diff --git a/.reuse/dep5 b/.reuse/dep5
index d512b69..17938f4 100644
--- a/.reuse/dep5
+++ b/.reuse/dep5
@@ -15,6 +15,6 @@
 License: BSD-2-Clause
 
 # certs are just math, no copyright
-Files: */files/certs/tls.* */files/certs/aether-roc-gui*
+Files: */files/certs/tls.* */files/certs/aether-roc-gui* */files/certs/aether-enterprise-portal*
 Copyright: 2021 Open Networking Foundation
 License: CC0-1.0
diff --git a/aether-enterprise-portal/.helmignore b/aether-enterprise-portal/.helmignore
new file mode 100644
index 0000000..f7a328e
--- /dev/null
+++ b/aether-enterprise-portal/.helmignore
@@ -0,0 +1,26 @@
+# SPDX-FileCopyrightText: 2021 Open Networking Foundation
+#
+# SPDX-License-Identifier: LicenseRef-ONF-Member-Only-1.0
+
+# Patterns to ignore when building packages.
+# This supports shell glob matching, relative path matching, and
+# negation (prefixed with !). Only one pattern per line.
+.DS_Store
+# Common VCS dirs
+.git/
+.gitignore
+.bzr/
+.bzrignore
+.hg/
+.hgignore
+.svn/
+# Common backup files
+*.swp
+*.bak
+*.tmp
+*~
+# Various IDEs
+.project
+.idea/
+*.tmproj
+.vscode/
diff --git a/aether-enterprise-portal/Chart.yaml b/aether-enterprise-portal/Chart.yaml
new file mode 100644
index 0000000..cd603e5
--- /dev/null
+++ b/aether-enterprise-portal/Chart.yaml
@@ -0,0 +1,20 @@
+# SPDX-FileCopyrightText: 2021-present Open Networking Foundation <info@opennetworking.org>
+#
+# SPDX-License-Identifier: LicenseRef-ONF-Member-Only-1.0
+
+apiVersion: v2
+name: aether-enterprise-portal
+description: Aether Enterprise Portal
+kubeVersion: ">=1.15.0"
+type: application
+version: 0.0.1
+appVersion: 0.0.1
+keywords:
+  - aether
+  - roc
+  - enterprise
+  - portal
+home: https://www.opennetworking.org/aether/
+maintainers:
+  - name: Aether Ops team
+    email: support@opennetworking.org
diff --git a/aether-enterprise-portal/README.md b/aether-enterprise-portal/README.md
new file mode 100644
index 0000000..6e6f2c0
--- /dev/null
+++ b/aether-enterprise-portal/README.md
@@ -0,0 +1,9 @@
+<!--
+SPDX-FileCopyrightText: 2021 Open Networking Foundation
+
+SPDX-License-Identifier: LicenseRef-ONF-Member-Only-1.0
+-->
+
+## Aether Enterprise Portal Helm Chart
+
+Provides a [Helm] chart for deploying Aether Enterprise Portal on [Kubernetes].
diff --git a/aether-enterprise-portal/files/certs/README.md b/aether-enterprise-portal/files/certs/README.md
new file mode 100644
index 0000000..7e6e434
--- /dev/null
+++ b/aether-enterprise-portal/files/certs/README.md
@@ -0,0 +1,32 @@
+<!--
+SPDX-FileCopyrightText: 2021 Open Networking Foundation
+
+SPDX-License-Identifier: LicenseRef-ONF-Member-Only-1.0
+-->
+
+This folder contains self-signed certificates for use in testing. _DO NOT USE THESE
+CERTIFICATES IN PRODUCTION!_
+
+The certificates were generated with the
+https://github.com/onosproject/simulators/blob/master/pkg/certs/generate_certs.sh 
+script as
+```bash
+generate-certs.sh onos-config.opennetworking.org
+```
+
+In this folder they **must** be (re)named
+* tls.cacrt
+* tls.crt
+* tls.key
+
+Use
+```bash
+openssl x509 -in deployments/helm/onos-config/files/certs/tls.crt -text -noout
+```
+to verify the contents (especially the subject).
+
+There is another Cert for onos-config in test/certs but these were created with:
+```
+generate-certs.sh onos-config
+```
+and are left named onf.cacrt, onos-config.key and onos-config.crt
\ No newline at end of file
diff --git a/aether-enterprise-portal/files/certs/aether-enterprise-portal.crt b/aether-enterprise-portal/files/certs/aether-enterprise-portal.crt
new file mode 100644
index 0000000..90be6b9
--- /dev/null
+++ b/aether-enterprise-portal/files/certs/aether-enterprise-portal.crt
@@ -0,0 +1,25 @@
+-----BEGIN CERTIFICATE-----
+MIIEMzCCAxugAwIBAgIUSsEbOxcejWXxuZlGYOQX6HZux1gwDQYJKoZIhvcNAQEL
+BQAwcjELMAkGA1UEBhMCVVMxCzAJBgNVBAgMAkNBMRIwEAYDVQQHDAlNZW5sb1Bh
+cmsxDDAKBgNVBAoMA09ORjEUMBIGA1UECwwLRW5naW5lZXJpbmcxHjAcBgNVBAMM
+FWNhLm9wZW5uZXR3b3JraW5nLm9yZzAeFw0yMDA5MjExMDIwMzZaFw0zMDA5MTkx
+MDIwMzZaMGsxCzAJBgNVBAYTAlVTMQswCQYDVQQIDAJDQTESMBAGA1UEBwwJTWVu
+bG9QYXJrMQwwCgYDVQQKDANPTkYxFDASBgNVBAsMC0VuZ2luZWVyaW5nMRcwFQYD
+VQQDDA5hZXRoZXItcm9jLWd1aTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoC
+ggEBAMWFBjPd37Kdj3HamDOiaFR0kHz5dRArxEflubl+E65HgxGEh6zq2WUZHtRO
+PL8Q/qoQ52IFADKzlGFAHJHDUesE6DRIsEyq/bEfwIuQtbBixYRL4h8BvcCZBf97
+KSHViezZBMEAyFfVrbrdQnUeuIKut8deJ559WYt8j/bNVHNLua+OJPHlKptmdpGY
+auNsKFF9G4Bnay7s9B4eYQKfOnxOLdpcshFXjZaZdFesp5MLHHURHgnuvUFYs9uX
+pegMXIgZvV8Mc443bF2QfRc1t4v7Bj3hNHwuKm1U86xMHs5sIvl3ruPuphhe4JFU
+OCJOmVJ+eGKm4rkiqsAsV2D9iiECAwEAAaOBxzCBxDCBjgYDVR0jBIGGMIGDoXak
+dDByMQswCQYDVQQGEwJVUzELMAkGA1UECAwCQ0ExEjAQBgNVBAcMCU1lbmxvUGFy
+azEMMAoGA1UECgwDT05GMRQwEgYDVQQLDAtFbmdpbmVlcmluZzEeMBwGA1UEAwwV
+Y2Eub3Blbm5ldHdvcmtpbmcub3JnggkA3vfX0jfasUkwCQYDVR0TBAIwADALBgNV
+HQ8EBAMCBPAwGQYDVR0RBBIwEIIOYWV0aGVyLXJvYy1ndWkwDQYJKoZIhvcNAQEL
+BQADggEBAIYqeb1s5vGdtJFVsUflxYOKHu9Ikj2tQ/zk+Q+VCchxm8NFo7sWQVwB
+94vccp9Lo5fw/3zYUa4Qc/TWaKC8KQrVpruY8SSkwqhtAbjHP4+SulxYmh8AKlEZ
+vM5K7d/f0Otn3tiwMihKf3YSlMqEdD86A+t79yqLuYSIz765eLfHmpyxLdrQCwEz
+YzQAW66VOrlx/J0Cv7S07of0/tjENuSiX0VTp5V+ThI8qtv0How+S1Jah/YtXf7B
+Az5eHcA/fwQ4sJuCHg+rPEnsRwL3CVbjYO2cVwRk+a/RgL549upBD/2e1/K+8n+h
+KN8Kga5HKpWtblEGWWVvNdc2Fm6vJS0=
+-----END CERTIFICATE-----
diff --git a/aether-enterprise-portal/files/certs/aether-enterprise-portal.key b/aether-enterprise-portal/files/certs/aether-enterprise-portal.key
new file mode 100644
index 0000000..c8edc9e
--- /dev/null
+++ b/aether-enterprise-portal/files/certs/aether-enterprise-portal.key
@@ -0,0 +1,28 @@
+-----BEGIN PRIVATE KEY-----
+MIIEvQIBADANBgkqhkiG9w0BAQEFAASCBKcwggSjAgEAAoIBAQDFhQYz3d+ynY9x
+2pgzomhUdJB8+XUQK8RH5bm5fhOuR4MRhIes6tllGR7UTjy/EP6qEOdiBQAys5Rh
+QByRw1HrBOg0SLBMqv2xH8CLkLWwYsWES+IfAb3AmQX/eykh1Yns2QTBAMhX1a26
+3UJ1HriCrrfHXieefVmLfI/2zVRzS7mvjiTx5SqbZnaRmGrjbChRfRuAZ2su7PQe
+HmECnzp8Ti3aXLIRV42WmXRXrKeTCxx1ER4J7r1BWLPbl6XoDFyIGb1fDHOON2xd
+kH0XNbeL+wY94TR8LiptVPOsTB7ObCL5d67j7qYYXuCRVDgiTplSfnhipuK5IqrA
+LFdg/YohAgMBAAECggEBALyxKAvEmj94ZeDOgzhQnnqQILhDV6HrLcfBnnumBgco
+Kf5CLZrzgFskdF89nqqpAaBWJbVuMZI+HDILnT9i6I8sUOghyMp1T4Y2Xyr1Q50N
+vsNz+sDEWRH1HdXDQrgf13N8nx4CMWI3r5Akb6iTgJDXeJntSMwP08t9Y8rSvSqm
+LoZqvJBSNOI0eUlJRjRA72JMGYndw3LlSKd5KdY1BTwQ7JrWtjpR2n4WZPSE9Rqq
+VwtbRaInFd5iMvRD15Kf+kp86ZDHGPD8Xr+iJIzraagVelXiE6YADnpArNl9fscm
+7vS2w0/Q+bxo+NK5wO7GW8CXhN1ePpfC1Q56hz5jSkECgYEA7qvAACZX1sMknhq2
+BWfW74+dNaerK+DRuH2zyg+010zF5dW8+6JhwwSiaDwpcKWFFemBOvESSmsgL4WU
+6q1EXo+0VrPlqbH0nHrLkgsklt+KH1yIaaaE5E2tK/gep1qdi9GIXscHSvGIfDw4
+50cdtTnBB+/52yBdc+hBu53fFEcCgYEA09xh/MbH/ZlptOIq4xrbzFaZdFA7s8FY
+jWsnl1gQarRyVET8ix6Fs7zg/MD9+V3KpbIm8dPrM4zqAQF02JP8vE7r1CFu+chJ
+Bz/+RuegYIMY5er6i1dhOZXxjFLZ8/+obISdod1cSxF/nqRSx5Bh+wgb8/5XV5Wf
+zilN5adWKlcCgYBfLJIV/TRN6edyPMiVA0GMqkJQoRn7F13KKiZFz1mX+X95FXCV
+D73YXMK+ui70Qqz9fe4QqQ1YK7vb93LY2ltHMhsB8B8HOnWG6NjA1jyzBVU5CFdF
+eifIOslxnTHsHpBwrw+oa8mWsxZwJDu0zoEkQXGeTq3eGdvqWpXL0TqiBQKBgDTZ
+GKhRfbnI9xFkCYa1QHbsc0MMcJgadthwDmQ2V4IGmS5kNwsNBhUb3JOwIKp/tvk2
+Q3i3gEhPsl+l2VvdLoJavYEhBenRCEaCtA9D4EGy8hcIUo9HsL0IpkR2tl+jOoQ3
+YIrsCQXAy7DrFKsrXQWdtDtdCrSSYlau/vt2jovpAoGAXc8a2A47boIFrC3RlLDx
+oPrAFPPt69TaZwuoYriF02/a965Zhgb2fRUUjjy5vTIolWCKQnfpc820umEVIqfb
+c46jacVkxqjQvoT6nUUnUjDsZFYq/M6mjWtBzVmKTitc1B1AZ0hLoUd9po5iuEWD
+bj7JUaqHjXzHcryPXTijqos=
+-----END PRIVATE KEY-----
diff --git a/aether-enterprise-portal/files/certs/tls.cacrt b/aether-enterprise-portal/files/certs/tls.cacrt
new file mode 100644
index 0000000..d4440bd
--- /dev/null
+++ b/aether-enterprise-portal/files/certs/tls.cacrt
@@ -0,0 +1,21 @@
+-----BEGIN CERTIFICATE-----
+MIIDYDCCAkgCCQDe99fSN9qxSTANBgkqhkiG9w0BAQsFADByMQswCQYDVQQGEwJV
+UzELMAkGA1UECAwCQ0ExEjAQBgNVBAcMCU1lbmxvUGFyazEMMAoGA1UECgwDT05G
+MRQwEgYDVQQLDAtFbmdpbmVlcmluZzEeMBwGA1UEAwwVY2Eub3Blbm5ldHdvcmtp
+bmcub3JnMB4XDTE5MDQxMTA5MDYxM1oXDTI5MDQwODA5MDYxM1owcjELMAkGA1UE
+BhMCVVMxCzAJBgNVBAgMAkNBMRIwEAYDVQQHDAlNZW5sb1BhcmsxDDAKBgNVBAoM
+A09ORjEUMBIGA1UECwwLRW5naW5lZXJpbmcxHjAcBgNVBAMMFWNhLm9wZW5uZXR3
+b3JraW5nLm9yZzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAMEg7CZR
+X8Y+syKHaQCh6mNIL1D065trwX8RnuKM2kBwSu034zefQAPloWugSoJgJnf5fe0j
+nUD8gN3Sm8XRhCkvf67pzfabgw4n8eJmHScyL/ugyExB6Kahwzn37bt3oT3gSqhr
+6PUznWJ8fvfVuCHZZkv/HPRp4eyAcGzbJ4TuB0go4s6VE0WU5OCxCSlAiK3lvpVr
+3DOLdYLVoCa5q8Ctl3wXDrfTLw5/Bpfrg9fF9ED2/YKIdV8KZ2ki/gwEOQqWcKp8
+0LkTlfOWsdGjp4opPuPT7njMBGXMJzJ8/J1e1aJvIsoB7n8XrfvkNiWL5U3fM4N7
+UZN9jfcl7ULmm7cCAwEAATANBgkqhkiG9w0BAQsFAAOCAQEAIh6FjkQuTfXddmZY
+FYpoTen/VD5iu2Xxc1TexwmKeH+YtaKp1Zk8PTgbCtMEwEiyslfeHTMtODfnpUIk
+DwvtB4W0PAnreRsqh9MBzdU6YZmzGyZ92vSUB3yukkHaYzyjeKM0AwgVl9yRNEZw
+Y/OM070hJXXzJh3eJpLl9dlUbMKzaoAh2bZx6y3ZJIZFs/zrpGfg4lvBAvfO/59i
+mxJ9bQBSN3U2Hwp6ioOQzP0LpllfXtx9N5LanWpB0cu/HN9vAgtp3kRTBZD0M1XI
+Ctit8bXV7Mz+1iGqoyUhfCYcCSjuWTgAxzir+hrdn7uO67Hv4ndCoSj4SQaGka3W
+eEfVeA==
+-----END CERTIFICATE-----
\ No newline at end of file
diff --git a/aether-enterprise-portal/files/certs/tls.crt b/aether-enterprise-portal/files/certs/tls.crt
new file mode 100644
index 0000000..2c7e2de
--- /dev/null
+++ b/aether-enterprise-portal/files/certs/tls.crt
@@ -0,0 +1,21 @@
+-----BEGIN CERTIFICATE-----
+MIIDcDCCAlgCFErBGzsXHo1l8bmZRmDkF+h2bsdTMA0GCSqGSIb3DQEBCwUAMHIx
+CzAJBgNVBAYTAlVTMQswCQYDVQQIDAJDQTESMBAGA1UEBwwJTWVubG9QYXJrMQww
+CgYDVQQKDANPTkYxFDASBgNVBAsMC0VuZ2luZWVyaW5nMR4wHAYDVQQDDBVjYS5v
+cGVubmV0d29ya2luZy5vcmcwHhcNMjAwNTA1MDc0MjEzWhcNMzAwNTAzMDc0MjEz
+WjB3MQswCQYDVQQGEwJVUzELMAkGA1UECAwCQ0ExEjAQBgNVBAcMCU1lbmxvUGFy
+azEMMAoGA1UECgwDT05GMRQwEgYDVQQLDAtFbmdpbmVlcmluZzEjMCEGA1UEAwwa
+Y2xpZW50MS5vcGVubmV0d29ya2luZy5vcmcwggEiMA0GCSqGSIb3DQEBAQUAA4IB
+DwAwggEKAoIBAQDK2amlhSGecWBI9jlj3OvCoGMAlHXffwHAsHskE/bFkyRKeYs0
+MHlcNBXSjgADtHt7FpGJ7nbZsMdu0XkNOlN/X0i8FKU7X9DnOHbHhOitg469J89D
+8tHnN2wrTyGxY2Km95PxeCQ4NH7z4MSSbdFfFXnw9k+qr+e1owswloJsYo+eyP7h
+jy7QvR2sAX8CC6D0ZaVuqLGK5kHJUyMxifqMa4D4wD8zfzahcTe2QAeOxQwhsaK2
+pZ/09bI/KCj8vxbxG2nkcwUgjl0Lgh0g1BFNSu39v1DjsiFWrIxnj3CL2Ncu0ps0
++dPSdpx90ImvjL4BRPz8V4iLPljmBmQfU2HpAgMBAAEwDQYJKoZIhvcNAQELBQAD
+ggEBADERPV5ykcjUaskgPHk081A0LmsKKL9AdqLfREreRIJgPg1T+ppE7PAf+i9m
+W6lojz+qCOkjd9d7Cd7wWRvrndRs6xt3HoIu3Z+knds/SC6emz/Rf+ZYsODNC3b3
+zv7agEeuD2M/Lq8pLfh9MsCxFmbz4JuiJ3kkT8zhiRAbUW6LkYFzdSeq6uUrhZPv
+C6VCZtHRQiEHE84Wwkxcz7shyknPwwDZxLoNeGjQPruESsY9Dyt96dz8yBQ6ukD1
+hPpnMDb+sksoX0ZOoEYpNdqDvZWa25n64LBBLuxbCuelSVUpsEdjRvh10znFY36x
+op/V1+9Wot9zMohw6bu5Aj9K6s8=
+-----END CERTIFICATE-----
diff --git a/aether-enterprise-portal/files/certs/tls.key b/aether-enterprise-portal/files/certs/tls.key
new file mode 100644
index 0000000..ca49789
--- /dev/null
+++ b/aether-enterprise-portal/files/certs/tls.key
@@ -0,0 +1,28 @@
+-----BEGIN PRIVATE KEY-----
+MIIEvgIBADANBgkqhkiG9w0BAQEFAASCBKgwggSkAgEAAoIBAQDK2amlhSGecWBI
+9jlj3OvCoGMAlHXffwHAsHskE/bFkyRKeYs0MHlcNBXSjgADtHt7FpGJ7nbZsMdu
+0XkNOlN/X0i8FKU7X9DnOHbHhOitg469J89D8tHnN2wrTyGxY2Km95PxeCQ4NH7z
+4MSSbdFfFXnw9k+qr+e1owswloJsYo+eyP7hjy7QvR2sAX8CC6D0ZaVuqLGK5kHJ
+UyMxifqMa4D4wD8zfzahcTe2QAeOxQwhsaK2pZ/09bI/KCj8vxbxG2nkcwUgjl0L
+gh0g1BFNSu39v1DjsiFWrIxnj3CL2Ncu0ps0+dPSdpx90ImvjL4BRPz8V4iLPljm
+BmQfU2HpAgMBAAECggEAVEd9Ca03m5nldEsA6zHVrmZu28XS94nQU5u/fezhgZMx
+59N597QQKDPnwTSIYwGwsCJfU5yFOssNAUj873cFTA1trd8yC2oy5G58Q0dAWR8o
+xgRtRAD2HwfS5GebSxVM3qxMhm3xNnzxJiiD44bHD6dfo7LixLsTHU9hjc1q4NaR
+BfJCl01f1EgEtPB4L7l3E1ivgy2OQ91gSJsIneA4RFLn5NbMac7ZWOTMGThjGFAw
+qR38Ua7TzQXL+qNzHU0JUOBg4smk5tzPxD8ik2p8VTc8WrPEBX129fn+JumhKoIC
+4LysZoazLhKem56LBVSW/TNybXPy9z+nBhbFbnoLAQKBgQDpPfvc83f/f5Iu3PaG
+8BsIoOonasqGsFoDB7XN/DZdjk8d9MKF+2tK8tRtwfZ+cWJL7m94ZCudtU72uhwN
+0x1E/p+qAUBvE3WR3MxQQb6R5kyzMUlwTjwrM49kMuQdU7CaL2abqRvvekkE6L13
+9KesvE0TQSTx+beMbzUUdDyCCQKBgQDepInF/pmwbM0E2zKYny0Ro3caW6HoUEoJ
+ZGcZ/NLdTgiQ3GJsVddc0M4jgXMndjOJFZcDDeFPgRAgQVnJHbDDWNygmNDBKavj
+LNcTIB2AO4ObWIH2C6x38V6l+62Nc9QPlI52tiekWVO1tAhy3FJXRHAUhP43bi36
+VnCg0mJY4QKBgFuSTEnpBJm4+imP8vHzXom6s3OaR70ti4lZA5XFiYqdjo5SQ/Ta
+Srt4LtKQrjfiSBdLm1QG7+DRCBlx5AXBduJZnVHff+6cEzKbH1P7G9ioNEC9/vkq
+nhDQA2HxYQHqk5FVPtGqSR9yQSy+O3TXBuWYYCJJFzoxMlDecFaBdCgRAoGBAIRc
+qZPOQyyB4nkKn8/ggfjEh+BhraXhZcKjsC/hALOU2r7UZqcleX2ynXq6UO2a9hR/
+g2HLdLHBdwbWEzzfq+DXCYNolmLgFVJfrBWwuBkuSJWoTssqMYS1OKHROGKqA96n
+YPLuZC7u9DdIKuWuWj2LcF6imkf19tunXBogOVvBAoGBAJvIYUGba3WU+/Ugs3yZ
+ubNBC52mS2kLrOTZfzQOP6sL3OC5rFgm7A4e/CMCWphns98ftB0c1RaZBCcwskUE
+mCxUxvivP7oUNf0CMZd6CW2M0LEWMVrIFJ1o0BtNpUVZ/+nipJblRA1B/JLsgNvn
+11mpIWR4KHd8A5wjkkfb2d/e
+-----END PRIVATE KEY-----
diff --git a/aether-enterprise-portal/templates/NOTES.txt b/aether-enterprise-portal/templates/NOTES.txt
new file mode 100644
index 0000000..7e54b13
--- /dev/null
+++ b/aether-enterprise-portal/templates/NOTES.txt
@@ -0,0 +1,22 @@
+# SPDX-FileCopyrightText: 2021 Open Networking Foundation
+#
+# SPDX-License-Identifier: LicenseRef-ONF-Member-Only-1.0
+
+Thank you for installing {{ .Chart.Name }} Helm chart.
+
+Your release is named {{ .Release.Name }} in namespace {{.Release.Namespace}}.
+See https://docs.onosproject.org/developers/deploy_with_helm/
+
+To learn more about the release, try:
+  $ helm -n {{.Release.Namespace}} status {{ .Release.Name }}
+  $ helm -n {{.Release.Namespace}} get all {{ .Release.Name }}
+
+{{ .Release.Name }} depends on the "aether-enterprise-portal which in turn depends
+on onos-config(with the Aether x.y.0 model plugins) and onos-topo"
+micro services.
+
+If you are using KinD as a Kubernetes server you will have to add a "port-forward" to access the aether-enterprise-portal e.g.
+$ kubectl -n {{.Release.Namespace}} port-forward service/{{.Values.fullnameOverride}} 8183:80
+and then access the API with:
+
+http://localhost:8183
diff --git a/aether-enterprise-portal/templates/_helpers.tpl b/aether-enterprise-portal/templates/_helpers.tpl
new file mode 100644
index 0000000..e786b78
--- /dev/null
+++ b/aether-enterprise-portal/templates/_helpers.tpl
@@ -0,0 +1,66 @@
+{{/* vim: set filetype=mustache: */}}
+{{/*
+SPDX-FileCopyrightText: 2021-present Open Networking Foundation <info@opennetworking.org>
+SPDX-License-Identifier: LicenseRef-ONF-Member-Only-1.0
+
+Expand the name of the chart.
+*/}}
+{{- define "aether-enterprise-portal.name" -}}
+{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" -}}
+{{- end -}}
+
+{{/*
+Create a default fully qualified app name.
+We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec).
+If release name contains chart name it will be used as a full name.
+*/}}
+{{- define "aether-enterprise-portal.fullname" -}}
+{{- if .Values.fullnameOverride -}}
+{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" -}}
+{{- else -}}
+{{- $name := default .Chart.Name .Values.nameOverride -}}
+{{- if contains $name .Release.Name -}}
+{{- .Release.Name | trunc 63 | trimSuffix "-" -}}
+{{- else -}}
+{{- printf "%s-%s" .Release.Name $name | trunc 63 | trimSuffix "-" -}}
+{{- end -}}
+{{- end -}}
+{{- end -}}
+
+{{/*
+Create chart name and version as used by the chart label.
+*/}}
+{{- define "aether-enterprise-portal.chart" -}}
+{{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" -}}
+{{- end -}}
+
+{{/*
+Common labels
+*/}}
+{{- define "aether-enterprise-portal.labels" -}}
+helm.sh/chart: {{ include "aether-enterprise-portal.chart" . }}
+{{ include "aether-enterprise-portal.selectorLabels" . }}
+{{- if .Chart.AppVersion }}
+app.kubernetes.io/version: {{ .Chart.AppVersion | quote }}
+{{- end }}
+app.kubernetes.io/managed-by: {{ .Release.Service }}
+{{- end -}}
+
+{{/*
+Selector labels
+*/}}
+{{- define "aether-enterprise-portal.selectorLabels" -}}
+app.kubernetes.io/name: {{ include "aether-enterprise-portal.name" . }}
+app.kubernetes.io/instance: {{ .Release.Name }}
+{{- end -}}
+
+{{/*
+Create the name of the service account to use
+*/}}
+{{- define "aether-enterprise-portal.serviceAccountName" -}}
+{{- if .Values.serviceAccount.create -}}
+    {{ default (include "aether-enterprise-portal.fullname" .) .Values.serviceAccount.name }}
+{{- else -}}
+    {{ default "default" .Values.serviceAccount.name }}
+{{- end -}}
+{{- end -}}
diff --git a/aether-enterprise-portal/templates/configmap.yaml b/aether-enterprise-portal/templates/configmap.yaml
new file mode 100644
index 0000000..a16976c
--- /dev/null
+++ b/aether-enterprise-portal/templates/configmap.yaml
@@ -0,0 +1,64 @@
+# SPDX-FileCopyrightText: 2021-present Open Networking Foundation <info@opennetworking.org>
+#
+# SPDX-License-Identifier: LicenseRef-ONF-Member-Only-1.0
+
+apiVersion: v1
+kind: ConfigMap
+metadata:
+  name: {{ template "aether-enterprise-portal.fullname" . }}
+  namespace: {{ .Release.Namespace }}
+  labels:
+    release: {{ .Release.Name }}
+    heritage: {{ .Release.Service }}
+data:
+  server-block.conf: |-
+    server {
+        listen {{.Values.Nginx.port}};
+        ssl_certificate /usr/share/certs/aether-enterprise-portal.crt;
+        ssl_certificate_key /usr/share/certs/aether-enterprise-portal.key;
+        {{- if .Values.websocket.proxyEnabled }}
+        location /ws {
+            proxy_pass {{ .Values.websocket.protocol }}://{{ .Values.websocket.service }}:{{ .Values.websocket.port }}/ws;
+            proxy_http_version 1.1;
+            proxy_set_header Upgrade $http_upgrade;
+            proxy_set_header Connection "Upgrade";
+            proxy_set_header Host $host;
+        }{{end}}
+        {{- if .Values.grafana.proxyEnabled }}
+        location /grafana/ {
+            proxy_pass {{ .Values.grafana.protocol }}://{{ .Values.grafana.service }}:{{ .Values.grafana.port }}/;
+            proxy_http_version 1.1;
+            proxy_redirect off;
+            proxy_set_header Upgrade $http_upgrade;
+            proxy_set_header Connection "Upgrade";
+            proxy_set_header X-Real-IP $remote_addr;
+            proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
+            proxy_set_header Host $http_host;
+            proxy_set_header X-NginX-Proxy true;
+            proxy_hide_header 'X-Frame-Options';
+            add_header X-Frame-Options SAMEORIGIN;
+        }{{end}}
+        {{- if .Values.prometheus.proxyEnabled }}
+        location /prometheus/ {
+            proxy_pass {{ .Values.prometheus.protocol }}://{{ .Values.prometheus.service }}:{{ .Values.prometheus.port }}/;
+            proxy_http_version 1.1;
+            proxy_set_header Upgrade $http_upgrade;
+            add_header X-Frame-Options SAMEORIGIN;
+        }{{end}}
+        location / {
+          root /usr/share/nginx/html;
+        }
+        {{- range $key, $value := .Values.aetherservices }}
+        location /{{ $key }}/ {
+            proxy_pass {{ $value.protocol}}://{{$key}}:{{ $value.http }}/;
+            proxy_http_version 1.1;
+            proxy_set_header Upgrade $http_upgrade;
+            proxy_set_header Connection "Upgrade";
+            proxy_connect_timeout       {{ $value.streamTimeout }};
+            proxy_send_timeout          {{ $value.streamTimeout }};
+            proxy_read_timeout          {{ $value.streamTimeout }};
+            send_timeout                {{ $value.streamTimeout }};
+        }
+        {{ end }}
+    }
+
diff --git a/aether-enterprise-portal/templates/deployment.yaml b/aether-enterprise-portal/templates/deployment.yaml
new file mode 100644
index 0000000..792d148
--- /dev/null
+++ b/aether-enterprise-portal/templates/deployment.yaml
@@ -0,0 +1,92 @@
+# SPDX-FileCopyrightText: 2021-present Open Networking Foundation <info@opennetworking.org>
+#
+# SPDX-License-Identifier: LicenseRef-ONF-Member-Only-1.0
+
+apiVersion: apps/v1
+kind: Deployment
+metadata:
+  name: {{ include "aether-enterprise-portal.fullname" . }}
+  namespace: {{ .Release.Namespace }}
+  labels:
+    {{- include "aether-enterprise-portal.labels" . | nindent 4 }}
+spec:
+  replicas: {{ .Values.replicaCount }}
+  selector:
+    matchLabels:
+      name: {{ template "aether-enterprise-portal.fullname" . }}
+      app: aether
+      type: arg
+      resource: {{ template "aether-enterprise-portal.fullname" . }}
+      {{- include "aether-enterprise-portal.selectorLabels" . | nindent 6 }}
+  template:
+    metadata:
+      labels:
+        name: {{ template "aether-enterprise-portal.fullname" . }}
+        app: aether
+        type: arg
+        resource: {{ template "aether-enterprise-portal.fullname" . }}
+        {{- include "aether-enterprise-portal.selectorLabels" . | nindent 8 }}
+    spec:
+    {{- with .Values.imagePullSecrets }}
+      imagePullSecrets:
+        {{- toYaml . | nindent 8 }}
+    {{- end }}
+      securityContext:
+        {{- toYaml .Values.podSecurityContext | nindent 8 }}
+      containers:
+        - name: {{ .Chart.Name }}
+          securityContext:
+            {{- toYaml .Values.securityContext | nindent 12 }}
+          image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}"
+          imagePullPolicy: {{ .Values.image.pullPolicy }}
+          env:
+            - name: NAMESPACE
+              valueFrom:
+                fieldRef:
+                  fieldPath: metadata.namespace
+            - name: OPENIDCISSUER
+              value: {{ .Values.openidc.issuer }}
+          stdin : true
+          resources:
+            {{- toYaml .Values.resources | nindent 12 }}
+          ports:
+            {{- with .Values.ports }}
+            {{- range $key, $port := . }}
+            - name: {{ $key }}
+              {{ toYaml $port | nindent 14 }}
+            {{- end }}
+            {{- end }}
+          livenessProbe:
+            tcpSocket:
+              port: web
+            initialDelaySeconds: 30
+          readinessProbe:
+            tcpSocket:
+              port: web
+            initialDelaySeconds: 30
+          volumeMounts:
+            - name: config
+              mountPath: /etc/nginx/conf.d
+            - name: secret
+              mountPath: /usr/share/certs
+              readOnly: true
+
+      volumes:
+        - name: config
+          configMap:
+            name: {{ template "aether-enterprise-portal.fullname" . }}
+        - name: secret
+          secret:
+            secretName: {{ template "aether-enterprise-portal.fullname" . }}-secret
+      {{- with .Values.nodeSelector }}
+      nodeSelector:
+        {{- toYaml . | nindent 8 }}
+      {{- end }}
+    {{- with .Values.affinity }}
+      affinity:
+        {{- toYaml . | nindent 8 }}
+    {{- end }}
+    {{- with .Values.tolerations }}
+      tolerations:
+        {{- toYaml . | nindent 8 }}
+    {{- end }}
diff --git a/aether-enterprise-portal/templates/ingress.yaml b/aether-enterprise-portal/templates/ingress.yaml
new file mode 100644
index 0000000..bb28795
--- /dev/null
+++ b/aether-enterprise-portal/templates/ingress.yaml
@@ -0,0 +1,35 @@
+# SPDX-FileCopyrightText: 2021-present Open Networking Foundation <info@opennetworking.org>
+#
+# SPDX-License-Identifier: LicenseRef-ONF-Member-Only-1.0
+
+{{- if .Values.ingress.enabled }}
+apiVersion: networking.k8s.io/v1
+kind: Ingress
+metadata:
+  name: {{ template "aether-enterprise-portal.fullname" . }}-ingress
+  namespace: {{ .Release.Namespace }}
+  labels:
+    chart: "{{ .Chart.Name }}-{{ .Chart.Version }}"
+    release: "{{ .Release.Name }}"
+    heritage: "{{ .Release.Service }}"
+  annotations:
+    kubernetes.io/ingress.class: "nginx"
+    nginx.ingress.kubernetes.io/ssl-redirect: "false"
+    nginx.ingress.kubernetes.io/backend-protocol: "HTTP"
+spec:
+  tls:
+    - secretName: {{ template "aether-enterprise-portal.fullname" . }}-secret
+      hosts:
+        - aether-enterprise-portal.onosproject.org
+  rules:
+    - host: aether-enterprise-portal.onosproject.org
+      http:
+        paths:
+          - pathType: Prefix
+            path: "/"
+            backend:
+              service:
+                name: {{ template "aether-enterprise-portal.fullname" . }}
+                port:
+                  number: {{ .Values.ports.web.containerPort }}
+{{- end }}
diff --git a/aether-enterprise-portal/templates/role.yaml b/aether-enterprise-portal/templates/role.yaml
new file mode 100644
index 0000000..779e746
--- /dev/null
+++ b/aether-enterprise-portal/templates/role.yaml
@@ -0,0 +1,13 @@
+# SPDX-FileCopyrightText: 2021-present Open Networking Foundation <info@opennetworking.org>
+#
+# SPDX-License-Identifier: LicenseRef-ONF-Member-Only-1.0
+
+kind: Role
+apiVersion: rbac.authorization.k8s.io/v1
+metadata:
+  namespace: {{ .Release.Namespace }}
+  name: {{ template "aether-enterprise-portal.fullname" . }}-service-role
+rules:
+  - apiGroups: [""] # "" indicates the core API group
+    resources: ["services"]
+    verbs: ["get", "watch", "list"]
diff --git a/aether-enterprise-portal/templates/rolebinding.yaml b/aether-enterprise-portal/templates/rolebinding.yaml
new file mode 100644
index 0000000..06e971f
--- /dev/null
+++ b/aether-enterprise-portal/templates/rolebinding.yaml
@@ -0,0 +1,17 @@
+# SPDX-FileCopyrightText: 2021-present Open Networking Foundation <info@opennetworking.org>
+#
+# SPDX-License-Identifier: LicenseRef-ONF-Member-Only-1.0
+
+apiVersion: rbac.authorization.k8s.io/v1
+kind: RoleBinding
+metadata:
+  name: {{ template "aether-enterprise-portal.fullname" . }}-access-services
+  namespace: {{ .Release.Namespace }}
+subjects:
+  - kind: ServiceAccount
+    name: default # Name is case sensitive
+    namespace: {{ .Release.Namespace }}
+roleRef:
+  kind: Role
+  name: {{ template "aether-enterprise-portal.fullname" . }}-service-role
+  apiGroup: rbac.authorization.k8s.io
diff --git a/aether-enterprise-portal/templates/secret.yaml b/aether-enterprise-portal/templates/secret.yaml
new file mode 100644
index 0000000..071304f
--- /dev/null
+++ b/aether-enterprise-portal/templates/secret.yaml
@@ -0,0 +1,18 @@
+# SPDX-FileCopyrightText: 2021-present Open Networking Foundation <info@opennetworking.org>
+#
+# SPDX-License-Identifier: LicenseRef-ONF-Member-Only-1.0
+
+apiVersion: v1
+kind: Secret
+metadata:
+  name: {{ template "aether-enterprise-portal.fullname" . }}-secret
+  labels:
+     chart: "{{ .Chart.Name }}-{{ .Chart.Version }}"
+     release: "{{ .Release.Name }}"
+     heritage: "{{ .Release.Service }}"
+data:
+  {{ $root := . }}
+  {{ range $path, $bytes := .Files.Glob "files/certs/*.*" }}
+  {{ base $path }}: '{{ $root.Files.Get $path | b64enc }}'
+  {{ end }}
+type: Opaque
diff --git a/aether-enterprise-portal/templates/service.yaml b/aether-enterprise-portal/templates/service.yaml
new file mode 100644
index 0000000..132efda
--- /dev/null
+++ b/aether-enterprise-portal/templates/service.yaml
@@ -0,0 +1,51 @@
+# SPDX-FileCopyrightText: 2021-present Open Networking Foundation <info@opennetworking.org>
+#
+# SPDX-License-Identifier: LicenseRef-ONF-Member-Only-1.0
+
+apiVersion: v1
+kind: Service
+metadata:
+  name: {{ template "aether-enterprise-portal.fullname" . }}
+  labels:
+    app: {{ template "aether-enterprise-portal.fullname" . }}
+    chart: "{{ .Chart.Name }}-{{ .Chart.Version }}"
+    release: "{{ .Release.Name }}"
+    heritage: "{{ .Release.Service }}"
+    {{- include "aether-enterprise-portal.labels" . | nindent 4 }}
+spec:
+  type: {{ .Values.service.type }}
+  selector:
+    name: {{ template "aether-enterprise-portal.fullname" . }}
+    app: aether
+    type: arg
+    resource: {{ template "aether-enterprise-portal.fullname" . }}
+    {{- include "aether-enterprise-portal.selectorLabels" . | nindent 4 }}
+  ports:
+    - name: web
+      port: 80
+---
+{{- if .Values.service.external.nodePort }}
+apiVersion: v1
+kind: Service
+metadata:
+  name: {{ template "aether-enterprise-portal.fullname" . }}-external
+  labels:
+    app: {{ template "aether-enterprise-portal.fullname" . }}
+    chart: "{{ .Chart.Name }}-{{ .Chart.Version }}"
+    release: "{{ .Release.Name }}"
+    heritage: "{{ .Release.Service }}"
+    {{- include "aether-enterprise-portal.labels" . | nindent 4 }}
+spec:
+  type: NodePort
+  selector:
+    name: {{ template "aether-enterprise-portal.fullname" . }}
+    app: aether
+    type: arg
+    resource: {{ template "aether-enterprise-portal.fullname" . }}
+    {{- include "aether-enterprise-portal.selectorLabels" . | nindent 4 }}
+  ports:
+    - name: web
+      port: 80
+      nodePort: {{ .Values.service.external.nodePort }}
+      protocol: TCP
+{{- end }}
diff --git a/aether-enterprise-portal/values.yaml b/aether-enterprise-portal/values.yaml
new file mode 100644
index 0000000..f3d7e49
--- /dev/null
+++ b/aether-enterprise-portal/values.yaml
@@ -0,0 +1,86 @@
+# SPDX-FileCopyrightText: 2021-present Open Networking Foundation <info@opennetworking.org>
+#
+# SPDX-License-Identifier: LicenseRef-ONF-Member-Only-1.0
+
+# Default values for aether-enterprise-portal.
+# This is a YAML-formatted file.
+# Declare variables to be passed into your templates.
+
+replicaCount: 1
+
+image:
+  repository: onosproject/aether-enterprise-portal
+  tag: latest
+  pullPolicy: IfNotPresent
+  pullSecrets: []
+
+imagePullSecrets: []
+nameOverride: ""
+fullnameOverride: "aether-enterprise-portal"
+
+## Client service.
+service:
+  enabled: true
+  ## Service name is user-configurable for maximum service discovery flexibility.
+  name: aether-enterprise-portal
+  type: LoadBalancer
+  external:
+    nodePort: 31195
+
+ingress:
+  enabled: false
+
+ports:
+  web:
+    containerPort: 80
+    protocol: TCP
+
+# Enable by giving a value like https://keycloak-dev.onlab.us/auth/realms/master
+# make sure this is reachable at https://keycloak-dev.onlab.us/auth/realms/master/.well-known/openid-configuration
+openidc:
+  issuer:
+
+resources: {}
+  # We usually recommend not to specify default resources and to leave this as a conscious
+  # choice for the user. This also increases chances charts run on environments with little
+  # resources, such as Minikube. If you do want to specify resources, uncomment the following
+  # lines, adjust them as necessary, and remove the curly braces after 'resources:'.
+  # limits:
+  #   cpu: 100m
+  #   memory: 128Mi
+  # requests:
+  #   cpu: 100m
+  #   memory: 128Mi
+
+nodeSelector: {}
+
+tolerations: []
+
+affinity: {}
+
+aetherservices:
+  chronos-exporter:
+    http: 2112
+    protocol: http
+    streamTimeout: 3600
+
+websocket:
+  proxyEnabled: false
+  service: aether-roc-websocket
+  protocol: http
+  port: 80
+
+grafana:
+  proxyEnabled: false
+  service: grafana
+  protocol: http
+  port: 80
+
+prometheus:
+  proxyEnabled: false
+  service: prometheus
+  protocol: http
+  port: 80
+
+Nginx:
+  port: 80
diff --git a/chronos-umbrella/Chart.yaml b/chronos-umbrella/Chart.yaml
index eefaa6a..890e03b 100644
--- a/chronos-umbrella/Chart.yaml
+++ b/chronos-umbrella/Chart.yaml
@@ -7,7 +7,7 @@
 description: Chronos Umbrella chart to deploy all Aether ROC
 kubeVersion: ">=1.18.0"
 type: application
-version: 0.0.3
+version: 0.0.4
 appVersion: v0.0.0
 keywords:
   - aether
@@ -30,3 +30,7 @@
     condition: import.chronos-exporter.enabled
     repository: "file://../chronos-exporter"
     version: 0.0.3
+  - name: aether-enterprise-portal
+    condition: import.aether-enterprise-portal.enabled
+    repository: "file://../aether-enterprise-portal"
+    version: 0.0.1
diff --git a/chronos-umbrella/values.yaml b/chronos-umbrella/values.yaml
index efb69bd..34af676 100644
--- a/chronos-umbrella/values.yaml
+++ b/chronos-umbrella/values.yaml
@@ -18,13 +18,16 @@
       enabled: true
   chronos-exporter:
     enabled: true
+  aether-enterprise-portal:
+    enabled: true
 
-#chronos-exporter:
-    #image:
-    #repository: onosproject/chronos-exporter
-    #tag: v0.0.1
-    #pullPolicy: IfNotPresent
-    #pullSecrets: []
+aether-enterprise-portal:
+  grafana:
+    proxyEnabled: true
+    service: chronos-umbrella-grafana
+  prometheus:
+    proxyEnabled: true
+    service: chronos-umbrella-prometheus-chronos-server
 
 grafana:
   sidecar:
