fix(cli): pin the reaper to its storage node; drop the stale uid-1000 note
Two things in the same surface. --reaper-node is the supported multi-node answer: the rendered CronJob's pod gets a kubernetes.io/hostname selector, so it reads the hostPath on the node that actually holds the worlds instead of possibly scheduling where it is empty (naming a node without --worlds-host-path is fail-loud). And the render note still told operators to grant uid-1000 traverse / setfacl after #35 moved every world executor to root+DAC_OVERRIDE — it now states that fact instead of the obsolete ritual.
This commit is contained in:
5 files changed
+112
-26
No files matched your search
@@ -648,6 +648,22 @@ func TestReaperCronJob_Gating(t *testing.T) {
|
||||
}
|
||||
}
|
||||
|
||||
// TestReaperCronJob_NodePin proves the optional multi-node pin: no selector by
|
||||
// default (the single-node starter), and exactly the kubernetes.io/hostname
|
||||
// selector when ReaperNode names the node holding the worlds hostPath.
|
||||
func TestReaperCronJob_NodePin(t *testing.T) {
|
||||
ps, _ := cronPodSpec(t, reaperCronJob(reaperParams()))
|
||||
if ps.NodeSelector != nil {
|
||||
t.Errorf("NodeSelector = %v, want none without ReaperNode", ps.NodeSelector)
|
||||
}
|
||||
p := reaperParams()
|
||||
p.ReaperNode = "node-a"
|
||||
ps, _ = cronPodSpec(t, reaperCronJob(p))
|
||||
if got := ps.NodeSelector["kubernetes.io/hostname"]; got != "node-a" {
|
||||
t.Errorf("nodeSelector = %v, want kubernetes.io/hostname=node-a", ps.NodeSelector)
|
||||
}
|
||||
}
|
||||
|
||||
// TestReaperCronJob_Shape pins the rendered CronJob: its scheduling guards, its
|
||||
// run-as identity (felis-reaper WITH an auto-mounted token, because it legitimately
|
||||
// calls the K8s API — unlike the weak Job/registry pods), the hardening, the
|
||||
|
||||
Reference in new issue
Block a user