AI Platform Engineer
You own: the GeneFlow platform itself — capacity, multi-tenancy, cost attribution, internal APIs, and the runtime path for any GeneAI workload at scale.
What's new for you
| Was | Now in GeneFlow |
|---|---|
| Glue scripts between MLflow, eval, serving | Single GeneFlow data model with tenant_id everywhere |
| Custom cost rollups in BI | cost_usd first-class on runs + endpoints |
| K8s manifests applied by hand | Helm + jobs-service deployer auto-reconciles gf_endpoints |
| Tenant quotas in Slack | CustomerTenantSettings.geneflow enforced in middleware |
Capacity-shaping levers
| Lever | File / table | What it controls |
|---|---|---|
| Tenant quota | gf_tenant_quotas (via tenant settings) | runs/hr, endpoints, GiB |
| Instance pricing | serving.ts HOURLY_COST_USD | $/hr per instance type |
| Snapshot interval | WS_SNAPSHOT_INTERVAL_MS env | WS gateway → API write frequency |
| K8s job TTL | ttlSecondsAfterFinished in spec | when finished jobs are cleaned |
| Drift PSI threshold | gf_endpoints.drift_psi_threshold | per-endpoint sensitivity |
| HPA target CPU% | k8s-serving-deployer.ts | default 70%, change to 50% for latency-bound |
Workflow 1 — Onboard a new tenant
genedata tenants create ACME \
--quota-runs-per-hour 5000 \
--quota-endpoints 200 \
--quota-artifact-gib 1000
# Wire IAM (AWS IRSA) so the runner pod can `aws s3 sync`
helm upgrade --reuse-values genedata \
--set global.agentRuntime.runnerIamRoleArn=arn:aws:iam::123:role/geneflow-ACME
# Issue tenant admin PAT
genedata auth issue-token --tenant ACME --scope geneflow:admin --user admin@acme.com
Workflow 2 — Per-tenant cost rollup
SELECT
date_trunc('day', start_time) AS day,
SUM(cost_usd) AS run_cost,
COUNT(*) AS runs
FROM gf_runs WHERE tenant_id='ACME'
GROUP BY 1 ORDER BY 1 DESC;
-- Endpoint hourly burn
SELECT name, hourly_cost_usd, total_cost_usd, replicas
FROM gf_endpoints WHERE tenant_id='ACME' AND status='READY';
Workflow 3 — Bring up a new GeneFlow region
- New K8s cluster + image registry mirror
- Helm install with
global.region=eu-west-1 - Storage: per-tenant prefix in regional bucket
- Federate audit chain via cross-region replication (read-only)
- Update Tenant
data_residency_regionfor tenants requiring EU-only
Workflow 4 — Capacity guardrails for inference
-- Find tenants near their endpoint quota
SELECT t.tenant_id,
t.quota_endpoints,
COUNT(*) FILTER (WHERE status='READY') AS in_use,
(COUNT(*) FILTER (WHERE status='READY')::FLOAT / t.quota_endpoints) AS usage
FROM gf_endpoints e JOIN tenant_quotas t USING (tenant_id)
WHERE tenant_id='ACME'
GROUP BY t.tenant_id, t.quota_endpoints;
Alert at 80% usage so SRE doesn't get paged at 100%.
Workflow 5 — Bring up a new instance class
- Add it to
HOURLY_COST_USDandRESOURCE_PRESETSinserving.ts/k8s-serving-deployer.ts - Bump migration:
ALTER TABLE gf_endpoints DROP CONSTRAINT … ADD CHECK (instance_type IN (...)) - Update SDK type literal in
serving.py - Add to UI dropdown in
endpoints/page.tsx - Document in api-reference.md
Workflow 6 — Strangler-fig: extract more from the monolith
The platform was originally monolithic. We've already extracted: agent-runtime, embedding, stream-processor, automl, plugin-runner, federated, explainer, geneflow-service, websocket-gateway, jobs-service.
To extract another:
- Mirror the engine code into
services/<name>-service/src/ - Use the
Dockerfilepattern that COPYs bothapps/api/srcandservices/<name>-service/src - Mount the same router in
services/<name>-service/index.ts - Add to
service-proxy.tswith env toggle (SERVICE_X_BACKEND=external) - Add to
helm/genedata/values.yamlservicesarray → ServiceMonitor auto-generated
Common gotchas
- A new column with no
tenant_idleading the index is a bug. Every gf_ migration MUST. - Quota enforcement must happen in middleware, not in the engine — engine is the per-call enforcer, middleware is the rate-limiter.
- Serving images need to live in the customer's registry namespace if data-residency requires it — don't hard-code
registry.genedata.io.
Where to go next
- architecture.md — strangler-fig + service boundaries
- 02-mlops-engineer.md — adjacent role
- 23-genedata-administrator.md — tenant admin