Sign inSign up

classifyre/classifyre-core

By classifyre

โ€ขUpdated about 9 hours ago

Classifyre Helm chart for production Kubernetes deployments

Helm
Security
Machine learning & AI
Data science
0

2.1K

classifyre/classifyre-core repository overview

Classifyre

โ Classifyre Helm Chart

Production Kubernetes deployment of the open-source Classifyre investigation platform โ€” web UI, API, worker, ephemeral scan jobs and PostgreSQL.

Classifyre turns the data scattered across the systems you already run โ€” file shares, Confluence, Jira, SharePoint, S3, Git repositories, databases โ€” into investigations you can act on: detectors raise findings (leaked secrets, PII, security risks), and analysts work them through inquiries, duplicates, cases and hypotheses, with an AI autopilot doing the legwork.

This chart (classifyre/classifyre-core) deploys Classifyre on Kubernetes 1.28+ (Helm 3.12+): the web UI and API deployments, the background worker, ephemeral classifyre/cliโ  scan Jobs with shared uv-cache, ingress/TLS, autoscaling, RBAC โ€” and PostgreSQL (embedded for trials, external or CloudNativePG for production). It runs the same classifyre/apiโ  / classifyre/webโ  / classifyre/cliโ  images as the all-in-one Docker imageโ , as separate, independently scalable workloads.

๐Ÿ“š Full documentation: chart source, values reference and production guidance at https://github.com/classifyre/classifyre/tree/develop/helmโ  ยท product docs at https://docs.classifyre.comโ  (Kubernetes guideโ )


โ Installation

No helm repo add โ€” the chart is published as OCI (Helm 3.8+ speaks OCI natively). Pin --version to the release you want.

Trial (embedded Postgres, single namespace):

helm upgrade --install classifyre \
  oci://registry-1.docker.io/classifyre/classifyre-core \
  --version '<version>' \
  -n classifyre --create-namespace

Production (external Postgres, pinned images):

kubectl create namespace classifyre

helm upgrade --install classifyre \
  oci://registry-1.docker.io/classifyre/classifyre-core \
  --version '<version>' \
  -n classifyre \
  -f your-values.yaml \
  --set api.image.tag='<version>' \
  --set api.cliJobs.image.tag='<version>' \
  --set frontend.image.tag='<version>'

Start your-values.yaml from values-production.example.yamlโ  โ€” a commented starting point, not a drop-in file.

External Postgres:

kubectl -n classifyre create secret generic classifyre-db --from-literal=password='<db-password>'

helm upgrade --install classifyre oci://registry-1.docker.io/classifyre/classifyre-core \
  -n classifyre --version '<version>' \
  --set postgres.mode=external \
  --set postgres.external.host='<db-host>' \
  --set postgres.external.port=5432 \
  --set postgres.external.database='classifyre' \
  --set postgres.external.username='classifyre' \
  --set postgres.external.existingSecret='classifyre-db' \
  --set postgres.external.existingSecretPasswordKey='password'

CloudNativePG:

helm upgrade --install classifyre oci://registry-1.docker.io/classifyre/classifyre-core \
  -n classifyre --create-namespace --version '<version>' \
  --set postgres.mode=cnpg \
  --set postgres.cnpg.appPassword='<app-password>'

โ Key values

ValueDefaultPurpose
postgres.modeembeddedembedded (trial only), external, or cnpg. Production: external/cnpg.
api.image.tag / frontend.image.tag / api.cliJobs.image.tagchart appVersionPin all three to the same immutable version in production (never latest).
api.maskedConfigEncryption.existingSecretโ€”Existing Secret holding CLASSIFYRE_MASKED_CONFIG_KEY (recommended); otherwise the chart auto-generates one.
api.maxOldSpaceSizeMb1536V8 heap cap for API+worker. Keep โ‰ˆ 0.75 ร— api.resources.limits.memory.
api.cliJobs.resources.*500mโ€“2 CPU, 4Gi memCPU/memory requests/limits per scan job.
api.cliJobs.huggingFace.existingSecret""Secret with an HF_TOKEN to raise model-download rate limits.
api.autoscaling.*enabled, 2โ€“10 replicasHPA for the API deployment.

Full values reference: helm/classifyreโ  (every value is documented inline in values.yaml).

โ Production checklist

  1. postgres.mode=external or cnpg (embedded is local/dev convenience).
  2. Pin all image tags to immutable versions.
  3. Configure ingress TLS, resource requests/limits and scheduling per environment.
  4. Provide CLASSIFYRE_MASKED_CONFIG_KEY via a Helm-managed or existing Secret.
  5. A namespace export moves work between the Docker and Kubernetes distributions โ€” no lock-in.

Classifyre is open source: https://github.com/classifyre/classifyreโ  ยท Docs: https://docs.classifyre.comโ 

Tag summary

Content type

Helm

Digest

sha256:f61085779โ€ฆ

Size

57.3 kB

Last updated

about 9 hours ago

helm pull oci://registry-1.docker.io/classifyre/classifyre-core --version 0.6.7