Skip to content

packages: add dranet - #1077

Open
maherthomsi wants to merge 1 commit into
bottlerocket-os:developfrom
maherthomsi:dranet
Open

maherthomsi wants to merge 1 commit into
bottlerocket-os:developfrom
maherthomsi:dranet

Conversation

@maherthomsi

@maherthomsi maherthomsi commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

Relies on bottlerocket-os/bottlerocket-settings-sdk#156

Description of changes:

Adds the dranet package, which builds the DRANET network device DRA driver (kubernetes-sigs/dranet, v1.5.0) and installs it as a host systemd service. The package joins the workspace and the kit manifest. Consuming variants can then include it.

The service is opt-in and gated on one setting. The unit carries ConditionFileNotEmpty=/etc/dranet/enabled. When settings.kubelet-dra-drivers.net.enabled is true, the marker renders run.

kubelet-dra-drivers.net.enabled marker dranet.service
true run running
false empty off
unset empty off
extension absent absent off

Two flags come from settings, and an empty value counts as unset for both, so each falls back to a safe value:

Setting Shipped default Empty value falls back to
net.bind-address 127.0.0.1:9177 127.0.0.1:9177
net.device-filter EFA devices only no --filter, so the driver's own default

When a bind address is blank, Go serves on port 80 of every interface. A blank filter disables filtering, which publishes the secondary ENIs that the Amazon VPC CNI creates and manages. A pod that claims one of those takes pod networking on the node with it. The shipped filter publishes EFA devices only, using the expression the AWS-supported aws-dranet Helm chart passes.

Testing done:

  • Built the kit and a variant for x86_64, then booted an AMI and ran the driver.
  • The node published 32 EFA devices and nothing else. No ENA interface and no CNI-managed ENI appeared, with the VPC CNI active on the node.
  • A pod claimed one EFA device, saw its RDMA device node, and fi_info -p efa reported the efa provider on the allocated device.
  • One pod claimed a GPU and an EFA device together, constrained to one resource.kubernetes.io/pcieRoot.
  • Off by default: a node booted with no DRA settings ran no service and published no slice.
  • Tested the enable and disable paths, a driver restart with live claims, and a node reboot with a live claim.
  • Tested ten claim and release cycles, allocation exclusivity at 32 devices, and a custom device-filter.
  • Tested the localhost metrics binding, and SELinux under enforcing mode with no AVC denial.
  • Not yet tested: aarch64

By submitting this pull request, I agree that this contribution is dual-licensed under the terms of both the Apache License, version 2.0, and the MIT license.

@maherthomsi maherthomsi changed the title Packages: add dranet packages: add dranet Oct 9, 2026
Add the dranet package, which builds the DRANET network device DRA
driver (kubernetes-sigs/dranet) and installs it as a host systemd
service and installs it as a host systemd service gated behind
settings.kubelet-dra-drivers.net.enabled.

Signed-off-by: Maher Homsi <maherhom@amazon.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant