release v0.1.8

This commit is contained in:
gpuk-release
2026-09-18 00:11:58 +00:00
parent 983733003b
commit a9df4fbc1f
4 changed files with 168 additions and 26 deletions
+51 -5
View File
@@ -56,6 +56,10 @@ PORT="${GPUK_PORT:-1337}"
MTLS_PORT="${GPUK_MTLS_PORT:-8443}"
INFERENCE_PORT="${GPUK_INFERENCE_PORT:-8200}"
CLUSTER="${GPUK_CLUSTER:-default}"
# The app container's docker network. Empty = gpuk's default (bridge, INS-49);
# an existing install keeps the mode it runs in (INS-03) — flipping the default
# must never move a host-mode install to bridge on its next re-run.
NETWORK="${GPUK_NETWORK:-}"
# Which of those came from the operator (flag or env) — an existing install keeps
# its own value for everything the operator did not ask to change (INS-03).
PORT_GIVEN=0; [ -z "${GPUK_PORT:-}" ] || PORT_GIVEN=1
@@ -64,6 +68,7 @@ INFERENCE_GIVEN=0; [ -z "${GPUK_INFERENCE_PORT:-}" ] || INFERENCE_GIVEN=1
DATA_ROOT_GIVEN=0; [ -z "${GPUK_DATA_ROOT:-}" ] || DATA_ROOT_GIVEN=1
CACHE_GIVEN=0; [ -z "${GPUK_CACHE_DIR:-}" ] || CACHE_GIVEN=1
CLUSTER_GIVEN=0; [ -z "${GPUK_CLUSTER:-}" ] || CLUSTER_GIVEN=1
NETWORK_GIVEN=0; [ -z "${GPUK_NETWORK:-}" ] || NETWORK_GIVEN=1
# Where an existing install keeps its manifest. Same override as gpuk's, and for
# the same reason: it is the only way to exercise the re-run path without root.
ETC_DIR="${GPUK_ETC_DIR:-/etc/gpu-kitchen}"
@@ -71,6 +76,7 @@ MANIFEST="$ETC_DIR/manifest.json"
UNIT_DEST="${GPUK_UNIT_DEST:-/etc/systemd/system/gpu-kitchen-worker.service}"
BIN_DEST="${GPUK_BIN_DEST:-/usr/local/bin/gpu-kitchen-worker}"
PROFILE=""
RESET_MANIFEST=0
DOMAIN=""
VERSION=""
IMAGE=""
@@ -124,10 +130,17 @@ Options:
--data-root <path> Where the database and secrets live (default /var/lib/gpu-kitchen)
--cache-dir <path> Model cache (default <data-root>/hf)
--cluster <name> Cluster name workers join (default "default")
--network <mode> bridge (default) | host. Bridged, only the three ports above
touch the host; host makes every listener of the container a
host-wide claim. An existing install keeps its mode.
--profile <p> homelab | studio | enterprise | public (no flag + a terminal
= the script asks; no flag + no terminal = first-run asks)
--domain <d> Domain for the public profile: writes a filled TLS
reverse-proxy example to <data-root>/caddy/Caddyfile
--reset-manifest Rebuild /etc/gpu-kitchen/manifest.json from this run's settings
when the daemon refuses the existing one (a field an older
release wrote); the old file is archived beside it and what
it carried that the rebuild does not is listed
--non-interactive Never ask anything, even with a terminal attached
--worker-binary <p> Use a locally-built gpu-kitchen-worker instead of downloading one
--gpuk-script <p> Use a local copy of the gpuk installer
@@ -150,9 +163,11 @@ while [ $# -gt 0 ]; do
--data-root) DATA_ROOT="$2"; DATA_ROOT_GIVEN=1; shift 2 ;;
--cache-dir) CACHE_DIR="$2"; CACHE_GIVEN=1; shift 2 ;;
--cluster) CLUSTER="$2"; CLUSTER_GIVEN=1; shift 2 ;;
--network) NETWORK="$2"; NETWORK_GIVEN=1; shift 2 ;;
--profile) PROFILE="$2"; shift 2 ;;
--domain) DOMAIN="$2"; shift 2 ;;
--non-interactive) NON_INTERACTIVE=1; shift ;;
--reset-manifest) RESET_MANIFEST=1; shift ;;
--worker-binary) WORKER_BINARY="$2"; shift 2 ;;
--gpuk-script) GPUK_SCRIPT="$2"; shift 2 ;;
--skip-gpu-check) SKIP_GPU_CHECK=1; shift ;;
@@ -177,6 +192,13 @@ case "$DOMAIN" in
*[!A-Za-z0-9.-]*) die "--domain must be a bare domain name (got '$DOMAIN')" ;;
esac
# bridge, host, or the name of a docker network gpuk hands to `docker create
# --network` — never a value that could be read as another flag or as whitespace.
case "$NETWORK" in
""|bridge|host) ;;
-*|*[!A-Za-z0-9_.-]*) die "--network must be bridge, host or a docker network name (got '$NETWORK')" ;;
esac
for _pv in "$PORT" "$MTLS_PORT" "$INFERENCE_PORT"; do
case "$_pv" in
''|*[!0-9]*) die "not a port number: '$_pv'" ;;
@@ -274,11 +296,17 @@ case "$EXISTING" in
[ "$PORT_GIVEN" -eq 1 ] || PORT="$OURS_UI"
[ "$MTLS_GIVEN" -eq 1 ] || MTLS_PORT="$OURS_MTLS"
[ "$INFERENCE_GIVEN" -eq 1 ] || INFERENCE_PORT="$OURS_INF"
# The network mode is a setting like the ports: an install that runs on the
# host network stays there when the default is bridge (INS-49), and the
# reverse — only --network moves it. An old manifest without the field is
# read as the daemon reads it (host).
[ "$NETWORK_GIVEN" -eq 1 ] || NETWORK="${C_NETMODE:-host}"
case "$_profile" in
homelab|studio|enterprise|public) [ -n "$PROFILE" ] || PROFILE="$_profile" ;;
esac
ok "data root $DATA_ROOT"
ok "ports UI $OURS_UI, worker channel $OURS_MTLS, inference $OURS_INF"
ok "network ${C_NETMODE:-host}"
[ -z "$_profile" ] || ok "profile $_profile"
ok "re-running updates it in place. Its settings are kept unless a flag says otherwise."
;;
@@ -606,6 +634,7 @@ if [ "$DRY_RUN" -eq 1 ]; then
echo " UI port : $PORT"
echo " worker channel: $MTLS_PORT"
echo " inference : $INFERENCE_PORT"
echo " network : ${NETWORK:-bridge}"
case "$EXISTING" in
manifest) echo " existing : yes — updated in place" ;;
leftovers) echo " existing : traces of a previous install — taken over" ;;
@@ -728,6 +757,10 @@ set -- install \
[ -z "$PROFILE" ] || set -- "$@" --profile "$PROFILE"
[ -z "$DOMAIN" ] || set -- "$@" --domain "$DOMAIN"
[ "$RESET_MANIFEST" -eq 0 ] || set -- "$@" --reset-manifest
# Inherited from the manifest or given by flag; unset on a first install, so
# gpuk's own default (bridge, INS-49) applies and this script never restates it.
[ -z "$NETWORK" ] || set -- "$@" --network "$NETWORK"
if [ -n "$WORKER_BINARY" ]; then
[ -f "$WORKER_BINARY" ] || die "no such worker binary: $WORKER_BINARY"
@@ -741,7 +774,11 @@ fi
# else: gpuk reuses an already-installed binary, or fails with its own message.
step "Installing — this pulls the image, so it can take a few minutes"
sh "$GPUK_SCRIPT" "$@" || die "the install failed. See: journalctl -u gpu-kitchen-worker"
# gpuk names its own failure on stderr before exiting (a refused manifest, a
# failed apply, a missing binary…), so the cause is the line right above this
# one. journalctl only has something to say once the daemon has started, and
# gpuk points at `gpuk logs` itself in that case.
sh "$GPUK_SCRIPT" "$@" || die "the install failed — gpuk reported the cause just above"
# ── 5. Wait for the app, then say where it is ────────────────────────────────
step "Waiting for the controller to answer"
@@ -776,10 +813,19 @@ else
echo " ${BOLD}Claim code:${RESET} consumed (the first account already exists)"
fi
echo
# The wizard's first step asks for a Kitchen ACCOUNT key (CPT-04). It is the
# person's credential, never the machine's — this script cannot create or print
# it, and the browser must not receive it in a URL (CPT-05/06). What it can do
# is say so, and say where the key comes from, before the page does.
echo " ${BOLD}Next:${RESET} open the URL above. Its first step asks for your GPU Kitchen account key"
echo " (gpuk_…). Sign in to your GPU Kitchen account and create one under Install keys:"
echo " https://gpu.kitchen/account#install-keys"
echo " That key is yours, not this machine's: the installer never sees it,"
echo " and the page exchanges it for a revocable installation token."
case "$PROFILE" in
public)
echo " ${BOLD}Next:${RESET} create the first administrator in the UI"
echo " ${BOLD}Then:${RESET} create the first administrator in the UI"
echo
# The public profile REQUIRES a TLS reverse proxy (OPS-13, INS-47) — the UI
# port speaks plain HTTP. The product cannot verify the proxy's presence
@@ -799,15 +845,15 @@ case "$PROFILE" in
echo
;;
enterprise)
echo " ${BOLD}Next:${RESET} create the first administrator in the UI"
echo " ${BOLD}Then:${RESET} create the first administrator in the UI"
echo
;;
homelab|studio)
echo " ${BOLD}Next:${RESET} finish first-run in the UI"
echo " ${BOLD}Then:${RESET} finish first-run in the UI"
echo
;;
"")
echo " ${BOLD}Next:${RESET} choose an installation profile in the first-run assistant"
echo " ${BOLD}Then:${RESET} choose an installation profile in the first-run assistant"
echo
;;
esac