skip the PodListeners lookup when the served Pod is being deleted
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 3/5
- Thời gian dự kiến
- 1-2 ngày
- Mức phù hợp với người mới
- 72/100
- Loại issue
- Lỗi
- Độ rõ ràng
- Đặc tả rõ ràng
- Mức độ hoạt động
- Sôi nổi
- Công nghệ
- kubernetes, rust
- Lĩnh vực
- infrastructure
Hướng nghiên cứu
Bắt đầu từ entry point NodePublishVolume và theo dõi cách deletionTimestamp của Pod được phục vụ và PodListeners được xử lý trước khi tạo chứng chỉ. Kiểm tra việc tra cứu PodListeners hiện có và đường dẫn chứng chỉ, sau đó xác nhận rằng các Pod đã bị xóa sẽ bỏ qua việc tra cứu, trong khi các Pod đang hoạt động vẫn giữ nguyên hành vi hiện tại và mount hoàn tất mà không có listener SANs.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Problem
The secret-operator needs to read PodListeners in order to retrieve additional listener addresses to generate into the SAN field of certificates it creates. It has a long timeout waiting for these objects to appear, when a pod is spawned and requests the listener scope on certificates.
Especially during namespace deletion (maybe at other times as well) this can become a problem, when the PodListeners get deleted and the secret operator waits for them indefinitely. Since this is part of the NodePublishVolume step, this results in the Pod being stuck and holding pvc-protection.
Fix
In NodePublishVolume, if the Pod the volume serves has a deletionTimestamp, skip the
PodListeners lookup and issue the (throwaway) certificate without listener SANs so the mount can
complete. A Pod that is being deleted does not need listener-addressed certs.
The startup/steady-state path is unchanged: live Pods still wait for their listener addresses, so no
correctness regression and no startup race, the guard only relaxes behaviour for Pods already
marked for deletion.
- Ngôn ngữ chính
- Rust
- Star
- 13
- Fork
- 8
- Merge trung bình
- 1 ngày 8 giờ
- Pull request đã merge (30 ngày)
- 10
Hướng dẫn đóng góp
Chưa lập chỉ mục được hướng dẫn đóng góp cho kho mã nguồn này
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của stackabletech/secret-operator
-
type/bug
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 45/100
stackabletech/secret-operator#754 ·
-
Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 48/100
stackabletech/secret-operator#753 · 1 bình luận ·
-
customer-request type/bug
Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 38/100
stackabletech/secret-operator#666 · 2 bình luận ·
-
customer-request type/feature-improvement
stackabletech/secret-operator#630 · 7 bình luận · 1 người được giao ·
-
stackabletech/secret-operator#620 · 2 bình luận · 1 người được giao ·
Tất cả issue của stackabletech/secret-operator
Issue tương tự
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 75/100
-
state:needs triage
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 70/100
zed-industries/zed#64680 · 2 bình luận ·
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 70/100
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 70/100
RustPython/RustPython#8802 ·
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 75/100
TheLarkInn/aipm#2390 ·