mirror of
https://github.com/actions-runner-controller/actions-runner-controller.git
synced 2026-09-30 01:31:27 +02:00
Fix custom runner mode volume injection (#4693)
This commit is contained in:
@@ -341,8 +341,10 @@ spec:
|
|||||||
volumes:
|
volumes:
|
||||||
{{- if eq $runnerMode "kubernetes" }}
|
{{- if eq $runnerMode "kubernetes" }}
|
||||||
{{- include "runner-mode-kubernetes.pod-volumes" . | nindent 8 }}
|
{{- include "runner-mode-kubernetes.pod-volumes" . | nindent 8 }}
|
||||||
{{- else }}
|
{{- else if eq $runnerMode "dind" }}
|
||||||
{{- include "runner-mode-dind.pod-volumes" . | nindent 8 }}
|
{{- include "runner-mode-dind.pod-volumes" . | nindent 8 }}
|
||||||
|
{{- else }}
|
||||||
|
{{- include "githubServerTLS.podVolumeItem" . | nindent 8 }}
|
||||||
{{- end }}
|
{{- end }}
|
||||||
{{- if $extraVolumes }}
|
{{- if $extraVolumes }}
|
||||||
{{- range $extraVolumes }}
|
{{- range $extraVolumes }}
|
||||||
|
|||||||
+59
-6
@@ -41,15 +41,68 @@ tests:
|
|||||||
name: github-server-tls-cert
|
name: github-server-tls-cert
|
||||||
mountPath: "/usr/local/share/ca-certificates/"
|
mountPath: "/usr/local/share/ca-certificates/"
|
||||||
readOnly: true
|
readOnly: true
|
||||||
- contains:
|
- equal:
|
||||||
path: spec.template.spec.volumes
|
path: spec.template.spec.volumes
|
||||||
|
value:
|
||||||
|
- name: github-server-tls-cert
|
||||||
|
configMap:
|
||||||
|
name: "my-ca-config"
|
||||||
|
items:
|
||||||
|
- key: "ca.crt"
|
||||||
|
path: "ca.crt"
|
||||||
|
|
||||||
|
- it: should preserve custom volumes alongside the TLS volume in mode-empty
|
||||||
|
set:
|
||||||
|
scaleset.name: "test"
|
||||||
|
auth.url: "https://github.com/org"
|
||||||
|
auth.githubToken: "gh_token12345"
|
||||||
|
controllerServiceAccount.name: "arc"
|
||||||
|
controllerServiceAccount.namespace: "arc-system"
|
||||||
|
githubServerTLS:
|
||||||
|
runnerMountPath: "/usr/local/share/ca-certificates/"
|
||||||
|
certificateFrom:
|
||||||
|
configMapKeyRef:
|
||||||
|
name: "my-ca-config"
|
||||||
|
key: "ca.crt"
|
||||||
|
runner:
|
||||||
|
mode: ""
|
||||||
|
container:
|
||||||
|
volumeMounts:
|
||||||
|
- name: work
|
||||||
|
mountPath: /home/runner/_work
|
||||||
|
pod:
|
||||||
|
spec:
|
||||||
|
volumes:
|
||||||
|
- name: work
|
||||||
|
persistentVolumeClaim:
|
||||||
|
claimName: runner-work
|
||||||
|
release:
|
||||||
|
name: "test-name"
|
||||||
|
namespace: "test-namespace"
|
||||||
|
asserts:
|
||||||
|
- equal:
|
||||||
|
path: spec.template.spec.volumes
|
||||||
|
value:
|
||||||
|
- name: github-server-tls-cert
|
||||||
|
configMap:
|
||||||
|
name: "my-ca-config"
|
||||||
|
items:
|
||||||
|
- key: "ca.crt"
|
||||||
|
path: "ca.crt"
|
||||||
|
- name: work
|
||||||
|
persistentVolumeClaim:
|
||||||
|
claimName: runner-work
|
||||||
|
- contains:
|
||||||
|
path: spec.template.spec.containers[0].volumeMounts
|
||||||
|
content:
|
||||||
|
name: work
|
||||||
|
mountPath: /home/runner/_work
|
||||||
|
- contains:
|
||||||
|
path: spec.template.spec.containers[0].volumeMounts
|
||||||
content:
|
content:
|
||||||
name: github-server-tls-cert
|
name: github-server-tls-cert
|
||||||
configMap:
|
mountPath: "/usr/local/share/ca-certificates/"
|
||||||
name: "my-ca-config"
|
readOnly: true
|
||||||
items:
|
|
||||||
- key: "ca.crt"
|
|
||||||
path: "ca.crt"
|
|
||||||
|
|
||||||
- it: should not override user-provided CA env + volumeMount in mode-empty
|
- it: should not override user-provided CA env + volumeMount in mode-empty
|
||||||
set:
|
set:
|
||||||
|
|||||||
+41
@@ -74,6 +74,47 @@ tests:
|
|||||||
- notExists:
|
- notExists:
|
||||||
path: spec.template.spec.volumes
|
path: spec.template.spec.volumes
|
||||||
|
|
||||||
|
- it: should preserve custom work volumes without adding dind volumes in mode-empty
|
||||||
|
set:
|
||||||
|
scaleset.name: "test"
|
||||||
|
auth.url: "https://github.com/org"
|
||||||
|
auth.githubToken: "gh_token12345"
|
||||||
|
controllerServiceAccount.name: "arc"
|
||||||
|
controllerServiceAccount.namespace: "arc-system"
|
||||||
|
runner:
|
||||||
|
mode: ""
|
||||||
|
container:
|
||||||
|
volumeMounts:
|
||||||
|
- name: work
|
||||||
|
mountPath: /home/runner/_work
|
||||||
|
pod:
|
||||||
|
spec:
|
||||||
|
volumes:
|
||||||
|
- name: work
|
||||||
|
persistentVolumeClaim:
|
||||||
|
claimName: runner-work
|
||||||
|
- name: cache
|
||||||
|
emptyDir: {}
|
||||||
|
release:
|
||||||
|
name: "test-name"
|
||||||
|
namespace: "test-namespace"
|
||||||
|
asserts:
|
||||||
|
- equal:
|
||||||
|
path: spec.template.spec.volumes
|
||||||
|
value:
|
||||||
|
- name: work
|
||||||
|
persistentVolumeClaim:
|
||||||
|
claimName: runner-work
|
||||||
|
- name: cache
|
||||||
|
emptyDir: {}
|
||||||
|
- equal:
|
||||||
|
path: spec.template.spec.containers[0].volumeMounts
|
||||||
|
value:
|
||||||
|
- name: work
|
||||||
|
mountPath: /home/runner/_work
|
||||||
|
- notExists:
|
||||||
|
path: spec.template.spec.initContainers
|
||||||
|
|
||||||
- it: should not allow overriding runner container name
|
- it: should not allow overriding runner container name
|
||||||
set:
|
set:
|
||||||
scaleset.name: "test"
|
scaleset.name: "test"
|
||||||
|
|||||||
@@ -230,6 +230,8 @@ runner:
|
|||||||
# - spec.containers: appended after the generated "runner" container (name "runner" is reserved)
|
# - spec.containers: appended after the generated "runner" container (name "runner" is reserved)
|
||||||
# - spec.initContainers: appended after any generated initContainers (e.g. dind mode)
|
# - spec.initContainers: appended after any generated initContainers (e.g. dind mode)
|
||||||
# - spec.volumes: appended after generated volumes
|
# - spec.volumes: appended after generated volumes
|
||||||
|
# In empty mode, only user-supplied volumes and the optional GitHub server TLS
|
||||||
|
# volume are included.
|
||||||
# - spec.restartPolicy: defaults to Never; an explicit Kubernetes restart policy is preserved
|
# - spec.restartPolicy: defaults to Never; an explicit Kubernetes restart policy is preserved
|
||||||
#
|
#
|
||||||
# Note: serviceAccountName is managed by the chart and cannot be overridden via runner.pod.spec.
|
# Note: serviceAccountName is managed by the chart and cannot be overridden via runner.pod.spec.
|
||||||
|
|||||||
Reference in New Issue
Block a user