Function Configuration
Configure KRM function execution with FunctionConfig resources
The Function Runner executes cached KRM function binaries over gRPC. Pod runtime flags moved to Porch Server with the pod evaluator.
KPT functions and KRM functions are synonymous terms referring to the same containerized functions.
Binary vs pod selection and most per-function settings come from
FunctionConfig resources, not from a static config file.
The Engine looks up a cached binary in its FunctionConfig store and sends exec_path on the gRPC request.
Function Runner executes that binary and returns NotFoundError when exec_path is empty so the Engine can fall through to the in-process pod evaluator.
Go execution is declared on the same CRD but runs in porch-server and porch-controllers, not in this process.
args:
- --port=9445 # Server port (default: 9445)
- --disable-runtimes=exec # Disable the exec runtime (the only runtime in this binary)
- --log-level=2 # Log verbosity level 0-5 (default: 2)
- --default-image-prefix=ghcr.io/kptdev/krm-functions-catalog # Prefix for unqualified function names
args:
- --functions=./functions # Directory of cached function binaries (default: ./functions)
Binary-to-image mappings come from FunctionConfig binaryExecutor entries.
--functions is the directory used when spec.binaryExecutor.path is relative.
The Engine may also send exec_path on the gRPC request. Function Runner does not read a --config image-to-binary mapping file.
These flags now belong to porch-server. See Porch Server. They moved with the pod evaluator:
args:
- --warm-up-pod-cache=true # Pre-create pods for FunctionConfig podExecutor images (default: true)
- --pod-namespace=porch-fn-system # Namespace for KRM function pods (default: porch-fn-system)
- --pod-ttl=30m # Default pod TTL before GC (default: 30m)
- --scan-interval=1m # GC scan interval (default: 1m)
- --max-request-body-size=6291456 # Max gRPC message size in bytes (default: 6MB)
- --max-waitlist-length=2 # Default waitlist length per pod (default: 2)
- --max-parallel-pods-per-function=1 # Default max pods per function (default: 1)
- --max-grpc-retries=2 # Retries on gRPC Unavailable (default: 2)
--pod-ttl, --max-waitlist-length, and --max-parallel-pods-per-function are fallbacks used when the matching FunctionConfig does not set timeToLive, preferredMaxQueueLength, or maxParallelExecutions.
These flags now belong to porch-server. See Private Registries.
args:
- --enable-private-registries=false # Enable private registry support
- --registry-auth-secret-path=/var/tmp/config-secret/.dockerconfigjson # Registry auth secret path
- --registry-auth-secret-name=auth-secret # Registry auth secret name
- --enable-private-registries-tls=false # Enable TLS for private registries
- --tls-secret-path=/var/tmp/tls-secret/ # TLS secret path
WRAPPER_SERVER_IMAGE is required on porch-server. The PackageRevision controller uses porch-server’s FunctionEvaluator gRPC (POD_EVALUATOR_ADDRESS); do not start a second in-process evaluator on controllers.
env:
- name: WRAPPER_SERVER_IMAGE
value: "<wrapper-server-image>" # Required for the Engine pod evaluator
Per-function executor choice, tags, binary paths, Go ids, pod TTL, and template overrides are declared on FunctionConfig objects in porch-fn-system.
The function-runner runs an embedded reconciler that watches those objects and updates its in-memory binary store without a process restart.
The Engine pod evaluator builds function pods from the base-pod-template PodTemplate and base-service-template ServiceTemplate in the pod namespace, then applies spec.podExecutor.templateOverrides.
There is no --function-pod-template flag and no ConfigMap template.
See Function Configuration and Pod Templates.
The exec runtime runs functions as local binaries listed on a FunctionConfig binaryExecutor.
--functions is only the directory that relative path values are resolved against.
args:
- --functions=/home/nonroot/functions # Directory containing cached function executables
The Engine supplies exec_path; Function Runner does not use --config.
The pod runtime runs in the Engine (porch-server). See Porch Server.
To disable the exec runtime:
args:
- --disable-runtimes=exec # Disable exec runtime
--disable-runtimes=pod is not valid; the pod evaluator is not in this binary.
resources:
requests:
memory: "512Mi"
cpu: "200m"
limits:
memory: "1Gi"
cpu: "1000m"
livenessProbe:
grpc:
port: 9445
initialDelaySeconds: 30
periodSeconds: 10
readinessProbe:
grpc:
port: 9445
initialDelaySeconds: 5
periodSeconds: 5
Complete Function Runner deployment configuration:
apiVersion: apps/v1
kind: Deployment
metadata:
name: function-runner
namespace: porch-system
spec:
replicas: 1
selector:
matchLabels:
app: function-runner
template:
metadata:
labels:
app: function-runner
spec:
containers:
- name: function-runner
image: function-runner:latest
args:
- --port=9445
- --log-level=2
- --functions=/home/nonroot/functions
- --max-request-body-size=6291456
ports:
- containerPort: 9445
protocol: TCP
resources:
requests:
memory: "512Mi"
cpu: "200m"
limits:
memory: "1Gi"
cpu: "1000m"
livenessProbe:
grpc:
port: 9445
initialDelaySeconds: 30
periodSeconds: 10
readinessProbe:
grpc:
port: 9445
initialDelaySeconds: 5
periodSeconds: 5
For advanced configuration options:
Configure KRM function execution with FunctionConfig resources