Skip to content

fix: use sparkImage.pullPolicy in all containers - #764

Open
sweb wants to merge 3 commits into
mainfrom
fix/use-pull-policy
Open

fix: use sparkImage.pullPolicy in all containers#764
sweb wants to merge 3 commits into
mainfrom
fix/use-pull-policy

Conversation

@sweb

@sweb sweb commented Sep 3, 2026

Copy link
Copy Markdown
Member

Description

Solves #762

sparkImage.pullPolicy is no longer ignored by the driver and executor containers, the Spark Connect executors and the truststore and job init containers, and it now covers the user-supplied spec.image too.

This has a breaking component, because this now leads to the default pull policy of Always for driver and executor.

Definition of Done Checklist

  • Not all of these items are applicable to all PRs, the author should update this template to only leave the boxes in that are relevant
  • Please make sure all these things are done and tick the boxes

Author

  • Changes are OpenShift compatible
  • CRD changes approved
  • CRD documentation for all fields, following the style guide.
  • Helm chart can be installed and deployed operator works
  • Integration tests passed (for non trivial changes)
  • Changes need to be "offline" compatible
  • Links to generated (nightly) docs added
  • Release note snippet added

Reviewer

  • Code contains useful comments
  • Code contains useful logging statements
  • (Integration-)Test cases added
  • Documentation added or updated. Follows the style guide.
  • Changelog updated
  • Cargo.toml only contains references to git tags (not specific commits or branches)

Acceptance

  • Feature Tracker has been updated
  • Proper release label has been added
  • Links to generated (nightly) docs added
  • Release note snippet added
  • Add type/deprecation label & add to the deprecation schedule
  • Add type/experimental label & add to the experimental features tracker

@sweb
sweb force-pushed the fix/use-pull-policy branch 3 times, most recently from a7f8906 to fd3967e Compare September 3, 2026 13:04
@sweb sweb self-assigned this Sep 3, 2026
@sweb
sweb marked this pull request as ready for review September 3, 2026 13:08
@sweb sweb moved this to Development: Waiting for Review in Stackable Engineering Sep 3, 2026
@adwk67
adwk67 self-requested a review September 8, 2026 10:10
@adwk67 adwk67 moved this from Development: Waiting for Review to Development: In Review in Stackable Engineering Sep 8, 2026
@sweb
sweb force-pushed the fix/use-pull-policy branch from e7a1601 to fb03739 Compare September 8, 2026 10:38
<2> Apache Spark version bundled in your custom image.

`sparkImage.pullPolicy` governs every container that the operator selects an image for: the submit, driver and executor containers, the `job`, `requirements` and `tls` init containers, and the Spark Connect server and its executors.
This includes the user-supplied `spec.image`, which the `job` init container runs.

@adwk67 adwk67 Sep 8, 2026

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Is the history server excluded? If so, maybe make that clear here. Also Connect Server takes spec.image and not sparkImage (maybe that is implied but we could make it clearer).

Comment thread docs/modules/spark-k8s/pages/usage-guide/job-dependencies.adoc Outdated
Comment thread docs/modules/spark-k8s/pages/usage-guide/job-dependencies.adoc Outdated

#[test]
fn image_pull_policy_is_set_on_every_container_spark_does_not_rebuild() {
let validated = validated_cluster_with_s3_tls();

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nit: if we passed PULL_POLICY_NEVER to this function it would make it a bit clearer as to what the test is expecting.

Some(spark_image),
),
(
"spark.kubernetes.container.image.pullPolicy".to_string(),

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The executor properties are merged last, so a user override for this property will be silently overridden (the other properties added in this function are "internal"). This should go before user overrides are applied e.g. in server_properties?

.iter()
.flatten()
.chain(pod_spec.containers.iter())
.filter(|container| container.name != SparkConnectContainer::Spark.to_string())

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can we also assert the expected value for the excluded container, so that it checks/guards that the template container does not carry its own pull policy? (and so we can't change that silently in the future)

}

#[cfg(test)]
pub(crate) fn tls_connection() -> Self {

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This seems to duplicate the ConnectionSpec part of connection_fixture: maybe consolidate them (e.g. move connection_fixture to here and have tls_connection call it)?

<2> Apache Spark version bundled in your custom image.

`sparkImage.pullPolicy` governs every container that the operator selects an image for: the submit, driver and executor containers, the `job`, `requirements` and `tls` init containers, and the Spark Connect server and its executors.
This includes the user-supplied `spec.image`, which the `job` init container runs.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Maybe we should mention the corner case where sparkImage.pullPolicy is set to Never (e.g. the user knows it is pre-loaded) - in which case spec.image also has to be pre-loaded (as it uses the same pull policy). It is implied but might be good to make that clear.

Co-authored-by: Andrew Kenworthy <1712947+adwk67@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Development: In Review

Development

Successfully merging this pull request may close these issues.

2 participants