feat: run a submission in a listed prebuilt simulator image - #190
Merged
Merged
Conversation
Every submission runs in one shared container whose package list is fixed here, so a workspace with conda-forge dependencies or a compiled extension cannot run. Its owners can now publish an OCI image, which the deployment lists by name (settings.prebuilt_simulators, PREBUILT_SIMULATORS as JSON). - POST /simulation/run takes an optional `simulator` query parameter; a name the deployment does not list is a 400, so a request can never pull an arbitrary image. - The submission's Apptainer definition is just `Bootstrap: docker` / `From: <image>`; its hash is the simulator version, as before. - The download step pulls that image itself (docker://<image>) instead of the shared repository's <hash> tag; building it remains the fallback. - Everything after is unchanged: one SIF per definition, and the job runs `singularity run --compat <sif> run /experiment/<id>.<suffix> -o ... -n ...`, which the image's entrypoint must answer. Tests: definition round trip, listing, the recorded simulator version, the pull source for prebuilt and shared simulators, and the 400. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
jcschaff
added a commit
that referenced
this pull request
Oct 6, 2026
A prebuilt simulator's image brings its own processes, which the registry manifest does not describe, so /simulation/run checks a `simulator=<name>` submission's name against settings.prebuilt_simulators and skips the address check (the deployment vouches for the image by listing it). Unlisted names are refused before the registry is consulted. The #190 test drops the pip allow list this branch removes. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
jcschaff
added a commit
that referenced
this pull request
Oct 6, 2026
…log ingest Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This was referenced Oct 6, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
Every submission runs in one shared container whose package list is fixed in this repo (the simulator registry). A process-bigraph workspace with conda-forge dependencies or a compiled extension can't be expressed that way.
The motivating case is vivarium-collective/viva-pde-particle: dolfinx, netgen, and a Smoldyn module built from source. Its owners can publish an OCI image instead, which the deployment lists by name.
What
prebuilt_simulators: dict[str, str], fromPREBUILT_SIMULATORSas JSON, mapping a simulator name to an image reference.POST /simulation/run?simulator=<name>:simulation/prebuilt.pyproduces an Apptainer definition that is just_download_or_build_containerpullsdocker://<image>itself for a prebuilt definition, instead of the shared repository's<hash>tag. Building that definition (singularity build --fakeroot) stays the fallback.Enabling it
Once the image is published (vivarium-collective/viva-pde-particle#46 builds and pushes it), add to
kustomize/config/compose-api-rke/api.env:That deployment config change isn't in this PR.
Interplay with #184 / #185 (registry enforcement)
Those refuse process addresses missing from this repo's registry manifest. A prebuilt image brings its own processes, so for
simulator=<name>submissions the check should be skipped, or should consult the image's own manifest. Whichever lands second adapts. I left #184 alone here, because this branch is based onmain.Not in this PR
Tests
tests/simulation/test_prebuilt.pycovers:docker://<image>) versus shared (<repository>:<hash>) simulators;make checkis clean (ruff,mypy --strict, deptry). Test runs:🤖 Generated with Claude Code