Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
21e40a1774 | ||
|
|
bdc844872d | ||
|
|
299b6dc0bb | ||
|
|
9589e58ce6 | ||
|
|
be0bb36317 | ||
|
|
9b267533c9 | ||
|
|
6f092ddc12 | ||
|
|
0228ccc296 | ||
|
|
9997913929 |
@@ -58,14 +58,14 @@ override file values. Invalid values fail at startup.
|
||||
| `LLM_BUSY_STATUS` | `503` | HTTP status for rejected LLM requests in reject mode (400–599, e.g. 429) |
|
||||
| `BUSY_RETRY_AFTER` | `30` | Seconds sent as `Retry-After` on busy responses (both modes) |
|
||||
| `WARM_MODEL` | _(empty)_ | Model to reload after an image job (off by default) |
|
||||
| `COMFY_CMD` | _(empty = unmanaged)_ | Supervise ComfyUI: start on demand, stop when idle to free VRAM. Requires `COMFY_URL` |
|
||||
| `COMFY_DIR` | _(empty)_ | Working directory for `COMFY_CMD` |
|
||||
| `COMFY_CMD` | _(derived from `COMFY_DIR`; both empty = unmanaged)_ | Supervise ComfyUI: start on demand, stop when idle to free VRAM. Requires `COMFY_URL` |
|
||||
| `COMFY_DIR` | _(empty)_ | Standard venv install root: set alone to supervise ComfyUI with the derived command (`.venv` + `main.py`); also the working directory for `COMFY_CMD` |
|
||||
| `COMFY_IDLE_TIMEOUT` | `5m` | Stop the managed ComfyUI after this long idle |
|
||||
| `COMFY_START_TIMEOUT` | `2m` | Max wait for the managed ComfyUI to come up |
|
||||
| `GAME_PROCS` | _(empty = disabled)_ | Process names (comma-separated); while any runs, the GPU counts as held: requests wait, Ollama unloads, managed ComfyUI stops |
|
||||
| `GPU_FOREIGN_VRAM_MB` | `0` (disabled) | Also treat the GPU as held when a non-ignored process uses more VRAM than this (needs nvidia-smi) |
|
||||
| `GPU_IGNORE_PROCS` | `ollama,ollama app,ollama_llama_server,python,pythonw` | Process names never counted as foreign GPU users |
|
||||
| `GAME_POLL_INTERVAL` | `5s` | How often game/VRAM detection runs |
|
||||
| `GAME_POLL_INTERVAL` | `15s` | How often game/VRAM detection runs (don't go below ~10s — nvidia-smi polls keep the GPU awake) |
|
||||
| `LOGLEVEL` | `warn` | `info` logs every request (colored arrows in text mode), `debug` adds lock transitions. `LOG_LEVEL` works as an alias |
|
||||
| `LOG_FORMAT` | `text` | `json` for structured JSON logs |
|
||||
| `LOG_FILE` | _(empty)_ | Append logs to this file instead of stderr |
|
||||
@@ -99,18 +99,28 @@ override file values. Invalid values fail at startup.
|
||||
class) in text mode, which renders in `docker compose logs` on Windows
|
||||
Terminal. Set `NO_COLOR` to disable colors.
|
||||
|
||||
## Managed ComfyUI (`COMFY_CMD`)
|
||||
## Managed ComfyUI (`COMFY_CMD` / `COMFY_DIR`)
|
||||
|
||||
Don't want ComfyUI running 24/7 (it holds VRAM even when idle — and the
|
||||
Desktop app kills its server when you close it)? Point `COMFY_CMD` at a
|
||||
standalone launch command and gpu-turnstile supervises it: the first
|
||||
request starts it, it stops again after `COMFY_IDLE_TIMEOUT` (default 5m)
|
||||
without work, freeing the GPU for games or the LLM. Example for a Desktop
|
||||
install (run it once manually to confirm it works):
|
||||
Desktop app kills its server when you close it)? gpu-turnstile can supervise
|
||||
it: the first request starts it, it stops again after `COMFY_IDLE_TIMEOUT`
|
||||
(default 5m) without work, freeing the GPU for games or the LLM.
|
||||
|
||||
The easy way — point `COMFY_DIR` at a standard venv install (a folder with
|
||||
`.venv` and `main.py`, or `.venv` and `ComfyUI\main.py`) and the launch
|
||||
command is derived from it, including `--port` from `COMFY_URL`:
|
||||
|
||||
```
|
||||
COMFY_URL=http://127.0.0.1:8188
|
||||
COMFY_CMD="C:\ComfyUI\.venv\Scripts\python.exe ComfyUI\main.py --port 8188"
|
||||
COMFY_URL=http://127.0.0.1:8189
|
||||
COMFY_DIR=C:\ComfyUI
|
||||
```
|
||||
|
||||
For other layouts, spell the command out yourself (run it once manually to
|
||||
confirm it works):
|
||||
|
||||
```
|
||||
COMFY_URL=http://127.0.0.1:8189
|
||||
COMFY_CMD="C:\ComfyUI\.venv\Scripts\python.exe" main.py --port 8189
|
||||
COMFY_DIR=C:\ComfyUI
|
||||
```
|
||||
|
||||
@@ -124,13 +134,22 @@ answers on the port, gpu-turnstile just uses it instead of spawning
|
||||
instance already holds the port when you open the desktop app, the
|
||||
desktop's server is the one that fails to bind.
|
||||
|
||||
One catch when gpu-turnstile runs as a service: the sandboxed service
|
||||
account may not enter your user profile, so a ComfyUI install under
|
||||
`C:\Users\...` (or `/home/...`) fails with "Access is denied".
|
||||
`--install-service` fixes that automatically — it grants
|
||||
`NT SERVICE\gpu-turnstile` recursive access to `COMFY_DIR` on Windows and
|
||||
adds a `BindPaths=` to the systemd unit on Linux. Re-run it after changing
|
||||
`COMFY_DIR`; or grant by hand from an admin shell:
|
||||
`icacls "<COMFY_DIR>" /grant "NT SERVICE\gpu-turnstile:(OI)(CI)M" /T`.
|
||||
|
||||
## Game detection
|
||||
|
||||
Want to game on the same GPU without Ollama/ComfyUI squatting on the VRAM?
|
||||
gpu-turnstile can watch for foreign GPU holders and, while one is active,
|
||||
make LLM/image requests wait (or 503, per `LLM_BUSY_MODE`), unload Ollama's
|
||||
models and stop the managed ComfyUI so the game gets the memory. Two
|
||||
detection paths, each optional, polled every `GAME_POLL_INTERVAL` (5s):
|
||||
detection paths, each optional, polled every `GAME_POLL_INTERVAL` (15s):
|
||||
|
||||
```
|
||||
GAME_PROCS=cyberpunk2077.exe,bg3.exe # the reliable way on Windows
|
||||
|
||||
@@ -128,10 +128,15 @@ state is `idle`, send `POST /api/generate {"model":WARM_MODEL,"keep_alive":-1}`
|
||||
with empty prompt to reload the chat model so the next chat doesn't pay the
|
||||
load time. Off by default.
|
||||
|
||||
### Managed ComfyUI (`COMFY_CMD`)
|
||||
### Managed ComfyUI (`COMFY_CMD` / `COMFY_DIR`)
|
||||
|
||||
When `COMFY_CMD` is set, gpu-turnstile runs ComfyUI as a supervised child
|
||||
process instead of expecting an always-on server:
|
||||
process instead of expecting an always-on server. Setting only `COMFY_DIR`
|
||||
enables the same management with the launch command derived from the
|
||||
standard venv layout under it (`.venv\Scripts\python.exe` on Windows,
|
||||
`.venv/bin/python` on Linux; `ComfyUI\main.py`, or a flat `main.py` when
|
||||
that is what exists; `--port` from the `COMFY_URL` port). Missing layout
|
||||
files are flagged in the startup log.
|
||||
|
||||
- **Start on demand**: any ComfyUI request spawns it (double quotes in the
|
||||
command line group arguments with spaces; `COMFY_DIR` sets the working
|
||||
@@ -154,12 +159,20 @@ process instead of expecting an always-on server:
|
||||
- Its stdout/stderr is forwarded to the log at INFO. The health check
|
||||
skips the intentionally-stopped/starting states; a failed probe while
|
||||
the process is alive and was previously ready is logged as DOWN.
|
||||
- **Permissions**: the service account is sandboxed (Windows virtual
|
||||
account, systemd `DynamicUser`), so a ComfyUI install inside a user
|
||||
profile is off-limits by default. `--install-service` opens it up —
|
||||
a recursive ACL grant for `NT SERVICE\gpu-turnstile` on Windows, a
|
||||
`BindPaths=` in the unit on Linux — reading `COMFY_DIR` from the config
|
||||
it installs. Re-run `--install-service` after changing `COMFY_DIR`, or
|
||||
grant by hand (admin shell):
|
||||
`icacls "<COMFY_DIR>" /grant "NT SERVICE\gpu-turnstile:(OI)(CI)M" /T`.
|
||||
|
||||
## Game detection (foreign GPU holders)
|
||||
|
||||
Games and other foreign GPU users sit outside the URL-based consumer model —
|
||||
nothing proxies through gpu-turnstile for them. Two independent detection
|
||||
paths, polled every `GAME_POLL_INTERVAL` (default 5 s); either one being
|
||||
paths, polled every `GAME_POLL_INTERVAL` (default 15 s); either one being
|
||||
configured enables the feature:
|
||||
|
||||
- **Process watch list** (`GAME_PROCS`, comma-separated, case-insensitive,
|
||||
@@ -211,14 +224,14 @@ override file values. A missing file is fine; a malformed one is fatal.
|
||||
| `LLM_BUSY_STATUS` | `503` | HTTP status for rejected LLM requests in reject mode (400–599, e.g. 429) |
|
||||
| `BUSY_RETRY_AFTER` | `30` | seconds sent as `Retry-After` on busy responses (both modes) |
|
||||
| `WARM_MODEL` | `` | optional model to reload after an image job |
|
||||
| `COMFY_CMD` | _(empty = unmanaged)_ | spawn and supervise ComfyUI on demand: first request starts it, idle stop after `COMFY_IDLE_TIMEOUT` frees its VRAM. Requires `COMFY_URL` |
|
||||
| `COMFY_DIR` | `` | working directory for `COMFY_CMD` |
|
||||
| `COMFY_CMD` | _(derived from `COMFY_DIR`; both empty = unmanaged)_ | spawn and supervise ComfyUI on demand: first request starts it, idle stop after `COMFY_IDLE_TIMEOUT` frees its VRAM. Requires `COMFY_URL` |
|
||||
| `COMFY_DIR` | `` | standard venv install root: set alone to supervise ComfyUI with the derived launch command (`.venv` + `main.py`, `--port` from `COMFY_URL`); also the working directory for `COMFY_CMD` |
|
||||
| `COMFY_IDLE_TIMEOUT` | `5m` | stop the managed ComfyUI after this long without requests or jobs |
|
||||
| `COMFY_START_TIMEOUT` | `2m` | how long a request waits for the managed ComfyUI to come up |
|
||||
| `GAME_PROCS` | _(empty = disabled)_ | comma-separated process names (case-insensitive, `.exe` optional); while any runs, the GPU counts as held by it: requests wait, Ollama unloads, the managed ComfyUI stops |
|
||||
| `GPU_FOREIGN_VRAM_MB` | `0` (disabled) | also treat the GPU as held when a process not in `GPU_IGNORE_PROCS` uses more VRAM than this; needs nvidia-smi |
|
||||
| `GPU_IGNORE_PROCS` | `ollama,ollama app,ollama_llama_server,python,pythonw` | process names never counted as foreign GPU users |
|
||||
| `GAME_POLL_INTERVAL` | `5s` | how often game/VRAM detection runs |
|
||||
| `GAME_POLL_INTERVAL` | `15s` | how often game/VRAM detection runs (nvidia-smi polls keep the GPU awake; don't go below ~10s) |
|
||||
| `LOGLEVEL` | `warn` | `info` logs every request (colored arrows in text mode), `debug` adds lock transitions. `LOG_LEVEL` is accepted as an alias |
|
||||
| `LOG_FORMAT` | `text` | `json` for structured JSON logs |
|
||||
| `LOG_FILE` | `` | append logs to this file instead of stderr (useful as a service) |
|
||||
@@ -237,7 +250,7 @@ override file values. A missing file is fine; a malformed one is fatal.
|
||||
| `UPDATE_REPO` | `https://git.rambossek.at/PUBLIC/gpu-turnstile` | repository to check for releases |
|
||||
| `UPDATE_ASSET` | `gpu-turnstile.exe` | release asset to download |
|
||||
| `APP_VER` | `stable` | version to run: `dev` disables updates, `stable` tracks the latest release, or an exact `vX.Y.Z` pin (up- or downgraded to) |
|
||||
| `CFG_VER` | _(installer-managed)_ | config format reference written by `--install-service` (always a concrete `vX.Y.Z`; a dev build stamps `v0.0.0`); missing = the file is replaced with a fresh sample (backup `.bak`) |
|
||||
| `CFG_VER` | _(installer-managed)_ | config format reference written by `--install-service` (always a concrete `vX.Y.Z`; a dev build stamps `v0.0.0`); missing = the file is replaced with a fresh sample (backup `.bak`). New settings are appended (commented out) at install and at every startup after an update changed the version |
|
||||
|
||||
Startup fails fast on unparsable values and when neither consumer URL is
|
||||
set. Enabled upstreams are probed once at start (`/api/version`,
|
||||
|
||||
@@ -15,6 +15,7 @@ import (
|
||||
"os"
|
||||
"os/signal"
|
||||
"path/filepath"
|
||||
"runtime"
|
||||
"strings"
|
||||
"syscall"
|
||||
"time"
|
||||
@@ -172,6 +173,7 @@ func main() {
|
||||
}
|
||||
log, logOut, logCloser := newLogger(cfg)
|
||||
defer logCloser.Close()
|
||||
syncEnvFile(resolveConfigPath(configPath), cfg.LogFile, log)
|
||||
|
||||
if service.IsService() {
|
||||
if err := service.Run(func(ctx context.Context) error { return run(ctx, cfg, log, logOut, true) }); err != nil {
|
||||
@@ -188,6 +190,27 @@ func main() {
|
||||
}
|
||||
}
|
||||
|
||||
// syncEnvFile upgrades an installer-written config file after an update:
|
||||
// settings added since its CFG_VER are appended (commented out) and CFG_VER
|
||||
// is bumped. Files not written by the installer (no CFG_VER), up-to-date
|
||||
// files and dev builds are left untouched; a write failure is logged, not
|
||||
// fatal.
|
||||
func syncEnvFile(path, logFile string, log *slog.Logger) {
|
||||
data, err := os.ReadFile(path)
|
||||
if err != nil {
|
||||
return // no config file; nothing to upgrade
|
||||
}
|
||||
synced, changed := config.SyncSample(string(data), version, logFile)
|
||||
if !changed {
|
||||
return
|
||||
}
|
||||
if err := os.WriteFile(path, []byte(synced), 0o644); err != nil {
|
||||
log.Warn("could not append new settings to the config file", "path", path, "err", err)
|
||||
return
|
||||
}
|
||||
log.Warn("config file updated: new settings appended", "path", path, "version", version)
|
||||
}
|
||||
|
||||
// defaultConfigPath returns gpu-turnstile.env next to the executable.
|
||||
func defaultConfigPath() string {
|
||||
exe, err := os.Executable()
|
||||
@@ -412,7 +435,26 @@ func orDisabled(url string) string {
|
||||
return url
|
||||
}
|
||||
|
||||
// managedComfyCommand resolves how ComfyUI is launched when it is managed:
|
||||
// COMFY_CMD verbatim, or the standard venv layout under COMFY_DIR. Empty
|
||||
// when neither is set (unmanaged).
|
||||
func managedComfyCommand(cfg config.Config) string {
|
||||
if cfg.ComfyCmd != "" {
|
||||
return cfg.ComfyCmd
|
||||
}
|
||||
if cfg.ComfyDir != "" {
|
||||
return supervise.DefaultComfyCommand(runtime.GOOS, cfg.ComfyDir, cfg.ComfyURL)
|
||||
}
|
||||
return ""
|
||||
}
|
||||
|
||||
func run(ctx context.Context, cfg config.Config, log *slog.Logger, logOut io.Writer, isService bool) error {
|
||||
// ComfyUI can run as a managed child — COMFY_CMD verbatim, or the
|
||||
// standard venv layout derived from COMFY_DIR alone: started on demand
|
||||
// by the proxy, stopped after COMFY_IDLE_TIMEOUT idle (and on shutdown)
|
||||
// so its VRAM is freed.
|
||||
comfyCmdLine := managedComfyCommand(cfg)
|
||||
|
||||
// The startup line carries the version and every setting and is emitted
|
||||
// at WARN so it is visible even with the default (quiet) log level.
|
||||
log.Log(ctx, slog.LevelWarn, "starting gpu-turnstile",
|
||||
@@ -438,7 +480,7 @@ func run(ctx context.Context, cfg config.Config, log *slog.Logger, logOut io.Wri
|
||||
"backoff_max", cfg.BackoffMax,
|
||||
"prompt_capture_limit", cfg.PromptCaptureLimit,
|
||||
"warm_model", cfg.WarmModel,
|
||||
"comfy_cmd", cfg.ComfyCmd,
|
||||
"comfy_cmd", orDisabled(comfyCmdLine),
|
||||
"comfy_dir", cfg.ComfyDir,
|
||||
"comfy_idle_timeout", cfg.ComfyIdleTimeout,
|
||||
"comfy_start_timeout", cfg.ComfyStartTimeout,
|
||||
@@ -472,13 +514,27 @@ func run(ctx context.Context, cfg config.Config, log *slog.Logger, logOut io.Wri
|
||||
}
|
||||
}
|
||||
|
||||
// With COMFY_CMD set, ComfyUI runs as a managed child: started on
|
||||
// demand by the proxy, stopped after COMFY_IDLE_TIMEOUT idle (and on
|
||||
// shutdown) so its VRAM is freed.
|
||||
var comfySup *supervise.Process
|
||||
if cfg.ComfyCmd != "" {
|
||||
if comfyCmdLine != "" {
|
||||
if cfg.ComfyCmd == "" {
|
||||
// Derived from COMFY_DIR: flag a wrong-looking layout early,
|
||||
// while the operator is still watching the startup log. Inside
|
||||
// a profile the service account may not enter, os.Stat fails
|
||||
// with EACCES — that reads as "not found" but means "grant
|
||||
// access", so say so.
|
||||
python, script := supervise.ComfyLayout(runtime.GOOS, cfg.ComfyDir)
|
||||
for _, p := range []string{python, script} {
|
||||
if _, err := os.Stat(p); err != nil {
|
||||
if isPermission(err) {
|
||||
log.Warn("COMFY_DIR: not accessible to the service account; grant access or re-run --install-service", "path", p)
|
||||
} else {
|
||||
log.Warn("COMFY_DIR: file not found; ComfyUI requests will fail until it exists", "path", p)
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
var err error
|
||||
comfySup, err = supervise.New("comfy", cfg.ComfyCmd, cfg.ComfyDir, comfyClient.Probe, cfg.ComfyStartTimeout, log)
|
||||
comfySup, err = supervise.New("comfy", comfyCmdLine, cfg.ComfyDir, comfyClient.Probe, cfg.ComfyStartTimeout, log)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
|
||||
@@ -6,7 +6,7 @@
|
||||
# ComfyUI --listen 0.0.0.0 --port 8189).
|
||||
services:
|
||||
gpu-turnstile:
|
||||
image: git.rambossek.at/public/gpu-turnstile:v0.1.8
|
||||
image: git.rambossek.at/public/gpu-turnstile:v0.2.0
|
||||
restart: unless-stopped
|
||||
environment:
|
||||
# Each consumer is enabled by setting its URL; leave one unset to
|
||||
|
||||
@@ -51,11 +51,14 @@ type Config struct {
|
||||
LLMBusyStatus int
|
||||
BusyRetryAfter int
|
||||
|
||||
// ComfyCmd spawns and supervises a ComfyUI server on demand (empty =
|
||||
// unmanaged, the current behavior). ComfyDir is its working directory.
|
||||
// The managed server is stopped after ComfyIdleTimeout without
|
||||
// requests, freeing its VRAM; ComfyStartTimeout bounds how long a
|
||||
// request waits for it to come up.
|
||||
// ComfyCmd spawns and supervises a ComfyUI server on demand. When
|
||||
// ComfyCmd is empty but ComfyDir is set, management is enabled with the
|
||||
// standard venv layout under ComfyDir (.venv + main.py or
|
||||
// ComfyUI/main.py; --port from the COMFY_URL port) — ComfyCmd is the
|
||||
// override for other layouts and doubles as the working directory when
|
||||
// set explicitly. The managed server is stopped after ComfyIdleTimeout
|
||||
// without requests, freeing its VRAM; ComfyStartTimeout bounds how long
|
||||
// a request waits for it to come up.
|
||||
ComfyCmd string
|
||||
ComfyDir string
|
||||
ComfyIdleTimeout time.Duration
|
||||
@@ -116,7 +119,7 @@ func Defaults() Config {
|
||||
// ComfyUI runs under python; excluding it (and Ollama) by name keeps
|
||||
// our own consumers from tripping the foreign-VRAM check.
|
||||
GPUIgnoreProcs: []string{"ollama", "ollama app", "ollama_llama_server", "python", "pythonw"},
|
||||
GamePollInterval: 5 * time.Second,
|
||||
GamePollInterval: 15 * time.Second,
|
||||
|
||||
LogLevel: slog.LevelWarn,
|
||||
}
|
||||
@@ -305,6 +308,9 @@ func Load(getenv func(string) string) (Config, error) {
|
||||
if cfg.ComfyCmd != "" && cfg.ComfyURL == "" {
|
||||
return cfg, fmt.Errorf("COMFY_CMD requires COMFY_URL to be set (the proxy needs somewhere to forward)")
|
||||
}
|
||||
if cfg.ComfyCmd == "" && cfg.ComfyDir != "" && cfg.ComfyURL == "" {
|
||||
return cfg, fmt.Errorf("COMFY_DIR without COMFY_CMD requires COMFY_URL to be set (it enables the managed ComfyUI)")
|
||||
}
|
||||
if cfg.OllamaURL == "" && cfg.ComfyURL == "" {
|
||||
return cfg, ErrNoConsumer
|
||||
}
|
||||
|
||||
@@ -201,8 +201,8 @@ func TestGameDetectionSettings(t *testing.T) {
|
||||
if len(cfg.GPUIgnoreProcs) != 2 || cfg.GPUIgnoreProcs[1] != "my-trainer" {
|
||||
t.Fatalf("GPUIgnoreProcs = %v", cfg.GPUIgnoreProcs)
|
||||
}
|
||||
if cfg.GamePollInterval != 5*time.Second {
|
||||
t.Fatalf("GamePollInterval = %v, want 5s default", cfg.GamePollInterval)
|
||||
if cfg.GamePollInterval != 15*time.Second {
|
||||
t.Fatalf("GamePollInterval = %v, want 15s default", cfg.GamePollInterval)
|
||||
}
|
||||
|
||||
// Defaults: both detection paths off, ignore list covers our consumers.
|
||||
@@ -222,3 +222,28 @@ func TestGameDetectionSettings(t *testing.T) {
|
||||
t.Fatal("GPUIgnoreProcs default must not be empty")
|
||||
}
|
||||
}
|
||||
|
||||
func TestComfyDirOnlyEnablesManaged(t *testing.T) {
|
||||
// COMFY_DIR without COMFY_CMD and without COMFY_URL is a mistake.
|
||||
_, err := Load(func(k string) string {
|
||||
if k == "COMFY_DIR" {
|
||||
return `C:\ComfyUI`
|
||||
}
|
||||
return ""
|
||||
})
|
||||
if err == nil || !strings.Contains(err.Error(), "COMFY_DIR") {
|
||||
t.Fatalf("err = %v, want COMFY_DIR/COMFY_URL validation error", err)
|
||||
}
|
||||
// With COMFY_URL it loads — the launch command is derived from the dir.
|
||||
if _, err := Load(func(k string) string {
|
||||
switch k {
|
||||
case "COMFY_DIR":
|
||||
return `C:\ComfyUI`
|
||||
case "COMFY_URL":
|
||||
return "http://127.0.0.1:8189"
|
||||
}
|
||||
return ""
|
||||
}); err != nil {
|
||||
t.Fatalf("COMFY_DIR with COMFY_URL must load: %v", err)
|
||||
}
|
||||
}
|
||||
|
||||
@@ -28,14 +28,14 @@ func sampleEntries(logFile string) []sampleEntry {
|
||||
{"OLLAMA_URL", "http://127.0.0.1:11434", "Ollama upstream URL; setting it enables the Ollama consumer (default: empty = disabled)", false},
|
||||
{"COMFY_URL", "http://127.0.0.1:8188", "ComfyUI upstream URL; setting it enables the ComfyUI consumer (default: empty = disabled)", false},
|
||||
{"WARM_MODEL", "", "Optional model to reload after an image job (default: empty = none)", false},
|
||||
{"COMFY_CMD", `"C:\ComfyUI\.venv\Scripts\python.exe" ComfyUI\main.py --port 8188`, "Spawn and supervise ComfyUI on demand: the first request starts it, it stops after COMFY_IDLE_TIMEOUT to free VRAM (default: empty = unmanaged)", false},
|
||||
{"COMFY_DIR", `C:\ComfyUI`, "Working directory for COMFY_CMD (default: empty = inherit)", false},
|
||||
{"COMFY_CMD", `"C:\ComfyUI\.venv\Scripts\python.exe" ComfyUI\main.py --port 8188`, "Spawn and supervise ComfyUI on demand: the first request starts it, it stops after COMFY_IDLE_TIMEOUT to free VRAM (default: derived from COMFY_DIR; both empty = unmanaged)", false},
|
||||
{"COMFY_DIR", `C:\ComfyUI`, "Root of a standard ComfyUI venv install (.venv + main.py): setting it alone supervises ComfyUI with the derived launch command; also the working directory for COMFY_CMD", false},
|
||||
{"COMFY_IDLE_TIMEOUT", "5m", "Stop the managed ComfyUI after this long without requests or jobs (frees VRAM)", false},
|
||||
{"COMFY_START_TIMEOUT", "2m", "How long a request waits for the managed ComfyUI to come up", false},
|
||||
{"GAME_PROCS", "cyberpunk2077.exe,hl2.exe", "While a listed process runs, the GPU counts as held by it: requests wait, Ollama unloads, managed ComfyUI stops (default: empty = disabled)", false},
|
||||
{"GPU_FOREIGN_VRAM_MB", "1024", "Also treat the GPU as held when a process not in GPU_IGNORE_PROCS uses more VRAM than this (needs nvidia-smi; 0/empty = disabled)", false},
|
||||
{"GPU_IGNORE_PROCS", "ollama,ollama app,ollama_llama_server,python,pythonw", "Process names never counted as foreign GPU users (ComfyUI runs under python)", false},
|
||||
{"GAME_POLL_INTERVAL", "5s", "How often game/VRAM detection runs", false},
|
||||
{"GAME_POLL_INTERVAL", "15s", "How often game/VRAM detection runs (nvidia-smi polls keep the GPU awake; don't go below ~10s)", false},
|
||||
{"UNLOAD_TIMEOUT", "60s", "How long to wait for Ollama to unload a model", false},
|
||||
{"JOB_TIMEOUT", "15m", "Maximum time to wait for a ComfyUI job", false},
|
||||
{"LLM_WAIT_TIMEOUT", "10m", "Max time an LLM request waits for the GPU before being answered 503 (wait mode)", false},
|
||||
@@ -66,7 +66,8 @@ func sampleEntries(logFile string) []sampleEntry {
|
||||
// comment line. Everything is commented out — so all defaults apply —
|
||||
// except the CFG_VER/APP_VER header and LOG_FILE when logFile is non-empty
|
||||
// (a Windows service has no console). CFG_VER records the version that
|
||||
// wrote the file so later installs can upgrade it.
|
||||
// wrote the file so installs — and startups after an update — can upgrade
|
||||
// it.
|
||||
func SampleEnv(version, logFile string) string {
|
||||
// CFG_VER is always a concrete vX.Y.Z — never "dev". A dev build
|
||||
// stamps v0.0.0, which sorts older than any release, so the next
|
||||
|
||||
@@ -45,3 +45,19 @@ func writeEnvFile(path, content string) error {
|
||||
}
|
||||
return nil
|
||||
}
|
||||
|
||||
// configuredValue reads one key from the env file the service will load, so
|
||||
// the installers can adapt the sandbox to it (ACL grants, unit directives).
|
||||
// "" when unset or unreadable.
|
||||
func configuredValue(configPath, key string) string {
|
||||
f, err := os.Open(configPath)
|
||||
if err != nil {
|
||||
return ""
|
||||
}
|
||||
defer f.Close()
|
||||
values, err := config.ParseEnvFile(f)
|
||||
if err != nil {
|
||||
return ""
|
||||
}
|
||||
return values[key]
|
||||
}
|
||||
|
||||
@@ -62,8 +62,14 @@ func Run(run func(ctx context.Context) error) error {
|
||||
// filesystem is read-only except StateDirectory (the install dir, so
|
||||
// self-updates can rewrite the binary), and the usual no-privilege-escalation
|
||||
// directives apply. The proxy needs nothing but outbound TCP/UDP and the
|
||||
// notify socket, so it loses nothing.
|
||||
func renderUnit(exePath, configPath string) string {
|
||||
// notify socket, so it loses nothing. A managed ComfyUI (comfyDir) gets a
|
||||
// BindPaths hole through ProtectHome/ProtectSystem: it reads its venv and
|
||||
// writes output/temp/user data under COMFY_DIR.
|
||||
func renderUnit(exePath, configPath, comfyDir string) string {
|
||||
bind := ""
|
||||
if comfyDir != "" {
|
||||
bind = "BindPaths=" + comfyDir + "\n"
|
||||
}
|
||||
return fmt.Sprintf(`[Unit]
|
||||
Description=gpu-turnstile GPU arbitration proxy for Ollama and ComfyUI
|
||||
After=network-online.target
|
||||
@@ -78,7 +84,7 @@ RestartSec=5s
|
||||
|
||||
DynamicUser=yes
|
||||
StateDirectory=%s
|
||||
ProtectSystem=strict
|
||||
%sProtectSystem=strict
|
||||
ProtectHome=yes
|
||||
PrivateTmp=yes
|
||||
NoNewPrivileges=yes
|
||||
@@ -100,7 +106,7 @@ SystemCallErrorNumber=EPERM
|
||||
|
||||
[Install]
|
||||
WantedBy=multi-user.target
|
||||
`, exePath, configPath, Name)
|
||||
`, exePath, configPath, Name, bind)
|
||||
}
|
||||
|
||||
// copyFile copies src to dst, creating dst with the given mode.
|
||||
@@ -125,7 +131,9 @@ func copyFile(src, dst string, mode os.FileMode) error {
|
||||
// sure /etc/gpu-turnstile.env exists (copied from the given config file if
|
||||
// provided), writes the hardened unit, then enables and starts it. With
|
||||
// copyBin=false the current executable location and config path are
|
||||
// registered as-is instead. Needs root.
|
||||
// registered as-is instead. When the config sets COMFY_DIR, the unit gets a
|
||||
// BindPaths= for it so the sandboxed service can reach the managed ComfyUI
|
||||
// even under /home. Needs root.
|
||||
//
|
||||
// Re-running install converges an existing unit instead of failing: it is
|
||||
// stopped first if active, the installed binary is replaced only when the
|
||||
@@ -186,7 +194,7 @@ func Install(configPath string, copyBin bool, version string) error {
|
||||
cfg = abs
|
||||
}
|
||||
}
|
||||
rendered := renderUnit(exe, cfg)
|
||||
rendered := renderUnit(exe, cfg, configuredValue(cfg, "COMFY_DIR"))
|
||||
if old, _ := os.ReadFile(unitPath); string(old) != rendered {
|
||||
if err := os.WriteFile(unitPath, []byte(rendered), 0o644); err != nil {
|
||||
return fmt.Errorf("write %s (run as root): %w", unitPath, err)
|
||||
|
||||
@@ -8,7 +8,7 @@ import (
|
||||
)
|
||||
|
||||
func TestRenderUnit(t *testing.T) {
|
||||
unit := renderUnit("/var/lib/gpu-turnstile/gpu-turnstile", "/etc/gpu-turnstile.env")
|
||||
unit := renderUnit("/var/lib/gpu-turnstile/gpu-turnstile", "/etc/gpu-turnstile.env", "")
|
||||
for _, want := range []string{
|
||||
"Type=notify",
|
||||
"WatchdogSec=30s",
|
||||
@@ -26,4 +26,12 @@ func TestRenderUnit(t *testing.T) {
|
||||
t.Fatalf("unit missing %q:\n%s", want, unit)
|
||||
}
|
||||
}
|
||||
if strings.Contains(unit, "BindPaths") {
|
||||
t.Fatalf("unit without COMFY_DIR must not bind anything:\n%s", unit)
|
||||
}
|
||||
|
||||
unit = renderUnit("/var/lib/gpu-turnstile/gpu-turnstile", "/etc/gpu-turnstile.env", "/home/gpu/ComfyUI")
|
||||
if !strings.Contains(unit, "BindPaths=/home/gpu/ComfyUI\n") {
|
||||
t.Fatalf("unit with COMFY_DIR must bind it:\n%s", unit)
|
||||
}
|
||||
}
|
||||
|
||||
@@ -24,8 +24,6 @@ import (
|
||||
"golang.org/x/sys/windows"
|
||||
"golang.org/x/sys/windows/svc"
|
||||
"golang.org/x/sys/windows/svc/mgr"
|
||||
|
||||
"gpu-turnstile/internal/config"
|
||||
)
|
||||
|
||||
// Name is the Windows service name.
|
||||
@@ -106,10 +104,12 @@ func (h *handler) Execute(_ []string, requests <-chan svc.ChangeRequest, status
|
||||
// the service after 5s on failure — this is also what brings up a staged
|
||||
// update after the updater exits with a non-zero code. After registering,
|
||||
// the virtual account is granted modify access to the install and data
|
||||
// directories (self-updates rewrite the exe), and read access to the
|
||||
// config file if it lives elsewhere. The grants must come after
|
||||
// CreateService: the virtual account's SID only exists once the service is
|
||||
// registered.
|
||||
// directories (self-updates rewrite the exe), read access to the
|
||||
// config file if it lives elsewhere, and — when the config sets COMFY_DIR —
|
||||
// recursive modify access to the managed ComfyUI's install tree, which may
|
||||
// live inside a user profile the account otherwise cannot enter. The grants
|
||||
// must come after CreateService: the virtual account's SID only exists once
|
||||
// the service is registered.
|
||||
//
|
||||
// Re-running install on an existing service converges instead of failing:
|
||||
// the service is stopped first if running (so the binary can be replaced),
|
||||
@@ -146,6 +146,7 @@ func Install(configPath string, copyBin bool, version string) error {
|
||||
if st, qErr := s.Query(); qErr == nil &&
|
||||
(st.State == svc.Running || st.State == svc.StartPending) {
|
||||
wasRunning = true
|
||||
fmt.Println("stopping the running gpu-turnstile service")
|
||||
if err := stopAndWait(s); err != nil {
|
||||
return err
|
||||
}
|
||||
@@ -161,6 +162,7 @@ func Install(configPath string, copyBin bool, version string) error {
|
||||
}
|
||||
installedExe := filepath.Join(installDir, "gpu-turnstile.exe")
|
||||
if same, _ := sameFileContent(exe, installedExe); !same {
|
||||
fmt.Printf("installing %s\n", installedExe)
|
||||
if err := copyFile(exe, installedExe); err != nil {
|
||||
return fmt.Errorf("copy binary to %s: %w", installedExe, err)
|
||||
}
|
||||
@@ -208,6 +210,7 @@ func Install(configPath string, copyBin bool, version string) error {
|
||||
// Best effort: start now instead of waiting for the next boot. A
|
||||
// missing config (no consumer URLs) fails the start; the service stays
|
||||
// registered and can be started once the config exists.
|
||||
fmt.Println("starting the gpu-turnstile service")
|
||||
s.Start()
|
||||
return nil
|
||||
}
|
||||
@@ -243,6 +246,7 @@ func Install(configPath string, copyBin bool, version string) error {
|
||||
return err
|
||||
}
|
||||
if wasRunning {
|
||||
fmt.Println("starting the gpu-turnstile service")
|
||||
if err := s.Start(); err != nil {
|
||||
return fmt.Errorf("start service: %w", err)
|
||||
}
|
||||
@@ -354,7 +358,7 @@ func grantAll(exe, configPath string) error {
|
||||
return err
|
||||
}
|
||||
}
|
||||
if logFile := configuredLogFile(configPath); logFile != "" {
|
||||
if logFile := configuredValue(configPath, "LOG_FILE"); logFile != "" {
|
||||
dir := filepath.Dir(logFile)
|
||||
if err := os.MkdirAll(dir, 0o755); err == nil {
|
||||
if err := grantAccess(dir, "(OI)(CI)(M)"); err != nil {
|
||||
@@ -362,6 +366,17 @@ func grantAll(exe, configPath string) error {
|
||||
}
|
||||
}
|
||||
}
|
||||
// A managed ComfyUI whose install lives somewhere the virtual account
|
||||
// may not go (a user profile) needs an explicit grant — recursively,
|
||||
// since ComfyUI also writes output/temp/user data next to its code. A
|
||||
// missing directory is skipped: the startup warning covers it.
|
||||
if comfyDir := configuredValue(configPath, "COMFY_DIR"); comfyDir != "" {
|
||||
if _, err := os.Stat(comfyDir); err == nil {
|
||||
if err := grantAccessTree(comfyDir, "(OI)(CI)(M)"); err != nil {
|
||||
return err
|
||||
}
|
||||
}
|
||||
}
|
||||
return nil
|
||||
}
|
||||
|
||||
@@ -466,28 +481,35 @@ func RelaunchElevated(args []string) (int, error) {
|
||||
// grantAccess gives the virtual account the icacls permission set (e.g.
|
||||
// "(OI)(CI)(M)") on path.
|
||||
func grantAccess(path, perms string) error {
|
||||
out, err := exec.Command("icacls", path, "/grant", virtualAccount+":"+perms).CombinedOutput()
|
||||
return runIcacls(path, perms, false)
|
||||
}
|
||||
|
||||
// grantAccessTree is grantAccess with /T: the ACE is applied to the
|
||||
// existing tree, not just inherited by children created later. Needed when
|
||||
// the tree already exists, e.g. a ComfyUI install in a user profile. On a
|
||||
// large tree (a venv has tens of thousands of files) this takes minutes,
|
||||
// so it says what it is doing instead of looking hung.
|
||||
func grantAccessTree(path, perms string) error {
|
||||
return runIcacls(path, perms, true)
|
||||
}
|
||||
|
||||
func runIcacls(path, perms string, recursive bool) error {
|
||||
args := []string{path, "/grant", virtualAccount + ":" + perms}
|
||||
if recursive {
|
||||
fmt.Printf("granting %s modify access to %s (large trees can take minutes)\n", virtualAccount, path)
|
||||
args = append(args, "/T")
|
||||
}
|
||||
start := time.Now()
|
||||
out, err := exec.Command("icacls", args...).CombinedOutput()
|
||||
if err != nil {
|
||||
return fmt.Errorf("grant %s access to %s: %w (%s)", virtualAccount, path, err, strings.TrimSpace(string(out)))
|
||||
}
|
||||
if recursive {
|
||||
fmt.Printf("access granted in %s\n", time.Since(start).Round(time.Second))
|
||||
}
|
||||
return nil
|
||||
}
|
||||
|
||||
// configuredLogFile reads LOG_FILE from the config file so the installer
|
||||
// can pre-create and ACL the log directory. "" when unset or unreadable.
|
||||
func configuredLogFile(configPath string) string {
|
||||
f, err := os.Open(configPath)
|
||||
if err != nil {
|
||||
return ""
|
||||
}
|
||||
defer f.Close()
|
||||
values, err := config.ParseEnvFile(f)
|
||||
if err != nil {
|
||||
return ""
|
||||
}
|
||||
return values["LOG_FILE"]
|
||||
}
|
||||
|
||||
// RestartIfRunning restarts the service when it is installed and running
|
||||
// (used after a forced update staged a new binary). Reports whether a
|
||||
// restart happened. A service that is not installed or not running is not
|
||||
|
||||
@@ -9,13 +9,54 @@ import (
|
||||
"fmt"
|
||||
"io"
|
||||
"log/slog"
|
||||
"net/url"
|
||||
"os"
|
||||
"os/exec"
|
||||
"path/filepath"
|
||||
"runtime"
|
||||
"strings"
|
||||
"sync"
|
||||
"time"
|
||||
)
|
||||
|
||||
// ComfyLayout returns the interpreter and script path of a standard ComfyUI
|
||||
// venv install rooted at dir for the given GOOS: .venv\Scripts\python.exe
|
||||
// on Windows, .venv/bin/python elsewhere. The script is main.py — either in
|
||||
// a ComfyUI subdirectory or directly under dir, whichever exists (the
|
||||
// subdirectory form wins ties and is the default when neither exists yet,
|
||||
// so the caller's missing-file warning points at the documented layout).
|
||||
func ComfyLayout(goos, dir string) (python, script string) {
|
||||
if goos == "windows" {
|
||||
python = filepath.Join(dir, ".venv", "Scripts", "python.exe")
|
||||
} else {
|
||||
python = filepath.Join(dir, ".venv", "bin", "python")
|
||||
}
|
||||
script = filepath.Join(dir, "ComfyUI", "main.py")
|
||||
if _, err := os.Stat(script); err != nil {
|
||||
if _, err := os.Stat(filepath.Join(dir, "main.py")); err == nil {
|
||||
script = filepath.Join(dir, "main.py")
|
||||
}
|
||||
}
|
||||
return python, script
|
||||
}
|
||||
|
||||
// DefaultComfyCommand builds the launch command for the standard venv
|
||||
// layout (see ComfyLayout): the script is passed relative to dir so dir
|
||||
// stays the working directory, and --port is taken from comfyURL when the
|
||||
// URL carries one.
|
||||
func DefaultComfyCommand(goos, dir, comfyURL string) string {
|
||||
python, script := ComfyLayout(goos, dir)
|
||||
rel, err := filepath.Rel(dir, script)
|
||||
if err != nil {
|
||||
rel = script
|
||||
}
|
||||
cmd := `"` + python + `" ` + rel
|
||||
if u, err := url.Parse(comfyURL); err == nil && u.Port() != "" {
|
||||
cmd += " --port " + u.Port()
|
||||
}
|
||||
return cmd
|
||||
}
|
||||
|
||||
// Process is one managed child process.
|
||||
type Process struct {
|
||||
name string
|
||||
|
||||
@@ -7,6 +7,8 @@ import (
|
||||
"net/http"
|
||||
"net/http/httptest"
|
||||
"os"
|
||||
"path/filepath"
|
||||
"strings"
|
||||
"testing"
|
||||
"time"
|
||||
)
|
||||
@@ -190,3 +192,50 @@ func TestWatchIdleRespectsBusyGPU(t *testing.T) {
|
||||
t.Fatal("process was stopped while the GPU was busy")
|
||||
}
|
||||
}
|
||||
|
||||
func TestComfyLayoutAndDefaultCommand(t *testing.T) {
|
||||
// Nested layout (ComfyUI/main.py under dir) wins.
|
||||
dir := t.TempDir()
|
||||
nested := filepath.Join(dir, "ComfyUI", "main.py")
|
||||
if err := os.MkdirAll(filepath.Dir(nested), 0o755); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if err := os.WriteFile(nested, []byte("x"), 0o644); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
python, script := ComfyLayout("windows", dir)
|
||||
if want := filepath.Join(dir, ".venv", "Scripts", "python.exe"); python != want {
|
||||
t.Errorf("python = %s, want %s", python, want)
|
||||
}
|
||||
if script != nested {
|
||||
t.Errorf("script = %s, want %s", script, nested)
|
||||
}
|
||||
cmd := DefaultComfyCommand("windows", dir, "http://127.0.0.1:8189")
|
||||
want := `"` + filepath.Join(dir, ".venv", "Scripts", "python.exe") + `" ` + filepath.Join("ComfyUI", "main.py") + " --port 8189"
|
||||
if cmd != want {
|
||||
t.Errorf("cmd = %q, want %q", cmd, want)
|
||||
}
|
||||
|
||||
// Flat layout (main.py directly under dir) is found too.
|
||||
flat := t.TempDir()
|
||||
if err := os.WriteFile(filepath.Join(flat, "main.py"), []byte("x"), 0o644); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if _, script := ComfyLayout("linux", flat); script != filepath.Join(flat, "main.py") {
|
||||
t.Errorf("flat script = %s", script)
|
||||
}
|
||||
cmd = DefaultComfyCommand("linux", flat, "http://comfy.internal")
|
||||
if strings.Contains(cmd, "--port") {
|
||||
t.Errorf("cmd = %q, want no --port for a port-less URL", cmd)
|
||||
}
|
||||
if !strings.HasSuffix(cmd, `" main.py`) {
|
||||
t.Errorf("cmd = %q, want quoted python + relative main.py", cmd)
|
||||
}
|
||||
|
||||
// Neither exists yet: default to the documented nested form so the
|
||||
// startup warning points there.
|
||||
empty := t.TempDir()
|
||||
if _, script := ComfyLayout("windows", empty); script != filepath.Join(empty, "ComfyUI", "main.py") {
|
||||
t.Errorf("missing-layout script = %s", script)
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user