Classification service

Maturity: implemented

The service loads one immutable radio-frequency (RF) classification artifact before it starts accepting requests. It exposes two routes:

  • GET /health reports readiness plus the exact classification-artifact and pretraining-checkpoint identities. Its task_name identifies the classification problem and ordered label vocabulary, such as modulation_classification; task_artifact_sha256 identifies the exact loaded classifier artifact.

  • POST /classify accepts the same typed in-phase and quadrature (I/Q) request used by local inference and returns the same classification response.

Start the application from a source checkout with:

PYTHONPATH=src:. \
RFFM_CLASSIFICATION_ARTIFACT=<exact-local-artifact-path> \
RFFM_CLASSIFICATION_ARTIFACT_SHA256=<manifest-backed-sha256> \
python -m rffm.applications.classification_service

The SHA-256 value comes from the classification run manifest. Startup verifies the exact local bytes against that expected identity before the service becomes ready.

HOST defaults to 0.0.0.0 and PORT defaults to 8080. The inference container fixes the artifact path inside the image and binds its expected SHA-256 at build time, so a deployed process cannot silently switch classifiers after startup.

This is a single-artifact service. It does not provide a model registry, multi-model routing, rollout policy, autoscaling policy, or a production service-level objective.

Build and deploy

Cloud Build copies the validation-selected task artifact into the inference image before publishing it:

gcloud builds submit \
  --config infra/runtime/cloudbuild-inference-image.yaml \
  --substitutions \
_TASK_ARTIFACT_URI=gs://RUNS_BUCKET/RUN/task_artifact.pt,_TASK_ARTIFACT_SHA256=sha256:DIGEST,_IMAGE_URI=REGION-docker.pkg.dev/PROJECT/REPOSITORY/classifier:REVISION

The artifact URI and SHA-256 come from the run manifest. The Docker build verifies the copied bytes against that expected identity before publishing the image.

Read the published image digest from Artifact Registry. Deployment accepts that immutable digest, not the build tag:

export SERVICE_NAME=radioml2018-classifier
export PROJECT_ID=PROJECT
export SERVICE_ACCOUNT=inference@PROJECT.iam.gserviceaccount.com
export IMAGE_URI=REGION-docker.pkg.dev/PROJECT/REPOSITORY/classifier@sha256:DIGEST

infra/runtime/deploy_classification_service.sh

The deploy command prints the provider revision identity and exact health and classification endpoints. Retain those values with the immutable image digest.

The service is private. Supply an identity token through RFFM_CLASSIFY_BEARER_TOKEN when calling it.

Smoke-test the live service

Use the existing remote classification command to exercise authentication, HTTP request handling, artifact-backed inference, and response serialization:

RFFM_CLASSIFY_BEARER_TOKEN="$(gcloud auth print-identity-token)" \
./rffm classify \
  --endpoint https://SERVICE/classify \
  --request request.json

Successful output is the typed classification response. Retain the request and response with the provider revision, endpoint, and immutable image digest.

See Also