Port kubernetes package to supervisor
This replaces the ad-hoc goroutine and process management
previously in the kubernetes package with a nice supervisor-based
implementation which should make it easier to understand and more
reliable. It also prevents creation of more ad-hoc launching code
for future features (like CSI & Provisioning).
Since porting SmalltownNode is rather involved I just instantiated a
new supervision tree in the Kubernetes main service and wired it
up to the old interface. Once we port SmalltownNode we can just
remove the legacy Start() method and directly call Run().
Test Plan:
Passes Bazel tests, Kubernetes functionality was manually
tested by running `bazel run //core/cmd/dbg -- kubectl run -i --image alpine:edge sh`
to verify that Kubernetes still works properly. Automated tests for this
are being worked on.
X-Origin-Diff: phab/D534
GitOrigin-RevId: 001de38eaa5c7ee661bf5db9a7c3d0125c1b6af2
diff --git a/core/internal/kubernetes/reconcile.go b/core/internal/kubernetes/reconcile.go
index cf991ce..092cd8e 100644
--- a/core/internal/kubernetes/reconcile.go
+++ b/core/internal/kubernetes/reconcile.go
@@ -33,6 +33,8 @@
metav1 "k8s.io/apimachinery/pkg/apis/meta/v1"
"k8s.io/client-go/kubernetes"
"k8s.io/client-go/tools/clientcmd"
+
+ "git.monogon.dev/source/nexantic.git/core/internal/common/supervisor"
)
const builtinRBACPrefix = "smalltown:"
@@ -174,47 +176,49 @@
},
}
-func runReconciler(ctx context.Context, masterKubeconfig []byte, log *zap.Logger) error {
- rawClientConfig, err := clientcmd.NewClientConfigFromBytes(masterKubeconfig)
- if err != nil {
- return err
- }
+type reconciler func(context.Context, *kubernetes.Clientset) error
- clientConfig, err := rawClientConfig.ClientConfig()
- clientset, err := kubernetes.NewForConfig(clientConfig)
- if err != nil {
- return err
- }
- t := time.NewTicker(10 * time.Second)
- for {
- err = reconcile(ctx, clientset)
- select {
- case <-t.C:
- err = reconcile(ctx, clientset)
- if err != nil {
- log.Warn("Failed to reconcile built-in resources", zap.Error(err))
+func runReconciler(masterKubeconfig []byte) supervisor.Runnable {
+ return func(ctx context.Context) error {
+ log := supervisor.Logger(ctx)
+ rawClientConfig, err := clientcmd.NewClientConfigFromBytes(masterKubeconfig)
+ if err != nil {
+ return err
+ }
+
+ clientConfig, err := rawClientConfig.ClientConfig()
+ clientSet, err := kubernetes.NewForConfig(clientConfig)
+ if err != nil {
+ return err
+ }
+ reconcilers := map[string]reconciler{
+ "psps": reconcilePSPs,
+ "clusterroles": reconcileClusterRoles,
+ "clusterrolebindings": reconcileClusterRoleBindings,
+ }
+ t := time.NewTicker(10 * time.Second)
+ reconcile := func() {
+ for name, reconciler := range reconcilers {
+ if err := reconciler(ctx, clientSet); err != nil {
+ log.Warn("Failed to reconcile built-in resources", zap.String("kind", name), zap.Error(err))
+ }
}
- case <-ctx.Done():
- return nil
+ }
+ supervisor.Signal(ctx, supervisor.SignalHealthy)
+ reconcile()
+ for {
+ select {
+ case <-t.C:
+ reconcile()
+ case <-ctx.Done():
+ return nil
+ }
}
}
}
-func reconcile(ctx context.Context, clientset *kubernetes.Clientset) error {
- if err := reconcilePSPs(ctx, clientset); err != nil {
- return err
- }
- if err := reconcileClusterRoles(ctx, clientset); err != nil {
- return err
- }
- if err := reconcileClusterRoleBindings(ctx, clientset); err != nil {
- return err
- }
- return nil
-}
-
-func reconcilePSPs(ctx context.Context, clientset *kubernetes.Clientset) error {
- pspClient := clientset.PolicyV1beta1().PodSecurityPolicies()
+func reconcilePSPs(ctx context.Context, clientSet *kubernetes.Clientset) error {
+ pspClient := clientSet.PolicyV1beta1().PodSecurityPolicies()
availablePSPs, err := pspClient.List(ctx, metav1.ListOptions{
LabelSelector: "smalltown.com/builtin=true",
})
@@ -246,8 +250,8 @@
return nil
}
-func reconcileClusterRoles(ctx context.Context, clientset *kubernetes.Clientset) error {
- crClient := clientset.RbacV1().ClusterRoles()
+func reconcileClusterRoles(ctx context.Context, clientSet *kubernetes.Clientset) error {
+ crClient := clientSet.RbacV1().ClusterRoles()
availableCRs, err := crClient.List(ctx, metav1.ListOptions{
LabelSelector: "smalltown.com/builtin=true",
})