Sitelet https://github.com/kubernetes/kops/commit/e4d1b65ae300e9a646b582d0986d9ba259cd5ea6
Skip to content

Commit e4d1b65

Browse files
Merge pull request #18555 from hakman/automated-cherry-pick-of-#18450-upstream-release-1.35
Automated cherry pick of #18450: etcd-manager: switch to go-runner-based distroless image
2 parents 659f2f5 + e7f6719 commit e4d1b65

186 files changed

Lines changed: 3952 additions & 2145 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

‎pkg/flagbuilder/build_flags.go‎

Lines changed: 17 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -29,19 +29,23 @@ import (
2929
"k8s.io/kops/util/pkg/reflectutils"
3030
)
3131

32-
// BuildFlags returns a space separated list arguments
32+
// BuildFlags returns a space-separated list of arguments.
3333
// @deprecated: please use BuildFlagsList
3434
func BuildFlags(options interface{}) (string, error) {
35-
flags, err := BuildFlagsList(options)
35+
flags, err := buildFlagsList(options, maybeQuote)
3636
if err != nil {
3737
return "", err
3838
}
3939

4040
return strings.Join(flags, " "), nil
4141
}
4242

43-
// BuildFlagsList reflects the options interface and extracts the flags from struct tags
43+
// BuildFlagsList reflects the options interface and extracts the flags from struct tags.
4444
func BuildFlagsList(options interface{}) ([]string, error) {
45+
return buildFlagsList(options, neverQuote)
46+
}
47+
48+
func buildFlagsList(options interface{}, quote func(string) string) ([]string, error) {
4549
var flags []string
4650

4751
walker := func(path *reflectutils.FieldPath, field *reflect.StructField, val reflect.Value) error {
@@ -143,7 +147,7 @@ func BuildFlagsList(options interface{}) ([]string, error) {
143147
case string:
144148
vString := fmt.Sprintf("%v", v)
145149
if vString != "" && vString != flagEmpty {
146-
flag = fmt.Sprintf("--%s=%s", flagName, maybeQuote(vString))
150+
flag = fmt.Sprintf("--%s=%s", flagName, quote(vString))
147151
}
148152

149153
case *string:
@@ -152,10 +156,10 @@ func BuildFlagsList(options interface{}) ([]string, error) {
152156
// just like the string case above.
153157
vString := fmt.Sprintf("%v", *v)
154158
if flagIncludeEmpty {
155-
flag = fmt.Sprintf("--%s=%s", flagName, maybeQuote(vString))
159+
flag = fmt.Sprintf("--%s=%s", flagName, quote(vString))
156160
} else {
157161
if vString != "" && vString != flagEmpty {
158-
flag = fmt.Sprintf("--%s=%s", flagName, maybeQuote(vString))
162+
flag = fmt.Sprintf("--%s=%s", flagName, quote(vString))
159163
}
160164
}
161165
}
@@ -214,9 +218,16 @@ func BuildFlagsList(options interface{}) ([]string, error) {
214218
return flags, nil
215219
}
216220

221+
// maybeQuote quotes s when it contains a double quote, so values survive the space-separated
222+
// string form that a shell or systemd may parse. argv values use neverQuote instead.
217223
func maybeQuote(s string) string {
218224
if strings.Contains(s, "\"") {
219225
return fmt.Sprintf("%q", s)
220226
}
221227
return s
222228
}
229+
230+
// neverQuote returns s unchanged, for values used directly as exec argv.
231+
func neverQuote(s string) string {
232+
return s
233+
}

‎pkg/flagbuilder/buildflags_test.go‎

Lines changed: 39 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -17,6 +17,7 @@ limitations under the License.
1717
package flagbuilder
1818

1919
import (
20+
"strings"
2021
"testing"
2122
"time"
2223

@@ -242,3 +243,41 @@ func TestBuildAPIServerFlags(t *testing.T) {
242243
}
243244
}
244245
}
246+
247+
// TestBuildFlagsQuoting checks that the quote function is applied: neverQuote leaves argv values
248+
// verbatim while maybeQuote quotes those containing a double quote. Regression for etcd-manager's
249+
// --static-config JSON, executes directly via go-runner with no shell to strip quotes.
250+
func TestBuildFlagsQuoting(t *testing.T) {
251+
options := &struct {
252+
StaticConfig string `flag:"static-config"`
253+
}{
254+
StaticConfig: `{"etcdVersion":"3.6.12"}`,
255+
}
256+
257+
grid := []struct {
258+
Quote func(string) string
259+
Expected string
260+
}{
261+
{
262+
Quote: neverQuote,
263+
Expected: `--static-config={"etcdVersion":"3.6.12"}`,
264+
},
265+
{
266+
Quote: maybeQuote,
267+
Expected: `--static-config="{\"etcdVersion\":\"3.6.12\"}"`,
268+
},
269+
}
270+
271+
for _, test := range grid {
272+
flags, err := buildFlagsList(options, test.Quote)
273+
if err != nil {
274+
t.Errorf("error from buildFlagsList: %v", err)
275+
continue
276+
}
277+
278+
actual := strings.Join(flags, " ")
279+
if actual != test.Expected {
280+
t.Errorf("unexpected flags. actual=%q expected=%q", actual, test.Expected)
281+
}
282+
}
283+
}

‎pkg/model/components/etcdmanager/model.go‎

Lines changed: 8 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -45,7 +45,6 @@ import (
4545
"k8s.io/kops/upup/pkg/fi/cloudup/scaleway"
4646
"k8s.io/kops/upup/pkg/fi/fitasks"
4747
"k8s.io/kops/util/pkg/env"
48-
"k8s.io/kops/util/pkg/exec"
4948
"k8s.io/kops/util/pkg/vfs"
5049
)
5150

@@ -210,7 +209,7 @@ metadata:
210209
spec:
211210
containers:
212211
- name: etcd-manager
213-
image: registry.k8s.io/etcd-manager/etcd-manager-slim:v3.0.20260531
212+
image: registry.k8s.io/etcd-manager/etcd-manager-slim:v3.0.20260608
214213
resources:
215214
requests:
216215
cpu: 100m
@@ -633,7 +632,13 @@ func (b *EtcdManagerBuilder) buildPod(etcdCluster kops.EtcdClusterSpec, instance
633632
}
634633

635634
{
636-
container.Command = exec.WithTee("/ko-app/etcd-manager", args, "/var/log/etcd.log")
635+
container.Command = []string{"/go-runner"}
636+
container.Args = []string{
637+
"--log-file=/var/log/etcd.log",
638+
"--also-stdout",
639+
"/ko-app/etcd-manager",
640+
}
641+
container.Args = append(container.Args, args...)
637642

638643
cpuRequest := resource.MustParse("200m")
639644
if etcdCluster.CPURequest != nil {

‎pkg/model/components/etcdmanager/tests/interval/tasks.yaml‎

Lines changed: 45 additions & 24 deletions
Original file line numberDiff line numberDiff line change
@@ -74,18 +74,28 @@ Contents: |
7474
namespace: kube-system
7575
spec:
7676
containers:
77-
- command:
78-
- /bin/sh
79-
- -c
80-
- mkfifo /tmp/pipe; (tee -a /var/log/etcd.log < /tmp/pipe & ) ; exec /ko-app/etcd-manager
81-
--backup-store=memfs://clusters.example.com/minimal.example.com/backups/etcd-events
82-
--client-urls=https://__name__:4002 --cluster-name=etcd-events --containerized=true
83-
--discovery-poll-interval=1m15s --dns-suffix=.internal.minimal.example.com --grpc-port=3997
84-
--peer-urls=https://__name__:2381 --quarantine-client-urls=https://__name__:3995
85-
--v=6 --volume-name-tag=k8s.io/etcd/events --volume-provider=aws --volume-tag=k8s.io/etcd/events
86-
--volume-tag=k8s.io/role/control-plane=1 --volume-tag=kubernetes.io/cluster/minimal.example.com=owned
87-
> /tmp/pipe 2>&1
88-
image: registry.k8s.io/etcd-manager/etcd-manager-slim:v3.0.20260531
77+
- args:
78+
- --log-file=/var/log/etcd.log
79+
- --also-stdout
80+
- /ko-app/etcd-manager
81+
- --backup-store=memfs://clusters.example.com/minimal.example.com/backups/etcd-events
82+
- --client-urls=https://__name__:4002
83+
- --cluster-name=etcd-events
84+
- --containerized=true
85+
- --discovery-poll-interval=1m15s
86+
- --dns-suffix=.internal.minimal.example.com
87+
- --grpc-port=3997
88+
- --peer-urls=https://__name__:2381
89+
- --quarantine-client-urls=https://__name__:3995
90+
- --v=6
91+
- --volume-name-tag=k8s.io/etcd/events
92+
- --volume-provider=aws
93+
- --volume-tag=k8s.io/etcd/events
94+
- --volume-tag=k8s.io/role/control-plane=1
95+
- --volume-tag=kubernetes.io/cluster/minimal.example.com=owned
96+
command:
97+
- /go-runner
98+
image: registry.k8s.io/etcd-manager/etcd-manager-slim:v3.0.20260608
8999
name: etcd-manager
90100
resources:
91101
requests:
@@ -248,18 +258,29 @@ Contents: |
248258
namespace: kube-system
249259
spec:
250260
containers:
251-
- command:
252-
- /bin/sh
253-
- -c
254-
- mkfifo /tmp/pipe; (tee -a /var/log/etcd.log < /tmp/pipe & ) ; exec /ko-app/etcd-manager
255-
--backup-interval=1h0m0s --backup-store=memfs://clusters.example.com/minimal.example.com/backups/etcd-main
256-
--client-urls=https://__name__:4001 --cluster-name=etcd --containerized=true
257-
--discovery-poll-interval=1m15s --dns-suffix=.internal.minimal.example.com --grpc-port=3996
258-
--peer-urls=https://__name__:2380 --quarantine-client-urls=https://__name__:3994
259-
--v=6 --volume-name-tag=k8s.io/etcd/main --volume-provider=aws --volume-tag=k8s.io/etcd/main
260-
--volume-tag=k8s.io/role/control-plane=1 --volume-tag=kubernetes.io/cluster/minimal.example.com=owned
261-
> /tmp/pipe 2>&1
262-
image: registry.k8s.io/etcd-manager/etcd-manager-slim:v3.0.20260531
261+
- args:
262+
- --log-file=/var/log/etcd.log
263+
- --also-stdout
264+
- /ko-app/etcd-manager
265+
- --backup-interval=1h0m0s
266+
- --backup-store=memfs://clusters.example.com/minimal.example.com/backups/etcd-main
267+
- --client-urls=https://__name__:4001
268+
- --cluster-name=etcd
269+
- --containerized=true
270+
- --discovery-poll-interval=1m15s
271+
- --dns-suffix=.internal.minimal.example.com
272+
- --grpc-port=3996
273+
- --peer-urls=https://__name__:2380
274+
- --quarantine-client-urls=https://__name__:3994
275+
- --v=6
276+
- --volume-name-tag=k8s.io/etcd/main
277+
- --volume-provider=aws
278+
- --volume-tag=k8s.io/etcd/main
279+
- --volume-tag=k8s.io/role/control-plane=1
280+
- --volume-tag=kubernetes.io/cluster/minimal.example.com=owned
281+
command:
282+
- /go-runner
283+
image: registry.k8s.io/etcd-manager/etcd-manager-slim:v3.0.20260608
263284
name: etcd-manager
264285
resources:
265286
requests:

‎pkg/model/components/etcdmanager/tests/minimal/tasks.yaml‎

Lines changed: 42 additions & 22 deletions
Original file line numberDiff line numberDiff line change
@@ -74,17 +74,27 @@ Contents: |
7474
namespace: kube-system
7575
spec:
7676
containers:
77-
- command:
78-
- /bin/sh
79-
- -c
80-
- mkfifo /tmp/pipe; (tee -a /var/log/etcd.log < /tmp/pipe & ) ; exec /ko-app/etcd-manager
81-
--backup-store=memfs://clusters.example.com/minimal.example.com/backups/etcd-events
82-
--client-urls=https://__name__:4002 --cluster-name=etcd-events --containerized=true
83-
--dns-suffix=.internal.minimal.example.com --grpc-port=3997 --peer-urls=https://__name__:2381
84-
--quarantine-client-urls=https://__name__:3995 --v=6 --volume-name-tag=k8s.io/etcd/events
85-
--volume-provider=aws --volume-tag=k8s.io/etcd/events --volume-tag=k8s.io/role/control-plane=1
86-
--volume-tag=kubernetes.io/cluster/minimal.example.com=owned > /tmp/pipe 2>&1
87-
image: registry.k8s.io/etcd-manager/etcd-manager-slim:v3.0.20260531
77+
- args:
78+
- --log-file=/var/log/etcd.log
79+
- --also-stdout
80+
- /ko-app/etcd-manager
81+
- --backup-store=memfs://clusters.example.com/minimal.example.com/backups/etcd-events
82+
- --client-urls=https://__name__:4002
83+
- --cluster-name=etcd-events
84+
- --containerized=true
85+
- --dns-suffix=.internal.minimal.example.com
86+
- --grpc-port=3997
87+
- --peer-urls=https://__name__:2381
88+
- --quarantine-client-urls=https://__name__:3995
89+
- --v=6
90+
- --volume-name-tag=k8s.io/etcd/events
91+
- --volume-provider=aws
92+
- --volume-tag=k8s.io/etcd/events
93+
- --volume-tag=k8s.io/role/control-plane=1
94+
- --volume-tag=kubernetes.io/cluster/minimal.example.com=owned
95+
command:
96+
- /go-runner
97+
image: registry.k8s.io/etcd-manager/etcd-manager-slim:v3.0.20260608
8898
name: etcd-manager
8999
resources:
90100
requests:
@@ -199,17 +209,27 @@ Contents: |
199209
namespace: kube-system
200210
spec:
201211
containers:
202-
- command:
203-
- /bin/sh
204-
- -c
205-
- mkfifo /tmp/pipe; (tee -a /var/log/etcd.log < /tmp/pipe & ) ; exec /ko-app/etcd-manager
206-
--backup-store=memfs://clusters.example.com/minimal.example.com/backups/etcd-main
207-
--client-urls=https://__name__:4001 --cluster-name=etcd --containerized=true
208-
--dns-suffix=.internal.minimal.example.com --grpc-port=3996 --peer-urls=https://__name__:2380
209-
--quarantine-client-urls=https://__name__:3994 --v=6 --volume-name-tag=k8s.io/etcd/main
210-
--volume-provider=aws --volume-tag=k8s.io/etcd/main --volume-tag=k8s.io/role/control-plane=1
211-
--volume-tag=kubernetes.io/cluster/minimal.example.com=owned > /tmp/pipe 2>&1
212-
image: registry.k8s.io/etcd-manager/etcd-manager-slim:v3.0.20260531
212+
- args:
213+
- --log-file=/var/log/etcd.log
214+
- --also-stdout
215+
- /ko-app/etcd-manager
216+
- --backup-store=memfs://clusters.example.com/minimal.example.com/backups/etcd-main
217+
- --client-urls=https://__name__:4001
218+
- --cluster-name=etcd
219+
- --containerized=true
220+
- --dns-suffix=.internal.minimal.example.com
221+
- --grpc-port=3996
222+
- --peer-urls=https://__name__:2380
223+
- --quarantine-client-urls=https://__name__:3994
224+
- --v=6
225+
- --volume-name-tag=k8s.io/etcd/main
226+
- --volume-provider=aws
227+
- --volume-tag=k8s.io/etcd/main
228+
- --volume-tag=k8s.io/role/control-plane=1
229+
- --volume-tag=kubernetes.io/cluster/minimal.example.com=owned
230+
command:
231+
- /go-runner
232+
image: registry.k8s.io/etcd-manager/etcd-manager-slim:v3.0.20260608
213233
name: etcd-manager
214234
resources:
215235
requests:

‎pkg/model/components/etcdmanager/tests/overwrite_settings/tasks.yaml‎

Lines changed: 42 additions & 22 deletions
Original file line numberDiff line numberDiff line change
@@ -74,20 +74,30 @@ Contents: |
7474
namespace: kube-system
7575
spec:
7676
containers:
77-
- command:
78-
- /bin/sh
79-
- -c
80-
- mkfifo /tmp/pipe; (tee -a /var/log/etcd.log < /tmp/pipe & ) ; exec /ko-app/etcd-manager
81-
--backup-store=memfs://clusters.example.com/minimal.example.com/backups/etcd-events
82-
--client-urls=https://__name__:4002 --cluster-name=etcd-events --containerized=true
83-
--dns-suffix=.internal.minimal.example.com --grpc-port=3997 --peer-urls=https://__name__:2381
84-
--quarantine-client-urls=https://__name__:3995 --v=3 --volume-name-tag=k8s.io/etcd/events
85-
--volume-provider=aws --volume-tag=k8s.io/etcd/events --volume-tag=k8s.io/role/control-plane=1
86-
--volume-tag=kubernetes.io/cluster/minimal.example.com=owned > /tmp/pipe 2>&1
77+
- args:
78+
- --log-file=/var/log/etcd.log
79+
- --also-stdout
80+
- /ko-app/etcd-manager
81+
- --backup-store=memfs://clusters.example.com/minimal.example.com/backups/etcd-events
82+
- --client-urls=https://__name__:4002
83+
- --cluster-name=etcd-events
84+
- --containerized=true
85+
- --dns-suffix=.internal.minimal.example.com
86+
- --grpc-port=3997
87+
- --peer-urls=https://__name__:2381
88+
- --quarantine-client-urls=https://__name__:3995
89+
- --v=3
90+
- --volume-name-tag=k8s.io/etcd/events
91+
- --volume-provider=aws
92+
- --volume-tag=k8s.io/etcd/events
93+
- --volume-tag=k8s.io/role/control-plane=1
94+
- --volume-tag=kubernetes.io/cluster/minimal.example.com=owned
95+
command:
96+
- /go-runner
8797
env:
8898
- name: ETCD_QUOTA_BACKEND_BYTES
8999
value: "10737418240"
90-
image: registry.k8s.io/etcd-manager/etcd-manager-slim:v3.0.20260531
100+
image: registry.k8s.io/etcd-manager/etcd-manager-slim:v3.0.20260608
91101
name: etcd-manager
92102
resources:
93103
requests:
@@ -250,20 +260,30 @@ Contents: |
250260
namespace: kube-system
251261
spec:
252262
containers:
253-
- command:
254-
- /bin/sh
255-
- -c
256-
- mkfifo /tmp/pipe; (tee -a /var/log/etcd.log < /tmp/pipe & ) ; exec /ko-app/etcd-manager
257-
--backup-store=memfs://clusters.example.com/minimal.example.com/backups/etcd-main
258-
--client-urls=https://__name__:4001 --cluster-name=etcd --containerized=true
259-
--dns-suffix=.internal.minimal.example.com --grpc-port=3996 --peer-urls=https://__name__:2380
260-
--quarantine-client-urls=https://__name__:3994 --v=3 --volume-name-tag=k8s.io/etcd/main
261-
--volume-provider=aws --volume-tag=k8s.io/etcd/main --volume-tag=k8s.io/role/control-plane=1
262-
--volume-tag=kubernetes.io/cluster/minimal.example.com=owned > /tmp/pipe 2>&1
263+
- args:
264+
- --log-file=/var/log/etcd.log
265+
- --also-stdout
266+
- /ko-app/etcd-manager
267+
- --backup-store=memfs://clusters.example.com/minimal.example.com/backups/etcd-main
268+
- --client-urls=https://__name__:4001
269+
- --cluster-name=etcd
270+
- --containerized=true
271+
- --dns-suffix=.internal.minimal.example.com
272+
- --grpc-port=3996
273+
- --peer-urls=https://__name__:2380
274+
- --quarantine-client-urls=https://__name__:3994
275+
- --v=3
276+
- --volume-name-tag=k8s.io/etcd/main
277+
- --volume-provider=aws
278+
- --volume-tag=k8s.io/etcd/main
279+
- --volume-tag=k8s.io/role/control-plane=1
280+
- --volume-tag=kubernetes.io/cluster/minimal.example.com=owned
281+
command:
282+
- /go-runner
263283
env:
264284
- name: ETCD_QUOTA_BACKEND_BYTES
265285
value: "10737418240"
266-
image: registry.k8s.io/etcd-manager/etcd-manager-slim:v3.0.20260531
286+
image: registry.k8s.io/etcd-manager/etcd-manager-slim:v3.0.20260608
267287
name: etcd-manager
268288
resources:
269289
requests:

0 commit comments

Comments
 (0)