RobotLB detection in cozy-lib reads a key nothing writes, so nodePorts are disabled on every cluster
I maintainer di solito rispondono entro 2 giorni
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 4/5
- Tempo stimato
- 3-5 giorni
- Idoneità per principianti
- 45/100
- Tipo di issue
- Bug
- Chiarezza
- Abbastanza chiara
- Stato di attività
- Attiva
- Stack tecnologico
- helm, kubernetes
- Ambito
- infrastructure, networking
Direzione di ricerca
Start with packages/library/cozy-lib/templates/_network.tpl and trace how cozy-lib.network.disableLoadBalancerNodePorts gets its values from _cluster, rendered in packages/core/platform/templates/apps.yaml. Compare the available cluster values with how RobotLB is enabled through bundles.enabledPackages; the issue proposes publishing the active load balancer or detecting its Package. Done means the helper uses a signal that exists in v1.6 and keeps nodePorts enabled for RobotLB services.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
What happens
cozy-lib.network.disableLoadBalancerNodePorts is meant to keep nodePorts allocated when RobotLB is the load balancer, because RobotLB cannot work without them. It never does: on every 1.6 cluster it returns true and nodePorts are switched off, RobotLB or not.
The detection reads a key that nothing writes any more.
packages/library/cozy-lib/templates/_network.tpl:
{{- define "cozy-lib.network.disableLoadBalancerNodePorts" }}
{{- include "cozy-lib.loadCozyConfig" (list "" .) }}
{{- $cozyConfig := index . "cozyConfig" }}
{{- if not $cozyConfig }}
{{- include "cozy-lib.network.defaultDisableLoadBalancerNodePorts" . }}
{{- else }}
{{- $enabledComponents := splitList "," ((index $cozyConfig.data "bundle-enable") | default "") }}
{{- not (has "robotlb" $enabledComponents) }}
{{- end }}
{{- end }}
loadCozyConfig does not load a ConfigMap, it aliases the platform values channel:
{{- $_ := set (index . 1) "cozyConfig" (dict "data" ((index . 1).Values._cluster | default dict)) }}
_cluster is rendered by packages/core/platform/templates/apps.yaml and carries root-host, bundle-name, solver, issuer-name, wildcard-secret-name, the dns01-* keys and so on. It has never carried bundle-enable, which is a 0.x ConfigMap key: git grep bundle-enable across the tree hits only this template, two changelogs and hack/migrate-to-version-1.0.sh. Nothing writes it.
So the else branch evaluates splitList "," "", which is [""], has "robotlb" [""] is false, and the helper returns true. The if not $cozyConfig branch would return true as well. Both paths disable nodePorts unconditionally.
Enabling RobotLB through bundles.enabledPackages as the Hetzner install guide documents has no effect on this, because that list never reaches _cluster under any spelling.
Why it matters
Six shipped applications gate allocateLoadBalancerNodePorts: false on this helper:
packages/apps/http-cache/templates/haproxy/service.yaml
packages/apps/mongodb/templates/external-svc.yaml
packages/apps/postgres/templates/external-svc.yaml
packages/apps/redis/templates/service.yaml
packages/apps/tcp-balancer/templates/service.yaml
packages/apps/vm-instance/templates/service.yaml
On a Hetzner cluster every one of them renders allocateLoadBalancerNodePorts: false, and RobotLB then skips the service: its README states that a port is only reachable through its nodePort, that ports without one are skipped, and that allocateLoadBalancerNodePorts: false is not supported. So exposing Postgres, Redis, MongoDB, a TCP balancer or a VM externally silently produces a Service that never gets an address.
The failure gives the operator nothing to work with. The chart renders, the HelmRelease goes Ready, the Service sits in <pending>, and the RobotLB logs do not mention the service at all, because it was filtered out before anything was attempted.
Suggested fix
The helper needs a signal that exists in 1.6. Two directions:
- Have the platform publish the active load balancer on the
_clusterchannel, the same way it publishessolverandissuer-name, and key the helper off that. It fits the existing mechanism and stays declarative. - Failing that, detect RobotLB from something observable at render time, such as the presence of its Package, rather than from a values key that no longer exists.
Whichever way, the legacy bundle-enable arm should go, or at least stop being the only thing that can return false.
Environment
Cozystack v1.6.4, bare metal on Hetzner, RobotLB enabled through bundles.enabledPackages: [cozystack.hetzner-robotlb] with MetalLB disabled.
- Lingua principale
- Go
- Stelle
- 2.2k
- Fork
- 209
- Merge medio
- 3g 10h
- PR unite (30g)
- 237
Preparare l'ambiente
- Nessun Dockerfile né file Docker Compose
- Ha un modello di pull request
- Leggi la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di cozystack/cozystack
-
chore(cilium): drop externalIPs.enabled and nodePort.enabled, the Cilium chart does not read themApertaarea/cilium kind/cleanup triage/needs-triage
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 82/100
cozystack/cozystack#4816 · 1 reazione ·
I maintainer di solito rispondono entro 2 giorni
-
e2e: cozyreport lists a shared zpool twice and ships an empty zfs-pools.txt that does not say whyApertatriage/needs-triage
Difficoltà 2/5 1-3 ore Idoneità per principianti 76/100
cozystack/cozystack#4809 · 1 reazione ·
I maintainer di solito rispondono entro 2 giorni
-
area/ci kind/bug triage/needs-triage
Difficoltà 2/5 1-3 ore Idoneità per principianti 85/100
cozystack/cozystack#4806 · 1 commento · 2 reazioni ·
I maintainer di solito rispondono entro 2 giorni
-
triage/needs-triage
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
cozystack/cozystack#4787 · 1 reazione ·
I maintainer di solito rispondono entro 2 giorni
-
kubernetes-nodes: raising minReplicas does not raise the MachineDeployment's replicas on upgradeApertatriage/needs-triage
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 88/100
cozystack/cozystack#4786 · 1 reazione ·
I maintainer di solito rispondono entro 2 giorni
Tutte le issue di cozystack/cozystack
Issue simili
-
agent-research agent-review-finding chore
Difficoltà 2/5 1-3 ore Idoneità per principianti 66/100
jordansmall/spindrift#4922 ·
I maintainer di solito rispondono entro 1 giorno
-
gcsartifact: deleting a missing version returns an errorForse già presa @ktsoator l’ha presa oggi. Apertabug
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
I maintainer di solito rispondono entro 2 giorni
-
govulncheck
Difficoltà 2/5 1-3 ore Idoneità per principianti 62/100
I maintainer di solito rispondono entro 1 giorno
-
Change wording for init command success messageForse già presa Una pull request collegata a questa issue è aperta o già unita. Aperta
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 82/100
I maintainer di solito rispondono entro 1 giorno
-
enhancement pkg:sdk
Difficoltà 2/5 1-3 ore Idoneità per principianti 80/100
aws/aws-durable-execution-sdk-go#144 ·
I maintainer di solito rispondono entro 1 giorno