crossplane / crossplane/function-runtime-oci

Cannot start function container when container user does not exist within crossplane-xfn container

Abierto
#30 0 comentarios 1 reacción 0 asignados Ver en GitHub
bug
Lenguaje dominante
Go
Estrellas
6
Forks
2
Métricas de merge de PR
Sin PR fusionados en 30 d

Descripción

### What happened?

Working on https://github.com/crossplane/crossplane/pull/4261 required creating a custom, but simple function image that labels all managed resources with a given label. My first idea was to use `yq` for that and the initial `Dockerfile` was just:

```Dockerfile
FROM mikefarah/yq:4.34.1

COPY labelizer.sh /bin

ENTRYPOINT ["/bin/labelizer.sh"]
```

with `/bin/labelizer.sh` being just:

```sh
#!/usr/bin/env sh

yq '(.desired.resources[] | .resource.metadata.labels) |= {"labelizer.xfn.crossplane.io/processed": "true"} + .'
```

Unfortunately, adding this function to a composition resulted with the following error in `crossplane-xfn` logs:

```
cannot compose resources: cannot run Composition Function pipeline: cannot run function "labelizer":
cannot run container: rpc error: code = Unknown desc = exit status 1: xfn: error: spark.Command.Run():
cannot create OCI runtime bundle: cannot write OCI runtime spec: cannot create new spec:
cannot apply spec option: cannot resolve user specified by OCI image config:
cannot resolve UID of user "yq" that doesn't exist in container's /etc/passwd
```

Modifying the image to use root to run the script resolved the issue.

### How can we reproduce it?

* deploy crossplane with enabled composition functions
* build and publish the function image using files stated above
* create a composition referring that function

### What environment did it happen in?

The issue is spotted on the latest master, but I am pretty sure that versions containing composition function feature suffer from the same issue.

### Expectations

Function containers should be successfully invoked independently if container user exists within `crossplane-xfn` container/image. We should even encourage function authors to use some arbitrary high/random UID for function.

Guía de contribución

No hay ninguna guía de contribución indexada para este repositorio

Línea de trabajo

Start by reproducing the failure with the Dockerfile and labelizer.sh shown in the issue, using a function image whose configured user is absent from /etc/passwd. Then trace the Go entry point that invokes the OCI container and resolves its user. Done means function containers start successfully even when their configured user is not present in the crossplane-xfn image, including arbitrary high or random UIDs.

Escrito por el modelo de indexación a partir del texto del issue.

Evaluación

Stack tecnológico
docker, go
Área
devops, infrastructure
Tipo de issue
Error
Dificultad
4/5
Tiempo estimado
3-5 días
Estado de actividad
Estancado
Claridad
Bastante claro
Aptitud para principiantes
35/100

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.