feat(distributed): 支持单主控多节点部署和停服迁移
复用现有 k3s 调度和 Job 生命周期,增加 worker 接入与批准、受保护节点身份、归档传输、持久迁移锁及活动 PVC 切换;同步管理员 API、CLI、面板和隔离规则。分布式模式默认关闭,保持单机兼容。 验证:Go 全量测试与 vet;面板 874 个测试、lint/build;Linux VM 安装器测试、清单服务端 dry-run、网络命名空间防火墙实测。A/B/C 三机 WireGuard、Velocity 和迁移验收仍待完成。
This commit is contained in:
77 files changed
+5224
-73
No files matched your search
@@ -37,6 +37,7 @@ func cmdEgressGate(args []string, stdout, stderr io.Writer) int {
|
||||
fs := flag.NewFlagSet("egress-gate", flag.ContinueOnError)
|
||||
fs.SetOutput(stderr)
|
||||
probe := fs.String("probe", "", "host:port the pod's NetworkPolicy denies (default: the Kubernetes API Service from KUBERNETES_SERVICE_HOST/PORT)")
|
||||
positive := fs.String("positive-probe", "", "allowed host:port that must remain reachable during denial checks")
|
||||
wait := fs.Duration("wait", 2*time.Minute, "how long the probe may keep answering before the gate gives up")
|
||||
failOpen := fs.Bool("fail-open", false, "when --wait runs out, warn and let the pod go on instead of refusing it")
|
||||
if err := fs.Parse(args); err != nil {
|
||||
@@ -53,6 +54,18 @@ func cmdEgressGate(args []string, stdout, stderr io.Writer) int {
|
||||
|
||||
start := time.Now()
|
||||
for {
|
||||
if *positive != "" {
|
||||
allowed, err := net.DialTimeout("tcp", *positive, egressDialTimeout)
|
||||
if err != nil {
|
||||
if time.Since(start) >= *wait {
|
||||
fmt.Fprintln(stderr, "felis egress-gate: positive probe unavailable; refusing to start", err)
|
||||
return 1
|
||||
}
|
||||
time.Sleep(egressPollInterval)
|
||||
continue
|
||||
}
|
||||
allowed.Close()
|
||||
}
|
||||
conn, err := net.DialTimeout("tcp", *probe, egressDialTimeout)
|
||||
if err != nil {
|
||||
fmt.Fprintf(stdout, "felis egress-gate: %s is unreachable after %s (%v); the egress lock is in effect\n",
|
||||
|
||||
Reference in new issue
Block a user