Sitelet https://github.com/kubernetes/kops/pull/18571/files
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions cmd/kops-controller/main.go
Original file line number Diff line number Diff line change
Expand Up @@ -36,6 +36,7 @@ import (
"k8s.io/kops/cmd/kops-controller/pkg/server"
"k8s.io/kops/pkg/apis/kops/v1alpha2"
"k8s.io/kops/pkg/bootstrap"
"k8s.io/kops/pkg/bootstrap/awsbootstrap"
"k8s.io/kops/pkg/bootstrap/pkibootstrap"
"k8s.io/kops/pkg/client/simple"
"k8s.io/kops/pkg/controllers/clusterapi"
Expand All @@ -50,7 +51,6 @@ import (
nodeidentitymetal "k8s.io/kops/pkg/nodeidentity/metal"
nodeidentityos "k8s.io/kops/pkg/nodeidentity/openstack"
nodeidentityscw "k8s.io/kops/pkg/nodeidentity/scaleway"
"k8s.io/kops/upup/pkg/fi/cloudup/awsup"
"k8s.io/kops/upup/pkg/fi/cloudup/azure"
"k8s.io/kops/upup/pkg/fi/cloudup/do"
"k8s.io/kops/upup/pkg/fi/cloudup/gce/tpm/gcetpmverifier"
Expand Down Expand Up @@ -150,7 +150,7 @@ func main() {
var verifiers []bootstrap.Verifier
var err error
if opt.Server.Provider.AWS != nil {
verifier, err := awsup.NewAWSVerifier(ctx, opt.Server.Provider.AWS)
verifier, err := awsbootstrap.NewAWSVerifier(ctx, opt.Server.Provider.AWS)
if err != nil {
setupLog.Error(err, "unable to create verifier")
os.Exit(1)
Expand Down
4 changes: 2 additions & 2 deletions cmd/kops-controller/pkg/config/options.go
Original file line number Diff line number Diff line change
Expand Up @@ -17,8 +17,8 @@ limitations under the License.
package config

import (
"k8s.io/kops/pkg/bootstrap/awsbootstrap"
"k8s.io/kops/pkg/bootstrap/pkibootstrap"
"k8s.io/kops/upup/pkg/fi/cloudup/awsup"
"k8s.io/kops/upup/pkg/fi/cloudup/azure"
"k8s.io/kops/upup/pkg/fi/cloudup/do"
gcetpm "k8s.io/kops/upup/pkg/fi/cloudup/gce/tpm"
Expand Down Expand Up @@ -86,7 +86,7 @@ type ServerOptions struct {
}

type ServerProviderOptions struct {
AWS *awsup.AWSVerifierOptions `json:"aws,omitempty"`
AWS *awsbootstrap.AWSVerifierOptions `json:"aws,omitempty"`
GCE *gcetpm.TPMVerifierOptions `json:"gce,omitempty"`
Hetzner *hetzner.HetznerVerifierOptions `json:"hetzner,omitempty"`
OpenStack *openstack.OpenStackVerifierOptions `json:"openstack,omitempty"`
Expand Down
4 changes: 2 additions & 2 deletions nodeup/pkg/model/bootstrap_client.go
Original file line number Diff line number Diff line change
Expand Up @@ -24,11 +24,11 @@ import (

"k8s.io/kops/pkg/apis/kops"
"k8s.io/kops/pkg/bootstrap"
"k8s.io/kops/pkg/bootstrap/awsbootstrap"
"k8s.io/kops/pkg/bootstrap/pkibootstrap"
"k8s.io/kops/pkg/kopscontrollerclient"
"k8s.io/kops/pkg/wellknownports"
"k8s.io/kops/upup/pkg/fi"
"k8s.io/kops/upup/pkg/fi/cloudup/awsup"
"k8s.io/kops/upup/pkg/fi/cloudup/azure"
"k8s.io/kops/upup/pkg/fi/cloudup/do"
"k8s.io/kops/upup/pkg/fi/cloudup/gce/tpm/gcetpmsigner"
Expand All @@ -53,7 +53,7 @@ func (b BootstrapClientBuilder) Build(c *fi.NodeupModelBuilderContext) error {

switch b.CloudProvider() {
case kops.CloudProviderAWS:
a, err := awsup.NewAWSAuthenticator(c.Context(), b.Cloud.Region())
a, err := awsbootstrap.NewAWSAuthenticator(c.Context(), b.Cloud.Region())
if err != nil {
return err
}
Expand Down
4 changes: 3 additions & 1 deletion nodeup/pkg/model/context.go
Original file line number Diff line number Diff line change
Expand Up @@ -34,6 +34,7 @@ import (
"k8s.io/kops/pkg/apis/nodeup"
"k8s.io/kops/pkg/systemd"
"k8s.io/kops/upup/pkg/fi"
"k8s.io/kops/upup/pkg/fi/nodeup/awsup"
"k8s.io/kops/upup/pkg/fi/nodeup/nodetasks"
"k8s.io/kops/upup/pkg/fi/utils"
"k8s.io/kops/util/pkg/architectures"
Expand All @@ -49,7 +50,8 @@ const (

// NodeupModelContext is the context supplied the nodeup tasks
type NodeupModelContext struct {
Cloud fi.Cloud
// Cloud holds the AWS clients, on AWS only.
Cloud *awsup.Cloud
Architecture architectures.Architecture
GPUVendor architectures.GPUVendor
Assets *fi.AssetStore
Expand Down
12 changes: 6 additions & 6 deletions nodeup/pkg/model/kube_scheduler.go
Original file line number Diff line number Diff line change
Expand Up @@ -27,8 +27,8 @@ import (
"k8s.io/kops/pkg/flagbuilder"
"k8s.io/kops/pkg/k8scodecs"
"k8s.io/kops/pkg/kubemanifest"
"k8s.io/kops/pkg/model/components/kubescheduler"
"k8s.io/kops/pkg/rbac"
"k8s.io/kops/pkg/wellknownpaths"
"k8s.io/kops/upup/pkg/fi"
"k8s.io/kops/upup/pkg/fi/nodeup/nodetasks"
"k8s.io/kops/util/pkg/env"
Expand Down Expand Up @@ -94,15 +94,15 @@ func (b *KubeSchedulerBuilder) Build(c *fi.NodeupModelBuilderContext) error {
kubeconfig := b.BuildIssuedKubeconfig("kube-scheduler", nodetasks.PKIXName{CommonName: rbac.KubeScheduler}, c)

c.AddTask(&nodetasks.File{
Path: kubescheduler.KubeConfigPath,
Path: wellknownpaths.KubeSchedulerKubeConfig,
Contents: kubeconfig,
Type: nodetasks.FileType_File,
Mode: s("0400"),
})
}

// Load the kube-scheduler config object if one has been provided.
kubeSchedulerConfigAsset := b.findFileAsset(kubescheduler.KubeSchedulerConfigPath)
kubeSchedulerConfigAsset := b.findFileAsset(wellknownpaths.KubeSchedulerConfig)

if kubeSchedulerConfigAsset != nil {
klog.Infof("using kubescheduler configuration from file assets")
Expand All @@ -117,7 +117,7 @@ func (b *KubeSchedulerBuilder) Build(c *fi.NodeupModelBuilderContext) error {
return err
}
c.AddTask(&nodetasks.File{
Path: kubescheduler.KubeSchedulerConfigPath,
Path: wellknownpaths.KubeSchedulerConfig,
Contents: fi.NewBytesResource(kubeSchedulerConfig),
Type: nodetasks.FileType_File,
Mode: s("0400"),
Expand All @@ -143,7 +143,7 @@ func NewSchedulerConfig(apiVersion string) *SchedulerConfig {
schedConfig.APIVersion = apiVersion
schedConfig.Kind = "KubeSchedulerConfiguration"
schedConfig.ClientConnection = ClientConnectionConfig{}
schedConfig.ClientConnection.Kubeconfig = kubescheduler.KubeConfigPath
schedConfig.ClientConnection.Kubeconfig = wellknownpaths.KubeSchedulerKubeConfig
return schedConfig
}

Expand Down Expand Up @@ -193,7 +193,7 @@ func (b *KubeSchedulerBuilder) buildPod(kubeScheduler *kops.KubeSchedulerConfig)
flags = append(flags, "--authentication-skip-lookup=false")
// Add kubeconfig flags
for _, flag := range []string{"authentication-", "authorization-"} {
flags = append(flags, "--"+flag+"kubeconfig="+kubescheduler.KubeConfigPath)
flags = append(flags, "--"+flag+"kubeconfig="+wellknownpaths.KubeSchedulerKubeConfig)
}

pod := &v1.Pod{
Expand Down
4 changes: 1 addition & 3 deletions nodeup/pkg/model/kubelet.go
Original file line number Diff line number Diff line change
Expand Up @@ -45,7 +45,6 @@ import (
"k8s.io/kops/pkg/rbac"
"k8s.io/kops/pkg/systemd"
"k8s.io/kops/upup/pkg/fi"
"k8s.io/kops/upup/pkg/fi/cloudup/awsup"
azurecloud "k8s.io/kops/upup/pkg/fi/cloudup/azure"
"k8s.io/kops/upup/pkg/fi/nodeup/nodetasks"
"k8s.io/kops/util/pkg/distributions"
Expand Down Expand Up @@ -783,9 +782,8 @@ func (b *KubeletBuilder) buildKubeletConfigSpec(ctx context.Context) (*kops.Kube
instanceTypeName = ec2types.InstanceType(*b.NodeupConfig.DefaultMachineType)
}

awsCloud := b.Cloud.(awsup.AWSCloud)
// Get the instance type's detailed information.
instanceType, err := awsup.GetMachineTypeInfo(awsCloud, instanceTypeName)
instanceType, err := b.Cloud.GetMachineTypeInfo(ctx, instanceTypeName)
if err != nil {
return nil, err
}
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -14,7 +14,7 @@ See the License for the specific language governing permissions and
limitations under the License.
*/

package awsup
package awsbootstrap

import (
"bytes"
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -14,7 +14,7 @@ See the License for the specific language governing permissions and
limitations under the License.
*/

package awsup
package awsbootstrap

import (
"bytes"
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -14,7 +14,7 @@ See the License for the specific language governing permissions and
limitations under the License.
*/

package awsup
package awsbootstrap

import (
"bytes"
Expand All @@ -38,10 +38,15 @@ import (
"github.com/aws/aws-sdk-go-v2/service/sts"
"k8s.io/apimachinery/pkg/util/sets"
"k8s.io/kops/pkg/bootstrap"
nodeidentityaws "k8s.io/kops/pkg/nodeidentity/aws"
"k8s.io/kops/pkg/wellknownports"
)

// cloudTagInstanceGroupName is the cloud tag that identifies the instance group an instance belongs to.
// It must match nodeidentityaws.CloudTagInstanceGroupName; it is declared here because importing
// pkg/nodeidentity/aws would store *ec2.Client in an interface, keeping every EC2 operation in the
// nodeup binary.
const cloudTagInstanceGroupName = "kops.k8s.io/instancegroup"

type AWSVerifierOptions struct {
// NodesRoles are the IAM roles that worker nodes are permitted to have.
NodesRoles []string `json:"nodesRoles"`
Expand Down Expand Up @@ -334,7 +339,7 @@ func (a awsVerifier) verifyCallerIdentity(ctx context.Context, callerIdentity *G

for _, tag := range instance.Tags {
tagKey := aws.ToString(tag.Key)
if tagKey == nodeidentityaws.CloudTagInstanceGroupName {
if tagKey == cloudTagInstanceGroupName {
result.InstanceGroupName = aws.ToString(tag.Value)
}
}
Expand Down Expand Up @@ -459,3 +464,43 @@ func buildSTSRequestValidator(ctx context.Context, stsClient *sts.Client) (*stsR
}
return &stsRequestValidator{Host: u.Host}, nil
}

// GetInstanceCertificateNames returns the instance hostname and addresses that should go into certificates.
// The first value is the node name and any additional values are the DNS name and IP addresses.
func GetInstanceCertificateNames(instances *ec2.DescribeInstancesOutput) (addrs []string, err error) {
if len(instances.Reservations) != 1 {
return nil, fmt.Errorf("too many reservations returned for the single instance-id")
}

if len(instances.Reservations[0].Instances) != 1 {
return nil, fmt.Errorf("too many instances returned for the single instance-id")
}

instance := instances.Reservations[0].Instances[0]

addrs = append(addrs, *instance.InstanceId)

if instance.PrivateDnsName != nil {
addrs = append(addrs, *instance.PrivateDnsName)
}

// We only use data for the first interface, and only the first IP
for _, iface := range instance.NetworkInterfaces {
if iface.Attachment == nil {
continue
}
if *iface.Attachment.DeviceIndex != 0 {
continue
}
if iface.PrivateIpAddress != nil {
addrs = append(addrs, *iface.PrivateIpAddress)
}
if len(iface.Ipv6Addresses) > 0 {
addrs = append(addrs, *iface.Ipv6Addresses[0].Ipv6Address)
}
if iface.Association != nil && iface.Association.PublicIp != nil {
addrs = append(addrs, *iface.Association.PublicIp)
}
}
return addrs, nil
}
Original file line number Diff line number Diff line change
Expand Up @@ -14,7 +14,7 @@ See the License for the specific language governing permissions and
limitations under the License.
*/

package awsup
package awsbootstrap

import (
"bytes"
Expand Down
26 changes: 26 additions & 0 deletions pkg/dns/placeholder.go
Original file line number Diff line number Diff line change
@@ -0,0 +1,26 @@
/*
Copyright 2026 The Kubernetes Authors.

Licensed under the Apache License, Version 2.0 (the "License");
you may not use this file except in compliance with the License.
You may obtain a copy of the License at

http://www.apache.org/licenses/LICENSE-2.0

Unless required by applicable law or agreed to in writing, software
distributed under the License is distributed on an "AS IS" BASIS,
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
See the License for the specific language governing permissions and
limitations under the License.
*/

package dns

const (
// PlaceholderIP is the IP kOps writes into DNS records before the control plane comes up.
// Clients treat a record resolving to this IP as not yet available.
// It is from TEST-NET-3: https://en.wikipedia.org/wiki/Reserved_IP_addresses
PlaceholderIP = "203.0.113.123"
// PlaceholderIPv6 is the IPv6 equivalent of PlaceholderIP.
PlaceholderIPv6 = "fd00:dead:add::"
)
4 changes: 2 additions & 2 deletions pkg/kopscontrollerclient/client.go
Original file line number Diff line number Diff line change
Expand Up @@ -34,8 +34,8 @@ import (
"k8s.io/apimachinery/pkg/util/wait"
"k8s.io/klog/v2"
"k8s.io/kops/pkg/bootstrap"
"k8s.io/kops/pkg/dns"
"k8s.io/kops/upup/pkg/fi"
"k8s.io/kops/upup/pkg/fi/cloudup"
"k8s.io/kops/util/pkg/vfs"
)

Expand Down Expand Up @@ -89,7 +89,7 @@ func (b *Client) Query(ctx context.Context, req any, resp any) error {
return fi.NewTryAgainLaterError(fmt.Sprintf("kops-controller DNS not setup yet (not found: %v)", dnsErr))
}
return err
} else if len(ips) == 1 && (ips[0].String() == cloudup.PlaceholderIP || ips[0].String() == cloudup.PlaceholderIPv6) {
} else if len(ips) == 1 && (ips[0].String() == dns.PlaceholderIP || ips[0].String() == dns.PlaceholderIPv6) {
return fi.NewTryAgainLaterError(fmt.Sprintf("kops-controller DNS not setup yet (placeholder IP found: %v)", ips))
}

Expand Down
11 changes: 3 additions & 8 deletions pkg/model/components/kubescheduler/model.go
Original file line number Diff line number Diff line change
Expand Up @@ -29,17 +29,12 @@ import (
"k8s.io/kops/pkg/assets"
"k8s.io/kops/pkg/kubemanifest"
"k8s.io/kops/pkg/model"
"k8s.io/kops/pkg/wellknownpaths"
"k8s.io/kops/upup/pkg/fi"
"k8s.io/kops/util/pkg/reflectutils"
"sigs.k8s.io/yaml"
)

// KubeSchedulerConfigPath is the path where we write the kube-scheduler config file (on the control-plane nodes)
const KubeSchedulerConfigPath = "/var/lib/kube-scheduler/config.yaml"

// Kubeconfig is the path where we write the kube-scheduler kubeconfig file (on the control-plane nodes)
const KubeConfigPath = "/var/lib/kube-scheduler/kubeconfig"

// KubeSchedulerBuilder builds the configuration file for kube-scheduler
type KubeSchedulerBuilder struct {
*model.KopsModelContext
Expand All @@ -57,7 +52,7 @@ func (b *KubeSchedulerBuilder) Build(c *fi.CloudupModelBuilderContext) error {
}

b.AssetBuilder.AddStaticFile(&assets.StaticFile{
Path: KubeSchedulerConfigPath,
Path: wellknownpaths.KubeSchedulerConfig,
Content: string(configYAML),
Roles: []kops.InstanceGroupRole{kops.InstanceGroupRoleControlPlane, kops.InstanceGroupRoleAPIServer},
})
Expand Down Expand Up @@ -94,7 +89,7 @@ func (b *KubeSchedulerBuilder) buildSchedulerConfig() ([]byte, error) {

// TODO: Handle different versions? e.g. gvk := config.GroupVersionKind()

if err := unstructured.SetNestedField(config.Object, KubeConfigPath, "clientConnection", "kubeconfig"); err != nil {
if err := unstructured.SetNestedField(config.Object, wellknownpaths.KubeSchedulerKubeConfig, "clientConnection", "kubeconfig"); err != nil {
return nil, fmt.Errorf("error setting clientConnection.kubeconfig in kube-scheduler configuration: %w", err)
}

Expand Down
4 changes: 2 additions & 2 deletions pkg/validation/validate_cluster.go
Original file line number Diff line number Diff line change
Expand Up @@ -28,8 +28,8 @@ import (
"k8s.io/client-go/rest"
"k8s.io/client-go/tools/pager"
"k8s.io/kops/pkg/apis/kops"
"k8s.io/kops/pkg/dns"
"k8s.io/kops/upup/pkg/fi"
"k8s.io/kops/upup/pkg/fi/cloudup"

v1 "k8s.io/api/core/v1"
metav1 "k8s.io/apimachinery/pkg/apis/meta/v1"
Expand Down Expand Up @@ -101,7 +101,7 @@ func hasPlaceHolderIP(host string) (string, error) {

sort.Strings(hostAddrs)
for _, h := range hostAddrs {
if h == cloudup.PlaceholderIP || h == cloudup.PlaceholderIPv6 {
if h == dns.PlaceholderIP || h == dns.PlaceholderIPv6 {
return h, nil
}
}
Expand Down
28 changes: 28 additions & 0 deletions pkg/wellknownpaths/wellknownpaths.go
Original file line number Diff line number Diff line change
@@ -0,0 +1,28 @@
/*
Copyright 2026 The Kubernetes Authors.

Licensed under the Apache License, Version 2.0 (the "License");
you may not use this file except in compliance with the License.
You may obtain a copy of the License at

http://www.apache.org/licenses/LICENSE-2.0

Unless required by applicable law or agreed to in writing, software
distributed under the License is distributed on an "AS IS" BASIS,
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
See the License for the specific language governing permissions and
limitations under the License.
*/

// Package wellknownpaths holds file paths that are shared between the
// cloudup model (which generates the files) and nodeup (which writes them
// to the nodes).
package wellknownpaths

const (
// KubeSchedulerConfig is the path where we write the kube-scheduler config file (on the control-plane nodes).
KubeSchedulerConfig = "/var/lib/kube-scheduler/config.yaml"

// KubeSchedulerKubeConfig is the path where we write the kube-scheduler kubeconfig file (on the control-plane nodes).
KubeSchedulerKubeConfig = "/var/lib/kube-scheduler/kubeconfig"
)
Loading
Loading