Sitelet https://github.com/kubernetes/kops/commit/512f9befb177ae277e25a0edd6fea52209367cd2
Skip to content

Commit 512f9be

Browse files
authored
Merge pull request #18211 from mfbonfigli/nlb_security_group_mode
Support NLBSecurityGroupMode for AWS Cloud Controller Manager
2 parents 9eeeaa4 + 22ab7ab commit 512f9be

21 files changed

Lines changed: 416 additions & 3 deletions

File tree

‎k8s/crds/kops.k8s.io_clusters.yaml‎

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -503,6 +503,11 @@ spec:
503503
multizone:
504504
description: GCE cloud-config options
505505
type: boolean
506+
nlbSecurityGroupMode:
507+
description: |-
508+
NLBSecurityGroupMode determines if the Cloud Controller Manager supports and manages
509+
security groups for Network Load Balancers (AWS only). Valid value: "Managed"
510+
type: string
506511
nodeIPFamilies:
507512
description: NodeIPFamilies controls the IP families reported
508513
for each node (AWS only).

‎nodeup/pkg/model/cloudconfig.go‎

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -104,6 +104,9 @@ func (b *CloudConfigBuilder) build(c *fi.NodeupModelBuilderContext, inTree bool)
104104
if b.NodeupConfig.ElbSecurityGroup != nil {
105105
lines = append(lines, "ElbSecurityGroup = "+*b.NodeupConfig.ElbSecurityGroup)
106106
}
107+
if b.NodeupConfig.NLBSecurityGroupMode != nil {
108+
lines = append(lines, "NLBSecurityGroupMode = "+*b.NodeupConfig.NLBSecurityGroupMode)
109+
}
107110
if !inTree {
108111
for _, family := range b.NodeupConfig.NodeIPFamilies {
109112
lines = append(lines, "NodeIPFamilies = "+family)

‎nodeup/pkg/model/cloudconfig_test.go‎

Lines changed: 46 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -159,3 +159,49 @@ func TestBuildAWSCustomNodeIPFamilies(t *testing.T) {
159159
t.Errorf("actual did not match expected:\n%s\n", diffString)
160160
}
161161
}
162+
163+
func TestBuildAWSNLBSecurityGroupMode(t *testing.T) {
164+
nlbSecurityGroupMode := "Managed"
165+
b := &CloudConfigBuilder{
166+
NodeupModelContext: &NodeupModelContext{
167+
BootConfig: &nodeup.BootConfig{
168+
CloudProvider: kops.CloudProviderAWS,
169+
},
170+
NodeupConfig: &nodeup.Config{
171+
NLBSecurityGroupMode: &nlbSecurityGroupMode,
172+
},
173+
HasAPIServer: true,
174+
},
175+
}
176+
ctx := &fi.NodeupModelBuilderContext{
177+
Tasks: map[string]fi.NodeupTask{},
178+
}
179+
if err := b.Build(ctx); err != nil {
180+
t.Fatalf("unexpected error from Build(): %v", err)
181+
}
182+
var task *nodetasks.File
183+
for _, v := range ctx.Tasks {
184+
if f, ok := v.(*nodetasks.File); ok && f.Path == CloudConfigFilePath {
185+
task = f
186+
break
187+
}
188+
}
189+
if task == nil {
190+
t.Fatalf("no File task found")
191+
}
192+
r, err := task.Contents.Open()
193+
if err != nil {
194+
t.Fatalf("unexpected error from task.Contents.Open(): %v", err)
195+
}
196+
awsCloudConfig, err := io.ReadAll(r)
197+
if err != nil {
198+
t.Fatalf("unexpected error from ReadAll(): %v", err)
199+
}
200+
201+
actual := string(awsCloudConfig)
202+
expected := "[global]\nNLBSecurityGroupMode = Managed\n"
203+
if actual != expected {
204+
diffString := diff.FormatDiff(expected, actual)
205+
t.Errorf("actual did not match expected:\n%s\n", diffString)
206+
}
207+
}

‎pkg/apis/kops/cluster.go‎

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -230,6 +230,9 @@ type AWSSpec struct {
230230
// Manager to assign to each ELB provisioned for a Service, instead of creating
231231
// one per ELB.
232232
ElbSecurityGroup *string `json:"elbSecurityGroup,omitempty"`
233+
// NLBSecurityGroupMode determines if the Cloud Controller Manager supports and manages
234+
// security groups for Network Load Balancers (AWS only). Valid value: "Managed"
235+
NLBSecurityGroupMode *string `json:"nlbSecurityGroupMode,omitempty"`
233236

234237
// Spotinst cloud-config specs
235238
SpotinstProduct *string `json:"spotinstProduct,omitempty"`

‎pkg/apis/kops/v1alpha2/componentconfig.go‎

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -999,6 +999,10 @@ type CloudConfiguration struct {
999999
// one per ELB (AWS only).
10001000
// +k8s:conversion-gen=false
10011001
ElbSecurityGroup *string `json:"elbSecurityGroup,omitempty"`
1002+
// NLBSecurityGroupMode determines if the Cloud Controller Manager supports and manages
1003+
// security groups for Network Load Balancers (AWS only). Valid value: "Managed"
1004+
// +k8s:conversion-gen=false
1005+
NLBSecurityGroupMode *string `json:"nlbSecurityGroupMode,omitempty"`
10021006
// VSphereUsername is unused.
10031007
// +k8s:conversion-gen=false
10041008
VSphereUsername *string `json:"vSphereUsername,omitempty"`

‎pkg/apis/kops/v1alpha2/conversion.go‎

Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -222,6 +222,13 @@ func Convert_v1alpha2_ClusterSpec_To_kops_ClusterSpec(in *ClusterSpec, out *kops
222222
val := *in.CloudConfig.ElbSecurityGroup
223223
out.CloudProvider.AWS.ElbSecurityGroup = &val
224224
}
225+
if in.CloudConfig.NLBSecurityGroupMode != nil {
226+
if out.CloudProvider.AWS == nil {
227+
return field.Forbidden(field.NewPath("spec").Child("cloudConfig", "nlbSecurityGroupMode"), "nlbSecurityGroupMode supports only AWS")
228+
}
229+
val := *in.CloudConfig.NLBSecurityGroupMode
230+
out.CloudProvider.AWS.NLBSecurityGroupMode = &val
231+
}
225232
if in.CloudConfig.GCPPDCSIDriver != nil {
226233
if out.CloudProvider.GCE == nil {
227234
return field.Forbidden(field.NewPath("spec").Child("cloudConfig", "gcpPDCSIDriver"), "PD CSI driver supports only GCE")
@@ -472,6 +479,13 @@ func Convert_kops_ClusterSpec_To_v1alpha2_ClusterSpec(in *kops.ClusterSpec, out
472479
val := *aws.ElbSecurityGroup
473480
out.CloudConfig.ElbSecurityGroup = &val
474481
}
482+
if aws.NLBSecurityGroupMode != nil {
483+
if out.CloudConfig == nil {
484+
out.CloudConfig = &CloudConfiguration{}
485+
}
486+
val := *aws.NLBSecurityGroupMode
487+
out.CloudConfig.NLBSecurityGroupMode = &val
488+
}
475489
if aws.NodeTerminationHandler != nil {
476490
out.NodeTerminationHandler = &NodeTerminationHandlerSpec{}
477491
if err := autoConvert_kops_NodeTerminationHandlerSpec_To_v1alpha2_NodeTerminationHandlerSpec(aws.NodeTerminationHandler, out.NodeTerminationHandler, s); err != nil {

‎pkg/apis/kops/v1alpha2/zz_generated.conversion.go‎

Lines changed: 1 addition & 0 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

‎pkg/apis/kops/v1alpha2/zz_generated.deepcopy.go‎

Lines changed: 5 additions & 0 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

‎pkg/apis/kops/v1alpha3/cluster.go‎

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -221,6 +221,9 @@ type AWSSpec struct {
221221
// Manager to assign to each ELB provisioned for a Service, instead of creating
222222
// one per ELB.
223223
ElbSecurityGroup *string `json:"elbSecurityGroup,omitempty"`
224+
// NLBSecurityGroupMode determines if the Cloud Controller Manager supports and manages
225+
// security groups for Network Load Balancers (AWS only). Valid value: "Managed"
226+
NLBSecurityGroupMode *string `json:"nlbSecurityGroupMode,omitempty"`
224227

225228
// Spotinst cloud-config specs
226229
SpotinstProduct *string `json:"spotinstProduct,omitempty"`

‎pkg/apis/kops/v1alpha3/zz_generated.conversion.go‎

Lines changed: 2 additions & 0 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

0 commit comments

Comments
 (0)