Skip to content

feat: Turn a network's egress on or off under a running workload - #613

Draft
scotwells wants to merge 1 commit into
feat/per-network-egress-routefrom
feat/egress-claim-sweep
Draft

scotwells wants to merge 1 commit into
feat/per-network-egress-routefrom
feat/egress-claim-sweep

Conversation

@scotwells

Copy link
Copy Markdown
Contributor

Summary

Enabling or disabling internet egress on a network only reached a running workload when it was attached again, because the node reads the declaration once, at attach time, and nothing re-reads it after the plugin exits.

The cell now records an EgressShardClaim against a node for each attachment whose network declares egress, and deletes it when the declaration is withdrawn. On its existing 30-second sweep the installer lists the claims naming its node and keeps each tenant VRF in step: a claimed VRF without an egress route gets one, and an unclaimed VRF with a route loses it.

A route written at attach time is left alone for two minutes before the sweep will withdraw it, which covers the gap between the attach returning and the cell recording the claim.

Test plan

  • Enabling egress on a network gives a running workload a default route within one sweep, and disabling it withdraws the route without touching the workload
  • A workload attached to a node whose claim has not appeared yet keeps its route through the grace period
  • A claimed VRF on a node naming no shard is logged and left for the next sweep rather than failed
  • Build, lint, and unit tests pass, including the root suite

Related to datum-cloud/network-services-operator#475

🤖 Generated with Claude Code

ADD installs a network's egress route from the declaration in its own
conflist stanza and nothing re-reads it once the plugin exits, so
enabling or disabling egress on a network only reached a workload when
it was attached again.

The installer now lists the EgressShardClaims the cell records against
this node on its 30-second sweep and keeps each tenant VRF in step: a
claimed VRF without a route gets one, an unclaimed VRF with a route
loses it. A route ADD wrote is left alone for two minutes, which covers
the gap between ADD returning and the cell recording the claim.

Key changes:
- Move the tenant SID rewrite and the install and withdraw helpers into
  a package both the plugin and the installer use
- Add the claim sweep, planned from the VRF registry and the egress
  route map and applied through the shared helpers
- Grant galactic-cni read access to egressshardclaims
- Pin the network API at the commit that adds the claim

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant