Skip to content

[Feature] KFP pipeline artifacts remain on in-cluster SeaweedFS while syncing to external AWS S3 or Azure Blob in the background - #311

Open
shay79il wants to merge 16 commits into
mlrun:developmentfrom
shay79il:CEML-713
Open

shay79il wants to merge 16 commits into
mlrun:developmentfrom
shay79il:CEML-713

Conversation

@shay79il

@shay79il shay79il commented Aug 18, 2026 •

Copy link
Copy Markdown
Collaborator

📝 Description

Adds SeaweedFS remote gateway support so KFP pipeline artifacts remain on in-cluster SeaweedFS (pipelines.storage.mode: local) while syncing to external AWS S3 or Azure Blob in the background.

This replaces the previous model where KFP talked directly to external object storage via pipelines.storage.mode: s3 / azure-blob. MLRun and Jupyter storage (storage.mode) is unchanged and independent.


🛠️ Changes Made

  • New SeaweedFS remote components (seaweedfs.remote.enabled):
    • seaweedfs-remote-secret.yaml — cloud credentials (S3 keys from storage.s3.*, Azure from storage.azure.*)
    • seaweedfs-remote-config-job.yaml — Helm hook Job that runs remote.configure + remote.mount on the filer
    • seaweedfs-remote-gateway-deployment.yaml — filer.remote.gateway syncs local bucket → remote backend
  • New example overlays: examples/seaweedfs-remote-s3-overlay.yaml, examples/seaweedfs-remote-azure-overlay.yaml
  • Storage validation (storage-validation.yaml):
    • Requires pipelines.storage.mode: local (rejects direct external KFP modes)
    • Validates seaweedfs.remote.* (provider, bucket, remote name charset, S3 endpoint, credentials)
  • Helpers refactor (_helpers.tpl):
    • mlrun-ce.pipelines.storage.mode hardcoded to local
    • Pipeline S3 settings delegate to in-cluster SeaweedFS
    • New remote-gateway helpers
  • KFP templates simplified for local-only object store:
    • Removed external providers block from kfp-launcher.yaml
    • Removed conditional OBJECTSTORECONFIG_REGION from ml-pipeline.yaml
    • Renamed secret template: mlpipeline-seaweedfs-artifact.yaml → mlpipeline-artifact-secret.yaml
  • MySQL (mysql.yaml): auth plugin flag selected by image tag — --default-authentication-plugin for 8.0.x, --mysql-native-password=ON for 8.4+
  • Jupyter (deployment.yaml + values.yaml): added startupProbe (/api); readiness probe path changed from /lab to /api for slow cold starts
  • Values: new seaweedfs.remote block (default enabled: false); added to values.yaml and all three install-mode values files
  • Chart version: 0.12.0-rc.11

✅ Checklist

  • I have tested the changes in this PR
  • I confirmed whether my changes require a change in documentation and if so, I created another PR in MLRun for the relevant documentation.
  • I confirmed whether my changes require a changes in QA tests, for example: credentials changes, resources naming change and if so, I updated the relevant Jira ticket for QA.
  • I increased the Chart version in charts/mlrun-ce/Chart.yaml.
  • I confirmed that the installation works both on a local Docker Desktop environment and on a real cluster when using the required prerequisites.
    • If installation issues were found, I updated the relevant Jira ticket with the issue and steps to reproduce, or updated the prerequisites documentation if the issue is related to missing or outdated prerequisites.
  • If needed, update https://github.com/mlrun/ce/blob/development/charts/mlrun-ce/README.md with the relevant installation instructions and version Matrix.
  • If needed, update the following values files for multi namespace support:

🧪 Testing

Please see

  • charts/mlrun-ce/examples/seaweedfs-remote-azure-overlay.yaml
  • charts/mlrun-ce/examples/seaweedfs-remote-s3-overlay.yaml

@shay79il shay79il changed the title [Feature] Bump chart version to 0.12.0-rc.11 and enhance storage validation for SeaweedFS remote configuration [Feature] KFP pipeline artifacts remain on in-cluster SeaweedFS while syncing to external AWS S3 or Azure Blob in the background Aug 18, 2026
Comment thread charts/mlrun-ce/examples/seaweedfs-local-overlay.yaml Outdated
Comment thread charts/mlrun-ce/examples/seaweedfs-remote-azure-overlay.yaml Outdated
Comment thread charts/mlrun-ce/templates/seaweedfs/seaweedfs-remote-secret.yaml Outdated
Comment thread charts/mlrun-ce/README.md
Comment thread charts/mlrun-ce/README.md Outdated
Comment thread charts/mlrun-ce/values.yaml Outdated
Comment thread charts/mlrun-ce/values.yaml Outdated
Comment thread charts/mlrun-ce/templates/seaweedfs/seaweedfs-remote-gateway-deployment.yaml Outdated
Comment thread charts/mlrun-ce/templates/seaweedfs/seaweedfs-remote-config-job.yaml Outdated
@shay79il
shay79il force-pushed the CEML-713 branch 3 times, most recently from 521a6bc to d9ecae2 Compare August 26, 2026 19:50
Comment thread charts/mlrun-ce/examples/seaweedfs-remote-azure-overlay.yaml Outdated
Comment thread charts/mlrun-ce/examples/seaweedfs-remote-s3-overlay.yaml Outdated
Comment thread charts/mlrun-ce/templates/seaweedfs/seaweedfs-remote-config-job.yaml Outdated
Comment thread charts/mlrun-ce/templates/seaweedfs/seaweedfs-remote-gateway-deployment.yaml Outdated
Comment thread charts/mlrun-ce/templates/_helpers.tpl Outdated
Comment thread charts/mlrun-ce/README.md Outdated
Comment thread charts/mlrun-ce/values.yaml Outdated
Comment thread charts/mlrun-ce/values.yaml
Comment thread charts/mlrun-ce/examples/README.md Outdated
Comment thread .claude/skills/pr/SKILL.md Outdated
@shay79il
shay79il force-pushed the CEML-713 branch 2 times, most recently from f65589e to 660543b Compare September 7, 2026 11:03
Comment thread charts/mlrun-ce/examples/seaweedfs-remote-s3-overlay.yaml Outdated
Comment thread charts/mlrun-ce/examples/seaweedfs-remote-s3-overlay.yaml Outdated
Comment thread charts/mlrun-ce/examples/seaweedfs-remote-azure-overlay.yaml Outdated
{{- include "mlrun-ce.pipelines.labels" . | nindent 4 }}
type: Opaque
stringData:
accesskey: {{ include "mlrun-ce.seaweedfs.s3.accessKey" . | quote }}

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

From the helper, it looks like it is using MLRun configuration. Can you please verify that you can point MLRun to local but pipelines to remote

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@shay79il this one still needs to be resolved - you are pointing to mlrun conf and not pipelines creds

{{- define "mlrun-ce.seaweedfs.s3.accessKey" -}}
{{- .Values.storage.local.accessKey -}}
{{- end -}}

Please try running your code and store MLRun to S3 bucket x with x creds and pipelines to S3 bucket y with different creds.
Other then that look good

@royischoss royischoss left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

…d, detailing local and remote storage options with configuration examples
… configuration; enhance validation checks for Azure provider
…etails; refactor static credentials usage in templates
…guration details; add nonempty option in values.yaml for handling existing pipeline data during upgrades
…structions; update values.yaml for Azure storage configuration; enhance validation checks for Azure provider in templates
…rom values files and templates; update README.md to clarify SeaweedFS usage for pipeline artifacts.
…nfiguration; enhance validation checks for SeaweedFS remote provider in templates.
… by breaking down the command into multiple lines for better readability and maintainability.
… configuration; enhance Azure Blob example and clarify usage in templates.
…te overlay examples for Azure and S3; streamline configuration for clarity and consistency.
… remote overlay example for improved compatibility with S3 storage.
… configuration; clarify usage of mount options and enhance Azure Blob example with command syntax.
…nd S3; clarify usage of emptyDir for lab/dev testing and provide verification steps for remote sync.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Critical IAM credential and mountExisting: false paths can fail, with additional validation gaps.

Review effort: Lite
Findings: 4 High severity · 1 Low severity

Open (5)
What changed in this PR

Adds optional SeaweedFS remote-gateway synchronization for KFP artifacts stored locally while syncing to AWS S3 or Azure Blob.

Changes:

  • Adds remote gateway configuration, credentials, mounting, deployment, and examples.
  • Simplifies KFP storage around in-cluster SeaweedFS and updates component configuration.
  • Adds storage validation, MySQL compatibility handling, documentation, and a chart version bump.
File Summary
charts/​mlrun-ce/​values.yaml Adds remote gateway settings and updated KFP values.
charts/​mlrun-ce/​templates/​seaweedfs/​seaweedfs-remote-secret.yaml Creates remote credential Secret.
charts/​mlrun-ce/​templates/​seaweedfs/​seaweedfs-remote-gateway-deployment.yaml Runs background remote synchronization.
charts/​mlrun-ce/​templates/​seaweedfs/​seaweedfs-remote-config-job.yaml Configures and mounts remote storage.
charts/​mlrun-ce/​templates/​seaweedfs/​s3-bucket-init-job.yaml Updates bucket initialization behavior.
charts/​mlrun-ce/​templates/​pipelines/​secrets/​mlpipeline-seaweedfs-artifact.yaml Removes the replaced artifact Secret template.
charts/​mlrun-ce/​templates/​pipelines/​secrets/​mlpipeline-artifact-secret.yaml Defines the replacement artifact Secret.
charts/​mlrun-ce/​templates/​pipelines/​deployments/​mysql.yaml Selects MySQL authentication flags by version.
charts/​mlrun-ce/​templates/​pipelines/​deployments/​ml-pipeline.yaml Configures KFP for local SeaweedFS storage.
charts/​mlrun-ce/​templates/​pipelines/​deployments/​ml-pipeline-ui.yaml Updates SeaweedFS service references.
charts/​mlrun-ce/​templates/​pipelines/​configmaps/​workflow-controller-configmap.yaml Points workflow artifacts to SeaweedFS.
charts/​mlrun-ce/​templates/​pipelines/​configmaps/​pipeline-install-config.yaml Updates local object-store settings.
charts/​mlrun-ce/​templates/​pipelines/​configmaps/​kfp-launcher.yaml Sets the local pipeline root.
charts/​mlrun-ce/​templates/​config/​storage-validation.yaml Validates remote storage configuration.
charts/​mlrun-ce/​templates/​_helpers.tpl Adds storage and gateway helpers.
charts/​mlrun-ce/​README.md Documents remote artifact storage.
charts/​mlrun-ce/​examples/​seaweedfs-remote-s3-overlay.yaml Adds an AWS S3 overlay example.
charts/​mlrun-ce/​examples/​seaweedfs-remote-azure-overlay.yaml Adds an Azure Blob overlay example.
charts/​mlrun-ce/​examples/​README.md Documents deployment and verification steps.
charts/​mlrun-ce/​Chart.yaml Bumps the chart version.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment on lines +28 to +33
{{- if and (eq (include "mlrun-ce.seaweedfs.remote.enabled" . | toString) "true") (eq .Values.seaweedfs.remote.provider "s3") (not .Values.global.infrastructure.aws.s3NonAnonymous) (not .Values.storage.s3.accessKey) }}
{{ fail "seaweedfs.remote with provider \"s3\" requires storage.s3.accessKey." }}
{{- end }}
{{- if and (eq (include "mlrun-ce.seaweedfs.remote.enabled" . | toString) "true") (eq .Values.seaweedfs.remote.provider "s3") (not .Values.global.infrastructure.aws.s3NonAnonymous) (not .Values.storage.s3.secretKey) }}
{{ fail "seaweedfs.remote with provider \"s3\" requires storage.s3.secretKey." }}
{{- end }}
Comment on lines +127 to +133
if [ "${MOUNT_EXISTING}" = "true" ]; then
MOUNT_CMD="remote.mount -dir=${MOUNT_DIR} -remote=${REMOTE_PATH}"
if [ "${MOUNT_NONEMPTY}" = "true" ]; then
MOUNT_CMD="${MOUNT_CMD} -nonempty"
fi
echo "${MOUNT_CMD}"
fi
Comment on lines +31 to +44
- name: wait-for-remote-mount
image: {{ include "mlrun-ce.seaweedfs.image" . | quote }}
imagePullPolicy: IfNotPresent
command:
- /bin/sh
- -ec
- |
FILER="{{ include "mlrun-ce.seaweedfs.filerAddress" . }}"
MASTER="{{ include "mlrun-ce.seaweedfs.masterAddress" . }}"
MOUNT_DIR="/buckets/{{ include "mlrun-ce.seaweedfs.remote.localBucket" . }}"
until printf 'remote.mount\n' | weed shell -filer="${FILER}" -master="${MASTER}" 2>&1 | grep -Fq "${MOUNT_DIR}"; do
echo "waiting for remote mount at ${MOUNT_DIR}..."
sleep 5
done
Comment on lines +12 to +13
AWS_ACCESS_KEY_ID: {{ required "storage.s3.accessKey is required for seaweedfs.remote provider s3" .Values.storage.s3.accessKey | quote }}
AWS_SECRET_ACCESS_KEY: {{ required "storage.s3.secretKey is required for seaweedfs.remote provider s3" .Values.storage.s3.secretKey | quote }}
Comment thread charts/mlrun-ce/README.md

| MLRun CE | MLRun | Nuclio | Jupyter | MPI Operator | SeaweedFS | Spark Operator | Pipelines | Kube-Prometheus-Stack | OpenTelemetry Operator |
| ---------------- | ----------- | ------- | ----------- | ------------ | --------- | -------------- | --------- | --------------------- | ---------------------- |
| **0.11.0** | 1.11.0 | 1.15.27 | 4.5.0 | 0.2.3 | 4.17.0 | 2.1.0 | 2.15.0 | 72.1.1 | 0.78.1 |

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants