Skip to content

Add ARTIFACTS_PROXY_ENABLED config option #973

Description

@mvlassis

Context

ARTIFACTS_PROXY_ENABLED is a configuration option that has been added in the pipeline-install-conifg ConfigMap. It was introduced in the PR that replaced minio with seaweedfs. According to the comments above the definition:

Controls whether the artifact proxy is enabled to support accessing out-of-kubeflow scope buckets. The artifact proxy has known security and architectural flaws, so it should only be enabled if you specifically need to access unique pipeline root buckets per namespace that are outside the kubeflow namespace's access valid values are 'true' and 'false'. Defaults to 'false'.

In practice, this config option affects the creation of ml-pipeline-ui deployment in the profile namespaces.

Handling of ml-pipeline-ui deployments in the user namespace

Advantages

  • The main advantage of this config option is to improve resource scaling of a Kubeflow cluster with a lot of Kubeflow profiles. In a standard Kubeflow cluster with 100 profiles:
  • With ARTIFACTS_PROXY_ENABLED=true, there will be one ml-pipeline-ui pod in the control plane namespace, and 100 pods in the profile namespaces, totaling 101 pods
  • With ARTIFACTS_PROXY_ENABLED=false, there will only be one ml-pipeline-ui pod in the control plane namespace

What needs to get done

  • Add config option in the kfp-api charm named artifacts-proxy-enabled
  • Discuss what the default value should be
  • Add unit tests
  • Add integration tests. The integration tests should check that with ARTIFACTS_PROXY_ENABLED=false, a ml-pipeline-ui pod is not created in the profile namespace

Definition of Done

.

Activity

  1. syncronize-issues-to-jira commented on Jul 15, 2026

    @syncronize-issues-to-jira

    Thank you for reporting your feedback to us!

    The internal ticket has been created: https://warthogs.atlassian.net/browse/KF-8855.

    This message was autogenerated

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions