Skip to content
Stackship documentation Svenska

Vector stores (Qdrant)Administrators

What vector stores need from the installation

The Qdrant operator, the Qdrant domain, the certificate issuer and the storage classes that vector stores depend on, and how their absence shows.

Vector stores come from the optional Qdrant Databases module (db-qdrant). The module does not run Qdrant itself: it writes a QdrantCluster resource (qdrantoperator.io/v1alpha1) into the resource group's namespace, and the Qdrant operator turns it into a StatefulSet of Qdrant servers. The module creates the load balancer Service and the HTTPS Ingress itself.

The Qdrant operator

Every cluster that hosts vector stores needs:

What Where
The resource definition qdrantclusters.qdrantoperator.io Cluster-wide
The Deployment qdrant-operator Namespace qdrant-operator-system

Both come from the installer's Qdrant Operator dependency: the Helm chart oci://registry.stackship.se/charts/qdrant-operator, installed as the release qdrant-operator. Its version is pinned by the Qdrant Databases module (0.1.3 today). To check a cluster:

bash
kubectl get crd qdrantclusters.qdrantoperator.io
kubectl -n qdrant-operator-system get deployment qdrant-operator

How a missing or broken operator shows to users:

  • Without the resource definition, creating a vector store is refused by the cluster.
  • With the resource definition but no working operator, the vector store stays Creating and turns Failed five minutes after it was created. Its status message — in the API and in stsh qdrant get — says The Qdrant operator has not started any pods for this cluster after 5 minutes.

To add the module and its dependency to an installation, see Install a component.

Module settings

The module reads these from the ConfigMap module-db-qdrant-config in stackship-system:

Setting Set from Used for
Qdrant__DomainSuffix The Qdrant Domain asked for at installation Platform hostnames for the HTTPS ingress. When empty, HTTPS without a custom hostname is refused
Qdrant__ClusterIssuer The certificate issuer the installation uses for apps Certificates for the HTTPS ingress. When empty, HTTPS is refused
Qdrant__IngressClassName The installation's ingress class, traefik The class of the HTTPS Ingress
Storage__Standard Standard Storage Class Volumes of the plans nano and small
Storage__Premium Premium Storage Class Volumes of the plans medium and larger

The storage classes are written into the plans when the module starts; a vector store keeps the class it was created with.

DNS for HTTPS

A vector store's platform hostname is its resource group's namespace without the rg- prefix, then its name, under the Qdrant domain: <boundary prefix>-<resource group>-<name>.<Qdrant domain>, shortened with a hash when the first label would be longer than 63 characters. The Qdrant domain therefore needs a wildcard DNS record that points at the cluster's ingress controller, or no certificate can be issued for new hostnames.

The Ingress carries the allowed-networks list and a request-body limit of 64 MiB as NGINX ingress annotations (nginx.ingress.kubernetes.io/whitelist-source-range and nginx.ingress.kubernetes.io/proxy-body-size). They take effect where the ingress controller honors those annotations.

Agent clusters

On a cluster connected as an Agent cluster, the API key of a vector store cannot be read through the platform, so the portal cannot show it. See Agent clusters.