Skip to content

Nebi Pack

The Nebari Nebi Pack deploys Nebi, an environment management platform, onto a Nebari cluster. Users get a browser UI for building and sharing Conda/Pip environments behind Keycloak SSO; operators get one Helm chart that deploys Nebi and its database and hands routing, TLS, and authentication to the nebari-operator.

Environments built in Nebi are available to the rest of the cluster — the jhub-apps environment selector reads them over Nebi’s API using a token exchanged in Keycloak.

ComponentWhat it isImage / chart
NebiThe environment management server and UI. Builds environments with pixi/rattler and stores them on a PersistentVolume. Listens on :8460.quay.io/nebari/nebi
PostgreSQLAn embedded single-instance database for Nebi’s metadata, deployed as a StatefulSet. Optional — point Nebi at your own with postgres.enabled=false.postgres:16
This chartRenders both, plus a NebariApp that gets the service routed, certificated, and put on the Nebari landing page.oci://quay.io/nebari/charts/nebari-nebi-pack

The service is exposed at a single hostname you choose:

https://nebi.example.com # the Nebi UI (SSO at the gateway)
https://nebi.example.com/api/ # the REST API (bearer token, bypasses the gateway filter)
https://nebi.example.com/docs/ # the OpenAPI browser
  • Getting started — install the chart on a Nebari cluster and open Nebi for the first time
  • Branding — rebrand the UI title, logo, favicon, and colors at deploy time
  • Local development — run the chart on a local k3d cluster with Tilt
  • Helm values — every value the chart accepts, and what each one derives when left empty
  • Architecture & auth — how Nebi, PostgreSQL, Keycloak, and the nebari-operator fit together, and why authentication happens at the gateway

A stock Nebari install needs almost nothing beyond a hostname. nebariapp.hostname is the only required value: from it the chart derives the Keycloak hostname, the OIDC issuer, the client ID, and the client secret name, all matching the client the nebari-operator provisions for this NebariApp. Every derived value has an explicit override if your cluster does not follow the convention — see Helm values.