mirror of
https://github.com/actions-runner-controller/actions-runner-controller.git
synced 2026-09-30 14:22:24 +02:00
An EphemeralRunner that exits as Outdated marks its EphemeralRunnerSet
Outdated, and the AutoscalingRunnerSet then stops scaling it. Without a way
to tell which runner spec an Outdated report refers to, a report from a
runner built before the spec was updated keeps the set switched off after
the update that was supposed to fix it.
Stamp each runner with the actionable revision it was built from, and judge
Outdated reports against the revision the set has applied:
- A runner whose revision is older than the applied one is reporting on a
spec that has already been replaced. It is deleted and rebuilt from the
current spec, and it does not hold the set Outdated.
- A runner whose revision is current is reporting on the live spec, so the
set stays Outdated. It is deliberately not delete-and-replaced: a fresh
runner at the same revision would report Outdated again, forever.
Runners without the annotation parse to revision 0, which matches the zero
value of Status.AppliedActionableRevision, so existing runners keep their
current behaviour across an upgrade.
The phase is derived inside patchAppliedActionableRevisionStatus, from a
list read through the same authoritative reader as the set itself, because
the optimistic lock on that patch covers the EphemeralRunnerSet object only
and cannot vouch for a separately-read list. The runners are classified
against the live applied revision rather than the revision this call was
asked to apply: the caller reads the spec from the cache while this function
re-reads the status from the API server, so a lagging reconcile can arrive
with a target behind the live marker, and judging against it would flip a
set that has already moved on back to Outdated.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
145 lines
5.3 KiB
Go
145 lines
5.3 KiB
Go
package actionsgithubcom
|
|
|
|
import (
|
|
"context"
|
|
"encoding/json"
|
|
"testing"
|
|
|
|
"github.com/actions/actions-runner-controller/apis/actions.github.com/v1alpha1"
|
|
"github.com/go-logr/logr"
|
|
"github.com/stretchr/testify/assert"
|
|
"github.com/stretchr/testify/require"
|
|
metav1 "k8s.io/apimachinery/pkg/apis/meta/v1"
|
|
"k8s.io/apimachinery/pkg/runtime"
|
|
"k8s.io/apimachinery/pkg/types"
|
|
clientgoscheme "k8s.io/client-go/kubernetes/scheme"
|
|
"sigs.k8s.io/controller-runtime/pkg/client"
|
|
"sigs.k8s.io/controller-runtime/pkg/client/fake"
|
|
"sigs.k8s.io/controller-runtime/pkg/client/interceptor"
|
|
)
|
|
|
|
// TestPatchAppliedActionableRevisionStatusUsesOptimisticLock pins the property
|
|
// that makes the applied revision marker monotonic: the status patch must carry
|
|
// a resourceVersion precondition.
|
|
//
|
|
// Without it the API server cannot reject the write as conflicting, so the
|
|
// surrounding retry.RetryOnConflict never fires and the freshness check inside
|
|
// it is unsound. Both the target revision and the re-fetched object come from
|
|
// the cache-backed client, so a stale reconcile can compare a stale target
|
|
// against an equally stale read, pass the check, and patch the applied revision
|
|
// backwards. That re-satisfies the spec > applied comparison in Reconcile and
|
|
// sends the controller through the idle and pending runner cleanup again.
|
|
//
|
|
// The property is asserted on the bytes the production code actually emits
|
|
// rather than on an independently constructed patch, so the test cannot pass
|
|
// while the reconciler builds its patch some other way. Reverting the patch
|
|
// option to a plain client.MergeFrom must fail this test.
|
|
func TestPatchAppliedActionableRevisionStatusUsesOptimisticLock(t *testing.T) {
|
|
scheme := runtime.NewScheme()
|
|
require.NoError(t, clientgoscheme.AddToScheme(scheme))
|
|
require.NoError(t, v1alpha1.AddToScheme(scheme))
|
|
|
|
ephemeralRunnerSet := &v1alpha1.EphemeralRunnerSet{
|
|
ObjectMeta: metav1.ObjectMeta{
|
|
Name: "test-ers",
|
|
Namespace: "default",
|
|
},
|
|
Spec: v1alpha1.EphemeralRunnerSetSpec{
|
|
ActionableRevision: 7,
|
|
},
|
|
Status: v1alpha1.EphemeralRunnerSetStatus{
|
|
AppliedActionableRevision: 2,
|
|
},
|
|
}
|
|
|
|
var capturedPatch []byte
|
|
c := fake.NewClientBuilder().
|
|
WithScheme(scheme).
|
|
WithObjects(ephemeralRunnerSet).
|
|
WithStatusSubresource(&v1alpha1.EphemeralRunnerSet{}).
|
|
WithIndex(&v1alpha1.EphemeralRunner{}, resourceOwnerKey, newGroupVersionOwnerKindIndexer("EphemeralRunnerSet")).
|
|
WithInterceptorFuncs(interceptor.Funcs{
|
|
SubResourcePatch: func(ctx context.Context, clt client.Client, subResourceName string, obj client.Object, patch client.Patch, opts ...client.SubResourcePatchOption) error {
|
|
data, err := patch.Data(obj)
|
|
if err != nil {
|
|
return err
|
|
}
|
|
capturedPatch = data
|
|
return clt.Status().Patch(ctx, obj, patch, opts...)
|
|
},
|
|
}).
|
|
Build()
|
|
|
|
reconciler := &EphemeralRunnerSetReconciler{
|
|
Client: c,
|
|
Log: logr.Discard(),
|
|
Scheme: scheme,
|
|
}
|
|
|
|
key := types.NamespacedName{Namespace: ephemeralRunnerSet.Namespace, Name: ephemeralRunnerSet.Name}
|
|
require.NoError(t, reconciler.patchAppliedActionableRevisionStatus(context.Background(), key, 7))
|
|
|
|
require.NotEmpty(t, capturedPatch, "expected the reconciler to emit a status patch")
|
|
|
|
var emitted struct {
|
|
Metadata struct {
|
|
ResourceVersion string `json:"resourceVersion"`
|
|
} `json:"metadata"`
|
|
Status struct {
|
|
AppliedActionableRevision int64 `json:"appliedActionableRevision"`
|
|
} `json:"status"`
|
|
}
|
|
require.NoError(t, json.Unmarshal(capturedPatch, &emitted))
|
|
|
|
assert.NotEmpty(
|
|
t,
|
|
emitted.Metadata.ResourceVersion,
|
|
"status patch must carry a resourceVersion precondition so a stale write is rejected instead of moving the applied revision backwards, got %s",
|
|
string(capturedPatch),
|
|
)
|
|
assert.Equal(t, int64(7), emitted.Status.AppliedActionableRevision)
|
|
|
|
var updated v1alpha1.EphemeralRunnerSet
|
|
require.NoError(t, c.Get(context.Background(), key, &updated))
|
|
assert.Equal(t, int64(7), updated.Status.AppliedActionableRevision)
|
|
}
|
|
|
|
// TestPatchAppliedActionableRevisionStatusDoesNotMoveBackwards covers the guard
|
|
// inside the retry: a reconcile carrying an older target revision must leave a
|
|
// marker that has already advanced further alone.
|
|
func TestPatchAppliedActionableRevisionStatusDoesNotMoveBackwards(t *testing.T) {
|
|
scheme := runtime.NewScheme()
|
|
require.NoError(t, clientgoscheme.AddToScheme(scheme))
|
|
require.NoError(t, v1alpha1.AddToScheme(scheme))
|
|
|
|
ephemeralRunnerSet := &v1alpha1.EphemeralRunnerSet{
|
|
ObjectMeta: metav1.ObjectMeta{
|
|
Name: "test-ers",
|
|
Namespace: "default",
|
|
},
|
|
Status: v1alpha1.EphemeralRunnerSetStatus{
|
|
AppliedActionableRevision: 5,
|
|
},
|
|
}
|
|
|
|
c := fake.NewClientBuilder().
|
|
WithScheme(scheme).
|
|
WithObjects(ephemeralRunnerSet).
|
|
WithStatusSubresource(&v1alpha1.EphemeralRunnerSet{}).
|
|
WithIndex(&v1alpha1.EphemeralRunner{}, resourceOwnerKey, newGroupVersionOwnerKindIndexer("EphemeralRunnerSet")).
|
|
Build()
|
|
|
|
reconciler := &EphemeralRunnerSetReconciler{
|
|
Client: c,
|
|
Log: logr.Discard(),
|
|
Scheme: scheme,
|
|
}
|
|
|
|
key := types.NamespacedName{Namespace: ephemeralRunnerSet.Namespace, Name: ephemeralRunnerSet.Name}
|
|
require.NoError(t, reconciler.patchAppliedActionableRevisionStatus(context.Background(), key, 3))
|
|
|
|
var updated v1alpha1.EphemeralRunnerSet
|
|
require.NoError(t, c.Get(context.Background(), key, &updated))
|
|
assert.Equal(t, int64(5), updated.Status.AppliedActionableRevision)
|
|
}
|