Commit Graph

29592 Commits

Author SHA1 Message Date
Patrick Ohly
f692e4e8f0 DRA upgrade/downgrade: add some debug output for stopping commands
In some (all?) CI jobs the initial kubelet instance keeps running, despite
command context cancellation. Not reproducible locally, so additional output
was necessary to track down the root cause in CI runs: signal propagation via
sudo didn't work for kube-proxy and kubelet, but only for those two and only in
the CI. The fix is to change the CI jobs so that they disable the usage of
sudo.

While at it, simplify by replacing atomic.Pointer with atomic.Boole.
2026-03-09 10:40:33 +01:00
Kubernetes Prow Robot
800a58b7c5 Merge pull request #137456 from liggitt/go126
Update go.mod to go 1.26, fix 1.26 vet errors
2026-03-06 10:58:23 +05:30
Kubernetes Prow Robot
4915f3f8b3 Merge pull request #137304 from aaron-prindle/fieldsv1-encapsulation
refactor: fieldsv1 encapsulation via accessors and deprecation of direct "Raw" field usage
2026-03-06 06:50:17 +05:30
Jordan Liggitt
45900a1deb Fix vet error 2026-03-05 18:11:02 -05:00
Jon Huhn
e52fe3b2fb Use HTTP GET for Node log queries in e2e logcheck 2026-03-05 16:38:24 -06:00
Aaron Prindle
e57b3a74f3 refactor: update in-tree FieldsV1 consumers to use format-specific accessors 2026-03-05 22:23:05 +00:00
Kubernetes Prow Robot
b50a6aa7cf Merge pull request #137374 from enj/enj/f/constrained_impersonation_metrics
KEP-5284: add constrained impersonation metrics
2026-03-06 03:42:25 +05:30
Kubernetes Prow Robot
dfa7c2bc0a Merge pull request #137329 from natasha41575/retry_oomscoreadj_verification
[InPlacePodVerticalScaling] deflake pod resize oom_score_adj check
2026-03-06 03:42:17 +05:30
Kubernetes Prow Robot
2a41bb390e Merge pull request #136759 from pravk03/ndf-guaranteedQos-fix
Remove `GuaranteedQoSPodCPUResize` declared feature
2026-03-06 02:00:18 +05:30
Monis Khan
ba2a68e1db KEP-5284: add constrained impersonation metrics
See https://kep.k8s.io/5284 for details.

apiserver_impersonation_attempts_total{mode, decision}
apiserver_impersonation_attempts_duration_seconds{mode, decision}
apiserver_impersonation_authorization_attempts_total{mode, decision}
apiserver_impersonation_authorization_attempts_duration_seconds{mode, decision}

Signed-off-by: Monis Khan <mok@microsoft.com>
2026-03-05 15:26:45 -05:00
Kubernetes Prow Robot
b5e83c2d21 Merge pull request #136762 from HarshalNeelkamal/client-ca-reload
Introduce a kubelet configuration that reloads ClientCA in TLSConfig
2026-03-06 00:46:25 +05:30
Kubernetes Prow Robot
c6f70e3a38 Merge pull request #136399 from tico88612/feat/storage-metric-beta
Rename metric `volume_operation_total_errors` to `volume_operation_errors_total`
2026-03-06 00:46:18 +05:30
Natasha Sarkar
8504c0d4e3 deflake pod resize oom_score_adj check 2026-03-05 18:36:03 +00:00
Rita Zhang
c4f88de33e Move DRAAdminAccess feature to GA (#137373)
* Move DRAAdminAccess feature to GA

Signed-off-by: Rita Zhang <rita.z.zhang@gmail.com>

* address comments

Signed-off-by: Rita Zhang <rita.z.zhang@gmail.com>

---------

Signed-off-by: Rita Zhang <rita.z.zhang@gmail.com>
2026-03-05 23:42:21 +05:30
Kubernetes Prow Robot
3369e51e09 Merge pull request #137080 from cpanato/update-go-1.26
Bump dependencies, images and versions used to Go 1.26.0 and distroless iptables
2026-03-05 21:56:21 +05:30
Kubernetes Prow Robot
8bd1505fc0 Merge pull request #137108 from pohly/logtools-update
golangci-lint: bump to logtools v0.10.1
2026-03-05 10:14:16 +05:30
Harshal Neelkamal
40d8705d28 Introduce a kubelet-server configuration that allows reloading ClientCA in TLSConfig 2026-03-05 02:04:08 +00:00
Kubernetes Prow Robot
83d2b7f7e0 Merge pull request #136568 from sairameshv/extRes_test
KEP-5004: Add upgrade/downgrade e2e tests for the DRAExtendedResources feature
2026-03-05 06:16:18 +05:30
Kubernetes Prow Robot
ad854f3495 Merge pull request #137411 from jpbetz/add-controlplane-test-owners
Add OWNERS file for test/integration/controlplane
2026-03-05 05:02:33 +05:30
Kubernetes Prow Robot
5f9a476986 Merge pull request #137337 from iPraveenParihar/fix/snapshot-metadata-script-permissions
e2e: add executable permission to snapshot metadata test script
2026-03-05 05:02:26 +05:30
Praveen Krishna
8af985c4fa fix: Remove GuaranteedQoSPodCPUResize declared feature 2026-03-04 21:17:44 +00:00
Kubernetes Prow Robot
281e96a048 Merge pull request #137403 from soltysh/replicaset_wait
Wait for RS to report status rather than count pods
2026-03-05 02:24:18 +05:30
Joe Betz
a48ca688da Add OWNERS file for test/integration/controlplane 2026-03-04 14:54:37 -05:00
Arda Güçlü
d37765936d kubectl wait: Support multiple conditions (#136855)
* kubectl wait: Support multiple conditions

* Error out when --for is not passed

* Add examples for AND'ing and OR'ing multiple conditions
2026-03-04 23:30:27 +05:30
kfess
7ea5b88209 cleanup: remove suggestfor from wait command (#137266)
* feature: remove suggestfor from wait command

* fix test case
2026-03-04 20:08:27 +05:30
Kubernetes Prow Robot
6ebcc611d2 Merge pull request #137221 from bishal7679/fix/flaky-kubectl-logs-137180
fix: [sig-cli] flaky kubectl logs --all-pods --all-containers Deployment test
2026-03-04 20:08:20 +05:30
Maciej Szulik
0dec4fa548 Wait for RS to report status rather than count pods
Signed-off-by: Maciej Szulik <soltysh@gmail.com>
2026-03-04 14:33:55 +01:00
Kubernetes Prow Robot
bd3c97fbd8 Merge pull request #137355 from lukaszwojciechowski/fix-cpuset-creation
cpumanager: Replace cpuset.CPUSet{} with cpuset.New() for proper initialization
2026-03-04 18:04:29 +05:30
Kubernetes Prow Robot
3c218d83cc Merge pull request #136973 from ardaguclu/valid-containers
List containers when given container is not found
2026-03-04 17:12:31 +05:30
Patrick Ohly
b895ce734f golangci-lint: bump to logtools v0.10.1
This fixes a bug that caused log calls involving `klog.Logger` to not be
checked.

As a result we have to fix some code that is now considered faulty:

    ERROR: pkg/controller/serviceaccount/tokens_controller.go:382:1: A function should accept either a context or a logger, but not both. Having both makes calling the function harder because it must be defined whether the context must contain the logger and callers have to follow that. (logcheck)
    ERROR: func (e *TokensController) generateTokenIfNeeded(ctx context.Context, logger klog.Logger, serviceAccount *v1.ServiceAccount, cachedSecret *v1.Secret) ( /* retry */ bool, error) {
    ERROR: ^
    ERROR: pkg/controller/storageversionmigrator/storageversionmigrator.go:299:1: A function should accept either a context or a logger, but not both. Having both makes calling the function harder because it must be defined whether the context must contain the logger and callers have to follow that. (logcheck)
    ERROR: func (svmc *SVMController) runMigration(ctx context.Context, logger klog.Logger, gvr schema.GroupVersionResource, resourceMonitor *garbagecollector.Monitor, toBeProcessedSVM *svmv1beta1.StorageVersionMigration, listResourceVersion string) (err error, failed bool) {
    ERROR: ^
    ERROR: pkg/proxy/node.go:121:3: logging function "Error" should not use format specifier "%q" (logcheck)
    ERROR: 		klog.FromContext(ctx).Error(nil, "Timed out waiting for node %q to exist", nodeName)
    ERROR: 		^
    ERROR: pkg/proxy/node.go:123:3: logging function "Error" should not use format specifier "%q" (logcheck)
    ERROR: 		klog.FromContext(ctx).Error(nil, "Timed out waiting for node %q to be assigned IPs", nodeName)
    ERROR: 		^
    ERROR: pkg/scheduler/backend/queue/scheduling_queue.go:610:1: A function should accept either a context or a logger, but not both. Having both makes calling the function harder because it must be defined whether the context must contain the logger and callers have to follow that. (logcheck)
    ERROR: func (p *PriorityQueue) runPreEnqueuePlugin(ctx context.Context, logger klog.Logger, pl fwk.PreEnqueuePlugin, pInfo *framework.QueuedPodInfo, shouldRecordMetric bool) *fwk.Status {
    ERROR: ^
    ERROR: pkg/scheduler/framework/plugins/dynamicresources/extendeddynamicresources.go:286:1: A function should accept either a context or a logger, but not both. Having both makes calling the function harder because it must be defined whether the context must contain the logger and callers have to follow that. (logcheck)
    ERROR: func (pl *DynamicResources) deleteClaim(ctx context.Context, claim *resourceapi.ResourceClaim, logger klog.Logger) error {
    ERROR: ^
    ERROR: pkg/scheduler/framework/plugins/dynamicresources/extendeddynamicresources.go:499:1: A function should accept either a context or a logger, but not both. Having both makes calling the function harder because it must be defined whether the context must contain the logger and callers have to follow that. (logcheck)
    ERROR: func (pl *DynamicResources) waitForExtendedClaimInAssumeCache(
    ERROR: ^
    ERROR: pkg/scheduler/framework/plugins/dynamicresources/extendeddynamicresources.go:528:1: A function should accept either a context or a logger, but not both. Having both makes calling the function harder because it must be defined whether the context must contain the logger and callers have to follow that. (logcheck)
    ERROR: func (pl *DynamicResources) createExtendedResourceClaimInAPI(
    ERROR: ^
    ERROR: pkg/scheduler/framework/plugins/dynamicresources/extendeddynamicresources.go:592:1: A function should accept either a context or a logger, but not both. Having both makes calling the function harder because it must be defined whether the context must contain the logger and callers have to follow that. (logcheck)
    ERROR: func (pl *DynamicResources) unreserveExtendedResourceClaim(ctx context.Context, logger klog.Logger, pod *v1.Pod, state *stateData) {
    ERROR: ^
    ERROR: pkg/scheduler/framework/runtime/batch.go:171:1: A function should accept either a context or a logger, but not both. Having both makes calling the function harder because it must be defined whether the context must contain the logger and callers have to follow that. (logcheck)
    ERROR: func (b *OpportunisticBatch) batchStateCompatible(ctx context.Context, logger klog.Logger, pod *v1.Pod, signature fwk.PodSignature, cycleCount int64, state fwk.CycleState, nodeInfos fwk.NodeInfoLister) bool {
    ERROR: ^
    ERROR: staging/src/k8s.io/component-base/featuregate/feature_gate.go:890:4: Additional arguments to Info should always be Key Value pairs. Please check if there is any key or value missing. (logcheck)
    ERROR: 			logger.Info("Warning: SetEmulationVersionAndMinCompatibilityVersion will change already queried feature", "featureGate", feature, "oldValue", oldVal, newVal)
    ERROR: 			^
    ERROR: test/images/sample-device-plugin/sampledeviceplugin.go:108:2: logging function "Info" should not use format specifier "%s" (logcheck)
    ERROR: 	logger.Info("pluginSocksDir: %s", pluginSocksDir)
    ERROR: 	^
    ERROR: test/images/sample-device-plugin/sampledeviceplugin.go:123:2: logging function "Info" should not use format specifier "%s" (logcheck)
    ERROR: 	logger.Info("CDI_ENABLED: %s", cdiEnabled)
    ERROR: 	^

While waiting for this to merge, another call was added which also doesn't
follow conventions:

    ERROR: pkg/kubelet/kubelet.go:2454:1: A function should accept either a context or a logger, but not both. Having both makes calling the function harder because it must be defined whether the context must contain the logger and callers have to follow that. (logcheck)
    ERROR: func (kl *Kubelet) deletePod(ctx context.Context, logger klog.Logger, pod *v1.Pod) error {
    ERROR: ^

Contextual logging has been beta and enabled by default for several releases
now. It's mostly just a matter of wrapping up and declaring it GA. Therefore
the calls which directly call WithName or WithValues (always have an effect)
are left as-is instead of converting them to use the klog wrappers (support
disabling the effect). To allow that, the linter gets reconfigured to not
complain about this anymore, anywhere.

The calls which would have to be fixed otherwise are:

    ERROR: pkg/kubelet/cm/dra/claiminfo.go:170:11: function "WithName" should be called through klogr.LoggerWithName (logcheck)
    ERROR: 	logger = logger.WithName("dra-claiminfo")
    ERROR: 	         ^
    ERROR: pkg/kubelet/cm/dra/healthinfo.go:45:11: function "WithName" should be called through klogr.LoggerWithName (logcheck)
    ERROR: 	logger = logger.WithName("dra-healthinfo")
    ERROR: 	         ^
    ERROR: pkg/kubelet/cm/dra/healthinfo.go:89:11: function "WithName" should be called through klogr.LoggerWithName (logcheck)
    ERROR: 	logger = logger.WithName("dra-healthinfo")
    ERROR: 	         ^
    ERROR: pkg/kubelet/cm/dra/healthinfo.go:157:11: function "WithName" should be called through klogr.LoggerWithName (logcheck)
    ERROR: 	logger = logger.WithName("dra-healthinfo")
    ERROR: 	         ^
    ERROR: pkg/kubelet/cm/dra/manager.go:175:12: function "WithName" should be called through klogr.LoggerWithName (logcheck)
    ERROR: 	logger := klog.FromContext(ctx).WithName("dra-manager")
    ERROR: 	          ^
    ERROR: pkg/kubelet/cm/dra/manager.go:239:12: function "WithName" should be called through klogr.LoggerWithName (logcheck)
    ERROR: 	logger := klog.FromContext(ctx).WithName("dra-manager")
    ERROR: 	          ^
    ERROR: pkg/kubelet/cm/dra/manager.go:593:12: function "WithName" should be called through klogr.LoggerWithName (logcheck)
    ERROR: 	logger := klog.FromContext(ctx).WithName("dra-manager")
    ERROR: 	          ^
    ERROR: pkg/kubelet/cm/dra/manager.go:781:12: function "WithName" should be called through klogr.LoggerWithName (logcheck)
    ERROR: 	logger := klog.FromContext(context.Background()).WithName("dra-manager")
    ERROR: 	          ^
    ERROR: pkg/kubelet/cm/dra/manager.go:898:12: function "WithName" should be called through klogr.LoggerWithName (logcheck)
    ERROR: 	logger := klog.FromContext(ctx).WithName("dra-manager")
    ERROR: 	          ^
    ERROR: pkg/kubelet/cm/dra/manager_test.go:1638:15: function "WithName" should be called through klogr.LoggerWithName (logcheck)
    ERROR: 				logger := klog.FromContext(streamCtx).WithName(st.Name())
    ERROR: 				          ^
    ERROR: pkg/kubelet/cm/dra/plugin/dra_plugin.go:77:12: function "WithName" should be called through klogr.LoggerWithName (logcheck)
    ERROR: 	logger := klog.FromContext(ctx).WithName("dra-plugin")
    ERROR: 	          ^
    ERROR: pkg/kubelet/cm/dra/plugin/dra_plugin.go:108:12: function "WithName" should be called through klogr.LoggerWithName (logcheck)
    ERROR: 	logger := klog.FromContext(ctx).WithName("dra-plugin")
    ERROR: 	          ^
    ERROR: pkg/kubelet/cm/dra/plugin/dra_plugin.go:161:12: function "WithName" should be called through klogr.LoggerWithName (logcheck)
    ERROR: 	logger := klog.FromContext(ctx).WithName("dra-plugin")
    ERROR: 	          ^
    ERROR: staging/src/k8s.io/dynamic-resource-allocation/resourceslice/tracker/tracker.go:695:14: function "WithValues" should be called through klogr.LoggerWithValues (logcheck)
    ERROR: 			logger := logger.WithValues("device", deviceID)
    ERROR: 			          ^
    ERROR: test/integration/apiserver/watchcache_test.go:42:54: function "WithName" should be called through klogr.LoggerWithName (logcheck)
    ERROR: 	etcd0URL, stopEtcd0, err := framework.RunCustomEtcd(klog.FromContext(ctx).WithName("etcd0"), "etcd_watchcache0", etcdArgs)
    ERROR: 	                                                    ^
    ERROR: test/integration/apiserver/watchcache_test.go:47:54: function "WithName" should be called through klogr.LoggerWithName (logcheck)
    ERROR: 	etcd1URL, stopEtcd1, err := framework.RunCustomEtcd(klog.FromContext(ctx).WithName("etcd1"), "etcd_watchcache1", etcdArgs)
    ERROR: 	                                                    ^
    ERROR: test/integration/scheduler_perf/scheduler_perf.go:1149:12: function "WithName" should be called through klogr.LoggerWithName (logcheck)
    ERROR: 		logger = logger.WithName(tCtx.Name())
    ERROR: 		         ^
2026-03-04 12:08:18 +01:00
Sai Ramesh Vanka
4bc4b7313e Address review comments
- Rebase the code with #137046 changes
- Remove the duplication in the DRAExtendedResource upgrade/downgrade test code

Signed-off-by: Sai Ramesh Vanka <svanka@redhat.com>
2026-03-04 12:48:44 +05:30
Kubernetes Prow Robot
dd0958fece Merge pull request #136851 from jiefeng-xu/jiefeng/fix-gpu-flake-136378
test/e2e/node: reduce flakiness in GPU nvidia-smi test
2026-03-04 08:56:17 +05:30
Kubernetes Prow Robot
80eaaa3991 Merge pull request #137192 from kannon92/observedpodgeneration-move-all-to-conformance
promote two test cases for Observedgeneration to conformance
2026-03-04 07:24:16 +05:30
Kubernetes Prow Robot
5bc6d200a2 Merge pull request #137379 from aramase/aramase/c/drop_v1alpha1_webhookadmission
drop v1alpha1 webhookadmission configuration
2026-03-04 05:20:35 +05:30
Kubernetes Prow Robot
5f18de61b0 Merge pull request #137174 from richabanker/flagz-beta
Graduate flagz API to beta
2026-03-04 05:20:18 +05:30
Kubernetes Prow Robot
cb01fb2641 Merge pull request #136368 from bhope/metrics-beta-endpointslice-controller
Promote endpointslice metrics to beta
2026-03-04 04:30:20 +05:30
Anish Ramasekar
2727957fec drop v1alpha1 webhookadmission configuration
Signed-off-by: Anish Ramasekar <anish.ramasekar@gmail.com>
2026-03-03 13:31:09 -08:00
Richa Banker
adbf7dee82 graduate config.k8s.io.v1alpha1.flagz to beta 2026-03-03 13:12:16 -08:00
Kevin Hannon
b26954bc0f merging the pod rejection
generation test into pod_admission.go and commenting out
PodReadyToStartContainers. Conformance promotion will follow in a
separate PR once this lands green, per review feedback.
2026-03-03 13:58:04 -05:00
Kubernetes Prow Robot
be6162afb8 Merge pull request #135196 from harche/i133202
KEP-4680: Add message field support to DRA device health reporting
2026-03-04 00:11:24 +05:30
Kubernetes Prow Robot
56262e6ab1 Merge pull request #137173 from richabanker/statusz-beta
Graduate statusz API to beta
2026-03-03 22:07:46 +05:30
Kubernetes Prow Robot
13010f06b2 Merge pull request #137167 from pohly/dra-device-taints-update-timestamp
DRA device taints: automatically bump TimeAdded when changing effect
2026-03-03 22:07:37 +05:30
Prathamesh Bhope
f1bf45e189 endpointslice/metrics: promote metrics to beta and add test 2026-03-03 08:37:35 -08:00
Kubernetes Prow Robot
5941fed3d6 Merge pull request #136912 from dfajmon/selinux-ga
Promote SELinuxChangePolicy & SELinuxMountReadWriteOncePod to GA
2026-03-03 22:07:29 +05:30
Kubernetes Prow Robot
228701ab24 Merge pull request #136611 from sunya-ch/kep-5075-beta
DRA: Promote DRAConsumableCapacity to Beta
2026-03-03 22:07:21 +05:30
Sunyanan Choochotkaew
e035c41256 DRA: Promote DRAConsumableCapacity to Beta
Signed-off-by: Sunyanan Choochotkaew <sunyanan.choochotkaew1@ibm.com>
2026-03-03 18:30:26 +09:00
Kubernetes Prow Robot
b9e0f9d10a Merge pull request #137289 from ffromani/e2e-node-cpumanager-pod-create
e2e: node: cpumanager: create helper creation function
2026-03-03 14:59:20 +05:30
Kubernetes Prow Robot
619ddd3117 Merge pull request #136821 from ffromani/fix-podresources-api
node: e2e: fix podresources api test
2026-03-03 12:20:35 +05:30
Kubernetes Prow Robot
7da167d135 Merge pull request #137252 from Chandan9112/fix-pod-observed-generation-test-image
Use localhost Image Reference in PodObservedGenerationTracking E2E Test
2026-03-03 06:30:59 +05:30
Lukasz Wojciechowski
48eecb3670 Replace cpuset.CPUSet{} with cpuset.New()
This patch replaces direct struct initialization cpuset.CPUSet{} with
cpuset.New() to ensure the internal map is properly initialized.

While most CPUSet methods work correctly without this change, the Equals
method uses reflect.DeepEqual which returns false when comparing CPUSet
instances where one has a nil internal map and the other has an initialized
(empty) map. This can lead to unexpected false negatives in equality checks.

For example, the following comparison would incorrectly return false:
  cpuset.CPUSet{}.Equals(cpuset.New())

This change ensures consistent behavior across all CPUSet operations.

Signed-off-by: Lukasz Wojciechowski <l.wojciechow@partner.samsung.com>
2026-03-03 01:42:28 +01:00