288b1546b2
* feat: broaden CPU and platform coverage across PyPI, nodes, and crates.io Replace static SIMD with runtime CPU-feature dispatch and expand the release wheel matrix so one set of artifacts runs on any target CPU and platform without illegal-instruction crashes. Rust core: - Add multiversion runtime dispatch (crates/ferro_ta_core/src/simd.rs); drop compile-time `wide`. `simd` feature is now default-on and forwarded through the pyo3 crate, and stays compatible with #![forbid(unsafe_code)]. Packaging: - abi3-py310: one cp310-abi3 wheel per platform (covers CPython 3.10+). - CI matrix adds Linux aarch64 + musllinux (x86_64/aarch64) and Windows arm64. Node/Docker + docs: - api/Dockerfile: document baseline+dispatch (no target-cpu pin) and add a fail-fast import check; aarch64 containers now install cleanly. - Rewrite docs/guides/simd.md; fix stale `wide` mention in ADR 0003. - Add ADR 0006 (CPU coverage strategy). Also bundles in-flight release prep already staged in the tree (DTW exception types, SBOM/provenance security, supporting docs). * fix(ci): clear cargo-deny and pip-audit failures; apply dependency bumps cargo-deny (advisories): - Ignore pyo3 RUSTSEC-2026-0176 / RUSTSEC-2026-0177 in deny.toml with a documented rationale: ferro-ta uses neither affected code path (PyList/PyTuple nth iterators; PyCFunction::new_closure). Upstream fix needs pyo3 >=0.29 (large API migration), tracked as a follow-up. pip-audit: - Bump dev lockfile idna 3.18, pytest 9.1.1, urllib3 2.7.0 to clear PYSEC-2026-215, CVE-2025-71176, PYSEC-2026-141/142. Dependency bumps (supersede open dependabot PRs; they auto-close on merge): - cargo: log 0.4.32, serde_json 1.0.150, rayon 1.12.0 - api/requirements.txt: uvicorn>=0.49.0, pydantic>=2.13.4, ferro-ta>=1.1.4 - CI actions: deploy-pages v5, upload-pages-artifact v5, action-gh-release v3 The open `wide` 1.5.0 bump (PR #24) is obsolete — the crate is removed in this branch. * chore: address CodeRabbit review; remove docs/adr section CodeRabbit findings: - CI sbom job: add `attestations: write` so attest-build-provenance can run (it had only contents:write + id-token:write). - simd.rs: vectorize `wma_seed` with lane-local accumulators — it was scalar behind the multiversion wrapper, adding dispatch overhead for no SIMD gain. - CHANGELOG: consolidate the duplicate `### Changed` heading. - python/ferro_ta/__init__.py: also re-export the `FerroTaError` alias. - docs/guides/dtw.md: soften "byte-for-byte" parity to within-tolerance. Remove docs/adr/ at maintainer request and clean up the ADR links in the SIMD and DTW guides. The ADR files remain in commit 9506a30 if ever needed.
51 lines
1.9 KiB
Docker
51 lines
1.9 KiB
Docker
# ferro-ta API — Docker image
|
|
#
|
|
# Build:
|
|
# docker build -t ferro-ta-api .
|
|
#
|
|
# Run:
|
|
# docker run -p 8000:8000 ferro-ta-api
|
|
#
|
|
# Environment variables (override at runtime):
|
|
# MAX_SERIES_LENGTH=100000 # maximum data-point count per request
|
|
#
|
|
# CPU portability
|
|
# ---------------
|
|
# This image installs the PRE-BUILT ferro-ta wheel from PyPI — we do NOT
|
|
# recompile from sdist with `RUSTFLAGS=-C target-cpu=...`. The wheel is built
|
|
# at the manylinux baseline (x86-64-v1) and selects AVX2/AVX-512/NEON kernels
|
|
# at RUNTIME via CPU dispatch. One image therefore runs on any node — old or
|
|
# new CPU, x86_64 or arm64 — with no illegal-instruction (SIGILL) crashes.
|
|
# Pinning a target-cpu would be faster on a uniform fleet but would crash on
|
|
# any older/heterogeneous node, which is the opposite of broad coverage.
|
|
#
|
|
# Build this image for whichever arch your nodes use:
|
|
# docker build --platform linux/amd64 -t ferro-ta-api .
|
|
# docker build --platform linux/arm64 -t ferro-ta-api . # Graviton/Ampere
|
|
# Both resolve a matching manylinux wheel — no Rust toolchain needed here.
|
|
|
|
FROM python:3.11-slim
|
|
|
|
WORKDIR /app
|
|
|
|
# Copy and install dependencies first (cache layer). No compiler is needed:
|
|
# ferro-ta, numpy, and pydantic-core all ship prebuilt wheels for linux
|
|
# x86_64 and aarch64.
|
|
COPY requirements.txt ./
|
|
RUN pip install --no-cache-dir -r requirements.txt
|
|
|
|
# Fail the build immediately if the wheel did not resolve for this arch
|
|
# (e.g. an exotic platform that fell back to an sdist build without Rust).
|
|
RUN python -c "import ferro_ta, numpy as np; ferro_ta.SMA(np.arange(10.0), 3); print('ferro_ta', ferro_ta.__version__, 'import OK')"
|
|
|
|
# Copy API source
|
|
COPY main.py ./
|
|
|
|
# Expose API port
|
|
EXPOSE 8000
|
|
|
|
ENV MAX_SERIES_LENGTH=100000
|
|
|
|
# Run with uvicorn (single worker; scale horizontally via Docker Compose / k8s)
|
|
CMD ["uvicorn", "main:app", "--host", "0.0.0.0", "--port", "8000"]
|