Repository navigation
v0.5.0: Startup hardening, max-pods support, and CI smoke tests
Release Notes
Summary
This release hardens pod-node startup reliability, adds CI validation for kubelet flag clamping, and improves operational diagnostics for vCluster Platform Auto Nodes.
Highlights
Reliability
- Restored stable cgroup startup flow (
unshare+ helper scripts) used by systemd/kubelet bootstrap. - Added startup fail-fast checks in
podnode-entrypoint.shfor required executables:/entrypoint.sh/usr/local/bin/podnode-clamp-allocatable.sh/escape-cgroup.sh/create-kubelet-cgroup.sh
- If required scripts are missing, container exits with a clear error message instead of failing later in bootstrap.
Node Sizing Behavior
PODNODE_CPUandPODNODE_MEMORYcontinue to clamp kubelet allocatable via kubelet args patching.PODNODE_PODSsupport remains enabled and sets kubelet--max-pods.- Kubelet arg patching remains idempotent (existing flags are replaced cleanly on reruns).
CI / Testing
- Added GitHub Actions CI workflow (
.github/workflows/ci.yaml) for:- shell syntax checks
- clamp smoke test execution
- Added smoke test (
tests/smoke-clamp.sh) that verifies kubelet args updates include:--kube-reserved--system-reserved--enforce-node-allocatable- reserved cgroup flags
--max-pods
Documentation
- README updated with:
- clarified behavior around
allocatablevscapacity - runtime diagnostics commands for troubleshooting
- vCluster Platform Auto Nodes NodeProvider guidance and env/resource mapping
- clarified behavior around
Operator Notes
- Use immutable image tags for NodeProvider updates.
- Ensure NodeProvider sets:
PODNODE_CPUPODNODE_MEMORYPODNODE_PODS
- Keep
resources.requests == resources.limitsfor Guaranteed QoS. - In this model, CPU/memory
allocatableis clamped from env values; CPU/memorycapacitymay still reflect host-detected values.