Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
59 commits
Select commit Hold shift + click to select a range
a18486d
[podman-port] Add first of several podman smoke tests.
rountree Aug 6, 2026
f7b7adc
[podman-port] Adds test of user switching.
rountree Aug 6, 2026
84169e6
[podman-port] Exercises filesystems.
rountree Aug 6, 2026
d2dcdc6
[podman-port] Networking test
rountree Aug 6, 2026
a5629fe
[podman-port] Flux test (no Spindle)
rountree Aug 6, 2026
713ed21
[podman-ports] Added slurm test.
rountree Aug 6, 2026
e9dbf83
[podman-port] Serial tests work (no SPINDLE_DEBUB yet)
rountree Aug 7, 2026
aafb9e3
[podman-ports] Proof of concept for SPINDLE_DEBUG on serial.
rountree Aug 7, 2026
57c31e1
[podman-port] Flux (not working)
rountree Aug 7, 2026
849b1bc
[podman-port] Adds slurm srun (working!)
rountree Aug 7, 2026
f921970
[podman-port] Slurm rshlaunch (not working)
rountree Aug 7, 2026
a1ee879
[podman-port] Porting to compute nodes.
rountree Aug 7, 2026
8269d82
[podman-port] Fixes for image load/store, enable-podman.
rountree Aug 7, 2026
f3a404d
[podman-port] enable-podman is awkward. Fix it later.
rountree Aug 7, 2026
0a10451
[podman-port] Parallelize container shutdown.
rountree Aug 7, 2026
058170b
[podman-port] Update .gitignore for testing-srun case.
rountree Aug 7, 2026
6785823
[podman-port] Allow container inspection after failed verification.
rountree Aug 8, 2026
14c803c
[podman-port] Add mariaDB password to image.
rountree Aug 8, 2026
2c6b511
[podman-port] Updating script readme, adding cleanup script.
rountree Aug 8, 2026
f39fbc3
[podman-port] Make cleanup.sh more robust
rountree Aug 8, 2026
54547b6
[podman-port] Save mariadb image locally.
rountree Aug 11, 2026
7cea4da
[podman-port] Optimizing spindle-slurm-srun script.
rountree Aug 11, 2026
466c521
[podman port] Debugging mariadb password issue again.
rountree Aug 11, 2026
068a814
[podman-port] Dynamic passwords for MariaDB.
rountree Aug 12, 2026
b9155aa
[podman-port] Scripts a spraling workflow.
rountree Aug 12, 2026
6a39c45
[podman-port] Fix permission issues in MariaDB setup.
rountree Aug 12, 2026
e2a1e07
[podman-port] Remove prompts to press enter to continue.
rountree Aug 12, 2026
a3da16b
[podman-port] More build process.
rountree Aug 12, 2026
83bd10d
[podman-port] Podman networking rework.
rountree Aug 12, 2026
4b5cdcc
[podman-enable] Networking and tarball tweaks
rountree Aug 12, 2026
3ade88a
[podman-port] Fix environment variable substitution bug
rountree Aug 13, 2026
1509be6
[podman-port] Fix incorrect quoting.
rountree Aug 13, 2026
74a70cf
[podman-port] Still tweaking networking.
rountree Aug 13, 2026
db76686
[podman-port] Moving to /etc/hosts for DNS
rountree Aug 13, 2026
eca2168
[podman-port] Enable spindle debugging
rountree Aug 13, 2026
5d1f49c
[podman-port] Fix for env var propagation to clients.
rountree Aug 14, 2026
58cc74f
[podman-port] Script modifications for intrusive debugging.
rountree Aug 14, 2026
1873f7b
Bump actions/checkout from 7.0.0 to 7.0.1 in /.github/workflows
dependabot[bot] Aug 1, 2026
154988c
Bump docker/setup-buildx-action in /.github/workflows
dependabot[bot] Aug 1, 2026
47bd3ad
Bump docker/login-action from 4.2.0 to 4.6.0 in /.github/workflows
dependabot[bot] Aug 1, 2026
2e5a8ff
Bump docker/build-push-action from 7.2.0 to 7.3.0 in /.github/workflows
dependabot[bot] Aug 1, 2026
6647312
Bump docker/setup-compose-action in /.github/workflows
dependabot[bot] Aug 1, 2026
31bc609
Handle PrologFlags=Alloc in Slurm plugin
nchaimov Jul 8, 2026
275adef
Bug fixes in Slurm plugin
nchaimov Jul 8, 2026
c0306af
Use PrologFlags=Contain in slurm-plugin container
nchaimov Jul 8, 2026
0cd19ec
Documentation for Slurm plugin
nchaimov Jul 8, 2026
ba770c5
Bug fixes in Slurm plugin
nchaimov Jul 9, 2026
4cbf85e
More robust Slurm plugin exit handling
nchaimov Jul 9, 2026
20f77c5
Bug fixes in Spindle plugin
nchaimov Jul 9, 2026
f6069bd
Bug fixes in Slurm plugin
nchaimov Jul 9, 2026
6924983
Forward env vars to Slurm job control in every launch mode
nchaimov Aug 5, 2026
667c1af
Document plugstack.conf config
nchaimov Aug 20, 2026
83e03ca
Bug fixes in Slurm plugin
nchaimov Aug 20, 2026
e3690d3
Send exit message with MSG_NOSIGNAL; ensure log daemon exits between …
nchaimov Aug 20, 2026
ace1ca7
Remove logd_kill_test; relocate logd check
nchaimov Aug 24, 2026
837ab0f
[podman-port] --enable-sec-none compiler warnings cleanup.
rountree Sep 12, 2026
8d6c912
Initial commit of spindle-podman script.
rountree Sep 12, 2026
d327c01
[podman-port] Updates .gitignore
rountree Sep 12, 2026
8a0e2f8
[podman-port] serial tests working, adds debug notes/scripts.
rountree Sep 13, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
26 changes: 26 additions & 0 deletions .containerignore
Original file line number Diff line number Diff line change
@@ -0,0 +1,26 @@
# Podman/Docker ignore file
# Excludes files from being copied into container images during build

# Exclude the saved images tarball (6+ GB)
spindle-podman-images.tar

# Exclude build artifacts
workspace-Spindle/build/
workspace-Spindle/install/
*.o
*.a
*.so

# Exclude git metadata
.git/
.gitignore

# Exclude test output
out.*
*.log

# Exclude investigation directory
podman-concurrency-investigation/

# Exclude debugging artifacts
debugging/
1 change: 1 addition & 0 deletions .dockerignore
30 changes: 15 additions & 15 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -25,10 +25,10 @@ jobs:
timeout-minutes: 20
steps:
- name: Check out Spindle
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1

- name: Setup Docker Compose
uses: docker/setup-compose-action@16feee727cbdc83b6a014e6cc26fec4a79bcf30c
uses: docker/setup-compose-action@4eb059ff7f16592f9c84d5ca339c53cb7c5064e2
with:
version: latest

Expand Down Expand Up @@ -78,10 +78,10 @@ jobs:
timeout-minutes: 30
steps:
- name: Check out Spindle
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1

- name: Setup Docker Compose
uses: docker/setup-compose-action@16feee727cbdc83b6a014e6cc26fec4a79bcf30c
uses: docker/setup-compose-action@4eb059ff7f16592f9c84d5ca339c53cb7c5064e2
with:
version: latest

Expand Down Expand Up @@ -131,10 +131,10 @@ jobs:
timeout-minutes: 20
steps:
- name: Check out Spindle
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1

- name: Setup Docker Compose
uses: docker/setup-compose-action@16feee727cbdc83b6a014e6cc26fec4a79bcf30c
uses: docker/setup-compose-action@4eb059ff7f16592f9c84d5ca339c53cb7c5064e2
with:
version: latest

Expand Down Expand Up @@ -184,16 +184,16 @@ jobs:
timeout-minutes: 20
steps:
- name: Check out Spindle
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1

- name: Setup Docker Compose
uses: docker/setup-compose-action@16feee727cbdc83b6a014e6cc26fec4a79bcf30c
uses: docker/setup-compose-action@4eb059ff7f16592f9c84d5ca339c53cb7c5064e2
with:
version: latest

- name: Login to GitHub Container Registry
if: ${{ !env.ACT }}
uses: docker/login-action@650006c6eb7dba73a995cc03b0b2d7f5ca915bee
uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f
with:
registry: ghcr.io
username: ${{ github.actor }}
Expand Down Expand Up @@ -251,16 +251,16 @@ jobs:
timeout-minutes: 20
steps:
- name: Check out Spindle
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1

- name: Setup Docker Compose
uses: docker/setup-compose-action@16feee727cbdc83b6a014e6cc26fec4a79bcf30c
uses: docker/setup-compose-action@4eb059ff7f16592f9c84d5ca339c53cb7c5064e2
with:
version: latest

- name: Login to GitHub Container Registry
if: ${{ !env.ACT }}
uses: docker/login-action@650006c6eb7dba73a995cc03b0b2d7f5ca915bee
uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f
with:
registry: ghcr.io
username: ${{ github.actor }}
Expand Down Expand Up @@ -309,16 +309,16 @@ jobs:
timeout-minutes: 20
steps:
- name: Check out Spindle
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1

- name: Setup Docker Compose
uses: docker/setup-compose-action@16feee727cbdc83b6a014e6cc26fec4a79bcf30c
uses: docker/setup-compose-action@4eb059ff7f16592f9c84d5ca339c53cb7c5064e2
with:
version: latest

- name: Login to GitHub Container Registry
if: ${{ !env.ACT }}
uses: docker/login-action@650006c6eb7dba73a995cc03b0b2d7f5ca915bee
uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f
with:
registry: ghcr.io
username: ${{ github.actor }}
Expand Down
8 changes: 4 additions & 4 deletions .github/workflows/container.yml
Original file line number Diff line number Diff line change
Expand Up @@ -11,20 +11,20 @@ jobs:
build:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1

- name: Set up Docker Buildx
uses: docker/setup-buildx-action@d7f5e7f509e45cec5c76c4d5afdd7de93d0b3df5
uses: docker/setup-buildx-action@bb05f3f5519dd87d3ba754cc423b652a5edd6d2c

- name: Login to GitHub Container Registry
uses: docker/login-action@650006c6eb7dba73a995cc03b0b2d7f5ca915bee
uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f
with:
registry: ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}

- name: Build & Push Slurm Base Image
uses: docker/build-push-action@f9f3042f7e2789586610d6e8b85c8f03e5195baf
uses: docker/build-push-action@53b7df96c91f9c12dcc8a07bcb9ccacbed38856a
with:
context: ./containers/spindle-slurm-ubuntu/base
platforms: linux/amd64
Expand Down
13 changes: 13 additions & 0 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -35,3 +35,16 @@ run_driver
run_driver_rm
preload_file_list
build

# Generated by generate_config.sh
containers/spindle-slurm-ubuntu/testing/conf/slurmdbd.conf
containers/spindle-slurm-ubuntu/testing/mariadb.env
containers/spindle-slurm-ubuntu/testing-srun/conf/slurmdbd.conf
containers/spindle-slurm-ubuntu/testing-srun/mariadb.env

# spindle-podman
.podman-state.json
.podman-metrics.log
.podman-logs


21 changes: 21 additions & 0 deletions DEBUGGING.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,21 @@
# Build
podman rm -f spindlenode-interactive
./scripts/podman/build-spindle-serial-interactive.sh
# Start
./scripts/podman/run-spindle-serial-interactive.sh
# Connect
podman exec -it spindlenode-interactive bash
# Enable core dumps
ulimit -c unlimited
# Set up spindle config file
mkdir -p /home/spindleuser/Spindle-inst/etc/spindle
cat > /home/spindleuser/Spindle-inst/etc/spindle/spindle.conf <<'EOF'
noclean = true
EOF
# cd
cd Spindle-build/testsuite
# Run the problematic test
SPINDLE_DEBUG=3 SPINDLE_FLAGS="--noclean" ./run_driver --thrdopen --push
# Core file analysis
RELOCATED=$(find /tmp/commpath/cachepath -name "*test_driver" -type f | grep -v "\.so" | head -1)
gdb ${RELOCATED} /tmp/core.test_driver.$(ls -t *.core | head -1 )
97 changes: 97 additions & 0 deletions containers/spindle-flux-ubuntu/Dockerfile.podman
Original file line number Diff line number Diff line change
@@ -0,0 +1,97 @@
# This is based on the Flux Container Tutorial
# See https://flux-framework.readthedocs.io/en/latest/tutorials/containers
ARG flux_sched_version=noble-v0.48.0-amd64
FROM fluxrm/flux-sched:${flux_sched_version} AS builder
ARG replicas=4
ENV workers=${replicas}
USER root
ENV TMPDIR=/tmp
RUN echo 'TMPDIR="/tmp"' >> /etc/environment
ENV SPINDLE_TEST_CONTAINER=1

# LC-specific fix for podman setgroups issue
ARG PODMAN_BUILD=false
RUN if [ "$PODMAN_BUILD" = "true" ]; then \
echo 'APT::Sandbox::User root;' > /etc/apt/apt.conf.d/00-apt-sandbox; \
fi

RUN DEBIAN_FRONTEND="noninteractive" apt-get update \
&& apt-get -qq install -y --no-install-recommends \
autotools-dev \
autoconf \
automake \
cmake \
git \
python3 \
openssh-server \
openssh-client \
libdb-dev \
apt-utils \
dnsutils \
iputils-ping \
python3-pip \
libgcrypt20 \
libgcrypt20-dev \
gdb \
libc6-dbg \
software-properties-common

ARG USER=fluxuser
ARG CONFIG_ROOT=containers/spindle-flux-ubuntu

# Allow fluxuser to run as other users so it can start munged
RUN sh -c "printf \"${USER} ALL=(ALL) NOPASSWD: ALL\\n\" >> /etc/sudoers"

# Configure flux
ENV STATE_DIR=/var/lib/flux
RUN mkdir -p ${STATE_DIR} /etc/flux/system /etc/flux/system/cron.d /etc/flux/config /run/flux /etc/flux/imp/conf.d
COPY ${CONFIG_ROOT}/flux/imp.toml /etc/flux/imp/conf.d/
COPY ${CONFIG_ROOT}/flux/broker.toml /etc/flux/config/
RUN mkdir -p /etc/flux/system/cron.d && \
mkdir -p /mnt/curve && \
flux keygen /mnt/curve/curve.cert && \
flux R encode --hosts="node-[1-${workers}]" > /etc/flux/system/R && \
chmod -R a+rX /etc/flux && \
chown -R ${USER}:${USER} /run/flux ${STATE_DIR} /mnt/curve/curve.cert

# Build Spindle
WORKDIR /home/${USER}
# Copy the whole git repo into the container
COPY . /home/${USER}/Spindle

# Fix permissions on Spindle source (configure needs +x)
RUN chmod -R u+rwX /home/${USER}/Spindle && \
chown -R ${USER}:${USER} /home/${USER}/Spindle

# Copy and prepare build script as root
COPY ${CONFIG_ROOT}/scripts/build_spindle.sh /home/${USER}/build_spindle.sh
RUN chmod +rx /home/${USER}/build_spindle.sh && \
chown ${USER}:${USER} /home/${USER}/build_spindle.sh

# Switch to user to run the build
USER ${USER}
RUN bash ./build_spindle.sh

# Copy scripts as root
USER root
RUN chown -R ${USER}:${USER} /home/fluxuser && \
chown -R ${USER}:${USER} /run/flux

COPY ${CONFIG_ROOT}/scripts/flux_healthcheck.sh /home/${USER}/flux_healthcheck.sh
COPY ${CONFIG_ROOT}/scripts/entrypoint.sh.podman /home/${USER}/entrypoint.sh
RUN chmod +rx /home/${USER}/flux_healthcheck.sh /home/${USER}/entrypoint.sh && \
chown ${USER}:${USER} /home/${USER}/flux_healthcheck.sh /home/${USER}/entrypoint.sh

USER ${USER}
WORKDIR /home/${USER}
ENV PATH /home/${USER}/Spindle-inst/bin:${PATH}
# Make libfabric work with fork.
ENV RDMAV_FORK_SAFE 1
# Silence warning from hwloc about unsupported PCI device
# on GitHub-hosted runners.
ENV HWLOC_HIDE_ERRORS 2
# Suppress UCX warnings about /proc/sys tuning parameters
# These are expected in rootless podman containers
ENV UCX_LOG_LEVEL=error

ENTRYPOINT /bin/bash ./entrypoint.sh
51 changes: 51 additions & 0 deletions containers/spindle-flux-ubuntu/scripts/entrypoint.sh.podman
Original file line number Diff line number Diff line change
@@ -0,0 +1,51 @@
#!/bin/bash
#
# Podman-compatible entrypoint for Flux containers
# Starts munged and the flux broker.
#
# For documentation on running Flux in containers, see
# https://flux-framework.readthedocs.io/en/latest/tutorials/containers

set -x # Debug output

brokerOptions="-Scron.directory=/etc/flux/system/cron.d \
-Stbon.fanout=256 \
-Srundir=/run/flux \
-Sstatedir=${STATE_DIRECTORY:-/var/lib/flux} \
-Slocal-uri=local:///run/flux/local \
-Slog-stderr-level=6 \
-Slog-stderr-mode=local"

# Get the hostname that will resolve for the Docker bridge network.
address=$(echo $( nslookup "$( hostname -i )" | head -n 1 ))
parts=(${address//=/ })
hostName=${parts[2]}
thisHost=(${hostName//./ })
thisHost=${thisHost[0]}
echo "This host: $thisHost"
echo "Main host: $mainHost"
export FLUX_FAKE_HOSTNAME=$thisHost

if [ -d /shared ]; then
sudo chown -R "$(id -un):$(id -gn)" /shared
sudo chmod 755 /shared
fi

# Start munged
echo "Starting munged..."
sudo -u munge /usr/sbin/munged

# Give munge time to start
sleep 2

if [ "${thisHost}" != "${mainHost}" ]; then
# Worker node -- wait for head node before connecting
echo "Worker node: waiting for head node..."
sleep 15
echo "Starting flux broker (worker)..."
exec flux start -o --config /etc/flux/config ${brokerOptions} sleep inf
else
# Head node
echo "Head node: starting flux broker..."
exec flux start -o --config /etc/flux/config ${brokerOptions} sleep inf
fi
28 changes: 28 additions & 0 deletions containers/spindle-hello-podman/01-basic/Dockerfile
Original file line number Diff line number Diff line change
@@ -0,0 +1,28 @@
FROM ubuntu:noble

# LC-specific fix for podman setgroups issue
# This is a no-op in Docker, but required for podman on LC systems
ARG PODMAN_BUILD=false
RUN if [ "$PODMAN_BUILD" = "true" ]; then \
echo 'APT::Sandbox::User root;' > /etc/apt/apt.conf.d/00-apt-sandbox; \
fi

# Install curl to test both apt-get and SSL connectivity
RUN apt-get update && apt-get install -y --no-install-recommends \
curl \
ca-certificates \
&& rm -rf /var/lib/apt/lists/*

# Test script that validates:
# 1. Container runs
# 2. Network access works
# 3. SSL certificates work
CMD echo "=== Hello from Podman! ===" && \
echo "Container is running successfully." && \
echo "" && \
echo "Testing network and SSL connectivity..." && \
curl -I https://www.google.com 2>&1 | head -5 && \
echo "" && \
echo "If you see HTTP headers above, SSL is working!" && \
echo "" && \
echo "=== 01-basic test complete ==="
Loading