Sitelet https://github.com/kubernetes/kops/pull/18666
Skip to content

azure: download nodeup from Blob Storage with curl - #18666

Merged
kubernetes-prow[bot] merged 1 commit into
kubernetes:masterfrom
hakman:azure-blob-nodeup-download
Aug 5, 2026
Merged

kubernetes-prow[bot] merged 1 commit into
kubernetes:masterfrom
hakman:azure-blob-nodeup-download

Conversation

@hakman

@hakman hakman commented Aug 5, 2026

Copy link
Copy Markdown
Member

When KOPS_BASE_URL is an azureblob://<account>/<container>/<key> URL on an Azure cluster, the bootstrap script downloads nodeup with curl. It requests an OAuth token for the system-assigned managed identity from the instance metadata service and passes the Authorization and x-ms-version headers to curl through stdin, so the token never reaches disk, process arguments, or console logs.

The download URL hard-codes the public blob.core.windows.net endpoint, so validation rejects non-public AZURE_ENVIRONMENT values. Source locations are percent-escaped and validated when the script is rendered, so malformed URLs fail during kops update rather than in the boot retry loop.

spec.assets.fileRepository now accepts an azureblob:// URL on Azure, so that the node assets can be hosted in the same private container. The URL must include a container, and nodes on other clouds cannot authenticate to Azure Blob Storage, so validation keeps rejecting it there. Nodeup reads these assets through VFS using the managed identity credentials, and kops get assets --copy can now also write to an azureblob:// repository.

Access is not granted automatically: the docs describe granting Storage Blob Data Reader on the assets container only, never on the state-store account, which would let nodes read the cluster PKI.

@kubernetes-prow

Copy link
Copy Markdown
Contributor

Skipping CI for Draft Pull Request.
If you want CI signal for your change, please convert it to an actual PR.
You can still manually trigger a test run with /test all

@kubernetes-prow kubernetes-prow Bot added the do-not-merge/work-in-progress Indicates that a PR should not merge because it is a work in progress. label Aug 5, 2026
@kubernetes-prow
kubernetes-prow Bot requested a review from olemarkus August 5, 2026 04:23
@kubernetes-prow
kubernetes-prow Bot requested a review from zetaab August 5, 2026 04:23
@kubernetes-prow kubernetes-prow Bot added area/documentation cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. size/L Denotes a PR that changes 100-499 lines, ignoring generated files. labels Aug 5, 2026
@hakman
hakman force-pushed the azure-blob-nodeup-download branch from ba3664b to f50792e Compare August 5, 2026 04:27
When KOPS_BASE_URL is an azureblob://<account>/<container>/<key> URL on
an Azure cluster, the bootstrap script downloads nodeup with curl. It
requests an OAuth token for the system-assigned managed identity from
the instance metadata service and passes the Authorization and
x-ms-version headers to curl through stdin, so the token never reaches
disk, process arguments, or console logs. The GCS branch now parses its
service account token with the same json-field helper.

The download URL hard-codes the public blob.core.windows.net endpoint,
so validation rejects non-public AZURE_ENVIRONMENT values. Source
locations are percent-escaped and validated when the script is
rendered, so malformed URLs fail during kops update rather than in the
boot retry loop.

spec.assets.fileRepository now accepts an azureblob:// URL on Azure, so
that the node assets can be hosted in the same private container. The
URL must include a container, and nodes on other clouds cannot
authenticate to Azure Blob Storage, so validation keeps rejecting it
there. Nodeup reads these assets through VFS using the managed identity
credentials, and "kops get assets --copy" can now also write to an
azureblob:// repository.

Access is not granted automatically: the docs describe granting Storage
Blob Data Reader on the assets container only, never on the state-store
account, which would let nodes read the cluster PKI.
@hakman
hakman force-pushed the azure-blob-nodeup-download branch from ac7f908 to 8e9cf58 Compare August 5, 2026 05:20
@hakman
hakman marked this pull request as ready for review August 5, 2026 05:48
@kubernetes-prow kubernetes-prow Bot removed the do-not-merge/work-in-progress Indicates that a PR should not merge because it is a work in progress. label Aug 5, 2026
@hakman

hakman commented Aug 5, 2026

Copy link
Copy Markdown
Member Author

/cc @rifelpet @ameukam

@kubernetes-prow
kubernetes-prow Bot requested review from ameukam and rifelpet August 5, 2026 05:48
@hakman
hakman removed request for olemarkus and zetaab August 5, 2026 05:48
@ameukam

ameukam commented Aug 5, 2026

Copy link
Copy Markdown
Member

/lgtm

@kubernetes-prow kubernetes-prow Bot added the lgtm "Looks good to me", indicates that a PR is ready to be merged. label Aug 5, 2026
@hakman

hakman commented Aug 5, 2026

Copy link
Copy Markdown
Member Author

/test all

@ameukam

ameukam commented Aug 5, 2026

Copy link
Copy Markdown
Member

/lgtm

@hakman

hakman commented Aug 5, 2026

Copy link
Copy Markdown
Member Author

/approve

@kubernetes-prow

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: hakman

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@kubernetes-prow kubernetes-prow Bot added the approved Indicates a PR has been approved by an approver from all required OWNERS files. label Aug 5, 2026
@kubernetes-prow
kubernetes-prow Bot merged commit 3439540 into kubernetes:master Aug 5, 2026
26 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved Indicates a PR has been approved by an approver from all required OWNERS files. area/api area/documentation cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. lgtm "Looks good to me", indicates that a PR is ready to be merged. size/L Denotes a PR that changes 100-499 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants