Avoid recursive chown of the home PVC on every workspace start #2
No reviewers
Labels
No labels
No milestone
No project
No assignees
2 participants
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
GuillaumeHemmen-k8s/coder-sindri-deployment!2
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "fix/fsgroup-change-policy"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Problem
Workspaces take ~4 minutes to start, and the Coder web UI reports that the agent is slow to come up.
The pod
security_contextsetsfs_group = 1000with nofs_group_change_policy, which defaults toAlways. kubelet therefore recursively chowns the entire/home/codervolume on every single workspace start, before the container is created.Evidence
Measured on workspace
ghe-perso(podcoder-12f3cdc1-...-p9f95, nodetalos-ovh-worker-one):VolumePermissionChangeInProgressPod events:
The home volume currently holds 1,144,713 inodes (
Projects871k,.cache218k,.nvm35k) on a 100Gi Longhorn RWO volume — several minutes of metadata operations on network-backed storage.The image is not the bottleneck. The 2.6 GB sindri image pulled from the node's containerd cache in 75ms (the digest check against
git.van-hemmen.comis fast from inside the cluster), and the agent loggedagent is starting now1 second after the container started.Fix
Set
fs_group_change_policy = "OnRootMismatch". kubelet then only chowns when the volume root is not already owned byfs_group— i.e. once, on first use. Expected effect: workspace start drops from ~4 min to ~15s.This also matters going forward: the cost grows linearly with file count, so it degrades as workspaces accumulate
node_modules, build caches and git objects.Notes / follow-ups (not in this PR)
image_pull_policy = "Always"with no node affinity means a workspace scheduled onto a node without the tag cached would eat a 2.6 GB pull. All three workers happen to have sindri images cached today, so this is latent rather than active.~/.cachewould shave ~20% of the inodes, but that is a band-aid; the policy change is the actual fix.Testing
Not applied to the cluster — investigation was read-only.
terraform validatewas not run (terraform is not installed in the workspace); the change is a single attribute addition to an existingsecurity_contextblock. Verification is to push the template and time the next workspace start.🤖 Generated with Claude Code
https://claude.ai/code/session_015QKnVbbjpAi4TaSmrkNXAE