Skip to content

feat: migrate AKernel deployment to Python YuanRong CLI - #19

Draft
mhsong1998-dot wants to merge 1 commit into
inclusionAI:mainfrom
mhsong1998-dot:smh/python-cli-migration
Draft

feat: migrate AKernel deployment to Python YuanRong CLI#19
mhsong1998-dot wants to merge 1 commit into
inclusionAI:mainfrom
mhsong1998-dot:smh/python-cli-migration

Conversation

@mhsong1998-dot

@mhsong1998-dot mhsong1998-dot commented Aug 7, 2026

Copy link
Copy Markdown

Summary

  • Migrate master, frontend, node, and standalone startup to the Python openYuanRong CLI.
  • Preserve AKernel's existing fixed deployment and log paths instead of introducing timestamped session directories.
  • Upgrade the packaged openYuanRong release to 0.10.1, including the core wheel checksums, RRT checksum, Python SDK/sandbox dependency pins, dependency constraints, and the src/yuanrong gitlink.

Runtime paths

  • master/frontend: DEPLOY_PATH=/home/yuanrong/master, YR_LOG_PATH=/home/yuanrong/master/log
  • node/standalone: DEPLOY_PATH=/home/yuanrong, YR_LOG_PATH=/home/yuanrong/logs
  • DataSystem master/worker, FunctionProxy runtime logs, the Python CLI daemon, and OTel use the role's YR_LOG_PATH.
  • The startup chain does not pass --log-dir-prefix and does not generate timestamps.

Review fixes

  • Render standalone node IP and embedded-etcd ports consistently.
  • Keep external resource collection for node and standalone roles.
  • Derive sandbox DNS from node.sandboxIPRange.
  • Fail image builds if either wheel safety patch no longer matches.
  • Use the complete Python 3.12 dependency constraint set.
  • Use Pod IP as values.host_ip, wait for sandbox0 IPv4 readiness, and use its bridge address as values.local_ip for the dual-address FunctionProxy path.

Validation

Current HEAD: 1852878cb054abc569db5a9f2a888073101ccb73, one author-signed Conventional Commit.

  • Built linux/amd64 runtime image akernel-ci/runtime:pr19-1852878-0.10.1-amd64.
  • Built linux/amd64 all-in-one image akernel-ci/all-in-one:pr19-1852878-0.10.1-amd64 (sha256:2edbe7881be46ecffd3cdc9b9ecfedbadc1b16865471ff2b35cd48f6bb2c14bd).
  • Verified the image contains openyuanrong-core==0.10.1; yr --help, OTel Collector, RRT rootfs, and both wheel safety patches passed smoke checks.
  • Rendered and merged standalone configuration with the packaged CLI. Verified grpc_listen_port=22773, component_grpc_port=22774, Pod host_ip, and distinct sandbox bridge local_ip.
  • Verified the 0.10.1 YuanRong gitlink and its merged FunctionSystem component gRPC implementation are present.

The local build used exact OBS 0.10.1 artifacts through temporary build arguments because public GitHub/PyPI publication was not yet complete when validated. No credential, test/plan file, temporary download URL, mirror, or trusted-host setting is committed.

@mhsong1998-dot
mhsong1998-dot force-pushed the smh/python-cli-migration branch 9 times, most recently from b7de90a to 7e5c006 Compare August 10, 2026 11:31
Comment thread builder/config/yr/config.toml.jinja Outdated
Comment thread builder/config/yr/config.toml.jinja Outdated
Comment thread deploy/akernel/charts/core/values.yaml
Comment thread builder/node.Dockerfile
Comment thread builder/node.Dockerfile
@mhsong1998-dot
mhsong1998-dot force-pushed the smh/python-cli-migration branch from 7e5c006 to 6a7e84d Compare August 11, 2026 12:36
@tianyuzhou95

Copy link
Copy Markdown
Collaborator

One remaining process issue before merge: the current commit body contains only the Signed-off-by trailer. The repository's AGENTS.md requires a Conventional Commit with a prose body explaining what changed and why, followed by the DCO sign-off. Please amend the commit message accordingly.

Also, GitHub currently reports no checks for this branch. The validation documented in the PR is extensive, but there is no automated status attached to the commit. Please ensure the expected CI checks are configured and passing before merge, or explicitly confirm that this repository does not currently provide PR checks.

@mhsong1998-dot
mhsong1998-dot force-pushed the smh/python-cli-migration branch 3 times, most recently from 3d195f7 to 317abec Compare August 18, 2026 08:38
Comment thread .dockerignore Outdated
@mhsong1998-dot
mhsong1998-dot force-pushed the smh/python-cli-migration branch 2 times, most recently from ae77634 to 1e30b39 Compare August 20, 2026 05:02
@mhsong1998-dot

Copy link
Copy Markdown
Author

Process items are addressed in current HEAD 1e30b39: the branch contains one lowercase Conventional Commit with a prose body, and its author, committer, and Signed-off-by trailer all match mhsong1998-dot. GitHub created CI run 32334113441 for this head, but currently marks it action_required, so a maintainer must approve the fork workflow before the checks can execute. The previously approved head passed all eight CI jobs.

@mhsong1998-dot
mhsong1998-dot marked this pull request as draft August 20, 2026 08:34
@mhsong1998-dot
mhsong1998-dot force-pushed the smh/python-cli-migration branch 6 times, most recently from bfa5b8b to 4d55ac6 Compare August 26, 2026 04:38
@mhsong1998-dot
mhsong1998-dot force-pushed the smh/python-cli-migration branch from 4d55ac6 to 1852878 Compare August 27, 2026 07:36
@@ -0,0 +1,30 @@
# Runtime dependency lock for openyuanrong-core 0.10.1 on Python 3.12.

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Why do we need this file?

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Kept. This file was added in response to the earlier reproducibility review (discussion_r3756876467): the core wheel metadata uses lower-bounded transitive dependencies, so pinning the complete Python 3.12 dependency closure prevents the same AKernel commit from resolving different versions over time. It is updated together with OPEN_YR_VERSION.

fi
fi

case "${role}" in

@WenYuLuo WenYuLuo Aug 28, 2026

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Seems to be a duplicate of line 10.

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Updated in 7485d18. The entrypoint now consumes the role argument once, validates the resulting role once, and then exports AKERNEL_ROLE; the duplicate role-selection case is gone.

Comment thread builder/scripts/akernel-entrypoint.sh Outdated
;;
node)
export DEPLOY_PATH="${DEPLOY_PATH:-/home/yuanrong}"
export YR_LOG_PATH="${YR_LOG_PATH:-${DEPLOY_PATH}/logs}"

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

These two environments should not be set in this file.
Please move them to the yuanrong setup bash.

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Updated in 7485d18. DEPLOY_PATH and YR_LOG_PATH are no longer set by akernel-entrypoint; the node/standalone YuanRong bootstrap remains the single place that supplies these defaults.

Comment thread builder/scripts/akernel-entrypoint.sh Outdated
;;
standalone)
export DEPLOY_PATH="${DEPLOY_PATH:-/home/yuanrong}"
export YR_LOG_PATH="${YR_LOG_PATH:-${DEPLOY_PATH}/logs}"

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Seems it's a duplicate set in the Yuanrong startup script.

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Updated in 7485d18 together with the node branch. The duplicate standalone assignments were removed, and the YuanRong bootstrap owns these defaults.

Comment thread builder/scripts/yr_node_bootstrap.sh Outdated
sleep 1
done

echo "timed out after 60s waiting for sandbox0 to have an IPv4 address" >&2

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Not an elegant way. Any method to resolve this dependency? For example, can we set the yuanrong service to start after the sandboxd service? And the IP can be obtained from the ‘ip_range’ config.

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Updated in 7485d18. sandboxd.service now has a bounded ExecStartPost readiness check for the live sandbox0 IPv4, and yuanrong.service explicitly Requires/starts After sandboxd. The YuanRong bootstrap therefore reads the address once instead of polling. The address is intentionally not derived from ip_range because the earlier review in discussion_r3734794038 required the actually assigned interface address as the source of truth.

Comment thread builder/node.Dockerfile Outdated
ARG FIRECRACKER_RELEASE
ARG FIRECRACKER_AMD64_SHA256
ARG FIRECRACKER_AMD64_URL
ARG KATA_LICENSE_URL=https://raw.githubusercontent.com/kata-containers/kata-containers/${KATA_RELEASE}/LICENSE

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Is it required for our deployment change? Why change the kata things?

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Updated in 7485d18. The Kata license URL parameter and local download-timeout adjustment were unrelated build-network accommodations, so this block is restored to the current main-branch implementation.

Comment thread builder/node.Dockerfile
echo "${wheel_sha} ${wheel}" | sha256sum -c -; \
python3 -m pip install \
--break-system-packages \
python3 -m venv /opt/openyuanrong; \

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Why we need to use venv?

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The venv is retained because the Python CLI wheel now installs its complete runtime dependency set. It keeps those dependencies isolated from Ubuntu system Python and avoids mutating the externally managed system environment with --break-system-packages.

Comment thread builder/node.Dockerfile
sed -i 's/"env_vars": comp.env_vars,/"env_vars": {},/' "${launcher_py}"; \
grep -Fq '"env_vars": {},' "${launcher_py}"; \
! grep -Fq '"env_vars": comp.env_vars,' "${launcher_py}"; \
test -x /opt/openyuanrong/bin/yr; \

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Those changes for what needs?

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Retained as a security hardening required by the earlier review in discussion_r3756876315. The 0.10.1 wheel still logs the full component environment and persists component env_vars in session JSON. The exact grep checks make the build fail if an upstream source change causes either redaction patch to stop applying, rather than silently exposing values such as LITEBUS_DATA_KEY.

Comment thread deploy/standalone/README.md Outdated
default)
- Print the Traefik container IP to use as `AKERNEL_SERVER_ADDRESS`

The openYuanRong bootstrap waits for `sandbox0` and uses the IPv4 address

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

unnecessary

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Removed in 7485d18. This implementation detail remains documented in the repository maintenance guidance and does not need to be part of the standalone user quick-start.

Replace the legacy Go launcher with the openYuanRong 0.10.1 Python CLI while preserving AKernel role behavior, fixed deployment paths, observability paths, and cloud deployment settings.

Order YuanRong after sandboxd network readiness so local_ip still comes from the live sandbox0 interface without polling in the YuanRong bootstrap. Remove duplicate entrypoint defaults and keep unrelated validation fixes intact.

Signed-off-by: mhsong1998-dot <258010372+mhsong1998-dot@users.noreply.github.com>
@mhsong1998-dot
mhsong1998-dot force-pushed the smh/python-cli-migration branch from 1852878 to 7485d18 Compare August 28, 2026 09:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants