- [registry] gains kaniko_image / trivy_image / build_cpu_limit / build_mem_limit overrides; empty keeps the compiled-in defaults. An air-gapped or mirrored install has no route to gcr.io/aquasec (the build egress policy allows only DNS + registry + package mirrors), so builds previously could not even start their executors. - deferred-seams: the uploads-context entry now records WHY a mount is impossible (PVCs cannot cross namespaces) and that the s3 lane also lacks credentials in the build Pod — options captured for the real fix. - troubleshooting 8e (executor ImagePullBackOff + the overrides), 13b rewritten (verified eviction refusal, 5m pressure-transition, image-GC recovery), 15 (upgrade/rollback runbook for Recreate). - Backup semantics decided and documented: a backup is the whole /data volume (worlds + config + plugins + cache) and a restore rolls all of it back — OpenAPI/README wording updated to match (same-tag images are still watched for regressions by the openapi parity gate).
This commit is contained in:
10 files changed
+165
-37
No files matched your search
@@ -119,6 +119,19 @@ type K8sConfig struct {
|
||||
type RegistryConfig struct {
|
||||
URL string `toml:"url"`
|
||||
BuildNamespace string `toml:"build_namespace"`
|
||||
// KanikoImage / TrivyImage / BuildCPULimit / BuildMemLimit override the
|
||||
// build subsystem's compiled-in defaults (gcr.io/kaniko-project/executor and
|
||||
// aquasec/trivy, 2 CPU / 4Gi per build container). The defaults assume the
|
||||
// build namespace can reach those registries; on an air-gapped or mirrored
|
||||
// install there IS no such reach (the build egress policy allows only DNS,
|
||||
// the internal registry and explicit package mirrors), so the operator must
|
||||
// point these at whatever their box can actually pull — typically images
|
||||
// imported into the node's containerd alongside the felis image. Empty keeps
|
||||
// the default.
|
||||
KanikoImage string `toml:"kaniko_image"`
|
||||
TrivyImage string `toml:"trivy_image"`
|
||||
BuildCPULimit string `toml:"build_cpu_limit"`
|
||||
BuildMemLimit string `toml:"build_mem_limit"`
|
||||
// UserUploadsContext is the object-store base under which a user-submitted
|
||||
// modpack's Kaniko build context is pinned. It belongs to the §16 build
|
||||
// subsystem's input domain (the build-context store), introduced by the
|
||||
|
||||
Reference in new issue
Block a user