When you deploy Knative services from container images, large images can slow pod creation during the pull phase. Use ECI ImageCache to pre-build image snapshots and create pods from them, reducing startup time.
For example, pulling a ~386.26 MB Apache Flink image from Docker Hub takes about 50 seconds without a cache, but about 5 seconds with one.
These figures are theoretical. Actual savings depend on image count, size, and network connection to the registry.
How it works
In an ACK cluster, image caches are managed as a cluster-level CRD named ImageCache. The ImageCache CRD is shared across all namespaces.
Create a cache snapshot from an image, then use it to deploy a pod on an elastic container instance. This reduces image layers to download and accelerates pod creation.
See Overview of image caches for management and billing.
Prerequisites
Ensure that you have:
-
An ACK cluster with Knative enabled
-
kubectl configured to connect to your cluster
Create an ImageCache
-
Create a file named
imagecache-secrets-test.yaml:The
k8s.aliyun.com/eci-image-cache: "true"annotation enables reuse of existing ImageCaches. If the images to cache share layers with an existing ImageCache, this speeds up caching. See Manage ImageCaches for all configurable parameters.apiVersion: eci.alibabacloud.com/v1 kind: ImageCache metadata: name: imagecache-sample-test annotations: k8s.aliyun.com/eci-image-cache: "true" # Enable the reuse of ImageCaches. spec: images: - registry.cn-shanghai.aliyuncs.com/eci_open/nginx:1.14.2 - registry.cn-shanghai.aliyuncs.com/eci_open/busybox:1.30 imageCacheSize: 25 retentionDays: 7 -
Create the ImageCache:
kubectl create -f imagecache-secrets-test.yaml -
Verify the ImageCache is ready:
kubectl get imagecache imagecache-sample-testThe ImageCache is ready when
PHASEshowsReadyandPROGRESSshows100%:NAME AGE CACHEID PHASE PROGRESS imagecache-sample-test 20h imc-2zeditzeoemfhqor**** Ready 100%
Use an ImageCache to accelerate pod creation
Annotate the Knative Service pod metadata to specify the ImageCache. Two annotations:
| Annotation | Behavior |
|---|---|
k8s.aliyun.com/eci-image-snapshot-id |
Uses the specified ImageCache |
k8s.aliyun.com/eci-image-cache |
Automatically selects the best available ImageCache |
If both are set, only k8s.aliyun.com/eci-image-snapshot-id takes effect.
Specify an ImageCache
Use the k8s.aliyun.com/eci-image-snapshot-id annotation to pin a Knative Service to a specific ImageCache.
The ImageCache must be in Ready state before you create the pod. Pods referencing a non-ready ImageCache fail to start.
apiVersion: serving.knative.dev/v1
kind: Service
metadata:
name: helloworld-go
spec:
template:
metadata:
labels:
app: helloworld-go
annotations:
k8s.aliyun.com/eci-image-snapshot-id: imc-2ze5tm5gehgtiiga**** # Specify the ImageCache that you want to use.
spec:
containers:
- image: registry.cn-hangzhou.aliyuncs.com/knative-sample/helloworld-go:73fbdd56
Automatically select an ImageCache
Use the k8s.aliyun.com/eci-image-cache: "true" annotation to let ECI select the best matching ImageCache automatically.
ECI filters ImageCaches in the region that fit the instance's temporary storage, then selects one by priority:
-
Match degree — The cache that best matches the pod's image registry and version.
-
Cache size — Among equal matches, the cache closest in size to the image.
-
Creation time — If tied, the most recently created cache.
If no cache matches, ECI pulls and caches the image during pod creation. Set the image pull policy to IfNotPresent for caching efficiency.
apiVersion: serving.knative.dev/v1
kind: Service
metadata:
name: helloworld-go
spec:
template:
metadata:
labels:
app: helloworld-go
annotations:
k8s.aliyun.com/eci-image-cache: "true" # Automatically select an ImageCache.
spec:
containers:
- image: registry.cn-hangzhou.aliyuncs.com/knative-sample/helloworld-go:73fbdd56
Next steps
-
Manage ImageCaches — Create, query, and delete ImageCaches
-
Image caches billing — Billing methods and pricing