Flyte
Kubernetes-native ML and data workflow orchestrator with first-class type safety, reproducibility, and multi-cloud support.
Flyte
Flyte is a production-grade workflow orchestration platform built by Lyft, Union.ai, and the open-source community. It models ML pipelines as strongly-typed Directed Acyclic Graphs (DAGs), with each task running as a containerized Kubernetes pod — giving full reproducibility, scalability, and multi-cloud portability.
Key Features
- Type-safe workflows — Python type hints on task inputs/outputs enforced at compile time and runtime
- Kubernetes-native — every task runs in its own pod; leverage GPU, TPU, Spark, Ray, or MPI backends
- Versioned artifacts — all executions, inputs, outputs, and code are stored and retrievable for reproducibility
- Dynamic workflows — fan-out, map tasks, and conditional branching in pure Python (no YAML required)
- Plugins — Spark, Ray, Dask, SageMaker, BigQuery, Snowflake, and 50+ integrations via
flytekit-plugins - UI — rich console with execution graphs, logs, and artifact lineage
- Multi-cloud — runs on AWS, GCP, Azure, and on-premises Kubernetes
Quick Start
pip install flytekit
flytectl demo start
from flytekit import task, workflow
@task
def say_hello(name: str) -> str:
return f"Hello, {name}!"
@workflow
def my_workflow(name: str = "world") -> str:
return say_hello(name=name)
Install via ai-supply
npx ai-supply add flyte-ml-workflow-orchestration
Curated mirror of the open-source Flyte (Apache-2.0). Get it from the source.
Compromise signals — malicious or tampered code (leaked secrets, backdoors, a dropped executable) — reduce the score, and known dependency CVEs carry a bounded penalty (they warrant review but never QUARANTINE — update the dependency to clear). Other dangerous-by-capability traits are risk surface, expected for some capabilities. Every finding is mapped to its OWASP control below.
Findings mapped to the OWASP Top 10 for LLM Applications (2025) and the OWASP Machine Learning Security Top 10. Expand any flagged control for the exact findings — compromise reduces the score; expected/risk-surface do not, except a known CVE, which carries a small bounded penalty (high/critical → Review).
The same gate an agent runs before installing (POST /api/v1/trust/flyte-ml-workflow-orchestration/check). Click a policy:
Consume Flyte programmatically. Authenticate with an API key or session — see Authorize an agent.
# Agents: CHECK BEFORE YOU INSTALL (no auth) — score, grade, level, capability manifest
curl https://ai-supply.store/api/v1/trust/flyte-ml-workflow-orchestration
# Gate against your org policy (returns { pass, violations })
curl -X POST https://ai-supply.store/api/v1/trust/flyte-ml-workflow-orchestration/check \
-H "Content-Type: application/json" \
-d '{"minGrade":"B","denyPermissions":["shell"],"denyUnknownEgress":true}'
# CLI
npx ai-supply add flyte-ml-workflow-orchestration
# REST (install → download)
curl -X POST https://ai-supply.store/api/v1/listings/flyte-ml-workflow-orchestration/install \
-H "Authorization: Bearer $AIM_KEY"
# MCP tool
install_listing({ "slug": "flyte-ml-workflow-orchestration" })OpenAPI spec →Curated mirror — latest upstream source. See the repository for tagged releases.