Skip to content

rstudio-workbench: set imagePullPolicy on launcher init containers - #958

Merged
stevenolen merged 1 commit into
mainfrom
init-container-pull-policy
Oct 5, 2026
Merged

stevenolen merged 1 commit into
mainfrom
init-container-pull-policy

Conversation

@stevenolen

Copy link
Copy Markdown
Contributor

Fixes #949

Summary

The .Job.initContainers loop in files/job.tpl emitted no imagePullPolicy, so Kubernetes defaulted to IfNotPresent for any non-:latest tag. With launcher-positron-preview-init-container-enabled, the Positron preview init image (ghcr.io/posit-dev/workbench-positron-init-preview:daily) was pulled once per node and then reused indefinitely, so different nodes served different (and stale) preview builds.

Changes

  • files/job.tpl: for launcher-provided init containers:
    • images ending in :daily or :latest get imagePullPolicy: Always;
    • otherwise, launcher.templateValues.pod.initContainerImagePullPolicy is emitted if set;
    • if empty (the default), nothing is emitted, which keeps today's behaviour.
  • values.yaml: new launcher.templateValues.pod.initContainerImagePullPolicy: "".
  • Chart version 0.22.4, NEWS entry, regenerated README.

The rule keys off the image tag rather than off whether preview is enabled: the template only sees the resulting image string, and a chart-wide switch would force Always onto pinned images for no benefit.

# Version: in job.tpl is unchanged; it tracks the upstream launcher template version, and chart-side edits to job.tpl have not bumped it.

Testing

  • make lint passes; just test rstudio-workbench passes (173 tests).
  • Rendered all lint/ scenarios on main and on this branch: the only differences are the new job.tpl lines, the new key in the template-values JSON, and the resulting checksum/config-general annotations.
  • Rendered job.tpl against sample init containers (...-preview:daily, foo:latest, posit/workbench-session-init:2026.09.0):
    • value empty: Always, Always, unset
    • value IfNotPresent: Always, Always, IfNotPresent
    • value Never: Always, Always, Never

Out of scope

This covers launcher.useTemplates only. Without templates, the Kubernetes launcher builds the pod itself and Workbench's launcher InitContainer has no pull-policy field, so a complete fix needs a Workbench change (see the issue).

Init containers added by the launcher had no imagePullPolicy, so
Kubernetes defaulted to IfNotPresent. The Positron preview init image
(ghcr.io/posit-dev/workbench-positron-init-preview:daily) therefore went
stale on each node after its first pull.

Images tagged :daily or :latest now always use Always. Other init
containers use the new launcher.templateValues.pod.initContainerImagePullPolicy
value when set; empty keeps the Kubernetes default.

Fixes #949
@stevenolen
stevenolen requested a review from a team October 5, 2026 17:37
@stevenolen
stevenolen merged commit b3982da into main Oct 5, 2026
9 checks passed
@stevenolen
stevenolen deleted the init-container-pull-policy branch October 5, 2026 17:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

rstudio-workbench: job.tpl sets no imagePullPolicy on launcher init containers, so the Positron preview (:daily) image goes stale on each node

2 participants