Some checks failed
ARM64 Build / Build generic ARM64 disk image (push) Failing after 4s
CI / Go Tests (push) Successful in 1m29s
CI / Shellcheck (push) Successful in 48s
CI / Build Go Binaries (amd64, linux, linux-amd64) (push) Successful in 1m12s
CI / Build Go Binaries (arm64, linux, linux-arm64) (push) Has been cancelled
Phase 8 of v0.3. Tightens the update lifecycle on both ends. Pre-flight (apply.go, before any download): - Free-space check on the passive partition: image size + 10% headroom must be available. Uses statfs(2) via the new pkg/partition.FreeBytes / HasFreeSpaceFor helpers (tests cover happy path, tiny request, huge request, missing path). Catches corrupted-FS and shrunk-partition cases before we destroy the existing slot data. - Node-block-label check: refuses if the local K8s node carries the updates.kubesolo.io/block=true label. New pkg/health.CheckNodeBlocked shells out to kubectl per the project's zero-deps stance. Silently bypassed when no kubeconfig is reachable (air-gap case). Skipped by --force. Healthcheck (extended via new pkg/health/extended.go + preflight.go): - CheckKubeSystemReady waits until every kube-system pod has held the Running phase for >= N seconds (default 30). Catches "started ok, will crash-loop" bugs that a single-shot phase check misses. - CheckProbeURL fetches an operator-supplied URL; 200 = pass. Wired through update.conf as healthcheck_url= and cloud-init updates.healthcheck_url. - CheckDiskWritable writes/fsyncs/reads a 1-KiB probe under /var/lib/kubesolo. Always runs in healthcheck so a wedged data partition fails fast. - pkg/health.Status grows KubeSystemReady, ProbeURL, DiskWritable booleans. Optional checks default to true in RunAll() so they don't block when unconfigured. health_test.go updated to the new 6-field shape. Auto-rollback (healthcheck.go): - state.UpdateState gains HealthCheckFailures (consecutive post-Activated failures). Reset on a clean pass. - --auto-rollback-after N (also auto_rollback_after= in update.conf) triggers env.ForceRollback() when the failure count reaches the threshold. State transitions to RolledBack with a descriptive LastError. The command still exits with the healthcheck error; the operator/init is expected to reboot. - Only fires while Phase == Activated. Doesn't second-guess a long-stable system that happens to fail one healthcheck. config / opts / cloud-init plumbing: - update.conf gains healthcheck_url= and auto_rollback_after= keys. - New CLI flags: --healthcheck-url, --auto-rollback-after, --kube-system-settle. - cloud-init full-config.yaml documents the new updates: subfields. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
86 lines
3.3 KiB
YAML
86 lines
3.3 KiB
YAML
# KubeSolo OS Cloud-Init — Full Configuration Reference
|
|
# Shows ALL supported KubeSolo parameters.
|
|
# Place at: /mnt/data/etc-kubesolo/cloud-init.yaml (on data partition)
|
|
# Or pass via boot param: kubesolo.cloudinit=/path/to/this.yaml
|
|
|
|
hostname: kubesolo-edge-01
|
|
|
|
network:
|
|
mode: dhcp
|
|
# interface: eth0 # Optional: specify interface (auto-detected if omitted)
|
|
# dns: # Optional: override DHCP-provided DNS
|
|
# - 8.8.8.8
|
|
|
|
kubesolo:
|
|
# Enable local-path-provisioner for persistent volumes (default: true)
|
|
local-storage: true
|
|
|
|
# Shared path for local-path-provisioner storage
|
|
local-storage-shared-path: "/mnt/shared"
|
|
|
|
# Extra SANs for API server TLS certificate
|
|
apiserver-extra-sans:
|
|
- kubesolo-edge-01.local
|
|
- 192.168.1.100
|
|
|
|
# Enable verbose debug logging
|
|
debug: false
|
|
|
|
# Enable Go pprof profiling server
|
|
pprof-server: false
|
|
|
|
# Portainer Edge Agent connection (alternative to portainer.edge-agent section)
|
|
# These generate --portainer-edge-id, --portainer-edge-key, --portainer-edge-async
|
|
# CLI flags for KubeSolo's built-in Edge Agent support.
|
|
portainer-edge-id: "your-edge-id"
|
|
portainer-edge-key: "your-edge-key"
|
|
portainer-edge-async: true
|
|
|
|
# KubeSolo v1.1.4+: skip the edge-optimised overrides and use upstream
|
|
# Kubernetes defaults. Useful for CI and high-spec machines. Default off.
|
|
full: false
|
|
|
|
# KubeSolo v1.1.5+: disable IPv6 throughout the cluster. Default off.
|
|
disable-ipv6: false
|
|
|
|
# KubeSolo v1.1.5+: detect SQLite WAL corruption at startup and recover
|
|
# from unclean shutdowns (e.g. power loss). Recommended ON for edge
|
|
# appliances that may lose power.
|
|
db-wal-repair: true
|
|
|
|
# Arbitrary extra flags passed directly to the KubeSolo binary
|
|
# extra-flags: "--disable traefik --disable servicelb"
|
|
|
|
# Update agent settings (written to /etc/kubesolo/update.conf on first boot).
|
|
# Omit any subfield to leave the corresponding default in place.
|
|
updates:
|
|
# Update server URL — HTTPS for the JSON+blob protocol, or an OCI registry
|
|
# reference (e.g. ghcr.io/portainer/kubesolo-os) when OCI distribution
|
|
# lands in v0.3.
|
|
server: "https://updates.kubesolo.example.com"
|
|
|
|
# Channel to track. "stable" is the default; "beta"/"edge" expose
|
|
# pre-release artifacts. The agent refuses to apply metadata whose
|
|
# channel doesn't match.
|
|
channel: "stable"
|
|
|
|
# Maintenance window (local time, HH:MM-HH:MM, wrapping midnight OK).
|
|
# `apply` refuses to run outside this window unless --force is passed.
|
|
# Leave empty (or omit) to allow updates at any time.
|
|
maintenance_window: "03:00-05:00"
|
|
|
|
# Path to Ed25519 public key for signature verification. Omit to disable
|
|
# signature verification (NOT recommended for production fleets).
|
|
# pubkey: "/etc/kubesolo/update-pubkey.hex"
|
|
|
|
# Optional post-boot healthcheck probe URL. If set, healthcheck GETs it
|
|
# and treats anything other than HTTP 200 as a failure. Useful when your
|
|
# workload exposes its own readiness on a known endpoint.
|
|
# healthcheck_url: "http://localhost:8000/ready"
|
|
|
|
# Auto-rollback threshold: after N consecutive post-activation healthcheck
|
|
# failures, the agent triggers a rollback on its own. 0 disables the
|
|
# feature (the bootloader still does GRUB-counter-based rollback after
|
|
# 3 failed boots). Recommended: 3 for production fleets.
|
|
# auto_rollback_after: 3
|