Repository navigation
Conversation
This makes it possible for us to switch to a read-only root filesystem. And it causes the logs to survive a container restart.
c542a20 to
789cbd9
Compare
| {{- if .Values.telemetry.fileLog.enabled }} | ||
| volumes: | ||
| - name: log | ||
| emptyDir: {} |
There was a problem hiding this comment.
We should default to emptyDir, but allow any volume type to be overridden via values (doesn't have to be now, but could be worth doing in the same PR).
There was a problem hiding this comment.
I want to push back on this.
stackabletech/issues#645
If we allow this to be anything else the PVC will be root-owned and we can't write to it.
To work around that we need to set an fsGroup. This happens automatically on OpenShift, it does not on vanilla Kubernetes. If we set one we break OpenShift.
So...it'd become complicated fast.
This can be done more easily as soon as we only support OpenShift with the restricted-v3 SCC.
So for now I'd like to hardcode this. It's already strictly better than what we have today.
a) It survives a container restart
b) It allows for read only root filesystem
c) It allows to attach (if needed) a log aggregator thing
Co-authored-by: Nick <10092581+NickLarsenNZ@users.noreply.github.com>
|
I would love to see us doing the same for the product pods :) |
This makes it possible for us to switch to a read-only root filesystem. And it causes the logs to survive a container restart.