docs(build): 修正上下文存储与构建镜像拉取的过时描述

This commit is contained in:
Lemon-miaow committed 2026-09-24 22:26:29 +08:00
1 parent e836a73a8a
commit a27d76ae1d
3 files changed
+17 -21

No files matched your search

+6 -5
View File
@@ -470,11 +470,12 @@ installer).
### 8e. Build Pods never start: executor images and air-gapped installs ### 8e. Build Pods never start: executor images and air-gapped installs
The build Job runs Kaniko and Trivy from external registries by default The build Job runs Kaniko and Trivy from external registries by default
(`gcr.io/kaniko-project/executor:latest`, `aquasec/trivy:latest`). On a box whose (`gcr.io/kaniko-project/executor:latest`, `aquasec/trivy:latest`). The kubelet
build namespace cannot reach those registries (the egress policy allows only pulls those images over the node's own network, so the build namespace's egress
DNS, the internal registry and `--package-cidr` mirrors — and an air-gapped box policy does not apply to the pull; what blocks it is a node without a route to
has no route at all), the Pods sit in `ImagePullBackOff`/`ErrImagePull` and the those registries (an air-gapped box, a firewall, a rate-limited Docker Hub).
build stays `building` until its deadline. Point the overrides at images **in The Pods then sit in `ImagePullBackOff`/`ErrImagePull` and the build stays
`building` until its deadline. Point the overrides at images **in
the internal registry** — the one pull source that survives an image GC (a bare the internal registry** — the one pull source that survives an image GC (a bare
node-containerd import does not: kubelet's image GC collects unused images under node-containerd import does not: kubelet's image GC collects unused images under
disk pressure, and an air-gapped box then has nothing to restore them from) — disk pressure, and an air-gapped box then has nothing to restore them from) —
+6 -8
View File
@@ -149,14 +149,12 @@ type RegistryConfig struct {
BuildNamespace string `toml:"build_namespace"` BuildNamespace string `toml:"build_namespace"`
// KanikoImage / TrivyImage / BuildCPULimit / BuildMemLimit override the // KanikoImage / TrivyImage / BuildCPULimit / BuildMemLimit override the
// build subsystem's compiled-in defaults (gcr.io/kaniko-project/executor and // build subsystem's compiled-in defaults (gcr.io/kaniko-project/executor and
// aquasec/trivy, 2 CPU / 4Gi per build container). The defaults assume the // aquasec/trivy, 2 CPU / 4Gi per build container). The kubelet pulls the
// build namespace can reach those registries; on an air-gapped or mirrored // executor images over the node's network, so the defaults need a node that
// install there IS no such reach (the build egress policy allows only DNS, // can reach those registries; an air-gapped or mirrored install points these
// the internal registry and explicit package mirrors), so the operator must // at images mirrored into the in-cluster registry (docs/troubleshooting.md
// point these at whatever their box can actually pull — typically images // §8e). A bare node-containerd import does not survive an image GC, there is
// mirrored into the in-cluster registry (docs/troubleshooting.md §8e); a // no pull source for it. Empty keeps the default.
// bare node-containerd import does not survive an image GC, there is no pull
// source for it. Empty keeps the default.
KanikoImage string `toml:"kaniko_image"` KanikoImage string `toml:"kaniko_image"`
TrivyImage string `toml:"trivy_image"` TrivyImage string `toml:"trivy_image"`
BuildCPULimit string `toml:"build_cpu_limit"` BuildCPULimit string `toml:"build_cpu_limit"`
+5 -8
View File
@@ -32,16 +32,13 @@ var idRE = regexp.MustCompile(`^[a-z0-9][a-z0-9-]{0,127}$`)
// Manager.Blobs nil so the upload endpoint returns 503 rather than pretending to // Manager.Blobs nil so the upload endpoint returns 503 rather than pretending to
// accept a file it cannot persist. // accept a file it cannot persist.
// //
// Base MUST equal the Manager's ContextStore so the blob lands exactly where // Base MUST equal the Manager's ContextStore; cmd/felis wires both from the one
// deriveContextRef points Kaniko's --context; cmd/felis wires both from the one
// config field (registry.user_uploads_context). // config field (registry.user_uploads_context).
// //
// INTEGRATION-ONLY seam (out of scope of the upload transport): persisting the // The build Pod never mounts this PVC. With Manager.ContextBaseURL set (every
// blob is end-to-end only once the same uploads PVC is mounted into the Kaniko // installed API) the derived context ref is the internal face's
// build Pod and Kaniko is told to read a local context (build/jobspec.go passes // /api/v1/internal/submissions/{id}/context route, which streams the blob out
// the ref straight into --context). The transport here makes the file durable at // of this store to the build Job's `felis fetch-context` step.
// the derived location; wiring that path into the sandboxed build Job is a
// separate deployment integration, exactly like the restore executor's PVC mount.
type LocalContextStore struct { type LocalContextStore struct {
// Base is the directory (uploads PVC mount) submission contexts are written // Base is the directory (uploads PVC mount) submission contexts are written
// under. Each submission gets its own {Base}/{id}/ subdirectory. // under. Each submission gets its own {Base}/{id}/ subdirectory.