etcd-manager: remove kops-utils-cp and use image volumes on all supported Kubernetes versions - #18688
Merged
kubernetes-prow[bot] merged 5 commits intoAug 14, 2026
Conversation
rifelpet
reviewed
Aug 14, 2026
| return false | ||
| } | ||
| return true | ||
| return !c.IsKubernetesLT("1.32.0") |
Member
There was a problem hiding this comment.
should this just unconditionally return true if 1.32.0 is the oldest supported k8s version?
Member
Author
There was a problem hiding this comment.
There might be some race during upgrades, I wouldn't worry too much about it.
rifelpet
approved these changes
Aug 14, 2026
Contributor
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: rifelpet The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:
Approvers can indicate their approval by writing |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
kOps master now requires containerd >= 2.1.0 (validation) and defaults to 2.3.4, so the runtime side of image volumes is guaranteed for every cluster. The only remaining users of the kops-utils-cp copy fallback were Kubernetes 1.32 clusters. This PR enables image volumes on 1.32 as well, by force-enabling the
ImageVolumekubelet feature gate the same way kOps already does for 1.33 through 1.35, and deletes the fallback and the image.Changes
HasImageVolumesSupport()now only checks for Kubernetes >= 1.32.0, which isOldestSupportedKubernetesVersion. The containerd conditions were dropped: validation guarantees >= 2.1.0, and with the fallback gone afalsereturn would only suppress the feature gate while the manifest still uses image volumes.optemptyDir is also dropped: etcd-manager only reads and execs binaries from/opt/etcd-v<version>(BindirForEtcdVersion) and never writes under/opt, so the volume existed solely for the fallback.cmd/kops-utils-cpand its build/publish plumbing are removed: Makefile targets, cloudbuild.yaml push step, hack/set-version, and theKOPS_BASE_URLimage preload entry in nodeup config.tests/e2e/pkg/tester/skip_regex.gois kept: on ContainerOS kOps does not install containerd, so cos-121 nodes run the OS-bundled containerd 1.7 regardless of the cluster spec.Why enabling on Kubernetes 1.32 is safe
Verified by source-level diffs of the kubelet code between release tags:
getImageVolumes,imageVolumePullsinpkg/kubelet/kuberuntime/kuberuntime_manager.go) is byte-identical, and image GC protection (realImageGCManager.handleImageVolumes) is functionally identical since 1.31. The 1.32 to 1.33 delta is only subPath plumbing (inert, kOps mounts whole images) and three kubelet metrics.ImageVolumeSourceAPI and its validation are byte-identical from 1.31 through 1.35 for no-subPath manifests. The mirror-pod behavior with the apiserver gate off is the same as with the existing 1.33/1.34 setup and is cosmetic for static pods.PullIfNotPresent, which mitigates it.Clusters older than 1.32 are already rejected unless
KOPS_RUN_OBSOLETE_VERSIONis set; through that escape hatch, etcd-manager will no longer work below 1.32./cc @rifelpet @ameukam