mrkeyoor.com_
Mon 28 Sept 00:14 UTC
Automationevaluationupdated 18 Sept 2026

skypilot review

SkyPilot lets you describe an AI job once, then launch it on Kubernetes, Slurm, or a supported cloud through the same command line or Python API. It provisions compute, syncs code, runs setup commands, streams logs, and can stop idle resources, which saves teams from rebuilding the workflow for each provider.

+29stars / 7d
Verdict

Our SkyPilot run installed 372 packages and used 1,672 MB, then its tests stopped in 10 seconds because UID 1000 had no passwd entry. That cost is defensible for a team that repeatedly places expensive AI jobs across clouds or clusters and wants one task format. A single-cluster team should choose a narrower scheduler, especially while the installed tree carries 13 known vulnerabilities and the current automation issues remain open.

We ran it

Lab card: what happened when we ran skypilotScreenshot of skypilot (skypilot.ai)
Install✓ · 157s372 packages · 1672 MB
Build✓ · 6s
Tests✗ · 10sran, no count parsed
Known vulns13(pip-audit)
Repo2526 files~524,825 lines of source · 98.8 MB · 29 CI workflows · Dockerfile · tests dir

Answers from our run

Does skypilot build from source?

Dependencies installed in 157 seconds (372 packages), and the build succeeded in 6 seconds. We cloned commit fd13618 into a clean Debian container with 3 CPUs and no project-specific setup.

Do skypilot's tests pass?

The test command failed in our container, and its output did not report a pass or fail count.

Does skypilot have known vulnerabilities in its dependencies?

pip-audit flagged 13 known advisories in the dependency tree at the time of our run.

Who should not use skypilot?

Developers with one fixed cluster and a small deployment surface: our install pulled 372 packages and occupied 1,672 MB before any workload ran.

What are the alternatives to skypilot?

dstack, Ray, Kueue. Our SkyPilot run installed 372 packages and used 1,672 MB, then its tests stopped in 10 seconds because UID 1000 had no passwd entry.

Setup2/5157-second install; UID lookup stopped the tests
Docs5/5Clear install, provider, quota, API server, and task guides
Community5/510,617 stars and active September 2026 issue work
Maturity4/5v0.13.0 spans many providers; current issues still affect operators

Discussed on

  1. hnSkyPilot: One system to use and manage all AI compute (K8s, 20 clouds, Slurm)15 points
  2. hnChat with your PDFs – Self-hosted LocalGPT on any cloud6 points
  3. hnGuide: Finetune Llama 3.1 on your infra5 points
  4. hnShow HN: Run LLaMA LLM chatbots on any cloud with one click4 points
  5. hnRun Llama2 in your cloud, completely privately3 points

Who it’s for

AI teams that repeatedly move training, serving, or batch jobs between clouds and clusters.
Infrastructure teams offering shared GPU capacity through one API server and job interface.
Kubernetes or Slurm operators who want developers to submit portable YAML tasks instead of writing provider-specific launch scripts.
Teams willing to own cloud credentials, quotas, cost controls, and the behavior of every enabled provider.

Who it’s NOT for

Developers with one fixed cluster and a small deployment surface: our install pulled 372 packages and occupied 1,672 MB before any workload ran.
Strict containers whose numeric user has no passwd entry: our test command stopped when Python could not resolve UID 1000 through getpwuid().
Automation that assumes every JSON output path is clean: open issue 10713 shows sky status -o json writing colored prose before its JSON payload.
Teams that pass credentials through --env and cannot accept plaintext request records: open issue 10741 reports that those values are persisted without the redaction used for --secret.
Windows users who require a native documented path: the installation guide directs Windows users to WSL for the uv environment flow.

Setup reality

Our sandbox install succeeded in 157 seconds, adding 372 packages and using 1,672 MB. The build passed in 6 seconds. Tests failed with exit 4 after 10 seconds because getpass.getuser() could not find UID 1000 through getpwuid(). Pip-audit reported 13 known vulnerabilities.

The local route needs Python, pip inside the uv environment, and extra packages for each cloud. Useful launches also need provider credentials, enabled APIs, account quotas, and access to the requested hardware. Teams can instead connect a thin client to a remote SkyPilot API server.

SkyPilot runs resources inside your own accounts, VPCs, and clusters. That keeps ownership with you, along with IAM, networking, quota requests, idle-resource policy, and cloud bills. In a container that maps users only by numeric UID, resolve the passwd-entry assumption before relying on the test suite.

One task file reaches more than 20 infrastructure targets

SkyPilot's README lists Kubernetes, Slurm, and more than 20 cloud or infrastructure providers behind one task format. A YAML file states the requested CPU or accelerator, the files to copy, setup commands, and the command to run. The same job can then move when capacity, price, or hardware availability changes. For a team that regularly hunts for GPUs, that is a concrete reduction in provider-specific scripts.

Across those 20-plus targets, the abstraction reaches beyond provisioning. SkyPilot queues jobs, streams logs, retries capacity failures, and can stop idle resources. It also exposes a Python API and a shared API server for teams. Those features put it between the workload and every account it touches. You gain one control surface, while failures in IAM, quotas, storage mounts, networking, or provider adapters still belong to your operators.

What happened when we ran it

Our sandbox installed commit fd13618 in 157 seconds. The process added 372 packages and left 1,672 MB on disk. The source checkout was already 98.8 MB, with 2,526 files and about 524,825 lines of source. That is a large local tool before a model, dataset, container image, or cloud workload enters the picture. The repository also contained 29 CI workflow files, a Dockerfile, and a tests directory.

The build succeeded in 6 seconds. Tests then failed with exit code 4 after 10 seconds. The log ends inside generate_user_hash(): Python's getpass.getuser() called pwd.getpwuid(os.getuid()), and UID 1000 had no passwd entry. The log supports that narrow finding. It does not show a failed cloud integration or a broken scheduler, and it does not prove how the suite behaves when the user lookup succeeds.

Pip-audit reported 13 known vulnerabilities in the 372-package environment. The supplied measurement does not include names or severities, so we cannot rank the exposure from that number alone. It is still enough to require an audit review before this environment handles cloud credentials. These results came from an unprivileged Debian container with 3 CPUs, 8 GB of RAM, no secrets, and Python 3.12 on August 24, 2026.

The first launch needs credentials and hardware quota

The installation guide supports uv and pip, with Python versions extending through 3.13 in its current examples. The uv environment must include pip because SkyPilot uses it to build wheels during remote setup. Provider extras are installed separately, then sky check inspects credentials. A remote API server removes most local provider dependencies, though somebody still has to deploy and secure that server.

The README's sample asks for 8 A100 GPUs and warns that the account needs access to those instances. New cloud accounts may begin with low or zero GPU quota, according to the setup guide. SkyPilot is bring-your-own-cloud: resources stay in your accounts, VPCs, and clusters. Budget limits and autostop help, but they do not replace IAM review, quota requests, network policy, or billing alerts.

Version 0.13.0 adds another operating layer

Release v0.13.0, published July 22, 2026, added Sky Batch, Hugging Face storage, lifecycle hooks, a debug-dump command, and per-instance hourly cost caps. The same release expanded GKE Autopilot handling and changed API-server behavior. This is useful work for a platform team. It also shows why SkyPilot should be evaluated as infrastructure software rather than a disposable launch script.

Sky Batch splits data across worker pools and reuses workers between jobs. Lifecycle hooks run around autostop, preemption, or shutdown events. The debug dump collects logs, state, and configuration into a zip. Each feature can save operator time, and each deserves its own access policy. A diagnostic archive and automatically supplied API-server credentials are sensitive artifacts, especially on a shared deployment.

Two open issues affect scripts and secret handling

Open issue 10713, updated September 16, 2026, demonstrates sky status -o json writing a colored human message before an empty JSON array when a cluster is absent. The command exits 0, but a normal JSON parser fails on the extra line. If cleanup, monitoring, or deployment code consumes this output, reproduce the absent-cluster case before trusting the machine-readable flag.

Open issue 10741 reports that credentials passed with --env persist in plaintext request records, while --secret values receive client-side redaction. Issue 10742 reports a separate naming collision in which distinct display names can map to the same cloud resource name. Both reports were opened September 12, 2026 and include code paths or reproductions. Treat them as open reports to verify against the revision you plan to deploy.

The narrower alternatives remove one whole layer

SkyPilot's 372-package install buys a broader job-and-infrastructure layer than Ray or Kueue. Ray is the closer choice when distributed Python execution is the main job and compute already exists. Kueue fits teams committed to Kubernetes that need admission and queueing. dstack deserves a direct trial when cross-provider AI orchestration is still the requirement.

That choice depends on how often infrastructure placement changes. The repository had 10,617 stars, 127 open issues, and a last push on September 18, 2026, so maintenance is active despite a sizable issue queue. A team launching the same workload into AWS, GCP, and Kubernetes each month can justify this control plane. A team with one stable cluster should keep the 372 packages and 1,672 MB out of its path.

Alternatives

ProjectWhat it isPick it when
dstackA vendor-neutral orchestrator for AI workloads across clouds, Kubernetes, and bare metal.pick this instead when you want a closer cross-provider comparison with a container-centered workflow.
Ray gh↗A distributed Python runtime and set of libraries for scaling AI and data programs.pick this instead when the hard problem is distributed execution inside compute you already control.
Kueue gh↗A Kubernetes-native queue for batch, AI, and high-performance computing jobs.pick this instead when every workload already runs on Kubernetes and queueing is the missing layer.

Sources

  1. SkyPilot README
  2. SkyPilot installation guide
  3. SkyPilot v0.13.0 release notes
  4. Issue 10713: JSON output contains prose
  5. Issue 10741: env credentials in request records
  6. Issue 10742: cloud cluster name collisions

More automation reviews

runner-images · agent-fleet-manager · kargo · Rose · alchemy · laya · the whole board →