Documentation
¶
Overview ¶
Package etcd provides a component for managing an etcd server using containerd. The component uses host networking with non-default ports (12379 for client, 12380 for peer) to avoid conflicts with existing etcd installations.
Index ¶
- Constants
- func Snapshot(ctx context.Context, log *slog.Logger, endpoint string, tls *TLSConfig, ...) error
- func VerifySnapshot(path string) error
- type Backup
- type EtcdComponent
- func (e *EtcdComponent) ClientEndpoint() string
- func (e *EtcdComponent) PeerEndpoint() string
- func (e *EtcdComponent) Restore(ctx context.Context, opts RestoreOptions) error
- func (e *EtcdComponent) SetMetricsWriter(w metrics.PointWriter)
- func (e *EtcdComponent) Start(ctx context.Context, config EtcdConfig) error
- func (e *EtcdComponent) StartMaintenanceLoop(ctx context.Context)
- func (e *EtcdComponent) TLSEnabled() bool
- type EtcdConfig
- type RestoreOptions
- type TLSConfig
Constants ¶
const (
// ContainerName is the containerd identity of Miren's embedded etcd.
ContainerName = "miren-etcd"
)
const DefaultBackupsToKeep = 3
DefaultBackupsToKeep bounds the pre-upgrade snapshots kept on disk. More than the one a rollback needs, because an upgrade that passed readiness can still turn out bad later and the snapshot is what an operator would reach for; few enough that the etcd quota bounds the disk they take.
Variables ¶
This section is empty.
Functions ¶
func Snapshot ¶ added in v0.16.0
func Snapshot(ctx context.Context, log *slog.Logger, endpoint string, tls *TLSConfig, path string) error
Snapshot writes a consistent copy of the etcd backend to path, in the format etcdctl snapshot save produces: the database followed by its sha256, which etcdutl snapshot restore verifies. It dials endpoint the way the maintenance loop does, so it works from any process that can read the server's certificates.
func VerifySnapshot ¶ added in v0.16.0
VerifySnapshot checks that path is a complete etcd snapshot: the database is page-aligned and the trailing sha256 matches it. It is what restore checks too, but running it first means a bad file is found before etcd is stopped for it.
Types ¶
type Backup ¶ added in v0.16.0
type Backup struct {
Dir string
Endpoint string
TLS *TLSConfig
// Keep is how many snapshots survive, newest first; 0 means
// DefaultBackupsToKeep.
Keep int
Log *slog.Logger
}
Backup is the lifecycle executor's DataBackup for a server with embedded etcd: one snapshot per operation under Dir, named by the operation id so the directory lists in operation order. The reference it hands back is the snapshot's path, which is what the server's data-restore component expects to find in a DataRestore request.
type EtcdComponent ¶
type EtcdComponent struct {
*base.BaseComponent
// contains filtered or unexported fields
}
func NewEtcdComponent ¶
func NewEtcdComponent(log *slog.Logger, cc *containerd.Client, namespace, dataPath string) *EtcdComponent
func (*EtcdComponent) ClientEndpoint ¶
func (e *EtcdComponent) ClientEndpoint() string
func (*EtcdComponent) PeerEndpoint ¶
func (e *EtcdComponent) PeerEndpoint() string
func (*EtcdComponent) Restore ¶ added in v0.16.0
func (e *EtcdComponent) Restore(ctx context.Context, opts RestoreOptions) error
Restore replaces the etcd data directory under the component's data path with the contents of a snapshot, using etcdutl from the same image the server runs, so the data directory is built by the version that will read it. It is meant for a server that is booting after the previous process died or was restarted. A graceful stop took that process's etcd down with it, but an unclean death (KillMode=process) leaves the container running; if so its task is stopped here, and the container is left in place for Start to reuse with a new task. Nothing else may be using etcd.
The new data directory is built in a staging directory and swapped in only once etcdutl has succeeded, so a failed restore leaves the live data untouched. The previous data directory is kept as etcd.replaced-<label>.
func (*EtcdComponent) SetMetricsWriter ¶ added in v0.12.0
func (e *EtcdComponent) SetMetricsWriter(w metrics.PointWriter)
SetMetricsWriter configures the metrics sink for the maintenance loop's health gauges. Safe to call with nil or at any time (the maintenance loop reads it atomically each tick).
func (*EtcdComponent) Start ¶
func (e *EtcdComponent) Start(ctx context.Context, config EtcdConfig) error
func (*EtcdComponent) StartMaintenanceLoop ¶ added in v0.7.0
func (e *EtcdComponent) StartMaintenanceLoop(ctx context.Context)
StartMaintenanceLoop runs a background goroutine that periodically checks etcd database health and triggers defragmentation when the BoltDB file has grown significantly larger than its live data. Compaction (already configured as periodic/1h) marks old revisions as deleted, but BoltDB never releases pages without an explicit defrag.
func (*EtcdComponent) TLSEnabled ¶ added in v0.4.0
func (e *EtcdComponent) TLSEnabled() bool
TLSEnabled returns whether TLS is enabled for client connections.
type EtcdConfig ¶
type EtcdConfig struct {
Name string
DataDir string
ClientPort int
HTTPClientPort int
PeerPort int
InitialToken string
ClusterState string
TLS *TLSConfig // If set, enables mTLS for client connections
// QuotaBackendBytes, when > 0, sets --quota-backend-bytes explicitly. When 0 the
// value is auto-derived from system RAM (see computeTuning).
QuotaBackendBytes int64
}
type RestoreOptions ¶ added in v0.16.0
type RestoreOptions struct {
// Snapshot is the host path of the file to restore.
Snapshot string
// Config must carry the same Name and PeerPort the container is started
// with; a data directory built for a different member name or peer URL
// makes etcd refuse to start.
Config EtcdConfig
// Label distinguishes the data directory moved aside by this restore,
// typically the operation id that asked for it.
Label string
}
RestoreOptions names the snapshot to restore and the member identity to build it for.