From e3ec3d85c44ca212624620afc8cd3e2a9b9e0483 Mon Sep 17 00:00:00 2001 From: Alexander Petric Date: Mon, 17 Nov 2025 18:12:13 -0500 Subject: [PATCH] feat: rhel8 + fix rhel9 (#7165) --- .github/workflows/build-publish-rh8-image.yml | 140 ++++++++++++++++++ docker/RHEL8/Dockerfile | 79 ++++++++++ docker/RHEL9/Dockerfile | 2 +- 3 files changed, 220 insertions(+), 1 deletion(-) create mode 100644 .github/workflows/build-publish-rh8-image.yml create mode 100644 docker/RHEL8/Dockerfile diff --git a/.github/workflows/build-publish-rh8-image.yml b/.github/workflows/build-publish-rh8-image.yml new file mode 100644 index 0000000000..aabb17a592 --- /dev/null +++ b/.github/workflows/build-publish-rh8-image.yml @@ -0,0 +1,140 @@ +env: + REGISTRY: ghcr.io + IMAGE_NAME: ${{ github.repository }} + +name: Build and publish windmill for RHEL8 +on: workflow_dispatch + +permissions: write-all + +jobs: + build_ee: + runs-on: ubicloud + steps: + - uses: actions/checkout@v4 + with: + fetch-depth: 0 + + - name: Read EE repo commit hash + run: | + echo "ee_repo_ref=$(cat ./backend/ee-repo-ref.txt)" >> "$GITHUB_ENV" + + - uses: actions/checkout@v4 + with: + repository: windmill-labs/windmill-ee-private + path: ./windmill-ee-private + ref: ${{ env.ee_repo_ref }} + token: ${{ secrets.WINDMILL_EE_PRIVATE_ACCESS }} + fetch-depth: 0 + + # - name: Set up Docker Buildx + # uses: docker/setup-buildx-action@v2 + - uses: depot/setup-action@v1 + + - name: Docker meta + id: meta-ee-public + uses: docker/metadata-action@v5 + with: + images: | + ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}-ee-rhel8 + flavor: | + latest=false + tags: | + type=sha + + - name: Login to registry + uses: docker/login-action@v3 + with: + registry: ${{ env.REGISTRY }} + username: ${{ github.actor }} + password: ${{ secrets.GITHUB_TOKEN }} + + - name: Substitute EE code + run: | + ./backend/substitute_ee_code.sh --copy --dir ./windmill-ee-private + + - name: Copy RHEL8 Dockerfile + run: | + cp ./docker/RHEL8/Dockerfile ./Dockerfile + + - name: Build and push publicly ee amd64 + uses: depot/build-push-action@v1 + with: + context: . + platforms: linux/amd64 + push: true + build-args: | + features=enterprise,enterprise_saml,stripe,embedding,parquet,prometheus,openidconnect,cloud,jemalloc,license,otel,http_trigger,zip,oauth2,kafka,sqs_trigger,nats,postgres_trigger,gcp_trigger,mqtt_trigger,websocket,smtp,static_frontend,all_languages,deno_core,mcp,private + secrets: | + rh_username=${{ secrets.RH_USERNAME }} + rh_password=${{ secrets.RH_PASSWORD }} + tags: | + ${{ steps.meta-ee-public.outputs.tags }}-amd64 + labels: | + ${{ steps.meta-ee-public.outputs.labels }}-amd64 + org.opencontainers.image.licenses=Windmill-Enterprise-License + + - name: Build and push publicly ee arm64 + uses: depot/build-push-action@v1 + with: + context: . + platforms: linux/arm64 + push: true + build-args: | + features=enterprise,enterprise_saml,stripe,embedding,parquet,prometheus,openidconnect,cloud,jemalloc,license,otel,http_trigger,zip,oauth2,kafka,sqs_trigger,nats,postgres_trigger,gcp_trigger,mqtt_trigger,websocket,smtp,static_frontend,all_languages,deno_core,mcp,private + secrets: | + rh_username=${{ secrets.RH_USERNAME }} + rh_password=${{ secrets.RH_PASSWORD }} + tags: | + ${{ steps.meta-ee-public.outputs.tags }}-arm64 + labels: | + ${{ steps.meta-ee-public.outputs.labels }}-arm64 + org.opencontainers.image.licenses=Windmill-Enterprise-License + + - uses: shrink/actions-docker-extract@v3 + id: extract-ee-amd64 + with: + image: ${{ steps.meta-ee-public.outputs.tags}}-amd64 + path: "/windmill/target/release/windmill" + + - uses: shrink/actions-docker-extract@v3 + id: extract-duckdb-ffi-internal + with: + image: ${{ steps.meta-ee-public.outputs.tags}}-amd64 + path: "/usr/src/app/libwindmill_duckdb_ffi_internal.so" + + # - uses: shrink/actions-docker-extract@v3 + # id: extract-ee-arm64 + # with: + # image: ${{ steps.meta-ee-public.outputs.tags}}-arm64 + # path: "/windmill/target/release/windmill" + + - name: Rename binary with corresponding architecture + run: | + mv "${{ steps.extract-ee-amd64.outputs.destination }}/windmill" "${{ steps.extract-ee-amd64.outputs.destination }}/windmill-ee-amd64-rhel8" + # mv "${{ steps.extract-ee-arm64.outputs.destination }}/windmill" "${{ steps.extract-ee-arm64.outputs.destination }}/windmill-ee-arm64-rhel8" + + - uses: actions/upload-artifact@v4 + with: + name: RHEL8-amd64 build + path: ${{ steps.extract-ee-amd64.outputs.destination }}/windmill-ee-amd64-rhel8 + + - uses: actions/upload-artifact@v4 + with: + name: RHEL8-amd64 dynamic libraries build + path: ${{ steps.extract-duckdb-ffi-internal.outputs.destination }}/libwindmill_duckdb_ffi_internal.so + + # - uses: actions/upload-artifact@v4 + # with: + # name: RHEL8-arm64 build + # path: + # ${{ steps.extract-ee-arm64.outputs.destination + # }}/windmill-ee-arm64-rhel8 + + # - name: Attach binary to release + # uses: softprops/action-gh-release@v2 + # if: startsWith(github.ref, 'refs/tags/') + # with: + # files: | + # ${{ steps.extract-ee-arm64.outputs.destination }}/windmill-ee-arm64-rhel8 + # ${{ steps.extract-ee-amd64.outputs.destination }}/windmill-ee-amd64-rhel8 diff --git a/docker/RHEL8/Dockerfile b/docker/RHEL8/Dockerfile new file mode 100644 index 0000000000..2d4ba3fb3a --- /dev/null +++ b/docker/RHEL8/Dockerfile @@ -0,0 +1,79 @@ +ARG DEBIAN_IMAGE=debian:bookworm-slim +ARG RUST_IMAGE=registry.access.redhat.com/ubi8/ubi:latest +ARG PYTHON_IMAGE=python:3.11.10-slim-bookworm + +FROM ${RUST_IMAGE} AS rust_base + +RUN yum update -y && \ + yum install -y git openssl-devel npm nodejs rustfmt + +# Install rust manually +RUN curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh -s -- -y +ENV PATH="/root/.cargo/bin:${PATH}" + +RUN CARGO_NET_GIT_FETCH_WITH_CLI=true cargo install cargo-chef --version ^0.1 + +WORKDIR /windmill + +ENV SQLX_OFFLINE=true +# ENV CARGO_INCREMENTAL=1 + +FROM node:20-alpine as frontend + +# install dependencies +WORKDIR /frontend +COPY ./frontend/package.json ./frontend/package-lock.json ./ +RUN npm ci + +# Copy all local files into the image. +COPY frontend . +RUN mkdir /backend +COPY /backend/windmill-api/openapi.yaml /backend/windmill-api/openapi.yaml +COPY /openflow.openapi.yaml /openflow.openapi.yaml +COPY /backend/windmill-api/build_openapi.sh /backend/windmill-api/build_openapi.sh + +RUN cd /backend/windmill-api && . ./build_openapi.sh +COPY /backend/parsers/windmill-parser-wasm/pkg/ /backend/parsers/windmill-parser-wasm/pkg/ +COPY /typescript-client/docs/ /frontend/static/tsdocs/ + +RUN npm run generate-backend-client +ENV NODE_OPTIONS "--max-old-space-size=10240" +RUN npm run build + + +FROM rust_base AS planner + +COPY ./openflow.openapi.yaml /openflow.openapi.yaml +COPY ./backend ./ + +RUN --mount=type=cache,target=/usr/local/cargo/registry \ + CARGO_NET_GIT_FETCH_WITH_CLI=true cargo chef prepare --recipe-path recipe.json + +FROM rust_base AS builder +ARG features="" + +COPY --from=planner /windmill/recipe.json recipe.json + +RUN --mount=type=secret,id=rh_username \ + --mount=type=secret,id=rh_password \ + subscription-manager register --username $(cat /run/secrets/rh_username) --password $(cat /run/secrets/rh_password) + +RUN subscription-manager repos --enable codeready-builder-for-rhel-8-$(arch)-rpms + +RUN yum update -y && \ + yum install -y perl-interpreter perl-IPC-Cmd perl-Time-Piece libxml2-devel xmlsec1-devel xmlsec1-openssl-devel clang llvm-devel cmake libtool-ltdl-devel + +# RUN --mount=type=cache,target=/usr/local/cargo/registry \ +# CARGO_NET_GIT_FETCH_WITH_CLI=true RUST_BACKTRACE=1 cargo chef cook --release --features "$features" --recipe-path recipe.json + +COPY ./openflow.openapi.yaml /openflow.openapi.yaml +COPY ./backend ./ + +COPY --from=frontend /frontend /frontend +COPY --from=frontend /backend/windmill-api/openapi-deref.yaml ./windmill-api/openapi-deref.yaml +COPY .git/ .git/ + +RUN --mount=type=cache,target=/usr/local/cargo/registry \ + CARGO_NET_GIT_FETCH_WITH_CLI=true cargo build --release --features "$features" + +RUN subscription-manager unregister diff --git a/docker/RHEL9/Dockerfile b/docker/RHEL9/Dockerfile index 7399fd690a..ace996cab5 100644 --- a/docker/RHEL9/Dockerfile +++ b/docker/RHEL9/Dockerfile @@ -61,7 +61,7 @@ RUN --mount=type=secret,id=rh_username \ RUN subscription-manager repos --enable codeready-builder-for-rhel-9-$(arch)-rpms RUN yum update -y && \ - yum install -y perl-FindBin perl-IPC-Cmd libxml2-devel xmlsec1-devel xmlsec1-openssl-devel clang llvm-devel cmake libtool-ltdl-devel + yum install -y perl-FindBin perl-IPC-Cmd perl-Time-Piece libxml2-devel xmlsec1-devel xmlsec1-openssl-devel clang llvm-devel cmake libtool-ltdl-devel # RUN --mount=type=cache,target=/usr/local/cargo/registry \ # CARGO_NET_GIT_FETCH_WITH_CLI=true RUST_BACKTRACE=1 cargo chef cook --release --features "$features" --recipe-path recipe.json