Promote v0.1.20 to production

This commit is contained in:
GPU Kitchen delivery
2026-09-29 12:59:25 +00:00
parent cd50796883
commit f5dfcbf583
3 changed files with 57 additions and 25 deletions
+33 -13
View File
@@ -682,7 +682,7 @@ cmd_install() {
render_worker_manifest() { render_worker_manifest() {
cat <<JSON cat <<JSON
{ {
"schemaVersion": 1, "schemaVersion": 2,
"image": "", "image": "",
"mode": "worker", "mode": "worker",
"cluster": "$(json_str "$CLUSTER")", "cluster": "$(json_str "$CLUSTER")",
@@ -698,7 +698,7 @@ JSON
# fresh render no longer carries it (a profile change drops GPUK_HSTS); any other # fresh render no longer carries it (a profile change drops GPUK_HSTS); any other
# key was pushed by the controller and is kept. Keep this list in step with # key was pushed by the controller and is kept. Keep this list in step with
# render_controller_manifest. # render_controller_manifest.
INSTALL_ENV_KEYS="NODE_ENV,GPUK_MODE,GPUK_CLUSTER,GPUK_SELF_ENROLL_FILE,NODE_DISPLAY_NAME,HF_HOME,GPUK_DATA_ROOT,GPUK_INSTALL_PROFILE,GPUK_HSTS,GPUK_SESSION_COOKIE_SECURE,GPUK_BOOTSTRAP_MUST_CHANGE,BACKEND_DOCKER_NETWORK,GPUK_PORT,GPUK_PUBLIC_PORT,GPUK_MTLS_PORT,GPUK_PUBLIC_MTLS_PORT,GPUK_LISTEN_ADDR,GPUK_PROXY_PUBLIC_PORT" INSTALL_ENV_KEYS="NODE_ENV,GPUK_MODE,GPUK_CLUSTER,GPUK_SELF_ENROLL_FILE,NODE_DISPLAY_NAME,HF_HOME,GPUK_DATA_ROOT,GPUK_INSTALL_PROFILE,GPUK_HSTS,GPUK_SESSION_COOKIE_SECURE,GPUK_BOOTSTRAP_MUST_CHANGE,BACKEND_DOCKER_NETWORK,GPUK_PORT,GPUK_PUBLIC_PORT,GPUK_MTLS_PORT,GPUK_PUBLIC_MTLS_PORT,GPUK_PROXY_PUBLIC_PORT"
# Write the manifest — or, when one exists, MERGE into it (INS-03). Re-running the # Write the manifest — or, when one exists, MERGE into it (INS-03). Re-running the
# installer is the update path, and the manifest is not ours alone: since the first # installer is the update path, and the manifest is not ours alone: since the first
@@ -776,29 +776,30 @@ render_controller_manifest() {
[ "$NETWORK" = "host" ] || EXTRA_ENV="$EXTRA_ENV,\"BACKEND_DOCKER_NETWORK\":\"$(json_str "$NETWORK")\"" [ "$NETWORK" = "host" ] || EXTRA_ENV="$EXTRA_ENV,\"BACKEND_DOCKER_NETWORK\":\"$(json_str "$NETWORK")\""
# Published != bound (INS-43). On a bridged network the container keeps the image's # Published != bound (INS-43). On a bridged network the container keeps the image's
# FIXED listeners — nginx 8080, worker mTLS 8443, gpuk-proxy 8200 — and the port # FIXED listeners — nginx 8080, worker mTLS 8443 — and the port flags only move the
# flags only move the HOST side of the publication; Settings -> Network moves it # HOST side of the publication; Settings -> Network moves it later by patching this
# later by patching this same manifest, so the container port must never become a # same manifest, so the container port must never become a variable. With host
# variable. With host networking nothing is published and the listeners themselves # networking nothing is published and the listeners themselves take the ports
# take the ports (core/published-ports.ts reads this back with the same rules; the # (core/published-ports.ts reads this back with the same rules).
# proxy port is GPUK_LISTEN_ADDR for the proxy, GPUK_PROXY_PUBLIC_PORT for what the # The inference port is neither: gpuk-proxy runs in its OWN container on the host
# backend shows — core/cluster-settings.ts proxyPublicPort). # network in both modes (PRX-84) and binds it itself — proxy.listenPort, which the
# daemon turns into the proxy's GPUK_LISTEN_ADDR. GPUK_PROXY_PUBLIC_PORT is what the
# backend shows (core/cluster-settings.ts proxyPublicPort).
PORTS_JSON="{}" PORTS_JSON="{}"
if [ "$NETWORK" = "host" ]; then if [ "$NETWORK" = "host" ]; then
EXTRA_ENV="$EXTRA_ENV,\"GPUK_PORT\":\"$(json_str "$HTTP_PORT")\"" EXTRA_ENV="$EXTRA_ENV,\"GPUK_PORT\":\"$(json_str "$HTTP_PORT")\""
EXTRA_ENV="$EXTRA_ENV,\"GPUK_MTLS_PORT\":\"$(json_str "$MTLS_PORT")\"" EXTRA_ENV="$EXTRA_ENV,\"GPUK_MTLS_PORT\":\"$(json_str "$MTLS_PORT")\""
EXTRA_ENV="$EXTRA_ENV,\"GPUK_LISTEN_ADDR\":\"0.0.0.0:$(json_str "$INFERENCE_PORT")\""
else else
EXTRA_ENV="$EXTRA_ENV,\"GPUK_PORT\":\"8080\"" EXTRA_ENV="$EXTRA_ENV,\"GPUK_PORT\":\"8080\""
EXTRA_ENV="$EXTRA_ENV,\"GPUK_PUBLIC_PORT\":\"$(json_str "$HTTP_PORT")\"" EXTRA_ENV="$EXTRA_ENV,\"GPUK_PUBLIC_PORT\":\"$(json_str "$HTTP_PORT")\""
EXTRA_ENV="$EXTRA_ENV,\"GPUK_PUBLIC_MTLS_PORT\":\"$(json_str "$MTLS_PORT")\"" EXTRA_ENV="$EXTRA_ENV,\"GPUK_PUBLIC_MTLS_PORT\":\"$(json_str "$MTLS_PORT")\""
PORTS_JSON="{\"8080\":$HTTP_PORT,\"8200\":$INFERENCE_PORT,\"8443\":$MTLS_PORT}" PORTS_JSON="{\"8080\":$HTTP_PORT,\"8443\":$MTLS_PORT}"
fi fi
EXTRA_ENV="$EXTRA_ENV,\"GPUK_PROXY_PUBLIC_PORT\":\"$(json_str "$INFERENCE_PORT")\"" EXTRA_ENV="$EXTRA_ENV,\"GPUK_PROXY_PUBLIC_PORT\":\"$(json_str "$INFERENCE_PORT")\""
cat <<JSON cat <<JSON
{ {
"schemaVersion": 1, "schemaVersion": 2,
"image": "$(json_str "$IMAGE")", "image": "$(json_str "$IMAGE")",
"containerName": "gpu-kitchen", "containerName": "gpu-kitchen",
"mode": "controller", "mode": "controller",
@@ -820,6 +821,10 @@ render_controller_manifest() {
"secretsRef": { "secretsRef": {
"ENCRYPTION_KEY": "$(json_str "$DATA_ROOT/secrets/encryption_key")", "ENCRYPTION_KEY": "$(json_str "$DATA_ROOT/secrets/encryption_key")",
"NODE_ID": "$(json_str "$DATA_ROOT/secrets/node_id")"$BOOTSTRAP_SECRET_JSON$CLAIM_SECRET_JSON "NODE_ID": "$(json_str "$DATA_ROOT/secrets/node_id")"$BOOTSTRAP_SECRET_JSON$CLAIM_SECRET_JSON
},
"proxy": {
"containerName": "gpu-kitchen-proxy",
"listenPort": $INFERENCE_PORT
} }
} }
JSON JSON
@@ -832,6 +837,13 @@ container_name() {
sed -n 's/.*"containerName"[[:space:]]*:[[:space:]]*"\([^"]*\)".*/\1/p' "$MANIFEST" 2>/dev/null | head -1 sed -n 's/.*"containerName"[[:space:]]*:[[:space:]]*"\([^"]*\)".*/\1/p' "$MANIFEST" 2>/dev/null | head -1
} }
# The proxy's own container (PRX-84): the second containerName of the manifest —
# the app container's comes first, the proxy section closes the document.
proxy_container_name() {
_pcn=$(sed -n 's/.*"containerName"[[:space:]]*:[[:space:]]*"\([^"]*\)".*/\1/p' "$MANIFEST" 2>/dev/null | sed -n 2p)
printf '%s' "${_pcn:-gpu-kitchen-proxy}"
}
manifest_data_root() { manifest_data_root() {
sed -n 's/.*"dataRoot"[[:space:]]*:[[:space:]]*"\([^"]*\)".*/\1/p' "$MANIFEST" 2>/dev/null | head -1 sed -n 's/.*"dataRoot"[[:space:]]*:[[:space:]]*"\([^"]*\)".*/\1/p' "$MANIFEST" 2>/dev/null | head -1
} }
@@ -1082,6 +1094,7 @@ cmd_status() {
if [ -n "$_img" ]; then if [ -n "$_img" ]; then
echo "app image : $_img" echo "app image : $_img"
echo "app cont. : $(docker inspect -f '{{.State.Status}}' "$(container_name)" 2>/dev/null || echo 'not running')" echo "app cont. : $(docker inspect -f '{{.State.Status}}' "$(container_name)" 2>/dev/null || echo 'not running')"
echo "proxy : $(docker inspect -f '{{.State.Status}} {{.State.Health.Status}}' "$(proxy_container_name)" 2>/dev/null || echo 'not running')"
else else
echo "role : worker (no app container)" echo "role : worker (no app container)"
fi fi
@@ -1295,6 +1308,7 @@ cmd_uninstall() {
esac esac
done done
_cn=$(container_name) _cn=$(container_name)
_pcn=$(proxy_container_name)
_root=$(manifest_data_root) _root=$(manifest_data_root)
systemctl disable --now "$SERVICE_NAME" 2>/dev/null || true systemctl disable --now "$SERVICE_NAME" 2>/dev/null || true
rm -f "$UNIT_DEST"; systemctl daemon-reload 2>/dev/null || true rm -f "$UNIT_DEST"; systemctl daemon-reload 2>/dev/null || true
@@ -1309,6 +1323,11 @@ cmd_uninstall() {
for _c in "$_cn" "$_cn-old" "$_cn-failed"; do for _c in "$_cn" "$_cn-old" "$_cn-failed"; do
docker rm -f "$_c" >/dev/null 2>&1 && echo "==> removed container $_c" docker rm -f "$_c" >/dev/null 2>&1 && echo "==> removed container $_c"
done done
# The proxy container and the generations a handover left (PRX-83).
for _c in "$_pcn" "$_pcn-next" "$_pcn-failed" \
$(docker ps -a --filter "name=^$_pcn-draining-" --format '{{.Names}}' 2>/dev/null); do
docker rm -f "$_c" >/dev/null 2>&1 && echo "==> removed container $_c"
done
fi fi
for _d in "$ETC_DIR" "$IDENTITY_DIR"; do for _d in "$ETC_DIR" "$IDENTITY_DIR"; do
case "$_d" in ""|/|/etc|/usr|/var) die "refusing to remove $_d" ;; esac case "$_d" in ""|/|/etc|/usr|/var) die "refusing to remove $_d" ;; esac
@@ -1341,7 +1360,8 @@ gpuk — GPU Kitchen host daemon (gpu-kitchen-worker)
gpuk install ... --dry-run Validate inputs and print the manifest without changing the host gpuk install ... --dry-run Validate inputs and print the manifest without changing the host
gpuk status Service state, enrollment, /health, app container status gpuk status Service state, enrollment, /health, app container status
gpuk enroll --controller wss://<host>:<port> --token gk_enroll_... gpuk enroll --controller wss://<host>:<port> --token gk_enroll_...
gpuk apply (controller) Reconcile the app container from the manifest gpuk apply (controller) Reconcile the app container, then the proxy container
by handover, from the manifest
gpuk update (controller) Move to the current release (pull + recreate, rollback) gpuk update (controller) Move to the current release (pull + recreate, rollback)
gpuk update --check (controller) Compare the installed version with the release gpuk update --check (controller) Compare the installed version with the release
gpuk update --version <tag> (controller) Move to a specific release gpuk update --version <tag> (controller) Move to a specific release
+21 -9
View File
@@ -1,14 +1,26 @@
{ {
"version": "v0.1.18", "version": "v0.1.20",
"semver": "0.1.18", "semver": "0.1.20",
"epoch": "0.1",
"contractRevision": "01bd9a2afdbe31317dc6457b2f14da65939719ce66b6909349d1920841da42f9",
"workerProtocolRevision": "82a46fb3cc34cb2c76939f29d5a81ba0964328e652181ef6594378ecdb1421ca",
"security": false,
"controllerMigrations": [
{ "tag": "0000_baseline", "hash": "fa8c006eee4721f4b8dafd56dfbac68ddff471feb9eef611b572010840645b74" },
{ "tag": "0001_schema_epoch", "hash": "ea428c2d25ce54c82ed358e7667ccb422cf23a3c09c4a4a55b41039e214adfc7" },
{ "tag": "0002_proxy_version", "hash": "63afece2501f332b5b8270de09835d9382c622bb9955c1d1a4c13d317ae9b4d6" },
{ "tag": "0003_installation_updates", "hash": "b879bde71949503153acd91a20f8a517d65599c016f58e9bd895c876e28e3d75" },
{ "tag": "0004_update_slot", "hash": "e252e03af080530b7b6000fd5c7f222224de5f7652dfead909ba89e897dc0598" },
{ "tag": "0005_feedback_lifecycle", "hash": "7a7c5f346d6ef2b470738ff669332bf05932c1a4ec7bde58ec0070e5d41818f6" }
],
"controllerImage": "repo.byterain.io/gpukitchen/gpukitchen-controller", "controllerImage": "repo.byterain.io/gpukitchen/gpukitchen-controller",
"controllerImageEnterprise": "repo.byterain.io/gpukitchen-private/gpukitchen-controller-ee", "controllerImageEnterprise": "repo.byterain.io/gpukitchen-private/gpukitchen-controller-ee",
"controllerImageDigest": "sha256:018b2f62519c2b8856022855dadff5cc43b6c23a70d0511e4475bb52fbc89df5", "controllerImageDigest": "sha256:bb472a9a4092f64faed79c3514a2223b5ea2e5feaad5ffb79f1307c6718442e1",
"controllerImageDigestEnterprise": "sha256:401e646d750d22102c4b5110418650bea551255b4fe830b99e789ac1a104aa54", "controllerImageDigestEnterprise": "sha256:d38f2739447c407e118b16b681c68c7124b9b0a52de01bdacb6a3178fa7129d1",
"gpukScriptSha256": "0e7acfa5d01ec83c4436304d166565937c1c682ebf5557b6d488f9a4192ba901", "gpukScriptSha256": "3dd5bcbb64fb7ac2b9f96fcda1545c4e6f5bed522bc5b6fde6b210bfacc774dc",
"workerBuildIdX86_64": "20260929011028-3858aae6ec272ae95a02c1860382802fedef55c9", "workerBuildIdX86_64": "20260929124008-2dcecac75e40e803ac237e61d4922d8845683f37",
"workerBuildIdAarch64": "20260929011028-3858aae6ec272ae95a02c1860382802fedef55c9", "workerBuildIdAarch64": "20260929124008-2dcecac75e40e803ac237e61d4922d8845683f37",
"workerBase": "https://repo.byterain.io/api/packages/gpukitchen/generic/gpu-kitchen-worker/v0.1.18", "workerBase": "https://repo.byterain.io/api/packages/gpukitchen/generic/gpu-kitchen-worker/v0.1.20",
"gpukScript": "https://repo.byterain.io/api/packages/gpukitchen/generic/gpu-kitchen-channel/v0.1.18/gpuk", "gpukScript": "https://repo.byterain.io/api/packages/gpukitchen/generic/gpu-kitchen-channel/v0.1.20/gpuk",
"releaseNotes": "https://repo.byterain.io/gpukitchen/channel" "releaseNotes": "https://repo.byterain.io/gpukitchen/channel"
} }
+3 -3
View File
@@ -1,4 +1,4 @@
untrusted comment: signature from minisign secret key untrusted comment: signature from minisign secret key
RUQ7BKXJqGX2jYPHJGXskiWTpLMBRffCSFrkWtpw8ijANWROGOzw6yUQoEV/HkogGFDnWfmPsvJTLrU1mYxUsdCy57uw/JCoPwI= RUQ7BKXJqGX2jYxPRWcqdjL5gFcsZ+YPIOeZ3WonbBijlxT/ldgD6CxmVs+zSxAiCAJh7kX5y2PtWhE2eHDSxqoYEfNS5lmwVw4=
trusted comment: gpu-kitchen channel v0.1.18 trusted comment: gpu-kitchen channel v0.1.20
OAAL3XLadiHW6lZ8PM3JBjVhSbyWANB0X4ERB1HOg4gzTg08EoiviEB55WCb8r1kNFwGAVZl18oHXejsoUy4Ag== q/jL+0dOYAqyLJe4eyRCGfDUKyFnVZk8UAq5COhPa4frEyYcw1CHtN5Fvom59zhR4lTA5UR1MDw8Sjb1kq77Dw==