Skip to content

For the complete documentation index, see llms.txt.

Deployment configuration

This reference covers the PIGDeployment resource used by the default Helm installation. The manual Helm reference covers worker chart 0.3.0; its values are a separate interface.

apiVersion: governance.promptless.ai/v1alpha1
kind: PIGDeployment
metadata:
name: acme
namespace: pig

Keep the resource name, namespace, and registered deployment ID stable. The example generates analyzer Deployment and Service acme-analyzer. Secret and ConfigMap references resolve in the deployment’s namespace.

The bootstrap chart’s watchNamespace selects the analyzer namespace. Install one supervisor for that scope and keep its bootstrap values with your recovery records.

Fields are under spec.release:

FieldMeaning
channelstable follows every stable release, including major releases and schema migrations.
pausedfalse permits release transitions. true stops new transitions while preserving service and credential refresh.
pinnedVersionEmpty follows the channel; an exact supported release pins the target. A pause takes precedence.
confirmation.configMapRefName of a customer-owned ConfigMap in the deployment namespace with confirmations for the exact deployment and target release.

The policy coordinates the analyzer and supervisor together. A pin does not bypass compatibility or migration checks. See updates and recovery.

The confirmation ConfigMap binds releaseDigest and the Kubernetes object’s deploymentUID. Recovery confirmation uses confirmedAt, postgresRecoveryPoint, and objectRecoveryPoint. Operator capacity acknowledgement uses capacityConfirmedAt, capacityRequirementsDigest, and capacityEvidence. Supply the fields required by the target release; see confirm release prerequisites. These acknowledgements do not replace live dependency checks or mirror Terraform state.

Fields are under spec:

FieldMeaning
serviceAccountNameExisting analyzer ServiceAccount, such as pig-analyzer, with cloud data-access bindings.
podLabelsAdditional analyzer pod labels required by your platform, such as Azure’s workload identity opt-in.
hosted.runtimeURLOptional Promptless endpoint override. Defaults to https://api.gopromptless.ai.
hosted.installTokenSecretRefSecret name and key containing the deployment token.
endpoint.hostnameAnalyzer hostname reachable from enrolled hosts.
endpoint.ingressClassNameAn existing Kubernetes ingress class.
endpoint.tlsSecretNameOptional TLS Secret covering the hostname; omit when the ingress controller uses an external certificate, such as ACM.
endpoint.ingressAnnotationsController-specific annotations, including the encoded upload-body limit of at least 10 MiB.

The generated Service uses port 8080. The supervisor derives the registered configuration from the effective settings. The install token identifies the installation and is separate from individual host credentials.

Fields are under spec.storage. Configure postgres and exactly one of s3, azureBlob, or gcs.

FieldMeaning
postgres.dsnSecretRefSecret name and key containing the database connection string with TLS settings.
postgres.caConfigMapRefOptional ConfigMap name and key for a CA bundle mounted at /etc/pig/postgres-ca/ca.pem.
s3.region, s3.bucket, s3.prefixAWS region, bucket, and dedicated trace prefix. Uses the analyzer’s AWS workload identity.
azureBlob.accountURL, azureBlob.container, azureBlob.prefixHTTPS storage account URL, private container, and trace prefix. Uses Microsoft Entra Workload ID.
gcs.bucket, gcs.prefixGoogle Cloud Storage bucket and trace prefix. Uses Workload Identity Federation for GKE.

Storage configuration grants no cloud management authority. Changing a location does not move existing data. Plan that transition using the object-storage guidance.

Fields are under spec.analysis:

FieldMeaning
activationAtTimezone-aware ISO timestamp for analysis eligibility. Leave empty for ingestion only.
quietWindowHoursPositive interval after session activity before analysis; the example uses 0.5 hours.
model.provideropenai, azure_openai, or aws_bedrock.
model.authenticationapi_key, or aws_sigv4 for Bedrock.
model.baseURLA supported HTTPS Responses API endpoint.
model.nameThe model or deployment name available in your provider account.
model.apiKeySecretRefSecret name and key; omit for Signature Version 4.

The model settings are required even when activationAt is empty. An organization administrator selects the instruction repositories the analyzer reads in PIG Settings; the analyzer reads GitHub repositories with a main branch. Hub publishing support for another Git host does not imply analyzer or remediation support for it.

Use the model-provider reference for accepted endpoint shapes and authentication. GitHub issues and proposed fixes use write access granted to the connected GitHub App for the selected repositories. A successful analysis clone does not verify that access.

Review configuration through its owner, such as your GitOps repository. Validate the manifest against the installed release’s custom resource definition:

Terminal window
kubectl apply --dry-run=server -f pig-deployment.yaml

Apply the change and inspect kubectl describe pigdeployment acme --namespace pig. Repeat deployment verification after changes to storage, identities, model access, or endpoints. Schema validation alone cannot prove those dependencies are reachable.