How to patch pod's container spec to start container with my version of exec, via kubernetes admission controller?

Viewed 139

I am writing an admission controller, which is responsible for starting all the containers with my version of exec say myexec.

I know, I can modify command in pod's container spec, to prefix with myexec.

But I am stuck in the case when there is no command in pod's container spec. In those cases, as per my understanding, I have to find which the entrypoint command/script of the image that container is going to load. And I need to set command as myexec entrypoint.sh.

That seems tricky and expensive since I have to inspect the image, find entrypoint, all inside the admission controller.

What i want to mention is that kubernetes already pulling image (in case if image was already pulled in previously or loaded explicitly beforehand in clusters) and having manifest on their nodes, it might be sending those entrypoint information as container config, but i am not aware how to capture those during admission.

So I am seeking some hint, trick or way that I am not aware of to achieve my goal.

PS: I can't change image configuration.

1 Answers

There is this project skopeo that allows you to query any container registy for metadata like e.g. entrypoint and command.

You can use skopeo cmd tool to test it.

Follow this install instructions to install it.

Now try the following:

$ skopeo inspect --config  docker://nginx:latest

What you probably saw is a lot of output. We don't need most of it for our usecase. What we are interested in is under .config. I used jq to query it. Have a look:

$ skopeo inspect --config  docker://nginx:latest | jq ".config"
{
  "ExposedPorts": {
    "80/tcp": {}
  },
  "Env": [
    "PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin",
    "NGINX_VERSION=1.19.5",
    "NJS_VERSION=0.4.4",
    "PKG_RELEASE=1~buster"
  ],
  "Entrypoint": [
    "/docker-entrypoint.sh"
  ],
  "Cmd": [
    "nginx",
    "-g",
    "daemon off;"
  ],
  "Labels": {
    "maintainer": "NGINX Docker Maintainers <docker-maint@nginx.com>"
  },
  "StopSignal": "SIGQUIT"
}

Notice the fields: Entrypoint and Cmd. I belive this is what you are looking for. And all of it is done without pulling any images. How cool is that?

You could probably take the source code (it's under apache licence so feel free to modify it), make rest service out of it and have admission controller to query it for the information about endpoints/cmds.

Related