Topology Provider permissions briefly dropped during reconciliation when the reflector watch resets
メンテナーはふだん 1 日以内に返信
まだ誰も着手していません。
評価
- 難易度
- 4/5
- 見積もり時間
- 3〜5日
- 初心者へのやさしさ
- 42/100
- issue の種類
- バグ
- 明瞭さ
- 説明が足りない
- 活発さ
- 静か
- 技術スタック
- kubernetes, rust
- 領域
- devops, infrastructure
調査の方向性
まず、HDFS operator の reconciliation path と kube-rs Reflector watcher のイベント処理を追跡します。特に Store の再構築と RoleBinding の更新を確認してください。Init、InitApply、InitDone、Apply、Delete、およびエラーイベントが現在 reconciliation にどのような影響を与えるかを確認します。完了の条件は、reconciliation が空または部分的にしか構築されていない Store に対して処理を実行できず、service-account の権限が保持され、処理が最終的に再キューされることです。
索引モデルが issue の本文から書いたものです。
説明
Affected Stackable version
Any up to and including SDP 26.3.0
Affected Apache HDFS version
N/A
Current and expected behavior
In the HDFS operator (and perhaps any operator based on kube-rs), when the Reflector watch resets, the Store has to be rebuilt.
Reconciliations before the Store is fully consistent can lead to service accounts being dropped from (Cluster)RoleBindings. The leads to the Topoology Provider not being able to determine the topology (or possibly builds an incorrect topology?)
The expected behaviour is that the above doesn't happen 😅.
Possible solution
We can requeue reconciliations (at least for some operations) until the store is fully consistent.
Eg:
- On error: log error and return early
watcher::Event::Init-> the store is empty, waiting for InitApply events, requeue/return early.watcher::Event::InitApply-> store is partially populated, requeue/return early until InitDone.watcher::Event::InitDone-> store is populated, continue with reconcilewatcher::Event::Apply-> store is populated, continue with reconcilewatcher::Event::Delete-> store is populated, continue with reconcile
[!CAUTION]
I haven't checked to see whether we can and should requeue, or just return an error which bubbles up as a Result for the error_policy handler which logs and does requeues.
Regardless, we need to make sure it eventually is reconciled and not just ignored.
Additional context
My understanding of the problem/solution should be double checked with someone else.
[!TIP]
This might only be when the topology provider is used... but also seems like something that might affect other products that have components that interact with Kubernetes API in SDP generally
Environment
No response
Would you like to work on fixing this bug?
yes
- 主要言語
- Rust
- スター
- 53
- フォーク
- 10
- 平均マージ
- 1日 5時間
- マージ済み PR(30日)
- 10
環境構築
- Dockerfile・Docker Compose ファイルなし
- プルリクエストのテンプレートあり
- コントリビューションガイドなし
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
stackabletech/hdfs-operator のほかの issue
-
type/bug
難易度 3/5 1〜2日 初心者へのやさしさ 58/100
stackabletech/hdfs-operator#773 ·
メンテナーはふだん 1 日以内に返信
-
type/internal-debt
難易度 5/5 1週間以上 初心者へのやさしさ 15/100
stackabletech/hdfs-operator#769 ·
メンテナーはふだん 1 日以内に返信
-
type/bug
難易度 3/5 1〜2日 初心者へのやさしさ 52/100
stackabletech/hdfs-operator#763 ·
メンテナーはふだん 1 日以内に返信
-
type/bug
難易度 4/5 3〜5日 初心者へのやさしさ 42/100
stackabletech/hdfs-operator#712 ·
メンテナーはふだん 1 日以内に返信
-
type/bug
難易度 3/5 1〜2日 初心者へのやさしさ 42/100
stackabletech/hdfs-operator#686 ·
メンテナーはふだん 1 日以内に返信
stackabletech/hdfs-operator の issue をすべて見る
似ている issue
-
contribution
難易度 2/5 1〜3時間 初心者へのやさしさ 76/100
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 82/100
tree-sitter/tree-sitter#6005 ·
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 90/100
-
agent:triaged bug bughunt pm:pipenv priority:p1
難易度 2/5 1〜3時間 初心者へのやさしさ 83/100
SocketDev/socket-patch#744 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 74/100
maplibre/maplibre-tile-spec#1844 ·
メンテナーはふだん 1 日以内に返信