-
Notifications
You must be signed in to change notification settings - Fork 1.6k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Failure to load images with kind v0.26.0 and kindes/node:v1.32.1 #3853
Comments
/assign @BenTheElder since he was discussing this with @AkihiroSuda recently during the upgrade to containerd 2.0, that seems that fixed the problem |
Looks like the kindest/node image was updated to containerd v2 ahead of the new release of the kind cmd. The kind cmd should have a new release, or, the image should be reverted |
Thanks, that was my thinking as well. I think either of them would work for us. |
See kubernetes-sigs/kind#3853 for issues fixes spiffe#5812 Signed-off-by: Sorin Dumitru <sdumitru@bloomberg.net>
See kubernetes-sigs/kind#3853 for issues fixes spiffe#5812 Signed-off-by: Sorin Dumitru <sdumitru@bloomberg.net>
See kubernetes-sigs/kind#3853 for issues fixes spiffe#5812 Signed-off-by: Sorin Dumitru <sdumitru@bloomberg.net>
See kubernetes-sigs/kind#3853 for issues fixes #5812 Signed-off-by: Sorin Dumitru <sdumitru@bloomberg.net>
FYI: new images like this are not necessarily supported with old releases (see the release notes and the docs which both clearly warn about image selection) This one should be working though. |
We will do a new release. But it is not a safe assumption that you can use any image with any release and every release's notes discuss this with the listed images as does the quick start docs section about changing versions / images. Further those docs warn that you should use images by digest for security and to avoid this. /close |
@BenTheElder: Closing this issue. In response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
Also noting that this does not collide with any previously existing tags (v1.32.0 was the tag available for 0.27? but it could have given we advertise the digests and instruct users to use the digests for exact images |
You should scrape the release notes instead of the docker hub tags. We can and have made breaking changes before by necessity to fix bugs. We avoid them where possible but don't guarantee it. This is one such example, we need to keep up with containerd. Really you should just select specific images and not scrape anything. These images run with full privileges and pulling random unvetted images is a serious risk, if you pull by digest then even if we are temporarily compromised you cannot be impacted. |
There is some possible discussion in open issues of using another tag scheme in the future, but the discussion has yet to settle. |
Is release notes in a reliable format that you can regex in a script? |
We are currently doing something like this to get latest k8s versions to use in CI. (here)
|
Avoid loading the images due to a known issue that makes kind v0.26.0 with kindest/node v1.32.1 fails when loading the images. This issue was reported here kubernetes-sigs/kind#3853 Signed-off-by: Jonathan Gonzalez V. <jonathan.gonzalez@enterprisedb.com>
Avoid loading the images due to a known issue that makes kind v0.26.0 with kindest/node v1.32.1 fails when loading the images. This issue was reported here kubernetes-sigs/kind#3853 Signed-off-by: Jonathan Gonzalez V. <jonathan.gonzalez@enterprisedb.com>
Avoid loading the images due to a known issue that makes kind v0.26.0 with kindest/node v1.32.1 fails when loading the images. This issue was reported here kubernetes-sigs/kind#3853 Signed-off-by: Jonathan Gonzalez V. <jonathan.gonzalez@enterprisedb.com> (cherry picked from commit 69a65e7)
Avoid loading the images due to a known issue that makes kind v0.26.0 with kindest/node v1.32.1 fails when loading the images. This issue was reported here kubernetes-sigs/kind#3853 Signed-off-by: Jonathan Gonzalez V. <jonathan.gonzalez@enterprisedb.com> (cherry picked from commit 69a65e7)
Avoid loading the images due to a known issue that makes kind v0.26.0 with kindest/node v1.32.1 fails when loading the images. This issue was reported here kubernetes-sigs/kind#3853 Signed-off-by: Jonathan Gonzalez V. <jonathan.gonzalez@enterprisedb.com> (cherry picked from commit 69a65e7)
We're still hoping for another containerd release with some some fixes for testing Kubernetes, otherwise I'm personally out a lot at the moment for personal reasons so it may be a bit before we officially release with this image. (To be clear, I am not the only person that can release, but I can't speak on anyone else's behalf) |
woot. perhaps I can use default node image of cli as upper bound in my prior script. |
This MR contains the following updates: | Package | Update | Change | |---|---|---| | [kubernetes-sigs/kind](https://github.com/kubernetes-sigs/kind) | minor | `v0.26.0` -> `v0.27.0` | MR created with the help of [el-capitano/tools/renovate-bot](https://gitlab.com/el-capitano/tools/renovate-bot). **Proposed changes to behavior should be submitted there as MRs.** --- ### Release Notes <details> <summary>kubernetes-sigs/kind (kubernetes-sigs/kind)</summary> ### [`v0.27.0`](https://github.com/kubernetes-sigs/kind/releases/tag/v0.27.0) [Compare Source](kubernetes-sigs/kind@v0.26.0...v0.27.0) **This release moves kind to containerd 2.x** and contains fixes for nerdctl. It also moves Kubernetes to 1.32.2 by default. <h1 id="breaking-changes">Breaking Changes</h1> **WARNING**: kind v0.27.0+ will be required to use `kind load ...` subcommands with these new containerd 2.0+ images (built by kind v0.27+). For other use cases, the new images should still work with recent kind releases, but are not guaranteed. As always we *strongly* recommend consuming images by their `sha256` digest for security and reliability. kubernetes-sigs/kind#3853 Older images from recent releases should continue to work with kind v0.27.0+. **NOTE**: As [previously warned](https://github.com/kubernetes-sigs/kind/releases/tag/v0.20.0) containerd 2.x requires that you must be using `config_path` mode for containerd registry config. If you're using the [local registry script](https://kind.sigs.k8s.io/docs/user/local-registry/) at, or more recent than kubernetes-sigs/kind@791b3dc (kind v0.20.0 / May 22, 2023) then no changes should be necessary. The default node image is now `kindest/node:v1.32.2@​sha256:f226345927d7e348497136874b6d207e0b32cc52154ad8323129352923a3142f` <h1 id="new-features">New Features</h1> - Updated to containerd 2.x - Updated default node image to Kubernetes 1.32.2 - Updated go to 1.23.6 Images pre-built for this release: - v1.32.2: `kindest/node:v1.32.2@​sha256:f226345927d7e348497136874b6d207e0b32cc52154ad8323129352923a3142f` - v1.31.6: `kindest/node:v1.30.6@​sha256:28b7cbb993dfe093c76641a0c95807637213c9109b761f1d422c2400e22b8e87` - v1.30.10: `kindest/node:v1.30.10@​sha256:4de75d0e82481ea846c0ed1de86328d821c1e6a6a91ac37bf804e5313670e507` - v1.29.14: `kindest/node:v1.29.14@​sha256:8703bd94ee24e51b778d5556ae310c6c0fa67d761fae6379c8e0bb480e6fea29` **NOTE**: You *must* use the `@sha256` digest to guarantee an image built for this release, until such a time as we switch to a different tagging scheme. Even then we will highly encourage digest pinning for security and reproducibility reasons. See also: - https://kind.sigs.k8s.io/docs/user/quick-start/#creating-a-cluster - https://kind.sigs.k8s.io/docs/user/quick-start/#building-images NOTE: These node images support amd64 and arm64, both of our supported platforms. **You must use the same platform as your host,** for more context see kubernetes-sigs/kind#2718 <h1 id="fixes">Fixes</h1> - Compatibility fixes for containerd 2.x - Fix `kind get clusters` with nerdctl - Statically link CNI binaries to match upstream - Fix no-arguments validation for multiple subcommands - Update shellescape dependency to current vanity import - When building node images: wait for containerd to be ready, and retry image pulls <h1 id="contributors">Contributors</h1> **Thank you to everyone who contributed to this kind over the years!** Committers for this release: - [@​AkihiroSuda](https://github.com/AkihiroSuda) - [@​BenTheElder](https://github.com/BenTheElder) - [@​bobsongplus](https://github.com/bobsongplus) - [@​dependeabot](https://github.com/dependeabot)\[bot] - [@​dims](https://github.com/dims) - [@​k8s-ci-robot](https://github.com/k8s-ci-robot) - [@​kachick](https://github.com/kachick) - [@​stmcginnis](https://github.com/stmcginnis) - [@​tao12345666333](https://github.com/tao12345666333) - [@​yashvardhan-kukreja](https://github.com/yashvardhan-kukreja) </details> --- ### Configuration 📅 **Schedule**: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined). 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever MR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this MR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this MR, check this box --- This MR has been generated by [Renovate Bot](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzOS4xNzEuMiIsInVwZGF0ZWRJblZlciI6IjM5LjE3MS4yIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJSZW5vdmF0ZSBCb3QiXX0=-->
What happened:
Our CI tries to figure out the latest versions of kind and kindest/node to run integration tests against various k8s versions. After the image with v1.32.1 (roughly, I know it worked on Tuesday the 21st, but not on Thursday the 23rd) we started seeing CI failures for the combination of kind 0.26.0 and kindes/node v1.32.1. The error occurs when trying to load an image into the cluster:
See also our issue for the build failing spiffe/spire#5812
Doing some more experiments from main I can see that:
So it's safe to say that 586b038 is what makes it work, but what makes it break is the new image for v1.32.1
What you expected to happen:
To be able to load images.
How to reproduce it (as minimally and precisely as possible):
Anything else we need to know?:
Environment:
Linux
kind version
): v0.26.0docker info
,podman info
ornerdctl info
):/etc/os-release
):Arch Linux (my laptop)/Ubuntu 22.04 for CI
kubectl version
):v1.32.1
No
The text was updated successfully, but these errors were encountered: