-
Notifications
You must be signed in to change notification settings - Fork 0
/
Copy pathinit-container.yaml
176 lines (175 loc) · 4.71 KB
/
init-container.yaml
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
# create secret generic blake-ssh-secret -n nnf-system --from-file=ssh-privatekey=./id_rsa --from-file=ssh-publickey=./id_rsa.pub
# create secret generic blake-ssh-secret -n default --from-file=ssh-privatekey=./id_rsa --from-file=ssh-publickey=./id_rsa.pub
apiVersion: v1
kind: Service
metadata:
name: workflow1
namespace: default
spec:
clusterIP: None
selector:
cray.nnf.container.workflow1: "true"
---
apiVersion: batch/v1
kind: Job
metadata:
name: container-mpi-kind-worker2
namespace: default
spec:
template:
metadata:
labels:
cray.nnf.container.workflow1: "true"
spec:
securityContext:
fsGroup: 1005
volumes:
- name: passwd
emptyDir: {}
- name: ssh-auth
secret:
defaultMode: 384
items:
- key: ssh-privatekey
path: id_rsa
- key: ssh-publickey
path: id_rsa.pub
- key: ssh-publickey
path: authorized_keys
secretName: blake-ssh-secret
initContainers:
- command:
- /bin/sh
- -c
- |
sed -i '/^mpiuser/d' /etc/passwd
echo "mpiuser:x:1041:1005::/home/mpiuser:/bin/sh" >> /etc/passwd
cp /etc/passwd /config/
exit 0
image: ghcr.io/nearnodeflash/nnf-container-example:latest
name: container-mpi-init
volumeMounts:
- name: passwd
mountPath: "/config"
containers:
- command:
- /bin/sh
- -c
- sleep 1000 && exit 0
image: ghcr.io/nearnodeflash/nnf-container-example:latest
name: container-mpi
volumeMounts:
- name: passwd
mountPath: "/etc/passwd"
subPath: "passwd"
- name: ssh-auth
mountPath: /home/mpiuser/.ssh
securityContext:
runAsNonRoot: true
runAsUser: 1041
runAsGroup: 1005
capabilities:
add: ["SETUID", "SETGID", "MKNOD"]
startupProbe:
exec:
command:
- service
- ssh
- status
initialDelaySeconds: 5
periodSeconds: 5
hostname: kind-worker2
nodeSelector:
kubernetes.io/hostname: kind-worker2
restartPolicy: Never
subdomain: workflow1
tolerations:
- effect: NoSchedule
key: cray.nnf.node
operator: Equal
value: "true"
---
apiVersion: batch/v1
kind: Job
metadata:
name: container-mpi-kind-worker3
namespace: default
spec:
template:
metadata:
labels:
cray.nnf.container.workflow1: "true"
spec:
securityContext:
fsGroup: 1005
volumes:
- name: passwd
emptyDir: {}
- name: ssh-auth
secret:
defaultMode: 384
items:
- key: ssh-privatekey
path: id_rsa
- key: ssh-publickey
path: id_rsa.pub
- key: ssh-publickey
path: authorized_keys
secretName: blake-ssh-secret
initContainers:
- command:
- /bin/sh
- -c
- |
sed -i '/^mpiuser/d' /etc/passwd
echo "mpiuser:x:1041:1005::/home/mpiuser:/bin/sh" >> /etc/passwd
echo "container-mpi:x:1041:1005::/home/container-mpi:/bin/sh" >> /etc/passwd
cp /etc/passwd /config/
exit 0
image: ghcr.io/nearnodeflash/nnf-container-example:latest
name: container-mpi-init
volumeMounts:
- name: passwd
mountPath: "/config"
containers:
- command:
- /bin/sh
- -c
- |
/usr/sbin/sshd -De &
sleep 1000 && exit 0
image: ghcr.io/nearnodeflash/nnf-container-example:latest
name: container-mpi
env:
- name: OMPI_MCA_orte_keep_fqdn_hostnames
value: "true"
volumeMounts:
- name: passwd
mountPath: "/etc/passwd"
subPath: "passwd"
- name: ssh-auth
mountPath: /home/mpiuser/.ssh
securityContext:
# runAsNonRoot: true
# runAsUser: 1041
# runAsGroup: 1005
capabilities:
add: ["SETUID", "SETGID", "MKNOD"]
startupProbe:
exec:
command:
- service
- ssh
- status
initialDelaySeconds: 5
periodSeconds: 5
hostname: kind-worker3
nodeSelector:
kubernetes.io/hostname: kind-worker3
restartPolicy: Never
subdomain: workflow1
tolerations:
- effect: NoSchedule
key: cray.nnf.node
operator: Equal
value: "true"