Skip to content

fix(render): do not overwrite function docker network if set, start crossplane-container in same network#65

Open
nkzk wants to merge 13 commits into
crossplane:mainfrom
nkzk:fix-render-docker-network
Open

fix(render): do not overwrite function docker network if set, start crossplane-container in same network#65
nkzk wants to merge 13 commits into
crossplane:mainfrom
nkzk:fix-render-docker-network

Conversation

@nkzk

@nkzk nkzk commented Jun 3, 2026

Copy link
Copy Markdown
Contributor

Description of your changes

Closes #75

Fixes:

  • Do not overwrite the docker-network annotation in functions if it has already been set
  • If the docker-network annotation is passed to the FunctionAnnotations flag, run crossplane-container in it.

I have:

Need help with this checklist? See the cheat sheet.

@adamwg

adamwg commented Jun 3, 2026

Copy link
Copy Markdown
Member

Thanks for the PR, @nkzk! Would you mind creating an issue for this as well, for discoverability and tracking? I haven't reviewed in detail yet, but the described fixes sound reasonable.

@nkzk nkzk changed the title fix: render docker network fix(render): do not overwrite function docker network if set, start crossplane-container in same network Jun 4, 2026
@nkzk nkzk force-pushed the fix-render-docker-network branch 2 times, most recently from cad5894 to abb26bd Compare June 4, 2026 07:55
@nkzk

nkzk commented Jun 4, 2026

Copy link
Copy Markdown
Contributor Author

I see that there are already tests for passing function annotations to the engine. I had copilot help me create unit tests for injectNetworkAnnotations. Also ran flake check.

@nkzk

nkzk commented Jun 4, 2026

Copy link
Copy Markdown
Contributor Author

Hmm, i got it to work in a devcontainer with this fix, but the current implemention has some issues in CI. But i think this can be solved on the user-side.

One of our earliest approaches was to start up functions as service-containers before running multiple/different renders, and it worked because gitlab/github connects the job-container to the bridge-network used by service-containers.

But since crossplane render will start up crossplane in another temporary bridge network, it doesnt seem that this will continue to work. However, my theory is that the user can specify the docker-network in their CI-provider (gitlab/github), and then specify the the docker-network flag in the crossplane render command with the fix in this branch to solve this.

We have another workflow which uses rootless DinD/PinP, but kind of the same issue there.

I'll do some more testing soon.

But let me know if something i say sounds off :D

nkzk added 5 commits June 10, 2026 10:11
Signed-off-by: Nikita Z <nkzk95@gmail.com>
…ntainer in it

Signed-off-by: Nikita Z <nkzk95@gmail.com>
Signed-off-by: Nikita Z <nkzk95@gmail.com>
Signed-off-by: Nikita Z <nkzk95@gmail.com>
Signed-off-by: Nikita Z <nkzk95@gmail.com>
@nkzk nkzk force-pushed the fix-render-docker-network branch from 669f038 to 396a2d1 Compare June 10, 2026 08:14
@nkzk

nkzk commented Jun 10, 2026

Copy link
Copy Markdown
Contributor Author

Think this PR is ready for review, i did some more testing in CI and did not completely figure it out yet, but i think its just an issue of configuring the docker-network in CI and setting that value as the function-docker-network flag in the render-command.

A quality of life improvement for us would be if we can spin up the crossplane container ourselves and make render use it. If we could configure the crossplane-containerthe same way as functions, with the development annotation to manage the container lifecycle ourselves, it would just simplify this alot for us.

But maybe its out of scope for this PR, i'm not sure whats the best way to implement this would be. But open to work on it if someone has some ideas.

@nkzk nkzk marked this pull request as ready for review June 10, 2026 11:13
@nkzk nkzk requested review from a team, jcogilvie and tampakrap as code owners June 10, 2026 11:13
@nkzk nkzk requested review from haarchri and removed request for a team June 10, 2026 11:13
Signed-off-by: Nikita Z <nkzk95@gmail.com>
@coderabbitai

coderabbitai Bot commented Jun 10, 2026

Copy link
Copy Markdown

Review Change Stack

📝 Walkthrough

Walkthrough

This PR adds an optional CrossplaneDockerNetwork flag, threads it into the docker render engine, makes dockerRenderEngine.Setup skip temporary network creation when a network is preconfigured, preserves existing runtime network annotations, and provides an annotation parser used by render commands to derive or override the network.

Changes

Docker network preconfiguration support

Layer / File(s) Summary
Annotation parsing utility
cmd/crossplane/render/annotation.go
New Annotations map type and NewAnnotationsFromStrings function parse key=value strings from CLI or function metadata, skipping malformed entries.
Engine network configuration and conditional setup
cmd/crossplane/render/engine.go, cmd/crossplane/render/engine_docker.go
EngineFlags.CrossplaneDockerNetwork parameter threads through NewEngineFromFlags to dockerRenderEngine. dockerRenderEngine.Setup conditionally creates a temporary Docker network only when e.network is empty; when preconfigured, it returns a no-op cleanup.
Network annotation preservation during render
cmd/crossplane/render/render.go
injectNetworkAnnotation now checks for existing AnnotationKeyRuntimeDockerNetwork annotations before setting them, preserving caller-provided or preexisting network values.
Op and xr command annotation parsing and wiring
cmd/crossplane/render/op/cmd.go, cmd/crossplane/render/xr/cmd.go
Both commands parse function annotations during Run to extract preconfigured networks and apply them to EngineFlags.CrossplaneDockerNetwork, with optional CLI overrides via --function-annotations.

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

Possibly related issues

  • Issue #75 (linked): This PR directly addresses the bug where function Docker network annotations are overwritten and temporary networks are always created. The changes implement Option A: allowing callers to preconfigure the network so the engine skips temporary network creation and preserves existing annotations.
  • Issue #96: The changes implement idempotent/externally-configurable Docker-network behavior (preconfigured network skip, non-overwriting annotation, and flag), which aligns with objectives noted in this issue.

Suggested reviewers

  • tampakrap
  • jcogilvie

Thank you for the clear patch — happy to review further if you want alternative behaviors (e.g., explicit validation of provided network names) or additional tests.

🚥 Pre-merge checks | ✅ 5 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Title check ⚠️ Warning The title exceeds the 72-character limit (104 characters) but accurately describes the main changes: preventing docker network overwriting and enabling crossplane container to run in specified networks. Shorten the title to under 72 characters while maintaining clarity, for example: 'fix(render): preserve docker network annotation and use it for crossplane'
✅ Passed checks (5 passed)
Check name Status Explanation
Linked Issues check ✅ Passed The changes comprehensively address issue #75 requirements: preventing docker-network annotation overwriting [render.go, cmd.go], enabling docker-network configuration via CLI and annotations [engine.go, engine_docker.go, annotation.go], and supporting devcontainer/DinD workflows.
Out of Scope Changes check ✅ Passed All changes directly support the linked issue #75 objectives: new Annotations API [annotation.go] enables CLI parsing, engine enhancements support network selection [engine.go, engine_docker.go], and render logic preserves existing annotations [render.go].
Breaking Changes ✅ Passed Checked current cmd/crossplane/render sources: EngineFlags only adds CrossplaneDockerNetwork; no public flags/fields are removed/renamed, and behavior is changed to respect existing docker-network...
Feature Gate Requirement ✅ Passed PR adds CrossplaneDockerNetwork flag/logic for docker networking, but no experimental/maturity feature gate mechanism is introduced or applied; changes don’t touch apis/**.
Description check ✅ Passed The PR description clearly references issue #75 and outlines the two main fixes: preventing overwriting docker-network annotations and enabling crossplane-container to run in specified networks.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

…tions in comment

Signed-off-by: Nikita Z <nkzk95@gmail.com>
@adamwg

adamwg commented Jun 10, 2026

Copy link
Copy Markdown
Member

A quality of life improvement for us would be if we can spin up the crossplane container ourselves and make render use it. If we could configure the crossplane-containerthe same way as functions, with the development annotation to manage the container lifecycle ourselves, it would just simplify this alot for us.

But maybe its out of scope for this PR, i'm not sure whats the best way to implement this would be. But open to work on it if someone has some ideas.

@nkzk Good thought - I can see how this would be useful. It's a little tricky, since the crossplane container in render doesn't actually run a server, it's just a one-off command (crossplane internal render ...).

For your use-case, would it be easier to download a crossplane binary and use the --crossplane-binary render flag? In that mode, the functions need to be accessible to the host (like with the old crossplane render), but there's no assumptions about inter-container networking.

@adamwg adamwg left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for filing an issue for this, and for the fix. A few comments inline, but the overall approach looks good to me.

Comment thread cmd/crossplane/render/engine_docker.go Outdated
Comment thread cmd/crossplane/render/engine.go Outdated
Comment thread cmd/crossplane/render/xr/cmd.go Outdated
nkzk added 3 commits June 11, 2026 11:43
…lags

if empty, default to the first docker-network annotation in the provided functions. If provided, the docker-network annotation in the FunctionAnnotations cli flag takes presedence

Signed-off-by: Nikita Z <nkzk95@gmail.com>
…aneDockerNetwork

Signed-off-by: Nikita Z <nkzk95@gmail.com>
Signed-off-by: Nikita Z <nkzk95@gmail.com>

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🧹 Nitpick comments (1)
cmd/crossplane/render/engine.go (1)

67-71: ⚡ Quick win

Update stale constructor docs after signature change.

Could you update this comment? On Line 69 it still mentions a network parameter, but NewEngineFromFlags now derives this from EngineFlags.CrossplaneDockerNetwork.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@cmd/crossplane/render/engine.go` around lines 67 - 71, Update the doc comment
for NewEngineFromFlags to remove the outdated reference to a `network parameter`
and instead state that the Docker network is derived from
EngineFlags.CrossplaneDockerNetwork; specifically edit the comment block above
the NewEngineFromFlags function to reflect that when no binary path is set it
returns a Docker engine using the resolved image reference and that the Docker
network is taken from EngineFlags.CrossplaneDockerNetwork (not supplied by the
caller).
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@cmd/crossplane/render/op/cmd.go`:
- Around line 170-185: The override parsing for
render.AnnotationKeyRuntimeDockerNetwork is nested inside the if
c.EngineFlags.CrossplaneDockerNetwork == "" block so the --function-annotations
override never applies when a network is already set; move the block that parses
c.FunctionAnnotations (using render.NewAnnotationsFromStrings and checking
render.AnnotationKeyRuntimeDockerNetwork) out of that conditional and always run
it so that when an annotation value exists you set
c.EngineFlags.CrossplaneDockerNetwork (and/or c.CrossplaneDockerNetwork if used
elsewhere) to that value, ensuring the function-annotations override takes
precedence.

---

Nitpick comments:
In `@cmd/crossplane/render/engine.go`:
- Around line 67-71: Update the doc comment for NewEngineFromFlags to remove the
outdated reference to a `network parameter` and instead state that the Docker
network is derived from EngineFlags.CrossplaneDockerNetwork; specifically edit
the comment block above the NewEngineFromFlags function to reflect that when no
binary path is set it returns a Docker engine using the resolved image reference
and that the Docker network is taken from EngineFlags.CrossplaneDockerNetwork
(not supplied by the caller).
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Run ID: 14a09b90-8615-4a74-831b-924cd8db6271

📥 Commits

Reviewing files that changed from the base of the PR and between 396a2d1 and a2deb33.

📒 Files selected for processing (6)
  • cmd/crossplane/render/annotation.go
  • cmd/crossplane/render/engine.go
  • cmd/crossplane/render/engine_docker.go
  • cmd/crossplane/render/op/cmd.go
  • cmd/crossplane/render/render.go
  • cmd/crossplane/render/xr/cmd.go
🚧 Files skipped from review as they are similar to previous changes (2)
  • cmd/crossplane/render/engine_docker.go
  • cmd/crossplane/render/render.go

Comment thread cmd/crossplane/render/op/cmd.go Outdated
nkzk added 2 commits June 11, 2026 14:03
Signed-off-by: Nikita Z <nkzk95@gmail.com>
Signed-off-by: Nikita Z <nkzk95@gmail.com>
@nkzk nkzk requested a review from adamwg June 12, 2026 06:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

bug(render/v2.3.0): function docker network is overwritten and crossplane container always start in temporary network

2 participants