fix(cli): pin the reaper to its storage node; drop the stale uid-1000 note
Two things in the same surface. --reaper-node is the supported multi-node answer: the rendered CronJob's pod gets a kubernetes.io/hostname selector, so it reads the hostPath on the node that actually holds the worlds instead of possibly scheduling where it is empty (naming a node without --worlds-host-path is fail-loud). And the render note still told operators to grant uid-1000 traverse / setfacl after #35 moved every world executor to root+DAC_OVERRIDE — it now states that fact instead of the obsolete ritual.
This commit is contained in:
5 files changed
+112
-26
No files matched your search
@@ -181,3 +181,41 @@ func TestManifestsRendersReaper(t *testing.T) {
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// TestManifestsReaperNodePin: --reaper-node pins the rendered CronJob's pod via
|
||||
// kubernetes.io/hostname and replaces the "no nodeSelector" hazard note with the
|
||||
// pin confirmation; using it without the worlds root is a fail-loud 2.
|
||||
func TestManifestsReaperNodePin(t *testing.T) {
|
||||
var out, errBuf bytes.Buffer
|
||||
code := run([]string{
|
||||
"manifests",
|
||||
"--felis-image", "registry.felis.svc:5000/felis:v1",
|
||||
"--velocity-cidr", "10.0.0.5/32",
|
||||
"--worlds-host-path", "/var/lib/felis/worlds",
|
||||
"--archive-local-path", "/backups",
|
||||
"--reaper-node", "node-a",
|
||||
}, &out, &errBuf)
|
||||
if code != 0 {
|
||||
t.Fatalf("exit code = %d, want 0; stderr=%q", code, errBuf.String())
|
||||
}
|
||||
for _, want := range []string{
|
||||
"kubernetes.io/hostname: node-a",
|
||||
} {
|
||||
if !strings.Contains(out.String(), want) {
|
||||
t.Errorf("pinned render missing %q", want)
|
||||
}
|
||||
}
|
||||
if !strings.Contains(errBuf.String(), "node-a") {
|
||||
t.Errorf("stderr must confirm the pin, got %q", errBuf.String())
|
||||
}
|
||||
|
||||
var out2, err2 bytes.Buffer
|
||||
if code := run([]string{
|
||||
"manifests",
|
||||
"--felis-image", "registry.felis.svc:5000/felis:v1",
|
||||
"--velocity-cidr", "10.0.0.5/32",
|
||||
"--reaper-node", "node-a",
|
||||
}, &out2, &err2); code != 2 {
|
||||
t.Errorf("--reaper-node without --worlds-host-path: exit = %d, want 2", code)
|
||||
}
|
||||
}
|
||||
Reference in new issue
Block a user