Files
foxhunt/infra/k8s/gitlab/runner-values.yaml
jgrusewski c731bef759 feat(infra): split training image into RL + supervised, rename ci-compile → ci-rl
RL models (DQN/PPO) only need basic CUDA runtime (~2GB), while supervised
models need cuDNN (~4GB). Splitting saves ~2GB pull time per RL job.
Rename the L4 GPU pool from ci-compile to ci-rl to reflect its actual use.
Add DaemonSet image pre-puller to cache training images on GPU nodes.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-28 10:16:42 +01:00

99 lines
4.0 KiB
YAML

# GitLab Runner — Kubernetes executor
# Runner manager pod lives on gitlab node pool
# Default: build pods spawn on ci-rl pool (L4: 24GB VRAM, cheaper)
# Training jobs override to ci-training pool (L40S: 48GB VRAM) via node_selector
gitlabUrl: http://gitlab-webservice-default.foxhunt.svc.cluster.local:8181
# runnerToken set via --set at install time
replicas: 1
nodeSelector:
k8s.scaleway.com/pool-name: gitlab
tolerations:
- key: gitlab
operator: Equal
value: "true"
effect: NoSchedule
runners:
# Override clone URL to internal service (pods can't reach Tailscale IPs)
cloneUrl: http://gitlab-webservice-default.foxhunt.svc.cluster.local:8181
config: |
[[runners]]
clone_url = "http://gitlab-webservice-default.foxhunt.svc.cluster.local:8181"
tag_list = ["kapsule", "rust", "docker", "gpu"]
[runners.kubernetes]
namespace = "foxhunt"
image = "rust:1.89-slim"
privileged = false
# Allow CI jobs to override node selector via KUBERNETES_NODE_SELECTOR_* vars
# Format: KUBERNETES_NODE_SELECTOR_<LABEL>: "key=value"
node_selector_overwrite_allowed = ".*"
# Allow CI jobs to override resources via KUBERNETES_*_{REQUEST,LIMIT} vars
# Values are maximums (not regexes) — training can request up to 80Gi
cpu_request_overwrite_max_allowed = "24000m"
cpu_limit_overwrite_max_allowed = "24000m"
memory_request_overwrite_max_allowed = "80Gi"
memory_limit_overwrite_max_allowed = "80Gi"
# L40S scale-to-zero needs ~3-5 min to provision; default 180s times out
poll_timeout = 600
# All GPU node pools (ci-rl L4, ci-training L40S) have nvidia GPU
# Setting runtimeClassName=nvidia on all pods so CUDA works everywhere
runtime_class_name = "nvidia"
# Default resource limits — balanced for both Rust compile and Kaniko builds
# L4 node: 8 vCPU / 30Gi RAM, ci-rl pool max_size=2
# Compile/test: runs 2 in parallel (1 per node), needs ~20Gi for ml+CUDA linking
# Kaniko: runs after compile, needs ~200m/512Mi but gets these defaults
# With 3500m/12Gi request: 2 pods fit per L4 node = 4 concurrent Kaniko builds
cpu_request = "3500m"
cpu_limit = "7800m"
memory_request = "12Gi"
memory_limit = "28Gi"
helper_cpu_request = "100m"
helper_cpu_limit = "500m"
helper_memory_request = "128Mi"
helper_memory_limit = "512Mi"
image_pull_secrets = ["scw-registry", "gitlab-registry"]
# Sub-tables must come AFTER all scalar values (TOML rule)
[runners.kubernetes.node_selector]
"k8s.scaleway.com/pool-name" = "ci-rl"
[runners.kubernetes.node_tolerations]
"nvidia.com/gpu" = "NoSchedule"
# Cilium CNI agent takes ~30s to initialize on fresh scale-from-zero nodes
"node.cilium.io/agent-not-ready" = "NoSchedule"
[runners.kubernetes.pod_labels]
"app.kubernetes.io/part-of" = "foxhunt-ci"
# Mount training data PVC (Databento futures .dbn.zst files)
# Path must NOT be under /data — Redis image's WORKDIR is /data and entrypoint chowns it
[[runners.kubernetes.volumes.pvc]]
name = "training-data-pvc"
mount_path = "/mnt/training-data"
read_only = true
# sccache on local block storage — faster than S3 for cache hits
[[runners.kubernetes.volumes.pvc]]
name = "sccache-pvc"
mount_path = "/mnt/sccache"
read_only = false
# Runner tags for job matching
tags: "kapsule,rust,docker,gpu"
# Concurrency — 10 allows all 9 Kaniko builds + test to run in parallel
concurrent: 10
# RBAC for runner to spawn pods
rbac:
create: true
rules:
- apiGroups: [""]
resources: ["pods", "pods/exec", "pods/log", "secrets", "configmaps"]
verbs: ["get", "list", "watch", "create", "delete", "update", "patch"]
- apiGroups: [""]
resources: ["pods/attach"]
verbs: ["create", "get"]
serviceAccount:
create: true
name: gitlab-runner