Skip to content

Support per-container image overrides (DatadogAgentGenericContainer.image) - #3551

Draft
Shallav91 wants to merge 1 commit into
DataDog:mainfrom
Shallav91:shallav/per-container-image-override
Draft

Shallav91 wants to merge 1 commit into
DataDog:mainfrom
Shallav91:shallav/per-container-image-override

Conversation

@Shallav91

Copy link
Copy Markdown

What does this PR do?

Adds an image field (AgentImageConfig) to DatadogAgentGenericContainer, so per-container image overrides become expressible in both the v2alpha1 DatadogAgent and v1alpha1 DatadogAgentProfile CRDs (the type is shared; DDAI and CSIDriver CRDs regenerate identically).

The container-level image is applied in overrideContainer(), which PodTemplateSpec() runs after the component-level image override — so a container-level image always wins for that container.

Motivation

Fixes #3550.

Today a component-level override.nodeAgent.image is applied to every known agent container, including otel-agent, which normally runs the separate ddot-collector image (internal/controller/datadogagent/override/podtemplatespec.go). Agent images do not ship the otel-agent binary (verified on release 7.83.2: /opt/datadog-agent/embedded/bin/otel-agent absent, /etc/services.d/otel removed at build), so changing the node-agent image on a cluster with features.otelCollector.enabled: true crashloops the collector — and the CRDs offered no way to pin it back (…containers.otel-agent.image: field not declared in schema).

This blocks profiles for custom/validation agent images or phased image rollouts whenever the collector is enabled. With this change:

override:
  nodeAgent:
    image:
      name: docker.io/datadog/agent-dev:validation-tag   # all agent containers
    containers:
      otel-agent:
        image:
          name: registry.datadoghq.com/ddot-collector:7.78.1   # collector stays put

Additional Notes

  • Precedence matches the existing ordering in PodTemplateSpec() (component image first, container overrides second); no behavior change for specs that don't set a container-level image.
  • PullPolicy is honored per container. PullSecrets are pod-level and intentionally not applied per container (noted in the field comment).
  • For cross-registry images, use the full-string form <REGISTRY>/<NAME>:<TAG> — fromImageConfig only parses the registry out of Name when the tag is embedded (pre-existing AgentImageConfig behavior, unchanged here).
  • Labels/milestone: needs a maintainer to add enhancement (and milestone or qa/skip-qa) — I can't set them from a fork.

Minimum Agent Versions

  • Agent: n/a (operator-only change)
  • Cluster Agent: n/a

Describe your test plan

  • TestContainer/override_container_image — container-level image (and pull policy) applied to the named container
  • TestPodTemplateSpecContainerImageOverride — the end-to-end precedence scenario: component-level image override + container-level pin on otel-agent; asserts agent/trace-agent move to the custom image while otel-agent stays on ddot-collector
  • make generate manifests run; CRDs + docs regenerated; go build ./..., go vet, and go test ./internal/controller/datadogagent/... ./api/... ./pkg/images/... green
  • Can additionally validate on a live cluster (single-node profile with a custom agent image + otelCollector enabled) on request

Checklist

  • PR has at least one valid label: bug, enhancement, refactoring, documentation, tooling, and/or dependencies
  • PR has a milestone or the qa/skip-qa label
  • All commits are signed (see: signing commits)

The component-level image override (override.nodeAgent.image) is applied
to every known agent container in the pod, including otel-agent, which
runs the separate ddot-collector image; agent images do not ship the
otel-agent binary, so the collector container crashloops whenever a
profile/DatadogAgent changes the node-agent image on a cluster with
features.otelCollector enabled. The per-container override type had no
image field to pin the collector back.

Adds Image (*AgentImageConfig) to DatadogAgentGenericContainer. Because
PodTemplateSpec() applies container overrides after the component-level
image override, a container-level image always wins for that container,
e.g. keep otel-agent on ddot-collector while the rest of the pod runs a
custom agent image. PullPolicy is honored per container; PullSecrets
remain pod-level.

Regenerates CRDs (datadogagents, datadogagentprofiles,
datadogagentinternals, datadogcsidrivers) and docs.

Fixes DataDog#3550

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[BUG] nodeAgent image override rewrites the otel-agent container image and crashloops the collector; no per-container image override in the CRDs

1 participant