Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,3 +4,4 @@ Reference architectures for various use cases at CoreWeave.
## Additional Reference Areas

- [secrets-management](./secrets-management/README.md): Cloud KMS-backed secret manager patterns for Kubernetes workloads.
- [kafka-local-nvme](./kafka-local-nvme/README.md): Strimzi Kafka reference for CoreWeave local NVMe, with opt-in local-PV repair.
2 changes: 2 additions & 0 deletions kafka-local-nvme/.dockerignore
Original file line number Diff line number Diff line change
@@ -0,0 +1,2 @@
.git
tests
12 changes: 12 additions & 0 deletions kafka-local-nvme/Dockerfile
Original file line number Diff line number Diff line change
@@ -0,0 +1,12 @@
FROM golang:1.24-alpine AS build
WORKDIR /src
COPY go.mod ./
RUN go mod download
COPY cmd ./cmd
COPY internal ./internal
RUN CGO_ENABLED=0 go test ./...
RUN CGO_ENABLED=0 go build -trimpath -ldflags='-s -w' -o /out/kafka-local-pv-repair ./cmd/kafka-local-pv-repair

FROM gcr.io/distroless/static-debian12:nonroot
COPY --from=build /out/kafka-local-pv-repair /kafka-local-pv-repair
ENTRYPOINT ["/kafka-local-pv-repair"]
203 changes: 203 additions & 0 deletions kafka-local-nvme/LICENSE
Original file line number Diff line number Diff line change
@@ -0,0 +1,203 @@
Copyright 2026 Chris Milsted

Apache License
Version 2.0, January 2004
http://www.apache.org/licenses/

TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION

1. Definitions.

"License" shall mean the terms and conditions for use, reproduction,
and distribution as defined by Sections 1 through 9 of this document.

"Licensor" shall mean the copyright owner or entity authorized by
the copyright owner that is granting the License.

"Legal Entity" shall mean the union of the acting entity and all
other entities that control, are controlled by, or are under common
control with that entity. For the purposes of this definition,
"control" means (i) the power, direct or indirect, to cause the
direction or management of such entity, whether by contract or
otherwise, or (ii) ownership of fifty percent (50%) or more of the
outstanding shares, or (iii) beneficial ownership of such entity.

"You" (or "Your") shall mean an individual or Legal Entity
exercising permissions granted by this License.

"Source" form shall mean the preferred form for making modifications,
including but not limited to software source code, documentation
source, and configuration files.

"Object" form shall mean any form resulting from mechanical
transformation or translation of a Source form, including but
not limited to compiled object code, generated documentation,
and conversions to other media types.

"Work" shall mean the work of authorship, whether in Source or
Object form, made available under the License, as indicated by a
copyright notice that is included in or attached to the work
(an example is provided in the Appendix below).

"Derivative Works" shall mean any work, whether in Source or Object
form, that is based on (or derived from) the Work and for which the
editorial revisions, annotations, elaborations, or other modifications
represent, as a whole, an original work of authorship. For the purposes
of this License, Derivative Works shall not include works that remain
separable from, or merely link (or bind by name) to the interfaces of,
the Work and Derivative Works thereof.

"Contribution" shall mean any work of authorship, including
the original version of the Work and any modifications or additions
to that Work or Derivative Works thereof, that is intentionally
submitted to Licensor for inclusion in the Work by the copyright owner
or by an individual or Legal Entity authorized to submit on behalf of
the copyright owner. For the purposes of this definition, "submitted"
means any form of electronic, verbal, or written communication sent
to the Licensor or its representatives, including but not limited to
communication on electronic mailing lists, source code control systems,
and issue tracking systems that are managed by, or on behalf of, the
Licensor for the purpose of discussing and improving the Work, but
excluding communication that is conspicuously marked or otherwise
designated in writing by the copyright owner as "Not a Contribution."

"Contributor" shall mean Licensor and any individual or Legal Entity
on behalf of whom a Contribution has been received by Licensor and
subsequently incorporated within the Work.

2. Grant of Copyright License. Subject to the terms and conditions of
this License, each Contributor hereby grants to You a perpetual,
worldwide, non-exclusive, no-charge, royalty-free, irrevocable
copyright license to reproduce, prepare Derivative Works of,
publicly display, publicly perform, sublicense, and distribute the
Work and such Derivative Works in Source or Object form.

3. Grant of Patent License. Subject to the terms and conditions of
this License, each Contributor hereby grants to You a perpetual,
worldwide, non-exclusive, no-charge, royalty-free, irrevocable
(except as stated in this section) patent license to make, have made,
use, offer to sell, sell, import, and otherwise transfer the Work,
where such license applies only to those patent claims licensable
by such Contributor that are necessarily infringed by their
Contribution(s) alone or by combination of their Contribution(s)
with the Work to which such Contribution(s) was submitted. If You
institute patent litigation against any entity (including a
cross-claim or counterclaim in a lawsuit) alleging that the Work
or a Contribution incorporated within the Work constitutes direct
or contributory patent infringement, then any patent licenses
granted to You under this License for that Work shall terminate
as of the date such litigation is filed.

4. Redistribution. You may reproduce and distribute copies of the
Work or Derivative Works thereof in any medium, with or without
modifications, and in Source or Object form, provided that You
meet the following conditions:

(a) You must give any other recipients of the Work or
Derivative Works a copy of this License; and

(b) You must cause any modified files to carry prominent notices
stating that You changed the files; and

(c) You must retain, in the Source form of any Derivative Works
that You distribute, all copyright, patent, trademark, and
attribution notices from the Source form of the Work,
excluding those notices that do not pertain to any part of
the Derivative Works; and

(d) If the Work includes a "NOTICE" text file as part of its
distribution, then any Derivative Works that You distribute must
include a readable copy of the attribution notices contained
within such NOTICE file, excluding those notices that do not
pertain to any part of the Derivative Works, in at least one
of the following places: within a NOTICE text file distributed
as part of the Derivative Works; within the Source form or
documentation, if provided along with the Derivative Works; or,
within a display generated by the Derivative Works, if and
wherever such third-party notices normally appear. The contents
of the NOTICE file are for informational purposes only and
do not modify the License. You may add Your own attribution
notices within Derivative Works that You distribute, alongside
or as an addendum to the NOTICE text from the Work, provided
that such additional attribution notices cannot be construed
as modifying the License.

You may add Your own copyright statement to Your modifications and
may provide additional or different license terms and conditions
for use, reproduction, or distribution of Your modifications, or
for any such Derivative Works as a whole, provided Your use,
reproduction, and distribution of the Work otherwise complies with
the conditions stated in this License.

5. Submission of Contributions. Unless You explicitly state otherwise,
any Contribution intentionally submitted for inclusion in the Work
by You to the Licensor shall be under the terms and conditions of
this License, without any additional terms or conditions.
Notwithstanding the above, nothing herein shall supersede or modify
the terms of any separate license agreement you may have executed
with Licensor regarding such Contributions.

6. Trademarks. This License does not grant permission to use the trade
names, trademarks, service marks, or product names of the Licensor,
except as required for reasonable and customary use in describing the
origin of the Work and reproducing the content of the NOTICE file.

7. Disclaimer of Warranty. Unless required by applicable law or
agreed to in writing, Licensor provides the Work (and each
Contributor provides its Contributions) on an "AS IS" BASIS,
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or
implied, including, without limitation, any warranties or conditions
of TITLE, NON-INFRINGEMENT, MERCHANTABILITY, or FITNESS FOR A
PARTICULAR PURPOSE. You are solely responsible for determining the
appropriateness of using or redistributing the Work and assume any
risks associated with Your exercise of permissions under this License.

8. Limitation of Liability. In no event and under no legal theory,
whether in tort (including negligence), contract, or otherwise,
unless required by applicable law (such as deliberate and grossly
negligent acts) or agreed to in writing, shall any Contributor be
liable to You for damages, including any direct, indirect, special,
incidental, or consequential damages of any character arising as a
result of this License or out of the use or inability to use the
Work (including but not limited to damages for loss of goodwill,
work stoppage, computer failure or malfunction, or any and all
other commercial damages or losses), even if such Contributor
has been advised of the possibility of such damages.

9. Accepting Warranty or Additional Liability. While redistributing
the Work or Derivative Works thereof, You may choose to offer,
and charge a fee for, acceptance of support, warranty, indemnity,
or other liability obligations and/or rights consistent with this
License. However, in accepting such obligations, You may act only
on Your own behalf and on Your sole responsibility, not on behalf
of any other Contributor, and only if You agree to indemnify,
defend, and hold each Contributor harmless for any liability
incurred by, or claims asserted against, such Contributor by reason
of your accepting any such warranty or additional liability.

END OF TERMS AND CONDITIONS

APPENDIX: How to apply the Apache License to your work.

To apply the Apache License to your work, attach the following
boilerplate notice, with the fields enclosed by brackets "[]"
replaced with your own identifying information. (Don't include
the brackets!) The text should be enclosed in the appropriate
comment syntax for the file format. We also recommend that a
file or class name and description of purpose be included on the
same "printed page" as the copyright notice for easier
identification within third-party archives.

Copyright [yyyy] [name of copyright owner]

Licensed under the Apache License, Version 2.0 (the "License");
you may not use this file except in compliance with the License.
You may obtain a copy of the License at

http://www.apache.org/licenses/LICENSE-2.0

Unless required by applicable law or agreed to in writing, software
distributed under the License is distributed on an "AS IS" BASIS,
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
See the License for the specific language governing permissions and
limitations under the License.
111 changes: 111 additions & 0 deletions kafka-local-nvme/README.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,111 @@
# Kafka on CoreWeave local NVMe

<!-- customer-reference: entry-point -->
[Customer reference architecture](docs/customer-reference-architecture.md)

This non-production reference deploys Strimzi Kafka with dynamically provisioned, node-local storage below `/mnt/local/kafka`. It is a deployment starting point, not a production architecture, recovery procedure, or validation of CoreWeave availability, performance, or security.

## Important storage limits

`/mnt/local` is node-local storage. Treat its contents as lost when a node is lost or rebooted; Kubernetes PV/PVC identity does not make the underlying bytes durable.

The `kafka-local` StorageClass uses `Retain` and the node pools use `deleteClaim: false`. Removing Kafka can therefore leave PVs, PVCs, and local data behind. Reusing the same namespace and Kafka resource names can reuse the same PVC-named directories; plan cleanup and identity changes deliberately.

The provisioner creates directories and local PVs by running a Kubernetes helper Pod on the scheduled node. `WaitForFirstConsumer` ensures that node is selected first. Directory-backed local-path volumes can exceed their PVC request: requests neither reserve nor enforce `/mnt/local` capacity. Operators must independently verify available capacity and leave operational headroom on every selected node.

## Profiles

| Profile | Brokers | Controllers | Broker storage | Topic RF / min ISR |
|---|---:|---:|---:|---:|
| `two-node` | 2 | 3 | 400Gi each | 2 / 1 |
| `five-node` | 5 | 3 | 400Gi each | 5 / 3 |

Profiles are mutually exclusive and use the same resource names. The three controllers each request 20Gi.
The five-node profile also enables Cruise Control and uses larger CPU and memory requests than the two-node profile.

## Prerequisites

- A Kubernetes cluster on CoreWeave, with `/mnt/local` available on every selected node.
- `kubectl`, cluster-admin access for the local-path provisioner, and a Strimzi Cluster Operator configured to watch and reconcile the `kafka` namespace.
- At least two or five nodes, respectively, labelled `kafka.local/kafka-local=true`.
- Enough free node-local capacity for the requested claims and Kafka operational headroom.

Install the Strimzi operator using its [official installation instructions](https://strimzi.io/docs/operators/latest/deploying.html) before applying a profile.

## Deploy

From this directory:

```bash
kubectl apply -k provisioner/local-path
kubectl create namespace kafka --dry-run=client -o yaml | kubectl apply -f -
kubectl label node NODE_NAME kafka.local/kafka-local=true
kubectl apply -k profiles/two-node
```

Use `five-node` in the last command for the five-broker profile.

Wait for the operator and Kafka resources to reconcile:

```bash
kubectl wait -n kafka --for=condition=Ready kafka/kafka-local --timeout=10m
kubectl wait -n kafka --for=condition=Ready kafkatopic/kafka-local-topic --timeout=10m
kubectl get kafka,kafkanodepool,kafkatopic,pvc -n kafka
kubectl get pods -n kafka -o wide
```

Confirm that each PV is local and bound to the node chosen for its consuming Kafka Pod:

```bash
kubectl get pv -o custom-columns=NAME:.metadata.name,PATH:.spec.local.path,NODE:.spec.nodeAffinity.required.nodeSelectorTerms[0].matchExpressions[0].values[0],CLAIM_NAMESPACE:.spec.claimRef.namespace,CLAIM_NAME:.spec.claimRef.name
```

After Kafka and `kafka-local-topic` are Ready, run the basic producer/readback check:

```bash
./scripts/smoke-test.sh
```

It verifies exact readback of a small uniquely tagged message set produced with `acks=all`; it does not test node loss, reboot recovery, HA, performance, or security.

## Optional Repair DaemonSet

The normal Kustomizations do not install repair. The optional Repair DaemonSet only recreates absent directories in the exact managed hierarchy `/mnt/local/kafka/<namespace>/<claim>` after it verifies the host mount and an authorized, unchanged Node identity. It never restores lost bytes, deletes anything, or mutates PVs or PVCs. Kafka can rebuild only from healthy replicas; this is not automatic reboot, replacement, cleanup, or provider-behavior proof.

Use it only during serialized operator maintenance:

1. Build and publish the image, then use its immutable `repository@sha256:...` digest. The image build runs the Linux test suite before compiling the binary.

```bash
docker build -t registry.example/kafka-local-pv-repair:VERSION .
docker push registry.example/kafka-local-pv-repair:VERSION
```
2. Capture each Node's exact `name`, hostname, Kubernetes UID, and nonempty provider ID in a tab-separated allowlist. Any identity difference requires explicit reauthorization and a newly rendered manifest.
3. Independently verify the host `/mnt/local` mount filesystem, source, and canonical sorted comma-separated mount options; omit the `ro`/`rw` mode because the agent verifies that the host mount is writable itself.
4. Render and apply the complete generated manifest (including ServiceAccount and RBAC). The renderer requires Python 3.

```bash
./scripts/render-kafka-local-pv-repair-manifest.sh \
--image registry.example/kafka-local-pv-repair@sha256:REPLACE_WITH_64_HEX \
--mount-fs ext4 --mount-source /dev/REPLACE_ME \
--mount-options nodev,nosuid \
--nodes nodes.tsv | kubectl apply -f -
```

5. Obtain the required Pod Security approval for `hostPID` and a read-write `/mnt/local` hostPath. The container runs as root only to create missing root-owned hierarchy components, with `CHOWN` and `DAC_OVERRIDE` as its only added capabilities. Check the DaemonSet rollout and logs, and serialize all related operator maintenance. A newly rendered authorization changes the Pod template and rolls the DaemonSet automatically.

The two-node profile can lose controller quorum. Simultaneous local-storage loss can be unrecoverable even with the five-node profile.

## Validate manifests

```bash
./scripts/validate.sh
kubectl apply --dry-run=server -k provisioner/local-path
kubectl apply --dry-run=server -k profiles/two-node
```

The server dry run is optional and requires a cluster with the Strimzi CRDs installed. Run it again with `profiles/five-node` when using that profile.

## Package license

This package is governed by [LICENSE](LICENSE) (Apache-2.0) and [THIRD_PARTY_NOTICES.md](THIRD_PARTY_NOTICES.md).
13 changes: 13 additions & 0 deletions kafka-local-nvme/THIRD_PARTY_NOTICES.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,13 @@
# Third-party notices

## Rancher Local Path Provisioner

The manifests under `provisioner/local-path/` are derived from Rancher Local
Path Provisioner version 0.0.36:

<https://github.com/rancher/local-path-provisioner>

Copyright 2014-2020 Rancher Labs, Inc.

Rancher Local Path Provisioner is licensed under the Apache License, Version
2.0. A copy of that license is included in this package as `LICENSE`.
Loading