fix(build): 构建并发上限与排队,构建命名空间加 ResourceQuota,SyncAll 逐个容错

This commit is contained in:
Lemon-miaow committed 2026-09-24 22:26:21 +08:00
1 parent e521cf5976
commit e836a73a8a
13 files changed
+273 -17

No files matched your search

+3 -1
View File
@@ -493,6 +493,7 @@ build_mem_limit = "4Gi"
build_disk_limit = "12Gi" # §8f
build_user_namespaces = "auto" # §8f: auto | on | off
build_runtime_class = "" # §8f: e.g. "gvisor"
max_concurrent_builds = 2 # §8f: 1-6; later builds queue
```
Mirror the executor images into the registry once. On the node itself, push
@@ -582,7 +583,8 @@ approved-but-hostile Dockerfile and the node is the pod around it:
| Sandbox runtime | optional `build_runtime_class` (gVisor, Kata) | below |
| Credentials | the registry credential lives only in the `push` container; the service token only in `context-fetch` | jobspec |
| Resources | CPU, memory and ephemeral-storage limits per container; `activeDeadlineSeconds`; the context extraction stops at 4 GiB or 200 000 entries | jobspec, `felis fetch-context` |
| Namespace backstop | `felis-build-limits` LimitRange gives any container without limits 1 CPU / 1 GiB / 1 GiB disk | bundle |
| Namespace backstop | `felis-build-limits` LimitRange gives any container without limits 1 CPU / 1 GiB / 1 GiB disk; `felis-build-quota` allows 8 running pods and no PVCs | bundle |
| Concurrency | at most `[registry] max_concurrent_builds` (default 2, at most 6) builds run; later ones wait as `pending` (Queued) and start oldest first | `build.Builder` |
**Reviewed bytes.** Every upload records the sha256 of the archive, and the
review page shows it. The context download carries the same value in the