feat(operator): 游戏容器加 startup/liveness 探针,超时启动按 1/2/4 分钟退避重建 Pod 至多 3 次,Running 每 60s 重探且连续 3 次失败才降级,Failed 放缓重排
This commit is contained in:
10 files changed
+440
-35
No files matched your search
@@ -189,11 +189,20 @@ func TestOperatorRole_ScopeExact(t *testing.T) {
|
||||
}
|
||||
}
|
||||
// Hard exclusions.
|
||||
for _, res := range []string{"persistentvolumeclaims", "pods", "events"} {
|
||||
for _, res := range []string{"persistentvolumeclaims", "events"} {
|
||||
if grantsResource(op, groupCore, res) {
|
||||
t.Errorf("operator must NOT touch core/%s", res)
|
||||
}
|
||||
}
|
||||
// Pods are delete-only: the bounded retry of a timed-out start.
|
||||
if !hasRule(op, groupCore, "pods", "delete") {
|
||||
t.Error("operator must have pods:delete (auto-restart of a timed-out start)")
|
||||
}
|
||||
for _, v := range []string{"get", "list", "watch", "create", "update", "patch", "deletecollection", "*"} {
|
||||
if hasRule(op, groupCore, "pods", v) {
|
||||
t.Errorf("operator pods rule must be delete-only, found %s", v)
|
||||
}
|
||||
}
|
||||
// The world-volume lock check lists Jobs uncached; it never writes one.
|
||||
if !hasRule(op, groupBatch, "jobs", "list") {
|
||||
t.Error("operator must have jobs:list (maintenance hold before scale-up)")
|
||||
|
||||
Reference in new issue
Block a user