/
externalip_controller.go
372 lines (325 loc) · 14 KB
/
externalip_controller.go
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
/*
Copyright 2021.
Licensed under the Apache License, Version 2.0 (the "License");
you may not use this file except in compliance with the License.
You may obtain a copy of the License at
http://www.apache.org/licenses/LICENSE-2.0
Unless required by applicable law or agreed to in writing, software
distributed under the License is distributed on an "AS IS" BASIS,
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
See the License for the specific language governing permissions and
limitations under the License.
*/
package controllers
import (
"context"
"encoding/json"
"fmt"
"time"
"github.com/go-logr/logr"
"github.com/google/uuid"
corev1 "k8s.io/api/core/v1"
"k8s.io/apimachinery/pkg/api/errors"
"k8s.io/apimachinery/pkg/runtime"
"k8s.io/apimachinery/pkg/types"
"k8s.io/apimachinery/pkg/util/strategicpatch"
ctrl "sigs.k8s.io/controller-runtime"
"sigs.k8s.io/controller-runtime/pkg/client"
"sigs.k8s.io/controller-runtime/pkg/handler"
"sigs.k8s.io/controller-runtime/pkg/reconcile"
"sigs.k8s.io/controller-runtime/pkg/source"
"github.com/quortex/kubestatic/api/v1alpha1"
"github.com/quortex/kubestatic/pkg/helper"
"github.com/quortex/kubestatic/pkg/provider"
)
const (
// externalIPFinalizer is a finalizer for ExternalIP
externalIPFinalizer = "externalip.finalizers.kubestatic.quortex.io"
)
// ExternalIPReconciler reconciles a ExternalIP object
type ExternalIPReconciler struct {
client.Client
Log logr.Logger
Scheme *runtime.Scheme
Provider provider.Provider
}
//+kubebuilder:rbac:groups=kubestatic.quortex.io,resources=externalips,verbs=get;list;watch;create;update;patch;delete
//+kubebuilder:rbac:groups=kubestatic.quortex.io,resources=externalips/status,verbs=get;update;patch
//+kubebuilder:rbac:groups=kubestatic.quortex.io,resources=externalips/finalizers,verbs=update
//+kubebuilder:rbac:groups=core,resources=nodes,verbs=get;list;watch;update;patch
// Reconcile is part of the main kubernetes reconciliation loop which aims to
// move the current state of the cluster closer to the desired state.
func (r *ExternalIPReconciler) Reconcile(ctx context.Context, req ctrl.Request) (ctrl.Result, error) {
log := r.Log.WithValues("externalip", req.NamespacedName, "reconciliationID", uuid.New().String())
log.V(1).Info("ExternalIP reconciliation started")
defer log.V(1).Info("ExternalIP reconciliation done")
externalIP := &v1alpha1.ExternalIP{}
if err := r.Get(ctx, req.NamespacedName, externalIP); err != nil {
if errors.IsNotFound(err) {
// Request object not found, could have been deleted after reconcile request.
// Return and don't requeue
log.Info("ExternalIP resource not found. Ignoring since object must be deleted")
return ctrl.Result{}, nil
}
// Error reading the object - requeue the request.
log.Error(err, "Failed to get ExternalIP")
return ctrl.Result{}, err
}
if externalIP.Spec.DisableReconciliation {
log.Info("Reconciliation disabled")
return ctrl.Result{}, nil
}
// Lifecycle reconciliation
if externalIP.ObjectMeta.DeletionTimestamp.IsZero() {
return r.reconcileExternalIP(ctx, log, externalIP)
}
// Deletion reconciliation
return r.reconcileExternalIPDeletion(ctx, log, externalIP)
}
func (r *ExternalIPReconciler) reconcileExternalIP(ctx context.Context, log logr.Logger, externalIP *v1alpha1.ExternalIP) (ctrl.Result, error) {
// 1st STEP
//
// Add finalizer
if !helper.ContainsString(externalIP.ObjectMeta.Finalizers, externalIPFinalizer) {
externalIP.ObjectMeta.Finalizers = append(externalIP.ObjectMeta.Finalizers, externalIPFinalizer)
log.V(1).Info("Updating ExternalIP", "finalizer", externalIPFinalizer)
return ctrl.Result{}, r.Update(ctx, externalIP)
}
// 2nd STEP
//
// Reserve external IP address
if externalIP.Status.State == v1alpha1.ExternalIPStateNone {
// Create external address
res, err := r.Provider.CreateAddress(ctx)
if err != nil {
log.Error(err, "Failed to create address")
return ctrl.Result{}, err
}
log.Info("Created address", "id", res.AddressID, "publicIP", res.PublicIP)
// Update status
externalIP.Status.State = v1alpha1.ExternalIPStateReserved
externalIP.Status.AddressID = &res.AddressID
externalIP.Status.PublicIPAddress = &res.PublicIP
log.V(1).Info("Updating ExternalIP", "state", externalIP.Status.State, "addressID", externalIP.Status.AddressID, "PublicIPAddress", externalIP.Status.PublicIPAddress)
return ctrl.Result{RequeueAfter: time.Second * 5}, r.Status().Update(ctx, externalIP)
}
// 3rd STEP
//
// Finally associate external ip to instance network interface.
// This must be the last step, since this exposes the instance on the outside.
if externalIP.IsReserved() {
if externalIP.Spec.NodeName != "" {
// Get node from ExternalIP spec
var node corev1.Node
if err := r.Get(ctx, types.NamespacedName{Name: externalIP.Spec.NodeName}, &node); err != nil {
if errors.IsNotFound(err) {
// Invalid nodeName, remove ExternalIP nodeName attribute.
log.Info("Node not found. Removing it from ExternalIP spec", "nodeName", externalIP.Spec.NodeName)
externalIP.Spec.NodeName = ""
return ctrl.Result{}, r.Update(ctx, externalIP)
}
// Error reading the object - requeue the request.
log.Error(err, "Failed to get Node")
return ctrl.Result{}, err
}
// Retrieve node instance
instanceID := r.Provider.GetInstanceID(node)
res, err := r.Provider.GetInstance(ctx, instanceID)
if err != nil {
log.Error(err, "Failed to get instance", "id", instanceID)
return ctrl.Result{}, err
}
// Interface with index 0 is the first attached to node, the one we're interested in.
// Each instance has a default network interface, called the primary network interface.
// You cannot detach a primary network interface from an instance.
var networkInterface *provider.NetworkInterface
for _, elem := range res.NetworkInterfaces {
if elem != nil && *elem.DeviceID == 0 {
networkInterface = elem
break
}
}
if networkInterface == nil {
err := fmt.Errorf("no network interface with public IP found for instance %s", instanceID)
log.Error(err, "Cannot associate an address with this instance", "instanceID", instanceID)
return ctrl.Result{}, err
}
// Finally, associate address to instance network interface, then update status.
if err := r.Provider.AssociateAddress(ctx, provider.AssociateAddressRequest{
AddressID: *externalIP.Status.AddressID,
NetworkInterfaceID: networkInterface.NetworkInterfaceID,
}); err != nil {
log.Error(err, "Failed to associate address", "addressID", *externalIP.Status.AddressID, "instanceID", instanceID, "networkInterfaceID", networkInterface.NetworkInterfaceID)
return ctrl.Result{}, err
}
log.Info("Associated address", "addressID", *externalIP.Status.AddressID, "instanceID", instanceID, "networkInterfaceID", networkInterface.NetworkInterfaceID)
// Update status
externalIP.Status.State = v1alpha1.ExternalIPStateAssociated
externalIP.Status.InstanceID = &instanceID
log.V(1).Info("Updating ExternalIP", "state", externalIP.Status.State, "InstanceID", externalIP.Status.InstanceID)
return ctrl.Result{RequeueAfter: time.Second * 5}, r.Status().Update(ctx, externalIP)
}
// No spec.nodeName, no association, end reconciliation for ExternalIP.
log.V(1).Info("No No spec.nodeName, no association, end reconciliation for ExternalIP.")
return ctrl.Result{}, nil
}
// ExternalIP reliability check
//
// Check if the associated node still exists and disassociate it if it does not.
// No nodeName or no living node, set state back to "Reserved"
if externalIP.IsAssociated() {
if externalIP.Spec.NodeName != "" {
// Get node from ExternalIP spec
var node corev1.Node
if err := r.Get(ctx, types.NamespacedName{Name: externalIP.Spec.NodeName}, &node); err != nil {
if errors.IsNotFound(err) {
// Invalid nodeName, remove ExternalIP nodeName attribute.
log.Info("Node not found. Removing it from ExternalIP spec", "nodeName", externalIP.Spec.NodeName)
// Set status back to Reserved
externalIP.Status.State = v1alpha1.ExternalIPStateReserved
log.V(1).Info("Updating ExternalIP", "state", externalIP.Status.State, "InstanceID", externalIP.Status.InstanceID)
if err = r.Status().Update(ctx, externalIP); err != nil {
log.Error(err, "Failed to update ExternalIP status", "externalIP", externalIP.Name, "status", externalIP.Status.State)
return ctrl.Result{}, err
}
externalIP.Spec.NodeName = ""
return ctrl.Result{}, r.Update(ctx, externalIP)
}
// Error reading the object - requeue the request.
log.Error(err, "Failed to get Node")
return ctrl.Result{}, err
}
// Node not being deleted, reconcile externalip label
if node.ObjectMeta.DeletionTimestamp.IsZero() {
// Marshal node, ...
old, err := json.Marshal(node)
if err != nil {
log.Error(err, "Failed to marshal node")
return ctrl.Result{}, err
}
// ... then compute new node to marshal it...
node.Labels[externalIPLabel] = *externalIP.Status.PublicIPAddress
new, err := json.Marshal(node)
if err != nil {
log.Error(err, "Failed to marshal new node")
return ctrl.Result{}, err
}
// ... and create a patch.
patch, err := strategicpatch.CreateTwoWayMergePatch(old, new, node)
if err != nil {
log.Error(err, "Failed to create patch for node")
return ctrl.Result{}, err
}
// Apply patch to set node's wanted labels.
if err = r.Client.Patch(ctx, &node, client.RawPatch(types.MergePatchType, patch)); err != nil {
log.Error(err, "Failed to patch node")
return ctrl.Result{}, err
}
return ctrl.Result{}, nil
}
}
// Set state back to "Reserved", disassociate address and end reconciliation
return r.disassociateAddress(ctx, r.Provider, log, externalIP)
}
return ctrl.Result{}, nil
}
func (r *ExternalIPReconciler) reconcileExternalIPDeletion(ctx context.Context, log logr.Logger, externalIP *v1alpha1.ExternalIP) (ctrl.Result, error) {
// 1st STEP
//
// Reconciliation of a possible external IP associated with the instance.
// If an IP is associated with the instance, disassociate it.
if externalIP.IsAssociated() {
return r.disassociateAddress(ctx, r.Provider, log, externalIP)
}
// 2nd STEP
//
// Release unassociated address.
if externalIP.IsReserved() {
// Do not delete EIP if flag PreventEIPDeallocation is set
if externalIP.Status.AddressID != nil && !externalIP.Spec.PreventEIPDeallocation {
if err := r.Provider.DeleteAddress(ctx, *externalIP.Status.AddressID); err != nil {
if !provider.IsErrNotFound(err) {
log.Error(err, "Failed to delete Address", "addressID", *externalIP.Status.AddressID)
return ctrl.Result{}, err
}
log.V(1).Info("Address not found", "addressID", *externalIP.Status.AddressID)
}
log.Info("Deleted Address", "addressID", *externalIP.Status.AddressID)
// Update status
externalIP.Status.AddressID = nil
}
// set State to None for finalizer to delete externalIP object
externalIP.Status.State = v1alpha1.ExternalIPStateNone
log.V(1).Info("Updating ExternalIP", "state", externalIP.Status.State)
return ctrl.Result{RequeueAfter: time.Second * 5}, r.Status().Update(ctx, externalIP)
}
// 3rd STEP
//
// Remove finalizer to release ExternalIP
if externalIP.Status.State == v1alpha1.ExternalIPStateNone {
if helper.ContainsString(externalIP.Finalizers, externalIPFinalizer) {
externalIP.Finalizers = helper.RemoveString(externalIP.Finalizers, externalIPFinalizer)
return ctrl.Result{}, r.Update(ctx, externalIP)
}
}
return ctrl.Result{}, nil
}
// disassociateAddress performs address disassociation tasks
func (r *ExternalIPReconciler) disassociateAddress(ctx context.Context, pvd provider.Provider, log logr.Logger, externalIP *v1alpha1.ExternalIP) (ctrl.Result, error) {
// Get address and disassociate it
if externalIP.Status.AddressID != nil {
res, err := pvd.GetAddress(ctx, *externalIP.Status.AddressID)
if err != nil {
log.Error(err, "Failed to retrieve address", "addressID", *externalIP.Status.AddressID)
return ctrl.Result{}, err
}
if res.AssociationID != nil {
if err := pvd.DisassociateAddress(ctx, provider.DisassociateAddressRequest{
AssociationID: *res.AssociationID,
}); err != nil {
log.Error(err, "Failed to disassociate address", "addressID", *externalIP.Status.AddressID, "instanceID", *externalIP.Status.InstanceID)
return ctrl.Result{}, err
}
log.Info("Disassociated address", "addressID", *externalIP.Status.AddressID, "instanceID", *externalIP.Status.InstanceID)
}
}
// Update status
externalIP.Status.State = v1alpha1.ExternalIPStateReserved
externalIP.Status.InstanceID = nil
log.V(1).Info("Updating ExternalIP", "state", externalIP.Status.State)
if err := r.Status().Update(ctx, externalIP); err != nil {
log.Error(err, "Failed to update ExternalIP state", "externalIP", externalIP.Name)
return ctrl.Result{}, err
}
log.V(1).Info("Removing ExternalIP NodeName", "externalIP", externalIP.Name)
externalIP.Spec.NodeName = ""
return ctrl.Result{}, r.Update(ctx, externalIP)
}
// SetupWithManager sets up the controller with the Manager.
func (r *ExternalIPReconciler) SetupWithManager(mgr ctrl.Manager) error {
return ctrl.NewControllerManagedBy(mgr).
For(&v1alpha1.ExternalIP{}).
Watches(
&source.Kind{Type: &corev1.Node{}},
handler.EnqueueRequestsFromMapFunc(func(o client.Object) []reconcile.Request {
ctx := context.Background()
log := r.Log.WithName("nodemapper")
node := o.(*corev1.Node)
log.V(1).Info("List all ExternalIP")
externalIPs := &v1alpha1.ExternalIPList{}
if err := r.Client.List(ctx, externalIPs); err != nil {
log.Error(err, "Unable to list ExternalIP resources", "nodeName", node.Name)
return []reconcile.Request{}
}
// Reconcile each matching ExternalIP
res := []reconcile.Request{}
for _, eip := range externalIPs.Items {
if eip.Spec.NodeName == node.Name {
res = append(res, reconcile.Request{NamespacedName: types.NamespacedName{Name: eip.Name}})
}
}
return res
}),
).
Complete(r)
}