Releases: loft-demos/pod-node
Release list
v0.6.0: Startup resilience, kubelet clamp CI, and diagnostics improvements
Changelog (v0.6.0)
Summary
v0.6.0 improves pod-node startup robustness, adds CI smoke coverage for kubelet flag clamping, and expands operational diagnostics/documentation for vCluster Platform Auto Nodes.
Added
- Added
PODNODE_PODSsupport in kubelet clamp logic to set--max-pods. - Added startup fail-fast checks in
podnode-entrypoint.shto verify required executables exist before continuing. - Added CI workflow (
.github/workflows/ci.yaml) with:- shell syntax checks
- clamp smoke test execution
- Added smoke test script (
tests/smoke-clamp.sh) to validate kubeadm flag patching behavior.
Changed
- Refactored Docker image setup to use file-based scripts rather than large inline Dockerfile heredocs.
- Updated clamp script to patch kubelet args idempotently (replace existing managed flags before re-adding).
- Added testability overrides to clamp script:
PODNODE_KUBEADM_FLAGS_PATHPODNODE_HOST_CPU_CORESPODNODE_HOST_MEM_KI
- Reverted to stable cgroup startup flow (
unshare+ helper scripts) after runtime instability with the no-escape variant. - Made cgroup setup more tolerant:
create-kubelet-cgroup.shnow warns and drains remaining root cgroup PIDs intoinit.scopeinstead of exiting hard.
Removed
- Removed deprecated GitHub Actions
::set-outputusage from release workflow.
Documentation
- Updated README with:
- env-based sizing guidance (
PODNODE_CPU,PODNODE_MEMORY,PODNODE_PODS) - vCluster Platform Auto Nodes / Pod NodeProvider configuration pattern
- clarified
allocatablevscapacitybehavior in this model - runtime diagnostics commands for troubleshooting startup/clamp behavior
- env-based sizing guidance (
Notes
- In this pod-node model, CPU/memory
allocatableis clamped from env values; CPU/memorycapacitymay still reflect host-detected values. - For best consistency, keep NodeProvider
resources.requests == resources.limits(Guaranteed QoS).
v0.5.0: Startup hardening, max-pods support, and CI smoke tests
Release Notes
Summary
This release hardens pod-node startup reliability, adds CI validation for kubelet flag clamping, and improves operational diagnostics for vCluster Platform Auto Nodes.
Highlights
Reliability
- Restored stable cgroup startup flow (
unshare+ helper scripts) used by systemd/kubelet bootstrap. - Added startup fail-fast checks in
podnode-entrypoint.shfor required executables:/entrypoint.sh/usr/local/bin/podnode-clamp-allocatable.sh/escape-cgroup.sh/create-kubelet-cgroup.sh
- If required scripts are missing, container exits with a clear error message instead of failing later in bootstrap.
Node Sizing Behavior
PODNODE_CPUandPODNODE_MEMORYcontinue to clamp kubelet allocatable via kubelet args patching.PODNODE_PODSsupport remains enabled and sets kubelet--max-pods.- Kubelet arg patching remains idempotent (existing flags are replaced cleanly on reruns).
CI / Testing
- Added GitHub Actions CI workflow (
.github/workflows/ci.yaml) for:- shell syntax checks
- clamp smoke test execution
- Added smoke test (
tests/smoke-clamp.sh) that verifies kubelet args updates include:--kube-reserved--system-reserved--enforce-node-allocatable- reserved cgroup flags
--max-pods
Documentation
- README updated with:
- clarified behavior around
allocatablevscapacity - runtime diagnostics commands for troubleshooting
- vCluster Platform Auto Nodes NodeProvider guidance and env/resource mapping
- clarified behavior around
Operator Notes
- Use immutable image tags for NodeProvider updates.
- Ensure NodeProvider sets:
PODNODE_CPUPODNODE_MEMORYPODNODE_PODS
- Keep
resources.requests == resources.limitsfor Guaranteed QoS. - In this model, CPU/memory
allocatableis clamped from env values; CPU/memorycapacitymay still reflect host-detected values.
Add Capacity Based on Pod
Changelog (2026-02-28)
Changed
- Simplified image startup by removing inline Dockerfile scripts and using file-backed scripts.
- Updated entrypoint flow to run systemd/kubelet inside the pod cgroup (removed cgroup escape/unshare path) so node CPU/memory capacity follows pod resource limits.
- Refactored kubelet flag clamping to patch
kubeadm-flags.envdirectly with idempotent replacement behavior.
Added
- Added
PODNODE_PODSsupport to set kubelet--max-pods. - Added
podnode-entrypoint.shwrapper to run allocatable clamping before the original startup flow.
Removed
- Removed unused cgroup escape helpers:
files/escape-cgroup.shfiles/create-kubelet-cgroup.sh
Documentation
- Added README documentation for env-based sizing:
PODNODE_CPUPODNODE_MEMORYPODNODE_PODS
- Added vCluster Platform Auto Nodes / Pod NodeProvider configuration guidance.
- Added explicit Terraform pattern showing
requests == limitsand NodeType resource mapping. - Added post-deploy verification commands for node
capacityandallocatable.
Major Clean up with Pod Limits
Changelog (2026-02-28)
Changed
- Simplified the
Dockerfileby removing large inline heredoc scripts. - Switched to file-based startup scripts (
files/*) for easier maintenance and review. - Startup now runs through
podnode-entrypoint.sh, which launches allocatable clamping and then hands off to the originalentrypoint.sh.
Added
- Added support for pod-capacity sizing via
PODNODE_PODS. podnode-clamp-allocatable.shnow sets kubelet--max-podswhenPODNODE_PODSis provided.- Added idempotent kubelet flag rewriting so repeated runs replace old values cleanly (CPU, memory, allocatable flags, cgroup flags, and max pods).
Improved
- Clamping logic now waits for kubelet bootstrap flags file (
/var/lib/kubelet/kubeadm-flags.env) and patches kubeadm args directly. - CPU and memory allocatable behavior remains driven by
PODNODE_CPUandPODNODE_MEMORY.
Documentation
- Updated
README.mdwith:- Env-based node sizing (
PODNODE_CPU,PODNODE_MEMORY,PODNODE_PODS) - Example env block
- New section for vCluster Platform Auto Nodes + Pod NodeProvider integration and Terraform mapping from NodeType resources.
- Env-based node sizing (
Working Version
Full Changelog: v0.1.7...v0.2.0
First working version, but overly complicated.
Allocation Fix 8
Allocation Fix 7
Allocation Fix 6
v0.1.5: Update Dockerfile
Add:
--enforce-node-allocatable=pods,kube-reserved,system-reserved
to the KUBELET_EXTRA_ARGS you write into /etc/vcluster/vcluster-flags.env.
Allocation Fix 4
updated Dockerfile that embeds:
• a watcher script
• a helper that computes reserves
• a shim entrypoint that starts the watcher in the background and then execs your existing /entrypoint.sh