Repository navigation
Conversation
| **The emulator is not Spanner.** Method B's write throughput and latency numbers | ||
| aren't super helpful and indicative of live spanner performance. | ||
|
|
||
| **Cloud Armor Adaptive Protection is armed on nonprod.** The policy has an |
There was a problem hiding this comment.
Is this still accurate? I thought we no longer had Cloud Armor after we moved to WAF (or just no longer its firewall?)
| | Method B | Write access to a GCS bucket you control. | | ||
|
|
||
| Sync's tenant is not onboarded to PAM, so there is no just-in-time elevation | ||
| available. `gcloud pam entitlements search` returns nothing. |
There was a problem hiding this comment.
I don't think this is true (anymore).
There was a problem hiding this comment.
Right, after you added our JIT entitlements. Will update 👍
|
|
||
| | For | You need | | ||
| | --- | --- | | ||
| | Creating the VM | Compute admin on some project. `sync/developers` has **no** compute roles on the sync tenant projects, so use your own project under the developers folder. | |
There was a problem hiding this comment.
I don't think that's been the case since https://github.com/mozilla/webservices-infra/commit/913b7d71d88d18a0526463bba7d4d3b066cc0af1
There was a problem hiding this comment.
Right, thx for pointing out. That grants compute.instanceAdmin.v1 on nonprod. Just had it wrong and didn't factor in that change
| > fails with `Quota 'CPUS_PER_VM_FAMILY' exceeded. Limit: 0.0`. N2 and E2 draw | ||
| > from the general `CPUS` pool, which does have a default allocation. Check with | ||
| > `gcloud compute regions describe us-west1 --project=$PROJ --flatten="quotas[]" | ||
| > --format="table(quotas.metric,quotas.limit,quotas.usage)"`. |
There was a problem hiding this comment.
I'm no gcloud compute pro so I was curious about this. And according to https://docs.cloud.google.com/compute/resource-usage#cpu_quota N2 has a separate pool.
| ```console | ||
| sudo apt update && sudo apt install -y git python3 python3-venv | ||
| mkdir -p ~/src && cd ~/src | ||
| git clone https://github.com/mozilla-services/syncstorage-rs.git |
There was a problem hiding this comment.
nit: clone with --depth=1 and maybe clone specific tag/commit?
There was a problem hiding this comment.
Yep, I can add --depth=1.
| ```console | ||
| echo hello | gcloud storage cp - gs://<your-bucket>/write-check.txt --project=$PROJ | ||
| gcloud storage rm gs://<your-bucket>/write-check.txt --project=$PROJ | ||
| ``` |
There was a problem hiding this comment.
I'm not sure I understand what's being verified here.
338d7f9 to
917d5f1
Compare
Description
Add a runbook for load testing the GCS payload offload path with the Molotov and gcloud cli commands, covering VM setup via gcloud, running against dev, and running a local syncserver with raised limits for expanded payloads.
docs/src/tools/payload-offload-load-testing.md
Closes STOR-715