Feature: Reduce Mounting time of large PVs
还没有人认领这个 Issue。
评估
- 难度
- 2/5
- 预计耗时
- 1-3 小时
- 新手友好度
- 48/100
- Issue 类型
- 功能
- 描述清晰度
- 基本清楚
- 活跃度
- 停滞
- 技术栈
- helm, kubernetes
- 领域
- devops, infrastructure
调研方向
定位 Helm chart 中 nextcloud.podSecurityContext 的定义,并检查其默认值如何渲染到 pod security context 中。确认默认值包含 fsGroupChangePolicy: "OnRootMismatch",然后验证渲染后的 Kubernetes manifest,并评估 rollout 期间报告的配置文件警告。
由索引模型根据 Issue 内容生成。
描述
Description of the change
Add the following by default to the nextcloud.podSecurityContext: fsGroupChangePolicy: "OnRootMismatch"
Benefits
I am mounting several large PVs with media archives. https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ states that setting fsGroup will make Kubernetes recursively change ownership and permissions for the contents of each volume. This takes about 30 minutes in my case.
Setting fsGroupChangePolicy: "OnRootMismatch" reduces this to just several seconds.
Possible drawbacks
It is probably not guaranteed that every file has the proper group permissions. However, I did not recognize any problems when syncing and opening files and folders (and cards and calenders) in nextcloud.
Also, the log of the nextcloud container gives some warnings:
Warning: /var/www/html/config/apache-pretty-urls.config.php differs from the latest version of this image at /usr/src/nextcloud/config/apache-pretty-urls.config.php
Warning: /var/www/html/config/apcu.config.php differs from the latest version of this image at /usr/src/nextcloud/config/apcu.config.php
Warning: /var/www/html/config/apps.config.php differs from the latest version of this image at /usr/src/nextcloud/config/apps.config.php
Warning: /var/www/html/config/redis.config.php differs from the latest version of this image at /usr/src/nextcloud/config/redis.config.php
Warning: /var/www/html/config/reverse-proxy.config.php differs from the latest version of this image at /usr/src/nextcloud/config/reverse-proxy.config.php
Warning: /var/www/html/config/s3.config.php differs from the latest version of this image at /usr/src/nextcloud/config/s3.config.php
Warning: /var/www/html/config/smtp.config.php differs from the latest version of this image at /usr/src/nextcloud/config/smtp.config.php
Warning: /var/www/html/config/swift.config.php differs from the latest version of this image at /usr/src/nextcloud/config/swift.config.php
Warning: /var/www/html/config/upgrade-disable-web.config.php differs from the latest version of this image at /usr/src/nextcloud/config/upgrade-disable-web.config.php
It seems that the files only differ by 1 byte (an additional line feed at the end of the file). But I am not sure if this could have side effects when a new image version is rolled out.
Additional information
None, I think.
- 主要语言
- Go Template
- 星标
- 536
- 派生
- 316
- 平均合并
- 4 天 16 小时
- 30 天内合并 PR
- 2
环境准备
- 没有 Dockerfile 或 Docker Compose 文件
- 有 Pull Request 模板
- 阅读贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
nextcloud/helm 的其他 Issue
-
No native support for REDIS_USER enviroment var可能已有人在做 @jholmes802 今天认领。 未关闭
难度 2/5 1-3 小时 新手友好度 70/100
-
难度 2/5 1-3 小时 新手友好度 72/100
-
难度 2/5 1-3 小时 新手友好度 68/100
-
nextcloud.openmetrics.allowedClients is silently ignored unless nextcloud.configs is set可能已有人在做 @JanWelker 于 17 天前认领。 未关闭
难度 3/5 1-2 天 新手友好度 78/100
-
External Redis not working: redis-session.ini: Permission denied可能已有人在做 @antoinetran 于 21 天前认领。 未关闭
难度 3/5 1-2 天 新手友好度 55/100
相似的 Issue
-
Sanity on ansible-core devel fails: ignore-2.23.txt references the removed import-3.9 test可能已有人在做 @yurnov 今天认领。 未关闭needs_triage
难度 1/5 1 小时以内 新手友好度 91/100
ansible-collections/kubernetes.core#1275 ·
维护者通常 1 天内回复
-
bug milestone-qa
难度 2/5 1-3 小时 新手友好度 85/100
lognorman20/monaco#3995 ·
-
难度 2/5 1-3 小时 新手友好度 70/100
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 72/100
gnosis/gnosis_vpn#540 ·
维护者通常 1 天内回复
-
e2e-failure ready-to-code
难度 2/5 1-3 小时 新手友好度 78/100
redhat-developer/rhdh-plugin-export-overlays#4261 · 1 条评论 ·
维护者通常 1 天内回复