| Lorenz Brun | b15abad | 2020-04-16 11:17:12 +0200 | [diff] [blame] | 1 | // Copyright 2020 The Monogon Project Authors. |
| 2 | // |
| 3 | // SPDX-License-Identifier: Apache-2.0 |
| 4 | // |
| 5 | // Licensed under the Apache License, Version 2.0 (the "License"); |
| 6 | // you may not use this file except in compliance with the License. |
| 7 | // You may obtain a copy of the License at |
| 8 | // |
| 9 | // http://www.apache.org/licenses/LICENSE-2.0 |
| 10 | // |
| 11 | // Unless required by applicable law or agreed to in writing, software |
| 12 | // distributed under the License is distributed on an "AS IS" BASIS, |
| 13 | // WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. |
| 14 | // See the License for the specific language governing permissions and |
| 15 | // limitations under the License. |
| 16 | |
| 17 | package kubernetes |
| 18 | |
| 19 | import ( |
| 20 | "context" |
| 21 | "errors" |
| 22 | "fmt" |
| Lorenz Brun | b15abad | 2020-04-16 11:17:12 +0200 | [diff] [blame] | 23 | "os" |
| 24 | "path/filepath" |
| 25 | |
| Lorenz Brun | 3705012 | 2021-03-30 14:00:27 +0200 | [diff] [blame] | 26 | "golang.org/x/sys/unix" |
| Lorenz Brun | b15abad | 2020-04-16 11:17:12 +0200 | [diff] [blame] | 27 | v1 "k8s.io/api/core/v1" |
| 28 | storagev1 "k8s.io/api/storage/v1" |
| 29 | apierrs "k8s.io/apimachinery/pkg/api/errors" |
| 30 | metav1 "k8s.io/apimachinery/pkg/apis/meta/v1" |
| 31 | "k8s.io/client-go/informers" |
| 32 | coreinformers "k8s.io/client-go/informers/core/v1" |
| 33 | storageinformers "k8s.io/client-go/informers/storage/v1" |
| 34 | "k8s.io/client-go/kubernetes" |
| 35 | "k8s.io/client-go/kubernetes/scheme" |
| 36 | typedcorev1 "k8s.io/client-go/kubernetes/typed/core/v1" |
| 37 | "k8s.io/client-go/tools/cache" |
| 38 | "k8s.io/client-go/tools/record" |
| 39 | ref "k8s.io/client-go/tools/reference" |
| 40 | "k8s.io/client-go/util/workqueue" |
| Serge Bazanski | c2c7ad9 | 2020-07-13 17:20:09 +0200 | [diff] [blame] | 41 | |
| Serge Bazanski | 31370b0 | 2021-01-07 16:31:14 +0100 | [diff] [blame] | 42 | "source.monogon.dev/metropolis/node/core/localstorage" |
| Tim Windelschmidt | 9f21f53 | 2024-05-07 15:14:20 +0200 | [diff] [blame] | 43 | "source.monogon.dev/osbase/fsquota" |
| 44 | "source.monogon.dev/osbase/logtree" |
| 45 | "source.monogon.dev/osbase/supervisor" |
| Lorenz Brun | b15abad | 2020-04-16 11:17:12 +0200 | [diff] [blame] | 46 | ) |
| 47 | |
| Lorenz Brun | 397f7ea | 2024-08-20 21:26:06 +0200 | [diff] [blame] | 48 | // inodeCapacityRatio describes the ratio between the byte capacity of a volume |
| 49 | // and its inode capacity. One inode on XFS is 512 bytes and by default 25% |
| 50 | // (1/4) of capacity can be used for metadata. |
| 51 | const inodeCapacityRatio = 4 * 512 |
| 52 | |
| Serge Bazanski | 216fe7b | 2021-05-21 18:36:16 +0200 | [diff] [blame] | 53 | // ONCHANGE(//metropolis/node/kubernetes/reconciler:resources_csi.go): needs to |
| 54 | // match csiProvisionerServerName declared. |
| Serge Bazanski | 662b5b3 | 2020-12-21 13:49:00 +0100 | [diff] [blame] | 55 | const csiProvisionerServerName = "dev.monogon.metropolis.vfs" |
| Lorenz Brun | b15abad | 2020-04-16 11:17:12 +0200 | [diff] [blame] | 56 | |
| Serge Bazanski | 216fe7b | 2021-05-21 18:36:16 +0200 | [diff] [blame] | 57 | // csiProvisionerServer is responsible for the provisioning and deprovisioning |
| 58 | // of CSI-based container volumes. It runs on all nodes and watches PVCs for |
| 59 | // ones assigned to the node it's running on and fulfills the provisioning |
| 60 | // request by creating a directory, applying a quota and creating the |
| 61 | // corresponding PV. When the PV is released and its retention policy is |
| 62 | // Delete, the directory and the PV resource are deleted. |
| Serge Bazanski | c2c7ad9 | 2020-07-13 17:20:09 +0200 | [diff] [blame] | 63 | type csiProvisionerServer struct { |
| 64 | NodeName string |
| 65 | Kubernetes kubernetes.Interface |
| 66 | InformerFactory informers.SharedInformerFactory |
| 67 | VolumesDirectory *localstorage.DataVolumesDirectory |
| 68 | |
| Lorenz Brun | b15abad | 2020-04-16 11:17:12 +0200 | [diff] [blame] | 69 | claimQueue workqueue.RateLimitingInterface |
| 70 | pvQueue workqueue.RateLimitingInterface |
| 71 | recorder record.EventRecorder |
| 72 | pvcInformer coreinformers.PersistentVolumeClaimInformer |
| 73 | pvInformer coreinformers.PersistentVolumeInformer |
| 74 | storageClassInformer storageinformers.StorageClassInformer |
| Serge Bazanski | c735967 | 2020-10-30 16:38:57 +0100 | [diff] [blame] | 75 | logger logtree.LeveledLogger |
| Lorenz Brun | b15abad | 2020-04-16 11:17:12 +0200 | [diff] [blame] | 76 | } |
| 77 | |
| Serge Bazanski | 216fe7b | 2021-05-21 18:36:16 +0200 | [diff] [blame] | 78 | // runCSIProvisioner runs the main provisioning machinery. It consists of a |
| 79 | // bunch of informers which keep track of the events happening on the |
| 80 | // Kubernetes control plane and informs us when something happens. If anything |
| 81 | // happens to PVCs or PVs, we enqueue the identifier of that resource in a work |
| 82 | // queue. Queues are being worked on by only one worker to limit load and avoid |
| 83 | // complicated locking infrastructure. Failed items are requeued. |
| Serge Bazanski | c2c7ad9 | 2020-07-13 17:20:09 +0200 | [diff] [blame] | 84 | func (p *csiProvisionerServer) Run(ctx context.Context) error { |
| Serge Bazanski | 216fe7b | 2021-05-21 18:36:16 +0200 | [diff] [blame] | 85 | // The recorder is used to log Kubernetes events for successful or failed |
| 86 | // volume provisions. These events then show up in `kubectl describe pvc` |
| 87 | // and can be used by admins to debug issues with this provisioner. |
| Serge Bazanski | c2c7ad9 | 2020-07-13 17:20:09 +0200 | [diff] [blame] | 88 | eventBroadcaster := record.NewBroadcaster() |
| 89 | eventBroadcaster.StartRecordingToSink(&typedcorev1.EventSinkImpl{Interface: p.Kubernetes.CoreV1().Events("")}) |
| 90 | p.recorder = eventBroadcaster.NewRecorder(scheme.Scheme, v1.EventSource{Component: csiProvisionerServerName, Host: p.NodeName}) |
| Lorenz Brun | b15abad | 2020-04-16 11:17:12 +0200 | [diff] [blame] | 91 | |
| Serge Bazanski | c2c7ad9 | 2020-07-13 17:20:09 +0200 | [diff] [blame] | 92 | p.pvInformer = p.InformerFactory.Core().V1().PersistentVolumes() |
| 93 | p.pvcInformer = p.InformerFactory.Core().V1().PersistentVolumeClaims() |
| 94 | p.storageClassInformer = p.InformerFactory.Storage().V1().StorageClasses() |
| Lorenz Brun | b15abad | 2020-04-16 11:17:12 +0200 | [diff] [blame] | 95 | |
| Serge Bazanski | c2c7ad9 | 2020-07-13 17:20:09 +0200 | [diff] [blame] | 96 | p.claimQueue = workqueue.NewRateLimitingQueue(workqueue.DefaultControllerRateLimiter()) |
| 97 | p.pvQueue = workqueue.NewRateLimitingQueue(workqueue.DefaultControllerRateLimiter()) |
| Lorenz Brun | b15abad | 2020-04-16 11:17:12 +0200 | [diff] [blame] | 98 | |
| Serge Bazanski | ce19acc | 2023-03-21 16:28:07 +0100 | [diff] [blame] | 99 | p.logger = supervisor.Logger(ctx) |
| 100 | |
| 101 | p.pvcInformer.Informer().SetWatchErrorHandler(func(_ *cache.Reflector, err error) { |
| 102 | p.logger.Errorf("pvcInformer watch error: %v", err) |
| 103 | }) |
| Serge Bazanski | c2c7ad9 | 2020-07-13 17:20:09 +0200 | [diff] [blame] | 104 | p.pvcInformer.Informer().AddEventHandler(cache.ResourceEventHandlerFuncs{ |
| 105 | AddFunc: p.enqueueClaim, |
| 106 | UpdateFunc: func(old, new interface{}) { |
| 107 | p.enqueueClaim(new) |
| 108 | }, |
| 109 | }) |
| 110 | p.pvInformer.Informer().AddEventHandler(cache.ResourceEventHandlerFuncs{ |
| 111 | AddFunc: p.enqueuePV, |
| 112 | UpdateFunc: func(old, new interface{}) { |
| 113 | p.enqueuePV(new) |
| 114 | }, |
| 115 | }) |
| Serge Bazanski | ce19acc | 2023-03-21 16:28:07 +0100 | [diff] [blame] | 116 | p.pvInformer.Informer().SetWatchErrorHandler(func(_ *cache.Reflector, err error) { |
| 117 | p.logger.Errorf("pvInformer watch error: %v", err) |
| 118 | }) |
| 119 | |
| 120 | p.storageClassInformer.Informer().SetWatchErrorHandler(func(_ *cache.Reflector, err error) { |
| 121 | p.logger.Errorf("storageClassInformer watch error: %v", err) |
| 122 | }) |
| Lorenz Brun | b15abad | 2020-04-16 11:17:12 +0200 | [diff] [blame] | 123 | |
| Serge Bazanski | c2c7ad9 | 2020-07-13 17:20:09 +0200 | [diff] [blame] | 124 | go p.pvcInformer.Informer().Run(ctx.Done()) |
| 125 | go p.pvInformer.Informer().Run(ctx.Done()) |
| 126 | go p.storageClassInformer.Informer().Run(ctx.Done()) |
| Lorenz Brun | b15abad | 2020-04-16 11:17:12 +0200 | [diff] [blame] | 127 | |
| Serge Bazanski | c2c7ad9 | 2020-07-13 17:20:09 +0200 | [diff] [blame] | 128 | // These will self-terminate once the queues are shut down |
| 129 | go p.processQueueItems(p.claimQueue, func(key string) error { |
| 130 | return p.processPVC(key) |
| 131 | }) |
| 132 | go p.processQueueItems(p.pvQueue, func(key string) error { |
| 133 | return p.processPV(key) |
| 134 | }) |
| Lorenz Brun | b15abad | 2020-04-16 11:17:12 +0200 | [diff] [blame] | 135 | |
| Serge Bazanski | c2c7ad9 | 2020-07-13 17:20:09 +0200 | [diff] [blame] | 136 | supervisor.Signal(ctx, supervisor.SignalHealthy) |
| 137 | <-ctx.Done() |
| 138 | p.claimQueue.ShutDown() |
| 139 | p.pvQueue.ShutDown() |
| 140 | return nil |
| Lorenz Brun | b15abad | 2020-04-16 11:17:12 +0200 | [diff] [blame] | 141 | } |
| 142 | |
| Serge Bazanski | 216fe7b | 2021-05-21 18:36:16 +0200 | [diff] [blame] | 143 | // isOurPVC checks if the given PVC is is to be provisioned by this provisioner |
| 144 | // and has been scheduled onto this node |
| Serge Bazanski | c2c7ad9 | 2020-07-13 17:20:09 +0200 | [diff] [blame] | 145 | func (p *csiProvisionerServer) isOurPVC(pvc *v1.PersistentVolumeClaim) bool { |
| 146 | if pvc.ObjectMeta.Annotations["volume.beta.kubernetes.io/storage-provisioner"] != csiProvisionerServerName { |
| 147 | return false |
| 148 | } |
| 149 | if pvc.ObjectMeta.Annotations["volume.kubernetes.io/selected-node"] != p.NodeName { |
| 150 | return false |
| 151 | } |
| 152 | return true |
| Lorenz Brun | b15abad | 2020-04-16 11:17:12 +0200 | [diff] [blame] | 153 | } |
| 154 | |
| Serge Bazanski | 216fe7b | 2021-05-21 18:36:16 +0200 | [diff] [blame] | 155 | // isOurPV checks if the given PV has been provisioned by this provisioner and |
| 156 | // has been scheduled onto this node |
| Serge Bazanski | c2c7ad9 | 2020-07-13 17:20:09 +0200 | [diff] [blame] | 157 | func (p *csiProvisionerServer) isOurPV(pv *v1.PersistentVolume) bool { |
| 158 | if pv.ObjectMeta.Annotations["pv.kubernetes.io/provisioned-by"] != csiProvisionerServerName { |
| 159 | return false |
| 160 | } |
| 161 | if pv.Spec.NodeAffinity.Required.NodeSelectorTerms[0].MatchExpressions[0].Values[0] != p.NodeName { |
| 162 | return false |
| 163 | } |
| 164 | return true |
| Lorenz Brun | b15abad | 2020-04-16 11:17:12 +0200 | [diff] [blame] | 165 | } |
| 166 | |
| 167 | // enqueueClaim adds an added/changed PVC to the work queue |
| Serge Bazanski | c2c7ad9 | 2020-07-13 17:20:09 +0200 | [diff] [blame] | 168 | func (p *csiProvisionerServer) enqueueClaim(obj interface{}) { |
| Lorenz Brun | b15abad | 2020-04-16 11:17:12 +0200 | [diff] [blame] | 169 | key, err := cache.MetaNamespaceKeyFunc(obj) |
| 170 | if err != nil { |
| Serge Bazanski | c735967 | 2020-10-30 16:38:57 +0100 | [diff] [blame] | 171 | p.logger.Errorf("Not queuing PVC because key could not be derived: %v", err) |
| Lorenz Brun | b15abad | 2020-04-16 11:17:12 +0200 | [diff] [blame] | 172 | return |
| 173 | } |
| 174 | p.claimQueue.Add(key) |
| 175 | } |
| 176 | |
| 177 | // enqueuePV adds an added/changed PV to the work queue |
| Serge Bazanski | c2c7ad9 | 2020-07-13 17:20:09 +0200 | [diff] [blame] | 178 | func (p *csiProvisionerServer) enqueuePV(obj interface{}) { |
| Lorenz Brun | b15abad | 2020-04-16 11:17:12 +0200 | [diff] [blame] | 179 | key, err := cache.MetaNamespaceKeyFunc(obj) |
| 180 | if err != nil { |
| Serge Bazanski | c735967 | 2020-10-30 16:38:57 +0100 | [diff] [blame] | 181 | p.logger.Errorf("Not queuing PV because key could not be derived: %v", err) |
| Lorenz Brun | b15abad | 2020-04-16 11:17:12 +0200 | [diff] [blame] | 182 | return |
| 183 | } |
| 184 | p.pvQueue.Add(key) |
| 185 | } |
| 186 | |
| Serge Bazanski | 216fe7b | 2021-05-21 18:36:16 +0200 | [diff] [blame] | 187 | // processQueueItems gets items from the given work queue and calls the process |
| 188 | // function for each of them. It self- terminates once the queue is shut down. |
| Serge Bazanski | c2c7ad9 | 2020-07-13 17:20:09 +0200 | [diff] [blame] | 189 | func (p *csiProvisionerServer) processQueueItems(queue workqueue.RateLimitingInterface, process func(key string) error) { |
| Lorenz Brun | b15abad | 2020-04-16 11:17:12 +0200 | [diff] [blame] | 190 | for { |
| 191 | obj, shutdown := queue.Get() |
| 192 | if shutdown { |
| 193 | return |
| 194 | } |
| 195 | |
| 196 | func(obj interface{}) { |
| 197 | defer queue.Done(obj) |
| 198 | key, ok := obj.(string) |
| 199 | if !ok { |
| 200 | queue.Forget(obj) |
| Serge Bazanski | c735967 | 2020-10-30 16:38:57 +0100 | [diff] [blame] | 201 | p.logger.Errorf("Expected string in workqueue, got %+v", obj) |
| Lorenz Brun | b15abad | 2020-04-16 11:17:12 +0200 | [diff] [blame] | 202 | return |
| 203 | } |
| 204 | |
| 205 | if err := process(key); err != nil { |
| Serge Bazanski | c735967 | 2020-10-30 16:38:57 +0100 | [diff] [blame] | 206 | p.logger.Warningf("Failed processing item %q, requeueing (numrequeues: %d): %v", key, queue.NumRequeues(obj), err) |
| Lorenz Brun | b15abad | 2020-04-16 11:17:12 +0200 | [diff] [blame] | 207 | queue.AddRateLimited(obj) |
| 208 | } |
| 209 | |
| 210 | queue.Forget(obj) |
| 211 | }(obj) |
| 212 | } |
| 213 | } |
| 214 | |
| Serge Bazanski | c2c7ad9 | 2020-07-13 17:20:09 +0200 | [diff] [blame] | 215 | // volumePath gets the path where the volume is stored. |
| 216 | func (p *csiProvisionerServer) volumePath(volumeID string) string { |
| 217 | return filepath.Join(p.VolumesDirectory.FullPath(), volumeID) |
| Lorenz Brun | b15abad | 2020-04-16 11:17:12 +0200 | [diff] [blame] | 218 | } |
| 219 | |
| Serge Bazanski | 216fe7b | 2021-05-21 18:36:16 +0200 | [diff] [blame] | 220 | // processPVC looks at a single PVC item from the queue, determines if it needs |
| 221 | // to be provisioned and logs the provisioning result to the recorder |
| Serge Bazanski | c2c7ad9 | 2020-07-13 17:20:09 +0200 | [diff] [blame] | 222 | func (p *csiProvisionerServer) processPVC(key string) error { |
| Lorenz Brun | b15abad | 2020-04-16 11:17:12 +0200 | [diff] [blame] | 223 | namespace, name, err := cache.SplitMetaNamespaceKey(key) |
| 224 | if err != nil { |
| 225 | return fmt.Errorf("invalid resource key: %s", key) |
| 226 | } |
| 227 | pvc, err := p.pvcInformer.Lister().PersistentVolumeClaims(namespace).Get(name) |
| 228 | if apierrs.IsNotFound(err) { |
| 229 | return nil // nothing to do, no error |
| 230 | } else if err != nil { |
| 231 | return fmt.Errorf("failed to get PVC for processing: %w", err) |
| 232 | } |
| 233 | |
| 234 | if !p.isOurPVC(pvc) { |
| 235 | return nil |
| 236 | } |
| 237 | |
| 238 | if pvc.Status.Phase != "Pending" { |
| 239 | // If the PVC is not pending, we don't need to provision anything |
| 240 | return nil |
| 241 | } |
| 242 | |
| 243 | storageClass, err := p.storageClassInformer.Lister().Get(*pvc.Spec.StorageClassName) |
| 244 | if err != nil { |
| Serge Bazanski | ce19acc | 2023-03-21 16:28:07 +0100 | [diff] [blame] | 245 | return fmt.Errorf("could not get storage class: %w", err) |
| Lorenz Brun | b15abad | 2020-04-16 11:17:12 +0200 | [diff] [blame] | 246 | } |
| 247 | |
| Serge Bazanski | c2c7ad9 | 2020-07-13 17:20:09 +0200 | [diff] [blame] | 248 | if storageClass.Provisioner != csiProvisionerServerName { |
| Serge Bazanski | 216fe7b | 2021-05-21 18:36:16 +0200 | [diff] [blame] | 249 | // We're not responsible for this PVC. Can only happen if |
| 250 | // controller-manager makes a mistake setting the annotations, but |
| 251 | // we're bailing here anyways for safety. |
| Lorenz Brun | b15abad | 2020-04-16 11:17:12 +0200 | [diff] [blame] | 252 | return nil |
| 253 | } |
| 254 | |
| 255 | err = p.provisionPVC(pvc, storageClass) |
| 256 | |
| 257 | if err != nil { |
| 258 | p.recorder.Eventf(pvc, v1.EventTypeWarning, "ProvisioningFailed", "Failed to provision PV: %v", err) |
| 259 | return err |
| 260 | } |
| 261 | p.recorder.Eventf(pvc, v1.EventTypeNormal, "Provisioned", "Successfully provisioned PV") |
| 262 | |
| 263 | return nil |
| 264 | } |
| 265 | |
| Serge Bazanski | 216fe7b | 2021-05-21 18:36:16 +0200 | [diff] [blame] | 266 | // provisionPVC creates the directory where the volume lives, sets a quota for |
| 267 | // the requested amount of storage and creates the PV object representing this |
| 268 | // new volume |
| Serge Bazanski | c2c7ad9 | 2020-07-13 17:20:09 +0200 | [diff] [blame] | 269 | func (p *csiProvisionerServer) provisionPVC(pvc *v1.PersistentVolumeClaim, storageClass *storagev1.StorageClass) error { |
| Lorenz Brun | b15abad | 2020-04-16 11:17:12 +0200 | [diff] [blame] | 270 | claimRef, err := ref.GetReference(scheme.Scheme, pvc) |
| 271 | if err != nil { |
| 272 | return fmt.Errorf("failed to get reference to PVC: %w", err) |
| 273 | } |
| 274 | |
| 275 | storageReq := pvc.Spec.Resources.Requests[v1.ResourceStorage] |
| 276 | if storageReq.IsZero() { |
| 277 | return fmt.Errorf("PVC is not requesting any storage, this is not supported") |
| 278 | } |
| 279 | capacity, ok := storageReq.AsInt64() |
| 280 | if !ok { |
| 281 | return fmt.Errorf("PVC requesting more than 2^63 bytes of storage, this is not supported") |
| 282 | } |
| 283 | |
| Lorenz Brun | b15abad | 2020-04-16 11:17:12 +0200 | [diff] [blame] | 284 | volumeID := "pvc-" + string(pvc.ObjectMeta.UID) |
| Serge Bazanski | c2c7ad9 | 2020-07-13 17:20:09 +0200 | [diff] [blame] | 285 | volumePath := p.volumePath(volumeID) |
| Lorenz Brun | b15abad | 2020-04-16 11:17:12 +0200 | [diff] [blame] | 286 | |
| Serge Bazanski | c735967 | 2020-10-30 16:38:57 +0100 | [diff] [blame] | 287 | p.logger.Infof("Creating local PV %s", volumeID) |
| Lorenz Brun | 3705012 | 2021-03-30 14:00:27 +0200 | [diff] [blame] | 288 | |
| 289 | switch *pvc.Spec.VolumeMode { |
| 290 | case "", v1.PersistentVolumeFilesystem: |
| 291 | if err := os.Mkdir(volumePath, 0644); err != nil && !os.IsExist(err) { |
| 292 | return fmt.Errorf("failed to create volume directory: %w", err) |
| 293 | } |
| Lorenz Brun | 764a2de | 2021-11-22 16:26:36 +0100 | [diff] [blame] | 294 | files, err := os.ReadDir(volumePath) |
| Lorenz Brun | 3705012 | 2021-03-30 14:00:27 +0200 | [diff] [blame] | 295 | if err != nil { |
| 296 | return fmt.Errorf("failed to list files in newly-created volume: %w", err) |
| 297 | } |
| 298 | if len(files) > 0 { |
| 299 | return errors.New("newly-created volume already contains data, bailing") |
| 300 | } |
| Lorenz Brun | 397f7ea | 2024-08-20 21:26:06 +0200 | [diff] [blame] | 301 | if err := fsquota.SetQuota(volumePath, uint64(capacity), uint64(capacity)/inodeCapacityRatio); err != nil { |
| Serge Bazanski | ce19acc | 2023-03-21 16:28:07 +0100 | [diff] [blame] | 302 | return fmt.Errorf("failed to update quota: %w", err) |
| Lorenz Brun | 3705012 | 2021-03-30 14:00:27 +0200 | [diff] [blame] | 303 | } |
| 304 | case v1.PersistentVolumeBlock: |
| 305 | imageFile, err := os.OpenFile(volumePath, os.O_CREATE|os.O_RDWR, 0644) |
| 306 | if err != nil { |
| 307 | return fmt.Errorf("failed to create volume image: %w", err) |
| 308 | } |
| 309 | defer imageFile.Close() |
| 310 | if err := unix.Fallocate(int(imageFile.Fd()), 0, 0, capacity); err != nil { |
| 311 | return fmt.Errorf("failed to fallocate() volume image: %w", err) |
| 312 | } |
| 313 | default: |
| 314 | return fmt.Errorf("VolumeMode \"%s\" is unsupported", *pvc.Spec.VolumeMode) |
| Lorenz Brun | b15abad | 2020-04-16 11:17:12 +0200 | [diff] [blame] | 315 | } |
| 316 | |
| 317 | vol := &v1.PersistentVolume{ |
| 318 | ObjectMeta: metav1.ObjectMeta{ |
| 319 | Name: volumeID, |
| 320 | Annotations: map[string]string{ |
| Serge Bazanski | c2c7ad9 | 2020-07-13 17:20:09 +0200 | [diff] [blame] | 321 | "pv.kubernetes.io/provisioned-by": csiProvisionerServerName}, |
| Lorenz Brun | b15abad | 2020-04-16 11:17:12 +0200 | [diff] [blame] | 322 | }, |
| 323 | Spec: v1.PersistentVolumeSpec{ |
| 324 | AccessModes: []v1.PersistentVolumeAccessMode{v1.ReadWriteOnce}, |
| 325 | Capacity: v1.ResourceList{ |
| 326 | v1.ResourceStorage: storageReq, // We're always giving the exact amount |
| 327 | }, |
| 328 | PersistentVolumeSource: v1.PersistentVolumeSource{ |
| 329 | CSI: &v1.CSIPersistentVolumeSource{ |
| Serge Bazanski | c2c7ad9 | 2020-07-13 17:20:09 +0200 | [diff] [blame] | 330 | Driver: csiProvisionerServerName, |
| Lorenz Brun | b15abad | 2020-04-16 11:17:12 +0200 | [diff] [blame] | 331 | VolumeHandle: volumeID, |
| 332 | }, |
| 333 | }, |
| Lorenz Brun | 3705012 | 2021-03-30 14:00:27 +0200 | [diff] [blame] | 334 | ClaimRef: claimRef, |
| 335 | VolumeMode: pvc.Spec.VolumeMode, |
| Lorenz Brun | b15abad | 2020-04-16 11:17:12 +0200 | [diff] [blame] | 336 | NodeAffinity: &v1.VolumeNodeAffinity{ |
| 337 | Required: &v1.NodeSelector{ |
| 338 | NodeSelectorTerms: []v1.NodeSelectorTerm{ |
| 339 | { |
| 340 | MatchExpressions: []v1.NodeSelectorRequirement{ |
| 341 | { |
| 342 | Key: "kubernetes.io/hostname", |
| 343 | Operator: v1.NodeSelectorOpIn, |
| Serge Bazanski | c2c7ad9 | 2020-07-13 17:20:09 +0200 | [diff] [blame] | 344 | Values: []string{p.NodeName}, |
| Lorenz Brun | b15abad | 2020-04-16 11:17:12 +0200 | [diff] [blame] | 345 | }, |
| 346 | }, |
| 347 | }, |
| 348 | }, |
| 349 | }, |
| 350 | }, |
| 351 | StorageClassName: *pvc.Spec.StorageClassName, |
| 352 | PersistentVolumeReclaimPolicy: *storageClass.ReclaimPolicy, |
| 353 | }, |
| 354 | } |
| 355 | |
| Serge Bazanski | c2c7ad9 | 2020-07-13 17:20:09 +0200 | [diff] [blame] | 356 | _, err = p.Kubernetes.CoreV1().PersistentVolumes().Create(context.Background(), vol, metav1.CreateOptions{}) |
| 357 | if err != nil && !apierrs.IsAlreadyExists(err) { |
| Lorenz Brun | b15abad | 2020-04-16 11:17:12 +0200 | [diff] [blame] | 358 | return fmt.Errorf("failed to create PV object: %w", err) |
| 359 | } |
| 360 | return nil |
| 361 | } |
| 362 | |
| Serge Bazanski | 216fe7b | 2021-05-21 18:36:16 +0200 | [diff] [blame] | 363 | // processPV looks at a single PV item from the queue and checks if it has been |
| 364 | // released and needs to be deleted. If yes it deletes the associated quota, |
| 365 | // directory and the PV object and logs the result to the recorder. |
| Serge Bazanski | c2c7ad9 | 2020-07-13 17:20:09 +0200 | [diff] [blame] | 366 | func (p *csiProvisionerServer) processPV(key string) error { |
| Lorenz Brun | b15abad | 2020-04-16 11:17:12 +0200 | [diff] [blame] | 367 | _, name, err := cache.SplitMetaNamespaceKey(key) |
| 368 | if err != nil { |
| 369 | return fmt.Errorf("invalid resource key: %s", key) |
| 370 | } |
| 371 | pv, err := p.pvInformer.Lister().Get(name) |
| 372 | if apierrs.IsNotFound(err) { |
| 373 | return nil // nothing to do, no error |
| 374 | } else if err != nil { |
| 375 | return fmt.Errorf("failed to get PV for processing: %w", err) |
| 376 | } |
| 377 | |
| 378 | if !p.isOurPV(pv) { |
| 379 | return nil |
| 380 | } |
| 381 | if pv.Spec.PersistentVolumeReclaimPolicy != v1.PersistentVolumeReclaimDelete || pv.Status.Phase != "Released" { |
| 382 | return nil |
| 383 | } |
| Serge Bazanski | c2c7ad9 | 2020-07-13 17:20:09 +0200 | [diff] [blame] | 384 | volumePath := p.volumePath(pv.Spec.CSI.VolumeHandle) |
| Lorenz Brun | b15abad | 2020-04-16 11:17:12 +0200 | [diff] [blame] | 385 | |
| 386 | // Log deletes for auditing purposes |
| Serge Bazanski | c735967 | 2020-10-30 16:38:57 +0100 | [diff] [blame] | 387 | p.logger.Infof("Deleting persistent volume %s", pv.Spec.CSI.VolumeHandle) |
| Lorenz Brun | 3705012 | 2021-03-30 14:00:27 +0200 | [diff] [blame] | 388 | switch *pv.Spec.VolumeMode { |
| 389 | case "", v1.PersistentVolumeFilesystem: |
| 390 | if err := fsquota.SetQuota(volumePath, 0, 0); err != nil { |
| Serge Bazanski | 216fe7b | 2021-05-21 18:36:16 +0200 | [diff] [blame] | 391 | // We record these here manually since a successful deletion |
| 392 | // removes the PV we'd be attaching them to. |
| Lorenz Brun | 3705012 | 2021-03-30 14:00:27 +0200 | [diff] [blame] | 393 | p.recorder.Eventf(pv, v1.EventTypeWarning, "DeprovisioningFailed", "Failed to remove quota: %v", err) |
| 394 | return fmt.Errorf("failed to remove quota: %w", err) |
| 395 | } |
| 396 | if err := os.RemoveAll(volumePath); err != nil && !os.IsNotExist(err) { |
| 397 | p.recorder.Eventf(pv, v1.EventTypeWarning, "DeprovisioningFailed", "Failed to delete volume: %v", err) |
| 398 | return fmt.Errorf("failed to delete volume: %w", err) |
| 399 | } |
| 400 | case v1.PersistentVolumeBlock: |
| 401 | if err := os.Remove(volumePath); err != nil && !os.IsNotExist(err) { |
| 402 | p.recorder.Eventf(pv, v1.EventTypeWarning, "DeprovisioningFailed", "Failed to delete volume: %v", err) |
| 403 | return fmt.Errorf("failed to delete volume: %w", err) |
| 404 | } |
| 405 | default: |
| 406 | p.recorder.Eventf(pv, v1.EventTypeWarning, "DeprovisioningFailed", "Invalid volume mode \"%v\"", *pv.Spec.VolumeMode) |
| 407 | return fmt.Errorf("invalid volume mode \"%v\"", *pv.Spec.VolumeMode) |
| Lorenz Brun | b15abad | 2020-04-16 11:17:12 +0200 | [diff] [blame] | 408 | } |
| 409 | |
| Serge Bazanski | c2c7ad9 | 2020-07-13 17:20:09 +0200 | [diff] [blame] | 410 | err = p.Kubernetes.CoreV1().PersistentVolumes().Delete(context.Background(), pv.Name, metav1.DeleteOptions{}) |
| Lorenz Brun | b15abad | 2020-04-16 11:17:12 +0200 | [diff] [blame] | 411 | if err != nil && !apierrs.IsNotFound(err) { |
| 412 | p.recorder.Eventf(pv, v1.EventTypeWarning, "DeprovisioningFailed", "Failed to delete PV object from K8s API: %v", err) |
| 413 | return fmt.Errorf("failed to delete PV object: %w", err) |
| 414 | } |
| 415 | return nil |
| 416 | } |