Conversation
ADD installs a network's egress route from the declaration in its own conflist stanza and nothing re-reads it once the plugin exits, so enabling or disabling egress on a network only reached a workload when it was attached again. The installer now lists the EgressShardClaims the cell records against this node on its 30-second sweep and keeps each tenant VRF in step: a claimed VRF without a route gets one, an unclaimed VRF with a route loses it. A route ADD wrote is left alone for two minutes, which covers the gap between ADD returning and the cell recording the claim. Key changes: - Move the tenant SID rewrite and the install and withdraw helpers into a package both the plugin and the installer use - Add the claim sweep, planned from the VRF registry and the egress route map and applied through the shared helpers - Grant galactic-cni read access to egressshardclaims - Pin the network API at the commit that adds the claim Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
4 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Enabling or disabling internet egress on a network only reached a running workload when it was attached again, because the node reads the declaration once, at attach time, and nothing re-reads it after the plugin exits.
The cell now records an EgressShardClaim against a node for each attachment whose network declares egress, and deletes it when the declaration is withdrawn. On its existing 30-second sweep the installer lists the claims naming its node and keeps each tenant VRF in step: a claimed VRF without an egress route gets one, and an unclaimed VRF with a route loses it.
A route written at attach time is left alone for two minutes before the sweep will withdraw it, which covers the gap between the attach returning and the cell recording the claim.
Test plan
Related to datum-cloud/network-services-operator#475
🤖 Generated with Claude Code