diff --git a/.konflux/profiles.toml b/.konflux/profiles.toml index 08cb82147..09aeb7d91 100644 --- a/.konflux/profiles.toml +++ b/.konflux/profiles.toml @@ -7,6 +7,6 @@ bootstrap_packages = ["maturin"] rhoai_index_url = "https://packages.redhat.com/api/pypi/public-rhai/rhoai/3.5/cpu-ubi9/simple/" output_suffix = "" tekton_files = [ - ".tekton/lightspeed-stack-0-7-pull-request.yaml", - ".tekton/lightspeed-stack-0-7-push.yaml", + ".tekton/lightspeed-stack-0-8-pull-request.yaml", + ".tekton/lightspeed-stack-0-8-push.yaml", ] diff --git a/.konflux/requirements.hashes.source.txt b/.konflux/requirements.hashes.source.txt index 29016231d..ca6a70bfa 100644 --- a/.konflux/requirements.hashes.source.txt +++ b/.konflux/requirements.hashes.source.txt @@ -102,9 +102,6 @@ google-cloud-resource-manager==1.18.0 \ oci==2.182.1 \ --hash=sha256:0c616a6bc3bc458464bc3456469d8da63a1a2d2277e9314b41a1c4e76d5df523 \ --hash=sha256:9862de221f2abe9cf8319393eec58ea59c014fd9b61afaf0a3cca163e2a508b0 -pydantic-ai-skills==1.2.0 \ - --hash=sha256:7ff4eb4b307deb6ef3bf31a6d9493c1e3a8e9b866a13b866a9ea4606bd914206 \ - --hash=sha256:e52f7e8243343dfa94206aae11cd142120edb8990fc392b1d8af32f99b6d351e pythainlp==5.3.4 \ --hash=sha256:76744e51e27c895630bafd74f53a1f0aa8782cef2f7f02eebd6427fe8ce8d84d \ --hash=sha256:e66fd76fb5931834fd4e32ed54337ec62350d7654f187850e4dd4f915e9f624f diff --git a/.konflux/requirements.hashes.wheel.pypi.txt b/.konflux/requirements.hashes.wheel.pypi.txt index c1d470df5..f4fd4d73a 100644 --- a/.konflux/requirements.hashes.wheel.pypi.txt +++ b/.konflux/requirements.hashes.wheel.pypi.txt @@ -1 +1,21 @@ --index-url https://pypi.org/simple +# Aligned with uv.lock. Pure PyPI wheels where RHOAI is too old for pydantic-ai 2.26. +# Wheel-only hashes — hermetic builds cannot install sdist build backends. +genai-prices==0.1.1 \ + --hash=sha256:de2e3d8ea3ca1d0d292025995c598da447a74e94f22cd3342df46941aeb5416b +httpcore2==2.9.1 \ + --hash=sha256:6182472379e855fe4221246a2bb7ecede403bc61c6798062ae1787d051ccde26 +httpx2==2.9.1 \ + --hash=sha256:1820fe14a9ab1107bfeff39259987429450b070ec0ff38cc87eb0d8c97fdc71a +openai==2.53.0 \ + --hash=sha256:c694ffc747a3c4d1663ef2b07b811315a476164ee5efa3a993967349ebca7618 +pydantic-ai==2.26.0 \ + --hash=sha256:1d2324407ed6c206b4c21436059c651051b836fa443b14165236ea9e53379c10 +pydantic-ai-skills==1.3.0 \ + --hash=sha256:4a8e001054b8c458d9b9b1d7688f0a30602246473ed8dfbe235dc4557b458dff +pydantic-ai-slim==2.26.0 \ + --hash=sha256:855a23f120328e7a12e8f4371db597d74f65925e20ce335d3a6db81203238f58 +pydantic-evals==2.26.0 \ + --hash=sha256:41f92eee7270dbb85e6639082256ff14877c1f0bba0d7dda30e683efb6555e0d +pydantic-graph==2.26.0 \ + --hash=sha256:4599a980747588faf17ac56cfa9c10b2a79723a5a20c3c7ee479e8366653097c diff --git a/.konflux/requirements.hashes.wheel.txt b/.konflux/requirements.hashes.wheel.txt index 53692dfc8..3bf348cbf 100644 --- a/.konflux/requirements.hashes.wheel.txt +++ b/.konflux/requirements.hashes.wheel.txt @@ -103,8 +103,6 @@ frozenlist==1.8.0 \ --hash=sha256:824190e162bc775e7f6ded9bde5897738987c51548677c213d1ff728b10efe5b fsspec==2026.4.0 \ --hash=sha256:ef0c6ca507776eab560612d5785f243e2e3f6cfe42468aacdce3609353366b5b -genai-prices==0.0.69 \ - --hash=sha256:f01ccb80e2ac9be9b7d978e4cc97a79023ddd1fc796f50eabd379c23687bb901 google-api-core==2.31.0 \ --hash=sha256:2975c76ecb910406ff6f71c62ed09848d0db421b27986413c448cb8766fc827e google-auth==2.55.1 \ @@ -140,14 +138,10 @@ hf-xet==1.5.1 \ --hash=sha256:e0b14eda87d8109be4ca52aa5daef4897ed046ff2e558f363be65008c048149e httpcore==1.0.9 \ --hash=sha256:fc0ea63671089523efc6fe94ec49d0b10c9660460cbca6172fc972c1c5f9c0ac -httpcore2==2.5.0 \ - --hash=sha256:1e8550e99da4297cb64d0cd5dd797c11a736a11f6fcbd8ffec350a9a85b39a27 httpx==0.28.1 \ --hash=sha256:40b3fef8650d88ced417b05b236427596a6da9117b0f64ef5b0a5d548d20addb httpx-sse==0.4.3 \ --hash=sha256:e163972748a0d3dcc718803a47bfad40fa1fa5a554d192f60ba685163ab2162a -httpx2==2.5.0 \ - --hash=sha256:78cf66523b7294f6cd2f18e8a04f0b46b2fec6bdb294c464ba111ddd44953129 huggingface-hub==1.22.0 \ --hash=sha256:54ae3efe94beb5a7c9eea3e911ca578945f178e1f211644a0d4f92a1b1648dde idna==3.18 \ @@ -222,8 +216,6 @@ numpy==2.3.5 \ --hash=sha256:a08c6c26c26d7530d09ac93bc177593958c2e3ce4a9b5750c14a80329cca157c oauthlib==3.3.1 \ --hash=sha256:c6fbab4f1a77a539f01175e2ea74b9552806bd0a849c70e744fda4ab801031c0 -openai==2.44.0 \ - --hash=sha256:87429e9a4d15b2918a03b040b6330fa03fc175bbf0bc6eaff7ae61c93cd42c53 ogx==1.0.2+rhaiv.0 \ --hash=sha256:52c891af9dfb22f884d2dae150e5e94d04e492f452ec811bbc61ba84257de000 ogx-api==1.0.2+rhaiv.0 \ @@ -291,9 +283,11 @@ py-key-value-aio==0.4.5 \ --hash=sha256:9a7d2708e89c3262fca6fe38d01239d481846aa30121a0520e449994e7e9a910 pyaml==26.7.0 \ --hash=sha256:667a4b440272f1376fae57023a213a583a707d29bc4127d354ecc3668adefd7a -pyarrow==24.0.0 \ - --hash=sha256:07fa0b8ce4ccf95d56446ec653a9cae31532dffa8a8841b6b1492ba2a46ee7cb \ - --hash=sha256:be6bbfda99fa5c67655c7cd99044bbde1db8319d2b9a2a54bff5dda2f4010dca +pyarrow==25.0.0 \ + --hash=sha256:b7cc7bfc4f74e1b44f9699468c26df0925f75cbef99346ac35efac8c13cb71b5 \ + --hash=sha256:dc55a12747b836dfd27b2055e343c6b00d9f726dec25ad097bbe536140b9bc1f \ + --hash=sha256:4f0260a86a95607e6f1941fd15b352b56be6743c272ba9e2a7ae65d3e63f0f22 \ + --hash=sha256:dd44b035b1fb5305894e7aee13247fb49d3eccd691430cbe1f3ca98b9d3c5377 pyasn1==0.6.3 \ --hash=sha256:6262dfa40ecb9b64fe0a62f791b6b733165ec158cf9f869d568fd8178044013d pyasn1-modules==0.4.2 \ @@ -302,17 +296,9 @@ pycparser==3.0 \ --hash=sha256:c2e6198bf8dc97ba19b5f42d9d0e08d5842ffb775e0e208b150080dcf423396e pydantic==2.13.4 \ --hash=sha256:1a3d4d45204182df30dbd68890bdf1becec13f689075099866dd4bdf06b04371 -pydantic-ai==2.5.0 \ - --hash=sha256:e2278856e6f3d653601e39ce626a90c99faa139b03c742532da58d64d9f8cab0 -pydantic-ai-slim==2.5.0 \ - --hash=sha256:8436abb3db39526cbc903de3d78c150a28fcc55463db3dfb5a82ee1b5cb27c50 pydantic-core==2.46.4 \ --hash=sha256:38235509e8f37596cc39453972c1a9b200287d92a98eb2a7c92d9708a98eec49 \ --hash=sha256:bbc9884932978a8f52c59aac4a0a273c8e514d303fd040c38b0436b37e57ed33 -pydantic-evals==2.5.0 \ - --hash=sha256:b7d38de7f719dd71f5b91302e7555198d0e19c5d62a7c19908ad5aadfb5e275a -pydantic-graph==2.5.0 \ - --hash=sha256:61ad8c88d52760b864e186e4342da3d5de5e2d8a232f66ac562c69b108889a62 pydantic-settings==2.14.2 \ --hash=sha256:0398c90f6e52de6fc403d1aa3dfd53c7be8e011759e7fcd7b317fffb0649f726 pygments==2.20.0 \ diff --git a/.tekton/lightspeed-stack-0-8-pull-request.yaml b/.tekton/lightspeed-stack-0-8-pull-request.yaml index 3fdd49476..a0c26fb3d 100644 --- a/.tekton/lightspeed-stack-0-8-pull-request.yaml +++ b/.tekton/lightspeed-stack-0-8-pull-request.yaml @@ -48,12 +48,13 @@ spec: "path": ".konflux", "requirements_files": [ "requirements.hashes.wheel.txt", + "requirements.hashes.wheel.pypi.txt", "requirements.hashes.source.txt", "requirements.hermetic.txt" ], "requirements_build_files": ["requirements-build.txt"], "binary": { - "packages": "a2a-sdk,accelerate,aiofile,aiohappyeyeballs,aiohttp,aiosignal,aiosqlite,annotated-doc,annotated-types,anthropic,anyio,argcomplete,asyncpg,attrs,authlib,autoevals,azure-core,azure-identity,beartype,cachetools,caio,certifi,cffi,chardet,charset-normalizer,chevron,click,cryptography,datasets,defusedxml,dill,distro,dnspython,docstring-parser,durationpy,einops,email-validator,emoji,exceptiongroup,executing,faiss-cpu,fastapi,fastmcp-slim,fastuuid,filelock,fire,frozenlist,fsspec,genai-prices,google-api-core,google-auth,google-cloud-core,google-cloud-storage,google-crc32c,google-genai,google-resumable-media,googleapis-common-protos,greenlet,griffelib,grpc-google-iam-v1,grpcio,grpcio-status,h11,hf-xet,httpcore,httpcore2,httpx,httpx-sse,httpx2,huggingface-hub,idna,importlib-metadata,jaraco-classes,jaraco-context,jaraco-functools,jeepney,jinja2,jiter,joblib,joserfc,jsonpath-ng,jsonschema,jsonschema-specifications,keyring,kubernetes,langdetect,litellm,logfire,logfire-api,markdown-it-py,markupsafe,maturin,mcp,mdurl,more-itertools,mpmath,msal,msal-extensions,multidict,multiprocess,narwhals,networkx,nltk,numpy,oauthlib,ogx,ogx-api,ogx-client,openai,opentelemetry-api,opentelemetry-distro,opentelemetry-exporter-otlp,opentelemetry-exporter-otlp-proto-common,opentelemetry-exporter-otlp-proto-grpc,opentelemetry-exporter-otlp-proto-http,opentelemetry-instrumentation,opentelemetry-instrumentation-httpx,opentelemetry-proto,opentelemetry-sdk,opentelemetry-semantic-conventions,opentelemetry-util-http,oracledb,packaging,pandas,peft,pip,platformdirs,polyleven,prometheus-client,prompt-toolkit,propcache,proto-plus,protobuf,psutil,psycopg2-binary,py-key-value-aio,pyaml,pyarrow,pyasn1,pyasn1-modules,pycparser,pydantic,pydantic-ai,pydantic-ai-slim,pydantic-core,pydantic-evals,pydantic-graph,pydantic-settings,pygments,pyjwt,pyopenssl,pypdf,pyperclip,python-dateutil,python-dotenv,python-multipart,pytz,pyyaml,referencing,regex,requests,requests-oauthlib,rich,rpds-py,safetensors,scikit-learn,scipy,secretstorage,semver,sentence-transformers,sentry-sdk,setuptools,shellingham,six,sniffio,sqlalchemy,sse-starlette,starlette,structlog,sympy,tenacity,termcolor,threadpoolctl,tiktoken,tokenizers,torch,tornado,tqdm,transformers,tree-sitter,triton,trl,truststore,typer,typing-extensions,typing-inspection,urllib3,uv,uv-build,uvicorn,wcwidth,websocket-client,websockets,wrapt,xxhash,yarl,zipp,zstandard", + "packages": "a2a-sdk,accelerate,aiofile,aiohappyeyeballs,aiohttp,aiosignal,aiosqlite,annotated-doc,annotated-types,anthropic,anyio,argcomplete,asyncpg,attrs,authlib,autoevals,azure-core,azure-identity,beartype,cachetools,caio,certifi,cffi,chardet,charset-normalizer,chevron,click,cryptography,datasets,defusedxml,dill,distro,dnspython,docstring-parser,durationpy,einops,email-validator,emoji,exceptiongroup,executing,faiss-cpu,fastapi,fastmcp-slim,fastuuid,filelock,fire,frozenlist,fsspec,genai-prices,google-api-core,google-auth,google-cloud-core,google-cloud-storage,google-crc32c,google-genai,google-resumable-media,googleapis-common-protos,greenlet,griffelib,grpc-google-iam-v1,grpcio,grpcio-status,h11,hf-xet,httpcore,httpcore2,httpx,httpx-sse,httpx2,huggingface-hub,idna,importlib-metadata,jaraco-classes,jaraco-context,jaraco-functools,jeepney,jinja2,jiter,joblib,joserfc,jsonpath-ng,jsonschema,jsonschema-specifications,keyring,kubernetes,langdetect,litellm,logfire,logfire-api,markdown-it-py,markupsafe,maturin,mcp,mdurl,more-itertools,mpmath,msal,msal-extensions,multidict,multiprocess,narwhals,networkx,nltk,numpy,oauthlib,ogx,ogx-api,ogx-client,openai,opentelemetry-api,opentelemetry-distro,opentelemetry-exporter-otlp,opentelemetry-exporter-otlp-proto-common,opentelemetry-exporter-otlp-proto-grpc,opentelemetry-exporter-otlp-proto-http,opentelemetry-instrumentation,opentelemetry-instrumentation-httpx,opentelemetry-proto,opentelemetry-sdk,opentelemetry-semantic-conventions,opentelemetry-util-http,oracledb,packaging,pandas,peft,pip,platformdirs,polyleven,prometheus-client,prompt-toolkit,propcache,proto-plus,protobuf,psutil,psycopg2-binary,py-key-value-aio,pyaml,pyarrow,pyasn1,pyasn1-modules,pycparser,pydantic,pydantic-ai,pydantic-ai-slim,pydantic-ai-skills,pydantic-core,pydantic-evals,pydantic-graph,pydantic-settings,pygments,pyjwt,pyopenssl,pypdf,pyperclip,python-dateutil,python-dotenv,python-multipart,pytz,pyyaml,referencing,regex,requests,requests-oauthlib,rich,rpds-py,safetensors,scikit-learn,scipy,secretstorage,semver,sentence-transformers,sentry-sdk,setuptools,shellingham,six,sniffio,sqlalchemy,sse-starlette,starlette,structlog,sympy,tenacity,termcolor,threadpoolctl,tiktoken,tokenizers,torch,tornado,tqdm,transformers,tree-sitter,triton,trl,truststore,typer,typing-extensions,typing-inspection,urllib3,uv,uv-build,uvicorn,wcwidth,websocket-client,websockets,wrapt,xxhash,yarl,zipp,zstandard", "os": "linux", "arch": "x86_64,aarch64", "py_version": 312 diff --git a/.tekton/lightspeed-stack-0-8-push.yaml b/.tekton/lightspeed-stack-0-8-push.yaml index 359a64293..d342ade92 100644 --- a/.tekton/lightspeed-stack-0-8-push.yaml +++ b/.tekton/lightspeed-stack-0-8-push.yaml @@ -49,12 +49,13 @@ spec: "path": ".konflux", "requirements_files": [ "requirements.hashes.wheel.txt", + "requirements.hashes.wheel.pypi.txt", "requirements.hashes.source.txt", "requirements.hermetic.txt" ], "requirements_build_files": ["requirements-build.txt"], "binary": { - "packages": "a2a-sdk,accelerate,aiofile,aiohappyeyeballs,aiohttp,aiosignal,aiosqlite,annotated-doc,annotated-types,anthropic,anyio,argcomplete,asyncpg,attrs,authlib,autoevals,azure-core,azure-identity,beartype,cachetools,caio,certifi,cffi,chardet,charset-normalizer,chevron,click,cryptography,datasets,defusedxml,dill,distro,dnspython,docstring-parser,durationpy,einops,email-validator,emoji,exceptiongroup,executing,faiss-cpu,fastapi,fastmcp-slim,fastuuid,filelock,fire,frozenlist,fsspec,genai-prices,google-api-core,google-auth,google-cloud-core,google-cloud-storage,google-crc32c,google-genai,google-resumable-media,googleapis-common-protos,greenlet,griffelib,grpc-google-iam-v1,grpcio,grpcio-status,h11,hf-xet,httpcore,httpcore2,httpx,httpx-sse,httpx2,huggingface-hub,idna,importlib-metadata,jaraco-classes,jaraco-context,jaraco-functools,jeepney,jinja2,jiter,joblib,joserfc,jsonpath-ng,jsonschema,jsonschema-specifications,keyring,kubernetes,langdetect,litellm,logfire,logfire-api,markdown-it-py,markupsafe,maturin,mcp,mdurl,more-itertools,mpmath,msal,msal-extensions,multidict,multiprocess,narwhals,networkx,nltk,numpy,oauthlib,ogx,ogx-api,ogx-client,openai,opentelemetry-api,opentelemetry-distro,opentelemetry-exporter-otlp,opentelemetry-exporter-otlp-proto-common,opentelemetry-exporter-otlp-proto-grpc,opentelemetry-exporter-otlp-proto-http,opentelemetry-instrumentation,opentelemetry-instrumentation-httpx,opentelemetry-proto,opentelemetry-sdk,opentelemetry-semantic-conventions,opentelemetry-util-http,oracledb,packaging,pandas,peft,pip,platformdirs,polyleven,prometheus-client,prompt-toolkit,propcache,proto-plus,protobuf,psutil,psycopg2-binary,py-key-value-aio,pyaml,pyarrow,pyasn1,pyasn1-modules,pycparser,pydantic,pydantic-ai,pydantic-ai-slim,pydantic-core,pydantic-evals,pydantic-graph,pydantic-settings,pygments,pyjwt,pyopenssl,pypdf,pyperclip,python-dateutil,python-dotenv,python-multipart,pytz,pyyaml,referencing,regex,requests,requests-oauthlib,rich,rpds-py,safetensors,scikit-learn,scipy,secretstorage,semver,sentence-transformers,sentry-sdk,setuptools,shellingham,six,sniffio,sqlalchemy,sse-starlette,starlette,structlog,sympy,tenacity,termcolor,threadpoolctl,tiktoken,tokenizers,torch,tornado,tqdm,transformers,tree-sitter,triton,trl,truststore,typer,typing-extensions,typing-inspection,urllib3,uv,uv-build,uvicorn,wcwidth,websocket-client,websockets,wrapt,xxhash,yarl,zipp,zstandard", + "packages": "a2a-sdk,accelerate,aiofile,aiohappyeyeballs,aiohttp,aiosignal,aiosqlite,annotated-doc,annotated-types,anthropic,anyio,argcomplete,asyncpg,attrs,authlib,autoevals,azure-core,azure-identity,beartype,cachetools,caio,certifi,cffi,chardet,charset-normalizer,chevron,click,cryptography,datasets,defusedxml,dill,distro,dnspython,docstring-parser,durationpy,einops,email-validator,emoji,exceptiongroup,executing,faiss-cpu,fastapi,fastmcp-slim,fastuuid,filelock,fire,frozenlist,fsspec,genai-prices,google-api-core,google-auth,google-cloud-core,google-cloud-storage,google-crc32c,google-genai,google-resumable-media,googleapis-common-protos,greenlet,griffelib,grpc-google-iam-v1,grpcio,grpcio-status,h11,hf-xet,httpcore,httpcore2,httpx,httpx-sse,httpx2,huggingface-hub,idna,importlib-metadata,jaraco-classes,jaraco-context,jaraco-functools,jeepney,jinja2,jiter,joblib,joserfc,jsonpath-ng,jsonschema,jsonschema-specifications,keyring,kubernetes,langdetect,litellm,logfire,logfire-api,markdown-it-py,markupsafe,maturin,mcp,mdurl,more-itertools,mpmath,msal,msal-extensions,multidict,multiprocess,narwhals,networkx,nltk,numpy,oauthlib,ogx,ogx-api,ogx-client,openai,opentelemetry-api,opentelemetry-distro,opentelemetry-exporter-otlp,opentelemetry-exporter-otlp-proto-common,opentelemetry-exporter-otlp-proto-grpc,opentelemetry-exporter-otlp-proto-http,opentelemetry-instrumentation,opentelemetry-instrumentation-httpx,opentelemetry-proto,opentelemetry-sdk,opentelemetry-semantic-conventions,opentelemetry-util-http,oracledb,packaging,pandas,peft,pip,platformdirs,polyleven,prometheus-client,prompt-toolkit,propcache,proto-plus,protobuf,psutil,psycopg2-binary,py-key-value-aio,pyaml,pyarrow,pyasn1,pyasn1-modules,pycparser,pydantic,pydantic-ai,pydantic-ai-slim,pydantic-ai-skills,pydantic-core,pydantic-evals,pydantic-graph,pydantic-settings,pygments,pyjwt,pyopenssl,pypdf,pyperclip,python-dateutil,python-dotenv,python-multipart,pytz,pyyaml,referencing,regex,requests,requests-oauthlib,rich,rpds-py,safetensors,scikit-learn,scipy,secretstorage,semver,sentence-transformers,sentry-sdk,setuptools,shellingham,six,sniffio,sqlalchemy,sse-starlette,starlette,structlog,sympy,tenacity,termcolor,threadpoolctl,tiktoken,tokenizers,torch,tornado,tqdm,transformers,tree-sitter,triton,trl,truststore,typer,typing-extensions,typing-inspection,urllib3,uv,uv-build,uvicorn,wcwidth,websocket-client,websockets,wrapt,xxhash,yarl,zipp,zstandard", "os": "linux", "arch": "x86_64,aarch64", "py_version": 312 diff --git a/deploy/lightspeed-stack/Containerfile b/deploy/lightspeed-stack/Containerfile index 8c1ef546f..491839817 100644 --- a/deploy/lightspeed-stack/Containerfile +++ b/deploy/lightspeed-stack/Containerfile @@ -70,7 +70,7 @@ RUN if [ -f /cachi2/cachi2.env ]; then \ . /cachi2/cachi2.env && \ uv venv --seed --no-index --find-links ${PIP_FIND_LINKS} && \ . .venv/bin/activate && \ - pip install --no-cache-dir --ignore-installed --no-index --find-links ${PIP_FIND_LINKS} --no-deps -r requirements.hashes.wheel.txt -r requirements.hashes.source.txt && \ + pip install --no-cache-dir --ignore-installed --no-index --find-links ${PIP_FIND_LINKS} --no-deps -r requirements.hashes.wheel.txt -r requirements.hashes.wheel.pypi.txt -r requirements.hashes.source.txt && \ pip check; \ else \ uv sync --locked --no-dev --group llslibdev; \ diff --git a/docker-compose.yaml b/docker-compose.yaml index 18e43be2d..f6097395e 100755 --- a/docker-compose.yaml +++ b/docker-compose.yaml @@ -57,6 +57,8 @@ services: - OGX_LOGGING=${OGX_LOGGING:-} # FAISS test - FAISS_VECTOR_STORE_ID=${FAISS_VECTOR_STORE_ID:-} + # Disable OGX ~/.llama → ~/.ogx migration (bind-mount under ~/.llama/storage/rag). + - OGX_CONFIG_DIR=/opt/app-root/src/.ogx # Prevent HuggingFace Hub update checks (HTTP 429 rate-limiting in CI from parallel jobs). - HF_HUB_OFFLINE=1 # OKP/Solr RAG diff --git a/tests/e2e-prow/rhoai/configs/run.yaml b/tests/e2e-prow/rhoai/configs/run.yaml index ec50feabb..1e10cfd50 100644 --- a/tests/e2e-prow/rhoai/configs/run.yaml +++ b/tests/e2e-prow/rhoai/configs/run.yaml @@ -63,12 +63,13 @@ server: port: 8321 storage: backends: - kv_default: # Single database for registry AND RAG data + kv_default: type: kv_sqlite - db_path: /opt/app-root/src/.llama/storage/rag/kv_store.db + db_path: ${env.KV_STORE_PATH:=/opt/app-root/src/.llama/storage/kv_store.db} kv_rag: type: kv_sqlite - db_path: /opt/app-root/src/.llama/storage/rag/kv_store.db + # Requires OGX_CONFIG_DIR so migrate_legacy_config_dir() does not move ~/.llama. + db_path: ${env.KV_RAG_PATH:=/opt/app-root/src/.llama/storage/rag/kv_store.db} sql_default: type: sql_sqlite db_path: ${env.SQL_STORE_PATH:=/opt/app-root/src/.llama/storage/sql_store.db} diff --git a/tests/e2e-prow/rhoai/manifests/lightspeed/lightspeed-stack.yaml b/tests/e2e-prow/rhoai/manifests/lightspeed/lightspeed-stack.yaml index f8aa35caf..d6ed459c4 100644 --- a/tests/e2e-prow/rhoai/manifests/lightspeed/lightspeed-stack.yaml +++ b/tests/e2e-prow/rhoai/manifests/lightspeed/lightspeed-stack.yaml @@ -54,8 +54,9 @@ spec: name: faiss-vector-store-secret key: id optional: true + # Unused for server-mode FAISS (llama pod owns the fixture); keep out of ~/.llama. - name: KV_RAG_PATH - value: "/app-root/src/.llama/storage/rag/kv_store.db" + value: "/app-root/.e2e-rag-work/kv_store.db" - name: VLLM_MODEL valueFrom: secretKeyRef: diff --git a/tests/e2e-prow/rhoai/manifests/lightspeed/llama-stack-openai.yaml b/tests/e2e-prow/rhoai/manifests/lightspeed/llama-stack-openai.yaml index 11e76dcf8..292db1f0b 100644 --- a/tests/e2e-prow/rhoai/manifests/lightspeed/llama-stack-openai.yaml +++ b/tests/e2e-prow/rhoai/manifests/lightspeed/llama-stack-openai.yaml @@ -1,8 +1,10 @@ -# Llama Stack from source on UBI: init clones repo + seeds FAISS, main enriches run.yaml and runs Llama. +# Llama Stack from source on UBI: init clones repo + seeds FAISS, main restores seed then uses +# scripts/llama-stack-entrypoint.sh (same enrich/start path as GitHub Actions docker-compose). # Needs ConfigMaps: llama-stack-config (run.yaml), rag-data (kv_store.db.gz), lightspeed-stack-config; # optional llama-stack-source for repo_url / repo_revision. # -# RAG: seeded in setup-from-source from rag-data ConfigMap (gzip); main re-inflates from rag-data mount. +# RAG fixture lives at KV_RAG_PATH outside ~/.llama, with OGX_CONFIG_DIR set, so +# migrate_legacy_config_dir() cannot move the fixture away on startup. apiVersion: v1 kind: Pod metadata: @@ -45,7 +47,7 @@ spec: && /opt/app-root/.venv/bin/python --version >/dev/null 2>&1 \ && [[ -d /opt/app-root/src ]]; then echo "PVC cache hit: app-root already provisioned — skipping full install" - mkdir -p /opt/app-root/.e2e-rag-seed /opt/app-root/src/.llama/storage/rag /opt/app-root/src/.llama/storage/files + mkdir -p /opt/app-root/.e2e-rag-seed /opt/app-root/.e2e-rag-work /opt/app-root/src/.ogx /opt/app-root/src/.llama/storage/files if [[ -f /rag-seed/kv_store.db.gz ]]; then gzip -dc /rag-seed/kv_store.db.gz > /opt/app-root/.e2e-rag-seed/kv_store.db _sz=$(stat -c%s /opt/app-root/.e2e-rag-seed/kv_store.db) @@ -53,8 +55,11 @@ spec: echo "FATAL: RAG seed too small (${_sz} bytes); check rag-data ConfigMap" exit 1 fi - cp -f /opt/app-root/.e2e-rag-seed/kv_store.db /opt/app-root/src/.llama/storage/rag/kv_store.db + cp -f /opt/app-root/.e2e-rag-seed/kv_store.db /opt/app-root/.e2e-rag-work/kv_store.db fi + cp -f /opt/app-root/scripts/llama-stack-entrypoint.sh /opt/app-root/enrich-entrypoint.sh + cp -f /opt/app-root/src/llama_stack_configuration.py /opt/app-root/llama_stack_configuration.py + chmod 755 /opt/app-root/enrich-entrypoint.sh chmod -R 775 /opt/app-root && chown -R 1001:0 /opt/app-root echo "PVC fast-path complete" exit 0 @@ -74,7 +79,7 @@ spec: (cd /opt/app-root/repo && tar cf - .) | (cd /opt/app-root && tar xf -) rm -rf /opt/app-root/repo sed -i 's|/opt/app-root/repo/.venv|/opt/app-root/.venv|g' /opt/app-root/.venv/bin/* 2>/dev/null || true - mkdir -p /opt/app-root/.e2e-rag-seed /opt/app-root/src/.llama/storage/rag /opt/app-root/src/.llama/storage/files + mkdir -p /opt/app-root/.e2e-rag-seed /opt/app-root/.e2e-rag-work /opt/app-root/src/.ogx /opt/app-root/src/.llama/storage/files if [[ ! -f /rag-seed/kv_store.db.gz ]]; then echo "FATAL: missing /rag-seed/kv_store.db.gz (ConfigMap rag-data key kv_store.db.gz)" ls -la /rag-seed || true @@ -86,8 +91,10 @@ spec: echo "FATAL: RAG seed too small (${_sz} bytes); check rag-data ConfigMap" exit 1 fi - cp -f /opt/app-root/.e2e-rag-seed/kv_store.db /opt/app-root/src/.llama/storage/rag/kv_store.db - cp /opt/app-root/src/llama_stack_configuration.py /opt/app-root/llama_stack_configuration.py + cp -f /opt/app-root/.e2e-rag-seed/kv_store.db /opt/app-root/.e2e-rag-work/kv_store.db + cp -f /opt/app-root/scripts/llama-stack-entrypoint.sh /opt/app-root/enrich-entrypoint.sh + cp -f /opt/app-root/src/llama_stack_configuration.py /opt/app-root/llama_stack_configuration.py + chmod 755 /opt/app-root/enrich-entrypoint.sh chmod -R 775 /opt/app-root && chown -R 1001:0 /opt/app-root volumeMounts: - name: app-root @@ -132,12 +139,17 @@ spec: value: "/opt/app-root/src" - name: HOME value: "/opt/app-root/src" + # Match GitHub Actions docker-compose + llama-stack-entrypoint.sh: + # registry/SQL under /tmp (writable); FAISS BYOK reads restored fixture outside ~/.llama + # so OGX migrate_legacy_config_dir() cannot move it away on startup. + - name: OGX_CONFIG_DIR + value: "/opt/app-root/src/.ogx" - name: KV_STORE_PATH - value: "/opt/app-root/src/.llama/storage/kv_store.db" + value: "/tmp/llama/kv_store.db" - name: KV_RAG_PATH - value: "/opt/app-root/src/.llama/storage/rag/kv_store.db" + value: "/opt/app-root/.e2e-rag-work/kv_store.db" - name: SQL_STORE_PATH - value: "/opt/app-root/src/.llama/storage/sql_store.db" + value: "/tmp/llama/sql_store.db" - name: OPENAI_API_KEY valueFrom: secretKeyRef: @@ -181,7 +193,10 @@ spec: set -e RAG_SEED="/opt/app-root/.e2e-rag-seed/kv_store.db" RAG_CM_GZ="/opt/app-root/rag-data-cm/kv_store.db.gz" - RAG_WORK="${KV_RAG_PATH:-/opt/app-root/src/.llama/storage/rag/kv_store.db}" + RAG_WORK="${KV_RAG_PATH:-/opt/app-root/.e2e-rag-work/kv_store.db}" + # Skip OGX ~/.llama → ~/.ogx migration (would steal a fixture under ~/.llama). + export OGX_CONFIG_DIR="${OGX_CONFIG_DIR:-/opt/app-root/src/.ogx}" + mkdir -p "$OGX_CONFIG_DIR" "$(dirname "$RAG_WORK")" restore_rag_seed() { mkdir -p "$(dirname "$RAG_WORK")" if [[ -f "$RAG_CM_GZ" ]]; then @@ -189,28 +204,21 @@ spec: elif [[ -f "$RAG_SEED" ]]; then cp -f "$RAG_SEED" "$RAG_WORK" chmod 664 "$RAG_WORK" 2>/dev/null || true + else + echo "FATAL: no RAG seed at $RAG_CM_GZ or $RAG_SEED" + exit 1 fi } + # Re-inflate golden FAISS fixture (same bytes GH bind-mounts from tests/e2e/rag). restore_rag_seed - INPUT_CONFIG="${LLAMA_STACK_CONFIG:-/opt/app-root/run.yaml}" - ENRICHED_CONFIG="/opt/app-root/run.yaml" - LIGHTSPEED_CONFIG="${LIGHTSPEED_CONFIG:-/opt/app-root/lightspeed-stack.yaml}" - if [[ -f "$LIGHTSPEED_CONFIG" ]]; then - echo "Enriching llama-stack config..." - ENRICHMENT_FAILED=0 - /opt/app-root/.venv/bin/python3 /opt/app-root/llama_stack_configuration.py \ - -c "$LIGHTSPEED_CONFIG" \ - -i "$INPUT_CONFIG" \ - -o "$ENRICHED_CONFIG" 2>&1 || ENRICHMENT_FAILED=1 - if [[ -f "$ENRICHED_CONFIG" ]] && [[ "$ENRICHMENT_FAILED" -eq 0 ]]; then - echo "Using enriched config: $ENRICHED_CONFIG" - restore_rag_seed - exec ogx stack run "$ENRICHED_CONFIG" - fi + if [[ ! -x /opt/app-root/enrich-entrypoint.sh ]]; then + echo "FATAL: missing /opt/app-root/enrich-entrypoint.sh (init should install it)" + exit 1 fi - echo "Using original config: $INPUT_CONFIG" - restore_rag_seed - exec ogx stack run "$INPUT_CONFIG" + # Same enrich + ogx start path as GitHub Actions (docker-compose entrypoint). + export LLAMA_STACK_CONFIG="${LLAMA_STACK_CONFIG:-/opt/app-root/run.yaml}" + export LIGHTSPEED_CONFIG="${LIGHTSPEED_CONFIG:-/opt/app-root/lightspeed-stack.yaml}" + exec /opt/app-root/enrich-entrypoint.sh ports: - containerPort: 8321 readinessProbe: diff --git a/tests/e2e-prow/rhoai/manifests/lightspeed/llama-stack-prow.yaml b/tests/e2e-prow/rhoai/manifests/lightspeed/llama-stack-prow.yaml index 271304cbd..aae24181e 100644 --- a/tests/e2e-prow/rhoai/manifests/lightspeed/llama-stack-prow.yaml +++ b/tests/e2e-prow/rhoai/manifests/lightspeed/llama-stack-prow.yaml @@ -30,13 +30,15 @@ spec: - -c - | set -e - mkdir -p /data/src/.llama/storage/rag /data/src/.llama/storage/files /data/.e2e-rag-seed + mkdir -p /data/src/.llama/storage/rag /data/src/.llama/storage/files /data/src/.ogx /data/.e2e-rag-seed if [ ! -f /rag-data/kv_store.db.gz ]; then echo "FATAL: missing /rag-data/kv_store.db.gz" ls -la /rag-data || true exit 1 fi gunzip -c /rag-data/kv_store.db.gz > /data/.e2e-rag-seed/kv_store.db + # Fixture stays on the emptyDir (mounted at .llama/storage in the main container). + # OGX_CONFIG_DIR must be set so migrate_legacy_config_dir() does not move ~/.llama. cp -f /data/.e2e-rag-seed/kv_store.db /data/src/.llama/storage/rag/kv_store.db chmod -R 777 /data/src /data/.e2e-rag-seed echo "RAG data extracted successfully" @@ -85,6 +87,9 @@ spec: value: "/opt/app-root/src" - name: HOME value: "/opt/app-root/src" + # Prevent OGX from shutil.move(~/.llama → ~/.ogx) which would steal the fixture. + - name: OGX_CONFIG_DIR + value: "/opt/app-root/src/.ogx" - name: KV_STORE_PATH value: "/opt/app-root/src/.llama/storage/kv_store.db" - name: KV_RAG_PATH @@ -134,6 +139,8 @@ spec: RAG_SEED="/opt/app-root/src/.llama/storage/.e2e-rag-seed/kv_store.db" RAG_CM_GZ="/opt/app-root/rag-data-cm/kv_store.db.gz" RAG_WORK="${KV_RAG_PATH:-/opt/app-root/src/.llama/storage/rag/kv_store.db}" + export OGX_CONFIG_DIR="${OGX_CONFIG_DIR:-/opt/app-root/src/.ogx}" + mkdir -p "$OGX_CONFIG_DIR" "$(dirname "$RAG_WORK")" restore_rag_seed() { mkdir -p "$(dirname "$RAG_WORK")" if [[ -f "$RAG_CM_GZ" ]]; then diff --git a/tests/e2e-prow/rhoai/pipeline-konflux.sh b/tests/e2e-prow/rhoai/pipeline-konflux.sh index c711826ed..9b90dfd4d 100755 --- a/tests/e2e-prow/rhoai/pipeline-konflux.sh +++ b/tests/e2e-prow/rhoai/pipeline-konflux.sh @@ -67,8 +67,10 @@ oc get ns "$NAMESPACE" >/dev/null 2>&1 || oc create namespace "$NAMESPACE" create_secret() { local name=$1; shift - log "Creating secret $name..." - oc create secret generic "$name" "$@" -n "$NAMESPACE" 2>/dev/null || log "Secret $name exists" + log "Creating/updating secret $name..." + # Upsert: a stale FAISS_VECTOR_STORE_ID from a prior run in this namespace + # would otherwise leave registration/search pointing at the wrong store. + oc create secret generic "$name" "$@" -n "$NAMESPACE" --dry-run=client -o yaml | oc apply -f - } create_secret openai-api-key-secret --from-literal=key="$OPENAI_API_KEY" @@ -215,7 +217,12 @@ conn.close() fi gzip -c "$RAG_DB_PATH" > /tmp/kv_store.db.gz - oc create configmap rag-data -n "$NAMESPACE" --from-file=kv_store.db.gz=/tmp/kv_store.db.gz + # Do not use `oc apply` here: client-side apply stores the full object in + # metadata.annotations.kubectl.kubernetes.io/last-applied-configuration + # (256KiB limit). The gzipped FAISS fixture (~800KiB+) overflows that. + oc delete configmap rag-data -n "$NAMESPACE" --ignore-not-found + oc create configmap rag-data -n "$NAMESPACE" \ + --from-file=kv_store.db.gz=/tmp/kv_store.db.gz rm /tmp/kv_store.db.gz log "✅ RAG data ConfigMap created from $RAG_DB_PATH" else @@ -408,8 +415,6 @@ log "LCS accessible at: http://$E2E_LSC_HOSTNAME:8080" log "Mock JWKS accessible at: http://$E2E_JWKS_HOSTNAME:8000" log "Llama Stack (e2e client hooks) at: http://$E2E_LLAMA_HOSTNAME:$E2E_LLAMA_PORT" - - #======================================== # 7. RUN TESTS #======================================== diff --git a/tests/e2e/features/unified-mode-validation.feature b/tests/e2e/features/unified-mode-validation.feature index a298e89f2..335dcbb51 100644 --- a/tests/e2e/features/unified-mode-validation.feature +++ b/tests/e2e/features/unified-mode-validation.feature @@ -19,6 +19,7 @@ Feature: Unified mode configuration validation Then the validation error contains --migrate-config + Scenario: config_format_version legacy with unified-shaped body fails at load Given The service uses the lightspeed-stack-invalid-version-legacy-unified-body.yaml configuration When configuration validation is attempted for the active configuration