fix(registry): stop requiring registry.cn-hangzhou.aliyuncs.com for HAMi - #2
Merged
Merged
Conversation
budcluster now overrides HAMi's kube-scheduler image from the chart's Alibaba CN-region default to registry.k8s.io/kube-scheduler, so GPU clusters no longer pull from registry.cn-hangzhou.aliyuncs.com. Requiring it blocked every cluster whose egress policy rightly excludes a CN-region registry. - Remove registry.cn-hangzhou.aliyuncs.com from the registry inventory, and record HAMi's kube-scheduler sidecar under registry.k8s.io, which is already required. - registry.hami-scheduler probes registry.k8s.io/kube-scheduler at the tag derived from the cluster's version. Its remedy covers mirroring the image, still warning that global.imageRegistry alone keeps the google_containers/ prefix. - Catalogue version 2026-09-15.1, so reports distinguish this inventory from the one 0.3.1 shipped. Verified on the tcs-vmware cluster: registry.from-cluster passes 8 of 8 and registry.k8s.io/kube-scheduler:v1.36.3 resolves. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
budcluster now points HAMi's kube-scheduler image at
registry.k8s.io/kube-schedulerinstead of the chart's Alibaba CN-region default. budctl still requiredregistry.cn-hangzhou.aliyuncs.comon every GPU cluster, so a correct egress policy that excludes a CN-region registry was reported as a blocker. On the tcs-vmware cluster that was the only blocker left.Changes
registry.cn-hangzhou.aliyuncs.comis removed from the registry inventory. HAMi's kube-scheduler sidecar is now listed underregistry.k8s.io, which was already required.registry.hami-schedulerprobesregistry.k8s.io/kube-schedulerat the tag derived from the cluster's version. Its remedy now covers mirroring the image, and still warns thatglobal.imageRegistryalone keeps the chart'sgoogle_containers/prefix.2026-09-15.1, so reports tell this inventory apart from the one 0.3.1 shipped.Verification
go vetandgo test ./...pass. A new test fails if the check ever probes the Alibaba registry again or the inventory lists it.registry.from-clusterpasses 8 of 8 andregistry.k8s.io/kube-scheduler:v1.36.3resolves.Part of the 0.3.2 release, together with the OpenShift ingress-class check.
🤖 Generated with Claude Code