Layout on 4x Tesla V100 32GB (PCIe, no NVLink), all TP=1: GPU0+1 vLLM DeepSeek-R1-Distill-Qwen-32B bnb-nf4 (2 replicas) GPU2 Ollama ornith:35b + qwen2.5:3b-instruct (co-resident) GPU3 vLLM Qwen2.5-Math-PRM-7B (reward model) CPU TEI nomic-embed-text-v2-moe, bge-reranker-base Volta constraints, each verified against live output rather than config: - vLLM pinned v0.11.0: sm_70 dropped from CUDA_SUPPORTED_ARCHS at v0.11.1. - AWQ hard-rejected (needs sm_75). GPTQ passes vLLM's min_capability=60 gate but is NUMERICALLY WRONG on sm_70 — emits garbage logits. Proven by an fp16 control run producing correct text on an identical backend. bitsandbytes nf4 verified correct by output. - flashinfer's check_cuda_arch() crashes on any sm_7x (calls .isdigit() on an int) -> VLLM_USE_FLASHINFER_SAMPLER=0. - xformers has no sm_70 kernel for V1's paged-attention bias, and V0 was removed in v0.11.0 -> TRITON_ATTN. - Ornith is Qwen3.5-MoE hybrid-attention; vLLM added that arch after dropping Volta, so no build has both -> Ollama, which also multiplexes a second model on the same card for free. Cluster prereqs that were absent: - RuntimeClass nvidia: the Talos toolkit extension registers the containerd handler but not the k8s object; without it every pod is rejected at admission. - gpu-system pinned to privileged PSA: a device plugin cannot satisfy the cluster-default baseline, it must mount hostPath. - device-plugin affinity=null: the chart requires NFD labels that do not exist here, so it matched zero nodes and reported desiredNumberScheduled=0 silently. - Recreate strategy on GPU services: with GPUs allocated exactly 4/4, a RollingUpdate surge pod has no card and deadlocks the rollout. - longhorn-llm-local SC (1 replica, strict-local, disk tag llm): the default 3-replica class could not place the volume at all (every control-plane disk was at its over-provisioning ceiling), and this keeps ~60GB of weights on worker-1's own NVMe instead of reading them over the network. deploy-gpu-serving.sh sequences ArgoCD syncs (or helm/kubectl in --manual mode) and never applies a manifest absent from git; doctor/unstick/teardown stages exist so this is diagnosable without ad-hoc kubectl archaeology.
44 lines
1.4 KiB
YAML
44 lines
1.4 KiB
YAML
# Default-deny ingress for the serving pods.
|
|
#
|
|
# This is a real compensating control, not hygiene: vLLM is pinned to v0.11.0
|
|
# (forced — last release with Volta kernels), which sits below the patch line on
|
|
# several advisories that will never be backported to that branch, incl.
|
|
# CVE-2026-54234 (remote DoS) and GHSA-7m6h-x95x-82q5 (cross-user data leak).
|
|
# Those are all remote/unauthenticated attack surface, so keeping the engines
|
|
# reachable only from opted-in in-cluster clients is what keeps exposure low.
|
|
#
|
|
# Consumers opt in with label `llm-client: "true"`. Do NOT expose these via
|
|
# Ingress.
|
|
apiVersion: networking.k8s.io/v1
|
|
kind: NetworkPolicy
|
|
metadata:
|
|
name: llm-serving-default-deny
|
|
spec:
|
|
podSelector:
|
|
matchLabels:
|
|
app.kubernetes.io/part-of: llm-serving
|
|
policyTypes:
|
|
- Ingress
|
|
ingress:
|
|
- from:
|
|
# Any pod, any namespace, that explicitly opts in as an LLM client.
|
|
- namespaceSelector: {}
|
|
podSelector:
|
|
matchLabels:
|
|
llm-client: "true"
|
|
# Sibling engines (harness may chain calls between them).
|
|
- podSelector:
|
|
matchLabels:
|
|
app.kubernetes.io/part-of: llm-serving
|
|
ports:
|
|
- protocol: TCP
|
|
port: 8080
|
|
- from:
|
|
# Prometheus scraping /metrics.
|
|
- namespaceSelector:
|
|
matchLabels:
|
|
kubernetes.io/metadata.name: monitoring
|
|
ports:
|
|
- protocol: TCP
|
|
port: 8080
|