3 Commits
Author SHA1 Message Date
eSlider bcd956d11a fix: wire live mode and Grafana to the generated data stream
CI & Release / Verify simulator (push) Successful in 11s
CI & Release / Trivy scan (push) Successful in 9s
CI & Release / Semantic Release (push) Successful in 5s
Use the real hive column name (`drone`) in the prototype's live query
and pin the Grafana datasource uid to `swarm-prom` so provisioned
dashboards resolve their Prometheus source in k3d.
2026-07-08 20:34:37 +01:00
eSlider 9f99d132e3 fix: chown var/t1 and var/t3 to simulator uid 10001 for k3d
CI & Release / Verify simulator (push) Successful in 12s
CI & Release / Trivy scan (push) Successful in 9s
CI & Release / Semantic Release (push) Successful in 4s
Non-root drone pods need write access on the hostPath lake. Ansible now
creates var/t1 and var/t3 owned by uid 10001 instead of relying on 0777
alone after legacy root-owned parquet trees.
2026-07-08 20:27:25 +01:00
eSlider 669e8ff005 fix: run simulator image as non-root user (Trivy DS-0002)
CI & Release / Verify simulator (push) Successful in 11s
CI & Release / Trivy scan (push) Successful in 9s
CI & Release / Semantic Release (push) Successful in 4s
Add swarm uid 10001 in both build stages so Trivy config scan passes
and containers do not run as root. Mounted /data volumes should be
world-writable or owned by uid 10001 (var/t1 from Ansible is 0777).
2026-07-08 20:20:19 +01:00
4 changed files with 24 additions and 7 deletions
+4
View File
@@ -29,12 +29,16 @@
path: "{{ data_dir }}" path: "{{ data_dir }}"
state: directory state: directory
mode: "0777" mode: "0777"
owner: "10001"
group: "10001"
- name: Create warehouse directory (T3 host path inside the k3d node) - name: Create warehouse directory (T3 host path inside the k3d node)
ansible.builtin.file: ansible.builtin.file:
path: "{{ warehouse_dir }}" path: "{{ warehouse_dir }}"
state: directory state: directory
mode: "0777" mode: "0777"
owner: "10001"
group: "10001"
- name: List existing clusters - name: List existing clusters
ansible.builtin.command: k3d cluster list -o json ansible.builtin.command: k3d cluster list -o json
+4
View File
@@ -298,8 +298,12 @@ resource "kubernetes_config_map" "grafana_provisioning" {
data = { data = {
"datasource.yml" = <<-EOT "datasource.yml" = <<-EOT
apiVersion: 1 apiVersion: 1
deleteDatasources:
- name: Prometheus
orgId: 1
datasources: datasources:
- name: Prometheus - name: Prometheus
uid: swarm-prom
type: prometheus type: prometheus
access: proxy access: proxy
url: http://prometheus:9090 url: http://prometheus:9090
+7 -7
View File
@@ -20,24 +20,24 @@ export interface LivePose {
// latest battery reading from telemetry. arg_max keeps it a single scan. // latest battery reading from telemetry. arg_max keeps it a single scan.
const LIVE_SQL = ` const LIVE_SQL = `
WITH pose AS ( WITH pose AS (
SELECT drone_id, SELECT drone,
arg_max(pos_x, ts_ns) AS x, arg_max(pos_x, ts_ns) AS x,
arg_max(pos_y, ts_ns) AS y, arg_max(pos_y, ts_ns) AS y,
arg_max(yaw, ts_ns) AS yaw, arg_max(yaw, ts_ns) AS yaw,
max(ts_ns) AS ts_ns max(ts_ns) AS ts_ns
FROM state FROM state
WHERE direction = 'sent' WHERE direction = 'sent'
GROUP BY drone_id GROUP BY drone
), ),
batt AS ( batt AS (
SELECT drone_id, arg_max(level_pct, ts_ns) AS battery SELECT drone, arg_max(level_pct, ts_ns) AS battery
FROM telemetry FROM telemetry
WHERE sensor = 'battery' WHERE sensor = 'battery'
GROUP BY drone_id GROUP BY drone
) )
SELECT p.drone_id, p.x, p.y, p.yaw, p.ts_ns, b.battery SELECT p.drone, p.x, p.y, p.yaw, p.ts_ns, b.battery
FROM pose p LEFT JOIN batt b USING (drone_id) FROM pose p LEFT JOIN batt b USING (drone)
ORDER BY p.drone_id`; ORDER BY p.drone`;
interface QueryResponse { interface QueryResponse {
columns?: string[]; columns?: string[];
+9
View File
@@ -7,6 +7,10 @@ COPY virtual_drone ./virtual_drone
COPY monitoring ./monitoring COPY monitoring ./monitoring
COPY explorer ./explorer COPY explorer ./explorer
COPY tests ./tests COPY tests ./tests
RUN groupadd --gid 10001 swarm \
&& useradd --uid 10001 --gid swarm --home-dir /app --shell /usr/sbin/nologin swarm \
&& chown -R swarm:swarm /app
USER swarm
RUN pytest tests/ -q RUN pytest tests/ -q
FROM python:3.12-slim FROM python:3.12-slim
@@ -19,6 +23,11 @@ COPY virtual_drone ./virtual_drone
# them without bind mounts (Compose overrides these with live mounts) # them without bind mounts (Compose overrides these with live mounts)
COPY monitoring ./monitoring COPY monitoring ./monitoring
COPY explorer ./explorer COPY explorer ./explorer
RUN groupadd --gid 10001 swarm \
&& useradd --uid 10001 --gid swarm --home-dir /app --shell /usr/sbin/nologin swarm \
&& mkdir -p /data \
&& chown -R swarm:swarm /app /data
ENV DATA_DIR=/data ENV DATA_DIR=/data
USER swarm
CMD ["python", "-m", "virtual_drone.main"] CMD ["python", "-m", "virtual_drone.main"]