Skip to content

update: add support for 'imagePullSecrets' propagation by root helm chart - #2191

Merged
k8s-ci-robot merged 1 commit into
kubernetes-sigs:masterfrom
heyvister1:modify-image-pull-secrets
Jul 29, 2025
Merged

k8s-ci-robot merged 1 commit into
kubernetes-sigs:masterfrom
heyvister1:modify-image-pull-secrets

Conversation

@heyvister1

Copy link
Copy Markdown
Contributor

nfd serves as sub-chart in our project, and we would like to propagate imagePullSecrets content in root values.yaml to nfd sub-chart. Therefore I have added .Values.global.imagePullSecrets and created a helper helm func to update accordingly.

@linux-foundation-easycla

linux-foundation-easycla Bot commented Jul 7, 2025 •

Copy link
Copy Markdown

CLA Signed

The committers listed above are authorized under a signed CLA.

  • ✅ login: heyvister1 / name: Ido Heyvi (23adbbf)

@netlify

netlify Bot commented Jul 7, 2025 •

Copy link
Copy Markdown

✅ Deploy Preview for kubernetes-sigs-nfd ready!

Name Link
🔨 Latest commit 23adbbf
🔍 Latest deploy log https://app.netlify.com/projects/kubernetes-sigs-nfd/deploys/68872cac569cea000865e53b
😎 Deploy Preview https://deploy-preview-2191--kubernetes-sigs-nfd.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

@k8s-ci-robot k8s-ci-robot added the cncf-cla: no Indicates the PR's author has not signed the CNCF CLA. label Jul 7, 2025
@k8s-ci-robot

Copy link
Copy Markdown
Contributor

Welcome @heyvister1!

It looks like this is your first PR to kubernetes-sigs/node-feature-discovery 🎉. Please refer to our pull request process documentation to help your PR have a smooth ride to approval.

You will be prompted by a bot to use commands during the review process. Do not be afraid to follow the prompts! It is okay to experiment. Here is the bot commands documentation.

You can also check if kubernetes-sigs/node-feature-discovery has its own contribution guidelines.

You may want to refer to our testing guide if you run into trouble with your tests not passing.

If you are having difficulty getting your pull request seen, please follow the recommended escalation practices. Also, for tips and tricks in the contribution process you may want to read the Kubernetes contributor cheat sheet. We want to make sure your contribution gets all the attention it needs!

Thank you, and welcome to Kubernetes. 😃

@k8s-ci-robot k8s-ci-robot added the needs-ok-to-test Indicates a PR that requires an org member to verify it is safe to test. label Jul 7, 2025
@k8s-ci-robot

Copy link
Copy Markdown
Contributor

Hi @heyvister1. Thanks for your PR.

I'm waiting for a kubernetes-sigs member to verify that this patch is reasonable to test. If it is, they should reply with /ok-to-test on its own line. Until that is done, I will not automatically test new commits in this PR, but the usual testing commands by org members will still work. Regular contributors should join the org to skip this step.

Once the patch is verified, the new status will be reflected by the ok-to-test label.

I understand the commands that are listed here.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@k8s-ci-robot k8s-ci-robot added size/M Denotes a PR that changes 30-99 lines, ignoring generated files. cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. and removed cncf-cla: no Indicates the PR's author has not signed the CNCF CLA. labels Jul 7, 2025
@heyvister1

Copy link
Copy Markdown
Contributor Author

cc @adrianchiris

Comment thread deployment/helm/node-feature-discovery/templates/_helpers.tpl Outdated
@heyvister1
heyvister1 force-pushed the modify-image-pull-secrets branch from e1ff13c to 9771b94 Compare July 8, 2025 08:02
@heyvister1
heyvister1 requested a review from adrianchiris July 8, 2025 08:03
@adrianchiris

Copy link
Copy Markdown
Contributor

/lgtm

can you please update docs/deplyment/helm.md as well ?

@k8s-ci-robot k8s-ci-robot added the lgtm "Looks good to me", indicates that a PR is ready to be merged. label Jul 20, 2025
@k8s-ci-robot

Copy link
Copy Markdown
Contributor

LGTM label has been added.

DetailsGit tree hash: bd701be73e52cd1fb44e3b3c89a9b22e7acbf7a5

@heyvister1
heyvister1 force-pushed the modify-image-pull-secrets branch from 9771b94 to 155d929 Compare July 20, 2025 12:26
@k8s-ci-robot k8s-ci-robot added cncf-cla: no Indicates the PR's author has not signed the CNCF CLA. size/XXL Denotes a PR that changes 1000+ lines, ignoring generated files. and removed lgtm "Looks good to me", indicates that a PR is ready to be merged. cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. size/M Denotes a PR that changes 30-99 lines, ignoring generated files. labels Jul 20, 2025
@heyvister1
heyvister1 force-pushed the modify-image-pull-secrets branch 2 times, most recently from d0ae92d to 2fde4d8 Compare July 20, 2025 12:32
@k8s-ci-robot k8s-ci-robot removed the cncf-cla: no Indicates the PR's author has not signed the CNCF CLA. label Jul 20, 2025
@heyvister1
heyvister1 requested a review from marquiz July 22, 2025 11:30
@heyvister1
heyvister1 force-pushed the modify-image-pull-secrets branch 2 times, most recently from 9b9d9ad to 210393f Compare July 22, 2025 13:23

@marquiz marquiz left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

New table is better 👍

@marquiz

marquiz commented Jul 24, 2025

Copy link
Copy Markdown
Contributor

@adrianchiris PTAL

Comment thread docs/deployment/helm.md Outdated

| Name | Type | Default | Description |
|---------------------------------------------|---------|----------------------------------|----------------------------------------------------------------------------------------------------------------------------|
| `global.imagePullSecrets` | array | [] | In case global `imagePullSecrets` are used, their values will be appended, when local `.Values.imagePullSecrets` are not specified. Local values take precedence over global values. |

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

i find the description hard to understand.

suggested reword:

An optional list of references to secrets with the same meaning as imagePullSecrets. If imagePullSecrets is specified, it takes precedence over global.imagePullSecrets

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Done

@heyvister1
heyvister1 force-pushed the modify-image-pull-secrets branch from 210393f to fa457bd Compare July 28, 2025 07:36
@k8s-ci-robot k8s-ci-robot added cncf-cla: no Indicates the PR's author has not signed the CNCF CLA. size/XXL Denotes a PR that changes 1000+ lines, ignoring generated files. and removed cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. size/M Denotes a PR that changes 30-99 lines, ignoring generated files. labels Jul 28, 2025
@heyvister1
heyvister1 force-pushed the modify-image-pull-secrets branch from fa457bd to 8dff365 Compare July 28, 2025 07:52
@k8s-ci-robot k8s-ci-robot added cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. size/M Denotes a PR that changes 30-99 lines, ignoring generated files. and removed cncf-cla: no Indicates the PR's author has not signed the CNCF CLA. size/XXL Denotes a PR that changes 1000+ lines, ignoring generated files. labels Jul 28, 2025
@heyvister1
heyvister1 force-pushed the modify-image-pull-secrets branch from 8dff365 to 23adbbf Compare July 28, 2025 07:54
…hart, in case nfd serves as sub-chart

Signed-off-by: Ido Heyvi 

@marquiz marquiz left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Even better 😊 Thank you @adrianchiris for sharp-eyed review

@adrianchiris adrianchiris left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

/lgtm

@k8s-ci-robot

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: adrianchiris, heyvister1, marquiz

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@marquiz

marquiz commented Jul 29, 2025

Copy link
Copy Markdown
Contributor

Thanks @adrianchiris. Why prow ignored your lgtm 😞
/lgtm

@k8s-ci-robot k8s-ci-robot added the lgtm "Looks good to me", indicates that a PR is ready to be merged. label Jul 29, 2025
@k8s-ci-robot

Copy link
Copy Markdown
Contributor

LGTM label has been added.

DetailsGit tree hash: d18ab7c45ceffa840a5c1b9935ace74b96cd6d63

@k8s-ci-robot
k8s-ci-robot merged commit 0bb3544 into kubernetes-sigs:master Jul 29, 2025
@marquiz marquiz mentioned this pull request Sep 30, 2025
24 of 25 tasks
blake-hamm added a commit to blake-hamm/bhamm-lab that referenced this pull request Jul 6, 2026
…270)

This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| [node-feature-discovery](https://github.com/kubernetes-sigs/node-feature-discovery) | minor | `v0.17.3` → `0.18.3` |

---

### Release Notes

kubernetes-sigs/node-feature-discovery (node-feature-discovery) ### [`v0.18.3`](https://github.com/kubernetes-sigs/node-feature-discovery/releases/tag/v0.18.3) [Compare Source](kubernetes-sigs/node-feature-discovery@v0.18.2...v0.18.3) #### What's Changed This patch release adds support for ppc64le and s390x architectures by providing official NFD container images for them. It also fixes the "test" subcommand of kubectl-nfd plugin. **Full Changelog**: <kubernetes-sigs/node-feature-discovery@v0.18.2...v0.18.3> ### [`v0.18.2`](https://github.com/kubernetes-sigs/node-feature-discovery/releases/tag/v0.18.2) [Compare Source](kubernetes-sigs/node-feature-discovery@v0.18.1...v0.18.2) This patch release fixes the /metrics endpoint of nfd-topology-updater ([#​2343](kubernetes-sigs/node-feature-discovery#2343)). ### [`v0.18.1`](https://github.com/kubernetes-sigs/node-feature-discovery/releases/tag/v0.18.1) [Compare Source](kubernetes-sigs/node-feature-discovery@v0.18.0...v0.18.1) This patch release fixes the deployment of PodMonitor object when prometheus-operator metrics collection is enabled. ### [`v0.18.0`](https://github.com/kubernetes-sigs/node-feature-discovery/releases/tag/v0.18.0) [Compare Source](kubernetes-sigs/node-feature-discovery@v0.17.4...v0.18.0) #### Changelog ##### Image compatibility (EXPERIMENTAL) The image compatibility related features introduced in [v0.17](https://github.com/kubernetes-sigs/node-feature-discovery/releases/v0.17.0) have been improved and enhanced. Major new feature is the `nfd export` command. See the [documentation](https://kubernetes-sigs.github.io/node-feature-discovery/v0.18/usage/image-compatibility.html) for more details ##### Helm The Helm chart is now served from the registry.k8s.io OCI registry at registry.k8s.io/nfd/charts/node-feature-discovery. One liner installation with ```bash helm install -n node-feature-discovery nfd oci://registry.k8s.io/nfd/charts/node-feature-discovery --version 0.18.0 --create-namespace ``` > \[!IMPORTANT] > The legacy Helm repository at <https://kubernetes-sigs.github.io/node-feature-discovery/charts> is still available, but will be deprecated and stop getting updated in a future release. Users are encouraged to migrate to the OCI registry. The release contains numerous small improvements and fixes to the Helm chart and its documentation, including: - Configurable DNS policy ([#​2025](kubernetes-sigs/node-feature-discovery#2025)) - Configurable PodDisruptionBudget ([#​2148](kubernetes-sigs/node-feature-discovery#2148)) - Configurable UpdateStrategy for nfd-worker ([#​2157](kubernetes-sigs/node-feature-discovery#2157)) - Global `global.imagePullSecrets` parameter ([#​2191](kubernetes-sigs/node-feature-discovery#2191)) - Fix for running with OwnerReferencesPermissionEnforcement validating webhook enabled ([#​2006](kubernetes-sigs/node-feature-discovery#2006)) - Post-delete hook: option to disable ([#​2076](kubernetes-sigs/node-feature-discovery#2076)) and configurable image pull secret ([#​2082](kubernetes-sigs/node-feature-discovery#2082)) ##### Deprecations The deprecated `autoDefaultNs` configuration parameter of nfd-master was removed. Toleration for the deprecated `node-role.kubernetes.io/master:NoSchedule` taint and affinity to the deprecated `node-role.kubernetes.io/master` label have been removed from the default nfd-master deployment manifests. If you still need these, they need to be explicitly added to the deployment (`master.tolerations` and `master.affinity` in the Helm chart). > \[!IMPORTANT] > In v0.18.0 the DisableAutoPrefix feature is still alpha and disabled by default. NFD adds `feature.node.kubernetes.io/` prefix to all unprefixed label, annotation and extended resource names. When DisableAutoPrefix is enabled (will be default in a future release), NFD will not add the default prefix automatilly (and add unprefixed names, verbatim). Users are stronglycencouraged to start using fully qualified names (with the prefix) for allccustom labels, annotations and extended resources. ##### Miscellaneous ##### Scalability The release contains improvements and fixes to NFD scalability in larger clusters. ##### NodeFeatureRules ##### Label templating The label templates in NodeFeatureRules now support [sprig](https://masterminds.github.io/sprig/) functions, greatly enhancing their flexibility. ##### New comparison operators New comparison operators `Ge`, `Le` and `GeLe` were added ([#​2085](kubernetes-sigs/node-feature-discovery#2085)). ##### Type field in MatchExpressions New `Type` field was added to `MatchExpressions`, allowing to specify the type of the value being compared ([#​2096](kubernetes-sigs/node-feature-discovery#2096)). Currently supported types are empty value (the default) and `version`. Use of `version` type enables version-aware comparisons. ##### CPU features Support for new CPUID flags were added, including AMXCOMPLEX, AMXTRANSPOSE and AMXTF32. ##### Memory features NFD now detects availability of hugepages and reports them as `memory-hugepages.enabled` and `hugepages-`features ([#​2056](kubernetes-sigs/node-feature-discovery#2056)). ##### Network features Detection of the MTU of network devices was added ([#​2044](kubernetes-sigs/node-feature-discovery#2044)). ##### Metrics and health endpoints The gRPC health endpoint was replaced by an HTTP healthz endpoint in all NFD daemons. In addition, both the metrics and healthz endpoints are now served on the same port (configurable with `--port`, default 8080). [**Full Changelog**](kubernetes-sigs/node-feature-discovery@v0.18.0-devel...v0.18.0) ### [`v0.17.4`](https://github.com/kubernetes-sigs/node-feature-discovery/releases/tag/v0.17.4) [Compare Source](kubernetes-sigs/node-feature-discovery@v0.17.3...v0.17.4) #### What's Changed This release updates dependencies. **Full Changelog**: <kubernetes-sigs/node-feature-discovery@v0.17.3...v0.17.4>
--- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate). Co-authored-by: Renovate Bot Reviewed-on: https://codeberg.org/blake-hamm/bhamm-lab/pulls/270
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved Indicates a PR has been approved by an approver from all required OWNERS files. cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. lgtm "Looks good to me", indicates that a PR is ready to be merged. ok-to-test Indicates a non-member PR verified by an org member that is safe to test. size/M Denotes a PR that changes 30-99 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants