Repository navigation
Conversation
521a6bc to
d9ecae2
Compare
f65589e to
660543b
Compare
| {{- include "mlrun-ce.pipelines.labels" . | nindent 4 }} | ||
| type: Opaque | ||
| stringData: | ||
| accesskey: {{ include "mlrun-ce.seaweedfs.s3.accessKey" . | quote }} |
There was a problem hiding this comment.
From the helper, it looks like it is using MLRun configuration. Can you please verify that you can point MLRun to local but pipelines to remote
There was a problem hiding this comment.
@shay79il this one still needs to be resolved - you are pointing to mlrun conf and not pipelines creds
{{- define "mlrun-ce.seaweedfs.s3.accessKey" -}}
{{- .Values.storage.local.accessKey -}}
{{- end -}}
Please try running your code and store MLRun to S3 bucket x with x creds and pipelines to S3 bucket y with different creds.
Other then that look good
…dation for SeaweedFS remote configuration
…d, detailing local and remote storage options with configuration examples
… configuration; enhance validation checks for Azure provider
…etails; refactor static credentials usage in templates
… disable remote storage
…guration details; add nonempty option in values.yaml for handling existing pipeline data during upgrades
…structions; update values.yaml for Azure storage configuration; enhance validation checks for Azure provider in templates
…rom values files and templates; update README.md to clarify SeaweedFS usage for pipeline artifacts.
…nfiguration; enhance validation checks for SeaweedFS remote provider in templates.
… by breaking down the command into multiple lines for better readability and maintainability.
… configuration; enhance Azure Blob example and clarify usage in templates.
…te overlay examples for Azure and S3; streamline configuration for clarity and consistency.
… remote overlay example for improved compatibility with S3 storage.
… configuration; clarify usage of mount options and enhance Azure Blob example with command syntax.
…nd S3; clarify usage of emptyDir for lab/dev testing and provide verification steps for remote sync.
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Critical IAM credential and mountExisting: false paths can fail, with additional validation gaps.
Review effort: Lite
Findings: 4
Open (5)
What changed in this PR
Adds optional SeaweedFS remote-gateway synchronization for KFP artifacts stored locally while syncing to AWS S3 or Azure Blob.
Changes:
- Adds remote gateway configuration, credentials, mounting, deployment, and examples.
- Simplifies KFP storage around in-cluster SeaweedFS and updates component configuration.
- Adds storage validation, MySQL compatibility handling, documentation, and a chart version bump.
| File | Summary |
|---|---|
charts/mlrun-ce/values.yaml |
Adds remote gateway settings and updated KFP values. |
charts/mlrun-ce/templates/seaweedfs/seaweedfs-remote-secret.yaml |
Creates remote credential Secret. |
charts/mlrun-ce/templates/seaweedfs/seaweedfs-remote-gateway-deployment.yaml |
Runs background remote synchronization. |
charts/mlrun-ce/templates/seaweedfs/seaweedfs-remote-config-job.yaml |
Configures and mounts remote storage. |
charts/mlrun-ce/templates/seaweedfs/s3-bucket-init-job.yaml |
Updates bucket initialization behavior. |
charts/mlrun-ce/templates/pipelines/secrets/mlpipeline-seaweedfs-artifact.yaml |
Removes the replaced artifact Secret template. |
charts/mlrun-ce/templates/pipelines/secrets/mlpipeline-artifact-secret.yaml |
Defines the replacement artifact Secret. |
charts/mlrun-ce/templates/pipelines/deployments/mysql.yaml |
Selects MySQL authentication flags by version. |
charts/mlrun-ce/templates/pipelines/deployments/ml-pipeline.yaml |
Configures KFP for local SeaweedFS storage. |
charts/mlrun-ce/templates/pipelines/deployments/ml-pipeline-ui.yaml |
Updates SeaweedFS service references. |
charts/mlrun-ce/templates/pipelines/configmaps/workflow-controller-configmap.yaml |
Points workflow artifacts to SeaweedFS. |
charts/mlrun-ce/templates/pipelines/configmaps/pipeline-install-config.yaml |
Updates local object-store settings. |
charts/mlrun-ce/templates/pipelines/configmaps/kfp-launcher.yaml |
Sets the local pipeline root. |
charts/mlrun-ce/templates/config/storage-validation.yaml |
Validates remote storage configuration. |
charts/mlrun-ce/templates/_helpers.tpl |
Adds storage and gateway helpers. |
charts/mlrun-ce/README.md |
Documents remote artifact storage. |
charts/mlrun-ce/examples/seaweedfs-remote-s3-overlay.yaml |
Adds an AWS S3 overlay example. |
charts/mlrun-ce/examples/seaweedfs-remote-azure-overlay.yaml |
Adds an Azure Blob overlay example. |
charts/mlrun-ce/examples/README.md |
Documents deployment and verification steps. |
charts/mlrun-ce/Chart.yaml |
Bumps the chart version. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| {{- if and (eq (include "mlrun-ce.seaweedfs.remote.enabled" . | toString) "true") (eq .Values.seaweedfs.remote.provider "s3") (not .Values.global.infrastructure.aws.s3NonAnonymous) (not .Values.storage.s3.accessKey) }} | ||
| {{ fail "seaweedfs.remote with provider \"s3\" requires storage.s3.accessKey." }} | ||
| {{- end }} | ||
| {{- if and (eq (include "mlrun-ce.seaweedfs.remote.enabled" . | toString) "true") (eq .Values.seaweedfs.remote.provider "s3") (not .Values.global.infrastructure.aws.s3NonAnonymous) (not .Values.storage.s3.secretKey) }} | ||
| {{ fail "seaweedfs.remote with provider \"s3\" requires storage.s3.secretKey." }} | ||
| {{- end }} |
| if [ "${MOUNT_EXISTING}" = "true" ]; then | ||
| MOUNT_CMD="remote.mount -dir=${MOUNT_DIR} -remote=${REMOTE_PATH}" | ||
| if [ "${MOUNT_NONEMPTY}" = "true" ]; then | ||
| MOUNT_CMD="${MOUNT_CMD} -nonempty" | ||
| fi | ||
| echo "${MOUNT_CMD}" | ||
| fi |
| - name: wait-for-remote-mount | ||
| image: {{ include "mlrun-ce.seaweedfs.image" . | quote }} | ||
| imagePullPolicy: IfNotPresent | ||
| command: | ||
| - /bin/sh | ||
| - -ec | ||
| - | | ||
| FILER="{{ include "mlrun-ce.seaweedfs.filerAddress" . }}" | ||
| MASTER="{{ include "mlrun-ce.seaweedfs.masterAddress" . }}" | ||
| MOUNT_DIR="/buckets/{{ include "mlrun-ce.seaweedfs.remote.localBucket" . }}" | ||
| until printf 'remote.mount\n' | weed shell -filer="${FILER}" -master="${MASTER}" 2>&1 | grep -Fq "${MOUNT_DIR}"; do | ||
| echo "waiting for remote mount at ${MOUNT_DIR}..." | ||
| sleep 5 | ||
| done |
| AWS_ACCESS_KEY_ID: {{ required "storage.s3.accessKey is required for seaweedfs.remote provider s3" .Values.storage.s3.accessKey | quote }} | ||
| AWS_SECRET_ACCESS_KEY: {{ required "storage.s3.secretKey is required for seaweedfs.remote provider s3" .Values.storage.s3.secretKey | quote }} |
|
|
||
| | MLRun CE | MLRun | Nuclio | Jupyter | MPI Operator | SeaweedFS | Spark Operator | Pipelines | Kube-Prometheus-Stack | OpenTelemetry Operator | | ||
| | ---------------- | ----------- | ------- | ----------- | ------------ | --------- | -------------- | --------- | --------------------- | ---------------------- | | ||
| | **0.11.0** | 1.11.0 | 1.15.27 | 4.5.0 | 0.2.3 | 4.17.0 | 2.1.0 | 2.15.0 | 72.1.1 | 0.78.1 | |


📝 Description
Adds SeaweedFS remote gateway support so KFP pipeline artifacts remain on in-cluster SeaweedFS (
pipelines.storage.mode: local) while syncing to external AWS S3 or Azure Blob in the background.This replaces the previous model where KFP talked directly to external object storage via
pipelines.storage.mode: s3/azure-blob. MLRun and Jupyter storage (storage.mode) is unchanged and independent.🛠️ Changes Made
seaweedfs.remote.enabled):seaweedfs-remote-secret.yaml— cloud credentials (S3 keys fromstorage.s3.*, Azure fromstorage.azure.*)seaweedfs-remote-config-job.yaml— Helm hook Job that runsremote.configure+remote.mounton the filerseaweedfs-remote-gateway-deployment.yaml—filer.remote.gatewaysyncs local bucket → remote backendexamples/seaweedfs-remote-s3-overlay.yaml,examples/seaweedfs-remote-azure-overlay.yamlstorage-validation.yaml):pipelines.storage.mode: local(rejects direct external KFP modes)seaweedfs.remote.*(provider, bucket, remote name charset, S3 endpoint, credentials)_helpers.tpl):mlrun-ce.pipelines.storage.modehardcoded tolocalprovidersblock fromkfp-launcher.yamlOBJECTSTORECONFIG_REGIONfromml-pipeline.yamlmlpipeline-seaweedfs-artifact.yaml→mlpipeline-artifact-secret.yamlmysql.yaml): auth plugin flag selected by image tag —--default-authentication-pluginfor 8.0.x,--mysql-native-password=ONfor 8.4+deployment.yaml+values.yaml): addedstartupProbe(/api); readiness probe path changed from/labto/apifor slow cold startsseaweedfs.remoteblock (defaultenabled: false); added tovalues.yamland all three install-mode values files0.12.0-rc.11✅ Checklist
charts/mlrun-ce/Chart.yaml.🧪 Testing
Please see