SovAIHub
ModulesSAI-270
SAI-270 table of contents
PublicDraftSAI-270 · v1.0.0Last content review: 2026-08-03

Kubernetes and OpenShift Operations

Operate restricted AI workloads with controlled networking, storage, GPU access, security contexts, updates, backup, and recovery.

14 chapters28 min read

Learning outcomes

What you should be able to do

  • Deploy AI workloads with restricted security controls
  • Operate storage, networking, and GPU dependencies
  • Plan controlled updates, backup, and recovery

Curriculum

Work through 5 sections in order.

The chapters are individually addressable documentation pages. You can link directly to a concept from another program, architecture decision, or implementation guide.

01

Restricted-platform foundations

Define the deployment boundary, platform dependencies, and controlled artifact path.

02

Platform and workload controls

Control workload placement, communication, storage, identity, secrets, administration, and accelerators.

03

Reliability and disconnected lifecycle

Operate capacity, updates, backup, rollback, and recovery using internal dependencies.

04

Decisions and evidence

Record design choices and retain evidence of controlled operation.

05

Apply and assess

Complete a restricted operations exercise and validate the runbook.

Practical completion package

  • Restricted cluster boundary and dependency map
  • Workload security and identity baseline
  • GPU and model-runtime operations plan
  • Disconnected update and rollback runbook
  • Backup, restore, and recovery evidence

Current release boundary

This curriculum is platform-neutral at the conceptual layer. Labs require a declared Kubernetes or OpenShift profile with tested cluster, operator, accelerator, storage, and runtime versions; no production cluster changes are authorized by this material.