Skip to content

Releases: NVIDIA/aicr

v0.22.0

Choose a tag to compare

@github-actions github-actions released this 21 Sep 21:02
Immutable release. Only release title and notes can be modified.
v0.22.0
7e3078d

As our last v0 release before v1 (scheduled on October 5th), this release focuses on component upgrade safety, validation hardening, and bundler and deployer reliability, landing alongside new platform and accelerator coverage and the last phase of ADR-022 described apiVersion migration that v1.0.0 will complete.

Highlights

Component Upgrade Safety - v1 commits AICR to safe component upgrades, and this release adds additional capabilities to that mechanism. ADR-021 defined a transition record, a per-component, per-version-boundary statement of safe, manual, or blocked, with the steps and the evidence that backs it, and a fail-closed loader that reports unknown rather than guessing. The new aicr upgrade-check command reads those records and reports the verdict for the boundary you are about to cross. Records also live beside the component they describe, so the obligation renews on each pin bump rather than decaying.

Validation Hardening - Every check that v1 will stand behind has to fail for the right reason. The DRA support check now gains an MNNVL IMEX channel subtest. The NCCL benchmark is derived from the shipped TCPXO runtime rather than a separately pinned image, with AICR_NCCL_RUNTIME_IMAGE available where a site needs its own. The GB200 NET preflight is now driver-version-aware, unsupported Hyperdisk types are rejected on a4x nodes, AKS cluster autoscaling is validated, NodeWright is read by discovery, and Job deadlines get headroom over the check budget so a slow check fails as a check rather than a timeout.

Bundler and Deployer Reliability — The bundle layout is a frozen v1 surface, so what it emits has to be right on every deployer, not just the common one. bundle-info.yaml now records the deployer and layout that produced the bundle. recipe.yaml is written for every deployer, not only Helm; ownsCRDs is honored on the helm and helmfile deployers; helm connection flags are translated for the CRD step, with the flag value redacted when the step rejects it; and dry-run no longer previews a stale cached chart archive.

Recipes and Coverage

  • k0s joins the supported services, with a validated H200 training leaf, a setup guide, and Preview coordinate coverage
  • GKE gains a GB200 (a4X) recipe with NVLS NCCL validation, and a torch-distributed-tcpxo runtime with the network mapping TCPXO requires
  • Five new training-kubeflow leaves, each with its evidence link kept intact
  • GB300 gets node tuning enabled and bumped NodeWright packages, plus its own NCCL thresholds
  • Kueue moves to 0.19.3 and kai-scheduler to v0.16.9

Other Improvements

  • Five opt-in NVSentinel mixins widen what a cluster reports about itself: audit logging and tracing, a Kubernetes Object Monitor, a preflight mixin, Node Problem Detector conditions consumed as NVSentinel signal, and NIC and fabric fault detection on Mellanox platforms.
  • SLSA provenance is attested per platform manifest; recipe digests are content-only via PredicateTypeV3; evidence fails closed on a mutable validator image tag; and overlay recipe digests are canonicalized so the same recipe hashes the same way
  • New signed evidence for GB300 EKS training and inference, VR200 training-kubeflow, and the H100 AKS training-kubeflow and inference-dynamo coordinates
  • A recipe can pin deployment identity so registry defaults can move underneath it; a profile value can tighten a composed constraint; and a direct -r overlay whose mixins were not applied is rejected rather than silently under-resolved

Thanks to @ArangoGutierrez, @atif1996, @ayuskauskas, @chris320211, @coffeepac, @lockwobr, @mikecook, @mohityadav8, @njhensley, @ramessesii2, @rorajani, @srao-nv, @sylvesterkaczmarek, @varmesh, @vineeth-bandi, @yuanchen8911, and @mchmarny.

Changelog

New Features

Bug Fixes

Read more

v0.21.1

Choose a tag to compare

@github-actions github-actions released this 09 Sep 16:33
Immutable release. Only release title and notes can be modified.
v0.21.1
41bd4bb

Changelog

Bug Fixes

Other Tasks

  • 41bd4bb: chore(ci): drop the demo deploy job from the release pipeline (@mchmarny)

v0.21.0

Choose a tag to compare

@github-actions github-actions released this 08 Sep 23:57
Immutable release. Only release title and notes can be modified.
v0.21.0
36f52ec

This release focuses on API surface hardening, GB300 and Vera Rubin support, major GPU Operator and Dynamo version bumps, and Kubernetes 1.37 with broad validation and bundler hardening.

Highlights

New Hardware and Platform Support - GB300 lands on both the cloud and bare-metal (NCP) paths: a generic gb300-generic-ubuntu-training recipe for self-managed Kubernetes (#2568), EKS training and inference recipes (#2382) with signed evidence (#2410), and a Slurm variant (#2544). Vera Rubin (VR200) arrives as preview overlays on RKE2 (#2520), with published evidence (#2573).

Component Upgrades - GPU Operator moves to v26.7.0 and the DRA driver to 0.5.0, with a workaround for the ComputeDomain CRD conflict v26.7.0 introduces and the driver held at 580 (#2439). dynamo-platform moves to 1.4.2: the request plane defaults to TCP and KV events to ZMQ, so bundled NATS is no longer deployed - re-enabling it is opt-in for standing clusters. The same bump takes Grove to v0.1.0-alpha.12 and picks up a NIXL loader-path fix (#1983).

Recipes and Coverage

  • GKE self-installed driver pools now carry the driver in the bundle: gpuStack=bundle-installer replaces driver-installer, pinning the version in the recipe so upgrades roll with the bundle (#2360)
  • OKE gains a gpuStack profile (#2355), with RDMA fabric wiring for L40S RoCE and GB200 InfiniBand landing alongside it (#2356)
  • An l40-any accelerator overlay and a declared RTX PRO 6000 Server Edition driver floor
  • Per-value readiness constraints for configuration profiles

Validation Hardening - Every NCCL benchmark run gets its own namespace, and cleanup fails the run when that namespace will not terminate. The validator rejects an incompatible StorageClass before creating the model-cache PVC, tolerates tainted nodes with a wider Trainer readiness timeout, retries transient reads while polling gang-scheduling pods, and resolves the GPU-node universe label per service. DaemonSet checks are guarded against stale rollouts, and concurrent snapshot runs no longer collide.

API Surface Hardening - The four surfaces AICR freezes for v1 - REST, Go SDK, CLI, and artifact schemas - are now each held to a committed baseline. The profile-aware /v2 REST family folds into a single /v1 (#2112) - a pre-adoption restructure with no consumers to notify. JSON Schemas for the v1 artifacts are published and gated, the per-deployer bundle layout is frozen, and artifacts read both their alpha apiVersion and the maturity-appropriate target from ADR-022. pkg/client/v1 is now the only path the CLI and server take into business logic, enforced by an architecture test. Backing all of it: gates that replay documented REST examples and CLI invocations against real handlers and assert the spec and server agree on routes.

Bundler and Deployer Reliability - A readiness gate landed for the Helm network-operator, DRA eviction is wired for GPU driver upgrades behind an opt-in node label, and OCP gates the GPU Operator on network readiness. Bundles missing a required node selector now fail instead of shipping, generated wrappers are stamped with both the AICR and payload versions, and Argo CD is forced to replace the readiness-gate Job on upgrade.

Other Improvements - Kubernetes moves to 1.37: recipe floors are raised to clear the DRA chart's kubeVersion, agentgateway moves to v1.5.0 for the tightened CRD cost budget, client libraries are on v0.37.0, and Kind and KWOK lanes run 1.37 with Argo CD server-side diff. Toolchain moves to Go 1.27.1.
CycloneDX SBOMs and OpenVEX documents are published per platform, and vendor/ is gone in favor of Go proxy resolution verified reproducible on every push to main (ADR-023), and ADR-025 proposes an NVIDIA Cluster Readiness Engine component.

Thanks to @atif1996, @ayuskauskas, @ezhang3333, @framsouza, @giuliocalzo, @haarchri, @Kevin-Hawkins, @lalitadithya, @lockwobr, @MDhamani, @mikecook, @mohityadav8, @njhensley, @ntheanh201, @rorajani, @srao-nv, @varmesh, @xdu31, @yankay, @yuanchen8911, and @mchmarny.

Changelog

New Features

Bug Fixes

Read more

v0.20.0

Choose a tag to compare

@github-actions github-actions released this 24 Aug 18:11
Immutable release. Only release title and notes can be modified.
v0.20.0
b8a6ead

This release focuses on SDK completeness, digest-pinned OCI recipes, runtime AI inventory, and validation and bundler reliability.

Highlights

Complete SDK Contract - Users can now verify and sign artifacts through the pkg/client/v1 facade. Compiled examples ship with the package, the CLI and server signing paths use the facade, and API compatibility remains gated.

Digest-Pinned OCI Recipe Sources - SDK consumers can load digest-pinned recipe catalogs from OCI registries. Each OCI-backed client uses a private workspace cleaned by Client.Close().

Runtime AI Inventory (ADR-019) - AICR adds optional k8s-aibom v1.3.0 to generate CycloneDX ML-BOMs for selected namespaces, with stock GKE adoption and CRD storage-version health checks.

Validation Hardening - GKE recipes now fail during deployment when required GPU NIC networks are missing, GPU host-driver floors are enforced, and build suffixes are compared correctly. Kubeflow Trainer lifecycle follows the recipe, partial installs roll back, and controller waits use the discovered name. Deadline-killed validators report the actual failure, while evidence verdicts require cleanup, avoid over-claiming, and clarify operator SKIP and Trainer namespace semantics.

Bundler & Deployer Reliability - Flux upgrades can replace component-owned CRDs, empty sources/ directories are omitted, and transient Helm index failures retry automatically. NVSentinel misconfigurations and unsupported --dynamic use with local-chart argocd-helm components now fail closed. Mixed vendored components receive a tracked -post release, and bundle vendoring is hardened against SSRF and resource exhaustion.

Recipes & Components

  • NVSentinel v1.20.0, configured for AKS, GKE-COS, OKE, and Kind
  • topograph moved to v1.0.0 across recipes; GAIE v1.5.0 CRDs vendored for agentgateway
  • Slinky/Slurm gained configurable Enroot settings with epilog/prolog examples
  • Nodewright tuning resources changed to whole-number equivalents

Other Improvements - nodes is now metadata-only for overlay selection while --nodes still satisfies CLI specificity checks. NIM gains a pinned, credential-free CNCF AI conformance example, and the toolchain moves to Go 1.27.

Thanks to @ayuskauskas, @bmcadams1, @Dhirenderchoudhary, @framsouza, @kaynetu, @Kevin-Hawkins, @lalitadithya, @lockwobr, @njhensley, @pdmack, @ravisoundar, @rorajani, @srao-nv, @TerryHowe, @tjrasche, @varmesh, @yuanchen8911, and @mchmarny.

Changelog

New Features

Bug Fixes

Other Tasks

  • 49ad450: chore(deps): Update dependency go to v1.26.6 (#2208) (@github-actions[bot])
  • b82c438: c...
Read more

v0.19.0

Choose a tag to compare

@github-actions github-actions released this 10 Aug 19:42
Immutable release. Only release title and notes can be modified.
v0.19.0
f1f6346

This release focuses on GPU stack profiles, broader recipe and platform coverage, signed release provenance, and validation hardening.

Highlights

GPU Stack Profiles (ADR-015) - As AICR covers more use-cases, one criteria combination increasingly maps to more than one valid infrastructure configuration. The only prior way to express the second was a bundle-time --set override that validation could not see, so aicr validate checked the stock configuration against a cluster running a different one. Recipes now declare a named gpuStack profile naming who owns a layer of the stack, the cloud service or the GPU Operator. One value is selected at generation time via aicr recipe --profile gpuStack=<value> or the declared default, hydrated into recipe.yaml, and its owned paths are locked against diverging overrides at bundle and mirror time. Selection is explicit intent, never inferred. So for example, the AKS pool reading supplied by aicr snapshot --aks-gpu-pools qualifies a selection and fails generation closed on mismatch. The mechanism landed in v0.18 with no adopter; AKS and the full GKE family have since converted. It is service-agnostic, so OKE addons and OCP operators extend it without new schema.

Supply Chain & Provenance - Release metadata and the aiperf-bench third-party source are published as signed OCI referrers alongside release artifacts, the latest release is re-verified daily, and Rekor identity monitoring gained a resumable scan that catches up large backlogs. aicr verify can be driven from AICRConfig (spec.verify), and POST /v1/bundle supports non-interactive attestation. A registry-inventory egress gate bounds which registries the supply chain may reach.

Validation Hardening - A pass now has to be earned. The validator fails closed on unmatched declared checks and on capability checks whose declared dependencies are missing, rolls back cluster-admin RBAC when prep fails, and re-establishes the Job watch after an apiserver idle-stream closure instead of reporting a false failure. Cordoned GPU and RDMA nodes are disclosed rather than silently skipped, gang-scheduling and webhook conformance tests are now behavioral, and six operator-owning health checks assert CRD Established=True. The evidence dashboard at validation.aicr.run gained multiple UX improvements, and validator outcomes carry redaction-safe CTRF extra data.

SDK Contract - The exported surface of pkg/client/v1 is pinned and gated by a compatibility check, alias and semver contracts are reconciled, and the selector API is context-aware with snapshot Jobs routed through the facade.

Recipes & Evidence

  • AKS H100 Ubuntu training and inference (Dynamo) recipe evidence
  • AKS training and inference Kubernetes floors aligned to the DRA-GA >= 1.34 rationale
  • Slurm/Slinky gains accounting ownership modes and shared RWX storage for home and data
  • Network Operator default bumped to v26.4.1; EKS GB200 enrolled in the nightly UAT
  • OpenShift Support - OCP-compatible components for cert-manager, prometheus-adapter, nvidia-dra-driver-gpu, and k8s-nim-operator, argocd-helm bundling now covers the OCP path with a pinned error contract, and recipes enabling both gpu-operator and gpu-operator-ocp are rejected at resolution

Other Improvements

  • aicr snapshot fails closed on unusable --snapshot input; the collector fails loud when Kubernetes collection is canceled mid-propagation and emits lossless label/taint readings
  • GET /v1/query requires a selector, versionless legacy bundle recipes are accepted, and duplicate ComponentRef names are rejected
  • Constraint measurement paths are validated at recipe load time; aicr validate --fail-on-error scoping and its exit-code and CTRF-suite semantics are documented
  • The BOM extracts nested operator images; the aiperf-bench runtime moved to NVIDIA distroless Python with pip removed
  • Readiness checks run in-process via pkg/chainsaw (promoted from validators/chainsaw), and the external chainsaw binary is gone from the validator images

Thanks to @andrewwhitecdw, @atif1996, @framsouza, @gat786, @kaynetu, @krtadev, @lockwobr, @mohityadav8, @njhensley, @rorajani, @rsd-darshan, @tjrasche, @varmesh, @yuanchen8911, and @mchmarny.

Changelog

New Features

Bug Fixes

Read more

v0.18.0

Choose a tag to compare

@github-actions github-actions released this 23 Jul 17:55
Immutable release. Only release title and notes can be modified.
v0.18.0
1439f2f

This release focuses on expanded Slurm-on-Kubernetes support, air-gapped signing and verification, parallel bundle deployment, and first-class GPU driver ownership.

Highlights

Slurm on Kubernetes

  • AKS H100 Slinky/Slurm recipe with Enroot/Pyxis support and Gres/GPU configuration
  • New topograph component with the slinky engine for topology-aware scheduling
  • Snapshot support for Slinky Slurm and the MariaDB operator
  • Functional Kueue with default quota CRs

Recipes & Coverage

  • Kubeflow training overlay for RTX PRO 6000 on EKS, plus RTX PRO 6000 inference (Dynamo) evidence
  • VR200 training and inference (Dynamo) recipe evidence on RKE2
  • AKS H100 driver-only and managed-driver recipe evidence
  • Recipe resolution now enforces stated-criteria coverage, failing fast when a recipe cannot satisfy its declared criteria

Air-Gapped Supply Chain - Bundles can now be signed and verified entirely offline: aicr bundle accepts --tlog-upload=false to skip transparency-log upload, and verification gains --insecure-ignore-tlog for disconnected environments. KMS-backed signing also adds HashiCorp Vault support. Verification also got stricter - bundles now verify as fully self-contained, air-gapped artifacts, recipe.yaml is covered by bundle checksums, and AICR now runs its own Rekor v2 identity monitoring for the release signer.

Parallel Deployment - The deployer now deploys independent components in parallel, following the dependency graph so unrelated components no longer wait on each other.

GPU Driver Ownership - Driver management is now an explicit contract: recipes auto-detect a pre-installed GPU driver from the snapshot, AKS defaults to the Azure-managed GPU driver profile, and a bundle-time coherence check catches conflicting driver-ownership configuration before deploy.

Validation & Evidence - The validator gains a configurable inference-perf router mode, recipe-supplied NCCL benchmark runtime via --data, a uniform-RDMA-fabric readiness gate, GPU readiness gated on runtime-required taint clearance, and fail-fast on degraded GPU nodes. The evidence dashboard at validation.aicr.run gains a cross-version combined view with deep links from recipe health.

Other Improvements

  • SDK supports custom kubeconfig paths for validation jobs, and aicr validate --kubeconfig now selects the target cluster end-to-end
  • aicr diff compares structured snapshot fields
  • GPU Operator upgraded to v26.3.3 with driver 580.173.02; nvidia-tuned bumped to 0.3.2
  • AICR container images are now based on nvcr.io/nvidia/distroless/static

Thanks to @ArangoGutierrez, @atif1996, @ayuskauskas, @kaynetu, @lockwobr, @mohityadav8, @njhensley, @tjrasche, @xdu31, @yuanchen8911, and @mchmarny.

Changelog

New Features

Bug Fixes

Other Tasks

Read more

v0.17.0

Choose a tag to compare

@github-actions github-actions released this 14 Jul 00:37
Immutable release. Only release title and notes can be modified.
v0.17.0
ef12565

This release continued our focus on scaling AICR validation across new services, intents, and new accelerators (GB300, metal3, GB200), as well as a new recipe-driven GPU allocation policy.

Highlights

New Accelerators & Services

  • GB300 accelerator and metal3 service support
  • GB200 Slurm recipe with IMEX compute-domain and channel conformance
  • slinky/slurm-operator upgraded to v1.2.0 with configurable operator and webhook placement
  • Akamai Cloud / Linode LKE provider-ID mapping

Expanding UAT Validation - The automated User Acceptance Testing (UAT) pipeline added Azure AKS to the AICR fleet with OIDC federation, a phase runner, and per-intent configs. A new reservation broker registry now gates GPU-pool acquisition, ensuring that scheduling lands GPU nodes only when needed. You can view evidence of every AICR UAT validation with a responsive corroborate dashboard UI and version-aware consensus at validation.aicr.run.

GPU Allocation Policy - GPU allocation became a first-class, recipe-driven contract. Recipes now default to the device-plugin allocation strategy in production, the validator enforces the recipe-configured allocation policy, and new capability inspection hardens allocation against misconfiguration.

NCCL & Fabric Validation - NCCL validation matured substantially: a GKE NCCL preflight with launcher-failure mitigations, AKS H100 all-reduce performance validation, recipe-driven benchmark applicability, cross-node fabric resource homogeneity checks, and rotation-proof bandwidth capture via pod termination messages. NCCL launcher diagnostics now surface to stdout for faster root-causing.

OS Tuning - AKS moved off the ib-node-config DaemonSet to nodewright tuning, a tuning-status table is now auto-generated, and nvidia-setup (v0.4.0) and nvidia-tuned (v0.3.1) were bumped.

Bundler

  • Multi-tenant Argo deploy options
  • argocd-helm children-only render via includeRootApp
  • repoURL default baked into values.yaml at bundle push time

Supply Chain & Evidence - Keyless and KMS signing now default to Rekor v2, with Rekor v2 identity monitoring for the release signer and restored SLSA Build L3 image provenance in the reusable workflow. The verifier now fails closed on invalid attestations under a unified allowlist. Evidence collection gained mode-aware CNCF DRA-support and secure-access phases, propagates CNCF section failures, and renders divergent recipe version pins as BOM variants.

Other Improvements

  • NFD bumped to v0.19.0, nvidia-dra-driver-gpu to v0.4.1 GA, dynamo-platform/runtime to v1.2.1

Thanks to @ArangoGutierrez, @atif1996, @ayuskauskas, @eljohnson92, @hogeheer499-commits, @kaynetu, @lockwobr, @mohityadav8, @njhensley, @srao-nv, @tjrasche, @yuanchen8911, and @mchmarny.

Changelog

New Features

Bug Fixes

Read more

v0.16.0

Choose a tag to compare

@github-actions github-actions released this 30 Jun 00:58
Immutable release. Only release title and notes can be modified.
v0.16.0
702f9ee

This release focuses on portable recipe validation evidence, the API domain migration to aicr.run, network topology discovery, and broader conformance validation.

Highlights

Evidence & Trust - Evidence handling matured into an end-to-end signing and verification workflow. aicr evidence sign signs an already-pushed bundle, push gains a --no-sign mode, and pointers are auto-signed on push under a per-source pointer contract with a signer allowlist. A new fork-based signing workflow lets external contributors publish signed evidence, the evidence gate now partitions protected vs. other sources with a component-scoped cascade, and aicr verify --trust-root validates against a private Sigstore trust root. A Rekor identity + consistency monitor watches the transparency log, evidence bundles minimize sensitive content, and the updated ingest path automates bundle verification.

Evidence Dashboard & Corroboration - New corroborate consensus model rolls per-source results into a unified verdict (with PARTIAL handling for incomplete phase coverage) and generates a dashboard published to GitHub Pages at validation.aicr.run. This is initial work using only 1st party data to validate that flow. More to come here in next release.

aicr.run API Domain Migration - The artifact API domain migrated to aicr.run, bumping the contract to v1alpha2/v1beta2 (see ADR-013). aicr validate now warns on aicr version skew across inputs and enforces artifact apiVersion compatibility so mismatched recipes and snapshots fail closed.

Network Topology Discovery - A new NetworkTopology measurement type and collector integrate the l8k library based on NVIDIA k8s-launch-kit project to capture cluster network fabric, enabling cross-repo consumption via Subtype.Items.

New Validators & Recipes

  • L40S accelerator support on OKE (Oracle Kubernetes Engine), with a new ol (Oracle Linux) OS value; OKE overlays now require explicit OS selection (no os: any fallback)
  • slinky-slurm conformance validator with a Critical User Journey (CUJ) demo
  • RoCE NET variant for nccl-all-reduce-bw
  • Prometheus/Alertmanager StatefulSet readiness in the kube-prometheus-stack check
  • OpenShift Container Platform (OCP) added as a supported --service value

Bundler

  • Structured deployer output with color and step headers
  • Private-by-default agentgateway inference-gateway exposure
  • Dynamic toleration injection for pre-built OCI bundles

Other Improvements

  • inference-perf frontend routing switched to least-loaded
  • New kwok argocd-git/gitea lanes support in test flow
  • Deployment ordering now honors enabled: false

Thanks to @almaslennikov, @atif1996, @haarchri, @kaynetu, @lockwobr, @mohityadav8, @njhensley, @rsd-darshan, @srao-nv, @yuanchen8911, and @mchmarny.

Changelog

New Features

Bug Fixes

Other Tasks

Read more

v0.15.0

Choose a tag to compare

@github-actions github-actions released this 15 Jun 19:54
Immutable release. Only release title and notes can be modified.
v0.15.0
915ed66

This release focuses on recipe health scoring, improved deployment validation, improved snapshot/discovery, and extending software supply chain capabilities for enterprise users.

Highlights

Recipe Structural Health - New pkg/health engine computes per-recipe health signals (chart_pinned, constraints_wellformed, declared_coverage) and rolls them up into a recipe-health matrix. aicr recipe list surfaces structural-health columns (with a --no-health opt-out), a tools/health generator and weekly recipe-health-refresh workflow keep the matrix current, and a lint guard now requires healthCheck.assertFile.

Improved Deployment Validation - The chainsaw deployment-phase runner is now an in-process executor rather than a shelled-out binary. aicr validate runs all phases by default with a --fail-fast opt-in, fails closed on evaluator errors, and is nil-safe across health checks.

Snapshot/Discovery - The collector now discovers GPU SKUs without nvidia-smi, removing the CUDA base image dependency and matching SKUs on token boundaries instead of substrings.

Closed Supply Chain - Signing and verification now work end-to-end in air-gapped and enterprise environments. aicr bundle supports KMS-backed signing (--signing-key) and private Sigstore deployments (--fulcio-url, --rekor-url); aicr verify --key validates bundles against a KMS or public key; and aicr evidence publish signs recipe evidence off-network. The recipe catalog itself now ships signed provenance for the V1 closed supply chain, and keyless signing warns before publishing identity to the public transparency log.

New Recipes & Overlays

  • A100 training Kubeflow overlay chains for EKS, AKS, GKE COS, and OKE
  • GB300 concrete EKS service-bound overlays
  • OKE GB200 and AKS H100 Dynamo performance checks

CLI & Bundling

  • aicr recipe list subcommand for catalog enumeration
  • Gatekeeper added as an optional component

Inference Performance & Validation

  • Inference-performance validation enhanced and tuned; gated on all worker services Ready
  • nccl-all-reduce-bw gates wired for EKS + H200; GKE NCCL node selector made dynamic
  • Bounded absent-resource retries in deployment-phase health checks

Thanks to @atif1996, @cdesiniotis, @dims, @haarchri, @JaydipGabani, @lalitadithya, @lockwobr, @njhensley, @pdmack, @pedjak, @rsd-darshan, @sttts, @xdu31, @yuanchen8911, and @mchmarny.

Changelog

New Features

Bug Fixes

Read more

v0.14.0

Choose a tag to compare

@github-actions github-actions released this 01 Jun 17:37
Immutable release. Only release title and notes can be modified.
v0.14.0
0479e45

This release focuses on further expansion to AICR recipe matrix (H200, B200, RTX PRO 6000, BCM, Slinky Slurm, Run:ai), new Go client for embedding AICR, and significant engine hardening that removes process-global state from the recipe and improves validator pipelines.

Highlights

In-Process Go Library — New pkg/aicr package exposes an aicr.Client facade for in-process consumers, allowing products and SDKs to drive recipe resolution, bundling, and validation without forking a CLI. The CLI and HTTP server already implement thin adapters over this facade.

aicr mirror — New top-level command for mirroring container images referenced by a recipe to an alternate registry, completing the air-gapped story that began with Helm vendoring in v0.13.0. The command reuses the recipe-bound DataProvider so its manifest reads are identical to what bundle and validate see.

Engine Hardening — The recipe and validator pipelines are now free of process-global state. Builder owns an isolated DataProvider, the criteria registry is per-provider (no more singleton), and the DataProvider interface is context-aware. Embedders can safely run multiple Builder instances concurrently against different sources.

New Recipes & Overlays

  • H200 promoted to a first-class accelerator type with EKS overlays
  • GKE B200 service-bound overlays
  • RTX PRO 6000 Blackwell (B40) overlays for EKS
  • BCM service type added with overlays and nodewright reapply-on-reboot
  • NVIDIA Run:ai platform support
  • Slinky Slurm gains a cluster chart with EKS, Kind, and GKE COS H100 leaves
  • H100 and generic tuning extended to H200 and RTX PRO 6000 EKS recipes

Validation & Performance

  • Strict performance floors scoped to accelerator-bound recipes
  • Deployment-phase floor delivered at per-accelerator wildcards
  • Per-field union merge for validation phase checks

Other Improvements

  • Bundle command supports app name for configurable Argo CD parent
  • argocd-helm mixed-component bundles use native OCI source shape
  • Recipe-set scheduling paths now correctly override CLI defaults
  • Kubeconfig-aware serializer for ConfigMap output

Thanks to @ayuskauskas, @faganihajizada, @fallintoplace, @gat786, @haarchri, @hkii, @lockwobr, @njhensley, @pdmack, @resker, @xdu31, @yuanchen8911, and @mchmarny.

Changelog

New Features

Bug Fixes

Read more