feat(langfuse): back object storage with SeaweedFS + restricted PSS - #10
Open
Mushtaq-BGA wants to merge 1 commit into
Open
Mushtaq-BGA wants to merge 1 commit into
Mushtaq-BGA wants to merge 1 commit into
Conversation
Companion to the enterprise-ai-solutions MinIO->SeaweedFS object_store migration. - Point langfuse S3 (event upload, batch export, media) at the SeaweedFS S3 endpoint with path-style addressing; read scoped creds from the object-store-credentials secret. - Set the chart's shared podSecurityContext/securityContext (uid 1001, seccomp RuntimeDefault, drop ALL) so web/worker pass restricted PSS.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Change
Companion to the
enterprise-ai-solutionsMinIO→SeaweedFSobject_storemigration — makes langfuse consume the shared SeaweedFS object store.object-store-credentialssecret.podSecurityContext/securityContext(uid 1001, seccompRuntimeDefault, drop ALL) so web/worker pass restricted PSS. Previously these were set underweb/workersubkeys, which the chart ignores, so the pods were rejected under restricted PSS.Dependency
Requires the SeaweedFS object store + the
object-store-credentialssecret keys from the enterprise-ai-solutions migration.Validation
litellm-mode install + validate exit 0; langfuse web/worker run under restricted PSS and read/write the
langfusebucket on SeaweedFS.