cockroachdb / cockroachdb/cockroach-operator

[BUG] The program crashes if the image name does not contain colon

Open
#918 0 comments 1 reaction 0 assignees View on GitHub
Dominant language
Go
Stars
318
Forks
104
Avg merge
1d 6h
Merged PRs (30d)
1

Description

**What version of operator are you using?**
commit 561cf47d783c368fd8795acb82a5a39099a35984 (HEAD -> master)

**What operating system and processor architecture are you using (`kubectl version`)?**
Ubuntu. 20.04

kubectl version Output

$ kubectl version

Client Version: version.Info{Major:"1", Minor:"24", GitVersion:"v1.24.0", GitCommit:"4ce5a8954017644c5420bae81d72b09b735c21f0", GitTreeState:"clean", BuildDate:"2022-05-03T13:46:05Z", GoVersion:"go1.18.1", Compiler:"gc", Platform:"darwin/amd64"}
Kustomize Version: v4.5.4
Server Version: version.Info{Major:"1", Minor:"22", GitVersion:"v1.22.9", GitCommit:"6df4433e288edc9c40c2e344eb336f63fad45cd2", GitTreeState:"clean", BuildDate:"2022-05-19T19:53:08Z", GoVersion:"go1.16.15", Compiler:"gc", Platform:"linux/amd64"}
WARNING: version difference between client (1.24) and server (1.22) exceeds the supported minor version skew of +/-1

**What did you do?**

We found that crdb-operator will crash if we do not supply version for cockroachdb image. We supplied `cockroachdb/cockroach` for the `spec.image` field, and the operator crashes at [this line](https://github.com/cockroachdb/cockroach-operator/blob/dda0a6308b0f1c64d41e0851a5ef8cb60cd98a37/pkg/resource/cluster.go#L350)

### Reproduce

We first applied the operator yaml file and crd yaml file to deploy the operator.
Then we applied the following cr.yaml file to deploy the cockroachdb cluster:
by using `kubectl apply -f cr.yaml -n cockroach-operator-system`

**cr.yaml:**
```yaml
apiVersion: crdb.cockroachlabs.com/v1alpha1
kind: CrdbCluster
metadata:
name: test-cluster
spec:
additionalLabels:
crdb: is-cool
dataStore:
pvc:
spec:
accessModes:
- ReadWriteOnce
resources:
requests:
storage: 1Gi
volumeMode: Filesystem
image:
name: cockroachdb/cockroach
nodes: 3
resources:
limits:
cpu: 2
memory: 2Gi
requests:
cpu: 100m
memory: 1Gi
tlsEnabled: true

```

**What did you see?**

The operator crashes.

**Possible root cause**
It seems that the cockroach operator has assumed that there will always be a colon in the image name, as [this line](https://github.com/cockroachdb/cockroach-operator/blob/dda0a6308b0f1c64d41e0851a5ef8cb60cd98a37/pkg/resource/cluster.go#L350) suggests. There is no code preventing the program from crashing if an image name without a colon is provided. And if the image name does not have a colon, there will be an "index going out of range" error.

This is a bug, since crashing behavior is considered as bad behavior. There should be a sanity check to examine the validation of the image name, at least not let the program crash.

Contributor guide

No contributing guide indexed for this repository

Research direction

Start in pkg/resource/cluster.go around line 350, where the issue reports the crash for an image name without a colon. Reproduce it with the provided cr.yaml and kubectl apply command, then verify the image is handled without an index-out-of-range crash and that invalid input receives a controlled response.

Written by the indexing model from the issue text.

Assessment

Tech stack
go, kubernetes
Domain
devops, infrastructure
Issue type
Bug
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
55/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.