pcbjam/scripts/bench/cloud-init/user-data

42 lines
1.4 KiB
Text
Raw Normal View History

#cloud-config
# NoCloud seed for the wasm-opt benchmark VM. setup-vm.sh substitutes
# __SSH_PUBKEY__ with your ~/.ssh/id_ed25519.pub before building the seed ISO.
hostname: kicad-bench
users:
- name: bench
sudo: "ALL=(ALL) NOPASSWD:ALL"
shell: /bin/bash
# Key auth only: setup-vm.sh requires an SSH pubkey and substitutes it below,
# so no password login is needed. Lock the password and disable SSH password
# auth (below); recover via the substituted key, not a shared password.
lock_passwd: true
ssh_authorized_keys:
- __SSH_PUBKEY__
# Disable SSH password authentication — the seed carries a pubkey.
ssh_pwauth: false
package_update: true
# Docker CE from the official repo (mirrors the CI workflow's install step) so
# scripts/bench/vm-build.sh can run the full docker/build.sh pipeline in-guest.
apt:
sources:
docker.list:
source: "deb [signed-by=$KEY_FILE] https://download.docker.com/linux/ubuntu noble stable"
keyid: 9DC858229FC7DD38854AE2D88D81803C0EBFCD88
packages:
- git
- curl
- ca-certificates
- time
- libjemalloc2
- strace
- rsync
- docker-ce
- docker-ce-cli
- containerd.io
- docker-buildx-plugin
- docker-compose-plugin
runcmd:
# The docker group only exists after the package installs, so the user's
# `groups:` stanza can't grant it — add membership here (applies to new
# ssh sessions, which is all vm-build.sh uses).
- usermod -aG docker bench