TL;DR

Identity + authorization plane
PeopleUsersBrowser clients
Authenticated edgeEnvoy GatewayBrowser routes · OIDC policy
Identity providerKeycloakOIDC login · full group paths
Data authorizationGeneric data catalogMetadata · grants · durable references
ATEP Kubernetes cluster
checkmaite-packUI + API
Web UIRayJob submitterBounded impersonation

Validates the person and tenant, then submits as the authenticated caller.

data-science-packJupyterHub + JupyterLab
User notebookTenant ServiceAccountRay client

Tenant-member access: launch approved RayClusters and RayJobs, then connect directly.

Extensible platformOther NIC packs
ServicesAPIsWorkflows

Reuse tenant identity, policy, compute, and S3.

Cluster control + orchestrationKubernetes API
KubeRay operatorArgo Workflows
Shared team boundary · not a per-user namespaceGroup A namespaceRBAC · quota · admission · NetworkPolicy
Notebook path · separate Ray runtimesInteractive RayClusters
AliceBob
Separate heads and object stores; shared tenant boundary
Batch path · notebook or UIRayJob + RayClusterOne ephemeral cluster per run
Serving pathRayServiceOne per group
tenant-member Rolenotebook / interactive ServiceAccountrunner ServiceAccountserving ServiceAccount
Repeated boundaryGroup BSeparate namespace

Its own clusters, RayService, identities, quota, and data grants.

AWS data planeEKS Pod Identity → IAM rolesNo static credentials
API result reader · Group ANotebook / interactive · Group ARunner / workflow · Group AServing · Group ANIC pack service rolesAPI result reader · Group B
Durable Kubernetes workload storageS3Datasets · models · run inputs · resultsArgo artifacts · group-separated prefixes
IdentityControl and submissionData and AWS identity

On a small screen, swipe the diagram horizontally.

27 items shown