Skip to content

Commit 4025894

Browse files
authored
chore(snap): remove early snap packaging (NVIDIA#1648)
1 parent 7274a6b commit 4025894

8 files changed

Lines changed: 76 additions & 474 deletions

File tree

‎deploy/snap/README.md‎

Lines changed: 0 additions & 177 deletions
This file was deleted.

‎deploy/snap/meta/snap.yaml.in‎

Lines changed: 0 additions & 53 deletions
This file was deleted.

‎docs/about/installation.mdx‎

Lines changed: 59 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -75,6 +75,65 @@ To keep the user service running after logout, enable linger:
7575
sudo loginctl enable-linger $USER
7676
```
7777

78+
## Snap
79+
80+
Install the OpenShell snap from the Snap Store:
81+
82+
```shell
83+
sudo snap install openshell --classic
84+
```
85+
86+
The snap defines two apps: the `openshell` CLI and the `openshell.gateway`
87+
systemd service. The gateway listens on `https://127.0.0.1:17670` and
88+
stores its database at `$SNAP_COMMON/gateway.db` (typically
89+
`/var/snap/openshell/common/gateway.db`). Create `$SNAP_COMMON/gateway.toml`
90+
when you need to override gateway settings.
91+
92+
### Snap store installs
93+
94+
When installing from the Snap Store, snapd automatically connects the `home`,
95+
`network`, `network-bind`, and `ssh-keys` plugs. The `docker` plug still
96+
requires manual connection:
97+
98+
```shell
99+
sudo snap connect openshell:docker docker:docker-daemon
100+
```
101+
102+
The snap declares `default-provider: docker` on the Docker plug so snapd will
103+
offer to install the Docker snap, but the connection itself must be made
104+
manually.
105+
106+
### Locally built snap packages
107+
108+
When installing a locally built `.snap` file, no plugs are connected by default:
109+
110+
```shell
111+
sudo snap install ./openshell_*.snap --dangerous --classic
112+
sudo snap connect openshell:home
113+
sudo snap connect openshell:network
114+
sudo snap connect openshell:network-bind
115+
sudo snap connect openshell:ssh-keys
116+
sudo snap connect openshell:docker docker:docker-daemon
117+
sudo snap connect openshell:log-observe
118+
sudo snap connect openshell:system-observe
119+
```
120+
121+
The `log-observe` and `system-observe` plugs are needed for the gateway service
122+
to read logs and inspect system processes. The `docker` plug requires the
123+
`docker:docker-daemon` slot from the Docker snap and does not work with
124+
system-installed Docker.
125+
126+
### Gateway service
127+
128+
The gateway runs as a snap daemon with `refresh-mode: endure`, meaning snapd
129+
will not restart it during snap refreshes. This prevents the gateway from
130+
killing active sandbox sessions mid-refresh. Restart the service manually after
131+
a snap refresh when you need the updated binary:
132+
133+
```shell
134+
sudo systemctl restart snap.openshell.gateway
135+
```
136+
78137
## Kubernetes
79138

80139
Kubernetes deployments use the OpenShell Helm chart. For step-by-step installation, refer to [Kubernetes Setup](/kubernetes/setup). For chart values and packaging details, refer to the [Helm chart README](https://github.com/NVIDIA/OpenShell/blob/main/deploy/helm/openshell/README.md).

‎python/openshell/release_formula_test.py‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -96,7 +96,7 @@ def test_generate_homebrew_formula_uses_tagged_macos_driver_asset_without_defaul
9696

9797
def test_snap_wrapper_uses_optional_gateway_config_without_generating_toml() -> None:
9898
repo_root = Path(__file__).resolve().parents[2]
99-
wrapper = (repo_root / "deploy/snap/bin/openshell-gateway-wrapper").read_text(
99+
wrapper = (repo_root / "tasks/scripts/snap-gateway-wrapper.sh").read_text(
100100
encoding="utf-8"
101101
)
102102

‎snapcraft.yaml‎

Lines changed: 10 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -46,12 +46,21 @@ apps:
4646
gateway:
4747
command: bin/openshell-gateway-wrapper
4848
daemon: simple
49+
# refresh-mode: endure prevents snapd from restarting the gateway daemon
50+
# during snap refreshes, which would kill active sandbox sessions.
51+
# Operators must manually restart the service after a refresh if needed.
4952
refresh-mode: endure
53+
# The wrapper sets OPENSHELL_DISABLE_TLS=true and OPENSHELL_DB_URL to
54+
# use $SNAP_COMMON/gateway.db. If $SNAP_COMMON/gateway.toml exists it is
55+
# passed to the gateway as --config, allowing operators to override
56+
# settings without rebuilding the snap.
5057
environment:
5158
XDG_DATA_HOME: "$SNAP_COMMON"
5259
XDG_RUNTIME_DIR: "$SNAP_COMMON"
5360
plugs:
5461
- docker
62+
# Docker snap is required because the snap uses the docker:docker-daemon
63+
# interface slot. It does not work with system-installed Docker.
5564
- log-observe
5665
- network
5766
- network-bind
@@ -90,7 +99,7 @@ parts:
9099
"$CRAFT_PART_INSTALL/bin/openshell-gateway"
91100
install -D -m 0755 "$CRAFT_PART_BUILD/target/release/openshell-sandbox" \
92101
"$CRAFT_PART_INSTALL/bin/openshell-sandbox"
93-
install -D -m 0755 "$CRAFT_PROJECT_DIR/deploy/snap/bin/openshell-gateway-wrapper" \
102+
install -D -m 0755 "$CRAFT_PROJECT_DIR/tasks/scripts/snap-gateway-wrapper.sh" \
94103
"$CRAFT_PART_INSTALL/bin/openshell-gateway-wrapper"
95104
install -D -m 0644 "$CRAFT_PROJECT_DIR/snap/local/term.desktop" \
96105
"$CRAFT_PART_INSTALL/meta/gui/term.desktop"

‎tasks/package.toml‎

Lines changed: 0 additions & 23 deletions
Original file line numberDiff line numberDiff line change
@@ -23,26 +23,3 @@ hide = true
2323
["package:deb:install"]
2424
description = "Build OpenShell from source and install the deb locally (requires sudo)"
2525
run = "tasks/scripts/package-deb-install.sh"
26-
27-
["package:snap"]
28-
description = "Build a snap package from supplied OpenShell binaries"
29-
run = "tasks/scripts/package-snap.sh"
30-
hide = true
31-
32-
["package:snap:amd64"]
33-
description = "Build an amd64 snap package from supplied OpenShell binaries"
34-
env = { OPENSHELL_SNAP_ARCH = "amd64" }
35-
run = "tasks/scripts/package-snap.sh"
36-
hide = true
37-
38-
["package:snap:arm64"]
39-
description = "Build an arm64 snap package from supplied OpenShell binaries"
40-
env = { OPENSHELL_SNAP_ARCH = "arm64" }
41-
run = "tasks/scripts/package-snap.sh"
42-
hide = true
43-
44-
["package:snap:stage"]
45-
description = "Stage a snap root from supplied OpenShell binaries without running snap pack"
46-
env = { OPENSHELL_SNAP_PACK = "0", OPENSHELL_SNAP_STAGE_DIR = "artifacts/snap-root" }
47-
run = "tasks/scripts/package-snap.sh"
48-
hide = true

0 commit comments

Comments
 (0)