Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
24 changes: 21 additions & 3 deletions docs.json
Original file line number Diff line number Diff line change
Expand Up @@ -82,9 +82,10 @@
{
"group": "Dedicated Cloud",
"pages": [
"platform/hosting/hosting-options/dedicated_cloud",
"platform/hosting/hosting-options/dedicated_regions",
"platform/hosting/export-data-from-dedicated-cloud"
"platform/hosting/hosting-options/dedicated-cloud",
"platform/hosting/hosting-options/dedicated-cloud/rate-limits",
"platform/hosting/hosting-options/dedicated-cloud/regions",
"platform/hosting/hosting-options/dedicated-cloud/export-data"
]
},
{
Expand All @@ -93,6 +94,7 @@
"platform/hosting/hosting-options/self-managed",
"platform/hosting/self-managed/ref-arch",
"platform/hosting/self-managed/requirements",
"platform/hosting/self-managed/rate-limits",
"platform/hosting/self-managed/operator",
"platform/hosting/self-managed/on-premises-deployments/kubernetes-airgapped",
"platform/hosting/server-upgrade-process",
Expand Down Expand Up @@ -3890,6 +3892,22 @@
"source": "/platform/hosting/secure-storage-connector",
"destination": "/platform/hosting/data-security/secure-storage-connector"
},
{
"source": "/platform/hosting/hosting-options/dedicated_cloud",
"destination": "/platform/hosting/hosting-options/dedicated-cloud"
},
{
"source": "/platform/hosting/hosting-options/rate-limits-dedicated-cloud",
"destination": "/platform/hosting/hosting-options/dedicated-cloud/rate-limits"
},
{
"source": "/platform/hosting/hosting-options/dedicated_regions",
"destination": "/platform/hosting/hosting-options/dedicated-cloud/regions"
},
{
"source": "/platform/hosting/export-data-from-dedicated-cloud",
"destination": "/platform/hosting/hosting-options/dedicated-cloud/export-data"
},
{
"source": "/platform/hosting/self-managed/install-on-public-cloud",
"destination": "/platform/hosting/self-managed"
Expand Down
6 changes: 3 additions & 3 deletions ja/platform/hosting/hosting-options/self-managed.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@ description: プロダクション環境での W&B Self-Managed のデプロイ
## クラウドまたはオンプレミスインフラストラクチャーでの W&B Self-Managed の利用

<Note>
W&B では、[W&B Multi-tenant Cloud](/platform/hosting/hosting-options/multi_tenant_cloud) または [W&B 専用クラウド](/platform/hosting/hosting-options/dedicated_cloud) などの完全管理型のデプロイメントオプションを推奨しています。W&B の完全管理型サービスは、設定がほとんど不要で、シンプルかつ安全に利用できます。
W&B では、[W&B Multi-tenant Cloud](/platform/hosting/hosting-options/multi_tenant_cloud) または [W&B 専用クラウド](/platform/hosting/hosting-options/dedicated-cloud) などの完全管理型のデプロイメントオプションを推奨しています。W&B の完全管理型サービスは、設定がほとんど不要で、シンプルかつ安全に利用できます。
</Note>

W&B Server は、お客様の [AWS、Google Cloud、または Azure のクラウド経由のアカウント](#deploy-wb-server-within-Self-Managed-cloud-accounts)、または [オンプレミスインフラストラクチャー](#オンプレミスインフラストラクチャーへの-wb-server-のデプロイ) 内にデプロイできます。
Expand All @@ -20,7 +20,7 @@ W&B Server は、お客様の [AWS、Google Cloud、または Azure のクラウ
- W&B Self-Managed デプロイメントの継続的なメンテナンス。

<Tip>
組織が規制要件の対象となる場合は、W&B がメンテナンスを行う [W&B 専用クラウド](/platform/hosting/hosting-options/dedicated_cloud.mdx) へのデプロイを検討してください。
組織が規制要件の対象となる場合は、W&B がメンテナンスを行う [W&B 専用クラウド](/platform/hosting/hosting-options/dedicated-cloud.mdx) へのデプロイを検討してください。

- W&B 専用クラウド のホスティングプラットフォームは、SOC 2 Type 2 の要件を満たしています。
- 適切に設定された場合、W&B 専用クラウド のデプロイメントは HIPAA に準拠します。
Expand Down Expand Up @@ -68,4 +68,4 @@ URL にアクセスすると、**Get a License for W&B Local** フォームに
3. **Get a License** ステップの **Name of Instance** フィールドにインスタンスの名前を入力し、任意で **Description** フィールドに説明を入力します。
4. **Generate License Key** ボタンを選択します。

デプロイメントの概要と、そのインスタンスに関連付けられたライセンスキーが表示されたページが表示されます。
デプロイメントの概要と、そのインスタンスに関連付けられたライセンスキーが表示されたページが表示されます。
6 changes: 3 additions & 3 deletions ko/platform/hosting/hosting-options/self-managed.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@ description: 프로덕션 환경에 W&B Self-Managed 배포하기
## 클라우드 또는 온프레미스 인프라에서 W&B Self-Managed 사용하기

<Note>
W&B는 [W&B Multi-tenant Cloud](/platform/hosting/hosting-options/multi_tenant_cloud) 또는 [W&B 전용 클라우드](/platform/hosting/hosting-options/dedicated_cloud) 배포 유형과 같은 완전 관리형 배포 옵션을 권장합니다. W&B 완전 관리형 서비스는 설정이 거의 또는 전혀 필요하지 않아 사용이 간편하고 안전합니다.
W&B는 [W&B Multi-tenant Cloud](/platform/hosting/hosting-options/multi_tenant_cloud) 또는 [W&B 전용 클라우드](/platform/hosting/hosting-options/dedicated-cloud) 배포 유형과 같은 완전 관리형 배포 옵션을 권장합니다. W&B 완전 관리형 서비스는 설정이 거의 또는 전혀 필요하지 않아 사용이 간편하고 안전합니다.
</Note>

[AWS, Google Cloud 또는 Azure 클라우드 계정](#deploy-wb-server-within-Self-Managed-cloud-accounts) 혹은 [온프레미스 인프라](#온프레미스-인프라에-wb-server-배포하기) 내에 W&B Server를 배포하세요.
Expand All @@ -19,7 +19,7 @@ W&B는 [W&B Multi-tenant Cloud](/platform/hosting/hosting-options/multi_tenant_c
- W&B Self-Managed 배포의 지속적인 유지 관리.

<Tip>
조직이 규제 요구 사항을 준수해야 하는 경우, W&B가 유지 관리하는 [W&B 전용 클라우드](/platform/hosting/hosting-options/dedicated_cloud.mdx)에 배포하는 것을 고려해 보세요.
조직이 규제 요구 사항을 준수해야 하는 경우, W&B가 유지 관리하는 [W&B 전용 클라우드](/platform/hosting/hosting-options/dedicated-cloud.mdx)에 배포하는 것을 고려해 보세요.
- W&B 전용 클라우드의 호스팅 플랫폼은 SOC 2 Type 2 요구 사항을 충족합니다.
- 적절하게 설정된 경우, W&B 전용 클라우드 배포는 HIPAA를 준수합니다.

Expand Down Expand Up @@ -66,4 +66,4 @@ W&B 계정이 없는 경우, 계정을 먼저 생성해야 무료 라이선스
3. **Get a License** 단계의 **Name of Instance** 필드에 인스턴스 이름을 입력하고, 선택 사항으로 **Description** 필드에 설명을 입력합니다.
4. **Generate License Key** 버튼을 클릭합니다.

배포 개요와 해당 인스턴스에 연결된 라이선스 키가 표시된 페이지가 나타납니다.
배포 개요와 해당 인스턴스에 연결된 라이선스 키가 표시된 페이지가 나타납니다.
2 changes: 1 addition & 1 deletion platform/hosting.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -21,7 +21,7 @@ Some features and functionality require an [Enterprise](https://wandb.ai/site/pr
<a id="wb-dedicated-cloud" aria-label="W&B Dedicated Cloud"></a><Card title="W&B Dedicated Cloud">
A single-tenant, fully managed service deployed in W&B's cloud infrastructure. It is the best place to onboard W&B if your organization requires conformance to strict governance controls including data residency, have need of advanced security capabilities, and are looking to optimize their AI operating costs by not having to build & manage the required infrastructure with security, scale & performance characteristics.

See **[W&B Dedicated Cloud](/platform/hosting/hosting-options/dedicated_cloud)** for more information.
See **[W&B Dedicated Cloud](/platform/hosting/hosting-options/dedicated-cloud)** for more information.
</Card>

<a id="wb-Self-Managed" aria-label="W&B Self-Managed"></a><Card title="W&B Self-Managed">
Expand Down
2 changes: 1 addition & 1 deletion platform/hosting/data-security/data-encryption.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@
title: Data encryption in Dedicated Cloud
---

W&B uses a W&B-managed cloud-native key to encrypt the W&B-managed database and object storage in every [Dedicated Cloud](/platform/hosting/hosting-options/dedicated_cloud), by using the customer-managed encryption key (CMEK) capability in each cloud. In this case, W&B acts as a `customer` of the cloud provider, while providing the W&B platform as a service to you. Using a W&B-managed key means that W&B has control over the keys that it uses to encrypt the data in each cloud, thus doubling down on its promise to provide a highly safe and secure platform to all of its customers.
W&B uses a W&B-managed cloud-native key to encrypt the W&B-managed database and object storage in every [Dedicated Cloud](/platform/hosting/hosting-options/dedicated-cloud), by using the customer-managed encryption key (CMEK) capability in each cloud. In this case, W&B acts as a `customer` of the cloud provider, while providing the W&B platform as a service to you. Using a W&B-managed key means that W&B has control over the keys that it uses to encrypt the data in each cloud, thus doubling down on its promise to provide a highly safe and secure platform to all of its customers.

W&B uses a `unique key` to encrypt the data in each customer instance, providing another layer of isolation between Dedicated Cloud tenants. The capability is available on AWS, Azure and Google Cloud.

Expand Down
2 changes: 1 addition & 1 deletion platform/hosting/data-security/ip-allowlisting.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@
title: Configure IP allowlisting for Dedicated Cloud
---

You can restrict access to your [Dedicated Cloud](/platform/hosting/hosting-options/dedicated_cloud) instance from only an authorized list of IP addresses. This applies to the access from your AI workloads to the W&B APIs and from your user browsers to the W&B app UI as well. Once IP allowlisting has been set up for your Dedicated Cloud instance, W&B denies any requests from other unauthorized locations. Reach out to your W&B team to configure IP allowlisting for your Dedicated Cloud instance.
You can restrict access to your [Dedicated Cloud](/platform/hosting/hosting-options/dedicated-cloud) instance from only an authorized list of IP addresses. This applies to the access from your AI workloads to the W&B APIs and from your user browsers to the W&B app UI as well. Once IP allowlisting has been set up for your Dedicated Cloud instance, W&B denies any requests from other unauthorized locations. Reach out to your W&B team to configure IP allowlisting for your Dedicated Cloud instance.

IP allowlisting is available on Dedicated Cloud instances on AWS, Google Cloud and Azure.

Expand Down
2 changes: 1 addition & 1 deletion platform/hosting/data-security/private-connectivity.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@
title: Configure private connectivity to Dedicated Cloud
---

You can connect to your [Dedicated Cloud](/platform/hosting/hosting-options/dedicated_cloud/) instance over the cloud provider's secure private network. This applies to the access from your AI workloads to the W&B APIs and optionally from your user browsers to the W&B app UI as well. When using private connectivity, the relevant requests and responses do not transit through the public network or internet.
You can connect to your [Dedicated Cloud](/platform/hosting/hosting-options/dedicated-cloud) instance over the cloud provider's secure private network. This applies to the access from your AI workloads to the W&B APIs and optionally from your user browsers to the W&B app UI as well. When using private connectivity, the relevant requests and responses do not transit through the public network or internet.

<Note>
Secure private connectivity is coming soon as an advanced security option with Dedicated Cloud.
Expand Down
14 changes: 7 additions & 7 deletions platform/hosting/data-security/secure-storage-connector.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,7 @@ import ByobContextNote from "/snippets/en/_includes/byob-context-note.mdx";
<ByobContextNote/>

## Overview
Bring your own bucket (BYOB) allows you to store W&B artifacts and other related sensitive data in your own cloud or on-prem infrastructure. In case of [Dedicated Cloud](/platform/hosting/hosting-options/dedicated_cloud) or [Multi-tenant Cloud](/platform/hosting/hosting-options/multi_tenant_cloud), data that you store in your bucket is not copied to the W&B managed infrastructure.
Bring your own bucket (BYOB) allows you to store W&B artifacts and other related sensitive data in your own cloud or on-prem infrastructure. In case of [Dedicated Cloud](/platform/hosting/hosting-options/dedicated-cloud) or [Multi-tenant Cloud](/platform/hosting/hosting-options/multi_tenant_cloud), data that you store in your bucket is not copied to the W&B managed infrastructure.

<Note>
* Communication between W&B SDK / CLI / UI and your buckets occurs using [pre-signed URLs](./presigned-urls).
Expand Down Expand Up @@ -37,7 +37,7 @@ There are two scopes you can configure your storage bucket to:

| Scope | Description |
|----------------|-------------|
| Instance level | In [Dedicated Cloud](/platform/hosting/hosting-options/dedicated_cloud) and [Self-Managed](/platform/hosting/hosting-options/self-managed), any user with the required permissions within your organization or instance can access files stored in your instance's storage bucket. Not applicable to [Multi-tenant Cloud](/platform/hosting/hosting-options/multi_tenant_cloud). |
| Instance level | In [Dedicated Cloud](/platform/hosting/hosting-options/dedicated-cloud) and [Self-Managed](/platform/hosting/hosting-options/self-managed), any user with the required permissions within your organization or instance can access files stored in your instance's storage bucket. Not applicable to [Multi-tenant Cloud](/platform/hosting/hosting-options/multi_tenant_cloud). |
| Team level | If a W&B Team is configured to use a Team level storage bucket, team members can access files stored in it. Team level storage buckets allow greater data access control and data isolation for teams with highly sensitive data or strict compliance requirements.<br/><br/>Team level storage can help different business units or departments sharing an instance to efficiently use the infrastructure and administrative resources. It can also allow separate project teams to manage AI workflows for separate customer engagements. Available for all deployment types. You configure team level BYOB when setting up the team. |

This flexible design allows for many different storage topologies, depending on your organization's needs. For example:
Expand Down Expand Up @@ -293,10 +293,10 @@ For details, see [Create an S3 bucket](https://docs.aws.amazon.com/AmazonS3/late

Replace `<wandb_bucket>` accordingly and keep a record of the bucket name. Next, [configure W&B](#configure-byob).

If you are using [Multi-tenant Cloud](/platform/hosting/hosting-options/multi_tenant_cloud) or [Dedicated Cloud](/platform/hosting/hosting-options/dedicated_cloud), replace `<aws_principal_and_role_arn>` with the corresponding value.
If you are using [Multi-tenant Cloud](/platform/hosting/hosting-options/multi_tenant_cloud) or [Dedicated Cloud](/platform/hosting/hosting-options/dedicated-cloud), replace `<aws_principal_and_role_arn>` with the corresponding value.

* For [Multi-tenant Cloud](/platform/hosting/hosting-options/multi_tenant_cloud): `arn:aws:iam::725579432336:role/WandbIntegration`
* For [Dedicated Cloud](/platform/hosting/hosting-options/dedicated_cloud): `arn:aws:iam::830241207209:root`
* For [Dedicated Cloud](/platform/hosting/hosting-options/dedicated-cloud): `arn:aws:iam::830241207209:root`

For more details, see the [AWS Self-Managed hosting guide](/platform/hosting/hosting-options).
</Tab>
Expand Down Expand Up @@ -342,10 +342,10 @@ For details, see [Create a bucket](https://docs.cloud.google.com/storage/docs/cr
gsutil cors get gs://<bucket_name>
```

1. If you are using [Multi-tenant Cloud](/platform/hosting/hosting-options/multi_tenant_cloud) or [Dedicated Cloud](/platform/hosting/hosting-options/dedicated_cloud), grant the `storage.admin` role to the Google Cloud service account linked to the W&B Platform. W&B requires this role to check the bucket's CORS configuration and attributes, such as whether object versioning is enabled. If the service account does not have the `storage.admin` role, these checks result in a HTTP 403 error.
1. If you are using [Multi-tenant Cloud](/platform/hosting/hosting-options/multi_tenant_cloud) or [Dedicated Cloud](/platform/hosting/hosting-options/dedicated-cloud), grant the `storage.admin` role to the Google Cloud service account linked to the W&B Platform. W&B requires this role to check the bucket's CORS configuration and attributes, such as whether object versioning is enabled. If the service account does not have the `storage.admin` role, these checks result in a HTTP 403 error.

* For [Multi-tenant Cloud](/platform/hosting/hosting-options/multi_tenant_cloud), the account is: `wandb-integration@wandb-production.iam.gserviceaccount.com`
* For [Dedicated Cloud](/platform/hosting/hosting-options/dedicated_cloud) the account is: `deploy@wandb-production.iam.gserviceaccount.com`
* For [Dedicated Cloud](/platform/hosting/hosting-options/dedicated-cloud) the account is: `deploy@wandb-production.iam.gserviceaccount.com`

Keep a record of the bucket name. Next, [configure W&B for BYOB](#configure-byob).
</Tab>
Expand Down Expand Up @@ -375,7 +375,7 @@ For details, see [Create a blob storage container](https://learn.microsoft.com/e
If data in your bucket expires due to an [object lifecycle management policy](https://learn.microsoft.com/en-us/azure/storage/blobs/lifecycle-management-policy-configure?tabs=azure-portal), you may lose the ability to read the history of some runs.
</Note>

1. Generate a storage account access key and make a note of its name and the storage account name. If you are using [Dedicated Cloud](/platform/hosting/hosting-options/dedicated_cloud), share the storage account name and access key with your W&B team using a secure sharing mechanism.
1. Generate a storage account access key and make a note of its name and the storage account name. If you are using [Dedicated Cloud](/platform/hosting/hosting-options/dedicated-cloud), share the storage account name and access key with your W&B team using a secure sharing mechanism.

**Team level BYOB**:

Expand Down
Loading
Loading