Bump runc to 1.3.3 and containerd to 2.1.5 in main - #3472
Conversation
It's from Gentoo commit b4c450b220406a895ed093b19b92241746408a66. Signed-off-by: Krzesimir Nowak <knowak@microsoft.com>
This is a hack - the ebuild will disappear on next weekly updates, unless Gentoo gets the 2.1.5 ebuild by then. Signed-off-by: Krzesimir Nowak <knowak@microsoft.com>
Signed-off-by: Krzesimir Nowak <knowak@microsoft.com>
8b79758 to
d50f08e
Compare
|
Tested by building them locally. |
|
Build action triggered: https://github.com/flatcar/scripts/actions/runs/19171756331 |
|
@tormath1 I am looking for the contained update. I need to use the image volumes feature that is only available in 2.1. |
Understood. New major stable has been relased in Nov. so we're planning to have it around for a while (5 to 6 months) to let folks use containerd v2.0.x and provide any additional feedback on this container runtime upgrade (cc @sayanchowdhury to confirm). In the meantime, you can:
|
|
Thanks for the advice, I was just asking to know what to communicate to our users that are hitting this, see kubernetes/kops#17780. Not sure I understand what you mean. containerd 2.1 is stable and it was released 6 months ago. With the release of contained 2.2 and has not become the previous stable. Generally speaking, Kubernetes works best with newer containerd versions, as this is what it's tested against. |
|
@hakman thanks for providing more context here with the kops issue!
We usually rely on Gentoo folks to upgrade containerd packages and/or security concerns (like this current PR). This is a trade-off between security and stability: we don't want to introduce new packages (especially container runtimes) to Stable without going through the stabilization process (alpha -> beta -> stable) to ensure users workloads stability.
FWIW Flatcar is running automated tests against current Kubernetes major versions (at this time 1.32, 1.33 and 1.34). We could investigated on extending our test suite to run kops tests but it seems you're already testing Flatcar in kops CI? |
|
Thanks for the detailed explanation @tormath1, much appreciated. |
|
@hakman ok, I understand. We are discussing about enabling back our automation to quickly catch-up on newer containerd releases. So now, to get back on the initial issue, I only see the two options mentioned above:
I never tried kOps, so I don't really know how the second option could apply. |
|
Thanks @tormath1, I appreciate the effort and the insights. |
changelog/directory (user-facing change, bug fix, security fix, update)/bootand/usrsize, packages, list files for any missing binaries, kernel modules, config files, kernel modules, etc.