No description
Find a file
Ondřej Budai 974c258382 schutzbot: run openstack/* jobs on a dedicated runner
We have limited resources in openstack. We can only run about 40 concurrent VMs.
Previously, the rate limiting was kinda stupid:

All (aws and openstack) jobs were run using the same runner. This runner was
globally limited to 60 concurrent jobs. For openstack, the individual
images were also limited to a certain number of concurrent jobs in
the gitlab-ci-terraform repository so we don't hit the quota. This limit
was applied at runtime - the first thing that an openstack job did was to
wait for a slot. This job counted towards the global limit of jobs (60)
and thus was blocking one slot without doing any useful work.

Applying local limits to please global quota is stupid though. We have much
more demand for rhel-8.5 runner than for e.g. Fedora. It would be much
better to just use global limit that would map much nicely to global
quota.

Today, I've introduced a new runner with tag terraform/openstack. It's
currently limited to 20 concurrent jobs. All jobs running on openstack should
run on the new runner. This runner has the local rate limiting for openstack
disabled. This means that we can run 20 concurrent openstack jobs and it
doesn't matter which distribution they run.

To sum it up, this has two benefits:
- no local limits, we can just use the full quota
- no idling jobs waiting for an openstack slot

Note that the openstack global limit is currently set to 20, I will raise
it once all PRs are rebased on top of this change.

Side effect: I moved all libvirt test to openstack. I think this is overall
better because testing guest images on KVM makes more sense than testing them
on TCG.

Signed-off-by: Ondřej Budai <ondrej@budai.cz>
2021-09-04 23:14:58 +02:00
.devcontainer devcontainer: run container with privileges 2021-08-28 09:20:19 +02:00
.github build(deps): bump actions/setup-go from 1 to 2.1.4 2021-09-04 12:13:36 +02:00
cmd auth: OpenID/OAUth2 middleware 2021-09-04 02:48:52 +02:00
containers/osbuild-composer containers: Specify port for the composer-api as argument 2020-12-23 17:31:29 +01:00
distribution jobqueue: Introduce jobqueue backed by a postgres database 2021-07-28 21:52:31 +01:00
docs auth: OpenID/OAUth2 middleware 2021-09-04 02:48:52 +02:00
image-types image-types: Update RHEL8 Amazon EC2 image information 2021-01-15 17:48:19 +01:00
internal auth: OpenID/OAUth2 middleware 2021-09-04 02:48:52 +02:00
repositories distro: introduce Fedora 36 alias 2021-09-03 15:05:00 +02:00
schutzbot ci: update terraform sha 2021-09-03 11:15:32 +02:00
test auth: OpenID/OAUth2 middleware 2021-09-04 02:48:52 +02:00
tools rhel90: fix libvirt_test 2021-09-03 11:15:32 +02:00
vendor build(deps): bump github.com/Azure/azure-storage-blob-go 2021-09-04 19:42:10 +02:00
.gitignore gitignore: add config and OSX metadata 2021-02-20 14:53:49 +01:00
.gitlab-ci.yml schutzbot: run openstack/* jobs on a dedicated runner 2021-09-04 23:14:58 +02:00
.golangci.yml ci/lint: add integration tag 2020-03-17 20:36:58 +01:00
.packit.yaml Add support for packit 2021-09-02 23:06:51 +02:00
codecov.yml codevoc: fix threshold 2020-05-17 10:12:06 +02:00
CONTRIBUTING.md rcm: drop sub-package 2020-07-17 19:13:15 +01:00
DEPLOYING.md Add DEPLOYING.md 2020-10-20 15:43:30 +02:00
dnf-json dnf-json: don't initialize dnf plugins 2020-08-23 16:08:25 +02:00
go.mod build(deps): bump github.com/Azure/azure-storage-blob-go 2021-09-04 19:42:10 +02:00
go.sum build(deps): bump github.com/Azure/azure-storage-blob-go 2021-09-04 19:42:10 +02:00
HACKING.md HACKING: Typo fixes 2021-02-11 09:37:36 +01:00
krb5.conf upload/koji: add support for GSSAPI/Kerberos auth 2020-08-27 17:29:57 +01:00
LICENSE Revert "Fill in the license template" 2019-11-15 15:26:51 +01:00
Makefile auth: OpenID/OAUth2 middleware 2021-09-04 02:48:52 +02:00
NEWS.md 33 2021-08-30 19:03:46 +02:00
osbuild-composer.spec auth: OpenID/OAUth2 middleware 2021-09-04 02:48:52 +02:00
README.md bump minimum go version to 1.15 2021-07-07 17:26:18 +01:00
RELEASING.md docs: document the release process 2021-07-14 12:11:35 +02:00
Schutzfile ci: unpin osbuild for RHEL 9.0 2021-08-28 09:20:19 +02:00

OSBuild Composer

Operating System Image Composition Services

The composer project is a set of HTTP services for composing operating system images. It builds on the pipeline execution engine of osbuild and defines its own class of images that it supports building.

Multiple APIs are available to access a composer service. This includes support for the lorax-composer API, and as such can serve as drop-in replacement for lorax-composer.

You can control a composer instance either directly via the provided APIs, or through higher-level user-interfaces from external projects. This, for instance, includes a Cockpit Module or using the composer-cli command-line tool.

Project

About

Composer is a middleman between the workhorses from osbuild and the user-interfaces like cockpit-composer, composer-cli, or others. It defines a set of high-level image compositions that it supports building. Builds of these compositions can be requested via the different APIs of Composer, which will then translate the requests into pipeline-descriptions for osbuild. The pipeline output is then either provided back to the user, or uploaded to a user specified target.

The following image visualizes the overall architecture of the OSBuild infrastructure and the place that Composer takes:

overview

Consult the osbuild-composer(7) man-page for an introduction into composer, information on running your own composer instance, as well as details on the provided infrastructure and services.

Requirements

The requirements for this project are:

  • osbuild >= 26
  • systemd >= 244

At build-time, the following software is required:

  • go >= 1.15
  • python-docutils >= 0.13

Build

The standard go package system is used. Consult upstream documentation for detailed help. In most situations the following commands are sufficient to build and install from source:

mkdir build
go build -o build ./...

The man-pages require python-docutils and can be built via:

make man

Repository:

Pull request gating

Each pull request against osbuild-composer starts a series of automated tests. Tests run via GitHub Actions and Jenkins. Each push to the pull request will launch theses tests automatically.

Jenkins only tests pull requests from members of the osbuild organization in GitHub. A member of the osbuild organization must say ok to test in a pull request comment to approve testing. Anyone can ask for testing to run by saying the bot's favorite word, schutzbot, in a pull request comment. Testing will begin shortly after the comment is posted.

Test results in Jenkins are available by clicking the Details link on the right side of the Schutzbot check in the pull request page.

License:

  • Apache-2.0
  • See LICENSE file for details.