Skip to content

Releases: loft-demos/pod-node

v0.6.0: Startup resilience, kubelet clamp CI, and diagnostics improvements

Choose a tag to compare

@kmadel kmadel released this 01 Mar 14:11

Changelog (v0.6.0)

Summary

v0.6.0 improves pod-node startup robustness, adds CI smoke coverage for kubelet flag clamping, and expands operational diagnostics/documentation for vCluster Platform Auto Nodes.

Added

  • Added PODNODE_PODS support in kubelet clamp logic to set --max-pods.
  • Added startup fail-fast checks in podnode-entrypoint.sh to verify required executables exist before continuing.
  • Added CI workflow (.github/workflows/ci.yaml) with:
    • shell syntax checks
    • clamp smoke test execution
  • Added smoke test script (tests/smoke-clamp.sh) to validate kubeadm flag patching behavior.

Changed

  • Refactored Docker image setup to use file-based scripts rather than large inline Dockerfile heredocs.
  • Updated clamp script to patch kubelet args idempotently (replace existing managed flags before re-adding).
  • Added testability overrides to clamp script:
    • PODNODE_KUBEADM_FLAGS_PATH
    • PODNODE_HOST_CPU_CORES
    • PODNODE_HOST_MEM_KI
  • Reverted to stable cgroup startup flow (unshare + helper scripts) after runtime instability with the no-escape variant.
  • Made cgroup setup more tolerant:
    • create-kubelet-cgroup.sh now warns and drains remaining root cgroup PIDs into init.scope instead of exiting hard.

Removed

  • Removed deprecated GitHub Actions ::set-output usage from release workflow.

Documentation

  • Updated README with:
    • env-based sizing guidance (PODNODE_CPU, PODNODE_MEMORY, PODNODE_PODS)
    • vCluster Platform Auto Nodes / Pod NodeProvider configuration pattern
    • clarified allocatable vs capacity behavior in this model
    • runtime diagnostics commands for troubleshooting startup/clamp behavior

Notes

  • In this pod-node model, CPU/memory allocatable is clamped from env values; CPU/memory capacity may still reflect host-detected values.
  • For best consistency, keep NodeProvider resources.requests == resources.limits (Guaranteed QoS).

v0.5.0: Startup hardening, max-pods support, and CI smoke tests

Choose a tag to compare

@kmadel kmadel released this 01 Mar 13:09

Release Notes

Summary

This release hardens pod-node startup reliability, adds CI validation for kubelet flag clamping, and improves operational diagnostics for vCluster Platform Auto Nodes.

Highlights

Reliability

  • Restored stable cgroup startup flow (unshare + helper scripts) used by systemd/kubelet bootstrap.
  • Added startup fail-fast checks in podnode-entrypoint.sh for required executables:
    • /entrypoint.sh
    • /usr/local/bin/podnode-clamp-allocatable.sh
    • /escape-cgroup.sh
    • /create-kubelet-cgroup.sh
  • If required scripts are missing, container exits with a clear error message instead of failing later in bootstrap.

Node Sizing Behavior

  • PODNODE_CPU and PODNODE_MEMORY continue to clamp kubelet allocatable via kubelet args patching.
  • PODNODE_PODS support remains enabled and sets kubelet --max-pods.
  • Kubelet arg patching remains idempotent (existing flags are replaced cleanly on reruns).

CI / Testing

  • Added GitHub Actions CI workflow (.github/workflows/ci.yaml) for:
    • shell syntax checks
    • clamp smoke test execution
  • Added smoke test (tests/smoke-clamp.sh) that verifies kubelet args updates include:
    • --kube-reserved
    • --system-reserved
    • --enforce-node-allocatable
    • reserved cgroup flags
    • --max-pods

Documentation

  • README updated with:
    • clarified behavior around allocatable vs capacity
    • runtime diagnostics commands for troubleshooting
    • vCluster Platform Auto Nodes NodeProvider guidance and env/resource mapping

Operator Notes

  • Use immutable image tags for NodeProvider updates.
  • Ensure NodeProvider sets:
    • PODNODE_CPU
    • PODNODE_MEMORY
    • PODNODE_PODS
  • Keep resources.requests == resources.limits for Guaranteed QoS.
  • In this model, CPU/memory allocatable is clamped from env values; CPU/memory capacity may still reflect host-detected values.

Add Capacity Based on Pod

Choose a tag to compare

@kmadel kmadel released this 28 Feb 14:43

Changelog (2026-02-28)

Changed

  • Simplified image startup by removing inline Dockerfile scripts and using file-backed scripts.
  • Updated entrypoint flow to run systemd/kubelet inside the pod cgroup (removed cgroup escape/unshare path) so node CPU/memory capacity follows pod resource limits.
  • Refactored kubelet flag clamping to patch kubeadm-flags.env directly with idempotent replacement behavior.

Added

  • Added PODNODE_PODS support to set kubelet --max-pods.
  • Added podnode-entrypoint.sh wrapper to run allocatable clamping before the original startup flow.

Removed

  • Removed unused cgroup escape helpers:
    • files/escape-cgroup.sh
    • files/create-kubelet-cgroup.sh

Documentation

  • Added README documentation for env-based sizing:
    • PODNODE_CPU
    • PODNODE_MEMORY
    • PODNODE_PODS
  • Added vCluster Platform Auto Nodes / Pod NodeProvider configuration guidance.
  • Added explicit Terraform pattern showing requests == limits and NodeType resource mapping.
  • Added post-deploy verification commands for node capacity and allocatable.

Major Clean up with Pod Limits

Choose a tag to compare

@kmadel kmadel released this 28 Feb 13:22

Changelog (2026-02-28)

Changed

  • Simplified the Dockerfile by removing large inline heredoc scripts.
  • Switched to file-based startup scripts (files/*) for easier maintenance and review.
  • Startup now runs through podnode-entrypoint.sh, which launches allocatable clamping and then hands off to the original entrypoint.sh.

Added

  • Added support for pod-capacity sizing via PODNODE_PODS.
  • podnode-clamp-allocatable.sh now sets kubelet --max-pods when PODNODE_PODS is provided.
  • Added idempotent kubelet flag rewriting so repeated runs replace old values cleanly (CPU, memory, allocatable flags, cgroup flags, and max pods).

Improved

  • Clamping logic now waits for kubelet bootstrap flags file (/var/lib/kubelet/kubeadm-flags.env) and patches kubeadm args directly.
  • CPU and memory allocatable behavior remains driven by PODNODE_CPU and PODNODE_MEMORY.

Documentation

  • Updated README.md with:
    • Env-based node sizing (PODNODE_CPU, PODNODE_MEMORY, PODNODE_PODS)
    • Example env block
    • New section for vCluster Platform Auto Nodes + Pod NodeProvider integration and Terraform mapping from NodeType resources.

Working Version

Choose a tag to compare

@kmadel kmadel released this 28 Feb 13:05
95344ba

Full Changelog: v0.1.7...v0.2.0

First working version, but overly complicated.

Allocation Fix 8

Choose a tag to compare

@kmadel kmadel released this 27 Feb 18:13
95344ba

Full Changelog: v0.1.7...v0.1.8

Allocation Fix 7

Choose a tag to compare

@kmadel kmadel released this 27 Feb 17:54
b641764

Full Changelog: v0.1.6...v0.1.7

Allocation Fix 6

Choose a tag to compare

@kmadel kmadel released this 27 Feb 17:32
d6b0672

Full Changelog: v0.1.5...v0.1.6

v0.1.5: Update Dockerfile

Choose a tag to compare

@kmadel kmadel released this 27 Feb 17:13
cf9b4a9

Add:

--enforce-node-allocatable=pods,kube-reserved,system-reserved

to the KUBELET_EXTRA_ARGS you write into /etc/vcluster/vcluster-flags.env.

Allocation Fix 4

Choose a tag to compare

@kmadel kmadel released this 27 Feb 16:56
d1aa245

updated Dockerfile that embeds:
• a watcher script
• a helper that computes reserves
• a shim entrypoint that starts the watcher in the background and then execs your existing /entrypoint.sh