Commit Graph

30 Commits

Author SHA1 Message Date
Jose Diaz-Gonzalez
1d2c7424aa fix: do not require a local image for k3s deploys
Kubernetes pulls the app image itself, so a k3s host is free to reap its local copy while the workload keeps running, which the `registry` plugin already does on its own. Deploys, restarts, `dokku run`, and in-cluster cron no longer assert that the image is present locally, falling back to the metadata recorded in the app's current Helm release. A `ps:restart` naming a single process type now rolls only that process type's pods rather than silently redeploying every one. Apps with an `app.json` postdeploy task still require the image locally, as that task runs on the Dokku host.
2026-08-12 02:14:56 -04:00
Jose Diaz-Gonzalez
cd1089500b feat: translate docker-options --sysctl on the k3s scheduler
The `docker-local` scheduler supports `--sysctl` for free because docker options are passed verbatim to `docker run`, but the k3s scheduler silently dropped it. Namespaced sysctls now render into the pod's `securityContext.sysctls` for deployments, cron jobs, and one-off runs. A sysctl the kernel does not namespace fails the deploy instead of being dropped, since it cannot take effect within a pod regardless of what was requested.
2026-08-07 05:43:00 -04:00
Jose Diaz-Gonzalez
b66df28d96 fix: harden scheduler-k3s cron manifests and dockerfile run startup
The cron-id label could exceed Kubernetes' 63-byte cap when commands or
schedules were long, and an all-digit job-suffix or cron-id rendered as
an unquoted YAML scalar caused the API server to reject manifests. Run
pods built from dockerfiles also occasionally hit the 10s startup wait
on a cold image pull, even though the pod was scheduled correctly.

The cron-id is now stored as an annotation and a shorter hash is used as
the selector label. Every interpolated annotation and label value in the
cron-job and deployment templates is now quoted to prevent numeric
coercion, and the run-pod wait timeout is raised to 30 seconds.
2026-05-11 14:49:58 -04:00
Jose Diaz-Gonzalez
3a845f4d14 fix: route CNB images through launcher on scheduler-k3s
Mirror the docker-local fix in #8525 for the k3s scheduler. CNB images default to a `/cnb/process/web` entrypoint that ignores incoming args, so non-web deployments, scheduled cron jobs, and ad-hoc `dokku run` / `cron:run` commands all need an explicit `launcher` entrypoint. The deployment and cron-job helm templates now set `command: [launcher]` when `image.type` is `pack`, and `TriggerSchedulerRun` sets the entrypoint to `launcher` for pack images while finishing the previously stubbed Procfile lookup branch so the resolved command is actually scheduled.
2026-05-11 02:05:56 -04:00
Jose Diaz-Gonzalez
cfb7da8ec0 feat: scheduler-k3s renders pvc-backed volumes from storage attachments
Adds a per-entry storage helm chart that owns the PVC and (when host_path is set) the PV, and three triggers for the storage plugin to drive: storage-create installs/upgrades the chart with storage-class existence validation, storage-destroy uninstalls it, storage-status reports the PVC phase. App deployment and cron-job charts now consume storage-app-mounts and reference each PVC by name; the // todo: implement volumes blocks are gone. ProcessVolume gained sub_path, read_only, and persistent_claim fields and the deployment/cron-job templates render them.
2026-04-29 14:49:15 -04:00
Jose Diaz-Gonzalez
ef9bdc0379 fix: split env config and image pull secret into separate helm releases
Bundling these Secrets in the app helm chart caused two bugs in the scheduler-k3s plugin: a chart rollback could delete Secrets that older ReplicaSets still referenced by exact timestamped name (`env-{app}.{ts}` and `ims-{app}.{ts}`), hard-crashing pods until manual intervention; and the strategic-merge `patchMergeKey` on `imagePullSecrets` let stale entries leak into the live Deployment until the list pointed at many nonexistent Secrets. Each Secret now lives in its own helm release with a stable name (`config-{app}` and `pull-secret-{app}`), installed before the app chart on every deploy. The deployment trigger also prunes any leaked `imagePullSecrets` entries from the live Deployment so the next deploy lands on a clean list, and the rename and destroy paths uninstall the new releases (and the previously-leaked TLS release on rename) under the old app name.
2026-04-29 12:18:03 -04:00
Jose Diaz-Gonzalez
5adf0a2b6a Merge pull request #8152 from dokku/k3s-keda-replicas 2025-11-22 21:28:28 -05:00
Jose Diaz-Gonzalez
4dce4d652a fix: ensure keda usage does not cause jank in scaling deployments
If the values set by keda do not match the current deployment replicas value, the deployment object may be scaled in unexpected ways during a helm release. This change ensures keda will continue to manage that value correctly without the deployment object setting it back to something else.
2025-11-22 19:51:29 -05:00
Jose Diaz-Gonzalez
0c96c4b6de feat: allow exposing non-web processes as kubernetes services
Closes #7204
2025-11-22 19:39:56 -05:00
Jose Diaz-Gonzalez
f90a4061c0 feat: create SecurityContext for k3s scheduler from docker-options
Closes #7664
2025-09-12 18:09:33 -04:00
Jose Diaz-Gonzalez
434a111976 fix: skip Deployment and ScaledObject generation for cron tasks 2025-08-22 02:29:00 -04:00
Jose Diaz-Gonzalez
390a2254a0 fix: do not skip generating certain templates when non-web processes are encountered 2025-08-22 01:24:53 -04:00
Jose Diaz-Gonzalez
2958f906e4 chore: update and move comment in rendered template 2025-07-23 20:28:40 -04:00
Jose Diaz-Gonzalez
68f909b91d fix: only process web-related templates when there is a web section embedded in the template 2025-07-23 20:16:49 -04:00
Jose Diaz-Gonzalez
1b95e01ea3 fix: move range 2025-07-04 04:24:09 -04:00
Jose Diaz-Gonzalez
65dd4bc1e0 feat: set shm-size volume/volumeMounts on kubernetes deployments 2025-03-06 22:59:35 -05:00
Jose Diaz-Gonzalez
fd2cfe8080 fix: correctly pull the deployment id from an app's helm values when executing dokku run under the k3s scheduler
- Fix the internal identifier of deployment_id -> deployment_id
- Add tests for both enter and run.
2024-11-04 14:44:25 -05:00
Jose Diaz-Gonzalez
7a5bd7ee0f refactor: use a helper function for printing out both labels and annotations 2024-03-01 17:42:24 -05:00
Jose Diaz-Gonzalez
55c85fb6aa fix: ensure non-web processes do not attempt to perform web logic in k3s templates 2024-02-25 13:58:30 -05:00
Jose Diaz-Gonzalez
1ae2df52f5 fix: use image pull secrets instead of registries.yaml to reference private repositories
While this will now more or less require a local docker login - which can be overridden by setting the image-pull-secrets property - this ensures every deploy has a valid context.

One annoying thing is that the secret is per-app vs global, meaning that if the secret must be rotated, all apps need to be redeployed. A future change can fix that by deploying a global secret, or if folks really desire, this can be done by setting the image-pull-secrets property on the app/globally.
2024-02-12 17:15:37 -05:00
Jose Diaz-Gonzalez
433eb26f3c feat: always skip the https ingress/ingress-route/deployment port entry if there is a corresponding http entry
Also inject the corresponding entries as necessary
2024-02-12 01:31:39 -05:00
Jose Diaz-Gonzalez
f5f583b12b feat: add support for specifying annotations
As the command contains a colon, it must be handled in the commands binary as opposed to subcommands.

Also include a simple bats test.
2024-02-06 13:54:53 -05:00
Jose Diaz-Gonzalez
d7ff8552d1 fix: index the process map to ensure the correct config is pulled
Without this change, certain generated process names - like those for a cron job - may be incorrectly handled when indexing the process map.
2024-02-06 04:41:14 -05:00
Jose Diaz-Gonzalez
6625846ecc Merge pull request #6555 from dokku/service-account
Add support for app-specific service accounts when deploying via k3s
2024-02-05 17:18:20 -05:00
Jose Diaz-Gonzalez
238535be0c fix: respect the release namespace when creating resources for a k3s deploy 2024-02-05 16:50:00 -05:00
Jose Diaz-Gonzalez
d02c04c2a5 feat: add support for app-specific service accounts when deploying via k3s
Service accounts must still be bound to a role, but this ensures apps do not get access to the default service account.
2024-02-05 16:47:57 -05:00
Jose Diaz-Gonzalez
f5182aa553 feat: allow specifying an ingress class via chart value
While Dokku currently only supports traefik, providing this setting will allow swapping out the ingress to another fairly easily.
2024-01-26 03:23:34 -05:00
Jose Diaz-Gonzalez
1d99e0bc6e fix: guard against missing healthcheck config
Also add support for liveness and readiness probes.
2024-01-24 02:39:39 -05:00
Jose Diaz-Gonzalez
c1b3c73096 chore: drop unnecessary key 2024-01-23 09:32:41 -05:00
Jose Diaz-Gonzalez
2336063ca2 refactor: move templating into pseudo-generated helm chart
The previous mechanism of constructing the helm chart was pretty obnoxious due to needing to have some things in the object and some in template files that were appended afterwards. This change simplifies that by using template files per type with minimal replacements.
2024-01-23 03:00:27 -05:00