Prevent successful containers from restarting with OnFailure restart policy

This commit is contained in:
Joel Smith 2017-10-27 09:57:00 -06:00
parent b00c15f1a4
commit 5f6c022737

View File

@ -268,13 +268,22 @@ func (m *manager) TerminatePod(pod *v1.Pod) {
// checkContainerStateTransition ensures that no container is trying to transition // checkContainerStateTransition ensures that no container is trying to transition
// from a terminated to non-terminated state, which is illegal and indicates a // from a terminated to non-terminated state, which is illegal and indicates a
// logical error in the kubelet. // logical error in the kubelet.
func checkContainerStateTransition(oldStatuses, newStatuses []v1.ContainerStatus) error { func checkContainerStateTransition(oldStatuses, newStatuses []v1.ContainerStatus, restartPolicy v1.RestartPolicy) error {
for _, newStatus := range newStatuses { // If we should always restart, containers are allowed to leave the terminated state
for _, oldStatus := range oldStatuses { if restartPolicy == v1.RestartPolicyAlways {
if newStatus.Name != oldStatus.Name { return nil
continue }
} for _, oldStatus := range oldStatuses {
if oldStatus.State.Terminated != nil && newStatus.State.Terminated == nil { // Skip any container that wasn't terminated
if oldStatus.State.Terminated == nil {
continue
}
// Skip any container that failed but is allowed to restart
if oldStatus.State.Terminated.ExitCode != 0 && restartPolicy == v1.RestartPolicyOnFailure {
continue
}
for _, newStatus := range newStatuses {
if oldStatus.Name == newStatus.Name && newStatus.State.Terminated == nil {
return fmt.Errorf("terminated container %v attempted illegal transition to non-terminated state", newStatus.Name) return fmt.Errorf("terminated container %v attempted illegal transition to non-terminated state", newStatus.Name)
} }
} }
@ -297,15 +306,13 @@ func (m *manager) updateStatusInternal(pod *v1.Pod, status v1.PodStatus, forceUp
} }
// Check for illegal state transition in containers // Check for illegal state transition in containers
if pod.Spec.RestartPolicy == v1.RestartPolicyNever { if err := checkContainerStateTransition(oldStatus.ContainerStatuses, status.ContainerStatuses, pod.Spec.RestartPolicy); err != nil {
if err := checkContainerStateTransition(oldStatus.ContainerStatuses, status.ContainerStatuses); err != nil { glog.Errorf("Status update on pod %v/%v aborted: %v", pod.Namespace, pod.Name, err)
glog.Errorf("Status update on pod %v/%v aborted: %v", pod.Namespace, pod.Name, err) return false
return false }
} if err := checkContainerStateTransition(oldStatus.InitContainerStatuses, status.InitContainerStatuses, pod.Spec.RestartPolicy); err != nil {
if err := checkContainerStateTransition(oldStatus.InitContainerStatuses, status.InitContainerStatuses); err != nil { glog.Errorf("Status update on pod %v/%v aborted: %v", pod.Namespace, pod.Name, err)
glog.Errorf("Status update on pod %v/%v aborted: %v", pod.Namespace, pod.Name, err) return false
return false
}
} }
// Set ReadyCondition.LastTransitionTime. // Set ReadyCondition.LastTransitionTime.