fix: lock rke2-common and pin rke2 to 1.33.13~rke2r2 to unblock puppet #516
Reference in New Issue
Block a user
Delete Branch "benvin/rke2-common-versionlock-drift"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Why
Every puppet run on k8s nodes (e.g. prodnxsr0002) fails on
Package[rke2-server]and stops applying the rest of the catalog, so the nodes stop receiving all further package/config updates:rke2::installversionlocks onlyrke2-server/rke2-agent, never their strict (= version)rke2-commondependency.rke2-commonis served from the rollingrancher-rke2-1.33-latestchannel, whose head is now1.33.13~rke2r2, sorke2-commondrifted up to1.33.13~rke2r2while the pin (#512) sat at1.33.11~rke2r1.dnf upgradecannot downgrade the newerrke2-commonto satisfy the older server, so the transaction fails. This is the rolling-channel drift#512flagged as needing follow-up.How
rke2-commonto the same${rke2_version}~${rke2_release}as the server/agent, so the rolling channel can no longer drift the dependency ahead of the pin.rke2_version1.33.11->1.33.13andrke2_releaserke2r1->rke2r2to match the current channel head and the already-drifted installedrke2-common, so the pinned server/agent, both versionlocks, and the preloaded airgap bundle resolve in one transaction.Verified against the live artifactapi rke2 remote:
rke2-server-1.33.13~rke2r2-0.el9.x86_64.rpmand thev1.33.13+rke2r2rke2-images.linux-amd64.tar.zstairgap bundle both serve HTTP 200.## Why k8s nodes fail every puppet run on Package[rke2-server] and stop applying the rest of their catalog (no further package/config updates): change from '1.33.4~rke2r1-1.el9' to '1.33.11~rke2r1' failed: dnf upgrade rke2-server-1.33.11~rke2r1 returned 1: Problem: problem with installed package rke2-common-1.33.13~rke2r2-0.el9 - package rke2-server-1.33.11~rke2r1 requires rke2-common = 1.33.11~rke2r1, but none of the providers can be installed - cannot install the best update candidate for rke2-server The module versionlocks only rke2-server/rke2-agent, not their strict (= version) rke2-common dependency. rke2-common is pulled from the rolling rancher-rke2-1.33-latest channel, whose head is now 1.33.13~rke2r2, so rke2-common drifted up to 1.33.13~rke2r2 while the pin sat at 1.33.11~rke2r1. dnf upgrade can't downgrade the newer rke2-common to satisfy the older server, so the transaction fails. ## Changes - Versionlock rke2-common to the same ${rke2_version}~${rke2_release} as the server/agent, so the rolling channel can no longer drift the dependency ahead of the pin. - Bump rke2_version 1.33.11 -> 1.33.13 and rke2_release rke2r1 -> rke2r2 to match the current channel head (and the already-drifted installed rke2-common), so the pinned server/agent, versionlocks, and preloaded airgap bundle all resolve in one transaction.