feat(build)/docs: make executor images configurable; document the build lane's real seams (#9, #10)

- [registry] gains kaniko_image / trivy_image / build_cpu_limit /
  build_mem_limit overrides; empty keeps the compiled-in defaults. An
  air-gapped or mirrored install has no route to gcr.io/aquasec (the
  build egress policy allows only DNS + registry + package mirrors), so
  builds previously could not even start their executors.
- deferred-seams: the uploads-context entry now records WHY a mount is
  impossible (PVCs cannot cross namespaces) and that the s3 lane also
  lacks credentials in the build Pod — options captured for the real fix.
- troubleshooting 8e (executor ImagePullBackOff + the overrides),
  13b rewritten (verified eviction refusal, 5m pressure-transition,
  image-GC recovery), 15 (upgrade/rollback runbook for Recreate).
- Backup semantics decided and documented: a backup is the whole /data
  volume (worlds + config + plugins + cache) and a restore rolls all of
  it back — OpenAPI/README wording updated to match (same-tag images are
  still watched for regressions by the openapi parity gate).
This commit is contained in:
Lemon-miaow committed 2026-09-22 22:03:48 +08:00
1 parent 0a2d654e68
commit 87a9f4eb25
10 files changed
+165 -37

No files matched your search

+13 -1
View File
@@ -44,7 +44,19 @@ A grep across `*.md` and `*.go` returns both sets; only the Go ones are seams.
apply is under way.
- `internal/submit/blobstore.go:40` — the uploads PVC is mounted into felis-api but
not into the Kaniko build Pod, so a submitted context is durable at the derived
location without yet being readable by the build that consumes it.
location without yet being readable by the build that consumes it. Audited
2026-09-22: this is not a missing volume line — a PVC cannot cross namespaces
(uploads live in the control namespace; build Pods run in `felis-build`), so the
fix is a transport, not a mount. The `s3://` lane does not close it either: the
build Job carries no AWS credentials (no env, and the weak SA's token is
deliberately unmounted, so no IAM either). Options on the table: (a) object
storage with credentials plumbed into the build Pod as a per-build Secret plus an
egress allowance; (b) a context-handoff PVC/Job pair in `felis-build` fed from
the API side; (c) a node-local path both sides mount (single-node only, and it
hands an arbitrary Dockerfile a filesystem view — needs its own security review).
Kaniko/Trivy images are external-only by default; `[registry] kaniko_image /
trivy_image / build_cpu_limit / build_mem_limit` now override them for mirrored
or air-gapped installs.
## Built; only its I/O is unverifiable from this repo