This tutorial shows you how to deploy and serve a DeepSeek-V3.1-Base language model by using the vLLM framework. You deploy this model on a Google Kubernetes Engine (GKE) Enterprise edition autopilot cluster and consume a single A4 virtual machine (VM) that has 8 B200 GPUs.
This tutorial is intended for machine learning (ML) engineers, platform administrators and operators, and for data and AI specialists who are interested in using Kubernetes container orchestration capabilities to handle inference workloads.
Objectives
- Access DeepSeek-V3.1-Base by using Hugging Face.
- Prepare your environment.
- Create a GKE cluster in Autopilot mode.
- Create a Kubernetes secret for Hugging Face credentials.
- Create a Cloud Storage bucket.
- Download the model to your Cloud Storage bucket.
- Deploy a vLLM container to your GKE cluster.
- Interact with DeepSeek-V3.1-Base by using curl.
- Clean up.
Costs
This tutorial uses billable components of Google Cloud, including:
To generate a cost estimate based on your projected usage, use the Pricing Calculator.
Before you begin
- Sign in to your Google Cloud account. If you're new to Google Cloud, create an account to evaluate how our products perform in real-world scenarios. New customers also get $300 in free credits to run, test, and deploy workloads.
-
Install the Google Cloud CLI.
-
If you're using an external identity provider (IdP), you must first sign in to the gcloud CLI with your federated identity.
-
To initialize the gcloud CLI, run the following command:
gcloud init -
Create or select a Google Cloud project.
Roles required to select or create a project
- Select a project: Selecting a project doesn't require a specific IAM role—you can select any project that you've been granted a role on.
-
Create a project: To create a project, you need the Project Creator role
(
roles/resourcemanager.projectCreator), which contains theresourcemanager.projects.createpermission. Learn how to grant roles.
-
Create a Google Cloud project:
gcloud projects create PROJECT_ID
Replace
PROJECT_IDwith a name for the Google Cloud project you are creating. -
Select the Google Cloud project that you created:
gcloud config set project PROJECT_ID
Replace
PROJECT_IDwith your Google Cloud project name.
-
Verify that billing is enabled for your Google Cloud project.
Enable the required API:
Roles required to enable APIs
To enable APIs, you need the
serviceusage.services.enablepermission. If you created the project, then you likely already have this permission through the Owner role (roles/owner). Otherwise, you can get this permission through the Service Usage Admin role (roles/serviceusage.serviceUsageAdmin). Learn how to grant roles.gcloud services enable container.googleapis.com
-
Install the Google Cloud CLI.
-
If you're using an external identity provider (IdP), you must first sign in to the gcloud CLI with your federated identity.
-
To initialize the gcloud CLI, run the following command:
gcloud init -
Create or select a Google Cloud project.
Roles required to select or create a project
- Select a project: Selecting a project doesn't require a specific IAM role—you can select any project that you've been granted a role on.
-
Create a project: To create a project, you need the Project Creator role
(
roles/resourcemanager.projectCreator), which contains theresourcemanager.projects.createpermission. Learn how to grant roles.
-
Create a Google Cloud project:
gcloud projects create PROJECT_ID
Replace
PROJECT_IDwith a name for the Google Cloud project you are creating. -
Select the Google Cloud project that you created:
gcloud config set project PROJECT_ID
Replace
PROJECT_IDwith your Google Cloud project name.
-
Verify that billing is enabled for your Google Cloud project.
Enable the required API:
Roles required to enable APIs
To enable APIs, you need the
serviceusage.services.enablepermission. If you created the project, then you likely already have this permission through the Owner role (roles/owner). Otherwise, you can get this permission through the Service Usage Admin role (roles/serviceusage.serviceUsageAdmin). Learn how to grant roles.gcloud services enable container.googleapis.com
-
Grant roles to your user account. Run the following command once for each of the following IAM roles:
roles/container.admingcloud projects add-iam-policy-binding PROJECT_ID --member="user:USER_IDENTIFIER" --role=ROLE
Replace the following:
PROJECT_ID: Your project ID.USER_IDENTIFIER: The identifier for your user account. For example,myemail@example.com.ROLE: The IAM role that you grant to your user account.
- Sign in to or create a Hugging Face account.
Access DeepSeek by using Hugging Face
To use Hugging Face to access DeepSeek, do the following:
- Sign in to Hugging Face and explore the DeepSeek-V3.1-Base model.
- Create a Hugging Face
readaccess token. - Copy and save the
read accesstoken value. You use it later in this tutorial.
Prepare your environment
To prepare your environment, set the default environment variables:
Replace the following:
YOUR_PROJECT_ID: the ID of the Google Cloud project where you want to create the GKE cluster.YOUR_RESERVATION_URL: the URL of the reservation that you want to use to create your GKE cluster. Based on the project in which the reservation exists, specify one of the following values:The reservation exists in your project:
RESERVATION_NAMEThe reservation exists in a different project, and your project can use the reservation:
projects/RESERVATION_PROJECT_ID/reservations/RESERVATION_NAME
YOUR_REGION: the region where you want to create your GKE cluster. You can only create the cluster in the region where your reservation exists.YOUR_CLUSTER_NAME: the name of the GKE cluster to create.YOUR_GCS_BUCKET: the name of the Cloud Storage bucket where you download the model.YOUR_HF_TOKEN: the Hugging Face access token that you created in the previous section.NETWORK_NAME: the network that the GKE cluster uses. Specify one of the following values:If you created a custom network, then specify the name of your network.
Otherwise, specify
default.
SUBNETWORK_NAME: the subnetwork that the GKE cluster uses. Specify one of the following values:If you created a custom subnetwork, then specify the name of your subnetwork. You can only specify a subnetwork that exists in the same region as the reservation.
Otherwise, specify
default.
Create a GKE cluster in Autopilot mode
To create a GKE cluster in Autopilot mode, run the following command:
Creating the GKE cluster might take some time to complete. To verify that Google Cloud has finished creating your cluster, go to Kubernetes clusters on the Google Cloud console.
Create a Kubernetes secret for Hugging Face credentials
To create a Kubernetes secret for Hugging Face credentials, do the following:
Configure
kubectlto communicate with your GKE cluster:Create a Kubernetes secret to store your Hugging Face token:
Create a Cloud Storage bucket
If you want to use a new bucket to store the model, run the following:
Grant write permissions on the Cloud Storage bucket to the default service account:
If you want to use an existing Cloud Storage bucket, you can skip this step. However, you must ensure that your bucket is in the same region as your cluster and that the service account has the required write permissions to it.
Download the model to your Cloud Storage bucket
Create a
deepseek-download-job.yamlfile:Apply the
deepseek-download-job.yamlmanifest to initialize the download job:To see the completion status, run the following command:
The
--timeoutflag specifies how long the command monitors the job before timing out.The job resource downloads the
DeepSeek-V3.1-Basemodel weights from Hugging Face to your Google Cloud Storage bucket using SSD volume. The download takes around 40 minutes to complete. Once the download finishes, proceed to the next section to launch the model deployment.To delete the job, run the following command:
Deploy a vLLM container to your GKE cluster
After you've downloaded the model to your Cloud Storage bucket, deploy a vLLM container to your GKE cluster by completing the following steps:
Create a
vllm-deepseek3-1-base.yamlfile with your chosen vLLM deployment:Apply the
vllm-deepseek3-1-base.yamlfile to your GKE cluster:To see the completion status, run the following command:
The
--timeoutflag allows the command to monitor the deployment for the specified period of time.
Interact with DeepSeek-V3.1-Base by using curl
To verify the DeepSeek-V3.1-Base model that you deployed, do the following:
Set up port forwarding to DeepSeek-V3.1-Base:
Open a new terminal window. You can then chat with your model by using
curl:The output that you see is similar to the following:
{ "id": "chatcmpl-1a47172070544a5d83199ed5548befca", "object": "chat.completion", "created": 1755891024, "model": "deepseek-ai/DeepSeek-V3.1-Base", "choices": [ { "index": 0, "message": { "role": "assistant", "content": "\nGenerative AI uses patterns from existing data to create new, similar content, like text, images, or music.\n", "refusal": null, "annotations": null, "audio": null, "function_call": null, "tool_calls": [], "reasoning_content": null }, "logprobs": null, "finish_reason": "stop", "stop_reason": null } ], "service_tier": null, "system_fingerprint": null, "usage": { "prompt_tokens": 17, "total_tokens": 42, "completion_tokens": 25, "prompt_tokens_details": null }, "prompt_logprobs": null, "kv_transfer_params": null }
Observe the performance of the model
If you want to observe your model's performance, then you can use the vLLM dashboard integration in Cloud Monitoring. This dashboard helps you view critical performance metrics for your model like token throughput, network latency, and error rates. For information, see vLLM in the Monitoring documentation.
Clean up
To avoid incurring charges to your Google Cloud account for the resources used in this tutorial, either delete the project that contains the resources, or keep the project and delete the individual resources.
Delete the resources
After you've completed the tutorial, delete the resources that you don't need any longer:
To delete the deployment and service defined in the
vllm-deepseek3-1-base.yamlfile and the Kubernetes secret from the GKE cluster, run the following command:To delete your Cloud Storage bucket, run the following command:
To delete your GKE cluster, do the following:
Delete your project
Delete a Google Cloud project:
gcloud projects delete PROJECT_ID