Repository navigation
468 lines (427 loc) · 17.6 KB
/
Copy pathrelease-canary.yml
File metadata and controls
468 lines (427 loc) · 17.6 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
435
436
437
438
439
440
441
442
443
444
445
446
447
448
449
450
451
452
453
454
455
456
457
458
459
460
461
462
463
464
465
466
467
468
name: Release Canary
on:
workflow_dispatch:
workflow_run:
workflows: ["Release Dev"]
types: [completed]
permissions:
actions: read
contents: read
defaults:
run:
shell: bash
env:
OPENSHELL_VERSION: dev
OPENSHELL_TELEMETRY_ENABLED: "false"
jobs:
macos:
name: macOS Homebrew
if: ${{ github.event_name == 'workflow_dispatch' || github.event.workflow_run.conclusion == 'success' }}
runs-on: macos-latest-xlarge
timeout-minutes: 20
steps:
- name: Ensure VM driver
run: |
launchctl setenv OPENSHELL_COMPUTE_DRIVER vm
launchctl setenv OPENSHELL_TELEMETRY_ENABLED "$OPENSHELL_TELEMETRY_ENABLED"
- name: Install and check gateway status
run: |
set -euo pipefail
curl -LsSf https://raw.githubusercontent.com/NVIDIA/OpenShell/${{ github.event.workflow_run.head_sha || github.sha }}/install.sh | sh
openshell --version
openshell status
# GitHub-hosted macOS runners do not expose the Hypervisor.framework
# support libkrun needs. Sandbox launch is covered by the VM E2E lane.
- name: Collect Homebrew diagnostics
if: failure()
run: |
set +e
brew services info openshell
for log in \
"$(brew --prefix)/var/log/openshell/openshell-gateway.out.log" \
"$(brew --prefix)/var/log/openshell/openshell-gateway.err.log"; do
if [ -f "$log" ]; then
echo "--- $log ---"
tail -n 300 "$log"
fi
done
ubuntu-deb:
name: Ubuntu DEB
if: ${{ github.event_name == 'workflow_dispatch' || github.event.workflow_run.conclusion == 'success' }}
runs-on: ubuntu-latest
timeout-minutes: 20
steps:
- name: Remove snapd
run: |
set -euo pipefail
snaps=$(snap list 2>/dev/null | awk 'NR > 1 { print $1 }')
if [ -n "$snaps" ]; then
sudo snap remove $snaps
fi
sudo apt-get -y --purge remove snapd
! command -v snap >/dev/null 2>&1
- name: Ensure Docker
run: |
if ! command -v docker >/dev/null 2>&1; then
sudo apt-get update
sudo apt-get install -y docker.io
fi
sudo systemctl start docker || sudo service docker start
mkdir -p "${HOME}/.config/openshell"
printf 'OPENSHELL_COMPUTE_DRIVER=docker\nOPENSHELL_TELEMETRY_ENABLED=%s\n' \
"$OPENSHELL_TELEMETRY_ENABLED" > "${HOME}/.config/openshell/gateway.env"
docker info
- name: Install and check status
run: |
set -euo pipefail
curl -LsSf https://raw.githubusercontent.com/NVIDIA/OpenShell/${{ github.event.workflow_run.head_sha || github.sha }}/install.sh | sh
openshell status
sandbox="rc-${GITHUB_RUN_ID}"
openshell sandbox create --name "$sandbox" --detach
openshell sandbox exec --name "$sandbox" --no-tty -- true
openshell sandbox delete "$sandbox"
fedora:
name: Fedora RPM
if: ${{ github.event_name == 'workflow_dispatch' || github.event.workflow_run.conclusion == 'success' }}
runs-on: linux-amd64-cpu8
timeout-minutes: 20
env:
FEDORA_CANARY_CONTAINER: openshell-fedora-canary-${{ github.run_id }}-${{ github.run_attempt }}
steps:
- name: Start Fedora systemd container and root user manager
run: |
set -euo pipefail
docker run --detach \
--name "${FEDORA_CANARY_CONTAINER}" \
--privileged \
--cgroupns=host \
--tmpfs /run \
--tmpfs /tmp \
--volume /sys/fs/cgroup:/sys/fs/cgroup:rw \
fedora:latest \
bash -lc 'dnf install -y curl dbus-daemon podman systemd && exec /usr/sbin/init'
for _ in $(seq 1 120); do
if docker exec "${FEDORA_CANARY_CONTAINER}" systemctl list-units --no-pager >/dev/null 2>&1; then
break
fi
if [ "$(docker inspect -f '{{.State.Running}}' "${FEDORA_CANARY_CONTAINER}")" != "true" ]; then
echo "::error::Fedora systemd container exited before systemd became reachable"
docker logs "${FEDORA_CANARY_CONTAINER}" >&2 || true
exit 1
fi
sleep 1
done
if ! docker exec "${FEDORA_CANARY_CONTAINER}" systemctl list-units --no-pager >/dev/null 2>&1; then
echo "::error::Fedora systemd container did not become reachable within 120s"
docker logs "${FEDORA_CANARY_CONTAINER}" >&2 || true
exit 1
fi
docker exec --interactive "${FEDORA_CANARY_CONTAINER}" env \
HOME=/root \
XDG_RUNTIME_DIR=/run/user/0 \
DBUS_SESSION_BUS_ADDRESS=unix:path=/run/user/0/bus \
bash -s <<'EOF'
set -euo pipefail
# install.sh manages the RPM gateway as a systemd user unit. This
# container is booted with systemd as PID 1, but it still has no
# login session. Start root's user manager explicitly so the
# installer can test service restart and gateway registration
# instead of its "restart later" fallback.
mkdir -p "${XDG_RUNTIME_DIR}"
chmod 700 "${XDG_RUNTIME_DIR}"
systemctl start user-runtime-dir@0.service || true
systemctl start user@0.service
for _ in $(seq 1 30); do
if systemctl --user daemon-reload; then
break
fi
sleep 1
done
if ! systemctl --user daemon-reload; then
systemctl status user@0.service --no-pager >&2 || true
journalctl -u user@0.service --no-pager -n 80 >&2 || true
systemctl --user status --no-pager >&2 || true
exit 1
fi
EOF
- name: Install and check status
run: |
set -euo pipefail
docker exec --interactive "${FEDORA_CANARY_CONTAINER}" env \
HOME=/root \
XDG_RUNTIME_DIR=/run/user/0 \
DBUS_SESSION_BUS_ADDRESS=unix:path=/run/user/0/bus \
OPENSHELL_VERSION="$OPENSHELL_VERSION" \
OPENSHELL_TELEMETRY_ENABLED="$OPENSHELL_TELEMETRY_ENABLED" \
CANARY_SANDBOX="rc-${GITHUB_RUN_ID}" \
INSTALL_SH_URL="https://raw.githubusercontent.com/NVIDIA/OpenShell/${{ github.event.workflow_run.head_sha || github.sha }}/install.sh" \
bash -s <<'EOF'
set -euo pipefail
mkdir -p "${HOME}/.config/openshell"
printf 'OPENSHELL_COMPUTE_DRIVER=podman\nOPENSHELL_TELEMETRY_ENABLED=%s\n' \
"$OPENSHELL_TELEMETRY_ENABLED" > "${HOME}/.config/openshell/gateway.env"
podman info
curl -LsSf "${INSTALL_SH_URL}" | sh
openshell status
openshell sandbox create --name "$CANARY_SANDBOX" --detach
openshell sandbox exec --name "$CANARY_SANDBOX" --no-tty -- true
openshell sandbox delete "$CANARY_SANDBOX"
EOF
- name: Stop Fedora systemd container
if: always()
run: |
docker rm -f "${FEDORA_CANARY_CONTAINER}" >/dev/null 2>&1 || true
ubuntu-snap-system-docker:
name: Ubuntu Snap with system Docker
if: ${{ github.event_name == 'workflow_dispatch' || github.event.workflow_run.conclusion == 'success' }}
runs-on: ubuntu-latest
env:
OPENSHELL_INSTALL_METHOD: snap
timeout-minutes: 20
steps:
- name: Install snapd
run: |
set -euo pipefail
sudo apt-get update
sudo apt-get install -y snapd
sudo systemctl enable --now snapd.socket
sudo systemctl start snapd
sudo snap wait system seed.loaded
- name: Ensure Docker
run: |
set -euo pipefail
if ! command -v docker >/dev/null 2>&1; then
sudo apt-get update
sudo apt-get install -y docker.io
fi
sudo systemctl start docker || sudo service docker start
docker info
- name: Install and check status
run: |
set -euo pipefail
sudo systemctl set-environment \
"OPENSHELL_TELEMETRY_ENABLED=${OPENSHELL_TELEMETRY_ENABLED}"
curl -LsSf https://raw.githubusercontent.com/NVIDIA/OpenShell/${{ github.event.workflow_run.head_sha || github.sha }}/install.sh | sh
sudo snap list openshell
if sudo snap list docker >/dev/null 2>&1; then
echo "install.sh unexpectedly installed the Docker snap" >&2
exit 1
fi
snap info openshell | grep -E '^tracking: +latest/edge$'
docker info
sudo snap connections openshell | grep -E '^docker +openshell:docker +:docker +'
openshell --version
openshell.prover --version
sudo snap services openshell
sudo journalctl -b -u snap.openshell.gateway.service --no-pager |
grep -F "mTLS user authentication enabled"
openshell gateway list | grep -F "https://127.0.0.1:17670"
openshell status
- name: Check a policy boundary with the Snap prover
run: |
set -euo pipefail
prover_dir=$(mktemp -d "$HOME/openshell-prover-canary.XXXXXX")
trap 'rm -rf "$prover_dir"' EXIT
cat >"$prover_dir/boundary.yaml" <<'EOF'
version: 1
filesystem_policy:
read_only:
- /usr
- /etc
EOF
cat >"$prover_dir/candidate.yaml" <<'EOF'
version: 1
filesystem_policy:
read_only:
- /usr
EOF
result=$(openshell.prover check "$prover_dir/candidate.yaml" \
--boundary "$prover_dir/boundary.yaml")
grep -q '^result: within_boundary$' <<<"$result"
- name: Create and exercise a sandbox
run: |
set -euo pipefail
sandbox="rc-${GITHUB_RUN_ID}"
openshell sandbox create --name "$sandbox" --detach
openshell sandbox exec --name "$sandbox" --no-tty -- true
openshell sandbox delete "$sandbox"
- name: Collect Snap diagnostics
if: failure()
run: |
set +e
docker info
sudo systemctl status docker.service --no-pager
sudo journalctl -b -u docker.service --no-pager -n 300
sudo snap services openshell
sudo snap connections openshell
sudo snap changes
sudo systemctl status snap.openshell.gateway.service --no-pager
sudo journalctl -b -u snap.openshell.gateway.service --no-pager -n 300
sudo journalctl -b -u snapd.service --no-pager -n 300
sudo snap logs openshell.gateway -n=300
sudo ss -ltnp '( sport = :17670 )'
ubuntu-snap-docker-preflight:
name: Ubuntu Snap Docker preflight
if: ${{ github.event_name == 'workflow_dispatch' || github.event.workflow_run.conclusion == 'success' }}
runs-on: ubuntu-latest
env:
OPENSHELL_INSTALL_METHOD: snap
timeout-minutes: 20
steps:
- name: Install snapd
run: |
set -euo pipefail
sudo apt-get update
sudo apt-get install -y snapd
sudo systemctl enable --now snapd.socket
sudo systemctl start snapd
sudo snap wait system seed.loaded
- name: Remove system Docker
run: |
set -euo pipefail
sudo systemctl stop docker.service docker.socket 2>/dev/null || true
sudo apt-get -y --purge remove docker-ce docker-ce-cli containerd.io \
docker-buildx-plugin docker-compose-plugin docker.io 2>/dev/null || true
! command -v docker >/dev/null 2>&1
- name: Verify installer rejects missing Docker
run: |
set -euo pipefail
curl -LsSf https://raw.githubusercontent.com/NVIDIA/OpenShell/${{ github.event.workflow_run.head_sha || github.sha }}/install.sh -o install.sh
if OPENSHELL_VERSION=dev sh install.sh >install.log 2>&1; then
echo "install.sh unexpectedly succeeded without Docker" >&2
cat install.log >&2
exit 1
fi
cat install.log
grep -F "Docker is required before installing the OpenShell snap" install.log
! sudo snap list docker >/dev/null 2>&1
! sudo snap list openshell >/dev/null 2>&1
- name: Verify installer rejects Docker snap
run: |
set -euo pipefail
sudo snap install docker
if OPENSHELL_VERSION=dev sh install.sh >docker-snap.log 2>&1; then
echo "install.sh unexpectedly succeeded with the Docker snap" >&2
cat docker-snap.log >&2
exit 1
fi
cat docker-snap.log
grep -F "the Docker snap is not currently compatible with OpenShell" docker-snap.log
sudo snap list docker >/dev/null
! sudo snap list openshell >/dev/null 2>&1
- name: Collect Snap diagnostics
if: failure()
run: |
set +e
cat install.log
cat docker-snap.log
sudo snap changes
sudo journalctl -b -u snapd.service --no-pager -n 300
kubernetes:
name: Kubernetes Helm (kind)
if: ${{ github.event_name == 'workflow_dispatch' || github.event.workflow_run.conclusion == 'success' }}
runs-on: ubuntu-latest
timeout-minutes: 20
env:
KIND_CLUSTER_NAME: release-canary-${{ github.run_id }}
RELEASE_NAME: openshell
RELEASE_NAMESPACE: openshell
KIND_GATEWAY_NAME: kind
AGENT_SANDBOX_VERSION: v1.0.3
steps:
- name: Checkout Agent Sandbox helper
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
sparse-checkout: |
e2e/support/install-agent-sandbox.sh
sparse-checkout-cone-mode: false
persist-credentials: false
- name: Install Helm
uses: azure/setup-helm@9bc31f4ebc9c6b171d7bfbaa5d006ae7abdb4310 # v5.0.1
- name: Create kind cluster
uses: helm/kind-action@ef37e7f390d99f746eb8b610417061a60e82a6cc # v1.14.0
with:
cluster_name: ${{ env.KIND_CLUSTER_NAME }}
wait: 120s
- name: Install Agent Sandbox controller
run: bash e2e/support/install-agent-sandbox.sh
- name: Install OpenShell Helm chart from GHCR OCI
run: |
set -euo pipefail
helm install "$RELEASE_NAME" oci://ghcr.io/nvidia/openshell/helm-chart \
--version 0.0.0-dev \
--namespace "$RELEASE_NAMESPACE" --create-namespace \
--set server.disableTls=true \
--set server.auth.allowUnauthenticatedUsers=true \
--set "server.telemetryEnabled=${OPENSHELL_TELEMETRY_ENABLED}" \
--wait --timeout 5m
- name: Verify gateway pod is Ready
run: |
set -euo pipefail
kubectl wait --namespace "$RELEASE_NAMESPACE" \
--for=condition=Ready pod \
--selector="app.kubernetes.io/name=openshell,app.kubernetes.io/instance=${RELEASE_NAME}" \
--timeout=300s
- name: Port-forward gateway service
run: |
set -euo pipefail
nohup kubectl port-forward --namespace "$RELEASE_NAMESPACE" \
"svc/${RELEASE_NAME}" 8080:8080 \
> port-forward.log 2>&1 &
echo $! > port-forward.pid
for _ in $(seq 1 30); do
if (echo > /dev/tcp/127.0.0.1/8080) >/dev/null 2>&1; then
echo "port-forward is reachable"
exit 0
fi
sleep 1
done
echo "port-forward did not become reachable" >&2
cat port-forward.log >&2
exit 1
- name: Remove snapd
run: |
set -euo pipefail
snaps=$(snap list 2>/dev/null | awk 'NR > 1 { print $1 }')
if [ -n "$snaps" ]; then
sudo snap remove $snaps
fi
sudo apt-get -y --purge remove snapd
! command -v snap >/dev/null 2>&1
- name: Install OpenShell CLI
run: |
set -euo pipefail
mkdir -p "${HOME}/.config/openshell"
printf 'OPENSHELL_COMPUTE_DRIVER=docker\n' > "${HOME}/.config/openshell/gateway.env"
curl -LsSf https://raw.githubusercontent.com/NVIDIA/OpenShell/${{ github.event.workflow_run.head_sha || github.sha }}/install.sh | sh
- name: Register kind gateway and check status
run: |
set -euo pipefail
openshell gateway add http://127.0.0.1:8080 --local --name "$KIND_GATEWAY_NAME"
openshell status
sandbox="rc-${GITHUB_RUN_ID}"
openshell sandbox create --name "$sandbox" --detach
openshell sandbox exec --name "$sandbox" --no-tty -- true
openshell sandbox delete "$sandbox"
- name: Diagnostics on failure
if: failure()
run: |
set +e
echo "--- helm status ---"
helm status "$RELEASE_NAME" --namespace "$RELEASE_NAMESPACE"
echo "--- helm get manifest ---"
helm get manifest "$RELEASE_NAME" --namespace "$RELEASE_NAMESPACE"
echo "--- get all ---"
kubectl get all --namespace "$RELEASE_NAMESPACE"
echo "--- describe pods ---"
kubectl describe pods --namespace "$RELEASE_NAMESPACE"
echo "--- pod logs ---"
kubectl logs --namespace "$RELEASE_NAMESPACE" \
--selector="app.kubernetes.io/name=openshell,app.kubernetes.io/instance=${RELEASE_NAME}" \
--tail=200 --all-containers --prefix
echo "--- port-forward log ---"
cat port-forward.log 2>/dev/null
echo "--- openshell gateway list ---"
openshell gateway list 2>/dev/null
echo "--- openshell version ---"
openshell --version 2>/dev/null