Context
ARTIFACTS_PROXY_ENABLED is a configuration option that has been added in the pipeline-install-conifg ConfigMap. It was introduced in the PR that replaced minio with seaweedfs. According to the comments above the definition:
Controls whether the artifact proxy is enabled to support accessing out-of-kubeflow scope buckets. The artifact proxy has known security and architectural flaws, so it should only be enabled if you specifically need to access unique pipeline root buckets per namespace that are outside the kubeflow namespace's access valid values are 'true' and 'false'. Defaults to 'false'.
In practice, this config option affects the creation of ml-pipeline-ui deployment in the profile namespaces.
Handling of ml-pipeline-ui deployments in the user namespace
Advantages
- The main advantage of this config option is to improve resource scaling of a Kubeflow cluster with a lot of Kubeflow profiles. In a standard Kubeflow cluster with 100 profiles:
- With
ARTIFACTS_PROXY_ENABLED=true, there will be one ml-pipeline-ui pod in the control plane namespace, and 100 pods in the profile namespaces, totaling 101 pods
- With
ARTIFACTS_PROXY_ENABLED=false, there will only be one ml-pipeline-ui pod in the control plane namespace
What needs to get done
- Add config option in the
kfp-api charm named artifacts-proxy-enabled
- Discuss what the default value should be
- Add unit tests
- Add integration tests. The integration tests should check that with
ARTIFACTS_PROXY_ENABLED=false, a ml-pipeline-ui pod is not created in the profile namespace
Definition of Done
.
Context
ARTIFACTS_PROXY_ENABLEDis a configuration option that has been added in the pipeline-install-conifg ConfigMap. It was introduced in the PR that replaced minio with seaweedfs. According to the comments above the definition:In practice, this config option affects the creation of
ml-pipeline-uideployment in the profile namespaces.Handling of
ml-pipeline-uideployments in the user namespacesync.pywas updated in chore: Seaweedfs as Minio replacement kubeflow/pipelines#11965 to conditionally create theml-pipeline-uideployments in the user namespace as well as the respective service, see https://github.com/kubeflow/pipelines/blob/bc89227f26afb8c5601581c2b7b5634ce017728d/manifests/kustomize/base/installs/multi-user/pipelines-profile-controller/sync.py#L230.ARTIFACTS_PROXY_ENABLED.frontendimage in thekfp-uiconditionally uses this environment variable to redirect requests to theml-pipeline-uiservice in the user deployment.ARTIFACTS_PROXY_ENABLEDwas changed tofalsein chore: Seaweedfs as Minio replacement kubeflow/pipelines#11965. Comments in https://github.com/kubeflow/manifests/blob/1a12e1be42f69ad4a3d374dc3e9cb2da6eb26706/applications/pipeline/upstream/base/installs/generic/pipeline-install-config.yaml#L97-L104 explain that this change was made for security reasons, the reasoning behind the change being still unclear.Advantages
ARTIFACTS_PROXY_ENABLED=true, there will be oneml-pipeline-uipod in the control plane namespace, and 100 pods in the profile namespaces, totaling 101 podsARTIFACTS_PROXY_ENABLED=false, there will only be oneml-pipeline-uipod in the control plane namespaceWhat needs to get done
kfp-apicharm namedartifacts-proxy-enabledARTIFACTS_PROXY_ENABLED=false, aml-pipeline-uipod is not created in the profile namespaceDefinition of Done
.