What vector stores need from the installation
The Qdrant operator, the Qdrant domain, the certificate issuer and the storage classes that vector stores depend on, and how their absence shows.
Vector stores come from the optional Qdrant Databases module (db-qdrant). The module does not
run Qdrant itself: it writes a QdrantCluster resource (qdrantoperator.io/v1alpha1) into the
resource group's namespace, and the Qdrant operator turns it into a StatefulSet of Qdrant servers.
The module creates the load balancer Service and the HTTPS Ingress itself.
The Qdrant operator
Every cluster that hosts vector stores needs:
| What | Where |
|---|---|
The resource definition qdrantclusters.qdrantoperator.io |
Cluster-wide |
The Deployment qdrant-operator |
Namespace qdrant-operator-system |
Both come from the installer's Qdrant Operator dependency: the Helm chart
oci://registry.stackship.se/charts/qdrant-operator, installed as the release qdrant-operator.
Its version is pinned by the Qdrant Databases module (0.1.3 today). To check a cluster:
kubectl get crd qdrantclusters.qdrantoperator.io
kubectl -n qdrant-operator-system get deployment qdrant-operatorHow a missing or broken operator shows to users:
- Without the resource definition, creating a vector store is refused by the cluster.
- With the resource definition but no working operator, the vector store stays Creating and
turns Failed five minutes after it was created. Its status message — in the API and in
stsh qdrant get— saysThe Qdrant operator has not started any pods for this cluster after 5 minutes.
To add the module and its dependency to an installation, see Install a component.
Module settings
The module reads these from the ConfigMap module-db-qdrant-config in stackship-system:
| Setting | Set from | Used for |
|---|---|---|
Qdrant__DomainSuffix |
The Qdrant Domain asked for at installation | Platform hostnames for the HTTPS ingress. When empty, HTTPS without a custom hostname is refused |
Qdrant__ClusterIssuer |
The certificate issuer the installation uses for apps | Certificates for the HTTPS ingress. When empty, HTTPS is refused |
Qdrant__IngressClassName |
The installation's ingress class, traefik |
The class of the HTTPS Ingress |
Storage__Standard |
Standard Storage Class | Volumes of the plans nano and small |
Storage__Premium |
Premium Storage Class | Volumes of the plans medium and larger |
The storage classes are written into the plans when the module starts; a vector store keeps the class it was created with.
DNS for HTTPS
A vector store's platform hostname is its resource group's namespace without the rg- prefix,
then its name, under the Qdrant domain: <boundary prefix>-<resource group>-<name>.<Qdrant domain>,
shortened with a hash when the first label would be longer than 63 characters.
The Qdrant domain therefore needs a wildcard DNS record that points at the cluster's ingress
controller, or no certificate can be issued for new hostnames.
The Ingress carries the allowed-networks list and a request-body limit of 64 MiB as NGINX ingress
annotations (nginx.ingress.kubernetes.io/whitelist-source-range and
nginx.ingress.kubernetes.io/proxy-body-size). They take effect where the ingress controller
honors those annotations.
Agent clusters
On a cluster connected as an Agent cluster, the API key of a vector store cannot be read through the platform, so the portal cannot show it. See Agent clusters.