mirror of
https://github.com/edgelesssys/constellation.git
synced 2025-01-24 22:26:43 -05:00
helm: masq traffic to the mini-qemu-metadata container so that the join-service can retrieve it's metadata (#2782)
* helm: masq traffic to the mini-qemu-metadata container * ci: fix waiting for nodes in miniconstellation e2e test
This commit is contained in:
parent
4d8f45cff6
commit
45479b307e
@ -49,20 +49,29 @@ echo "Done waiting."
|
|||||||
|
|
||||||
export KUBECONFIG="${PWD}/constellation-admin.conf"
|
export KUBECONFIG="${PWD}/constellation-admin.conf"
|
||||||
|
|
||||||
# Wait for nodes to actually show up in K8s
|
# Wait for nodes to actually show up in K8s (taken from .github/actions/constellation_create/action.yml)
|
||||||
count=0
|
echo "::group::Wait for nodes"
|
||||||
until kubectl wait --for=condition=Ready --timeout=2s nodes control-plane-0 2> /dev/null || [[ ${count} -eq 30 ]]; do
|
NODES_COUNT=2
|
||||||
echo "Control-planes are not registered in Kubernetes yet. Waiting..."
|
JOINWAIT=0
|
||||||
sleep 10
|
JOINTIMEOUT="600" # 10 minutes timeout for all nodes to join
|
||||||
count=$((count + 1))
|
until [[ "$(kubectl get nodes -o json | jq '.items | length')" == "${NODES_COUNT}" ]] || [[ $JOINWAIT -gt $JOINTIMEOUT ]]; do
|
||||||
done
|
echo "$(kubectl get nodes -o json | jq '.items | length')/${NODES_COUNT} nodes have joined.. waiting.."
|
||||||
|
JOINWAIT=$((JOINWAIT + 30))
|
||||||
count=0
|
sleep 30
|
||||||
until kubectl wait --for=condition=Ready --timeout=2s nodes worker-0 2> /dev/null || [[ ${count} -eq 30 ]]; do
|
|
||||||
echo "Worker nodes are not registered in Kubernetes yet. Waiting..."
|
|
||||||
sleep 10
|
|
||||||
count=$((count + 1))
|
|
||||||
done
|
done
|
||||||
|
if [[ $JOINWAIT -gt $JOINTIMEOUT ]]; then
|
||||||
|
echo "Timed out waiting for nodes to join"
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
echo "$(kubectl get nodes -o json | jq '.items | length')/${NODES_COUNT} nodes have joined"
|
||||||
|
if ! kubectl wait --for=condition=ready --all nodes --timeout=20m; then
|
||||||
|
kubectl get pods -n kube-system
|
||||||
|
kubectl get events -n kube-system
|
||||||
|
echo "::error::kubectl wait timed out before all nodes became ready"
|
||||||
|
echo "::endgroup::"
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
echo "::endgroup::"
|
||||||
|
|
||||||
# Wait for deployments
|
# Wait for deployments
|
||||||
kubectl -n kube-system wait --for=condition=Available=True --timeout=180s deployment coredns
|
kubectl -n kube-system wait --for=condition=Available=True --timeout=180s deployment coredns
|
||||||
|
@ -59,9 +59,18 @@ func extraCiliumValues(provider cloudprovider.Provider, conformanceMode bool, ou
|
|||||||
extraVals["encryption"] = map[string]any{
|
extraVals["encryption"] = map[string]any{
|
||||||
"strictMode": strictMode,
|
"strictMode": strictMode,
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// On QEMU e.g. the join-service must talk to our mini-qemu-metadata docker container
|
||||||
|
// This container runs inside the node CIDR, so we need to masq any pod traffic to it
|
||||||
|
// with the node's IP address. To archive that, we override Cilium's default masq ranges
|
||||||
|
// with an empty list.
|
||||||
|
masqCIDRs := []string{}
|
||||||
|
if provider != cloudprovider.QEMU {
|
||||||
|
masqCIDRs = append(masqCIDRs, output.IPCidrNode)
|
||||||
|
}
|
||||||
extraVals["ipMasqAgent"] = map[string]any{
|
extraVals["ipMasqAgent"] = map[string]any{
|
||||||
"config": map[string]any{
|
"config": map[string]any{
|
||||||
"nonMasqueradeCIDRs": []string{output.IPCidrNode},
|
"nonMasqueradeCIDRs": masqCIDRs,
|
||||||
},
|
},
|
||||||
}
|
}
|
||||||
|
|
||||||
|
Loading…
Reference in New Issue
Block a user