apiVersion: apps.nvidia.com/v1alpha1 kind: NIMCache metadata: name: qwen3-32b-instruct namespace: nim-service spec: source: ngc: modelPuller: nvcr.io/nim/qwen/qwen3-32b-dgx-spark:1.1.0-variant pullSecret: ngc-secret authSecret: ngc-api-secret model: engine: "vllm" tensorParallelism: "1" profiles: - c4f105d92c72ab56200884dfacde9d2128b139755c06b9c883eeb3e287b7408a storage: pvc: create: true size: "100Gi" volumeAccessMode: ReadWriteOnce --- apiVersion: apps.nvidia.com/v1alpha1 kind: NIMCache metadata: name: qwen36-27b-fp8 namespace: nim-service spec: source: hf: endpoint: "https://huggingface.co" namespace: "Qwen" authSecret: hf-api-secret modelPuller: nvcr.io/nim/nvidia/llm-nim:1.12 pullSecret: ngc-secret modelName: "Qwen3.6-27B-FP8" storage: pvc: create: true size: "50Gi" volumeAccessMode: ReadWriteOnce --- apiVersion: apps.nvidia.com/v1alpha1 kind: NIMService metadata: name: qwen36-27b-fp8 namespace: nim-service spec: userID: 0 groupID: 0 image: repository: vllm/vllm-openai tag: v0.19.1-cu130 pullPolicy: IfNotPresent command: - python3 args: - -m - vllm.entrypoints.openai.api_server - --model - /model-store - --served-model-name - qwen36 - --gpu-memory-utilization - "0.85" - --max-model-len - "262144" - --enable-prefix-caching authSecret: hf-api-secret storage: nimCache: name: qwen36-27b-fp8 replicas: 1 resources: limits: nvidia.com/gpu: 1 expose: service: type: ClusterIP port: 8000 --- apiVersion: gateway.networking.k8s.io/v1 kind: HTTPRoute metadata: name: llm-route namespace: nim-service spec: parentRefs: - name: envoy-gateway namespace: default hostnames: - "mcp.corredorconect.com" rules: - matches: - path: type: PathPrefix value: / backendRefs: - name: qwen36-27b-fp8 port: 8000 timeouts: request: 600s backendRequest: 600s --- apiVersion: gateway.envoyproxy.io/v1alpha1 kind: SecurityPolicy metadata: name: llm-bearer-auth namespace: nim-service spec: targetRefs: - group: gateway.networking.k8s.io kind: HTTPRoute name: llm-route apiKeyAuth: credentialRefs: - group: "" kind: Secret name: mcp-bearer-token extractFrom: - headers: - authorization