fix(reaper): 回收前先停服并持有世界维护锁再归档,锁丢失不删卷;无世界卷的无主服务器只重置时钟不再重复回收

This commit is contained in:
Lemon-miaow committed 2026-09-25 03:31:50 +08:00
1 parent 89a0134707
commit 7766e8efa4
14 files changed
+751 -51

No files matched your search

+12 -1
View File
@@ -221,12 +221,23 @@ func TestReaperRole_ScopeExact(t *testing.T) {
t.Errorf("reaper must NOT touch %s/%s (operator/api territory)", res.group, res.name)
}
}
// The reaper never lists from the cluster (candidates come from Postgres).
// The reaper never lists servers from the cluster (candidates come from Postgres).
for _, v := range []string{"list", "watch"} {
if hasRule(rp, groupFelis, "minecraftservers", v) {
t.Errorf("reaper must NOT %s minecraftservers (candidates come from the store)", v)
}
}
// Taking the world lock reads the game pod and the maintenance Jobs, list only.
if !hasRule(rp, groupCore, "pods", "list") || !hasRule(rp, groupBatch, "jobs", "list") {
t.Error("reaper must list pods and jobs to take the world maintenance lock")
}
for _, res := range []struct{ group, name string }{{groupCore, "pods"}, {groupBatch, "jobs"}} {
for _, v := range []string{"get", "watch", "create", "update", "patch", "delete"} {
if hasRule(rp, res.group, res.name, v) {
t.Errorf("reaper must NOT %s %s (list-only)", v, res.name)
}
}
}
}
// TestReaperRBAC_GatedOnRetention locks the reaper identity to its consumer: the