Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
20 changes: 20 additions & 0 deletions pmoves/chit/secrets_manifest.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -982,6 +982,26 @@ entries:
- file: env.tier-agent
key: TAILSCALE_AUTHKEY
required: false
- id: tailscale_api_key
source:
type: cgp
label: TAILSCALE_API_KEY
Comment on lines +985 to +988

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Add the Tailscale secrets to the v2 manifest

These entries are added only to the generated v1 manifest. The canonical secrets-funnel runs chit-manifest-sync, which rebuilds this file from secrets_manifest_v2.yaml; because neither ID exists there, the next funnel run deletes both entries before hydration, so TAILSCALE_API_KEY and TAILSCALE_TAILNET never reach env.tier-agent. Add them to the v2 source and regenerate the v1 file instead.

AGENTS.md reference: AGENTS.md:L92-L95

Useful? React with 👍 / 👎.

targets:
- file: .env.generated
key: TAILSCALE_API_KEY
- file: env.tier-agent
key: TAILSCALE_API_KEY
required: false
- id: tailscale_tailnet
source:
type: cgp
label: TAILSCALE_TAILNET
targets:
- file: .env.generated
key: TAILSCALE_TAILNET
- file: env.tier-agent
key: TAILSCALE_TAILNET
required: false
- id: telegram_bot_token
source:
type: cgp
Expand Down
25 changes: 25 additions & 0 deletions pmoves/chit/secrets_manifest_v2.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -1225,6 +1225,31 @@ entries:
- docker_secret: pmoves_tailscale_authkey
required: false
tier: agent
- id: tailscale_api_key
source:
type: cgp
label: TAILSCALE_APIKEY
aliases:
- TAILSCALE_API_KEY
targets:
- file: .env.generated
key: TAILSCALE_API_KEY
- file: env.tier-agent
key: TAILSCALE_API_KEY
- github_secret: TAILSCALE_APIKEY
required: false
tier: agent
- id: tailscale_tailnet
source:
type: cgp
label: TAILSCALE_TAILNET
targets:
- file: .env.generated
key: TAILSCALE_TAILNET
- file: env.tier-agent
key: TAILSCALE_TAILNET
required: false
tier: agent
- id: telegram_bot_token
source:
type: cgp
Expand Down
34 changes: 25 additions & 9 deletions pmoves/config/mcp_inventory.json
Original file line number Diff line number Diff line change
@@ -1,11 +1,11 @@
{
"version": 1,
"note": "Canonical inventory of PMOVES MCP servers. Used by pmoves/tools/mcp_config_generator.py to produce client-native config snippets for Claude, Kimi, KiloCode, Hermes, and Crush.",
"note": "Canonical inventory of PMOVES MCP servers. Used by pmoves/tools/mcp_config_generator.py to produce client-native config snippets for Claude, Kimi, KiloCode, Hermes, and Crush. Server entries support an optional 'disabled: true' field to mark servers that should be emitted as disabled in generated configs.",
"defaults": {
"cipher_local_url": "http://localhost:8105/api/mcp/sse",
"cipher_fleet_url": "http://${TS_Z890}:8105/api/mcp/sse",
"agent_zero_local_url": "http://localhost:8080/mcp",
"agent_zero_fleet_url": "http://${TS_Z890}:8080/mcp",
"agent_zero_local_url": "http://localhost:8081/mcp/t-${AGENT_ZERO_MCP_TOKEN}/sse",
"agent_zero_fleet_url": "http://${TS_Z890}:8081/mcp/t-${AGENT_ZERO_MCP_TOKEN}/sse",
Comment thread
coderabbitai[bot] marked this conversation as resolved.
"archon_local_url": "http://localhost:8051",
"archon_fleet_url": "http://${TS_Z890}:8051",
"docker_gateway_port": 8090
Expand Down Expand Up @@ -38,17 +38,18 @@
},
{
"key": "agent-zero",
"description": "Agent Zero orchestrator",
"transport": "http",
"endpoint": "fleet",
"description": "Agent Zero orchestrator (SSE with MCP token auth)",
"transport": "sse",
"endpoint": "local",
"endpoint_prefix": "agent_zero"
},
{
"key": "archon",
"description": "Archon knowledge / task orchestrator",
"description": "Archon knowledge / task orchestrator (REST-only MCP, no standard transport — disabled by default)",
"transport": "http",
"endpoint": "fleet",
"endpoint_prefix": "archon"
"endpoint": "local",
"endpoint_prefix": "archon",
"disabled": true
Comment thread
coderabbitai[bot] marked this conversation as resolved.
},
{
"key": "pmoves-nats-fleet",
Expand Down Expand Up @@ -122,6 +123,21 @@
"TAILSCALE_API_KEY": "${TAILSCALE_API_KEY}",
"TAILSCALE_TAILNET": "${TAILSCALE_TAILNET}"
}
},
{
"key": "hostinger",
"description": "Hostinger VPS API (requires pmz-hostinger container)",
"transport": "stdio",
"command": "docker",
"args": [
"exec",
"-i",
"pmz-hostinger",
"hostinger-api-mcp"
],
"env": {
"HOSTINGER_API_TOKEN": "${HOSTINGER_API_TOKEN}"
}
Comment thread
coderabbitai[bot] marked this conversation as resolved.
}
]
},
Expand Down
3 changes: 3 additions & 0 deletions pmoves/docker-compose.agents.yml
Original file line number Diff line number Diff line change
Expand Up @@ -95,6 +95,9 @@ services:
- A0_SET_browser_model_name=tensorzero::function_name::${AGENT_ZERO_TZ_FUNCTION:-agent_zero}
- A0_SET_browser_model_api_base=http://tensorzero-gateway:3000/openai/v1
- A0_SET_a2a_server_enabled=true
# Expose Agent Zero's MCP SSE server so external clients (Crush, Archon,
# other nodes) can connect via standard MCP transport at /t-{token}/sse.
- A0_SET_mcp_server_enabled=true
# A0_SET_mcp_server_token: soft default (CANONICAL_NAMES.md §5). The previous
# ${MCP_SERVER_TOKEN:?...} hard-require made *every* compose invocation on the
# shared file fail interpolation on nodes without the var — blocking bring-up
Expand Down
6 changes: 5 additions & 1 deletion pmoves/docker-compose.amd-voice.yml
Original file line number Diff line number Diff line change
Expand Up @@ -22,6 +22,10 @@
# RDNA2 (gfx1030/1031, RX6000): set HSA_OVERRIDE_GFX_VERSION=10.3.0
services:
ultimate-tts-studio:
build:
context: ./docker/ultimate-tts-studio
dockerfile: Dockerfile.rocm
image: ${ULTIMATE_TTS_ROCM_IMAGE:-ghcr.io/powerfulmoves/pmoves-ultimate-tts-studio:rocm-latest}
environment:
- HSA_OVERRIDE_GFX_VERSION=${HSA_OVERRIDE_GFX_VERSION:-12.0.1}
- PYTORCH_HIP_ALLOC_CONF=garbage_collection_threshold:0.6,max_split_size_mb:512
Expand All @@ -34,7 +38,7 @@ services:
deploy:
resources:
reservations:
devices: []
devices: !reset []
limits:
memory: 16G
cpus: '8.0'
Expand Down
3 changes: 3 additions & 0 deletions pmoves/docker-compose.yml
Original file line number Diff line number Diff line change
Expand Up @@ -2875,6 +2875,9 @@ services:
- A0_SET_browser_model_name=tensorzero::function_name::${AGENT_ZERO_TZ_FUNCTION:-agent_zero}
- A0_SET_browser_model_api_base=http://tensorzero-gateway:3000/openai/v1
- A0_SET_a2a_server_enabled=true
# Expose Agent Zero's MCP SSE server so external clients (Crush, Archon,
# other nodes) can connect via standard MCP transport at /t-{token}/sse.
- A0_SET_mcp_server_enabled=true
# A0_SET_mcp_server_token: soft default (CANONICAL_NAMES.md §5). The previous
# ${MCP_SERVER_TOKEN:?...} hard-require made *every* compose invocation on the
# shared file fail interpolation on nodes without the var — blocking bring-up
Expand Down
11 changes: 10 additions & 1 deletion pmoves/docker/ultimate-tts-studio/Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -51,7 +51,9 @@ RUN apt-get update && apt-get install -y --no-install-recommends \
# Step 1: Conda packages first (pynini + portaudio + scipy/numpy from conda-forge)
# CRITICAL: Install scipy/numpy from conda for proper ABI compatibility
# scipy 1.11.x works with numpy 1.26.x; scipy 1.14+ requires numpy 2.x
RUN conda install -c conda-forge pynini==2.1.6 portaudio scipy=1.11.4 numpy=1.26.4 -y && \
RUN conda tos accept --override-channels --channel https://repo.anaconda.com/pkgs/main 2>/dev/null; \
conda tos accept --override-channels --channel https://repo.anaconda.com/pkgs/r 2>/dev/null; \
conda install --override-channels -c conda-forge pynini==2.1.6 portaudio scipy=1.11.4 numpy=1.26.4 -y && \
conda clean -afy

# Step 2: Clone from PMOVES fork (same requirements.txt as SUP3RMASS1VE)
Expand Down Expand Up @@ -88,6 +90,12 @@ RUN echo "onnx==1.16.0" > /tmp/constraints.txt && \
RUN pip install -c /tmp/constraints.txt -r requirements.txt || \
pip install --use-deprecated=legacy-resolver -c /tmp/constraints.txt -r requirements.txt

# Step 5c.1: Install supplementary PMOVES requirements (einops, omegaconf, etc.)
# These are TTS engine dependencies not included in the upstream repo's requirements.txt
COPY requirements-ultimate-tts.txt /tmp/requirements-ultimate-tts.txt
RUN pip install -c /tmp/constraints.txt -r /tmp/requirements-ultimate-tts.txt || \
echo "WARN: Some supplementary deps failed (non-fatal — engines will lazy-load)"

# Step 5d: Skipped deepspeed compilation (removing it later to avoid runtime crashes)


Expand Down Expand Up @@ -166,6 +174,7 @@ RUN apt-get update && apt-get install -y --no-install-recommends \
libsox3 \
sox \
curl \
ca-certificates \
# CUDA runtime libraries for ONNX GPU provider
cuda-nvrtc-12-4 \
&& rm -rf /var/lib/apt/lists/* \
Expand Down
180 changes: 180 additions & 0 deletions pmoves/docker/ultimate-tts-studio/Dockerfile.rocm
Original file line number Diff line number Diff line change
@@ -0,0 +1,180 @@
# PMOVES.AI Ultimate-TTS-Studio — ROCm (AMD GPU) variant
# Multi-engine TTS for AMD ROCm nodes (RDNA3/RDNA4: gfx1100, gfx1201)
#
# Uses the same pytorch/pytorch conda base as the CUDA Dockerfile to get
# Python 3.11 + conda + pynini, then replaces CUDA PyTorch with ROCm PyTorch
# via pip. This avoids conda solver conflicts with pynini on Ubuntu.
#
# Build:
# docker build -f docker/ultimate-tts-studio/Dockerfile.rocm \
# -t ghcr.io/powerfulmoves/pmoves-ultimate-tts-studio:rocm-latest \
# --build-arg HSA_OVERRIDE_GFX_VERSION=12.0.1 \
# ./docker/ultimate-tts-studio/
#
# Usage:
# make -C pmoves up-voice-amd

# ── Stage 1: Builder ──────────────────────────────────────────────────────────
# Same base as CUDA Dockerfile — provides conda + Python 3.11 + pynini
FROM pytorch/pytorch:2.5.1-cuda12.4-cudnn9-runtime@sha256:c8268a92a69bd500f8be0e665b2630ee006dadaf7bfbc24249141b15ff622755 AS builder

ENV DEBIAN_FRONTEND=noninteractive \
PYTHONDONTWRITEBYTECODE=1 \
PYTHONUNBUFFERED=1 \
PIP_DISABLE_PIP_VERSION_CHECK=1 \
PIP_NO_CACHE_DIR=1

WORKDIR /build

# System deps for audio + build utilities
RUN apt-get update && apt-get install -y --no-install-recommends \
ffmpeg \
espeak-ng \
libespeak-ng1 \
libespeak-ng-dev \
libsndfile1 \
libportaudio2 \
portaudio19-dev \
libaio-dev \
libsox-dev \
sox \
git \
curl \
build-essential \
cmake \
protobuf-compiler \
libprotobuf-dev \
&& rm -rf /var/lib/apt/lists/*

# Conda packages (pynini + scipy/numpy ABI compat — same as CUDA Dockerfile)
RUN conda install -c conda-forge pynini==2.1.6 portaudio scipy=1.11.4 numpy=1.26.4 -y && \
conda clean -afy

# Replace CUDA PyTorch with ROCm PyTorch
# The base image ships torch+cu124; we uninstall and reinstall the ROCm wheel
RUN pip uninstall -y torch torchaudio torchvision 2>/dev/null || true && \
pip install --pre torch torchaudio torchvision \
--index-url https://download.pytorch.org/whl/nightly/rocm6.3

# Clone from PMOVES fork
RUN git clone --depth 1 https://github.com/POWERFULMOVES/PMOVES-Ultimate-TTS-Studio.git app

WORKDIR /build/app

# Install gradio and devicetorch first
RUN pip install --upgrade pip && \
pip install gradio devicetorch

# Pin huggingface-hub <1.0 before requirements
RUN pip install "huggingface-hub>=0.25.0,<1.0"

# Pre-install packages that fail to build from source
RUN pip install \
onnx==1.16.0 \
s3tokenizer>=0.1.6

# Constraint file (same as CUDA Dockerfile)
RUN echo "onnx==1.16.0" > /tmp/constraints.txt && \
echo "scipy==1.11.4" >> /tmp/constraints.txt && \
echo "numpy==1.26.4" >> /tmp/constraints.txt && \
echo "pydantic<2.12" >> /tmp/constraints.txt

# Install upstream requirements.txt
RUN pip install -c /tmp/constraints.txt -r requirements.txt || \
pip install --use-deprecated=legacy-resolver -c /tmp/constraints.txt -r requirements.txt

# Install supplementary PMOVES requirements (einops, omegaconf, etc.)
COPY requirements-ultimate-tts.txt /tmp/requirements-ultimate-tts.txt
RUN pip install -c /tmp/constraints.txt -r /tmp/requirements-ultimate-tts.txt || \
echo "WARN: Some supplementary deps failed (non-fatal)"

# WeTextProcessing without deps
RUN pip install WeTextProcessing --no-deps || true

# Fix phonemizer-fork
RUN pip uninstall -y phonemizer 2>/dev/null || true && \
pip install phonemizer-fork

# onnxruntime (CPU on ROCm — GPU provider needs ROCm-specific build)
RUN pip install -c /tmp/constraints.txt --upgrade --force-reinstall --no-deps --no-cache-dir onnxruntime==1.22.0 || \
pip install -c /tmp/constraints.txt onnxruntime==1.22.0

# voxcpm and openai-whisper without deps
RUN pip install -c /tmp/constraints.txt voxcpm openai-whisper --no-deps || true

# NOTE: Triton is CUDA-only — skipped on ROCm. PyTorch uses native attention.

# MCP for Gradio MCP server support
RUN pip install -c /tmp/constraints.txt mcp

# Download spacy model
RUN python -m spacy download en_core_web_sm || true

# Final numpy/scipy fix
RUN pip uninstall -y numpy deepspeed 2>/dev/null || true && \
rm -rf /opt/conda/lib/python3.11/site-packages/numpy* && \
pip install --force-reinstall "numpy==1.26.4" "scipy==1.11.4" && \
pip install --upgrade numba llvmlite && \
rm -rf /opt/conda/lib/python3.11/site-packages/numpy/_core

# Pre-download model checkpoint
RUN huggingface-cli download cocktailpeanut/oa --local-dir ./checkpoints/openaudio-s1-mini --quiet || \
echo "Model download will happen at runtime"

# ── Stage 2: Runtime ──────────────────────────────────────────────────────────
# Use Ubuntu 22.04 (no CUDA runtime needed — ROCm PyTorch ships its own libs)
FROM ubuntu:22.04 AS runtime

ENV DEBIAN_FRONTEND=noninteractive \
PYTHONDONTWRITEBYTECODE=1 \
PYTHONUNBUFFERED=1 \
GRADIO_SERVER_NAME=0.0.0.0 \
GRADIO_SERVER_PORT=7861 \
GRADIO_MCP_SERVER=false \
HF_HOME=/data/hf \
HUGGINGFACE_HUB_CACHE=/data/hf \
XDG_CACHE_HOME=/data/cache \
HSA_OVERRIDE_GFX_VERSION=12.0.1 \
PYTORCH_HIP_ALLOC_CONF=garbage_collection_threshold:0.6,max_split_size_mb:512 \
LD_LIBRARY_PATH="/opt/conda/lib:/opt/rocm/lib:${LD_LIBRARY_PATH}" \
PATH="/opt/conda/bin:${PATH}" \
DISABLE_NVIDIA=true

# Runtime system deps
RUN apt-get update && apt-get install -y --no-install-recommends \
ffmpeg \
espeak-ng \
libespeak-ng1 \
libsndfile1 \
libportaudio2 \
libaio1 \
libsox3 \
sox \
curl \
ca-certificates \
&& rm -rf /var/lib/apt/lists/* \
&& apt-get clean

# Create non-root user
RUN groupadd -g 65532 pmoves && \
useradd -u 65532 -g pmoves -d /app -s /bin/bash pmoves

# Copy Python environment from builder
COPY --from=builder /opt/conda /opt/conda

# Copy application code
COPY --from=builder /build/app /app

RUN mkdir -p /app/outputs /app/models /data/hf /data/cache && \
chown -R pmoves:pmoves /app /data

WORKDIR /app

USER pmoves

EXPOSE 7861

HEALTHCHECK --interval=30s --timeout=10s --start-period=180s --retries=3 \
CMD curl -f http://localhost:7861/gradio_api/info || exit 1

CMD ["python", "launch.py"]
3 changes: 2 additions & 1 deletion pmoves/scripts/crush-env.sh
Original file line number Diff line number Diff line change
Expand Up @@ -63,7 +63,8 @@ for var in \
HF_TOKEN \
OLLAMA_BASE_URL \
TAILSCALE_API_KEY \
TAILSCALE_TAILNET; do
TAILSCALE_TAILNET \
AGENT_ZERO_MCP_TOKEN; do

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Export the Tailscale MCP credentials from tier files

When the new Tailscale secrets are populated only in env.tier-agent, build_config() can read them from its environment-file cache and therefore enables the Tailscale MCP server, but crush-pmoves launches Crush with only the variables exported by this list. Since TAILSCALE_API_KEY and TAILSCALE_TAILNET are omitted, the inherited npx tailscale-mcp process starts without either credential and cannot authenticate.

Useful? React with 👍 / 👎.

if [ -n "${ENV_MAP[$var]:-}" ] && [ -z "${!var:-}" ]; then
export "$var"="${ENV_MAP[$var]}"
fi
Expand Down
Loading
Loading