Configure automatic sidecar injection for Agent Sandbox
Configure the spec.runtimes field in your Sandbox resource to automatically inject CSI storage mount and AgentRuntime sidecar configurations, eliminating manual YAML setup.
Prerequisites
-
An Agent Sandbox environment is created. Create an Agent Sandbox.
-
In the Add-ons section of your cluster, ensure that the
ack-agent-sandbox-controlleradd-on is version v0.5.12 or later.When the add-on is installed, a ConfigMap named
sandbox-injection-configis automatically created in thesandbox-systemnamespace. This ConfigMap contains two configurations:agent-runtimeandcsi.Before customizing this configuration, contact Alibaba Cloud technical support to validate your changes.
Overview
Manually configuring CSI and sidecar containers for dynamic storage mounts requires complex YAML. With automatic sidecar injection, you declare the spec.runtimes field in your SandboxSet or Sandbox resource, and the system injects the required configurations into new Sandbox instances. Two injection types are supported:
-
csi: Injects init container and volume configurations for CSI storage mounts, enabling shared storage such as NAS or OSS.To enable dynamic storage mounting, you must allow privileged containers and access to the hostPath (
/var/run/csi). You can submit a ticket to have the security restrictions lifted. However, you must assume responsibility for the associated security risks. For more information about this mechanism, see the shared responsibility model. -
agent-runtime: Injects an AgentRuntime init container (such as envd) and adds required environment variables and lifecycle hooks to the business container.
Injecting agent-runtime is required for the Command and Filesystem interfaces. Automatic sidecar injection applies only to newly created Sandbox instances.
Configure sidecar injection
Declare the runtime types in the spec.runtimes field of a SandboxSet or Sandbox resource.
Example SandboxSet resource configuration
apiVersion: agents.kruise.io/v1alpha1
kind: SandboxSet
metadata:
name: code-interpreter-inject-test
namespace: default
spec:
runtimes:
- name: csi # Enables CSI mount capabilities. New Sandbox instances are injected with the corresponding sidecar configuration.
- name: agent-runtime # Injects environment management tools such as envd.
replicas: 4
template:
metadata:
labels:
alibabacloud.com/acs: "true"
alibabacloud.com/compute-class: agent-sandbox # Agent Sandbox instance type.
alibabacloud.com/compute-qos: default # Compute QoS: default/best-effort.
spec:
automountServiceAccountToken: false
containers:
- image: registry-cn-zhangjiakou-vpc.ack.aliyuncs.com/acs/code-interpreter:v1.6 # Replace this with the region of your cluster.
imagePullPolicy: IfNotPresent
name: sandbox
resources:
limits:
cpu: "1"
memory: 1Gi
requests:
cpu: "1"
memory: 1Gi
terminationGracePeriodSeconds: 30
Example Sandbox resource configuration
apiVersion: agents.kruise.io/v1alpha1
kind: Sandbox
metadata:
name: code-interpreter-inject-test-xxx
namespace: default
spec:
runtimes:
- name: csi # Provides CSI mount capabilities.
- name: agent-runtime # Injects environment management tools such as envd.
...
Injection configuration
The following default injection configurations apply to v0.5.12 and later. You typically do not need to modify them. The <region-id> placeholder in image addresses is automatically replaced with your cluster's region ID, such as cn-zhangjiakou.
Each configuration item includes the following fields:
|
Field |
Description |
|
|
Configurations injected into the main container: environment variables ( |
|
|
Sidecar containers that inject CSI plugins or AgentRuntime init containers. Format: array of |
|
|
Volume configurations injected at the Pod level. Format: array of |