Arch / EndeavourOS now ships CUDA 13 (libcublas.so.13); ctranslate2
4.7.2 (which faster-whisper rides) wants CUDA 12 + cuDNN 9 and won't
load against the system libs. Travis got it working ad-hoc with a
shell export of LD_LIBRARY_PATH + manual pip install, but systemd
doesn't inherit either, so the next reboot would refire the
libcublas.so.12 load error.
Making it permanent + reproducible:
- pyproject `tower` extra now pins the CUDA-12 runtime as pip wheels
alongside faster-whisper:
nvidia-cublas-cu12; sys_platform == 'linux'
nvidia-cudnn-cu12>=9,<10; sys_platform == 'linux'
uv.lock resolves nvidia-cublas-cu12 12.9.2.10 + nvidia-cudnn-cu12
9.22.0.52. Dev side (no --extra tower) stays clean — verified by a
no-extra `uv sync` followed by `uv pip list | grep nvidia` returning
empty.
- deploy/tower/run-transcribe-worker.sh (new, +x): computes the venv's
CUDA-12 lib dirs at runtime via `uv run python` (resolving
nvidia.cublas / nvidia.cudnn through __path__ — they're PEP 420
namespace packages with no __file__), prepends them to
LD_LIBRARY_PATH, then execs `uv run second-brain transcribe-worker`.
No hard-coded python3.XX path so it survives Python upgrades. If the
wheels aren't installed it aborts with a clear "uv sync --extra
tower" hint instead of a silent libcublas load failure deep inside
ctranslate2.
- second-brain-transcribe.service: ExecStart now points at the
wrapper. Also moves StartLimitIntervalSec / StartLimitBurst from
[Service] into [Unit] where modern systemd expects them
(systemd-analyze verify previously flagged the misplaced keys as
silently ignored). Restart=always, EnvironmentFile, After=/Wants=
wg-quick@wg-lan.service, User=herbyadmin all unchanged.
- second-brain-transcribe.env.example: trimmed to just
SECOND_BRAIN_DATABASE_URL with the placeholder spelled out, plus a
clear pointer to the ready-to-scp env file generated on herbys-dev
at /opt/backups/postgres-consolidation/second-brain-transcribe.env
(mode 0600, regeneratable from credentials.env without ever echoing
the password). The committed example never carries a real secret.
- deploy/tower/README.md: documents the CUDA-13-vs-CUDA-12 gotcha
upfront ("don't `pacman -S cuda cudnn`"), the wrapper-based
ExecStart, the scp-from-dev EnvironmentFile recipe with the
password-regen one-liner, and the EnvironmentFile-vs-shell-export
note.
Verified locally on dev (no GPU):
- uv.lock resolves with the new tower deps.
- A throwaway venv installed with the same `nvidia-cublas-cu12
nvidia-cudnn-cu12>=9,<10` pins produces lib dirs containing
libcublas.so.12 and libcudnn.so.9 via the wrapper's path probe.
- systemd-analyze verify is clean except the expected
"/opt/projects/... not executable on this host" warning (the
wrapper exists only in the tower's checkout).
- 27 passed / 2 skipped in pytest; zero-check 5/5.
GPU large-v3 + live service start under systemd remain tower-only
validation steps.
39 lines
1.7 KiB
Plaintext
39 lines
1.7 KiB
Plaintext
# /etc/default/second-brain-transcribe (template — copy + fill in the password).
|
|
#
|
|
# systemd reads this BEFORE dropping to User=herbyadmin, so installing it
|
|
# root:root mode 0600 is the right shape. NEVER commit the real value.
|
|
#
|
|
# Sourcing the password:
|
|
# The lovebug Postgres password is the LOVEBUG_PG_PASSWORD value in
|
|
# /opt/backups/postgres-consolidation/credentials.env on herbys-dev
|
|
# (mode 0600, host-only). It's a 64-character hex string — no URL
|
|
# encoding required.
|
|
#
|
|
# On herbys-dev there's already a ready-to-scp env file with the real
|
|
# password populated:
|
|
# /opt/backups/postgres-consolidation/second-brain-transcribe.env
|
|
# scp that to the tower instead of hand-copying:
|
|
# scp herbys-dev:/opt/backups/postgres-consolidation/second-brain-transcribe.env \
|
|
# tower:/tmp/sb-env
|
|
# sudo install -m 0600 -o root -g root /tmp/sb-env \
|
|
# /etc/default/second-brain-transcribe
|
|
# rm /tmp/sb-env
|
|
#
|
|
# DB host is db.wg.herbylab.dev:5432 over WireGuard, database name
|
|
# `petalbrain` (the post-consolidation rename).
|
|
#
|
|
# Note: this file is NOT a shell init script — `export VAR=...`
|
|
# additions in your interactive shell don't apply here, and changes
|
|
# require `systemctl restart second-brain-transcribe` to take effect.
|
|
|
|
SECOND_BRAIN_DATABASE_URL=postgresql://lovebug:REPLACE_WITH_LOVEBUG_PG_PASSWORD@db.wg.herbylab.dev:5432/petalbrain
|
|
|
|
# OPTIONAL — only set to override the [whisper] block in settings.toml.
|
|
# Defaults are large-v3 / cuda / float16.
|
|
# WHISPER_MODEL=large-v3
|
|
# WHISPER_DEVICE=cuda
|
|
# WHISPER_COMPUTE_TYPE=float16
|
|
|
|
# OPTIONAL — identifier stamped into sources.claimed_by (default tower:<hostname>).
|
|
# SECOND_BRAIN_WORKER_ID=tower-main
|