Skip to content

KEP-4944: Kustomize Wasm Plugin #4946

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
wants to merge 5 commits into
base: master
Choose a base branch
from

Conversation

koba1t
Copy link
Member

@koba1t koba1t commented Nov 4, 2024

  • One-line PR description: Kustomize Wasm Plugin
  • Other comments:

@k8s-ci-robot
Copy link
Contributor

Skipping CI for Draft Pull Request.
If you want CI signal for your change, please convert it to an actual PR.
You can still manually trigger a test run with /test all

@k8s-ci-robot k8s-ci-robot added do-not-merge/work-in-progress Indicates that a PR should not merge because it is a work in progress. cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. labels Nov 4, 2024
@k8s-ci-robot k8s-ci-robot added kind/kep Categorizes KEP tracking issues and PRs modifying the KEP directory sig/cli Categorizes an issue or PR as relevant to SIG CLI. size/XL Denotes a PR that changes 500-999 lines, ignoring generated files. labels Nov 4, 2024
@koba1t koba1t mentioned this pull request Nov 4, 2024
4 tasks
@koba1t koba1t force-pushed the kep/kustomize_add_wasm_plugin branch 4 times, most recently from 936ebc5 to 82b898a Compare November 12, 2024 01:08
@koba1t koba1t force-pushed the kep/kustomize_add_wasm_plugin branch from 82b898a to fb77246 Compare November 12, 2024 01:13
@koba1t koba1t marked this pull request as ready for review December 11, 2024 16:24
@k8s-ci-robot k8s-ci-robot removed the do-not-merge/work-in-progress Indicates that a PR should not merge because it is a work in progress. label Dec 11, 2024
@k8s-triage-robot
Copy link

The Kubernetes project currently lacks enough contributors to adequately respond to all PRs.

This bot triages PRs according to the following rules:

  • After 90d of inactivity, lifecycle/stale is applied
  • After 30d of inactivity since lifecycle/stale was applied, lifecycle/rotten is applied
  • After 30d of inactivity since lifecycle/rotten was applied, the PR is closed

You can:

  • Mark this PR as fresh with /remove-lifecycle stale
  • Close this PR with /close
  • Offer to help out with Issue Triage

Please send feedback to sig-contributor-experience at kubernetes/community.

/lifecycle stale

@k8s-ci-robot k8s-ci-robot added the lifecycle/stale Denotes an issue or PR has remained open with no activity and has become stale. label Mar 11, 2025
@k8s-triage-robot
Copy link

The Kubernetes project currently lacks enough active contributors to adequately respond to all PRs.

This bot triages PRs according to the following rules:

  • After 90d of inactivity, lifecycle/stale is applied
  • After 30d of inactivity since lifecycle/stale was applied, lifecycle/rotten is applied
  • After 30d of inactivity since lifecycle/rotten was applied, the PR is closed

You can:

  • Mark this PR as fresh with /remove-lifecycle rotten
  • Close this PR with /close
  • Offer to help out with Issue Triage

Please send feedback to sig-contributor-experience at kubernetes/community.

/lifecycle rotten

@k8s-ci-robot k8s-ci-robot added lifecycle/rotten Denotes an issue or PR that has aged beyond stale and will be auto-closed. and removed lifecycle/stale Denotes an issue or PR has remained open with no activity and has become stale. labels Apr 10, 2025
@k8s-triage-robot
Copy link

The Kubernetes project currently lacks enough active contributors to adequately respond to all issues and PRs.

This bot triages PRs according to the following rules:

  • After 90d of inactivity, lifecycle/stale is applied
  • After 30d of inactivity since lifecycle/stale was applied, lifecycle/rotten is applied
  • After 30d of inactivity since lifecycle/rotten was applied, the PR is closed

You can:

  • Reopen this PR with /reopen
  • Mark this PR as fresh with /remove-lifecycle rotten
  • Offer to help out with Issue Triage

Please send feedback to sig-contributor-experience at kubernetes/community.

/close

@k8s-ci-robot
Copy link
Contributor

@k8s-triage-robot: Closed this PR.

In response to this:

The Kubernetes project currently lacks enough active contributors to adequately respond to all issues and PRs.

This bot triages PRs according to the following rules:

  • After 90d of inactivity, lifecycle/stale is applied
  • After 30d of inactivity since lifecycle/stale was applied, lifecycle/rotten is applied
  • After 30d of inactivity since lifecycle/rotten was applied, the PR is closed

You can:

  • Reopen this PR with /reopen
  • Mark this PR as fresh with /remove-lifecycle rotten
  • Offer to help out with Issue Triage

Please send feedback to sig-contributor-experience at kubernetes/community.

/close

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@github-project-automation github-project-automation bot moved this from Needs Triage to Closed in SIG CLI May 10, 2025
@koba1t
Copy link
Member Author

koba1t commented May 11, 2025

/reopen

@k8s-ci-robot k8s-ci-robot reopened this May 11, 2025
@k8s-ci-robot
Copy link
Contributor

@koba1t: Reopened this PR.

In response to this:

/reopen

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@github-project-automation github-project-automation bot moved this from Closed to In Progress in SIG CLI May 11, 2025
@k8s-ci-robot
Copy link
Contributor

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by: koba1t
Once this PR has been reviewed and has the lgtm label, please assign ardaguclu for approval. For more information see the Code Review Process.

The full list of commands accepted by this bot can be found here.

Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@k8s-triage-robot
Copy link

The Kubernetes project currently lacks enough active contributors to adequately respond to all issues and PRs.

This bot triages PRs according to the following rules:

  • After 90d of inactivity, lifecycle/stale is applied
  • After 30d of inactivity since lifecycle/stale was applied, lifecycle/rotten is applied
  • After 30d of inactivity since lifecycle/rotten was applied, the PR is closed

You can:

  • Reopen this PR with /reopen
  • Mark this PR as fresh with /remove-lifecycle rotten
  • Offer to help out with Issue Triage

Please send feedback to sig-contributor-experience at kubernetes/community.

/close

@k8s-ci-robot
Copy link
Contributor

@k8s-triage-robot: Closed this PR.

In response to this:

The Kubernetes project currently lacks enough active contributors to adequately respond to all issues and PRs.

This bot triages PRs according to the following rules:

  • After 90d of inactivity, lifecycle/stale is applied
  • After 30d of inactivity since lifecycle/stale was applied, lifecycle/rotten is applied
  • After 30d of inactivity since lifecycle/rotten was applied, the PR is closed

You can:

  • Reopen this PR with /reopen
  • Mark this PR as fresh with /remove-lifecycle rotten
  • Offer to help out with Issue Triage

Please send feedback to sig-contributor-experience at kubernetes/community.

/close

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@github-project-automation github-project-automation bot moved this from In Progress to Closed in SIG CLI Jun 10, 2025
@koba1t
Copy link
Member Author

koba1t commented Jun 16, 2025

/reopen

@k8s-ci-robot k8s-ci-robot reopened this Jun 16, 2025
@k8s-ci-robot
Copy link
Contributor

@koba1t: Reopened this PR.

In response to this:

/reopen

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@github-project-automation github-project-automation bot moved this from Closed to In Progress in SIG CLI Jun 16, 2025
@soltysh soltysh mentioned this pull request Jun 26, 2025
4 tasks
isolation.

And promote kustomize KRM plugins to GA with the addition and stability of Wasm
KRM Function.
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

There's #2953 which was targetting krm graduation. I think, it's best to split the graduation from wasm plugins.

The one question I have is how you're planning to handle the relationship between wasm plugins and krm plugins? Wasm will be alpha and KRM GA?

1. The Wasm OCI Artifact specification is a relatively new standard in the OCI
ecosystem. Maybe not mature enough.
1. Containaized KRM function is alpha feature but that used some user.
- Provide container to exec conversion tools.
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Not sure I understand how this is a risk. I believe you've mentioned earlier (and I also suggested to split this out) to promote KRM functions to GA, so the only risk is that we haven't done it yet and we have users relying on it, right?

image: ghcr.io/koba1t/krm-fn-app:v0.0.3-wasm
spec:
port: 8080
```
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'm not sure I follow, what the above files are meant for.

implementing this enhancement to ensure the enhancements have also solid foundations.
-->

##### Unit tests
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

For kustomize, I'm certain we can just skip interrogation and e2e tests, but listing units would be reasonable.
Something like:

- sigs.k8s.io/kustomize/kustomize/v5/commands/build	- 2025-06-01 - 79.4
- sigs.k8s.io/kustomize/kustomize/v5/commands/create - 2025-06-26 - 84.9
etc...

Just make sure to list only the directories you'll be modifying as part of this functionality. There's no need to list all of them 😉


Below are some examples to consider, in addition to the aforementioned [maturity levels][maturity-levels].

#### Alpha
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Clear graduation criteria will be needed. In the risks section you've mentioned that WASI is still not fully stable, is there a plan when it will be? Should we block GA promotion of this functionality until it does?

stable: TBD
# # The following PRR answers are required at alpha release
# # List the feature gate name and the components for which it must be enabled
# feature-gates:
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Are you planning on gating the access to this functionality through an environment variable, like we do with kubectl or in any other way?

1. Implement Wasm plugin support in the Kustomize KRM framework
1. Provide a secure sandboxed environment for executing custom transformations
1. Improve portability of custom transformers across different platforms
1. Enhance performance of resource transformations through WebAssembly
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nowhere in this document there's a clear information how this new mechanism will affect the kustomize version that is available in kubectl? IIRC the KRM functions are NOT available in kubectl, so I believe this one is also not going to be available, is that right assumption?

Copy link
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Honesty, Exec KRM functions is disabled by kubectl, but the Container KRM functions is available for kustomize in kubectl now.
(We can use with kubectl kustomize --enable-alpha-plugins ...)
kubernetes-sigs/kustomize#4556 (comment)

According to my understanding, the Exec KRM functions mechanism, which directly executes binaries, raises security concerns and was disabled in kubectl. With the Wasm Plugin, since the execution environment is sandboxed, I thought it seemed reasonable to make it available in the same way as current Container functions.

@k8s-ci-robot
Copy link
Contributor

@koba1t: The following tests failed, say /retest to rerun all failed tests or /retest-required to rerun all mandatory failed tests:

Test name Commit Details Required Rerun command
pull-enhancements-test 662e1a8 link true /test pull-enhancements-test
pull-enhancements-verify 662e1a8 link true /test pull-enhancements-verify

Full PR test history. Your PR dashboard. Please help us cut down on flakes by linking to an open issue when you hit one in your PR.

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. kind/kep Categorizes KEP tracking issues and PRs modifying the KEP directory lifecycle/rotten Denotes an issue or PR that has aged beyond stale and will be auto-closed. sig/cli Categorizes an issue or PR as relevant to SIG CLI. size/XL Denotes a PR that changes 500-999 lines, ignoring generated files.
Projects
Status: In Progress
Development

Successfully merging this pull request may close these issues.

4 participants