Platform dependency matrix
This is the human-readable companion to the authored build data in src/data/platform-dependencies.yaml. Missing pins or sources are build errors.
For runtime controls, see the VLLMB12X runtime configuration reference. For standard vLLM settings, use the vLLM configuration reference.
| Layer | Exact pin | Installer / owner | Depends on | Readiness gate | Evidence |
|---|---|---|---|---|---|
| DGX OS / Ubuntu | 24.04 arm64 | host operator | firmware/repositories | dpkg --print-architecture |
tested host lane |
| 64 KiB kernel | 7.0.0-1019-nvidia-64k |
host operator | DGX OS packages | uname -r; page size 65536 |
current host lane; availability must be checked |
| NVIDIA open fork | 615.71.09, release spark-615.71.09-1, commit c5296e2…f96c42 |
DKMS nvidia-open |
exact kernel headers | five module versions/paths, nvidia-smi, CUDA allocation |
tested host lane |
| NVIDIA Container Toolkit | 1.17.8-1 |
host operator | NVIDIA driver/userspace | nvidia-container-runtime visible to k3s service |
source-observed pin |
| k3s | v1.34.6+k3s1 |
k3s | toolkit before agent start | three Nodes Ready after Cilium | newly verified release; combination untested |
| Gateway API CRDs | v1.5.0 |
cluster operator | k3s API | Gateway and HTTPRoute CRDs exist | release matched to Inference Extension v1.5.0 |
| Cilium | 1.19.4 |
primary CNI/policy | k3s custom-CNI config | cilium status --wait; connectivity test |
newly verified; production uses Cilium on kubeadm |
| CoreDNS | k3s-bundled | k3s | working Cilium | Deployment Available, DNS lookup | combination untested |
| NFD | bundled with GPU Operator 26.7.0 | GPU Operator on fresh lane | Nodes | NVIDIA feature label | one-owner rule; combination untested |
| GPU Operator | 26.7.0 |
GPU Operator | NFD, host toolkit/driver | operands ready, one GPU/node, CUDA sample | source-observed family; k3s combination untested |
| Multus thick plugin | v4.2.2 |
cluster operator | working Cilium | DaemonSet ready, primary traffic still works | newly verified release |
| macvlan | k3s-bundled CNI plugins | k3s | Multus | secondary interface appears | combination untested |
| Whereabouts | v0.9.2 |
cluster operator | Multus, non-overlap subnet | DaemonSet/CRDs ready, unique secondary IPs | newly verified release |
| Network Operator | 26.7.0 |
RDMA allocator only | NFD + host mlx5 + Multus | policy ready; rdma.com/roce allocatable |
source-observed family; combination untested |
| cert-manager | v1.21.2 |
cluster operator | DNS/network | all deployments Available | source-observed pin |
| LeaderWorkerSet | v0.10.0 |
LWS controller | cert-manager | controller/webhook Available | tested deployment API; k3s untested |
| Inference Extension | v1.5.0 |
CRDs + per-model EPP | Gateway API | InferencePool CRD; EPP healthy | tested routing config; live pool CRD carries inference.networking.k8s.io/bundle-version: v1.5.0 and serves v1 only |
| Envoy Gateway | 1.8.3 |
Envoy Gateway | cert-manager, Gateway API | controller Available; class Accepted | tested routing config; live controller image gateway:v1.8.3, data plane envoy:distroless-v1.38.3, installed with the AI Gateway extension-manager hook |
| Envoy AI Gateway | v1.1.0 |
AI Gateway controller | Envoy Gateway, cert-manager | CRDs/controller Available | charts pinned v1.1.0; the author’s controller runs a private v1.1.0 build carrying one upstream pull request, which changes ext_proc wiring to one filter per pool instead of one per route |
| Model snapshot | 6821d6ad…0a380 |
vllm-image model-sync |
token, 200 GiB storage | config and indexed shards validated | tested recipe |
| Model/JIT storage | operator-supplied absolute host paths; 200 GiB model minimum | host and cluster operator | model snapshot, topology | both directories exist and free-space gate passes | tested storage shape; paths site-specific |
Source index
Section titled “Source index”- DGX OS 7 user guide
- Driver fork at the exact accepted commit
- NVIDIA Container Toolkit installation
- k3s v1.34.6+k3s1 release, requirements, custom CNI, Multus
- Gateway API v1.5.0
- Cilium 1.19.4 release, k3s installation, Helm reference
- GPU Operator release notes, platform support
- Multus v4.2.2, Whereabouts v0.9.2, macvlan
- Network Operator 26.7.0 release notes, GPUDirect RDMA test
- cert-manager Helm installation
- LWS v0.10.0
- Inference Extension v1.5.0
- Envoy Gateway 1.8.3
- Envoy AI Gateway v1.1.0
- Pinned model snapshot
- Kubernetes hostPath volume semantics
Hard ownership invariants
Section titled “Hard ownership invariants”- The host, not GPU Operator, owns driver and toolkit.
- Exactly one NFD installation owns feature labels.
- Cilium owns the primary CNI; Multus adds secondary networks and must coexist non-exclusively.
- Network Operator advertises RDMA only; it does not install OFED or replace the host driver.
- LWS owns group lifecycle; EPP/Gateway own endpoint selection and routing.
- Tokens exist only in local environment/Secrets, never recipe data or browser state.