Install with Helm
The official chart installs the Norn API, web dashboard, worker, database migrations, and authorisation policy seed. By default, it also installs single-node PostgreSQL, Valkey, and Garage.
Requirements
- Kubernetes 1.34 or newer
- Helm 3 or 4
- an Ingress controller and TLS certificate, unless routing is managed separately
- persistent storage for each bundled data service
- two DNS names: one for Norn and one for object storage
The bundled data services are suitable for evaluation and small installations. For production, use managed or highly available PostgreSQL, Valkey, and S3-compatible storage. The application workloads are the same in either configuration.
Configure the release
Create a values file. This is the minimum configuration for an installation using the bundled data services:
ingress:
className: nginx
host: norn.example.com
annotations:
cert-manager.io/cluster-issuer: letsencrypt
postgresql:
persistence:
storageClass: fast-retained
size: 20Gi
valkey:
persistence:
storageClass: fast-retained
size: 4Gi
garage:
persistence:
storageClass: bulk-retained
size: 50Gi
Point norn.example.com and storage.norn.example.com at the Ingress. The storage hostname defaults
to storage.<ingress.host>; set garage.publicHost to use another name. The TLS certificate must
cover both names.
The chart generates its own application, database, Valkey, and Garage credentials. They are retained on uninstall and reused on upgrade. For production, use an existing Secret or external secret controller as described in Helm secrets.
Install
helm install norn oci://ghcr.io/usenorn/charts/norn \
--namespace norn \
--create-namespace \
--values values.yaml \
--wait \
--timeout 15m
Without --version, Helm installs the newest published chart. Pin it with
--version <chart-version> to install a specific one; the available versions are the
Norn releases.
During installation, the chart waits for the data services, applies embedded database migrations, seeds the authorisation policy, and then starts Norn. The API and web workloads default to two replicas. The worker runs exactly one replica.
Verify and open Norn
helm status norn --namespace norn
helm test norn --namespace norn --logs
Open https://norn.example.com and create the first account. If the instance is invite-only, close
signups after bootstrap:
norn:
configEnv:
NORN_INSTANCE_SIGNUPS_OPEN: "false"
Apply the change using the upgrade procedure.
Production checklist
Before adding users, confirm that you have:
- external or backed-up PostgreSQL and object storage
- Valkey configured with
noeviction - an offline recovery copy of
NORN_SECURITY_ENCRYPTION_KEY - SMTP configured and account recovery tested
- unbuffered SSE routing for
/v1/workspaces/<workspace>/events - a tested upgrade and restore procedure
Continue with the shared Norn configuration, then review the Helm-specific settings and operations.