-
Notifications
You must be signed in to change notification settings - Fork 38.6k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
check duplicate toleration of pod template with effect and key #124964
base: master
Are you sure you want to change the base?
check duplicate toleration of pod template with effect and key #124964
Conversation
This issue is currently awaiting triage. If a SIG or subproject determines this is a relevant issue, they will accept it by applying the The Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
Hi @olderTaoist. Thanks for your PR. I'm waiting for a kubernetes member to verify that this patch is reasonable to test. If it is, they should reply with Once the patch is verified, the new status will be reflected by the I understand the commands that are listed here. Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
@@ -3938,6 +3938,8 @@ func ValidateHostAliases(hostAliases []core.HostAlias, fldPath *field.Path) fiel | |||
// ValidateTolerations tests if given tolerations have valid data. | |||
func ValidateTolerations(tolerations []core.Toleration, fldPath *field.Path) field.ErrorList { | |||
allErrors := field.ErrorList{} | |||
|
|||
uniqueTaints := map[core.TaintEffect]sets.Set[string]{} |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I guess using map[string]core.TaintEffect
would seem simpler?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
yeah, just unique with Toleration.Key
、Toleration.Operator
、Toleration.Value
、Toleration.Effect
if len(uniqueTaints[toleration.Effect]) > 0 && uniqueTaints[toleration.Effect].Has(toleration.Key) { | ||
duplicatedError := field.Duplicate(idxPath, toleration) | ||
duplicatedError.Detail = "taints must be unique by key and effect pair" | ||
allErrors = append(allErrors, duplicatedError) |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I'm afraid this will be a breaking change for the to be created Pods/PodTemplates but also for the existing ones.
To be checked with the maintainers, but maybe all we can do is deduplicate the tolerations before storing and make sure duplication doesn't break equality...
If we really want to enforce this for new objects, we'll need to migrate/deduplicate the existing ones in the store (maybe sth like https://kubernetes.io/docs/tasks/manage-kubernetes-objects/storage-version-migration/ could help) and then we can require this.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
duplicate toleration error will be prompted when the existing one with duplicate toleration is updated, but I think it is acceptable, because an update operation occurs, the pod will be rebuilt. At this time, duplicate toleration in pod template is removed.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
i aslo add UniqueToleration
feature gate
3a5e689
to
dab18b4
Compare
[APPROVALNOTIFIER] This PR is NOT APPROVED This pull-request has been approved by: olderTaoist The full list of commands accepted by this bot can be found here.
Needs approval from an approver in each of these files:
Approvers can indicate their approval by writing |
PR needs rebase. Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
It looks a API change to me. Please refer to API review process for review: https://github.com/kubernetes/community/blob/master/sig-architecture/api-review-process.md /remove-sig api-machinery |
What type of PR is this?
/kind feature
What this PR does / why we need it:
duplicate tolerations are not being ignored and are applied to resources, potentially resulting in unintended behaviors.
Which issue(s) this PR fixes:
Fixes #124881
Special notes for your reviewer:
Does this PR introduce a user-facing change?
Additional documentation e.g., KEPs (Kubernetes Enhancement Proposals), usage docs, etc.: