Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
37 commits
Select commit Hold shift + click to select a range
1deba7d
docs: PLTF-388 add Helm-based installer instructions for OpenHands En…
aivong-openhands Jul 15, 2026
fc3bfa1
docs: PLTF-388 make the starter values a usable install (auth, runtim…
aivong-openhands Jul 15, 2026
c8f6cce
docs: PLTF-388 link the create_github_app script for auth setup
aivong-openhands Jul 15, 2026
1fb7701
docs: PLTF-388 single GitHub auth path, drop GitLab tab
aivong-openhands Jul 15, 2026
412e526
docs: PLTF-388 note other auth providers are supported
aivong-openhands Jul 15, 2026
dd0f509
docs: PLTF-388 name Bitbucket Data Center explicitly
aivong-openhands Jul 15, 2026
19610d8
docs: PLTF-388 simplify GitHub App script links
aivong-openhands Jul 15, 2026
a36a177
docs: PLTF-388 generalize auth prerequisite, GitHub as the example
aivong-openhands Jul 15, 2026
07d8343
docs: PLTF-388 next-steps links and Replicated chart URL in upgrade e…
aivong-openhands Jul 15, 2026
c152da8
docs: PLTF-388 corrections from live end-to-end validation
aivong-openhands Jul 16, 2026
e824822
docs(k8s-install): clarify channel slug, BYO-cert, CLI install, and b…
aivong-openhands Jul 16, 2026
df1a37b
docs(k8s-install): drop channel-slug guidance (customers install from…
aivong-openhands Jul 16, 2026
53117f1
docs(k8s-install): soften TLS trust language, trim storage-class trou…
aivong-openhands Jul 16, 2026
8dceef5
docs(k8s-install): drop the support-bundle upload no-link note
aivong-openhands Jul 16, 2026
5865a23
docs(k8s-install): cross-link Quick Start DNS reference
aivong-openhands Jul 16, 2026
33a0b50
docs(k8s-install): drop redundant 'not optional' from TLS prerequisite
aivong-openhands Jul 16, 2026
4325c3d
docs(k8s-install): remove DNS-01 issuer note from TLS prerequisite
aivong-openhands Jul 16, 2026
16f6332
docs(k8s-install): simplify GitHub App prerequisite to a link
aivong-openhands Jul 16, 2026
5071280
docs(k8s-install): make bring-your-own-cert the minimal TLS example
aivong-openhands Jul 16, 2026
d85723f
docs(k8s-install): regenerate llms-full.txt for BYO-cert example
aivong-openhands Jul 16, 2026
4982f4e
docs(k8s-install): add generic default-cert pointer for non-Traefik c…
aivong-openhands Jul 16, 2026
d9c5a5d
docs(k8s-install): regenerate llms-full.txt
aivong-openhands Jul 16, 2026
3975591
docs(k8s-install): trim 'no separate license file' aside from intro
aivong-openhands Jul 16, 2026
036b244
docs(k8s-install): use dns-checks anchor; trim TLS explanation
aivong-openhands Jul 16, 2026
49ee804
docs(k8s-install): trim helm-version prerequisite (covered in common …
aivong-openhands Jul 16, 2026
d807220
docs(k8s-install): trim cert-manager prereq and non-optional warning
aivong-openhands Jul 16, 2026
c9648be
docs(k8s-install): remove bring-your-own certificate note
aivong-openhands Jul 16, 2026
555419f
Merge branch 'main' into aivong/pltf-388-update-docsopenhandsdev-with…
aivong-openhands Jul 16, 2026
b0e3662
docs(k8s-install): fix minimal values so the install actually works
aivong-openhands Jul 16, 2026
2ca0c0e
docs(k8s-install): enable the bundled Keycloak in the minimal values
aivong-openhands Jul 17, 2026
3249a4b
docs(k8s-install): require STORAGE_CLASS for sandbox volumes
aivong-openhands Jul 17, 2026
9e11e69
docs: PLTF-388 link Replicated trial page in Helm install note
openhands-agent Jul 17, 2026
02e88cb
docs: PLTF-388 use Helm v4 as prerequisite
openhands-agent Jul 17, 2026
d3b80c8
docs: PLTF-388 note embedded PostgreSQL is PoC-only with no migration…
openhands-agent Jul 17, 2026
7836ddc
Merge branch 'main' into aivong/pltf-388-update-docsopenhandsdev-with…
aivong-openhands Jul 17, 2026
506c633
Add Amazon EKS installation guide
jlav Jul 20, 2026
87ba41f
Unnest Sysbox and DNS/TLS docs from EKS as general k8s guides
jlav Jul 20, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 5 additions & 1 deletion docs.json
Original file line number Diff line number Diff line change
Expand Up @@ -500,7 +500,11 @@
"group": "K8s Install",
"pages": [
"enterprise/k8s-install/index",
"enterprise/k8s-install/resource-limits"
"enterprise/k8s-install/installation",
"enterprise/k8s-install/sysbox",
"enterprise/k8s-install/dns-and-tls",
"enterprise/k8s-install/resource-limits",
"enterprise/k8s-install/eks"
]
}
]
Expand Down
4 changes: 2 additions & 2 deletions enterprise/analytics.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,7 @@

Laminar helps you understand what your OpenHands deployment is doing in production:

- Inspect prompts, tool calls, answers, and nested agent behavior in Laminar's [trace views](https://laminar.sh/docs/platform/viewing-traces).

Check warning on line 19 in enterprise/analytics.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai) - vale-spellcheck

enterprise/analytics.mdx#L19

Did you really mean 'Laminar's'?
- Use [session replay for browser agents](https://laminar.sh/docs/tracing/browser-agent-observability) when conversations drive browser automation.
- For Helm installs, define [signals](https://laminar.sh/docs/signals/introduction) to classify failures, measure outcomes, and monitor recurring patterns across many traces.

Expand Down Expand Up @@ -93,7 +93,7 @@
Apply your updated `values.yaml` override file:

```bash
helm upgrade openhands oci://ghcr.io/openhands/helm-charts/openhands \
helm upgrade openhands oci://registry.replicated.com/openhands/openhands \
--namespace openhands \
--values values.yaml
```
Expand All @@ -107,13 +107,13 @@
Once the deployment status shows **Ready**, navigate to the Laminar frontend URL:

- VM install: `https://analytics.app.<your-base-domain>`
- Kubernetes install: the hostname configured in `laminar.frontend.ingress.hostname`

Check warning on line 110 in enterprise/analytics.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai) - vale-spellcheck

enterprise/analytics.mdx#L110

Did you really mean 'hostname'?

Click the **Continue with Keycloak** button:

Check warning on line 112 in enterprise/analytics.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai) - vale-spellcheck

enterprise/analytics.mdx#L112

Did you really mean 'Keycloak'?

![Laminar Keycloak Auth](./images/laminar-keycloak-auth.png)

Check warning on line 114 in enterprise/analytics.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai) - vale-spellcheck

enterprise/analytics.mdx#L114

Did you really mean 'Keycloak'?

If you want more background on Laminar Cloud versus self-hosting outside OHE, see Laminar's official [hosting options](https://laminar.sh/docs/hosting-options).

Check warning on line 116 in enterprise/analytics.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai) - vale-spellcheck

enterprise/analytics.mdx#L116

Did you really mean 'Laminar's'?

## Create a Laminar Project

Expand Down Expand Up @@ -249,7 +249,7 @@
Apply your updated `values.yaml` override file:

```bash
helm upgrade openhands oci://ghcr.io/openhands/helm-charts/openhands \
helm upgrade openhands oci://registry.replicated.com/openhands/openhands \
--namespace openhands \
--values values.yaml
```
Expand All @@ -270,11 +270,11 @@

## What to Do Next in Laminar

Once traces are flowing, use Laminar's official docs to go deeper:

Check warning on line 273 in enterprise/analytics.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai) - vale-spellcheck

enterprise/analytics.mdx#L273

Did you really mean 'Laminar's'?

- [Viewing Traces](https://laminar.sh/docs/platform/viewing-traces) to inspect a single conversation in transcript, tree, or timeline views.
- For Helm installs, [Signals](https://laminar.sh/docs/signals/introduction) to extract structured outcomes or failure modes across many traces.
- [Session replay for browser agents](https://laminar.sh/docs/tracing/browser-agent-observability) to debug browser-based automations.

Check warning on line 277 in enterprise/analytics.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai) - vale-spellcheck

enterprise/analytics.mdx#L277

Did you really mean 'automations'?
- [Observability for OpenHands Software Agent SDK](https://laminar.sh/docs/tracing/integrations/openhands-sdk) for the OpenHands-specific tracing model.

## Next Steps
Expand Down
148 changes: 148 additions & 0 deletions enterprise/k8s-install/dns-and-tls.mdx
Original file line number Diff line number Diff line change
@@ -0,0 +1,148 @@
---
title: DNS and TLS
description: Automate DNS records and TLS certificates with external-dns and cert-manager
icon: lock
---

OpenHands needs DNS records and TLS certificates for its hostnames. We recommend automating both with

Check warning on line 7 in enterprise/k8s-install/dns-and-tls.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai-aivong-pltf-388-update-docsopenhandsdev-with-hel) - vale-spellcheck

enterprise/k8s-install/dns-and-tls.mdx#L7

Did you really mean 'hostnames'?

Check warning on line 7 in enterprise/k8s-install/dns-and-tls.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai) - vale-spellcheck

enterprise/k8s-install/dns-and-tls.mdx#L7

Did you really mean 'hostnames'?
**external-dns** and **cert-manager** — they run on any Kubernetes distribution and support the major
cloud DNS providers. If you can't run them, provision the records and certificates by hand — see
[Manual Setup](#manual-setup).

## Hostnames

Check warning on line 12 in enterprise/k8s-install/dns-and-tls.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai-aivong-pltf-388-update-docsopenhandsdev-with-hel) - vale-spellcheck

enterprise/k8s-install/dns-and-tls.mdx#L12

Did you really mean 'Hostnames'?

Check warning on line 12 in enterprise/k8s-install/dns-and-tls.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai) - vale-spellcheck

enterprise/k8s-install/dns-and-tls.mdx#L12

Did you really mean 'Hostnames'?

OpenHands serves these hostnames, using `openhands.example.com` as the base domain (matching the

Check warning on line 14 in enterprise/k8s-install/dns-and-tls.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai-aivong-pltf-388-update-docsopenhandsdev-with-hel) - vale-spellcheck

enterprise/k8s-install/dns-and-tls.mdx#L14

Did you really mean 'hostnames'?

Check warning on line 14 in enterprise/k8s-install/dns-and-tls.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai) - vale-spellcheck

enterprise/k8s-install/dns-and-tls.mdx#L14

Did you really mean 'hostnames'?
[Helm install](/enterprise/k8s-install/installation)):

| Hostname | Purpose |

Check warning on line 17 in enterprise/k8s-install/dns-and-tls.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai-aivong-pltf-388-update-docsopenhandsdev-with-hel) - vale-spellcheck

enterprise/k8s-install/dns-and-tls.mdx#L17

Did you really mean 'Hostname'?

Check warning on line 17 in enterprise/k8s-install/dns-and-tls.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai) - vale-spellcheck

enterprise/k8s-install/dns-and-tls.mdx#L17

Did you really mean 'Hostname'?
|---|---|
| `app.openhands.example.com` | Application |
| `auth.app.openhands.example.com` | Login (Keycloak) |

Check warning on line 20 in enterprise/k8s-install/dns-and-tls.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai-aivong-pltf-388-update-docsopenhandsdev-with-hel) - vale-spellcheck

enterprise/k8s-install/dns-and-tls.mdx#L20

Did you really mean 'Keycloak'?

Check warning on line 20 in enterprise/k8s-install/dns-and-tls.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai) - vale-spellcheck

enterprise/k8s-install/dns-and-tls.mdx#L20

Did you really mean 'Keycloak'?
| `runtime-api.openhands.example.com` | Runtime API |
| `*.runtime.openhands.example.com` | Per-session sandboxes |

All of these resolve to your ingress load balancer. The sandbox entry must be a **wildcard** — each
session gets its own subdomain.

## external-dns

external-dns watches your Ingresses and Services and creates the matching DNS records automatically.
It supports many providers, including Amazon Route 53, Google Cloud DNS, Azure DNS, and Cloudflare.

- Install it from its [Helm chart](https://kubernetes-sigs.github.io/external-dns/).
- Set `provider` to your DNS provider and grant it access to your zone (the access mechanism is
provider-specific).
- Recommended settings:

```yaml
provider:
name: aws # or google, azure, cloudflare, ...
policy: upsert-only # only ever create/update, never delete
registry: txt
txtOwnerId: openhands
domainFilters:
- openhands.example.com # only manage names under your base domain
```

With `upsert-only` and a TXT registry, external-dns only ever touches records it created.

<Note>
**Amazon EKS / Route 53.** Grant access with IRSA or EKS Pod Identity:
`route53:ChangeResourceRecordSets` on the zone, plus `route53:ListHostedZones` and
`route53:ListResourceRecordSets`. If your hosted zone is a *parent* of the domain filter (zone
`example.com`, filter `openhands.example.com`), add the `--aws-zone-match-parent` flag, or
external-dns matches no zone and creates nothing.
</Note>

## cert-manager

cert-manager issues and renews certificates from Let's Encrypt. Use the **DNS-01** challenge — it's
the only one that can issue the **wildcard** certificate the sandbox hostnames need.

Check warning on line 60 in enterprise/k8s-install/dns-and-tls.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai-aivong-pltf-388-update-docsopenhandsdev-with-hel) - vale-spellcheck

enterprise/k8s-install/dns-and-tls.mdx#L60

Did you really mean 'hostnames'?

Check warning on line 60 in enterprise/k8s-install/dns-and-tls.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai) - vale-spellcheck

enterprise/k8s-install/dns-and-tls.mdx#L60

Did you really mean 'hostnames'?

<Steps>
<Step title="Install cert-manager">
Install it from its [Helm chart](https://cert-manager.io/docs/installation/helm/), and grant it
access to your DNS provider so it can solve DNS-01 challenges.
</Step>
<Step title="Create a ClusterIssuer">
The `solvers` block is specific to your DNS provider — the Route 53 solver is shown here.

```yaml
apiVersion: cert-manager.io/v1
kind: ClusterIssuer
metadata:
name: letsencrypt-prod
spec:
acme:
server: https://acme-v02.api.letsencrypt.org/directory
email: you@example.com
privateKeySecretRef:
name: letsencrypt-prod
solvers:
- dns01:
route53: # swap for cloudDNS, azureDNS, cloudflare, ...
hostedZoneID: <your-zone-id>
```

<Tip>
Start with the staging server (`https://acme-staging-v02.api.letsencrypt.org/directory`) while
you get the setup working — it has generous rate limits — then switch to production.
</Tip>
</Step>
<Step title="Request a wildcard certificate">
A single wildcard covers every sandbox host. With Traefik, serve it as the default `TLSStore` so

Check warning on line 93 in enterprise/k8s-install/dns-and-tls.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai-aivong-pltf-388-update-docsopenhandsdev-with-hel) - vale-spellcheck

enterprise/k8s-install/dns-and-tls.mdx#L93

Did you really mean 'Traefik'?

Check warning on line 93 in enterprise/k8s-install/dns-and-tls.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai) - vale-spellcheck

enterprise/k8s-install/dns-and-tls.mdx#L93

Did you really mean 'Traefik'?
no per-ingress TLS config is needed.

```yaml
apiVersion: cert-manager.io/v1
kind: Certificate
metadata:
name: runtime-wildcard
namespace: openhands
spec:
secretName: runtime-wildcard-tls
issuerRef:
name: letsencrypt-prod
kind: ClusterIssuer
dnsNames:
- "*.runtime.openhands.example.com"
```

Issue certificates for the `app`, `auth`, and `runtime-api` hosts the same way.
</Step>
</Steps>

<Note>
**Amazon EKS / Route 53.** Grant cert-manager Route 53 access with IRSA or EKS Pod Identity:
`route53:ChangeResourceRecordSets` on the zone and `route53:GetChange`. Use the `route53` solver as
shown above.
</Note>

## Manual Setup

If you don't run external-dns and cert-manager, provision these by hand and point the ingress
controller at them.

**DNS** — create a record for each hostname in the table above, all pointing to your ingress load

Check warning on line 126 in enterprise/k8s-install/dns-and-tls.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai-aivong-pltf-388-update-docsopenhandsdev-with-hel) - vale-spellcheck

enterprise/k8s-install/dns-and-tls.mdx#L126

Did you really mean 'hostname'?

Check warning on line 126 in enterprise/k8s-install/dns-and-tls.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai) - vale-spellcheck

enterprise/k8s-install/dns-and-tls.mdx#L126

Did you really mean 'hostname'?
balancer (typically a CNAME to the load balancer's hostname, or a cloud DNS alias). The sandbox

Check warning on line 127 in enterprise/k8s-install/dns-and-tls.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai-aivong-pltf-388-update-docsopenhandsdev-with-hel) - vale-spellcheck

enterprise/k8s-install/dns-and-tls.mdx#L127

Did you really mean 'balancer's'?

Check warning on line 127 in enterprise/k8s-install/dns-and-tls.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai-aivong-pltf-388-update-docsopenhandsdev-with-hel) - vale-spellcheck

enterprise/k8s-install/dns-and-tls.mdx#L127

Did you really mean 'hostname'?

Check warning on line 127 in enterprise/k8s-install/dns-and-tls.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai) - vale-spellcheck

enterprise/k8s-install/dns-and-tls.mdx#L127

Did you really mean 'balancer's'?

Check warning on line 127 in enterprise/k8s-install/dns-and-tls.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai) - vale-spellcheck

enterprise/k8s-install/dns-and-tls.mdx#L127

Did you really mean 'hostname'?
record must be the wildcard `*.runtime.openhands.example.com`.

**TLS** — obtain certificates covering those hostnames and load them into the ingress controller as

Check warning on line 130 in enterprise/k8s-install/dns-and-tls.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai-aivong-pltf-388-update-docsopenhandsdev-with-hel) - vale-spellcheck

enterprise/k8s-install/dns-and-tls.mdx#L130

Did you really mean 'hostnames'?

Check warning on line 130 in enterprise/k8s-install/dns-and-tls.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai) - vale-spellcheck

enterprise/k8s-install/dns-and-tls.mdx#L130

Did you really mean 'hostnames'?
Kubernetes TLS secrets. A single wildcard isn't enough, because the hostnames sit at different

Check warning on line 131 in enterprise/k8s-install/dns-and-tls.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai-aivong-pltf-388-update-docsopenhandsdev-with-hel) - vale-spellcheck

enterprise/k8s-install/dns-and-tls.mdx#L131

Did you really mean 'hostnames'?

Check warning on line 131 in enterprise/k8s-install/dns-and-tls.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai) - vale-spellcheck

enterprise/k8s-install/dns-and-tls.mdx#L131

Did you really mean 'hostnames'?
depths. You need:

- `*.runtime.openhands.example.com` for the sandboxes, and
- certificates for `app.openhands.example.com`, `auth.app.openhands.example.com`, and
`runtime-api.openhands.example.com` (for example a `*.openhands.example.com` wildcard, which covers
`app` and `runtime-api`, plus a certificate for `auth.app.openhands.example.com`).

## Next Steps

<CardGroup cols={2}>
<Card title="Installing Sysbox" icon="cube" href="/enterprise/k8s-install/sysbox">
Install the sandbox runtime on your sandbox nodes.
</Card>
<Card title="Install with Helm" icon="ship" href="/enterprise/k8s-install/installation">
Deploy OpenHands once the cluster is ready.
</Card>
</CardGroup>
139 changes: 139 additions & 0 deletions enterprise/k8s-install/eks.mdx
Original file line number Diff line number Diff line change
@@ -0,0 +1,139 @@
---
title: Amazon EKS
description: Prepare an Amazon EKS cluster to run OpenHands Enterprise
icon: aws
---

Running OpenHands Enterprise on Amazon EKS follows the standard
[Helm install](/enterprise/k8s-install/installation), with a few EKS-specific choices for node
groups, storage, ingress, and the sandbox runtime. This guide covers preparing the cluster; once
it's ready, follow the Helm install to deploy.

## Cluster Requirements

| Requirement | Recommendation |
|---|---|
| EKS version | 1.32–1.35 (the range [Sysbox](/enterprise/k8s-install/sysbox) supports) |
| Add-ons | VPC CNI, CoreDNS, kube-proxy, and the **EBS CSI driver** (sandboxes and stateful components use EBS volumes) |
| Storage class | A `gp3` StorageClass backed by the EBS CSI driver |
| Metrics | Metrics Server, for `kubectl top` and autoscaling |

Check warning on line 19 in enterprise/k8s-install/eks.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai-aivong-pltf-388-update-docsopenhandsdev-with-hel) - vale-spellcheck

enterprise/k8s-install/eks.mdx#L19

Did you really mean 'autoscaling'?

Check warning on line 19 in enterprise/k8s-install/eks.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai) - vale-spellcheck

enterprise/k8s-install/eks.mdx#L19

Did you really mean 'autoscaling'?

The chart's default sandbox storage class (`standard-rwo`) is GKE-only. Set
`runtime-api.env.STORAGE_CLASS` to your `gp3` class or sandboxes will never start.

## Node Groups

OpenHands runs two very different workloads, so use two node groups:

- **General** — the OpenHands services (server, runtime API, Keycloak, LiteLLM, Redis) and the

Check warning on line 28 in enterprise/k8s-install/eks.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai-aivong-pltf-388-update-docsopenhandsdev-with-hel) - vale-spellcheck

enterprise/k8s-install/eks.mdx#L28

Did you really mean 'Keycloak'?

Check warning on line 28 in enterprise/k8s-install/eks.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai) - vale-spellcheck

enterprise/k8s-install/eks.mdx#L28

Did you really mean 'Keycloak'?
cluster add-ons (ingress, DNS, and certificate controllers). Standard EKS nodes on the Amazon
Linux 2023 AMI; on-demand or Spot.
- **Sysbox** — the agent sandboxes, one pod per session. These need the Sysbox runtime, which
requires an **Ubuntu** AMI and at least **4 vCPU** per node, on **on-demand** capacity. See
[Installing Sysbox](/enterprise/k8s-install/sysbox).

Check warning on line 33 in enterprise/k8s-install/eks.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai-aivong-pltf-388-update-docsopenhandsdev-with-hel) - vale-spellcheck

enterprise/k8s-install/eks.mdx#L33

Did you really mean 'Sysbox'?

Check warning on line 33 in enterprise/k8s-install/eks.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai) - vale-spellcheck

enterprise/k8s-install/eks.mdx#L33

Did you really mean 'Sysbox'?

We recommend [Karpenter](https://karpenter.sh/) for autoscaling both groups (managed node groups

Check warning on line 35 in enterprise/k8s-install/eks.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai-aivong-pltf-388-update-docsopenhandsdev-with-hel) - vale-spellcheck

enterprise/k8s-install/eks.mdx#L35

Did you really mean 'autoscaling'?

Check warning on line 35 in enterprise/k8s-install/eks.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai) - vale-spellcheck

enterprise/k8s-install/eks.mdx#L35

Did you really mean 'autoscaling'?
also work). The sandbox group is the one that scales with usage — size it by peak concurrent
sessions, and configure it so a node is only removed when empty, never while a session is running.

Sandboxes are pinned to Sysbox nodes automatically by the `sysbox-runc` RuntimeClass. Keep the

Check warning on line 39 in enterprise/k8s-install/eks.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai-aivong-pltf-388-update-docsopenhandsdev-with-hel) - vale-spellcheck

enterprise/k8s-install/eks.mdx#L39

Did you really mean 'Sysbox'?

Check warning on line 39 in enterprise/k8s-install/eks.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai) - vale-spellcheck

enterprise/k8s-install/eks.mdx#L39

Did you really mean 'Sysbox'?
ingress, DNS, and certificate controllers on the general group with a node selector.

### Sizing the Sandbox Nodes

Each sandbox requests **0.5 vCPU**, **3 GiB memory** (request = limit, so it's guaranteed), and
**10 GiB** of ephemeral storage. Memory is usually the binding constraint, so `m`-family instances
(4 GiB per vCPU) pack most efficiently:

| Instance | vCPU / memory | Sandboxes per node | Bound by |
|---|---|---|---|
| `c6i.2xlarge` | 8 / 16 GiB | ~4 | memory |
| `m6i.2xlarge` | 8 / 32 GiB | ~9 | memory |
| `r6i.2xlarge` | 8 / 64 GiB | ~14 | CPU |
| `m6i.4xlarge` | 16 / 64 GiB | ~19 | memory |

Two things to size for:

- **Root volume** — ephemeral scratch is `10 GiB × sandboxes per node`. A full `m6i.4xlarge` needs
~190 GiB of scratch, so give Sysbox nodes a large root volume (200 GiB or more), or prefer more,

Check warning on line 58 in enterprise/k8s-install/eks.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai-aivong-pltf-388-update-docsopenhandsdev-with-hel) - vale-spellcheck

enterprise/k8s-install/eks.mdx#L58

Did you really mean 'Sysbox'?

Check warning on line 58 in enterprise/k8s-install/eks.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai) - vale-spellcheck

enterprise/k8s-install/eks.mdx#L58

Did you really mean 'Sysbox'?
smaller nodes.
- **Warm capacity** — a new sandbox otherwise waits for a node to boot, which takes a few minutes.
Keeping a small pool of spare capacity (for example a low-priority placeholder Deployment sized to
one sandbox) lets sessions start instantly. Size it to your expected burst.

For per-pod tuning — larger sandboxes, server replicas, autoscaling — see

Check warning on line 64 in enterprise/k8s-install/eks.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai-aivong-pltf-388-update-docsopenhandsdev-with-hel) - vale-spellcheck

enterprise/k8s-install/eks.mdx#L64

Did you really mean 'autoscaling'?

Check warning on line 64 in enterprise/k8s-install/eks.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai) - vale-spellcheck

enterprise/k8s-install/eks.mdx#L64

Did you really mean 'autoscaling'?
[Resource Limits](/enterprise/k8s-install/resource-limits).

## Object Storage

OpenHands stores conversation and session state in a file store. The bundled MinIO is ephemeral;
for production, back it with an **S3 bucket**:

1. Create a bucket in the cluster's region.
2. Grant access with either an IAM user access key scoped to the bucket, or — to avoid a long-lived
credential — IRSA / EKS Pod Identity.
3. For the access-key approach, store the credentials in a secret:

```bash
kubectl -n openhands create secret generic openhands-s3-credentials \
--from-literal=AWS_ACCESS_KEY_ID=<access-key-id> \
--from-literal=AWS_SECRET_ACCESS_KEY=<secret-access-key>
```

Then point the file store at the bucket in your values:

```yaml
filestore:
ephemeral: false
type: s3
bucket: <your-bucket>
region: <your-region>
existingSecret: openhands-s3-credentials
```

## Database

Use an external **Amazon RDS for PostgreSQL** instance rather than the bundled database. Place it in
the cluster's VPC, reachable from the nodes on port 5432. See
[External PostgreSQL](/enterprise/external-postgres) for the values.

## Ingress

Install an ingress controller on the general node group and expose it with an **AWS Network Load
Balancer**, provisioned directly from Service annotations (no AWS Load Balancer Controller required).
Both Traefik and NGINX are supported:

Check warning on line 104 in enterprise/k8s-install/eks.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai-aivong-pltf-388-update-docsopenhandsdev-with-hel) - vale-spellcheck

enterprise/k8s-install/eks.mdx#L104

Did you really mean 'Traefik'?

Check warning on line 104 in enterprise/k8s-install/eks.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai) - vale-spellcheck

enterprise/k8s-install/eks.mdx#L104

Did you really mean 'Traefik'?

- **Traefik (recommended)** — set `ingress.class: traefik` in your OpenHands values. Its default

Check warning on line 106 in enterprise/k8s-install/eks.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai-aivong-pltf-388-update-docsopenhandsdev-with-hel) - vale-spellcheck

enterprise/k8s-install/eks.mdx#L106

Did you really mean 'Traefik'?

Check warning on line 106 in enterprise/k8s-install/eks.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai) - vale-spellcheck

enterprise/k8s-install/eks.mdx#L106

Did you really mean 'Traefik'?
`TLSStore` lets one wildcard certificate serve every host.
- **NGINX** — set `ingress.class: nginx` and use `nginx.ingress.kubernetes.io/*` annotations for
per-ingress tuning.

Expose the controller's Service as an NLB in the controller's own chart values:

```yaml
service:
type: LoadBalancer
annotations:
service.beta.kubernetes.io/aws-load-balancer-type: nlb
service.beta.kubernetes.io/aws-load-balancer-scheme: internet-facing
```

Then set up certificates and DNS records for the OpenHands hostnames — see

Check warning on line 121 in enterprise/k8s-install/eks.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai-aivong-pltf-388-update-docsopenhandsdev-with-hel) - vale-spellcheck

enterprise/k8s-install/eks.mdx#L121

Did you really mean 'hostnames'?

Check warning on line 121 in enterprise/k8s-install/eks.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai) - vale-spellcheck

enterprise/k8s-install/eks.mdx#L121

Did you really mean 'hostnames'?
[DNS and TLS](/enterprise/k8s-install/dns-and-tls).

## Next Steps

<CardGroup cols={2}>
<Card title="Installing Sysbox" icon="cube" href="/enterprise/k8s-install/sysbox">
Install the sandbox runtime on your Sysbox node group.

Check warning on line 128 in enterprise/k8s-install/eks.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai-aivong-pltf-388-update-docsopenhandsdev-with-hel) - vale-spellcheck

enterprise/k8s-install/eks.mdx#L128

Did you really mean 'Sysbox'?

Check warning on line 128 in enterprise/k8s-install/eks.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai) - vale-spellcheck

enterprise/k8s-install/eks.mdx#L128

Did you really mean 'Sysbox'?
</Card>
<Card title="DNS and TLS" icon="lock" href="/enterprise/k8s-install/dns-and-tls">
Automate records and certificates with external-dns and cert-manager.
</Card>
<Card title="Install with Helm" icon="ship" href="/enterprise/k8s-install/installation">
Deploy OpenHands once the cluster is ready.
</Card>
<Card title="Resource Limits" icon="gauge-high" href="/enterprise/k8s-install/resource-limits">
Size memory, CPU, and replicas for production.
</Card>
</CardGroup>
16 changes: 16 additions & 0 deletions enterprise/k8s-install/index.mdx
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
---
title: Kubernetes Installation
description: Deploy OpenHands Enterprise into your own Kubernetes cluster using Helm
icon: dharmachakra

Check warning on line 4 in enterprise/k8s-install/index.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai-aivong-pltf-388-update-docsopenhandsdev-with-hel) - vale-spellcheck

enterprise/k8s-install/index.mdx#L4

Did you really mean 'dharmachakra'?

Check warning on line 4 in enterprise/k8s-install/index.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai) - vale-spellcheck

enterprise/k8s-install/index.mdx#L4

Did you really mean 'dharmachakra'?
---

OpenHands Enterprise can be deployed into an existing Kubernetes cluster using Helm.
Expand Down Expand Up @@ -35,8 +35,8 @@
|-----------|-------------|
| **OpenHands Server** | Main application server handling UI, API, and agent orchestration |
| **Runtime API** | Manages sandbox lifecycle—provisioning, scaling, and cleanup |
| **Runtimes (Sandboxes)** | Isolated containers where agents execute code |

Check warning on line 38 in enterprise/k8s-install/index.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai-aivong-pltf-388-update-docsopenhandsdev-with-hel) - vale-spellcheck

enterprise/k8s-install/index.mdx#L38

Did you really mean 'Runtimes'?

Check warning on line 38 in enterprise/k8s-install/index.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai) - vale-spellcheck

enterprise/k8s-install/index.mdx#L38

Did you really mean 'Runtimes'?
| **Keycloak** | Identity and access management |

Check warning on line 39 in enterprise/k8s-install/index.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai-aivong-pltf-388-update-docsopenhandsdev-with-hel) - vale-spellcheck

enterprise/k8s-install/index.mdx#L39

Did you really mean 'Keycloak'?

Check warning on line 39 in enterprise/k8s-install/index.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai) - vale-spellcheck

enterprise/k8s-install/index.mdx#L39

Did you really mean 'Keycloak'?
| **LiteLLM Proxy** | Routes requests to your LLM provider(s) |
| **PostgreSQL** | Persistent storage for application data |
| **Redis** | Caching and session management |
Expand All @@ -50,6 +50,22 @@

## Guides

<Card title="Install with Helm" icon="ship" href="/enterprise/k8s-install/installation">
End-to-end installation instructions using your OpenHands Enterprise license.
</Card>

<Card title="Installing Sysbox" icon="cube" href="/enterprise/k8s-install/sysbox">
Install the Sysbox runtime so agent sandboxes can run securely.

Check warning on line 58 in enterprise/k8s-install/index.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai-aivong-pltf-388-update-docsopenhandsdev-with-hel) - vale-spellcheck

enterprise/k8s-install/index.mdx#L58

Did you really mean 'Sysbox'?

Check warning on line 58 in enterprise/k8s-install/index.mdx

View check run for this annotation

Mintlify / Mintlify Validation (allhandsai) - vale-spellcheck

enterprise/k8s-install/index.mdx#L58

Did you really mean 'Sysbox'?
</Card>

<Card title="DNS and TLS" icon="lock" href="/enterprise/k8s-install/dns-and-tls">
Automate DNS records and TLS certificates with external-dns and cert-manager.
</Card>

<Card title="Amazon EKS" icon="aws" href="/enterprise/k8s-install/eks">
EKS-specific setup — node groups, EBS storage, S3, RDS, and NLB ingress.
</Card>

<Card title="External PostgreSQL" icon="database" href="/enterprise/external-postgres">
Configure OpenHands to use your own PostgreSQL database instead of the bundled instance.
</Card>
Expand Down
Loading
Loading