-
Notifications
You must be signed in to change notification settings - Fork 15
Expand file tree
/
Copy pathContainerfile.kernel
More file actions
48 lines (44 loc) · 2.66 KB
/
Copy pathContainerfile.kernel
File metadata and controls
48 lines (44 loc) · 2.66 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
# The kernel cache image.
#
# Compiling the OGC kernel takes roughly half an hour and building NVIDIA's open
# module takes several minutes more, and neither depends on anything Utah's own
# Containerfile does -- only on the base image and on the pins inside
# scripts/install-ogc-kernel.sh and scripts/install-nvidia.sh. Doing that work
# inside every image build meant paying it again on every push, for three of the
# four flavors, for inputs that had not moved.
#
# So it is paid once here. The result is the same base image plus a /utah-cache
# directory of archives, published as ghcr.io/<owner>/utah-kernel-cache:<key>
# where <key> is a hash of exactly those inputs (`just kernel-cache-tag`). The
# gaming, nvidia and nvidia-gaming builds then use this as their BASE_IMAGE and
# the install scripts unpack instead of compiling. `main` needs neither, so it
# keeps using the pristine base and pays nothing for this.
#
# The cache image's own build has no /utah-cache, so the same scripts take their
# source-build path here. There is no second implementation to drift.
ARG BASE_IMAGE=quay.io/hummingbird-community/bootc-os:latest@sha256:6d10289774167be62fba06df77b49918d7d1d3cc72b96f47314d455db4135752
FROM ${BASE_IMAGE} AS builder
# The toolchain the kernel build needs comes from the same pairing the image
# itself installs from: Hummingbird's overlay plus the pinned Fedora 44
# buildroot. Fedora is builder-only; it is not copied into the runtime stage.
COPY packages/hummingbird.repo /etc/yum.repos.d/hummingbird.repo
# hummingbird.repo runs with gpgcheck=1; the key it names has to exist here too.
COPY packages/RPM-GPG-KEY-redhat-release-2 /etc/pki/rpm-gpg/
COPY packages/fedora-44.repo /etc/yum.repos.d/fedora-44.repo
RUN mkdir -p /usr/local/libexec
COPY scripts/install-ogc-kernel.sh /usr/local/libexec/utah-install-ogc-kernel
COPY scripts/install-nvidia.sh /usr/local/libexec/utah-install-nvidia
# nvidia-gaming is the superset: it produces a module for the base kernel and
# one for the OGC kernel, so a single cache image serves all three flavors.
RUN chmod 0755 /usr/local/libexec/utah-install-ogc-kernel /usr/local/libexec/utah-install-nvidia && \
mkdir -p /cache-out && \
UTAH_KERNEL_CACHE_OUT=/cache-out/ogc.tar \
/usr/local/libexec/utah-install-ogc-kernel && \
UTAH_NVIDIA_MODULES_ONLY=1 UTAH_KERNEL_CACHE_OUT_DIR=/cache-out \
/usr/local/libexec/utah-install-nvidia nvidia-gaming && \
ls -l /cache-out
# The builder's toolchain, kernel tree and object files stay behind in the
# builder. What ships is the untouched base image plus the archives, so this
# remains a legitimate base for a bootc build.
FROM ${BASE_IMAGE}
COPY --from=builder /cache-out /utah-cache