supabase-postgres.git / summary / log / commit / refs

commit    d488045c4ff8850a7bc558cf0730fcd47e24e02a
Author:   Div Arora <darora@users.noreply.github.com>
Commit:   GitHub <noreply@github.com>
Date:     Tue May 05 04:10:55 2026 +0000

    feat: x86 support GENCOMP-44 (#2128)
    
    * feat: ability to build x86 AMI
    
    * fix: action linting
    
    * fix: correct release name and checksum
    
    * fix: postgrest
    
    * fix: kong handling
    
    * fix: admin agent fix
    
    * fix: boot for both targets
    
    * fix: supascan off for x86 for now
    
    * fix: retry on handshake failure
    
    * fix: arch handling postgrest
    
    * tests: new suffix
    
    * fix: envoy architecture handling
    
    * tests: cache bust to test x86 vm test run in ci
    
    * chore: change arch-aware naming scheme for upgrade bundles
    
    The updated scheme makes other parts of our overall architecture
    simpler.
    
    * fix: single ami build
    
    * feat: make stage1 AMI build idempotent
    
    The stage2 AMI build process is somewhat flaky, and retrying the job
    if it fails results in an error as the stage1 AMI has already been
    built. This change attempts to re-use the stage1 AMI if it can be
    found. Further changes will be required to reduce the flakiness on the
    stage2 build.
    
    * fix: remove unnecessary apt update
    
    * perf: attempt to make builds faster
    
    * feat: retry get_url calls on failures
    
    Builds frequently fail on 502 flakes on some requests. This change
    retries them a few times to paper over these issues.
    
    * fix: attempt to reduce variance in build times
    
    * fix: update x86 build disks as well
    
    * fix: remove -x86 from ami naming scheme for historical consistency
    
    * chore: increase timeout
    
    * chore: clean up versions
    
    * chore: upgrade admin-api to build with x86 nano param generation support
    
    * chore: rc image release
    
    * chore: continue other builds even if one fails
    
    This prevents flakes from causing the entire matrix to fail. The rate
    of flakes is elevated right now due to Ubuntu servers being under a
    DDoS attack.
    
    * fix: temporarily disable ppa
    
    * feat: support x86 mirror fallbacks
    
    * fix: create dir before writing file
    
    .
    
    * chore: temporarily disable arm builds
    
    For simpler testing on x86
    
    * chore: re-enable arm builds
    
    * ci: increase task parallelism
    
    * chore: clean up changes
    
    * fix: add arch to the ami name
    
    ---------
    
    Co-authored-by: Sam Rose <samuel@supabase.io>


.github/actions/build-ami/action.yml | 11 +- .github/workflows/ami-release-nix-single.yml | 51 ++++- .github/workflows/ami-release-nix.yml | 81 +++++-- .github/workflows/nix-build.yml | 12 +- amazon-amd64-nix.pkr.hcl | 275 ++++++++++++++++++++++++ amazon-arm64-nix.pkr.hcl | 28 +-- ansible/manifest-playbook.yml | 63 ++++-- ansible/playbook.yml | 2 +- ansible/tasks/internal/admin-api.yml | 4 +- ansible/tasks/internal/admin-mgr.yml | 4 + ansible/tasks/internal/install-salt.yml | 8 + ansible/tasks/internal/postgres-exporter.yml | 4 + ansible/tasks/internal/setup-ansible-pull.yml | 3 +- ansible/tasks/internal/supabase-admin-agent.yml | 8 +- ansible/tasks/internal/supautils.yml | 4 + ansible/tasks/setup-envoy.yml | 12 +- ansible/tasks/setup-gotrue.yml | 6 +- ansible/tasks/setup-kong.yml | 8 +- ansible/tasks/setup-nginx.yml | 4 + ansible/tasks/setup-pgbouncer.yml | 4 + ansible/tasks/setup-postgrest.yml | 12 +- ansible/tasks/setup-supabase-internal.yml | 6 +- ansible/vars.yml | 21 +- development-x86.vars.pkr.hcl | 5 + ebssurrogate/scripts/chroot-bootstrap-nix.sh | 51 +++-- ebssurrogate/scripts/qemu-bootstrap-nix.sh | 9 +- ebssurrogate/scripts/surrogate-bootstrap-nix.sh | 84 +++++--- nix/packages/build-ami.nix | 3 +- scripts/90-cleanup-qemu.sh | 2 +- scripts/90-cleanup.sh | 2 +- scripts/nix-provision.sh | 8 +- stage2-nix-psql.pkr.hcl | 7 +- 32 files changed, 661 insertions(+), 141 deletions(-) diff --git a/.github/actions/build-ami/action.yml b/.github/actions/build-ami/action.yml index b733cbd2..c10bc406 100644 --- a/.github/actions/build-ami/action.yml +++ b/.github/actions/build-ami/action.yml @@ -18,6 +18,14 @@ inputs: description: 'Prefix for the AMI name' required: false default: 'supabase-postgres' + packer_template: + description: 'Packer template for stage 1 (e.g., amazon-arm64-nix.pkr.hcl)' + required: false + default: 'amazon-arm64-nix.pkr.hcl' + instance_type: + description: 'EC2 instance type for the build' + required: false + default: 'c6g.4xlarge' outputs: stage2_ami_id: @@ -65,7 +73,7 @@ runs: -var "packer-execution-id=${{ env.EXECUTION_ID }}" \ -var "ansible_arguments=-e postgresql_major=${{ inputs.postgres_version }}" \ -var 'ami_regions=${{ inputs.ami_regions }}' \ - amazon-arm64-nix.pkr.hcl + ${{ inputs.packer_template }} - name: Build AMI stage 2 id: build-stage2 @@ -84,4 +92,5 @@ runs: -var "postgres_major_version=${{ inputs.postgres_version }}" \ -var "ami_name=${{ inputs.ami_name_prefix }}" \ -var "git_sha=${{ inputs.git_sha }}" \ + -var "instance_type=${{ inputs.instance_type }}" \ stage2-nix-psql.pkr.hcl diff --git a/.github/workflows/ami-release-nix-single.yml b/.github/workflows/ami-release-nix-single.yml index ff23bddd..e5ef7399 100644 --- a/.github/workflows/ami-release-nix-single.yml +++ b/.github/workflows/ami-release-nix-single.yml @@ -12,6 +12,14 @@ on: required: true type: string default: 'main' + arch: + description: 'Architecture to build' + required: true + type: choice + options: + - arm64 + - amd64 + default: arm64 permissions: contents: write @@ -19,7 +27,7 @@ permissions: jobs: build: - runs-on: large-linux-arm + runs-on: ${{ github.event.inputs.arch == 'amd64' && 'blacksmith-2vcpu-ubuntu-2404' || 'large-linux-arm' }} timeout-minutes: 150 steps: @@ -41,6 +49,26 @@ jobs: run: | echo "sha=$(git rev-parse HEAD)" >> "$GITHUB_OUTPUT" + - name: Set arch-specific variables + id: arch_vars + run: | + ARCH="${{ github.event.inputs.arch }}" + if [ "$ARCH" = "amd64" ]; then + { + echo "packer_template=amazon-amd64-nix.pkr.hcl" + echo "instance_type=c6i.4xlarge" + echo "ami_name_prefix=supabase-postgres-x86" + echo "arch_suffix=-x86" + } >> "$GITHUB_OUTPUT" + else + { + echo "packer_template=amazon-arm64-nix.pkr.hcl" + echo "instance_type=c6g.4xlarge" + echo "ami_name_prefix=supabase-postgres" + echo "arch_suffix=" + } >> "$GITHUB_OUTPUT" + fi + - name: Install nix uses: ./.github/actions/nix-install-ephemeral with: @@ -57,6 +85,9 @@ jobs: region: us-east-1 ami_regions: '["us-east-1"]' git_sha: ${{ steps.get_sha.outputs.sha }} + packer_template: ${{ steps.arch_vars.outputs.packer_template }} + instance_type: ${{ steps.arch_vars.outputs.instance_type }} + ami_name_prefix: ${{ steps.arch_vars.outputs.ami_name_prefix }} - name: Grab release version id: process_release_version @@ -86,13 +117,14 @@ jobs: -e "ami_release_version=${{ steps.process_release_version.outputs.version }}" \ -e "internal_artifacts_bucket=${{ secrets.ARTIFACTS_BUCKET }}" \ -e "postgres_major_version=${{ github.event.inputs.postgres_version }}" \ + -e "arch=${{ github.event.inputs.arch }}" \ manifest-playbook.yml - name: Upload nix flake revision to s3 staging run: | - aws s3 cp /tmp/pg_binaries.tar.gz s3://${{ secrets.ARTIFACTS_BUCKET }}/upgrades/postgres/supabase-postgres-${{ steps.process_release_version.outputs.version }}/20.04.tar.gz - aws s3 cp /tmp/pg_binaries.tar.gz s3://${{ secrets.ARTIFACTS_BUCKET }}/upgrades/postgres/supabase-postgres-${{ steps.process_release_version.outputs.version }}/24.04.tar.gz - aws s3 cp /tmp/pg_binaries.tar.gz s3://${{ secrets.ARTIFACTS_BUCKET }}/upgrades/postgres/supabase-postgres-${{ steps.process_release_version.outputs.version }}/upgrade_bundle.tar.gz + aws s3 cp /tmp/pg_binaries.tar.gz s3://${{ secrets.ARTIFACTS_BUCKET }}/upgrades/postgres/supabase-postgres-${{ steps.process_release_version.outputs.version }}${{ steps.arch_vars.outputs.arch_suffix }}/20.04.tar.gz + aws s3 cp /tmp/pg_binaries.tar.gz s3://${{ secrets.ARTIFACTS_BUCKET }}/upgrades/postgres/supabase-postgres-${{ steps.process_release_version.outputs.version }}${{ steps.arch_vars.outputs.arch_suffix }}/24.04.tar.gz + aws s3 cp /tmp/pg_binaries.tar.gz s3://${{ secrets.ARTIFACTS_BUCKET }}/upgrades/postgres/supabase-postgres-${{ steps.process_release_version.outputs.version }}${{ steps.arch_vars.outputs.arch_suffix }}/upgrade_bundle.tar.gz - name: configure aws credentials - prod uses: aws-actions/configure-aws-credentials@7474bc4690e29a8392af63c5b98e7449536d5c3a # v4.3.1 @@ -107,19 +139,20 @@ jobs: -e "ami_release_version=${{ steps.process_release_version.outputs.version }}" \ -e "internal_artifacts_bucket=${{ secrets.PROD_ARTIFACTS_BUCKET }}" \ -e "postgres_major_version=${{ github.event.inputs.postgres_version }}" \ + -e "arch=${{ github.event.inputs.arch }}" \ manifest-playbook.yml - name: Upload nix flake revision to s3 prod run: | - aws s3 cp /tmp/pg_binaries.tar.gz s3://${{ secrets.PROD_ARTIFACTS_BUCKET }}/upgrades/postgres/supabase-postgres-${{ steps.process_release_version.outputs.version }}/20.04.tar.gz - aws s3 cp /tmp/pg_binaries.tar.gz s3://${{ secrets.PROD_ARTIFACTS_BUCKET }}/upgrades/postgres/supabase-postgres-${{ steps.process_release_version.outputs.version }}/24.04.tar.gz - aws s3 cp /tmp/pg_binaries.tar.gz s3://${{ secrets.PROD_ARTIFACTS_BUCKET }}/upgrades/postgres/supabase-postgres-${{ steps.process_release_version.outputs.version }}/upgrade_bundle.tar.gz + aws s3 cp /tmp/pg_binaries.tar.gz s3://${{ secrets.PROD_ARTIFACTS_BUCKET }}/upgrades${{ steps.arch_vars.outputs.arch_suffix }}/postgres/supabase-postgres-${{ steps.process_release_version.outputs.version }}/20.04.tar.gz + aws s3 cp /tmp/pg_binaries.tar.gz s3://${{ secrets.PROD_ARTIFACTS_BUCKET }}/upgrades${{ steps.arch_vars.outputs.arch_suffix }}/postgres/supabase-postgres-${{ steps.process_release_version.outputs.version }}/24.04.tar.gz + aws s3 cp /tmp/pg_binaries.tar.gz s3://${{ secrets.PROD_ARTIFACTS_BUCKET }}/upgrades${{ steps.arch_vars.outputs.arch_suffix }}/postgres/supabase-postgres-${{ steps.process_release_version.outputs.version }}/upgrade_bundle.tar.gz - name: Create release uses: softprops/action-gh-release@a06a81a03ee405af7f2048a818ed3f03bbf83c7b # v2.5.0 with: - name: ${{ steps.process_release_version.outputs.version }} - tag_name: ${{ steps.process_release_version.outputs.version }} + name: ${{ steps.process_release_version.outputs.version }}${{ steps.arch_vars.outputs.arch_suffix }} + tag_name: ${{ steps.process_release_version.outputs.version }}${{ steps.arch_vars.outputs.arch_suffix }} target_commitish: ${{ steps.get_sha.outputs.sha }} - name: Slack Notification on Failure diff --git a/.github/workflows/ami-release-nix.yml b/.github/workflows/ami-release-nix.yml index 778e24eb..aa6a05c3 100644 --- a/.github/workflows/ami-release-nix.yml +++ b/.github/workflows/ami-release-nix.yml @@ -37,11 +37,25 @@ jobs: build: needs: prepare strategy: + fail-fast: false matrix: postgres_version: ${{ fromJson(needs.prepare.outputs.postgres_versions) }} - include: - - runner: blacksmith-2vcpu-ubuntu-2404-arm - runs-on: ${{ matrix.runner }} + arch: + - name: arm64 + runner: blacksmith-2vcpu-ubuntu-2404-arm + packer_template: amazon-arm64-nix.pkr.hcl + vars_file: development-arm.vars.pkr.hcl + instance_type: c6g.4xlarge + nix_system: aarch64-linux + ami_arch_filter: arm64 + - name: amd64 + runner: blacksmith-2vcpu-ubuntu-2404 + packer_template: amazon-amd64-nix.pkr.hcl + vars_file: development-x86.vars.pkr.hcl + instance_type: c6i.4xlarge + nix_system: x86_64-linux + ami_arch_filter: x86_64 + runs-on: ${{ matrix.arch.runner }} timeout-minutes: 150 steps: @@ -67,7 +81,7 @@ jobs: - name: Set PostgreSQL version environment variable run: | echo "POSTGRES_MAJOR_VERSION=${{ matrix.postgres_version }}" >> "$GITHUB_ENV" - echo "EXECUTION_ID=${{ github.run_id }}-${{ matrix.postgres_version }}" >> "$GITHUB_ENV" + echo "EXECUTION_ID=${{ github.run_id }}-${{ matrix.postgres_version }}-${{ matrix.arch.name }}" >> "$GITHUB_ENV" - name: Generate common-nix.vars.pkr.hcl run: | @@ -79,13 +93,14 @@ jobs: POSTGRES_MAJOR_VERSION: ${{ env.POSTGRES_MAJOR_VERSION }} run: | GIT_SHA=${{github.sha}} - nix run github:supabase/postgres/${GIT_SHA}#packer -- init amazon-arm64-nix.pkr.hcl - # why is postgresql_major defined here instead of where the _three_ other postgresql_* variables are defined? - nix run github:supabase/postgres/${GIT_SHA}#packer -- build -var "git-head-version=${GIT_SHA}" -var "packer-execution-id=${EXECUTION_ID}" -var-file="development-arm.vars.pkr.hcl" -var-file="common-nix.vars.pkr.hcl" -var "ansible_arguments=-e postgresql_major=${POSTGRES_MAJOR_VERSION}" -var "region=us-east-1" -var 'ami_regions=["us-east-1"]' amazon-arm64-nix.pkr.hcl + + nix run github:supabase/postgres/${GIT_SHA}#packer -- init ${{ matrix.arch.packer_template }} + nix run github:supabase/postgres/${GIT_SHA}#packer -- build -var "git-head-version=${GIT_SHA}" -var "packer-execution-id=${EXECUTION_ID}" -var-file="${{ matrix.arch.vars_file }}" -var-file="common-nix.vars.pkr.hcl" -var "ansible_arguments=-e postgresql_major=${POSTGRES_MAJOR_VERSION}" -var "region=us-east-1" -var 'ami_regions=["us-east-1"]' -var "ami_name=supabase-postgres-${{ matrix.arch.ami_arch_filter }}" ${{ matrix.arch.packer_template }} - name: Find stage 1 AMI run: | GIT_SHA=${{github.sha}} + PG_VERSION=$(sed -n 's/postgres-version = "\(.*\)"/\1/p' common-nix.vars.pkr.hcl) REGION="us-east-1" @@ -98,6 +113,7 @@ jobs: "Name=tag:postgresVersion,Values=${PG_VERSION}-stage1" \ "Name=tag:sourceSha,Values=${GIT_SHA}" \ "Name=state,Values=available" \ + "Name=architecture,Values=${{ matrix.arch.ami_arch_filter }}" \ --query 'Images[0].ImageId' \ --output text) @@ -115,8 +131,7 @@ jobs: run: | GIT_SHA=${{github.sha}} nix run github:supabase/postgres/${GIT_SHA}#packer -- init stage2-nix-psql.pkr.hcl - POSTGRES_MAJOR_VERSION=${{ env.POSTGRES_MAJOR_VERSION }} - nix run github:supabase/postgres/${GIT_SHA}#packer -- build -var "git_sha=${GIT_SHA}" -var "git-head-version=${GIT_SHA}" -var "packer-execution-id=${EXECUTION_ID}" -var "postgres_major_version=${POSTGRES_MAJOR_VERSION}" -var "source_ami=${STAGE1_AMI_ID}" -var-file="development-arm.vars.pkr.hcl" -var-file="common-nix.vars.pkr.hcl" -var "region=us-east-1" stage2-nix-psql.pkr.hcl + nix run github:supabase/postgres/${GIT_SHA}#packer -- build -var "git_sha=${GIT_SHA}" -var "git-head-version=${GIT_SHA}" -var "packer-execution-id=${EXECUTION_ID}" -var "postgres_major_version=${POSTGRES_MAJOR_VERSION}" -var "source_ami=${STAGE1_AMI_ID}" -var-file="${{ matrix.arch.vars_file }}" -var-file="common-nix.vars.pkr.hcl" -var "region=us-east-1" -var "instance_type=${{ matrix.arch.instance_type }}" -var "ami_name=supabase-postgres-${{ matrix.arch.ami_arch_filter }}" stage2-nix-psql.pkr.hcl - name: Grab release version id: process_release_version @@ -125,6 +140,24 @@ jobs: echo "version=$VERSION" >> "$GITHUB_OUTPUT" echo "::notice title=AMI Published::Postgres AMI version: $VERSION" + - name: Set arch-qualified version + id: arch_version + run: | + VERSION="${{ steps.process_release_version.outputs.version }}" + if [ "${{ matrix.arch.name }}" = "amd64" ]; then + { + echo "version=${VERSION}" + echo "arch_suffix=-x86" + echo "release_tag=${VERSION}-x86" + } >> "$GITHUB_OUTPUT" + else + { + echo "version=${VERSION}" + echo "arch_suffix=" + echo "release_tag=${VERSION}" + } >> "$GITHUB_OUTPUT" + fi + - name: Create nix flake revision tarball run: | GIT_SHA=${{github.sha}} @@ -144,16 +177,17 @@ jobs: run: | cd ansible ansible-playbook -i localhost \ - -e "ami_release_version=${{ steps.process_release_version.outputs.version }}" \ + -e "ami_release_version=${{ steps.arch_version.outputs.version }}" \ -e "internal_artifacts_bucket=${{ secrets.ARTIFACTS_BUCKET }}" \ -e "postgres_major_version=${{ matrix.postgres_version }}" \ + -e "arch=${{ matrix.arch.name }}" \ manifest-playbook.yml - name: Upload nix flake revision to s3 staging run: | - aws s3 cp /tmp/pg_binaries.tar.gz s3://${{ secrets.ARTIFACTS_BUCKET }}/upgrades/postgres/supabase-postgres-${{ steps.process_release_version.outputs.version }}/20.04.tar.gz - aws s3 cp /tmp/pg_binaries.tar.gz s3://${{ secrets.ARTIFACTS_BUCKET }}/upgrades/postgres/supabase-postgres-${{ steps.process_release_version.outputs.version }}/24.04.tar.gz - aws s3 cp /tmp/pg_binaries.tar.gz s3://${{ secrets.ARTIFACTS_BUCKET }}/upgrades/postgres/supabase-postgres-${{ steps.process_release_version.outputs.version }}/upgrade_bundle.tar.gz + aws s3 cp /tmp/pg_binaries.tar.gz s3://${{ secrets.ARTIFACTS_BUCKET }}/upgrades${{ steps.arch_version.outputs.arch_suffix }}/postgres/supabase-postgres-${{ steps.arch_version.outputs.version }}/20.04.tar.gz + aws s3 cp /tmp/pg_binaries.tar.gz s3://${{ secrets.ARTIFACTS_BUCKET }}/upgrades${{ steps.arch_version.outputs.arch_suffix }}/postgres/supabase-postgres-${{ steps.arch_version.outputs.version }}/24.04.tar.gz + aws s3 cp /tmp/pg_binaries.tar.gz s3://${{ secrets.ARTIFACTS_BUCKET }}/upgrades${{ steps.arch_version.outputs.arch_suffix }}/postgres/supabase-postgres-${{ steps.arch_version.outputs.version }}/upgrade_bundle.tar.gz - name: configure aws credentials - prod uses: aws-actions/configure-aws-credentials@7474bc4690e29a8392af63c5b98e7449536d5c3a # v4.3.1 @@ -165,16 +199,17 @@ jobs: run: | cd ansible ansible-playbook -i localhost \ - -e "ami_release_version=${{ steps.process_release_version.outputs.version }}" \ + -e "ami_release_version=${{ steps.arch_version.outputs.version }}" \ -e "internal_artifacts_bucket=${{ secrets.PROD_ARTIFACTS_BUCKET }}" \ -e "postgres_major_version=${{ matrix.postgres_version }}" \ + -e "arch=${{ matrix.arch.name }}" \ manifest-playbook.yml - name: Upload nix flake revision to s3 prod run: | - aws s3 cp /tmp/pg_binaries.tar.gz s3://${{ secrets.PROD_ARTIFACTS_BUCKET }}/upgrades/postgres/supabase-postgres-${{ steps.process_release_version.outputs.version }}/20.04.tar.gz - aws s3 cp /tmp/pg_binaries.tar.gz s3://${{ secrets.PROD_ARTIFACTS_BUCKET }}/upgrades/postgres/supabase-postgres-${{ steps.process_release_version.outputs.version }}/24.04.tar.gz - aws s3 cp /tmp/pg_binaries.tar.gz s3://${{ secrets.PROD_ARTIFACTS_BUCKET }}/upgrades/postgres/supabase-postgres-${{ steps.process_release_version.outputs.version }}/upgrade_bundle.tar.gz + aws s3 cp /tmp/pg_binaries.tar.gz s3://${{ secrets.PROD_ARTIFACTS_BUCKET }}/upgrades${{ steps.arch_version.outputs.arch_suffix }}/postgres/supabase-postgres-${{ steps.arch_version.outputs.version }}/20.04.tar.gz + aws s3 cp /tmp/pg_binaries.tar.gz s3://${{ secrets.PROD_ARTIFACTS_BUCKET }}/upgrades${{ steps.arch_version.outputs.arch_suffix }}/postgres/supabase-postgres-${{ steps.arch_version.outputs.version }}/24.04.tar.gz + aws s3 cp /tmp/pg_binaries.tar.gz s3://${{ secrets.PROD_ARTIFACTS_BUCKET }}/upgrades${{ steps.arch_version.outputs.arch_suffix }}/postgres/supabase-postgres-${{ steps.arch_version.outputs.version }}/upgrade_bundle.tar.gz - name: GitHub OIDC Auth uses: aws-actions/configure-aws-credentials@ececac1a45f3b08a01d2dd070d28d111c5fe6722 # v4.1.0 @@ -197,13 +232,13 @@ jobs: VERSION="${{ steps.process_release_version.outputs.version }}" GIT_SHA="${{ github.sha }}" PG_VERSION="${{ matrix.postgres_version }}" - SYSTEM="aarch64-linux" + SYSTEM="${{ matrix.arch.nix_system }}" # Get store path for this build STORE_PATH=$(nix eval --raw ".#psql_${PG_VERSION}/bin.outPath") # Each postgres version gets its own catalog file (no race conditions) - CATALOG_S3="s3://${{ secrets.SHARED_AWS_ARTIFACTS_BUCKET }}/nix-catalog/${GIT_SHA}-psql_${PG_VERSION}.json" + CATALOG_S3="s3://${{ secrets.SHARED_AWS_ARTIFACTS_BUCKET }}/nix-catalog/${GIT_SHA}-psql_${PG_VERSION}-${SYSTEM}.json" # Create catalog JSON for this version jq -n \ @@ -225,12 +260,12 @@ jobs: - name: Create release uses: softprops/action-gh-release@a06a81a03ee405af7f2048a818ed3f03bbf83c7b # v2.5.0 with: - name: ${{ steps.process_release_version.outputs.version }} - tag_name: ${{ steps.process_release_version.outputs.version }} + name: ${{ steps.arch_version.outputs.release_tag }} + tag_name: ${{ steps.arch_version.outputs.release_tag }} target_commitish: ${{github.sha}} - name: Create CLI tag for PG 17 - if: matrix.postgres_version == '17' && github.event_name != 'workflow_dispatch' + if: matrix.postgres_version == '17' && matrix.arch.name == 'arm64' && github.event_name != 'workflow_dispatch' env: GH_TOKEN: ${{ github.token }} run: | @@ -241,6 +276,7 @@ jobs: git push origin "${CLI_TAG}" - name: Trigger pg_upgrade_scripts workflow + if: matrix.arch.name == 'arm64' env: GH_TOKEN: ${{ github.token }} run: | @@ -249,6 +285,7 @@ jobs: -f postgresVersion="${{ steps.process_release_version.outputs.version }}" - name: Trigger pg_upgrade_bin flake version workflow + if: matrix.arch.name == 'arm64' env: GH_TOKEN: ${{ github.token }} run: | diff --git a/.github/workflows/nix-build.yml b/.github/workflows/nix-build.yml index d1f1ea5d..f45e5d1e 100644 --- a/.github/workflows/nix-build.yml +++ b/.github/workflows/nix-build.yml @@ -34,7 +34,7 @@ jobs: if: ${{ fromJSON(needs.nix-eval.outputs.packages_matrix).aarch64_linux != null }} strategy: fail-fast: false - max-parallel: 5 + max-parallel: 25 matrix: ${{ fromJSON(needs.nix-eval.outputs.packages_matrix).aarch64_linux }} steps: - name: Checkout Repo @@ -66,7 +66,7 @@ jobs: if: ${{ fromJSON(needs.nix-eval.outputs.checks_matrix).aarch64_linux != null }} strategy: fail-fast: false - max-parallel: 5 + max-parallel: 25 matrix: ${{ fromJSON(needs.nix-eval.outputs.checks_matrix).aarch64_linux }} steps: - name: Checkout Repo @@ -98,7 +98,7 @@ jobs: if: ${{ fromJSON(needs.nix-eval.outputs.packages_matrix).aarch64_darwin != null }} strategy: fail-fast: false - max-parallel: 5 + max-parallel: 25 matrix: ${{ fromJSON(needs.nix-eval.outputs.packages_matrix).aarch64_darwin }} steps: - name: Checkout Repo @@ -122,7 +122,7 @@ jobs: if: ${{ fromJSON(needs.nix-eval.outputs.checks_matrix).aarch64_darwin != null }} strategy: fail-fast: false - max-parallel: 5 + max-parallel: 25 matrix: ${{ fromJSON(needs.nix-eval.outputs.checks_matrix).aarch64_darwin }} steps: - name: Checkout Repo @@ -146,7 +146,7 @@ jobs: if: ${{ fromJSON(needs.nix-eval.outputs.packages_matrix).x86_64_linux != null }} strategy: fail-fast: false - max-parallel: 5 + max-parallel: 25 matrix: ${{ fromJSON(needs.nix-eval.outputs.packages_matrix).x86_64_linux }} steps: - name: Checkout Repo @@ -175,7 +175,7 @@ jobs: if: ${{ fromJSON(needs.nix-eval.outputs.checks_matrix).x86_64_linux != null }} strategy: fail-fast: false - max-parallel: 5 + max-parallel: 25 matrix: ${{ fromJSON(needs.nix-eval.outputs.checks_matrix).x86_64_linux }} steps: - name: Checkout Repo diff --git a/amazon-amd64-nix.pkr.hcl b/amazon-amd64-nix.pkr.hcl new file mode 100644 index 00000000..9a3476f3 --- /dev/null +++ b/amazon-amd64-nix.pkr.hcl @@ -0,0 +1,275 @@ +variable "ami" { + type = string + default = "ubuntu/images/hvm-ssd-gp3/ubuntu-noble-24.04-amd64-server-*" +} + +variable "profile" { + type = string + default = "${env("AWS_PROFILE")}" +} + +variable "ami_name" { + type = string + default = "supabase-postgres" +} + +variable "ami_regions" { + type = list(string) + default = ["ap-southeast-1"] +} + +variable "ansible_arguments" { + type = string + default = "--skip-tags install-postgrest,install-pgbouncer,install-supabase-internal" +} + +variable "region" { + type = string +} + +variable "build-vol" { + type = string + default = "xvdc" +} + +# ccache docker image details +variable "docker_user" { + type = string + default = "" +} + +variable "docker_passwd" { + type = string + default = "" +} + +variable "docker_image" { + type = string + default = "" +} + +variable "docker_image_tag" { + type = string + default = "latest" +} + +locals { + creator = "packer" +} + +variable "postgres-version" { + type = string + default = "" +} + +variable "git-head-version" { + type = string + default = "unknown" +} + +variable "packer-execution-id" { + type = string + default = "unknown" +} + +variable "force-deregister" { + type = bool + default = false +} + +variable "input-hash" { + type = string + default = "" + description = "Content hash of all input sources" +} + +packer { + required_plugins { + amazon = { + source = "github.com/hashicorp/amazon" + version = "~> 1" + } + } +} + +# source block +source "amazon-ebssurrogate" "source" { + profile = "${var.profile}" + ami_name = "${var.ami_name}-${var.postgres-version}-${var.input-hash}-stage-1" + ami_virtualization_type = "hvm" + ami_architecture = "x86_64" + ami_regions = "${var.ami_regions}" + instance_type = "c6i.4xlarge" + region = "${var.region}" + force_deregister = var.force-deregister + + # Increase timeout for instance stop operations to handle large instances + aws_polling { + delay_seconds = 15 + max_attempts = 120 # 120 * 15s = 30 minutes max wait + } + + # Use latest official ubuntu noble ami owned by Canonical. + source_ami_filter { + filters = { + virtualization-type = "hvm" + name = "${var.ami}" + root-device-type = "ebs" + } + owners = [ "099720109477" ] + most_recent = true + } + + ena_support = true + launch_block_device_mappings { + device_name = "/dev/xvdf" + delete_on_termination = true + volume_size = 20 + volume_type = "gp3" + iops = 10000 + throughput = 1000 + } + + # NOTE: /dev/xvdh is mounted as /data (PostgreSQL data/WAL). The 1 GiB size + # is a minimal default for this AMI; consumers should override this volume + # size at launch. + launch_block_device_mappings { + device_name = "/dev/xvdh" + delete_on_termination = true + volume_size = 1 + volume_type = "gp3" + } + + launch_block_device_mappings { + device_name = "/dev/${var.build-vol}" + delete_on_termination = true + volume_size = 20 + volume_type = "gp3" + omit_from_artifact = true + iops = 10000 # Added for build performance + throughput = 1000 # Added for build performance + } + + run_tags = { + creator = "packer" + appType = "postgres" + packerExecutionId = "${var.packer-execution-id}" + } + run_volume_tags = { + creator = "packer" + appType = "postgres" + } + snapshot_tags = { + creator = "packer" + appType = "postgres" + } + tags = { + creator = "packer" + appType = "postgres" + postgresVersion = "${var.postgres-version}-stage1" + sourceSha = "${var.git-head-version}" + inputHash = "${var.input-hash}" + } + + communicator = "ssh" + ssh_pty = true + ssh_username = "ubuntu" + ssh_timeout = "5m" + + ami_root_device { + source_device_name = "/dev/xvdf" + device_name = "/dev/xvda" + delete_on_termination = true + volume_size = 10 + volume_type = "gp3" + } + + associate_public_ip_address = true +} + +# a build block invokes sources and runs provisioning steps on them. +build { + sources = ["source.amazon-ebssurrogate.source"] + + provisioner "file" { + source = "ebssurrogate/files/sources.cfg" + destination = "/tmp/sources.list" + } + + provisioner "file" { + source = "ebssurrogate/files/ebsnvme-id" + destination = "/tmp/ebsnvme-id" + } + + provisioner "file" { + source = "ebssurrogate/files/70-ec2-nvme-devices.rules" + destination = "/tmp/70-ec2-nvme-devices.rules" + } + + provisioner "file" { + source = "ebssurrogate/scripts/chroot-bootstrap-nix.sh" + destination = "/tmp/chroot-bootstrap-nix.sh" + } + + provisioner "file" { + source = "ebssurrogate/files/cloud.cfg" + destination = "/tmp/cloud.cfg" + } + + provisioner "file" { + source = "ebssurrogate/files/vector.timer" + destination = "/tmp/vector.timer" + } + + provisioner "file" { + source = "ebssurrogate/files/apparmor_profiles" + destination = "/tmp" + } + + provisioner "file" { + source = "migrations" + destination = "/tmp" + } + + # Copy ansible playbook + provisioner "shell" { + inline = ["mkdir /tmp/ansible-playbook"] + } + + provisioner "file" { + source = "ansible" + destination = "/tmp/ansible-playbook" + } + + provisioner "file" { + source = "scripts" + destination = "/tmp/ansible-playbook" + } + + provisioner "file" { + source = "ansible/vars.yml" + destination = "/tmp/ansible-playbook/vars.yml" + } + + provisioner "shell" { + environment_vars = [ + "ARGS=${var.ansible_arguments}", + "DOCKER_USER=${var.docker_user}", + "DOCKER_PASSWD=${var.docker_passwd}", + "DOCKER_IMAGE=${var.docker_image}", + "DOCKER_IMAGE_TAG=${var.docker_image_tag}", + "POSTGRES_SUPABASE_VERSION=${var.postgres-version}" + ] + use_env_var_file = true + script = "ebssurrogate/scripts/surrogate-bootstrap-nix.sh" + execute_command = "sudo -S sh -c '. {{.EnvVarFile}} && cd /tmp/ansible-playbook && {{.Path}}'" + start_retry_timeout = "5m" + skip_clean = true + } + + provisioner "file" { + source = "/tmp/ansible.log" + destination = "/tmp/ansible.log" + direction = "download" + } +} diff --git a/amazon-arm64-nix.pkr.hcl b/amazon-arm64-nix.pkr.hcl index 0ff67996..a0f89974 100644 --- a/amazon-arm64-nix.pkr.hcl +++ b/amazon-arm64-nix.pkr.hcl @@ -122,28 +122,32 @@ source "amazon-ebssurrogate" "source" { ena_support = true launch_block_device_mappings { - device_name = "/dev/xvdf" + device_name = "/dev/xvdf" delete_on_termination = true - volume_size = 10 - volume_type = "gp3" + volume_size = 20 + volume_type = "gp3" + iops = 10000 + throughput = 1000 } # NOTE: /dev/xvdh is mounted as /data (PostgreSQL data/WAL). The 1 GiB size # is a minimal default for this AMI; consumers should override this volume # size at launch. launch_block_device_mappings { - device_name = "/dev/xvdh" + device_name = "/dev/xvdh" delete_on_termination = true - volume_size = 1 - volume_type = "gp3" + volume_size = 1 + volume_type = "gp3" } launch_block_device_mappings { device_name = "/dev/${var.build-vol}" delete_on_termination = true - volume_size = 16 - volume_type = "gp2" + volume_size = 20 + volume_type = "gp3" omit_from_artifact = true + iops = 10000 # Added for build performance + throughput = 1000 # Added for build performance } run_tags = { @@ -173,11 +177,11 @@ source "amazon-ebssurrogate" "source" { ssh_timeout = "5m" ami_root_device { - source_device_name = "/dev/xvdf" - device_name = "/dev/xvda" + source_device_name = "/dev/xvdf" + device_name = "/dev/xvda" delete_on_termination = true - volume_size = 10 - volume_type = "gp2" + volume_size = 10 + volume_type = "gp3" } associate_public_ip_address = true diff --git a/ansible/manifest-playbook.yml b/ansible/manifest-playbook.yml index ce02c805..b0e46722 100644 --- a/ansible/manifest-playbook.yml +++ b/ansible/manifest-playbook.yml @@ -4,36 +4,55 @@ vars_files: - ./vars.yml + vars: + arch: "{{ arch | default('arm64') }}" + postgrest_binary: "{{ 'ubuntu-aarch64' if arch == 'arm64' else 'linux-static-x86-64' }}" + gotrue_arch: "{{ 'arm64' if arch == 'arm64' else 'x86' }}" + gotrue_checksum: "{{ gotrue_arm_release_checksum if arch == 'arm64' else gotrue_x86_release_checksum }}" + postgrest_checksum: "{{ postgrest_arm_release_checksum if arch == 'arm64' else postgrest_x86_release_checksum }}" + tasks: - name: Write out image manifest action: template src=files/manifest.json dest=./image-manifest-{{ ami_release_version }}.json - name: Upload image manifest shell: | - aws s3 cp ./image-manifest-{{ ami_release_version }}.json s3://{{ internal_artifacts_bucket }}/manifests/postgres-{{ ami_release_version }}/software-manifest.json + aws s3 cp ./image-manifest-{{ ami_release_version }}.json s3://{{ internal_artifacts_bucket }}/manifests/postgres-{{ ami_release_version }}/software-manifest-{{ arch }}.json # upload software artifacts of interest # Generally - download, extract, repack as xz archive, upload # currently, we upload gotrue, adminapi, postgrest - name: gotrue - download commit archive get_url: - url: "https://github.com/supabase/gotrue/releases/download/v{{ gotrue_release }}/auth-v{{ gotrue_release }}-arm64.tar.gz" - dest: /tmp/auth-v{{ gotrue_release }}-arm64.tar.gz - checksum: "{{ gotrue_release_checksum }}" + url: "https://github.com/supabase/gotrue/releases/download/v{{ gotrue_release }}/auth-v{{ gotrue_release }}-{{ gotrue_arch }}.tar.gz" + dest: /tmp/auth-v{{ gotrue_release }}-{{ gotrue_arch }}.tar.gz + checksum: "{{ gotrue_checksum }}" timeout: 60 + register: download_result + until: download_result is succeeded + retries: 3 + delay: 2 - name: PostgREST - download ubuntu binary archive (arm) get_url: - url: "https://github.com/PostgREST/postgrest/releases/download/v{{ postgrest_release }}/postgrest-v{{ postgrest_release }}-ubuntu-aarch64.tar.xz" - dest: /tmp/postgrest-{{ postgrest_release }}-arm64.tar.xz - checksum: "{{ postgrest_arm_release_checksum }}" + url: "https://github.com/PostgREST/postgrest/releases/download/v{{ postgrest_release }}/postgrest-v{{ postgrest_release }}-{{ postgrest_binary }}.tar.xz" + dest: /tmp/postgrest-{{ postgrest_release }}-{{ arch }}.tar.xz + checksum: "{{ postgrest_checksum }}" timeout: 60 + register: download_result + until: download_result is succeeded + retries: 3 + delay: 2 - name: Download adminapi archive get_url: - url: "https://supabase-public-artifacts-bucket.s3.amazonaws.com/supabase-admin-api/v{{ adminapi_release }}/supabase-admin-api_{{ adminapi_release }}_linux_arm64.tar.gz" + url: "https://supabase-public-artifacts-bucket.s3.amazonaws.com/supabase-admin-api/v{{ adminapi_release }}/supabase-admin-api_{{ adminapi_release }}_linux_{{ arch }}.tar.gz" dest: "/tmp/adminapi.tar.gz" timeout: 90 + register: download_result + until: download_result is succeeded + retries: 3 + delay: 2 - name: adminapi - unpack archive in /tmp unarchive: @@ -43,13 +62,17 @@ - name: adminapi - pack archive shell: | - cd /tmp && tar -cJf supabase-admin-api-{{ adminapi_release }}-arm64.tar.xz supabase-admin-api + cd /tmp && tar -cJf supabase-admin-api-{{ adminapi_release }}-{{ arch }}.tar.xz supabase-admin-api - name: Download admin-mgr archive get_url: - url: "https://supabase-public-artifacts-bucket.s3.amazonaws.com/admin-mgr/v{{ adminmgr_release }}/admin-mgr_{{ adminmgr_release }}_linux_arm64.tar.gz" + url: "https://supabase-public-artifacts-bucket.s3.amazonaws.com/admin-mgr/v{{ adminmgr_release }}/admin-mgr_{{ adminmgr_release }}_linux_{{ arch }}.tar.gz" dest: "/tmp/admin-mgr.tar.gz" timeout: 90 + register: download_result + until: download_result is succeeded + retries: 3 + delay: 2 - name: admin-mgr - unpack archive in /tmp unarchive: @@ -59,13 +82,17 @@ - name: admin-mgr - pack archive shell: | - cd /tmp && tar -cJf admin-mgr-{{ adminmgr_release }}-arm64.tar.xz admin-mgr + cd /tmp && tar -cJf admin-mgr-{{ adminmgr_release }}-{{ arch }}.tar.xz admin-mgr - name: Download supabase-admin-agent archive get_url: - url: "https://supabase-public-artifacts-bucket.s3.amazonaws.com/supabase-admin-agent/v{{ supabase_admin_agent_release }}/supabase-admin-agent-{{ supabase_admin_agent_release }}-linux-arm64.tar.gz" + url: "https://supabase-public-artifacts-bucket.s3.amazonaws.com/supabase-admin-agent/v{{ supabase_admin_agent_release }}/supabase-admin-agent-{{ supabase_admin_agent_release }}-linux-{{ arch }}.tar.gz" dest: "/tmp/supabase-admin-agent.tar.gz" timeout: 90 + register: download_result + until: download_result is succeeded + retries: 3 + delay: 2 - name: supabase-admin-agent - unpack archive in /tmp unarchive: @@ -75,19 +102,19 @@ - name: supabase-admin-agent - pack archive shell: | - cd /tmp && tar -cJf supabase-admin-agent-{{ supabase_admin_agent_release }}-arm64.tar.xz supabase-admin-agent-{{ supabase_admin_agent_release }}-linux-arm64 + cd /tmp && tar -cJf supabase-admin-agent-{{ supabase_admin_agent_release }}-{{ arch }}.tar.xz supabase-admin-agent-{{ supabase_admin_agent_release }}-linux-{{ arch }} - name: upload archives shell: | aws s3 cp /tmp/{{ item.file }} s3://{{ internal_artifacts_bucket }}/upgrades/{{ item.service }}/{{ item.file }} with_items: - service: gotrue - file: auth-v{{ gotrue_release }}-arm64.tar.gz + file: auth-v{{ gotrue_release }}-{{ gotrue_arch }}.tar.gz - service: postgrest - file: postgrest-{{ postgrest_release }}-arm64.tar.xz + file: postgrest-{{ postgrest_release }}-{{ arch }}.tar.xz - service: supabase-admin-api - file: supabase-admin-api-{{ adminapi_release }}-arm64.tar.xz + file: supabase-admin-api-{{ adminapi_release }}-{{ arch }}.tar.xz - service: admin-mgr - file: admin-mgr-{{ adminmgr_release }}-arm64.tar.xz + file: admin-mgr-{{ adminmgr_release }}-{{ arch }}.tar.xz - service: supabase-admin-agent - file: supabase-admin-agent-{{ supabase_admin_agent_release }}-arm64.tar.xz + file: supabase-admin-agent-{{ supabase_admin_agent_release }}-{{ arch }}.tar.xz diff --git a/ansible/playbook.yml b/ansible/playbook.yml index f2d5b683..73db87d7 100644 --- a/ansible/playbook.yml +++ b/ansible/playbook.yml @@ -236,7 +236,7 @@ become: yes shell: | /bin/bash /tmp/ansible-playbook/ansible/files/supascan_ami.sh /tmp/ansible-playbook/audit-specs/baselines/ami-build - when: stage2_nix and qemu_mode is not defined + when: stage2_nix and qemu_mode is not defined and ansible_architecture != "x86_64" - name: Remove supascan after validation become: yes diff --git a/ansible/tasks/internal/admin-api.yml b/ansible/tasks/internal/admin-api.yml index 1770433e..0c8e4020 100644 --- a/ansible/tasks/internal/admin-api.yml +++ b/ansible/tasks/internal/admin-api.yml @@ -27,9 +27,9 @@ shell: | chmod g+w /etc -- name: Setting arch (x86) +- name: Setting arch (amd64) set_fact: - arch: "x86" + arch: "amd64" when: platform == "amd64" - name: Setting arch (arm) diff --git a/ansible/tasks/internal/admin-mgr.yml b/ansible/tasks/internal/admin-mgr.yml index 073b8661..46a1231c 100644 --- a/ansible/tasks/internal/admin-mgr.yml +++ b/ansible/tasks/internal/admin-mgr.yml @@ -13,6 +13,10 @@ url: "https://supabase-public-artifacts-bucket.s3.amazonaws.com/admin-mgr/v{{ adminmgr_release }}/admin-mgr_{{ adminmgr_release }}_linux_{{ arch }}.tar.gz" dest: "/tmp/admin-mgr.tar.gz" timeout: 90 + register: download_result + until: download_result is succeeded + retries: 3 + delay: 2 - name: admin-mgr - unpack archive in /usr/bin/ unarchive: diff --git a/ansible/tasks/internal/install-salt.yml b/ansible/tasks/internal/install-salt.yml index 73cd6ee8..9ebbd26b 100644 --- a/ansible/tasks/internal/install-salt.yml +++ b/ansible/tasks/internal/install-salt.yml @@ -11,6 +11,10 @@ url: https://packages.broadcom.com/artifactory/api/security/keypair/SaltProjectKey/public dest: /etc/apt/keyrings/salt-archive-keyring-2023.pgp mode: '0644' + register: download_result + until: download_result is succeeded + retries: 3 + delay: 2 - name: salt apt repo ansible.builtin.apt_repository: @@ -32,6 +36,10 @@ url: https://packages.broadcom.com/artifactory/api/security/keypair/SaltProjectKey/public dest: /etc/apt/keyrings/salt-archive-keyring-2023.pgp mode: '0644' + register: download_result + until: download_result is succeeded + retries: 3 + delay: 2 - name: salt apt repo ansible.builtin.apt_repository: diff --git a/ansible/tasks/internal/postgres-exporter.yml b/ansible/tasks/internal/postgres-exporter.yml index 0292157b..29dc896e 100644 --- a/ansible/tasks/internal/postgres-exporter.yml +++ b/ansible/tasks/internal/postgres-exporter.yml @@ -26,6 +26,10 @@ dest: /tmp/postgres_exporter.tar.gz checksum: "{{ postgres_exporter_release_checksum[platform] }}" timeout: 60 + register: download_result + until: download_result is succeeded + retries: 3 + delay: 2 - name: expand postgres exporter unarchive: diff --git a/ansible/tasks/internal/setup-ansible-pull.yml b/ansible/tasks/internal/setup-ansible-pull.yml index 7cce74a8..06559e28 100644 --- a/ansible/tasks/internal/setup-ansible-pull.yml +++ b/ansible/tasks/internal/setup-ansible-pull.yml @@ -2,7 +2,8 @@ shell: cmd: | apt install -y software-properties-common - add-apt-repository --yes --update ppa:ansible/ansible + # TODO (darora): temporarily disabling while Launchpad is under ddos attack and very frequently timing out + # add-apt-repository --yes --update ppa:ansible/ansible apt install -y ansible sed -i -e 's/#callback_whitelist.*/callback_whitelist = profile_tasks/' /etc/ansible/ansible.cfg diff --git a/ansible/tasks/internal/supabase-admin-agent.yml b/ansible/tasks/internal/supabase-admin-agent.yml index 0dfc4427..6ac42d76 100644 --- a/ansible/tasks/internal/supabase-admin-agent.yml +++ b/ansible/tasks/internal/supabase-admin-agent.yml @@ -31,9 +31,9 @@ dest: /etc/sudoers.d/supabase-admin-agent mode: "0440" -- name: Setting arch (x86) +- name: Setting arch (amd64) set_fact: - arch: "x86" + arch: "amd64" when: platform == "amd64" - name: Setting arch (arm) @@ -53,6 +53,10 @@ url: "https://supabase-public-artifacts-bucket.s3.amazonaws.com/supabase-admin-agent/v{{ supabase_admin_agent_release }}/supabase-admin-agent-{{ supabase_admin_agent_release }}-linux-{{ arch }}.tar.gz" dest: "/tmp/supabase-admin-agent.tar.gz" timeout: 90 + register: download_result + until: download_result is succeeded + retries: 3 + delay: 2 - name: supabase-admin-agent - unpack archive in /opt unarchive: diff --git a/ansible/tasks/internal/supautils.yml b/ansible/tasks/internal/supautils.yml index 33811b5a..dc8866eb 100644 --- a/ansible/tasks/internal/supautils.yml +++ b/ansible/tasks/internal/supautils.yml @@ -13,6 +13,10 @@ dest: /tmp/supautils-{{ supautils_release }}.tar.gz checksum: "{{ supautils_release_checksum }}" timeout: 60 + register: download_result + until: download_result is succeeded + retries: 3 + delay: 2 - name: supautils - unpack archive unarchive: diff --git a/ansible/tasks/setup-envoy.yml b/ansible/tasks/setup-envoy.yml index 1552393e..7901cd63 100644 --- a/ansible/tasks/setup-envoy.yml +++ b/ansible/tasks/setup-envoy.yml @@ -5,13 +5,17 @@ - name: Envoy - download binary ansible.builtin.get_url: - checksum: "{{ envoy_release_checksum }}" + checksum: "{{ envoy_arm_release_checksum if platform == 'arm64' else envoy_x86_release_checksum }}" dest: '/opt/envoy' group: 'envoy' mode: '0700' owner: 'envoy' # yamllint disable-line rule:line-length - url: "https://github.com/envoyproxy/envoy/releases/download/v{{ envoy_release }}/envoy-{{ envoy_release }}-linux-aarch_64" + url: "https://github.com/envoyproxy/envoy/releases/download/v{{ envoy_release }}/envoy-{{ envoy_release }}-linux-{{ 'aarch_64' if platform == 'arm64' else 'x86_64' }}" + register: download_result + until: download_result is succeeded + retries: 3 + delay: 2 - name: Envoy - download hot restarter script ansible.builtin.get_url: @@ -22,6 +26,10 @@ owner: 'envoy' # yamllint disable-line rule:line-length url: "https://raw.githubusercontent.com/envoyproxy/envoy/v{{ envoy_release }}/restarter/hot-restarter.py" + register: download_result + until: download_result is succeeded + retries: 3 + delay: 2 - name: Envoy - bump up ulimit community.general.pam_limits: diff --git a/ansible/tasks/setup-gotrue.yml b/ansible/tasks/setup-gotrue.yml index 70bbbf85..940ce60d 100644 --- a/ansible/tasks/setup-gotrue.yml +++ b/ansible/tasks/setup-gotrue.yml @@ -20,9 +20,13 @@ - name: gotrue - download commit archive ansible.builtin.get_url: - checksum: "{{ gotrue_release_checksum }}" + checksum: "{{ gotrue_arm_release_checksum if platform == 'arm64' else gotrue_x86_release_checksum }}" dest: '/tmp/gotrue.tar.gz' url: "https://github.com/supabase/gotrue/releases/download/v{{ gotrue_release }}/auth-v{{ gotrue_release }}-{{ arch }}.tar.gz" + register: download_result + until: download_result is succeeded + retries: 3 + delay: 2 - name: gotrue - create /opt/gotrue and /etc/auth.d ansible.builtin.file: diff --git a/ansible/tasks/setup-kong.yml b/ansible/tasks/setup-kong.yml index 22a34897..1908481f 100644 --- a/ansible/tasks/setup-kong.yml +++ b/ansible/tasks/setup-kong.yml @@ -14,9 +14,13 @@ - name: Kong - download deb package get_url: - checksum: "{{ kong_deb_checksum }}" + checksum: "{{ kong_deb_checksum[platform] }}" dest: '/tmp/kong.deb' - url: "https://packages.konghq.com/public/gateway-28/deb/ubuntu/pool/{{ kong_release_target }}/main/k/ko/kong_2.8.1/{{ kong_deb }}" + url: "https://packages.konghq.com/public/gateway-28/deb/ubuntu/pool/{{ kong_release_target }}/main/k/ko/kong_2.8.1/{{ kong_deb[platform] }}" + register: download_result + until: download_result is succeeded + retries: 3 + delay: 2 - name: Kong - deb installation ansible.builtin.apt: diff --git a/ansible/tasks/setup-nginx.yml b/ansible/tasks/setup-nginx.yml index 1f10ceec..8dda21e7 100644 --- a/ansible/tasks/setup-nginx.yml +++ b/ansible/tasks/setup-nginx.yml @@ -17,6 +17,10 @@ checksum: "{{ nginx_release_checksum }}" dest: '/tmp/nginx-{{ nginx_release }}.tar.gz' url: "https://nginx.org/download/nginx-{{ nginx_release }}.tar.gz" + register: download_result + until: download_result is succeeded + retries: 3 + delay: 2 - name: nginx - unpack archive ansible.builtin.unarchive: diff --git a/ansible/tasks/setup-pgbouncer.yml b/ansible/tasks/setup-pgbouncer.yml index 06925c6a..16cdfbb3 100644 --- a/ansible/tasks/setup-pgbouncer.yml +++ b/ansible/tasks/setup-pgbouncer.yml @@ -17,6 +17,10 @@ dest: "/tmp/pgbouncer-{{ pgbouncer_release }}.tar.gz" timeout: 60 url: "https://www.pgbouncer.org/downloads/files/{{ pgbouncer_release }}/pgbouncer-{{ pgbouncer_release }}.tar.gz" + register: download_result + until: download_result is succeeded + retries: 3 + delay: 2 - name: PgBouncer - unpack archive ansible.builtin.unarchive: diff --git a/ansible/tasks/setup-postgrest.yml b/ansible/tasks/setup-postgrest.yml index 13cea264..2fd001fa 100644 --- a/ansible/tasks/setup-postgrest.yml +++ b/ansible/tasks/setup-postgrest.yml @@ -9,6 +9,12 @@ force: true mode: '0644' url: 'https://www.postgresql.org/media/keys/ACCC4CF8.asc' + timeout: 60 + validate_certs: true + register: pgdg_key_download + retries: 6 + delay: 2 + until: pgdg_key_download is succeeded - name: PostgREST - add Postgres PPA main ansible.builtin.apt_repository: @@ -51,10 +57,14 @@ - name: PostgREST - download ubuntu binary archive (arm) ansible.builtin.get_url: - checksum: "{{ postgrest_arm_release_checksum }}" + checksum: "{{ postgrest_arm_release_checksum if platform == 'arm64' else postgrest_x86_release_checksum }}" dest: '/tmp/postgrest.tar.xz' timeout: 60 url: "https://github.com/PostgREST/postgrest/releases/download/v{{ postgrest_release }}/postgrest-v{{ postgrest_release }}-{{ download_binary }}.tar.xz" + register: download_result + until: download_result is succeeded + retries: 3 + delay: 2 vars: download_binary: >- {%- if platform == "arm64" -%} diff --git a/ansible/tasks/setup-supabase-internal.yml b/ansible/tasks/setup-supabase-internal.yml index 00007ecd..2427470e 100644 --- a/ansible/tasks/setup-supabase-internal.yml +++ b/ansible/tasks/setup-supabase-internal.yml @@ -10,6 +10,10 @@ dest: '/tmp/awscliv2.zip' timeout: 60 url: "https://awscli.amazonaws.com/awscli-exe-linux-{{ 'aarch64' if platform == 'arm64' else 'x86_64' }}-{{ aws_cli_release }}.zip" + register: download_result + until: download_result is succeeded + retries: 3 + delay: 2 - name: AWS CLI - expand @@ -40,7 +44,7 @@ timeout: 120 become: true retries: 3 - delay: 10 + delay: 2 register: vector_download until: vector_download is success diff --git a/ansible/vars.yml b/ansible/vars.yml index c2be6ac1..ab150f6e 100644 --- a/ansible/vars.yml +++ b/ansible/vars.yml @@ -10,9 +10,9 @@ postgres_major: # Full version strings for each major version postgres_release: - postgresorioledb-17: "17.6.0.070-orioledb" - postgres17: "17.6.1.113" - postgres15: "15.14.1.113" + postgresorioledb-17: "17.6.0.071" + postgres17: "17.6.1.114" + postgres15: "15.14.1.114" # Non Postgres Extensions pgbouncer_release: 1.25.1 @@ -27,6 +27,8 @@ postgrest_x86_release_checksum: sha256:ab5cc7e974d4940447991804588cfb8b3f7b2c57b gotrue_release: 2.188.1 gotrue_release_checksum: sha1:236e8c7bb93e1246b3ff31dbda0fbebe6c3114ca +gotrue_arm_release_checksum: sha1:236e8c7bb93e1246b3ff31dbda0fbebe6c3114ca +gotrue_x86_release_checksum: sha1:b7a6d2c3cb32358710db919f1178569ec19590f0 aws_cli_release: 2.23.11 @@ -38,12 +40,17 @@ golang_version_checksum: amd64: sha256:9ebfcab26801fa4cf0627c6439db7a4da4d3c6766142a3dd83508240e4f21031 envoy_release: 1.28.0 -envoy_release_checksum: sha1:b0a06e9cfb170f1993f369beaa5aa9d7ec679ce5 +envoy_arm_release_checksum: sha256:eb930e32ab5555643e09d11d490e392d0a790c5a80eb0b0ebacb1046bdbb114d +envoy_x86_release_checksum: sha256:2639563ce9bc09b1ee6bd4731760b596c8ed1e474cdd83cc9df9364516e14367 envoy_hot_restarter_release_checksum: sha1:6d43b89d266fb2427a4b51756b649883b0617eda kong_release_target: focal -kong_deb: kong_2.8.1_arm64.deb -kong_deb_checksum: sha1:2086f6ccf8454fe64435252fea4d29d736d7ec61 +kong_deb: + arm64: kong_2.8.1_arm64.deb + amd64: kong_2.8.1_amd64.deb +kong_deb_checksum: + arm64: sha1:2086f6ccf8454fe64435252fea4d29d736d7ec61 + amd64: sha1:7346d558a467f05d9ed63675b59f974300647e9f nginx_release: 1.22.0 nginx_release_checksum: sha1:419efb77b80f165666e2ee406ad8ae9b845aba93 @@ -53,7 +60,7 @@ postgres_exporter_release_checksum: arm64: sha256:29ba62d538b92d39952afe12ee2e1f4401250d678ff4b354ff2752f4321c87a0 amd64: sha256:cb89fc5bf4485fb554e0d640d9684fae143a4b2d5fa443009bd29c59f9129e84 -adminapi_release: "0.95.1" +adminapi_release: "0.100.2" adminmgr_release: "0.32.3" supabase_admin_agent_release: 1.8.0 supabase_admin_agent_splay: 30s diff --git a/development-x86.vars.pkr.hcl b/development-x86.vars.pkr.hcl new file mode 100644 index 00000000..9167010c --- /dev/null +++ b/development-x86.vars.pkr.hcl @@ -0,0 +1,5 @@ +arch = "amd64" +ami_regions = ["ap-southeast-1"] +environment = "dev" +instance-type = "c6i.4xlarge" +region = "ap-southeast-1" diff --git a/ebssurrogate/scripts/chroot-bootstrap-nix.sh b/ebssurrogate/scripts/chroot-bootstrap-nix.sh index bb9da1b8..3a58d73b 100755 --- a/ebssurrogate/scripts/chroot-bootstrap-nix.sh +++ b/ebssurrogate/scripts/chroot-bootstrap-nix.sh @@ -31,7 +31,11 @@ fi # Get current mirror from sources.list function get_current_mirror { - grep -oP 'http://[^/]+(?=/ubuntu-ports/)' /etc/apt/sources.list | head -1 || echo "" + if [ "${ARCH}" = "amd64" ]; then + grep -oP 'https?://[^/]+(?=/ubuntu/)' /etc/apt/sources.list | head -1 || echo "" + else + grep -oP 'http://[^/]+(?=/ubuntu-ports/)' /etc/apt/sources.list | head -1 || echo "" + fi } # Switch to a different mirror @@ -40,7 +44,11 @@ function switch_mirror { local sources_file="/etc/apt/sources.list" echo "Switching to mirror: ${new_mirror}" - sed -i "s|http://[^/]*/ubuntu-ports/|http://${new_mirror}/ubuntu-ports/|g" "${sources_file}" + if [ "${ARCH}" = "amd64" ]; then + sed -i "s|http://[^/]*/ubuntu/|http://${new_mirror}/ubuntu/|g" "${sources_file}" + else + sed -i "s|http://[^/]*/ubuntu-ports/|http://${new_mirror}/ubuntu-ports/|g" "${sources_file}" + fi # Show what we're using echo "Current sources.list configuration:" @@ -50,8 +58,6 @@ function switch_mirror { # Get list of mirrors to try function get_mirror_list { local sources_file="/etc/apt/sources.list" - local current_region=$(grep -oP '(?<=http://)[^.]+(?=\.clouds\.ports\.ubuntu\.com)' "${sources_file}" | head -1 || echo "") - local -a mirrors=() # Priority order: @@ -59,16 +65,28 @@ function get_mirror_list { # 2. Regional CDN (can be inconsistent) # 3. Global fallback - # Singapore country mirror for ap-southeast-1 - if [ "${current_region}" = "ap-southeast-1" ]; then - mirrors+=("sg.ports.ubuntu.com") - fi + if [ "${ARCH}" = "amd64" ]; then + local current_region=$(grep -oP '(?<=http://)[^.]+(?=\.ec2\.archive\.ubuntu\.com)' "${sources_file}" | head -1 || echo "") - if [ -n "${current_region}" ]; then - mirrors+=("${current_region}.clouds.ports.ubuntu.com") - fi + if [ -n "${current_region}" ]; then + mirrors+=("${current_region}.ec2.archive.ubuntu.com") + fi - mirrors+=("ports.ubuntu.com") + mirrors+=("archive.ubuntu.com") + else + local current_region=$(grep -oP '(?<=http://)[^.]+(?=\.clouds\.ports\.ubuntu\.com)' "${sources_file}" | head -1 || echo "") + + # Singapore country mirror for ap-southeast-1 + if [ "${current_region}" = "ap-southeast-1" ]; then + mirrors+=("sg.ports.ubuntu.com") + fi + + if [ -n "${current_region}" ]; then + mirrors+=("${current_region}.clouds.ports.ubuntu.com") + fi + + mirrors+=("ports.ubuntu.com") + fi echo "${mirrors[@]}" } @@ -250,6 +268,11 @@ function update_install_packages { echo "FATAL: Failed to install arm64 boot packages" exit 1 fi + else + if ! apt_install_with_fallback $APT_OPTIONS --yes install initramfs-tools; then + echo "FATAL: Failed to install amd64 boot packages" + exit 1 + fi fi } @@ -308,7 +331,7 @@ function setup_apparmor { cp -rv /tmp/apparmor_profiles/* /etc/apparmor.d/ } -function setup_grub_conf_arm64 { +function setup_grub_conf { cat << EOF > /etc/default/grub GRUB_DEFAULT=0 GRUB_TIMEOUT=0 @@ -320,12 +343,12 @@ EOF # Install GRUB function install_configure_grub { + setup_grub_conf if [ "${ARCH}" = "arm64" ]; then if ! apt_install_with_fallback $APT_OPTIONS --yes install cloud-guest-utils fdisk grub-efi-arm64 efibootmgr; then echo "FATAL: Failed to install grub packages for arm64" exit 1 fi - setup_grub_conf_arm64 rm -rf /etc/grub.d/30_os-prober sleep 1 fi diff --git a/ebssurrogate/scripts/qemu-bootstrap-nix.sh b/ebssurrogate/scripts/qemu-bootstrap-nix.sh index 0a83c21b..43e1d98f 100755 --- a/ebssurrogate/scripts/qemu-bootstrap-nix.sh +++ b/ebssurrogate/scripts/qemu-bootstrap-nix.sh @@ -22,13 +22,15 @@ function waitfor_boot_finished { } function install_packages { - apt-get update && sudo apt-get install software-properties-common e2fsprogs nfs-common locales iptables arptables ebtables ufw logrotate -y - add-apt-repository --yes --update ppa:ansible/ansible && sudo apt-get install ansible -y + apt-get update && sudo apt-get install software-properties-common e2fsprogs nfs-common locales iptables arptables ebtables ufw logrotate -y + # TODO (darora): temporarily disabling while Launchpad is under ddos attack and very frequently timing out + # add-apt-repository --yes --update ppa:ansible/ansible && + sudo apt-get install ansible -y ansible-galaxy collection install community.general } function execute_playbook { - + sudo mkdir -p /etc/ansible tee /etc/ansible/ansible.cfg <<EOF [defaults] callbacks_enabled = timer, profile_tasks, profile_roles @@ -93,6 +95,7 @@ EXTRA_NIX_CONF" -s /bin/bash root } function execute_stage2_playbook { + sudo mkdir -p /etc/ansible sudo tee /etc/ansible/ansible.cfg <<EOF [defaults] callbacks_enabled = timer, profile_tasks, profile_roles diff --git a/ebssurrogate/scripts/surrogate-bootstrap-nix.sh b/ebssurrogate/scripts/surrogate-bootstrap-nix.sh index a3c79ae1..cf804bf5 100755 --- a/ebssurrogate/scripts/surrogate-bootstrap-nix.sh +++ b/ebssurrogate/scripts/surrogate-bootstrap-nix.sh @@ -29,14 +29,22 @@ function apt_update_with_fallback { fi # Define mirror tiers (in priority order) - local -a mirror_tiers=( - "${REGION}.clouds.ports.ubuntu.com" # Tier 1: Regional CDN - "ports.ubuntu.com" # Tier 2: Global pool - ) + local -a mirror_tiers=() + if [ "${ARCH}" = "amd64" ]; then + if [ -n "${REGION}" ]; then + mirror_tiers+=("${REGION}.ec2.archive.ubuntu.com") + fi + mirror_tiers+=("archive.ubuntu.com") + else + if [ -n "${REGION}" ]; then + mirror_tiers+=("${REGION}.clouds.ports.ubuntu.com") + fi + mirror_tiers+=("ports.ubuntu.com") + fi # If we couldn't get REGION, skip tier 1 if [ -z "${REGION}" ]; then - echo "Warning: Could not determine EC2 region, skipping regional CDN" + echo "Warning: Could not determine EC2 region, skipping regional mirror" mirror_tiers=("${mirror_tiers[@]:1}") # Remove first element fi @@ -47,10 +55,12 @@ function apt_update_with_fallback { echo "=========================================" # Update sources.list to use current mirror - # Replace the region-specific mirror URL - sed -i "s|http://[^/]*/ubuntu-ports/|http://${mirror}/ubuntu-ports/|g" "${sources_file}" - # Also update any security sources - sed -i "s|http://ports.ubuntu.com/ubuntu-ports|http://${mirror}/ubuntu-ports|g" "${sources_file}" + if [ "${ARCH}" = "amd64" ]; then + sed -i "s|http://[^/]*/ubuntu/|http://${mirror}/ubuntu/|g" "${sources_file}" + else + sed -i "s|http://[^/]*/ubuntu-ports/|http://${mirror}/ubuntu-ports/|g" "${sources_file}" + sed -i "s|http://ports.ubuntu.com/ubuntu-ports|http://${mirror}/ubuntu-ports|g" "${sources_file}" + fi # Show what we're using echo "Current sources.list configuration:" @@ -109,7 +119,8 @@ function install_packages { fi sudo apt-get install software-properties-common -y - add-apt-repository --yes --update ppa:ansible/ansible + # TODO (darora): temporarily disabling while Launchpad is under ddos attack and very frequently timing out + # add-apt-repository --yes --update ppa:ansible/ansible if ! apt_update_with_fallback; then echo "FATAL: Failed to update package lists after adding Ansible PPA" @@ -119,12 +130,6 @@ function install_packages { sudo apt-get install ansible -y ansible-galaxy collection install community.general - # Update apt and install required packages - if ! apt_update_with_fallback; then - echo "FATAL: Failed to update package lists before installing tools" - exit 1 - fi - apt-get install -y \ gdisk \ e2fsprogs \ @@ -228,31 +233,51 @@ function pull_docker { # Create fstab function create_fstab { FMT="%-42s %-11s %-5s %-17s %-5s %s" -cat > "/mnt/etc/fstab" << EOF -$(printf "${FMT}" "# DEVICE UUID" "MOUNTPOINT" "TYPE" "OPTIONS" "DUMP" "FSCK") -$(findmnt -no SOURCE /mnt | xargs blkid -o export | awk -v FMT="${FMT}" '/^UUID=/ { printf(FMT, $0, "/", "ext4", "defaults,discard", "0", "1" ) }') -$(findmnt -no SOURCE /mnt/boot/efi | xargs blkid -o export | awk -v FMT="${FMT}" '/^UUID=/ { printf(FMT, $0, "/boot/efi", "vfat", "umask=0077", "0", "1" ) }') -$(findmnt -no SOURCE /mnt/data | xargs blkid -o export | awk -v FMT="${FMT}" '/^UUID=/ { printf(FMT, $0, "/data", "ext4", "defaults,discard,nofail,x-systemd.device-timeout=5s", "0", "2" ) }') -$(printf "$FMT" "/swapfile" "none" "swap" "sw" "0" "0") -EOF + local ROOT_LINE=$(findmnt -no SOURCE /mnt | xargs blkid -o export | awk -v FMT="${FMT}" '/^UUID=/ { printf(FMT, $0, "/", "ext4", "defaults,discard", "0", "1" ) }') + local DATA_LINE=$(findmnt -no SOURCE /mnt/data | xargs blkid -o export | awk -v FMT="${FMT}" '/^UUID=/ { printf(FMT, $0, "/data", "ext4", "defaults,discard,nofail,x-systemd.device-timeout=5s", "0", "2" ) }') + local SWAP_LINE=$(printf "$FMT" "/swapfile" "none" "swap" "sw" "0" "0") + + local EFI_LINE="" + if [ "${ARCH}" = "arm64" ]; then + EFI_LINE=$(findmnt -no SOURCE /mnt/boot/efi | xargs blkid -o export | awk -v FMT="${FMT}" '/^UUID=/ { printf(FMT, $0, "/boot/efi", "vfat", "umask=0077", "0", "1" ) }') + fi + + { + printf "${FMT}\n" "# DEVICE UUID" "MOUNTPOINT" "TYPE" "OPTIONS" "DUMP" "FSCK" + echo "${ROOT_LINE}" + [ -n "${EFI_LINE}" ] && echo "${EFI_LINE}" + echo "${DATA_LINE}" + echo "${SWAP_LINE}" + } > "/mnt/etc/fstab" unset FMT } function setup_chroot_environment { UBUNTU_VERSION=$(lsb_release -cs) # 'noble' for Ubuntu 24.04 + # sometimes debootstrap will get stuck on a download for a long time + # the default read timeout in wget is 900s, which can cause a ~15min increase in build time + # this forces the process to fail-fast and retry + cat <<EOF > ~/.wgetrc +read_timeout = 30 +timeout = 35 +tries = 5 +EOF + # Update ec2-region REGION=$(curl --silent --fail http://169.254.169.254/latest/meta-data/placement/availability-zone | sed -E 's|[a-z]+$||g') - # Bootstrap Ubuntu into /mnt using the regional mirror (avoids global ports.ubuntu.com stalls) - debootstrap --arch ${ARCH} --variant=minbase "$UBUNTU_VERSION" /mnt "http://${REGION}.clouds.ports.ubuntu.com/ubuntu-ports" + # Bootstrap Ubuntu into /mnt using the regional mirror (avoids global mirror stalls) + if [ "${ARCH}" = "amd64" ]; then + debootstrap --arch ${ARCH} --variant=minbase "$UBUNTU_VERSION" /mnt "http://${REGION}.ec2.archive.ubuntu.com/ubuntu" + else + debootstrap --arch ${ARCH} --variant=minbase "$UBUNTU_VERSION" /mnt "http://${REGION}.clouds.ports.ubuntu.com/ubuntu-ports" + fi sed -i "s/REGION/${REGION}/g" /tmp/sources.list cp /tmp/sources.list /mnt/etc/apt/sources.list - if [ "${ARCH}" = "arm64" ]; then - create_fstab - fi + create_fstab # Create mount points and mount the filesystem mkdir -p /mnt/{dev,proc,sys} @@ -304,10 +329,11 @@ function download_ccache { } function execute_playbook { - + sudo mkdir -p /etc/ansible tee /etc/ansible/ansible.cfg <<EOF [defaults] callbacks_enabled = timer, profile_tasks, profile_roles +pipelining = True EOF # Run Ansible playbook #export ANSIBLE_LOG_PATH=/tmp/ansible.log && export ANSIBLE_DEBUG=True && export ANSIBLE_REMOTE_TEMP=/mnt/tmp diff --git a/nix/packages/build-ami.nix b/nix/packages/build-ami.nix index 980223fd..c847f47a 100644 --- a/nix/packages/build-ami.nix +++ b/nix/packages/build-ami.nix @@ -19,6 +19,7 @@ let (root + "/ansible") (root + "/migrations") (root + "/scripts") + (root + "/amazon-amd64-nix.pkr.hcl") (root + "/amazon-arm64-nix.pkr.hcl") (root + "/development-arm.vars.pkr.hcl") (lib.fileset.maybeMissing (root + "/common-nix.vars.pkr.hcl")) @@ -111,7 +112,7 @@ writeShellApplication { echo "No cached AMI found" cd "$PACKER_SOURCES" - packer init amazon-arm64-nix.pkr.hcl + packer init "$@" packer build \ -var-file="development-arm.vars.pkr.hcl" \ -var "input-hash=$INPUT_HASH" \ diff --git a/scripts/90-cleanup-qemu.sh b/scripts/90-cleanup-qemu.sh index e6a58500..ef21aae1 100644 --- a/scripts/90-cleanup-qemu.sh +++ b/scripts/90-cleanup-qemu.sh @@ -38,7 +38,7 @@ elif [ -n "$(command -v apt-get)" ]; then ansible \ snapd - add-apt-repository --yes --remove ppa:ansible/ansible + # add-apt-repository --yes --remove ppa:ansible/ansible source /etc/os-release diff --git a/scripts/90-cleanup.sh b/scripts/90-cleanup.sh index 644e5f7f..ecb63a8d 100644 --- a/scripts/90-cleanup.sh +++ b/scripts/90-cleanup.sh @@ -36,7 +36,7 @@ elif [ -n "$(command -v apt-get)" ]; then libgcc-9-dev \ ansible - add-apt-repository --yes --remove ppa:ansible/ansible + # add-apt-repository --yes --remove ppa:ansible/ansible source /etc/os-release diff --git a/scripts/nix-provision.sh b/scripts/nix-provision.sh index 755ec190..dfca0326 100644 --- a/scripts/nix-provision.sh +++ b/scripts/nix-provision.sh @@ -18,8 +18,9 @@ function install_packages { sudo apt-key adv --keyserver hkp://keyserver.ubuntu.com:80 --recv-keys 93C4A3FD7BB9C367 # Add repository and install - sudo add-apt-repository --yes ppa:ansible/ansible - sudo apt-get update + # TODO (darora): temporarily disabling while Launchpad is under ddos attack and very frequently timing out + # sudo add-apt-repository --yes ppa:ansible/ansible + # sudo apt-get update sudo apt-get install -y ansible ansible-galaxy collection install community.general @@ -42,6 +43,7 @@ EXTRA_NIX_CONF" -s /bin/bash root function execute_stage2_playbook { echo "POSTGRES_MAJOR_VERSION: ${POSTGRES_MAJOR_VERSION}" echo "GIT_SHA: ${GIT_SHA}" + sudo mkdir -p /etc/ansible sudo tee /etc/ansible/ansible.cfg <<EOF [defaults] callbacks_enabled = timer, profile_tasks, profile_roles @@ -62,7 +64,7 @@ EOF function cleanup_packages { sudo apt-get -y remove --purge ansible - sudo add-apt-repository --yes --remove ppa:ansible/ansible + # sudo add-apt-repository --yes --remove ppa:ansible/ansible } install_packages diff --git a/stage2-nix-psql.pkr.hcl b/stage2-nix-psql.pkr.hcl index 032dd71e..58e60a24 100644 --- a/stage2-nix-psql.pkr.hcl +++ b/stage2-nix-psql.pkr.hcl @@ -37,6 +37,11 @@ variable "source_ami" { description = "Source AMI ID from stage 1" } +variable "instance_type" { + type = string + default = "c6g.4xlarge" +} + packer { required_plugins { amazon = { @@ -48,7 +53,7 @@ packer { source "amazon-ebs" "ubuntu" { ami_name = "${var.ami_name}-${var.postgres-version}" - instance_type = "c6g.4xlarge" + instance_type = var.instance_type region = "${var.region}" source_ami = "${var.source_ami}" [parent: 899f7b7ffb02]