Apply rail-knative's declared Knative CPU requests in the installer (RAIL-BS-WP-0015).
install.sh now renders the checksum-verified upstream assets through kustomize overlays: CRDs first and verbatim, then serving-core and kourier with the six CPU requests lowered live on 2026-09-21, the Kourier Service as ClusterIP and the Envoy image pinned. verify.sh checks the requests read-only, and tests/test_knative_render.py proves the render offline against upstream and rail-knative's declaration. Not run against the cluster. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Assistant: claude-code Assistant-Model: opus Assistant-Process: 63291@bnt-lap001 Assistant-Session: 8bd77868-ca68-4f49-bb1e-d539ecc0d703
This commit is contained in:
parent
4abd781ce3
commit
3a5432270e
11 changed files with 465 additions and 16 deletions
|
|
@ -2,7 +2,20 @@
|
|||
|
||||
`install.sh` verifies repository-pinned SHA-256 checksums for the upstream
|
||||
Serving and Kourier v1.22.0 assets before applying them over SSH. It is
|
||||
idempotent. Kourier is kept `ClusterIP`; public entry through Traefik, DNS, and
|
||||
idempotent.
|
||||
|
||||
It does not apply the upstream manifests as published. `render.sh` (also
|
||||
usable on its own, with no cluster contact) renders them through the kustomize
|
||||
overlays in `overlays/`: CRDs verbatim and first, because `serving-core.yaml`
|
||||
repeats one of them; then serving-core and kourier with the CPU requests that
|
||||
rail-knative declares in `substrate/v1.22.0/cpu-requests.patch.yaml`
|
||||
(activator 50m, autoscaler/controller/webhook/net-kourier-controller 30m,
|
||||
3scale-kourier-gateway 50m), the Kourier Service as `ClusterIP` and the Envoy
|
||||
gateway image pinned to `ENVOY_IMAGE`. Memory requests and all limits stay
|
||||
upstream. Applying the unpatched upstream files restores 300m/200m/100m and
|
||||
exhausts railiance01's CPU requests again. `tests/test_knative_render.py`
|
||||
proves the render offline and fails if these overlays drift from rail-knative's
|
||||
declaration. `install.sh` needs a local `kubectl` for `kubectl kustomize`. Kourier is kept `ClusterIP`; public entry through Traefik, DNS, and
|
||||
TLS requires separate reef admission evidence.
|
||||
|
||||
The installer enables only Knative's
|
||||
|
|
@ -10,7 +23,8 @@ The installer enables only Knative's
|
|||
containers for fail-closed admission checks such as verifying that egress
|
||||
policy has reconciled before application code starts.
|
||||
|
||||
Run `install.sh railiance01`, then `verify.sh railiance01`.
|
||||
Run `install.sh railiance01`, then `verify.sh railiance01`; `verify.sh` is
|
||||
read-only and also checks the six CPU requests and the Envoy pin.
|
||||
|
||||
Before workload admission, rollback deletes Kourier, Serving core, then CRDs
|
||||
using the same verified assets. After Knative Services exist, removal requires
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue