# Copyright 2026 Zyvor
# SPDX-License-Identifier: Apache-2.0
#
# One instance per fluxvm-capable node, matching the "node-local
# daemonset" model crates/fluxvm-kube/src/crd.rs and controller.rs are
# written for. Requires:
#   - the node labeled `ragnarok.io/fluxvm-capable: "true"` (KVM-capable,
#     QEMU/CH/Firecracker tooling reachable, `nbd` kernel module loaded —
#     the last one is a host prerequisite this DaemonSet cannot satisfy
#     itself; see README.md)
#   - crd.yaml and rbac.yaml applied first
#   - VM images pre-staged under the state_dir hostPath below (no
#     k8s-native image pull path exists yet — see README.md)
apiVersion: apps/v1
kind: DaemonSet
metadata:
  name: fluxvm-kube
  namespace: fluxvm-system
  labels:
    app: fluxvm-kube
spec:
  selector:
    matchLabels:
      app: fluxvm-kube
  template:
    metadata:
      labels:
        app: fluxvm-kube
    spec:
      serviceAccountName: fluxvm-kube
      nodeSelector:
        ragnarok.io/fluxvm-capable: "true"
      # TAP/bridge devices and the per-VM-netns dnsmasq DHCP server are
      # host-network-namespace objects in FluxVM's design (see
      # fluxvm_network::netns and NetworkSpec::Tap) — the `fluxvm`
      # container needs the pod in the host's network namespace for that to
      # mean anything, the same way fluxvm.service runs directly on the
      # host rather than in a container's isolated netns. Not a hardening
      # relaxation to revisit later.
      hostNetwork: true
      dnsPolicy: ClusterFirstWithHostNet
      containers:
        - name: fluxctl
          image: ghcr.io/zyvorai/fluxvm:0.1.0
          command: ["fluxvm", "--config", "/etc/fluxvm.toml", "serve"]
          securityContext:
            capabilities:
              add: ["NET_ADMIN", "SYS_ADMIN", "SYS_RESOURCE", "NET_BIND_SERVICE", "NET_RAW"]
              drop: ["ALL"]
          volumeMounts:
            - name: kvm
              mountPath: /dev/kvm
            - name: netns
              mountPath: /run/netns
            - name: var-lib-fluxvm
              mountPath: /var/lib/fluxvm
            - name: run-fluxvm
              mountPath: /run/fluxvm
            - name: bpffs
              mountPath: /sys/fs/bpf
            - name: cilium-run
              mountPath: /var/run/cilium
              readOnly: true
            - name: config
              mountPath: /etc/fluxvm.toml
              subPath: fluxvm.toml
          readinessProbe:
            httpGet:
              path: /readyz
              port: 7788
            initialDelaySeconds: 3
            periodSeconds: 10
          livenessProbe:
            httpGet:
              path: /healthz
              port: 7788
            initialDelaySeconds: 10
            periodSeconds: 20
        - name: fluxvm-kube
          image: ghcr.io/zyvorai/fluxvm:0.1.0
          command: ["fluxvm-kube"]
          env:
            # Must be the real Kubernetes node name — this is what a
            # DisposableVm's spec.node has to equal for this instance to
            # pick it up (see crd.rs's doc comment on `node`).
            - name: NODE_NAME
              valueFrom:
                fieldRef:
                  fieldPath: spec.nodeName
            - name: FLUXVM_URL
              value: "http://127.0.0.1:7788"
          securityContext:
            runAsNonRoot: true
            runAsUser: 65532
            allowPrivilegeEscalation: false
            readOnlyRootFilesystem: true
            capabilities:
              drop: ["ALL"]
      volumes:
        - name: kvm
          hostPath:
            path: /dev/kvm
            type: CharDevice
        - name: netns
          hostPath:
            path: /run/netns
            type: DirectoryOrCreate
        - name: var-lib-fluxvm
          hostPath:
            path: /var/lib/fluxvm
            type: DirectoryOrCreate
        - name: run-fluxvm
          hostPath:
            path: /run/fluxvm
            type: DirectoryOrCreate
        - name: bpffs
          hostPath:
            path: /sys/fs/bpf
            type: Directory
        - name: cilium-run
          hostPath:
            path: /var/run/cilium
            type: DirectoryOrCreate
        - name: config
          configMap:
            name: fluxvm-config
