write command output outside snapshotted rootfs - #397
Conversation
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: dd94f569cd
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| // here would only bound the tmpfs, not add capacity. Usage counts against the | ||
| // pod's memory budget. | ||
| sandboxPod.Spec.Volumes = append(sandboxPod.Spec.Volumes, corev1.Volume{ | ||
| Name: sandboxCommandOutputVolumeName, |
There was a problem hiding this comment.
Reserve or de-duplicate the injected volume name
If a Sandbox podTemplate.spec.volumes already contains a volume named command-output, CreateSandboxPod copies that user spec and this append adds a second volume with the same name, which Kubernetes rejects during Pod creation. Since the CRD explicitly allows users to define volumes, existing sandboxes using this common name will start failing to create unless the injected name is made clearly internal or conflicts are detected/handled before appending.
Useful? React with 👍 / 👎.
No description provided.