How to use Google Cloud Kubernetes Jobs with Google Auth Credentials

Viewed 34

I have been able to create jobs inside Google Cloud Kubernetes containers that run on clusters.

The C++ application that we use inside Kubernetes Job is supposed to mount a Google Cloud Storage Bucket. So we need to somehow use Google Cloud Auth credentials inside within the job.

Here below is the code we execute in our Django/Python App to create a job

    body = client.V1Job(api_version="batch/v1", kind="Job")
    body.metadata = client.V1ObjectMeta(namespace=namespace, name=name)
    body.status = client.V1JobStatus()
    template = client.V1PodTemplate()
    template.template = client.V1PodTemplateSpec()
    env_list = []
    for env_name, env_value in env_vars.items():
        env_list.append( client.V1EnvVar(name=env_name, value=env_value) )
    security = client.V1SecurityContext(privileged=True, allow_privilege_escalation=True, capabilities= client.V1Capabilities(add=["CAP_SYS_ADMIN"]))
    container = client.V1Container(name=container_name, command=["xvfb-run"], args=["-a", "\"/app/bin/Renderer\"", ">", "/app/bin/renderer.logs", "2"], image=container_image, env=env_list, security_context=security)
    # container = client.V1Container(name=container_name, command=["/usr/bin/sleep"], args=["1000"], image=container_image, env=env_list, security_context=security)
    template.template.spec = client.V1PodSpec(containers=[container], restart_policy='Never')
    body.spec = client.V1JobSpec(backoff_limit=0, ttl_seconds_after_finished=600, template=template.template)

When I login to the pod and check if the binary has been executed inside the Job, I can see that it is created but consumes zero memory and cpu power :

$  gcloud container clusters get-credentials cluster-1 --region us-central1 --project videoo2  && kubectl exec frz95ifyr6tr-k5kk8 -c jobcontainer -- ps aux
Fetching cluster endpoint and auth data.
kubeconfig entry generated for cluster-1.
USER         PID %CPU %MEM    VSZ   RSS TTY      STAT START   TIME COMMAND
root           1  0.0  0.0   2892  1800 ?        Ss   07:51   0:00 /bin/sh /usr/bin/xvfb-run -a "/app/bin/Renderer" > /app/bin/renderer.logs 2
root          17  0.0  1.6 196204 67660 ?        S    07:51   0:00 Xvfb :99 -screen 0 1280x1024x24 -nolisten tcp -auth /tmp/xvfb-run.qY412C/Xauthority
root         105  0.0  0.0   7020  1528 ?        Rs   07:55   0:00 ps aux

I can also mount a Google Storage Bucket via kubectl command on Google Cloud Dashboard :

gcloud container clusters get-credentials cluster-1 --region us-central1 --project videoo2  && kubectl exec frz95ifyr6tr-k5kk8 -c jobcontainer -- gcsfuse  BUCKETNAME /media
Fetching cluster endpoint and auth data.
kubeconfig entry generated for cluster-1.
2022/08/16 07:56:38.379228 Start gcsfuse/0.41.5 (Go version go1.18.4) for app "" using mount point: /media
2022/08/16 07:56:38.424381 Opening GCS connection...
2022/08/16 07:56:39.135988 Mounting file system "BUCKETNAME"...
2022/08/16 07:56:39.136678 File system has been successfully mounted.

I can see that sleep executes successfully as well on a different execution experiment :

enter image description here

However, my C++ application just seems to somehow hangs after execution. It feels like it lacks the privileges and auth info to mount a bucket.

How can I add auth information to the python code to use inside the Job execution.

0 Answers
Related