Nodus for kubectl users
View MarkdownIf you know kubectl, you already know most of nodus. Every Nodus resource (Jobs, Sandboxes, Volumes, Secrets,
InferenceEndpoints, Budgets and the rest) is a Kubernetes-style object in the nodus.dev API group, with
metadata, spec and status, and the CLI speaks the same verbs over all of them.
The mapping
Section titled “The mapping”| Kubernetes | Nodus |
|---|---|
| Cluster | The Nodus API (https://api.nodus-compute.ai) |
Namespace (-n) |
Project (-p; -n is accepted) |
| User and credentials | An API key per org, kept in the OS keychain |
| kubeconfig context | One context per org, in ~/.nodus/config |
kubectl get pods |
nodus get jobs, nodus get sandboxes, nodus get all |
kubectl exec |
nodus exec into a Job, Sandbox or Workspace; each command is recorded as a Process |
Your org comes from the API key, so there is no org in a manifest. Projects are created in the console or with
nodus create -f, and default always exists.
Verbs you already know
Section titled “Verbs you already know”nodus get jobs -o wide # tables are rendered by the servernodus get jobs -l team=nlp --field-selector status.phase=Runningnodus get job/train -o jsonpath='{.status.phase}'nodus get jobs -o custom-columns=NAME:.metadata.name,GPU:.spec.resources.gpunodus get jobs -w # watchnodus describe job/train # includes a Placement section and eventsnodus apply -f job.yaml # client-side three-way mergenodus diff -f job.yaml # what apply would change (exit 1 on differences)nodus apply -f jobs/ --prune -l app=nightly # delete what was applied before and is gone nownodus edit job/train # $EDITOR, saved as a merge patchnodus patch job/train --type merge --patch '{"spec":{"maxCostUSD":"50"}}'nodus label job/train tier=goldnodus wait job/train --for=jsonpath='{.status.phase}'=Succeeded --timeout 30mnodus delete job/train --waitnodus logs -f job/trainnodus exec -it sb/dev -- bashnodus shell sandbox/dev # create the Sandbox if needed, then exec -it bashnodus events -w --for job/train # events as they are recordednodus port-forward job/train 6006nodus explain job.spec.resourcesnodus api-resourcesnodus auth can-i create jobsShort names work as in kubectl: sb for sandboxes, vol for volumes, sec for secrets, sa for service
accounts. nodus api-resources lists them all.
What is different
Section titled “What is different”- Server dry-run returns a cost estimate.
nodus apply -f job.yaml --dry-run=server -o estimateprints the estimated cost, start time and the hold that would be placed, without creating anything. - State verbs instead of scaling.
suspend,resumeandcancelapply to Jobs, Pipelines and Sweeps;startandstopto Sandboxes, Workspaces, Functions, Agents and InferenceEndpoints. They setspec.state. - Requests are annotations.
nodus request restart sb/dev(ornodus rollout restart sb/dev) asks a controller to act once, recorded on the object. - Typed generators.
nodus create sandbox dev --cpu 2,nodus create secret hf --from-literal HF_TOKEN=…,nodus create volume weights --size 200Gi,nodus create budget research --limit 2000. Add--dry-run=client -o yamlto print the manifest instead of creating it. Kinds that show a secret once print it alone on standard output:nodus create apikey ci --scopes jobs:write,nodus create enrollmenttoken --pool lab(the host installer) andnodus create token sa/ci.nodus create sshkey --from-file ~/.ssh/id_ed25519.pubadds a public key, or--generatemakes the pair. - Outputs are files you download.
nodus cp job/train:outputs/model ./modelcopies a declared output and checks its SHA-256 digest. - Merge patches only. Strategic merge patch and server-side apply are not supported;
applydoes the three-way merge in the client and records the applied manifest in a last-applied annotation on the object. - Exit codes. Every command exits
0,1on an error or2on a usage error, like kubectl.nodus runpasses your command’s exit code through instead.
Use kubectl itself
Section titled “Use kubectl itself”~/.nodus/config is a real kubeconfig whose user entry runs nodus auth token as an exec credential plugin, so
kubectl and any client-go tool (k9s included) can read and write Nodus resources:
export KUBECONFIG=~/.nodus/configkubectl get jobs.nodus.devkubectl apply -f job.yamlkubectl get jobs.nodus.dev -wkubectl wait jobs.nodus.dev/train --for=jsonpath='{.status.phase}'=SucceededUse the full jobs.nodus.dev resource name with kubectl, because it also knows the built-in batch/v1 Jobs.
Plugins
Section titled “Plugins”Like kubectl, nodus runs any executable called nodus-<name> on your PATH as nodus <name>, so you can add
your own commands.