feat(k8s): accept image_pull_policy in the create payload - #122
Conversation
Signed-off-by: Oleksandr Piskun <oleksandr2088@icloud.com>
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (1)
Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthrough
Priority: ➖ Normal Merge Risk: ⚪ Minimal · up to The change applies the selected Kubernetes image pull policy and reports missing images under Never without waiting for the startup timeout. No concrete merge-blocking risk was found. Security Architecture ReviewSecurity architecture risk: 🟡 Moderate · up to Existing requests retain their prior behavior, but callers can now select image-loading behavior that affects which image runs and what remains deployed after a startup failure. The impact depends on image identity rules and cleanup behavior that are not established here. Retained concerns
Security review detailsSecurity Blast Radius
Security Findings and Attack Paths
Trust Boundaries and Controls
Resilience and Maintainability Implications
Hardening Proposals
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
AppAPI deploy daemons can map a registry to the special target
local, which on Docker keeps the image name and skips the pull. On Kubernetes HaRP always created the ExApp Deployment withimagePullPolicy: IfNotPresent, so there was no way to express "use only the image that is already on the node".Changes
CreateExAppPayloadaccepts an optionalimage_pull_policy(IfNotPresent,NeverorAlways, defaultIfNotPresent), and the Kubernetes Deployment manifest uses it. The Docker backend ignores the field.ErrImageNeverPull, so aNeverpolicy without the image on the node is reported within seconds instead of after the startup timeout.Related: nextcloud/app_api#1046 sends
image_pull_policy: Neverfor alocalregistry mapping. Older HaRP versions ignore the field and keep the current behaviour.