Skip to content

move kubelet --system-reserved deprecated flag to kubelet-config file#1947

Open
ffais wants to merge 2 commits into
kubernetes-sigs:mainfrom
ffais:kubelet-config-dropin-folder
Open

move kubelet --system-reserved deprecated flag to kubelet-config file#1947
ffais wants to merge 2 commits into
kubernetes-sigs:mainfrom
ffais:kubelet-config-dropin-folder

Conversation

@ffais
Copy link
Copy Markdown
Contributor

@ffais ffais commented Mar 3, 2026

Change description

Kubelet '--system-reserved' has been deprecated. With this PR, the flag has been moved to a specific configuration file in the drop-ins directory. The drop-ins directory specified with '--config-dir' flag allows the user to optionally specify additional configs to overwrite what is provided by default and in the KubeletConfigFile flag.

@k8s-ci-robot k8s-ci-robot added the needs-ok-to-test Indicates a PR that requires an org member to verify it is safe to test. label Mar 3, 2026
@k8s-ci-robot
Copy link
Copy Markdown
Contributor

Hi @ffais. Thanks for your PR.

I'm waiting for a kubernetes-sigs member to verify that this patch is reasonable to test. If it is, they should reply with /ok-to-test on its own line. Until that is done, I will not automatically test new commits in this PR, but the usual testing commands by org members will still work.

Tip

We noticed you've done this a few times! Consider joining the org to skip this step and gain /lgtm and other bot rights. We recommend asking approvers on your previous PRs to sponsor you.

Once the patch is verified, the new status will be reflected by the ok-to-test label.

I understand the commands that are listed here.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@ffais ffais marked this pull request as draft March 3, 2026 12:14
@k8s-ci-robot k8s-ci-robot added the do-not-merge/work-in-progress Indicates that a PR should not merge because it is a work in progress. label Mar 3, 2026
@k8s-ci-robot
Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by:
Once this PR has been reviewed and has the lgtm label, please assign jsturtevant for approval. For more information see the Code Review Process.

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@k8s-ci-robot k8s-ci-robot added size/S Denotes a PR that changes 10-29 lines, ignoring generated files. cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. labels Mar 3, 2026
@ffais ffais force-pushed the kubelet-config-dropin-folder branch from abfb593 to 0c1a5e4 Compare April 22, 2026 16:18
@k8s-ci-robot k8s-ci-robot added size/M Denotes a PR that changes 30-99 lines, ignoring generated files. and removed size/S Denotes a PR that changes 10-29 lines, ignoring generated files. labels Apr 22, 2026
@ffais ffais marked this pull request as ready for review April 22, 2026 16:19
@k8s-ci-robot k8s-ci-robot removed the do-not-merge/work-in-progress Indicates that a PR should not merge because it is a work in progress. label Apr 22, 2026
@k8s-ci-robot k8s-ci-robot requested a review from drew-viles April 22, 2026 16:20
@drew-viles
Copy link
Copy Markdown
Contributor

/ok-to-test

@k8s-ci-robot k8s-ci-robot added ok-to-test Indicates a non-member PR verified by an org member that is safe to test. and removed needs-ok-to-test Indicates a PR that requires an org member to verify it is safe to test. labels Apr 29, 2026
@Whisper40
Copy link
Copy Markdown
Contributor

@ffais Hi, any news about this ?

@ffais
Copy link
Copy Markdown
Contributor Author

ffais commented Apr 30, 2026

Hi @Whisper40, looks like pull-ova-all test failing is not related to the changes made in this PR.

I'm waiting for a review from one of the maintainers. I know @drew-viles is very busy these days, @mboersma could take a look?

@linux-foundation-easycla
Copy link
Copy Markdown

linux-foundation-easycla Bot commented May 1, 2026

CLA Signed

The committers listed above are authorized under a signed CLA.

@k8s-ci-robot k8s-ci-robot added cncf-cla: no Indicates the PR's author has not signed the CNCF CLA. and removed cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. labels May 1, 2026
…beadm.conf

Signed-off-by: ffais <ffais@fbk.eu>
@ffais ffais force-pushed the kubelet-config-dropin-folder branch from bb4109f to b6b93c9 Compare May 1, 2026 10:37
@k8s-ci-robot k8s-ci-robot added cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. and removed cncf-cla: no Indicates the PR's author has not signed the CNCF CLA. labels May 1, 2026
@ffais ffais requested a review from mboersma May 6, 2026 15:12
@drew-viles
Copy link
Copy Markdown
Contributor

/override pull-ova-all

Known photon-5 build failure.

@k8s-ci-robot
Copy link
Copy Markdown
Contributor

@drew-viles: Overrode contexts on behalf of drew-viles: pull-ova-all

Details

In response to this:

/override pull-ova-all

Known photon-5 build failure.

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

Copy link
Copy Markdown
Contributor

@drew-viles drew-viles left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

with the changed been made.

/lgtm

@k8s-ci-robot k8s-ci-robot added the lgtm "Looks good to me", indicates that a PR is ready to be merged. label May 6, 2026
Copy link
Copy Markdown
Contributor

@mboersma mboersma left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One follow-up on the systemReserved-already-set guard:

. "${KUBELET_SYSCONFIG}"
# If system-reserved is already set by user, ignore
if grep -q 'KUBELET_EXTRA_ARGS=.*--system-reserved' "${KUBELET_SYSCONFIG}"; then
if grep -q 'systemReserved' "${KUBELET_SYSCONFIG}"; then
Copy link
Copy Markdown
Contributor

@mboersma mboersma May 11, 2026

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This check no longer does what the comment above it claims. ${KUBELET_SYSCONFIG} is /etc/sysconfig/kubelet or /etc/default/kubelet — a shell-style env file consumed by the kubelet unit, not a KubeletConfiguration. A user who wants to pre-set systemReserved would do it in /var/lib/kubelet/config.yaml or in a drop-in under /var/lib/kubelet/kubelet.conf.d/, so systemReserved will essentially never appear in sysconfig and this guard will never trip.

Since this PR moves system-reserved out of KUBELET_EXTRA_ARGS and into a drop-in, I think the intent should be: "if the user has already provided a systemReserved value via the main kubelet config or any other drop-in, don't overwrite it." Something like:

# If the user has already configured systemReserved (in the main kubelet
# config or any other drop-in), don't overwrite their value.
USER_KUBELET_CONFIGS=( "/var/lib/kubelet/config.yaml" )
if [ -d /var/lib/kubelet/kubelet.conf.d ]; then
  while IFS= read -r -d '' f; do
    [ "$f" = "$KUBELET_CONFIG" ] && continue
    USER_KUBELET_CONFIGS+=( "$f" )
  done < <(find /var/lib/kubelet/kubelet.conf.d -maxdepth 1 -type f -print0)
fi

for cfg in "${USER_KUBELET_CONFIGS[@]}"; do
  [ -f "$cfg" ] || continue
  if grep -Eq '^[[:space:]]*systemReserved[[:space:]]*:' "$cfg" \
     || grep -q '"systemReserved"' "$cfg"; then
    exit 0
  fi
done

The outer loop over KUBELET_SYSCONFIG_FILES can probably be dropped entirely now — sourcing it was only useful for the old KUBELET_EXTRA_ARGS path. It's worth a sanity check that nothing downstream still relies on that.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. lgtm "Looks good to me", indicates that a PR is ready to be merged. ok-to-test Indicates a non-member PR verified by an org member that is safe to test. size/M Denotes a PR that changes 30-99 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants