Friday, 2021-11-05

kata-irc-bot<eric.ernst> (woa, you’re on slack!)01:24
kata-irc-bot<eric.ernst> @bergwolf if you can PTAL: https://github.com/kata-containers/kata-containers/pull/2974 this is a final step before being able to cleanly make a seperate hypervisor pkg01:24
kata-irc-bot<eric.ernst> I’m a bit mixed, but the main point is, technically we don’t need to specify a kernel when utilizing the hypervisor. In our case, as a sanbox runtime, we do. So, perhaps we should do that validation on the sandbox side rather than inside they hypervisor pkg.01:25
kata-irc-bot<eric.ernst> once we move it all into its own package it should be easier to manage, and we can decide where this validation should live01:26
kata-irc-bot<eric.ernst> also, some other house cleaning: https://github.com/kata-containers/kata-containers/pull/297301:30
kata-irc-bot<bergwolf> It's a generic check for all hypervisor types. I'm wonder in what case these can be empty?02:58
kata-irc-bot<eric.ernst> Yeah; @mcastelino wdyt?05:44
kata-irc-bot<fidencio> @wmoschet, hey, what's your plan about the failures on https://github.com/kata-containers/tests/pull/3658? What I had planned is to open issues for each one of the failures that are related to using the distro as rootfs, and group into a meta (not as in, Facebook) issue, and then slowly attack each one of those.14:54
kata-irc-bot<fidencio> Did you have something different in mind?14:54
kata-irc-bot<fidencio> @christophe @gkurz @samuel.ortiz @ssheribe @fgiudici... about cgroupsv2 on the host side :thread:14:55
kata-irc-bot<fidencio> Yesterday on the CRI-O community call Mrunal asked about whether we'd be using libcontainer/cgroups rather than containerd/cgroups as Kir Kolyshkin is working on that14:57
kata-irc-bot<fidencio> Mrunal also mentioned that kube itself may be moving to using systemd cgroups, and that Kir is working on (long term) a library that could be used by containerd, kube, CRI-O, kata-containers, ...14:58
kata-irc-bot<fidencio> @james.o.hunt also brought up an interesting point about what we should do on the guest side, but I'll avoid mixing the discussions here.14:59
kata-irc-bot<fidencio> So, why am I saying those things?  To let you know that I'll open an issue to track those things, cc y'all there (including Mrunal and Kir), and then we can get things done, done right, in agreement with folks from outside as well.14:59
kata-irc-bot<fidencio> If you already have something opened to track that, please, point that at my direction as well.15:00
kata-irc-bot<fgiudici> Hey thanks @fidencio. systemd cgroups driver is the recommended by kubernetes docs indeed. So, the things we have are the issue opened by @christophe  and @ssheribe (and @gkurz) PR.15:13
kata-irc-bot<fidencio> @fgiudici, wonderful!15:15
kata-irc-bot<fidencio> One thing is not exactly clear for me though (and bear with me as I didn't go through Snir's / Greg's  PR) is whether they're using the libcontainers/cgroups in addition to the containerd/cgroups or instead of containerd/cgroups.15:18
kata-irc-bot<fidencio> It seems to be *in addition* from a quick look at the PR15:18
kata-irc-bot<fidencio> And maybe we may want to take the full path of just switching to libcontainers/cgroups entirely (maybe not as part of this PR, but that's what I got from Mrunal Yesterday)15:19
kata-irc-bot<fgiudici> Yeah, it is in addition (also if I'm not sure if they rely on libcontainer fully or go with systemd lib directly... @ssheribe should know more :slightly_smiling_face: )15:21
kata-irc-bot<fgiudici> From what I see, I think a bigger rework may be needed to do things completely right for systemd15:21
kata-irc-bot<fgiudici> Also in order to be ready to add support to cgroups v215:22
kata-irc-bot<fidencio> Yep, I agree.  @christophe said he'd work on that.  Still, opening issues and looping in the correct folks (Mrunal and Kir) may be a good idea.15:22
kata-irc-bot<fidencio> I will try to sync with Snir on Monday, and then we can open the needed issues.15:23
kata-irc-bot<fidencio> @fgiudici, as always, thanks for the clarification!15:23
kata-irc-bot<fgiudici> Hey thanks to you for jumping on this! :slightly_smiling_face:15:24
kata-irc-bot<christophe> The issue above was really for the regression. I don't recall that I opened one for the host cgroup v2 support, and I'm positive I did not open one for the switch to `libcontainers/cgroups` .15:29
kata-irc-bot<fidencio> Ack, then I can open one later on (Monday, most likely), and we can follow up in the issue.16:25
kata-irc-bot<fidencio> Thanks @christophe!16:25

Generated by irclog2html.py 2.17.2 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!