Scaffold kea-operator: CRDs, controllers, config rendering, REST API, CI
Replace the ISC dhcpd PXE-boot VM with a Kea DHCP Kubernetes operator, modelled on bind-operator. The operator renders kea-dhcp4 config from CRs and runs an HA pair of kea-dhcp4 + kea-ctrl-agent servers behind an anycast Service. - add KeaCluster/KeaSubnet/KeaClientClass/KeaAPI CRDs (group kea.unkin.net) - render deterministic kea-dhcp4.conf + kea-ctrl-agent.conf into a ConfigMap and roll the StatefulSet via a config-hash annotation; best-effort hot-reload via the kea-ctrl-agent REST channel - run HA hot-standby (memfile leases) with stable per-peer DNS identity from a StatefulSet; expose an anycast LoadBalancer Service for PureLB - represent the full legacy dhcpd config: 198.18.13-17.0/24 pools, pool-less 198.18.25.0/24, and the Legacy/UEFI-64 PXE arch classes (option 93) - add the KeaAPI-spawned REST service: Terraform-friendly CRUD over subnet and client-class CRs (stable IDs, PUT upsert, 404 drift, bearer-token auth) - add Makefile (patch/minor/major tag targets), distroless operator/api images, an AlmaLinux+EPEL kea workload image, and woodpecker CI with k8s resources + serviceAccountName on every step - unit tests for config rendering, controller reconcile/config-hash, and the API Claude-Session: https://claude.ai/code/session_01JUoARVdmhxKQHyyyp1pxeT
This commit is contained in:
@@ -0,0 +1,51 @@
|
||||
package kea
|
||||
|
||||
import "fmt"
|
||||
|
||||
type ctrlAgentRoot struct {
|
||||
ControlAgent controlAgent `json:"Control-agent"`
|
||||
}
|
||||
|
||||
type controlAgent struct {
|
||||
HTTPHost string `json:"http-host"`
|
||||
HTTPPort int `json:"http-port"`
|
||||
ControlSockets map[string]map[string]any `json:"control-sockets"`
|
||||
Loggers []logger `json:"loggers"`
|
||||
}
|
||||
|
||||
// RenderCtrlAgent renders the deterministic kea-ctrl-agent.conf JSON. The
|
||||
// control agent exposes the HA/REST control channel on CtrlAgentPort and
|
||||
// forwards to kea-dhcp4 over the shared unix socket.
|
||||
func RenderCtrlAgent() (string, error) {
|
||||
return marshal(ctrlAgentRoot{ControlAgent: controlAgent{
|
||||
HTTPHost: "0.0.0.0",
|
||||
HTTPPort: CtrlAgentPort,
|
||||
ControlSockets: map[string]map[string]any{
|
||||
"dhcp4": {"socket-type": "unix", "socket-name": CtrlSocketPath},
|
||||
},
|
||||
Loggers: loggers("kea-ctrl-agent"),
|
||||
}})
|
||||
}
|
||||
|
||||
// EntrypointDHCP4 is the kea-dhcp4 container entrypoint. It derives this pod's
|
||||
// HA peer name from the StatefulSet ordinal, substitutes the placeholder in the
|
||||
// projected config, and execs the server.
|
||||
func EntrypointDHCP4() string {
|
||||
return fmt.Sprintf(`#!/bin/sh
|
||||
set -e
|
||||
ORD="${HOSTNAME##*-}"
|
||||
mkdir -p %[1]s
|
||||
sed "s/%[2]s/server${ORD}/g" %[3]s/kea-dhcp4.conf > %[4]s
|
||||
exec %[5]s -c %[4]s
|
||||
`, RunDir, ThisServerPlaceholder, ConfigDir, DHCP4ConfPath, DHCP4Bin)
|
||||
}
|
||||
|
||||
// EntrypointCtrlAgent is the kea-ctrl-agent container entrypoint.
|
||||
func EntrypointCtrlAgent() string {
|
||||
return fmt.Sprintf(`#!/bin/sh
|
||||
set -e
|
||||
mkdir -p %[1]s
|
||||
cp %[2]s/kea-ctrl-agent.conf %[3]s
|
||||
exec %[4]s -c %[3]s
|
||||
`, RunDir, ConfigDir, CtrlAgentConfPath, CtrlAgentBin)
|
||||
}
|
||||
Reference in New Issue
Block a user