Documentation
¶
Overview ¶
Package node replays "kubeadm join" and kubelet node registration in-process so a mock DPU shows up as a Ready Node in the DPU cluster without kubeadm, kubelet or any admin credentials. The DPU cluster sees the same traffic as with a real kubelet: bootstrap token authentication, a CSR for the kube-apiserver-client-kubelet signer, a Node object and Lease heartbeats.
Index ¶
- Constants
- func DiscoverCA(ctx context.Context, server string, hashes []string) ([]byte, error)
- type JoinCommand
- type Joiner
- func (j *Joiner) Clientset() kubernetes.Interface
- func (j *Joiner) EnsureCredentials(ctx context.Context, joinCmd string) error
- func (j *Joiner) NodeName() string
- func (j *Joiner) RegisterNode(ctx context.Context, kubeletVersion string) error
- func (j *Joiner) RunHeartbeat(ctx context.Context, kubeletVersion string)
- func (j *Joiner) ServerVersion() (string, error)
Constants ¶
const (
// FakeNodeLabel marks the Node as a stand-in so e2e tooling can tell it from real DPUs.
FakeNodeLabel = "e2e.test.io/fake-node"
)
Variables ¶
This section is empty.
Functions ¶
func DiscoverCA ¶
DiscoverCA performs kubeadm token discovery: it reads the kube-public/cluster-info ConfigMap anonymously (TLS unverified), takes the cluster CA from the embedded kubeconfig and pins it against the SPKI hashes of the join command. The JWS signature check kubeadm also performs is omitted; the hash pin is what protects against a spoofed API server.
Types ¶
type JoinCommand ¶
JoinCommand is the parsed "kubeadm join" line the controller stores in the <dpu>-kubeadm-join Secret.
func ParseJoinCommand ¶
func ParseJoinCommand(cmd string) (*JoinCommand, error)
ParseJoinCommand extracts server, token and CA hashes from a kubeadm join command line.
type Joiner ¶
type Joiner struct {
// contains filtered or unexported fields
}
Joiner holds one mock kubelet's DPU cluster credentials. Files live under dir so a restarted process (VM mode) or a rebooted agent run reuses the node certificate instead of the token. EnsureCredentials is not safe for concurrent calls; the agent runs of one DPU are sequential.
func (*Joiner) Clientset ¶
func (j *Joiner) Clientset() kubernetes.Interface
Clientset returns the node-identity client, valid after EnsureCredentials.
func (*Joiner) EnsureCredentials ¶
EnsureCredentials makes the node client certificate available. joinCmd is the current kubeadm join command, or "" when the controller has already deleted the join Secret; in that case the certificate obtained by an earlier run must still be on disk. Certificate rotation runs until ctx is canceled.
func (*Joiner) RegisterNode ¶
RegisterNode creates the Node object the way a kubelet does on first start. An existing Node with the same name (reprovisioning) is adopted, which NodeRestriction allows for the node itself.
func (*Joiner) RunHeartbeat ¶
RunHeartbeat renews the node Lease and re-posts a Ready status every 10 seconds until ctx is canceled, which is what keeps cutil.IsNodeReady true for the Cluster Config phase.
func (*Joiner) ServerVersion ¶
ServerVersion returns the DPU cluster API server version; the mock reports it as kubeletVersion.