Skip to content

chore: open-source readiness — PR CI, drop the internal pipeline, public images, English docs - #2

Open
imneov wants to merge 15 commits into
mainfrom
chore/open-source-readiness
Open

imneov wants to merge 15 commits into
mainfrom
chore/open-source-readiness

Conversation

@imneov

@imneov imneov commented Oct 2, 2026 •

Copy link
Copy Markdown

What type of PR is this?

  • bug fix
  • documentation
  • install / chart
  • CI / tooling

What this PR does and why

Brings autoconfig in line with the organization's open-source baseline (same as console and hang-watcher). One concern per commit:

  1. chore: stop tracking the .DS_Store committed at the root; ignore it.
  2. chore(ci): delete .gitlab-ci.yml. It only built images and the chart for the internal registry and named that registry, its base-image cache and its runner. The comments in release.yml and the three Dockerfiles that pointed at it now document the build args with placeholders.
  3. chore: the Makefile, config/manager and the chart default to the images release.yml publishes (4pdosc/autoconfig*) instead of the internal registry. make docker-build no longer passes internal base-image / China Go-proxy overrides by default (BUILD_ARGS still accepts them). Chart home points at GitHub. The kustomize tag moves from 0.3.41 (no public image) to 0.4.0.
  4. chore: samples and e2e scripts use public images: 4pdosc/autoconfig* (default tag 0.4.0, the first release under routing.modelsphere.dev), 4pdosc/llm-openresty:0.1.20, 4pdosc/cache_aware_router:0.6.5, python:3.12-alpine, upstream lmsysorg/sglang:v0.5.10.post1 (instead of an internally patched build of the same version). llm-monitor has no public image, so MON_IMG must now be set and the scripts say so. A hard-coded node of an internal cluster in the backend samples is now a commented nodeName placeholder.
  5. docs: four comments named an internal routing product as the example of a proxy in front of openresty; they now say "upstream proxy".
  6. docs(deploy): DEPLOY.md installed everything from the internal ChartMuseum; it now uses https://modelsphere.github.io/helm-charts (modelsphere/autoconfig, modelsphere/openresty, modelsphere/cart). monitor has no public chart: the guide says so and how to skip it (spec.monitor is optional).
  7. fix(docker): release.yml builds linux/amd64 and linux/arm64, but the Dockerfiles fixed GOARCH=amd64, so the arm64 images contain an amd64 binary. GOOS/GOARCH now come from BuildKit's TARGETOS/TARGETARCH (defaulting to linux/amd64 for the legacy builder, so the amd64 image is unchanged).
  8. ci: ci.yml on every pull request and push to main — gofmt, go vet, make test (regenerates CRD/RBAC/deepcopy, vets, runs the unit tests; there is no envtest) plus a check that generation leaves no diff, helm lint --strict + helm template of deploy/helm/autoconfig, a docker build of the main Dockerfile, and the license/credential gate. Actions pinned to SHAs, read-only token.
  9. ci: Dependabot for Go modules (k8s grouped) and Actions. No docker entry: the FROM lines are build args, which Dependabot cannot follow.
  10. docs: NOTICE — the direct Go dependencies in the images with licenses read from their LICENSE files, and the base images.
  11. docs: README.md is now English; the Chinese original is README.zh-CN.md. Two stale statements corrected in both (how images are released; CI now reruns generation).
  12. docs: DEPLOY.md is now English; the Chinese is DEPLOY.zh-CN.md.
  13. docs(changelog): CHANGELOG.md in Keep a Changelog form: one dated section per tag on the remote (0.3.45, 0.3.46, 0.3.47, 0.4.0), from git log between the tags, plus Unreleased for this PR.
  14. docs: a test comment named an internal machine; now "a test cluster".

Not in this PR: code comments, CRD field descriptions, templates and e2e scripts are still largely Chinese (about 1,150 lines in Go, 230 in the generated CRDs, 360 in e2e scripts, 230 in config/chart YAML); translating them is a separate PR. RUN_BOOK.md is removed (last commit): it was the runbook for one internal cluster — its machine, a day's version snapshot, tools outside this repo.

The Helm chart in modelsphere/helm-charts (charts/autoconfig) is a separate copy and is not touched here.

Which issue(s) this PR fixes

None — open-source readiness.

How it was tested

  • make test (controller-gen crd/rbac/object, go fmt, go vet, go test ./...): pass — controller, discovery, reload, sink ok; git status clean afterwards (generated files match).
  • gofmt -l .: empty.
  • helm lint --strict deploy/helm/autoconfig: 1 chart linted, 0 failed; helm template: renders.
  • GOOS=linux GOARCH=arm64 go build ./cmd: produces an aarch64 ELF (the Dockerfile fix relies on this).
  • bash -n on every e2e script: no syntax errors. The e2e scripts themselves need a cluster and were not run.
  • docker build: this machine cannot pull from Docker Hub; the docker job in this PR's CI builds the main Dockerfile.

Checks

  • Tests and linters for what changed pass locally (see the repository's README or CONTRIBUTING)
  • Docs updated where behaviour, a config key or a chart value moved
  • No internal hostnames, IPs, registries or credentials

Release note

The arm64 images now contain an arm64 binary (they shipped an amd64 one). The chart, kustomize manifests and Makefile default to the public 4pdosc/autoconfig images.

imneov added 15 commits October 2, 2026 12:19
A macOS Finder metadata file was committed at the repository root.
Remove it and ignore it everywhere.
.gitlab-ci.yml only built images and the chart for the internal registry,
and named that registry, its base-image cache and its runner. Public images
are built by .github/workflows/release.yml.

The comments in release.yml and the three Dockerfiles that pointed at it
are rewritten: the build args are documented with placeholders instead of
internal hosts.
The Makefile, the kustomize manager config and the Helm chart defaulted to
images in the internal registry, and the Makefile passed internal base-image
and Go-proxy overrides to every docker build.

- IMG / RELOAD_IMG, config/manager and the chart's image.repository now
  name the images release.yml publishes (4pdosc/autoconfig*). The kustomize
  tag moves from 0.3.41, which has no public image, to 0.4.0.
- BUILD_ARGS is empty by default; the Dockerfile defaults are public.
- Chart.yaml home points at the GitHub repository and lists it as source.
The e2e scripts and sample manifests pulled every image from the internal
registry, and the backend samples pinned a node of an internal cluster.

- autoconfig images: 4pdosc/autoconfig{,-reload,-hagate}. The default tag
  moves from 0.3.22 to 0.4.0, the first release serving the
  routing.modelsphere.dev API group these scripts already use. AC/ACR can
  now be overridden like the other images.
- openresty and CART: the public 4pdosc/llm-openresty:0.1.20 and
  4pdosc/cache_aware_router:0.6.5 (overridable as before).
- Mock/utility pods: python:3.12-alpine from Docker Hub.
- llm-monitor has no public image: MON_IMG must now be set explicitly and
  the scripts stop with a message if it is not.
- qwen sample: upstream lmsysorg/sglang:v0.5.10.post1 instead of an
  internally patched build of the same version.
- Backend samples: the hard-coded nodeName is a commented placeholder.
- Script comments no longer name an internal host.
Four comments (controller, openresty sink and its test, the minimax-h3
sample) named an internal routing product as the example of a proxy in
front of openresty. They now say "upstream proxy"; the reasoning they
explain is unchanged.
DEPLOY.md installed every chart from the internal ChartMuseum and listed
versions through its API. It now uses https://modelsphere.github.io/helm-charts:
modelsphere/autoconfig, modelsphere/openresty and modelsphere/cart (the
public name of the cache_aware_router chart), with helm search for versions.

monitor has no public chart or image; the guide says so and how to skip it
(drop spec.monitor from the ModelRoute). Pointers to an internal scripts
directory and an internal host default are replaced.
release.yml builds every image for linux/amd64 and linux/arm64, but the
three Dockerfiles fixed GOARCH=amd64 in the builder stage. Under QEMU the
arm64 build therefore produced an amd64 binary and shipped it in the arm64
image, which cannot run it.

GOOS/GOARCH now come from BuildKit's TARGETOS/TARGETARCH, defaulting to
linux/amd64 for the legacy builder, so the amd64 image is unchanged.
Until now the only workflow was the tag-triggered release, so a pull
request got no feedback. ci.yml runs on pull requests and pushes to main:

- go: gofmt, go vet, make test (regenerates CRD/RBAC/deepcopy, vets and
  runs the unit tests), then fails if the regeneration changed anything.
- helm: helm lint --strict and helm template of deploy/helm/autoconfig.
- docker: builds the controller image from the Dockerfile.
- gate: the license text and committed credential files, as in console.

Actions are pinned to commit SHAs; the token is read-only.
Weekly updates for Go modules (k8s.io and sigs.k8s.io grouped) and the
pinned GitHub Actions. Docker is left out: the Dockerfiles take their base
images from build args, which Dependabot does not follow.
Project copyright and license, the direct Go dependencies compiled into the
images with their licenses (read from each module's LICENSE), and the base
images.
README.md was written in Chinese. It is now an English translation, and the
Chinese original moves to README.zh-CN.md; each links to the other.

Two statements in the original were no longer true and are corrected in
both: images are released by release.yml to Docker Hub (the chart lives in
modelsphere/helm-charts), and CI now reruns code generation.
DEPLOY.md was written in Chinese. It is now an English translation of the
(already de-internalised) guide, and the Chinese original moves to
DEPLOY.zh-CN.md; each links to the other. Both now mention that the backend
samples read the model from a hostPath and need nodeName set.
One dated section per tag on the remote (0.3.45, 0.3.46, 0.3.47, 0.4.0),
derived from git log between the tags and dated by the tag commit, plus an
Unreleased section for this change set. Compare links at the bottom.
A comment in slo_test.go named the internal machine an experiment ran on;
it now says a test cluster.
RUN_BOOK.md walked through one internal cluster: its machine, the versions
deployed there on one day, and tools outside this repository. Nothing in it
applies to anyone else's installation; DEPLOY.md is the public guide.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant