Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 2 additions & 0 deletions cmd/driver/main.go
Original file line number Diff line number Diff line change
Expand Up @@ -40,6 +40,8 @@ func main() {
"Secret name containing ca.crt for sandbox TLS verification (OPENSHELL_TLS_CA)")
flag.StringVar(&cfg.TLSClientSecret, "tls-client-secret", cfg.TLSClientSecret,
"Secret name containing tls.crt and tls.key for sandbox mTLS client auth")
flag.StringVar(&cfg.ImagePullPolicy, "sandbox-image-pull-policy", cfg.ImagePullPolicy,
"Image pull policy for sandbox pod containers (Always, IfNotPresent, Never); empty uses K8s default")
flag.Parse()

if cfg.Tenant == "" {
Expand Down
1 change: 1 addition & 0 deletions internal/driver/config.go
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,7 @@ type Config struct {
GatewayEndpoint string
TLSCASecret string // Secret name containing ca.crt for gateway TLS verification
TLSClientSecret string // Secret name containing tls.crt and tls.key for mTLS client auth
ImagePullPolicy string // Policy for sandbox pod containers (Always, IfNotPresent, Never); empty means K8s default
}

func DefaultConfig() Config {
Expand Down
6 changes: 6 additions & 0 deletions internal/driver/provisioner.go
Original file line number Diff line number Diff line change
Expand Up @@ -248,6 +248,9 @@ func (p *K8sProvisioner) buildSandboxSpec(sb *pb.DriverSandbox) map[string]inter
},
},
}
if p.cfg.ImagePullPolicy != "" {
initContainer["imagePullPolicy"] = p.cfg.ImagePullPolicy
}

// Agent container runs the supervisor and mounts it read-only.
agentVolumeMounts := []interface{}{
Expand Down Expand Up @@ -286,6 +289,9 @@ func (p *K8sProvisioner) buildSandboxSpec(sb *pb.DriverSandbox) map[string]inter
},
"volumeMounts": agentVolumeMounts,
}
if p.cfg.ImagePullPolicy != "" {
container["imagePullPolicy"] = p.cfg.ImagePullPolicy
}

if res := tmpl.GetResources(); res != nil {
container["resources"] = buildResources(res, spec.GetGpu())
Expand Down
80 changes: 80 additions & 0 deletions internal/driver/provisioner_test.go
Original file line number Diff line number Diff line change
Expand Up @@ -379,3 +379,83 @@ func TestK8sProvisioner_Watch_ChannelCloses(t *testing.T) {
for range ch {
}
}

func TestBuildSandboxSpec_ImagePullPolicy(t *testing.T) {
cfg := testConfig()
cfg.ImagePullPolicy = "IfNotPresent"

logger := testLogger()
scheme := runtime.NewScheme()
dynClient := dynamicfake.NewSimpleDynamicClientWithCustomListKinds(
scheme,
map[schema.GroupVersionResource]string{sandboxGVR: "SandboxList"},
)
clientset := kubefake.NewSimpleClientset()
p := NewK8sProvisioner(dynClient, clientset, cfg, logger)

sb := &pb.DriverSandbox{
Id: "sb-pull",
Spec: &pb.DriverSandboxSpec{
Template: &pb.DriverSandboxTemplate{
Image: "agent:latest",
},
},
}

spec := p.buildSandboxSpec(sb)
podTemplate := spec["podTemplate"].(map[string]interface{})
podSpec := podTemplate["spec"].(map[string]interface{})

// Verify init container has imagePullPolicy set.
initContainers := podSpec["initContainers"].([]interface{})
initC := initContainers[0].(map[string]interface{})
if initC["imagePullPolicy"] != "IfNotPresent" {
t.Errorf("expected init container imagePullPolicy=IfNotPresent, got %v", initC["imagePullPolicy"])
}

// Verify agent container has imagePullPolicy set.
containers := podSpec["containers"].([]interface{})
agentC := containers[0].(map[string]interface{})
if agentC["imagePullPolicy"] != "IfNotPresent" {
t.Errorf("expected agent container imagePullPolicy=IfNotPresent, got %v", agentC["imagePullPolicy"])
}
}

func TestBuildSandboxSpec_ImagePullPolicy_Empty(t *testing.T) {
cfg := testConfig()
// ImagePullPolicy left empty — should not appear in spec.

logger := testLogger()
scheme := runtime.NewScheme()
dynClient := dynamicfake.NewSimpleDynamicClientWithCustomListKinds(
scheme,
map[schema.GroupVersionResource]string{sandboxGVR: "SandboxList"},
)
clientset := kubefake.NewSimpleClientset()
p := NewK8sProvisioner(dynClient, clientset, cfg, logger)

sb := &pb.DriverSandbox{
Id: "sb-nopull",
Spec: &pb.DriverSandboxSpec{
Template: &pb.DriverSandboxTemplate{
Image: "agent:latest",
},
},
}

spec := p.buildSandboxSpec(sb)
podTemplate := spec["podTemplate"].(map[string]interface{})
podSpec := podTemplate["spec"].(map[string]interface{})

initContainers := podSpec["initContainers"].([]interface{})
initC := initContainers[0].(map[string]interface{})
if _, ok := initC["imagePullPolicy"]; ok {
t.Error("expected no imagePullPolicy on init container when config is empty")
}

containers := podSpec["containers"].([]interface{})
agentC := containers[0].(map[string]interface{})
if _, ok := agentC["imagePullPolicy"]; ok {
t.Error("expected no imagePullPolicy on agent container when config is empty")
}
}
Loading