Sitelet https://github.com/kubernetes/kops/pull/18571
Skip to content

nodeup: reduce binary size by decoupling from cloudup awsup - #18571

Merged
kubernetes-prow[bot] merged 5 commits into
kubernetes:masterfrom
hakman:nodeup-lean-aws
Jul 10, 2026
Merged

kubernetes-prow[bot] merged 5 commits into
kubernetes:masterfrom
hakman:nodeup-lean-aws

Conversation

@hakman

@hakman hakman commented Jul 10, 2026

Copy link
Copy Markdown
Member

The nodeup binary embedded most of the AWS SDK v2 because it imported upup/pkg/fi/cloudup/awsup, whose cloud implementation constructs clients for EC2, IAM, SSM, S3, Autoscaling, Route53, ELB, ELBv2, EventBridge, SQS and STS. nodeup also contains reflect.Value.MethodByName call sites, so the linker keeps every exported method of any type reachable from an interface-stored type. Verified with -ldflags=-dumpdep, this retained all EC2 operations (2252 ec2.Client methods) even though nodeup only calls two of them.

This PR removes cloudup and its AWS dependencies from the nodeup dependency graph:

  • Move the AWS bootstrap authenticator and verifier to a new leaf package pkg/bootstrap/awsbootstrap, following the pkibootstrap layout.
  • Add a lean upup/pkg/fi/nodeup/awsup package that constructs only the EC2 and Autoscaling clients. The clients live in unexported package state rather than struct fields, because the linker propagates the used-in-interface property through all struct fields of interface-stored types such as NodeupModelContext; keeping the clients out of reach of reflection allows dead-code elimination of the unused SDK operations.
  • Move the DNS placeholder IPs to pkg/dns, so that pkg/kopscontrollerclient no longer imports all of upup/pkg/fi/cloudup for two constants.
  • Move the kube-scheduler file paths to a new pkg/wellknownpaths package, so that nodeup/pkg/model no longer pulls pkg/model and the cloudup task graph.

Results for linux/arm64 with -trimpath -ldflags="-s -w":

  • nodeup shrinks from 121962658 to 73138338 bytes, about 40% smaller.
  • Retained ec2.Client methods drop from 2252 to 10, autoscaling.Client from 203 to 10.
  • The only AWS service clients left in the dependency graph are ec2, autoscaling, s3 and sts, plus the sso/ssooidc/signin packages of the credentials chain.
  • kops, kops-controller, protokube and channels are unchanged in size.

Behavior is unchanged: same AWS config loading (adaptive retries, KOPS_AWS_ROLE_ARN support, request logging), same machine type caching, and the same warm pool, dryrun and bootstrap code paths. The kops-controller configuration JSON shape is unchanged.

hakman added 5 commits July 10, 2026 12:40
…tstrap

The STS-based node bootstrap protocol (authenticator, verifier and
shared token format) moves from upup/pkg/fi/cloudup/awsup to a leaf
package, following the pkibootstrap layout. This lets nodeup build the
AWS authenticator without importing the full awsup cloud
implementation and all AWS SDK service clients it constructs.
nodeup only needs the region, two EC2 calls (DescribeInstanceTypes,
AssignIpv6Addresses) and the warm pool lifecycle hook calls, but by
importing upup/pkg/fi/cloudup/awsup it linked every AWS SDK client that
awsCloudImplementation constructs. Because nodeup also contains
reflect MethodByName call sites, storing those clients in interfaces
kept every operation of every service in the binary.

Introduce upup/pkg/fi/nodeup/awsup with a concrete Cloud type that only
constructs the EC2 and autoscaling clients, and store it as a concrete
type in NodeupModelContext and LocalTarget so unused SDK operations are
dead-code eliminated.
pkg/kopscontrollerclient imported the whole upup/pkg/fi/cloudup package
only for the PlaceholderIP/PlaceholderIPv6 constants, which pulled the
entire cloudup task graph (awsmodel, awstasks, spotinst, ...) into the
nodeup binary. Move the constants to the leaf pkg/dns package.
nodeup/pkg/model imported pkg/model/components/kubescheduler only for
the two path constants, which pulled pkg/model and the cloudup awstasks
graph into the nodeup binary. Move the constants to a leaf package
shared by both sides.
The lean Cloud type still retained every EC2 and autoscaling operation:
nodeup contains reflect MethodByName call sites, and the linker
propagates the used-in-interface property from interface-stored types
(NodeupModelContext, LocalTarget) through all struct fields,
transitively, marking every exported method of the SDK clients
reachable. Verified with -ldflags=-dumpdep:

  type:nodeup/pkg/model.NodeupModelContext <UsedInIface>
    -> type:*upup/pkg/fi/nodeup/awsup.Cloud <UsedInIface>
  type:upup/pkg/fi/nodeup/awsup.Cloud <UsedInIface>
    -> type:*aws-sdk-go-v2/service/ec2.Client <UsedInIface>

Keep Cloud as a region-only handle and move the SDK clients to
unexported package state, which is referenced from code but not from
any type descriptor. Also stop importing pkg/nodeidentity/aws from the
verifier, which stores *ec2.Client in an interface, for the same
reason.

This reduces the linux/arm64 nodeup binary (-trimpath -s -w) from
121962658 to 73924770 bytes. Retained ec2.Client methods drop from
2252 to 10.
@kubernetes-prow
kubernetes-prow Bot requested review from olemarkus and zetaab July 10, 2026 09:46
@kubernetes-prow kubernetes-prow Bot added area/kops-controller cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. area/nodeup area/provider/aws Issues or PRs related to aws provider size/L Denotes a PR that changes 100-499 lines, ignoring generated files. labels Jul 10, 2026
@hakman

hakman commented Jul 10, 2026

Copy link
Copy Markdown
Member Author

/cc @rifelpet @justinsb

@kubernetes-prow
kubernetes-prow Bot requested review from justinsb and rifelpet July 10, 2026 09:48
@kubernetes-prow kubernetes-prow Bot added the lgtm "Looks good to me", indicates that a PR is ready to be merged. label Jul 10, 2026
@kubernetes-prow

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: rifelpet

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@kubernetes-prow kubernetes-prow Bot added the approved Indicates a PR has been approved by an approver from all required OWNERS files. label Jul 10, 2026
@hakman

hakman commented Jul 10, 2026

Copy link
Copy Markdown
Member Author

/override pull-kops-e2e-azure-cni-cilium

@kubernetes-prow

Copy link
Copy Markdown
Contributor

@hakman: Overrode contexts on behalf of hakman: pull-kops-e2e-azure-cni-cilium

Details

In response to this:

/override pull-kops-e2e-azure-cni-cilium

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@hakman

hakman commented Jul 10, 2026

Copy link
Copy Markdown
Member Author

/override pull-kops-e2e-cni-cilium-eni

@kubernetes-prow

Copy link
Copy Markdown
Contributor

@hakman: Overrode contexts on behalf of hakman: pull-kops-e2e-cni-cilium-eni

Details

In response to this:

/override pull-kops-e2e-cni-cilium-eni

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@kubernetes-prow
kubernetes-prow Bot merged commit 2c6b569 into kubernetes:master Jul 10, 2026
34 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved Indicates a PR has been approved by an approver from all required OWNERS files. area/kops-controller area/nodeup area/provider/aws Issues or PRs related to aws provider cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. lgtm "Looks good to me", indicates that a PR is ready to be merged. size/L Denotes a PR that changes 100-499 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants