forked from NVIDIA/aicr
-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy path.settings.yaml
More file actions
206 lines (197 loc) · 11.1 KB
/
Copy path.settings.yaml
File metadata and controls
206 lines (197 loc) · 11.1 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
# Copyright (c) 2026, NVIDIA CORPORATION & AFFILIATES. All rights reserved.
#
# Licensed under the Apache License, Version 2.0 (the "License");
# you may not use this file except in compliance with the License.
# You may obtain a copy of the License at
#
# http://www.apache.org/licenses/LICENSE-2.0
#
# Unless required by applicable law or agreed to in writing, software
# distributed under the License is distributed on an "AS IS" BASIS,
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
# See the License for the specific language governing permissions and
# limitations under the License.
# Language Versions
# Go toolchain version is owned by .go-version (single source of truth).
# Makefile, CI workflows, and validator Dockerfiles all read from there.
# Build Tools
build_tools:
# renovate: datasource=github-releases depName=goreleaser/goreleaser depType=build_tools
goreleaser: 'v2.17.1'
# renovate: datasource=github-releases depName=ko-build/ko depType=build_tools
ko: 'v0.19.1'
# renovate: datasource=github-releases depName=google/go-containerregistry depType=build_tools
crane: 'v0.21.9'
# renovate: datasource=github-releases depName=orhun/git-cliff depType=build_tools
git_cliff: '2.13.1'
# Linting
linting:
# renovate: datasource=go depName=golang.org/x/exp depType=linting
apidiff: 'v0.0.0-20260813180055-c1d0aacb2297'
# renovate: datasource=github-releases depName=golangci/golangci-lint depType=linting
golangci_lint: 'v2.12.2'
# renovate: datasource=pypi depName=yamllint depType=linting
yamllint: '1.38.0'
# renovate: datasource=github-releases depName=google/addlicense depType=linting
addlicense: 'v1.2.0'
# renovate: datasource=github-releases depName=google/go-licenses depType=linting
go_licenses: 'v2.0.1'
# MDX toolchain for tools/check-docs-mdx-parse (the parser-level docs gate) is
# owned by tools/mdx/package.json + package-lock.json, not listed here. The
# lockfile freezes the full transitive tree, which a version string cannot;
# this gate decides which docs merge, so its verdict must be reproducible.
# Renovate updates it natively via the npm manager. Same single-source-of-truth
# split as the Go toolchain living in .go-version.
# Security Tools
security_tools:
# renovate: datasource=github-releases depName=anchore/grype depType=security_tools
grype: 'v0.117.0'
# renovate: datasource=github-releases depName=sigstore/cosign depType=security_tools
cosign: 'v3.1.3'
# renovate: datasource=github-releases depName=anchore/syft depType=security_tools
syft: 'v1.51.0'
# renovate: datasource=github-releases depName=oras-project/oras depType=security_tools
# Attaches the aiperf-bench third-party source archive as an OCI 1.1 referrer
# (tools/generate-aiperf-source). Cosign cannot attach arbitrary artifacts, so
# this is a separate dependency from the signing/attestation path.
#
# Stored WITHOUT the leading 'v', unlike cosign/syft/grype above:
# oras-project/setup-oras looks the version up against bare release keys and
# throws on 'v1.3.0'. tools/setup-tools re-adds the prefix for the download URL.
oras: '1.3.0'
# E2E Testing Tools
testing_tools:
# renovate: datasource=github-releases depName=kubernetes/kubernetes depType=testing_tools
kubectl: 'v1.36.3'
# kubelogin: Entra exec-plugin for AKS kubeconfigs, installed by uat-azure.yaml
# via `az aks install-cli` (which defaults to latest without an explicit pin).
# renovate: datasource=github-releases depName=Azure/kubelogin depType=testing_tools
kubelogin: 'v0.2.19'
# renovate: datasource=github-releases depName=kubernetes-sigs/kind depType=testing_tools
kind: '0.32.0'
# renovate-digest: datasource=git-refs depName=nvkind packageName=https://github.com/NVIDIA/nvkind branch=main depType=testing_tools
nvkind: 'c57050497cffee36f10c8b918d2727c4f26d886e'
# renovate: datasource=github-releases depName=tilt-dev/ctlptl depType=testing_tools
ctlptl: '0.9.4'
# renovate: datasource=github-releases depName=tilt-dev/tilt depType=testing_tools
tilt: '0.37.7'
# renovate: datasource=github-releases depName=helm/helm depType=testing_tools
helm: 'v4.2.4'
# renovate: datasource=github-releases depName=databus23/helm-diff depType=testing_tools
helm_diff: 'v3.15.11'
# renovate: datasource=github-releases depName=helmfile/helmfile depType=testing_tools
helmfile: 'v1.7.3'
# helmfile_checksums are refreshed automatically by tools/update-helmfile-checksums
# via Renovate postUpgradeTasks whenever the helmfile version above is bumped.
helmfile_checksums:
linux_amd64: '23d7df593f704ab1709b3020c8c8083b1517c9e780b5010e756a7d36bd901552'
linux_arm64: '4a2346df40362f49f395e47d5d6a16a29322b5c6968720c1bde60d101ae97e3b'
darwin_amd64: 'b1be552f6ff68c7c10f064dec657e4297bc581eecf1ed66ff433964e17d9eb36'
darwin_arm64: 'b69933ab364b010c320d1c858265d1845735784d8b317211e046cf74e22c6e80'
# renovate: datasource=github-releases depName=kubernetes-sigs/kwok depType=testing_tools
kwok: 'v0.8.0'
# renovate: datasource=github-releases depName=kyverno/chainsaw depType=testing_tools
chainsaw: 'v0.2.15'
# chainsaw_checksums are refreshed automatically by tools/update-chainsaw-checksums
# via Renovate postUpgradeTasks whenever the chainsaw version above is bumped.
chainsaw_checksums:
linux_amd64: '295d226c89f126c0a97775d364be149f47a810c8a3f9829ee410583d0c1abe3c'
linux_arm64: 'fecf5f3ea74d11da2cd5d95a4c016d5d2543cbc4844ce21adf5e727e7ffd9e44'
darwin_amd64: 'ddb56002ff8c6265f55ec40c82eb0ef0dddec5127dd12d4fc5e7953453481f4b'
darwin_arm64: '502bef17dd822217e82590e9ccf01c1e26a56b3fa34a835789b9af73e82a169a'
# renovate: datasource=github-releases depName=mikefarah/yq depType=testing_tools
yq: 'v4.53.3'
# AWS CLI used by the KMS e2e to provision keys against the MiniStack emulator.
# renovate: datasource=pypi depName=awscli depType=testing_tools
awscli: '1.46.0'
# MiniStack: MIT-licensed, token-free AWS emulator (https://ministack.org) used
# by the KMS e2e in place of LocalStack, whose latest/stable images now refuse
# to boot without a paid license token. Pinned (never :latest) for reproducibility.
# Run with USE_SSL=1: sigstore's awskms signer hardcodes https://, so the e2e
# serves TLS with a mkcert cert (see mkcert below).
# renovate: datasource=docker depName=ministackorg/ministack depType=testing_tools
ministack_image: 'ministackorg/ministack:1.4.17'
# OpenBAO: the Linux Foundation Apache-2.0 fork of HashiCorp Vault, used by the
# Vault KMS e2e to exercise the hashivault:// signing/verification path against
# a real Transit secrets engine. API-identical to Vault; the sigstore hashivault
# provider drives it over plain HTTP in dev mode (no TLS needed). Pinned (never
# :latest) for reproducibility.
# renovate: datasource=docker depName=openbao/openbao depType=testing_tools
openbao_image: 'openbao/openbao:2.6.1'
# mkcert issues a trusted localhost cert for MiniStack's TLS and installs its CA
# into the system trust store, so the Go AWS SDK accepts the awskms:// endpoint.
# renovate: datasource=github-releases depName=FiloSottile/mkcert depType=testing_tools
mkcert: 'v1.4.4'
# SHA256 of the mkcert release binaries (Linux only; macOS installs via brew).
# Update alongside the mkcert version above.
mkcert_checksums:
linux_amd64: '6d31c65b03972c6dc4a14ab429f2928300518b26503f58723e532d1b0a3bbb52'
linux_arm64: 'b98f2cc69fd9147fe4d405d859c57504571adec0d3611c3eefd04107c7ac00d0'
# renovate: datasource=github-releases depName=kubernetes-sigs/karpenter depType=testing_tools
karpenter: 'v1.14.0'
# In-cluster OCI registry for KWOK deployer-matrix CI (issue #843).
# Pulled from ECR Public (AWS's first-party mirror of Docker official
# images): anonymous Docker Hub pulls rate-limit on shared CI runners
# (main red 4 consecutive KWOK runs, 2026-07-09). Do not regress to a
# bare Docker Hub pin on bump.
# renovate: datasource=docker depName=public.ecr.aws/docker/library/registry depType=testing_tools
registry_image: 'public.ecr.aws/docker/library/registry:3.1.1'
# Argo CD Helm chart for KWOK deployer-matrix CI. v9.5.x pins app v3.4.x,
# the first stable line with native OCI artifact source (issue #843).
# renovate: datasource=helm depName=argo-cd registryUrl=https://argoproj.github.io/argo-helm depType=testing_tools
argocd_chart: '9.5.14'
# sigstore scaffold umbrella chart for the private-Sigstore signing e2e
# (Fulcio + Rekor + CTLog + Trillian). Deploys plain Deployment + ClusterIP
# Services reachable via port-forward on macOS and Linux (issue #1215).
# renovate: datasource=helm depName=scaffold registryUrl=https://sigstore.github.io/helm-charts depType=testing_tools
scaffold_chart: '0.6.109'
# Flux 2 release for KWOK deployer-matrix CI flux-oci lane (issue #843).
# install.yaml is downloaded from the GitHub release; source-controller,
# kustomize-controller and helm-controller are the only controllers the
# bundle consumes (OCIRepository -> Kustomization -> HelmRelease).
# renovate: datasource=github-releases depName=fluxcd/flux2 depType=testing_tools
flux_version: 'v2.9.4'
# In-cluster Git server for the KWOK flux-git deployer lane (issue #963).
# Rootless variant so the admin-user bootstrap can `kubectl exec gitea
# admin user create` directly without su gymnastics.
# Pulled from docker.gitea.com (Gitea's first-party registry): anonymous
# Docker Hub pulls rate-limit on shared CI runners. Do not regress to a
# Docker Hub pin on bump.
# renovate: datasource=docker depName=docker.gitea.com/gitea depType=testing_tools
gitea_image: 'docker.gitea.com/gitea:1.26.4-rootless'
# renovate: datasource=github-releases depName=hauler-dev/hauler depType=testing_tools
hauler: 'v2.0.3'
# renovate: datasource=github-releases depName=zarf-dev/zarf depType=testing_tools
zarf: 'v0.83.0'
# Quality Thresholds
quality:
coverage_threshold: '80'
lint_timeout: '10m'
test_timeout: '10m'
# Build Configuration
build:
image_registry: 'ghcr.io/nvidia'
# Testing Configuration
testing:
# renovate: datasource=docker depName=kindest/node depType=testing
kind_node_image: 'kindest/node:v1.36.1'
# renovate: datasource=docker depName=kindest/node depType=testing
h100_kind_node_image: 'kindest/node:v1.36.1'
# GPU CI runtime pins consumed through .github/actions/load-versions.
# renovate: datasource=helm depName=gpu-operator depType=testing
gpu_operator_chart_version: 'v26.3.3'
# Base image for the CI smoke-test snapshot-agent image. The agent binary is
# static Go and detects GPUs driver-free via NFD/PCI, so it no longer needs a
# CUDA base / nvidia-smi. Matches the NVIDIA static distroless base used for
# the aicr image (see .ko.yaml).
snapshot_agent_base_image: 'nvcr.io/nvidia/distroless/static:v4.0.0@sha256:d90158b69e250d2018f32622b5c622925202ee97224a990a54b63811cb1e3d69'
# Component test harness configuration
# Used by tools/component-test/ scripts to validate individual components
component_test:
nvml_mock_version: '0.1.0'
nvml_mock_image: 'ghcr.io/nvidia/nvml-mock'
default_gpu_profile: 'a100'
default_gpu_count: 8
cluster_name: 'aicr-component-test'
helm_timeout: '300s'
health_check_timeout: '5m'