Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

packer provisioner #5604

Merged
merged 10 commits into from
Mar 2, 2021
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
34 changes: 34 additions & 0 deletions .circleci/config.yml
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,7 @@ version: 2.1
orbs:
go: gotest/tools@0.0.13
aws-cli: circleci/aws-cli@1.3.2
packer: salaxander/packer@0.0.3

executors:
golang:
Expand Down Expand Up @@ -277,6 +278,11 @@ jobs:
- install-deps
- prepare
- run: make calibnet
- run: mkdir linux-calibnet && mv lotus lotus-miner lotus-worker linux-calibnet
- persist_to_workspace:
root: "."
paths:
- linux-calibnet
build-lotus-soup:
description: |
Compile `lotus-soup` Testground test plan
Expand Down Expand Up @@ -583,6 +589,22 @@ jobs:
docker push $<<parameters.account-url>>/<<parameters.repo>>:${tag}
done

publish-packer:
description: build and push AWS IAM and DigitalOcean droplet.
executor:
name: packer/default
packer-version: 1.6.6
steps:
- checkout
- attach_workspace:
at: "."
- packer/build:
template: tools/packer/lotus.pkr.hcl
args: "-var ci_workspace_bins=./linux -var lotus_network=mainnet -var git_tag=$CIRCLE_TAG"
- packer/build:
template: tools/packer/lotus.pkr.hcl
args: "-var ci_workspace_bins=./linux-calibnet -var lotus_network=calibrationnet -var git_tag=$CIRCLE_TAG"

workflows:
version: 2.1
ci:
Expand Down Expand Up @@ -683,3 +705,15 @@ workflows:
path: .
repo: lotus-dev
tag: '${CIRCLE_SHA1:0:8}'
- publish-packer:
requires:
- build-all
- build-ntwk-calibration
filters:
branches:
ignore:
- /.*/
tags:
Copy link
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

When I initially wrote this, the filters matched the behavior of the docker image pusher, but the docker publisher was changed since this was written.

only:
- /^v\d+\.\d+\.\d+$/

57 changes: 57 additions & 0 deletions tools/packer/etc/motd
Original file line number Diff line number Diff line change
@@ -0,0 +1,57 @@
Your lotus node is up and running!

This image contains the two most important pieces of the lotus filecoin suite, the
daemon and the miner. The daemon is is configured to download a snapshot and start
running. In fact, by the time you read this, the daemon may already be in sync.
Go ahead and make sure everything is working correctly with the following commands.



To check if the daemon is running:

systemctl status lotus-daemon



To check if the daemon is in sync:

lotus sync status

**note: When starting lotus for the first time, it will download a chain snapshot.
This is a large download and will take several minutes to complete. During
this time, the lotus API will not be up yet. Give it time! You can see
progress by looking at the systemd journal.


To check if the daemon is connecting to other lotus nodes:

lotus net peers



No wallets are crated by default. You can view, create, and delete wallets with
the lotus command. On this image, lotus is running as the user `fc`.
Be careful, now. Don't delete a wallet with funds!

sudo -E -u fc lotus wallet list
sudo -E -u fc lotus wallet new bls



The lotus miner is also installed, but it's not running by default. If you have no
special disk or worker requirements, you can initialize the lotus-miner repo like this:

sudo -E -u fc lotus-miner init -o <wallet_you_created_before>



You only need to do this once, after which, you can enable and start the miner.

sudo systemctl enable lotus-miner
sudo systemctl start lotus-miner



For more information, see https://docs.filecoin.io/
Found a bug? let us know! https://github.com/filecoin-project/lotus
Chat with us on slack! https://filecoinproject.slack.com/archives/CEGN061C5
5 changes: 5 additions & 0 deletions tools/packer/homedir/bashrc
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
PS1="[\h \w] ⨎ "

export PROMT_DIRTRIM=1
export LOTUS_PATH=/var/lib/lotus
export LOTUS_MINER_PATH=/var/lib/lotus-miner
100 changes: 100 additions & 0 deletions tools/packer/lotus.pkr.hcl
Original file line number Diff line number Diff line change
@@ -0,0 +1,100 @@
variable "ci_workspace_bins" {
type = string
default = "./linux"
}

variable "lotus_network" {
type = string
default = "mainnet"
}

variable "git_tag" {
type = string
default = ""
}

locals {
timestamp = regex_replace(timestamp(), "[- TZ:]", "")
}

source "amazon-ebs" "lotus" {
ami_name = "lotus-${var.lotus_network}-${var.git_tag}-${local.timestamp}"
ami_regions = [
"us-east-1",
"us-west-2",
]
ami_groups = [
# This causes the ami to be publicly-accessable.
"all",
]
ami_description = "Lotus Filecoin AMI"
launch_block_device_mappings {
device_name = "/dev/sda1"
volume_size = 100
delete_on_termination = true
}

instance_type = "t2.micro"
source_ami_filter {
filters = {
name = "ubuntu-minimal/images/*ubuntu-focal-20.04-amd64-minimal*"
root-device-type = "ebs"
virtualization-type = "hvm"
}
most_recent = true
owners = ["099720109477"]
}
ssh_username = "ubuntu"
}

source "digitalocean" "lotus" {
droplet_name = "lotus-${var.lotus_network}"
size = "s-1vcpu-1gb"
region = "nyc3"
image = "ubuntu-20-04-x64"
snapshot_name = "lotus-${var.lotus_network}-${var.git_tag}-${local.timestamp}"
ssh_username = "root"
}
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

You are putting the git_tag in the amazon ami, should it also show up in the digital ocean image?

Copy link
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Good point, added the git_tag to the droplet snapshot.


build {
sources = [
"source.amazon-ebs.lotus",
"source.digitalocean.lotus",
]

# Lotus software (from CI workspace)
provisioner "file" {
source = "${var.ci_workspace_bins}/lotus"
destination = "lotus"
}
provisioner "file" {
source = "${var.ci_workspace_bins}/lotus-miner"
destination = "lotus-miner"
}
# First run script
provisioner "file" {
source = "./tools/packer/scripts/${var.lotus_network}/lotus-init.sh"
destination = "lotus-init.sh"
}
# Systemd service units.
provisioner "file" {
source = "./tools/packer/systemd/lotus-daemon.service"
destination = "lotus-daemon.service"
}
provisioner "file" {
source = "./tools/packer/systemd/lotus-miner.service"
destination = "lotus-miner.service"
}
provisioner "file" {
source = "./tools/packer/etc/motd"
destination = "motd"
}
provisioner "file" {
source = "./tools/packer/homedir/bashrc"
destination = ".bashrc"
}
# build it.
provisioner "shell" {
script = "./tools/packer/setup.sh"
}
}
20 changes: 20 additions & 0 deletions tools/packer/scripts/calibrationnet/lotus-init.sh
Original file line number Diff line number Diff line change
@@ -0,0 +1,20 @@
#!/usr/bin/env bash

# This script sets up an initial configuraiton for the lotus daemon and miner
# It will only run once.

GATE="$LOTUS_PATH"/date_initialized

# Don't init if already initialized.
if [ -f "GATE" ]; then
echo lotus already initialized.
exit 0
fi

# Not importing snapshot on calibrationnet.
#
# echo importing minimal snapshot
# lotus daemon --import-snapshot https://fil-chain-snapshots-fallback.s3.amazonaws.com/mainnet/minimal_finality_stateroots_latest.car --halt-after-import

# Block future inits
date > "$GATE"
18 changes: 18 additions & 0 deletions tools/packer/scripts/mainnet/lotus-init.sh
Original file line number Diff line number Diff line change
@@ -0,0 +1,18 @@
#!/usr/bin/env bash

# This script sets up an initial configuraiton for the lotus daemon and miner
# It will only run once.

GATE="$LOTUS_PATH"/date_initialized

# Don't init if already initialized.
if [ -f "GATE" ]; then
echo lotus already initialized.
exit 0
fi

echo importing minimal snapshot
lotus daemon --import-snapshot https://fil-chain-snapshots-fallback.s3.amazonaws.com/mainnet/minimal_finality_stateroots_latest.car --halt-after-import

# Block future inits
date > "$GATE"
57 changes: 57 additions & 0 deletions tools/packer/setup.sh
Original file line number Diff line number Diff line change
@@ -0,0 +1,57 @@
#!/usr/bin/env bash

# This script is executed by packer to setup the image.
# When this script is run, packer will have already copied binaries into the home directory of
# whichever user it has access too. This script is executed from within the home directory of that
# user. Bear in mind that different cloud providers, and different images on the same cloud
# provider will have a different initial user account.

set -x

# Become root, if we aren't already.
# Docker images will already be root. AMIs will have an SSH user account.
UID=$(id -u)
if [ x$UID != x0 ]
then
printf -v cmd_str '%q ' "$0" "$@"
exec sudo su -c "$cmd_str"
fi

MANAGED_BINS=( lotus lotus-miner lotus-init.sh )
MANAGED_FILES=(
/lib/systemd/system/lotus-daemon.service
/lib/systemd/system/lotus-miner.service
/etc/motd
)

# install libs.
apt update
apt -y install libhwloc15 ocl-icd-libopencl1
ln -s /usr/lib/x86_64-linux-gnu/libhwloc.so.15 /usr/lib/x86_64-linux-gnu/libhwloc.so.5
Copy link
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is here because in our CI, where make buildall is executed, it is linked with the older libhwloc. Ubuntu 20.04, which I'm using for the images, comes with newer glibc and libhwloc. Is this a problem?


# Create lotus user
useradd -c "lotus system account" -r fc
install -o fc -g fc -d /var/lib/lotus
install -o fc -g fc -d /var/lib/lotus-miner

# Install software
for i in "${MANAGED_BINS[@]}"
do
install -o root -g root -m 755 -t /usr/local/bin $i
rm $i
done

# Install systemd and other files.
# Because packer doesn't copy files with root permisison,
# files are in the home directory of the ssh user. Copy
# these files into the right position.
for i in "${MANAGED_FILES[@]}"
do
fn=$(basename $i)
install -o root -g root -m 644 $fn $i
rm $fn
done

# Enable services
systemctl daemon-reload
systemctl enable lotus-daemon
17 changes: 17 additions & 0 deletions tools/packer/systemd/lotus-daemon.service
Original file line number Diff line number Diff line change
@@ -0,0 +1,17 @@
[Unit]
Copy link
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

These could be the same units in ./scripts, though I rather not run as root.

Description=Lotus Daemon
After=network.target

[Service]
User=fc
Group=fc
ExecStartPre=/usr/local/bin/lotus-init.sh
ExecStart=/usr/local/bin/lotus daemon
ExecStop=/usr/local/bin/lotus daemon stop
Environment=LOTUS_PATH=/var/lib/lotus
Restart=always
RestartSec=30
TimeoutSec=infinity

[Install]
WantedBy=multi-user.target
15 changes: 15 additions & 0 deletions tools/packer/systemd/lotus-miner.service
Original file line number Diff line number Diff line change
@@ -0,0 +1,15 @@
[Unit]
Description=Lotus Miner
After=network.target

[Service]
User=fc
Group=fc
ExecStart=/usr/local/bin/lotus-miner run
Environment=LOTUS_PATH=/var/lib/lotus
Environment=LOTUS_MINER_PATH=/var/lib/lotus-miner
Restart=always
RestartSec=30

[Install]
WantedBy=multi-user.target