Image volume injection is the recommended way to deliver OneAgent code modules on Kubernetes 1.35+. The container runtime mounts the code modules image directly as a read-only volume in each injected pod. Because the container runtime caches image at the node level, the image is pulled once per node and shared across all pods running on the same node.
Use this guide if you have an existing deployment using CSI driver or ephemeral volume injection and want to migrate to image volume injection.
subPath mounts:
kubectl get nodes -o jsonpath='{range .items[*]}{.metadata.name}{"\t"}{.status.nodeInfo.containerRuntimeVersion}{"\n"}{end}'
Example output:
ip-172-31-0-249.ec2.internal containerd://2.2.5
To migrate specific pods before committing to a full cluster-wide migration, annotate individual pods. Non-annotated pods continue to use their current injection mode.
Add the oneagent.dynatrace.com/volume-type: "image" annotation to your pod definition:
metadata:annotations:oneagent.dynatrace.com/volume-type: "image"
Pod-level annotations override the DynaKube-configured injection mode. A pod annotated with oneagent.dynatrace.com/volume-type: "image" is injected with image volumes even if the DynaKube is configured for CSI or ephemeral volume injection.
A pod restart is required for the annotation to take effect. Existing running pods are not re-injected automatically.
To verify injection, see Verify injection. Once pod-level migration is validated, cluster-wide migration can be performed by enabling image volume injection on the DynaKube and restarting all injected workloads.
A full migration requires a rolling restart of all injected workloads.
Add the feature.dynatrace.com/mount-code-modules-via-image-volume annotation to your DynaKube:
apiVersion: dynatrace.com/v1beta6kind: DynaKubemetadata:name: dynakubeannotations:feature.dynatrace.com/mount-code-modules-via-image-volume: "true"
The feature.dynatrace.com/mount-code-modules-via-image-volume annotation is mutually exclusive with feature.dynatrace.com/node-image-pull. Enabling both results in a validation error.
Restart all workloads that are not yet using image volumes. The webhook re-injects them with image volumes on the next pod start.
kubectl rollout restart deployment <deployment-name> -n <namespace>
Confirm that pods are injected with image volumes by checking the volume mounts on an injected pod:
kubectl describe pod <pod-name> -n <namespace>
In the output, look for a volume of type image in the Volumes section. Example:
Volumes:oneagent-bin:Type: Image (a container image or OCI artifact)Reference: public.ecr.aws/dynatrace/dynatrace-codemodules:<version>
To revert, remove the feature.dynatrace.com/mount-code-modules-via-image-volume: "true" annotation from your DynaKube, re-apply it, then restart your workloads. Pods revert to their previous injection mode.