mirror of
https://github.com/actions-runner-controller/actions-runner-controller.git
synced 2026-10-01 12:32:07 +02:00
The `actions.github.com/integrity-hash` annotation was used as an opaque fingerprint to detect spec drift across AutoscalingRunnerSet, EphemeralRunnerSet and the listener resources. Hashes are brittle: they change whenever unrelated serialization details change, they are invisible to users, and they are not restart-safe. FNV-32a also carries a real collision risk, where the consequence is an update silently never applied. Replace it with explicit, typed state: - `AutoscalingRunnerSetStatus.ObservedGeneration` drives the Pending phase transition via `metadata.generation` instead of an annotation hash. - `EphemeralRunnerSetSpec.ActionableRevision` and `EphemeralRunnerSetStatus.AppliedActionableRevision` form a restart-safe applied marker. The revision is bumped by the AutoscalingRunnerSet controller when `EphemeralRunnerSpec` changes, and only advanced in status after idle/pending runner cleanup succeeds. - `EphemeralRunnerSetStatus.FinishedRunnerCleanupPatchID` records the listener patch ID for which finished runners were reaped, so scale-up is suppressed until the listener publishes a fresh desired state. This prevents creating a replacement runner for a job that already completed. - Listener pod recreation compares pod specs semantically instead of comparing hash annotations. Drift detection uses `apiequality.Semantic`, not `cmp` or `reflect`: - `Semantic.DeepEqual` for the EphemeralRunnerSpec. Most PodSpec collection fields carry `omitempty`, so a template containing an explicitly empty value (`env: []`) is dropped when the EphemeralRunnerSet is written and reads back as nil. A strict comparison reports drift on every reconcile, bumping ActionableRevision each time and deleting every idle and pending runner, forever. Semantic treats nil and empty as equal, understands resource.Quantity, and cannot panic on unexported fields the way cmp can. It is also roughly six times cheaper than cmp.Equal on a realistic spec. - `Semantic.DeepDerivative` for the listener pod, because the live pod carries many fields the desired pod never sets (nodeName, dnsPolicy, default tolerations, the kube-api-access volume, ...). DeepEqual there would spin in a delete/create loop. Container port length is checked separately, since ports come from the --listener-metrics-addr flag rather than from a resource, so disabling metrics would otherwise leave the port on the pod forever. Drift detection is deliberately not short-circuited on metadata.generation. Re-registration changes the runner scale set ID through an annotation, and metadata changes do not bump generation, so a generation-based shortcut would leave the EphemeralRunnerSet pointing at a scale set that no longer exists. The measured saving did not justify the risk. Additionally: - Count deleting runners toward the scale-up total so terminating runners are not double-replaced. - Cleanup of finished runners is no longer deferred; failures now surface as reconcile errors instead of being logged and swallowed. - Status patches for the new fields use `RetryOnConflict` against a freshly read object. - Keep merging EphemeralRunnerSet annotations and labels rather than overwriting them, so metadata applied by admission webhooks or other controllers is preserved. Drift detection compares against the merge result so foreign keys cannot cause a permanent patch loop. - Add unit tests and benchmarks for both drift checks, including a guard that fails if the listener comparison is ever tightened to DeepEqual. - Cover the re-registration path, which previously had no assertion that the new runner scale set ID reaches the EphemeralRunnerSet at all.
107 lines
4.4 KiB
Go
107 lines
4.4 KiB
Go
package actionsgithubcom
|
|
|
|
import (
|
|
"github.com/actions/actions-runner-controller/apis/actions.github.com/v1alpha1"
|
|
corev1 "k8s.io/api/core/v1"
|
|
apiequality "k8s.io/apimachinery/pkg/api/equality"
|
|
)
|
|
|
|
var (
|
|
_ = ephemeralRunnerSetActionableSpecChanged
|
|
_ = nextActionableRevision
|
|
)
|
|
|
|
// ephemeralRunnerSetActionableSpecChanged reports whether the runner spec the
|
|
// EphemeralRunnerSet is running differs from the one derived from the
|
|
// AutoscalingRunnerSet, in a way that requires re-applying it to the runners.
|
|
//
|
|
// Semantic.DeepEqual is used rather than cmp.Equal or reflect.DeepEqual because
|
|
// it treats a nil slice/map as equal to an empty one. That matters here: most
|
|
// PodSpec collection fields carry omitempty, so a template containing an
|
|
// explicitly empty value (`env: []`) is dropped when the EphemeralRunnerSet is
|
|
// written and reads back as nil. A strict comparison would report drift on every
|
|
// single reconcile, bumping ActionableRevision each time and making the
|
|
// EphemeralRunnerSet controller delete every idle and pending runner, forever.
|
|
// Semantic also knows how to compare resource.Quantity, and unlike cmp.Equal it
|
|
// cannot panic on types with unexported fields.
|
|
func ephemeralRunnerSetActionableSpecChanged(current, desired *v1alpha1.EphemeralRunnerSet) bool {
|
|
if current == nil || desired == nil {
|
|
return current != desired
|
|
}
|
|
|
|
return !apiequality.Semantic.DeepEqual(current.Spec.EphemeralRunnerSpec, desired.Spec.EphemeralRunnerSpec)
|
|
}
|
|
|
|
func nextActionableRevision(current *v1alpha1.EphemeralRunnerSet) int64 {
|
|
if current == nil {
|
|
return 1
|
|
}
|
|
|
|
if current.Spec.ActionableRevision > current.Status.AppliedActionableRevision {
|
|
return current.Spec.ActionableRevision + 1
|
|
}
|
|
|
|
return current.Status.AppliedActionableRevision + 1
|
|
}
|
|
|
|
// listenerPodSpecRequiresRecreation reports whether the live listener pod must be
|
|
// deleted and rebuilt to match the desired spec.
|
|
//
|
|
// DeepDerivative, not DeepEqual: the live pod carries a large number of fields
|
|
// the desired pod never sets, written by the API server and by admission
|
|
// (nodeName, dnsPolicy, schedulerName, securityContext, enableServiceLinks,
|
|
// the default tolerations, the kube-api-access-* projected volume and its mount,
|
|
// terminationMessagePath, imagePullPolicy, secret defaultMode, ...). DeepEqual
|
|
// would therefore report drift on every reconcile of every healthy listener and
|
|
// spin in a delete/create loop. It cannot be made to work by pre-populating the
|
|
// defaults either, since nodeName is scheduler-assigned and the access-token
|
|
// volume has a generated name. See TestListenerPodSpecRequiresRecreation.
|
|
//
|
|
// The cost of DeepDerivative is that it ignores empty values on the desired side,
|
|
// so a field being *removed* is invisible to it. For everything sourced from the
|
|
// user-facing template that is harmless: the AutoscalingRunnerSet controller
|
|
// compares the whole AutoscalingListener spec with cmp.Equal and deletes the
|
|
// listener outright, which takes the pod with it. Container ports are the
|
|
// exception, because they come from the --listener-metrics-addr controller flag
|
|
// rather than from any resource, so disabling metrics would otherwise leave the
|
|
// port on the pod forever. Comparing port length is enough: additions and value
|
|
// changes are already caught by DeepDerivative, only removal is blind. The
|
|
// contents are deliberately not compared, because the API server defaults
|
|
// protocol to TCP and that would reintroduce the delete/create loop.
|
|
func listenerPodSpecRequiresRecreation(current, desired *corev1.Pod) bool {
|
|
if current == nil || desired == nil {
|
|
return current != desired
|
|
}
|
|
|
|
if listenerContainerPortsRemoved(current, desired) {
|
|
return true
|
|
}
|
|
|
|
return !apiequality.Semantic.DeepDerivative(desired.Spec, current.Spec)
|
|
}
|
|
|
|
func listenerContainerPortsRemoved(current, desired *corev1.Pod) bool {
|
|
for i := range desired.Spec.Containers {
|
|
desiredContainer := &desired.Spec.Containers[i]
|
|
currentContainer := findContainerByName(current.Spec.Containers, desiredContainer.Name)
|
|
if currentContainer == nil {
|
|
// A container the live pod does not have at all is drift that
|
|
// DeepDerivative already reports; nothing to decide here.
|
|
continue
|
|
}
|
|
if len(desiredContainer.Ports) < len(currentContainer.Ports) {
|
|
return true
|
|
}
|
|
}
|
|
return false
|
|
}
|
|
|
|
func findContainerByName(containers []corev1.Container, name string) *corev1.Container {
|
|
for i := range containers {
|
|
if containers[i].Name == name {
|
|
return &containers[i]
|
|
}
|
|
}
|
|
return nil
|
|
}
|