igneum/infra/build-server/README.md
igneum-labs b6e5dffa32 Build boxes: one host file per box and a route by class (suites and benches to build-2, proving to build-3, the rest to build-1); the no-mining rule in a box README and as a guard in the capacity layer
Main's order of 7 October 2026 (igneum-build-2, AX162-1, and igneum-build-3, AX102-1, on order). lib.sh: bs_box_file N and
bs_route <class>; a class whose box has no host file yet falls back to box 1 and says so. run-from-mac.sh --box N <ip> provisions
igneum-build-N and writes build-server-N. tools/build-remote.sh --box N overrides the route; --priority gate always runs on box 1;
the proving crate routes to box 3. README.md: the kind map and the project lead's rule, no mining on any Hetzner box, ever (nodes, builds, tests,
benchmarks and CPU proving only; the pool's fast-time network mines on rented GPU pods, never on build-3). capacity/run.sh refuses a
job that would start igneum-miner mine or a GPU worker, whatever SEQUENCE says.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-07 10:34:16 +00:00

3 KiB

The build boxes (infra/build-server)

Three Hetzner dedicated servers in Falkenstein run everything the Mac must not: builds, test suites, benchmarks, CPU proving, the devnet hands and the observer. The Mac keeps macOS binaries, the DMG and Metal tests (CLAUDE.md, "Running agents on this Mac").

No mining on any Hetzner box, ever

the project lead's rule through main, 7 October 2026: Hetzner's policies forbid crypto mining. The boxes run nodes, builds, tests, benchmarks and CPU proving only. The pool's fast-time network runs its miners on rented GPU pods (tools/fleet), never on a box; a box may run the network's nodes. The capacity layer refuses a job that would start igneum-miner mine or a GPU worker (capacity/run.sh), and no hands unit carries a miner. A node started with --enable-unsynced-mining is a node flag, not a miner; nothing feeds it blocks here.

The boxes and the kind map

Box Host file on the Mac Takes Never
igneum-build-1 (188.40.146.49, AX162-1-LTD) ~/.config/igneum/build-server release gates (--priority gate), builds and cross-builds, checks, the GPU workers' host side, the devnet hands (node 1, the observer node, the observer), the Devnet 2 seed, the CI runner, the dashboard feed suites and benches once box 2 exists
igneum-build-2 (AX162-1, on order) ~/.config/igneum/build-server-2 suites (cargo test), benches (cargo bench), the attack rows (--box 2) gates, hands
igneum-build-3 (AX102-1, on order) ~/.config/igneum/build-server-3 proving and aggregation CPU work (proving/igneum-prove builds and suites), the second prover's shadow runner, the pool's fast-time NETWORK (nodes only, --box 3) miners of any kind

tools/build-remote.sh routes by class (lib.sh bs_route): suite and bench to box 2, the proving crate to box 3, everything else to box 1; --box N overrides; a class whose box has no host file yet falls back to box 1 and says so. --priority gate always runs on box 1. Each box has its own mirrors, slots, locks and JSONL log under /srv; run-from-mac.sh --box N <ip> provisions a box and writes its host file; the dashboard collector reads every box it is told about.

Files

File What
provision.sh the box itself: install mode (rescue system, Ubuntu 24.04, RAID 1, no swap) and provision mode (user build, toolchains, the pin, sccache, zig, CUDA headers, docker, Caddy, mirrors, slots, sshd, ufw)
run-from-mac.sh ships provision.sh, writes the host file, wires the build remotes and pushes every branch
lib.sh, remote-run.sh the Mac and box halves of a remote run: sync, checkout, slots, scheduling classes, the JSONL line
hands/ the devnet hands' units, the mover and the restart read-backs
capacity/ the capacity layer (the box-work lane's): background jobs under the build slots, never a miner
repro/, night/, prover/, runner/, workers/ other lanes' pieces that live on the boxes

Plan, numbers and the gotchas: docs/plans/build-server.md; the hands: docs/plans/hands-on-build-1.md.