Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
18 changes: 18 additions & 0 deletions .ci/clusters/values-standalone.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -18,6 +18,24 @@
#
standalone:
enabled: true
# Exercises standalone-deployment.yaml's nodeAffinity passthrough, which the
# all-values runs can't reach (standalone is disabled there). This file is
# also installed on kind, so every term must be satisfiable by any node.
affinity:
nodeAffinity:
requiredDuringSchedulingIgnoredDuringExecution:
nodeSelectorTerms:
- matchExpressions:
- key: kubernetes.io/os
operator: In
values:
- linux
preferredDuringSchedulingIgnoredDuringExecution:
- weight: 1
preference:
matchExpressions:
- key: kubernetes.io/arch
operator: Exists

auth:
authentication:
Expand Down
33 changes: 33 additions & 0 deletions .ci/templates-all-values-patch1.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -89,6 +89,26 @@ volumes:
# the storageClassName: "local-storage" branch
# -----------------------------------------------------------------------------
zookeeper:
affinity:
# nodeAffinity: replace the base file's single-entry preferred list with a
# two-entry weighted one. Helm deep-merges maps, so the base file's
# requiredDuringScheduling... term survives alongside it.
nodeAffinity: &nodeAffinity
preferredDuringSchedulingIgnoredDuringExecution:
- weight: 100
preference:
matchExpressions:
- key: node-pool
operator: In
values:
- pool-a
- weight: 10
preference:
matchExpressions:
- key: node-pool
operator: In
values:
- fallback-pool
statefulsetUpgrade:
enabled: false
volumes:
Expand All @@ -111,6 +131,8 @@ zookeeper:
# bookkeeper-storageclass.yaml common-volume branch.
# -----------------------------------------------------------------------------
bookkeeper:
affinity:
nodeAffinity: *nodeAffinity
volumes:
useSingleCommonVolume: true
journal:
Expand Down Expand Up @@ -145,6 +167,8 @@ bookkeeper:
# enablePackagesManagement keys in broker-configmap.yaml).
# -----------------------------------------------------------------------------
broker:
affinity:
nodeAffinity: *nodeAffinity
statefulsetUpgrade:
enabled: false
packageManagement:
Expand Down Expand Up @@ -216,3 +240,12 @@ auth:
- pulsar
openIDRoleClaim: sub
openIDRequireIssuersUseHttps: "true"

# -----------------------------------------------------------------------------
# Function worker nodeAffinity -- the separate function-worker StatefulSet only
# renders under this overlay (components.function_worker), so the base file has
# no function_worker block to carry it.
# -----------------------------------------------------------------------------
function_worker:
affinity:
nodeAffinity: *nodeAffinity
63 changes: 63 additions & 0 deletions .ci/templates-all-values.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -212,6 +212,18 @@ auth:
affinity:
anti_affinity: true
type: requiredDuringSchedulingIgnoredDuringExecution
# Single required term -- the anchored multi-term value used by the
# component blocks is defined later in the file, so this one is
# spelled out in full.
nodeAffinity:
requiredDuringSchedulingIgnoredDuringExecution:
nodeSelectorTerms:
- matchExpressions:
- key: node-pool
operator: In
values:
- pool-a
- pool-b
# Two annotation keys on the signing-key secret -- exercises the
# `range $k, $v := ...secretAnnotations.key` loop in jwt-secret-init.yaml
secretAnnotations:
Expand Down Expand Up @@ -269,6 +281,37 @@ extraDeploy:
# / annotations indent.
# -----------------------------------------------------------------------------
zookeeper:
affinity:
# Two nodeSelectorTerms (OR), several matchExpressions per term (AND),
# matchFields, and required + preferred together -- exercises the
# `toYaml | nindent` passthrough with a deeply nested multi-element value.
nodeAffinity: &nodeAffinity
requiredDuringSchedulingIgnoredDuringExecution:
nodeSelectorTerms:
- matchExpressions:
- key: node-pool
operator: In
values:
- pool-a
- pool-b
- key: dedicated
operator: Exists
- matchExpressions:
- key: gpu-count
operator: Gt
values:
- "2"
matchFields:
- key: metadata.name
operator: In
values:
- node-1
preferredDuringSchedulingIgnoredDuringExecution:
- weight: 50
preference:
matchExpressions:
- key: spot
operator: DoesNotExist
replicaCount: 3
podMonitor:
enabled: true
Expand Down Expand Up @@ -343,6 +386,8 @@ zookeeper:
# bookkeeper-configmap.yaml multi-volume directory list rendering.
# -----------------------------------------------------------------------------
bookkeeper:
affinity:
nodeAffinity: *nodeAffinity
replicaCount: 4
podMonitor:
enabled: true
Expand Down Expand Up @@ -449,6 +494,8 @@ bookkeeper:
# Autorecovery -- multi-element lists/maps + custom timeout
# -----------------------------------------------------------------------------
autorecovery:
affinity:
nodeAffinity: *nodeAffinity
podMonitor:
enabled: true
interval: 30s
Expand Down Expand Up @@ -507,6 +554,8 @@ autorecovery:
# pulsar_metadata -- exercise PIP-45 metadata driver toggles + extra init cmd
# -----------------------------------------------------------------------------
pulsar_metadata:
affinity:
nodeAffinity: *nodeAffinity
bookkeeper:
usePulsarMetadataClientDriver: true
usePulsarMetadataBookieDriver: true
Expand All @@ -516,6 +565,8 @@ extraInitCommand: "echo 'extra init command'"
# Standalone -- left disabled (mutually exclusive with the distributed setup)
# -----------------------------------------------------------------------------
standalone:
affinity:
nodeAffinity: *nodeAffinity
Comment thread
smbecker marked this conversation as resolved.
enabled: false

# -----------------------------------------------------------------------------
Expand All @@ -526,6 +577,8 @@ standalone:
# block.
# -----------------------------------------------------------------------------
broker:
affinity:
nodeAffinity: *nodeAffinity
replicaCount: 3
autoscaling:
enabled: true
Expand Down Expand Up @@ -632,6 +685,8 @@ functions:
# and is covered indirectly by other scenarios).
# -----------------------------------------------------------------------------
proxy:
affinity:
nodeAffinity: *nodeAffinity
replicaCount: 3
podMonitor:
enabled: true
Expand Down Expand Up @@ -720,6 +775,8 @@ proxy:
# Toolset -- multi-element lists/maps
# -----------------------------------------------------------------------------
toolset:
affinity:
nodeAffinity: *nodeAffinity
useProxy: true
priorityClassName: high-priority-nonpreempting
appAnnotations:
Expand Down Expand Up @@ -769,6 +826,8 @@ oxia:
initialShardCount: 3
replicationFactor: 3
coordinator:
affinity:
nodeAffinity: *nodeAffinity
priorityClassName: high-priority-nonpreempting
appAnnotations:
deploy/owner: pulsar-team
Expand Down Expand Up @@ -814,6 +873,8 @@ oxia:
- oxia-internal.example.com:6648
- oxia-external.example.com:6648
server:
affinity:
nodeAffinity: *nodeAffinity
priorityClassName: high-priority-nonpreempting
appAnnotations:
deploy/owner: pulsar-team
Expand Down Expand Up @@ -850,6 +911,8 @@ oxia:
# -----------------------------------------------------------------------------
dekaf:
deployment:
affinity:
nodeAffinity: *nodeAffinity
priorityClassName: high-priority-nonpreempting
annotations:
deploy/owner: pulsar-team
Expand Down
18 changes: 18 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -216,6 +216,24 @@ We provide some instructions to guide you through the preparation: http://pulsar
anti_affinity: false
```

To pin a component to specific nodes (for example a dedicated GKE node pool), set that component's
`affinity.nodeAffinity`. It is passed through to the pod spec verbatim, so any native
[node affinity](https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity)
expression works, and it composes with the chart's own pod anti-affinity rather than replacing them:

```yaml
broker:
affinity:
nodeAffinity:
requiredDuringSchedulingIgnoredDuringExecution:
nodeSelectorTerms:
- matchExpressions:
- key: cloud.google.com/gke-nodepool
operator: In
values:
- pulsar-pool
```

2. Install the chart:

```bash
Expand Down
4 changes: 4 additions & 0 deletions charts/pulsar/templates/autorecovery-statefulset.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -73,6 +73,10 @@ spec:
{{- toYaml .Values.autorecovery.topologySpreadConstraints | nindent 8 }}
{{- end }}
affinity:
{{- with .Values.autorecovery.affinity.nodeAffinity }}
nodeAffinity:
{{- toYaml . | nindent 10 }}
{{- end }}
{{- if and .Values.affinity.anti_affinity .Values.autorecovery.affinity.anti_affinity}}
podAntiAffinity:
{{ if eq .Values.autorecovery.affinity.type "requiredDuringSchedulingIgnoredDuringExecution"}}
Expand Down
5 changes: 5 additions & 0 deletions charts/pulsar/templates/bookkeeper-cluster-initialize.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -52,6 +52,11 @@ spec:
{{- if .Values.pulsar_metadata.tolerations }}
{{ toYaml .Values.pulsar_metadata.tolerations | indent 8 }}
{{- end }}
{{- with (.Values.pulsar_metadata.affinity).nodeAffinity }}
affinity:
nodeAffinity:
{{- toYaml . | nindent 10 }}
{{- end }}
initContainers:
{{- if .Values.tls.bookie.cacerts.enabled }}
- name: cacerts
Expand Down
4 changes: 4 additions & 0 deletions charts/pulsar/templates/bookkeeper-statefulset.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -70,6 +70,10 @@ spec:
{{- toYaml .Values.bookkeeper.topologySpreadConstraints | nindent 8 }}
{{- end }}
affinity:
{{- with .Values.bookkeeper.affinity.nodeAffinity }}
nodeAffinity:
{{- toYaml . | nindent 10 }}
{{- end }}
{{- if and .Values.affinity.anti_affinity .Values.bookkeeper.affinity.anti_affinity}}
podAntiAffinity:
{{- if eq .Values.bookkeeper.affinity.type "requiredDuringSchedulingIgnoredDuringExecution"}}
Expand Down
26 changes: 26 additions & 0 deletions charts/pulsar/templates/broker-statefulset-upgrade.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -90,9 +90,35 @@ spec:
spec:
serviceAccountName: "{{ template "pulsar.fullname" . }}-{{ .Values.broker.component }}-sts-cleanup"
restartPolicy: Never
{{- include "pulsar.imagePullSecrets" . | nindent 6 }}
{{- if .Values.broker.nodeSelector }}
nodeSelector:
{{ toYaml .Values.broker.nodeSelector | indent 8 }}
{{- end }}
{{- if .Values.broker.priorityClassName }}
priorityClassName: {{ .Values.broker.priorityClassName }}
{{- end }}
{{- if .Values.broker.tolerations }}
tolerations:
{{ toYaml .Values.broker.tolerations | indent 8 }}
{{- end }}
{{- if .Values.broker.topologySpreadConstraints }}
topologySpreadConstraints:
{{- toYaml .Values.broker.topologySpreadConstraints | nindent 8 }}
{{- end }}
{{- /* This short-lived cleanup hook intentionally has no pod anti-affinity: spreading a
single-shot kubectl pod across nodes buys nothing, and inheriting the component's
required anti-affinity would make the hook unschedulable once every node already
runs a broker pod. */}}
{{- with .Values.broker.affinity.nodeAffinity }}
affinity:
nodeAffinity:
{{- toYaml . | nindent 10 }}
{{- end }}
containers:
- name: sts-cleanup
image: "{{ template "pulsar.imageFullName" (dict "image" .Values.images.kubectl "root" .) }}"
imagePullPolicy: "{{ template "pulsar.imagePullPolicy" (dict "image" .Values.images.kubectl "root" .) }}"
command:
- sh
- -c
Expand Down
4 changes: 4 additions & 0 deletions charts/pulsar/templates/broker-statefulset.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -95,6 +95,10 @@ spec:
{{- toYaml .Values.broker.topologySpreadConstraints | nindent 8 }}
{{- end }}
affinity:
{{- with .Values.broker.affinity.nodeAffinity }}
nodeAffinity:
{{- toYaml . | nindent 10 }}
{{- end }}
{{- if and .Values.affinity.anti_affinity .Values.broker.affinity.anti_affinity}}
podAntiAffinity:
{{- if eq .Values.broker.affinity.type "requiredDuringSchedulingIgnoredDuringExecution"}}
Expand Down
6 changes: 6 additions & 0 deletions charts/pulsar/templates/dekaf-deployment.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -57,6 +57,12 @@ spec:
priorityClassName: {{ .Values.dekaf.deployment.priorityClassName }}
{{- end }}

{{- with (((.Values.dekaf).deployment).affinity).nodeAffinity }}
affinity:
nodeAffinity:
{{- toYaml . | nindent 10 }}
{{- end }}

containers:
- name: dekaf
image: "{{ .Values.images.dekaf.repository }}:{{ .Values.images.dekaf.tag }}"
Expand Down
4 changes: 4 additions & 0 deletions charts/pulsar/templates/function-worker-statefulset.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -71,6 +71,10 @@ spec:
{{- toYaml .Values.function_worker.topologySpreadConstraints | nindent 8 }}
{{- end }}
affinity:
{{- with .Values.function_worker.affinity.nodeAffinity }}
nodeAffinity:
{{- toYaml . | nindent 10 }}
{{- end }}
{{- if and .Values.affinity.anti_affinity .Values.function_worker.affinity.anti_affinity }}
podAntiAffinity:
{{- if eq .Values.function_worker.affinity.type "requiredDuringSchedulingIgnoredDuringExecution" }}
Expand Down
8 changes: 7 additions & 1 deletion charts/pulsar/templates/jwt-secret-init.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -106,8 +106,13 @@ spec:
tolerations:
{{ toYaml .Values.auth.authentication.jwt.generateSecrets.tolerations | indent 8 }}
{{- end }}
{{- if and .Values.affinity.anti_affinity .Values.auth.authentication.jwt.generateSecrets.affinity.anti_affinity }}
{{- if or .Values.auth.authentication.jwt.generateSecrets.affinity.nodeAffinity (and .Values.affinity.anti_affinity .Values.auth.authentication.jwt.generateSecrets.affinity.anti_affinity) }}
affinity:
{{- with .Values.auth.authentication.jwt.generateSecrets.affinity.nodeAffinity }}
nodeAffinity:
{{- toYaml . | nindent 10 }}
{{- end }}
{{- if and .Values.affinity.anti_affinity .Values.auth.authentication.jwt.generateSecrets.affinity.anti_affinity }}
podAntiAffinity:
{{- if eq .Values.auth.authentication.jwt.generateSecrets.affinity.type "requiredDuringSchedulingIgnoredDuringExecution" }}
{{ .Values.auth.authentication.jwt.generateSecrets.affinity.type }}:
Expand Down Expand Up @@ -146,6 +151,7 @@ spec:
- jwt-secret-init
topologyKey: {{ .Values.auth.authentication.jwt.generateSecrets.affinity.anti_affinity_topology_key }}
{{- end }}
{{- end }}
{{- end }}
volumes:
- name: jwt-secrets
Expand Down
5 changes: 5 additions & 0 deletions charts/pulsar/templates/oxia-coordinator-deployment.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -59,6 +59,11 @@ spec:
{{- end }}
{{- if .Values.oxia.coordinator.priorityClassName }}
priorityClassName: {{ .Values.oxia.coordinator.priorityClassName }}
{{- end }}
{{- with (.Values.oxia.coordinator.affinity).nodeAffinity }}
affinity:
nodeAffinity:
{{- toYaml . | nindent 10 }}
{{- end }}
serviceAccountName: {{ template "pulsar.fullname" . }}-{{ .Values.oxia.component }}-coordinator
containers:
Expand Down
Loading