third_party/linux: improve kernel configuration

These configuration changes are required to boot the Metropolis kernel
via kexec on a PowerEdge R750.

kexec needs to be enabled even if we're not using it as just using kexec
to launch a kernel on an EFI machine requires a fixup performed only if
the target kernel is built with kexec enabled. Otherwise it crashes
immediately after mounting efivars by dereferencing a null pointer.

bpfilter should be disabled because it needs a userspace helper (the
.ko actually runs in userspacee) and we ship none of that, causing an
error-level log message on every boot.
Until we actually ship the required infrastructure disable it.

irq_remap is required for x2apic, without it
the kernel can't even boot on that platform.

intel_iommu is just a drive-by enable because the AMD IOMMU is already
enabled and we want the protection.

Change-Id: Iaf0012e8c0427114c56fc5d90a9748ebeb800a54
Reviewed-on: https://review.monogon.dev/c/monogon/+/904
Tested-by: Jenkins CI
Reviewed-by: Sergiusz Bazanski <serge@monogon.tech>
1 file changed
tree: 195657113c01909686a9de30aa36d1ebc5014353
  1. .github/
  2. build/
  3. intellij/
  4. metropolis/
  5. scripts/
  6. third_party/
  7. .bazelignore
  8. .bazelproject
  9. .bazelrc
  10. .git-ignore-revs
  11. .gitignore
  12. BUILD
  13. CODING_STANDARDS.md
  14. go.mod
  15. go.sum
  16. LICENSE
  17. README.md
  18. WORKSPACE
README.md

Monogon Monorepo

This is the main repository containing the source code for the Monogon Project.

This is pre-release software - feel free to look around, and check back later for our first release!

Environment

Our build environment requires a working Podman binary (your distribution should have one).

Usage

Spinning up: scripts/create_container.sh

Spinning down: scripts/destroy_container.sh

Running commands: scripts/run_in_container.sh <...>

Using bazel using a wrapper script: scripts/bin/bazel <...> (add to your local $PATH for convenience)

IntelliJ

This repository is compatible with the IntelliJ Bazel plugin, which enables full autocompletion for external dependencies and generated code. All commands run inside the container, and necessary paths are mapped into the container.

The following steps are necessary:

  • Install Google's Bazel plugin in IntelliJ. On IntelliJ 2020.3 or later, you need to install a beta release of the plugin.

  • Add the absolute path to your ~/.cache/bazel-monogon folder to your idea64.vmoptions (Help → Edit Custom VM Options) and restart IntelliJ:

    -Dbazel.bep.path=/home/leopold/.cache/bazel-monogon

  • Set "Bazel Binary Location" in Other Settings → Bazel Settings to the absolute path of scripts/bin/bazel. This is a wrapper that will execute Bazel inside the container.

  • Use File → Import Bazel project... to create a new project from .bazelproject.

After running the first sync, everything should now resolve in the IDE, including generated code.

Metropolis

Run a single node cluster

Launch the node:

scripts/bin/bazel run //:launch -c dbg

Run a kubectl command:

scripts/bin/bazel run //metropolis/cli/dbg -c dbg -- kubectl describe

Run tests:

scripts/bin/bazel test -c dbg //...