azure: download nodeup from Blob Storage with curl - #18666
Merged
kubernetes-prow[bot] merged 1 commit intoAug 5, 2026
Merged
Conversation
Contributor
|
Skipping CI for Draft Pull Request. |
hakman
force-pushed
the
azure-blob-nodeup-download
branch
from
August 5, 2026 04:27
ba3664b to
f50792e
Compare
When KOPS_BASE_URL is an azureblob://<account>/<container>/<key> URL on an Azure cluster, the bootstrap script downloads nodeup with curl. It requests an OAuth token for the system-assigned managed identity from the instance metadata service and passes the Authorization and x-ms-version headers to curl through stdin, so the token never reaches disk, process arguments, or console logs. The GCS branch now parses its service account token with the same json-field helper. The download URL hard-codes the public blob.core.windows.net endpoint, so validation rejects non-public AZURE_ENVIRONMENT values. Source locations are percent-escaped and validated when the script is rendered, so malformed URLs fail during kops update rather than in the boot retry loop. spec.assets.fileRepository now accepts an azureblob:// URL on Azure, so that the node assets can be hosted in the same private container. The URL must include a container, and nodes on other clouds cannot authenticate to Azure Blob Storage, so validation keeps rejecting it there. Nodeup reads these assets through VFS using the managed identity credentials, and "kops get assets --copy" can now also write to an azureblob:// repository. Access is not granted automatically: the docs describe granting Storage Blob Data Reader on the assets container only, never on the state-store account, which would let nodes read the cluster PKI.
hakman
force-pushed
the
azure-blob-nodeup-download
branch
from
August 5, 2026 05:20
ac7f908 to
8e9cf58
Compare
hakman
marked this pull request as ready for review
August 5, 2026 05:48
Member
Author
Member
|
/lgtm |
Member
Author
|
/test all |
Member
|
/lgtm |
Member
Author
|
/approve |
Contributor
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: hakman The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:
Approvers can indicate their approval by writing |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
When
KOPS_BASE_URLis anazureblob://<account>/<container>/<key>URL on an Azure cluster, the bootstrap script downloads nodeup with curl. It requests an OAuth token for the system-assigned managed identity from the instance metadata service and passes theAuthorizationandx-ms-versionheaders to curl through stdin, so the token never reaches disk, process arguments, or console logs.The download URL hard-codes the public
blob.core.windows.netendpoint, so validation rejects non-publicAZURE_ENVIRONMENTvalues. Source locations are percent-escaped and validated when the script is rendered, so malformed URLs fail duringkops updaterather than in the boot retry loop.spec.assets.fileRepositorynow accepts anazureblob://URL on Azure, so that the node assets can be hosted in the same private container. The URL must include a container, and nodes on other clouds cannot authenticate to Azure Blob Storage, so validation keeps rejecting it there. Nodeup reads these assets through VFS using the managed identity credentials, andkops get assets --copycan now also write to anazureblob://repository.Access is not granted automatically: the docs describe granting
Storage Blob Data Readeron the assets container only, never on the state-store account, which would let nodes read the cluster PKI.