-
Notifications
You must be signed in to change notification settings - Fork 2.1k
feat(backend): postgres integration #12379
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,16 @@ | ||
| apiVersion: apps/v1 | ||
| kind: Deployment | ||
| metadata: | ||
| name: ml-pipeline | ||
| spec: | ||
| template: | ||
| spec: | ||
| containers: | ||
| - name: ml-pipeline-api-server | ||
| env: | ||
| - name: V2_DRIVER_IMAGE | ||
| value: kind-registry:5000/driver:ci | ||
| - name: V2_LAUNCHER_IMAGE | ||
| value: kind-registry:5000/launcher:ci | ||
| - name: LOG_LEVEL | ||
| value: "debug" |
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,112 @@ | ||
| apiVersion: kustomize.config.k8s.io/v1beta1 | ||
| kind: Kustomization | ||
|
|
||
| # CI overlay for Multi-user + PostgreSQL testing | ||
| # This CI overlay does three things: | ||
| # 1. It uses `platform-agnostic-multi-user-postgresql` as its base | ||
| # 2. It applies CI-specific environment variables | ||
| # 3. It overrides image names to use locally built images from Kind registry | ||
| resources: | ||
| - ../../base | ||
| - ../../../../../manifests/kustomize/env/platform-agnostic-multi-user-postgresql | ||
|
|
||
| # The Kind PostgreSQL instance does not use TLS. Configure that deliberate CI | ||
| # choice through the same ConfigMap input consumed by both database clients. | ||
| configMapGenerator: | ||
| - name: pipeline-install-config | ||
| behavior: merge | ||
| literals: | ||
| - postgresExtraParams={"sslmode":"disable"} | ||
|
|
||
| images: | ||
| - name: ghcr.io/kubeflow/kfp-api-server | ||
| newName: kind-registry:5000/apiserver | ||
| newTag: latest | ||
| - name: ghcr.io/kubeflow/kfp-persistence-agent | ||
| newName: kind-registry:5000/persistenceagent | ||
| newTag: latest | ||
| - name: ghcr.io/kubeflow/kfp-scheduled-workflow-controller | ||
| newName: kind-registry:5000/scheduledworkflow | ||
| newTag: latest | ||
| - name: ghcr.io/kubeflow/kfp-frontend | ||
| newName: kind-registry:5000/frontend | ||
| newTag: latest | ||
| - name: ghcr.io/kubeflow/kfp-metadata-writer | ||
| newName: kind-registry:5000/metadata-writer | ||
| newTag: latest | ||
| - name: ghcr.io/kubeflow/kfp-viewer-crd-controller | ||
| newName: kind-registry:5000/viewer-crd-controller | ||
| newTag: latest | ||
| - name: ghcr.io/kubeflow/kfp-visualization-server | ||
| newName: kind-registry:5000/visualization-server | ||
| newTag: latest | ||
| - name: ghcr.io/kubeflow/kfp-cache-deployer | ||
| newName: kind-registry:5000/cache-deployer | ||
| newTag: latest | ||
| - name: ghcr.io/kubeflow/kfp-cache-server | ||
| newName: kind-registry:5000/cache-server | ||
| newTag: latest | ||
| - name: ghcr.io/kubeflow/kfp-metadata-envoy | ||
| newName: kind-registry:5000/metadata-envoy | ||
| newTag: latest | ||
|
|
||
| patches: | ||
| - path: ../../base/apiserver-env.yaml | ||
| target: | ||
| kind: Deployment | ||
| name: ml-pipeline | ||
| - path: ../../base/ci-stability-tuning.yaml | ||
| - path: apiserver-env.yaml | ||
| target: | ||
| kind: Deployment | ||
| name: ml-pipeline | ||
| - path: ../../base/grpc-specs.yaml | ||
| target: | ||
| kind: Deployment | ||
| name: metadata-grpc-deployment | ||
| - path: ../../base/cache-specs.yaml | ||
| target: | ||
| kind: Deployment | ||
| name: cache-server | ||
| - path: ../../base/metadata-writer-pull-policy.yaml | ||
| target: | ||
| kind: Deployment | ||
| name: metadata-writer | ||
| - path: ../../base/viewer-crd-pull-policy.yaml | ||
| target: | ||
| kind: Deployment | ||
| name: ml-pipeline-viewer-crd | ||
| - path: ../../base/cache-deployer-pull-policy.yaml | ||
| target: | ||
| kind: Deployment | ||
| name: cache-deployer-deployment | ||
| - path: ../../base/cache-server-pull-policy.yaml | ||
| target: | ||
| kind: Deployment | ||
| name: cache-server | ||
| - path: ../../base/metadata-envoy-pull-policy.yaml | ||
| target: | ||
| kind: Deployment | ||
| name: metadata-envoy-deployment | ||
|
|
||
| replacements: | ||
| - source: | ||
| kind: ConfigMap | ||
| name: dns-config | ||
| fieldPath: data.namespaceDns | ||
| targets: | ||
| - select: | ||
| kind: Deployment | ||
| name: ml-pipeline | ||
| fieldPaths: | ||
| - spec.template.spec.dnsConfig.searches.[=NAMESPACE.svc.cluster.local] | ||
| - select: | ||
| kind: Deployment | ||
| name: metadata-grpc-deployment | ||
| fieldPaths: | ||
| - spec.template.spec.dnsConfig.searches.[=NAMESPACE.svc.cluster.local] | ||
| - select: | ||
| kind: Deployment | ||
| name: cache-server | ||
| fieldPaths: | ||
| - spec.template.spec.dnsConfig.searches.[=NAMESPACE.svc.cluster.local] | ||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,16 @@ | ||
| apiVersion: apps/v1 | ||
| kind: Deployment | ||
| metadata: | ||
| name: ml-pipeline | ||
| spec: | ||
| template: | ||
| spec: | ||
| containers: | ||
| - name: ml-pipeline-api-server | ||
| env: | ||
| - name: V2_DRIVER_IMAGE | ||
| value: kind-registry:5000/driver:ci | ||
| - name: V2_LAUNCHER_IMAGE | ||
| value: kind-registry:5000/launcher:ci | ||
| - name: LOG_LEVEL | ||
| value: "debug" |
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. The PostgreSQL CI overlays (both standalone and multiuser) are missing the Verified: Suggested fix: Add to both - path: ../../base/ci-stability-tuning.yaml |
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,117 @@ | ||
| apiVersion: kustomize.config.k8s.io/v1beta1 | ||
| kind: Kustomization | ||
|
|
||
| # This CI overlay for PostgreSQL testing does three things: | ||
| # 1. It uses `platform-agnostic-postgresql` as its base. This is the project's | ||
| # standard way to deploy KFP with PostgreSQL, which correctly includes both | ||
| # the KFP core components and the third-party PostgreSQL instance, and | ||
| # patches the API server to use the 'pgx' driver. | ||
| # 2. It applies an additional patch (`apiserver-env.yaml`) to inject | ||
| # CI-specific environment variables, like the V2 image path. This aligns | ||
| # with the pattern used in other CI overlays like `minio`. | ||
| # 3. It overrides the image names to use the locally built images from the | ||
| # Kind registry, which is standard practice for all CI tests. | ||
| resources: | ||
| - ../../base | ||
| - ../../../../../manifests/kustomize/env/platform-agnostic-postgresql | ||
|
|
||
| # The Kind PostgreSQL instance does not use TLS. Configure that deliberate CI | ||
| # choice through the same ConfigMap input consumed by both database clients. | ||
| configMapGenerator: | ||
| - name: pipeline-install-config | ||
| behavior: merge | ||
| literals: | ||
| - postgresExtraParams={"sslmode":"disable"} | ||
|
|
||
| images: | ||
| - name: ghcr.io/kubeflow/kfp-api-server | ||
| newName: kind-registry:5000/apiserver | ||
| newTag: latest | ||
| - name: ghcr.io/kubeflow/kfp-persistence-agent | ||
| newName: kind-registry:5000/persistenceagent | ||
| newTag: latest | ||
| - name: ghcr.io/kubeflow/kfp-scheduled-workflow-controller | ||
| newName: kind-registry:5000/scheduledworkflow | ||
| newTag: latest | ||
| - name: ghcr.io/kubeflow/kfp-frontend | ||
| newName: kind-registry:5000/frontend | ||
| newTag: latest | ||
| - name: ghcr.io/kubeflow/kfp-metadata-writer | ||
| newName: kind-registry:5000/metadata-writer | ||
| newTag: latest | ||
| - name: ghcr.io/kubeflow/kfp-viewer-crd-controller | ||
| newName: kind-registry:5000/viewer-crd-controller | ||
| newTag: latest | ||
| - name: ghcr.io/kubeflow/kfp-visualization-server | ||
| newName: kind-registry:5000/visualization-server | ||
| newTag: latest | ||
| - name: ghcr.io/kubeflow/kfp-cache-deployer | ||
| newName: kind-registry:5000/cache-deployer | ||
| newTag: latest | ||
| - name: ghcr.io/kubeflow/kfp-cache-server | ||
| newName: kind-registry:5000/cache-server | ||
| newTag: latest | ||
| - name: ghcr.io/kubeflow/kfp-metadata-envoy | ||
| newName: kind-registry:5000/metadata-envoy | ||
| newTag: latest | ||
|
|
||
| patches: | ||
|
HumairAK marked this conversation as resolved.
|
||
| - path: ../../base/apiserver-env.yaml | ||
| target: | ||
| kind: Deployment | ||
| name: ml-pipeline | ||
| - path: ../../base/ci-stability-tuning.yaml | ||
| - path: apiserver-env.yaml | ||
| target: | ||
| kind: Deployment | ||
| name: ml-pipeline | ||
| - path: ../../base/grpc-specs.yaml | ||
| target: | ||
| kind: Deployment | ||
| name: metadata-grpc-deployment | ||
| - path: ../../base/cache-specs.yaml | ||
| target: | ||
| kind: Deployment | ||
| name: cache-server | ||
| - path: ../../base/metadata-writer-pull-policy.yaml | ||
| target: | ||
| kind: Deployment | ||
| name: metadata-writer | ||
| - path: ../../base/viewer-crd-pull-policy.yaml | ||
| target: | ||
| kind: Deployment | ||
| name: ml-pipeline-viewer-crd | ||
| - path: ../../base/cache-deployer-pull-policy.yaml | ||
| target: | ||
| kind: Deployment | ||
| name: cache-deployer-deployment | ||
| - path: ../../base/cache-server-pull-policy.yaml | ||
| target: | ||
| kind: Deployment | ||
| name: cache-server | ||
| - path: ../../base/metadata-envoy-pull-policy.yaml | ||
| target: | ||
| kind: Deployment | ||
| name: metadata-envoy-deployment | ||
|
|
||
| replacements: | ||
| - source: | ||
| kind: ConfigMap | ||
| name: dns-config | ||
| fieldPath: data.namespaceDns | ||
| targets: | ||
| - select: | ||
| kind: Deployment | ||
| name: ml-pipeline | ||
| fieldPaths: | ||
| - spec.template.spec.dnsConfig.searches.[=NAMESPACE.svc.cluster.local] | ||
| - select: | ||
| kind: Deployment | ||
| name: metadata-grpc-deployment | ||
| fieldPaths: | ||
| - spec.template.spec.dnsConfig.searches.[=NAMESPACE.svc.cluster.local] | ||
| - select: | ||
| kind: Deployment | ||
| name: cache-server | ||
| fieldPaths: | ||
| - spec.template.spec.dnsConfig.searches.[=NAMESPACE.svc.cluster.local] | ||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
This multi-user PostgreSQL CI overlay drops the
pipeline-crd-rbac.yamlpatch that the other three multi-user CI overlays apply.multiuser/default,multiuser/artifact-proxy, andmultiuser/cache-disabledall apply../pipeline-crd-rbac.yaml(addspipelines.kubeflow.orgpipelines/pipelineversions verbs to theml-pipelineClusterRole). This overlay is deployed for the multi-user pgx lane, so omitting it is an RBAC inconsistency that could surface as permission errors on pipeline-CRD paths.../pipeline-crd-rbac.yamlpatch here for parity.There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I have a concern about this. All four multi-user CI overlays deploy in database pipeline store mode (
--pipelinesStoreKubernetesis never set), so theml-pipelineClusterRole should not need full CRUD permissions onpipelines.kubeflow.orgCRDs — the defaultget/list/watchfrom the base manifest is sufficient for the webhook's needs.I've opened #13919 to discuss whether we should remove
pipeline-crd-rbac.yamlfrom the other three multi-user overlays as well, rather than adding it here.