mirror of
https://github.com/actions-runner-controller/actions-runner-controller.git
synced 2026-09-30 18:06:52 +02:00
Replacing the integrity hash with a pod spec comparison lost the one signal the spec cannot carry. The listener mounts its config as a secret volume and parses it once at startup, so a change to the scale set URL, the TLS certificate, the metrics configuration or the scaler tuning only reaches the listener after a restart. The pod references the secret by name, so the spec is byte-identical before and after and the pod was never recreated. The desired pod now carries the config secret's resource version as an annotation, which is free to read and moves exactly when the secret is written. An empty annotation on the live pod is ignored so that pods created by an older controller are not all recreated on upgrade. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
99 lines
4.3 KiB
Go
99 lines
4.3 KiB
Go
package actionsgithubcom
|
|
|
|
import (
|
|
"github.com/actions/actions-runner-controller/logging"
|
|
)
|
|
|
|
const (
|
|
LabelKeyRunnerTemplateHash = "runner-template-hash"
|
|
LabelKeyPodTemplateHash = "pod-template-hash"
|
|
)
|
|
|
|
const (
|
|
EnvVarRunnerJITConfig = "ACTIONS_RUNNER_INPUT_JITCONFIG"
|
|
EnvVarRunnerExtraUserAgent = "GITHUB_ACTIONS_RUNNER_EXTRA_USER_AGENT"
|
|
// Environment variable setting the exit code to return when the runner version is deprecated.
|
|
// This is used by the runner to signal to the controller that it should switch off the scaleset.
|
|
EnvVarRunnerDeprecatedExitCode = "ACTIONS_RUNNER_RETURN_VERSION_DEPRECATED_EXIT_CODE"
|
|
)
|
|
|
|
// Environment variable names used to set proxy variables for containers
|
|
const (
|
|
EnvVarHTTPProxy = "http_proxy"
|
|
EnvVarHTTPSProxy = "https_proxy"
|
|
EnvVarNoProxy = "no_proxy"
|
|
)
|
|
|
|
// Labels applied to resources
|
|
const (
|
|
// Kubernetes labels
|
|
LabelKeyKubernetesPartOf = "app.kubernetes.io/part-of"
|
|
LabelKeyKubernetesComponent = "app.kubernetes.io/component"
|
|
LabelKeyKubernetesVersion = "app.kubernetes.io/version"
|
|
|
|
// Well-known Kubernetes node labels
|
|
LabelKeyKubernetesOS = "kubernetes.io/os"
|
|
|
|
// Github labels
|
|
LabelKeyGitHubScaleSetName = "actions.github.com/scale-set-name"
|
|
LabelKeyGitHubScaleSetNamespace = "actions.github.com/scale-set-namespace"
|
|
LabelKeyGitHubEnterprise = "actions.github.com/enterprise"
|
|
LabelKeyGitHubOrganization = "actions.github.com/organization"
|
|
LabelKeyGitHubRepository = "actions.github.com/repository"
|
|
)
|
|
|
|
// AutoscalingRunnerSetCleanupFinalizerName is a finalizer used to protect resources
|
|
// from deletion while AutoscalingRunnerSet is running
|
|
const AutoscalingRunnerSetCleanupFinalizerName = "actions.github.com/cleanup-protection"
|
|
|
|
const (
|
|
AnnotationKeyGitHubRunnerGroupName = "actions.github.com/runner-group-name"
|
|
AnnotationKeyGitHubRunnerScaleSetName = "actions.github.com/runner-scale-set-name"
|
|
AnnotationKeyPatchID = "actions.github.com/patch-id"
|
|
// AnnotationKeyActionableRevision records the EphemeralRunnerSet
|
|
// Spec.ActionableRevision that was in effect when the runner was created. It
|
|
// lets the set tell apart a runner that reported Outdated against the current
|
|
// runner spec from one that reported it against a spec that has since been
|
|
// updated.
|
|
AnnotationKeyActionableRevision = "actions.github.com/actionable-revision"
|
|
// AnnotationKeyListenerConfigResourceVersion records the resource version of
|
|
// the listener config secret the listener pod was created from. The pod
|
|
// mounts that secret and parses it once at startup, so a change to its
|
|
// contents only takes effect after a restart. Nothing about the change is
|
|
// visible in the pod spec, which references the secret by name, so the
|
|
// resource version is carried on the pod to make the drift observable.
|
|
AnnotationKeyListenerConfigResourceVersion = "actions.github.com/listener-config-resource-version"
|
|
)
|
|
|
|
// Labels applied to listener roles
|
|
const (
|
|
labelKeyListenerName = "auto-scaling-listener-name"
|
|
labelKeyListenerNamespace = "auto-scaling-listener-namespace"
|
|
)
|
|
|
|
// Annotations applied for later cleanup of resources
|
|
const (
|
|
AnnotationKeyManagerRoleBindingName = "actions.github.com/cleanup-manager-role-binding"
|
|
AnnotationKeyManagerRoleName = "actions.github.com/cleanup-manager-role-name"
|
|
AnnotationKeyKubernetesModeRoleName = "actions.github.com/cleanup-kubernetes-mode-role-name"
|
|
AnnotationKeyKubernetesModeRoleBindingName = "actions.github.com/cleanup-kubernetes-mode-role-binding-name"
|
|
AnnotationKeyKubernetesModeServiceAccountName = "actions.github.com/cleanup-kubernetes-mode-service-account-name"
|
|
AnnotationKeyGitHubSecretName = "actions.github.com/cleanup-github-secret-name"
|
|
AnnotationKeyNoPermissionServiceAccountName = "actions.github.com/cleanup-no-permission-service-account-name"
|
|
)
|
|
|
|
// DefaultScaleSetListenerLogLevel is the default log level applied
|
|
const DefaultScaleSetListenerLogLevel = string(logging.LogLevelDebug)
|
|
|
|
// DefaultScaleSetListenerLogFormat is the default log format applied
|
|
const DefaultScaleSetListenerLogFormat = string(logging.LogFormatText)
|
|
|
|
// ownerKey is field selector matching the owner name of a particular resource
|
|
const resourceOwnerKey = ".metadata.controller"
|
|
|
|
// EphemeralRunner pod creation failure reasons
|
|
const (
|
|
ReasonTooManyPodFailures = "TooManyPodFailures"
|
|
ReasonInvalidPodFailure = "InvalidPod"
|
|
)
|