Remove support for gossip DNS - #18601
Conversation
40d517c to
cc60d82
Compare
|
/test all |
|
/retest |
|
CSI flakes... |
|
@hakman: Overrode contexts on behalf of hakman: pull-kops-e2e-azure-cni-calico DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
cc60d82 to
7ce9fac
Compare
|
/approve i'll let someone else take a pass too since it is so large. |
@rifelpet quite right on this one, so decided to revert some of the mechanical changes to make it more reviewable. |
|
/test pull-kops-e2e-cni-cilium-etcd |
|
/test pull-kops-e2e-cni-cilium-etcd |
20cb470 to
c2c893f
Compare
Gossip DNS support is removed in kOps 1.37. Clusters whose name ends in .k8s.local without dns=none now fail validation with a message pointing at the migration path, and the deprecated gossipConfig and dnsControllerGossipConfig fields are rejected with an error asking for their removal. kops create cluster keeps defaulting .k8s.local names to dns=none.
Nodes no longer install or run protokube, whose only remaining responsibility was gossip DNS. Remove the gossip mode from dns-controller, the hosts controller and discovery options from kops-controller, the gossip branches from nodeup and the cluster model, and the gossip firewall rules. The gossipConfig and dnsControllerGossipConfig cluster spec fields are deprecated, no longer have any effect, and are rejected by validation when set. The protokube binary itself is still built and shipped; removing it is left for a separate change.
The minimal_openstack, openstack_floatingip and minimal_scaleway fixtures migrate to dns=none, as they are the only integration test coverage for their clouds.
Generated with ./hack/update-expected.sh
Keep the deprecated nodeup wire field temporarily to avoid rewriting generated nodeup configs while gossip runtime support remains removed.
Keep control-plane nodeup asset lists and hashes stable temporarily while leaving the protokube model and service removed.
Leave the unregistered gossip fixtures in place temporarily so their bulk deletion can be reviewed and merged separately.
c2c893f to
b645998
Compare
|
/test all |
|
/test pull-kops-e2e-cni-cilium |
| for _, a := range n.protokubeAsset[arch] { | ||
| config.Assets[arch] = append(config.Assets[arch], a.CompactString()) | ||
| } | ||
| // Keep protokube in control-plane nodeup configs temporarily to avoid changing |
There was a problem hiding this comment.
I'm guessing we're going to tackle this in a follow-on PR, but it would make this one huge?
There was a problem hiding this comment.
yup, too many files in this PR and make GitHub hard to use.
|
Thanks @hakman Looking at this, there are quite a few pitfalls and complexity! So if anyone is still on gossip, I think they will be much happier on dns=none at this point. Removal seems like the right call. /approve |
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: justinsb, rifelpet The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:
Approvers can indicate their approval by writing |
|
Thanks @justinsb, hope everyone will migrate safely using kOps 1.36. |
|
/override pull-kops-e2e-cni-amazonvpc |
|
@hakman: Overrode contexts on behalf of hakman: pull-kops-e2e-cni-amazonvpc DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
Support for gossip DNS, deprecated since kOps 1.29, is removed in kOps 1.37, see #18240.
New gossip clusters are rejected, and existing clusters need to migrate before they can be upgraded. This affects clusters whose name ends in
.k8s.localand that were not created with--dns=none; clusters using--dns=none, even with a.k8s.localname, are not affected. Migrate to--dns=noneor a hosted DNS zone using kOps 1.36, which introduced hybrid bootstrap to make that migration easier.What changed
kops createandkops update cluster, whilekops get,kops delete cluster,kops validate cluster, and anedit/replacethat switches the cluster todns: nonekeep working for unmigrated clusters.--dns=gossip(effectively running dns-controller with no provider) is removed; AWS now always usesaws-route53.spec.gossipConfigandspec.dnsControllerGossipConfigcluster spec fields are removed from all API versions. Old stored specs still load, as unknown fields are dropped on decode.ec2:DescribeInstancespermissions that legacy gossip bootstrap required.minimal_openstack,openstack_floatingipandminimal_scalewayfixtures migrate todns=none, as they are the only integration test coverage for their clouds.Notes for reviewers
DenyNodesToEtcdNSG rule narrows from port range 4000-4001 to just 4001, as 4000 was the protokube memberlist port.upgrade-ab-gossipe2e scenario is deleted; the corresponding prow job needs to be removed in test-infra../hack/update-expected.sh./cc @rifelpet @justinsb