// AI NATIVE STACK

AI Native › AI Native Infra › Orchestration and Scheduling › Kubernetes

LONG GUIDE · AI-NATIVE · intermediate · 13 min read · v1.36

Kubernetes for AI — the substrate everything else runs on.

orchestration ai-native kubernetes gpu scheduling

TL;DR — Kubernetes is the operating system of the AI stack: it schedules pods onto nodes, keeps them alive, and now — since Dynamic Resource Allocation (DRA) went GA in v1.34 — allocates GPUs and TPUs as first-class resources. Every other tool in this section (Volcano, Kueue, KubeRay) builds on its scheduler. Learn the core objects and how GPU scheduling works, and the rest of the infra layer makes sense.

What it is

Kubernetes (K8s) is the open-source container orchestrator: you declare desired state (run N copies of this container, expose this port, give it this much GPU), and the control plane continuously reconciles reality toward it. It handles scheduling, self-healing, scaling, networking, and storage across a cluster of machines.

In the AI Native landscape it's the root of AI Native Infra › Orchestration and Scheduling — and effectively the foundation the whole group stands on. Per CNCF data, ~66% of organizations already run generative-AI inference on Kubernetes.

Why AI runs on it

AI workloads are bursty, expensive, and hardware-hungry. Training jobs need many GPUs scheduled together; inference needs autoscaling and fast restarts; both need to pack scarce, costly accelerators efficiently. Kubernetes gives you one declarative control plane for all of it — and a portable one, so the same manifests run on any cloud or on-prem instead of a proprietary GPU scheduler per vendor.

Core objects (the AI-relevant ones)

ObjectRole
PodSmallest unit — one or more containers sharing network/storage. Your model server runs here.
DeploymentKeeps N replicas of a stateless pod running; rolling updates. Good for inference servers.
Job / Indexed JobRun-to-completion work — a training or batch run.
Service / GatewayStable network endpoint + load balancing in front of pods.
schedulerDecides which node each pod lands on — the piece AI schedulers extend.

GPU scheduling — the hard part

Historically GPUs were exposed through the device plugin API as opaque countable resources (nvidia.com/gpu: 1) — crude: no sharing, no topology awareness, no fractional or multi-instance allocation.

Dynamic Resource Allocation (DRA) replaces that. It went GA in Kubernetes v1.34 (March 2026), and lets workloads request devices with rich constraints — specific GPU models, memory, topology, MIG partitions — via declarative ResourceClaims. NVIDIA donated its DRA GPU driver and Google its TPU driver to the community, so accelerator scheduling now lives in the K8s control plane instead of per-cloud tooling.

Pod +ResourceClaim scheduler+ DRA drivertopology aware node: full GPU node: MIG slice node: TPU

Fig 1 — DRA: pods claim accelerators with constraints; the scheduler matches them to the right device.

Where it's heading

The AI direction is now explicit in the project. v1.35 launched the Kubernetes AI Conformance program — a standard for what an "AI-ready" cluster must support. v1.36 added workload-aware scheduling, bringing DRA into the Workload API and driving integration with KubeRay, so jobs can declaratively request specific GPU types and topologies. The trend line: accelerator-first scheduling is becoming native, not bolted on.

Quick start

Spin up a throwaway local cluster and inspect it:

kind create cluster                 # or minikube start
kubectl get nodes
kubectl create deployment web --image=nginx --replicas=2
kubectl get pods -w

Requesting a GPU is a field on the pod spec — classically a resource limit, or a resourceClaims entry under DRA:

resources:
  limits:
    nvidia.com/gpu: 1        # device-plugin style (still common)

When to use, and what builds on it

Use it whenever AI workloads outgrow a single box: multiple models, shared GPUs, autoscaling, or team-level quotas. It's the default substrate of the AI Native Infra layer.

The default scheduler is great for services but weak for batch/gang-scheduled training. That gap is why the rest of this category exists: Volcano and YuniKorn add batch/gang scheduling, Kueue adds job queueing and quotas, and KubeRay runs Ray clusters on top.

heads up Don't hand-roll a cluster to learn — use a managed offering (EKS/GKE/AKS) or kind locally. And don't expect the stock scheduler to gang-schedule a distributed training job correctly; that's exactly what Volcano/Kueue are for.

References

Extra reads

Verified against kubernetes.io docs and CNCF sources, May 2026. DRA is GA as of v1.34; latest covered release v1.36.

Depth: production guideFreshness review: 10 July 2026Category: Orchestration and Scheduling

Where Kubernetes fits: the mental model

Kubernetes is a compute or serving layer that places expensive AI workloads and turns models into reliable runtime services. The useful question is not simply “can it run the demo?” It is whether the component gives your team a clear ownership boundary, predictable failure behavior, and enough evidence to operate changes safely. Treat it as one replaceable layer in a larger system rather than letting it quietly become the architecture.

Start by drawing the request and data path. Mark where untrusted input enters, where identity is checked, where durable state changes, and where retries can repeat work. That diagram tells you which guarantees belong to Kubernetes and which still belong to your application, platform, cloud provider, or database. The distinction matters during incidents: a healthy process is not proof that the end-to-end task is correct.

Model + workload spec
Queue or API
Kubernetes runtime
CPU/GPU workers
Results + utilization
A reference flow, not a mandatory topology. Put authentication before the trust boundary, persist authoritative state outside transient workers, and attach one correlation ID across all five stages.
Architecture noteConfiguration and execution paths often fail independently. Document what continues working if Kubernetes cannot be configured or invoked, and what stops when one of its dependencies is unavailable.

Core concepts you should understand first

The vocabulary below is more important than any single SDK method. It lets application engineers, platform engineers, security reviewers, and incident responders describe the same system without confusing a framework feature with an end-to-end guarantee.

ConceptMeaning in this layerDesign question
Resource requestCapacity reserved for placement; inaccurate requests create pending work or stranded accelerators.Write down how Kubernetes represents or enforces this before production.
TopologyNUMA, PCIe, NVLink, rack, and zone relationships that can dominate distributed workload performance.Write down how Kubernetes represents or enforces this before production.
BatchingCombining requests or examples to improve accelerator utilization at the cost of queueing latency.Write down how Kubernetes represents or enforces this before production.
ParallelismSplitting model weights, pipeline stages, data, or requests across devices and processes.Write down how Kubernetes represents or enforces this before production.
PreemptionReclaiming resources from lower-priority work; safe jobs need checkpoint and resume semantics.Write down how Kubernetes represents or enforces this before production.
Cold startTime to schedule, pull images, load weights, compile kernels, and become ready.Write down how Kubernetes represents or enforces this before production.

From quick start to a production deployment

The earlier quick start proves that the package or service runs. Production readiness is a different exercise. Build the smallest vertical slice that crosses every real boundary—identity, network, persistence, upstream provider, telemetry, and rollback—before broadening the feature set.

  1. Pin the compatibility envelope. Record the Kubernetes release, language/runtime version, client SDK version, model or backend version, and—where applicable—Kubernetes API or driver requirements. Use a lock file, immutable image digest, or chart version; floating “latest” tags prevent repeatable rollback.
  2. Define contracts before configuration. Write the accepted input, successful output, error classes, timeout, idempotency behavior, and ownership of durable state. Validate at the boundary so corrupt work fails early instead of surfacing deep in a workflow.
  3. Create separate development, staging, and production identities. Do not copy a broad personal API key into every environment. Prefer workload identity or short-lived credentials, scope access by tenant and operation, and verify denial cases as part of deployment.
  4. Add bounded failure behavior. Every remote call needs a deadline. Retry only transient, idempotent operations with exponential backoff and jitter. Set concurrency and queue limits so an upstream slowdown becomes controlled backpressure rather than resource exhaustion.
  5. Instrument the complete path. Emit a correlation ID, component and release version, duration, outcome, retry count, and resource or cost dimensions. Keep sensitive prompt, document, and credential values out of ordinary logs.
  6. Ship through a reversible rollout. Run compatibility and regression tests, deploy to a canary or isolated workload, compare service-level indicators, then increase exposure. Preserve the previous artifact and configuration until rollback has been exercised.
Practical tipBuild one deliberately failing test for each boundary: invalid credentials, unreachable backend, malformed input, timeout, exhausted quota, and an incompatible version. A green happy-path demo otherwise proves very little.

Production configuration checklist

  • Pin artifacts by version and, where possible, digest.
  • Set connect, request, and total workflow deadlines.
  • Bound retries, concurrency, queue length, and payload size.
  • Separate read-only operations from mutations.
  • Use idempotency keys for replayable mutations.
  • Persist canonical state outside disposable workers.
  • Encrypt traffic and durable data with managed keys.
  • Redact secrets, tokens, prompts, and personal data.
  • Apply per-tenant quotas and authorization filters.
  • Expose readiness separately from process liveness.
  • Back up metadata and test restore, not only backup.
  • Document owner, escalation path, RPO, and RTO.
WarningNever interpret a successful API response as proof of correct business behavior. Validate the returned schema and policy, record the side effect, and reconcile critical outcomes against the system of record.

Failure modes and the response you should design

Failure modeWhat you observeEngineering response
Unschedulable gangSome workers start but the full distributed job cannot fit.Use gang scheduling or admission so the group starts together.
Topology penaltyWorkers span slow links or cross zones.Express topology constraints and measure collective communication.
Memory fragmentationFree memory exists but a large allocation fails.Tune allocation/batching and recycle workers under controlled policy.
Driver mismatchHost driver, runtime, CUDA, and framework are incompatible.Qualify an immutable compatibility matrix before rollout.
Cold-start spikeScale-out misses the latency objective.Pre-pull images, cache weights, keep warm capacity, and measure each phase.
Noisy neighborOne workload consumes shared network, CPU, or storage.Apply quotas, priorities, isolation, and per-tenant saturation metrics.

Turn these rows into runbook entries with an alert, first diagnostic query, safe mitigation, and escalation owner. Test at least one failure in staging every release cycle. If the system cannot be forced into a failure safely, it is usually not yet observable or isolated enough.

Security, privacy, and tenant isolation

Place Kubernetes in a threat model, not just an architecture diagram. Identify human users, workload identities, administrators, upstream services, model providers, artifact registries, and data stores. For each edge, document authentication, authorization, encryption, audit evidence, and the consequence of credential compromise.

Apply least privilege at the operation and resource level. A component that only retrieves documents should not be able to delete the index; an evaluation worker should not inherit production mutation credentials; a model-serving pod should not need cluster-admin. In multi-tenant systems, enforce the tenant boundary before retrieval or execution and include tenant identity in quotas and audit events. Never rely on a prompt instruction, namespace string supplied by the client, or UI filtering as authorization.

Decide what data is permitted in telemetry. Prompts, retrieved chunks, tool arguments, model responses, notebooks, and traces can contain secrets or regulated data. Redact close to collection, keep high-sensitivity payload capture opt-in, encrypt exports, restrict support access, and give each class an explicit retention period. Verify deletion across caches, replicas, indexes, backups, and derived evaluation datasets.

Observability and service-level objectives

A useful dashboard follows the user-visible unit of work and then decomposes it by component, release, tenant tier, backend, and failure class. Start with these signals for Kubernetes:

  • accelerator utilization and memory — graph both rate and distribution, then compare with the previous release and traffic mix.
  • queue wait and pending duration — graph both rate and distribution, then compare with the previous release and traffic mix.
  • time to first token or first result — graph both rate and distribution, then compare with the previous release and traffic mix.
  • throughput per device — graph both rate and distribution, then compare with the previous release and traffic mix.
  • cold-start and model-load time — graph both rate and distribution, then compare with the previous release and traffic mix.
  • failure, eviction, and preemption rate — graph both rate and distribution, then compare with the previous release and traffic mix.

Choose an SLO at the boundary your users experience, such as “99% of accepted tasks complete correctly within five minutes over 28 days.” Availability alone is insufficient for AI systems because a fast but incorrect or ungrounded result is still a failure. Pair latency and completion objectives with a reviewed quality or policy indicator. Page on rapid error-budget burn; use tickets for slow capacity trends.

Testing and release strategy

Use four layers. Unit tests cover deterministic adapters, schemas, policy, and error mapping without a live external service. Contract tests exercise the pinned integration boundary—API, CLI, SDK, protocol, or ephemeral service—and verify its exact surface. Scenario tests exercise representative end-to-end cases, including permissions and state. Load and resilience tests establish saturation, queue behavior, retry amplification, and recovery after dependency loss.

Keep a small blocking suite for every commit and a broader scheduled suite for expensive or probabilistic checks. Store results with the application version, Kubernetes version, configuration hash, model/backend version, dataset version, and random seed. A score without that provenance cannot explain a regression. Before upgrading, read the migration notes, run both versions against the same replay set, and explicitly test rollback across any schema or state transition.

How to decide whether Kubernetes is the right tool

QuestionEvidence to collectRed flag
Does it remove a real constraint?A measured bottleneck, missing guarantee, or repeated custom component.Adoption is based only on a demo or feature count.
Can the team operate it?Named owner, upgrade path, alerts, runbooks, backup, restore, and on-call skills.Only the original prototype author understands failure behavior.
Is the interface portable?Your domain contracts wrap vendor-specific APIs; data and state have an export path.Business objects are inseparable from framework internals.
Does it meet the envelope?Benchmarks using your payloads, concurrency, topology, quality bar, and cost model.Published benchmark hardware or workload does not resemble production.
Is failure affordable?Tested degraded mode, bounded blast radius, rollback, RPO, and RTO.A component outage blocks unrelated tenants or irreversible actions.

Prefer the smallest component that satisfies the required guarantees. A provider SDK, relational table, background job, or standard Kubernetes controller is often better than another platform when the workload is small and predictable. Choose Kubernetes when its specific abstraction removes sustained engineering work and the team is willing to own its lifecycle.

A focused 90-minute validation lab

  1. Minutes 0–15: run the documented quick start in a disposable environment with pinned dependencies. Save the exact commands and a known-good input/output fixture.
  2. Minutes 15–35: replace the toy input with one representative case from your system. Add schema validation, a deadline, and a correlation ID.
  3. Minutes 35–55: force invalid credentials, a timeout, malformed input, and one dependency failure. Record the observed errors and whether retries are safe.
  4. Minutes 55–75: run a small concurrency test and capture latency, throughput, saturation, and unit cost. Do not extrapolate beyond the tested range.
  5. Minutes 75–90: write the adoption decision: required guarantees met, open risks, owner, next experiment, and the simplest credible alternative.

Frequently asked questions

Should we standardize on Kubernetes for every team?

Standardize the contracts, telemetry, security controls, and release evidence first. Standardizing one implementation is useful only when workloads share requirements and a platform team owns upgrades and support.

Can we use the hosted version and skip operations work?

Hosted service removes part of the control-plane burden, not architecture ownership. You still own identity, tenant isolation, data classification, quotas, dependency failure, observability, export, and an exit plan.

What should be pinned for reproducibility?

Pin the tool/server, client SDK, runtime, configuration, model or backend, container image digest, and test dataset. Record these values with every benchmark and evaluation result.

When is a proof of concept ready for production?

After representative success and failure tests pass, sensitive data paths are approved, limits and SLOs are defined, telemetry and runbooks exist, restore or rollback is rehearsed, and an accountable owner accepts the remaining risk.

Official sources and freshness

This guide was reviewed for architecture and operational guidance on 10 July 2026. Projects evolve quickly: verify installation syntax, supported versions, feature maturity, and upgrade notes against the exact release you deploy.

← AI Native Stack
© cvam — written in plaintext, served warm