Repository navigation
fix: strip deprecated --containerd kubelet flag before kubelet starts - #137
Draft
bschimke95 wants to merge 1 commit into
Draft
bschimke95 wants to merge 1 commit into
bschimke95 wants to merge 1 commit into
Conversation
kubelet's own systemd unit is restarted by snapd as part of a snap
refresh, independent of and not gated by k8sd's daemon startup. The
existing in-daemon cleanup (postRefreshHook -> removeDeprecatedKubeletFlags)
only runs once k8sd itself is up, which is too late: kubelet can already
be started (and crash) with the deprecated --containerd flag, removed in
Kubernetes 1.37, before k8sd gets a chance to strip it.
Extract the cleanup into a standalone snaputil.RemoveDeprecatedKubeletFlags
function and expose it as a new hidden CLI subcommand
("k8s x-cleanup deprecated-kubelet-flags"), so a snap hook can invoke it
synchronously before kubelet is (re)started, closing the race. The
existing in-daemon call now reuses the same function, removing the
duplicate implementation.
This was referenced Oct 7, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Stacked on #132. kubelet's own systemd unit is restarted by snapd as part of a
snap refresh, independent of and not gated by k8sd's daemon startup. The existing in-daemon cleanup (postRefreshHook→removeDeprecatedKubeletFlags) only runs once k8sd itself is up, which is too late: kubelet can already be started (and crash withunknown flag: --containerd) before k8sd gets a chance to strip the deprecated flag, removed in Kubernetes 1.37. Reproduced deterministically intest_version_upgrades(kubelet: 1 restart, failingcheck_service_restarts); confirmed unrelated to #132 — different hook, different subsystem (refresh vs. bootstrap).Change
snaputil.RemoveDeprecatedKubeletFlags, safe to call before k8sd itself is up (filesystem + service restart only, no API/DB dependency).k8s x-cleanup deprecated-kubelet-flags, so a snap hook can invoke it synchronously before kubelet is (re)started, closing the race at its source.