feat(distributed): 支持单主控多节点部署和停服迁移
复用现有 k3s 调度和 Job 生命周期,增加 worker 接入与批准、受保护节点身份、归档传输、持久迁移锁及活动 PVC 切换;同步管理员 API、CLI、面板和隔离规则。分布式模式默认关闭,保持单机兼容。 验证:Go 全量测试与 vet;面板 874 个测试、lint/build;Linux VM 安装器测试、清单服务端 dry-run、网络命名空间防火墙实测。A/B/C 三机 WireGuard、Velocity 和迁移验收仍待完成。
This commit is contained in:
77 files changed
+5224
-73
No files matched your search
@@ -1334,7 +1334,7 @@ expect "a failed fetch into an existing checkout names the token" "set FELIS_GIT
|
||||
|
||||
mblock="$(awk '/^ log "rendering \+ applying the control-plane bundle"/,/kube apply -f -/' "$BS")"
|
||||
[ -n "$mblock" ] || { echo "FAIL: no manifest_args block found in $BS"; exit 1; }
|
||||
[ "$(printf '%s\n' "$mblock" | wc -l)" -lt 60 ] \
|
||||
[ "$(printf '%s\n' "$mblock" | wc -l)" -lt 100 ] \
|
||||
|| { echo "FAIL: the extracted block is not the manifest_args block -- did it move?"; exit 1; }
|
||||
|
||||
run_bundle_flags() { # backup-pvc worlds-host-path
|
||||
@@ -4910,6 +4910,36 @@ case "$out" in
|
||||
esac
|
||||
rm -rf "$credir" "$credcalls"
|
||||
|
||||
# Worker admission reuses the installer but must never enter host control-plane setup.
|
||||
expect "distributed admission preserves existing API-server arguments" \
|
||||
"echo 'kube-apiserver-arg+:'" "$(bsfn write_k3s_config)"
|
||||
worker="$(bsfn main_worker)"
|
||||
before "worker identity is checked before the agent config is written" \
|
||||
'refusing to rename it' 'cat > "$K3S_CONFIG_DROPIN"' "$worker"
|
||||
expect "worker rejects server tokens and verifies the CA-pinned bootstrap shape" \
|
||||
'K10[0-9a-f]{64}::[a-z0-9]{6}\.[a-z0-9]{16}' "$worker"
|
||||
expect "worker cannot replace a controller" 'refusing to turn a controller into a worker' "$worker"
|
||||
expect "worker is quarantined" 'felis.lolicon.best/unapproved=true:NoSchedule' "$worker"
|
||||
expect "worker mirror preserves logical references and points at the cluster service" \
|
||||
'http://${WORKER_REGISTRY_IP}:5000' "$worker"
|
||||
expect "worker disables registry endpoint fallback" 'disable-default-registry-endpoint: true' "$worker"
|
||||
for forbidden in deploy_bundle install_cloudflared install_velocity run_migrations load_or_make_secrets; do
|
||||
case "$worker" in
|
||||
*"$forbidden"*) echo "FAIL worker invokes $forbidden"; fails=$((fails + 1));;
|
||||
*) echo "PASS worker does not invoke $forbidden";;
|
||||
esac
|
||||
done
|
||||
badtoken="$(mktemp)"
|
||||
printf 'server-token-not-bootstrap' > "$badtoken"
|
||||
out="$(WORKER_TOKEN_FILE="$badtoken" bash -c '
|
||||
die() { printf "DIE: %s\n" "$*"; exit 1; }
|
||||
WORKER_NAME=b WORKER_SERVER=https://192.0.2.1:6443 WORKER_REGISTRY_IP=10.43.0.10 WORKER_PEERS=192.0.2.1/32
|
||||
'"$worker"'
|
||||
main_worker
|
||||
')"
|
||||
expect "worker refuses a copied server token before changing the machine" 'worker accepts only CA-pinned bootstrap tokens' "$out"
|
||||
rm -f "$badtoken"
|
||||
|
||||
# ---------------------------------------------------------------------------------------
|
||||
if [ "$fails" -eq 0 ]; then
|
||||
echo "ALL PASS"
|
||||
|
||||
Reference in new issue
Block a user