diff --git a/services/maintenance/node-ops/node-nofile-daemonset.yaml b/services/maintenance/node-ops/node-nofile-daemonset.yaml index f259dbfc..f28d75e8 100644 --- a/services/maintenance/node-ops/node-nofile-daemonset.yaml +++ b/services/maintenance/node-ops/node-nofile-daemonset.yaml @@ -10,6 +10,9 @@ spec: app: node-nofile updateStrategy: type: RollingUpdate + rollingUpdate: + # Host settings persist while these setup-only helpers are replaced. + maxUnavailable: 25% template: metadata: labels: diff --git a/services/maintenance/node-ops/scripts/node_nofile.sh b/services/maintenance/node-ops/scripts/node_nofile.sh index dfeed339..000c960b 100644 --- a/services/maintenance/node-ops/scripts/node_nofile.sh +++ b/services/maintenance/node-ops/scripts/node_nofile.sh @@ -30,13 +30,9 @@ printf "524288" > /host/proc/sys/fs/inotify/max_user_watches printf "32768" > /host/proc/sys/fs/inotify/max_queued_events if [ "${changed}" -eq 1 ]; then - sleep "$(( (RANDOM % 300) + 10 ))" + # Load unit definitions now; activate new limits at a planned K3s restart. + # A setup-helper rollout must not restart the node's entire pod runtime. chroot /host /bin/systemctl daemon-reload - for unit in k3s k3s-agent; do - if [ -f "/host/etc/systemd/system/${unit}.service" ]; then - chroot /host /bin/systemctl restart "${unit}" - fi - done fi sleep infinity