Skip to content

fix(render): do not overwrite function docker network if set, start crossplane-container in same network#65

Open
nkzk wants to merge 13 commits into
crossplane:mainfrom
nkzk:fix-render-docker-network
Open

fix(render): do not overwrite function docker network if set, start crossplane-container in same network#65
nkzk wants to merge 13 commits into
crossplane:mainfrom
nkzk:fix-render-docker-network

Conversation

@nkzk

@nkzk nkzk commented Jun 3, 2026

Copy link
Copy Markdown
Contributor

Description of your changes

Closes #75

Fixes:

  • Do not overwrite the docker-network annotation in functions if it has already been set
  • If the docker-network annotation is passed to the FunctionAnnotations flag, run crossplane-container in it.

I have:

Need help with this checklist? See the cheat sheet.

@adamwg

adamwg commented Jun 3, 2026

Copy link
Copy Markdown
Member

Thanks for the PR, @nkzk! Would you mind creating an issue for this as well, for discoverability and tracking? I haven't reviewed in detail yet, but the described fixes sound reasonable.

@nkzk nkzk changed the title fix: render docker network fix(render): do not overwrite function docker network if set, start crossplane-container in same network Jun 4, 2026
@nkzk nkzk force-pushed the fix-render-docker-network branch 2 times, most recently from cad5894 to abb26bd Compare June 4, 2026 07:55
@nkzk

nkzk commented Jun 4, 2026

Copy link
Copy Markdown
Contributor Author

I see that there are already tests for passing function annotations to the engine. I had copilot help me create unit tests for injectNetworkAnnotations. Also ran flake check.

@nkzk

nkzk commented Jun 4, 2026

Copy link
Copy Markdown
Contributor Author

Hmm, i got it to work in a devcontainer with this fix, but the current implemention has some issues in CI. But i think this can be solved on the user-side.

One of our earliest approaches was to start up functions as service-containers before running multiple/different renders, and it worked because gitlab/github connects the job-container to the bridge-network used by service-containers.

But since crossplane render will start up crossplane in another temporary bridge network, it doesnt seem that this will continue to work. However, my theory is that the user can specify the docker-network in their CI-provider (gitlab/github), and then specify the the docker-network flag in the crossplane render command with the fix in this branch to solve this.

We have another workflow which uses rootless DinD/PinP, but kind of the same issue there.

I'll do some more testing soon.

But let me know if something i say sounds off :D

@nkzk

nkzk commented Jun 10, 2026

Copy link
Copy Markdown
Contributor Author

Think this PR is ready for review, i did some more testing in CI and did not completely figure it out yet, but i think its just an issue of configuring the docker-network in CI and setting that value as the function-docker-network flag in the render-command.

A quality of life improvement for us would be if we can spin up the crossplane container ourselves and make render use it. If we could configure the crossplane-containerthe same way as functions, with the development annotation to manage the container lifecycle ourselves, it would just simplify this alot for us.

But maybe its out of scope for this PR, i'm not sure whats the best way to implement this would be. But open to work on it if someone has some ideas.

@nkzk nkzk marked this pull request as ready for review June 10, 2026 11:13
@nkzk nkzk requested review from a team, jcogilvie and tampakrap as code owners June 10, 2026 11:13
@nkzk nkzk requested review from haarchri and removed request for a team June 10, 2026 11:13
@coderabbitai

coderabbitai Bot commented Jun 10, 2026

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Run ID: 866b7565-a610-4516-92c5-08ed0333ea33

📥 Commits

Reviewing files that changed from the base of the PR and between 5ecd13a and 2c2f39b.

📒 Files selected for processing (6)
  • cmd/crossplane/render/annotation.go
  • cmd/crossplane/render/engine.go
  • cmd/crossplane/render/engine_docker.go
  • cmd/crossplane/render/op/cmd.go
  • cmd/crossplane/render/render.go
  • cmd/crossplane/render/xr/cmd.go
🚧 Files skipped from review as they are similar to previous changes (6)
  • cmd/crossplane/render/annotation.go
  • cmd/crossplane/render/render.go
  • cmd/crossplane/render/xr/cmd.go
  • cmd/crossplane/render/engine.go
  • cmd/crossplane/render/op/cmd.go
  • cmd/crossplane/render/engine_docker.go

📝 Walkthrough

Walkthrough

This PR adds an optional CrossplaneDockerNetwork flag, threads it into the docker render engine, makes dockerRenderEngine.Setup skip temporary network creation when a network is preconfigured, preserves existing runtime network annotations, and provides an annotation parser used by render commands to derive or override the network.

Changes

Docker network preconfiguration support

Layer / File(s) Summary
Annotation parsing utility
cmd/crossplane/render/annotation.go
New Annotations map type and NewAnnotationsFromStrings function parse key=value strings from CLI or function metadata, skipping malformed entries.
Engine network configuration and conditional setup
cmd/crossplane/render/engine.go, cmd/crossplane/render/engine_docker.go
EngineFlags.CrossplaneDockerNetwork parameter threads through NewEngineFromFlags to dockerRenderEngine. dockerRenderEngine.Setup conditionally creates a temporary Docker network only when e.network is empty; when preconfigured, it returns a no-op cleanup.
Network annotation preservation during render
cmd/crossplane/render/render.go
injectNetworkAnnotation now checks for existing AnnotationKeyRuntimeDockerNetwork annotations before setting them, preserving caller-provided or preexisting network values.
Op and xr command annotation parsing and wiring
cmd/crossplane/render/op/cmd.go, cmd/crossplane/render/xr/cmd.go
Both commands parse function annotations during Run to extract preconfigured networks and apply them to EngineFlags.CrossplaneDockerNetwork, with optional CLI overrides via --function-annotations.

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

Possibly related issues

  • Issue #75 (linked): This PR directly addresses the bug where function Docker network annotations are overwritten and temporary networks are always created. The changes implement the capability for callers to preconfigure the network so the engine skips temporary network creation and preserves existing annotations.
🚥 Pre-merge checks | ✅ 5 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Title check ⚠️ Warning The title exceeds the 72-character limit at 104 characters and does not meet length requirements, though it is descriptive. Reduce title to under 72 characters while preserving the key message about not overwriting docker networks and container behavior.
✅ Passed checks (5 passed)
Check name Status Explanation
Description check ✅ Passed The description directly addresses the linked issue #75, explaining the bug fix for docker-network annotation handling.
Linked Issues check ✅ Passed Code changes fully implement the issue requirements: preventing docker-network annotation overwriting [render.go], supporting network configuration via flags [engine.go, op/cmd.go, xr/cmd.go], and enabling container network connectivity for devcontainer/CI workflows [engine_docker.go].
Out of Scope Changes check ✅ Passed All changes are directly scoped to fixing issue #75: annotation handling, network configuration flags, and engine setup logic remain focused on the docker-network functionality.
Breaking Changes ✅ Passed No breaking changes found. New CrossplaneDockerNetwork field is optional with safe empty-string default. Exports are purely additive. Behavior changes are backwards-compatible enhancements.
Feature Gate Requirement ✅ Passed PR is a bug fix (not an experimental feature), does not affect apis/**, and adds a standard CLI flag without experimental designation. No feature gate required.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@adamwg

adamwg commented Jun 10, 2026

Copy link
Copy Markdown
Member

A quality of life improvement for us would be if we can spin up the crossplane container ourselves and make render use it. If we could configure the crossplane-containerthe same way as functions, with the development annotation to manage the container lifecycle ourselves, it would just simplify this alot for us.

But maybe its out of scope for this PR, i'm not sure whats the best way to implement this would be. But open to work on it if someone has some ideas.

@nkzk Good thought - I can see how this would be useful. It's a little tricky, since the crossplane container in render doesn't actually run a server, it's just a one-off command (crossplane internal render ...).

For your use-case, would it be easier to download a crossplane binary and use the --crossplane-binary render flag? In that mode, the functions need to be accessible to the host (like with the old crossplane render), but there's no assumptions about inter-container networking.

@adamwg adamwg left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for filing an issue for this, and for the fix. A few comments inline, but the overall approach looks good to me.

Comment thread cmd/crossplane/render/engine_docker.go Outdated
Comment thread cmd/crossplane/render/engine.go Outdated
Comment thread cmd/crossplane/render/xr/cmd.go Outdated

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🧹 Nitpick comments (1)
cmd/crossplane/render/engine.go (1)

67-71: ⚡ Quick win

Update stale constructor docs after signature change.

Could you update this comment? On Line 69 it still mentions a network parameter, but NewEngineFromFlags now derives this from EngineFlags.CrossplaneDockerNetwork.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@cmd/crossplane/render/engine.go` around lines 67 - 71, Update the doc comment
for NewEngineFromFlags to remove the outdated reference to a `network parameter`
and instead state that the Docker network is derived from
EngineFlags.CrossplaneDockerNetwork; specifically edit the comment block above
the NewEngineFromFlags function to reflect that when no binary path is set it
returns a Docker engine using the resolved image reference and that the Docker
network is taken from EngineFlags.CrossplaneDockerNetwork (not supplied by the
caller).
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@cmd/crossplane/render/op/cmd.go`:
- Around line 170-185: The override parsing for
render.AnnotationKeyRuntimeDockerNetwork is nested inside the if
c.EngineFlags.CrossplaneDockerNetwork == "" block so the --function-annotations
override never applies when a network is already set; move the block that parses
c.FunctionAnnotations (using render.NewAnnotationsFromStrings and checking
render.AnnotationKeyRuntimeDockerNetwork) out of that conditional and always run
it so that when an annotation value exists you set
c.EngineFlags.CrossplaneDockerNetwork (and/or c.CrossplaneDockerNetwork if used
elsewhere) to that value, ensuring the function-annotations override takes
precedence.

---

Nitpick comments:
In `@cmd/crossplane/render/engine.go`:
- Around line 67-71: Update the doc comment for NewEngineFromFlags to remove the
outdated reference to a `network parameter` and instead state that the Docker
network is derived from EngineFlags.CrossplaneDockerNetwork; specifically edit
the comment block above the NewEngineFromFlags function to reflect that when no
binary path is set it returns a Docker engine using the resolved image reference
and that the Docker network is taken from EngineFlags.CrossplaneDockerNetwork
(not supplied by the caller).
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Run ID: 14a09b90-8615-4a74-831b-924cd8db6271

📥 Commits

Reviewing files that changed from the base of the PR and between 396a2d1 and a2deb33.

📒 Files selected for processing (6)
  • cmd/crossplane/render/annotation.go
  • cmd/crossplane/render/engine.go
  • cmd/crossplane/render/engine_docker.go
  • cmd/crossplane/render/op/cmd.go
  • cmd/crossplane/render/render.go
  • cmd/crossplane/render/xr/cmd.go
🚧 Files skipped from review as they are similar to previous changes (2)
  • cmd/crossplane/render/engine_docker.go
  • cmd/crossplane/render/render.go

Comment thread cmd/crossplane/render/op/cmd.go Outdated
@nkzk nkzk requested a review from adamwg June 12, 2026 06:59
nkzk added 8 commits June 15, 2026 16:29
Signed-off-by: Nikita Z <nkzk95@gmail.com>
…ntainer in it

Signed-off-by: Nikita Z <nkzk95@gmail.com>
Signed-off-by: Nikita Z <nkzk95@gmail.com>
Signed-off-by: Nikita Z <nkzk95@gmail.com>
Signed-off-by: Nikita Z <nkzk95@gmail.com>
Signed-off-by: Nikita Z <nkzk95@gmail.com>
…tions in comment

Signed-off-by: Nikita Z <nkzk95@gmail.com>
nkzk added 5 commits June 15, 2026 16:29
…lags

if empty, default to the first docker-network annotation in the provided functions. If provided, the docker-network annotation in the FunctionAnnotations cli flag takes presedence

Signed-off-by: Nikita Z <nkzk95@gmail.com>
…aneDockerNetwork

Signed-off-by: Nikita Z <nkzk95@gmail.com>
Signed-off-by: Nikita Z <nkzk95@gmail.com>
Signed-off-by: Nikita Z <nkzk95@gmail.com>
Signed-off-by: Nikita Z <nkzk95@gmail.com>
@nkzk nkzk force-pushed the fix-render-docker-network branch from 5ecd13a to 2c2f39b Compare June 15, 2026 14:29
@jcogilvie

Copy link
Copy Markdown
Collaborator

I like this change and I want to see it land, but you've checked off the PR checklist box about adding tests and I don't see any. Have I missed something?

@adamwg adamwg left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM. Per @jcogilvie's comment, this could probably use a bit of test coverage (may be easiest to factor out the network defaulting logic from both render commands and test it separately).

@nkzk

nkzk commented Jun 15, 2026

Copy link
Copy Markdown
Contributor Author

yeah my bad, had some tests but dissapeared in a revert+refactor. i can look into it tomorrow!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

bug(render/v2.3.0): function docker network is overwritten and crossplane container always start in temporary network

3 participants