Skip to content

feat(template): Write operator file logs to an emptyDir under /var/log - #656

Open
lfrancke wants to merge 2 commits into
mainfrom
push-ozpklznmrroq
Open

lfrancke wants to merge 2 commits into
mainfrom
push-ozpklznmrroq

Conversation

@lfrancke

@lfrancke lfrancke commented Oct 6, 2026

Copy link
Copy Markdown
Member

This makes it possible for us to switch to a read-only root filesystem. And it causes the logs to survive a container restart.

@lfrancke lfrancke self-assigned this Oct 6, 2026
This makes it possible for us to switch to a read-only root filesystem.
And it causes the logs to survive a container restart.
{{- if .Values.telemetry.fileLog.enabled }}
volumes:
- name: log
emptyDir: {}

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We should default to emptyDir, but allow any volume type to be overridden via values (doesn't have to be now, but could be worth doing in the same PR).

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I want to push back on this.
stackabletech/issues#645

If we allow this to be anything else the PVC will be root-owned and we can't write to it.
To work around that we need to set an fsGroup. This happens automatically on OpenShift, it does not on vanilla Kubernetes. If we set one we break OpenShift.

So...it'd become complicated fast.
This can be done more easily as soon as we only support OpenShift with the restricted-v3 SCC.

So for now I'd like to hardcode this. It's already strictly better than what we have today.
a) It survives a container restart
b) It allows for read only root filesystem
c) It allows to attach (if needed) a log aggregator thing

Comment thread template/deploy/helm/[[operator]]/templates/_telemetry.tpl.j2 Outdated
sbernauer
sbernauer previously approved these changes Oct 6, 2026

@sbernauer sbernauer left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM % Nicks comments

Co-authored-by: Nick <10092581+NickLarsenNZ@users.noreply.github.com>
@sbernauer

sbernauer commented Oct 6, 2026 •

Copy link
Copy Markdown
Member

I would love to see us doing the same for the product pods :)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Development: In Review

Development

Successfully merging this pull request may close these issues.

3 participants