gpuledger v0.3.0
A hardened cluster: Nomad and Consul over mutual TLS, a workload identity in place of a
static token, fleet through Nomad's own service discovery, and release binaries with
build provenance. Every item observed in the Nomad matrix on each version that has the
feature; the driver side, as before, only against a fake nvidia-smi (GL-10, v0.4.0).
Upgrading from 0.2.0
- The system job now requires
-var checksum=sha256:…of the binary, from the
release's checksums file (README: Run it); Nomad refuses a download that does not match. - Both job specs pass
--nomad-node-id ${node.unique.id}; nothing to do unless you run
gpuledger by other means with a workload identity before Nomad 1.11. - This is the first release with build provenance:
gh attestation verify(README: Install).
Added
--nomad-node-id: the node's Nomad id given,/v1/agent/selfis not called. Both
job specs pass${node.unique.id}(GL-25).deploy/nomad/gpuledger.wi.nomad.hcl: the system job with no static token, Nomad
1.5+ —identity { env = true }and the policy file bound to the job. The Nomad
matrix runs gpuledger with a task's workload identity on every version from 1.5, and
observed that/v1/agent/selfrefuses one before 1.11 (GL-25).- Verifiable releases: build provenance attestations on every binary and the checksums
file, verified by the release workflow before it publishes;gh attestation verifyin
the README's install steps; a dry run of those steps, with a tampered binary that must
fail, on every change to the release workflow (GL-28).
Changed
- The system job requires
-var checksum=sha256:…and passes it to the artifact, so
Nomad refuses a binary that does not match the release's checksums file. The Nomad
matrix checks the job validates with it and is refused without it (GL-28). - Consul over TLS for
fleet:--consul-ca-cert,--consul-ca-path,
--consul-client-cert,--consul-client-key,--consul-tls-server-name, defaulting
to the Consul CLI's variables, andCONSUL_HTTP_SSLfor a bare address. The matrix
runs a Consul dev agent withverify_incoming(GL-27). fleet --nomad-service NAME(and--nomad-namespace): the endpoints from Nomad's
own service discovery, Nomad 1.3+, with the same address, token and TLS as the rest —
for clusters without Consul. Observed on every matrix version from 1.3 (GL-26).- Nomad over mutual TLS:
--nomad-ca-cert,--nomad-ca-path,--nomad-client-cert,
--nomad-client-key,--nomad-tls-server-name, defaulting to the Nomad CLI's
NOMAD_CACERT,NOMAD_CAPATH,NOMAD_CLIENT_CERT,NOMAD_CLIENT_KEY,
NOMAD_TLS_SERVER_NAME. The Nomad matrix runs an agent withverify_https_clienton
every version (GL-24).