23 May 2022 |
zorba(손주형) | what will be done in community call? | 02:50:04 |
| Lize Cai joined the room. | 08:25:53 |
| Abhishek Sharma joined the room. | 11:34:49 |
Jan Buijnsters | https://kserve.github.io/website/0.8/blog/articles/2022-02-18-KServe-0.8-release/#join-the-community
Biweekly Wednesday 9am PST | 14:22:45 |
| Thomas Ounnas joined the room. | 16:11:39 |
24 May 2022 |
| Benjamin Tan changed their profile picture. | 15:25:17 |
croberts | Trying to debug a kserve-raw deployment. Can anyone think of reasons why the storage-initializer init container is not getting attached to the tensorflow pod? | 15:57:02 |
Dan Sun | which namespace it is deployed to? it does not work in the kserve control plane namespace | 16:07:24 |
croberts | The person trying it originally put it in the kserve namespace, but later tried in another namespace and had the same result | 16:22:01 |
croberts | We even tried uninstalling "everything" and re-installing, but we can't seem to get the init-container to happen....no errors in any place we've looked so far | 16:22:39 |
croberts | Oh...interesting...her project does have the control-plane: controller-manager label | 16:28:55 |
croberts | Thanks Dan Sun that was it. Somehow, she tried in the one project that would NOT work. | 16:32:28 |
Dan Sun | ye the pod mutator webhook checks the namespace label
https://github.com/kserve/kserve/blob/master/config/webhook/manifests.yaml#L40 | 16:37:15 |
Rachit Chauhan | I observed there are 3 PeerAuthentication policies that are being created as part of knative istio controller (https://github.com/knative/serving/blob/591e12dafbcb79a34e0a3bdc586d408b2830aef1/third_party/istio-latest/net-istio.yaml
lines 203, 222, 240).
Why these webhooks deployments getting istio’s sidecars injected ? Which other components are calling them apart from kube-apiserver ? | 23:28:33 |
25 May 2022 |
Dan Sun | As the comment says these policies are created to work with both mesh and non mesh mode in case sidecar is injected | 04:23:18 |
zorba(손주형) | I think this is bug.
I’m using fake client with NewSimpleClientset .
and testing InferenceService.List function
list, err := suite.fakeClient.InferenceService.List(v12.ListOptions{})
s.NoError(err)
this error occurs
no kind "InferenceServiceList" is registered for version "serving/v1beta1" in scheme "pkg/runtime/scheme.go:100" | 11:06:48 |
Shri Javadekar | Hey everyone..
I missed the community meeting today 😞
What's the zoom link for the community meeting? The doc only shows a Google meet link. Also, are the community meeting recordings available somewhere? | 17:04:14 |
| Sree joined the room. | 19:10:50 |
Dan Sun | We are in progress of migrating to zoom from gmeet, hopefully we can get recordings there | 19:16:28 |
Shri Javadekar | Got it.. What is the Zoom link for the meetings right now? I want to join the meetings. | 19:42:10 |
Dan Sun | it is the gmeet link on the doc | 19:46:01 |
Rachit Chauhan | Dan Sun: found the detailed reasoning why they still want sidecars even though the communication will not be over TLS (as it’s PERMISSIVE )
https://github.com/knative-sandbox/net-istio/issues/150
Not having sidecars will lead to loss of metrics.
ref: this comment | 21:34:45 |
Dan Sun | ye if you have strict security and audit requirement, you would need the sidecar | 21:41:22 |
Rachit Chauhan | For audits => logs and metrics
But for security purposes, STRICT was expected but it would cause failure as kube-apiserver is not part of the mesh and doesn’t have envoy | 21:43:47 |
Dan Sun | ye that makes sense | 21:51:41 |
26 May 2022 |
| _slack_kubeflow_U03H27PMSMR joined the room. | 06:03:04 |
| Kuba Dawczynski joined the room. | 08:13:24 |
| Kuba Dawczynski changed their display name from _slack_kubeflow_U03HSETDZPA to Kuba Dawczynski. | 09:07:31 |
| Kuba Dawczynski set a profile picture. | 09:07:32 |
Kuba Dawczynski | Hi everyone.
I have one question maybe someone already had this issue.
We are using kubeflow 1.4 and when we create new InferenceService, kserver is creating new virtual service with internal and external endpoint
where external endpoint is looking like
http://{name_of_model}.{namespace}.{domain}
unfortunately our network setup is a little bit complex and we would like to expose it like:
http://{domain}/{namespace}/{name_of_model}
I've tried to dig in this channel and github to get some information but i haven't found nothing | 09:07:33 |