Switch receiver rollout to Recreate and pin bounded-readyz image
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s

RollingUpdate maxSurge cannot schedule a second 50m pod on a node
packed to 99% CPU requests. Recreate replaces in place; the Service
already has no ready endpoints.

Image sha256:ec15f63d… is commit bc3d80f. Local release check passed
against disposable Postgres. No schema migration. Live Ready still
depends on a fresh runtime lease from ESO/OpenBao.

Assistant: grok
Assistant-Session: 01a0a182-bab7-7f11-b32b-d06f3af52082
This commit is contained in:
tegwick 2026-09-14 23:01:23 +02:00
parent bc3d80fbd9
commit cf8c740b1b
4 changed files with 47 additions and 7 deletions

View file

@ -55,10 +55,10 @@ spec:
replicas: 1
revisionHistoryLimit: 5
strategy:
type: RollingUpdate
rollingUpdate:
maxUnavailable: 0
maxSurge: 1
# Recreate, not RollingUpdate: the node is packed to 99% CPU requests, so
# maxSurge: 1 cannot schedule a second 50m pod. The Service already has no
# ready endpoints, so replacing in place does not add a delivery gap.
type: Recreate
selector:
matchLabels:
app.kubernetes.io/name: audit-core
@ -86,7 +86,7 @@ spec:
- name: audit-core
# REPLACE at release time with the built digest. A mutable tag is not
# an immutable image, and `:latest` must never be the only reference.
image: forgejo.coulomb.social/coulomb/audit-core@sha256:c82e0442de0fd181342916ae9cd5d6de41d859e1efda637bd93936c67873afa5
image: forgejo.coulomb.social/coulomb/audit-core@sha256:ec15f63d49226bfe507af2bc38ffbd5e83f549ba2c6d1ae7a338e7e053f34615
imagePullPolicy: IfNotPresent
ports:
- name: http