release v0.1.8
This commit is contained in:
+51
-5
@@ -56,6 +56,10 @@ PORT="${GPUK_PORT:-1337}"
|
||||
MTLS_PORT="${GPUK_MTLS_PORT:-8443}"
|
||||
INFERENCE_PORT="${GPUK_INFERENCE_PORT:-8200}"
|
||||
CLUSTER="${GPUK_CLUSTER:-default}"
|
||||
# The app container's docker network. Empty = gpuk's default (bridge, INS-49);
|
||||
# an existing install keeps the mode it runs in (INS-03) — flipping the default
|
||||
# must never move a host-mode install to bridge on its next re-run.
|
||||
NETWORK="${GPUK_NETWORK:-}"
|
||||
# Which of those came from the operator (flag or env) — an existing install keeps
|
||||
# its own value for everything the operator did not ask to change (INS-03).
|
||||
PORT_GIVEN=0; [ -z "${GPUK_PORT:-}" ] || PORT_GIVEN=1
|
||||
@@ -64,6 +68,7 @@ INFERENCE_GIVEN=0; [ -z "${GPUK_INFERENCE_PORT:-}" ] || INFERENCE_GIVEN=1
|
||||
DATA_ROOT_GIVEN=0; [ -z "${GPUK_DATA_ROOT:-}" ] || DATA_ROOT_GIVEN=1
|
||||
CACHE_GIVEN=0; [ -z "${GPUK_CACHE_DIR:-}" ] || CACHE_GIVEN=1
|
||||
CLUSTER_GIVEN=0; [ -z "${GPUK_CLUSTER:-}" ] || CLUSTER_GIVEN=1
|
||||
NETWORK_GIVEN=0; [ -z "${GPUK_NETWORK:-}" ] || NETWORK_GIVEN=1
|
||||
# Where an existing install keeps its manifest. Same override as gpuk's, and for
|
||||
# the same reason: it is the only way to exercise the re-run path without root.
|
||||
ETC_DIR="${GPUK_ETC_DIR:-/etc/gpu-kitchen}"
|
||||
@@ -71,6 +76,7 @@ MANIFEST="$ETC_DIR/manifest.json"
|
||||
UNIT_DEST="${GPUK_UNIT_DEST:-/etc/systemd/system/gpu-kitchen-worker.service}"
|
||||
BIN_DEST="${GPUK_BIN_DEST:-/usr/local/bin/gpu-kitchen-worker}"
|
||||
PROFILE=""
|
||||
RESET_MANIFEST=0
|
||||
DOMAIN=""
|
||||
VERSION=""
|
||||
IMAGE=""
|
||||
@@ -124,10 +130,17 @@ Options:
|
||||
--data-root <path> Where the database and secrets live (default /var/lib/gpu-kitchen)
|
||||
--cache-dir <path> Model cache (default <data-root>/hf)
|
||||
--cluster <name> Cluster name workers join (default "default")
|
||||
--network <mode> bridge (default) | host. Bridged, only the three ports above
|
||||
touch the host; host makes every listener of the container a
|
||||
host-wide claim. An existing install keeps its mode.
|
||||
--profile <p> homelab | studio | enterprise | public (no flag + a terminal
|
||||
= the script asks; no flag + no terminal = first-run asks)
|
||||
--domain <d> Domain for the public profile: writes a filled TLS
|
||||
reverse-proxy example to <data-root>/caddy/Caddyfile
|
||||
--reset-manifest Rebuild /etc/gpu-kitchen/manifest.json from this run's settings
|
||||
when the daemon refuses the existing one (a field an older
|
||||
release wrote); the old file is archived beside it and what
|
||||
it carried that the rebuild does not is listed
|
||||
--non-interactive Never ask anything, even with a terminal attached
|
||||
--worker-binary <p> Use a locally-built gpu-kitchen-worker instead of downloading one
|
||||
--gpuk-script <p> Use a local copy of the gpuk installer
|
||||
@@ -150,9 +163,11 @@ while [ $# -gt 0 ]; do
|
||||
--data-root) DATA_ROOT="$2"; DATA_ROOT_GIVEN=1; shift 2 ;;
|
||||
--cache-dir) CACHE_DIR="$2"; CACHE_GIVEN=1; shift 2 ;;
|
||||
--cluster) CLUSTER="$2"; CLUSTER_GIVEN=1; shift 2 ;;
|
||||
--network) NETWORK="$2"; NETWORK_GIVEN=1; shift 2 ;;
|
||||
--profile) PROFILE="$2"; shift 2 ;;
|
||||
--domain) DOMAIN="$2"; shift 2 ;;
|
||||
--non-interactive) NON_INTERACTIVE=1; shift ;;
|
||||
--reset-manifest) RESET_MANIFEST=1; shift ;;
|
||||
--worker-binary) WORKER_BINARY="$2"; shift 2 ;;
|
||||
--gpuk-script) GPUK_SCRIPT="$2"; shift 2 ;;
|
||||
--skip-gpu-check) SKIP_GPU_CHECK=1; shift ;;
|
||||
@@ -177,6 +192,13 @@ case "$DOMAIN" in
|
||||
*[!A-Za-z0-9.-]*) die "--domain must be a bare domain name (got '$DOMAIN')" ;;
|
||||
esac
|
||||
|
||||
# bridge, host, or the name of a docker network gpuk hands to `docker create
|
||||
# --network` — never a value that could be read as another flag or as whitespace.
|
||||
case "$NETWORK" in
|
||||
""|bridge|host) ;;
|
||||
-*|*[!A-Za-z0-9_.-]*) die "--network must be bridge, host or a docker network name (got '$NETWORK')" ;;
|
||||
esac
|
||||
|
||||
for _pv in "$PORT" "$MTLS_PORT" "$INFERENCE_PORT"; do
|
||||
case "$_pv" in
|
||||
''|*[!0-9]*) die "not a port number: '$_pv'" ;;
|
||||
@@ -274,11 +296,17 @@ case "$EXISTING" in
|
||||
[ "$PORT_GIVEN" -eq 1 ] || PORT="$OURS_UI"
|
||||
[ "$MTLS_GIVEN" -eq 1 ] || MTLS_PORT="$OURS_MTLS"
|
||||
[ "$INFERENCE_GIVEN" -eq 1 ] || INFERENCE_PORT="$OURS_INF"
|
||||
# The network mode is a setting like the ports: an install that runs on the
|
||||
# host network stays there when the default is bridge (INS-49), and the
|
||||
# reverse — only --network moves it. An old manifest without the field is
|
||||
# read as the daemon reads it (host).
|
||||
[ "$NETWORK_GIVEN" -eq 1 ] || NETWORK="${C_NETMODE:-host}"
|
||||
case "$_profile" in
|
||||
homelab|studio|enterprise|public) [ -n "$PROFILE" ] || PROFILE="$_profile" ;;
|
||||
esac
|
||||
ok "data root $DATA_ROOT"
|
||||
ok "ports UI $OURS_UI, worker channel $OURS_MTLS, inference $OURS_INF"
|
||||
ok "network ${C_NETMODE:-host}"
|
||||
[ -z "$_profile" ] || ok "profile $_profile"
|
||||
ok "re-running updates it in place. Its settings are kept unless a flag says otherwise."
|
||||
;;
|
||||
@@ -606,6 +634,7 @@ if [ "$DRY_RUN" -eq 1 ]; then
|
||||
echo " UI port : $PORT"
|
||||
echo " worker channel: $MTLS_PORT"
|
||||
echo " inference : $INFERENCE_PORT"
|
||||
echo " network : ${NETWORK:-bridge}"
|
||||
case "$EXISTING" in
|
||||
manifest) echo " existing : yes — updated in place" ;;
|
||||
leftovers) echo " existing : traces of a previous install — taken over" ;;
|
||||
@@ -728,6 +757,10 @@ set -- install \
|
||||
|
||||
[ -z "$PROFILE" ] || set -- "$@" --profile "$PROFILE"
|
||||
[ -z "$DOMAIN" ] || set -- "$@" --domain "$DOMAIN"
|
||||
[ "$RESET_MANIFEST" -eq 0 ] || set -- "$@" --reset-manifest
|
||||
# Inherited from the manifest or given by flag; unset on a first install, so
|
||||
# gpuk's own default (bridge, INS-49) applies and this script never restates it.
|
||||
[ -z "$NETWORK" ] || set -- "$@" --network "$NETWORK"
|
||||
|
||||
if [ -n "$WORKER_BINARY" ]; then
|
||||
[ -f "$WORKER_BINARY" ] || die "no such worker binary: $WORKER_BINARY"
|
||||
@@ -741,7 +774,11 @@ fi
|
||||
# else: gpuk reuses an already-installed binary, or fails with its own message.
|
||||
|
||||
step "Installing — this pulls the image, so it can take a few minutes"
|
||||
sh "$GPUK_SCRIPT" "$@" || die "the install failed. See: journalctl -u gpu-kitchen-worker"
|
||||
# gpuk names its own failure on stderr before exiting (a refused manifest, a
|
||||
# failed apply, a missing binary…), so the cause is the line right above this
|
||||
# one. journalctl only has something to say once the daemon has started, and
|
||||
# gpuk points at `gpuk logs` itself in that case.
|
||||
sh "$GPUK_SCRIPT" "$@" || die "the install failed — gpuk reported the cause just above"
|
||||
|
||||
# ── 5. Wait for the app, then say where it is ────────────────────────────────
|
||||
step "Waiting for the controller to answer"
|
||||
@@ -776,10 +813,19 @@ else
|
||||
echo " ${BOLD}Claim code:${RESET} consumed (the first account already exists)"
|
||||
fi
|
||||
echo
|
||||
# The wizard's first step asks for a Kitchen ACCOUNT key (CPT-04). It is the
|
||||
# person's credential, never the machine's — this script cannot create or print
|
||||
# it, and the browser must not receive it in a URL (CPT-05/06). What it can do
|
||||
# is say so, and say where the key comes from, before the page does.
|
||||
echo " ${BOLD}Next:${RESET} open the URL above. Its first step asks for your GPU Kitchen account key"
|
||||
echo " (gpuk_…). Sign in to your GPU Kitchen account and create one under Install keys:"
|
||||
echo " https://gpu.kitchen/account#install-keys"
|
||||
echo " That key is yours, not this machine's: the installer never sees it,"
|
||||
echo " and the page exchanges it for a revocable installation token."
|
||||
|
||||
case "$PROFILE" in
|
||||
public)
|
||||
echo " ${BOLD}Next:${RESET} create the first administrator in the UI"
|
||||
echo " ${BOLD}Then:${RESET} create the first administrator in the UI"
|
||||
echo
|
||||
# The public profile REQUIRES a TLS reverse proxy (OPS-13, INS-47) — the UI
|
||||
# port speaks plain HTTP. The product cannot verify the proxy's presence
|
||||
@@ -799,15 +845,15 @@ case "$PROFILE" in
|
||||
echo
|
||||
;;
|
||||
enterprise)
|
||||
echo " ${BOLD}Next:${RESET} create the first administrator in the UI"
|
||||
echo " ${BOLD}Then:${RESET} create the first administrator in the UI"
|
||||
echo
|
||||
;;
|
||||
homelab|studio)
|
||||
echo " ${BOLD}Next:${RESET} finish first-run in the UI"
|
||||
echo " ${BOLD}Then:${RESET} finish first-run in the UI"
|
||||
echo
|
||||
;;
|
||||
"")
|
||||
echo " ${BOLD}Next:${RESET} choose an installation profile in the first-run assistant"
|
||||
echo " ${BOLD}Then:${RESET} choose an installation profile in the first-run assistant"
|
||||
echo
|
||||
;;
|
||||
esac
|
||||
|
||||
Reference in New Issue
Block a user