Puts today's merged dev on the sandbox (S/MIME, offline replica, SRC branding) without waiting on CI, which still can't push anywhere: GitLab's registry vhost serves Rails/dependency-proxy (see .gitlab-ci.yml) and GHCR needs a PAT that only a human can mint. The amd64 image was built locally and side-loaded into all three nodes' containerd via `microk8s ctr images import`, so IfNotPresent is required - Always would ignore the local image and try to pull a tag no registry has. IfNotPresent is the correct policy for immutable sha- tags regardless; see the comment in patch-image-pull-policy.yaml for the full runbook.
30 lines
1.2 KiB
YAML
30 lines
1.2 KiB
YAML
# base/deployment.yaml sets imagePullPolicy: Always, which is the right
|
|
# default for a mutable tag like :latest. The dev overlay pins an immutable
|
|
# sha-<commit> tag instead (see image-tag/), and for an immutable tag Always
|
|
# is pure waste - the content behind that tag can never change, so re-pulling
|
|
# it on every pod start only adds a registry round-trip and a hard dependency
|
|
# on the registry being reachable at scheduling time.
|
|
#
|
|
# It is also load-bearing right now: until CI can actually push (GitLab's
|
|
# registry vhost serves Rails, not the registry - see .gitlab-ci.yml's
|
|
# "Registry history" note), sha- tagged images are side-loaded straight into
|
|
# each node's containerd:
|
|
#
|
|
# docker save --platform linux/amd64 -o vncmail.tar <image>:<tag>
|
|
# scp vncmail.tar dev-k8s-N:/tmp/ && ssh dev-k8s-N \
|
|
# 'microk8s ctr images import /tmp/vncmail.tar'
|
|
#
|
|
# imported to ALL of dev-k8s-1/2/3 so the pod can schedule anywhere. With
|
|
# Always, kubelet would ignore that local image and fail on a registry pull
|
|
# for a tag the registry has never seen.
|
|
apiVersion: apps/v1
|
|
kind: Deployment
|
|
metadata:
|
|
name: vncmail-plus
|
|
spec:
|
|
template:
|
|
spec:
|
|
containers:
|
|
- name: vncmail-plus
|
|
imagePullPolicy: IfNotPresent
|