Ready-to-adapt RotationPolicy manifests for node-rotation-controller. Policy
is configured through cluster-scoped RotationPolicy objects (spec
§5.4); the controller
resolves each NodePool's governing policy at reconcile time. A NodePool matched
by no policy is never rotated — its expireAfter backstop still applies.
These manifests are illustrative: edit the nodePoolSelector labels, windows,
and timeouts for your cluster before applying. The full field reference is in the
Helm chart README.
| File | Shows |
|---|---|
single-policy.yaml |
The simplest setup — one catch-all policy governing every NodePool. Start here. |
multi-nodepool.yaml |
Divergent policy per NodePool (issue #119): different cadence/timeouts for api vs batch pools, selected by label. |
specificity-resolution.yaml |
How a broad default and a narrower override coexist — most-specific selector wins; an equal-specificity tie is a hard error. |
maintenance-windows.yaml |
Composing maintenanceWindows: the union of entries, the no-overnight-wrap split at midnight, and multiple timezones. |
# CRD ships with the Helm chart; install it first if you have not already:
kubectl apply -f ../charts/node-rotation-controller/crds/
# Then apply an example (after editing the selectors/windows for your cluster):
kubectl apply -f single-policy.yaml
# Inspect resolved policies (short name: rotpol):
kubectl get rotpol -o widekubectl get rotpol -o wide shows each policy's Age-Threshold and the
Matched / Rotating NodePool counts from its status. A policy that ties with
another for some pool, or fails validation, reports it on the pool via a
PolicyConflict Warning event and the noderotation_policy_conflict metric —
see the production runbook for symptom-based triage.
surge.maxUnavailableis fixed at1in v1 (serial per NodePool); other values are rejected.prePullis reserved for v2 and must stayenabled: false(the default); the schema rejects enabling it.ageThreshold: autois recommended — it derives the threshold from the window cadence soKrotation chances stay belowexpireAfter(spec §3.2). An explicit duration is allowed but still validated.