Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[RHOAIENG-19717] Pod now has correct imagepull secret when updated in raw deployment #522

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

andresllh
Copy link
Member

@andresllh andresllh commented Mar 10, 2025

What this PR does / why we need it:
This issue was found while using Modelcars feature. For Modelcars, users may prefer using a private container registry to store their models. When using a private registry, it is required to provide a pull secret in the InferenceService so that the cluster can pull the model container.

At any time, and for any reason, users may require to replace/update the pull secret. This operation is done on the InferenceService. It is observed that when replacing the pull secret, the old one won't be removed in the updated deployment.
Which issue(s) this PR fixes (optional, in fixes #<issue number>(, fixes #<issue_number>, ...) format, will close the issue(s) when PR gets merged):
Fixes #
RHOAIENG-19717
Type of changes
Please delete options that are not relevant.

  • Bug fix (non-breaking change which fixes an issue)

Feature/Issue validation/testing:

Please describe the tests that you ran to verify your changes and relevant result summary. Provide instructions so it can be reproduced.
Please also list any relevant details for your test configuration.

  • Test A
  1. Created the following Inference Service
apiVersion: serving.kserve.io/v1beta1
kind: InferenceService
metadata:
  name: sample-isvc-using-oci
  namespace: oci-model-example
  annotations:
    serving.kserve.io/deploymentMode: RawDeployment
spec:
  predictor:
    imagePullSecrets:
    - name: pull-secret-one
    model:
      runtime: vllm-runtime # This is the name of the ServingRuntime resource
      modelFormat:
        name: vLLM
      storageUri: oci://quay.io/rh-ee-allausas/huggingface:latest
      args:
        - --dtype=half
      resources:
        limits:
          nvidia.com/gpu: 1
        requests:
          nvidia.com/gpu: 1
  1. Check the imagePullSecret from the pod that gets created
  2. Edit the Inference Service and change the imagePullSecret
  3. Check the imagePullSecret from the new pod that gets created and verify that it matches
  • Logs

Special notes for your reviewer:

  1. Please confirm that if this PR changes any image versions, then that's the sole change this PR makes.

Checklist:

  • Have you added unit/e2e tests that prove your fix is effective or that this feature works?
  • Has code been commented, particularly in hard-to-understand areas?

Release note:


Re-running failed tests

  • /rerun-all - rerun all failed workflows.
  • /rerun-workflow <workflow name> - rerun a specific failed workflow. Only one workflow name can be specified. Multiple /rerun-workflow commands are allowed per comment.

Copy link

openshift-ci bot commented Mar 10, 2025

Skipping CI for Draft Pull Request.
If you want CI signal for your change, please convert it to an actual PR.
You can still manually trigger a test run with /test all

@andresllh andresllh force-pushed the feature/RHOAIENG-19717-replacing-pull-secre-persists-when-using-modelcar branch from 4ca5a36 to 93a74dd Compare March 11, 2025 15:57
@andresllh andresllh marked this pull request as ready for review March 11, 2025 15:57
@andresllh
Copy link
Member Author

@andresllh andresllh changed the title Pod now has correct imagepull secret when updated in raw deployment [RHOAIENG-19717] Pod now has correct imagepull secret when updated in raw deployment Mar 11, 2025
@andresllh andresllh force-pushed the feature/RHOAIENG-19717-replacing-pull-secre-persists-when-using-modelcar branch 2 times, most recently from c00967a to 181c53f Compare March 12, 2025 15:38
@andresllh andresllh force-pushed the feature/RHOAIENG-19717-replacing-pull-secre-persists-when-using-modelcar branch from 017bd4b to a6d925d Compare March 12, 2025 22:00
@israel-hdez
Copy link

/retest

@andresllh
Copy link
Member Author

/retest

@andresllh
Copy link
Member Author

/rerun-all

Signed-off-by: Andres Llausas <[email protected]>

Signed-off-by: Andres Llausas <[email protected]>
@andresllh andresllh force-pushed the feature/RHOAIENG-19717-replacing-pull-secre-persists-when-using-modelcar branch from f2f8704 to 1d50681 Compare March 13, 2025 16:25
Copy link

openshift-ci bot commented Mar 13, 2025

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: andresllh, brettmthompson

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Needs approval from an approver in each of these files:
  • OWNERS [andresllh,brettmthompson]

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
Status: New/Backlog
Development

Successfully merging this pull request may close these issues.

3 participants