Run work in a namespace of your own Kubernetes GPU cluster (Beta)
Beta, turned on per organization. Make a namespace only for Nodus, choose Connect Kubernetes, apply the shown manifest, paste the
ServiceAccount’s kubeconfig and declare each GPU type with your hourly rate per GPU, or run
nodus cloud connect kubernetes <name> --kubeconfig-file nodus.kubeconfig --namespace nodus --gpu H100-SXM=2.10 --credit-limit 2000.
Nodus checks and stores the kubeconfig today; it places work in Kubernetes namespaces once its tests against a live
cluster pass. Until then the account shows NotAdmitted and your work runs elsewhere.
The manifest’s Role covers pods, their logs and Secrets in that namespace only. Nodus cannot read Secrets through
the API, but its pods can mount any Secret in the namespace, so keep nothing else there. Nodus refuses a token
with access outside the namespace, keeps only the API server, certificate authority and token, and acts only on
the pods it names and labels. A NetworkPolicy in the manifest takes no inbound traffic to Nodus pods.
A pod no node has room for waits up to 10 minutes for your autoscaler, or not at all for a fixed-size pool.
To stop, disconnect the namespace in Nodus first, so Nodus deletes its pods, then delete the manifest, which
leaves the namespace.