Standardize host-side tooling delivery with onebox-kit
メンテナーはふだん 1 日以内に返信
まだ誰も着手していません。
評価
- 難易度
- 5/5
- 見積もり時間
- 1週間以上
- 初心者へのやさしさ
- 35/100
調査の方向性
まず、/schedule/execution-v1.py にある現在の永続 helper、wal-g のアップロードおよびチェックサムのパス、既存の onebox-postgres イメージのリリースパスを追跡します。次に、apply、enable、スケジュール実行、読み取り専用診断に対応する ob のエントリポイントを調べます。digest、rollback、air-gapped、cleanup、および Docker に依存しない診断動作が、テストによってカバーされた状態で設計が実装されていれば完了です。
索引モデルが issue の本文から書いたものです。
説明
Context
ob runs from the operator machine and manages one Linux host over SSH. Onebox is agentless: it must not add a resident daemon or listening control port to that host. Linux, SSH, Docker, and Buildx are already prerequisites.
Today, host-side artifacts arrive through different paths:
- The proxy stack is a multi-arch OCI image.
- Durable scheduled executions use an embedded Python helper, copied over SSH to
<appdir>/schedule/execution-v1.py; it requires/usr/bin/python33.8+. - wal-g is downloaded on the operator machine, checked against a hand-maintained per-architecture SHA-256 table, then uploaded over SSH and mounted into Postgres.
onebox-postgresis already a custom multi-arch OCI image.
Workload volume backup will require Onebox-owned host-side logic plus a backup engine. Adding another uploaded binary or interpreter would create another delivery, verification, architecture, upgrade, and test path.
Problem
Settle a durable installation model for Onebox-owned host-side tooling, including workload-volume backup, without violating the agentless contract.
The design must cover:
- delivery and verification across amd64 and arm64;
- registry-mirrored or preloaded hosts as well as normal registry access;
- versioning, upgrades, rollback, retention, and cleanup;
- the Python durable-execution helper and its host prerequisite;
- wal-g, which PostgreSQL must execute inside its own container;
- Docker-unavailable diagnostics; and
- a small, stable public runtime interface rather than an unbounded utility image.
Proposal
Use OCI images as the standard delivery mechanism. Add a multi-arch, digest-pinned companion image:
ghcr.io/labstack/onebox-kit@sha256:…
onebox-kit is a short-lived runtime, never a daemon. ob pulls or verifies the exact image digest during an explicit apply/enable operation; generated units and durable state record that digest. Scheduled invocations use the installed image and must not fetch from a registry.
The image contains only:
onebox-kit, a Go program replacing the embedded Python helper and implementing the durable-execution state protocol plus volume-backup orchestration;- Docker CLI and Compose plugin while the execution protocol still uses Docker/Compose inspection and control through the mounted host Docker socket;
- one folder-backup engine, initially expected to be restic; and
- CA certificates and timezone data.
Its interface is intentionally small:
onebox-kit execution …
onebox-kit volume …
onebox-kit version
Do not expose the backup engine directly as the Onebox protocol. Do not add SSH, package management, credentials, a generic administration toolbox, a listener, or a resident process.
Package wal-g in the existing multi-arch onebox-postgres image instead of materializing it from onebox-kit: wal-g runs from PostgreSQL archive commands, so the database image is its natural runtime location. This removes the uploaded per-architecture binary and checksum map without adding a host-side installer or tool-volume garbage collector.
Keep Docker-independent execution evidence available: list/inspect should read and validate durable records over SSH without requiring the Docker daemon. Mutating execution paths can require Docker; read-only diagnosis must not regress.
Delivery and maintenance contract
- Compile the immutable image index digest into the matching
obrelease; human-readable tags are informational only. - Build/test/publish amd64 and arm64 variants in the normal release train, with SBOM/provenance attestations and signature verification if publisher provenance is a product requirement. A digest establishes content identity, not publisher identity.
- Start with one repository and release train, while retaining separate Go packages and tests for execution and backup. Split release cadence only if an operational need becomes concrete.
- Before rewriting units or backup state, verify the pinned digest is locally available or pull it. Fail before mutation if it is unavailable.
- For air-gapped or registry-restricted hosts, support the existing mirror/preload model and qualify the exact Docker stores/versions used. Do not add an SSH-push fallback, and do not assume arbitrary
docker save/loadpreserves the source multi-arch digest reference without testing it. - Retain images referenced by installed units, recorded execution state, or live backup state. Remove only specifically identified, unreferenced digests; never use broad Docker prune as lifecycle management.
- Give each invocation the least authority needed: execution receives the Docker socket and only required host state; backup receives only its declared source/destination mounts and read-only credentials/CA material.
Non-goals
- Installing a host package, interpreter, or resident Onebox agent.
- A new control port.
- A generic remote administration container.
- Hiding workload-backup consistency semantics; that contract is separate and must be explicit.
Decision criteria
The result should replace, rather than add to, the current artifact-delivery matrix; remove host Python and architecture tables for Onebox-owned logic; preserve safe rollback and diagnostics; and keep Onebox agentless.
- 主要言語
- Go
- スター
- 4
- フォーク
- 0
- 平均マージ
- 2時間 46分
- マージ済み PR(30日)
- 38
環境構築
- Dockerfile・Docker Compose ファイルなし
- プルリクエストのテンプレートあり
- コントリビューションガイドを読む
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
labstack/onebox のほかの issue
-
bug
難易度 1/5 1時間未満 初心者へのやさしさ 80/100
メンテナーはふだん 1 日以内に返信
-
bug
難易度 1/5 1時間未満 初心者へのやさしさ 85/100
メンテナーはふだん 1 日以内に返信
-
bug
難易度 1/5 1時間未満 初心者へのやさしさ 85/100
メンテナーはふだん 1 日以内に返信
-
bug
難易度 3/5 1〜2日 初心者へのやさしさ 65/100
メンテナーはふだん 1 日以内に返信
-
難易度 4/5 3〜5日 初心者へのやさしさ 55/100
メンテナーはふだん 1 日以内に返信
labstack/onebox の issue をすべて見る
似ている issue
-
enhancement exporter/awss3 needs triage
難易度 2/5 1〜3時間 初心者へのやさしさ 66/100
open-telemetry/opentelemetry-collector-contrib#51905 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
area/docs theme/validation
難易度 1/5 1〜3時間 初心者へのやさしさ 88/100
メンテナーはふだん 1 日以内に返信
-
a11y P1-significant
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
メンテナーはふだん 1 日以内に返信
-
[correctness][missing-coverage][sort] Strict uniqueness checks lack numeric-key equivalence coverageオープン
難易度 2/5 1〜3時間 初心者へのやさしさ 77/100
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 83/100
infiniflow/ragflow#20625 · リアクション 1 件 ·
メンテナーはふだん 1 日以内に返信