dzueck opened a new pull request, #8572:
URL: https://github.com/apache/texera/pull/8572
<!--
Thanks for sending a pull request (PR)! Here are some tips for you:
1. If this is your first time, please read our contributor guidelines:
[Contributing to
Texera](https://github.com/apache/texera/blob/main/CONTRIBUTING.md)
2. Ensure you have added or run the appropriate tests for your PR
3. If the PR is work in progress, mark it a draft on GitHub.
4. Please write your PR title to summarize what this PR proposes, we
are following Conventional Commits style for PR titles as well:
- `fix` is for behavior that worked before and no longer does; adding
or
removing a functionality, or reworking one so that user-facing
behavior
intentionally changes, is a `feat`; a change that leaves the
user-facing
behavior unchanged is a `refactor`.
- A test-only PR is `test(<module>): ...`; repairing a broken test is
`fix(test, <module>): ...`.
- A dependency bump is `fix(deps, <module>): ...` when it patches a CVE
and `chore(deps, <module>): ...` otherwise; GitHub Actions bumps take
`ci` as their module, e.g. `chore(deps, ci): ...`.
- A PR targeting a release branch appends the version as the last scope
component, e.g. `fix(deps, frontend, v1.2): ...`.
See CONTRIBUTING.md for the full convention.
5. Be sure to keep the PR description updated to reflect all changes.
-->
### What changes were proposed in this PR?
<!--
Please clarify what changes you are proposing. The purpose of this section
is to outline the changes. Here are some tips for you:
1. If you propose a new API, clarify the use case for a new API.
2. If you fix a bug, you can clarify why it is a bug.
3. If it is a refactoring, clarify what has been changed.
3. It would be helpful to include a before-and-after comparison using
screenshots or GIFs.
4. Please consider writing useful notes for better and faster reviews.
-->
Adds support for running compute units and micro services inside a vm using
[kata containers](https://katacontainers.io/). This is important for security
as arbitrary code submitted by users can run inside these compute units. This
PR adds the option to use VMs, but does not require it. It is only targeted at
k8s deployments and was tested using RKE2. Note: k8s distributions like
minikube may need additional steps to support VMs.
To enable VMs you must first install kata containers following [these
instructions](https://kata-containers.github.io/kata-containers/installation/).
Make sure to follow the helm instructions. After this, you can enable Compute
Units to use a VM by modifying these two lines in bin/k8s/values.yaml:
- name: KUBERNETES_COMPUTING_UNIT_RUNTIME_CLASS_CPU
value: "kata-qemu-runtime-rs"
- name: KUBERNETES_COMPUTING_UNIT_RUNTIME_CLASS_GPU
value: "kata-qemu-nvidia-gpu-runtime-rs"
To enable texera specific micro services to run in a VM modify this line:
global:
texeraMicroServiceRuntimeClass: "kata-qemu-runtime-rs"
### Any related issues, documentation, discussions?
<!--
Please use this section to link other resources if not mentioned already.
1. If this PR fixes an issue, please include `Fixes #1234`, `Resolves
#1234`
or `Closes #1234`. If it is only related, simply mention the issue
number.
2. If there is design documentation, please add the link.
3. If there is a discussion in the mailing list, please add the link.
-->
Closes #8545
Discussed in #8430
### How was this PR tested?
<!--
If tests were added, say they were added here. Or simply mention that if the
PR
is tested with existing test cases. Make sure to include/update test cases
that
check the changes thoroughly including negative and positive cases if
possible.
If it was tested in a way different from regular unit tests, please clarify
how
you tested step by step, ideally copy and paste-able, so that other
reviewers can
test and check, and descendants can verify in the future. If tests were not
added,
please describe why they were not added and/or why it was difficult to add.
-->
Primarily tested in v1.2.0 where performance tests were done with various
micro benchmark workflows which can be seen in #8430. Additional functionality
testing still needs to be done on the latest commits.
### Was this PR authored or co-authored using generative AI tooling?
<!--
If generative AI tooling has been used in the process of authoring this PR,
please include the phrase: 'Generated-by: ' followed by the name of the tool
and its version. If no, write 'No'.
Please refer to the [ASF Generative Tooling
Guidance](https://www.apache.org/legal/generative-tooling.html) for details.
-->
Generated-by: Gemini 4.1 Pro
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]