vishesh92 opened a new pull request, #109:
URL: https://github.com/apache/cloudstack-kubernetes-provider/pull/109
## Problem
On a VPC tier the controller opened a Service port with one Network ACL rule
matched only on
protocol and port. Every Service using that port shared it, and it was
deleted when any of them
was deleted or moved off the port, so the other Services lost ingress until
their next sync.
Rules an operator made for the same port were taken over and deleted the
same way.
## Change
- Each rule the controller creates carries the reason
`Managed by the CloudStack Kubernetes Provider for <lb name>`, and only
rules with the
Service's own reason are deleted. Each Service gets its own rule, even
when another Service
already has one for the port.
- A rule created by an earlier release (allow, `0.0.0.0/0`, one port, no
reason) is taken over on
the first sync with `updateNetworkACLItem`. If that is refused, the
Service creates its own
rule; if creating is refused too, it keeps using the old rule, as before.
- Rules someone else made for the port are left alone, and the controller
adds none, as before.
They are no longer deleted with the Service. Rules in a global ACL list
are never taken over.
- `EnsureLoadBalancerDeleted` looks the ACL rule up in the load balancer
rule's own network, and
keeps a load balancer rule whose ACL rule could not be deleted, so the
cleanup is retried.
- Unchanged: firewall rules, public IP handling, and rules stored with an
upper-case protocol,
which are still ignored.
The issue proposed resource tags. This uses the rule's `reason` instead: it
is set in the create
call, so a new rule is never unmarked, and the account CloudStack's
Kubernetes service creates
for project clusters cannot call `createTags`.
## Upgrading
README has a new "Upgrading" section listing what users will notice, what to
do before upgrading
and what to check after. In short: give hand-made `0.0.0.0/0` rules a
reason, allow
`updateNetworkACLItem`, and upgrade every controller whose Services share a
tier or ACL list.
## Testing
- Unit tests for rule classification, listing, take-over, deferring to other
rules, owner-scoped
delete, and full `EnsureLoadBalancer` / `EnsureLoadBalancerDeleted` runs
on a VPC tier.
- New e2e tests: `TestVPC_ACLRulePerService` (the issue's reproduction),
`TestVPC_LegacyACLRuleAdopted` and `TestVPC_OperatorACLRuleKept`.
`TestVPC_ACLRulePerService` fails against `main` with "port 80 is no
longer open on the tier
after deleting one of the two Services using it" and passes with this
change.
- Simulator, CloudStack 4.22.1.0 and Kubernetes v1.37.0: phase 1 24 passed,
1 skipped
(`TestNode_ProviderID`, kind sets provider IDs); phase 2 8 passed.
Fixes #107
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]