Skip to content

feat(chart): mount the CoreDNS config without subPath - #12

Closed
alexander-turner wants to merge 1 commit into
METR:mainfrom
alexander-turner:claude/glovebox-kata-hawk-7pmocy-main
Closed

alexander-turner wants to merge 1 commit into
METR:mainfrom
alexander-turner:claude/glovebox-kata-hawk-7pmocy-main

Conversation

@alexander-turner

Copy link
Copy Markdown

The agent-env chart mounts two single files with subPath: the CoreDNS sidecar's Corefile, and the workload's /etc/resolv.conf. Some container runtimes cannot mount a single file that way. Kata Containers' documentation lists subPath as a limitation.

This PR:

  • mounts the Corefile as a directory at /etc/coredns, which works on every runtime;
  • adds an opt-in corednsUpstream value (a list of DNS server IPs, e.g. the cluster DNS Service IP). When set, the pod uses dnsPolicy: None with the sidecar as its only nameserver, and the sidecar forwards to those IPs instead of reading the kubelet's resolv.conf. No subPath mount remains. Init containers cannot resolve names in that mode, because they run before the sidecar starts.

Default behaviour is unchanged when corednsUpstream is empty.

Testing: new Helm-template tests cover the directory mount, the dnsPolicy: None form, the forward line, and schema rejection of a non-IP entry. Four of them fail on the old chart.

Note: under a Kata config with shared_fs = "none" (block-device rootfs), the existing subPath mounts worked in our tests. So corednsUpstream matters for runtimes and configs that really lack subPath support. The Corefile directory mount is a portability improvement either way.

The agent-env chart mounts the sidecar's Corefile and the workload's
/etc/resolv.conf with subPath, which some container runtimes cannot do.
The Corefile becomes a directory mount. A new corednsUpstream value
switches the pod to dnsPolicy: None with the sidecar as its nameserver,
and points the sidecar at explicit upstreams instead of the kubelet's
resolv.conf.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016rjBF5dmtAKQKV1yH6vwAQ
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants