feat(chart): mount the CoreDNS config without subPath - #12
Closed
alexander-turner wants to merge 1 commit into
Closed
alexander-turner wants to merge 1 commit into
alexander-turner wants to merge 1 commit into
Conversation
The agent-env chart mounts the sidecar's Corefile and the workload's /etc/resolv.conf with subPath, which some container runtimes cannot do. The Corefile becomes a directory mount. A new corednsUpstream value switches the pod to dnsPolicy: None with the sidecar as its nameserver, and points the sidecar at explicit upstreams instead of the kubelet's resolv.conf. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_016rjBF5dmtAKQKV1yH6vwAQ
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The agent-env chart mounts two single files with
subPath: the CoreDNS sidecar'sCorefile, and the workload's/etc/resolv.conf. Some container runtimes cannot mount a single file that way. Kata Containers' documentation listssubPathas a limitation.This PR:
Corefileas a directory at/etc/coredns, which works on every runtime;corednsUpstreamvalue (a list of DNS server IPs, e.g. the cluster DNS Service IP). When set, the pod usesdnsPolicy: Nonewith the sidecar as its only nameserver, and the sidecar forwards to those IPs instead of reading the kubelet'sresolv.conf. NosubPathmount remains. Init containers cannot resolve names in that mode, because they run before the sidecar starts.Default behaviour is unchanged when
corednsUpstreamis empty.Testing: new Helm-template tests cover the directory mount, the
dnsPolicy: Noneform, the forward line, and schema rejection of a non-IP entry. Four of them fail on the old chart.Note: under a Kata config with
shared_fs = "none"(block-device rootfs), the existingsubPathmounts worked in our tests. SocorednsUpstreammatters for runtimes and configs that really lacksubPathsupport. TheCorefiledirectory mount is a portability improvement either way.