Compare commits
4 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| 0a1f949937 | |||
| 64ca39ddd4 | |||
| 3c426f45f5 | |||
| 1d3e9e859c |
@@ -61,6 +61,13 @@ class AgentProviderRuntime:
|
|||||||
prompt_mode: PromptMode
|
prompt_mode: PromptMode
|
||||||
bypass_args: tuple[str, ...]
|
bypass_args: tuple[str, ...]
|
||||||
resume_args: tuple[str, ...]
|
resume_args: tuple[str, ...]
|
||||||
|
# argv run inside a throwaway container of a freshly built agent
|
||||||
|
# image, right after `build_image()`, to catch a build that
|
||||||
|
# exited 0 but produced a broken CLI (e.g. an npm
|
||||||
|
# optionalDependencies fetch for a platform-native binary that
|
||||||
|
# silently no-ops on a transient failure). Empty tuple skips the
|
||||||
|
# check — not every provider has opted in yet.
|
||||||
|
smoke_test: tuple[str, ...] = ()
|
||||||
|
|
||||||
|
|
||||||
@dataclass(frozen=True)
|
@dataclass(frozen=True)
|
||||||
|
|||||||
@@ -36,6 +36,7 @@ from contextlib import ExitStack, contextmanager
|
|||||||
from pathlib import Path
|
from pathlib import Path
|
||||||
from typing import Callable, Generator
|
from typing import Callable, Generator
|
||||||
|
|
||||||
|
from ...agent_provider import runtime_for
|
||||||
from ...egress import egress_resolve_token_values
|
from ...egress import egress_resolve_token_values
|
||||||
from ...git_gate import (
|
from ...git_gate import (
|
||||||
provision_git_gate_dynamic_keys,
|
provision_git_gate_dynamic_keys,
|
||||||
@@ -110,6 +111,9 @@ def launch(
|
|||||||
plan.image, _REPO_DIR,
|
plan.image, _REPO_DIR,
|
||||||
dockerfile=plan.dockerfile_path,
|
dockerfile=plan.dockerfile_path,
|
||||||
)
|
)
|
||||||
|
docker_mod.verify_agent_image(
|
||||||
|
plan.image, runtime_for(plan.agent_provider_template).smoke_test,
|
||||||
|
)
|
||||||
|
|
||||||
# Step 2: mint the git-gate dynamic (gitea) deploy keys, if any, before
|
# Step 2: mint the git-gate dynamic (gitea) deploy keys, if any, before
|
||||||
# provisioning the bottle's repos into the shared gateway.
|
# provisioning the bottle's repos into the shared gateway.
|
||||||
|
|||||||
@@ -4,11 +4,13 @@ existence, and building images."""
|
|||||||
|
|
||||||
from __future__ import annotations
|
from __future__ import annotations
|
||||||
|
|
||||||
|
import os
|
||||||
import re
|
import re
|
||||||
import shutil
|
import shutil
|
||||||
import subprocess
|
import subprocess
|
||||||
from typing import Iterable, Iterator
|
from typing import Iterable, Iterator
|
||||||
|
|
||||||
|
from ...docker_cmd import run_docker
|
||||||
from ...log import die, info
|
from ...log import die, info
|
||||||
# from ...workspace import WorkspacePlan
|
# from ...workspace import WorkspacePlan
|
||||||
|
|
||||||
@@ -88,6 +90,29 @@ def docker_exec_root(container: str, argv: list[str]) -> None:
|
|||||||
)
|
)
|
||||||
|
|
||||||
|
|
||||||
|
def docker_exec(container: str, argv: list[str], *, user: str = "") -> None:
|
||||||
|
"""Run `docker exec` in the named container, dying with the
|
||||||
|
command's own stderr on failure. Pass `user=\"0\"` to run as root."""
|
||||||
|
cmd = ["docker", "exec"]
|
||||||
|
if user:
|
||||||
|
cmd += ["-u", user]
|
||||||
|
cmd += [container, *argv]
|
||||||
|
result = run_docker(cmd)
|
||||||
|
if result.returncode != 0:
|
||||||
|
die(
|
||||||
|
f"docker exec in {container} failed: "
|
||||||
|
f"{(result.stderr or '').strip() or '<no stderr>'}"
|
||||||
|
)
|
||||||
|
|
||||||
|
|
||||||
|
def docker_cp(src: str, dest: str) -> None:
|
||||||
|
"""Run `docker cp`, dying with the command's own stderr on failure."""
|
||||||
|
result = run_docker(["docker", "cp", src, dest])
|
||||||
|
if result.returncode != 0:
|
||||||
|
die(f"docker cp {src} -> {dest} failed: "
|
||||||
|
f"{(result.stderr or '').strip() or '<no stderr>'}")
|
||||||
|
|
||||||
|
|
||||||
_SLUG_RE = re.compile(r"[^a-z0-9]+")
|
_SLUG_RE = re.compile(r"[^a-z0-9]+")
|
||||||
|
|
||||||
|
|
||||||
@@ -108,15 +133,40 @@ def build_image(ref: str, context: str, *, dockerfile: str = "") -> None:
|
|||||||
|
|
||||||
`dockerfile` is an optional path (relative to `context`, or
|
`dockerfile` is an optional path (relative to `context`, or
|
||||||
absolute) for callers that need to build from a non-default
|
absolute) for callers that need to build from a non-default
|
||||||
Dockerfile in the same context — e.g. `Dockerfile.git-gate`."""
|
Dockerfile in the same context — e.g. `Dockerfile.git-gate`.
|
||||||
|
|
||||||
|
Set `BOT_BOTTLE_NO_CACHE=1` (the `start --no-cache` flag) to force
|
||||||
|
`--no-cache`. The npm/curl installers some provider Dockerfiles
|
||||||
|
shell out to can silently no-op on a transient network failure —
|
||||||
|
e.g. an `optionalDependencies` fetch for a platform-native binary —
|
||||||
|
and Docker will then cache that broken layer indefinitely."""
|
||||||
info(f"building image {ref} from {context} (layer cache keeps repeat builds fast)")
|
info(f"building image {ref} from {context} (layer cache keeps repeat builds fast)")
|
||||||
args = ["docker", "build", "-t", ref]
|
args = ["docker", "build", "-t", ref]
|
||||||
|
if os.environ.get("BOT_BOTTLE_NO_CACHE") == "1":
|
||||||
|
args.append("--no-cache")
|
||||||
if dockerfile:
|
if dockerfile:
|
||||||
args.extend(["-f", dockerfile])
|
args.extend(["-f", dockerfile])
|
||||||
args.append(context)
|
args.append(context)
|
||||||
subprocess.run(args, check=True)
|
subprocess.run(args, check=True)
|
||||||
|
|
||||||
|
|
||||||
|
def verify_agent_image(image: str, argv: tuple[str, ...]) -> None:
|
||||||
|
"""Run `argv` inside a throwaway container of a freshly built agent
|
||||||
|
image and die loudly if it fails, instead of shipping an image
|
||||||
|
whose CLI only breaks at first real use. No-op when the provider
|
||||||
|
hasn't declared a smoke test (`AgentProviderRuntime.smoke_test`)."""
|
||||||
|
if not argv:
|
||||||
|
return
|
||||||
|
result = run_docker(["docker", "run", "--rm", "--entrypoint", argv[0], image, *argv[1:]])
|
||||||
|
if result.returncode != 0:
|
||||||
|
detail = (result.stderr or result.stdout or "").strip()
|
||||||
|
die(
|
||||||
|
f"agent image {image!r} failed its post-build smoke test "
|
||||||
|
f"({' '.join(argv)}): {detail}\n"
|
||||||
|
f"Try rebuilding from scratch: bot-bottle start --no-cache"
|
||||||
|
)
|
||||||
|
|
||||||
|
|
||||||
# def build_image_with_cwd(
|
# def build_image_with_cwd(
|
||||||
# derived: str,
|
# derived: str,
|
||||||
# base: str,
|
# base: str,
|
||||||
|
|||||||
@@ -0,0 +1,164 @@
|
|||||||
|
"""Consolidated bottle launch sequence for the Firecracker backend (PRD 0070).
|
||||||
|
|
||||||
|
Mirrors bot_bottle.backend.docker.consolidated_launch but wired for
|
||||||
|
Firecracker's TAP-based network topology instead of a shared Docker bridge.
|
||||||
|
|
||||||
|
The per-bottle sidecar bundle (one `docker run` per bottle, published on the
|
||||||
|
slot's host-side TAP IP) is replaced by a single persistent gateway that
|
||||||
|
every Firecracker VM shares. The gateway runs as a Docker container in the
|
||||||
|
dev-harness (a Firecracker VM is stage B per PRD 0070), with its ports
|
||||||
|
published on the host (`0.0.0.0:PORT`). VMs reach it at their slot's
|
||||||
|
host-side TAP IP because Docker's iptables PREROUTING DNAT redirects
|
||||||
|
port 9099/9100/9420 traffic to the gateway container — a path the nft
|
||||||
|
isolation table already allows via `ct status dnat accept` in the forward
|
||||||
|
chain.
|
||||||
|
|
||||||
|
Attribution is by the VM's guest IP, which is unspoofable by construction:
|
||||||
|
the /31 point-to-point TAP topology + the `bot_bottle_fc` nft table ensure
|
||||||
|
that only the expected VM can source-IP that address.
|
||||||
|
|
||||||
|
Sequence:
|
||||||
|
1. ensure the Firecracker-flavoured orchestrator + gateway are up;
|
||||||
|
2. register the bottle by its guest IP (attribution key) → bottle id +
|
||||||
|
identity token;
|
||||||
|
3. provision its git-gate repos/creds into the running gateway;
|
||||||
|
4. fetch the shared gateway CA for the provisioner to install in the rootfs.
|
||||||
|
|
||||||
|
The TAP slot allocation, rootfs build, and VM boot are the caller's job.
|
||||||
|
"""
|
||||||
|
|
||||||
|
from __future__ import annotations
|
||||||
|
|
||||||
|
from dataclasses import dataclass
|
||||||
|
|
||||||
|
from ...egress import EgressPlan
|
||||||
|
from ...git_gate import GitGatePlan
|
||||||
|
from ...orchestrator.client import OrchestratorClient
|
||||||
|
from ...orchestrator.gateway import (
|
||||||
|
GATEWAY_NETWORK,
|
||||||
|
DockerGateway,
|
||||||
|
)
|
||||||
|
from ...orchestrator.lifecycle import (
|
||||||
|
OrchestratorService,
|
||||||
|
OrchestratorStartError, # re-exported so callers can catch it
|
||||||
|
)
|
||||||
|
from ...orchestrator.registration import registration_inputs
|
||||||
|
from ..docker.egress import EGRESS_PORT
|
||||||
|
from ..docker.gateway_provision import deprovision_git_gate, provision_git_gate
|
||||||
|
from ...supervise import SUPERVISE_PORT
|
||||||
|
|
||||||
|
_GIT_HTTP_PORT = 9420
|
||||||
|
|
||||||
|
# Separate names from the Docker gateway so both backends can coexist on one
|
||||||
|
# host (and for clarity in `docker ps` output).
|
||||||
|
_FC_GATEWAY_NAME = "bot-bottle-fc-gateway"
|
||||||
|
_FC_ORCHESTRATOR_NAME = "bot-bottle-fc-orchestrator"
|
||||||
|
_FC_ORCHESTRATOR_LABEL = "bot-bottle-fc-orchestrator=1"
|
||||||
|
# Ports the gateway publishes on the host so Firecracker VMs can reach it
|
||||||
|
# via their TAP link. Docker's PREROUTING DNAT + nft's `ct status dnat
|
||||||
|
# accept` in the forward chain route the traffic.
|
||||||
|
_FC_GATEWAY_HOST_PORTS = (EGRESS_PORT, SUPERVISE_PORT, _GIT_HTTP_PORT)
|
||||||
|
|
||||||
|
|
||||||
|
class ConsolidatedLaunchError(RuntimeError):
|
||||||
|
"""The consolidated register/provision sequence could not complete."""
|
||||||
|
|
||||||
|
|
||||||
|
@dataclass(frozen=True)
|
||||||
|
class LaunchContext:
|
||||||
|
"""What the Firecracker launch needs from the consolidated sequence."""
|
||||||
|
|
||||||
|
bottle_id: str
|
||||||
|
identity_token: str
|
||||||
|
source_ip: str # the VM's guest IP — the attribution key
|
||||||
|
gateway_ca_pem: str # the shared gateway CA the provisioner installs
|
||||||
|
orchestrator_url: str
|
||||||
|
|
||||||
|
|
||||||
|
class _FirecrackerOrchestratorService(OrchestratorService):
|
||||||
|
"""Dev-harness orchestrator for the Firecracker backend.
|
||||||
|
|
||||||
|
Uses a gateway that publishes its ports on the host so Firecracker VMs can
|
||||||
|
reach it via their TAP link. The gateway and orchestrator containers use
|
||||||
|
`*-fc-*` names so both backends can run independently on the same host.
|
||||||
|
"""
|
||||||
|
|
||||||
|
def __init__(self, **kwargs: object) -> None:
|
||||||
|
super().__init__(
|
||||||
|
orchestrator_name=_FC_ORCHESTRATOR_NAME,
|
||||||
|
orchestrator_label=_FC_ORCHESTRATOR_LABEL,
|
||||||
|
**kwargs, # type: ignore[arg-type]
|
||||||
|
)
|
||||||
|
|
||||||
|
def _gateway(self) -> DockerGateway:
|
||||||
|
# The heavy data-plane image (#384 split it from the lean control-plane
|
||||||
|
# `image` this service's orchestrator container runs).
|
||||||
|
return DockerGateway(
|
||||||
|
self._gateway_image,
|
||||||
|
name=_FC_GATEWAY_NAME,
|
||||||
|
network=self.network,
|
||||||
|
orchestrator_url=self.internal_url,
|
||||||
|
host_port_bindings=_FC_GATEWAY_HOST_PORTS,
|
||||||
|
)
|
||||||
|
|
||||||
|
|
||||||
|
def launch_consolidated(
|
||||||
|
egress_plan: EgressPlan,
|
||||||
|
git_gate_plan: GitGatePlan,
|
||||||
|
*,
|
||||||
|
guest_ip: str,
|
||||||
|
image_ref: str = "",
|
||||||
|
tokens: dict[str, str] | None = None,
|
||||||
|
service: OrchestratorService | None = None,
|
||||||
|
gateway_name: str = _FC_GATEWAY_NAME,
|
||||||
|
) -> LaunchContext:
|
||||||
|
"""Ensure the orchestrator + Firecracker gateway are up, register the
|
||||||
|
bottle by its guest IP, and provision its git-gate state. Returns the
|
||||||
|
context the VM launch needs. Raises `ConsolidatedLaunchError` (or the
|
||||||
|
primitives' own errors) on failure — the caller tears down on failure."""
|
||||||
|
service = service or _FirecrackerOrchestratorService()
|
||||||
|
url = service.ensure_running()
|
||||||
|
client = OrchestratorClient(url)
|
||||||
|
|
||||||
|
inputs = registration_inputs(egress_plan)
|
||||||
|
reg = client.register_bottle(
|
||||||
|
guest_ip, image_ref=image_ref, policy=inputs.policy,
|
||||||
|
metadata=inputs.metadata, tokens=tokens,
|
||||||
|
)
|
||||||
|
try:
|
||||||
|
provision_git_gate(gateway_name, reg.bottle_id, git_gate_plan)
|
||||||
|
except Exception:
|
||||||
|
client.teardown_bottle(reg.bottle_id)
|
||||||
|
raise
|
||||||
|
|
||||||
|
# Fetch the shared gateway CA here so the caller can install it in the
|
||||||
|
# rootfs (the same CA every agent on this host trusts for TLS interception).
|
||||||
|
gateway_ca_pem = DockerGateway(
|
||||||
|
name=gateway_name, network=GATEWAY_NETWORK,
|
||||||
|
).ca_cert_pem()
|
||||||
|
|
||||||
|
return LaunchContext(
|
||||||
|
bottle_id=reg.bottle_id,
|
||||||
|
identity_token=reg.identity_token,
|
||||||
|
source_ip=guest_ip,
|
||||||
|
gateway_ca_pem=gateway_ca_pem,
|
||||||
|
orchestrator_url=url,
|
||||||
|
)
|
||||||
|
|
||||||
|
|
||||||
|
def teardown_consolidated(
|
||||||
|
bottle_id: str, *, orchestrator_url: str, gateway_name: str = _FC_GATEWAY_NAME,
|
||||||
|
) -> None:
|
||||||
|
"""Deregister the bottle and remove its git-gate state from the gateway.
|
||||||
|
Both steps are idempotent so this is safe from a cleanup trap."""
|
||||||
|
OrchestratorClient(orchestrator_url).teardown_bottle(bottle_id)
|
||||||
|
deprovision_git_gate(gateway_name, bottle_id)
|
||||||
|
|
||||||
|
|
||||||
|
__all__ = [
|
||||||
|
"LaunchContext",
|
||||||
|
"launch_consolidated",
|
||||||
|
"teardown_consolidated",
|
||||||
|
"ConsolidatedLaunchError",
|
||||||
|
"OrchestratorStartError",
|
||||||
|
]
|
||||||
@@ -1,25 +1,64 @@
|
|||||||
"""Launch flow for the Firecracker backend — temporarily disabled (#385).
|
"""Launch flow for the Firecracker backend (PRD 0070, consolidated).
|
||||||
|
|
||||||
The firecracker backend launched a per-bottle companion container (the
|
Per bottle:
|
||||||
egress / git-gate / supervise data plane) alongside each microVM. That
|
1. build the agent image (docker), export it to a cached ext4 rootfs;
|
||||||
per-bottle-companion architecture was removed in the companion-container removal;
|
2. ensure the per-host orchestrator + shared gateway are up;
|
||||||
firecracker's replacement — the consolidated per-host gateway — lands in
|
3. claim a free TAP pool slot (rootless flock);
|
||||||
its own cutover (#354).
|
4. register the bottle on the orchestrator by the VM's guest IP (the
|
||||||
|
attribution key) and provision its git-gate state into the gateway;
|
||||||
|
5. boot the microVM on that TAP; wait for SSH;
|
||||||
|
6. provision (shared gateway CA, prompt, skills, workspace, git, supervise)
|
||||||
|
over SSH.
|
||||||
|
|
||||||
Until that lands, launching a firecracker bottle fails closed rather than
|
The per-bottle Docker sidecar bundle is gone. The shared gateway handles
|
||||||
silently running the removed path. `prepare` / `status` / cleanup still
|
egress / git-gate / supervise for every VM; Docker's PREROUTING DNAT routes
|
||||||
work, so `backend status --backend=firecracker` and orphan cleanup are
|
the VMs' traffic to it, and the nft table's `ct status dnat accept` rule
|
||||||
unaffected.
|
in the forward chain lets it pass. The VM still sends to `host_tap_ip:PORT`
|
||||||
|
— the address its world is, by nft design, limited to.
|
||||||
|
|
||||||
|
Isolation is enforced by the operator-provisioned nft table (checked
|
||||||
|
fail-closed in preflight): a VM reaches only the sidecar (DNAT'd from
|
||||||
|
the host TAP IP) and nothing else.
|
||||||
"""
|
"""
|
||||||
|
|
||||||
from __future__ import annotations
|
from __future__ import annotations
|
||||||
|
|
||||||
from contextlib import contextmanager
|
import dataclasses
|
||||||
|
import os
|
||||||
|
from contextlib import ExitStack, contextmanager
|
||||||
|
from pathlib import Path
|
||||||
from typing import Callable, Generator
|
from typing import Callable, Generator
|
||||||
|
|
||||||
from ...log import die
|
from ...agent_provider import runtime_for
|
||||||
|
from ...bottle_state import (
|
||||||
|
egress_state_dir,
|
||||||
|
git_gate_state_dir,
|
||||||
|
read_committed_image,
|
||||||
|
)
|
||||||
|
from ...egress import (
|
||||||
|
egress_agent_env_entries,
|
||||||
|
egress_resolve_token_values,
|
||||||
|
)
|
||||||
|
from ...git_gate import (
|
||||||
|
provision_git_gate_dynamic_keys,
|
||||||
|
revoke_git_gate_provisioned_keys,
|
||||||
|
)
|
||||||
|
from ...log import info, warn
|
||||||
|
from ...supervise import SUPERVISE_PORT
|
||||||
|
from ..docker import util as docker_mod
|
||||||
|
from ..docker.egress import EGRESS_PORT
|
||||||
|
from ..util import AGENT_CA_BUNDLE, AGENT_CA_PATH
|
||||||
|
from . import firecracker_vm, isolation_probe, netpool, util
|
||||||
from .bottle import FirecrackerBottle
|
from .bottle import FirecrackerBottle
|
||||||
from .bottle_plan import FirecrackerBottlePlan
|
from .bottle_plan import FirecrackerBottlePlan
|
||||||
|
from .consolidated_launch import (
|
||||||
|
launch_consolidated,
|
||||||
|
teardown_consolidated,
|
||||||
|
)
|
||||||
|
|
||||||
|
|
||||||
|
_REPO_DIR = str(Path(__file__).resolve().parent.parent.parent.parent)
|
||||||
|
_GIT_HTTP_PORT = 9420
|
||||||
|
|
||||||
|
|
||||||
@contextmanager
|
@contextmanager
|
||||||
@@ -28,12 +67,181 @@ def launch(
|
|||||||
*,
|
*,
|
||||||
provision: Callable[[FirecrackerBottlePlan, "FirecrackerBottle"], str | None],
|
provision: Callable[[FirecrackerBottlePlan, "FirecrackerBottle"], str | None],
|
||||||
) -> Generator[FirecrackerBottle, None, None]:
|
) -> Generator[FirecrackerBottle, None, None]:
|
||||||
"""Fail closed: the firecracker backend is disabled while its
|
"""Build, launch, and provision a Firecracker bottle via the consolidated
|
||||||
consolidated (gateway-backed) launch is built in #354."""
|
orchestrator. Teardown on exit."""
|
||||||
del plan, provision
|
stack = ExitStack()
|
||||||
die(
|
bottle_for_revoke = plan.manifest.bottle
|
||||||
"the firecracker backend is temporarily disabled during the "
|
git_gate_dir_for_revoke = git_gate_state_dir(plan.slug)
|
||||||
"companion-container removal (#385); its consolidated relaunch "
|
|
||||||
"lands in #354. Use --backend=docker for now."
|
def teardown() -> None:
|
||||||
|
teardown_exc: BaseException | None = None
|
||||||
|
try:
|
||||||
|
stack.close()
|
||||||
|
except BaseException as exc: # noqa: W0718 - teardown must continue
|
||||||
|
teardown_exc = exc
|
||||||
|
warn(f"firecracker teardown failed: {exc!r}")
|
||||||
|
revoke_git_gate_provisioned_keys(bottle_for_revoke, git_gate_dir_for_revoke)
|
||||||
|
if teardown_exc is not None:
|
||||||
|
raise teardown_exc
|
||||||
|
|
||||||
|
try:
|
||||||
|
# Step 1: agent image. The sidecar bundle image is built by the
|
||||||
|
# orchestrator service (ensure_running → ensure_built); we only
|
||||||
|
# build the agent image here. Use a committed snapshot when available.
|
||||||
|
plan = _build_agent_image(plan)
|
||||||
|
|
||||||
|
# Step 2: mint the git-gate dynamic (gitea) deploy keys, if any.
|
||||||
|
git_gate_plan = plan.git_gate_plan
|
||||||
|
if git_gate_plan.upstreams:
|
||||||
|
git_gate_plan = provision_git_gate_dynamic_keys(
|
||||||
|
plan.manifest.bottle, git_gate_plan, git_gate_state_dir(plan.slug),
|
||||||
|
)
|
||||||
|
|
||||||
|
# Step 3: claim a TAP slot; the flock is held until teardown.
|
||||||
|
slot, lock = netpool.allocate(plan.slug)
|
||||||
|
stack.callback(lock.close)
|
||||||
|
info(f"firecracker slot {slot.iface}: host={slot.host_ip} "
|
||||||
|
f"guest={slot.guest_ip}")
|
||||||
|
|
||||||
|
# Step 4: register on the orchestrator + provision this bottle's
|
||||||
|
# git-gate state into the shared gateway. The per-bottle egress tokens
|
||||||
|
# are resolved from the host env now and handed to the orchestrator
|
||||||
|
# (in memory) for the gateway to inject — the agent never sees them.
|
||||||
|
# Attribution is by the VM's guest IP (unspoofable via /31 TAP + nft).
|
||||||
|
effective_env = {**os.environ, **plan.agent_provision.provisioned_env}
|
||||||
|
token_values = egress_resolve_token_values(
|
||||||
|
plan.egress_plan.token_env_map, effective_env,
|
||||||
|
)
|
||||||
|
ctx = launch_consolidated(
|
||||||
|
plan.egress_plan, git_gate_plan,
|
||||||
|
guest_ip=slot.guest_ip,
|
||||||
|
image_ref=plan.image,
|
||||||
|
tokens=token_values,
|
||||||
|
)
|
||||||
|
stack.callback(
|
||||||
|
teardown_consolidated, ctx.bottle_id,
|
||||||
|
orchestrator_url=ctx.orchestrator_url,
|
||||||
|
)
|
||||||
|
|
||||||
|
# Step 5: install the SHARED gateway CA (replaces the per-bottle CA).
|
||||||
|
# Write it to a stable host path so the provisioner can copy it over SSH.
|
||||||
|
ca_dir = egress_state_dir(plan.slug) / "gateway-ca"
|
||||||
|
ca_dir.mkdir(parents=True, exist_ok=True)
|
||||||
|
ca_file = ca_dir / "gateway-ca.pem"
|
||||||
|
ca_file.write_text(ctx.gateway_ca_pem)
|
||||||
|
egress_plan = dataclasses.replace(
|
||||||
|
plan.egress_plan,
|
||||||
|
mitmproxy_ca_host_path=ca_file,
|
||||||
|
mitmproxy_ca_cert_only_host_path=ca_file,
|
||||||
|
)
|
||||||
|
# Point the agent's git-gate insteadOf rewrites and supervise MCP URL
|
||||||
|
# at the shared gateway (reached at the slot's host TAP IP — the VM
|
||||||
|
# sends there and Docker DNAT routes to the gateway container).
|
||||||
|
git_gate_url = (
|
||||||
|
f"http://{slot.host_ip}:{_GIT_HTTP_PORT}" if git_gate_plan.upstreams else ""
|
||||||
|
)
|
||||||
|
supervise_url = (
|
||||||
|
f"http://{slot.host_ip}:{SUPERVISE_PORT}/"
|
||||||
|
if plan.supervise_plan is not None else ""
|
||||||
|
)
|
||||||
|
plan = dataclasses.replace(
|
||||||
|
plan,
|
||||||
|
git_gate_plan=git_gate_plan,
|
||||||
|
egress_plan=egress_plan,
|
||||||
|
agent_proxy_url=f"http://{slot.host_ip}:{EGRESS_PORT}",
|
||||||
|
agent_git_gate_url=git_gate_url,
|
||||||
|
agent_supervise_url=supervise_url,
|
||||||
|
)
|
||||||
|
|
||||||
|
# Step 6: build the per-bottle rootfs + SSH key, then boot.
|
||||||
|
base_dir = util.build_base_rootfs_dir(plan.image)
|
||||||
|
run_dir = util.cache_dir() / "run" / plan.slug
|
||||||
|
run_dir.mkdir(parents=True, exist_ok=True)
|
||||||
|
rootfs = run_dir / "rootfs.ext4"
|
||||||
|
util.build_rootfs_ext4(base_dir, rootfs)
|
||||||
|
private_key, pubkey = util.generate_keypair(run_dir)
|
||||||
|
|
||||||
|
vm = firecracker_vm.boot(
|
||||||
|
name=plan.container_name,
|
||||||
|
rootfs=rootfs,
|
||||||
|
tap=slot.iface,
|
||||||
|
guest_ip=slot.guest_ip,
|
||||||
|
host_ip=slot.host_ip,
|
||||||
|
pubkey=pubkey,
|
||||||
|
run_dir=run_dir,
|
||||||
|
)
|
||||||
|
stack.callback(vm.terminate)
|
||||||
|
firecracker_vm.wait_for_ssh(vm, private_key)
|
||||||
|
|
||||||
|
# Authoritative fail-closed egress-boundary check, before the agent
|
||||||
|
# runs: prove the VM cannot reach the host directly.
|
||||||
|
isolation_probe.verify_isolation(private_key, slot.guest_ip)
|
||||||
|
|
||||||
|
bottle = FirecrackerBottle(
|
||||||
|
plan.container_name,
|
||||||
|
private_key=private_key,
|
||||||
|
guest_ip=slot.guest_ip,
|
||||||
|
guest_env=_agent_guest_env(plan, slot.host_ip),
|
||||||
|
agent_command=plan.agent_command,
|
||||||
|
agent_prompt_mode=plan.agent_prompt_mode,
|
||||||
|
agent_provider_template=plan.agent_provider_template,
|
||||||
|
terminal_title=(
|
||||||
|
f"{plan.spec.label} ({plan.spec.agent_name})"
|
||||||
|
if plan.spec.label else plan.spec.agent_name
|
||||||
|
),
|
||||||
|
terminal_color=plan.spec.color,
|
||||||
|
agent_workdir=plan.workspace_plan.workdir,
|
||||||
|
)
|
||||||
|
bottle.prompt_path = provision(plan, bottle)
|
||||||
|
|
||||||
|
yield bottle
|
||||||
|
finally:
|
||||||
|
teardown()
|
||||||
|
|
||||||
|
|
||||||
|
def _build_agent_image(plan: FirecrackerBottlePlan) -> FirecrackerBottlePlan:
|
||||||
|
committed = read_committed_image(plan.slug)
|
||||||
|
if committed and docker_mod.image_exists(committed):
|
||||||
|
info(f"using committed image {committed!r}")
|
||||||
|
return dataclasses.replace(
|
||||||
|
plan,
|
||||||
|
agent_provision=dataclasses.replace(plan.agent_provision, image=committed),
|
||||||
|
)
|
||||||
|
docker_mod.build_image(plan.image, _REPO_DIR, dockerfile=plan.dockerfile_path)
|
||||||
|
docker_mod.verify_agent_image(
|
||||||
|
plan.image, runtime_for(plan.agent_provider_template).smoke_test,
|
||||||
)
|
)
|
||||||
yield # unreachable — `die` raises; keeps this a generator/contextmanager
|
return plan
|
||||||
|
|
||||||
|
|
||||||
|
# --- agent guest env -------------------------------------------------
|
||||||
|
|
||||||
|
def _agent_guest_env(plan: FirecrackerBottlePlan, host_ip: str) -> dict[str, str]:
|
||||||
|
"""Env injected into every agent/exec call over SSH. The VM has no
|
||||||
|
baked process env (it just runs init), so the proxy/CA/git/supervise
|
||||||
|
wiring is applied per-invocation."""
|
||||||
|
proxy_url = f"http://{host_ip}:{EGRESS_PORT}"
|
||||||
|
no_proxy = f"localhost,127.0.0.1,{host_ip}"
|
||||||
|
env: dict[str, str] = {
|
||||||
|
"HTTPS_PROXY": proxy_url, "HTTP_PROXY": proxy_url,
|
||||||
|
"https_proxy": proxy_url, "http_proxy": proxy_url,
|
||||||
|
"NO_PROXY": no_proxy, "no_proxy": no_proxy,
|
||||||
|
"NODE_EXTRA_CA_CERTS": AGENT_CA_PATH,
|
||||||
|
"SSL_CERT_FILE": AGENT_CA_BUNDLE,
|
||||||
|
"REQUESTS_CA_BUNDLE": AGENT_CA_BUNDLE,
|
||||||
|
}
|
||||||
|
if plan.agent_git_gate_url:
|
||||||
|
env["GIT_GATE_URL"] = plan.agent_git_gate_url
|
||||||
|
if plan.agent_supervise_url:
|
||||||
|
env["MCP_SUPERVISE_URL"] = plan.agent_supervise_url
|
||||||
|
for entry in egress_agent_env_entries(plan.egress_plan):
|
||||||
|
key, _, value = entry.partition("=")
|
||||||
|
env[key] = value
|
||||||
|
env.update(plan.agent_provision.guest_env)
|
||||||
|
# Forwarded (bare-name) env: resolve host values now, since the VM
|
||||||
|
# can't inherit them from a `docker run --env NAME`.
|
||||||
|
for name in plan.forwarded_env:
|
||||||
|
value = os.environ.get(name)
|
||||||
|
if value is not None:
|
||||||
|
env[name] = value
|
||||||
|
return env
|
||||||
|
|||||||
@@ -60,13 +60,21 @@ def dns_server() -> str:
|
|||||||
|
|
||||||
|
|
||||||
def build_image(ref: str, context: str, *, dockerfile: str = "") -> None:
|
def build_image(ref: str, context: str, *, dockerfile: str = "") -> None:
|
||||||
"""Build an OCI image with Apple's BuildKit-backed `container build`."""
|
"""Build an OCI image with Apple's BuildKit-backed `container build`.
|
||||||
|
|
||||||
|
Set `BOT_BOTTLE_NO_CACHE=1` (the `start --no-cache` flag) to force
|
||||||
|
`--no-cache`. The npm/curl installers some provider Dockerfiles
|
||||||
|
shell out to can silently no-op on a transient network failure —
|
||||||
|
e.g. an `optionalDependencies` fetch for a platform-native binary —
|
||||||
|
and the builder will then cache that broken layer indefinitely."""
|
||||||
info(
|
info(
|
||||||
f"building image {ref} from {context} with Apple Container "
|
f"building image {ref} from {context} with Apple Container "
|
||||||
"(layer cache keeps repeat builds fast)"
|
"(layer cache keeps repeat builds fast)"
|
||||||
)
|
)
|
||||||
_ensure_builder_dns()
|
_ensure_builder_dns()
|
||||||
args = [_CONTAINER, "build", "-t", ref, "--dns", dns_server()]
|
args = [_CONTAINER, "build", "-t", ref, "--dns", dns_server()]
|
||||||
|
if os.environ.get("BOT_BOTTLE_NO_CACHE") == "1":
|
||||||
|
args.append("--no-cache")
|
||||||
if dockerfile:
|
if dockerfile:
|
||||||
# `container build` resolves -f relative to the current working
|
# `container build` resolves -f relative to the current working
|
||||||
# directory, not the build context. Anchor a relative Dockerfile to
|
# directory, not the build context. Anchor a relative Dockerfile to
|
||||||
@@ -78,6 +86,28 @@ def build_image(ref: str, context: str, *, dockerfile: str = "") -> None:
|
|||||||
subprocess.run(args, check=True)
|
subprocess.run(args, check=True)
|
||||||
|
|
||||||
|
|
||||||
|
def verify_agent_image(image: str, argv: tuple[str, ...]) -> None:
|
||||||
|
"""Run `argv` inside a throwaway container of a freshly built agent
|
||||||
|
image and die loudly if it fails, instead of shipping an image
|
||||||
|
whose CLI only breaks at first real use. No-op when the provider
|
||||||
|
hasn't declared a smoke test (`AgentProviderRuntime.smoke_test`)."""
|
||||||
|
if not argv:
|
||||||
|
return
|
||||||
|
result = subprocess.run(
|
||||||
|
[_CONTAINER, "run", "--rm", "--entrypoint", argv[0], image, *argv[1:]],
|
||||||
|
capture_output=True,
|
||||||
|
text=True,
|
||||||
|
check=False,
|
||||||
|
)
|
||||||
|
if result.returncode != 0:
|
||||||
|
detail = (result.stderr or result.stdout or "").strip()
|
||||||
|
die(
|
||||||
|
f"agent image {image!r} failed its post-build smoke test "
|
||||||
|
f"({' '.join(argv)}): {detail}\n"
|
||||||
|
f"Try rebuilding from scratch: bot-bottle start --no-cache"
|
||||||
|
)
|
||||||
|
|
||||||
|
|
||||||
def commit_container(container_name: str, image_tag: str) -> None:
|
def commit_container(container_name: str, image_tag: str) -> None:
|
||||||
"""Snapshot a running Apple Container as a local image.
|
"""Snapshot a running Apple Container as a local image.
|
||||||
|
|
||||||
|
|||||||
@@ -46,6 +46,17 @@ def cmd_start(argv: list[str]) -> int:
|
|||||||
parser = argparse.ArgumentParser(prog=f"{PROG} start", add_help=True)
|
parser = argparse.ArgumentParser(prog=f"{PROG} start", add_help=True)
|
||||||
parser.add_argument("--dry-run", action="store_true")
|
parser.add_argument("--dry-run", action="store_true")
|
||||||
parser.add_argument("--cwd", action="store_true", help="copy host cwd into the running bottle")
|
parser.add_argument("--cwd", action="store_true", help="copy host cwd into the running bottle")
|
||||||
|
parser.add_argument(
|
||||||
|
"--no-cache",
|
||||||
|
action="store_true",
|
||||||
|
help=(
|
||||||
|
"rebuild agent/sidecar images from scratch, bypassing the "
|
||||||
|
"build layer cache. Use when an image looks broken after a "
|
||||||
|
"dependency bump — e.g. an installer's optionalDependencies "
|
||||||
|
"fetch silently no-op'd on a transient failure and got baked "
|
||||||
|
"into a cached layer."
|
||||||
|
),
|
||||||
|
)
|
||||||
parser.add_argument(
|
parser.add_argument(
|
||||||
"--backend",
|
"--backend",
|
||||||
choices=known_backend_names(),
|
choices=known_backend_names(),
|
||||||
@@ -97,6 +108,11 @@ def cmd_start(argv: list[str]) -> int:
|
|||||||
args = parser.parse_args(argv)
|
args = parser.parse_args(argv)
|
||||||
|
|
||||||
dry_run = args.dry_run or os.environ.get("BOT_BOTTLE_DRY_RUN") == "1"
|
dry_run = args.dry_run or os.environ.get("BOT_BOTTLE_DRY_RUN") == "1"
|
||||||
|
if args.no_cache or os.environ.get("BOT_BOTTLE_NO_CACHE") == "1":
|
||||||
|
# Read by build_image() in each backend's util module — set here
|
||||||
|
# so both the interactive and --headless paths pick it up without
|
||||||
|
# threading a no_cache field through every backend's plan dataclass.
|
||||||
|
os.environ["BOT_BOTTLE_NO_CACHE"] = "1"
|
||||||
|
|
||||||
manifest = ManifestIndex.resolve(USER_CWD)
|
manifest = ManifestIndex.resolve(USER_CWD)
|
||||||
backend_name: str | None = args.backend
|
backend_name: str | None = args.backend
|
||||||
|
|||||||
@@ -91,6 +91,7 @@ _RUNTIME = AgentProviderRuntime(
|
|||||||
prompt_mode="append_file",
|
prompt_mode="append_file",
|
||||||
bypass_args=("--dangerously-skip-permissions",),
|
bypass_args=("--dangerously-skip-permissions",),
|
||||||
resume_args=("--continue",),
|
resume_args=("--continue",),
|
||||||
|
smoke_test=("claude", "--version"),
|
||||||
)
|
)
|
||||||
|
|
||||||
|
|
||||||
|
|||||||
@@ -61,6 +61,7 @@ _RUNTIME = AgentProviderRuntime(
|
|||||||
prompt_mode="read_prompt_file",
|
prompt_mode="read_prompt_file",
|
||||||
bypass_args=("--dangerously-bypass-approvals-and-sandbox",),
|
bypass_args=("--dangerously-bypass-approvals-and-sandbox",),
|
||||||
resume_args=("resume", "--last"),
|
resume_args=("resume", "--last"),
|
||||||
|
smoke_test=(_CODEX_CLI, "--version"),
|
||||||
)
|
)
|
||||||
|
|
||||||
|
|
||||||
|
|||||||
@@ -100,6 +100,7 @@ class DockerGateway(Gateway):
|
|||||||
orchestrator_url: str = "",
|
orchestrator_url: str = "",
|
||||||
build_context: Path | None = None,
|
build_context: Path | None = None,
|
||||||
dockerfile: str | None = GATEWAY_DOCKERFILE,
|
dockerfile: str | None = GATEWAY_DOCKERFILE,
|
||||||
|
host_port_bindings: tuple[int, ...] = (),
|
||||||
) -> None:
|
) -> None:
|
||||||
self.image_ref = image_ref
|
self.image_ref = image_ref
|
||||||
self.name = name
|
self.name = name
|
||||||
@@ -110,6 +111,10 @@ class DockerGateway(Gateway):
|
|||||||
self._orchestrator_url = orchestrator_url
|
self._orchestrator_url = orchestrator_url
|
||||||
self._build_context = build_context or _REPO_ROOT
|
self._build_context = build_context or _REPO_ROOT
|
||||||
self._dockerfile = dockerfile
|
self._dockerfile = dockerfile
|
||||||
|
# Ports published on the host (0.0.0.0). Used by the Firecracker
|
||||||
|
# backend's dev-harness gateway so VMs can reach it via their TAP link;
|
||||||
|
# Docker's DNAT + the nft `ct status dnat accept` rule handle the rest.
|
||||||
|
self._host_port_bindings = host_port_bindings
|
||||||
|
|
||||||
def image_exists(self) -> bool:
|
def image_exists(self) -> bool:
|
||||||
return run_docker(["docker", "image", "inspect", self.image_ref]).returncode == 0
|
return run_docker(["docker", "image", "inspect", self.image_ref]).returncode == 0
|
||||||
@@ -188,6 +193,8 @@ class DockerGateway(Gateway):
|
|||||||
# trust it) — see GATEWAY_CA_VOLUME.
|
# trust it) — see GATEWAY_CA_VOLUME.
|
||||||
"--volume", f"{GATEWAY_CA_VOLUME}:{MITMPROXY_HOME}",
|
"--volume", f"{GATEWAY_CA_VOLUME}:{MITMPROXY_HOME}",
|
||||||
]
|
]
|
||||||
|
for port in self._host_port_bindings:
|
||||||
|
argv += ["--publish", f"0.0.0.0:{port}:{port}"]
|
||||||
if self._orchestrator_url:
|
if self._orchestrator_url:
|
||||||
# Makes the gateway's egress / git / supervise daemons multi-tenant:
|
# Makes the gateway's egress / git / supervise daemons multi-tenant:
|
||||||
# each request resolves source-IP -> policy against the control plane.
|
# each request resolves source-IP -> policy against the control plane.
|
||||||
|
|||||||
@@ -78,7 +78,13 @@ def _source_hash(repo_root: Path) -> str:
|
|||||||
|
|
||||||
class OrchestratorService:
|
class OrchestratorService:
|
||||||
"""Manages the orchestrator control-plane container + the shared gateway.
|
"""Manages the orchestrator control-plane container + the shared gateway.
|
||||||
Callers only need `ensure_running()` + `url`."""
|
Callers only need `ensure_running()` + `url`.
|
||||||
|
|
||||||
|
`orchestrator_name` / `orchestrator_label` let backends run independent
|
||||||
|
orchestrators on the same host without name collisions (e.g. the
|
||||||
|
Firecracker backend uses `bot-bottle-fc-orchestrator` alongside the Docker
|
||||||
|
backend's `bot-bottle-orchestrator`). Subclass and override `_gateway()`
|
||||||
|
to supply a backend-specific gateway variant."""
|
||||||
|
|
||||||
def __init__(
|
def __init__(
|
||||||
self,
|
self,
|
||||||
@@ -89,6 +95,8 @@ class OrchestratorService:
|
|||||||
gateway_image: str = GATEWAY_IMAGE,
|
gateway_image: str = GATEWAY_IMAGE,
|
||||||
repo_root: Path = _REPO_ROOT,
|
repo_root: Path = _REPO_ROOT,
|
||||||
host_root: Path | None = None,
|
host_root: Path | None = None,
|
||||||
|
orchestrator_name: str = ORCHESTRATOR_NAME,
|
||||||
|
orchestrator_label: str = ORCHESTRATOR_LABEL,
|
||||||
) -> None:
|
) -> None:
|
||||||
self.port = port
|
self.port = port
|
||||||
self.network = network
|
self.network = network
|
||||||
@@ -100,6 +108,8 @@ class OrchestratorService:
|
|||||||
self._gateway_image = gateway_image
|
self._gateway_image = gateway_image
|
||||||
self._repo_root = repo_root
|
self._repo_root = repo_root
|
||||||
self._host_root = host_root or bot_bottle_root()
|
self._host_root = host_root or bot_bottle_root()
|
||||||
|
self._orchestrator_name = orchestrator_name
|
||||||
|
self._orchestrator_label = orchestrator_label
|
||||||
|
|
||||||
@property
|
@property
|
||||||
def url(self) -> str:
|
def url(self) -> str:
|
||||||
@@ -111,7 +121,7 @@ class OrchestratorService:
|
|||||||
"""Control-plane URL as the gateway container reaches it — by name over
|
"""Control-plane URL as the gateway container reaches it — by name over
|
||||||
docker DNS on the shared network. This is the gateway's
|
docker DNS on the shared network. This is the gateway's
|
||||||
BOT_BOTTLE_ORCHESTRATOR_URL."""
|
BOT_BOTTLE_ORCHESTRATOR_URL."""
|
||||||
return f"http://{ORCHESTRATOR_NAME}:{self.port}"
|
return f"http://{self._orchestrator_name}:{self.port}"
|
||||||
|
|
||||||
def is_healthy(self, *, timeout: float = _HEALTH_REQUEST_TIMEOUT_SECONDS) -> bool:
|
def is_healthy(self, *, timeout: float = _HEALTH_REQUEST_TIMEOUT_SECONDS) -> bool:
|
||||||
try:
|
try:
|
||||||
@@ -129,11 +139,11 @@ class OrchestratorService:
|
|||||||
fixed-name container first). Register-only broker → no docker socket.
|
fixed-name container first). Register-only broker → no docker socket.
|
||||||
Labels the container with `source_hash` so a later `ensure_running`
|
Labels the container with `source_hash` so a later `ensure_running`
|
||||||
can detect a real code change (see `_source_hash`)."""
|
can detect a real code change (see `_source_hash`)."""
|
||||||
run_docker(["docker", "rm", "--force", ORCHESTRATOR_NAME])
|
run_docker(["docker", "rm", "--force", self._orchestrator_name])
|
||||||
proc = run_docker([
|
proc = run_docker([
|
||||||
"docker", "run", "--detach",
|
"docker", "run", "--detach",
|
||||||
"--name", ORCHESTRATOR_NAME,
|
"--name", self._orchestrator_name,
|
||||||
"--label", ORCHESTRATOR_LABEL,
|
"--label", self._orchestrator_label,
|
||||||
"--label", f"{ORCHESTRATOR_SOURCE_HASH_LABEL}={source_hash}",
|
"--label", f"{ORCHESTRATOR_SOURCE_HASH_LABEL}={source_hash}",
|
||||||
"--network", self.network,
|
"--network", self.network,
|
||||||
# Host CLI reaches the control plane here; bound to loopback so it
|
# Host CLI reaches the control plane here; bound to loopback so it
|
||||||
@@ -185,12 +195,12 @@ class OrchestratorService:
|
|||||||
*current* bind-mounted source. Mirrors `DockerGateway`'s
|
*current* bind-mounted source. Mirrors `DockerGateway`'s
|
||||||
image-staleness check, but by content hash rather than image id since
|
image-staleness check, but by content hash rather than image id since
|
||||||
the orchestrator runs bind-mounted source, not a built image."""
|
the orchestrator runs bind-mounted source, not a built image."""
|
||||||
if not self._container_running(ORCHESTRATOR_NAME):
|
if not self._container_running(self._orchestrator_name):
|
||||||
return False
|
return False
|
||||||
proc = run_docker([
|
proc = run_docker([
|
||||||
"docker", "inspect", "--format",
|
"docker", "inspect", "--format",
|
||||||
"{{ index .Config.Labels \"" + ORCHESTRATOR_SOURCE_HASH_LABEL + "\" }}",
|
"{{ index .Config.Labels \"" + ORCHESTRATOR_SOURCE_HASH_LABEL + "\" }}",
|
||||||
ORCHESTRATOR_NAME,
|
self._orchestrator_name,
|
||||||
])
|
])
|
||||||
if proc.returncode != 0:
|
if proc.returncode != 0:
|
||||||
return True # can't compare -> don't churn a working container
|
return True # can't compare -> don't churn a working container
|
||||||
@@ -219,7 +229,10 @@ class OrchestratorService:
|
|||||||
return self.url
|
return self.url
|
||||||
|
|
||||||
self._ensure_orchestrator_image()
|
self._ensure_orchestrator_image()
|
||||||
log.info("starting orchestrator container", context={"name": ORCHESTRATOR_NAME})
|
log.info(
|
||||||
|
"starting orchestrator container",
|
||||||
|
context={"name": self._orchestrator_name},
|
||||||
|
)
|
||||||
self._run_orchestrator_container(current_hash)
|
self._run_orchestrator_container(current_hash)
|
||||||
|
|
||||||
deadline = time.monotonic() + startup_timeout
|
deadline = time.monotonic() + startup_timeout
|
||||||
@@ -234,7 +247,7 @@ class OrchestratorService:
|
|||||||
|
|
||||||
def stop(self) -> None:
|
def stop(self) -> None:
|
||||||
"""Remove the orchestrator + gateway containers (idempotent)."""
|
"""Remove the orchestrator + gateway containers (idempotent)."""
|
||||||
run_docker(["docker", "rm", "--force", ORCHESTRATOR_NAME])
|
run_docker(["docker", "rm", "--force", self._orchestrator_name])
|
||||||
self._gateway().stop()
|
self._gateway().stop()
|
||||||
|
|
||||||
|
|
||||||
|
|||||||
@@ -91,6 +91,7 @@ class TestLaunchCommittedImage(unittest.TestCase):
|
|||||||
with mock.patch.object(launch_mod, "read_committed_image", return_value=committed_tag), \
|
with mock.patch.object(launch_mod, "read_committed_image", return_value=committed_tag), \
|
||||||
mock.patch.object(launch_mod.docker_mod, "image_exists", return_value=image_present), \
|
mock.patch.object(launch_mod.docker_mod, "image_exists", return_value=image_present), \
|
||||||
mock.patch.object(launch_mod.docker_mod, "build_image", side_effect=_build), \
|
mock.patch.object(launch_mod.docker_mod, "build_image", side_effect=_build), \
|
||||||
|
mock.patch.object(launch_mod.docker_mod, "verify_agent_image"), \
|
||||||
mock.patch.object(launch_mod, "launch_consolidated", return_value=_CTX), \
|
mock.patch.object(launch_mod, "launch_consolidated", return_value=_CTX), \
|
||||||
mock.patch.object(launch_mod, "teardown_consolidated"), \
|
mock.patch.object(launch_mod, "teardown_consolidated"), \
|
||||||
mock.patch.object(launch_mod, "DockerGateway", return_value=gw), \
|
mock.patch.object(launch_mod, "DockerGateway", return_value=gw), \
|
||||||
|
|||||||
@@ -94,6 +94,7 @@ class TestTeardownWarning(unittest.TestCase):
|
|||||||
)
|
)
|
||||||
|
|
||||||
with mock.patch.object(launch_mod.docker_mod, "build_image"), \
|
with mock.patch.object(launch_mod.docker_mod, "build_image"), \
|
||||||
|
mock.patch.object(launch_mod.docker_mod, "verify_agent_image"), \
|
||||||
mock.patch.object(launch_mod, "launch_consolidated", return_value=ctx), \
|
mock.patch.object(launch_mod, "launch_consolidated", return_value=ctx), \
|
||||||
mock.patch.object(launch_mod, "teardown_consolidated"), \
|
mock.patch.object(launch_mod, "teardown_consolidated"), \
|
||||||
mock.patch.object(launch_mod, "DockerGateway", return_value=gw), \
|
mock.patch.object(launch_mod, "DockerGateway", return_value=gw), \
|
||||||
|
|||||||
Reference in New Issue
Block a user