zededa:patch-envelopes
Differences
This shows you the differences between two versions of the page.
| Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
| zededa:patch-envelopes [2026/07/23 23:11] – mc | zededa:patch-envelopes [2026/07/23 23:24] (current) – mc | ||
|---|---|---|---|
| Line 14: | Line 14: | ||
| attach a patch envelope to the app instance and update //just// that data. Typical scenarios: | attach a patch envelope to the app instance and update //just// that data. Typical scenarios: | ||
| - | * Pushing | + | * Making |
| * Rotating credentials, | * Rotating credentials, | ||
| * Delivering site-specific or device-specific parameters to a generic image | * Delivering site-specific or device-specific parameters to a generic image | ||
| Line 23: | Line 23: | ||
| ===== What can the binary artifact be? ===== | ===== What can the binary artifact be? ===== | ||
| + | |||
| + | You attach one or more **binary artifacts** to a patch envelope and present them to the app | ||
| + | instance; the app then pulls them from the metadata service. So what can that artifact | ||
| + | actually be? | ||
| **Anything — it is an opaque blob to EVE.** EVE does not parse, validate, or execute the | **Anything — it is an opaque blob to EVE.** EVE does not parse, validate, or execute the | ||
| Line 31: | Line 35: | ||
| * certs, keys, a license file, a token | * certs, keys, a license file, a token | ||
| * a firmware image, a tarball / zip, a small dataset, a DB seed | * a firmware image, a tarball / zip, a small dataset, a DB seed | ||
| + | * a file with **any** extension ('' | ||
| * essentially any file you would otherwise have to bake into the image | * essentially any file you would otherwise have to bake into the image | ||
| Line 87: | Line 92: | ||
| > instance (the same '' | > instance (the same '' | ||
| > An app on a pure switch NI with no local-NI path will not see it. | > An app on a pure switch NI with no local-NI path will not see it. | ||
| + | |||
| + | ==== ⚠ Gotcha — reachability of 169.254.169.254 ==== | ||
| + | |||
| + | The metadata service **lives inside EVE** on the edge node — it is **not** exposed outside the | ||
| + | node. This has direct consequences for how the workload is networked: | ||
| + | |||
| + | * **Local-type NI can reach it; Switch-type cannot.** A **Local** network instance routes to '' | ||
| + | * **Multi-NIC default-route trap.** If a workload is attached to **two** network instances (e.g. one Local + one Switch, or two with default routes) and **both provide a default gateway**, the guest may pick the **Switch** interface as its default route — and then traffic to '' | ||
| + | * **Fix — configure it on the Local network instance, NOT inside the guest.** EVE hands routes to the app through the **Local NI configuration** (advertised to the attached app via the NI's DHCP), not via manual '' | ||
| + | prefix | ||
| + | gateway = "< | ||
| + | }</ | ||
| **How to detect changes without busy-polling: | **How to detect changes without busy-polling: | ||
zededa/patch-envelopes.1784848276.txt.gz · Last modified: by mc
