forked from cri-o/cri-o
-
Notifications
You must be signed in to change notification settings - Fork 0
/
sandbox_network.go
98 lines (84 loc) · 2.75 KB
/
sandbox_network.go
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
package server
import (
"fmt"
"net"
cnitypes "github.com/containernetworking/cni/pkg/types"
"github.com/kubernetes-sigs/cri-o/lib/sandbox"
"github.com/sirupsen/logrus"
"k8s.io/kubernetes/pkg/kubelet/dockershim/network/hostport"
)
// networkStart sets up the sandbox's network and returns the pod IP on success
// or an error
func (s *Server) networkStart(sb *sandbox.Sandbox) (podIP string, result cnitypes.Result, err error) {
if sb.HostNetwork() {
return s.bindAddress, nil, nil
}
// Ensure network resources are cleaned up if the plugin succeeded
// but an error happened between plugin success and the end of networkStart()
defer func() {
if err != nil {
s.networkStop(sb)
}
}()
podNetwork := newPodNetwork(sb)
result, err = s.netPlugin.SetUpPod(podNetwork)
if err != nil {
err = fmt.Errorf("failed to create pod network sandbox %s(%s): %v", sb.Name(), sb.ID(), err)
return
}
logrus.Debugf("CNI setup result: %v", result)
podIP, err = s.netPlugin.GetPodNetworkStatus(podNetwork)
if err != nil {
err = fmt.Errorf("failed to get network status for pod sandbox %s(%s): %v", sb.Name(), sb.ID(), err)
return
}
if len(sb.PortMappings()) > 0 {
ip := net.ParseIP(podIP)
if ip == nil {
err = fmt.Errorf("failed to get valid ip address for sandbox %s(%s)", sb.Name(), sb.ID())
return
}
err = s.hostportManager.Add(sb.ID(), &hostport.PodPortMapping{
Name: sb.Name(),
PortMappings: sb.PortMappings(),
IP: ip,
HostNetwork: false,
}, "lo")
if err != nil {
err = fmt.Errorf("failed to add hostport mapping for sandbox %s(%s): %v", sb.Name(), sb.ID(), err)
return
}
}
return
}
// getSandboxIP retrieves the IP address for the sandbox
func (s *Server) getSandboxIP(sb *sandbox.Sandbox) (string, error) {
if sb.HostNetwork() {
return s.bindAddress, nil
}
podNetwork := newPodNetwork(sb)
ip, err := s.netPlugin.GetPodNetworkStatus(podNetwork)
if err != nil {
return "", fmt.Errorf("failed to get network status for pod sandbox %s(%s): %v", sb.Name(), sb.ID(), err)
}
return ip, nil
}
// networkStop cleans up and removes a pod's network. It is best-effort and
// must call the network plugin even if the network namespace is already gone
func (s *Server) networkStop(sb *sandbox.Sandbox) {
if !sb.HostNetwork() {
if err := s.hostportManager.Remove(sb.ID(), &hostport.PodPortMapping{
Name: sb.Name(),
PortMappings: sb.PortMappings(),
HostNetwork: false,
}); err != nil {
logrus.Warnf("failed to remove hostport for pod sandbox %s(%s): %v",
sb.Name(), sb.ID(), err)
}
podNetwork := newPodNetwork(sb)
if err := s.netPlugin.TearDownPod(podNetwork); err != nil {
logrus.Warnf("failed to destroy network for pod sandbox %s(%s): %v",
sb.Name(), sb.ID(), err)
}
}
}