Deploy on Kubernetes
This page walks through deploying KMI on Kubernetes with Helm. Complete the prerequisites first.
Installation Steps
Section titled “Installation Steps”-
Extract the package.
Terminal window tar -xzf kmi-airgap-kubernetes-vX.x-amd64.tar.gzcd kmi-airgap-kubernetes-vX.x-amd64 -
Create the configuration file.
Copy the Kubernetes-specific example configuration and edit it:
Terminal window cp .env-k8s.example .envOpen
.envin your preferred editor and configure all required values. -
Configure the container registry.
Add your container registry details to
.env:Terminal window # =============================================================================# CONTAINER REGISTRY CONFIGURATION# =============================================================================# Supported: ECR, GCR, ACR, Docker Hub, Harbor, Nexus, JFrog, GitLab, QuayREGISTRY_URL=your-registry-urlIMAGE_TAG=your-image-tagIMAGE_PULL_SECRET=your-pull-secret # Required for Docker Hub, Harbor, Nexus, JFrog -
Configure a secret manager (recommended) or set secrets in
.env.For production deployments, a cloud secret manager is recommended for storing sensitive values (passwords, keys, tokens). If not configured, the deployment script falls back to reading sensitive values directly from the
.envfile.Terminal window # =============================================================================# SECRET MANAGER CONFIGURATION (Optional - recommended for production)# =============================================================================# Supported: aws, gcp, azure, vault# Set to 'false' to read all sensitive values from this .env file insteadSECRET_MANAGER=falseSECRET_PREFIX=kmiSECRET_REGION= # AWS only (optional)GCP_PROJECT_ID= # GCP only (auto-detected from gcloud config if not set)AZURE_KEY_VAULT_NAME= # Azure Key Vault only# VAULT_ADDR=https://vault.example.com:8200 # HashiCorp Vault onlyFor the full secret-manager setup, see Secret Managers.
-
Configure application settings.
Terminal window # =============================================================================# APPLICATION CONFIGURATION# =============================================================================NAMESPACE=kmiRELEASE_NAME=kafka-mobility-intelligencePLATFORM= # Auto-detect if empty (eks, gke, aks, openshift, onprem)# Service emails (update with your domain)DATA_REPLICATION_SERVICE_EMAIL=datarepl@yourcompany.comMONITORING_SERVICE_EMAIL=monitoring@yourcompany.comCOLLECTOR_SERVICE_EMAIL=collector@yourcompany.com# Deployment optionsAUTO_LOGIN=false # Auto-login to cloud registriesAUTO_CREATE_REPO=false # Auto-create registry reposKEEP_VALUES=false # Keep Helm values on upgradeSKIP_LOAD=false # Skip loading imagesSKIP_PUSH=false # Skip pushing images -
Configure OIDC / SSO (optional).
To enable Single Sign-On via OpenID Connect, add the following to your
.env:Terminal window # =============================================================================# OIDC / SSO CONFIGURATION (Optional)# =============================================================================# Supported providers: Azure AD (Entra ID), Keycloak, Okta, Auth0, etc.OIDC_ENABLED=trueOIDC_ISSUER_URL=https://login.microsoftonline.com/<tenant-id>/v2.0OIDC_CLIENT_ID=your_client_idOIDC_REDIRECT_URI=https://your-app-url/api/auth/oidc/callbackOIDC_SCOPES=openid email profileOIDC_BUTTON_LABEL=Sign in with SSONEXTAUTH_URL=https://your-app-url -
Configure sensitive values.
Generate secure values and store them in your secret manager or directly in your
.envfile:Terminal window # Generate JWT secret (16 bytes hex)openssl rand -hex 16# Generate AES key (32 bytes hex)openssl rand -hex 32Required secrets:
Secret Key Description MONGO_USERNAME MongoDB root username MONGO_PASSWORD MongoDB root password ADMIN_PASSWORD KMI admin user password JWT_SECRET JWT signing secret (16 bytes hex) AES_KEY AES encryption key (32 bytes hex) OIDC_CLIENT_SECRET OIDC client secret (only if OIDC_ENABLED=true)If not using a secret manager, set these directly in
.env:Terminal window # =============================================================================# SENSITIVE VALUES (set here if not using a secret manager)# =============================================================================MONGO_USERNAME=your_mongo_usernameMONGO_PASSWORD=your_mongo_passwordADMIN_PASSWORD=your_admin_passwordJWT_SECRET=your_generated_jwt_secretAES_KEY=your_generated_aes_key# OIDC_CLIENT_SECRET=your_oidc_client_secret # Only if OIDC_ENABLED=true -
Authenticate to the registry.
For cloud registries (no
IMAGE_PULL_SECRETneeded):Terminal window # AWS ECRaws ecr get-login-password --region <region> | docker login --username AWS --password-stdin <registry># GCP Artifact Registry / GCRgcloud auth configure-docker# Azure ACRaz acr login --name <registry-name>For private registries (Docker Hub, Harbor, Nexus, JFrog), also create a pull secret:
Terminal window docker login <registry-url>kubectl create namespace kmikubectl create secret docker-registry <your-pull-secret> \--namespace=kmi \--docker-server=<registry-url> \--docker-username=<username> \--docker-password=<password> -
Run the deployment script.
Simple deployment, everything from
.env:Terminal window ./k8s-deploy.shWith custom options (rarely needed):
Terminal window ./k8s-deploy.sh --env-file /path/to/custom.env --chart /path/to/custom-chartThe script loads Docker images from
images.tar.gz, pushes images to your registry (if needed), auto-detects the platform and applies the correct values overlay, updates configuration from.env, creates Kubernetes secrets, and deploys the application using Helm.
Platform-Specific Deployment
Section titled “Platform-Specific Deployment”All platforms use the same deployment process. Configure your platform-specific settings in .env, then run ./k8s-deploy.sh.
# In .env fileREGISTRY_URL=123456789.dkr.ecr.us-west-2.amazonaws.comPLATFORM=eksAUTO_LOGIN=trueAUTO_CREATE_REPO=true
# Then run./k8s-deploy.sh# In .env fileREGISTRY_URL=us-west1-docker.pkg.dev/my-project/kmiPLATFORM=gkeAUTO_LOGIN=true
# Then run./k8s-deploy.sh# In .env fileREGISTRY_URL=myregistry.azurecr.ioPLATFORM=aksAUTO_LOGIN=true
# Then run./k8s-deploy.shFor Docker Hub, Harbor, Nexus, or JFrog:
# In .env fileREGISTRY_URL=docker.io/yourorgIMAGE_PULL_SECRET=your-registry-secret
# Then run (after creating the secret)./k8s-deploy.shPost-Installation Verification
Section titled “Post-Installation Verification”-
Verify pod status.
Wait approximately 30-60 seconds for all services to initialize, then verify:
Terminal window kubectl get pods -n kmiYou should see these pods running:
kafka-mobility-intelligence-mongodb-0kafka-mobility-intelligence-frontend-xxxxxxxxxx-xxxxxkafka-mobility-intelligence-backend-xxxxxxxxxx-xxxxx
-
Check services.
Terminal window kubectl get services -n kmiExpected services:
kafka-mobility-intelligence-mongodb(ClusterIP, Port 27017)kafka-mobility-intelligence-frontend(ClusterIP, Port 3000)kafka-mobility-intelligence-backend(ClusterIP, Ports 18002-18004)
-
Check ingress.
Terminal window kubectl get ingress -n kmi -
Access the application.
The application is accessible only from within your private network.
Via ingress (from VPN or internal network):
Terminal window INGRESS_URL=$(kubectl get ingress kafka-mobility-intelligence-frontend -n kmi -o jsonpath='{.spec.rules[0].host}')echo "Access URL: http://$INGRESS_URL"Via port forward (for local testing):
Terminal window kubectl port-forward svc/kafka-mobility-intelligence-frontend 3000:3000 -n kmi# Open http://localhost:3000 -
Verify application health.
Terminal window kubectl logs -f deployment/kafka-mobility-intelligence-frontend -n kmikubectl logs -f deployment/kafka-mobility-intelligence-backend -n kmiLog in with username
admin(or your configuredADMIN_USER_ID) and your configured admin password.
Configuration Reference
Section titled “Configuration Reference”The complete .env file structure:
# =============================================================================# MONGODB CONFIGURATION# =============================================================================MONGODB_DATABASE=kmimigration
# =============================================================================# ADMIN USER# =============================================================================ADMIN_USER_ID=adminADMIN_EMAIL=admin@yourcompany.com
# =============================================================================# SERVICE EMAILS# =============================================================================DATA_REPLICATION_SERVICE_EMAIL=datarepl@yourcompany.comMONITORING_SERVICE_EMAIL=monitoring@yourcompany.comCOLLECTOR_SERVICE_EMAIL=collector@yourcompany.com
# =============================================================================# APPLICATION SETTINGS# =============================================================================JWT_EXPIRES_IN=8hJWT_EXPIRES_INT=8USE_SECURE_COOKIES=false
# =============================================================================# SERVICE PORTS# =============================================================================MONGODB_PORT=27017FRONTEND_PORT=3000DATA_REPLICATOR_PORT=18002MONITORING_SERVICE_PORT=18003MONITORING_SOCKET_PORT=18004
# =============================================================================# CONTAINER REGISTRY# =============================================================================REGISTRY_URL=your-registry-urlIMAGE_TAG=your-image-tagIMAGE_PULL_SECRET=your-pull-secret
# =============================================================================# KUBERNETES SETTINGS# =============================================================================NAMESPACE=kmiRELEASE_NAME=kafka-mobility-intelligencePLATFORM= # Auto-detect if empty
# =============================================================================# DEPLOYMENT OPTIONS# =============================================================================AUTO_LOGIN=falseAUTO_CREATE_REPO=falseKEEP_VALUES=falseRECREATE_MONGODB_STATEFULSET=falseSKIP_LOAD=falseSKIP_PUSH=false
# =============================================================================# SECRET MANAGER (Optional - recommended for production)# =============================================================================SECRET_MANAGER=false # aws, gcp, azure, vault, or false (.env fallback)SECRET_PREFIX=kmiSECRET_REGION=GCP_PROJECT_ID=AZURE_KEY_VAULT_NAME=VAULT_ADDR=
# =============================================================================# SENSITIVE VALUES (secret manager or .env - secret manager takes priority)# =============================================================================MONGO_USERNAME=MONGO_PASSWORD=ADMIN_PASSWORD=JWT_SECRET=AES_KEY=OIDC_CLIENT_SECRET= # Only if OIDC_ENABLED=true
# =============================================================================# OIDC / SSO CONFIGURATION (Optional)# =============================================================================OIDC_ENABLED=falseOIDC_ISSUER_URL=OIDC_CLIENT_ID=# OIDC_CLIENT_SECRET - set above in SENSITIVE VALUES, or in secret manager as: kmi-OIDC_CLIENT_SECRETOIDC_REDIRECT_URI=OIDC_SCOPES=openid email profileOIDC_BUTTON_LABEL=Sign in with SSONEXTAUTH_URL=Common Operations
Section titled “Common Operations”Check Application Status
Section titled “Check Application Status”kubectl get pods,svc,ingress -n kmiView Logs
Section titled “View Logs”# Frontend logskubectl logs -f deployment/kafka-mobility-intelligence-frontend -n kmi
# Backend logskubectl logs -f deployment/kafka-mobility-intelligence-backend -n kmi
# MongoDB logskubectl logs -f statefulset/kafka-mobility-intelligence-mongodb -n kmiScale the Application
Section titled “Scale the Application”# Scale frontendkubectl scale deployment kafka-mobility-intelligence-frontend --replicas=2 -n kmi
# Scale backendkubectl scale deployment kafka-mobility-intelligence-backend --replicas=2 -n kmiUpdate Configuration
Section titled “Update Configuration”# Edit the .env file with new values, then redeploy./k8s-deploy.shUninstall
Section titled “Uninstall”helm uninstall kafka-mobility-intelligence -n kmikubectl delete namespace kmiTo deploy new images to a running cluster without downtime, see Rolling Updates.