Blender is now a mandatory stage in draupnir's pipeline (Prime, 2026-09-28), and draupnir asked for eight add-ons from extensions.blender.org: SurfacePsycho 0.10.4, CAD Sketcher 0.32.1, 3D-Print Toolbox 1.4.1, STEP Importer 1.2.1, Bool Tool 2.1.0, LoopTools 4.7.7, MeasureIt 1.8.4, 3MF Import/Export 2.7.7. - stacks/blender/extensions.lock pins each by version and archive sha256. - scripts/blender-extensions sync builds fv-ml1:/tank/blender-extensions/5.2/system with Blender's own install-file, pre-warms and byte-compiles it, checks a read-only enable, then swaps it in. It refuses while the GUI or a blender-run job holds the old directory. - conf/scripts/startup/fleet_extensions.py enables every package in the System repo: in a timer in the GUI (after the prefs load), and as --python ahead of the caller's args in blender-run --extensions (a failed enable exits 1 before the caller's script). - It also patches SurfacePsycho's sp_overwrite_segment_selection from eval() to literal_eval(): the eval walked past MCP safe mode (control: unpatched ran code, patched refuses). - blender-run: --extensions (bind mounts via --mount so a missing source fails instead of being created); USER/LOGNAME set, which CAD Sketcher's getpass needs. - compose.yaml mounts the repo read-only and the hook into the GUI container. NOT yet deployed. - scripts/blender-probes/extensions_acceptance.py: one operator run per add-on, safe-mode compliant. Headless 8/9 online and with --network none; CAD Sketcher sketching is GUI-only. A Python audit hook saw no network/process events (positive control fired).
64 lines
3.5 KiB
YAML
64 lines
3.5 KiB
YAML
# blender: Blender 5.2 LTS on fv-ml1 GPU 3, driven by agents (MCP) with a browser desktop for
|
|
# watching. Prime, 2026-09-27: "go ahead with gpu 3, both".
|
|
#
|
|
# ⚠ ON DEMAND ONLY. GPU 3 is the fleet's deliberately empty card, the reserve for a full-size
|
|
# vLLM seat (flash-next needs 93 of 96 GiB, and vLLM sizes KV against TOTAL VRAM). Blender
|
|
# borrows it: `restart: "no"`, so a reboot never brings it back, and it is stopped whenever a big
|
|
# seat needs the card. Start: `docker compose up -d`. Stop: `docker compose down`.
|
|
#
|
|
# Image: linuxserver/blender (Selkies web desktop, official Blender build with sm_120 CUDA +
|
|
# OptiX kernels). Its NVIDIA mode needs host driver >= 580 (fv-ml1: 580.65.06) and
|
|
# /dev/nvidia-modeset. HTTPS only (Selkies' WebCodecs need a secure context), self-signed cert.
|
|
# Basic auth from .env (CUSTOM_USER / PASSWORD; vault fv-ml1/blender-web-password). The desktop grants
|
|
# a shell inside the container, so never expose it beyond the LAN.
|
|
#
|
|
# Paths: /config (home: prefs, add-ons) → /opt/docker/data/blender (restic via /opt/docker).
|
|
# /work (projects, assets, renders) → /tank/blender (big, NOT backed up; renders are
|
|
# regenerable, and anything precious is copied out).
|
|
#
|
|
# .env (tunables): IMAGE, HTTPS_PORT, CUSTOM_USER, PASSWORD.
|
|
|
|
name: blender
|
|
|
|
services:
|
|
blender:
|
|
image: ${IMAGE:?set IMAGE}
|
|
container_name: blender
|
|
restart: "no"
|
|
runtime: nvidia
|
|
environment:
|
|
PUID: "1002" # infra-ops, so agents can read and write /work over ssh
|
|
PGID: "1003"
|
|
TZ: America/Los_Angeles
|
|
CUSTOM_USER: ${CUSTOM_USER:?set CUSTOM_USER}
|
|
PASSWORD: ${PASSWORD:?set PASSWORD}
|
|
NVIDIA_VISIBLE_DEVICES: "3" # GPU 3 only: never touch the serving cards
|
|
NVIDIA_DRIVER_CAPABILITIES: all # compute (Cycles), graphics (viewport), video (NVENC stream)
|
|
devices:
|
|
- /dev/nvidia-modeset:/dev/nvidia-modeset
|
|
volumes:
|
|
- /opt/docker/data/blender:/config
|
|
- /tank/blender:/work
|
|
# MCP bridge (stacks/blender/conf → /opt/docker/conf/blender): the pinned add-on, plus a
|
|
# startup hook that enables it and keeps its socket serving. Read-only; update via the repo.
|
|
- /opt/docker/conf/blender/scripts/addons/blender_mcp.py:/config/.config/blender/5.2/scripts/addons/blender_mcp.py:ro
|
|
- /opt/docker/conf/blender/scripts/startup/fleet_mcp.py:/config/.config/blender/5.2/scripts/startup/fleet_mcp.py:ro
|
|
# Pinned extensions (stacks/blender/extensions.lock, built by scripts/blender-extensions sync)
|
|
# as Blender's System repository, READ-ONLY: agents cannot install or alter add-ons. The
|
|
# startup hook enables every package in it once the prefs have loaded. README "Extensions".
|
|
- /tank/blender-extensions/5.2/system:/blender/5.2/extensions/system:ro
|
|
- /opt/docker/conf/blender/scripts/startup/fleet_extensions.py:/config/.config/blender/5.2/scripts/startup/fleet_extensions.py:ro
|
|
ports:
|
|
- "${HTTPS_PORT:-3001}:3001"
|
|
# ⚠ NO port for the MCP add-on socket (it runs arbitrary Python, no auth). It listens on the
|
|
# container's own localhost. The MCP server runs INSIDE this container
|
|
# (/work/.mcp-venv), and agents reach it as `ssh … docker exec -i` stdio
|
|
# (scripts/blender-mcp). Never publish 9876.
|
|
shm_size: "1gb"
|
|
labels:
|
|
- homepage.group=AI - Studios
|
|
- homepage.name=Blender
|
|
- homepage.icon=si-blender
|
|
- homepage.description=Blender 5.2 on fv-ml1 GPU 3 (on demand)
|
|
- homepage.href=https://10.251.50.54:${HTTPS_PORT:-3001}
|