Files
esh-pfi-infrastructure/docs/fleettools/blender.md
T
vh 83dc497b40 feat(blender): pinned extension set in a read-only System repo, for the GUI and blender-run --extensions
Blender is now a mandatory stage in draupnir's pipeline (Prime, 2026-09-28), and draupnir asked
for eight add-ons from extensions.blender.org: SurfacePsycho 0.10.4, CAD Sketcher 0.32.1,
3D-Print Toolbox 1.4.1, STEP Importer 1.2.1, Bool Tool 2.1.0, LoopTools 4.7.7, MeasureIt 1.8.4,
3MF Import/Export 2.7.7.

- stacks/blender/extensions.lock pins each by version and archive sha256.
- scripts/blender-extensions sync builds fv-ml1:/tank/blender-extensions/5.2/system with Blender's
  own install-file, pre-warms and byte-compiles it, checks a read-only enable, then swaps it in.
  It refuses while the GUI or a blender-run job holds the old directory.
- conf/scripts/startup/fleet_extensions.py enables every package in the System repo: in a timer
  in the GUI (after the prefs load), and as --python ahead of the caller's args in
  blender-run --extensions (a failed enable exits 1 before the caller's script).
- It also patches SurfacePsycho's sp_overwrite_segment_selection from eval() to literal_eval():
  the eval walked past MCP safe mode (control: unpatched ran code, patched refuses).
- blender-run: --extensions (bind mounts via --mount so a missing source fails instead of being
  created); USER/LOGNAME set, which CAD Sketcher's getpass needs.
- compose.yaml mounts the repo read-only and the hook into the GUI container. NOT yet deployed.
- scripts/blender-probes/extensions_acceptance.py: one operator run per add-on, safe-mode
  compliant. Headless 8/9 online and with --network none; CAD Sketcher sketching is GUI-only.
  A Python audit hook saw no network/process events (positive control fired).
2026-09-28 12:50:57 -07:00

72 lines
4.4 KiB
Markdown

# Blender: headless and agent-driven 3D on fv-ml1 GPU 3
**Blender 5.2.2 LTS** (bundled Python 3.13), runs on **fv-ml1 GPU 3** (RTX PRO 6000 Blackwell,
96 GB). Stack and full notes: `/home/lkraven/development/eshpfi-management/stacks/blender/README.md`.
⚠ **GPU 3 is borrowed.** It is the fleet's reserve card for a full-size vLLM seat. Blender
runs only while in use, and this access ends if a big seat moves onto the card.
## Two ways in
| You are… | Use | Shape |
|---|---|---|
| a script or CLI caller (renders, conversions) | `scripts/blender-run` | one-shot `docker run --rm`: no desktop, gone when Blender exits |
| an agent building scenes interactively | `scripts/blender-mcp` (MCP, per task) | a GUI Blender plus the mcp-for-blender add-on; `up` / `status` / `down` |
Both scripts are in `/home/lkraven/development/eshpfi-management/scripts/` and run from nh3-dev,
reaching fv-ml1 as `infra-ops@10.251.50.54` over ssh. **No HTTP API** and no openapi.json.
## blender-run (headless)
```sh
scripts/blender-run --job /path/to/jobdir -- --python render.py -- out.png
scripts/blender-run --extensions --job /path/to/jobdir -- --python model.py
scripts/blender-run -- --python-expr 'import bpy; print(bpy.app.version_string)'
```
- Always adds `-b --factory-startup --python-exit-code 1`. Arguments go after `--`.
- **Files:** fv-ml1 does not mount `/mnt/smithy`. `--job DIR` mirrors DIR to
`fv-ml1:/tank/blender/jobs/<basename>-<hash of DIR's absolute path>/`, runs with that as
the working directory, and copies new or changed files back into DIR. Nothing is ever
deleted locally, and a rerun starts from an exact mirror, never from leftovers. Use
relative input paths inside the job. Do not run the same DIR twice at once.
- **Engines headless (tested 2026-09-28):** Cycles on GPU (OptiX/CUDA), Cycles on CPU, EEVEE
(EGL, no display needed, ~9 s with the shader compile on first use), Workbench. In 5.2 the
EEVEE id is `BLENDER_EEVEE` (`BLENDER_EEVEE_NEXT` is gone). For Cycles GPU, set
`prefs.compute_device_type = 'OPTIX'` and enable the OPTIX devices, then
`scene.cycles.device = 'GPU'`. Factory startup defaults to CPU.
- **Import:** STL is built in (`bpy.ops.wm.stl_import`). STEP, 3MF and the other add-ons need
`--extensions` (below).
- **`--extensions`** enables the pinned add-on set: SurfacePsycho 0.10.4 (NURBS patches, STEP/IGES
export via its bundled OCP), CAD Sketcher 0.32.1, 3D-Print Toolbox 1.4.1, STEP Importer 1.2.1,
Bool Tool 2.1.0, LoopTools 4.7.7, MeasureIt 1.8.4, 3MF Import/Export 2.7.7. Pins:
`stacks/blender/extensions.lock`. If any add-on fails to enable, the run exits 1 before your
script starts. It adds a few seconds of startup (the add-on wheels unpack per run), so it is
off by default. **CAD Sketcher's sketch operators need the GUI** (they activate a workspace
tool); headless they fail with "'NoneType' object has no attribute 'widget'". Operators that
want a 3D View (MeasureIt, LoopTools) take a `bpy.context.temp_override(area=...)` with a
screen datablock's VIEW_3D area. Worked calls for every add-on:
`scripts/blender-probes/extensions_acceptance.py`. Full notes and foot-guns: the stack README,
section "Extensions".
- **Budget:** each run is capped at 64 GB RAM and 48 CPUs, with up to the whole 96 GB of VRAM.
Keep to about 2 concurrent renders. It is not on irv-ml1, so irv-ml1's working-set budget
does not apply.
⚠ **Foot-guns** (all measured):
- A `--python` script that raises exits **0** unless `--python-exit-code` is set. blender-run
sets it.
- `render.filepath` must be **absolute**. Blender does not resolve a relative output path
against the working directory ("cannot save 'out.png'"). Importers and Python file I/O do.
- Harmless stderr noise: "HIPEW initialization failed" (the AMD backend probing), and "Failed to
create secure directory (/defaults): Operation not permitted" (the image's runtime-dir setup
running as a non-root user; reported by draupnir 2026-09-28).
- The first OptiX render in a process includes about 1-2 s of kernel load.
## blender-mcp (agents)
Register it **per task**, never user- or project-wide (Prime, 2026-09-27):
`claude mcp add blender -- /home/lkraven/development/eshpfi-management/scripts/blender-mcp`.
Then run `scripts/blender-mcp up`, wait for `status` to say answering, work, and run `down`
when finished. Safe mode is on (no os/open/network in agent code), so the startup hook has
already pointed Cycles at OptiX. Save to `/work/…`. Details and traps are in the stack README.