forked from pelican-dev/wings
-
Notifications
You must be signed in to change notification settings - Fork 0
feat: auto-set LB IP-pinning and sharing-key annotations from allocation IP #1
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Merged
Changes from all commits
Commits
File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
🔴 Stale LB IP-pinning annotations persist on Service update when allocation IP becomes invalid
When updating an existing LoadBalancer Service, the annotation merge at lines 148-155 only adds/overwrites keys from the new
annotationsmap — it never removes annotations that are no longer desired. If a server's allocation IP changes from a valid address (e.g.23.227.184.222) to0.0.0.0,127.0.0.1, or empty,allocationIP()(network.go:362-371) returns"", so theLBIPAnnotationandLBSharingKeykeys are not included in theannotationsmap. However, those annotation keys from the previousEnsureServicecall remain on the existing Service object, keeping the LoadBalancer pinned to the old/stale IP.Example scenario
23.227.184.222;EnsureServicecreates the Service withlbipam.cilium.io/ips: "23.227.184.222"0.0.0.0(wildcard)EnsureServiceruns again:allocationIP()returns"", so annotations map only hasLBAnnotationsentriesLBAnnotationsbut the stalelbipam.cilium.io/ipskey is never deleted23.227.184.222(Refers to lines 148-155)
Prompt for agents
Was this helpful? React with 👍 or 👎 to provide feedback.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Good catch. Fixed in 7457b9d — the update path now replaces annotations entirely (
existing.Annotations = annotations) instead of merging, so stale IP-pinning and sharing-key annotations are cleaned up when the allocation IP becomes invalid. Added a test that verifies the stale annotation removal scenario.