* feat: introduce hindsight-api-slim and hindsight-all-slim packages Closes #552 - Move all source code from hindsight-api/ to new hindsight-api-slim/ - hindsight-api-slim has heavy ML deps (torch, sentence-transformers, transformers, einops, flashrank, mlx, mlx-lm, safetensors) and pg0-embedded as optional extras: [local-ml], [embedded-db], [all] - hindsight-api becomes a zero-code meta-package depending on hindsight-api-slim[all] for full backward compatibility - Add hindsight-all-slim meta-package: hindsight-api-slim + client + embed - hindsight-all updated to depend on hindsight-api-slim[all] - pg0.py: lazy-import pg0 with clear ImportError pointing to [embedded-db] - Dockerfile: replace sed hack with proper uv sync --extra flags - Update release.yml, test.yml, lint.sh, release.sh, CLAUDE.md and all path references throughout the repo * refactor: rename hindsight/ directory to hindsight-all/ * docs: document hindsight-api-slim and hindsight-all-slim package variants Add package variants table and extras explanation to installation.md * docs: remove emojis from installation.md, use professional tone * docs: link Docker slim variant to pip package variants section * docs: consolidate Docker image variants into single table * ci: fix working-directory paths after package restructure - Replace all hindsight-api → hindsight-api-slim in test.yml - Replace hindsight → hindsight-all in test.yml - Add --extra embedded-db to test-embed API install step * ci: add local-ml and embedded-db extras to API sync steps These extras were previously implicit in the old hindsight-api package (which bundled everything). Now that hindsight-api-slim uses optional extras, we must explicitly request local-ml and embedded-db in CI. * ci: add API install step with embedded-db to test-embed smoke test The smoke test starts hindsight-api as a daemon, which requires pg0-embedded. Add a dedicated install step for hindsight-api-slim with embedded-db extra so the daemon can start successfully. * ci: remove --no-install-project when using optional extras When --no-install-project is combined with --extra, the optional deps are not installed because extras require the project to be active. Remove --no-install-project from steps that need local-ml or embedded-db. * ci: fix ordering of uv sync steps to preserve optional extras When uv sync runs for a different workspace member, it removes optional extras installed for other members. Fix by always running extra-requiring API sync last, after other workspace member syncs. Also remove --no-install-project from embedded-db sync in test-embed, as --no-install-project prevents optional extras from being active. * ci: add local-ml extra to test-embed API install for smoke test The smoke test starts the full API server which needs sentence-transformers for local embeddings (default provider). Add local-ml extra to the install. * ci: simplify extras with --all-extras and add slim pip smoke test - Replace explicit --extra local-ml --extra embedded-db with --all-extras for cleaner, more maintainable sync steps - Add test-pip-slim job: tests hindsight-api-slim[embedded-db] without local ML models, using Cohere for embeddings/reranking (mirrors Docker slim smoke test approach) * ci: simplify slim smoke test to health check only (mirrors Docker test)
105 lines
4 KiB
Python
105 lines
4 KiB
Python
"""Google Cloud Storage backend using obstore."""
|
|
|
|
import logging
|
|
import os
|
|
from datetime import datetime, timedelta, timezone
|
|
|
|
import obstore as obs
|
|
from obstore.store import GCSStore
|
|
|
|
from .base import FileStorage
|
|
|
|
logger = logging.getLogger(__name__)
|
|
|
|
|
|
def _make_google_auth_credential_provider():
|
|
"""Create a credential provider using google.auth (supports all credential types).
|
|
|
|
obstore's built-in credential parsing only supports service_account and
|
|
authorized_user JSON types. This provider uses the google-auth library
|
|
which additionally handles external_account (Workload Identity Federation),
|
|
impersonated credentials, and metadata-server credentials.
|
|
"""
|
|
import google.auth
|
|
import google.auth.transport.requests
|
|
|
|
credentials, _ = google.auth.default(scopes=["https://www.googleapis.com/auth/cloud-platform"])
|
|
request = google.auth.transport.requests.Request()
|
|
|
|
def _provide():
|
|
credentials.refresh(request)
|
|
expiry = credentials.expiry
|
|
if expiry and expiry.tzinfo is None:
|
|
expiry = expiry.replace(tzinfo=timezone.utc)
|
|
return {"token": credentials.token, "expires_at": expiry}
|
|
|
|
return _provide
|
|
|
|
|
|
class GCSFileStorage(FileStorage):
|
|
"""
|
|
Google Cloud Storage backend.
|
|
|
|
Uses obstore (Rust-backed) for high-throughput async access to GCS.
|
|
Supports Application Default Credentials, service account keys, and explicit credentials.
|
|
"""
|
|
|
|
def __init__(
|
|
self,
|
|
bucket: str,
|
|
service_account_key: str | None = None,
|
|
):
|
|
kwargs: dict = {}
|
|
if service_account_key:
|
|
kwargs["service_account_key"] = service_account_key
|
|
else:
|
|
# Use google.auth credential provider for broad credential type support
|
|
# (service_account, authorized_user, external_account, metadata server, etc.)
|
|
try:
|
|
kwargs["credential_provider"] = _make_google_auth_credential_provider()
|
|
logger.info("Using google.auth credential provider for GCS")
|
|
except Exception as e:
|
|
logger.warning(
|
|
f"Failed to create google.auth credential provider, falling back to obstore defaults: {e}"
|
|
)
|
|
|
|
# Workaround for https://github.com/developmentseed/obstore/issues/605
|
|
# obstore's Rust layer doesn't support external_account credentials (Workload
|
|
# Identity Federation) and eagerly parses GOOGLE_APPLICATION_CREDENTIALS even
|
|
# when credential_provider is given. Per the obstore maintainer's guidance,
|
|
# remove env vars so the Rust code doesn't try to authenticate itself.
|
|
# google.auth (used by credential_provider above) has already loaded credentials.
|
|
gac = os.environ.pop("GOOGLE_APPLICATION_CREDENTIALS", None)
|
|
try:
|
|
self._store = GCSStore(bucket, **kwargs)
|
|
finally:
|
|
if gac is not None:
|
|
os.environ["GOOGLE_APPLICATION_CREDENTIALS"] = gac
|
|
logger.info(f"Initialized GCS file storage: bucket={bucket}")
|
|
|
|
async def store(self, file_data: bytes, key: str, metadata: dict[str, str] | None = None) -> str:
|
|
await obs.put_async(self._store, key, file_data)
|
|
logger.debug(f"Stored file {key} ({len(file_data)} bytes) in GCS")
|
|
return key
|
|
|
|
async def retrieve(self, key: str) -> bytes:
|
|
try:
|
|
response = await obs.get_async(self._store, key)
|
|
return await response.bytes_async()
|
|
except Exception as e:
|
|
if "not found" in str(e).lower():
|
|
raise FileNotFoundError(f"File not found: {key}") from e
|
|
raise
|
|
|
|
async def delete(self, key: str) -> None:
|
|
await obs.delete_async(self._store, key)
|
|
|
|
async def exists(self, key: str) -> bool:
|
|
try:
|
|
await obs.head_async(self._store, key)
|
|
return True
|
|
except Exception:
|
|
return False
|
|
|
|
async def get_download_url(self, key: str, expires_in: int = 3600) -> str:
|
|
return await obs.sign_async(self._store, "GET", key, timedelta(seconds=expires_in))
|