Compare commits
22 Commits
1fbd3af379
...
main
| Author | SHA1 | Date | |
|---|---|---|---|
| f5f58daad1 | |||
| 554ac3b8ba | |||
| 3255c5adb3 | |||
| 64e9dcc74a | |||
| 085e4b76c5 | |||
| 2c2617e219 | |||
| 1d09d1d4fa | |||
| 7ad5ce520b | |||
| 3b9d188efa | |||
| 84ee9a6a6c | |||
| 10abd1b7f6 | |||
| 4e11b7f06b | |||
| 5da1c1a918 | |||
| 17a30c454e | |||
| 802c19db0a | |||
| 582ec570d0 | |||
| decead019d | |||
| 83d151f014 | |||
| cb65d0f9e1 | |||
| c038200106 | |||
| 99fb8fd168 | |||
| 4a49e28408 |
+92
-37
@@ -1,10 +1,44 @@
|
|||||||
FROM registry.fedoraproject.org/fedora:43
|
FROM registry.fedoraproject.org/fedora:43
|
||||||
|
|
||||||
|
# Proxy configuration ARGs
|
||||||
|
ARG HTTP_PROXY=""
|
||||||
|
ARG HTTPS_PROXY=""
|
||||||
|
ARG SOCKS_PROXY=""
|
||||||
|
ARG MAX_JOBS="32"
|
||||||
|
|
||||||
|
# Set environment variables if proxies are provided
|
||||||
|
ENV http_proxy=$HTTP_PROXY
|
||||||
|
ENV https_proxy=$HTTPS_PROXY
|
||||||
|
ENV no_proxy="localhost,127.0.0.1,::1"
|
||||||
|
ENV MAX_JOBS=$MAX_JOBS
|
||||||
|
ENV CMAKE_BUILD_PARALLEL_LEVEL=$MAX_JOBS
|
||||||
|
ENV NINJAFLAGS="-j$MAX_JOBS"
|
||||||
|
|
||||||
|
# Configure DNF proxy if provided
|
||||||
|
RUN if [ -n "$HTTP_PROXY" ]; then \
|
||||||
|
echo "proxy=$HTTP_PROXY" >> /etc/dnf/dnf.conf; \
|
||||||
|
fi
|
||||||
|
|
||||||
|
# Copy proxychains configuration
|
||||||
|
COPY proxychains4.conf /etc/proxychains.conf
|
||||||
|
|
||||||
|
# Update proxychains4.conf if SOCKS_PROXY is provided (format: host:port)
|
||||||
|
RUN if [ -n "$SOCKS_PROXY" ]; then \
|
||||||
|
HOST=$(echo $SOCKS_PROXY | cut -d: -f1); \
|
||||||
|
PORT=$(echo $SOCKS_PROXY | cut -d: -f2); \
|
||||||
|
sed -i "s/socks5.*/socks5 $HOST $PORT/g" /etc/proxychains.conf; \
|
||||||
|
fi
|
||||||
|
|
||||||
|
# Define a proxy wrapper
|
||||||
|
RUN echo '#!/bin/bash' > /usr/local/bin/maybe_proxy && \
|
||||||
|
echo 'if grep -q "^socks5 [0-9]" /etc/proxychains.conf; then if command -v proxychains4 >/dev/null 2>&1; then proxychains4 "$@"; else proxychains "$@"; fi; else "$@"; fi' >> /usr/local/bin/maybe_proxy && \
|
||||||
|
chmod +x /usr/local/bin/maybe_proxy
|
||||||
|
|
||||||
# 1. System Base & Build Tools
|
# 1. System Base & Build Tools
|
||||||
RUN dnf -y install --setopt=install_weak_deps=False --nodocs \
|
RUN dnf -y install --setopt=install_weak_deps=False --nodocs \
|
||||||
python3.13 python3.13-devel git rsync libatomic bash ca-certificates curl \
|
python3.13 python3.13-devel git rsync libatomic bash ca-certificates curl \
|
||||||
gcc gcc-c++ binutils make ffmpeg-free \
|
gcc gcc-c++ binutils make ffmpeg-free \
|
||||||
cmake ninja-build aria2c tar xz vim nano proxychains \
|
cmake ninja-build aria2c tar xz vim nano proxychains-ng \
|
||||||
libdrm-devel zlib-devel openssl-devel jq \
|
libdrm-devel zlib-devel openssl-devel jq \
|
||||||
numactl-devel gperftools-libs procps-ng \
|
numactl-devel gperftools-libs procps-ng \
|
||||||
&& dnf clean all && rm -rf /var/cache/dnf/*
|
&& dnf clean all && rm -rf /var/cache/dnf/*
|
||||||
@@ -13,18 +47,26 @@ RUN dnf -y install --setopt=install_weak_deps=False --nodocs \
|
|||||||
WORKDIR /tmp
|
WORKDIR /tmp
|
||||||
ARG ROCM_MAJOR_VER=7
|
ARG ROCM_MAJOR_VER=7
|
||||||
ARG GFX=gfx120X-all
|
ARG GFX=gfx120X-all
|
||||||
|
|
||||||
|
# 智能处理:如果 build context 里有 therock.tar.gz 就用本地的,没有就从网络拉取
|
||||||
|
# 注意:Dockerfile 的 COPY 无法直接做条件判断,我们通过 shell 逻辑处理
|
||||||
RUN set -euo pipefail; \
|
RUN set -euo pipefail; \
|
||||||
BASE="https://therock-nightly-tarball.s3.amazonaws.com"; \
|
if [ -f "therock.tar.gz" ]; then \
|
||||||
PREFIX="therock-dist-linux-${GFX}-${ROCM_MAJOR_VER}"; \
|
echo "Using local therock.tar.gz from build context."; \
|
||||||
KEY="$(proxychains curl -s "${BASE}?list-type=2&prefix=${PREFIX}" \
|
else \
|
||||||
| tr '<' '\n' \
|
echo "Local SDK not found, downloading from remote..."; \
|
||||||
| grep -o "therock-dist-linux-${GFX}-${ROCM_MAJOR_VER}\..*\.tar\.gz" \
|
BASE="https://therock-nightly-tarball.s3.amazonaws.com"; \
|
||||||
| sort -V | tail -n1)"; \
|
PREFIX="therock-dist-linux-${GFX}-${ROCM_MAJOR_VER}"; \
|
||||||
echo "Downloading Latest Tarball: ${KEY}"; \
|
KEY="$(maybe_proxy curl -s "${BASE}?list-type=2&prefix=${PREFIX}" \
|
||||||
proxychains aria2c -x 16 -s 16 -j 16 --file-allocation=none "${BASE}/${KEY}" -o therock.tar.gz; \
|
| tr '<' '\n' \
|
||||||
mkdir -p /opt/rocm; \
|
| grep -o "therock-dist-linux-${GFX}-${ROCM_MAJOR_VER}\..*\.tar\.gz" \
|
||||||
tar xzf therock.tar.gz -C /opt/rocm --strip-components=1; \
|
| sort -V | tail -n1)"; \
|
||||||
rm therock.tar.gz
|
echo "Downloading Latest Tarball: ${KEY}"; \
|
||||||
|
maybe_proxy aria2c -x 16 -s 16 -k 1M --file-allocation=none "${BASE}/${KEY}" -o therock.tar.gz; \
|
||||||
|
fi && \
|
||||||
|
mkdir -p /opt/rocm && \
|
||||||
|
tar xzf therock.tar.gz -C /opt/rocm --strip-components=1 && \
|
||||||
|
rm therock.tar.gz
|
||||||
|
|
||||||
# 3. Configure Global ROCm Environment
|
# 3. Configure Global ROCm Environment
|
||||||
RUN export ROCM_PATH=/opt/rocm && \
|
RUN export ROCM_PATH=/opt/rocm && \
|
||||||
@@ -54,32 +96,54 @@ ENV PIP_NO_CACHE_DIR=1
|
|||||||
RUN printf 'source /opt/venv/bin/activate\n' > /etc/profile.d/venv.sh
|
RUN printf 'source /opt/venv/bin/activate\n' > /etc/profile.d/venv.sh
|
||||||
RUN python -m pip install --upgrade pip wheel packaging "setuptools<80.0.0"
|
RUN python -m pip install --upgrade pip wheel packaging "setuptools<80.0.0"
|
||||||
|
|
||||||
# 5. Install PyTorch (TheRock Nightly) and PyYAML
|
# 5. Install PyTorch (TheRock Nightly)
|
||||||
RUN proxychains python -m pip install \
|
RUN maybe_proxy python -m pip install \
|
||||||
--index-url https://rocm.nightlies.amd.com/v2-staging/gfx120X-all/ \
|
--index-url https://rocm.nightlies.amd.com/v2-staging/gfx120X-all/ \
|
||||||
--pre torch torchaudio torchvision && \
|
--pre torch torchaudio torchvision && \
|
||||||
proxychains python -m pip install pyyaml
|
maybe_proxy python -m pip install pyyaml
|
||||||
|
|
||||||
# Flash-Attention
|
# Flash-Attention
|
||||||
WORKDIR /opt
|
WORKDIR /opt
|
||||||
ENV FLASH_ATTENTION_TRITON_AMD_ENABLE="TRUE"
|
ENV FLASH_ATTENTION_TRITON_AMD_ENABLE="TRUE"
|
||||||
|
ENV ROCM_HOME="/opt/rocm"
|
||||||
|
ENV HIP_PATH="/opt/rocm"
|
||||||
|
ENV PATH="/opt/rocm/bin:/opt/rocm/llvm/bin:$PATH"
|
||||||
|
ENV LD_LIBRARY_PATH="/opt/rocm/lib:/opt/rocm/lib64:/opt/rocm/llvm/lib"
|
||||||
|
|
||||||
RUN proxychains git clone https://github.com/ROCm/flash-attention.git &&\
|
RUN set -euo pipefail; \
|
||||||
cd flash-attention &&\
|
git config --global http.postBuffer 524288000; \
|
||||||
git checkout main_perf &&\
|
git config --global http.lowSpeedLimit 0; \
|
||||||
python setup.py install && \
|
git config --global http.lowSpeedTime 999999; \
|
||||||
|
git config --global http.version HTTP/1.1; \
|
||||||
|
if [ -n "$SOCKS_PROXY" ]; then \
|
||||||
|
git config --global http.proxy "socks5://$SOCKS_PROXY"; \
|
||||||
|
git config --global https.proxy "socks5://$SOCKS_PROXY"; \
|
||||||
|
fi; \
|
||||||
|
CLONED=0; \
|
||||||
|
for i in 1 2 3 4 5; do \
|
||||||
|
rm -rf /opt/flash-attention; \
|
||||||
|
if maybe_proxy git clone --recursive --branch main_perf --depth 1 --shallow-submodules https://github.com/ROCm/flash-attention.git /opt/flash-attention; then \
|
||||||
|
CLONED=1; \
|
||||||
|
break; \
|
||||||
|
fi; \
|
||||||
|
echo "flash-attention clone failed (attempt ${i}/5), retrying..."; \
|
||||||
|
sleep $((i * 5)); \
|
||||||
|
done; \
|
||||||
|
if [ "${CLONED}" -ne 1 ]; then \
|
||||||
|
echo "flash-attention clone failed after retries"; \
|
||||||
|
exit 1; \
|
||||||
|
fi; \
|
||||||
|
cd /opt/flash-attention; \
|
||||||
|
python setup.py install; \
|
||||||
cd /opt && rm -rf /opt/flash-attention
|
cd /opt && rm -rf /opt/flash-attention
|
||||||
|
|
||||||
# 6. Clone vLLM
|
# 6. Clone vLLM
|
||||||
RUN proxychains git clone https://github.com/vllm-project/vllm.git /opt/vllm
|
RUN maybe_proxy git clone https://github.com/vllm-project/vllm.git /opt/vllm
|
||||||
WORKDIR /opt/vllm
|
WORKDIR /opt/vllm
|
||||||
|
|
||||||
# --- PATCHING ---
|
# --- PATCHING ---
|
||||||
# vLLM relies on 'amdsmi' to detect AMD GPUs. If it's missing or fails (common in containers),
|
|
||||||
# vLLM falls back to CPU. We patch it to force ROCm detection.
|
|
||||||
RUN echo "import sys, re" > patch_vllm.py && \
|
RUN echo "import sys, re" > patch_vllm.py && \
|
||||||
echo "from pathlib import Path" >> patch_vllm.py && \
|
echo "from pathlib import Path" >> patch_vllm.py && \
|
||||||
# Patch 1: __init__.py - Force is_rocm=True and bypass amdsmi checks
|
|
||||||
echo "p = Path('vllm/platforms/__init__.py')" >> patch_vllm.py && \
|
echo "p = Path('vllm/platforms/__init__.py')" >> patch_vllm.py && \
|
||||||
echo "txt = p.read_text()" >> patch_vllm.py && \
|
echo "txt = p.read_text()" >> patch_vllm.py && \
|
||||||
echo "txt = txt.replace('import amdsmi', '# import amdsmi')" >> patch_vllm.py && \
|
echo "txt = txt.replace('import amdsmi', '# import amdsmi')" >> patch_vllm.py && \
|
||||||
@@ -88,7 +152,6 @@ RUN echo "import sys, re" > patch_vllm.py && \
|
|||||||
echo "txt = txt.replace('amdsmi.amdsmi_init()', 'pass')" >> patch_vllm.py && \
|
echo "txt = txt.replace('amdsmi.amdsmi_init()', 'pass')" >> patch_vllm.py && \
|
||||||
echo "txt = txt.replace('amdsmi.amdsmi_shut_down()', 'pass')" >> patch_vllm.py && \
|
echo "txt = txt.replace('amdsmi.amdsmi_shut_down()', 'pass')" >> patch_vllm.py && \
|
||||||
echo "p.write_text(txt)" >> patch_vllm.py && \
|
echo "p.write_text(txt)" >> patch_vllm.py && \
|
||||||
# Patch 2: rocm.py - Mock amdsmi and force device name
|
|
||||||
echo "p = Path('vllm/platforms/rocm.py')" >> patch_vllm.py && \
|
echo "p = Path('vllm/platforms/rocm.py')" >> patch_vllm.py && \
|
||||||
echo "txt = p.read_text()" >> patch_vllm.py && \
|
echo "txt = p.read_text()" >> patch_vllm.py && \
|
||||||
echo "header = 'import sys\nfrom unittest.mock import MagicMock\nsys.modules[\"amdsmi\"] = MagicMock()\n'" >> patch_vllm.py && \
|
echo "header = 'import sys\nfrom unittest.mock import MagicMock\nsys.modules[\"amdsmi\"] = MagicMock()\n'" >> patch_vllm.py && \
|
||||||
@@ -108,11 +171,8 @@ ENV VLLM_TARGET_DEVICE="rocm"
|
|||||||
ENV PYTORCH_ROCM_ARCH="gfx1201"
|
ENV PYTORCH_ROCM_ARCH="gfx1201"
|
||||||
ENV HIP_ARCHITECTURES="gfx1201"
|
ENV HIP_ARCHITECTURES="gfx1201"
|
||||||
ENV AMDGPU_TARGETS="gfx1201"
|
ENV AMDGPU_TARGETS="gfx1201"
|
||||||
ENV MAX_JOBS="32"
|
ENV MAX_JOBS=$MAX_JOBS
|
||||||
|
|
||||||
# --- FIX FOR SEGFAULT ---
|
|
||||||
# We force the Host Compiler (CC/CXX) to be the ROCm Clang, not Fedora GCC.
|
|
||||||
# This aligns the ABI of the compiled vLLM extensions with PyTorch.
|
|
||||||
ENV CC="/opt/rocm/llvm/bin/clang"
|
ENV CC="/opt/rocm/llvm/bin/clang"
|
||||||
ENV CXX="/opt/rocm/llvm/bin/clang++"
|
ENV CXX="/opt/rocm/llvm/bin/clang++"
|
||||||
|
|
||||||
@@ -123,16 +183,14 @@ RUN export HIP_DEVICE_LIB_PATH=$(find /opt/rocm -type d -name bitcode -print -qu
|
|||||||
python -m pip wheel --no-build-isolation --no-deps -w /tmp/dist -v . && \
|
python -m pip wheel --no-build-isolation --no-deps -w /tmp/dist -v . && \
|
||||||
python -m pip install /tmp/dist/*.whl
|
python -m pip install /tmp/dist/*.whl
|
||||||
|
|
||||||
# --- bitsandbytes (ROCm) ---
|
# bitsandbytes
|
||||||
WORKDIR /opt
|
WORKDIR /opt
|
||||||
RUN proxychains git clone -b rocm_enabled_multi_backend https://github.com/ROCm/bitsandbytes.git
|
RUN maybe_proxy git clone -b rocm_enabled_multi_backend https://github.com/ROCm/bitsandbytes.git
|
||||||
WORKDIR /opt/bitsandbytes
|
WORKDIR /opt/bitsandbytes
|
||||||
|
|
||||||
# Explicitly set HIP_PLATFORM (Docker ENV, not /etc/profile)
|
|
||||||
ENV HIP_PLATFORM="amd"
|
ENV HIP_PLATFORM="amd"
|
||||||
ENV CMAKE_PREFIX_PATH="/opt/rocm"
|
ENV CMAKE_PREFIX_PATH="/opt/rocm"
|
||||||
|
|
||||||
# Force CMake to use the System ROCm Compiler (/opt/rocm/llvm/bin/clang++)
|
|
||||||
RUN cmake -S . \
|
RUN cmake -S . \
|
||||||
-DGPU_TARGETS="gfx1201" \
|
-DGPU_TARGETS="gfx1201" \
|
||||||
-DBNB_ROCM_ARCH="gfx1201" \
|
-DBNB_ROCM_ARCH="gfx1201" \
|
||||||
@@ -143,7 +201,7 @@ RUN cmake -S . \
|
|||||||
make -j$(nproc) && \
|
make -j$(nproc) && \
|
||||||
python -m pip install --no-cache-dir . --no-build-isolation --no-deps
|
python -m pip install --no-cache-dir . --no-build-isolation --no-deps
|
||||||
|
|
||||||
# 8. Final Cleanup & Runtime
|
# Cleanup
|
||||||
WORKDIR /opt
|
WORKDIR /opt
|
||||||
RUN chmod -R a+rwX /opt && \
|
RUN chmod -R a+rwX /opt && \
|
||||||
find /opt/venv -type f -name "*.so" -exec strip -s {} + 2>/dev/null || true && \
|
find /opt/venv -type f -name "*.so" -exec strip -s {} + 2>/dev/null || true && \
|
||||||
@@ -151,11 +209,8 @@ RUN chmod -R a+rwX /opt && \
|
|||||||
rm -rf /root/.cache/pip || true && \
|
rm -rf /root/.cache/pip || true && \
|
||||||
dnf clean all && rm -rf /var/cache/dnf/*
|
dnf clean all && rm -rf /var/cache/dnf/*
|
||||||
|
|
||||||
# Create vLLM configuration directory and model directory
|
RUN mkdir -p /etc/vllm && mkdir -p /model
|
||||||
RUN mkdir -p /etc/vllm && \
|
|
||||||
mkdir -p /model
|
|
||||||
|
|
||||||
# Copy necessary scripts
|
|
||||||
COPY scripts/01-rocm-envs.sh /etc/profile.d/01-rocm-envs.sh
|
COPY scripts/01-rocm-envs.sh /etc/profile.d/01-rocm-envs.sh
|
||||||
COPY scripts/99-toolbox-banner.sh /etc/profile.d/99-toolbox-banner.sh
|
COPY scripts/99-toolbox-banner.sh /etc/profile.d/99-toolbox-banner.sh
|
||||||
COPY scripts/zz-venv-last.sh /etc/profile.d/zz-venv-last.sh
|
COPY scripts/zz-venv-last.sh /etc/profile.d/zz-venv-last.sh
|
||||||
|
|||||||
+74
-1
@@ -82,6 +82,8 @@ show_usage() {
|
|||||||
echo " -m, --models DIR 指定模型目录路径"
|
echo " -m, --models DIR 指定模型目录路径"
|
||||||
echo " -p, --port PORT 指定服务端口"
|
echo " -p, --port PORT 指定服务端口"
|
||||||
echo " -b, --branch NAME 指定 Git 分支(默认:main)"
|
echo " -b, --branch NAME 指定 Git 分支(默认:main)"
|
||||||
|
echo " --http-proxy URL 指定构建时的 HTTP 代理 (例如: http://192.168.0.10:7890)"
|
||||||
|
echo " --socks-proxy HOST:PORT 指定构建时的 SOCKS 代理 (例如: 192.168.0.10:1080)"
|
||||||
echo " -h, --help 显示此帮助信息"
|
echo " -h, --help 显示此帮助信息"
|
||||||
echo ""
|
echo ""
|
||||||
echo "示例:"
|
echo "示例:"
|
||||||
@@ -98,6 +100,8 @@ FORCE_BUILD=false
|
|||||||
STOP_ONLY=false
|
STOP_ONLY=false
|
||||||
DETACH=true
|
DETACH=true
|
||||||
CUSTOM_CONFIG=""
|
CUSTOM_CONFIG=""
|
||||||
|
HTTP_PROXY_ARG=""
|
||||||
|
SOCKS_PROXY_ARG=""
|
||||||
CUSTOM_MODELS=""
|
CUSTOM_MODELS=""
|
||||||
CUSTOM_PORT=""
|
CUSTOM_PORT=""
|
||||||
|
|
||||||
@@ -107,6 +111,14 @@ while [[ $# -gt 0 ]]; do
|
|||||||
FORCE_BUILD=true
|
FORCE_BUILD=true
|
||||||
shift
|
shift
|
||||||
;;
|
;;
|
||||||
|
--http-proxy)
|
||||||
|
HTTP_PROXY_ARG="$2"
|
||||||
|
shift 2
|
||||||
|
;;
|
||||||
|
--socks-proxy)
|
||||||
|
SOCKS_PROXY_ARG="$2"
|
||||||
|
shift 2
|
||||||
|
;;
|
||||||
-s|--stop)
|
-s|--stop)
|
||||||
STOP_ONLY=true
|
STOP_ONLY=true
|
||||||
shift
|
shift
|
||||||
@@ -258,6 +270,58 @@ has_local_changes() {
|
|||||||
|
|
||||||
# 构建镜像
|
# 构建镜像
|
||||||
build_image() {
|
build_image() {
|
||||||
|
print_step "准备 ROCm SDK..."
|
||||||
|
|
||||||
|
SDK_FILE="therock.tar.gz"
|
||||||
|
if [ ! -f "$SDK_FILE" ]; then
|
||||||
|
print_warning "本地未发现 $SDK_FILE,开始宿主机预下载..."
|
||||||
|
|
||||||
|
# 自动检测 proxychains
|
||||||
|
PROXY_WRAPPER=""
|
||||||
|
if command -v proxychains4 >/dev/null 2>&1; then
|
||||||
|
PROXY_WRAPPER="proxychains4"
|
||||||
|
elif command -v proxychains >/dev/null 2>&1; then
|
||||||
|
PROXY_WRAPPER="proxychains"
|
||||||
|
fi
|
||||||
|
|
||||||
|
# 获取下载地址
|
||||||
|
BASE="https://therock-nightly-tarball.s3.amazonaws.com"
|
||||||
|
PREFIX="therock-dist-linux-gfx120X-all-7"
|
||||||
|
|
||||||
|
print_info "正在获取最新版本信息..."
|
||||||
|
CURL_CMD="curl -s"
|
||||||
|
[ -n "$PROXY_WRAPPER" ] && CURL_CMD="$PROXY_WRAPPER $CURL_CMD"
|
||||||
|
[ -z "$PROXY_WRAPPER" ] && [ -n "$HTTP_PROXY_ARG" ] && CURL_CMD="curl -x $HTTP_PROXY_ARG -s"
|
||||||
|
|
||||||
|
KEY=$($CURL_CMD "${BASE}?list-type=2&prefix=${PREFIX}" \
|
||||||
|
| tr '<' '\n' \
|
||||||
|
| grep -o "therock-dist-linux-gfx120X-all-7\..*\.tar\.gz" \
|
||||||
|
| sort -V | tail -n1)
|
||||||
|
|
||||||
|
if [ -n "$KEY" ]; then
|
||||||
|
DOWNLOAD_URL="${BASE}/${KEY}"
|
||||||
|
print_info "开始下载: $DOWNLOAD_URL"
|
||||||
|
|
||||||
|
# 优先使用 aria2c
|
||||||
|
if command -v aria2c >/dev/null 2>&1; then
|
||||||
|
ARIA2_CMD="aria2c -x 16 -s 16 -k 1M -c"
|
||||||
|
[ -n "$PROXY_WRAPPER" ] && ARIA2_CMD="$PROXY_WRAPPER $ARIA2_CMD"
|
||||||
|
[ -z "$PROXY_WRAPPER" ] && [ -n "$HTTP_PROXY_ARG" ] && ARIA2_CMD="$ARIA2_CMD --all-proxy=$HTTP_PROXY_ARG"
|
||||||
|
$ARIA2_CMD "$DOWNLOAD_URL" -o "$SDK_FILE"
|
||||||
|
else
|
||||||
|
DL_CMD="curl -L -C - "
|
||||||
|
[ -n "$PROXY_WRAPPER" ] && DL_CMD="$PROXY_WRAPPER $DL_CMD"
|
||||||
|
[ -z "$PROXY_WRAPPER" ] && [ -n "$HTTP_PROXY_ARG" ] && DL_CMD="curl -x $HTTP_PROXY_ARG -L -C - "
|
||||||
|
$DL_CMD "$DOWNLOAD_URL" -o "$SDK_FILE"
|
||||||
|
fi
|
||||||
|
else
|
||||||
|
print_error "无法获取 SDK 下载地址,请检查代理设置或手动下载。"
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
else
|
||||||
|
print_success "发现本地 $SDK_FILE,跳过下载。"
|
||||||
|
fi
|
||||||
|
|
||||||
print_step "开始构建 Docker 镜像..."
|
print_step "开始构建 Docker 镜像..."
|
||||||
print_info "镜像名称:${IMAGE_NAME}:${IMAGE_TAG}"
|
print_info "镜像名称:${IMAGE_NAME}:${IMAGE_TAG}"
|
||||||
print_info "构建目录:${PROJECT_DIR}"
|
print_info "构建目录:${PROJECT_DIR}"
|
||||||
@@ -265,7 +329,16 @@ build_image() {
|
|||||||
|
|
||||||
BUILD_START=$(date +%s)
|
BUILD_START=$(date +%s)
|
||||||
|
|
||||||
if DOCKER_BUILDKIT=1 docker build --build-arg MAX_JOBS=32 -t "${IMAGE_NAME}:${IMAGE_TAG}" .; then
|
# 准备构建参数
|
||||||
|
BUILD_ARGS="--network=host --build-arg MAX_JOBS=${MAX_JOBS:-32}"
|
||||||
|
if [ -n "$HTTP_PROXY_ARG" ]; then
|
||||||
|
BUILD_ARGS="${BUILD_ARGS} --build-arg HTTP_PROXY=${HTTP_PROXY_ARG} --build-arg HTTPS_PROXY=${HTTP_PROXY_ARG}"
|
||||||
|
fi
|
||||||
|
if [ -n "$SOCKS_PROXY_ARG" ]; then
|
||||||
|
BUILD_ARGS="${BUILD_ARGS} --build-arg SOCKS_PROXY=${SOCKS_PROXY_ARG}"
|
||||||
|
fi
|
||||||
|
|
||||||
|
if docker build ${BUILD_ARGS} -t "${IMAGE_NAME}:${IMAGE_TAG}" .; then
|
||||||
BUILD_END=$(date +%s)
|
BUILD_END=$(date +%s)
|
||||||
BUILD_TIME=$((BUILD_END - BUILD_START))
|
BUILD_TIME=$((BUILD_END - BUILD_START))
|
||||||
|
|
||||||
|
|||||||
@@ -0,0 +1,165 @@
|
|||||||
|
# proxychains.conf VER 4.x
|
||||||
|
#
|
||||||
|
# HTTP, SOCKS4a, SOCKS5 tunneling proxifier with DNS.
|
||||||
|
|
||||||
|
|
||||||
|
# The option below identifies how the ProxyList is treated.
|
||||||
|
# only one option should be uncommented at time,
|
||||||
|
# otherwise the last appearing option will be accepted
|
||||||
|
#
|
||||||
|
#dynamic_chain
|
||||||
|
#
|
||||||
|
# Dynamic - Each connection will be done via chained proxies
|
||||||
|
# all proxies chained in the order as they appear in the list
|
||||||
|
# at least one proxy must be online to play in chain
|
||||||
|
# (dead proxies are skipped)
|
||||||
|
# otherwise EINTR is returned to the app
|
||||||
|
#
|
||||||
|
# strict_chain
|
||||||
|
dynamic_chain
|
||||||
|
#
|
||||||
|
# Strict - Each connection will be done via chained proxies
|
||||||
|
# all proxies chained in the order as they appear in the list
|
||||||
|
# all proxies must be online to play in chain
|
||||||
|
# otherwise EINTR is returned to the app
|
||||||
|
#
|
||||||
|
#round_robin_chain
|
||||||
|
#
|
||||||
|
# Round Robin - Each connection will be done via chained proxies
|
||||||
|
# of chain_len length
|
||||||
|
# all proxies chained in the order as they appear in the list
|
||||||
|
# at least one proxy must be online to play in chain
|
||||||
|
# (dead proxies are skipped).
|
||||||
|
# the start of the current proxy chain is the proxy after the last
|
||||||
|
# proxy in the previously invoked proxy chain.
|
||||||
|
# if the end of the proxy chain is reached while looking for proxies
|
||||||
|
# start at the beginning again.
|
||||||
|
# otherwise EINTR is returned to the app
|
||||||
|
# These semantics are not guaranteed in a multithreaded environment.
|
||||||
|
#
|
||||||
|
#random_chain
|
||||||
|
#
|
||||||
|
# Random - Each connection will be done via random proxy
|
||||||
|
# (or proxy chain, see chain_len) from the list.
|
||||||
|
# this option is good to test your IDS :)
|
||||||
|
|
||||||
|
# Make sense only if random_chain or round_robin_chain
|
||||||
|
#chain_len = 2
|
||||||
|
|
||||||
|
# Quiet mode (no output from library)
|
||||||
|
#quiet_mode
|
||||||
|
|
||||||
|
## Proxy DNS requests - no leak for DNS data
|
||||||
|
# (disable all of the 3 items below to not proxy your DNS requests)
|
||||||
|
|
||||||
|
# method 1. this uses the proxychains4 style method to do remote dns:
|
||||||
|
# a thread is spawned that serves DNS requests and hands down an ip
|
||||||
|
# assigned from an internal list (via remote_dns_subnet).
|
||||||
|
# this is the easiest (setup-wise) and fastest method, however on
|
||||||
|
# systems with buggy libcs and very complex software like webbrowsers
|
||||||
|
# this might not work and/or cause crashes.
|
||||||
|
proxy_dns
|
||||||
|
|
||||||
|
# method 2. use the old proxyresolv script to proxy DNS requests
|
||||||
|
# in proxychains 3.1 style. requires `proxyresolv` in $PATH
|
||||||
|
# plus a dynamically linked `dig` binary.
|
||||||
|
# this is a lot slower than `proxy_dns`, doesn't support .onion URLs,
|
||||||
|
# but might be more compatible with complex software like webbrowsers.
|
||||||
|
#proxy_dns_old
|
||||||
|
|
||||||
|
# method 3. use proxychains4-daemon process to serve remote DNS requests.
|
||||||
|
# this is similar to the threaded `proxy_dns` method, however it requires
|
||||||
|
# that proxychains4-daemon is already running on the specified address.
|
||||||
|
# on the plus side it doesn't do malloc/threads so it should be quite
|
||||||
|
# compatible with complex, async-unsafe software.
|
||||||
|
# note that if you don't start proxychains4-daemon before using this,
|
||||||
|
# the process will simply hang.
|
||||||
|
#proxy_dns_daemon 127.0.0.1:1053
|
||||||
|
|
||||||
|
# set the class A subnet number to use for the internal remote DNS mapping
|
||||||
|
# we use the reserved 224.x.x.x range by default,
|
||||||
|
# if the proxified app does a DNS request, we will return an IP from that range.
|
||||||
|
# on further accesses to this ip we will send the saved DNS name to the proxy.
|
||||||
|
# in case some control-freak app checks the returned ip, and denies to
|
||||||
|
# connect, you can use another subnet, e.g. 10.x.x.x or 127.x.x.x.
|
||||||
|
# of course you should make sure that the proxified app does not need
|
||||||
|
# *real* access to this subnet.
|
||||||
|
# i.e. dont use the same subnet then in the localnet section
|
||||||
|
#remote_dns_subnet 127
|
||||||
|
#remote_dns_subnet 10
|
||||||
|
remote_dns_subnet 224
|
||||||
|
|
||||||
|
# Some timeouts in milliseconds
|
||||||
|
tcp_read_time_out 15000
|
||||||
|
tcp_connect_time_out 8000
|
||||||
|
|
||||||
|
### Examples for localnet exclusion
|
||||||
|
## localnet ranges will *not* use a proxy to connect.
|
||||||
|
## note that localnet works only when plain IP addresses are passed to the app,
|
||||||
|
## the hostname resolves via /etc/hosts, or proxy_dns is disabled or proxy_dns_old used.
|
||||||
|
|
||||||
|
## Exclude connections to 192.168.1.0/24 with port 80
|
||||||
|
# localnet 192.168.1.0:80/255.255.255.0
|
||||||
|
|
||||||
|
## Exclude connections to 192.168.100.0/24
|
||||||
|
# localnet 192.168.100.0/255.255.255.0
|
||||||
|
|
||||||
|
## Exclude connections to ANYwhere with port 80
|
||||||
|
# localnet 0.0.0.0:80/0.0.0.0
|
||||||
|
# localnet [::]:80/0
|
||||||
|
|
||||||
|
## RFC6890 Loopback address range
|
||||||
|
## if you enable this, you have to make sure remote_dns_subnet is not 127
|
||||||
|
## you'll need to enable it if you want to use an application that
|
||||||
|
## connects to localhost.
|
||||||
|
# localnet 127.0.0.0/255.0.0.0
|
||||||
|
# localnet ::1/128
|
||||||
|
|
||||||
|
## RFC1918 Private Address Ranges
|
||||||
|
# localnet 10.0.0.0/255.0.0.0
|
||||||
|
# localnet 172.16.0.0/255.240.0.0
|
||||||
|
# localnet 192.168.0.0/255.255.0.0
|
||||||
|
|
||||||
|
### Examples for dnat
|
||||||
|
## Trying to proxy connections to destinations which are dnatted,
|
||||||
|
## will result in proxying connections to the new given destinations.
|
||||||
|
## Whenever I connect to 1.1.1.1 on port 1234 actually connect to 1.1.1.2 on port 443
|
||||||
|
# dnat 1.1.1.1:1234 1.1.1.2:443
|
||||||
|
|
||||||
|
## Whenever I connect to 1.1.1.1 on port 443 actually connect to 1.1.1.2 on port 443
|
||||||
|
## (no need to write :443 again)
|
||||||
|
# dnat 1.1.1.2:443 1.1.1.2
|
||||||
|
|
||||||
|
## No matter what port I connect to on 1.1.1.1 port actually connect to 1.1.1.2 on port 443
|
||||||
|
# dnat 1.1.1.1 1.1.1.2:443
|
||||||
|
|
||||||
|
## Always, instead of connecting to 1.1.1.1, connect to 1.1.1.2
|
||||||
|
# dnat 1.1.1.1 1.1.1.2
|
||||||
|
|
||||||
|
# ProxyList format
|
||||||
|
# type ip port [user pass]
|
||||||
|
# (values separated by 'tab' or 'blank')
|
||||||
|
#
|
||||||
|
# only numeric ipv4 addresses are valid
|
||||||
|
#
|
||||||
|
#
|
||||||
|
# Examples:
|
||||||
|
#
|
||||||
|
# socks5 192.168.67.78 1080 lamer secret
|
||||||
|
# http 192.168.89.3 8080 justu hidden
|
||||||
|
# socks4 192.168.1.49 1080
|
||||||
|
# http 192.168.39.93 8080
|
||||||
|
#
|
||||||
|
#
|
||||||
|
# proxy types: http, socks4, socks5, raw
|
||||||
|
# * raw: The traffic is simply forwarded to the proxy without modification.
|
||||||
|
# ( auth types supported: "basic"-http "user/pass"-socks )
|
||||||
|
#
|
||||||
|
[ProxyList]
|
||||||
|
|
||||||
|
|
||||||
|
# add proxy here ...
|
||||||
|
# meanwile
|
||||||
|
# defaults set to "tor"
|
||||||
|
# socks4 127.0.0.1 9050
|
||||||
|
socks5 192.168.0.11 1080
|
||||||
Reference in New Issue
Block a user