mirror of
https://github.com/heygen-com/hyperframes.git
synced 2026-09-03 04:38:33 +00:00
* feat(gcp-cloud-run): add Google Cloud Run + Workflows distributed render adapter Adds @hyperframes/gcp-cloud-run, the GCP counterpart to @hyperframes/aws-lambda (issue #932). The OSS distributed primitives (plan, renderChunk x N, assemble) are unchanged; this package is the storage/compute/orchestration glue. Package: Cloud Run handler (one image, three actions), runs under bun; GCS transport; in-image chrome-headless-shell resolver; client SDK (renderToCloudRun, getRenderProgress, deploySite, computeRenderCost); Dockerfile; Cloud Workflows definition; Terraform module; CLI cloudrun deploy|sites|render|render-batch|progress|destroy with --output-resolution and --strict-variables; 62 unit tests + docs + live smoke script. Shared extraction (removes ~640 lines of adapter duplication): move the cloud-agnostic config validator + content-hash into producer/distributed; both adapters import them. Validated end-to-end on GCP at 37.4 dB PSNR vs baseline. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * fix(cli): resolve @hyperframes/gcp-cloud-run in the CLI build + root build The CLI bundle (esbuild) couldn't resolve `@hyperframes/gcp-cloud-run/sdk`, failing Build/Typecheck/CLI-smoke (and the perf/windows/regression jobs that build first). Mirror the aws-lambda handling: mark the gcp adapter + its /sdk subpath external in tsup.config.ts with a source alias, and add gcp-cloud-run to the root `build` filter so its dist exists for publish + runtime. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * fix(ci): copy gcp-cloud-run manifest in Dockerfile.test for frozen install The regression test image runs `bun install --frozen-lockfile` after copying each workspace package.json individually. The CLI now depends on @hyperframes/gcp-cloud-run (workspace:*), so the frozen install fails to resolve it unless its manifest is present. Add the COPY line. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * feat(cli): add machine-sizing flags to `cloudrun deploy` Closes the parity gap with `lambda deploy` (which exposes --memory etc.). `cloudrun deploy` now threads --cpu, --memory, --max-instances, and --timeout into the Terraform apply; omitted flags keep the module defaults (4 vCPU / 16Gi / 100 instances / 3600s). For finer control, apply the module directly. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * fix(gcp-cloud-run): address PR review (security, waste, limits, alerts) - server.ts: bucket-allowlist guard no longer fails open silently. Unset env logs a one-time WARNING; "*" is an explicit opt-out; otherwise it enforces. - server.ts: stop double-shipping audio.aac. It already rides in the plan tarball every consumer downloads, so drop the redundant standalone upload (plan) + re-download/overwrite (assemble); assemble reads it from the untar, falling back to a supplied AudioGcsUri for compat. - server.ts: chunk extension via path.extname() instead of slice(lastIndexOf). - workflow.yaml: clamp parallel concurrency_limit to math.min(chunkCount, 20) — Cloud Workflows hard-caps concurrent iterations at 20. - Dockerfile: pin bun (bun-v1.3.9) so an interop change can't silently break the image rebuild. - terraform: add min_instances var (default 0); add a workflow-failure alert (finished_execution_count status=FAILED) alongside the request-count one. - costAccounting: document that displayCost excludes GCS storage/egress. Verified against the actual APIs: @google-cloud/workflows@4.4.0 ICreateExecutionRequest has no executionId (so the idempotency-token suggestion isn't available in this client); Workflows concurrency cap is 20; failure metric is workflows.googleapis.com/finished_execution_count (status label). 174 adapter tests pass, fallow/oxlint/oxfmt/terraform clean. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * fix(gcp-cloud-run): address round-2 review — error code + CFR forwarding - workflow.yaml: rename the zero-chunk failure code PLAN_TOO_LARGE → PLAN_PRODUCED_ZERO_CHUNKS. The old code implied a size-ceiling breach (the opposite cause), misleading anyone triaging the alert. - workflow.yaml: forward Config.cfr to the assemble step (`Cfr: ${("cfr" in config) and config.cfr}`). It was read by the handler but never sent, so exact-CFR was silently off for every Cloud Run render. Uses the same `in`-operator guard already proven in the retryable predicate. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * fix(release): include gcp-cloud-run in set-version PACKAGES list set-version.ts (driven by release:prepare) bumps an explicit package list to the shared version on each release. gcp-cloud-run was wired into the build + publish.yml but missing here, so a release would leave it at a stale version and publish.yml would push the wrong version. Add it so the new package version-bumps + publishes in lockstep with the others. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
119 lines
5.0 KiB
Docker
119 lines
5.0 KiB
Docker
# HyperFrames distributed render — Cloud Run image.
|
|
#
|
|
# One container image, three roles (plan / renderChunk / assemble). Cloud
|
|
# Workflows POSTs a JSON body with an `Action` field; `dist/server.js`
|
|
# dispatches to the matching `@hyperframes/producer/distributed` primitive.
|
|
#
|
|
# Build context is the REPOSITORY ROOT (not this package dir) because the
|
|
# package depends on the `@hyperframes/producer` workspace and renders with
|
|
# the same chrome-headless-shell + fonts + ffmpeg the production renderer
|
|
# uses. The example smoke script and `hyperframes cloudrun deploy` both
|
|
# build with the repo root as context:
|
|
#
|
|
# docker build -f packages/gcp-cloud-run/Dockerfile -t <image> .
|
|
#
|
|
# NOTE: this Dockerfile only builds from a full hyperframes monorepo checkout
|
|
# — it COPYs sibling workspace packages (core/engine/producer). It is NOT
|
|
# buildable from the published npm tarball alone; install the repo (or use
|
|
# `hyperframes cloudrun deploy`, which builds from your checkout via Cloud
|
|
# Build) to produce the image.
|
|
#
|
|
# Unlike the AWS Lambda adapter there is no ZIP-size ceiling and no runtime
|
|
# Chrome decompression step — the binary lives in the image at a fixed path.
|
|
|
|
FROM node:22-bookworm-slim
|
|
|
|
# ── System dependencies (identical set to the producer's render image) ───────
|
|
RUN apt-get update && apt-get install -y --no-install-recommends \
|
|
ca-certificates \
|
|
curl \
|
|
unzip \
|
|
ffmpeg \
|
|
libgbm1 \
|
|
libnss3 \
|
|
libatk-bridge2.0-0 \
|
|
libdrm2 \
|
|
libxcomposite1 \
|
|
libxdamage1 \
|
|
libxrandr2 \
|
|
libcups2 \
|
|
libasound2 \
|
|
libpangocairo-1.0-0 \
|
|
libxshmfence1 \
|
|
libgtk-3-0 \
|
|
fonts-liberation \
|
|
fonts-noto-color-emoji \
|
|
fonts-noto-cjk \
|
|
fonts-noto-core \
|
|
fonts-noto-extra \
|
|
fonts-noto-ui-core \
|
|
fonts-freefont-ttf \
|
|
fonts-dejavu-core \
|
|
fontconfig \
|
|
&& rm -rf /var/lib/apt/lists/* \
|
|
&& apt-get clean \
|
|
&& fc-cache -fv
|
|
|
|
# ── chrome-headless-shell (deterministic BeginFrame capture) ─────────────────
|
|
# Pinned to the SAME build the producer regression baselines were generated
|
|
# against so distributed renders are pixel-comparable. Bump together with the
|
|
# producer's Dockerfile.test pin and a baseline regen.
|
|
RUN npx --yes @puppeteer/browsers install chrome-headless-shell@148.0.7778.167 \
|
|
--path /opt/puppeteer \
|
|
&& CHS="$(find /opt/puppeteer/chrome-headless-shell -name chrome-headless-shell -type f | head -n1)" \
|
|
&& mkdir -p /opt/chrome \
|
|
&& ln -s "$CHS" /opt/chrome/chrome-headless-shell \
|
|
&& /opt/chrome/chrome-headless-shell --version
|
|
|
|
# The chromium.ts resolver reads this first; pointing the engine straight at
|
|
# the symlinked binary avoids the runtime cache scan.
|
|
ENV HYPERFRAMES_CHROME_PATH=/opt/chrome/chrome-headless-shell
|
|
ENV PRODUCER_HEADLESS_SHELL_PATH=/opt/chrome/chrome-headless-shell
|
|
ENV PUPPETEER_SKIP_CHROMIUM_DOWNLOAD=true
|
|
ENV CONTAINER=true
|
|
|
|
WORKDIR /app
|
|
|
|
# Install bun (the repo's package manager / build driver). Pin the version:
|
|
# the container runs `bun dist/server.js` and relies on bun's ESM `require`
|
|
# interop to load the producer bundle, so a future bun release changing that
|
|
# behaviour shouldn't silently break the next image rebuild. Bump deliberately.
|
|
RUN curl -fsSL https://bun.sh/install | bash -s "bun-v1.3.9"
|
|
ENV PATH="/root/.bun/bin:$PATH"
|
|
|
|
# Install workspace dependencies. Copy manifests first for layer caching.
|
|
COPY package.json bun.lock ./
|
|
COPY packages/core/package.json packages/core/package.json
|
|
COPY packages/engine/package.json packages/engine/package.json
|
|
COPY packages/player/package.json packages/player/package.json
|
|
COPY packages/producer/package.json packages/producer/package.json
|
|
COPY packages/cli/package.json packages/cli/package.json
|
|
COPY packages/studio/package.json packages/studio/package.json
|
|
COPY packages/shader-transitions/package.json packages/shader-transitions/package.json
|
|
COPY packages/aws-lambda/package.json packages/aws-lambda/package.json
|
|
COPY packages/gcp-cloud-run/package.json packages/gcp-cloud-run/package.json
|
|
RUN bun install --frozen-lockfile
|
|
|
|
# Copy source for the packages the render path needs.
|
|
COPY packages/core/ packages/core/
|
|
COPY packages/engine/ packages/engine/
|
|
COPY packages/producer/ packages/producer/
|
|
COPY packages/gcp-cloud-run/ packages/gcp-cloud-run/
|
|
|
|
# Build core runtime artifacts (needed by the renderer) + producer, then the
|
|
# adapter. Generate embedded font data so glyph layout matches production.
|
|
RUN bun run --filter @hyperframes/core build:hyperframes-runtime:modular \
|
|
&& (cd packages/producer && bunx tsx scripts/generate-font-data.ts) \
|
|
&& bun run --cwd packages/producer build \
|
|
&& bun run --cwd packages/gcp-cloud-run build
|
|
|
|
# Cloud Run injects PORT (default 8080). The server reads it.
|
|
ENV PORT=8080
|
|
EXPOSE 8080
|
|
|
|
WORKDIR /app/packages/gcp-cloud-run
|
|
# Run under bun, not node. The repo is bun-native and `@hyperframes/producer`'s
|
|
# bundled `distributed.js` relies on a `require` being available at runtime
|
|
# (its esbuild interop shim); bun provides one in ESM, bare `node` does not.
|
|
CMD ["bun", "dist/server.js"]
|