feat(distributed): 支持单主控多节点部署和停服迁移
复用现有 k3s 调度和 Job 生命周期,增加 worker 接入与批准、受保护节点身份、归档传输、持久迁移锁及活动 PVC 切换;同步管理员 API、CLI、面板和隔离规则。分布式模式默认关闭,保持单机兼容。 验证:Go 全量测试与 vet;面板 874 个测试、lint/build;Linux VM 安装器测试、清单服务端 dry-run、网络命名空间防火墙实测。A/B/C 三机 WireGuard、Velocity 和迁移验收仍待完成。
This commit is contained in:
77 files changed
+5224
-73
No files matched your search
+10
-4
@@ -29,10 +29,11 @@ import (
|
||||
|
||||
// API holds the dependencies shared by every handler.
|
||||
type API struct {
|
||||
Repo Repo
|
||||
Cluster Cluster
|
||||
Internal InternalAuth
|
||||
External ExternalAuth
|
||||
Distribution Distribution
|
||||
Repo Repo
|
||||
Cluster Cluster
|
||||
Internal InternalAuth
|
||||
External ExternalAuth
|
||||
|
||||
// Builder is the image build subsystem (spec §16). It is optional: when nil
|
||||
// the /images routes report 503 rather than 404, so the admin boundary is
|
||||
@@ -721,6 +722,11 @@ func (a *API) externalAPIRoutes() []apiRoute {
|
||||
// Zero-Trust path, unlike the app-tier /me/servers. A path distinct from the
|
||||
// internal velocity GET /api/v1/servers on purpose: the parity test forbids one
|
||||
// {method, path} from carrying both the service and admin tiers.
|
||||
{Method: "GET", Pattern: "/api/v1/nodes", Admin: true, h: a.handleNodes},
|
||||
{Method: "GET", Pattern: "/api/v1/servers/{name}/migrations", Admin: true, h: a.handleMigrationStatus},
|
||||
{Method: "POST", Pattern: "/api/v1/servers/{name}/migrations", Admin: true, h: a.handleMigration},
|
||||
{Method: "GET", Pattern: "/api/v1/servers/{name}/migrations/{id}", Admin: true, h: a.handleMigrationStatus},
|
||||
{Method: "POST", Pattern: "/api/v1/servers/{name}/migrations/{id}/retry", Admin: true, h: a.handleMigrationRetry},
|
||||
{Method: "GET", Pattern: "/api/v1/fleet", Admin: true, h: a.handleFleet},
|
||||
// Image build + whitelist (spec §16, §15). Every route is admin-tier: a build
|
||||
// is build-time RCE against the cluster, so submission requires the admin
|
||||
|
||||
Reference in new issue
Block a user