Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

To install Kubeflow on Amazon EKS, first choose either the AWS-specific distribution or the upstream community manifests, then select compatible Kubeflow, manifest, and Kubernetes release versions. Create or prepare the EKS cluster before deploying Kubeflow, configure identity and storage for the workloads you plan to run, and change any default authentication credentials before production use. Historical AWS setup pages include a Kubeflow v1.7.0 example, AWS manifests v1.7.0-aws-b1.0.3, and an EKS Kubernetes v1.25 cluster command; do not treat those examples as current version recommendations.

Choose an EKS deployment family

There are two main ways to set up Kubeflow on AWS. The AWS-specific distribution offers a vanilla option designed to stay close to upstream, plus integrations for selected AWS services. The upstream community manifests also support EKS and let you deploy the whole platform or choose individual components. Choose based on the identity, storage, database, and component-management approach your team wants to operate—not on an assumption that one option is universally best.

Deployment choice What it provides Consider when
Vanilla Kubeflow on AWS Minimal changes to upstream and optimization for EKS. You want the AWS distribution while staying relatively close to upstream.
AWS distribution with RDS Managed database integration for Pipelines and metadata, avoiding locally managed MySQL. You want the database handled through a managed service and accept that service dependency.
AWS distribution with S3 Pipeline artifact storage that avoids hosting local MinIO. You want artifacts stored through an AWS service rather than a locally hosted object store.
AWS distribution with Cognito An AWS identity option that avoids managing users or Dex connectors. Your identity and account-administration needs fit this approach.
Upstream community manifests EKS support and deployment of all or selected components using Kustomize. You want upstream customization or more control over which components are deployed.
Terraform AWS deployment Listed as an AWS deployment option; the AWS deployment-options page reviewed describes the Terraform options as preview. You are prepared to assess preview maturity before relying on this route.

The AWS-specific deployment choices are described in an AWS deployment-options page modified in September 2022; treat it as a guide to the integration choices, not proof of current release compatibility. The cited documentation does not establish a cheapest option or provide a cost comparison. Evaluate service costs alongside operational ownership, security, availability, identity, and storage requirements.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Match Kubeflow, manifests, and Kubernetes versions first

Before creating a cluster or applying manifests, choose a Kubeflow release and verify that the corresponding AWS manifests or upstream manifests support it and the Kubernetes version you intend to run. Use the release-specific documentation for that exact combination. The AWS prerequisites guide, modified in September 2023, gives Kubeflow v1.7.0 with AWS manifests v1.7.0-aws-b1.0.3 as an example. The AWS EKS creation page, changed in April 2023, shows a Kubernetes v1.25 cluster example. These are historical examples, not current recommendations.

Do not copy an old version pair or cluster command simply because it appears in an AWS guide. Release compatibility can change; confirm it in the documentation for the selected release before proceeding. The AWS prerequisites guide also says to check out aligned Kubeflow and AWS manifest release branches. The upstream installation guidance recommends using a stable release branch for a conservative deployment.

Prepare the deployment environment

The AWS prerequisites guide describes a Ubuntu-based environment and calls for cloning both awslabs/kubeflow-manifests and kubeflow/manifests, then checking out the release branches chosen for the deployment. Follow the instructions for your selected release rather than assuming the same branch names or setup commands apply to every version.

That guide’s make install-tools target installs AWS CLI, eksctl, kubectl, yq, jq, Kustomize, Python, Terraform, and Helm. Its tool and Python 3.8 details are historical documentation, not confirmation of the current supported toolchain. Check the selected release’s prerequisites before using the target or installing tools independently. Verify that your AWS credentials work and that the intended AWS region is selected before creating or modifying cloud resources.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Create or select the EKS cluster

For the AWS Kustomize or Helm procedure, the AWS guide expects an EKS cluster to exist before Kubeflow deployment. You can prepare a compatible cluster for the chosen release or select an existing one, provided it meets that release’s requirements. The older AWS cluster example uses eksctl and includes OIDC configuration, but its Kubernetes version and five-node M5 sizing are dated examples; they should not be copied without checking compatibility and sizing for your workloads.

OIDC matters when workloads or add-ons need AWS permissions through workload-specific IAM patterns such as IRSA. The current EKS user guide recommends an OIDC provider for some add-ons and workload-specific IAM permissions; confirm the identity setup needed by the components you will deploy. If workloads will use EBS volumes, AWS EKS guidance says to install the EBS CSI driver before deploying those workloads.

Deploy the manifests using the selected release’s instructions

The AWS-specific deployment page lists Kustomize, Helm, and Terraform routes. The upstream community manifests support a single-command deployment or installation of individual components with Kustomize. The exact commands and overlays depend on the distribution and release branch, so use the instructions in the selected release documentation rather than mixing commands from different branches.

  1. Select the distribution and release branches. Choose the AWS-specific or upstream manifests, and verify their compatibility with the Kubeflow release and EKS Kubernetes version.
  2. Prepare the cluster. Confirm access to the intended EKS cluster and region, configure the OIDC/IAM approach required by your components, and install EBS CSI if workloads need EBS-backed volumes.
  3. Apply the release-specific deployment path. Follow the matching Kustomize, Helm, Terraform, or upstream component instructions. The AWS page reviewed describes its Terraform choices as preview, so account for that maturity status if evaluating that route.
  4. Verify the deployed components and access configuration. Check the authentication configuration actually used by your deployment and confirm that the components and AWS permissions required by your workloads are available.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Secure authentication and check workload assumptions

Replace default Dex credentials

The upstream community installation documentation identifies the default Dex credentials as user@example.com and password 12341234, and warns that production deployments should change the default password. Change it using the instructions for the authentication configuration in your selected deployment, and verify which authentication provider is active rather than assuming every deployment uses the same login setup.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Check container image architecture

Some Kubeflow images may not be available for ARM64/aarch64. Before using ARM nodes, check image support for every selected component; an unsupported image can prevent a workload or component from running even if the cluster itself is healthy.

Validate AWS access and storage

Check that each controller or workload requiring AWS access has the intended IAM permissions, and that its storage dependencies are installed and configured. In particular, workloads that use EBS need the EBS CSI driver in place before deployment. Match these checks to the components and integrations actually selected rather than treating the AWS distribution options as interchangeable tiers.

Use release documentation as the deployment authority

The AWS prerequisites and cluster-creation pages cited here were modified in September 2023 and April 2023, respectively; the AWS deployment-options page was modified in September 2022. They explain the deployment sequence and integration choices, but they do not certify a current Kubeflow/EKS version pair. The current EKS user guide is relevant for EKS prerequisites such as OIDC and EBS CSI, while Kubeflow and manifest compatibility must be confirmed in release-specific documentation. Once those versions and requirements are settled, the safe sequence is to prepare tools, prepare EKS, deploy the matching manifests, and validate identity, storage, and image support before admitting production workloads.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.