f20b26fd71
## Why kea-dhcp4 crash-loops on a cold container start: the HA hook resolves the StatefulSet peer URL hostnames once at config load, but the peer DNS records are not resolvable in the first moment of a fresh container, and kea exits hard instead of retrying (HA_CONFIGURATION_FAILED / "Failed to convert string to address"). Once DNS is warm the exact config validates, so the failure is purely a startup race. ## How - gate the dhcp4 entrypoint on `kea-dhcp4 -t` and retry until the config validates before exec'ing the server
63 lines
2.0 KiB
Go
63 lines
2.0 KiB
Go
package kea
|
|
|
|
import "fmt"
|
|
|
|
type ctrlAgentRoot struct {
|
|
ControlAgent controlAgent `json:"Control-agent"`
|
|
}
|
|
|
|
type controlAgent struct {
|
|
HTTPHost string `json:"http-host"`
|
|
HTTPPort int `json:"http-port"`
|
|
ControlSockets map[string]map[string]any `json:"control-sockets"`
|
|
Loggers []logger `json:"loggers"`
|
|
}
|
|
|
|
// RenderCtrlAgent renders the deterministic kea-ctrl-agent.conf JSON. The
|
|
// control agent exposes the HA/REST control channel on CtrlAgentPort and
|
|
// forwards to kea-dhcp4 over the shared unix socket.
|
|
func RenderCtrlAgent() (string, error) {
|
|
return marshal(ctrlAgentRoot{ControlAgent: controlAgent{
|
|
HTTPHost: "0.0.0.0",
|
|
HTTPPort: CtrlAgentPort,
|
|
ControlSockets: map[string]map[string]any{
|
|
"dhcp4": {"socket-type": "unix", "socket-name": CtrlSocketPath},
|
|
},
|
|
Loggers: loggers("kea-ctrl-agent"),
|
|
}})
|
|
}
|
|
|
|
// EntrypointDHCP4 is the kea-dhcp4 container entrypoint. It derives this pod's
|
|
// HA peer name from the StatefulSet ordinal, substitutes the placeholder in the
|
|
// projected config, and execs the server.
|
|
func EntrypointDHCP4() string {
|
|
return fmt.Sprintf(`#!/bin/sh
|
|
set -e
|
|
ORD="${HOSTNAME##*-}"
|
|
mkdir -p %[1]s
|
|
chmod 0750 %[1]s
|
|
sed "s/%[2]s/server${ORD}/g" %[3]s/kea-dhcp4.conf > %[4]s
|
|
# The HA hook resolves peer URL hostnames once at load; on a cold container
|
|
# start the StatefulSet peer DNS records may not resolve yet, and kea exits
|
|
# hard instead of retrying. Wait for the config to validate before starting.
|
|
i=0
|
|
until %[5]s -t %[4]s >/dev/null 2>&1; do
|
|
i=$((i+1))
|
|
if [ "$i" -ge 60 ]; then break; fi
|
|
sleep 2
|
|
done
|
|
exec %[5]s -c %[4]s
|
|
`, RunDir, ThisServerPlaceholder, ConfigDir, DHCP4ConfPath, DHCP4Bin)
|
|
}
|
|
|
|
// EntrypointCtrlAgent is the kea-ctrl-agent container entrypoint.
|
|
func EntrypointCtrlAgent() string {
|
|
return fmt.Sprintf(`#!/bin/sh
|
|
set -e
|
|
mkdir -p %[1]s
|
|
chmod 0750 %[1]s
|
|
cp %[2]s/kea-ctrl-agent.conf %[3]s
|
|
exec %[4]s -c %[3]s
|
|
`, RunDir, ConfigDir, CtrlAgentConfPath, CtrlAgentBin)
|
|
}
|