Files
esh-pfi-infrastructure/stacks/blender/compose.yaml
T
vh 7ae7193c21 feat(blender): Blender 5.2.2 LTS on fv-ml1 GPU 3, on demand (Prime)
Uses linuxserver/blender (Selkies Wayland desktop, NVENC), digest-pinned. The
container sees only GPU 3, has restart "no", and runs only while in use,
because GPU 3 is the reserve card for a full-size vLLM seat. Web desktop on
:3001 with basic auth (vault fv-ml1/blender-web-password). /work is on /tank
and is not backed up; /config lives under /opt/docker (restic).

Acceptance: Cycles finds the card on OptiX and CUDA (sm_120 kernels ship in the
build). The heavy self-test renders in 3.54 s on OptiX vs 22.71 s on CPU, a
functional check with n=1. Web auth answers 401 without credentials and with a
wrong password, and 200 with the right one.
2026-09-27 13:57:35 -07:00

51 lines
2.3 KiB
YAML

# blender: Blender 5.2 LTS on fv-ml1 GPU 3, driven by agents (MCP) with a browser desktop for
# watching. Prime, 2026-09-27: "go ahead with gpu 3, both".
#
# ⚠ ON DEMAND ONLY. GPU 3 is the fleet's deliberately empty card, the reserve for a full-size
# vLLM seat (flash-next needs 93 of 96 GiB, and vLLM sizes KV against TOTAL VRAM). Blender
# borrows it: `restart: "no"`, so a reboot never brings it back, and it is stopped whenever a big
# seat needs the card. Start: `docker compose up -d`. Stop: `docker compose down`.
#
# Image: linuxserver/blender (Selkies web desktop, official Blender build with sm_120 CUDA +
# OptiX kernels). Its NVIDIA mode needs host driver >= 580 (fv-ml1: 580.65.06) and
# /dev/nvidia-modeset. HTTPS only (Selkies' WebCodecs need a secure context), self-signed cert.
# Basic auth from .env (CUSTOM_USER / PASSWORD; vault fv-ml1/blender-web). The desktop grants
# a shell inside the container, so never expose it beyond the LAN.
#
# Paths: /config (home: prefs, add-ons) → /opt/docker/data/blender (restic via /opt/docker).
# /work (projects, assets, renders) → /tank/blender (big, NOT backed up; renders are
# regenerable, and anything precious is copied out).
#
# .env (tunables): IMAGE, HTTPS_PORT, CUSTOM_USER, PASSWORD.
name: blender
services:
blender:
image: ${IMAGE:?set IMAGE}
container_name: blender
restart: "no"
runtime: nvidia
environment:
PUID: "1002" # infra-ops, so agents can read and write /work over ssh
PGID: "1003"
TZ: America/Los_Angeles
CUSTOM_USER: ${CUSTOM_USER:?set CUSTOM_USER}
PASSWORD: ${PASSWORD:?set PASSWORD}
NVIDIA_VISIBLE_DEVICES: "3" # GPU 3 only: never touch the serving cards
NVIDIA_DRIVER_CAPABILITIES: all # compute (Cycles), graphics (viewport), video (NVENC stream)
devices:
- /dev/nvidia-modeset:/dev/nvidia-modeset
volumes:
- /opt/docker/data/blender:/config
- /tank/blender:/work
ports:
- "${HTTPS_PORT:-3001}:3001"
shm_size: "1gb"
labels:
- homepage.group=AI - Studios
- homepage.name=Blender
- homepage.icon=si-blender
- homepage.description=Blender 5.2 on fv-ml1 GPU 3 (on demand)
- homepage.href=https://10.251.50.54:${HTTPS_PORT:-3001}