containerd / containerd/nri

Kubernetes / NRI communication path

Open
#282 19 comments 0 reactions 0 assignees View on GitHub
Dominant language
Go
Stars
406
Forks
102
Avg merge
1d 10h
Merged PRs (30d)
8

Description

This was found by @gauravkghildiyal , see [doc](https://docs.google.com/document/d/1bssPQW4L_RVyVtGhq1rWidxFSVmvN2iwEHG0t5KN7S4/edit?tab=t.0#heading=h.ss87mhtpkle3) with more details.

in DRANET, a DRA driver for kubernetes networking, we implement an architecture with 2 legs for the driver:

1. Kubelet via DRA
2. Container runtime via NRI

This architecture allow to handle complex workloads that require to execute at different stages of a pod creation. Also, this guarantees that the kubernetes system will not schedule nothing to the node until the DRA driver in the node is running, the driver can store the state in memory during the kubelet DRA NodePrepareResources() callback, and use the NRI callback to execute the actions on the Pod during the container runtime stage.

However, there is still a race in this process, if for any case the runtime is restarted, the DRA driver will not be able to notice it and the Pod can be running without the NRI call back called ... we need to ensure that a specific driver is always called for a specific pod

NRI added the concept of required plugins https://github.com/containerd/nri/pull/278 , this indicates that drivers can implement this behavior globally modifying the configuration or via annotations.

Since global is an admin option that requires changing containerd config, is hard for independent drivers to modify it, so we need to use the annotations path, however, the DRA hook in kubelet does not have a way to plumb dumb annotations (Device plugin does have)

I commented this during kubecon with NRI maintainers @klihub @kad they mentioned it should be possible to use the existing NodePrepareResources() hook to be able to use CDI to allow this functionality, but may require some work in some places to enable it.

@klihub @gauravkghildiyal @samuelkarp @chrishenzie

Contributor guide

No contributing guide indexed for this repository

Research direction

Start with the linked design document and the existing NodePrepareResources() hook, then review NRI required plugins, annotations, and CDI as described in the issue. Trace how DRA and NRI currently communicate across kubelet and the container runtime. Done means a driver can ensure the intended NRI callback is invoked for a specific pod after runtime restarts without requiring global containerd configuration.

Written by the indexing model from the issue text.

Assessment

Tech stack
go, kubernetes
Domain
distributed-systems, infrastructure
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
32/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.