Skip to main content
SUNK Standard A SUNK Anywhere deployment starts with the SUNK artifacts: the SUNK operator image and the sunk and slurm Helm charts. You authenticate to CoreWeave with an API access token, pull them, and configure your cluster to pull the operator image too. The deployment track for your provider lives in the coreweave/sunk-anywhere repository. This page covers the CoreWeave half: getting a token, pulling the artifacts, and configuring your cluster to pull images. For what SUNK Anywhere is and what you take on by running it, see About SUNK Anywhere.

Prerequisites

Step 1: Create an API access token

In the Cloud Console, create an API access token and copy the token secret. For the full procedure, see Manage API access tokens. The token secret is your registry password, and your username is the email address associated with the token.

Step 2: Log in with Docker

Authenticate Docker with your email address and token. Replace [EMAIL] with the email address associated with the token, and [API-ACCESS-TOKEN] with the token secret.
To verify the login, pull the SUNK operator image:
Pull the version you intend to deploy. Each SUNK release pairs with one Slurm version. For the full mapping, see SUNK to Slurm version mapping.

Step 3: Log in with Helm

Authenticate Helm against the same registry with the same credentials.
Pull both charts. The sunk chart installs the SUNK operator and its cluster-wide dependencies, and the slurm chart describes one Slurm cluster.

Step 4: Configure your cluster to pull images

Your Docker login authenticates you, not the cluster. Pods pull images with a Kubernetes secret, and a Pod can use only a secret in its own namespace. Create a docker-registry secret in each namespace that you install a chart into. In the repository’s tracks, the SUNK operator runs in sunk and the Slurm cluster runs in tenant-slurm, so you need two. If both charts share one namespace, one secret covers both. Replace [NAMESPACE], [EMAIL], and [API-ACCESS-TOKEN], and run the command once for each namespace.
By default, both charts pull the SUNK operator image from a CoreWeave-internal registry that clusters outside CoreWeave can’t reach, and neither chart sets a pull secret. Without the following values, the operator, Syncer, and scheduler Pods fail with ImagePullBackOff. In the sunk chart’s values, point the operator at the registry and give its Pod the secret:
In the slurm chart’s values, sunkImage covers the Syncer and scheduler, which run the operator image. imagePullSecrets covers the control plane and compute NodeSet Pods, but not login Pods, which pull the public Slurm images:
The Slurm images come from a public registry, so they need no override. Both charts also schedule the SUNK operator and the Slurm control plane only onto Nodes labeled node.coreweave.cloud/class=cpu. If your Nodes don’t carry that label, set operator.affinity in the sunk chart and slurmCluster.spec.affinity in the slurm chart, or those Pods stay Pending.

Step 5: Deploy SUNK

Clone the repository and follow the track for your provider.
The repository has a track for GKE, one for EKS, and a generic track for any other Kubernetes. Every track covers storage, monitoring, and user access, and the GKE and EKS tracks also cover your provider’s node pools. You can work through a track yourself, or open the repository in an AI coding agent and ask it to deploy on your provider. See Deploy with an agent and the repository README.
The repository’s tracks don’t use Steps 1 to 4. They install the charts from a Helm repository URL that CoreWeave sends you, rather than from the registry you logged in to in Step 3. The guides show that URL as <COREWEAVE_HELM_REPO_URL>, and the EKS scripts read it from the COREWEAVE_HELM_REPO environment variable. The tracks’ values files also target SUNK 7.x, not the charts you pulled in Step 3. If a track asks for that URL, or you want a track to deploy the charts from Step 3, contact CoreWeave at sunk@coreweave.com.

Next steps

Last modified on September 29, 2026