Support externalTrafficPolicy on the client Service
ci/woodpecker/pr/build Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
ci/woodpecker/pr/test Pipeline was successful

Adds BindCluster.spec.service.externalTrafficPolicy so DNS LoadBalancers
can preserve client source IPs (Local), which the source-IP ACLs on the
authoritative/resolver need to actually restrict external clients (Cluster
SNATs everything to node IPs).

- api: ClusterServiceSpec.externalTrafficPolicy (enum Cluster;Local)
- set it on the client Service for LoadBalancer/NodePort types
- regenerate CRDs + install.yaml
This commit is contained in:
2026-07-04 22:15:22 +10:00
parent 547d168c12
commit e0bd3973ed
5 changed files with 30 additions and 0 deletions
+7
View File
@@ -33,6 +33,13 @@ type ClusterServiceSpec struct {
// +optional
LoadBalancerIP string `json:"loadBalancerIP,omitempty"`
// ExternalTrafficPolicy for a LoadBalancer/NodePort Service. Local preserves
// client source IPs (required for source-IP ACLs on the DNS servers) but
// only routes to nodes running a pod. Defaults to Cluster.
// +kubebuilder:validation:Enum=Cluster;Local
// +optional
ExternalTrafficPolicy corev1.ServiceExternalTrafficPolicy `json:"externalTrafficPolicy,omitempty"`
// Annotations added to the client-facing Service (e.g. PureLB/MetalLB hints).
// +optional
Annotations map[string]string `json:"annotations,omitempty"`
@@ -1094,6 +1094,15 @@ spec:
description: Annotations added to the client-facing Service (e.g.
PureLB/MetalLB hints).
type: object
externalTrafficPolicy:
description: |-
ExternalTrafficPolicy for a LoadBalancer/NodePort Service. Local preserves
client source IPs (required for source-IP ACLs on the DNS servers) but
only routes to nodes running a pod. Defaults to Cluster.
enum:
- Cluster
- Local
type: string
loadBalancerIP:
description: LoadBalancerIP requests a specific address when Type
is LoadBalancer.
+9
View File
@@ -1399,6 +1399,15 @@ spec:
description: Annotations added to the client-facing Service (e.g.
PureLB/MetalLB hints).
type: object
externalTrafficPolicy:
description: |-
ExternalTrafficPolicy for a LoadBalancer/NodePort Service. Local preserves
client source IPs (required for source-IP ACLs on the DNS servers) but
only routes to nodes running a pod. Defaults to Cluster.
enum:
- Cluster
- Local
type: string
loadBalancerIP:
description: LoadBalancerIP requests a specific address when Type
is LoadBalancer.
@@ -273,6 +273,10 @@ func (r *BindClusterReconciler) reconcileServices(ctx context.Context, c *bindv1
LoadBalancerIP: c.Spec.Service.LoadBalancerIP,
},
}
// externalTrafficPolicy is only valid for LoadBalancer/NodePort Services.
if svcType == corev1.ServiceTypeLoadBalancer || svcType == corev1.ServiceTypeNodePort {
client.Spec.ExternalTrafficPolicy = c.Spec.Service.ExternalTrafficPolicy
}
return r.upsertService(ctx, c, client)
}
+1
View File
@@ -57,6 +57,7 @@ func (r *BindClusterReconciler) upsertService(ctx context.Context, c *bindv1alph
existing.Spec.Selector = desired.Spec.Selector
existing.Spec.Type = desired.Spec.Type
existing.Spec.LoadBalancerIP = desired.Spec.LoadBalancerIP
existing.Spec.ExternalTrafficPolicy = desired.Spec.ExternalTrafficPolicy
if desired.Annotations != nil {
if existing.Annotations == nil {
existing.Annotations = map[string]string{}