Function Runner Design
Evaluator patterns and architectural decisions.
The Function Runner is a standalone gRPC service that executes KRM (Kubernetes Resource Model) functions in isolated environments. It provides the runtime infrastructure for executing user-defined functions that mutate, validate, and generate Kubernetes configuration resources.
The Function Runner is responsible for:
exec_path supplied by the Engine. Arbitrary function images are evaluated by the pod evaluator in the Engine (porch-server and the PackageRevision controller).The Function Runner sits as a separate service that the Task Handler (and the PackageRevision controller, when FUNCTION_RUNNER_ADDRESS is set) communicates with via gRPC. The pod evaluator, pod lifecycle, and image/registry boxes in this diagram now run inside the Engine; Function Runner itself hosts the gRPC server and the executable evaluator (exec_path).
┌─────────────────────────────────────────────────────────┐
│ Function Runner Service │
│ │
│ ┌──────────────────┐ ┌──────────────────┐ │
│ │ gRPC Server │ │ Evaluators │ │
│ │ │ ───> │ │ │
│ │ • FunctionEval │ │ • Pod Evaluator │ │
│ │ Service │ │ • Exec Evaluator│ │
│ │ • Health Check │ │ • Multi-Eval │ │
│ └────────┬─────────┘ └────────┬─────────┘ │
│ │ │ │
│ └────────┬────────────────┘ │
│ ↓ │
│ ┌──────────────────┐ ┌──────────────────┐ │
│ │ Pod Lifecycle │ │ Image & Registry│ │
│ │ Management │ │ Management │ │
│ │ │ │ │ │
│ │ • Pod Cache │ │ • Metadata Cache│ │
│ │ • Pod Manager │ │ • Auth & TLS │ │
│ │ • GC & TTL │ │ • Pull Secrets │ │
│ └────────┬─────────┘ └────────┬─────────┘ │
│ │ │ │
│ └────────┬────────────────┘ │
│ ↓ │
│ ┌──────────────────────┐ │
│ │ Kubernetes API │ │
│ │ & Registries │ │
│ └──────────────────────┘ │
└─────────────────────────────────────────────────────────┘
↑
│
gRPC Connection
│
↓
┌──────────────────────┐
│ Task Handler │
│ (in Porch) │
└──────────────────────┘
Key architectural responsibilities:
exec_path from the Engine. The Engine falls through to the in-process pod evaluator when no binary is cachedexec_path) and returning transformed resourcesThe Function Runner is instantiated as a separate deployment. Porch-server reaches it with --function-runner. The only runtime in this binary is exec (--disable-runtimes accepts exec).
Evaluator patterns and architectural decisions.
Overview of function runner functionality and detailed documentation pages.
How the function runner integrates with Porch and external systems.