Skip to content

fix: strip deprecated --containerd kubelet flag before kubelet starts - #137

Draft
bschimke95 wants to merge 1 commit into
fix/join-wait-for-bootstrap-node-registrationfrom
fix/post-refresh-deprecated-kubelet-flags
Draft

bschimke95 wants to merge 1 commit into
fix/join-wait-for-bootstrap-node-registrationfrom
fix/post-refresh-deprecated-kubelet-flags

Conversation

@bschimke95

Copy link
Copy Markdown
Collaborator

Stacked on #132. kubelet's own systemd unit is restarted by snapd as part of a snap refresh, independent of and not gated by k8sd's daemon startup. The existing in-daemon cleanup (postRefreshHook → removeDeprecatedKubeletFlags) only runs once k8sd itself is up, which is too late: kubelet can already be started (and crash with unknown flag: --containerd) before k8sd gets a chance to strip the deprecated flag, removed in Kubernetes 1.37. Reproduced deterministically in test_version_upgrades (kubelet: 1 restart, failing check_service_restarts); confirmed unrelated to #132 — different hook, different subsystem (refresh vs. bootstrap).

Change

  • Extract the cleanup into a standalone snaputil.RemoveDeprecatedKubeletFlags, safe to call before k8sd itself is up (filesystem + service restart only, no API/DB dependency).
  • Expose it as a new hidden CLI subcommand, k8s x-cleanup deprecated-kubelet-flags, so a snap hook can invoke it synchronously before kubelet is (re)started, closing the race at its source.
  • The existing in-daemon call now reuses the same function instead of duplicating the logic.

kubelet's own systemd unit is restarted by snapd as part of a snap
refresh, independent of and not gated by k8sd's daemon startup. The
existing in-daemon cleanup (postRefreshHook -> removeDeprecatedKubeletFlags)
only runs once k8sd itself is up, which is too late: kubelet can already
be started (and crash) with the deprecated --containerd flag, removed in
Kubernetes 1.37, before k8sd gets a chance to strip it.

Extract the cleanup into a standalone snaputil.RemoveDeprecatedKubeletFlags
function and expose it as a new hidden CLI subcommand
("k8s x-cleanup deprecated-kubelet-flags"), so a snap hook can invoke it
synchronously before kubelet is (re)started, closing the race. The
existing in-daemon call now reuses the same function, removing the
duplicate implementation.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant