mirror of
https://github.com/seaweedfs/seaweedfs.git
synced 2026-08-24 16:17:08 +00:00
* worker: name the binary weed-worker It is the Rust side of `weed worker`, the way weed-volume is the Rust side of `weed volume`, and lance is the first family of jobs it carries rather than the only one it ever will. The crate keeps its own name: when a second family arrives the bin target moves to a crate of its own, under this name. Claude-Session: https://claude.ai/code/session_01Rkp1Mw5E89Jp6dzJFYiMrm * docker: ship the Rust maintenance worker in the image Lance table buckets need a worker that can read the format, and until now the only way to get one was a Rust toolchain and a cargo build. It now sits at /usr/bin/weed-worker beside the Rust volume server, reached as `docker run chrislusf/seaweedfs worker-rust --admin host:23646` — the verb mirrors volume-rust, so plain `worker` still runs the Go one. Taken pre-built or not at all: the lance jobs pull in arrow and datafusion, far too large a tree to compile inside the image build, so an architecture CI did not build for gets the empty placeholder the entrypoint refuses to exec, the way the Rust volume server already does. Claude-Session: https://claude.ai/code/session_01Rkp1Mw5E89Jp6dzJFYiMrm * ci: build the Rust worker for the container images The same native cross-compile the volume server uses, so the release, latest and dev images all carry it on amd64 and arm64. The artifact holds both binaries now, so it is named for that rather than for the volume server. Only the release directory each job builds is cached: with a debug profile beside it the worker's target/ reaches 24GB, against a 10GB cache budget. Claude-Session: https://claude.ai/code/session_01Rkp1Mw5E89Jp6dzJFYiMrm * ci: publish Rust worker binaries with the release Linux amd64 and arm64 only: the worker runs beside the cluster it maintains, and its dependency tree makes every extra target an expensive build. Claude-Session: https://claude.ai/code/session_01Rkp1Mw5E89Jp6dzJFYiMrm * ci: build and test the Rust workers on change Nothing built seaweed-worker in CI, so the release and the container images would have been the first place a break showed up. Tests run in release too, rather than compiling lance, arrow and datafusion again in another profile. Claude-Session: https://claude.ai/code/session_01Rkp1Mw5E89Jp6dzJFYiMrm * docs: say how to get a released worker Neither the image nor the release tarballs were mentioned; a toolchain and a cargo build read as the only way in. Claude-Session: https://claude.ai/code/session_01Rkp1Mw5E89Jp6dzJFYiMrm * ci: install protoc for the Rust worker builds lance's crates compile their own protos, and unlike seaweed-volume they do not vendor a protoc to do it with, so every job that builds the worker failed at lance-encoding's build script. Claude-Session: https://claude.ai/code/session_01Rkp1Mw5E89Jp6dzJFYiMrm * ci: do not persist credentials in the worker release checkout The upload step is handed a token explicitly; a cargo build script should not find another one sitting in the checkout's git config. Claude-Session: https://claude.ai/code/session_01Rkp1Mw5E89Jp6dzJFYiMrm * docker: keep the worker's argument boundaries Unquoted $@ splits on whitespace and expands globs, so an argument carrying either arrived as something else. Claude-Session: https://claude.ai/code/session_01Rkp1Mw5E89Jp6dzJFYiMrm
143 lines
3.8 KiB
Bash
Executable File
143 lines
3.8 KiB
Bash
Executable File
#!/bin/sh
|
|
|
|
# Enable FIPS 140-3 mode by default (Go 1.24+)
|
|
# To disable: docker run -e GODEBUG=fips140=off ...
|
|
export GODEBUG="${GODEBUG:+$GODEBUG,}fips140=on"
|
|
|
|
# Fix permissions for mounted volumes
|
|
# If /data is mounted from host, it might have different ownership
|
|
# Fix this by ensuring seaweed user owns the directory
|
|
if [ "$(id -u)" = "0" ]; then
|
|
# Running as root, check and fix permissions if needed
|
|
SEAWEED_UID=$(id -u seaweed)
|
|
SEAWEED_GID=$(id -g seaweed)
|
|
|
|
# Verify seaweed user and group exist
|
|
if [ -z "$SEAWEED_UID" ] || [ -z "$SEAWEED_GID" ]; then
|
|
echo "Error: 'seaweed' user or group not found. Cannot fix permissions." >&2
|
|
exit 1
|
|
fi
|
|
|
|
DATA_UID=$(stat -c '%u' /data 2>/dev/null)
|
|
DATA_GID=$(stat -c '%g' /data 2>/dev/null)
|
|
|
|
# Only run chown -R if ownership doesn't already match (avoids expensive
|
|
# recursive chown on subsequent starts, and is a no-op on OpenShift when
|
|
# fsGroup has already set correct ownership on the PVC).
|
|
if [ "$DATA_UID" != "$SEAWEED_UID" ] || [ "$DATA_GID" != "$SEAWEED_GID" ]; then
|
|
echo "Fixing /data ownership for seaweed user (uid=$SEAWEED_UID, gid=$SEAWEED_GID)"
|
|
if ! chown -R seaweed:seaweed /data; then
|
|
echo "Warning: Failed to change ownership of /data. This may cause permission errors." >&2
|
|
echo "If /data is read-only or has mount issues, the application may fail to start." >&2
|
|
fi
|
|
fi
|
|
|
|
# Use su-exec to drop privileges and run as seaweed user
|
|
exec su-exec seaweed "$0" "$@"
|
|
fi
|
|
|
|
isArgPassed() {
|
|
# Match both `-flag` and `--flag` (and their `=value` forms): the Go fla9
|
|
# library accepts both, and users may pick either form on the CLI.
|
|
arg="$1"
|
|
argWithEqualSign="$1="
|
|
argDouble="-$1"
|
|
argDoubleWithEqualSign="-$1="
|
|
shift
|
|
while [ $# -gt 0 ]; do
|
|
passedArg="$1"
|
|
shift
|
|
case $passedArg in
|
|
"$arg"|"$argDouble")
|
|
return 0
|
|
;;
|
|
"$argWithEqualSign"*|"$argDoubleWithEqualSign"*)
|
|
return 0
|
|
;;
|
|
esac
|
|
done
|
|
return 1
|
|
}
|
|
|
|
case "$1" in
|
|
|
|
'master')
|
|
ARGS="-mdir=/data -volumeSizeLimitMB=1024"
|
|
shift
|
|
exec /usr/bin/weed -logtostderr=true master $ARGS $@
|
|
;;
|
|
|
|
'volume')
|
|
ARGS="-dir=/data -max=0"
|
|
if isArgPassed "-max" "$@"; then
|
|
ARGS="-dir=/data"
|
|
fi
|
|
shift
|
|
exec /usr/bin/weed -logtostderr=true volume $ARGS $@
|
|
;;
|
|
|
|
'volume-rust')
|
|
ARGS="-dir /data -max 0"
|
|
if isArgPassed "-max" "$@"; then
|
|
ARGS="-dir /data"
|
|
fi
|
|
shift
|
|
if [ ! -s /usr/bin/weed-volume ]; then
|
|
echo "Error: Rust volume server is not available on this platform ($(uname -m))." >&2
|
|
echo "Use 'volume' for the Go volume server instead." >&2
|
|
exit 1
|
|
fi
|
|
exec /usr/bin/weed-volume $ARGS $@
|
|
;;
|
|
|
|
'worker-rust')
|
|
shift
|
|
if [ ! -s /usr/bin/weed-worker ]; then
|
|
echo "Error: Rust maintenance worker is not available on this platform ($(uname -m))." >&2
|
|
echo "Use 'worker' for the Go maintenance worker instead." >&2
|
|
exit 1
|
|
fi
|
|
exec /usr/bin/weed-worker "$@"
|
|
;;
|
|
|
|
'server')
|
|
ARGS="-dir=/data -volume.max=0 -master.volumeSizeLimitMB=1024"
|
|
if isArgPassed "-volume.max" "$@"; then
|
|
ARGS="-dir=/data -master.volumeSizeLimitMB=1024"
|
|
fi
|
|
shift
|
|
exec /usr/bin/weed -logtostderr=true server $ARGS $@
|
|
;;
|
|
|
|
'mini')
|
|
ARGS="-dir=/data"
|
|
if isArgPassed "-dir" "$@"; then
|
|
ARGS=""
|
|
fi
|
|
shift
|
|
exec /usr/bin/weed -logtostderr=true mini $ARGS $@
|
|
;;
|
|
|
|
'filer')
|
|
ARGS=""
|
|
shift
|
|
exec /usr/bin/weed -logtostderr=true filer $ARGS $@
|
|
;;
|
|
|
|
's3')
|
|
ARGS="-domainName=$S3_DOMAIN_NAME -key.file=$S3_KEY_FILE -cert.file=$S3_CERT_FILE"
|
|
shift
|
|
exec /usr/bin/weed -logtostderr=true s3 $ARGS $@
|
|
;;
|
|
|
|
'shell')
|
|
ARGS="-cluster=$SHELL_CLUSTER -filer=$SHELL_FILER -filerGroup=$SHELL_FILER_GROUP -master=$SHELL_MASTER -options=$SHELL_OPTIONS"
|
|
shift
|
|
exec echo "$@" | /usr/bin/weed -logtostderr=true shell $ARGS
|
|
;;
|
|
|
|
*)
|
|
exec /usr/bin/weed $@
|
|
;;
|
|
esac
|