Skip to content

gpuledger v0.3.0

Choose a tag to compare

@github-actions github-actions released this 26 Sep 20:00
· 11 commits to main since this release
95d29e8

A hardened cluster: Nomad and Consul over mutual TLS, a workload identity in place of a
static token, fleet through Nomad's own service discovery, and release binaries with
build provenance. Every item observed in the Nomad matrix on each version that has the
feature; the driver side, as before, only against a fake nvidia-smi (GL-10, v0.4.0).

Upgrading from 0.2.0

  • The system job now requires -var checksum=sha256:… of the binary, from the
    release's checksums file (README: Run it); Nomad refuses a download that does not match.
  • Both job specs pass --nomad-node-id ${node.unique.id}; nothing to do unless you run
    gpuledger by other means with a workload identity before Nomad 1.11.
  • This is the first release with build provenance: gh attestation verify (README: Install).

Added

  • --nomad-node-id: the node's Nomad id given, /v1/agent/self is not called. Both
    job specs pass ${node.unique.id} (GL-25).
  • deploy/nomad/gpuledger.wi.nomad.hcl: the system job with no static token, Nomad
    1.5+ — identity { env = true } and the policy file bound to the job. The Nomad
    matrix runs gpuledger with a task's workload identity on every version from 1.5, and
    observed that /v1/agent/self refuses one before 1.11 (GL-25).
  • Verifiable releases: build provenance attestations on every binary and the checksums
    file, verified by the release workflow before it publishes; gh attestation verify in
    the README's install steps; a dry run of those steps, with a tampered binary that must
    fail, on every change to the release workflow (GL-28).

Changed

  • The system job requires -var checksum=sha256:… and passes it to the artifact, so
    Nomad refuses a binary that does not match the release's checksums file. The Nomad
    matrix checks the job validates with it and is refused without it (GL-28).
  • Consul over TLS for fleet: --consul-ca-cert, --consul-ca-path,
    --consul-client-cert, --consul-client-key, --consul-tls-server-name, defaulting
    to the Consul CLI's variables, and CONSUL_HTTP_SSL for a bare address. The matrix
    runs a Consul dev agent with verify_incoming (GL-27).
  • fleet --nomad-service NAME (and --nomad-namespace): the endpoints from Nomad's
    own service discovery, Nomad 1.3+, with the same address, token and TLS as the rest —
    for clusters without Consul. Observed on every matrix version from 1.3 (GL-26).
  • Nomad over mutual TLS: --nomad-ca-cert, --nomad-ca-path, --nomad-client-cert,
    --nomad-client-key, --nomad-tls-server-name, defaulting to the Nomad CLI's
    NOMAD_CACERT, NOMAD_CAPATH, NOMAD_CLIENT_CERT, NOMAD_CLIENT_KEY,
    NOMAD_TLS_SERVER_NAME. The Nomad matrix runs an agent with verify_https_client on
    every version (GL-24).