Conversation
The component-level image override (override.nodeAgent.image) is applied to every known agent container in the pod, including otel-agent, which runs the separate ddot-collector image; agent images do not ship the otel-agent binary, so the collector container crashloops whenever a profile/DatadogAgent changes the node-agent image on a cluster with features.otelCollector enabled. The per-container override type had no image field to pin the collector back. Adds Image (*AgentImageConfig) to DatadogAgentGenericContainer. Because PodTemplateSpec() applies container overrides after the component-level image override, a container-level image always wins for that container, e.g. keep otel-agent on ddot-collector while the rest of the pod runs a custom agent image. PullPolicy is honored per container; PullSecrets remain pod-level. Regenerates CRDs (datadogagents, datadogagentprofiles, datadogagentinternals, datadogcsidrivers) and docs. Fixes DataDog#3550
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What does this PR do?
Adds an
imagefield (AgentImageConfig) toDatadogAgentGenericContainer, so per-container image overrides become expressible in both the v2alpha1DatadogAgentand v1alpha1DatadogAgentProfileCRDs (the type is shared; DDAI and CSIDriver CRDs regenerate identically).The container-level image is applied in
overrideContainer(), whichPodTemplateSpec()runs after the component-level image override — so a container-level image always wins for that container.Motivation
Fixes #3550.
Today a component-level
override.nodeAgent.imageis applied to every known agent container, includingotel-agent, which normally runs the separateddot-collectorimage (internal/controller/datadogagent/override/podtemplatespec.go). Agent images do not ship theotel-agentbinary (verified on release7.83.2:/opt/datadog-agent/embedded/bin/otel-agentabsent,/etc/services.d/otelremoved at build), so changing the node-agent image on a cluster withfeatures.otelCollector.enabled: truecrashloops the collector — and the CRDs offered no way to pin it back (…containers.otel-agent.image: field not declared in schema).This blocks profiles for custom/validation agent images or phased image rollouts whenever the collector is enabled. With this change:
Additional Notes
PodTemplateSpec()(component image first, container overrides second); no behavior change for specs that don't set a container-level image.PullPolicyis honored per container.PullSecretsare pod-level and intentionally not applied per container (noted in the field comment).<REGISTRY>/<NAME>:<TAG>—fromImageConfigonly parses the registry out ofNamewhen the tag is embedded (pre-existingAgentImageConfigbehavior, unchanged here).enhancement(and milestone orqa/skip-qa) — I can't set them from a fork.Minimum Agent Versions
Describe your test plan
TestContainer/override_container_image— container-level image (and pull policy) applied to the named containerTestPodTemplateSpecContainerImageOverride— the end-to-end precedence scenario: component-level image override + container-level pin onotel-agent; asserts agent/trace-agent move to the custom image while otel-agent stays onddot-collectormake generate manifestsrun; CRDs + docs regenerated;go build ./...,go vet, andgo test ./internal/controller/datadogagent/... ./api/... ./pkg/images/...greenChecklist
bug,enhancement,refactoring,documentation,tooling, and/ordependenciesqa/skip-qalabel