# Install on a Kubernetes cluster using Helm charts

This page guides you through installing and configuring Datalore On-Premises on a Kubernetes cluster.

> **Warning:**
> If you do not have strict platform requirements or are building a proof of concept, use a simpler and more straightforward [installation method with Docker Compose](install-datalore-on-premises-using-docker.html).
>
>
>
> We recommend using this installation method only if you need to use Kubernetes and have a solid understanding of both Kubernetes and Helm.

Kubernetes deployment of Datalore On-Premises contains the following components:

![Kubernetes-based Datalore setup](https://resources.jetbrains.com.cn/help/img/datalore/2026.3/k8s.png)

The installation process consists of two parts:

1.  [Basic installation](#basic-datalore-installation_helm) to get Datalore On-Premises up and running.

2.  [Configuration steps](#required-configuration-steps) to customize the installation.

> **Warning:**
> Datalore On-Premises only supports 64-bit Linux as a host system.
>
>
>
> ARM-based platforms, macOS, and Windows are not supported.

Prerequisites
: Before you start, be sure to:
:
:
:
: 1.
:
: Set up a Kubernetes cluster.
:
:
:
: > **Note:**
: > This installation was tested with Kubernetes v1.30, but other versions may work too.
:
:
:
:
:
: 2. Install `kubectl` locally and configure it to work with this cluster.
:
: 3.
:
: Install Helm.
:
:
:
: > **Note:**
: > This installation was tested with Helm v3.17, but other versions may work too.
:
:
:
: 4.  [Install an Ingress controller](https://kubernetes.io/docs/concepts/services-networking/ingress-controllers/) to be able to expose Datalore.

Hardware requirements
: Datalore On-Premises requires resources for running both the server, database, and computations. When selecting the amount of resources, consider your expected computational workload and the number of agents working concurrently.
:
:
:
: * CPU: Minimum 1 core (2 or more cores recommended)
:
: * RAM: Minimum 4 GB (8 GB recommended). At least 4 GB is recommended for each notebook running concurrently.
:
: * Available memory: Minimum 4 GB (6 GB or more recommended)

AWS EKS deployment considerations
: * Datalore’s [Reactive mode](use-reactive-mode.html) may not operate properly on an Amazon EKS cluster with the Amazon Linux compute nodes (default option). We recommend that you use Ubuntu 22.04 with the corresponding AMIs specifically designed for EKS.
:
: * To find an AMI for manual setup, select a suitable option from the [worker node image list](https://cloud-images.ubuntu.com/docs/aws/eks/) based on the cluster version and region.
:
: * To configure the cluster deployment using Terraform, you can use the [sample Terraform config file](https://github.com/JetBrains/datalore-configs/blob/main/terraform/eks/main.tf).

AWS Fargate restrictions
: AWS Fargate is a serverless compute engine for containers.
:
:
:
: Datalore On-Premises can run in Fargate, but you need to be aware of the following restrictions:
:
:
:
: * Attached files and [Reactive mode](use-reactive-mode.html) do not work because of Fargate’s security policies.
:
: * Spawning agents in privileged mode, which is the default setup, is not supported by Fargate.
:
: * Fargate does not support EBS volumes, which are our default volume option. As a workaround, we suggest that you set up an AWS EFS, create the `PersistentVolume` and `PersistentVolumeContainer` objects, and edit the `datalore.values.yaml` config file as shown in the example: ```YAML volumeClaimTemplates: - metadata: name: postgresql-data spec: accessModes: - ReadWriteMany storageClassName: efs-sc resources: requests: storage: 2Gi - metadata: name: storage spec: accessModes: - ReadWriteMany storageClassName: efs-sc resources: requests: storage: 10Gi ```

## Basic Datalore installation

Procedure: Step 1. Add the Datalore Helm repository

To add the repository, run the following command:

```BASH
helm repo add datalore https://jetbrains.github.io/datalore-configs/charts
```

Procedure: Step 2. Start configuring deployment

1. Create a `datalore.values.yaml` file.

> **Tip:**
> We recommend that you add this file to your version control system. It will serve as the single source of truth for the Datalore configuration.

2. Add the Datalore domain by adding the following parameter to `datalore.values.yaml`:

```YAML
dataloreEnv:
  ...
  # Make sure the URL doesn't have a trailing slash
  DATALORE_PUBLIC_URL: "<url>"
```

Replace `<url>` with the desired URL.

3. Datalore requires at least two volumes to store the files attached to notebooks and outputs that notebooks produce.

To configure volumes, add the following parameters to `datalore.values.yaml`:

```YAML
volumeClaimTemplates:
  - metadata:
      name: storage
    spec:
      accessModes:
        - ReadWriteOnce
      resources:
        requests:
          storage: 120Gi
  - metadata:
      name: postgresql-data
    spec:
      accessModes:
        - ReadWriteOnce
      resources:
        requests:
          storage: 10Gi
```

Procedure: Step 3. Create a Kubernetes secret for the database password

To create a Kubernetes secret for storing the database password in a secure way:

1. Generate the password and store it in the [Kubernetes secret](https://kubernetes.io/docs/tasks/configmap-secret/managing-secret-using-kubectl/), as described below. The `pwgen` tool is used here as an example. You can use any other tool or method to generate a password.

```SHELL
PASSWORD=$(pwgen -N1 -y 32)
kubectl create secret generic datalore-db-password --from-literal=DATALORE_DB_PASSWORD="$PASSWORD"
```

2. Modify (or add, if not present yet) the `databaseSecret` block in your `datalore.values.yaml` as follows:

```YAML
databaseSecret:
  create: false
  name: datalore-db-password
  key: DATALORE_DB_PASSWORD
```

The value of the name value is referring to a secret name defined at the previous step, while the key value is referring to the key within the secret that contains the password.

> **Tip:**
> If, for any reason, you do not want to create a secret manually, you may specify the password in the Helm config file. In this case, the secret will be provisioned automatically - but keep in mind that the password will be stored in plain text in your configuration file.
>
>
>
> In that scenario, adjust the `databaseSecret` block in `datalore.values.yaml`, as follows:
>
>
>
>
> ```YAML
> databaseSecret:
> create: true
> password: xxxx
> ```

3. (Optional) If you are moving from plain text password storage to the secret reference: remove the `password` key with its value from the `databaseSecret` block.

Procedure: Step 4. (Optional) Use an external Postgres database

Datalore requires a PostgreSQL database (version 15 or higher). The default Helm chart that deploys Datalore also provisions a single-instance PostgreSQL database.

If you want to use an external database, take the following steps:

1. Deploy a Postgres database (version 15 or higher), create a database user, and get the connection string.

2. Add the `internalDatabase` parameter to `datalore.values.yaml`:

```YAML
internalDatabase: false
```

3. Add the database user and connection string in the `dataloreEnv` block as follows:

```YAML
dataloreEnv:
  ...
  DB_USER: <database_user>
  DB_URL: "jdbc:postgresql://<database_host>:<database_port>/<database_name>"
```

Procedure: Step 5. (Optional) Enable an email allowlist

You can enable an allowlist for new user registration so that only users with email addresses included in the allowlist can register.

To do this, add the following parameter to `datalore.values.yaml`:

```YAML
dataloreEnv:
  ...
  EMAIL_ALLOWLIST_ENABLED: "true"
```

The `Email allowlist` tab will be available in the Admin panel. For more details, see [Restrict registration with Email allowlist](manage-email-allowlist.html).

Procedure: Step 6. (Optional) Enable user filtration based on Hub group membership

By default, all Hub users can get registered unless you disable registration in the [Admin panel](manage-users.html).

If you want to grant Datalore access only to members of a specific Hub group, add the following parameter to `datalore.values.yaml`:

```YAML
dataloreEnv:
  ...
  HUB_ALLOWLIST_GROUP: <group_name>
```

Procedure: Step 7. Deploy Datalore

Default namespace:

1.

To deploy the Datalore server into the default namespace, run the following command and wait for Datalore to start up:

```BASH
helm install -f datalore.values.yaml datalore datalore/datalore --version 0.2.45
```

> **Tip:**
> You can run `kubectl port-forward svc/datalore 8080` to test if Datalore can start up.

2.  Forward traffic from `localhost:8080` to the Datalore server:

```BASH
kubectl port-forward svc/datalore 8080
```

Non-default namespace:

1.

To deploy the Datalore server into a non-default namespace, run the following command:

```BASH
helm install -n <namespace> -f datalore.values.yaml datalore datalore/datalore --version 0.2.45
```

2.

To specify the non-default namespace for your agents configs, define the namespace variable in the `datalore.values.yaml` file as shown in the code block:

```YAML
agentsConfig:
  k8s:
    namespace: <namespace>
    instances:
      ...
```

For more details, see [Configure agents](configure-agents-helm-installation.html).

3.

Under `dataloreEnv` in `datalore.values.yaml`, define the following variables:

`DATABASES_K8S_NAMESPACE`
: String
:
:
:
: Kubernetes namespace where all database connector pods will be spawned.
:
:
:
: Default: `default`

`GIT_TASK_K8S_NAMESPACE`
: String
:
:
:
: Kubernetes namespace where all Git-related task pods will be spawned.
:
:
:
: Default: `default`

You can find the full list of customizable server configuration options in [Configure Datalore server](server-configuration.html).

4.  Forward traffic from `localhost:8080` to the Datalore server:

```BASH
kubectl -n <namespace> port-forward svc/datalore 8080
```

Procedure: Step 8. Expose Datalore

1. To route traffic to Datalore, configure [Ingress](https://kubernetes.io/docs/concepts/services-networking/ingress/#the-ingress-resource).

> **Tip:**
> A plain HTTP Ingress setup example looks as follows:
>
>
>
>
> ```YAML
> ingress:
> enabled: true
> hosts:
> - host: "<url>"
> paths:
> - path: /
> pathType: Prefix
> ```
>
>
>
> To adjust the file size limit in your configuration, use the [client_max_body_size annotation](https://github.com/kubernetes/ingress-nginx/blob/main/docs/user-guide/nginx-configuration/annotations.md#custom-max-body-size).

2. (Optional, recommended) If you use a reverse proxy, enable Gzip compression by following [these instructions](https://nginx.org/en/docs/http/ngx_http_gzip_module.html).

Procedure: Step 9. Add your Datalore license

1. Open the URL you earlier specified in `DATALORE_PUBLIC_URL` and register as a new user. This first user automatically receives the Super Admin role.

> **Tip:**
> Datalore On-Premises will not send a registration confirmation at this point. You can log in right after you register.
>
>
>
> To send confirmation emails to new users, you can [enable the email service](enable-email-service.html) during post-installation configuration.

2. Add your license. To do this, click your avatar at the top right, select `Admin panel | License`, and provide your license key.

For more information about Datalore licensing, see [Manage licenses](manage-licenses.html).

![Opening Admin panel](https://resources.jetbrains.com.cn/help/img/datalore/2026.3/admin-panel.png)

## Next steps

Procedure: Required configuration steps

1. [Configure agents](configure-agents-helm-installation.html): Customize how your agents work to manage your computational resources.

2. [Enable GPU machines](enable-gpu-machines.html): Enable GPU machines in your installation.

3. [Manage users](manage-users.html): Create and manage users and viewers.

4. [Configure plans](configure-plans.html): Customize resource usage among your Datalore users.

Procedure: Optional configuration steps

* [Set up JetBrains Hub](use-hub-for-helm-installation.html): Integrate an authentication service.

* [Use a sidecar container](use-sidecar-container.html): Use a two-container configuration to run the notebook agent without elevated privileges.

* [Customize or update environment](customize-or-update-environment.html): Build custom images tailored for your needs.

* [Enable gift codes](enable-gift-codes.html): Activate the service for generating and processing gift codes.

* [Enable the email service](enable-email-service.html): Activate email notifications.

* [Enable audit logging](enable-user-activity-logging-helm-installation.html): Turn on extended activity logging for Datalore users.

> **Tip:**
> For the full list of Datalore server configuration options, see [Server configuration](server-configuration.html).

## Keywords

Datalore installation, Datalore deployment, install Datalore, installation procedures, installation requirements, Kubernetes deployment

