Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
27 changes: 22 additions & 5 deletions vm_images/linux-amd64/linux-amd64.pkr.hcl
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,15 @@ packer {
}
}

variable "iam_instance_profile" {
type = string
description = "EC2 instance profile with permission to pull xgb-ci.gpu from ECR."
validation {
condition = length(trimspace(var.iam_instance_profile)) > 0
error_message = "An instance profile with ECR pull permissions is required."
}
}

locals {
ami_name_prefix = "xgboost-ci"
image_name = "RunsOn worker with Ubuntu 24.04 AMD64 + CUDA driver 580"
Expand Down Expand Up @@ -34,20 +43,21 @@ source "amazon-ebs" "runs-on-linux-amd64" {
associate_public_ip_address = true
communicator = "ssh"
instance_type = "g4dn.xlarge"
iam_instance_profile = var.iam_instance_profile
region = "${local.region}"
ssh_timeout = "10m"
ssh_username = "ubuntu"
ssh_file_transfer_method = "sftp"
user_data_file = "setup_ssh.sh"
launch_block_device_mappings {
device_name = "/dev/sda1"
volume_size = "${local.volume_size}"
volume_type = "gp3"
device_name = "/dev/sda1"
volume_size = "${local.volume_size}"
volume_type = "gp3"
delete_on_termination = true
}
aws_polling { # Wait up to 1 hour until the AMI is ready
aws_polling { # Wait up to 1 hour until the AMI is ready
delay_seconds = 15
max_attempts = 240
max_attempts = 240
}
snapshot_tags = {
Name = "${local.image_name}"
Expand Down Expand Up @@ -76,4 +86,11 @@ build {
pause_before = "1m0s"
script = "bootstrap.sh"
}

provisioner "shell" {
script = "preload_gpu_image.sh"
environment_vars = [
"AWS_DEFAULT_REGION=${local.region}",
]
}
}
23 changes: 23 additions & 0 deletions vm_images/linux-amd64/preload_gpu_image.sh
Original file line number Diff line number Diff line change
@@ -0,0 +1,23 @@
#!/bin/bash
# Cache Docker layers in the AMI to avoid downloading/extracting them on every job.
# Remove this step if runners gain a persistent image cache or stop using xgb-ci.gpu.
set -euo pipefail

registry=492475357299.dkr.ecr.us-west-2.amazonaws.com
image="${registry}/xgb-ci.gpu:main"

# Use the builder's instance profile and an ephemeral Docker config so ECR tokens
# are not baked into the AMI. CI must still pull its requested tag to pick up updates.
docker_config=$(mktemp -d)
trap 'sudo rm -rf "$docker_config"' EXIT
sudo systemctl start docker
aws ecr get-login-password --region "$AWS_DEFAULT_REGION" |
sudo docker --config "$docker_config" login --username AWS --password-stdin "$registry"
sudo docker --config "$docker_config" pull "$image"
sudo docker run --rm --pull=never --gpus all --entrypoint nvidia-smi "$image"
# Record the digest and size in the build log to identify what the snapshot contains.
sudo docker image inspect --format '{{json .RepoDigests}} {{.Size}}' "$image"

# Preserve the downloaded layers, but stop writes before Packer snapshots the disk.
sudo systemctl stop docker.service docker.socket containerd.service
sync
Loading