Skip to main content

Enable ML Commons for Aiven for OpenSearch®

Configure ML Commons cluster settings for your Aiven for OpenSearch® service, and deploy a pretrained or externally hosted model.

For background on what ML Commons supports in Aiven for OpenSearch, see ML Commons for Aiven for OpenSearch.

Configure ML Commons cluster settings​

Configure the ML Commons cluster settings as advanced parameters on your Aiven for OpenSearch service. The following example sets ml_commons_only_run_on_ml_node to false, which is only needed on a plan without dedicated ML nodes.

  1. Log in to the Aiven Console.
  2. Click Services, then select your Aiven for OpenSearch service.
  3. Click Service settings. Scroll to the Advanced configuration section and click Configure.
  4. Click Add configuration options, then select an ml_commons_* option from the list.
  5. Set the value and click Save configuration.

The full list of ml_commons_* options, including their types and defaults, is in Advanced parameters for Aiven for OpenSearch.

Run ML tasks on the right nodes​

By default, ml_commons_only_run_on_ml_node is true, so ML tasks only run on nodes with the ml role.

  • If your service uses a cluster plan with dedicated ML nodes, leave this setting at its default so ML tasks run there instead of on data nodes.
  • If your service doesn't have dedicated ML nodes, set ml_commons_only_run_on_ml_node to false so ML tasks can run on data nodes.

Deploy a pretrained model​

To deploy an OpenSearch-provided pretrained model, use the ML Commons REST API through the standard OpenSearch API. Registering, deploying, and running predictions with a pretrained model follows the same steps as registering a pretrained model in OpenSearch.

Connect to an externally hosted model​

To connect to a model hosted outside your Aiven for OpenSearch service, such as a third-party LLM API:

  1. Add the endpoint of your model provider to ml_commons_trusted_connector_endpoints_regex.
  2. Create a connector and register a remote model using the OpenSearch connector blueprint for your model provider.

Restrict access to ML models and connectors​

By default, all service users have the ml_full_access role and can register, deploy, use, and delete any model or connector. To restrict which users can manage or use ML models and connectors:

  1. Enable OpenSearch Security management for your service.
  2. Set ml_commons_model_access_control_enabled, ml_commons_connector_access_control_enabled, or both to true.
  3. Map the ml_full_access and ml_readonly_access roles to specific backend roles using OpenSearch Security.

Redeploy models after node changes​

  • If some of a service's ml-role nodes (or data nodes, on plans without dedicated ML nodes) become unavailable, for example during a node replacement or plan change, affected models move to a PARTIALLY_DEPLOYED state. They redeploy automatically if ml_commons_model_auto_redeploy_enable is true (the default).
  • If all of those nodes become unavailable at once, for example during a power cycle, models move to DEPLOY_FAILED. Call _deploy for each model to make it available again.

ml_commons_model_auto_deploy_enable (true by default) only applies to externally hosted models that haven't been deployed yet: it deploys them automatically on their first prediction request. Pretrained built-in models always need an explicit _deploy call.

Related pages