Skip to content

k8s: extension volumeMounts leak onto all containers (shared CONTAINER_VOLUMES array) #442

Description

@ohookins

What happens

A volumeMounts entry added to any $-prefixed container in the hook extension template (ACTIONS_RUNNER_CONTAINER_HOOK_TEMPLATE) ends up on every container in the job pod, not just the one it was declared under. Same goes for a mount declared on $job leaking into the service containers.

This bit us when we needed to mount a shared volume into two containers at different paths — mounting it at the natural path in one container shadowed files that container needs, so we wanted it there only for the other container. The leak makes that impossible: the mount lands on every container.

Why

CONTAINER_VOLUMES is a module-level array, and every container gets that same array assigned by reference:

podContainer.volumeMounts = CONTAINER_VOLUMES

Then mergeContainerWithOptions appends the extension's mounts with mergeLists, which mutates base in place:

base.volumeMounts = mergeLists(base.volumeMounts, volumeMounts)

So the first container's merge pushes onto the shared array, and every later container starts from that already-polluted array. Net result: union of all containers' mounts on all containers.

Repro

Template:

spec:
  containers:
    - name: $job
      volumeMounts:
        - name: shared
          mountPath: /a
    - name: $mysvc
      volumeMounts:
        - name: shared
          mountPath: /b
  volumes:
    - name: shared
      emptyDir: {}

Both /a and /b show up in the job container and the service container.

Fix

Give each container its own copy, e.g. at prepare-job.ts#L287:

podContainer.volumeMounts = [...CONTAINER_VOLUMES]

(Env and ports go through the same mergeLists path but happen to start from per-container arrays, so this is the only one affected.)

Related

Seen on the kubernetes-novolume hook shipped in actions-runner:2.336.0; code above is current main.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions