Skip to content

fix(registry): stop requiring registry.cn-hangzhou.aliyuncs.com for HAMi - #2

Merged
dittops merged 1 commit into
mainfrom
claude/hami-scheduler-registry-k8s
Sep 15, 2026
Merged

dittops merged 1 commit into
mainfrom
claude/hami-scheduler-registry-k8s

Conversation

@dittops

@dittops dittops commented Sep 15, 2026

Copy link
Copy Markdown
Member

Why

budcluster now points HAMi's kube-scheduler image at registry.k8s.io/kube-scheduler instead of the chart's Alibaba CN-region default. budctl still required registry.cn-hangzhou.aliyuncs.com on every GPU cluster, so a correct egress policy that excludes a CN-region registry was reported as a blocker. On the tcs-vmware cluster that was the only blocker left.

Changes

  • registry.cn-hangzhou.aliyuncs.com is removed from the registry inventory. HAMi's kube-scheduler sidecar is now listed under registry.k8s.io, which was already required.
  • registry.hami-scheduler probes registry.k8s.io/kube-scheduler at the tag derived from the cluster's version. Its remedy now covers mirroring the image, and still warns that global.imageRegistry alone keeps the chart's google_containers/ prefix.
  • Catalogue version is 2026-09-15.1, so reports tell this inventory apart from the one 0.3.1 shipped.

Verification

  • go vet and go test ./... pass. A new test fails if the check ever probes the Alibaba registry again or the inventory lists it.
  • On tcs-vmware: registry.from-cluster passes 8 of 8 and registry.k8s.io/kube-scheduler:v1.36.3 resolves.

Part of the 0.3.2 release, together with the OpenShift ingress-class check.

🤖 Generated with Claude Code

budcluster now overrides HAMi's kube-scheduler image from the chart's Alibaba
CN-region default to registry.k8s.io/kube-scheduler, so GPU clusters no longer
pull from registry.cn-hangzhou.aliyuncs.com. Requiring it blocked every cluster
whose egress policy rightly excludes a CN-region registry.

- Remove registry.cn-hangzhou.aliyuncs.com from the registry inventory, and
  record HAMi's kube-scheduler sidecar under registry.k8s.io, which is already
  required.
- registry.hami-scheduler probes registry.k8s.io/kube-scheduler at the tag
  derived from the cluster's version. Its remedy covers mirroring the image,
  still warning that global.imageRegistry alone keeps the google_containers/
  prefix.
- Catalogue version 2026-09-15.1, so reports distinguish this inventory from
  the one 0.3.1 shipped.

Verified on the tcs-vmware cluster: registry.from-cluster passes 8 of 8 and
registry.k8s.io/kube-scheduler:v1.36.3 resolves.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@dittops
dittops merged commit 28cb62d into main Sep 15, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant