Promote v0.1.20 to production

This commit is contained in:
GPU Kitchen delivery
2026-09-29 12:59:25 +00:00
parent cd50796883
commit f5dfcbf583
3 changed files with 57 additions and 25 deletions
+33 -13
View File
@@ -682,7 +682,7 @@ cmd_install() {
render_worker_manifest() {
cat <<JSON
{
"schemaVersion": 1,
"schemaVersion": 2,
"image": "",
"mode": "worker",
"cluster": "$(json_str "$CLUSTER")",
@@ -698,7 +698,7 @@ JSON
# fresh render no longer carries it (a profile change drops GPUK_HSTS); any other
# key was pushed by the controller and is kept. Keep this list in step with
# render_controller_manifest.
INSTALL_ENV_KEYS="NODE_ENV,GPUK_MODE,GPUK_CLUSTER,GPUK_SELF_ENROLL_FILE,NODE_DISPLAY_NAME,HF_HOME,GPUK_DATA_ROOT,GPUK_INSTALL_PROFILE,GPUK_HSTS,GPUK_SESSION_COOKIE_SECURE,GPUK_BOOTSTRAP_MUST_CHANGE,BACKEND_DOCKER_NETWORK,GPUK_PORT,GPUK_PUBLIC_PORT,GPUK_MTLS_PORT,GPUK_PUBLIC_MTLS_PORT,GPUK_LISTEN_ADDR,GPUK_PROXY_PUBLIC_PORT"
INSTALL_ENV_KEYS="NODE_ENV,GPUK_MODE,GPUK_CLUSTER,GPUK_SELF_ENROLL_FILE,NODE_DISPLAY_NAME,HF_HOME,GPUK_DATA_ROOT,GPUK_INSTALL_PROFILE,GPUK_HSTS,GPUK_SESSION_COOKIE_SECURE,GPUK_BOOTSTRAP_MUST_CHANGE,BACKEND_DOCKER_NETWORK,GPUK_PORT,GPUK_PUBLIC_PORT,GPUK_MTLS_PORT,GPUK_PUBLIC_MTLS_PORT,GPUK_PROXY_PUBLIC_PORT"
# Write the manifest — or, when one exists, MERGE into it (INS-03). Re-running the
# installer is the update path, and the manifest is not ours alone: since the first
@@ -776,29 +776,30 @@ render_controller_manifest() {
[ "$NETWORK" = "host" ] || EXTRA_ENV="$EXTRA_ENV,\"BACKEND_DOCKER_NETWORK\":\"$(json_str "$NETWORK")\""
# Published != bound (INS-43). On a bridged network the container keeps the image's
# FIXED listeners — nginx 8080, worker mTLS 8443, gpuk-proxy 8200 — and the port
# flags only move the HOST side of the publication; Settings -> Network moves it
# later by patching this same manifest, so the container port must never become a
# variable. With host networking nothing is published and the listeners themselves
# take the ports (core/published-ports.ts reads this back with the same rules; the
# proxy port is GPUK_LISTEN_ADDR for the proxy, GPUK_PROXY_PUBLIC_PORT for what the
# backend shows — core/cluster-settings.ts proxyPublicPort).
# FIXED listeners — nginx 8080, worker mTLS 8443 — and the port flags only move the
# HOST side of the publication; Settings -> Network moves it later by patching this
# same manifest, so the container port must never become a variable. With host
# networking nothing is published and the listeners themselves take the ports
# (core/published-ports.ts reads this back with the same rules).
# The inference port is neither: gpuk-proxy runs in its OWN container on the host
# network in both modes (PRX-84) and binds it itself — proxy.listenPort, which the
# daemon turns into the proxy's GPUK_LISTEN_ADDR. GPUK_PROXY_PUBLIC_PORT is what the
# backend shows (core/cluster-settings.ts proxyPublicPort).
PORTS_JSON="{}"
if [ "$NETWORK" = "host" ]; then
EXTRA_ENV="$EXTRA_ENV,\"GPUK_PORT\":\"$(json_str "$HTTP_PORT")\""
EXTRA_ENV="$EXTRA_ENV,\"GPUK_MTLS_PORT\":\"$(json_str "$MTLS_PORT")\""
EXTRA_ENV="$EXTRA_ENV,\"GPUK_LISTEN_ADDR\":\"0.0.0.0:$(json_str "$INFERENCE_PORT")\""
else
EXTRA_ENV="$EXTRA_ENV,\"GPUK_PORT\":\"8080\""
EXTRA_ENV="$EXTRA_ENV,\"GPUK_PUBLIC_PORT\":\"$(json_str "$HTTP_PORT")\""
EXTRA_ENV="$EXTRA_ENV,\"GPUK_PUBLIC_MTLS_PORT\":\"$(json_str "$MTLS_PORT")\""
PORTS_JSON="{\"8080\":$HTTP_PORT,\"8200\":$INFERENCE_PORT,\"8443\":$MTLS_PORT}"
PORTS_JSON="{\"8080\":$HTTP_PORT,\"8443\":$MTLS_PORT}"
fi
EXTRA_ENV="$EXTRA_ENV,\"GPUK_PROXY_PUBLIC_PORT\":\"$(json_str "$INFERENCE_PORT")\""
cat <<JSON
{
"schemaVersion": 1,
"schemaVersion": 2,
"image": "$(json_str "$IMAGE")",
"containerName": "gpu-kitchen",
"mode": "controller",
@@ -820,6 +821,10 @@ render_controller_manifest() {
"secretsRef": {
"ENCRYPTION_KEY": "$(json_str "$DATA_ROOT/secrets/encryption_key")",
"NODE_ID": "$(json_str "$DATA_ROOT/secrets/node_id")"$BOOTSTRAP_SECRET_JSON$CLAIM_SECRET_JSON
},
"proxy": {
"containerName": "gpu-kitchen-proxy",
"listenPort": $INFERENCE_PORT
}
}
JSON
@@ -832,6 +837,13 @@ container_name() {
sed -n 's/.*"containerName"[[:space:]]*:[[:space:]]*"\([^"]*\)".*/\1/p' "$MANIFEST" 2>/dev/null | head -1
}
# The proxy's own container (PRX-84): the second containerName of the manifest —
# the app container's comes first, the proxy section closes the document.
proxy_container_name() {
_pcn=$(sed -n 's/.*"containerName"[[:space:]]*:[[:space:]]*"\([^"]*\)".*/\1/p' "$MANIFEST" 2>/dev/null | sed -n 2p)
printf '%s' "${_pcn:-gpu-kitchen-proxy}"
}
manifest_data_root() {
sed -n 's/.*"dataRoot"[[:space:]]*:[[:space:]]*"\([^"]*\)".*/\1/p' "$MANIFEST" 2>/dev/null | head -1
}
@@ -1082,6 +1094,7 @@ cmd_status() {
if [ -n "$_img" ]; then
echo "app image : $_img"
echo "app cont. : $(docker inspect -f '{{.State.Status}}' "$(container_name)" 2>/dev/null || echo 'not running')"
echo "proxy : $(docker inspect -f '{{.State.Status}} {{.State.Health.Status}}' "$(proxy_container_name)" 2>/dev/null || echo 'not running')"
else
echo "role : worker (no app container)"
fi
@@ -1295,6 +1308,7 @@ cmd_uninstall() {
esac
done
_cn=$(container_name)
_pcn=$(proxy_container_name)
_root=$(manifest_data_root)
systemctl disable --now "$SERVICE_NAME" 2>/dev/null || true
rm -f "$UNIT_DEST"; systemctl daemon-reload 2>/dev/null || true
@@ -1309,6 +1323,11 @@ cmd_uninstall() {
for _c in "$_cn" "$_cn-old" "$_cn-failed"; do
docker rm -f "$_c" >/dev/null 2>&1 && echo "==> removed container $_c"
done
# The proxy container and the generations a handover left (PRX-83).
for _c in "$_pcn" "$_pcn-next" "$_pcn-failed" \
$(docker ps -a --filter "name=^$_pcn-draining-" --format '{{.Names}}' 2>/dev/null); do
docker rm -f "$_c" >/dev/null 2>&1 && echo "==> removed container $_c"
done
fi
for _d in "$ETC_DIR" "$IDENTITY_DIR"; do
case "$_d" in ""|/|/etc|/usr|/var) die "refusing to remove $_d" ;; esac
@@ -1341,7 +1360,8 @@ gpuk — GPU Kitchen host daemon (gpu-kitchen-worker)
gpuk install ... --dry-run Validate inputs and print the manifest without changing the host
gpuk status Service state, enrollment, /health, app container status
gpuk enroll --controller wss://<host>:<port> --token gk_enroll_...
gpuk apply (controller) Reconcile the app container from the manifest
gpuk apply (controller) Reconcile the app container, then the proxy container
by handover, from the manifest
gpuk update (controller) Move to the current release (pull + recreate, rollback)
gpuk update --check (controller) Compare the installed version with the release
gpuk update --version <tag> (controller) Move to a specific release