You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit c30d7b8
Browse filesBrowse the repository at this point in the historyBrowse files
@@ -4,17 +4,30 @@ description: Prepare an Azure Kubernetes Service cluster to run OpenHands Enterp
4
4
icon: /enterprise/images/azure-logo.svg
5
5
---
6
6
7
-
Prepare Azure Kubernetes Service (AKS) for OpenHands Enterprise, then follow the
8
-
[Helm installation](/enterprise/k8s-install/installation) for application configuration.
9
-
This page covers Azure permissions, node pools, persistent storage, and ingress.
7
+
Running OpenHands Enterprise on Azure Kubernetes Service (AKS) follows the standard
8
+
[Helm installation](/enterprise/k8s-install/installation), with provider-specific
9
+
choices for node pools, storage, ingress and the sandbox runtime. This guide covers
10
+
preparing the cluster with standard runc sandboxes. Once it is ready, follow the
11
+
Helm guide to deploy using the runtime values below. Skip
12
+
[Installing Sysbox](/enterprise/k8s-install/sysbox). Wherever the Helm guide installs
13
+
or checks Sysbox, use the runc values and checks on this page instead.
14
+
15
+
<Warning>
16
+
Sysbox is not yet supported for OpenHands Enterprise on AKS. This guide uses the
17
+
node’s default runc runtime, evaluated with ordinary coding workflows (see Validation Scope). Docker builds
18
+
and Docker Compose inside the sandbox are unavailable in this configuration.
19
+
Other system-container workloads, such as systemd or nested containers, were not validated.
20
+
Runc does not provide Sysbox’s additional system-container isolation; review the
21
+
isolation requirements for your workloads before production adoption.
22
+
</Warning>
10
23
11
24
## Cluster Requirements
12
25
13
26
| Requirement | Recommendation |
14
27
| --- | --- |
15
28
| Access | An Azure subscription and permissions to create the resource group, cluster, node pools and networking |
16
-
| AKS version |A supported AKS version compatible with [Sysbox](/enterprise/k8s-install/sysbox); verify the actual Ubuntu image and containerd version |
17
-
| Sandbox OS | Ubuntu nodes with a working Sysbox runtime |
29
+
| AKS version |An AKS-supported version; verify the actual Ubuntu image and containerd version against your target Enterprise release|
30
+
| Sandbox OS | Ubuntu nodes using the default containerd/runc runtime |
18
31
| Storage class | Azure Disk CSI, such as `managed-csi`, with expansion enabled |
19
32
| Capacity | Sufficient regional and VM-family vCPU quota for application nodes, sandbox nodes and upgrades |
20
33
@@ -33,48 +46,94 @@ Use separate pools for application services and sandbox workloads:
33
46
34
47
-**General pool:** runs OpenHands services and cluster add-ons. Keep application
35
48
workloads here through node affinity or selectors.
36
-
-**Sysbox pool:** an Ubuntu user node pool for agent sandboxes. Configure
37
-
`sysbox-install=yes` as a persistent node-pool label so new nodes receive the installer.
49
+
-**Sandbox pool:** an Ubuntu user node pool for agent sandboxes. Set
50
+
`workload=openhands-sandbox` as a persistent node-pool label so new nodes match
51
+
the Runtime API selector. Do not install the Sysbox DaemonSet or add its installer label.
38
52
39
53
The evaluation used Azure CNI overlay with Calico, two platform nodes and a sandbox
40
54
pool with autoscaler bounds of one to two nodes. Size the pools using the
41
55
[Sizing Guide](/enterprise/sizing-guide) and
42
56
[Resource Limits](/enterprise/k8s-install/resource-limits), including node overhead,
43
57
image storage and warm sandbox capacity. Validate scale-down behavior for active sessions.
44
58
45
-
### Set Up the Sandbox Runtime
59
+
AKS rejected a manual node-pool scale-down with `UnsatisfiablePDB` because of a
60
+
sandbox PodDisruptionBudget with `maxUnavailable: 0`. Node-image and Kubernetes
61
+
upgrades, which drain nodes, were not tested. Validate maintenance before relying
62
+
on it; do not delete or patch PodDisruptionBudgets to force it.
46
63
47
-
1. Follow [Installing Sysbox](/enterprise/k8s-install/sysbox) to install Sysbox on
48
-
your Ubuntu sandbox pool.
49
-
2. Before installing OpenHands, run a Sysbox test pod with an Azure Disk workspace
50
-
using the [AKS installation skill and companion checks](https://github.com/OpenHands/OpenHands-Cloud/tree/832e57028298f3ad564e6ee7461ee1d9d2ee6d62/aks-install).
51
-
Confirm the pod starts and can write and read a file.
52
-
3. After installing OpenHands, start a conversation and ask it to run `pwd`.
53
-
Confirm it returns the workspace directory.
64
+
### Configure runc Sandboxes
54
65
55
-
<Warning>
56
-
Some AKS node images need an additional Sysbox setup step. If the test pod fails
57
-
with an error mentioning `sysbox-runc`, contact OpenHands support before continuing.
58
-
The AKS installation skill includes the workaround used for the evaluation.
59
-
</Warning>
66
+
Override the Sysbox defaults in the Enterprise chart through Helm values:
60
67
61
-
Before enabling sandbox-pool autoscaling, confirm that each newly created node can
62
-
start a sandbox. A setup correction applied to existing nodes must also be applied
63
-
to replacement and new nodes. Validate this with your support team before relying
0 commit comments