Skip to content

Deploy with Helm ​

The chart deploys the guardrail service and, optionally, its Redis and Presidio dependencies.

Install ​

bash
helm install pseudonymizer \
  ./deploy/helm/palena-litellm-pseudonymizer \
  --namespace guardrails --create-namespace

By default this brings up the guardrail plus a single-instance Redis and both Presidio services — a self-contained stack for a proof of concept. Helm prints the in-cluster URL and a ready-to-paste LiteLLM guardrail block on install.

Production: bring your own dependencies ​

Disable the bundled Redis and Presidio and point at managed instances:

yaml
redis:
  enabled: false
  url: redis://my-managed-redis:6379/0

presidio:
  analyzer:
    enabled: false
    url: http://my-presidio-analyzer:3000
  imageRedactor:
    enabled: false
    url: http://my-image-redactor:3000

Organization names ​

Add your known company names for high-precision masking (see Organization detection):

yaml
presidio:
  analyzer:
    organizations:
      - Novartis
      - Roche

Common values ​

KeyDefaultPurpose
replicaCount2Guardrail replicas.
image.tagchart appVersionService image tag.
config.entitiesPERSON,ORGANIZATIONDetected entity types.
apiKey.enabledfalseRequire an x-api-key header.
redis.enabledtrueBundle Redis.
presidio.analyzer.nerOrganizationtruespaCy org detection.
presidio.analyzer.organizations[]Exact-match org deny-list.
autoscaling.enabledfalseHPA on CPU.
serviceMonitor.enabledfalsePrometheus Operator scrape.

The full list lives in the chart's values.yaml.

Security ​

Set an API key before exposing the service beyond the proxy:

yaml
apiKey:
  enabled: true
  value: "a-long-random-secret"       # or reference an existing Secret
  # existingSecret: my-secret
  # existingSecretKey: api-key

Uninstall ​

bash
helm uninstall pseudonymizer --namespace guardrails

Released under the Apache 2.0 License.