Promote v0.1.20 to production
This commit is contained in:
@@ -682,7 +682,7 @@ cmd_install() {
|
||||
render_worker_manifest() {
|
||||
cat <<JSON
|
||||
{
|
||||
"schemaVersion": 1,
|
||||
"schemaVersion": 2,
|
||||
"image": "",
|
||||
"mode": "worker",
|
||||
"cluster": "$(json_str "$CLUSTER")",
|
||||
@@ -698,7 +698,7 @@ JSON
|
||||
# fresh render no longer carries it (a profile change drops GPUK_HSTS); any other
|
||||
# key was pushed by the controller and is kept. Keep this list in step with
|
||||
# render_controller_manifest.
|
||||
INSTALL_ENV_KEYS="NODE_ENV,GPUK_MODE,GPUK_CLUSTER,GPUK_SELF_ENROLL_FILE,NODE_DISPLAY_NAME,HF_HOME,GPUK_DATA_ROOT,GPUK_INSTALL_PROFILE,GPUK_HSTS,GPUK_SESSION_COOKIE_SECURE,GPUK_BOOTSTRAP_MUST_CHANGE,BACKEND_DOCKER_NETWORK,GPUK_PORT,GPUK_PUBLIC_PORT,GPUK_MTLS_PORT,GPUK_PUBLIC_MTLS_PORT,GPUK_LISTEN_ADDR,GPUK_PROXY_PUBLIC_PORT"
|
||||
INSTALL_ENV_KEYS="NODE_ENV,GPUK_MODE,GPUK_CLUSTER,GPUK_SELF_ENROLL_FILE,NODE_DISPLAY_NAME,HF_HOME,GPUK_DATA_ROOT,GPUK_INSTALL_PROFILE,GPUK_HSTS,GPUK_SESSION_COOKIE_SECURE,GPUK_BOOTSTRAP_MUST_CHANGE,BACKEND_DOCKER_NETWORK,GPUK_PORT,GPUK_PUBLIC_PORT,GPUK_MTLS_PORT,GPUK_PUBLIC_MTLS_PORT,GPUK_PROXY_PUBLIC_PORT"
|
||||
|
||||
# Write the manifest — or, when one exists, MERGE into it (INS-03). Re-running the
|
||||
# installer is the update path, and the manifest is not ours alone: since the first
|
||||
@@ -776,29 +776,30 @@ render_controller_manifest() {
|
||||
[ "$NETWORK" = "host" ] || EXTRA_ENV="$EXTRA_ENV,\"BACKEND_DOCKER_NETWORK\":\"$(json_str "$NETWORK")\""
|
||||
|
||||
# Published != bound (INS-43). On a bridged network the container keeps the image's
|
||||
# FIXED listeners — nginx 8080, worker mTLS 8443, gpuk-proxy 8200 — and the port
|
||||
# flags only move the HOST side of the publication; Settings -> Network moves it
|
||||
# later by patching this same manifest, so the container port must never become a
|
||||
# variable. With host networking nothing is published and the listeners themselves
|
||||
# take the ports (core/published-ports.ts reads this back with the same rules; the
|
||||
# proxy port is GPUK_LISTEN_ADDR for the proxy, GPUK_PROXY_PUBLIC_PORT for what the
|
||||
# backend shows — core/cluster-settings.ts proxyPublicPort).
|
||||
# FIXED listeners — nginx 8080, worker mTLS 8443 — and the port flags only move the
|
||||
# HOST side of the publication; Settings -> Network moves it later by patching this
|
||||
# same manifest, so the container port must never become a variable. With host
|
||||
# networking nothing is published and the listeners themselves take the ports
|
||||
# (core/published-ports.ts reads this back with the same rules).
|
||||
# The inference port is neither: gpuk-proxy runs in its OWN container on the host
|
||||
# network in both modes (PRX-84) and binds it itself — proxy.listenPort, which the
|
||||
# daemon turns into the proxy's GPUK_LISTEN_ADDR. GPUK_PROXY_PUBLIC_PORT is what the
|
||||
# backend shows (core/cluster-settings.ts proxyPublicPort).
|
||||
PORTS_JSON="{}"
|
||||
if [ "$NETWORK" = "host" ]; then
|
||||
EXTRA_ENV="$EXTRA_ENV,\"GPUK_PORT\":\"$(json_str "$HTTP_PORT")\""
|
||||
EXTRA_ENV="$EXTRA_ENV,\"GPUK_MTLS_PORT\":\"$(json_str "$MTLS_PORT")\""
|
||||
EXTRA_ENV="$EXTRA_ENV,\"GPUK_LISTEN_ADDR\":\"0.0.0.0:$(json_str "$INFERENCE_PORT")\""
|
||||
else
|
||||
EXTRA_ENV="$EXTRA_ENV,\"GPUK_PORT\":\"8080\""
|
||||
EXTRA_ENV="$EXTRA_ENV,\"GPUK_PUBLIC_PORT\":\"$(json_str "$HTTP_PORT")\""
|
||||
EXTRA_ENV="$EXTRA_ENV,\"GPUK_PUBLIC_MTLS_PORT\":\"$(json_str "$MTLS_PORT")\""
|
||||
PORTS_JSON="{\"8080\":$HTTP_PORT,\"8200\":$INFERENCE_PORT,\"8443\":$MTLS_PORT}"
|
||||
PORTS_JSON="{\"8080\":$HTTP_PORT,\"8443\":$MTLS_PORT}"
|
||||
fi
|
||||
EXTRA_ENV="$EXTRA_ENV,\"GPUK_PROXY_PUBLIC_PORT\":\"$(json_str "$INFERENCE_PORT")\""
|
||||
|
||||
cat <<JSON
|
||||
{
|
||||
"schemaVersion": 1,
|
||||
"schemaVersion": 2,
|
||||
"image": "$(json_str "$IMAGE")",
|
||||
"containerName": "gpu-kitchen",
|
||||
"mode": "controller",
|
||||
@@ -820,6 +821,10 @@ render_controller_manifest() {
|
||||
"secretsRef": {
|
||||
"ENCRYPTION_KEY": "$(json_str "$DATA_ROOT/secrets/encryption_key")",
|
||||
"NODE_ID": "$(json_str "$DATA_ROOT/secrets/node_id")"$BOOTSTRAP_SECRET_JSON$CLAIM_SECRET_JSON
|
||||
},
|
||||
"proxy": {
|
||||
"containerName": "gpu-kitchen-proxy",
|
||||
"listenPort": $INFERENCE_PORT
|
||||
}
|
||||
}
|
||||
JSON
|
||||
@@ -832,6 +837,13 @@ container_name() {
|
||||
sed -n 's/.*"containerName"[[:space:]]*:[[:space:]]*"\([^"]*\)".*/\1/p' "$MANIFEST" 2>/dev/null | head -1
|
||||
}
|
||||
|
||||
# The proxy's own container (PRX-84): the second containerName of the manifest —
|
||||
# the app container's comes first, the proxy section closes the document.
|
||||
proxy_container_name() {
|
||||
_pcn=$(sed -n 's/.*"containerName"[[:space:]]*:[[:space:]]*"\([^"]*\)".*/\1/p' "$MANIFEST" 2>/dev/null | sed -n 2p)
|
||||
printf '%s' "${_pcn:-gpu-kitchen-proxy}"
|
||||
}
|
||||
|
||||
manifest_data_root() {
|
||||
sed -n 's/.*"dataRoot"[[:space:]]*:[[:space:]]*"\([^"]*\)".*/\1/p' "$MANIFEST" 2>/dev/null | head -1
|
||||
}
|
||||
@@ -1082,6 +1094,7 @@ cmd_status() {
|
||||
if [ -n "$_img" ]; then
|
||||
echo "app image : $_img"
|
||||
echo "app cont. : $(docker inspect -f '{{.State.Status}}' "$(container_name)" 2>/dev/null || echo 'not running')"
|
||||
echo "proxy : $(docker inspect -f '{{.State.Status}} {{.State.Health.Status}}' "$(proxy_container_name)" 2>/dev/null || echo 'not running')"
|
||||
else
|
||||
echo "role : worker (no app container)"
|
||||
fi
|
||||
@@ -1295,6 +1308,7 @@ cmd_uninstall() {
|
||||
esac
|
||||
done
|
||||
_cn=$(container_name)
|
||||
_pcn=$(proxy_container_name)
|
||||
_root=$(manifest_data_root)
|
||||
systemctl disable --now "$SERVICE_NAME" 2>/dev/null || true
|
||||
rm -f "$UNIT_DEST"; systemctl daemon-reload 2>/dev/null || true
|
||||
@@ -1309,6 +1323,11 @@ cmd_uninstall() {
|
||||
for _c in "$_cn" "$_cn-old" "$_cn-failed"; do
|
||||
docker rm -f "$_c" >/dev/null 2>&1 && echo "==> removed container $_c"
|
||||
done
|
||||
# The proxy container and the generations a handover left (PRX-83).
|
||||
for _c in "$_pcn" "$_pcn-next" "$_pcn-failed" \
|
||||
$(docker ps -a --filter "name=^$_pcn-draining-" --format '{{.Names}}' 2>/dev/null); do
|
||||
docker rm -f "$_c" >/dev/null 2>&1 && echo "==> removed container $_c"
|
||||
done
|
||||
fi
|
||||
for _d in "$ETC_DIR" "$IDENTITY_DIR"; do
|
||||
case "$_d" in ""|/|/etc|/usr|/var) die "refusing to remove $_d" ;; esac
|
||||
@@ -1341,7 +1360,8 @@ gpuk — GPU Kitchen host daemon (gpu-kitchen-worker)
|
||||
gpuk install ... --dry-run Validate inputs and print the manifest without changing the host
|
||||
gpuk status Service state, enrollment, /health, app container status
|
||||
gpuk enroll --controller wss://<host>:<port> --token gk_enroll_...
|
||||
gpuk apply (controller) Reconcile the app container from the manifest
|
||||
gpuk apply (controller) Reconcile the app container, then the proxy container
|
||||
by handover, from the manifest
|
||||
gpuk update (controller) Move to the current release (pull + recreate, rollback)
|
||||
gpuk update --check (controller) Compare the installed version with the release
|
||||
gpuk update --version <tag> (controller) Move to a specific release
|
||||
|
||||
Reference in New Issue
Block a user