Make imagePullPolicy a template variable instead of hardcoding it #3
No reviewers
Labels
No labels
No milestone
No project
No assignees
2 participants
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
GuillaumeHemmen-k8s/coder-sindri-deployment!3
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "fix/image-pull-policy"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Problem
image_pull_policywas hardcoded to"Always", so every workspace start made kubelet re-resolve the tag against the Forgejo registry even when the full layer set was already cached on the node.Approach
Rather than flipping the constant, this exposes it as a template variable so whoever pushes the template decides. It validates against
Always/IfNotPresent/Never, plusauto.Why
autois the defaultThe policy and the tag are not independent knobs. Current registry digests:
latestis a moving alias CI re-points at each release, so it needsAlwaysor a workspace silently pins to whatever layer set its node happened to have cached. Version and build-SHA tags are published once and never reused, soIfNotPresentis always correct for them.autoderives the policy fromimage_tagon exactly that rule. Sinceimage_tagstill defaults to"latest",autopreserves today's behaviour on the default path and only relaxes it where relaxing is safe. An admin who wants a fixed policy sets one explicitly.What this actually buys
Resilience, not speed. The registry round-trip measured 75ms on the last workspace start, so this saves no meaningful wall-clock time. The real gain is decoupling: under
Always, a workspace on a pinned tag fails withImagePullBackOffwhenever the registry is unreachable, even though the 2.6 GB image is already on the node. Forgejo runs in this same cluster, so a registry outage currently takes pinned workspaces down with it.Testing
Not applied to the cluster; investigation was read-only.
terraform validatewas not run (terraform is not installed in the workspace) — worth aterraform validateor a dry-run template push before merging, since this adds avalidationblock and alocalsblock rather than just changing a literal. Digests above were read from the Forgejo registry API. Verification is to push the template and confirm a pinned-tag workspace starts with noPullingevent.Follow-up to #2.
🤖 Generated with Claude Code
https://claude.ai/code/session_015QKnVbbjpAi4TaSmrkNXAE
c43d7967d1to45eae290e7Only force image re-pull when the tag is a moving aliasto Make imagePullPolicy a template variable instead of hardcoding itReworked per review: instead of hardcoding
IfNotPresent, the policy is now a template variable (image_pull_policy) chosen atcoder templates push, validated againstauto/Always/IfNotPresent/Never.image_tagis left as-is, as requested.The default is
auto, which derives the policy fromimage_tag—Alwaysfor the movinglatestalias,IfNotPresentfor pinned version/SHA tags. Sinceimage_tagstill defaults tolatest, this preserves current behaviour on the default path.Branch was force-pushed (
c43d796->45eae29); the earlier hardcoded-conditional commit is gone. README variables table updated too.