Skip to content

Production install

The development install bundles Postgres, Redis/Valkey, and an object store for convenience. A production install brings those as managed/external services and turns on the hardening dials.

  • Kubernetes v1.31+ with etcd encryption at rest enabled.
  • Knative Serving (for the serving execution model); KEDA if you use queue-depth scaling.
  • External state you bring: a managed Postgres (control-plane state — runs, versions, datasets, cost), a managed Redis/Valkey (the State Layer for session memory), and an S3-compatible object store (blobs, datasets, checkpoints).
  • A base domain + TLS (cert-manager or your ingress’ certificates).
  • At least one model provider key in your secret backend (or use the mock provider first).
Terminal window
helm install ctxmesh oci://ghcr.io/ctxmesh/charts/ctxmesh \
--version 0.1.0-beta.8 \
--namespace ctxmesh --create-namespace \
--set profile=production \
--set postgres.dsn=... \
--set stateLayer.redis.addr=... \
--set objectStore.endpoint=... \
--set baseDomain=agents.example.com

The profile=production dial flips the platform from “integrated dev stores” to “bring-your-own,” and turns on the availability guards (see High availability).

  • The CRDs and the controller (operator).
  • The gateway (model routing + budgets).
  • The console / BFF.
  • A run worker (durable run execution) — required in production.
  1. Verify the control plane is Available with 0 restarts.
  2. Apply your first ModelRoute + SecretBinding.
  3. Bind RBAC personas per namespace.
  4. Wire your trace backend and review the security posture.

High availability · Upgrade & versioning · Helm values · Secrets