#!/usr/bin/env bash # blender-run — one-shot HEADLESS Blender on fv-ml1 GPU 3, for scripted/CLI callers (draupnir etc.). # The agent-driven, interactive path is scripts/blender-mcp; this is the batch path. # # scripts/blender-run [--job DIR] [--extensions] [--cpu] -- # scripts/blender-run --job /mnt/smithy/draupnir/j42 -- --python render.py -- --out out.png # scripts/blender-run --extensions -- --python-expr 'import bpy; print(bpy.app.version_string)' # # Each call is its own `docker run --rm` of the stacks/blender image (Blender 5.2.2 LTS, Python # 3.13): no desktop, no MCP socket, gone when Blender exits. So it never collides with the on-demand # GUI container, and GPU 3 goes back to 0 when the render ends. Always added: `-b --factory-startup # --python-exit-code 1`. Without that last flag, Blender exits 0 even when a --python script raises # (measured). # # ⚠ Give render.filepath an ABSOLUTE path (os.path.abspath). Blender does not resolve a relative # output path against the working directory: "cannot save 'out.png'". Python file I/O and # importers do use the cwd. # # --extensions: also enable the pinned add-on set (stacks/blender/extensions.lock: SurfacePsycho, # CAD Sketcher, 3D-Print Toolbox, STEP Importer, Bool Tool, LoopTools, MeasureIt, 3MF). It mounts # /tank/blender-extensions/5.2/system read-only as Blender's System repository and runs # fleet_extensions.py ahead of your arguments. If any add-on fails to enable, the run exits 1 # before your script starts. Off by default, so a plain render stays factory-clean. # # Files: fv-ml1 does NOT mount /mnt/smithy. With --job DIR, DIR is mirrored to # fv-ml1:/tank/blender/jobs/-/, Blender runs WITH THAT AS ITS # WORKING DIRECTORY, and new or changed files are copied back into DIR afterwards (nothing is ever # deleted locally). Use relative paths inside the job. Running the SAME DIR twice concurrently # still shares one remote dir, so don't do that. Remote job dirs are never swept: one copy is kept # per distinct DIR (small files, on /tank). Without --job, the only paths Blender sees are under # /work (= fv-ml1:/tank/blender). # # --cpu: no GPU attached at all (no nvidia runtime), so the run never touches GPU 3. For modelling, # add-on work, import/export and Cycles on CPU (the 2026-09-28 extension acceptance ran this way). # EEVEE and Workbench render through EGL on the GPU and are expected to fail here (untested). It is # also the shape of the fallback if GPU 3 goes back to vLLM. Asked for by draupnir, whose design # stage never renders (2026-09-28). # # The container's hostname is fixed as fv-ml1-blender, so socket.gethostname() is stable across # runs (callers record it as provenance; draupnir, 2026-09-28). Without it, it is the container id. # # Budget: GPU 3 (96 GB, borrowed from the vLLM reserve: this ends if a full-size seat moves in). # The container is capped at 64 GB RAM / 48 CPUs so a runaway render cannot starve the inference # seats on the same host. set -euo pipefail HOST=${BLENDER_SSH_HOST:-infra-ops@10.251.50.54} ENV_FILE=/opt/docker/compose/blender/.env JOB="" EXT="" GPU="--runtime nvidia -e NVIDIA_VISIBLE_DEVICES=3 -e NVIDIA_DRIVER_CAPABILITIES=all" while [ $# -gt 0 ]; do case "$1" in --job) JOB=${2:?--job needs a directory}; shift 2 ;; --extensions) # --mount, not -v: a missing source is an error, where -v would silently create it as an # empty root-owned DIRECTORY on fv-ml1 (and a directory where the hook file belongs). EXT="--mount type=bind,src=/tank/blender-extensions/5.2/system,dst=/blender/5.2/extensions/system,readonly \ --mount type=bind,src=/opt/docker/conf/blender/scripts/startup/fleet_extensions.py,dst=/fleet/fleet_extensions.py,readonly" shift ;; --cpu) GPU=""; shift ;; --) shift; break ;; -h|--help) sed -n 2,43p "$0"; exit 0 ;; *) echo "blender-run: unknown option $1 (blender args go after --)" >&2; exit 2 ;; esac done WORKDIR=/work if [ -n "$JOB" ]; then [ -d "$JOB" ] || { echo "blender-run: --job $JOB is not a directory" >&2; exit 2; } ABS=$(realpath "$JOB") BASE=$(basename "$ABS") [[ $BASE =~ ^[A-Za-z0-9._-]+$ ]] || { echo "blender-run: job dir name '$BASE' must be [A-Za-z0-9._-]" >&2; exit 2; } # Keyed on basename + a hash of the ABSOLUTE local path (draupnir, 2026-09-28): two different # dirs that share a basename no longer share a remote dir. `--delete` makes the remote an exact # mirror of DIR, so a rerun never inherits an earlier run's leftovers. rsync removes only # inside that one remote dir; there is no rm on a computed path. NAME=$BASE-$(printf '%s' "$ABS" | sha256sum | cut -c1-8) ssh -n -o BatchMode=yes "$HOST" "mkdir -p /tank/blender/jobs/$NAME" rsync -a --delete "$JOB"/ "$HOST:/tank/blender/jobs/$NAME/" WORKDIR=/work/jobs/$NAME fi # Arguments travel as one shell-quoted string: ssh flattens argv into a remote command line. ARGS=$(printf '%q ' "$@") PRE="" [ -n "$EXT" ] && PRE="--python /fleet/fleet_extensions.py" set +e ssh -n -o BatchMode=yes "$HOST" "IMG=\$(grep '^IMAGE=' $ENV_FILE | cut -d= -f2) && \ exec docker run --rm --name blender-run-\$\$ --hostname fv-ml1-blender $GPU \ --user 1002:1003 -e HOME=/tmp -e USER=infra-ops -e LOGNAME=infra-ops --memory 64g --cpus 48 \ -v /tank/blender:/work $EXT -w $WORKDIR --entrypoint /blender/blender \"\$IMG\" \ -b --factory-startup --python-exit-code 1 $PRE $ARGS" RC=$? set -e if [ -n "$JOB" ]; then rsync -a --update "$HOST:/tank/blender/jobs/$NAME/" "$JOB"/ fi exit $RC