Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
16 commits
Select commit Hold shift + click to select a range
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
137 changes: 133 additions & 4 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
@@ -1,10 +1,10 @@
name: CI

# Trigger model:
# pull_request → lints + release builds + e2e
# push to master → lints + release builds
# workflow_dispatch (release) → push artifacts (TODO)
# pull_request → checks + image builds; publish previews for trusted branches
# push to master / workflow_dispatch → checks + commit-tagged images
on:
workflow_dispatch:
pull_request:
push:
branches: [master]
Expand Down Expand Up @@ -86,7 +86,34 @@ jobs:
- if: runner.environment == 'github-hosted'
uses: NixOS/nix-installer-action@62c1943b776c509394b550f3f983adc14e9212d6
- name: nix build .#${{ matrix.attr }}
run: nix build --accept-flake-config --print-build-logs --no-link '.#packages.x86_64-linux.${{ matrix.attr }}'
id: build
run: |
output=$(nix build --accept-flake-config --print-build-logs --no-link --print-out-paths '.#packages.x86_64-linux.${{ matrix.attr }}')
echo "output=$output" >> "$GITHUB_OUTPUT"
- name: Package portable binaries and WASM
if: startsWith(matrix.name, 'static-') || matrix.name == 'hellas-rpc-wasm'
env:
BUILD_NAME: ${{ matrix.name }}
BUILD_OUTPUT: ${{ steps.build.outputs.output }}
run: |
set -euo pipefail
if [ "$BUILD_NAME" = hellas-rpc-wasm ]; then
test -s "$BUILD_OUTPUT/lib/libhellas_rpc.rlib"
else
test -x "$BUILD_OUTPUT/bin/hellas-cli"
fi
mkdir artifacts
tar --dereference -C "$BUILD_OUTPUT" -czf "artifacts/hellas-$BUILD_NAME-$GITHUB_SHA.tar.gz" .
cd artifacts
sha256sum ./*.tar.gz > SHA256SUMS
- uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4
if: startsWith(matrix.name, 'static-') || matrix.name == 'hellas-rpc-wasm'
with:
name: hellas-${{ matrix.name }}
path: artifacts/
if-no-files-found: error
compression-level: 0
retention-days: 14

build-smoke-passed:
if: always()
Expand Down Expand Up @@ -160,3 +187,105 @@ jobs:
echo '::error::E2E validation did not complete: matrix=${{ needs.e2e-matrix.result }}, tests=${{ needs.e2e.result }}. Inspect the first failed prerequisite, including Lints and Build smoke passed.'
exit 1
fi

# Build archives with read-only permissions. No registry login, Docker daemon,
# or provider credential is needed. Forks exercise the network variants only.
images:
needs: lints
runs-on: ${{ github.event_name == 'pull_request' && github.event.pull_request.head.repo.fork && 'ubuntu-latest' || 'shared' }}
timeout-minutes: 120
strategy:
fail-fast: false
matrix:
backend: ${{ fromJSON(github.event_name == 'pull_request' && github.event.pull_request.head.repo.fork && '["network"]' || '["network","cuda","hip"]') }}
steps:
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
with:
persist-credentials: false
- if: runner.environment == 'github-hosted'
uses: NixOS/nix-installer-action@62c1943b776c509394b550f3f983adc14e9212d6
- name: Build ordinary and managed images
env:
BACKEND: ${{ matrix.backend }}
run: |
set -euo pipefail
mkdir images
for variant in node cloud; do
attr=docker
flavor="$BACKEND"
if [ "$variant" = cloud ]; then
attr=docker-cloud
flavor="cloud-$BACKEND"
fi
if [ "$BACKEND" != network ]; then
attr="$attr-$BACKEND"
fi
stream=$(nix build --accept-flake-config --print-build-logs --no-link --print-out-paths ".#packages.x86_64-linux.$attr")
"$stream" | gzip -1 > "images/$flavor.tar.gz"
done
cd images
sha256sum ./*.tar.gz > SHA256SUMS
- uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4
with:
name: images-${{ matrix.backend }}
path: images/
if-no-files-found: error
compression-level: 0
retention-days: 3

# Publishing consumes image archives only, on a fresh hosted runner. The job
# never checks out or executes PR scripts with the package-write token.
publish-images:
needs: [images, build-smoke-passed, e2e-passed]
if: >-
always() &&
needs.images.result == 'success' &&
needs.build-smoke-passed.result == 'success' &&
(github.event_name != 'pull_request' || needs.e2e-passed.result == 'success') &&
(github.event_name != 'pull_request' ||
(github.event.pull_request.head.repo.full_name == github.repository && github.actor != 'dependabot[bot]'))
runs-on: ubuntu-latest
timeout-minutes: 30
permissions:
contents: read
packages: write
strategy:
fail-fast: false
matrix:
backend: [network, cuda, hip]
steps:
- uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4
with:
name: images-${{ matrix.backend }}
path: images
- name: Verify and load archives
working-directory: images
run: |
set -euo pipefail
sha256sum --check SHA256SUMS
for archive in ./*.tar.gz; do
docker load --input "$archive"
done
- name: Publish commit-tagged images
env:
GH_TOKEN: ${{ github.token }}
BACKEND: ${{ matrix.backend }}
PR_NUMBER: ${{ github.event.pull_request.number }}
run: |
set -euo pipefail
repository="ghcr.io/${GITHUB_REPOSITORY,,}"
config_dir=$(mktemp -d)
export DOCKER_CONFIG="$config_dir"
trap 'rm -rf "$config_dir"' EXIT
printf '%s' "$GH_TOKEN" | docker login ghcr.io --username "$GITHUB_ACTOR" --password-stdin
prefix="sha-$GITHUB_SHA"
if [ -n "$PR_NUMBER" ]; then prefix="pr-$PR_NUMBER-$GITHUB_SHA"; fi
for flavor in "$BACKEND" "cloud-$BACKEND"; do
source="ghcr.io/hellas-ai/hellas:$flavor"
target="$repository:$prefix-$flavor"
docker tag "$source" "$target"
docker push "$target"
digest=$(docker image inspect --format '{{index .RepoDigests 0}}' "$target")
[[ "$digest" == "$repository@sha256:"* ]]
printf '%s: %s\n\nPull by digest: %s\n\n' "$flavor" "$target" "$digest" >> "$GITHUB_STEP_SUMMARY"
done
23 changes: 23 additions & 0 deletions Cargo.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

2 changes: 2 additions & 0 deletions Cargo.toml
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,7 @@ members = [
"crates/chain",
"crates/cli",
"crates/client",
"crates/cloud",
"crates/executor",
"crates/gateway",
"crates/genesis",
Expand Down Expand Up @@ -59,6 +60,7 @@ hellas-adaptors = { path = "crates/adaptors", default-features = false }
hellas-attestation = { path = "crates/attestation", default-features = false }
hellas-chain = { path = "crates/chain", default-features = false }
hellas-client = { path = "crates/client", default-features = false }
hellas-cloud = { path = "crates/cloud", default-features = false }
hellas-executor = { path = "crates/executor", default-features = false }
hellas-gateway = { path = "crates/gateway", default-features = false }
hellas-genesis = { path = "crates/genesis", default-features = false }
Expand Down
4 changes: 4 additions & 0 deletions crates/cli/Cargo.toml
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,9 @@ documentation.workspace = true
[features]
default = []

# Remote machine management; credentials stay with the operator identity.
cloud = ["dep:hellas-cloud"]

# Enables Apple App Attest verification for clients. Native enrollment and
# proof production belong to the signed host application (Gate), not the CLI.
apple-app-attest = []
Expand Down Expand Up @@ -93,6 +96,7 @@ hellas-adaptors.workspace = true
hellas-attestation = { workspace = true, features = ["apple-app-attest"] }
hellas-chain = { workspace = true, default-features = false, optional = true }
hellas-client = { workspace = true, features = ["iroh"] }
hellas-cloud = { workspace = true, optional = true }
hellas-executor = { workspace = true, default-features = false, optional = true }
hellas-gateway = { workspace = true, optional = true }
hellas-kernel = { workspace = true, default-features = false, optional = true }
Expand Down
44 changes: 44 additions & 0 deletions crates/cli/src/cloud.rs
Original file line number Diff line number Diff line change
@@ -0,0 +1,44 @@
//! Thin adapter between the main CLI identity and the machine management library.
use super::{Commands, identity};
use anyhow::{Context, Result};
use hellas_cloud::management::Service;
use std::path::Path;

pub(super) async fn run(command: Commands, identity_path: Option<&Path>) -> Result<()> {
let needs_identity = match &command {
Commands::Cloud(args) => args.needs_identity() || identity_path.is_some(),
_ => true,
};
let service = if needs_identity {
Some(Service::open(
identity::load_existing(identity_path)?.transport_key,
)?)
} else {
None
};
match command {
Commands::Cloud(args) => args.run_owned(service.as_ref()).await,
Commands::Machines(args) => args.run(service.context("owner identity required")?).await,
Commands::Control(args) => args.run(service.context("owner identity required")?).await,
_ => unreachable!("only management commands reach this adapter"),
}
}

pub(super) async fn machine_route(
machine: Option<&str>,
key: &iroh::SecretKey,
node_id: Option<iroh::EndpointId>,
mut trust: super::RemoteTrustArgs,
) -> Result<(Option<iroh::EndpointId>, super::RemoteTrustArgs)> {
let Some(machine) = machine else {
return Ok((node_id, trust));
};
anyhow::ensure!(
trust.assurance == hellas_rpc::Assurance::ProducerSigned,
"owned machine currently supports producer-signed assurance only"
);
let enrollment = Service::open(key.clone())?.resolve(machine).await?;
trust.provider_genesis =
Some(super::parse_content_id_hex(&enrollment.enrollment_id).map_err(anyhow::Error::msg)?);
Ok((Some(enrollment.node_id.parse()?), trust))
}
Loading
Loading