cockroachdb / cockroachdb/cockroach-operator
[BUG] The program crashes if the image name does not contain colon
- Dominant language
- Go
- Stars
- 318
- Forks
- 104
- Avg merge
- 1d 6h
- Merged PRs (30d)
- 1
Description
**What version of operator are you using?**
commit 561cf47d783c368fd8795acb82a5a39099a35984 (HEAD -> master)
**What operating system and processor architecture are you using (`kubectl version`)?**
Ubuntu. 20.04
kubectl version Output
$ kubectl version
Client Version: version.Info{Major:"1", Minor:"24", GitVersion:"v1.24.0", GitCommit:"4ce5a8954017644c5420bae81d72b09b735c21f0", GitTreeState:"clean", BuildDate:"2022-05-03T13:46:05Z", GoVersion:"go1.18.1", Compiler:"gc", Platform:"darwin/amd64"}
Kustomize Version: v4.5.4
Server Version: version.Info{Major:"1", Minor:"22", GitVersion:"v1.22.9", GitCommit:"6df4433e288edc9c40c2e344eb336f63fad45cd2", GitTreeState:"clean", BuildDate:"2022-05-19T19:53:08Z", GoVersion:"go1.16.15", Compiler:"gc", Platform:"linux/amd64"}
WARNING: version difference between client (1.24) and server (1.22) exceeds the supported minor version skew of +/-1
**What did you do?**
We found that crdb-operator will crash if we do not supply version for cockroachdb image. We supplied `cockroachdb/cockroach` for the `spec.image` field, and the operator crashes at [this line](https://github.com/cockroachdb/cockroach-operator/blob/dda0a6308b0f1c64d41e0851a5ef8cb60cd98a37/pkg/resource/cluster.go#L350)
### Reproduce
We first applied the operator yaml file and crd yaml file to deploy the operator.
Then we applied the following cr.yaml file to deploy the cockroachdb cluster:
by using `kubectl apply -f cr.yaml -n cockroach-operator-system`
**cr.yaml:**
```yaml
apiVersion: crdb.cockroachlabs.com/v1alpha1
kind: CrdbCluster
metadata:
name: test-cluster
spec:
additionalLabels:
crdb: is-cool
dataStore:
pvc:
spec:
accessModes:
- ReadWriteOnce
resources:
requests:
storage: 1Gi
volumeMode: Filesystem
image:
name: cockroachdb/cockroach
nodes: 3
resources:
limits:
cpu: 2
memory: 2Gi
requests:
cpu: 100m
memory: 1Gi
tlsEnabled: true
```
**What did you see?**
The operator crashes.
**Possible root cause**
It seems that the cockroach operator has assumed that there will always be a colon in the image name, as [this line](https://github.com/cockroachdb/cockroach-operator/blob/dda0a6308b0f1c64d41e0851a5ef8cb60cd98a37/pkg/resource/cluster.go#L350) suggests. There is no code preventing the program from crashing if an image name without a colon is provided. And if the image name does not have a colon, there will be an "index going out of range" error.
This is a bug, since crashing behavior is considered as bad behavior. There should be a sanity check to examine the validation of the image name, at least not let the program crash.
Contributor guide
No contributing guide indexed for this repository
Research direction
Start in pkg/resource/cluster.go around line 350, where the issue reports the crash for an image name without a colon. Reproduce it with the provided cr.yaml and kubectl apply command, then verify the image is handled without an index-out-of-range crash and that invalid input receives a controlled response.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- go, kubernetes
- Domain
- devops, infrastructure
- Issue type
- Bug
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 55/100