Document approaches for site builds on top of EESSI - #778
Conversation
first attempt at writing the shared fs section
…, after a reboot, the stratum 0 overlay won't mount
…cript. Also, added a full, copyable script combining all the previous components.
Neves-P
left a comment
There was a problem hiding this comment.
Looks really nice! This is my first pass of comments, as of know I only focused on the text. This week I will follow the documentation in practice and review again.
Co-authored-by: Pedro Santos Neves <10762799+Neves-P@users.noreply.github.com>
Co-authored-by: Bob Dröge <b.e.droge@rug.nl>
Co-authored-by: Bob Dröge <b.e.droge@rug.nl>
Neves-P
left a comment
There was a problem hiding this comment.
Suggestions with updates accounting for VERSIONS_SUBPATH workflow in ingest-tarball.sh.
Co-authored-by: Pedro Santos Neves <10762799+Neves-P@users.noreply.github.com>
| # We will leverage a script from eessi-bot-software-layer (for signature verification - optional) | ||
| git clone https://github.com/EESSI/eessi-bot-software-layer.git | ||
|
|
||
| # We will leverage a script from filesystem-layer (for tarball ingestion) | ||
| git clone https://github.com/EESSI/filesystem-layer.git |
There was a problem hiding this comment.
Having these here will break things for a second run, as these dirs will already exist. We should either add a check, or maybe just let people do this manually and add a variable for the paths to these dirs at the top? I think I'd prefer the latter, makes it a bit more flexible in case you want to (temporarily) modify these scripts, e.g. for testing.
| if [ $? -eq 0 ]; then | ||
| echo "Tarball signature file downloaded." | ||
| else | ||
| echo "WARNING: Failed to download tarball signature file. Continuing to next tarball (not ingesting ${filename})." | ||
| # No point in continuing this loop iteration, we'll fail the signature verification check anyway | ||
| continue | ||
| fi |
There was a problem hiding this comment.
This basically does mean that it's not optional, as it will now entirely skip tarballs with a signature file. Maybe we should have another variable at the top that allows people to enable/disable the signature checking? If it's enabled but the sig file(s) cannot be downloaded -> hard error for that tarball. If it's disabled, don't even try.
There was a problem hiding this comment.
I tried addressing this in the last batch of suggestions.
Neves-P
left a comment
There was a problem hiding this comment.
I haven't tested this in the wild yet, but here's a simple proposal for handling cases when we don't want to sign the files. It ignores that step if $ALLOWED_SIGNERS is not set and writes a message saying so. If the file is there, it carries on with the signature workflow as usual.
Co-authored-by: Pedro Santos Neves <10762799+Neves-P@users.noreply.github.com>
Co-authored-by: Pedro Santos Neves <10762799+Neves-P@users.noreply.github.com>
Co-authored-by: Bob Dröge <b.e.droge@rug.nl>
|
I think I got everything now, @bedroge 🤞 |
bedroge
left a comment
There was a problem hiding this comment.
The current version of the auto-ingestion script worked fine for me (I didn't use/test the signing part, though). Note that I haven't checked the other parts in detail, but it looks like @Neves-P did that (?). So, if you're also okay with it, I'd say we merge this and improve things later if necessary. Given the size of this document, it's hard to read/review the unrendered document anyway 😄
|
I think we should merge this indeed! We've collectively reviewed and tried this a lot. We may find small issues along the way as more and more sites test it, but I think we're at a stage where the information is tried in the wild for a couple of sites, RUG included. As more sysadmins implement it we will probably find out edge cases or inaccuracies we haven't spotted yet, but we can should always keep improving the docs anyway. |
|
I think we also need @ocaisa's approval here ;) |
He better reads the entire document and tests all the steps 🤣 |
|
I didn't know we could dismiss comments 😆 Then sure, that makes sense (unless you're looking for a new book to read, Alan 😆 ) |
I think these have all been addressed already in subsequent reviews.
No description provided.