diff --git a/deploy/k8s/overlays/dev/image-tag/kustomization.yaml b/deploy/k8s/overlays/dev/image-tag/kustomization.yaml index 25cc7058..0d3f0e3a 100644 --- a/deploy/k8s/overlays/dev/image-tag/kustomization.yaml +++ b/deploy/k8s/overlays/dev/image-tag/kustomization.yaml @@ -8,4 +8,4 @@ kind: Component images: - name: ghcr.io/brvncde-dotcom/vncmail-plus-dev newName: ghcr.io/brvncde-dotcom/vncmail-plus-dev - newTag: latest + newTag: sha-d0a1cee6 diff --git a/deploy/k8s/overlays/dev/kustomization.yaml b/deploy/k8s/overlays/dev/kustomization.yaml index 95540993..c1b97a63 100644 --- a/deploy/k8s/overlays/dev/kustomization.yaml +++ b/deploy/k8s/overlays/dev/kustomization.yaml @@ -8,6 +8,7 @@ resources: patches: - path: patch-ingress.yaml + - path: patch-image-pull-policy.yaml components: - image-tag diff --git a/deploy/k8s/overlays/dev/patch-image-pull-policy.yaml b/deploy/k8s/overlays/dev/patch-image-pull-policy.yaml new file mode 100644 index 00000000..05011284 --- /dev/null +++ b/deploy/k8s/overlays/dev/patch-image-pull-policy.yaml @@ -0,0 +1,29 @@ +# base/deployment.yaml sets imagePullPolicy: Always, which is the right +# default for a mutable tag like :latest. The dev overlay pins an immutable +# sha- tag instead (see image-tag/), and for an immutable tag Always +# is pure waste - the content behind that tag can never change, so re-pulling +# it on every pod start only adds a registry round-trip and a hard dependency +# on the registry being reachable at scheduling time. +# +# It is also load-bearing right now: until CI can actually push (GitLab's +# registry vhost serves Rails, not the registry - see .gitlab-ci.yml's +# "Registry history" note), sha- tagged images are side-loaded straight into +# each node's containerd: +# +# docker save --platform linux/amd64 -o vncmail.tar : +# scp vncmail.tar dev-k8s-N:/tmp/ && ssh dev-k8s-N \ +# 'microk8s ctr images import /tmp/vncmail.tar' +# +# imported to ALL of dev-k8s-1/2/3 so the pod can schedule anywhere. With +# Always, kubelet would ignore that local image and fail on a registry pull +# for a tag the registry has never seen. +apiVersion: apps/v1 +kind: Deployment +metadata: + name: vncmail-plus +spec: + template: + spec: + containers: + - name: vncmail-plus + imagePullPolicy: IfNotPresent