License File Installation
Every Kamiwaza installation runs with a signed license file issued by Kamiwaza. This page covers installing the file on a cluster, confirming the platform sees it, rotating it, and what the startup messages mean. A license file is required for every installation.
What the license file is
- A single file,
license.lic, issued to your organization by Kamiwaza. - Signed. The platform verifies the signature at startup with a key built into the Kamiwaza images. Nothing is sent to Kamiwaza and no network access is needed to validate it, so it works in air-gapped environments.
- Carries who the license was issued to, the edition, and an optional expiry date for the commercial term.
Do not edit the file. Any change to its contents, including a stray newline added during copy-paste, invalidates the signature.
If you do not have a license file, contact your Kamiwaza representative or get in touch at https://www.kamiwaza.ai/contact.
Install the license file
1. Create a Secret from the file. The Secret must contain exactly one key named
license.lic:
kubectl create secret generic kamiwaza-license \
--namespace kamiwaza \
--from-file=license.lic=./license.lic
2. Point the chart at the Secret in your Helm values file. The license setting
belongs under core::
core:
license:
existingSecret: kamiwaza-license
Then install or upgrade as usual; see Installing Kamiwaza. Kamiwaza mounts the Secret as a whole directory at
/app/licenses (the core.license.mountPath default) and reads
/app/licenses/license.lic. Keep the directory mount: a subPath mount would never
receive a rotated license.
Separately from the license file, the chart requires the EULA to be accepted before
it renders anything: set global.eula.accepted: true in your values. If an install
stops with an EULA message, this is the value it is asking for.
Enforcement
Every published Kamiwaza core image is a release build and always requires a valid license. Enforcement is compiled into the release artifact rather than configured by the chart, so there is no chart setting that weakens this policy. Kamiwaza core refuses to start on any license problem listed under Troubleshooting. A passed commercial term is not one of those startup failures.
Verify the license is active
Every API response from the platform carries two headers:
| Header | Values |
|---|---|
x-kamiwaza-license-state | valid, expiring (term ends within 30 days), or expired |
x-kamiwaza-license-expires | The term end date as YYYY-MM-DD; absent when the license has no expiry |
curl -skI https://<your-kamiwaza-host>/api/ | grep -i x-kamiwaza-license
-k accepts an edge certificate your workstation does not trust, such as a
self-signed one.
The web UI shows the same information: an amber banner when the term ends within 30 days (dismissible), and a red banner once it has ended. An expired commercial term never stops the platform. The banner is the only effect; contact your Kamiwaza representative to renew.
If no license headers are present, verify that you are querying a path that goes through the Kamiwaza API. A release build cannot start without a valid license.
Rotate or renew a license
-
Replace the Secret's contents with the new file:
kubectl create secret generic kamiwaza-license \--namespace kamiwaza \--from-file=license.lic=./license.lic \--dry-run=client -o yaml | kubectl apply -f - -
In your values file, change
core.license.rolloutKeyto any new value (a date works) so the scheduler pod restarts and re-reads the file, and setcore.rayServe.forceRedeployOnStartup: trueso the model-serving layer is redeployed on that restart:core:license:existingSecret: kamiwaza-licenserolloutKey: "2026-09-01"rayServe:forceRedeployOnStartup: trueWithout
forceRedeployOnStartup, the scheduler leaves a healthy serving deployment alone, and the serving layer keeps reporting the old license state even though the new file was accepted. A renewal that "did not take" in the banner is almost always this. -
Rerun
helm upgrade --installwith the updated values file. Afterward, removeforceRedeployOnStartupfrom your values file; its default isfalse. -
Re-check the
x-kamiwaza-license-*headers.
Troubleshooting
When the license check fails, the core-scheduler pod log contains one block that
starts with License check failed (<condition>), names the file path it looked in,
and ends with a Condition: line you can search for. On release builds, core exits
after logging this block, and the API stops serving with it: on refusal the platform
also retires the Ray Serve application, so you lose the API as well as the
scheduler.
| Condition | Meaning | What to do |
|---|---|---|
license_file_missing | No file at /app/licenses/license.lic | Create the Secret with key license.lic and set core.license.existingSecret, or request a license |
license_file_unreadable | The file exists but could not be read | Check the Secret holds the complete file and is mounted as a directory, not a subPath |
license_tampered | The signature does not verify | The file was modified or truncated in transit. Request a fresh copy; do not edit license files |
license_wrong_account | Issued by a different vendor account | This file is not a Kamiwaza-issued license |
license_wrong_product | Issued for a different Kamiwaza product | Check which product the file was issued for and request the right one |
license_suspended | The license has been suspended by Kamiwaza | Contact Kamiwaza licensing support |
license_file_stale | The signed file itself carries an expiry that has passed (distinct from the commercial term, which never blocks startup) | Request a re-issued file |
license_claims_invalid | A field in the file is malformed, or the file uses a newer format than this Kamiwaza version understands | If the message says the file's schema version is above the maximum this build supports, upgrade Kamiwaza or request a file issued for your version; for any other detail, request a re-issued file — upgrading will not help |
license_gate_misconfigured | The image itself is missing its built-in trust data | Redeploy a correctly published Kamiwaza image; changing the license file cannot fix this |
There is deliberately no license_expired condition: an ended commercial term is
reported through the headers and banner above, never through the startup check.
Getting a license
Contact your Kamiwaza representative, or get in touch at
https://www.kamiwaza.ai/contact. Deliver the returned license.lic to the cluster
as described above; it does not need to be placed anywhere else.