From b47c530d468752366edcb969d571683d1cf2ae6e Mon Sep 17 00:00:00 2001 From: ILay Date: Mon, 31 Aug 2026 17:34:18 +0200 Subject: [PATCH] [SIMPL-30451] Put the sandbox pull secrets where the chart actually reads them dagster 1.12.8 has no per-deployment imagePullSecrets field: deployment-user.yaml reads the dagster-user-deployments subchart value and the run launcher helper reads the parent chart value. The pull secret nested under the deployments[] entry was silently discarded, which would have produced ImagePullBackOff against a values file that reads as correct. Also records the unresolved 1.13.19 vs 1.12.8 skew between these images and the sandbox control plane. Changelog: fixed --- yaml/sandbox/values-sandbox-gitea.yaml | 29 ++++++++++++++++++++++---- 1 file changed, 25 insertions(+), 4 deletions(-) diff --git a/yaml/sandbox/values-sandbox-gitea.yaml b/yaml/sandbox/values-sandbox-gitea.yaml index 949cc63..1d7be11 100644 --- a/yaml/sandbox/values-sandbox-gitea.yaml +++ b/yaml/sandbox/values-sandbox-gitea.yaml @@ -4,6 +4,13 @@ # registry whose auth behaviour was checked, but they have not been applied to a # Simpl cluster. Confirm and amend after the first deployment. # +# VERSION SKEW, unresolved. These images carry dagster 1.13.19 (requirements.txt +# pins no upper bound, so the build took whatever was current). The sandbox +# control plane is 1.12.8. A code server is a gRPC server the webserver and +# daemon call into, so the two versions have to be compatible; a minor-version +# gap is not a supported configuration. Pin dagster to the control plane version +# and rebuild before reading a failure here as a bug in this service. +# # Use these instead of the code.europa.eu references in # yaml/values-dagster-distributed-execution.yaml and # yaml/loosely-coupled/values-pipes-payload.yaml when deploying to the @@ -26,17 +33,33 @@ # The payload namespace needs it too: PipesK8sClient creates that Job, and a # missing pull secret there leaves the op waiting on a pod that never starts, # which surfaces as pod_wait_timeout rather than as an image error. +# +# PULL SECRET PLACEMENT. Checked against the chart templates in dagster 1.12.8, +# which is what the sandbox runs. There is no per-deployment imagePullSecrets +# field - deployment-user.yaml reads the SUBCHART value and the run launcher +# helper reads the PARENT value - so a pull secret nested under a deployments[] +# entry is silently discarded, and the pod fails with ImagePullBackOff against a +# values file that looks correct. +# +# Both keys below therefore apply to every code location in the release, not +# just this one. Extra pull secrets are ignored for registries they do not match, +# so the existing code locations are unaffected. dagster: + # Run pods, webserver and daemon. + imagePullSecrets: + - name: gitea-registry + dagster-user-deployments: + # Code server pods. + imagePullSecrets: + - name: gitea-registry deployments: - name: distributed-execution image: repository: gitea.dataprovider01.sandbox-cat-dat.simpl-europe.eu/j.r/distributed-execution tag: 5122da4691f9 pullPolicy: IfNotPresent - imagePullSecrets: - - name: gitea-registry env: - name: PIPES_PAYLOAD_IMAGE value: gitea.dataprovider01.sandbox-cat-dat.simpl-europe.eu/j.r/distributed-execution-payload:5122da4691f9 @@ -46,8 +69,6 @@ dagster: runLauncher: config: k8sRunLauncher: - imagePullSecrets: - - name: gitea-registry runK8sConfig: containerConfig: env: