From 69f2a2a6ece0da78dd1c578736497dd947450f23 Mon Sep 17 00:00:00 2001 From: unkin-agent Date: Sat, 10 Oct 2026 01:06:10 +1100 Subject: [PATCH] add artifactapi image-keeper daemonset (#535) artifactapi pulls its own images from itself, so a cold boot with every api pod down cannot pull them. Kubelet GC never removes images referenced by pods on the node, so a pod on every node holding the pinned tags keeps them local. - add image-keeper DaemonSet referencing the api and ui images as no-op init containers - run a static busybox as `true` inside the distroless api image - tolerate all taints, run at low priority with tiny non-root resources Reviewed-on: https://git.unkin.net/unkin/argocd-apps/pulls/535 Co-authored-by: unkin-agent Co-committed-by: unkin-agent --- apps/base/artifactapi/image-keeper.yaml | 105 +++++++++++++++++++++++ apps/base/artifactapi/kustomization.yaml | 1 + 2 files changed, 106 insertions(+) create mode 100644 apps/base/artifactapi/image-keeper.yaml diff --git a/apps/base/artifactapi/image-keeper.yaml b/apps/base/artifactapi/image-keeper.yaml new file mode 100644 index 0000000..49488cd --- /dev/null +++ b/apps/base/artifactapi/image-keeper.yaml @@ -0,0 +1,105 @@ +--- +apiVersion: apps/v1 +kind: DaemonSet +metadata: + name: image-keeper + namespace: artifactapi +spec: + selector: + matchLabels: + app: image-keeper + updateStrategy: + rollingUpdate: + maxUnavailable: 25% + type: RollingUpdate + template: + metadata: + labels: + app: image-keeper + spec: + automountServiceAccountToken: false + priorityClassName: low + tolerations: + - operator: Exists + securityContext: + runAsNonRoot: true + runAsUser: 65532 + runAsGroup: 65532 + seccompProfile: + type: RuntimeDefault + initContainers: + # artifactapi is distroless with no exit-0 flag, so run a static busybox as `true` + - name: copy-true + image: busybox:1.37.0-musl + imagePullPolicy: IfNotPresent + command: ["cp", "/bin/busybox", "/keeper/true"] + volumeMounts: + - name: keeper + mountPath: /keeper + resources: + limits: + cpu: 10m + memory: 16Mi + requests: + cpu: 1m + memory: 4Mi + securityContext: + allowPrivilegeEscalation: false + readOnlyRootFilesystem: true + capabilities: + drop: ["ALL"] + - name: api + image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/artifactapi:v3.13.1 + imagePullPolicy: IfNotPresent + command: ["/keeper/true"] + volumeMounts: + - name: keeper + mountPath: /keeper + readOnly: true + resources: + limits: + cpu: 10m + memory: 16Mi + requests: + cpu: 1m + memory: 4Mi + securityContext: + allowPrivilegeEscalation: false + readOnlyRootFilesystem: true + capabilities: + drop: ["ALL"] + - name: ui + image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/artifactapi-ui:v3.13.1 + imagePullPolicy: IfNotPresent + command: ["true"] + resources: + limits: + cpu: 10m + memory: 16Mi + requests: + cpu: 1m + memory: 4Mi + securityContext: + allowPrivilegeEscalation: false + readOnlyRootFilesystem: true + capabilities: + drop: ["ALL"] + containers: + - name: pause + image: rancher/mirrored-pause:3.6 + imagePullPolicy: IfNotPresent + resources: + limits: + cpu: 10m + memory: 16Mi + requests: + cpu: 1m + memory: 4Mi + securityContext: + allowPrivilegeEscalation: false + readOnlyRootFilesystem: true + capabilities: + drop: ["ALL"] + volumes: + - name: keeper + emptyDir: {} diff --git a/apps/base/artifactapi/kustomization.yaml b/apps/base/artifactapi/kustomization.yaml index 6053989..27b0815 100644 --- a/apps/base/artifactapi/kustomization.yaml +++ b/apps/base/artifactapi/kustomization.yaml @@ -11,6 +11,7 @@ resources: - cnpg_pooler.yaml - gateway.yaml - httproute.yaml + - image-keeper.yaml - namespace.yaml - oauth2-proxy-configmap.yaml - oauth2-proxy-deployment.yaml