dagster 1.12.8 has no per-deployment imagePullSecrets field: deployment-user.yaml reads the dagster-user-deployments subchart value and the run launcher helper reads the parent chart value. The pull secret nested under the deployments[] entry was silently discarded, which would have produced ImagePullBackOff against a values file that reads as correct. Also records the unresolved 1.13.19 vs 1.12.8 skew between these images and the sandbox control plane. Changelog: fixed
79 lines
3.6 KiB
YAML
79 lines
3.6 KiB
YAML
# Sandbox deployment values - Gitea registry.
|
|
#
|
|
# NOT CLUSTER-VERIFIED. These values are written against images that exist and a
|
|
# registry whose auth behaviour was checked, but they have not been applied to a
|
|
# Simpl cluster. Confirm and amend after the first deployment.
|
|
#
|
|
# VERSION SKEW, unresolved. These images carry dagster 1.13.19 (requirements.txt
|
|
# pins no upper bound, so the build took whatever was current). The sandbox
|
|
# control plane is 1.12.8. A code server is a gRPC server the webserver and
|
|
# daemon call into, so the two versions have to be compatible; a minor-version
|
|
# gap is not a supported configuration. Pin dagster to the control plane version
|
|
# and rebuild before reading a failure here as a bug in this service.
|
|
#
|
|
# Use these instead of the code.europa.eu references in
|
|
# yaml/values-dagster-distributed-execution.yaml and
|
|
# yaml/loosely-coupled/values-pipes-payload.yaml when deploying to the
|
|
# dataprovider01 sandbox. Both images were built and published by a Gitea Actions
|
|
# workflow held in the sandbox Gitea mirror of this repository, not here.
|
|
#
|
|
# The tag below is a short commit SHA and is the same for both images. That is
|
|
# the version lock: the code location and the payload it dispatches must come
|
|
# from one commit. Bump both together or not at all.
|
|
#
|
|
# The sandbox Gitea registry requires authentication - an anonymous manifest GET
|
|
# returns 401 - so a pull secret is required in every namespace that pulls either
|
|
# image. Create it with a Gitea access token that has read:package scope:
|
|
#
|
|
# kubectl -n <namespace> create secret docker-registry gitea-registry \
|
|
# --docker-server=gitea.dataprovider01.sandbox-cat-dat.simpl-europe.eu \
|
|
# --docker-username=<gitea-user> \
|
|
# --docker-password=<gitea-token>
|
|
#
|
|
# The payload namespace needs it too: PipesK8sClient creates that Job, and a
|
|
# missing pull secret there leaves the op waiting on a pod that never starts,
|
|
# which surfaces as pod_wait_timeout rather than as an image error.
|
|
#
|
|
# PULL SECRET PLACEMENT. Checked against the chart templates in dagster 1.12.8,
|
|
# which is what the sandbox runs. There is no per-deployment imagePullSecrets
|
|
# field - deployment-user.yaml reads the SUBCHART value and the run launcher
|
|
# helper reads the PARENT value - so a pull secret nested under a deployments[]
|
|
# entry is silently discarded, and the pod fails with ImagePullBackOff against a
|
|
# values file that looks correct.
|
|
#
|
|
# Both keys below therefore apply to every code location in the release, not
|
|
# just this one. Extra pull secrets are ignored for registries they do not match,
|
|
# so the existing code locations are unaffected.
|
|
|
|
dagster:
|
|
# Run pods, webserver and daemon.
|
|
imagePullSecrets:
|
|
- name: gitea-registry
|
|
|
|
dagster-user-deployments:
|
|
# Code server pods.
|
|
imagePullSecrets:
|
|
- name: gitea-registry
|
|
deployments:
|
|
- name: distributed-execution
|
|
image:
|
|
repository: gitea.dataprovider01.sandbox-cat-dat.simpl-europe.eu/j.r/distributed-execution
|
|
tag: 5122da4691f9
|
|
pullPolicy: IfNotPresent
|
|
env:
|
|
- name: PIPES_PAYLOAD_IMAGE
|
|
value: gitea.dataprovider01.sandbox-cat-dat.simpl-europe.eu/j.r/distributed-execution-payload:5122da4691f9
|
|
- name: PIPES_PAYLOAD_NAMESPACE
|
|
value: dagster
|
|
|
|
runLauncher:
|
|
config:
|
|
k8sRunLauncher:
|
|
runK8sConfig:
|
|
containerConfig:
|
|
env:
|
|
- name: PIPES_PAYLOAD_IMAGE
|
|
value: gitea.dataprovider01.sandbox-cat-dat.simpl-europe.eu/j.r/distributed-execution-payload:5122da4691f9
|
|
- name: PIPES_PAYLOAD_NAMESPACE
|
|
value: dagster
|