Skip to content

Add pinned image selectors to exclude images from kubelet GC - #571

Merged
athongsamai merged 1 commit into
Mirantis:release/0.4from
athongsamai:pinned-images-to-exclude-from-GC
Sep 8, 2026
Merged

athongsamai merged 1 commit into
Mirantis:release/0.4from
athongsamai:pinned-images-to-exclude-from-GC

Conversation

@athongsamai

Copy link
Copy Markdown
Contributor

Fixes #

Why does this need?

The kubelet omits images the runtime reports as pinned from its eviction list, but cri-dockerd only ever pinned the pod sandbox image. Any other image that cannot simply be re-pulled -- a platform image side-loaded onto an air-gapped node, for example -- is deleted once the node crosses its image GC threshold.

Proposed Changes

Add two flags that let an operator pin additional images:

  • --pinned-images : image references: a full "repo:tag" or "repo@digest", a bare repository (pinning every tag of it), or a prefix ending in '*'
  • --pinned-image-labels: label selectors in "key" or "key=value" form, pinning a whole set of images without enumerating it

Matching lives in a new pinnedImageMatcher (core/pinned.go), which NewDockerService builds once and ListImages/ImageStatus consult through dockerService.isImagePinned. The sandbox image stays pinned unconditionally, and a nil or empty matcher matches nothing, so the default configuration behaves exactly as before. Reference parsing treats a registry port as part of the repository rather than a tag.

ImageStatus now reads labels from the image inspect config so label selectors apply to it as well as to ListImages.

The kubelet omits images the runtime reports as pinned from its
eviction list, but cri-dockerd only ever pinned the pod sandbox image.
Any other image that cannot simply be re-pulled -- a platform image
side-loaded onto an air-gapped node, for example -- is deleted once the
node crosses its image GC threshold.

Add two flags that let an operator pin additional images:

  --pinned-images        image references: a full "repo:tag" or
                         "repo@digest", a bare repository (pinning every
                         tag of it), or a prefix ending in '*'
  --pinned-image-labels  label selectors in "key" or "key=value" form,
                         pinning a whole set of images without
                         enumerating it

Matching lives in a new pinnedImageMatcher (core/pinned.go), which
NewDockerService builds once and ListImages/ImageStatus consult through
dockerService.isImagePinned. The sandbox image stays pinned
unconditionally, and a nil or empty matcher matches nothing, so the
default configuration behaves exactly as before. Reference parsing
treats a registry port as part of the repository rather than a tag.

ImageStatus now reads labels from the image inspect config so
label selectors apply to it as well as to ListImages.

@awmirantis awmirantis left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@chenyaooo
chenyaooo self-requested a review September 4, 2026 14:46

@chenyaooo chenyaooo left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@awmirantis awmirantis left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@athongsamai
athongsamai merged commit 15898bd into Mirantis:release/0.4 Sep 8, 2026
13 checks passed
@athongsamai
athongsamai deleted the pinned-images-to-exclude-from-GC branch September 8, 2026 23:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants