From 24c017faab3cad7aa68457aa8b18641428e20747 Mon Sep 17 00:00:00 2001 From: wbsong111 Date: Wed, 25 Jun 2025 14:09:06 +0900 Subject: [PATCH] Add kubeflow applicationset --- charts/kubeflow/dip/README.md | 75 +++++++++++++++++++ .../kubeflow-applicationset.yaml | 59 +++++++++++++++ .../dip/istio-system/kustomization.yaml | 31 ++++++++ .../{ => kubeflow-core}/cluster-policy.yaml | 0 .../dip/{ => kubeflow-core}/cluster-role.yaml | 0 .../cluster-rolebinding.yaml | 0 .../kubeflow/dip/kubeflow-core/ingress.yaml | 24 ++++++ .../dip/kubeflow-core/kustomization.yaml | 42 +++++++++++ .../kubeflow-dependencies/kustomization.yaml | 19 +++++ 9 files changed, 250 insertions(+) create mode 100644 charts/kubeflow/dip/README.md create mode 100644 charts/kubeflow/dip/applicationset/kubeflow-applicationset.yaml create mode 100644 charts/kubeflow/dip/istio-system/kustomization.yaml rename charts/kubeflow/dip/{ => kubeflow-core}/cluster-policy.yaml (100%) rename charts/kubeflow/dip/{ => kubeflow-core}/cluster-role.yaml (100%) rename charts/kubeflow/dip/{ => kubeflow-core}/cluster-rolebinding.yaml (100%) create mode 100644 charts/kubeflow/dip/kubeflow-core/ingress.yaml create mode 100644 charts/kubeflow/dip/kubeflow-core/kustomization.yaml create mode 100644 charts/kubeflow/dip/kubeflow-dependencies/kustomization.yaml diff --git a/charts/kubeflow/dip/README.md b/charts/kubeflow/dip/README.md new file mode 100644 index 0000000..6693dc9 --- /dev/null +++ b/charts/kubeflow/dip/README.md @@ -0,0 +1,75 @@ +# ArgoCD를 이용한 Kubeflow 배포 + +이 저장소에는 **ApplicationSet을 사용한 Kubeflow 배포** 구현이 포함되어 있습니다. + +### 배포 방법 + +1. ApplicationSet 적용: + ```bash + kubectl apply -f argocd-solutions/applicationset/kubeflow-applicationset.yaml + ``` + +2. ArgoCD UI에서 배포 상태 확인: + - `istio-system` → `kubeflow-dependencies` → `kubeflow-core` 순서로 배포 + - 각 단계별 동기화 상태 모니터링 + +### 배포 구조 + +ApplicationSet은 다음과 같은 3단계 배포 순서로 구성되어 있습니다: + +#### Wave 0: Istio System (`istio-system`) +- **네임스페이스**: `istio-system` +- **의존성**: 없음 (최우선 배포) +- **구성 요소**: + - Istio CRDs + - Istio Namespace + - Istio 설치 (OAuth2-Proxy 오버레이) + - 클러스터 로컬 게이트웨이 + +#### Wave 1: Kubeflow Dependencies (`kubeflow-dependencies`) +- **네임스페이스**: `kubeflow` +- **의존성**: `istio-system` +- **구성 요소**: + - Cert-Manager (Kubeflow Issuer) + - OAuth2-Proxy (M2M Keycloak 오버레이) + - KNative Serving (Gateway 오버레이) + - Kubeflow Namespace + - Network Policies + - Kubeflow Roles + - Kubeflow Istio Resources + +#### Wave 2: Kubeflow Core (`kubeflow-core`) +- **네임스페이스**: `kubeflow` +- **의존성**: `kubeflow-dependencies` +- **구성 요소**: + - Kubeflow Pipelines (Multi-user, Cert-Manager) + - Katib (Kubeflow 통합) + - Central Dashboard (OAuth2-Proxy) + - Admission Webhook (Cert-Manager) + - Jupyter Web App & Notebook Controller + - Profiles + KFAM + - PVC Viewer & Volumes Web App + - Tensorboard Controller & Web App + - Training Operator + - KServe & Models Web App + - Spark Operator + - User Namespace + - Kubeflow Ingress + +### 주요 특징 + +1. **순차적 배포**: Sync Wave를 통한 명확한 배포 순서 보장 +2. **자동화된 동기화**: + - 자동 Prune 및 Self-Heal 활성화 + - Server-Side Apply 사용 + - 네임스페이스 자동 생성 +3. **재시도 정책**: 실패 시 지수 백오프로 최대 5회 재시도 +4. **의존성 추적**: 각 Application의 의존성 정보를 메타데이터로 관리 + + + +### 장점 +- **중앙집중식 관리**: 하나의 ApplicationSet으로 전체 Kubeflow 스택 관리 +- **명확한 의존성**: Wave 기반 순차 배포로 의존성 문제 해결 +- **확장성**: 새로운 컴포넌트 추가 시 리스트에 항목만 추가 +- **일관성**: 모든 Application이 동일한 정책과 설정 적용 \ No newline at end of file diff --git a/charts/kubeflow/dip/applicationset/kubeflow-applicationset.yaml b/charts/kubeflow/dip/applicationset/kubeflow-applicationset.yaml new file mode 100644 index 0000000..5fec5af --- /dev/null +++ b/charts/kubeflow/dip/applicationset/kubeflow-applicationset.yaml @@ -0,0 +1,59 @@ +# ApplicationSet을 사용한 방법 +apiVersion: argoproj.io/v1alpha1 +kind: ApplicationSet +metadata: + name: kubeflow-applicationset + namespace: platform +spec: + generators: + - list: + elements: + - name: istio-system + path: kubeflow/dip/istio-system + namespace: istio-system + wave: "0" + dependencies: "" + - name: kubeflow-dependencies + path: kubeflow/dip/kubeflow-dependencies + namespace: kubeflow + wave: "1" + dependencies: "istio-system" + - name: kubeflow-core + path: kubeflow/dip/kubeflow-core + namespace: kubeflow + wave: "2" + dependencies: "kubeflow-dependencies" + template: + metadata: + name: '{{name}}' + annotations: + argocd.argoproj.io/sync-wave: '{{wave}}' + finalizers: + - resources-finalizer.argocd.argoproj.io + spec: + project: default + source: + repoURL: https://gitea.example.org/dip/tenant-catalog + targetRevision: kubeflow/v1.10.0 + path: '{{path}}' + destination: + server: https://kubernetes.default.svc + namespace: '{{namespace}}' + syncPolicy: + automated: + prune: true + selfHeal: true + syncOptions: + - CreateNamespace=true + - ServerSideApply=true + retry: + limit: 5 + backoff: + duration: 5s + factor: 2 + maxDuration: 3m + info: + - name: 'Wave' + value: '{{wave}}' + - name: 'Dependencies' + value: '{{dependencies}}' \ No newline at end of file diff --git a/charts/kubeflow/dip/istio-system/kustomization.yaml b/charts/kubeflow/dip/istio-system/kustomization.yaml new file mode 100644 index 0000000..86fcf08 --- /dev/null +++ b/charts/kubeflow/dip/istio-system/kustomization.yaml @@ -0,0 +1,31 @@ +# Istio System Kustomization +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization + +# 배포 순서 정의 +sortOptions: + order: legacy + legacySortOptions: + orderFirst: + - Namespace + - CustomResourceDefinition + - ServiceAccount + - ClusterRole + - ClusterRoleBinding + - ConfigMap + - Secret + - Service + orderLast: + - ValidatingWebhookConfiguration + - MutatingWebhookConfiguration + - Deployment + +resources: +# 1. CRDs 먼저 +- ../../common/istio-1-24/istio-crds/base +# 2. Namespace +- ../../common/istio-1-24/istio-namespace/base +# 3. Istio 설치 +- ../../common/istio-1-24/istio-install/overlays/oauth2-proxy +# 4. 클러스터 로컬 게이트웨이 +- ../../common/istio-1-24/cluster-local-gateway/base diff --git a/charts/kubeflow/dip/cluster-policy.yaml b/charts/kubeflow/dip/kubeflow-core/cluster-policy.yaml similarity index 100% rename from charts/kubeflow/dip/cluster-policy.yaml rename to charts/kubeflow/dip/kubeflow-core/cluster-policy.yaml diff --git a/charts/kubeflow/dip/cluster-role.yaml b/charts/kubeflow/dip/kubeflow-core/cluster-role.yaml similarity index 100% rename from charts/kubeflow/dip/cluster-role.yaml rename to charts/kubeflow/dip/kubeflow-core/cluster-role.yaml diff --git a/charts/kubeflow/dip/cluster-rolebinding.yaml b/charts/kubeflow/dip/kubeflow-core/cluster-rolebinding.yaml similarity index 100% rename from charts/kubeflow/dip/cluster-rolebinding.yaml rename to charts/kubeflow/dip/kubeflow-core/cluster-rolebinding.yaml diff --git a/charts/kubeflow/dip/kubeflow-core/ingress.yaml b/charts/kubeflow/dip/kubeflow-core/ingress.yaml new file mode 100644 index 0000000..fd83082 --- /dev/null +++ b/charts/kubeflow/dip/kubeflow-core/ingress.yaml @@ -0,0 +1,24 @@ +apiVersion: networking.k8s.io/v1 +kind: Ingress +metadata: + name: kubeflow-ingress + namespace: istio-system + annotations: + nginx.ingress.kubernetes.io/rewrite-target: / + cert-manager.io/cluster-issuer: "kubeflow-self-signing-issuer" +spec: + tls: + - hosts: + - $HOST + secretName: kubeflow-tls + rules: + - host: $HOST + http: + paths: + - path: / + pathType: Prefix + backend: + service: + name: istio-ingressgateway + port: + number: 80 \ No newline at end of file diff --git a/charts/kubeflow/dip/kubeflow-core/kustomization.yaml b/charts/kubeflow/dip/kubeflow-core/kustomization.yaml new file mode 100644 index 0000000..150156a --- /dev/null +++ b/charts/kubeflow/dip/kubeflow-core/kustomization.yaml @@ -0,0 +1,42 @@ +# Kubeflow Core Applications Kustomization +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization + +resources: +# Kubeflow Pipelines +- ../../apps/pipeline/upstream/env/cert-manager/platform-agnostic-multi-user +# Katib +- ../../apps/katib/upstream/installs/katib-with-kubeflow +# Central Dashboard +- ../../apps/centraldashboard/overlays/oauth2-proxy +# Admission Webhook +- ../../apps/admission-webhook/upstream/overlays/cert-manager +# Jupyter Web App +- ../../apps/jupyter/jupyter-web-app/upstream/overlays/istio +# Notebook Controller +- ../../apps/jupyter/notebook-controller/upstream/overlays/kubeflow +# Profiles + KFAM +- ../../apps/profiles/upstream/overlays/kubeflow +# PVC Viewer +- ../../apps/pvcviewer-controller/upstream/base +# Volumes Web App +- ../../apps/volumes-web-app/upstream/overlays/istio +# Tensorboards Controller +- ../../apps/tensorboard/tensorboard-controller/upstream/overlays/kubeflow +# Tensorboard Web App +- ../../apps/tensorboard/tensorboards-web-app/upstream/overlays/istio +# Training Operator +- ../../apps/training-operator/upstream/overlays/kubeflow +# User namespace +- ../../common/user-namespace/base +# KServe +- ../../apps/kserve/kserve +- ../../apps/kserve/models-web-app/overlays/kubeflow +# Spark Operator +- ../../apps/spark/spark-operator/overlays/kubeflow +# Ingress +- ingress.yaml +# dip +- cluster-policy.yaml +- cluster-role.yaml +- cluster-rolebinding.yaml \ No newline at end of file diff --git a/charts/kubeflow/dip/kubeflow-dependencies/kustomization.yaml b/charts/kubeflow/dip/kubeflow-dependencies/kustomization.yaml new file mode 100644 index 0000000..a09cda9 --- /dev/null +++ b/charts/kubeflow/dip/kubeflow-dependencies/kustomization.yaml @@ -0,0 +1,19 @@ +# Kubeflow Dependencies Kustomization +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization + +resources: +# Cert-Manager +- ../../common/cert-manager/kubeflow-issuer/base +# OAuth2-Proxy +- ../../common/oauth2-proxy/overlays/m2m-keycloak +# KNative +- ../../common/knative/knative-serving/overlays/gateways +# Kubeflow namespace +- ../../common/kubeflow-namespace/base +# NetworkPolicies +- ../../common/networkpolicies/base +# Kubeflow Roles +- ../../common/kubeflow-roles/base +# Kubeflow Istio Resources +- ../../common/istio-1-24/kubeflow-istio-resources/base \ No newline at end of file