feat(tmachine): support runtime input overrides
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 4/5
- Tempo stimato
- 3-5 giorni
- Idoneità per principianti
- 68/100
- Tipo di issue
- Funzionalità
- Chiarezza
- Abbastanza chiara
- Stato di attività
- Attiva
- Stack tecnologico
- rust
- Ambito
- cli, release, testing-qa
Direzione di ricerca
Inizia dai punti di ingresso dei comandi install e test di tmachine e dalla gestione degli input di config.yaml descritta nell’issue. Traccia il modo in cui gli input dell’installer vengono canonicalizzati, inclusi nell’hash del livello di installazione e passati ad Ansible. Aggiungi unit test per il parsing, la precedenza, la validazione e l’invalidazione della cache; il lavoro è completato quando entrambi i comandi accettano override ripetibili e la suite di conformità Debian utilizza riferimenti immutabili a immagini candidate senza tag :tmachine fissi.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
User Story
As an integration-test author, I want to override named tmachine inputs at runtime, so that CI can test candidate artifacts using values that are known only when the workflow runs.
Problem Statement
Tmachine inputs are currently fixed in its generated YAML configuration. The install and test commands have no runtime input override, even though release-specific values such as the candidate image SHA are available to the workflow only at runtime.
The Debian conformance lane introduced in #3461 therefore loads candidate supervisor and sandbox images under the fixed :tmachine tag and writes those references into the test user's gateway configuration. This safely prevents the packaged gateway from resolving its embedded dev or release-version tag, but it hides the candidate image identity and couples the playbook to a synthetic tag.
Using the package's embedded image tag is not a safe replacement. Release Dev could refresh :dev from the registry and test an older published image, while Release Tag runs before the versioned images are published.
Impact / Why This Matters
The current fixed-tag override keeps conformance deterministic, but CI cannot express the actual candidate image tag through tmachine. That makes artifact provenance less obvious and creates a risk that a future cleanup removes the override and accidentally pulls a previously published image during release validation.
Regenerating the Nix-backed tmachine configuration for every workflow value would move runtime CI data into build-time configuration and make local reproduction unnecessarily difficult.
Proposed Design
Add a repeatable runtime --input NAME=VALUE option to the tmachine install and test commands. Runtime values should override matching configured inputs before tmachine hashes the install layer and invokes Ansible.
The resulting workflow should allow release CI to retain the candidate images' immutable source-SHA tags and invoke tmachine with an override such as:
tmachine test ubuntu-docker-rootful deb conformance \
--input openshell_runtime_image_tag="$SOURCE_SHA"
The Debian installer can then write the source-SHA image references into its minimal per-user gateway configuration. The packaged systemd unit and all other built-in gateway defaults remain unchanged.
Acceptance Criteria
-
tmachine installaccepts repeatable--input NAME=VALUEoverrides. -
tmachine testaccepts the same overrides for the installer phase. - Runtime values take precedence over matching installer inputs from
config.yaml. - Malformed overrides and unknown input names fail with actionable errors.
- Effective override values participate in the install-layer cache key.
- Existing file-path inputs continue to be canonicalized when the referenced file exists, while scalar values do not need to name an existing file.
- Unit tests cover parsing, precedence, validation, and cache invalidation.
- Release Dev and Release Tag can pass the candidate source SHA to the Debian installer and remove the fixed
:tmachineimage references. - The Debian conformance lane continues to use a local immutable candidate image and does not pull
devor release-version runtime images from the registry.
Alternatives Considered
- Keep the fixed
:tmachinealias. This is deterministic but obscures which candidate image is under test and leaves the workflow coupled to a synthetic name. - Use the image tag embedded in the packaged gateway. This can pull an older
devimage, and versioned release images are not published until after conformance succeeds. - Generate a new tmachine configuration in CI. This mixes runtime workflow values into Nix evaluation and makes equivalent local invocations harder to reproduce.
Agent Investigation
Tmachine currently stores installer and testsuite inputs as BTreeMap<String, PathBuf>. Existing paths are canonicalized before becoming Ansible extra variables; nonexistent paths are already passed through as literal values. Installer inputs are also part of the cached install-layer hash, so runtime overrides must be applied before both hashing and playbook execution.
Related to #3454 and follow-up to #3461.
- Lingua principale
- Rust
- Stelle
- 8.7k
- Fork
- 1.3k
- Merge medio
- 2g 8h
- PR unite (30g)
- 271
Guida per i contributori
Apri la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di NVIDIA/OpenShell
-
area:docs
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 88/100
-
state:triage-needed
Difficoltà 2/5 1-3 ore Idoneità per principianti 82/100
-
area:cli state:validated
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
-
state:triage-needed
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 90/100
-
area:build spike state:review-ready state:stale
Difficoltà 2/5 Mezza giornata Idoneità per principianti 68/100
Tutte le issue di NVIDIA/OpenShell
Issue simili
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 75/100
-
issue
Difficoltà 2/5 1-3 ore Idoneità per principianti 65/100
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 75/100
-
agentic-workflows
Difficoltà 2/5 1-3 ore Idoneità per principianti 70/100
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 88/100
web-infra-dev/rspack#15847 ·