Repository navigation
Conversation
rhnvrm
marked this pull request as ready for review
September 28, 2026 11:18
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why this MR
We wanted to develop and test Dummie end to end on one NixOS machine: run the control plane locally, enroll a VM host, create a guest through the API or console, reach it over SSH and the browser console, and use pi and Codex inside dubuntu through Dummie's LLM proxy.
Trying that flow exposed several gaps. Building a kernel and setting up tap/NAT made the host expensive and cumbersome to start. The local proxy needs high ports, but VM URLs and the login callback assumed ports 80/443. The browser and QEMU host reach the same object store at different addresses. Finally, dubuntu needed agent configuration for the internal model proxy without baking a local-only domain into a generic or production image. This MR records the working local path and the fixes found while exercising it.
What changed
DEV.mdanddocker-compose.local.ymlset up PostgreSQL, ClickHouse, RustFS, the control server, and the website for local development.LOCAL_VMS.mdwalks through host enrollment, a small guest, SSH, browser access, dubuntu, and the local Vector settings that ship host usage logs to ClickHouse.qemu-locallauncher uses packaged host and guest kernels, QEMU user networking, a persistent disk, and a loopback artifact server.vm-local-*recipes operate it; the existingqemu-host, tap networking, andvm-*recipes keep their previous behavior. An archive based kernel source recipe is optional.LOCAL_VM_SSH_PORTalso tells the VM page to copy an SSH command with the forwarded local port; production keeps the default port 22.S3_HOST_ENDPOINTlets dclient receive presigned kernel and rootfs URLs for the QEMU gateway while browser downloads keep usingS3_PUBLIC_ENDPOINT. Without the new setting, host downloads use the existing public endpoint.just image-build-local-dubuntuenables both agents against the local LLM proxy. Generic builds leave the Dummie provider unconfigured; a fleet build can supply its own domain and proxy URL.How to review and try it
Start with
DEV.mdandLOCAL_VMS.mdfor the intended flow. The implementation is grouped injustfile/nix-vms, the control URL and S3 code, dproxy auth, and the dubuntu image. The local values live in ignored env and artifact files; no enrollment key or model credential is included in the image or this MR.For a local smoke test, follow the two guides, then run
just vm-local-start, enroll the host, and create an Alpine or dubuntu VM.just vm-local-sshreaches the host;just vm-local-proxy-tunnelexposes guest SSH and browser access on local ports.Verification and limits
qemu-hostand use user networking forqemu-local.git diff --checkpass. The migrated local QEMU disk boots with SSH anddclientactive; pi and Codex were exercised against the local proxy during development.10.68.0.1:8123; dclient installed Vector 0.57.0, and its ClickHouse sink passed its health check. A dubuntu LLM request then appeared automatically in the personal usage report with its VM name and estimated cost.ssh -p 2224 dubuntu-test@dummie.localhostauthenticated with the account's saved public key and reached the guest asubuntu. The VM API now returnsssh_port: 2224for the UI; the port is omitted in production.go test ./...suites were red on both basemain(9d0d074) and the earlier MR revision (b030834). The five control failures and four dproxy failures had identical test names on both revisions; they are addressed separately in PR 2. Focused tests for the changed behavior pass.