fix(installer): preserve stopped Station containers - #7155
Conversation
Signed-off-by: Senthil Ravichandran <senthilr@nvidia.com>
|
Note Reviews pausedIt looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the Use the following commands to manage reviews:
Use the checkboxes below for quick actions:
📝 WalkthroughWalkthroughDGX Station preparation now records the initial Docker container inventory, blocks unsafe mutations and restarts, verifies inventory preservation, and uses separate agent/inference conflict checks. Tests cover Docker coexistence, restart policies, baseline changes, and updated quiescence contracts. Documentation describes these guarantees. ChangesDocker-safe station preparation
Estimated code review effort: 4 (Complex) | ~45 minutes Sequence Diagram(s)sequenceDiagram
participant Operator
participant StationPreparation
participant Docker
participant SystemServices
Operator->>StationPreparation: run host preparation
StationPreparation->>Docker: capture container baseline
StationPreparation->>Docker: check mutation or restart quiescence
StationPreparation->>SystemServices: configure and start runtime services
StationPreparation->>Docker: verify baseline preservation
StationPreparation-->>Operator: continue or fail closed
Possibly related PRs
Suggested labels: Suggested reviewers: 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
PR Review Advisor — Blocking findings reportedAdvisor assessment: Blockers require maintainer review Model lanes
Nemotron output stays in workflow artifacts and does not change the assessment above. E2E guidanceAdvisory only. E2E / PR Gate selects and runs jobs independently. Recommended E2E: None 1 optional E2E recommendation
Blockers
|
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@scripts/prepare-dgx-station-host.sh`:
- Around line 911-915: Update require_docker_mutation_quiescence to validate the
captured Docker container inventory, including stopped containers, before
allowing any mutation to proceed. Reuse the existing baseline/inventory
verification helper and preserve the current conflict and running-container
checks; ensure require_docker_restart_quiescence inherits this validation
through its delegation.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: CHILL
Plan: Enterprise
Run ID: fe39c03d-07f5-47c6-af01-667cda453b5b
📒 Files selected for processing (5)
docs/get-started/dgx-station-preparation.mdxscripts/prepare-dgx-station-host.shtest/install-station-container-coexistence.test.tstest/install-station-dgx-os.test.tstest/install-station-host-preparation.test.ts
Signed-off-by: Senthil Ravichandran <senthilr@nvidia.com>
|
Addressed PRA-1 in b4d507b: generic |
There was a problem hiding this comment.
Actionable comments posted: 2
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@test/install-station-container-coexistence.test.ts`:
- Around line 120-128: Update the docker() stub in the coexistence test to
handle the running-container query with an empty result, then assert the test’s
stopped-container allowance or equivalent behavior is actually exercised. Keep
the preserved-container inventory checks, and ensure the test title reflects
stopped-container preservation rather than only inventory preservation.
- Around line 103-129: Update the test to invoke the public --verify command
entrypoint instead of calling verify_host() directly, and remove preloaded
internal baseline globals such as DOCKER_BASELINE_CAPTURED and
DOCKER_CONTAINER_BASELINE_TOTAL. Retain only the Docker and tooling stubs
required to isolate the verification behavior, ensuring the test validates that
the public command wires baseline verification correctly.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: CHILL
Plan: Enterprise
Run ID: 7cbc3e78-b799-402f-a1ad-45ba81164fc3
📒 Files selected for processing (2)
scripts/prepare-dgx-station-host.shtest/install-station-container-coexistence.test.ts
🚧 Files skipped from review as they are similar to previous changes (1)
- scripts/prepare-dgx-station-host.sh
Signed-off-by: Senthil Ravichandran <senthilr@nvidia.com>
Signed-off-by: Senthil Ravichandran <senthilr@nvidia.com>
There was a problem hiding this comment.
🧹 Nitpick comments (1)
test/install-station-container-coexistence.test.ts (1)
251-251: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick winNarrow the
systemctlmock to the expected active-service checks.Returning success for every
systemctlinvocation lets this pass iffinish_runtimeprobes the wrong units or skips the active-runtime condition. Handle only the expected status query/queryies and fail unexpected commands.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@test/install-station-container-coexistence.test.ts` at line 251, Update the systemctl mock in the coexistence test to return success only for the expected active-service status queries, and return failure for any other invocation. Preserve the test’s intended finish_runtime validation by matching the specific queried units and command form rather than accepting all systemctl calls.Source: Path instructions
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Nitpick comments:
In `@test/install-station-container-coexistence.test.ts`:
- Line 251: Update the systemctl mock in the coexistence test to return success
only for the expected active-service status queries, and return failure for any
other invocation. Preserve the test’s intended finish_runtime validation by
matching the specific queried units and command form rather than accepting all
systemctl calls.
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: CHILL
Plan: Enterprise
Run ID: 439fccad-8323-415b-9af9-af38a96aa146
📒 Files selected for processing (2)
scripts/prepare-dgx-station-host.shtest/install-station-container-coexistence.test.ts
🚧 Files skipped from review as they are similar to previous changes (1)
- scripts/prepare-dgx-station-host.sh
Signed-off-by: Aaron Erickson <aerickson@nvidia.com>
ericksoa
left a comment
There was a problem hiding this comment.
Reviewed exact head 7cfb1ea795d4e9117f5abfc4e94d7ed7452cb850, including the sensitive Station host-preparation paths. The stopped-container baseline remains fail-closed across Docker mutations, runtime starts, rollback restarts, and every reboot handoff; active services are enabled without a start-capable --now call.
Local verification: focused Station suite 132/132 passed; npm run check:diff, ShellCheck, Bash syntax, Biome, and diff hygiene passed. Approved pending final-head CI.
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@test/install-station-container-coexistence.test.ts`:
- Around line 384-411: Update the test identified by “applies restart-policy
blocking before starting an inactive runtime service” to assert ordering, not
just presence: compare the output positions of “RESTART_QUIESCENCE” and
“systemctl enable --now containerd.service docker.service” and require restart
quiescence to appear first. Keep the existing mutation-quiescence exclusion
assertion.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: CHILL
Plan: Enterprise
Run ID: a772c81a-88af-4c99-9df4-fce96c26640c
📒 Files selected for processing (3)
scripts/prepare-dgx-station-host.shtest/install-station-container-coexistence.test.tstest/install-station-host-preparation.test.ts
🚧 Files skipped from review as they are similar to previous changes (1)
- scripts/prepare-dgx-station-host.sh
Signed-off-by: Senthil Ravichandran <senthilr@nvidia.com>
|
Live BaseOS validation completed for the Docker coexistence path.
The later product commit |
<!-- markdownlint-disable MD041 --> ## Summary Adds the canonical `docs/changelog/2026-07-18.mdx` release-prep entry with the exact `## v0.0.88` heading. The entry summarizes every user-visible change on `main` since v0.0.87 and links each release theme to the focused user documentation. ## Changes - Add one parser-safe dated changelog entry for v0.0.88 covering DGX Station preparation, inference health, multi-gateway sandbox operations and recovery, onboarding policy defaults, and rebuild credential reuse. - Reconcile the changelog against the merged v0.0.88-labeled PRs and the complete `v0.0.87..origin/main` commit range. - Source mapping: - [#7152](#7152) -> `docs/changelog/2026-07-18.mdx`: Document RDMA-aware OpenIB service remediation during DGX Station preparation. - [#7155](#7155) -> `docs/changelog/2026-07-18.mdx`: Document stopped-container preservation and fail-closed restart-policy boundaries. - [#7158](#7158) -> `docs/changelog/2026-07-18.mdx`: Document bounded packaged CDI refresh for the exact AI Developer Tools Station profile. - [#7074](#7074) -> `docs/changelog/2026-07-18.mdx`: Document authenticated upstream model probes and precise route-reachability claims. - [#7007](#7007) -> `docs/changelog/2026-07-18.mdx`: Document the explicit serving-process health gap in `status` and `doctor`. - [#7113](#7113) -> `docs/changelog/2026-07-18.mdx`: Document owning-gateway selection for sandbox-scoped status and exec operations. - [#7092](#7092) -> `docs/changelog/2026-07-18.mdx`: Document idempotent recovery for target-owned active port forwards. - [#7133](#7133) -> `docs/changelog/2026-07-18.mdx`: Document web-search-aware policy preset defaults during onboarding. - [#7129](#7129) -> `docs/changelog/2026-07-18.mdx`: Document gateway-registered web-search credential reuse during rebuild preflight. ## Type of Change - [ ] Code change (feature, bug fix, or refactor) - [ ] Code change with doc updates - [x] Doc only (prose changes, no code sample modifications) - [ ] Doc only (includes code sample changes) ## Quality Gates <!-- Check one tests line and one docs line. Check other lines when applicable. Add every requested justification or approval reference. --> - [ ] Tests added or updated for changed behavior - [x] Existing tests cover changed behavior — justification: `test/changelog-docs.test.ts` validates the dated changelog contract, exact release heading, and parser-safe MDX structure. - [ ] Tests not applicable — justification: - [x] Docs updated for user-facing behavior changes - [ ] Docs not applicable — justification: - [ ] Sensitive paths changed (security, policy, credentials, preflight, onboarding, inference, runner, sandbox, or messaging) - [ ] Sensitive-path review completed or maintainer-approved waiver recorded — reviewer/approval link/justification: - [ ] Non-success, skipped, or missing CI check accepted by maintainer — check name, approval link, and follow-up issue: ## Verification <!-- Check each applicable item only when supported by the requested evidence. Run targeted tests once per relevant change set and rerun after later edits or hook autofixes that can affect the tested behavior. Do not rerun hook-covered checks. --> - [x] PR description includes a `Signed-off-by:` line and every commit appears as `Verified` in GitHub - [x] Normal `pre-commit`, `commit-msg`, and `pre-push` hooks passed, or `npm run check:diff` passed when hooks were skipped or unavailable - [x] Targeted behavior tests pass for the current change set, or tests are marked not applicable above — command/result or justification: `npx vitest run test/changelog-docs.test.ts` passed 6 tests. - [ ] Applicable broad gate passed — `npm test` for broad runtime/test-harness changes; `npm run check` for repo-wide validation/coverage changes — command/result: - [x] Quality Gates section completed with required justifications or waivers - [x] No secrets, API keys, or credentials committed - [ ] `npm run docs` builds without warnings (doc changes only) — completed successfully with 0 errors and 2 existing Fern warnings. - [x] Doc pages follow the [style guide](https://github.com/NVIDIA/NemoClaw/blob/main/docs/CONTRIBUTING.md) (doc changes only) - [ ] New doc pages include SPDX header and frontmatter (new pages only) — not applicable because native changelog entries use the required parser-safe MDX SPDX comment without frontmatter. --- Signed-off-by: Aaron Erickson <aerickson@nvidia.com> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added improved DGX Station preparation workflows. * Enhanced sandbox status and diagnostic reporting for inference health. * Improved state selection and recovery across multiple gateways. * Added safer onboarding defaults for web search policies. * Improved rebuild preflight handling for credential reuse and fail-closed behavior. * **Documentation** * Added release notes for version 0.0.88. <!-- end of auto-generated comment: release notes by coderabbit.ai --> Signed-off-by: Aaron Erickson <aerickson@nvidia.com>
Summary
DGX Station host preparation previously rejected any pre-existing Docker container record, including stopped containers. This change preserves stopped containers while continuing to fail closed on running containers, inventory changes, and stopped containers that could automatically restart during a Docker restart or host reboot.
This is the stopped-container coexistence slice of #7153. Conflict-aware continuation for running workloads remains follow-up work.
Related Issue
Part of #7153
Changes
no.enable --nowwill not restart them.Type of Change
Quality Gates
Verification
Signed-off-by:line and every commit appears asVerifiedin GitHubpre-commit,commit-msg, andpre-pushhooks passed, ornpm run check:diffpassed when hooks were skipped or unavailablenpx vitest run test/install-station-host-preparation.test.ts test/install-station-container-coexistence.test.ts test/install-station-dgx-os.test.ts(126 passed)npm testfor broad runtime/test-harness changes;npm run checkfor repo-wide validation/coverage changes — command/result:npm run docsbuilds without warnings (doc changes only) — not applicable to this code-and-docs PR;npm run docspassed, with Fern reporting two warningsSigned-off-by: Senthil Ravichandran senthilr@nvidia.com
Summary by CodeRabbit
Documentation
no.Bug Fixes
Tests