Conversation
1. Removed redundant Docker pulls: Removed the old sudo docker pull ... block in the Docker installation step, which was
storing images in Docker's Moby engine store (/var/lib/docker/) where containerd / kubeadm could not see them.
2. Added containerd pre-pull provisioner (ctr -n k8s.io): Positioned right after containerd is configured and restarted,
pulling directly into the k8s.io CRI namespace.
3. Authenticated private GCP registry pulls: Pulls from us-west1-docker.pkg.dev using TOKEN=$(gcloud auth print-access-
token) via sudo ctr -n k8s.io images pull -u "oauth2accesstoken:$TOKEN" "$img".
4. Complete image coverage:
• Core KNE & topology components (meshnet:ga, bridge:ga, init-wait:ga).
• Vendor NOS images (ceos:ga, xrd:ga, 8000e:ga, ncptx:ga, srlinux:ga, lemming:ga).
• CNI & Ingress (flannel, flannel-cni-plugin, kindnetd, metallb/controller, metallb/speaker).
• Controllers & Operators (srl-controller, arista-ceoslab-operator, openconfig-lemming/release/operator, kube-rbac-
proxy, keng-operator).
• Keysight / OTG engine images (keng-controller, otg-gnmi-server, ixia-c-traffic-engine, ixia-c-protocol-engine).
This allows it to share the same images stored for kubeadm use. If the image isn't found that way fall back to the established docker pull / kind load method, to minimize the risk of breaking any existing usages.
kraney
force-pushed
the
image-fixing
branch
from
September 30, 2026 17:16
082255a to
ba56ded
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
placed images into Docker's Moby storage engine (
/var/lib/docker). However, KNE Kubernetes clusters running with Kubeadm use containerdwith the
k8s.ioCRI namespace (/var/lib/containerd).immediately pulled live
:gatags fromus-west1-docker.pkg.devat cluster startup. This bypassed KNE VM image qualification tests andintroduced live tag drift. Furthermore, many critical infrastructure images (CNI, wait containers, MetalLB, OTG controllers/engines) were
never pre-pulled during the VM image bake.
namespace using
sudo ctr -n k8s.io images pull.- Uses
gcloud auth print-access-tokenfor authenticated access tous-west1-docker.pkg.dev.- Bakes the complete set of required images:
- Core & Meshnet:
meshnet:ga,bridge:ga,init-wait:ga- Vendor NOS DUTs:
ceos:ga,xrd:ga,8000e:ga,ncptx:ga,srlinux:ga,lemming:ga- CNI & Ingress:
flannel,flannel-cni-plugin,kindnetd,metallb/controller,metallb/speaker- Controllers & Operators:
srl-controller,arista-ceoslab-operator,openconfig-lemming/operator,kube-rbac-proxy,keng-operator- OTG Keysight:
keng-controller,otg-gnmi-server,ixia-c-traffic-engine,ixia-c-protocol-engine2. Containerd-first KinD loading with Docker fallback (
deploy/deploy.go):- Updates
KindSpec.loadContainerImages()to check if the image is available in containerd on the host. If present, it exports to atemporary tarball and loads it into the KinD cluster via
kind load image-archive, tagging within the KinD node if destination differsfrom source. This avoids pulling over the network and avoids duplicating multi-gigabyte NOS images into host Docker daemon storage.
- If containerd or the requested image is absent, it cleanly falls back to the previous
docker pull->docker tag->kind load docker-imageworkflow.3. Export
ClusterKindNodes()(cluster/kind/kind.go):- Exports
ClusterKindNodes()so that node container names can be queried across packages for tagging.4. Unit Tests (
deploy/deploy_test.go,cluster/kind/kind_test.go):- Added unit test cases for containerd
image-archiveloading with and without retagging.- Updated existing test cases to maintain coverage of the Docker fallback path.