feat(distributed): 支持单主控多节点部署和停服迁移
复用现有 k3s 调度和 Job 生命周期,增加 worker 接入与批准、受保护节点身份、归档传输、持久迁移锁及活动 PVC 切换;同步管理员 API、CLI、面板和隔离规则。分布式模式默认关闭,保持单机兼容。 验证:Go 全量测试与 vet;面板 874 个测试、lint/build;Linux VM 安装器测试、清单服务端 dry-run、网络命名空间防火墙实测。A/B/C 三机 WireGuard、Velocity 和迁移验收仍待完成。
This commit is contained in:
77 files changed
+5224
-73
No files matched your search
@@ -15,6 +15,20 @@ func shrinkEgressGate(t *testing.T) {
|
||||
t.Cleanup(func() { egressDialTimeout, egressPollInterval = dial, poll })
|
||||
}
|
||||
|
||||
func TestEgressGateRequiresPositiveReachability(t *testing.T) {
|
||||
shrinkEgressGate(t)
|
||||
ln, err := net.Listen("tcp", "127.0.0.1:0")
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
closed := ln.Addr().String()
|
||||
ln.Close()
|
||||
var out, errb bytes.Buffer
|
||||
if code := cmdEgressGate([]string{"--positive-probe", closed, "--probe", closed, "--wait", "20ms"}, &out, &errb); code != 1 {
|
||||
t.Fatal("unavailable probes allowed startup", code)
|
||||
}
|
||||
}
|
||||
|
||||
// The gate holds while the probe answers and lets the pod go on once the policy
|
||||
// lands, which the test plays by closing the listener.
|
||||
func TestEgressGateWaitsForTheLock(t *testing.T) {
|
||||
|
||||
Reference in new issue
Block a user