vishesh92 opened a new pull request, #109:
URL: https://github.com/apache/cloudstack-kubernetes-provider/pull/109

   ## Problem
   
   On a VPC tier the controller opened a Service port with one Network ACL rule 
matched only on
   protocol and port. Every Service using that port shared it, and it was 
deleted when any of them
   was deleted or moved off the port, so the other Services lost ingress until 
their next sync.
   Rules an operator made for the same port were taken over and deleted the 
same way.
   
   ## Change
   
   - Each rule the controller creates carries the reason
     `Managed by the CloudStack Kubernetes Provider for <lb name>`, and only 
rules with the
     Service's own reason are deleted. Each Service gets its own rule, even 
when another Service
     already has one for the port.
   - A rule created by an earlier release (allow, `0.0.0.0/0`, one port, no 
reason) is taken over on
     the first sync with `updateNetworkACLItem`. If that is refused, the 
Service creates its own
     rule; if creating is refused too, it keeps using the old rule, as before.
   - Rules someone else made for the port are left alone, and the controller 
adds none, as before.
     They are no longer deleted with the Service. Rules in a global ACL list 
are never taken over.
   - `EnsureLoadBalancerDeleted` looks the ACL rule up in the load balancer 
rule's own network, and
     keeps a load balancer rule whose ACL rule could not be deleted, so the 
cleanup is retried.
   - Unchanged: firewall rules, public IP handling, and rules stored with an 
upper-case protocol,
     which are still ignored.
   
   The issue proposed resource tags. This uses the rule's `reason` instead: it 
is set in the create
   call, so a new rule is never unmarked, and the account CloudStack's 
Kubernetes service creates
   for project clusters cannot call `createTags`.
   
   ## Upgrading
   
   README has a new "Upgrading" section listing what users will notice, what to 
do before upgrading
   and what to check after. In short: give hand-made `0.0.0.0/0` rules a 
reason, allow
   `updateNetworkACLItem`, and upgrade every controller whose Services share a 
tier or ACL list.
   
   ## Testing
   
   - Unit tests for rule classification, listing, take-over, deferring to other 
rules, owner-scoped
     delete, and full `EnsureLoadBalancer` / `EnsureLoadBalancerDeleted` runs 
on a VPC tier.
   - New e2e tests: `TestVPC_ACLRulePerService` (the issue's reproduction),
     `TestVPC_LegacyACLRuleAdopted` and `TestVPC_OperatorACLRuleKept`.
     `TestVPC_ACLRulePerService` fails against `main` with "port 80 is no 
longer open on the tier
     after deleting one of the two Services using it" and passes with this 
change.
   - Simulator, CloudStack 4.22.1.0 and Kubernetes v1.37.0: phase 1 24 passed, 
1 skipped
     (`TestNode_ProviderID`, kind sets provider IDs); phase 2 8 passed.
   
   Fixes #107


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to