Amoenus / Amoenus/waycloak

v0.4: prove node ownership of VXLAN routing DNS and drift repair

Aperta
#110 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub
enhancement
Lingua principale
Go
Stelle
1
Fork
0
Merge medio
18m
PR unite (30g)
19

Descrizione

Parent epic: #6
Depends on the CNI handoff and node-agent ownership core.

Prototype node ownership of the complete non-port-forward feature subset after the cgroup deny is attached: VXLAN, overlay address, protected and exception routes, all cluster-traffic modes, UDP/TCP DNS translation, gateway health, endpoint replacement, verification, and drift repair.

Measure and document every required namespace/capability/host access. `CAP_SYS_ADMIN` or host PID is not implicitly accepted. Preserve unrelated netns and CNI state. The selected path must remove the two privileged networking init operations and long-running privileged networking sidecar or the release-value gate fails.

PortForwardLease remains rejected until its DNAT and renewable-delivery path is complete.

Guida per i contributori

Apri la guida per i contributori

Direzione di ricerca

No files, tests, or entry points are named; start by resolving the CNI handoff and node-agent ownership dependencies from #6. Inventory the required namespace, capability, and host access while checking that unrelated netns and CNI state remain unchanged. Done means the privileged networking init operations and long-running sidecar are removed, the non-port-forward subset is verified with drift repair, and access requirements are documented.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Valutazione

Stack tecnologico
go, kubernetes, linux
Ambito
infrastructure, networking
Tipo di issue
Funzionalità
Difficoltà
5/5
Tempo stimato
Più di una settimana
Stato di attività
Tranquilla
Chiarezza
Da chiarire
Idoneità per principianti
25/100

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.