Move kea entrypoints out of Go fmt.Sprintf into an initContainer
Container entrypoints were rendered as `fmt.Sprintf` shell strings in Go, so every entrypoint fix needed a full operator release, nothing was shellcheckable, and the escaping was a hazard. How: - Add a `kea-init` initContainer that finalises the per-pod config and bounded-waits for HA peer DNS, replacing the in-entrypoint retry. It hardens the shared run dir to 0750, substitutes `this-server-name` from the pod ordinal (`POD_NAME` via the downward API), stages both configs into the shared emptyDir, and gates on `kea-dhcp4 -t` (60x2s) — failing loud after the cap so the kubelet restarts it instead of starting a doomed server. - Run the main kea-dhcp4 / kea-ctrl-agent containers with kea exec'd directly, dropping both wrapper shells. - Replace the two `fmt.Sprintf` entrypoints with a single committed `internal/kea/scripts/init.sh` embedded via `go:embed` and parameterised entirely by env vars — no Go string interpolation. - Add a shellcheck step to the pre-commit pipeline. Test: - Assert the pod shape: one kea-init initContainer, POD_NAME from the downward API, main containers exec kea directly, and the ConfigMap carries init.sh (not the old per-container entrypoints). - Assert init.sh hardens the socket dir, gates on `kea-dhcp4 -t`, fails loud after the cap, and is free of fmt verbs. - shellcheck the embedded script.
This commit is contained in:
@@ -35,9 +35,18 @@ Kea HA needs a **stable per-peer identity** (each server must know which peer it
|
||||
is, and peers reference each other by stable URL). That is exactly why this
|
||||
operator (like bind-operator) uses a **StatefulSet** rather than a bare
|
||||
Deployment: pods get stable ordinals (`<cluster>-0`, `<cluster>-1`) and headless
|
||||
DNS, the entrypoint derives `this-server-name` from the ordinal, and the peer
|
||||
DNS, an initContainer derives `this-server-name` from the ordinal, and the peer
|
||||
URLs are DNS names (never pod IPs, so the config hash never loops).
|
||||
|
||||
Startup preconditions live in a `kea-init` initContainer (a committed,
|
||||
shellcheck-clean `internal/kea/scripts/init.sh` embedded via `go:embed` and
|
||||
parameterised by env vars — no shell is interpolated in Go). It hardens the
|
||||
shared run dir to `0750`, substitutes `this-server-name` from the pod ordinal,
|
||||
stages both configs into the shared `emptyDir`, and bounded-waits for the HA
|
||||
peer DNS to resolve (`kea-dhcp4 -t`, failing loud after the cap so the kubelet
|
||||
restarts it). The main `kea-dhcp4` and `kea-ctrl-agent` containers then exec kea
|
||||
directly with no wrapper shell.
|
||||
|
||||
### Anycast routing caveat (deployment follow-up)
|
||||
|
||||
The DHCP `Service` is a `LoadBalancer` intended to receive a PureLB anycast IP;
|
||||
|
||||
Reference in New Issue
Block a user