Documentation
¶
Index ¶
- Constants
- Variables
- type Body
- type BootstrapRequest
- type BootstrapResponse
- type DiagnosticAcceptedResponse
- type DiagnosticRequest
- type KAPMTLSCredentialsRequest
- type KAPMTLSStatus
- type KubeletCredentials
- type NodeCredentialFile
- type NodeCredentialsRequest
- type Op
- type OpOption
- func WithAuditLogger(auditLogger log.AuditLogger) OpOption
- func WithAutoUpdateExitCode(autoUpdateExitCode int) OpOption
- func WithComponentsRegistry(componentsRegistry components.Registry) OpOption
- func WithDB(dbRW *sql.DB, dbRO *sql.DB) OpOption
- func WithDBInMemory(dbInMemory bool) OpOption
- func WithDataDir(dataDir string) OpOption
- func WithEnableAutoUpdate(enableAutoUpdate bool) OpOption
- func WithFaultInjector(faultInjector pkgfaultinjector.Injector) OpOption
- func WithMachineID(machineID string) OpOption
- func WithMachineProof(machineProof string) OpOption
- func WithMetricsStore(metricsStore pkgmetrics.Store) OpOption
- func WithNvidiaInstance(nvmlInstance nvidianvml.Instance) OpOption
- func WithPipeInterval(t time.Duration) OpOption
- func WithProtocol(protocol string) OpOption
- func WithRebootCommands(commands string) OpOption
- func WithSavePluginSpecsFunc(...) OpOption
- func WithSkipUpdateConfig(skip bool) OpOption
- type Protocol
- type Request
- type Response
- type Session
Constants ¶
const (
DefaultQuerySince = 30 * time.Minute
)
Variables ¶
var ErrAutoUpdateDisabledButExitCodeSet = errors.New("auto update is disabled but auto update by exit code is set")
Functions ¶
This section is empty.
Types ¶
type BootstrapRequest ¶ added in v0.5.0
type BootstrapRequest struct {
// TimeoutInSeconds is the timeout for the bootstrap script.
// If not set, the default timeout is 10 seconds.
TimeoutInSeconds int `json:"timeout_in_seconds,omitempty"`
// ScriptBase64 is the base64 encoded script to run.
ScriptBase64 string `json:"script_base64,omitempty"`
}
type BootstrapResponse ¶ added in v0.5.0
type DiagnosticAcceptedResponse ¶ added in v0.11.9
type DiagnosticRequest ¶ added in v0.11.9
type KAPMTLSCredentialsRequest ¶ added in v0.12.9
type KAPMTLSCredentialsRequest struct {
CertificatePEM []byte `json:"certificate_pem"`
PrivateKeyPEM []byte `json:"private_key_pem"`
GatewayCAPEM []byte `json:"gateway_ca_pem"`
GatewayEndpoint string `json:"gateway_endpoint"`
ServerName string `json:"server_name"`
ClientCAFingerprint string `json:"client_ca_fingerprint"`
GatewayCAFingerprint string `json:"gateway_ca_fingerprint"`
}
type KAPMTLSStatus ¶ added in v0.12.9
type KAPMTLSStatus struct {
CredentialsInstalled bool `json:"credentials_installed"`
CertificateSerial string `json:"certificate_serial,omitempty"`
CertificateNotAfter time.Time `json:"certificate_not_after,omitempty"`
AgentInstalled bool `json:"agent_installed"`
AgentActive bool `json:"agent_active"`
AgentReady bool `json:"agent_ready"`
AgentVersion string `json:"agent_version,omitempty"`
GatewayEndpoint string `json:"gateway_endpoint,omitempty"`
ServerName string `json:"server_name,omitempty"`
ClientCAFingerprint string `json:"client_ca_fingerprint,omitempty"`
GatewayCAFingerprint string `json:"gateway_ca_fingerprint,omitempty"`
}
type KubeletCredentials ¶
type KubeletCredentials struct {
// Config is the kubelet configuration, which carries the providerID.
Config *NodeCredentialFile `json:"config,omitempty"`
// ClientCertificate is the client certificate and its private key, in the
// single file kubelet reads them from.
ClientCertificate *NodeCredentialFile `json:"client_certificate,omitempty"`
}
KubeletCredentials is what a kubelet needs to register. The fields are named rather than a list, so each file's role is part of the contract instead of something this side has to infer from a path.
type NodeCredentialFile ¶
type NodeCredentialFile struct {
// Path is absolute and must fall under an allowed prefix.
Path string `json:"path"`
// Contents is the file body. Empty contents are rejected: a credential
// truncated to nothing looks like a successful write to the caller and
// fails much later, wherever the file is actually read.
Contents []byte `json:"contents"`
// Mode defaults to 0600 when zero.
Mode uint32 `json:"mode,omitempty"`
}
NodeCredentialFile is one file to place on the node.
type NodeCredentialsRequest ¶
type NodeCredentialsRequest struct {
// Kubelet is the material a kubelet needs to register.
Kubelet *KubeletCredentials `json:"kubelet,omitempty"`
}
NodeCredentialsRequest carries credential material for one node, grouped by the subsystem that owns it. Grouping rather than flattening means a new kind of credential is a new field, not a change to an existing one.
func (*NodeCredentialsRequest) Files ¶
func (r *NodeCredentialsRequest) Files() []NodeCredentialFile
Files flattens the request into the order the files should be written. Every named field a caller may set has to appear here, or the file it carries is accepted by the wire format and then silently never written.
type OpOption ¶
type OpOption func(*Op)
func WithAuditLogger ¶ added in v0.5.0
func WithAuditLogger(auditLogger log.AuditLogger) OpOption
func WithAutoUpdateExitCode ¶
Triggers an auto update of GPUd itself by exiting the process with the given exit code. Useful when the machine is managed by the Kubernetes daemonset and we want to trigger an auto update when the daemonset restarts the machine.
func WithComponentsRegistry ¶ added in v0.5.0
func WithComponentsRegistry(componentsRegistry components.Registry) OpOption
func WithDBInMemory ¶ added in v0.9.0
func WithDataDir ¶ added in v0.9.0
func WithEnableAutoUpdate ¶
func WithFaultInjector ¶ added in v0.5.0
func WithFaultInjector(faultInjector pkgfaultinjector.Injector) OpOption
func WithMachineID ¶
func WithMachineProof ¶ added in v0.12.9
WithMachineProof sets the per-machine proof returned by control-plane login.
func WithMetricsStore ¶ added in v0.5.0
func WithMetricsStore(metricsStore pkgmetrics.Store) OpOption
func WithNvidiaInstance ¶ added in v0.5.0
func WithNvidiaInstance(nvmlInstance nvidianvml.Instance) OpOption
func WithPipeInterval ¶
func WithProtocol ¶ added in v0.12.12
WithProtocol selects the control-plane session transport.
func WithRebootCommands ¶ added in v0.12.1
WithRebootCommands configures the bash script to run for session reboot requests. Empty keeps the built-in host reboot path.
func WithSavePluginSpecsFunc ¶ added in v0.5.0
func WithSkipUpdateConfig ¶ added in v0.9.0
WithSkipUpdateConfig skips processing updateConfig session requests when true.
type Protocol ¶ added in v0.12.12
type Protocol string
Protocol selects the transport used for the control-plane session.
type Request ¶
type Request struct {
Method string `json:"method,omitempty"`
Components []string `json:"components,omitempty"`
StartTime time.Time `json:"start_time"`
EndTime time.Time `json:"end_time"`
Since time.Duration `json:"since"`
UpdateVersion string `json:"update_version,omitempty"`
UpdateConfig map[string]string `json:"update_config,omitempty"`
Bootstrap *BootstrapRequest `json:"bootstrap,omitempty"`
InjectFaultRequest *pkgfaultinjector.Request `json:"inject_fault_request,omitempty"`
Diagnostic *DiagnosticRequest `json:"diagnostic,omitempty"`
// ComponentName is the name of the component to query or deregister.
ComponentName string `json:"component_name,omitempty"`
// TagName is the tag of the component to trigger check.
// Optional. If set, it triggers all the component checks
// that match this tag value.
TagName string `json:"tag_name,omitempty"`
// CustomPluginSpecs is the specs for the custom plugins to register or overwrite.
CustomPluginSpecs pkgcustomplugins.Specs `json:"custom_plugin_specs,omitempty"`
// Token is the new token to update on the agent side.
Token string `json:"token,omitempty"`
// KAPMTLSCredentials carries short-lived client credentials for the
// node-local KAP mTLS agent. The private key must never be logged.
KAPMTLSCredentials *KAPMTLSCredentialsRequest `json:"kap_mtls_credentials,omitempty"`
// NodeCredentials carries credential material the control plane places on
// the node, with the destination of each file in the request. Private keys
// travel here, so it must never be logged.
NodeCredentials *NodeCredentialsRequest `json:"node_credentials,omitempty"`
}
Request is the request from the control plane to GPUd.
type Response ¶
type Response struct {
// Error is the error message from session processor.
// don't use "error" type as it doesn't marshal/unmarshal well
Error string `json:"error,omitempty"`
// ErrorCode is the error code from session processor.
// It uses the same semantics as the HTTP status code.
// See: https://www.iana.org/assignments/http-status-codes/http-status-codes.xhtml
ErrorCode int32 `json:"error_code,omitempty"`
GossipRequest *apiv1.GossipRequest `json:"gossip_request,omitempty"`
States apiv1.GPUdComponentHealthStates `json:"states,omitempty"`
Events apiv1.GPUdComponentEvents `json:"events,omitempty"`
Metrics apiv1.GPUdComponentMetrics `json:"metrics,omitempty"`
Bootstrap *BootstrapResponse `json:"bootstrap,omitempty"`
Diagnostic *DiagnosticAcceptedResponse `json:"diagnostic,omitempty"`
PackageStatus []apiv1.PackageStatus `json:"package_status,omitempty"`
// CustomPluginSpecs lists the specs for the custom plugins.
CustomPluginSpecs pkgcustomplugins.Specs `json:"custom_plugin_specs,omitempty"`
// Token is the current token value from the agent.
Token string `json:"token,omitempty"`
// KAPMTLSStatus contains only non-secret credential and process metadata.
KAPMTLSStatus *KAPMTLSStatus `json:"kap_mtls_status,omitempty"`
}
Response is the response from GPUd to the control plane.
Source Files
¶
- bootstrap.go
- deregister.go
- diagnostic.go
- events.go
- gossip.go
- health_states.go
- inject_fault.go
- kap_mtls.go
- logout.go
- metrics.go
- node_credentials.go
- package_status.go
- plugins.go
- protocol.go
- session.go
- session_keepalive.go
- session_process_request.go
- session_reconnect.go
- session_serve.go
- session_v2.go
- session_v2_adapter.go
- set_healthy.go
- token.go
- trigger_component.go
- update.go
- update_config.go
Directories
¶
| Path | Synopsis |
|---|---|
|
Package states provides tracking of login success and failure events as well as the state of ongoing session loops (token expiration, etc.).
|
Package states provides tracking of login success and failure events as well as the state of ongoing session loops (token expiration, etc.). |
|
Package sessionv2 defines the single-connection GPUd session protocol.
|
Package sessionv2 defines the single-connection GPUd session protocol. |