惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

H
Help Net Security
宝玉的分享
宝玉的分享
The Cloudflare Blog
Apple Machine Learning Research
Apple Machine Learning Research
V
Visual Studio Blog
Last Week in AI
Last Week in AI
Hugging Face - Blog
Hugging Face - Blog
博客园 - 司徒正美
博客园 - 三生石上(FineUI控件)
A
About on SuperTechFans
MyScale Blog
MyScale Blog
aimingoo的专栏
aimingoo的专栏
Microsoft Security Blog
Microsoft Security Blog
D
Docker
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Recent Announcements
Recent Announcements
大猫的无限游戏
大猫的无限游戏
IT之家
IT之家
P
Proofpoint News Feed
L
LangChain Blog
Blog — PlanetScale
Blog — PlanetScale
The GitHub Blog
The GitHub Blog
博客园 - 【当耐特】
Martin Fowler
Martin Fowler

Rafael Magalhaes

Internal Developer Platform 简介 故郷で野良猫を保護したことについて 我喜欢的动漫女角色 在日本租房 Blog Enhanced 我遭遇的网络安全事件及应对 きつい日々はやっと終わりそう 在东京救助流浪猫 仇恨教育真实存在吗 什么是创业 向中国程序员介绍日本 IT Blog Reimplemented 马伯庸写做爱 Dynamic 3D Physical Rope in Godot - Part2 Abandoned Space Werewolf Indiegame Showcase Dynamic 3D Physical Rope in Godot - Part1 我挤上了女性专用车厢 日本见闻(其一) Integrate Godot Headless Server with Nakama Jet Animation Sequence Lamp Animation Rigged 第一次用数位板画画 计算机能解决的问题 一个淘宝商品封面 黄奇帆的观点 中国历史王朝的巅峰 - 宋 历史上公司的极致 GDP 简介 为什么要读历史 两个困扰了很久的问题终于有了答案
Deploy Perforce Server into Kubernetes
2024-05-19 · via Rafael Magalhaes

Why Perforce

Perforce is a version control tool just like git, svn, but optimized for large binary files.

Perforce is widely used by top tier game studios like Naughty Dogs, Electronic Arts and Ubisoft.

To me, the reason I choose Perfoce rather than Git LFS is that I already have a k8s cluster up and running and don't want to buy datapacks on Github as there would be large, large asset files for game projects.

Dockerfile

All my nodes are arm64-based AWS virtual machines. Perforce don't maintain Linux packages for arm64 anymore. I tried the way to build docker image by downloading binaries and it worked.

FROM ubuntu:jammy

# Update our main system
RUN apt-get update -y

# Install dependencies
RUN apt-get install -y wget tar

# Set the working directory
WORKDIR /perforce

# Download and extract Perforce binaries
RUN wget https://www.perforce.com/downloads/perforce/r24.1/bin.linux26aarch64/helix-core-server.tgz -O helix-core-server.tgz \
    && tar -xzf helix-core-server.tgz \
    && rm helix-core-server.tgz

# Add Perforce binaries to PATH
ENV PATH="/perforce:${PATH}"

# Define environment variables for Perforce
ENV P4ROOT=/perforce
ENV P4PORT=1666

# Expose the Perforce server port
EXPOSE 1666

# Start Perforce server and tail logs
CMD p4d -r /perforce -p $P4PORT -L /perforce/logs/log && tail -F /perforce/logs/log

The download url can be found on official perforce download page. By the time when this article is written, the latest version for helix server is 2024.1/2596294. Be sure to check new releases when you make your own docker image.

Build and push to registry

#!/bin/bash

# Variables
repositoryHost='your-registry'
repository='your-repo'
imageBaseName='helix-core-server'
platforms='linux/arm64' # Define platforms

# Extract version from package.json
version='0.0.1'

# Full image tag with version
imageTag="$imageBaseName:$version"

# Create a new builder instance that supports multi-platform builds, if not already done
docker buildx create --name mymultiarchbuilder --use

# Start up the build instance, if not already done
docker buildx inspect --bootstrap

# Build and push Docker image
docker buildx build --platform $platforms -t $repositoryHost/$repository/$imageTag --push .

K8s Deployment

Everytime I expose a service from my k8s cluster I will consider DDoS problem because you will meet them sooner or later if you don't. Usually I expose them through nodeport + nginx ingress controller, and put them behind cloudflare.

However Perforce is not a http service and cannot be proxied through cloudflare orange cloud. I have to disable orange cloud and access them directly using nodeport. It is not a big problem because I only use it for myself. If the Perforce server is going to be public over the Internet, you will have to consider DDoS protection.

deployment.yaml

I already have a PVC setup based on juicefs in my k8s cluster, so the pod will not lose any data during redeployments. I mapped data/perforce-root in juicefs for /etc/perforce and /perforce inside container. Make sure to adjust it for your case.

This article doesn't talk about how to deploy juicefs to your k8s cluster as PersistentVolume. They are detailed written in the official documentation of juicefs.

apiVersion: apps/v1
kind: Deployment
metadata:
  name: perforce-server
  namespace: default
spec:
  replicas: 1
  selector:
    matchLabels:
      app: perforce-server
  template:
    metadata:
      labels:
        app: perforce-server
    spec:
      containers:
        - name: perforce-server
          image: your-registry/helix-core-server:0.0.1
          ports:
            - containerPort: 1666
          volumeMounts:
            - mountPath: /etc/perforce
              name: perforce-storage
              subPath: data/perforce-root/etc/perfoce
            - mountPath: /perfoce
              name: perforce-storage
              subPath: data/perfoce-root/perfoce
          env:
            - name: P4ROOT
              value: /perforce
            - name: P4PORT
              value: '1666'
      volumes:
        - name: perforce-storage
          persistentVolumeClaim:
            claimName: juicefs-pvc

nodeport.yaml

apiVersion: v1
kind: Service
metadata:
  name: perforce-service
  namespace: default
spec:
  type: NodePort
  ports:
    - port: 1666
      targetPort: 1666
  selector:
    app: perforce-server

Apply them

kubectl apply -f deployment.yaml
kubectl apply -f nodeport.yaml

Check port k8s assigned for perforce-server by

kubectl get svc

In my case the port is 30222. Point your domain to the public IP of node. Your Perforce address is your-domain:30222. Remember to adjust your firewall or other related security policies.

Set Password

Although you can do this step using init containers with some tricks and let k8s do this for you, it is tedious so I just get into the pod and do it manually and only once because the setup will be persistent as the pod is provided with PVC.

Get pod name

kubectl get pods -l app=perforce-server

Then get into it

kubectl exec pod-name-you-just-got -it -- /bin/bash

Enable authorization

p4 protect -o > protections.p4s

In googled results, the usernames of admin are supers but in my protection.p4s I only see a root. Never mind, just set password for root

p4 -u root passwd

Now you can connect to Perforce server using your-domain:30222 with root and password.

You can connect to it with root using p4admin GUI client and create users with normal permission for daily development.

Reference