v0.4: package atomic prepared-node install upgrade rollback and uninstall
- Langage dominant
- Go
- Étoiles
- 1
- Forks
- 0
- Merge moyen
- 18 min
- PR mergées (30 j)
- 19
Description
Parent epic: #6
Depends on #108 and #109; final behavior also depends on #110.
Package immutable amd64/arm64 CNI and node-agent artifacts and an opt-in prepared-node lifecycle:
- atomically install the chained entry and request containerd `cgroupPath`;
- preserve and validate the exact prior conflist;
- use a narrow AppArmor/seccomp/capability/RBAC profile;
- remove preview scheduling eligibility before mutation;
- coordinate upgrades without detaching the last deny;
- drain or explicitly replace preview workloads before uninstall;
- restore the byte-identical prior chain and remove only exact Waycloak-owned pins.
Prove interrupted install, partial files, incompatible CNI, node reboot, upgrade, rollback, and uninstall on amd64 Flatcar and arm64 Ubuntu/k3s. Helm remains the primary surface and the feature is disabled by default.
Guide de contribution
Ouvrir le guide de contribution
Piste de recherche
Start by reading the parent epic #6 and dependencies #108, #109, and #110, then inspect the Helm surface named in this issue. The work is complete only when the prepared-node lifecycle covers atomic install, upgrade, rollback, and uninstall, with the listed interruption and platform scenarios proven on amd64 Flatcar and arm64 Ubuntu/k3s.
Rédigé par le modèle d'indexation à partir du texte de l'issue.
Évaluation
- Stack technique
- go, helm, kubernetes, linux, ubuntu
- Domaine
- devops, infrastructure, networking, operating-systems, security
- Type d'issue
- Fonctionnalité
- Difficulté
- 5/5
- Temps estimé
- Plus d'une semaine
- Activité
- Calme
- Clarté
- À clarifier
- Accessibilité débutants
- 20/100