Skip to content

Conversation

@CoreyCook8
Copy link
Contributor

Based on the issue described here : kubernetes/kubernetes#133442

priorityClassName is currently ignored by Kubelet for static pod files so setting this value has no impact on the gracefulShutdown order causing the static pods to start to be killed as soon as shutdown begins.

To prevent this we must set priority explicitly

@openshift-ci openshift-ci bot requested a review from ingvagabund August 29, 2025 17:21
@openshift-ci openshift-ci bot added the needs-ok-to-test Indicates a PR that requires an org member to verify it is safe to test. label Aug 29, 2025
@openshift-ci
Copy link
Contributor

openshift-ci bot commented Aug 29, 2025

Hi @CoreyCook8. Thanks for your PR.

I'm waiting for a openshift member to verify that this patch is reasonable to test. If it is, they should reply with /ok-to-test on its own line. Until that is done, I will not automatically test new commits in this PR, but the usual testing commands by org members will still work. Regular contributors should join the org to skip this step.

Once the patch is verified, the new status will be reflected by the ok-to-test label.

I understand the commands that are listed here.

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@CoreyCook8
Copy link
Contributor Author

👋 @ingvagabund you're the recommended reviewer here, would you be able to take a look at these? 🙏 We opened 4 PRs to fix this issue, one has been merged. I linked the other two below:

openshift/cluster-kube-controller-manager-operator#865
openshift/cluster-kube-apiserver-operator#1915

@ingvagabund
Copy link
Member

/ok-to-test

@openshift-ci openshift-ci bot added ok-to-test Indicates a non-member PR verified by an org member that is safe to test. and removed needs-ok-to-test Indicates a PR that requires an org member to verify it is safe to test. labels Sep 15, 2025
- mountPath: /etc/kubernetes/static-pod-certs
name: cert-dir
hostNetwork: true
priority: 2000001000
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Priority admission plugin mentions:

// if the pod contained a priority that differs from the one computed from the priority class, error

As long as the priority of system-node-critical PC does not change we are ok.

Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@CoreyCook8 we need to introduce a new e2e test under https://github.com/openshift/origin/tree/main/test/extended to make sure the priority number does not change for system-node-critical. Would you be willing to go through this exercise? :)

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

👋 I created openshift/origin#30268 if you don't mind taking a look and giving an ok-to-test?

@ingvagabund
Copy link
Member

/approve
/lgtm

@ingvagabund
Copy link
Member

/retest-required

@openshift-ci openshift-ci bot added lgtm Indicates that a PR is ready to be merged. approved Indicates a PR has been approved by an approver from all required OWNERS files. labels Oct 13, 2025
@ingvagabund
Copy link
Member

/verified by ci/prow/e2e-aws-operator

The operator needs to see the mirrored pod up and running. The KA admission plugin will fail when the priority class number is different from what is normally defined.

@openshift-ci-robot openshift-ci-robot added the verified Signifies that the PR passed pre-merge verification criteria label Oct 14, 2025
@openshift-ci-robot
Copy link

@ingvagabund: This PR has been marked as verified by ci/prow/e2e-aws-operator.

In response to this:

/verified by ci/prow/e2e-aws-operator

The operator needs to see the mirrored pod up and running. The KA admission plugin will fail when the priority class number is different from what is normally defined.

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@ingvagabund
Copy link
Member

/re-title no-jira: Add priority field to prevent early shutdown

@ingvagabund
Copy link
Member

@CoreyCook8 the unit tests are failing

@ingvagabund
Copy link
Member

/retitle no-jira: Add priority field to prevent early shutdown

@openshift-ci openshift-ci bot changed the title Add priority field to prevent early shutdown no-jira: Add priority field to prevent early shutdown Oct 14, 2025
@openshift-ci-robot openshift-ci-robot added the jira/valid-reference Indicates that this PR references a valid Jira ticket of any type. label Oct 14, 2025
@openshift-ci-robot
Copy link

@CoreyCook8: This pull request explicitly references no jira issue.

In response to this:

Based on the issue described here : kubernetes/kubernetes#133442

priorityClassName is currently ignored by Kubelet for static pod files so setting this value has no impact on the gracefulShutdown order causing the static pods to start to be killed as soon as shutdown begins.

To prevent this we must set priority explicitly

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@openshift-ci-robot
Copy link

/retest-required

Remaining retests: 0 against base HEAD 6007b0f and 2 for PR HEAD 48e3986 in total

@openshift-ci-robot openshift-ci-robot removed the verified Signifies that the PR passed pre-merge verification criteria label Oct 14, 2025
@openshift-ci openshift-ci bot removed the lgtm Indicates that a PR is ready to be merged. label Oct 14, 2025
@openshift-ci
Copy link
Contributor

openshift-ci bot commented Oct 14, 2025

@CoreyCook8: all tests passed!

Full PR test history. Your PR dashboard.

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here.

@ingvagabund
Copy link
Member

/lgtm

@ingvagabund
Copy link
Member

/verified by ci/prow/e2e-aws-operator

@openshift-ci openshift-ci bot added the lgtm Indicates that a PR is ready to be merged. label Oct 14, 2025
@openshift-ci-robot openshift-ci-robot added the verified Signifies that the PR passed pre-merge verification criteria label Oct 14, 2025
@openshift-ci-robot
Copy link

@ingvagabund: This PR has been marked as verified by ci/prow/e2e-aws-operator.

In response to this:

/verified by ci/prow/e2e-aws-operator

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@openshift-ci
Copy link
Contributor

openshift-ci bot commented Oct 14, 2025

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: CoreyCook8, ingvagabund

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@openshift-merge-bot openshift-merge-bot bot merged commit 75b90c6 into openshift:main Oct 14, 2025
13 checks passed
@dinhxuanvu
Copy link
Member

/cherry-pick release-4.20

@openshift-cherrypick-robot

@dinhxuanvu: new pull request created: #586

In response to this:

/cherry-pick release-4.20

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved Indicates a PR has been approved by an approver from all required OWNERS files. jira/valid-reference Indicates that this PR references a valid Jira ticket of any type. lgtm Indicates that a PR is ready to be merged. ok-to-test Indicates a non-member PR verified by an org member that is safe to test. verified Signifies that the PR passed pre-merge verification criteria

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants