live wire
AI · Red Hat documents usage-based admission fair sharing for Kueue 1.4 on OpenShiftRed Hat DeveloperAI: Red Hat maps governed firewall changes from ServiceNow through Ansible and two human approval gatesRed Hat DeveloperCLUSTER MGMT · ACM 2.17 makes Submariner 0.24 GA with Important-rated fixesRed Hat ErrataPLATFORM · Red Hat makes on-premises Lightspeed recommendations GA for Satellite 6.18Red Hat ErrataSECURITY · Red Hat Hardened Images updates Tomcat 10 for nine authentication, access-control and DoS flawsRed Hat ErrataAI · Open Data Hub 3.6.0 EA1 bundles Trainer, MLflow and llm-d componentsOpen Data HubAI · Speculators 0.6.0 adds P-EAGLE parallel drafting for vLLM speculative decodingRed Hat DeveloperSECURITY · OpenShift 4.17.57 fixes seven Go and TLS CVEs in an Important-rated updateRed Hat ErrataAI · Red Hat benchmarks local LLM guardrails with EvalHub, exposing regex accuracy and latency trade-offsRed Hat DeveloperAI · Red Hat maps silent tool-call failures across agentic pipelinesRed HatAPI · Kuadrant 1.5.3 adds GRPCRoute policies and developer-portal API-key workflowsKuadrantAI · (Aug 25) IBM releases Apache-2.0 Granite 4.2 reasoning models in 3B, 8B and 30B sizesIBM ResearchJAVA · Red Hat build of Quarkus 3.33.3.SP1 fixes 13 CVEs in an Important-rated updateRed Hat errataAI · vLLM moves Kimi K2 RL weight sync across 384 H100s in 7.53 seconds (Aug 22)vLLMAI · Red Hat documents usage-based admission fair sharing for Kueue 1.4 on OpenShiftRed Hat DeveloperAI: Red Hat maps governed firewall changes from ServiceNow through Ansible and two human approval gatesRed Hat DeveloperCLUSTER MGMT · ACM 2.17 makes Submariner 0.24 GA with Important-rated fixesRed Hat ErrataPLATFORM · Red Hat makes on-premises Lightspeed recommendations GA for Satellite 6.18Red Hat ErrataSECURITY · Red Hat Hardened Images updates Tomcat 10 for nine authentication, access-control and DoS flawsRed Hat ErrataAI · Open Data Hub 3.6.0 EA1 bundles Trainer, MLflow and llm-d componentsOpen Data HubAI · Speculators 0.6.0 adds P-EAGLE parallel drafting for vLLM speculative decodingRed Hat DeveloperSECURITY · OpenShift 4.17.57 fixes seven Go and TLS CVEs in an Important-rated updateRed Hat ErrataAI · Red Hat benchmarks local LLM guardrails with EvalHub, exposing regex accuracy and latency trade-offsRed Hat DeveloperAI · Red Hat maps silent tool-call failures across agentic pipelinesRed HatAPI · Kuadrant 1.5.3 adds GRPCRoute policies and developer-portal API-key workflowsKuadrantAI · (Aug 25) IBM releases Apache-2.0 Granite 4.2 reasoning models in 3B, 8B and 30B sizesIBM ResearchJAVA · Red Hat build of Quarkus 3.33.3.SP1 fixes 13 CVEs in an Important-rated updateRed Hat errataAI · vLLM moves Kimi K2 RL weight sync across 384 H100s in 7.53 seconds (Aug 22)vLLM
upstreambeat.ai
guideFIELD BUILDS

Treat the OpenShift AI 3.4 installation workshop as a cluster-wide evaluation, not a quickstart

The runnable sequence is useful, but it assumes an AWS workshop cluster, cluster-admin authority and disposable credentials across a broad operator stack.

By The News Desk· Aug 20, 2026

Red Hat AI Americas’ OpenShift AI 3.4 installation workshop is a useful runnable map of the platform. It is not a minimal product install. The repository deliberately carries a cluster from base preparation through NVIDIA enablement, distributed-workload operators, observability, Models as a Service, object storage, pipelines and Kueue demonstrations.

That breadth makes the workshop valuable for evaluation, but it also makes the boundary important: run it on a dedicated lab cluster, not by pointing oc apply -k at a shared environment.

Check the assumptions first

The top-level guide says the material was built and tested with OpenShift 4.20.31 or later and recommends the Red Hat Demo Platform’s AWS open environment with m6a.4xlarge control-plane instances. The cluster setup then creates an AWS GPU MachineSet and scales both GPU and ordinary workers to two nodes.

This is therefore an AWS-shaped capacity plan, not a portable sizing prescription. Teams evaluating on another infrastructure provider should replace the MachineSet step and confirm storage classes, GPU provisioning and non-GPU headroom before continuing.

The sequence also changes cluster-scoped services. It replaces OAuth configuration with an HTPasswd provider, creates a group bound to cluster-admin, enables user-workload monitoring and installs operators in cluster namespaces. Those are administrator operations with a larger blast radius than an application-namespace tutorial.

Bound the security exposure

The workshop’s credential generator creates admin/admin and dev/dev. Its MaaS database manifest also contains a fixed workshop password. Those choices make a classroom repeatable; they are not suitable for a reachable or persistent cluster.

Before running the manifests, substitute unique credentials, keep the cluster access-limited and plan to remove the HTPasswd provider and workshop role bindings afterward. Treat the repository as an evaluation asset rather than a production baseline.

Preserve the install sequence

The order is part of the design. Prepare capacity and authentication first; install Node Feature Discovery and the NVIDIA GPU Operator; verify that GPUs are advertised; then install the OpenShift AI dependencies, including LeaderWorkerSet, JobSet, Kueue, OpenTelemetry, Tempo, Cluster Observability and Connectivity Link.

Only after those dependencies are healthy should the OpenShift AI setup create the operator and DataScienceCluster. The supplied cluster enables KServe with Models as a Service, workbenches, pipelines, model registry, Ray, training, TrustyAI, Llama Stack and MLflow while leaving Kueue unmanaged because its operator was installed separately.

Use each section’s validation commands as gates. In particular, wait for GPU driver pods, the DataScienceCluster Ready phase and accepted MaaS AuthPolicies. The Cluster Observability subscription is pinned for manual approval, so an unattended run can pause there by design. A successful evaluation is not “all YAML applied”; it is every dependency healthy before the next layer is introduced.

Filed by The News Desk. Corrections: desk@upstreambeat.ai · Our standards →

comments · 0

    Comments are moderated before they appear. Your email is used once to confirm it is you — never shown, never sold. Corrections and questions get an answer from the desk when we have one.