New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
support fetching containerd from non public GCS buckets #7771
Conversation
- add support to fetch and download containerd tarball from GCS buckets that require authentication. GCS_BUCKET_TOKEN should have read access to the bucket from which artifacts are to be fetched. The token is expected to be present in the instance metadata of the VM, similar to other node environment variables Signed-off-by: Akhil Mohan <makhil@vmware.com>
Hi @akhilerm. Thanks for your PR. I'm waiting for a containerd member to verify that this patch is reasonable to test. If it is, they should reply with Once the patch is verified, the new status will be reflected by the I understand the commands that are listed here. Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. |
/cc @estesp @samuelkarp |
@@ -104,6 +104,15 @@ if [ -f "${CONTAINERD_HOME}/${CONTAINERD_ENV_METADATA}" ]; then | |||
source "${CONTAINERD_HOME}/${CONTAINERD_ENV_METADATA}" | |||
fi | |||
|
|||
# GCS_BUCKET_TOKEN_METADATA is the metadata key for the GCS bucket token |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Is it okay to keep set -o xtrace
on the top of this file? I'm fine removing that to be honest.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I dont want to remove tracing from the file, as it greatly helps with debugging the tests. Will figure out a way so that the token is not directly printed into the logs.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
@kzys Have updated the changes so that tracing is disabled when dealing with tokens
Signed-off-by: Akhil Mohan <makhil@vmware.com>
/cc @kzys |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM
GCS_BUCKET_TOKEN should have read access to the bucket from which artifacts are to be fetched. The token is expected to be present in the instance metadata of the VM, similar to other node environment variables
Signed-off-by: Akhil Mohan makhil@vmware.com
To use this in tests from kubernetes, a new node env can be added as follows here.
<your_gcs_bucket_token>
can be fetched from a secret or from an env.