node

package
v0.1.0-latest-stable Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 30, 2026 License: Apache-2.0 Imports: 32 Imported by: 0

Documentation

Overview

Package node replays "kubeadm join" and kubelet node registration in-process so a mock DPU shows up as a Ready Node in the DPU cluster without kubeadm, kubelet or any admin credentials. The DPU cluster sees the same traffic as with a real kubelet: bootstrap token authentication, a CSR for the kube-apiserver-client-kubelet signer, a Node object and Lease heartbeats.

Index

Constants

View Source
const (
	// FakeNodeLabel marks the Node as a stand-in so e2e tooling can tell it from real DPUs.
	FakeNodeLabel = "e2e.test.io/fake-node"
)

Variables

This section is empty.

Functions

func DiscoverCA

func DiscoverCA(ctx context.Context, server string, hashes []string) ([]byte, error)

DiscoverCA performs kubeadm token discovery: it reads the kube-public/cluster-info ConfigMap anonymously (TLS unverified), takes the cluster CA from the embedded kubeconfig and pins it against the SPKI hashes of the join command. The JWS signature check kubeadm also performs is omitted; the hash pin is what protects against a spoofed API server.

Types

type JoinCommand

type JoinCommand struct {
	Server       string
	Token        string
	CACertHashes []string
}

JoinCommand is the parsed "kubeadm join" line the controller stores in the <dpu>-kubeadm-join Secret.

func ParseJoinCommand

func ParseJoinCommand(cmd string) (*JoinCommand, error)

ParseJoinCommand extracts server, token and CA hashes from a kubeadm join command line.

type Joiner

type Joiner struct {
	// contains filtered or unexported fields
}

Joiner holds one mock kubelet's DPU cluster credentials. Files live under dir so a restarted process (VM mode) or a rebooted agent run reuses the node certificate instead of the token. EnsureCredentials is not safe for concurrent calls; the agent runs of one DPU are sequential.

func NewJoiner

func NewJoiner(dir, nodeName string) *Joiner

NewJoiner returns a joiner for nodeName whose files live under dir.

func (*Joiner) Clientset

func (j *Joiner) Clientset() kubernetes.Interface

Clientset returns the node-identity client, valid after EnsureCredentials.

func (*Joiner) EnsureCredentials

func (j *Joiner) EnsureCredentials(ctx context.Context, joinCmd string) error

EnsureCredentials makes the node client certificate available. joinCmd is the current kubeadm join command, or "" when the controller has already deleted the join Secret; in that case the certificate obtained by an earlier run must still be on disk. Certificate rotation runs until ctx is canceled.

func (*Joiner) NodeName

func (j *Joiner) NodeName() string

NodeName returns the DPU cluster Node name.

func (*Joiner) RegisterNode

func (j *Joiner) RegisterNode(ctx context.Context, kubeletVersion string) error

RegisterNode creates the Node object the way a kubelet does on first start. An existing Node with the same name (reprovisioning) is adopted, which NodeRestriction allows for the node itself.

func (*Joiner) RunHeartbeat

func (j *Joiner) RunHeartbeat(ctx context.Context, kubeletVersion string)

RunHeartbeat renews the node Lease and re-posts a Ready status every 10 seconds until ctx is canceled, which is what keeps cutil.IsNodeReady true for the Cluster Config phase.

func (*Joiner) ServerVersion

func (j *Joiner) ServerVersion() (string, error)

ServerVersion returns the DPU cluster API server version; the mock reports it as kubeletVersion.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL