Skip to content

feat: Add a CLI to help prepare a precompiled driver image - #658

Open
dlipovetsky wants to merge 1 commit into
ROCm:mainfrom
dlipovetsky:prepareimage-cli
Open

dlipovetsky wants to merge 1 commit into
ROCm:mainfrom
dlipovetsky:prepareimage-cli

Conversation

@dlipovetsky

@dlipovetsky dlipovetsky commented Sep 24, 2026 •

Copy link
Copy Markdown

Motivation

There are many reasons to use precompiled driver container images. There is not an official upstream source of these images, so users need to create their own.

The process for doing that right now is described in https://instinct.docs.amd.com/projects/gpu-operator/en/latest/drivers/precompiled-driver.html. Because it takes multiple steps, and copying/pasting, it can be prone to errors.

This PR proposes a CLI to simplify the process. It takes the guess work out of choosing the right Dockerfile template, as well as using the correct image tag.

Demo:

$ make prepareimage
$ ./prepareimage \
-os-pretty-name="Ubuntu 24.04.4 LTS" \
-drivers-version=31.40.1 \
-kernel-full-version=6.8.0-139-generic \
-image-name=docker.io/dlipovetsky/amdgpu \ 
> create-image.sh
$ sh create-image.sh
[+] Building 0.0s (18/18) FINISHED                                                                                                           docker:default
 => [internal] load build definition from Dockerfile                                                                                                   0.0s
 => => transferring dockerfile: 2.02kB                                                                                                                 0.0s
 => WARN: FromAsCasing: 'as' and 'FROM' keywords' casing do not match (line 1)                                                                         0.0s
 => WARN: SecretsUsedInArgOrEnv: Do not use ARG or ENV instructions for sensitive data (ARG "GPG_KEY_URL") (line 11)                                   0.0s
 => [internal] load metadata for docker.io/library/ubuntu:24.04                                                                                        0.0s
 => [internal] load .dockerignore                                                                                                                      0.0s
 => => transferring context: 2B                                                                                                                        0.0s
 => [builder 1/7] FROM docker.io/library/ubuntu:24.04                                                                                                  0.0s
 => CACHED [stage-1 2/8] RUN apt-get update && apt-get install -y kmod                                                                                 0.0s
 => CACHED [stage-1 3/8] RUN mkdir -p /opt/lib/modules/6.8.0-139-generic/updates/dkms/                                                                 0.0s
 => CACHED [builder 2/7] RUN apt-get update && apt-get install -y bc     bison     flex     libelf-dev     gnupg     wget     git     make     gcc     0.0s
 => CACHED [builder 3/7] RUN mkdir --parents --mode=0755 /etc/apt/keyrings                                                                             0.0s
 => CACHED [builder 4/7] RUN if [ -n "${GPG_KEY_URL}" ]; then         wget ${GPG_KEY_URL} -O - | gpg --dearmor | tee /etc/apt/keyrings/rocm.gpg > /de  0.0s
 => CACHED [builder 5/7] RUN if [ -n "${PACKAGE_REPO_URL}" ]; then         echo "deb [arch=amd64 signed-by=/etc/apt/keyrings/rocm.gpg] ${PACKAGE_REPO  0.0s
 => CACHED [builder 6/7] RUN apt-get update && apt-get install -y amdgpu-dkms                                                                          0.0s
 => CACHED [builder 7/7] RUN depmod 6.8.0-139-generic                                                                                                  0.0s
 => CACHED [stage-1 4/8] COPY --from=builder /lib/modules/6.8.0-139-generic/updates/dkms/amd* /opt/lib/modules/6.8.0-139-generic/updates/dkms/         0.0s
 => CACHED [stage-1 5/8] COPY --from=builder /lib/modules/6.8.0-139-generic/modules.* /opt/lib/modules/6.8.0-139-generic/                              0.0s
 => CACHED [stage-1 6/8] COPY --from=builder /lib/modules/6.8.0-139-generic/kernel /opt/lib/modules/6.8.0-139-generic/kernel                           0.0s
 => CACHED [stage-1 7/8] RUN mkdir -p /firmwareDir/updates/amdgpu                                                                                      0.0s
 => CACHED [stage-1 8/8] COPY --from=builder /lib/firmware/updates/amdgpu /firmwareDir/updates/amdgpu                                                  0.0s
 => exporting to image                                                                                                                                 0.0s
 => => exporting layers                                                                                                                                0.0s
 => => writing image sha256:47b255a15c3ca7e98234a217c8afbc29ec6a2ffdf109041bffd6843a6ce47ec7                                                           0.0s
 => => naming to docker.io/dlipovetsky/amdgpu:ubuntu-24.04-6.8.0-139-generic-31.40.1                                                                   0.0s

 2 warnings found (use docker --debug to expand):
 - FromAsCasing: 'as' and 'FROM' keywords' casing do not match (line 1)
 - SecretsUsedInArgOrEnv: Do not use ARG or ENV instructions for sensitive data (ARG "GPG_KEY_URL") (line 11)

Note that the default output is shell script that embeds the Dockerfile, and executes a docker build command. This is needed in order to guarantee the right image tag is used, since the tag cannot be defined by the Dockerfile itself. If the wrong image tag is used, the operator will not find the image.

The CLI can emit shell scripts for docker, podman, or buildah. The CLI can also output just the Dockerfile, and leave the rest to the user. See the -format flag.

The user can specify the drivers version, kernel version, as well as other inputs. The CLI assigns the values as defaults to the build args in the Dockerfile, so that the user does not need to set build args.

Technical Details

The CLI uses the same functions as the operator uses in the cluster to derive the Dockerfile. The API surface is very small: it imports internal/kmmodule and calls GetOSName, GetCMName. It also calls the NewKMMModule constructor, and then SetBuildConfigMapAsDesired to derive the Dockerfile.

Test Plan

I have added unit tests that exercise creation of the output. They are not exhaustive, but I will expand them, if the project is interested in merging this PR.

Test Result

The CLI defines its own unit tests, which are passing. The CLI is separate from the operator.

Submission Checklist

@dlipovetsky

Copy link
Copy Markdown
Author

I first asked about a CLI for this purpose in this discussion: #641

@dlipovetsky
dlipovetsky marked this pull request as ready for review September 24, 2026 21:03

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant