fix(reaper): 回收前先停服并持有世界维护锁再归档,锁丢失不删卷;无世界卷的无主服务器只重置时钟不再重复回收
This commit is contained in:
14 files changed
+751
-51
No files matched your search
@@ -221,12 +221,23 @@ func TestReaperRole_ScopeExact(t *testing.T) {
|
||||
t.Errorf("reaper must NOT touch %s/%s (operator/api territory)", res.group, res.name)
|
||||
}
|
||||
}
|
||||
// The reaper never lists from the cluster (candidates come from Postgres).
|
||||
// The reaper never lists servers from the cluster (candidates come from Postgres).
|
||||
for _, v := range []string{"list", "watch"} {
|
||||
if hasRule(rp, groupFelis, "minecraftservers", v) {
|
||||
t.Errorf("reaper must NOT %s minecraftservers (candidates come from the store)", v)
|
||||
}
|
||||
}
|
||||
// Taking the world lock reads the game pod and the maintenance Jobs, list only.
|
||||
if !hasRule(rp, groupCore, "pods", "list") || !hasRule(rp, groupBatch, "jobs", "list") {
|
||||
t.Error("reaper must list pods and jobs to take the world maintenance lock")
|
||||
}
|
||||
for _, res := range []struct{ group, name string }{{groupCore, "pods"}, {groupBatch, "jobs"}} {
|
||||
for _, v := range []string{"get", "watch", "create", "update", "patch", "delete"} {
|
||||
if hasRule(rp, res.group, res.name, v) {
|
||||
t.Errorf("reaper must NOT %s %s (list-only)", v, res.name)
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// TestReaperRBAC_GatedOnRetention locks the reaper identity to its consumer: the
|
||||
|
||||
Reference in new issue
Block a user