Deploying Nutanix Enterprise AI
Version 2.8.0
This version of the NAI deployment is based on the Nutanix Enterprise AI (NAI) v2.8.0 release.
Prepare for NAI Deployment
GA Software with NAI v2.8.0
In this lab, we will deploy GA version of the following software to test the following:
-
Nutanix Enterprise AI
- Unified Endpoints - multiple endpoints for HA and token-based rate limiting
- Providers - Add remote endpoints from providers to utilize their models in Nutanix Enterprise AI workloads.
Info
Changes in NAI v2.8.0
- Kserve is of at least of
v0.19.0 - Cert-manager is at least of
v1.17.2 - OpenTelemetry operator is at least of
v0.114.1 - Envoy Gateway is at least of
v1.8.1 - Prometheus Monitoring is at least of
82.13.6 - CloudNativePG Operator is ar least of
0.28.0[usually pre-installed with NKP] - LeaderWorkerSet is at least of
0.8.0
Enable Pre-requisite Applications
Warning
Make sure to license NKP cluster with at least NKP Pro License to make use of the NKP Applications catalog to provision NAI (and other applications)
Prometheus
The following pre-requisite applications will be enabled on NKP GUI:
Note
In this lab, we will be using the Management Cluster Workspace to deploy our Nutanix Enterprise AI (NAI)
However, in a customer environment, it is recommended to use a separate workload NKP cluster.
Search and Enable the following applications: follow this order to install dependencies for NAI application
- In the NKP GUI, Go to Clusters
- Click on Management Cluster Workspace
-
Go to Applications to search and enable the following:
- Prometheus Monitoring : version
82.13.6or higher with the followingValuesconfiguration
- Prometheus Monitoring : version
-
Wait for
Deployedstate in the GUI
Cert Manager
Cert Manager is pre-installed on all NKP Clusters. If not installed, use the following method to install:
- In the NKP GUI, Go to Clusters
- Click on Management Cluster Workspace
-
Go to Applications to search and enable the following:
- Cert-manager- at least
v1.17.2
- Cert-manager- at least
-
Wait for
Deployedstate in the GUI
Envoy Gateway
- In the NKP GUI, Go to Clusters
- Click on Management Cluster Workspace
-
Go to Applications to search and enable the following:
-
NAI - Envoy Gateway : version
v1.8.1or higher with the followingValuesconfigurationconfig: envoyGateway: gateway: controllerName: "gateway.envoyproxy.io/gatewayclass-controller" logging: level: default: "info" provider: kubernetes: rateLimitDeployment: container: image: "docker.io/envoyproxy/ratelimit:1e50889b" patch: type: "StrategicMerge" value: spec: template: spec: containers: - imagePullPolicy: "IfNotPresent" name: "envoy-ratelimit" image: "docker.io/envoyproxy/ratelimit:1e50889b" env: - name: REDIS_TYPE value: "sentinel" - name: REDIS_PIPELINE_WINDOW value: "150us" type: "Kubernetes" extensionApis: enableEnvoyPatchPolicy: true enableBackend: true extensionManager: maxMessageSize: 11Mi backendResources: - group: inference.networking.k8s.io kind: InferencePool version: v1 hooks: xdsTranslator: translation: listener: includeAll: true route: includeAll: true cluster: includeAll: true secret: includeAll: true post: - "Translation" - "Cluster" - "Route" service: fqdn: hostname: "ai-gateway-controller.nai-system.svc.cluster.local" port: 1063 rateLimit: backend: type: "Redis" redis: url: "mymaster,nai-valkey-sentinel.nai-system.svc.cluster.local:26379"
-
-
Check if Envoy Gateway resources are ready either in the GUI by watching for
Deployedstate or in the commandline as follows:Warning
The
envoy-ratelimit-pod will temporarily be inCrashLoopBackOffstate and eventually will transition toRunningafter redis-standalone pod is fully deployed in the upcoming Deploy NAI section.Ignore the
CrashLoopBackOffstate for now and move on to the next section.
Kserve
Kserve and Kserve LLMInferenceService
Note that Kserve and Kserve LLMInferenceService are bundled in the same Kserve NKP catalog application.
Installing Kserve will also install Kserve LLMInferenceService CRDs and resources.
For more information, see catalog application packaging here on Github.
- In the NKP GUI, Go to Clusters
- Click on Management Cluster Workspace
-
Go to Applications to search and enable the following:
-
Kserve : version
v0.19.0or higher with the followingValuesconfiguration
-
-
Check if
KserveandKserve LLMInferenceServiceresources are ready either in the GUI by watching forRunningstate or in the commandline as follows:
CloudNativePG
Note
NKP will have CloudNativePG pre-installed as a part of regular install. Check in the Applications Catalog of the NKP cluster for its presence.
Check for CloudNativePG v0.28.0, if present, skip this section.
- In the NKP GUI, Go to Clusters
- Click on Management Cluster Workspace
-
Go to Applications to search and enable the following:
- CloudNativePG : version
0.28.0
- CloudNativePG : version
LeaderWorkerSet
LeaderWorkerSet (LWS) is an open-source, custom Kubernetes API designed to deploy and manage multi-node AI/ML workloads—such as large language model (LLM) distributed inference and training—as a single, cohesive unit. It automatically groups a collection of pods into a specific topology consisting of one leader pod and multiple worker pods, managing their entire lifecycle simultaneously so that if a single pod fails, the entire group restarts together to prevent data inconsistency. Furthermore, LWS simplifies network communication across these nodes by automatically injecting group environment variables and optimizing pod placement within the same network topology to guarantee high-throughput, low-latency data transfers between GPUs.
- In the NKP GUI, Go to Clusters
- Click on Management Cluster Workspace
-
Go to Applications to search and enable the following:
- LeaderWorkerSet : version
0.8.0
- LeaderWorkerSet : version
Opentelemetry
- In the NKP GUI, Go to Clusters
- Click on Management Cluster Workspace
-
Go to Applications to search and enable the following:
- Opentelemetry Operator : version
v0.114.1
- Opentelemetry Operator : version
Deploy NAI
We will use the Docker login credentials we created in the previous section to download the NAI Docker images.
Deploy NAI Profiles using Helm
NAI v2.8.0 onwards has support for profiles for different capacity of NAI use cases.
Use the Helm method here to install these profiles depending on your requirements.
| Name | Capacity |
|---|---|
| Default | 300 concurrent requests and 100 API Keys |
| c1k_k200 | 1000 concurrent requests and 200 API Keys |
| c5k_k1k | 5000 concurrent requests and 1000 API Keys |
Change the Docker login credentials
The following Docker based environment variable values need to be changed from your own Docker environment variables to the credentials downloaded from Nutanix Portal.
$DOCKER_NAI_USERNAME$DOCKER_NAI_ASSWORD$DOCKER_NAI_EMAIL
-
Open
$HOME/.envfile inVSCode -
Add (append) the following environment variables and save it
export NAI_USER=_your_desired_nai_ui_username export NAI_TEMP_PASS=_your_desired_nai_ui_password # At least 8 characters export REGISTRY_SECRET_NAME=_k8s_secret_for_nai export DOCKER_SERVER=https://index.docker.io/v1/ export DOCKER_NAI_USERNAME=_GA_release_docker_username export DOCKER_NAI_PASSWORD=_GA_release_docker_password export DOCKER_NAI_EMAIL=_GA_release_docker_email export NAI_CORE_VERSION=_GA_release_nai_core_version export NAI_API_RWX_STORAGECLASS=_nkp_rwx_storage_class export NAI_DEFAULT_RWO_STORAGECLASS=_nkp_rwo_storage_class export NKP_WORKSPACE_NAMESPACE=_nkp_workspace name # (1)! export CLUSTER_ISSUER=_cluster_issuer_name export NAI_PUBLIC_DOMAIN_NAME=_nai_domain_name-
To get the workspace namespace, run the following commmand. Note the WORKSPACE NAMESPACE column in the output
export NAI_USER=admin export NAI_TEMP_PASS=_Xxxxxxxxxx export REGISTRY_SECRET_NAME=nai-regcred export DOCKER_SERVER=https://index.docker.io/v1/ export DOCKER_NAI_USERNAME=ntnxsvcgpt export DOCKER_NAI_PASSWORD=dckr_pat_XXXXXXXXXXXXXXXXXXXXXXXXX export DOCKER_NAI_EMAIL=ntnxsvcgpt export NAI_CORE_VERSION=2.8.0 export NAI_API_RWX_STORAGECLASS=nai-nfs-storage export NAI_DEFAULT_RWO_STORAGECLASS=nutanix-volume export NKP_WORKSPACE_NAMESPACE=kommander export CLUSTER_ISSUER=letsencrypt-cloudflare export NAI_PUBLIC_DOMAIN_NAME=nai.domain.com -
-
Source the environment variables
-
Create the nai-system namespace to install Nutanix Enterprise AI
-
Create docker registry Secrets in both
nai-systemandenvoy-gateway-systemnamespaces. -
In the NKP GUI, Go to Clusters
- Click on Management Cluster Workspace
-
Create a template file with Values configuration
cat << EOF > nai-core-values.yaml global: imagePullSecrets: - name: ${REGISTRY_SECRET_NAME} storage: storageClassNameRWX: ${NAI_API_RWX_STORAGECLASS} storageClassName: ${NAI_DEFAULT_RWO_STORAGECLASS} naiMonitoring: nodeExporter: serviceMonitor: namespaceSelector: matchNames: - ${NKP_WORKSPACE_NAMESPACE} dcgmExporter: serviceMonitor: namespaceSelector: matchNames: - ${NKP_WORKSPACE_NAMESPACE} naiApi: superAdmin: username: ${NAI_UI_USER} password: ${NAI_TEMP_PASS} # At least 8 characters # email: admin@nutanix.com # firstName: admin gateway: tlsSecretName: "nai-cert" # secret name written by cert-manager certManager: selfSigned: true # enables self-signed issuer + certificate # Optional - use if you are using cert-manager and ClusterIssuer with your own domain # gateway: # certManager: # issuerRef: # name: letsencrypt-cloudflare # ClusterIssuer must be existing # kind: ClusterIssuer # dnsNames: # - nai.domain.com EOFglobal: imagePullSecrets: - name: nai-regcred storage: storageClassNameRWX: nai-nfs-storage storageClassName: nutanix-volume naiMonitoring: nodeExporter: serviceMonitor: namespaceSelector: matchNames: - kommander dcgmExporter: serviceMonitor: namespaceSelector: matchNames: - kommander naiApi: superAdmin: username: admin password: _XXXXXXXXX # At least 8 characters # email: admin@nutanix.com # firstName: admin gateway: tlsSecretName: "nai-cert" # secret name written by cert-manager certManager: selfSigned: true # enables self-signed issuer + certificate # Optional - use if you are using cert-manager and ClusterIssuer with your own domain # gateway: # certManager: # issuerRef: # name: letsencrypt-cloudflare # kind: ClusterIssuer # dnsNames: # - nai.domain.com -
Go to Applications to search and enable the following:
- Nutanix Enterprise AI : version
v2.8.0or higher with contents ofnai-core-values.yamlfile from previous step.
- Nutanix Enterprise AI : version
-
Check if NAI resources are ready either in the GUI by watching for
Deployedstate or in the commandline as follows:Note
This operation will take at least
5 - 8 minutesdepending on the resources available.The NKP Catalog application will deploy nai-operators first before proceeding to install NAI resources.
Active namespace is "nai-system". NAME READY STATUS RESTARTS AGE ai-gateway-controller-6fff98cbd6-lv8dd 1/1 Running 0 67m chi-nai-clickhouse-server-chcluster1-0-0-0 1/1 Running 0 64m chk-nai-clickhouse-keeper-chkeeper-0-0-0 1/1 Running 0 63m iam-database-bootstrap-pdzxh-7j9m7 0/1 Completed 0 64m iam-proxy-5bd954bb85-qmdwx 1/1 Running 0 64m iam-proxy-control-plane-5ff697cdfb-5pnlz 1/1 Running 0 64m iam-themis-849478f448-7c6bx 2/2 Running 0 60m iam-themis-bootstrap-e5pyk-pl96p 0/1 Completed 0 64m iam-ui-7476458cb-q8rns 1/1 Running 0 64m iam-user-authn-57d8b4dd67-nsdt5 2/2 Running 0 60m nai-agent-5d7b86946d-8b8jn 1/1 Running 0 64m nai-api-86d58c7b6f-5fg4h 1/1 Running 0 64m nai-api-db-migrate-vk5y2-2dfr8 0/1 Completed 5 64m nai-clickhouse-schema-job-1788408841-hvwl8 0/1 Completed 0 64m nai-db-iep-1 1/1 Running 0 66m nai-oauth2-proxy-595d65db9c-lt6bs 1/1 Running 0 64m nai-operators-nai-clickhouse-operator-687479c97b-m9hn7 2/2 Running 0 67m nai-otel-collector-collector-2b5xm 1/1 Running 0 64m nai-otel-collector-collector-5xj4k 1/1 Running 0 64m nai-otel-collector-collector-7jdln 1/1 Running 0 64m nai-otel-collector-collector-7tlz8 1/1 Running 0 64m nai-otel-collector-collector-b6vpl 1/1 Running 0 64m nai-otel-collector-collector-k52pv 1/1 Running 0 64m nai-otel-collector-collector-qnk9d 1/1 Running 0 64m nai-otel-collector-collector-w4zlf 1/1 Running 0 64m nai-otel-collector-targetallocator-7fcccfc477-ndgkr 1/1 Running 0 64m nai-securityscan-manager-77679b5554-94p4z 1/1 Running 0 64m nai-ui-7b5b9b88b4-c9wzz 1/1 Running 0 64m nai-valkey-0 1/1 Running 0 67m nai-valkey-sentinel-0 1/1 Running 0 67m
Install SSL Certificate and Gateway Elements
In this section we will install SSL Certificate to access the NAI UI. This is required as the endpoint will only work with a ssl endpoint with a valid certificate.
NAI UI is accessible using the Envoy Ingress Gateway.
Optional and manual - using Public Certificate Authority (CA)
If an organization generates certificates using a different mechanism then obtain the certificate + key and create a kubernetes secret manually using the following command:
-
Create the certificate from the files (generated using certbot or provided to you)
-
Combine the certificates to get the certificate bundle
-
Create a kubernetes secret in the nai-system namespace to use during NAI install
-
Patch the Envoy gateway with the
nai-certcertificate details
Optional to automate - using Public Certificate Authority (CA) and Cert Manager
Using Cert Manager to manage the Public Certificate Authority (CA) for NAI SSL Certificate is also a possiblity.
At a high level (Cloudflare Example):
- Get a API key from DNS provider woth Edit Zone rights
-
Create a Kubernetes
Secretfrom the API key -
Create a
ClusterIssuerwith Cert Mangager/Let's Encrypt - Configure cert-manager to use DNS-01 challenge with Cloudflare for automatic certificate issuance.apiVersion: cert-manager.io/v1 kind: ClusterIssuer metadata: name: letsencrypt-cloudflare namespace: cert-manager spec: acme: email: _YOUR_DOMAIN_OWNER_EMAIL_ADDRESS server: https://acme-v02.api.letsencrypt.org/directory privateKeySecretRef: name: letsencrypt-cloudflare-account-key solvers: - dns01: cloudflare: apiTokenSecretRef: name: cloudflare-api-token-secret key: api-tokenapiVersion: cert-manager.io/v1 kind: ClusterIssuer metadata: name: letsencrypt-cloudflare spec: acme: email: _YOUR_DOMAIN_OWNER_EMAIL_ADDRESS server: https://acme-v02.api.letsencrypt.org/directory privateKeySecretRef: name: nai-letsencrypt-cluster solvers: - dns01: route53: region: us-east-1 accessKeyIDSecretRef: name: route53-api-token-secret key: access-key-id secretAccessKeySecretRef: name: route53-api-token-secret key: secret-access-key hostedZoneID: _HOSTED_ZONE_ID -
Create the ingress resource certificate using the following command:
-
Patch the Envoy gateway with the
nai-certcertificate details
The following steps show how cert-manager can be used to generate a self signed certificate using the default selfsigned-issuer present in the cluster for the purposes of the lab.
-
Get the NAI UI ingress gateway host using the following command:
-
Get the value of
NAI_UI_ENDPOINTenvironment variable -
We will use the command output e.g:
10.x.x.216as the IP address for NAI as reserved in this section -
Construct the FQDN of NAI UI using nip.io and we will use this FQDN as the certificate's Common Name (CN).
-
Create the ingress resource certificate using the following command:
cat << EOF | k apply -f - apiVersion: cert-manager.io/v1 kind: Certificate metadata: name: nai-cert namespace: nai-system spec: issuerRef: name: selfsigned-issuer kind: ClusterIssuer secretName: nai-cert commonName: nai.${NAI_UI_ENDPOINT}.nip.io dnsNames: - nai.${NAI_UI_ENDPOINT}.nip.io ipAddresses: - ${NAI_UI_ENDPOINT} EOF -
Patch the Envoy gateway with the
nai-certcertificate details -
Create EnvoyProxy
-
Patch the
nai-ingress-gatewayresource with the newEnvoyProxydetails
Accessing the UI
-
In a browser, open the following URL to connect to the NAI UI
-
Change the password for the
adminuser -
Login using
adminuser and password that was set in the install workflow