Secret:
kubectl apply -f webhook-cert.yaml
kubectl wait certificate/konfidence-webhook-server-cert \
--namespace konfidence-system \
--for=condition=Ready \
--timeout=60sThe Secret konfidence-webhook-server-cert now holds tls.crt and tls.key. Enable the webhook and let cert-manager inject the CA. Save the following as webhook-values.yaml:
webhook:
enabled: true
annotations:
cert-manager.io/inject-ca-from: konfidence-system/konfidence-webhook-server-certRun the install command again with --values webhook-values.yaml and without --set webhook.enabled=false:
helm upgrade --install konfidence oci://ghcr.io/konfidence-project/charts/konfidence \
--version "$KONFIDENCE_VERSION" \
--namespace "$KONFIDENCE_NAMESPACE" \
--create-namespace \
--set image.repository=ghcr.io/konfidence-project/konfidence-operator \
--set image.tag="$KONFIDENCE_VERSION" \
--set api.oidc.enabled=false \
--values webhook-values.yaml \
--waitKeep login sessions in PostgreSQL
The API server keeps login sessions in memory by default. A restart signs every user out, and two replicas do not share sessions. To keep sessions across restarts and replicas, store them in PostgreSQL.
Prerequisite: a PostgreSQL database the API server can reach, and its connection string in the URL form postgres://konfidence:<PASSWORD>@postgres.example.com:5432/konfidence.
Store the connection string in a Secret:
kubectl create secret generic konfidence-api-db \
--namespace konfidence-system \
--from-literal=connection='postgres://konfidence:<PASSWORD>@postgres.example.com:5432/konfidence'Save the following as session-values.yaml. The chart exposes the store type as a value and reads the connection string from the environment:
api:
session:
storageType: db-pg
env:
- name: API_DB_CONNECTION
valueFrom:
secretKeyRef:
name: konfidence-api-db
key: connectionRun the install command again with --values session-values.yaml. The API server refuses to start when storageType is db-pg and the connection string is empty. Pool sizes are set under api.database.
Next steps
- Give teams access to the dashboard and API publishes both and enables login through your identity provider.
- Choose a deployer selects the capabilities your applications need. Then install the Kubernetes deployer for Helm and Kustomize artifacts.
- Connect artifact registries configures control plane credentials now and deployer credentials after you create a landscape.