feat(platform): 渲染 k3s 内的 felis-postgres 及其入站隔离
This commit is contained in:
9 files changed
+770
-15
No files matched your search
@@ -82,14 +82,21 @@ type JobParams struct {
|
||||
// backup and a restore of the same server never collide.
|
||||
func BackupJobName(server string) string { return "backup-" + server }
|
||||
|
||||
func backupLabels(p JobParams) map[string]string {
|
||||
// PodSelector matches every world-backup Job pod, whichever server it backs up:
|
||||
// the peer the database's ingress fence admits (internal/platform/postgres.go).
|
||||
func PodSelector() map[string]string {
|
||||
return map[string]string{
|
||||
LabelManagedBy: managedByValue,
|
||||
LabelComponent: componentValue,
|
||||
LabelServer: p.Server,
|
||||
}
|
||||
}
|
||||
|
||||
func backupLabels(p JobParams) map[string]string {
|
||||
labels := PodSelector()
|
||||
labels[LabelServer] = p.Server
|
||||
return labels
|
||||
}
|
||||
|
||||
// BackupJob renders the on-demand world-backup Job (spec §18/§19 WorldArchiver,
|
||||
// run on demand rather than on the reaper's daily schedule). Its isolation mirrors
|
||||
// the restore Job (weak SA, non-root, read-only root fs, drop ALL, one-shot with a
|
||||
|
||||
Reference in new issue
Block a user