nextflow-io / nextflow-io/nextflow

Capture and elevate cloud executor injected metadata, specifically the Docker image digest

Open
#6,923 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

stale
Dominant language
Groovy
Stars
3.5k
Forks
811
Avg merge
2d 11h
Merged PRs (30d)
61

Description

New feature

Hi, we're using Nextflow on AWS Batch.

We find all our tasks have this environmental variable injected ECS_CONTAINER_METADATA_URI_V4, that contains an HTTP+JSON endpoint to GET useful metadata from:
https://docs.aws.amazon.com/AmazonECS/latest/developerguide/task-metadata-endpoint-v4.html

And we can then call the endpoint and get a json of really handy metadata:
curl -sS --fail --connect-timeout 5 --max-time 10 "\$ECS_CONTAINER_METADATA_URI_V4" > ecs_metadata.json || true ## variable is an endpoint injected into all AWS Batch jobs that run on ECS-backed compute environments

Most importantly is the ImageID (i.e. content based digest) of the Docker container that is running, that I haven't seen accessible anywhere else in Nextflow
cat ecs_metadata.json | jq '.ImageID' "sha256:47d74d2f1d360a3167ea062129a4af229af095ef0fd23b842f62647e3ad29c6c"

The new feature would be to bake in fetching and parsing this metadata as appropriate for Nextflow cloud executors like AWS Batch.

Use case

Whenever you're running Docker containers on the cloud, and you want traceability as to the source container. (Other metadata presumably useful as well, but this is our use case with ImageID).

Suggested implementation

For each cloud executor, research if they have a similar pattern to this AWS Batch pattern, and then make a bespoke before script execution. Then injest it and make it available via trace.csv , report.html, etc.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by examining the AWS Batch cloud executor and the existing paths that populate trace.csv and report.html. Use the AWS ECS task metadata endpoint as the reference, then compare metadata mechanisms for other cloud executors. Done means the container image digest is fetched, parsed, and exposed in the requested reporting outputs with an agreed scope for supported executors.

Written by the indexing model from the issue text.

Assessment

Tech stack
aws, docker, groovy
Domain
cloud, devops
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.