crossplane / crossplane/function-runtime-oci

Cannot start function container when container user does not exist within crossplane-xfn container

オープン
#30 コメント 0 件 リアクション 1 件 担当者 0 名 GitHub で見る
bug
主要言語
Go
スター
6
フォーク
2
PR マージ指標
30日以内にマージされた PR はありません

説明

### What happened?

Working on https://github.com/crossplane/crossplane/pull/4261 required creating a custom, but simple function image that labels all managed resources with a given label. My first idea was to use `yq` for that and the initial `Dockerfile` was just:

```Dockerfile
FROM mikefarah/yq:4.34.1

COPY labelizer.sh /bin

ENTRYPOINT ["/bin/labelizer.sh"]
```

with `/bin/labelizer.sh` being just:

```sh
#!/usr/bin/env sh

yq '(.desired.resources[] | .resource.metadata.labels) |= {"labelizer.xfn.crossplane.io/processed": "true"} + .'
```

Unfortunately, adding this function to a composition resulted with the following error in `crossplane-xfn` logs:

```
cannot compose resources: cannot run Composition Function pipeline: cannot run function "labelizer":
cannot run container: rpc error: code = Unknown desc = exit status 1: xfn: error: spark.Command.Run():
cannot create OCI runtime bundle: cannot write OCI runtime spec: cannot create new spec:
cannot apply spec option: cannot resolve user specified by OCI image config:
cannot resolve UID of user "yq" that doesn't exist in container's /etc/passwd
```

Modifying the image to use root to run the script resolved the issue.

### How can we reproduce it?

* deploy crossplane with enabled composition functions
* build and publish the function image using files stated above
* create a composition referring that function

### What environment did it happen in?

The issue is spotted on the latest master, but I am pretty sure that versions containing composition function feature suffer from the same issue.

### Expectations

Function containers should be successfully invoked independently if container user exists within `crossplane-xfn` container/image. We should even encourage function authors to use some arbitrary high/random UID for function.

コントリビューションガイド

このリポジトリのコントリビューションガイドは索引されていません

調査の方向性

まず、issue に示されている Dockerfile と labelizer.sh を使い、設定されたユーザーが /etc/passwd に存在しない function image で障害を再現します。次に、OCI コンテナを呼び出してそのユーザーを解決する Go のエントリーポイントを追跡します。設定されたユーザーが crossplane-xfn イメージに存在しない場合でも、任意の高い UID やランダムな UID を含めて function コンテナが正常に起動すれば完了です。

索引モデルが issue の本文から書いたものです。

評価

技術スタック
docker, go
領域
devops, infrastructure
issue の種類
バグ
難易度
4/5
見積もり時間
3〜5日
活発さ
停滞
明瞭さ
おおむね明確
初心者へのやさしさ
35/100

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。