v0.4: prove node ownership of VXLAN routing DNS and drift repair
- Lingua principale
- Go
- Stelle
- 1
- Fork
- 0
- Merge medio
- 18m
- PR unite (30g)
- 19
Descrizione
Parent epic: #6
Depends on the CNI handoff and node-agent ownership core.
Prototype node ownership of the complete non-port-forward feature subset after the cgroup deny is attached: VXLAN, overlay address, protected and exception routes, all cluster-traffic modes, UDP/TCP DNS translation, gateway health, endpoint replacement, verification, and drift repair.
Measure and document every required namespace/capability/host access. `CAP_SYS_ADMIN` or host PID is not implicitly accepted. Preserve unrelated netns and CNI state. The selected path must remove the two privileged networking init operations and long-running privileged networking sidecar or the release-value gate fails.
PortForwardLease remains rejected until its DNAT and renewable-delivery path is complete.
Guida per i contributori
Apri la guida per i contributori
Direzione di ricerca
No files, tests, or entry points are named; start by resolving the CNI handoff and node-agent ownership dependencies from #6. Inventory the required namespace, capability, and host access while checking that unrelated netns and CNI state remain unchanged. Done means the privileged networking init operations and long-running sidecar are removed, the non-port-forward subset is verified with drift repair, and access requirements are documented.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Valutazione
- Stack tecnologico
- go, kubernetes, linux
- Ambito
- infrastructure, networking
- Tipo di issue
- Funzionalità
- Difficoltà
- 5/5
- Tempo stimato
- Più di una settimana
- Stato di attività
- Tranquilla
- Chiarezza
- Da chiarire
- Idoneità per principianti
- 25/100