Compare commits

..
40 Commits
Author SHA1 Message Date
Fedor Korotkov 1a2f187ac8 Fixed mouse/keyboard on Monterey guest (#535)
I guess [my comment was accurate](https://github.com/cirruslabs/tart/pull/524/files#r1239939939). Fixes #534

Tested by running `ghcr.io/cirruslabs/macos-monterey-base:latest` locally on a Sonoma host.
2023-07-01 10:35:45 +04:00
Fedor Korotkov 285bf9b6c2 Run gon right after building (#533)
To sing and stuff
2023-06-29 23:01:08 +04:00
Fedor KorotkovandNikolay Edigaryev 415ed3388d Optimistically check if we need to do anything on a pull (#531)
* Optimistically check if we need to do anything on a pull

Right now on a pull we always acquire a lock for a registry host. This is problematic because, for example, host can be pulling `ghcr.io/cirruslabs/macos-ventura-xcode:15-beta-2` image when a new request will come to pull `ghcr.io/cirruslabs/macos-ventura-xcode:latest` if needed.

In this situation, even though `ghcr.io/cirruslabs/macos-ventura-xcode:latest` is already cached and linked, `tart pull` will wait for a lock.

This change optimistically check if there is something to do at all before acquiring a lock.

* Fix linter errors

---------

Co-authored-by: Nikolay Edigaryev <edigaryev@gmail.com>
2023-06-29 10:51:41 -04:00
Nikolay Edigaryev 870b414994 tart clone: try to reclaim disk space if needed (#532) 2023-06-29 18:46:00 +04:00
Stefan Mitterrutzner be7011bf11 Adds the OCI access_token fallback field (#530) 2023-06-29 10:33:20 +00:00
Nikolay Edigaryev 859050cb42 .goreleaser.yml: remove Tart binary from the root of the archive (#526) 2023-06-29 10:54:30 +04:00
Fedor Korotkov 4f321ec264 Use "License Tier" term (#528)
Instead of a "Sponsorship"
2023-06-27 15:17:50 +00:00
Nikolay Edigaryev 1b53ce42f8 Use Mac-specific input devices when possible (#524)
* Use VZMacKeyboardConfiguration when possible

* Use VZMacTrackpadConfiguration when possible
2023-06-23 17:54:47 +00:00
Nikolay Edigaryevandfedor e89ef32a83 Enable automatic display reconfiguration for Sonoma (#521)
* Enable automatic display reconfiguration for Sonoma

* Xcode 15 Beta

---------

Co-authored-by: fedor <fedor.korotkov@gmail.com>
2023-06-23 15:25:22 +00:00
Nikolay Edigaryev 62a34bf89f Fix "file “config.json” couldn’t be opened" error when pruning (#525)
* Fix "file “config.json” couldn’t be opened" error when pruning

* No need to use the ";"
2023-06-23 15:23:25 +00:00
Jontified 0608b2b9d1 Add Mullvad logo to list of users (#520) 2023-06-21 17:04:02 +04:00
fedor 91e859de9b Updated template with removed mentions on Cirrus CI 2023-06-19 14:17:02 -07:00
Nikolay Edigaryev c79da6a12b .goreleaser.yml: include LICENSE file in the release archive (#519) 2023-06-16 15:04:14 +04:00
Fedor Korotkov 2b7ca12324 Document manual installation via release archives (#516)
* Document manual installation via release archives

* Fixed typo
2023-06-09 20:01:08 +04:00
Nikolay Edigaryev 9016fcfdd4 Use MainActor to ensure we're running on main queue (#515)
* Use MainActor to ensure we're running on main queue

...and to simplify the code.

* VZVirtualMachine.requestStop() is not asynchronous
2023-06-07 15:06:33 +04:00
Andrzej Fiedukowicz 546238d9df Replace mentions of Monteray with Ventura in quickstart guide (#510)
* Replace mentions of Monteray with Ventura in quickstart guide

They seem to just be leftovers from previous versions of the docs, so a small cleanup could be helpful.

* Update quick-start.md

* Update quick-start.md

* Update quick-start.md
2023-06-02 05:48:04 -04:00
Fedor Korotkov 2b6818c493 Clarify Licensing Use Limitation (#506)
For both Tart and Orchard

[skip ci]
2023-05-26 17:06:55 +04:00
Nikolay Edigaryev cf49fd10b6 Print errors to stderr (#504) 2023-05-18 19:11:22 +04:00
pheianoxandFedor Korotkov 59b3e0c0fb Add PITS Global Data Recovery Services to the list of companies (#499)
* Add PITS Global Data Recovery Services to the list of companies

* Remove unnecessary change at line 48

Co-authored-by: Fedor Korotkov <fedor.korotkov@gmail.com>

* Update PITS Global Data Recovery logo location

---------

Co-authored-by: Fedor Korotkov <fedor.korotkov@gmail.com>
2023-05-16 14:36:13 -04:00
pheianox 7bbdfc06e7 Add PITSGlobalDataRecoveryServices.png logo (#500) 2023-05-16 14:35:51 -04:00
Nikolay Edigaryev 637c54e1d1 FAQ: document how to change the default DHCP lease time (#494)
* FAQ: document how to change the default DHCP lease time

* Use shell for code snippets

* Note about persistence
2023-05-09 13:30:28 +00:00
Fedor Korotkov e611d97b69 Minor docs improvements (#492)
I realised we didn't add a proper link to Orchard
2023-05-07 17:55:55 +00:00
Fedor Korotkov 8e11bbe1cd Improve error reporting for unsupported host OS version (#491)
Fixes #489
2023-05-07 21:07:26 +04:00
Nikolay Edigaryev 6de31de6bf tart login: trim newline characters at the end of --password-stdin (#486) 2023-05-04 14:02:46 +04:00
fedor 37ae7888e6 Cross-link blog posts 2023-04-28 11:52:02 -04:00
Nikolay Edigaryev 64482f4345 Blog: how we implemented SSH over gRPC in Orchard (#480) 2023-04-28 10:36:26 -04:00
Nikolay Edigaryev 4f70d01dd6 Set User-Agent header for OCI HTTP requests (#478)
* Set User-Agent header for OCI HTTP requests

* IORegistry value is actually a NUL-terminated C string

* Use sysctl instead of IOKit
2023-04-28 18:02:57 +04:00
Fedor Korotkov 9098eaf024 Optimized landing page loading (#477)
Converting all the images to WebP reduced the size more than 2x.

Plus enabled `privacy` plugin for mkdocs so the site will bundle remote resources. It appeared that loading Roboto font dynamically was adding 700ms to the page load.
2023-04-25 14:00:58 +00:00
fedor 337d95ac95 Fixed date in the blog post link 2023-04-25 09:18:45 -04:00
Fedor Korotkov 3eb8ae2aa5 [blog] Orchard Announcement (#476)
* [blog] Announcing Orchard orchestration

* Added animation to the post

* Moved date
2023-04-25 09:13:28 -04:00
Nikolay Edigaryev b03408f856 tart ip: wait for the VM to start if --wait was set (#467) 2023-04-10 10:37:00 +00:00
fedor c749bdeaf1 Update Sponsorship Template 2023-04-06 16:35:08 -04:00
fedor 8e75a59d54 Revert "Revert pkg (#462)"
This reverts commit 3fdf82079a.
2023-04-06 10:36:07 -04:00
Nikolay EdigaryevandFedor Korotkov 1d3aa5ac81 tart push: allow pushing OCI VMs from the cache too (#465)
* tart push: allow pushing OCI VMs from the cache too

* Check for RemoteName earlier

* Refactored pushing of OCI images under new tag (#466)

* Refactored pushing of OCI images under new tag

* Fixed compilation

---------

Co-authored-by: Fedor Korotkov <fedor.korotkov@gmail.com>
2023-04-06 14:20:04 +00:00
Fedor Korotkov 261c1806df Improve tart ip error message (#464)
Resolves #460
2023-04-05 18:19:39 +00:00
Fedor Korotkov 92a4b3164d Document GitLab Runner Executor (#463) 2023-04-05 09:00:54 +04:00
Fedor Korotkov 3fdf82079a Revert pkg (#462)
* Revert "Revert "Build pkg again (#457)""

This reverts commit a05684157e.

* Updated identifier for pkg
2023-04-03 19:52:05 +04:00
fedor a05684157e Revert "Build pkg again (#457)"
This reverts commit e62e921eec.
2023-04-03 10:27:12 -04:00
Fedor Korotkov e62e921eec Build pkg again (#457)
* Build .pkg again

Last time it broke in #441. The theory is that notarization of the `.pkg` before after notarizaation of the binary was breaking validation on Apple side.

This attempt does build the .pkg before we do all the dance with gon ang goreleaser.

* codesign deep

* Move back to before hooks
2023-04-03 10:09:10 -04:00
Fedor Korotkov e1bb565c3b UI improvements (#459) 2023-03-31 10:58:14 -04:00
54 changed files with 727 additions and 180 deletions
+7 -4
View File
@@ -1,5 +1,8 @@
use_compute_credits: true
env:
XCODE_TAG: 15-beta-2
task:
name: Test on Ventura
alias: test
@@ -28,7 +31,7 @@ task:
name: Lint
alias: lint
macos_instance:
image: ghcr.io/cirruslabs/macos-ventura-xcode:latest
image: ghcr.io/cirruslabs/macos-ventura-xcode:$XCODE_TAG
lint_script:
- swift package plugin --allow-writing-to-package-directory swiftformat --cache ignore --lint --report swiftformat.json .
always:
@@ -41,7 +44,7 @@ task:
alias: build
only_if: $CIRRUS_TAG == ''
macos_instance:
image: ghcr.io/cirruslabs/macos-ventura-xcode:latest
image: ghcr.io/cirruslabs/macos-ventura-xcode:$XCODE_TAG
build_script: swift build --product tart
sign_script: codesign --sign - --entitlements Resources/tart-dev.entitlements --force .build/debug/tart
binary_artifacts:
@@ -54,7 +57,7 @@ task:
- lint
- build
macos_instance:
image: ghcr.io/cirruslabs/macos-ventura-xcode:latest
image: ghcr.io/cirruslabs/macos-ventura-xcode:$XCODE_TAG
env:
MACOS_CERTIFICATE: ENCRYPTED[552b9d275d1c2bdbc1bff778b104a8f9a53cbd0d59344d4b7f6d0ca3c811a5cefb97bef9ba0ef31c219cb07bdacdd2c2]
AC_PASSWORD: ENCRYPTED[4a761023e7e06fe2eb350c8b6e8e7ca961af193cb9ba47605f25f1d353abc3142606f412e405be48fd897a78787ea8c2]
@@ -89,7 +92,7 @@ task:
- test
- build
macos_instance:
image: ghcr.io/cirruslabs/macos-ventura-xcode:latest
image: ghcr.io/cirruslabs/macos-ventura-xcode:$XCODE_TAG
env:
MACOS_CERTIFICATE: ENCRYPTED[552b9d275d1c2bdbc1bff778b104a8f9a53cbd0d59344d4b7f6d0ca3c811a5cefb97bef9ba0ef31c219cb07bdacdd2c2]
AC_PASSWORD: ENCRYPTED[4a761023e7e06fe2eb350c8b6e8e7ca961af193cb9ba47605f25f1d353abc3142606f412e405be48fd897a78787ea8c2]
+6 -7
View File
@@ -4,6 +4,9 @@ before:
hooks:
- .ci/set-version.sh
- swift build -c release --product tart
- gon gon.hcl
- mkdir -p tart.app/Contents/MacOS
- cp .build/arm64-apple-macosx/release/tart tart.app/Contents/MacOS/
builds:
- builder: prebuilt
@@ -11,11 +14,9 @@ builds:
- darwin
goarch:
- arm64
binary: tart.app/Contents/MacOS/tart
prebuilt:
path: .build/arm64-apple-macosx/release/tart
hooks:
post:
- gon gon.hcl
path: tart.app/Contents/MacOS/tart
archives:
- name_template: "{{ .ProjectName }}"
@@ -23,9 +24,7 @@ archives:
- src: Resources/embedded.provisionprofile
dst: tart.app/Contents
strip_parent: true
- src: ".build/arm64-apple-macosx/release/tart"
dst: tart.app/Contents/MacOS
strip_parent: true
- LICENSE
release:
prerelease: auto
-17
View File
@@ -1,17 +0,0 @@
<component name="ProjectRunConfigurationManager">
<configuration default="false" name="sign debug" type="ShConfigurationType">
<option name="SCRIPT_TEXT" value="codesign --sign - --entitlements Resources/tart-dev.entitlements --force .build/debug/tart" />
<option name="INDEPENDENT_SCRIPT_PATH" value="true" />
<option name="SCRIPT_PATH" value="$PROJECT_DIR$/scripts/sign.sh" />
<option name="SCRIPT_OPTIONS" value="" />
<option name="INDEPENDENT_SCRIPT_WORKING_DIRECTORY" value="true" />
<option name="SCRIPT_WORKING_DIRECTORY" value="$PROJECT_DIR$" />
<option name="INDEPENDENT_INTERPRETER_PATH" value="true" />
<option name="INTERPRETER_PATH" value="/bin/zsh" />
<option name="INTERPRETER_OPTIONS" value="" />
<option name="EXECUTE_IN_TERMINAL" value="true" />
<option name="EXECUTE_SCRIPT_FILE" value="false" />
<envs />
<method v="2" />
</configuration>
</component>
-8
View File
@@ -1,8 +0,0 @@
<component name="ProjectRunConfigurationManager">
<configuration default="false" name="tart create" type="SwiftPackageManagerRunConfiguration" factoryName="Swift Package Run" PROGRAM_PARAMS="create latest --from-ipsw=latest" REDIRECT_INPUT="false" ELEVATE="false" USE_EXTERNAL_CONSOLE="false" PASS_PARENT_ENVS_2="true" PROJECT_NAME="tart" TARGET_NAME="tart" CONFIG_NAME="tart" RUN_TARGET_PROJECT_NAME="tart" RUN_TARGET_NAME="tart" WAS_MODIFIED="">
<method v="2">
<option name="SPM.BUILD_TASK_PROVIDER" enabled="true" />
<option name="RunConfigurationTask" enabled="true" run_configuration_name="sign debug" run_configuration_type="ShConfigurationType" />
</method>
</configuration>
</component>
-8
View File
@@ -1,8 +0,0 @@
<component name="ProjectRunConfigurationManager">
<configuration default="false" name="tart run" type="SwiftPackageManagerRunConfiguration" factoryName="Swift Package Run" PROGRAM_PARAMS="run latest" REDIRECT_INPUT="false" ELEVATE="false" USE_EXTERNAL_CONSOLE="false" PASS_PARENT_ENVS_2="true" PROJECT_NAME="tart" TARGET_NAME="tart" CONFIG_NAME="tart" RUN_TARGET_PROJECT_NAME="tart" RUN_TARGET_NAME="tart" WAS_MODIFIED="">
<method v="2">
<option name="SPM.BUILD_TASK_PROVIDER" enabled="true" />
<option name="RunConfigurationTask" enabled="true" run_configuration_name="sign debug" run_configuration_type="ShConfigurationType" />
</method>
</configuration>
</component>
+9
View File
@@ -81,6 +81,15 @@
"version" : "1.0.2"
}
},
{
"identity" : "swift-sysctl",
"kind" : "remoteSourceControl",
"location" : "https://github.com/sersoft-gmbh/swift-sysctl.git",
"state" : {
"revision" : "71fd64ee84819bb19fbecfb36d5a4503726b6fb7",
"version" : "1.6.0"
}
},
{
"identity" : "swiftdate",
"kind" : "remoteSourceControl",
+2
View File
@@ -20,6 +20,7 @@ let package = Package(
.package(url: "https://github.com/nicklockwood/SwiftFormat", from: "0.50.6"),
.package(url: "https://github.com/getsentry/sentry-cocoa", from: "8.3.3"),
.package(url: "https://github.com/cfilipov/TextTable", branch: "master"),
.package(url: "https://github.com/sersoft-gmbh/swift-sysctl.git", from: "1.0.0"),
],
targets: [
.executableTarget(name: "tart", dependencies: [
@@ -32,6 +33,7 @@ let package = Package(
.product(name: "Atomics", package: "swift-atomics"),
.product(name: "Sentry", package: "sentry-cocoa"),
.product(name: "TextTable", package: "TextTable"),
.product(name: "Sysctl", package: "swift-sysctl"),
], exclude: [
"OCI/Reference/Makefile",
"OCI/Reference/Reference.g4",
+6
View File
@@ -31,6 +31,9 @@ Many more companies are using Tart in their internal setups. Here are a few of t
<a href="https://krisp.ai/" target=_blank>
<img src="https://github.com/cirruslabs/tart/raw/main/Resources/Users/Krisp.png" height="65"/>
</a>
<a href="https://mullvad.net/" target=_blank>
<img src="https://github.com/cirruslabs/tart/raw/main/Resources/Users/Mullvad.png" height="65"/>
</a>
<a href="https://suran.com/" target=_blank>
<img src="https://github.com/cirruslabs/tart/raw/main/Resources/Users/Suran.png" height="65"/>
</a>
@@ -40,6 +43,9 @@ Many more companies are using Tart in their internal setups. Here are a few of t
<a href="https://transloadit.com/" target=_blank>
<img src="https://github.com/cirruslabs/tart/raw/main/Resources/Users/Transloadit.png" height="65"/>
</a>
<a href="https://www.pitsdatarecovery.net/" target=_blank>
<img src="https://github.com/cirruslabs/tart/raw/main/Resources/Users/PITSGlobalDataRecoveryServices.png" height="65"/>
</a>
</p>
**Note:** If your company or project is using Tart please consider [adding yourself to the list above](/Resources/Users/HowToAddYourself.md).
Binary file not shown.

After

Width:  |  Height:  |  Size: 7.0 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 4.1 KiB

+1
View File
@@ -31,6 +31,7 @@ struct Clone: AsyncParsableCommand {
}
let sourceVM = try VMStorageHelper.open(sourceName)
try Prune.reclaimIfNeeded(UInt64(sourceVM.sizeBytes()))
let tmpVMDir = try VMDirectory.temporary()
+12 -1
View File
@@ -35,8 +35,19 @@ struct IP: AsyncParsableCommand {
let vmMACAddress = MACAddress(fromString: vmConfig.macAddress.string)!
guard let ip = try await IP.resolveIP(vmMACAddress, resolutionStrategy: resolver, secondsToWait: wait) else {
throw RuntimeError.NoIPAddressFound("no IP address found, is your VM running?")
var message = "no IP address found"
if try !vmDir.running() {
message += ", is your VM running?"
}
if (vmConfig.os == .linux && resolver == .arp) {
message += " (not all Linux distributions are compatible with the ARP resolver)"
}
throw RuntimeError.NoIPAddressFound(message)
}
print(ip)
}
+3
View File
@@ -35,6 +35,9 @@ struct Login: AsyncParsableCommand {
let passwordData = FileHandle.standardInput.readDataToEndOfFile()
password = String(decoding: passwordData, as: UTF8.self)
// Support "echo $PASSWORD | tart login --username $USERNAME --password-stdin $REGISTRY"
password.trimSuffix { c in c.isNewline }
} else {
(user, password) = try StdinCredentials.retrieve()
}
+48 -4
View File
@@ -77,7 +77,50 @@ struct Prune: AsyncParsableCommand {
try prunablesToDelete.forEach { try $0.delete() }
}
static func pruneReclaim(reclaimBytes: UInt64) throws {
static func reclaimIfNeeded(_ requiredBytes: UInt64) throws {
SentrySDK.configureScope { scope in
scope.setContext(value: ["requiredBytes": requiredBytes], key: "Prune")
}
// Figure out how much disk space is available
let attrs = try Config().tartCacheDir.resourceValues(forKeys: [
.volumeAvailableCapacityKey,
.volumeAvailableCapacityForImportantUsageKey
])
let volumeAvailableCapacityCalculated = max(
UInt64(attrs.volumeAvailableCapacity!),
UInt64(attrs.volumeAvailableCapacityForImportantUsage!)
)
SentrySDK.configureScope { scope in
scope.setContext(value: [
"volumeAvailableCapacity": attrs.volumeAvailableCapacity!,
"volumeAvailableCapacityForImportantUsage": attrs.volumeAvailableCapacityForImportantUsage!,
"volumeAvailableCapacityCalculated": volumeAvailableCapacityCalculated
], key: "Prune")
}
if volumeAvailableCapacityCalculated <= 0 {
SentrySDK.capture(message: "Zero volume capacity reported") { scope in
scope.setLevel(.warning)
}
return
}
// Now that we know how much free space is left,
// check if we even need to reclaim anything
if requiredBytes < volumeAvailableCapacityCalculated {
return
}
try Prune.reclaimIfPossible(requiredBytes - volumeAvailableCapacityCalculated)
}
private static func reclaimIfPossible(_ reclaimBytes: UInt64) throws {
let transaction = SentrySDK.startTransaction(name: "Pruning cache", operation: "prune", bindToScope: true)
defer { transaction.finish() }
let prunableStorages: [PrunableStorage] = [VMStorageOCI(), try IPSWCache()]
let prunables: [Prunable] = try prunableStorages
.flatMap { try $0.prunables() }
@@ -98,10 +141,11 @@ struct Prune: AsyncParsableCommand {
break
}
cacheReclaimedBytes += try prunable.sizeBytes()
try prunable.delete()
try SentrySDK.span?.setData(value: prunable.sizeBytes(), key: prunable.url.path)
try SentrySDK.span?.setExtra(value: prunable.sizeBytes(), key: prunable.url.path);
cacheReclaimedBytes += try prunable.sizeBytes()
try prunable.delete()
}
SentrySDK.span?.setMeasurement(name: "gc_disk_reclaimed", value: cacheReclaimedBytes as NSNumber, unit: MeasurementUnitInformation.byte);
+44 -11
View File
@@ -6,7 +6,7 @@ import Compression
struct Push: AsyncParsableCommand {
static var configuration = CommandConfiguration(abstract: "Push a VM to a registry")
@Argument(help: "local VM name")
@Argument(help: "local or remote VM name")
var localName: String
@Argument(help: "remote VM name(s)")
@@ -28,7 +28,8 @@ struct Push: AsyncParsableCommand {
var populateCache: Bool = false
func run() async throws {
let localVMDir = try VMStorageLocal().open(localName)
let ociStorage = VMStorageOCI()
let localVMDir = try VMStorageHelper.open(localName)
// Parse remote names supplied by the user
let remoteNames = try remoteNames.map{
@@ -53,23 +54,55 @@ struct Push: AsyncParsableCommand {
defaultLogger.appendNewLine("pushing \(localName) to "
+ "\(registryIdentifier.host)/\(registryIdentifier.namespace)\(remoteNamesForRegistry.referenceNames())...")
let pushedRemoteName = try await localVMDir.pushToRegistry(
registry: registry,
references: remoteNamesForRegistry.map{ $0.reference.value },
chunkSizeMb: chunkSize
)
let references = remoteNamesForRegistry.map{ $0.reference.value }
// Populate the local cache (if requested)
let pushedRemoteName: RemoteName
// If we're pushing a local OCI VM, check if points to an already existing registry manifest
// and if so, only upload manifests (without config, disk and NVRAM) to the user-specified references
if let remoteName = try? RemoteName(localName) {
pushedRemoteName = try await lightweightPushToRegistry(
registry: registry,
remoteName: remoteName,
references: references
)
} else {
pushedRemoteName = try await localVMDir.pushToRegistry(
registry: registry,
references: references,
chunkSizeMb: chunkSize
)
// Populate the local cache (if requested)
if populateCache {
let expectedPushedVMDir = try ociStorage.create(pushedRemoteName)
try localVMDir.clone(to: expectedPushedVMDir, generateMAC: false)
}
}
// link the rest remote names
if populateCache {
let ociStorage = VMStorageOCI()
let expectedPushedVMDir = try ociStorage.create(pushedRemoteName)
try localVMDir.clone(to: expectedPushedVMDir, generateMAC: false)
for remoteName in remoteNamesForRegistry {
try ociStorage.link(from: remoteName, to: pushedRemoteName)
}
}
}
}
func lightweightPushToRegistry(registry: Registry, remoteName: RemoteName, references: [String]) async throws -> RemoteName {
// Is the local OCI VM already present in the registry?
let digest = try VMStorageOCI().digest(remoteName)
let (remoteManifest, _) = try await registry.pullManifest(reference: digest)
// Overwrite registry's references with the retrieved manifest
for reference in references {
defaultLogger.appendNewLine("pushing manifest for \(reference)...")
_ = try await registry.pushManifest(reference: reference, manifest: remoteManifest)
}
return RemoteName(host: registry.baseURL.host!, namespace: registry.namespace,
reference: Reference(digest: digest))
}
}
extension Collection where Element == RemoteName {
+65 -5
View File
@@ -1,4 +1,5 @@
import ArgumentParser
import Cocoa
import Dispatch
import SwiftUI
import Virtualization
@@ -208,7 +209,7 @@ struct Run: AsyncParsableCommand {
SentrySDK.capture(error: error)
SentrySDK.flush(timeout: 2.seconds.timeInterval)
print(error)
fputs("\(error)\n", stderr)
Foundation.exit(1)
}
@@ -391,6 +392,8 @@ struct Run: AsyncParsableCommand {
nsApp.applicationIconImage = NSImage(data: AppIconData)
struct MainApp: App {
@NSApplicationDelegateAdaptor private var appDelegate: MinimalMenuAppDelegate
var body: some Scene {
WindowGroup(vm!.name) {
Group {
@@ -405,7 +408,14 @@ struct Run: AsyncParsableCommand {
NSApplication.shared.terminate(self)
}
}
}.frame(width: CGFloat(vm!.config.display.width), height: CGFloat(vm!.config.display.height))
}.frame(
minWidth: CGFloat(vm!.config.display.width),
idealWidth: CGFloat(vm!.config.display.width),
maxWidth: .infinity,
minHeight: CGFloat(vm!.config.display.height),
idealHeight: CGFloat(vm!.config.display.height),
maxHeight: .infinity
)
}.commands {
// Remove some standard menu options
CommandGroup(replacing: .help, addition: {})
@@ -415,7 +425,18 @@ struct Run: AsyncParsableCommand {
CommandGroup(replacing: .undoRedo, addition: {})
CommandGroup(replacing: .windowSize, addition: {})
// Replace some standard menu options
CommandGroup(replacing: .appInfo) { AboutTart() }
CommandGroup(replacing: .appInfo) { AboutTart(config: vm!.config) }
CommandMenu("Control") {
Button("Start") {
Task { try await vm!.virtualMachine.start() }
}
Button("Stop") {
Task { try await vm!.virtualMachine.stop() }
}
Button("Request Stop") {
Task { try vm!.virtualMachine.requestStop() }
}
}
}
}
}
@@ -424,14 +445,42 @@ struct Run: AsyncParsableCommand {
}
}
// The only way to fully remove Edit menu item.
class MinimalMenuAppDelegate: NSObject, NSApplicationDelegate, ObservableObject {
let indexOfEditMenu = 2
func applicationDidFinishLaunching(_ : Notification) {
NSApplication.shared.mainMenu?.removeItem(at: indexOfEditMenu)
}
}
struct AboutTart: View {
var credits: NSAttributedString
init(config: VMConfig) {
let mutableAttrStr = NSMutableAttributedString()
let style = NSMutableParagraphStyle()
style.alignment = NSTextAlignment.center
let attrCenter: [NSAttributedString.Key : Any] = [
.paragraphStyle: style,
]
mutableAttrStr.append(NSAttributedString(string: "CPU: \(config.cpuCount) cores\n", attributes: attrCenter))
mutableAttrStr.append(NSAttributedString(string: "Memory: \(config.memorySize / 1024 / 1024) MB\n", attributes: attrCenter))
mutableAttrStr.append(NSAttributedString(string: "Display: \(config.display.description)\n", attributes: attrCenter))
mutableAttrStr.append(NSAttributedString(string: "https://github.com/cirruslabs/tart", attributes: [
.paragraphStyle: style,
.link : "https://github.com/cirruslabs/tart"
]))
credits = mutableAttrStr
}
var body: some View {
Button("About Tart") {
NSApplication.shared.orderFrontStandardAboutPanel(options: [
NSApplication.AboutPanelOptionKey.applicationIcon: NSApplication.shared.applicationIconImage as Any,
NSApplication.AboutPanelOptionKey.applicationName: "Tart",
NSApplication.AboutPanelOptionKey.applicationVersion: CI.version,
NSApplication.AboutPanelOptionKey.credits: try! NSAttributedString(markdown: "https://github.com/cirruslabs/tart"),
NSApplication.AboutPanelOptionKey.credits: credits,
])
}
}
@@ -444,7 +493,18 @@ struct VMView: NSViewRepresentable {
func makeNSView(context: Context) -> NSViewType {
let machineView = VZVirtualMachineView()
machineView.capturesSystemKeys = true
// Do not capture system keys so that shortcuts like
// Shift-Command-4 + Space (capture a screenshot of window)
// work on the host instead of the guest
machineView.capturesSystemKeys = false
// Enable automatic display reconfiguration
// for guests that support it
if #available(macOS 14.0, *) {
machineView.automaticallyReconfiguresDisplay = true
}
return machineView
}
+37
View File
@@ -0,0 +1,37 @@
import Foundation
import Sysctl
class DeviceInfo {
private static var osMemoized: String? = nil
private static var modelMemoized: String? = nil
static var os: String {
if let os = osMemoized {
return os
}
osMemoized = getOS()
return osMemoized!
}
static var model: String {
if let model = modelMemoized {
return model
}
modelMemoized = getModel()
return modelMemoized!
}
private static func getOS() -> String {
let osVersion = ProcessInfo.processInfo.operatingSystemVersion
return "macOS \(osVersion.majorVersion).\(osVersion.minorVersion).\(osVersion.patchVersion)"
}
private static func getModel() -> String {
return SystemControl().hardware.model
}
}
+13 -3
View File
@@ -45,7 +45,8 @@ struct TokenResponse: Decodable, Authentication {
let defaultIssuedAt = Date()
let defaultExpiresIn = 60
var token: String
var token: String?
var accessToken: String?
var expiresIn: Int?
var issuedAt: Date?
@@ -65,7 +66,13 @@ struct TokenResponse: Decodable, Authentication {
return dateFormatter.date(from: dateString) ?? Date()
}
return try decoder.decode(TokenResponse.self, from: fromData)
let response = try decoder.decode(TokenResponse.self, from: fromData)
guard response.token != nil || response.accessToken != nil else {
throw DecodingError.keyNotFound(CodingKeys.token, .init(codingPath: [], debugDescription: "Missing token or access_token. One must be present."))
}
return response
}
var tokenExpiresAt: Date {
@@ -83,7 +90,7 @@ struct TokenResponse: Decodable, Authentication {
}
func header() -> (String, String) {
("Authorization", "Bearer \(token)")
return ("Authorization", "Bearer \(token ?? accessToken ?? "")")
}
func isValid() -> Bool {
@@ -387,6 +394,9 @@ class Registry {
request.addValue(value, forHTTPHeaderField: name)
}
request.setValue("Tart/\(CI.version) (\(DeviceInfo.os); \(DeviceInfo.model))",
forHTTPHeaderField: "User-Agent")
return try await Fetcher.fetch(request, viaFile: viaFile)
}
}
+24 -3
View File
@@ -1,5 +1,11 @@
import Virtualization
struct UnsupportedHostOSError: Error, CustomStringConvertible {
var description: String {
"error: host macOS version is outdated to run this virtual machine"
}
}
struct Darwin: Platform {
var ecid: VZMacMachineIdentifier
var hardwareModel: VZMacHardwareModel
@@ -50,11 +56,18 @@ struct Darwin: Platform {
VZMacOSBootLoader()
}
func platform(nvramURL: URL) -> VZPlatformConfiguration {
func platform(nvramURL: URL) throws -> VZPlatformConfiguration {
let result = VZMacPlatformConfiguration()
result.machineIdentifier = ecid
result.auxiliaryStorage = VZMacAuxiliaryStorage(contentsOf: nvramURL)
if !hardwareModel.isSupported {
// At the moment support of M1 chip is not yet dropped in any macOS version
// This mean that host software is not supporting this hardware model and should be updated
throw UnsupportedHostOSError()
}
result.hardwareModel = hardwareModel
return result
@@ -85,10 +98,18 @@ struct Darwin: Platform {
return result
}
func keyboards() -> [VZKeyboardConfiguration] {
if #available(macOS 14, *) {
// Mac keyboard is only supported by guests starting with macOS Ventura
return [VZMacKeyboardConfiguration(), VZUSBKeyboardConfiguration()]
} else {
return [VZUSBKeyboardConfiguration()]
}
}
func pointingDevices() -> [VZPointingDeviceConfiguration] {
if #available(macOS 13, *) {
// Trackpad is only supported starting with macOS Ventura
// macOS Monterey will continue using a USB device == .darwin
// Trackpad is only supported by guests starting with macOS Ventura
return [VZMacTrackpadConfiguration(), VZUSBScreenCoordinatePointingDeviceConfiguration()]
} else {
return [VZUSBScreenCoordinatePointingDeviceConfiguration()]
+5 -1
View File
@@ -14,7 +14,7 @@ struct Linux: Platform {
return result
}
func platform(nvramURL: URL) -> VZPlatformConfiguration {
func platform(nvramURL: URL) throws -> VZPlatformConfiguration {
VZGenericPlatformConfiguration()
}
@@ -31,6 +31,10 @@ struct Linux: Platform {
return result
}
func keyboards() -> [VZKeyboardConfiguration] {
[VZUSBKeyboardConfiguration()]
}
func pointingDevices() -> [VZPointingDeviceConfiguration] {
[VZUSBScreenCoordinatePointingDeviceConfiguration()]
}
+2 -1
View File
@@ -3,7 +3,8 @@ import Virtualization
protocol Platform: Codable {
func os() -> OS
func bootLoader(nvramURL: URL) throws -> VZBootLoader
func platform(nvramURL: URL) -> VZPlatformConfiguration
func platform(nvramURL: URL) throws -> VZPlatformConfiguration
func graphicsDevice(vmConfig: VMConfig) -> VZGraphicsDeviceConfiguration
func keyboards() -> [VZKeyboardConfiguration]
func pointingDevices() -> [VZPointingDeviceConfiguration]
}
+1 -1
View File
@@ -94,7 +94,7 @@ struct Root: AsyncParsableCommand {
// Handle a non-ArgumentParser's exception that requires a specific exit code to be set
if let errorWithExitCode = error as? HasExitCode {
print(error)
fputs("\(error)\n", stderr)
Foundation.exit(errorWithExitCode.exitCode)
}
+11 -19
View File
@@ -5,34 +5,26 @@ import Dynamic
// Kudos to @saagarjha's VirtualApple for finding about _VZVirtualMachineStartOptions
extension VZVirtualMachine {
@available(macOS 12, *)
@MainActor @available(macOS 12, *)
func start(_ recovery: Bool) async throws {
if !recovery {
// just use the regular API
return try await withCheckedThrowingContinuation { continuation in
DispatchQueue.main.async {
self.start(completionHandler: { result in
continuation.resume(with: result)
})
}
}
return try await self.start()
}
// use some private stuff only for recovery
return try await withCheckedThrowingContinuation { (continuation: CheckedContinuation<Void, Error>) in
DispatchQueue.main.async {
let handler: @convention(block) (_ result: Any?) -> Void = { result in
if let error = result as? Error {
continuation.resume(throwing: error)
} else {
continuation.resume(returning: ())
}
let handler: @convention(block) (_ result: Any?) -> Void = { result in
if let error = result as? Error {
continuation.resume(throwing: error)
} else {
continuation.resume(returning: ())
}
// dynamic magic
let options = Dynamic._VZVirtualMachineStartOptions()
options.bootMacOSRecovery = recovery
Dynamic(self)._start(withOptions: options, completionHandler: handler)
}
// dynamic magic
let options = Dynamic._VZVirtualMachineStartOptions()
options.bootMacOSRecovery = recovery
Dynamic(self)._start(withOptions: options, completionHandler: handler)
}
}
}
+23 -24
View File
@@ -223,24 +223,9 @@ class VM: NSObject, VZVirtualMachineDelegate, ObservableObject {
func run(_ recovery: Bool) async throws {
try network.run(sema)
let startTask = DispatchQueue.main.sync {
Task {
if #available(macOS 13, *) {
// new API introduced in Ventura
let startOptions = VZMacOSVirtualMachineStartOptions()
startOptions.startUpFromMacOSRecovery = recovery
try await virtualMachine.start(options: startOptions)
} else {
// use method that also available on Monterey
try await virtualMachine.start(recovery)
}
}
}
try await withTaskCancellationHandler(operation: {
// Await on VZVirtualMachine.start() result
_ = try await startTask.value
try await start(recovery)
await withTaskCancellationHandler(operation: {
// Wait for the VM to finish running
// or for the exit condition
sema.wait()
@@ -249,16 +234,30 @@ class VM: NSObject, VZVirtualMachineDelegate, ObservableObject {
})
if Task.isCancelled {
DispatchQueue.main.sync {
Task {
try await self.virtualMachine.stop()
}
}
try await stop()
}
try await network.stop()
}
@MainActor
private func start(_ recovery: Bool) async throws {
if #available(macOS 13, *) {
// new API introduced in Ventura
let startOptions = VZMacOSVirtualMachineStartOptions()
startOptions.startUpFromMacOSRecovery = recovery
try await virtualMachine.start(options: startOptions)
} else {
// use method that also available on Monterey
try await virtualMachine.start(recovery)
}
}
@MainActor
private func stop() async throws {
try await self.virtualMachine.stop()
}
static func craftConfiguration(
diskURL: URL,
nvramURL: URL,
@@ -278,7 +277,7 @@ class VM: NSObject, VZVirtualMachineDelegate, ObservableObject {
configuration.memorySize = vmConfig.memorySize
// Platform
configuration.platform = vmConfig.platform.platform(nvramURL: nvramURL)
configuration.platform = try vmConfig.platform.platform(nvramURL: nvramURL)
// Display
configuration.graphicsDevices = [vmConfig.platform.graphicsDevice(vmConfig: vmConfig)]
@@ -293,7 +292,7 @@ class VM: NSObject, VZVirtualMachineDelegate, ObservableObject {
configuration.audioDevices = [soundDeviceConfiguration]
// Keyboard and mouse
configuration.keyboards = [VZUSBKeyboardConfiguration()]
configuration.keyboards = vmConfig.platform.keyboards()
configuration.pointingDevices = vmConfig.platform.pointingDevices()
// Networking
+2 -2
View File
@@ -55,9 +55,9 @@ struct VMDirectory: Prunable {
try? FileManager.default.removeItem(at: nvramURL)
}
func validate() throws {
func validate(userFriendlyName: String) throws {
if !FileManager.default.fileExists(atPath: baseURL.path) {
throw RuntimeError.VMDoesNotExist(name: baseURL.lastPathComponent)
throw RuntimeError.VMDoesNotExist(name: userFriendlyName)
}
if !initialized {
+3
View File
@@ -57,6 +57,7 @@ enum RuntimeError : Error {
case ExportFailed(_ message: String)
case ImportFailed(_ message: String)
case SoftnetFailed(_ message: String)
case OCIStorageError(_ message: String)
}
protocol HasExitCode {
@@ -98,6 +99,8 @@ extension RuntimeError : CustomStringConvertible {
return "VM import failed: \(message)"
case .SoftnetFailed(let message):
return "Softnet failed: \(message)"
case .OCIStorageError(let message):
return "OCI storage error: \(message)"
}
}
}
+1 -1
View File
@@ -14,7 +14,7 @@ class VMStorageLocal {
func open(_ name: String) throws -> VMDirectory {
let vmDir = VMDirectory(baseURL: vmURL(name))
try vmDir.validate()
try vmDir.validate(userFriendlyName: name)
return vmDir
}
+34 -28
View File
@@ -16,10 +16,20 @@ class VMStorageOCI: PrunableStorage {
VMDirectory(baseURL: vmURL(name)).initialized
}
func digest(_ name: RemoteName) throws -> String {
let digest = vmURL(name).resolvingSymlinksInPath().lastPathComponent
if !digest.starts(with: "sha256:") {
throw RuntimeError.OCIStorageError("\(name) is not a digest and doesn't point to a digest")
}
return digest
}
func open(_ name: RemoteName) throws -> VMDirectory {
let vmDir = VMDirectory(baseURL: vmURL(name))
try vmDir.validate()
try vmDir.validate(userFriendlyName: name.description)
try vmDir.baseURL.updateAccessDate()
@@ -123,6 +133,10 @@ class VMStorageOCI: PrunableStorage {
}
func pull(_ name: RemoteName, registry: Registry) async throws {
SentrySDK.configureScope { scope in
scope.setContext(value: ["imageName": name], key: "OCI")
}
defaultLogger.appendNewLine("pulling manifest...")
let (manifest, manifestData) = try await registry.pullManifest(reference: name.reference.value)
@@ -130,6 +144,12 @@ class VMStorageOCI: PrunableStorage {
let digestName = RemoteName(host: name.host, namespace: name.namespace,
reference: Reference(digest: Digest.hash(manifestData)))
if exists(name) && exists(digestName) && linked(from: name, to: digestName) {
// optimistically check if we need to do anything at all before locking
defaultLogger.appendNewLine("\(digestName) image is already cached and linked!")
return
}
// Ensure that host directory for given RemoteName exists in OCI storage
let hostDirectoryURL = hostDirectoryURL(digestName)
try FileManager.default.createDirectory(at: hostDirectoryURL, withIntermediateDirectories: true)
@@ -158,36 +178,13 @@ class VMStorageOCI: PrunableStorage {
// Try to reclaim some cache space if we know the VM size in advance
if let uncompressedDiskSize = manifest.uncompressedDiskSize() {
let requiredCapacityBytes = UInt64(uncompressedDiskSize + 128 * 1024 * 1024)
let attrs = try Config().tartCacheDir.resourceValues(forKeys: [.volumeAvailableCapacityForImportantUsageKey, .volumeAvailableCapacityKey])
let capacityImportant = attrs.volumeAvailableCapacityForImportantUsage!
let capacityAvailable = attrs.volumeAvailableCapacity!
let availableCapacityBytes = max(UInt64(capacityImportant), UInt64(capacityAvailable))
if capacityImportant == 0 || capacityAvailable == 0 {
SentrySDK.capture(message: "Zero capacity") { scope in
scope.setLevel(.warning)
scope.setContext(value: [
"volumeAvailableCapacityForImportantUsageKey": capacityImportant,
"volumeAvailableCapacityKey": capacityAvailable,
], key: "Attributes")
}
SentrySDK.configureScope { scope in
scope.setContext(value: ["imageUncompressedDiskSize": uncompressedDiskSize], key: "OCI")
}
// There is a suspicious that occasionally capacity is returned as zero which can't be true.
// Let's validate to avoid unnecessary pruning.
if 0 < availableCapacityBytes && availableCapacityBytes < requiredCapacityBytes {
let transaction = SentrySDK.startTransaction(name: "Automatically Pruning Cache", operation: "prune", bindToScope: true)
transaction.setData(value: name, key: "name")
transaction.setData(value: uncompressedDiskSize, key: "uncompressedDiskSize")
transaction.setData(value: availableCapacityBytes, key: "availableCapacity")
transaction.setData(value: requiredCapacityBytes, key: "requiredCapacity")
defer { transaction.finish() }
let otherVMFilesSize: UInt64 = 128 * 1024 * 1024
try Prune.pruneReclaim(reclaimBytes: requiredCapacityBytes - availableCapacityBytes)
}
try Prune.reclaimIfNeeded(uncompressedDiskSize + otherVMFilesSize)
}
try await withTaskCancellationHandler(operation: {
@@ -212,6 +209,15 @@ class VMStorageOCI: PrunableStorage {
}
}
func linked(from: RemoteName, to: RemoteName) -> Bool {
do {
let resolvedFrom = try FileManager.default.destinationOfSymbolicLink(atPath: vmURL(from).path)
return resolvedFrom == vmURL(to).path
} catch {
return false
}
}
func link(from: RemoteName, to: RemoteName) throws {
if FileManager.default.fileExists(atPath: vmURL(from).path) {
try FileManager.default.removeItem(at: vmURL(from))
Binary file not shown.
Binary file not shown.

After

Width:  |  Height:  |  Size: 175 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 33 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 23 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 23 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 11 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 65 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 9.9 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 23 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 12 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 84 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 30 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 6.1 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 3.1 KiB

@@ -13,7 +13,7 @@ categories:
**TLDR:** We are transitioning Tart's licensing from AGPL-3.0 to [Fair Source 100](https://fair.io/). This change will
permit unlimited installations on personal computers, but organizations that exceed a certain number of server
installations utilizing 100 CPU cores will be required to obtain a paid sponsorship.
installations utilizing 100 CPU cores will be required to obtain a paid license.
## Background
@@ -55,15 +55,15 @@ of Tart virtual machines on a cluster of Apple Silicon servers. Concurrently, we
which will establish a stable API and offer long-term support under a new Fair Source 100 license.
The Fair Source 100 license for Tart means that once a certain threshold of server installations utilizing 100 CPU cores
is exceeded, a paid sponsorship will be required. A "server installation" refers to the installation of Tart on a physical
is exceeded, a paid license will be required. A "server installation" refers to the installation of Tart on a physical
device without a physical display connected. For example, a Mac Mini with a HDMI Dummy Plug is considered a server,
but a Mac Mini on a desk with a connected physical display is considered a personal computer. **Usage on personal computers
and before reaching the 100 CPU cores limit is royalty-free and does not have the viral properties of AGPL.**
When an organization surpasses the 100 CPU cores limit, they will be required to obtain a [Gold Sponsorship](/licensing#sponsorships),
which costs \$1000 per month. Upon reaching a limit of 500 CPU cores, a [Platinum Sponsorship](/licensing#sponsorships)
(\$5000 per month) will be required, and for organizations that exceed 5000 CPU cores, a custom [Diamond Sponsorship](/licensing#sponsorships)
(\$1 per core per month) will be necessary. **All sponsorships will include priority feature development and SLAs on support with urgent issues.**
When an organization surpasses the 100 CPU cores limit, they will be required to obtain a [Gold Tier License](/licensing#license-tiers),
which costs \$1000 per month. Upon reaching a limit of 500 CPU cores, a [Platinum Tier License](/licensing#license-tiers)
(\$5000 per month) will be required, and for organizations that exceed 5000 CPU cores, a custom [Diamond Tier License](/licensing#license-tiers)
(\$1 per core per month) will be necessary. **All paid license tiers will include priority feature development and SLAs on support with urgent issues.**
## Have we considered alternatives?
+94
View File
@@ -0,0 +1,94 @@
---
draft: false
date: 2023-04-25
search:
exclude: true
authors:
- fkorotkov
categories:
- announcement
- orchard
---
# Announcing Orchard orchestration for managing macOS virtual machines at scale
Today we are happy to announce general availability of Orchard – our new orchestrator to manage Tart virtual machines at scale.
In this post we’ll cover the motivation behind creating yet another orchestrator and why we didn’t go with Kubernetes or Nomad integration.
## What problem are we trying to solve?
After releasing Tart we pretty quickly started getting requests about managing macOS virtual machines on a cluster of
Apple Silicon machines rather than just a single host which only allows a maximum of two virtual machines at a time.
By the end of 2022 the requests reached a tipping point, and we started planning.
<!-- more -->
First, we established some constraints about the end users and potential workload our solution should handle.
Running macOS or Linux virtual machines on Apple Silicon is a very niche use case. These VMs are either used in
automation solutions like CI/CD or for managing remote desktop environments. In this case **we are aiming to manage
only thousands of virtual machines and not millions**.
Second, **operators of such solutions won’t have experience of operating Kubernetes or Nomad**. Operators will most likely
come with experience of using such systems but not managing them. And again, having built-in things like RBAC and
ability to scale to millions were appealing but it seemed like it would be a solution for a few rather than a solution
for everybody to use. Additionally Orchard should provide **first class support for accessing virtual machines over SSH/VNC**
and support script execution.
By that time, the idea of building a simple opinionated orchestrator got more and more appealing. Plus we kind of already did it
for [Cirrus CI’s persistent workers](https://cirrus-ci.org/guide/persistent-workers/) feature.
## Technical constraints
With the UX constraints and expectations in place we started thinking about architecture for the orchestrator that we
started calling **Orchard**.
<script src="https://unpkg.com/@dotlottie/player-component@latest/dist/dotlottie-player.js"></script>
<dotlottie-player
src="/assets/animations/Orchard.lottie"
mode="normal"
style="width: 100%; height: 360px; margin: auto; background-color: rgb(5 62 94)"
autoplay
loop
/>
Since Orchard will manage a maximum of a couple thousands virtual machines and not millions we **decided to not think much
about horizontal scalability.** Just a single instance of Orchard controller should be enough if it can restart quickly and
persist state between restarts.
**Orchard should be secure by default**. All the communication between a controller and workers should be secure.
All external API requests to Orchard controller should be authorized.
During development it’s crucial to have a quick feedback cycle. **It should be extremely easy to run Orchard in development**.
Configuring a production cluster should be also easy for novice operators.
## High-level implementation details
Cirrus Labs started as a predominantly Kotlin shop with a little Go. But over the years we gradually moved a lot of things to Go.
We love the expressibility of Kotlin as a language but the ecosystem for writing system utilities and services is superb in Go.
Orchard is a single Go project that implements both controller server interface and worker client logic in a single repository.
This simplifies code sharing and testability of the both components and allows to change them in a single pull request.
Another benefit is that Orchard can be distributed as a single binary. We intend to run Orchard controller on a single host.
Data model for the orchestration didn’t look complex as well. These observations lead us to exploring the use of an embedded database.
Just imagine! **Orchard can be distributed as a single binary with no external dependencies on any database or runtime!**
And we did exactly that! Orchard is distributed as a single binary that can be run in “controller” mode on a Linux/macOS host and
in “worker” mode on macOS hosts. Orchard controller is using extremely fast [BadgerDB](https://dgraph.io/docs/badger/) key-value storage to persist data.
## Conclusion
Please give [Orchard](https://github.com/cirruslabs/orchard) a try! To run it locally in development mode on any Apple Silicon device
please run the following command:
```bash
brew install cirruslabs/cli/orchard
orchard dev
```
This will launch a development cluster with a single worker on your machine. Refer to [Orchard documentation](https://github.com/cirruslabs/orchard#creating-virtual-machines)
on how to create your first virtual machine and access it.
In a [separate blog post](/blog/2023/04/28/ssh-over-grpc-or-how-orchard-simplifies-accessing-vms-in-private-networks/)
we’ll cover how Orchard implements seamless SSH access over a gRPC connection. Stay tuned and please don’t hesitate to
[reach out](https://github.com/cirruslabs/orchard/discussions/landing)!
@@ -0,0 +1,115 @@
---
draft: false
date: 2023-04-28
search:
exclude: true
authors:
- edigaryev
categories:
- orchard
---
# SSH over gRPC or how Orchard simplifies accessing VMs in private networks
We started developing [Orchard](https://github.com/cirruslabs/orchard), an orchestrator for [Tart](https://tart.run/), with the requirement that it should allow users to access virtual machines running on worker nodes in private networks that users might not have access to.
At the same time, we wanted to enable users to access VMs on these remote workers just as easily as they’d access network services on their local Tart VMs.
While these features sound great on paper, they pose a technical problem: how do we connect to the remote workers, let alone VMs running on these workers, if we can’t assume that these workers will be easily reachable? And how do we establish an SSH connection with a VM running on a remote worker through all these hoops?
<!-- more -->
## Implementing port forwarding: gRPC to the rescue
We need to keep a full-duplex connection with the controller for the port-forwarding to work, and the two obvious protocol options are:
- WebSocket API through a new controller’s REST API endpoint
- gRPC using `Content-Type` differentiation
We’ve chosen the gRPC for controller ↔︎ worker connection, simply because it requires less code on our side and it will only be used internally, which means we don’t need to document it as extensively as our REST API. In essence, port forwarding is streaming of bytes of a connection in both ways, so gRPC streams looked like a natural solution. The resulting protocol is dead simple:
```Protobuf
service Controller {
rpc Watch(google.protobuf.Empty) returns (stream WatchInstruction);
rpc PortForward(stream PortForwardData) returns (stream PortForwardData);
}
message WatchInstruction {
message PortForward {
string session = 1;
string vm_uid = 2;
uint32 vm_port = 3;
}
oneof action {
PortForward port_forward_action = 1;
}
}
message PortForwardData {
bytes data = 1;
}
```
On bootstrap, each Orchard worker establishes a `Watch()` RPC stream and waits for the `PortForward` instruction from the controller indefinitely. This long-running session might be used not just for port-forwarding, but for notifying the workers about changed resources, which results in workers picking up your VM for execution instantly.
Once `PortForward` instruction is received, the worker connects to the specified VM and port locally and opens a new `PortForward()` RPC stream with the controller, carrying the unique `session` identifier in the gRPC metadata to help distinguish several port forwarding requests.
We’re using a pretty ingenious Golang package that turns any gRPC stream into a `net.Conn`: https://github.com/mitchellh/go-grpc-net-conn. This allows us to abstract from the gRPC details and simply proxy two `net.Conns`, thus providing the port forwarding functionality.
We’ve also initially considered using [Yamux](https://github.com/hashicorp/yamux) to only keep a single connection with each worker, however, that involves the burden of dealing with flow control and potential implementation bugs associated with it, so we’ve decided to simply open an additional connection for each port forwarding session and let the OS deal with it.
## Building on top of the port-forwarding
First of all, we’ve made the new port-forwarding functionality available for integrations via the Orchard’s REST API:
![OpenAPI documentation for Orchard's port-forwarding endpoint](/assets/images/orchard-port-forwarding-api.png)
All you need is to use a WebSocket client when accessing this endpoint to make it work.
Secondly, we’ve exposed three commands in the Orchard CLI that all use this endpoint:
### `orchard port-forward`
Opens a TCP port locally and forwards everything sent to it to the specified VM (and vice versa).
For example, `orchard port-forward vm ventura-builder 2222:22` will forward traffic from the local TCP port `2222` to the `ventura-builder` VM’s TCP port `22`.
### `orchard ssh`
Connects to the specified VM on the default SSH port `22`, optionally only launching a command (if specified), similarly to what the official OpenSSH client does.
For example, `orchard ssh vm ventura-builder` will open an interactive session with the `ventura-builder` VM.
You can also send local scripts for execution by utilizing redirection:
```shell
orchard ssh vm ventura-builder 'sh -s' < script.sh
```
### `orchard vnc`
Establishes a port forwarding to the specified VM’s default VNC port `5900` and opens the default macOS Screen Sharing app.
For example, `orchard vnc vm ventura-builder` will establish a port-forwarding to the `ventura-builder` VM's port `5900` under the hood and launch macOS Screen Sharing app.
Note that the SSH and VNC commands expect the VM resource to specify credentials in it’s definition (can be done via `orchard create vm`), and will otherwise fall back to the credentials specified by `--username` and `--password`, or if none specified — to de-facto standard of `admin:admin` credentials.
## Conclusion
Overall, the technology described in this article somewhat resembles what [we previously did for Cirrus Terminal](https://cirrus-ci.org/blog/2021/08/06/introducing-cirrus-terminal-a-simple-way-to-get-ssh-like-access-to-your-tasks/). The only difference is that in Cirrus Terminal we carry terminal-specific characters, and in Orchard — we carry bytes for an arbitrary TCP connection.
We really hope this feature will be useful for many, just as the Cirrus Terminal, and that it will remove the pain of scaling Tart beyond a single machine.
You can give [Orchard](https://github.com/cirruslabs/orchard) a try by running it locally in development mode on any Apple Silicon device:
```bash
brew install cirruslabs/cli/orchard
orchard dev
```
This will launch a development cluster with a single worker on your machine. Refer to [Orchard documentation](https://github.com/cirruslabs/orchard#creating-virtual-machines)
on how to create your first virtual machine and access it.
Stay tuned and don’t hesitate to send us your feedback either [on GitHub](https://github.com/cirruslabs/orchard) or [Twitter](https://twitter.com/cirrus_labs)!
+17 -5
View File
@@ -31,7 +31,7 @@ please first make sure that the service is binded to `0.0.0.0`.
Then from within a virtual machine you can access the service using the router's IP address that you can get either from `Preferences -> Network`
or by running the following command in the Terminal:
```bash
```shell
netstat -nr | grep default | head -n 1 | awk '{print $2}'
```
@@ -43,7 +43,7 @@ is stricter and it's not only possible to access the host.
To change the default network to `192.168.77.1`:
```bash
```shell
sudo defaults write /Library/Preferences/SystemConfiguration/com.apple.vmnet.plist Shared_Net_Address -string 192.168.77.1
```
@@ -51,6 +51,18 @@ Note that even through a network would normally be specified as `192.168.77.0`,
The default subnet mask `255.255.255.0` should suffice for most use-cases, however, you can also change it to `255.255.0.0`, for example:
```bash
sudo defaults write /Library/Preferences/SystemConfiguration/com.apple.vmnet.plist Shared_Net_Mask -string 255.255.0.0
```
```shell
sudo defaults write /Library/Preferences/SystemConfiguration/com.apple.vmnet.plist Shared_Net_Mask -string 255.255.0.0
```
## Changing the default DHCP lease time
By default, the built-in macOS DHCP server allocates IP-addresses to the VMs for the duration of 86,400 seconds (one day), which may easily cause DHCP exhaustion if you run more than ~253 VMs per day, or in other words, more than one VM every ~6 minutes.
This issue is worked around automatically [when using Softnet](http://github.com/cirruslabs/softnet), however, if you don't use or can't use it, the following command will reduce the lease time from the default 86,400 seconds (one day) to 600 seconds (10 minutes):
```shell
sudo defaults write /Library/Preferences/SystemConfiguration/com.apple.InternetSharing.default.plist bootpd -dict DHCPLeaseTimeSecs -int 600
```
Note that this tweak persists across reboots, so normally you'll only need to do it once per new host.
+49
View File
@@ -0,0 +1,49 @@
# GitLab Runner Executor
It is possible to run GitLab jobs in isolated ephemeral Tart Virtual Machines via [Tart Executor](https://github.com/cirruslabs/gitlab-tart-executor).
Tart Executor utilizes [custom executor](https://docs.gitlab.com/runner/executors/custom.html) feature of GitLab Runner.
# Basic Configuration
Configuring Tart Executor for GitLab Runner is as simple as installing `gitlab-tart-executor` binary from Homebrew:
```bash
brew install cirruslabs/cli/gitlab-tart-executor
```
And updating configuration of your self-hosted GitLab Runner to use `gitlab-tart-executor` binary:
```toml
concurrent = 2
[[runners]]
# ...
executor = "custom"
builds_dir = "/Users/admin/builds" # directory inside the
cache_dir = "/Users/admin/cache"
[runners.feature_flags]
FF_RESOLVE_FULL_TLS_CHAIN = false
[runners.custom]
prepare_exec = "gitlab-tart-executor"
prepare_args = ["prepare"]
run_exec = "gitlab-tart-executor"
run_args = ["run"]
cleanup_exec = "gitlab-tart-executor"
cleanup_args = ["cleanup"]
```
Now you can use Tart Images in your `.gitlab-ci.yml`:
```yaml
# You can use any remote Tart Image.
# Tart Executor will pull it from the registry and use it for creating ephemeral VMs.
image: ghcr.io/cirruslabs/macos-ventura-base:latest
test:
tags:
- tart-installed # in case you tagged runners with Tart Executor installed
script:
- uname -a
```
For more advanced configuration please refer to [GitLab Tart Executor repository](https://github.com/cirruslabs/gitlab-tart-executor).
+13 -12
View File
@@ -3,9 +3,10 @@ hide:
- navigation
---
Both [Tart Virtualization](https://github.com/cirruslabs/tart) and **Orchard Orchestration** (coming soon)
are licensed under [Fair Source 100 License](https://fair.io/). Usage on personal computers including personal workstations is royalty-free,
but organizations that exceed a certain number of server installations utilizing 100 CPU cores will be required to obtain a paid sponsorship.
Both [Tart Virtualization](https://github.com/cirruslabs/tart) and [Orchard Orchestration](https://github.com/cirruslabs/orchard)
are licensed under [Fair Source License](https://fair.io/). Usage on personal computers including personal workstations is royalty-free,
but organizations that exceed a certain number of server installations (100 CPU cores for Tart and/or 4 hosts for Orchard)
will be required to obtain a paid license.
??? note "Performance and Efficiency Cores"
The virtual CPU cores in Tart VMs do not differentiate between the high-performance and high-efficient cores
@@ -13,27 +14,27 @@ but organizations that exceed a certain number of server installations utilizing
being executed within the virtual machines. As a result, both performance and energy-efficient cores of the host CPU
are treated equally in terms of licensing.
# Sponsorships
# License Tiers
When an organization surpasses the 100 CPU cores limit, it is required to obtain a Gold Sponsorship, which costs \$1000 per month.
Upon reaching a limit of 500 CPU cores, a Platinum Sponsorship (\$5000 per month) will be required, and for organizations
that exceed 5000 CPU cores, a custom Diamond Sponsorship (\$1 per core per month) will be necessary.
When an organization surpasses the 100 CPU cores limit, it is required to obtain a Gold Tier License, which costs \$1000 per month.
Upon reaching a limit of 500 CPU cores, a Platinum Tier License (\$5000 per month) will be required, and for organizations
that exceed 5000 CPU cores, a custom Diamond Tier License (\$1 per core per month) will be necessary.
If your organization is interested in purchasing one of the sponsorships, please email [licensing@cirruslabs.org](mailto:licensing@cirruslabs.org).
You can see a template of a sponsorship subscription agreement [here](assets/TartSponsorshipSubscriptionTemplate.pdf).
If your organization is interested in purchasing one of the license tiers, please email [licensing@cirruslabs.org](mailto:licensing@cirruslabs.org).
You can see a template of a license subscription agreement [here](assets/TartLicenseSubscription.pdf).
# General Support
The best way to ask general questions about particular use cases is to email our support team at [support@cirruslabs.org](mailto:support@cirruslabs.org).
Our support team is trying our best to respond ASAP, but there is no guarantee on a response time unless your organization
has a sponsorship subscription which includes [Priority Support](#priority-support).
has a paid license subscription which includes [Priority Support](#priority-support).
If you have a feature request or noticed lack of some documentation please feel free to [create a GitHub issue](https://github.com/cirruslabs/tart/issues/new).
Our support team will answer it by replying to the issue or by updating the documentation.
# Priority Support
In addition to the general support we provide a *Priority Support* with guaranteed response times included in all the paid sponsorships .
In addition to the general support we provide a *Priority Support* with guaranteed response times included in all the paid license tiers.
| Severity | Support Impact | First Response Time SLA | Hours | How to Submit |
|----------|-----------------------------------------------------------------------------------------------|-------------------------|-------|--------------------------------------------------------------------------------------------------|
@@ -56,5 +57,5 @@ In addition to the general support we provide a *Priority Support* with guarante
Information, an enhancement, or documentation clarification is requested, but there is no impact on the operation of Tart and/or Orchard.
!!! info "How to submit a priority or an urgent issue"
Once your organization [signs the Sponsorship Subscription contract](#sponsorships), members of your organization
Once your organization [obtains a license](#license-tiers), members of your organization
will get access to separate support emails specified in your subscription contract.
+14 -1
View File
@@ -11,6 +11,19 @@ tart clone ghcr.io/cirruslabs/macos-ventura-base:latest ventura-base
tart run ventura-base
```
??? info "Manual installation from a release archive"
It's also possible to manually install `tart` binary from the latest released archive:
```bash
curl -LO https://github.com/cirruslabs/tart/releases/latest/download/tart.tar.gz
tar -xzvf tart.tar.gz
./tart.app/Contents/MacOS/tart clone ghcr.io/cirruslabs/macos-ventura-base:latest ventura-base
./tart.app/Contents/MacOS/tart run ventura-base
```
Please note that `./tart.app/Contents/MacOS/tart` binary is required to be used in order to trick macOS
to pick `tart.app/Contents/embedded.provisionprofile` for elevated privileges that Tart needs.
<p align="center">
<img src="https://github.com/cirruslabs/tart/raw/main/Resources/TartScreenshot.png"/>
</p>
@@ -20,7 +33,7 @@ tart run ventura-base
If the guest VM is running and configured to accept incoming SSH connections you can conveniently connect to it like so:
```bash
ssh admin@$(tart ip macos-monterey-base)
ssh admin@$(tart ip macos-ventura-base)
```
## Mounting directories
+10
View File
@@ -127,6 +127,16 @@
max-width: 100%;
}
.mdx-spotlight__feature > #lottie-player {
display: block;
flex-shrink: 0;
border-radius: 0.2rem;
box-shadow: var(--md-shadow-z2);
width: 25rem;
max-width: 100%;
background-color: rgb(5 62 94);
}
.mdx-spotlight__feature figcaption {
margin-top: 0.8rem;
}
+35 -7
View File
@@ -1,5 +1,11 @@
{% extends "base.html" %}
{% block announce %}
<a href="/blog/2023/04/25/announcing-orchard-orchestration-for-managing-macos-virtual-machines-at-scale/">
🚀🚀🚀&nbsp&nbspAnnouncing <strong>Orchard</strong> orchestration for managing macOS virtual machines at scale&nbsp;&nbsp;🚀🚀🚀
</a>
{% endblock %}
<!-- Render landing page under tabs -->
{% block tabs %} {{ super() }}
@@ -75,6 +81,8 @@
}
</style>
<script src="https://unpkg.com/@dotlottie/player-component@latest/dist/dotlottie-player.js"></script>
<!-- landing page for landing page -->
<!-- Hero -->
<section class="tx-container">
@@ -82,7 +90,6 @@
<div class="tx-landing">
<!-- landing image -->
<div class="tx-landing__image">
<script src="https://unpkg.com/@dotlottie/player-component@latest/dist/dotlottie-player.js"></script>
<dotlottie-player
src="/assets/animations/TartLogo.lottie"
mode="normal"
@@ -125,7 +132,7 @@
<div class="mdx-spotlight">
<figure class="mdx-spotlight__feature">
<img
src="assets/images/spotlight/virtualization-framework.png"
src="assets/images/spotlight/virtualization-framework.webp"
alt="Apple’s native Virtualization.Framework"
loading="lazy"
width="500"
@@ -144,13 +151,14 @@
</figure>
<figure class="mdx-spotlight__feature">
<img
src="assets/images/spotlight/supported-registries.png"
src="assets/images/spotlight/supported-registries.webp"
alt="OCI-compatible container registries"
loading="lazy"
width="500"
height="160"
/>
<figcaption class="md-typeset">
<h2>Remote storage for Virtual Machines</h2>
<p>
For storing virtual machine images Tart integrates with
OCI-compatible container registries. Work with virtual machines as
@@ -160,13 +168,14 @@
</figure>
<figure class="mdx-spotlight__feature">
<img
src="assets/images/spotlight/github-actions runners.png"
src="assets/images/spotlight/github-actions-runners.webp"
alt="GitHub Actions Runners"
loading="lazy"
width="500"
height="280"
/>
<figcaption class="md-typeset">
<h2>Seamless integration with your existing automations</h2>
<p>
Tart powers several continuous integration systems including
<a href="/integrations/github-actions"
@@ -180,6 +189,25 @@
</p>
</figcaption>
</figure>
<figure class="mdx-spotlight__feature">
<div id="lottie-player">
<dotlottie-player
src="/assets/animations/Orchard.lottie"
mode="normal"
style="height: 280px; margin: auto"
autoplay
loop
/>
</div>
<figcaption class="md-typeset">
<h2>Run at scale with <a href="https://github.com/cirruslabs/orchard">Orchard</a></h2>
<p>
Tart toolset includes Orchard Orchestration &mdash; tool to run and manage Tart virtual machines
at scale on a cluster of Apple Silicon hosts. An Orchard Cluster exposes a simple REST API to manage
thousands virtual machines. Orchard CLI allows accessing remote virtual machines like they run locally.
</p>
</figcaption>
</figure>
</div>
</div>
</div>
@@ -246,7 +274,7 @@
<div class="mdx-users">
<figure class="mdx-users__testimonial">
<img
src="assets/images/users/seb-jachec.jpg"
src="assets/images/users/seb-jachec.webp"
alt="Sebastian Jachec"
loading="lazy"
width="200"
@@ -270,7 +298,7 @@
</figure>
<figure class="mdx-users__testimonial">
<img
src="assets/images/users/mikhail-tokarev.jpeg"
src="assets/images/users/mikhail-tokarev.webp"
alt="Mikhail Tokarev"
loading="lazy"
width="200"
@@ -294,7 +322,7 @@
</figure>
<figure class="mdx-users__testimonial">
<img
src="assets/images/users/max-lapides.jpeg"
src="assets/images/users/max-lapides.webp"
alt="Max Lapides"
loading="lazy"
width="200"
+4 -1
View File
@@ -42,6 +42,7 @@ extra_css:
plugins:
- blog
- privacy
- rss:
match_path: blog/posts/.*
date_from_meta:
@@ -87,9 +88,11 @@ nav:
- "Quick Start": quick-start.md
- "Integrations":
- "GitHub Actions": integrations/github-actions.md
- "GitLab Runner": integrations/gitlab-runner.md
- "Self-hosted CI": integrations/cirrus-cli.md
- "Managing VMs": integrations/vm-management.md
- "Licensing": licensing.md
- "Support & Licensing": licensing.md
- "Orchestration": https://github.com/cirruslabs/orchard
- "FAQ": faq.md
- "Legal":
- 'Terms of Service': legal/terms.md
+11
View File
@@ -0,0 +1,11 @@
#!/bin/sh
# helper script to build and run a signed tart binary
# usage: ./scripts/run-signed.sh run ventura-base
set -e
swift build --product tart
codesign --sign - --entitlements Resources/tart-dev.entitlements --force .build/debug/tart
.build/debug/tart "$@"