feat(sglang-deploy): replace nginx with caddy
Assisted-by: GLM 5.3 Flash
This commit is contained in:
+37
-16
@@ -138,7 +138,7 @@ is((valid_dir_path('/opt/sg lang') ? 1 : 0), 0, 'valid_dir_path: whitespace is r
|
||||
is((valid_dir_path('/opt/%h/sglang') ? 1 : 0), 0,
|
||||
'valid_dir_path: a systemd specifier is refused');
|
||||
is((valid_dir_path('/opt/x;/sglang') ? 1 : 0), 0,
|
||||
'valid_dir_path: an nginx directive end is refused');
|
||||
'valid_dir_path: a path with a semicolon is refused');
|
||||
|
||||
# ---- run(): exit status, signals and timeout ------------------------------
|
||||
my $killed = run([$^X, '-e', 'kill 9, $$']);
|
||||
@@ -164,22 +164,43 @@ is(scalar @{ radeon_env_for(undef, 1) }, 2,
|
||||
'env: a custom image on a Radeon-only host carries the Radeon defaults');
|
||||
is(scalar @{ radeon_env_for('mi30x', 0) }, 0, 'env: an Instinct host carries none');
|
||||
|
||||
# ---- nginx config --------------------------------------------------------
|
||||
my $conf = nginx_conf_content(8000, '[::1]', '/etc/ssl/sglang');
|
||||
like($conf, qr/listen \[::\]:443 ssl;/, 'nginx: IPv6 listener on a dual-stack kernel');
|
||||
like($conf, qr/listen 443 ssl;/, 'nginx: IPv4 listener');
|
||||
like($conf, qr|ssl_certificate /etc/ssl/sglang/sglang\.crt;|, 'nginx: certificate path');
|
||||
like($conf, qr/ssl_certificate_key \/etc\/ssl\/sglang\/sglang\.key;/, 'nginx: key path');
|
||||
like($conf, qr|proxy_pass http://\[::1\]:8000;|, 'nginx: loopback upstream with the port');
|
||||
like($conf, qr/proxy_http_version 1\.1;/, 'nginx: HTTP/1.1 for streaming');
|
||||
like($conf, qr/proxy_buffering off;/, 'nginx: buffering off for streaming');
|
||||
like($conf, qr/proxy_set_header Host \$host;/, 'nginx: $host survives the heredoc');
|
||||
like($conf, qr/proxy_set_header X-Forwarded-For \$proxy_add_x_forwarded_for;/,
|
||||
'nginx: $proxy_add_x_forwarded_for survives the heredoc');
|
||||
# ---- caddy drop-in --------------------------------------------------------
|
||||
my $conf = caddyfile_content(8000, '[::1]', '/etc/ssl/sglang');
|
||||
like($conf, qr/^:443 \{$/m, 'caddy: the endpoint site on 443');
|
||||
like($conf, qr|tls /etc/ssl/sglang/sglang\.crt /etc/ssl/sglang/sglang\.key|,
|
||||
'caddy: certificate pair paths');
|
||||
like($conf, qr/reverse_proxy \[::1\]:8000 \{/, 'caddy: loopback upstream with the port');
|
||||
like($conf, qr/flush_interval -1/, 'caddy: unbuffered streaming');
|
||||
like($conf, qr/header_up X-Real-IP \{remote_host\}/, 'caddy: X-Real-IP survives the heredoc');
|
||||
like($conf, qr/max_size 50MB/, 'caddy: the request body limit');
|
||||
like($conf, qr/\treverse_proxy /, 'caddy: tab-indented as the Caddyfile is formatted');
|
||||
check_unlike($conf, qr/\bbind\b/, 'caddy: no bind directive, the kernel decides the families');
|
||||
check_unlike($conf, qr/acme|on_demand|http:\/\/\{/i, 'caddy: no ACME, the self-signed pair is used');
|
||||
|
||||
my $conf4 = nginx_conf_content(8000, '127.0.0.1', '/etc/ssl/sglang');
|
||||
is($conf4 =~ /\[::\]/ ? 'yes' : 'no',
|
||||
(-e '/proc/net/if_inet6' ? 'yes' : 'no'), 'nginx: IPv6 listener follows the kernel');
|
||||
my $conf4 = caddyfile_content(9000, '127.0.0.1', '/etc/ssl/llm');
|
||||
like($conf4, qr/reverse_proxy 127\.0\.0\.1:9000 \{/, 'caddy: an IPv4 upstream carries the port');
|
||||
like($conf4, qr|tls /etc/ssl/llm/sglang\.crt|, 'caddy: the certificate directory follows --cert-dir');
|
||||
is(caddyfile_path('sglang'), '/etc/caddy/Caddyfile.d/sglang.caddyfile',
|
||||
'caddy: the drop-in path follows the service name');
|
||||
is(caddy_main_config(), '/etc/caddy/Caddyfile', 'caddy: the main Caddyfile path');
|
||||
|
||||
# ---- caddy release binary -------------------------------------------------
|
||||
is(uname_to_arch('x86_64'), 'amd64', 'caddy binary: x86_64 maps to amd64');
|
||||
is(uname_to_arch('aarch64'), 'arm64', 'caddy binary: aarch64 maps to arm64');
|
||||
is(uname_to_arch('ppc64le'), undef, 'caddy binary: an unmapped machine is refused');
|
||||
is(caddy_asset_url('2.10.2', 'amd64'),
|
||||
'https://github.com/caddyserver/caddy/releases/download/v2.10.2/caddy_2.10.2_linux_amd64.tar.gz',
|
||||
'caddy binary: the release asset URL');
|
||||
|
||||
my $caddy_unit = caddy_unit_content();
|
||||
like($caddy_unit, qr|ExecStartPre=/usr/local/bin/caddy validate --config /etc/caddy/Caddyfile|,
|
||||
'caddy binary: the unit validates before it starts');
|
||||
like($caddy_unit, qr|ExecStart=/usr/local/bin/caddy run --environ --config /etc/caddy/Caddyfile|,
|
||||
'caddy binary: the unit runs the release binary');
|
||||
like($caddy_unit, qr|ExecReload=/usr/local/bin/caddy reload --config /etc/caddy/Caddyfile|,
|
||||
'caddy binary: the unit reloads through the admin endpoint');
|
||||
like($caddy_unit, qr/^User=caddy$/m, 'caddy binary: the unit runs as the caddy user');
|
||||
like($caddy_unit, qr/AmbientCapabilities=CAP_NET_BIND_SERVICE/, 'caddy binary: the port capability');
|
||||
|
||||
# ---- systemd unit --------------------------------------------------------
|
||||
my $unit = systemd_content({
|
||||
|
||||
Reference in New Issue
Block a user