-
Notifications
You must be signed in to change notification settings - Fork 4
Sync kubex charts from automation-controller main @ 2ed7cc9 #113
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -4,6 +4,34 @@ Use this sequence when rightsizing does not happen as expected. | |
|
|
||
| For a consolidated map of the controller's safety gates, see [Safety Controls](./Safety-Controls.md). | ||
|
|
||
| ## 0. Temporarily Enable Debug Logging (and Revert) | ||
|
|
||
| Most of the time you only want debug logs briefly. The quickest way is to update the live Deployment args (this triggers a rollout and will be overwritten by the next `helm upgrade`). | ||
|
|
||
| Enable debug (temporary): | ||
|
|
||
| ```bash | ||
| kubectl -n kubex patch deploy/$(kubectl -n kubex get deploy -l app.kubernetes.io/name=kubex-automation-engine -o jsonpath='{.items[0].metadata.name}') --type='json' -p='[{"op":"replace","path":"/spec/template/spec/containers/0/args/3","value":"--zap-log-level=debug"}]' | ||
| ``` | ||
|
Contributor
Author
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. CONTENT OF THIS REVIEW IS AI GENERATED [Severity: Minor] [Confidence: High] Issue: The Why it matters: If the chart's Suggested fix: Add a warning note such as: "Verify the argument index before running: |
||
|
|
||
| Revert back to info: | ||
|
|
||
| ```bash | ||
| kubectl -n kubex patch deploy/$(kubectl -n kubex get deploy -l app.kubernetes.io/name=kubex-automation-engine -o jsonpath='{.items[0].metadata.name}') --type='json' -p='[{"op":"replace","path":"/spec/template/spec/containers/0/args/3","value":"--zap-log-level=info"}]' | ||
| ``` | ||
|
|
||
| If you want the setting to persist across upgrades, use Helm instead: | ||
|
|
||
| ```bash | ||
| helm upgrade kubex-automation kubex/kubex-automation-engine -n kubex --reuse-values --set 'controllerManager.extraArgs[0]=--zap-log-level=debug' | ||
| ``` | ||
|
|
||
| Revert with Helm: | ||
|
|
||
| ```bash | ||
| helm upgrade kubex-automation kubex/kubex-automation-engine -n kubex --reuse-values --set 'controllerManager.extraArgs[0]=--zap-log-level=info' | ||
| ``` | ||
|
|
||
| ## 1. Interpret `rightsizing summary` Logs | ||
|
|
||
| ```bash | ||
|
|
||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -10,6 +10,9 @@ kind: Deployment | |
| metadata: | ||
| name: {{ include "kubex-automation-engine.fullname" . }} | ||
| namespace: {{ include "kubex-automation-engine.namespace" . }} | ||
| annotations: | ||
|
Contributor
Author
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. CONTENT OF THIS REVIEW IS AI GENERATED [Severity: Minor] [Confidence: High] Issue: The Why it matters: While the self-automation-prevention intent is sound, hardcoding this annotation means:
Suggested fix: Either expose this via a |
||
| # This annotation is set by default so that the automation doesn't attempt to automate itself | ||
| rightsizing.kubex.ai/pause-until: infinite | ||
| labels: | ||
| {{- include "kubex-automation-engine.labels" . | nindent 4 }} | ||
| spec: | ||
|
|
||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -1,8 +1,8 @@ | ||
| apiVersion: v2 | ||
| name: kubex-crds | ||
| description: CRDs for Kubex Automation Engine | ||
| icon: https://kubex.ai/wp-content/uploads/kubex-logo-landscape.svg | ||
| version: 1.0.1 | ||
| version: 1.0.0 | ||
|
Contributor
Author
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. CONTENT OF THIS REVIEW IS AI GENERATED [Severity: Major] [Confidence: High] Issue: Chart version is being downgraded from Why it matters: Same semver immutability concern applies here. A chart registry (e.g., OCI or a classic chart museum) that already has Suggested fix: Bump the version to |
||
| appVersion: v0.1 | ||
| keywords: | ||
| - crd | ||
| - kubex | ||
|
|
||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,247 @@ | ||
| --- | ||
| apiVersion: apiextensions.k8s.io/v1 | ||
| kind: CustomResourceDefinition | ||
| metadata: | ||
| annotations: | ||
| controller-gen.kubebuilder.io/version: v0.19.0 | ||
| name: podaffinities.rightsizing.kubex.ai | ||
| spec: | ||
| group: rightsizing.kubex.ai | ||
| names: | ||
| kind: PodAffinity | ||
| listKind: PodAffinityList | ||
| plural: podaffinities | ||
| singular: podaffinity | ||
| scope: Cluster | ||
| versions: | ||
| - name: v1alpha1 | ||
| schema: | ||
| openAPIV3Schema: | ||
| description: PodAffinity is the Schema for the podaffinities API. | ||
| properties: | ||
| apiVersion: | ||
| description: |- | ||
| APIVersion defines the versioned schema of this representation of an object. | ||
| Servers should convert recognized schemas to the latest internal value, and | ||
| may reject unrecognized values. | ||
| More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources | ||
| type: string | ||
| kind: | ||
| description: |- | ||
| Kind is a string value representing the REST resource this object represents. | ||
| Servers may infer this from the endpoint the client submits requests to. | ||
| Cannot be updated. | ||
| In CamelCase. | ||
| More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds | ||
| type: string | ||
| metadata: | ||
| type: object | ||
| spec: | ||
| description: spec defines the desired state of PodAffinity | ||
| properties: | ||
| affinity: | ||
| description: affinity describes the preferred node affinity to inject | ||
| at pod admission time. | ||
| properties: | ||
| nodes: | ||
| description: nodes lists hostname label values to prefer on replacement | ||
| pods. | ||
| items: | ||
| type: string | ||
| minItems: 1 | ||
| type: array | ||
| required: | ||
| - nodes | ||
| type: object | ||
| scope: | ||
| description: scope narrows the workloads and namespaces this policy | ||
| applies to. | ||
| properties: | ||
| labelSelector: | ||
| description: labelSelector limits the workload objects (e.g., | ||
| Deployments, CronJobs) this policy applies to. | ||
| properties: | ||
| matchExpressions: | ||
| description: matchExpressions is a list of label selector | ||
| requirements. The requirements are ANDed. | ||
| items: | ||
| description: |- | ||
| A label selector requirement is a selector that contains values, a key, and an operator that | ||
| relates the key and values. | ||
| properties: | ||
| key: | ||
| description: key is the label key that the selector | ||
| applies to. | ||
| type: string | ||
| operator: | ||
| description: |- | ||
| operator represents a key's relationship to a set of values. | ||
| Valid operators are In, NotIn, Exists and DoesNotExist. | ||
| type: string | ||
| values: | ||
| description: |- | ||
| values is an array of string values. If the operator is In or NotIn, | ||
| the values array must be non-empty. If the operator is Exists or DoesNotExist, | ||
| the values array must be empty. This array is replaced during a strategic | ||
| merge patch. | ||
| items: | ||
| type: string | ||
| type: array | ||
| x-kubernetes-list-type: atomic | ||
| required: | ||
| - key | ||
| - operator | ||
| type: object | ||
| type: array | ||
| x-kubernetes-list-type: atomic | ||
| matchLabels: | ||
| additionalProperties: | ||
| type: string | ||
| description: |- | ||
| matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels | ||
| map is equivalent to an element of matchExpressions, whose key field is "key", the | ||
| operator is "In", and the values array contains only "value". The requirements are ANDed. | ||
| type: object | ||
| type: object | ||
| x-kubernetes-map-type: atomic | ||
| namespaceSelector: | ||
|
Contributor
Author
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. CONTENT OF THIS REVIEW IS AI GENERATED [Severity: Minor] [Confidence: Medium] Issue: The CRD's Why it matters: Users relying solely on Suggested fix: Augment the description: |-
values contains the namespace name patterns to match.
Supports shell-style '*' wildcards (e.g. 'prod-*'). |
||
| description: namespaceSelector restricts the namespaces this policy | ||
| applies to. | ||
| properties: | ||
| operator: | ||
| description: operator determines how the listed values are | ||
| evaluated. | ||
| enum: | ||
| - In | ||
| - NotIn | ||
| type: string | ||
| values: | ||
| description: values contains the namespace name patterns to | ||
| match. | ||
| items: | ||
| type: string | ||
| minItems: 1 | ||
| type: array | ||
| required: | ||
| - operator | ||
| - values | ||
| type: object | ||
| workloadTypes: | ||
| default: | ||
| - Deployment | ||
| - StatefulSet | ||
| - CronJob | ||
| - Rollout | ||
| - Job | ||
| - AnalysisRun | ||
| - DaemonSet | ||
| description: workloadTypes limits the workload kinds this policy | ||
| applies to. When omitted, all supported workload types are targeted. | ||
| items: | ||
| description: WorkloadType enumerates the workload kinds a policy | ||
| can target. | ||
| enum: | ||
| - Deployment | ||
| - StatefulSet | ||
| - DaemonSet | ||
| - CronJob | ||
| - Rollout | ||
| - Job | ||
| - AnalysisRun | ||
| type: string | ||
| type: array | ||
| required: | ||
| - namespaceSelector | ||
| type: object | ||
| weight: | ||
| default: 0 | ||
| description: |- | ||
| weight determines which policy wins when multiple PodAffinity policies match. | ||
| Higher weights take precedence. When weights are equal, older policies win. | ||
| format: int32 | ||
| minimum: 0 | ||
|
Contributor
Author
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. CONTENT OF THIS REVIEW IS AI GENERATED [Severity: Minor] [Confidence: Medium] Issue: The Why it matters: Stale/incorrect documentation in a CRD's OpenAPI schema is surfaced directly to Suggested fix: Update the description to reference description: |-
conditions represent the current state of the PodAffinity resource.
... |
||
| type: integer | ||
| required: | ||
| - affinity | ||
| - scope | ||
| type: object | ||
| status: | ||
| description: status defines the observed state of PodAffinity | ||
| properties: | ||
| conditions: | ||
| description: |- | ||
| conditions represent the current state of the StaticPolicy resource. | ||
| Each condition has a unique type and reflects the status of a specific aspect of the resource. | ||
|
|
||
| Standard condition types include: | ||
| - "Available": the resource is fully functional | ||
| - "Progressing": the resource is being created or updated | ||
| - "Degraded": the resource failed to reach or maintain its desired state | ||
|
|
||
| The status of each condition is one of True, False, or Unknown. | ||
| items: | ||
| description: Condition contains details for one aspect of the current | ||
| state of this API Resource. | ||
| properties: | ||
| lastTransitionTime: | ||
| description: |- | ||
| lastTransitionTime is the last time the condition transitioned from one status to another. | ||
| This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable. | ||
| format: date-time | ||
| type: string | ||
| message: | ||
| description: |- | ||
| message is a human readable message indicating details about the transition. | ||
| This may be an empty string. | ||
| maxLength: 32768 | ||
| type: string | ||
| observedGeneration: | ||
| description: |- | ||
| observedGeneration represents the .metadata.generation that the condition was set based upon. | ||
| For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date | ||
| with respect to the current state of the instance. | ||
| format: int64 | ||
| minimum: 0 | ||
| type: integer | ||
| reason: | ||
| description: |- | ||
| reason contains a programmatic identifier indicating the reason for the condition's last transition. | ||
| Producers of specific condition types may define expected values and meanings for this field, | ||
| and whether the values are considered a guaranteed API. | ||
| The value should be a CamelCase string. | ||
| This field may not be empty. | ||
| maxLength: 1024 | ||
| minLength: 1 | ||
| pattern: ^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$ | ||
| type: string | ||
| status: | ||
| description: status of the condition, one of True, False, Unknown. | ||
| enum: | ||
| - "True" | ||
| - "False" | ||
| - Unknown | ||
| type: string | ||
| type: | ||
| description: type of condition in CamelCase or in foo.example.com/CamelCase. | ||
| maxLength: 316 | ||
| pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$ | ||
| type: string | ||
| required: | ||
| - lastTransitionTime | ||
| - message | ||
| - reason | ||
| - status | ||
| - type | ||
| type: object | ||
| type: array | ||
| x-kubernetes-list-map-keys: | ||
| - type | ||
| x-kubernetes-list-type: map | ||
| type: object | ||
| required: | ||
| - spec | ||
| type: object | ||
| served: true | ||
| storage: true | ||
| subresources: | ||
| status: {} | ||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
CONTENT OF THIS REVIEW IS AI GENERATED
[Severity: Major] [Confidence: High]
Issue: Chart version is being downgraded from
1.0.1→1.0.0.Why it matters: Helm uses semver to determine whether an upgrade or a downgrade is happening. Reverting the chart version to a lower number than what is already published/deployed can cause
helm upgradeto no-op or behave unexpectedly for users who already have1.0.1installed. It also breaks immutability guarantees in chart repositories — if1.0.0was already released, pushing a different chart under the same version is a breaking convention violation.Suggested fix: If this is intentional (e.g., a reset before a new release cycle), document it explicitly in the PR body and ensure the chart repository has no prior
1.0.0artifact. Otherwise, bump the version to1.0.2(or higher) to reflect the new content being added in this PR.