> ## Documentation Index
> Fetch the complete documentation index at: https://notes.kodekloud.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Demo What Was Installed

> Guide to inspecting a Kubeflow installation, listing deployed CRDs, namespaces, Istio and Kubeflow resources, and kubectl commands to explore deployed components

Now that Kubeflow is installed, this short demo inspects the cluster to show what components and custom resources were deployed. Use the commands shown below to explore CRDs, namespaces, and namespace-scoped resources so you understand how Kubeflow wires together multiple subsystems.

<Frame>
  <img src="https://mintcdn.com/kodekloud-c4ac6d9a/MGkgrGfKHDtoCnUb/images/Kubeflow/Fundamentals-of-Kubeflow/Demo-What-Was-Installed/demo-what-was-installed-slide.jpg?fit=max&auto=format&n=MGkgrGfKHDtoCnUb&q=85&s=f51aafdb99b072099e83fbac7e1ad543" alt="A blue-to-teal gradient slide with bold white centered text that reads &#x22;Demo: What was Installed.&#x22; A small &#x22;© Copyright KodeKloud&#x22; notice appears in the bottom-left." width="1920" height="1080" data-path="images/Kubeflow/Fundamentals-of-Kubeflow/Demo-What-Was-Installed/demo-what-was-installed-slide.jpg" />
</Frame>

## CustomResourceDefinitions (CRDs)

Kubeflow installs many CRDs to extend Kubernetes with ML-specific abstractions and to enable dependent projects (Dex, cert-manager, Istio, Knative, Argo, KServe, Katib, Spark operator, etc.). To list them:

```bash theme={null}
kubectl get crd
```

Below is representative output from the demo cluster (timestamps removed for readability):

```bash theme={null}
# kubectl get crd
NAME                                              
authcodes.dex.coreos.com
authrequests.dex.coreos.com
devicetokens.dex.coreos.com
oauth2clients.dex.coreos.com
offlinesessionses.dex.coreos.com
passwords.dex.coreos.com
refreshtokens.dex.coreos.com
signingkeys.dex.coreos.com

certificaterequests.cert-manager.io
certificates.cert-manager.io
orders.acme.cert-manager.io
clusterissuers.cert-manager.io
challenges.acme.cert-manager.io

profiles.kubeflow.org
notebooks.kubeflow.org
poddefaults.kubeflow.org
pvcviewers.kubeflow.org
scheduledworkflows.kubeflow.org
tensorboards.tensorboard.kubeflow.org
trainingjobs.trainer.kubeflow.org
trainingruntimes.trainer.kubeflow.org
trials.kubeflow.org
viewers.kubeflow.org
suggestions.kubeflow.org

workflows.argoproj.io
workflowtemplates.argoproj.io
workfloweventbindings.argoproj.io
workflowtaskresults.argoproj.io
workflowartifactgctasks.argoproj.io
workflowtasksets.argoproj.io

configurations.serving.knative.dev
revisions.serving.knative.dev
routes.serving.knative.dev
services.serving.knative.dev
domainmappings.serving.knative.dev

serviceentries.networking.istio.io
virtualservices.networking.istio.io
destinationrules.networking.istio.io
gateways.networking.istio.io
sidecars.networking.istio.io
workloadentries.networking.istio.io
workloadgroups.networking.istio.io
peerAuthentications.security.istio.io
requestAuthentications.security.istio.io
telemetries.telemetry.istio.io
wasmplugins.extensions.istio.io

sparkapplications.sparkoperator.k8s.io
scheduledsparkapplications.sparkoperator.k8s.io
sparkconnects.sparkoperator.k8s.io

inferenceservices.serving.kserve.io
servingruntimes.serving.kserve.io
trainedmodels.serving.kserve.io
localmodelcaches.serving.kserve.io
localmodelnodes.serving.kserve.io
localmodelnodegroups.serving.kserve.io
```

Selected CRDs map to these subsystems:

| Subsystem | Example CRDs | Purpose |
| - | - | - |
| Authentication | `authcodes.dex.coreos.com`, `oauth2clients.dex.coreos.com` | Dex provides OIDC authentication for Kubeflow. |
| Certificates | `certificates.cert-manager.io`, `clusterissuers.cert-manager.io` | cert-manager manages TLS certificates. |
| Pipelines / Orchestration | `workflows.argoproj.io`, `workflowtemplates.argoproj.io` | Argo Workflows powers Kubeflow Pipelines & scheduled workflows. |
| Serving | `inferenceservices.serving.kserve.io`, `servingruntimes.serving.kserve.io` | KServe model inference resources. |
| Hyperparameter Tuning | `trials.kubeflow.org`, `suggestions.kubeflow.org` | Katib CRDs for tuning jobs. |
| Networking | `virtualservices.networking.istio.io`, `routes.serving.knative.dev` | Istio and Knative CRDs for ingress/networking and serverless. |
| Spark | `sparkapplications.sparkoperator.k8s.io` | Spark operator CRDs for Spark jobs. |

## Namespaces

Kubeflow and its dependencies create several namespaces. List them with:

```bash theme={null}
kubectl get ns
```

Example output from the demo cluster:

```bash theme={null}
# kubectl get ns
NAME                  STATUS   AGE
auth                  Active   8m
cert-manager          Active   8m
default               Active   11m
istio-system          Active   8m
knative-serving       Active   8m
kube-system           Active   11m
kubeflow              Active   8m
kubeflow-system       Active   8m
local-path-storage    Active   11m
oauth2-proxy          Active   8m
```

Quick lookup table for these namespaces:

| Namespace | Role |
| - | - |
| `auth` | Dex-related resources (authentication). |
| `cert-manager` | cert-manager controllers and CRDs for TLS. |
| `istio-system` | Istio control plane and gateways (ingress/service mesh). |
| `knative-serving` | Knative Serving components used by Kubeflow for serverless services. |
| `kubeflow` | Core Kubeflow application components (pipelines, notebook controllers, KServe, Katib, etc.). |
| `kubeflow-system` | System-level controllers and shared services for Kubeflow. |
| `local-path-storage` | Local storage provisioner used for PVCs in demos/labs. |
| `oauth2-proxy` | OAuth2 proxy components used for auth flows. |

## Inspecting Istio (ingress / mesh)

Istio is generally used to provide ingress (and service mesh) for Kubeflow. To see Istio components:

```bash theme={null}
kubectl get all -n istio-system
```

Representative output (pods, services, deployments):

```bash theme={null}
# kubectl get all -n istio-system
# Pods
pod/cluster-local-gateway-76b84b4595-qnmlm      1/1 Running   0    7m
pod/istio-ingressgateway-6c6cd59b78-tzpwb      1/1 Running   0    7m
pod/istiod-9c8c8997d-fdndp                     1/1 Running   0    7m

# Services
service/cluster-local-gateway         ClusterIP   10.96.215.185   <none>   15020/TCP,80/TCP
service/istio-ingressgateway          ClusterIP   10.96.219.208   <none>   15021/TCP,80/TCP,443/TCP
service/istiod                        ClusterIP   10.96.118.44    <none>   15010/TCP,15012/TCP,443/TCP,15014/TCP
service/knative-local-gateway         ClusterIP   10.96.51.247    <none>   80/TCP,443/TCP

# Deployments
deployment.apps/cluster-local-gateway    1/1 1 1 7m
deployment.apps/istio-ingressgateway     1/1 1 1 7m
deployment.apps/istiod                   1/1 1 1 7m
```

Note: `istio-ingressgateway` is typically the entry point for accessing Kubeflow’s UI (it exposes ports 80 and 443 in this example).

## The `kubeflow` namespace (applications & services)

The `kubeflow` namespace contains the main Kubeflow application components: central dashboard, pipelines UI, Jupyter frontends, notebook controller, KServe (model serving), Katib (hyperparameter tuning), TensorBoard controllers, Spark operator, storage (MinIO / SeaweedFS), metadata service, and more.

Inspect resources in the namespace:

```bash theme={null}
kubectl get all -n kubeflow
```

Representative pods:

```bash theme={null}
# kubectl get pods -n kubeflow
pod/centraldashboard-5fb5f85d46-8d6q6                2/2 Running   0   8m
pod/jupyter-web-app-deployment-66bffddb4b-8nt6m      2/2 Running   0   8m
pod/katib-controller-675fb66f44-bmn2v                1/1 Running   0   8m
pod/katib-ui-775c8466cd-7gnd5                        2/2 Running   0   8m
pod/kserve-controller-manager-649f8dc4bf-bf5cg       2/2 Running   0   8m
pod/ml-pipeline-79f44dfcf4-tb4sp                     2/2 Running   3   8m
pod/ml-pipeline-ui-74f95cc94c-w7tff                  2/2 Running   0   8m
pod/mysql-5bb7cf8b95-rt5tg                           2/2 Running   0   8m
pod/notebook-controller-deployment-56b9b8dd59-qx88n  2/2 Running   0   8m
pod/pvcviewer-controller-manager-566c84dd58-khpqh   3/3 Running   0   8m
pod/seaweedfs-5bf7bfdf8c-dztmf                       2/2 Running   0   8m
pod/spark-operator-controller-85799644d7-thgnl       1/1 Running   0   8m
pod/workflow-controller-6c4b8695cf-54tgm             2/2 Running   0   8m
```

Representative services:

```bash theme={null}
# kubectl get svc -n kubeflow
service/centraldashboard                       ClusterIP   10.96.97.217    <none>   80/TCP
service/jupyter-web-app-service                ClusterIP   10.96.118.173   <none>   80/TCP
service/katib-controller                       ClusterIP   10.96.103.233   <none>   443/TCP,8080/TCP,18080/TCP
service/minio-service                          ClusterIP   10.96.65.88     <none>   9000/TCP
service/ml-pipeline                             ClusterIP   10.96.179.196   <none>   8888/TCP,8887/TCP
service/mysql                                  ClusterIP   10.96.52.81     <none>   3306/TCP
service/kserve-controller-manager-service      ClusterIP   10.96.119.122   <none>   8443/TCP
service/tensorboards-web-app-service           ClusterIP   10.96.184.118   <none>   80/TCP
service/seaweedfs                              ClusterIP   10.96.37.179    <none>   8111/TCP,8333/TCP,9333/TCP,19333/TCP,18888/TCP,8888/TCP
```

Representative controllers and sets:

```bash theme={null}
# kubectl get deployments,statefulsets,replicasets -n kubeflow
deployment.apps/centraldashboard                   1/1 1 1 8m
deployment.apps/jupyter-web-app-deployment          1/1 1 1 8m
deployment.apps/ml-pipeline                         1/1 1 1 8m
deployment.apps/mysql                               1/1 1 1 8m
statefulset.apps/metacontroller                     1/1 8m
replicaset.apps/jupyter-web-app-deployment-66bffddb 1/1 1 8m
replicaset.apps/mysql-5bb7cf8b95                     1/1 1 8m
# ...many other ReplicaSets managing each deployment/pod
```

What this demonstrates:

* Kubeflow installs a broad suite of components: UI (centraldashboard, pipelines UI), Jupyter frontends, metadata services, Argo-based pipeline controllers, KServe for model serving, Katib for hyperparameter tuning, Spark operator, storage backends (MinIO, SeaweedFS), and more.
* These components are managed using Kubernetes primitives: Deployments, ReplicaSets, StatefulSets, Services, ConfigMaps, Secrets, and CRDs where domain-specific resources are required.

<Callout icon="lightbulb" color="#1CB2FE">
  You don’t need to memorize every CRD, pod, or service. The important thing is to recognize that Kubeflow brings in multiple subsystems (auth, networking, orchestration, serving, tuning, storage) and extends Kubernetes via CRDs to provide ML-specific abstractions.
</Callout>

## Quick checklist — Commands to explore your installation

| Task | Command |
| - | - |
| List CRDs | `kubectl get crd` |
| List namespaces | `kubectl get ns` |
| List all resources in a namespace | `kubectl get all -n <namespace>` |
| Inspect Istio resources | `kubectl get all -n istio-system` |
| Inspect Kubeflow resources | `kubectl get all -n kubeflow` |

## Links and references

* [Kubeflow documentation](https://www.kubeflow.org/docs/)
* [Kubernetes documentation](https://kubernetes.io/docs/)
* [Istio documentation](https://istio.io/latest/docs/)
* [Argo Workflows](https://argoproj.github.io/argo-workflows/)
* [KServe documentation](https://kserve.github.io/)

Closing

* This demo walked through how to inspect what Kubeflow installed: CRDs, namespaces, Istio resources, and Kubeflow-specific pods/services/deployments. Use the commands above to explore your cluster and map how the pieces are connected.

<CardGroup>
  <Card title="Watch Video" icon="video" cta="Learn more" href="https://learn.kodekloud.com/user/courses/kubeflow/module/24395bd8-eef8-4e7a-aa70-510287e3a88d/lesson/49209ac4-d208-4547-b95a-0c88bb03979a" />
</CardGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.