supabase-postgres.git / summary / log / commit / refs
commit d488045c4ff8850a7bc558cf0730fcd47e24e02a
Author: Div Arora <darora@users.noreply.github.com>
Commit: GitHub <noreply@github.com>
Date: Tue May 05 04:10:55 2026 +0000
feat: x86 support GENCOMP-44 (#2128)
* feat: ability to build x86 AMI
* fix: action linting
* fix: correct release name and checksum
* fix: postgrest
* fix: kong handling
* fix: admin agent fix
* fix: boot for both targets
* fix: supascan off for x86 for now
* fix: retry on handshake failure
* fix: arch handling postgrest
* tests: new suffix
* fix: envoy architecture handling
* tests: cache bust to test x86 vm test run in ci
* chore: change arch-aware naming scheme for upgrade bundles
The updated scheme makes other parts of our overall architecture
simpler.
* fix: single ami build
* feat: make stage1 AMI build idempotent
The stage2 AMI build process is somewhat flaky, and retrying the job
if it fails results in an error as the stage1 AMI has already been
built. This change attempts to re-use the stage1 AMI if it can be
found. Further changes will be required to reduce the flakiness on the
stage2 build.
* fix: remove unnecessary apt update
* perf: attempt to make builds faster
* feat: retry get_url calls on failures
Builds frequently fail on 502 flakes on some requests. This change
retries them a few times to paper over these issues.
* fix: attempt to reduce variance in build times
* fix: update x86 build disks as well
* fix: remove -x86 from ami naming scheme for historical consistency
* chore: increase timeout
* chore: clean up versions
* chore: upgrade admin-api to build with x86 nano param generation support
* chore: rc image release
* chore: continue other builds even if one fails
This prevents flakes from causing the entire matrix to fail. The rate
of flakes is elevated right now due to Ubuntu servers being under a
DDoS attack.
* fix: temporarily disable ppa
* feat: support x86 mirror fallbacks
* fix: create dir before writing file
.
* chore: temporarily disable arm builds
For simpler testing on x86
* chore: re-enable arm builds
* ci: increase task parallelism
* chore: clean up changes
* fix: add arch to the ami name
---------
Co-authored-by: Sam Rose <samuel@supabase.io>
.github/actions/build-ami/action.yml | 11 +-
.github/workflows/ami-release-nix-single.yml | 51 ++++-
.github/workflows/ami-release-nix.yml | 81 +++++--
.github/workflows/nix-build.yml | 12 +-
amazon-amd64-nix.pkr.hcl | 275 ++++++++++++++++++++++++
amazon-arm64-nix.pkr.hcl | 28 +--
ansible/manifest-playbook.yml | 63 ++++--
ansible/playbook.yml | 2 +-
ansible/tasks/internal/admin-api.yml | 4 +-
ansible/tasks/internal/admin-mgr.yml | 4 +
ansible/tasks/internal/install-salt.yml | 8 +
ansible/tasks/internal/postgres-exporter.yml | 4 +
ansible/tasks/internal/setup-ansible-pull.yml | 3 +-
ansible/tasks/internal/supabase-admin-agent.yml | 8 +-
ansible/tasks/internal/supautils.yml | 4 +
ansible/tasks/setup-envoy.yml | 12 +-
ansible/tasks/setup-gotrue.yml | 6 +-
ansible/tasks/setup-kong.yml | 8 +-
ansible/tasks/setup-nginx.yml | 4 +
ansible/tasks/setup-pgbouncer.yml | 4 +
ansible/tasks/setup-postgrest.yml | 12 +-
ansible/tasks/setup-supabase-internal.yml | 6 +-
ansible/vars.yml | 21 +-
development-x86.vars.pkr.hcl | 5 +
ebssurrogate/scripts/chroot-bootstrap-nix.sh | 51 +++--
ebssurrogate/scripts/qemu-bootstrap-nix.sh | 9 +-
ebssurrogate/scripts/surrogate-bootstrap-nix.sh | 84 +++++---
nix/packages/build-ami.nix | 3 +-
scripts/90-cleanup-qemu.sh | 2 +-
scripts/90-cleanup.sh | 2 +-
scripts/nix-provision.sh | 8 +-
stage2-nix-psql.pkr.hcl | 7 +-
32 files changed, 661 insertions(+), 141 deletions(-)
diff --git a/.github/actions/build-ami/action.yml b/.github/actions/build-ami/action.yml
index b733cbd2..c10bc406 100644
--- a/.github/actions/build-ami/action.yml
+++ b/.github/actions/build-ami/action.yml
@@ -18,6 +18,14 @@ inputs:
description: 'Prefix for the AMI name'
required: false
default: 'supabase-postgres'
+ packer_template:
+ description: 'Packer template for stage 1 (e.g., amazon-arm64-nix.pkr.hcl)'
+ required: false
+ default: 'amazon-arm64-nix.pkr.hcl'
+ instance_type:
+ description: 'EC2 instance type for the build'
+ required: false
+ default: 'c6g.4xlarge'
outputs:
stage2_ami_id:
@@ -65,7 +73,7 @@ runs:
-var "packer-execution-id=${{ env.EXECUTION_ID }}" \
-var "ansible_arguments=-e postgresql_major=${{ inputs.postgres_version }}" \
-var 'ami_regions=${{ inputs.ami_regions }}' \
- amazon-arm64-nix.pkr.hcl
+ ${{ inputs.packer_template }}
- name: Build AMI stage 2
id: build-stage2
@@ -84,4 +92,5 @@ runs:
-var "postgres_major_version=${{ inputs.postgres_version }}" \
-var "ami_name=${{ inputs.ami_name_prefix }}" \
-var "git_sha=${{ inputs.git_sha }}" \
+ -var "instance_type=${{ inputs.instance_type }}" \
stage2-nix-psql.pkr.hcl
diff --git a/.github/workflows/ami-release-nix-single.yml b/.github/workflows/ami-release-nix-single.yml
index ff23bddd..e5ef7399 100644
--- a/.github/workflows/ami-release-nix-single.yml
+++ b/.github/workflows/ami-release-nix-single.yml
@@ -12,6 +12,14 @@ on:
required: true
type: string
default: 'main'
+ arch:
+ description: 'Architecture to build'
+ required: true
+ type: choice
+ options:
+ - arm64
+ - amd64
+ default: arm64
permissions:
contents: write
@@ -19,7 +27,7 @@ permissions:
jobs:
build:
- runs-on: large-linux-arm
+ runs-on: ${{ github.event.inputs.arch == 'amd64' && 'blacksmith-2vcpu-ubuntu-2404' || 'large-linux-arm' }}
timeout-minutes: 150
steps:
@@ -41,6 +49,26 @@ jobs:
run: |
echo "sha=$(git rev-parse HEAD)" >> "$GITHUB_OUTPUT"
+ - name: Set arch-specific variables
+ id: arch_vars
+ run: |
+ ARCH="${{ github.event.inputs.arch }}"
+ if [ "$ARCH" = "amd64" ]; then
+ {
+ echo "packer_template=amazon-amd64-nix.pkr.hcl"
+ echo "instance_type=c6i.4xlarge"
+ echo "ami_name_prefix=supabase-postgres-x86"
+ echo "arch_suffix=-x86"
+ } >> "$GITHUB_OUTPUT"
+ else
+ {
+ echo "packer_template=amazon-arm64-nix.pkr.hcl"
+ echo "instance_type=c6g.4xlarge"
+ echo "ami_name_prefix=supabase-postgres"
+ echo "arch_suffix="
+ } >> "$GITHUB_OUTPUT"
+ fi
+
- name: Install nix
uses: ./.github/actions/nix-install-ephemeral
with:
@@ -57,6 +85,9 @@ jobs:
region: us-east-1
ami_regions: '["us-east-1"]'
git_sha: ${{ steps.get_sha.outputs.sha }}
+ packer_template: ${{ steps.arch_vars.outputs.packer_template }}
+ instance_type: ${{ steps.arch_vars.outputs.instance_type }}
+ ami_name_prefix: ${{ steps.arch_vars.outputs.ami_name_prefix }}
- name: Grab release version
id: process_release_version
@@ -86,13 +117,14 @@ jobs:
-e "ami_release_version=${{ steps.process_release_version.outputs.version }}" \
-e "internal_artifacts_bucket=${{ secrets.ARTIFACTS_BUCKET }}" \
-e "postgres_major_version=${{ github.event.inputs.postgres_version }}" \
+ -e "arch=${{ github.event.inputs.arch }}" \
manifest-playbook.yml
- name: Upload nix flake revision to s3 staging
run: |
- aws s3 cp /tmp/pg_binaries.tar.gz s3://${{ secrets.ARTIFACTS_BUCKET }}/upgrades/postgres/supabase-postgres-${{ steps.process_release_version.outputs.version }}/20.04.tar.gz
- aws s3 cp /tmp/pg_binaries.tar.gz s3://${{ secrets.ARTIFACTS_BUCKET }}/upgrades/postgres/supabase-postgres-${{ steps.process_release_version.outputs.version }}/24.04.tar.gz
- aws s3 cp /tmp/pg_binaries.tar.gz s3://${{ secrets.ARTIFACTS_BUCKET }}/upgrades/postgres/supabase-postgres-${{ steps.process_release_version.outputs.version }}/upgrade_bundle.tar.gz
+ aws s3 cp /tmp/pg_binaries.tar.gz s3://${{ secrets.ARTIFACTS_BUCKET }}/upgrades/postgres/supabase-postgres-${{ steps.process_release_version.outputs.version }}${{ steps.arch_vars.outputs.arch_suffix }}/20.04.tar.gz
+ aws s3 cp /tmp/pg_binaries.tar.gz s3://${{ secrets.ARTIFACTS_BUCKET }}/upgrades/postgres/supabase-postgres-${{ steps.process_release_version.outputs.version }}${{ steps.arch_vars.outputs.arch_suffix }}/24.04.tar.gz
+ aws s3 cp /tmp/pg_binaries.tar.gz s3://${{ secrets.ARTIFACTS_BUCKET }}/upgrades/postgres/supabase-postgres-${{ steps.process_release_version.outputs.version }}${{ steps.arch_vars.outputs.arch_suffix }}/upgrade_bundle.tar.gz
- name: configure aws credentials - prod
uses: aws-actions/configure-aws-credentials@7474bc4690e29a8392af63c5b98e7449536d5c3a # v4.3.1
@@ -107,19 +139,20 @@ jobs:
-e "ami_release_version=${{ steps.process_release_version.outputs.version }}" \
-e "internal_artifacts_bucket=${{ secrets.PROD_ARTIFACTS_BUCKET }}" \
-e "postgres_major_version=${{ github.event.inputs.postgres_version }}" \
+ -e "arch=${{ github.event.inputs.arch }}" \
manifest-playbook.yml
- name: Upload nix flake revision to s3 prod
run: |
- aws s3 cp /tmp/pg_binaries.tar.gz s3://${{ secrets.PROD_ARTIFACTS_BUCKET }}/upgrades/postgres/supabase-postgres-${{ steps.process_release_version.outputs.version }}/20.04.tar.gz
- aws s3 cp /tmp/pg_binaries.tar.gz s3://${{ secrets.PROD_ARTIFACTS_BUCKET }}/upgrades/postgres/supabase-postgres-${{ steps.process_release_version.outputs.version }}/24.04.tar.gz
- aws s3 cp /tmp/pg_binaries.tar.gz s3://${{ secrets.PROD_ARTIFACTS_BUCKET }}/upgrades/postgres/supabase-postgres-${{ steps.process_release_version.outputs.version }}/upgrade_bundle.tar.gz
+ aws s3 cp /tmp/pg_binaries.tar.gz s3://${{ secrets.PROD_ARTIFACTS_BUCKET }}/upgrades${{ steps.arch_vars.outputs.arch_suffix }}/postgres/supabase-postgres-${{ steps.process_release_version.outputs.version }}/20.04.tar.gz
+ aws s3 cp /tmp/pg_binaries.tar.gz s3://${{ secrets.PROD_ARTIFACTS_BUCKET }}/upgrades${{ steps.arch_vars.outputs.arch_suffix }}/postgres/supabase-postgres-${{ steps.process_release_version.outputs.version }}/24.04.tar.gz
+ aws s3 cp /tmp/pg_binaries.tar.gz s3://${{ secrets.PROD_ARTIFACTS_BUCKET }}/upgrades${{ steps.arch_vars.outputs.arch_suffix }}/postgres/supabase-postgres-${{ steps.process_release_version.outputs.version }}/upgrade_bundle.tar.gz
- name: Create release
uses: softprops/action-gh-release@a06a81a03ee405af7f2048a818ed3f03bbf83c7b # v2.5.0
with:
- name: ${{ steps.process_release_version.outputs.version }}
- tag_name: ${{ steps.process_release_version.outputs.version }}
+ name: ${{ steps.process_release_version.outputs.version }}${{ steps.arch_vars.outputs.arch_suffix }}
+ tag_name: ${{ steps.process_release_version.outputs.version }}${{ steps.arch_vars.outputs.arch_suffix }}
target_commitish: ${{ steps.get_sha.outputs.sha }}
- name: Slack Notification on Failure
diff --git a/.github/workflows/ami-release-nix.yml b/.github/workflows/ami-release-nix.yml
index 778e24eb..aa6a05c3 100644
--- a/.github/workflows/ami-release-nix.yml
+++ b/.github/workflows/ami-release-nix.yml
@@ -37,11 +37,25 @@ jobs:
build:
needs: prepare
strategy:
+ fail-fast: false
matrix:
postgres_version: ${{ fromJson(needs.prepare.outputs.postgres_versions) }}
- include:
- - runner: blacksmith-2vcpu-ubuntu-2404-arm
- runs-on: ${{ matrix.runner }}
+ arch:
+ - name: arm64
+ runner: blacksmith-2vcpu-ubuntu-2404-arm
+ packer_template: amazon-arm64-nix.pkr.hcl
+ vars_file: development-arm.vars.pkr.hcl
+ instance_type: c6g.4xlarge
+ nix_system: aarch64-linux
+ ami_arch_filter: arm64
+ - name: amd64
+ runner: blacksmith-2vcpu-ubuntu-2404
+ packer_template: amazon-amd64-nix.pkr.hcl
+ vars_file: development-x86.vars.pkr.hcl
+ instance_type: c6i.4xlarge
+ nix_system: x86_64-linux
+ ami_arch_filter: x86_64
+ runs-on: ${{ matrix.arch.runner }}
timeout-minutes: 150
steps:
@@ -67,7 +81,7 @@ jobs:
- name: Set PostgreSQL version environment variable
run: |
echo "POSTGRES_MAJOR_VERSION=${{ matrix.postgres_version }}" >> "$GITHUB_ENV"
- echo "EXECUTION_ID=${{ github.run_id }}-${{ matrix.postgres_version }}" >> "$GITHUB_ENV"
+ echo "EXECUTION_ID=${{ github.run_id }}-${{ matrix.postgres_version }}-${{ matrix.arch.name }}" >> "$GITHUB_ENV"
- name: Generate common-nix.vars.pkr.hcl
run: |
@@ -79,13 +93,14 @@ jobs:
POSTGRES_MAJOR_VERSION: ${{ env.POSTGRES_MAJOR_VERSION }}
run: |
GIT_SHA=${{github.sha}}
- nix run github:supabase/postgres/${GIT_SHA}#packer -- init amazon-arm64-nix.pkr.hcl
- # why is postgresql_major defined here instead of where the _three_ other postgresql_* variables are defined?
- nix run github:supabase/postgres/${GIT_SHA}#packer -- build -var "git-head-version=${GIT_SHA}" -var "packer-execution-id=${EXECUTION_ID}" -var-file="development-arm.vars.pkr.hcl" -var-file="common-nix.vars.pkr.hcl" -var "ansible_arguments=-e postgresql_major=${POSTGRES_MAJOR_VERSION}" -var "region=us-east-1" -var 'ami_regions=["us-east-1"]' amazon-arm64-nix.pkr.hcl
+
+ nix run github:supabase/postgres/${GIT_SHA}#packer -- init ${{ matrix.arch.packer_template }}
+ nix run github:supabase/postgres/${GIT_SHA}#packer -- build -var "git-head-version=${GIT_SHA}" -var "packer-execution-id=${EXECUTION_ID}" -var-file="${{ matrix.arch.vars_file }}" -var-file="common-nix.vars.pkr.hcl" -var "ansible_arguments=-e postgresql_major=${POSTGRES_MAJOR_VERSION}" -var "region=us-east-1" -var 'ami_regions=["us-east-1"]' -var "ami_name=supabase-postgres-${{ matrix.arch.ami_arch_filter }}" ${{ matrix.arch.packer_template }}
- name: Find stage 1 AMI
run: |
GIT_SHA=${{github.sha}}
+
PG_VERSION=$(sed -n 's/postgres-version = "\(.*\)"/\1/p' common-nix.vars.pkr.hcl)
REGION="us-east-1"
@@ -98,6 +113,7 @@ jobs:
"Name=tag:postgresVersion,Values=${PG_VERSION}-stage1" \
"Name=tag:sourceSha,Values=${GIT_SHA}" \
"Name=state,Values=available" \
+ "Name=architecture,Values=${{ matrix.arch.ami_arch_filter }}" \
--query 'Images[0].ImageId' \
--output text)
@@ -115,8 +131,7 @@ jobs:
run: |
GIT_SHA=${{github.sha}}
nix run github:supabase/postgres/${GIT_SHA}#packer -- init stage2-nix-psql.pkr.hcl
- POSTGRES_MAJOR_VERSION=${{ env.POSTGRES_MAJOR_VERSION }}
- nix run github:supabase/postgres/${GIT_SHA}#packer -- build -var "git_sha=${GIT_SHA}" -var "git-head-version=${GIT_SHA}" -var "packer-execution-id=${EXECUTION_ID}" -var "postgres_major_version=${POSTGRES_MAJOR_VERSION}" -var "source_ami=${STAGE1_AMI_ID}" -var-file="development-arm.vars.pkr.hcl" -var-file="common-nix.vars.pkr.hcl" -var "region=us-east-1" stage2-nix-psql.pkr.hcl
+ nix run github:supabase/postgres/${GIT_SHA}#packer -- build -var "git_sha=${GIT_SHA}" -var "git-head-version=${GIT_SHA}" -var "packer-execution-id=${EXECUTION_ID}" -var "postgres_major_version=${POSTGRES_MAJOR_VERSION}" -var "source_ami=${STAGE1_AMI_ID}" -var-file="${{ matrix.arch.vars_file }}" -var-file="common-nix.vars.pkr.hcl" -var "region=us-east-1" -var "instance_type=${{ matrix.arch.instance_type }}" -var "ami_name=supabase-postgres-${{ matrix.arch.ami_arch_filter }}" stage2-nix-psql.pkr.hcl
- name: Grab release version
id: process_release_version
@@ -125,6 +140,24 @@ jobs:
echo "version=$VERSION" >> "$GITHUB_OUTPUT"
echo "::notice title=AMI Published::Postgres AMI version: $VERSION"
+ - name: Set arch-qualified version
+ id: arch_version
+ run: |
+ VERSION="${{ steps.process_release_version.outputs.version }}"
+ if [ "${{ matrix.arch.name }}" = "amd64" ]; then
+ {
+ echo "version=${VERSION}"
+ echo "arch_suffix=-x86"
+ echo "release_tag=${VERSION}-x86"
+ } >> "$GITHUB_OUTPUT"
+ else
+ {
+ echo "version=${VERSION}"
+ echo "arch_suffix="
+ echo "release_tag=${VERSION}"
+ } >> "$GITHUB_OUTPUT"
+ fi
+
- name: Create nix flake revision tarball
run: |
GIT_SHA=${{github.sha}}
@@ -144,16 +177,17 @@ jobs:
run: |
cd ansible
ansible-playbook -i localhost \
- -e "ami_release_version=${{ steps.process_release_version.outputs.version }}" \
+ -e "ami_release_version=${{ steps.arch_version.outputs.version }}" \
-e "internal_artifacts_bucket=${{ secrets.ARTIFACTS_BUCKET }}" \
-e "postgres_major_version=${{ matrix.postgres_version }}" \
+ -e "arch=${{ matrix.arch.name }}" \
manifest-playbook.yml
- name: Upload nix flake revision to s3 staging
run: |
- aws s3 cp /tmp/pg_binaries.tar.gz s3://${{ secrets.ARTIFACTS_BUCKET }}/upgrades/postgres/supabase-postgres-${{ steps.process_release_version.outputs.version }}/20.04.tar.gz
- aws s3 cp /tmp/pg_binaries.tar.gz s3://${{ secrets.ARTIFACTS_BUCKET }}/upgrades/postgres/supabase-postgres-${{ steps.process_release_version.outputs.version }}/24.04.tar.gz
- aws s3 cp /tmp/pg_binaries.tar.gz s3://${{ secrets.ARTIFACTS_BUCKET }}/upgrades/postgres/supabase-postgres-${{ steps.process_release_version.outputs.version }}/upgrade_bundle.tar.gz
+ aws s3 cp /tmp/pg_binaries.tar.gz s3://${{ secrets.ARTIFACTS_BUCKET }}/upgrades${{ steps.arch_version.outputs.arch_suffix }}/postgres/supabase-postgres-${{ steps.arch_version.outputs.version }}/20.04.tar.gz
+ aws s3 cp /tmp/pg_binaries.tar.gz s3://${{ secrets.ARTIFACTS_BUCKET }}/upgrades${{ steps.arch_version.outputs.arch_suffix }}/postgres/supabase-postgres-${{ steps.arch_version.outputs.version }}/24.04.tar.gz
+ aws s3 cp /tmp/pg_binaries.tar.gz s3://${{ secrets.ARTIFACTS_BUCKET }}/upgrades${{ steps.arch_version.outputs.arch_suffix }}/postgres/supabase-postgres-${{ steps.arch_version.outputs.version }}/upgrade_bundle.tar.gz
- name: configure aws credentials - prod
uses: aws-actions/configure-aws-credentials@7474bc4690e29a8392af63c5b98e7449536d5c3a # v4.3.1
@@ -165,16 +199,17 @@ jobs:
run: |
cd ansible
ansible-playbook -i localhost \
- -e "ami_release_version=${{ steps.process_release_version.outputs.version }}" \
+ -e "ami_release_version=${{ steps.arch_version.outputs.version }}" \
-e "internal_artifacts_bucket=${{ secrets.PROD_ARTIFACTS_BUCKET }}" \
-e "postgres_major_version=${{ matrix.postgres_version }}" \
+ -e "arch=${{ matrix.arch.name }}" \
manifest-playbook.yml
- name: Upload nix flake revision to s3 prod
run: |
- aws s3 cp /tmp/pg_binaries.tar.gz s3://${{ secrets.PROD_ARTIFACTS_BUCKET }}/upgrades/postgres/supabase-postgres-${{ steps.process_release_version.outputs.version }}/20.04.tar.gz
- aws s3 cp /tmp/pg_binaries.tar.gz s3://${{ secrets.PROD_ARTIFACTS_BUCKET }}/upgrades/postgres/supabase-postgres-${{ steps.process_release_version.outputs.version }}/24.04.tar.gz
- aws s3 cp /tmp/pg_binaries.tar.gz s3://${{ secrets.PROD_ARTIFACTS_BUCKET }}/upgrades/postgres/supabase-postgres-${{ steps.process_release_version.outputs.version }}/upgrade_bundle.tar.gz
+ aws s3 cp /tmp/pg_binaries.tar.gz s3://${{ secrets.PROD_ARTIFACTS_BUCKET }}/upgrades${{ steps.arch_version.outputs.arch_suffix }}/postgres/supabase-postgres-${{ steps.arch_version.outputs.version }}/20.04.tar.gz
+ aws s3 cp /tmp/pg_binaries.tar.gz s3://${{ secrets.PROD_ARTIFACTS_BUCKET }}/upgrades${{ steps.arch_version.outputs.arch_suffix }}/postgres/supabase-postgres-${{ steps.arch_version.outputs.version }}/24.04.tar.gz
+ aws s3 cp /tmp/pg_binaries.tar.gz s3://${{ secrets.PROD_ARTIFACTS_BUCKET }}/upgrades${{ steps.arch_version.outputs.arch_suffix }}/postgres/supabase-postgres-${{ steps.arch_version.outputs.version }}/upgrade_bundle.tar.gz
- name: GitHub OIDC Auth
uses: aws-actions/configure-aws-credentials@ececac1a45f3b08a01d2dd070d28d111c5fe6722 # v4.1.0
@@ -197,13 +232,13 @@ jobs:
VERSION="${{ steps.process_release_version.outputs.version }}"
GIT_SHA="${{ github.sha }}"
PG_VERSION="${{ matrix.postgres_version }}"
- SYSTEM="aarch64-linux"
+ SYSTEM="${{ matrix.arch.nix_system }}"
# Get store path for this build
STORE_PATH=$(nix eval --raw ".#psql_${PG_VERSION}/bin.outPath")
# Each postgres version gets its own catalog file (no race conditions)
- CATALOG_S3="s3://${{ secrets.SHARED_AWS_ARTIFACTS_BUCKET }}/nix-catalog/${GIT_SHA}-psql_${PG_VERSION}.json"
+ CATALOG_S3="s3://${{ secrets.SHARED_AWS_ARTIFACTS_BUCKET }}/nix-catalog/${GIT_SHA}-psql_${PG_VERSION}-${SYSTEM}.json"
# Create catalog JSON for this version
jq -n \
@@ -225,12 +260,12 @@ jobs:
- name: Create release
uses: softprops/action-gh-release@a06a81a03ee405af7f2048a818ed3f03bbf83c7b # v2.5.0
with:
- name: ${{ steps.process_release_version.outputs.version }}
- tag_name: ${{ steps.process_release_version.outputs.version }}
+ name: ${{ steps.arch_version.outputs.release_tag }}
+ tag_name: ${{ steps.arch_version.outputs.release_tag }}
target_commitish: ${{github.sha}}
- name: Create CLI tag for PG 17
- if: matrix.postgres_version == '17' && github.event_name != 'workflow_dispatch'
+ if: matrix.postgres_version == '17' && matrix.arch.name == 'arm64' && github.event_name != 'workflow_dispatch'
env:
GH_TOKEN: ${{ github.token }}
run: |
@@ -241,6 +276,7 @@ jobs:
git push origin "${CLI_TAG}"
- name: Trigger pg_upgrade_scripts workflow
+ if: matrix.arch.name == 'arm64'
env:
GH_TOKEN: ${{ github.token }}
run: |
@@ -249,6 +285,7 @@ jobs:
-f postgresVersion="${{ steps.process_release_version.outputs.version }}"
- name: Trigger pg_upgrade_bin flake version workflow
+ if: matrix.arch.name == 'arm64'
env:
GH_TOKEN: ${{ github.token }}
run: |
diff --git a/.github/workflows/nix-build.yml b/.github/workflows/nix-build.yml
index d1f1ea5d..f45e5d1e 100644
--- a/.github/workflows/nix-build.yml
+++ b/.github/workflows/nix-build.yml
@@ -34,7 +34,7 @@ jobs:
if: ${{ fromJSON(needs.nix-eval.outputs.packages_matrix).aarch64_linux != null }}
strategy:
fail-fast: false
- max-parallel: 5
+ max-parallel: 25
matrix: ${{ fromJSON(needs.nix-eval.outputs.packages_matrix).aarch64_linux }}
steps:
- name: Checkout Repo
@@ -66,7 +66,7 @@ jobs:
if: ${{ fromJSON(needs.nix-eval.outputs.checks_matrix).aarch64_linux != null }}
strategy:
fail-fast: false
- max-parallel: 5
+ max-parallel: 25
matrix: ${{ fromJSON(needs.nix-eval.outputs.checks_matrix).aarch64_linux }}
steps:
- name: Checkout Repo
@@ -98,7 +98,7 @@ jobs:
if: ${{ fromJSON(needs.nix-eval.outputs.packages_matrix).aarch64_darwin != null }}
strategy:
fail-fast: false
- max-parallel: 5
+ max-parallel: 25
matrix: ${{ fromJSON(needs.nix-eval.outputs.packages_matrix).aarch64_darwin }}
steps:
- name: Checkout Repo
@@ -122,7 +122,7 @@ jobs:
if: ${{ fromJSON(needs.nix-eval.outputs.checks_matrix).aarch64_darwin != null }}
strategy:
fail-fast: false
- max-parallel: 5
+ max-parallel: 25
matrix: ${{ fromJSON(needs.nix-eval.outputs.checks_matrix).aarch64_darwin }}
steps:
- name: Checkout Repo
@@ -146,7 +146,7 @@ jobs:
if: ${{ fromJSON(needs.nix-eval.outputs.packages_matrix).x86_64_linux != null }}
strategy:
fail-fast: false
- max-parallel: 5
+ max-parallel: 25
matrix: ${{ fromJSON(needs.nix-eval.outputs.packages_matrix).x86_64_linux }}
steps:
- name: Checkout Repo
@@ -175,7 +175,7 @@ jobs:
if: ${{ fromJSON(needs.nix-eval.outputs.checks_matrix).x86_64_linux != null }}
strategy:
fail-fast: false
- max-parallel: 5
+ max-parallel: 25
matrix: ${{ fromJSON(needs.nix-eval.outputs.checks_matrix).x86_64_linux }}
steps:
- name: Checkout Repo
diff --git a/amazon-amd64-nix.pkr.hcl b/amazon-amd64-nix.pkr.hcl
new file mode 100644
index 00000000..9a3476f3
--- /dev/null
+++ b/amazon-amd64-nix.pkr.hcl
@@ -0,0 +1,275 @@
+variable "ami" {
+ type = string
+ default = "ubuntu/images/hvm-ssd-gp3/ubuntu-noble-24.04-amd64-server-*"
+}
+
+variable "profile" {
+ type = string
+ default = "${env("AWS_PROFILE")}"
+}
+
+variable "ami_name" {
+ type = string
+ default = "supabase-postgres"
+}
+
+variable "ami_regions" {
+ type = list(string)
+ default = ["ap-southeast-1"]
+}
+
+variable "ansible_arguments" {
+ type = string
+ default = "--skip-tags install-postgrest,install-pgbouncer,install-supabase-internal"
+}
+
+variable "region" {
+ type = string
+}
+
+variable "build-vol" {
+ type = string
+ default = "xvdc"
+}
+
+# ccache docker image details
+variable "docker_user" {
+ type = string
+ default = ""
+}
+
+variable "docker_passwd" {
+ type = string
+ default = ""
+}
+
+variable "docker_image" {
+ type = string
+ default = ""
+}
+
+variable "docker_image_tag" {
+ type = string
+ default = "latest"
+}
+
+locals {
+ creator = "packer"
+}
+
+variable "postgres-version" {
+ type = string
+ default = ""
+}
+
+variable "git-head-version" {
+ type = string
+ default = "unknown"
+}
+
+variable "packer-execution-id" {
+ type = string
+ default = "unknown"
+}
+
+variable "force-deregister" {
+ type = bool
+ default = false
+}
+
+variable "input-hash" {
+ type = string
+ default = ""
+ description = "Content hash of all input sources"
+}
+
+packer {
+ required_plugins {
+ amazon = {
+ source = "github.com/hashicorp/amazon"
+ version = "~> 1"
+ }
+ }
+}
+
+# source block
+source "amazon-ebssurrogate" "source" {
+ profile = "${var.profile}"
+ ami_name = "${var.ami_name}-${var.postgres-version}-${var.input-hash}-stage-1"
+ ami_virtualization_type = "hvm"
+ ami_architecture = "x86_64"
+ ami_regions = "${var.ami_regions}"
+ instance_type = "c6i.4xlarge"
+ region = "${var.region}"
+ force_deregister = var.force-deregister
+
+ # Increase timeout for instance stop operations to handle large instances
+ aws_polling {
+ delay_seconds = 15
+ max_attempts = 120 # 120 * 15s = 30 minutes max wait
+ }
+
+ # Use latest official ubuntu noble ami owned by Canonical.
+ source_ami_filter {
+ filters = {
+ virtualization-type = "hvm"
+ name = "${var.ami}"
+ root-device-type = "ebs"
+ }
+ owners = [ "099720109477" ]
+ most_recent = true
+ }
+
+ ena_support = true
+ launch_block_device_mappings {
+ device_name = "/dev/xvdf"
+ delete_on_termination = true
+ volume_size = 20
+ volume_type = "gp3"
+ iops = 10000
+ throughput = 1000
+ }
+
+ # NOTE: /dev/xvdh is mounted as /data (PostgreSQL data/WAL). The 1 GiB size
+ # is a minimal default for this AMI; consumers should override this volume
+ # size at launch.
+ launch_block_device_mappings {
+ device_name = "/dev/xvdh"
+ delete_on_termination = true
+ volume_size = 1
+ volume_type = "gp3"
+ }
+
+ launch_block_device_mappings {
+ device_name = "/dev/${var.build-vol}"
+ delete_on_termination = true
+ volume_size = 20
+ volume_type = "gp3"
+ omit_from_artifact = true
+ iops = 10000 # Added for build performance
+ throughput = 1000 # Added for build performance
+ }
+
+ run_tags = {
+ creator = "packer"
+ appType = "postgres"
+ packerExecutionId = "${var.packer-execution-id}"
+ }
+ run_volume_tags = {
+ creator = "packer"
+ appType = "postgres"
+ }
+ snapshot_tags = {
+ creator = "packer"
+ appType = "postgres"
+ }
+ tags = {
+ creator = "packer"
+ appType = "postgres"
+ postgresVersion = "${var.postgres-version}-stage1"
+ sourceSha = "${var.git-head-version}"
+ inputHash = "${var.input-hash}"
+ }
+
+ communicator = "ssh"
+ ssh_pty = true
+ ssh_username = "ubuntu"
+ ssh_timeout = "5m"
+
+ ami_root_device {
+ source_device_name = "/dev/xvdf"
+ device_name = "/dev/xvda"
+ delete_on_termination = true
+ volume_size = 10
+ volume_type = "gp3"
+ }
+
+ associate_public_ip_address = true
+}
+
+# a build block invokes sources and runs provisioning steps on them.
+build {
+ sources = ["source.amazon-ebssurrogate.source"]
+
+ provisioner "file" {
+ source = "ebssurrogate/files/sources.cfg"
+ destination = "/tmp/sources.list"
+ }
+
+ provisioner "file" {
+ source = "ebssurrogate/files/ebsnvme-id"
+ destination = "/tmp/ebsnvme-id"
+ }
+
+ provisioner "file" {
+ source = "ebssurrogate/files/70-ec2-nvme-devices.rules"
+ destination = "/tmp/70-ec2-nvme-devices.rules"
+ }
+
+ provisioner "file" {
+ source = "ebssurrogate/scripts/chroot-bootstrap-nix.sh"
+ destination = "/tmp/chroot-bootstrap-nix.sh"
+ }
+
+ provisioner "file" {
+ source = "ebssurrogate/files/cloud.cfg"
+ destination = "/tmp/cloud.cfg"
+ }
+
+ provisioner "file" {
+ source = "ebssurrogate/files/vector.timer"
+ destination = "/tmp/vector.timer"
+ }
+
+ provisioner "file" {
+ source = "ebssurrogate/files/apparmor_profiles"
+ destination = "/tmp"
+ }
+
+ provisioner "file" {
+ source = "migrations"
+ destination = "/tmp"
+ }
+
+ # Copy ansible playbook
+ provisioner "shell" {
+ inline = ["mkdir /tmp/ansible-playbook"]
+ }
+
+ provisioner "file" {
+ source = "ansible"
+ destination = "/tmp/ansible-playbook"
+ }
+
+ provisioner "file" {
+ source = "scripts"
+ destination = "/tmp/ansible-playbook"
+ }
+
+ provisioner "file" {
+ source = "ansible/vars.yml"
+ destination = "/tmp/ansible-playbook/vars.yml"
+ }
+
+ provisioner "shell" {
+ environment_vars = [
+ "ARGS=${var.ansible_arguments}",
+ "DOCKER_USER=${var.docker_user}",
+ "DOCKER_PASSWD=${var.docker_passwd}",
+ "DOCKER_IMAGE=${var.docker_image}",
+ "DOCKER_IMAGE_TAG=${var.docker_image_tag}",
+ "POSTGRES_SUPABASE_VERSION=${var.postgres-version}"
+ ]
+ use_env_var_file = true
+ script = "ebssurrogate/scripts/surrogate-bootstrap-nix.sh"
+ execute_command = "sudo -S sh -c '. {{.EnvVarFile}} && cd /tmp/ansible-playbook && {{.Path}}'"
+ start_retry_timeout = "5m"
+ skip_clean = true
+ }
+
+ provisioner "file" {
+ source = "/tmp/ansible.log"
+ destination = "/tmp/ansible.log"
+ direction = "download"
+ }
+}
diff --git a/amazon-arm64-nix.pkr.hcl b/amazon-arm64-nix.pkr.hcl
index 0ff67996..a0f89974 100644
--- a/amazon-arm64-nix.pkr.hcl
+++ b/amazon-arm64-nix.pkr.hcl
@@ -122,28 +122,32 @@ source "amazon-ebssurrogate" "source" {
ena_support = true
launch_block_device_mappings {
- device_name = "/dev/xvdf"
+ device_name = "/dev/xvdf"
delete_on_termination = true
- volume_size = 10
- volume_type = "gp3"
+ volume_size = 20
+ volume_type = "gp3"
+ iops = 10000
+ throughput = 1000
}
# NOTE: /dev/xvdh is mounted as /data (PostgreSQL data/WAL). The 1 GiB size
# is a minimal default for this AMI; consumers should override this volume
# size at launch.
launch_block_device_mappings {
- device_name = "/dev/xvdh"
+ device_name = "/dev/xvdh"
delete_on_termination = true
- volume_size = 1
- volume_type = "gp3"
+ volume_size = 1
+ volume_type = "gp3"
}
launch_block_device_mappings {
device_name = "/dev/${var.build-vol}"
delete_on_termination = true
- volume_size = 16
- volume_type = "gp2"
+ volume_size = 20
+ volume_type = "gp3"
omit_from_artifact = true
+ iops = 10000 # Added for build performance
+ throughput = 1000 # Added for build performance
}
run_tags = {
@@ -173,11 +177,11 @@ source "amazon-ebssurrogate" "source" {
ssh_timeout = "5m"
ami_root_device {
- source_device_name = "/dev/xvdf"
- device_name = "/dev/xvda"
+ source_device_name = "/dev/xvdf"
+ device_name = "/dev/xvda"
delete_on_termination = true
- volume_size = 10
- volume_type = "gp2"
+ volume_size = 10
+ volume_type = "gp3"
}
associate_public_ip_address = true
diff --git a/ansible/manifest-playbook.yml b/ansible/manifest-playbook.yml
index ce02c805..b0e46722 100644
--- a/ansible/manifest-playbook.yml
+++ b/ansible/manifest-playbook.yml
@@ -4,36 +4,55 @@
vars_files:
- ./vars.yml
+ vars:
+ arch: "{{ arch | default('arm64') }}"
+ postgrest_binary: "{{ 'ubuntu-aarch64' if arch == 'arm64' else 'linux-static-x86-64' }}"
+ gotrue_arch: "{{ 'arm64' if arch == 'arm64' else 'x86' }}"
+ gotrue_checksum: "{{ gotrue_arm_release_checksum if arch == 'arm64' else gotrue_x86_release_checksum }}"
+ postgrest_checksum: "{{ postgrest_arm_release_checksum if arch == 'arm64' else postgrest_x86_release_checksum }}"
+
tasks:
- name: Write out image manifest
action: template src=files/manifest.json dest=./image-manifest-{{ ami_release_version }}.json
- name: Upload image manifest
shell: |
- aws s3 cp ./image-manifest-{{ ami_release_version }}.json s3://{{ internal_artifacts_bucket }}/manifests/postgres-{{ ami_release_version }}/software-manifest.json
+ aws s3 cp ./image-manifest-{{ ami_release_version }}.json s3://{{ internal_artifacts_bucket }}/manifests/postgres-{{ ami_release_version }}/software-manifest-{{ arch }}.json
# upload software artifacts of interest
# Generally - download, extract, repack as xz archive, upload
# currently, we upload gotrue, adminapi, postgrest
- name: gotrue - download commit archive
get_url:
- url: "https://github.com/supabase/gotrue/releases/download/v{{ gotrue_release }}/auth-v{{ gotrue_release }}-arm64.tar.gz"
- dest: /tmp/auth-v{{ gotrue_release }}-arm64.tar.gz
- checksum: "{{ gotrue_release_checksum }}"
+ url: "https://github.com/supabase/gotrue/releases/download/v{{ gotrue_release }}/auth-v{{ gotrue_release }}-{{ gotrue_arch }}.tar.gz"
+ dest: /tmp/auth-v{{ gotrue_release }}-{{ gotrue_arch }}.tar.gz
+ checksum: "{{ gotrue_checksum }}"
timeout: 60
+ register: download_result
+ until: download_result is succeeded
+ retries: 3
+ delay: 2
- name: PostgREST - download ubuntu binary archive (arm)
get_url:
- url: "https://github.com/PostgREST/postgrest/releases/download/v{{ postgrest_release }}/postgrest-v{{ postgrest_release }}-ubuntu-aarch64.tar.xz"
- dest: /tmp/postgrest-{{ postgrest_release }}-arm64.tar.xz
- checksum: "{{ postgrest_arm_release_checksum }}"
+ url: "https://github.com/PostgREST/postgrest/releases/download/v{{ postgrest_release }}/postgrest-v{{ postgrest_release }}-{{ postgrest_binary }}.tar.xz"
+ dest: /tmp/postgrest-{{ postgrest_release }}-{{ arch }}.tar.xz
+ checksum: "{{ postgrest_checksum }}"
timeout: 60
+ register: download_result
+ until: download_result is succeeded
+ retries: 3
+ delay: 2
- name: Download adminapi archive
get_url:
- url: "https://supabase-public-artifacts-bucket.s3.amazonaws.com/supabase-admin-api/v{{ adminapi_release }}/supabase-admin-api_{{ adminapi_release }}_linux_arm64.tar.gz"
+ url: "https://supabase-public-artifacts-bucket.s3.amazonaws.com/supabase-admin-api/v{{ adminapi_release }}/supabase-admin-api_{{ adminapi_release }}_linux_{{ arch }}.tar.gz"
dest: "/tmp/adminapi.tar.gz"
timeout: 90
+ register: download_result
+ until: download_result is succeeded
+ retries: 3
+ delay: 2
- name: adminapi - unpack archive in /tmp
unarchive:
@@ -43,13 +62,17 @@
- name: adminapi - pack archive
shell: |
- cd /tmp && tar -cJf supabase-admin-api-{{ adminapi_release }}-arm64.tar.xz supabase-admin-api
+ cd /tmp && tar -cJf supabase-admin-api-{{ adminapi_release }}-{{ arch }}.tar.xz supabase-admin-api
- name: Download admin-mgr archive
get_url:
- url: "https://supabase-public-artifacts-bucket.s3.amazonaws.com/admin-mgr/v{{ adminmgr_release }}/admin-mgr_{{ adminmgr_release }}_linux_arm64.tar.gz"
+ url: "https://supabase-public-artifacts-bucket.s3.amazonaws.com/admin-mgr/v{{ adminmgr_release }}/admin-mgr_{{ adminmgr_release }}_linux_{{ arch }}.tar.gz"
dest: "/tmp/admin-mgr.tar.gz"
timeout: 90
+ register: download_result
+ until: download_result is succeeded
+ retries: 3
+ delay: 2
- name: admin-mgr - unpack archive in /tmp
unarchive:
@@ -59,13 +82,17 @@
- name: admin-mgr - pack archive
shell: |
- cd /tmp && tar -cJf admin-mgr-{{ adminmgr_release }}-arm64.tar.xz admin-mgr
+ cd /tmp && tar -cJf admin-mgr-{{ adminmgr_release }}-{{ arch }}.tar.xz admin-mgr
- name: Download supabase-admin-agent archive
get_url:
- url: "https://supabase-public-artifacts-bucket.s3.amazonaws.com/supabase-admin-agent/v{{ supabase_admin_agent_release }}/supabase-admin-agent-{{ supabase_admin_agent_release }}-linux-arm64.tar.gz"
+ url: "https://supabase-public-artifacts-bucket.s3.amazonaws.com/supabase-admin-agent/v{{ supabase_admin_agent_release }}/supabase-admin-agent-{{ supabase_admin_agent_release }}-linux-{{ arch }}.tar.gz"
dest: "/tmp/supabase-admin-agent.tar.gz"
timeout: 90
+ register: download_result
+ until: download_result is succeeded
+ retries: 3
+ delay: 2
- name: supabase-admin-agent - unpack archive in /tmp
unarchive:
@@ -75,19 +102,19 @@
- name: supabase-admin-agent - pack archive
shell: |
- cd /tmp && tar -cJf supabase-admin-agent-{{ supabase_admin_agent_release }}-arm64.tar.xz supabase-admin-agent-{{ supabase_admin_agent_release }}-linux-arm64
+ cd /tmp && tar -cJf supabase-admin-agent-{{ supabase_admin_agent_release }}-{{ arch }}.tar.xz supabase-admin-agent-{{ supabase_admin_agent_release }}-linux-{{ arch }}
- name: upload archives
shell: |
aws s3 cp /tmp/{{ item.file }} s3://{{ internal_artifacts_bucket }}/upgrades/{{ item.service }}/{{ item.file }}
with_items:
- service: gotrue
- file: auth-v{{ gotrue_release }}-arm64.tar.gz
+ file: auth-v{{ gotrue_release }}-{{ gotrue_arch }}.tar.gz
- service: postgrest
- file: postgrest-{{ postgrest_release }}-arm64.tar.xz
+ file: postgrest-{{ postgrest_release }}-{{ arch }}.tar.xz
- service: supabase-admin-api
- file: supabase-admin-api-{{ adminapi_release }}-arm64.tar.xz
+ file: supabase-admin-api-{{ adminapi_release }}-{{ arch }}.tar.xz
- service: admin-mgr
- file: admin-mgr-{{ adminmgr_release }}-arm64.tar.xz
+ file: admin-mgr-{{ adminmgr_release }}-{{ arch }}.tar.xz
- service: supabase-admin-agent
- file: supabase-admin-agent-{{ supabase_admin_agent_release }}-arm64.tar.xz
+ file: supabase-admin-agent-{{ supabase_admin_agent_release }}-{{ arch }}.tar.xz
diff --git a/ansible/playbook.yml b/ansible/playbook.yml
index f2d5b683..73db87d7 100644
--- a/ansible/playbook.yml
+++ b/ansible/playbook.yml
@@ -236,7 +236,7 @@
become: yes
shell: |
/bin/bash /tmp/ansible-playbook/ansible/files/supascan_ami.sh /tmp/ansible-playbook/audit-specs/baselines/ami-build
- when: stage2_nix and qemu_mode is not defined
+ when: stage2_nix and qemu_mode is not defined and ansible_architecture != "x86_64"
- name: Remove supascan after validation
become: yes
diff --git a/ansible/tasks/internal/admin-api.yml b/ansible/tasks/internal/admin-api.yml
index 1770433e..0c8e4020 100644
--- a/ansible/tasks/internal/admin-api.yml
+++ b/ansible/tasks/internal/admin-api.yml
@@ -27,9 +27,9 @@
shell: |
chmod g+w /etc
-- name: Setting arch (x86)
+- name: Setting arch (amd64)
set_fact:
- arch: "x86"
+ arch: "amd64"
when: platform == "amd64"
- name: Setting arch (arm)
diff --git a/ansible/tasks/internal/admin-mgr.yml b/ansible/tasks/internal/admin-mgr.yml
index 073b8661..46a1231c 100644
--- a/ansible/tasks/internal/admin-mgr.yml
+++ b/ansible/tasks/internal/admin-mgr.yml
@@ -13,6 +13,10 @@
url: "https://supabase-public-artifacts-bucket.s3.amazonaws.com/admin-mgr/v{{ adminmgr_release }}/admin-mgr_{{ adminmgr_release }}_linux_{{ arch }}.tar.gz"
dest: "/tmp/admin-mgr.tar.gz"
timeout: 90
+ register: download_result
+ until: download_result is succeeded
+ retries: 3
+ delay: 2
- name: admin-mgr - unpack archive in /usr/bin/
unarchive:
diff --git a/ansible/tasks/internal/install-salt.yml b/ansible/tasks/internal/install-salt.yml
index 73cd6ee8..9ebbd26b 100644
--- a/ansible/tasks/internal/install-salt.yml
+++ b/ansible/tasks/internal/install-salt.yml
@@ -11,6 +11,10 @@
url: https://packages.broadcom.com/artifactory/api/security/keypair/SaltProjectKey/public
dest: /etc/apt/keyrings/salt-archive-keyring-2023.pgp
mode: '0644'
+ register: download_result
+ until: download_result is succeeded
+ retries: 3
+ delay: 2
- name: salt apt repo
ansible.builtin.apt_repository:
@@ -32,6 +36,10 @@
url: https://packages.broadcom.com/artifactory/api/security/keypair/SaltProjectKey/public
dest: /etc/apt/keyrings/salt-archive-keyring-2023.pgp
mode: '0644'
+ register: download_result
+ until: download_result is succeeded
+ retries: 3
+ delay: 2
- name: salt apt repo
ansible.builtin.apt_repository:
diff --git a/ansible/tasks/internal/postgres-exporter.yml b/ansible/tasks/internal/postgres-exporter.yml
index 0292157b..29dc896e 100644
--- a/ansible/tasks/internal/postgres-exporter.yml
+++ b/ansible/tasks/internal/postgres-exporter.yml
@@ -26,6 +26,10 @@
dest: /tmp/postgres_exporter.tar.gz
checksum: "{{ postgres_exporter_release_checksum[platform] }}"
timeout: 60
+ register: download_result
+ until: download_result is succeeded
+ retries: 3
+ delay: 2
- name: expand postgres exporter
unarchive:
diff --git a/ansible/tasks/internal/setup-ansible-pull.yml b/ansible/tasks/internal/setup-ansible-pull.yml
index 7cce74a8..06559e28 100644
--- a/ansible/tasks/internal/setup-ansible-pull.yml
+++ b/ansible/tasks/internal/setup-ansible-pull.yml
@@ -2,7 +2,8 @@
shell:
cmd: |
apt install -y software-properties-common
- add-apt-repository --yes --update ppa:ansible/ansible
+ # TODO (darora): temporarily disabling while Launchpad is under ddos attack and very frequently timing out
+ # add-apt-repository --yes --update ppa:ansible/ansible
apt install -y ansible
sed -i -e 's/#callback_whitelist.*/callback_whitelist = profile_tasks/' /etc/ansible/ansible.cfg
diff --git a/ansible/tasks/internal/supabase-admin-agent.yml b/ansible/tasks/internal/supabase-admin-agent.yml
index 0dfc4427..6ac42d76 100644
--- a/ansible/tasks/internal/supabase-admin-agent.yml
+++ b/ansible/tasks/internal/supabase-admin-agent.yml
@@ -31,9 +31,9 @@
dest: /etc/sudoers.d/supabase-admin-agent
mode: "0440"
-- name: Setting arch (x86)
+- name: Setting arch (amd64)
set_fact:
- arch: "x86"
+ arch: "amd64"
when: platform == "amd64"
- name: Setting arch (arm)
@@ -53,6 +53,10 @@
url: "https://supabase-public-artifacts-bucket.s3.amazonaws.com/supabase-admin-agent/v{{ supabase_admin_agent_release }}/supabase-admin-agent-{{ supabase_admin_agent_release }}-linux-{{ arch }}.tar.gz"
dest: "/tmp/supabase-admin-agent.tar.gz"
timeout: 90
+ register: download_result
+ until: download_result is succeeded
+ retries: 3
+ delay: 2
- name: supabase-admin-agent - unpack archive in /opt
unarchive:
diff --git a/ansible/tasks/internal/supautils.yml b/ansible/tasks/internal/supautils.yml
index 33811b5a..dc8866eb 100644
--- a/ansible/tasks/internal/supautils.yml
+++ b/ansible/tasks/internal/supautils.yml
@@ -13,6 +13,10 @@
dest: /tmp/supautils-{{ supautils_release }}.tar.gz
checksum: "{{ supautils_release_checksum }}"
timeout: 60
+ register: download_result
+ until: download_result is succeeded
+ retries: 3
+ delay: 2
- name: supautils - unpack archive
unarchive:
diff --git a/ansible/tasks/setup-envoy.yml b/ansible/tasks/setup-envoy.yml
index 1552393e..7901cd63 100644
--- a/ansible/tasks/setup-envoy.yml
+++ b/ansible/tasks/setup-envoy.yml
@@ -5,13 +5,17 @@
- name: Envoy - download binary
ansible.builtin.get_url:
- checksum: "{{ envoy_release_checksum }}"
+ checksum: "{{ envoy_arm_release_checksum if platform == 'arm64' else envoy_x86_release_checksum }}"
dest: '/opt/envoy'
group: 'envoy'
mode: '0700'
owner: 'envoy'
# yamllint disable-line rule:line-length
- url: "https://github.com/envoyproxy/envoy/releases/download/v{{ envoy_release }}/envoy-{{ envoy_release }}-linux-aarch_64"
+ url: "https://github.com/envoyproxy/envoy/releases/download/v{{ envoy_release }}/envoy-{{ envoy_release }}-linux-{{ 'aarch_64' if platform == 'arm64' else 'x86_64' }}"
+ register: download_result
+ until: download_result is succeeded
+ retries: 3
+ delay: 2
- name: Envoy - download hot restarter script
ansible.builtin.get_url:
@@ -22,6 +26,10 @@
owner: 'envoy'
# yamllint disable-line rule:line-length
url: "https://raw.githubusercontent.com/envoyproxy/envoy/v{{ envoy_release }}/restarter/hot-restarter.py"
+ register: download_result
+ until: download_result is succeeded
+ retries: 3
+ delay: 2
- name: Envoy - bump up ulimit
community.general.pam_limits:
diff --git a/ansible/tasks/setup-gotrue.yml b/ansible/tasks/setup-gotrue.yml
index 70bbbf85..940ce60d 100644
--- a/ansible/tasks/setup-gotrue.yml
+++ b/ansible/tasks/setup-gotrue.yml
@@ -20,9 +20,13 @@
- name: gotrue - download commit archive
ansible.builtin.get_url:
- checksum: "{{ gotrue_release_checksum }}"
+ checksum: "{{ gotrue_arm_release_checksum if platform == 'arm64' else gotrue_x86_release_checksum }}"
dest: '/tmp/gotrue.tar.gz'
url: "https://github.com/supabase/gotrue/releases/download/v{{ gotrue_release }}/auth-v{{ gotrue_release }}-{{ arch }}.tar.gz"
+ register: download_result
+ until: download_result is succeeded
+ retries: 3
+ delay: 2
- name: gotrue - create /opt/gotrue and /etc/auth.d
ansible.builtin.file:
diff --git a/ansible/tasks/setup-kong.yml b/ansible/tasks/setup-kong.yml
index 22a34897..1908481f 100644
--- a/ansible/tasks/setup-kong.yml
+++ b/ansible/tasks/setup-kong.yml
@@ -14,9 +14,13 @@
- name: Kong - download deb package
get_url:
- checksum: "{{ kong_deb_checksum }}"
+ checksum: "{{ kong_deb_checksum[platform] }}"
dest: '/tmp/kong.deb'
- url: "https://packages.konghq.com/public/gateway-28/deb/ubuntu/pool/{{ kong_release_target }}/main/k/ko/kong_2.8.1/{{ kong_deb }}"
+ url: "https://packages.konghq.com/public/gateway-28/deb/ubuntu/pool/{{ kong_release_target }}/main/k/ko/kong_2.8.1/{{ kong_deb[platform] }}"
+ register: download_result
+ until: download_result is succeeded
+ retries: 3
+ delay: 2
- name: Kong - deb installation
ansible.builtin.apt:
diff --git a/ansible/tasks/setup-nginx.yml b/ansible/tasks/setup-nginx.yml
index 1f10ceec..8dda21e7 100644
--- a/ansible/tasks/setup-nginx.yml
+++ b/ansible/tasks/setup-nginx.yml
@@ -17,6 +17,10 @@
checksum: "{{ nginx_release_checksum }}"
dest: '/tmp/nginx-{{ nginx_release }}.tar.gz'
url: "https://nginx.org/download/nginx-{{ nginx_release }}.tar.gz"
+ register: download_result
+ until: download_result is succeeded
+ retries: 3
+ delay: 2
- name: nginx - unpack archive
ansible.builtin.unarchive:
diff --git a/ansible/tasks/setup-pgbouncer.yml b/ansible/tasks/setup-pgbouncer.yml
index 06925c6a..16cdfbb3 100644
--- a/ansible/tasks/setup-pgbouncer.yml
+++ b/ansible/tasks/setup-pgbouncer.yml
@@ -17,6 +17,10 @@
dest: "/tmp/pgbouncer-{{ pgbouncer_release }}.tar.gz"
timeout: 60
url: "https://www.pgbouncer.org/downloads/files/{{ pgbouncer_release }}/pgbouncer-{{ pgbouncer_release }}.tar.gz"
+ register: download_result
+ until: download_result is succeeded
+ retries: 3
+ delay: 2
- name: PgBouncer - unpack archive
ansible.builtin.unarchive:
diff --git a/ansible/tasks/setup-postgrest.yml b/ansible/tasks/setup-postgrest.yml
index 13cea264..2fd001fa 100644
--- a/ansible/tasks/setup-postgrest.yml
+++ b/ansible/tasks/setup-postgrest.yml
@@ -9,6 +9,12 @@
force: true
mode: '0644'
url: 'https://www.postgresql.org/media/keys/ACCC4CF8.asc'
+ timeout: 60
+ validate_certs: true
+ register: pgdg_key_download
+ retries: 6
+ delay: 2
+ until: pgdg_key_download is succeeded
- name: PostgREST - add Postgres PPA main
ansible.builtin.apt_repository:
@@ -51,10 +57,14 @@
- name: PostgREST - download ubuntu binary archive (arm)
ansible.builtin.get_url:
- checksum: "{{ postgrest_arm_release_checksum }}"
+ checksum: "{{ postgrest_arm_release_checksum if platform == 'arm64' else postgrest_x86_release_checksum }}"
dest: '/tmp/postgrest.tar.xz'
timeout: 60
url: "https://github.com/PostgREST/postgrest/releases/download/v{{ postgrest_release }}/postgrest-v{{ postgrest_release }}-{{ download_binary }}.tar.xz"
+ register: download_result
+ until: download_result is succeeded
+ retries: 3
+ delay: 2
vars:
download_binary: >-
{%- if platform == "arm64" -%}
diff --git a/ansible/tasks/setup-supabase-internal.yml b/ansible/tasks/setup-supabase-internal.yml
index 00007ecd..2427470e 100644
--- a/ansible/tasks/setup-supabase-internal.yml
+++ b/ansible/tasks/setup-supabase-internal.yml
@@ -10,6 +10,10 @@
dest: '/tmp/awscliv2.zip'
timeout: 60
url: "https://awscli.amazonaws.com/awscli-exe-linux-{{ 'aarch64' if platform == 'arm64' else 'x86_64' }}-{{ aws_cli_release }}.zip"
+ register: download_result
+ until: download_result is succeeded
+ retries: 3
+ delay: 2
- name: AWS CLI - expand
@@ -40,7 +44,7 @@
timeout: 120
become: true
retries: 3
- delay: 10
+ delay: 2
register: vector_download
until: vector_download is success
diff --git a/ansible/vars.yml b/ansible/vars.yml
index c2be6ac1..ab150f6e 100644
--- a/ansible/vars.yml
+++ b/ansible/vars.yml
@@ -10,9 +10,9 @@ postgres_major:
# Full version strings for each major version
postgres_release:
- postgresorioledb-17: "17.6.0.070-orioledb"
- postgres17: "17.6.1.113"
- postgres15: "15.14.1.113"
+ postgresorioledb-17: "17.6.0.071"
+ postgres17: "17.6.1.114"
+ postgres15: "15.14.1.114"
# Non Postgres Extensions
pgbouncer_release: 1.25.1
@@ -27,6 +27,8 @@ postgrest_x86_release_checksum: sha256:ab5cc7e974d4940447991804588cfb8b3f7b2c57b
gotrue_release: 2.188.1
gotrue_release_checksum: sha1:236e8c7bb93e1246b3ff31dbda0fbebe6c3114ca
+gotrue_arm_release_checksum: sha1:236e8c7bb93e1246b3ff31dbda0fbebe6c3114ca
+gotrue_x86_release_checksum: sha1:b7a6d2c3cb32358710db919f1178569ec19590f0
aws_cli_release: 2.23.11
@@ -38,12 +40,17 @@ golang_version_checksum:
amd64: sha256:9ebfcab26801fa4cf0627c6439db7a4da4d3c6766142a3dd83508240e4f21031
envoy_release: 1.28.0
-envoy_release_checksum: sha1:b0a06e9cfb170f1993f369beaa5aa9d7ec679ce5
+envoy_arm_release_checksum: sha256:eb930e32ab5555643e09d11d490e392d0a790c5a80eb0b0ebacb1046bdbb114d
+envoy_x86_release_checksum: sha256:2639563ce9bc09b1ee6bd4731760b596c8ed1e474cdd83cc9df9364516e14367
envoy_hot_restarter_release_checksum: sha1:6d43b89d266fb2427a4b51756b649883b0617eda
kong_release_target: focal
-kong_deb: kong_2.8.1_arm64.deb
-kong_deb_checksum: sha1:2086f6ccf8454fe64435252fea4d29d736d7ec61
+kong_deb:
+ arm64: kong_2.8.1_arm64.deb
+ amd64: kong_2.8.1_amd64.deb
+kong_deb_checksum:
+ arm64: sha1:2086f6ccf8454fe64435252fea4d29d736d7ec61
+ amd64: sha1:7346d558a467f05d9ed63675b59f974300647e9f
nginx_release: 1.22.0
nginx_release_checksum: sha1:419efb77b80f165666e2ee406ad8ae9b845aba93
@@ -53,7 +60,7 @@ postgres_exporter_release_checksum:
arm64: sha256:29ba62d538b92d39952afe12ee2e1f4401250d678ff4b354ff2752f4321c87a0
amd64: sha256:cb89fc5bf4485fb554e0d640d9684fae143a4b2d5fa443009bd29c59f9129e84
-adminapi_release: "0.95.1"
+adminapi_release: "0.100.2"
adminmgr_release: "0.32.3"
supabase_admin_agent_release: 1.8.0
supabase_admin_agent_splay: 30s
diff --git a/development-x86.vars.pkr.hcl b/development-x86.vars.pkr.hcl
new file mode 100644
index 00000000..9167010c
--- /dev/null
+++ b/development-x86.vars.pkr.hcl
@@ -0,0 +1,5 @@
+arch = "amd64"
+ami_regions = ["ap-southeast-1"]
+environment = "dev"
+instance-type = "c6i.4xlarge"
+region = "ap-southeast-1"
diff --git a/ebssurrogate/scripts/chroot-bootstrap-nix.sh b/ebssurrogate/scripts/chroot-bootstrap-nix.sh
index bb9da1b8..3a58d73b 100755
--- a/ebssurrogate/scripts/chroot-bootstrap-nix.sh
+++ b/ebssurrogate/scripts/chroot-bootstrap-nix.sh
@@ -31,7 +31,11 @@ fi
# Get current mirror from sources.list
function get_current_mirror {
- grep -oP 'http://[^/]+(?=/ubuntu-ports/)' /etc/apt/sources.list | head -1 || echo ""
+ if [ "${ARCH}" = "amd64" ]; then
+ grep -oP 'https?://[^/]+(?=/ubuntu/)' /etc/apt/sources.list | head -1 || echo ""
+ else
+ grep -oP 'http://[^/]+(?=/ubuntu-ports/)' /etc/apt/sources.list | head -1 || echo ""
+ fi
}
# Switch to a different mirror
@@ -40,7 +44,11 @@ function switch_mirror {
local sources_file="/etc/apt/sources.list"
echo "Switching to mirror: ${new_mirror}"
- sed -i "s|http://[^/]*/ubuntu-ports/|http://${new_mirror}/ubuntu-ports/|g" "${sources_file}"
+ if [ "${ARCH}" = "amd64" ]; then
+ sed -i "s|http://[^/]*/ubuntu/|http://${new_mirror}/ubuntu/|g" "${sources_file}"
+ else
+ sed -i "s|http://[^/]*/ubuntu-ports/|http://${new_mirror}/ubuntu-ports/|g" "${sources_file}"
+ fi
# Show what we're using
echo "Current sources.list configuration:"
@@ -50,8 +58,6 @@ function switch_mirror {
# Get list of mirrors to try
function get_mirror_list {
local sources_file="/etc/apt/sources.list"
- local current_region=$(grep -oP '(?<=http://)[^.]+(?=\.clouds\.ports\.ubuntu\.com)' "${sources_file}" | head -1 || echo "")
-
local -a mirrors=()
# Priority order:
@@ -59,16 +65,28 @@ function get_mirror_list {
# 2. Regional CDN (can be inconsistent)
# 3. Global fallback
- # Singapore country mirror for ap-southeast-1
- if [ "${current_region}" = "ap-southeast-1" ]; then
- mirrors+=("sg.ports.ubuntu.com")
- fi
+ if [ "${ARCH}" = "amd64" ]; then
+ local current_region=$(grep -oP '(?<=http://)[^.]+(?=\.ec2\.archive\.ubuntu\.com)' "${sources_file}" | head -1 || echo "")
- if [ -n "${current_region}" ]; then
- mirrors+=("${current_region}.clouds.ports.ubuntu.com")
- fi
+ if [ -n "${current_region}" ]; then
+ mirrors+=("${current_region}.ec2.archive.ubuntu.com")
+ fi
- mirrors+=("ports.ubuntu.com")
+ mirrors+=("archive.ubuntu.com")
+ else
+ local current_region=$(grep -oP '(?<=http://)[^.]+(?=\.clouds\.ports\.ubuntu\.com)' "${sources_file}" | head -1 || echo "")
+
+ # Singapore country mirror for ap-southeast-1
+ if [ "${current_region}" = "ap-southeast-1" ]; then
+ mirrors+=("sg.ports.ubuntu.com")
+ fi
+
+ if [ -n "${current_region}" ]; then
+ mirrors+=("${current_region}.clouds.ports.ubuntu.com")
+ fi
+
+ mirrors+=("ports.ubuntu.com")
+ fi
echo "${mirrors[@]}"
}
@@ -250,6 +268,11 @@ function update_install_packages {
echo "FATAL: Failed to install arm64 boot packages"
exit 1
fi
+ else
+ if ! apt_install_with_fallback $APT_OPTIONS --yes install initramfs-tools; then
+ echo "FATAL: Failed to install amd64 boot packages"
+ exit 1
+ fi
fi
}
@@ -308,7 +331,7 @@ function setup_apparmor {
cp -rv /tmp/apparmor_profiles/* /etc/apparmor.d/
}
-function setup_grub_conf_arm64 {
+function setup_grub_conf {
cat << EOF > /etc/default/grub
GRUB_DEFAULT=0
GRUB_TIMEOUT=0
@@ -320,12 +343,12 @@ EOF
# Install GRUB
function install_configure_grub {
+ setup_grub_conf
if [ "${ARCH}" = "arm64" ]; then
if ! apt_install_with_fallback $APT_OPTIONS --yes install cloud-guest-utils fdisk grub-efi-arm64 efibootmgr; then
echo "FATAL: Failed to install grub packages for arm64"
exit 1
fi
- setup_grub_conf_arm64
rm -rf /etc/grub.d/30_os-prober
sleep 1
fi
diff --git a/ebssurrogate/scripts/qemu-bootstrap-nix.sh b/ebssurrogate/scripts/qemu-bootstrap-nix.sh
index 0a83c21b..43e1d98f 100755
--- a/ebssurrogate/scripts/qemu-bootstrap-nix.sh
+++ b/ebssurrogate/scripts/qemu-bootstrap-nix.sh
@@ -22,13 +22,15 @@ function waitfor_boot_finished {
}
function install_packages {
- apt-get update && sudo apt-get install software-properties-common e2fsprogs nfs-common locales iptables arptables ebtables ufw logrotate -y
- add-apt-repository --yes --update ppa:ansible/ansible && sudo apt-get install ansible -y
+ apt-get update && sudo apt-get install software-properties-common e2fsprogs nfs-common locales iptables arptables ebtables ufw logrotate -y
+ # TODO (darora): temporarily disabling while Launchpad is under ddos attack and very frequently timing out
+ # add-apt-repository --yes --update ppa:ansible/ansible &&
+ sudo apt-get install ansible -y
ansible-galaxy collection install community.general
}
function execute_playbook {
-
+ sudo mkdir -p /etc/ansible
tee /etc/ansible/ansible.cfg <<EOF
[defaults]
callbacks_enabled = timer, profile_tasks, profile_roles
@@ -93,6 +95,7 @@ EXTRA_NIX_CONF" -s /bin/bash root
}
function execute_stage2_playbook {
+ sudo mkdir -p /etc/ansible
sudo tee /etc/ansible/ansible.cfg <<EOF
[defaults]
callbacks_enabled = timer, profile_tasks, profile_roles
diff --git a/ebssurrogate/scripts/surrogate-bootstrap-nix.sh b/ebssurrogate/scripts/surrogate-bootstrap-nix.sh
index a3c79ae1..cf804bf5 100755
--- a/ebssurrogate/scripts/surrogate-bootstrap-nix.sh
+++ b/ebssurrogate/scripts/surrogate-bootstrap-nix.sh
@@ -29,14 +29,22 @@ function apt_update_with_fallback {
fi
# Define mirror tiers (in priority order)
- local -a mirror_tiers=(
- "${REGION}.clouds.ports.ubuntu.com" # Tier 1: Regional CDN
- "ports.ubuntu.com" # Tier 2: Global pool
- )
+ local -a mirror_tiers=()
+ if [ "${ARCH}" = "amd64" ]; then
+ if [ -n "${REGION}" ]; then
+ mirror_tiers+=("${REGION}.ec2.archive.ubuntu.com")
+ fi
+ mirror_tiers+=("archive.ubuntu.com")
+ else
+ if [ -n "${REGION}" ]; then
+ mirror_tiers+=("${REGION}.clouds.ports.ubuntu.com")
+ fi
+ mirror_tiers+=("ports.ubuntu.com")
+ fi
# If we couldn't get REGION, skip tier 1
if [ -z "${REGION}" ]; then
- echo "Warning: Could not determine EC2 region, skipping regional CDN"
+ echo "Warning: Could not determine EC2 region, skipping regional mirror"
mirror_tiers=("${mirror_tiers[@]:1}") # Remove first element
fi
@@ -47,10 +55,12 @@ function apt_update_with_fallback {
echo "========================================="
# Update sources.list to use current mirror
- # Replace the region-specific mirror URL
- sed -i "s|http://[^/]*/ubuntu-ports/|http://${mirror}/ubuntu-ports/|g" "${sources_file}"
- # Also update any security sources
- sed -i "s|http://ports.ubuntu.com/ubuntu-ports|http://${mirror}/ubuntu-ports|g" "${sources_file}"
+ if [ "${ARCH}" = "amd64" ]; then
+ sed -i "s|http://[^/]*/ubuntu/|http://${mirror}/ubuntu/|g" "${sources_file}"
+ else
+ sed -i "s|http://[^/]*/ubuntu-ports/|http://${mirror}/ubuntu-ports/|g" "${sources_file}"
+ sed -i "s|http://ports.ubuntu.com/ubuntu-ports|http://${mirror}/ubuntu-ports|g" "${sources_file}"
+ fi
# Show what we're using
echo "Current sources.list configuration:"
@@ -109,7 +119,8 @@ function install_packages {
fi
sudo apt-get install software-properties-common -y
- add-apt-repository --yes --update ppa:ansible/ansible
+ # TODO (darora): temporarily disabling while Launchpad is under ddos attack and very frequently timing out
+ # add-apt-repository --yes --update ppa:ansible/ansible
if ! apt_update_with_fallback; then
echo "FATAL: Failed to update package lists after adding Ansible PPA"
@@ -119,12 +130,6 @@ function install_packages {
sudo apt-get install ansible -y
ansible-galaxy collection install community.general
- # Update apt and install required packages
- if ! apt_update_with_fallback; then
- echo "FATAL: Failed to update package lists before installing tools"
- exit 1
- fi
-
apt-get install -y \
gdisk \
e2fsprogs \
@@ -228,31 +233,51 @@ function pull_docker {
# Create fstab
function create_fstab {
FMT="%-42s %-11s %-5s %-17s %-5s %s"
-cat > "/mnt/etc/fstab" << EOF
-$(printf "${FMT}" "# DEVICE UUID" "MOUNTPOINT" "TYPE" "OPTIONS" "DUMP" "FSCK")
-$(findmnt -no SOURCE /mnt | xargs blkid -o export | awk -v FMT="${FMT}" '/^UUID=/ { printf(FMT, $0, "/", "ext4", "defaults,discard", "0", "1" ) }')
-$(findmnt -no SOURCE /mnt/boot/efi | xargs blkid -o export | awk -v FMT="${FMT}" '/^UUID=/ { printf(FMT, $0, "/boot/efi", "vfat", "umask=0077", "0", "1" ) }')
-$(findmnt -no SOURCE /mnt/data | xargs blkid -o export | awk -v FMT="${FMT}" '/^UUID=/ { printf(FMT, $0, "/data", "ext4", "defaults,discard,nofail,x-systemd.device-timeout=5s", "0", "2" ) }')
-$(printf "$FMT" "/swapfile" "none" "swap" "sw" "0" "0")
-EOF
+ local ROOT_LINE=$(findmnt -no SOURCE /mnt | xargs blkid -o export | awk -v FMT="${FMT}" '/^UUID=/ { printf(FMT, $0, "/", "ext4", "defaults,discard", "0", "1" ) }')
+ local DATA_LINE=$(findmnt -no SOURCE /mnt/data | xargs blkid -o export | awk -v FMT="${FMT}" '/^UUID=/ { printf(FMT, $0, "/data", "ext4", "defaults,discard,nofail,x-systemd.device-timeout=5s", "0", "2" ) }')
+ local SWAP_LINE=$(printf "$FMT" "/swapfile" "none" "swap" "sw" "0" "0")
+
+ local EFI_LINE=""
+ if [ "${ARCH}" = "arm64" ]; then
+ EFI_LINE=$(findmnt -no SOURCE /mnt/boot/efi | xargs blkid -o export | awk -v FMT="${FMT}" '/^UUID=/ { printf(FMT, $0, "/boot/efi", "vfat", "umask=0077", "0", "1" ) }')
+ fi
+
+ {
+ printf "${FMT}\n" "# DEVICE UUID" "MOUNTPOINT" "TYPE" "OPTIONS" "DUMP" "FSCK"
+ echo "${ROOT_LINE}"
+ [ -n "${EFI_LINE}" ] && echo "${EFI_LINE}"
+ echo "${DATA_LINE}"
+ echo "${SWAP_LINE}"
+ } > "/mnt/etc/fstab"
unset FMT
}
function setup_chroot_environment {
UBUNTU_VERSION=$(lsb_release -cs) # 'noble' for Ubuntu 24.04
+ # sometimes debootstrap will get stuck on a download for a long time
+ # the default read timeout in wget is 900s, which can cause a ~15min increase in build time
+ # this forces the process to fail-fast and retry
+ cat <<EOF > ~/.wgetrc
+read_timeout = 30
+timeout = 35
+tries = 5
+EOF
+
# Update ec2-region
REGION=$(curl --silent --fail http://169.254.169.254/latest/meta-data/placement/availability-zone | sed -E 's|[a-z]+$||g')
- # Bootstrap Ubuntu into /mnt using the regional mirror (avoids global ports.ubuntu.com stalls)
- debootstrap --arch ${ARCH} --variant=minbase "$UBUNTU_VERSION" /mnt "http://${REGION}.clouds.ports.ubuntu.com/ubuntu-ports"
+ # Bootstrap Ubuntu into /mnt using the regional mirror (avoids global mirror stalls)
+ if [ "${ARCH}" = "amd64" ]; then
+ debootstrap --arch ${ARCH} --variant=minbase "$UBUNTU_VERSION" /mnt "http://${REGION}.ec2.archive.ubuntu.com/ubuntu"
+ else
+ debootstrap --arch ${ARCH} --variant=minbase "$UBUNTU_VERSION" /mnt "http://${REGION}.clouds.ports.ubuntu.com/ubuntu-ports"
+ fi
sed -i "s/REGION/${REGION}/g" /tmp/sources.list
cp /tmp/sources.list /mnt/etc/apt/sources.list
- if [ "${ARCH}" = "arm64" ]; then
- create_fstab
- fi
+ create_fstab
# Create mount points and mount the filesystem
mkdir -p /mnt/{dev,proc,sys}
@@ -304,10 +329,11 @@ function download_ccache {
}
function execute_playbook {
-
+ sudo mkdir -p /etc/ansible
tee /etc/ansible/ansible.cfg <<EOF
[defaults]
callbacks_enabled = timer, profile_tasks, profile_roles
+pipelining = True
EOF
# Run Ansible playbook
#export ANSIBLE_LOG_PATH=/tmp/ansible.log && export ANSIBLE_DEBUG=True && export ANSIBLE_REMOTE_TEMP=/mnt/tmp
diff --git a/nix/packages/build-ami.nix b/nix/packages/build-ami.nix
index 980223fd..c847f47a 100644
--- a/nix/packages/build-ami.nix
+++ b/nix/packages/build-ami.nix
@@ -19,6 +19,7 @@ let
(root + "/ansible")
(root + "/migrations")
(root + "/scripts")
+ (root + "/amazon-amd64-nix.pkr.hcl")
(root + "/amazon-arm64-nix.pkr.hcl")
(root + "/development-arm.vars.pkr.hcl")
(lib.fileset.maybeMissing (root + "/common-nix.vars.pkr.hcl"))
@@ -111,7 +112,7 @@ writeShellApplication {
echo "No cached AMI found"
cd "$PACKER_SOURCES"
- packer init amazon-arm64-nix.pkr.hcl
+ packer init "$@"
packer build \
-var-file="development-arm.vars.pkr.hcl" \
-var "input-hash=$INPUT_HASH" \
diff --git a/scripts/90-cleanup-qemu.sh b/scripts/90-cleanup-qemu.sh
index e6a58500..ef21aae1 100644
--- a/scripts/90-cleanup-qemu.sh
+++ b/scripts/90-cleanup-qemu.sh
@@ -38,7 +38,7 @@ elif [ -n "$(command -v apt-get)" ]; then
ansible \
snapd
- add-apt-repository --yes --remove ppa:ansible/ansible
+ # add-apt-repository --yes --remove ppa:ansible/ansible
source /etc/os-release
diff --git a/scripts/90-cleanup.sh b/scripts/90-cleanup.sh
index 644e5f7f..ecb63a8d 100644
--- a/scripts/90-cleanup.sh
+++ b/scripts/90-cleanup.sh
@@ -36,7 +36,7 @@ elif [ -n "$(command -v apt-get)" ]; then
libgcc-9-dev \
ansible
- add-apt-repository --yes --remove ppa:ansible/ansible
+ # add-apt-repository --yes --remove ppa:ansible/ansible
source /etc/os-release
diff --git a/scripts/nix-provision.sh b/scripts/nix-provision.sh
index 755ec190..dfca0326 100644
--- a/scripts/nix-provision.sh
+++ b/scripts/nix-provision.sh
@@ -18,8 +18,9 @@ function install_packages {
sudo apt-key adv --keyserver hkp://keyserver.ubuntu.com:80 --recv-keys 93C4A3FD7BB9C367
# Add repository and install
- sudo add-apt-repository --yes ppa:ansible/ansible
- sudo apt-get update
+ # TODO (darora): temporarily disabling while Launchpad is under ddos attack and very frequently timing out
+ # sudo add-apt-repository --yes ppa:ansible/ansible
+ # sudo apt-get update
sudo apt-get install -y ansible
ansible-galaxy collection install community.general
@@ -42,6 +43,7 @@ EXTRA_NIX_CONF" -s /bin/bash root
function execute_stage2_playbook {
echo "POSTGRES_MAJOR_VERSION: ${POSTGRES_MAJOR_VERSION}"
echo "GIT_SHA: ${GIT_SHA}"
+ sudo mkdir -p /etc/ansible
sudo tee /etc/ansible/ansible.cfg <<EOF
[defaults]
callbacks_enabled = timer, profile_tasks, profile_roles
@@ -62,7 +64,7 @@ EOF
function cleanup_packages {
sudo apt-get -y remove --purge ansible
- sudo add-apt-repository --yes --remove ppa:ansible/ansible
+ # sudo add-apt-repository --yes --remove ppa:ansible/ansible
}
install_packages
diff --git a/stage2-nix-psql.pkr.hcl b/stage2-nix-psql.pkr.hcl
index 032dd71e..58e60a24 100644
--- a/stage2-nix-psql.pkr.hcl
+++ b/stage2-nix-psql.pkr.hcl
@@ -37,6 +37,11 @@ variable "source_ami" {
description = "Source AMI ID from stage 1"
}
+variable "instance_type" {
+ type = string
+ default = "c6g.4xlarge"
+}
+
packer {
required_plugins {
amazon = {
@@ -48,7 +53,7 @@ packer {
source "amazon-ebs" "ubuntu" {
ami_name = "${var.ami_name}-${var.postgres-version}"
- instance_type = "c6g.4xlarge"
+ instance_type = var.instance_type
region = "${var.region}"
source_ami = "${var.source_ami}"
[parent: 899f7b7ffb02]