Merge pull request 'Fix kea CrashLoopBackOff: render socket paths under /var/run/kea' (#3) from benvin/fix-runstatedir-path into main
ci/woodpecker/tag/docker Pipeline was successful

Reviewed-on: #3
This commit was merged in pull request #3.
This commit is contained in:
2026-08-08 18:15:06 +10:00
3 changed files with 23 additions and 3 deletions
+1 -1
View File
@@ -13,7 +13,7 @@ RUN dnf -y install epel-release \
&& dnf -y install kea kea-hooks \ && dnf -y install kea kea-hooks \
&& dnf clean all \ && dnf clean all \
&& rm -rf /var/cache/dnf \ && rm -rf /var/cache/dnf \
&& mkdir -p /run/kea && mkdir -p /var/run/kea
EXPOSE 67/udp 8000/tcp EXPOSE 67/udp 8000/tcp
# Command is supplied by the operator (per-container entrypoint scripts). # Command is supplied by the operator (per-container entrypoint scripts).
+17
View File
@@ -231,4 +231,21 @@ func TestRenderCtrlAgent(t *testing.T) {
t.Errorf("ctrl-agent config missing %q", m) t.Errorf("ctrl-agent config missing %q", m)
} }
} }
// Kea 2.6+ only accepts unix socket paths under /var/run/kea (exact string).
if !strings.Contains(out, `"socket-name": "/var/run/kea/`) {
t.Errorf("ctrl-agent socket-name must be under /var/run/kea, got: %s", out)
}
}
func TestControlSocketPathAllowedByKea(t *testing.T) {
if !strings.HasPrefix(CtrlSocketPath, "/var/run/kea/") {
t.Errorf("CtrlSocketPath %q must live under /var/run/kea (kea 2.6+ restriction)", CtrlSocketPath)
}
out, err := RenderDHCP4(referenceInput())
if err != nil {
t.Fatal(err)
}
if !strings.Contains(out, `"socket-name": "/var/run/kea/`) {
t.Errorf("dhcp4 control-socket must be under /var/run/kea, got: %s", out)
}
} }
+5 -2
View File
@@ -10,8 +10,11 @@ const (
// ConfigDir is where projected config is mounted read-only. // ConfigDir is where projected config is mounted read-only.
ConfigDir = "/etc/kea-operator" ConfigDir = "/etc/kea-operator"
// RunDir is a shared emptyDir for the config copy and control socket. // RunDir is a shared emptyDir for the config copy and control socket. Kea
RunDir = "/run/kea" // 2.6+ restricts unix socket paths to its compiled runstatedir and rejects
// anything else by exact string ("supported path is '/var/run/kea'"), even
// though /var/run symlinks to /run, so this must be the literal /var/run/kea.
RunDir = "/var/run/kea"
// DHCP4ConfPath is the runtime kea-dhcp4 config. // DHCP4ConfPath is the runtime kea-dhcp4 config.
DHCP4ConfPath = RunDir + "/kea-dhcp4.conf" DHCP4ConfPath = RunDir + "/kea-dhcp4.conf"