Fix custom runner mode volume injection (#4693)

This commit is contained in:
Nikola Jokic
2026-09-29 14:46:09 +02:00
committed by GitHub
parent c48f2ca5e9
commit ce0c6b7437
4 changed files with 105 additions and 7 deletions
@@ -341,8 +341,10 @@ spec:
volumes:
{{- if eq $runnerMode "kubernetes" }}
{{- include "runner-mode-kubernetes.pod-volumes" . | nindent 8 }}
{{- else }}
{{- else if eq $runnerMode "dind" }}
{{- include "runner-mode-dind.pod-volumes" . | nindent 8 }}
{{- else }}
{{- include "githubServerTLS.podVolumeItem" . | nindent 8 }}
{{- end }}
{{- if $extraVolumes }}
{{- range $extraVolumes }}
@@ -41,15 +41,68 @@ tests:
name: github-server-tls-cert
mountPath: "/usr/local/share/ca-certificates/"
readOnly: true
- contains:
- equal:
path: spec.template.spec.volumes
value:
- name: github-server-tls-cert
configMap:
name: "my-ca-config"
items:
- key: "ca.crt"
path: "ca.crt"
- it: should preserve custom volumes alongside the TLS volume in mode-empty
set:
scaleset.name: "test"
auth.url: "https://github.com/org"
auth.githubToken: "gh_token12345"
controllerServiceAccount.name: "arc"
controllerServiceAccount.namespace: "arc-system"
githubServerTLS:
runnerMountPath: "/usr/local/share/ca-certificates/"
certificateFrom:
configMapKeyRef:
name: "my-ca-config"
key: "ca.crt"
runner:
mode: ""
container:
volumeMounts:
- name: work
mountPath: /home/runner/_work
pod:
spec:
volumes:
- name: work
persistentVolumeClaim:
claimName: runner-work
release:
name: "test-name"
namespace: "test-namespace"
asserts:
- equal:
path: spec.template.spec.volumes
value:
- name: github-server-tls-cert
configMap:
name: "my-ca-config"
items:
- key: "ca.crt"
path: "ca.crt"
- name: work
persistentVolumeClaim:
claimName: runner-work
- contains:
path: spec.template.spec.containers[0].volumeMounts
content:
name: work
mountPath: /home/runner/_work
- contains:
path: spec.template.spec.containers[0].volumeMounts
content:
name: github-server-tls-cert
configMap:
name: "my-ca-config"
items:
- key: "ca.crt"
path: "ca.crt"
mountPath: "/usr/local/share/ca-certificates/"
readOnly: true
- it: should not override user-provided CA env + volumeMount in mode-empty
set:
@@ -74,6 +74,47 @@ tests:
- notExists:
path: spec.template.spec.volumes
- it: should preserve custom work volumes without adding dind volumes in mode-empty
set:
scaleset.name: "test"
auth.url: "https://github.com/org"
auth.githubToken: "gh_token12345"
controllerServiceAccount.name: "arc"
controllerServiceAccount.namespace: "arc-system"
runner:
mode: ""
container:
volumeMounts:
- name: work
mountPath: /home/runner/_work
pod:
spec:
volumes:
- name: work
persistentVolumeClaim:
claimName: runner-work
- name: cache
emptyDir: {}
release:
name: "test-name"
namespace: "test-namespace"
asserts:
- equal:
path: spec.template.spec.volumes
value:
- name: work
persistentVolumeClaim:
claimName: runner-work
- name: cache
emptyDir: {}
- equal:
path: spec.template.spec.containers[0].volumeMounts
value:
- name: work
mountPath: /home/runner/_work
- notExists:
path: spec.template.spec.initContainers
- it: should not allow overriding runner container name
set:
scaleset.name: "test"
@@ -230,6 +230,8 @@ runner:
# - spec.containers: appended after the generated "runner" container (name "runner" is reserved)
# - spec.initContainers: appended after any generated initContainers (e.g. dind mode)
# - spec.volumes: appended after generated volumes
# In empty mode, only user-supplied volumes and the optional GitHub server TLS
# volume are included.
# - spec.restartPolicy: defaults to Never; an explicit Kubernetes restart policy is preserved
#
# Note: serviceAccountName is managed by the chart and cannot be overridden via runner.pod.spec.