docs(evidence): attest gb300-generic-ubuntu-training recipe-evidence v3 - #2851
Conversation
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Repository: NVIDIA/aicr/.coderabbit.yaml Review profile: ASSERTIVE Plan: Enterprise Run ID: 📒 Files selected for processing (1)
Included review availability: Your plan provides up to 12 included reviews per hour; 11 remain after this review. 📝 WalkthroughWalkthroughThe change adds a community signer entry to the evidence allowlist. It also adds attestation metadata for the Priority: ⬇️ Low Estimated code review effort: 1 (Trivial) | ~5 minutes Change: Other Suggested reviewers: 🚥 Pre-merge checks | ✅ 4✅ Passed checks (4 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
Recipe evidence checkProtected recipesRecipes with committed evidence (
This gate is warning-only and never blocks merge. See ADR-007 for the trust model. |
Coverage Report ✅
Coverage BadgeNo Go source files changed in this PR. |
58b182f to
4b2ca21
Compare
Signed-off-by: Atif Mahmood <atif1996@users.noreply.github.com>
4b2ca21 to
498dde6
Compare
Summary
Add the signed recipe-evidence v3 attestation for
gb300-generic-ubuntu-training, collected on a bare-metal GB300 NVL72 cluster, and allowlist the signer source it was published under.Motivation / Context
gb300-generic-ubuntu-training(#2568) shipped without committed evidence: the run that qualified it predated the leaf rename, so its bundle was never pointed to. This is the first pointer for the leaf, produced against currentmainso the content-only recipe digest (173b1baf…,mainatebddbb2adwith nodewright-operator v0.19.0 from #2829) matches what the evidence gate computes from the overlay.Fixes: N/A
Related: #2568, #2813, #2829, #2846, #2847, #2848
Type of Change
Component(s) Affected
recipes/evidence/(pointer +allowlist.yaml)Implementation Notes
recipes/evidence/gb300-generic-ubuntu-training/728b071aed7124418b1fa9c7f0521e24/sha256-74c42dc3….yaml, signed keyless (Fulcio/Rekor public-good, Rekor index 116117498) viaaicr evidence publish; bundle atghcr.io/atif1996/aicr-evidence:gb300-generic-ubuntu-training-6d21f4209def(public package). A first run against pre-fix(validator): read NodeWright by discovery; pin nodewright v0.19.0 #2829mainattested1f87a241…and went stale on rebase; the cluster was re-bundled (nodewright-operator v0.17.1 → v0.19.0 viadeploy.sh), re-validated and re-published against the current pin.728b071aed7124418b1fa9c7f0521e24is a new signer source (GitHub OAuth, noreply identity), added undercommunitywithlabel: atif1996— the same class as the existing OAuth entries.:edgeimage (AICR_VALIDATOR_IMAGE_TAG=edge, built fromc35f47577) because:latestpredates fix(validator): suppress dra-node-labeler health check when eviction not opted in #2847 and failsexpected-resourceson the not-opted-indra-node-labeler(expected-resources fails NOT_FOUND on dra-node-labeler when DRA eviction not opted in (#2813) #2846). The evidence attests recipe content and validator results; the image tag is not part of the digest.--node-selector nvidia.com/gpu.clique=<id>to the two GPU nodes sharing one NVLink clique. The cluster's third GPU node sits in a different rack/clique; without the selector NCCL cannot form the NVLS tree across cliques and falls back to sockets (0.1–0.4 GB/s, then the 30m budget). The check itself could group bygpu.cliqueor fail fast — noted for a follow-up issue.Testing
Cluster: bare-metal GB300 NVL72, Kubernetes v1.35.3, Ubuntu 24.04 on a 64k-page
nvidiakernel, 2 system + 3 GPU nodes (4 GPUs each), skyhooktuning3/3 complete before the driver rolled out.Risk Assessment
Rollout notes: N/A.
Checklist
make testwith-race) — N/A for a pointer;recipes/...package tests passmake lint) —yamllintclean on the changed filesgit commit -S -s)