Repository navigation
Enable unattended upgrades on Kubernetes nodes - #3167
Conversation
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
📒 Files selected for processing (1)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. WalkthroughThe change adds an Ansible role for unattended upgrades and optional APT snapshots. When node exporter is enabled, the role publishes APT metrics. Prometheus rules alert on pending upgrades, stale package lists, and required reboots. ChangesAPT upgrades and monitoring
Priority: ➖ Normal Estimated code review effort: 3 (Moderate) | ~25 minutes Change: Feature Sequence Diagram(s)sequenceDiagram
participant AptTimer as apt-info timer
participant AptService as apt-info service
participant AptInfo as apt_info.py
participant Textfile as node_exporter textfile collector
AptTimer->>AptService: Start on schedule
AptService->>AptInfo: Run exporter
AptInfo->>AptService: Return metrics
AptService->>Textfile: Write apt.prom after success
Merge Risk: ⚪ Minimal · up to No actionable merge-blocking issue is established for the APT metrics service. 🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)✅ Passed checks (4 passed)Full details: Docstring CoverageExplanation Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 9 functions across 1 files. (1 skipped: 1 unsupported.)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: ba2acc0d68
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
ba2acc0 to
80fb01c
Compare
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 80fb01c6fe
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
80fb01c to
466ae92
Compare
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 466ae925de
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
466ae92 to
e836664
Compare
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: e836664413
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
The Kubernetes nodes never installed updates on their own. apt's daily timers ran, but the installer had preset automatic upgrades off, so security fixes waited for a manual dist-upgrade. This adds an unattended_upgrades role for k1-k5 that installs Debian's security updates and stable point releases each morning and never reboots; reboots are left to Kured later. The role writes its own apt.conf.d file instead of editing the package's ucf-managed ones, and sets the APT::Periodic keys itself so it does not depend on how the installer answered. k4 and k5 install updates as soon as they appear. k1, k2 and k3 read Debian's main archive from snapshot.debian.org as it was seven days earlier, so a bad point release reaches the canaries a week before the control plane and the GPU node. Security updates stay live everywhere. A script run before each apt-daily update advances the snapshot, and saves the new ID only once every list for it has downloaded, since the ID is part of each source URL. trixie-updates' Release file expires seven days after publication, so validity is extended for the Debian label alone. A delayed host takes its first snapshot before the periodic settings are written, so a failure there leaves it without automatic upgrades rather than on live ones. apt_info.py from node-exporter-textfile-collector-scripts exports apt metrics through node_exporter. It is vendored unmodified, so the ruff hooks skip it. Its timer runs as node_exporter, which owns the textfile directory, so the root account never writes into a path another account controls. New alerts cover Debian upgrades pending for more than 10 days, package lists more than 3 days old for a full day (so a newly set up host, whose lists report a zero timestamp until its first daily refresh, does not alert), and a reboot pending for more than 10 days. Failed runs are mailed to root.
e836664 to
6f48d0d
Compare
The Kubernetes nodes never installed updates on their own. apt's daily timers ran, but the installer had preset automatic upgrades off, so security fixes waited for a manual dist-upgrade. This adds an unattended_upgrades role for k1-k5 that installs Debian's security updates and stable point releases each morning and never reboots; reboots are left to Kured later.
The role writes its own apt.conf.d file instead of editing the package's ucf-managed ones, and sets the APT::Periodic keys itself so it does not depend on how the installer answered.
k4 and k5 install updates as soon as they appear. k1, k2 and k3 read Debian's main archive from snapshot.debian.org as it was seven days earlier, so a bad point release reaches the canaries a week before the control plane and the GPU node. Security updates stay live everywhere. A script run before each apt-daily update advances the snapshot, and saves the new ID only once every list for it has downloaded, since the ID is part of each source URL. trixie-updates' Release file expires seven days after publication, so validity is extended for the Debian label alone. A delayed host takes its first snapshot before the periodic settings are written, so a failure there leaves it without automatic upgrades rather than on live ones.
apt_info.py from node-exporter-textfile-collector-scripts exports apt metrics through node_exporter. It is vendored unmodified, so the ruff hooks skip it. Its timer runs as node_exporter, which owns the textfile directory, so the root account never writes into a path another account controls. New alerts cover Debian upgrades pending for more than 10 days, package lists more than 3 days old for a full day (so a newly set up host, whose lists report a zero timestamp until its first daily refresh, does not alert), and a reboot pending for more than 10 days. Failed runs are mailed to root.