Kubernetes & Helm
Install the Edgee AI Gateway on Kubernetes with the public Helm chart.
Install the gateway on Kubernetes with the public Helm chart edgee-ai/gateway.
- Requirements: Kubernetes 1.24+ and Helm 3.8+.
- Chart:
edgee-ai/gateway(chart0.2.0, appVersion1.9.0). - Image:
ghcr.io/edgee-ai/gateway(public, anonymous pull — no image pull secrets). - The container listens on
8080, runs non-root (uid65534) with a read-only root filesystem and a/tmpemptyDir. Health:GET /status.
Install
The commands are the same in both modes — the chart is public. Author a values.yaml (see below), then:
helm repo add edgee-ai https://edgee-ai.github.io/helm-charts
helm repo update
helm upgrade --install gateway edgee-ai/gateway \
--namespace edgee --create-namespace \
-f values.yaml
Values
Pick the mode that matches your deployment. Connected is the default once licenseKey is set. Get licenseKey (and, in connected mode, signatureKey) from the Edgee Console under Org settings → On-Premise → Reveal deployment secrets.
The gateway pulls its configuration from the Edgee API and keeps it in sync (apiSync.enabled: true), and exports usage metering automatically — see Common values below.
gateway:
# Connected: pull config from the Edgee API and keep it in sync.
apiSync:
enabled: true
intervalSecs: 15
# Reveal these in the console; keep them secret (or use gateway.existingSecret).
licenseKey: "" # -> LICENSE_KEY
signatureKey: "" # -> EDGEE_SIGNATURE_KEY
Common values
| Path | Purpose |
|---|---|
image.{repository,tag,pullPolicy} | Optional — override the chart's default image and tag. Not needed for a normal install. |
gateway.apiSync.{enabled,intervalSecs} | Connected-mode config sync. enabled defaults to true; set false to opt out into headless/air-gapped mode. |
gateway.telemetry.{enabled,otlpEndpoint} | Telemetry export. |
gateway.usage.{otlpEndpoint,otlpHeaders,useLicenseAuth} | Usage metering export. Connected mode defaults to https://onprem-logs.edgee.ai/v1/logs, authenticated with your license key. useLicenseAuth (default true) controls whether that auth is still sent when otlpEndpoint points at your own collector. |
gateway.licenseKey / gateway.signatureKey | Deployment secrets (env LICENSE_KEY / EDGEE_SIGNATURE_KEY). |
gateway.configContent / gateway.providerKeysContent / gateway.providerKeysEnabled | Headless config and provider keys. |
gateway.existingSecret / gateway.existingConfigSecret | Reference pre-created Secrets instead of inline values. |
service.type | Service type (defaults to ClusterIP). |
ingress.enabled | Optional ingress. |
Secrets
Create the credentials Secret out of band with kubectl and point values.yaml at it via gateway.existingSecret — the chart never sees the plaintext. Required keys:
| Key | Required | Notes |
|---|---|---|
LICENSE_KEY | Always | From the Console — see Values. |
EDGEE_SIGNATURE_KEY | Connected mode only | Optional at the Secret level — the chart mounts it as an optional env var, so a headless Secret can omit it. |
provider_keys.toml | Only if gateway.providerKeysEnabled: true | Contents of your provider keys file (flat TOML). |
kubectl -n edgee create secret generic gateway-secret \
--from-literal=LICENSE_KEY='<license key from console>' \
--from-literal=EDGEE_SIGNATURE_KEY='<signature key from console>'
gateway:
existingSecret: gateway-secret
Ingress
The Service defaults to ClusterIP. To expose the gateway outside the cluster, either front it with your own ingress controller or set ingress.enabled: true and configure the chart's ingress values. The gateway serves traffic on port 8080.
Verify
Confirm the pod is running and healthy:
kubectl -n edgee get pods
kubectl -n edgee port-forward svc/gateway 8080:8080
curl http://localhost:8080/status
Upgrading
New gateway versions ship as new chart releases. Pull the latest chart and re-run the same install command — helm upgrade --install applies the change in place:
helm repo update
helm upgrade --install gateway edgee-ai/gateway \
--namespace edgee \
-f values.yaml
To pin a specific release, pass --version <chart-version>.
Verify model traffic
After the health check, send an authenticated test model request. Then configure the CLI gateway endpoint and verify an agent request. A healthy process does not prove that provider credentials or the model registry are correct.