nodeup: reduce binary size by decoupling from cloudup awsup - #18571
Conversation
…tstrap The STS-based node bootstrap protocol (authenticator, verifier and shared token format) moves from upup/pkg/fi/cloudup/awsup to a leaf package, following the pkibootstrap layout. This lets nodeup build the AWS authenticator without importing the full awsup cloud implementation and all AWS SDK service clients it constructs.
nodeup only needs the region, two EC2 calls (DescribeInstanceTypes, AssignIpv6Addresses) and the warm pool lifecycle hook calls, but by importing upup/pkg/fi/cloudup/awsup it linked every AWS SDK client that awsCloudImplementation constructs. Because nodeup also contains reflect MethodByName call sites, storing those clients in interfaces kept every operation of every service in the binary. Introduce upup/pkg/fi/nodeup/awsup with a concrete Cloud type that only constructs the EC2 and autoscaling clients, and store it as a concrete type in NodeupModelContext and LocalTarget so unused SDK operations are dead-code eliminated.
pkg/kopscontrollerclient imported the whole upup/pkg/fi/cloudup package only for the PlaceholderIP/PlaceholderIPv6 constants, which pulled the entire cloudup task graph (awsmodel, awstasks, spotinst, ...) into the nodeup binary. Move the constants to the leaf pkg/dns package.
nodeup/pkg/model imported pkg/model/components/kubescheduler only for the two path constants, which pulled pkg/model and the cloudup awstasks graph into the nodeup binary. Move the constants to a leaf package shared by both sides.
The lean Cloud type still retained every EC2 and autoscaling operation:
nodeup contains reflect MethodByName call sites, and the linker
propagates the used-in-interface property from interface-stored types
(NodeupModelContext, LocalTarget) through all struct fields,
transitively, marking every exported method of the SDK clients
reachable. Verified with -ldflags=-dumpdep:
type:nodeup/pkg/model.NodeupModelContext <UsedInIface>
-> type:*upup/pkg/fi/nodeup/awsup.Cloud <UsedInIface>
type:upup/pkg/fi/nodeup/awsup.Cloud <UsedInIface>
-> type:*aws-sdk-go-v2/service/ec2.Client <UsedInIface>
Keep Cloud as a region-only handle and move the SDK clients to
unexported package state, which is referenced from code but not from
any type descriptor. Also stop importing pkg/nodeidentity/aws from the
verifier, which stores *ec2.Client in an interface, for the same
reason.
This reduces the linux/arm64 nodeup binary (-trimpath -s -w) from
121962658 to 73924770 bytes. Retained ec2.Client methods drop from
2252 to 10.
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: rifelpet The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:
Approvers can indicate their approval by writing |
|
/override pull-kops-e2e-azure-cni-cilium |
|
@hakman: Overrode contexts on behalf of hakman: pull-kops-e2e-azure-cni-cilium DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
|
/override pull-kops-e2e-cni-cilium-eni |
|
@hakman: Overrode contexts on behalf of hakman: pull-kops-e2e-cni-cilium-eni DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
The nodeup binary embedded most of the AWS SDK v2 because it imported
upup/pkg/fi/cloudup/awsup, whose cloud implementation constructs clients for EC2, IAM, SSM, S3, Autoscaling, Route53, ELB, ELBv2, EventBridge, SQS and STS. nodeup also containsreflect.Value.MethodByNamecall sites, so the linker keeps every exported method of any type reachable from an interface-stored type. Verified with-ldflags=-dumpdep, this retained all EC2 operations (2252ec2.Clientmethods) even though nodeup only calls two of them.This PR removes cloudup and its AWS dependencies from the nodeup dependency graph:
pkg/bootstrap/awsbootstrap, following thepkibootstraplayout.upup/pkg/fi/nodeup/awsuppackage that constructs only the EC2 and Autoscaling clients. The clients live in unexported package state rather than struct fields, because the linker propagates the used-in-interface property through all struct fields of interface-stored types such asNodeupModelContext; keeping the clients out of reach of reflection allows dead-code elimination of the unused SDK operations.pkg/dns, so thatpkg/kopscontrollerclientno longer imports all ofupup/pkg/fi/cloudupfor two constants.pkg/wellknownpathspackage, so thatnodeup/pkg/modelno longer pullspkg/modeland the cloudup task graph.Results for linux/arm64 with
-trimpath -ldflags="-s -w":ec2.Clientmethods drop from 2252 to 10,autoscaling.Clientfrom 203 to 10.Behavior is unchanged: same AWS config loading (adaptive retries,
KOPS_AWS_ROLE_ARNsupport, request logging), same machine type caching, and the same warm pool, dryrun and bootstrap code paths. The kops-controller configuration JSON shape is unchanged.