Skip to content

Commit 8c335fc

Browse files
committed
feat(recipes): add GKE GB200 (A4X) recipe with NVLS NCCL validation
Add the gb200-gke-cos-{training,training-kubeflow,training-slurm, inference,inference-dynamo} recipe leaves, covering GB200 (A4X) on GKE with COS. New gke-gb200-rdma component wires the NCCL gIB ARM64 plugin installer needed for GPUDirect-RDMA over RoCE, plus its health check and BOM/tuning docs. The GKE multi-networking objects (GKENetworkParamSet/Network: gvnic-1, rdma-0..rdma-3) are provisioned with the cluster before the node pool exists, not by this component: AICR treats them as a prerequisite and validates all 5 objects, including deviceMode and parametersRef linkage, via health check. GB200 on GKE is NVLS-only: MNNVL across the A4X nodes' IMEX domain is the fabric that actually carries all-reduce traffic, so nccl-all-reduce-bw-nvls (not the plain check) is wired into the training leaves' performance phase, backed by a new runtime-nvls.yaml TrainingRuntime template with IMEX ComputeDomain wiring. GPU NIC discovery in the NCCL validator is skipped for this accelerator/service pair since it uses the gke-gb200-rdma Network CRs instead of the TCPXO gpu-nic-* fabric. GB200 already has a Kubeflow leaf overlay on EKS and OKE; adds the same kubeflow-trainer component here so GKE isn't the only GB200 platform missing one, giving robust-controller conformance a supported operator to validate instead of always skipping. Also adds a gb200-gke-cos-inference-dynamo leaf (grove + dynamo-platform, DRA-gated to Kubernetes 1.34+), mirroring the GB200 EKS/OKE Dynamo overlays' performance-gate thresholds until a GKE-specific baseline is published. This turns the bare gb200-gke-cos-inference overlay from a leaf into a base shared by both the plain and Dynamo inference leaves, the same base/platform-variant pattern already used above for training/training-kubeflow. And a gb200-gke-cos-training-slurm leaf (Slinky operator + a Slinky-managed Slurm cluster), mirroring gb200-eks-ubuntu-training-slurm's GPU GRES, task isolation, and NVLS/IMEX ComputeDomain wiring for the same 4-GPU-per-node accelerator shape. Unlike the Kubeflow Trainer/JobSet controllers above, Slinky's controller/restapi/nodeset Deployments already go through AICR's ordinary nodeScheduling tolerationPaths, so this leaf needs no Trainer-style toleration workaround. Floor calibrated on a4x-highgpu-4g (4x GB200/node): 2-node/8-GPU all_reduce_perf measured 281.936 GB/s avg bus bandwidth. Validated on a live A4X cluster across conformance, deployment, and NVLS performance for the training and training-kubeflow leaves. gb200-gke-cos-inference-dynamo is validated across all three phases on the same cluster: deployment, conformance, and performance (103,971 tokens/sec throughput, 1388.55ms TTFT p99). gb200-gke-cos-training-slurm is validated through deployment and conformance, including the GB200-specific slinky-slurm-imex-channel health check; its NVLS performance phase has not yet been run. Signed evidence bundles for both (Sigstore/Rekor, keyless OIDC) are pushed to ghcr.io/mikecook/aicr-evidence with pointers committed under recipes/evidence/, and the signer is added to the community allowlist. Signed-off-by: Mike Cook <micook@nvidia.com>
1 parent e17758c commit 8c335fc

35 files changed

Lines changed: 2224 additions & 15 deletions

File tree

‎docs/README.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -46,7 +46,7 @@ For pipelines and platforms that call AICR programmatically or host
4646
| Add or modify recipe metadata | [Recipe Development](integrator/recipe-development.md) |
4747
| Verify artifacts (SLSA, SBOM, attestations) | [Supply Chain Verification](integrator/supply-chain-verification.md) |
4848
| Ship custom validators via `--data` | [Validator Extension](integrator/validator-extension.md) |
49-
| Cloud-specific GPU setup | [AKS](integrator/aks-gpu-setup.md), [GKE](integrator/gke-gpu-setup.md), [EKS networking](integrator/eks-dynamo-networking.md), [GKE networking](integrator/gke-tcpxo-networking.md), [Talos](integrator/talos-integration.md) |
49+
| Cloud-specific GPU setup | [AKS](integrator/aks-gpu-setup.md), [GKE](integrator/gke-gpu-setup.md), [EKS networking](integrator/eks-dynamo-networking.md), [GKE TCPXO networking](integrator/gke-tcpxo-networking.md), [GKE GB200 networking](integrator/gke-gb200-networking.md), [Talos](integrator/talos-integration.md) |
5050

5151
### Contributor Guide
5252

‎docs/contributor/validator.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -804,7 +804,7 @@ default** (`Qwen/Qwen3-8B` at 256/GPU). A non-positive / non-integer
804804
| `AICR_INFERENCE_PERF_WORKLOAD_READY_TIMEOUT` | `10m` | Wait for the `DynamoGraphDeployment` to become ready (image pull + model load + worker health). Large models load slower — raise this **and** the catalog entry's `timeout` in tandem, or the parent deadline caps it. |
805805
| `AICR_INFERENCE_PERF_HEALTH_TIMEOUT` | `5m` | Wait for the endpoint to serve a real chat-completion *after* the workload reports Ready. Concurrent first-load from one RWO cache PVC can push first-serve past 5m; raise it (bounded by the catalog `timeout`). |
806806
| `AICR_INFERENCE_PERF_MODEL_CACHE_SIZE` | `100Gi` (on) | The PVC-backed model-weights cache is **on by default**. Set a different K8s quantity to resize, or a disable sentinel (`off`/`0`/`none`/`disabled`) to turn it off and download from HF directly. |
807-
| `AICR_INFERENCE_PERF_MODEL_CACHE_STORAGE_CLASS` | cluster default | StorageClass for the cache PVC. On a cluster with **no default SC and no value here**, the check **fails fast** with guidance rather than leaving the PVC `Pending` until timeout. AICR-deployed EKS gets a default `gp3` SC from `aws-ebs-csi-driver`; GKE has `standard-rwo`. |
807+
| `AICR_INFERENCE_PERF_MODEL_CACHE_STORAGE_CLASS` | cluster default | StorageClass for the cache PVC. On a cluster with **no default SC and no value here**, the check **fails fast** with guidance rather than leaving the PVC `Pending` until timeout. AICR-deployed EKS gets a default `gp3` SC from `aws-ebs-csi-driver`; GKE has `standard-rwo`, **except A4X/GB200 nodes**, which reject `standard-rwo`'s `pd-balanced` disks and need a Hyperdisk-backed class (see [GKE GB200 Storage Prerequisites](../integrator/gke-gb200-networking.md#storage-prerequisites)). |
808808
| `AICR_INFERENCE_PERF_MODEL_CACHE_POPULATE_TIMEOUT` | `13m` | Wait for the one-time model-cache populate Job (cold image pull + first-ever Hugging Face download into the PVC). Separate from — and larger than — `AICR_INFERENCE_PERF_WORKLOAD_READY_TIMEOUT` because the populate Job pays a cold pull *and* a multi-GB download; provide the optional HF-token secret to remove anonymous-download throttling. Raise it (and the catalog `timeout`) for very large models. **Migration:** the cache-populate wait no longer honors `AICR_INFERENCE_PERF_WORKLOAD_READY_TIMEOUT` (which now bounds only the DynamoGraphDeployment readiness wait) — set this knob instead to widen the populate budget. |
809809

810810
For gated models, or to lift Hugging Face rate limits on large downloads,

‎docs/index.yml‎

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -75,6 +75,8 @@ navigation:
7575
path: integrator/eks-dynamo-networking.md
7676
- page: GKE TCPXO Networking
7777
path: integrator/gke-tcpxo-networking.md
78+
- page: GKE GB200 Networking
79+
path: integrator/gke-gb200-networking.md
7880
- page: OpenShift Deployment
7981
path: integrator/openshift.md
8082
- page: Talos Integration

‎docs/integrator/components/nodewright.md‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -86,6 +86,7 @@ The table below is generated from the recipes by `make tuning-docs` — **do not
8686
| eks | rtx-pro-6000 | generic | - | nvidia-tuned 0.3.2 |
8787
| gke | a100 | h100 | - | nvidia-tuning-gke 0.1.2 |
8888
| gke | b200 | - | - | nvidia-tuning-gke 0.1.2 |
89+
| gke | gb200 | - | - | nvidia-tuning-gke 0.1.2 |
8990
| gke | h100 | - | - | nvidia-tuning-gke 0.1.2 |
9091

9192
{/* END AICR-TUNING */}
Lines changed: 358 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,358 @@
1+
# GKE GB200 (A4X) Networking Prerequisites
2+
3+
For the **GB200 GKE COS** recipes (`gb200-gke-cos-training`,
4+
`gb200-gke-cos-training-kubeflow`, `gb200-gke-cos-training-slurm`, and
5+
`gb200-gke-cos-inference-dynamo`, all on `a4x-highgpu-4g` nodes),
6+
GPUDirect-RDMA over RoCE enables high-speed inter-node GPU communication on
7+
GKE. The recipe's NCCL workloads set `NCCL_NET=gIB` explicitly (see
8+
`recipes/components/gke-gb200-rdma/manifests/nccl-gib-installer-arm64.yaml`)
9+
rather than letting NCCL auto-select a plugin, so a missing or
10+
misconfigured RDMA fabric doesn't silently fall back to a slower network
11+
path: it fails outright.
12+
13+
GPUDirect RDMA on `a4x-highgpu-4g` is also incompatible with NCCL Fast
14+
Socket and the GPUDirect TCPX/TCPXO plugin (see
15+
[GKE TCPXO Networking](gke-tcpxo-networking.md) for that alternative,
16+
non-RDMA path); don't enable either on a cluster that uses RDMA.
17+
18+
## Infrastructure Prerequisites
19+
20+
GKE clusters must have multi-networking configured before deploying AICR bundles:
21+
22+
- Multi-networking enabled (1 gVNIC + 4 RDMA NICs per `a4x-highgpu-4g` node)
23+
- `Network` + `GKENetworkParamSet` CRs for the gVNIC and 4 RDMA NICs (cluster-specific
24+
VPC/subnet values, but fixed object names; see below, not managed by AICR)
25+
- `nccl-rdma-installer` DaemonSet on GPU nodes (included in the AICR bundle)
26+
- Each Pod must request all 4 GPUs and use all 4 RDMA NICs on a single node;
27+
RDMA can't be shared between Pods on the same node (a GKE `a4x-highgpu-4g`
28+
constraint, not an AICR-specific one). AICR's own recipes already request
29+
whole nodes this way; a custom workload built against this component must too.
30+
31+
The last one ships in the AICR bundle. The first is **cluster provisioning**:
32+
AICR's `gke-gb200-rdma` health check detects it but does not create it.
33+
34+
### Provisioning multi-networking
35+
36+
These steps are ordered, following Google's
37+
[A4X custom setup guide](https://docs.cloud.google.com/ai-hypercomputer/docs/create/gke-ai-hypercompute-custom-a4x):
38+
39+
1. **Create the VPCs and subnets**: two VPCs in the cluster's region, one for
40+
the gVNIC (with one subnet) and one RDMA VPC (with four subnets, one per
41+
RDMA NIC); five subnets total across the two VPCs, not five separate VPCs.
42+
2. **Create the cluster** with multi-networking enabled (HIPPO's `GKECluster` CR
43+
does this via `spec.networks.managed.gb200NetworkStrategy`).
44+
3. **Create the GPU node pool** on an `a4x-highgpu-4g` machine type, attaching
45+
the five network/subnet pairs as `additionalNodeNetworkConfigs` (the RDMA
46+
VPC repeated across its four subnets, plus the gVNIC VPC/subnet).
47+
4. **Apply the `Network` and `GKENetworkParamSet` CRs**: one pair per NIC,
48+
binding each additional node network into the cluster so pods can reference
49+
it. Unlike TCPXO (see [GKE TCPXO Networking](gke-tcpxo-networking.md)), the
50+
**object names are fixed, not cluster-specific**: `gvnic-1` for the gVNIC and
51+
`rdma-0` through `rdma-3` for the RDMA NICs. Only the `vpc`/`vpcSubnet` fields
52+
inside each `GKENetworkParamSet` vary per cluster (they name the VPC/subnet
53+
your cluster actually has):
54+
55+
```yaml
56+
apiVersion: networking.gke.io/v1
57+
kind: GKENetworkParamSet
58+
metadata:
59+
name: gvnic-1
60+
spec:
61+
vpc: "PREFIX-gvnic"
62+
vpcSubnet: "PREFIX-gvnic"
63+
deviceMode: NetDevice
64+
---
65+
apiVersion: networking.gke.io/v1
66+
kind: Network
67+
metadata:
68+
name: gvnic-1
69+
spec:
70+
type: "Device"
71+
parametersRef:
72+
group: networking.gke.io
73+
kind: GKENetworkParamSet
74+
name: gvnic-1
75+
```
76+
77+
Repeat for `rdma-0` through `rdma-3`, pointing `vpc` at the single RDMA VPC
78+
from step 1 (the same value for all four) and `vpcSubnet` at that VPC's
79+
four subnets (`PREFIX-rdma-sub-0` through `PREFIX-rdma-sub-3`, or whatever
80+
names your subnets were given in step 1, with `PREFIX` replaced by your
81+
own), and set **`deviceMode: RDMA`** on all four, not `NetDevice` (that
82+
value is only correct for `gvnic-1` above).
83+
84+
> **The fixed naming is a requirement, not a convention.** AICR's
85+
> `checks/gke-gb200-rdma/health-check.yaml` asserts these five objects by exact
86+
> name (`gvnic-1`, `rdma-0`..`rdma-3`), including `spec.deviceMode` and
87+
> `spec.parametersRef` linkage. A cluster provisioned with different `Network`
88+
> names passes Google's own setup guide but fails this check; rename to match
89+
> before running `aicr validate`.
90+
91+
AICR installs the `nccl-rdma-installer` DaemonSet and detects the CRs; it does
92+
not provision the networking itself. These steps are a summary of the
93+
prerequisite AICR depends on, not a complete provisioning runbook; follow
94+
Google's guide above for the full procedure, including firewall rules and
95+
supported GKE version floors.
96+
97+
Separately from GKE's own networking version floor, all AICR GB200 GKE
98+
recipes (including `gb200-gke-cos-training-slurm`, which inherits it from
99+
`gb200-gke-cos-training`) enforce `K8s.server.version >= 1.34`: NVLS
100+
provisions the IMEX channel through a DRA `ComputeDomain`, which requires
101+
the GA `resource.k8s.io/v1` API. `aicr validate` fails readiness on an
102+
older control plane with this constraint by name.
103+
104+
### Verifying
105+
106+
```shell
107+
kubectl get network.networking.gke.io \
108+
-o custom-columns='NAME:.metadata.name,PARAMETERS-REF:.spec.parametersRef.name'
109+
kubectl get gkenetworkparamset.networking.gke.io \
110+
-o custom-columns='NAME:.metadata.name,DEVICE-MODE:.spec.deviceMode'
111+
```
112+
113+
Expect `gvnic-1` and `rdma-0` through `rdma-3` (the five prerequisite
114+
`Network`s from step 4), each bound to its `GKENetworkParamSet` via
115+
`spec.parametersRef` (shown in the `PARAMETERS-REF` column above). Fewer
116+
than five, or a `GKENetworkParamSet` with the wrong `DEVICE-MODE`, means
117+
the prerequisite is incomplete or misconfigured; `aicr validate` (via the
118+
`gke-gb200-rdma` health check) reports the shortfall by name.
119+
120+
You'll also see a `default` network/`GKENetworkParamSet` pair in the same
121+
output; that one is GKE-managed (created automatically once
122+
multi-networking is enabled), not part of this prerequisite, and isn't
123+
checked by name.
124+
125+
## Driver Installer
126+
127+
`a4x-highgpu-4g` recipes generated with `--profile gpuStack=driver-installer`
128+
(see [GKE GPU Setup](gke-gpu-setup.md#alternative-let-gpu-operator-manage-the-device-plugin))
129+
need Google's standalone `nvidia-driver-installer` DaemonSet applied before
130+
GPU workloads can schedule; this presumes the node-pool prerequisite
131+
(pools created with `gpu-driver-version=disabled` plus the
132+
`gke-no-default-nvidia-gpu-device-plugin=true` label) is already in place.
133+
The manifest below is Google's generic upstream COS driver-installer
134+
DaemonSet (`daemonset-preloaded.yaml`, including its `partition-gpus`
135+
init container, Google's `nvidia-partition-gpu` MIG tool, carried over
136+
unchanged and a no-op here since this recipe allocates whole GPUs per
137+
node rather than configuring MIG), adapted two ways for GB200: the
138+
`nodeAffinity` also requires the `gke-no-default-nvidia-gpu-device-plugin`
139+
label (the `driver-installer` profile's node-pool prerequisite, which the
140+
plain upstream manifest doesn't check), and the install step pins an
141+
explicit
142+
[COS-qualified driver version](https://cloud.google.com/kubernetes-engine/docs/how-to/gpus#cos)
143+
instead of letting `cos-gpu-installer` pick its own default:
144+
145+
```yaml
146+
apiVersion: apps/v1
147+
kind: DaemonSet
148+
metadata:
149+
name: nvidia-driver-installer
150+
namespace: kube-system
151+
labels:
152+
k8s-app: nvidia-driver-installer
153+
spec:
154+
selector:
155+
matchLabels:
156+
k8s-app: nvidia-driver-installer
157+
updateStrategy:
158+
type: RollingUpdate
159+
template:
160+
metadata:
161+
labels:
162+
name: nvidia-driver-installer
163+
k8s-app: nvidia-driver-installer
164+
spec:
165+
priorityClassName: system-node-critical
166+
affinity:
167+
nodeAffinity:
168+
requiredDuringSchedulingIgnoredDuringExecution:
169+
nodeSelectorTerms:
170+
- matchExpressions:
171+
- key: cloud.google.com/gke-accelerator
172+
operator: Exists
173+
- key: cloud.google.com/gke-gpu-driver-version
174+
operator: DoesNotExist
175+
- key: gke-no-default-nvidia-gpu-device-plugin
176+
operator: In
177+
values: ["true"]
178+
- key: cloud.google.com/gke-confidential-nodes-instance-type
179+
operator: DoesNotExist
180+
tolerations:
181+
- operator: Exists
182+
hostNetwork: true
183+
hostPID: true
184+
volumes:
185+
- name: dev
186+
hostPath:
187+
path: /dev
188+
- name: vulkan-icd-mount
189+
hostPath:
190+
path: /home/kubernetes/bin/nvidia/vulkan/icd.d
191+
- name: nvidia-install-dir-host
192+
hostPath:
193+
path: /home/kubernetes/bin/nvidia
194+
- name: root-mount
195+
hostPath:
196+
path: /
197+
- name: cos-tools
198+
hostPath:
199+
path: /var/lib/cos-tools
200+
- name: nvidia-config
201+
hostPath:
202+
path: /etc/nvidia
203+
initContainers:
204+
- image: "cos-nvidia-installer:fixed"
205+
imagePullPolicy: Never
206+
name: nvidia-driver-installer
207+
resources:
208+
requests:
209+
cpu: 150m
210+
securityContext:
211+
privileged: true
212+
env:
213+
- name: NVIDIA_INSTALL_DIR_HOST
214+
value: /home/kubernetes/bin/nvidia
215+
- name: NVIDIA_INSTALL_DIR_CONTAINER
216+
value: /usr/local/nvidia
217+
- name: VULKAN_ICD_DIR_HOST
218+
value: /home/kubernetes/bin/nvidia/vulkan/icd.d
219+
- name: VULKAN_ICD_DIR_CONTAINER
220+
value: /etc/vulkan/icd.d
221+
- name: ROOT_MOUNT_DIR
222+
value: /root
223+
- name: COS_TOOLS_DIR_HOST
224+
value: /var/lib/cos-tools
225+
- name: COS_TOOLS_DIR_CONTAINER
226+
value: /build/cos-tools
227+
volumeMounts:
228+
- name: nvidia-install-dir-host
229+
mountPath: /usr/local/nvidia
230+
- name: vulkan-icd-mount
231+
mountPath: /etc/vulkan/icd.d
232+
- name: dev
233+
mountPath: /dev
234+
- name: root-mount
235+
mountPath: /root
236+
- name: cos-tools
237+
mountPath: /build/cos-tools
238+
command:
239+
- bash
240+
- -c
241+
- |
242+
echo "Checking for existing GPU driver modules"
243+
if lsmod | grep nvidia; then
244+
echo "GPU driver is already installed, skipping installation"
245+
exit 0
246+
else
247+
echo "No GPU driver module detected, installing 580.126.20"
248+
/cos-gpu-installer install --version=580.126.20 || exit 1
249+
chmod 755 /root/home/kubernetes/bin/nvidia
250+
fi
251+
- image: "gcr.io/gke-release/nvidia-partition-gpu@sha256:de12f85ebfb4fb6c1893cd30c23aab662a72fa0448f97ef74fccb82d7522ef17"
252+
name: partition-gpus
253+
env:
254+
- name: LD_LIBRARY_PATH
255+
value: /usr/local/nvidia/lib64
256+
resources:
257+
requests:
258+
cpu: 150m
259+
securityContext:
260+
privileged: true
261+
volumeMounts:
262+
- name: nvidia-install-dir-host
263+
mountPath: /usr/local/nvidia
264+
- name: dev
265+
mountPath: /dev
266+
- name: nvidia-config
267+
mountPath: /etc/nvidia
268+
containers:
269+
- image: "gke.gcr.io/pause:3.8@sha256:880e63f94b145e46f1b1082bb71b85e21f16b99b180b9996407d61240ceb9830"
270+
name: pause
271+
```
272+
273+
Re-pin the driver version (`580.126.20` above) and the `partition-gpus` image
274+
digest to whatever your GKE version's COS driver table and Google's release
275+
notes currently list; both drift over time and are not managed by AICR.
276+
277+
### Validate before deploying the rest of the bundle
278+
279+
Once the driver installer and the RDMA `Network`/`GKENetworkParamSet` CRs
280+
are applied, confirm both before running the bundle's full `deploy.sh`:
281+
282+
```shell
283+
aicr validate --recipe recipe.yaml --phase deployment --fail-fast
284+
```
285+
286+
`check-nvidia-smi` and the `gke-gb200-rdma` health check only need the GPU
287+
nodes to exist, not the rest of the bundle deployed, so this catches a
288+
missing driver or un-applied CRs in seconds instead of surfacing them deep
289+
into a 20-component deploy, for example as a DRA-driver pod stuck
290+
`Init:0/1` waiting on a driver that was never installed. `--fail-fast`
291+
stops there instead of continuing on to conformance and performance (see
292+
[Validation](../user/validation.md)).
293+
294+
## Storage Prerequisites
295+
296+
`a4x-highgpu-4g` nodes can't attach Persistent Disk at all (regional or
297+
zonal, any type, including `pd-balanced`); only Hyperdisk. On a stock GKE
298+
Standard cluster the default StorageClass is `standard-rwo`
299+
(`pd.csi.storage.gke.io`, `pd-balanced`), but "default" isn't inherent to
300+
GKE Standard itself: a cluster admin can repoint the
301+
`storageclass.kubernetes.io/is-default-class` annotation to any
302+
StorageClass. Run `kubectl get storageclass` first and check which one is
303+
annotated `(default)`, its `PROVISIONER`, and (via `kubectl get
304+
storageclass -o yaml`) its `parameters.type`; don't assume it's
305+
`standard-rwo`/`pd-balanced`. Any PVC scheduled onto a GB200 node with no
306+
`storageClassName` set (which binds it to the cluster default) fails
307+
this way unless that default's `parameters.type` is already
308+
Hyperdisk-backed: `pd-balanced disk type cannot be used by
309+
a4x-highgpu-4g machine type` (or the equivalent for whatever `pd-*` type
310+
the default actually provisions).
311+
312+
This includes the `inference-perf` validator's model-weights cache PVC
313+
when `AICR_INFERENCE_PERF_MODEL_CACHE_STORAGE_CLASS` (see
314+
[Validation](../user/validation.md)) is left unset, it then falls back
315+
to the cluster default too. Set that variable to name a Hyperdisk-backed
316+
StorageClass explicitly (for example `hyperdisk-balanced`, applied below)
317+
and the cache PVC uses it directly via `storageClassName`, independent of
318+
whatever the cluster default resolves to.
319+
320+
If the cluster default isn't already Hyperdisk-backed, apply one. Like
321+
the RDMA CRs above, this is a cluster prerequisite AICR does not
322+
provision:
323+
324+
```yaml
325+
apiVersion: storage.k8s.io/v1
326+
kind: StorageClass
327+
metadata:
328+
name: hyperdisk-balanced
329+
provisioner: pd.csi.storage.gke.io
330+
parameters:
331+
type: hyperdisk-balanced
332+
volumeBindingMode: WaitForFirstConsumer
333+
allowVolumeExpansion: true
334+
```
335+
336+
Apply it once per cluster, then point the validator's model cache at it via
337+
an `AICR_INFERENCE_PERF_MODEL_CACHE_STORAGE_CLASS=hyperdisk-balanced` entry
338+
on the `inference-perf` catalog entry's `env` (or a catalog overlay in the
339+
`aicr validate --data <dir>` directory).
340+
341+
## Running the NCCL Benchmark
342+
343+
The GB200 GKE training recipe (`gb200-gke-cos-training`) selects the
344+
NVLS-variant performance check (`nccl-all-reduce-bw-nvls`): MNNVL across the
345+
A4X nodes' IMEX domain is the fabric that carries all-reduce traffic; gIB is the
346+
transport driver underneath, not the NCCL algorithm itself. Run it via:
347+
348+
```shell
349+
aicr validate --recipe recipes/overlays/gb200-gke-cos-training.yaml \
350+
--phase performance
351+
```
352+
353+
## References
354+
355+
- [GKE A4X custom setup guide](https://docs.cloud.google.com/ai-hypercomputer/docs/create/gke-ai-hypercompute-custom-a4x)
356+
- [Component Catalog](../user/component-catalog.md)
357+
- [Validation readiness gate](../user/validation.md)
358+
- [GKE TCPXO Networking](gke-tcpxo-networking.md)

0 commit comments

Comments
 (0)