Documentation
¶
Overview ¶
Package activator contains a userspace TCP proxy that listens on a random port and loads an eBPF program to intercept and redirect packets destined to the configured ports. The activator accepts the connection, calls onAccept, signals to disable the eBPF redirect and then proxies the initial data to the defined ports as soon as something is listening.
Index ¶
- Constants
- Variables
- func CleanPinPath(pid int) error
- func ContainerPids(pid int) ([]int, error)
- func ConvertBPFTime(t uint64) (time.Time, error)
- func GetSandboxIPs(ifaceName string) ([]netip.Addr, error)
- func ManagedByShim(pid int) bool
- func MapsPath() string
- func MountBPFFS(path string) error
- func PinPath(pid int) string
- func SetKubeletAddr(pid int, addr netip.Addr) error
- func TCXPinned(pid int, ifaces ...string) bool
- type Activator
- type BPF
- type BPFConfig
- type BPFOpts
- type ConnHook
- type Listener
- type Listeners
- type Network
- type NoActivityRecordedErr
- type Option
- type RestoreHook
- type Server
- func (s *Server) AttachExec() error
- func (s *Server) DisableRedirects() error
- func (s *Server) ForwardToTarget(_ context.Context, addr string) error
- func (s *Server) GetKubeletAddr(isV6 bool) (*netip.Addr, error)
- func (s *Server) GetListeners(ctx context.Context, pid int) []Listener
- func (s *Server) LastActivity(port uint16) (time.Time, error)
- func (s *Server) RedirectPort(from, to uint16) error
- func (s *Server) Reset() error
- func (s *Server) SetConnectTimeout(d time.Duration)
- func (s *Server) SetKubeletAddr(addr *netip.Addr)
- func (s *Server) SetPeekBufferSize(size int)
- func (s *Server) SetProxyTimeout(d time.Duration)
- func (s *Server) Start(ctx context.Context, _ int, listeners Listeners, skipStart bool) error
- func (s *Server) Started() bool
- func (s *Server) Stop(ctx context.Context)
Constants ¶
const ( IfaceETH0 = "eth0" IfaceLoopback = "lo" )
const ( BPFFSPath = "/sys/fs/bpf" SocketTrackerMap = bpfMapSocketTracker PodKubeletAddrMapv4 = bpfMapKubeletAddrV4 PodKubeletAddrMapv6 = bpfMapKubeletAddrV6 ManagedByShimSuffix = "_managed_by_shim" )
const AttachActivatorFlag = "-zeropod-attach-activator"
Variables ¶
var ( ErrMapNotFound = errors.New("bpf map could not be found") DefaultIfaces = []string{IfaceLoopback, IfaceETH0} )
var ErrNoListeningSockets = errors.New("no listening sockets found")
Functions ¶
func CleanPinPath ¶ added in v0.12.1
func ContainerPids ¶ added in v0.13.0
ContainerPids returns a slice of all pids in the same pidns of pid (including pid).
func ConvertBPFTime ¶ added in v0.13.0
ConvertBPFTime takes the value of bpf_ktime_get_ns and converts it to a time.Time.
func ManagedByShim ¶ added in v0.12.0
ManagedByShim returns true if loading/pinning is managed by the shim itself.
func MountBPFFS ¶ added in v0.2.0
MountBPFFS executes a bpf mount on the supplied path. It has been adapted by: https://github.com/cilium/cilium/blob/cf3889af46a4058d5e89495d502fc19c10713110/pkg/bpf/bpffs_linux.go#L124
func SetKubeletAddr ¶ added in v0.13.0
SetKubeletAddr puts the kubelet addr in the respective BPF map for v4/v6. It will create and pin the map if it does not exist and freeze it afterwards. If the map already exists and is frozen, this is a noop.
Types ¶
type Activator ¶ added in v0.13.0
type Activator interface {
Start(ctx context.Context, pid int, listeners Listeners, skipStart bool) error
Started() bool
Reset() error
DisableRedirects() error
AttachExec() error
SetProxyTimeout(d time.Duration)
SetConnectTimeout(d time.Duration)
LastActivity(port uint16) (time.Time, error)
Stop(ctx context.Context)
GetListeners(ctx context.Context, pid int) []Listener
ForwardToTarget(ctx context.Context, addr string) error
}
type BPF ¶ added in v0.2.0
type BPF struct {
// contains filtered or unexported fields
}
func (*BPF) AttachInNetNS ¶ added in v0.12.0
func (*BPF) AttachRedirector ¶ added in v0.2.0
type BPFConfig ¶ added in v0.9.0
type BPFConfig struct {
// contains filtered or unexported fields
}
type BPFOpts ¶ added in v0.9.0
type BPFOpts func(cfg *BPFConfig)
func DisablePinning ¶ added in v0.10.0
func DisablePinning() BPFOpts
func OverrideMapSize ¶ added in v0.9.0
func ShimManaged ¶ added in v0.12.0
func ShimManaged() BPFOpts
func TrackerIgnoreLocalhost ¶ added in v0.9.2
type Listener ¶ added in v0.13.0
type Listeners ¶ added in v0.13.0
type Listeners []Listener
func GetListenersOfPID ¶ added in v0.13.0
GetListenersOfPID gets all Listeners in the pid namespace.
type NoActivityRecordedErr ¶ added in v0.9.0
type NoActivityRecordedErr struct{}
func (NoActivityRecordedErr) Error ¶ added in v0.9.0
func (err NoActivityRecordedErr) Error() string
type RestoreHook ¶ added in v0.7.0
type Server ¶
type Server struct {
// contains filtered or unexported fields
}
func (*Server) AttachExec ¶ added in v0.12.0
AttachExec attaches the activator using exec on itself.
func (*Server) DisableRedirects ¶ added in v0.1.0
func (*Server) ForwardToTarget ¶ added in v0.13.0
ForwardToTarget instructs the activator to forward any incoming traffic to the specified address. The connHook and restoreHook will both be disabled.
func (*Server) GetKubeletAddr ¶ added in v0.13.0
func (*Server) GetListeners ¶ added in v0.13.0
func (*Server) LastActivity ¶ added in v0.9.0
func (*Server) RedirectPort ¶ added in v0.1.0
RedirectPort redirects the port from to on ingress and to from on egress.