about summary refs log tree commit diff
path: root/tools/nixery/server/builder
AgeCommit message (Collapse)AuthorFilesLines
2019-10-28 refactor(server): Change setup to create new storage backendsVincent Ambo2-5/+1
2019-10-28 refactor(server): Introduce pluggable interface for storage backendsVincent Ambo2-132/+63
This abstracts over the functionality of Google Cloud Storage and other potential underlying storage backends to make it possible to replace these in Nixery. The GCS backend is not yet reimplemented.
2019-10-11 refactor(server): Only compress symlink forest layer onceVincent Ambo1-8/+19
Instead of compressing & decompressing again to get the underlying tar hash, use a similar mechanism as for store path layers for the symlink layer and only compress it once while uploading.
2019-10-11 fix(server): Use uncompressed tarball hashes in image configVincent Ambo2-11/+32
Docker expects hashes of compressed tarballs in the manifest (as these are used to fetch from the content-addressable layer store), but for some reason it expects hashes in the configuration layer to be of uncompressed tarballs. To achieve this an additional SHA256 hash is calculcated while creating the layer tarballs, but before passing them to the gzip writer. In the current constellation the symlink layer is first compressed and then decompressed again to calculate its hash. This can be refactored in a future change.
2019-10-11 feat(server): Apply GZIP compression to all image layersVincent Ambo2-5/+11
This fixes #62
2019-10-06 refactor(server): Use logrus convenience functions for logsVincent Ambo2-80/+42
Makes use of the `.WithError` and `.WithField` convenience functions in logrus to simplify log statement construction. This has the added benefit of making it easier to correctly log errors.
2019-10-06 refactor(server): Convert existing log entries to structured formatVincent Ambo3-34/+158
This rewrites all existing log statements into the structured logrus format. For consistency, all errors are always logged separately from the primary message in a field called `error`. Only the "info", "error" and "warn" severities are used.
2019-10-06 fix(server): Amend package path for Go tooling compatibilityVincent Ambo3-5/+5
With these changes it is possible to keep Nixery in $GOPATH and build the server in there, while still having things work correctly via Nix.
2019-10-06 refactor(server): Replace log calls with logrusVincent Ambo3-3/+3
This introduces a structured logging library that can be used (next step) to attach additional metadata to log entries.
2019-10-03 refactor(server): Always include 'cacert' & 'iana-etc'Vincent Ambo1-2/+3
These two packages almost always end up being required by programs, but people don't necessarily consider them. They will now always be added and their popularity is artificially inflated to ensure they end up at the top of the layer list.
2019-10-03 fix(server): Ensure build cache objects are written to GCSVincent Ambo1-0/+5
Cache writes might not be flushed without this call.
2019-10-03 feat(server): Order layers in image manifest based on merge ratingVincent Ambo1-0/+1
Image layers in manifests are now sorted in a stable (descending) order based on their merge rating, meaning that layers more likely to be shared between images come first. The reason for this change is Docker's handling of image layers on overlayfs2: Images are condensed into a single representation on disk after downloading. Due to this Docker will constantly redownload all layers that are applied in a different order in different images (layer order matters in imperatively created images), based on something it calls the 'ChainID'. Sorting the layers this way raises the likelihood of a long chain of matching layers at the beginning of an image. This relates to #39.
2019-10-03 feat(server): Implement creation of layer tarballs in the serverVincent Ambo2-79/+158
This will create, upload and hash the layer tarballs in one disk read.
2019-10-03 fix(server): Do not invoke layer build if no layers are missingVincent Ambo1-1/+5
This previously invoked a Nix derivation that spent a few seconds on making an empty object in JSON ...
2019-10-03 feat(server): Reimplement local manifest cache backed by filesVincent Ambo3-46/+56
Implements a local manifest cache that uses the temporary directory to cache manifest builds. This is necessary due to the size of manifests: Keeping them entirely in-memory would quickly balloon the memory usage of Nixery, unless some mechanism for cache eviction is implemented.
2019-10-03 refactor(builder): Streamline layer creation & reintroduce cachingVincent Ambo1-28/+53
The functions used for layer creation are now easier to follow and have clear points at which the layer cache is checked and populated. This relates to #50.
2019-10-03 refactor: Remove remaining MD5-hash mentions and computationsVincent Ambo1-15/+9
2019-10-03 refactor(server): Cache manifest entries for layer buildsVincent Ambo1-30/+26
MD5 hash checking is no longer performed by Nixery (it does not seem to be necessary), hence the layer cache now only keeps the SHA256 hash and size in the form of the manifest entry. This makes it possible to restructure the builder code to perform cache-fetching and cache-populating for layers in the same place.
2019-10-03 feat(server): Reintroduce manifest caching to GCSVincent Ambo2-29/+29
The new builder now caches and reads cached manifests to/from GCS. The in-memory cache is disabled, as manifests are no longer written to local file and the caching of file paths does not work (unless we reintroduce reading/writing from temp files as part of the local cache).
2019-10-03 refactor(server): Clean up cache implementationVincent Ambo2-23/+22
A couple of minor fixes and improvements to the cache implementation.
2019-10-03 chore(server): Remove "layer seen" cacheVincent Ambo1-29/+5
This cache is no longer required as it is implicit because the layer cache (mapping store path hashes to layer hashes) implies that a layer has been seen.
2019-10-03 fix(server): Upload symlink layer created by first Nix buildVincent Ambo1-1/+6
This layer is needed in addition to those that are built in the second Nix build.
2019-10-03 fix(server): Specify correct authentication scope for GCSVincent Ambo1-1/+4
When retrieving tokens for service service accounts, some methods of retrieval require a scope to be specified.
2019-10-03 feat(server): Implement new build process coreVincent Ambo1-58/+52
Implements the new build process to the point where it can actually construct and serve image manifests. It is worth noting that this build process works even if the Nix sandbox is enabled! It is also worth nothing that none of the caching functionality that the new build process enables (such as per-layer build caching) is actually in use yet, hence running Nixery at this commit is prone to doing more work than previously. This relates to #50.
2019-10-03 fix(server): Minor fixes to updated new builder codeVincent Ambo1-6/+5
2019-10-03 feat(server): Reimplement creation & uploading of layersVincent Ambo1-85/+248
The new build process can now call out to Nix to create layers and upload them to the bucket if necessary. The layer cache is populated, but not yet used.
2019-10-03 refactor(server): Introduce a state type to carry runtime stateVincent Ambo1-0/+24
The state type contains things such as the bucket handle and Nixery's configuration which need to be passed around in the builder. This is only added for convenience.
2019-10-03 feat(server): Add cache for layer builds in GCS & local cacheVincent Ambo1-0/+86
This cache is going to be used for looking up whether a layer build has taken place already (based on a hash of the layer contents). See the caching section in the updated documentation for details. Relates to #50.
2019-09-21 feat(server): Log Nix output live during the buildsVincent Ambo1-3/+12
Instead of dumping all Nix output as one at the end of the build process, stream it live as the lines come in. This is a lot more useful for debugging stuff like where manifest retrievals get stuck.
2019-09-21 feat: Add configuration option for popularity data URLVincent Ambo1-0/+4
2019-09-10 refactor(builder): Calculate image cache key only onceVincent Ambo2-17/+15
2019-09-10 feat(server): Cache built manifests to the GCS bucketVincent Ambo2-22/+95
Caches manifests under `manifests/$cacheKey` in the GCS bucket and introduces two-tiered retrieval of manifests from the caches (local first, bucket second). There is some cleanup to be done in this code, but the initial version works.
2019-09-10 refactor(server): Use package source specific cache keysVincent Ambo2-32/+21
Use the PackageSource.CacheKey function introduced in the previous commit to determine the key at which a manifest should be cached in the local cache. Due to this change, manifests for moving target sources are no longer cached and the recency threshold logic has been removed.
2019-09-10 refactor(server): Move package source management logic to serverVincent Ambo1-3/+4
Introduces three new types representing each of the possible package sources and moves the logic for specifying the package source to the server. Concrete changes: * Determining whether a specified git reference is a commit vs. a branch/tag is now done in the server, and is done more precisely by using a regular expression. * Package sources now have a new `CacheKey` function which can be used to retrieve a key under which a build manifest can be cached *if* the package source is not a moving target (i.e. a full git commit hash of either nixpkgs or a private repository). This function is not yet used. * Users *must* now specify a package source, Nixery no longer defaults to anything and will fail to launch if no source is configured.
2019-09-02 feat(server): Add configuration option for Nix build timeoutsVincent Ambo1-0/+1
Adds a NIX_TIMEOUT environment variable which can be set to a number of seconds that is the maximum allowed time each Nix builder can run. By default this is set to 60 seconds, which should be plenty for most use-cases as Nixery is not expected to be performing builds of uncached binaries in most production cases. Currently the errors Nix throws on a build timeout are not separated from other types of errors, meaning that users will see a generic 500 server error in case of a timeout. This fixes #47
2019-08-17 fix(server): Sort requested packages in image name & specVincent Ambo1-3/+13
Before this change, Nixery would pass on the image name unmodified to Nix which would lead it to cache-bust the manifest and configuration layers for images that are content-identical but have different package ordering. This fixes #38.
2019-08-16 feat(server): add iana-etc and cacert to the shell convenience packageFlorian Klink1-1/+1
These probably should be part of every container image by default, but adding it to the "shell" convenience name probably is our best bet for now.
2019-08-14 feat(builder): Implement build cache for manifests & layersVincent Ambo2-41/+148
Implements a cache that keeps track of: a) Manifests that have already been built (for up to 6 hours) b) Layers that have already been seen (and uploaded to GCS) This significantly speeds up response times for images that are full or partial matches with previous images served by an instance.
2019-08-14 refactor(server): Extract build logic into separate moduleVincent Ambo1-0/+208
This module is going to get more complex as the implementation of #32 progresses.