kubernetes: build with an initContainer or a Job
还没有人认领这个 Issue。
- 主要语言
- Go
- 星标
- 300
- 派生
- 64
- 平均合并
- 20 分钟
- 30 天内合并 PR
- 1
描述
## Context
Currently, envbuilder runs at the start up of a workspace, exposing elements of the buildtime to the runtime and vice-versa:
* Build secrets (e.g. dockerconfig)
* Environment variables (#91)
* Mounts (#187)
* Privileges (#181)
* Container layers are downloaded in each container rather than on the nodes
* ... (feel free to grow the list)
## Proposal 1: initContainer
1. Envbuilder would build the image as an [initContainer](https://kubernetes.io/docs/concepts/workloads/pods/init-containers/) and push it to a container registry
2. The main container would pull and run the image (todo: validate that the pod can be created without the image existing yet)
This would require to generate/know the image reference ahead of time.
## Proposal 2: Kubernetes Job
Entire decoupling of buildtime and runtime:
1. Envbuilder runs as Kubernetes `Job` to build and push the container image
2. It writes a `ConfigMap` with the reference of the built image
3. Terraform [waits for completion](https://registry.terraform.io/providers/hashicorp/kubernetes/latest/docs/resources/job#wait_for_completion) of the `Job`
4. Terraform reads the `ConfigMap` with [`kubernetes_config_map`](https://registry.terraform.io/providers/hashicorp/kubernetes/latest/docs/data-sources/config_map) datasource ([explicitly depending on](https://developer.hashicorp.com/terraform/language/meta-arguments/depends_on) the `Job` creation)
5. The image reference from the `ConfigMap` is then used to create a `Deployment`
6. A short [`ttl_seconds_after_finished`](https://registry.terraform.io/providers/hashicorp/kubernetes/latest/docs/resources/job#ttl_seconds_after_finished) would allow clean up of the Job for it to be recreated on the next `terraform apply`
The `ConfigMap` could be used to share of information between `envbuilder` and Terraform (#121), like the volumes defined in the `devcontainer.json` (#220)
Detail to consider: I believe the Coder server starts streaming the logs from the deployment after the `terraform apply` has finished, it would need to be able to do it for the `Job` while the apply is running to expose the build logs to the user.
Is it something that has been thought of/done but not documented yet?
贡献指南
这个仓库没有索引到贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
调研方向
未指定文件或测试。首先检查当前的 Kubernetes deployment 和 Terraform 资源,然后跟踪 envbuilder 在 workspace 启动期间如何执行构建;完成标准是选择并实现一个提案、验证镜像引用的交接,并处理构建日志流式传输。
由索引模型根据 Issue 内容生成。
评估
- 技术栈
- kubernetes, terraform
- 领域
- cloud, infrastructure
- Issue 类型
- 功能
- 难度
- 5/5
- 预计耗时
- 一周以上
- 活跃度
- 停滞
- 描述清晰度
- 需要澄清
- 新手友好度
- 25/100