Containerd upgrade patch #750
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Description
Containerd was upgraded in #735, but the related patch does not work, since it does not handle specific problems with iptables which occur during containerd 1.6 -> 1.7 upgrade (from ubuntu repositories)
Solution
Test Cases
TestCase 1
Steps:
containerd.io=1.6*
. Note that this should be explicitly specified in cluster.yaml, since regularcontainerd=1.6*
package (without .io) is no longer available.containerd.io=1.7*
in cluster.yaml, without running install tasks (just inventory update). This step simulates inconsistency between nodes and "cluster.yaml"migrate_kubemarine
Results:
upgrade_cri
step just installs new version on all nodes, without handling specific problems for 1.6 -> 1.7 upgradecontainerd_upgrade
step performs installation with special considerations for iptables issue: per-node, with drain, kubelet start/stop, contaieners removal, waiting for podsChecklist