Documentation
¶
Index ¶
- Constants
- func Bootstrap(ctx context.Context, conf *operv1.Network, client cnoclient.Client) (*bootstrap.BootstrapResult, error)
- func DeprecatedCanonicalize(conf *operv1.NetworkSpec)
- func FillDefaults(conf, previous *operv1.NetworkSpec, hostMTU int)
- func GetDefaultMTU() (int, error)
- func GetIPsecMode(conf *operv1.OVNKubernetesConfig) operv1.IPsecMode
- func GetTLSProfile(ctx context.Context, client cnoclient.Client, ...) (bootstrap.TLSProfile, error)
- func IsChangeSafe(prev, next *operv1.NetworkSpec, infraStatus *bootstrap.InfraStatus) error
- func IsIPsecLegacyAPI(conf *operv1.OVNKubernetesConfig) bool
- func IsMultusAdmissionControllerIgnoredNamespace(ns *corev1.Namespace) bool
- func MergeClusterConfig(operConf *operv1.NetworkSpec, clusterConf configv1.NetworkSpec)
- func NeedMTUProbe(prev, next *operv1.NetworkSpec) bool
- func Render(ctx context.Context, operConf *operv1.NetworkSpec, ...) ([]*uns.Unstructured, bool, error)
- func StatusFromOperatorConfig(operConf *operv1.NetworkSpec, oldStatus *configv1.NetworkStatus) *configv1.NetworkStatus
- func Validate(conf *operv1.NetworkSpec) error
- func ValidateClusterConfig(clusterConfig *configv1.Network, infraRes *bootstrap.InfraStatus, ...) error
- func ValidateMTUForNoOverlay(conf *operv1.NetworkSpec, hostMTU int) error
Constants ¶
const ( MinMTUIPv4 uint32 = 576 // RFC 791 MinMTUIPv6 uint32 = 1280 // RFC 8200 MaxMTU uint32 = 65536 )
const ( SystemCNIConfDir = "/etc/kubernetes/cni/net.d" MultusCNIConfDir = "/var/run/multus/cni/net.d" CNIBinDir = "/var/lib/cni/bin" MultusSocketParentDir = "/run/multus" )
const ( OVSFlowsConfigMapName = "ovs-flows-config" OVNKubernetesConfigOverridesCMName = "ovn-kubernetes-config-overrides" OVSFlowsConfigNamespace = names.AppliedNamespace )
const ( // UseTLSProfileKey is the template data key indicating whether to use the cluster TLS profile UseTLSProfileKey = "UseTLSProfile" // TLSMinVersionKey is the template data key for the minimum TLS version TLSMinVersionKey = "TLSMinVersion" // TLSCipherSuitesKey is the template data key for the comma-separated cipher suites TLSCipherSuitesKey = "TLSCipherSuites" // NginxTLSProtocolsKey is the template data key for NGINX ssl_protocols directive NginxTLSProtocolsKey = "NginxTLSProtocols" // NginxTLSCiphersKey is the template data key for NGINX ssl_ciphers directive NginxTLSCiphersKey = "NginxTLSCiphers" )
const ClusterConfigName = "cluster-config-v1"
const ClusterConfigNamespace = "kube-system"
const DPUNodeLeaseDurationDefault = 40
const DPUNodeLeaseRenewIntervalDefault = 10
DPUNodeLeaseRenewIntervalDefault and DPUNodeLeaseDurationDefault are the default DPU health check lease configuration. Setting renew-interval to 0 disables the health check.
const NetworkNodeIdentityNamespace = "openshift-network-node-identity"
const NetworkNodeIdentityWebhookPort = "9743"
const OVNCertCN = "ovn"
const OVNEgressIPHealthCheckPort = "9107"
OVNEgressIPHealthCheckPort is the gRPC healthcheck port. See: https://github.com/openshift/enhancements/pull/1209
const OVNLocalGWMode = "local"
const OVNLogPatternConsole = "%D{%Y-%m-%dT%H:%M:%S.###Z}|%05N|%c%T|%p|%m"
const OVNNodeIdentityCertDuration = "24h"
const OVNNodeModeDPU = "dpu"
const OVNNodeModeDPUHost = "dpu-host"
const OVNNodeModeFull = "full"
const OVNNodeModeSmartNIC = "smart-nic"
const OVNNodeSelectorDefaultDPU = "network.operator.openshift.io/dpu="
const OVNNodeSelectorDefaultDPUHost = "network.operator.openshift.io/dpu-host="
const OVNNodeSelectorDefaultSmartNIC = "network.operator.openshift.io/smart-nic="
Variables ¶
This section is empty.
Functions ¶
func Bootstrap ¶
func Bootstrap(ctx context.Context, conf *operv1.Network, client cnoclient.Client) (*bootstrap.BootstrapResult, error)
Bootstrap creates resources required by the network plugin on the cloud.
func DeprecatedCanonicalize ¶
func DeprecatedCanonicalize(conf *operv1.NetworkSpec)
DeprecatedCanonicalize converts configuration to a canonical form for backward compatibility.
*** DO NOT ADD ANY NEW CANONICALIZATION TO THIS FUNCTION! ***
Altering the user-provided configuration from CNO causes problems when other components need to look at the configuration before CNO starts. Users should just write the configuration in the correct form to begin with.
However, we cannot remove any of the existing canonicalizations because this might break existing clusters.
func FillDefaults ¶
func FillDefaults(conf, previous *operv1.NetworkSpec, hostMTU int)
FillDefaults computes any default values and applies them to the configuration This is a mutating operation. It should be called after Validate.
Defaults are carried forward from previous if it is provided. This is so we can change defaults as we move forward, but won't disrupt existing clusters.
We may need to know the MTU of nodes in the cluster, so we can compute the correct underlay MTU for OVN-K.
func GetDefaultMTU ¶
GetDefaultMTU gets the mtu of the default route.
func GetIPsecMode ¶
func GetIPsecMode(conf *operv1.OVNKubernetesConfig) operv1.IPsecMode
GetIPsecMode return the ipsec mode accounting for upgrade scenarios Find the IPsec mode from the IPsecConfig in the OVNKubernetesConfig. if IPsecConfig == nil (bw compatibility) || IPsecConfig == Off ==> ipsec is disabled if IPsecConfig.mode == "" (bw compatibility) || IPsecConfig == Full ==> ipsec is enabled for NS and EW if IPsecConfig.mode == External ==> ipsec is enabled for NS only
func GetTLSProfile ¶
func GetTLSProfile(ctx context.Context, client cnoclient.Client, hcp *hypershift.HostedControlPlane) (bootstrap.TLSProfile, error)
GetTLSProfile fetches the TLS profile from either the APIServer (standalone) or HostedControlPlane (HyperShift)
func IsChangeSafe ¶
func IsChangeSafe(prev, next *operv1.NetworkSpec, infraStatus *bootstrap.InfraStatus) error
IsChangeSafe checks to see if the change between prev and next are allowed FillDefaults and Validate should have been called, but beware that prev may be from an older version.
func IsIPsecLegacyAPI ¶
func IsIPsecLegacyAPI(conf *operv1.OVNKubernetesConfig) bool
IsIPsecLegacyAPI returns true if the old (pre 4.15) IPsec API is used, and false otherwise.
func IsMultusAdmissionControllerIgnoredNamespace ¶
IsMultusAdmissionControllerIgnoredNamespace reports whether a namespace should be excluded from Multus admission validation.
func MergeClusterConfig ¶
func MergeClusterConfig(operConf *operv1.NetworkSpec, clusterConf configv1.NetworkSpec)
MergeClusterConfig merges the cluster configuration into the real CRD configuration.
func NeedMTUProbe ¶
func NeedMTUProbe(prev, next *operv1.NetworkSpec) bool
NeedMTUProbe returns true if we need to probe the cluster's MTU. We need this if we don't have an MTU configured, either directly, or previously to "carry forward". If not, we'll have to probe it.
func Render ¶
func Render(ctx context.Context, operConf *operv1.NetworkSpec, clusterConf *configv1.NetworkSpec, manifestDir string, client cnoclient.Client, featureGates featuregates.FeatureGate, bootstrapResult *bootstrap.BootstrapResult) ([]*uns.Unstructured, bool, error)
func StatusFromOperatorConfig ¶
func StatusFromOperatorConfig(operConf *operv1.NetworkSpec, oldStatus *configv1.NetworkStatus) *configv1.NetworkStatus
StatusFromOperatorConfig generates the cluster NetworkStatus from the currently applied operator configuration.
func Validate ¶
func Validate(conf *operv1.NetworkSpec) error
Validate checks that the supplied configuration is reasonable. This should be called after Canonicalize
func ValidateClusterConfig ¶
func ValidateClusterConfig(clusterConfig *configv1.Network, infraRes *bootstrap.InfraStatus, featureGates featuregates.FeatureGate) error
ValidateClusterConfig ensures the cluster config is valid.
func ValidateMTUForNoOverlay ¶
func ValidateMTUForNoOverlay(conf *operv1.NetworkSpec, hostMTU int) error
ValidateMTUForNoOverlay validates that the configured MTU does not exceed the host MTU when no-overlay mode is enabled for the default network. In no-overlay mode, there is no encapsulation overhead, so the MTU can be set up to the host MTU but not higher.
Types ¶
This section is empty.