> ## Documentation Index
> Fetch the complete documentation index at: https://danswer-docs-versions-opensearch-example.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Kubernetes

> Deploy Onyx with Helm

<Tip>
  Check out our [Resourcing Guide](/deployment/getting_started/resourcing) before getting started.
</Tip>

## Guide

The Onyx Helm chart packages all the required services (API, web, PostgreSQL, OpenSearch, etc.)
into a single deployment. By default, persistent volumes will be created for stateful services (e.g. PostgreSQL,
OpenSearch).

<Steps>
  <Step title="Add the Onyx Helm repository">
    ```bash theme={null}
    helm repo add onyx https://onyx-dot-app.github.io/onyx/
    helm repo update
    helm search repo onyx
    ```
  </Step>

  <Step title="Install Onyx">
    Install into its own namespace (recommended):

    ```bash theme={null}
    kubectl create namespace onyx
    helm install onyx onyx/onyx -n onyx
    ```

    This will pull the latest Onyx chart and deploy all dependencies.
  </Step>

  <Step title="Verify the installation">
    ```bash theme={null}
    helm list -n onyx
    kubectl get pods -n onyx
    ```

    Wait until all pods are in a `Running` state before accessing Onyx.
  </Step>

  <Step title="Access Onyx">
    By default, the chart exposes Onyx via a Kubernetes Service. For local testing, you can port-forward:

    ```bash theme={null}
    kubectl -n onyx port-forward service/onyx-nginx 8080:80
    ```

    Then open [http://localhost:8080](http://localhost:8080).
  </Step>

  <Step title="Configure Onyx">
    Configure your deployment by modifying the `values.yaml` file in the `onyx/deployment/helm/charts/onyx` directory.

    You'll need to restart Onyx after changing any `values.yaml` variables.

    ```bash theme={null}
    helm upgrade onyx onyx/onyx -n onyx -f deployment/helm/charts/onyx/values.yaml
    ```
  </Step>
</Steps>

See the [Helm chart README](https://github.com/onyx-dot-app/onyx/tree/main/deployment/helm)
for advanced options such as running as non-root and testing with Kind.

## Production

Before you run Onyx in production, read these guides:

* [External Services](/deployment/production/external_services): use managed PostgreSQL, Redis, OpenSearch, and
  object storage.
* [High Availability and Scaling](/deployment/production/high_availability): replicas, autoscaling, probes, and
  long-running requests.
* [Security Hardening](/deployment/production/security): image pinning, credentials, security contexts, and network
  policies.
* [Code Interpreter](/deployment/production/code_interpreter): restricted clusters, OpenShift, and capacity.

## Enabling Onyx Craft

Craft adds per-user sandbox pods, scoped RBAC, NetworkPolicies, an egress proxy,
and a Scheduled Task worker to the Helm deployment.

<Card title="Deploy Craft on Kubernetes" icon="dharmachakra" href="/deployment/local/craft_kubernetes">
  Prepare sandbox nodes and authentication, configure Helm, plan capacity, and verify the runtime.
</Card>

## Next Steps

<CardGroup cols={2}>
  <Card title="Configure Authentication" icon="shield-check" href="/deployment/authentication/basic">
    Set up authentication for your Onyx deployment with OAuth, OIDC, or SAML.
  </Card>

  <Card title="More Onyx Configuration Options" icon="gear" href="/deployment/configuration/configuration">
    Learn about all available configuration options for your Onyx deployment.
  </Card>
</CardGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.